2024ǯ2·î¡¢¥ª¥é¥ó¥À·³¾ðÊóÊݰ¶É(MIVD)¤ÈÁí¹ç¾ðÊóÊݰ¶É(AIVD)¤¬¡¢Ãæ¹ñÀ¯Éܤλٱç¤ò¼õ¤±¤¿¥Ï¥Ã¥«¡¼¤¬¥ª¥é¥ó¥À¹ñËɾʤʤɤǻÈÍѤµ¤ì¤ë¼¡À¤Âå¥Õ¥¡¥¤¥¢¥¦¥©¡¼¥ë¡ÖFortiGate¡×¤Î¥Í¥Ã¥È¥ï¡¼¥¯¤Ë¿¯Æþ¤·¤¿¤ÈÊó¹ð¤·¤Þ¤·¤¿¡£¤½¤Î¸å¤ÎÄ´ºº¤Î·ë²Ì¡¢MIVD¤ÏÌó2ËüÂæ¤â¤Î¥Ç¥Ð¥¤¥¹¤¬Ãæ¹ñ¤Î¥Ï¥Ã¥«¡¼¤Ë¤è¤ëÈï³²¤ò¼õ¤±¤¿¤³¤È¤òÌÀ¤é¤«¤Ë¤·¤Þ¤·¤¿¡£

Aanhoudende statelijke cyberspionagecampagne via kwetsbare edge devices | Nieuwsbericht | Nationaal Cyber Security Centrum

https://www.ncsc.nl/actueel/nieuws/2024/juni/10/aanhoudende-statelijke-cyberspionagecampagne-via-kwetsbare-edge-devices



20,000 Fortinet devices breached - reboots no defence

https://www.thestack.technology/20-000-fortinet-devices-breached-by-chinese-hackers-reboots-firmware-updates-no-defence/

Chinese hackers breached 20,000 FortiGate systems worldwide

https://www.bleepingcomputer.com/news/security/chinese-hackers-breached-20-000-fortigate-systems-worldwide/

MIVD¤Ë¤è¤ë¤È¡¢Ãæ¹ñ¤Î¥Ï¥Ã¥«¡¼¤Ï2022ǯ¤«¤é2023ǯ¤Ë¤«¤±¤Æ¤Î¿ô¥«·î´Ö¡¢FortiGate¤òÆ°ºî¤µ¤»¤ë¤¿¤á¤ÎOS¤Ç¤¢¤ëFortiOS¤äFortiProxy¤Ë¸ºß¤·¤¿ÀȼåÀ­¡ÖCVE-2022-42475¡×¤ò°­ÍѤ·¤Æ¡¢FortiGate¤Î¥Í¥Ã¥È¥ï¡¼¥¯¥»¥­¥å¥ê¥Æ¥£¥¢¥×¥é¥¤¥¢¥ó¥¹¤ËCOATHANGER¤È¸Æ¤Ð¤ì¤ë¥Þ¥ë¥¦¥§¥¢¤òŸ³«¤·¤¿¤È¤Î¤³¤È¡£

¿ô½½¤ÎÀ¾Â¦À¯Éܤä¹ñºÝµ¡´Ø¡¢Â¿¿ô¤ÎËɱһº¶È¤Ë´Ø¤¹¤ë´ë¶È¤Ê¤É¤ÎɸŪ¤Î¥Í¥Ã¥È¥ï¡¼¥¯¤Ë¿¯Æþ¤·¤¿COATHANGER¤Ï¡¢¼«Æ°Åª¤Ë¥Ð¥Ã¥¯¥É¥¢¤Î¥¤¥ó¥¹¥È¡¼¥ë¤ò¼Â¹Ô¤·¤Þ¤¹¡£

Ãæ¹ñ¤Î¥µ¥¤¥Ð¡¼¥¹¥Ñ¥¤¤¬¥ª¥é¥ó¥À¤Î·³»ö¥Í¥Ã¥È¥ï¡¼¥¯¤Ë¥¢¥¯¥»¥¹¤·¤¿¤ÈĵÊ󵡴ؤ¬¸øɽ - GIGAZINE



2024ǯ2·î¤ÎÊó¹ð°Ê¹ß¤âMIVD¤ÈAIVD¤ÏÄ´ºº¤ò³¤±¡¢¡ÖÃæ¹ñ¤Î¥µ¥¤¥Ð¡¼¥¹¥Ñ¥¤³èÆ°¤Ï¤³¤ì¤Þ¤ÇÃΤé¤ì¤Æ¤¤¤¿¤è¤ê¤â¤Ï¤ë¤«¤Ë¹­ÈϰϤ˵ڤó¤Ç¤¤¤ë¤³¤È¤¬ÌÀ¤é¤«¤Ë¤Ê¤ê¤Þ¤·¤¿¡×¤ÈÊó¹ð¡£¶ñÂÎŪ¤Ë¤Ï¡¢CVE-2022-42475¤Î°­ÍѤ«¤é2023ǯ1·î¤ÎFortinet¤Ë¤è¤ë¸øɽ¤Þ¤Ç¤Ë¡¢COATHANGER¤ÏÌó1Ëü4000Âæ¤â¤Î¥Ç¥Ð¥¤¥¹¤Ë´¶À÷¡£¸øɽ¸å¤â¹¶·â¼Ô¤Ï¥Ñ¥Ã¥Á¤òŬÍѤ·¤Æ¤¤¤Ê¤¤¥Ç¥Ð¥¤¥¹¤Ë¹¶·â¤ò³¤±¡¢2022ǯ¤«¤é2023ǯ¤Ë¤«¤±¤Æ¤Î¿ô¥«·î´Ö¤Ç¾¯¤Ê¤¯¤È¤â2ËüÂæ¤â¤ÎFortiGate¥·¥¹¥Æ¥à¤Ë¥¢¥¯¥»¥¹¤·¤¿¤³¤È¤¬¸ì¤é¤ì¤Æ¤¤¤Þ¤¹¡£

