¶íÂÞ˹µç×Ó½»Ò×ƽ̨RoseltorgÔâÇ×ÎÚ¿ËÀ¼ºÚ¿Í×éÖ¯ÍøÂç¹¥»÷
Ðû²¼Ê±¼ä 2025-01-171. ¶íÂÞ˹µç×Ó½»Ò×ƽ̨RoseltorgÔâÇ×ÎÚ¿ËÀ¼ºÚ¿Í×éÖ¯ÍøÂç¹¥»÷
1ÔÂ14ÈÕ£¬¶íÂÞ˹Ö÷ÒªµÄÕþ¸®ºÍÆóÒµ²É¹ºµç×Ó½»Ò×ƽ̨RoseltorgÔÚÖÜһȷÈÏ£¬Æäƽ̨ÔâÓöÁËÍøÂç¹¥»÷£¬µ¼Ö·þÎñÔÝʱÖÐÖ¹¡£RoseltorgÊǶíÂÞ˹Õþ¸®Ñ¡¶¨µÄ×î´óµÄµç×Ó½»Ò×ÔËÓªÉÌÖ®Ò»£¬ÂôÁ¦¹«¹²²É¹º£¬°üÂÞ¹ú·ÀºÍ½¨ÖþÐÐÒµµÄºÏͬ£¬²¢Ìṩµç×ÓÎĵµ¹ÜÀíºÍ²É¹º¹æ»®¹¤¾ß¡£ºÚ¿Í×éÖ¯Yellow DriftÉù³Æ¶Ô´Ë´Î¹¥»÷ÂôÁ¦£¬Éù³Æɾ³ýÁË550TBµÄÊý¾Ý£¬°üÂÞµç×ÓÓʼþºÍ±¸·Ý£¬²¢Ðû²¼Á˾ݳƱ»ÈëÇֵĻù´¡ÉèÊ©µÄ½Øͼ¡£´Ë´Î¹¥»÷ÒѾӰÏìµ½ÒÀÀµRoseltorgÔËÓªµÄ¿Í»§£¬°üÂÞÕþ¸®»ú¹¹¡¢¹úÓÐÆóÒµºÍ¹©Ó¦ÉÌ£¬µ¼ÖÂDZÔڵIJÆÕþËðʧºÍ²É¹ºÁ÷³ÌµÄÑÓÎó¡£¾¡¹ÜRoseltorgÌåÏÖËùÓÐÊý¾ÝºÍ»ù´¡ÉèÊ©ÒÑÍêÈ«»Ö¸´£¬½»Ò×ϵͳԤ¼Æ½«ºÜ¿ì»Ö¸´ÔËÐУ¬µ«½ØÖÁÏà¹Ø±¨µÀ׫дʱ£¬ÆäÍøÕ¾ÈÔ´¦ÓÚÀëÏß״̬¡£RoseltorgÊDZ¾ÔÂÔâµ½Ç×ÎÚ¿ËÀ¼ºÚ¿Í¹¥»÷µÄ¼¸¼Ò¶íÂÞ˹¹«Ë¾Ö®Ò»£¬ÆäËû¹«Ë¾Èç¶íÂÞ˹Õþ¸®»ú¹¹RosreestrºÍ»¥ÁªÍøÌṩÉÌNodexÒ²Ôâµ½ÁËÀàËƵĹ¥»÷¡£´ËÍ⣬һ¸öÃûΪCyber Anarchy SquadµÄÎÚ¿ËÀ¼ºÚ¿Í×éÖ¯»¹Ðû²¼¹¥»÷Á˶íÂÞ˹¿Æ¼¼¹«Ë¾Infobis£¬Éù³ÆÇÔÈ¡ÁË3TBµÄÐÅÏ¢²¢ÆÆ»µÁ˸ù«Ë¾µÄ²¿ÃÅ»ù´¡ÉèÊ©¡£
https://therecord.media/russian-platform-for-state-procurement-hit-cyberattack
2. Avery ProductsÔâºÚ¿Í¹¥»÷£¬6Íò¿Í»§Êý¾Ýй¶
