S¨¹dwestfalen IT±»ºÚµ¼Öµ¹ú70¶à¸ö³ÇÊеÄϵͳ崻ú

°ä²¼¹¦·ò 2023-11-03

1¡¢S¨¹dwestfalen IT±»ºÚµ¼Öµ¹ú70¶à¸ö³ÇÊеÄϵͳ崻ú


¾ÝýÌå11ÔÂ1ÈÕ±¨Â·£¬£¬£¬£¬ £¬·þÎñÌṩÉÌS¨¹dwestfalen ITÔâµ½ÀÕË÷¹¥»÷£¬£¬£¬£¬ £¬µ¼Öµ¹ú70¶à¸ö³ÇÊеÄÊÐÕþϵͳ崻ú¡£¡£¡£¡£¡£¡£¡£¡£±¾ÖÜÒ»£¬£¬£¬£¬ £¬¸Ã·þÎñÌṩÉ̵Äϵͳ±»¼ÓÃÜ¡£¡£¡£¡£¡£¡£¡£¡£ÎªÁËÔ¤·À¶ñÒâÈí¼þ´«²¼£¬£¬£¬£¬ £¬¸Ã¹«Ë¾ÖжÏÁË70¶à¸ö³ÇÊÐ¶ÔÆä»ù´¡ÉèÊ©µÄ½Ó¼û£¬£¬£¬£¬ £¬ÖØÒªÓ°ÏìÁ˵¹úÎ÷²¿µÄ±±À³Òð-ÍþË¹ÌØ·¨Â×ÖÝ¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷µ±Ì죬£¬£¬£¬ £¬µÂ¹úÎý¸ùÊе±¾ÖÈ¡µÞÁ˹«ÃñµÄÔ¤Ô¼£¬£¬£¬£¬ £¬½ØÖÁ±¾Öܶþ£¬£¬£¬£¬ £¬¸ÃÊе±¾ÖµÄ´ó²¿ÃÅÔÚÏß·þÎñÈÔÎÞ·¨Ê¹Óᣡ£¡£¡£¡£¡£¡£¡£Î¤Ã·¶û˹»ùÐ˺Ͳ¼¶ûɳÒÁµÂÊе±¾ÖµÄÍøÕ¾Ò²ÔÚÖÜÈý¹Ø¹Ø¡£¡£¡£¡£¡£¡£¡£¡£µÂ¹ú¾¯·½ºÍ°²È«»ú¹¹ÔÚµ÷²éÕâÆðÊÂÎñ£¬£¬£¬£¬ £¬²¢ÖÂÁ¦¸´Ô­³ÇÊÐÖÎÀí²¿ÃŵķþÎñ¡£¡£¡£¡£¡£¡£¡£¡£


https://therecord.media/massive-cyberattack-hinders-services-in-germany


2¡¢Êý¾ÝÖÐÐÄÍ£µçµ¼ÖÂCloudflare¶à¸ö²úÆ·ÁÙʱÎÞ·¨Ê¹ÓÃ


¾Ý11ÔÂ2ÈÕ±¨Â·£¬£¬£¬£¬ £¬CloudflareÖжϵ¼ÖÂÆäºÜ¶à²úÆ·ÎÞ·¨Ê¹Óᣡ£¡£¡£¡£¡£¡£¡£Cloudflare°µÊ¾£¬£¬£¬£¬ £¬Õâ¸öÎÊÌâÓ°ÏìÁËËùÓÐÒÀÀµÆäAPI»ù´¡ÉèÊ©µÄ·þÎñ£¬£¬£¬£¬ £¬Ô̺¬½ÚÔìÃæ°å¡¢Cloudflare API¡¢LogpushºÍAlert Notification SystemµÈ¡£¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿Í»§ÔÚ³¢ÊԵǼÕÊ»§²¢½Ó¼ûCloudflare½ÚÔìÃæ°åʱ£¬£¬£¬£¬ £¬»á¿´µ½¡°Code:10000¡±Éí·ÝÑéÖ¤ÃýÎóºÍÄÚ²¿·þÎñÆ÷ÃýÎ󡣡£¡£¡£¡£¡£¡£¡£ÖжÏÁ½Ó×ʱºó£¬£¬£¬£¬ £¬¸Ã¹«Ë¾Ð¹Â©£¬£¬£¬£¬ £¬ÕâÊǶà¸öÊý¾ÝÖÐÐÄÍ£µçµ¼Öµġ£¡£¡£¡£¡£¡£¡£¡£µ××ÓÔ­ÒòÊÇ·¢µç»ú¹ÊÕϵ¼ÖµÄÇøÓòÐÔµçÁ¦ÎÊÌ⣬£¬£¬£¬ £¬Ôì³ÉÉ豸ÍÑ»ú¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬ £¬´ó²¿ÃÅ·þÎñ¶¼ÒѸ´Ô­¡£¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/cloudflare-dashboard-and-apis-down-after-data-center-power-outage/


