SloppyLemmingʹÓÃCloudflare WorkersµÈ¹¤¾ß·¢¶¯Ìع¤¹¥»÷
Ðû²¼Ê±¼ä 2024-09-279ÔÂ25ÈÕ£¬£¬£¬£¬¸ß¼¶Ò»Á¬ÐÔÍþв£¨APT£©×éÖ¯¡°SloppyLemming¡±½üÆÚ±»·¢Ã÷ʹÓÃCloudflareµÄWorkerÔÆÐ§ÀÍÒÔ¼°Discord¡¢Dropbox¡¢GitHubµÈ¹¤¾ß£¬£¬£¬£¬ÔÚÓ¡¶È´Î´ó½¼°ÖܱߵØÇø¶ÔÕþ¸®ºÍÖ´·¨»ú¹¹¾ÙÐÐÆÕ±éµÄÌØ¹¤»î¶¯¡£¡£¡£¸Ã×éÖ¯±»Crowdstrike×·×ÙΪ¡°Outrider Tiger¡±£¬£¬£¬£¬ÆäÐж¯Óë´ÓÓ¡¶È¼°Öܱ߹ú¼ÒÃô¸Ð×éÖ¯ÇÔÈ¡Ç鱨¸ß¶ÈÏà¹Ø¡£¡£¡£Êܺ¦Õß°üÀ¨Õþ¸®»ú¹¹¡¢ITºÍµçÐÅÆóÒµ¡¢ÐÞ½¨¹«Ë¾£¬£¬£¬£¬ÉõÖÁ°Í»ù˹̹µÄºËµçÉèÊ©£¬£¬£¬£¬ÇÒ¹¥»÷¹æÄ£»¹À©Õ¹ÖÁÃϼÓÀ¹ú¡¢Ë¹ÀïÀ¼¿¨¼°ÖйúµÄÄÜÔ´ÓëѧÊõ»ú¹¹£¬£¬£¬£¬ÉõÖÁ¿ÉÄÜ´¥¼°°Ä´óÀûÑÇÊ×¶¼¿°ÅàÀ¡£¡£¡£SloppyLemmingͨ¹ýÈ«ÐÄÉè¼ÆµÄÓã²æÊ½ÍøÂç´¹ÂÚÓʼþÆô¶¯¹¥»÷£¬£¬£¬£¬Ê¹ÓÃCloudflare WorkersÕâÒ»ÎÞЧÀÍÆ÷ÅÌËãÆ½Ì¨Ö´ÐжñÒâ¾ç±¾£¬£¬£¬£¬×èµ²²¢²Ù×÷Á÷¾CloudflareµÄWebÁ÷Á¿£¬£¬£¬£¬ÒÔÇÔÈ¡µÇ¼ƾ֤ºÍй¶µç×ÓÓʼþ¡£¡£¡£±ðµÄ£¬£¬£¬£¬SloppyLemming»¹¿ª·¢ÁËÃûΪ¡°CloudPhish¡±µÄ¶¨Öƹ¤¾ß£¬£¬£¬£¬×¨ÃÅÓÃÓÚÆ¾Ö¤ÇÔÈ¡ºÍй¶£¬£¬£¬£¬Í¨¹ýÄ£ÄâÄ¿µÄWebmailµÇÂ¼Ò³ÃæÀ´ÓÕÆÓû§ÊäÈëÐÅÏ¢¡£¡£¡£Í¬Ê±£¬£¬£¬£¬¸Ã×éÖ¯»¹Ê¹ÓÃGoogle OAuthÁîÅÆÍøÂçºÍRARÎļþÎó²îʹÓã¨CVE-2023-38831£©µÈÊֶΣ¬£¬£¬£¬¹¹½¨ÖØ´óµÄ¹¥»÷Á´£¬£¬£¬£¬½øÒ»²½¼Ó¾çÁËÇå¾²Íþв¡£¡£¡£
https://www.darkreading.com/cloud-security/sloppylemming-apt-cloudflare-pakistan-attacks
