¶íÀÕ¸ÔÖݶ¯ÎïÔ°ÊÛÆ±·þÎñÔâºÚ¿Í¹¥»÷ £¬11.8ÍòÓû§ÐÅÏ¢±»µÁ

°ä²¼¹¦·ò 2024-08-21
1. ¶íÀÕ¸ÔÖݶ¯ÎïÔ°ÊÛÆ±·þÎñÔâºÚ¿Í¹¥»÷ £¬11.8ÍòÓû§ÐÅÏ¢±»µÁ


8ÔÂ19ÈÕ £¬¶íÀÕ¸ÔÖݶ¯ÎïÔ°½üÆÚ²úÉúÁËһ·ÑϳÁµÄÊý¾Ýй¶ÊÂÎñ £¬Ô¼118,000ÃûÓû§µÄÓ×ÎÒÐÅÏ¢ºÍÖ§¸¶¿¨Êý¾ÝÔÚ2023Äê12ÔÂ20ÈÕÖÁ2024Äê6ÔÂ26ÈÕÆÚ¼äµÄÔÚÏßÊÛÆ±·þÎñÖб»µÁ¡£ÕâЩÐÅÏ¢Ô̺¬ÐÕÃû¡¢Ö§¸¶¿¨ºÅ¡¢CVV°²È«Âë¼°µ½ÆÚÈÕÆÚ £¬¶ÔÊܺ¦Õß×é³ÉDZÔÚ·çÏÕ¡£ÊÂÎñÓÚ6ÔÂ26ÈÕ±»·¢ÏÖºó £¬¶¯ÎïÔ°Á¢¼´Í£ÓÃÁËÊÜÓ°ÏìµÄÍøÕ¾ £¬²¢³ÉÁ¢ÁËÐµİ²È«¹ºÆ±Æ½Ì¨¡£¶¯ÎïÔ°ÒÑÏòÃåÒòÖÝ×ܼì²ì³¤°ì¹«Êһ㱨 £¬²¢Ïò¿ÉÄÜÊÜÓ°ÏìµÄ117,815ÃûÓû§·¢ËÍÁË֪ͨÐÅ £¬Í¬Ê±ÎªËûÃÇÌṩÁËÒ»ÄêµÄÃâ·ÑÐÅÓþ¼à¿ØºÍÉí·Ý±£»¤·þÎñ¡£¶¯ÎïÔ°°µÊ¾ £¬Õâ´Îй¶ÊÇÓÉÓÚµÚÈý·½¹©¸øÉÌÂòÂô±»ÍþвÕß³Á¶¨ÏòËùÖ £¬²¢ÒÑÏòÁª¹ú·¨Âɲ¿ÃÅ´«µÝ¡£ÎªÔ¤·À½«À´ÀàËÆÊÂÎñ £¬¶¯ÎïÔ°Õý»ý¼«Éó²éÆä°²È«Õþ²ßºÍ·¨Ê½¡£Ö»¹Üδ¹«¿ª¾ßÌå¹¥»÷ÀàÐÍ £¬µ«·ÖÎöÒÔΪ¿ÉÄÜÊÇÍøÂçä¯ÀÀÆ÷ϰȾÁËÊý×ÖÇÔÈ¡Æ÷ £¬ÕâÀà¶ñÒâÈí¼þ³£±»ÓÃÓÚÔÚ½áÕËÒ³ÃæµÈ¹Ø¼üµØÎ»ÇÔÈ¡Óû§Ãô¸ÐÐÅÏ¢¡£


