CleoÎļþ´«ÊäÈí¼þÁãÈÕÎó²îÔâºÚ¿ÍʹÓþÙÐÐÊý¾Ý͵ÇÔ¹¥»÷

Ðû²¼Ê±¼ä 2024-12-12

1. CleoÎļþ´«ÊäÈí¼þÁãÈÕÎó²îÔâºÚ¿ÍʹÓþÙÐÐÊý¾Ý͵ÇÔ¹¥»÷


12ÔÂ10ÈÕ£¬£¬ £¬£¬£¬ £¬£¬ºÚ¿ÍÕýÔÚÆð¾¢Ê¹ÓÃCleoÖÎÀíÎļþ´«ÊäÈí¼þÖеÄз¢Ã÷µÄÁãÈÕÎó²î£¬£¬ £¬£¬£¬ £¬£¬ÇÖÈëÈ«ÇòÊýǧ¼Ò¹«Ë¾ÍøÂ磬£¬ £¬£¬£¬ £¬£¬°üÀ¨Target¡¢ÎÖ¶ûÂêµÈ×ÅÃûÆóÒµ£¬£¬ £¬£¬£¬ £¬£¬¾ÙÐÐÊý¾Ý͵ÇÔ¹¥»÷¡£¡£¡£¡£¡£¸ÃÎó²î±£´æÓÚCleo LexiCom¡¢VLTraderºÍHarmony²úÆ·ÖУ¬£¬ £¬£¬£¬ £¬£¬ÔÊÐí²»ÊÜÏÞÖÆµÄÎļþÉÏ´«ºÍÏÂÔØ£¬£¬ £¬£¬£¬ £¬£¬µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£Ö»¹ÜCleo֮ǰÒÑÐÞ¸´ÁËÒ»¸öÏà¹ØÎó²îCVE-2024-50623£¬£¬ £¬£¬£¬ £¬£¬µ«ÍþвÐÐΪÕßÈÔÈÆ¹ýÁËÐÞ¸´¼ÌÐø¹¥»÷¡£¡£¡£¡£¡£ÍøÂçÇ徲ר¼ÒÖ¸³ö£¬£¬ £¬£¬£¬ £¬£¬ÕâЩ¹¥»÷ÓëеÄTermiteÀÕË÷Èí¼þÍÅ»ïÓйØ¡£¡£¡£¡£¡£HuntressÇå¾²Ñо¿Ö°Ô±Ê״η¢Ã÷Á˸ÃÎó²îµÄ×Ô¶¯¹¥»÷£¬£¬ £¬£¬£¬ £¬£¬²¢ÖÒÑÔÓû§½ÓÄɽôÆÈÐж¯£¬£¬ £¬£¬£¬ £¬£¬°üÀ¨½«ÏµÍ³ÒƵ½·À»ðǽºóÃæ£¬£¬ £¬£¬£¬ £¬£¬ÏÞÖÆÍⲿ»á¼û£¬£¬ £¬£¬£¬ £¬£¬²¢¼ì²é¿ÉÒÉÎļþ¡£¡£¡£¡£¡£CleoÒÑÈ·ÈÏÎó²î±£´æ£¬£¬ £¬£¬£¬ £¬£¬²¢ÕýÔÚ¿ª·¢Çå¾²¸üУ¬£¬ £¬£¬£¬ £¬£¬Í¬Ê±ÌṩÁË»º½â²½·¥½¨Òé¡£¡£¡£¡£¡£¾ÝÔ¤¼Æ£¬£¬ £¬£¬£¬ £¬£¬ÃÀ¹úÓоø´ó´ó¶¼Ò×Êܹ¥»÷µÄЧÀÍÆ÷£¬£¬ £¬£¬£¬ £¬£¬È«Çò¹æÄ£ÄÚÒÑÓÐÖÁÉÙÊ®¸ö×éÖ¯Êܵ½Ó°Ïì¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-cleo-zero-day-rce-flaw-exploited-in-data-theft-attacks/


