Binarly·¢Ã÷Ó°ÏìUEFIÖÐͼÏñÆÊÎö×é¼þµÄÎó²îLogoFAIL

Ðû²¼Ê±¼ä 2023-12-04
1¡¢Binarly·¢Ã÷Ó°ÏìUEFIÖÐͼÏñÆÊÎö×é¼þµÄÎó²îLogoFAIL


¾ÝýÌå11ÔÂ30ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬Binarly·¢Ã÷ÁËͳ³ÆÎªLogoFAILµÄ¶à¸öÇå¾²Îó²î£¬£¬£¬£¬£¬£¬¿ÉÓ°Ïì¸÷¸ö¹©Ó¦É̵ÄUEFI´úÂëÖеÄͼÏñÆÊÎö×é¼þ¡£¡£¡£¡£¡£ ¡£¡£Ñо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ½«¶ñÒâͼÏñ»òlogo´æ´¢ÔÚEFIϵͳ·ÖÇø(ESP)»ò¹Ì¼þ¸üеÄδÊðÃû²¿·ÖÖС£¡£¡£¡£¡£ ¡£¡£ÒÔÕâÖÖ·½·¨Ö²Èë¶ñÒâÈí¼þ¿ÉÈ·±£ÔÚϵͳÖÐÒ»Á¬±£´æ£¬£¬£¬£¬£¬£¬ÏÕЩ²»»á±»·¢Ã÷¡£¡£¡£¡£¡£ ¡£¡£BinarlyÒѾ­È·¶¨Ó¢Ìضû¡¢ºê³ž¡¢åÚÏëºÍÆäËü¹©Ó¦É̵ÄÊý°Ù¸öÐͺſÉÄܱ£´æÎó²î£¬£¬£¬£¬£¬£¬¶¨ÖÆUEFI¹Ì¼þ´úÂëµÄÈý´ó×ÔÁ¦ÌṩÉÌAMI¡¢InsydeºÍPhoenixÒ²ÊÇÔÆÔÆ¡£¡£¡£¡£¡£ ¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬¸ÃÎó²îµÄÏêϸӰÏì¹æÄ£ÈÔÔÚÈ·¶¨ÖС£¡£¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/logofail-attack-can-install-uefi-bootkits-through-bootup-logos/


2¡¢ÃÀ¹ú¹«Ë¾StaplesÔâµ½ÍøÂç¹¥»÷ÓªÒµÔËÓªÊܵ½Ó°Ïì


ýÌå11ÔÂ30Èճƣ¬£¬£¬£¬£¬£¬ÃÀ¹ú°ì¹«ÓÃÆ·ÁãÊÛÉÌStaplesÔâµ½ÍøÂç¹¥»÷ºó¹Ø±ÕÁ˲¿·Öϵͳ¡£¡£¡£¡£¡£ ¡£¡£×ÔÉÏÖÜÒ»ÒÔÀ´£¬£¬£¬£¬£¬£¬StaplesÓöµ½ÁËÖÖÖÖÄÚ²¿ÔËÓªÎÊÌ⣬£¬£¬£¬£¬£¬°üÀ¨ÎÞ·¨»á¼ûZendesk¡¢VPNÔ±¹¤ÃÅ»§¡¢´òÓ¡µç×ÓÓʼþºÍʹÓõ绰Ïߵȡ£¡£¡£¡£¡£ ¡£¡£ÓÐÔ±¹¤³Æ£¬£¬£¬£¬£¬£¬Ò»Çж¼´¦ÓÚå´»ú״̬£¬£¬£¬£¬£¬£¬ÔÚÃŵêÊÂÇéÎÞ·¨»á¼ûµç×ÓÓʼþ¡¢bizfit¡¢pogsºÍµç×ÓЧÀĮ́¡£¡£¡£¡£¡£ ¡£¡£StaplesÌåÏÖËûÃÇÔÚ11ÔÂ27ÈÕ·¢Ã÷¹¥»÷ºóÁ¬Ã¦½ÓÄÉÁËÏìÓ¦²½·¥£¬£¬£¬£¬£¬£¬µ«Õâµ¼ÖÂØÊºǫ́´¦Öóͷ£ºÍ½»¸¶ÒÔ¼°Í¨Ñ¶ÇþµÀºÍ¿Í»§Ð§ÀÍÔÝʱÖÐÖ¹¡£¡£¡£¡£¡£ ¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬Õâ´Î¹¥»÷ÖÐûÓÐ×°ÖÃÀÕË÷Èí¼þ£¬£¬£¬£¬£¬£¬Ò²Ã»ÓÐÎļþ±»¼ÓÃÜ¡£¡£¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/staples-confirms-cyberattack-behind-service-outages-delivery-issues/


