10/07/2567

Microsoft ออกแพทซ์อัปเดตประจำเดือน กรกฎาคม 2567


Microsoft ได้ทำการออกแพทซ์อัปเดตประเดือน กรกฎาคม 2567 ด้วยการอัปเดตความปลอดภัย 142 รายการ รวมถึงช่องโหว่ 2 รายการ และแก้ไขช่องโหว่แบบ Zero-Day ที่ถูกเปิดเผยแล้วอีกจำนวน 2 รายการ
การแก้ไขที่มากับการอัปเดตในรอบนี้ได้แก่ช่องโหว่ที่ร้ายแรงถึง 5 รายการ โดยใน 5 รายการนั้นเป็นช่องโหว่จากการใช้งาน RCE ทั้งหมดและมีรายการแก้ไขหรืออัปเดตดังต่อไปนี้:
  • 26 Elevation of Privilege Vulnerabilities
  • 24 Security Feature Bypass Vulnerabilities
  • 59 Remote Code Execution Vulnerabilities
  • 9 Information Disclosure Vulnerabilities
  • 17 Denial of Service Vulnerabilities
  • 7 Spoofing Vulnerabilities
รายละเอียดเพิ่มเติม
Windows 11 KB5040442: bleepingcomputer
Windows 10 KB5040427: bleepingcomputer

แก้ไขช่องโหว่ที่เป็น Zero-Day
ในการอัปเดตรอบนี้ได้มีการแก้ไขช่องโหว่ที่เป็น Zero-Day จำนวน 4 รายการด้วยกัน เป็นที่ถูกเปิดเผยแล้ว 2 และอีก 2 กำลังใช้โจมตีอยู่ในตอนนี้
2 รายการแรกนั้นกำลังถูกใช้โจมตีอย่างหนักและทำการแก้ไขแล้ว ดังนี้:
  • CVE-2024-38080 Windows Hyper-V Elevation of Privilege Vulnerability
    คือการที่ผู้ไม่ประสงค์ดีเมื่อโจมตีสำเร็จจะถูกยกระดับให้เป็นระบบ Systemadmin ทันที: update-guide
  • CVE-2024-38112 Windows MSHTML Platform Spoofing Vulnerability
    คือการที่ผู้ไม่ประสงค์ดีจะทำการปลอมแแปลง MSHTML ของ Windows ส่งไฟล์หรือแนบลิงค์โดยที่เป้าหมายนั้นต้องดำเนินการตามที่ระบุในเนื้อหา (บังคับ): update-guide

ช่องโหว่อีก 2 รายการที่ถูกเปิดเผยออกไปสู่สาธารนะ ดังนี้:
  • CVE-2024-35264 .NET and Visual Studio Remote Code Execution Vulnerability
ผู้ไม่ประสงค์ดีใช้ช่องโหว่ของ .NET และ Visual Studio โดยการปิดสตรีมแบบ http/3: update-guide
  • CVE-2024-37985 Arm: CVE-2024-37985 Systematic Identification and Characterization of Proprietary Prefetchers
ผู้ไม่ประสงค์ใช้ประโยชน์จากช่องโหว่นี้ได้สำเร็จจะสามารถดูหน่วยความจำฮีปจากกระบวนการที่มีสิทธิพิเศษที่ทำงานบนเซิร์ฟเวอร์ได้: update-guide

อับเดตจากบริษัทอื่น ๆ:
Adobe: Premiere Pro, InDesign และ Bridge Link
Cisco: NX-OS Software CLI Link
Fortinet: แก้ไขช่องโหว่ใน FortiOS และผลิตภัณฑ์อื่น ๆ Link
Mozilla: เปิดตัว Firefox128 และแก้ไขช่องโหว่ในหลายรายการ Link
OpenSSH: แก้ไขช่องโหว่ regreSSHion RCE Link
VMware: แก้ไขช่องโหว่การแทรก HTML ใน Cloud Director Link

