LinuxÏµÍ³Ãæ¶ÔÐÂÍþв£ºBootkitty UEFIÆô¶¯¹¤¾ß°ü±»·¢ÏÖ

°ä²¼¹¦·ò 2024-11-29

1. LinuxÏµÍ³Ãæ¶ÔÐÂÍþв£ºBootkitty UEFIÆô¶¯¹¤¾ß°ü±»·¢ÏÖ


11ÔÂ27ÈÕ  £¬Ò»¿îÃûΪBootkittyµÄLinux¶ñÒâÈí¼þ×÷ΪÊ׸öרÃÅÕë¶ÔLinuxϵͳµÄUEFIÆô¶¯¹¤¾ß°üÒѱ»·¢ÏÖ  £¬±ê־ȡ¶ÔWindowsµÄÒþÃØÆô¶¯¹¤¾ß°üÍþвÕý²úÉúת±ä¡£Ö»¹ÜĿǰËü½öÔÚijЩUbuntu°æ±¾ºÍÅäÖÃÉÏÆð×÷Óà  £¬ÇÒ´æÔںܶàδʹÓõÄÖ°ÄܺͼæÈÝÐÔÎÊÌâ  £¬³£µ¼ÖÂϵͳ±ÀÀ£  £¬µ«Æä´æÔÚ±ê־ȡUEFIÆô¶¯Ì×¼þÍþвÁìÓòµÄÒ»¸ö³Á´ó·¢Õ¹¡£Bootkittyͨ¹ý¹Ò½ÓUEFI°²È«ÈÏÖ¤ºÍ̸ºÍGRUBº¯ÊýÀ´Èƹý°²È«Æô¶¯ºÍÆëÈ«ÐÔÑéÖ¤  £¬´Ó¶ø¼ÓÔØ¶ñÒâ×é¼þ¡£Ëü»¹»áÀ¹½ØLinuxÄں˵Ľâѹ¹ý³Ì²¢¹Ò½ÓÓйغ¯Êý  £¬Ê¹¶ñÒâÈí¼þ¿ÉÄܼÓÔØ¶ñÒâÄ £¿é  £¬²¢ÔÚϵͳÆô¶¯Ê±×¢Èë¶ñÒâ¿â¡£×êÑÐÈËÔ±Ö¸³ö  £¬½«BootkittyÉÏ´«µ½VirusTotalµÄͳһÓû§»¹ÉÏ´«ÁËÒ»¸öÃûΪBCDropperµÄδÊðÃûÄÚºËÄ £¿é  £¬µ«Á½ÕßÖ®¼äµÄÁªÏµ½ÏÈõ¡£´ËÀà¶ñÒâÈí¼þµÄ·¢ÏÖÅú×¢  £¬Ëæ×ÅLinuxÔÚÆóÒµÖеı鼰  £¬¹¥»÷ÕßÔÚ¿ª·¢Ö®Ç°½öÏÞÓÚWindowsµÄLinux¶ñÒâÈí¼þ¡£ÓëBootkittyÓйصÄÈëÇÖÖ¸±êÒÑÔÚGitHubÉϹ²Ïí¡£


https://www.bleepingcomputer.com/news/security/researchers-discover-bootkitty-first-uefi-bootkit-malware-for-linux/


