ÍøÂç·¸×ï·Ö×Ó½« Raspberry Pi Äð³ÉÆÛÕ©ºÍ¼äµý¹¤¾ß
Ðû²¼Ê±¼ä 2024-03-273ÔÂ25ÈÕ£¬Ò»ÖÖÃûΪ GEOBOX µÄÐÂÈí¼þ°ü½ÓÄɼ۸ñʵ»ÝÇҹ㷺ʹÓõÄRaspberry Pi¼ÆËã»ú£¬²¢½«Æäת±äΪÅÓ´óµÄÄäÃû¹¤¾ß - רΪÆÛÕ©¡¢¼äµý»î¶¯ºÍÈÆ¹ýÄþ¾²¿ØÖƶø¶¨ÖÆ¡£GEOBOX ÔÚ°µÍøÂÛ̳ÉÏµÄ¹ã¸æ¼Û¸ñ½öΪÿÔ 80 ÃÀÔª£¬ÔÊÐíÍøÂç·¸×ï·Ö×ÓÄܹ»£ºÐé¼Ù GPS λÖã»ÆÛÆÍøÂçÉèÖúÍÑڸǻ¥ÁªÍø»î¶¯¡£GEOBOX ϵͳµÄÉè¼Æ·Ç³£¼òµ¥¡£Í¨¹ýÌṩÓû§Êֲᣬ¼´Ê¹¼¼Êõרҵ֪ʶÓÐÏÞµÄÈËÒ²¿ÉÄܻᲿÊðÕâÖÖΣÏյŤ¾ß¡£GEOBOX ÒÔ¼°ÀàËÆ¹¤¾ß¸øÖ´·¨²¿ÃźÍÍøÂçÄþ¾²ÉçÇø´øÀ´ÁËÔ½À´Ô½´óµÄÌôÕ½¡£Ëæ×ÅÁªÍøÉ豸±äµÃÔ½·¢Ç¿´óÇÒ¼Û¸ñʵ»Ý£¬ÍøÂç·¸×ï·Ö×ÓÕýÔÚѰÕÒеÄÒªÁìÀ´ÀûÓÃËüÃÇ¡£
https://securityonline.info/cybercriminals-turn-cheap-raspberry-pi-into-powerful-fraud-and-espionage-tool/
2. kimsuky Á÷´«Î±×°³Éº«¹úij¹«¹²»ú¹¹°²×°·¨Ê½µÄ¶ñÒâÈí¼þ
3ÔÂ26ÈÕ£¬AhnLab Äþ¾²Ç鱨ÖÐÐÄ (ASEC) ×î½ü·¢ÏÖ Kimsuky ×éÖ¯Á÷´«Î±×°³Éº«¹ú¹«¹²»ú¹¹°²×°·¨Ê½µÄ¶ñÒâÈí¼þ¡£ËùÉæ¼°µÄ¶ñÒâÈí¼þÊÇÒ»¸ö´´½¨EndorºóÃŵÄÖ²È뷨ʽ¡£ËäȻûÓÐÔÚʵ¼Ê¹¥»÷ÖÐʹÓøÃÖ²È뷨ʽµÄ¼Ç¼£¬µ«ÔÚÓë¸ÃÖ²È뷨ʽ±»ÊÕ¼¯µÄԼĪͬһʱÆÚ£¬ÓÐÒ»¸öÉæ¼°¸ÃÖ²È뷨ʽ´´½¨ºóÃŵĹ¥»÷°¸Àý¡£ÍþвÐÐΪÕßʹÓúóÃÅÏÂÔØÆäËû¶ñÒâÈí¼þ»ò°²×°½ØÆÁ¶ñÒâÈí¼þ¡£Endor Ò²¾³£ÓÃÓÚÆäËû¹¥»÷£»¹ýÈ¥£¬ËüÓëNikidoorÒ»ÆðʹÓã¬Nikidoor ͨ¹ýÓã²æÊ½ÍøÂçµöÓã¹¥»÷½øÐзַ¢¡£Dropper ±»Î±×°³Éº«¹úij¹«¹²»ú¹¹µÄ°²×°·¨Ê½¡£Æäͼ±ê½ÓÄÉÁ˸ûú¹¹µÄ±êÖ¾£¬Ïà¹ØÒªº¦´Ê¿ÉÔÚ°æ±¾ÐÅÏ¢ºÍÉèÖÃÒ³ÃæÖÐÕÒµ½¡£ÁíÍ⣬ûÓÐÈκκϷ¨·¨Ê½µÄ°æ±¾Óë´ËÏàͬ¡£Õâ±íÃ÷¸Ã¶ñÒâÈí¼þÖ»ÊDZ»Éè¼ÆµÃÏñÈÎºÎÆäËûºÏ·¨·¨Ê½Ò»Ñù£¬ÎÞÒ⽫×Ô¼ºÎ±×°³ÉÏÖÓз¨Ê½¡£¼´Ê¹ÔÚ°²×°¹ý³ÌÖУ¬¶ñÒâÈí¼þÒ²ÊÇΨһÒÔÕý³£·½Ê½°²×°µÄ·¨Ê½¡£
