¶íÂÞ˹ÄÜÔ´¹«Ë¾GazpromÔ¼1.5 GBµÄÊý¾Ýй¶
°ä²¼¹¦·ò 2023-02-02
¾ÝýÌå1ÔÂ31ÈÕ±¨Â·£¬IT Army of UkraineÐû³ÆÒѾÈëÇÖÁ˶íÂÞ˹ÄÜÔ´¹«Ë¾GazpromµÄ»ù´¡ÉèÊ©£¬²¢»ñµÃÁË1.5 GBµÄÊý¾Ý¡£Ð¹Â¶µÄÊý¾ÝÉæ¼°Óë½ðÈں;¼Ã»î¶¯ÓйصÄÐÅÏ¢¡¢²âÊÔºÍ×ê̽»ã±¨ÒÔ¼°¿ÆÎ¬¿Ë͢˹»ù¾®×Ô¶¯»¯ÏµÍ³µÄÖ´Ðк͵÷Õû¡£´Ë±í£¬¸ÃÍŻﻹ°ä²¼ÁËÒ»·ÝÔ̺¬ÔÚGazpromºÍ̸Öеı£ÃÜÉêÃ÷¡£2022Äê4Ô£¬°²È«×êÑÐÈËÔ±Jeff CarrÔøÐ¹Â©£¬ ÎÚ¿ËÀ¼¹ú·À²¿µý±¨×ܾÖ(GURMOÒ»ÏòÔÚÕë¶ÔGazprom¡£
https://securityaffairs.com/141640/hacktivism/it-army-of-ukraine-hacked-gazprom.html
2¡¢Å·ÖÞÆû³µÁãÊÛÉÌArnold ClarkÔâµ½PlayÀÕË÷¹¥»÷
ýÌå2ÔÂ1Èճƣ¬Æû³µÁãÊÛÉÌArnold ClarkÔÚ֪ͨ²¿Ãſͻ§¹ØÓÚPlayÀÕË÷¹¥»÷µ¼ÖµÄÊý¾Ýй¶ÊÂÎñ¡£¸Ã¹«Ë¾×Ô³ÆÎªÅ·ÖÞ×î´óµÄ¶ÀÁ¢Æû³µÁãÊÛÉÌ£¬Æä±¾ÖܶþÔÚ·¢Ë͸ø±»Ó°Ïì¿Í»§µÄ֪ͨй©£¬±»µÁÊý¾ÝÔ̺¬Ó×ÎÒÉí·ÝÐÅÏ¢ºÍÒøÐÐÕÊ»§¾ßÌåÐÅÏ¢¡£¹¥»÷²úÉúÔÚ2022Äê12ÔÂ23ÈÕ£¬ÆäÓÚ12ÔÂ24ÈÕÉÏÎç¶Ï¿ªÁËϵͳµÄÍøÂçÀ´¶Â½Ø¹¥»÷ÕߵĽӼû¡£´ÓÄÇʱÆð£¬Arnold ClarkÒ»ÏòÔÚÖÂÁ¦ÓÚ¸´ÔÊÜËðϵͳ¡£¸Ã¹«Ë¾Òѽ«´ËÊÂ·î¸æ·¨Âɲ¿ÃźÍÓйص±¾Ö£¬²¢ÌáÐѿͻ§Ó×ÐÄDZÔڵĴ¹µö»î¶¯¡£
https://www.bleepingcomputer.com/news/security/arnold-clark-customer-data-stolen-in-attack-claimed-by-play-ransomware/
3¡¢EclypsiumÅû¶AMI MegaRAC BMCÈí¼þÖеĶà¸ö·ì϶
EclypsiumÔÚ1ÔÂ30ÈÕÅû¶ÁËAMI MegaRAC»ù°åÖÎÀí½ÚÔìÆ÷(BMC)Èí¼þÖеÄÁ½¸ö·ì϶¡£×êÑÐÈËÔ±×î³õ·¢ÏÖÁËÎå¸ö·ì϶²¢½«ËüÃÇͳ³ÆÎªBMC&C£¬ÆäÖÐÈý¸öÒÑÓÚ2022Äê12Ô·ÝÅû¶£¬Áí±íÁ½¸ö±£Áôµ½´Ë¿ÌÊÇΪAMIÌṩ¸ü¶à¹¦·òÀ´Éè¼ÆÊʵ±µÄ»º½â´ëÊ©¡£ÕâÁ½¸ö·ì϶±ðÀëΪͨ¹ýAPI½øÐÐÃÜÂë³ÁÖÃÀ¹½ØµÄ·ì϶£¨CVE-2022-26872£©ºÍRedfishºÍAPIµÄÈõÃÜÂëhash·ì϶£¨CVE-2022-40258£©¡£Ä¿Ç°£¬¼¼¼Î¡¢»ÝÆÕ¡¢Ó¢ÌضûºÍåÚÏë¶¼°ä²¼Á˸üУ¬NVIDIAÔ¤¼Æ»áÔÚ5Ô°䲼½¨¸´·¨Ê½¡£
https://eclypsium.com/2022/12/05/supply-chain-vulnerabilities-put-server-ecosystem-at-risk/
