Nitrogenαװ³É PuTTY »ò FileZilla ²¿ÊðBlackCat

Ðû²¼Ê±¼ä 2024-04-11
1. Nitrogenαװ³É PuTTY »ò FileZilla ²¿ÊðBlackCat


4ÔÂ9ÈÕ £¬×î³õµÄÈëÇÖÊÇ´Óͨ¹ý Google ËÑË÷ÏÔʾµÄ¶ñÒâ¹ã¸æ¿ªÊ¼µÄ¡£ÎÒÃÇÊӲ쵽Á˼¸¸ö²îÒìµÄ¹ã¸æ¿Í»§ÕÊ»§ £¬ÕâЩÕÊ»§¶¼³ÂË߸øÁ˹ȸè¡£ÕâЩÓÕ¶üÊÇ IT ¹ÜÀíÔ±³£ÓõÄʵÓ÷¨Ê½ £¬ÀýÈç PuTTY ºÍ FileZilla¡£Nitrogen ÍþвÐÐΪÕß²¿ÊðµÄ¶ñÒâ¹ã¸æ»ù´¡ÉèʩʹÓÃαװҳÃæ £¬¸ÃÒ³Ãæ¿ÉÒÔÖض¨Ïòµ½ÓÕ¶üÍøÕ¾»òÎÛÃûÕÑÖøµÄ Rick Astley ÊÓƵ¡£Èç¹û»î¶¯ÉÐδÎäÆ÷»¯»ò¶ñÒâ·þÎñÆ÷¼ì²âµ½ÎÞЧÁ÷Á¿£¨»úÆ÷ÈË¡¢ÅÀ³æµÈ£© £¬Ôò¿ÉÒÔ¼¤»îµ½ÓÕ¶üÒ³ÃæµÄÖض¨Ïò¡£¸Ã¶ñÒâ¹ã¸æÁ´µÄ×îºóÒ»²½°üÂÞÏÂÔز¢ÔËÐжñÒâÈí¼þÓÐЧ¸ºÔØ¡£Nitrogen ʹÓÃÒ»ÖÖ³ÆΪ DLL ÅÔ¼ÓÔصļ¼Êõ £¬Í¨¹ý¸Ã¼¼Êõ £¬ºÏ·¨ÇÒ¾­¹ýÇ©ÃûµÄ¿ÉÖ´ÐÐÎļþ»áÆô¶¯ DLL¡£ÔÚ±¾ÀýÖÐ £¬setup.exe£¨À´×Ô Python Software Foundation£©²àÔØpython311.dll (Nitrogen)¡£


https://www.malwarebytes.com/blog/threat-intelligence/2024/04/active-nitrogen-campaign-delivered-via-malicious-ads-for-putty-filezilla


2. ΢ÈíÐÞ¸´ÁË Windows Á½¸öÒѾ­±»ÀûÓõÄÁãÈÕ©¶´


4ÔÂ9ÈÕ £¬Î¢ÈíÔÚ 2024 Äê 4 ÔµIJ¹¶¡ÐÇÆÚ¶þÆÚ¼äÐÞ¸´ÁËÁ½¸ö±»»ý¼«ÀûÓõÄÁãÈÕ©¶´ £¬¾¡¹Ü¸Ã¹«Ë¾×î³õδÄܶÔËüÃǽøÐбêÖ¾¡£µÚÒ»¸ö©¶´±»¸ú×ÙΪCVE-2024-26234 £¬±»ÃèÊöΪÊðÀíÇý¶¯·¨Ê½ÆÛƭ©¶´ £¬Ö¼ÔÚ¸ú×٠ʹÓÃÓÐЧµÄ Microsoft Ó²¼þ¿¯ÐÐÉÌÖ¤ÊéÇ©ÃûµÄ¶ñÒâÇý¶¯·¨Ê½ £¬¸Ã¶ñÒâÎļþ±»¡°Catalog Thales¡±±ê־Ϊ¡°Catalog Authentication Client Service¡± £¬¿ÉÄÜÊÇÊÔͼð³ä Thales Group¡£µÚ¶þ¸öÁãÈÕ©¶´±»×·×ÙΪCVE-2024-29988 £¬±»ÃèÊöΪÓɱ£»¤»úÖƹÊÕÏÈõµãµ¼ÖµÄSmartScreenÌáʾÄþ¾²¹¦Ð§Èƹý©¶´¡£CVE-2024-29988 ÊÇ CVE-2024-21412 ȱÏݵÄÈƹýÒªÁì £¬ÓÉÇ÷ÊƿƼ¼ÁãÈռƻ®µÄ Peter Girnus ÒÔ¼° Google Íþв·ÖÎöС×é Dmitrij Lenz ºÍ Vlad Stolyarov ³ÂËß¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-two-windows-zero-days-exploited-in-malware-attacks/


