CleoÎļþ´«ÊäÈí¼þÁãÈÕ©¶´ÔâºÚ¿ÍÀûÓýøÐÐÊý¾Ý͵ÇÔ¹¥»÷

Ðû²¼Ê±¼ä 2024-12-12

1. CleoÎļþ´«ÊäÈí¼þÁãÈÕ©¶´ÔâºÚ¿ÍÀûÓýøÐÐÊý¾Ý͵ÇÔ¹¥»÷


12ÔÂ10ÈÕ £¬ºÚ¿ÍÕýÔÚ»ý¼«ÀûÓÃCleo¹ÜÀíÎļþ´«ÊäÈí¼þÖеÄз¢ÏÖµÄÁãÈÕ©¶´ £¬ÇÖÈëÈ«ÇòÊýǧ¼Ò¹«Ë¾ÍøÂç £¬°üÂÞTarget¡¢ÎÖ¶ûÂêµÈÖªÃûÆóÒµ £¬½øÐÐÊý¾Ý͵ÇÔ¹¥»÷ ¡£¸Ã©¶´´æÔÚÓÚCleo LexiCom¡¢VLTraderºÍHarmony²úÎïÖÐ £¬ÔÊÐí²»ÊÜÏÞÖÆµÄÎļþÉÏ´«ºÍÏÂÔØ £¬µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ ¡£¾¡¹ÜCleo֮ǰÒÑÐÞ¸´ÁËÒ»¸öÏà¹ØÂ©¶´CVE-2024-50623 £¬µ«ÍþвÐÐΪÕßÈÔÈÆ¹ýÁËÐÞ¸´¼ÌÐø¹¥»÷ ¡£ÍøÂçÄþ¾²×¨¼ÒÖ¸³ö £¬ÕâЩ¹¥»÷ÓëеÄTermiteÀÕË÷Èí¼þÍÅ»ïÓйØ ¡£HuntressÄþ¾²Ñо¿ÈËÔ±Ê״η¢ÏÖÁ˸é¶´µÄÖ÷¶¯¹¥»÷ £¬²¢¾¯¸æÓû§½ÓÄɽô¼±Ðж¯ £¬°üÂÞ½«ÏµÍ³ÒƵ½·À»ðǽºóÃæ £¬ÏÞÖÆÍⲿ·ÃÎÊ £¬²¢¼ì²é¿ÉÒÉÎļþ ¡£CleoÒÑÈ·ÈÏ©¶´´æÔÚ £¬²¢ÕýÔÚ¿ª·¢Äþ¾²¸üР£¬Í¬Ê±ÌṩÁË»º½â´ëÊ©½¨Òé ¡£¾ÝÔ¤¼Æ £¬ÃÀ¹úÓоø´ó¶àÊýÒ×Êܹ¥»÷µÄ·þÎñÆ÷ £¬È«Çò·¶Î§ÄÚÒÑÓÐÖÁÉÙÊ®¸ö×éÖ¯Êܵ½Ó°Ïì ¡£


https://www.bleepingcomputer.com/news/security/new-cleo-zero-day-rce-flaw-exploited-in-data-theft-attacks/


