Àè°ÍÄÛ´«ºô»ú±¬Õ¨ £¬ÕæÖ÷µ³ÔâÖØ´´ £¬ÒÔÉ«Áб»Ö¸Ä»ºóºÚÊÖ

Ðû²¼Ê±¼ä 2024-09-18

1. Àè°ÍÄÛ´«ºô»ú±¬Õ¨ £¬ÕæÖ÷µ³ÔâÖØ´´ £¬ÒÔÉ«Áб»Ö¸Ä»ºóºÚÊÖ


9ÔÂ17ÈÕ £¬Àè°ÍÄÛ·¢ÉúÁËÒ»³¡´ó¹æÄ£µÄ´«ºô»ú±¬Õ¨Ê¼þ £¬Ôì³ÉÖÁÉÙ11ÈËËÀÍö £¬4000¶àÈËÊÜÉË £¬ÆäÖаüÂÞ¶àÃûÕæÖ÷µ³³ÉÔ±¡£´Ë´Îʼþ±»ÈÏΪÊÇÀè°ÍÄÛÓëÒÔÉ«ÁнüÒ»Äê³åÍ»Öеġ°×î´óÄþ¾²Ê§°Ü¡± £¬ÕæÖ÷µ³¹ÙÔ±¶Ô´ËÌåÏÖÇ¿ÁÒÇ´Ô𡣾ݱ¨µÀ £¬±¬Õ¨·¢ÉúÔÚ±´Â³ÌØÄϽ¼µÈ¶à¸öµØÓò £¬´«ºô»úÔÚÈËÃǵĿڴü»òÊÖÖÐͻȻ·¢ÉÕ²¢±¬Õ¨ £¬ÁôÏÂһƬ»ìÂҺͿֻÅ¡£Àè°ÍÄÛÎÀÉú²¿½ô¼±ºôÓõÒ½ÎñÈËÔ±¾ÈÖÎÉËÕß £¬²¢½¨ÒéÃñÖÚÔÝͣʹÓô«ºô»ú¡£Ä¿Ç° £¬±¬Õ¨µÄ¾ßÌåÔ­ÒòÉÐδÃ÷È· £¬µ«ÒÑÈ·ÈÏÊÇÈËΪԶ³ÌÒý·¢µÄ¡£¿ÉÄܵÄÒòËØ°üÂÞÔ¶³ÌÒý±¬×°Öá¢ÍøÂç¹¥»÷»ò¹©Ó¦Á´¹¥»÷¡£´Ë´Îʼþ·¢Éúʱ £¬ÕýÖµÒÔÉ«ÁÐÓëÕæÖ÷µ³Ö®¼ä½ôÕžÖÊÆ²»Í£Éý¼¶Ö®¼Ê¡£×ÔÈ¥Äê10ÔÂÒÔÀ´ £¬Ë«·½ÔÚÀè°ÍÄÛÄϲ¿½®ÓòµÄ³åÍ»Á¬Ðø²»Í£¡£ÕæÖ÷µ³¹ÙÔ±Ö¸ÔðÒÔÉ«Áз¢¶¯ÁËÕâ´ÎÅÓ´óµÄÔ¶³Ì¹¥»÷ £¬¶øÒÔÉ«Áз½ÃæÔò¾Ü¾øÖÃÆÀ¡£ÁªºÏ¹úפÀè°ÍÄÛÎÊÌâÌØ±ðЭµ÷Ô±¶Ô´Ë´ÎÏ®»÷ÌåÏÖÇ´Ô𠣬²¢¾¯¸æ¾ÖÊÆµÄ½øÒ»²½Éý¼¶½«¶ÔµØÓòÎȶ¨Ôì³ÉÑÏÖØÓ°Ïì¡£¹ú¼ÊÉç»áÒ²ÔÚÃÜÇйØ×¢´ËʵĽøÕ¹ £¬ºôÓõ¸÷·½±£³Ö¿ËÖÆ £¬Í¨¹ý¶Ô»°ºÍ̸Åнâ¾öÕù¶Ë¡£


https://www.securityweek.com/hundreds-of-pagers-exploded-in-lebanon-and-syria-in-a-deadly-attack-heres-what-we-know/


