ÃÀ¹ú°®´ïºÉ¹ú¼ÒʵÑéÊÒÊýǧÃûÔ±¹¤µÄÏêϸÐÅÏ¢±»¹ûÈ»

Ðû²¼Ê±¼ä 2023-11-22
1¡¢ÃÀ¹ú°®´ïºÉ¹ú¼ÒʵÑéÊÒÊýǧÃûÔ±¹¤µÄÏêϸÐÅÏ¢±»¹ûÈ»


¾ÝýÌå11ÔÂ20ÈÕ±¨µÀ£¬ºÚ¿ÍSiegedSecÔÚ°µÍø¹ûÈ»Á˰®´ïºÉ¹ú¼ÒʵÑéÊÒ(INL)Ô±¹¤µÄÊý¾Ý¡£INLÊÇÃÀ¹úÄÜÔ´²¿ÔËÓªµÄºËÑо¿ÖÐÐÄ£¬ÓµÓÐ5700ÃûÔ­×ÓÄÜ¡¢×ÛºÏÄÜÔ´ºÍ¹ú¼ÒÄþ¾²ÁìÓòµÄרҵÈËÔ±¡£ÖÜÒ»£¬SiegedSecÐû²¼ÒÑ»ñµÃINLϵͳµÄ·ÃÎÊȨÏÞ£¬ÆäÖаüÂÞ¡°ÊýÊ®Íò¡±Ô±¹¤¡¢Óû§ºÍ¹«ÃñµÄÏêϸÐÅÏ¢¡£¹¥»÷ÕßÐû²¼ÁËй¶ÐÅÏ¢µÄÑù±¾£¬Éæ¼°Éç»áÄþ¾²ºÅ¡¢Ò½ÁƱ£½¡ÐÅÏ¢ºÍÒøÐÐÕË»§µÈ¡£ÆäÖÐÒ»¸ö°üÂÞÏêϸԱ¹¤ÐÅÏ¢µÄÎļþÓÐ58000¶àÐÐÊý¾Ý£¬º­¸ÇÔÚÖ°¡¢ÍËÐݺÍÀëÖ°Ô±¹¤¡£


https://cyberscoop.com/idaho-national-laboratory-siegedsec/


2¡¢°ÍÀèÎÛË®´¦Öûú¹¹SIAAPÔâµ½¹¥»÷ÍⲿÁ¬½ÓÔÝʱ¶Ï¿ª


¾Ý11ÔÂ21ÈÕ±¨µÀ£¬Îª°ÍÀè¼°ÆäÖܱߵØÓò900ÍòÈËÌṩÎÛË®´¦Ö÷þÎñµÄ»ú¹¹SIAAPÔâµ½¹¥»÷¡£SIAAP¹ÜÀí×Å·¨¹úËĸöÊ¡½ü275Ó¢ÀïµÄ¹ÜµÀ£¬ËüÔÚ·¢ÏÖ¹¥»÷ºóÒѹرÕËùÓÐÍⲿÁ¬½Ó£¬À´·ÀÖ¹¹¥»÷µÄÁ÷´«¡£ÊÂÇéÈËÔ±ÌåÏÖ£¬ËûÃÇÒѽÓÄÉ´ëÊ©£¬ÒÔά³Ö·¨À¼Î÷µº¾ÓÃñ¹«¹²ÎÀÉú·þÎñµÄÁ¬ÐøÐÔ¡£Ò»·Ý½ô¼±ÃüÁîÒÑÊÚȨ¸Ã»ú¹¹Æ¸ÇëÄþ¾²¹«Ë¾²¢¹ºÖÃÉ豸£¬À´»Ö¸´»ò»¹Ô­ËûÃÇÊÂÇéËùÐèµÄϵͳ¡£Ä¿Ç°£¬Ã»ÓкڿÍÍÅ»ïÉù³Æ¶ÔÕâ´Î¹¥»÷ÂôÁ¦¡£


