¡°´«È¾ÐԲɷᱻÖÐOtterCookieÐÂÐͶñÒâÈí¼þÍþвÈí¼þ¿ª·¢ÈËÔ±

°ä²¼¹¦·ò 2024-12-27

1. ¡°´«È¾ÐԲɷᱻÖÐOtterCookieÐÂÐͶñÒâÈí¼þÍþвÈí¼þ¿ª·¢ÈËÔ±


12ÔÂ26ÈÕ £¬³¯ÏÊÍþвÐÐΪÕß½üÆÚÔÚÕë¶ÔÈí¼þ¿ª·¢ÈËÔ±µÄ¡°´«È¾ÐԲɷᱻÖÐ £¬ÍƳöÁËÒ»ÖÖÃûΪOtterCookieµÄÐÂÐͶñÒâÈí¼þ ¡£¾ÝÍøÂ簲ȫ¹«Ë¾Palo Alto NetworksµÄ×êÑÐÈËÔ±³Æ £¬¸Ã»î¶¯×Ô2022Äê12ÔÂÒÔÀ´Ò»Ïò»îÔ¾ £¬Í¨¹ýÌṩÐéαµÄ¹¤×÷»úÓö´«²¼¶ñÒâÈí¼þ £¬ÈçBeaverTailºÍInvisibleFerretµÈ ¡£¶øNTT Security JapanµÄ»ã±¨Ö¸³ö £¬OtterCookieºÜ¿ÉÄÜÓÚ9ÔÂÍÆ³ö £¬²¢ÔÚ11Ô³öÏÖÁËеıäÖÖ ¡£¸Ã¶ñÒâÈí¼þͨ¹ý¼ÓÔØÆ÷´«µÝ £¬»ñÈ¡JSONÊý¾Ý²¢Ö´ÐÐJavaScript´úÂë £¬Äܹ»ÓëBeaverTailһ·²¿Êð»òµ¥¶À²¿Êð ¡£ËüÀûÓÃGitHub»òBitbucketÏÂÔØµÄNode.jsÏîÄ¿»ònpm°üϰȾָ±ê £¬Ò²Ê¹ÓÃÁËQt»òElectronÀûÓ÷¨Ê½¹¹½¨µÄÎļþ ¡£Ò»µ©¼¤»î £¬OtterCookie¾Í»áʹÓÃSocket.IO WebSocket¹¤¾ßÓëºÅÁîºÍ½ÚÔì»ù´¡ÉèÊ©³ÉÁ¢°²È«Í¨Ñ¶ £¬²¢Ö´ÐÐÊý¾Ý͵ÇÔµÄshellºÅÁî £¬Ô̺¬ÍøÂç¼ÓÃÜÇ®±ÒÇ®°üÃÜÔ¿¡¢Îĵµ¡¢Í¼ÏñµÅ×мÛÖµÐÅÏ¢ ¡£×îа汾µÄOtterCookie»¹Äܹ»Ð¹Â¶¼ôÌù°åÊý¾Ý £¬²¢¼ì²âµ½ÓÃÓÚ¿úËŵĺÅÁî £¬Åú×¢¹¥»÷Õß³ïËã½øÐиüÉîµµ´ÎµÄÉøÈë»òºáÏòÒÆ¶¯ ¡£


https://www.bleepingcomputer.com/news/security/new-ottercookie-malware-used-to-backdoor-devs-in-fake-job-offers/


