Binarly·¢Ã÷Ó°ÏìUEFIÖÐͼÏñÆÊÎö×é¼þµÄÎó²îLogoFAIL
Ðû²¼Ê±¼ä 2023-12-04¾ÝýÌå11ÔÂ30ÈÕ±¨µÀ£¬£¬£¬£¬Binarly·¢Ã÷ÁËͳ³ÆÎªLogoFAILµÄ¶à¸öÇå¾²Îó²î£¬£¬£¬£¬¿ÉÓ°Ïì¸÷¸ö¹©Ó¦É̵ÄUEFI´úÂëÖеÄͼÏñÆÊÎö×é¼þ¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ½«¶ñÒâͼÏñ»òlogo´æ´¢ÔÚEFIϵͳ·ÖÇø(ESP)»ò¹Ì¼þ¸üеÄδÊðÃû²¿·ÖÖС£¡£¡£ÒÔÕâÖÖ·½·¨Ö²Èë¶ñÒâÈí¼þ¿ÉÈ·±£ÔÚϵͳÖÐÒ»Á¬±£´æ£¬£¬£¬£¬ÏÕЩ²»»á±»·¢Ã÷¡£¡£¡£BinarlyÒѾȷ¶¨Ó¢Ìضû¡¢ºê³ž¡¢åÚÏëºÍÆäËü¹©Ó¦É̵ÄÊý°Ù¸öÐͺſÉÄܱ£´æÎó²î£¬£¬£¬£¬¶¨ÖÆUEFI¹Ì¼þ´úÂëµÄÈý´ó×ÔÁ¦ÌṩÉÌAMI¡¢InsydeºÍPhoenixÒ²ÊÇÔÆÔÆ¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬¸ÃÎó²îµÄÏêϸӰÏì¹æÄ£ÈÔÔÚÈ·¶¨ÖС£¡£¡£
https://www.bleepingcomputer.com/news/security/logofail-attack-can-install-uefi-bootkits-through-bootup-logos/
2¡¢ÃÀ¹ú¹«Ë¾StaplesÔâµ½ÍøÂç¹¥»÷ÓªÒµÔËÓªÊܵ½Ó°Ïì
ýÌå11ÔÂ30Èճƣ¬£¬£¬£¬ÃÀ¹ú°ì¹«ÓÃÆ·ÁãÊÛÉÌStaplesÔâµ½ÍøÂç¹¥»÷ºó¹Ø±ÕÁ˲¿·Öϵͳ¡£¡£¡£×ÔÉÏÖÜÒ»ÒÔÀ´£¬£¬£¬£¬StaplesÓöµ½ÁËÖÖÖÖÄÚ²¿ÔËÓªÎÊÌ⣬£¬£¬£¬°üÀ¨ÎÞ·¨»á¼ûZendesk¡¢VPNÔ±¹¤ÃÅ»§¡¢´òÓ¡µç×ÓÓʼþºÍʹÓõ绰Ïߵȡ£¡£¡£ÓÐÔ±¹¤³Æ£¬£¬£¬£¬Ò»Çж¼´¦ÓÚå´»ú״̬£¬£¬£¬£¬ÔÚÃŵêÊÂÇéÎÞ·¨»á¼ûµç×ÓÓʼþ¡¢bizfit¡¢pogsºÍµç×ÓЧÀĮ́¡£¡£¡£StaplesÌåÏÖËûÃÇÔÚ11ÔÂ27ÈÕ·¢Ã÷¹¥»÷ºóÁ¬Ã¦½ÓÄÉÁËÏìÓ¦²½·¥£¬£¬£¬£¬µ«Õâµ¼ÖÂØÊºǫ́´¦Öóͷ£ºÍ½»¸¶ÒÔ¼°Í¨Ñ¶ÇþµÀºÍ¿Í»§Ð§ÀÍÔÝʱÖÐÖ¹¡£¡£¡£¾ÝϤ£¬£¬£¬£¬Õâ´Î¹¥»÷ÖÐûÓÐ×°ÖÃÀÕË÷Èí¼þ£¬£¬£¬£¬Ò²Ã»ÓÐÎļþ±»¼ÓÃÜ¡£¡£¡£