https://therecord.media/paris-wastewater-agency-hit-cyberattack


3¡¢RhysidaÍÅ»ïÒÔ20 BTCµÄ¼Û¸ñÅÄÂô´óӢͼÊé¹ÝµÄÊý¾Ý


ýÌå11ÔÂ20Èճƣ¬ÀÕË÷ÍÅ»ïRhysida½«´óӢͼÊé¹ÝÌí¼Óµ½ÆäTorÐ¹Â¶ÍøÕ¾¡£¸ÃÍÅ»ïÉù³ÆÇÔÈ¡ÁË´óÁ¿¡°ÁîÈËÓ¡ÏóÉî¿ÌµÄÊý¾Ý¡±£¬²¢ÒÔ20 BTCµÄ¼Û¸ñ½øÐÐÅÄÂô¡£Rhysida¼Æ»®½«ÕâЩÊý¾ÝÂô¸øÎ¨Ò»µÄÂò¼Ò£¬²¢Áô³ö7ÌìµÄʱ¼ä¡£¹¥»÷·¢ÉúÓÚ10ÔÂ28ÈÕ£¬µ¼ÖÂITϵÍÂä¬ÐøµÄÖжÏ£¬Ó°ÏìÁË´óӢͼÊé¹ÝµÄÔÚÏßϵͳ¡¢·þÎñºÍWi-FiµÈ¡£´óӢͼÊé¹ÝÔÚ20ÈÕ·¢Ìû֤ʵÁËÆäÈËÁ¦×ÊÔ´Îļþ±»µÁµÄÏûÏ¢£¬²¢ÌáÐÑÓû§ÖØÖÃÃÜÂëÒÔ·ÀÍòÒ»¡£»¹ÌåÏÖÔ¤¼ÆÔÚδÀ´¼¸ÖÜÄÚ»Ö¸´Ðí¶à·þÎñ£¬µ«²¿ÃÅÖжϿÉÄÜ»áÁ¬ÐøºÜ³¤Ò»¶Îʱ¼ä¡£


https://securityaffairs.com/154473/data-breach/rhysida-ransomware-gang-british-library.html


4¡¢Æû³µÁã¼þ¹«Ë¾AutoZone֪ͨÊýÍò¿Í»§ÆäÊý¾ÝÒÑй¶


11ÔÂ21ÈÕ±¨µÀ³Æ£¬ÃÀ¹úÆû³µÁ㲿¼þÁãÊÛÉ̺ͷÖÏúÉÌAutoZoneй¶ÁËÁè¼Ý18ÍòÈ˵ÄÊý¾Ý¡£AutoZoneÄêÊÕÈë½ü175ÒÚÃÀÔª£¬Ã¿ÔÂÓÐ3500ÍòÓû§·ÃÎÊÆäÔÚÏßÉ̵ê¡£AutoZoneÔÚ21ÈÕ֪ͨÃÀ¹úÕþ¸®ËüÔÚ5ÔÂ28ÈÕ·¢ÉúÁËÊý¾Ýй¶£¬Ó°Ïì184995ÈË¡£8ÔÂ15ÈÕ×óÓÒ£¬AutoZoneÈ·¶¨£¬Î´¾­ÊÚȨµÄµÚÈý·½ÀûÓÃMOVEitÖеÄ©¶´ÇÔÈ¡ÁËAutoZoneϵͳÖеÄijЩÊý¾Ý¡£Ö®ºó£¬¸Ã¹«Ë¾ÓÖ»¨ÁË3¸öÔµÄʱ¼äÀ´È·¶¨ÄÄЩÊý¾Ý±»µÁ£¬ÒÔ¼°ÐèҪ֪ͨÄÄЩÈË¡£


https://www.bleepingcomputer.com/news/security/auto-parts-giant-autozone-warns-of-moveit-data-breach/


