ºÚ¿ÍÕë¶Ô FCC ºÍ¼ÓÃÜ»õ±Ò¹«Ë¾Ìᳫ¸ß¼¶ Okta ÍøÂçµöÓã¹¥»÷

Ðû²¼Ê±¼ä 2024-03-04
1. ºÚ¿ÍÕë¶Ô FCC ºÍ¼ÓÃÜ»õ±Ò¹«Ë¾Ìᳫ¸ß¼¶ Okta ÍøÂçµöÓã¹¥»÷


3ÔÂ2ÈÕ£¬Ò»ÖÖÃûΪ CryptoChameleon µÄÐÂÍøÂçµöÓ㹤¾ß°ü±»ÓÃÓÚÕë¶ÔÁª°îͨÐÅίԱ»á (FCC) Ô±¹¤£¬¸Ã¹¤¾ß°üʹÓÃרÃÅΪ Okta ÖÆ×÷µÄµ¥µãµÇ¼ (SSO) Ò³Ãæ£¬ÕâÐ©Ò³ÃæÓëÔ­Ê¼Ò³Ãæ·Ç³£ÏàËÆ¡£¸Ã»î¶¯»¹Õë¶Ô Binance¡¢Coinbase¡¢Kraken ºÍ Gemini µÈ¼ÓÃÜ»õ±Òƽ̨µÄÓû§ºÍÔ±¹¤£¬Ê¹ÓÃð³ä Okta¡¢Gmail¡¢iCloud¡¢Outlook¡¢Twitter¡¢Yahoo ºÍ AOL µÄÍøÂçµöÓãÒ³Ãæ¡£¹¥»÷Õß¾«ÐijïıÁËÅÓ´óµÄÍøÂçµöÓãºÍÉç»á¹¤³Ì¹¥»÷£¬°üÂÞµç×ÓÓʼþ¡¢¶ÌÐźÍÓïÒôÍøÂçµöÓ㣬ÒÔÆÛÆ­Êܺ¦ÕßÔÚÍøÂçµöÓãÒ³ÃæÉÏÊäÈëÃô¸ÐÐÅÏ¢£¬ÀýÈçÓû§Ãû¡¢ÃÜÂ룬ÔÚijЩÇé¿öÏÂÉõÖÁ°üÂÞ´øÕÕÆ¬µÄÉí·ÝÖ¤¼þ¡£LookoutÑо¿ÈËÔ±·¢ÏÖµÄÍøÂçµöÓã²Ù×÷ ÓëScattered SpiderºÚ¿Í×éÖ¯ÔÚ 2022 Äê ½øÐÐµÄ Oktapus »î¶¯ ÀàËÆ  £¬µ«Ã»ÓÐ×ã¹»µÄÖ¤¾ÝÖ¤Ã÷Æä¹éÊô¡£


https://www.bleepingcomputer.com/news/security/hackers-target-fcc-crypto-firms-in-advanced-okta-phishing-attacks/