MIVD¤Ë¤è¤ë¤È¡¢COATHANGER¤Ï¥¹¥­¥ã¥ó¤«¤é¥Þ¥ë¥¦¥§¥¢¤Î¸ºß¤òÈëÆ¿¤¹¤ë¥¹¥Æ¥ë¥¹À­¤È¡¢ºÆµ¯Æ°¤ä¥Õ¥¡¡¼¥à¥¦¥§¥¢¤Î¥¢¥Ã¥×¥Ç¡¼¥È¤ËÂѤ¨¤¦¤ë·Ñ³À­¤òÈ÷¤¨¤Æ¤¤¤ë¤È¤Î¤³¤È¡£¤½¤Î¤¿¤á¡¢°ìÅÙCOATHANGER¤Î¿¯Æþ¤òµö¤¹¤Èºï½ü¤¬º¤Æñ¤Ç¤¹¡£MIVD¤Ï¡ÖCOATHANGER¤¬¿¯Æþ¤¹¤ë¤È¡¢Ãæ¹ñÀ¯ÉܤÏFortiGate¥·¥¹¥Æ¥à¤Ø¤Î¹±µ×Ū¤Ê¥¢¥¯¥»¥¹¤¬²Äǽ¤Ë¤Ê¤ê¤Þ¤¹¡£¤¿¤È¤¨Èï³²¼Ô¤¬FortiGate¤«¤é¥»¥­¥å¥ê¥Æ¥£¥¢¥Ã¥×¥Ç¡¼¥È¤ò¥¤¥ó¥¹¥È¡¼¥ë¤·¤¿¤È¤·¤Æ¤â¡¢Ãæ¹ñÀ¯ÉܤÏÈï³²¼Ô¤Î¥Ç¥Ð¥¤¥¹¤Ø¤Î¥¢¥¯¥»¥¹¤ò°Ý»ý¤¹¤ë¤³¤È¤¬²Äǽ¤Ç¤¹¡×¤È»ØŦ¡£

¤Þ¤¿¡¢¡Ö¼ÂºÝ¤ËCOATHANGER¤ò¥¤¥ó¥¹¥È¡¼¥ë¤·¤Æ¤¤¤ëÈï³²¼Ô¤Î¿ô¤ÏÉÔÌÀ¤Ç¤¹¡£¥ª¥é¥ó¥À¤ÎĵÊ󵡴ؤȥµ¥¤¥Ð¡¼¥»¥­¥å¥ê¥Æ¥£µ¡´Ø¤Ç¤¢¤ëNCSC¤Ï¡¢Ãæ¹ñÀ¯Éܤλٱç¤ò¼õ¤±¤¿¥Ï¥Ã¥«¡¼¤¬¹¶·âÈϰϤò¤µ¤é¤Ë³ÈÂ礷¡¢¥Ç¡¼¥¿¤ÎÀà¼è¤Ê¤É¤ÎÄɲùÔÆ°¤ò¼Â¹Ô¤¹¤ë²ÄǽÀ­¤¬¤¢¤ë¤È¹Í¤¨¤Æ¤¤¤Þ¤¹¡×¤È½Ò¤Ù¤Þ¤·¤¿¡£



³¤³°¥á¥Ç¥£¥¢¤ÎThe Stack¤Ï¡Ö´¶À÷¤·¤¿FortiGate¥Ç¥Ð¥¤¥¹¤«¤éCOATHANGER¤òºï½ü¤¹¤ëÍ£°ì¤ÎÊýË¡¤Ï¡¢¥Ç¥Ð¥¤¥¹¤ò¥Õ¥©¡¼¥Þ¥Ã¥È¤·¡¢ºÆ¥¤¥ó¥¹¥È¡¼¥ë¤·¤ÆºÆ¹½À®¤¹¤ë¤³¤È¤Ç¤¹¡×¤È½Ò¤Ù¤Æ¤¤¤Þ¤¹¡£¤µ¤é¤Ë¥ª¥é¥ó¥À¹ñËɾʤϡÖCOATHANGER¤ò¸¡½Ð¤¹¤ë¤¿¤á¤ÎYARA¥ë¡¼¥ë¡¢JA3¥Õ¥£¥ó¥¬¡¼¥×¥ê¥ó¥È¤Ê¤É¤ÎÊýË¡¤òÆÃÄꤷ¤Æ¤¤¤Þ¤¹¡×¤ÈÊó¹ð¤·¤Þ¤·¤¿¡£