ºÚ¿ÍÔÚ°µÍø³öÊÛ¼ÓÄôóÔËÓªÉÌRogersµÄ3¸öADÊý¾Ý¿â
Ðû²¼Ê±¼ä 2023-04-111¡¢ºÚ¿ÍÔÚ°µÍø³öÊÛ¼ÓÄôóÔËÓªÉÌRogersµÄ3¸öADÊý¾Ý¿â
¾ÝýÌå4ÔÂ7ÈÕ±¨µÀ£¬¹¥»÷ÕßÔÚÒ»¸ö¶íÓïµÄºÚ¿ÍÂÛ̳ÉÏÐû²¼ÁËÒ»Ôò¹ã¸æ£¬Éù³ÆÒª³öÊÛ¼ÓÄôóÍøÂçÔËÓªÉÌRogers CommunicationsµÄÊý¾Ý¿â¡£ÆäÖаüÂÞRogersµÄ3¸ö»î¶¯Ä¿Â¼£¨AD£©Êý¾Ý¿â£ºusers¡¢groupsºÍdevices¡£Í¨³££¬AD°üÂÞÓйع«Ë¾»·¾³µÄÒªº¦Êý¾Ý¡£Rogers֤ʵ£¬¸Ã¹«Ë¾µÄ²¿ÃÅÊý¾ÝÔÚ°µÍøÉÏй¶£¬È»¶øÐ¹Â¶µÄÊý¾Ý¿âÖнö°üÂÞÔ±¹¤Êý¾Ý£¬Ã»Óпͻ§µÄÏêϸÐÅÏ¢¡£Õâ3¸öÊý¾Ý¿âµÄ±ê¼ÛΪ14000ÃÀÔª£¬Ã»ÓоßÌå˵Ã÷Êý¾Ý¿âµÄ¾Þϸ»òËüËù¹ûÈ»µÄ¹«Ë¾Óû§ÊýÁ¿¡£
https://cybernews.com/news/rogers-communications-data-breach/
2¡¢SD WorxÔâµ½¹¥»÷±»ÆÈ¹Ø±ÕÆäÓ¢¹úºÍ°®¶ûÀ¼µÄ»ù´¡ÉèÊ©
ýÌå4ÔÂ10Èճƣ¬±ÈÀûʱÈËÁ¦×ÊÔ´¹«Ë¾SD WorxÔâµ½ÍøÂç¹¥»÷£¬±»ÆÈ¹Ø±ÕÆäÓ¢¹úºÍ°®¶ûÀ¼µÄIT»ù´¡ÉèÊ©¡£SD Worx¸øÓ¢¹úºÍ°®¶ûÀ¼¿Í»§µÄ֪ͨ³Æ£¬ËûÃÇÔÚÍйÜÊý¾ÝÖÐÐÄ·¢ÏÖ¶ñÒâ»î¶¯£¬ÒѽÓÄÉÐж¯²¢¸ôÀëÁËËùÓÐϵͳºÍ·þÎñÆ÷¡£¸Ã¹«Ë¾Õë¶ÔÆäËüÅ·ÖÞ¹ú¼ÒµÄµÇÂ¼ÍøÕ¾ÈÔÈ»ÔËÐÐÕý³££¬µ«Ó¢¹úµÄÍøÕ¾ÎÞ·¨·ÃÎÊ¡£Ã»ÓйØÓڴ˴ι¥»÷ÀàÐ͵ÄÏêϸÐÅÏ¢£¬ÓÐÈ˵£ÓÇÃô¸ÐÊý¾ÝÔÚ¹¥»÷ÆÚ¼ä±»µÁ¡£×÷Ϊһ¼ÒÈËÁ¦×ÊÔ´ºÍн×ʹ«Ë¾£¬SD WorxΪÆä¿Í»§µÄÔ±¹¤¹ÜÀí×Å´óÁ¿Ãô¸ÐÊý¾Ý£¬Èç˰ÎñÐÅÏ¢¡¢Éí·ÝÖ¤ºÅÂëºÍÒøÐÐÕʺŵȡ£
https://securityaffairs.com/144629/hacking/sd-worx-suffered-cyberattack.html
3¡¢ÈûÆÖ·˹¿ª·Å´óѧOUCÔâµ½ÀÕË÷ÍÅ»ïMedusaµÄ¹¥»÷
¾Ý4ÔÂ6ÈÕ±¨µÀ£¬ÀÕË÷ÍÅ»ïMedusaÉù³Æ¹¥»÷ÁËÈûÆÖ·˹¿ª·Å´óѧ(OUC)¡£OUCÊÇλÓÚÈûÆÖ·˹Äá¿ÆÎ÷ÑǵÄÒ»ËùÔÚÏß´óѧ£¬ÌṩԶ³Ìѧϰ¡£ÉÏÖÜ£¬¸Ã´óѧÐû²¼ÁËÒ»·Ý¹ØÓÚ3ÔÂ27ÈÕ·¢ÉúµÄÍøÂç¹¥»÷µÄͨ¸æ£¬´Ë´Î¹¥»÷µ¼Ö¶àÆäÖÐÑë·þÎñºÍÒªº¦ÏµÍ³å´»ú¡£4ÔÂ6ÈÕ£¬MedusaÔÚÍøÕ¾ÉÏÁгöÁËOUC²¢ÀÕË÷100000ÃÀÔª£¬Áô¸ø¸Ã»ú¹¹14ÌìµÄʱ¼ä¡£¸ÃÍŻﻹÐû²¼Á˱»µÁÊý¾ÝÑù±¾£¬É漰ѧÉúÃûµ¥ºÍ³Ð°üÉ̵IJÆÕþϸ½ÚµÈ¡£
https://www.bleepingcomputer.com/news/security/medusa-ransomware-claims-attack-on-open-university-of-cyprus/