https://www.securityweek.com/oregon-zoo-ticketing-service-hack-impacts-118000/


2. Jewish Home LifecareÔâBlackCatÀÕË÷Èí¼þ¹¥»÷ £¬10ÍòÈËÊý¾Ýй¶


8ÔÂ19ÈÕ £¬Å¦Ô¼ÊеķÇͶ»úÐÔÒ½ÁƱ£½¡×éÖ¯Jewish Home Lifecare£¨ÏÖ³ÆÐÂÓÌÌ«¼ÒÍ¥ÖÐÐÄ£©Åû¶Á˽üÆÚ²úÉúµÄһ·³Á´óÊý¾Ýй¶ÊÂÎñ £¬¸ÃÊÂÎñ²¨¼°³¬¹ý104,000Ãû»¼Õß¼°ÉçÇø³ÉÔ±¡£½ñÄê2Ô £¬¸ÃÖÐÐÄÏòÊÜÓ°Ïì¿Í»§´«µÝ³Æ £¬ÆäÍøÂçÔÚ1ÔÂ7ÈÕÔâ·êÒì³£»î¶¯ £¬ºÚ¿Í¿ÉÄÜÒÑ»ñÈ¡Ô̺¬Ó×ÎÒÉí·ÝÐÅÏ¢¡¢½ðÈÚÕË»§ÏêÇé¡¢Ò½ÁƼͼÔÚÄÚµÄÃô¸ÐÐÅÏ¢¡£ÎªÈ·±£Êܺ¦Õß°²È« £¬ÖÐÐÄÌṩÁËÃâ·ÑµÄÐÅÓþ¼à¿Ø·þÎñ £¬²¢Ç¿µ÷ËäÎÞÖ±½ÓÖ¤¾ÝÅú×¢ÐÅÏ¢Òѱ»ÀÄÓà £¬µ«ÈÔÉóÉ÷°ä²¼Í¨Öª¡£Õâ´Îй¶ÓëÀÕË÷Èí¼þ×éÖ¯BlackCat(Alphv)ÓйØ £¬ËüÃÇÐû³Æ¹¥»÷ÁËJewish Home Lifecare²¢»ñÈ¡ÁËÁÙ´²×êÑÓ×¢²ÆÕþ¼°Ô±¹¤¿Í»§Êý¾Ý £¬ÉõÖÁÉæ¼°¾èÔù×ʽðÀÄÓõÄÖ¤¾Ý¡£È»¶ø £¬±»µÁÎļþÊÇ·ñ¹«¿ªÉдýÈ·ÈÏ £¬ÇÒBlackCat×éÖ¯ÔÚ3Ô³õºöÈ»Òþû £¬ÆäÍøÕ¾ÒÑÎÞ·¨½Ó¼û¡£


https://www.securityweek.com/100000-impacted-by-jewish-home-lifecare-data-breach/


