CleoÎļþ´«ÊäÈí¼þÁãÈÕ·ì϶ÔâºÚ¿ÍÀûÓýøÐÐÊý¾Ý͵ÇÔ¹¥»÷
°ä²¼¹¦·ò 2024-12-121. CleoÎļþ´«ÊäÈí¼þÁãÈÕ·ì϶ÔâºÚ¿ÍÀûÓýøÐÐÊý¾Ý͵ÇÔ¹¥»÷
12ÔÂ10ÈÕ£¬ºÚ¿ÍÔÚ»ý¼«ÀûÓÃCleoÖÎÀíÎļþ´«ÊäÈí¼þÖеÄз¢ÏÖµÄÁãÈÕ·ì϶£¬ÇÖÈëÈ«ÇòÊýǧ¼Ò¹«Ë¾ÍøÂ磬Ô̺¬Target¡¢ÎÖ¶ûÂêµÈ³ÛÃûÆóÒµ£¬½øÐÐÊý¾Ý͵ÇÔ¹¥»÷¡£¸Ã·ì϶´æÔÚÓÚCleo LexiCom¡¢VLTraderºÍHarmony²úÆ·ÖУ¬ÔÊÐí²»ÊÜÏ޶ȵÄÎļþÉÏ´«ºÍÏÂÔØ£¬µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£Ö»¹ÜCleo֮ǰÒѽ¨¸´ÁËÒ»¸öÓйطì϶CVE-2024-50623£¬µ«ÍþвÐÐΪÕßÈÔÈÆ¹ýÁ˽¨¸´³ÖÐø¹¥»÷¡£ÍøÂ簲ȫר¼ÒÖ¸³ö£¬ÕâЩ¹¥»÷ÓëеÄTermiteÀÕË÷Èí¼þÍÅ»ïÓйء£Huntress°²È«×êÑÐÈËÔ±³õ´Î·¢ÏÖÁ˸÷ì϶µÄ×Ô¶¯¹¥»÷£¬²¢ÖÒ¸æÓû§²ÉÈ¡´¹Î£Ðж¯£¬Ô̺¬½«ÏµÍ³ÒƵ½·À»ðǽºóÃæ£¬ÏÞ¶È±í²¿½Ó¼û£¬²¢²é³¿ÉÒÉÎļþ¡£CleoÒÑÈ·ÈÏ·ì϶´æÔÚ£¬²¢ÔÚ¿ª·¢°²È«¸üУ¬Í¬Ê±ÌṩÁË»º½â´ëÊ©½¨Òé¡£¾Ý¹À¼Æ£¬ÃÀ¹úÓоø´óÎÞÊýÒ×Êܹ¥»÷µÄ·þÎñÆ÷£¬È«ÇòÁìÓòÄÚÒÑÓÐÖÁÉÙÊ®¸ö×éÖ¯Êܵ½Ó°Ïì¡£
https://www.bleepingcomputer.com/news/security/new-cleo-zero-day-rce-flaw-exploited-in-data-theft-attacks/
2. AppLite Banker¶ñÒâÈí¼þÒÔÒøÐÐÀûÓ÷¨Ê½ÎªÖ¸±êÌáÒéÍøÂç´¹µö»î¶¯
12ÔÂ10ÈÕ£¬Ò»³¡¸´ÔÓµÄÍøÂç´¹µö»î¶¯ÔÚ´«²¼ÃûΪAppLite BankerµÄжñÒâÈí¼þ±äÖÖ£¬¸Ã¶ñÒâÈí¼þ±»¼ø±ðΪAntidotÒøÐÐľÂíµÄ¸üа汾£¬ÖØÒªÕë¶ÔAndroidÉ豸¡£¹¥»÷Õßͨ¹ý¼ÙÒâ³ÛÃû¹«Ë¾ÕÐÆ¸ÈËԱijÈËÁ¦×ÊÔ´´ú±í£¬·¢ËÍÍøÂç´¹µöµç×ÓÓʼþÊèµ¼Óû§ÏÂÔØÚ²ÆÐÔCRMÀûÓ÷¨Ê½£¬½ø¶ø×°ÖÃAppLite¶ñÒâÈí¼þ¡£¸Ã¶ñÒâÈí¼þÄÜÖ´ÐÐÆ¾Ö¤ÍµÇÔ¡¢ÀÄÓÃÎÞ×è°·þÎñ¡¢Ô¶³Ì½ÚÔì¡¢ºýŪÐÔ¸²¸ÇµÈ¶àÖÖ¶ñÒâ»î¶¯£¬²¢Õë¶Ô172¸öÀûÓ÷¨Ê½£¬Ô̺¬½ðÈÚÆ½Ì¨ºÍ¼ÓÃÜÇ®°ü¡£ÎªÈƹý¼ì²â£¬AppLiteʹÓÃZIPÎļþ²Ù×÷ºÍǶÈëHTML¸²¸Ç²ã»ìºÏ°²È«¹¤¾ß¡£¸Ã¶ñÒâÈí¼þ¹¥»÷ÁìÓò¿í·º£¬Éæ¼°¶àÖÖ˵»°Óû§£¬²¢ÄÜÇÔÈ¡ËøÆÁƾ֤×Ô¶¯½âËøÆÁÄ»£¬ÊµÏÖÆëÈ«½ÚÔìÊÜϰȾÉ豸¡£°²È«×êÑÐÈËԱǿµ÷×Ô¶¯·ÀÓù³ÁÒªÐÔ£¬½¨ÒéÖ´ÐÐ׳´óµÄÒÆ¶¯É豸ÖÎÀíÕþ²ß²¢¶¨ÆÚ¸üÐÂÉ豸ºÍ°²È«Èí¼þÒÔ·À±¸´ËÀàÍþв¡£
https://www.infosecurity-magazine.com/news/applite-malware-targets-banking/
3. Microsoft 365Öжϵ¼Ö Office WebÀûÓ÷¨Ê½ºÍÖÎÀíÖÐÐÄ̱»¾
12ÔÂ10ÈÕ£¬Î¢ÈíÔÚµ÷²éһ·ӰÏìOffice WebÀûÓúÍMicrosoft 365ÖÎÀíÖÐÐĵĴóÃæ»ýÇÒ³ÖÐøµÄMicrosoft 365ÖжÏÊÂÎñ¡£Óû§»ã±¨ÔÚÏνÓOutlook¡¢OneDriveºÍÆäËûOffice 365ÀûÓ÷¨Ê½ºÍ·þÎñʱ³öÏÖÎÊÌ⣬²¢ÊÕµ½·þÎñÖжϵÄÐÂÎÅ¡£Î¢ÈíÖ¸³ö£¬ÎÊÌâ¿ÉÄÜÓëÉí·ÝÑéÖ¤»ù´¡ÉèÊ©ÖеÄÁîÅÆÌìÉúÓйأ¬²¢ÔÚÉó²é×î½üµÄ±ä¶¯ÒÔÈ·¶¨µ××ÓÔÒò¡£×÷Ϊ½â¾ö²½Ö裬΢Èí½¨ÒéÊÜÓ°ÏìµÄÓû§Ê¹ÓÃ×ÀÃæÀûÓ÷¨Ê½½Ó¼ûMicrosoft 365ÀûÓ÷¨Ê½ºÍÎĵµ¡£´Ëǰ£¬Microsoft 365Ò²Ôø²úÉú¹ýÈ«ÇòÖжÏÊÂÎñ£¬Ô̺¬Ó°Ïì¶àÏî·þÎñºÍÖ°ÄܵÄÇé¿ö¡£¶øÔÚ7Ô£¬Ò»´Î´ó¹æÄ£ÖжÏÔòÊÇÓÉÉ¢²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©¹¥»÷ÒýÆðµÄ¡£Ä¿Ç°£¬Î¢ÈíÔÚ²âÊÔÒ»¸öDZÔڵĽ¨¸´·¨Ê½£¬²¢ÒѲ¿ÊðÁËÒ»¸ö½¨¸´·¨Ê½ÒÔ»º½âÖжÏÎÊÌ⡣΢Èí°µÊ¾£¬Õâ´ÎÖжÏÊÇÓÉÓÚ×î½üµÄ·þÎñµ÷»»µ¼Ö¼ø±ðÁîÅÆµ½ÆÚ¹¦·ò³öÏÖÎÊÌ⣬´Ó¶øµ¼ÖÂÉí·ÝÑéÖ¤ÒªÇóʧ°Ü¡£¾¹ýÒ»¶Î¹¦·òµÄ¼à¿Ø·þÎñÒ£²âºó£¬¸Ã¹«Ë¾È·ÈϸÃÎÊÌâÏÖÒѽâ¾ö¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-365-outage-takes-down-office-web-apps-admin-center/
