LinuxÏµÍ³Ãæ¶ÔÐÂÍþв£ºBootkitty UEFIÆô¶¯¹¤¾ß°ü±»·¢ÏÖ

°ä²¼¹¦·ò 2024-11-29

1. LinuxÏµÍ³Ãæ¶ÔÐÂÍþв£ºBootkitty UEFIÆô¶¯¹¤¾ß°ü±»·¢ÏÖ


11ÔÂ27ÈÕ £¬Ò»¿îÃûΪBootkittyµÄLinux¶ñÒâÈí¼þ×÷ΪÊ׸öרÃÅÕë¶ÔLinuxϵͳµÄUEFIÆô¶¯¹¤¾ß°üÒѱ»·¢ÏÖ £¬±ê־ȡ¶ÔWindowsµÄÒþÃØÆô¶¯¹¤¾ß°üÍþвÕý²úÉúת±ä¡£Ö»¹ÜĿǰËü½öÔÚijЩUbuntu°æ±¾ºÍÅäÖÃÉÏÆð×÷Óà £¬ÇÒ´æÔںܶàδʹÓõÄÖ°ÄܺͼæÈÝÐÔÎÊÌâ £¬³£µ¼ÖÂϵͳ±ÀÀ£ £¬µ«Æä´æÔÚ±ê־ȡUEFIÆô¶¯Ì×¼þÍþвÁìÓòµÄÒ»¸ö³Á´ó·¢Õ¹¡£Bootkittyͨ¹ý¹Ò½ÓUEFI°²È«ÈÏÖ¤ºÍ̸ºÍGRUBº¯ÊýÀ´Èƹý°²È«Æô¶¯ºÍÆëÈ«ÐÔÑéÖ¤ £¬´Ó¶ø¼ÓÔØ¶ñÒâ×é¼þ¡£Ëü»¹»áÀ¹½ØLinuxÄں˵Ľâѹ¹ý³Ì²¢¹Ò½ÓÓйغ¯Êý £¬Ê¹¶ñÒâÈí¼þ¿ÉÄܼÓÔØ¶ñÒâÄ£¿é £¬²¢ÔÚϵͳÆô¶¯Ê±×¢Èë¶ñÒâ¿â¡£×êÑÐÈËÔ±Ö¸³ö £¬½«BootkittyÉÏ´«µ½VirusTotalµÄͳһÓû§»¹ÉÏ´«ÁËÒ»¸öÃûΪBCDropperµÄδÊðÃûÄÚºËÄ£¿é £¬µ«Á½ÕßÖ®¼äµÄÁªÏµ½ÏÈõ¡£´ËÀà¶ñÒâÈí¼þµÄ·¢ÏÖÅú×¢ £¬Ëæ×ÅLinuxÔÚÆóÒµÖеı鼰 £¬¹¥»÷ÕßÔÚ¿ª·¢Ö®Ç°½öÏÞÓÚWindowsµÄLinux¶ñÒâÈí¼þ¡£ÓëBootkittyÓйصÄÈëÇÖÖ¸±êÒÑÔÚGitHubÉϹ²Ïí¡£


https://www.bleepingcomputer.com/news/security/researchers-discover-bootkitty-first-uefi-bootkit-malware-for-linux/


