¡°Ñ¬È¾ÐԲɷᱻÖÐOtterCookieÐÂÐͶñÒâÈí¼þÍþвÈí¼þ¿ª·¢ÈËÔ±

Ðû²¼Ê±¼ä 2024-12-27

1. ¡°Ñ¬È¾ÐԲɷᱻÖÐOtterCookieÐÂÐͶñÒâÈí¼þÍþвÈí¼þ¿ª·¢ÈËÔ±


12ÔÂ26ÈÕ£¬³¯ÏÊÍþвÐÐΪÕß½üÆÚÔÚÕë¶ÔÈí¼þ¿ª·¢ÈËÔ±µÄ¡°Ñ¬È¾ÐԲɷᱻÖУ¬ÍƳöÁËÒ»ÖÖÃûΪOtterCookieµÄÐÂÐͶñÒâÈí¼þ¡£¾ÝÍøÂçÄþ¾²¹«Ë¾Palo Alto NetworksµÄÑо¿ÈËÔ±³Æ£¬¸Ã»î¶¯×Ô2022Äê12ÔÂÒÔÀ´Ò»Ö±»îÔ¾£¬Í¨¹ýÌṩÐé¼ÙµÄÊÂÇé»ú»áÁ÷´«¶ñÒâÈí¼þ£¬ÈçBeaverTailºÍInvisibleFerretµÈ¡£¶øNTT Security JapanµÄ³ÂËßÖ¸³ö£¬OtterCookieºÜ¿ÉÄÜÓÚ9ÔÂÍƳö£¬²¢ÔÚ11Ô·ºÆðÁËеıäÖÖ¡£¸Ã¶ñÒâÈí¼þͨ¹ý¼ÓÔØÆ÷ͨ±¨£¬»ñÈ¡JSONÊý¾Ý²¢Ö´ÐÐJavaScript´úÂ룬¿ÉÒÔÓëBeaverTailÒ»Æð²¿Êð»òµ¥¶À²¿Êð¡£ËüÀûÓÃGitHub»òBitbucketÏÂÔصÄNode.jsÏîÄ¿»ònpm°üѬȾĿ±ê£¬Ò²Ê¹ÓÃÁËQt»òElectronÓ¦Ó÷¨Ê½¹¹½¨µÄÎļþ¡£Ò»µ©¼¤»î£¬OtterCookie¾Í»áʹÓÃSocket.IO WebSocket¹¤¾ßÓëÃüÁîºÍ¿ØÖÆ»ù´¡ÉèÊ©½¨Á¢Äþ¾²Í¨ÐÅ£¬²¢Ö´ÐÐÊý¾Ý͵ÇÔµÄshellÃüÁ°üÂÞÊÕ¼¯¼ÓÃÜ»õ±ÒÇ®°üÃÜÔ¿¡¢Îĵµ¡¢Í¼ÏñµÈÓмÛÖµÐÅÏ¢¡£×îа汾µÄOtterCookie»¹¿ÉÒÔй¶¼ôÌù°åÊý¾Ý£¬²¢¼ì²âµ½ÓÃÓÚÕì²ìµÄÃüÁ±íÃ÷¹¥»÷Õ߼ƻ®½øÐиüÉîÌõÀíµÄÉø͸»òºáÏòÒƶ¯¡£


https://www.bleepingcomputer.com/news/security/new-ottercookie-malware-used-to-backdoor-devs-in-fake-job-offers/


