¡°´«È¾ÐԲɷᱻÖÐOtterCookieÐÂÐͶñÒâÈí¼þÍþвÈí¼þ¿ª·¢ÈËÔ±
°ä²¼¹¦·ò 2024-12-271. ¡°´«È¾ÐԲɷᱻÖÐOtterCookieÐÂÐͶñÒâÈí¼þÍþвÈí¼þ¿ª·¢ÈËÔ±
12ÔÂ26ÈÕ£¬£¬£¬£¬£¬³¯ÏÊÍþвÐÐΪÕß½üÆÚÔÚÕë¶ÔÈí¼þ¿ª·¢ÈËÔ±µÄ¡°´«È¾ÐԲɷᱻÖУ¬£¬£¬£¬£¬ÍƳöÁËÒ»ÖÖÃûΪOtterCookieµÄÐÂÐͶñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¾ÝÍøÂ簲ȫ¹«Ë¾Palo Alto NetworksµÄ×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬¸Ã»î¶¯×Ô2022Äê12ÔÂÒÔÀ´Ò»Ïò»îÔ¾£¬£¬£¬£¬£¬Í¨¹ýÌṩÐéαµÄ¹¤×÷»úÓö´«²¼¶ñÒâÈí¼þ£¬£¬£¬£¬£¬ÈçBeaverTailºÍInvisibleFerretµÈ¡£¡£¡£¡£¡£¡£¡£¶øNTT Security JapanµÄ»ã±¨Ö¸³ö£¬£¬£¬£¬£¬OtterCookieºÜ¿ÉÄÜÓÚ9ÔÂÍÆ³ö£¬£¬£¬£¬£¬²¢ÔÚ11Ô³öÏÖÁËеıäÖÖ¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þͨ¹ý¼ÓÔØÆ÷´«µÝ£¬£¬£¬£¬£¬»ñÈ¡JSONÊý¾Ý²¢Ö´ÐÐJavaScript´úÂ룬£¬£¬£¬£¬Äܹ»ÓëBeaverTailһ·²¿Êð»òµ¥¶À²¿Ê𡣡£¡£¡£¡£¡£¡£ËüÀûÓÃGitHub»òBitbucketÏÂÔØµÄNode.jsÏîÄ¿»ònpm°üϰȾָ±ê£¬£¬£¬£¬£¬Ò²Ê¹ÓÃÁËQt»òElectronÀûÓ÷¨Ê½¹¹½¨µÄÎļþ¡£¡£¡£¡£¡£¡£¡£Ò»µ©¼¤»î£¬£¬£¬£¬£¬OtterCookie¾Í»áʹÓÃSocket.IO WebSocket¹¤¾ßÓëºÅÁîºÍ½ÚÔì»ù´¡ÉèÊ©³ÉÁ¢°²È«Í¨Ñ¶£¬£¬£¬£¬£¬²¢Ö´ÐÐÊý¾Ý͵ÇÔµÄshellºÅÁ£¬£¬£¬£¬Ô̺¬ÍøÂç¼ÓÃÜÇ®±ÒÇ®°üÃÜÔ¿¡¢Îĵµ¡¢Í¼ÏñµÅ×мÛÖµÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£×îа汾µÄOtterCookie»¹Äܹ»Ð¹Â¶¼ôÌù°åÊý¾Ý£¬£¬£¬£¬£¬²¢¼ì²âµ½ÓÃÓÚ¿úËŵĺÅÁ£¬£¬£¬£¬Åú×¢¹¥»÷Õß³ïËã½øÐиüÉîµµ´ÎµÄÉøÈë»òºáÏòÒÆ¶¯¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/new-ottercookie-malware-used-to-backdoor-devs-in-fake-job-offers/
