¼ÓÖÝij¸£Àûƽ̨Ôâµ½¹¥»÷Êýǧ¸öÕË»§ÐÅϢй¶
Ðû²¼Ê±¼ä 2024-04-294ÔÂ27ÈÕ£¬£¬£¬£¬£¬£¬ÍþвÐÐΪÕßÈëÇÖÁ˼ÓÖÝÒ»¸öרÃÅÓÃÓÚ¸£ÀûÏîÄ¿µÄƽ̨É쵀 19000 ¶à¸öÔÚÏßÕÊ»§¡£¡£¡£¹ÙÔ±ÃDZ¨¸æ³Æ£¬£¬£¬£¬£¬£¬Çå¾²Îó²î±¬·¢ÔÚ 2 Ô 9 ÈÕ£¬£¬£¬£¬£¬£¬ÆäʱÓÐÈ˵ǼÁËһЩ BenefitsCal Óû§µÄÕË»§¡£¡£¡£ÍþвÐÐΪÕßʹÓôӵÚÈý·½ÍøÕ¾»ñµÃµÄÖØ¸´Ê¹ÓõÄÃÜÂë¡£¡£¡£BenefitsCal ÊÇÒ»¸öλÓÚ¼ÓÀû¸£ÄáÑÇÖݵÄÍøÂçÆ½Ì¨£¬£¬£¬£¬£¬£¬Ê¹Óû§Äܹ»ÉêÇëºÍ¼àÊÓһϵÁи£ÀûÍýÏ룬£¬£¬£¬£¬£¬°üÀ¨Ê³Îïȯ¡¢ÏÖ½ðÔ®ÖúºÍÒ½ÁƸ£Àû¡£¡£¡£Æ¾Ö¤ÈÕÆÚй¶֪ͨ£¬£¬£¬£¬£¬£¬Ç±ÔÚй¶µÄÐÅÏ¢¿ÉÄܰüÀ¨Óû§ÐÕÃû¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢Éç»áÇå¾²ºÅÂëµÄÍêÕû»ò×îºóËÄλÊý×Ö¡¢µç×ÓÓʼþµØµã¡¢µç»°ºÅÂë¡¢EBT ¿¨ºÅ¡¢°¸¼þ±àºÅ¡¢Medi-Cal ID ºÅÒÔ¼°ÓÐ¹ØÆäÍýÏë×ʸñºÍ¸£ÀûµÄÐÅÏ¢¡£¡£¡£BenefitsCal ÕýÔÚ֪ͨÊÜÓ°ÏìµÄÓû§²¢ÏòËûÃÇÌṩ¿ÉÒÔ×öʲôµÄ˵Ã÷¡£¡£¡£ÎªÁËÓ¦¶ÔÕâÒ»ÊÂÎñ£¬£¬£¬£¬£¬£¬¸Ã»ú¹¹Í£ÓÃÁËÕË»§²¢Æô¶¯ÁËÊӲ죬£¬£¬£¬£¬£¬Ð§¹ûÏÔʾ¹¥»÷ÕßÔÚ 2023 Äê 3 Ô 1 ÈÕÖÁ 2024 Äê 2 Ô 13 ÈÕʱ´úÓµÓлá¼ûȨÏÞ¡£¡£¡£
https://securityaffairs.com/162408/data-breach/california-state-welfare-platform-accounts-compromise.html
2. Å·ÖÞÐ̾¯×éÖ¯Ðû²¼ÔÚÖ´·¨Ðж¯ÖÐÈ¡µÞLabHost
