Binarly·¢Ã÷Ó°ÏìUEFIÖÐͼÏñÆÊÎö×é¼þµÄÎó²îLogoFAIL

Ðû²¼Ê±¼ä 2023-12-04
1¡¢Binarly·¢Ã÷Ó°ÏìUEFIÖÐͼÏñÆÊÎö×é¼þµÄÎó²îLogoFAIL


¾ÝýÌå11ÔÂ30ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬ £¬Binarly·¢Ã÷ÁËͳ³ÆÎªLogoFAILµÄ¶à¸öÇå¾²Îó²î£¬£¬£¬£¬£¬£¬ £¬¿ÉÓ°Ïì¸÷¸ö¹©Ó¦É̵ÄUEFI´úÂëÖеÄͼÏñÆÊÎö×é¼þ¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬£¬£¬ £¬¹¥»÷Õß¿ÉÒÔ½«¶ñÒâͼÏñ»òlogo´æ´¢ÔÚEFIϵͳ·ÖÇø(ESP)»ò¹Ì¼þ¸üеÄδÊðÃû²¿·ÖÖС£¡£¡£¡£¡£¡£¡£ÒÔÕâÖÖ·½·¨Ö²Èë¶ñÒâÈí¼þ¿ÉÈ·±£ÔÚϵͳÖÐÒ»Á¬±£´æ£¬£¬£¬£¬£¬£¬ £¬ÏÕЩ²»»á±»·¢Ã÷¡£¡£¡£¡£¡£¡£¡£BinarlyÒѾ­È·¶¨Ó¢Ìضû¡¢ºê³ž¡¢åÚÏëºÍÆäËü¹©Ó¦É̵ÄÊý°Ù¸öÐͺſÉÄܱ£´æÎó²î£¬£¬£¬£¬£¬£¬ £¬¶¨ÖÆUEFI¹Ì¼þ´úÂëµÄÈý´ó×ÔÁ¦ÌṩÉÌAMI¡¢InsydeºÍPhoenixÒ²ÊÇÔÆÔÆ¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬ £¬¸ÃÎó²îµÄÏêϸӰÏì¹æÄ£ÈÔÔÚÈ·¶¨ÖС£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/logofail-attack-can-install-uefi-bootkits-through-bootup-logos/


2¡¢ÃÀ¹ú¹«Ë¾StaplesÔâµ½ÍøÂç¹¥»÷ÓªÒµÔËÓªÊܵ½Ó°Ïì


ýÌå11ÔÂ30Èճƣ¬£¬£¬£¬£¬£¬ £¬ÃÀ¹ú°ì¹«ÓÃÆ·ÁãÊÛÉÌStaplesÔâµ½ÍøÂç¹¥»÷ºó¹Ø±ÕÁ˲¿·Öϵͳ¡£¡£¡£¡£¡£¡£¡£×ÔÉÏÖÜÒ»ÒÔÀ´£¬£¬£¬£¬£¬£¬ £¬StaplesÓöµ½ÁËÖÖÖÖÄÚ²¿ÔËÓªÎÊÌ⣬£¬£¬£¬£¬£¬ £¬°üÀ¨ÎÞ·¨»á¼ûZendesk¡¢VPNÔ±¹¤ÃÅ»§¡¢´òÓ¡µç×ÓÓʼþºÍʹÓõ绰Ïߵȡ£¡£¡£¡£¡£¡£¡£ÓÐÔ±¹¤³Æ£¬£¬£¬£¬£¬£¬ £¬Ò»Çж¼´¦ÓÚå´»ú״̬£¬£¬£¬£¬£¬£¬ £¬ÔÚÃŵêÊÂÇéÎÞ·¨»á¼ûµç×ÓÓʼþ¡¢bizfit¡¢pogsºÍµç×ÓЧÀĮ́¡£¡£¡£¡£¡£¡£¡£StaplesÌåÏÖËûÃÇÔÚ11ÔÂ27ÈÕ·¢Ã÷¹¥»÷ºóÁ¬Ã¦½ÓÄÉÁËÏìÓ¦²½·¥£¬£¬£¬£¬£¬£¬ £¬µ«Õâµ¼ÖÂØÊºǫ́´¦Öóͷ£ºÍ½»¸¶ÒÔ¼°Í¨Ñ¶ÇþµÀºÍ¿Í»§Ð§ÀÍÔÝʱÖÐÖ¹¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬ £¬Õâ´Î¹¥»÷ÖÐûÓÐ×°ÖÃÀÕË÷Èí¼þ£¬£¬£¬£¬£¬£¬ £¬Ò²Ã»ÓÐÎļþ±»¼ÓÃÜ¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/staples-confirms-cyberattack-behind-service-outages-delivery-issues/


