΢Èí¸ß¹ÜµÄµç×ÓÓʼþÕ˺ÅÔâ¶íÂÞ˹ºÚ¿ÍNobeliumµÄÈëÇÖ

Ðû²¼Ê±¼ä 2024-01-22

1. ΢Èí¸ß¹ÜµÄµç×ÓÓʼþÕ˺ÅÔâ¶íÂÞ˹ºÚ¿ÍNobeliumµÄÈëÇÖ


1ÔÂ20ÈÕ £¬ £¬£¬£¬ £¬ £¬ £¬£¬£¬ £¬Î¢ÈíÅû¶һ¸öÓë¶íÂÞ˹ÓйصÄÃûΪNobelium µÄºÚ¿Í×éÖ¯»ñµÃÁ˼¸Î»¸ß¹ÜµÄµç×ÓÓʼþÕÊ»§µÄ»á¼ûȨÏÞ £¬ £¬£¬£¬ £¬ÆäÖаüÀ¨¸Ã¹«Ë¾¸ß¼¶Ïòµ¼ÍŶӵijÉÔ±¡£¡£¡£¡£¡£¡£¡£Nobelium £¬ £¬£¬£¬ £¬Ò²³ÆÎªMidnight Blizzard £¬ £¬£¬£¬ £¬ÊÇÒ»¸öÍøÂç·¸·¨×éÖ¯ £¬ £¬£¬£¬ £¬Òò¼ÓÈë 2020 Äê 12 ÔÂSolarWinds ¹©Ó¦Á´¹¥»÷¶øÎÛÃûÕÑÖø £¬ £¬£¬£¬ £¬¸Ã¹¥»÷Ëðº¦ÁËÖÚ¶àÕþ¸®»ú¹¹ºÍ˽Ӫ¹«Ë¾µÄÀûÒæ¡£¡£¡£¡£¡£¡£¡£ÔÚ×îеÄÊÂÎñÖÐ £¬ £¬£¬£¬ £¬ºÚ¿ÍʹÓá°ÒÅÁô¡±²âÊÔÕÊ»§ÔÚ΢ÈíµÄ¹«Ë¾ÍøÂçÖлñµÃפ×ãµã¡£¡£¡£¡£¡£¡£¡£È»ºó £¬ £¬£¬£¬ £¬ËûÃÇʹÓÃÕÊ»§µÄȨÏÞ»á¼ûһС²¿·ÖÔ±¹¤µç×ÓÓʼþÕÊ»§ £¬ £¬£¬£¬ £¬°üÀ¨ÊôÓڸ߼¶ÖÎÀíÖ°Ô±¡¢ÍøÂçÇå¾²Ö°Ô±¡¢Ö´·¨Ö°Ô±ºÍÆäËûÖ°Ô±µÄµç×ÓÓʼþÕÊ»§¡£¡£¡£¡£¡£¡£¡£ËäÈ»´Ë´Îй¶µÄËùÓйæÄ£ÈÔÔÚÊÓ²ìÖÐ £¬ £¬£¬£¬ £¬µ«Î¢Èí¼á³Æ´Ë´Î¹¥»÷²¢Î´Éæ¼°Æä½¹µã²úÆ·»òЧÀÍÖеÄÎó²î¡£¡£¡£¡£¡£¡£¡£±ðµÄ £¬ £¬£¬£¬ £¬ËûÃÇÏò¿Í»§°ü¹Ü £¬ £¬£¬£¬ £¬¿Í»§Êý¾Ý²»»áÊܵ½Ë𺦡£¡£¡£¡£¡£¡£¡£


