ZDIÅû¶Microsoft ExchangeÖÐ4¸öЩ¶´µÄϸ½Ú

Ðû²¼Ê±¼ä 2023-11-07

1¡¢ZDIÅû¶Microsoft ExchangeÖÐ4¸öЩ¶´µÄϸ½Ú


 ¾ÝýÌå11ÔÂ3ÈÕ±¨µÀ£¬Trend Micro ZDIÅû¶ÁËMicrosoft ExchangeÖеÄ4¸ö©¶´ ¡£¾­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔÔ¶³ÌÀûÓÃÕâЩ©¶´À´Ö´ÐÐÈÎÒâ´úÂë»òÇÔÈ¡Ãô¸ÐÐÅÏ¢ ¡£ÕâЩ©¶´·Ö±ðÊÇChainedSerializationBinderÀàÖеÄRCE©¶´¡¢DownloadDataFromUriÖеÄÐÅϢй¶©¶´¡¢DownloadDataFromOfficeMarketPlaceÖеÄÐÅϢй¶©¶´ºÍCreateAttachmentFromUriÖеÄÐÅϢй¶©¶´ ¡£ZDIÓÚ9ÔÂ7ÈÕÖÁ8ÈÕÏò΢Èí³ÂËßÁËÕâЩ©¶´£¬Î¢ÈíÈÏ¿ÉÁËÕâЩ©¶´£¬µ«ÒòΪÆäÄþ¾²¹¤³ÌʦÈÏΪ»¹²»¹»ÑÏÖØ£¬ÉÐδ½øÐÐÐÞ¸´ ¡£


https://securityaffairs.com/153599/hacking/microsoft-exchange-zero-day-flaws.html


2¡¢ÃÀ¹úAce HardwareÔâµ½¹¥»÷1202̨¼ÆËã»úÊܵ½Ó°Ïì


 ¾Ý11ÔÂ2ÈÕ±¨µÀ£¬ÃÀ¹úÎå½ðÁ¬ËøµêAce HardwareÔâµ½¹¥»÷£¬ÈÕ³£µÄÔËÓª»î¶¯Êܵ½Ó°Ïì ¡£¸Ã¹«Ë¾ÓÚ10ÔÂ29ÈÕ¼ì²âµ½´Ë´Î¹¥»÷£¬ACENET¡¢Warehouse Management SystemsºÍARMAµÈϵͳÖжÏ£¬µ¼ÖÂÎÞ·¨½»»õ»ò϶©µ¥ ¡£Ace HardwareµÄCEO³Æ£¬¸Ã¹«Ë¾ÔËÓª×Å1400̨·þÎñÆ÷ºÍ3500Ì¨ÍøÂçÉ豸£¬ÆäÖÐ1202̨Êܵ½Ó°Ïì¼±Ðè»Ö¸´ ¡£½ØÖÁ11ÔÂ2ÈÕÔçÉÏ5µã31·Ö£¬ÕâЩ·þÎñÆ÷µÄ51%ÒѾ­»Ö¸´ ¡£


https://www.bleepingcomputer.com/news/security/ace-hardware-says-1-202-devices-were-hit-during-cyberattack/


3¡¢ÃÀ¹úº½¿ÕµÄ·ÉÐÐÔ±¹¤»áAPAÔâµ½ÀÕË÷¹¥»÷ϵͳÈÔÔÚ»Ö¸´ÖÐ


11ÔÂ4ÈÕ±¨µÀ³Æ£¬ÃÀ¹úº½¿Õ·ÉÐÐÔ±¹¤»áAllied Pilots Association(APA)Ôâµ½ÀÕË÷¹¥»÷ ¡£APA¹¤»á½¨Á¢ÓÚ1963Ä꣬ÊÇĿǰÊÀ½çÉÏ×î´óµÄ¶ÀÁ¢·ÉÐÐÔ±¹¤»á ¡£¹¥»÷·¢ÉúÓÚ10ÔÂ30ÈÕ£¬²¿ÃÅϵͳ±»¼ÓÃÜ ¡£APAÌåÏÖ£¬ÆäITÍŶÓÕýÔÚŬÁ¦Í¨¹ý±¸·ÝÀ´»Ö¸´ÊÜÀÕË÷¹¥»÷Ó°ÏìµÄϵͳ£¬×î³õµÄÖØµãÊÇÔÚδÀ´¼¸Ð¡Ê±ºÍ¼¸ÌìÄÚÊ×ÏȻָ´ÃæÏò·ÉÐÐÔ±µÄ²úÎïºÍ¹¤¾ß ¡£APAÉÐδ͸¶ÊÇ·ñÓзÉÐÐÔ±µÄ¸öÈËÐÅϢй¶£¬Ò²Ã»ÓÐ͸¶ÊÜÓ°ÏìµÄ¾ßÌåÈËÊý ¡£


