΢ÈíÔ¶³Ì×¢²á±í¿Í»§¶Ë©¶´CVE-2024-43532¹ûÈ»
Ðû²¼Ê±¼ä 2024-10-2410ÔÂ22ÈÕ£¬Õë¶Ô΢ÈíÔ¶³Ì×¢²á±í¿Í»§¶ËµÄ©¶´CVE-2024-43532ÏÖÒѹûÈ»£¬¸Ã©¶´ÀûÓÃWindows×¢²á±í¿Í»§¶ËʵÏÖÖеĻØÍË»úÖÆ£¬ÔÚSMB´«Êä²»ÐÐÓÃʱÒÀÀµÓھɴ«ÊäÐÒ飬²¢½µµÍÉí·ÝÑéÖ¤¹ý³ÌµÄÄþ¾²ÐÔ£¬´Ó¶ø¿ØÖÆWindowsÓò¡£¸Ã©¶´Ó°ÏìWindows·þÎñÆ÷°æ±¾2008ÖÁ2022ÒÔ¼°Windows 10ºÍ11¡£¹¥»÷Õß¿Éͨ¹ýÀ¹½ØNTLMÉí·ÝÑéÖ¤ÎÕÊÖ²¢½«Æäת·¢µ½Active DirectoryÖ¤Êé·þÎñ(ADCS)µÈ·þÎñ£¬´´½¨ÐµÄÓò¹ÜÀíÔ±ÕÊ»§¡£CVE-2024-43532Ô´ÓÚÔ¶³Ì×¢²á±í¿Í»§¶ËÔÚ´¦ÖÃRPCÉí·ÝÑé֤ʱµÄÎÊÌ⣬µ±SMB´«Êä²»ÐÐÓÃʱ£¬¿Í»§¶Ë»áÇл»µ½½Ï¾ÉµÄÐÒ鲢ʹÓÃÈõÉí·ÝÑéÖ¤¼¶±ð¡£AkamaiÑо¿Ô±Stiv KupchikÓÚ2ÔÂ1ÈÕÏò΢ÈíÅû¶Á˸鶴£¬µ«×î³õ±»²µ»Ø£¬ºóÓÚ6ÔÂÖÐÑ®ÖØÐÂÌá½»²¢µÃµ½È·ÈÏ£¬Î¢ÈíÓÚÈý¸öÔºóÐû²¼ÁËÐÞ¸´·¨Ê½¡£Ä¿Ç°£¬KupchikÒÑÐû²¼ÓÐЧµÄ¿´·¨ÑéÖ¤´úÂ룬²¢ÔÚNo HatÄþ¾²»áÒéÉϽâÊÍÁËÀûÓùý³Ì¡£AkamaiµÄ³ÂËß»¹ÌṩÁ˼ì²âÒ×Êܹ¥»÷µÄ»úÆ÷ºÍ¼àÊÓÌض¨RPCµ÷ÓõÄÒªÁì¡£
https://www.bleepingcomputer.com/news/security/exploit-released-for-new-windows-server-winreg-ntlm-relay-attack/
2. Gophish¹¤¾ß°ü±»ÀÄÓÃÓÚÖÆ×÷Õë¶Ô¶íÓïƬÇøÓû§µÄRATľÂí
10ÔÂ22ÈÕ£¬GophishÕâÒ»¿ªÔ´ÍøÂçµöÓ㹤¾ß°üÕý±»·Ç·¨·Ö×ÓÀûÓã¬ÒÔÖÆ×÷²¢Á÷´«DarkCrystal RAT£¨DCRat£©ºÍPowerRATµÈÔ¶³Ì·ÃÎÊľÂí£¬Ö÷ҪĿ±êÊǶíÓïƬÇøÓû§£¬°üÂÞ¶íÂÞ˹¼°ÆäÖܱ߹ú¼ÒÈçÎÚ¿ËÀ¼¡¢°×¶íÂÞ˹¡¢¹þÈø¿Ë˹̹¡¢ÎÚ×ȱð¿Ë˹̹ºÍ°¢Èû°Ý½®¡£GophishÔ±¾±»Éè¼ÆÓÃÓÚ×éÖ¯²âÊÔÍøÂçµöÓã·ÀÓùÄÜÁ¦£¬µ«¹¥»÷ÕßÈ´½è´ËÖÆ×÷αװ³ÉYandex DiskÁ´½ÓºÍVKÉç½»ÍøÂçÒ³ÃæµÄÍøÂçµöÓãÓʼþ¡£ÕâЩÓʼþÓÕµ¼Óû§ÏÂÔØ°üÂÞDCRat»òPowerRAT¶ñÒâľÂíµÄMicrosoft