https://asec.ahnlab.com/en/63396/
3. ·ðÂÞÀï´ïÖݵÄÊ¥¿ËÀ͵ÂÊÐÔâµ½ÀÕË÷¹¥»÷
3ÔÂ26ÈÕ£¬Ê¥¿ËÀ͵ÂÊÐÌåÏÖ£¬ÀÕË÷¹¥»÷µ¼ÖÂÐí¶à²¿ÃÅÊܵ½Ó°Ï죬µ«ËûÃÇÕýÔÚ¾¡¿ÉÄÜ×î¼ÑµØÔË×÷£¬Ö±µ½ÎÊÌâµÃµ½½â¾ö¡£Ê¥¿ËÀ͵ÂλÓÚ°ÂÀ¼¶àÒÔÄÏԼһСʱ³µ³Ì´¦£¬ÓµÓÐ 60000 Ãû¾ÓÃñ¡£¶øÇÒ¹«Ô°ºÍÐÝÏл¼°·þÎñµÄÏÖ³¡¸¶¿îÒ²ÔÝʱֻÄÜʹÓÃÏÖ½ð¡£ÔÚÏßÉèʩԤ¶©¸¶¿îºÍÔÚÏ߻ע²áÈÔÈ»½ÓÊÜÐÅÓÿ¨¸¶¿î¡£¾¯²ìºÍÏû·À¾ÈÔ®ÕýÔÚÏìÓ¦·þÎñÇëÇó¡£×ªÔËÕ¾µÄ·þÎñÓöÈÔÝʱֻÄÜÓÃÏÖ½ðÖ§¸¶£¬ËùÓÐÀ¬»øºÍ»ØÊÕÊÕ¼¯Â·Ïß½«°´¼Æ»®ÔËÐС£°ÂÎ÷°ÂÀÏØË°Îñ¾ÖºÍ OUC µÈÍⲿ¹«ÓÃÊÂÒµµÄÌṩÉ̲¢Î´Êܵ½´Ë´Î¹¥»÷µÄÓ°Ïì¡£
https://therecord.media/st-cloud-hit-with-ransomware-florida-string
4. Top.gg Discord »úÆ÷ÈËÉçÇøÔâµ½¹©Ó¦Á´¹¥»÷
3ÔÂ25ÈÕ£¬¶àÄêÀ´£¬ÍþвÐÐΪÕßÒ»Ö±ÔÚʹÓöàÖÖ¼ÆÄ±¡¢¼¼ÊõºÍ·¨Ê½ (TTP)£¬°üÂÞ½Ù³Ö GitHub ÕÊ»§¡¢·Ö·¢¶ñÒâ Python °ü¡¢Ê¹ÓÃÐé¼ÙµÄ Python »ù´¡ÉèÊ©ºÍÉç»á¹¤³Ì¡£ÉÏ´«µ½ PyPI µÄ¶ñÒâ°ü³äµ±ÁËÆÆ»µÏµÍ³µÄ³õÊ¼ÔØÌå¡£Ò»µ©ÏµÍ³Ôâµ½ÆÆ»µ£¬»òÕß¹¥»÷Õß½Ù³ÖÁËÌØÈ¨ GitHub ÕÊ»§£¬ËûÃǾͻá¸ü¸ÄÏîÄ¿ÎļþÒÔÖ¸Ïò¼Ù¾µÏñÉÏÍйܵÄÒÀÀµÏî¡£Top.gg Êǹ¥»÷Õß×î½üµÄÊܺ¦ÕßÖ®Ò»£¬ÕâÊÇÒ»¸öÁ÷ÐеÄËÑË÷ºÍ·¢ÏÖÆ½Ì¨£¬ÊÊÓÃÓÚ Discord ·þÎñÆ÷¡¢»úÆ÷ÈËºÍÆäËûÉç½»¹¤¾ß£¬Ö¼ÔÚÓÎÏ·¡¢Ìá¸ß¼ÓÈë¶ÈºÍ¸ïй¦Ð§¡£¹¥»÷ÕßÈëÇÖÁË top.gg ά»¤Õß¡°editor-syntax¡±µÄÕÊ»§£¬¸Ãά»¤Õß¶Ô¸ÃÆ½Ì¨µÄ GitHub ´æ´¢¿âÓµÓÐÖØÒªµÄдÈë·ÃÎÊȨÏÞ¡£
https://www.bleepingcomputer.com/news/security/hackers-poison-source-code-from-largest-discord-bot-platform/
5. ÓëÒÁÀÊÏà¹ØµÄ APT TA450 ÔÚ PDF ¸½¼þÖÐǶÈë¶ñÒâÁ´½Ó
