ÍøÂç¹¥»÷µ¼ÖÂÅíÈø¿ÆÀÊÐÕþ¸®µç»°Ïß·̱»¾
Ðû²¼Ê±¼ä 2024-03-213ÔÂ20ÈÕ£¬·ðÂÞÀï´ïÖÝÅíÈø¿ÆÀÊÐÕþ¸®ÕýÔÚ´¦Öóͷ£ÒòÉÏÖÜÄ©Ðû²¼µÄÍøÂç¹¥»÷¶øÔì³ÉµÄ´ó¹æÄ£µç»°ÖÐÖ¹ÎÊÌâ¡£ÊÐÕþ¸®½²»°È˼ÖÉ¡¤»ÝÀÕ (Jason Wheeler) ¸æËß Recorded Future News£¬ÊÐÕþ¸®¸÷¸ö²¿·ÖµÄ¹ÙÔ±¶¼Óöµ½Á˵绰ÎÊÌ⣬µ¼Ö 311 ¹«ÃñÖ§³ÖϵͳÎüÊÕ·þÎñ·ºÆðÑÓÎó¡£911 µÈ½ôÆȵ绰ºÅÂëÈÔÔÚʹÓ㬻ÝÀÕÌåÏÖ£¬¿ÉÒÔʹÓ÷ǽôÆȵ绰ºÅÂëÁªÏµÅíÈø¿ÆÀ¾¯Ô±¾ÖºÍÏû·À¾Ö¡£¸ÃÊл¹ÎªÄÜÔ´²¿·Ö¡¢ÎÀÉú²¿·Ö¡¢¹«¹²¹¤³Ì¡¢¹¤³Ì¡¢×¡·¿ºÍÆäËû²¿·Ö½¨ÉèÁ˱¸Óõ绰ºÅÂë¡£¡¶ÅíÈø¿ÆÀÐÂÎÅÈÕ±¨¡·³Æ»ÝÀÕÏòËûÃÇת´ïÁËÍøÂç¹¥»÷£¬²¢ÖØÉ꾯ԱºÍÏû·ÀµÈ½ôÆÈ·þÎñ²¢Î´Êܵ½Í£Ó°Ï·Ïì¡£ÅíÈø¿ÆÀλÓÚ·ðÂÞÀï´ïÖݺͰ¢À°ÍÂíÖݽÓÈÀ´¦£¬¾àĪ±È¶ûԼһСʱ³µ³Ì£¬ÓµÓÐÁè¼Ý 53,000 ÃûסÃñ¡£¸ÃÊдËÇ°ÔøÔâÓö¹ýÀÕË÷Èí¼þ¹¥»÷£¬ÔÚ 2019 ÄêµÄÒ»´ÎÊÂÎñÖÐÔøÓëÀ´×Ô Maze ÀÕË÷Èí¼þÍÅ»ïµÄºÚ¿Í´ò½»µÀ¡£¾Ý¡¶ÅíÈø¿ÆÀÐÂÎÅÔÓÖ¾¡·±¨µÀ£¬¸ÃÍÅ»ïÇÔÈ¡ÁË 2GB Êý¾Ý£¬µ«ÊÐÕþ¸®¾Ü¾øÖ§¸¶Êê½ð£¬¶øÊÇÆÆ·ÑÁËÔ¼ 30 ÍòÃÀÔª´ÓÊÂÎñÖлָ´¹ýÀ´¡£¸ÃÊб»ÆÈ֪ͨÁè¼Ý 57000 ÈË£¬ËûÃǵÄÐÅÏ¢ÔÚÏ®»÷ʱ´ú±»ÍµÈ¡¡£
https://therecord.media/cyberattack-pensacola-florida-knocks-out-phones?&web_view=true
2. °×¹¬ºÍ»·±£¾ÖÖÒÑÔºÚ¿Í¿ÉÄܹ¥»÷¹©Ë®ÏµÍ³
3ÔÂ19ÈÕ£¬ÃÀ¹ú¹ú¼ÒÇå¾²ÕÕÁϽܿˡ¤É³ÀûÎĺÍÇéÐα£»¤¾Ö (EPA) ¾Ö³¤Âõ¿Ë¶û¡¤Àï¸ù½ñÌìÖÒÑÔÖݳ¤ÃÇ£¬ºÚ¿ÍÕýÔÚ¹¥»÷ÌìÏÂË®Îñ²¿·ÖµÄÒªº¦»ù´¡ÉèÊ©¡£ÔÚÖܶþ·¢Ë͵ÄÒ»·âÍŽáÐÅÖУ¬ËûÃÇÇëÇóÖݳ¤ÃÇÌṩ֧³Ö£¬ÒÔÈ·±£¸÷ÖݵĹ©Ë®ÏµÍ³»ñµÃ³ä·Ö·ÀÓù£¬ÃâÊÜÍøÂç¹¥»÷£¬²¢ÇÒÔÚÔâµ½ÆÆËðʱÄܹ»»Ö¸´¡£¹ú¼ÒÇ徲ίԱ»á (NSC) ºÍÇéÐα£»¤¾Ö (EPA) Ô¼ÇëÖݳ¤ÃǼÓÈë 3 Ô 21 ÈÕµÄÐéÄâ¾Û»á£¬ÒÔÔöÇ¿Õþ¸®ÊµÌåºÍˮϵͳ֮¼äµÄÏàÖú£¬²¢½¨ÉèË®²¿·ÖÍøÂçÇå¾²ÊÂÇé×é¡£¸ÃÊÂÇé×齫ÈÏÕæÈ·¶¨¿ÉÔÚÌìϹæÄ£ÄÚʵÑéµÄÐж¯ºÍÕ½ÂÔ£¬ÒÔÖ»¹ÜïÔ̹©Ë®ÏµÍ³ÔâÊÜÍøÂç¹¥»÷µÄΣº¦¡£½ü¼¸¸öÔÂÀ´£¬¶à¸öÍþв×éÖ¯¶¼Ãé×¼²¢ÆÆËðÁËÃÀ¹úµÄ¹©Ë®ÏµÍ³¡£IRGC Á¥ÊôÍþвÐÐΪÕßÉø͸Á˱öϦ·¨ÄáÑÇÖݵĹ©Ë®ÉèÊ©£¬¶ø Volt Typhoon ºÚ¿ÍÔòÈëÇÖÁËÒªº¦»ù´¡ÉèÊ©×éÖ¯µÄÍøÂ磬°üÀ¨ÒûÓÃˮϵͳ¡£
https://www.bleepingcomputer.com/news/security/white-house-and-epa-warn-of-hackers-breaching-water-systems/
3. еĴ¹ÂÚ¹¥»÷ʹÓà Office °²ÅÅ NetSupport RAT
3ÔÂ19ÈÕ£¬Ò»ÏîеÄÍøÂç´¹ÂÚÔ˶¯Õë¶ÔÃÀ¹ú£¬Ö¼ÔÚ°²ÅÅÃûΪ NetSupport RAT µÄÔ¶³Ì»á¼ûľÂí¡£ÒÔÉ«ÁÐÍøÂçÇå¾²¹«Ë¾ Perception Point ÕýÔÚ×·×ÙÃûΪ¡°Operation PhantomBlu¡±µÄÔ˶¯¡£PhantomBlu ²Ù×÷ÒýÈëÁËÒ»ÖÖÐþÃîµÄʹÓÃÒªÁ죬Óë NetSupport RAT µÄµä·¶½»¸¶»úÖƲî±ð£¬ËüʹÓà OLE£¨¹¤¾ßÁ´½ÓºÍǶÈ룩ģ°å²Ù×÷£¬Ê¹Óà Microsoft Office ÎĵµÄ£°åÖ´ÐжñÒâ´úÂ룬ͬʱÌӱܼì²â¡£NetSupport RAT ÊÇÕýµ±Ô¶³Ì×ÀÃ湤¾ß£¨³ÆΪ NetSupport Manager£©µÄ¶ñÒâ·ÖÖ§£¬ÔÊÐíÍþв¼ÓÈëÕßÔÚÊÜѬȾµÄ¶ËµãÉÏÖ´ÐÐһϵÁÐÊý¾ÝÍøÂç²Ù×÷¡£ÆðµãÊÇÒ»·âÒÔн×ÊΪÖ÷ÌâµÄÍøÂç´¹ÂÚµç×ÓÓʼþ£¬¸Ãµç×ÓÓʼþÉù³ÆÀ´×Ô»á¼Æ²¿·Ö£¬²¢±Þ²ßÊÕ¼þÈË·¿ªË渽µÄ Microsoft Word ÎĵµÒÔÉó²é¡°Ô¶Èн×ʱ¨¸æ¡±¡£¶Ôµç×ÓÓʼþ±êÍ·£¨ÓÈÆäÊÇ Return-Path ºÍ Message-ID ×ֶΣ©µÄ×ÐϸÆÊÎöÅú×¢£¬¹¥»÷ÕßʹÓÃÃûΪ Brevo£¨ÒÔÇ°³ÆΪ Sendinblue£©µÄÕýµ±µç×ÓÓʼþÓªÏúƽ̨À´·¢Ë͵ç×ÓÓʼþ¡£Word Îĵµ·¿ªºó£¬»áָʾÊܺ¦ÕßÊäÈëµç×ÓÓʼþÕýÎÄÖÐÌṩµÄÃÜÂë²¢ÆôÓñ༣¬È»ºóË«»÷ÎĵµÖÐǶÈëµÄ´òÓ¡»úͼ±êÒÔÉó²éÈËΪͼ±í¡£