2. AppLite Banker¶ñÒâÈí¼þÒÔÒøÐÐÓ¦ÓóÌÐòΪĿµÄÌá³«ÍøÂç´¹Âڻ


12ÔÂ10ÈÕ£¬£¬ £¬£¬£¬ £¬£¬Ò»³¡ÖØ´óµÄÍøÂç´¹ÂڻÕýÔÚÈö²¥ÃûΪAppLite BankerµÄжñÒâÈí¼þ±äÖÖ£¬£¬ £¬£¬£¬ £¬£¬¸Ã¶ñÒâÈí¼þ±»Ê¶±ðΪAntidotÒøÐÐľÂíµÄ¸üа汾£¬£¬ £¬£¬£¬ £¬£¬Ö÷ÒªÕë¶ÔAndroid×°±¸¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýð³ä×ÅÃû¹«Ë¾ÕÐÆ¸Ö°Ô±Ä³ÈËÁ¦×ÊÔ´´ú±í£¬£¬ £¬£¬£¬ £¬£¬·¢ËÍÍøÂç´¹ÂÚµç×ÓÓʼþÖ¸µ¼Óû§ÏÂÔØÚ²Æ­ÐÔCRMÓ¦ÓóÌÐò£¬£¬ £¬£¬£¬ £¬£¬½ø¶ø×°ÖÃAppLite¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÄÜÖ´ÐÐÆ¾Ö¤ÍµÇÔ¡¢ÀÄÓÃÎÞÕϰ­Ð§ÀÍ¡¢Ô¶³Ì¿ØÖÆ¡¢ÓÕÆ­ÐÔÁýÕֵȶàÖÖ¶ñÒâ»î¶¯£¬£¬ £¬£¬£¬ £¬£¬²¢Õë¶Ô172¸öÓ¦ÓóÌÐò£¬£¬ £¬£¬£¬ £¬£¬°üÀ¨½ðÈÚÆ½Ì¨ºÍ¼ÓÃÜÇ®°ü¡£¡£¡£¡£¡£ÎªÈƹý¼ì²â£¬£¬ £¬£¬£¬ £¬£¬AppLiteʹÓÃZIPÎļþ²Ù×÷ºÍǶÈëHTMLÁýÕÖ²ã»ìÏýÇå¾²¹¤¾ß¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ¹¥»÷¹æÄ£ÆÕ±é£¬£¬ £¬£¬£¬ £¬£¬Éæ¼°¶àÖÖÓïÑÔÓû§£¬£¬ £¬£¬£¬ £¬£¬²¢ÄÜÇÔÈ¡ËøÆÁƾ֤×Ô¶¯½âËøÆÁÄ»£¬£¬ £¬£¬£¬ £¬£¬ÊµÏÖÍêÈ«¿ØÖÆÊÜѬȾװ±¸¡£¡£¡£¡£¡£Çå¾²Ñо¿Ö°Ô±Ç¿µ÷×Ô¶¯·ÀÓùÖ÷ÒªÐÔ£¬£¬ £¬£¬£¬ £¬£¬½¨ÒéʵÑéǿʢµÄÒÆ¶¯×°±¸ÖÎÀíÕþ²ß²¢°´ÆÚ¸üÐÂ×°±¸ºÍÇå¾²Èí¼þÒÔÌá·À´ËÀàÍþв¡£¡£¡£¡£¡£


