MicroliseÔâÍøÂç¹¥»÷ £¬Ö¼àÓü³µºÍ¿ìµÝ³µÁ¾×·×Ùϵͳ̱»¾

°ä²¼¹¦·ò 2024-11-08

1. MicroliseÔâÍøÂç¹¥»÷ £¬Ö¼àÓü³µºÍ¿ìµÝ³µÁ¾×·×Ùϵͳ̱»¾


11ÔÂ7ÈÕ £¬MicroliseÊÇÒ»¼ÒΪ³µ¶ÓÔËÓªÉÌÌṩ³µÁ¾×·×Ù½â¾ö¹æ»®µÄ¹«Ë¾ £¬½üÆÚÔâ·êÁËÍøÂç¹¥»÷ £¬µ¼ÖÂÆä¼àÓü³µºÍ¿ìµÝ³µÁ¾µÄ×·×ÙϵͳºÍ¾¯±¨ÏµÍ³±»½ûÓ᣸ù«Ë¾ÔÚ10ÔÂ31ÈÕ֪ͨÂ×¶ØÖ¤È¯ÂòÂôËùÆäÍøÂçÉϲúÉúÁË¡°Î´¾­ÊÚȨµÄ»î¶¯¡± £¬²¢ÀñƸÁË±í²¿ÍøÂ簲ȫר¼Ò½øÐе÷²éºÍ¸´Ô­¹¤×÷¡£½ØÖÁ11ÔÂ6ÈÕ £¬Microlise°µÊ¾ÒÑÔÚ½ÚÔìºÍ¶Ï¸ùÍøÂçÍþв·½Ãæ»ñµÃÄÚÈÝÐÔ½øÕ¹ £¬²¢¸´Ô­ÁËËùÓзþÎñ £¬Ô¤¼ÆÏÂÖÜÄ©½«È«ÃæÍ¶ÈëÔËÓª¡£Õâ´Î¹¥»÷δÇÖº¦¿Í»§ÏµÍ³Êý¾Ý £¬µ«²¿ÃÅÔ±¹¤Êý¾ÝÊܵ½Ó°Ïì £¬ÊÜÓ°ÏìÓ×ÎÒ½«Æ¾¾Ý¹«Ë¾¼à¹ÜʹÃüµÃµ½Í¨Öª £¬²¢·î¸æÓйز¿ÃÅ¡£ÊÜÓ°ÏìµÄ¿Í»§Ô̺¬Ó¢¹úµ±¾Ö³Ð°üÉÌSercoºÍ¿ìµÝ¹«Ë¾DHL £¬ÆäÖÐSercoÔÚÏ®»÷Ó°Ïì·¢ÏÖǰµÄ¼¸ÌìÄÚ £¬²¿ÃÅÇô·¸»¤ËÍ·þÎñ²»×ãµØÎ»¸ú×ٺͰ²È«±£ÏÕ £¬¶øDHLµÄ²¿Ãųµ¶ÓÒ²²»×ã×·×ÙÖ°ÄÜ¡£MicroliseÎ´Ð¹Â©ÍøÂç¹¥»÷ÀàÐͼ°ÊÜÓ°Ïì¿Í»§µÄ¾ßÌåÐÅÏ¢¡£


https://www.securityweek.com/cyberattack-on-microlise-disables-tracking-in-prison-vans-courier-vehicles/