2. TorÏîÄ¿´¹Î£ºôÓõ£º²¿Êð¸ü¶àWebTunnelÇÅÆ¥µÐµ±¾ÖÉó²é


11ÔÂ28ÈÕ  £¬TorÏîÄ¿½üÆÚÏòÒþÖÔÉçÇø·¢³ö´¹Î£ºôÓõ  £¬ÒªÇó×ÔÔ¸ÕßÔÚ2025Äê3ÔÂ10ÈÕǰЭÖú²¿Êð200¸öеÄWebTunnelÇÅ  £¬ÒÔÓ¦¶ÔÈÕÒæÑϸñÈ·µ±¾ÖÉó²éÌôÕ½¡£Ä¿Ç°  £¬TorÏîÄ¿ÒÑÔËÓª143¸öWebTunnelÇÅ  £¬Ô®ÊÖÊÜÉó²éÏ޶ȵØÓòµÄÓû§½Ó¼û»¥ÁªÍø¡£´Ë¾ÙÖØÒªÕë¶Ô¶íÂÞ˹²»ÐݼÓÇ¿µÄÉó²éÔì¶È  £¬¸ÃÔì¶ÈÒÑÓ°Ïìä¯ÀÀÆ÷ÄÚÖõÄÉó²é¶ã±Ü»úÔì  £¬Èçobfs4ÏνӺÍSnowflake¡£TorÏîÄ¿ÒÔΪ  £¬³ÉÁ¢¸ü¶àWebTunnelÇÅÊÇÓ¦¶ÔÉó²éÉý¼¶µÄÓÐЧսÊõ  £¬ÓÉÓÚ¿ª·¢Ð½â¾ö¹æ»®±ØÒª¹¦·ò  £¬¶øÓû§ÔÚ´ËÆÚ¼ä¿ÉÄÜÃæ¶Ô·çÏÕ¡£WebTunnelsÊÇTorÏîÄ¿ÓÚ2024Äê3ÔÂÍÆ³öµÄÒ»ÖÖÐÂÐÍÇÅÁº  £¬Í¨¹ý½«TorÁ÷Á¿ÓëͨÀýÍøÂçÁ÷Á¿»ìºÏ  £¬²¢Ê¹Æ÷ÓµÓÐÓÐЧSSL/TLSÖ¤ÊéµÄWeb·þÎñÆ÷¼Ù×°³ÉHTTPSÁ÷Á¿  £¬´Ó¶ø¶ã±ÜÉó²é¡£TorÏîÄ¿Æô¶¯ÁËÒ»Ïîл  £¬ºôÓõ×ÔÔ¸Õ߲μӳÉÁ¢ºÍÊØ»¤WebTunnelÇÅ  £¬ÉèÁ¢Îå×ù»ò¸ü¶àÇŵÄ×ÔÔ¸Õß½«»ñµÃTÐô×÷Ϊ¸Ð¼¤¡£²Î¼ÓÒªÇóÔ̺¬Ã¿¸öIPv4Ò»¸öÇÅ¡¢ÌṩÓÐЧµç×ÓÓʼþ¡¢Î¬³ÖÇÅÁºÔËÐÐÖÁÉÙÒ»ÄêµÈ¡£×ÔÔ¸ÕßÄܹ»²é¿´¹Ù·½Ö¸ÄÏÏàʶ¸ü¶àÐÅÏ¢²¢²Î¼Ó»î¶¯¡£


https://www.bleepingcomputer.com/news/security/tor-needs-200-new-webtunnel-bridges-to-fight-censorship/


3. Ó¢¹úÍþÀÕ¶û´óѧ½²ÊÚÒ½ÔºÔâÍøÂç¹¥»÷  £¬·þÎñÖжÏÔ¤Ô¼ÍÆ³Ù


11ÔÂ28ÈÕ  £¬Ó¢¹úÖØÒªÒ½ÁƱ£½¡ÌṩÉÌÍþÀÕ¶û´óѧ½²ÊÚÒ½Ôº£¨WUTH£©  £¬×÷ΪNHS»ù½ð»áµÄÒ»²¿ÃÅ  £¬½üÆÚÔâ·êÁËÍøÂç¹¥»÷  £¬µ¼ÖÂϵͳÖÐ¶Ï  £¬Ô¤Ô¼ºÍÔ¤Ô¼·¨Ê½±»ÆÈÍÆ³Ù¡£WUTHÔËÓª×Ŷà¼ÒÒ½Ôº  £¬ÌṩÔ̺¬´¹Î£·þÎñ¡¢¼±ÐÔÒ½ÁÆ·þÎñ¡¢³ÁÖ¢¼à»¤¡¢±í¿Æ¡¢¶ù¿Æ¡¢²ú¿Æ·þÎñºÍ°©Ö¢»¤ÀíÔÚÄÚµÄÈ«ÃæÒ½ÁÆ·þÎñ¡£Õâ´ÎÍøÂç¹¥»÷ʹµÃ²¿ÃÅITϵͳÏÂÏß²¢×ªÎªÊÖ¶¯²Ù×÷  £¬²»³ÉÔ¤·ÀÏßÔì³ÉÁË·þÎñÖжϺÍÑÓÎó¡£Ò½ÔºÒѸ´Ô­ÒµÎñÂ½ÐøÐÔÁ÷³Ì  £¬Ê¹ÓÃÖ½ÖÊÎļþ´úÌæÊý×ÖÎļþ  £¬µ«´¹Î£Ò½ÖÎµÄÆÚ´ý¹¦·òÓÐËùÔö³¤¡£Ò½Ôº¶½´Ù¹«¼Ò½öÔÚÕæÕý´¹Î£Çé¿öÏÂǰÍù¼¹ØïÊÒ¡£Ä¿Ç°  £¬Ò½ÔºÈÔÎÞ·¨¹À¼ÆºÎʱÄܸ´Ô­Õý³£ÔËÓª  £¬ÇÒÉÐδÓÐÈκÎÀÕË÷Èí¼þ×éÖ¯¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü¡£¸ÃÒ½ÁÆ»ú¹¹ÉÐδ¶Ô¹¥»÷ÐÔÖÊÌṩ¸ü¶àÐÅÏ¢¡£


https://www.bleepingcomputer.com/news/security/uk-hospital-network-postpones-procedures-after-cyberattack/


