¹ú¼ÊÍøÂç·¸×OÍųÉÔ±½« Airbnb Ôì³ÉÚ¿Æ­ÖÐÐĺ󱻲¶

°ä²¼¹¦·ò 2024-12-11

1. ¹ú¼ÊÍøÂç·¸×OÍųÉÔ±½« Airbnb Ôì³ÉÚ¿Æ­ÖÐÐĺ󱻲¶


12ÔÂ9ÈÕ£¬Ò»¸ö¹ú¼Ê·¸×ïÍøÂçµÄ°ËÃû³ÉÔ±ÔÚ±ÈÀûʱºÍºÉÀ¼±»²¶£¬¸ÃÍøÂçÉæÏÓ´ÓÊܺ¦ÕßÊÖÖÐÇÔÈ¡Êý°ÙÍòÅ·Ôª£¬²¢ÉèÁ¢AirbnbڲƭÖÐÐÄ¡£Õâ´ÎÐж¯ÓÉÅ·ÖÞÐ̾¯×é֯Эµ÷£¬ÓÚ12ÔÂ3ÈÕÔÚÁ½¹úͬʱ½øÐÐÁËÂÅ´ÎËѲé¡£ºÉÀ¼¾¯·½¿ÛÁôÁËËÄÃûÏÓÒÉÈË£¬Ö¸¿ØËûÃÇ·¸ÓÐÍøÂç´¹µö¡¢ÔÚÏßڲƭ¡¢ÒøÐÐÔ®ÊǪ̈ڲƭ¡¢Ï´Ç®ºÍ²Î¼Ó·¸×ï×éÖ¯µÈ×ï×´£¬²¢³ä¹«ÁËÊý¾ÝÔØÌå¡¢ÊÖ»ú¡¢ÉÝ³ÞÆ·ºÍ´óÁ¿Ïֽ𡣾ݾ¯·½½éÉÜ£¬¸ÃÍøÂç·¸×OÍÅ×âÓÃAirbnb·¿²úºÍÉÝ»ª¹«Ô¢×÷Ϊһʱºô½ÐÖÐÐÄ£¬¼ÙÒâÒøÐÐÔ±¹¤»ò·´Ú²Æ­¹¤×÷×é³ÉÔ±£¬Í¨¹ýµç×ÓÓʼþ¡¢¶ÌÐÅ»òWhatsAppÐÂÎÅÁªÏµÊܺ¦Õߣ¬ÓÕÆ­ËûÃǵã»÷´¹µöÍøÕ¾Á´½Ó£¬½ø¶øµÁÈ¡ÕË»§×ʽð¡£Å·ÖÞÐ̾¯×éÖ¯ÖҸ湫¼ÒÒªÉóÉ÷¶Ô´ýδ¾­ÒªÇóµÄͨѶ£¬Ô¤·ÀÊܵ½ÍøÂç´¹µöºÍÔ®ÊǪ̈ڲƭµÄºýŪ£¬²¢ÌáÐÑÔÚÏúÊÛ¶þÊÖÉÌÆ·µÄÍøÕ¾ÉϽøÐÐÓ×¶îÖ§¸¶Ê±¿ÉÄÜ´æÔÚÐÅÓþ¿¨/½è¼Ç¿¨ÐÅÏ¢±»µÁµÄ·çÏÕ¡£


https://www.bleepingcomputer.com/news/security/cybercrime-gang-arrested-after-turning-airbnbs-into-fraud-centers/


