IconBurstÕë¶ÔNPMµÄ¹©Ó¦Á´¹¥»÷Ó°ÏìÊý°Ù¸öÍøÕ¾ºÍÓ¦ÓÃ

Ðû²¼Ê±¼ä 2022-07-06

1¡¢IconBurstÕë¶ÔNPMµÄ¹©Ó¦Á´¹¥»÷Ó°ÏìÊý°Ù¸öÍøÕ¾ºÍÓ¦ÓÃ


7ÔÂ5ÈÕ£¬ReversingLabsÅû¶ÁËIconBurstÕë¶ÔNPMµÄ¹©Ó¦Á´¹¥»÷»î¶¯µÄϸ½ÚÐÅÏ¢ ¡£¸Ã»î¶¯¿É×·Ëݵ½2021Äê12Ô£¬¹¥»÷ÕßʹÓÃÁËÊýÊ®¸ö°üÂÞ»ìÏýJavascript´úÂëµÄ¶ñÒâNPMÀ´Ñ¬È¾Êý°Ù¸ö×ÀÃæÓ¦Ó÷¨Ê½ºÍÍøÕ¾ ¡£Óë֮ǰÀàËƵĹ¥»÷Ò»Ñù£¬¸Ã»î¶¯Ò²Ö÷ÒªÒÀÀµÓÚƴд´íÎó£¬Ã°³äÁ÷ÐеÄNPMÄ £¿é£¬ÈçumbrellajsºÍionic.io NPMÄ £¿é ¡£Ñо¿ÈËÔ±»¹·¢ÏÖÁËЭͬ¹©Ó¦Á´¹¥»÷µÄÖ¤¾Ý£¬´óÁ¿µÄNPM°ü°üÂÞjQuery½Å±¾£¬Ö¼ÔÚ´Ó°üÂÞËüÃǵÄÓ¦Ó÷¨Ê½ÖÐÇÔÈ¡±íµ¥Êý¾Ý ¡£


https://blog.reversinglabs.com/blog/iconburst-npm-software-supply-chain-attack-grabs-data-from-apps-websites


2¡¢ÀÕË÷ÍÅ»ïAstraLocker¼Æ»®Í£Ö¹ÔËÓª²¢Ðû²¼Æä½âÃÜÆ÷


¾ÝýÌå7ÔÂ4ÈÕ±¨µÀ£¬ÀÕË÷ÍÅ»ïAstraLocker¼Æ»®Í£Ö¹ÔËÓª£¬²¢ÔÚVirusTotalÌá½»ÁËÒ»¸öº¬ÓÐAstraLocker½âÃÜÆ÷µÄZIPÎļþ ¡£´ËÍ⣬¸ÃÍŻﻹ͸¶ËûÃǼƻ®×ªÏò¼ÓÃܽٳֹ¥»÷»î¶¯ ¡£Ñо¿ÈËÔ±ÏÂÔز¢È·ÈϸÃZIPÎļþÊǺϷ¨µÄ£¬¾­¹ý²âÊÔºó֤ʵ½âÃÜÆ÷Ò²¿ÉÒÔÕý³£ÊÂÇé ¡£ËäÈ»¹¥»÷ÕßûÓÐÃ÷È·Í£Ö¹ÔËÓªµÄÔ­Òò£¬µ«ºÜ¿ÉÄÜÊÇÓÉÓÚ½üÆÚ¹ØÓÚËüµÄ±¨µÀÒýÆðÁ˹«ÖڵĹØ×¢£¬Ê¹Æä³ÉΪִ·¨»ú¹¹µÄÄ¿±ê ¡£ 


https://www.bleepingcomputer.com/news/security/astralocker-ransomware-shuts-down-and-releases-decryptors/


3¡¢ÈÕ±¾Kokikai YasueҽԺй¶ʮÍò¶à»¼ÕߺÍÔ±¹¤µÄÐÅÏ¢


ýÌå7ÔÂ4Èճƣ¬ÈÕ±¾Kokikai YasueҽԺй¶ÁË111191Ãû»¼ÕߺÍ715ÃûÔ±¹¤µÄÐÅÏ¢ ¡£¸ÃÒ½ÔºÓÚ5ÔÂ27ÈÕ·¢ÏÖ¶ÔÆä¼ÆËã»úϵͳδ¾­ÊÚȨµÄ·ÃÎÊ£¬ÆäʱÎÞ·¨·ÃÎÊ»¼ÕßÐÅÏ¢Êý¾Ý¿â£¬ÇÒµç×Ó²¡ÀúϵͳµÈ²¿ÃÅϵͳֹͣÔËÐÐ ¡£µ±Ìì½ÓÄÉÁËÏÞÖƲ¿ÃÅÒµÎñµÄÕïÁÆÌåÖÆ£¬²¢ÔÚ28ÈÕ»Ö¸´Õý³£ÔËÓª ¡£´Ë´Îʼþ鶻¼ÕßµÄÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢Ò½ÁÆÐÅÏ¢ºÍÒßÃç½ÓÖÖÊ·µÈÐÅÏ¢£»ÒÔ¼°Ô±¹¤µÄÐÕÃû¡¢µØÖ·ºÍµç»°µÈ ¡£


https://www.databreaches.net/jp-information-of-111191-patients-and-715-employees-at-kokikai-yasue-hospital-leaked/


