Ó¢¹ú¾üÊÂÊý¾Ýй¶ÌáÐѹú·À²¿ÃÅ´æÔÚµÚÈý·½·çÏÕ

Ðû²¼Ê±¼ä 2024-05-10
1. Ó¢¹ú¾üÊÂÊý¾Ýй¶ÌáÐѹú·À²¿ÃÅ´æÔÚµÚÈý·½·çÏÕ


5ÔÂ9ÈÕ£¬´Ë´Îй¶Ê¼þ̻¶ÁËÁè¼Ý 225,000 ÃûÓ¢¹ú¾üÊÂÈËÔ±µÄÊý¾Ý£¬Í¹ÏÔÁËÓë¹ú·ÀʵÌåÍⲿ³Ð°üÉÌÏà¹ØµÄÈ«ÇòÄþ¾²·çÏÕ¡£´Ë´ÎÆعâÓÚ±¾ÖÜÆع⣬ԴÓÚÒ»ÃûÍþвÐÐΪÕß´ÓÒ»¼Ò¹«Ë¾»ñÈ¡ÁËÓ¢¹ú½¾ü¡¢º£¾üºÍ»Ê¼Ò¿Õ¾üÏÖÈΡ¢Ç°ÈκÍÔ¤±¸ÒÛ³ÉÔ±µÄÐÕÃû¡¢ÒøÐÐÕË»§ÏêϸÐÅÏ¢ºÍÆäËûÐÅϢΪӢ¹ú¹ú·À²¿ (MoD) ´¦ÖÃн×Ê·þÎñ¡£BBCºÍÆäËûÓ¢¹úýÌåÈ·ÈÏÍⲿ³Ð°üÉÌΪ Shared Services Connected Ltd£¬²¢ÌåÏÖ±»ÈëÇÖµÄн×Êϵͳ°üÂÞ¶àÄêÇ°µÄ¾üÊÂÈËÔ±ÐÅÏ¢¡£Ó¢¹ú¹ú·À´ó³¼¸ñÀ¼ÌØ¡¤É³ÆÕ˹ÔÚÏòÒé»áÒéÔ±·¢±íµÄÆÀÂÛÖÐÖ¸³ö£¬Õâ´ÎÏ®»÷ÊÇ¡°¶ñÒâÐÐΪÕß¡±ËùΪ£¬ºÜ¿ÉÄܵõ½ÁËÃñ×å¹ú¼ÒµÄÖ§³Ö¡£¾¡¹ÜһЩ¸ß¼¶Õþ¸®¹ÙÔ±Ö¸³öÖйúÊÇ×îÓпÉÄܵÄÏÓÒÉÈË£¬µ«É³ÆÕ˹±¾È˲¢Ã»Óн«Õâ´ÎÏ®»÷¹é¾ÌÓÚÈκÎÈ˵ÄÃû×Ö¡£´ËÀàÎ¥¹æÐÐΪ͹ÏÔÁËÍⲿ³Ð°üÉÌÏòÏëÒªÕë¶Ô¾üʺ͹ú·ÀÊý¾ÝºÍϵͳµÄ¹¥»÷ÕßÌá³öµÄ´àÈõÈõµã¡£


https://www.darkreading.com/cyberattacks-data-breaches/breach-of-uk-military-personnel-data-a-reminder-of-third-party-risk-in-defense-sector


