BlackCatÉù³ÆÒÑ»ñÈ¡RedditµÄ80GBÊý¾Ý²¢ÀÕË÷450ÍòÃÀÔª

Ðû²¼Ê±¼ä 2023-06-19

1¡¢BlackCatÉù³ÆÒÑ»ñÈ¡RedditµÄ80GBÊý¾Ý²¢ÀÕË÷450ÍòÃÀÔª 


¾ÝýÌå6ÔÂ17ÈÕ±¨µÀ£¬BlackCat(ALPHV)Éù³Æ¶ÔRedditÔâµ½µÄ¹¥»÷ÂôÁ¦£¬²¢ÌåÏÖÒÑÇÔÈ¡80 GB£¨Ñ¹Ëõ£©µÄÊý¾Ý¡£2ÔÂ9ÈÕ£¬Reddit͸¶ÆäϵͳÔÚ2ÔÂ5ÈÕ±»ºÚ£¬ÒòΪһÃûÔ±¹¤Ôâµ½Á˵öÓã¹¥»÷¡£Õâµ¼Ö¹¥»÷ÕßÄܹ»·ÃÎÊRedditµÄϵͳ£¬²¢ÇÔÈ¡ÄÚ²¿Îĵµ¡¢Ô´´úÂë¡¢Ô±¹¤ÐÅÏ¢ÒÔ¼°Óйع«Ë¾¹ã¸æÉ̵ÄÊý¾Ý¡£BlackCatÍÅ»ïÌåÏÖ£¬ËûÃÇÔøÔÚ4ÔÂ13ÈÕºÍ6ÔÂ16ÈÕÁ½´ÎÊÔͼÁªÏµReddit£¬²¢ÒªÇóÆä½»450ÍòÃÀµÄÊê½ð£¬µ«Ã»ÓÐÊÕµ½»Ø¸´¡£


https://www.databreaches.net/blackcat-claims-they-hacked-reddit-and-will-leak-the-data/


2¡¢ProgressÐÞ¸´MOVEitÖÐÓÖÒ»¸öSQLi©¶´CVE-2023-35708  


ýÌå6ÔÂ15Èճƣ¬Progress SoftwareÐÞ¸´ÁËÆäMOVEit TransferÖеĵÚÈý¸öSQL×¢Èë©¶´£¨CVE-2023-35708£©¡£¸Ã¹«Ë¾³Æ£¬ËûÃÇÒѾ­½µµÍÁËMOVEit CloudµÄHTTPsÁ÷Á¿£¬²¢ÒªÇóÓû§ÔÚ´´½¨ºÍ²âÊÔ²¹¶¡Ê±½µµÍHTTPºÍHTTPsÁ÷Á¿ÒÔ± £»¤ËûÃǵÄϵͳ¡£ÔÚ°²×°²¹¶¡Ç°£¬ProgressÇ¿ÁÒ½¨ÒéÐ޸ķÀ»ðǽ¹æÔòÒԾܾø¶Ë¿Ú80ºÍ443ÉϵÄMOVEit TransferµÄHTTPºÍHTTPsÁ÷Á¿£¬×÷ΪһÖÖÁÙʱ½â¾öÒªÁì¡£ËùÓÐÓû§¶¼±ØÐëÓ¦ÓÃÔÚ6ÔÂ16ÈÕÐû²¼µÄв¹¶¡¡£Õâ¸öЩ¶´µÄϸ½ÚÉÐδ¹ûÈ»£¬µ«ÒÑÓÐÑо¿ÈËÔ±Ðû²¼PoC¡£


https://www.bleepingcomputer.com/news/security/moveit-transfer-customers-warned-of-new-flaw-as-poc-info-surfaces/


3¡¢ÀÕË÷ÍÅ»ïRhysida¹ûÈ»´ÓÖÇÀû¾ü¶ÓµÄϵͳÖÐÇÔÈ¡µÄÎļþ


¾Ý6ÔÂ15ÈÕ±¨µÀ£¬ÀÕË÷ÍÅ»ïRhysida¹ûÈ»ÁË´ÓÖÇÀû¾ü¶Ó(Ej¨¦rcito de Chile)µÄϵͳÖÐÇÔÈ¡µÄÎļþ¡£¾ÝÄþ¾²¹«Ë¾CronUp³Æ£¬ÖÇÀû¾ü¶ÓÓÚ5ÔÂ29ÈÕÈ·ÈÏÆäϵͳÊܵ½ÁËÔÚ5ÔÂ27ÈÕ¼ì²âµ½µÄÄþ¾²Ê¼þµÄÓ°Ï죬²¿ÃÅÊý¾Ýй¶¡£¹¥»÷ʼþÅû¶µÄ¼¸Ììºó£¬µ±µØÃ½Ì屨µÀ³Æ£¬Ò»Ãû½¾üÏÂÊ¿Òò¼ÓÈëÀÕË÷¹¥»÷¶ø±»²¶¡£RhysidaĿǰÐû²¼ÁËԼĪ360000·ÝÖÇÀû¾ü¶ÓµÄÎļþ£¨¾Ý³Æ½öÕ¼ËùÓб»µÁÊý¾ÝµÄ30%£©¡£


https://www.bleepingcomputer.com/news/security/rhysida-ransomware-leaks-documents-stolen-from-chilean-army/