4¡¢ÎÚ¿ËÀ¼¾¯·½´þ²¶ÍµÈ¡Áè¼Ý300ÍòÃÀÔªµÄµöÓãÍÅ»ïµÄ³ÉÔ±


¾Ý7ÔÂ4ÈÕ±¨µÀ£¬ÎÚ¿ËÀ¼¾¯·½Àֳɴþ²¶ÁËÒ»¸öµöÓãÍÅ»ïµÄ9Ãû³ÉÔ± ¡£Ö´·¨ÈËÔ±ÌåÏÖ£¬ËûÃÇ´´½¨ÁË400¶à¸öµöÓãÍøÕ¾£¬ÒÔÊÕ¼¯Ä¿±êµÄÒøÐп¨Êý¾Ý²¢´ÓËûÃǵÄÕË»§ÖÐ͵ȡ×ʽ𠡣Ŀǰ£¬ÏÓÒÉÈËÒÑ»ñµÃÁËÔ¼1ÒÚ¸ñÀï·òÄÉ£¨337ÍòÃÀÔª£©£¬¿ÉÄÜ»áÃæÁÙ³¤´ï15ÄêµÄÀÎÓüÖ®ÔÖ ¡£´Ë´ÎÖ´·¨Ðж¯Ã»ÊÕÁËËûÃǵļÆËã»ú¡¢ÊÖ»ú¡¢ÒøÐп¨ÒÔ¼°·Ç·¨»ñµÃµÄÊÕÒæ ¡£Éв»Çå³þÆäµöÓãÁ´½ÓµÄ·Ö·¢Í¾¾¶£¬¿ÉÄÜÊǶÌÐŵöÓ㣨smishing£©¡¢À¬»øÓʼþ¡¢É罻ýÌåÓ¦ÓÃÏûÏ¢ºÍSEOÖж¾µÈ ¡£


https://thehackernews.com/2022/07/ukrainian-authorities-arrested-phishing.html


5¡¢CiscoÐû²¼ÔÚ°µÍøÉ϶ÔÀÕË÷Èí¼þÓòÈ¥ÄäÃû»¯µÄ¼¼Êõ³ÂËß


ýÌå7ÔÂ5ÈÕ±¨µÀ£¬CiscoÏêϸ½éÉÜÁËÈçºÎÔÚ°µÍøÉ϶ÔÀÕË÷Èí¼þµÄÓò½øÐÐÈ¥ÄäÃû»¯ ¡£´ó¶àÊýÀÕË÷ÍÅ»ïʹÓÃʹÓÃÆäÔ­¼®¹úÒÔÍâµÄÍйܹ©Ó¦ÉÌ£¨ÈçÈðµä¡¢µÂ¹úºÍмÓÆ£©À´ÍйÜËûÃǵÄÍøÕ¾£¬µ±ËûÃÇÁ¬½ÓÆä»ù´¡ÉèÊ©À´Ö´ÐÐÔ¶³Ì¹ÜÀíÈÎÎñʱ£¬»áʹÓÃVPSÌøµã×÷ΪÊðÀíÀ´Òþ²ØËûÃǵÄÕæʵλÖà ¡£Ñо¿ÈËԱʹÓõÄÈ¥ÄäÃû·½Ê½°üÂÞ£ºTLSÖ¤ÊéÆ¥Å䣬ͨ¹ý½«¹¥»÷ÕßµÄ×ÔÇ©ÃûTLSÖ¤ÊéÐòÁкźÍÒ³ÃæÔªËØÓëÍøÂçÉϵÄË÷ÒýµÄ½øÐÐÆ¥Å䣻Íøվͼ±êÆ¥Å䣬²éÕÒ°µÍøÉÏÌض¨µÄÍøվͼ±êÊÇ·ñÒ²·ºÆðÔÚ¹«ÍøÉÏ£»ÒÔ¼°OPSEC¹ÊÕÏ£¬¹¥»÷ÍÅ»ïÓÐʱ»á·¸ÔÖÄÑÐÔµÄÄþ¾²´íÎ󣬵¼ÖÂÄäÃûʧЧ ¡£   


https://thehackernews.com/2022/07/researchers-share-techniques-to-uncover.html


6¡¢ÆÏÌÑÑÀ2022ÄêQ2Íþв³ÂËß³ÆÒøÐгÉΪÖ÷Òª¹¥»÷Ä¿±ê


7ÔÂ4ÈÕ£¬Segran?a-Inform¨¢ticaÐû²¼ÁËÆÏÌÑÑÀ2022ÄêµÚ¶þ¼¾¶ÈµÄÍþв·ÖÎö³ÂËß ¡£³ÂËßÏÔʾ£¬ÔÚµÚ¶þ¼¾¶È£¬ÍøÂçµöÓã»î¶¯(68.9%)±È¶ñÒâÈí¼þ(31.1%)¸ü³£¼û ¡£QakbotľÂí¡¢Satori/Mirai½©Ê¬ÍøÂçºÍMS OfficeÎĵµ£¨ºê£©ÊÇÆÏÌÑÑÀÔÚµÚ¶þ¼¾¶ÈÃæÁÙµÄ×î³£¼ûµÄÍþв ¡£´ËÍ⣬ÓдóÁ¿µÄµöÓã»î¶¯Óë°ü¹üµÝËÍ·þÎñÓйØ£¬°üÂÞCTT¡¢DHL¡¢UPSºÍFedExµÈ ¡£¹ØÓÚÊÜÓ°ÏìµÄÐÐÒµ£¬ÒøÐгÉΪÖ÷Òª¹¥»÷Ä¿±ê£¬Æä´ÎÊÇÁãÊÛºÍÒ½Áƽ¡¿µÐÐÒµ ¡£  


https://seguranca-informatica.pt/threat-report-portugal-q2-2022/#.YsT3wnZBxPY