Ó¢¹ú¾üÊÂÊý¾Ýй¶ÌáÐѹú·À²¿ÃÅ´æÔÚµÚÈý·½·çÏÕ

°ä²¼¹¦·ò 2024-05-10
1. Ó¢¹ú¾üÊÂÊý¾Ýй¶ÌáÐѹú·À²¿ÃÅ´æÔÚµÚÈý·½·çÏÕ


5ÔÂ9ÈÕ £¬Õâ´Îй¶ÊÂÎñ¶³öÁ˳¬¹ý 225,000 ÃûÓ¢¹ú¾üÊÂÈËÔ±µÄÊý¾Ý £¬Í¹ÏÔÁËÓë¹ú·ÀʵÌå±í²¿³Ð°üÉÌÓйصÄÈ«Çò°²È«·çÏÕ¡£Õâ´ÎÆØ¹âÓÚ±¾ÖÜÆØ¹â £¬Ô´ÓÚÒ»ÃûÍþвÐÐΪÕß´ÓÒ»¼Ò¹«Ë¾»ñÈ¡ÁËÓ¢¹ú½¾ü¡¢Ë®Ê¦ºÍ»Ê¼Ò¿Õ¾üÏÖÈΡ¢Ç°ÈκÍÔ¤±¸ÒÛ³ÉÔ±µÄÐÕÃû¡¢ÒøÐÐÕË»§¾ßÌåÐÅÏ¢ºÍÆäËûÐÅϢΪӢ¹ú¹ú·À²¿ (MoD) ´¦ÖÃн×Ê·þÎñ¡£BBCºÍÆäËûÓ¢¹úýÌåÈ·ÈÏ±í²¿³Ð°üÉÌΪ Shared Services Connected Ltd £¬²¢°µÊ¾±»ÈëÇÖµÄн×ÊϵͳÔ̺¬¶àÄêǰµÄ¾üÊÂÈËÔ±ÐÅÏ¢¡£Ó¢¹ú¹ú·À´ó³¼¸ñÀ¼ÌØ¡¤É³ÆÕ˹ÔÚÏòÒé»áÒéÔ±°ä·¢µÄÆÀÂÛÖÐÖ¸³ö £¬Õâ´ÎÏ®»÷ÊÇ¡°¶ñÒâÐÐΪÕß¡±ËùΪ £¬ºÜ¿ÉÄܵõ½ÁËÃñ×å¹ú¶ÈµÄÖ§³Ö¡£Ö»¹ÜһЩ¸ß¼¶µ±¾Ö¹ÙÔ±Ö¸³öÖйúÊÇ×îÓпÉÄܵÄÏÓÒÉÈË £¬µ«É³ÆÕ˹×Ô¼º²¢Ã»Óн«Õâ´ÎÏ®»÷¹é×ïÓÚÈκÎÈ˵ÄÃû×Ö¡£´ËÀàÎ¥¹æÐÐΪ͹ÏÔÁË±í²¿³Ð°üÉÌÏòÏëÒªÕë¶Ô¾üʺ͹ú·ÀÊý¾ÝºÍϵͳµÄ¹¥»÷ÕßÌá³öµÄ´àÈõÈõµã¡£


https://www.darkreading.com/cyberattacks-data-breaches/breach-of-uk-military-personnel-data-a-reminder-of-third-party-risk-in-defense-sector