2. AppLite Banker¶ñÒâÈí¼þÒÔÒøÐÐÓ¦Ó÷¨Ê½ÎªÄ¿±êÌá³«ÍøÂçµöÓã»î¶¯


12ÔÂ10ÈÕ £¬Ò»³¡ÅÓ´óµÄÍøÂçµöÓã»î¶¯ÕýÔÚÁ÷´«ÃûΪAppLite BankerµÄжñÒâÈí¼þ±äÖÖ £¬¸Ã¶ñÒâÈí¼þ±»Ê¶±ðΪAntidotÒøÐÐľÂíµÄ¸üа汾 £¬Ö÷ÒªÕë¶ÔAndroidÉ豸 ¡£¹¥»÷Õßͨ¹ýð³äÖªÃû¹«Ë¾ÕÐÆ¸ÈËÔ±»òÈËÁ¦×ÊÔ´´ú±í £¬·¢ËÍÍøÂçµöÓãµç×ÓÓʼþÒýµ¼Óû§ÏÂÔØÆÛÕ©ÐÔCRMÓ¦Ó÷¨Ê½ £¬½ø¶ø°²×°AppLite¶ñÒâÈí¼þ ¡£¸Ã¶ñÒâÈí¼þÄÜÖ´ÐÐÆ¾Ö¤ÍµÇÔ¡¢ÀÄÓÃÎÞÕϰ­·þÎñ¡¢Ô¶³Ì¿ØÖÆ¡¢ÆÛÆ­ÐÔÁýÕֵȶàÖÖ¶ñÒâ»î¶¯ £¬²¢Õë¶Ô172¸öÓ¦Ó÷¨Ê½ £¬°üÂÞ½ðÈÚÆ½Ì¨ºÍ¼ÓÃÜÇ®°ü ¡£ÎªÈƹý¼ì²â £¬AppLiteʹÓÃZIPÎļþ²Ù×÷ºÍǶÈëHTMLÁýÕÖ²ã»ìÏýÄþ¾²¹¤¾ß ¡£¸Ã¶ñÒâÈí¼þ¹¥»÷·¶Î§¹ã·º £¬Éæ¼°¶àÖÖÓïÑÔÓû§ £¬²¢ÄÜÇÔÈ¡ËøÆÁƾ֤×Ô¶¯½âËøÆÁÄ» £¬ÊµÏÖÍêÈ«¿ØÖÆÊÜѬȾÉ豸 ¡£Äþ¾²Ñо¿ÈËԱǿµ÷Ö÷¶¯·ÀÓùÖØÒªÐÔ £¬½¨Òéʵʩǿ´óµÄÒÆ¶¯É豸¹ÜÀíÕþ²ß²¢¶¨ÆÚ¸üÐÂÉ豸ºÍÄþ¾²Èí¼þÒÔ·À·¶´ËÀàÍþв ¡£


https://www.infosecurity-magazine.com/news/applite-malware-targets-banking/


3. Microsoft 365Öжϵ¼Ö Office WebÓ¦Ó÷¨Ê½ºÍ¹ÜÀíÖÐÐÄ̱»¾


12ÔÂ10ÈÕ £¬Î¢ÈíÕýÔÚÊÓ²ìÒ»ÆðÓ°ÏìOffice WebÓ¦ÓúÍMicrosoft 365¹ÜÀíÖÐÐĵĴóÃæ»ýÇÒÁ¬ÐøµÄMicrosoft 365ÖжÏʼþ ¡£Óû§³ÂËßÔÚÁ¬½ÓOutlook¡¢OneDriveºÍÆäËûOffice 365Ó¦Ó÷¨Ê½ºÍ·þÎñʱ·ºÆðÎÊÌâ £¬²¢ÊÕµ½·þÎñÖжϵÄÏûÏ¢ ¡£Î¢ÈíÖ¸³ö £¬ÎÊÌâ¿ÉÄÜÓëÉí·ÝÑéÖ¤»ù´¡ÉèÊ©ÖеÄÁîÅÆÉú³ÉÓйØ £¬²¢ÕýÔÚÉó²é×î½üµÄ±ä»¯ÒÔÈ·¶¨»ù´¡Ô­Òò ¡£×÷Ϊ½â¾öÒªÁì £¬Î¢Èí½¨ÒéÊÜÓ°ÏìµÄÓû§Ê¹ÓÃ×ÀÃæÓ¦Ó÷¨Ê½·ÃÎÊMicrosoft 365Ó¦Ó÷¨Ê½ºÍÎĵµ ¡£´Ëǰ £¬Microsoft 365Ò²Ôø·¢Éú¹ýÈ«ÇòÖжÏʼþ £¬°üÂÞÓ°Ïì¶àÏî·þÎñºÍ¹¦Ð§µÄÇé¿ö ¡£¶øÔÚ7Ô £¬Ò»´Î´ó¹æÄ£ÖжÏÔòÊÇÓÉÂþÑÜʽ¾Ü¾ø·þÎñ£¨DDoS£©¹¥»÷ÒýÆðµÄ ¡£Ä¿Ç° £¬Î¢ÈíÕýÔÚ²âÊÔÒ»¸öDZÔÚµÄÐÞ¸´·¨Ê½ £¬²¢ÒѲ¿ÊðÁËÒ»¸öÐÞ¸´·¨Ê½ÒÔ»º½âÖжÏÎÊÌâ ¡£Î¢ÈíÌåÏÖ £¬´Ë´ÎÖжÏÊÇÓÉÓÚ×î½üµÄ·þÎñ±ä»»µ¼ÖÂʶ±ðÁîÅÆµ½ÆÚʱ¼ä·ºÆðÎÊÌâ £¬´Ó¶øµ¼ÖÂÉí·ÝÑéÖ¤ÇëÇóʧ°Ü ¡£¾­¹ýÒ»¶Îʱ¼äµÄ¼à¿Ø·þÎñÒ£²âºó £¬¸Ã¹«Ë¾È·ÈϸÃÎÊÌâÏÖÒѽâ¾ö ¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-365-outage-takes-down-office-web-apps-admin-center/


