°®¶ûÀ¼¹ú¼Ò¾¯¾ÖµÄ³Ð°üÉÌй¶50ÍòÌõ¿ÛѺ³µÁ¾µÄ¼Ç¼
Ðû²¼Ê±¼ä 2023-10-251¡¢°®¶ûÀ¼¹ú¼Ò¾¯¾ÖµÄ³Ð°üÉÌй¶50ÍòÌõ¿ÛѺ³µÁ¾µÄ¼Ç¼
¾Ý10ÔÂ23ÈÕ±¨µÀ£¬Ñо¿ÈËÔ±·¢ÏÖÁËÒ»¸ö¹ûÈ»µÄÊý¾Ý¿â£¬°üÂÞÁè¼Ý50ÍòÌõÓë°®¶ûÀ¼¹ú¼Ò¾¯¾ÖGarda S¨ªoch¨¢na¿ÛѺ³µÁ¾Ïà¹ØµÄ¼Ç¼¡£Îĵµ×ÜÊýΪ521043¸ö£¬¾ÞϸΪ271.8 GB¡£Æ¾¾Ý°®¶ûÀ¼Ö´·¨£¬µ±³µÁ¾±»¿ÛѺʱ£¬³µÖ÷Ðë³öʾÉí·ÝÖ¤Ã÷ºÍ±£ÏÕÎļþµÈ¶à·ÝÎļþ£¬Òò´Ëй¶µÄ50Íò·ÝÎĵµ¿ÉÄÜÓ°ÏìÁËÔ¼15ÍòÃû³µÖ÷¡£½øÒ»·¨Ê½²éÏÔʾ£¬¸ÃÊý¾Ý¿âÊôÓÚ°®¶ûÀ¼ÀûĬÀï¿ËµÄÒ»¼Ò˽È˼¼Êõ³Ð°üÉÌ¡£Ä¿Ç°£¬Ð¹Â¶Êý¾ÝÒѱ»±£»¤ÆðÀ´¡£
https://www.hackread.com/contractor-data-breach-irish-national-police-vehicle-seizure/
2¡¢ºÚ¿ÍÒÔ8ÍòÃÀÔª¼Û¸ñ³öÊÛ8.15ÒÚÌõÓ¡¶È¹«ÃñµÄPII¼Ç¼
ýÌå10ÔÂ24Èճƣ¬ºÚ¿ÍÔÚ°µÍø³öÊÛÊýÒÚÌõÓ¡¶È¹«ÃñµÄPII¼Ç¼£¬°üÂÞAadhaar¿¨¡£AadhaarÊÇÒ»¸ö12λµÄ¸öÈËʶ±ðÂ룬ÓÉÓ¡¶ÈΨһÉí·Ýʶ±ð»ú¹¹´ú±íÓ¡¶ÈÕþ¸®·¢±í¡£10ÔÂ9ÈÕ£¬ÃûΪpwn0001µÄºÚ¿ÍÔÚ°µÍøÐû²¼ÁËÒ»¸öÌû×Ó£¬³ÆÓµÓÐ8.15ÒÚÓ¡¶È¹«ÃñAadhaarºÍ»¤ÕռǼ£¬²¢Ô¸ÒâÒÔ80000ÃÀÔªµÄ¼Û¸ñ³öÊÛÕû¸öÊý¾Ý¿â¡£Í¬Ê±£¬pwn0001»¹¹ûÈ»ÁË4¸öÑù±¾£¬ÆäÖÐÒ»¸öÑù±¾°üÂÞ100000ÌõÓ¡¶È¾ÓÃñµÄPII¡£
https://securityaffairs.com/152957/security/pii-indian-citizens-dark-web.html
3¡¢BHI EnergyÏêÊöAkiraÈçºÎÈëÇÖÆäϵͳ²¢ÇÔÈ¡Êý¾Ý
¾ÝýÌå10ÔÂ23ÈÕ±¨µÀ£¬ÃÀ¹úÄÜÔ´¹«Ë¾BHI EnergyÅû¶ÁËAkiraÔÚ5ÔÂ30ÈÕÈëÇÖÆäϵͳµÄÏêϸÐÅÏ¢¡£AkiraʹÓÃÇÔÈ¡µÄµÚÈý·½µÄVPNƾ֤·ÃÎÊBGIµÄÄÚÍø£¬ÔÚÊ״ηÃÎʺóµÄÒ»ÖÜÄÚʹÓÃͬһ¸öÕË»§¶ÔÄÚÍø½øÐÐÕì²ì¡£6ÔÂ16ÈÕ£¬AkiraÔٴηÃÎÊϵͳ£¬ÁоÙÊý¾Ý£¬²¢ÔÚ6ÔÂ20ÈÕÖÁ29ÈÕÇÔÈ¡ÁË767k¸öÎļþ£¬¹²690 GB£¬°üÂÞWindows Active DirectoryÊý¾Ý¿â¡£×îºó£¬¹¥»÷ÕßÓÚ6ÔÂ29ÈÕÇÔÈ¡ÁËÈ«²¿Êý¾Ýºó£¬ÔÚËùÓÐÉ豸Éϰ²×°ÁËAkiraÀÕË÷Èí¼þÀ´¼ÓÃÜÎļþ¡£Õâʱ£¬BHI²ÅÒâʶµ½¹«Ë¾Òѱ»ÈëÇÖ¡£
https://www.bleepingcomputer.com/news/security/us-energy-firm-shares-how-akira-ransomware-hacked-its-systems/
