Binarly·¢Ã÷Ó°ÏìUEFIÖÐͼÏñÆÊÎö×é¼þµÄÎó²îLogoFAIL

Ðû²¼Ê±¼ä 2023-12-04
1¡¢Binarly·¢Ã÷Ó°ÏìUEFIÖÐͼÏñÆÊÎö×é¼þµÄÎó²îLogoFAIL


¾ÝýÌå11ÔÂ30ÈÕ±¨µÀ£¬Binarly·¢Ã÷ÁËͳ³ÆÎªLogoFAILµÄ¶à¸öÇå¾²Îó²î£¬¿ÉÓ°Ïì¸÷¸ö¹©Ó¦É̵ÄUEFI´úÂëÖеÄͼÏñÆÊÎö×é¼þ¡£Ñо¿Ö°Ô±·¢Ã÷£¬¹¥»÷Õß¿ÉÒÔ½«¶ñÒâͼÏñ»òlogo´æ´¢ÔÚEFIϵͳ·ÖÇø(ESP)»ò¹Ì¼þ¸üеÄδÊðÃû²¿·ÖÖС£ÒÔÕâÖÖ·½·¨Ö²Èë¶ñÒâÈí¼þ¿ÉÈ·±£ÔÚϵͳÖÐÒ»Á¬±£´æ£¬ÏÕЩ²»»á±»·¢Ã÷¡£BinarlyÒѾ­È·¶¨Ó¢Ìضû¡¢ºê³ž¡¢åÚÏëºÍÆäËü¹©Ó¦É̵ÄÊý°Ù¸öÐͺſÉÄܱ£´æÎó²î£¬¶¨ÖÆUEFI¹Ì¼þ´úÂëµÄÈý´ó×ÔÁ¦ÌṩÉÌAMI¡¢InsydeºÍPhoenixÒ²ÊÇÔÆÔÆ¡£ÏÖÔÚ£¬¸ÃÎó²îµÄÏêϸӰÏì¹æÄ£ÈÔÔÚÈ·¶¨ÖС£


https://www.bleepingcomputer.com/news/security/logofail-attack-can-install-uefi-bootkits-through-bootup-logos/


2¡¢ÃÀ¹ú¹«Ë¾StaplesÔâµ½ÍøÂç¹¥»÷ÓªÒµÔËÓªÊܵ½Ó°Ïì


ýÌå11ÔÂ30Èճƣ¬ÃÀ¹ú°ì¹«ÓÃÆ·ÁãÊÛÉÌStaplesÔâµ½ÍøÂç¹¥»÷ºó¹Ø±ÕÁ˲¿·Öϵͳ¡£×ÔÉÏÖÜÒ»ÒÔÀ´£¬StaplesÓöµ½ÁËÖÖÖÖÄÚ²¿ÔËÓªÎÊÌ⣬°üÀ¨ÎÞ·¨»á¼ûZendesk¡¢VPNÔ±¹¤ÃÅ»§¡¢´òÓ¡µç×ÓÓʼþºÍʹÓõ绰Ïߵȡ£ÓÐÔ±¹¤³Æ£¬Ò»Çж¼´¦ÓÚå´»ú״̬£¬ÔÚÃŵêÊÂÇéÎÞ·¨»á¼ûµç×ÓÓʼþ¡¢bizfit¡¢pogsºÍµç×Ó·þÎñ̨¡£StaplesÌåÏÖËûÃÇÔÚ11ÔÂ27ÈÕ·¢Ã÷¹¥»÷ºóÁ¬Ã¦½ÓÄÉÁËÏìÓ¦²½·¥£¬µ«Õâµ¼ÖÂØÊºǫ́´¦Öóͷ£ºÍ½»¸¶ÒÔ¼°Í¨Ñ¶ÇþµÀºÍ¿Í»§·þÎñÔÝʱÖÐÖ¹¡£¾ÝϤ£¬Õâ´Î¹¥»÷ÖÐûÓÐ×°ÖÃÀÕË÷Èí¼þ£¬Ò²Ã»ÓÐÎļþ±»¼ÓÃÜ¡£


https://www.bleepingcomputer.com/news/security/staples-confirms-cyberattack-behind-service-outages-delivery-issues/


3¡¢Ô¼60¼ÒÐÅÓÃÏàÖúÉçÒò¹©Ó¦É̱»ÀÕË÷¹¥»÷·þÎñÔÝʱÖÐÖ¹


12ÔÂ2ÈÕ±¨µÀ³Æ£¬ÔÆ·þÎñÌṩÉÌOngoing OperationsÔâµ½ÁËÀÕË÷¹¥»÷£¬ËüÁ¥ÊôÓÚÐÅÓÃÉçÊÖÒÕ¹«Ë¾Trellance¡£¹ú¼ÒÐÅÓÃÉçÖÎÀí¾Ö(NCUA)ÌåÏÖ£¬²¿·ÖÐÅÓÃÉçÊÕµ½ÁËÀ´×ÔOngoing OperationsµÄÐÅÏ¢£¬Í¸Â¶¸Ã¹«Ë¾ÔÚ11ÔÂ26ÈÕÔâµ½ÁËÀÕË÷¹¥»÷¡£ÏÖÔÚ£¬ÊÓ²ìÈÔÔÚ¾ÙÐÐÖУ¬ÏÖÒÑÈ·ÈÏÔ¼60¼ÒÐÅÓÃÏàÖúÉçÓÉÓÚµÚÈý·½·þÎñÌṩÉÌÔâµ½¹¥»÷£¬ÕýÔÚÂÄÀúÒ»¶¨Ë®Æ½µÄ·þÎñÖÐÖ¹¡£


