ÄÜÔ´ÐÐÒµ³Ð°üÉÌENGlobalÔâÀÕË÷Èí¼þ¹¥»÷ £¬ITϵͳ·ÃÎÊÊÜÏÞ

Ðû²¼Ê±¼ä 2024-12-04

1. ÄÜÔ´ÐÐÒµ³Ð°üÉÌENGlobalÔâÀÕË÷Èí¼þ¹¥»÷ £¬ITϵͳ·ÃÎÊÊÜÏÞ


12ÔÂ3ÈÕ £¬ENGlobal CorporationÊÇÒ»¼ÒÔÚÄÜÔ´ÐÐÒµÉè¼ÆºÍ½¨Ôì×Ô¶¯¿ØÖÆϵͳµÄÖ÷Òª³Ð°üÉÌ £¬½üÈÕ֤ʵÆäÕýÃæÁÙÀÕË÷Èí¼þ¹¥»÷ £¬¸Ã¹¥»÷×è°­ÁËÆäÕý³£ÔËÓª¡£¸Ã¹«Ë¾ÓÚ11ÔÂ25ÈÕ·¢ÏÖÕâÒ»¹¥»÷ £¬²¢ËæºóÏòÃÀ¹ú֤ȯ½»Ò×ίԱ»áÌá½»ÁËÏà¹Ø³ÂËß¡£¾Ý³Æ £¬Ò»¸öÍþвÐÐΪÕß·Ç·¨·ÃÎÊÁ˹«Ë¾µÄÐÅÏ¢¼¼Êõϵͳ £¬²¢¼ÓÃÜÁ˲¿ÃÅÊý¾ÝÎļþ £¬µ¼ÖÂENGlobalÏÞÖÆÁËÔ±¹¤¶ÔITϵͳµÄ·ÃÎÊ £¬½öÏÞÓÚÐëÒªµÄÒµÎñÔËÓª¡£Ä¿Ç° £¬¹«Ë¾ÕýÔÚ½ÓÄɶàÏî´ëÊ©½â¾öÎÊÌâ £¬°üÂÞÆô¶¯ÄÚ²¿ÊÓ²ìºÍƸÇëÍⲿÍøÂçÄþ¾²×¨¼Ò £¬µ«È«Ãæ»Ö¸´ITϵͳ·ÃÎÊȨÏÞµÄʱ¼äÉв»Çå³þ £¬ÇÒÉÐÎÞ·¨È·¶¨ÕâһʼþÊÇ·ñ»á¶Ô¹«Ë¾²ÆÕþÒµ¼¨·¢ÉúÖØ´óÓ°Ïì¡£ÖµµÃ×¢ÒâµÄÊÇ £¬ENGlobalÔø³ÂËßÉϸö¼¾¶ÈÊÕÈë½Ó½ü600ÍòÃÀÔª £¬½ñÄêÇ°¾Å¸öÔÂÊÕÈëΪ1840ÍòÃÀÔª £¬ÇҸù«Ë¾×¨ÃÅΪÃÀ¹ú¹ú·À¹¤ÒµÌṩ½»Ô¿³××Ô¶¯»¯ºÍÒDZíϵͳ¡£ÀàËÆÉæ¼°ENGlobalºÍ֮ǰ½­É­×ԿصÄÀÕË÷Èí¼þ¹¥»÷¿ÉÄÜ»áй¶ÃÀ¹úÕþ¸®ÉèÊ©µÄÃô¸ÐÎļþ¡¢ºÏͬºÍ¼Æ»® £¬Òý·¢¹úÍÁÄþ¾²²¿¹ÙÔ±µÄ¾¯Ìè¡£