รายการช่องโหว่ที่ได้รับการแก้ไขครบถ้วนในอัปเดต Patch Tuesday ประจำเดือนกรกฎาคม 2024
TagCVE IDCVE TitleSeverity
.NET and Visual StudioCVE-2024-30105.NET Core and Visual Studio Denial of Service VulnerabilityImportant
.NET and Visual StudioCVE-2024-38081.NET, .NET Framework, and Visual Studio Elevation of Privilege VulnerabilityImportant
.NET and Visual StudioCVE-2024-35264.NET and Visual Studio Remote Code Execution VulnerabilityImportant
.NET and Visual StudioCVE-2024-38095.NET and Visual Studio Denial of Service VulnerabilityImportant
Active Directory Rights Management ServicesCVE-2024-39684Github: CVE-2024-39684 TenCent RapidJSON Elevation of Privilege VulnerabilityModerate
Active Directory Rights Management ServicesCVE-2024-38517Github: CVE-2024-38517 TenCent RapidJSON Elevation of Privilege VulnerabilityModerate
Azure CycleCloudCVE-2024-38092Azure CycleCloud Elevation of Privilege VulnerabilityImportant
Azure DevOpsCVE-2024-35266Azure DevOps Server Spoofing VulnerabilityImportant
Azure DevOpsCVE-2024-35267Azure DevOps Server Spoofing VulnerabilityImportant
Azure Kinect SDKCVE-2024-38086Azure Kinect SDK Remote Code Execution VulnerabilityImportant
Azure Network WatcherCVE-2024-35261Azure Network Watcher VM Extension Elevation of Privilege VulnerabilityImportant
IntelCVE-2024-37985Arm: CVE-2024-37985 Systematic Identification and Characterization of Proprietary PrefetchersImportant
Line Printer Daemon Service (LPD)CVE-2024-38027Windows Line Printer Daemon Service Denial of Service VulnerabilityImportant
Microsoft Defender for IoTCVE-2024-38089Microsoft Defender for IoT Elevation of Privilege VulnerabilityImportant
Microsoft DynamicsCVE-2024-30061Microsoft Dynamics 365 (On-Premises) Information Disclosure VulnerabilityImportant
Microsoft Graphics ComponentCVE-2024-38079Windows Graphics Component Elevation of Privilege VulnerabilityImportant
Microsoft Graphics ComponentCVE-2024-38051Windows Graphics Component Remote Code Execution VulnerabilityImportant
Microsoft OfficeCVE-2024-38021Microsoft Office Remote Code Execution VulnerabilityImportant
Microsoft Office OutlookCVE-2024-38020Microsoft Outlook Spoofing VulnerabilityModerate
Microsoft Office SharePointCVE-2024-38024Microsoft SharePoint Server Remote Code Execution VulnerabilityImportant
Microsoft Office SharePointCVE-2024-38023Microsoft SharePoint Server Remote Code Execution VulnerabilityCritical
Microsoft Office SharePointCVE-2024-32987Microsoft SharePoint Server Information Disclosure VulnerabilityImportant
Microsoft Office SharePointCVE-2024-38094Microsoft SharePoint Remote Code Execution VulnerabilityImportant
Microsoft Streaming ServiceCVE-2024-38057Kernel Streaming WOW Thunk Service Driver Elevation of Privilege VulnerabilityImportant
Microsoft Streaming ServiceCVE-2024-38054Kernel Streaming WOW Thunk Service Driver Elevation of Privilege VulnerabilityImportant
Microsoft Streaming ServiceCVE-2024-38052Kernel Streaming WOW Thunk Service Driver Elevation of Privilege VulnerabilityImportant
Microsoft Windows Codecs LibraryCVE-2024-38055Microsoft Windows Codecs Library Information Disclosure VulnerabilityImportant
Microsoft Windows Codecs LibraryCVE-2024-38056Microsoft Windows Codecs Library Information Disclosure VulnerabilityImportant
Microsoft WS-DiscoveryCVE-2024-38091Microsoft WS-Discovery Denial of Service VulnerabilityImportant
NDISCVE-2024-38048Windows Network Driver Interface Specification (NDIS) Denial of Service VulnerabilityImportant
NPS RADIUS ServerCVE-2024-3596CERT/CC: CVE-2024-3596 RADIUS Protocol Spoofing VulnerabilityImportant
Role: Active Directory Certificate Services; Active Directory Domain ServicesCVE-2024-38061DCOM Remote Cross-Session Activation Elevation of Privilege VulnerabilityImportant
Role: Windows Hyper-VCVE-2024-38080Windows Hyper-V Elevation of Privilege VulnerabilityImportant
SQL ServerCVE-2024-28928SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-38088SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-20701SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-21317SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-21331SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-21308SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-21333SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-35256SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-21303SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-21335SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-35271SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-35272SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-21332SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-38087SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-21425SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-21449SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-37324SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-37330SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-37326SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-37329SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-37328SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-37327SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-37334Microsoft