2. ÃÀ¹úÍøÂçºÍÖ´·¨»ú¹¹¶Ô PHOBOS ÀÕË÷Èí¼þ¹¥»÷·¢³ö¾¯¸æ


3ÔÂ2ÈÕ£¬ÃÀ¹ú CISA¡¢FBI ºÍ MS-ISAC Ðû²¼ÁªºÏÍøÂçÄþ¾²Í¨¸æ (CSA)£¬¾¯¸æÉæ¼°Backmydata¡¢Devos¡¢Eight¡¢Elking ºÍ Faust µÈPhobos ÀÕË÷Èí¼þ±äÖֵĹ¥»÷¡£ÕâЩ¹¥»÷×î½ü·¢ÉúÔÚ 2024 Äê 2 Ô£¬Ä¿±êÊÇÕþ¸®¡¢½ÌÓý¡¢½ô¼±·þÎñ¡¢Ò½ÁƱ£½¡ºÍÆäËûÒªº¦»ù´¡ÉèÊ©²¿ÃÅ¡£Phobos ²Ù×÷½ÓÄÉÀÕË÷Èí¼þ¼´·þÎñ (RaaS) ģʽ£¬×Ô 2019 Äê 5 ÔÂÒÔÀ´Ò»Ö±»îÔ¾¡£Æ¾¾Ý¹ûÈ»À´Ô´µÄÐÅÏ¢£¬ÓÉÓÚÊӲ쵽սÊõ¡¢¼¼ÊõºÍ·¨Ê½ (TTP) ·½ÃæµÄÏàËÆÐÔ£¬Õþ¸®×¨¼Ò½«¶à¸ö Phobos ÀÕË÷Èí¼þ±äÌåÓë Phobos ÈëÇÖÁªÏµÆðÀ´¡£Phobos ÈëÇÖ»¹É漰ʹÓÃÖÖÖÖ¿ªÔ´¹¤¾ß£¬°üÂÞ Smokeloader¡¢Cobalt StrikeºÍ Bloodhound¡£ÕâЩ¹¤¾ßÔÚ²îÒìµÄ²Ù×÷»·¾³Öй㷺¿ÉÓÃÇÒÓû§ÓѺã¬ÓÐÖúÓÚ Phobos ¼°ÆäÏà¹Ø±äÌåÔÚÖÖÖÖÍþв¼ÓÈëÕßÖеÄÁ÷ÐС£¾ÝÊӲ죬Phobos ¹¥»÷±³ºóµÄÍþв¼ÓÈëÕßͨ¹ýÀûÓÃÍøÂçµöÓã»î¶¯»ñµÃÁ˶ÔÒ×Êܹ¥»÷ÍøÂçµÄ³õʼ·ÃÎÊȨÏÞ¡£ËûÃÇÅׯúÒþ²ØµÄÓÐЧ¸ºÔØ»òʹÓû¥ÁªÍøÐ­Òé (IP) ɨÃ蹤¾ß£¨ÀýÈç Angry IP Scanner£©À´ËÑË÷Ò×Êܹ¥»÷µÄÔ¶³Ì×ÀÃæÐ­Òé (RDP) ¶Ë¿Ú»òÔÚ Microsoft Windows »·¾³ÖÐÀûÓà RDP¡£Phobos ʹÓà Windows Æô¶¯Îļþ¼ÐºÍÔËÐÐ×¢²á±íÏîÔÚÊÜѬȾµÄ»·¾³Öб£³Ö³Ö¾ÃÐÔ¡£Íþв¼ÓÈëÕßʹÓà Bloodhound¡¢Sharphound¡¢Mimikatz¡¢NirSoft ºÍ Remote Desktop Passview µÈ¿ªÔ´¹¤¾ßÀ´Ã¶¾Ù»î¶¯Ä¿Â¼²¢ÊÕ¼¯Æ¾¾Ý¡£Phobos ÔËÓªÉÌʹÓà WinSCP ºÍ Mega.io ½«Êý¾Ýй¶µ½ FTP ·þÎñÆ÷»òÔÆ´æ´¢¡£


https://securityaffairs.com/159822/cyber-crime/cisa-phobos-ransomware-attacks.html