2. CISAÖҸ棺Palo Alto Networks Expedition´æÔÚÉí·ÝÑéÖ¤·ì϶Ôâ¹¥»÷


11ÔÂ7ÈÕ £¬CISA½üÈÕ·¢³öÖÒ¸æ £¬Ö¸³ö¹¥»÷ÕßÔÚÀûÓÃPalo Alto Networks ExpeditionÖеÄÑϳÁÉí·ÝÑéÖ¤·ì϶¡£ExpeditionÊÇÒ»ÖÖǨá㹤¾ß £¬ÓÃÓÚ½«·À»ðǽÅäÖôÓCheckpoint¡¢CiscoµÈ¹©¸øÉÌת»»ÎªPAN-OS¡£¸Ã·ì϶£¨CVE-2024-5910£©ÒÑÔÚ7Ôµõ½½¨¸´ £¬µ«ÍþвÕßÈÔÄÜÔ¶³ÌÀûÓÃËü³ÁÖö³öÔÚ»¥ÁªÍøÉϵÄExpedition·þÎñÆ÷ÉϵÄÀûÓ÷¨Ê½ÖÎÀíԱʹ´¦¡£CISAÖ¸³ö £¬´Ë·ì϶ÔÊÐí¹¥»÷ÕßÊÕÊÜExpeditionÖÎÀíÔ¹ØÊ»§ £¬²¢¿ÉÄܽӼû»úÃÜÅäÖá¢Í´´¦¼°ÆäËûÊý¾Ý¡£Ö»¹ÜÍøÂ簲ȫ»ú¹¹Î´Ìṩ¸ü¶à¹¥»÷ϸ½Ú £¬µ«Horizon3.ai·ì϶×êÑÐÔ±Zach Hanley°ä²¼ÁËÒ»¸ö¸ÅÏëÑéÖ¤·ì϶ £¬¿É½áºÏÁíÒ»¸öÒѽ¨²¹µÄºÅÁî×¢Èë·ì϶£¨CVE-2024-9464£© £¬ÔÚÒ×Êܹ¥»÷µÄ·þÎñÆ÷ÉÏʵÏÖδ¾­Éí·ÝÑéÖ¤µÄËÁÒâºÅÁîÖ´ÐС£Palo Alto Networks½¨ÒéÖÎÀíÔ±ÏÞ¶ÈExpeditionµÄÍøÂç½Ó¼û £¬²¢ÔÚÉý¼¶µ½¹Ì¶¨°æ±¾ºóÂÖ»»ËùÓÐЧ»§Ãû¡¢ÃÜÂëºÍAPIÃÜÔ¿¡£CISAÒѽ«¸Ã·ì϶Ôö³¤µ½ÆäÒÑÖª±»ÀûÓ÷ì϶Ŀ¼ÖÐ £¬ÒªÇóÃÀ¹úÁª¹ú»ú¹¹ÔÚÈýÖÜÄÚ£¨¼´11ÔÂ28ÈÕǰ£©±£»¤ÆäÍøÂçÉϵÄÒ×Êܹ¥»÷·þÎñÆ÷¡£


https://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-palo-alto-networks-bug-exploited-in-attacks/


3. Androxgh0stÓëMozi½©Ê¬ÍøÂ缯³É £¬ÍþвȫÇòWebºÍIoTÉ豸°²È«


11ÔÂ7ÈÕ £¬CloudSEK»ã±¨Ö¸³ö £¬Androxgh0st½©Ê¬ÍøÂçÒÑÓëMozi½©Ê¬ÍøÂ缯³É £¬ÀûÓÃWebÀûÓ÷¨Ê½ºÍIoTÉ豸ÖеĶàÖÖ·ì϶½øÐй¥»÷¡£×Ô2024Äê1ÔÂÆð £¬Androxgh0stÕë¶ÔÍøÂç·þÎñÆ÷½øÐÐˢкó³ÁгöÏÖ £¬²¢¹²ÏíÁËMozi½©Ê¬ÍøÂçµÄ×é¼þ £¬´Ó¶ø¿ÉÄÜϰȾ¸ü¶àIoTÉ豸¡£×êÑÐÈËÔ±·¢ÏÖ £¬Androxgh0stµÄ¹¥»÷²½ÖèÒÑÀ©´ó £¬¶Ô×¼ÁËÔ̺¬Cisco ASA¡¢Atlassian JIRA¡¢PHP¿ò¼Ü¡¢Metabase¡¢Apache Web·þÎñÆ÷ºÍ¶àÖÖÎïÁªÍøÉ豸ÔÚÄڵĶà¸ö·ì϶¡£Í¨¹ýÕûºÏMoziµÄÖ°ÄÜ £¬Androxgh0st¿ÉÄÜÀûÓÃÅäÖÃÃýÎóµÄ·ÓÉÆ÷ºÍÉ豸 £¬ÔÚÈ«ÇòÁìÓòÄÚϰȾÉ豸¡£´Ë±í £¬¸Ã½©Ê¬ÍøÂ绹Õë¶Ô¶à¸ö¹ú¶ÈºÍµØÓòµÄÉ豸½øÐй¥»÷ £¬µÂ¹úλ¾ÓÊÜϰȾÉ豸ÊýÁ¿°ñÊס£×éÖ¯Ó¦Á¢¼´½¨²¹Óйطì϶ £¬¼à¿ØÍøÂçÁ÷Á¿ £¬²¢·ÖÎöÈÕÖ¾ÒÔ²éÕÒÈëÇÖ¼£Ïó £¬ÒÔ±£»¤ÏµÍ³ÃâÊÜÕâÖÖ²»ÐÝÑݱäµÄÍþв¡£


