Slack³ÆÒѽ¨¸´¿Éй¼ûÜÂëµÄ·ì϶²¢Îª²¿ÃÅÓû§³ÁÖÃÃÜÂë

°ä²¼¹¦·ò 2022-08-08

1¡¢Slack³ÆÒѽ¨¸´¿Éй¼ûÜÂëµÄ·ì϶²¢Îª²¿ÃÅÓû§³ÁÖÃÃÜÂë

      

¾ÝýÌå8ÔÂ6ÈÕ±¨Â· £¬Slack½¨¸´ÁËÔÚ´´½¨»ò³·Ïú¹¤×÷ÇøµÄ¹²ÏíÔ¼ÇëÁ´½Óʱй¶¼ÓÑÎÃÜÂë¹þÏ£µÄ·ì϶¡£¸Ã¹«Ë¾Ú¹ÊÍ £¬µ±Óû§Ö´ÐÐÕâЩ²Ù×÷ÖÐʱ £¬Slack»á½«ÆäÃÜÂëµÄ¹þÏ££¨²»ÊÇÃ÷ÎÄ£©·¢Ë͸øÆäËü¹¤×÷Çø³ÉÔ± £¬¸Ã·ì϶ӰÏìÁËÔÚ2017Äê4ÔÂ17ÈÕÖÁ2022Äê7ÔÂ17ÈÕÆÚ¼ä´´½¨»ò³·Ïú¹²ÏíÔ¼ÇëÁ´½ÓµÄËùÓÐЧ»§¡£Ä¿Ç° £¬SlackÒÑΪÊÜÓ°ÏìµÄÔ¼0.5%µÄÓû§³ÁÖÃÃÜÂë £¬»¹½¨ÒéËùÓÐЧ»§ÆôÓÃ2FAÑéÖ¤²¢´´½¨Î¨Ò»µÄÃÜÂë¡£


https://thehackernews.com/2022/08/slack-resets-passwords-after-bug.html


2¡¢ÐµÄRapperBot¿Éͨ¹ýSSH±©Á¦¹¥»÷Õë¶ÔLinux·þÎñÆ÷

     

FortinetÔÚ8ÔÂ3ÈÕÅû¶ÁË¿Éͨ¹ýSSH±©Á¦¹¥»÷Õë¶ÔLinux·þÎñÆ÷µÄжñÒâÈí¼þRapperBot¡£×êÑÐÈËÔ±Åú×¢ £¬RapperBotÊÇ»ùÓÚMiraiľÂí £¬×Ô2022Äê6ÔÂÖÐÑ®ÒÔÀ´Ò»Ïò±»ÓÃÓÚ¹¥»÷»î¶¯ £¬ÒÑʹÓÃÈ«Çò3500¶à¸öΨһµÄIPÀ´É¨Ãè²¢³¢ÊÔSSH±©Á¦ÆÆ½âLinux·þÎñÆ÷¡£SSH±©Á¦ÆÆ½âÒÀÀµÓÚͨ¹ýÖ÷»úΨһTCPÒªÇó´ÓC2ÏÂÔØµÄÍ´´¦Áбí £¬¶ø¶ñÒâÈí¼þÔڳɹ¦Ê±»áÏòC2»ã±¨¡£´Ë±í £¬RapperBotµÄÖ¸±ê²¢²»ÏÔÖø £¬ÇÒÆä¿ª·¢ÕßÒ»ÏòÔÚÏÞ¶ÈÆäDDoSÖ°ÄÜ¡£


https://www.fortinet.com/blog/threat-research/rapperbot-malware-discovery


3¡¢Ó¢¹úNHSµÄ111´¹Î£·þÎñÒòÆäMSPÔâµ½¹¥»÷³ÖÐøÖжÏ

      

ýÌå8ÔÂ5ÈÕ³Æ £¬Ó¢¹ú¹ú¶ÈÎÀÉú·þÎñ(NHS)111´¹Î£·þÎñ²úÉúÁ˳ÖÐøµÄÖжÏ¡£Ó¢¹úÍйܷþÎñÌṩÉÌ(MSP)Advanced³ÆÆäÉÏÖÜËÄÔâµ½ÍøÂç¹¥»÷µ¼Ö·þÎñÖжÏ £¬¶ø85%µÄNHS 111·þÎñ¶¼Ê¹ÓÃÁËAdvancedµÄAdastra»¼ÕßÖÎÀí½â¾ö¹æ»®¡£¾ÝϤ £¬Õâ´ÎÖжÏÓ°ÏìÁËÓ¢¹úÈ«ÊýµÄ4¸ö¹ú¶È £¬NHS½¨ÒéÓ¢¹ú¹«¼ÒʹÓÃÔÚÏ߯½Ì¨½Ó¼ûNHS 111´¹Î£·þÎñ £¬Ö±µ½´Ëʵõ½½â¾ö¡£¹ÌȻûÓйØÓÚ¹¥»÷µÄ¾ßÌåÐÅÏ¢ £¬µ«×êÑÐÈËԱƾ¾Ý´ë´Ç´§Ä¦Õâ¿ÉÄÜÊÇÀÕË÷¹¥»÷¡£


https://www.bleepingcomputer.com/news/security/uk-nhs-suffers-outage-after-cyberattack-on-managed-service-provider/


