ÃÀ¹úPurFoodsÔâµ½ÀÕË÷¹¥»÷Ô¼120ÍòÓû§µÄÐÅϢй¶
°ä²¼¹¦·ò 2023-08-301¡¢ÃÀ¹úPurFoodsÔâµ½ÀÕË÷¹¥»÷Ô¼120ÍòÓû§µÄÐÅϢй¶
¾ÝýÌå8ÔÂ28ÈÕ±¨Â·£¬ÃÀ¹ú²ÍÒû¹«Ë¾PurFoods¶ÁËһ·ӰÏ쳬¹ý120ÍòÈ˵ÄÊý¾Ýй¶ÊÂÎñ¡£¸Ã¹«Ë¾³Æ£¬ËüÓÚ2ÔÂ22ÈÕ·¢ÏÔìäÍøÂçÉϵĿÉÒɻ¡£µ÷²éÈ·¶¨£¬¹¥»÷²úÉúÓÚ1ÔÂ16ÈÕÖÁ2ÔÂ22ÈÕ£¬µ¼Ö²¿ÃÅÎļþ±»¼ÓÃÜ¡£Éî¿Ìµ÷²éÓÚ7ÔÂ10ÈÕʵÏÖ£¬·¢ÏֺڿͽӼûÁ˼ÝÕÕ¡¢Éí·ÝÖ¤ºÅ¡¢½ðÈÚÕË»§ÐÅÏ¢¡¢Ö§¸¶¿¨ÐÅÏ¢ºÍÒ½ÖÎÐÅÏ¢µÈÊý¾Ý¡£Õâ´ÎÊý¾Ýй¶ӰÏìÁ˿ͻ§¡¢Ô±¹¤ÒÔ¼°¶ÀÁ¢³Ð°üÉÌ£¬Éæ¼°1237681ÈË£¬PurFoods½«Í¨¹ýKrollΪËûÃÇÌṩ12¸öÔµÄÐÅÓþ¼à¿ØºÍÉí·Ý±£»¤·þÎñ¡£
https://therecord.media/purfoods-delivery-service-reports-data-breach
2¡¢¶à¹ú½áºÏ·¨ÂÉÐж¯Duck Huntµ·»Ù½©Ê¬ÍøÂçQakbot
SymantecÔÚ8ÔÂ30Èճƣ¬·¨ÂÉÐж¯Duck Hunt³É¹¦µ·»ÙÁ˽©Ê¬ÍøÂçQakbot¡£¸ÃÐж¯ÓÉÃÀ¹úÁª¹úµ÷²é¾ÖºÍ˾·¨²¿Ç£Í·£¬ÒÔ¼°·¨¹ú¡¢µÂ¹ú¡¢ºÉÀ¼¡¢Ó¢¹ú¡¢ÂÞÂíÄáÑǺÍÀÍÑάÑǵȹú²Î¼Ó¡£·¨ÂÉÈËÔ±ÒÑ´Ó³¬¹ý70Íǫ̀±»Ï°È¾µÄÍÆËã»úÖÐɾ³ýÁËQakbot¶ñÒâÈí¼þ£¬²¢²é»ñÁ˼ÛÖµ860ÍòÃÀÔªµÄ¼ÓÃÜÇ®±Ò¡£QakbotÊÇÔËÐй¦·ò×µÄ½©Ê¬ÍøÂçÖ®Ò»£¬ÓÚ2007Äê³õ´Î³öÏÖ£¬½öÔÚ´Óǰ18¸öÔ¾ÍÒÑÔì³ÉÁ˳¬¹ý5800ÍòÃÀÔªµÄËðʧ¡£
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/qakbot-takedown-disruption
3¡¢¿ÕÖн»Í¨¹ÜÔìϵͳ崻úµ¼ÖÂÓ¢¹úº½°à´óÃæ»ýÈ¡µÞºÍÑÓÎó
¾Ý8ÔÂ28ÈÕ±¨Â·£¬Ó¢¹ú¿ÕÖн»Í¨¹ÜÔìϵͳ崻ú£¬ÊýÊ®Íò´î¿ÍµÄÐгÌÊܵ½Ó°Ïì¡£¹ú¶È¿ÕÖн»Í¨¹ÜÔìÌṩÉÌNATS³ÆËüÓöµ½ÁË¡°¼¼ÊõÎÊÌ⡱£¬²¢Ö´ÐÐÁ˽»Í¨Á÷Á¿ÏÞ¶ÈÒÔÊØ»¤°²È«¡£¸ÃÎÊÌâµ¼ÖÂÓ¢¹ú¸÷µØº½°à´óÃæ»ýÑÓÎóºÍÈ¡µÞ£¬»¹¶ÔÕû¸öÅ·Ö޵ĺ½°à²úÉúÁËÁ¬Ëø·´Ó³£¬Ò»Ð©º½¿Õ¹«Ë¾È¡µÞÁËÍù·µÓ¢¹úµÄº½°à¡£NATSÒѾÍÕâ´ÎÖжÏÊÂÎñÖÂǸ£¬²¢°µÊ¾ÔÚÖÂÁ¦ÒÔ¾¡¿ì½â¾öÎÊÌâ¡£
https://www.hackread.com/uk-air-traffic-control-system-collapses-travel-chaos/
4¡¢Sophos³ÆÀûÓ÷ì϶CVE-2023-3519µÄ¹¥»÷ÓëFIN8ÓйØ
