MetaÒòFacebookÊý¾Ýй¶±»°®¶ûÀ¼DPC·£¿î2.65ÒÚÅ·Ôª
°ä²¼¹¦·ò 2022-11-29¾ÝýÌå11ÔÂ28ÈÕ±¨Â·£¬Meta±»°®¶ûÀ¼Êý¾Ý±£»¤Î¯Ô±»á(DPC)·£¿î2.65ÒÚÅ·Ôª£¨2.755 ÒÚÃÀÔª£©¡£ÔÒòÊÇ2021ÄêFacebook´ó¹æÄ£Êý¾Ýй¶ÊÂÎñ£¬Éæ¼°È«ÇòÊýÒÚÓû§µÄÐÅÏ¢¡£ÔںڿͰ䲼5.33ÒÚFacebookÓû§µÄÊý¾Ýºó£¬DPCÓÚ2021Äê4ÔÂ14ÈÕÆô¶¯Á˶ÔMetaÎ¥·´GDPRµÄµ÷²é¡£DPCµÄµ÷²éµÃ³ö½áÂÛ£¬MetaÎ¥·´ÁËGDPRµÄµÚ25(1)ºÍ25(2)Ìõ¡£
https://www.bleepingcomputer.com/news/security/meta-fined-265m-for-not-protecting-facebook-users-data-from-scrapers/
2¡¢ÒÁÀÊ·¨¶û˹ͨѶÉçµÄÍøÕ¾Ôâµ½¹¥»÷250 TBÊý¾Ý±»É¾³ý
¾Ý11ÔÂ27ÈÕ±¨Â·£¬ÒÁÀÊ·¨¶û˹ͨѶÉçµÄÍøÕ¾Ôâµ½ºÚ¿Í¹¥»÷¡£ÃûΪBlack RewardµÄºÚ¿ÍÍÅ»ïÐû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü£¬²¢°µÊ¾ÒÑ´Ó¸ÃÍøÕ¾µÄ·þÎñÆ÷ºÍÍÆËã»úÖÐɾ³ýÁ˽ü250 TBµÄÊý¾Ý£¬»¹³ÆÇÔÈ¡Á˸ÃͨѶÉç·¢Ë͸ø¹þ÷ÄÚÒÁ°ì¹«ÊҵĻúÃܲ¼¸æºÍÅúʾ¡£È»¶ø£¬·¨¶û˹ͨѶÉç·ñ¶¨Á˺ڿÍËùÃèÊöµÄ¹¥»÷ˮƽ£¬³ÆºÚ¿ÍÖ»ÄÜÓ°ÏìÖÜÎåµÄÐÅÏ¢ºÍÐÂÎÅ£¬²¢³ÁÉêÐÂÎÅ»ú¹¹µÄÆäËûÐÅÏ¢ºÍÊý¾Ý¿âûÓб»·ÛËé¡£
https://www.hackread.com/fars-news-agency-website-iran-hacked/
3¡¢Ragnar Locker¹«¿ª±ÈÀûʱZwijndrecht¾¯Ô±¾ÖµÄÊý¾Ý
ýÌå11ÔÂ26Èճƣ¬Ragnar Locker¹«¿ªÁËËûÃÇÒÔΪÊÇ´ÓZwijndrechtÊÐÕþµ±¾ÖÇÔÈ¡µÄÊý¾Ý£¬µ«Á˾ÖÖ¤Ã÷ÕâЩÊý¾ÝÊÇ´ÓZwijndrecht¾¯Ô±¾ÖÇÔÈ¡µÄ¡£¾ÝϤ£¬Ð¹Â¶Êý¾ÝÔ̺¬´óÁ¿³µÅÆ¡¢·£¿î¡¢·¸×ï»ã±¨Îļþ¡¢ÈËÔ±¾ßÌåÐÅÏ¢ºÍµ÷²é»ã±¨µÈ¡£´ËÀàÊý¾Ý¿ÉÄܻᶳö¾Ù±¨·¸×ï״ΪµÄÈË£¬²¢Î£¼°ÔÚ½øÐеķ¨ÂÉÐж¯ºÍµ÷²é¡£±ÈÀûʱýÌ峯Õâ´ÎÊý¾Ýй¶ÊÇ´ËÀàÊÂÎñÖÐÓ°Ïì¸Ã¹ú¹«¹²·þÎñµÄ×îÑϳÁÊÂÎñÖ®Ò»£¬Ð¹Â¶ÁËZwijndrecht¾¯·½´Ó2006Äêµ½2022Äê9Ô±£ÁôµÄËùº±¼û¾Ý¡£
https://www.bleepingcomputer.com/news/security/ransomware-gang-targets-belgian-municipality-hits-police-instead/
4¡¢Õë¶ÔÎÚ¿ËÀ¼µÄÐÂÀÕË÷Èí¼þRansomBoggsÓëSandwormÓйØ