2. ´¨ÆéĦÍгµÅ·ÖÞ¹«Ë¾ÔâRansomHubÀÕË÷Èí¼þ¹¥»÷


9ÔÂ13ÈÕ £¬´¨ÆéĦÍгµÅ·ÖÞ¹«Ë¾£¨KME£©½üÆÚÔâÓöRansomHubÀÕË÷Èí¼þÍÅ»ïµÄÍøÂç¹¥»÷ £¬¸ÃÍÅ»ïÍþвй¶´Ó¹«Ë¾ÇÔÈ¡µÄÊý¾Ý¡£¾¡¹Ü¹¥»÷δÍêÈ«ÀÖ³É £¬µ«KMEµÄ·þÎñÆ÷±»ÔÝʱ¸ôÀëÒÔÈ·±£Äþ¾² £¬¹«Ë¾Ëæ¼´Æô¶¯ÁËÕ½ÂÔ»Ö¸´¼Æ»®¡£KME×÷Ϊ´¨ÆéÖØ¹¤ÒµÖêʽ»áÉçÔÚÅ·ÖÞµÄ×Ó¹«Ë¾ £¬ÂôÁ¦Ä¦ÍгµµÈ²úÎïµÄ·ÖÏúÓëÓªÏú £¬ÆäITÍŶÓÕýÓëÍⲿר¼Ò½ôÃܺÏ×÷ £¬·ÖÎö²¢Çå³ýϵͳÄÚµÄDZÔÚ¶ñÒâÈí¼þ £¬ÒÔÈ·±£ËùÓзþÎñÆ÷µÃµ½³¹µ×¼ì²éÓëÇåÀí¡£¹«Ë¾Ô¤¼ÆÏÂÖܳõ½«»Ö¸´90%µÄ·þÎñÆ÷»ù´¡ÉèÊ© £¬ÇÒ´Ëʼþ¶ÔÈÕ³£ÒµÎñÔËÓª¡¢¾­ÏúÉÌÍøÂç¼°ÎïÁ÷·þÎñÎÞÖ±½ÓÓ°Ï졣Ȼ¶ø £¬RansomHubÒÑÐû³ÆÇÔÈ¡KME 487GBÊý¾Ý £¬²¢ÉèÖõ¹¼ÆÊ±Íþв¹ûÈ»Êý¾Ý £¬ÆäÖлò°üÂÞ¿Í»§×ÊÁÏ £¬¾ßÌåÇé¿öÉдý½øÒ»²½È·ÈÏ¡£´Ë´ÎʼþÔÙ´Î͹ÏÔÁËRansomHubÀÕË÷Èí¼þµÄ»îÔ¾ÓëÍþв £¬¸ÃÍÅ»ï×ÔBlackCat/ALPHVÐж¯¼Å¾²ºóѸËÙáÈÆð £¬Àֳɹ¥»÷Á˰üÂÞRite Aid¡¢FrontierÔÚÄڵĶà¼ÒÖªÃûÆóÒµ¡£FBI¡¢CISA¼°HHSÁªºÏ³ÂËßÖ¸³ö £¬RansomHubÒÑÓ°ÏìÃÀ¹úÁè¼Ý210ÃûÊܺ¦Õß £¬Í¹ÏÔÁËÍøÂçÄþ¾²ÐÎÊÆµÄÑϾþÐÔ¡£


https://www.bleepingcomputer.com/news/security/ransomhub-claims-kawasaki-cyberattack-threatens-to-leak-stolen-data/


