Windows Server ¸üе¼ÖÂÓò¿ØÖÆÆ÷Íß½â²¢ÖØÐÂÆô¶¯

Ðû²¼Ê±¼ä 2024-03-22

1. Windows Server ¸üе¼ÖÂÓò¿ØÖÆÆ÷Íß½â²¢ÖØÐÂÆô¶¯


3ÔÂ21ÈÕ £¬ÓÉÓÚ Windows Server 2016 ºÍ Windows Server 2022 µÄ 2024 Äê 3 ÔÂÀÛ»ý¸üÐÂÖÐÒýÈëÁ˵±µØÄþ¾²»ú¹¹×Óϵͳ·þÎñ (LSASS)  £¬ÊÜÓ°ÏìµÄ·þÎñÆ÷ÕýÔÚ¶³½á²¢ÖØÐÂÆô¶¯ ¡£LSASS ÊÇÒ»Ïî Windows ·þÎñ £¬ÓÃÓÚÖ´ÐÐÄþ¾²¼ÆÄ±²¢´¦ÖÃÓû§µÇ¼¡¢·ÃÎÊÁîÅÆ´´½¨ºÍÃÜÂë¸ü¸Ä ¡£ÕýÈçÐí¶à¹ÜÀíÔ±¾¯¸æµÄÄÇÑù £¬ÔÚ°²×°ÖܶþÐû²¼µÄ KB5035855 ºÍ KB5035857 Windows Server ¸üкó £¬¾ßÓÐ×îиüеÄÓò¿ØÖÆÆ÷½«ÓÉÓÚ LSASS ÄÚ´æÊ¹ÓÃÁ¿Ôö¼Ó¶øÍß½â²¢ÖØÐÂÆô¶¯ ¡£ÔÚ Microsoft ÕýʽÈϿɴËÄÚ´æÐ¹Â¶ÎÊÌâ֮ǰ £¬½¨Òé¹ÜÀíÔ±´ÓÆäÓò¿ØÖÆÆ÷Ð¶ÔØÓÐÎÊÌâµÄ Windows Server ¸üР¡£


https://www.bleepingcomputer.com/news/microsoft/new-windows-server-updates-cause-domain-controller-crashes-reboots/


2. ³¯ÏÊ Kimsuky ÍøÂç·¸×ïÍÅ»ïÒÑ¿ªÊ¼Ê¹ÓÃмÆÄ±¿ªÕ¹»î¶¯


3ÔÂ21ÈÕ £¬¾ÝÐÅÏ¢Äþ¾²¹©Ó¦ÉÌ Rapid7 ³Æ £¬³¯ÏÊÎÛÃûÕÑÖøµÄ Kimsuky ÍøÂç·¸×ïÍÅ»ïÒÑ¿ªÊ¼Ê¹ÓÃмÆÄ±¿ªÕ¹»î¶¯ ¡£¸ÃÍÅ»ïÒ²±»³ÆÎª Black Banshee¡¢Thallium¡¢APT 43 ºÍ Velvet Chollima¡ª¡ªºã¾ÃÒÔÀ´Ò»Ö±ÊÔͼ´ÓÕþ¸®»ú¹¹ºÍÖÇ¿âµÈ»ú¹¹»ñÈ¡ÐÅÏ¢ £¬Rapid7 ²»È·¶¨¸ÃÍÅ»ïÈçºÎ·Ö·¢Æä×îй¥»÷ £¬µ«È·ÐÅÓÐЧ¸ºÔذüÂÞÓж¾µÄ Microsoft ±àÒë HTML ×ÊÖú (CHM) ÎļþÒÔ¼° ISO¡¢VHD¡¢ZIP ºÍ RAR Îļþ ¡£CHM Îļþ¿ÉÒÔ°üÂÞÎı¾¡¢Í¼ÏñºÍ³¬Á´½Ó ¡£Kimsuky ¿ÉÄܶÔËüÃǸü¸ÐÐËȤ £¬ÒòΪËüÃÇ¿ÉÒÔÖ´ÐÐ JavaScript ¡£Rapid7 µÄÑо¿ÈËÔ±ÆÆ½âÁËÆäÖÐÒ»¸ö CHM Îļþ £¬ËûÃÇÈÏΪÕâÊÇ Kimsuky µÄ×÷Æ· £¬²¢·¢ÏÖÁË¡°Ò»¸öʹÓà HTML ºÍ ActiveX ÔÚ Windows ¼ÆËã»úÉÏÖ´ÐÐÈÎÒâÃüÁîµÄʾÀý £¬Í¨³£ÓÃÓÚ¶ñÒâÄ¿µÄ¡± ¡£


