Òâ´óÀûÆóÒµÊܵ½ÎäÆ÷»¯µÄ USB Á÷´«¼ÓÃܽٳֶñÒâÈí¼þµÄ¹¥»÷

Ðû²¼Ê±¼ä 2024-02-02
1. Òâ´óÀûÆóÒµÊܵ½ÎäÆ÷»¯µÄ USB Á÷´«¼ÓÃܽٳֶñÒâÈí¼þµÄ¹¥»÷


1ÔÂ31ÈÕ £¬Ò»¸öÃûΪUNC4990µÄ³öÓÚ¾­¼Ã¶¯»úµÄÍþвÐÐΪÕßÕýÔÚÀûÓÃÎäÆ÷»¯ USB É豸×÷Ϊ³õʼѬȾý½é £¬ÒÔÒâ´óÀûµÄ×é֯ΪĿ±ê¡£UNC4990 ²Ù×÷ͨ³£Éæ¼°¹ã·ºµÄ USB ѬȾ £¬È»ºó²¿Êð EMPTYSPACE ÏÂÔØ·¨Ê½¡£ÔÚÕâЩ²Ù×÷¹ý³ÌÖÐ £¬¼¯ÈºÒÀÀµ GitHub¡¢Vimeo ºÍ Ars Technica Æ·¼¶Èý·½ÍøÕ¾À´ÍйܱàÂëµÄ¸½¼Ó½×¶Î £¬²¢ÔÚÖ´ÐÐÁ´µÄÔçÆÚͨ¹ý PowerShell ÏÂÔØºÍ½âÂë¡£UNC4990 ×Ô 2020 Äêµ×¿ªÊ¼»îÔ¾ £¬Æ¾¾ÝÒâ´óÀû»ù´¡ÉèÊ©¹ã·ºÓÃÓÚÖ¸»ÓÓë¿ØÖÆ (C2) Ä¿µÄ £¬¾ÝÆÀ¹ÀÔÚÒâ´óÀû¾³ÍâÔËÓª¡£Ä¿Ç°Éв»Çå³þ UNC4990 ÊÇ·ñ½ö³äµ±ÆäËû¼ÓÈëÕߵijõʼ·ÃÎÊ´Ù½øÕß¡£ÍþвÐÐΪÕßµÄ×îÖÕÄ¿±êÒ²²»Çå³þ £¬¾¡¹ÜÔÚÒ»¸öÀý×ÓÖÐ £¬¾Ý˵ÔÚ¾­¹ýÊýÔµÄÐűê»î¶¯ºó²¿ÊðÁË¿ªÔ´¼ÓÃÜ»õ±ÒÍÚ¿ó·¨Ê½¡£


https://thehackernews.com/2024/01/italian-businesses-hit-by-weaponized.html?&web_view=true


2. CISA ¾¯¸æ iOS¡¢iPadOS ºÍ macOS ÖеÄÑÏÖØÂ©¶´±»Ö÷¶¯ÀûÓÃ


2ÔÂ1ÈÕ £¬ÃÀ¹úÍøÂçÄþ¾²ºÍ»ù´¡ÉèÊ©Äþ¾²¾Ö (CISA)ƾ¾Ý»îÔ¾ÀûÓõÄÖ¤¾Ý £¬½«Ó°Ïì iOS¡¢iPadOS¡¢macOS¡¢tvOS ºÍ watchOS µÄ¸ßÑÏÖØÐÔȱÏÝÌí¼Óµ½ÆäÒÑÖª¿ÉÀûÓé¶´ ( KEV ) Ŀ¼ÖС£¸Ã©¶´±àºÅΪCVE-2022-48618£¨CVSS ÆÀ·Ö£º7.8£© £¬Éæ¼°ÄÚºË×é¼þÖеĴíÎ󡣯»¹ûÔÚÒ»·Ýͨ¸æÖÐÌåÏÖ £¬ ¡°¾ßÓÐÈÎÒâ¶ÁдÄÜÁ¦µÄ¹¥»÷Õß¿ÉÄÜÄܹ»ÈƹýÖ¸ÕëÉí·ÝÑéÖ¤¡± £¬²¢Ôö²¹Ëµ¸ÃÎÊÌâ¡°¿ÉÄÜÒѱ»Õë¶Ô iOS 15.7.1 ֮ǰÐû²¼µÄ iOS °æ±¾ËùÀûÓᱡ£Õâ¼Ò iPhone ÖÆÔìÉÌÌåÏÖ £¬¸ÃÎÊÌâÒÑͨ¹ý¸ïмì²éµÃµ½½â¾ö¡£Ä¿Ç°Éв»Çå³þ¸Ã©¶´ÈçºÎÔÚÏÖʵÊÀ½çµÄ¹¥»÷Öб»ÎäÆ÷»¯¡£ÓÐȤµÄÊÇ £¬¸Ã©¶´µÄ²¹¶¡ÓÚ 2022 Äê 12 Ô 13 ÈÕËæiOS 16.2¡¢iPadOS 16.2¡¢macOS Ventura 13.1¡¢tvOS 16.2ºÍwatchOS 9.2µÄÐû²¼¶øÐû²¼ £¬¾¡¹ÜÒ»Äê¶àºóµÄ 2024 Äê 1 Ô 9 ÈղŹûÈ»Åû¶¡£ÖµµÃ×¢ÒâµÄÊÇ £¬Æ»¹ûȷʵÔÚ 2022 Äê 7 Ô 20 ÈÕÐû²¼µÄ iOS 15.6 ºÍ iPadOS 15.6 Öнâ¾öÁËÄÚºËÖеÄÀàËÆÈ±ÏÝ£¨ CVE-2022-32844 £¬CVSS ÆÀ·Ö£º6.3£©¡£