2. ÈÕº½ÔâDDoS¹¥»÷Öº½°àÑÓÎ󣬣¬£¬£¬£¬ÏµÍ³ÒѸ´Ô
12ÔÂ26ÈÕ£¬£¬£¬£¬£¬ÈÕ±¾Æì½¢º½¿Õ¹«Ë¾ÈÕ±¾º½¿Õ(JAL)Ôâ·êÁËÒ»´ÎÍøÂ簲ȫÊÂÎñ£¬£¬£¬£¬£¬µ¼ÖÂÆä²¿ÃŹúÄں͹ú¼Êº½°à³öÏÖÑÓÎ󡣡£¡£¡£¡£¡£¡£ÊÂÎñÆðÒòÊÇÆäÓÃÓÚÓë±í²¿ÏµÍ³½øÐÐÊý¾ÝͨѶµÄÍøÂçÉ豸Ôâ·êÁËÉ¢²¼Ê½»Ø¾ø·þÎñ(DDoS)¹¥»÷£¬£¬£¬£¬£¬µ¼ÖÂϵÍÂä÷Á¿¼¤Ôö²¢³öÏÖ¹ÊÕÏ¡£¡£¡£¡£¡£¡£¡£¹¥»÷»¹Ó°ÏìÁ˳˿ÍÐÐÀîÖÎÀíϵͳºÍÒÆ¶¯ÀûÓ÷¨Ê½£¬£¬£¬£¬£¬µ«ÈÕº½°µÊ¾Ã»Óпͻ§ÐÅϢй¶¡¢ÍÆËã»ú²¡¶¾ÇÖº¦»ò·ÉÐа²È«ÎÊÌâ¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄϵͳÒÑÁÙʱ¹Ø¹Ø£¬£¬£¬£¬£¬²¢ÔÝÍ£Á˵±ÈÕÆô³ÌµÄ»úƱÏúÊۺͲ¿ÃÅÔÚÏß·þÎñ¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜÓÐ40¶à¸öº½°àÑÓÎ󣬣¬£¬£¬£¬µ«ÈÕº½°µÊ¾µÚ¶þÌìµÄº½°à´òËãÕý³£ÔËÐÓ×£¡£¡£¡£¡£¡£¡£º½¿ÕÒµÈÔÊÇÈ«ÇòºÚ¿ÍµÄÈȵãÖ¸±ê£¬£¬£¬£¬£¬´ËÇ°Ò²Ôø²úÉú¶àÆðÕë¶Ôº½¿Õ¹«Ë¾ºÍ»ú³¡µÄÍøÂç¹¥»÷ÊÂÎñ£¬£¬£¬£¬£¬ÕâЩϮ»÷´ó¶à³öÓÚ¾¼Ã¶¯»ú£¬£¬£¬£¬£¬µ«Ò²ÓÐÕþÖζ¯»úµÄ°¸Àý¡£¡£¡£¡£¡£¡£¡£
https://therecord.media/japan-airlines-resumes-operations-after-cyberattack
3. °ÍÎ÷ºÚ¿ÍÒòÉæÏÓÚ²ÆÀÕË÷ÔÚÃÀ¹úÔâÖ¸¿Ø
12ÔÂ26ÈÕ£¬£¬£¬£¬£¬Ò»Ãû°ÍÎ÷¹«ÃñJunior Barros De OliveiraÒòÉæÏÓºÚ¿ÍÈëÇÖ²¢Ú²ÆÀÕË÷Ò»¼ÒλÓÚÐÂÔóÎ÷µÄ¹«Ë¾¶ø±»ÃÀ¹ú˾·¨²¿¸æ×´¡£¡£¡£¡£¡£¡£¡£¾Ý¸æ×´ÊéÏÔʾ£¬£¬£¬£¬£¬µÂ°ÂÀûάÀÓÚ2020Äê3ÔÂÈëÇÖÁ˸ù«Ë¾µÄ°ÍÎ÷×Ó¹«Ë¾ÍøÂ磬£¬£¬£¬£¬ÇÔÈ¡ÁËÔ¼30ÍòÃû¿Í»§µÄ»úÃÜÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