¼ÓÖÝij¸£Àûƽ̨Ôâµ½¹¥»÷Êýǧ¸öÕË»§ÐÅϢй¶

Ðû²¼Ê±¼ä 2024-04-29
1. ¼ÓÖÝij¸£Àûƽ̨Ôâµ½¹¥»÷Êýǧ¸öÕË»§ÐÅϢй¶


4ÔÂ27ÈÕ£¬ÍþвÐÐΪÕßÈëÇÖÁ˼ÓÖÝÒ»¸öרÃÅÓÃÓÚ¸£ÀûÏîÄ¿µÄƽ̨É쵀 19000 ¶à¸öÔÚÏßÕÊ»§¡£¹ÙÔ±ÃDZ¨¸æ³Æ£¬Çå¾²Îó²î±¬·¢ÔÚ 2 Ô 9 ÈÕ£¬ÆäʱÓÐÈ˵ǼÁËһЩ BenefitsCal Óû§µÄÕË»§¡£ÍþвÐÐΪÕßʹÓôӵÚÈý·½ÍøÕ¾»ñµÃµÄÖظ´Ê¹ÓõÄÃÜÂë¡£BenefitsCal ÊÇÒ»¸öλÓÚ¼ÓÀû¸£ÄáÑÇÖݵÄÍøÂçƽ̨£¬Ê¹Óû§Äܹ»ÉêÇëºÍ¼àÊÓһϵÁи£ÀûÍýÏ룬°üÀ¨Ê³Îïȯ¡¢ÏÖ½ðÔ®ÖúºÍÒ½ÁƸ£Àû¡£Æ¾Ö¤ÈÕÆÚй¶֪ͨ£¬Ç±ÔÚ鶵ÄÐÅÏ¢¿ÉÄÜ°üÀ¨Óû§ÐÕÃû¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢Éç»áÇå¾²ºÅÂëµÄÍêÕû»ò×îºóËÄλÊý×Ö¡¢µç×ÓÓʼþµØµã¡¢µç»°ºÅÂë¡¢EBT ¿¨ºÅ¡¢°¸¼þ±àºÅ¡¢Medi-Cal ID ºÅÒÔ¼°ÓйØÆäÍýÏë×ʸñºÍ¸£ÀûµÄÐÅÏ¢¡£BenefitsCal ÕýÔÚ֪ͨÊÜÓ°ÏìµÄÓû§²¢ÏòËûÃÇÌṩ¿ÉÒÔ×öʲôµÄ˵Ã÷¡£ÎªÁËÓ¦¶ÔÕâÒ»ÊÂÎñ£¬¸Ã»ú¹¹Í£ÓÃÁËÕË»§²¢Æô¶¯ÁËÊӲ죬Ч¹ûÏÔʾ¹¥»÷ÕßÔÚ 2023 Äê 3 Ô 1 ÈÕÖÁ 2024 Äê 2 Ô 13 ÈÕʱ´úÓµÓлá¼ûȨÏÞ¡£ 


https://securityaffairs.com/162408/data-breach/california-state-welfare-platform-accounts-compromise.html