WordÎĵµ»òǶÈëJavaScriptµÄHTMLÎļþ¡£Ò»µ©Êܺ¦Õß´ò¿ªÎĵµ²¢ÆôÓú꣬¾Í»á´¥·¢¶ñÒâVisual Basic (VB)½Å±¾£¬½ø¶øÏÂÔز¢Ö´ÐÐHTAÎļþºÍPowerShell¼ÓÔØÆ÷¡£ÕâЩ½Å±¾°üÂÞPowerRATµÄbase64±àÂëÊý¾Ý¿é£¬½âÂëºóÔÚÊܺ¦Õß»úÆ÷ÉÏÖ´ÐС£³ýÁËϵͳÕì²ì£¬¸Ã¶ñÒâÈí¼þ»¹»áÊÕ¼¯Çý¶¯Æ÷ÐòÁкŲ¢Á¬½Óµ½¶íÂÞ˹Զ³Ì·þÎñÆ÷½ÓÊÕÖ¸Áî¡£Èôδ»ñÏìÓ¦£¬ÔòÖ´ÐÐǶÈëµÄPowerShell½Å±¾¡£DCRat×÷ΪһÖÖÄ£¿é»¯¶ñÒâÈí¼þ£¬ÄÜÇÔÈ¡Êý¾Ý¡¢²¶×½ÆÁÄ»½ØͼºÍ»÷¼ü£¬ÌṩԶ³Ì¿ØÖÆ£¬²¢ÏÂÔØÖ´ÐÐÆäËûÎļþ¡£
https://thehackernews.com/2024/10/gophish-framework-used-in-phishing.html
3. GrandoreiroÒøÐÐľÂí£ºÈ«Çò½ðÈÚÍþвÁ¬ÐøÉý¼¶
10ÔÂ22ÈÕ£¬¿¨°Í˹»ùʵÑéÊÒ×î½üÐû²¼µÄÒ»·Ý³ÂËßÏÔʾ£¬GrandoreiroÒøÐÐľÂíÒѳÉΪȫÇòÖØ´ó½ðÈÚÍþв¡£¸ÃľÂíÆðÔ´ÓÚ°ÍÎ÷£¬×Ô2016ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬Ö¼ÔÚÇÔÈ¡ÒøÐÐƾ֤²¢ÈƹýÄþ¾²´ëÊ©¡£¾¡¹ÜÖ´·¨²¿ÃÅÒÑŬÁ¦¹¥»÷£¬µ«GrandoreiroµÄ¹¥»÷·¶Î§ÒÑÏÔÖøÀ©´ó£¬ÏÖÒÑÕë¶Ô45¸ö¹ú¼ÒµÄ1700¼ÒÒøÐкÍ276¸ö¼ÓÃÜ»õ±ÒÇ®°ü£¬ÏÔʾ³öÆäÕæÕýµÄÈ«ÇòÍþвÐÔ¡£ÔÚÎ÷°àÑÀ£¬GrandoreiroÔì³ÉµÄ¾¼ÃËðʧԤ¼Æ´ï350ÍòÅ·Ôª£¬µ«³ÂËßÖ¸³öÆä¿ÉÄÜ´øÀ´µÄÀûÈóÁè¼Ý1.1ÒÚÅ·Ôª¡£GrandoreiroľÂí²»Í£´´Ð¼Æı£¬Ê¹ÓÃÓòÉú³ÉËã·¨´´½¨ÐµÄÃüÁîºÍ¿ØÖÆ·þÎñÆ÷£¬½ÓÄÉÃÜÎÄÇÔÈ¡¼ÓÃÜÔö¼Ó·ÖÎöÄѶȣ¬²¢ÒýÈëɳºÐ¹æ±Ü¼¼ÊõÈç¸ú×ÙÊó±êÒƶ¯ÒÔÄ£·ÂºÏ·¨Óû§½»»¥£¬ÆÛÆ·´ÆÛթϵͳ¡£ÆäÄ£¿é»¯ÌØÐÔÔÊÐí¶à¸ö²Ù×÷Ô±´´½¨Õë¶ÔÌض¨µØÓò»ò½ðÈÚ»ú¹¹µÄËéƬ»¯°æ±¾¡£×Ô2022ÄêÒÔÀ´£¬¿¨°Í˹»ùÊӲ쵽¸ÃľÂí´´½¨Á˽ÏС¡¢½ÏÇáµÄ°æ±¾£¬×¨×¢ÓÚ½ÏÉÙµÄÄ¿±ê£¬ÌرðÊÇÔÚÄ«Î÷¸ç¡£Grandoreiroͨ³£ÒÔ¶ñÒâÈí¼þ¼´·þÎñµÄÐÎʽÔËÐУ¬ÆäÁ÷´«Êܵ½¿ØÖÆ£¬Ö»ÓÐÖµµÃÐÅÀµµÄºÏ×÷»ï°é²ÅÆø·ÃÎÊÔ´´úÂë¡£
