¡°´«È¾ÐԲɷᱻÖÐOtterCookieÐÂÐͶñÒâÈí¼þÍþвÈí¼þ¿ª·¢ÈËÔ±

°ä²¼¹¦·ò 2024-12-27

1. ¡°´«È¾ÐԲɷᱻÖÐOtterCookieÐÂÐͶñÒâÈí¼þÍþвÈí¼þ¿ª·¢ÈËÔ±


12ÔÂ26ÈÕ£¬ £¬£¬£¬ £¬³¯ÏÊÍþвÐÐΪÕß½üÆÚÔÚÕë¶ÔÈí¼þ¿ª·¢ÈËÔ±µÄ¡°´«È¾ÐԲɷᱻÖУ¬ £¬£¬£¬ £¬ÍƳöÁËÒ»ÖÖÃûΪOtterCookieµÄÐÂÐͶñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¾ÝÍøÂ簲ȫ¹«Ë¾Palo Alto NetworksµÄ×êÑÐÈËÔ±³Æ£¬ £¬£¬£¬ £¬¸Ã»î¶¯×Ô2022Äê12ÔÂÒÔÀ´Ò»Ïò»îÔ¾£¬ £¬£¬£¬ £¬Í¨¹ýÌṩÐéαµÄ¹¤×÷»úÓö´«²¼¶ñÒâÈí¼þ£¬ £¬£¬£¬ £¬ÈçBeaverTailºÍInvisibleFerretµÈ¡£¡£¡£¡£¡£¡£¡£¶øNTT Security JapanµÄ»ã±¨Ö¸³ö£¬ £¬£¬£¬ £¬OtterCookieºÜ¿ÉÄÜÓÚ9ÔÂÍÆ³ö£¬ £¬£¬£¬ £¬²¢ÔÚ11Ô³öÏÖÁËеıäÖÖ¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þͨ¹ý¼ÓÔØÆ÷´«µÝ£¬ £¬£¬£¬ £¬»ñÈ¡JSONÊý¾Ý²¢Ö´ÐÐJavaScript´úÂ룬 £¬£¬£¬ £¬Äܹ»ÓëBeaverTailһ·²¿Êð»òµ¥¶À²¿Ê𡣡£¡£¡£¡£¡£¡£ËüÀûÓÃGitHub»òBitbucketÏÂÔØµÄNode.jsÏîÄ¿»ònpm°üϰȾָ±ê£¬ £¬£¬£¬ £¬Ò²Ê¹ÓÃÁËQt»òElectronÀûÓ÷¨Ê½¹¹½¨µÄÎļþ¡£¡£¡£¡£¡£¡£¡£Ò»µ©¼¤»î£¬ £¬£¬£¬ £¬OtterCookie¾Í»áʹÓÃSocket.IO WebSocket¹¤¾ßÓëºÅÁîºÍ½ÚÔì»ù´¡ÉèÊ©³ÉÁ¢°²È«Í¨Ñ¶£¬ £¬£¬£¬ £¬²¢Ö´ÐÐÊý¾Ý͵ÇÔµÄshellºÅÁ £¬£¬£¬ £¬Ô̺¬ÍøÂç¼ÓÃÜÇ®±ÒÇ®°üÃÜÔ¿¡¢Îĵµ¡¢Í¼ÏñµÅ×мÛÖµÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£×îа汾µÄOtterCookie»¹Äܹ»Ð¹Â¶¼ôÌù°åÊý¾Ý£¬ £¬£¬£¬ £¬²¢¼ì²âµ½ÓÃÓÚ¿úËŵĺÅÁ £¬£¬£¬ £¬Åú×¢¹¥»÷Õß³ïËã½øÐиüÉîµµ´ÎµÄÉøÈë»òºáÏòÒÆ¶¯¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-ottercookie-malware-used-to-backdoor-devs-in-fake-job-offers/