4¡¢×êÑÐÈËÔ±·¢ÏÖ¶à¸ö¼ÙÒâChatGPTµÄÀûÓÃÖ¼ÔÚÇÔÊØÐÅÏ¢
¾Ý1ÔÂ31ÈÕ±¨Â·£¬×êÑÐÈËÔ±ÔÚiOSºÍPlay Store·¢ÏÖÁ˶à¸ö¼ÙðµÄChatGPT¿Ë¡ÀûÓ㬻áÍøÂçÓû§Êý¾Ý²¢·¢Ë͵½Ô¶³Ì·þÎñÆ÷¡£ChatGPTÊÇOpenAIÓÚ2022Äê11ÔÂÍÆ³öµÄ̸Ìì»úеÈË£¬²¢Ã»ÓкÏÓÃÓÚiOS»òPlay StoreµÄ¹Ù·½ÀûÓ÷¨Ê½¡£×êÑÐÈËÔ±·ÖÎöÁËÈí¼þÉ̳ÇÖÐÅÅÃû×î¸ßµÄÊ®¸ö¿Ë¡ÀûÓã¬ËüÃǶ¼ÔÚÍøÂçºÍ¹²ÏíÒþÖÔ±£»¤Ç·°²µÄÊý¾Ý¡£³ö¸ñÊÇÆäÖеÄÒ»¸öAndroidÀûÓã¬ÏÂÔØÁ¿Òѳ¬¹ý100000£¬»á¸ú×Ù²¢Óë×Ö½ÚÌø¶¯ºÍÑÇÂíÑ·µÈ¹«Ë¾¹²ÏíµØÎ»Êý¾Ý¡£
https://www.hackread.com/chatgpt-clone-apps-collect-ios-play-store/
5¡¢Ó¢¹úPlanet IceµÄϵͳ±»ºÚ³¬¹ý24ÍòÈ˵ÄÐÅϢй¶
ýÌå2ÔÂ1ÈÕ±¨Â·£¬Ó¢¹úPlanet Ice³ÆºÚ¿ÍÈëÇÔìäϵͳ²¢ÇÔÈ¡ÁË240488¸ö¿Í»§µÄ¾ßÌåÐÅÏ¢¡£ÉÏÖܳõ£¬Óû§ÔÚÍøÉ϶©Æ±Ê±ÊÕµ½ÁËÒ»Ìõ¼ò¶ÌµÄÐÂÎÅ£¬Ú¹ÊÍ˵Planet IceµÄ·þÎñÆ÷ÔÚ¾Àú´òËã±íµÄÍ£»ú¡£Ö®ºó£¬²¿Ãſͻ§ÊÕµ½À´×ÔPlanet IceµÄÓʼþ£¬Ð¹Â©ËüµÄIce AccountϵͳÔâµ½¹¥»÷£¬Î´¾ÊÚȨµÄ¸÷·½¿É½Ó¼ûϵͳµÄ·Ç²ÆÕþÐÅÏ¢¡£¸Ã¹«Ë¾Òѽ«Õâ´ÎÎ¥¹æÊÂÎñ֪ͨICO£¬²¢¶ÔÆä·¢Õ¹µ÷²é¡£
https://www.bitdefender.com/blog/hotforsecurity/planet-ice-hacked-240-000-skating-fans-details-stolen/
6¡¢ESET°ä²¼¹ØÓÚ2022ÄêT3 APT¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨
1ÔÂ31ÈÕ£¬ESET°ä²¼2022ÄêT3 APT»î¶¯·ÖÎö»ã±¨£¬×ܽáÁË´Ó2022Äê9ÔÂÖÁ12Ôµ׹۲졢µ÷²éºÍ·ÖÎöµÄÌØ¶¨APT×éÖ¯µÄ»î¶¯¡£ÔÚ¼à²âµÄ¹¦·òÄڵĻÔ̺¬£¬Õë¶ÔÎÚ¿ËÀ¼²¿Êð·ÛËéÐÔµÄÊý¾Ý²Á³ý·¨Ê½ºÍÀÕË÷Èí¼þµÄ»î¶¯¡¢Õë¶ÔÈÕ±¾ÕþÖÎ×éÖ¯µÄMirrorFaceÓã²æÊ½´¹µö»î¶¯¡¢POLONIUM¹¥»÷ÒÔÉ«Áй«Ë¾µÄ±í¹ú×Ó¹«Ë¾ÒÔ¼°Ó볯ÏÊÓйصÄ×éÖ¯ÀûÓþɷì϶À´ÈëÇÖ¼ÓÃÜÇ®±Ò¹«Ë¾ºÍÂòÂôËùµÈ»î¶¯¡£
https://www.welivesecurity.com/wp-content/uploads/2023/01/eset_apt_activity_report_t32022.pdf


¾©¹«Íø°²±¸11010802024551ºÅ