¼ÓÖÝij¸£Àûƽ̨Ôâµ½¹¥»÷Êýǧ¸öÕË»§ÐÅϢй¶

Ðû²¼Ê±¼ä 2024-04-29
1. ¼ÓÖÝij¸£Àûƽ̨Ôâµ½¹¥»÷Êýǧ¸öÕË»§ÐÅϢй¶


4ÔÂ27ÈÕ £¬ÍþвÐÐΪÕßÈëÇÖÁ˼ÓÖÝÒ»¸öרÃÅÓÃÓÚ¸£ÀûÏîÄ¿µÄƽ̨É쵀 19000 ¶à¸öÔÚÏßÕÊ»§¡£¹ÙÔ±ÃdzÂËß³Æ £¬Äþ¾²Â©¶´·¢ÉúÔÚ 2 Ô 9 ÈÕ £¬ÆäʱÓÐÈ˵ǼÁËһЩ BenefitsCal Óû§µÄÕË»§¡£ÍþвÐÐΪÕßÀûÓôӵÚÈý·½ÍøÕ¾»ñµÃµÄÖظ´Ê¹ÓõÄÃÜÂë¡£BenefitsCal ÊÇÒ»¸öλÓÚ¼ÓÀû¸£ÄáÑÇÖݵÄÍøÂçƽ̨ £¬Ê¹Óû§Äܹ»ÉêÇëºÍ¼à¶½Ò»ÏµÁи£Àû¼Æ»® £¬°üÂÞʳƷȯ¡¢ÏÖ½ðÔ®ÖúºÍÒ½ÁƸ£Àû¡£Æ¾¾ÝÈÕÆÚй¶֪ͨ £¬Ç±ÔÚ鶵ÄÐÅÏ¢¿ÉÄÜ°üÂÞÓû§ÐÕÃû¡¢µØÖ·¡¢³öÉúÈÕÆÚ¡¢Éç»áÄþ¾²ºÅÂëµÄÍêÕû»ò×îºóËÄλÊý×Ö¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢EBT ¿¨ºÅ¡¢°¸¼þ±àºÅ¡¢Medi-Cal ID ºÅÒÔ¼°ÓйØÆä¼Æ»®×ʸñºÍ¸£ÀûµÄÐÅÏ¢¡£BenefitsCal ÕýÔÚ֪ͨÊÜÓ°ÏìµÄÓû§²¢ÏòËûÃÇÌṩ¿ÉÒÔ×öʲôµÄ˵Ã÷¡£ÎªÁËÓ¦¶ÔÕâһʼþ £¬¸Ã»ú¹¹Í£ÓÃÁËÕË»§²¢Æô¶¯ÁËÊÓ²ì £¬½á¹ûÏÔʾ¹¥»÷ÕßÔÚ 2023 Äê 3 Ô 1 ÈÕÖÁ 2024 Äê 2 Ô 13 ÈÕÆÚ¼äÓµÓзÃÎÊȨÏÞ¡£ 


https://securityaffairs.com/162408/data-breach/california-state-welfare-platform-accounts-compromise.html


