¶íÀÕ¸ÔÖݶ¯ÎïÔ°ÊÛƱ·þÎñÔâºÚ¿Í¹¥»÷ £¬11.8ÍòÓû§ÐÅÏ¢±»µÁ

Ðû²¼Ê±¼ä 2024-08-21
1. ¶íÀÕ¸ÔÖݶ¯ÎïÔ°ÊÛƱ·þÎñÔâºÚ¿Í¹¥»÷ £¬11.8ÍòÓû§ÐÅÏ¢±»µÁ


8ÔÂ19ÈÕ £¬¶íÀÕ¸ÔÖݶ¯ÎïÔ°½üÆÚ·¢ÉúÁËÒ»ÆðÑÏÖصÄÊý¾Ýй¶Ê¼þ £¬Ô¼118,000ÃûÓû§µÄ¸öÈËÐÅÏ¢ºÍÖ§¸¶¿¨Êý¾ÝÔÚ2023Äê12ÔÂ20ÈÕÖÁ2024Äê6ÔÂ26ÈÕÆÚ¼äµÄÔÚÏßÊÛƱ·þÎñÖб»µÁ¡£ÕâЩÐÅÏ¢°üÂÞÐÕÃû¡¢Ö§¸¶¿¨ºÅ¡¢CVVÄþ¾²Âë¼°µ½ÆÚÈÕÆÚ £¬¶ÔÊܺ¦Õß×é³ÉDZÔÚ·çÏÕ¡£Ê¼þÓÚ6ÔÂ26ÈÕ±»·¢ÏÖºó £¬¶¯ÎïÔ°Á¢¼´Í£ÓÃÁËÊÜÓ°ÏìµÄÍøÕ¾ £¬²¢½¨Á¢ÁËеÄÄþ¾²¹ºÆ±Æ½Ì¨¡£¶¯ÎïÔ°ÒÑÏòÃåÒòÖÝ×ܼì²ì³¤°ì¹«ÊÒ³ÂËß £¬²¢Ïò¿ÉÄÜÊÜÓ°ÏìµÄ117,815ÃûÓû§·¢ËÍÁË֪ͨÐÅ £¬Í¬Ê±ÎªËûÃÇÌṩÁËÒ»ÄêµÄÃâ·ÑÐÅÓüà¿ØºÍÉí·Ý±  £»¤·þÎñ¡£¶¯ÎïÔ°ÌåÏÖ £¬´Ë´Îй¶ÊÇÓÉÓÚµÚÈý·½¹©Ó¦É̽»Ò×±»ÍþвÕßÖض¨ÏòËùÖ £¬²¢ÒÑÏòÁª°îÖ´·¨²¿ÃÅͨ±¨¡£ÎªÔ¤·ÀδÀ´ÀàËÆʼþ £¬¶¯ÎïÔ°Õý»ý¼«Éó²éÆäÄþ¾²Õþ²ßºÍ·¨Ê½¡£¾¡¹Üδ¹ûÈ»¾ßÌå¹¥»÷ÀàÐÍ £¬µ«·ÖÎöÈÏΪ¿ÉÄÜÊÇÍøÂçä¯ÀÀÆ÷ѬȾÁËÊý×ÖÇÔÈ¡Æ÷ £¬ÕâÀà¶ñÒâÈí¼þ³£±»ÓÃÓÚÔÚ½áÕËÒ³ÃæµÈÒªº¦Î»ÖÃÇÔÈ¡Óû§Ãô¸ÐÐÅÏ¢¡£