1ÔÂ15ÈÕ£¬°¬Àû²úÎ﹫˾£¨Avery Products Corporation£©£¬Ò»¼ÒרעÓÚ²»¸É½º±êÇ©¡¢·þ×°Æ·ÅÆÔªËؼ°Ó¡Ë¢·þÎñµÄÃÀ¹úÆóÒµ£¬½üÆÚ¾¯¸æ³ÆÆäÍøÕ¾avery.comÔâÓöÁ˺ڿ͹¥»÷£¬µ¼Ö¿ͻ§ÐÅÓÿ¨ºÍ¸öÈËÐÅϢй¶¡£2024Äê12ÔÂ9ÈÕ£¬¹«Ë¾·¢ÏÖÕâÒ»¹¥»÷£¬¾ÄÚ²¿Êý×Öȡ֤ר¼ÒÊÓ²ìÈ·ÈÏ£¬¹¥»÷ÕßÔçÔÚͬÄê7ÔÂ18ÈÕ¾ÍÔÚÆäÔÚÏßÉ̵êÖ²ÈëÁË¿¨Æ¬µÁË¢Æ÷£¬ÖÂʹ7ÔÂ18ÈÕÖÁ12ÔÂ9ÈÕÆÚ¼äÔÚÍøÕ¾ÉÏÊäÈëµÄÖ§¸¶ÐÅÏ¢±»ÇÔÈ¡¡£Ð¹Â¶ÐÅÏ¢°üÂÞÐÕÃû¡¢µØÖ·¡¢µç×ÓÓʼþ¡¢µç»°ºÅÂë¡¢Ö§¸¶¿¨ºÅ¡¢CVVÂë¡¢ÓÐЧÆÚ¼°¹ºÖýð¶îµÈ£¬ËäδÉæ¼°Éç»áÄþ¾²ºÅ¡¢¼ÝÕպš¢Éí·ÝÖ¤ºÅ¼°³öÉúÈÕÆÚµÈÃô¸ÐÐÅÏ¢£¬µ«ÒÑ×ã¹»½øÐÐÆÛÕ©½»Òס£AveryÌåÏÖ£¬ËäÎÞ·¨È·ÈÏÆÛÕ©ÊÕ·ÑÓë´Ë´ÎʼþÖ±½ÓÏà¹Ø£¬µ«Òѽӵ½¿Í»§ÔâÊÜÆÛÕ©ÐÔÊշѺÍÍøÂçµöÓãÓʼþµÄ³ÂËß¡£´Ë´ÎʼþÓ°ÏìÁË61,193Ãû¿Í»§£¬AveryΪ´ËÌṩ12¸öÔÂÃâ·ÑÐÅÓüà¿Ø·þÎñ£¬²¢½¨ÒéÊÕ¼þÈ˾¯Ìèδ¾ÇëÇóµÄͨÐÅ£¬¼°Ê±³ÂËß¿ÉÒɻ¡£Í¬Ê±£¬¹«Ë¾ÉèÁ¢ÁË×ÊÖúÈÈÏߣ¬ÒÔ½â´ð¿Í»§¶Ô´ËʼþµÄÒÉÎʺ͵£ÓÇ¡£
https://www.bleepingcomputer.com/news/security/label-giant-avery-says-website-hacked-to-steal-credit-cards/
3. MikroTik½©Ê¬ÍøÂçÀûÓÃSPFÅäÖôíÎóÁ÷´«¶ñÒâÈí¼þ
1ÔÂ15ÈÕ£¬Ò»¸öÓÉÔ¼13,000̨MikroTikÉ豸×é³ÉµÄ½©Ê¬ÍøÂç±»·¢ÏÖÀûÓÃÓòÃû·þÎñÆ÷¼Ç¼ÖеĴíÎóÅäÖÃÀ´Èƹýµç×ÓÓʼþ±£»¤£¬²¢ÆÛÆԼĪ20,000¸öÍøÂçÓòÁ÷´«¶ñÒâÈí¼þ¡£¸Ã¶ñÒâ»î¶¯ÓÚ2024Äê11ÔÂÏÂÑ®¿ªÊ¼»îÔ¾£¬ÍþвÐÐΪÕßͨ¹ýαÔìDHL