https://therecord.media/energy-industry-contractor-ransomware-disruption


2. µ¤Âó×î´óÍøÂçÌṩÉÌTDC NetÈí¼þ¸üÐÂÒý·¢´ó¹æÄ£µçÐÅÖжÏ


11ÔÂ28ÈÕ £¬µ¤Âó×î´óµÄÍøÂçÌṩÉÌTDC NetÔÚ11ÔÂ27ÈÕÔâÓö´ó¹æÄ£µçÐÅÖжÏ £¬Ô­Òò¹é¾ÌÓÚÆäʵʩµÄÈí¼þ¸üС£´Ë´ÎÖжϵ¼ÖÂÊýǧÃû¿Í»§ÎÞ·¨²¦´òµç»° £¬°üÂÞ½ô¼±·þÎñµç»°112 £¬¸ø¿Í»§´øÀ´¼«´óδ±ã¡£¾ÝABCÐÂÎű¨µÀ £¬TDC Net²»ÈÏΪ´Ë´ÎÖжÏÊÇÓÉÍøÂç¹¥»÷ÒýÆðµÄ¡£´Ë´Îʼþ»¹µ¼ÖÂÖÁÉÙÒ»¼ÒÒ½Ôº±»ÆȼõÉÙ·ÇÒªº¦Ò½ÁÆ·þÎñ £¬Äþ¾²²¿ÃÅÒ²ÔÚ½ÖÉÏѲÂßÒÔÑ°ÕÒÐèÒª×ÊÖúµÄÈË¡£TDC NetÒѽÓÄÉ´ëÊ©ÐÞ¸´ÎÊÌâ £¬ÔÊÐí¿Í»§²¦´òµç»° £¬µ«ÉùÒôÖÊÁ¿ÓÐËùϽµ¡£ÔËÓªÉ̽¨Òé¿Í»§ÔÚ²¦´ò112֮ǰÏÈÈ¡³öSIM¿¨¡£TDC NetÌṩÒƶ¯¡¢¹âÏ˺ÍÍ­Ïß·þÎñ £¬ÓÉTDC GroupÓÚ2019Ä꽨Á¢ £¬ÆäÀúÊ·¿ÉÒÔ×·Ëݵ½1879Äê £¬ÆäʱÑÇÀúɽ´ó¡¤¸ñÀ׶òÄ·¡¤±´¶ûµÄ±´¶ûµç»°¹«Ë¾ÔÚµ¤Âó¿ªÉèÁË·Ö¹«Ë¾ £¬1881ÄêÔڸ籾¹þ¸ù¿ªÉèÁ˵ÚÒ»¼Òµç»°½»»»»ú¡£


https://www.datacenterdynamics.com/en/news/danish-telco-tdc-net-suffers-telecoms-outage-impacts-emergency-calls/


3. ˹ÍÐÀû¼¯ÍÅÔÚÔâÊÜÀÕË÷Èí¼þ¹¥»÷ºóÔÚÃÀ¹úÉêÇëÆƲú


12ÔÂ3ÈÕ £¬Ë¹ÍÐÀû¼¯ÍÅÃÀ¹ú¹«Ë¾½üÆÚÉêÇëÁËÆƲú £¬ÕâÒ»¾ö¶¨ÊÇÔÚ¾­ÀúÁËһϵÁÐÖØ´ó¹¥»÷Ö®ºó×ö³öµÄ¡£8Ô·Ý £¬¸Ã¼¯ÍÅÔâÊÜÁËÀÕË÷Èí¼þ¹¥»÷ £¬µ¼ÖÂÆäITϵͳ £¬°üÂÞÆóÒµ×ÊÔ´¹æ»®Æ½Ì¨ £¬ÔâÊÜÑÏÖØÆÆ»µ £¬ÆÈʹÕû¸ö¼¯ÍÅתΪÊÖ¶¯²Ù×÷ £¬Ó°ÏìÁË°üÂÞ»á¼ÆÔÚÄÚµÄÒªº¦Á÷³Ì £¬Ô¤¼ÆÒªµ½2025Äê³õ²ÅÆøÈ«Ãæ»Ö¸´¡£Õâһʼþ»¹µ¼ÖÂ˹ÍÐÀûÃÀ¹ú×Ó¹«Ë¾ÎÞ·¨Ïò´û·½Ìṩ²ÆÕþ³ÂËß £¬±»´û·½Ö¸¿ØÍÏÇ·ÁË7800ÍòÃÀÔªµÄÕ®Îñ¡£¶øÔÚ7Ô·Ý £¬Ë¹ÍÐÀû¼¯ÍÅÔÚ¶íÂÞ˹µÄÁ½¼ÒÄð¾Æ³§±»Ã»ÊÕ £¬Ô­ÒòÊǸü¯Íż°ÆäÊ×´´ÈËÓÈÀл·òÀÕ±»Ö¸¶¨Îª¡°¼«¶Ë·Ö×Ó¡± £¬ÕâÓëËûÃÇÔÚÎÚ¿ËÀ¼Õ½ÕùÆÚ¼äΪÎÚ¿ËÀ¼ÄÑÃñ¿ªÕ¹µÄÈ˵ÀÖ÷ÒåÔ®ÖúÊÂÇéºÍÏà¹ØÓªÏú»î¶¯ÓйØ¡£´ËÍâ £¬Ë¹ÍÐÀû¼¯ÍÅ»¹Óë¶íÂÞ˹¹úÓÐÆóÒµ¾Í·üÌؼÓÉ̱êȨչ¿ªÁ˳¤´ï23ÄêµÄ·¨Í¥¶·Õù £¬ºÄ×ÊÊýǧÍòÃÀÔª¡£¹«Ë¾Ê×´´ÈËл·òÀÕÒ²ÒòÅúÆÀÆÕ¾©ÕþȨ¶ø±»ÆÈÌÓÀë¶íÂÞ˹ £¬²¢ÔÚÈðÊ¿»ñµÃ±Ó»¤ºÍÓ¢¹ú¹«ÃñÉí·Ý¡£ÕâЩʼþÅäºÏµ¼ÖÂÁË˹ÍÐÀû¼¯ÍÅÃÀ¹ú¹«Ë¾µÄÆƲúÉêÇë¡£


