{"id":1342,"date":"2024-06-13T21:54:43","date_gmt":"2024-06-13T19:54:43","guid":{"rendered":"https:\/\/techlance.ddns.net\/?p=1342"},"modified":"2024-06-13T21:55:29","modified_gmt":"2024-06-13T19:55:29","slug":"black-basta-kiristysohjelmaoperaatio","status":"publish","type":"post","link":"https:\/\/techlance.ddns.net\/en\/black-basta-kiristysohjelmaoperaatio\/","title":{"rendered":"Black Basta -kiristysohjelmaoperaatio"},"content":{"rendered":"<p>Black Basta -kiristysohjelmaoperaation ep\u00e4ill\u00e4\u00e4n hy\u00f6dynt\u00e4neen Windowsin k\u00e4ytt\u00f6oikeuksien laajentamisheikkoutta (CVE-2024-26169) nollap\u00e4iv\u00e4haavoittuvuutena ennen korjauksen saatavuutta.<\/p>\n\n\n\n<p>Kyseinen heikkous on korkean vakavuusasteen ongelma (CVSS v3.1: 7.8) Windowsin virheraportointipalvelussa, jonka avulla hy\u00f6kk\u00e4\u00e4j\u00e4t voivat laajentaa k\u00e4ytt\u00f6oikeuksiaan SYSTEM-tasolle.<\/p>\n\n\n\n<p>Microsoft korjasi t\u00e4m\u00e4n heikkouden 12. maaliskuuta 2024 kuukausittaisten Patch Tuesday -p\u00e4ivitystens\u00e4 yhteydess\u00e4, ja toimittajan sivulla ei ole merkint\u00f6j\u00e4 aktiivisesta hy\u00f6dynt\u00e4misest\u00e4.<\/p>\n\n\n\n<p>Symantecin raportin mukaan CVE-2024-26169:\u00e4\u00e4 on kuitenkin aktiivisesti hy\u00f6dynt\u00e4nyt Cardinal-kyberrikollisryhm\u00e4 (Storm-1811, UNC4394), joka operoi Black Basta -jengin nimiss\u00e4, ja on hyvin todenn\u00e4k\u00f6ist\u00e4, ett\u00e4 haavoittuvuutta k\u00e4ytettiin nollap\u00e4iv\u00e4n\u00e4.<\/p>\n\n\n\n<p>Lis\u00e4tietoja l\u00f6yd\u00e4t <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/black-basta-ransomware-gang-linked-to-windows-zero-day-attacks\/\">BleepingComputerin artikkelista<\/a>.<\/p>","protected":false},"excerpt":{"rendered":"<p>Black Basta -kiristysohjelmaoperaation ep\u00e4ill\u00e4\u00e4n hy\u00f6dynt\u00e4neen Windowsin k\u00e4ytt\u00f6oikeuksien laajentamisheikkoutta (CVE-2024-26169) nollap\u00e4iv\u00e4haavoittuvuutena ennen korjauksen saatavuutta. Kyseinen heikkous on korkean vakavuusasteen ongelma (CVSS [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[21,9],"tags":[22,15],"class_list":["post-1342","post","type-post","status-publish","format-standard","hentry","category-data-protection","category-security","tag-data-protection","tag-tietoturva"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/posts\/1342","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/comments?post=1342"}],"version-history":[{"count":0,"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/posts\/1342\/revisions"}],"wp:attachment":[{"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/media?parent=1342"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/categories?post=1342"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/tags?post=1342"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}