¼ÓÄôóÁ¬Ëø³¬ÊÐSobeysÔâµ½Black BastaµÄÀÕË÷¹¥»÷

°ä²¼¹¦·ò 2022-11-14
1¡¢¼ÓÄôóÁ¬Ëø³¬ÊÐSobeysÔâµ½Black BastaµÄÀÕË÷¹¥»÷

¾ÝýÌå11ÔÂ12ÈÕ±¨Â· £¬×ÔÉÏÖÜÄ©ÒÔÀ´ £¬¼ÓÄôóSobeysÆìϵÄÔÓ»õµêºÍÒ©µêµÄITϵͳһÏò´æÔÚÎÊÌâ ¡£SobeysµÄĸ¹«Ë¾Empireй© £¬¹ÌÈ»ÆäÉ̵êÈÔÔÚ½»Ò× £¬Ä¿Ç°Ã»ÓгöÏÖÑϳÁÖжÏ £¬µ«ÊDz¿ÃŵêÄÚ·þÎñ¿ÉÄÜÊܵ½Ó°Ïì ¡£¾ÝÔ±¹¤Ð¹Â© £¬ÊÜÓ°ÏìÉ̵êÖеÄËùÓÐÍÆËã»ú¶¼Òѱ»Ëø¶¨ £¬µ«POSºÍÖ§¸¶´¦ÖÃϵͳÒÀÈ»ÔÚÏß £¬ÓÉÓÚËüÃÇÔÚµ¥¶ÀµÄÍøÂçÉÏ ¡£Ö»¹Ü¸Ã¹«Ë¾ÉÐδÅû¶¹ØÓÚÕâ´ÎÖжϵÄϸ½ÚÐÅÏ¢ £¬µ«×êÑÐÈËԱͨ¹ýÊê½ð¼Í¼ºÍ½»Éæ¶Ô»°´§Ä¦¸Ã¹«Ë¾µÄϵͳϰȾÁËBlack Basta ¡£

https://securityaffairs.co/wordpress/138424/cyber-crime/sobeys-ransomware-attack.html

2¡¢ºÚ¿ÍÐû³ÆÒÑÈëÇÖµÂÒâÖ¾ÒøÐв¢ÔÚÍøÉÏÏúÊÛÆä½Ó¼ûȨÏÞ

¾Ý11ÔÂ11ÈÕ±¨Â· £¬¹¥»÷Õß(0x_dump)Ðû³ÆÒÑÈëÇÖ¿ç¹úͶ×ÊÒøÐеÂÒâÖ¾ÒøÐÐ £¬²¢ÔÚÏßÏúÊÛÆäÍøÂçµÄ½Ó¼ûȨÏÞ ¡£¸ÃIAB£¨initial access broker£©°µÊ¾Äܹ»½Ó¼ûÒøÐÐϵͳÖеÄÔ¼21000̨É豸 £¬ÆäÖдó²¿ÃÅÊÇWindowsϵͳ £¬Ëû»¹³Æ±»Ï°È¾µÄÉ豸ÊÜSymantec EDR½â¾ö¹æ»®µÄ±£»¤ ¡£Âô¼Ò˵ËûÄܹ»½Ó¼ûÓÃÓÚÄÚ²¿Í¨Ñ¶µÄ̸Ìì·þÎñ £¬»¹Äܹ»½Ó¼ûÔ̺¬16 TBÊý¾ÝµÄÎļþ·þÎñÆ÷ ¡£¶ÔµÂÒâÖ¾ÒøÐнӼûȨÏÞµÄÊÛ¼ÛΪ7.5±ÈÌØ±Ò £¬¼ÛÖµÔ¼156274ÃÀÔª ¡£

https://securityaffairs.co/wordpress/138416/data-breach/deutsche-bank-alleged-data-breach.html

3¡¢Ó¢¹úÓÊÕþ¹«Ë¾Royal MailµÄÍøÕ¾·þÎñÖжϳ¬¹ý24Ó×ʱ

ýÌå11ÔÂ11ÈÕ³Æ £¬Ó¢¹ú»Ê¼ÒÓÊÕþµÄTrack&TraceÍøÕ¾Öжϳ¬¹ý24Ó×ʱ £¬Óû§ÎÞ·¨×·×ÙËûÃǵİü¹üºÍÓʼþµÝËÍ ¡£Óû§½Ó¼û¸ÃÍøÕ¾Ê±»áÊÕµ½¡°·þÎñÁÙʱ²»³ÉÓá±ÌáÐÑ £¬¶øTrack & Trace APIÒ»ÏòÔÚ·µ»ØHTTP 429״̬´úÂë £¬ÕâÅú×¢·þÎñÆ÷½Ó¹Üµ½µÄÒªÇó¹ý¶à ¡£×êÑÐÈËԱѯÎÊÊÇ·ñÔâµ½ÁËÍøÂç¹¥»÷ £¬¹«Ë¾µÄ½²»°È˰µÊ¾ÍøÕ¾´æÔÚ¼¼ÊõÎÊÌâ £¬µ«Óû§Äܹ»ÔÚRoyal MailÀûÓÃÉϸú×Ù°ü¹ü ¡£ÉÏÖÜ £¬Click&DropÍøÕ¾ÉϵĿͻ§ÐÅϢй¶ £¬ÆÈʹ»Ê¼ÒÓÊÕþÁÙʱ¹Ø¹ØÆäÔÚÏßÒµÎñ ¡£

https://www.bleepingcomputer.com/news/security/royal-mail-down-tracking-unavailable-as-outage-exceeds-24-hours/