3. CutOut.Pro AI¹¤¾ßÊý¾Ýй¶£¬ºÚ¿Íй¶2000ÍòÓû§ÐÅÏ¢


3ÔÂ2ÈÕ£¬CutOut.Pro ÊÇÒ»¸öרÃÅ´ÓÊÂͼÏñºÍÊÓÆµ±à¼­µÄÈ˹¤ÖÇÄÜÆ½Ì¨£¬ÓÚ 2024 Äê 2 Ô 27 ÈÕÃæÁÙºÚ¿ÍÉù³ÆµÄÊý¾Ýй¶¡£Ò»Ãû×Ô³Æ KryptonZambie µÄÈËͦÉí¶ø³ö£¬Éù³ÆËûÃÇÒѾ­Àֳɹ¥ÆÆÁË CutOut.Pro£¬ÕâÊÇÒ»¼Ò×ܲ¿Î»ÓÚÐÂ¼ÓÆÂµÄÆ½Ì¨£¬ÒÔÆäÈ˹¤ÖÇÄÜÇý¶¯µÄ¹¤¾ß¶øÎÅÃû£¬ÊʺÏÊÓ¾õÉè¼ÆºÍÄÚÈÝ´´×÷£¬ÌرðÊÇÔÚͼÏñºÍÊÓÆµ±à¼­ÁìÓò¡£½ñºó´Îй¶ÖÐÌáÈ¡µÄÊý¾ÝÒÑÔÚÎÛÃûÕÑÖøµÄÍøÂç·¸×ïºÍºÚ¿ÍÂÛ̳£¨°üÂÞBreach Forums £©ÉÏй¶£¬Ä¿Ç°ÕýÔÚ¶íÓïÂÛ̳ÖÐÁ÷´«¡£¶ÔÓÚй¶Êý¾ÝµÄÄÚÈÝ£¬Hackread.comÉîÈë·ÖÎö·¢ÏÖ£¬¼Ç¼°üÂÞÒÔÏÂÐÅÏ¢£ºÈ«Ãû¡¢IPµØÖ·¡¢µç×ÓÓʼþµØÖ·¡¢ÃÜÂë¹þÏ£Öµ¡¢ºÍÕÊ»§×¢²áÊý¾Ý¡£ÓëºÚ¿ÍÔÚÁбíÖеÄ˵·¨Ïà·´£¬Hackread ½øÐеķÖÎö±íÃ÷£¬Ð¹Â¶µÄÊý¾Ý²»°üÂ޵绰ºÅÂë¡¢API ·ÃÎÊȨÏÞ»òÓ¦Ó÷¨Ê½ÃÜÔ¿¡£Õâ²¢²»ÊÇ CutOut.Pro µÚÒ»´ÎÒòΪ´íÎóµÄÔ­Òò³ÉΪͷÌõÐÂÎÅ¡£2023 Äê 2 Ô£¬ËûÃǵÄһ̨ Elasticsearch ·þÎñÆ÷й¶Á˸ߴï 9 GB µÄ¿Í»§Êý¾Ý¡£ÕâЩÊý¾ÝÖÐÓÐÁè¼Ý 2200 ÍòÌõÈÕÖ¾ÌõÄ¿£¬ÆäÖÐÌáµ½Á˸öÈËÓû§ºÍÆóÒµÕÊ»§µÄÓû§Ãû¡£


https://www.hackread.com/hacker-cutout-pro-ai-tool-data-breach/


4. ÕÛ¿ÛÁãÊÛ¾ÞÍ· Pepco ÒòÍøÂç·¸×ï·Ö×ÓËðʧ 1500 ÍòÅ·Ôª


2ÔÂ29ÈÕ£¬Õâ¼Ò×ܲ¿Î»ÓÚÓ¢¹úµÄ¹«Ë¾³ÂË߳ƣ¬ÓÉÓÚ¡°ÅÓ´óµÄÆÛÕ©ÐÔÍøÂçµöÓã¹¥»÷¡±£¬ËðʧÁË 1550 ÍòÅ·Ôª£¨Ô¼ºÏ 1680 ÍòÃÀÔª£©µÄÏÖ½ð¡£ÊÓ²ìÒѾ­Æô¶¯£¬Pepco ÕýÔÚÓëÒøÐк;¯·½ºÏ×÷×·»ØÕâ±Ê×ʽ𣬵«¸Ã¹«Ë¾ÌåÏÖ£¬Ä¿Ç°Éв»Çå³þÊÇ·ñ¿ÉÒÔ×·»Ø×ʽð¡£Pepco ¼¯ÍÅÌåÏÖ£º¡°Ïֽ׶Σ¬¸ÃʼþËÆºõ²¢Î´Éæ¼°Èκοͻ§¡¢¹©Ó¦ÉÌ»òͬʵÄÐÅÏ¢»òÊý¾Ý¡£¡±Pepco ¼¯ÍÅÓµÓÐ Pepco¡¢Dealz ºÍ Poundland Æ·ÅÆ¡£Pepco µÄ 3,600 ¼ÒÃŵê±é²¼ 19 ¸öÅ·ÖÞ¹ú¼Ò£¬Ã¿ÔÂÓµÓÐÁè¼Ý 3000 ÍòÖ÷¹Ë¡£Æ¾¾Ý¸Ã¹«Ë¾¶ÔʼþµÄ¼òÒªÃèÊöºÍËðʧ½ð¶î£¬¸Ã¹«Ë¾¿ÉÄÜÊÇÉÌÒµµç×ÓÓʼþй¶ (BEC) ¼Æ»®µÄÄ¿±ê£¬Ôڸüƻ®ÖУ¬ÍøÂç·¸×ï·Ö×ÓʹÓñ»ºÚ¿ÍÈëÇֵĵç×ÓÓʼþÕÊ»§À´ÓÕÆ­Ä¿±ê×éÖ¯µÄÔ±¹¤½«×ʽðתÈëËûÃǵÄÒøÐÐÕË»§¿ØÖÆ¡£


