Íйܹ«Ë¾CloudNordicÔâÀÕË÷¹¥»÷ËùÓпͻ§Êý¾ÝÃÔʧ

°ä²¼¹¦·ò 2023-08-24

1¡¢Íйܹ«Ë¾CloudNordicÔâÀÕË÷¹¥»÷ËùÓпͻ§Êý¾ÝÃÔʧ


¾Ý8ÔÂ23ÈÕ±¨Â·£¬µ¤ÂóÍйܹ«Ë¾CloudNordicºÍAzeroCloudÔâµ½ÀÕË÷¹¥»÷£¬´ó²¿Ãſͻ§µÄÊý¾ÝÃÔʧ¡£ÕâÁ½¸öÆ·ÅÆÊôÓÚͳһ¼Ò¹«Ë¾£¬¹¥»÷²úÉúÔÚ8ÔÂ18ÈÕÁ賿¡£¸Ã¹«Ë¾³ÎÇå²»»áÏò¹¥»÷Õß½»Êê½ð£¬µ«²»ÐÒµÄÊÇ£¬ÏµÍ³ºÍÊý¾Ý¸´Ô­¹ý³Ì²¢²»Ë³Àû£¬CloudNordicÃÔʧÁË´óÎÞÊý¿Í»§µÄËùº±¼û¾Ý¡£¾ÝϤ£¬Õâ´Î¹¥»÷½ö¼ÓÃÜÁËÊý¾Ý£¬Ã»ÓÐÈκÎÊý¾Ý±»½Ó¼û»òй¶¡£Õâ´Î¹¥»÷Ó°ÏìÁËÊý°Ù¼Òµ¤ÂóµÄ¹«Ë¾£¬ËûÃÇÃÔʧÁË´æ´¢ÔÚÔÆÖеÄËùÓÐÄÚÈÝ£¬Ô̺¬ÍøÕ¾¡¢µç×ÓÓʼþºÍÎĵµµÈ¡£Ä¿Ç°£¬¸Ã¹«Ë¾µÄÔËÓªÈÔ´æÔںܴóÎÊÌâ¡£


https://www.bleepingcomputer.com/news/security/hosting-firm-says-it-lost-all-customer-data-after-ransomware-attack/


2¡¢DuoLingo 260ÍòÓû§µÄÊý¾ÝÔÚBreachedÂÛ̳¹«¿ª


¾ÝýÌå8ÔÂ22ÈÕ±¨Â·£¬260ÍòDuoLingoÓû§µÄÊý¾ÝÔÚºÚ¿ÍÂÛ̳BreachedÉÏй¶¡£1Ô·Ý£¬ÓÐÈËÔøÔÚÒѹعصÄBreachedÉÏÒÔ1500ÃÀÔªµÄ¼ÛÖµÏúÊÛ260ÍòDuoLingoÓû§µÄÊý¾Ý£¬ÆäÖÐÔ̺¬µÇ¼Ãû¡¢ÕæÊµÐÕÃû¡¢ÓʼþµØÖ·ºÍDuoLingo·þÎñÓйصÄÄÚ²¿ÐÅÏ¢µÈ·Ç¹«¿ªÐÅÏ¢¡£8ÔÂ21ÈÕ£¬260ÍòÓû§Êý¾ÝÓÖ±»¹«¿ªÔÚаæBreachedÉÏ£¬½öÐè8¸öÕ¾µã»ý·Ö£¬¼ÛֵΪ2.13ÃÀÔª¡£ÕâЩÊý¾ÝÊÇͨ¹ýAPIץȡµÄ£¬¸Ã½Ó¿ÚÖÁÉÙ×Ô3ÔÂÆð¾ÍÒѹ«¿ª¡£


https://www.bleepingcomputer.com/news/security/scraped-data-of-26-million-duolingo-users-released-on-hacking-forum/


3¡¢ÃÀ¹ú¹ú·À¹«Ë¾BelcanÅäÖÃÃýÎ󳬵ÈÖÎÀíԱʹ´¦Ð¹Â¶


ýÌå8ÔÂ23Èճƣ¬ÃÀ¹úµ±¾ÖºÍ¹ú·À³Ð°üÉÌBelcanµÄ³¬µÈÖÎÀíԱʹ´¦Ð¹Â¶¡£5ÔÂ15ÈÕ£¬×êÑÐÍŶӷ¢ÏÖÁËÒ»¸öÊ¢¿ªµÄKibanaÊ·ý£¬Éæ¼°Belcan¼°ÆäÔ±¹¤ºÍ»ù´¡ÉèÊ©µÄÃô¸ÐÐÅÏ¢¡£Ð¹Â¶ÐÅÏ¢Ô̺¬ÖÎÀíÔ±µç×ÓÓʼþ¡¢ÖÎÀíÔ±ÃÜÂ루ʹÓÃbcrypt´¦Öã©¡¢ÖÎÀíÔ±Óû§Ãû¡¢ÖÎÀíÔ±½ÇÉ«ºÍÄÚ²¿ÍøÂçµØÖ·µÈ¡£ÕâЩÐÅÏ¢¿ÉÓÃÀ´¼ø±ð´æÔÚ·ì϶µÄÒ×±»¹¥»÷ϵͳ£¬²¢Ìṩ½Ï¸ßȨÏÞµÄÕÊ»§Í´´¦£¬½«¸øÕû¸ö¹©¸øÁ´´øÀ´·çÏÕ¡£Ä¿Ç°£¬¸ÃÎÊÌâÒѱ»½â¾ö¡£