£Í¬Äê9Ô£¬£¬£¬£¬£¬ËûʹÓû¯ÃûÏò¸Ã¹«Ë¾Ê×ϯִÐйٷ¢Ë͵ç×ÓÓʼþ£¬£¬£¬£¬£¬ÒªÇóÖ§¸¶300±ÈÌØ±Ò£¨µ±ÊмÛÖµÔ¼320ÍòÃÀÔª£©×÷Ϊ²»ÏúÊÛÊý¾ÝµÄǰÌá¡£¡£¡£¡£¡£¡£¡£Ò»¸öÔº󣬣¬£¬£¬£¬ËûÓÖ½«Ò»ÑùµÄÐÅϢת·¢¸øÁ˸ù«Ë¾ÔÚ°ÍÎ÷µÄÊ×ϯִÐйٺÍÒ»Ãû¸ß¹Ü£¬£¬£¬£¬£¬²¢°µÊ¾Ô¸ÒâÒÔ75±ÈÌØ±Ò£¨ÆäʱԼºÏ80ÍòÃÀÔª£©µÄÕ÷ѯ·ÑÔ®ÊÖËûÃǽâ¾ö°²È«·ì϶¡£¡£¡£¡£¡£¡£¡£µÂ°ÂÀûάÀÒò¶ø±»Ö¸¿ØËÄÏîÉæ¼°´ÓÊܱ£»£»£»£»£»£»£»£»¤µÄÍÆËã»ú»ñÊØÐÅÏ¢µÄÚ²ÆÀÕË÷×ïºÍËÄÏîÍþвÐÔͨѶ×ï¡£¡£¡£¡£¡£¡£¡£ÈôÊÇ×ïÃû³ÉÁ¢£¬£¬£¬£¬£¬Ëû½«Ãæ¶Ô×î¸ß¿É´ï20ÄêµÄ½ûïÀºÍ¸ß´ï100ÍòÃÀÔªµÄ·£¿£¿£¿£¿£¿î£¬£¬£¬£¬£¬»òÊÕÒæÓëËðʧ¼ÛÖµµÄÁ½±¶£¨ÒԽϸßÕßΪ׼£©¡£¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2024/12/brazilian-hacker-charged-for-extorting.html
4. ͨÓö¯Á¦¹«Ë¾ÔâÍøÂç´¹µö¹¥»÷£¬£¬£¬£¬£¬ÊýʮԱ¹¤¸£ÀûÕË»§±»ÈëÇÖ
12ÔÂ26ÈÕ£¬£¬£¬£¬£¬º½¿Õº½ÌìºÍ¹ú·À¾ÞͷͨÓö¯Á¦¹«Ë¾Ôâ·êÁËÒ»´Î³É¹¦µÄÍøÂç´¹µö¹¥»÷£¬£¬£¬£¬£¬µ¼ÖÂÊýÊ®¸öÔ±¹¤¸£ÀûÕË»§±»ÈëÇÖ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýµÚÈý·½ÍйܵĵǼÃÅ»§½Ó¼û²¢¸ü¸ÄÁËÔ±¹¤¸£ÀûÕË»§£¬£¬£¬£¬£¬ÕâЩÕË»§Ô̺¬ÁËÔ±¹¤µÄÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢µ±¾ÖÐû¸æµÄÉí·ÝÖ¤ºÅÂë¡¢Éç»á°²È«ºÅÂë¡¢ÒøÐÐÕË»§ÐÅÏ¢ºÍ²Ð¼²Çé¿öµÈÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¾ÝͨÓö¯Á¦¹«Ë¾Ð¹Â©£¬£¬£¬£¬£¬¹²ÓÐ37ÈËÊܵ½Ó°Ï죬£¬£¬£¬£¬¹¥»÷ÕßÔÚijЩÇé¿öÏ»¹¸ü¸ÄÁ˱»µÁÕË»§µÄÒøÐÐÕË»§ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