https://www.bleepingcomputer.com/news/security/staples-confirms-cyberattack-behind-service-outages-delivery-issues/
3¡¢Ô¼60¼ÒÐÅÓÃÏàÖúÉçÒò¹©Ó¦É̱»ÀÕË÷¹¥»÷ЧÀÍÔÝʱÖÐÖ¹
12ÔÂ2ÈÕ±¨µÀ³Æ£¬£¬£¬£¬ÔÆÐ§ÀÍÌṩÉÌOngoing OperationsÔâµ½ÁËÀÕË÷¹¥»÷£¬£¬£¬£¬ËüÁ¥ÊôÓÚÐÅÓÃÉçÊÖÒÕ¹«Ë¾Trellance¡£¡£¡£¹ú¼ÒÐÅÓÃÉçÖÎÀí¾Ö(NCUA)ÌåÏÖ£¬£¬£¬£¬²¿·ÖÐÅÓÃÉçÊÕµ½ÁËÀ´×ÔOngoing OperationsµÄÐÅÏ¢£¬£¬£¬£¬Í¸Â¶¸Ã¹«Ë¾ÔÚ11ÔÂ26ÈÕÔâµ½ÁËÀÕË÷¹¥»÷¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬ÊÓ²ìÈÔÔÚ¾ÙÐÐÖУ¬£¬£¬£¬ÏÖÒÑÈ·ÈÏÔ¼60¼ÒÐÅÓÃÏàÖúÉçÓÉÓÚµÚÈý·½Ð§ÀÍÌṩÉÌÔâµ½¹¥»÷£¬£¬£¬£¬ÕýÔÚÂÄÀúÒ»¶¨Ë®Æ½µÄЧÀÍÖÐÖ¹¡£¡£¡£
https://therecord.media/credit-unions-facing-outages-due-to-ransomware
4¡¢Å²ÍþÀ͹¤ºÍ¸£ÀûÖÎÀí¾ÖÒòÊý¾Ýй¶±»·£¿£¿£¿£¿£¿£¿î185ÍòÃÀÔª
¾Ý12ÔÂ3ÈÕ±¨µÀ£¬£¬£¬£¬Å²ÍþÀ͹¤ºÍ¸£ÀûÖÎÀí¾Ö(NAV)±»Å²Íþî¿Ïµ¾Ö£¨Datatilsynet£©·£¿£¿£¿£¿£¿£¿î170ÍòÅ·Ôª¡£¡£¡£Å²ÍþÊý¾Ý±£»£»£»£»£»£»¤¾ÖÔÚNAVµÄÉó¼ÆÖз¢Ã÷ÁË12ÆðÎ¥·´Ð¡ÎÒ˽¼ÒÊý¾Ý±£»£»£»£»£»£»¤ÌõÀýµÄÐÐΪ¡£¡£¡£×÷ΪÊÓ²ìµÄÒ»²¿·Ö£¬£¬£¬£¬DPA·¢Ã÷¿ØÖÆÕßδÄܽÓÄÉÊʵ±µÄÊÖÒÕºÍ×éÖ¯²½·¥À´±£»£»£»£»£»£»¤Ð¡ÎÒ˽¼ÒÊý¾Ý£¬£¬£¬£¬ÀýÈçITϵͳûÓлñµÃ³ä·ÖµÄ±£»£»£»£»£»£»¤¡£¡£¡£±ðµÄ£¬£¬£¬£¬¹ý¶àµÄÔ±¹¤¿ÉÒÔ»á¼ûСÎÒ˽¼ÒÊý¾Ý£¬£¬£¬£¬ÔÚijЩÇéÐÎϰüÀ¨ºÜÊÇÃô¸ÐµÄÊý¾Ý¡£¡£¡£Í¬Ê±£¬£¬£¬£¬¿ØÖÆÕßδÄܶÔÔ±¹¤Ê¹ÓÃITϵͳ¾ÙÐÐϵͳµÄ¿ØÖÆ¡£¡£¡£