11ÔÂ25ÈÕ±¨Â·³Æ£¬Õë¶ÔÎÚ¿ËÀ¼×éÖ¯µÄÐÂÐÍÀÕË÷Èí¼þRansomBoggsÓëºÚ¿ÍÍÅ»ïSandwormÓйء£RansomBoggsÓÚ½ñÄê11ÔÂ21ÈÕ³õ´Î±»ESET¼ì²âµ½£¬¸Ã¹«Ë¾Ö¸³ö£¬¹ÌÈ»ÓÃ.NET±àдµÄ¶ñÒâÈí¼þÊÇÐµģ¬µ«ËüµÄ·Ö·¢ÀàËÆÓÚ֮ǰ¹éÒòÓÚSandwormµÄ¹¥»÷»î¶¯¡£ÆäÓÃÓÚ´ÓÓò½ÚÔìÆ÷·Ö·¢.NETÀÕË÷Èí¼þµÄPowerShell¾ç±¾ÏÕЩÓëÈ¥Äê4ÔÂÔÚIndustroyer2¹¥»÷ÄÜÔ´×éÖ¯ÆÚ¼äµÄ¾ç±¾Ò»Ñù¡£Ò»µ©½øÈëÖ¸±êÍøÂ磬RansomBoggs»áÌìÉúÒ»¸öËæ»úÃÜÔ¿£¬ÔÚCBCģʽÏÂʹÓÃAES-256¼ÓÃÜÎļþ£¬²¢¸½¼Ó.chschÀ©´óÃû¡£
https://thehackernews.com/2022/11/russia-based-ransomboggs-ransomware.html
5¡¢×êÑÐÍŶӷ¢ÏÖCrysisµÄ±äÖÖWikiÔÚº«¹ú·Ö·¢µÄ»î¶¯
AhnLabÓÚ11ÔÂ25ÈÕÅû¶ÁËÀÕË÷Èí¼þWikiÔÚº«¹ú·Ö·¢µÄ»î¶¯¡£¸ÃÀÕË÷Èí¼þÒѱ»È·¶¨ÎªCrysisµÄ±äÖÖ£¬¼Ù×°³ÉÕý³£·¨Ê½¡£ÔÚÖ´ÐÐÏÖʵ¼ÓÃÜ֮ǰ£¬Wiki½«×Ô¼º¸´Ôìµ½%AppData%»ò%windir%\system32õè¾¶£¬²¢Ôö³¤µ½×¢²á±íÖÐ×¢²áΪÆô¶¯·¨Ê½Ö®Ò»¡£´Ë±í£¬Ëü»¹»á½âÂëÒªÔÚÄÚ´æÖÐÖÕÖ¹µÄÓëÊý¾Ý¿âÓйصķþÎñºÍ¹ý³ÌÃû³Æ£¬²¢²éÕÒµ±Ç°ÔÚÔËÐеķþÎñºÍ¹ý³Ì²¢ÖÕÖ¹ËüÃÇ¡£ÓÉÓÚCrysisÀàÐ͵ÄÀÕË÷Èí¼þͨ³£Í¨¹ýRDP·Ö·¢£¬×êÑÐÈËÔ±½¨Òé°ÑÎÈRDPÏνӻ·¾³¡£
https://asec.ahnlab.com/en/42507/
6¡¢FortiGuard°ä²¼¹ØÓÚÀÕË÷Èí¼þCryptonitµÄ·ÖÎö»ã±¨
11ÔÂ23ÈÕ£¬FortiGuard°ä²¼Á˹ØÓÚÀÕË÷Èí¼þCryptonitµÄ·ÖÎö»ã±¨¡£CryptoniteÊÇÒ»¸öÒÔFOSS´ó¾Ö´æÔÚµÄÀÕË÷Èí¼þ¹¤¾ß°ü£¬ÓÉPython¿ª·¢£¬Ê¹ÓÃPyInstaller½øÐдò°ü¡£CryptoniteÓÃÓÚ¼ÓÃÜÎļþµÄ²½ÖèÊÇͨ¹ýPython¼ÓÃÜÄ£¿é£¬ËüʹÓÃFernetµÄʵÏÖÀ´ÌṩÕë¶ÔÕû¸öÖ¸±êÎļþµÄ128λAES£¬¼ÓÃÜÎļþµÄÀ©´óÃûĬÈϸü¸ÄΪ.cryptn8¡£Ò»µ©ËùÓÐÎļþ¶¼±»¼ÓÃÜ£¬Cryptonite¾Í»á³¢ÊÔʹÓÃipinfo.io´ÓÖ¸±êµÄIPµØÖ·¼ø±ðÆäµØÎ»£¬²¢ËûµÄ¸ø¼ÒÀï´òµç»°¡£
https://www.fortinet.com/blog/threat-research/Ransomware-Roundup-Cryptonite-Ransomware


¾©¹«Íø°²±¸11010802024551ºÅ