2. ·¨¹ú9500ÍòÌõ¹«ÃñÊý¾ÝÔâй¶£¬£¬£¬£¬Éæ¼°¶àÐÐÒµÐÅÏ¢
9ÔÂ25ÈÕ£¬£¬£¬£¬·¨¹ú½üÆÚ±¬·¢ÁËÒ»ÆðÕ𾪵ÄÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬Éæ¼°Áè¼Ý9500ÍòÌõ¹«ÃñÊý¾Ý¼Í¼±»¹ûÕæÖÃÓÚ»¥ÁªÍøÉÏ£¬£¬£¬£¬Ô¶³¬·¨¹ú×ÜÉú³ÝÊý£¬£¬£¬£¬Êý¾Ý¹æÄ£º¸ÇÐÕÃû¡¢ÁªÏµ·½·¨¡¢µç×ÓÓʼþ¼°²¿·ÖÖ§¸¶ÐÅÏ¢µÈÃô¸ÐÄÚÈÝ¡£¡£¡£´Ë´ÎÊÂÎñÓÉCybernewsÓëÍøÂçÇ徲ר¼ÒÅäºÏ½ÒÆÆ£¬£¬£¬£¬Ô´Í·Ö¸ÏòÒ»¸ö¿ª·ÅµÄElasticsearchЧÀÍÆ÷¡°vip-v3¡±£¬£¬£¬£¬ÎÞÐèÈÏÖ¤¼´¿É»á¼û£¬£¬£¬£¬ÄÚº¬ÖÁÉÙ30GBÊý¾Ý£¬£¬£¬£¬Ô´ÓÚ17Æð²î±ðµÄÊý¾Ýй¶Ê¹ʡ£¡£¡£Ð¹Â¶Êý¾Ý²»µ«ÊýÄ¿ÖØ´ó£¬£¬£¬£¬ÇÒÖÖÀà·±¶à£¬£¬£¬£¬Éæ¼°µçÐÅ¡¢µçÉÌ¡¢É罻ýÌåµÈ¶à¸öÐÐÒµ£¬£¬£¬£¬°üÀ¨×ÅÃû¹«Ë¾ÈçLycamobile¡¢Pandabuy¡¢Darty¡¢Discord¼°SnapchatµÈ£¬£¬£¬£¬·´Ó¦ÁËÊý¾Ýй¶ÎÊÌâµÄÆÕ±éÐÔºÍÑÏÖØÐÔ¡£¡£¡£ÓÈΪֵµÃ¹Ø×¢µÄÊÇ£¬£¬£¬£¬Êý¾Ý¿â¹ûÕæ×´Ì¬ÒÑÒ»Á¬Ò»¶Îʱ¼ä£¬£¬£¬£¬²»É¨³ýÒÑÓжñÒâµÚÈý·½¸´ÖÆÊý¾ÝÓÃÓÚ²»·¨»î¶¯¡£¡£¡£±ðµÄ£¬£¬£¬£¬¸ÃÐÐΪÏÔ×ÅÎ¥·´ÁËÅ·ÃËGDPR¹æÔò£¬£¬£¬£¬ÏÔʾ³öÊý¾Ý¿âÖÎÀíÕß¶ÔÖ´·¨µÄÎÞÊÓ¼°Ç±ÔڵĶñÒâÄ¿µÄ¡£¡£¡£Ñо¿Ö°Ô±ÖÒÑÔ£¬£¬£¬£¬ÔÆÔƼ¯ÖÐÇÒÏ꾡µÄСÎÒ˽¼ÒÐÅϢ̻¶£¬£¬£¬£¬½«¼«´óÌáÉýÉí·Ý͵ÇÔ¡¢Ú²Æ¼°ÍøÂç¹¥»÷µÄΣº¦£¬£¬£¬£¬¶ÔÊý°ÙÍòСÎÒ˽¼Ò¼°ÆóÒµ×é³ÉÍþв¡£¡£¡£
https://cybernews.com/security/french-records-exposed-by-mysterious-data-hoarder/
