¶íÀÕ¸ÔÖݶ¯ÎïÔ°ÊÛÆ±Ð§ÀÍÔâºÚ¿Í¹¥»÷£¬£¬ £¬ £¬£¬£¬11.8ÍòÓû§ÐÅÏ¢±»µÁ

Ðû²¼Ê±¼ä 2024-08-21
1. ¶íÀÕ¸ÔÖݶ¯ÎïÔ°ÊÛÆ±Ð§ÀÍÔâºÚ¿Í¹¥»÷£¬£¬ £¬ £¬£¬£¬11.8ÍòÓû§ÐÅÏ¢±»µÁ


8ÔÂ19ÈÕ£¬£¬ £¬ £¬£¬£¬¶íÀÕ¸ÔÖݶ¯ÎïÔ°½üÆÚ±¬·¢ÁËÒ»ÆðÑÏÖØµÄÊý¾Ýй¶ÊÂÎñ£¬£¬ £¬ £¬£¬£¬Ô¼118,000ÃûÓû§µÄСÎÒ˽¼ÒÐÅÏ¢ºÍÖ§¸¶¿¨Êý¾ÝÔÚ2023Äê12ÔÂ20ÈÕÖÁ2024Äê6ÔÂ26ÈÕʱ´úµÄÔÚÏßÊÛÆ±Ð§ÀÍÖб»µÁ¡£¡£¡£¡£ÕâЩÐÅÏ¢°üÀ¨ÐÕÃû¡¢Ö§¸¶¿¨ºÅ¡¢CVVÇå¾²Âë¼°µ½ÆÚÈÕÆÚ£¬£¬ £¬ £¬£¬£¬¶ÔÊܺ¦Õß×é³ÉDZÔÚΣº¦¡£¡£¡£¡£ÊÂÎñÓÚ6ÔÂ26ÈÕ±»·¢Ã÷ºó£¬£¬ £¬ £¬£¬£¬¶¯ÎïÔ°Á¬Ã¦Í£ÓÃÁËÊÜÓ°ÏìµÄÍøÕ¾£¬£¬ £¬ £¬£¬£¬²¢½¨ÉèÁËеÄÇå¾²¹ºÆ±Æ½Ì¨¡£¡£¡£¡£¶¯ÎïÔ°ÒÑÏòÃåÒòÖÝ×ÜÉó²é³¤°ì¹«ÊÒ±¨¸æ£¬£¬ £¬ £¬£¬£¬²¢Ïò¿ÉÄÜÊÜÓ°ÏìµÄ117,815ÃûÓû§·¢ËÍÁË֪ͨÐÅ£¬£¬ £¬ £¬£¬£¬Í¬Ê±ÎªËûÃÇÌṩÁËÒ»ÄêµÄÃâ·ÑÐÅÓÃ¼à¿ØºÍÉí·Ý± £»£»£»£» £» £»¤Ð§ÀÍ¡£¡£¡£¡£¶¯ÎïÔ°ÌåÏÖ£¬£¬ £¬ £¬£¬£¬´Ë´Îй¶ÊÇÓÉÓÚµÚÈý·½¹©Ó¦ÉÌÉúÒâ±»ÍþвÕßÖØ¶¨ÏòËùÖ£¬£¬ £¬ £¬£¬£¬²¢ÒÑÏòÁª°îÖ´·¨²¿·Öת´ï¡£¡£¡£¡£ÎªÔ¤·ÀδÀ´ÀàËÆÊÂÎñ£¬£¬ £¬ £¬£¬£¬¶¯ÎïÔ°ÕýÆð¾¢Éó²éÆäÇå¾²Õþ²ßºÍ³ÌÐò¡£¡£¡£¡£Ö»¹Üδ¹ûÕæÏêϸ¹¥»÷ÀàÐÍ£¬£¬ £¬ £¬£¬£¬µ«ÆÊÎöÒÔΪ¿ÉÄÜÊÇÍøÂçä¯ÀÀÆ÷ѬȾÁËÊý×ÖÇÔÈ¡Æ÷£¬£¬ £¬ £¬£¬£¬ÕâÀà¶ñÒâÈí¼þ³£±»ÓÃÓÚÔÚ½áÕËÒ³ÃæµÈÒªº¦Î»ÖÃÇÔÈ¡Óû§Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£