2. Å·ÖÞÐ̾¯×éÖ¯Ðû²¼ÔÚÖ´·¨Ðж¯ÖÐÈ¡µÞLabHost


4ÔÂ26ÈÕ£¬Å·ÖÞÐ̾¯×éÖ¯Ðû²¼£¬È«Çò×î´óµÄPhaasƽ̨֮һ LabHost ÔÚÈ«ÇòÖ´·¨Ðж¯Öб»µ·»Ù¡£À´×Ô²»ÉÙÓÚ 19 ¸ö¹ú¼ÒµÄÕþ¸®¼ÓÈëÁËÓÉÓ¢¹úÂ׶ؾ¯Ô±ÌüǣͷµÄΪÆÚÒ»ÄêµÄÐж¯£¬¾Ð²¶ÁË 37 ÃûÏÓÒÉÈË£¬ÆäÖаüÀ¨¾Ý³ÆÓë¸Ã·þÎñÔËÓª¼°Æäԭʼ¿ª·¢ÓйصÄÈË¡£È«ÇòÔ¼ÓÐ 10000 ÈËʹÓø÷þÎñ£¬Ô·Ñƽ¾ùΪ 249 ÃÀÔª¡£ÊӲ췢Ã÷ÖÁÉÙ 40000 ¸öÓë LabHost Á´½ÓµÄÍøÂç´¹ÂÚÓòÃû£¬²¢ÓÕÆ­Óû§½»³öÃô¸ÐÏêϸÐÅÏ¢¡£ÏàʶÓйØÊÓƵÖеĴÌÍ´µÄ¸ü¶àÐÅÏ¢£¬²¢È·±£ÄúÖªµÀÔõÑù×èÖ¹³ÉΪÍøÂç´¹ÂÚ¹¥»÷µÄÊܺ¦Õß¡£ÔÚÆäËûÍøÂç·¸·¨ÐÂÎÅÖУ¬ÃÀ¹úÖ´·¨²¿·Ö¶Ô Samourai Wallet¼ÓÃÜÇ®±Ò»ìÏý·þÎñµÄÊ×´´ÈËÌá³öϴǮָ¿Ø£¬Í¬Ê±Áª°î¹¥»÷´ËÀà·þÎñ¡£


https://www.welivesecurity.com/en/videos/major-phishing-as-a-service-platform-disrupted-week-security-tony-anscombe/


3. Ñо¿ÍŶӷ¢Ã÷ʹÓÃofficeÎó²îÕë¶ÔÎÚ¿ËÀ¼µÄ¹¥»÷Ô˶¯


4ÔÂ27ÈÕ£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÁËÕë¶ÔÎÚ¿ËÀ¼µÄÒ»ÏîÓÐÕë¶ÔÐԵĹ¥»÷Ô˶¯£¬¸ÃÐж¯Ê¹ÓÃÁË Microsoft Office ÖнüÆßÄêµÄij¸öÎó²î£¬ÔÚÊÜѬȾµÄϵͳÉÏ´« Cobalt Strike¡£¾Ý Deep Instinct ³Æ£¬¸Ã¹¥»÷Á´±¬·¢ÓÚ 2023 Äêµ×£¬½ÓÄÉ PowerPoint »ÃµÆƬÎļþ£¨¡°signal-2023-12-20-160512.ppsx¡±£©×÷ΪÆðµã£¬ÎļþÃûÌåÏÖËü¿ÉÄÜÒÑͨ¹ý Signal ¼´Ê±Í¨Ñ¶Ó¦ÓóÌÐò¹²Ïí¡£Ö»¹ÜÔÆÔÆ£¬Ã»ÓÐÏÖʵ֤¾ÝÅú×¢ PPSX ÎļþÊÇÒÔÕâÖÖ·½·¨·Ö·¢µÄ£¬Ö»¹ÜÎÚ¿ËÀ¼ÅÌËã»ú½ôÆÈÏìӦС×é (CERT-UA) ·¢Ã÷ÁËÁ½¸öʹÓøÃÐÂÎÅÓ¦ÓóÌÐò×÷Ϊ¶ñÒâÈí¼þת´ïµÄ²î±ðÔ˶¯ÒÑÍùµÄÏòÁ¿¡£ÕâÉ漰ʹÓÃCVE-2017-8570£¨CVSS ·ÖÊý£º7.8£©£¬ÕâÊÇ Office ÖÐÏÖÒÑÐÞ²¹µÄÔ¶³Ì´úÂëÖ´Ðйýʧ£¬¸Ã¹ýʧ¿ÉÄÜÔÊÐí¹¥»÷ÕßÔÚ˵·þÊܺ¦Õß·­¿ªÌØÖÆÎļþ¡¢¼ÓÔØÔ¶³Ì¾ç±¾ÍйÜÔÚ weavesilk[.]space ÉÏ¡£


