Nitrogen¼Ù×°³É PuTTY »ò FileZilla ²¿ÊðBlackCat
°ä²¼¹¦·ò 2024-04-114ÔÂ9ÈÕ£¬£¬£¬£¬£¬×î³õµÄÈëÇÖÊÇ´Óͨ¹ý Google ËÑË÷ÏÔʾµÄ¶ñÒâ¸æ°×ÆðÍ·µÄ¡£¡£¡£¡£¡£¡£¡£ÎÒÃǹ۲쵽Á˼¸¸ö·ÖÆçµÄ¸æ°×¿Í»§ÕÊ»§£¬£¬£¬£¬£¬ÕâЩÕÊ»§¶¼»ã±¨¸øÁ˹ȸ衣¡£¡£¡£¡£¡£¡£ÕâЩµö¶üÊÇ IT ÖÎÀíÔ±³£ÓõÄʵÓ÷¨Ê½£¬£¬£¬£¬£¬ÀýÈç PuTTY ºÍ FileZilla¡£¡£¡£¡£¡£¡£¡£Nitrogen ÍþвÐÐΪÕß²¿ÊðµÄ¶ñÒâ¸æ°×»ù´¡ÉèʩʹÓüÙ×°Ò³Ãæ£¬£¬£¬£¬£¬¸ÃÒ³ÃæÄܹ»³Á¶¨Ïòµ½µö¶üÍøÕ¾»ò³ôÃûÔ¶ÑïµÄ Rick Astley ÊÓÆµ¡£¡£¡£¡£¡£¡£¡£ÈôÊǻÉÐδ±øÆ÷»¯»ò¶ñÒâ·þÎñÆ÷¼ì²âµ½ÎÞЧÁ÷Á¿£¨»úеÈË¡¢ÅÀ³æµÈ£©£¬£¬£¬£¬£¬ÔòÄܹ»¼¤»îµ½µö¶üÒ³ÃæµÄ³Á¶¨Ïò¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâ¸æ°×Á´µÄ×îºóÒ»²½Ô̺¬ÏÂÔØ²¢ÔËÐжñÒâÈí¼þÓÐЧ¸ºÔØ¡£¡£¡£¡£¡£¡£¡£Nitrogen ʹÓÃÒ»ÖÖ³ÆÎª DLL ÅÔ¼ÓÔØµÄ¼¼Êõ£¬£¬£¬£¬£¬Í¨¹ý¸Ã¼¼Êõ£¬£¬£¬£¬£¬ºÏ·¨ÇÒ¾¹ýÊðÃûµÄ¿ÉÖ´ÐÐÎļþ»áÆô¶¯ DLL¡£¡£¡£¡£¡£¡£¡£ÔÚ±¾ÀýÖУ¬£¬£¬£¬£¬setup.exe£¨À´×Ô Python Software Foundation£©²àÔØpython311.dll (Nitrogen)¡£¡£¡£¡£¡£¡£¡£
https://www.malwarebytes.com/blog/threat-intelligence/2024/04/active-nitrogen-campaign-delivered-via-malicious-ads-for-putty-filezilla
2. ΢Èí½¨¸´ÁË Windows Á½¸öÒѾ±»ÀûÓõÄÁãÈÕ·ì϶
4ÔÂ9ÈÕ£¬£¬£¬£¬£¬Î¢ÈíÔÚ 2024 Äê 4 ÔµIJ¹¶¡ÐÇÆÚ¶þÆÚ¼ä½¨¸´ÁËÁ½¸ö±»»ý¼«ÀûÓõÄÁãÈÕ·ì϶£¬£¬£¬£¬£¬Ö»¹Ü¸Ã¹«Ë¾×î³õδÄܶÔËüÃǽøÐÐÏóÕ÷¡£¡£¡£¡£¡£¡£¡£µÚÒ»¸ö·ì϶±»¸ú×ÙΪCVE-2024-26234£¬£¬£¬£¬£¬±»ÃèÊöΪ´úÀíÇý¶¯·¨Ê½ºýŪ·ì϶£¬£¬£¬£¬£¬Ö¼ÔÚ¸ú×٠ʹÓÃÓÐЧµÄ Microsoft