https://www.securityweek.com/oregon-zoo-ticketing-service-hack-impacts-118000/


2. Jewish Home LifecareÔâBlackCatÀÕË÷Èí¼þ¹¥»÷ £¬10ÍòÈËÊý¾Ýй¶


8ÔÂ19ÈÕ £¬Å¦Ô¼ÊеķÇÓªÀûÐÔÒ½ÁƱ£½¡×éÖ¯Jewish Home Lifecare£¨ÏÖ³ÆÐÂÓÌÌ«¼ÒÍ¥ÖÐÐÄ£©Åû¶Á˽üÆÚ·¢ÉúµÄÒ»ÆðÖØ´óÊý¾Ýй¶Ê¼þ £¬¸Ãʼþ²¨¼°Áè¼Ý104,000Ãû»¼Õß¼°ÉçÇø³ÉÔ±¡£½ñÄê2Ô £¬¸ÃÖÐÐÄÏòÊÜÓ°Ïì¿Í»§Í¨±¨³Æ £¬ÆäÍøÂçÔÚ1ÔÂ7ÈÕÔâÓöÒì³  £»î¶¯ £¬ºÚ¿Í¿ÉÄÜÒÑ»ñÈ¡°üÂÞ¸öÈËÉí·ÝÐÅÏ¢¡¢½ðÈÚÕË»§ÏêÇé¡¢Ò½ÁƼǼÔÚÄÚµÄÃô¸ÐÐÅÏ¢¡£ÎªÈ·±£Êܺ¦ÕßÄþ¾² £¬ÖÐÐÄÌṩÁËÃâ·ÑµÄÐÅÓüà¿Ø·þÎñ £¬²¢Ç¿µ÷ËäÎÞÖ±½ÓÖ¤¾Ý±íÃ÷ÐÅÏ¢Òѱ»ÀÄÓà £¬µ«ÈÔ½÷É÷Ðû²¼Í¨Öª¡£´Ë´Îй¶ÓëÀÕË÷Èí¼þ×éÖ¯BlackCat(Alphv)ÓйØ £¬ËüÃÇÉù³Æ¹¥»÷ÁËJewish Home Lifecare²¢»ñÈ¡ÁËÁÙ´²Ñо¿¡¢²ÆÕþ¼°Ô±¹¤¿Í»§Êý¾Ý £¬ÉõÖÁÉæ¼°¾èÔù×ʽðÀÄÓõÄÖ¤¾Ý¡£È»¶ø £¬±»µÁÎļþÊÇ·ñ¹ûÈ»ÉдýÈ·ÈÏ £¬ÇÒBlackCat×éÖ¯ÔÚ3Ô³õͻȻÏûʧ £¬ÆäÍøÕ¾ÒÑÎÞ·¨·ÃÎÊ¡£


https://www.securityweek.com/100000-impacted-by-jewish-home-lifecare-data-breach/