2. ¶ñÒâ½©Ê¬ÍøÂçSocks5SystemzÖ§³ÖPROXY.AM´úÀí·þÎñ


12ÔÂ9ÈÕ£¬Bitsight·¢ÏÖÃûΪSocks5SystemzµÄ¶ñÒâ½©Ê¬ÍøÂçÔÚΪPROXY.AM´úÀí·þÎñÌṩ֧³Ö£¬¸Ã·þÎñʹ·¸×ïÕß¿ÉÄÜÔö³¤ÄäÃû²ã²¢Ö´ÐжñÒâ»î¶¯¡£Socks5Systemz×Ô2013ÄêÆð±ãÔÚÍøÂç·¸×ïµØÀ´ÊÀ½çÖÐÐû´«£¬Æä¹æÄ£ÔÚ2024Äê1ÔÂÔø¼¤ÔöÖÁÿÌìÔ¼25Íǫ̀»úе£¬µ«Ä¿Ç°¹À¼ÆÔÚ85,000µ½100,000̨֮¼ä¡£Í¬Ê±£¬PROXY.AMÐû³ÆÕ¼ÓÐÀ´×Ô31¸ö¹ú¶ÈµÄ80,888¸ö´úÀí½Úµã¡£¸Ã½©Ê¬ÍøÂç×î³õÓÉPrivateLoader¡¢SmokeLoaderºÍAmadeyµÈ¼ÓÔØÆ÷¿ªÊÍ£¬ÏÖÒÑ·¢Õ¹µ½Socks5Systemz V2°æ±¾¡£´Ë±í£¬ÍøÂ簲ȫÁìÓò»¹Ãæ¶ÔÆäËûÍþв£¬ÈçGafgyt½©Ê¬ÍøÂç¶ñÒâÈí¼þÀûÓÃÅäÖÃÃýÎóµÄDocker Remote API·þÎñÆ÷½øÐÐDDoS¹¥»÷£¬ÒÔ¼°ÔÆÅäÖÃÃýÎó³ÉΪ¹¥»÷ÕßµÄÖ¸±ê¡£À³¶Ù´óѧºÍ´ú¶û·òÌØÀí¹¤´óѧµÄ×êÑÐÈËÔ±·¢ÏÖ¶à´ï215¸öÊ·ý¶³öÁËÃô¸Ðƾ֤£¬Éæ¼°¶à¸öÁìÓò£¬Ç¿µ÷±ØÒª¸üºÃµÄϵͳÖÎÀíºÍ¾¯ÌèµÄ¼à¶½ÒÔÔ¤·ÀÊý¾Ýй¶¡£


https://thehackernews.com/2024/12/socks5systemz-botnet-powers-illegal.html


3. ¶íÂÞ˹ºÚ¿ÍÒÉËÆ¶Ô×¼ÎÚ¿ËÀ¼¹ú·ÀÆóÒµ·¢Õ¹Ð¼äµý»î¶¯


12ÔÂ9ÈÕ£¬¾Ýл㱨³Æ£¬ÒÉËÆ¶íÂÞ˹ºÚ¿ÍÔÚÕë¶ÔÎÚ¿ËÀ¼¾üʺ͹ú·ÀÆóÒµ·¢Õ¹Ðµļäµý»î¶¯¡£ÎÚ¿ËÀ¼¾ü·½ÍÆËã»úÓ¦¼±ÏìÓ¦Ó××éMIL.CERT-UA×·×Ùµ½¸Ã»î¶¯±³ºóµÄÍþвÐÐΪÕßΪUAC-0185£¨Ò²³ÆÎªUNC4221£©£¬¸Ã×éÖ¯×Ô2022ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬ÖØÒªÍ¨¹ýÐÂÎÅÀûÓ÷¨Ê½ºÍ±¾µØ¾üÊÂϵͳÇÔÈ¡ÎÚ¿ËÀ¼¾üÊÂÈËÔ±µÄƾ֤¡£¹¥»÷Õß·¢ËÍÍøÂç´¹µöµç×ÓÓʼþ£¬¼Ù×°³É»ù¸¨ºÏ·¨¹ú·À»áÒéµÄÔ¼Ç룬²¢Ñ¡ÔñÐԵضÔÎÚ¿ËÀ¼¹ú·À¹¤Òµ×ÛºÏÌåºÍ¹ú·À¶ÓÁÐÔ±¹¤µÄÍÆËã»ú·¢ÆðÍøÂç¹¥»÷¡£Ö»¹ÜÎÚ¿ËÀ¼ÉÐ佫¸Ã×éÖ¯¹é×ïÓÚij¸öÌØ¶¨¹ú¶È£¬µ«×êÑÐÈËÔ±´ËÇ°Ôø½«ÆäÓë¶íÂÞ˹ÁªÏµÆðÀ´¡£¸Ã×é֯ʹÓóÛÃû¹¤¾ßÈçMeshAgentºÍUltraVNCϰȾÊܺ¦ÕßµÄÉ豸£¬²¢Í¨¹ý¶àÖÖ·½Ê½ÈëÇÖϵͳ£¬Ô̺¬ÀûÓÃÔ̺¬¶ñÒâºêµÄµç×ÓÓʼþ»î¶¯¡£ÎÚ¿ËÀ¼¾ü·½ºÍ¹ú·ÀÆóÒµÊǺڿ͵ij£¼ûÖ¸±ê£¬´ËÇ°Ò²ÔøÔâ·êÆäËûÓë¶íÂÞ˹ÓÐÁªÏµµÄºÚ¿Í×éÖ¯µÄ¹¥»÷¡£


https://therecord.media/suspected-russian-hackers-target-ukrainian-enterprises-espionage