3¡¢Ô¼60¼ÒÐÅÓÃÏàÖúÉçÒò¹©Ó¦É̱»ÀÕË÷¹¥»÷ЧÀÍÔÝʱÖÐÖ¹


12ÔÂ2ÈÕ±¨µÀ³Æ£¬£¬£¬£¬£¬£¬ÔÆÐ§ÀÍÌṩÉÌOngoing OperationsÔâµ½ÁËÀÕË÷¹¥»÷£¬£¬£¬£¬£¬£¬ËüÁ¥ÊôÓÚÐÅÓÃÉçÊÖÒÕ¹«Ë¾Trellance¡£¡£¡£¡£¡£ ¡£¡£¹ú¼ÒÐÅÓÃÉçÖÎÀí¾Ö(NCUA)ÌåÏÖ£¬£¬£¬£¬£¬£¬²¿·ÖÐÅÓÃÉçÊÕµ½ÁËÀ´×ÔOngoing OperationsµÄÐÅÏ¢£¬£¬£¬£¬£¬£¬Í¸Â¶¸Ã¹«Ë¾ÔÚ11ÔÂ26ÈÕÔâµ½ÁËÀÕË÷¹¥»÷¡£¡£¡£¡£¡£ ¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬ÊÓ²ìÈÔÔÚ¾ÙÐÐÖУ¬£¬£¬£¬£¬£¬ÏÖÒÑÈ·ÈÏÔ¼60¼ÒÐÅÓÃÏàÖúÉçÓÉÓÚµÚÈý·½Ð§ÀÍÌṩÉÌÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬ÕýÔÚÂÄÀúÒ»¶¨Ë®Æ½µÄЧÀÍÖÐÖ¹¡£¡£¡£¡£¡£ ¡£¡£


https://therecord.media/credit-unions-facing-outages-due-to-ransomware


4¡¢Å²ÍþÀ͹¤ºÍ¸£ÀûÖÎÀí¾ÖÒòÊý¾Ýй¶±»·£¿£¿£¿£¿î185ÍòÃÀÔª


¾Ý12ÔÂ3ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬Å²ÍþÀ͹¤ºÍ¸£ÀûÖÎÀí¾Ö(NAV)±»Å²Íþî¿Ïµ¾Ö£¨Datatilsynet£©·£¿£¿£¿£¿î170ÍòÅ·Ôª¡£¡£¡£¡£¡£ ¡£¡£Å²ÍþÊý¾Ý±£»£»£»£»£»£» £»£»¤¾ÖÔÚNAVµÄÉó¼ÆÖз¢Ã÷ÁË12ÆðÎ¥·´Ð¡ÎÒ˽¼ÒÊý¾Ý±£»£»£»£»£»£» £»£»¤ÌõÀýµÄÐÐΪ¡£¡£¡£¡£¡£ ¡£¡£×÷ΪÊÓ²ìµÄÒ»²¿·Ö£¬£¬£¬£¬£¬£¬DPA·¢Ã÷¿ØÖÆÕßδÄܽÓÄÉÊʵ±µÄÊÖÒÕºÍ×éÖ¯²½·¥À´±£»£»£»£»£»£» £»£»¤Ð¡ÎÒ˽¼ÒÊý¾Ý£¬£¬£¬£¬£¬£¬ÀýÈçITϵͳûÓлñµÃ³ä·ÖµÄ±£»£»£»£»£»£» £»£»¤¡£¡£¡£¡£¡£ ¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬¹ý¶àµÄÔ±¹¤¿ÉÒÔ»á¼ûСÎÒ˽¼ÒÊý¾Ý£¬£¬£¬£¬£¬£¬ÔÚijЩÇéÐÎϰüÀ¨ºÜÊÇÃô¸ÐµÄÊý¾Ý¡£¡£¡£¡£¡£ ¡£¡£Í¬Ê±£¬£¬£¬£¬£¬£¬¿ØÖÆÕßδÄܶÔÔ±¹¤Ê¹ÓÃITϵͳ¾ÙÐÐϵͳµÄ¿ØÖÆ¡£¡£¡£¡£¡£ ¡£¡£


