¶íÀÕ¸ÔÖݶ¯ÎïÔ°ÊÛƱ·þÎñÔâºÚ¿Í¹¥»÷£¬11.8ÍòÓû§ÐÅÏ¢±»µÁ
Ðû²¼Ê±¼ä 2024-08-218ÔÂ19ÈÕ£¬¶íÀÕ¸ÔÖݶ¯ÎïÔ°½üÆÚ·¢ÉúÁËÒ»ÆðÑÏÖصÄÊý¾Ýй¶Ê¼þ£¬Ô¼118,000ÃûÓû§µÄ¸öÈËÐÅÏ¢ºÍÖ§¸¶¿¨Êý¾ÝÔÚ2023Äê12ÔÂ20ÈÕÖÁ2024Äê6ÔÂ26ÈÕÆÚ¼äµÄÔÚÏßÊÛƱ·þÎñÖб»µÁ¡£ÕâЩÐÅÏ¢°üÂÞÐÕÃû¡¢Ö§¸¶¿¨ºÅ¡¢CVVÄþ¾²Âë¼°µ½ÆÚÈÕÆÚ£¬¶ÔÊܺ¦Õß×é³ÉDZÔÚ·çÏÕ¡£Ê¼þÓÚ6ÔÂ26ÈÕ±»·¢Ïֺ󣬶¯ÎïÔ°Á¢¼´Í£ÓÃÁËÊÜÓ°ÏìµÄÍøÕ¾£¬²¢½¨Á¢ÁËеÄÄþ¾²¹ºÆ±Æ½Ì¨¡£¶¯ÎïÔ°ÒÑÏòÃåÒòÖÝ×ܼì²ì³¤°ì¹«ÊÒ³ÂËߣ¬²¢Ïò¿ÉÄÜÊÜÓ°ÏìµÄ117,815ÃûÓû§·¢ËÍÁË֪ͨÐÅ£¬Í¬Ê±ÎªËûÃÇÌṩÁËÒ»ÄêµÄÃâ·ÑÐÅÓüà¿ØºÍÉí·Ý±£»¤·þÎñ¡£¶¯ÎïÔ°ÌåÏÖ£¬´Ë´Îй¶ÊÇÓÉÓÚµÚÈý·½¹©Ó¦É̽»Ò×±»ÍþвÕßÖض¨ÏòËùÖ£¬²¢ÒÑÏòÁª°îÖ´·¨²¿ÃÅͨ±¨¡£ÎªÔ¤·ÀδÀ´ÀàËÆʼþ£¬¶¯ÎïÔ°Õý»ý¼«Éó²éÆäÄþ¾²Õþ²ßºÍ·¨Ê½¡£¾¡¹Üδ¹ûÈ»¾ßÌå¹¥»÷ÀàÐÍ£¬µ«·ÖÎöÈÏΪ¿ÉÄÜÊÇÍøÂçä¯ÀÀÆ÷ѬȾÁËÊý×ÖÇÔÈ¡Æ÷£¬ÕâÀà¶ñÒâÈí¼þ³£±»ÓÃÓÚÔÚ½áÕËÒ³ÃæµÈÒªº¦Î»ÖÃÇÔÈ¡Óû§Ãô¸ÐÐÅÏ¢¡£
https://www.securityweek.com/oregon-zoo-ticketing-service-hack-impacts-118000/
2. Jewish Home LifecareÔâBlackCatÀÕË÷Èí¼þ¹¥»÷£¬10ÍòÈËÊý¾Ýй¶
