BuyGoodsÅäÖÃÃýÎóй¶198GBÄÚ²¿Êý¾ÝºÍÓû§ÐÅÏ¢

°ä²¼¹¦·ò 2024-01-26
1. BuyGoodsÅäÖÃÃýÎóй¶198GBÄÚ²¿Êý¾ÝºÍÓû§ÐÅÏ¢


1ÔÂ24ÈÕ £¬ÍøÂ簲ȫ×êÑÐÔ± Jeremiah Fowler ×î½ü·¢ÏÖÁËÒ»¸öÅäÖÃÃýÎóµÄÔÆÊý¾Ý¿â £¬µ¼Ö´óÁ¿Ãô¸ÐÊý¾Ý¶³ö¡£ÊÜÓ°ÏìµÄÊý¾Ý¿âÔ̺¬¹éÊôÓÚBuyGoods.com¡£Â¶³öµÄÊý¾Ý¿â´óÓ××Ü¼Æ 198.3 GB £¬²»×ãÈκδó¾ÖµÄ°²È«ÈÏÖ¤ £¬¿É¹©¹«¼Ò¹«¿ª½Ó¼û¡£Õâ¸öδÊܱ£»¤µÄÊý¾Ý¿âÖÐÓг¬¹ý 260,000 ±Ê¼Í¼ £¬Ô̺¬È«ÃæµÄÐÅÏ¢¡£ÕâÔ̺¬ÓйØÁªÓª¹«Ë¾¸¶¿î¡¢ÍË¿îÂòÂô¡¢·¢Æ±¡¢¹ÜÕʼͼºÍ¸÷ÀàÆäËû´ó¾ÖµÄÊý¾ÝµÄ¾ßÌåÐÅÏ¢¡£¸üÔã¸âµÄÊÇ £¬Â¶³öµÄ·þÎñÆ÷»¹Â¶³öÁ˿ͻ§ºÍ´ÓÊô¹«Ë¾µÄÓ×ÎҼͼ £¬ÆäÖÐÔ̺¬¸ß¶ÈÃô¸ÐµÄÓ×ÎÒÉí·ÝÐÅÏ¢£¨PII£©ºÍÏàʶÄãµÄ¿Í»§£¨KYC£©Êý¾Ý¡£ÕâЩ¶³öµÄÐÅÏ¢Ô̺¬¿Í»§µÄ×ÔÅÄÕÕÒÔ¼°ËûÃǵÄÓ×ÎÒÉí·ÝÖ¤¡¢ÅÆÕÕ¡¢»¤ÕÕ £¬ÉõÖÁδ¾­±à×ëµÄÐÅÓþ¿¨¾ßÌåÐÅÏ¢¡£Õâ´ÎÒþÖÔй¶ÊÂÎñµÄÈ«ÇòÓ°Ïì¿ÉÄÜÊǾ޴óµÄ £¬ÓÉÓÚÕâЩ¼ÍÂ¼Éæ¼°À´×ÔÊÀ½ç¸÷µØµÄÓ×ÎÒ¡£


2. »ÝÆÕÏòÃÀ¹ú¼à¹Ü»ú¹¹Åû¶ÆäÔâµ½Cozy BearµÄÈëÇÖ


1ÔÂ25ÈÕ £¬¼¼ÊõÔì×÷ÉÌ»ÝÆÕÆóÒµ¹«Ë¾ (HPE) ÖÜÈý°µÊ¾ £¬ÒÉËÆÓë¶íÂÞ˹µ±¾ÖÓÐÁªÏµµÄºÚ¿Í½øÈëÁ˸ù«Ë¾»ùÓÚÔÆµÄµç×ÓÓʼþ»·¾³¡£ÓëCozy Bear£¨Ò²³ÆÎª Midnight Blizzard£©ÓйصĺڿÍÒѾ­ÇÖÈëÆäÍøÂç £¬²¢ÆÆ·ÑÊýÔ¹¦·òÇÔÈ¡Êý¾Ý¡£¸Ã¹«Ë¾Ã»ÓлØÓ¦ÓйØË­Í¨ÖªËûÃÇÕâÒ»ÊÂÎñµÄÖÃÆÀÒªÇó¡£¹¥»÷»î¶¯´Ó 2023 Äê 5 ÔÂÆðÍ· £¬¸Ã×éÖ¯ÖØÒª±»³ÆÎª APT29 £¬¾ÝÐÅÊǶíÂÞ˹¶Ô±íµý±¨¾Ö (SVR) µÄÒ»²¿ÃÅ £¬Õƹܱí¹ú¼äµý»î¶¯ºÍµç×Ӽල¡£ÕâЩºÚ¿ÍÊǶíÂÞ˹¶ÔÃÀ¹úһЩ×î¾ß·ÛËéÐԵĹ¥»÷µÄÄ»ºóºÚÊÖ £¬Ô̺¬ 2020 Äê SolarWinds ºÚ¿Í¹¥»÷ºÍ 2016 Äê¶ÔÃñÖ÷µ³È«¹úίԱ»áµÄ¹¥»÷¡£


