Binarly·¢Ã÷Ó°ÏìUEFIÖÐͼÏñÆÊÎö×é¼þµÄÎó²îLogoFAIL

Ðû²¼Ê±¼ä 2023-12-04
1¡¢Binarly·¢Ã÷Ó°ÏìUEFIÖÐͼÏñÆÊÎö×é¼þµÄÎó²îLogoFAIL


¾ÝýÌå11ÔÂ30ÈÕ±¨µÀ£¬£¬£¬£¬ £¬£¬Binarly·¢Ã÷ÁËͳ³ÆÎªLogoFAILµÄ¶à¸öÇå¾²Îó²î£¬£¬£¬£¬ £¬£¬¿ÉÓ°Ïì¸÷¸ö¹©Ó¦É̵ÄUEFI´úÂëÖеÄͼÏñÆÊÎö×é¼þ¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬ £¬£¬¹¥»÷Õß¿ÉÒÔ½«¶ñÒâͼÏñ»òlogo´æ´¢ÔÚEFIϵͳ·ÖÇø(ESP)»ò¹Ì¼þ¸üеÄδÊðÃû²¿·ÖÖС£¡£¡£¡£¡£¡£¡£ÒÔÕâÖÖ·½·¨Ö²Èë¶ñÒâÈí¼þ¿ÉÈ·±£ÔÚϵͳÖÐÒ»Á¬±£´æ£¬£¬£¬£¬ £¬£¬ÏÕЩ²»»á±»·¢Ã÷¡£¡£¡£¡£¡£¡£¡£BinarlyÒѾ­È·¶¨Ó¢Ìضû¡¢ºê³ž¡¢åÚÏëºÍÆäËü¹©Ó¦É̵ÄÊý°Ù¸öÐͺſÉÄܱ£´æÎó²î£¬£¬£¬£¬ £¬£¬¶¨ÖÆUEFI¹Ì¼þ´úÂëµÄÈý´ó×ÔÁ¦ÌṩÉÌAMI¡¢InsydeºÍPhoenixÒ²ÊÇÔÆÔÆ¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬ £¬£¬¸ÃÎó²îµÄÏêϸӰÏì¹æÄ£ÈÔÔÚÈ·¶¨ÖС£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/logofail-attack-can-install-uefi-bootkits-through-bootup-logos/


2¡¢ÃÀ¹ú¹«Ë¾StaplesÔâµ½ÍøÂç¹¥»÷ÓªÒµÔËÓªÊܵ½Ó°Ïì


ýÌå11ÔÂ30Èճƣ¬£¬£¬£¬ £¬£¬ÃÀ¹ú°ì¹«ÓÃÆ·ÁãÊÛÉÌStaplesÔâµ½ÍøÂç¹¥»÷ºó¹Ø±ÕÁ˲¿·Öϵͳ¡£¡£¡£¡£¡£¡£¡£×ÔÉÏÖÜÒ»ÒÔÀ´£¬£¬£¬£¬ £¬£¬StaplesÓöµ½ÁËÖÖÖÖÄÚ²¿ÔËÓªÎÊÌ⣬£¬£¬£¬ £¬£¬°üÀ¨ÎÞ·¨»á¼ûZendesk¡¢VPNÔ±¹¤ÃÅ»§¡¢´òÓ¡µç×ÓÓʼþºÍʹÓõ绰Ïߵȡ£¡£¡£¡£¡£¡£¡£ÓÐÔ±¹¤³Æ£¬£¬£¬£¬ £¬£¬Ò»Çж¼´¦ÓÚå´»ú״̬£¬£¬£¬£¬ £¬£¬ÔÚÃŵêÊÂÇéÎÞ·¨»á¼ûµç×ÓÓʼþ¡¢bizfit¡¢pogsºÍµç×ÓЧÀĮ́¡£¡£¡£¡£¡£¡£¡£StaplesÌåÏÖËûÃÇÔÚ11ÔÂ27ÈÕ·¢Ã÷¹¥»÷ºóÁ¬Ã¦½ÓÄÉÁËÏìÓ¦²½·¥£¬£¬£¬£¬ £¬£¬µ«Õâµ¼ÖÂØÊºǫ́´¦Öóͷ£ºÍ½»¸¶ÒÔ¼°Í¨Ñ¶ÇþµÀºÍ¿Í»§Ð§ÀÍÔÝʱÖÐÖ¹¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬ £¬£¬Õâ´Î¹¥»÷ÖÐûÓÐ×°ÖÃÀÕË÷Èí¼þ£¬£¬£¬£¬ £¬£¬Ò²Ã»ÓÐÎļþ±»¼ÓÃÜ¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/staples-confirms-cyberattack-behind-service-outages-delivery-issues/