2. Å·ÖÞÐ̾¯×éÖ¯Ðû²¼ÔÚÖ´·¨Ðж¯ÖÐÈ¡µÞLabHost


4ÔÂ26ÈÕ £¬Å·ÖÞÐ̾¯×éÖ¯Ðû²¼ £¬È«Çò×î´óµÄPhaasƽ̨֮һ LabHost ÔÚÈ«ÇòÖ´·¨Ðж¯Öб»µ·»Ù¡£À´×Ô²»ÉÙÓÚ 19 ¸ö¹ú¼ÒµÄÕþ¸®¼ÓÈëÁËÓÉÓ¢¹úÂ׶ؾ¯²ìÌüǣͷµÄΪÆÚÒ»ÄêµÄÐж¯ £¬´þ²¶ÁË 37 ÃûÏÓÒÉÈË £¬ÆäÖаüÂ޾ݳÆÓë¸Ã·þÎñÔËÓª¼°Æäԭʼ¿ª·¢ÓйصÄÈË¡£È«ÇòÔ¼ÓÐ 10000 ÈËʹÓø÷þÎñ £¬Ô·Ñƽ¾ùΪ 249 ÃÀÔª¡£ÊӲ췢ÏÖÖÁÉÙ 40000 ¸öÓë LabHost Á´½ÓµÄÍøÂçµöÓãÓòÃû £¬²¢ÓÕÆ­Óû§½»³öÃô¸ÐÏêϸÐÅÏ¢¡£Á˽âÓйØÊÓƵÖеĴÌÍ´µÄ¸ü¶àÐÅÏ¢ £¬²¢È·±£ÄúÖªµÀÈçºÎÖÆÖ¹³ÉΪÍøÂçµöÓã¹¥»÷µÄÊܺ¦Õß¡£ÔÚÆäËûÍøÂç·¸×ïÐÂÎÅÖÐ £¬ÃÀ¹úÖ´·¨²¿ÃÅ¶Ô Samourai Wallet¼ÓÃÜ»õ±Ò»ìºÏ·þÎñµÄÊ×´´ÈËÌá³öϴǮָ¿Ø £¬Í¬Ê±Áª°î¹¥»÷´ËÀà·þÎñ¡£


https://www.welivesecurity.com/en/videos/major-phishing-as-a-service-platform-disrupted-week-security-tony-anscombe/


3. Ñо¿ÍŶӷ¢ÏÖʹÓÃoffice©¶´Õë¶ÔÎÚ¿ËÀ¼µÄ¹¥»÷»î¶¯


4ÔÂ27ÈÕ £¬ÍøÂçÄþ¾²Ñо¿ÈËÔ±·¢ÏÖÁËÕë¶ÔÎÚ¿ËÀ¼µÄÒ»ÏîÓÐÕë¶ÔÐԵĹ¥»÷»î¶¯ £¬¸ÃÐж¯ÀûÓÃÁË Microsoft Office ÖнüÆßÄêµÄij¸ö©¶´ £¬ÔÚÊÜѬȾµÄϵͳÉÏ´« Cobalt Strike¡£¾Ý Deep Instinct ³Æ £¬¸Ã¹¥»÷Á´·¢ÉúÓÚ 2023 Äêµ× £¬½ÓÄÉ PowerPoint »ÃµÆƬÎļþ£¨¡°signal-2023-12-20-160512.ppsx¡±£©×÷ΪÆðµã £¬ÎļþÃûÌåÏÖËü¿ÉÄÜÒÑͨ¹ý Signal ¼´Ê±Í¨Ñ¶Ó¦Ó÷¨Ê½¹²Ïí¡£¾¡¹ÜÈç´Ë £¬Ã»ÓÐʵ¼ÊÖ¤¾Ý±íÃ÷ PPSX ÎļþÊÇÒÔÕâÖÖ·½Ê½·Ö·¢µÄ £¬¾¡¹ÜÎÚ¿ËÀ¼¼ÆËã»ú½ô¼±ÏìӦС×é (CERT-UA) ·¢ÏÖÁËÁ½¸öʹÓøÃÏûÏ¢Ó¦Ó÷¨Ê½×÷Ϊ¶ñÒâÈí¼þͨ±¨µÄ²îÒì»î¶¯¹ýÈ¥µÄÏòÁ¿¡£ÕâÉæ¼°ÀûÓÃCVE-2017-8570£¨CVSS ·ÖÊý£º7.8£© £¬ÕâÊÇ Office ÖÐÏÖÒÑÐÞ²¹µÄÔ¶³Ì´úÂëÖ´ÐдíÎó £¬¸Ã´íÎó¿ÉÄÜÔÊÐí¹¥»÷ÕßÔÚ˵·þÊܺ¦Õß´ò¿ªÌØÖÆÎļþ¡¢¼ÓÔØÔ¶³Ì½Å±¾ÍйÜÔÚ weavesilk[.]space ÉÏ¡£


