Óý±ÌÔâµ½LAPSUS$µÄ¹¥»÷ £¬ÆäÓÎÏ·¡¢ÏµÍ³ºÍ·þÎñÖжÏ

Ðû²¼Ê±¼ä 2022-03-15

Óý±ÌÔâµ½LAPSUS$µÄ¹¥»÷ £¬ÆäÓÎÏ·¡¢ÏµÍ³ºÍ·þÎñÖжÏ


¾ÝýÌå3ÔÂ12ÈÕ±¨µÀ £¬ÊÓÆµÓÎÏ·¿ª·¢ÉÌÓý±Ì£¨Ubisoft £©Ö¤Êµ £¬ËüÔÚÉÏÖÜÔâµ½ÍøÂç¹¥»÷ £¬µ¼ÖÂÆäÓÎÏ·¡¢ÏµÍ³ºÍ·þÎñÖжÏ¡£¸Ã¹«Ë¾ÌåÏÖËûÃǵÄÍŶÓÕýÔÚÊÓ²ì´ËÎÊÌâ £¬ÏÖÒÑÈ·ÈÏûÓÐÊý¾Ýй¶¼£Ïó £¬¶øÇÒÖØÖÃÁËÈ«¹«Ë¾µÄÃÜÂë¡£3ÔÂ4ÈÕ £¬¾ÍÓÐÓû§ÔÚTwitterºÍDowndetectorÉÏÌåÏÖËûÃÇÔÚ·ÃÎÊÓý±ÌµÄijЩ·þÎñʱ·ºÆðÎÊÌ⡣ĿǰÉÐÎÞ¹ØÓڴ˴ι¥»÷µÄÏêϸÐÅÏ¢ £¬µ«Lapsus$Ðû²¼ÁËÏûÏ¢ÌåÏÖ´ËÊÂÓëËüÓйØ¡£


https://securityaffairs.co/wordpress/128929/hacking/ubisoft-cyber-security-incident.html


LockBitÉù³Æ¶ÔÆÕÀû˾ͨÃÀÖÞ¹«Ë¾µÄ¹¥»÷ʼþÂôÁ¦


LockBitÔÚ3ÔÂ11ÈÕÐû²¼ÏûÏ¢ £¬Éù³Æ¶ÔÆÕÀû˾ͨÃÀÖÞ¹«Ë¾£¨Bridgestone Americas£©µÄ¹¥»÷ʼþÂôÁ¦¡£ÕâÊÇÈ«Çò×î´óµÄÂÖÌ¥ÖÆÔìÉÌÖ®Ò» £¬ÔÚÈ«ÇòÓµÓÐÊýÊ®¸öÉú²úµ¥ÔªºÍÁè¼Ý130000¸öÔ±¹¤¡£ÆÕÀû˾ͨÐû²¼µÄÉùÃ÷³Æ £¬ËûÃÇÔÚ2ÔÂ27ÈÕ¼ì²âµ½Ò»ÆðITÄþ¾²Ê¼þ £¬ÕýÔÚ¶ÔʼþµÄ·¶Î§ºÍÐÔÖÊÕ¹¿ªÊӲ졣LockBitÊǵ±½ñ×î»îÔ¾µÄÀÕË÷ÍÅ»ïÖ®Ò» £¬Ä¿Ç°Éв»Çå³þËü´ÓÆÕÀû˾ͨÇÔÈ¡ÁËÄÄЩÊý¾Ý¡£


https://www.bleepingcomputer.com/news/security/bridgestone-americas-confirms-ransomware-attack-lockbit-leaks-data/


