¡°Ñ¬È¾ÐԲɷᱻÖÐOtterCookieÐÂÐͶñÒâÈí¼þÍþвÈí¼þ¿ª·¢Ö°Ô±

Ðû²¼Ê±¼ä 2024-12-27

1. ¡°Ñ¬È¾ÐԲɷᱻÖÐOtterCookieÐÂÐͶñÒâÈí¼þÍþвÈí¼þ¿ª·¢Ö°Ô±


12ÔÂ26ÈÕ£¬£¬£¬£¬ £¬£¬³¯ÏÊÍþвÐÐΪÕß½üÆÚÔÚÕë¶ÔÈí¼þ¿ª·¢Ö°Ô±µÄ¡°Ñ¬È¾ÐԲɷᱻÖУ¬£¬£¬£¬ £¬£¬ÍƳöÁËÒ»ÖÖÃûΪOtterCookieµÄÐÂÐͶñÒâÈí¼þ¡£¡£¡£¡£¾ÝÍøÂçÇå¾²¹«Ë¾Palo Alto NetworksµÄÑо¿Ö°Ô±³Æ£¬£¬£¬£¬ £¬£¬¸Ã»î¶¯×Ô2022Äê12ÔÂÒÔÀ´Ò»Ö±»îÔ¾£¬£¬£¬£¬ £¬£¬Í¨¹ýÌṩÐéαµÄÊÂÇéʱ»úÈö²¥¶ñÒâÈí¼þ£¬£¬£¬£¬ £¬£¬ÈçBeaverTailºÍInvisibleFerretµÈ¡£¡£¡£¡£¶øNTT Security JapanµÄ±¨¸æÖ¸³ö£¬£¬£¬£¬ £¬£¬OtterCookieºÜ¿ÉÄÜÓÚ9ÔÂÍÆ³ö£¬£¬£¬£¬ £¬£¬²¢ÔÚ11Ô·ºÆðÁËеıäÖÖ¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þͨ¹ý¼ÓÔØÆ÷ת´ï£¬£¬£¬£¬ £¬£¬»ñÈ¡JSONÊý¾Ý²¢Ö´ÐÐJavaScript´úÂ룬£¬£¬£¬ £¬£¬¿ÉÒÔÓëBeaverTailÒ»Æð°²ÅÅ»òµ¥¶À°²ÅÅ¡£¡£¡£¡£ËüʹÓÃGitHub»òBitbucketÏÂÔØµÄNode.jsÏîÄ¿»ònpm°üѬȾĿµÄ£¬£¬£¬£¬ £¬£¬Ò²Ê¹ÓÃÁËQt»òElectronÓ¦ÓóÌÐò¹¹½¨µÄÎļþ¡£¡£¡£¡£Ò»µ©¼¤»î£¬£¬£¬£¬ £¬£¬OtterCookie¾Í»áʹÓÃSocket.IO WebSocket¹¤¾ßÓëÏÂÁîºÍ¿ØÖÆ»ù´¡ÉèÊ©½¨ÉèÇ徲ͨѶ£¬£¬£¬£¬ £¬£¬²¢Ö´ÐÐÊý¾Ý͵ÇÔµÄshellÏÂÁ£¬£¬£¬ £¬£¬°üÀ¨ÍøÂç¼ÓÃÜÇ®±ÒÇ®°üÃÜÔ¿¡¢Îĵµ¡¢Í¼ÏñµÈÓмÛÖµÐÅÏ¢¡£¡£¡£¡£×îа汾µÄOtterCookie»¹¿ÉÒÔй¶¼ôÌù°åÊý¾Ý£¬£¬£¬£¬ £¬£¬²¢¼ì²âµ½ÓÃÓÚÕì̽µÄÏÂÁ£¬£¬£¬ £¬£¬Åú×¢¹¥»÷ÕßÍýÏë¾ÙÐиüÉîÌõÀíµÄÉøÍ¸»òºáÏòÒÆ¶¯¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-ottercookie-malware-used-to-backdoor-devs-in-fake-job-offers/