2. ÈÕº½ÔâDDoS¹¥»÷Öº½°àÑÓÎó £¬ÏµÍ³ÒѸ´Ô­


12ÔÂ26ÈÕ £¬ÈÕ±¾Æì½¢º½¿Õ¹«Ë¾ÈÕ±¾º½¿Õ(JAL)Ôâ·êÁËÒ»´ÎÍøÂ簲ȫÊÂÎñ £¬µ¼ÖÂÆä²¿ÃŹúÄں͹ú¼Êº½°à³öÏÖÑÓÎó ¡£ÊÂÎñÆðÒòÊÇÆäÓÃÓÚÓë±í²¿ÏµÍ³½øÐÐÊý¾ÝͨѶµÄÍøÂçÉ豸Ôâ·êÁËÉ¢²¼Ê½»Ø¾ø·þÎñ(DDoS)¹¥»÷ £¬µ¼ÖÂϵÍÂä÷Á¿¼¤Ôö²¢³öÏÖ¹ÊÕÏ ¡£¹¥»÷»¹Ó°ÏìÁ˳˿ÍÐÐÀîÖÎÀíϵͳºÍÒÆ¶¯ÀûÓ÷¨Ê½ £¬µ«ÈÕº½°µÊ¾Ã»Óпͻ§ÐÅϢй¶¡¢ÍÆËã»ú²¡¶¾ÇÖº¦»ò·ÉÐа²È«ÎÊÌâ ¡£ÊÜÓ°ÏìµÄϵͳÒÑÁÙʱ¹Ø¹Ø £¬²¢ÔÝÍ£Á˵±ÈÕÆô³ÌµÄ»úƱÏúÊۺͲ¿ÃÅÔÚÏß·þÎñ ¡£Ö»¹ÜÓÐ40¶à¸öº½°àÑÓÎó £¬µ«ÈÕº½°µÊ¾µÚ¶þÌìµÄº½°à´òËãÕý³£ÔËÐÐ ¡£º½¿ÕÒµÈÔÊÇÈ«ÇòºÚ¿ÍµÄÈȵãÖ¸±ê £¬´ËÇ°Ò²Ôø²úÉú¶àÆðÕë¶Ôº½¿Õ¹«Ë¾ºÍ»ú³¡µÄÍøÂç¹¥»÷ÊÂÎñ £¬ÕâЩϮ»÷´ó¶à³öÓÚ¾­¼Ã¶¯»ú £¬µ«Ò²ÓÐÕþÖζ¯»úµÄ°¸Àý ¡£


https://therecord.media/japan-airlines-resumes-operations-after-cyberattack


3. °ÍÎ÷ºÚ¿ÍÒòÉæÏÓڲƭÀÕË÷ÔÚÃÀ¹úÔâÖ¸¿Ø


12ÔÂ26ÈÕ £¬Ò»Ãû°ÍÎ÷¹«ÃñJunior Barros De OliveiraÒòÉæÏÓºÚ¿ÍÈëÇÖ²¢Ú²Æ­ÀÕË÷Ò»¼ÒλÓÚÐÂÔóÎ÷µÄ¹«Ë¾¶ø±»ÃÀ¹ú˾·¨²¿¸æ×´ ¡£¾Ý¸æ×´ÊéÏÔʾ £¬µÂ°ÂÀûάÀ­ÓÚ2020Äê3ÔÂÈëÇÖÁ˸ù«Ë¾µÄ°ÍÎ÷×Ó¹«Ë¾ÍøÂç £¬ÇÔÈ¡ÁËÔ¼30ÍòÃû¿Í»§µÄ»úÃÜÐÅÏ¢ ¡£Í¬Äê9Ô £¬ËûʹÓû¯ÃûÏò¸Ã¹«Ë¾Ê×ϯִÐйٷ¢Ë͵ç×ÓÓʼþ £¬ÒªÇóÖ§¸¶300±ÈÌØ±Ò£¨µ±ÊмÛÖµÔ¼320ÍòÃÀÔª£©×÷Ϊ²»ÏúÊÛÊý¾ÝµÄǰÌá ¡£Ò»¸öÔºó £¬ËûÓÖ½«Ò»ÑùµÄÐÅϢת·¢¸øÁ˸ù«Ë¾ÔÚ°ÍÎ÷µÄÊ×ϯִÐйٺÍÒ»Ãû¸ß¹Ü £¬²¢°µÊ¾Ô¸ÒâÒÔ75±ÈÌØ±Ò£¨ÆäʱԼºÏ80ÍòÃÀÔª£©µÄÕ÷ѯ·ÑÔ®ÊÖËûÃǽâ¾ö°²È«·ì϶ ¡£µÂ°ÂÀûάÀ­Òò¶ø±»Ö¸¿ØËÄÏîÉæ¼°´ÓÊܱ£»¤µÄÍÆËã»ú»ñÊØÐÅÏ¢µÄڲƭÀÕË÷×ïºÍËÄÏîÍþвÐÔͨѶ×ï ¡£ÈôÊÇ×ïÃû³ÉÁ¢ £¬Ëû½«Ãæ¶Ô×î¸ß¿É´ï20ÄêµÄ½ûïÀºÍ¸ß´ï100ÍòÃÀÔªµÄ·£¿î £¬»òÊÕÒæÓëËðʧ¼ÛÖµµÄÁ½±¶£¨ÒԽϸßÕßΪ׼£© ¡£