3. ÃÀ¹ú¹ú»á³¬3000ÃûÊÂÇéÖ°Ô±ÐÅÏ¢Ôâ°µÍøÐ¹Â¶
9ÔÂ26ÈÕ£¬£¬£¬£¬ÃÀ¹ú¹ú»á´óÏýüÆÚ³ÉΪ´ó¹æÄ£ÍøÂç¹¥»÷µÄÊܺ¦Õߣ¬£¬£¬£¬µ¼ÖÂÁè¼Ý3,000Ãû¹ú»áÊÂÇéÖ°Ô±µÄÃô¸ÐСÎÒ˽¼ÒÐÅÏ¢ÔÚ°µÍøÉÏÆØ¹â¡£¡£¡£¾ÝProtonºÍConstella Intelligence¹«Ë¾µÄÑо¿·¢Ã÷£¬£¬£¬£¬ÕâЩй¶Êý¾Ý°üÀ¨ÃÜÂë¡¢IPµØµã¼°É罻ýÌåÐÅÏ¢£¬£¬£¬£¬¹²¼ÆÔ¼3,191Ìõ¼Í¼£¬£¬£¬£¬ÆäÖнüÎå·ÖÖ®Ò»µÄ¹ú»áÔ±¹¤Êܵ½²¨¼°¡£¡£¡£ÌØÊâÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬£¬²¿·ÖÔ±¹¤Òò²»Á¼Ï°¹ß£¬£¬£¬£¬ÈçʹÓùٷ½ÓÊÏä×¢²á°üÀ¨Ô¼»áºÍ³ÉÈËÍøÕ¾µÈ¸ßΣº¦ÍøÕ¾£¬£¬£¬£¬µ¼ÖÂÐÅÏ¢±»¶à´Îй¶£¬£¬£¬£¬×î¸ßµ¥ÀýÉæ¼°31¸öÃÜÂë¡£¡£¡£ProtonÖ¸³ö£¬£¬£¬£¬ÕâÖÖ½«ÊÂÇéÓÊÏäÓë²»Ç徲ƽ̨°ó¶¨µÄÐÐΪ×é³ÉÁËÑÏÖØÇå¾²Îó²î¡£¡£¡£¹«Ë¾ÔÊÐí½«½øÒ»²½Ðû²¼ÊÓ²ìЧ¹û£¬£¬£¬£¬²¢Ç¿µ÷ÔÚ×Üͳѡ¾Ùʱ´úÔöÇ¿·À»¤µÄÖ÷ÒªÐÔ¡£¡£¡£Í¬Ê±£¬£¬£¬£¬¹«Ë¾ÒÑÏòËùÓÐÊÜÓ°ÏìµÄ¹ú»áÊÂÇéÖ°Ô±·¢³ö¾¯Ê¾¡£¡£¡£±ðµÄ£¬£¬£¬£¬½ñÄê6Ô£¬£¬£¬£¬Í³Ò»ÊÓ²ìÍŶӻ¹·¢Ã÷Êý°ÙÃûÓ¢¹ú¼°Å·ÃËÕþ¿ÍµÄСÎÒ˽¼ÒÐÅϢͬÑùÔÚ°µÍøÊг¡ÉÏÁ÷ͨ£¬£¬£¬£¬°üÀ¨µç×ÓÓÊÏä¡¢ÃÜÂë¼°³öÉúÈÕÆÚµÈÃô¸ÐÊý¾Ý£¬£¬£¬£¬Í¹ÏÔÁËÈ«ÇòÕþÖÎÁìÓòÃæÁÙµÄÍøÂçÇå¾²ÌôÕ½¡£¡£¡£
https://securityaffairs.com/168912/deep-web/3000-congressional-staffers-data-leaked-dark-web.html
4. Unit 42Õ¹ÏÖRomCom¶ñÒâÈí¼þбäÖÖSnipBot