2. ÈÕº½ÔâDDoS¹¥»÷Öº½°àÑÓÎ󣬣¬£¬£¬ £¬£¬ÏµÍ³Òѻָ´


12ÔÂ26ÈÕ£¬£¬£¬£¬ £¬£¬ÈÕ±¾Æì½¢º½¿Õ¹«Ë¾ÈÕ±¾º½¿Õ(JAL)ÔâÓöÁËÒ»´ÎÍøÂçÇå¾²ÊÂÎñ£¬£¬£¬£¬ £¬£¬µ¼ÖÂÆä²¿·Öº£Äں͹ú¼Êº½°à·ºÆðÑÓÎ󡣡£¡£¡£ÊÂÎñÒòÓÉÊÇÆäÓÃÓÚÓëÍⲿϵͳ¾ÙÐÐÊý¾ÝͨѶµÄÍøÂç×°±¸ÔâÊÜÁËÂþÑÜʽ¾Ü¾øÐ§ÀÍ(DDoS)¹¥»÷£¬£¬£¬£¬ £¬£¬µ¼ÖÂϽµµÍ÷Á¿¼¤Ôö²¢·ºÆð¹ÊÕÏ¡£¡£¡£¡£¹¥»÷»¹Ó°ÏìÁËÂÿÍÐÐÀîÖÎÀíϵͳºÍÒÆ¶¯Ó¦ÓóÌÐò£¬£¬£¬£¬ £¬£¬µ«ÈÕº½ÌåÏÖûÓпͻ§ÐÅϢй¶¡¢ÅÌËã»ú²¡¶¾Ë𺦻òº½ÐÐÇå¾²ÎÊÌâ¡£¡£¡£¡£ÊÜÓ°ÏìµÄϵͳÒÑÔÝʱ¹Ø±Õ£¬£¬£¬£¬ £¬£¬²¢ÔÝÍ£Á˵±ÈÕ³ö·¢µÄ»úƱÏúÊۺͲ¿·ÖÔÚÏßЧÀÍ¡£¡£¡£¡£Ö»¹ÜÓÐ40¶à¸öº½°àÑÓÎ󣬣¬£¬£¬ £¬£¬µ«ÈÕº½ÌåÏÖµÚ¶þÌìµÄº½°àÍýÏëÕý³£ÔËÐС£¡£¡£¡£º½¿ÕÒµÈÔÊÇÈ«ÇòºÚ¿ÍµÄÈÈÃÅÄ¿µÄ£¬£¬£¬£¬ £¬£¬´ËÇ°Ò²Ôø±¬·¢¶àÆðÕë¶Ôº½¿Õ¹«Ë¾ºÍ»ú³¡µÄÍøÂç¹¥»÷ÊÂÎñ£¬£¬£¬£¬ £¬£¬ÕâЩϮ»÷´ó¶à³öÓÚ¾­¼ÃÄîÍ·£¬£¬£¬£¬ £¬£¬µ«Ò²ÓÐÕþÖÎÄîÍ·µÄ°¸Àý¡£¡£¡£¡£