2. ÈÕº½ÔâDDoS¹¥»÷Öº½°àÑÓÎó£¬ÏµÍ³Òѻָ´


12ÔÂ26ÈÕ£¬ÈÕ±¾Æì½¢º½¿Õ¹«Ë¾ÈÕ±¾º½¿Õ(JAL)ÔâÓöÁËÒ»´ÎÍøÂçÄþ¾²Ê¼þ£¬µ¼ÖÂÆ䲿ÃŹúÄں͹ú¼Êº½°à·ºÆðÑÓÎó¡£Ê¼þÆðÒòÊÇÆäÓÃÓÚÓëÍⲿϵͳ½øÐÐÊý¾ÝͨÐŵÄÍøÂçÉ豸ÔâÊÜÁËÂþÑÜʽ¾Ü¾ø·þÎñ(DDoS)¹¥»÷£¬µ¼ÖÂϵÍÂä÷Á¿¼¤Ôö²¢·ºÆð¹ÊÕÏ¡£¹¥»÷»¹Ó°ÏìÁË´î¿ÍÐÐÀî¹ÜÀíϵͳºÍÒƶ¯Ó¦Ó÷¨Ê½£¬µ«ÈÕº½ÌåÏÖûÓпͻ§ÐÅϢй¶¡¢¼ÆËã»ú²¡¶¾Ë𺦻ò·ÉÐÐÄþ¾²ÎÊÌâ¡£ÊÜÓ°ÏìµÄϵͳÒÑÔÝʱ¹Ø±Õ£¬²¢ÔÝÍ£Á˵±ÈÕ³ö·¢µÄ»úƱÏúÊۺͲ¿ÃÅÔÚÏß·þÎñ¡£¾¡¹ÜÓÐ40¶à¸öº½°àÑÓÎ󣬵«ÈÕº½ÌåÏÖµÚ¶þÌìµÄº½°à¼Æ»®Õý³£ÔËÐС£º½¿ÕÒµÈÔÊÇÈ«ÇòºÚ¿ÍµÄÈÈÃÅÄ¿±ê£¬´ËÇ°Ò²Ôø·¢Éú¶àÆðÕë¶Ôº½¿Õ¹«Ë¾ºÍ»ú³¡µÄÍøÂç¹¥»÷ʼþ£¬ÕâЩϮ»÷´ó¶à³öÓÚ¾­¼Ã¶¯»ú£¬µ«Ò²ÓÐÕþÖζ¯»úµÄ°¸Àý¡£


https://therecord.media/japan-airlines-resumes-operations-after-cyberattack


3. °ÍÎ÷ºÚ¿ÍÒòÉæÏÓÇÃÕ©ÀÕË÷ÔÚÃÀ¹úÔâÖ¸¿Ø


12ÔÂ26ÈÕ£¬Ò»Ãû°ÍÎ÷¹«ÃñJunior Barros De OliveiraÒòÉæÏÓºÚ¿ÍÈëÇÖ²¢ÇÃÕ©ÀÕË÷Ò»¼ÒλÓÚÐÂÔóÎ÷µÄ¹«Ë¾¶ø±»ÃÀ¹ú˾·¨²¿ÆðËß¡£¾ÝÆðËßÊéÏÔʾ£¬µÂ°ÂÀûάÀ­ÓÚ2020Äê3ÔÂÈëÇÖÁ˸ù«Ë¾µÄ°ÍÎ÷×Ó¹«Ë¾ÍøÂ磬ÇÔÈ¡ÁËÔ¼30ÍòÃû¿Í»§µÄ»úÃÜÐÅÏ¢¡£Í¬Äê9Ô£¬ËûʹÓû¯ÃûÏò¸Ã¹«Ë¾Ê×ϯִÐйٷ¢Ë͵ç×ÓÓʼþ£¬ÒªÇóÖ§¸¶300±ÈÌرң¨Æäʱ¼ÛÖµÔ¼320ÍòÃÀÔª£©×÷Ϊ²»³öÊÛÊý¾ÝµÄÌõ¼þ¡£Ò»¸öÔºó£¬ËûÓÖ½«ÏàͬµÄÐÅϢת·¢¸øÁ˸ù«Ë¾ÔÚ°ÍÎ÷µÄÊ×ϯִÐйٺÍÒ»Ãû¸ß¹Ü£¬²¢ÌåÏÖÔ¸ÒâÒÔ75±ÈÌرң¨ÆäʱԼºÏ80ÍòÃÀÔª£©µÄ×Éѯ·Ñ×ÊÖúËûÃǽâ¾öÄþ¾²Â©¶´¡£µÂ°ÂÀûάÀ­Òò´Ë±»Ö¸¿ØËÄÏîÉæ¼°´ÓÊܱ £»¤µÄ¼ÆËã»ú»ñÈ¡ÐÅÏ¢µÄÇÃÕ©ÀÕË÷×ïºÍËÄÏîÍþвÐÔͨÐÅ×ï¡£Èç¹û×ïÃû½¨Á¢£¬Ëû½«ÃæÁÙ×î¸ß¿É´ï20ÄêµÄ¼à½ûºÍ¸ß´ï100ÍòÃÀÔªµÄ·£¿î£¬»òÊÕÒæÓëËðʧ¼ÛÖµµÄÁ½±¶£¨ÒԽϸßÕßΪ׼£©¡£