3. Arctic Wolf LabsÆØ¹âÓÃGo¿ª·¢µÄCherryLoader


1ÔÂ24ÈÕ £¬CherryLoader Åû×ÅÎÞ¹¼µÄ±íÒ½øÐкýŪ £¬¼Ù×°³ÉºÏ·¨µÄ CherryTree ±Ê¼ÇÀûÓ÷¨Ê½¡£È»¶ø £¬ÔÚÕâ¸ö±í±í֮ϰµ²Ø×ÅÒ»¸öµó»¬¶øÎ£ÏյŤ¾ß £¬Ö¼ÔÚÒÔ¾ªÈ˵ÄЧÄÜÉøÈëϵͳ¡£Í¨¹ýÀûÓà Go µÄ׳´óÖ°ÄÜ £¬CherryLoader ÒýÈëÁ˶ñÒâÈí¼þÏÂÔØÆ÷ÖÐÒÔÇ°Î´Ôø¼û¹ýµÄÄ£¿é»¯Ë®Æ½ºÍ½Ã½ÝÐÔ £¬Ê¹¹¥»÷Õß¿ÉÄÜ»¥»»·ì϶¶øÎÞÐè³ÁбàÒë¡£CherryLoader µÄ¹¥»÷Á´¼È¸´ÔÓÓÖÓÐЧ¡£×î³õ £¬Êܺ¦Õß´ÓÌØ¶¨µÄ IP µØÖ·½Ó¹Ü¶ñÒâÈí¼þ £¬µ¼ÖÂÏÂÔØÁ½¸öÎļþ£ºÒ»¸öÊÜÃÜÂë±£»¤µÄ RAR ÎļþºÍÒ»¸öÕÆ¹Ü½âѹ RAR ÄÚÈݵĿÉÖ´ÐÐÎļþ¡£½âѹºóµÄÄÚÈÝÏÔʾÁËÒ»¸ö Golang ¶þ½øÔìÎļþÒÔ¼°ÆäËûÎļþ £¬ÕâЩ¶¼ÊǼÓÔØ·¨Ê½¹¤¾ß°üµÄÒ»²¿ÃÅ £¬Ö¼ÔÚͨ¹ý°þÀë¶þ½øÔìÎļþºÍ·ÛËéµ¼ÈëµØÖ·±íµÈ¼¼ÊõÀ´¹ÊÕÏ·ÖÎö¹¤×÷¡£CherryLoader µÄÖ´ÐÐÉæ¼°Ò»¸ö¶à²½Öè¹ý³Ì £¬´ÓÃÜÂë²é³­ÆðÍ· £¬¶øºóʹÓõ¥Ò»µÄ XOR Ëã·¨½âÃÜǶÈëÎļþ¡£ÖµÍ×ÌùÐĵÄÊÇ £¬¸Ã½âÃܹý³Ì²»ÒÀÀµÓÚÊäÈëµÄÃÜÂë £¬ÕⰵʾÆäÖØÒª×÷ÓÃÊÇ×èÖ¹·ÖÎö¶ø²»Êǰ²È«¡£


4. GKE¼¯ÈºÑϳÁ·ì϶Sys:All¿Éµ¼ÖÂ25Íò¸ö¼¯Èº±»½ÚÔì


1ÔÂ24ÈÕ £¬ÍøÂ簲ȫ×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸öÓ°Ïì Google Kubernetes Engine (GKE) µÄ·ì϶ £¬Õ¼ÓÐ Google ÕÊ»§µÄÍþв²Î¼ÓÕß¿ÉÄÜ»áÀûÓø÷ì϶À´½ÚÔì Kubernetes ¼¯Èº¡£Ôư²È«¹«Ë¾ Orca½«ÕâÒ»ÑϳÁȱµã´úºÅΪSys:All ¡£¾Ý¹À¼Æ £¬¶à´ï 250,000 ¸ö»îÔ¾µÄ GKE ¼¯ÈºÈÝÒ×Êܵ½¹¥»÷¡£system:authentiated group ÊÇÒ»¸öÌØÊâµÄ×é £¬Ô̺¬ËùÓо­¹ýÉí·ÝÑéÖ¤µÄʵÌå £¬Ô̺¬ÈËÀàÓû§ºÍ·þÎñÕÊ»§¡£Òò¶ø £¬µ±ÖÎÀíÔ±ÎÞÒâÖÐÊÚÓèËü¹ýÓÚ¿íËɵĽÇɫʱ £¬¿ÉÄÜ»á²úÉúÑϳÁºó¹û¡£Sys:All Òѱ»·¢ÏÖÓ°Ïì¶à¶à×éÖ¯ £¬µ¼Ö¸÷ÀàÃô¸ÐÊý¾Ý¶³ö £¬ÀýÈç JWT ÁîÅÆ¡¢GCP API ÃÜÔ¿¡¢AWS ÃÜÔ¿¡¢Google OAuth ƾ֤¡¢Ë½Ô¿ºÍÈÝÆ÷×¢²á±íƾ֤ £¬ÆäÖÐ×îºóÒ»¸ö¿ÉÄܶøºóÓÃÓÚ¶ÔÈÝÆ÷¾µÏñ½øÐÐľÂí»¯¡£ÔÚÏò Google ÕÆ¹ÜÈεØÅû¶ºó £¬¸Ã¹«Ë¾ÒѲÉÈ¡´ëÊ©×èÖ¹½« system:authentiated ×é°ó¶¨µ½ GKE 1.28 ¼°¸ü¸ß°æ±¾ÖÐµÄ cluster-admin ½ÇÉ«¡£