3. Apache OFBiz©¶´CVE-2024-45195Òý·¢´ó¹æÄ£¹¥»÷


9ÔÂ12ÈÕ £¬×ÔApache OFBizÖеÄCVE-2024-45195©¶´ÆØ¹âºó £¬Imperva³ÂËßÖ¸³öÒÑÓÐÁè¼Ý25,000´Î¶ñÒâÇëÇóÕë¶Ô4,000¸ö²îÒìÕ¾µãÌᳫ £¬Ö÷ҪĿ±êΪ½ðÈÚ·þÎñÒµºÍÉÌÒµ²¿ÃÅ¡£ÕâЩ¹¥»÷ÀûÓÃGoÓïÑÔ±àдµÄ¶ñÒâ»úÆ÷È˺Ͷ¨Öƹ¤¾ß £¬Æóͼͨ¹ýÈÆ¹ýÊÚȨ¼ì²éÖ´ÐÐÈÎÒâ´úÂë £¬½ø¶ø²¿Êð¶ñÒâÈí¼þ¡¢ÇÔÈ¡Êý¾Ý»òÆÆ»µÒµÎñ¡£CVE-2024-45195µÄÑÏÖØÐÔÔÚÓÚÆäÄÜÈÆ¹ý¶à¸öÏÈǰÒÑÐÞ¸´µÄ©¶´ £¬°üÂÞÔø±»ÓÃÓÚMirai½©Ê¬ÍøÂ粿ÊðµÄCVE-2024-32113 £¬ÏÔʾÁ˸ÃÄþ¾²ÎÊÌâµÄÍç¹ÌÐÔºÍÑÏÖØÐÔ¡£Apache OFBiz 18.12.16֮ǰ°æ±¾¾ùÊÜÓ°Ïì £¬µ«×îа汾ÒÑÐû²¼²¹¶¡ £¬Í¨¹ýÔöÇ¿ÑéÖ¤»úÖÆÈ·±£ÊÓͼÊÚȨµÄÕýÈ·Ö´ÐÐ £¬²¢×èÖ¹¿ØÖÆÆ÷ÊÓͼ²îÒ첽©¶´µÄÀûÓà £¬ÎªÏµÍ³ÌṩҪº¦·À»¤¡£´ËÍâ £¬Ð°汾»¹ÐÞ¸´ÁËÁíÒ»¸ö¸ß·çÏյķþÎñÆ÷¶ËÇëÇóαÔì©¶´£¨CVE-2024-45507 £¬CVSSÆÀ·Ö9.8£© £¬¸Ã©¶´¿ÉÄÜÒý·¢Î´ÊÚȨ·ÃÎʺÍϵͳÈëÇÖ¡£Òò´Ë £¬Ç¿ÁÒ½¨ÒéËùÓÐʹÓÃApache OFBizµÄ×éÖ¯Á¢¼´Éý¼¶ÖÁ×îа汾 £¬ÒÔÓÐЧ»º½âÕâЩҪº¦Äþ¾²·çÏÕ¡£


https://securityonline.info/hackers-target-apache-ofbiz-rce-flaw-cve-2024-45195-after-poc-exploit-released/?&web_view=true