£Í¨Óö¯Á¦¹«Ë¾ÔÚ·¢ÏÖÕâһδ¾ÊÚȨµÄ»î¶¯ºóÁ¢¼´ÔÝÍ£Á˶Ը÷þÎñµÄ½Ó¼û£¬£¬£¬£¬£¬²¢ÏòÊÜÓ°ÏìµÄÈËÔ±ÌṩÁËÁ½ÄêµÄÃâ·ÑÐÅÓþ¼à¿Ø¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬Í¨Óö¯Á¦¹«Ë¾»¹ÌáÐÑÊÜÓ°ÏìµÄÓ×ÎÒ³ÁÖÃËûÃǵĸ»´ïÕË»§µÇ¼ƾ֤£¬£¬£¬£¬£¬²¢Ô¤·ÀÔÚ¶à¸öÕË»§ÖÐʹÓÃÒ»ÑùµÄƾ֤¡£¡£¡£¡£¡£¡£¡£½ñÄêÔçЩʱ³½£¬£¬£¬£¬£¬¸»´ï¹«Ë¾Ò²ÔøÔâ·ê¹ýÁ½´ÎÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬Ó°ÏìÁËÊýÍòÓ×ÎÒ¡£¡£¡£¡£¡£¡£¡£
https://www.securityweek.com/defense-giant-general-dynamics-says-employees-targeted-in-phishing-attack/
5. WDACÔâÀûÓ㬣¬£¬£¬£¬¹¥»÷Õ߿ɽûÓÃEDR´«¸ÐÆ÷·¢Æð¹¥»÷
12ÔÂ25ÈÕ£¬£¬£¬£¬£¬°²È«×¨¼Ò·¢ÏÖÁËÒ»ÖÖÀûÓÃWindows DefenderÀûÓ÷¨Ê½½ÚÔ죨WDAC£©µÄ¹¥»÷¼¼Êõ£¬£¬£¬£¬£¬Äܹ»½ûÓÃWindowsÉ豸ÉϵĶ˵ã¼ì²âºÍÏìÓ¦£¨EDR£©´«¸ÐÆ÷£¬£¬£¬£¬£¬Ê¹¹¥»÷Õß¿ÉÄÜÈÆ¹ý°²È«¼ì²â²¢¶Ôϵͳ·¢Æð¹¥»÷¡£¡£¡£¡£¡£¡£¡£WDACÊÇWindows 10ºÍWindows Server 2016ÒýÈëµÄ¼¼Êõ£¬£¬£¬£¬£¬Ö¼ÔÚ½ÚÔìWindowsÉ豸ÉϵĿÉÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»Ôì¶©ºÍ²¿ÊðרÃÅÉè¼ÆµÄWDACÕ½Êõ£¬£¬£¬£¬£¬×èÖ¹EDR´«¸ÐÆ÷ÔÚϵͳÆô¶¯Ê±¼ÓÔØ£¬£¬£¬£¬£¬Ê¹ÆäÎÞ·¨¹¤×÷¡£¡£¡£¡£¡£¡£¡£¹¥»÷·½Ê½Ô̺¬Õë¶Ôµ¥¸öÉ豸ºÍÕû¸öÓò£¬£¬£¬£¬£¬Õ¼ÓÐÓòÖÎÀíԱȨÏ޵Ĺ¥»÷ÕßÄܹ»ÔÚÕû¸ö×éÖ¯ÄÚ·Ö·¢¶ñÒâWDACÕ½Êõ£¬£¬£¬£¬£¬ÏµÍ³ÐԵؽûÓÃËùÓж˵ãÉϵÄEDR´«¸ÐÆ÷¡£¡£¡£¡£¡£¡£¡£¹¥»÷Éæ¼°Õ½Êõ¸éÖᢳÁÆôÖն˺ͽûÓÃEDRÈý¸öÖØÒª½×¶Î¡£¡£¡£¡£¡£¡£¡£°²È«ÈËÔ±´´½¨ÁË¡°Krueger¡±¸ÅÏëÑéÖ¤¹¤¾ßÀ´¼ì²âÕâÖÖ¹¥»÷¡£¡£¡£¡£¡£¡£¡£»£»£»£»£»£»£»£»º½âÕ½ÊõÔ̺¬Í¨¹ýGPOÖ´ÐÐWDACÕ½Êõ¡¢ÀûÓÃ×îÓ×ȨÏÞ×¼ÔòºÍÖ´Ðа²È«µÄÖÎÀíʵ¼Ê¡£¡£¡£¡£¡£¡£¡£Ãæ¶ÔгöÏֵĹ¥»÷¼¼Êõ£¬£¬£¬£¬£¬±ØÒª²ÉÈ¡¶àµµ´ÎµÄÍøÂ簲ȫ²½Ö裬£¬£¬£¬£¬²¢Ê±¿Ìά³Ö¾¯Ìè¡£¡£¡£¡£¡£¡£¡£
