΢Èí³ÆºÚ¿ÍÀûÓÃBoa·þÎñÆ÷ÖеÄ©¶´¹¥»÷ÄÜÔ´ÐÐÒµ×éÖ¯

Ðû²¼Ê±¼ä 2022-11-24
1¡¢Î¢Èí³ÆºÚ¿ÍÀûÓÃBoa·þÎñÆ÷ÖеÄ©¶´¹¥»÷ÄÜÔ´ÐÐÒµ×éÖ¯

΢ÈíÔÚ11ÔÂ22ÈÕÐû²¼³ÂËߣ¬³Æ·¢ÏÖ¹¥»÷ÕßÀûÓÃBoa web·þÎñÆ÷ÖеÄ©¶´¹¥»÷ÄÜÔ´ÐÐÒµ×éÖ¯ ¡£Recorded FutureÔøÓÚ2022Äê4ÔÂÅû¶Õë¶ÔÓ¡¶È¶à¸öµçÍøÔËÓªÉ̵Ĺ¥»÷»î¶¯£¬µ«Ã»ÓÐÏêϸ˵Ã÷¹¥»÷ý½é ¡£Î¢ÈíÌåÏÖ£¬¹¥»÷ÕßÀûÓÃÁËBoaÍøÂç·þÎñÆ÷ÖеÄÒ»¸öÒ×Êܹ¥»÷µÄ×é¼þ ¡£Boa×Ô2005ÄêÒÔÀ´ÒÑÕýʽͣ²ú£¬µ«ÎïÁªÍøÉ豸ÈÔÔÚʹÓøýâ¾ö·½°¸£¬Î¢ÈíÒ»¸öÐÇÆÚÄÚÔÚÈ«Çò·¢ÏÖÁËÁè¼Ý100Íò¸ö̻¶ÔÚ»¥ÁªÍøÉϵÄBoa·þÎñÆ÷×é¼þ ¡£Boa·þÎñÆ÷´æÔÚ¶à¸ö©¶´£¬°üÂÞÈÎÒâÎļþ·ÃÎÊ©¶´(CVE-2017-9833)ºÍÐÅϢй¶©¶´(CVE-2021-33558) ¡£

https://www.microsoft.com/en-us/security/blog/2022/11/22/vulnerable-sdk-components-lead-to-supply-chain-risks-in-iot-and-ot-environments/

2¡¢KillnetÉù³Æ¶Ôµ¼ÖÂÅ·ÖÞÒé»áÍøÕ¾¹Ø±ÕµÄDDS¹¥»÷ÂôÁ¦

¾ÝýÌå11ÔÂ23ÈÕ±¨µÀ£¬ºÚ¿ÍÍÅ»ïKillnetµÄÒ»²¿ÃÅAnonymous RussiaÉù³ÆÌᳫDDoS¹¥»÷£¬µ¼ÖÂÅ·ÖÞÒé»áµÄÍøÕ¾ ¡£Å·ÖÞÒé»áÖ÷ϯ֤ʵÁËÕâһʼþ£¬³ÆÒé»áµÄITÈËÔ±ÕýÔÚ»¹»÷²¢±£»¤ÏµÍ³ ¡£´ËÍ⣬11ÔÂ22ÈÕÁ賿£¬Killnet»¹¹¥»÷ÁËÓ¢¹úÍþÁ®Íõ×ÓµÄÍøÕ¾£¬¾¡¹Ü¸ÃÍøÕ¾ÏÖÔÚ¿ÉÒÔÕý³£ÔËÐУ¬µ«Cloudflare¶ÔÁ¬½Ó½øÐÐÁËÌØ±ðµÄÄþ¾²¼ì²é ¡£Killnet»¹·¢Ìû³Æ£¬ÆäÄ¿±êÊÇÂ×¶ØÖ¤È¯½»Ò×Ëù¡¢Ó¢¹ú¾ü¶ÓºÍÒøÐÐ×Ô¶¯ÇåËãϵͳ(Bacs)µÄÍøÕ¾ ¡£

https://www.bleepingcomputer.com/news/security/pro-russian-hacktivists-take-down-eu-parliament-site-in-ddos-attack/

3¡¢²¨¶àÀè¸÷µÄDCHÒ½ÔºÔâµ½ÀÕË÷¹¥»÷Ó°ÏìÔ¼120ÍòÃû»¼Õß

ýÌå11ÔÂ22Èճƣ¬²¨¶àÀè¸÷µÄÒ½ÉúÖÐÐÄÒ½Ôº£¨DCH£©Ôâµ½ÐÂÀÕË÷ÍÅ»ïProject RelicµÄ¹¥»÷ ¡£¹¥»÷ÕßÒѹûÈ»ÆäÇÔÈ¡µÄ211 GBÎļþÖеÄ114 MBÊý¾Ý£¬Ñù±¾Êý¾Ý°üÂÞÁËҽԺϵͳµÄÄÚ²¿Îļþ£¬¹ØÓÚÔ±¹¤µÄÎļþÒÔ¼°Éæ¼°²¡ÈËÒ½ÁÆÐÅÏ¢µÄÎļþµÈ ¡£DCHÔÚ11ÔÂ9ÈÕ֪ͨHHS£¬ÓÐ1195220Ãû»¼ÕßÊܵ½´Ë´ÎʼþµÄÓ°Ïì ¡£¾ÝBlackPoint³Æ£¬Project RelicÀÕË÷Èí¼þÊÇÓÃGoÓïÑÔ¿ª·¢µÄ£¬µ«ÓÃÓÚ°²×°¶ñÒâÈí¼þºÍÇÔÈ¡Êý¾ÝµÄÒªÁìÈÔȻδ֪ ¡£

https://www.databreaches.net/doctors-center-hospital-reports-1-2-million-patients-affected-by-ransomware-attack/