4ÔÂ26ÈÕ£¬£¬£¬£¬£¬£¬Å·ÖÞÐ̾¯×éÖ¯Ðû²¼£¬£¬£¬£¬£¬£¬È«Çò×î´óµÄPhaasƽ̨֮һ LabHost ÔÚÈ«ÇòÖ´·¨Ðж¯Öб»µ·»Ù¡£¡£¡£À´×Ô²»ÉÙÓÚ 19 ¸ö¹ú¼ÒµÄÕþ¸®¼ÓÈëÁËÓÉÓ¢¹úÂ׶ؾ¯Ô±ÌüǣͷµÄΪÆÚÒ»ÄêµÄÐж¯£¬£¬£¬£¬£¬£¬¾Ð²¶ÁË 37 ÃûÏÓÒÉÈË£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨¾Ý³ÆÓë¸ÃЧÀÍÔËÓª¼°ÆäÔʼ¿ª·¢ÓйصÄÈË¡£¡£¡£È«ÇòÔ¼ÓÐ 10000 ÈËʹÓøÃЧÀÍ£¬£¬£¬£¬£¬£¬ÔÂ·ÑÆ½¾ùΪ 249 ÃÀÔª¡£¡£¡£ÊӲ췢Ã÷ÖÁÉÙ 40000 ¸öÓë LabHost Á´½ÓµÄÍøÂç´¹ÂÚÓòÃû£¬£¬£¬£¬£¬£¬²¢ÓÕÆÓû§½»³öÃô¸ÐÏêϸÐÅÏ¢¡£¡£¡£ÏàʶÓйØÊÓÆµÖеĴÌÍ´µÄ¸ü¶àÐÅÏ¢£¬£¬£¬£¬£¬£¬²¢È·±£ÄúÖªµÀÔõÑù×èÖ¹³ÉÎªÍøÂç´¹ÂÚ¹¥»÷µÄÊܺ¦Õß¡£¡£¡£ÔÚÆäËûÍøÂç·¸·¨ÐÂÎÅÖУ¬£¬£¬£¬£¬£¬ÃÀ¹úÖ´·¨²¿·Ö¶Ô Samourai Wallet¼ÓÃÜÇ®±Ò»ìÏýЧÀ͵ÄÊ×´´ÈËÌá³öϴǮָ¿Ø£¬£¬£¬£¬£¬£¬Í¬Ê±Áª°î¹¥»÷´ËÀàЧÀÍ¡£¡£¡£
https://www.welivesecurity.com/en/videos/major-phishing-as-a-service-platform-disrupted-week-security-tony-anscombe/
3. Ñо¿ÍŶӷ¢Ã÷ʹÓÃofficeÎó²îÕë¶ÔÎÚ¿ËÀ¼µÄ¹¥»÷»î¶¯
4ÔÂ27ÈÕ£¬£¬£¬£¬£¬£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÁËÕë¶ÔÎÚ¿ËÀ¼µÄÒ»ÏîÓÐÕë¶ÔÐԵĹ¥»÷»î¶¯£¬£¬£¬£¬£¬£¬¸ÃÐж¯Ê¹ÓÃÁË Microsoft Office ÖнüÆßÄêµÄij¸öÎó²î£¬£¬£¬£¬£¬£¬ÔÚÊÜѬȾµÄϵͳÉÏ´« Cobalt Strike¡£¡£¡£¾Ý Deep Instinct ³Æ£¬£¬£¬£¬£¬£¬¸Ã¹¥»÷Á´±¬·¢ÓÚ 2023 Äêµ×£¬£¬£¬£¬£¬£¬½ÓÄÉ PowerPoint »ÃµÆÆ¬Îļþ£¨¡°signal-2023-12-20-160512.ppsx¡±£©×÷ΪÆðµã£¬£¬£¬£¬£¬£¬ÎļþÃûÌåÏÖËü¿ÉÄÜÒÑͨ¹ý Signal ¼´Ê±Í¨Ñ¶Ó¦ÓóÌÐò¹²Ïí¡£¡£¡£Ö»¹ÜÔÆÔÆ£¬£¬£¬£¬£¬£¬Ã»ÓÐÏÖʵ֤¾ÝÅú×¢ PPSX ÎļþÊÇÒÔÕâÖÖ·½·¨·Ö·¢µÄ£¬£¬£¬£¬£¬£¬Ö»¹ÜÎÚ¿ËÀ¼ÅÌËã»ú½ôÆÈÏìӦС×é (CERT-UA) ·¢Ã÷ÁËÁ½¸öʹÓøÃÐÂÎÅÓ¦ÓóÌÐò×÷Ϊ¶ñÒâÈí¼þת´ïµÄ²î±ð»î¶¯ÒÑÍùµÄÏòÁ¿¡£¡£¡£ÕâÉæ¼°Ê¹ÓÃCVE-2017-8570£¨CVSS ·ÖÊý£º7.8£©£¬£¬£¬£¬£¬£¬ÕâÊÇ Office ÖÐÏÖÒÑÐÞ²¹µÄÔ¶³Ì´úÂëÖ´Ðйýʧ£¬£¬£¬£¬£¬£¬¸Ã¹ýʧ¿ÉÄÜÔÊÐí¹¥»÷ÕßÔÚ˵·þÊܺ¦Õß·¿ªÌØÖÆÎļþ¡¢¼ÓÔØÔ¶³Ì¾ç±¾ÍйÜÔÚ weavesilk[.]space ÉÏ¡£¡£¡£
https://thehackernews.com/2024/04/ukraine-targeted-in-cyberattack.html
4. Okta ÖÒÑÔ¿Í»§¿ÉÄÜÔâÊÜØ¨¹ÅδÓеÄײ¿â¹¥»÷
4ÔÂ27ÈÕ£¬£¬£¬£¬£¬£¬Okta ÖÒÑԳƣ¬£¬£¬£¬£¬£¬Õë¶ÔÆäÉí·ÝºÍ»á¼ûÖÎÃ÷È·¾ö¼Æ»®µÄײ¿â¹¥»÷·ºÆðÁËØ¨¹ÅδÓеļ¤Ôö¡£¡£¡£ÍþвÐÐΪÕßͨ¹ý×Ô¶¯ÊµÑéͨ³£´ÓÍøÂç·¸·¨·Ö×ÓÄÇÀﹺÖõÄÓû§ÃûºÍÃÜÂëÁÐ±í£¬£¬£¬£¬£¬£¬Ê¹ÓÃÆ¾Ö¤Ìî³äÀ´µÇ¼¡£¡£¡£Okta ÔÚ½ñÌìµÄÒ»·Ýͨ¸æÖÐÌåÏÖ£¬£¬£¬£¬£¬£¬ÕâЩ¹¥»÷ËÆºõÔ´×Ô Cisco Talos ֮ǰ±¨¸æµÄ±©Á¦ÆÆ½âºÍÃÜÂëÅçÉä¹¥»÷ÖÐʹÓõÄÏàͬ»ù´¡ÉèÊ©¡£¡£¡£ÔÚ Okta ÊӲ쵽µÄËùÓй¥»÷ÖУ¬£¬£¬£¬£¬£¬ÇëÇó¾ùÀ´×Ô TOR ÄäÃûÍøÂçºÍÖÖÖÖסլÊðÀí£¨ÀýÈç NSOCKS¡¢Luminati ºÍ DataImpulse£©¡£¡£¡£Okta ÌåÏÖ£¬£¬£¬£¬£¬£¬¼à²âµ½µÄ¹¥»÷Õë¶ÔÔÚ Okta Classic Engine ÉÏÔËÐÐÇÒ ThreatInsight ÉèÖÃΪ½öÉóºËģʽ¶ø²»ÊÇÈÕÖ¾ºÍÇ¿ÖÆÄ£Ê½µÄ×éÖ¯ÌØÊâÈÝÒס£¡£¡£Í¬Ñù£¬£¬£¬£¬£¬£¬²»¾Ü¾øÄäÃûÊðÆÊÎö¼ûµÄ×éÖ¯Ò²¿´µ½Á˸ü¸ßµÄ¹¥»÷ÀÖ³ÉÂÊ¡£¡£¡£Okta ÌåÏÖ£¬£¬£¬£¬£¬£¬Ö»ÓÐһС²¿·Ö¿Í»§µÄ¹¥»÷È¡µÃÁËÀֳɡ£¡£¡£