2. LOCKBIT ÍÅ»ïÉù³Æ¶ÔÍþÆæÍÐÊÐÏ®»÷ʼþÂôÁ¦


5ÔÂ8ÈÕ£¬LockBit ÀÕË÷Èí¼þ×éÖ¯Òѽ«ÍþÆæÍÐÊÐÌí¼Óµ½Æä Tor й¶վµã£¬²¢ÍþвҪÐû²¼±»µÁÊý¾Ý¡£ÍþÆæÍÐÊÇÃÀ¹ú¿°Èø˹ÖÝÈË¿Ú×î¶àµÄ¶¼ÊУ¬Ò²ÊÇÈûÆæÍþ¿ËÏصÄÏسÇ¡£½ØÖÁ2020ÄêÈË¿ÚÆղ飬¸ÃÊÐÈË¿ÚΪ397,532ÈË¡£Äþ¾²Â©¶´·¢ÉúÓÚ 2024 Äê 5 Ô 5 ÈÕ£¬ÊÐÕþ¸®Á¢¼´Æô¶¯Ê¼þÏìÓ¦·¨Ê½£¬ÒÔ·ÀÖ¹ÍþвÂûÑÓ¡£¸ÃÊÐÕýÔÚµÚÈý·½Äþ¾²×¨¼ÒÒÔ¼°Áª°îºÍµØ·½Ö´·¨»ú¹¹µÄ×ÊÖúÏÂÊӲ첢ֹͣÕâһʼþ¡£¡°³öÓÚ²Ù×÷Äþ¾²µÄÄ¿µÄ£¬Õâ¸ö[Éù³Æ¶Ô´Ë´Î¹¥»÷ÂôÁ¦µÄ×éÖ¯µÄÃû³Æ²»»á±»¹²Ïí¡£¡±³ÂËßÖ¸³ö¡£È»¶ø£¬LockBit ÀÕË÷Èí¼þÍÅ»ïÉù³Æ¶ÔÍþÆæÍÐÊеÄÍøÂç¹¥»÷ÂôÁ¦¡£Ö§¸¶Êê½ðµÄ½ØÖ¹ÈÕÆÚÊÇ 2024 Äê 5 Ô 15 ÈÕ¡£


https://securityaffairs.com/162910/cyber-crime/city-of-wichita-lockbit-ransomware.html


3. ´ÓÀ¬»øÓʼþµ½ AsyncRAT£¬¸ú×Ù·ÇPEÍøÂçÍþвµÄ¼¤Ôö


5ÔÂ8ÈÕ£¬AsyncRAT£¬Ò²³ÆΪ¡°Òì²½Ô¶³Ì·ÃÎÊľÂí¡±£¬ÊÇÒ»Öָ߶ÈÅÓ´óµÄ¶ñÒâÈí¼þ±äÌ壬¾­¹ý¾«ÐÄÉè¼Æ£¬Ö¼ÔÚÆÆ»µ¼ÆËã»úϵͳÄþ¾²²¢ÇÔÈ¡»úÃÜÊý¾Ý¡£Âõ¿Ë·ÆʵÑéÊÒ×î½ü·¢ÏÖÁËÒ»ÖÖÐÂÐÍѬȾÁ´£¬½ÒʾÁËÆäÇ¿´óµÄɱÉËÁ¦¼°Æä½ÓÄɵÄÖÖÖÖÄþ¾²ÅÔ·»úÖÆ¡£ËüÀûÓöàÖÖÎļþÀàÐÍ£¬ÀýÈç PowerShell¡¢Windows ½Å±¾Îļþ (WSF)¡¢VBScript (VBS) ÒÔ¼°¶ñÒâ HTML ÎļþÖеÄÆäËûÎļþÀàÐÍ¡£ÕâÖֶ෽ÃæµÄÒªÁìÖ¼ÔÚ¹æ±Ü·À²¡¶¾¼ì²âÒªÁì²¢´Ù½øѬȾµÄÁ÷´«¡£Ñ¬È¾ÊÇͨ¹ý°üÂÞ HTML Ò³Ã渽¼þµÄÀ¬»øÓʼþÆô¶¯µÄ¡£ÔÚÎÞÒâÖдò¿ª HTML Ò³Ãæʱ£¬»á×Ô¶¯ÏÂÔØ Windows ½Å±¾Îļþ (WSF)¡£¸Ã WSF ÎļþµÄÃüÃû·½Ê½¹ÊÒâÌåÏÖ¶©µ¥ ID£¬´Ó¶øÓªÔìºÏ·¨ÐԵļÙÏó²¢ÓÕʹÓû§Ö´ÐÐËü¡£Ö´ÐÐ WSF Îļþºó£¬Ñ¬È¾»á×Ô¶¯½øÐУ¬ÎÞÐè½øÒ»²½µÄÓû§¸ÉÔ¤¡£Ñ¬È¾Á´µÄºóÐø½×¶Î°üÂÞ Visual Basic ½Å±¾ (VBS)¡¢JavaScript (JS)¡¢Åú´¦Öà (BAT)¡¢Îı¾ (TXT) ºÍ PowerShell (PS1) ÎļþµÄ²¿Êð¡£×îÖÕ£¬¸ÃÁ´×îÖÕµ¼ÖÂÕë¶Ô aspnet_compiler.exe µÄ½ø³Ì×¢Èë¡£


https://www.mcafee.com/blogs/other-blogs/mcafee-labs/from-spam-to-asyncrat-tracking-the-surge-in-non-pe-cyber-threats/