https://thehackernews.com/2024/12/brazilian-hacker-charged-for-extorting.html


4. ͨÓö¯Á¦¹«Ë¾ÔâÍøÂçµöÓã¹¥»÷£¬ÊýʮԱ¹¤¸£ÀûÕË»§±»ÈëÇÖ


12ÔÂ26ÈÕ£¬º½¿Õº½ÌìºÍ¹ú·À¾ÞͷͨÓö¯Á¦¹«Ë¾ÔâÓöÁËÒ»´ÎÀֳɵÄÍøÂçµöÓã¹¥»÷£¬µ¼ÖÂÊýÊ®¸öÔ±¹¤¸£ÀûÕË»§±»ÈëÇÖ¡£¹¥»÷Õßͨ¹ýµÚÈý·½ÍйܵĵǼÃÅ»§·ÃÎʲ¢¸ü¸ÄÁËÔ±¹¤¸£ÀûÕË»§£¬ÕâЩÕË»§°üÂÞÁËÔ±¹¤µÄÐÕÃû¡¢³öÉúÈÕÆÚ¡¢Õþ¸®·¢±íµÄÉí·ÝÖ¤ºÅÂë¡¢Éç»áÄþ¾²ºÅÂë¡¢ÒøÐÐÕË»§ÐÅÏ¢ºÍ²Ð¼²×´¿öµÈÃô¸ÐÐÅÏ¢¡£¾ÝͨÓö¯Á¦¹«Ë¾Í¸Â¶£¬¹²ÓÐ37ÈËÊܵ½Ó°Ï죬¹¥»÷ÕßÔÚijЩÇé¿öÏ»¹¸ü¸ÄÁ˱»µÁÕË»§µÄÒøÐÐÕË»§ÐÅÏ¢¡£Í¨Óö¯Á¦¹«Ë¾ÔÚ·¢ÏÖÕâһδ¾­ÊÚȨµÄ»î¶¯ºóÁ¢¼´ÔÝÍ£Á˶Ը÷þÎñµÄ·ÃÎÊ£¬²¢ÏòÊÜÓ°ÏìµÄÈËÔ±ÌṩÁËÁ½ÄêµÄÃâ·ÑÐÅÓüà¿Ø¡£´ËÍ⣬ͨÓö¯Á¦¹«Ë¾»¹ÌáÐÑÊÜÓ°ÏìµÄ¸öÈËÖØÖÃËûÃǵĸ»´ïÕË»§µÇ¼ƾ֤£¬²¢ÖÆÖ¹ÔÚ¶à¸öÕË»§ÖÐʹÓÃÏàͬµÄƾ֤¡£½ñÄêÔçЩʱºò£¬¸»´ï¹«Ë¾Ò²ÔøÔâÓö¹ýÁ½´ÎÊý¾Ýй¶Ê¼þ£¬Ó°ÏìÁËÊýÍò¸öÈË¡£


https://www.securityweek.com/defense-giant-general-dynamics-says-employees-targeted-in-phishing-attack/