https://hackread.com/androxgh0st-botnet-integrate-mozi-iot-vulnerabilities/


4. ³¯ÏʺڿÍÀûÓá°°µ²Ø·çÏÕ¡±¶ñÒâÈí¼þ¹¥»÷¼ÓÃÜÇ®±ÒÆóÒµ


11ÔÂ7ÈÕ £¬³¯Ïʵ±¾ÖÖ§³ÖµÄAPT×éÖ¯BlueNoroffÔÚÀûÓÃÒ»ÖÖÃûΪ¡°°µ²Ø·çÏÕ¡±µÄÐÂÐͶñÒâÈí¼þ¹¥»÷¼ÓÃÜÇ®±ÒÆóÒµ¡£¸Ã¹¥»÷ͨ¹ý¾«ÐÄÔì×÷µÄÍøÂç´¹µöµç×ÓÓʼþ £¬ÓÕʹÊܺ¦Õßµã»÷¶ñÒâÁ´½Ó £¬ÏÂÔØ¼Ù×°³ÉPDFÔĶÁÆ÷µÄ¶ñÒâMacÀûÓ÷¨Ê½¡£Ò»µ©Ö´ÐÐ £¬¸ÃÀûÓ÷¨Ê½»á°ÂÃØÏÂÔØ²¢Ö´ÐжñÒâ¶þ½øÔìÎļþ £¬×°ÖúóÃŲ¢ÍøÂçϵͳÃô¸ÐÐÅÏ¢ £¬ÓëÔ¶³Ì·þÎñÆ÷ͨѶ £¬½Ó¹Ü²¢Ö´ÐкÅÁΪÁËÈ·Î¬ÓÆ¾ÃÐÔ £¬¹¥»÷Õß»¹Åú¸ÄÁËZshÅäÖÃÎļþ £¬Ê¹ºóÃÅÄܹ»ÔÚϵͳÆô¶¯Ê±×Ô¶¯Ö´ÐС£×êÑÐÈËÔ±ÒÔΪ £¬Õâ´Î¹¥»÷»î¶¯ÓëBlueNoroffÓйØÁª £¬ÒòÆä¼¼ÊõÓëBlueNoroff´ÓǰµÄ¹¥»÷»î¶¯ÀàËÆ £¬ÇÒʹÓÃÁËÓëÆäÓйصĶñÒâÈí¼þµÄÓû§´úÀí×Ö·û´® £¬²¢ÀûÓÿª·¢ÕßÕÊ»§ÈÃApple¹«Ö¤¶ñÒâÈí¼þ £¬´Ó¶øÈƹý°²È«´ëÊ©¡£¼øÓÚBlueNoroffÂÅ´ÎÒÔ¼ÓÃÜÇ®±ÒÂòÂôËù¡¢·çÏÕͶ×ʹ«Ë¾ºÍÒøÐÐΪָ±ê £¬ÐÐҵӦά³Ö¾¯Ìè¡£Óû§Ó¦×Ðϸ²é³­µç×ÓÓʼþµØÖ· £¬Ô¤·Àµã»÷δ֪µç×ÓÓʼþÖеÄÁ´½Ó £¬ÓÈÆäÊÇÒªÇóÏÂÔØÀûÓ÷¨Ê½/PDFµÄÁ´½Ó £¬ÒÔÈ·±£×ÔÉí°²È«¡£