4. Google Sheets³ÉÐÂÕ½³¡£ºProofpoint½Ò¶´ó¹æÄ£C2©¶´¹¥»÷


9ÔÂ13ÈÕ £¬ÍøÂçÄþ¾²×¨¼ÒProofpoint½üÆÚ½Ò¶ÁËÒ»ÏîÕë¶ÔGoogle SheetsµÄÅÓ´ó©¶´ÀûÓû £¬¸Ã»î¶¯Ê¼ÓÚ2024Äê8ÔÂ5ÈÕ £¬ÍþвÕßÀûÓÃ¸ÃÆ½Ì¨×÷ΪÃüÁîÓë¿ØÖÆ£¨C2£©»úÖÆ £¬Ã°³ä¶à¹ú˰Îñ»ú¹ØÏòÈ«Çò70¼Ò×éÖ¯·¢ËÍÁËÔ¼20,000·âÕ©Æ­Óʼþ¡£ÕâЩÓʼþÓÕµ¼Óû§µã»÷αװ³ÉÄÉ˰É걨µ¥±ä»¯µÄÁ´½Ó £¬½ø¶øÍ¨¹ýһϵÁо«ÐÄÉè¼ÆµÄ²½Öè £¬°üÂÞ¼ì²é²Ù×÷ϵͳ¡¢ÀûÓÃWindows¿ì½Ý·½Ê½Îļþ¡¢PowerShell½Å±¾Ö´Ðм°WebDAV¹²ÏíÉϵÄPython½Å±¾ÔËÐÐ £¬×îÖÕÊÕ¼¯²¢·¢ËÍÊܺ¦ÕßϵͳÐÅÏ¢¡£¹¥»÷ÊÖ¶ÎÖÐ £¬Voldemort¹¤¾ßÊÎÑÝÁËÒªº¦½ÇÉ« £¬¸Ã¹¤¾ßÓÃCÓïÑÔ±àд £¬Äܹ»ÀûÓÃGoogle SheetsʵÏÖÊý¾Ýй¶¡¢Ö´ÐÐÔ¶³ÌÃüÁîµÈ¶àÖÖ¶ñÒâ»î¶¯¡£´ËÍâ £¬¹¥»÷»¹Éæ¼°DLL²àÔØ¼¼Êõ £¬Í¨¹ýαװ³ÉºÏ·¨Èí¼þµÄ¶ñÒâ¿ÉÖ´ÐÐÎļþºÍDLLÎļþ½øÒ»²½ÉøÍ¸ÏµÍ³¡£´Ë´Î¹¥»÷ÁýÕÖÁ˰üÂÞ±£ÏÕ¡¢º½Ìì¡¢½ðÈÚ¡¢Õþ¸®ÔÚÄڵĶà¸öÐÐÒµ £¬ÏÔʾ³öÍþвÕ߹㷺µÄ¹¥»÷·¶Î§ºÍÅÓ´óµÄ¹¥»÷¼ÆÄ±¡£¾¡¹Ü»î¶¯ÉÐδÃ÷È·¹é¾ÌÓÚÌØ¶¨Íþв×éÖ¯ £¬µ«ÆäÊÖ·¨ÓëLatrodectus¡¢DarkGateµÈÒÑÖª¶ñÒâÈí¼þ¼Ò×åÏàËÆ¡£


https://securityboulevard.com/2024/09/espionage-alert-google-sheets-exploit-for-malware-control/


5. Æ»¹ûVision ProÆØÄþ¾²Â©¶´£ºGAZEploit¹¥»÷ÍþвÓû§Òþ˽Äþ¾²


9ÔÂ13ÈÕ £¬Æ»¹û¹«Ë¾Vision Pro»ìºÏÏÖʵͷ´÷É豸½üÈÕÆØ³öÖØ´óÄþ¾²Â©¶´CVE-2024-40865 £¬¼´GAZEploit¹¥»÷ £¬¸Ã©¶´ÔÊÐíºÚ¿Íͨ¹ý·ÖÎöÓû§ÐéÄ⻯ÉíÖеÄÑÛÇòÔ˶¯£¨ÄýÊÓ£©Êý¾Ý £¬ÍƶϳöÓû§ÔÚÐéÄâ¼üÅÌÉϵÄÊäÈëÄÚÈÝ £¬ÑÏÖØÍþвÓû§Òþ˽Äþ¾²¡£ÕâÒ»ÐÂÓ±¹¥»÷·½Ê½ÀûÓÃÁËÉ豸ÔÚ¹²ÏíÐéÄ⻯Éíʱ £¬ÄýÊÓ¿ØÖÆÎı¾ÊäÈëµÄ¹ÌÓÐÄþ¾²È±ÏÝ¡£ºÚ¿ÍÄÜÀûÓÃÊÓÆµÍ¨»°¡¢ÔÚÏß»áÒé»òÖ±²¥Æ½Ì¨ÉϵĹ²ÏíÊÓÆµ £¬Ô¶³ÌÖ´Ðа´¼üÍÆ¶Ï £¬ÇÔÈ¡ÃÜÂëµÈÃô¸ÐÐÅÏ¢¡£Æ»¹û¹«Ë¾ÔÚvisionOS 1.3¸üÐÂÖÐÐÞ¸´ÁËÕâÒ»ÎÊÌâ £¬Í¨¹ýÔÝÍ£Persona¹¦Ð§ÔÚÐéÄâ¼üÅ̼¤»îʱµÄʹÓà £¬À´×è¶Ï´ËÀ๥»÷·¾¶¡£GAZEploit¹¥»÷ÒÀÀµÓÚ¶ÔÑÛÇò³¤¿í±È£¨EAR£©ºÍ×¢ÊÓÔ¤¼ÆµÄ¼à¶½Ñ§Ï°Ä£ÐÍ £¬¾«È·Ó³Éä×¢ÊÓÆ«ÏòÖÁ¼üÅ̰´¼ü £¬ÊµÏÖ»÷¼üÍÆ¶Ï¡£ÕâÒ»·¢ÏÖ½ÒʾÁË»ìºÏÏÖʵÉ豸ÔÚÒþ˽±£»¤·½ÃæµÄÐÂÌôÕ½ £¬´ÙʹÐÐÒµ¼ÓÇ¿¶Ô´ËÀàÄþ¾²Â©¶´µÄ·À·¶ÓëÓ¦¶Ô¡£