https://www.infosecurity-magazine.com/news/applite-malware-targets-banking/


3. Microsoft 365ÖÐÖ¹µ¼Ö Office WebÓ¦ÓóÌÐòºÍÖÎÀíÖÐÐÄ̱»¾


12ÔÂ10ÈÕ£¬£¬ £¬£¬£¬ £¬£¬Î¢ÈíÕýÔÚÊÓ²ìÒ»ÆðÓ°ÏìOffice WebÓ¦ÓúÍMicrosoft 365ÖÎÀíÖÐÐĵĴóÃæ»ýÇÒÒ»Á¬µÄMicrosoft 365ÖÐÖ¹ÊÂÎñ¡£¡£¡£¡£¡£Óû§±¨¸æÔÚÅþÁ¬Outlook¡¢OneDriveºÍÆäËûOffice 365Ó¦ÓóÌÐòºÍЧÀÍʱ·ºÆðÎÊÌ⣬£¬ £¬£¬£¬ £¬£¬²¢ÊÕµ½Ð§ÀÍÖÐÖ¹µÄÐÂÎÅ¡£¡£¡£¡£¡£Î¢ÈíÖ¸³ö£¬£¬ £¬£¬£¬ £¬£¬ÎÊÌâ¿ÉÄÜÓëÉí·ÝÑéÖ¤»ù´¡ÉèÊ©ÖеÄÁîÅÆÌìÉúÓйØ£¬£¬ £¬£¬£¬ £¬£¬²¢ÕýÔÚÉó²é×î½üµÄת±äÒÔÈ·¶¨»ù´¡Ôµ¹ÊÔ­ÓÉ¡£¡£¡£¡£¡£×÷Ϊ½â¾öÒªÁ죬£¬ £¬£¬£¬ £¬£¬Î¢Èí½¨ÒéÊÜÓ°ÏìµÄÓû§Ê¹ÓÃ×ÀÃæÓ¦ÓóÌÐò»á¼ûMicrosoft 365Ó¦ÓóÌÐòºÍÎĵµ¡£¡£¡£¡£¡£´Ëǰ£¬£¬ £¬£¬£¬ £¬£¬Microsoft 365Ò²Ôø±¬·¢¹ýÈ«ÇòÖÐÖ¹ÊÂÎñ£¬£¬ £¬£¬£¬ £¬£¬°üÀ¨Ó°Ïì¶àÏîЧÀͺ͹¦Ð§µÄÇéÐΡ£¡£¡£¡£¡£¶øÔÚ7Ô£¬£¬ £¬£¬£¬ £¬£¬Ò»´Î´ó¹æÄ£ÖÐÖ¹ÔòÊÇÓÉÂþÑÜʽ¾Ü¾øÐ§ÀÍ£¨DDoS£©¹¥»÷ÒýÆðµÄ¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬ £¬£¬£¬ £¬£¬Î¢ÈíÕýÔÚ²âÊÔÒ»¸öDZÔÚµÄÐÞ¸´³ÌÐò£¬£¬ £¬£¬£¬ £¬£¬²¢ÒѰ²ÅÅÁËÒ»¸öÐÞ¸´³ÌÐòÒÔ»º½âÖÐÖ¹ÎÊÌâ¡£¡£¡£¡£¡£Î¢ÈíÌåÏÖ£¬£¬ £¬£¬£¬ £¬£¬´Ë´ÎÖÐÖ¹ÊÇÓÉÓÚ×î½üµÄЧÀͱ任µ¼ÖÂʶ±ðÁîÅÆµ½ÆÚʱ¼ä·ºÆðÎÊÌ⣬£¬ £¬£¬£¬ £¬£¬´Ó¶øµ¼ÖÂÉí·ÝÑéÖ¤ÇëÇóʧ°Ü¡£¡£¡£¡£¡£¾­ÓÉÒ»¶Îʱ¼äµÄ¼à¿ØÐ§ÀÍÒ£²âºó£¬£¬ £¬£¬£¬ £¬£¬¸Ã¹«Ë¾È·ÈϸÃÎÊÌâÏÖÒѽâ¾ö¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-365-outage-takes-down-office-web-apps-admin-center/


4. MetaÆìÏÂËÄ´óÉ罻ƽ̨ÔâÈ«Çò¹æÄ£¹¥»÷ÖÂЧÀÍÖÐÖ¹


12ÔÂ11ÈÕ£¬£¬ £¬£¬£¬ £¬£¬È«Çò¹æÄ£ÄÚµÄFacebook¡¢Instagram¡¢ThreadsºÍWhatsAppÔâÊÜÁËÑÏÖØ¹¥»÷£¬£¬ £¬£¬£¬ £¬£¬µ¼ÖÂЧÀÍÖÐÖ¹£¬£¬ £¬£¬£¬ £¬£¬²î±ðµØÇøµÄÓû§Êܵ½Á˲î±ðˮƽµÄÓ°Ïì¡£¡£¡£¡£¡£¾ÝDownDetector³Æ£¬£¬ £¬£¬£¬ £¬£¬ÖÐÖ¹±¬·¢ÔÚÃÀ¹ú¶«²¿Ê±¼äÏÂÖç12:40×óÓÒ£¬£¬ £¬£¬£¬ £¬£¬Ðí¶àÓû§ÎÞ·¨Í¨¹ýÍøÕ¾ºÍÓ¦ÓóÌÐò»á¼ûÕâЩЧÀÍ£¬£¬ £¬£¬£¬ £¬£¬Ò²ÎÞ·¨Í¨¹ýWhatsApp·¢ËÍÐÂÎÅ¡£¡£¡£¡£¡£µ±Óû§ÊµÑé»á¼ûFacebookʱ£¬£¬ £¬£¬£¬ £¬£¬»áÊÕµ½¹ýʧÌáÐÑ¡£¡£¡£¡£¡£ËäÈ»MetaµÄÓªÒµÆ½Ì¨×´Ì¬Ò³ÃæÃ»ÓÐÏÔʾ´ó¹æÄ£Ð§ÀÍÖÐÖ¹£¬£¬ £¬£¬£¬ £¬£¬µ«MetaÈÏ¿ÉÁËÖÐÖ¹µÄ±¬·¢£¬£¬ £¬£¬£¬ £¬£¬²¢ÌåÏÖÕýÔÚÆð¾¢»Ö¸´Ð§ÀÍ¡£¡£¡£¡£¡£²¿·ÖµØÇøµÄЧÀÍÔÚÃÀ¹ú¶«²¿Ê±¼äÏÂÖç1:20×óÓÒ×îÏȻָ´£¬£¬ £¬£¬£¬ £¬£¬µ«ÈÔÓÐÓû§±¨¸æÎÞ·¨»á¼ûƽ̨¡£¡£¡£¡£¡£´Ëǰ£¬£¬ £¬£¬£¬ £¬£¬MetaÔøÔÚ3Ô·ݺÍ2021ÄêÔâÓö¹ýÀàËÆµÄЧÀÍÖÐÖ¹¡£¡£¡£¡£¡£×èÖ¹ÃÀ¹ú¶«²¿Ê±¼ä12ÔÂ11ÈÕÏÂÖç7:21£¬£¬ £¬£¬£¬ £¬£¬MetaÌåÏÖÖÐÖ¹ÎÊÌâÒÑ»ù±¾½â¾ö£¬£¬ £¬£¬£¬ £¬£¬²¢ÏòÊÜÓ°ÏìµÄÓû§ÌåÏÖǸÒâ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/technology/facebook-instagram-whatsapp-hit-by-massive-worldwide-outage/


