Windows Server ¸üе¼ÖÂÓò¿ØÖÆÆ÷Í߽ⲢÖØÐÂÆô¶¯
Ðû²¼Ê±¼ä 2024-03-221. Windows Server ¸üе¼ÖÂÓò¿ØÖÆÆ÷Í߽ⲢÖØÐÂÆô¶¯
3ÔÂ21ÈÕ£¬ÓÉÓÚ Windows Server 2016 ºÍ Windows Server 2022 µÄ 2024 Äê 3 ÔÂÀÛ»ý¸üÐÂÖÐÒýÈëÁËÍâµØÇå¾²»ú¹¹×Óϵͳ·þÎñ (LSASS) £¬ÊÜÓ°ÏìµÄ·þÎñÆ÷ÕýÔÚ¶³½á²¢ÖØÐÂÆô¶¯¡£LSASS ÊÇÒ»Ïî Windows ·þÎñ£¬ÓÃÓÚÖ´ÐÐÇå¾²Õ½ÂÔ²¢´¦Öóͷ£Óû§µÇ¼¡¢»á¼ûÁîÅƽ¨ÉèºÍÃÜÂë¸ü¸Ä¡£ÕýÕâÑù¶àÖÎÀíÔ±ÖÒÑÔµÄÄÇÑù£¬ÔÚ×°ÖÃÖܶþÐû²¼µÄ KB5035855 ºÍ KB5035857 Windows Server ¸üк󣬾ßÓÐ×îиüеÄÓò¿ØÖÆÆ÷½«ÓÉÓÚ LSASS ÄÚ´æʹÓÃÁ¿ÔöÌí¶øÍ߽ⲢÖØÐÂÆô¶¯¡£ÔÚ Microsoft ÕýʽÈÏ¿É´ËÄÚ´æй¶ÎÊÌâ֮ǰ£¬½¨ÒéÖÎÀíÔ±´ÓÆäÓò¿ØÖÆÆ÷жÔØÓÐÎÊÌâµÄ Windows Server ¸üС£
https://www.bleepingcomputer.com/news/microsoft/new-windows-server-updates-cause-domain-controller-crashes-reboots/
2. ³¯ÏÊ Kimsuky ÍøÂç·¸·¨ÍÅ»ïÒÑ×îÏÈʹÓÃÐÂÕ½ÂÔ¿ªÕ¹Ô˶¯
3ÔÂ21ÈÕ£¬¾ÝÐÅÏ¢Çå¾²¹©Ó¦ÉÌ Rapid7 ³Æ£¬³¯ÏÊÎÛÃûÕÑÖøµÄ Kimsuky ÍøÂç·¸·¨ÍÅ»ïÒÑ×îÏÈʹÓÃÐÂÕ½ÂÔ¿ªÕ¹Ô˶¯¡£¸ÃÍÅ»ïÒ²±»³ÆΪ Black Banshee¡¢Thallium¡¢APT 43 ºÍ Velvet Chollima¡ª¡ªºã¾ÃÒÔÀ´Ò»Ö±ÊÔͼ´ÓÕþ¸®»ú¹¹ºÍÖÇ¿âµÈ»ú¹¹»ñÊØÐÅÏ¢£¬Rapid7 ²»È·¶¨¸ÃÍÅ»ïÔõÑù·Ö·¢Æä×îй¥»÷£¬µ«È·ÐÅÓÐÓøºÔØ°üÀ¨Óж¾µÄ Microsoft ±àÒë HTML ×ÊÖú (CHM) ÎļþÒÔ¼° ISO¡¢VHD¡¢ZIP ºÍ RAR Îļþ¡£CHM Îļþ¿ÉÒÔ°üÀ¨Îı¾¡¢Í¼ÏñºÍ³¬Á´½Ó¡£Kimsuky ¿ÉÄܶÔËüÃǸü¸ÐÐËȤ£¬ÓÉÓÚËüÃÇ¿ÉÒÔÖ´ÐÐ JavaScript¡£Rapid7 µÄÑо¿Ö°Ô±ÆƽâÁËÆäÖÐÒ»¸ö CHM Îļþ£¬ËûÃÇÒÔΪÕâÊÇ Kimsuky µÄ×÷Æ·£¬²¢·¢Ã÷ÁË¡°Ò»¸öʹÓà HTML ºÍ ActiveX ÔÚ Windows ÅÌËã»úÉÏÖ´ÐÐí§ÒâÏÂÁîµÄʾÀý£¬Í¨³£ÓÃÓÚ¶ñÒâÄ¿µÄ¡±¡£
https://www.theregister.com/2024/03/21/kimsuky_chm_file_campaign/