4. MetaÆìÏÂËÄ´óÉ罻ƽ̨ÔâÈ«ÇòÁìÓò¹¥»÷Ö·þÎñÖжÏ
12ÔÂ11ÈÕ£¬È«ÇòÁìÓòÄÚµÄFacebook¡¢Instagram¡¢ThreadsºÍWhatsAppÔâ·êÁËÑϳÁ¹¥»÷£¬µ¼Ö·þÎñÖжϣ¬·ÖÆçµØÓòµÄÓû§Êܵ½ÁË·ÖÆçˮƽµÄÓ°Ïì¡£¾ÝDownDetector³Æ£¬ÖжϲúÉúÔÚÃÀ¹ú¶«²¿¹¦·òÏÂÎç12:40×óÓÒ£¬ºÜ¶àÓû§ÎÞ·¨Í¨¹ýÍøÕ¾ºÍÀûÓ÷¨Ê½½Ó¼ûÕâЩ·þÎñ£¬Ò²ÎÞ·¨Í¨¹ýWhatsApp·¢ËÍÐÂÎÅ¡£µ±Óû§³¢ÊÔ½Ó¼ûFacebookʱ£¬»áÊÕµ½ÃýÎóÌáÐÑ¡£¹ÌÈ»MetaµÄÒµÎñÆ½Ì¨×´Ì¬Ò³ÃæÃ»ÓÐÏÔʾ´ó¹æÄ£·þÎñÖжϣ¬µ«MetaÈÏ¿ÉÁËÖжϵIJúÉú£¬²¢°µÊ¾ÔÚÖÂÁ¦¸´Ô·þÎñ¡£²¿ÃŵØÓòµÄ·þÎñÔÚÃÀ¹ú¶«²¿¹¦·òÏÂÎç1:20×óÓÒÆðÍ·¸´Ô£¬µ«ÈÔÓÐЧ»§»ã±¨ÎÞ·¨½Ó¼ûƽ̨¡£´Ëǰ£¬MetaÔøÔÚ3Ô·ݺÍ2021ÄêÔâ·ê¹ýÀàËÆµÄ·þÎñÖжϡ£½ØÖÁÃÀ¹ú¶«²¿¹¦·ò12ÔÂ11ÈÕÏÂÎç7:21£¬Meta°µÊ¾ÖжÏÎÊÌâÒѸù»ù½â¾ö£¬²¢ÏòÊÜÓ°ÏìµÄÓû§°µÊ¾Ç¸Òâ¡£
https://www.bleepingcomputer.com/news/technology/facebook-instagram-whatsapp-hit-by-massive-worldwide-outage/
5. ¹ú¼ÊÐж¯¡°Operation PowerOFF¡±³ÁȽø¹¥DDoS³ö×â·þÎñ
12ÔÂ11ÈÕ£¬¹ú¼ÊÐж¯¡°Operation PowerOFF¡¹Øë¶ÔÍøÂç·¸×ïÖеÄÉ¢²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©¹¥»÷»ñµÃÁËÏÔÖø³É¾Í¡£À´×Ô15¸ö¹ú¶ÈµÄ·¨ÂÉ»ú¹¹ºÏ×÷£¬³É¹¦ÏÂÏßÁË27¸öDDoS³ö×â·þÎñƽ̨£¬¿ÛÁôÁËÈýÃûÖÎÀíÔ±£¬²¢È·¶¨ÁËÕâЩƽ̨µÄ300Ãû¿Í»§¡£ÕâЩƽ̨ÀûÓý©Ê¬ÍøÂç¶ÔÔÚÏßÖ¸±êÌáÒé¹¥»÷£¬¿ÉÄܵ¼Ö·þÎñÖжϺÍÒµÎñËðʧ£¬³ö¸ñÊÇÔÚÍøÉϹºÎï¶¥·åÆÚ¡£Å·ÖÞÐ̾¯×é֯е÷ÁËÕâ´ÎÐж¯£¬Éæ¼°¶à¸ö¹ú¶È£¬Õë¶Ô²Î¼Ó´ËÀà·¸×ïµÄ¸÷¸ö²ãÃæµÄÈËÔ±¡£ÆäÖУ¬ºÉÀ¼¾¯·½¿ÛÁôÁËËÄÃûÉæÏÓÖ´ÐÐDDoS¹¥»÷µÄÏÓÒÉÈË£¬²¢È·¶¨ÁËÔ¼200ÃûÉæÏÓʹÓñ»²é»ñDDoS·þÎñµÄºÉÀ¼ÈË¡£Õâ´ÎÐж¯µÄ³É¹¦µÃÒæÓÚÅ·ÖÞÐ̾¯×éÖ¯µÄ·ÖÎöÖ§³Ö¡¢¼ÓÃÜ×·×ÙÐÅÏ¢ÒÔ¼°½áºÏÍøÂç·¸×ï×´¶¯³ö¸ñ¹¤×÷×éר¼ÒµÄÐÖú¡£´Ëǰ£¬¡°Operation