4. Å·ÖÞ¶à¹ú½áºÏ½ø¹¥·¸·¨Á÷ýÌåÍøÂç  £¬È¡µÞµÁ°æ²¢¼ÓÇ¿ÍøÂç·¸×ï·À±¸


11ÔÂ28ÈÕ  £¬Å·ÖÞÐ̾¯×éÖ¯½áºÏ¶à¹ú·¨ÂÉ»ú¹¹  £¬³É¹¦È¡µÞÁËÒ»¸ö·¸·¨Á÷ýÌåÍøÂç  £¬¿ÛÁôÁ˽üÊ®¼¸ÃûÉæ°¸ÈËÔ±¡£¸ÃÍøÂçµÁ°æÁ˳¬¹ý2500¸öµçÊÓÆµÂ·  £¬ÏòÈ«Çò³¬¹ý2200ÍòÈËÌṩ·þÎñ  £¬Ã¿ÄêÔì³É100ÒÚÅ·ÔªµÄËðʧ¡£Å·ÖÞÐ̾¯×éÖ¯ÔÚÐж¯Öе÷²éÁË102ÃûÏÓÒÉÈË  £¬²¢Ö¸¿ØÉæ¼°Ï´Ç®ºÍÍøÂç·¸×ï¡£·¨ÂÉ»ú¹¹½øÐÐÁËÂÅ´ÎÍ»»÷²é³­  £¬²é»ñÁË·þÎñÆ÷ºÍIPTVÉ豸  £¬²¢ÔÚͻϮÆÚ¼ä·¢ÏÖÁ˶¾Æ·¡¢±øÆ÷ÒÔ¼°´óÁ¿¼ÓÃÜÇ®±ÒºÍÏÖ½ð¡£Õâ´ÎÐж¯µÃµ½Á˱£¼ÓÀûÑÇ¡¢¿ËÂÞµØÑÇ¡¢·¨¹úµÈ¶à¸öÅ·ÖÞ¹ú¶È·¨ÂÉ»ú¹¹µÄÖ§³Ö  £¬Òâ´óÀû¹ÙÔ±³ÆÆäΪ¸Ã¹úÊ·ÉÏ×î´ó¹æÄ£µÄ½ø¹¥ÒôÏñµÁ°æÐж¯¡£´Ë±í  £¬Å·ÖÞÐ̾¯×éÖ¯ºÍ¹ú¼ÊÐ̾¯×éÖ¯ÒÑ´òËãÔÚ2024ÄêÔ½·¢»ý¼«×Ô¶¯µØ½ø¹¥ÍøÂç·¸×ï  £¬½üÆÚ»¹°ä·¢ÁËÉæ¼°40¶à¸ö¹ú¶ÈµÄ¡°HAECHI¡±Ðж¯  £¬¿ÛÁôÁË5500¶àÃûÏÓÒÉÈË  £¬²¢½É»ñÁËÔ¼4ÒÚÃÀÔª¡£¹ú¼ÊÐ̾¯×éÖ¯ÃØÊ鳤°µÊ¾  £¬ÍøÂç·¸×ïµÄºó¹û¿ÉÄÜÊǸ²ÃðÐ﵀  £¬¹ú¼Ê¾¯Ô±ºÏ×÷ÖÁ¹Ø³ÁÒª¡£