3. BlindEagle£¨APT-C-36£©£ºÀ­¶¡ÃÀÖÞµÄÁ¬ÐøÍþв


8ÔÂ20ÈÕ £¬¿¨°Í˹»ùʵÑéÊÒ¶ÔÃûΪBlindEagle£¨ÓÖ½ÐAPT-C-36£©µÄÁ¬ÐøÐÔÍþв×éÖ¯·¢³ö¾¯¸æ £¬¸Ã×é֯ר³¤ÓÚÕë¶ÔÀ­¶¡ÃÀÖÞµÄÍøÂç¹¥»÷ £¬BlindEagleÖ÷Ҫͨ¹ý¾«ÐÄÉè¼ÆµÄÍøÂçµöÓã»îÐж¯°¸ £¬¼Ùð¹Ù·½»ú¹¹ÈçË°Îñ²¿ÃÅ»òÍâ½»²¿ £¬ÓÕÆ­Óû§µã»÷¶ñÒâÁ´½Ó £¬ÏÂÔØαװ³É¹Ù·½ÎļþµÄѹËõ°ü £¬ÄÚº¬Ö¸ÏòÊܿضñÒâÈí¼þÕ¾µãµÄÁ´½Ó¡£ÕâЩÓʼþ´«ÉñÄ£Äâ¹Ù·½Í¨Ñ¶ £¬ÀûÓÃURLËõ¶ÌÆ÷ºÍ¶¯Ì¬DNS·þÎñÔö¼ÓÒþ±ÎÐÔ £¬Æ¾¾ÝÓû§Î»ÖÃÖض¨Ïò £¬ÒÔÌӱܼì²â¡£Ò»µ©Óû§ÖÐÕÐ £¬BlindEagle±ãÆô¶¯¶à½×¶ÎѬȾ £¬²¿Êð°üÂÞnjRAT¡¢LimeRATµÈ¹ûȻԶ³Ì·ÃÎÊľÂí£¨RAT£© £¬ÕâЩ¹¤¾ß±»¶¨ÖÆÒÔÂú×ã²îÒì¹¥»÷ÐèÇó £¬ÔÊÐí¸Ã×éÖ¯¼à¿ØÊܺ¦Õß¡¢ÇÔÈ¡Ãô¸ÐÐÅÏ¢¼°²ÆÕþƾ֤¡£BlindEagle»¹ÀûÓýø³Ì×¢Èë¼¼Êõ £¬Èç½ø³ÌÍÚ¿Õ £¬½«¶ñÒâ´úÂëÒþ²ØÓںϷ¨½ø³ÌÖÐ £¬ÒԴ˹æ±ÜÄþ¾²¼ì²â £¬ÊµÏÖºã¾ÃDZ·üÓëÊý¾ÝÇÔÈ¡¡£BlindEagleµÄ¹¥»÷Ä¿±ê°üÂÞ¸çÂ×±ÈÑÇ¡¢¶ò¹Ï¶à¶û¡¢ÖÇÀûºÍ°ÍÄÃÂíµÄ¸öÈ˺Í×éÖ¯ £¬Éæ¼°Õþ¸®¡¢½ÌÓý¡¢ÎÀÉúºÍ½»Í¨µÈ¸÷¸öÁìÓò¡£


https://securityonline.info/blindeagle-apt-group-a-persistent-threat-in-latin-america/


4. ΢о¿Æ¼¼ÔâÓöÍøÂç¹¥»÷ £¬²¿ÃÅÒµÎñÊÜÓ°Ïì


8ÔÂ21ÈÕ £¬ÃÀ¹ú°ëµ¼ÌåÖÆÔìÉÌ΢о¿Æ¼¼Microchip½üÆÚÔâÓöÁËÒ»ÆðÍøÂçÄþ¾²Ê¼þ £¬¶Ô¹«Ë¾ÔËÓªÔì³ÉÁËÏÔÖøÓ°Ïì¡£¾Ý¸Ã¹«Ë¾Í¸Â¶ £¬8ÔÂ17ÈÕ £¬Î¢Ð¾¿Æ¼¼µÄÐÅÏ¢¼¼Êõϵͳ±»¼ì²âµ½´æÔÚDZÔڵĿÉÒɻ £¬ËæºóÓÚ8ÔÂ19ÈÕÈ·ÈÏϵͳÒÑÔ⵽δ¾­ÊÚȨµÄ·ÃÎÊ¡£Ãæ¶ÔÕâÒ»½ô¼±Çé¿ö £¬¹«Ë¾Ñ¸ËÙ½ÓÄÉÐж¯ £¬¸ôÀëÁËÊÜÓ°ÏìµÄ·þÎñÆ÷ϵͳ £¬²¢¹Ø±ÕÁË¿ÉÄÜÊܲ¨¼°µÄÆäËûϵͳ £¬Í¬Ê±Æ¸ÇëÁËרҵµÄÍⲿÍøÂçÄþ¾²ÕÕÁÏÍŶÓÀ´È«ÃæÆÀ¹ÀʼþµÄÑÏÖØˮƽ¼°Ó°Ï췶Χ¡£´Ë´ÎÄþ¾²Ê¼þµ¼ÖÂ΢о¿Æ¼¼²¿ÃÅÖÆÔìÉèÊ©µÄÔËӪЧÂʽµÖÁÕý³£Ë®Æ½ÒÔÏ £¬Ö±½ÓÓ°ÏìÁ˹«Ë¾¶¨Ê±ÂÄÐпͻ§¶©µ¥µÄÄÜÁ¦¡£¾¡¹Ü¹«Ë¾ÕýÈ«Á¦ÒÔ¸°½â¾öÕâÒ»ÎÊÌâ £¬²¢ÔÊÐí½«¾¡¿ì»Ö¸´Õý³£ÔËÓª £¬µ«Ä¿Ç°¹ØÓÚʼþµÄ¾ßÌåÔ­Òò¡¢Ð¾Æ¬ÖÆÔìÒµÎñÊÜ×ÌÈŵÄÏêϸˮƽ £¬ÒÔ¼°ÊÇ·ñÉæ¼°ÀÕË÷Èí¼þµÈÃô¸ÐÐÅÏ¢ £¬ÈÔ´ý½øÒ»·¨Ê½²éÈ·ÈÏ¡£ÖµµÃ×¢ÒâµÄÊÇ £¬Î¢Ð¾¿Æ¼¼½ÓÄɸôÀë´ëÊ©µÄ×ö·¨±íÃ÷ £¬Î´¾­ÊÚȨ·½µÄ»î¶¯¿ÉÄÜÒÑ¿ª¶ËÏÔʾ³öÏò¹«Ë¾¸ü¹ã·ºIT×ʲúÀ©É¢µÄ¼£Ïó¡£


