·¨¹úµçÐŹ«Ë¾La Poste MobileÔâµ½LockbitµÄÀÕË÷¹¥»÷
°ä²¼¹¦·ò 2022-07-121¡¢·¨¹úµçÐŹ«Ë¾La Poste MobileÔâµ½LockbitµÄÀÕË÷¹¥»÷
ýÌå7ÔÂ10ÈÕ±¨Â·³Æ£¬·¨¹úµçÐÅÔËÓªÉÌLa Poste MobileÔâµ½ÁËLockbitÍÅ»ïµÄÀÕË÷¹¥»÷¡£¸Ã¹«Ë¾ÔÚÆäÍøÕ¾Éϰ䲼µÄÒ»·ÝÉêÃ÷ÖÐд·£¬¹¥»÷ʼÓÚ7ÔÂ4ÈÕ£¬Ó°ÏìÁËÆäÐÐÕþºÍÖÎÀí·þÎñ¡£ËûÃÇÔÚ»ñϤ´Ë¹ýºóµ±¼´²ÉÈ¡±ØÒªµÄ´ëÊ©£¬¹Ø¹ØÁËÓйØÍÆËã»úϵͳ£¬Ô̺¬ÍøÕ¾ºÍ¿Í»§Çø¡£´Ë±í£¬Ô±¹¤ÍÆËã»úÖеIJ¿ÃÅÎļþй¶£¬¿ÉÄÜÉæ¼°Ó×ÎÒÊý¾Ý¡£ÉÏÖÜÎ壬LockBitÍÅ»ïÒѽ«La Poste MobileÔö³¤µ½ÆäÊý¾ÝÐ¹Â¶ÍøÕ¾¡£
https://securityaffairs.co/wordpress/133080/cyber-crime/la-poste-mobile-ransomware.html
2¡¢ALPHVÍÅ»ïÐû³ÆÒÑÈëÇÖÈÕ±¾µÄÓÎÏ·¿¯ÐÐÉÌÍò´úÄÏÃι¬
¾ÝVGCÔÚ7ÔÂ11Èյı¨Â·£¬ALPHVÍÅ»ïÐû³ÆÒѾÀÕË÷¹¥»÷ÁËÍò´úÄÏÃ鬣¨Bandai Namco£©¡£Íò´úÄÏÃι¬ÊÇÈÕ±¾³ÛÃûµÄÓÎÏ·¿¯ÐÐÉÌ£¬ÒÔ¡¶³Ô¶¹ÈË¡·¡¢¡¶ÌúÈ¡·ºÍ¡¶ÒõÓôÖ®»ê¡·µÅ×ÎÏ·¶øÎÅÃû¡£¸ÃÐÂÎÅÓÉvx-undergroundÓÚ±¾ÖÜÒ»°ä²¼ÔÚTwitterÉÏ£¬Ä¿Ç°£¬VGCÒÑÁªÏµÍò´úÄÏÃι¬¶Ô´Ëʰ䷢ÆÀÂÛ¡£ÓÎÏ·¹¤×÷ÊÒCD Projekt RedÔÚÈ¥ÄêÒ²Ôâµ½ÁËÀÕË÷¹¥»÷£¬µ¼ÖÂÈü²©Åó¿Ë2077ºÍÎ×ʦ3µÄÔ´´úÂ룬ÒÔ¼°Ô±¹¤µÄ¾ßÌåÐÅϢй¶¡£
https://www.videogameschronicle.com/news/elden-ring-publisher-bandai-namco-reportedly-targeted-in-a-ransomware-attack/
3¡¢Emsisoft°ä²¼AstraLockerºÍYashmaµÄÃâ·Ñ½âÃÜÆ÷
¾ÝýÌå7ÔÂ8ÈÕ±¨Â·£¬ÐÂÎ÷À¼°²È«¹«Ë¾Emsisoft°ä²¼ÁËÀÕË÷Èí¼þAstraLockerºÍYashmaµÄÃâ·Ñ½âÃܹ¤¾ß¡£Emsisoft³Æ£¬AstraLocker½âÃÜÆ÷ºÏÓÃÓÚʹÓÃ.Astra»ò.babykÀ©´óÃû²¢»ùÓÚBabukµÄ½âÃÜÆ÷£¬ËûÃÇ×ܹ²°ä²¼ÁË8¸öÃÜÔ¿£»Yashma½âÃÜÆ÷ºÏÓÃÓÚʹÓÃ.AstraLocker»òËæ»ú.[a-z0-9]{4}À©´óÃû²¢»ùÓÚChaosµÄ½âÃÜÆ÷£¬ËûÃÇ×ܹ²°ä²¼ÁË3¸öÃÜÔ¿¡£Emsisoft»¹½¨Òéͨ¹ýWindowsÔ¶³Ì×ÀÃæ±»ÈëÇÖµÄϵͳ¸ü¸ÄËùÓÐÓµÓÐȨԶ³ÌµÇ¼ȨÏÞµÄÓû§µÄÍ´´¦£¬²¢ÕÒ³ö¹¥»÷Õß¿ÉÄÜÔö³¤µÄÆäËû±¾µØÕÊ»§¡£
https://www.bleepingcomputer.com/news/security/free-decryptor-released-for-astralocker-yashma-ransomware-victims/