3¡¢Ô¼60¼ÒÐÅÓÃÏàÖúÉçÒò¹©Ó¦É̱»ÀÕË÷¹¥»÷ЧÀÍÔÝʱÖÐÖ¹


12ÔÂ2ÈÕ±¨µÀ³Æ£¬£¬£¬£¬£¬£¬ £¬ÔÆÐ§ÀÍÌṩÉÌOngoing OperationsÔâµ½ÁËÀÕË÷¹¥»÷£¬£¬£¬£¬£¬£¬ £¬ËüÁ¥ÊôÓÚÐÅÓÃÉçÊÖÒÕ¹«Ë¾Trellance¡£¡£¡£¡£¡£¡£¡£¹ú¼ÒÐÅÓÃÉçÖÎÀí¾Ö(NCUA)ÌåÏÖ£¬£¬£¬£¬£¬£¬ £¬²¿·ÖÐÅÓÃÉçÊÕµ½ÁËÀ´×ÔOngoing OperationsµÄÐÅÏ¢£¬£¬£¬£¬£¬£¬ £¬Í¸Â¶¸Ã¹«Ë¾ÔÚ11ÔÂ26ÈÕÔâµ½ÁËÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬ £¬ÊÓ²ìÈÔÔÚ¾ÙÐÐÖУ¬£¬£¬£¬£¬£¬ £¬ÏÖÒÑÈ·ÈÏÔ¼60¼ÒÐÅÓÃÏàÖúÉçÓÉÓÚµÚÈý·½Ð§ÀÍÌṩÉÌÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬ £¬ÕýÔÚÂÄÀúÒ»¶¨Ë®Æ½µÄЧÀÍÖÐÖ¹¡£¡£¡£¡£¡£¡£¡£


https://therecord.media/credit-unions-facing-outages-due-to-ransomware


4¡¢Å²ÍþÀ͹¤ºÍ¸£ÀûÖÎÀí¾ÖÒòÊý¾Ýй¶±»·£¿£¿£¿î185ÍòÃÀÔª


¾Ý12ÔÂ3ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬ £¬Å²ÍþÀ͹¤ºÍ¸£ÀûÖÎÀí¾Ö(NAV)±»Å²Íþî¿Ïµ¾Ö£¨Datatilsynet£©·£¿£¿£¿î170ÍòÅ·Ôª¡£¡£¡£¡£¡£¡£¡£Å²ÍþÊý¾Ý±£»£»£»¤¾ÖÔÚNAVµÄÉó¼ÆÖз¢Ã÷ÁË12ÆðÎ¥·´Ð¡ÎÒ˽¼ÒÊý¾Ý±£»£»£»¤ÌõÀýµÄÐÐΪ¡£¡£¡£¡£¡£¡£¡£×÷ΪÊÓ²ìµÄÒ»²¿·Ö£¬£¬£¬£¬£¬£¬ £¬DPA·¢Ã÷¿ØÖÆÕßδÄܽÓÄÉÊʵ±µÄÊÖÒÕºÍ×éÖ¯²½·¥À´±£»£»£»¤Ð¡ÎÒ˽¼ÒÊý¾Ý£¬£¬£¬£¬£¬£¬ £¬ÀýÈçITϵͳûÓлñµÃ³ä·ÖµÄ±£»£»£»¤¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬ £¬¹ý¶àµÄÔ±¹¤¿ÉÒÔ»á¼ûСÎÒ˽¼ÒÊý¾Ý£¬£¬£¬£¬£¬£¬ £¬ÔÚijЩÇéÐÎϰüÀ¨ºÜÊÇÃô¸ÐµÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬£¬ £¬¿ØÖÆÕßδÄܶÔÔ±¹¤Ê¹ÓÃITϵͳ¾ÙÐÐϵͳµÄ¿ØÖÆ¡£¡£¡£¡£¡£¡£¡£


https://www.databreaches.net/norwegian-labor-and-welfare-administration-fined-for-data-protection-failures/


