Ó¢¹úÑ¡¾ÙίԱ»áй¶2014ÖÁ2022ÄêͶƱµÄÑ¡ÃñµÄÐÅÏ¢
Ðû²¼Ê±¼ä 2023-08-101¡¢Ó¢¹úÑ¡¾ÙίԱ»áй¶2014ÖÁ2022ÄêͶƱµÄÑ¡ÃñµÄÐÅÏ¢
¾ÝýÌå8ÔÂ8ÈÕ±¨µÀ£¬Ó¢¹úÑ¡¾ÙίԱ»áÅû¶ÁËÒ»Æð´ó¹æÄ£Êý¾Ýй¶Ê¼þ£¬Éæ¼°2014ÄêÖÁ2022Äê¼äÔÚÓ¢¹ú¹ÒºÅͶƱµÄÑ¡ÃñÐÅÏ¢¡£´Ë´ÎÅû¶ÊÇÔÚίԱ»áÊ״η¢ÏÖй¶10¸öÔºó£¬Ò²¾ÍÊÇÔÚ¹¥»÷·¢ÉúµÄÁ½Äêºó¡£¸Ã»ú¹¹³ÆÔÚ2022Äê10ÔÂÊ״μì²âµ½´Ë´Î¹¥»÷£¬·¢ÏÖ¹¥»÷ÕßÔÚ2021Äê8ÔÂÈëÇÖÁËϵͳ¡£¾ÝϤ£¬¹¥»÷Õß·ÃÎÊÁËÉú´æµç×ÓÓʼþ¡¢¿ØÖÆÏµÍ³ºÍÑ¡¾Ù¹ÒºÅ²á¸±±¾µÄ·þÎñÆ÷¡£¸Ã»ú¹¹ÊÔͼµ»¯Õâ´Î¹¥»÷£¬³Æ¹¥»÷ûÓÐÓ°ÏìÈκÎÑ¡¾Ù»òÑ¡ÃñµÄ¹ÒºÅ¡£
https://securityaffairs.com/149288/data-breach/uk-electoral-commission-data-breach.html
2¡¢¹ú¼ÊÖ´·¨»ú¹¹µ·»ÙPhaaSƽ̨16shop²¢´þ²¶ÆäÔËÓªÈËÔ±
¾Ý8ÔÂ9ÈÕ±¨µÀ£¬¹ú¼ÊÐ̾¯×éÖ¯ºÍÄþ¾²¹«Ë¾Ö®¼äµÄÁªºÏÐж¯µ·»ÙÁ˵öÓã¼´·þÎñ(PhaaS)ƽ̨16shop¡£Group-IB³Æ£¬16shopƽ̨ÌṩÁËÕë¶ÔApple¡¢PayPal¡¢American Express¡¢AmazonºÍCash AppÕË»§µÄµöÓ㹤¾ß°ü¡£Êý¾ÝÏÔʾ£¬16shopÒÑ´´½¨15Íò¸öµöÓãÒ³Ãæ£¬Ö÷ÒªÕë¶ÔµÂ¹ú¡¢ÈÕ±¾¡¢·¨¹ú¡¢ÃÀ¹úºÍÓ¢¹ú¡£Ö´·¨»ú¹¹ÔøÓÚ2022Äê2ÔÂÔÚÓ¡¶ÈÄáÎ÷ÑÇ´þ²¶ÁËÒ»Ãû21ËêµÄƽ̨ÔËÓªÈËÔ±£¬ËæºóÓÖÔÚÈÕ±¾ºÍÓ¡¶ÈÄáÎ÷ÑÇ´þ²¶ÁËÁ½ÃûÐÖúÕß¡£16shopµÄ·þÎñÆ÷ÓÉÒ»¼ÒÃÀ¹ú¹«Ë¾Íйܣ¬µ«Æä×¢²áÐÅÏ¢ÏÔʾÆä×ܲ¿Î»ÓÚÓ¡¶ÈÄáÎ÷ÑÇ¡£
https://www.theregister.com/2023/08/09/interpol_16shop_phishing_shutdown/
