ZDIÅû¶Microsoft ExchangeÖÐ4¸öÐÂÎó²îµÄϸ½Ú
Ðû²¼Ê±¼ä 2023-11-071¡¢ZDIÅû¶Microsoft ExchangeÖÐ4¸öÐÂÎó²îµÄϸ½Ú
¾ÝýÌå11ÔÂ3ÈÕ±¨µÀ£¬Trend Micro ZDIÅû¶ÁËMicrosoft ExchangeÖеÄ4¸öÎó²î¡£¾ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔÔ¶³ÌʹÓÃÕâЩÎó²îÀ´Ö´ÐÐí§Òâ´úÂë»òÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£ÕâЩÎó²î»®·ÖÊÇChainedSerializationBinderÀàÖеÄRCEÎó²î¡¢DownloadDataFromUriÖеÄÐÅϢй¶Îó²î¡¢DownloadDataFromOfficeMarketPlaceÖеÄÐÅϢй¶Îó²îºÍCreateAttachmentFromUriÖеÄÐÅϢй¶Îó²î¡£ZDIÓÚ9ÔÂ7ÈÕÖÁ8ÈÕÏò΢Èí±¨¸æÁËÕâЩÎó²î£¬Î¢ÈíÈÏ¿ÉÁËÕâЩÎó²î£¬µ«ÓÉÓÚÆäÇå¾²¹¤³ÌʦÒÔΪ»¹²»·óÑÏÖØ£¬ÉÐδ¾ÙÐÐÐÞ¸´¡£
https://securityaffairs.com/153599/hacking/microsoft-exchange-zero-day-flaws.html
2¡¢ÃÀ¹úAce HardwareÔâµ½¹¥»÷1202̨ÅÌËã»úÊܵ½Ó°Ïì
¾Ý11ÔÂ2ÈÕ±¨µÀ£¬ÃÀ¹úÎå½ðÁ¬ËøµêAce HardwareÔâµ½¹¥»÷£¬Ò»Ñùƽ³£µÄÔËÓªÔ˶¯Êܵ½Ó°Ïì¡£¸Ã¹«Ë¾ÓÚ10ÔÂ29ÈÕ¼ì²âµ½´Ë´Î¹¥»÷£¬ACENET¡¢Warehouse Management SystemsºÍARMAµÈϵͳÖÐÖ¹£¬µ¼ÖÂÎÞ·¨½»»õ»ò϶©µ¥¡£Ace HardwareµÄCEO³Æ£¬¸Ã¹«Ë¾ÔËÓª×Å1400̨·þÎñÆ÷ºÍ3500̨ÍøÂç×°±¸£¬ÆäÖÐ1202̨Êܵ½Ó°Ïì¼±Ðè»Ö¸´¡£×èÖ¹11ÔÂ2ÈÕÔçÉÏ5µã31·Ö£¬ÕâЩ·þÎñÆ÷µÄ51%ÒѾ»Ö¸´¡£
https://www.bleepingcomputer.com/news/security/ace-hardware-says-1-202-devices-were-hit-during-cyberattack/
3¡¢ÃÀ¹úº½¿ÕµÄº½ÐÐÔ±¹¤»áAPAÔâµ½ÀÕË÷¹¥»÷ϵͳÈÔÔÚ»Ö¸´ÖÐ
11ÔÂ4ÈÕ±¨µÀ³Æ£¬ÃÀ¹úº½¿Õº½ÐÐÔ±¹¤»áAllied Pilots Association(APA)Ôâµ½ÀÕË÷¹¥»÷¡£APA¹¤»á½¨ÉèÓÚ1963Ä꣬ÊÇÏÖÔÚÌìÏÂÉÏ×î´óµÄ×ÔÁ¦º½ÐÐÔ±¹¤»á¡£¹¥»÷±¬·¢ÓÚ10ÔÂ30ÈÕ£¬²¿·Öϵͳ±»¼ÓÃÜ¡£APAÌåÏÖ£¬ÆäITÍŶÓÕýÔÚÆð¾¢Í¨¹ý±¸·ÝÀ´»Ö¸´ÊÜÀÕË÷¹¥»÷Ó°ÏìµÄϵͳ£¬×î³õµÄÖصãÊÇÔÚδÀ´¼¸Ð¡Ê±ºÍ¼¸ÌìÄÚÊ×ÏȻָ´ÃæÏòº½ÐÐÔ±µÄ²úÆ·ºÍ¹¤¾ß¡£APAÉÐδ͸¶ÊÇ·ñÓк½ÐÐÔ±µÄСÎÒ˽¼ÒÐÅϢй¶£¬Ò²Ã»ÓÐ͸¶ÊÜÓ°ÏìµÄÏêϸÈËÊý¡£
https://therecord.media/american-airlines-pilot-union-cyberattack
4¡¢Ð¼Óƶà¼Ò¹«¹²Ò½ÁÆ»ú¹¹µÄÍøÕ¾ÒòDDoS¹¥»÷ÖÐÖ¹ÊýСʱ