https://www.bleepingcomputer.com/news/security/okta-warns-of-unprecedented-credential-stuffing-attacks-on-customers/
5. ¾É´úÂëÖеÄйýʧºÍÕë¶Ô KASLR µÄ²àͨµÀ
4ÔÂ26ÈÕ£¬£¬£¬£¬£¬£¬¼´½«ÍƳöµÄ Windows 11 °æ±¾ 24H2 ÏÖÔÚÕýÔÚͨ¹ý Windows Insider ÍýÏë¾ÙÐйûÕæÔ¤ÀÀ¡£¡£¡£ÕâÆªÎÄÕÂÏÈÈÝÁË·¢Ã÷ 24H2 ÖÐÒýÈëµÄ¶à¸öÄÚºËÎó²î²¢±àдÎó²îʹÓóÌÐòµÄÀú³Ì£¬£¬£¬£¬£¬£¬°üÀ¨ÈƹýÄÚºË ASLR (KASLR) µÄÐÂÇ¿»¯¡£¡£¡£ÕâÀïÐÎòµÄËùÓÐÎó²î¶¼±£´æÓÚ NT ÄÚºË×Ô¼º (ntoskrnl.exe) ÖУ¬£¬£¬£¬£¬£¬Î»ÓÚ¿ÉÓÉÈκÎÀú³ÌŲÓõÄϵͳŲÓÃÖУ¬£¬£¬£¬£¬£¬ÎÞÂÛÆäȨÏÞ¼¶±ð»òɳÏäÔõÑù¡£¡£¡£ÔÚ 24H2 ¶Ô NT Äں˵ĸ÷¸ö²¿·Ö¾ÙÐÐÄæÏò¹¤³Ìʱ£¬£¬£¬£¬£¬£¬ÎÒ·¢Ã÷ÁËÁ½¸öÎó²î£¬£¬£¬£¬£¬£¬ÕâÁ½¸öÎó²î¶¼ÊÇÓû§Ä£Ê½ÄÚ´æµÄË«ÖØ»ñÈ¡¡£¡£¡£ÕâЩ¹ýÊ§ÌØÊâÓÐȤ£¬£¬£¬£¬£¬£¬ÓÉÓÚËüÃÇ·ºÆðÔÚÒÔǰÇå¾²µÄºã¾Ã±£´æµÄ´úÂëÖС£¡£¡£ÔÚÒÔǰµÄ Windows °æ±¾ÖУ¬£¬£¬£¬£¬£¬ÓÉÓÚÐí¶àϵͳŲÓÃÔÚÆäÊä³öÖаüÀ¨ÄÚºËÖ¸Õ룬£¬£¬£¬£¬£¬Òò´Ë»÷°Ü KASLR ÊÇ΢ȱ·¦µÀµÄ¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬£¬ÔÚ 24H2 ÖУ¬£¬£¬£¬£¬£¬ÕâЩÄں˵صã×ß©²»Ôٿɹ©·ÇÌØÈ¨Å²ÓÃÕßʹÓᣡ£¡£ÔÚûÓоµäµÄ KASLR ÈÆ¹ýµÄÇéÐÎÏ£¬£¬£¬£¬£¬£¬ÎªÁËÈ·¶¨Äں˵Ľṹ£¬£¬£¬£¬£¬£¬ÐèÒªÒ»ÖÖÐÂÊÖÒÕ¡£¡£¡£ÎÒÌý˵¹ýÒ»ÖÖÔÚ Linux ÉÏʹÓõÄÊÖÒÕ£¬£¬£¬£¬£¬£¬³ÆÎªEntryBleed£¬£¬£¬£¬£¬£¬ËüʹÓüÆÊ±ÅÔ·À´È·¶¨Äں˵ĵص㣬£¬£¬£¬£¬£¬²¢¾öÒéÑо¿ÊÇ·ñ¿ÉÒÔÔÚ Windows ÉÏʹÓÃÀàËÆµÄÊÖÒÕ¡£¡£¡£