4¡¢×êÑÐÈËÔ±·¢ÏÖÐÂÀÕË÷Èí¼þ0megaÕë¶ÔÈ«ÇòÁìÓòÄÚµÄ×éÖ¯
ýÌå7ÔÂ8Èճƣ¬ÃûΪ0megaµÄÐÂÀÕË÷ÍÅ»ïÕë¶ÔÈ«ÇòÁìÓòÄÚµÄ×éÖ¯½øÐÐË«³ÁÀÕË÷¹¥»÷£¬²¢ÀÕË÷Êý°ÙÍòÃÀÔªµÄÊê½ð¡£0mega×Ô2022Äê5ÔÂÆðÍ·»îÔ¾£¬×êÑÐÈËÔ±ÉÐδÕÒµ½ÆäÀÕË÷Èí¼þÑù±¾£¬Òò¶øÃ»ÓÐÌ«¶à¹ØÓÚÎļþÈôºÎ±»¼ÓÃܵľßÌåÐÅÏ¢¡£¸ÃÍÅ»ïÔËÓª×ÅÒ»¸öÊý¾ÝÐ¹Â¶ÍøÕ¾£¬Ä¿Ç°ÍйÜ×Å152 GBÊý¾Ý£¬¾Ý³ÆÊÇ5ÔµĹ¥»÷»î¶¯ÖдÓÒ»¼Òµç×Óά½¨¹«Ë¾ÇÔÈ¡µÄ¡£´Ë±í£¬ÉÏÖÜÓÐÒ»¸ö±»¹¥»÷Ö¸±êÒѱ»´ÓÖÐÒÆ³ý£¬ÕâÅú×¢¸Ã¹«Ë¾¿ÉÄÜÒѾ֧¸¶ÁËÊê½ð¡£
https://www.bleepingcomputer.com/news/security/new-0mega-ransomware-targets-businesses-in-double-extortion-attacks/
5¡¢Fortinet°ä²¼°²È«¸üУ¬½¨¸´¶à¸ö²úÆ·Öеķì϶
ýÌå7ÔÂ9ÈÕ±¨Â·³Æ£¬Fortinet½¨¸´ÁËÆä¶à¿î²úÆ·Öеķì϶¡£ÊÜÓ°ÏìµÄ²úÆ·Ô̺¬FortiADC¡¢FortiAnalyzer¡¢FortiManager¡¢FortiOSºÍFortiProxyµÈ¡£Õâ´Î½¨¸´µÄ½ÏΪÑϳÁµÄÊÇFortiNACÖпÕÃÜÂëȱµã£¨CVE-2022-26117£©£¬¿ÉÓÃÀ´Í¨¹ýCLI½Ó¼ûMySQLÊý¾Ý¿â£»»ùÓÚ²Ö¿âµÄ»º³åÇøÒç¶Âí½Å£¨CVE-2021-43072£©£¬¿Éͨ¹ýÌØÔìµÄCLIÖ´ÐкÅÁõè¾¶±éÀú·ì϶£¨CVE-2022-30302£©£¬¿Éͨ¹ýÌØÔìµÄWebÒªÇó´Óµ×²ãÎļþϵͳÖмìË÷ºÍɾ³ýËÁÒâÎļþ£»ÒÔ¼°Ä¿Â¼±éÀú·ì϶£¨CVE-2021-41031£©£¬¿É½«È¨ÏÞÌáÉýµ½SYSTEM¡£
https://securityaffairs.co/wordpress/133059/security/fortinet-multiple-issues-several-products.html
6¡¢CheckmarxÅû¶CuteBoiÀûÓÃNPM°üµÄ´ó¹æÄ£ÍÚ¿ó»î¶¯
7ÔÂ6ÈÕ£¬CheckmarxÅû¶ÁËÕë¶ÔNPM JavaScript°ü´æ´¢¿âµÄÐÂÒ»ÂֵĴó¹æÄ£ÍÚ¿ó»î¶¯¡£¸Ã»î¶¯¹éÒòÓÚ¹¥»÷ÍÅ»ïCuteBoi£¬Éæ¼°1283¸önpm°ü£¬ÕâЩ°üÄܹ»×Ô¶¯´Ó1000¶à¸ö·ÖÆçµÄÓû§ÕÊ»§Öа䲼¡£ËùÓÐÕâЩ°ü¶¼ÓµÓÐÏÕЩһÑùµÄeazyminer°üµÄ´úÂ븱±¾£¬eazyminerÊÇXMRigµÄJS wrapper£¬Ö¼ÔÚÀûÓÃÍÆËã»úÉÏδʹÓõÄ×ÊÔ´£¬Èçci/cdºÍweb·þÎñÆ÷¡£×êÑÐÈËÔ±³Æ£¬CuteBoiÊǽñÄêµÚ¶þ¸ö×Ô¶¯»¯¶ÔNPMÌáÒé´ó¹æÄ£¹¥»÷µÄÍŻ²¢Ô¤¼Æ½«À´½«¿´µ½¸ü¶à´ËÀ๥»÷¡£
https://checkmarx.com/blog/cuteboi-detected-preparing-a-large-scale-crypto-mining-campaign-on-npm-users/


¾©¹«Íø°²±¸11010802024551ºÅ