YandexÔ̺¬Ô´´úÂëÔÚÄÚµÄ44.7GBÊý¾Ý±»°ä²¼ÔÚºÚ¿ÍÂÛ̳
°ä²¼¹¦·ò 2023-01-30
¾ÝýÌå1ÔÂ29ÈÕ±¨Â·£¬ºÚ¿ÍÔÚBrached ForumsÉϰ䲼ÁËYandexµÄ44.7 GBÊý¾Ý£¬ÆäÖÐÔ̺¬Ô´´úÂë´æ´¢¿â¡£YandexÒ²³ÆÎª¶íÂÞ˹¹È¸è£¬Õâ´Îй¶²»Éæ¼°Óû§ºÍÔ±¹¤µÄÊý¾Ý£¬µ«ÊÇÔ̺¬1900¶à¸öÓÃÓÚ¶ÔËÑË÷Á˾ֽøÐÐÅÅÃûµÄ³É·Ö¡£Yandex°µÊ¾Ëü֪·´Ëй¶£¬²¢ÇÒÒѾÆðÍ·µ÷²éÆäÔÒò¡£µ«Æä·ñ¶¨Ôâµ½Á˺ڿ͹¥»÷£¬²¢Ð¹Â©¸ÃÊÂÎñ¿ÉÄÜÓ빫˾µÄǰ¹ÍÔ±Óйء£YandexʱʱÔâµ½ÍøÂç¹¥»÷£¬2016ÄêÆä630Íò¸öÓû§µÄÊý¾Ý±»ÏúÊÛ£¬2021Äê9ÔÂÓÖÔâµ½ÁËÉæ¼°200000¸ö±»Ï°È¾ÎïÁªÍøÉ豸µÄDDoS¹¥»÷¡£
https://www.hackread.com/yandex-source-code-hacked-leaked/
2¡¢Killnet DDoS¹¥»÷µÂ¹ú»ú³¡¡¢ÐÐÕþ»ú¹¹ºÍÒøÐеÄÍøÕ¾
ýÌå1ÔÂ29ÈÕ±¨Â·³Æ£¬ºÚ¿Í×éÖ¯KillnetÊÇÕë¶ÔµÂ¹ú»ú³¡¡¢ÐÐÕþ»ú¹¹ºÍ½ðÈÚ×éÖ¯ÍøÕ¾µÄDDoS¹¥»÷µÄÄ»ºóºÚÊÖ¡£½²»°È˳ƣ¬Áª¹úÍøÂ簲ȫ¾Ö£¨BSI£©ÔÚµ÷²éÕë¶ÔµÂ¹ú×éÖ¯µÄDDoS¹¥»÷£¬ÕâЩ¹¥»÷ÖØÒªÕë¶Ô»ú³¡ÍøÕ¾£¬½ðÈÚÐÐÒµÒÔ¼°Áª¹úºÍÖݵ±¾ÖµÄÍøÕ¾¡£KillnetÔÚÆäTelegramƵ·Éϰ䷢ÁËÕâЩ¹¥»÷£¬ÕâÊǸÃ×éÖ¯µÄ¹ßÓÃ×ö·¨¡£BSI°µÊ¾£¬¶ÔÐÐÕþ²¿ÃŵĹ¥»÷ÔںܴóˮƽÉÏÒѱ»×èÖ¹£¬Ã»ÓÐÔì³ÉÑϳÁµÄÓ°Ïì¡£
https://securityaffairs.com/141513/hacktivism/killnet-targets-germany.html
3¡¢ÀÍÑάÑǹú·À²¿Ôâµ½ºÚ¿ÍÍÅ»ïGamaredonµÄ´¹µö¹¥»÷
ýÌå1ÔÂ28Èճƣ¬ÀÍÑάÑǹú·À²¿Ôâµ½ÁËGamaredonµÄ´¹µö¹¥»÷¡£¹ú·À²¿Ð¹Â©ºÚ¿Í¼ÙÒâÎÚ¿ËÀ¼µ±¾Ö¹ÙÔ±ÏòÆä¼¸ÃûÔ±¹¤·¢ËÍ´¹µöÓʼþ£¬µ«²¢Î´³É¹¦¡£¹¥»÷»î¶¯µÄϰȾÁ´ÎªHTMLSmuggling -> ZIP -> LNK -> HTA£¬»¹Ê¹ÓÃÁËÓòÃûadmou[.]orgÀ´·¢ËÍÓʼþ£¬¸ÃÓò±»ÒÔΪÓëGamaredonÓÐÓйØÁª¡£Ä¿Ç°£¬µ÷²éÈÔÔÚ½øÐÐÖС£GamaredonÖØÒªÕë¶ÔÎÚ¿ËÀ¼£¬CERT-UA³Æ2022ÄêÎÚ¿ËÀ¼¼Í¼ÁË70¶àÆðÓë¸ÃÍÅ»ïÓйصĹ¥»÷ÊÂÎñ¡£
https://therecord.media/latvia-confirms-phishing-attack-on-ministry-of-defense-linking-it-to-russian-hacking-group/
4¡¢Î¢Èí³ÆÂ·ÓÉÆ÷IP¸ü¸Äµ¼ÖÂMicrosoft 365Öжϳ¤´ïÎåÓ×ʱ