3. BlindEagle£¨APT-C-36£©£ºÀ­¶¡ÃÀÖ޵ijÖÐøÍþв


8ÔÂ20ÈÕ £¬¿¨°Í˹»ù³¢ÊÔÊÒ¶ÔÃûΪBlindEagle£¨ÓÖ½ÐAPT-C-36£©µÄ³ÖÐøÐÔÍþв×éÖ¯·¢³öÖÒ¸æ £¬¸Ã×é֯ר³¤ÓÚÕë¶ÔÀ­¶¡ÃÀÖÞµÄÍøÂç¹¥»÷ £¬BlindEagleÖØÒªÍ¨¹ý¾«ÐÄÉè¼ÆµÄÍøÂç´¹µö»î×÷Ϊ°¸ £¬¼Ùð¹Ù·½»ú¹¹Èç˰Îñ²¿ÃÅ»ò±í½»²¿ £¬ÓÕÆ­Óû§µã»÷¶ñÒâÁ´½Ó £¬ÏÂÔØ¼Ù×°³É¹Ù·½ÎļþµÄѹËõ°ü £¬ÄÚº¬Ö¸ÏòÊܿضñÒâÈí¼þÕ¾µãµÄÁ´½Ó¡£ÕâЩÓʼþÕæÇзÂÕÕ¹Ù·½Í¨Ñ¶ £¬ÀûÓÃURLËõ¶ÌÆ÷ºÍ¶¯Ì¬DNS·þÎñÔö³¤Òñ±ÎÐÔ £¬Æ¾¾ÝÓû§µØÎ»³Á¶¨Ïò £¬ÒÔÌӱܼì²â¡£Ò»µ©Óû§ÖÐÕÐ £¬BlindEagle±ãÆô¶¯¶à½×¶ÎϰȾ £¬²¿ÊðÔ̺¬njRAT¡¢LimeRATµÈ¹«¿ªÔ¶³Ì½Ó¼ûľÂí£¨RAT£© £¬ÕâЩ¹¤¾ß±»¶¨ÔìÒÔÂú×ã·ÖÆç¹¥»÷ÐèÒª £¬ÔÊÐí¸Ã×éÖ¯¼à¿ØÊܺ¦Õß¡¢ÇÔÈ¡Ãô¸ÐÐÅÏ¢¼°²ÆÕþƾ֤¡£BlindEagle»¹ÀûÓùý³Ì×¢Èë¼¼Êõ £¬Èç¹ý³ÌÍÚ¿Õ £¬½«¶ñÒâ´úÂë°µ²ØÓںϷ¨¹ý³ÌÖÐ £¬ÒԴ˶ã±Ü°²È«¼ì²â £¬ÊµÏÖ³Ö¾ÃÂñ·üÓëÊý¾ÝÇÔÈ¡¡£BlindEagleµÄ¹¥»÷Ö¸±êÔ̺¬¸çÂ×±ÈÑÇ¡¢¶ò¹Ï¶à¶û¡¢ÖÇÀûºÍ°ÍÄÃÂíµÄÓ×ÎÒºÍ×éÖ¯ £¬Éæ¼°µ±¾Ö¡¢½ÌÓý¡¢ÎÀÉúºÍ½»Í¨µÈ¸÷¸öÁìÓò¡£


https://securityonline.info/blindeagle-apt-group-a-persistent-threat-in-latin-america/


4. ΢о¿Æ¼¼Ôâ·êÍøÂç¹¥»÷ £¬²¿ÃÅÒµÎñÊÜÓ°Ïì


8ÔÂ21ÈÕ £¬ÃÀ¹ú°ëµ¼ÌåÔì×÷ÉÌ΢о¿Æ¼¼Microchip½üÆÚÔâ·êÁËÒ»Â·ÍøÂ簲ȫÊÂÎñ £¬¶Ô¹«Ë¾ÔËÓªÔì³ÉÁËÏÔÖøÓ°Ïì¡£¾Ý¸Ã¹«Ë¾Ð¹Â© £¬8ÔÂ17ÈÕ £¬Î¢Ð¾¿Æ¼¼µÄÐÅÏ¢¼¼Êõϵͳ±»¼ì²âµ½´æÔÚDZÔڵĿÉÒɻ £¬ËæºóÓÚ8ÔÂ19ÈÕÈ·ÈÏϵͳÒÑÔ⵽δ¾­ÊÚȨµÄ½Ó¼û¡£Ãæ¶ÔÕâÒ»´¹Î£Çé¿ö £¬¹«Ë¾Ñ¸ËÙ²ÉÈ¡Ðж¯ £¬¸ôÀëÁËÊÜÓ°ÏìµÄ·þÎñÆ÷ϵͳ £¬²¢¹Ø¹ØÁË¿ÉÄÜÊܲ¨¼°µÄÆäËûϵͳ £¬Í¬Ê±ÀñƸÁËרҵµÄ±í²¿ÍøÂ簲ȫÕÕ·÷ÍŶÓÀ´È«ÃæÆÀ¹ÀÊÂÎñµÄÑϳÁˮƽ¼°Ó°ÏìÁìÓò¡£Õâ´Î°²È«ÊÂÎñµ¼ÖÂ΢о¿Æ¼¼²¿ÃÅÔì×÷ÉèÊ©µÄÔËӪЧÄܽµÖÁÕý³£Ë®Æ½ÒÔÏ £¬Ö±½ÓÓ°ÏìÁ˹«Ë¾°´Ê±Íƹã¿Í»§¶©µ¥µÄÄÜÁ¦¡£Ö»¹Ü¹«Ë¾ÕýÈ«Á¦ÒÔ¸°½â¾öÕâÒ»ÎÊÌâ £¬²¢³Ðŵ½«¾¡¿ì¸´Ô­Õý³£ÔËÓª £¬µ«Ä¿Ç°¹ØÓÚÊÂÎñµÄ¾ßÌåÔ­Òò¡¢Ð¾Æ¬Ôì×÷ÒµÎñÊÜ×ÌÈŵľßÌåˮƽ £¬ÒÔ¼°ÊÇ·ñÉæ¼°ÀÕË÷Èí¼þµÈÃô¸ÐÐÅÏ¢ £¬ÈÔ´ý½øÒ»´ëÊ©²éÈ·ÈÏ¡£ÖµÍ×ÌùÐĵÄÊÇ £¬Î¢Ð¾¿Æ¼¼²ÉÈ¡¸ôÀë´ëÊ©µÄ×ö·¨Åú×¢ £¬Î´¾­ÊÚȨ·½µÄ»î¶¯¿ÉÄÜÒѳõ²½ÏÔʾ³öÏò¹«Ë¾¸ü¿í·ºIT×ʲúÀ©É¢µÄ¼£Ïó¡£