2. Ñо¿ÍŶӳÆ3AM¡¢RoyalºÍContiÍøÂç·¸·¨¼¯Íű£´æ¹ØÁª


1ÔÂ20ÈÕ £¬ £¬£¬£¬ £¬Çå¾²Ñо¿Ö°Ô±ÆÊÎöÁË×î½ü·ºÆðµÄ 3AM ÀÕË÷Èí¼þ²Ù×÷µÄ»î¶¯ £¬ £¬£¬£¬ £¬·¢Ã÷ÆäÓë Conti ¼¯ÍÅºÍ Royal ÀÕË÷Èí¼þÍÅ»ïµÈÎÛÃûÕÑÖøµÄ×éÖ¯ÓÐÇ×½üÁªÏµ¡£¡£¡£¡£¡£¡£¡£3AM£¨Ò²Æ´Ð´Îª ThreeAM£©Ò²Ò»Ö±ÔÚʵÑéÒ»ÖÖеÄÀÕË÷Õ½ÂÔ£ºÓëÊܺ¦ÕßµÄÉ罻ýÌ幨עÕß·ÖÏíÊý¾Ýй¶µÄÐÂÎÅ £¬ £¬£¬£¬ £¬²¢Ê¹ÓûúеÈ˻ظ´ X£¨ÒÔǰ³ÆÎª Twitter£©Éϵĸ߼¶ÕÊ»§ £¬ £¬£¬£¬ £¬·¢ËÍÖ¸ÏòÊý¾Ýй¶µÄÐÂÎÅ¡£¡£¡£¡£¡£¡£¡£·¨¹úÍøÂçÇå¾²¹«Ë¾IntrinsecµÄÑо¿Ö°Ô±ÌåÏÖ £¬ £¬£¬£¬ £¬ThreeAM ºÜ¿ÉÄÜÓë Royal ÀÕË÷Èí¼þ×éÖ¯ÓÐ¹Ø £¬ £¬£¬£¬ £¬¸Ã×éÖ¯ÏÖÒÑ ¸üÃûΪ Blacksuit £¬ £¬£¬£¬ £¬¸ÃÍÅ»ïÓÉ Conti ¼¯ÍÅÄÚ Team 2 µÄǰ³ÉÔ±×é³É¡£¡£¡£¡£¡£¡£¡£Ëæ×Å Intrinsec ¶Ô¸Ã×éÖ¯µÄÕ½ÂÔ¡¢¹¥»÷ÖÐʹÓõĻù´¡ÉèÊ©ºÍͨѶÇþµÀµÄÊÓ²ìÈ¡µÃÏ£Íû £¬ £¬£¬£¬ £¬3AM ÀÕË÷Èí¼þÓë Conti ¼¯ÍÅÖ®¼äµÄÁªÏµ±äµÃÔ½·¢Ï¸ÃÜ¡£¡£¡£¡£¡£¡£¡£Éó²é Tor ÍøÂçÖÐµÄ 3AM Êý¾Ýй¶վµã £¬ £¬£¬£¬ £¬¿ÉÒÔ¿´µ½ 19 ÃûÊܺ¦ÕßµÄÃûµ¥ £¬ £¬£¬£¬ £¬ËûÃÇûÓÐÖ§¸¶Êê½ð £¬ £¬£¬£¬ £¬µ«ÍþвÕßй¶ÁËËûÃǵÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£ÁîÈ˾ªÑȵÄÊÇ £¬ £¬£¬£¬ £¬3AM µÄÍøÕ¾¿´ÆðÀ´Óë LockBit ÀÕË÷Èí¼þ²Ù×÷ËùʹÓõÄÍøÕ¾ºÜÊÇÏàËÆ¡£¡£¡£¡£¡£¡£¡£