https://www.bleepingcomputer.com/news/security/vodka-maker-stoli-files-for-bankruptcy-in-us-after-ransomware-attack/


4. CloudflareÓòÃûÔâÀÄÓãºÍøÂçµöÓãÓë¶ñÒâ»î¶¯¼¤Ôö


12ÔÂ3ÈÕ £¬CloudflareµÄ¡°pages.dev¡±ºÍ¡°workers.dev¡±ÓòÃûÒòÆäÆ·ÅÆÐÅÓþ¡¢·þÎñ¿É¿¿ÐԺ͵ÍʹÓóɱ¾ £¬ÕýÔ½À´Ô½¶àµØ±»ÍøÂç·¸×ï·Ö×ÓÀÄÓÃÓÚÍøÂçµöÓãºÍÆäËû¶ñÒâ»î¶¯¡£¾ÝÍøÂçÄþ¾²¹«Ë¾Fortra³ÂËß £¬Óë2023ÄêÏà±È £¬ÕâЩÓòÃûµÄÀÄÓÃÂÊÉÏÉýÁË100%ÖÁ250%¡£Cloudflare Pages×÷Ϊǰ¶Ë¿ª·¢ÈËԱƽ̨ £¬±»ÓÃÓÚÍйÜÖмäÍøÂçµöÓãÒ³Ãæ £¬½«Êܺ¦ÕßÖض¨Ïòµ½¶ñÒâÍøÕ¾ £¬Èç¼ÙðµÄMicrosoft Office365µÇ¼ҳÃæ¡£FortraÖ¸³ö £¬Õë¶ÔCloudflare PagesµÄÍøÂçµöÓã¹¥»÷Ôö¼ÓÁË198% £¬Ô¤¼Æµ½Äêµ×¹¥»÷×ÜÊý½«Áè¼Ý1600Æð¡£Í¬Ê± £¬Cloudflare WorkersÎÞ·þÎñÆ÷¼ÆËãƽ̨Ҳ±»ÀÄÓà £¬°üÂÞ½øÐÐDDoS¹¥»÷¡¢²¿ÊðÍøÂçµöÓãÍøÕ¾¡¢×¢ÈëÓк¦½Å±¾ºÍ±©Á¦ÆƽâÃÜÂëµÈ¡£Fortra³ÂËß³Æ £¬Õë¶ÔCloudflare WorkersµÄÍøÂçµöÓã¹¥»÷¼¤Ôö104% £¬Ô¤¼Æµ½Äêµ××ÜÊý½«µ½´ï½ü6000Æð¡£Óû§Ó¦ÑéÖ¤URLµÄÕæʵÐÔ²¢¼¤»îË«ÒòËØÉí·ÝÑéÖ¤µÈÄþ¾²´ëÊ© £¬ÒÔ·À·¶ÕâЩÀÄÓÃÐÐΪ¡£


https://www.bleepingcomputer.com/news/security/cloudflares-developer-domains-increasingly-abused-by-threat-actors/


