Ï£À°ÌìÈ»ÆøÔËÓªÉÌDESFAÔâµ½Ragnar LockerµÄÀÕË÷¹¥»÷

Ðû²¼Ê±¼ä 2022-08-24
1¡¢Ï£À°ÌìÈ»ÆøÔËÓªÉÌDESFAÔâµ½Ragnar LockerµÄÀÕË÷¹¥»÷

      

¾ÝýÌå8ÔÂ22ÈÕ±¨µÀ£¬Ï£À°×î´óµÄÌìÈ»ÆøÔËÓªÉÌDESFAÔâµ½ÍøÂç¹¥»÷ºóITϵͳÖжÏ ¡£DESFA½âÊͳÆ£¬¹¥»÷ÕßÊÔͼÈëÇÖÆäÍøÂ磬²¿ÃÅÎļþºÍÊý¾Ý¿ÉÄÜÒѱ»·ÃÎÊ£¬ÆäÍ£ÓÃÁËÐí¶àÔÚÏß·þÎñÒÔ±£»¤¿Í»§Êý¾Ý ¡£DESFAÏòÏû·ÑÕß±£Ö¤£¬´Ëʼþ²»»áÓ°ÏìÌìÈ»ÆøµÄ¹©Ó¦£¬ËùÓÐÊäÈëºÍÊä³öµã¾ùÕý³£ÔËÐÐ ¡£ÉÏÖÜÎ壬Ragnar LockerÉù³Æ¶Ô´Ë´Î¹¥»÷ÂôÁ¦£¬ÔÚÆäÊý¾Ý¹ûÈ»ÍøÕ¾Ðû²¼Ò»·Ý±»µÁÊý¾ÝµÄÁбíºó£¬»¹ÌåÏÖËûÃÇÔÚDESFAµÄϵͳÉÏ·¢ÏÖÁ˶à¸öÄþ¾²Â©¶´ ¡£


https://therecord.media/greek-gas-operator-refuses-to-negotiate-with-ransomware-group-after-attack/


2¡¢VMware Carbon Black¿Éµ¼ÖÂWindows·ºÆðBSODÎÊÌâ

      

¾Ý8ÔÂ23ÈÕ±¨µÀ£¬VMware Carbon Black¶ËµãÄþ¾²½â¾ö·½°¸µÄ²¿ÃŰ汾¿ÉÄܵ¼ÖÂWindows·ºÆðBSODÎÊÌâ ¡£ÎÊÌâÔ´ÓÚµ±ÈÕ²¿Êðµ½Carbon Black Cloud Sensor 3.6.0.1979-3.8.0.398µÄ¹æÔò¼¯£¬Ëü»áµ¼ÖÂÉ豸Íß½âÔÚÆô¶¯Ê±ÏÔʾÀ¶ÆÁ£¬²¢¾Ü¾ø·ÃÎÊ ¡£ÔÚÊÜÓ°ÏìµÄϵͳÉÏ£¬´íÎó±»Ê¶±ðΪ"PFN_LIST_CORRUPT" ¡£Carbon BlackºÍAVÇ©Ãû°ü8.19.22.224Ö®¼äËÆºõ´æÔÚ³åÍ»£¬VMwareĿǰÕýÔÚ¶Ô´ËʽøÐÐÊӲ죬²¢»Ø¹öÓÐÎÊÌâµÄ¹æÔò¼¯ ¡£


https://www.bleepingcomputer.com/news/security/vmware-carbon-black-causing-bsod-crashes-on-windows/


3¡¢LockBitµÄÊý¾Ý¹ûÈ»ÍøÕ¾Ôâµ½À´×ÔEntrustµÄDDoS¹¥»÷

      

ýÌå8ÔÂ22Èճƣ¬LockBitµÄÊý¾Ý¹ûÈ»ÍøÕ¾Ôâµ½ÁËÄþ¾²¹«Ë¾EntrustµÄDDoS¹¥»÷ ¡£LockBitÔÚ6Ô·ݹ¥»÷ÁËEntrust£¬²¢ÓÚÉÏÖÜÎåÍíÉÏ¿ªÊ¼¹ûÈ»¸Ã¹«Ë¾µÄÊý¾Ý ¡£´Ë´Îй¶°üÂÞ30½ØÍ¼£¬Éæ¼°Ö´·¨Îļþ¡¢ÓªÏúµç×Ó±í¸ñºÍ»á¼ÆÊý¾Ý ¡£Ñо¿ÈËÔ±³Æ£¬ÔÚй¶ºó²»¾Ã£¬¸ÃÍÅ»ïµÄTorÊý¾Ý¹ûÈ»ÍøÕ¾ÒòDDoS¹¥»÷¶øÎÞ·¨·ÃÎÊ ¡£´ËÍ⣬¹¥»÷Õß»¹ÔÚHTTPSÇëÇóÖÐÌí¼ÓÁËÒ»ÌõÏûÏ¢£¬ÒªÇóËûÃÇɾ³ýEntrustµÄÊý¾Ý ¡£Cisco³Æ¹¥»÷ΪÿÃëÀ´×Ô1000¶ą̀·þÎñÆ÷µÄ400¸öÇëÇó£¬EntrustÉÐδ¶Ô´ËÊÂ×ö³ö»Ø¸´ ¡£


https://www.bleepingcomputer.com/news/security/lockbit-ransomware-blames-entrust-for-ddos-attacks-on-leak-sites/


