CleoÎļþ´«ÊäÈí¼þÁãÈÕ·ì϶ÔâºÚ¿ÍÀûÓýøÐÐÊý¾Ý͵ÇÔ¹¥»÷

°ä²¼¹¦·ò 2024-12-12

1. CleoÎļþ´«ÊäÈí¼þÁãÈÕ·ì϶ÔâºÚ¿ÍÀûÓýøÐÐÊý¾Ý͵ÇÔ¹¥»÷


12ÔÂ10ÈÕ £¬ºÚ¿ÍÔÚ»ý¼«ÀûÓÃCleoÖÎÀíÎļþ´«ÊäÈí¼þÖеÄз¢ÏÖµÄÁãÈÕ·ì϶ £¬ÇÖÈëÈ«ÇòÊýǧ¼Ò¹«Ë¾ÍøÂç £¬Ô̺¬Target¡¢ÎÖ¶ûÂêµÈ³ÛÃûÆóÒµ £¬½øÐÐÊý¾Ý͵ÇÔ¹¥»÷¡£¸Ã·ì϶´æÔÚÓÚCleo LexiCom¡¢VLTraderºÍHarmony²úÆ·ÖÐ £¬ÔÊÐí²»ÊÜÏ޶ȵÄÎļþÉÏ´«ºÍÏÂÔØ £¬µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£Ö»¹ÜCleo֮ǰÒѽ¨¸´ÁËÒ»¸öÓйطì϶CVE-2024-50623 £¬µ«ÍþвÐÐΪÕßÈÔÈÆ¹ýÁ˽¨¸´³ÖÐø¹¥»÷¡£ÍøÂ簲ȫר¼ÒÖ¸³ö £¬ÕâЩ¹¥»÷ÓëеÄTermiteÀÕË÷Èí¼þÍÅ»ïÓйØ¡£Huntress°²È«×êÑÐÈËÔ±³õ´Î·¢ÏÖÁ˸÷ì϶µÄ×Ô¶¯¹¥»÷ £¬²¢ÖÒ¸æÓû§²ÉÈ¡´¹Î£Ðж¯ £¬Ô̺¬½«ÏµÍ³ÒƵ½·À»ðǽºóÃæ £¬ÏÞ¶È±í²¿½Ó¼û £¬²¢²é³­¿ÉÒÉÎļþ¡£CleoÒÑÈ·ÈÏ·ì϶´æÔÚ £¬²¢ÔÚ¿ª·¢°²È«¸üР£¬Í¬Ê±ÌṩÁË»º½â´ëÊ©½¨Òé¡£¾Ý¹À¼Æ £¬ÃÀ¹úÓоø´óÎÞÊýÒ×Êܹ¥»÷µÄ·þÎñÆ÷ £¬È«ÇòÁìÓòÄÚÒÑÓÐÖÁÉÙÊ®¸ö×éÖ¯Êܵ½Ó°Ïì¡£


https://www.bleepingcomputer.com/news/security/new-cleo-zero-day-rce-flaw-exploited-in-data-theft-attacks/