9ÔÂ25ÈÕ£¬£¬£¬£¬Unit 42Çå¾²ÍŶӽüÆÚ½ÒÆÆÁËÎÛÃûÕÑÖøµÄRomCom¶ñÒâÈí¼þ¼Ò×åµÄбäÖÖ¡°SnipBot¡±£¬£¬£¬£¬¸Ã±äÖÖÓÚ2024Äêͷո¶ͷ½Ç£¬£¬£¬£¬×¨ÎªÆóÒµÍøÂçÉè¼Æ£¬£¬£¬£¬¾ß±¸Ô¶³Ì²Ù¿ØÓë¶ñÒâ¸ºÔØÏÂÔØÄÜÁ¦¡£¡£¡£SnipBotÒÔÆäÁ¢ÒìµÄ´úÂë»ìÏýÊÖÒպ͸߼¶·´¼ì²âÕ½ÂÔÎªÌØµã£¬£¬£¬£¬±»ÍƲâΪÕë¶ÔITЧÀÍ¡¢ÆóÒµ·¨È˼°Å©ÒµµÈÐÐÒµÌᳫµÄÆÕ±éÍøÂç¹¥»÷µÄÒ»²¿·Ö¡£¡£¡£2024Äê4Ô£¬£¬£¬£¬Unit 42²¶»ñµ½Ò»¸öÒì³£DLLÄ£¿£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬È·ÒÔΪSnipBot¹¤¾ß°ü×é¼þ¡£¡£¡£Í¨¹ýÉîÈëÆÊÎö£¬£¬£¬£¬Ñо¿Ö°Ô±»¹ÔÁËSnipBotµÄѬȾ·¾¶¼°ºóÐø»î¶¯¡£¡£¡£ÆäѬȾʼÓÚαװ³ÉÕýµ±PDFÎļþµÄ´¹ÂÚÓʼþ£¬£¬£¬£¬ÄÚº¬¶ñÒâ¿ÉÖ´ÐÐÎļþ¡£¡£¡£Ò»µ©ÈëÇÖÀֳɣ¬£¬£¬£¬SnipBot¸¶Óë¹¥»÷ÕßÖÜÈ«¿ØÖÆÈ¨£¬£¬£¬£¬ÔÊÐíÆäÖ´ÐÐí§ÒâÏÂÁî¡¢ËѼ¯ÏµÍ³ÐÅÏ¢¼°ÇÔÈ¡Êý¾Ý¡£¡£¡£Í¬Ê±£¬£¬£¬£¬SnipBotÄÜÏÂÔØÈçSnippingTool.dll¡¢svcnet.exeµÈÌØÊâÄ£¿£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬ÔöÇ¿¹¥»÷ÄÜÁ¦¡£¡£¡£Unit 42ÊӲ쵽£¬£¬£¬£¬¹¥»÷ÕßÌØÊâ¹Ø×¢´ÓÊܺ¦ÕßÍøÂçÖÐÌáÈ¡Êý¾Ý£¬£¬£¬£¬ÓÈÆäÊÇÓò¿ØÖÆÆ÷ÐÅÏ¢£¬£¬£¬£¬Ê¹ÓÃPuTTY¡¢WinRARµÈÕýµ±¹¤¾ß¼°fsutil.exe¡¢dsutil.exeµÈαװִÐжñÒâ²Ù×÷¡£¡£¡£Ö»¹ÜRomCom¼Ò×å³£ÓëÀÕË÷Èí¼þ»î¶¯Ïà¹ØÁª£¬£¬£¬£¬µ«SnipBotµÄÐÐΪģʽÏÔʾ³öÆäÕýתÏòÇé±¨ÍøÂçÓëÌØ¹¤»î¶¯¡£¡£¡£