ExpressµÄÔËÊ乫˾Éí·Ý£¬·¢ËÍ´øÓжñÒâJavaScriptÎļþµÄZIP¸½¼þ£¬¸ÃÎļþÄÜ»ã±àºÍÔËÐÐPowerShell½Å±¾£¬½ø¶øÓëλÓÚ֮ǰÓë¶íÂÞ˹ºÚ¿ÍÏà¹ØµÄÓòÖеÄÃüÁîºÍ¿ØÖÆ·þÎñÆ÷½¨Á¢Á¬½Ó¡£DNSÄþ¾²¹«Ë¾InfobloxÖ¸³ö£¬ÕâЩ¶ñÒâÓʼþÏÔʾ³ö´óÁ¿ÓòÃûºÍSMTP·þÎñÆ÷IPµØÖ·£¬½ÒʾÁËÒ»¸öÅÓ´óµÄ½©Ê¬ÍøÂç¡£Ô¼20,000¸öÓòµÄSPF DNS¼Ç¼ÅäÖùýÓÚ¿íËÉ£¬Ê¹ÓÃÁË¡°+all¡±Ñ¡ÏÔÊÐíÈκηþÎñÆ÷´ú±íÕâЩÓò·¢Ë͵ç×ÓÓʼþ£¬ÕâΪÆÛƺÍδ¾ÊÚȨµÄµç×ÓÓʼþ·¢ËÍÌṩÁË»ú»á¡£MikroTikÉ豸ÒòÆ书Чǿ´ó¶ø³ÉΪĿ±ê£¬¾¡¹ÜÈ¥ÄêÏÄÌìÒѶشÙÉ豸ËùÓÐÕ߸üÐÂϵͳ£¬µ«²¹¶¡Ðû²¼»ºÂý£¬Ðí¶à·ÓÉÆ÷ÈÔ´æÔÚ©¶´¡£¸Ã½©Ê¬ÍøÂ罫É豸ÅäÖÃΪSOCKS4ÊðÀí£¬ÓÃÓÚÌᳫDDoS¹¥»÷¡¢·¢ËÍÍøÂçµöÓãÓʼþ¡¢ÇÔÈ¡Êý¾Ý£¬²¢ÑڸǶñÒâÁ÷Á¿À´Ô´¡£
https://www.bleepingcomputer.com/news/security/mikrotik-botnet-uses-misconfigured-spf-dns-records-to-spread-malware/
4. ºÚ¿ÍÀûÓùȸèËÑË÷¹ã¸æÍƹãµöÓãÍøÕ¾ÇÔÈ¡¹ã¸æÉÌƾ֤
1ÔÂ15ÈÕ£¬ÍøÂç·¸×ï·Ö×ÓÈç½ñ¾¹ÀûÓùȸèËÑË÷¹ã¸æÍƹãµöÓãÍøÕ¾£¬ÆóͼÇÔÈ¡¹ã¸æÉ̵Ĺȸè¹ã¸æƽ̨ƾ֤£¬ÕâÒ»ÐÐΪ¼«¾ß¼¥Ð¦Òâζ¡£ËûÃÇͨ¹ýÔÚGoogleËÑË÷ÉÏͶ·Åð³äGoogle¹ã¸æµÄ¹ã¸æ£¬ÏÔʾΪÔÞÖú½á¹û£¬ÓÕµ¼Ç±ÔÚÊܺ¦Õß½øÈë¿´Ëƹٷ½µÄÐé¼ÙµÇ¼ҳÃ棬½ø¶øÆÈ¡ÕË»§ÐÅÏ¢¡£ÕâЩµöÓãÒ³ÃæÍйÜÔÚGoogle SitesÉÏ£¬ÆäURLÓëGoogle