ÃÀ·¨ÔºÊÚȨ΢ÈíÊÕÊܳ¯ÏÊAPT37½ÚÔìµÄ50¸öÓòÃû£»haveibeenpwnedÊÕ¼Factualй¶µÄ250ÍòÓû§Êý¾Ý

°ä²¼¹¦·ò 2019-12-31

1.ÃÀ¹ú¹ÜÕÊʦÊÂÎñËùMoss AdamsÔâºÚ¿ÍÈëÇÖ£¬¿Í»§Êý¾Ý±»µÁ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾




ÃÀ¹ú×î´óµÄ¹«¹²¹ÜÕÊʦÊÂÎñËùÖ®Ò»Moss AdamsÅû¶Êý¾Ýй¶ÊÂÎñ£¬¾ßÌåÀ´Ëµ£¬ºÚ¿ÍÓÚ2019Äê10ÔÂ10Èճɹ¦ÊÕÊÜÁËÒ»ÃûÔ±¹¤µÄµç×ÓÓÊÏäÕË»§£¬²¢½Ó¼ûÁËÔ̺¬¿Í»§ÐÕÃûºÍÉç»á°²È«ºÅÂëÔÚÄÚµÄÃô¸ÐÐÅÏ¢£¨PII£© ¡£Æ¾¾Ý¸Ã¹«Ë¾°ä²¼µÄÊý¾Ýй¶֪ͨ£¬Ã»ÓÐÆäËüÐÅÏ¢Êܵ½Ó°Ï죬ºÚ¿ÍҲûÓнӼû¹«Ë¾µÄÄÚ²¿ÍøÂç ¡£¸Ã¹«Ë¾Ã»ÓÐÅû¶ÊÜÓ°Ïì¼òÖ±ÇÐÈËÊý£¬Ò²¿ÉÄÜÊǸÃÊý×ÖÉÐδȷ¶¨ ¡£¸Ã¹«Ë¾°µÊ¾ÒѲÉÈ¡Êʵ±µÄ°²È«ºÍ·þÎñ¸´Ô­²½Ö裬²¢ÎªÊÜÓ°ÏìµÄ¿Í»§ÆôÓÃÉí·Ý͵ÇÔ±£ÏÕ´òËã ¡£


Ô­ÎÄÁ´½Ó£º

https://www.technadu.com/moss-adams-discloses-data-breach-exposing-names-social-security-numbers/88684/



2.haveibeenpwnedÊÕ¼Factualй¶µÄ250ÍòÓû§Êý¾Ý


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



haveibeenpwnedÍøÕ¾ÊÕ¼ÁËFactualй¶µÄ250ÍòÓû§Êý¾Ý£¬¾Ý³ÆÕâЩÊý¾ÝµÄй¶ÈÕÆÚΪ2017Äê3ÔÂ22ÈÕ£¬Ô­Ê¼Êý¾Ý¼¯¹²Ô̺¬800ÍòÐÐÊý¾Ý£¬µ«È¥³ÁºóΪԼ250Íò£¨2461696£©£¬Êý¾ÝÔ̺¬Óû§µÄµç×ÓÓʼþµØÖ·¡¢¹«Ë¾Ãû³Æ¡¢µØÖ·ºÍµç»°ºÅÂë ¡£Factual»ØÓ¦³ÆÕâЩÊý¾ÝÊÇÓëóÒ×ºÍÆäËüÐËÖµãÓйصĹ«¿ªÊý¾Ý ¡£


Ô­ÎÄÁ´½Ó£º

https://haveibeenpwned.com/PwnedWebsites#Factual



3.HelloTech¹«Ë¾Òâ±íй¶²¿ÃųаüÉÌÒþÖÔÐÅÏ¢


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾




HelloTech¹«Ë¾°ä²¼Êý¾Ýй¶֪ͨ³Æ£¬¸Ã¹«Ë¾²¿ÃŶÀÁ¢³Ð°üÉ̵ÄÃô¸ÐÐÅÏ¢±»Òâ±í°ä²¼ÔÚ¹«ÍøÉÏ£¬¸Ã¹«Ë¾ÔÚ½Óµ½»ã±¨ºóÂíÉ϶ÔÕâЩÊý¾Ý²ÉÈ¡Á˱£»¤´ëÊ©£¬µ«²»ÄÜÈ·¶¨ËüÃÇÊÇ·ñÒÑÔâ½Ó¼û ¡£¸ÃÊÂÎñ²úÉúÔÚ11ÔÂ15ÈÕ£¬¿ÉÄÜй¶µÄÊý¾ÝÔ̺¬ÐÕÃû¡¢µØÖ·¡¢¼ÝÕÕÐÅÏ¢¡¢ÕÕÆ¬µÈ£¬µ«²»Ô̺¬ÈκÎÉç»á°²È«ºÅÂëºÍ²ÆÕþÐÅÏ¢ ¡£¸Ã¹«Ë¾Î´Ð¹Â©ÊÜÓ°ÏìµÄ¾ßÌåÈËÊý£¬µ«°µÊ¾½«ÎªÊÜÓ°ÏìµÄÈËÌṩһÄêµÄÃâ·ÑÐÅÓþ¼à¿Ø·þÎñ ¡£


