RustDoorͨ¹ýJustice AV Solutions JAVS Viewer½øÐд«²¼
°ä²¼¹¦·ò 2024-05-271. RustDoorͨ¹ýJustice AV Solutions JAVS Viewer½øÐд«²¼
5ÔÂ26ÈÕ£¬Rapid7 µÄ×êÑÐÈËÔ±ÖÒ¸æ³Æ£¬ÍþвÐÐΪÕßÔÚ Justice AV Solutions JAVS Viewer Èí¼þµÄ×°Ö÷¨Ê½ÖÐÔö³¤Á˺óÃÅ¡£¹¥»÷Õß¿ÉÄÜÔÚ´Ó JAVS ·þÎñÆ÷·Ö·¢µÄ JAVS Viewer v8.3.7 ×°Ö÷¨Ê½ÖÐ×¢ÈëºóÃÅ¡£Justice AV Solutions (JAVS) ÊÇÒ»¼Ò×ܲ¿Î»ÓÚÃÀ¹úµÄ¹«Ë¾£¬Îª·¨Í¥»·¾³ºÍÆäËû»·¾³£¨Ô̺¬¼àÓü¡¢Òé»áºÍÑݽ²ÊÒ£©ÌṩÊý×ÖÊÓÌý¼Ôì½â¾ö¹æ»®¡£JAVS Viewer ÔÚÈ«ÇòÕ¼Óг¬¹ý 10,000 ¸ö×°Öá£×êÑÐÈËÔ±ÌṩµÄºóÃÅÔÊÐí¹¥»÷Õ߯ëÈ«½ÚÔìÊÜϰȾµÄϵͳ¡£Rapid7 ר¼Ò½¨Òé³ÁÐÂÓ³ÏñÊÜÓ°ÏìµÄϵͳ£¬³ÁÖÃÓйØÍ´´¦£¬²¢×°ÖÃ×îа汾µÄ JAVS Viewer£¨v8.3.8 »ò¸ü¸ß°æ±¾£©¡£×êÑÐÈËÔ±°ÑÎȵ½£¬JAVS Viewer Setup 8.3.7.250-1.exe µÄ×°Ö÷¨Ê½Ê¹ÓÃÒâ±íµÄ Authenticode ÊðÃû½øÐÐÊý×ÖÊðÃû£¬²¢Ô̺¬Ò»¸öÃûΪ fffmpeg.exe µÄ¶þ½øÔìÎļþ¡£¸Ã¶þ½øÔìÎļþÖ´ÐбàÂëµÄ PowerShell ¾ç±¾£¬Rapid7 ½« fffmpeg.exe ÓëGateDoor / Rustdoor¶ñÒâÈí¼þÁªÏµÆðÀ´£¬¸Ã¶ñÒâÈí¼þÒѱ»°²È«¹«Ë¾ S2W ¼ø±ð¡£
https://securityaffairs.com/163683/hacking/supplay-chain-attack-javs-viewer.html
2. SlashNext°ä²¼2024ÄêÉϰëÄêÍøÂç´¹µöÇé¿ö»ã±¨
5ÔÂ24ÈÕ£¬»ã±¨³Æ£¬´ÓǰÁù¸öÔÂÖжñÒâÍøÂç´¹µöÁ´½Ó¡¢Ã³Ò×µç×ÓÓʼþÈëÇÖ (BEC)¡¢¶þάÂëºÍ»ùÓÚ¸½¼þµÄÍþвÔö³¤ÁË 341%¡£¸ÃÊý¾ÝÀ´×Ô SlashNext µÄÄêÖÓ×¶2024 ÄêÍøÂç´¹µöÇé¿ö¡·»ã±¨ £¬¸Ã»ã±¨»¹·¢ÏÖ£¬ÔÚ´Óǰ 12 ¸öÔÂÖУ¬¶ñÒâµç×ÓÓʼþºÍÐÂÎÅÍþвÔö³¤ÁË 856%¡£×Ô 2022 Äê 11 ÔÂÍÆ³ö ChatGPT ÒÔÀ´£¬¶ñÒâÍøÂç´¹µöÐÂÎż¤ÔöÁË 4151%¡£Keeper Security Ê×ϯִÐйټæ½áºÏÊ×´´ÈË Darren Guccione ÖÒ¸æ³Æ£º²»Á¼ÐÐΪÕßÄܹ»Í¨¹ý¶àÖÖ·½Ê½ÀûÓà ChatGPT£¬Ô̺¬´´½¨ÁîÈËÕÛ·þµÄÍøÂç´¹µöµç×ÓÓʼþ¡£ÕâЩ¹¤¾ß²»½öÄܹ»Ô®ÊÖ·¸·¨·Ö×Ó´´½¨¿ÉÐŵÄÍøÂç´¹µöµç×ÓÓʼþ»òÀÕË÷Èí¼þ¹¥»÷µÄ¶ñÒâ´úÂëµÈÄÚÈÝ£¬²¢ÇÒËûÃÇÄܹ»¼±¾çÇáËɵØÊµÏÖÕâЩ²Ù×÷¡£·ÀÓùÄÜÁ¦×îÈõµÄ×éÖ¯½«³ö¸ñÈÝÒ×Êܵ½¹¥»÷£¬ÓÉÓÚ¹¥»÷Á¿¿ÉÄÜ»á³ÖÐøÔö³¤¡£»ã±¨»¹·¢ÏÖ£¬ÔÚ´ÓǰÁù¸öÔÂÖУ¬Æ¾Ö¤ÇÔÈ¡ÍøÂç´¹µö¹¥»÷Ôö³¤ÁË 217%£¬BEC ¹¥»÷Ôö³¤ÁË 29%¡£»ùÓÚ CAPTCHA µÄ¹¥»÷Ò²ÔÚÔö³¤£¬¹¥»÷ÕßʹÓà CloudFlare µÄ CAPTCHA À´°µ²ØÆ¾Ö¤ÍøÂç±í¸ñ¡£´Ë±í£¬ÍøÂç·¸×ï·Ö×ÓÔÚÀûÓà Microsoft SharePoint¡¢AWS ºÍ Salesforce µÈ¿ÉÕÛ·þÎñÀ´°µ²ØÍøÂç´¹µöºÍ¶ñÒâÈí¼þ¡£»ùÓÚ¶þάÂëµÄ¹¥»÷´Ë¿ÌÕ¼ËùÓжñÒâµç×ÓÓʼþµÄ 11%£¬Í¨³£¼¯³Éµ½ºÏ·¨»ù´¡ÉèÊ©ÖС£
https://www.infosecurity-magazine.com/news/341-rise-advanced-phishing-attacks/?&web_view=true
3. ShrinkLocker ½Ù³Ö BitLocker Õë¶ÔÆóÒµÌáÒé¹¥»÷
5ÔÂ25ÈÕ£¬¿¨°Í˹»ù³¢ÊÔÊÒµÄר¼ÒÒѾȷ¶¨Ê¹ÓÃÒ»ÖÖÃûΪ ShrinkLocker µÄÐÂÀÕË÷Èí¼þ·¨Ê½¶ÔÆóÒµÉ豸½øÐй¥»÷£¬¸Ã·¨Ê½ÀûÓÃÁË BitLocker¡£BitLocker ÊÇ Windows ÖеÄÒ»ÏȫְÄÜ£¬¿Éͨ¹ý¼ÓÃܱ£»¤Êý¾Ý¡£ÕâЩ¹¥»÷µÄÖ¸±êÔ̺¬¹¤ÒµºÍÔìÒ©¹«Ë¾ÒÔ¼°µ±¾Ö»ú¹¹¡£¹¥»÷ÕßʹÓà VBScript ±àдÁËÒ»¸ö¶ñÒâ¾ç±¾¡£¸Ã¾ç±¾»á²é³É豸ÉÏ×°ÖÃµÄ Windows °æ±¾²¢¼¤»îÏàÓ¦µÄ BitLocker