OLE DB Driver for SQL Server Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-37321SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-37320SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-37319SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-37322SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-37333SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-37336SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-37323SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-37331SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-21398SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-21373SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-37318SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-21428SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-21415SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-37332SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
SQL ServerCVE-2024-21414SQL Server Native Client OLE DB Provider Remote Code Execution VulnerabilityImportant
Windows BitLockerCVE-2024-38058BitLocker Security Feature Bypass VulnerabilityImportant
Windows COM SessionCVE-2024-38100Windows File Explorer Elevation of Privilege VulnerabilityImportant
Windows CoreMessagingCVE-2024-21417Windows Text Services Framework Elevation of Privilege VulnerabilityImportant
Windows Cryptographic ServicesCVE-2024-30098Windows Cryptographic Services Security Feature Bypass VulnerabilityImportant
Windows DHCP ServerCVE-2024-38044DHCP Server Service Remote Code Execution VulnerabilityImportant
Windows Distributed Transaction CoordinatorCVE-2024-38049Windows Distributed Transaction Coordinator Remote Code Execution VulnerabilityImportant
Windows Enroll EngineCVE-2024-38069Windows Enroll Engine Security Feature Bypass VulnerabilityImportant
Windows Fax and Scan ServiceCVE-2024-38104Windows Fax Service Remote Code Execution VulnerabilityImportant
Windows FilteringCVE-2024-38034Windows Filtering Platform Elevation of Privilege VulnerabilityImportant
Windows Image AcquisitionCVE-2024-38022Windows Image Acquisition Elevation of Privilege VulnerabilityImportant
Windows Imaging ComponentCVE-2024-38060Windows Imaging Component Remote Code Execution VulnerabilityCritical
Windows Internet Connection Sharing (ICS)CVE-2024-38105Windows Layer-2 Bridge Network Driver Denial of Service VulnerabilityImportant
Windows Internet Connection Sharing (ICS)CVE-2024-38053Windows Layer-2 Bridge Network Driver Remote Code Execution VulnerabilityImportant
Windows Internet Connection Sharing (ICS)CVE-2024-38102Windows Layer-2 Bridge Network Driver Denial of Service VulnerabilityImportant
Windows Internet Connection Sharing (ICS)CVE-2024-38101Windows Layer-2 Bridge Network Driver Denial of Service VulnerabilityImportant
Windows iSCSICVE-2024-35270Windows iSCSI Service Denial of Service VulnerabilityImportant
Windows KernelCVE-2024-38041Windows Kernel Information Disclosure VulnerabilityImportant
Windows Kernel-Mode DriversCVE-2024-38062Windows Kernel-Mode Driver Elevation of Privilege VulnerabilityImportant
Windows LockDown Policy (WLDP)CVE-2024-38070Windows LockDown Policy (WLDP) Security Feature Bypass VulnerabilityImportant
Windows Message QueuingCVE-2024-38017Microsoft Message Queuing Information Disclosure VulnerabilityImportant
Windows MSHTML PlatformCVE-2024-38112Windows MSHTML Platform Spoofing VulnerabilityImportant
Windows MultiPoint ServicesCVE-2024-30013Windows MultiPoint Services Remote Code Execution VulnerabilityImportant
Windows NTLMCVE-2024-30081Windows NTLM Spoofing VulnerabilityImportant
Windows Online Certificate Status Protocol (OCSP)CVE-2024-38068Windows Online Certificate Status Protocol (OCSP) Server Denial of Service VulnerabilityImportant
Windows Online Certificate Status Protocol (OCSP)CVE-2024-38067Windows Online Certificate Status Protocol (OCSP) Server Denial of Service VulnerabilityImportant
Windows Online Certificate Status Protocol (OCSP)CVE-2024-38031Windows Online Certificate Status Protocol (OCSP) Server Denial of Service VulnerabilityImportant
Windows Performance MonitorCVE-2024-38028Microsoft Windows Performance Data Helper Library Remote Code Execution VulnerabilityImportant
