BitdefenderÐû²¼ShrinkLockerÀÕË÷Èí¼þ½âÃÜÆ÷

Ðû²¼Ê±¼ä 2024-11-14

1. BitdefenderÐû²¼ShrinkLockerÀÕË÷Èí¼þ½âÃÜÆ÷


11ÔÂ13ÈÕ £¬BitdefenderÐû²¼ÁËÕë¶ÔShrinkLockerÀÕË÷Èí¼þµÄ½âÃÜÆ÷ £¬²¢·¢±íÁËһƪÏêϸ½âÊÍÆäÊÂÇéÔ­ÀíµÄÑо¿²©¿Í¡£ShrinkLockerÀûÓÃWindowsµÄºÏ·¨¹¦Ð§BitLocker £¬¿ìËÙ¼ÓÃÜ°üÂÞϵͳÇý¶¯Æ÷ÔÚÄÚµÄÕû¸öÇý¶¯Æ÷ £¬È»ºóɾ³ý»Ö¸´Ñ¡Ïî¡£¸ÃÀÕË÷Èí¼þÊ×´ÎÔÚÖж«Ò»¼ÒÒ½ÁƱ£½¡¹«Ë¾µÄʼþÖб»·¢ÏÖ £¬¹¥»÷Õßͨ¹ýºáÏòÒƶ¯ÔÚϵͳÄÚ²¿ÊðShrinkLocker¡£ËüÕë¶ÔÄ«Î÷¸ç¡¢Ó¡¶ÈÄáÎ÷ÑǺÍÔ¼µ©µÄ×éÖ¯ £¬Ó°ÏìÁ˸ÖÌú¡¢ÒßÃçÖÆÔìµÈÐÐÒµ¼°Õþ¸®ÊµÌå¡£ÓëÒÀÀµÅÓ´ó¼ÓÃÜËã·¨µÄÏÖ´úÀÕË÷Èí¼þ²îÒì £¬ShrinkLocker½ÓÄɸü¼òµ¥µÄÒªÁì £¬Ïȼì²éBitLockerÊÇ·ñÆôÓà £¬ÈôδÆôÓÃÔò°²×° £¬²¢Ê¹ÓÃËæ»úÉú³ÉµÄÃÜÂëÖØмÓÃÜϵͳ¡£ÖØÆôºó £¬Óû§ÐèÊäÈëÃÜÂë½âËøÇý¶¯Æ÷ £¬Ö§¸¶Êê½ðÒÔ»»È¡½âÃÜÃÜÔ¿¡£¸ÃÀÕË÷Èí¼þµÄ¼òµ¥ÐÔʹÆä¶ÔµÍ¼¶ÍøÂç·¸×ï·Ö×Ó¾ßÓÐÎüÒýÁ¦ £¬ÇÒÒѱ»¶à¸öÍþвÐÐΪÕ߸ıàÓÃÓÚ¸ü¼òµ¥µÄ¹¥»÷¡£ShrinkLocker¿ÉÔھɰæWindowsºÍServerϵͳÉÏÖ´ÐС£Î¢ÈíÔøÌåÏÖ £¬ÒÁÀÊÕþ¸®Ö§³ÖµÄÍþв×éÖ¯ÀÄÓÃBitLocker¹¦Ð§½øÐй¥»÷ £¬ÆäËûÍøÂç·¸×ï·Ö×ÓҲʹÓÃÀàËƼ¼Êõ¡£