https://www.securityweek.com/oregon-zoo-ticketing-service-hack-impacts-118000/


2. Jewish Home LifecareÔâBlackCatÀÕË÷Èí¼þ¹¥»÷£¬£¬ £¬ £¬£¬£¬10ÍòÈËÊý¾Ýй¶


8ÔÂ19ÈÕ£¬£¬ £¬ £¬£¬£¬Å¦Ô¼ÊеķÇÓªÀûÐÔÒ½ÁƱ£½¡×éÖ¯Jewish Home Lifecare£¨ÏÖ³ÆÐÂÓÌÌ«¼ÒÍ¥ÖÐÐÄ£©Åû¶Á˽üÆÚ±¬·¢µÄÒ»ÆðÖØ´óÊý¾Ýй¶ÊÂÎñ£¬£¬ £¬ £¬£¬£¬¸ÃÊÂÎñ²¨¼°Áè¼Ý104,000Ãû»¼Õß¼°ÉçÇø³ÉÔ±¡£¡£¡£¡£½ñÄê2Ô£¬£¬ £¬ £¬£¬£¬¸ÃÖÐÐÄÏòÊÜÓ°Ïì¿Í»§×ª´ï³Æ£¬£¬ £¬ £¬£¬£¬ÆäÍøÂçÔÚ1ÔÂ7ÈÕÔâÓöÒì³ £»£»£»£» £» £»î¶¯£¬£¬ £¬ £¬£¬£¬ºÚ¿Í¿ÉÄÜÒÑ»ñÈ¡°üÀ¨Ð¡ÎÒ˽¼ÒÉí·ÝÐÅÏ¢¡¢½ðÈÚÕË»§ÏêÇé¡¢Ò½ÁƼͼÔÚÄÚµÄÃô¸ÐÐÅÏ¢¡£¡£¡£¡£ÎªÈ·±£Êܺ¦ÕßÇå¾²£¬£¬ £¬ £¬£¬£¬ÖÐÐÄÌṩÁËÃâ·ÑµÄÐÅÓÃ¼à¿ØÐ§ÀÍ£¬£¬ £¬ £¬£¬£¬²¢Ç¿µ÷ËäÎÞÖ±½ÓÖ¤¾ÝÅú×¢ÐÅÏ¢Òѱ»ÀÄÓ㬣¬ £¬ £¬£¬£¬µ«ÈÔÉóÉ÷Ðû²¼Í¨Öª¡£¡£¡£¡£´Ë´Îй¶ÓëÀÕË÷Èí¼þ×éÖ¯BlackCat(Alphv)Óйأ¬£¬ £¬ £¬£¬£¬ËüÃÇÉù³Æ¹¥»÷ÁËJewish Home Lifecare²¢»ñÈ¡ÁËÁÙ´²Ñо¿¡¢²ÆÎñ¼°Ô±¹¤¿Í»§Êý¾Ý£¬£¬ £¬ £¬£¬£¬ÉõÖÁÉæ¼°¾èÔù×ʽðÀÄÓõÄÖ¤¾Ý¡£¡£¡£¡£È»¶ø£¬£¬ £¬ £¬£¬£¬±»µÁÎļþÊÇ·ñ¹ûÕæÉдýÈ·ÈÏ£¬£¬ £¬ £¬£¬£¬ÇÒBlackCat×éÖ¯ÔÚ3Ô³õͻȻÏûÊÅ£¬£¬ £¬ £¬£¬£¬ÆäÍøÕ¾ÒÑÎÞ·¨»á¼û¡£¡£¡£¡£


https://www.securityweek.com/100000-impacted-by-jewish-home-lifecare-data-breach/