Windows Performance MonitorCVE-2024-38019Microsoft Windows Performance Data Helper Library Remote Code Execution VulnerabilityImportant
Windows Performance MonitorCVE-2024-38025Microsoft Windows Performance Data Helper Library Remote Code Execution VulnerabilityImportant
Windows PowerShellCVE-2024-38043PowerShell Elevation of Privilege VulnerabilityImportant
Windows PowerShellCVE-2024-38047PowerShell Elevation of Privilege VulnerabilityImportant
Windows PowerShellCVE-2024-38033PowerShell Elevation of Privilege VulnerabilityImportant
Windows Remote Access Connection ManagerCVE-2024-30071Windows Remote Access Connection Manager Information Disclosure VulnerabilityImportant
Windows Remote Access Connection ManagerCVE-2024-30079Windows Remote Access Connection Manager Elevation of Privilege VulnerabilityImportant
Windows Remote DesktopCVE-2024-38076Windows Remote Desktop Licensing Service Remote Code Execution VulnerabilityCritical
Windows Remote DesktopCVE-2024-38015Windows Remote Desktop Gateway (RD Gateway) Denial of Service VulnerabilityImportant
Windows Remote Desktop Licensing ServiceCVE-2024-38071Windows Remote Desktop Licensing Service Denial of Service VulnerabilityImportant
Windows Remote Desktop Licensing ServiceCVE-2024-38073Windows Remote Desktop Licensing Service Denial of Service VulnerabilityImportant
Windows Remote Desktop Licensing ServiceCVE-2024-38074Windows Remote Desktop Licensing Service Remote Code Execution VulnerabilityCritical
Windows Remote Desktop Licensing ServiceCVE-2024-38072Windows Remote Desktop Licensing Service Denial of Service VulnerabilityImportant
Windows Remote Desktop Licensing ServiceCVE-2024-38077Windows Remote Desktop Licensing Service Remote Code Execution VulnerabilityCritical
Windows Remote Desktop Licensing ServiceCVE-2024-38099Windows Remote Desktop Licensing Service Denial of Service VulnerabilityImportant
Windows Secure BootCVE-2024-38065Secure Boot Security Feature Bypass VulnerabilityImportant
Windows Secure BootCVE-2024-37986Secure Boot Security Feature Bypass VulnerabilityImportant
Windows Secure BootCVE-2024-37981Secure Boot Security Feature Bypass VulnerabilityImportant
Windows Secure BootCVE-2024-37987Secure Boot Security Feature Bypass VulnerabilityImportant
Windows Secure BootCVE-2024-28899Secure Boot Security Feature Bypass VulnerabilityImportant
Windows Secure BootCVE-2024-26184Secure Boot Security Feature Bypass VulnerabilityImportant
Windows Secure BootCVE-2024-38011Secure Boot Security Feature Bypass VulnerabilityImportant
Windows Secure BootCVE-2024-37984Secure Boot Security Feature Bypass VulnerabilityImportant
Windows Secure BootCVE-2024-37988Secure Boot Security Feature Bypass VulnerabilityImportant
Windows Secure BootCVE-2024-37977Secure Boot Security Feature Bypass VulnerabilityImportant
Windows Secure BootCVE-2024-37978Secure Boot Security Feature Bypass VulnerabilityImportant
Windows Secure BootCVE-2024-37974Secure Boot Security Feature Bypass VulnerabilityImportant
Windows Secure BootCVE-2024-38010Secure Boot Security Feature Bypass VulnerabilityImportant
Windows Secure BootCVE-2024-37989Secure Boot Security Feature Bypass VulnerabilityImportant
Windows Secure BootCVE-2024-37970Secure Boot Security Feature Bypass VulnerabilityImportant
Windows Secure BootCVE-2024-37975Secure Boot Security Feature Bypass VulnerabilityImportant
Windows Secure BootCVE-2024-37972Secure Boot Security Feature Bypass VulnerabilityImportant
Windows Secure BootCVE-2024-37973Secure Boot Security Feature Bypass VulnerabilityImportant
Windows Secure BootCVE-2024-37971Secure Boot Security Feature Bypass VulnerabilityImportant
Windows Secure BootCVE-2024-37969Secure Boot Security Feature Bypass VulnerabilityImportant
Windows Server BackupCVE-2024-38013Microsoft Windows Server Backup Elevation of Privilege VulnerabilityImportant
Windows TCP/IPCVE-2024-38064Windows TCP/IP Information Disclosure VulnerabilityImportant
Windows ThemesCVE-2024-38030Windows Themes Spoofing VulnerabilityImportant
Windows Win32 Kernel SubsystemCVE-2024-38085Windows Graphics Component Elevation of Privilege VulnerabilityImportant
Windows Win32K - GRFXCVE-2024-38066Windows Win32k Elevation of Privilege VulnerabilityImportant
Windows Win32K - ICOMPCVE-2024-38059Win32k Elevation of Privilege VulnerabilityImportant
Windows Workstation ServiceCVE-2024-38050Windows Workstation Service Elevation of Privilege VulnerabilityImportant
XBox Crypto Graphic ServicesCVE-2024-38032Microsoft Xbox Remote Code Execution VulnerabilityImportant
XBox Crypto Graphic ServicesCVE-2024-38078Xbox Wireless Adapter Remote Code Execution VulnerabilityImportant