2. ÈÕº½ÔâDDoS¹¥»÷Öº½°àÑÓÎó£¬ £¬£¬£¬ £¬ÏµÍ³ÒѸ´Ô­


12ÔÂ26ÈÕ£¬ £¬£¬£¬ £¬ÈÕ±¾Æì½¢º½¿Õ¹«Ë¾ÈÕ±¾º½¿Õ(JAL)Ôâ·êÁËÒ»´ÎÍøÂ簲ȫÊÂÎñ£¬ £¬£¬£¬ £¬µ¼ÖÂÆä²¿ÃŹúÄں͹ú¼Êº½°à³öÏÖÑÓÎ󡣡£¡£¡£¡£¡£¡£ÊÂÎñÆðÒòÊÇÆäÓÃÓÚÓë±í²¿ÏµÍ³½øÐÐÊý¾ÝͨѶµÄÍøÂçÉ豸Ôâ·êÁËÉ¢²¼Ê½»Ø¾ø·þÎñ(DDoS)¹¥»÷£¬ £¬£¬£¬ £¬µ¼ÖÂϵÍÂä÷Á¿¼¤Ôö²¢³öÏÖ¹ÊÕÏ¡£¡£¡£¡£¡£¡£¡£¹¥»÷»¹Ó°ÏìÁ˳˿ÍÐÐÀîÖÎÀíϵͳºÍÒÆ¶¯ÀûÓ÷¨Ê½£¬ £¬£¬£¬ £¬µ«ÈÕº½°µÊ¾Ã»Óпͻ§ÐÅϢй¶¡¢ÍÆËã»ú²¡¶¾ÇÖº¦»ò·ÉÐа²È«ÎÊÌâ¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄϵͳÒÑÁÙʱ¹Ø¹Ø£¬ £¬£¬£¬ £¬²¢ÔÝÍ£Á˵±ÈÕÆô³ÌµÄ»úƱÏúÊۺͲ¿ÃÅÔÚÏß·þÎñ¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜÓÐ40¶à¸öº½°àÑÓÎó£¬ £¬£¬£¬ £¬µ«ÈÕº½°µÊ¾µÚ¶þÌìµÄº½°à´òËãÕý³£ÔËÐÓ×£¡£¡£¡£¡£¡£¡£º½¿ÕÒµÈÔÊÇÈ«ÇòºÚ¿ÍµÄÈȵãÖ¸±ê£¬ £¬£¬£¬ £¬´ËÇ°Ò²Ôø²úÉú¶àÆðÕë¶Ôº½¿Õ¹«Ë¾ºÍ»ú³¡µÄÍøÂç¹¥»÷ÊÂÎñ£¬ £¬£¬£¬ £¬ÕâЩϮ»÷´ó¶à³öÓÚ¾­¼Ã¶¯»ú£¬ £¬£¬£¬ £¬µ«Ò²ÓÐÕþÖζ¯»úµÄ°¸Àý¡£¡£¡£¡£¡£¡£¡£