https://www.theregister.com/2024/08/21/microchip_technology_security_incident/


5. ½Ý¿ËÒÆ¶¯Óû§ÔâPWAÍøÂç´¹µö¹¥»÷


8ÔÂ20ÈÕ £¬½Ý¿Ë¹²ºÍ¹úµÄÒÆ¶¯Óû§ÕýÃæ¶ÔÒ»ÖÖÐÂÐÍÇÒ¸´ÔÓµÄÍøÂç´¹µöÍþв £¬¸ÃÍþвÀûÓý¥½øÊ½WebÀûÓ÷¨Ê½£¨PWA£©¼¼Êõ £¬Õë¶Ô¶à¼ÒÒøÐÐÓû§ÇÔÈ¡ÒøÐÐÕË»§Æ¾Ö¤¡£¾Ý˹Âå·¥¿ËÍøÂ簲ȫ¹«Ë¾ESET»ã±¨ £¬¹¥»÷Ö¸±êÔ̺¬½Ý¿ËµÄCSOBÒøÐÓ×¢ÐÙÑÀÀûµÄOTPÒøÐкϸñ³¼ªÑǵÄTBCÒøÐС£¹¥»÷Õßͨ¹ý×Ô¶¯ÓïÒôµç»°¡¢¶ÌÐż°É罻ýÌå¶ñÒâ¸æ°×É¢²¼´¹µöÁ´½Ó £¬ÓÕµ¼Óû§µã»÷²¢×°Öÿ´ËƺϷ¨µÄÒøÐÐÀûÓ÷¨Ê½PWA»òAndroidÉϵÄWebAPK £¬ÕâЩÀûÓÃÏÕЩÃÀÂú¸´ÔìÁËÕæÊµÒøÐÐÀûÓõĽçÃæ £¬´Ó¶øÈƹýÁË´«Í³ä¯ÀÀÆ÷µÄ°²È«ÖҸ档ֵÍ×ÌùÐĵÄÊÇ £¬¹¥»÷±³ºóÉæ¼°Á½¸ö·ÖÆçµÄÍþвÐÐΪÕß £¬ËûÃÇÀûÓÃChrome WebAPK¼¼ÊõµÄĬÈÏÐÐΪ £¬ÀÄÓøÃÖ°ÄÜÒÔ°µ²Ø¡°À´×Ô²»ÊÜÐÅÀµÆðÔ´µÄ×°Öá±ÖÒ¸æ £¬Ê¹µÃÓû§ÄÑÒÔ¾õ²ì·çÏÕ¡£¶ÔÓÚiOSÓû§ £¬Ôòͨ¹ýÁìµ¼½«Î±ÔìµÄPWAÔö³¤µ½Ö÷ÆÁÄ»À´Ö´Ðй¥»÷¡£Ò»µ©Óû§ÔÚÕâЩÀûÓÃÖÐÊäÈëÒøÐÐÆ¾Ö¤ £¬ÐÅÏ¢±ã»á±»Ð¹Â¶ÖÁ¹¥»÷Õß½ÚÔìµÄºÅÁîÓë½ÚÔ죨C2£©·þÎñÆ÷»òTelegramȺÁÄÖС£ESETÒѼà²âµ½¶à²¨ÀàËÆ»î¶¯¡£