https://therecord.media/bitdefender-releases-decryptor-shrinklocker


2. 1.22ÒÚÉÌÒµÁªÏµÐÅÏ¢ÔâB2Bƽ̨DemandScienceÊý¾Ýй¶


11ÔÂ13ÈÕ £¬ÏÖÒÑÈ·ÈÏ £¬×Ô2024Äê2ÔÂÒÔÀ´ £¬B2BÐèÇóÉú³Éƽ̨DemandScience£¨Ç°ÉíΪPure Incubation£©µÄ1.22ÒÚÈ˵ÄÉÌÒµÁªÏµÐÅÏ¢±»ÇÔÈ¡²¢ÔÚÍøÂç·¸×ïÂÛ̳ÉϳöÊÛ¡£ÕâЩÊý¾Ý°üÂÞÈ«Ãû¡¢µØÖ·¡¢µç×ÓÓʼþ¡¢µç»°ºÅÂ롢ְλºÍÉ罻ýÌåÁ´½ÓµÈ £¬ÊÇ´Ó¹«¹²À´Ô´ºÍµÚÈý·½ÊÕ¼¯µÄ¡£2024Äê2Ô £¬ÃûΪ¡°KryptonZambie¡±µÄÍþвÐÐΪÕßÔÚBreachForumsÉÏÉù³ÆÕâЩÊý¾ÝÊÇ´ÓPure IncubationµÄ̻¶ϵͳÖÐÇÔÈ¡µÄ¡£DemandScienceÆäʱ·ñÈÏ´æÔÚй¶ £¬²¢ÌåÏÖÆäϵͳδÊܹ¥»÷¡£È»¶ø £¬µ½2024Äê8ÔÂ15ÈÕ £¬KryptonZambieÃâ·Ñй¶ÁËÊý¾Ý¼¯¡£ÌØÂåÒÁ¡¤ºàÌØÔÚ²©¿ÍÎÄÕÂÖÐÈ·ÈÏÊý¾ÝÕæʵ¿É¿¿ £¬²¢Ö¸³ö鶵ÄÊý¾ÝÀ´×ÔDemandScienceÁ½ÄêÇ°ÒÑÍËÒÛµÄϵͳ¡£ºàÌØ»¹È·ÈÏ鶵ÄÊý¾ÝÖаüÂÞËû×Ô¼ºµÄ¼Ç¼¡£±»µÁÊý¾Ý¼¯ÖеÄËùÓÐ1.22ÒÚ¸öΨһµç×ÓÓʼþµØÖ·ÒÑÌí¼Óµ½¡°Have I Been Pwned¡±ÖÐ £¬ÊÜÓ°ÏìµÄ¶©ÔÄÕß½«ÊÕµ½Í¨Öª¡£


https://www.bleepingcomputer.com/news/security/leaked-info-of-122-million-linked-to-b2b-data-aggregator-breach/


3. ÒÁÀʺڿÍ×éÖ¯TA455Õë¶Ôº½¿Õº½ÌìÐÐÒµÌᳫÍøÂçµöÓã¹¥»÷


11ÔÂ14ÈÕ £¬×ÔÈ¥Äê9ÔÂÆ𠣬һÏîÕë¶ÔLinkedInµÈƽ̨Óû§µÄÍøÂçµöÓã»î¶¯¿ªÊ¼»îÔ¾ £¬¸Ã»î¶¯ÓÉÓëÒÁÀÊÏà¹ØµÄÍþвÐÐΪÕßTA455Ìᳫ¡£TA455½ÓÄÉÓã²æʽÍøÂçµöÓãÒªÁì £¬Ã°³äº½¿Õº½ÌìÐÐÒµµÄÕÐƸÈËÔ±ÓëÊܺ¦Õß½¨Á¢ÁªÏµ £¬²¢ÓÕµ¼ËûÃÇÏÂÔØÃûΪ¡°SIgnedConnection.zip¡±µÄѹËõÎļþ¡£Í¬Ê± £¬ÍþвÐÐΪÕß»¹ÌṩPDFÖ¸ÄÏ £¬Ö¸µ¼Êܺ¦ÕßÈçºÎÄþ¾²ÏÂÔغʹò¿ª¸ÃÎļþ¡£È»¶ø £¬¸ÃѹËõÎļþʵ¼ÊÉÏ°üÂÞÒ»¸ö¿ÉÖ´ÐÐÎļþ £¬Í¨¹ýDLL²àÔؽ«ÃûΪ¡°secure32.dll¡±µÄ¶ñÒâDLLÎļþ¼ÓÔص½Êܺ¦ÕßϵͳÖÐ £¬Ê¹¹¥»÷ÕßÄܹ»ÔËÐÐδ±»¼ì²âµ½µÄ´úÂë¡£Ëæºó £¬¶ñÒâÈí¼þÆô¶¯Ñ¬È¾Á´ £¬×îÖÕ²¿ÊðÓÉÁíÒ»¸öÒÁÀÊÍþвÐÐΪÕßCharming Kitten¿ª·¢µÄSnail Resin¶ñÒâÈí¼þ £¬²¢´ò¿ªÃûΪ¡°SlugResin¡±µÄºóÃÅ¡£TA455ʹÓöàÖÖÌӱܼì²âµÄÒªÁì £¬°üÂÞÔÚGitHubÉ϶ÔÃüÁîºÍ¿ØÖÆ£¨C2£©Í¨ÐŽøÐбàÂë £¬ÒÔ¼°Ä£·ÂLazarus GroupµÄ¼Æı £¬Ê¹µÃ¹éÒò±äµÃÅÓ´ó¡£ÓÉÓÚTA455Ö÷ÒªÕë¶Ôº½¿Õº½ÌìרҵÈËÊ¿ £¬Òò´Ë¸ÃÁìÓòµÄLinkedInµÈƽ̨Óû§Ó¦¾¯ÌèÀ´×Ôδ֪À´Ô´µÄÏûÏ¢ºÍÁªÏµ¡£


https://www.darkreading.com/cyberattacks-data-breaches/iranian-cybercriminals-aerospace-workers-linkedin