https://therecord.media/japan-airlines-resumes-operations-after-cyberattack


3. °ÍÎ÷ºÚ¿ÍÒòÉæÏÓڲƭÀÕË÷ÔÚÃÀ¹úÔâÖ¸¿Ø


12ÔÂ26ÈÕ£¬ £¬£¬£¬ £¬Ò»Ãû°ÍÎ÷¹«ÃñJunior Barros De OliveiraÒòÉæÏÓºÚ¿ÍÈëÇÖ²¢Ú²Æ­ÀÕË÷Ò»¼ÒλÓÚÐÂÔóÎ÷µÄ¹«Ë¾¶ø±»ÃÀ¹ú˾·¨²¿¸æ×´¡£¡£¡£¡£¡£¡£¡£¾Ý¸æ×´ÊéÏÔʾ£¬ £¬£¬£¬ £¬µÂ°ÂÀûάÀ­ÓÚ2020Äê3ÔÂÈëÇÖÁ˸ù«Ë¾µÄ°ÍÎ÷×Ó¹«Ë¾ÍøÂ磬 £¬£¬£¬ £¬ÇÔÈ¡ÁËÔ¼30ÍòÃû¿Í»§µÄ»úÃÜÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£Í¬Äê9Ô£¬ £¬£¬£¬ £¬ËûʹÓû¯ÃûÏò¸Ã¹«Ë¾Ê×ϯִÐйٷ¢Ë͵ç×ÓÓʼþ£¬ £¬£¬£¬ £¬ÒªÇóÖ§¸¶300±ÈÌØ±Ò£¨µ±ÊмÛÖµÔ¼320ÍòÃÀÔª£©×÷Ϊ²»ÏúÊÛÊý¾ÝµÄǰÌá¡£¡£¡£¡£¡£¡£¡£Ò»¸öÔÂºó£¬ £¬£¬£¬ £¬ËûÓÖ½«Ò»ÑùµÄÐÅϢת·¢¸øÁ˸ù«Ë¾ÔÚ°ÍÎ÷µÄÊ×ϯִÐйٺÍÒ»Ãû¸ß¹Ü£¬ £¬£¬£¬ £¬²¢°µÊ¾Ô¸ÒâÒÔ75±ÈÌØ±Ò£¨ÆäʱԼºÏ80ÍòÃÀÔª£©µÄÕ÷ѯ·ÑÔ®ÊÖËûÃǽâ¾ö°²È«·ì϶¡£¡£¡£¡£¡£¡£¡£µÂ°ÂÀûάÀ­Òò¶ø±»Ö¸¿ØËÄÏîÉæ¼°´ÓÊܱ£»£»£»£»£» £»£»£»¤µÄÍÆËã»ú»ñÊØÐÅÏ¢µÄڲƭÀÕË÷×ïºÍËÄÏîÍþвÐÔͨѶ×ï¡£¡£¡£¡£¡£¡£¡£ÈôÊÇ×ïÃû³ÉÁ¢£¬ £¬£¬£¬ £¬Ëû½«Ãæ¶Ô×î¸ß¿É´ï20ÄêµÄ½ûïÀºÍ¸ß´ï100ÍòÃÀÔªµÄ·£¿£¿£¿£¿£¿î£¬ £¬£¬£¬ £¬»òÊÕÒæÓëËðʧ¼ÛÖµµÄÁ½±¶£¨ÒԽϸßÕßΪ׼£©¡£¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2024/12/brazilian-hacker-charged-for-extorting.html


4. ͨÓö¯Á¦¹«Ë¾ÔâÍøÂç´¹µö¹¥»÷£¬ £¬£¬£¬ £¬ÊýʮԱ¹¤¸£ÀûÕË»§±»ÈëÇÖ


12ÔÂ26ÈÕ£¬ £¬£¬£¬ £¬º½¿Õº½ÌìºÍ¹ú·À¾ÞͷͨÓö¯Á¦¹«Ë¾Ôâ·êÁËÒ»´Î³É¹¦µÄÍøÂç´¹µö¹¥»÷£¬ £¬£¬£¬ £¬µ¼ÖÂÊýÊ®¸öÔ±¹¤¸£ÀûÕË»§±»ÈëÇÖ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýµÚÈý·½ÍйܵĵǼÃÅ»§½Ó¼û²¢¸ü¸ÄÁËÔ±¹¤¸£ÀûÕË»§£¬ £¬£¬£¬ £¬ÕâЩÕË»§Ô̺¬ÁËÔ±¹¤µÄÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢µ±¾ÖÐû¸æµÄÉí·ÝÖ¤ºÅÂë¡¢Éç»á°²È«ºÅÂë¡¢ÒøÐÐÕË»§ÐÅÏ¢ºÍ²Ð¼²Çé¿öµÈÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¾ÝͨÓö¯Á¦¹«Ë¾Ð¹Â©£¬ £¬£¬£¬ £¬¹²ÓÐ37ÈËÊܵ½Ó°Ï죬 £¬£¬£¬ £¬¹¥»÷ÕßÔÚijЩÇé¿öÏ»¹¸ü¸ÄÁ˱»µÁÕË»§µÄÒøÐÐÕË»§ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£Í¨Óö¯Á¦¹«Ë¾ÔÚ·¢ÏÖÕâһδ¾­ÊÚȨµÄ»î¶¯ºóÁ¢¼´ÔÝÍ£Á˶Ը÷þÎñµÄ½Ó¼û£¬ £¬£¬£¬ £¬²¢ÏòÊÜÓ°ÏìµÄÈËÔ±ÌṩÁËÁ½ÄêµÄÃâ·ÑÐÅÓþ¼à¿Ø¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬ £¬£¬£¬ £¬Í¨Óö¯Á¦¹«Ë¾»¹ÌáÐÑÊÜÓ°ÏìµÄÓ×ÎÒ³ÁÖÃËûÃǵĸ»´ïÕË»§µÇ¼ƾ֤£¬ £¬£¬£¬ £¬²¢Ô¤·ÀÔÚ¶à¸öÕË»§ÖÐʹÓÃÒ»ÑùµÄƾ֤¡£¡£¡£¡£¡£¡£¡£½ñÄêÔçЩʱ³½£¬ £¬£¬£¬ £¬¸»´ï¹«Ë¾Ò²ÔøÔâ·ê¹ýÁ½´ÎÊý¾Ýй¶ÊÂÎñ£¬ £¬£¬£¬ £¬Ó°ÏìÁËÊýÍòÓ×ÎÒ¡£¡£¡£¡£¡£¡£¡£