https://thehackernews.com/2024/04/ukraine-targeted-in-cyberattack.html


4. Okta ¾¯¸æ¿Í»§¿ÉÄÜÔâÊÜÇ°ËùδÓеÄײ¿â¹¥»÷


4ÔÂ27ÈÕ £¬Okta ¾¯¸æ³Æ £¬Õë¶ÔÆäÉí·ÝºÍ·ÃÎʹÜÀí½â¾ö·½°¸µÄײ¿â¹¥»÷·ºÆðÁËÇ°ËùδÓеļ¤Ôö¡£ÍþвÐÐΪÕßͨ¹ý×Ô¶¯ÊµÑéͨ³£´ÓÍøÂç·¸×ï·Ö×ÓÄÇÀﹺÖõÄÓû§ÃûºÍÃÜÂëÁбí £¬Ê¹ÓÃƾ֤Ìî³äÀ´µÇ¼¡£Okta ÔÚ½ñÌìµÄÒ»·Ýͨ¸æÖÐÌåÏÖ £¬ÕâЩ¹¥»÷ËƺõÔ´×Ô Cisco Talos ֮ǰ³ÂËߵı©Á¦ÆƽâºÍÃÜÂëÅçÉä¹¥»÷ÖÐʹÓõÄÏàͬ»ù´¡ÉèÊ©¡£ÔÚ Okta ÊӲ쵽µÄËùÓй¥»÷ÖÐ £¬ÇëÇó¾ùÀ´×Ô TOR ÄäÃûÍøÂçºÍÖÖÖÖסլÊðÀí£¨ÀýÈç NSOCKS¡¢Luminati ºÍ DataImpulse£©¡£Okta ÌåÏÖ £¬¼à²âµ½µÄ¹¥»÷Õë¶ÔÔÚ Okta Classic Engine ÉÏÔËÐÐÇÒ ThreatInsight ÅäÖÃΪ½öÉóºËģʽ¶ø²»ÊÇÈÕÖ¾ºÍÇ¿ÖÆģʽµÄ×éÖ¯ÌرðÈÝÒס£Í¬Ñù £¬²»¾Ü¾øÄäÃûÊðÀí·ÃÎʵÄ×éÖ¯Ò²¿´µ½Á˸ü¸ßµÄ¹¥»÷ÀÖ³ÉÂÊ¡£Okta ÌåÏÖ £¬Ö»ÓÐһС²¿ÃÅ¿Í»§µÄ¹¥»÷È¡µÃÁËÀֳɡ£


https://www.bleepingcomputer.com/news/security/okta-warns-of-unprecedented-credential-stuffing-attacks-on-customers/


5. ¾É´úÂëÖеÄдíÎóºÍÕë¶Ô KASLR µÄ²àͨµÀ


4ÔÂ26ÈÕ £¬¼´½«ÍƳöµÄ Windows 11 °æ±¾ 24H2 Ä¿Ç°ÕýÔÚͨ¹ý Windows Insider ¼Æ»®½øÐйûȻԤÀÀ¡£ÕâƪÎÄÕ½éÉÜÁË·¢ÏÖ 24H2 ÖÐÒýÈëµÄ¶à¸öÄں˩¶´²¢±à䩶´ÀûÓ÷¨Ê½µÄ¹ý³Ì £¬°üÂÞÈƹýÄÚºË ASLR (KASLR) µÄÐÂÇ¿»¯¡£ÕâÀïÃèÊöµÄËùÓЩ¶´¶¼´æÔÚÓÚ NT ÄÚºË×Ô¼º (ntoskrnl.exe) ÖÐ £¬Î»ÓÚ¿ÉÓÉÈκνø³Ìµ÷ÓõÄϵͳµ÷ÓÃÖÐ £¬ÎÞÂÛÆäȨÏÞ¼¶±ð»òɳÏäÈçºÎ¡£ÔÚ 24H2 ¶Ô NT Äں˵ĸ÷¸ö²¿ÃŽøÐÐÄæÏò¹¤³Ìʱ £¬ÎÒ·¢ÏÖÁËÁ½¸ö©¶´ £¬ÕâÁ½¸ö©¶´¶¼ÊÇÓû§Ä£Ê½ÄÚ´æµÄË«ÖØ»ñÈ¡¡£ÕâЩ´íÎóÌرðÓÐȤ £¬ÒòΪËüÃÇ·ºÆðÔÚÒÔÇ°Äþ¾²µÄºã¾Ã´æÔڵĴúÂëÖС£ÔÚÒÔÇ°µÄ Windows °æ±¾ÖÐ £¬ÓÉÓÚÐí¶àϵͳµ÷ÓÃÔÚÆäÊä³öÖаüÂÞÄÚºËÖ¸Õë £¬Òò´Ë»÷°Ü KASLR ÊÇ΢²»×ãµÀµÄ¡£È»¶ø £¬ÔÚ 24H2 ÖÐ £¬ÕâЩÄں˵Øַй©²»Ôٿɹ©·ÇÌØȨµ÷ÓÃÕßʹÓá£ÔÚûÓо­µäµÄ KASLR ÈƹýµÄÇé¿öÏ £¬ÎªÁËÈ·¶¨Äں˵Ľṹ £¬ÐèÒªÒ»ÖÖм¼Êõ¡£ÎÒÌý˵¹ýÒ»ÖÖÔÚ Linux ÉÏʹÓõļ¼Êõ £¬³ÆΪEntryBleed £¬ËüʹÓüÆʱÅÔ·À´È·¶¨Äں˵ĵØÖ· £¬²¢¾ö¶¨Ñо¿ÊÇ·ñ¿ÉÒÔÔÚ Windows ÉÏʹÓÃÀàËƵļ¼Êõ¡£


