Microsoft Windows DWM ÁãÈÕ©¶´±»´ó¹æÄ£ÀûÓÃ

Ðû²¼Ê±¼ä 2024-05-16
1. Microsoft Windows DWM ÁãÈÕ©¶´±»´ó¹æÄ£ÀûÓÃ


5ÔÂ15ÈÕ £¬Î¢ÈíÐû²¼ÎåÔ²¹¶¡¸üР£¬×ܹ² 59 ¸ö CVE  £¬ÖÁÉÙÓÐÒ»¸öÖÚËùÖÜÖªµÄ©¶´Òѱ»´ó¹æÄ£ÀûÓà £¬¶øÇÒȷʵÒѾ­±» QakBot ËùʹÓᣱ¾ÔÂÅû¶µÄȱÏÝÓ°ÏìÁ˼ÆËã kahuna µÄÕû¸ö²úÎï×éºÏ £¬°üÂÞ Windows¡¢Office¡¢.NET Framework ºÍ Visual Studio £»Î¢Èí365 £»µçÁ¦ÉÌÒµÖÇÄÜ £»DHCP ·þÎñÆ÷ £»Microsoft Edge£¨»ùÓÚ Chromium£© £»ºÍ Windows Òƶ¯¿í´ø¡ £»ùÓÚ Chromium µÄ Edge ä¯ÀÀÆ÷Êܵ½ CVE-2024-4761 µÄÓ°Ïì £¬ÕâÊÇ Google ½ñÌìÐÞ²¹µÄÒ»¸öÖ÷¶¯ÀûÓÃµÄ Chrome ÁãÈÕ©¶´ £¬ÕâÊÇÒ»¸öÑÏÖصÄɳÏäÌÓÒÝ´íÎó £¬Ó¦Á¢¼´ÐÞ²¹¡£


https://www.darkreading.com/vulnerabilities-threats/microsoft-windows-dwm-zero-day-mass-exploit


2. Î÷ÃÅ×Ó Ruggedcom Crossbow Öжà¸öÈÎÒâ´úÂëÖ´ÐЩ¶´


5ÔÂ14ÈÕ £¬Î÷ÃÅ×Ó Ruggedcom Crossbow Öз¢ÏÖÁ˶à¸ö©¶´ £¬ÆäÖÐ×îÑÏÖصÄ©¶´¿ÉÄÜÔÊÐíÈÎÒâ´úÂëÖ´ÐС£Î÷ÃÅ×Ó Ruggedcom Crossbow ·ÃÎʹÜÀí½â¾ö·½°¸Ö¼ÔÚΪ¹¤Òµ¿ØÖÆϵͳÌṩÍøÂçÄþ¾²ºÏ¹æÐÔ¡£ÀÖ³ÉÀûÓÃÆäÖÐ×îÑÏÖصÄ©¶´¿ÉÄÜ»áÔÊÐíÔڵǼÓû§µÄÉÏÏÂÎÄÖÐÖ´ÐÐÈÎÒâ´úÂ롣ƾ¾ÝÓëÓû§¹ØÁªµÄȨÏÞ £¬¹¥»÷Õß¿ÉÒÔ°²×°·¨Ê½ £»¼ì²ì¡¢¸ü¸Ä»òɾ³ýÊý¾Ý £»»ò´´½¨¾ßÓÐÍêÈ«Óû§È¨ÏÞµÄÐÂÕÊ»§¡£Óë¾ßÓйÜÀíÓû§È¨ÏÞµÄÓû§Ïà±È £¬ÆäÕÊ»§ÅäÖÃΪÔÚϵͳÉÏÓµÓнÏÉÙÓû§È¨ÏÞµÄÓû§Êܵ½µÄÓ°Ïì¿ÉÄܸüС¡£ÊÜÓ°ÏìµÄϵͳ°üÂÞRuggedcom Crossbow 5.5 ֮ǰµÄ°æ±¾¡£


https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-siemens-ruggedcom-crossbow-could-allow-for-arbitrary-code-execution_2024-055


