S¨¹dwestfalen IT±»ºÚµ¼Öµ¹ú70¶à¸ö³ÇÊеÄϵͳ崻ú

°ä²¼¹¦·ò 2023-11-03

1¡¢S¨¹dwestfalen IT±»ºÚµ¼Öµ¹ú70¶à¸ö³ÇÊеÄϵͳ崻ú


¾ÝýÌå11ÔÂ1ÈÕ±¨Â· £¬·þÎñÌṩÉÌS¨¹dwestfalen ITÔâµ½ÀÕË÷¹¥»÷ £¬µ¼Öµ¹ú70¶à¸ö³ÇÊеÄÊÐÕþϵͳ崻ú ¡£±¾ÖÜÒ» £¬¸Ã·þÎñÌṩÉ̵Äϵͳ±»¼ÓÃÜ ¡£ÎªÁËÔ¤·À¶ñÒâÈí¼þ´«²¼ £¬¸Ã¹«Ë¾ÖжÏÁË70¶à¸ö³ÇÊÐ¶ÔÆä»ù´¡ÉèÊ©µÄ½Ó¼û £¬ÖØÒªÓ°ÏìÁ˵¹úÎ÷²¿µÄ±±À³Òð-ÍþË¹ÌØ·¨Â×ÖÝ ¡£¹¥»÷µ±Ìì £¬µÂ¹úÎý¸ùÊе±¾ÖÈ¡µÞÁ˹«ÃñµÄÔ¤Ô¼ £¬½ØÖÁ±¾Öܶþ £¬¸ÃÊе±¾ÖµÄ´ó²¿ÃÅÔÚÏß·þÎñÈÔÎÞ·¨Ê¹Óà ¡£Î¤Ã·¶û˹»ùÐ˺Ͳ¼¶ûɳÒÁµÂÊе±¾ÖµÄÍøÕ¾Ò²ÔÚÖÜÈý¹Ø¹Ø ¡£µÂ¹ú¾¯·½ºÍ°²È«»ú¹¹ÔÚµ÷²éÕâÆðÊÂÎñ £¬²¢ÖÂÁ¦¸´Ô­³ÇÊÐÖÎÀí²¿ÃŵķþÎñ ¡£


https://therecord.media/massive-cyberattack-hinders-services-in-germany


2¡¢Êý¾ÝÖÐÐÄÍ£µçµ¼ÖÂCloudflare¶à¸ö²úÆ·ÁÙʱÎÞ·¨Ê¹ÓÃ


¾Ý11ÔÂ2ÈÕ±¨Â· £¬CloudflareÖжϵ¼ÖÂÆäºÜ¶à²úÆ·ÎÞ·¨Ê¹Óà ¡£Cloudflare°µÊ¾ £¬Õâ¸öÎÊÌâÓ°ÏìÁËËùÓÐÒÀÀµÆäAPI»ù´¡ÉèÊ©µÄ·þÎñ £¬Ô̺¬½ÚÔìÃæ°å¡¢Cloudflare API¡¢LogpushºÍAlert Notification SystemµÈ ¡£¿Í»§ÔÚ³¢ÊԵǼÕÊ»§²¢½Ó¼ûCloudflare½ÚÔìÃæ°åʱ £¬»á¿´µ½¡°Code:10000¡±Éí·ÝÑéÖ¤ÃýÎóºÍÄÚ²¿·þÎñÆ÷ÃýÎó ¡£ÖжÏÁ½Ó×ʱºó £¬¸Ã¹«Ë¾Ð¹Â© £¬ÕâÊǶà¸öÊý¾ÝÖÐÐÄÍ£µçµ¼ÖµÄ ¡£µ××ÓÔ­ÒòÊÇ·¢µç»ú¹ÊÕϵ¼ÖµÄÇøÓòÐÔµçÁ¦ÎÊÌâ £¬Ôì³ÉÉ豸ÍÑ»ú ¡£Ä¿Ç° £¬´ó²¿ÃÅ·þÎñ¶¼ÒѸ´Ô­ ¡£


https://www.bleepingcomputer.com/news/security/cloudflare-dashboard-and-apis-down-after-data-center-power-outage/


3¡¢Advarra¹«Ë¾Ôâµ½AlphVÀÕË÷¹¥»÷³¬¹ý120 GBÊý¾Ýй¶


ýÌå11ÔÂ1ÈÕ³Æ £¬Ò½ÁÆ×ۺϽâ¾ö¹æ»®¹«Ë¾AdvarraÔâµ½ÁËÀÕË÷¹¥»÷ ¡£¾ÝϤ £¬¹¥»÷²úÉúÓÚ10ÔÂ25ÈÕ×óÓÒ £¬¹«Ë¾ÖÎÀíÈËÔ±°µÊ¾»Ø¾ø½»Êê½ð £¬Ò²²»Óë¹¥»÷Õß½»Éæ ¡£10ÔÂ31ÈÕ £¬¹¥»÷ÕßÔÚAlphVÍøÕ¾ÉÏÁгöÁ˸ù«Ë¾ £¬Ðû³ÆÒÑÇÔÈ¡Á˳¬¹ý120GBÊý¾Ý £¬Éæ¼°¿Í»§¡¢»¼ÕßÒÔ¼°Ô±¹¤ ¡£Advarra°µÊ¾ £¬¹¥»÷Ô´ÓÚÒ»ÃûÔ±¹¤µÄµç»°ºÅÂë±»µÁ £¬¹¥»÷Õß½è´Ë½Ó¼ûÁ˸ÃÔ±¹¤µÄһЩÕË»§ £¬Ô̺¬LinkedInºÍ¹¤×÷ÕË»§ ¡£


https://www.databreaches.net/exclusive-advarra-hacked-threat-actors-threatening-to-leak-data/