2. LOCKBIT ÍÅ»ïÐû³Æ¶ÔÍþÆæÍÐÊÐÏ®»÷ÊÂÎñÕÆ¹Ü


5ÔÂ8ÈÕ £¬LockBit ÀÕË÷Èí¼þ×éÖ¯Òѽ«ÍþÆæÍÐÊÐÔö³¤µ½Æä Tor й¶վµã £¬²¢ÍþвҪ°ä²¼±»µÁÊý¾Ý¡£ÍþÆæÍÐÊÇÃÀ¹ú¿°ÈøË¹ÖÝÈ˶¡×î¶àµÄ³ÇÊÐ £¬Ò²ÊÇÈûÆæÍþ¿ËÏØµÄÏØ³Ç¡£½ØÖÁ2020ÄêÈ˶¡ÆÕ²é £¬¸ÃÊÐÈ˶¡Îª397,532ÈË¡£°²È«·ì϶²úÉúÓÚ 2024 Äê 5 Ô 5 ÈÕ £¬Êе±¾ÖÁ¢¼´Æô¶¯ÊÂÎñÏìÓ¦·¨Ê½ £¬ÒÔÔ¤·ÀÍþÐ²ÊæÕ¹¡£¸ÃÊÐÔÚµÚÈý·½°²È«×¨¼ÒÒÔ¼°Áª¹úºÍ´¦Ëù·¨ÂÉ»ú¹¹µÄÔ®ÊÖϵ÷²é²¢¶ôÔìÕâÒ»ÊÂÎñ¡£¡°³öÓÚ²Ù×÷°²È«µÄÖ÷ÕÅ £¬Õâ¸ö[Ðû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹ÜµÄ×éÖ¯µÄÃû³Æ²»»á±»¹²Ïí¡£¡±»ã±¨Ö¸³ö¡£È»¶ø £¬LockBit ÀÕË÷Èí¼þÍÅ»ïÐû³Æ¶ÔÍþÆæÍÐÊеÄÍøÂç¹¥»÷ÕÆ¹Ü¡£Ö§¸¶Êê½ðµÄ½ØÖ¹ÈÕÆÚÊÇ 2024 Äê 5 Ô 15 ÈÕ¡£


https://securityaffairs.com/162910/cyber-crime/city-of-wichita-lockbit-ransomware.html


3. ´ÓÀ¬»øÓʼþµ½ AsyncRAT £¬¸ú×Ù·ÇPEÍøÂçÍþвµÄ¼¤Ôö


5ÔÂ8ÈÕ £¬AsyncRAT £¬Ò²³ÆÎª¡°Òì²½Ô¶³Ì½Ó¼ûľÂí¡± £¬ÊÇÒ»Öָ߶ȸ´ÔӵĶñÒâÈí¼þ±äÌå £¬¾­¹ý¾«ÐÄÉè¼Æ £¬Ö¼ÔÚ·ÛËéÍÆËã»úϵͳ°²È«²¢ÇÔÈ¡»úÃÜÊý¾Ý¡£Âõ¿Ë·Æ³¢ÊÔÊÒ×î½ü·¢ÏÖÁËÒ»ÖÖÐÂÐÍϰȾÁ´ £¬½ÒʾÁËÆä׳´óµÄɱÉËÁ¦¼°ÆäѡȡµÄ¸÷ÀలȫÅÔ·»úÔì¡£ËüÀûÓöàÖÖÎļþÀàÐÍ £¬ÀýÈç PowerShell¡¢Windows ¾ç±¾Îļþ (WSF)¡¢VBScript (VBS) ÒÔ¼°¶ñÒâ HTML ÎļþÖÐµÄÆäËûÎļþÀàÐÍ¡£ÕâÖÖ¶à·½ÃæµÄ²½ÖèÖ¼ÔÚ¶ã±Ü·À²¡¶¾¼ì²â²½Öè²¢ÍÆ½øÏ°È¾µÄ´«²¼¡£Ï°È¾ÊÇͨ¹ýÔ̺¬ HTML Ò³Ãæ¸½¼þµÄÀ¬»øÓʼþÆô¶¯µÄ¡£ÔÚÎÞÒâÖдò¿ª HTML Ò³ÃæÊ± £¬»á×Ô¶¯ÏÂÔØ Windows ¾ç±¾Îļþ (WSF)¡£¸Ã WSF ÎļþµÄ¶¨Ãû·½Ê½ÓÐÒⰵʾ¶©µ¥ ID £¬´Ó¶øÓªÔìºÏ·¨ÐԵļÙÏó²¢ÓÕʹÓû§Ö´ÐÐËü¡£Ö´ÐÐ WSF Îļþºó £¬Ï°È¾»á×Ô¶¯½øÐÐ £¬ÎÞÐè½øÒ»²½µÄÓû§¹ýÎÊ¡£Ï°È¾Á´µÄºóÐø½×¶ÎÔ̺¬ Visual Basic ¾ç±¾ (VBS)¡¢JavaScript (JS)¡¢Åú´¦Öà (BAT)¡¢Îı¾ (TXT) ºÍ PowerShell (PS1) ÎļþµÄ²¿Êð¡£×îÖÕ £¬¸ÃÁ´×îÖÕµ¼ÖÂÕë¶Ô aspnet_compiler.exe µÄ¹ý³Ì×¢Èë¡£


https://www.mcafee.com/blogs/other-blogs/mcafee-labs/from-spam-to-asyncrat-tracking-the-surge-in-non-pe-cyber-threats/