https://www.theregister.com/2024/03/21/kimsuky_chm_file_campaign/


3. ÍþвÐÐΪÕßÀûÓà JETBRAINS TEAMCITY ©¶´Á÷´«¶ñÒâÈí¼þ


3ÔÂ20ÈÕ £¬Ç÷ÊÆ¿Æ¼¼Ñо¿ÈËÔ±·¢ÏÖÀûÓà JetBrains TeamCity ÖÐ×î½üÅû¶µÄ©¶´CVE-2024-27198  £¨CVSS ÆÀ·Ö£º9.8£©ºÍCVE-2024-27199£¨CVSS ÆÀ·Ö 7.3£©Äþ¾²Â©¶´À´²¿Êð¶à¸ö¶ñÒâÈí¼þµÄ¹¥»÷»î¶¯ ¡£CVE-2024-27198 ÊÇ TeamCity Web ×é¼þÖеÄÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ý©¶´ £¬ÓÉÌæ´ú·¾¶ÎÊÌâ ( CWE-288 ) ÒýÆð £¬CVSS »ù±¾ÆÀ·ÖΪ 9.8£¨ÑÏÖØ£© ¡£CVE-2024-27199ÊÇ TeamCity Web ×é¼þÖеÄÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ý©¶´ £¬ÓÉ·¾¶±éÀúÎÊÌâ ( CWE-22 ) ÒýÆð £¬CVSS »ù±¾ÆÀ·ÖΪ 7.3£¨¸ß£© ¡£ÕâЩ©¶´¿ÉÄÜʹδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ý HTTP(S) ·ÃÎÊ TeamCity ·þÎñÆ÷À´ÈƹýÉí·ÝÑéÖ¤¼ì²é²¢»ñµÃ¶Ô¸Ã TeamCity ·þÎñÆ÷µÄ¹ÜÀí¿ØÖÆ ¡£


https://securityaffairs.com/160823/breaking-news/jetbrains-teamcity-flaws-actively-exploited.html


4. еÄÑ­»· DoS ¹¥»÷¿ÉÄÜ»áÓ°Ïì¶à´ï 30Íò¸öϵͳ


3ÔÂ20ÈÕ £¬Ò»ÖÖÃûΪ¡°Ñ­»· DoS¡±µÄоܾø·þÎñ¹¥»÷Õë¶ÔÓ¦ÓòãЭÒé £¬¿ÉÒÔ½«ÍøÂç·þÎñÅä¶Ôµ½ÎÞÏÞͨÐÅÑ­»·ÖÐ £¬´Ó¶ø·¢Éú´óÁ¿Á÷Á¿ ¡£¸Ã¹¥»÷ÓÉCISPA º¥Ä·»ô×ÈÐÅÏ¢Äþ¾²ÖÐÐĵÄÑо¿ÈËÔ±Éè¼Æ £¬Ê¹ÓÃÓû§Êý¾Ý±¨Ð­Òé (UDP) £¬Ó°ÏìÔ¤¼Æ 300,000 ̨Ö÷»ú¼°ÆäÍøÂç ¡£´Ë´Î¹¥»÷¿ÉÄÜÊÇÓÉÓÚ UDP ЭÒéʵÏÖÖеÄÒ»¸ö©¶´£¨Ä¿Ç°¸ú×ÙΪCVE-2024-2169 £©Ôì³ÉµÄ £¬¸Ã©¶´ÈÝÒ×Êܵ½ IP ÆÛÆ­ £¬¶øÇÒ²»Ìṩ×ã¹»µÄÊý¾Ý°üÑéÖ¤ ¡£ÀûÓøÃ©¶´µÄ¹¥»÷Õ߻ᴴ½¨Ò»ÖÖ×ÔÎÒÑÓÐøµÄ»úÖÆ £¬¸Ã»úÖÆ»áÎÞÏÞÖÆµØ·¢Éú¹ý¶àµÄÁ÷Á¿ £¬¶øÇÒÎÞ·¨×èÖ¹Ëü £¬´Ó¶øµ¼ÖÂÄ¿±êϵͳÉõÖÁÕû¸öÍøÂç·ºÆð¾Ü¾ø·þÎñ (DoS) Çé¿ö ¡£Ñ­»· DoS ÒÀÀµÓÚ IP ÆÛÆ­ £¬¶øÇÒ¿ÉÒÔ´Ó·¢ËÍÒ»ÌõÏûÏ¢ÒÔÆô¶¯Í¨Ðŵĵ¥¸öÖ÷»ú´¥·¢ ¡£


https://www.bleepingcomputer.com/news/security/new-loop-dos-attack-may-impact-up-to-300-000-online-systems/