4¡¢¹¥»÷Õß¹«¿ªÒÔÉ«ÁÐÊý×Öµý±¨¹«Ë¾CellebriteµÄ4TBÊý¾Ý

      

¾Ý8ÔÂ5ÈÕ±¨Â· £¬Ä³ÄäÃû¹¥»÷Õßй¶ÁËCellebriteÔ¼4TBµÄÊý¾Ý¡£CellebriteÊÇÒÔÉ«ÁеÄÒ»¼ÒÊý×Öµý±¨¹«Ë¾ £¬´ËÇ°ÔøÓÉÓÚÃÀ¹ú·¨ÂɺͰ²È«»ú¹¹½âËøPhoneÉ豸¶ø³ÉΪÐÂÎÅÍ·Ìõ¡£Êý¾ÝÖØÒª·ÖΪÁ½²¿ÃÅ £¬Cellebrite Mobilogy£¨3.6TB£©ºÍCellebrite Team Foundation Server£¨430 GB£©¡£Ä¿Ç° £¬Ð¹Â¶µÄÊý¾ÝÖ»ÄÜͨ¹ýDDoSecretsÌṩ¸ø×êÑÐÈËÔ±ºÍ¼ÇÕß £¬ÉÐδÓй¥»÷ÍÅ»ïÐû³ÆÎª´ËÊÂÕÆ¹Ü¡£


https://www.hackread.com/anonymous-leaks-4tb-cellebrite-data-cyberattack/


5¡¢ºÉÀ¼µÄ120¶à¼ÒÑÀ¿ÆÕïËùÒòÔâµ½ÍøÂç¹¥»÷¶ø¹Ø¹ØÊýÈÕ

      

ýÌå8ÔÂ5ÈÕ±¨Â· £¬ºÉÀ¼µÄ120¶à¼ÒÑÀ¿ÆÕïËù×ÔÉÏÖÜËÄÒÔÀ´ÒѹعØÊýÈÕ¡£¸ÃÊÂÎñÔ´ÓÚColosseum Dental BeneluxÔâµ½µÄÍøÂç¹¥»÷ £¬¸Ã¹«Ë¾ÔÚ±ÈÀûʱºÍºÉÀ¼Õ¼ÓÐ130¶à¼Ò·ÖÖ§»ú¹¹ £¬µ«´ËÊÂÎñÖ»Ó°ÏìÁËλÓÚºÉÀ¼µÄÃÅÕï¡£¾ÝϤ £¬¹¤×÷ÈËÔ±ÎÞ·¨½Ó¼û¿Í»§µÄ»¼Õß²¡Ê· £¬ESET×êÑÐÈËÔ±Ôò°µÊ¾ £¬ÕâÓµÓÐÀÕË÷¹¥»÷µÄËùÓÐÌØµã¡£Ä¿Ç° £¬¸Ã¹«Ë¾ÔÚÖÂÁ¦¸´Ô­ÏµÍ³ £¬²¢Óë±í²¿¸÷·½Ò»Â·µ÷²é´ËÊ¡£


https://www.databreaches.net/more-than-100-dutch-dental-practices-closed-for-days-due-to-cyber-attack/


6¡¢Meta°ä²¼2022ÄêµÚ¶þ¼¾¶ÈÆ¥µÐÐÔÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨

      

MetaÔÚ8Ô·ݰ䲼ÁË2022ÄêµÚ¶þ¼¾¶ÈÆ¥µÐÐÔÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£ÆäÖеÄÁÁµãÊÇ·¢ÏÖÁËÁ½¸ö¼äµý×éÖ¯ £¬ËüÃÇÓëºÚ¿ÍÍÅ»ïBitter APTºÍAPT36£¨±ðÃûTransparent Tribe£©ÓйØ £¬Ê¹ÓÃÁËеÄAndroid¶ñÒâÈí¼þ¡£»ã±¨Ú¹ÊͳÆ £¬Bitter APT¶ÔÐÂÎ÷À¼¡¢Ó¡¶È¡¢°Í»ù˹̹ºÍÓ¢¹úµÄ½øÐÐÁËÉç»á¹¤³Ì¹¥»÷ £¬²¢Í¶ÈëÁË´óÁ¿µÄ¹¦·òºÍ¾«Á¦¡£¶øAPT36µÄ×îÐÂ»î¶¯ÖØÒªÕë¶Ô°¢¸»º¹¡¢Ó¡¶È¡¢°Í»ù˹̹¡¢°¢À­²®½áºÏÇõ³¤¹úºÍÉ³ÌØ°¢À­²® £¬³ö¸ñÊǾüʹÙÔ±ºÍ»î¶¯¼ÒµÈ¡£


https://about.fb.com/wp-content/uploads/2022/08/Quarterly-Adversarial-Threat-Report-Q2-2022.pdf