https://hackread.com/north-korean-hackers-crypto-fake-news-hidden-risk-malware/


5. °×ñºÚ¿ÍSean Kahler¸æ·¢²¢Öú½¨EAÕË»§ÏµÍ³ÑϳÁ·ì϶


11ÔÂ6ÈÕ £¬ÓÎÏ·¿ª·¢Õß¼æÄæÏò¹¤³ÌʦSean Kahler·¢ÏÖ²¢ÀûÓÃÁËÒ»¸öÓ°Ïìµç×ÓÒս磨EA£©ÕË»§ÏµÍ³µÄÑϳÁ·ì϶ £¬·¸·¨»ñÈ¡Á˳¬¹ý7ÒÚEAÓû§ÕË»§ÐÅÏ¢ £¬Ô̺¬ÓÎϷͳ¼ÆÊý¾Ý¡£Ëûͨ¹ýÔÚÓÎÏ·¿ÉÖ´ÐÐÎļþÖÐÕÒµ½Ó²±àÂëÆ¾Ö¤ £¬»ñµÃÁËEA¿ª·¢ÈËÔ±²âÊÔ»·¾³ÖеÄÌØÈ¨½Ó¼ûÁîÅÆ £¬½ø¶ø·¢ÏÖÁËÒ»¸ö¶³öµÄÄÚ²¿·þÎñAPI £¬¸ÃAPIÔÊÐíÅú¸ÄÍæ¼Ò×ÊÁÏ¡£KahlerÀûÓô˷ì϶½«EAÕË»§×´Ì¬¸ü¸ÄΪ¡°ÒѲ»ÈÝ¡± £¬×èÖ¹Óû§µÇ¼ÓÎÏ· £¬²¢Äܽ«Steam»òXboxÕË»§Á´½Óµ½ÆäËûÓû§µÄEAÕË»§ £¬ÎÞÐèÑéÖ¤»òÃÜÂë¼´¿ÉµÇ¼ÆäËûÕË»§¡£ËûÒâʶµ½ÕâÒ»·ì϶µÄÑϳÁÐÔºó £¬ÓÚ2024Äê6ÔÂ16ÈÕÏòEAÕÆ¹ÜÈεØÅû¶ÁË·ì϶ £¬EAÈ·ÈÏÁË·ì϶²¢°ä²¼ÁËÎå¸ö²¹¶¡½øÐн¨¸´¡£È»¶ø £¬KahlerÖ¸³öEA»¨Á˽ϳ¤¹¦·ò²Å½¨¸´·ì϶ £¬ÇÒÉÐδÆô¶¯·ì϶Éͽð´òËã £¬²»×ã»ã±¨·ì϶µÄ¶¯Á¦¡£


https://cybernews.com/security/whitehat-gains-access-to-over-700-million-ea-accounts/


6. GodFather¶ñÒâÈí¼þÈ«ÇòÀ©ÕÅ£ºÕë¶Ô500¶à¸ö½ðÈÚÀûÓÃ


11ÔÂ7ÈÕ £¬Cyble ×êÑÐÓëµý±¨³¢ÊÔÊÒ (CRIL) »ã±¨Ö¸³ö £¬GodFather ¶ñÒâÈí¼þµÄÁìÓòÒÑÀ©´óÖÁÈ«Çò 500 ¶à¸öÒøÐкͼÓÃÜÇ®±ÒÀûÓ÷¨Ê½ £¬Ñ¡È¡¸´ÔÓ¼¼ÊõÈç±¾»ú´úÂëʵÏÖºÍ×îµÍȨÏÞ £¬Ê¹Æä±ÈÒÔǰԽ·¢ÄÑÒÔ×½ÃþºÍΣÏÕ¡£¸Ã¶ñÒâÈí¼þÀûÓô¹µöÍøÕ¾·Ö·¢¼Ù×°³ÉºÏ·¨ÀûÓ÷¨Ê½µÄ¶ñÒâ APK Îļþ £¬Ö¼ÔÚÇÔÈ¡ÒøÐÐÆ¾Ö¤¡£Ëü»¹ÄÜÀûÓà Android É豸µÄ Accessibility ·þÎñÖ´Ðи÷Àà¶ñÒâÖ°ÄÜ £¬Èç×Ô×ÅÊÖÊÆ¡¢ÓëºÅÁîºÍ½ÚÔì·þÎñÆ÷³ÉÁ¢ÏνÓÒÔ¼°¼üÅ̼ͼ¡£Ò»µ©¼ì²âµ½Ö¸±êÀûÓ÷¨Ê½ £¬GodFather ¾Í»á¹Ø¹ØºÏ·¨ÀûÓ÷¨Ê½²¢¼ÓÔØÐéαµÇÂ¼Ò³ÃæÒÔÇÔȡʹ´¦¡£´Ë±í £¬ÆäµØÀí¸²¸ÇÁìÓòÒ²ÔÚÀ©´ó £¬ÏÖÒÑÕë¶ÔÈÕ±¾¡¢ÐÂ¼ÓÆÂ¡¢°¢Èû°Ý½®ºÍÏ£À°µÄÓû§¡£CRIL ×Ü½á³Æ £¬Æ¾½èÆäеÄ×Ô¶¯»¯²Ù×÷ºÍÔÚ¸ü¶à¹ú¶È/µØÓòÕë¶ÔÀûÓ÷¨Ê½µÄ¸ü¿í·ºÖ¸±ê £¬GodFather ¶ñÒâÈí¼þ¶ÔÈ«ÇòÓû§×é³ÉÁËÔ½À´Ô½´óµÄ·çÏÕ £¬Òò¶øÎ¬³Ö¾¯Ìè²¢ÔÚÒÆ¶¯É豸ÉϲÉȡ׳´óµÄ°²È«´ëÊ©ÖÁ¹Ø³ÁÒª¡£


https://securityonline.info/godfather-malware-now-targets-500-banking-and-crypto-apps