4. MetaÆìÏÂËÄ´óÉ罻ƽ̨ÔâÈ«Çò·¶Î§¹¥»÷Ö·þÎñÖжÏ


12ÔÂ11ÈÕ £¬È«Çò·¶Î§ÄÚµÄFacebook¡¢Instagram¡¢ThreadsºÍWhatsAppÔâÊÜÁËÑÏÖØ¹¥»÷ £¬µ¼Ö·þÎñÖжÏ £¬²îÒìµØÓòµÄÓû§Êܵ½Á˲îÒìˮƽµÄÓ°Ïì ¡£¾ÝDownDetector³Æ £¬ÖжϷ¢ÉúÔÚÃÀ¹ú¶«²¿Ê±¼äÏÂÎç12:40×óÓÒ £¬Ðí¶àÓû§ÎÞ·¨Í¨¹ýÍøÕ¾ºÍÓ¦Ó÷¨Ê½·ÃÎÊÕâЩ·þÎñ £¬Ò²ÎÞ·¨Í¨¹ýWhatsApp·¢ËÍÏûÏ¢ ¡£µ±Óû§ÊµÑé·ÃÎÊFacebookʱ £¬»áÊÕµ½´íÎóÌáʾ ¡£ËäÈ»MetaµÄÒµÎñÆ½Ì¨×´Ì¬Ò³ÃæÃ»ÓÐÏÔʾ´ó¹æÄ£·þÎñÖжÏ £¬µ«MetaÈÏ¿ÉÁËÖжϵķ¢Éú £¬²¢ÌåÏÖÕýÔÚŬÁ¦»Ö¸´·þÎñ ¡£²¿ÃŵØÓòµÄ·þÎñÔÚÃÀ¹ú¶«²¿Ê±¼äÏÂÎç1:20×óÓÒ¿ªÊ¼»Ö¸´ £¬µ«ÈÔÓÐÓû§³ÂËßÎÞ·¨·ÃÎÊÆ½Ì¨ ¡£´Ëǰ £¬MetaÔøÔÚ3Ô·ݺÍ2021ÄêÔâÓö¹ýÀàËÆµÄ·þÎñÖжÏ ¡£½ØÖÁÃÀ¹ú¶«²¿Ê±¼ä12ÔÂ11ÈÕÏÂÎç7:21 £¬MetaÌåÏÖÖжÏÎÊÌâÒÑ»ù±¾½â¾ö £¬²¢ÏòÊÜÓ°ÏìµÄÓû§ÌåÏÖǸÒâ ¡£


https://www.bleepingcomputer.com/news/technology/facebook-instagram-whatsapp-hit-by-massive-worldwide-outage/


5. ¹ú¼ÊÐж¯¡°Operation PowerOFF¡±ÖØÈ­¹¥»÷DDoS³ö×â·þÎñ


12ÔÂ11ÈÕ £¬¹ú¼ÊÐж¯¡°Operation PowerOFF¡±Õë¶ÔÍøÂç·¸×ïÖеÄÂþÑÜʽ¾Ü¾ø·þÎñ£¨DDoS£©¹¥»÷È¡µÃÁËÏÔÖø½á¹û ¡£À´×Ô15¸ö¹ú¼ÒµÄÖ´·¨»ú¹¹ºÏ×÷ £¬ÀÖ³ÉÏÂÏßÁË27¸öDDoS³ö×â·þÎñƽ̨ £¬´þ²¶ÁËÈýÃû¹ÜÀíÔ± £¬²¢È·¶¨ÁËÕâЩƽ̨µÄ300Ãû¿Í»§ ¡£ÕâЩƽ̨ÀûÓý©Ê¬ÍøÂç¶ÔÔÚÏßÄ¿±êÌᳫ¹¥»÷ £¬¿ÉÄܵ¼Ö·þÎñÖжϺÍÒµÎñËðʧ £¬ÌرðÊÇÔÚÍøÉϹºÎïá¯ÁëÆÚ ¡£Å·ÖÞÐ̾¯×é֯Эµ÷ÁË´Ë´ÎÐж¯ £¬Éæ¼°¶à¸ö¹ú¼Ò £¬Õë¶Ô¼ÓÈë´ËÀà·¸×ïµÄ¸÷¸ö²ãÃæµÄÈËÔ± ¡£ÆäÖÐ £¬ºÉÀ¼¾¯·½´þ²¶ÁËËÄÃûÉæÏÓʵʩDDoS¹¥»÷µÄÏÓÒÉÈË £¬²¢È·¶¨ÁËÔ¼200ÃûÉæÏÓʹÓñ»²é»ñDDoS·þÎñµÄºÉÀ¼ÈË ¡£´Ë´ÎÐж¯µÄÀֳɵÃÒæÓÚÅ·ÖÞÐ̾¯×éÖ¯µÄ·ÖÎöÖ§³Ö¡¢¼ÓÃÜ×·×ÙÐÅÏ¢ÒÔ¼°ÁªºÏÍøÂç·¸×ïÐж¯ÌرðÊÂÇé×éר¼ÒµÄЭÖú ¡£´Ëǰ £¬¡°Operation PowerOFF¡±ÒѶÔDDoS×âÁÞÁìÓò½øÐÐÁ˶à´Î¹¥»÷ £¬°üÂÞ²é·â´óÐÍÆ½Ì¨Dstat.ccºÍÈëÇÖ²¢¹Ø±ÕDigitalStress·þÎñ ¡£