3. ·ðÃÉÌØÖÝͨ¹ýÊý¾ÝÒþ˽·¨ÔÊÐíÏû·ÑÕßÆðËß¹«Ë¾


5ÔÂ14ÈÕ £¬·ðÃÉÌØÖÝÁ¢·¨»ú¹¹ÖÜÎåͨ¹ýÁ˸ùú×îÇ¿´óµÄ×ÛºÏÊý¾ÝÒþ˽·¨Ö®Ò» £¬ÆäÖÐÔÊÐí¸öÈËÆðËßÇÖ·¸ÆäÒþ˽ȨµÄ¹«Ë¾¡ª¡ªÕâÊÇÏÖÓÐÀàËÆÖÝÖ´·¨ÖÐÇ°ËùδÓеĹ涨¡£¸Ã·¨°¸°üÂÞÊý¾Ý×îС»¯ÒªÇó £¬Õ⼫´óµØÏÞÖÆÁ˹«Ë¾¿ÉÒÔÊÕ¼¯ºÍʹÓõĸöÈËÊý¾Ý £¬²¢½ûÖ¹¹«Ë¾³öÊÛÏû·ÑÕßµÄÃô¸ÐÊý¾Ý £¬ÔÊÐí¸öÈËÔÚÈÏΪÆóÒµÕâÑù×öʱÌáÆðËßËÏ¡£Ë½ÈËËßËÏȨÔÊÐí¸öÈËÒªÇóËûÃÇÈÏΪÇÖ·¸ÆäȨÀûµÄ¹«Ë¾¸ºµ£ÔðÈÎ £¬¶øÎÞÐèÒÀÀµ¹ú¼ÒÕþ¸®½ÓÄÉÐж¯¡£ÒÁÀûŵÒÁÖÝÉúÎïʶ±ðÒþ˽·¨ÖаüÂÞµÄÀàËÆÌõ¿îÒý·¢ÁËÒ»²¨Ö¸¿ØÆóÒµäÂÖ°µÄ¼¯ÌåËßËÏ¡£·ðÃÉÌØÖÝ·¨°¸µÄ˽ÈËËßËÏȨÐèÒªÔÚÁ½ÄêºóÖØÐÂÊÚȨ £¬²¢ÊÊÓÃÓÚ´¦ÖÃÁè¼Ý 100,000 ÌõÏû·ÑÕ߼ǼµÄÈκÎÆóÒµ»ò¸öÈË¡£¸ÃÁ¢·¨»¹Öƶ¨ÁËÑϸñµÄ¹«ÃñȨÀû±£ÕÏ´ëÊ©ÒÔ·ÀÖ¹ÆçÊÓ¡£¼ÓÖÝÇ¿´óµÄ×ÛºÏÊý¾ÝÒþ˽·¨»¹ÔÊÐí¸öÈËÆðËßËûÃÇÈÏΪÇÖ·¸ÆäȨÀûµÄÆóÒµ £¬µ«¸ÃÌõ¿î½öÊÊÓÃÓÚÊý¾Ýй¶ £¬²»ÊÊÓÃÓÚÊý×ÖÒþ˽¡£


https://therecord.media/vermont-passes-data-privacy-law?&web_view=true


4. Android ¶ñÒâÈí¼þð³ä WhatsApp µÈAPPÇÔÈ¡Êý¾Ý


5ÔÂ15ÈÕ £¬SonicWall Capture Labs ÍþвÑо¿ÍŶӳÂËß³Æ £¬ÍþвÐÐΪÕßÕýÔÚʹÓöñÒâ Android Ó¦Ó÷¨Ê½À´Ã°³ä Google¡¢Instagram¡¢Snapchat¡¢WhatsApp ºÍ X µÈÁ÷ÐеÄÔÚÏß·þÎñ¡£ÕâЩӦÓ÷¨Ê½Ö¼ÔÚ´ÓÒ×Êܹ¥»÷µÄ Android ÊÖ»úÖÐÇÔÈ¡Ãô¸ÐÊý¾Ý £¬°üÂÞÁªÏµÈË¡¢¶ÌÐÅ¡¢Í¨»°¼Ç¼ºÍÃÜÂë¡£ÕâЩӦÓ÷¨Ê½¿´ÆðÀ´ºÏ·¨ £¬ÒòΪËüÃÇʹÓÃÊìϤµÄ»Õ±êºÍÃû³ÆÀ´ÆÛÆ­ºÁÎÞ½äÐĵÄÓû§²¢Òþ²ØÔÚÖÚÄ¿î¥î¥Ö®Ï¡£´ò¿ªÊ± £¬Ó¦Ó÷¨Ê½ÇëÇó·ÃÎÊÁ½¸öȨÏÞ£ºAndroid Accessibility Service ºÍÉ豸¹ÜÀíȨÏÞ¡£Èç¹ûÊܺ¦ÕßÊÚÓèÕâЩȨÏÞ £¬Ó¦Ó÷¨Ê½¾Í¿ÉÒÔ»ñµÃÉ豸µÄÍêÈ«¿ØÖÆȨ¡£È»ºó £¬¶ñÒâÓ¦Ó÷¨Ê½ÓëºÚ¿Í¿ØÖÆµÄ C2 ·þÎñÆ÷½¨Á¢Á¬½Ó £¬½ÓÊÕ¸½¼ÓÖ¸Áî¡£Ëü¿ÉÒÔ¶ÁÈ¡ÏûÏ¢¡¢Í¨»°¼Ç¼¡¢·ÃÎÊ֪ͨÊý¾Ý¡¢·¢ËÍÏûÏ¢¡¢°²×°¶ñÒâÈí¼þÒÔ¼°´ò¿ª¶ñÒâÍøÕ¾ÒÔ½øÐÐÍøÂçµöÓã¡£


https://www.hackread.com/android-malware-whatsapp-instagram-snapchat-data/


5. Ebury½©Ê¬ÍøÂç¶ñÒâÈí¼þÒÑѬȾ40Íǫ̀Linux·þÎñÆ÷


5ÔÂ14ÈÕ £¬Ò»¸öÃûΪ¡°Ebury¡±µÄ¶ñÒâÈí¼þ½©Ê¬ÍøÂçÒÑѬȾÁ˽ü 400,000 ̨ Linux ·þÎñÆ÷ £¬½ØÖÁ 2023 Äêµ× £¬Ô¼ÓÐ 100,000 ̨·þÎñÆ÷ÈÔÊܵ½Íþв¡£ESET Ñо¿ÈËԱʮ¶àÄêÀ´Ò»Ö±ÔÚ¸ú×ÙÕâÖÖ³öÓÚ¾­¼Ã¶¯»úµÄ¶ñÒâÈí¼þ²Ù×÷ £¬²¢ÔÚ 2014 ÄêºÍ 2017 ÄêÔٴξ¯¸æÓÐЧ¸ºÔع¦Ð§µÄÖØ´ó¸üС£ESET ×Ô 2009 ÄêÒÔÀ´Ò»Ö±¹Ø×¢µÄ Ebury ѬȾÇé¿ö £¬ÏÔʾѬȾÁ¿Ëæ×Åʱ¼äµÄÍÆÒƶøÔö³¤¡£×î½üµÄ Ebury ¹¥»÷±íÃ÷ £¬¹¥»÷ÍÅ»ïÇãÏòÓÚÆÆ»µÍйÜÌṩÉÌ £¬²¢¶ÔÔÚÊÜѬȾÌṩÉÌÉÏ×âÓÃÐéÄâ·þÎñÆ÷µÄ¿Í»§½øÐй©Ó¦Á´¹¥»÷¡£×î³õµÄΣº¦ÊÇͨ¹ýƾ֤Ìî³ä¹¥»÷½øÐеÄ £¬Ê¹ÓÃÇÔÈ¡µÄƾ֤µÇ¼·þÎñÆ÷¡£Ò»µ©·þÎñÆ÷Êܵ½Íþв £¬¶ñÒâÈí¼þ¾Í»á´Ówtmp ºÍ known_hosts ÎļþÖÐÇÔÈ¡ÈëÕ¾/´øÍâ SSH Á¬½ÓÁбí £¬²¢ÇÔÈ¡ SSH Éí·ÝÑéÖ¤ÃÜÔ¿ £¬È»ºóʹÓÃÕâЩÃÜԿʵÑéµÇ¼ÆäËûϵͳ¡£ 