Ö°ÄÜ¡£ShrinkLocker Äܹ»Ï°È¾Ð¾ɰ汾µÄ²Ù×÷ϵͳ£¬×î¸ß¿ÉϰȾ Windows Server 2008¡£¸Ã¾ç±¾»áÅú¸Ä²Ù×÷ϵͳµÄÆô¶¯²ÎÊý£¬¶øºó³¢ÊÔʹÓà BitLocker ¼ÓÃÜÓ²ÅÌ·ÖÇø¡£´´½¨Ò»¸öÐÂµÄÆô¶¯·ÖÇø£¬ÒÔ±ãÉÔºó¼ÓÔØ¼ÓÃܵÄÍÆËã»ú¡£¹¥»÷Õß»¹»áɾ³ýÓÃÓÚ±£»¤ BitLocker ¼ÓÃÜÃÜÔ¿µÄ°²È«¹¤¾ß£¬×èÖ¹Óû§¸´ÔËüÃÇ¡£Ëæºó£¬¶ñÒâ¾ç±¾½«ÊÜÏ°È¾ÍÆËã»úÉÏÌìÉúµÄϵͳÐÅÏ¢ºÍ¼ÓÃÜÃÜÔ¿·¢Ë͵½¹¥»÷ÕߵķþÎñÆ÷¡£¶øºó£¬Ëü»áͨ¹ýɾ³ýÈÕÖ¾ºÍ¸÷Àà¿ÉÄÜÓÐÖúÓÚµ÷²é¹¥»÷µÄÎļþÀ´¡°¸²¸ÇÆä×ÙÓ°¡±¡£
https://meterpreter.org/new-ransomware-threat-shrinklocker-hijacks-bitlocker-for-corporate-attacks/
4. APT36ÀûÓÃLinux¼äµýÈí¼þ¹¥»÷Ó¡¶ÈµÄ¹ú·À×éÖ¯
5ÔÂ25ÈÕ£¬Ò»¸öÓë°Í»ù˹̹ÀûÒæÏà·ûµÄ¡¢³öÓÚÕþÖζ¯»úµÄºÚ¿Í×éÖ¯ÕýÓëÓ¡¶È¾ü·½Í¬²½ÉÕ»Ù Windows ²Ù×÷ϵͳ£¬²¢½«³Áµã·ÅÔÚΪ Linux ±àÂëµÄ¶ñÒâÈí¼þÉÏ¡£¸ÃÍøÂç¼äµý×éÖ¯ÀûÓõç×ÓÓʼþ×÷ΪÓã²æÊ½ÍøÂç´¹µö¹¥»÷µÄÔØÌ壬»¹ÀûÓà Telegram¡¢Discord¡¢Slack ºÍ Google Drive µÈÊ¢ÐÐÍøÂç·þÎñÀ´´æ´¢ºÍ·Ö·¢µö¶üºÍ¶ñÒâÈí¼þ¡£Ã¿´Î¹¥»÷µÄ»úÓö¶¼ÊÇÓÐÕ½ÊõÐԵģ¬ÕâÅú×¢ºÚ¿ÍÔÚ·¢Æðÿ´Î¹¥»÷ʱ¶¼½øÐÐÁ˾ßÌåµÄ¹æ»®£¬²¢ÓÐÌØ¶¨µÄÖ¸±ê¡£×Ô×êÑÐÈËÔ±ÆðÍ·¸ú×Ù APT36 Ðж¯ÒÔÀ´£¬¸Ã×éÖ¯³õ´ÎʹÓà ISO Ó³Ïñ×÷Ϊ¹¥»÷ý½é¡£ÔÚÓ¡¶Èµ±¾Ö°ä·¢Õбê²É°ìÕ½¶·»úºÍÉý¼¶ÊýÊ®¼ÜËÕ»ôÒÁ 30MKI Õ½¶·»úÖ®¼Ê£¬¸Ã×éÖ¯»¹ÔÚÓã²æÊ½ÍøÂç´¹µöµç×ÓÓʼþÖÐʹÓà ISO Ó³ÏñÀ´¹¥»÷Ó¡¶È¿Õ¾ü¹ÙÔ±¡£ºÚÝ®³Æ£¬¸Ã¼äµý×éÖ¯·ÂÕÕÓ¡¶È¹ú·ÀºÍÕ½ÊõÖǿ⼰µ±¾Ö»ú¹¹µÄÍøÕ¾ÓòÃû£¬ÓÕÆÊܺ¦ÕßÏÂÔØ¶ñÒâµö¶üÎļþ¡£ÕâЩ×éÖ¯Ô̺¬Î»ÓÚеÂÀïµÄ¶ÀÁ¢ÖÇ¿â½ս×êÑÐÖÐÐÄ¡¢Ó¡¶ÈÍÆËã»úÓ¦¼±ÏìÓ¦Ó××éºÍ½¾ü¸£Àû½ÌÓýлᡣ