3¡¢Ô¼60¼ÒÐÅÓÃÏàÖúÉçÒò¹©Ó¦É̱»ÀÕË÷¹¥»÷ЧÀÍÔÝʱÖÐÖ¹


12ÔÂ2ÈÕ±¨µÀ³Æ£¬£¬£¬£¬ £¬£¬ÔÆÐ§ÀÍÌṩÉÌOngoing OperationsÔâµ½ÁËÀÕË÷¹¥»÷£¬£¬£¬£¬ £¬£¬ËüÁ¥ÊôÓÚÐÅÓÃÉçÊÖÒÕ¹«Ë¾Trellance¡£¡£¡£¡£¡£¡£¡£¹ú¼ÒÐÅÓÃÉçÖÎÀí¾Ö(NCUA)ÌåÏÖ£¬£¬£¬£¬ £¬£¬²¿·ÖÐÅÓÃÉçÊÕµ½ÁËÀ´×ÔOngoing OperationsµÄÐÅÏ¢£¬£¬£¬£¬ £¬£¬Í¸Â¶¸Ã¹«Ë¾ÔÚ11ÔÂ26ÈÕÔâµ½ÁËÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬ £¬£¬ÊÓ²ìÈÔÔÚ¾ÙÐÐÖУ¬£¬£¬£¬ £¬£¬ÏÖÒÑÈ·ÈÏÔ¼60¼ÒÐÅÓÃÏàÖúÉçÓÉÓÚµÚÈý·½Ð§ÀÍÌṩÉÌÔâµ½¹¥»÷£¬£¬£¬£¬ £¬£¬ÕýÔÚÂÄÀúÒ»¶¨Ë®Æ½µÄЧÀÍÖÐÖ¹¡£¡£¡£¡£¡£¡£¡£


https://therecord.media/credit-unions-facing-outages-due-to-ransomware


4¡¢Å²ÍþÀ͹¤ºÍ¸£ÀûÖÎÀí¾ÖÒòÊý¾Ýй¶±»· £¿£¿£¿£¿£¿î185ÍòÃÀÔª


¾Ý12ÔÂ3ÈÕ±¨µÀ£¬£¬£¬£¬ £¬£¬Å²ÍþÀ͹¤ºÍ¸£ÀûÖÎÀí¾Ö(NAV)±»Å²Íþî¿Ïµ¾Ö£¨Datatilsynet£©· £¿£¿£¿£¿£¿î170ÍòÅ·Ôª¡£¡£¡£¡£¡£¡£¡£Å²ÍþÊý¾Ý±£»£» £» £»£»£»¤¾ÖÔÚNAVµÄÉó¼ÆÖз¢Ã÷ÁË12ÆðÎ¥·´Ð¡ÎÒ˽¼ÒÊý¾Ý±£»£» £» £»£»£»¤ÌõÀýµÄÐÐΪ¡£¡£¡£¡£¡£¡£¡£×÷ΪÊÓ²ìµÄÒ»²¿·Ö£¬£¬£¬£¬ £¬£¬DPA·¢Ã÷¿ØÖÆÕßδÄܽÓÄÉÊʵ±µÄÊÖÒÕºÍ×éÖ¯²½·¥À´±£»£» £» £»£»£»¤Ð¡ÎÒ˽¼ÒÊý¾Ý£¬£¬£¬£¬ £¬£¬ÀýÈçITϵͳûÓлñµÃ³ä·ÖµÄ±£»£» £» £»£»£»¤¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ £¬£¬¹ý¶àµÄÔ±¹¤¿ÉÒÔ»á¼ûСÎÒ˽¼ÒÊý¾Ý£¬£¬£¬£¬ £¬£¬ÔÚijЩÇéÐÎϰüÀ¨ºÜÊÇÃô¸ÐµÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬ £¬£¬¿ØÖÆÕßδÄܶÔÔ±¹¤Ê¹ÓÃITϵͳ¾ÙÐÐϵͳµÄ¿ØÖÆ¡£¡£¡£¡£¡£¡£¡£


https://www.databreaches.net/norwegian-labor-and-welfare-administration-fined-for-data-protection-failures/