5. WhatsUp GoldÑÏÖØÔ¶³Ì´úÂëÖ´ÐЩ¶´ £¬¼±Ðè¸üÐÂÄþ¾²²¹¶¡


12ÔÂ3ÈÕ £¬Progress WhatsUp Gold±»·¢ÏÖ´æÔÚÒ»¸ö±àºÅΪCVE-2024-8785µÄÑÏÖØÔ¶³Ì´úÂëÖ´ÐЩ¶´ £¬¸Ã©¶´ÓÉTenableÔÚ2024Äê8ÔÂÖÐÑ®·¢ÏÖ £¬CVSS v3.1ÆÀ·Ö¸ß´ï9.8¡£Â©¶´´æÔÚÓÚNmAPI.exe½ø³ÌÖÐ £¬ÓÉÓÚ´«ÈëÊý¾ÝÑéÖ¤²»×ã £¬¹¥»÷Õß¿É·¢ËÍÌØÖÆÇëÇóÐ޸ĻòÁýÕÖWindows×¢²á±íÏî £¬½ø¶ø¿ØÖÆWhatsUp GoldµÄÅäÖÃÎļþ¶ÁȡλÖ᣹¥»÷Õß¿Éͨ¹ýnetTcpBindingµ÷ÓÃUpdateFailoverRegistryValues²Ù×÷ £¬¸ü¸Ä×¢²á±íÖµ»ò´´½¨ÐÂÖµ £¬Ê¹·þÎñÖØÆôʱ´ÓÔ¶³Ì¹²Ïí¶ÁÈ¡ÅäÖÃÎļþ £¬Ö´ÐÐÈÎÒâÔ¶³Ì¿ÉÖ´ÐÐÎļþ¡£¸Ã©¶´ÎÞÐèÉí·ÝÑéÖ¤ £¬ÇÒNmAPI.exe·þÎñ¿Éͨ¹ýÍøÂç·ÃÎÊ £¬·çÏÕ¼«´ó¡£Progress SoftwareÓÚ9ÔÂ24ÈÕÐû²¼ÁË°üÂÞÐÞ¸´´Ë©¶´ÔÚÄÚµÄÄþ¾²¸üР£¬½¨Òéϵͳ¹ÜÀíÔ±¾¡¿ìÉý¼¶µ½°æ±¾24.0.1¡£½üÆÚ £¬WhatsUp GoldÒѶà´Î³ÉΪºÚ¿Í¹¥»÷Ä¿±ê £¬ÀûÓùûȻ©¶´»ñÈ¡¿ª¶Ë·ÃÎÊȨÏÞ»ò½Ó¹Ü¹ÜÀíÔ±ÕÊ»§ £¬Òò´Ë¼°Ê±Ó¦ÓÃÄþ¾²¸üÐÂÖÁ¹ØÖØÒª¡£


https://www.bleepingcomputer.com/news/security/exploit-released-for-critical-whatsup-gold-rce-flaw-patch-now/


6. µÂÖ´·¨²¿Ãŵ·»ÙCrimenetworkÍøÂç·¸×ïÊг¡ £¬´þ²¶¹ÜÀíÔ±


12ÔÂ3ÈÕ £¬µÂ¹úÖ´·¨²¿Ãŵ·»ÙÁ˵ÂÓïµØÓò×î´óµÄÍøÂç·¸×ïÊг¡Crimenetwork £¬²¢´þ²¶ÁËÆä¹ÜÀíÔ± £¬×ïÃûÊÇЭÖú··Âô¶¾Æ·¡¢ÇÔÈ¡Êý¾ÝºÍÌṩ·Ç·¨·þÎñ¡£¸ÃÊг¡½¨Á¢ÓÚ2012Äê £¬¹Ø±ÕʱӵÓÐÁè¼Ý100Ãû×¢²áÂô¼ÒºÍ10ÍòÓû§ £¬ÆäÖдó¶àÊýλÓÚµÂÓï¹ú¼Ò¡£Óû§¿ÉÒÔʹÓñÈÌرһòÄÑÒÔ×·×ٵļÓÃÜ»õ±ÒÃÅÂÞ±ÒÖ§¸¶ÉÌÆ·ºÍ·þÎñ £¬½»Ò×Á¿¾Þ´ó £¬Æ½Ì¨´ÓÖÐ׬ȡÌá³É¡¢Ô¶©ÔķѺ͹ã¸æÊÕÈë¡£±»²¶µÄ¹ÜÀíÔ±ÊÇÒ»Ãû29ËêµÄÏÓÒÉÈË £¬ÃæÁÙ¶àÏîÖ¸¿Ø¡£´ËÍâ £¬µÂ¹úÖ´·¨²¿ÃÅ»¹¾¯¸æ³Æ £¬ÒÑ»ñµÃÓйظÃÍøÂç·¸×ïƽ̨ע²á»áÔ±µÄÐÅÏ¢ £¬Î´À´¿ÉÄÜ»á´þ²¶¸ü¶àÏÓÒÉÈË¡£´Ë´ÎÐж¯Êǵ¹ú½üÆÚ·´ÍøÂç·¸×ïÐж¯µÄÒ»²¿ÃÅ £¬»¹Éæ¼°ÆäËûÖøÃû°¸¼þ £¬Èç²é·âDstat.cc DDoSÉó²éƽ̨ºÍ²é»ñ47¼Ò¼ÓÃÜ»õ±Ò½»Ò×·þÎñ»ú¹¹¡£


https://www.bleepingcomputer.com/news/security/police-seizes-largest-german-online-crime-marketplace-arrests-admin/