3. Áè¼Ý9.1Íǫ̀ LG ÖÇÄܵçÊÓÈÝÒ×Êܵ½ºÚ¿Í¹¥»÷


4ÔÂ9ÈÕ £¬Bitdefender Ñо¿ÈËÔ±ÔÚÖÇÄܵçÊÓÉÏÔËÐÐµÄ LG webOS Öз¢ÏÖÁ˶à¸ö©¶´ £¬ÕâЩ©¶´¿É±»ÓÃÀ´ÈƹýÊÚȨ²¢»ñµÃÉ豸µÄ root ·ÃÎÊȨÏÞ¡£Ñо¿ÈËÔ±·¢Ïֵĩ¶´Ó°Ïì LG µçÊÓÉÏÔËÐÐµÄ WebOS °æ±¾ 4 ÖÁ 7¡£WebOS ÔÚ¶Ë¿Ú 3000/3001 (HTTP/HTTPS/WSS) ÉÏÔËÐÐÒ»Ïî·þÎñ £¬LG ThinkQ ÖÇÄÜÊÖ»úÓ¦Ó÷¨Ê½Ê¹Óø÷þÎñÀ´¿ØÖƵçÊÓ¡£ÒªÉèÖøÃÓ¦Ó÷¨Ê½ £¬Óû§±ØÐëÔÚµçÊÓÆÁÄ»ÉÏÊäÈë PIN Âë¡£ÕÊ»§´¦Ö÷¨Ê½ÖеĴíÎóʹ¹¥»÷Õß¿ÉÒÔÍêÈ«Ìø¹ý PIN ÑéÖ¤²¢´´½¨ÌØȨÓû§ÅäÖÃÎļþ¡£¾¡¹Ü¸ÃÒ×Êܹ¥»÷µÄ·þÎñ½öÓÃÓÚ LAN ·ÃÎÊ £¬µ«Í¨¹ý²éѯ Shodan £¬ËûÃÇ·¢ÏÖÁËÁè¼Ý 91000 ¸ö½«¸Ã ·þÎñ̻¶µ½»¥ÁªÍøµÄÉ豸¡£´Ëʱ £¬Ì»Â¶µÄÉ豸ÊýÁ¿¼õÉÙÖÁ88000¸ö¡£´ó¶àÊýÃæÏò»¥ÁªÍøµÄÉ豸λÓÚº«¹ú¡¢ÃÀ¹ú¡¢ÈðµäºÍ·ÒÀ¼µÈ¡£


https://securityaffairs.com/161651/hacking/lg-smart-tvs-vulnerable.html


4. GHC-SCW³ÆÀÕË÷Èí¼þÍÅ»ïÇÔÈ¡ÁËÆä53ÍòÈ˵Ľ¡¿µÊý¾Ý


4ÔÂ9ÈÕ £¬Íþ˹¿µÐÇÖÝÖÐÄϲ¿·ÇÓªÀûÐÔÒ½ÁÆ·þÎñÌṩÉÌ Group Health Cooperative (GHC-SCW) Åû¶ £¬ÀÕË÷Èí¼þÍÅ»ïÓÚ 1 Ô·ÝÇÖÈëÆäÍøÂç £¬ÇÔÈ¡ÁË°üÂÞÁè¼Ý 50 ÍòÈ˵ĸöÈ˺ÍÒ½ÁÆÐÅÏ¢µÄÎļþ¡£È»¶ø £¬¹¥»÷ÕßÎÞ·¨¼ÓÃÜÊÜѬȾµÄÉ豸 £¬ÕâʹµÃ GHC-SCW ÔÚÍⲿÍøÂçʼþÏìӦר¼ÒµÄ×ÊÖúϱ£»¤Æäϵͳ £¬²¢ÔÚ¸ôÀëÕâЩÉ豸ÒÔֹͣ©¶´ºó½«Æä»Ö¸´ÔÚÏß¡£Ò»Ô·ÝÀÕË÷Èí¼þ¹¥»÷Æڼ䱻µÁµÄ½¡¿µÊý¾Ý°üÂÞÊÜÓ°Ïì¸öÈ˵ÄÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·¡¢³öÉúºÍ/»òËÀÍöÈÕÆÚ¡¢Éç»áÄþ¾²ºÅÂë¡¢»áÔ±ºÅÂëÒÔ¼°Ò½ÁƱ£ÏÕºÍ/»òÒ½ÁƲ¹ÖúºÅÂë¡£¾¡¹ÜûÓÐÌṩÊÜÓ°ÏìÈËÊýµÄ¾ßÌåÊý×Ö £¬µ«ÓëÃÀ¹úÎÀÉúÓ빫ÖÚ·þÎñ²¿¹²ÏíµÄÆäËûÐÅÏ¢ÏÔʾ £¬Êý¾Ýй¶ӰÏìÁË 533809 ÈË¡£


https://www.bleepingcomputer.com/news/security/ghc-scw-ransomware-gang-stole-health-data-of-533-000-people/


