·¨º½ºÍºÉº½Í¨ÖªFlying Blue¿Í»§Æä¸öÈËÐÅÏ¢ÒÑй¶
Ðû²¼Ê±¼ä 2023-01-09
¾ÝýÌå1ÔÂ6ÈÕ±¨µÀ£¬·¨º½ºÍºÉº½ÒÑ֪ͨFlying Blue¿Í»§£¬Æä¸öÈËÐÅÏ¢ÒѾй¶¡£ºÉº½¹Ù·½ÍÆÌØÕ˺Å֤ʵÁËÕâ´Î¹¥»÷£¬³Æ¹¥»÷±»¼°Ê±×èÖ¹£¬Óû§Àï³ÌûÓÐÊÜÓ°Ï죬µ«Êǽ¨Òé¿Í»§Í¨¹ýFlying BlueÍøÕ¾¸ü¸ÄÃÜÂë¡£¾ÝϤ£¬¿ÉÄÜ鶵ÄÊý¾Ý°üÂÞÐÕÃû¡¢ÓʼþµØÖ·¡¢µç»°¡¢½»Ò׼ǼºÍ·ÉÐÐÐÅÏ¢µÈ£¬¿Í»§µÄÐÅÓÿ¨»ò¸¶¿îÐÅÏ¢²¢Î´Ð¹Â¶¡£Ä¿Ç°£¬ºÉº½ºÍ·¨º½Ã»Óлظ´Ñо¿ÈËÔ±µÄÖÃÆÀÇëÇó¡£
https://www.bleepingcomputer.com/news/security/air-france-and-klm-notify-customers-of-account-hacks/
2¡¢ÀÕË÷ÍÅ»ïHive¹ûÈ»Consulate Health CareµÄ550GBÊý¾Ý
ýÌå1ÔÂ7Èճƣ¬ÀÕË÷ÍÅ»ïHiveй¶ÁËConsulate Health CareµÄ550GBÊý¾Ý¡£¸ÃÍÅ»ïÌåÏÖ£¬¹¥»÷·¢ÉúÔÚ2022Äê12ÔÂ3ÈÕ£¬²¢ÓÚ2023Äê1ÔÂ6ÈÕÅû¶¡£Æð³õ£¬¹¥»÷ÕßÐû²¼Á˱»µÁÊý¾ÝµÄÑù±¾£¬²¢Éù³ÆÇÔÈ¡Á˺Ïͬ¡¢NDAºÍÆäËüÐÒéÎļþ¡¢¹«Ë¾ÐÅÏ¢¡¢Ô±¹¤ÐÅÏ¢ºÍ¿Í»§ÐÅÏ¢µÈ¡£ºóÀ´£¬Ñо¿ÈËÔ±·¢ÏÖ¸ÃÍÅ»ïй¶ÁË´ÓConsulate Health CareÇÔÈ¡µÄ550GBÊý¾Ý£¬°üÂÞ¿Í»§ºÍÔ±¹¤µÄPII¡£¾ÝÍƲ⣬ÒòΪ̸ÅÐʧ°ÜÁË£¬ÀÕË÷ÍÅ»ïûÓеȵ½¼Æ»®µÄ½ØÖ¹ÈÕÆھ͹ûÈ»ÁËËùÓÐÊý¾Ý¡£
https://securityaffairs.com/140452/cyber-crime/consulate-health-care-hive-ransomware.html
3¡¢ÃÀ¹úÁ¬ËøµêChick-fil-AÊÓ²ìÆ䲿ÃÅ¿Í»§ÕË»§±»ºÚµÄÎÊÌâ
¾Ý1ÔÂ6ÈÕ±¨µÀ£¬ÃÀ¹ú¿ì²ÍÁ¬ËøµêChick-fil-AÕýÔÚÊÓ²ìÓëÆ䲿ÃÅ¿Í»§ÕË»§Ïà¹ØµÄ¿ÉÒɻ¡£¾ÝϤ£¬±»½Ù³ÖµÄÕË»§ÓëÒ»´ÎÐÔµç×ÓÓʼþµØÖ·Ò»Æð±»ÓÃÀ´ÔÚ¹¥»÷ÖйºÖÃʳÎһЩ±»µÁÕË»§ÒÔ2ÖÁ200ÃÀÔªµÄ¼Û¸ñ±»³öÊÛ£¬ÕâÈ¡¾öÓÚÕË»§Óà¶î¡¢Á´½ÓµÄÖ§¸¶·½Ê½»òChick-fil-A One»ý·ÖÓà¶î¡£»¹Óпͻ§³ÂËß˵ËûÃǵÄÕË»§±»ºÚ£¬»ý·Ö±»Çå¿Õ¡£Ä¿Ç°£¬Chick-Fil-AÒÑÔÝÍ£´´½¨ÐÂÕÊ»§²¢½ûֹʹÓÃÒ»´ÎÐÔµç×ÓÓʼþµØÖ·£¬½¨Òé¿Í»§Á¢¼´ÖØÖÃÆäÕÊ»§ÃÜÂë¡£
https://www.bleepingcomputer.com/news/security/chick-fil-a-investigates-reports-of-hacked-customer-accounts/
4¡¢¸ßͨÐû²¼2023Äê1Ô·ÝÄþ¾²¸üÐÂÐÞ¸´Æä¹Ì¼þÖеÄ22¸ö©¶´