https://therecord.media/japan-airlines-resumes-operations-after-cyberattack


3. °ÍÎ÷ºÚ¿ÍÒòÉæÏÓڲƭÀÕË÷ÔÚÃÀ¹úÔâÖ¸¿Ø


12ÔÂ26ÈÕ£¬£¬£¬£¬ £¬£¬Ò»Ãû°ÍÎ÷¹«ÃñJunior Barros De OliveiraÒòÉæÏÓºÚ¿ÍÈëÇÖ²¢Ú²Æ­ÀÕË÷Ò»¼ÒλÓÚÐÂÔóÎ÷µÄ¹«Ë¾¶ø±»ÃÀ¹ú˾·¨²¿ÆðËß¡£¡£¡£¡£¾ÝÆðËßÊéÏÔʾ£¬£¬£¬£¬ £¬£¬µÂ°ÂÀûάÀ­ÓÚ2020Äê3ÔÂÈëÇÖÁ˸ù«Ë¾µÄ°ÍÎ÷×Ó¹«Ë¾ÍøÂ磬£¬£¬£¬ £¬£¬ÇÔÈ¡ÁËÔ¼30ÍòÃû¿Í»§µÄÉñÃØÐÅÏ¢¡£¡£¡£¡£Í¬Äê9Ô£¬£¬£¬£¬ £¬£¬ËûʹÓüÙÃûÏò¸Ã¹«Ë¾Ê×ϯִÐйٷ¢Ë͵ç×ÓÓʼþ£¬£¬£¬£¬ £¬£¬ÒªÇóÖ§¸¶300±ÈÌØ±Ò£¨ÆäÊмÛÖµÔ¼320ÍòÃÀÔª£©×÷Ϊ²»³öÊÛÊý¾ÝµÄÌõ¼þ¡£¡£¡£¡£Ò»¸öԺ󣬣¬£¬£¬ £¬£¬ËûÓÖ½«ÏàͬµÄÐÅϢת·¢¸øÁ˸ù«Ë¾ÔÚ°ÍÎ÷µÄÊ×ϯִÐйٺÍÒ»Ãû¸ß¹Ü£¬£¬£¬£¬ £¬£¬²¢ÌåÏÖÔ¸ÒâÒÔ75±ÈÌØ±Ò£¨ÆäʱԼºÏ80ÍòÃÀÔª£©µÄ×Éѯ·Ñ×ÊÖúËûÃǽâ¾öÇå¾²Îó²î¡£¡£¡£¡£µÂ°ÂÀûάÀ­Òò´Ë±»Ö¸¿ØËÄÏîÉæ¼°´ÓÊܱ£»£»£»£»£»£» £»¤µÄÅÌËã»ú»ñÊØÐÅÏ¢µÄڲƭÀÕË÷×ïºÍËÄÏîÍþвÐÔͨѶ×ï¡£¡£¡£¡£ÈôÊÇ×ïÃû½¨É裬£¬£¬£¬ £¬£¬Ëû½«ÃæÁÙ×î¸ß¿É´ï20ÄêµÄî¿ÏµºÍ¸ß´ï100ÍòÃÀÔªµÄ·£¿£¿£¿£¿£¿£¿£¿î£¬£¬£¬£¬ £¬£¬»òÊÕÒæÓëËðʧ¼ÛÖµµÄÁ½±¶£¨ÒԽϸßÕßΪ׼£©¡£¡£¡£¡£


https://thehackernews.com/2024/12/brazilian-hacker-charged-for-extorting.html


4. ͨÓö¯Á¦¹«Ë¾ÔâÍøÂç´¹ÂÚ¹¥»÷£¬£¬£¬£¬ £¬£¬ÊýʮԱ¹¤¸£ÀûÕË»§±»ÈëÇÖ


12ÔÂ26ÈÕ£¬£¬£¬£¬ £¬£¬º½¿Õº½ÌìºÍ¹ú·À¾ÞͷͨÓö¯Á¦¹«Ë¾ÔâÓöÁËÒ»´ÎÀֳɵÄÍøÂç´¹ÂÚ¹¥»÷£¬£¬£¬£¬ £¬£¬µ¼ÖÂÊýÊ®¸öÔ±¹¤¸£ÀûÕË»§±»ÈëÇÖ¡£¡£¡£¡£¹¥»÷Õßͨ¹ýµÚÈý·½ÍйܵĵǼÃÅ»§»á¼û²¢¸ü¸ÄÁËÔ±¹¤¸£ÀûÕË»§£¬£¬£¬£¬ £¬£¬ÕâЩÕË»§°üÀ¨ÁËÔ±¹¤µÄÐÕÃû¡¢³öÉúÈÕÆÚ¡¢Õþ¸®½ÒÏþµÄÉí·ÝÖ¤ºÅÂë¡¢Éç»áÇå¾²ºÅÂë¡¢ÒøÐÐÕË»§ÐÅÏ¢ºÍ²Ð¼²×´Ì¬µÈÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¾ÝͨÓö¯Á¦¹«Ë¾Í¸Â¶£¬£¬£¬£¬ £¬£¬¹²ÓÐ37ÈËÊܵ½Ó°Ï죬£¬£¬£¬ £¬£¬¹¥»÷ÕßÔÚijЩÇéÐÎÏ»¹¸ü¸ÄÁ˱»µÁÕË»§µÄÒøÐÐÕË»§ÐÅÏ¢¡£¡£¡£¡£Í¨Óö¯Á¦¹«Ë¾ÔÚ·¢Ã÷Õâһδ¾­ÊÚȨµÄ»î¶¯ºóÁ¬Ã¦ÔÝÍ£Á˶ԸÃЧÀ͵Ļá¼û£¬£¬£¬£¬ £¬£¬²¢ÏòÊÜÓ°ÏìµÄÖ°Ô±ÌṩÁËÁ½ÄêµÄÃâ·ÑÐÅÓÃ¼à¿Ø¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ £¬£¬Í¨Óö¯Á¦¹«Ë¾»¹ÌáÐÑÊÜÓ°ÏìµÄСÎÒ˽¼ÒÖØÖÃËûÃǵĸ»´ïÕË»§µÇ¼ƾ֤£¬£¬£¬£¬ £¬£¬²¢×èÖ¹ÔÚ¶à¸öÕË»§ÖÐʹÓÃÏàͬµÄƾ֤¡£¡£¡£¡£½ñÄêÔçЩʱ¼ä£¬£¬£¬£¬ £¬£¬¸»´ï¹«Ë¾Ò²ÔøÔâÓö¹ýÁ½´ÎÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬ £¬£¬Ó°ÏìÁËÊýÍòСÎÒ˽¼Ò¡£¡£¡£¡£