4. ÃÀ¹úÒ©·¿ÁªºÏ»á£¨AAP£©ÔâEmbargoÀÕË÷Èí¼þ¹¥»÷


11ÔÂ13ÈÕ £¬ÃÀ¹úÒ©·¿ÁªºÏ»á£¨AAP£©³ÉΪ×îÐÂÒ»¼ÒÊý¾ÝÔâµ½ÍøÂç·¸×ï·Ö×ÓÇÔÈ¡ºÍ¼ÓÃܵÄÃÀ¹úÒ½ÁƱ£½¡×éÖ¯¡£AAP½¨Á¢ÓÚ2009Äê £¬¹ÜÀí×ÅÈ«ÃÀ2000¶à¼Ò¶ÀÁ¢Ò©·¿¡£EmbargoÀÕË÷Èí¼þÐж¯µÄ·¸×ï·Ö×ÓÉù³Æ¶Ô´Ë´ÎÏ®»÷ÂôÁ¦ £¬ËûÃÇÇÔÈ¡ÁËAAPµÄ1.469TBÊý¾Ý²¢ÒªÇ󸶿î²ÅÆø»Ö¸´ÐÅÏ¢¡£EmbargoÊÇÒ»¸öÏà¶Ô½ÏеÄÀÕË÷Èí¼þ×éÖ¯ £¬ÓÚ½ñÄê6ÔÂÊ״α»Ñо¿ÈËÔ±×¢Òâµ½¡£¾¡¹ÜAAPÉÐδÕýʽȷÈÏÔâµ½¹¥»÷ £¬µ«ÆäÍøÕ¾ÒѾ¯¸æËùÓÐÓû§ÃÜÂë×î½ü¾ù±»Ç¿ÖÆÖØÖà £¬µ«Î´½âÊÍÔ­Òò»òÌá¼°ÍøÂç¹¥»÷¡£Í¬Ê± £¬EmbargoÉù³ÆAAPÒÑÖ§¸¶130ÍòÃÀÔªÀ´½âÃÜϵͳ £¬²¢ÒªÇóÔÙÖ§¸¶130ÍòÃÀÔªÀ´ÑڸDZ»µÁÎļþ¡£Èç¹û¸Ã˵·¨Êôʵ £¬ÄÇôEmbargoÌá³öµÄÒªÇó½«Áè¼ÝÃÀ¹úÁª°îÊÓ²ì¾Ö½ñÄêÔçЩʱºòÐû²¼µÄƽ¾ùˮƽ¡£Ä¿Ç°Éв»Çå³þÀÕË÷Èí¼þ×éÖ¯´ÓAAPÇÔÈ¡ÁËÄÄЩÊý¾Ý £¬µ«¸ÃÒ©·¿ÍøÂç±ØÐëÔÚ11ÔÂ20ÈÕ֮ǰ֧¸¶Ê£ÓàµÄ¡°Óà¶î¡± £¬·ñÔòÆäÊý¾Ý½«±»Ð¹Â¶µ½ÍøÉÏ¡£