3¡¢Advarra¹«Ë¾Ôâµ½AlphVÀÕË÷¹¥»÷³¬¹ý120 GBÊý¾Ýй¶


ýÌå11ÔÂ1Èճƣ¬£¬£¬£¬ £¬Ò½ÁÆ×ۺϽâ¾ö¹æ»®¹«Ë¾AdvarraÔâµ½ÁËÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬ £¬¹¥»÷²úÉúÓÚ10ÔÂ25ÈÕ×óÓÒ£¬£¬£¬£¬ £¬¹«Ë¾ÖÎÀíÈËÔ±°µÊ¾»Ø¾ø½»Êê½ð£¬£¬£¬£¬ £¬Ò²²»Óë¹¥»÷Õß½»Éæ¡£¡£¡£¡£¡£¡£¡£¡£10ÔÂ31ÈÕ£¬£¬£¬£¬ £¬¹¥»÷ÕßÔÚAlphVÍøÕ¾ÉÏÁгöÁ˸ù«Ë¾£¬£¬£¬£¬ £¬Ðû³ÆÒÑÇÔÈ¡Á˳¬¹ý120GBÊý¾Ý£¬£¬£¬£¬ £¬Éæ¼°¿Í»§¡¢»¼ÕßÒÔ¼°Ô±¹¤¡£¡£¡£¡£¡£¡£¡£¡£Advarra°µÊ¾£¬£¬£¬£¬ £¬¹¥»÷Ô´ÓÚÒ»ÃûÔ±¹¤µÄµç»°ºÅÂë±»µÁ£¬£¬£¬£¬ £¬¹¥»÷Õß½è´Ë½Ó¼ûÁ˸ÃÔ±¹¤µÄһЩÕË»§£¬£¬£¬£¬ £¬Ô̺¬LinkedInºÍ¹¤×÷ÕË»§¡£¡£¡£¡£¡£¡£¡£¡£


https://www.databreaches.net/exclusive-advarra-hacked-threat-actors-threatening-to-leak-data/


4¡¢VMware·¢ÏÖÊýÊ®¸öÄÚºËÇý¶¯·¨Ê½ÈÝÒ×Ôâµ½ÍøÂç¹¥»÷


VMware Carbon Black TAUÔÚ10ÔÂ31ÈÕ³ÆÆä·¢ÏÖÁË34¸öÒ×±»¹¥»÷µÄÄÚºËÇý¶¯·¨Ê½£¨30¸öWDMºÍ4¸öWDF£©¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖÐ6¸öÄܹ»ÓÃÀ´½Ó¼ûÄÚºËÄڴ棬£¬£¬£¬ £¬ËùÓÐÇý¶¯·¨Ê½¶¼¿É±»ÓµÓзÇϵͳȨÏ޵Ĺ¥»÷ÕßÓÃÓÚÆëÈ«½ÚÔìÉ豸¡£¡£¡£¡£¡£¡£¡£¡£Í¨¹ýÀûÓÃÕâЩÇý¶¯·¨Ê½£¬£¬£¬£¬ £¬¹¥»÷ÕßÄܹ»²Á³ý»ò¸ü¸Ä¹Ì¼þ£¬£¬£¬£¬ £¬ÒÔ¼°ÌáÉýȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩÇý¶¯µÄ¿ª·¢ÈËÔ±ÒÑÓÚ2023Äê´º¼¾ÊÕµ½Í¨Öª£¬£¬£¬£¬ £¬µ«Ö»ÓÐÁ½¼Ò¹«Ë¾½¨¸´ÁË·ì϶¡£¡£¡£¡£¡£¡£¡£¡£VMwareÕë¶Ô¶à¸öÇý¶¯·¨Ê½¿ª·¢ÁËPoC·ì϶£¬£¬£¬£¬ £¬ÒÔÑÝʾÈôºÎÀûÓÃËüÃÇÀ´²Á³ý¹Ì¼þ»òÌáÉýȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£