https://exploits.forsale/24h2-nt-exploit/


6. ICICIÒøÐÐй¶17000Ãû¿Í»§µÄÐÅÓÿ¨Êý¾Ý


4ÔÂ28ÈÕ £¬ICICI ÒøÐÐÊÇÓ¡¶ÈÁìÏȵÄ˽ÈËÒøÐÐÖ®Ò» £¬ÒâÍâµØ½«ÊýǧÕÅÐÂÐÅÓÿ¨µÄÊý¾Ý̻¶¸ø·ÇÔ¤ÆÚ½ÓÊÕÕߵĿͻ§¡£ICICI ÒøÐÐÓÐÏÞ¹«Ë¾ÊÇÒ»¼ÒÓ¡¶È¿ç¹úÒøÐкͽðÈÚ·þÎñ¹«Ë¾ £¬×ܲ¿Î»ÓÚÃÏÂò¡£ËüΪÆóÒµºÍÁãÊÛ¿Í»§Ìṩ¹ã·ºµÄÒøÐкͽðÈÚ·þÎñ¡£¸ÃÒøÐÐÔÚÓ¡¶È¸÷µØÓµÓÐ 6000 ¼Ò·ÖÐÐºÍ 17000 ̨ ATM »ú £¬ÒµÎñ±é¼° 17 ¸ö¹ú¼Ò¡£ÓÉÓÚÆäÒƶ¯ÒøÐÐÓ¦Ó÷¨Ê½¡°iMobile¡±Öеļ¼Êõ´íÎó £¬¸ÃÒøÐж³½áÁË 17,000 ÕÅÐÅÓÿ¨¡£¸Ã¹ÊÕϵ¼ÖÂÓû§¿É»ñÈ¡ÆäËû¿Í»§µÄÏêϸÐÅÏ¢¡£Ì»Â¶µÄ²ÆÕþÐÅÏ¢°üÂÞÐÅÓÿ¨ºÅ¡¢ÓÐЧÆںͿ¨ÑéÖ¤Öµ (CVV)¡£ÔÚһЩ¿Í»§ÔÚÉ罻ýÌåÉϳÂË߸ÃÎÊÌâºó £¬¸ÃÒøÐÐÒâʶµ½ÁËÕâÒ»ÎÊÌâ¡£¸ÃÒøÐÐÌåÏÖ £¬¸ÃʼþÓ°ÏìÁ˸ÃÒøÐÐÔ¼ 0.1% µÄÐÅÓÿ¨¡£ICICI ÒøÐÐÕýÔÚÏòÊÜÓ°ÏìµÄ¿Í»§¿¯ÐÐеÄÐÅÓÿ¨¡£2023 Äê 4 Ô £¬Cybernews µÄÑо¿ÈËÔ±³ÂËß³Æ £¬ICICI ÒøÐÐй¶ÁËÊý°ÙÍòÌõ°üÂÞÃô¸ÐÊý¾ÝµÄ¼Ç¼ £¬°üÂÞ¸ÃÒøÐпͻ§µÄ²ÆÕþÐÅÏ¢ºÍ¸öÈËÎļþ¡£


https://securityaffairs.com/162479/security/icici-bank-technical-glitch.html