2. TorÏîÄ¿´¹Î£ºôÓõ£º²¿Êð¸ü¶àWebTunnelÇÅÆ¥µÐµ±¾ÖÉó²é


11ÔÂ28ÈÕ £¬TorÏîÄ¿½üÆÚÏòÒþÖÔÉçÇø·¢³ö´¹Î£ºôÓõ £¬ÒªÇó×ÔÔ¸ÕßÔÚ2025Äê3ÔÂ10ÈÕǰЭÖú²¿Êð200¸öеÄWebTunnelÇÅ £¬ÒÔÓ¦¶ÔÈÕÒæÑϸñÈ·µ±¾ÖÉó²éÌôÕ½¡£Ä¿Ç° £¬TorÏîÄ¿ÒÑÔËÓª143¸öWebTunnelÇÅ £¬Ô®ÊÖÊÜÉó²éÏ޶ȵØÓòµÄÓû§½Ó¼û»¥ÁªÍø¡£´Ë¾ÙÖØÒªÕë¶Ô¶íÂÞ˹²»ÐݼÓÇ¿µÄÉó²éÔì¶È £¬¸ÃÔì¶ÈÒÑÓ°Ïìä¯ÀÀÆ÷ÄÚÖõÄÉó²é¶ã±Ü»úÔì £¬Èçobfs4ÏνӺÍSnowflake¡£TorÏîÄ¿ÒÔΪ £¬³ÉÁ¢¸ü¶àWebTunnelÇÅÊÇÓ¦¶ÔÉó²éÉý¼¶µÄÓÐЧսÊõ £¬ÓÉÓÚ¿ª·¢Ð½â¾ö¹æ»®±ØÒª¹¦·ò £¬¶øÓû§ÔÚ´ËÆÚ¼ä¿ÉÄÜÃæ¶Ô·çÏÕ¡£WebTunnelsÊÇTorÏîÄ¿ÓÚ2024Äê3ÔÂÍÆ³öµÄÒ»ÖÖÐÂÐÍÇÅÁº £¬Í¨¹ý½«TorÁ÷Á¿ÓëͨÀýÍøÂçÁ÷Á¿»ìºÏ £¬²¢Ê¹Æ÷ÓµÓÐÓÐЧSSL/TLSÖ¤ÊéµÄWeb·þÎñÆ÷¼Ù×°³ÉHTTPSÁ÷Á¿ £¬´Ó¶ø¶ã±ÜÉó²é¡£TorÏîÄ¿Æô¶¯ÁËÒ»Ïîл £¬ºôÓõ×ÔÔ¸Õ߲μӳÉÁ¢ºÍÊØ»¤WebTunnelÇÅ £¬ÉèÁ¢Îå×ù»ò¸ü¶àÇŵÄ×ÔÔ¸Õß½«»ñµÃTÐô×÷Ϊ¸Ð¼¤¡£²Î¼ÓÒªÇóÔ̺¬Ã¿¸öIPv4Ò»¸öÇÅ¡¢ÌṩÓÐЧµç×ÓÓʼþ¡¢Î¬³ÖÇÅÁºÔËÐÐÖÁÉÙÒ»ÄêµÈ¡£×ÔÔ¸ÕßÄܹ»²é¿´¹Ù·½Ö¸ÄÏÏàʶ¸ü¶àÐÅÏ¢²¢²Î¼Ó»î¶¯¡£


https://www.bleepingcomputer.com/news/security/tor-needs-200-new-webtunnel-bridges-to-fight-censorship/


3. Ó¢¹úÍþÀÕ¶û´óѧ½²ÊÚÒ½ÔºÔâÍøÂç¹¥»÷ £¬·þÎñÖжÏÔ¤Ô¼ÍÆ³Ù


11ÔÂ28ÈÕ £¬Ó¢¹úÖØÒªÒ½ÁƱ£½¡ÌṩÉÌÍþÀÕ¶û´óѧ½²ÊÚÒ½Ôº£¨WUTH£© £¬×÷ΪNHS»ù½ð»áµÄÒ»²¿ÃÅ £¬½üÆÚÔâ·êÁËÍøÂç¹¥»÷ £¬µ¼ÖÂϵͳÖжÏ £¬Ô¤Ô¼ºÍÔ¤Ô¼·¨Ê½±»ÆÈÍÆ³Ù¡£WUTHÔËÓª×Ŷà¼ÒÒ½Ôº £¬ÌṩÔ̺¬´¹Î£·þÎñ¡¢¼±ÐÔÒ½ÁÆ·þÎñ¡¢³ÁÖ¢¼à»¤¡¢±í¿Æ¡¢¶ù¿Æ¡¢²ú¿Æ·þÎñºÍ°©Ö¢»¤ÀíÔÚÄÚµÄÈ«ÃæÒ½ÁÆ·þÎñ¡£Õâ´ÎÍøÂç¹¥»÷ʹµÃ²¿ÃÅITϵͳÏÂÏß²¢×ªÎªÊÖ¶¯²Ù×÷ £¬²»³ÉÔ¤·ÀÏßÔì³ÉÁË·þÎñÖжϺÍÑÓÎó¡£Ò½ÔºÒѸ´Ô­ÒµÎñÂ½ÐøÐÔÁ÷³Ì £¬Ê¹ÓÃÖ½ÖÊÎļþ´úÌæÊý×ÖÎļþ £¬µ«´¹Î£Ò½ÖÎµÄÆÚ´ý¹¦·òÓÐËùÔö³¤¡£Ò½Ôº¶½´Ù¹«¼Ò½öÔÚÕæÕý´¹Î£Çé¿öÏÂǰÍù¼¹ØïÊÒ¡£Ä¿Ç° £¬Ò½ÔºÈÔÎÞ·¨¹À¼ÆºÎʱÄܸ´Ô­Õý³£ÔËÓª £¬ÇÒÉÐδÓÐÈκÎÀÕË÷Èí¼þ×éÖ¯¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü¡£¸ÃÒ½ÁÆ»ú¹¹ÉÐδ¶Ô¹¥»÷ÐÔÖÊÌṩ¸ü¶àÐÅÏ¢¡£


https://www.bleepingcomputer.com/news/security/uk-hospital-network-postpones-procedures-after-cyberattack/