4¡¢¶íÂÞ˹RoskomnadzorµÄÄÚÍø±»Cyber PartisansÈëÇÖ

¾Ý11ÔÂ22ÈÕ±¨µÀ£¬¶íÂÞ˹»¥ÁªÍøºÍýÌå¼à¹Ü»ú¹¹RoskomnadzorÔâµ½ºÚ¿Í¹¥»÷ ¡£Cyber PartisansÓÚÉÏÖÜÎåÉù³Æ´Ó¸Ã»ú¹¹ÇÔÈ¡ÁËÊýǧ·ÝÄÚ²¿Îļþ²¢¼ÓÃÜÁËÆäϵͳ ¡£¶íÂÞ˹ͨÓÃÎÞÏßµçÆµÂÊÖÐÐÄ(GRFC)ÌåÏÖ£¬ºÚ¿ÍÉϸöÔÂÊ×´ÎʵÑéʹÓÃÒÔǰδÀûÓùýµÄ©¶´ÈëÇָûú¹¹£¬Ä¿Ç°ÍøÂç¹¥»÷Òѵõ½¿ØÖÆ£¬Ã»ÓÐÈκλúÃÜÐÅϢй¶ ¡£×÷Ϊ»ØÓ¦£¬Cyber PartisansÔÚÖÜÁù͸¶ËûÃÇ»ñµÃÁËÔ±¹¤µÄ»¤ÕÕÊý¾ÝºÍÒ½ÁƼǼ¡¢ÄÚ²¿ÓʼþºÍ¸Ã»ú¹¹ÏîÄ¿µÄ³ÂËß ¡£

https://therecord.media/belarusian-hacktivists-claim-to-breach-russias-internet-regulator/

5¡¢Bitdefender͸¶SharkBotľÂíÖØ·µGoogle PlayÉ̵ê

BitdefenderÔÚ11ÔÂ21Èճƣ¬Ò»×éαװ³ÉÎļþ¹ÜÀíÆ÷µÄ¶ñÒâAndroidÓ¦ÓÃÒÑÉøÍ¸µ½¹Ù·½Google PlayÓ¦ÓÃÉ̵ּ꣬ÔÚʹÓû§Ñ¬È¾SharkbotľÂí ¡£·¢ÏֵĶñÒâÓ¦ÓÃΪX-File Manager¡¢FileVoyagerºÍLiteCleaner M ¡£BitdefenderÒ£²âÊý¾Ý·´Ó³³ö´Ë´Î»î¶¯µÄÄ¿±ê·¶Î§½ÏС£¬´ó¶àÊýÄ¿±êλÓÚÓ¢¹ú£¬Æä´ÎÊÇÒâ´óÀû¡¢ÒÁÀʺ͵¹ú ¡£Ä¿Ç°£¬ÕâЩ·¨Ê½¶¼ÒÑ´ÓGoogle PlayÉ̵êÖÐɾ³ý ¡£

https://www.bitdefender.com/blog/labs/android-sharkbot-droppers-on-google-play-underlines-platforms-security-needs/

6¡¢KasperskyÐû²¼2023ÄêICSÍøÂçÍþÐ²Ì¬ÊÆµÄÔ¤²â³ÂËß

11ÔÂ22ÈÕ£¬KasperskyÐû²¼Á˹ØÓÚ2023ÄêICSÍøÂçÍþÐ²Ì¬ÊÆµÄÔ¤²â³ÂËß ¡£³ÂËßÖ¸³ö£¬Ëæ×ÅÏÖÓеĺÍеÄÕ½ÊõÒÔ¼°Õ½ÂÔÁªÃ˵ķºÆð£¬¹¥»÷Ä¿±êµÄµØÀíλÖý«²»ÐÐÖÆÖ¹µØ·¢Éú±ä»¯£¬×òÌìµÄÃËÓÑ¿ÉÄÜ»á³ÉΪ½ñÌìµÄÄ¿±ê ¡£ÐÐÒµÖØÐĽ«·¢Éú±ä»¯£¬ºÜ¿ì¾Í»á¿´µ½Õë¶ÔũҵºÍʳƷ¡¢ÎïÁ÷ºÍÔËÊä¡¢ÄÜÔ´¡¢¸ß¿Æ¼¼ºÍÒ½ÁÆÏà¹Ø²¿ÃŵĹ¥»÷ ¡£Õë¶Ô´«Í³Ä¿±êµÄAPT¹¥»÷ÈÔ»á´æÔÚ£¬Ö÷Òª°üÂÞ¾ü¹¤ÆóÒµ¡¢Õþ¸®»ú¹¹ºÍÒªº¦µÄ»ù´¡ÉèÊ© ¡£

https://securelist.com/ics-cyberthreats-in-2023/108011/