3. TA866¾íÍÁÖØÀ´²¢°²ÅÅWasabiSeedºÍScreenshotter


1ÔÂ20ÈÕ £¬ £¬£¬£¬ £¬TA866 µÄÍþвÐÐΪÕßÔÚÖÐÖ¹¾Å¸öÔºóÔٴηºÆð £¬ £¬£¬£¬ £¬ÌᳫÁËÒ»³¡ÐµĴó¹æÄ£ÍøÂç´¹Âڻ £¬ £¬£¬£¬ £¬ÒÔÈö²¥ WasabiSeed ºÍ Screenshotter µÈÒÑÖª¶ñÒâÈí¼þϵÁС£¡£¡£¡£¡£¡£¡£¸Ã»î¶¯ÓÚ±¾ÔÂÔçЩʱ¼äÊӲ쵽 £¬ £¬£¬£¬ £¬²¢ÓÚ 2024 Äê 1 Ô 11 ÈÕ±» Proofpoint ×èÖ¹ £¬ £¬£¬£¬ £¬ÆäÖÐÉæ¼°Ïò±±ÃÀ·¢ËÍÊýǧ·â´øÓÐÓÕ¶ü PDF ÎļþµÄ·¢Æ±Ö÷Ìâµç×ÓÓʼþ¡£¡£¡£¡£¡£¡£¡£ÕâЩ PDF °üÀ¨ OneDrive URL £¬ £¬£¬£¬ £¬ÈôÊǵã»÷ÕâЩ URL £¬ £¬£¬£¬ £¬¾Í»áÆô¶¯¶à°ì·¨Ñ¬È¾Á´ £¬ £¬£¬£¬ £¬¼´ WasabiSeed ºÍ Screenshotter ×Ô½ç˵¹¤¾ß¼¯µÄ±äÌå¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÓÚ 2023 Äê 2 ÔÂÊ״μͼTA866 £¬ £¬£¬£¬ £¬½«Æä¹éÒòÓÚÃûΪ Screentime µÄ»î¶¯ £¬ £¬£¬£¬ £¬¸Ã»î¶¯·Ö·¢ÁË WasabiSeed £¬ £¬£¬£¬ £¬ÕâÊÇÒ»ÖÖÓÃÓÚÏÂÔØ Screenshotter µÄ Visual Basic ¾ç±¾Í¶·Å³ÌÐò £¬ £¬£¬£¬ £¬Äܹ»°´ÆÚ½ØÈ¡Êܺ¦Õß×ÀÃæµÄÆÁÄ»½ØÍ¼²¢ÇÔÈ¡Êý¾Ý½«¸ÃÊý¾Ý·¢Ë͵½¼ÓÈëÕß¿ØÖƵÄÓò¡£¡£¡£¡£¡£¡£¡£ÓÐÖ¤¾ÝÅú×¢ £¬ £¬£¬£¬ £¬ÓÐ×éÖ¯µÄÐÐΪÕß¿ÉÄÜÊdzöÓÚ¾­¼ÃÄîÍ· £¬ £¬£¬£¬ £¬ÓÉÓÚ Screenshotter ³äµ±Õì̽¹¤¾ßÀ´Ê¶±ðºóʹÓõĸ߼ÛֵĿµÄ £¬ £¬£¬£¬ £¬²¢°²ÅÅ»ùÓÚ AutoHotKey (AHK) µÄ»úеÈË¡£¡£¡£¡£¡£¡£¡£