Ô­ÎÄÁ´½Ó£º

https://oag.ca.gov/system/files/General%20Notice%20Z507_v02.PDF



4.Lumber LiquidatorsÔâÀÕË÷Èí¼þ¹¥»÷£¬ÊÕÈëËðʧ´ï800ÍòÃÀÔª


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



Lumber Liquidators¹«Ë¾ÔÚ8ÔÂ21ÈÕÔâµ½¶ñÒâÈí¼þ¹¥»÷£¬ÆäÍÆËã»úϵͳ¹Ø¹Ø ¡£¸Ã¹«Ë¾µÄÁãÊÛÔ±¹¤ÎÞ·¨²é¿´²úÆ·¼ÛÖµ»ò¿â´æ£¬ËûÃDZØÐëͨ¹ýµç»°»ò´ÓÆäÓ×ÎÒµç×ÓÓʼþÕÊ»§ÏòÅäËÍÖÐÐÄ·¢ËͶ©µ¥£¬²¢ÔÚÖ½Éϼͼ¿Í»§µÄÐÅÓþ¿¨ÐÅÏ¢£¬Ã¿´ÎÂòÂô×î¶àÆÆ·Ñ°ëÓ×ʱµÄ¹¦·ò ¡£¸Ã¹«Ë¾ÔÚ11Ôµĵ÷²éÎļþÖаµÊ¾£¬Õâ´Î¹¥»÷Ô¤¼ÆÔì³ÉÁË600ÍòÖÁ800ÍòÃÀÔªµÄÊÕÈëËðʧ ¡£



Ô­ÎÄÁ´½Ó£º

https://www.salon.com/2019/12/29/like-voldemort-ransomware-is-too-scary-to-be-named_partner/



5.×êÑÐÍŶӰ䲼APT×éÖ¯BRONZE PRESIDENTµÄ·ÖÎö»ã±¨


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



SecureworksÍþвµý±¨ÖÐÐİ䲼¹ØÓÚAPT×éÖ¯BRONZE PRESIDENTµÄ·ÖÎö»ã±¨ ¡£BRONZE PRESIDENTÖØÒªÕë¶Ô·Çµ±¾Ö×éÖ¯ºÍÄÏÑǼ°¶«Ñǹú¶ÈÈ·µ±¾ÖºÍ·¨ÂÉ»ú¹¹£¬¸Ã×éÖ¯¿ª·¢ÁË×Ô¼ºµÄÔ¶¿Ø¹¤¾ß£¬²¢Ê¹ÓöàÖÖ¹«¿ª¿ÉÓõŤ¾ß¼¯ ¡£×êÑÐÈËÔ±¹Û²ìµ½¸Ã×é֯ʹÓùýµÄ¹¤¾ßÔ̺¬£ºCobalt Strike¡¢Ô¶¿ØÄ¾ÂíPlugX¡¢ORat¡¢RCSession¡¢Nbtscan¡¢Nmap¼°Wmiexec ¡£¸Ã×éÖ¯¿ÉÄÜÔçÔÚ2014Äê¾ÍÆðÍ·Á˹¥»÷»î¶¯ ¡£



Ô­ÎÄÁ´½Ó£º

https://www.secureworks.com/research/bronze-president-targets-ngos



6.ÃÀ·¨ÔºÊÚȨ΢ÈíÊÕÊܳ¯ÏÊAPT37½ÚÔìµÄ50¸öÓòÃû


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



΢Èí³É¹¦ÊÕÊÜÁËÓɳ¯ÏʺڿÍ×éÖ¯APT37½ÚÔìµÄ50¸öÓòÃû£¬ÕâЩÓòÃû±»¸Ã×éÖ¯ÓÃÀ´ÌáÒéÍøÂç¹¥»÷£¬Ô̺¬·¢ËÍ´¹µöÓʼþºÍÍйܴ¹µöÒ³ÃæµÈ ¡£Î¢Èí°µÊ¾ÆäÊý×Ö·¸×ﲿÃÅ£¨DCU£©ºÍÍþвµý±¨ÖÐÐÄ£¨MSTIC£©ÒѾ­¼à¶½APT37³¤´ïÊýԵŦ·ò£¬²¢ÓÚ12ÔÂ18ÈÕÔÚ¸¥¼ªÄáÑÇÖÝ·¨Ôº¶Ô¸Ã×éÖ¯Ìá¸æ×´ËÏ ¡£¸Ã·¨ÔºÊÚÓè΢ÈíȨÏÞÒÔÊÕÊÜAPT37ÔÚ·¸×ï»î¶¯ÖÐʹÓõÄ50¸öÓòÃû ¡£Î¢Èí¸ß¹Ü°µÊ¾¸Ã×éÖ¯µÄ´óÎÞÊýÖ¸±ê¶¼Î»ÓÚÃÀ¹ú¡¢ÈÕ±¾ÒÔ¼°º«¹ú ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/microsoft-takes-down-50-domains-operated-by-north-korean-hackers/