8ÔÂ19ÈÕ£¬Å¦Ô¼ÊеķÇÓªÀûÐÔÒ½ÁƱ£½¡×éÖ¯Jewish Home Lifecare£¨ÏÖ³ÆÐÂÓÌÌ«¼ÒÍ¥ÖÐÐÄ£©Åû¶Á˽üÆÚ·¢ÉúµÄÒ»ÆðÖØ´óÊý¾Ýй¶Ê¼þ£¬¸Ãʼþ²¨¼°Áè¼Ý104,000Ãû»¼Õß¼°ÉçÇø³ÉÔ±¡£½ñÄê2Ô£¬¸ÃÖÐÐÄÏòÊÜÓ°Ïì¿Í»§Í¨±¨³Æ£¬ÆäÍøÂçÔÚ1ÔÂ7ÈÕÔâÓöÒì³£»î¶¯£¬ºÚ¿Í¿ÉÄÜÒÑ»ñÈ¡°üÂÞ¸öÈËÉí·ÝÐÅÏ¢¡¢½ðÈÚÕË»§ÏêÇé¡¢Ò½ÁƼǼÔÚÄÚµÄÃô¸ÐÐÅÏ¢¡£ÎªÈ·±£Êܺ¦ÕßÄþ¾²£¬ÖÐÐÄÌṩÁËÃâ·ÑµÄÐÅÓüà¿Ø·þÎñ£¬²¢Ç¿µ÷ËäÎÞÖ±½ÓÖ¤¾Ý±íÃ÷ÐÅÏ¢Òѱ»ÀÄÓ㬵«ÈÔ½÷É÷Ðû²¼Í¨Öª¡£´Ë´Îй¶ÓëÀÕË÷Èí¼þ×éÖ¯BlackCat(Alphv)Óйأ¬ËüÃÇÉù³Æ¹¥»÷ÁËJewish Home Lifecare²¢»ñÈ¡ÁËÁÙ´²Ñо¿¡¢²ÆÕþ¼°Ô±¹¤¿Í»§Êý¾Ý£¬ÉõÖÁÉæ¼°¾èÔù×ʽðÀÄÓõÄÖ¤¾Ý¡£È»¶ø£¬±»µÁÎļþÊÇ·ñ¹ûÈ»ÉдýÈ·ÈÏ£¬ÇÒBlackCat×éÖ¯ÔÚ3Ô³õͻȻÏûʧ£¬ÆäÍøÕ¾ÒÑÎÞ·¨·ÃÎÊ¡£
https://www.securityweek.com/100000-impacted-by-jewish-home-lifecare-data-breach/
3. BlindEagle£¨APT-C-36£©£ºÀ¶¡ÃÀÖÞµÄÁ¬ÐøÍþв
8ÔÂ20ÈÕ£¬¿¨°Í˹»ùʵÑéÊÒ¶ÔÃûΪBlindEagle£¨ÓÖ½ÐAPT-C-36£©µÄÁ¬ÐøÐÔÍþв×éÖ¯·¢³ö¾¯¸æ£¬¸Ã×é֯ר³¤ÓÚÕë¶ÔÀ¶¡ÃÀÖÞµÄÍøÂç¹¥»÷£¬BlindEagleÖ÷Ҫͨ¹ý¾«ÐÄÉè¼ÆµÄÍøÂçµöÓã»îÐж¯°¸£¬¼Ùð¹Ù·½»ú¹¹ÈçË°Îñ²¿ÃÅ»òÍâ½»²¿£¬ÓÕÆÓû§µã»÷¶ñÒâÁ´½Ó£¬ÏÂÔØαװ³É¹Ù·½ÎļþµÄѹËõ°ü£¬ÄÚº¬Ö¸ÏòÊܿضñÒâÈí¼þÕ¾µãµÄÁ´½Ó¡£ÕâЩÓʼþ´«ÉñÄ£Äâ¹Ù·½Í¨Ñ¶£¬ÀûÓÃURLËõ¶ÌÆ÷ºÍ¶¯Ì¬DNS·þÎñÔö¼ÓÒþ±ÎÐÔ£¬Æ¾¾ÝÓû§Î»ÖÃÖض¨Ïò£¬ÒÔÌӱܼì²â¡£Ò»µ©Óû§ÖÐÕУ¬BlindEagle