https://thehackernews.com/2024/12/brazilian-hacker-charged-for-extorting.html


4. ͨÓö¯Á¦¹«Ë¾ÔâÍøÂç´¹µö¹¥»÷ £¬ÊýʮԱ¹¤¸£ÀûÕË»§±»ÈëÇÖ


12ÔÂ26ÈÕ £¬º½¿Õº½ÌìºÍ¹ú·À¾ÞͷͨÓö¯Á¦¹«Ë¾Ôâ·êÁËÒ»´Î³É¹¦µÄÍøÂç´¹µö¹¥»÷ £¬µ¼ÖÂÊýÊ®¸öÔ±¹¤¸£ÀûÕË»§±»ÈëÇÖ ¡£¹¥»÷Õßͨ¹ýµÚÈý·½ÍйܵĵǼÃÅ»§½Ó¼û²¢¸ü¸ÄÁËÔ±¹¤¸£ÀûÕË»§ £¬ÕâЩÕË»§Ô̺¬ÁËÔ±¹¤µÄÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢µ±¾ÖÐû¸æµÄÉí·ÝÖ¤ºÅÂë¡¢Éç»á°²È«ºÅÂë¡¢ÒøÐÐÕË»§ÐÅÏ¢ºÍ²Ð¼²Çé¿öµÈÃô¸ÐÐÅÏ¢ ¡£¾ÝͨÓö¯Á¦¹«Ë¾Ð¹Â© £¬¹²ÓÐ37ÈËÊܵ½Ó°Ïì £¬¹¥»÷ÕßÔÚijЩÇé¿öÏ»¹¸ü¸ÄÁ˱»µÁÕË»§µÄÒøÐÐÕË»§ÐÅÏ¢ ¡£Í¨Óö¯Á¦¹«Ë¾ÔÚ·¢ÏÖÕâһδ¾­ÊÚȨµÄ»î¶¯ºóÁ¢¼´ÔÝÍ£Á˶Ը÷þÎñµÄ½Ó¼û £¬²¢ÏòÊÜÓ°ÏìµÄÈËÔ±ÌṩÁËÁ½ÄêµÄÃâ·ÑÐÅÓþ¼à¿Ø ¡£´Ë±í £¬Í¨Óö¯Á¦¹«Ë¾»¹ÌáÐÑÊÜÓ°ÏìµÄÓ×ÎÒ³ÁÖÃËûÃǵĸ»´ïÕË»§µÇ¼ƾ֤ £¬²¢Ô¤·ÀÔÚ¶à¸öÕË»§ÖÐʹÓÃÒ»ÑùµÄƾ֤ ¡£½ñÄêÔçЩʱ³½ £¬¸»´ï¹«Ë¾Ò²ÔøÔâ·ê¹ýÁ½´ÎÊý¾Ýй¶ÊÂÎñ £¬Ó°ÏìÁËÊýÍòÓ×ÎÒ ¡£


https://www.securityweek.com/defense-giant-general-dynamics-says-employees-targeted-in-phishing-attack/


