AT&Tij¹©¸øÉ̱»ºÚµ¼ÖÂÆäÔ¼900Íò¿Í»§µÄÊý¾Ýй¶

°ä²¼¹¦·ò 2023-03-10

1¡¢AT&Tij¹©¸øÉ̱»ºÚµ¼ÖÂÆäÔ¼900Íò¿Í»§µÄÊý¾Ýй¶


¾Ý3ÔÂ9ÈÕ±¨Â·  £¬AT&T֪ͨԼ900Íò¿Í»§ÆäÐÅÏ¢ÒѾ­Ð¹Â¶  £¬ÓÉÓÚËüµÄÒ»¼ÒÓªÏú¹©¸øÉÌÔÚ1Ô·ÝÔâµ½Á˺ڿ͹¥»÷¡£Ð¹Â¶Êý¾ÝÔ̺¬¿Í»§ÐÕÃû¡¢ÎÞÏßÕʺš¢ÎÞÏߵ绰ºÅÂëºÍÓʼþµØÖ·µÈ  £¬ÒÔ¼°²¿Ãſͻ§µÄÎÞÏß·ÑÂÊ´òËã¡¢ÓâÆÚ½ð¶îºÍ¸¶¿î½ð¶îµÈ¡£¸Ã¹«Ë¾²¹³ä˵  £¬Æäϵͳ²¢Î´ÊÜÓ°Ïì  £¬Ð¹Â¶Êý¾ÝÖØÒªÓëÉ豸Éý¼¶×ʸñÓйØ¡£AT&T»Ø¾øÐ¹Â©¹©¸øÉ̵ÄÉí·Ý  £¬µ«The Register°µÊ¾  £¬µç×ÓÓʼþÓªÏú¹«Ë¾MailchimpÔÚ1Ô·ÝÔøÔâµ½¹¥»÷  £¬¹¥»÷Õß»ñµÃÁË100¶à¸ö¿Í»§ÕÊ»§µÄ½Ó¼ûȨÏÞ¡£


https://www.theregister.com/2023/03/09/att_wireless_breach/


2¡¢Ã÷Äá°¢²¨Àû˹¹«Á¢Ñ§ÌÃÑ§Çø±»MedusaÀÕË÷100ÍòÃÀÔª


ýÌå3ÔÂ8ÈÕ³Æ  £¬Ã÷Äá°¢²¨Àû˹¹«Á¢Ñ§ÌÃ(MPS)Ñ§Çø±»MedusaÍÅ»ïÀÕË÷100ÍòÃÀÔª¡£¸ÃÍŻォMPSÔö³¤µ½ÆäTorÍøÕ¾ÉÏ  £¬²¢ÍþвҪÔÚ3ÔÂ17ÈÕ֮ǰ°ä²¼´Ó¸ÃÑ§ÇøÇÔÈ¡µÄËùº±¼û¾Ý¡£¸ÃÊÂÎñÖ®ËùÒÔÒýÈËÖõÄ¿  £¬ÊÇÓÉÓÚ¹¥»÷ÕßÔì×÷ÁËÒ»¶Îʱ³¤Ô¼51·ÖÖÓµÄÊÓÆµ  £¬ÏÔʾ´ÓMPSÇÔÈ¡µÄÊý¾Ý¡£MPSÖÎÀí×ÅÔ¼100Ëù¹«Á¢ÖÐÓ×ѧ  £¬ËüÓÚ3ÔÂ1ÈÕ°ä²¼²¼¸æ  £¬Ð¹Â©Æä2ÔÂ21ÈÕÔâµ½¹¥»÷µ¼ÖÂϵͳÖжÏ¡£¸Ã×éÖ¯»¹°µÊ¾  £¬Ëü²»³ïË㸶Êê½ð  £¬¶øÊÇÑ¡ÔñʹÓÃÄÚ²¿±¸·Ý¸´Ô­±»¼ÓÃܵÄÊý¾Ý¡£


https://www.bleepingcomputer.com/news/security/ransomware-gang-posts-video-of-data-stolen-from-minneapolis-schools/


3¡¢Ó¡¶ÈHDFC Bank×Ó¹«Ë¾³¬¹ý7200Íò±Ê¼Í¼±»°ä²¼ÔÚ°µÍø


¾ÝýÌå3ÔÂ8ÈÕ±¨Â·  £¬ºÚ¿ÍKernelwareÔÚ°µÍøBreached forumÉϰ䲼ÁËHDB Financial ServicesÔ¼7.5 GBµÄ¿Í»§Êý¾Ý¡£HDB Financial ServicesÊÇÓ¡¶È×î´óµÄ¸öÈËÒøÐÐHDFC BankµÄ×Ó¹«Ë¾¡£Ð¹Â¶ÐÅÏ¢Ô̺¬³¬¹ý7200Íò±Ê¼Í¼  £¬Éæ¼°2022Äê5ÔÂÖÁ2023Äê2ÔÂÉêÇë´û¿îµÄHDBÏû·ÑÕß¡£HDFC Bank·ñ¶¨ÁËÊý¾Ýй¶ÊÂÎñ  £¬µ«HDB FinancialÒÑÈ·Èϲ¢ÔÚµ÷²é¸Ã°²È«ÊÂÎñ¡£ÖµÍ×ÌùÐĵÄÊÇ  £¬Kernelware¾ÍÊÇй¶ÁËAcerÔ¼160GBÊý¾ÝµÄºÚ¿Í¡£