https://thehackernews.com/2024/03/new-phishing-attack-uses-clever.html
4. ·¨¹ú×îTravailÖØ´óÇå¾²Îó²îй¶Áè¼Ý 4300 ÍòСÎÒ˽¼ÒÐÅÏ¢
3ÔÂ13ÈÕ£¬¾Ý±¨µÀ£¬¸Ã¹«Ë¾³ÉΪÊý¾Ý鶵ÄÊܺ¦Õߣ¬¸ÃÊÂÎñ̻¶ÁË×¢²áÓû§µÄСÎÒ˽¼ÒÏêϸÐÅÏ¢£¬°üÀ¨ÐÕÃû¡¢Éç»áÇå¾²ºÅÂë¡¢³öÉúÈÕÆÚ¡¢µç×ÓÓʼþµØµã¡¢ÓÊÕþµØµã¡¢µç»°ºÅÂëºÍÓû§±êʶ·û¡£ÕâÒ»ÊÂÎñÓ°ÏìÁ˸ùúÔ¼Èý·ÖÖ®¶þµÄÉú³Ý£¬Òý·¢ÁËÈËÃǶÔڲƺÍÉí·Ý͵ÇÔΣº¦µÄµ£ÐÄ¡£·¢Ã÷ÕâÒ»ÊÂÎñºó£¬¸Ã»ú¹¹Á¬Ã¦Í¨Öª·¨¹ú¹ú¼ÒÐÅÏ¢Óë×ÔÓÉίԱ»á£¨CNIL£©²¢Ïò¾¯·½±¨°¸£¬Æô¶¯ÕýʽÊӲ졣³õ³ÌÐò²éЧ¹ûÏÔʾ£¬·¸·¨ÕßÓÚ 2 Ô 6 ÈÕð³äÒ»ÃûÔ±¹¤£¬Î´¾ÊÚȨ»á¼ûÁ˸ûú¹¹µÄϵͳ¡£Ö»¹Ü¸Ã»ú¹¹Ç¿µ÷ÒøÐÐÐÅÏ¢ºÍÕË»§ÃÜÂ벢δ±»µÁ£¬µ« CNIL ÖÒÑԳƣ¬·¸·¨·Ö×Ó¿ÉÄÜ»áʹÓÃÅû¶µÄÊý¾Ý´ÓÆäËûȪԴÍøÂç¸ü¶àÐÅÏ¢¡£Òò´Ë£¬½¨Ò鹫Ãñ¶ÔDZÔÚµÄÍøÂç´¹ÂÚ¡¢Ú²ÆºÍÉí·Ý͵ÇÔ¼á³ÖСÐÄ¡£¸ÃίԱ»á»¹Í¸Â¶£¬´Ë´ÎÊý¾Ýй¶¿ÉÄÜ»áÓ°ÏìÒÑÍù 20 ÄêÀ´µÄÏÖÈκÍÇ°ÈÎÇóÖ°Õß¡£¾Ý CNIL ³Æ£¬ËùÓÐÊÜÓ°ÏìµÄÓû§¶¼½«ÊÕµ½µ¥¶À֪ͨ¡£±ðµÄ£¬ÃãÀøËùÓÐÊܺ¦ÕßÏò°ÍÀèÉó²é¹Ù°ì¹«ÊÒÌá³öÉêËߣ¬ÒÔÐÖúÊӲ졣
https://meterpreter.org/france-travail-breach-compromises-data-of-millions/
5. Êý°Ù¸öÍøÕ¾¹ýʧÉèÖà Firebase й¶Áè¼Ý 1.25 ÒÚÌõÓû§¼Í¼