1ÔÂ5ÈÕ£¬¸ßͨÐû²¼ÁË2023Äê1ÔµÄÄþ¾²¸üУ¬ÐÞ¸´Æä¹Ì¼þÖеÄ22¸ö©¶´¡£ÆäÖУ¬½ÏΪÑÏÖصÄÊÇAutomotiveÖеĻº³åÇøÒç³ö©¶´£¨CVE-2022-33219£©£¬CVSSÆÀ·ÖΪ9.3£¬ÔÚʹÓù²Ïí»º³åÇø×¢²áмàÌýÆ÷ʱ£¬ÓÉÓÚÕûÊýÒç³öµ½»º³åÇøÒç³öµ¼ÖÂAutomotiveÄÚ´æË𻵡£Æä´ÎÊÇAutomotiveÖеÄÊäÈëÑéÖ¤²»Í×£¨CVE-2022-33218£©ºÍAndroid CoreÖÐÊý×éË÷ÒýµÄÑéÖ¤²»ÕýÈ·£¨CVE-2022-33274£©µÈ¡£ÕâЩ©¶´¿ÉÄÜÓ°ÏìÁªÏ롢΢ÈíºÍÈýÐÇÖÆÔìµÄÉ豸£¬ÒÔ¼°»ùÓÚARM¼Ü¹¹µÄ΢ÈíSurfaceºÍWindows Dev Kit 2023/Project Volterra¼ÆËã»ú¡£
https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2023-bulletin.html
5¡¢Mandiant·¢ÏÖTurla·Ö·¢KOPILUWAKºÍQUIETCANARYµÄ»î¶¯
MandiantÔÚ1ÔÂ5ÈÕ³ÆÆä·¢ÏÖÁËTurlaÍÅ»ï½Ù³ÖÊ®ÄêÇ°µÄ¶ñÒâÈí¼þ»ù´¡ÉèÊ©À´·Ö·¢ÐºóÃŵĻ¡£2022Äê9Ô£¬Ñо¿ÈËÔ±·¢ÏÖ¸ÃÍÅ»ïÖØÐÂ×¢²áÁËÖÁÉÙ3¸ö¹ýÆÚµÄANDROMEDA C2Óò£¬²¢·Ö·¢Õì²ì·¨Ê½KOPILUWAKºÍºóÃÅQUIETCANARY¡£ANDROMEDAÓÚ2010Äê´ú¿ªÊ¼Á÷´«£¬±»¹¥»÷Õ߽ٳֵİ汾ÓÚ2013ÄêÊ×´ÎÉÏ´«µ½VirusTotal£¬²¢Í¨¹ý±»Ñ¬È¾µÄUSBÃÜÔ¿Á÷´«¡£´ËÍ⣬¹¥»÷ÕßÇÔÈ¡ÁË2021Äê1ÔÂ1ÈÕÖ®ºó´´½¨µÄÎļþ¡£
https://www.mandiant.com/resources/blog/turla-galaxy-opportunity
6¡¢CheckPointÐû²¼BLINDEAGLEÕë¶Ô¶ò¹Ï¶à¶ûµÄ·ÖÎö³ÂËß
1ÔÂ5ÈÕ£¬Check PointÐû²¼Á˹ØÓÚBLINDEAGLE¹¥»÷¶ò¹Ï¶à¶ûºÍ¸çÂ×±ÈÑǵķÖÎö³ÂËß¡£¹¥»÷ʼÓÚÀ´×Ô¸çÂ×±ÈÑÇÕþ¸®µÄµöÓãÓʼþ£¬×îÖջᰲװ¿ªÔ´Ä¾ÂíQuasar RAT£¬Ö¼ÔÚ»ñµÃÄ¿±êÒøÐÐÕË»§µÄ·ÃÎÊȨÏÞ¡£´ËÍ⣬»¹»á·ÖÎö´«ÈëHTTPÇëÇó£¬ÒÔ¼ì²éÄ¿±êÊÇ·ñÀ´×Ô¸çÂ×±ÈÑǾ³Í⣬Èç¹ûÀ´×Ô¾³ÍâÔòÖÐÖ¹¹¥»÷£¬²¢½«ÆäÖض¨Ïòµ½¸çÂ×±ÈÑÇÍâ½»²¿ÒÆÃñ²¿ÃŵÄÕæʵÍøÕ¾¡£ÁíÒ»¸ö»î¶¯Ã°³äÁ˶ò¹Ï¶à¶û¹úË°¾Ö£¬ÀûÓÃÀàËƵļ¼Êõ¹ýÂ˵ôÀ´×ÔÆäËû¹ú¼ÒµÄÇëÇó¡£¹¥»÷ûÓзַ¢RAT£¬¶øÊÇÀÄÓúϷ¨µÄmshta.exeÀ´Ö´ÐÐǶÈëÔÚHTMLÎļþÖеÄVBScript£¬×îÖÕÏÂÔØÁ½¸öPython½Å±¾¡£
https://research.checkpoint.com/2023/blindeagle-targeting-ecuador-with-sharpened-tools/