8ÔÂ28ÈÕ±¨Â·£¬ÓëFIN8ÓйصĹ¥»÷ÕßÀûÓÃÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2023-3519£©¹¥»÷Citrix NetScaler¡£8ÔÂ2ÈÕ£¬Óл㱨³ÆÔÚCitrix·þÎñÆ÷Öз¢ÏÖÁË640¸öWebshell£¬Á½Öܺó£¬ÕâÒ»Êý×ÖÔö³¤µ½1952¸ö¡£Sophos³Æ£¬STAC4663ÔÚÀûÓø÷ì϶£¬²¢ÒÔΪÕâÊDZ¾ÔÂÔçЩʱ³½±¨Â·µÄͳһ»î¶¯µÄÒ»²¿ÃÅ¡£Sophos´§¶È£¬¸Ã»î¶¯ÓëFIN8Óп϶¨¹ØÁª£¬ÕâÒ»´§¶È»ùÓÚÓòÃûµÄ¿úËÅ¡¢plink¡¢BlueVPSÍйܡ¢²»Ñ°³£µÄPowerShell¾ç±¾ºÍPuTTY°²È«¸´Ôì¡£
https://www.bleepingcomputer.com/news/security/attacks-on-citrix-netscaler-systems-linked-to-ransomware-actor/
5¡¢×êÑÐÈËÔ±·¢ÏÖÄܹ»Í¨¹ýSkypeÀûÓÃÈ·¶¨Ö¸±êµÄIPµØÖ·
ýÌå8ÔÂ28Èճƣ¬×êÑÐÈËÔ±Yossi·¢ÏÖÄܹ»Í¨¹ýSkypeÒÆ¶¯ÀûÓ÷¢ËÍÁ´½ÓÀ´»ñȡָ±êµÄIPµØÖ·¡£¹¥»÷Ö»±ØÒªÖ¸±ê´ò¿ªÐÂÎż´¿É£¬²»±ØÖصã»÷Á´½Ó»òÒÔÆäËü·½Ê½Óë¹¥»÷Õß½»»¥¡£YossiÓÚ±¾Ô³õÏò΢Èí»ã±¨Á˸÷ì϶£¬µ«Î¢Èí×î³õµ»¯Á˸ÃÎÊÌ⣬²¢Ã»ÓаµÊ¾½«½¨¸´¸Ã·ì϶¡£°²È«¼ÇÕß²âÊÔ·¢ÏÖ£¬µ±Ê¹ÓÃVPNÏνӵ½Skypeʱ£¬ÒÔ¼°ÔÚ²»Ê¹ÓÃVPNµÄÇé¿öÏÂÏνӵ½¹«¹²Wi-FiÍøÂçʱ£¬¸Ã¼¼Êõ¶¼ÓÐЧ¡£ÔÙ´ÎÁªÏµÎ¢Èíºó£¬¸Ã¹«Ë¾°µÊ¾´òËãÔÚ¼´½«°ä²¼µÄ¸üÐÂÖнâ¾ö¸ÃÎÊÌâ
https://securityaffairs.com/150000/hacking/grabbing-ip-addr-via-skype-mobile-app.html
6¡¢Trend Micro°ä²¼ÐÂAndroid¶ñÒâÈí¼þMMRatµÄ·ÖÎö»ã±¨
8ÔÂ29ÈÕ£¬Trend Micro°ä²¼Á˹ØÓÚеÄAndroid¶ñÒâÈí¼þMMRatµÄ·ÖÎö»ã±¨¡£MMRatÓÚ6ÔÂÏÂÑ®³õ´Î±»·¢ÏÖ£¬ÖØÒªÕë¶Ô¶«ÄÏÑǵØÓò£¬²¢ÇÒÔÚVirusTotalµÈɱ¶¾É¨Ãè·þÎñÖÐÈÔδ±»·¢ÏÖ¡£ËüÄܹ»ÇÔÈ¡Óû§ÊäÈëºÍÆÁÄ»ÄÚÈÝ£¬»¹Äܹ»Í¨¹ý¸÷À༼ÊõÔ¶³Ì½ÚÔìÖ¸±êÉ豸£¬²¢Ö´ÐÐÒøÐÐڲơ£´Ë±í£¬¸Ã¶ñÒâÈí¼þʹÓÃÁË»ùÓÚºÍ̸»º³åÇø£¨±ðÃûProtobuf£©µÄÌØÊâϵ½ç˵C&CºÍ̸£¬¿ÉÌá¸ßÆäÔÚ´«Êä´óÁ¿Êý¾ÝʱµÄ»úÄÜ¡£Éв»È·¶¨¶ñÒâÈí¼þ×î³õÊÇÈôºÎ´«²¼µÄ£¬µ«ËüÊÇͨ¹ý¼Ù×°³É¹Ù·½ÀûÓÃÉ̵êµÄÍøÕ¾·Ö·¢µÄ¡£
https://www.trendmicro.com/en_us/research/23/h/mmrat-carries-out-bank-fraud-via-fake-app-stores.html


¾©¹«Íø°²±¸11010802024551ºÅ