https://www.securityweek.com/defense-giant-general-dynamics-says-employees-targeted-in-phishing-attack/


5. WDACÔâʹÓ㬣¬£¬£¬ £¬£¬¹¥»÷Õ߿ɽûÓÃEDR´«¸ÐÆ÷·¢¶¯¹¥»÷


12ÔÂ25ÈÕ£¬£¬£¬£¬ £¬£¬Ç徲ר¼Ò·¢Ã÷ÁËÒ»ÖÖʹÓÃWindows DefenderÓ¦ÓóÌÐò¿ØÖÆ£¨WDAC£©µÄ¹¥»÷ÊÖÒÕ£¬£¬£¬£¬ £¬£¬¿ÉÒÔ½ûÓÃWindowsÉè±¹ØÁ¬Ä¶Ëµã¼ì²âºÍÏìÓ¦£¨EDR£©´«¸ÐÆ÷£¬£¬£¬£¬ £¬£¬Ê¹¹¥»÷ÕßÄܹ»ÈƹýÇå¾²¼ì²â²¢¶Ôϵͳ·¢¶¯¹¥»÷¡£¡£¡£¡£WDACÊÇWindows 10ºÍWindows Server 2016ÒýÈëµÄÊÖÒÕ£¬£¬£¬£¬ £¬£¬Ö¼ÔÚ¿ØÖÆWindowsÉè±¹ØÁ¬Ä¿ÉÖ´ÐдúÂë¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔÖÆ¶©ºÍ°²ÅÅרÃÅÉè¼ÆµÄWDACÕ½ÂÔ£¬£¬£¬£¬ £¬£¬×èÖ¹EDR´«¸ÐÆ÷ÔÚϵͳÆô¶¯Ê±¼ÓÔØ£¬£¬£¬£¬ £¬£¬Ê¹ÆäÎÞ·¨ÊÂÇé¡£¡£¡£¡£¹¥»÷·½·¨°üÀ¨Õë¶Ôµ¥¸ö×°±¸ºÍÕû¸öÓò£¬£¬£¬£¬ £¬£¬ÓµÓÐÓòÖÎÀíԱȨÏ޵Ĺ¥»÷Õß¿ÉÒÔÔÚÕû¸ö×éÖ¯ÄÚ·Ö·¢¶ñÒâWDACÕ½ÂÔ£¬£¬£¬£¬ £¬£¬ÏµÍ³ÐԵؽûÓÃËùÓж˵ãÉϵÄEDR´«¸ÐÆ÷¡£¡£¡£¡£¹¥»÷Éæ¼°Õ½ÂÔ°²ÅÅ¡¢ÖØÆôÖն˺ͽûÓÃEDRÈý¸öÖ÷Òª½×¶Î¡£¡£¡£¡£Çå¾²Ö°Ô±½¨ÉèÁË¡°Krueger¡±¿´·¨ÑéÖ¤¹¤¾ßÀ´¼ì²âÕâÖÖ¹¥»÷¡£¡£¡£¡£»£»£»£»£»£» £»º½âÕ½ÂÔ°üÀ¨Í¨¹ýGPOÖ´ÐÐWDACÕ½ÂÔ¡¢Ó¦ÓÃ×îСȨÏÞÔ­ÔòºÍʵÑéÇå¾²µÄÖÎÀíʵ¼ù¡£¡£¡£¡£ÃæÁÙзºÆðµÄ¹¥»÷ÊÖÒÕ£¬£¬£¬£¬ £¬£¬ÐèÒª½ÓÄɶàÌõÀíµÄÍøÂçÇå¾²ÒªÁ죬£¬£¬£¬ £¬£¬²¢Ê±¿Ì¼á³ÖСÐÄ¡£¡£¡£¡£