https://thehackernews.com/2024/02/cisa-warns-of-active-exploitation-of.html


3. ¿¨°Í˹»ù2024ÄêÔ¤²â£ºÀÕË÷Èí¼þºáÐÐ


2ÔÂ1ÈÕ £¬¿¨°Í˹»ùÐû²¼Á˹¤Òµ¿ØÖÆÏµÍ³ÍøÂçÓ¦¼±ÏìӦС×é (ICS CERT) 2024 ÄêµÄÔ¤²â £¬¸ÅÊöÁ˹¤ÒµÆóÒµÔÚδÀ´Ò»ÄêÃæÁÙµÄÖ÷ÒªÍøÂçÄþ¾²ÌôÕ½¡£ÕâЩԤ²âÇ¿µ÷ÁËÀÕË÷Èí¼þÍþвµÄÁ¬Ðø´æÔÚ¡¢ÊÀ½çÕþÖκڿÍÐж¯Ö÷ÒåµÄÐËÆð¡¢¶Ô¡°½ø¹¥ÐÔÍøÂçÄþ¾²¡±×´¿öµÄÕ¹Íû £¬ÒÔ¼°ÎïÁ÷ºÍÔËÊäÍþвµÄÀå¸ïÐÔת±ä¡£»Ø¹Ë 2023 Äê £¬¿¨°Í˹»ùÔ¤²â¹¤ÒµÍøÂçÄþ¾²¸ñʽ½«¼ÌÐøÉú³¤ £¬²¢·ºÆð¼¸¸öÒªº¦Ç÷ÊÆ¡£IIoT ºÍ SmartXXX ϵͳ¶ÔЧÂʵÄ×·ÇóÍÆ¶¯Á˹¥»÷ÃæµÄÀ©´ó £¬¶øÄÜÔ´ÔËÓªÉ̼۸ñµÄì­Éýµ¼ÖÂÓ²¼þ³É±¾ÉÏÉý £¬´ÙʹսÂÔתÏòÔÆ·þÎñ¡£Õþ¸®¶Ô¹¤ÒµÁ÷³ÌµÄÔ½À´Ô½¶àµÄ¼ÓÈëÒ²´øÀ´ÁËеķçÏÕ £¬°üÂÞÓÉÓÚÔ±ÈËΪ¸ñ²»×ãºÍÂôÁ¦ÈεÄÅû¶ʵ¼ù²»×ã¶øµ¼ÖÂÊý¾Ýй¶µÄµ£ÓÇ¡£2024 Ä깤ҵÆóÒµÃæÁÙµÄÍøÂçÄþ¾²ÐÎÊÆ°üÂÞ£ºÕë¶Ô¸ß¼ÛֵʵÌåµÄÀÕË÷Èí¼þ¡¢ÊÀ½çÕþÖο¹ÒéºÚ¿ÍÐж¯Ö÷ÒåºÍ¸ü΢ÃîµÄÍþвºÍ¼ì²âÌôÕ½µÈ¡£


https://www.darkreading.com/vulnerabilities-threats/kasperskys-ics-cert-predictions-for-2024-ransomware-rampage-cosmopolitical-hacktivism-and-beyond