https://www.bankinfosecurity.com/pakistani-aligned-apt36-targets-indian-defense-organizations-a-25296?&web_view=true
5. ¼Ùð Pegasus ¼äµýÈí¼þ²¡¶¾³äÒ缴ʱͨѶƽ̨ºÍ°µÍø
5ÔÂ25ÈÕ£¬CloudSEK ·¢ÏÖ£¬¼Ùð Pegasus ¼äµýÈí¼þµÄÔ´´úÂëÔÚ±í²ãÍøÂç¡¢°µÍøºÍ¼´Ê±Í¨Ñ¶Æ½Ì¨ÉÏÏúÊÛ¡£¼ÌÆ»¹û¹«Ë¾×î½ü·¢³öÓйء°¹ÍÓ¶ÐͼäµýÈí¼þ¡±¹¥»÷µÄÖÒ¸æºó£¬Ôư²È«ÌṩÉÌ CloudSEK ¶ÔÃ÷ÍøºÍ°µÍøÖÐÓë¼äµýÈí¼þÓйصÄÍþв½øÐÐÁ˵÷²é¡£¸Ã¹«Ë¾·ÖÎöÁËԼĪ 25,000 Ìõ Telegram Ìû×Ó£¬·¢ÏֺܶàÌû×ÓÐû³ÆÏúÊÛ Pegasus µÄÕæÊµÔ´´úÂë¡£Pegasus ÊÇÓÉÒÔÉ«Áй«Ë¾ NSO Group óÒ×»¯µÄ¼äµýÈí¼þ¡£ÕâЩÌû×Ó´ó¶à×ñÑÌṩ·¸·¨·þÎñµÄͨÓÃÄ£°å£¬ÆäÖÐʱʱÌáµ½ Pegasus ºÍ NSO ¹¤¾ß¡£Í¨¹ýÓë 150 ¶àÃûDZÔÚÂô¼Ò»¥¶¯£¬×êÑÐÈËÔ±Éî¿ÌÏàʶÁ˸÷ÀàÑù±¾ºÍÖ¸±ê£¬Ô̺¬ËùνµÄ Pegasus Ô´´úÂë¡¢ÏÖ³¡ÑÝʾ¡¢Îļþ½á¹¹ºÍ¿ìÕÕ¡£ÔÚ·ÖÎöÁËÀ´×Ô°µÍøÔ´µÄ 15 ¸öÔ´´úÂëÑù±¾ºÍ 30 ¶à¸öÖ¸±êºó£¬CloudSEK ·¢ÏÖÏÕЩËùÓÐÑù±¾¶¼ÊÇÚ²ÆÐÔµÄÇÒÎÞЧµÄ¡£ÍþвÐÐΪÕß´´½¨ÁË×Ô¼ºµÄ¹¤¾ßºÍ¾ç±¾£¬²¢ÒÔ Pegasus µÄÃûÒå·Ö·¢£¬ÀûÓÃÆä¶ñÃû»ñÈ¡¾¼ÃÀûÒæ¡£ÕâÒ»Ç÷ÏòÔÚ¶à¸öµØÏÂÂÛ̳ÖÐÒ²ÓÐËùÌåÏÖ£¬·¸×ïÕßÔÚÕâЩÂÛ̳ÉÏÓªÏúºÍ·Ö·¢Ñù±¾£¬Àû
Óà Pegasus µÄÃûÒå»ñÈ¡½ðÇ®ÀûÒæ£¬²¢ÔڵرíÍøÂç´úÂë¹²ÏíÆ½Ì¨ÉÏ´«²¼Óë Pegasus Ðéα¹ØÁªµÄËæ»úÌìÉúµÄÔ´´úÂë¡£
https://www.infosecurity-magazine.com/news/fake-pegasus-spyware-dark-web/