รายละเอียดเพิ่มเติม: Link

09/07/2567

Microsoft เตือนผู้ใช้งาน Windows 11 22H2 จะสิ้นสุดการให้บริการในเดือนตุลาคม 2567


    วันที่ 9 กรกฏาคม 2567 ทาง Microsoft ได้ออกมาแจ้งเตือนถึงกลุ่มผู้ใช้งาน Windows 11 Home, Pro, Pro Education และ Pro for Workstations ที่เวอร์ชั่น 22H2 ที่ได้เปิดตัวให้ใช้งานตั้งแต่วันที่ 20 กันยายน 2022 จะสิ้นสุดการให้บริการ (EOS) ในวันที่ 8 ตุลาคม 2567 ทาง Microsoft ได้กล่าวก่อนการอัปเดตแพทซ์ความปลอดภัยในเดือนตุลาคม 2024 และในวันเดียวกันนั้นเอง Windows 11 21H2 Enterprise, Education และ IoT Enterprise ก็จะสิ้นสุดการให้บริการเช่นเดียวกัน

Microsoft ออกแนวบังคับให้ผู้ใช้งานต้องทำการติดตั้ง Windows 11 เวอร์ชั้น 2023
    Microsoft เริ่มบังคับติดตั้งการอัปเดตนี้ในเดือนกุมภาพันธ์บนระบบที่มีสิทธิ์ซึ่งถึงหรือใกล้ถึงวันที่สิ้นสุดบริการแล้วพร้อมยังกล่าวเพิ่มเติมว่า "Windows 11 เวอร์ชัน 23H2 หรือที่เรียกอีกอย่างว่า Windows 11 2023 Update กำลังเข้าสู่ขั้นตอนการเปิดตัวใหม่ เรากำลังเริ่มอัปเดตอุปกรณ์ Windows 11 ที่มีสิทธิ์เป็นเวอร์ชัน 23H2 โดยอัตโนมัติ"


    โดยที่คุณสามารถตรวจสอบระบบปฏิบัติการของคุณเองได้โดยไปที่ Find Windows 11 specs หรือใช้งาน PC Health Check app
หมายเหตุ support.microsoft

08/07/2567

New Ransomware Eldorado ที่กำลังโจมตีกำหนดเป้าหมายเป็นกลุ่มผู้ใช้งาน Windows และ VMware ESXI VMs

 