5. WDACÔâÀûÓ㬹¥»÷Õ߿ɽûÓÃEDR´«¸ÐÆ÷·¢¶¯¹¥»÷


12ÔÂ25ÈÕ£¬Äþ¾²×¨¼Ò·¢ÏÖÁËÒ»ÖÖÀûÓÃWindows DefenderÓ¦Ó÷¨Ê½¿ØÖÆ£¨WDAC£©µÄ¹¥»÷¼¼Êõ£¬¿ÉÒÔ½ûÓÃWindowsÉè±¹ØÁ¬Ä¶Ëµã¼ì²âºÍÏìÓ¦£¨EDR£©´«¸ÐÆ÷£¬Ê¹¹¥»÷ÕßÄܹ»ÈƹýÄþ¾²¼ì²â²¢¶Ôϵͳ·¢¶¯¹¥»÷¡£WDACÊÇWindows 10ºÍWindows Server 2016ÒýÈëµÄ¼¼Êõ£¬Ö¼ÔÚ¿ØÖÆWindowsÉè±¹ØÁ¬Ä¿ÉÖ´ÐдúÂë¡£¹¥»÷Õß¿ÉÒÔÖƶ¨ºÍ²¿ÊðרÃÅÉè¼ÆµÄWDAC¼Æı£¬×èÖ¹EDR´«¸ÐÆ÷ÔÚϵͳÆô¶¯Ê±¼ÓÔØ£¬Ê¹ÆäÎÞ·¨ÊÂÇé¡£¹¥»÷·½Ê½°üÂÞÕë¶Ôµ¥¸öÉ豸ºÍÕû¸öÓò£¬ÓµÓÐÓò¹ÜÀíԱȨÏ޵Ĺ¥»÷Õß¿ÉÒÔÔÚÕû¸ö×éÖ¯ÄÚ·Ö·¢¶ñÒâWDAC¼Æı£¬ÏµÍ³ÐԵؽûÓÃËùÓж˵ãÉϵÄEDR´«¸ÐÆ÷¡£¹¥»÷Éæ¼°¼Æı·ÅÖá¢ÖØÆôÖն˺ͽûÓÃEDRÈý¸öÖ÷Òª½×¶Î¡£Äþ¾²ÈËÔ±´´½¨ÁË¡°Krueger¡±¿´·¨ÑéÖ¤¹¤¾ßÀ´¼ì²âÕâÖÖ¹¥»÷¡ £»º½â¼Æı°üÂÞͨ¹ýGPOÖ´ÐÐWDAC¼Æı¡¢Ó¦ÓÃ×îСȨÏÞÔ­ÔòºÍʵʩÄþ¾²µÄ¹ÜÀíʵ¼ù¡£Ãæ¶ÔзºÆðµÄ¹¥»÷¼¼Êõ£¬ÐèÒª½ÓÄɶàÌõÀíµÄÍøÂçÄþ¾²ÒªÁ죬²¢Ê±¿Ì±£³Ö¾¯Ìè¡£


https://cybersecuritynews.com/attack-weaponizes-windows-defender/#google_vignette


6. ΢Èí¾¯¸æ£ºÊ¹ÓÃýÌå°²×°Windows 11 24H2¿ÉÖÂÎÞ·¨½ÓÊÕÄþ¾²¸üÐÂ


12ÔÂ26ÈÕ£¬Î¢Èí·¢³ö¾¯¸æ£¬Ö¸³öʹÓÃýÌåÖ§³Ö°²×°Windows 11°æ±¾24H2ʱ´æÔÚÒ»¸öÎÊÌ⣬¿ÉÄܵ¼Ö²Ù×÷ϵͳÎÞ·¨½ÓÊܽøÒ»²½µÄÄþ¾²¸üС£¾ßÌå¶øÑÔ£¬ÔÚ2024Äê10ÔÂ8ÈÕÖÁ11ÔÂ12ÈÕÆڼ䣬ʹÓÃCDºÍUSBÉÁ´æÇý¶¯Æ÷°²×°°üÂÞ´ËÆÚ¼äÄþ¾²¸üеÄWindows 11°æ±¾24H2ʱ£¬É豸¿ÉÄÜ»áÏÝÈëÎÞ·¨½ÓÊܺóÐøWindowsÄþ¾²¸üеÄ״̬¡£²»Í⣬Õâ¸ö©¶´²»»áÓ°Ïìͨ¹ýWindows¸üлòMicrosoft¸üÐÂĿ¼ÍøÕ¾Ó¦ÓõÄÄþ¾²¸üУ¬Ò²²»»áÔÚʹÓÃ×îеÄ2024Äê12ÔÂÄþ¾²¸üÐÂʱ·ºÆð¡£Î¢ÈíÕýÔÚÖÂÁ¦ÓÚÓÀ¾ÃÐÞ¸´´ËÎÊÌ⣬²¢½¨ÒéʹÓûùÓÚýÌåµÄWindows 11 24H2°²×°µÄÓû§Ó¦ÓÃ2024Äê12ÔÂ10ÈÕÐû²¼µÄÄþ¾²¸üУ¬ÒÔÖÆÖ¹ºóÐø¸üÐÂÎÊÌâ¡£´ËÍ⣬Windows 11 24H2»¹ÃæÁÙ×ÅһϵÁÐÆäËûÎÊÌ⣬°üÂÞÒôƵÎÊÌâ¡¢ÓÎÏ·ÐÔÄÜÎÊÌâ¡¢Íß½âºÍËÀ»úµÈ£¬ÉõÖÁÔÚÌض¨µÄÓ²¼þºÍÈí¼þÅäÖÃÉϱ»ÔÝʱ×èÖ¹¡£


https://www.bleepingcomputer.com/news/security/windows-11-installation-media-bug-causes-security-update-failures/