3. BlindEagle£¨APT-C-36£©£ºÀ­¶¡ÃÀÖÞµÄÒ»Á¬Íþв


8ÔÂ20ÈÕ£¬£¬ £¬ £¬£¬£¬¿¨°Í˹»ùʵÑéÊÒ¶ÔÃûΪBlindEagle£¨ÓÖ½ÐAPT-C-36£©µÄÒ»Á¬ÐÔÍþв×éÖ¯·¢³öÖÒÑÔ£¬£¬ £¬ £¬£¬£¬¸Ã×é֯ר³¤ÓÚÕë¶ÔÀ­¶¡ÃÀÖÞµÄÍøÂç¹¥»÷£¬£¬ £¬ £¬£¬£¬BlindEagleÖ÷Ҫͨ¹ýÈ«ÐÄÉè¼ÆµÄÍøÂç´¹ÂÚ»îÐж¯°¸£¬£¬ £¬ £¬£¬£¬Ã°³ä¹Ù·½»ú¹¹Èç˰Îñ²¿·Ö»òÍâ½»²¿£¬£¬ £¬ £¬£¬£¬ÓÕÆ­Óû§µã»÷¶ñÒâÁ´½Ó£¬£¬ £¬ £¬£¬£¬ÏÂÔØÎ±×°³É¹Ù·½ÎļþµÄѹËõ°ü£¬£¬ £¬ £¬£¬£¬ÄÚº¬Ö¸ÏòÊܿضñÒâÈí¼þÕ¾µãµÄÁ´½Ó¡£¡£¡£¡£ÕâЩÓʼþ±ÆÕæÄ£Äâ¹Ù·½Í¨Ñ¶£¬£¬ £¬ £¬£¬£¬Ê¹ÓÃURLËõ¶ÌÆ÷ºÍ¶¯Ì¬DNSЧÀÍÔöÌíÒþ²ØÐÔ£¬£¬ £¬ £¬£¬£¬Æ¾Ö¤Óû§Î»ÖÃÖØ¶¨Ïò£¬£¬ £¬ £¬£¬£¬ÒÔÌӱܼì²â¡£¡£¡£¡£Ò»µ©Óû§ÖÐÕУ¬£¬ £¬ £¬£¬£¬BlindEagle±ãÆô¶¯¶à½×¶ÎѬȾ£¬£¬ £¬ £¬£¬£¬°²ÅŰüÀ¨njRAT¡¢LimeRATµÈ¹ûÕæÔ¶³Ì»á¼ûľÂí£¨RAT£©£¬£¬ £¬ £¬£¬£¬ÕâЩ¹¤¾ß±»¶¨ÖÆÒÔÖª×ã²î±ð¹¥»÷ÐèÇ󣬣¬ £¬ £¬£¬£¬ÔÊÐí¸Ã×éÖ¯¼à¿ØÊܺ¦Õß¡¢ÇÔÈ¡Ãô¸ÐÐÅÏ¢¼°²ÆÎñƾ֤¡£¡£¡£¡£BlindEagle»¹Ê¹ÓÃÀú³Ì×¢ÈëÊÖÒÕ£¬£¬ £¬ £¬£¬£¬ÈçÀú³ÌÍÚ¿Õ£¬£¬ £¬ £¬£¬£¬½«¶ñÒâ´úÂëÒþ²ØÓÚÕýµ±Àú³ÌÖУ¬£¬ £¬ £¬£¬£¬ÒԴ˹æ±ÜÇå¾²¼ì²â£¬£¬ £¬ £¬£¬£¬ÊµÏÖºã¾ÃDZÔÚÓëÊý¾ÝÇÔÈ¡¡£¡£¡£¡£BlindEagleµÄ¹¥»÷Ä¿µÄ°üÀ¨¸çÂ×±ÈÑÇ¡¢¶ò¹Ï¶à¶û¡¢ÖÇÀûºÍ°ÍÄÃÂíµÄСÎÒ˽¼ÒºÍ×éÖ¯£¬£¬ £¬ £¬£¬£¬Éæ¼°Õþ¸®¡¢½ÌÓý¡¢ÎÀÉúºÍ½»Í¨µÈ¸÷¸öÁìÓò¡£¡£¡£¡£


https://securityonline.info/blindeagle-apt-group-a-persistent-threat-in-latin-america/