    มีการแจ้งเตือนจากทีมรักษาความปลอดภัยของ Group-IB ได้พบการโจมตีแบบ Ransomware-as-a-Service (RaaS) ที่ใช้ชื่อว่า Eldorado
    โดยมีกลุ่มเป้าหมายเป็นกลุ่มผู้ใช้งาน Windows และ VMware ESXI VMs มีการพบการแจ้งเหตุการณ์นี้ไปยัง CISA ของสหรัฐฯ ว่าบริษัท หรือหน่วยงานของตนนั้นถูกโจมตีด้วย Eldorado แล้วถึง 16 รายแต่ส่วนมากอยู่ในสหรัฐ ในภาคของ อสังหา การศีกษา สุขภาพ และสายการผลิต
    ทีมรักษาความปลอดภัยของ Group-IB ได้มีการติดตามการดำเนินกิจกรรมของกลุ่ม Eldorado พบว่ามีการโปรโมตการให้บริการ RaaS Eldorado ผ่านทาง Forum RAMPและเปิดให้ผู้ทีมีความสามารถในเรื่องของการเจาะระบบเข้าร่วมทีม ด้วยการโปรโมตว่า Eldorado ได้ทำการโจมตีไปยังหน่วยงานต่าง ๆ ในสหรัฐ ฯ อิตาลี และ โครเอเชีย


การโจมตีบน Windows และ Linux
    Eldorado เป็น Ransomware ที่ใช้ Go ซึ่งสามารถเข้ารหัสได้บนแพลต์ฟอร์ม Windows และ Linux ผ่านวิธีการต่าง ๆ กันไปแต่การทำงานเหมือนกันพร้อมทั้งยังกล่าวอีกว่า
    Eldoraro นั้นเป็น Malware ที่มีความเป็นเอกเทศน์สูง เพราะพัฒนาด้วยตนเองและไม่สนใจแหล่งความรู้อื่น ๆ เมื่อถูกเข้ารหัส Eldorado คำขู่มาในรูปแบบ Text ไฟล์จะถูกวางใว้ที่ Desktop


    Eldorado ยังเข้ารหัสการแชร์เครือข่ายโดยใช้โปรโตคอลการสื่อสาร SMB เพื่อเพิ่มผลกระทบให้สูงสุดและจะลบ Shadow Copy เพื่อป้องกันการกู้คืนอีกครั้งและรวมไปถึงไฟล์จำพวก
.DLL, .LNk, .SYS, .EXE ตลอดจนไฟล์ Directory ที่เกี่ยวกับการบูจและฟังก์ชั่นพื้นฐานเพื่อไม่ให้เป้าหมายทำอะไรกับเครื่องได้เลย

วิธีการป้องกัน Malware Eldorado ที่สามารถป้องกันได้ในระดับหนึ่งมีวิธีการดังนี้:
  • เปิดใช้งานระบบตรวจสอบหลายปัจจุบัย Multifactor Autentication
  • เปิดใช้งาน Endpoint Detection and Response (EDR)
  • ทำการ Backup ข้อมูลอยู่สม่ำเสมอ
  • Update Patch ของระบบต่าง ๆ ให้เป็นปัจจุบันสม่ำเสมอ

04/07/2567

เครือข่ายองค์กร TeamViewer ถูกโจมตีจากกลุ่มผู้ไม่ประสงค์ดี


    TeamViewer บริษัทซอฟต์แวร์สำหรับ Remote Access ออกมายืนยันว่าระบบของบริษัทได้ถูกโจมตีทางไซเบอร์เมื่อวันที่ 26 มิถุนายน ที่ผ่านมา โดยบริษัทคาดว่าผู้โจมตีเป็นกลุ่ม APT
    ทาง Team Viewer ได้เผยว่า ได้ใช้มาตรการ และขั้นตอนด้านความปลอดภัยทันที เริ่มจากการสอบสวนร่วมกับทีมผู้เชี่ยวชาญด้านความปลอดภัยทางไซเบอร์ที่มีชื่อเสียงระดับโลก และดำเนินการแก้ไขที่จำเป็น
    ระบบไอทีภายในของ TeamViewer ถูกแยกออกจากระบบหลักโดยสิ้นเชิง ยังไม่มีหลักฐานที่แสดงให้เห็นว่าระบบหลัก หรือข้อมูลของลูกค้าได้รับผลกระทบ แต่การตรวจสอบยังคงมีการดำเนินต่อไป และเป้าหมายหลักของบริษัทยังคงเป็นการรักษาความสมบูรณ์ของระบบ