https://therecord.media/11-arrested-europol-streaming-shutdown


5. ZelloÒªÇóÀÏÓû§³ÁÖÃÃÜÂë  £¬ÒÉÒò°²È«·ì϶


11ÔÂ27ÈÕ  £¬ZelloÊÇÒ»ÏîÕ¼ÓÐ1.4ÒÚÓû§µÄÒÆ¶¯·þÎñ  £¬½üÆÚÏòÓû§·¢³ö°²È«ÖÒ¸æ  £¬ÒªÇóËùÓÐÔÚ2024Äê11ÔÂ2ÈÕ֮ǰ´´½¨µÄÕË»§³ÁÖÃÃÜÂë¡£ÕâÒ»´ëÊ©ËÆºõÊǶÔDZÔÚ°²È«·ì϶µÄÔ¤·À´ëÊ©¡£¶à¶àÓû§ÔÚ11ÔÂ15ÈÕÊÕµ½ÁËÕâһ֪ͨ  £¬µ«ZelloδÌṩ½øÒ»²½µÄÐÅÏ¢»òÚ¹ÊÍ¡£Óû§±»Êèµ¼ÖÁÖ§³ÖÒ³ÃæÏàʶÈôºÎ¸ü¸ÄÃÜÂë  £¬²¢±»½¨Òé¸ü¸ÄÔÚÆäËûÔÚÏß·þÎñÖпÉÄÜʹÓùýµÄÒ»ÑùÃÜÂë¡£Ö»¹ÜĿǰÉв»Ã÷ÏÔÊÇ·ñ²úÉúÁËÊý¾Ýй¶»òƾ֤Ìî³ä¹¥»÷  £¬µ«Í¨ÖªÅú×¢ÍþвÐÐΪÕß¿ÉÄÜÒÑ»ñÈ¡¿Í»§ÃÜÂëµÄ½Ó¼ûȨÏÞ¡ £Ë¼¿¼µ½Zello³ö¸ñÖ¸³öÊÜÓ°ÏìµÄÊÇ11ÔÂ2ÈÕǰµÄÕË»§  £¬°²È«ÊÂÎñºÜ¿ÉÄܲúÉúÔڴ˹¦·òµã×ó½ü¡£ÖµÍ×ÌùÐĵÄÊÇ  £¬ZelloÔÚ2020ÄêÔø¾­Àú¹ýÒ»´ÎÊý¾Ýй¶  £¬µ¼Ö¿ͻ§µÄµç×ÓÓʼþµØÖ·ºÍÉ¢ÁÐÃÜÂë±»µÁ¡£


https://www.bleepingcomputer.com/news/security/zello-asks-users-to-reset-passwords-after-security-incident/


6. WotNotÊý¾Ýй¶ÊÂÎñ£ºAI¹©¸øÁ´ÖеÄÊý¾Ý°²È«ÓëÒþÖÔ·çÏÕ


11ÔÂ28ÈÕ  £¬Ó¡¶ÈÈËΪÖÇÄܲݴ´¹«Ë¾WotNot½üÆÚ²úÉúÁËһ·ÑϳÁµÄÊý¾Ýй¶ÊÂÎñ  £¬ÆäGoogle Cloud Storage´æ´¢Í°ÒòÅäÖÃÃýÎó¶øÂ¶³ö  £¬µ¼ÖÂ346,381¸öÎļþ±»Î´¾­ÊÚȨ½Ó¼û  £¬ÆäÖÐÔ̺¬»¤ÕÕ¡¢Ò½ÁƼͼ¡¢¼òÀúµÈÃô¸ÐÓ×ÎÒÊý¾Ý¡£WotNot×÷Ϊһ¼ÒΪÆóÒµ¶¨Ôì̸Ìì»úеÈËµÄÆ½Ì¨  £¬Æä¿Í»§º­¸ÇÁËĬ¿Ë¹«Ë¾¡¢¼ÓÖÝ´óѧµÈ³ÛÃûÆóÒµºÍ»ú¹¹¡£Õâ´Îй¶¶ÔÊÜÓ°ÏìµÄÓ×ÎÒ×é³ÉÁ˳Á´ó°²È«ºÍÒþÖÔÍþв  £¬ÎªÍøÂç·¸×ï·Ö×ÓÌṩÁËÉí·Ý͵ÇÔ¡¢Ú²Æ­µÈ»î¶¯µÄ¹¤¾ß°ü¡£¸ÃÊÂÎñ½ÒʾÁËAI·þÎñÒýÈëµÄÓ°×ÓIT×ÊÔ´·çÏÕ  £¬¼´²»ÊÜ×éÖ¯Ö±½Ó½ÚÔìµÄϵͳ¿ÉÄÜ´øÀ´µÄÊý¾ÝÁ÷²»ÊܽÚÔìÎÊÌâ¡£WotNotµÄ°¸ÀýÅú×¢  £¬µ¥¸ö¹©¸øÉ̵ݲȫ·ì϶¿ÉÄÜΣ¼°ÏÂÓζà¼Ò¹«Ë¾ºÍÊýǧÃûÓ×ÎÒµÄÊý¾Ý¡£Òò¶ø  £¬ÆóÒµ±ØÐëÒâʶµ½¶ÔÊý¾Ý°²È«µÄÔðÈβ»½öÏÞÓÚÄÚ²¿ÏµÍ³  £¬»¹Ó¦³¹µ×Éó²éAIÖ´ÐÐÁ´ÖÐÿ¸öºÏ×÷ͬ°éµÄ°²È«Êµ¼Ê¡£Cybernews×êÑÐÈËÔ±ÓÚ9ÔÂ9ÈÕÏòWotNotÅû¶ÁËÊý¾Ýй¶ÎÊÌâ  £¬µ«¸Ã¹«Ë¾»¨ÁËÁ½¸ö¶àÔ²ŹعØÁ˶Ôй¶Êý¾ÝµÄ½Ó¼û¡£


https://cybernews.com/security/wotnot-exposes-346k-sensitive-customer-files/