ºÉÀ¼º½Ô˹«Ë¾Royal DirkzwagerÔâµ½PlayµÄÀÕË÷¹¥»÷
Ðû²¼Ê±¼ä 2023-03-211¡¢ºÉÀ¼º½Ô˹«Ë¾Royal DirkzwagerÔâµ½PlayµÄÀÕË÷¹¥»÷
¾Ý3ÔÂ20ÈÕ±¨µÀ£¬ºÉÀ¼º½Ô˹«Ë¾Royal DirkzwagerÔâµ½ÀÕË÷ÍÅ»ïPlayµÄ¹¥»÷¡£ÀÕË÷ÍŻォ¸Ã¹«Ë¾Ìí¼Óµ½ÆäÍøÕ¾ÉÏ£¬²¢Ðû²¼ÇÔÈ¡ÁËÔ±¹¤ ID¡¢»¤ÕպͺÏͬµÈ»úÃÜÊý¾Ý¡£¸ÃÍÅ»ï×î³õ¹ûÈ»ÁËÒ»¸ö5 GBµÄÎļþ×÷Ϊ¹¥»÷Ö¤¾Ý£¬²¢Íþв˵£¬Èç¹û¹«Ë¾²»¸¶Êê½ð¾Í¹ûȻȫ²¿µÄÊý¾Ý¡£¸Ãº½Ô˹«Ë¾ÌåÏÖ£¬¹¥»÷»î¶¯²¢Î´Ó°Ï칫˾µÄÔËÓª£¬²¢Ö¤Êµ¹¥»÷ÕßÒѾ´ÓÆä»ù´¡ÉèÊ©ÖÐÇÔÈ¡ÁËÃô¸ÐÊý¾Ý¡£¸Ã¹«Ë¾Òѽ«´ËÊÂ֪ͨÁ˺ÉÀ¼Êý¾Ý±£»¤¾Ö£¬²¢ÕýÔÚÓëÀÕË÷ÍÅ»ï½øÐÐ̸ÅС£
https://securityaffairs.com/143714/cyber-crime/play-ransomware-royal-dirkzwager.html
2¡¢Ñо¿ÍŶӷ¢ÏÖÒøÐÐľÂíMispaduµÄ´ó¹æÄ£¹¥»÷»î¶¯
¾ÝýÌå3ÔÂ20Èճƣ¬Ñо¿ÍŶӷ¢ÏÖÁË20¸öÕë¶ÔÖÇÀû¡¢Ä«Î÷¸ç¡¢ÃØÂ³ºÍÆÏÌÑÑÀµÄ´ó¹æÄ£À¬»øÓʼþ»î¶¯¡£»î¶¯ÓÚ2022Äê8ÔÂ×óÓÒ¿ªÊ¼£¬½ØÖÁ2023Äê3ÔÂÉÏÑ®ÈÔÈ»»îÔ¾¡£ÕâЩ»î¶¯ÒÀÀµÓÚÒøÐÐľÂíMispadu£¬ÊÓ²ì½á¹ûÏÔʾ£¬¹¥»÷ÕßÒÑ´Ó×ܹ²17595¸öÆæÌØÍøÕ¾ÖÐÇÔÈ¡ÁË90518¸öƾ¾Ý¡£Mispadu½ÓÄÉÁË´Ù½øÑ¬È¾ºÍ±£³Ö³Ö¾ÃÐÔµÄм¼Êõ£¬°üÂÞÓÃÓÚ»ìÏý³õʼ½×¶Î¶ñÒâÈí¼þµÄαÔìÖ¤ÊéºÍÒ»¸öеĻùÓÚ.NETµÄºóÃÅ¡£
https://www.infosecurity-magazine.com/news/mispadu-steals-90000-banking/
3¡¢Lowe's MarketϵͳÅäÖôíÎó´óÁ¿Æ¾¾ÝºÍ¿Í»§ÐÅϢй¶
ýÌå3ÔÂ17ÈÕ͸¶£¬Ñо¿ÈËÔ±ÔÚLowe's MarketÍøÕ¾ÉÏ·¢ÏÖÁËÒ»¸ö¿É¹ûÈ»·ÃÎʵĻ·¾³Îļþ(.env)¡£Õâ¶Ô¹«Ë¾ÏµÍ³µÄÄþ¾²×é³ÉÁË·çÏÕ£¬ÒòΪËüй¶ÁË´óÁ¿Æ¾¾Ý¡£¸Ã»·¾³Îļþй¶ÁËAWS S3·þÎñÆ÷µÄ·ÃÎÊÃÜÔ¿ºÍ´æ´¢Í°Ãû³Æ£¬Ðí¶àרÓÃÓÚÌØ¶¨ÍøÕ¾¹¦Ð§µÄÓ¦Ó÷¨Ê½±à³Ì½Ó¿Ú(API)ÃÜÔ¿£¬ÒÔ¼°Facebook OAuthƾ¾ÝºÍGithub OAuthÁîÅÆµÈÐÅÏ¢¡£Ñо¿ÈËÔ±ÌåÏÖ£¬Ð¹Â¶µÄƾ¾Ý¿É±»¹¥»÷ÕßÓÃÓÚ¿ØÖÆ´ó²¿ÃÅÔÚÏßÉ̵êµÄ¹¦Ð§£¬¼ì²ì¿Í»§ÐÅÏ¢£¬²¢ÀÄÓø¶·Ñ·þÎñµÄ·ÃÎÊȨÏÞ¡£Ä¿Ç°£¬¸ÃÎÊÌâÒѾ±»½â¾ö¡£
https://cybernews.com/security/lowes-market-data-leak/
