AT&Tij¹©Ó¦É̱»ºÚµ¼ÖÂÆäÔ¼900Íò¿Í»§µÄÊý¾Ýй¶

Ðû²¼Ê±¼ä 2023-03-10

1¡¢AT&Tij¹©Ó¦É̱»ºÚµ¼ÖÂÆäÔ¼900Íò¿Í»§µÄÊý¾Ýй¶


¾Ý3ÔÂ9ÈÕ±¨µÀ£¬AT&T֪ͨԼ900Íò¿Í»§ÆäÐÅÏ¢ÒѾ­Ð¹Â¶£¬ÒòΪËüµÄÒ»¼ÒÓªÏú¹©Ó¦ÉÌÔÚ1Ô·ÝÔâµ½Á˺ڿ͹¥»÷¡£Ð¹Â¶Êý¾Ý°üÂÞ¿Í»§ÐÕÃû¡¢ÎÞÏßÕʺš¢ÎÞÏߵ绰ºÅÂëºÍÓʼþµØÖ·µÈ£¬ÒÔ¼°²¿Ãſͻ§µÄÎÞÏß·ÑÂʼƻ®¡¢ÓâÆÚ½ð¶îºÍ¸¶¿î½ð¶îµÈ¡£¸Ã¹«Ë¾Ôö²¹Ëµ£¬Æäϵͳ²¢Î´ÊÜÓ°Ï죬й¶Êý¾ÝÖ÷ÒªÓëÉ豸Éý¼¶×ʸñÓйØ¡£AT&T¾Ü¾øÍ¸Â¶¹©Ó¦É̵ÄÉí·Ý£¬µ«The RegisterÌåÏÖ£¬µç×ÓÓʼþÓªÏú¹«Ë¾MailchimpÔÚ1Ô·ÝÔøÔâµ½¹¥»÷£¬¹¥»÷Õß»ñµÃÁË100¶à¸ö¿Í»§ÕÊ»§µÄ·ÃÎÊȨÏÞ¡£


https://www.theregister.com/2023/03/09/att_wireless_breach/


2¡¢Ã÷Äá°¢²¨Àû˹¹«Á¢Ñ§Ð£Ñ§Çø±»MedusaÀÕË÷100ÍòÃÀÔª


ýÌå3ÔÂ8Èճƣ¬Ã÷Äá°¢²¨Àû˹¹«Á¢Ñ§Ð£(MPS)Ñ§Çø±»MedusaÍÅ»ïÀÕË÷100ÍòÃÀÔª¡£¸ÃÍŻォMPSÌí¼Óµ½ÆäTorÍøÕ¾ÉÏ£¬²¢ÍþвҪÔÚ3ÔÂ17ÈÕ֮ǰÐû²¼´Ó¸ÃÑ§ÇøÇÔÈ¡µÄËùÓÐÊý¾Ý¡£¸ÃʼþÖ®ËùÒÔÒýÈËעĿ£¬ÊÇÒòΪ¹¥»÷ÕßÖÆ×÷ÁËÒ»¶Îʱ³¤Ô¼51·ÖÖÓµÄÊÓÆµ£¬ÏÔʾ´ÓMPSÇÔÈ¡µÄÊý¾Ý¡£MPS¹ÜÀí×ÅÔ¼100Ëù¹«Á¢ÖÐСѧ£¬ËüÓÚ3ÔÂ1ÈÕÐû²¼Í¨¸æ£¬Í¸Â¶Æä2ÔÂ21ÈÕÔâµ½¹¥»÷µ¼ÖÂϵͳÖжÏ¡£¸Ã×éÖ¯»¹ÌåÏÖ£¬Ëü²»¼Æ»®¸¶Êê½ð£¬¶øÊÇÑ¡ÔñʹÓÃÄÚ²¿±¸·Ý»Ö¸´±»¼ÓÃܵÄÊý¾Ý¡£


https://www.bleepingcomputer.com/news/security/ransomware-gang-posts-video-of-data-stolen-from-minneapolis-schools/


3¡¢Ó¡¶ÈHDFC Bank×Ó¹«Ë¾Áè¼Ý7200ÍòÌõ¼Ç¼±»Ðû²¼ÔÚ°µÍø


¾ÝýÌå3ÔÂ8ÈÕ±¨µÀ£¬ºÚ¿ÍKernelwareÔÚ°µÍøBreached forumÉÏÐû²¼ÁËHDB Financial ServicesÔ¼7.5 GBµÄ¿Í»§Êý¾Ý¡£HDB Financial ServicesÊÇÓ¡¶È×î´óµÄ˽ÈËÒøÐÐHDFC BankµÄ×Ó¹«Ë¾¡£Ð¹Â¶ÐÅÏ¢°üÂÞÁè¼Ý7200ÍòÌõ¼Ç¼£¬Éæ¼°2022Äê5ÔÂÖÁ2023Äê2ÔÂÉêÇë´û¿îµÄHDBÏû·ÑÕß¡£HDFC Bank·ñÈÏÁËÊý¾Ýй¶Ê¼þ£¬µ«HDB FinancialÒÑÈ·Èϲ¢ÔÚÊÓ²ì¸ÃÄþ¾²Ê¼þ¡£ÖµµÃ×¢ÒâµÄÊÇ£¬Kernelware¾ÍÊÇй¶ÁËAcerÔ¼160GBÊý¾ÝµÄºÚ¿Í¡£