4. еĹí»êʽ̽·Õß¹¥»÷Õë¶ÔÓ¢ÌØ¶û CPU


5ÔÂ8ÈÕ £¬×êÑÐÈËÔ±·¢ÏÖÁËÁ½ÖÖÕë¶Ô¸ß»úÄÜÓ¢ÌØ¶û CPU µÄÐÂÏʹ¥»÷²½Öè £¬¿ÉÀûÓÃÕâЩ²½Öè¶Ô¸ß¼¶¼ÓÃÜ³ß¶È (AES) Ëã·¨ÌáÒéÃÜÔ¿¸´Ô­¹¥»÷¡£ÕâЩ¼¼Êõ±»À´×Ô¼ÓÖÝ´óѧʥµØÑǸç·ÖУ¡¢ÆÕ¶É´óѧ¡¢±±¿¨ÂÞÀ´ÄÉ´óѧ½ÌÌÃɽ·ÖУ¡¢×ôÖÎÑÇÀí¹¤Ñ§ÔººÍ¹È¸èµÄÒ»×éѧÕßͳ³ÆÎªÌ½Â·Õß¡£Spectre ÊÇÒ»Àà²àͨ·¹¥»÷µÄÃû³Æ £¬ÕâЩ¹¥»÷ÀûÓÃÏÖ´ú CPU ÉϵķÖÖ§Ô¤²âºÍ´§Ä¦Ö´ÐÐÀ´¶ÁÈ¡ÄÚ´æÖеÄÌØÈ¨Êý¾Ý £¬´Ó¶øÈƹýÀûÓ÷¨Ê½Ö®¼äµÄ¸ôÀë±£»¤¡£×îÐµĹ¥»÷²½ÖèÕë¶ÔµÄÊÇ·ÖÖ§Ô¤²âÆ÷ÖгÆÎªõè¾¶º¹Çà¼Ä·ÅÆ÷ ( PHR ) µÄÖ°ÄÜ£¨¸ÃÖ°Äܱ£Áô×îºóѡȡµÄ·ÖÖ§µÄ¼Í¼£© £¬ÒÔÓÕ·¢·ÖÖ§ÃýÎóÔ¤²â²¢µ¼ÖÂÊܺ¦Õß·¨Ê½Ö´ÐзÇÔ¤ÆÚµÄ´úÂëõè¾¶ £¬´Ó¶øÎÞÒâÖж³öÆä»úÃÜÊý¾Ý¡£¾ßÌåÀ´Ëµ £¬ËüÒýÈëÁËеÄÔ­Óï £¬Äܹ»°Ñ³Ö PHR ÒÔ¼°Ç°Ìá·ÖÖ§Ô¤²âÆ÷ (CBR) ÄÚµÄÔ¤²âº¹Çà±í (PHT) £¬ÒÔй©º¹ÇàÖ´ÐÐÊý¾Ý²¢×îÖÕ´¥·¢ Spectre ʽ·ì϶¡£ÔÚ×êÑÐÖиÅÊöµÄÒ»×éÑÝʾÖÐ £¬ÎÒÃÇ·¢Ïָò½ÖèÄܹ»ÓÐЧµØÌáÈ¡°ÂÃØ AES ¼ÓÃÜÃÜÔ¿ÒÔ¼°ÔÚ¿í·ºÊ¹ÓÃµÄ libjpeg ͼÏñ¿â´¦Öùý³ÌÖÐй¶°ÂÃØÍ¼Ïñ¡£