PowerOFF¡±ÒѶÔDDoS×âÁÞÁìÓò½øÐÐÁËÂŴνø¹¥£¬Ô̺¬²é·â´óÐÍÆ½Ì¨Dstat.ccºÍÈëÇÖ²¢¹Ø¹ØDigitalStress·þÎñ¡£
https://www.bleepingcomputer.com/news/security/operation-poweroff-shuts-down-27-ddos-for-hire-platforms/
6. Krispy KremeÔâÍøÂç¹¥»÷£¬Ó°ÏìÔÚÏß¶©¹ººÍÔËÓª
12ÔÂ11ÈÕ£¬ÃÀ¹úÌðÌðȦÁ¬ËøµêKrispy KremeÔÚ2024Äê11ÔÂÔâ·êÁËÍøÂç¹¥»÷£¬µ¼ÖÂÆäÔÚÃÀ¹úµÄÔÚÏß¶©¹ºÏµÍ³Öжϣ¬Ó°ÏìÁ˲¿ÃÅÒµÎñÔËÓª¡£¸Ã¹«Ë¾Õ¼ÓÐ1,521¼ÒÃŵêºÍ¶à¶àÔ±¹¤£¬²¢ÓëÂóµ±À͵ȺÏ×÷ͬ°éÓлý¼«¹ØÏµ¡£Êý×Ö¶©µ¥Õ¼¹«Ë¾ÏúÊÛ¶îµÄ15.5%£¬¶Ô¹«Ë¾Òµ¼¨ÓгÁÒªÓ°Ïì¡£ÔÚ¹¥»÷²úÉúºó£¬Krispy Kremeµ±¼´×·Çó¶¥¼âÍøÂ簲ȫר¼ÒµÄÔ®ÊÖ£¬²¢²ÉÈ¡´ëÊ©½ÚÔìºÍ²¹¾ÈÊÂÎñ£¬µ«µ÷²éÈÔÔÚ½øÐÐÖУ¬¾ßÌåÓ°ÏìÉдýÆÀ¹À¡£Õâ´Î¹¥»÷¶Ô¹«Ë¾µÄÒµÎñ²úÉúÁ˳Á´óÓ°Ï죬²¢½«³ÖÐøµ½¸´ÔʵÏÖΪֹ¡£Í¬Ê±£¬¹«Ë¾Ô¤¼ÆÊý×ÖÏúÊÛÊÕÈëµÄËðʧ¡¢ÍøÂ簲ȫר¼ÒºÍÕÕ·÷µÄÓöÈÒÔ¼°ÏµÍ³¸´Ô¹¤×÷Óйصijɱ¾½«²úÉú³Á´óµÄ²ÆÕþÓ°Ïì¡£Êг¡¶Ô´ËÐÂÎÅ×ö³öÁ˸ºÃæ·´Ó³£¬Krispy KremeµÄ¹É¼Û×ÅÂäÁË2%¡£Ä¿Ç°Éв»Ã÷ÏÔÕâÊÇÒ»´ÎÀÕË÷Èí¼þ¹¥»÷»¹ÊÇÆäËûÀàÐ͵Ĺ¥»÷£¬Ò²Ã»ÓÐÀÕË÷Èí¼þ×éÖ¯¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü¡£
https://www.bleepingcomputer.com/news/security/krispy-kreme-cyberattack-impacts-online-orders-and-operations/


¾©¹«Íø°²±¸11010802024551ºÅ