4. CISA½«Windows CLFS·ì϶CVE-2024-49138²ÎÓëÒÑÖªÀûÓ÷ì϶Ŀ¼


12ÔÂ11ÈÕ£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©Òѽ«Microsoft WindowsͨÓÃÈÕÖ¾Îļþϵͳ(CLFS)Çý¶¯·¨Ê½ÖеÄÒ»¸ö·ì϶CVE-2024-49138£¨CVSSÆÀ·Ö7.8£©ÁÐÈëÆäÒÑÖªÀûÓ÷ì϶£¨KEV£©Ä¿Â¼¡£¸Ã·ì϶ÔÚ΢Èí2024Äê12ÔµIJ¹¶¡ÐÇÆÚ¶þ°²È«¸üÐÂÖеõ½½¨¸´£¬ÊÇÕâ´Î¸üеÄ71¸ö·ì϶֮һ£¬ÇÒ±»ÏóÕ÷ΪÔÚ±»»ý¼«ÀûÓõÄÁãÈÕ·ì϶¡£Ö»¹Ü΢Èíδ¹«¿ªÓйش˷ì϶±»ÀûÓõľßÌå¹¥»÷ÐÅÏ¢£¬µ«¹¥»÷Õß¿ÉÀûÓÃËü»ñÈ¡SYSTEMȨÏÞ¡£²¼¸æÖ¸³ö£¬CLFSÇý¶¯·¨Ê½´æÔÚ»ùÓڶѵĻº³åÇøÒç¶Âí½Å£¬ÔÊÐí±¾µØ¹¥»÷ÕßÌáÉýȨÏÞ¡£Æ¾¾ÝÓµÓÐÔ¼ÊøÁ¦µÄ²Ù×÷Ö¸Áî22-01£¬Áª¹ú»ú¹¹±ØÐëÔÚ»®¶¨½ØÖ¹ÈÕÆÚǰ½â¾öÒÑ·¢Ïֵķì϶£¬ÒÔ±£»¤ÍøÂçÃâÊÜÀûÓÃĿ¼Öзì϶µÄ¹¥»÷¡£CISAÒªÇóÁª¹ú»ú¹¹ÔÚ2024Äê12ÔÂ31ÈÕǰ½¨¸´´Ë·ì϶£¬Í¬Ê±×¨¼ÒÒ²½¨Òé¸öÈË×éÖ¯Éó²é¸ÃĿ¼²¢½â¾öÆä»ù´¡ÉèÊ©ÖеÄÓйطì϶¡£


https://securityaffairs.com/171851/hacking/u-s-cisa-adds-microsoft-windows-clfs-driver-flaw-to-its-known-exploited-vulnerabilities-catalog.html