https://www.theregister.com/2024/08/21/microchip_technology_security_incident/


5. ½Ý¿ËÒƶ¯Óû§ÔâPWAÍøÂçµöÓã¹¥»÷


8ÔÂ20ÈÕ £¬½Ý¿Ë¹²ºÍ¹úµÄÒƶ¯Óû§ÕýÃæÁÙÒ»ÖÖÐÂÐÍÇÒÅÓ´óµÄÍøÂçµöÓãÍþв £¬¸ÃÍþвÀûÓý¥½øʽWebÓ¦Ó÷¨Ê½£¨PWA£©¼¼Êõ £¬Õë¶Ô¶à¼ÒÒøÐÐÓû§ÇÔÈ¡ÒøÐÐÕË»§Æ¾Ö¤¡£¾Ý˹Âå·¥¿ËÍøÂçÄþ¾²¹«Ë¾ESET³ÂËß £¬¹¥»÷Ä¿±ê°üÂ޽ݿ˵ÄCSOBÒøÐС¢ÐÙÑÀÀûµÄOTPÒøÐм°¸ñ³¼ªÑǵÄTBCÒøÐС£¹¥»÷Õßͨ¹ý×Ô¶¯ÓïÒôµç»°¡¢¶ÌÐż°É罻ýÌå¶ñÒâ¹ã¸æÉ¢²¼µöÓãÁ´½Ó £¬ÓÕµ¼Óû§µã»÷²¢°²×°¿´ËƺϷ¨µÄÒøÐÐÓ¦Ó÷¨Ê½PWA»òAndroidÉϵÄWebAPK £¬ÕâЩӦÓü¸ºõÍêÃÀ¸´ÖÆÁËÕæʵÒøÐÐÓ¦ÓõĽçÃæ £¬´Ó¶øÈƹýÁË´«Í³ä¯ÀÀÆ÷µÄÄþ¾²¾¯¸æ¡£ÖµµÃ×¢ÒâµÄÊÇ £¬¹¥»÷±³ºóÉæ¼°Á½¸ö²îÒìµÄÍþвÐÐΪÕß £¬ËûÃÇÀûÓÃChrome WebAPK¼¼ÊõµÄĬÈÏÐÐΪ £¬ÀÄÓøù¦Ð§ÒÔÒþ²Ø¡°À´×Ô²»ÊÜÐÅÈÎÀ´Ô´µÄ°²×°¡±¾¯¸æ £¬Ê¹µÃÓû§ÄÑÒÔ²ì¾õ·çÏÕ¡£¶ÔÓÚiOSÓû§ £¬Ôòͨ¹ýÖ¸µ¼½«Î±ÔìµÄPWAÌí¼Óµ½Ö÷ÆÁÄ»À´ÊµÊ©¹¥»÷¡£Ò»µ©Óû§ÔÚÕâЩӦÓÃÖÐÊäÈëÒøÐÐƾ֤ £¬ÐÅÏ¢±ã»á±»Ð¹Â¶ÖÁ¹¥»÷Õß¿ØÖƵÄÃüÁîÓë¿ØÖÆ£¨C2£©·þÎñÆ÷»òTelegramȺÁÄÖС£ESETÒѼà²âµ½¶à²¨ÀàËƻ¡£