5. ¹ú¼ÊÐж¯¡°Operation PowerOFF¡±ÖØÈ­¹¥»÷DDoS³ö×âЧÀÍ


12ÔÂ11ÈÕ£¬£¬ £¬£¬£¬ £¬£¬¹ú¼ÊÐж¯¡°Operation PowerOFF¡±Õë¶ÔÍøÂç·¸·¨ÖеÄÂþÑÜʽ¾Ü¾øÐ§ÀÍ£¨DDoS£©¹¥»÷È¡µÃÁËÏÔÖøÐ§¹û¡£¡£¡£¡£¡£À´×Ô15¸ö¹ú¼ÒµÄÖ´·¨»ú¹¹ÏàÖú£¬£¬ £¬£¬£¬ £¬£¬ÀÖ³ÉÏÂÏßÁË27¸öDDoS³ö×âЧÀÍÆ½Ì¨£¬£¬ £¬£¬£¬ £¬£¬¾Ð²¶ÁËÈýÃûÖÎÀíÔ±£¬£¬ £¬£¬£¬ £¬£¬²¢È·¶¨ÁËÕâЩƽ̨µÄ300Ãû¿Í»§¡£¡£¡£¡£¡£ÕâЩƽ̨ʹÓý©Ê¬ÍøÂç¶ÔÔÚÏßÄ¿µÄÌᳫ¹¥»÷£¬£¬ £¬£¬£¬ £¬£¬¿ÉÄܵ¼ÖÂЧÀÍÖÐÖ¹ºÍÓªÒµËðʧ£¬£¬ £¬£¬£¬ £¬£¬ÌØÊâÊÇÔÚÍøÉϹºÎïá¯ÁëÆÚ¡£¡£¡£¡£¡£Å·ÖÞÐ̾¯×é֯Эµ÷ÁË´Ë´ÎÐж¯£¬£¬ £¬£¬£¬ £¬£¬Éæ¼°¶à¸ö¹ú¼Ò£¬£¬ £¬£¬£¬ £¬£¬Õë¶Ô¼ÓÈë´ËÀà·¸·¨µÄ¸÷¸ö²ãÃæµÄÖ°Ô±¡£¡£¡£¡£¡£ÆäÖУ¬£¬ £¬£¬£¬ £¬£¬ºÉÀ¼¾¯·½¾Ð²¶ÁËËÄÃûÉæÏÓʵÑéDDoS¹¥»÷µÄÏÓÒÉÈË£¬£¬ £¬£¬£¬ £¬£¬²¢È·¶¨ÁËÔ¼200ÃûÉæÏÓʹÓñ»²é»ñDDoSЧÀ͵ĺÉÀ¼ÈË¡£¡£¡£¡£¡£´Ë´ÎÐж¯µÄÀֳɵÃÒæÓÚÅ·ÖÞÐ̾¯×éÖ¯µÄÆÊÎöÖ§³Ö¡¢¼ÓÃÜ×·×ÙÐÅÏ¢ÒÔ¼°ÁªºÏÍøÂç·¸·¨Ðж¯ÌØÊâÊÂÇé×éר¼ÒµÄЭÖú¡£¡£¡£¡£¡£´Ëǰ£¬£¬ £¬£¬£¬ £¬£¬¡°Operation PowerOFF¡±ÒѶÔDDoS×âÁÞÁìÓò¾ÙÐÐÁ˶à´Î¹¥»÷£¬£¬ £¬£¬£¬ £¬£¬°üÀ¨²é·â´óÐÍÆ½Ì¨Dstat.ccºÍÈëÇÖ²¢¹Ø±ÕDigitalStressЧÀÍ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/operation-poweroff-shuts-down-27-ddos-for-hire-platforms/