5. ÒÁÀʺڿÍÉù³ÆÒÑÈëÇÖÒÔÉ«ÁеĺËÉèÊ©


3ÔÂ21ÈÕ £¬ Ò»¸öÓëÒÁÀÊÓйصĺڿÍ×éÖ¯Éù³ÆÔÚ¡°ÄäÃû¡±ºÚ¿ÍÐû²¼µÄÒ»ÆðʼþÖÐÆÆ»µÁËÒÔÉ«ÁÐÃô¸ÐºËÉèÊ©µÄ¼ÆËã»úÍøÂç £¬ÒÔ¿¹Òé¼ÓɳսÕù ¡£ºÚ¿ÍÉù³Æ´ÓÎ÷ÃÉ¡¤ÅåÀ×˹¡¤ÄڸǷòºËÑо¿ÖÐÐÄÇÔÈ¡²¢Ðû²¼ÁËÊýǧ·ÝÎļþ £¬°üÂÞ PDF¡¢µç×ÓÓʼþºÍ PowerPoint »ÃµÆÆ¬ ¡£Õâ¸öÃØÃÜÉèÊ©ÄÚÓÐÒ»¸öÓëÒÔÉ«ÁÐδ¹ûÈ»µÄºËÎäÆ÷¼Æ»®Óйصĺ˷´Ó³¶Ñ £¬ÀúÊ·ÉÏÒ»Ö±ÊǹþÂí˹»ð¼ýµÄÄ¿±ê ¡£¸Ã×éÖ¯ÔÚÉ罻ýÌåÏûÏ¢ÖнâÊÍÁËËûÃǵÄÒâͼ £¬Éù³Æ¡°ÎÒÃDz»ÏñÊÈѪµÄÄÚËþÄáÑǺúºÍËûµÄ¿Ö²À¾ü¶ÓÄÇÑù £¬ÎÒÃÇÒÔûÓÐÆ½ÃñÊܵ½É˺¦µÄ·½Ê½½øÐÐÕâ´ÎÐж¯ ¡£¡± ¾¡¹ÜÓÐÕâÒ»ÉùÃ÷ £¬¸Ã×éÖ¯ÔÚÁíÒ»ÌõÉ罻ýÌåÏûÏ¢ÖÐÌåÏÖ £¬Ëü¡°ÎÞÒâ½øÐк˱¬Õ¨ £¬µ«Õâ´ÎÐж¯ºÜΣÏÕ £¬ÈκÎÊÂÇé¶¼¿ÉÄÜ·¢Éú¡± £¬Í¬Ê±»¹Ðû²¼ÁËÒ»¶ÎÃè»æºË±¬Õ¨ºÍºôÓõ³·ÀëÈËÔ±µÄ¶¯»­ÊÓÆµ ¡£


https://news.hitb.org/content/iranian-hackers-claim-have-breached-israeli-nuclear-facility


6. Ñо¿ÈËÔ±³Æ AceCryptor ¶ñÒâÈí¼þÔÚÅ·ÖÞ¼¤Ôö


3ÔÂ21ÈÕ £¬×÷ΪÕë¶ÔÅ·ÖÞ¸÷µØ×éÖ¯µÄ»î¶¯µÄÒ»²¿ÃÅ £¬ÒѾ­·¢ÏÖÁËÉæ¼° AceCryptor ¹¤¾ßµÄÊýǧ¸öÐÂѬȾ £¬ºÚ¿Í»ìÏý¶ñÒâÈí¼þ²¢½«ÆäÖ²Èëϵͳ¶ø²»±»·À²¡¶¾Èí¼þ¼ì²âµ½ ¡£ESET µÄÑо¿ÈËÔ±»¨ÁËÊýÄêʱ¼ä¸ú×Ù AceCryptor £¬ËûÃÇÖÜÈýÌåÏÖ £¬×î½üµÄ¹¥»÷»î¶¯Óë֮ǰµÄµü´ú²îÒì £¬ÒòΪ¹¥»÷ÕßÀ©Õ¹ÁËÄÚ²¿´ò°üµÄ¶ñÒâ´úÂëÀàÐÍ ¡£AceCryptor ͨ³£ÓëÃûΪ Remcos»ò Rescoms µÄ¶ñÒâÈí¼þÒ»ÆðʹÓà £¬ÕâÊÇÒ»ÖÖÇ¿´óµÄÔ¶³Ì¼àÊÓ¹¤¾ß £¬Ñо¿ÈËÔ±ÒÑ·¢Ïָù¤¾ß¶à´ÎÓÃÓÚÕë¶ÔÎÚ¿ËÀ¼µÄ×éÖ¯ ¡£³ýÁË Remcos ºÍÁíÒ»¸öÊìϤµÄ¹¤¾ß SmokeLoader Ö®Íâ £¬ESET ÌåÏÖ £¬ÏÖÔÚ»¹·¢ÏÖ AceCryptor ·Ö·¢ STOP ÀÕË÷Èí¼þºÍ Vidar ÇÔÈ¡·¨Ê½µÈ¶ñÒâÈí¼þ ¡£ESET ƾ¾ÝÄ¿±ê¹ú¼Ò/µØÓò·¢ÏÖÁËһЩ²îÒì ¡£ÎÚ¿ËÀ¼µÄ¹¥»÷ʹÓÃÁËSmokeLoader £¬¶ø²¨À¼¡¢Ë¹Âå·¥¿Ë¡¢±£¼ÓÀûÑǺÍÈû¶ûάÑǵĹ¥»÷ÔòʹÓÃÁËRemcos ¡£ 


https://therecord.media/acecryptor-malware-surge-europe-remcos