https://www.securityweek.com/defense-giant-general-dynamics-says-employees-targeted-in-phishing-attack/


5. WDACÔâÀûÓ㬠£¬£¬£¬ £¬¹¥»÷Õ߿ɽûÓÃEDR´«¸ÐÆ÷·¢Æð¹¥»÷


12ÔÂ25ÈÕ£¬ £¬£¬£¬ £¬°²È«×¨¼Ò·¢ÏÖÁËÒ»ÖÖÀûÓÃWindows DefenderÀûÓ÷¨Ê½½ÚÔ죨WDAC£©µÄ¹¥»÷¼¼Êõ£¬ £¬£¬£¬ £¬Äܹ»½ûÓÃWindowsÉ豸ÉϵĶ˵ã¼ì²âºÍÏìÓ¦£¨EDR£©´«¸ÐÆ÷£¬ £¬£¬£¬ £¬Ê¹¹¥»÷Õß¿ÉÄÜÈÆ¹ý°²È«¼ì²â²¢¶Ôϵͳ·¢Æð¹¥»÷¡£¡£¡£¡£¡£¡£¡£WDACÊÇWindows 10ºÍWindows Server 2016ÒýÈëµÄ¼¼Êõ£¬ £¬£¬£¬ £¬Ö¼ÔÚ½ÚÔìWindowsÉ豸ÉϵĿÉÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»Ôì¶©ºÍ²¿ÊðרÃÅÉè¼ÆµÄWDACÕ½Êõ£¬ £¬£¬£¬ £¬×èÖ¹EDR´«¸ÐÆ÷ÔÚϵͳÆô¶¯Ê±¼ÓÔØ£¬ £¬£¬£¬ £¬Ê¹ÆäÎÞ·¨¹¤×÷¡£¡£¡£¡£¡£¡£¡£¹¥»÷·½Ê½Ô̺¬Õë¶Ôµ¥¸öÉ豸ºÍÕû¸öÓò£¬ £¬£¬£¬ £¬Õ¼ÓÐÓòÖÎÀíԱȨÏ޵Ĺ¥»÷ÕßÄܹ»ÔÚÕû¸ö×éÖ¯ÄÚ·Ö·¢¶ñÒâWDACÕ½Êõ£¬ £¬£¬£¬ £¬ÏµÍ³ÐԵؽûÓÃËùÓж˵ãÉϵÄEDR´«¸ÐÆ÷¡£¡£¡£¡£¡£¡£¡£¹¥»÷Éæ¼°Õ½Êõ¸éÖᢳÁÆôÖն˺ͽûÓÃEDRÈý¸öÖØÒª½×¶Î¡£¡£¡£¡£¡£¡£¡£°²È«ÈËÔ±´´½¨ÁË¡°Krueger¡±¸ÅÏëÑéÖ¤¹¤¾ßÀ´¼ì²âÕâÖÖ¹¥»÷¡£¡£¡£¡£¡£¡£¡£»£»£»£»£» £»£»£»º½âÕ½ÊõÔ̺¬Í¨¹ýGPOÖ´ÐÐWDACÕ½Êõ¡¢ÀûÓÃ×îÓ×ȨÏÞ×¼ÔòºÍÖ´Ðа²È«µÄÖÎÀíʵ¼Ê¡£¡£¡£¡£¡£¡£¡£Ãæ¶ÔгöÏֵĹ¥»÷¼¼Êõ£¬ £¬£¬£¬ £¬±ØÒª²ÉÈ¡¶àµµ´ÎµÄÍøÂ簲ȫ²½Ö裬 £¬£¬£¬ £¬²¢Ê±¿Ìά³Ö¾¯Ìè¡£¡£¡£¡£¡£¡£¡£