https://thehackernews.com/2024/04/ukraine-targeted-in-cyberattack.html


4. Okta ÖÒÑÔ¿Í»§¿ÉÄÜÔâÊÜب¹ÅδÓеÄײ¿â¹¥»÷


4ÔÂ27ÈÕ£¬Okta ÖÒÑԳƣ¬Õë¶ÔÆäÉí·ÝºÍ»á¼ûÖÎÃ÷È·¾ö¼Æ»®µÄײ¿â¹¥»÷·ºÆðÁËب¹ÅδÓеļ¤Ôö¡£ÍþвÐÐΪÕßͨ¹ý×Ô¶¯ÊµÑéͨ³£´ÓÍøÂç·¸·¨·Ö×ÓÄÇÀﹺÖõÄÓû§ÃûºÍÃÜÂëÁбí£¬Ê¹ÓÃƾ֤Ìî³äÀ´µÇ¼¡£Okta ÔÚ½ñÌìµÄÒ»·Ýͨ¸æÖÐÌåÏÖ£¬ÕâЩ¹¥»÷ËƺõÔ´×Ô Cisco Talos ֮ǰ±¨¸æµÄ±©Á¦ÆƽâºÍÃÜÂëÅçÉä¹¥»÷ÖÐʹÓõÄÏàͬ»ù´¡ÉèÊ©¡£ÔÚ Okta ÊӲ쵽µÄËùÓй¥»÷ÖУ¬ÇëÇó¾ùÀ´×Ô TOR ÄäÃûÍøÂçºÍÖÖÖÖסլÊðÀí£¨ÀýÈç NSOCKS¡¢Luminati ºÍ DataImpulse£©¡£Okta ÌåÏÖ£¬¼à²âµ½µÄ¹¥»÷Õë¶ÔÔÚ Okta Classic Engine ÉÏÔËÐÐÇÒ ThreatInsight ÉèÖÃΪ½öÉóºËģʽ¶ø²»ÊÇÈÕÖ¾ºÍÇ¿ÖÆģʽµÄ×éÖ¯ÌØÊâÈÝÒס£Í¬Ñù£¬²»¾Ü¾øÄäÃûÊðÆÊÎö¼ûµÄ×éÖ¯Ò²¿´µ½Á˸ü¸ßµÄ¹¥»÷ÀÖ³ÉÂÊ¡£Okta ÌåÏÖ£¬Ö»ÓÐһС²¿·Ö¿Í»§µÄ¹¥»÷È¡µÃÁËÀֳɡ£


https://www.bleepingcomputer.com/news/security/okta-warns-of-unprecedented-credential-stuffing-attacks-on-customers/


5. ¾É´úÂëÖеÄйýʧºÍÕë¶Ô KASLR µÄ²àͨµÀ


4ÔÂ26ÈÕ£¬¼´½«ÍƳöµÄ Windows 11 °æ±¾ 24H2 ÏÖÔÚÕýÔÚͨ¹ý Windows Insider ÍýÏë¾ÙÐйûÕæÔ¤ÀÀ¡£ÕâƪÎÄÕÂÏÈÈÝÁË·¢Ã÷ 24H2 ÖÐÒýÈëµÄ¶à¸öÄÚºËÎó²î²¢±àдÎó²îʹÓóÌÐòµÄÀú³Ì£¬°üÀ¨ÈƹýÄÚºË ASLR (KASLR) µÄÐÂÇ¿»¯¡£ÕâÀïÐÎòµÄËùÓÐÎó²î¶¼±£´æÓÚ NT ÄÚºË×Ô¼º (ntoskrnl.exe) ÖУ¬Î»ÓÚ¿ÉÓÉÈκÎÀú³ÌŲÓõÄϵͳŲÓÃÖУ¬ÎÞÂÛÆäȨÏÞ¼¶±ð»òɳÏäÔõÑù¡£ÔÚ 24H2 ¶Ô NT Äں˵ĸ÷¸ö²¿·Ö¾ÙÐÐÄæÏò¹¤³Ìʱ£¬ÎÒ·¢Ã÷ÁËÁ½¸öÎó²î£¬ÕâÁ½¸öÎó²î¶¼ÊÇÓû§Ä£Ê½ÄÚ´æµÄË«ÖØ»ñÈ¡¡£ÕâЩ¹ýʧÌØÊâÓÐȤ£¬ÓÉÓÚËüÃÇ·ºÆðÔÚÒÔÇ°Çå¾²µÄºã¾Ã±£´æµÄ´úÂëÖС£ÔÚÒÔÇ°µÄ Windows °æ±¾ÖУ¬ÓÉÓÚÐí¶àϵͳŲÓÃÔÚÆäÊä³öÖаüÀ¨ÄÚºËÖ¸Õ룬Òò´Ë»÷°Ü KASLR ÊÇ΢ȱ·¦µÀµÄ¡£È»¶ø£¬ÔÚ 24H2 ÖУ¬ÕâЩÄں˵صã×ß©²»Ôٿɹ©·ÇÌØȨŲÓÃÕßʹÓá£ÔÚûÓо­µäµÄ KASLR ÈƹýµÄÇéÐÎÏ£¬ÎªÁËÈ·¶¨Äں˵Ľṹ£¬ÐèÒªÒ»ÖÖÐÂÊÖÒÕ¡£ÎÒÌý˵¹ýÒ»ÖÖÔÚ Linux ÉÏʹÓõÄÊÖÒÕ£¬³ÆΪEntryBleed£¬ËüʹÓüÆʱÅÔ·À´È·¶¨Äں˵ĵص㣬²¢¾öÒéÑо¿ÊÇ·ñ¿ÉÒÔÔÚ Windows ÉÏʹÓÃÀàËƵÄÊÖÒÕ¡£


