ÂíÀ´Î÷ÑÇË®Îñ¹«Ë¾RanhillÊý¾Ý¿âºÍ±¸·Ý±»DESORDENɾ³ý
°ä²¼¹¦·ò 2023-07-281¡¢ÂíÀ´Î÷ÑÇË®Îñ¹«Ë¾RanhillÊý¾Ý¿âºÍ±¸·Ý±»DESORDENɾ³ý
¾ÝýÌå7ÔÂ26ÈÕ±¨Â·£¬DESORDENÍÅ»ïÐû³Æ¹¥»÷ÁËÂíÀ´Î÷ÑÇÖØÒªµÄË®ÎñºÍ¹©µç¹«Ë¾Ranhill Utilities Berhad¡£¹¥»÷Õß³ÆÆä»÷¹¥»÷ÁËRanhillµÄ¼Æ·ÑÒµÎñºÍ¹©Ë®ÒµÎñ£¬Ó°ÏìÁË100¶àÍò¿Í»§¡£²¢Ð¹Â©¹¥»÷ʼÓÚ2021Äê11Ô£¬Ö®ºóDESORDENÒ»Ïò´æÔÚÓÚËûÃǵÄϵͳÖС£½ñÄê7ÔÂ17ÈÕ£¬¹¥»÷ÕßÈëÇÖÁ˸ù«Ë¾µÄʵʱ¼Æ·ÑϵͳLIVE Billing£¬²¢ÓÚ7ÔÂ18ÈÕµ½19ÈÕ£¬ÇÔÈ¡Á˼ƷÑϵͳÖеÄËùº±¼û¾Ý¿â£¬²¢É¾³ýÁ˱¸·ÝºÍÊý¾Ý¿â¡£DESORDEN³ÆÒѾÇÔÈ¡Êý°ÙGBµÄÊý¾Ý£¬RanhillÉÐδ¶Ô´Ëʱ×÷³ö»ØÓ¦¡£
https://www.databreaches.net/major-malaysian-water-utilities-company-hit-by-hackers-ranhill-offline-hackers-claim-databases-and-backups-deleted/
2¡¢ÃÀ¹úµ±¾Ö·þÎñ³Ð°üÉÌMaximus³¬¹ý800ÍòÈ˵ÄÐÅϢй¶
¾Ý7ÔÂ26ÈÕ±¨Â·£¬ÃÀ¹úµ±¾Ö·þÎñ³Ð°üÉÌMaximusй©800ÖÁ1100ÍòÈ˵ÄÐÅϢй¶¡£MaximusÖØÒªÕÆ¹ÜÖÎÀíÃÀ¹úµ±¾ÖÔÞÖúµÄÏîÄ¿£¬ÄêÊÕÈëԼΪ42.5ÒÚÃÀÔª£¬ÒµÎñ±é¼°ÃÀ¹ú¡¢¼ÓÄô󡢰ĴóÀûÑǺÍÓ¢¹ú¡£µ÷²é·¢ÏÖ£¬ºÚ¿ÍÀûÓÃÁËMOVEit TransferÖеķì϶¡£7ÔÂ25ÈÕ£¬Clop½«MaximusÔö³¤µ½ÆäÍøÕ¾µÄ±»¹¥»÷Ö¸±êÁбíÖС£MaximusĿǰ´òËãÔÚ½ØÖÁ2023Äê6ÔÂ30Èյļ¾¶ÈÖмͼԼ1500ÍòÃÀÔªµÄÓöȣ¬ÕâÊǸù«Ë¾¶ÔÕâ´ÎÊÂÎñÓйصĵ÷²éºÍ²¹¾È»î¶¯ÓöÈ×ܶîµÄ¹ÀËã¡£
https://www.bleepingcomputer.com/news/security/8-million-people-hit-by-data-breach-at-us-govt-contractor-maximus/
3¡¢Ò½ÁÆÉ豸ÌṩÉÌCardioCommÔâµ½¹¥»÷·þÎñÁÙʱÖжÏ
ýÌå7ÔÂ26Èճƣ¬¼ÓÄôóÏûÐÄÔà¼à²â¼¼ÊõÌṩÉÌCardioComm SolutionsÔâµ½¹¥»÷£¬µ¼Ö·þÎñÁÙʱÖжϡ£¸Ã¹«Ë¾°µÊ¾£¬ÔÚÆä·þÎñÆ÷²úÉú°²È«ÊÂÎñºó£¬ÒµÎñÔËÓª½«Êܵ½ÊýÌìÉõÖÁ¸ü³¤¹¦·òµÄÓ°Ï졣Ŀǰ£¬CardioCommÍøÕ¾ÎÞ·¨½Ó¼û£¬²¢ÏÔʾ¡°GA»Æ½ð¼×·þÎñÔÚ¾ÀúÍ£»ú¡±¡£ÆäºÜ¶à²úÆ·Ò²Ó°Ï죬ÆäÖÐÔ̺¬Ò»¿îÊÖ³ÖʽÐĵçͼ(ECG)¼à²âÒÇHeartCheck CardiBeat£¬Ëü¿Éͨ¹ýÀ¶ÑÀÏνӵ½Óû§µÄÖÇÄÜÊÖ»ú½«¼ì²âÁ˾ִ«µÝ¸øÒ½Éú¡£´Ë¿ÌÉв»Ã÷ÏÔÖжÏÁìÓòÒÔ¼°ÊÂÎñÐÔÖÊ£¬µ«ÆäÔÚÖÂÁ¦¸´ÔÊý¾Ý²¢³Á½¨Æä·þÎñÆ÷»·¾³£¬ÕâÅú×¢¿ÉÄÜÊÇÀÕË÷¹¥»÷µÈ·ÛËéÐÔ¹¥»÷¡£
