¼ÓÄôóÁ¬Ëø³¬ÊÐSobeysÔâµ½Black BastaµÄÀÕË÷¹¥»÷
°ä²¼¹¦·ò 2022-11-14¾ÝýÌå11ÔÂ12ÈÕ±¨Â·£¬×ÔÉÏÖÜÄ©ÒÔÀ´£¬¼ÓÄôóSobeysÆìϵÄÔÓ»õµêºÍÒ©µêµÄITϵͳһÏò´æÔÚÎÊÌâ¡£SobeysµÄĸ¹«Ë¾Empireй©£¬¹ÌÈ»ÆäÉ̵êÈÔÔÚ½»Ò×£¬Ä¿Ç°Ã»ÓгöÏÖÑϳÁÖжϣ¬µ«ÊDz¿ÃŵêÄÚ·þÎñ¿ÉÄÜÊܵ½Ó°Ïì¡£¾ÝÔ±¹¤Ð¹Â©£¬ÊÜÓ°ÏìÉ̵êÖеÄËùÓÐÍÆËã»ú¶¼Òѱ»Ëø¶¨£¬µ«POSºÍÖ§¸¶´¦ÖÃϵͳÒÀÈ»ÔÚÏߣ¬ÓÉÓÚËüÃÇÔÚµ¥¶ÀµÄÍøÂçÉÏ¡£Ö»¹Ü¸Ã¹«Ë¾ÉÐδÅû¶¹ØÓÚÕâ´ÎÖжϵÄϸ½ÚÐÅÏ¢£¬µ«×êÑÐÈËԱͨ¹ýÊê½ð¼Í¼ºÍ½»Éæ¶Ô»°´§Ä¦¸Ã¹«Ë¾µÄϵͳϰȾÁËBlack Basta¡£
https://securityaffairs.co/wordpress/138424/cyber-crime/sobeys-ransomware-attack.html
2¡¢ºÚ¿ÍÐû³ÆÒÑÈëÇÖµÂÒâÖ¾ÒøÐв¢ÔÚÍøÉÏÏúÊÛÆä½Ó¼ûȨÏÞ
¾Ý11ÔÂ11ÈÕ±¨Â·£¬¹¥»÷Õß(0x_dump)Ðû³ÆÒÑÈëÇÖ¿ç¹úͶ×ÊÒøÐеÂÒâÖ¾ÒøÐУ¬²¢ÔÚÏßÏúÊÛÆäÍøÂçµÄ½Ó¼ûȨÏÞ¡£¸ÃIAB£¨initial access broker£©°µÊ¾Äܹ»½Ó¼ûÒøÐÐϵͳÖеÄÔ¼21000̨É豸£¬ÆäÖдó²¿ÃÅÊÇWindowsϵͳ£¬Ëû»¹³Æ±»Ï°È¾µÄÉ豸ÊÜSymantec EDR½â¾ö¹æ»®µÄ±£»¤¡£Âô¼Ò˵ËûÄܹ»½Ó¼ûÓÃÓÚÄÚ²¿Í¨Ñ¶µÄ̸Ìì·þÎñ£¬»¹Äܹ»½Ó¼ûÔ̺¬16 TBÊý¾ÝµÄÎļþ·þÎñÆ÷¡£¶ÔµÂÒâÖ¾ÒøÐнӼûȨÏÞµÄÊÛ¼ÛΪ7.5±ÈÌØ±Ò£¬¼ÛÖµÔ¼156274ÃÀÔª¡£
https://securityaffairs.co/wordpress/138416/data-breach/deutsche-bank-alleged-data-breach.html
3¡¢Ó¢¹úÓÊÕþ¹«Ë¾Royal MailµÄÍøÕ¾·þÎñÖжϳ¬¹ý24Ó×ʱ
ýÌå11ÔÂ11Èճƣ¬Ó¢¹ú»Ê¼ÒÓÊÕþµÄTrack&TraceÍøÕ¾Öжϳ¬¹ý24Ó×ʱ£¬Óû§ÎÞ·¨×·×ÙËûÃǵİü¹üºÍÓʼþµÝËÍ¡£Óû§½Ó¼û¸ÃÍøÕ¾Ê±»áÊÕµ½¡°·þÎñÁÙʱ²»³ÉÓá±ÌáÐÑ£¬¶øTrack & Trace APIÒ»ÏòÔÚ·µ»ØHTTP 429״̬´úÂ룬ÕâÅú×¢·þÎñÆ÷½Ó¹Üµ½µÄÒªÇó¹ý¶à¡£×êÑÐÈËԱѯÎÊÊÇ·ñÔâµ½ÁËÍøÂç¹¥»÷£¬¹«Ë¾µÄ½²»°È˰µÊ¾ÍøÕ¾´æÔÚ¼¼ÊõÎÊÌ⣬µ«Óû§Äܹ»ÔÚRoyal MailÀûÓÃÉϸú×Ù°ü¹ü¡£ÉÏÖÜ£¬Click&DropÍøÕ¾ÉϵĿͻ§ÐÅϢй¶£¬ÆÈʹ»Ê¼ÒÓÊÕþÁÙʱ¹Ø¹ØÆäÔÚÏßÒµÎñ¡£
https://www.bleepingcomputer.com/news/security/royal-mail-down-tracking-unavailable-as-outage-exceeds-24-hours/