AdsµÄ¸ùÓòÏàÆ¥Å䣬ʹµÃαװԽ·¢´«Éñ£¬ÇáÒ×ÈƹýÁËÖ¼ÔÚ·ÀÖ¹ÀÄÓúÍð³äµÄ¹æÔò¡£¾ÝÊܺ¦ÕßÃèÊö£¬¹¥»÷Á÷³Ì°üÂÞÊäÈëÕË»§ÐÅÏ¢¡¢ÊÕ¼¯±êʶ·ûºÍƾ֤¡¢ÊÕµ½Òì³£µÇ¼ËùÔÚÌáʾÒÔ¼°ÕË»§±»Ð¹ÜÀíÔ±½Ó¹ÜµÈ½×¶Î¡£ÖÁÉÙÓÐÈý¸öÍøÂç·¸×ïÍÅ»ïÉæ¼°´ËÀ๥»÷£¬ËûÃÇ×îÖÕÄ¿µÄÊÇÔÚºÚ¿ÍÂÛ̳ÉϳöÊÛ±»µÁÕË»§²¢·¢¶¯¸ü¶à¹¥»÷¡£Malwarebytes LabsÖ¸³ö£¬ÕâÊÇËûÃÇ×·×Ùµ½µÄ×î¶ñÁӵĶñÒâ¹ã¸æÐж¯Ö®Ò»£¬¿ÉÄÜÓ°ÏìÈ«ÇòÊýǧÃû¿Í»§¡£¶ø¹È¸èÔòÌåÏÖÃ÷È·½ûÖ¹´ËÀàÆÛÆÐÔ¹ã¸æ£¬²¢ÕýÔÚ»ý¼«ÊӲ첢½ÓÄÉÐж¯¡£
https://www.bleepingcomputer.com/news/security/hackers-use-google-search-ads-to-steal-google-ads-accounts/
5. Wolf Haldenstein ÔâÊý¾Ýй¶£¬½ü350ÍòÈËÐÅÏ¢ÊÜÓ°Ïì
1ÔÂ16ÈÕ£¬Wolf Haldenstein Adler Freeman & Herz LLP£¨Wolf Haldenstein£©£¬Ò»¼Ò½¨Á¢ÓÚ1888Äê²¢ÔÚÃÀ¹ú¶àµØÉèÓзþÎñ´¦µÄÖªÃûÂÉʦÊÂÎñËù£¬ÓÚ2023Äê12ÔÂ13ÈÕÔâÓöÁËÊý¾Ýй¶Ê¼þ¡£ºÚ¿ÍÇÔÈ¡Á˽ü344ÍòÈ˵ĸöÈËÐÅÏ¢£¬°üÂÞÐÕÃû¡¢Éç»áÄþ¾²ºÅÂë¡¢Ô±¹¤Ê¶±ðºÅ¡¢Ò½ÁÆÕï¶Ï¼°Ë÷ÅâÐÅÏ¢µÈÃô¸ÐÊý¾Ý¡£ÓÉÓÚÊý¾Ý·ÖÎöºÍÊý×ÖÈ¡Ö¤µÄÅÓ´óÐÔ£¬¸ÃʼþµÄÊÓ²ì½ø¶ÈÑÏÖØÖͺó£¬Ö±µ½2024Äê12ÔÂ3ÈÕ²Å×îÖÕÈ·¶¨ÁËÊÜÓ°ÏìÈËÊý¡£È»¶ø£¬ÓÉÓÚÎÞ·¨ÕÒµ½²¿ÃÅÊÜÓ°ÏìÈËÔ±µÄÁªÏµÐÅÏ¢£¬Wolf HaldensteinÉÐδÏòËùÓÐÈË·¢ËÍ֪ͨ¡£¾¡¹ÜûÓÐÖ¤¾Ý±íÃ÷Êý¾ÝÒѱ»ÀÄÓ㬵«Ð¹Â¶µÄÐÅÏ¢¿ÉÄÜʹÊÜÓ°Ïì¸öÈËÃæÁÙÍøÂçµöÓ㡢թƵȷçÏÕÔö¼Ó¡£¸Ã¹«Ë¾ÒѶԴ洢ÔÚ·þÎñÆ÷ÉϵÄÊý¾Ý½øÐÐÁËÏêϸÉó²é£¬²¢Îª¿ÉÄÜÊÜÓ°ÏìµÄ¸öÈËÌṩÔö²¹ÐÅÓüà¿Ø±£ÕÏ¡£Í¬Ê±£¬Wolf HaldensteinÃãÀø¸öÈ˱£³Ö¾¯Ì裬ÉèÖÃÆÛÕ©¾¯±¨»òÄþ¾²¶³½á¡£Ä¿Ç°£¬Éв»Çå³þ鶵ÄÊý¾ÝÊÇÊôÓÚ¿Í»§¡¢Ô±¹¤»¹ÊÇÆäËû´æ´¢ÔÚÆä·þÎñÆ÷ÉϵĸöÈË¡£Èç¹ûÄúÓëWolf HaldensteinÓÐÒµÎñÍùÀ´£¬½¨ÒéÁªÏµËûÃÇÁ˽â´Ëʼþ¶ÔÄúµÄÓ°Ïì¡£