https://cybersecuritynews.com/attack-weaponizes-windows-defender/#google_vignette
6. ΢ÈíÖҸ棺ʹÓÃýÌå×°ÖÃWindows 11 24H2¿ÉÖÂÎÞ·¨½Ó¹Ü°²È«¸üÐÂ
12ÔÂ26ÈÕ£¬£¬£¬£¬£¬Î¢Èí·¢³öÖҸ棬£¬£¬£¬£¬Ö¸³öʹÓÃýÌåÖ§³Ö×°ÖÃWindows 11°æ±¾24H2ʱ´æÔÚÒ»¸öÎÊÌ⣬£¬£¬£¬£¬¿ÉÄܵ¼Ö²Ù×÷ϵͳÎÞ·¨½ÓÊܽøÒ»²½µÄ°²È«¸üС£¡£¡£¡£¡£¡£¡£¾ßÌå¶øÑÔ£¬£¬£¬£¬£¬ÔÚ2024Äê10ÔÂ8ÈÕÖÁ11ÔÂ12ÈÕÆÚ¼ä£¬£¬£¬£¬£¬Ê¹ÓÃCDºÍUSBÉÁ´æÇý¶¯Æ÷×°ÖÃÔ̺¬´ËÆÚ¼ä°²È«¸üеÄWindows 11°æ±¾24H2ʱ£¬£¬£¬£¬£¬É豸¿ÉÄÜ»áÏÝÈëÎÞ·¨½ÓÊܺóÐøWindows°²È«¸üеÄ״̬¡£¡£¡£¡£¡£¡£¡£²»Í⣬£¬£¬£¬£¬Õâ¸ö·ì϶²»»áÓ°Ïìͨ¹ýWindows¸üлòMicrosoft¸üÐÂÄ¿Â¼ÍøÕ¾ÀûÓõݲȫ¸üУ¬£¬£¬£¬£¬Ò²²»»áÔÚʹÓÃ×îеÄ2024Äê12Ô°²È«¸üÐÂʱ³öÏÖ¡£¡£¡£¡£¡£¡£¡£Î¢ÈíÔÚÖÂÁ¦ÓÚÓÀÔ¶½¨¸´´ËÎÊÌ⣬£¬£¬£¬£¬²¢½¨ÒéʹÓûùÓÚýÌåµÄWindows 11 24H2×°ÖõÄÓû§ÀûÓÃ2024Äê12ÔÂ10ÈÕ°ä²¼µÄ°²È«¸üУ¬£¬£¬£¬£¬ÒÔÔ¤·ÀºóÐø¸üÐÂÎÊÌâ¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬Windows 11 24H2»¹Ãæ¶Ô×ÅһϵÁÐÆäËûÎÊÌ⣬£¬£¬£¬£¬Ô̺¬ÒôƵÎÊÌâ¡¢ÓÎÏ·»úÄÜÎÊÌâ¡¢±ÀÀ£ºÍËÀ»úµÈ£¬£¬£¬£¬£¬ÉõÖÁÔÚÌØ¶¨µÄÓ²¼þºÍÈí¼þÅäÖÃÉϱ»ÁÙʱ×èÖ¹¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/windows-11-installation-media-bug-causes-security-update-failures/


¾©¹«Íø°²±¸11010802024551ºÅ