5¡¢Ñо¿ÈËÔ±ÑÝʾÈçºÎ´ÓSSH·þÎñÆ÷Ç©Ãû´íÎóÖÐÌáÈ¡RSAÃÜÔ¿


ýÌå11ÔÂ19ÈÕ±¨µÀ£¬Ñо¿ÈËÔ±·¢ÏÖ£¬ÔÚijЩÌõ¼þÏ£¬±»¶¯¹¥»÷ÕßÓпÉÄÜ´Óµ¼ÖÂSSHÁ¬½ÓʵÑéʧ°ÜµÄ´íÎóÖÐÌáÈ¡RSAÃÜÔ¿¡£Èç¹ûʹÓÃCRT-RSAµÄÇ©Ãû·¨Ê½ÔÚÇ©Ãû¼ÆËã¹ý³ÌÖзºÆð¹ÊÕÏ£¬ÊӲ쵽¸ÃÇ©ÃûµÄ¹¥»÷Õß¾ÍÓпÉÄܼÆËã³öÇ©ÃûÕßµÄ˽Կ¡£¾¡¹Ü´ËÀà´íÎóºÜÉÙ¼û£¬µ«ÓÉÓÚÓ²¼þȱÏÝ£¬ËüÃÇÊDz»ÐÐÖÆÖ¹µÄ¡£Ö»ÒªÓÐ×ã¹»´óµÄÊý¾Ý³Ø£¬¹¥»÷Õ߾ͿÉÒÔÕÒµ½²¢ÀûÓÃÐí¶à»ú»á¡£ÕâÖ»Ó°ÏìÁ˾ɰæTLS£¬TLS 1.3ͨ¹ý¼ÓÃܽ¨Á¢Á¬½ÓµÄÎÕÊÖ¹ý³Ì½â¾öÁËÕâÒ»ÎÊÌ⣬´Ó¶ø·ÀÖ¹ÇÔÌýÕß¶ÁȡǩÃû¡£


https://www.bleepingcomputer.com/news/security/researchers-extract-rsa-keys-from-ssh-server-signing-errors/


6¡¢Outpost24Ðû²¼¹ØÓÚÐÅÏ¢ÇÔÈ¡Èí¼þLummaµÄ·ÖÎö³ÂËß


11ÔÂ20ÈÕ£¬Outpost24Ðû²¼Á˹ØÓÚÐÅÏ¢ÇÔÈ¡Èí¼þLummaµÄ·ÖÎö³ÂËß¡£Lumma£¨ÓÖÃûLummaC2£©ÓÉCÓïÑÔ¿ª·¢£¬×Ô2022Äê12ÔÂÆðÔÚµØÏÂÂÛ̳ÉϳöÊÛ¡£¸Ã¶ñÒâÈí¼þÔÚÈÆ¹ý¼ì²âºÍ×èÖ¹×Ô¶¯·ÖÎö·½Ãæ½øÐÐÁËÖØ´ó¸üУ¬°üÂÞ¿ØÖÆÁ÷±âƽ»¯»ìÏý¡¢human-mouse»î¶¯¼ì²â¡¢XOR¼ÓÃÜ×Ö·û´®¡¢Ö§³Ö¶¯Ì¬ÅäÖÃÎļþÒÔ¼°ÔÚËùÓй¹½¨ÖÐÇ¿ÖÆÊ¹ÓüÓÃܼ¼Êõ¡£ÆäÖÐ×îÓÐȤµÄÊÇʹÓÃÈý½Ç·¨¼ì²âhuman-mouse»î¶¯£¬ÕâÏî¼¼Êõ¿¼ÂÇÁ˹â±êÔÚ¶Ìʱ¼äÄڵIJîÒìλÖã¬ÒÔ¼ì²âÈËÀà»î¶¯£¬´Ó¶øÓÐЧµØÈƹýÁË´ó¶àÊýÎÞ·¨ÕæÊµÄ£ÄâÊó±êÒÆ¶¯µÄ·ÖÎöϵͳµÄ¼ì²â¡£


https://outpost24.com/blog/lummac2-anti-sandbox-technique-trigonometry-human-detection/