3¡¢Ñо¿ÈËÔ±Åû¶¿ÉÇÔÈ¡Intel CPUÊý¾ÝµÄDownfall¹¥»÷
8ÔÂ8ÈÕ±¨µÀ³Æ£¬¹È¸èµÄÒ»ÃûÑо¿ÈËÔ±·¢ÏÖÁËÕë¶ÔIntel CPUµÄDownfall¹¥»÷£¬¿ÉÇÔÈ¡¼ÓÃÜÃÜÔ¿ºÍÊý¾Ý¡£¸Ã©¶´ÊÇÒ»¸ö˲ִ̬ÐвàÐŵÀÎÊÌ⣨CVE-2022-40982£©£¬»áÓ°ÏìIntel´ÓSkylakeÖÁIce LakeµÄËùÓд¦ÖÃÆ÷¡£¹¥»÷ÕßÀûÓøÃ©¶´¿ÉÒÔÇÔÈ¡ÊÜSGX±£»¤µÄÐÅÏ¢£¬SGXÊÇIntelÓ²¼þµÄÄÚ´æ¼ÓÃܼ¼Êõ£¬¿É½«ÄÚ´æ´úÂëºÍÊý¾ÝÓëϵͳÉϵÄÈí¼þÀ뿪¡£Ñо¿ÈËÔ±¼Æ»®ÔÚBlack Hat USA´ó»áÉÏ̸ÂÛDownfall©¶´ºÍ¹¥»÷¼¼Êõ¡£IntelÓÚÈ¥Äê8ÔÂÁ˽⵽¸Ã©¶´£¬²¢ÒÑÌṩ΢Âë¸üлº½â¸ÃÎÊÌ⣬»¹ÌṩÁË»ùÓÚÈí¼þµÄÁÙʱ½â¾ö·½°¸¡£
https://www.bleepingcomputer.com/news/security/new-downfall-attacks-on-intel-cpus-steal-encryption-keys-data/
4¡¢·¨¹úºÍºÉÀ¼µÄ¶à¸öÊÐÕþºÍ¹«¹²·þÎñÍøÕ¾Ôâµ½DDoS¹¥»÷
ýÌå8ÔÂ10ÈÕ±¨µÀ£¬NoName057(16)Éù³Æ¶Ô·¨¹úºÍºÉÀ¼¶à¸öÍøÕ¾Ôâµ½µÄ¹¥»÷ÂôÁ¦¡£¸ÃÍÅ»ï³Æ¹¥»÷Á˺ÉÀ¼¹«¹²½»Í¨ÍøÕ¾¡¢µ±µØÒøÐÐSNS¡¢¸ñÂÞÄþ¸ùº£¸ÛºÍ¸¥À¶¡¸ùÊÐÕþ¸®ÍøÕ¾¡£½ØÖÁĿǰ£¬ÕâÐ©ÍøÕ¾ÈÔÎÞ·¨·ÃÎÊ¡£ÔÚ·¨¹ú£¬ºÚ¿ÍÉù³Æ¹¥»÷ÁËÆäº£¹Ø²¿ÃÅ¡£¸Ã²¿ÃÅÌåÏÖ£¬ÓÉÓڼƻ®Öеġ°Î¬»¤»î¶¯¡±£¬ÍøÕ¾Òѹرա£¾Ý±¨µÀ£¬ÓÉÓÚÍøÂç¹¥»÷£¬·¨¹ú½ðÈÚ¼à¹Ü»ú¹¹µÄÍøÕ¾Ä¿Ç°Ò²ÎÞ·¨·ÃÎÊ£¬²¢ÏÔÊ¾ÍøÕ¾ÔÝʱÕýÔÚ½øÐÐά»¤¡£
https://therecord.media/prorussian-hackers-claim-attacks
5¡¢Insikt GroupÐû²¼¹ØÓÚRedHotelÍÅ»ïµÄ·ÖÎö³ÂËß