6. Krispy KremeÔâÍøÂç¹¥»÷£¬£¬ £¬£¬£¬ £¬£¬Ó°ÏìÔÚÏß¶©¹ººÍÔËÓª


12ÔÂ11ÈÕ£¬£¬ £¬£¬£¬ £¬£¬ÃÀ¹úÌðÌðȦÁ¬ËøµêKrispy KremeÔÚ2024Äê11ÔÂÔâÊÜÁËÍøÂç¹¥»÷£¬£¬ £¬£¬£¬ £¬£¬µ¼ÖÂÆäÔÚÃÀ¹úµÄÔÚÏß¶©¹ºÏµÍ³ÖÐÖ¹£¬£¬ £¬£¬£¬ £¬£¬Ó°ÏìÁ˲¿·ÖÓªÒµÔËÓª¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÓµÓÐ1,521¼ÒÃŵêºÍÖÚ¶àÔ±¹¤£¬£¬ £¬£¬£¬ £¬£¬²¢ÓëÂóµ±À͵ÈÏàÖúͬ°éÓÐÆð¾¢¹ØÏµ¡£¡£¡£¡£¡£Êý×Ö¶©µ¥Õ¼¹«Ë¾ÏúÊÛ¶îµÄ15.5%£¬£¬ £¬£¬£¬ £¬£¬¶Ô¹«Ë¾Òµ¼¨ÓÐÖ÷ÒªÓ°Ïì¡£¡£¡£¡£¡£ÔÚ¹¥»÷±¬·¢ºó£¬£¬ £¬£¬£¬ £¬£¬Krispy KremeÁ¬Ã¦×·Çó¶¥¼âÍøÂçÇ徲ר¼ÒµÄ×ÊÖú£¬£¬ £¬£¬£¬ £¬£¬²¢½ÓÄɲ½·¥¿ØÖƺ͵÷½âÊÂÎñ£¬£¬ £¬£¬£¬ £¬£¬µ«ÊÓ²ìÈÔÔÚ¾ÙÐÐÖУ¬£¬ £¬£¬£¬ £¬£¬ÏêϸӰÏìÉдýÆÀ¹À¡£¡£¡£¡£¡£´Ë´Î¹¥»÷¶Ô¹«Ë¾µÄÓªÒµ±¬·¢ÁËÖØ´óÓ°Ï죬£¬ £¬£¬£¬ £¬£¬²¢½«Ò»Á¬µ½»Ö¸´Íê³ÉΪֹ¡£¡£¡£¡£¡£Í¬Ê±£¬£¬ £¬£¬£¬ £¬£¬¹«Ë¾Ô¤¼ÆÊý×ÖÏúÊÛÊÕÈëµÄËðʧ¡¢ÍøÂçÇ徲ר¼ÒºÍÕÕÁϵÄÓöÈÒÔ¼°ÏµÍ³»Ö¸´ÊÂÇéÏà¹ØµÄ±¾Ç®½«±¬·¢ÖØ´óµÄ²ÆÎñÓ°Ïì¡£¡£¡£¡£¡£Êг¡¶Ô´ËÐÂÎÅ×ö³öÁ˸ºÃæ·´Ó¦£¬£¬ £¬£¬£¬ £¬£¬Krispy KremeµÄ¹É¼ÛϵøÁË2%¡£¡£¡£¡£¡£ÏÖÔÚÉв»ÇåÎúÕâÊÇÒ»´ÎÀÕË÷Èí¼þ¹¥»÷ÕվɯäËûÀàÐ͵Ĺ¥»÷£¬£¬ £¬£¬£¬ £¬£¬Ò²Ã»ÓÐÀÕË÷Èí¼þ×éÖ¯¶Ô´Ë´Î¹¥»÷ÈÏÕæ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/krispy-kreme-cyberattack-impacts-online-orders-and-operations/