Ó²¼þ¿¯ÐÐÉÌÖ¤ÊéÊðÃûµÄ¶ñÒâÇý¶¯·¨Ê½£¬£¬£¬£¬£¬¸Ã¶ñÒâÎļþ±»¡°Catalog Thales¡±ÏóÕ÷Ϊ¡°Catalog Authentication Client Service¡±£¬£¬£¬£¬£¬¿ÉÄÜÊÇÊÔͼ¼ÙÒâ Thales Group¡£¡£¡£¡£¡£¡£¡£µÚ¶þ¸öÁãÈÕ·ì϶±»×·×ÙΪCVE-2024-29988£¬£¬£¬£¬£¬±»ÃèÊöΪÓɱ£»£»£»£»£»£»£»£»¤»úÔì¹ÊÕÏÈõµãµ¼ÖµÄSmartScreenÌáÐѰ²È«Ö°ÄÜÈÆ¹ý·ì϶¡£¡£¡£¡£¡£¡£¡£CVE-2024-29988 ÊÇ CVE-2024-21412 ȱµãµÄÈÆ¹ý²½Ö裬£¬£¬£¬£¬ÓÉÇ÷Ïò¿Æ¼¼ÁãÈÕ´òËãµÄ Peter Girnus ÒÔ¼° Google Íþв·ÖÎöÓ××é Dmitrij Lenz ºÍ Vlad Stolyarov »ã±¨¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-two-windows-zero-days-exploited-in-malware-attacks/
3. ³¬¹ý9.1Íǫ̀ LG ÖÇÄܵçÊÓÈÝÒ×Êܵ½ºÚ¿Í¹¥»÷
4ÔÂ9ÈÕ£¬£¬£¬£¬£¬Bitdefender ×êÑÐÈËÔ±ÔÚÖÇÄܵçÊÓÉÏÔËÐÐµÄ LG webOS Öз¢ÏÖÁ˶à¸ö·ì϶£¬£¬£¬£¬£¬ÕâЩ·ì϶¿É±»ÓÃÀ´ÈƹýÊÚȨ²¢»ñµÃÉ豸µÄ root ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢Ïֵķì϶ӰÏì LG µçÊÓÉÏÔËÐÐµÄ WebOS °æ±¾ 4 ÖÁ 7¡£¡£¡£¡£¡£¡£¡£WebOS ÔÚ¶Ë¿Ú 3000/3001 (HTTP/HTTPS/WSS) ÉÏÔËÐÐÒ»Ïî·þÎñ£¬£¬£¬£¬£¬LG ThinkQ ÖÇÄÜÊÖ»úÀûÓ÷¨Ê½Ê¹Óø÷þÎñÀ´½ÚÔìµçÊÓ¡£¡£¡£¡£¡£¡£¡£ÒªÉèÖøÃÀûÓ÷¨Ê½£¬£¬£¬£¬£¬Óû§±ØÐëÔÚµçÊÓÆÁÄ»ÉÏÊäÈë PIN Âë¡£¡£¡£¡£¡£¡£¡£ÕÊ»§´¦Ö÷¨Ê½ÖеÄÃýÎóʹ¹¥»÷ÕßÄܹ»ÆëÈ«Ìø¹ý PIN ÑéÖ¤²¢´´½¨ÌØÈ¨Óû§ÅäÖÃÎļþ¡£¡£¡£¡£¡£¡£¡£Ö»¹Ü¸ÃÒ×Êܹ¥»÷µÄ·þÎñ½öÓÃÓÚ LAN ½Ó¼û£¬£¬£¬£¬£¬µ«Í¨¹ý²éÎÊ Shodan£¬£¬£¬£¬£¬ËûÃÇ·¢ÏÖÁ˳¬¹ý 91000 ¸ö½«¸Ã ·þÎñ¶³öµ½»¥ÁªÍøµÄÉ豸¡£¡£¡£¡£¡£¡£¡£´Ëʱ£¬£¬£¬£¬£¬Â¶³öµÄÉ豸ÊýÁ¿Ï÷¼õÖÁ88000¸ö¡£¡£¡£¡£¡£¡£¡£´óÎÞÊýÃæÏò»¥ÁªÍøµÄÉ豸λÓÚº«¹ú¡¢ÃÀ¹ú¡¢ÈðµäºÍ·ÒÀ¼µÈ¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/161651/hacking/lg-smart-tvs-vulnerable.html