±ãÆô¶¯¶à½×¶ÎѬȾ£¬²¿Êð°üÂÞnjRAT¡¢LimeRATµÈ¹ûȻԶ³Ì·ÃÎÊľÂí£¨RAT£©£¬ÕâЩ¹¤¾ß±»¶¨ÖÆÒÔÂú×ã²îÒì¹¥»÷ÐèÇó£¬ÔÊÐí¸Ã×éÖ¯¼à¿ØÊܺ¦Õß¡¢ÇÔÈ¡Ãô¸ÐÐÅÏ¢¼°²ÆÕþƾ֤¡£BlindEagle»¹ÀûÓýø³Ì×¢Èë¼¼Êõ£¬Èç½ø³ÌÍÚ¿Õ£¬½«¶ñÒâ´úÂëÒþ²ØÓںϷ¨½ø³ÌÖУ¬ÒԴ˹æ±ÜÄþ¾²¼ì²â£¬ÊµÏÖºã¾ÃDZ·üÓëÊý¾ÝÇÔÈ¡¡£BlindEagleµÄ¹¥»÷Ä¿±ê°üÂÞ¸çÂ×±ÈÑÇ¡¢¶ò¹Ï¶à¶û¡¢ÖÇÀûºÍ°ÍÄÃÂíµÄ¸öÈ˺Í×éÖ¯£¬Éæ¼°Õþ¸®¡¢½ÌÓý¡¢ÎÀÉúºÍ½»Í¨µÈ¸÷¸öÁìÓò¡£
https://securityonline.info/blindeagle-apt-group-a-persistent-threat-in-latin-america/
4. ΢о¿Æ¼¼ÔâÓöÍøÂç¹¥»÷£¬²¿ÃÅÒµÎñÊÜÓ°Ïì
8ÔÂ21ÈÕ£¬ÃÀ¹ú°ëµ¼ÌåÖÆÔìÉÌ΢о¿Æ¼¼Microchip½üÆÚÔâÓöÁËÒ»ÆðÍøÂçÄþ¾²Ê¼þ£¬¶Ô¹«Ë¾ÔËÓªÔì³ÉÁËÏÔÖøÓ°Ïì¡£¾Ý¸Ã¹«Ë¾Í¸Â¶£¬8ÔÂ17ÈÕ£¬Î¢Ð¾¿Æ¼¼µÄÐÅÏ¢¼¼Êõϵͳ±»¼ì²âµ½´æÔÚDZÔڵĿÉÒɻ£¬ËæºóÓÚ8ÔÂ19ÈÕÈ·ÈÏϵͳÒÑÔ⵽δ¾ÊÚȨµÄ·ÃÎÊ¡£Ãæ¶ÔÕâÒ»½ô¼±Çé¿ö£¬¹«Ë¾Ñ¸ËÙ½ÓÄÉÐж¯£¬¸ôÀëÁËÊÜÓ°ÏìµÄ·þÎñÆ÷ϵͳ£¬²¢¹Ø±ÕÁË¿ÉÄÜÊܲ¨¼°µÄÆäËûϵͳ£¬Í¬Ê±Æ¸ÇëÁËרҵµÄÍⲿÍøÂçÄþ¾²ÕÕÁÏÍŶÓÀ´È«ÃæÆÀ¹ÀʼþµÄÑÏÖØˮƽ¼°Ó°Ï췶Χ¡£´Ë´ÎÄþ¾²Ê¼þµ¼ÖÂ΢о¿Æ¼¼²¿ÃÅÖÆÔìÉèÊ©µÄÔËӪЧÂʽµÖÁÕý³£Ë®Æ½ÒÔÏ£¬Ö±½ÓÓ°ÏìÁ˹«Ë¾¶¨Ê±ÂÄÐпͻ§¶©µ¥µÄÄÜÁ¦¡£¾¡¹Ü¹«Ë¾ÕýÈ«Á¦ÒÔ¸°½â¾öÕâÒ»ÎÊÌ⣬²¢ÔÊÐí½«¾¡¿ì»Ö¸´Õý³£ÔËÓª£¬µ«Ä¿Ç°