https://www.securityweek.com/discount-retail-giant-pepco-loses-e15-million-to-cybercriminals/


5. Ð嵀 Silver SAML ¹¥»÷¿É¹æ±ÜÉí·ÝϵͳÖÐµÄ Golden SAML ·ÀÓù


2ÔÂ29ÈÕ£¬ÍøÂçÄþ¾²Ñо¿ÈËÔ±Åû¶ÁËÒ»ÖÖÃûΪSilver SAMLµÄй¥»÷¼¼Êõ£¬¼´Ê¹ÔÚÕë¶Ô Golden SAML ¹¥»÷½ÓÄÉ»º½â´ëÊ©µÄÇé¿öÏ£¬¸Ã¼¼ÊõÒ²ÄÜÀֳɡ£Semperis Ñо¿ÈËÔ± Tomer Nahum ºÍ Eric Woodruff ÔÚÓë The Hacker News ·ÖÏíµÄÒ»·Ý³ÂËßÖÐÌåÏÖ£¬Silver SAML¡°Ê¹µÃ Entra ID µÈÉí·ÝÌṩÉÌÄܹ»ÀûÓà SAML ¶ÔÅäÖÃΪʹÓà SAML ½øÐÐÉí·ÝÑéÖ¤µÄÓ¦Ó÷¨Ê½£¨ÀýÈç Salesforce£©Ìᳫ¹¥»÷¡± ¡£Golden SAML£¨Äþ¾²¶ÏÑÔ±êÖ¾ÓïÑÔµÄËõд£©ÓÉ Cyber Ark ÓÚ 2017 ÄêÊ״μǼ¡£¼ò¶øÑÔÖ®£¬¸Ã¹¥»÷ý½éÐèÒªÀÄÓÿɻ¥²Ù×÷µÄÉí·ÝÑéÖ¤³ß¶ÈÀ´Ã°³ä×éÖ¯Öеļ¸ºõÈκÎÉí·Ý¡£ËüÒ²ÀàËÆÓÚ½ðÆ±¹¥»÷£¬ÒòΪËüʹ¹¥»÷ÕßÄܹ»ÒÔÈκÎȨÏÞδ¾­ÊÚȨµØ·ÃÎÊÁªºÏÖеÄÈκηþÎñ£¬²¢ÒÔÒþÃØµÄ·½Ê½Ôڸû·¾³Öб£³Ö³Ö¾ÃÐÔ¡£ÀûÓøÃÒªÁìµÄÏÖʵ¹¥»÷ºÜÉÙ¼û£¬µÚÒ»¸ö ÓмǼµÄ¹¥»÷ÊÇͨ¹ýʹÓÃÊÜËðµÄ SAML ÁîÅÆÇ©ÃûÖ¤ÊéαÔì SAML ÁîÅÆÀ´Ë𺦠SolarWinds »ù´¡ÉèÊ©£¬´Ó¶ø»ñµÃ¹ÜÀí·ÃÎÊȨÏÞ ¡£Î¢ÈíÔÚ 2023 Äê 9 ÔÂ͸¶£¬Golden SAML »¹±»´úºÅΪPeach SandstormµÄÒÁÀÊÍþвÐÐΪÕßÔÚ 2023 Äê 3 ÔµÄÒ»´ÎÈëÇÖÖÐÎäÆ÷»¯£¬ÎÞÐèÈκÎÃÜÂë¼´¿É·ÃÎÊδÃüÃûÄ¿±êµÄÔÆ×ÊÔ´¡£