2. AppLite Banker¶ñÒâÈí¼þÒÔÒøÐÐÀûÓ÷¨Ê½ÎªÖ¸±êÌáÒéÍøÂç´¹µö»î¶¯


12ÔÂ10ÈÕ £¬Ò»³¡¸´ÔÓµÄÍøÂç´¹µö»î¶¯ÔÚ´«²¼ÃûΪAppLite BankerµÄжñÒâÈí¼þ±äÖÖ £¬¸Ã¶ñÒâÈí¼þ±»¼ø±ðΪAntidotÒøÐÐľÂíµÄ¸üа汾 £¬ÖØÒªÕë¶ÔAndroidÉ豸¡£¹¥»÷Õßͨ¹ý¼ÙÒâ³ÛÃû¹«Ë¾ÕÐÆ¸ÈËԱijÈËÁ¦×ÊÔ´´ú±í £¬·¢ËÍÍøÂç´¹µöµç×ÓÓʼþÊèµ¼Óû§ÏÂÔØÚ²Æ­ÐÔCRMÀûÓ÷¨Ê½ £¬½ø¶ø×°ÖÃAppLite¶ñÒâÈí¼þ¡£¸Ã¶ñÒâÈí¼þÄÜÖ´ÐÐÆ¾Ö¤ÍµÇÔ¡¢ÀÄÓÃÎÞ×è°­·þÎñ¡¢Ô¶³Ì½ÚÔì¡¢ºýŪÐÔ¸²¸ÇµÈ¶àÖÖ¶ñÒâ»î¶¯ £¬²¢Õë¶Ô172¸öÀûÓ÷¨Ê½ £¬Ô̺¬½ðÈÚÆ½Ì¨ºÍ¼ÓÃÜÇ®°ü¡£ÎªÈƹý¼ì²â £¬AppLiteʹÓÃZIPÎļþ²Ù×÷ºÍǶÈëHTML¸²¸Ç²ã»ìºÏ°²È«¹¤¾ß¡£¸Ã¶ñÒâÈí¼þ¹¥»÷ÁìÓò¿í·º £¬Éæ¼°¶àÖÖ˵»°Óû§ £¬²¢ÄÜÇÔÈ¡ËøÆÁƾ֤×Ô¶¯½âËøÆÁÄ» £¬ÊµÏÖÆëÈ«½ÚÔìÊÜϰȾÉ豸¡£°²È«×êÑÐÈËԱǿµ÷×Ô¶¯·ÀÓù³ÁÒªÐÔ £¬½¨ÒéÖ´ÐÐ׳´óµÄÒÆ¶¯É豸ÖÎÀíÕþ²ß²¢¶¨ÆÚ¸üÐÂÉ豸ºÍ°²È«Èí¼þÒÔ·À±¸´ËÀàÍþв¡£


https://www.infosecurity-magazine.com/news/applite-malware-targets-banking/


3. Microsoft 365Öжϵ¼Ö Office WebÀûÓ÷¨Ê½ºÍÖÎÀíÖÐÐÄ̱»¾


12ÔÂ10ÈÕ £¬Î¢ÈíÔÚµ÷²éһ·ӰÏìOffice WebÀûÓúÍMicrosoft 365ÖÎÀíÖÐÐĵĴóÃæ»ýÇÒ³ÖÐøµÄMicrosoft 365ÖжÏÊÂÎñ¡£Óû§»ã±¨ÔÚÏνÓOutlook¡¢OneDriveºÍÆäËûOffice 365ÀûÓ÷¨Ê½ºÍ·þÎñʱ³öÏÖÎÊÌâ £¬²¢ÊÕµ½·þÎñÖжϵÄÐÂÎÅ¡£Î¢ÈíÖ¸³ö £¬ÎÊÌâ¿ÉÄÜÓëÉí·ÝÑéÖ¤»ù´¡ÉèÊ©ÖеÄÁîÅÆÌìÉúÓйØ £¬²¢ÔÚÉó²é×î½üµÄ±ä¶¯ÒÔÈ·¶¨µ××ÓÔ­Òò¡£×÷Ϊ½â¾ö²½Öè £¬Î¢Èí½¨ÒéÊÜÓ°ÏìµÄÓû§Ê¹ÓÃ×ÀÃæÀûÓ÷¨Ê½½Ó¼ûMicrosoft 365ÀûÓ÷¨Ê½ºÍÎĵµ¡£´Ëǰ £¬Microsoft 365Ò²Ôø²úÉú¹ýÈ«ÇòÖжÏÊÂÎñ £¬Ô̺¬Ó°Ïì¶àÏî·þÎñºÍÖ°ÄܵÄÇé¿ö¡£¶øÔÚ7Ô £¬Ò»´Î´ó¹æÄ£ÖжÏÔòÊÇÓÉÉ¢²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©¹¥»÷ÒýÆðµÄ¡£Ä¿Ç° £¬Î¢ÈíÔÚ²âÊÔÒ»¸öDZÔڵĽ¨¸´·¨Ê½ £¬²¢ÒѲ¿ÊðÁËÒ»¸ö½¨¸´·¨Ê½ÒÔ»º½âÖжÏÎÊÌ⡣΢Èí°µÊ¾ £¬Õâ´ÎÖжÏÊÇÓÉÓÚ×î½üµÄ·þÎñµ÷»»µ¼Ö¼ø±ðÁîÅÆµ½ÆÚ¹¦·ò³öÏÖÎÊÌâ £¬´Ó¶øµ¼ÖÂÉí·ÝÑéÖ¤ÒªÇóʧ°Ü¡£¾­¹ýÒ»¶Î¹¦·òµÄ¼à¿Ø·þÎñÒ£²âºó £¬¸Ã¹«Ë¾È·ÈϸÃÎÊÌâÏÖÒѽâ¾ö¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-365-outage-takes-down-office-web-apps-admin-center/