¹ØÓÚʼþµÄ¾ßÌåÔÒò¡¢Ð¾Æ¬ÖÆÔìÒµÎñÊÜ×ÌÈŵÄÏêϸˮƽ£¬ÒÔ¼°ÊÇ·ñÉæ¼°ÀÕË÷Èí¼þµÈÃô¸ÐÐÅÏ¢£¬ÈÔ´ý½øÒ»·¨Ê½²éÈ·ÈÏ¡£ÖµµÃ×¢ÒâµÄÊÇ£¬Î¢Ð¾¿Æ¼¼½ÓÄɸôÀë´ëÊ©µÄ×ö·¨±íÃ÷£¬Î´¾ÊÚȨ·½µÄ»î¶¯¿ÉÄÜÒÑ¿ª¶ËÏÔʾ³öÏò¹«Ë¾¸ü¹ã·ºIT×ʲúÀ©É¢µÄ¼£Ïó¡£
https://www.theregister.com/2024/08/21/microchip_technology_security_incident/
5. ½Ý¿ËÒƶ¯Óû§ÔâPWAÍøÂçµöÓã¹¥»÷
8ÔÂ20ÈÕ£¬½Ý¿Ë¹²ºÍ¹úµÄÒƶ¯Óû§ÕýÃæÁÙÒ»ÖÖÐÂÐÍÇÒÅÓ´óµÄÍøÂçµöÓãÍþв£¬¸ÃÍþвÀûÓý¥½øʽWebÓ¦Ó÷¨Ê½£¨PWA£©¼¼Êõ£¬Õë¶Ô¶à¼ÒÒøÐÐÓû§ÇÔÈ¡ÒøÐÐÕË»§Æ¾Ö¤¡£¾Ý˹Âå·¥¿ËÍøÂçÄþ¾²¹«Ë¾ESET³ÂËߣ¬¹¥»÷Ä¿±ê°üÂ޽ݿ˵ÄCSOBÒøÐС¢ÐÙÑÀÀûµÄOTPÒøÐм°¸ñ³¼ªÑǵÄTBCÒøÐС£¹¥»÷Õßͨ¹ý×Ô¶¯ÓïÒôµç»°¡¢¶ÌÐż°É罻ýÌå¶ñÒâ¹ã¸æÉ¢²¼µöÓãÁ´½Ó£¬ÓÕµ¼Óû§µã»÷²¢°²×°¿´ËƺϷ¨µÄÒøÐÐÓ¦Ó÷¨Ê½PWA»òAndroidÉϵÄWebAPK£¬ÕâЩӦÓü¸ºõÍêÃÀ¸´ÖÆÁËÕæʵÒøÐÐÓ¦ÓõĽçÃ棬´Ó¶øÈƹýÁË´«Í³ä¯ÀÀÆ÷µÄÄþ¾²¾¯¸æ¡£ÖµµÃ×¢ÒâµÄÊÇ£¬¹¥»÷±³ºóÉæ¼°Á½¸ö²îÒìµÄÍþвÐÐΪÕߣ¬ËûÃÇÀûÓÃChrome WebAPK¼¼ÊõµÄĬÈÏÐÐΪ£¬ÀÄÓøù¦Ð§ÒÔÒþ²Ø¡°À´×Ô²»ÊÜÐÅÈÎÀ´Ô´µÄ°²×°¡±¾¯¸æ£¬Ê¹µÃÓû§ÄÑÒÔ²ì¾õ·çÏÕ¡£¶ÔÓÚiOSÓû§£¬Ôòͨ¹ýÖ¸µ¼½«Î±ÔìµÄPWAÌí¼Óµ½Ö÷ÆÁÄ»À´ÊµÊ©¹¥»÷¡£Ò»µ©Óû§ÔÚÕâЩӦÓÃÖÐÊäÈëÒøÐÐƾ֤£¬ÐÅÏ¢±ã»á±»Ð¹Â¶ÖÁ¹¥»÷Õß¿ØÖƵÄÃüÁîÓë¿ØÖÆ£¨C2£©·þÎñÆ÷»òTelegramȺÁÄÖС£ESETÒѼà²âµ½¶à²¨ÀàËƻ¡£