5. WordPress²å¼þWPForms·¢ÏÖ¸ßÑϳÁÐÔ·ì϶£¬Ó°Ï쳬600ÍòÍøÕ¾


12ÔÂ10ÈÕ£¬WordPress²å¼þWPFormsÖдæÔÚÒ»¸ö±àºÅΪCVE-2024-11205µÄ¸ßÑϳÁÐÔ·ì϶£¬¿ÉÄÜÓ°Ï쳬¹ý600Íò¸öÍøÕ¾¡£¸Ã·ì϶ÔÊÐí¾­¹ýÉí·ÝÑéÖ¤µÄÓû§£¨Ô̺¬¶©ÔÄÕߣ©ËÁÒâ·¢³öStripeÍË¿î»òÈ¡µÞ¶©ÔÄÒªÇó¡£ÎÊÌâÔ´ÓÚ²»µ±Ê¹Óú¯Êý¡°wpforms_is_admin_ajax()¡±£¬Î´Ç¿ÔìÖ´ÐÐÖ°Äܲ鳭ÒÔÏ޶ȽӼû¡£·ì϶ӰÏìWPForms 1.8.4ÖÁ1.9.2.1°æ±¾£¬ÒÑÔÚ1.9.2.2°æ±¾Öн¨¸´¡£WPFormsÊÇÒ»¸öÊ¢ÐеÄÍÏ·ÅʽWordPress±íµ¥¹¹½¨Æ÷£¬Ö§³Ö¶àÖÖÖ§¸¶Æ½Ì¨¡£°²È«×êÑÐÔ±¡°vullu164¡±·¢Ïָ÷ì϶²¢»ã±¨¸øWordfence£¬»ñµÃÉͽð¡£WordfenceÈ·ÈÏ·ì϶ºó֪ͨ¹©¸øÉÌAwesome Motive£¬ºóÕß°ä²¼½¨¸´°æ±¾¡£È»¶ø£¬ÓÉÓÚԼĪһ°ëʹÓÃWPFormsµÄÍøÕ¾Î´Ê¹ÓÃ×îа汾£¬Òò¶øÖÁÉÙÓÐ300Íò¸öÍøÕ¾ÈÔÃæ¶Ô·çÏÕ¡£Ö»¹ÜÉÐδ¼ì²âµ½Ò°±íÀûÓ㬵«ÈÔ½¨Ò龡¿ìÉý¼¶»ò½ûÓøòå¼þ¡£


https://www.bleepingcomputer.com/news/security/wpforms-bug-allows-stripe-refunds-on-millions-of-wordpress-sites/


6. Black BastaÀÕË÷Èí¼þÀûÓÃMS TeamsºÍµç×ÓÓʼþºäÕ¨´«²¼¶ñÒâÈí¼þ


12ÔÂ10ÈÕ£¬Black BastaÀÕË÷Èí¼þ×éÖ¯½üÆÚ¸´ËÕ£¬²¢ÌáÒéÁËÒ»³¡Õë¶ÔÈ«Çò×éÖ¯µÄ¸´ÔÓÉç»á¹¤³Ì»î¶¯¡£Rapid7×êÑÐÈËÔ±¶Ô´Ë½øÐÐÁ˾ßÌåµ÷²é£¬²¢°ä²¼ÁËÒ»·Ýл㱨¡£¹¥»÷Õßͨ¹ýµç×ÓÓʼþºäÕ¨¡¢Microsoft Teams¼ÙÒâÒÔ¼°ÀûÓÃQuickAssistºÍAnyDeskµÈ¹¤¾ß»ñȡԶ³Ì½Ó¼ûȨÏÞ£¬ÈƹýMFA²¢Ö´ÐжñÒâ¸ºÔØ¡£ÔÚ´«²¼Black BastaÀÕË÷Èí¼þ֮ǰ£¬ÍþвÐÐΪÕ߻ᲿÊðZbotºÍDarkGateµÈ¹¤¾ßÀ´»ñȡƾ֤¡¢Ð¹Â¶Êý¾ÝºÍά³ÖÓÆ¾ÃÐÔ¡£ËûÃÇʹÓÃÁ˸üеļ¼Êõ£¬Èç×Ô½ç˵´ò°ü·¨Ê½»ìºÏÓÐÐ§ÔØºÉ¡¢Í¨¹ýrundll32.exeÖ´ÐÐDLLÒÔ¼°¸ß¼¶¶ã±ÜÕ½Êõ¡£ÎªÁË»º½â´ËÀ๥»÷µÄ·çÏÕ£¬×é֯Ӧѡȡ¸ü׳´óµÄÃÜÂëÕ½Êõ¡¢Ìṩ°²È«Åàѵ²¢Ö´ÐÐÏȽøµÄ·ÀÓù´ëÊ©¡£Õâ´Î¹¥»÷»î¶¯Ê¼ÓÚµç×ÓÓʼþºäÕ¨£¬Í¨¹ýÓÕÆ­Óû§ÊÚÓèÔ¶³Ì½Ó¼ûȨÏÞ£¬×îÖÕÖ¸±êÊDz¿ÊðBlack BastaÀÕË÷Èí¼þ¼ÓÃܹؼüÊý¾Ý²¢Ë÷ÒªÊê½ð¡£


https://hackread.com/black-basta-gang-ms-teams-email-bombing-malware/