https://exploits.forsale/24h2-nt-exploit/


6. ICICIÒøÐÐй¶17000Ãû¿Í»§µÄÐÅÓÿ¨Êý¾Ý


4ÔÂ28ÈÕ£¬ICICI ÒøÐÐÊÇÓ¡¶ÈÁìÏȵÄ˽ÈËÒøÐÐÖ®Ò»£¬ÒâÍâµØ½«ÊýǧÕÅÐÂÐÅÓÿ¨µÄÊý¾Ý̻¶¸ø·ÇÔ¤ÆÚÎüÊÕÕߵĿͻ§¡£ICICI ÒøÐÐÓÐÏÞ¹«Ë¾ÊÇÒ»¼ÒÓ¡¶È¿ç¹úÒøÐкͽðÈÚ·þÎñ¹«Ë¾£¬×ܲ¿Î»ÓÚÃÏÂò¡£ËüΪÆóÒµºÍÁãÊÛ¿Í»§ÌṩÆÕ±éµÄÒøÐкͽðÈÚ·þÎñ¡£¸ÃÒøÐÐÔÚÓ¡¶È¸÷µØÓµÓÐ 6000 ¼Ò·ÖÐÐºÍ 17000 ̨ ATM »ú£¬ÓªÒµÆÕ±é 17 ¸ö¹ú¼Ò¡£ÓÉÓÚÆäÒƶ¯ÒøÐÐÓ¦ÓóÌÐò¡°iMobile¡±ÖеÄÊÖÒÕ¹ýʧ£¬¸ÃÒøÐж³½áÁË 17,000 ÕÅÐÅÓÿ¨¡£¸Ã¹ÊÕϵ¼ÖÂÓû§¿É»ñÈ¡ÆäËû¿Í»§µÄÏêϸÐÅÏ¢¡£Ì»Â¶µÄ²ÆÎñÐÅÏ¢°üÀ¨ÐÅÓÿ¨ºÅ¡¢ÓÐÓÃÆںͿ¨ÑéÖ¤Öµ (CVV)¡£ÔÚһЩ¿Í»§ÔÚÉ罻ýÌåÉϱ¨¸æ¸ÃÎÊÌâºó£¬¸ÃÒøÐÐÒâʶµ½ÁËÕâÒ»ÎÊÌâ¡£¸ÃÒøÐÐÌåÏÖ£¬¸ÃÊÂÎñÓ°ÏìÁ˸ÃÒøÐÐÔ¼ 0.1% µÄÐÅÓÿ¨¡£ICICI ÒøÐÐÕýÔÚÏòÊÜÓ°ÏìµÄ¿Í»§¿¯ÐÐеÄÐÅÓÿ¨¡£2023 Äê 4 Ô£¬Cybernews µÄÑо¿Ö°Ô±±¨¸æ³Æ£¬ICICI ÒøÐÐй¶ÁËÊý°ÙÍòÌõ°üÀ¨Ãô¸ÐÊý¾ÝµÄ¼Í¼£¬°üÀ¨¸ÃÒøÐпͻ§µÄ²ÆÎñÐÅÏ¢ºÍСÎÒ˽¼ÒÎļþ¡£


https://securityaffairs.com/162479/security/icici-bank-technical-glitch.html