Ñо¿ÈËÔ±·¢ÏÖ¶à¸öÖ÷Á÷±£Ö¤ÀíÆ÷ÖдæÔÚÄþ¾²Â©¶´


¾Ý3ÔÂ11ÈÕ±¨µÀ £¬SonarSourceµÄÑо¿ÈËÔ±·¢ÏÖ¶à¸öÖ÷Á÷±£Ö¤ÀíÆ÷ÖдæÔÚÄþ¾²Â©¶´¡£±£Ö¤ÀíÆ÷ÊÇÖ¸ÓÃÓÚ×Ô¶¯°²×°¡¢Éý¼¶¡¢ÅäÖÿª·¢Ó¦Ó÷¨Ê½ËùÐèµÄµÚÈý·½ÒÀÀµÏîµÄϵͳ»ò¹¤¾ß £¬´æÔÚ©¶´µÄÓ¦ÓðüÂÞComposer¡¢Bundler¡¢Bower¡¢Poetry¡¢Yarn¡¢pnpm¡¢PipºÍPipenv¡£Ñо¿ÈËÔ±ÌåÏÖ £¬¹¥»÷Õß¿ÉÒÔÀûÓÃÕâЩ©¶´À´Ö´ÐÐÈÎÒâ´úÂë²¢´ÓÄ¿±êÉ豸ÖÐÇÔÈ¡Ãô¸ÐÐÅÏ¢ £¬°üÂÞÔ´´úÂëºÍ·ÃÎÊÁîÅÆµÈ¡£


https://thehackernews.com/2022/03/multiple-security-flaws-discovered-in.html


¶íÂÞ˹¹ú·À¹«Ë¾RostecÒòÔâµ½DDoS¹¥»÷ÍøÕ¾¹Ø±Õ


3ÔÂ11ÈÕ £¬¶íÂÞ˹¹úÓк½¿Õº½ÌìºÍ¹ú·À¼¯ÍÅRostecÌåÏÖ £¬ÆäÍøÕ¾ÒòÔâµ½ÍøÂç¹¥»÷¶ø±»¹Ø±Õ¡£¸Ã¹«Ë¾ÌåÏÖ £¬×Ô2ÔÂÏÂÑ®ÒÔÀ´ÆäÍøÕ¾Ò»Ö±ÔâÊÜ×ÅΧ¹¥¡£×îеÄÒ»´Î¹¥»÷ʼÓÚµ±ÈÕÉÏÎç11µã30·Ö £¬À´×ÔÎÚ¿ËÀ¼Ð½¨Á¢µÄIT¾ü¶Ó¡£¸ÃÎÚ¿ËÀ¼×éÖ¯ÔçЩʱºòÔÚTelegramÖÐÐû²¼ÏûÏ¢ £¬½«RostecµÄ¶à¸öÓòÈ·ÈÏΪÆäÂþÑÜʽ¾Ü¾ø·þÎñ(DDoS)¹¥»÷µÄÄ¿±ê¡£Rostec³ÆÍøÕ¾ºÜ¿ì¾Í»Ö¸´ÁËÕý³£ÔËÐÐ £¬Ä¿Ç°ËùÓÐÐÅÏ¢¾ùÒÑ¿ÉÓá£


https://www.bleepingcomputer.com/news/security/russian-defense-firm-rostec-shuts-down-website-after-ddos-attack/


Anonymousй¶¶íÂÞ˹»ú¹¹RoskomnadzorµÄ820GBÊý¾Ý


¾ÝýÌå3ÔÂ11ÈÕ±¨µÀ £¬AnonymousÉù³ÆÈëÇÖÁ˶íÂÞ˹Ö÷ÒªµÄ¹Ù·½»ú¹¹Roskomnadzor£¨ÓÖÃûÁª°îͨÐÅ¡¢ÐÅÏ¢¼¼ÊõºÍ¹«¹²Ã½Ìå¼à¶½¾Ö£©¡£¸ÃÍÅ»ï×ܹ²Ð¹Â¶ÁËÔ¼820GBµÄÊý¾Ý £¬ÆäÖаüÂÞÁè¼Ý360000¸öÎļþ£¨536.9 GB£©ºÍ2¸ö°üÂÞHR·¨Ê½µÄÊý¾Ý¿â£¨290.6 GB£©¡£´ËÍâ £¬AnonymousÔÚ½üÆÚ»¹ÈëÇÖÁ˶íÂÞ˹Լ90%µÄÅäÖôíÎóµÄÔÆÊý¾Ý¿â¡£