4. VF CorpÈ¥Äê12Ô·ݵÄÊý¾Ýй¶ÊÂÎñÓ°ÏìÖÁÉÙ3550Íò¿Í»§


1ÔÂ20ÈÕ £¬ £¬£¬£¬ £¬VF Corporation ÊÇÒ»¼ÒÃÀ¹úÈ«Çò´ò°çºÍЬÀ๫˾ £¬ £¬£¬£¬ £¬ÓµÓÐ 13 ¸öÆ·ÅÆ¡£¡£¡£¡£¡£¡£¡£2015Äê £¬ £¬£¬£¬ £¬¸Ã¹«Ë¾ÒÀ¸½JanSport¡¢Dickies¡¢Eastpak¡¢Timberland¡¢Smartwool¡¢VansºÍThe North FaceÆ·ÅÆ¿ØÖÆÁËÃÀ¹ú±³°üÊг¡55%µÄ·Ý¶î¡£¡£¡£¡£¡£¡£¡£2023 Äê 12 Ô £¬ £¬£¬£¬ £¬VF Corp Ðû²¼³ÉΪÀÕË÷Èí¼þ¹¥»÷µÄÊܺ¦Õß £¬ £¬£¬£¬ £¬±»ÆÈ¹Ø±Õ²¿·ÖϵͳÒÔ×èÖ¹Íþв¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ £¬ £¬£¬£¬ £¬¸Ã¹«Ë¾È·ÈϹ¥»÷ÕßÇÔÈ¡ÁËÓ°Ïì 3550 Íò¿Í»§µÄ¹«Ë¾ºÍСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£2023 Äê 12 Ô 13 ÈÕ £¬ £¬£¬£¬ £¬VF Corp ¼ì²âµ½¶ÔÆä²¿·Ö»ù´¡ÉèÊ©¾ÙÐÐδ¾­ÊÚȨµÄ»á¼û¡£¡£¡£¡£¡£¡£¡£VF Á¬Ã¦×îÏȽÓÄɲ½·¥ÐÞ¸´´Ë´Î¹¥»÷ £¬ £¬£¬£¬ £¬²¢¶ÔÇå¾²Îó²îÕö¿ªÊӲ졣¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ö¸³ö £¬ £¬£¬£¬ £¬ËüµÄϵͳÖÐûÓд洢Éç»áÇå¾²ºÅÂëºÍ²ÆÎñÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£VF Corp »¹Ôö²¹Ëµ £¬ £¬£¬£¬ £¬Ã»Óз¢Ã÷¿Í»§ÃÜÂë±»µÁµÄÖ¤¾Ý¡£¡£¡£¡£¡£¡£¡£Ä³Ð©ÏµÍ³¹Ø±Õºó £¬ £¬£¬£¬ £¬VF µÄÔËÓªÓöµ½ÁËÖÐÖ¹¡£¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñÖÐÖ¹ÁËÁãÊÛÊÐËÁµÄ¿â´æÔö²¹²¢ÑÓ³ÙÁ˶©µ¥ÍÆÐС£¡£¡£¡£¡£¡£¡£ÕâЩÎÊÌâµ¼Ö¿ͻ§ºÍÏûºÄÕß×÷·Ï²úÆ·¶©µ¥¡¢Ä³Ð©Æ·ÅƵç×ÓÉÌÎñÍøÕ¾µÄÐèÇóïÔÌ­ÒÔ¼°Ò»Ð©Åú·¢·¢»õµÄÑÓ³Ù¡£¡£¡£¡£¡£¡£¡£