5. WDACÔâÀûÓà £¬¹¥»÷Õ߿ɽûÓÃEDR´«¸ÐÆ÷·¢Æð¹¥»÷


12ÔÂ25ÈÕ £¬°²È«×¨¼Ò·¢ÏÖÁËÒ»ÖÖÀûÓÃWindows DefenderÀûÓ÷¨Ê½½ÚÔ죨WDAC£©µÄ¹¥»÷¼¼Êõ £¬Äܹ»½ûÓÃWindowsÉ豸ÉϵĶ˵ã¼ì²âºÍÏìÓ¦£¨EDR£©´«¸ÐÆ÷ £¬Ê¹¹¥»÷Õß¿ÉÄÜÈÆ¹ý°²È«¼ì²â²¢¶Ôϵͳ·¢Æð¹¥»÷ ¡£WDACÊÇWindows 10ºÍWindows Server 2016ÒýÈëµÄ¼¼Êõ £¬Ö¼ÔÚ½ÚÔìWindowsÉ豸ÉϵĿÉÖ´ÐдúÂë ¡£¹¥»÷ÕßÄܹ»Ôì¶©ºÍ²¿ÊðרÃÅÉè¼ÆµÄWDACÕ½Êõ £¬×èÖ¹EDR´«¸ÐÆ÷ÔÚϵͳÆô¶¯Ê±¼ÓÔØ £¬Ê¹ÆäÎÞ·¨¹¤×÷ ¡£¹¥»÷·½Ê½Ô̺¬Õë¶Ôµ¥¸öÉ豸ºÍÕû¸öÓò £¬Õ¼ÓÐÓòÖÎÀíԱȨÏ޵Ĺ¥»÷ÕßÄܹ»ÔÚÕû¸ö×éÖ¯ÄÚ·Ö·¢¶ñÒâWDACÕ½Êõ £¬ÏµÍ³ÐԵؽûÓÃËùÓж˵ãÉϵÄEDR´«¸ÐÆ÷ ¡£¹¥»÷Éæ¼°Õ½Êõ¸éÖᢳÁÆôÖն˺ͽûÓÃEDRÈý¸öÖØÒª½×¶Î ¡£°²È«ÈËÔ±´´½¨ÁË¡°Krueger¡±¸ÅÏëÑéÖ¤¹¤¾ßÀ´¼ì²âÕâÖÖ¹¥»÷ ¡£»º½âÕ½ÊõÔ̺¬Í¨¹ýGPOÖ´ÐÐWDACÕ½Êõ¡¢ÀûÓÃ×îÓ×ȨÏÞ×¼ÔòºÍÖ´Ðа²È«µÄÖÎÀíʵ¼Ê ¡£Ãæ¶ÔгöÏֵĹ¥»÷¼¼Êõ £¬±ØÒª²ÉÈ¡¶àµµ´ÎµÄÍøÂ簲ȫ²½Öè £¬²¢Ê±¿Ìά³Ö¾¯Ìè ¡£


https://cybersecuritynews.com/attack-weaponizes-windows-defender/#google_vignette


6. ΢ÈíÖҸ棺ʹÓÃýÌå×°ÖÃWindows 11 24H2¿ÉÖÂÎÞ·¨½Ó¹Ü°²È«¸üÐÂ


12ÔÂ26ÈÕ £¬Î¢Èí·¢³öÖÒ¸æ £¬Ö¸³öʹÓÃýÌåÖ§³Ö×°ÖÃWindows 11°æ±¾24H2ʱ´æÔÚÒ»¸öÎÊÌâ £¬¿ÉÄܵ¼Ö²Ù×÷ϵͳÎÞ·¨½ÓÊܽøÒ»²½µÄ°²È«¸üР¡£¾ßÌå¶øÑÔ £¬ÔÚ2024Äê10ÔÂ8ÈÕÖÁ11ÔÂ12ÈÕÆÚ¼ä £¬Ê¹ÓÃCDºÍUSBÉÁ´æÇý¶¯Æ÷×°ÖÃÔ̺¬´ËÆÚ¼ä°²È«¸üеÄWindows 11°æ±¾24H2ʱ £¬É豸¿ÉÄÜ»áÏÝÈëÎÞ·¨½ÓÊܺóÐøWindows°²È«¸üеÄ״̬ ¡£²»Íâ £¬Õâ¸ö·ì϶²»»áÓ°Ïìͨ¹ýWindows¸üлòMicrosoft¸üÐÂÄ¿Â¼ÍøÕ¾ÀûÓõݲȫ¸üР£¬Ò²²»»áÔÚʹÓÃ×îеÄ2024Äê12Ô°²È«¸üÐÂʱ³öÏÖ ¡£Î¢ÈíÔÚÖÂÁ¦ÓÚÓÀÔ¶½¨¸´´ËÎÊÌâ £¬²¢½¨ÒéʹÓûùÓÚýÌåµÄWindows 11 24H2×°ÖõÄÓû§ÀûÓÃ2024Äê12ÔÂ10ÈÕ°ä²¼µÄ°²È«¸üР£¬ÒÔÔ¤·ÀºóÐø¸üÐÂÎÊÌâ ¡£´Ë±í £¬Windows 11 24H2»¹Ãæ¶Ô×ÅһϵÁÐÆäËûÎÊÌâ £¬Ô̺¬ÒôƵÎÊÌâ¡¢ÓÎÏ·»úÄÜÎÊÌâ¡¢±ÀÀ£ºÍËÀ»úµÈ £¬ÉõÖÁÔÚÌØ¶¨µÄÓ²¼þºÍÈí¼þÅäÖÃÉϱ»ÁÙʱ×èÖ¹ ¡£


https://www.bleepingcomputer.com/news/security/windows-11-installation-media-bug-causes-security-update-failures/