https://cybersecuritynews.com/attack-weaponizes-windows-defender/#google_vignette


6. ΢ÈíÖÒÑÔ£ºÊ¹ÓÃýÌå×°ÖÃWindows 11 24H2¿ÉÖÂÎÞ·¨ÎüÊÕÇå¾²¸üÐÂ


12ÔÂ26ÈÕ£¬£¬£¬£¬ £¬£¬Î¢Èí·¢³öÖÒÑÔ£¬£¬£¬£¬ £¬£¬Ö¸³öʹÓÃýÌåÖ§³Ö×°ÖÃWindows 11°æ±¾24H2ʱ±£´æÒ»¸öÎÊÌ⣬£¬£¬£¬ £¬£¬¿ÉÄܵ¼Ö²Ù×÷ϵͳÎÞ·¨½ÓÊܽøÒ»²½µÄÇå¾²¸üС£¡£¡£¡£Ïêϸ¶øÑÔ£¬£¬£¬£¬ £¬£¬ÔÚ2024Äê10ÔÂ8ÈÕÖÁ11ÔÂ12ÈÕʱ´ú£¬£¬£¬£¬ £¬£¬Ê¹ÓÃCDºÍUSBÉÁ´æÇý¶¯Æ÷×°ÖðüÀ¨´Ëʱ´úÇå¾²¸üеÄWindows 11°æ±¾24H2ʱ£¬£¬£¬£¬ £¬£¬×°±¸¿ÉÄÜ»áÏÝÈëÎÞ·¨½ÓÊܺóÐøWindowsÇå¾²¸üеÄ״̬¡£¡£¡£¡£²»¹ý£¬£¬£¬£¬ £¬£¬Õâ¸öÎó²î²»»áÓ°Ïìͨ¹ýWindows¸üлòMicrosoft¸üÐÂÄ¿Â¼ÍøÕ¾Ó¦ÓõÄÇå¾²¸üУ¬£¬£¬£¬ £¬£¬Ò²²»»áÔÚʹÓÃ×îеÄ2024Äê12ÔÂÇå¾²¸üÐÂʱ·ºÆð¡£¡£¡£¡£Î¢ÈíÕýÔÚÖÂÁ¦ÓÚÓÀÊÀÐÞ¸´´ËÎÊÌ⣬£¬£¬£¬ £¬£¬²¢½¨ÒéʹÓûùÓÚýÌåµÄWindows 11 24H2×°ÖõÄÓû§Ó¦ÓÃ2024Äê12ÔÂ10ÈÕÐû²¼µÄÇå¾²¸üУ¬£¬£¬£¬ £¬£¬ÒÔ×èÖ¹ºóÐø¸üÐÂÎÊÌâ¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ £¬£¬Windows 11 24H2»¹ÃæÁÙ×ÅһϵÁÐÆäËûÎÊÌ⣬£¬£¬£¬ £¬£¬°üÀ¨ÒôƵÎÊÌâ¡¢ÓÎÏ·ÐÔÄÜÎÊÌâ¡¢Íß½âºÍËÀ»úµÈ£¬£¬£¬£¬ £¬£¬ÉõÖÁÔÚÌØ¶¨µÄÓ²¼þºÍÈí¼þÉèÖÃÉϱ»ÔÝʱ×èÖ¹¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/windows-11-installation-media-bug-causes-security-update-failures/