5. ˼¿Æ½¨¸´Éæ¼°¶à¸ö²úÆ·µÄRCE·ì϶CVE-2024-20253


1ÔÂ24ÈÕ £¬Ë¼¿ÆÒѾ­½¨¸´ÁËͳһͨѶºÍÁªÏµÖÐÐĽâ¾ö¹æ»®µÄÒ»¸ö¹Ø¼ü°²È«·ì϶ £¬¸Ã·ì϶¿ÉÄÜÈÃδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÔÚÊÜÓ°ÏìµÄÉ豸ÉÏÖ´ÐÐËÁÒâ´úÂë¡£¸Ã°²È«·ì϶¹Ù·½±àºÅΪ CVE-2024-20253 £¬ÔÚ CVSS ÉϵÄÑϳÁµÈ¼¶¸ß´ï 9.9¡£CVE-2024-20253 µÄÖ÷ÌâÔÚÓÚÒ»¸öΣÏյݲȫ·ì϶£ºÔÚ½«Óû§ÌṩµÄÊý¾ÝÉãÈëÄÚ´æÊ±¶ÔÆä½øÐв»µ±´¦ÖᣴËȱµãΪδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß´ò¿ªÁË´óÃÅ £¬Äܹ»Ôì×÷¶ñÒâÐÂÎŲ¢½«Æä·¢Ë͵½Ò×Êܹ¥»÷µÄÉ豸ÉϵÄÕìÌý¶Ë¿Ú¡£¸Ã·ì϶ӰÏìÒÔÏÂĬÈÏÅäÖõÄ˼¿Æ²úÆ·PCCE¡¢Unified CM¡¢UCCEºÍUCCXµÈ¡£


6. ×êÑÐÍŶӰ䲼APT10µÄ¶ñÒ⹤¾ßLODEINFOµÄ·ÖÎö»ã±¨


1ÔÂ24ÈÕ £¬ÔÚÊý×ÖÊÀ½çµÄÓݵ½ÇÂä £¬ÍøÂ簲ȫ·ÀÓùÕߺ͹¥»÷ÕßÖ®¼äµÄÕ½¶·²»ÐÝÇ¿Áҵط¢Õ¹ £¬Ò»¸öеĵÐÊÖÒѾ­³öÏÖ £¬ËûÃÇʹÓø´ÔӵĺýŪºÍÌӱܹ¤¾ß£ºLODEINFO¶ñÒâÈí¼þ¡£ÕâÖÖÎÞÎļþÍþв×Ô 2019 Äê 12 ÔÂÒÔÀ´Ò»ÏòÀ§ÈÅ×ÅÍøÂç¿Õ¼ä £¬´ú±í×ÅÍøÂç·¸×ï·Ö×ÓÕ½ÊõµÄ³Á´óת±ä £¬³ö¸ñÊÇÕë¶ÔÈÕ±¾²¿ÃÅ £¬Ô̺¬Ã½Ìå¡¢±í½»¡¢¹«¹²»ú¹¹¡¢¹ú·À¹¤ÒµºÍÖÇ¿âµÄÍøÂç·¸×ï·Ö×ÓÕ½ÊõµÄ³Á´óת±ä¡£×î½ü £¬ ITOCHU Cyber & Intelligence Inc.µÄ°²È«×êÑÐÈËÔ±¡£·ÖÎöÁË LODEINFO ¶ñÒâÈí¼þµÄÿ¸ö°æ±¾²¢·¢ÏÖÁ˱䶯¡£

LODEINFO ÊdzôÃûÔ¶ÑïµÄ APT ×éÖ¯ APT10 µÄǰ·æ £¬Õ¹Ê¾ÁËÍøÂçÍþвµÄ¾ªÈËÑݱä¡£Ëüͨ¹ý¿´ËÆÎÞº¦µÄÓã²æÊ½ÍøÂç´¹µöµç×ÓÓʼþÉøÈëϵͳ £¬ÀûÓöñÒâ Word Îĵ·´Ö´ÐÐÆäÏÕ¶ñµÄÒé³Ì¡£×î³õҲʹÓà Excel Îļþ £¬µ«¹¥»÷Õ߸ĽøÁ˲½ÖèÒÔÌá¸ß³É¹¦ÂÊ¡£