5. BatBadBut Rust ©¶´Ê¹ Windows ϵͳÃæÁÙ¹¥»÷


4ÔÂ10ÈÕ £¬Rust ³ß¶È¿âÖеÄÒ»¸öÒªº¦Äþ¾²Â©¶´¿ÉÄܻᱻÀûÓÃÀ´Õë¶Ô Windows Óû§²¢ÌᳫÃüÁî×¢Èë¹¥»÷¡£¸Ã©¶´µÄ±àºÅΪCVE-2024-24576 £¬CVSS ÆÀ·ÖΪ 10.0 £¬±íÃ÷ÑÏÖØˮƽ×î¸ß¡£Ò²¾ÍÊÇ˵ £¬Ëü½öÓ°ÏìÔÚ Windows ÉÏʹÓò»ÊÜÐÅÈεIJÎÊýµ÷ÓÃÅú´¦ÖÃÎļþµÄ³¡¾°¡£Rust Äþ¾²ÏìÓ¦ÊÂÇé×éÔÚ 2024 Äê 4 Ô 9 ÈÕÐû²¼µÄͨ¸æÖÐÌåÏÖ£ºÔÚ Windows ÉÏʹÓà Command API µ÷ÓÃÅú´¦ÖÃÎļþ£¨´øÓÐ bat ºÍ cmd À©Õ¹Ãû£©Ê± £¬Rust ³ß¶È¿âûÓÐÕýȷתÒå²ÎÊý¡£Äܹ»¿ØÖÆͨ±¨¸øÉú³É½ø³ÌµÄ²ÎÊýµÄ¹¥»÷Õß¿ÉÒÔͨ¹ýÈƹýתÒåÀ´Ö´ÐÐÈÎÒâ shell ÃüÁî¡£¸ÃȱÏÝÓ°Ïì 1.77.2 ֮ǰµÄËùÓÐ Rust °æ±¾¡£


https://thehackernews.com/2024/04/critical-batbadbut-rust-vulnerability.html


6. Medusa ÍÅ»ï³Æ¶ÔµÂ¿ËÈø˹ÖÝijÕþ¸®»ú¹¹µÄ¹¥»÷ÂôÁ¦


4ÔÂ9ÈÕ £¬ËþÀ¼ÌØÏØÆÀ¹ÀÇø£¨Tarrant County Appraisal District£©ÂôÁ¦È·¶¨ÎÖ˹±¤µØÓòÓÃÓÚË°ÊÕÄ¿µÄµÄ·¿µØ²ú £¬Á½ÖÜÇ°Ïò Recorded Future News  Ö¤Êµ £¬¸ÃÏØÊÇÀÕË÷Èí¼þ¹¥»÷µÄÊܺ¦Õß¡£ÖÜÒ» £¬Medusa ÍøÂç·¸×ïÍÅ»ïÉù³Æ¶ÔÕâÆðʼþÂôÁ¦ £¬²¢Íþв³Æ £¬Èç¹û²»Ö§¸¶ 10 ÍòÃÀÔªµÄÊê½ð £¬ËûÃǽ«ÔÚÁùÌìÄÚ¹ûÈ»½ü 218 GB µÄÊý¾Ý¡£ÏعÙԱûÓлØÓ¦ÓйØÊÇ·ñÖ§¸¶Êê½ðµÄÖÃÆÀÇëÇó £¬µ«ËûÃÇÓÚ 4 Ô 3 ÈÕÐû²¼¾¯¸æ³Æ £¬ºÚ¿Í¹ûÈ»ÁËÔ¼ 300 È˵ÄÊý¾Ý¡£¸Ã×éÖ¯ÓÚ 2023 ÄêÊ״ηºÆ𠣬ÆäÊܺ¦ÕßÃûµ¥Ñ¸ËÙÀ©´ó¡£ÃÀ¶ÅɯÒò¶Ô·áÌïºÍ¼ÓÄôóÁ½¼Ò×î´óÒøÐеĹ¥»÷¶ø³ÉΪͷÌõÐÂÎÅ¡£


https://therecord.media/tarrant-county-texas-ransomware-attack-medusa