4¡¢Î¢Èí͸¶½üÆÚAzure¡¢OutlookºÍOneDriveÖжÏÔ´ÓÚDDoS¹¥»÷


6ÔÂ18ÈÕ±¨µÀ³Æ£¬Î¢Èí͸¶6ÔÂÉÏÑ®ÆäAzure¡¢OutlookºÍOneDrive·þÎñÖжÏÊÇÕë¶Ô¹«Ë¾·þÎñµÄµÚ7²ãDDoS¹¥»÷µ¼ÖµÄ¡£´Ë´Î¹¥»÷±»¹éÒòÓÚ΢Èí×·×ÙΪStorm-1359µÄÍŻ¸ÃÍÅ»ï×Ô³ÆAnonymous Sudan¡£ÕâЩ¹¥»÷¿ÉÄÜÒÀÀµÓÚ·ÃÎʶà¸öÐéÄâרÓ÷þÎñÆ÷(VPS)ÒÔ¼°×âÓõÄÔÆ»ù´¡ÉèÊ©¡¢¿ª·ÅÊðÀíºÍDDoS¹¤¾ß¡£×î³õ£¬Õâ¼ÒIT¹«Ë¾Ã»ÓÐÌṩÓйØÖжÏʼþµÄÏêϸÐÅÏ¢£¬µ«ÔÚ6ÔÂ16ÈÕÐû²¼ÁËMicrosoft¶ÔµÚ7²ãDDoS¹¥»÷µÄÏìÓ¦³ÂËߣ¬Í¸Â¶ÁËÖжϵÄÔ­Òò¡£


https://securityaffairs.com/147605/hacking/microsoft-outages-ddos.html


5¡¢Ö´·¨Ðж¯PowerOffµ·»Ù2013Ä꿪ʼ»îÔ¾µÄDDoS³ö×â·þÎñ


¾Ý6ÔÂ17ÈÕýÌ屨µÀ£¬¹ú¼ÊÖ´·¨Ðж¯Operation PowerOFFµ·»ÙÁË×Ô2013Ä꿪ʼ»îÔ¾µÄDDoS³ö×â·þÎñ (ÓÖ³Æbooter»òstresser)¡£DDoS³ö×⣨DDoS-for-hire£©·þÎñÔÊÐí×¢²áÓû§ÔÚ²»¾ß±¸Ìض¨ÖªÊ¶µÄÇé¿öÏÂÖ´ÐÐÓÐÐòµÄDDoS¹¥»÷¡£¾ÝϤ£¬²¨À¼¾¯·½´þ²¶ÁË¸ÃÆ½Ì¨µÄÁ½ÃûÔËÓªÈËÔ±£¬²¢´ÓËûÃÇλÓÚÈðÊ¿µÄ·þÎñÆ÷ÖÐÊÕ¼¯µ½ÁËÓмÛÖµµÄÊý¾Ý¡£ÓÐÁè¼Ý35000¸öÓû§ÕÊ»§¡¢76000¸öµÇ¼¼Ç¼ºÍÁè¼Ý320000¸öÓëDDoS³ö×â·þÎñÏà¹ØµÄIPµØÖ·µÄÐÅÏ¢¡£Operation PowerOFFÊÇÒ»Ïîºã¾ÃÖ´ÐеÄÖ´·¨Ðж¯£¬ÒѹرÕÁËÊýÊ®¸öÖ÷ÒªµÄDDoS³ö×âÆ½Ì¨¡£ 


https://securityaffairs.com/147564/cyber-crime/ddos-for-eye-service-seized.html


6¡¢ESET·¢ÏÖAndroid¶ñÒâÈí¼þGravityRATÐÂÒ»ÂÖ¹¥»÷»î¶¯


6ÔÂ15ÈÕ£¬ESETÅû¶ÁËAndroid¶ñÒâÈí¼þGravityRATµÄÐÂÒ»ÂÖ¹¥»÷»î¶¯¡£¸Ã»î¶¯×Ô2022Äê8Ô¿ªÊ¼»îÔ¾£¬Ê¹ÓÃľÂí»¯ÁÄÌìÓ¦ÓÃBingeChatºÍChaticoÑ¬È¾ÒÆ¶¯É豸£¬²¢ÊÔͼ´ÓÄ¿±êÉ豸ÖÐÇÔÈ¡Êý¾Ý¡£Ä¿Ç°£¬Ê¹ÓÃChaticoµÄ»î¶¯ÒѲ»ÔÙ»îÔ¾¡£¶ñÒâÓ¦Óû¹Ìṩ»ùÓÚ¿ªÔ´OMEMO Instant MessengerÓ¦Ó÷¨Ê½µÄºÏ·¨ÁÄÌ칦Ч¡£Õâ¸öа汾µÄGravityRAT¾ßÓÐÁ½¸öй¦Ð§£¬¿É½ÓÊÕɾ³ýÎļþµÄÃüÁîºÍй¶WhatsApp±¸·ÝÎļþ¡£


https://www.welivesecurity.com/2023/06/15/android-gravityrat-goes-after-whatsapp-backups/