ýÌå11ÔÂ3ÈÕ±¨µÀ£¬Ð¼Óƶà¼Ò¹«¹²Ò½ÁÆ»ú¹¹µÄÍøÕ¾ÒòDDoS¹¥»÷ÖÐÖ¹³¤´ï7¸öСʱ¡£¹ú¼ÒÎÀÍâÐÐÒÕÌṩÉÌSynapxeΪ46¼Ò¹«¹²Ò½ÁÆ»ú¹¹ºÍÔ¼1400¸öÉçÇøÏàÖúͬ°éµÄÔËÓªÌṩ֧³Ö¡£Synapxe¶©ÔÄÁËһЩ·þÎñ£¬ÔÚÍøÂçÁ÷Á¿Òì³£¼¤ÔöÇ°¶ÔÆä¾ÙÐÐ×èµ²£¬È»¶ø11ÔÂ1ÈÕµÄDDoS¹¥»÷Á÷Á¿ÈƹýÁË×èµ²·þÎñ¡£Òò´Ë£¬SynapxeµÄ·À»ðǽÔÚÊÔͼ¹ýÂËÁ÷Á¿Ê±²»¿°Öظº£¬µ¼ÖÂËùÓÐÍøÕ¾ºÍÒÀÀµÍøÂçµÄ·þÎñ¶¼ÎÞ·¨»á¼û¡£SynapxeÁ¬Ã¦½ÓÄɲ½·¥£¬·þÎñ´Óµ±ÈÕÏÂÖç4µã30·ÖÆðÖð²½»Ö¸´¡£SynapxeÌåÏÖ£¬DDoS¹¥»÷ÈÔÔÚ¼ÌÐø£¬Òò´Ë·þÎñ¿ÉÄÜ»áÎÞÒâÖÐÖ¹¡£
https://www.todayonline.com/singapore/cyberattack-caused-7-hour-internet-outage-hit-public-hospitals-polyclinics-attacks-continuing-synapxe-2297036
5¡¢°²¼òªʡ5¼ÒÒ½ÔºÔâµ½ÀÕË÷¹¥»÷560Íò»¼ÕßÐÅϢй¶
ýÌå11ÔÂ6ÈÕ±¨µÀ³Æ£¬°²¼òªʡÎ÷Äϲ¿5¼ÒÒ½ÔºÔâµ½µÄÀÕË÷¹¥»÷£¬Ó°ÏìÁË560Íò»¼ÕßÐÅÏ¢¡£10ÔÂ23ÈÕ£¬Ò½ÔºµÄITºÍн×ÊÖÎÀí»ú¹¹TransFormÔâµ½¹¥»÷£¬µ¼ÖÂWindsor Regional HospitalµÈ5¼ÒÒ½ÔºµÄϵͳÖÐÖ¹¡£ÊÓ²ìÈ·¶¨£¬Ð¹Â¶ÐÅÏ¢°üÀ¨Bluewater HealthµÄ560ÍòÌõ¾ÍÕïÐÅÏ¢ºÍChatham-Kent Health AllianceµÄ1446ÃûÔ±¹¤µÄÐÅÏ¢µÈ¡£Ò½ÔººÍTransForm¶¼²»¿ÏÒâ½»Êê½ð£¬×èÖ¹ÏÖÔÚ£¬¹¥»÷ÕßÒѾ¹ûÕæÁËÈýÂÖ±»µÁÐÅÏ¢¡£
https://www.cbc.ca/news/canada/windsor/ransomware-attack-third-bunch-data-hospital-1.7019701
6¡¢Ñо¿Ö°Ô±ÑÝʾÔõÑùʹÓÃApple¡°Find My¡±ÇÔÊØÐÅÏ¢
11ÔÂ4ÈÕ±¨µÀ£¬Ñо¿Ö°Ô±ÑÝʾÁËÔõÑùʹÓÃApple×°±¸µÄ¡°Find My¡±À´ÇÔÈ¡¼üÅ̼ͼµÄÃÜÂë¡£ÔçÔÚÁ½ÄêÇ°£¬¾ÍÓÐÑо¿ÍŶÓÔø·¢Ã÷¿ÉʹÓá°Find My¡±À´´«Êä³ý×°±¸Î»ÖÃÖ®ÍâµÄÊý¾Ý£¬²¢³ÆΪ¡°Send My¡±¡£´Ë´Î£¬Ñо¿Ö°Ô±½«´øÓÐESP32À¶ÑÀ·¢ÉäÆ÷µÄ¼üÅ̼ͼ³ÌÐò¼¯³Éµ½USB¼üÅÌÖУ¬ÒÔ֤ʵ¿ÉÒÔͨ¹ýÀ¶ÑÀ½«¼üÅÌÉÏÊäÈëµÄÃÜÂëºÍÆäËüÃô¸ÐÊý¾Ý´«Ë͵½Find MyµÄÍøÂç¡£À¶ÑÀ´«ÊäÒª±ÈWLAN¼üÅ̼ͼ³ÌÐò»òRaspberry Pi×°±¸Òþ²ØµÃ¶à£¬Ëü¿ÉÒÔÉñÃصØʹÓÃÎÞ´¦²»ÔÚµÄApple×°±¸¾ÙÐÐÖм̡£
https://www.bleepingcomputer.com/news/apple/apple-find-my-network-can-be-abused-to-steal-keylogged-passwords/