https://thehackernews.com/2024/05/new-spectre-style-pathfinder-attack.html


5. ¡¶×îÖÕ¿ÕÏë¡·ÓÎÏ··þÎñÆ÷Ôâ·êÂÅ´Î DDoS ¹¥»÷


5ÔÂ8ÈÕ £¬ÓÉÓÚһϵÁгÖÐøµÄ DDoS ¹¥»÷ £¬´óÁ¿À¬»øÁ÷Á¿¸²Ã»ÁËÈȵãÊÓÆµÓÎϷϵÁÓ×¶×îÖÕ¿ÕÏë¡·µÄ·þÎñÆ÷ £¬±¾ÖÜÍæ¼ÒµÇ¼ʱÓöµ½ÁËÎÊÌâ¡£¡¶×îÖÕ¿ÕÏë 14¡·µÄ³õ´Î¹¥»÷´ÓÖÜһ·ͷ £¬³ÖÐøÁ˳¬¹ý 24 Ó×ʱ £¬Ó°ÏìÁËÊÀ½ç¸÷µØµÄÍæ¼Ò¡£Æäʱ £¬¸ÃÓÎÏ·µÄ¿¯ÐÐÉÌ¡¢ÈÕ±¾Ê·¿ËÍþ¶û°¬Äá¿Ë˹¹«Ë¾°µÊ¾ £¬ÔÚ¡°µ÷²éÕâ´Î¹¥»÷²¢²ÉÈ¡¶Ô²ß¡±¡£È»¶ø £¬ÖܶþµÄ¹¥»÷ÔٴβúÉú £¬ÖÜÈýÈÔÔÚ³ÖÐø £¬µ¼ÖÂÍæ¼ÒµÇ¼ÄÑÌâ £¬²¿ÃÅÅ·ÖÞ¡¢±±ÃÀºÍ´óÑóÖÞµÄÊý¾ÝÖÐÐÄÎÞ·¨½Ó¼û¡£Square Enix ÉÐ佫Õâ´Î¹¥»÷¹é×ïÓÚÈκκڿÍ×éÖ¯¡£¸Ã¹«Ë¾°µÊ¾£º¡°Ëæ×ÅÇé¿öµÄ·¢Õ¹ £¬½«Ìṩ¸ü¶àÐÅÏ¢¡£¡±µ±ÓÎÏ··þÎñÆ÷³öÏÖÏνÓÎÊÌâ»ò×ÌÈÅʱ £¬Í¨³£»á³öÏÖ90002 ÃýÎó¡£


https://therecord.media/final-fantasy-game-ddos-incident-square-enix


6. ºÚ¿ÍÀÄÓÃGoogleËÑË÷¸æ°×´«²¼MSI´ò°üµÄ¶ñÒâÈí¼þ


5ÔÂ8ÈÕ £¬ÈËÃÇ·¢ÏÖºÚ¿ÍÀûÓÃGoogle ËÑË÷¸æ°×ͨ¹ý MSI£¨Î¢Èí×°Ö÷¨Ê½£©°ü´«²¼¶ñÒâÈí¼þ¡£¸Ã»î¶¯Éæ¼°ÃûΪ FakeBat µÄ¶ñÒâÈí¼þ¼ÓÔØ·¨Ê½ £¬Í¨¹ý¼Ù×°³ÉºÏ·¨Èí¼þÏÂÔØÀ´¶Ô×¼ºÁÎÞ½äÐĵÄÓû§¡£¹¥»÷´Ó¿´ËƺϷ¨µÄ¹È¸èËÑË÷¸æ°×ÆðÍ· £¬Ê¹ÓÃÁË Notion µÈÊ¢ÐÐÈí¼þµÄÕæÊµÍøÕ¾µØÖ·¡£È»¶ø £¬ÕâÔò¸æ°×Ö»ÊÇÒ»¸ö»Ï×Ó £¬ÊÇÓÉÒ»ÏòʹÓÃÓë¹þÈø¿Ë˹̹ÓйصÄÉí·ÝµÄÍþвÐÐΪÕ߲ɰìµÄ¡£¾ÝThreatDown±¨Â· £¬ºÚ¿ÍÔÚʹÓà Google ËÑË÷¸æ°×À´´«²¼´øÓÐ MSI µÄ¶ñÒâÈí¼þ¡£µã»÷¸æ°×»á½øÈëÒ»¸öÒÔºýŪÐÔ URL ÍйܵÄÍøÂç´¹µöÍøÕ¾ £¬ÓëÕæÊµÍøÕ¾ÀàËÆ¡£¸ÃÍøÕ¾ÌáÐÑÓû§ÏÂÔØMSIX ÌåʽµÄ³ß¶ÈÈí¼þ×°Ö÷¨Ê½ £¬²¢ÒÔ¿´ËÆ¿ÉÐŵÄÃû³Æ¡°Forth View Designs Ltd¡±ÊðÃû¡£¸Ã»î¶¯ÀûÓõã»÷¸ú×Ù·þÎñÀ´ÖÎÀí¸æ°×µÄÓÐЧÐÔ²¢¹ýÂ˵ô²»±ØÒªµÄÁ÷Á¿¡£


https://gbhackers.com/abuse-google-search-ads/#google_vignette