https://www.bleepingcomputer.com/news/security/wolf-haldenstein-law-firm-says-35-million-impacted-by-data-breach/
6. W3 Total Cache²å¼þ´æÑÏÖØ©¶´£¬ÊýÊ®ÍòWordPressÍøÕ¾ÃæÁÙ·çÏÕ
1ÔÂ16ÈÕ£¬W3 Total Cache²å¼þÊÇÒ»¿î¹ã·ºÓ¦ÓÃÓÚWordPressÍøÕ¾µÄ¼ÓËÙ¹¤¾ß£¬½üÆÚ±»·¢ÏÖ´æÔÚÒ»¸ö±àºÅΪCVE-2024-12365µÄÑÏÖØÄþ¾²Â©¶´¡£¸Ã©¶´¿ÉÄܵ¼Ö¹¥»÷ÕßÇáÒ×·ÃÎÊÃô¸ÐÐÅÏ¢£¬°üÂÞÔÆÓ¦ÓÃÔªÊý¾Ý£¬¶ÔÍøÕ¾Äþ¾²×é³ÉÖØ´óÍþв¡£¾¡¹Ü¿ª·¢ÈËÔ±ÒÑÔÚ×îа汾2.8.2ÖÐÐÞ¸´ÁË´ËÎÊÌ⣬µ«ÈÔÓÐÊýÊ®ÍòÍøÕ¾ÉÐδ¸üУ¬ÈÔ´¦ÓÚ·çÏÕÖ®ÖС£WordfenceÖ¸³ö£¬Â©¶´Ô´Óھɰ汾ÖС°is_w3tc_admin_page¡±º¯ÊýµÄ¹¦Ð§¼ì²éȱʧ£¬Ê¹µÃ¹¥»÷ÕßÄÜÔڵͼ¶±ðÉí·ÝÑéÖ¤ºóÖ´ÐÐδÊÚȨ²Ù×÷¡£´Ë©¶´µÄ·çÏÕ°üÂÞ·þÎñÆ÷¶ËÇëÇóαÔì¡¢ÐÅÏ¢Åû¶ºÍ·þÎñÀÄÓ㬿ÉÄܵ¼ÖÂÃô¸ÐÊý¾Ýй¶¡¢ÍøÕ¾ÐÔÄÜϽµ¼°³É±¾Ôö¼Ó¡£ÊÜÓ°ÏìÓû§Ó¦¾¡¿ìÉý¼¶ÖÁW3 Total Cache 2.8.2°æ±¾ÒÔÏû³ýÒþ»¼¡£Í¬Ê±£¬ÍøÕ¾ËùÓÐÕßÓ¦½÷É÷°²×°²å¼þ£¬ÖÆÖ¹²»ÐëÒªµÄ²úÎ²¢¿¼ÂÇʹÓÃWebÓ¦Ó÷¨Ê½·À»ðǽÀ´Ê¶±ðºÍ×èÖ¹¹¥»÷ʵÑ飬ÒÔ½øÒ»²½ÌáÉýÍøÕ¾Äþ¾²ÐÔ¡£
https://www.bleepingcomputer.com/news/security/w3-total-cache-plugin-flaw-exposes-1-million-wordpress-sites-to-attacks/