https://www.bleepingcomputer.com/news/security/ebury-botnet-malware-infected-400-000-linux-servers-since-2009/


6. ºÚ¿ÍÀÄÓà GoTo »áÒ鹤¾ß²¿Êð Remcos RAT


5ÔÂ14ÈÕ £¬ÔÚÒ»´ÎÅÓ´óµÄÍøÂç¹¥»÷»î¶¯Öз¢ÏÖºÚ¿ÍÀûÓÃÔÚÏß»áÒéƽ̨ GoToMeeting Á÷´«ÃûΪ Remcos µÄÔ¶³Ì·ÃÎÊľÂí¡£ÕâÒ»ÁîÈËÕ𾪵ÄÉú³¤Í»ÏÔÁËÍøÂç·¸×ï·Ö×ÓÀûÓÿÉÐÅÈí¼þÍ»ÆÆÄþ¾²·ÀÓù²¢Î´¾­ÊÚȨ·ÃÎÊÊܺ¦ÕßϵͳµÄ²»Í£ÑݱäµÄ¼Æı¡£¹¥»÷»úÖÆÉæ¼°ÀûÓà GoToMeeting£¨Ò»ÖÖ±»ÆóÒµ¹ã·ºÓÃÓÚÐéÄâ»áÒéµÄ¹¤¾ß£©×÷Ϊ Remcos RAT µÄÇþµÀ¡£Remcos ÊÇÒ»ÖÖÇ¿´óµÄ¶ñÒâÈí¼þ £¬¹¥»÷Õß¿ÉÒÔÀûÓÃËüÔ¶³Ì¿ØÖÆÊÜѬȾµÄ¼ÆËã»ú¡¢ÇÔÈ¡Ãô¸ÐÐÅÏ¢ £¬ÉõÖÁ²¿ÊðÆäËû¶ñÒ⸺ÔØ¡£¹¥»÷ÕßÇÉÃîµØÔÚ¿´ËƺϷ¨µÄ GoToMeeting ֪ͨÖÐαװÁË Remcos ÓÐЧ¸ºÔØ¡£ºÁÎÞ½äÐĵÄÓû§ÏàÐÅÕâЩ֪ͨÊÇÕæʵµÄ £¬Òò´Ë±»ÓÕÆ­ÔÚËûÃǵÄϵͳÉÏÖ´ÐжñÒâÈí¼þ¡£Ò»µ©°²×° £¬Remcos ¾Í»áÊÚÓè¹¥»÷Õ߶ÔÊÜѬȾ¼ÆËã»úµÄÍêÈ«¿ØÖÆȨ £¬Ê¹ËûÃÇÄܹ»ÔÚ²»±»·¢ÏÖµÄÇé¿öϽøÐмäµý»î¶¯¡¢Êý¾Ý͵ÇԺͽøÒ»²½µÄ¶ñÒâ»î¶¯¡£Remcos µÄÒþÃØÐÔºÍÅÓ´óÐÔ £¬¼ÓÉÏ¶Ô GoToMeeting µÄ¹ã·ºÐÅÈÎ £¬Ê¹µÃÕâÖÖ¹¥»÷ÌرðÒõÏÕÇÒÄÑÒÔÓ¦¶Ô¡£


https://gbhackers.com/hackers-abuse-goto-meeting-tool/