5¡¢Unit 42Åû¶Õë¶ÔÖж«¡¢·ÇÖÞºÍÃÀ¹úµÈµØµÄ¹¥»÷»î¶¯


Unit 42ÔÚ12ÔÂ1ÈÕÅû¶ÁËкóÃÅAgent Raccoon£¬£¬£¬£¬£¬£¬ £¬Ëü±»ÓÃÓÚÕë¶ÔÖж«¡¢·ÇÖÞºÍÃÀ¹úµÈµØµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¸Ã»î¶¯Ö÷ÒªÕë¶Ô½ÌÓý¡¢·¿µØ²ú¡¢ÁãÊÛ¡¢·ÇÓªÀû×éÖ¯¡¢µçÐŹ«Ë¾ºÍÕþ¸®»ú¹¹£¬£¬£¬£¬£¬£¬ £¬¹¥»÷ÍŻﱻUnit 42×·×ÙΪCL-STA-0002¡£¡£¡£¡£¡£¡£¡£ºóÃÅÓÃ.NET¿ª·¢£¬£¬£¬£¬£¬£¬ £¬²¢Ê¹ÓÃÓòÃûЧÀÍ(DNS)ЭÒéÓëC2»ù´¡ÉèÊ©½¨ÉèÒþ²ØµÄͨѶͨµÀ¡£¡£¡£¡£¡£¡£¡£Agent RaccoonÔÚ¶à´Î¹¥»÷ÖÐÓëÆäËüÁ½¸ö¹¤¾ßÁ¬ÏµÊ¹Ó㬣¬£¬£¬£¬£¬ £¬ÆäÖÐÒ»¸öÊÇÇÔÈ¡Óû§Æ¾Ö¤µÄNetwork Provider DLLÄ£¿£¿£¿éNtospy£¬£¬£¬£¬£¬£¬ £¬ÁíÒ»¸öÊDZ»³ÆÎªMimiliteµÄ¶¨ÖưæMimikatz¡£¡£¡£¡£¡£¡£¡£


https://unit42.paloaltonetworks.com/new-toolset-targets-middle-east-africa-usa/


6¡¢KasperskyÐû²¼2023ÄêQ3 ITÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ


12ÔÂ1ÈÕ£¬£¬£¬£¬£¬£¬ £¬KasperskyÐû²¼ÁË2023ÄêµÚÈý¼¾¶ÈITÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£±¨¸æÖÐÌá¼°µÄÓÐÕë¶ÔÐԵĹ¥»÷ÆÊÎö°üÀ¨£ºÊ¹ÓÃDroxiDatºÍCobalt Strike¹¥»÷ÄÜÔ´ÐÐÒµ¡¢Ê¹ÓÃCVE-2023-23397Îó²îµÄ¹¥»÷¡¢Õë¶Ô¹¤¿ØÐÐÒµµÄ¹¥»÷Öг£¼ûµÄTTPºÍαÔìµÄTelegramÓ¦ÓõÈ¡£¡£¡£¡£¡£¡£¡£ÆäËü¶ñÒâÈí¼þ°üÀ¨£ºÕë¶ÔLinuxµÄ¹©Ó¦Á´¹¥»÷¡¢CubaÀÕË÷ÍŻй¶µÄLockbit 3¹¹½¨Æ÷¡¢Ò»Ö±Éú³¤µÄ¶ñÒâÈí¼þÃûÌÃÒÔ¼°cryptor¡¢stealerºÍbanking TrojanµÈ¡£¡£¡£¡£¡£¡£¡£


https://securelist.com/it-threat-evolution-q3-2023/111171/