3. ÍþвÐÐΪÕßʹÓà JETBRAINS TEAMCITY Îó²îÈö²¥¶ñÒâÈí¼þ
3ÔÂ20ÈÕ£¬Ç÷ÊƿƼ¼Ñо¿Ö°Ô±·¢Ã÷ʹÓà JetBrains TeamCity ÖÐ×î½üÅû¶µÄÎó²îCVE-2024-27198 £¨CVSS ÆÀ·Ö£º9.8£©ºÍCVE-2024-27199£¨CVSS ÆÀ·Ö 7.3£©Çå¾²Îó²îÀ´°²ÅŶà¸ö¶ñÒâÈí¼þµÄ¹¥»÷Ô˶¯¡£CVE-2024-27198 ÊÇ TeamCity Web ×é¼þÖеÄÒ»¸öÉí·ÝÑéÖ¤ÈƹýÎó²î£¬ÓÉÌ滻·¾¶ÎÊÌâ ( CWE-288 ) ÒýÆð£¬CVSS »ù±¾ÆÀ·ÖΪ 9.8£¨ÑÏÖØ£©¡£CVE-2024-27199ÊÇ TeamCity Web ×é¼þÖеÄÒ»¸öÉí·ÝÑéÖ¤ÈƹýÎó²î£¬ÓÉ·¾¶±éÀúÎÊÌâ ( CWE-22 ) ÒýÆð£¬CVSS »ù±¾ÆÀ·ÖΪ 7.3£¨¸ß£©¡£ÕâЩÎó²î¿ÉÄÜʹδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ý HTTP(S) »á¼û TeamCity ·þÎñÆ÷À´ÈƹýÉí·ÝÑéÖ¤¼ì²é²¢»ñµÃ¶Ô¸Ã TeamCity ·þÎñÆ÷µÄÖÎÀí¿ØÖÆ¡£
https://securityaffairs.com/160823/breaking-news/jetbrains-teamcity-flaws-actively-exploited.html
4. еÄÑ»· DoS ¹¥»÷¿ÉÄÜ»áÓ°Ïì¶à´ï 30Íò¸öϵͳ
3ÔÂ20ÈÕ£¬Ò»ÖÖÃûΪ¡°Ñ»· DoS¡±µÄоܾø·þÎñ¹¥»÷Õë¶ÔÓ¦ÓòãÐÒ飬¿ÉÒÔ½«ÍøÂç·þÎñÅä¶Ôµ½ÎÞÏÞͨѶѻ·ÖУ¬´Ó¶ø±¬·¢´ó×ÚÁ÷Á¿¡£¸Ã¹¥»÷ÓÉCISPA º¥Ä·»ô×ÈÐÅÏ¢Çå¾²ÖÐÐĵÄÑо¿Ö°Ô±Éè¼Æ£¬Ê¹ÓÃÓû§Êý¾Ý±¨ÐÒé (UDP)£¬Ó°ÏìÔ¤¼Æ 300,000 ̨Ö÷»ú¼°ÆäÍøÂç¡£´Ë´Î¹¥»÷¿ÉÄÜÊÇÓÉÓÚ UDP ÐÒéʵÏÖÖеÄÒ»¸öÎó²î£¨ÏÖÔÚ¸ú×ÙΪCVE-2024-2169 £©Ôì³ÉµÄ£¬¸ÃÎó²îÈÝÒ×Êܵ½ IP ÓÕÆ£¬²¢ÇÒ²»Ìṩ×ã¹»µÄÊý¾Ý°üÑéÖ¤¡£Ê¹ÓøÃÎó²îµÄ¹¥»÷Õ߻ὨÉèÒ»ÖÖ×ÔÎÒÑÓÐøµÄ»úÖÆ£¬¸Ã»úÖÆ»áÎÞÏÞÖƵر¬·¢¹ý¶àµÄÁ÷Á¿£¬²¢ÇÒÎÞ·¨×èÖ¹Ëü£¬´Ó¶øµ¼ÖÂÄ¿µÄϵͳÉõÖÁÕû¸öÍøÂç·ºÆð¾Ü¾ø·þÎñ (DoS) ÇéÐΡ£Ñ»· DoS ÒÀÀµÓÚ IP ÓÕÆ£¬²¢ÇÒ¿ÉÒÔ´Ó·¢ËÍÒ»ÌõÐÂÎÅÒÔÆô¶¯Í¨Ñ¶µÄµ¥¸öÖ÷»ú´¥·¢¡£
https://www.bleepingcomputer.com/news/security/new-loop-dos-attack-may-impact-up-to-300-000-online-systems/
5. ÒÁÀʺڿÍÉù³ÆÒÑÈëÇÖÒÔÉ«ÁеĺËÉèÊ©
3ÔÂ21ÈÕ£¬ Ò»¸öÓëÒÁÀÊÓйصĺڿÍ×éÖ¯Éù³ÆÔÚ¡°ÄäÃû¡±ºÚ¿ÍÐû²¼µÄÒ»ÆðÊÂÎñÖÐÆÆËðÁËÒÔÉ«ÁÐÃô¸ÐºËÉèÊ©µÄÅÌËã»úÍøÂ磬ÒÔ¿¹Òé¼ÓɳսÕù¡£ºÚ¿ÍÉù³Æ´ÓÎ÷ÃÉ¡¤ÅåÀ×˹¡¤ÄڸǷòºËÑо¿ÖÐÐÄÇÔÈ¡²¢Ðû²¼ÁËÊýǧ·ÝÎļþ£¬°üÀ¨ PDF¡¢µç×ÓÓʼþºÍ PowerPoint »ÃµÆƬ¡£Õâ¸öÉñÃØÉèÊ©ÄÚÓÐÒ»¸öÓëÒÔÉ«ÁÐδ¹ûÕæµÄºËÎäÆ÷ÍýÏëÓйصĺ˷´Ó¦¶Ñ£¬ÀúÊ·ÉÏÒ»Ö±ÊǹþÂí˹»ð¼ýµÄÄ¿µÄ¡£¸Ã×éÖ¯ÔÚÉ罻ýÌåÐÂÎÅÖÐÚ¹ÊÍÁËËûÃǵÄÒâͼ£¬Éù³Æ¡°ÎÒÃDz»ÏñÊÈѪµÄÄÚËþÄáÑǺúºÍËûµÄ¿Ö²À¾ü¶ÓÄÇÑù£¬ÎÒÃÇÒÔûÓÐƽÃñÊܵ½Î£Ïյķ½·¨¾ÙÐÐÕâ´ÎÐж¯¡£¡± Ö»¹ÜÓÐÕâÒ»ÉùÃ÷£¬¸Ã×éÖ¯ÔÚÁíÒ»ÌõÉ罻ýÌåÐÂÎÅÖÐÌåÏÖ£¬Ëü¡°ÎÞÒâ¾ÙÐк˱¬Õ¨£¬µ«Õâ´ÎÐж¯ºÜΣÏÕ£¬ÈκÎÊÂÇ鶼¿ÉÄܱ¬·¢¡±£¬Í¬Ê±»¹Ðû²¼ÁËÒ»¶ÎÃè»æºË±¬Õ¨ºÍºôÓõ³·ÀëÖ°Ô±µÄ¶¯»ÊÓƵ¡£
https://news.hitb.org/content/iranian-hackers-claim-have-breached-israeli-nuclear-facility
6. Ñо¿Ö°Ô±³Æ AceCryptor ¶ñÒâÈí¼þÔÚÅ·ÖÞ¼¤Ôö
3ÔÂ21ÈÕ£¬×÷ΪÕë¶ÔÅ·ÖÞ¸÷µØ×éÖ¯µÄÔ˶¯µÄÒ»²¿·Ö£¬ÒѾ·¢Ã÷ÁËÉæ¼° AceCryptor ¹¤¾ßµÄÊýǧ¸öÐÂѬȾ£¬ºÚ¿Í»ìÏý¶ñÒâÈí¼þ²¢½«ÆäÖ²Èëϵͳ¶ø²»±»·À²¡¶¾Èí¼þ¼ì²âµ½¡£ESET µÄÑо¿Ö°Ô±»¨ÁËÊýÄêʱ¼ä¸ú×Ù AceCryptor£¬ËûÃÇÖÜÈýÌåÏÖ£¬×î½üµÄ¹¥»÷Ô˶¯Óë֮ǰµÄµü´ú²î±ð£¬ÓÉÓÚ¹¥»÷ÕßÀ©Õ¹ÁËÄÚ²¿´ò°üµÄ¶ñÒâ´úÂëÀàÐÍ¡£AceCryptor ͨ³£ÓëÃûΪ Remcos»ò Rescoms µÄ¶ñÒâÈí¼þÒ»ÆðʹÓã¬ÕâÊÇÒ»ÖÖÇ¿Ê¢µÄÔ¶³Ì¼àÊÓ¹¤¾ß£¬Ñо¿Ö°Ô±ÒÑ·¢Ã÷¸Ã¹¤¾ß¶à´ÎÓÃÓÚÕë¶ÔÎÚ¿ËÀ¼µÄ×éÖ¯¡£³ýÁË Remcos ºÍÁíÒ»¸öÊìϤµÄ¹¤¾ß SmokeLoader Ö®Í⣬ESET ÌåÏÖ£¬ÏÖÔÚ»¹·¢Ã÷ AceCryptor ·Ö·¢ STOP ÀÕË÷Èí¼þºÍ Vidar ÇÔÈ¡³ÌÐòµÈ¶ñÒâÈí¼þ¡£ESET ƾ֤ĿµÄ¹ú¼Ò/µØÇø·¢Ã÷ÁËһЩ²î±ð¡£ÎÚ¿ËÀ¼µÄ¹¥»÷ʹÓÃÁËSmokeLoader£¬¶ø²¨À¼¡¢Ë¹Âå·¥¿Ë¡¢±£¼ÓÀûÑǺÍÈû¶ûάÑǵĹ¥»÷ÔòʹÓÃÁËRemcos¡£
https://therecord.media/acecryptor-malware-surge-europe-remcos