4. еÄÓÄÁéʽ̽·Õß¹¥»÷Õë¶ÔÓ¢Ìضû CPU


5ÔÂ8ÈÕ£¬Ñо¿ÈËÔ±·¢ÏÖÁËÁ½ÖÖÕë¶Ô¸ßÐÔÄÜÓ¢Ìضû CPU µÄÐÂÓ±¹¥»÷ÒªÁ죬¿ÉÀûÓÃÕâЩҪÁì¶Ô¸ß¼¶¼ÓÃÜ³ß¶È (AES) Ëã·¨ÌᳫÃÜÔ¿»Ö¸´¹¥»÷¡£ÕâЩ¼¼Êõ±»À´×Ô¼ÓÖÝ´óѧʥµØÑǸç·ÖУ¡¢Æնɴóѧ¡¢±±¿¨ÂÞÀ´ÄÉ´óѧ½ÌÌÃɽ·ÖУ¡¢×ôÖÎÑÇÀí¹¤Ñ§ÔººÍ¹È¸èµÄÒ»×éѧÕßͳ³ÆΪ̽·Õß¡£Spectre ÊÇÒ»Àà²àͨµÀ¹¥»÷µÄÃû³Æ£¬ÕâЩ¹¥»÷ÀûÓÃÏÖ´ú CPU ÉϵķÖÖ§Ô¤²âºÍÍƲâÖ´ÐÐÀ´¶ÁÈ¡ÄÚ´æÖеÄÌØȨÊý¾Ý£¬´Ó¶øÈƹýÓ¦Ó÷¨Ê½Ö®¼äµÄ¸ôÀë±£»¤¡£×îÐµĹ¥»÷ÒªÁìÕë¶ÔµÄÊÇ·ÖÖ§Ô¤²âÆ÷ÖгÆΪ·¾¶ÀúÊ·¼Ä´æÆ÷ ( PHR ) µÄ¹¦Ð§£¨¸Ã¹¦Ð§±£Áô×îºó½ÓÄɵķÖÖ§µÄ¼Ç¼£©£¬ÒÔÓÕ·¢·ÖÖ§´íÎóÔ¤²â²¢µ¼ÖÂÊܺ¦Õß·¨Ê½Ö´ÐзÇÔ¤ÆڵĴúÂë·¾¶£¬´Ó¶øÎÞÒâÖÐ̻¶Æä»úÃÜÊý¾Ý¡£¾ßÌåÀ´Ëµ£¬ËüÒýÈëÁËеÄÔ­Ó¿ÉÒÔÀûÓà PHR ÒÔ¼°Ìõ¼þ·ÖÖ§Ô¤²âÆ÷ (CBR) ÄÚµÄÔ¤²âÀúÊ·±í (PHT)£¬ÒÔй©ÀúÊ·Ö´ÐÐÊý¾Ý²¢×îÖÕ´¥·¢ Spectre ʽ©¶´¡£ÔÚÑо¿ÖиÅÊöµÄÒ»×éÑÝʾÖУ¬ÎÒÃÇ·¢ÏÖ¸ÃÒªÁì¿ÉÒÔÓÐЧµØÌáÈ¡ÃØÃÜ AES ¼ÓÃÜÃÜÔ¿ÒÔ¼°Ôڹ㷺ʹÓÃµÄ libjpeg ͼÏñ¿â´¦Öùý³ÌÖÐй¶ÃØÃÜͼÏñ¡£