4. MetaÆìÏÂËÄ´óÉ罻ƽ̨ÔâÈ«ÇòÁìÓò¹¥»÷Ö·þÎñÖжÏ


12ÔÂ11ÈÕ £¬È«ÇòÁìÓòÄÚµÄFacebook¡¢Instagram¡¢ThreadsºÍWhatsAppÔâ·êÁËÑϳÁ¹¥»÷ £¬µ¼Ö·þÎñÖжÏ £¬·ÖÆçµØÓòµÄÓû§Êܵ½ÁË·ÖÆçˮƽµÄÓ°Ïì¡£¾ÝDownDetector³Æ £¬ÖжϲúÉúÔÚÃÀ¹ú¶«²¿¹¦·òÏÂÎç12:40×óÓÒ £¬ºÜ¶àÓû§ÎÞ·¨Í¨¹ýÍøÕ¾ºÍÀûÓ÷¨Ê½½Ó¼ûÕâЩ·þÎñ £¬Ò²ÎÞ·¨Í¨¹ýWhatsApp·¢ËÍÐÂÎÅ¡£µ±Óû§³¢ÊÔ½Ó¼ûFacebookʱ £¬»áÊÕµ½ÃýÎóÌáÐÑ¡£¹ÌÈ»MetaµÄÒµÎñÆ½Ì¨×´Ì¬Ò³ÃæÃ»ÓÐÏÔʾ´ó¹æÄ£·þÎñÖжÏ £¬µ«MetaÈÏ¿ÉÁËÖжϵIJúÉú £¬²¢°µÊ¾ÔÚÖÂÁ¦¸´Ô­·þÎñ¡£²¿ÃŵØÓòµÄ·þÎñÔÚÃÀ¹ú¶«²¿¹¦·òÏÂÎç1:20×óÓÒÆðÍ·¸´Ô­ £¬µ«ÈÔÓÐЧ»§»ã±¨ÎÞ·¨½Ó¼ûƽ̨¡£´Ëǰ £¬MetaÔøÔÚ3Ô·ݺÍ2021ÄêÔâ·ê¹ýÀàËÆµÄ·þÎñÖжÏ¡£½ØÖÁÃÀ¹ú¶«²¿¹¦·ò12ÔÂ11ÈÕÏÂÎç7:21 £¬Meta°µÊ¾ÖжÏÎÊÌâÒѸù»ù½â¾ö £¬²¢ÏòÊÜÓ°ÏìµÄÓû§°µÊ¾Ç¸Òâ¡£


https://www.bleepingcomputer.com/news/technology/facebook-instagram-whatsapp-hit-by-massive-worldwide-outage/


5. ¹ú¼ÊÐж¯¡°Operation PowerOFF¡±³ÁÈ­½ø¹¥DDoS³ö×â·þÎñ


12ÔÂ11ÈÕ £¬¹ú¼ÊÐж¯¡°Operation PowerOFF¡¹Øë¶ÔÍøÂç·¸×ïÖеÄÉ¢²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©¹¥»÷»ñµÃÁËÏÔÖø³É¾Í¡£À´×Ô15¸ö¹ú¶ÈµÄ·¨ÂÉ»ú¹¹ºÏ×÷ £¬³É¹¦ÏÂÏßÁË27¸öDDoS³ö×â·þÎñƽ̨ £¬¿ÛÁôÁËÈýÃûÖÎÀíÔ± £¬²¢È·¶¨ÁËÕâЩƽ̨µÄ300Ãû¿Í»§¡£ÕâЩƽ̨ÀûÓý©Ê¬ÍøÂç¶ÔÔÚÏßÖ¸±êÌáÒé¹¥»÷ £¬¿ÉÄܵ¼Ö·þÎñÖжϺÍÒµÎñËðʧ £¬³ö¸ñÊÇÔÚÍøÉϹºÎï¶¥·åÆÚ¡£Å·ÖÞÐ̾¯×é֯Эµ÷ÁËÕâ´ÎÐж¯ £¬Éæ¼°¶à¸ö¹ú¶È £¬Õë¶Ô²Î¼Ó´ËÀà·¸×ïµÄ¸÷¸ö²ãÃæµÄÈËÔ±¡£ÆäÖÐ £¬ºÉÀ¼¾¯·½¿ÛÁôÁËËÄÃûÉæÏÓÖ´ÐÐDDoS¹¥»÷µÄÏÓÒÉÈË £¬²¢È·¶¨ÁËÔ¼200ÃûÉæÏÓʹÓñ»²é»ñDDoS·þÎñµÄºÉÀ¼ÈË¡£Õâ´ÎÐж¯µÄ³É¹¦µÃÒæÓÚÅ·ÖÞÐ̾¯×éÖ¯µÄ·ÖÎöÖ§³Ö¡¢¼ÓÃÜ×·×ÙÐÅÏ¢ÒÔ¼°½áºÏÍøÂç·¸×ï×´¶¯³ö¸ñ¹¤×÷×éר¼ÒµÄЭÖú¡£´Ëǰ £¬¡°Operation PowerOFF¡±ÒѶÔDDoS×âÁÞÁìÓò½øÐÐÁËÂŴνø¹¥ £¬Ô̺¬²é·â´óÐÍÆ½Ì¨Dstat.ccºÍÈëÇÖ²¢¹Ø¹ØDigitalStress·þÎñ¡£