4¡¢SucuriÅû¶Õë¶ÔWPÍøÕ¾µÄ´ó¹æÄ£Balad Injector»î¶¯
SucuriÔÚ4ÔÂ6ÈÕÅû¶ÁË×Ô2017ÄêÒÔÀ´Ò»Ö±¹¥»÷WordPressÍøÕ¾µÄ´ó¹æÄ£Balada Injector»î¶¯¡£Sucuri³Æ£¬Balada Injector¹¥»÷ԼĪÿÔ·¢ÉúÒ»´Î£¬Ã¿´Î¹¥»÷¶¼Ê¹ÓÃÐÂ×¢²áµÄÓòÃûÀ´ÈƹýÀ¹½ØÃûµ¥¡£Í¨³££¬¶ñÒâÈí¼þ»áÀûÓÃËùÓÐÒÑÖªºÍ×î½ü·¢ÏÖµÄÖ÷ÌâºÍ²å¼þ©¶´£¬Ö÷ҪעÈëLinuxºóÃÅ¡£SucuriÊӲ쵽µÄ×¢ÈëÒªÁì°üÂÞsiteurl hack¡¢HTML×¢Èë¡¢Êý¾Ý¿â×¢ÈëºÍÈÎÒâÎļþÉÏ´«¡£Ñо¿ÈËÔ±Ô¤¼Æ£¬Áè¼Ý100Íò¸öWordPressÍøÕ¾Òѱ»´Ë»î¶¯Ñ¬È¾¡£
https://blog.sucuri.net/2023/04/balada-injector-synopsis-of-a-massive-ongoing-wordpress-malware-campaign.html
5¡¢MicrosoftÐû²¼MERCURYÓëDEV-1084Ð×÷¹¥»÷µÄ³ÂËß
4ÔÂ7ÈÕ£¬MicrosoftÐû²¼Á˹ØÓÚMERCURYÓëDEV-1084Ð×÷¹¥»÷µÄ·ÖÎö³ÂËß¡£Microsoft¼ì²âµ½ÁËÓëÒÁÀÊÏà¹ØµÄMERCURYµÄ¹¥»÷»î¶¯¡£ÒÔǰµÄMERCURY¹¥»÷ÊÇÕë¶Ôµ±µØ»·¾³£¬È»¶ø£¬´Ë´Î¹¥»÷»¹Õë¶ÔÔÆ×ÊÔ´¡£MicrosoftÈÏΪ£¬Ëü¿ÉÄÜÓëDEV-1084ºÏ×÷£¬ºóÕßÔÚMERCURYÀֳɽøÈëÄ¿±ê»·¾³ºóÖ´Ðй¥»÷¡£MERCURY¿ÉÄÜÀûÓÃδÐÞ¸´Ó¦ÓÃÖеÄ©¶´½øÐгõʼ·ÃÎÊ£¬Ö®ºó½«·ÃÎÊȨÏÞÒÆ½»¸øDEV-1084£¬È»ºóÖ´ÐÐÕì²ì¡¢½¨Á¢³Ö¾ÃÐÔ²¢ºáÏòÒÆ¶¯£¬Í¨³£ÐèÒªÆÚ´ýÊýÖÜÉõÖÁÊýÔÂ²ÅÆø½øÈëÏÂÒ»½×¶Î¡£
https://www.microsoft.com/en-us/security/blog/2023/04/07/mercury-and-dev-1084-destructive-attack-on-hybrid-environment/
6¡¢CyfirmaÐû²¼¹ØÓÚARES LeaksÔËÓª¡¢Éú³¤ºÍÄÜÁ¦µÄ·ÖÎö
ýÌå4ÔÂ8ÈÕ±¨µÀ£¬CyfirmaÐû²¼¹ØÓÚÐÂÍþв×éÖ¯ARES LeaksµÄ·ÖÎö³ÂËß¡£×ÔBreachedForum¹Ø±ÕÒÔÀ´£¬ARES Leaks»î¶¯ÓÐËùÔö¼Ó£¬±íÃ÷ÔÚ²»¾ÃµÄ½«À´ËüÓпÉÄܳÉΪ±¸Ñ¡·½°¸Ö®Ò»¡£OSINTËÑË÷·¢ÏÖARES GroupµÄ¹ÜÀíÔ±³öÊÛÁãÈÕ©¶´£¬±íÃ÷¸Ã×éÖ¯ÕýÔÚÀûÓé¶´À´¹¥»÷»µÏµÍ³¡£¸Ã×éÖ¯ÓÉÉøÍ¸²âÊÔÈËÔ±ºÍ¶ñÒâÈí¼þ¿ª·¢ÕßµÈ×ÊÔ´×é³É¡£³ýÁËÊý¾Ýй¶Í⣬Ëü»¹Ìṩ½©Ê¬ÍøÂçºÍDDoS·þÎñ¡£ARES»¹ÌåÏÖ³öÀàËÆcartelµÄÐÐΪ£¬»ý¼«Ñ°ÇóÓëÆäËû¹¥»÷ÕßµÄÁªÏµ¡£
https://www.cyfirma.com/outofband/ares-leaks-emerging-cyber-crime-cartel/