https://techcrunch.com/2023/07/26/cardiocomm-ecg-monitoring-cyberattack/
4¡¢Sophos·¢ÏÖÕë¶Ô±±ÃÀ¿Æ¼¼ºÍ·ÇͶ»ú×éÖ¯µÄNitrogen»î¶¯
SophosÔÚ7ÔÂ26ÈÕÅû¶ÁËÖØÒªÕë¶Ô±±ÃÀ¿Æ¼¼ºÍ·ÇͶ»ú×éÖ¯µÄNitrogen³õʼ½Ó¼û¶ñÒâÈí¼þ»î¶¯µÄϸ½Ú¡£¸Ã»î¶¯ÀûÓÃGoogleºÍBingËÑË÷¸æ°×À´ÍƹãαÔìµÄÈí¼þÍøÕ¾£¬Ö¼ÔÚ»ñµÃÆóҵϵͳµÄ½Ó¼ûȨÏÞ²¢²¿ÊðCobalt StrikeºÍºÍÀÕË÷Èí¼þµÈ¹¤¾ß¡£Nitrogen»î¶¯µÄµö¶üÈí¼þÔ̺¬AnyDesk¡¢WinSCP¡¢Cisco AnyConnectºÍTreeSize Free¡£Ä¿Ç°ÉÐδȷ¶¨¹¥»÷ÕßµÄÖ÷ÕÅ£¬µ«Ï°È¾Á´×¢Ã÷¿ÉÄÜÓÃÓÚ²¿ÊðÀÕË÷Èí¼þ¡£Trend MicroÔø±¨Â·¸Ã¹¥»÷Á´ÖÁÉÙÔÚÒ»¸ö¹¥»÷°¸ÀýÖÐ×°ÖÃÁËBlackCat¡£Google½²»°È˳ÆÒѾ¼ì²âµ½¶ñÒâ»î¶¯£¬²¢É¾³ýÁËÎ¥·´ÆäÕþ²ßµÄ¸æ°×¡£
https://news.sophos.com/en-us/2023/07/26/into-the-tank-with-nitrogen/
5¡¢Metabase QÅû¶Õë¶ÔÀ¶¡ÃÀÖ޵Ľ©Ê¬ÍøÂçFenixµÄ¹¥»÷
7ÔÂ26ÈÕ±¨Â·³Æ£¬Metabase Q·¢ÏÖÁËн©Ê¬ÍøÂçFenixµÄ¹¥»÷»î¶¯£¬ÖØÒªÕë¶ÔÄ«Î÷¸çºÍÖÇÀû½Ó¼ûµ±¾Ö·þÎñµÄÓû§¡£¸Ã»î¶¯¼ÙÒâÁËÄ«Î÷¸çServicio de Administraci¨®n Tributaria(SAT)ºÍÖÇÀûServicio de Impuestos Internos(SII)µÄ¹Ù·½ÃÅ»§ÍøÕ¾£¬²¢½«Ö¸±ê³Á¶¨Ïòµ½ÕâÐ©ÍøÕ¾¡£ÕâЩαÔìµÄÍøÕ¾ÌáÐÑÓû§ÏÂÔØËùνµÄ°²È«¹¤¾ß£¬ÕâÏÖʵÉÏ×°ÖÃÁ˶ñÒâÈí¼þµÄ³õʼ½×¶Î£¬×îÖջᵼÖÂÍ´´¦µÈÃô¸ÐÐÅϢй¶¡£
https://www.metabaseq.com/fenix-botnet/
6¡¢Netenrich°ä²¼»ùÓÚAIµÄºÚ¿Í¹¤¾ßFraudGPTµÄ·ÖÎö»ã±¨
7ÔÂ25ÈÕ£¬Netenrich°ä²¼ÁËÓÖÒ»¸ö»ùÓÚAIµÄкڿ͹¤¾ßFraudGPTµÄ·ÖÎö»ã±¨¡£ÕâÊÇÒ»Ó×ÎÒ¹¤ÖÇÄÜ»úеÈË£¬ÓÃÓÚ´´½¨Óã²æÊ½´¹µöÓʼþ¡¢ÆÆ½â¹¤¾ßÒÔ¼°Ë¢¿¨µÈ¡£¸Ã¹¤¾ßÖÁÉÙ×Ô7ÔÂ22ÈÕÆð¾ÍÆðÍ·ÔÚ¸÷Àà°µÍøÊг¡ºÍTelegramƽ̨ÉÏÏúÊÛ£¬¶©ÔÄÓöÈΪÿÔÂ200ÃÀÔª£¬»òÒ»Äê1700ÃÀÔª¡£¿ª·¢Õß»¹°µÊ¾£¬¸Ã¹¤¾ßÓµÓпª·¢¶ñÒâ´úÂë¡¢¿ª·¢ÎÞ·¨¼ì²âµÄ¶ñÒâÈí¼þºÍ²éÕÒ·ì϶µÈÖ°ÄÜ¡£ÓëFraudGPTÀàËÆµÄWormGPTÓÚ7ÔÂ13ÈÕ±»ÍƳö¡£
https://netenrich.com/blog/fraudgpt-the-villain-avatar-of-chatgpt


¾©¹«Íø°²±¸11010802024551ºÅ