4. ΢о¿Æ¼¼ÔâÓöÍøÂç¹¥»÷£¬£¬ £¬ £¬£¬£¬²¿·ÖÓªÒµÊÜÓ°Ïì


8ÔÂ21ÈÕ£¬£¬ £¬ £¬£¬£¬ÃÀ¹ú°ëµ¼ÌåÖÆÔìÉÌ΢о¿Æ¼¼Microchip½üÆÚÔâÓöÁËÒ»ÆðÍøÂçÇå¾²ÊÂÎñ£¬£¬ £¬ £¬£¬£¬¶Ô¹«Ë¾ÔËÓªÔì³ÉÁËÏÔÖøÓ°Ïì¡£¡£¡£¡£¾Ý¸Ã¹«Ë¾Í¸Â¶£¬£¬ £¬ £¬£¬£¬8ÔÂ17ÈÕ£¬£¬ £¬ £¬£¬£¬Î¢Ð¾¿Æ¼¼µÄÐÅÏ¢ÊÖÒÕϵͳ±»¼ì²âµ½±£´æÇ±ÔڵĿÉÒɻ£¬£¬ £¬ £¬£¬£¬ËæºóÓÚ8ÔÂ19ÈÕÈ·ÈÏϵͳÒÑÔ⵽δ¾­ÊÚȨµÄ»á¼û¡£¡£¡£¡£ÃæÁÙÕâÒ»½ôÆÈÇéÐΣ¬£¬ £¬ £¬£¬£¬¹«Ë¾Ñ¸ËÙ½ÓÄÉÐж¯£¬£¬ £¬ £¬£¬£¬¸ôÀëÁËÊÜÓ°ÏìµÄЧÀÍÆ÷ϵͳ£¬£¬ £¬ £¬£¬£¬²¢¹Ø±ÕÁË¿ÉÄÜÊܲ¨¼°µÄÆäËûϵͳ£¬£¬ £¬ £¬£¬£¬Í¬Ê±Ô¼ÇëÁËרҵµÄÍâ²¿ÍøÂçÇå¾²ÕÕÁÏÍŶÓÀ´ÖÜÈ«ÆÀ¹ÀÊÂÎñµÄÑÏÖØË®Æ½¼°Ó°Ïì¹æÄ£¡£¡£¡£¡£´Ë´ÎÇå¾²ÊÂÎñµ¼ÖÂ΢о¿Æ¼¼²¿·ÖÖÆÔìÉèÊ©µÄÔËӪЧÂʽµÖÁÕý³£Ë®Æ½ÒÔÏ£¬£¬ £¬ £¬£¬£¬Ö±½ÓÓ°ÏìÁ˹«Ë¾×¼Ê±ÍÆÐпͻ§¶©µ¥µÄÄÜÁ¦¡£¡£¡£¡£Ö»¹Ü¹«Ë¾ÕýÈ«Á¦ÒÔ¸°½â¾öÕâÒ»ÎÊÌ⣬£¬ £¬ £¬£¬£¬²¢ÔÊÐí½«¾¡¿ì»Ö¸´Õý³£ÔËÓª£¬£¬ £¬ £¬£¬£¬µ«ÏÖÔÚ¹ØÓÚÊÂÎñµÄÏêϸԵ¹ÊÔ­ÓÉ¡¢Ð¾Æ¬ÖÆÔìÓªÒµÊÜ×ÌÈŵÄÏêϸˮƽ£¬£¬ £¬ £¬£¬£¬ÒÔ¼°ÊÇ·ñÉæ¼°ÀÕË÷Èí¼þµÈÃô¸ÐÐÅÏ¢£¬£¬ £¬ £¬£¬£¬ÈÔ´ý½øÒ»³ÌÐò²éÈ·ÈÏ¡£¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬£¬ £¬ £¬£¬£¬Î¢Ð¾¿Æ¼¼½ÓÄɸôÀë²½·¥µÄ×ö·¨Åú×¢£¬£¬ £¬ £¬£¬£¬Î´¾­ÊÚȨ·½µÄ»î¶¯¿ÉÄÜÒÑÆðÔ´ÏÔʾ³öÏò¹«Ë¾¸üÆÕ±éIT×ʲúÀ©É¢µÄ¼£Ï󡣡£¡£¡£