https://thehackernews.com/2024/09/apple-vision-pro-vulnerability-exposed.html


6. Access SportsÔâInc RansomÀÕË÷Èí¼þ¹¥»÷ £¬88,000ÈËÐÅϢй¶


9ÔÂ16ÈÕ £¬Access Sports Medicine & Orthopaedics £¬Ò»¼ÒλÓÚк±²¼Ê²¶ûÖݵĹǿƷþÎñÌṩÉÌ £¬½üÆÚÔâÓöÑÏÖØÍøÂç¹¥»÷ £¬µ¼ÖÂÁè¼Ý88,000Ãû¸öÈ˵ÄÃô¸ÐÐÅϢй¶¡£¸ÃʼþÓÚ2024Äê5ÔÂ10ÈÕ±»·¢ÏÖ £¬É漰δ¾­ÊÚȨ·ÃÎÊ´æ´¢ÓиöÈËÉí·Ý¡¢Éç»áÄþ¾²ºÅÂë¡¢³öÉúÈÕÆÚ¡¢²ÆÕþÐÅÏ¢¡¢Ò½ÁƼǼ¼°½¡¿µ±£ÏÕÐÅÏ¢µÄϵͳ¡£¾¡¹ÜAccess SportsÒÑѸËÙΪÊÜÓ°ÏìÓû§ÌṩÆÛÕ©±£»¤·þÎñ £¬²¢Ç¿µ÷ÉÐÎÞÖ¤¾Ý±íÃ÷ÐÅÏ¢±»ÀÄÓà £¬µ«³öÓÚ͸Ã÷¶È¿¼ÂÇÈÔ½øÐÐÁËÈ«ÃæÍ¨±¨¡£ÖµµÃ×¢ÒâµÄÊÇ £¬Ò»¸öÃûΪInc RansomµÄÀÕË÷Èí¼þ×éÖ¯Ðû³Æ¶Ô´Ë´Î¹¥»÷ÂôÁ¦ £¬²¢ÔÚÆäйÃÜÍøÕ¾ÉϹûÈ»ÁËAccess SportsµÄÐÅÏ¢ £¬°üÂÞºÏͬ¡¢Ô±ÈËΪÁÏ¡¢»úÃÜÎļþ¼°²ÆÕþÊý¾Ý £¬½øÒ»²½¼Ó¾çÁËÊÂ̬µÄÑÏÖØÐÔ¡£Inc Ransom×Ô2023Äê7ÔÂÒÔÀ´ £¬±ãÒÔÒ½ÁÆ¡¢½ÌÓý¼°Õþ¸®²¿ÃÅΪĿ±ê £¬Í¨¹ý¼ÓÃÜÊý¾ÝºÍÇÔÈ¡Ãô¸ÐÐÅÏ¢À´ÀÕË÷Êê½ð¡£


https://www.securityweek.com/88000-impacted-by-access-sports-data-breach-resulting-from-ransomware-attack/