4. Å·ÖÞ¶à¹ú½áºÏ½ø¹¥·¸·¨Á÷ýÌåÍøÂç £¬È¡µÞµÁ°æ²¢¼ÓÇ¿ÍøÂç·¸×ï·À±¸


11ÔÂ28ÈÕ £¬Å·ÖÞÐ̾¯×éÖ¯½áºÏ¶à¹ú·¨ÂÉ»ú¹¹ £¬³É¹¦È¡µÞÁËÒ»¸ö·¸·¨Á÷ýÌåÍøÂç £¬¿ÛÁôÁ˽üÊ®¼¸ÃûÉæ°¸ÈËÔ±¡£¸ÃÍøÂçµÁ°æÁ˳¬¹ý2500¸öµçÊÓÆµÂ· £¬ÏòÈ«Çò³¬¹ý2200ÍòÈËÌṩ·þÎñ £¬Ã¿ÄêÔì³É100ÒÚÅ·ÔªµÄËðʧ¡£Å·ÖÞÐ̾¯×éÖ¯ÔÚÐж¯Öе÷²éÁË102ÃûÏÓÒÉÈË £¬²¢Ö¸¿ØÉæ¼°Ï´Ç®ºÍÍøÂç·¸×ï¡£·¨ÂÉ»ú¹¹½øÐÐÁËÂÅ´ÎÍ»»÷²é³­ £¬²é»ñÁË·þÎñÆ÷ºÍIPTVÉ豸 £¬²¢ÔÚͻϮÆÚ¼ä·¢ÏÖÁ˶¾Æ·¡¢±øÆ÷ÒÔ¼°´óÁ¿¼ÓÃÜÇ®±ÒºÍÏÖ½ð¡£Õâ´ÎÐж¯µÃµ½Á˱£¼ÓÀûÑÇ¡¢¿ËÂÞµØÑÇ¡¢·¨¹úµÈ¶à¸öÅ·ÖÞ¹ú¶È·¨ÂÉ»ú¹¹µÄÖ§³Ö £¬Òâ´óÀû¹ÙÔ±³ÆÆäΪ¸Ã¹úÊ·ÉÏ×î´ó¹æÄ£µÄ½ø¹¥ÒôÏñµÁ°æÐж¯¡£´Ë±í £¬Å·ÖÞÐ̾¯×éÖ¯ºÍ¹ú¼ÊÐ̾¯×éÖ¯ÒÑ´òËãÔÚ2024ÄêÔ½·¢»ý¼«×Ô¶¯µØ½ø¹¥ÍøÂç·¸×ï £¬½üÆÚ»¹°ä·¢ÁËÉæ¼°40¶à¸ö¹ú¶ÈµÄ¡°HAECHI¡±Ðж¯ £¬¿ÛÁôÁË5500¶àÃûÏÓÒÉÈË £¬²¢½É»ñÁËÔ¼4ÒÚÃÀÔª¡£¹ú¼ÊÐ̾¯×éÖ¯ÃØÊ鳤°µÊ¾ £¬ÍøÂç·¸×ïµÄºó¹û¿ÉÄÜÊǸ²ÃðÐ﵀ £¬¹ú¼Ê¾¯Ô±ºÏ×÷ÖÁ¹Ø³ÁÒª¡£