5¡¢Unit 42Åû¶Õë¶ÔÖж«¡¢·ÇÖÞºÍÃÀ¹úµÈµØµÄ¹¥»÷»î¶¯


Unit 42ÔÚ12ÔÂ1ÈÕÅû¶ÁËкóÃÅAgent Raccoon£¬£¬£¬£¬ £¬£¬Ëü±»ÓÃÓÚÕë¶ÔÖж«¡¢·ÇÖÞºÍÃÀ¹úµÈµØµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¸Ã»î¶¯Ö÷ÒªÕë¶Ô½ÌÓý¡¢·¿µØ²ú¡¢ÁãÊÛ¡¢·ÇÓªÀû×éÖ¯¡¢µçÐŹ«Ë¾ºÍÕþ¸®»ú¹¹£¬£¬£¬£¬ £¬£¬¹¥»÷ÍŻﱻUnit 42×·×ÙΪCL-STA-0002¡£¡£¡£¡£¡£¡£¡£ºóÃÅÓÃ.NET¿ª·¢£¬£¬£¬£¬ £¬£¬²¢Ê¹ÓÃÓòÃûЧÀÍ(DNS)ЭÒéÓëC2»ù´¡ÉèÊ©½¨ÉèÒþ²ØµÄͨѶͨµÀ¡£¡£¡£¡£¡£¡£¡£Agent RaccoonÔÚ¶à´Î¹¥»÷ÖÐÓëÆäËüÁ½¸ö¹¤¾ßÁ¬ÏµÊ¹Ó㬣¬£¬£¬ £¬£¬ÆäÖÐÒ»¸öÊÇÇÔÈ¡Óû§Æ¾Ö¤µÄNetwork Provider DLLÄ £¿£¿£¿£¿£¿éNtospy£¬£¬£¬£¬ £¬£¬ÁíÒ»¸öÊDZ»³ÆÎªMimiliteµÄ¶¨ÖưæMimikatz¡£¡£¡£¡£¡£¡£¡£


https://unit42.paloaltonetworks.com/new-toolset-targets-middle-east-africa-usa/


6¡¢KasperskyÐû²¼2023ÄêQ3 ITÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ


12ÔÂ1ÈÕ£¬£¬£¬£¬ £¬£¬KasperskyÐû²¼ÁË2023ÄêµÚÈý¼¾¶ÈITÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£±¨¸æÖÐÌá¼°µÄÓÐÕë¶ÔÐԵĹ¥»÷ÆÊÎö°üÀ¨£ºÊ¹ÓÃDroxiDatºÍCobalt Strike¹¥»÷ÄÜÔ´ÐÐÒµ¡¢Ê¹ÓÃCVE-2023-23397Îó²îµÄ¹¥»÷¡¢Õë¶Ô¹¤¿ØÐÐÒµµÄ¹¥»÷Öг£¼ûµÄTTPºÍαÔìµÄTelegramÓ¦ÓõÈ¡£¡£¡£¡£¡£¡£¡£ÆäËü¶ñÒâÈí¼þ°üÀ¨£ºÕë¶ÔLinuxµÄ¹©Ó¦Á´¹¥»÷¡¢CubaÀÕË÷ÍŻй¶µÄLockbit 3¹¹½¨Æ÷¡¢Ò»Ö±Éú³¤µÄ¶ñÒâÈí¼þÃûÌÃÒÔ¼°cryptor¡¢stealerºÍbanking TrojanµÈ¡£¡£¡£¡£¡£¡£¡£


https://securelist.com/it-threat-evolution-q3-2023/111171/