5. OutlookÎó²îCVE-2023-35636¿Éµ¼ÖÂNTLM v2ÃÜÂëй¶


1ÔÂ18ÈÕ £¬ £¬£¬£¬ £¬ÔÚ×î½üµÄÒ»Ïî·¢Ã÷ÖÐ £¬ £¬£¬£¬ £¬Varonis ÍþвʵÑéÊÒÐû²¼ÁËÍøÂç¹¥»÷Õß¿ÉʹÓõÄÈýÖÖÐÂÒªÁìÀ´»á¼û NTLM v2 ¹þÏ£ÃÜÂë £¬ £¬£¬£¬ £¬´Ó¶øÊ¹ÎÞÊýϵͳºÍÓû§Êý¾ÝÃæÁÙΣº¦¡£¡£¡£¡£¡£¡£¡£ÔÚÕâЩÎó²îÖÐ £¬ £¬£¬£¬ £¬ÓÐÒ»¸öÌØÊâÑÏÖØ£ºCVE-2023-35636 £¬ £¬£¬£¬ £¬ÕâÊÇÒ»ÖÖй¶Ãô¸ÐÐÅÏ¢µÄ Outlook Îó²î¡£¡£¡£¡£¡£¡£¡£CVE-2023-35636 ÊÇ Microsoft Outlook Öз¢Ã÷µÄÒ»¸öÇå¾²Îó²î £¬ £¬£¬£¬ £¬ÌØÊâÊÇÔÚÈÕÀú¹²Ïí¹¦Ð§ÖС£¡£¡£¡£¡£¡£¡£´ËÎó²îʹ¹¥»÷ÕßÄܹ»×èµ² NTLM v2 ¹þÏ£Öµ £¬ £¬£¬£¬ £¬¸Ã¹þÏ£ÖµÓÃÓÚ Microsoft Windows ϵͳÖеÄÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£¡£¡£NTLM v2 ËäÈ»±ÈÆäǰÉí¸üÇå¾² £¬ £¬£¬£¬ £¬µ«ÈÔÈ»ÈÝÒ×Êܵ½ÀëÏß±©Á¦ºÍÉí·ÝÑéÖ¤Öм̹¥»÷¡£¡£¡£¡£¡£¡£¡£³ýÁËOutlookÖ®Íâ £¬ £¬£¬£¬ £¬¹¥»÷Õß»¹¿ÉÒÔʹÓà Windows ÐÔÄÜÆÊÎöÆ÷ (WPA) ºÍ Windows Îļþ×ÊÔ´ÖÎÀíÆ÷À´»á¼û NTLM v2 ¹þÏ£¡£¡£¡£¡£¡£¡£¡£Í¨¹ýʹÓà URI ´¦Öóͷ£³ÌÐòºÍÌØ¶¨²ÎÊý £¬ £¬£¬£¬ £¬¹¥»÷Õß¿ÉÒÔÓÕÆ­ÕâЩӦÓóÌÐòй¶Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£


6. CISAºÍFBIÁªºÏÐû²¼WWS²¿·ÖµÄÊÂÎñÏìÓ¦Ö¸ÄÏ


1ÔÂ19ÈÕ £¬ £¬£¬£¬ £¬ÒÑÍù¼¸Äê £¬ £¬£¬£¬ £¬ÀÕË÷Èí¼þºÍδ¾­ÊÚȨµÄ»á¼ûµÈ¶ñÒâÍøÂçÊÂÎñÒѾ­Ó°ÏìÁ˹©Ë®ºÍ·ÏË®´¦Öóͷ£²¿·Ö (WWS)¡£¡£¡£¡£¡£¡£¡£ÌØÊâÊÇ £¬ £¬£¬£¬ £¬ÀÕË÷Èí¼þÊÇÍøÂç·¸·¨·Ö×ÓÕë¶Ô WWS ÊÊÓóÌÐòʹÓõij£¼ûÕ½ÂÔ¡£¡£¡£¡£¡£¡£¡£ÍøÂçÍþв¹¥»÷ÕßÃé×¼ WWS ÊÇÓÉÓÚËüÊÇÄÜÔ´¡¢Ò½ÁƱ£½¡ºÍ¹«¹²ÎÀÉúµÈÖÚ¶àÃÀ¹úÒªº¦»ù´¡ÉèÊ©²¿·ÖµÄÖ÷Òª×é³É²¿·Ö¡£¡£¡£¡£¡£¡£¡£CISA¡¢ÇéÐα£»£»£»£»£»£»¤¾Ö (EPA) ºÍÁª°îÊÓ²ì¾Ö (FBI) ÅäºÏÖÆ¶©ÁËWWS ²¿·ÖµÄЭ×÷ÊÂÎñÏìÓ¦Ö¸ÄÏ (IRG) £¬ £¬£¬£¬ £¬ÒÔÓ¦¶Ô WWS ²¿·ÖµÄÍøÂçÇå¾²ÌôÕ½¡£¡£¡£¡£¡£¡£¡£±¾Ö¸ÄÏΪ WWS ²¿·ÖµÄËùÓÐÕߺÍÔËÓªÉÌÏêϸÏÈÈÝÁËÍøÂçÊÂÎñÏìÓ¦ (IR) ÉúÃüÖÜÆÚÿ¸ö½×¶ÎµÄÁª°î½ÇÉ«¡¢×ÊÔ´ºÍÔðÈΡ£¡£¡£¡£¡£¡£¡£