https://therecord.media/11-arrested-europol-streaming-shutdown


5. ZelloÒªÇóÀÏÓû§³ÁÖÃÃÜÂë £¬ÒÉÒò°²È«·ì϶


11ÔÂ27ÈÕ £¬ZelloÊÇÒ»ÏîÕ¼ÓÐ1.4ÒÚÓû§µÄÒÆ¶¯·þÎñ £¬½üÆÚÏòÓû§·¢³ö°²È«ÖÒ¸æ £¬ÒªÇóËùÓÐÔÚ2024Äê11ÔÂ2ÈÕ֮ǰ´´½¨µÄÕË»§³ÁÖÃÃÜÂë¡£ÕâÒ»´ëÊ©ËÆºõÊǶÔDZÔÚ°²È«·ì϶µÄÔ¤·À´ëÊ©¡£¶à¶àÓû§ÔÚ11ÔÂ15ÈÕÊÕµ½ÁËÕâһ֪ͨ £¬µ«ZelloδÌṩ½øÒ»²½µÄÐÅÏ¢»òÚ¹ÊÍ¡£Óû§±»Êèµ¼ÖÁÖ§³ÖÒ³ÃæÏàʶÈôºÎ¸ü¸ÄÃÜÂë £¬²¢±»½¨Òé¸ü¸ÄÔÚÆäËûÔÚÏß·þÎñÖпÉÄÜʹÓùýµÄÒ»ÑùÃÜÂë¡£Ö»¹ÜĿǰÉв»Ã÷ÏÔÊÇ·ñ²úÉúÁËÊý¾Ýй¶»òƾ֤Ìî³ä¹¥»÷ £¬µ«Í¨ÖªÅú×¢ÍþвÐÐΪÕß¿ÉÄÜÒÑ»ñÈ¡¿Í»§ÃÜÂëµÄ½Ó¼ûȨÏÞ¡£Ë¼¿¼µ½Zello³ö¸ñÖ¸³öÊÜÓ°ÏìµÄÊÇ11ÔÂ2ÈÕǰµÄÕË»§ £¬°²È«ÊÂÎñºÜ¿ÉÄܲúÉúÔڴ˹¦·òµã×ó½ü¡£ÖµÍ×ÌùÐĵÄÊÇ £¬ZelloÔÚ2020ÄêÔø¾­Àú¹ýÒ»´ÎÊý¾Ýй¶ £¬µ¼Ö¿ͻ§µÄµç×ÓÓʼþµØÖ·ºÍÉ¢ÁÐÃÜÂë±»µÁ¡£


https://www.bleepingcomputer.com/news/security/zello-asks-users-to-reset-passwords-after-security-incident/


6. WotNotÊý¾Ýй¶ÊÂÎñ£ºAI¹©¸øÁ´ÖеÄÊý¾Ý°²È«ÓëÒþÖÔ·çÏÕ


11ÔÂ28ÈÕ £¬Ó¡¶ÈÈËΪÖÇÄܲݴ´¹«Ë¾WotNot½üÆÚ²úÉúÁËһ·ÑϳÁµÄÊý¾Ýй¶ÊÂÎñ £¬ÆäGoogle Cloud Storage´æ´¢Í°ÒòÅäÖÃÃýÎó¶øÂ¶³ö £¬µ¼ÖÂ346,381¸öÎļþ±»Î´¾­ÊÚȨ½Ó¼û £¬ÆäÖÐÔ̺¬»¤ÕÕ¡¢Ò½ÁƼͼ¡¢¼òÀúµÈÃô¸ÐÓ×ÎÒÊý¾Ý¡£WotNot×÷Ϊһ¼ÒΪÆóÒµ¶¨Ôì̸Ìì»úеÈËµÄÆ½Ì¨ £¬Æä¿Í»§º­¸ÇÁËĬ¿Ë¹«Ë¾¡¢¼ÓÖÝ´óѧµÈ³ÛÃûÆóÒµºÍ»ú¹¹¡£Õâ´Îй¶¶ÔÊÜÓ°ÏìµÄÓ×ÎÒ×é³ÉÁ˳Á´ó°²È«ºÍÒþÖÔÍþв £¬ÎªÍøÂç·¸×ï·Ö×ÓÌṩÁËÉí·Ý͵ÇÔ¡¢Ú²Æ­µÈ»î¶¯µÄ¹¤¾ß°ü¡£¸ÃÊÂÎñ½ÒʾÁËAI·þÎñÒýÈëµÄÓ°×ÓIT×ÊÔ´·çÏÕ £¬¼´²»ÊÜ×éÖ¯Ö±½Ó½ÚÔìµÄϵͳ¿ÉÄÜ´øÀ´µÄÊý¾ÝÁ÷²»ÊܽÚÔìÎÊÌâ¡£WotNotµÄ°¸ÀýÅú×¢ £¬µ¥¸ö¹©¸øÉ̵ݲȫ·ì϶¿ÉÄÜΣ¼°ÏÂÓζà¼Ò¹«Ë¾ºÍÊýǧÃûÓ×ÎÒµÄÊý¾Ý¡£Òò¶ø £¬ÆóÒµ±ØÐëÒâʶµ½¶ÔÊý¾Ý°²È«µÄÔðÈβ»½öÏÞÓÚÄÚ²¿ÏµÍ³ £¬»¹Ó¦³¹µ×Éó²éAIÖ´ÐÐÁ´ÖÐÿ¸öºÏ×÷ͬ°éµÄ°²È«Êµ¼Ê¡£Cybernews×êÑÐÈËÔ±ÓÚ9ÔÂ9ÈÕÏòWotNotÅû¶ÁËÊý¾Ýй¶ÎÊÌâ £¬µ«¸Ã¹«Ë¾»¨ÁËÁ½¸ö¶àÔ²ŹعØÁ˶Ôй¶Êý¾ÝµÄ½Ó¼û¡£


https://cybernews.com/security/wotnot-exposes-346k-sensitive-customer-files/