https://thehackernews.com/2024/08/czech-mobile-users-targeted-in-new.html


6. ÐÂÐÍDNSºóÃÅBackdoor.MsupedgeÕë¶Ǫ̂Íå´óѧ


8ÔÂ20ÈÕ £¬Íþв·ÖÎöÈËÔ±½üÆÚÔŲ́Íå´óѧÔâ·êµÄ¹¥»÷Öи淢ÁËÒ»ÖÖÐÂÐͰ²È«ÍþвBackdoor.Msupedge £¬ÓÉÈüÃÅÌú¿Ë¹«Ë¾·¢ÏÖ²¢¶¨Ãû¡£¶ûºóÃÅѡȡÁËÒ»ÖÖº±¼ûµÄDNSͨѶ»úÔì £¬ËäΪÒÑÖª¼¼Êõµ«ÏʼûÓÚÍøÂç·¸×ï»î¶¯ÖС£MsupedgeÒÔDLL´ó¾ÖDZ²ØÓÚÊÜϰȾϵͳµÄÌØ¶¨õè¾¶ £¬Í¨¹ýDNS²éÎʽӹܲ¢Ö´ÐÐÖ¸Áî £¬ÕâÒ»Õ½Êõ²»½ö¶ã±ÜÁËͨÀý¼ì²â £¬»¹ÊµÏÖÁ˶ÔÖ¸±ê»úеµÄÒþÃØ²Ù¿Ø¡£ÓÈΪֵÍ×ÌùÐĵÄÊÇ £¬MsupedgeÄÜÆ¾¾ÝDNS²éÎʽâÎö³öµÄIPµØÖ·ÖеÄÌØ¶¨×Ö½ÚÀ´½Ã½Ýµ÷ÕûÆäÐÐΪ £¬ÈçÆô¶¯¹ý³Ì¡¢ÏÂÔØ¶ñÒâÎļþ¡¢É趨ϵͳÐÝÃßʱ³¤µÈ £¬¼«´ó¼ÓÇ¿ÁËÆä½Ã½ÝÐÔºÍÒñ±ÎÐÔ¡£´Ë±í £¬¸ÃºóÃÅÖ§³Ö¶àÖÖ²Ù×÷Ö¸Áî £¬Ô̺¬»ùÓÚDNS TXT¼Í¼´´½¨¹ý³Ì¡¢´ÓÖ¸¶¨URLÏÂÔØÎļþ¡¢Ê¹ÏµÍ³ÐÝÃß³¤´ï24Ó×ʱ¼°ËãÕʺۼ£µÈ¡£¾ÝÈüÃÅÌú¿Ë·ÖÎö £¬Õâ´ÎÈëÇֵijõʼÈë¿Úµã¼«ÓпÉÄÜÊǽüÆÚÆØ¹âµÄPHP·ì϶£¨CVE-2024-4577£© £¬¸Ã·ì϶Äܵ¼ÖÂWindowsƽ̨ÉϵÄPHP°æ±¾Ô¶³Ì´úÂëÖ´ÐС£ÈüÃÅÌú¿Ë°ä²¼ÁËÏ꾡µÄÈëÇÖÖ¸±ê£¨IOC£© £¬ÒÔЭÖúÓû§¼ø±ðºÍ·ÀÓùBackdoor.MsupedgeµÄ¹¥»÷¡£


https://www.infosecurity-magazine.com/news/dns-based-backdoor-taiwanese/