https://thehackernews.com/2024/02/new-silver-saml-attack-evades-golden.html


6. ÂÉʦÊÂÎñËùHouser LLP³ÂËßÊý¾Ýй¶ӰÏìÁè¼Ý 325000 ÈË


2ÔÂ29ÈÕ£¬×¨ÃÅΪ֪Ãû½ðÈÚ»ú¹¹Ìṩ·þÎñµÄÃÀ¹úÂÉʦÊÂÎñËù Houser LLP ÌåÏÖ£¬2023 Äê 5 Ô·¢ÏÖµÄÒ»´Îϵͳ©¶´Ì»Â¶ÁËÁè¼Ý 325,000 È˵ĸöÈËÊý¾Ý£¬¿ÉÄܰüÂÞÐÅÓÿ¨ºÅµÈÃô¸ÐÐÅÏ¢¡£ÔÚÃåÒòÖÝ×ܼì²ì³¤ÖÜÈýÐû²¼µÄÒ»·Ý¼à¹ÜÎļþÖУ¬¸Ã¹«Ë¾ÌåÏÖ£¬Ä³Ð©ÎļþÔÚʼþÆÚ¼ä±»¼ÓÃÜ£¬²¢¡°´ÓÍøÂçÖи´ÖƺͻñÈ¡¡±¡£ºÀɪ˵£¬ÕâЩÊý¾Ý°üÂÞÐÕÃû¡°ÒÔ¼°Éç»áÄþ¾²ºÅÂë¡¢¼ÝʻִÕÕºÅÂë¡¢¸öÈËÄÉ˰ʶ±ðºÅÂë¡¢½ðÈÚÕË»§ÐÅÏ¢ºÍÒ½ÁÆÐÅÏ¢ÖеÄÒ»Ïî»ò¶àÏ¡£¸Ã¹«Ë¾»¹Ïò¼ÓÖÝ×ܼì²ì³¤Ìá½»ÁË֪ͨ¡£¸Ã¹«Ë¾ÌåÏÖ£¬Ò»¼Òδ¾ßÌå˵Ã÷µÄµÚÈý·½¹«Ë¾ºóÀ´È·¶¨£¬5 Ô 7 ÈÕÖÁ 9 ÈÕÆÚ¼ä£¬Houser µÄÍøÂç´æÔÚ¡°Î´¾­ÊÚȨµÄ·ÃÎÊ¡±¡£¼à¹ÜÎļþ³Æ£¬ºÀɪºÜ¿ì¾ÍÓë¹¥»÷ÕßÈ¡µÃÁËÁªÏµ£¬µ«Ã»ÓнâÊÍͨÐŵÄÐÔÖÊ¡£Recorded Future News ÒÑÁªÏµ¸Ã¹«Ë¾ÒÔ»ñÈ¡¸ü¶àÐÅÏ¢¡£¸Ã¹«Ë¾ÌåÏÖ£¬ÔÚ 2023 Äê 6 ÔµÄij¸öʱºò£¬¡°Î´¾­ÊÚȨµÄÐÐΪÕß֪ͨ Houser£¬ËûÃÇɾ³ýÁËÈκα»µÁÊý¾ÝµÄ¸±±¾£¬¶øÇÒ²»»á·Ö·¢Èκα»µÁÎļþ¡±¡£Îļþ³Æ£¬µÚÈý·½¹©Ó¦ÉÌÓÚ½ñÄê 1 Ô 18 ÈÕÍê³ÉÁËÉó²é¡£


https://therecord.media/houser-law-firm-reports-data-breach