https://thehackernews.com/2024/08/czech-mobile-users-targeted-in-new.html


6. ÐÂÐÍDNSºóÃÅBackdoor.MsupedgeÕë¶Ǫ̂Íå´óѧ


8ÔÂ20ÈÕ £¬Íþв·ÖÎöÈËÔ±½üÆÚÔŲ́Íå´óѧÔâÊܵĹ¥»÷ÖнÒ¶ÁËÒ»ÖÖÐÂÐÍÄþ¾²ÍþвBackdoor.Msupedge £¬ÓÉÈüÃÅÌú¿Ë¹«Ë¾·¢ÏÖ²¢ÃüÃû¡£½ñºóÃŽÓÄÉÁËÒ»ÖÖº±¼ûµÄDNSͨÐÅ»úÖÆ £¬ËäΪÒÑÖª¼¼Êõµ«ÏʼûÓÚÍøÂç·¸×ï»î¶¯ÖС£MsupedgeÒÔDLLÐÎʽDZ²ØÓÚÊÜѬȾϵͳµÄÌض¨Â·¾¶ £¬Í¨¹ýDNS²éѯ½ÓÊÕ²¢Ö´ÐÐÖ¸Áî £¬ÕâÒ»¼Æı²»½ö¹æ±ÜÁËͨÀý¼ì²â £¬»¹ÊµÏÖÁ˶ÔÄ¿±ê»úÆ÷µÄÒþÃزٿØ¡£ÓÈΪֵµÃ×¢ÒâµÄÊÇ £¬MsupedgeÄÜÒÀ¾ÝDNS²éѯ½âÎö³öµÄIPµØÖ·ÖеÄÌض¨×Ö½ÚÀ´Áé»îµ÷ÕûÆäÐÐΪ £¬ÈçÆô¶¯½ø³Ì¡¢ÏÂÔضñÒâÎļþ¡¢É趨ϵͳÐÝÃßʱ³¤µÈ £¬¼«´óÔöÇ¿ÁËÆäÁé»îÐÔºÍÒþ±ÎÐÔ¡£´ËÍâ £¬¸ÃºóÃÅÖ§³Ö¶àÖÖ²Ù×÷Ö¸Áî £¬°üÂÞ»ùÓÚDNS TXT¼Ç¼´´½¨½ø³Ì¡¢´ÓÖ¸¶¨URLÏÂÔØÎļþ¡¢Ê¹ÏµÍ³ÐÝÃß³¤´ï24Сʱ¼°ÇåÀíºÛ¼£µÈ¡£¾ÝÈüÃÅÌú¿Ë·ÖÎö £¬´Ë´ÎÈëÇֵijõʼÈë¿Úµã¼«ÓпÉÄÜÊǽüÆÚÆعâµÄPHP©¶´£¨CVE-2024-4577£© £¬¸Ã©¶´Äܵ¼ÖÂWindowsƽ̨ÉϵÄPHP°æ±¾Ô¶³Ì´úÂëÖ´ÐС£ÈüÃÅÌú¿ËÐû²¼ÁËÏ꾡µÄÈëÇÖÖ¸±ê£¨IOC£© £¬ÒÔЭÖúÓû§Ê¶±ðºÍ·ÀÓùBackdoor.MsupedgeµÄ¹¥»÷¡£


https://www.infosecurity-magazine.com/news/dns-based-backdoor-taiwanese/