https://blogs.vmware.com/security/2023/10/hunting-vulnerable-kernel-drivers.html


5¡¢Unit 42°ä²¼¹ØÓÚTurlaµÄºóÃÅKazuarбäÌåµÄ»ã±¨


10ÔÂ31ÈÕ£¬£¬£¬£¬ £¬Unit 42°ä²¼Á˹ØÓÚTurlaºóÃÅKazuarµÄбäÌåµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£¡£KazuarÊÇÒ»¸ö.NETºóÃÅ£¬£¬£¬£¬ £¬×÷ΪTurlaµÄµÚ¶þ½×¶ÎpayloadÓëÆäËü³£Óù¤¾ßһ·ʹÓᣡ£¡£¡£¡£¡£¡£¡£ÔÚа汾ÖУ¬£¬£¬£¬ £¬¹¥»÷ÕßʹÓÃÁ˸÷ÀิÔӵķ´·ÖÎö¼¼Êõ£¬£¬£¬£¬ £¬²¢Í¨¹ýÓÐЧµÄ¼ÓÃܺͻìºÏÀ´±£»£» £»£» £»¤¶ñÒâÈí¼þ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£KazuarµÄÐÂÖ°ÄÜÔ̺¬£º¸üÈ«ÃæµÄϵͳ·ÖÎö£¬£¬£¬£¬ £¬ÇÔÈ¡ÔÆÀûÓ÷¨Ê½ºÍÐźÅÐÂÎÅÀûÓ÷¨Ê½£¬£¬£¬£¬ £¬Ö§³Ö45¸öºÅÁ£¬£¬£¬ £¬¹¥»÷Õ߿ɿªÆô/¹Ø¹ØÒ»ÏµÁÐ×Ô¶¯»¯¹¤×÷£¬£¬£¬£¬ £¬ÊµÏÖ·ÖÆçµÄ¼ÓÃÜËã·¨ºÍ¹æ»®£¬£¬£¬£¬ £¬ÒÔ¼°ÓµÓжàÖÖ×¢Èëģʽ¡£¡£¡£¡£¡£¡£¡£¡£


https://unit42.paloaltonetworks.com/pensive-ursa-uses-upgraded-kazuar-backdoor/


6¡¢HP°ä²¼2023ÄêµÚÈý¼¾¶ÈÍøÂç°²È«Ì¬ÊÆµÄ·ÖÎö»ã±¨


10ÔÂ31ÈÕ£¬£¬£¬£¬ £¬HP°ä²¼ÁË2023ÄêµÚÈý¼¾¶ÈÍøÂç°²È«Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÔÚQ3³ÖÐøÀûÓÃliving-off-the-land¹¥»÷Õ½Êõ£¬£¬£¬£¬ £¬Í¨¹ýWindowsÄÚÖõŤ¾ßÖ´Ðй¥»÷¡£¡£¡£¡£¡£¡£¡£¡£ÀûÓÃExcel²å¼þ(XLL)ÎļþµÄ»î¶¯¼¤Ôö£¬£¬£¬£¬ £¬ÔÚ¹¥»÷Õß×î³£ÓõÄÎļþÀ©´óÃûÖУ¬£¬£¬£¬ £¬ÆôÓúêµÄExcel²å¼þ¶ñÒâÈí¼þ´ÓQ2µÄµÚ46λÉÏÉýµ½µÚ7λ¡£¡£¡£¡£¡£¡£¡£¡£HP»¹·¢ÏÖÁËÒ»¸öÕë¶ÔÀ­¶¡ÃÀÖ޾ƵêµÄ¹¥»÷»î¶¯£¬£¬£¬£¬ £¬Ê¹ÓÃÁËÆôÓúêµÄPowerPoint²å¼þ¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹ÔÚGitHubÉÏÍйÜαÔìµÄRAT£¬£¬£¬£¬ £¬ÊÔͼÓÕÆ­²»×ã¾­ÑéµÄºÚ¿ÍϰȾËûÃÇ×Ô¼ºµÄPC¡£¡£¡£¡£¡£¡£¡£¡£


https://threatresearch.ext.hp.com/hp-wolf-security-threat-insights-report-q3-2023/