https://www.databreaches.net/norwegian-labor-and-welfare-administration-fined-for-data-protection-failures/
5¡¢Unit 42Åû¶Õë¶ÔÖж«¡¢·ÇÖÞºÍÃÀ¹úµÈµØµÄ¹¥»÷»î¶¯
Unit 42ÔÚ12ÔÂ1ÈÕÅû¶ÁËкóÃÅAgent Raccoon£¬£¬£¬£¬Ëü±»ÓÃÓÚÕë¶ÔÖж«¡¢·ÇÖÞºÍÃÀ¹úµÈµØµÄ¹¥»÷»î¶¯¡£¡£¡£¸Ã»î¶¯Ö÷ÒªÕë¶Ô½ÌÓý¡¢·¿µØ²ú¡¢ÁãÊÛ¡¢·ÇÓªÀû×éÖ¯¡¢µçÐŹ«Ë¾ºÍÕþ¸®»ú¹¹£¬£¬£¬£¬¹¥»÷ÍŻﱻUnit 42×·×ÙΪCL-STA-0002¡£¡£¡£ºóÃÅÓÃ.NET¿ª·¢£¬£¬£¬£¬²¢Ê¹ÓÃÓòÃûЧÀÍ(DNS)ÐÒéÓëC2»ù´¡ÉèÊ©½¨ÉèÒþ²ØµÄͨѶͨµÀ¡£¡£¡£Agent RaccoonÔÚ¶à´Î¹¥»÷ÖÐÓëÆäËüÁ½¸ö¹¤¾ßÁ¬ÏµÊ¹Ó㬣¬£¬£¬ÆäÖÐÒ»¸öÊÇÇÔÈ¡Óû§Æ¾Ö¤µÄNetwork Provider DLLÄ£¿£¿£¿£¿£¿£¿éNtospy£¬£¬£¬£¬ÁíÒ»¸öÊDZ»³ÆÎªMimiliteµÄ¶¨ÖưæMimikatz¡£¡£¡£
https://unit42.paloaltonetworks.com/new-toolset-targets-middle-east-africa-usa/
6¡¢KasperskyÐû²¼2023ÄêQ3 ITÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ
12ÔÂ1ÈÕ£¬£¬£¬£¬KasperskyÐû²¼ÁË2023ÄêµÚÈý¼¾¶ÈITÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£±¨¸æÖÐÌá¼°µÄÓÐÕë¶ÔÐԵĹ¥»÷ÆÊÎö°üÀ¨£ºÊ¹ÓÃDroxiDatºÍCobalt Strike¹¥»÷ÄÜÔ´ÐÐÒµ¡¢Ê¹ÓÃCVE-2023-23397Îó²îµÄ¹¥»÷¡¢Õë¶Ô¹¤¿ØÐÐÒµµÄ¹¥»÷Öг£¼ûµÄTTPºÍαÔìµÄTelegramÓ¦Óõȡ£¡£¡£ÆäËü¶ñÒâÈí¼þ°üÀ¨£ºÕë¶ÔLinuxµÄ¹©Ó¦Á´¹¥»÷¡¢CubaÀÕË÷ÍŻй¶µÄLockbit 3¹¹½¨Æ÷¡¢Ò»Ö±Éú³¤µÄ¶ñÒâÈí¼þÃûÌÃÒÔ¼°cryptor¡¢stealerºÍbanking TrojanµÈ¡£¡£¡£
https://securelist.com/it-threat-evolution-q3-2023/111171/


¾©¹«Íø°²±¸11010802024551ºÅ