https://securityonline.info/1700-banks-45-countries-grandoreiro-trojan-expands-its-reach/
4. ºÚ¿ÍÀûÓÃgRPCÐÒéÔÚDocker APIÉϲ¿Êð¼ÓÃÜ»õ±ÒÍÚ¿ó·¨Ê½
10ÔÂ22ÈÕ£¬Trend Micro Ñо¿ÈËÔ±·¢ÏÖÁËÒ»ÖÖÐÂÐÍÍøÂç¹¥»÷ÊֶΣ¬¹¥»÷ÕßÀûÓà Docker Ô¶³Ì API ·þÎñÆ÷É쵀 gRPC ÐÒ飨ͨ¹ý h2c Ã÷ÎÄ HTTP/2£©À´²¿Êð SRBMiner ¼ÓÃÜ»õ±ÒÍÚ¿ó·¨Ê½£¬Ä¿±êÊÇÍÚ¾ò Ripple Labs ¿ª·¢µÄ XRP ¼ÓÃÜ»õ±Ò¡£¹¥»÷Á÷³ÌʼÓÚɨÃèÒ×Êܹ¥»÷µÄ Docker API ·þÎñÆ÷£¬Ëæºó¼ì²éÆä¿ÉÓÃÐԺͰ汾£¬²¢·¢ËÍ gRPC/h2c Éý¼¶ÇëÇóÒÔÔ¶³ÌÀûÓà Docker ¹¦Ð§¶ø²»±»·¢ÏÖ¡£Ò»µ©½¨Á¢¿ØÖÆ£¬¹¥»÷Õß±ãʹÓúϷ¨»ù´¡Ó³Ïñ¹¹½¨ Docker Ó³Ïñ£¬ÔÚ /usr/sbin Ŀ¼Öв¿ÊðÍÚ¿ó·¨Ê½£¬²¢´Ó GitHub ÏÂÔضñÒâÈí¼þ¡£ËûÃÇ»¹ÌṩÁË Ripple Ç®°üµØÖ·ÒÔÊÕ¼¯ÍÚ³öµÄ¼ÓÃÜ»õ±Ò¡£´Ë´Î¹¥»÷Ö®ËùÒÔÁîÈ˵£ÓÇ£¬ÊÇÒòΪʹÓà h2c É쵀 gRPC ÐÒé¿ÉÈƹýÄþ¾²²ã£¬Ê¹Äþ¾²¹¤¾ßÄÑÒÔ¼ì²âµ½¼ÓÃܿ󹤵IJ¿Êð¡£Õâ±íÃ÷ÍøÂç·¸×ï·Ö×ӵļÆıÔÚ²»Í£Ñݱ䣬ËûÃÇÕýÔÚÑ°ÕÒ´´ÐÂÒªÁìÀ´ÀûÓà Docker µÈÈÝÆ÷»¯»·¾³¡£Òò´Ë£¬±£»¤ Docker Ô¶³Ì API ºÍ¼à¿ØÒì³£»î¶¯±äµÃÓÈΪÖØÒª¡£
https://securityonline.info/cryptojacking-alert-hackers-exploit-grpc-and-http-2-to-deploy-miners/
5. CISA½«Microsoft SharePoint©¶´ÁÐΪÒÑÖª±»ÀûÓ鶴
10ÔÂ23ÈÕ£¬ÃÀ¹úÍøÂçÄþ¾²ºÍ»ù´¡ÉèÊ©Äþ¾²¾Ö£¨CISA£©Òѽ«Microsoft SharePointµÄÒ»¸ö·´ÐòÁл¯Â©¶´CVE-2024-38094£¨CVSS v4ÆÀ·Ö£º7.2£©ÄÉÈëÆäÒÑÖª±»ÀûÓ鶴£¨KEV£©Ä¿Â¼ÖС£¸Ã©¶´ÔÊÐíÓµÓÐÕ¾µãËùÓÐÕßȨÏ޵Ĺ¥»÷Õßͨ¹ýSharePoint Server×¢Èë²¢Ö´ÐÐÈÎÒâ´úÂë¡£¾Ý΢Èíͨ¸æ£¬´Ë©¶´Ô´ÓÚSharePoint