3ÔÂ19ÈÕ£¬ÕâÒ»Çж¼Ê¼ÓÚChattr µÄºÚ¿Í¹¥»÷£¬ÕâÊÇÒ»¸öΪÃÀ¹ú¶à¸ö×éÖ¯Ìṩ·þÎñµÄÈ˹¤ÖÇÄÜÕÐƸϵͳ£¬ÆäÖаüÀ¨ Applebee's¡¢Chick-fil-A¡¢KFC¡¢Subway¡¢Taco Bell ºÍ Wendy's µÈ¿ì²ÍÁ¬Ëøµê¡£Chattr µÄFirebaseʵÑéÖеÄÒ»¸öÈõµãʹµÃÑо¿Ö°Ô±Äܹ»Í¨¹ý×¢²áÐÂÓû§À´»ñµÃÊý¾Ý¿âµÄÍêȫȨÏÞ¡£ËûÃÇ»ñµÃÁËÐÕÃû¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØµã¡¢Ä³Ð©ÕÊ»§µÄÃ÷ÎÄÃÜÂë¡¢ÉñÃØÐÂÎŵȵĻá¼ûȨÏÞ¡£Ñо¿Ö°Ô±ÌåÏÖ£¬ÊÜÓ°ÏìµÄСÎÒ˽¼Ò°üÀ¨Ô±¹¤¡¢ÌØÐíı»®Ë¾ÀíºÍÇóÖ°Õß¡£Í¨¹ý½¨ÉèеÄÖÎÀíÕÊ»§£¬Ñо¿Ö°Ô±¿ÉÒÔ»á¼ûÖÎÀíÒDZí°å£¬ÕâÌṩÁ˶ÔϵͳµÄ¸ü¶à»á¼ûȨÏÞ£¬°üÀ¨ÍË¿îÑ¡Ïî¡£»¹·¢Ã÷ÁËÒ»ÖÖÌØÁíÍâ¡°ÓÄÁ顱ģʽ£¬Ìṩ¶ÔÕ˵¥ÐÅÏ¢µÄ»á¼û¡¢¶ÔÓû§ÕÊ»§µÄÍêÈ«¿ØÖÆÒÔ¼°ÕÐƸְԱµÄÑ¡Ïî¡£
https://www.securityweek.com/misconfigured-firebase-instances-expose-125-million-user-records/
6. Áè¼Ý 13Íǫ̀ Fortinet ×°±¸Ò×Êܵ½ CVE-2024-21762 µÄÓ°Ïì
3ÔÂ19ÈÕ£¬Ö»¹ÜÎó²î²¹¶¡ÒѾ¸üУ¬µ«Ì»Â¶ÔÚ¹«¹²»¥ÁªÍøÉÏÇÒÒ×ÊÜ FortiOS Ò»¸öÔÂÇ°ÑÏÖØÇå¾²Îó²îÓ°ÏìµÄ Fortinet ºÐ×ÓÊýÄ¿ÈÔÈ»ºÜÊǸߡ£Æ¾Ö¤Çå¾²·ÇÓªÀû×éÖ¯ Shadowserver µÄ×îÐÂÊý¾Ý£¬Ò×ÊÜ CVE-2024-21762 Ó°ÏìµÄ Fortinet ×°±¸ÊýÄ¿Áè¼Ý 133000 ̨£¬½ö±ÈÊ®ÌìÇ°µÄ 150000 ¶ą̀ÂÔÓÐϽµ¡£ÊýÄ¿×î¶àµÄÊÇÑÇÖÞ£¬ÓÐ 54310 ̨װ±¸ÈÔÈ»ÈÝÒ×Êܵ½ÑÏÖØ RCE Îó²îµÄÓ°Ïì¡£±±ÃÀºÍÅ·ÖÞ»®·ÖÒÔ 34945 ºÍ 28058 Õ¼ÓеڶþºÍµÚÈý룬ÆäÓàΪÄÏÃÀÖÞ¡¢·ÇÖ޺ʹóÑóÖÞ¡£Ì»Â¶µÄ SSL VPN µÄÊýĿ˵Ã÷Îú¸ÃÒªº¦Îó²îµÄÆձ鹥»÷Ã棬²¢ÇÒÒÑÖª¸ÃÎó²îÒѱ»Æð¾¢Ê¹Óá£
https://www.theregister.com/2024/03/18/more_than_133000_fortinet_appliances/?&web_view=true