https://thehackernews.com/2024/08/czech-mobile-users-targeted-in-new.html
6. ÐÂÐÍDNSºóÃÅBackdoor.MsupedgeÕë¶Ǫ̂Íå´óѧ
8ÔÂ20ÈÕ£¬Íþв·ÖÎöÈËÔ±½üÆÚÔŲ́Íå´óѧÔâÊܵĹ¥»÷ÖнÒ¶ÁËÒ»ÖÖÐÂÐÍÄþ¾²ÍþвBackdoor.Msupedge£¬ÓÉÈüÃÅÌú¿Ë¹«Ë¾·¢ÏÖ²¢ÃüÃû¡£½ñºóÃŽÓÄÉÁËÒ»ÖÖº±¼ûµÄDNSͨÐÅ»úÖÆ£¬ËäΪÒÑÖª¼¼Êõµ«ÏʼûÓÚÍøÂç·¸×ï»î¶¯ÖС£MsupedgeÒÔDLLÐÎʽDZ²ØÓÚÊÜѬȾϵͳµÄÌض¨Â·¾¶£¬Í¨¹ýDNS²éѯ½ÓÊÕ²¢Ö´ÐÐÖ¸ÁÕâÒ»¼Æı²»½ö¹æ±ÜÁËͨÀý¼ì²â£¬»¹ÊµÏÖÁ˶ÔÄ¿±ê»úÆ÷µÄÒþÃزٿء£ÓÈΪֵµÃ×¢ÒâµÄÊÇ£¬MsupedgeÄÜÒÀ¾ÝDNS²éѯ½âÎö³öµÄIPµØÖ·ÖеÄÌض¨×Ö½ÚÀ´Áé»îµ÷ÕûÆäÐÐΪ£¬ÈçÆô¶¯½ø³Ì¡¢ÏÂÔضñÒâÎļþ¡¢É趨ϵͳÐÝÃßʱ³¤µÈ£¬¼«´óÔöÇ¿ÁËÆäÁé»îÐÔºÍÒþ±ÎÐÔ¡£´ËÍ⣬¸ÃºóÃÅÖ§³Ö¶àÖÖ²Ù×÷Ö¸Á°üÂÞ»ùÓÚDNS TXT¼Ç¼´´½¨½ø³Ì¡¢´ÓÖ¸¶¨URLÏÂÔØÎļþ¡¢Ê¹ÏµÍ³ÐÝÃß³¤´ï24Сʱ¼°ÇåÀíºÛ¼£µÈ¡£¾ÝÈüÃÅÌú¿Ë·ÖÎö£¬´Ë´ÎÈëÇֵijõʼÈë¿Úµã¼«ÓпÉÄÜÊǽüÆÚÆعâµÄPHP©¶´£¨CVE-2024-4577£©£¬¸Ã©¶´Äܵ¼ÖÂWindowsƽ̨ÉϵÄPHP°æ±¾Ô¶³Ì´úÂëÖ´ÐС£ÈüÃÅÌú¿ËÐû²¼ÁËÏ꾡µÄÈëÇÖÖ¸±ê£¨IOC£©£¬ÒÔÐÖúÓû§Ê¶±ðºÍ·ÀÓùBackdoor.MsupedgeµÄ¹¥»÷¡£
https://www.infosecurity-magazine.com/news/dns-based-backdoor-taiwanese/