4¡¢ÂíÀ´Î÷ÑÇÑ¡¾ÙίԱ»áµÄÊý¾Ý¿âй¶½ü80ÍòÑ¡ÃñµÄÐÅÏ¢
11ÔÂ11ÈÕ±¨Â·³Æ£¬ÂíÀ´Î÷ÑÇÔ¼80ÍòÃûÑ¡ÃñµÄÓ×ÎÒÐÅϢй¶¡£¾Ý³Æ£¬Ð¹Â¶µÄ67 GBÊý¾ÝÐÂäį´×ÔÑ¡¾ÙίԱ»áµÄÊý¾Ý¿â£¬¸ÃÊý¾Ý¿âĿǰÔÚÒ»¸ö°µÍøÊг¡ÉÏÒÔ2000ÃÀÔªµÄ¼ÛÖµÏúÊÛ¡£11ÔÂ10ÈÕ£¬×êÑÐÈËÔ±ÔÚlowyat.net·¢ÏÖÁËÏúÊÛµÄÐÅÏ¢£¬Éæ¼°¾ÓÃñµÄÐÕÃû¡¢Éí·ÝÖ¤ºÅÂë¡¢ÓʼþµØÖ·¡¢µ®ÉúÈÕÆÚºÍ¼ÒͥסַµÈ¡£¾Ý³Æ£¬ÕâЩÊý¾ÝÊÇ´ÓÑ¡¾ÙίԱ»áµÄMySPRÍøÕ¾ÉÏÇÔÈ¡µÄ¡£Õâһй¶ÊÂÎñ²úÉúÔÚ11ÔÂ19ÈÕÈ«¹úͶƱǰһÖÜ£¬ÒýÆðÁËÂíÀ´Î÷ÑǾÓÃñµÄÓÇÓô¡£
https://www.nst.com.my/news/crime-courts/2022/11/849700/personal-info-800000-voters-compromised-alleged-breach-ec-database
5¡¢Zscaler·¢ÏÖGoogle PlayÖзַ¢XenomorphľÂíµÄÀûÓÃ
ZscalerÔÚ11ÔÂ10ÈÕй©ÆäÔÚGoogle PlayÉ̵êµÄÀûÓÃÖз¢ÏÖÁËÒøÐÐľÂíXenomorph¡£XenomorphÓëAlienÓÐËù³Áµþ£¬µ«ËüÃǵÄÖ°ÄÜÆëÈ«·ÖÆç£¬×êÑÐÈËÔ±´§Ä¦ÕâÁ½ÖÖ¶ñÒâÈí¼þ¿ÉÄÜÊÇÓÉͳһ¿ª·¢ÈËÔ±¿ª·¢¡£¸Ã¶ñÒâÀûÓÃÃûΪTodo: Day manager£¬ÏÂÔØÁ¿³¬¹ý1000´Î¡£Zscaler»¹·¢ÏÖÁíÒ»¸öÀûÓá°½U·Ñ¥©`¥Ñ©`¡±£¨Expense Keeper£©Ò²²û·¢³öÁËÀàËÆµÄÐÐΪ£¬µ«ÊÇ´ËÀûÓò»»á¼ìË÷payloadµÄdropper URL¡£
https://www.zscaler.com/blogs/security-research/rise-banking-trojan-dropper-google-play-0
6¡¢Lookout°ä²¼¹ØÓÚBadBazaarºÍMOONSHINEµÄ·ÖÎö»ã±¨
11ÔÂ10ÈÕ£¬Lookout°ä²¼Á˹ØÓÚ¶ñÒâÈí¼þBadBazaarºÍMOONSHINEµÄ·ÖÎö»ã±¨¡£×Ô2018ÄêÒÔÀ´£¬BadBazaar¼äµýÈí¼þÒÑʹÓÃÖÁÉÙ111¸ö·ÖÆçµÄÀûÓ÷¨Ê½Ï°È¾Ö¸±ê£¬Èç×ֵ䡢µç³ØÓÅ»¯¹¤¾ßºÍÊÓÆµ²¥·ÅÆ÷µÈ£¬²¢ÔÚÌØ¶¨µÄͨѶÇþ·ÉϽøÐÐÐû´«¡£´Ó2022Äê7ÔÂÆðÍ·£¬Lookout¾Í¹Û²ìµ½Ò»Â·ÐµĻ£¬ÀûÓÃ50¸öÀûÓÃÏòÖ¸±êÍÆËÍа汾µÄMoonshine£¬ËüÄܹ»¼à¶½Ö¸±êµÄÍøÂç»î¶¯¡¢IP µØÖ·ºÍÓ²¼þÐÅÏ¢µÈ¡£
https://www.lookout.com/blog/uyghur-surveillance-campaign-badbazaar-moonshine


¾©¹«Íø°²±¸11010802024551ºÅ