4. Europcar·ñÈÏ5000ÍòÓû§Êý¾Ýй¶ £¬³ÆÊý¾ÝÊǼٵÄ


1ÔÂ31ÈÕ £¬Æû³µ×âÁÞ¹«Ë¾ Europcar ÌåÏÖ £¬ÔÚÍþвÐÐΪÕßÉù³Æ³öÊÛ 5000 Íò¿Í»§µÄ¸öÈËÐÅÏ¢ºó £¬¸Ã¹«Ë¾²¢Î´ÔâÊÜÊý¾Ýй¶ £¬¶øÇÒ¹²ÏíµÄ¿Í»§Êý¾ÝÊÇαÔìµÄ¡£ÓÐÈËÉù³ÆÔÚÒ»¸öÁ÷ÐеĺڿÍÂÛ̳ÉϳöÊÛ 48,606,700 Europcar.com ¿Í»§µÄÊý¾Ý¡£¸ÃÌû×Ó°üÂÞ 31 Ãû Europcar ¿Í»§µÄ±»µÁÊý¾ÝÑù±¾ £¬°üÂÞÐÕÃû¡¢µØÖ·¡¢³öÉúÈÕÆÚ¡¢¼ÝʻִÕÕºÅÂëºÍÆäËûÐÅÏ¢¡£Europcar ¸æËß BleepingComputer ËûÃÇÏàÐÅÕâЩÊý¾ÝÊÇʹÓÃÈ˹¤ÖÇÄÜ´´½¨µÄ £¬µ« Hunt Ö¸³ö £¬Ò»Ð©µç×ÓÓʼþµØÖ·ÊÇÕæÊµµÄ £¬·ºÆðÔÚ Have I Been Pwned ¼à¿ØµÄ֮ǰµÄÊý¾Ýй¶Ê¼þÖС£ÕýÈçÄþ¾²Ñо¿ÈËÔ±NexusFuzzyÖ¸³öµÄÄÇÑù £¬ ÏÖÓеÄÏîÄ¿ ÔÊÐíÈκÎÈË´´½¨¿´ÆðÀ´¼¸ºõÓëÐé¼ÙÊý¾Ýй¶Ñù±¾Öй²ÏíµÄÊý¾ÝһģһÑùµÄÊý¾Ý¡£ËäÈ» ÍþвÐÐΪÕßÒѾ­Ê¹ÓÃÈ˹¤ÖÇÄÜ ×÷ΪÆäÕ©Æ­ºÍ¹¥»÷µÄÒ»²¿ÃÅ £¬¶øÇÒ Î´À´¿ÉÄÜ»áÀ©´óÆäʹÓ÷¶Î§ £¬µ«ÕâһʼþËÆºõ²¢²»ÊÇÆäÖÐÖ®Ò»¡£


https://www.bleepingcomputer.com/news/security/europcar-denies-data-breach-of-50-million-users-says-data-is-fake/


5. Êý°Ù¸ö±»µÁµÄ RIPE ƾ֤ÔÚ°µÍøÉϳöÊÛ


2ÔÂ1ÈÕ £¬RIPE ÊÇÖж«¸÷¹úÒÔ¼°Å·Ö޺ͷÇÖÞ¸÷¹úµÄ IP µØÖ·¼°ÆäËùÓÐÕßÊý¾Ý¿â £¬×î½üÒѳÉΪÈÈÃÅÄ¿±ê £¬ÒòΪ¹¥»÷ÕßΪÁËÊÕ¼¯ÐÅÏ¢¶øÆÆ»µÁËÕÊ»§µÇ¼¡£²»Á¼ÐÐΪÕßÀûÓûñµÃµÄ RIPE ºÍÆäËûÃÅ»§µÄй¶ƾ¾ÝÀ´Ì½²âÊܺ¦Õß¿ÉÄÜÓÐÌØÈ¨·ÃÎÊµÄÆäËûÓ¦Ó÷¨Ê½ºÍ·þÎñ¡£Æ¾¾ÝÎÒÃÇµÄÆÀ¹À £¬´ËÀà¼ÆÄ±Ôö¼ÓÁËËûÃÇÀÖ³ÉÈëÇÖÄ¿±êÆóÒµºÍµçÐÅÔËÓªÉÌÍøÂçµÄ»ú»á¡£±¾ÔÂÔçЩʱºò £¬  Orange Spain ÔâÊÜÁË»¥ÁªÍøÖÐ¶Ï £¬Ô­ÒòÊǺڿÍÇÖÈëÁ˸ù«Ë¾µÄ RIPE ÕÊ»§ £¬´íÎóÅäÖÃÁË BGP ·ÓÉºÍ RPKI ÅäÖá£Resecurity ×ܹ²ÔÚ RIPE ºÍÆäËûÇøÓòÍøÂ磨°üÂÞ APNIC¡¢AFRINIC ºÍ LACNIC£©Öз¢ÏÖÁË 1,572 ¸ö¿Í»§ÕÊ»§ £¬ÕâЩÕÊ»§ÒòÉæ¼°Redline¡¢Vidar¡¢Lumma¡¢Azorult ºÍ Taurus µÈ ÖªÃûÃÜÂëÇÔÈ¡·¨Ê½µÄ¶ñÒâÈí¼þ»î¶¯¶øÊܵ½Ë𺦡£