https://therecord.media/american-airlines-pilot-union-cyberattack


4¡¢ÐÂ¼ÓÆÂ¶à¼Ò¹«¹²Ò½ÁÆ»ú¹¹µÄÍøÕ¾ÒòDDoS¹¥»÷ÖжÏÊýСʱ


ýÌå11ÔÂ3ÈÕ±¨µÀ£¬ÐÂ¼ÓÆÂ¶à¼Ò¹«¹²Ò½ÁÆ»ú¹¹µÄÍøÕ¾ÒòDDoS¹¥»÷Öжϳ¤´ï7¸öСʱ ¡£¹ú¼ÒÎÀÉú¼¼ÊõÌṩÉÌSynapxeΪ46¼Ò¹«¹²Ò½ÁÆ»ú¹¹ºÍÔ¼1400¸öÉçÇøºÏ×÷»ï°éµÄÔËÓªÌṩ֧³Ö ¡£Synapxe¶©ÔÄÁËһЩ·þÎñ£¬ÔÚÍøÂçÁ÷Á¿Òì³£¼¤Ôöǰ¶ÔÆä½øÐÐÀ¹½Ø£¬È»¶ø11ÔÂ1ÈÕµÄDDoS¹¥»÷Á÷Á¿ÈƹýÁËÀ¹½Ø·þÎñ ¡£Òò´Ë£¬SynapxeµÄ·À»ðǽÔÚÊÔͼ¹ýÂËÁ÷Á¿Ê±²»¿°Öظº£¬µ¼ÖÂËùÓÐÍøÕ¾ºÍÒÀÀµÍøÂçµÄ·þÎñ¶¼ÎÞ·¨·ÃÎÊ ¡£SynapxeÁ¢¼´½ÓÄÉ´ëÊ©£¬·þÎñ´Óµ±ÈÕÏÂÎç4µã30·ÖÆðÖð²½»Ö¸´ ¡£SynapxeÌåÏÖ£¬DDoS¹¥»÷ÈÔÔÚ¼ÌÐø£¬Òò´Ë·þÎñ¿ÉÄܻῶûÖжÏ ¡£


https://www.todayonline.com/singapore/cyberattack-caused-7-hour-internet-outage-hit-public-hospitals-polyclinics-attacks-continuing-synapxe-2297036


5¡¢°²´óÂÔÊ¡5¼ÒÒ½ÔºÔâµ½ÀÕË÷¹¥»÷560Íò»¼ÕßÐÅϢй¶


ýÌå11ÔÂ6ÈÕ±¨µÀ³Æ£¬°²´óÂÔÊ¡Î÷Äϲ¿5¼ÒÒ½ÔºÔâµ½µÄÀÕË÷¹¥»÷£¬Ó°ÏìÁË560Íò»¼ÕßÐÅÏ¢ ¡£10ÔÂ23ÈÕ£¬Ò½ÔºµÄITºÍн×ʹÜÀí»ú¹¹TransFormÔâµ½¹¥»÷£¬µ¼ÖÂWindsor Regional HospitalµÈ5¼ÒÒ½ÔºµÄϵͳÖжÏ ¡£ÊÓ²ìÈ·¶¨£¬Ð¹Â¶ÐÅÏ¢°üÂÞBluewater HealthµÄ560ÍòÌõ¾ÍÕïÐÅÏ¢ºÍChatham-Kent Health AllianceµÄ1446ÃûÔ±¹¤µÄÐÅÏ¢µÈ ¡£Ò½ÔººÍTransForm¶¼²»Ô¸Òâ½»Êê½ð£¬½ØÖÁĿǰ£¬¹¥»÷ÕßÒѾ­¹ûÈ»ÁËÈýÂÖ±»µÁÐÅÏ¢ ¡£


https://www.cbc.ca/news/canada/windsor/ransomware-attack-third-bunch-data-hospital-1.7019701


6¡¢Ñо¿ÈËÔ±ÑÝʾÈçºÎÀûÓÃApple¡°Find My¡±ÇÔÈ¡ÐÅÏ¢


 11ÔÂ4ÈÕ±¨µÀ£¬Ñо¿ÈËÔ±ÑÝʾÁËÈçºÎÀûÓÃAppleÉ豸µÄ¡°Find My¡±À´ÇÔÈ¡¼üÅ̼ǼµÄÃÜÂë ¡£ÔçÔÚÁ½Äêǰ£¬¾ÍÓÐÑо¿ÍŶÓÔø·¢ÏÖ¿ÉÀûÓá°Find My¡±À´´«Êä³ýÉ豸λÖÃÖ®ÍâµÄÊý¾Ý£¬²¢³ÆÎª¡°Send My¡± ¡£´Ë´Î£¬Ñо¿ÈËÔ±½«´øÓÐESP32À¶ÑÀ·¢ÉäÆ÷µÄ¼üÅ̼Ǽ·¨Ê½¼¯³Éµ½USB¼üÅÌÖУ¬ÒÔÖ¤Ã÷¿ÉÒÔͨ¹ýÀ¶ÑÀ½«¼üÅÌÉÏÊäÈëµÄÃÜÂëºÍÆäËüÃô¸ÐÊý¾Ý´«Ë͵½Find MyµÄÍøÂç ¡£À¶ÑÀ´«ÊäÒª±ÈWLAN¼üÅ̼Ǽ·¨Ê½»òRaspberry PiÉ豸Òþ±ÎµÃ¶à£¬Ëü¿ÉÒÔÃØÃܵØÀûÓÃÎÞ´¦²»ÔÚµÄAppleÉ豸½øÐÐÖмÌ ¡£


https://www.bleepingcomputer.com/news/apple/apple-find-my-network-can-be-abused-to-steal-keylogged-passwords/