4¡¢VMware·¢ÏÖÊýÊ®¸öÄÚºËÇý¶¯·¨Ê½ÈÝÒ×Ôâµ½ÍøÂç¹¥»÷


VMware Carbon Black TAUÔÚ10ÔÂ31ÈÕ³ÆÆä·¢ÏÖÁË34¸öÒ×±»¹¥»÷µÄÄÚºËÇý¶¯·¨Ê½£¨30¸öWDMºÍ4¸öWDF£© ¡£ÆäÖÐ6¸öÄܹ»ÓÃÀ´½Ó¼ûÄÚºËÄÚ´æ £¬ËùÓÐÇý¶¯·¨Ê½¶¼¿É±»ÓµÓзÇϵͳȨÏ޵Ĺ¥»÷ÕßÓÃÓÚÆëÈ«½ÚÔìÉ豸 ¡£Í¨¹ýÀûÓÃÕâЩÇý¶¯·¨Ê½ £¬¹¥»÷ÕßÄܹ»²Á³ý»ò¸ü¸Ä¹Ì¼þ £¬ÒÔ¼°ÌáÉýȨÏÞ ¡£ÕâЩÇý¶¯µÄ¿ª·¢ÈËÔ±ÒÑÓÚ2023Äê´º¼¾ÊÕµ½Í¨Öª £¬µ«Ö»ÓÐÁ½¼Ò¹«Ë¾½¨¸´ÁË·ì϶ ¡£VMwareÕë¶Ô¶à¸öÇý¶¯·¨Ê½¿ª·¢ÁËPoC·ì϶ £¬ÒÔÑÝʾÈôºÎÀûÓÃËüÃÇÀ´²Á³ý¹Ì¼þ»òÌáÉýȨÏÞ ¡£


https://blogs.vmware.com/security/2023/10/hunting-vulnerable-kernel-drivers.html


5¡¢Unit 42°ä²¼¹ØÓÚTurlaµÄºóÃÅKazuarбäÌåµÄ»ã±¨


10ÔÂ31ÈÕ £¬Unit 42°ä²¼Á˹ØÓÚTurlaºóÃÅKazuarµÄбäÌåµÄ·ÖÎö»ã±¨ ¡£KazuarÊÇÒ»¸ö.NETºóÃÅ £¬×÷ΪTurlaµÄµÚ¶þ½×¶ÎpayloadÓëÆäËü³£Óù¤¾ßһ·ʹÓà ¡£ÔÚа汾ÖÐ £¬¹¥»÷ÕßʹÓÃÁ˸÷ÀิÔӵķ´·ÖÎö¼¼Êõ £¬²¢Í¨¹ýÓÐЧµÄ¼ÓÃܺͻìºÏÀ´±£»¤¶ñÒâÈí¼þ´úÂë ¡£KazuarµÄÐÂÖ°ÄÜÔ̺¬£º¸üÈ«ÃæµÄϵͳ·ÖÎö £¬ÇÔÈ¡ÔÆÀûÓ÷¨Ê½ºÍÐźÅÐÂÎÅÀûÓ÷¨Ê½ £¬Ö§³Ö45¸öºÅÁî £¬¹¥»÷Õ߿ɿªÆô/¹Ø¹ØÒ»ÏµÁÐ×Ô¶¯»¯¹¤×÷ £¬ÊµÏÖ·ÖÆçµÄ¼ÓÃÜËã·¨ºÍ¹æ»® £¬ÒÔ¼°ÓµÓжàÖÖ×¢Èëģʽ ¡£


https://unit42.paloaltonetworks.com/pensive-ursa-uses-upgraded-kazuar-backdoor/


6¡¢HP°ä²¼2023ÄêµÚÈý¼¾¶ÈÍøÂç°²È«Ì¬ÊÆµÄ·ÖÎö»ã±¨


10ÔÂ31ÈÕ £¬HP°ä²¼ÁË2023ÄêµÚÈý¼¾¶ÈÍøÂç°²È«Ì¬ÊÆµÄ·ÖÎö»ã±¨ ¡£¹¥»÷ÕßÔÚQ3³ÖÐøÀûÓÃliving-off-the-land¹¥»÷Õ½Êõ £¬Í¨¹ýWindowsÄÚÖõŤ¾ßÖ´Ðй¥»÷ ¡£ÀûÓÃExcel²å¼þ(XLL)ÎļþµÄ»î¶¯¼¤Ôö £¬ÔÚ¹¥»÷Õß×î³£ÓõÄÎļþÀ©´óÃûÖÐ £¬ÆôÓúêµÄExcel²å¼þ¶ñÒâÈí¼þ´ÓQ2µÄµÚ46λÉÏÉýµ½µÚ7λ ¡£HP»¹·¢ÏÖÁËÒ»¸öÕë¶ÔÀ­¶¡ÃÀÖ޾ƵêµÄ¹¥»÷»î¶¯ £¬Ê¹ÓÃÁËÆôÓúêµÄPowerPoint²å¼þ ¡£¹¥»÷Õß»¹ÔÚGitHubÉÏÍйÜαÔìµÄRAT £¬ÊÔͼÓÕÆ­²»×ã¾­ÑéµÄºÚ¿ÍϰȾËûÃÇ×Ô¼ºµÄPC ¡£


https://threatresearch.ext.hp.com/hp-wolf-security-threat-insights-report-q3-2023/