·áÌïÒâ´óÀû¹«Ë¾ÓªÏú¹¤¾ßµÄ½Ó¼ûȨÏÞй¶³¤´ïÒ»Äê°ë
°ä²¼¹¦·ò 2023-03-301¡¢·áÌïÒâ´óÀû¹«Ë¾ÓªÏú¹¤¾ßµÄ½Ó¼ûȨÏÞй¶³¤´ïÒ»Äê°ë
ýÌå3ÔÂ29ÈÕ±¨Â·³Æ£¬·áÌïÒâ´óÀû¹«Ë¾Òâ±íй¶ÁËÆäÓªÏú¹¤¾ßµÄ½Ó¼ûȨÏÞ¡£2ÔÂ14ÈÕ£¬CybernewsÍŶÓÔÚ·áÌïÒâ´óÀû¹Ù·½ÍøÕ¾ÉÏ·¢ÏÖÁËÒ»¸ö»·¾³Îļþ(.env)¡£Ëü¹«¿ªÁËÆäSalesforce Marketing CloudºÍMapbox APIµÄÍ´´¦£¬¹¥»÷Õß¿ÉÄÜ»áÀÄÓôËÐÅÏ¢À´»ñÈ¡·áÌï¿Í»§µÄµç»°ºÅÂëºÍÓʼþµØÖ·µÈÐÅÏ¢£¬²¢Ö´Ðд¹µö¹¥»÷¡£¸Ã»·¾³ÎļþÓÚ2021Äê5ÔÂ21ÈÕ³õ´Î±»IoTËÑË÷ÒýÇæ±àÈëË÷Òý£¬ÕâÒâζ×ÅËüÒѹ«¿ªÁËÒ»Äê°ëÒÔÉÏ¡£Ä¿Ç°£¬Ð¹Â¶Êý¾ÝÒѾ±»±£»¤ÆðÀ´¡£
https://cybernews.com/security/toyota-customer-data-leak/
2¡¢QNAP°ä²¼¸üУ¬½¨¸´ÆäNASÉ豸ÖеÄSudoÌáȨ·ì϶
¾Ý3ÔÂ29ÈÕ±¨Â·£¬QNAP½¨¸´ÁË»ùÓÚLinuxµÄÍøÂ總¼Ó´æ´¢(NAS)É豸ÖеÄSudoÌáȨ·ì϶¡£¸Ã·ì϶׷×ÙΪCVE-2023-22809£¬±»ÃèÊöΪ¡°ÔÚSudo1.9.12p1°æ±¾ÖÐʹÓÃsudoeditÊ±ÈÆ¹ýsudoersÕ½Êõ¡±¡£³É¹¦ÀûÓø÷ì϶£¬¹¥»÷ÕßÄܹ»Í¨¹ý½«ËÁÒâÌõ¿îÔö³¤µ½Òª´¦ÖõÄÎļþÁбíºó±à×ëδ¾ÊÚȨµÄÎļþÀ´ÌáÉýȨÏÞ¡£¸Ã¹«Ë¾ÒѾ½â¾öÁËQTSºÍQuTS heroƽ̨Öеķì϶£¬²¢ÔÚÖÂÁ¦ÌṩQuTScloudºÍQVP°²È«¸üС£
https://www.bleepingcomputer.com/news/security/qnap-warns-customers-to-patch-linux-sudo-flaw-in-nas-devices/
3¡¢ÃÀ¹ú¹ºÕ®¹«Ë¾NCBÔâµ½¹¥»÷½ü50Íò¿Í»§µÄ²ÆÕþÐÅϢй¶
¾ÝýÌå3ÔÂ29ÈÕ±¨Â·£¬ÃÀ¹ú¹ºÕ®¹«Ë¾NCB Management ServicesÔâµ½¹¥»÷£¬½ü50Íò¿Í»§µÄ²ÆÕþÐÅϢй¶¡£NCBÓÚ2ÔÂ4ÈÕ·¢ÏÖ£¬Î´¾ÊÚȨµÄµÚÈý·½ÓÚ2ÔÂ1ÈÕ»ñµÃÁËNCBϵͳµÄ½Ó¼ûȨÏÞ£¬²¢ÓÚ3ÔÂ8ÈÕÈ·ÈϿͻ§ÓëÃÀ¹úÒøÐÐÐÅÓþ¿¨ÕË»§ÓйصÄһЩÐÅϢй¶¡£¸ÃÊÂÎñÉæ¼°494969È˵ÄÐÕÃû¡¢¼ÝÕÕºÅÂë¡¢Éç»á°²È«ºÅÂë¡¢ÐÅÓþ¿¨ºÅÂ롢·ÓɺÅÂë¡¢ÕË»§Óà¶îºÍÕË»§×´Ì¬µÈ¡£ÃÀ¹úÒøÐн«ÎªÊÜÓ°ÏìµÄÓ×ÎÒÌṩExperian IdentityWorksSMÁ½ÄêµÄÉí·Ý͵ÇÔ±£»¤·þÎñ¡£
https://therecord.media/debt-buyer-cyberattack-data-breach