4. GHC-SCW³ÆÀÕË÷Èí¼þÍÅ»ïÇÔÈ¡ÁËÆä53ÍòÈ˵Ľ¡È«Êý¾Ý
4ÔÂ9ÈÕ£¬£¬£¬£¬£¬Íþ˹¿µÐÇÖÝÖÐÄϲ¿·ÇͶ»úÐÔÒ½ÁÆ·þÎñÌṩÉÌ Group Health Cooperative (GHC-SCW) Åû¶£¬£¬£¬£¬£¬ÀÕË÷Èí¼þÍÅ»ïÓÚ 1 Ô·ÝÇÖÈëÆäÍøÂ磬£¬£¬£¬£¬ÇÔÈ¡ÁËÔ̺¬³¬¹ý 50 ÍòÈ˵ÄÓ×ÎÒºÍÒ½ÁÆÐÅÏ¢µÄÎļþ¡£¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬¹¥»÷ÕßÎÞ·¨¼ÓÃÜÊÜϰȾµÄÉ豸£¬£¬£¬£¬£¬ÕâʹµÃ GHC-SCW ÔÚ±í²¿ÍøÂçÊÂÎñÏìӦר¼ÒµÄÔ®ÊÖϱ£»£»£»£»£»£»£»£»¤Æäϵͳ£¬£¬£¬£¬£¬²¢ÔÚ¸ôÀëÕâЩÉ豸ÒÔ¶ôÔì·ì϶ºó½«Æä¸´ÔÔÚÏß¡£¡£¡£¡£¡£¡£¡£Ò»Ô·ÝÀÕË÷Èí¼þ¹¥»÷ÆÚ¼ä±»µÁµÄ½¡È«Êý¾ÝÔ̺¬ÊÜÓ°ÏìÓ×ÎÒµÄÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·¡¢µ®ÉúºÍ/»òéæÃüÈÕÆÚ¡¢Éç»á°²È«ºÅÂë¡¢»áÔ±ºÅÂëÒÔ¼°Ò½ÁƱ£ÏÕºÍ/»òÒ½ÁƲ¹ÖúºÅÂë¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜûÓÐÌṩÊÜÓ°ÏìÈËÊýµÄ¾ßÌåÊý×Ö£¬£¬£¬£¬£¬µ«ÓëÃÀ¹úÎÀÉúÓ빫¼Ò·þÎñ²¿¹²ÏíµÄÆäËûÐÅÏ¢ÏÔʾ£¬£¬£¬£¬£¬Êý¾Ýй¶ӰÏìÁË 533809 ÈË¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/ghc-scw-ransomware-gang-stole-health-data-of-533-000-people/
5. BatBadBut Rust ·ì϶ʹ Windows ÏµÍ³Ãæ¶Ô¹¥»÷
4ÔÂ10ÈÕ£¬£¬£¬£¬£¬Rust ³ß¶È¿âÖеÄÒ»¸ö¹Ø¼ü°²È«·ì϶¿ÉÄܻᱻÀûÓÃÀ´Õë¶Ô Windows Óû§²¢ÌáÒéºÅÁî×¢Èë¹¥»÷¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶µÄ±àºÅΪCVE-2024-24576£¬£¬£¬£¬£¬CVSS ÆÀ·ÖΪ 10.0£¬£¬£¬£¬£¬Åú×¢ÑϳÁˮƽ×î¸ß¡£¡£¡£¡£¡£¡£¡£Ò²¾ÍÊÇ˵£¬£¬£¬£¬£¬Ëü½öÓ°ÏìÔÚ Windows ÉÏʹÓò»ÊÜÐÅÀµµÄ²ÎÊýŲÓÃÅú´¦ÖÃÎļþµÄ³¡¾°¡£¡£¡£¡£¡£¡£¡£Rust °²È«ÏìÓ¦¹¤×÷×éÔÚ 2024 Äê 4 Ô 9 ÈÕ°ä²¼µÄ²¼¸æÖаµÊ¾£ºÔÚ Windows ÉÏʹÓà Command API ŲÓÃÅú´¦ÖÃÎļþ£¨´øÓÐ bat ºÍ cmd À©´óÃû£©Ê±£¬£¬£¬£¬£¬Rust ³ß¶È¿âûÓÐÕýȷתÒå²ÎÊý¡£¡£¡£¡£¡£¡£¡£¿ÉÄܽÚÔì´«µÝ¸øÌìÉú¹ý³ÌµÄ²ÎÊýµÄ¹¥»÷ÕßÄܹ»Í¨¹ýÈÆ¹ýתÒåÀ´Ö´ÐÐËÁÒâ shell ºÅÁî¡£¡£¡£¡£¡£¡£¡£¸ÃȱµãÓ°Ïì 1.77.2 ֮ǰµÄËùÓÐ Rust °æ±¾¡£¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2024/04/critical-batbadbut-rust-vulnerability.html
6. Medusa ÍÅ»ï³Æ¶ÔµÂ¿ËÈøË¹ÖÝijµ±¾Ö»ú¹¹µÄ¹¥»÷ÕÆ¹Ü
4ÔÂ9ÈÕ£¬£¬£¬£¬£¬ËþÀ¼ÌØÏØÆÀ¹ÀÇø£¨Tarrant County Appraisal District£©ÕƹÜÈ·¶¨ÎÖ˹±¤µØÓòÓÃÓÚ˰ÊÕÖ÷Õŵķ¿µØ²ú£¬£¬£¬£¬£¬Á½ÖÜǰÏò Recorded Future News ֤ʵ£¬£¬£¬£¬£¬¸ÃÏØÊÇÀÕË÷Èí¼þ¹¥»÷µÄÊܺ¦Õß¡£¡£¡£¡£¡£¡£¡£ÖÜÒ»£¬£¬£¬£¬£¬Medusa ÍøÂç·¸×ïÍÅ»ïÐû³Æ¶ÔÕâÆðÊÂÎñÕÆ¹Ü£¬£¬£¬£¬£¬²¢Íþв³Æ£¬£¬£¬£¬£¬ÈôÊDz»Ö§¸¶ 10 ÍòÃÀÔªµÄÊê½ð£¬£¬£¬£¬£¬ËûÃǽ«ÔÚÁùÌìÄÚ¹«¿ª½ü 218 GB µÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£ÏعÙԱûÓлØÓ¦ÓйØÊÇ·ñÖ§¸¶Êê½ðµÄÖÃÆÀÒªÇ󣬣¬£¬£¬£¬µ«ËûÃÇÓÚ 4 Ô 3 ÈÕ°ä²¼ÖÒ¸æ³Æ£¬£¬£¬£¬£¬ºÚ¿Í¹«¿ªÁËÔ¼ 300 È˵ÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯ÓÚ 2023 Äê³õ´Î³öÏÖ£¬£¬£¬£¬£¬ÆäÊܺ¦ÕßÃûµ¥Ñ¸ËÙÀ©´ó¡£¡£¡£¡£¡£¡£¡£ÃÀ¶ÅɯÒò¶Ô·áÌïºÍ¼ÓÄôóÁ½¼Ò×î´óÒøÐеĹ¥»÷¶ø³ÉΪͷÌõÐÂÎÅ¡£¡£¡£¡£¡£¡£¡£
https://therecord.media/tarrant-county-texas-ransomware-attack-medusa


¾©¹«Íø°²±¸11010802024551ºÅ