4¡¢Î÷°àÑÀ¾¯·½µ·»ÙÄ³ÍøÂçÕ©ÆÍŻﲢ´þ²¶34ÃûÏÓÒÉÈË
10ÔÂ24ÈÕ±¨µÀ£¬Î÷°àÑÀ¹ú¼Ò¾¯²ì¾Öµ·»ÙÁËÒ»¸öÍøÂç·¸×ïÍŻ¸ÃÍÅ»ïÖ´ÐÐÖÖÖÖ¼ÆËã»úÕ©Æ£¬ÇÔÈ¡ÁËÁè¼Ý400ÍòÈ˵ÄÊý¾Ý£¬×¬È¡ÁËÔ¼300ÍòÅ·Ôª¡£Ö´·¨²¿ÃÅÔÚÂíµÂÀï¡¢ÂíÀ¼Ó¡¢Î¤¶ûÍß¡¢°¢Àû¿²ÌغÍĶûÎ÷ÑǽøÐÐÁË16´ÎÓÐÕë¶ÔÐÔµÄËѲ飬ÒÑ´þ²¶34Ãû·¸×ïÍÅ»ïµÄ³ÉÔ±¡£¾¯·½³Æ£¬±»²¶ÕßÓëð³ä¿ìµÝ¹«Ë¾ºÍµçÁ¦¹©Ó¦É̵ĵöÓã»î¶¯Óйء£¸ÃÍÅ»ïµÄÍ·Ä¿Òѱ»´þ²¶£¬¶ÔÆäËû³ÉÔ±Éí·ÝµÄÊÓ²ìÈÔÔÚ½øÐÐÖС£
https://securityaffairs.com/152946/cyber-crime/spanish-police-dismantled-cybercriminal-group.html
5¡¢Ñо¿ÈËÔ±Ðû²¼VMwarev©¶´CVE-2023-34051µÄPoC
ýÌå10ÔÂ24Èճƣ¬VMwarevÌáÐÑvRealize Log Insight£¨ÏÖ³ÆÎªVMware Aria Operations for Logs£©ÖЩ¶´µÄPoCÒÑÐû²¼¡£ÕâÊÇÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ý©¶´£¨CVE-2023-34051£©£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔ½«Îļþ×¢ÈëÄ¿±êϵͳÖУ¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£Horizon3Ðû²¼ÁËPoC£¬ËüÀûÓÃIPµØÖ·ÆÛƺÍÖÖÖÖThrift RPC¶ËµãÀ´ÊµÏÖÈÎÒâÎļþдÈë¡£Ñо¿ÈËÔ±½¨ÒéÁ¢¼´°²×°¸üС£
https://www.bleepingcomputer.com/news/security/vmware-warns-admins-of-public-exploit-for-vrealize-rce-flaw/
6¡¢KasperskyÐû²¼Triangulation»î¶¯µÄÒþ±ÎÐԵijÂËß
10ÔÂ23ÈÕ£¬KasperskyÐû²¼Á˹ØÓÚTriangulation»î¶¯µÄÒþ±ÎÐԵķÖÎö³ÂËß¡£¸Ã³ÂËß½éÉÜÁ˴˴ι¥»÷µÄÖÖÖÖÒþÐμ¼Êõ£¬ÒÔ¼°¹¥»÷ÖÐʹÓõÄ×é¼þ¡£ÔÚ²¿ÊðTriangleDB֮ǰ£¬»áʹÓÃÁ½¸öÑéÖ¤Æ÷À´ÊÕ¼¯É豸ÐÅÏ¢£¬²¢È·±£´úÂë²»»áÔÚ·ÖÎö»·¾³ÖÐÖ´ÐС£Ëü»¹°üÂÞÒ»¸öÂó¿Ë·ç¼ÒôÄ£¿émsu3h£¬Ä¬ÈÏ¿ÉÒÔ¼ÒôÈý¸öСʱ£¬µ«Èç¹ûµçÁ¿µÍÓÚ10%ÇÒÉ豸ÆÁÄ»ÕýÔÚʹÓý«ÔÝͣ¼Òô¡£¹¥»÷Õß»¹ÊµÊ©ÁËÌØ±ðµÄÔ¿³×´®Ð¹Â¶Ä£¿é¡¢SQLiteÊý¾Ý¿âÇÔÈ¡¹¦Ð§ÒÔ¼°Î»ÖÃ¼à¿ØÄ£¿é£¨ÔÚGPS²»ÐÐÓÃʱʹÓÃÍøÂçÔªÊý¾Ý£©¡£
https://securelist.com/triangulation-validators-modules/110847/