https://www.hackread.com/anonymous-hacks-roskomnadzor-russia-agency/


¶«Ó³¶¯»­¹«Ë¾»òÒòÔâµ½ÀÕË÷¹¥»÷º£ÔôÍõµÈ¶¯ÂþÑÓ²¥


3ÔÂ11ÈÕ £¬ÈÕ±¾¶«Ó³¶¯»­¹«Ë¾£¨Toei£©Ðû²¼×îÐÂÏûÏ¢ £¬³ÆÓÉÓÚÍøÂç¹¥»÷µ¼ÖÂÄÚ²¿ÏµÍ³¹Ø±Õ £¬¶¯ÂþµÄÖÆ×÷Òѱ»ÍƳÙ¡£Òò´Ë £¬¡¶ÓÂÕß¶·¶ñÁú´óÍõ½£¡·¡¢¡¶Delicious Party Precure¡·¡¢¡¶ÊýÂ뱦ÎïÓÄÁéÓÎÏ·¡·ºÍ¡¶º£ÔôÍõ¡·Ð¾缯µÄ²¥³ö½«ÑÓ³Ù £¬Ö±ÖÁÁíÐÐ֪ͨ¡£ÕâÁÔôÍõµÄ·ÛË¿ÃǷdz£Ê§Íû £¬ËûÃÇÕýÆÚ´ý¸ÃϵÁеÚ1000ÕµÄÐû²¼¡£Æ¾¾ÝToeiµÄͨ¸æ £¬ÆäÔÚ3ÔÂ6ÈÕ¼ì²âµ½Î´¾­ÊÚȨµÄ·ÃÎÊ £¬²¢ÔÚÔ½ÈչرÕÁËËùÓеÄÄÚ²¿ÏµÍ³ £¬¶Ô´ËÊÂÕ¹¿ªÊӲ졣ÖÖÖÖ¼£Ïó±íÃ÷ÕâÊÇÒ»ÆðÀÕË÷¹¥»÷ʼþ £¬µ«Ä¿Ç°Ñо¿ÈËÔ±»¹ÎÞ·¨Ö¤ÊµÕâÒ»µã¡£


https://www.bleepingcomputer.com/news/security/new-one-piece-anime-episodes-delayed-after-toei-cyberattack/




Äþ¾²¹¤¾ß


ASSAMEE 


Anonfiles µÄÃâ·Ñ¸ß¼¶¼ÓÃÜÆ÷ £¬Ê¹Óø߼¶¼ÓÃÜÒªÁìʹÓà AES-256 ¼ÓÃÜĿ¼¡£


https://github.com/samhaxr/ASSAMEE


Scanmycode Ce


ËüÊÇÒ»ÖÖ´úÂëɨÃè/SAST/¾²Ì¬·ÖÎö/Linting ½â¾ö·½°¸ £¬Ê¹ÓÃÐí¶à¹¤¾ß/ɨÃèÒǺÍÒ»¸ö³ÂËß¡£


https://github.com/marcinguy/scanmycode-ce


Oh365UserFinder


ÓÃÓÚʶ±ðÓÐЧµÄ o365 ÕÊ»§ºÍÓò £¬¶ø²»´æÔÚÕÊ»§Ëø¶¨µÄ·çÏÕ¡£


https://github.com/dievus/Oh365UserFinder


ADExplorerSnapshot.py


ÊÇAD Explorer ¿ìÕÕ½âÎöÆ÷ £¬×÷Ϊ BloodHound µÄ ingestor £¬»¹Ö§³Ö½«ÍêÕû¹¤¾ßת´¢µ½ NDJSON¡£


https://github.com/c3c/ADExplorerSnapshot.py



Äþ¾²·ÖÎö


AnonymousÈëÇÖÁ˶íÂÞ˹µÄ 400 ¸öÄþ¾²ÉãÏñÍ·


https://www.hackread.com/anonymous-sent-texts-to-russians-hacked-security-cams/


Riverbed Èí¼þÖдæÔÚµÄ4¸öÑÏÖØµÄ©¶´


https://www.theregister.com/2022/03/11/riverbed_vulnerabilities/


ͨ¹ýËÙÂÊÏÞÖÆ RDP ±©Á¦¹¥»÷


https://blog.malwarebytes.com/explained/2022/03/blunting-rdp-brute-force-attacks-with-rate-limiting/


Kali Linux ΪÂã»ú°²×°Ìí¼ÓÁËÀàËÆ VM µÄ¿ìÕÕ¹¦Ð§


https://www.bleepingcomputer.com/news/linux/kali-linux-adds-vm-like-snapshot-feature-to-bare-metal-installs/


Å·Ä·Áú PLC ±à³ÌÈí¼þÖÐÐÞ²¹µÄ¸ßΣ©¶´


https://www.securityweek.com/high-severity-vulnerabilities-patched-omron-plc-programming-software