https://therecord.media/credit-unions-facing-outages-due-to-ransomware


4¡¢Å²ÍþÀ͹¤ºÍ¸£ÀûÖÎÀí¾ÖÒòÊý¾Ýй¶±»· £¿î185ÍòÃÀÔª


¾Ý12ÔÂ3ÈÕ±¨µÀ£¬Å²ÍþÀ͹¤ºÍ¸£ÀûÖÎÀí¾Ö(NAV)±»Å²Íþî¿Ïµ¾Ö£¨Datatilsynet£©· £¿î170ÍòÅ·Ôª¡£Å²ÍþÊý¾Ý± £»¤¾ÖÔÚNAVµÄÉó¼ÆÖз¢Ã÷ÁË12ÆðÎ¥·´Ð¡ÎÒ˽¼ÒÊý¾Ý± £»¤ÌõÀýµÄÐÐΪ¡£×÷ΪÊÓ²ìµÄÒ»²¿·Ö£¬DPA·¢Ã÷¿ØÖÆÕßδÄܽÓÄÉÊʵ±µÄÊÖÒÕºÍ×éÖ¯²½·¥À´± £»¤Ð¡ÎÒ˽¼ÒÊý¾Ý£¬ÀýÈçITϵͳûÓлñµÃ³ä·ÖµÄ± £»¤¡£±ðµÄ£¬¹ý¶àµÄÔ±¹¤¿ÉÒÔ»á¼ûСÎÒ˽¼ÒÊý¾Ý£¬ÔÚijЩÇéÐÎϰüÀ¨ºÜÊÇÃô¸ÐµÄÊý¾Ý¡£Í¬Ê±£¬¿ØÖÆÕßδÄܶÔÔ±¹¤Ê¹ÓÃITϵͳ¾ÙÐÐϵͳµÄ¿ØÖÆ¡£


https://www.databreaches.net/norwegian-labor-and-welfare-administration-fined-for-data-protection-failures/


5¡¢Unit 42Åû¶Õë¶ÔÖж«¡¢·ÇÖÞºÍÃÀ¹úµÈµØµÄ¹¥»÷Ô˶¯


Unit 42ÔÚ12ÔÂ1ÈÕÅû¶ÁËкóÃÅAgent Raccoon£¬Ëü±»ÓÃÓÚÕë¶ÔÖж«¡¢·ÇÖÞºÍÃÀ¹úµÈµØµÄ¹¥»÷Ô˶¯¡£¸ÃÔ˶¯Ö÷ÒªÕë¶Ô½ÌÓý¡¢·¿µØ²ú¡¢ÁãÊÛ¡¢·ÇÓªÀû×éÖ¯¡¢µçÐŹ«Ë¾ºÍÕþ¸®»ú¹¹£¬¹¥»÷ÍŻﱻUnit 42×·×ÙΪCL-STA-0002¡£ºóÃÅÓÃ.NET¿ª·¢£¬²¢Ê¹ÓÃÓòÃû·þÎñ(DNS)ЭÒéÓëC2»ù´¡ÉèÊ©½¨ÉèÒþ²ØµÄͨѶͨµÀ¡£Agent RaccoonÔÚ¶à´Î¹¥»÷ÖÐÓëÆäËüÁ½¸ö¹¤¾ßÍŽáʹÓã¬ÆäÖÐÒ»¸öÊÇÇÔÈ¡Óû§Æ¾Ö¤µÄNetwork Provider DLLÄ £¿éNtospy£¬ÁíÒ»¸öÊDZ»³ÆÎªMimiliteµÄ¶¨ÖưæMimikatz¡£


https://unit42.paloaltonetworks.com/new-toolset-targets-middle-east-africa-usa/


6¡¢KasperskyÐû²¼2023ÄêQ3 ITÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ


12ÔÂ1ÈÕ£¬KasperskyÐû²¼ÁË2023ÄêµÚÈý¼¾¶ÈITÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£±¨¸æÖÐÌá¼°µÄÓÐÕë¶ÔÐԵĹ¥»÷ÆÊÎö°üÀ¨£ºÊ¹ÓÃDroxiDatºÍCobalt Strike¹¥»÷ÄÜÔ´ÐÐÒµ¡¢Ê¹ÓÃCVE-2023-23397Îó²îµÄ¹¥»÷¡¢Õë¶Ô¹¤¿ØÐÐÒµµÄ¹¥»÷Öг£¼ûµÄTTPºÍαÔìµÄTelegramÓ¦ÓõÈ¡£ÆäËü¶ñÒâÈí¼þ°üÀ¨£ºÕë¶ÔLinuxµÄ¹©Ó¦Á´¹¥»÷¡¢CubaÀÕË÷ÍŻй¶µÄLockbit 3¹¹½¨Æ÷¡¢Ò»Ö±Éú³¤µÄ¶ñÒâÈí¼þÃûÌÃÒÔ¼°cryptor¡¢stealerºÍbanking TrojanµÈ¡£


https://securelist.com/it-threat-evolution-q3-2023/111171/