https://www.hackread.com/hackers-india-hdfc-bank-data-leak/


4¡¢VeeamÐÞ¸´Ó°ÏìÆäËùÓÐVBR°æ±¾µÄ©¶´CVE-2023-27532


3ÔÂ8ÈÕ±¨µÀ³Æ£¬VeeamÐû²¼¸üУ¬ÐÞ¸´ÆäBackup & Replication²úÎïÖеÄ©¶´CVE-2023-27532¡£Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÔÚ»ñÈ¡´æ´¢ÔÚVeeamVBRÅäÖÃÊý¾Ý¿âÖеļÓÃÜÆ¾¾Ýºó£¬ÀûÓÃËü·ÃÎʱ¸·Ý»ù´¡¼Ü¹¹Ö÷»ú¡£Æ¾¾ÝVeeamͨ¸æ£¬¸Ã©¶´»ù´¡Ô­ÒòÊÇVeeam.Backup.Service.exe£¨Ä¬ÈÏÇé¿öÏÂÔÚTCP 9401ÉÏÔËÐУ©¿É±»Î´¾­Éí·ÝÑéÖ¤µÄÓû§ÓÃÀ´ÇëÇó¼ÓÃÜÆ¾¾Ý¡£Veeam»¹ÌṩÁËÁÙʱÐÞ¸´ÒªÁ죬ʹÓñ¸·Ý·þÎñÆ÷·À»ðǽ×èÖ¹Óë¶Ë¿ÚTCP 9401µÄÍⲿÁ¬½Ó¡£


https://www.bleepingcomputer.com/news/security/veeam-fixes-bug-that-lets-hackers-breach-backup-infrastructure/


5¡¢FortinetÅû¶8220 GangÀûÓÃScrubCryptµÄ¹¥»÷»î¶¯


FortinetÔÚ3ÔÂ8ÈÕÅû¶ÁË8220 Gang×î½üµÄ¼ÓÃܽٳֹ¥»÷¡£¹¥»÷·¢ÉúÔÚ2023Äê1ÔÂÖÁ2Ô£¬¹¥»÷Á´Ê¼ÓÚÀÖ³ÉÀûÓÃÒ×±»¹¥»÷µÄOracle WebLogic ServerÏÂÔØ°üÂÞScrubCryptµÄPowerShell½Å±¾¡£PowerShell½Å±¾ÒѾ­¹ý±àÂ룬À´ÈƹýÄþ¾²·½°¸µÄ¼ì²â¡£ScrubCrypt¼ÓÃÜÆ÷ÔÚºÚ¿ÍÂÛ̳ÉÏÓÐÊÛ£¬¿ÉʹÓÃÆæÌصÄBAT´ò°üÒªÁì± £»¤Ó¦Ó÷¨Ê½¡ £»ùÓڻÖÐʹÓõļÓÃÜÇ®°üµØÖ·ºÍMonero¿ó¹¤Ê¹ÓõķþÎñÆ÷IPµØÖ·£¬Ñо¿ÈËÔ±½«´Ë´Î»î¶¯¹éÒòÓÚ8220 Gang¡£


https://www.fortinet.com/blog/threat-research/old-cyber-gang-uses-new-crypter-scrubcrypt


6¡¢KasperskyÐû²¼2022Äê¸ú×ÙÈí¼þÌ¬ÊÆµÄ·ÖÎö³ÂËß


3ÔÂ8ÈÕ£¬KasperskyÐû²¼ÁË2022Äê¸ú×ÙÈí¼þ£¨Stalkerware£©Ì¬ÊƵķÖÎö³ÂËß¡£Êý¾ÝÏÔʾ£¬2022ÄêÈ«ÇòÓÐ29312¸öÓû§Êܵ½¸ú×ÙÈí¼þµÄÓ°Ï죬ƽ¾ùÿÔÂÓÐ3333¸öÓû§Êܵ½¸ú×ÙÈí¼þµÄÓ°Ïì¡£¸ú×ÙÈí¼þÈÔÈ»ÊÇÒ»¸öÈ«ÇòÐÔÎÊÌ⣬Kaspersky¼ì²âµ½176¸ö¹ú¼Ò/µØÓòÊܵ½Ó°Ï죬ÆäÖжíÂÞ˹£¨8281£©¡¢°ÍÎ÷£¨4969£©ºÍÓ¡¶È£¨1807£©ÊÜÓ°Ïì×îÑÏÖØ¡£2022Äê¼ì²âµ½182ÖÖ²îÒìµÄ¸ú×ÙÈí¼þÓ¦Óã¬×î³£¼ûµÄÊÇReptilicus£¬Æä´ÎÊÇCerberusºÍKeyLog¡£


https://securelist.com/the-state-of-stalkerware-in-2022/108985/