https://cybernews.com/security/belcan-leaks-admin-password-flaws/


4¡¢SnatchÐû³ÆÒÑÈëÇÖÄϷǹú·À²¿²¢»ñÈ¡1.6 TBµÄÊý¾Ý


8ÔÂ22ÈÕ±¨Â·³Æ£¬ÀÕË÷ÍÅ»ïSnatch½«ÄϷǹú·À²¿Ôö³¤µ½ÆäÊý¾ÝÐ¹Â¶ÍøÕ¾¡£¸ÃÍÅ»ïÐû³ÆÇÔÈ¡Á˾üʺÏͬ¡¢ÄÚ²¿ºôºÅºÍÓ×ÎÒÐÅÏ¢µÈ£¬×ܼÆ1.6TBÊý¾Ý¡£ÈôÊÇÕâ´Î¹¥»÷µÃµ½Ö¤Êµ£¬»úÃÜÐÅÏ¢µÄй¶½«¶Ô²Î¼ÓºÏͬµÄ×éÖ¯×é³ÉÑϳÁ·çÏÕ¡£½ØÖÁĿǰ£¬¸ÃÊý¾ÝÐ¹Â¶ÍøÕ¾ÒÑÎÞ·¨½Ó¼û¡£2022Äê10Ô£¬SnatchÔøÐû³ÆÈëÇÖÁË·¨¹úHENSOLDT France£¬ÕâÊÇÒ»¼ÒרÃÅ´Óʾüʺ͹ú·Àµç×Ó²úÆ·µÄ¹«Ë¾¡£


https://securityaffairs.com/149760/cyber-crime/snatch-ransomware-department-of-defence-south-africa.html


5¡¢SymantecÅû¶CarderbeeÕë¶ÔÖйúÏã¸ÛµÄ¹¥»÷»î¶¯


8ÔÂ22ÈÕ£¬SymantecÅû¶ÁËCarderbeeÕë¶ÔÖйúÏã¸ÛµÄ¹¥»÷»î¶¯¡£×êÑÐÈËÔ±ÓÚ4Ô·¢ÏÖÁËCarderbeeµÄµÚÒ»¸ö»î¶¯¼£Ï󣬵«¹¥»÷»î¶¯»òÄܹ»×·Òäµ½2021Äê9Ô¡£¹¥»÷ÕßʹÓúϷ¨µÄCobra DocGuardÈí¼þÖ´Ðй©¸øÁ´¹¥»÷£¬Ö÷ÕÅÊÇÔÚÖ¸±êÍÆËã»úÉÏ×°ÖúóÃÅKorplug£¨±ðÃûPlugX£©¡£¹¥»÷»î¶¯»¹Ê¹ÓÃÁ˺Ϸ¨µÄMicrosoftÖ¤ÊéÊðÃûµÄ¶ñÒâÈí¼þ¡£¸Ã»î¶¯µÄ´óÎÞÊýÖ¸±êλÓÚÖйúÏã¸Û£¬Ò²ÓÐÒ»²¿ÃÅλÓÚÑÇÖÞµÄÆäËüµØÓò¡£×êÑÐÈËÔ±°µÊ¾£¬¹ØÓÚCarderbee»î¶¯ÈÔÓÐһЩδ½âÖ®ÃÕ£¬ºÃ±ÈÈ·ÇеÄÖ¸±êÁìÓòÈÔ²»Ã÷ÏÔ¡£


https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/carderbee-software-supply-chain-certificate-abuse


6¡¢Ó¢¹úIT¹«Ë¾Swan RetailÔâµ½¹¥»÷Ó°ÏìÊý°Ù¼ÒÁãÊÛÉÌ


ýÌå8ÔÂ22ÈÕ±¨Â·£¬Ó¢¹úIT¹«Ë¾Swan RetailÔâµ½ÍøÂç¹¥»÷£¬Ó°ÏìÁËÔ¼300¼ÒÁãÊÛÉÌ¡£8ÔÂ13ÈÕ£¬Õâ¼ÒÁãÊÛÖÎÀíºÍEPOS½â¾ö¹æ»®ÌṩÉÌ·¢ÏÖ¶à¸öºó¶Üϵͳ³öÏÖ¼¼ÊõÎÊÌ⣬µ¼Ö·þÎñÖжÏ¡£Æä°ä²¼ÉêÃ÷°µÊ¾Ôâµ½ÁËÍøÂç¹¥»÷²¢ÒÑѸ¿ì×ö³ö·´Ó³£¬µ«ÊÇûÓÐ×¢Ã÷¹¥»÷ÀàÐÍ¡£Õâ´Î¹¥»÷Ó°ÏìÁËÏÕЩËùÓÐÐÐÒµµÄ¶ÀÁ¢ÁãÊÛÉÌ£¬²¢¸øºÜ¶à¹©¸øÉÌ´øÀ´ÑϳÁµÄ¾­¼ÃËðʧ¡£¸Ã¹«Ë¾µÄ·þÎñ×ÔÖÜÈÕÒÔÀ´Ò»Ïò´¦ÓÚÔÝͣ״̬£¬Ä¿Ç°ÔÚ¸´Ô­ÖС£


https://www.hackread.com/cyberattack-uk-swan-retail-affects-retailers/