https://www.bleepingcomputer.com/news/security/operation-poweroff-shuts-down-27-ddos-for-hire-platforms/


6. Krispy KremeÔâÍøÂç¹¥»÷ £¬Ó°ÏìÔÚÏß¶©¹ººÍÔËÓª


12ÔÂ11ÈÕ £¬ÃÀ¹úÌðÌðȦÁ¬ËøµêKrispy KremeÔÚ2024Äê11ÔÂÔâÊÜÁËÍøÂç¹¥»÷ £¬µ¼ÖÂÆäÔÚÃÀ¹úµÄÔÚÏß¶©¹ºÏµÍ³ÖжÏ £¬Ó°ÏìÁ˲¿ÃÅÒµÎñÔËÓª ¡£¸Ã¹«Ë¾ÓµÓÐ1,521¼ÒÃŵêºÍÖÚ¶àÔ±¹¤ £¬²¢ÓëÂóµ±À͵ȺÏ×÷»ï°éÓлý¼«¹ØÏµ ¡£Êý×Ö¶©µ¥Õ¼¹«Ë¾ÏúÊÛ¶îµÄ15.5% £¬¶Ô¹«Ë¾Òµ¼¨ÓÐÖØÒªÓ°Ïì ¡£ÔÚ¹¥»÷·¢Éúºó £¬Krispy KremeÁ¢¼´Ñ°Çó¶¥¼âÍøÂçÄþ¾²×¨¼ÒµÄ×ÊÖú £¬²¢½ÓÄÉ´ëÊ©¿ØÖƺ͵÷ͣʼþ £¬µ«ÊÓ²ìÈÔÔÚ½øÐÐÖÐ £¬¾ßÌåÓ°ÏìÉдýÆÀ¹À ¡£´Ë´Î¹¥»÷¶Ô¹«Ë¾µÄÒµÎñ·¢ÉúÁËÖØ´óÓ°Ïì £¬²¢½«Á¬Ðøµ½»Ö¸´Íê³ÉΪֹ ¡£Í¬Ê± £¬¹«Ë¾Ô¤¼ÆÊý×ÖÏúÊÛÊÕÈëµÄËðʧ¡¢ÍøÂçÄþ¾²×¨¼ÒºÍÕÕÁϵÄÓöÈÒÔ¼°ÏµÍ³»Ö¸´ÊÂÇéÏà¹ØµÄ³É±¾½«·¢ÉúÖØ´óµÄ²ÆÕþÓ°Ïì ¡£Êг¡¶Ô´ËÏûÏ¢×ö³öÁ˸ºÃæ·´Ó³ £¬Krispy KremeµÄ¹É¼ÛϵøÁË2% ¡£Ä¿Ç°Éв»Çå³þÕâÊÇÒ»´ÎÀÕË÷Èí¼þ¹¥»÷»¹ÊÇÆäËûÀàÐ͵Ĺ¥»÷ £¬Ò²Ã»ÓÐÀÕË÷Èí¼þ×éÖ¯¶Ô´Ë´Î¹¥»÷ÂôÁ¦ ¡£


https://www.bleepingcomputer.com/news/security/krispy-kreme-cyberattack-impacts-online-orders-and-operations/