4¡¢ÐµÄGAIROSCOPE¹¥»÷Ä£ÐÍ¿É´ÓÆøÏ¶ÏµÍ³ÖÐÇÔÈ¡ÐÅÏ¢

      

ýÌå8ÔÂ22ÈÕ±¨µÀ£¬Ñо¿ÈËÔ±·¢ÏÖʹÓÃMEMSÍÓÂÝÒdz¬Éù²¨Òþ±ÎͨµÀÇÔÈ¡Êý¾ÝµÄGAIROSCOPE¹¥»÷Ä£ÐÍ ¡£ÓëÆäËüÕë¶ÔÆøÏ¶ÏµÍ³µÄ¹¥»÷Ò»Ñù£¬GAIROSCOPEÐèÒªÒÀ¿¿¹¥»÷Õßͨ¹ý±»Ñ¬È¾µÄUSB¡¢Ë®¿Ó¹¥»÷»ò¹©Ó¦Á´¹¥»÷µÈ¼ÆÄ±À´ÈëÇÖÄ¿±êÍøÂç²¢Á÷´«¶ñÒâÈí¼þ£¬»¹ÐèҪʹÓöñÒâÓ¦ÓÃѬȾԱ¹¤µÄÊÖ»ú ¡£±»Ñ¬È¾µÄÊÖ»ú»áÔÚÎïÀí¾àÀëºÜ½üµÄµØ·½¼ì²âµ½´«Ê䣬²¢Í¨¹ýÉ豸ÄÚÖõÄÍÓÂÝÒÇ´«¸ÐÆ÷½øÐмàÌý£¬Ëæºó½«Êý¾Ý±»½âµ÷ºÍ½âÂ룬ͨ¹ýWi-Fi´«Ê䏸¹¥»÷Õß ¡£


https://thehackernews.com/2022/08/new-air-gap-attack-uses-mems-gyroscope.html


5¡¢Ñо¿ÍŶӷ¢ÏÖLinuxÄÚºËÖдæÔÚ8ÄêµÄ©¶´DirtyCred 

      

8ÔÂ22ÈÕ±¨µÀ³Æ£¬Ñо¿ÍŶӷ¢ÏÖLinuxÄÚºËÖдæÔÚ8ÄêµÄDirtyCred£¬ÏñDirtyPipeÒ»ÑùÁîÈËÌÖÑá ¡£DirtyCredÊÇÒ»¸öÄÚºËÀûÓÿ´·¨£¬Ëü½«·ÇÌØÈ¨ÄÚºËÆ¾Ö¤ÓëÌØÈ¨Æ¾Ö¤½»»»À´ÌáÉýÌØÈ¨ ¡£DirtyCredûÓÐÁýÕÖÄں˶ÑÉϵÄÈκÎÒªº¦Êý¾Ý×ֶΣ¬¶øÊÇÀÄÓöÑÄÚ´æÖØÓûúÖÆÀ´»ñµÃÌØÈ¨ ¡£DirtyCredÀûÓÃÁËÊͷźóʹÓé¶´£¨CVE-2022-2588£©£¬¸Ã©¶´´æÔÚÓÚLinuxÄÚºËÖÐnet/sched/ls_route.c¹ýÂËÆ÷ʵÏÖµÄroute4_change ¡£


https://thehackernews.com/2022/08/as-nasty-as-dirty-pipe-8-year-old-linux.html


6¡¢Ó¢¹úijÆû³µ¾­ÏúÉÌÔâµ½ÀÕË÷¹¥»÷ºóºËÐÄϵͳÎÞ·¨»Ö¸´

      

¾ÝýÌå8ÔÂ22Èճƣ¬Ó¢¹úÆû³µ¾­ÏúÉÌHoldcroft Motor GroupÔâµ½ÁËÀÕË÷¹¥»÷ ¡£¹¥»÷·¢ÉúÔÚ7ÔÂ28ÈÕ£¬¸Ã¹«Ë¾µÄIT»ù´¡ÉèÊ©Êܵ½ÁËÑÏÖØµÄÓ°Ï죬ÄÚ²¿´æ´¢ÇøÓòµÄÊý¾Ý¶ªÊ§ ¡£¾­¹ýÊӲ죬ȷÈϲ¿ÃÅÔ±¹¤µÄ¸öÈËÐÅÏ¢ÒѾ­Ð¹Â¶ ¡£¸Ã¹«Ë¾µÄÉùÃ÷ÌåÏÖ£¬ËûÃÇÒѾ­Éè·¨½â¾öÁË´ó²¿ÃŵķÃÎÊÎÊÌ⣬µ«Ò»Ð©ºËÐÄϵͳÒѱ»Ëð»µÎÞ·¨»Ö¸´»ò±»ÓÀ¾Ãɾ³ý ¡£¼øÓÚÆû³µ¾­ÏúÉÌ´¦ÖÃÁË´óÁ¿¿Í»§µÄ¸öÈ˺ͲÆÕþÐÅÏ¢£¬¸ÃÐÐÒµÔâµ½ÀÕË÷¹¥»÷µÄÇ÷ÊÆÉÏÉý ¡£


https://www.infosecurity-magazine.com/news/car-dealership-hit-by-major/