3ÔÂ25ÈÕ£¬ÓëÒÁÀÊÓÐ¹ØµÄ APT ×éÖ¯MuddyWater £¨ÓÖÃû SeedWorm¡¢ TEMP.Zagros¡¢TA450 ºÍ Static Kitten£©ÊÇ 2024 Äê 3 ÔÂÌᳫµÄÒ»´ÎеÄÍøÂçµöÓã»î¶¯µÄÄ»ºóºÚÊÖ£¬¸Ã»î¶¯ÊÔͼÔÚ 2024 Äê 3 ÔÂͶ·ÅÃûΪ Atera µÄºÏ·¨Ô¶³Ì¼à¿ØºÍ¹ÜÀí (RMM) ½â¾ö·½°¸¡£¸Ã»î¶¯Õë¶Ô´óÐÍ¿ç¹ú×éÖ¯µÄÒÔÉ«ÁÐÔ±¹¤£¬ÀûÓÃÓëн³êÏà¹ØµÄÉç»á¹¤³Ì¡£¸ÃÍøÂçµöÓã»î¶¯ÓÚ 3 Ô 7 ÈÕ¿ªÊ¼£¬Ò»Ö±Á¬Ðøµ½ 2024 Äê 3 Ô 11 ÈÕÕâÒ»ÖÜ¡£TA450 ×éÖ¯·¢ËÍÓã²æÊ½ÍøÂçµöÓãÓʼþ£¬ÆäÖаüÂÞ°üÂÞ¶ñÒâÁ´½ÓµÄ PDF ¸½¼þ¡£ÍþвÐÐΪÕßÏòͬһÊÕ¼þÈË·¢ËÍÁ˶à·â´øÓÐ PDF ¸½¼þµÄÍøÂçµöÓãµç×ÓÓʼþ£¬ÆäÖÐǶÈëµÄÁ´½ÓÂÔÓвîÒì¡£Proofpoint ƾ¾Ý¶ÔÓëÍøÂç¼äµý×éÖ¯¡¢»î¶¯Ä¿±êÒÔ¼°¹¥»÷ÖÐʹÓõĶñÒâÈí¼þÏà¹ØµÄ¼ÆÄ±¡¢¼¼ÊõºÍ·¨Ê½µÄÊӲ죬½«´Ë´Î»î¶¯¹éÒòÓÚ TA450¡£
https://securityaffairs.com/161042/apt/iran-ta450-rmm-atera.html
6. ºÚ¿Í¿É½âËø Dormakaba ÏúÊÛµÄ 300 ¶àÍò¸ö·¿ÃÅ
3ÔÂ25ÈÕ£¬ÊýǧÃûÄþ¾²Ñо¿ÈËÔ±Æë¾ÛÀ˹ά¼Ó˹¼ÓÈëËùνµÄ¡°ºÚ¿ÍÏÄÁîÓª¡±£¨Á¬Ðø¾ÙÐÐ Black Hat ºÍ Defcon ºÚ¿Í»áÒ飩ʱ£¬ËûÃÇÖеÄһЩÈ˿϶¨»áʵÑéÈëÇÖ»ù´¡Éèʩά¼Ó˹×Ô¼º£¬Õâ×ù¶¼ÊÐÓµÓÐһϵÁо«ÐÄÉè¼ÆµÄ¶Ä³¡ºÍ¾Æµê¼¼Êõ¡£Ian Carroll¡¢Lennert Wouters ºÍÆäËûÄþ¾²Ñо¿ÈËÔ±ÍŶӽÒʾÁËÒ»ÖÖËûÃdzÆÖ®Îª Unsaflok µÄ¾ÆµêÔ¿³×¿¨ºÚ¿Í¼¼Êõ¡£¸Ã¼¼ÊõÊÇһϵÁÐÄþ¾²Â©¶´µÄ¼¯ºÏ£¬ºÚ¿Í¼¸ºõ¿ÉÒÔÁ¢¼´´ò¿ªÈðÊ¿Ëø¾ßÖÆÔìÉÌ Dormakaba ÏúÊÛµÄ Saflok Æ·ÅÆ»ùÓÚ RFID µÄÔ¿³×¿¨ËøµÄ¶àÖÖÐͺš£Saflok ϵͳ°²×°ÔÚÈ«Çò 131 ¸ö¹ú¼Ò 13000 ´¦·¿²úµÄ 300 ÍòÉÈÃÅÉÏ¡£
https://news.hitb.org/content/hackers-can-unlock-over-3-million-hotel-doors-seconds