¾Ý1ÔÂ27ÈÕ±¨Â·£¬Î¢Èíй©ÉÏÖÜMicrosoft 365ÔÚÈ«ÇòÁìÓòÄÚÀï¶Ï³¤´ïÎåÓ×ʱÊÇÓÉ·ÓÉÆ÷IPµØÖ·¸ü¸ÄÒýÆðµÄ£¬¸Ã¸ü¸Äµ¼ÖÂÆä¹ãÓòÍø(WAN)ÖÐËùÓÐÆäËü·ÓÉÆ÷Ö®¼äµÄÊý¾Ý°üת·¢³öÏÖÎÊÌâ¡£Redmond»¨ÁËÎå¸ö¶àÓ×ʱ²Å½â¾öÁËÕâ¸öÎÊÌ⣬´Ó2023Äê1ÔÂ25ÈÕ07:05µ½12:43¡£Î¢Èí»¹Ð¹Â©£¬µ±Ê¹ÓÃδ¾³¹µ×Éó²éÇÒÔÚ·ÖÆçÍøÂçÉ豸ÉÏÓµÓÐ·ÖÆçҵΪµÄºÅÁî¸ü¸ÄWAN·ÓÉÆ÷µÄIPµØÖ·Ê±£¬»á´¥·¢¸ÃÎÊÌâ¡£ÔÚ´ËÊÂÎñÖ®ºó£¬Î¢Èí°µÊ¾Ëü´Ë¿ÌÔÚ×èÖ¹Ö´ÐÐÓ°ÏìºÜ´óµÄºÅÁ²¢ÇÒ»¹½«ÒªÇóËùÓкÅÁîµÄÖ´Ðж¼×ñѰ²È«ÅäÖøü¸ÄµÄ×¼Ôò¡£
https://www.bleepingcomputer.com/news/microsoft/massive-microsoft-365-outage-caused-by-wan-router-ip-change/
5¡¢SOLAR INDUSTRIES INDIAÔ¼2TBµÄ¾üʰÂÃØÊý¾Ýй¶
ýÌå1ÔÂ27ÈÕ±¨Â·£¬ÀÕË÷ÍÅ»ïBlackCat³ÆÒÑÈëÇÖSOLAR INDUSTRIES INDIA²¢ÇÔÈ¡ÁË2TBµÄ¾üʰÂÃØÊý¾Ý¡£¸Ã¹«Ë¾ÊÇÈ«Çò¹«ÈϵĹ¤Òµ»ðÒ©Ôì×÷ÉÌ£¬ÌṩÆëÈ«µÄ±¬ÆÆ½â¾ö¹æ»®¡£Ð¹Â¶Êý¾ÝÔ̺¬¹«Ë¾Ô±¹¤ºÍ¿Í»§µÄÓ×ÎÒÐÅÏ¢¡¢¸÷ÀàÆðÔ´µÄ¾ü±¸¹©¸øÁ´¡¢±øÆ÷µÄÀ¶Í¼ºÍ¹¤³ÌÎļþÒÔ¼°µ±¾ÖÎļþϸ½ÚµÈ¡£BlackCat°ä²¼Á˱»µÁÎļþµÄ½ØÍ¼ºÍ´Ó¹«Ë¾ÉãÏñÍ·ÅÄÉãµÄÕÕÆ¬×÷Ϊ¹¥»÷µÄÖ¤¾Ý¡£ÖµÍ×ÌùÐĵÄÊÇ£¬¸ÃÍÅ»ïÐû³ÆÕ¼ÓÐÔÚÆäËû¹ú¶È½øÐмäµý»î¶¯µÄÖ¤¾Ý¡£
https://securityaffairs.com/141409/data-breach/blackcat-ransomware-solar-industries-india.html
6¡¢¹ú¼Ê½áºÏ·¨ÂÉÐж¯³É¹¦²é»ñÀÕË÷Èí¼þHiveµÄ»ù´¡ÉèÊ©
¾ÝýÌå1ÔÂ26Èճƣ¬¹ú¼Ê½áºÏ·¨ÂÉÐж¯³É¹¦ÒѲé»ñÓëHiveÀÕË÷Èí¼þ¼´·þÎñ(RaaS)»î¶¯ÓйصĻù´¡ÉèÊ©¡£ÃÀ¹úDoJ°µÊ¾£¬FBIÓÚ2022Äê7ÔÂÉøÈëÁËHiveÊý¾Ý¿â·þÎñÆ÷£¬»ñµÃÁË336¸ö½âÃÜÃÜÔ¿²¢Ìṩ¸øÈ«ÇòÁìÓòÄÚ±»¹¥»÷µÄÖ¸±ê£¬½Ú¼óÁË1.3ÒÚÃÀÔªµÄÊê½ð¡£´Ë±í£¬FBI»ñµÃÁ˼ÓÀû¸£ÄáÑÇÒ»¼ÒÍйܷþÎñÌṩÉ̵ÄÁ½Ì¨×¨Ó÷þÎñÆ÷ºÍһ̨Ð鹹רÓ÷þÎñÆ÷µÄ½Ó¼ûȨ£¬ËûÃÇÓÉHive³ÉÔ±×âÓá£ÔÚе÷Ðж¯ÖУ¬ºÉÀ¼¾¯·½»¹»ñµÃÁ˶ÔÔÚºÉÀ¼ÍйܵÄÁ½¸ö±¸·ÝרÓ÷þÎñÆ÷µÄ½Ó¼ûȨ¡£
https://thehackernews.com/2023/01/hive-ransomware-infrastructure-seized.html


¾©¹«Íø°²±¸11010802024551ºÅ