4¡¢ÂíÀ´Î÷ÑÇÑ¡¾ÙίԱ»áµÄÊý¾Ý¿âй¶½ü80ÍòÑ¡ÃñµÄÐÅÏ¢

11ÔÂ11ÈÕ±¨Â·³Æ £¬ÂíÀ´Î÷ÑÇÔ¼80ÍòÃûÑ¡ÃñµÄÓ×ÎÒÐÅϢй¶ ¡£¾Ý³Æ £¬Ð¹Â¶µÄ67 GBÊý¾ÝÐÂäį´×ÔÑ¡¾ÙίԱ»áµÄÊý¾Ý¿â £¬¸ÃÊý¾Ý¿âĿǰÔÚÒ»¸ö°µÍøÊг¡ÉÏÒÔ2000ÃÀÔªµÄ¼ÛÖµÏúÊÛ ¡£11ÔÂ10ÈÕ £¬×êÑÐÈËÔ±ÔÚlowyat.net·¢ÏÖÁËÏúÊÛµÄÐÅÏ¢ £¬Éæ¼°¾ÓÃñµÄÐÕÃû¡¢Éí·ÝÖ¤ºÅÂë¡¢ÓʼþµØÖ·¡¢µ®ÉúÈÕÆÚºÍ¼ÒͥסַµÈ ¡£¾Ý³Æ £¬ÕâЩÊý¾ÝÊÇ´ÓÑ¡¾ÙίԱ»áµÄMySPRÍøÕ¾ÉÏÇÔÈ¡µÄ ¡£Õâһй¶ÊÂÎñ²úÉúÔÚ11ÔÂ19ÈÕÈ«¹úͶƱǰһÖÜ £¬ÒýÆðÁËÂíÀ´Î÷ÑǾÓÃñµÄÓÇÓô ¡£

https://www.nst.com.my/news/crime-courts/2022/11/849700/personal-info-800000-voters-compromised-alleged-breach-ec-database

5¡¢Zscaler·¢ÏÖGoogle PlayÖзַ¢XenomorphľÂíµÄÀûÓÃ

ZscalerÔÚ11ÔÂ10ÈÕй©ÆäÔÚGoogle PlayÉ̵êµÄÀûÓÃÖз¢ÏÖÁËÒøÐÐľÂíXenomorph ¡£XenomorphÓëAlienÓÐËù³Áµþ £¬µ«ËüÃǵÄÖ°ÄÜÆëÈ«·ÖÆç £¬×êÑÐÈËÔ±´§Ä¦ÕâÁ½ÖÖ¶ñÒâÈí¼þ¿ÉÄÜÊÇÓÉͳһ¿ª·¢ÈËÔ±¿ª·¢ ¡£¸Ã¶ñÒâÀûÓÃÃûΪTodo: Day manager £¬ÏÂÔØÁ¿³¬¹ý1000´Î ¡£Zscaler»¹·¢ÏÖÁíÒ»¸öÀûÓá°½U·Ñ¥­©`¥Ñ©`¡±£¨Expense Keeper£©Ò²²û·¢³öÁËÀàËÆµÄÐÐΪ £¬µ«ÊÇ´ËÀûÓò»»á¼ìË÷payloadµÄdropper URL ¡£

https://www.zscaler.com/blogs/security-research/rise-banking-trojan-dropper-google-play-0

6¡¢Lookout°ä²¼¹ØÓÚBadBazaarºÍMOONSHINEµÄ·ÖÎö»ã±¨

11ÔÂ10ÈÕ £¬Lookout°ä²¼Á˹ØÓÚ¶ñÒâÈí¼þBadBazaarºÍMOONSHINEµÄ·ÖÎö»ã±¨ ¡£×Ô2018ÄêÒÔÀ´ £¬BadBazaar¼äµýÈí¼þÒÑʹÓÃÖÁÉÙ111¸ö·ÖÆçµÄÀûÓ÷¨Ê½Ï°È¾Ö¸±ê £¬Èç×ֵ䡢µç³ØÓÅ»¯¹¤¾ßºÍÊÓÆµ²¥·ÅÆ÷µÈ £¬²¢ÔÚÌØ¶¨µÄͨѶÇþ·ÉϽøÐÐÐû´« ¡£´Ó2022Äê7ÔÂÆðÍ· £¬Lookout¾Í¹Û²ìµ½Ò»Â·ÐµĻ £¬ÀûÓÃ50¸öÀûÓÃÏòÖ¸±êÍÆËÍа汾µÄMoonshine £¬ËüÄܹ»¼à¶½Ö¸±êµÄÍøÂç»î¶¯¡¢IP µØÖ·ºÍÓ²¼þÐÅÏ¢µÈ ¡£

https://www.lookout.com/blog/uyghur-surveillance-campaign-badbazaar-moonshine