https://cybersecuritynews.com/attack-weaponizes-windows-defender/#google_vignette


6. ΢ÈíÖҸ棺ʹÓÃýÌå×°ÖÃWindows 11 24H2¿ÉÖÂÎÞ·¨½Ó¹Ü°²È«¸üÐÂ


12ÔÂ26ÈÕ£¬ £¬£¬£¬ £¬Î¢Èí·¢³öÖҸ棬 £¬£¬£¬ £¬Ö¸³öʹÓÃýÌåÖ§³Ö×°ÖÃWindows 11°æ±¾24H2ʱ´æÔÚÒ»¸öÎÊÌ⣬ £¬£¬£¬ £¬¿ÉÄܵ¼Ö²Ù×÷ϵͳÎÞ·¨½ÓÊܽøÒ»²½µÄ°²È«¸üС£¡£¡£¡£¡£¡£¡£¾ßÌå¶øÑÔ£¬ £¬£¬£¬ £¬ÔÚ2024Äê10ÔÂ8ÈÕÖÁ11ÔÂ12ÈÕÆÚ¼ä£¬ £¬£¬£¬ £¬Ê¹ÓÃCDºÍUSBÉÁ´æÇý¶¯Æ÷×°ÖÃÔ̺¬´ËÆÚ¼ä°²È«¸üеÄWindows 11°æ±¾24H2ʱ£¬ £¬£¬£¬ £¬É豸¿ÉÄÜ»áÏÝÈëÎÞ·¨½ÓÊܺóÐøWindows°²È«¸üеÄ״̬¡£¡£¡£¡£¡£¡£¡£²»Í⣬ £¬£¬£¬ £¬Õâ¸ö·ì϶²»»áÓ°Ïìͨ¹ýWindows¸üлòMicrosoft¸üÐÂÄ¿Â¼ÍøÕ¾ÀûÓõݲȫ¸üУ¬ £¬£¬£¬ £¬Ò²²»»áÔÚʹÓÃ×îеÄ2024Äê12Ô°²È«¸üÐÂʱ³öÏÖ¡£¡£¡£¡£¡£¡£¡£Î¢ÈíÔÚÖÂÁ¦ÓÚÓÀÔ¶½¨¸´´ËÎÊÌ⣬ £¬£¬£¬ £¬²¢½¨ÒéʹÓûùÓÚýÌåµÄWindows 11 24H2×°ÖõÄÓû§ÀûÓÃ2024Äê12ÔÂ10ÈÕ°ä²¼µÄ°²È«¸üУ¬ £¬£¬£¬ £¬ÒÔÔ¤·ÀºóÐø¸üÐÂÎÊÌâ¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬ £¬£¬£¬ £¬Windows 11 24H2»¹Ãæ¶Ô×ÅһϵÁÐÆäËûÎÊÌ⣬ £¬£¬£¬ £¬Ô̺¬ÒôƵÎÊÌâ¡¢ÓÎÏ·»úÄÜÎÊÌâ¡¢±ÀÀ£ºÍËÀ»úµÈ£¬ £¬£¬£¬ £¬ÉõÖÁÔÚÌØ¶¨µÄÓ²¼þºÍÈí¼þÅäÖÃÉϱ»ÁÙʱ×èÖ¹¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/windows-11-installation-media-bug-causes-security-update-failures/