https://www.theregister.com/2024/11/13/embargo_ransomware_breach_aap/


5. D-LinkÍ£²úNASÉ豸ÔâCVE-2024-10914©¶´¹¥»÷


11ÔÂ13ÈÕ £¬Äþ¾²Ñо¿Ô±Netsecfish·¢ÏÖÁËÒ»¸öÑÏÖØ©¶´£¨CVE-2024-10914£© £¬¸Ã©¶´Ó°Ïì¶àÖÖÒÑÍ£²úµÄD-LinkÍøÂ總¼Ó´æ´¢£¨NAS£©É豸¡£¹¥»÷Õß¿Éͨ¹ý·¢ËͶñÒâHTTP GETÇëÇó £¬ÏòÔÚÏß̻¶µÄÒ×Êܹ¥»÷É豸עÈëÈÎÒâshellÃüÁî¡£D-LinkÔÚÉÏÖÜÎåÌåÏÖ²»»áÐÞ¸´´Ë©¶´ £¬²¢½¨Òé¿Í»§ÌÔÌ­ÊÜÓ°ÏìµÄÉ豸»òÉý¼¶µ½½ÏеIJúÎȻ¶ø £¬ShadowserverÍþв¼à¿Ø·þÎñ·¢ÏÖ £¬´Ó11ÔÂ12ÈÕ¿ªÊ¼ £¬ÒÑÓÐÍþвÐÐΪÕß¿ªÊ¼Ãé×¼¸Ã©¶´¡£Shadowserver¾¯¸æ³Æ £¬Ó¦½«´Ó»¥ÁªÍøÉÏÒƳýÒ×Êܹ¥»÷µÄEOL/EOSÉ豸¡£NetsecfishÔÚ»¥ÁªÍøɨÃèÖз¢ÏÖÁËÁè¼Ý41,000¸öÒ×Êܹ¥»÷É豸µÄΨһIPµØÖ·¡£´ËÍâ £¬½ñÄê4Ô £¬Netsecfish»¹³ÂËßÁËÁíÒ»¸öÓ°Ï켸ºõÏàͬD-Link NASÐͺŵÄ©¶´£¨CVE-2024-3273£©¡£ÓÉÓÚÕâЩÉ豸ûÓÐ×Ô¶¯¸üй¦Ð§»ò¿Í»§ÍâÁª¹¦Ð§À´ÍÆË;¯±¨ £¬Òò´Ë½¨ÒéÄÇЩʹÓñ¨·ÏÉ豸µÄÈ˾¡¿ìÏÞÖÆ»¥ÁªÍø·ÃÎÊ £¬ÒÔÖÆÖ¹³ÉΪÀÕË÷Èí¼þ¹¥»÷µÄÄ¿±ê¡£D-LinkÇ¿µ÷ £¬¼ÌÐøʹÓÃÕâЩÉ豸¿ÉÄÜ»á¶ÔÁ¬½ÓµÄÉ豸Ôì³É·çÏÕ £¬²¢¾¯¸æÏû·ÑÕßÈ·±£É豸¾ßÓÐ×îеĹ̼þ¡£


https://www.bleepingcomputer.com/news/security/critical-bug-in-eol-d-link-nas-devices-now-exploited-in-attacks/


6. Ï£²©ÒÁ¸ùÊÐÔâÍøÂç¹¥»÷ £¬ºÚ¿ÍË÷ÒªÊê½ð²¢Ö¼¼Êõ¹ÊÕÏ


11ÔÂ13ÈÕ £¬Íþ˹¿µÐÇÖÝÏ£²©ÒÁ¸ùÊб¾ÖÜÔâÓöÁËÍøÂç¹¥»÷ £¬µ¼Ö¼¼Êõ¹ÊÕÏ £¬²¢ÊÕµ½Á˺ڿ͵ÄÊê½ðÒªÇó¡£×Ô10ÔÂÏÂÑ®ÒÔÀ´ £¬¸ÃÊÐÒ»Ö±ÔÚÓ¦¶ÔÕâЩÎÊÌâ £¬²¢ÔÚÖÜÈÕ֤ʵÁ˺ڿÍδ¾­ÊÚȨ·ÃÎÊÁ˸ÃÊеÄÍøÂç¡£¾¡¹Ü¸ÃÊÐûÓÐ͸¶Êê½ðÊý¶î»òÌá³öÒªÇóµÄ×éÖ¯Ãû³Æ £¬µ«ËûÃÇÒÑÏòÖ´·¨²¿ÃųÂËßÁË´Ëʼþ £¬²¢ÓëÍøÂçÄþ¾²×¨¼ÒºÏ×÷½â¾ö¹¥»÷ÒýÆðµÄÎÊÌ⡣ͬʱ £¬ËûÃǸôÀëÁ˲¿ÃÅÍøÂçÒÔ±£»¤ÆäËûÍøÂç²¢×èÖ¹ºÚ¿ÍÈëÇÖ¡£´Ë´Î¹¥»÷¶Ô¹«¹²Äþ¾²·þÎñÔì³ÉÁËÒ»¶¨Ó°Ïì £¬µ«»ùÓÚÔƵķþÎñÈÔÔÚÔËÐÐ £¬Ô±¹¤¿ÉÒÔ½øÐÐÔÚÏß½»Á÷¡£Ï£²©ÒÁ¸ùÊÐλÓÚÃܶûÎÖ»ùÒÔ±±Ô¼Ò»Ð¡Ê±³µ³Ì´¦ £¬¹ýÈ¥Á½ÄêÖÐ £¬Íþ˹¿µÐÇÖÝÕþ¸®»ú¹¹Ôø¶à´ÎÔâÊÜÀÕË÷Èí¼þ¹¥»÷ £¬Òò´Ë¸ÃÖݶԴËÀ๥»÷±£³Ö¸ß¶È¾¯Ìè¡£


https://therecord.media/sheboygan-wisconsin-hackers-demand-ransom