4¡¢ÈÕÁ¢ÄÜÔ´ÒòµÚÈý·½Èí¼þÌṩÉÌÔâµ½CLOP¹¥»÷Êý¾Ýй¶
3ÔÂ17ÈÕ±¨µÀ£¬ÈÕÁ¢ÄÜÔ´µÄÉùÃ÷³Æ£¬µÚÈý·½Èí¼þÌṩÉÌFORTRA GoAnywhere MFTÔâµ½ÁËCLOPµÄÀÕË÷¹¥»÷£¬¿ÉÄܵ¼ÖÂÔÚijЩ¹ú¼Ò/µØÓòµÄÔ±¹¤Êý¾Ý±»·Ç·¨·ÃÎÊ¡£¸Ã¹¥»÷ÊÇͨ¹ýÀûÓÃGoAnywhere MFTÖеÄ©¶´£¨CVE-2023-0669£©ÊµÏֵģ¬¸Ã©¶´ÓÚ2023Äê2ÔÂ3ÈÕÊ×´ÎÅû¶¡£ÈÕÁ¢ÄÜÔ´³ÆÆäÁ¢¼´¶Ô¸Ãʼþ×÷³ö·´Ó³£¬¶Ï¿ªÁËÊÜѬȾϵͳµÄÁ¬½Ó£¬²¢Æô¶¯ÄÚ²¿ÊÓ²ìÒÔÈ·¶¨Î¥¹æµÄÓ°Ïì¡£¸Ã¹«Ë¾Ö¸³ö£¬ÆäÍøÂçÔËÓª»ò¿Í»§Êý¾ÝµÄÄþ¾²²¢Î´Êܵ½Ó°Ïì¡£
https://www.bleepingcomputer.com/news/security/hitachi-energy-confirms-data-breach-after-clop-goanywhere-attacks/
5¡¢KasperskyÐû²¼»ùÓÚContiµÄMeowCorpÀÕË÷Èí¼þ½âÃÜÆ÷
ýÌå3ÔÂ16Èճƣ¬KasperskyÐû²¼ÁË»ùÓÚContiµÄÀÕË÷Èí¼þMeowCorpµÄÃâ·Ñ½âÃÜÆ÷¡£2023Äê2ÔÂÏÂÑ®£¬Ñо¿ÈËÔ±·¢ÏÖÁËÂÛ̳ÉÏÐû²¼µÄÒ»²¿ÃÅеÄÊý¾Ý¡£·ÖÎöºó·¢ÏÖËüÃÇÓë2022Äê12Ô·¢ÏÖµÄ Conti±äÖÖMeowCorpÓйء£ÔÚ¶Ô°üÂÞ258¸ö˽Կ¡¢Ô´´úÂëºÍһЩԤ±àÒë½âÃÜÆ÷µÄÊý¾Ý½øÐзÖÎöºó£¬KasperskyÐû²¼ÁËа汾µÄ¹«¹²½âÃÜÆ÷¡£½âÃÜÆ÷¿ÉÒÔ»Ö¸´ÃüÃûģʽºÍÀ©Õ¹ÃûΪ<file_name>.KREMLIN¡¢<file_name>.RUSSIAºÍ<file_name>.PUTINµÄ¼ÓÃÜÎļþ¡£
https://www.bleepingcomputer.com/news/security/conti-based-ransomware-meowcorp-gets-free-decryptor/
6¡¢RedactedÐû²¼¹ØÓÚÀÕË÷ÍÅ»ïBianLianµÄ·ÖÎö³ÂËß
3ÔÂ16ÈÕ£¬RedactedÐû²¼ÁËÀÕË÷ÍÅ»ïBianLianÉú³¤Ç÷ÊÆµÄ·ÖÎö³ÂËß¡£BianLianÓÚ2022Äê7ÔÂÊ×´ÎÔÚÒ°Íâ·ºÆð£¬AvastÔÚ2023Äê1ÔÂÐû²¼ÁËÃâ·Ñ½âÃÜÆ÷¡£½ØÖÁ2023Äê3ÔÂ13ÈÕ£¬¸ÃÍÅ»ïÔÚÆäÍøÕ¾ÉÏÁгöÁË×ܹ²118¸ö×éÖ¯£¬ÆäÖоø´ó¶àÊý(71%)ÊÇÃÀ¹ú¹«Ë¾¡£ÔÚ×î½üµÄ¹¥»÷ÖеÄÖ÷񻂿±ðÊÇ£¬BianLianÒѽ«ÆäÖØµã´Ó¼ÓÃÜÄ¿±êÊý¾Ý×ªÒÆµ½½öÇÔȡϵͳÖÐÊý¾Ý²¢½øÐÐÀÕË÷¡£Ä¿Ç°Éв»Çå³þBianLian·ÅÆú¼ÓÃܼÆÄ±ÊÇÒòΪAvastµÄ½âÃÜÆ÷£¬»¹ÊÇÒòΪÒâʶµ½²»ÐèÒªÕâÒ»²¿ÃÅÀ´ÀÕË÷Êê½ð¡£
https://redacted.com/blog/bianlian-ransomware-gang-continues-to-evolve/