    TeamViewer เป็นซอฟต์แวร์สำหรับ Remote Access ที่ได้รับความนิยมอย่างมาก ซึ่งช่วยให้ผู้ใช้สามารถควบคุมคอมพิวเตอร์จากระยะไกล และใช้งานได้ราวกับว่านั่งอยู่หน้าอุปกรณ์ บริษัทระบุว่าปัจจุบันมีลูกค้าใช้งานมากกว่า 640,000 รายทั่วโลก และมีการติดตั้งบนอุปกรณ์มากกว่า 2.5 พันล้านเครื่องนับตั้งแต่บริษัทเปิดตัว
   แม้ว่า TeamViewer จะระบุว่าไม่มีหลักฐานว่าระบบหลัก หรือข้อมูลของลูกค้าถูกละเมิด แต่การใช้งานอย่างแพร่หลายทั้งในระดับผู้บริโภค และระดับองค์กร ทำให้การถูกโจมตีของ TeamViewer เป็นเรื่องที่น่ากังวลอย่างมาก เนื่องจากอาจจะทำให้ผู้โจมตีสามารถเข้าถึงเครือข่ายภายในได้อย่างเต็มรูปแบบในปี 2019 TeamViewer เคยยืนยันเหตุการณ์การถูกโจมตีในปี 2016 ที่เชื่อมโยงกับกลุ่มแฮ็กเกอร์ชาวจีน เนื่องจากการใช้แบ็กดอร์ Winnti โดยบริษัทระบุว่าไม่ได้เปิดเผยการถูกโจมตีในช่วงเวลานั้น เนื่องจากไม่มีการขโมยข้อมูลจากการโจมตี

กลุ่ม APT ที่ถูกกล่าวหาว่าอยู่เบื้องหลังการโจมตี
    ข่าวการโจมตีถูกเปิดเผยครั้งแรกบน Mastodon โดย Jeffrey ผู้เชี่ยวชาญด้านความปลอดภัยด้านไอที ซึ่งแชร์ส่วนหนึ่งของการแจ้งเตือนบน Dutch Digital Trust Center ซึ่งเป็นเว็บพอร์ทัลที่ใช้โดยรัฐบาล ผู้เชี่ยวชาญด้านความปลอดภัย และบริษัทในเนเธอร์แลนด์เพื่อแบ่งปันข้อมูลเกี่ยวกับภัยคุกคามด้านความปลอดภัยทางไซเบอร์
 การแจ้งเตือนจากบริษัทด้านความปลอดภัยทางไซเบอร์ NCC Group ระบุว่า ทีม Global Threat Intelligence ของ NCC Group ได้รับทราบถึงการถูกโจมตีของ TeamViewer โดยกลุ่ม APT เนื่องจากการใช้งานซอฟต์แวร์นี้อย่างแพร่หลาย การแจ้งเตือนต่อไปนี้จึงถูกส่งต่อเพื่อความปลอดภัยของลูกค้า
    การแจ้งเตือนจาก Health-ISAC ซึ่งเป็นชุมชนสำหรับผู้เชี่ยวชาญด้านการดูแลสุขภาพเพื่อแบ่งปันข้อมูลด้านภัยคุกคาม ได้แจ้งเตือนในวันนี้ว่าบริการของ TeamViewer ถูกโจมตีจากกลุ่มแฮ็กเกอร์ชาวรัสเซีย APT29 ซึ่งรู้จักกันในชื่อ Cozy Bear, NOBELIUM และ Midnight Blizzard
    แม้ว่าการแจ้งเตือนจากทั้งสองบริษัทจะเป็นเวลาเดียวกับที่ TeamViewer เปิดเผยเหตุการณ์ แต่ยังไม่ชัดเจนว่ามีความเกี่ยวข้องกันหรือไม่ เนื่องจากการแจ้งเตือนของ TeamViewer และ NCC กล่าวถึงการโจมตีระบบขององค์กร ในขณะที่การแจ้งเตือนของ Health-ISAC เน้นไปที่การโจมตีการเชื่อมต่อของ TeamViewer มากกว่า

อัปเดต: ปัจจุบัน TeamViewer ระบุว่าการโจมตีดังกล่าวมาจากกลุ่มแฮ็กเกอร์ที่ได้รับการสนับสนุนจากรัฐบาลรัสเซียที่รู้จักกันในชื่อ Midnight Blizzard