https://www.databreaches.net/norwegian-labor-and-welfare-administration-fined-for-data-protection-failures/


5¡¢Unit 42Åû¶Õë¶ÔÖж«¡¢·ÇÖÞºÍÃÀ¹úµÈµØµÄ¹¥»÷»î¶¯


Unit 42ÔÚ12ÔÂ1ÈÕÅû¶ÁËкóÃÅAgent Raccoon£¬£¬£¬£¬£¬£¬Ëü±»ÓÃÓÚÕë¶ÔÖж«¡¢·ÇÖÞºÍÃÀ¹úµÈµØµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£ ¡£¡£¸Ã»î¶¯Ö÷ÒªÕë¶Ô½ÌÓý¡¢·¿µØ²ú¡¢ÁãÊÛ¡¢·ÇÓªÀû×éÖ¯¡¢µçÐŹ«Ë¾ºÍÕþ¸®»ú¹¹£¬£¬£¬£¬£¬£¬¹¥»÷ÍŻﱻUnit 42×·×ÙΪCL-STA-0002¡£¡£¡£¡£¡£ ¡£¡£ºóÃÅÓÃ.NET¿ª·¢£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃÓòÃûЧÀÍ(DNS)ЭÒéÓëC2»ù´¡ÉèÊ©½¨ÉèÒþ²ØµÄͨѶͨµÀ¡£¡£¡£¡£¡£ ¡£¡£Agent RaccoonÔÚ¶à´Î¹¥»÷ÖÐÓëÆäËüÁ½¸ö¹¤¾ßÁ¬ÏµÊ¹Ó㬣¬£¬£¬£¬£¬ÆäÖÐÒ»¸öÊÇÇÔÈ¡Óû§Æ¾Ö¤µÄNetwork Provider DLLÄ£¿£¿£¿£¿éNtospy£¬£¬£¬£¬£¬£¬ÁíÒ»¸öÊDZ»³ÆÎªMimiliteµÄ¶¨ÖưæMimikatz¡£¡£¡£¡£¡£ ¡£¡£


https://unit42.paloaltonetworks.com/new-toolset-targets-middle-east-africa-usa/


6¡¢KasperskyÐû²¼2023ÄêQ3 ITÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ


12ÔÂ1ÈÕ£¬£¬£¬£¬£¬£¬KasperskyÐû²¼ÁË2023ÄêµÚÈý¼¾¶ÈITÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£ ¡£¡£±¨¸æÖÐÌá¼°µÄÓÐÕë¶ÔÐԵĹ¥»÷ÆÊÎö°üÀ¨£ºÊ¹ÓÃDroxiDatºÍCobalt Strike¹¥»÷ÄÜÔ´ÐÐÒµ¡¢Ê¹ÓÃCVE-2023-23397Îó²îµÄ¹¥»÷¡¢Õë¶Ô¹¤¿ØÐÐÒµµÄ¹¥»÷Öг£¼ûµÄTTPºÍαÔìµÄTelegramÓ¦Óõȡ£¡£¡£¡£¡£ ¡£¡£ÆäËü¶ñÒâÈí¼þ°üÀ¨£ºÕë¶ÔLinuxµÄ¹©Ó¦Á´¹¥»÷¡¢CubaÀÕË÷ÍŻй¶µÄLockbit 3¹¹½¨Æ÷¡¢Ò»Ö±Éú³¤µÄ¶ñÒâÈí¼þÃûÌÃÒÔ¼°cryptor¡¢stealerºÍbanking TrojanµÈ¡£¡£¡£¡£¡£ ¡£¡£


https://securelist.com/it-threat-evolution-q3-2023/111171/