Server Search×é¼þµÄÊäÈëÑéÖ¤´íÎó£¬Ê¹µÃδ¾Éí·ÝÑéÖ¤µÄÓû§Ò²ÄÜͨ¹ý·¢ËÍÌØÖÆHTTPÇëÇóÀ´ÀûÓ鶴£¬½ø¶øÔÚ·þÎñÆ÷ÉÏÖ´ÐÐÈÎÒâ´úÂ룬¿ÉÄܽӹÜÕû¸öϵͳ¡£Æ¾¾Ý¾ßÓÐÔ¼ÊøÁ¦µÄ²Ù×÷Ö¸Áî22-01£¬ÒªÇóÁª°î»ú¹¹£¨FCEB£©±ØÐëÔڹ涨½ØÖ¹ÈÕÆÚÇ°½â¾öÒÑ·¢Ïֵĩ¶´£¬ÒÔ±£»¤ÍøÂçÃâÊÜĿ¼ÖЩ¶´µÄ¹¥»÷¡£CISAÌرðÒªÇóÁª°î»ú¹¹ÔÚ2024Äê11ÔÂ12ÈÕÇ°ÐÞ¸´´ËSharePoint©¶´¡£Í¬Ê±£¬×¨¼ÒÒ²½¨Òé˽ÈË×éÖ¯Éó²éCISAµÄ©¶´Ä¿Â¼£¬²¢¼°Ê±½â¾öÆä»ù´¡ÉèÊ©ÖдæÔÚµÄÏàӦ©¶´£¬ÒÔÈ·±£ÍøÂçÄþ¾²¡£
https://securityaffairs.com/170157/security/u-s-cisa-adds-microsoft-sharepoint-flaw-known-exploited-vulnerabilities-catalog.html
6. ±±·Çµç×Ó¾º¼¼Æ½Ì¨ESNAÓû§Êý¾ÝÔâºÚ¿Íй¶
10ÔÂ24ÈÕ£¬ÔÚ½ÇÖðǰϦ£¬ÃûΪ¡°Shooked¡±µÄºÚ¿ÍÓÚ2024Äê10ÔÂ23ÈÕÔÚBreach ForumsÉÏй¶Á˱±·Çµç×Ó¾º¼¼(ESNA)ƽ̨Áè¼Ý18ÍòÃûÓû§µÄ¸öÈËÊý¾Ý£¬¸ÃÊý¾Ýת´¢¾ÞϸΪ3GB£¬²¢Éù³ÆÊÇ¡°ÍêÕûÊý¾Ý¿â¡±¡£´Ë´Îй¶·¢ÉúÔÚESNA½ÇÖðÓÚĦÂå¸ç¿ªÈüµÄÇ°Ò»Ìì¡£ESNAÊÇÒ»¸öÖ¼ÔÚ´Ù½ø±±·ÇµØÓò¾º¼¼ÓÎÏ·Éú³¤µÄƽ̨£¬×éÖ¯ÁË°üÂÞFC25¡¢Free Fire¡¢½ÖÍ·°ÔÍõ6µÈÈÈÃÅÓÎÏ·µÄ½õ±êÈü¡£¾Ý·ÖÎö£¬Ð¹Â¶µÄÊý¾Ý°üÂÞÁè¼Ý900ÍòÐУ¬µ«È¥ÖغóΨһÓû§¼Ç¼Ϊ180,000Ìõ£¬°üÂÞÓû§Éí·Ý¡¢¹ú¼Ò¡¢Óû§Ãû¡¢IPµØÖ·¡¢Ê±¼ä´Á¡¢»á»°ID¡¢WordPress URLºÍµç×ÓÓʼþµØÖ·µÈÐÅÏ¢£¬µ«²»°üÂÞÃÜÂë»ò²ÆÕþÐÅÏ¢¡£¾¡¹ÜÈç´Ë£¬Óû§ÈÔ±»½¨Òé¸ü¸ÄÃÜÂëÒÔ·ÀÍòÒ»£¬²¢¾¯Ìè¿ÉÄÜÓÉ´Ë´Îй¶Òý·¢µÄÍøÂçµöÓã¹¥»÷¡£Ä¿Ç°£¬ESNA×éÖ¯ÉÐδ¶Ô´ËÊÂ×÷³ö»ØÓ¦£¬µ«Óû§Ó¦±£³Ö¾¯Ì裬ÒÔ·ÀÍøÂç·¸×ï·Ö×ÓÀûÓô˴Îй¶½øÐжñÒâ»î¶¯¡£
https://hackread.com/hackers-leak-esport-north-africa-user-record-before-tournament/