8ÔÂ8ÈÕ£¬Insikt GroupÐû²¼Á˹ØÓÚRedHotelÍÅ»ïµÄ·ÖÎö³ÂËß¡£×Ô2021ÄêÒÔÀ´£¬¸ÃÍŻ﹥»÷ÁËÑÇÖÞ¡¢Å·Ö޺ͱ±ÃÀµÄÖÁÉÙ17¸ö¹ú¼Ò£¬É漰ѧÊõ¡¢º½¿Õº½Ìì¡¢Õþ¸®¡¢Ã½Ìå¡¢µçÐźÍÑо¿ÐÐÒµ¡£Æ¾¾ÝĿǰÇ÷ÊÆ£¬RedHotelºÜ¿ÉÄÜͬʱ¼ç¸º×ÅÇ鱨ÊÕ¼¯ºÍ¾¼Ã¼äµýµÄÈÎÎñ¡£RedHotelÔËÓª×ÅÁ½¸ö²îÒìµÄ»ù´¡ÉèÊ©¼¯Èº£¬Ò»¸öÖ÷ÒªÓÃÓÚÕì²ìºÍ³õʼ·ÃÎÊ£¬ÁíÒ»¸öÓÃÓÚ±£³Ö¶ÔÄ¿±êµÄºã¾Ã·ÃÎÊ¡£¸ÃÍÅ»ïÖÁÉÙ×Ô2019Ä꿪ʼ»îÔ¾£¬ÀûÓÃÁ˹¥»÷¹¤¾ß£¨ÈçCobalt StrikeºÍBrute Ratel£©¡¢±ÕÔ´µ«¹²ÏíµÄ¹¦Ð§£¨ÈçShadowPadºÍWinnti£©ºÍ¶¨Öƹ¤¾ß£¨ÈçSpyderºÍFunnySwitch£©µÈ¡£
https://go.recordedfuture.com/hubfs/reports/cta-2023-0808.pdf
6¡¢CrowdStrikeÐû²¼2023ÄêÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß
¾Ý8ÔÂ8ÈÕ±¨µÀ£¬CrowdStrikeÐû²¼ÁË2023ÄêÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß¡£³ÂËß»ùÓÚ2022Äê7ÔÂÖÁ2023Äê6ÔÂÊÕ¼¯µÄÊý¾Ý£¬º¸ÇÉæ¼°Éí·ÝÍþв¡¢ºÚ¿ÍÍÅ»ïµÄ¼¼ÊõºÍ¼ÆÄ±¡¢LinuxºÍmacOS¼û½âºÍÇ÷ÊÆµÈ·½Ãæ¡£62%µÄ½»»¥Ê½ÈëÇÖÉæ¼°ÓÐЧÕË»§µÄÀûÓã¬34%µÄÈëÇÖÉæ¼°Ê¹ÓÃÓòÕË»§»òĬÈÏÕË»§¡£ÓëÉí·ÝÍþвÏà¹ØµÄ×î´óÔö·ù·ºÆðÔÚKerberoasting¹¥»÷ÖУ¬Ôö¼ÓÁË583%¡£½»»¥Ê½¹¥»÷ʼþͬ±ÈÔö³¤ÁË40%£¬ÆäÖм¼ÊõÐÐÒµÁ¬ÐøµÚÁùÄê³ÉΪ×îÒ×±»¹¥»÷µÄÄ¿±ê¡£ºÏ·¨Ô¶³Ì¼à¿ØºÍ¹ÜÀí(RMM)¹¤¾ßµÄʹÓÃÁ¿Ôö¼ÓÁË300%ÒÔÉÏ¡£
https://go.crowdstrike.com/rs/281-OBQ-266/images/report-crowdstrike-2023-threat-hunting-report.pdf