https://www.theregister.com/2024/08/21/microchip_technology_security_incident/


5. ½Ý¿ËÒÆ¶¯Óû§ÔâPWAÍøÂç´¹ÂÚ¹¥»÷


8ÔÂ20ÈÕ£¬£¬ £¬ £¬£¬£¬½Ý¿Ë¹²ºÍ¹úµÄÒÆ¶¯Óû§ÕýÃæÁÙÒ»ÖÖÐÂÐÍÇÒÖØ´óµÄÍøÂç´¹ÂÚÍþв£¬£¬ £¬ £¬£¬£¬¸ÃÍþвʹÓý¥½øÊ½WebÓ¦ÓóÌÐò£¨PWA£©ÊÖÒÕ£¬£¬ £¬ £¬£¬£¬Õë¶Ô¶à¼ÒÒøÐÐÓû§ÇÔÈ¡ÒøÐÐÕË»§Æ¾Ö¤¡£¡£¡£¡£¾Ý˹Âå·¥¿ËÍøÂçÇå¾²¹«Ë¾ESET±¨¸æ£¬£¬ £¬ £¬£¬£¬¹¥»÷Ä¿µÄ°üÀ¨½Ý¿ËµÄCSOBÒøÐС¢ÐÙÑÀÀûµÄOTPÒøÐм°¸ñ³¼ªÑǵÄTBCÒøÐС£¡£¡£¡£¹¥»÷Õßͨ¹ý×Ô¶¯ÓïÒôµç»°¡¢¶ÌÐż°É罻ýÌå¶ñÒâ¹ã¸æÉ¢²¼´¹ÂÚÁ´½Ó£¬£¬ £¬ £¬£¬£¬ÓÕµ¼Óû§µã»÷²¢×°Öÿ´ËÆÕýµ±µÄÒøÐÐÓ¦ÓóÌÐòPWA»òAndroidÉϵÄWebAPK£¬£¬ £¬ £¬£¬£¬ÕâЩӦÓÃÏÕЩÍêÉÆ¸´ÖÆÁËÕæÊµÒøÐÐÓ¦ÓõĽçÃæ£¬£¬ £¬ £¬£¬£¬´Ó¶øÈƹýÁ˹Űåä¯ÀÀÆ÷µÄÇå¾²ÖÒÑÔ¡£¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬£¬ £¬ £¬£¬£¬¹¥»÷±³ºóÉæ¼°Á½¸ö²î±ðµÄÍþвÐÐΪÕߣ¬£¬ £¬ £¬£¬£¬ËûÃÇʹÓÃChrome WebAPKÊÖÒÕµÄĬÈÏÐÐΪ£¬£¬ £¬ £¬£¬£¬ÀÄÓøù¦Ð§ÒÔÒþ²Ø¡°À´×Ô²»ÊÜÐÅÈÎȪԴµÄ×°Öá±ÖÒÑÔ£¬£¬ £¬ £¬£¬£¬Ê¹µÃÓû§ÄÑÒÔ²ì¾õΣº¦¡£¡£¡£¡£¹ØÓÚiOSÓû§£¬£¬ £¬ £¬£¬£¬Ôòͨ¹ýÖ¸µ¼½«Î±ÔìµÄPWAÌí¼Óµ½Ö÷ÆÁÄ»À´ÊµÑé¹¥»÷¡£¡£¡£¡£Ò»µ©Óû§ÔÚÕâЩӦÓÃÖÐÊäÈëÒøÐÐÆ¾Ö¤£¬£¬ £¬ £¬£¬£¬ÐÅÏ¢±ã»á±»Ð¹Â¶ÖÁ¹¥»÷Õß¿ØÖƵÄÏÂÁîÓë¿ØÖÆ£¨C2£©Ð§ÀÍÆ÷»òTelegramȺÁÄÖС£¡£¡£¡£ESETÒѼà²âµ½¶à²¨ÀàËÆ»î¶¯¡£¡£¡£¡£