6. CencoraÊý¾Ýй¶µ¼ÖÂ11¼ÒÔìÒ©¹«Ë¾µÄÃÀ¹ú»¼ÕßÐÅÏ¢±»Ð¹Â¶
5ÔÂ25ÈÕ£¬È«ÇòһЩ×î´óµÄÔìÒ©¹«Ë¾Åû¶ÁËÊý¾Ýй¶ÊÂÎñ£¬ÔÒòÊÇ 2024 Äê 2 ÔÂ¶ÔÆäÔìÒ©ºÍóÒ×·þÎñºÏ×÷ͬ°é Cencora ÌáÒéµÄÍøÂç¹¥»÷¡£Cencora£¨Ç°ÉíΪ AmerisourceBergen£©ÊÇÒ»¼ÒרÃÅ´ÓÊÂÒ©Æ··ÖÏú¡¢×¨ÒµÒ©·¿¡¢Õ÷ѯºÍÁÙ´²ÊÔÑéÖ§³ÖµÄÒ½Ò©·þÎñÌṩÉÌ¡£¸Ã¹«Ë¾×ܲ¿Î»ÓÚ±öϦ·¨ÄáÑÇÖÝ£¬ÒµÎñ±é¼° 50 ¸ö¹ú¶È£¬Õ¼ÓÐ 46,000 ÃûÔ±¹¤£¬2023 ÄêÓªÊÕΪ 2620 ÒÚÃÀÔª¡£2024 Äê 2 Ô£¬Cencora ÔÚÏòÃÀ¹ú֤ȯÂòÂôίԱ»áÌá½»µÄ 8-K ±í¸ñÖÐÅû¶ÁËÊý¾Ýй¶ÊÂÎñ £¬³ÆÎ´¾ÊÚȨµÄ¸÷·½½Ó¼ûÁËÆäÐÅϢϵͳ²¢ÇÔÈ¡ÁËÓ×ÎÒÊý¾Ý¡£Æäʱ£¬¸Ã¹«Ë¾Ñ¡Ôñ²»·ÖÏíÓйظÃÊÂÎñ¼°Æä¶Ô¿Í»§µÄDZÔÚÓ°ÏìµÄÈÎºÎÆäËûÐÅÏ¢¡£´Ë±í£¬Ã»ÓÐÈκÎÀÕË÷Èí¼þ×éÖ¯ÈϿɶÔÕâ´Î¹¥»÷ÕÆ¹Ü¡£½ñÌ죬¼ÓÖÝ×ܼì²ì³¤°ì¹«ÊÒ°ä²¼ÁËÃÀ¹úһЩ×î´óµÄÔìÒ©¹«Ë¾ÔÚ´Óǰ¼¸ÌìÌá½»µÄ¶à·ÝÊý¾Ýй¶֪ͨÑù±¾£¬ÕâЩ¹«Ë¾¾ù½«ÆäÊý¾Ýй¶¹é×ïÓÚ 2 ÔÂ·ÝµÄ Cencora ÊÂÎñ¡£Êý¾Ýй¶֪ͨÖÒ¸æ³Æ£¬Cencora µÄÄÚ²¿µ÷²éÓÚ 2024 Äê 4 Ô 10 ÈÕʵÏÖ£¬µ÷²é֤ʵÒÔÏÂÐÅÏ¢Òѱ»Ð¹Â¶£ºÈ«Ãû¡¢µØÖ·¡¢½¡È«Õï¶Ï¡¢Ò©ÎïºÍ´¦·½¡£ÐÅÖÐÖ¸³ö£¬½ØÖÁĿǰ£¬Ã»ÓÐÖ¤¾ÝÅú×¢ÇÔÈ¡µÄÐÅÏ¢ÒÑÔÚ»¥ÁªÍøÉϹ«¿ªÅû¶»ò±»ÓÃÓÚÚ²ÆÖ÷ÕÅ¡£ÎªÁËÓ¦¶ÔÊÜÓ°ÏìÓ×ÎÒÃæ¶ÔµÄ½Ï¸ß·çÏÕ£¬Cencora ½«Í¨¹ý Experian ΪÊÜÖúÕßÌṩÁ½ÄêµÄÃâ·ÑÉí·Ý±£»¤ºÍÐÅÓþ¼à¿Ø·þÎñ£¬ÊÜÖúÕßÄܹ»Ê¹ÓÃÕâЩ·þÎñÖ±µ½ 2024 Äê 8 Ô 30 ÈÕ¡£
https://www.bleepingcomputer.com/news/security/cencora-data-breach-exposes-us-patient-info-from-11-drug-companies/


¾©¹«Íø°²±¸11010802024551ºÅ