https://thehackernews.com/2024/05/new-spectre-style-pathfinder-attack.html


5. ¡¶×îÖÕ»ÃÏë¡·ÓÎÏ··þÎñÆ÷ÔâÊܶà´Î DDoS ¹¥»÷


5ÔÂ8ÈÕ£¬ÓÉÓÚһϵÁÐÁ¬ÐøµÄ DDoS ¹¥»÷£¬´óÁ¿À¬»øÁ÷Á¿ÑÍûÁËÈÈÃÅÊÓƵÓÎϷϵÁС¶×îÖÕ»ÃÏë¡·µÄ·þÎñÆ÷£¬±¾ÖÜÍæ¼ÒµÇ¼ʱÓöµ½ÁËÎÊÌâ¡£¡¶×îÖÕ»ÃÏë 14¡·µÄÊ״ι¥»÷´ÓÖÜÒ»¿ªÊ¼£¬Á¬ÐøÁËÁè¼Ý 24 Сʱ£¬Ó°ÏìÁËÊÀ½ç¸÷µØµÄÍæ¼Ò¡£Æäʱ£¬¸ÃÓÎÏ·µÄ¿¯ÐÐÉÌ¡¢ÈÕ±¾Ê·¿ËÍþ¶û°¬Äá¿Ë˹¹«Ë¾ÌåÏÖ£¬ÕýÔÚ¡°ÊÓ²ì´Ë´Î¹¥»÷²¢½ÓÄɶԲߡ±¡£È»¶ø£¬ÖܶþµÄ¹¥»÷Ôٴη¢Éú£¬ÖÜÈýÈÔÔÚÁ¬Ðø£¬µ¼ÖÂÍæ¼ÒµÇ¼À§ÄÑ£¬²¿ÃÅÅ·ÖÞ¡¢±±ÃÀºÍ´óÑóÖÞµÄÊý¾ÝÖÐÐÄÎÞ·¨·ÃÎÊ¡£Square Enix ÉÐ佫´Ë´Î¹¥»÷¹é¾ÌÓÚÈκκڿÍ×éÖ¯¡£¸Ã¹«Ë¾ÌåÏÖ£º¡°Ëæ×ÅÇé¿öµÄÉú³¤£¬½«Ìṩ¸ü¶àÐÅÏ¢¡£¡±µ±ÓÎÏ··þÎñÆ÷·ºÆðÁ¬½ÓÎÊÌâ»ò×ÌÈÅʱ£¬Í¨³£»á·ºÆð90002 ´íÎó¡£


https://therecord.media/final-fantasy-game-ddos-incident-square-enix


6. ºÚ¿ÍÀÄÓÃGoogleËÑË÷¹ã¸æÁ÷´«MSI´ò°üµÄ¶ñÒâÈí¼þ


5ÔÂ8ÈÕ£¬ÈËÃÇ·¢ÏÖºÚ¿ÍÀûÓÃGoogle ËÑË÷¹ã¸æͨ¹ý MSI£¨Î¢Èí°²×°·¨Ê½£©°üÁ÷´«¶ñÒâÈí¼þ¡£¸Ã»î¶¯Éæ¼°ÃûΪ FakeBat µÄ¶ñÒâÈí¼þ¼ÓÔØ·¨Ê½£¬Í¨¹ýαװ³ÉºÏ·¨Èí¼þÏÂÔØÀ´Ãé×¼ºÁÎÞ½äÐĵÄÓû§¡£¹¥»÷´Ó¿´ËƺϷ¨µÄ¹È¸èËÑË÷¹ã¸æ¿ªÊ¼£¬Ê¹ÓÃÁË Notion µÈÁ÷ÐÐÈí¼þµÄÕæʵÍøÕ¾µØÖ·¡£È»¶ø£¬ÕâÔò¹ã¸æÖ»ÊÇÒ»¸ö»Ï×Ó£¬ÊÇÓÉһֱʹÓÃÓë¹þÈø¿Ë˹̹Ïà¹ØµÄÉí·ÝµÄÍþвÐÐΪÕß¹ºÖõÄ¡£¾ÝThreatDown±¨µÀ£¬ºÚ¿ÍÕýÔÚʹÓà Google ËÑË÷¹ã¸æÀ´Á÷´«´øÓÐ MSI µÄ¶ñÒâÈí¼þ¡£µã»÷¹ã¸æ»á½øÈëÒ»¸öÒÔÆÛÆ­ÐÔ URL ÍйܵÄÍøÂçµöÓãÍøÕ¾£¬ÓëÕæʵÍøÕ¾ÀàËÆ¡£¸ÃÍøÕ¾ÌáʾÓû§ÏÂÔØMSIX ¸ñʽµÄ³ß¶ÈÈí¼þ°²×°·¨Ê½£¬²¢ÒÔ¿´ËÆ¿ÉÐŵÄÃû³Æ¡°Forth View Designs Ltd¡±Ç©Ãû¡£¸Ã»î¶¯ÀûÓõã»÷¸ú×Ù·þÎñÀ´¹ÜÀí¹ã¸æµÄÓÐЧÐÔ²¢¹ýÂ˵ô²»ÐèÒªµÄÁ÷Á¿¡£


https://gbhackers.com/abuse-google-search-ads/#google_vignette