https://thehackernews.com/2024/08/czech-mobile-users-targeted-in-new.html


6. ÐÂÐÍDNSºóÃÅBackdoor.MsupedgeÕë¶Ǫ̂Íå´óѧ


8ÔÂ20ÈÕ£¬£¬ £¬ £¬£¬£¬ÍþвÆÊÎöÖ°Ô±½üÆÚÔŲ́Íå´óѧÔâÊܵĹ¥»÷ÖÐ½ÒÆÆÁËÒ»ÖÖÐÂÐÍÇå¾²ÍþвBackdoor.Msupedge£¬£¬ £¬ £¬£¬£¬ÓÉÈüÃÅÌú¿Ë¹«Ë¾·¢Ã÷²¢ÃüÃû¡£¡£¡£¡£ÒÔºóÃŽÓÄÉÁËÒ»ÖÖÓÐÊýµÄDNSͨѶ»úÖÆ£¬£¬ £¬ £¬£¬£¬ËäΪÒÑÖªÊÖÒÕµ«ÏʼûÓÚÍøÂç·¸·¨»î¶¯ÖС£¡£¡£¡£MsupedgeÒÔDLLÐÎʽDZ²ØÓÚÊÜѬȾϵͳµÄÌØ¶¨Â·¾¶£¬£¬ £¬ £¬£¬£¬Í¨¹ýDNSÅÌÎÊÎüÊÕ²¢Ö´ÐÐÖ¸Á£¬ £¬ £¬£¬£¬ÕâÒ»Õ½ÂÔ²»µ«¹æ±ÜÁËͨÀý¼ì²â£¬£¬ £¬ £¬£¬£¬»¹ÊµÏÖÁ˶ÔÄ¿µÄ»úеµÄÒþÃØ²Ù¿Ø¡£¡£¡£¡£ÓÈΪֵµÃ×¢ÖØµÄÊÇ£¬£¬ £¬ £¬£¬£¬MsupedgeÄÜÒÀ¾ÝDNSÅÌÎÊÆÊÎö³öµÄIPµØµãÖеÄÌØ¶¨×Ö½ÚÀ´ÎÞаµ÷½âÆäÐÐΪ£¬£¬ £¬ £¬£¬£¬ÈçÆô¶¯Àú³Ì¡¢ÏÂÔØ¶ñÒâÎļþ¡¢É趨ϵͳÐÝÃßʱ³¤µÈ£¬£¬ £¬ £¬£¬£¬¼«´óÔöÇ¿ÁËÆäÎÞаÐÔºÍÒþ²ØÐÔ¡£¡£¡£¡£±ðµÄ£¬£¬ £¬ £¬£¬£¬¸ÃºóÃÅÖ§³Ö¶àÖÖ²Ù×÷Ö¸Á£¬ £¬ £¬£¬£¬°üÀ¨»ùÓÚDNS TXT¼Í¼½¨ÉèÀú³Ì¡¢´ÓÖ¸¶¨URLÏÂÔØÎļþ¡¢Ê¹ÏµÍ³ÐÝÃß³¤´ï24Сʱ¼°ÕûÀíºÛ¼£µÈ¡£¡£¡£¡£¾ÝÈüÃÅÌú¿ËÆÊÎö£¬£¬ £¬ £¬£¬£¬´Ë´ÎÈëÇֵijõʼÈë¿Úµã¼«ÓпÉÄÜÊǽüÆÚÆØ¹âµÄPHPÎó²î£¨CVE-2024-4577£©£¬£¬ £¬ £¬£¬£¬¸ÃÎó²îÄܵ¼ÖÂWindowsƽ̨ÉϵÄPHP°æ±¾Ô¶³Ì´úÂëÖ´ÐС£¡£¡£¡£ÈüÃÅÌú¿ËÐû²¼ÁËÏ꾡µÄÈëÇÖÖ¸±ê£¨IOC£©£¬£¬ £¬ £¬£¬£¬ÒÔЭÖúÓû§Ê¶±ðºÍ·ÀÓùBackdoor.MsupedgeµÄ¹¥»÷¡£¡£¡£¡£


https://www.infosecurity-magazine.com/news/dns-based-backdoor-taiwanese/