https://www.hackread.com/hackers-india-hdfc-bank-data-leak/


4¡¢Veeam½¨¸´Ó°ÏìÆäËùÓÐVBR°æ±¾µÄ·ì϶CVE-2023-27532


3ÔÂ8ÈÕ±¨Â·³Æ  £¬Veeam°ä²¼¸üР £¬½¨¸´ÆäBackup & Replication²úÆ·Öеķì϶CVE-2023-27532¡£Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÔÚ»ñÈ¡´æ´¢ÔÚVeeamVBRÅäÖÃÊý¾Ý¿âÖеļÓÃÜÍ´´¦ºó  £¬ÀûÓÃËü½Ó¼û±¸·Ý»ù´¡¼Ü¹¹Ö÷»ú¡£Æ¾¾ÝVeeam²¼¸æ  £¬¸Ã·ì϶µ××ÓÔ­ÒòÊÇVeeam.Backup.Service.exe£¨Ä¬ÈÏÇé¿öÏÂÔÚTCP 9401ÉÏÔËÐУ©¿É±»Î´¾­Éí·ÝÑéÖ¤µÄÓû§ÓÃÀ´ÒªÇó¼ÓÃÜÍ´´¦¡£Veeam»¹ÌṩÁËһʱ½¨¸´²½Öè  £¬Ê¹Óñ¸·Ý·þÎñÆ÷·À»ðǽ×èÖ¹Óë¶Ë¿ÚTCP 9401µÄ±í²¿ÏνÓ¡£


https://www.bleepingcomputer.com/news/security/veeam-fixes-bug-that-lets-hackers-breach-backup-infrastructure/


5¡¢FortinetÅû¶8220 GangÀûÓÃScrubCryptµÄ¹¥»÷»î¶¯


FortinetÔÚ3ÔÂ8ÈÕÅû¶ÁË8220 Gang×î½üµÄ¼ÓÃܽٳֹ¥»÷¡£¹¥»÷²úÉúÔÚ2023Äê1ÔÂÖÁ2Ô  £¬¹¥»÷Á´Ê¼Óڳɹ¦ÀûÓÃÒ×±»¹¥»÷µÄOracle WebLogic ServerÏÂÔØÔ̺¬ScrubCryptµÄPowerShell¾ç±¾¡£PowerShell¾ç±¾ÒѾ­¹ý±àÂë  £¬À´Èƹý°²È«¹æ»®µÄ¼ì²â¡£ScrubCrypt¼ÓÃÜÆ÷ÔÚºÚ¿ÍÂÛ̳ÉÏÓÐÊÛ  £¬¿ÉʹÓùÖÒìµÄBAT´ò°ü²½Öè± £»¤ÀûÓ÷¨Ê½¡ £»ùÓڻÖÐʹÓõļÓÃÜÇ®°üµØÖ·ºÍMonero¿ó¹¤Ê¹ÓõķþÎñÆ÷IPµØÖ·  £¬×êÑÐÈËÔ±½«Õâ´Î»î¶¯¹éÒòÓÚ8220 Gang¡£


https://www.fortinet.com/blog/threat-research/old-cyber-gang-uses-new-crypter-scrubcrypt


6¡¢Kaspersky°ä²¼2022Äê¸ú×ÙÈí¼þÌ¬ÊÆµÄ·ÖÎö»ã±¨


3ÔÂ8ÈÕ  £¬Kaspersky°ä²¼ÁË2022Äê¸ú×ÙÈí¼þ£¨Stalkerware£©Ì¬ÊƵķÖÎö»ã±¨¡£Êý¾ÝÏÔʾ  £¬2022ÄêÈ«ÇòÓÐ29312¸öÓû§Êܵ½¸ú×ÙÈí¼þµÄÓ°Ïì  £¬¾ùÔÈÿÔÂÓÐ3333¸öÓû§Êܵ½¸ú×ÙÈí¼þµÄÓ°Ïì¡£¸ú×ÙÈí¼þÒÀÈ»ÊÇÒ»¸öÈ«ÇòÐÔÎÊÌâ  £¬Kaspersky¼ì²âµ½176¸ö¹ú¶È/µØÓòÊܵ½Ó°Ïì  £¬ÆäÖжíÂÞ˹£¨8281£©¡¢°ÍÎ÷£¨4969£©ºÍÓ¡¶È£¨1807£©ÊÜÓ°Ïì×îÑϳÁ¡£2022Äê¼ì²âµ½182ÖÖ·ÖÆçµÄ¸ú×ÙÈí¼þÀûÓà  £¬×î³£¼ûµÄÊÇReptilicus  £¬Æä´ÎÊÇCerberusºÍKeyLog¡£


https://securelist.com/the-state-of-stalkerware-in-2022/108985/