https://www.bleepingcomputer.com/news/security/operation-poweroff-shuts-down-27-ddos-for-hire-platforms/


6. Krispy KremeÔâÍøÂç¹¥»÷ £¬Ó°ÏìÔÚÏß¶©¹ººÍÔËÓª


12ÔÂ11ÈÕ £¬ÃÀ¹úÌðÌðȦÁ¬ËøµêKrispy KremeÔÚ2024Äê11ÔÂÔâ·êÁËÍøÂç¹¥»÷ £¬µ¼ÖÂÆäÔÚÃÀ¹úµÄÔÚÏß¶©¹ºÏµÍ³ÖжÏ £¬Ó°ÏìÁ˲¿ÃÅÒµÎñÔËÓª¡£¸Ã¹«Ë¾Õ¼ÓÐ1,521¼ÒÃŵêºÍ¶à¶àÔ±¹¤ £¬²¢ÓëÂóµ±À͵ȺÏ×÷ͬ°éÓлý¼«¹ØÏµ¡£Êý×Ö¶©µ¥Õ¼¹«Ë¾ÏúÊÛ¶îµÄ15.5% £¬¶Ô¹«Ë¾Òµ¼¨ÓгÁÒªÓ°Ïì¡£ÔÚ¹¥»÷²úÉúºó £¬Krispy KremeÁ¢¼´×·Çó¶¥¼âÍøÂ簲ȫר¼ÒµÄÔ®ÊÖ £¬²¢²ÉÈ¡´ëÊ©½ÚÔìºÍ²¹¾ÈÊÂÎñ £¬µ«µ÷²éÈÔÔÚ½øÐÐÖÐ £¬¾ßÌåÓ°ÏìÉдýÆÀ¹À¡£Õâ´Î¹¥»÷¶Ô¹«Ë¾µÄÒµÎñ²úÉúÁ˳Á´óÓ°Ïì £¬²¢½«³ÖÐøµ½¸´Ô­ÊµÏÖΪֹ¡£Í¬Ê± £¬¹«Ë¾Ô¤¼ÆÊý×ÖÏúÊÛÊÕÈëµÄËðʧ¡¢ÍøÂ簲ȫר¼ÒºÍÕÕ·÷µÄÓöÈÒÔ¼°ÏµÍ³¸´Ô­¹¤×÷Óйصijɱ¾½«²úÉú³Á´óµÄ²ÆÕþÓ°Ïì¡£Êг¡¶Ô´ËÐÂÎÅ×ö³öÁ˸ºÃæ·´Ó³ £¬Krispy KremeµÄ¹É¼Û×ÅÂäÁË2%¡£Ä¿Ç°Éв»Ã÷ÏÔÕâÊÇÒ»´ÎÀÕË÷Èí¼þ¹¥»÷»¹ÊÇÆäËûÀàÐ͵Ĺ¥»÷ £¬Ò²Ã»ÓÐÀÕË÷Èí¼þ×éÖ¯¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü¡£


https://www.bleepingcomputer.com/news/security/krispy-kreme-cyberattack-impacts-online-orders-and-operations/