https://exploits.forsale/24h2-nt-exploit/
6. ICICIÒøÐÐй¶17000Ãû¿Í»§µÄÐÅÓÿ¨Êý¾Ý
4ÔÂ28ÈÕ£¬£¬£¬£¬£¬£¬ICICI ÒøÐÐÊÇÓ¡¶ÈÁìÏȵÄ˽ÈËÒøÐÐÖ®Ò»£¬£¬£¬£¬£¬£¬ÒâÍâµØ½«ÊýǧÕÅÐÂÐÅÓÿ¨µÄÊý¾Ý̻¶¸ø·ÇÔ¤ÆÚÎüÊÕÕߵĿͻ§¡£¡£¡£ICICI ÒøÐÐÓÐÏÞ¹«Ë¾ÊÇÒ»¼ÒÓ¡¶È¿ç¹úÒøÐкͽðÈÚЧÀ͹«Ë¾£¬£¬£¬£¬£¬£¬×ܲ¿Î»ÓÚÃÏÂò¡£¡£¡£ËüΪÆóÒµºÍÁãÊÛ¿Í»§ÌṩÆÕ±éµÄÒøÐкͽðÈÚЧÀÍ¡£¡£¡£¸ÃÒøÐÐÔÚÓ¡¶È¸÷µØÓµÓÐ 6000 ¼Ò·ÖÐÐºÍ 17000 ̨ ATM »ú£¬£¬£¬£¬£¬£¬ÓªÒµÆÕ±é 17 ¸ö¹ú¼Ò¡£¡£¡£ÓÉÓÚÆäÒÆ¶¯ÒøÐÐÓ¦ÓóÌÐò¡°iMobile¡±ÖеÄÊÖÒÕ¹ýʧ£¬£¬£¬£¬£¬£¬¸ÃÒøÐж³½áÁË 17,000 ÕÅÐÅÓÿ¨¡£¡£¡£¸Ã¹ÊÕϵ¼ÖÂÓû§¿É»ñÈ¡ÆäËû¿Í»§µÄÏêϸÐÅÏ¢¡£¡£¡£Ì»Â¶µÄ²ÆÎñÐÅÏ¢°üÀ¨ÐÅÓÿ¨ºÅ¡¢ÓÐÓÃÆÚºÍ¿¨ÑéÖ¤Öµ (CVV)¡£¡£¡£ÔÚһЩ¿Í»§ÔÚÉ罻ýÌåÉϱ¨¸æ¸ÃÎÊÌâºó£¬£¬£¬£¬£¬£¬¸ÃÒøÐÐÒâʶµ½ÁËÕâÒ»ÎÊÌâ¡£¡£¡£¸ÃÒøÐÐÌåÏÖ£¬£¬£¬£¬£¬£¬¸ÃÊÂÎñÓ°ÏìÁ˸ÃÒøÐÐÔ¼ 0.1% µÄÐÅÓÿ¨¡£¡£¡£ICICI ÒøÐÐÕýÔÚÏòÊÜÓ°ÏìµÄ¿Í»§¿¯ÐÐеÄÐÅÓÿ¨¡£¡£¡£2023 Äê 4 Ô£¬£¬£¬£¬£¬£¬Cybernews µÄÑо¿Ö°Ô±±¨¸æ³Æ£¬£¬£¬£¬£¬£¬ICICI ÒøÐÐй¶ÁËÊý°ÙÍòÌõ°üÀ¨Ãô¸ÐÊý¾ÝµÄ¼Í¼£¬£¬£¬£¬£¬£¬°üÀ¨¸ÃÒøÐпͻ§µÄ²ÆÎñÐÅÏ¢ºÍСÎÒ˽¼ÒÎļþ¡£¡£¡£
https://securityaffairs.com/162479/security/icici-bank-technical-glitch.html


¾©¹«Íø°²±¸11010802024551ºÅ