https://securityonline.info/new-romcom-variant-snipbot-unveiled-a-sophisticated-malware-targeting-enterprise-networks/
5. ÆðÑǾÏúÉÌÍøÕ¾ÏÖÑÏÖØÎó²î£ººÚ¿Í¿Éƾ³µÅƺÅÔ¶³Ì¿ØÖÆÊý°ÙÍò³µÁ¾
9ÔÂ26ÈÕ£¬£¬£¬£¬Çå¾²ÁìÓò½üÆÚÆØ³öÒ»ÆðÕë¶ÔÆðÑÇÆû³µµÄÇå¾²Îó²îÊÂÎñ£¬£¬£¬£¬¸ÃÎó²îÉæ¼°ÆðÑÇÆû³µ¾ÏúÉÌÃÅ»§ÍøÕ¾£¬£¬£¬£¬Ê¹µÃºÚ¿Í½öƾ³µÅƺžÍÄÜÔÚ¼«¶Ìʱ¼äÄÚÔ¶³Ì¿ØÖÆÊý°ÙÍòÁ¾2013ÄêºóÉú²úµÄÆðÑÇÆû³µ¡£¡£¡£ÕâÒ»·¢Ã÷×·ËÝÖÁ½ñÄê6Ô£¬£¬£¬£¬ÓÉÇå¾²Ñо¿Ô±ÈøÄ·-¿âÀïµÈÈË½ÒÆÆ¡£¡£¡£ÓëÈ¥ÄêÆØ¹âµÄÉæ¼°¶à¼ÒÆû³µÆ·ÅƵÄÎó²îÀàËÆ£¬£¬£¬£¬´Ë´ÎÆðÑÇÎó²î²»µ«ÈúڿÍÄÜÔ¶³Ì²Ù¿Ø³µÁ¾£¬£¬£¬£¬»¹Ì»Â¶Á˳µÖ÷µÄÃô¸ÐСÎÒ˽¼ÒÐÅÏ¢£¬£¬£¬£¬ÈçÐÕÃû¡¢ÁªÏµ·½·¨¼°µØµã¡£¡£¡£Ñо¿Ö°Ô±Í¨¹ý×¢²á¾ÏúÉÌÕË»§²¢»ñÈ¡»á¼ûÁîÅÆ£¬£¬£¬£¬ÀÖ³ÉÉøÍ¸ºó¶ËAPI£¬£¬£¬£¬½ø¶øÊµÏÖ¶Ô³µÁ¾¼°³µÖ÷Êý¾ÝµÄÖÜÈ«»á¼û¡£¡£¡£ËûÃÇ¿ª·¢ÁËÒ»¸öÑÝʾ¹¤¾ß£¬£¬£¬£¬Õ¹Ê¾Á˺ڿÍÔõÑùͨ¹ý³µÅƺÅÔÚ30ÃëÄÚÖ´ÐаüÀ¨Ëø¶¨/½âËø¡¢Æô¶¯/×èÖ¹³µÁ¾¡¢ÃùµÑ¼°¶¨Î»ÔÚÄÚµÄÔ¶³Ì¿ØÖƲÙ×÷¡£¡£¡£¸üΪÑÏÖØµÄÊÇ£¬£¬£¬£¬ºÚ¿Í»¹ÄÜÔÚ³µÖ÷¾ø²»ÖªÇéµÄÇéÐÎÏ£¬£¬£¬£¬½«×Ô¼ºÌí¼ÓΪ³µÁ¾µÄµÚ¶þÓû§£¬£¬£¬£¬ÊµÏÖÒþ²ØµÄÔ¶³Ì²Ù¿Ø¡£¡£¡£ÐÒÔ˵ÄÊÇ£¬£¬£¬£¬ÕâЩÎó²îÒѱ»ÊµÊ±·¢Ã÷²¢ÐÞ¸´£¬£¬£¬£¬ÇÒδ·¢Ã÷ÓжñÒâʹÓõļͼ¡£¡£¡£ÆðÑÇÍŶÓҲȷÈÏÁËÎó²îδ±»Íⲿ¶ñÒâ¹¥»÷ËùʹÓᣡ£¡£
https://www.bleepingcomputer.com/news/security/kia-dealer-portal-flaw-could-let-attackers-hack-millions-of-cars/