4¡¢ÐÂAPT43ÔÚ´ÓǰµÄ5ÄêÖÐÒ»Ïò¹¥»÷Å·ÃÀÈÕº«µÈµØÓòµÄ×éÖ¯
3ÔÂ28ÈÕ±¨Â·³Æ£¬Ð·¢ÏֵĺڿÍÍÅ»ïAPT43×Ô2018ÄêÒÔÀ´Ò»Ö¹Øë¶ÔÃÀ¹ú¡¢Å·ÖÞ¡¢ÈÕ±¾ºÍº«¹úÈ·µ±¾Ö¡¢Ñ§ÊõºÍÖÇÄÒÍÅÓйØ×éÖ¯¡£APT43ʹÓÃÓã²æÊ½´¹µöÓʼþÀ´ÇÔȡָ±êµÄÕÊ»§Í´´¦£¬¶øºóÒÔÖ¸±êÈËÎïµÄÉí·ÝµÇ¼²¢×ÔÐÐÖ´Ðеý±¨ÍøÂç¡£APT43»¹ÀûÓöñÒâAndroidÀûÓã¬Õë¶Ô¼ÓÃÜÇ®±ÒÁìÓò¡£Mandiant»ã±¨Ëµ£¬ÆäËû×êÑÐÈËÔ±ÔÚ´ÓÇ°Ôø·¢ÏÖÁËAPT43»î¶¯£¬µ«Í¨³£½«Æä¹éÒòÓÚKimsuky»òThalium¡£
https://www.mandiant.com/resources/reports/apt43-north-korea-cybercrime-espionage
5¡¢´óÁ¿Ä¾Âí»¯Torä¯ÀÀÆ÷×°Ö÷¨Ê½Õë¶Ô¶íÂÞ˹ºÍ¶«Å·µØÓò
3ÔÂ28ÈÕ£¬Kaspersky³ÆÆä·¢ÏÖÁË´óÁ¿Ä¾Âí»¯Torä¯ÀÀÆ÷×°Ö÷¨Ê½£¬ÖØÒªÕë¶Ô¶íÂÞ˹ºÍ¶«Å·µØÓò¡£ÕâЩװÖ÷¨Ê½Ô̺¬Ò»¸ö³ß¶È°æ±¾µÄTorä¯ÀÀÆ÷£¬ÒÔ¼°Ò»¸ö¶î±íµÄ¿ÉÖ´ÐÐÎļþ£¬°µ²ØÔÚÊÜÃÜÂë±£»¤µÄRARÖС£Torä¯ÀÀÆ÷ÔÚǰ̨Æô¶¯Ê±£¬¸ÃÎļþÔÚºó¶ÜÌáÈ¡¶ñÒâÈí¼þ¡£¸Ã¶ñÒâÈí¼þ»á¼à¶½¼ôÌù°åÖпÉʶ´ËÍâ¼ÓÃÜÇ®°üµØÖ·£¬²¢ÔÚ¼ì²âµ½Ê±½«Æä´úÌæÎª¹¥»÷ÕߵļÓÃÜÇ®±ÒµØÖ·¡£ÔÚ2022Äê8ÔÂÖÁ2023Äê2ÔÂÆÚ¼ä£¬×êÑÐÈËÔ±ÔÚ52¸ö¹ú¶È/µØÓò¼ì²âµ½16000¸ö´ËÀàTor×°Ö÷¨Ê½µÄ±äÌå¡£
https://securelist.com/copy-paste-heist-clipboard-injector-targeting-cryptowallets/109186/
6¡¢µçÐŹ«Ë¾LumenÅû¶Æä½üÆÚÔâµ½µÄÁ½Æð¹¥»÷ÊÂÎñµÄÏêÇé
3ÔÂ28ÈÕ±¨Â·£¬µçÐŹ«Ë¾Lumen TechnologiesÅû¶ÁËÆä½üÆÚÔâµ½µÄÁ½Æð¹¥»÷ÊÂÎñ¡£Ê×ÏÈ£¬¸Ã¹«Ë¾ÔÚÉÏÖÜ·¢ÏÔì䲿ÃÅÖ§³Ö·Ö¶ÎÍйܷþÎñµÄ·þÎñÆ÷ϰȾÁËÀÕË÷Èí¼þ¡£ÔÚ·¢ÏÖÀÕË÷¹¥»÷ºó£¬¸Ã¹«Ë¾¼Ó¹ÌÁ˰²È«Èí¼þ²¢·¢ÏÖÁËÁíһ·¹¥»÷ÊÂÎñ¡£ÔÚÕâµÚ¶þ´ÎÊÂÎñÖУ¬¹¥»÷ÕßÈëÇÖÁ˹«Ë¾µÄÄÚ²¿ÐÅÏ¢¼¼Êõϵͳ£¬×°ÖöñÒâÈí¼þ²¢ÇÔÈ¡Êý¾Ý¡£LumenÒѽ«´ËÊÂ֪ͨ·¨Âɲ¿ÃÅ£¬²¢ÏòÊÜÓ°ÏìµÄ¿Í»§»ã±¨ÁËÕâÒ»ÊÂÎñ¡£
https://securityaffairs.com/144113/hacking/lumen-suffered-ransomware-attack.html


¾©¹«Íø°²±¸11010802024551ºÅ