https://www.darkreading.com/cyberattacks-data-breaches/looted-ripe-credentials-for-sale-on-dark-web


6. ½­É­×ԿسÆÀÕË÷Èí¼þ¹¥»÷Ôì³É 2700 ÍòÃÀÔªËðʧ

1ÔÂ31ÈÕ £¬½­É­×Կعú¼Ê¹«Ë¾ (Johnson Controls International) È·ÈÏ £¬2023 Äê 9 ÔµÄÒ»´ÎÀÕË÷Èí¼þ¹¥»÷¸ø¸Ã¹«Ë¾Ôì³ÉÁË 2700 ÍòÃÀÔªµÄÓÃ¶È £¬²¢µ¼ÖºڿÍÇÔÈ¡¹«Ë¾Êý¾Ýºó·¢ÉúÊý¾Ýй¶¡£½­É­×Ô¿ØÊÇÒ»¼Ò¿ª·¢ºÍÖÆÔ칤ҵ¿ØÖÆÏµÍ³¡¢Äþ¾²É豸¡¢¿Õµ÷ºÍÏû·ÀÄþ¾²É豸µÄ¿ç¹úÆóÒµ¼¯ÍÅ¡£ÕýÈç BleepingComputer Ê״ᨵÀµÄÄÇÑù £¬ ½­É­×Ô¿Ø ÔÚÆäÑÇÖÞ·þÎñ´¦×î³õÔâµ½ÈëÇÖºó £¬ÓÚ 9 Ô·ÝÔâÊÜÁËÀÕË÷Èí¼þ¹¥»÷ £¬¹¥»÷Õ߱鲼Õû¸öÍøÂç¡£´Ë´Î¹¥»÷ÆÈʹ¸Ã¹«Ë¾¹Ø±ÕÁË´ó²¿ÃÅ IT »ù´¡ÉèÊ© £¬´Ó¶øÓ°ÏìÁËÃæÏò¿Í»§µÄϵͳ¡£Dark Angels ÀÕË÷Èí¼þÍÅ»ïÊǴ˴ι¥»÷µÄÄ»ºóºÚÊÖ £¬²¢Éù³Æ´Ó Johnson Controls ÇÔÈ¡ÁËÁè¼Ý 27 TB µÄ»úÃÜÊý¾Ý¡£Ëæºó £¬ÍþвÐÐΪÕßË÷Òª 5100 ÍòÃÀÔªµÄÊê½ð £¬ÒÔɾ³ýÊý¾Ý²¢ÌṩÎļþ½âÃÜÆ÷¡£Dark Angels ÊÇÒ»¸öÀÕË÷Èí¼þÍÅ»ï £¬ÓÚ 2022 Äê 5 ÔÂÌᳫ £¬Ê¹ÓûùÓÚÏÖÒѽâÉ¢µÄ Babuk ºÍ Ragnar Locker ²Ù×÷µÄй¶Դ´úÂëµÄ¼ÓÃÜÆ÷¡£¸Ã¹«Ë¾ÈϿɷþÎñÖÐ¶Ï £¬ºóÀ´½«Ô­Òò¹éÒòÓÚ¡°ÍøÂçÄþ¾²Ê¼þ¡± £¬µ«Ã»ÓÐÌṩÓйع¥»÷ÀàÐÍ»òµ¼ÖÂÊý¾Ýй¶µÄ¿ÉÄÜÐÔµÄÏêϸÐÅÏ¢¡£


https://www.bleepingcomputer.com/news/security/johnson-controls-says-ransomware-attack-cost-27-million-data-stolen/