6. RhadamanthysÔÚ0.7.0°æ±¾ÖÐÌí¼ÓÁËÁ¢ÒìµÄAI¹¦Ð§
9ÔÂ26ÈÕ£¬£¬£¬£¬RhadamanthysÊÇÒ»¿î×Ô2022ÄêÆðѸËÙÑݽøµÄ¸ß¼¶ÐÅÏ¢ÇÔÈ¡³ÌÐò£¬£¬£¬£¬Æä×îÐÂ0.7.0°æ±¾¼¯³ÉÁËÈ˹¤ÖÇÄÜÇý¶¯µÄ¹âѧ×Ö·ûʶ±ðÊÖÒÕ£¬£¬£¬£¬ÄÜ´ÓͼÏñÖÐÌáÈ¡¼ÓÃÜÇ®±ÒÖÖ×Ó¶ÌÓ£¬£¬£¬¼«´óÌáÉýÁËÆäÍþвÐÔ¡£¡£¡£Ö»¹ÜÃæÁÙµØÇøÐÔ½ûÁ£¬£¬£¬¸Ã¶ñÒâÈí¼þÈÔ»îÔ¾ÓÚµØÏÂÊг¡£¬£¬£¬£¬Ê¹ÓÃMSI×°ÖóÌÐòαװµÈÊֶιæ±Ü¼ì²â£¬£¬£¬£¬ÒÔ͵ȡƾ֤¡¢ÏµÍ³ÐÅÏ¢¼°²ÆÎñÊý¾Ý¡£¡£¡£ÆäAIͼÏñʶ±ð¹¦Ð§ÓÈΪÒýÈËעĿ£¬£¬£¬£¬Ê¹¹¥»÷ÕßÄÜ×Ô¶¯²¶»ñ²¢Ð¹Â¶¼ÓÃÜÇ®±ÒÐÅÏ¢¡£¡£¡£RhadamanthysµÄ¿ª·¢Õßͨ¹ýTOXºÍTelegramµÈƽ̨һÁ¬Íƹ㣬£¬£¬£¬²¢Õë¶Ô±±ÃÀ¡¢ÄÏÃÀµÈµØ¼ÓÃÜÇ®±ÒÓû§ÊµÑ龫׼¹¥»÷¡£¡£¡£ÎªÓ¦¶ÔÕâÒ»Íþв£¬£¬£¬£¬Insikt GroupÌá³öÁ˶àÖÖ»º½âÕ½ÂÔ£¬£¬£¬£¬°üÀ¨»ùÓÚ»¥³âËøµÄÖÕÖ¹¿ª¹Ø¡¢¸ß¼¶¼ì²â¹æÔò¼°Ç¿»¯¶Ëµã±£»£»£»¤µÈ£¬£¬£¬£¬Ö¼ÔÚ×Ô¶¯×èÖ¹¶ñÒâÈí¼þÖ´Ðв¢ÌáÉýϵͳ·À»¤ÄÜÁ¦¡£¡£¡£Õ¹ÍûδÀ´£¬£¬£¬£¬Ëæ×ÅRhadamanthys 0.8.0µÈа汾µÄÑз¢£¬£¬£¬£¬Ô¤¼ÆÆä½«Èںϸü¶à»úеѧϰÊÖÒÕ£¬£¬£¬£¬½øÒ»²½ÌáÉýÇÔȡЧÂÊÓëÒþ²ØÐÔ¡£¡£¡£Òò´Ë£¬£¬£¬£¬¼á³Ö¼ì²âÊÖÒÕµÄÒ»Á¬¸üÐÂÓëÉý¼¶£¬£¬£¬£¬¹ØÓÚÓÐÓõÖÓù´ËÀà¸ß¼¶ÍþвÖÁ¹ØÖ÷Òª¡£¡£¡£
https://www.recordedfuture.com/research/rhadamanthys-stealer-adds-innovative-ai-feature-version


¾©¹«Íø°²±¸11010802024551ºÅ