Mixin Network±»ºÚËðʧ¸ß´ï2ÒÚÃÀÔª²¢ÔÝÍ£ÔËÓª

°ä²¼¹¦·ò 2023-09-26

1¡¢Mixin Network±»ºÚËðʧ¸ß´ï2ÒÚÃÀÔª²¢ÔÝÍ£ÔËÓª


¾Ý9ÔÂ25ÈÕ±¨Â·£¬Î»ÓÚÖйúÏã¸ÛµÄ¼ÓÃÜÇ®±Ò¹«Ë¾Mixin NetworkÔâµ½ÍøÂç¹¥»÷£¬Ëðʧ¸ß´ï2ÒÚÃÀÔª ¡£Õâ´ÎÊÂÎñ²úÉúÔÚ9ÔÂ23ÈÕÁ賿£¬¸Ã¹«Ë¾µ±¼´ÔÝÍ£ÁË´æ¿îºÍÈ¡¿î ¡£¾Ý³Æ¹¥»÷ÕßÄܹ»½Ó¼ûMixin NetworkÔÆ·þÎñÌṩÉ̵ÄÊý¾Ý¿â£¬ÇÔÈ¡Ö÷ÍøÉϵIJ¿ÃÅ×ʲú ¡£PeckShieldµÈÇø¿éÁ´×·×ÙÆ÷ÒѼø±ð³öÔ¼1.41ÒÚÃÀÔªµÄ±»µÁ×ʲú£¬ÆäÖÐ9350ÍòÃÀԪΪETH£¬2350ÍòÃÀԪΪDAI£¨´ÓUSDT»»À´£©£¬2330ÍòÃÀԪΪBTC ¡£


https://www.bleepingcomputer.com/news/security/mixin-network-suspends-operations-following-200-million-hack/


2¡¢°Ä´óÀûÑÇTissuPathÒò¹©¸øÉ̱»¹¥»÷446 GBÊý¾Ýй¶


¾ÝýÌå9ÔÂ21ÈÕ±¨Â·£¬°Ä´óÀûÑÇרҵ²¡Àíѧ¹«Ë¾TissuPathÔâµ½¹¥»÷µ¼ÖÂÊý¾Ýй¶ ¡£¸ÃÊÂÎñ²úÉúÓÚ8ÔÂ24ÈÕ£¬Ô´ÓÚTissuPathµÄÒ»¼ÒµÚÈý·½¹©¸øÉÌÔâµ½¹©¸øÁ´¹¥»÷ ¡£µ÷²é·¢ÏÖ£¬ÓÉÓÚÔ¶³Ì½Ó¼û¹¤¾ß°ü(RAT)´æÔÚ·ì϶£¬¹©¸øÉ̵ÄϵͳºÍÓû§ÕÊ»§±»ÈëÇÖ ¡£ÕâЩºÏ·¨µÄÖÎÀíÔ¹ØË»§±»·ÂÕÕ£¬ÒÔ½øÈëTissuPathµÄϵͳ£¬¹¥»÷Õß¿ÉÄÜ»ñµÃÁË2011ÄêÖÁ2020ÄêÏòTissuPath·¢³öµÄ²¡Àíת½é ¡£9ÔÂ2ÈÕ£¬AlphVÐû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü£¬²¢ÔÚ9ÔÂ5ÈÕ³Æ446 GBºÍ735414¸öÎļþÒѱ»Ð¹Â¶ ¡£


https://www.databreaches.net/tissupaths-data-breach-notice-provides-details-about-how-they-were-attacked-and-their-incident-response/


3¡¢Google³ÆAppleºÍChrome·ì϶±»ÓÃÓÚ×°ÖÃPredator


ýÌå9ÔÂ22ÈÕ±¨Â·£¬Googleй©AppleÔÚÉÏÖÜËĽ¨¸´µÄÈý¸ö·ì϶Òѱ»ÀÄÓã¬×÷ΪװÖüäµýÈí¼þPredatorµÄ·ì϶ÀûÓÃÁ´µÄÒ»²¿ÃÅ ¡£½ñÄê5ÔÂÖÁ9Ô£¬¹¥»÷ÕßÀûÓÃÕâЩ·ì϶£¨CVE-2023-41991¡¢CVE-2023-41992ºÍCVE-2023-41993£©£¬Í¨¹ýµö¶ü¶ÌÐźÍWhatsAppÐÂÎÅ£¬Õë¶Ô°£¼°Ç°¹ú»áÒéÔ±Ahmed EltantawyÖ´Ðй¥»÷ ¡£Google TAG»¹¹Û²ìµ½Chrome·ì϶£¨CVE-2023-4762£©Ò²±»ÓÃÓÚÕë¶Ô°£¼°µÄAndroidÉ豸װÖÃPredator ¡£Apple³ÆiOSËø¶¨Ä£Ê½Äܹ»·ÀÓù´ËÀ๥»÷ ¡£


https://www.bleepingcomputer.com/news/security/recently-patched-apple-chrome-zero-days-exploited-in-spyware-attacks/


4¡¢Akamai·¢ÏÖÀûÓÃÐéαBookingÍøÕ¾µÄ¸´ÔÓ´¹µö»î¶¯


AkamaiÔÚ9ÔÂ21ÈճƷ¢ÏÖÁËÕë¶Ô¾ÆµêÐÐÒµµÄ¸´ÔӵĴ¹µö»î¶¯ ¡£ÔÚԭʼָ±ê£¨¾Æµê£©ÉÏÖ´ÐÐÐÅÏ¢ÇÔÈ¡·¨Ê½ºó£¬¹¥»÷ÕßÄܹ»½Ó¼ûÓë¿Í»§Ö®¼äµÄÐÂÎÅ ¡£¹¥»÷ÕßÓë×îÖÕÖ¸±êÖ®¼ä³ÉÁ¢¿ÉÐŵÄͨѶÇþ·ºó£¬¾Í¼Ù×°³É¾Æµê¡¢Ô¤Ô¼·þÎñ»ò¹Û¹âÉç·¢ËÍ´¹µöÐÅÏ¢£¬ÒªÇó½øÐжî±íµÄÐÅÓþ¿¨ÑéÖ¤ ¡£¹¥»÷Õß»¹Ñ¡È¡Á˶àÖÖ°²È«ÑéÖ¤ºÍ·´·ÖÎö¼¼Êõ£¬ÈôÊÇÖ¸±êͨ¹ýÕâЩ²âÊÔ£¬½«»á¿´µ½Ò»¸ö¼Ù×°³ÉBooking.com¸¶¿îÒ³ÃæµÄ´¹µöÍøÕ¾£¬ÒªÇóÐÅÓþ¿¨ÐÅÏ¢ ¡£¹¥»÷Õß»¹Ôö³¤ÁËÖÇÄÜ̸ÌìÖ§³ÖÇþ·£¬ÒÔÈ·±£´¹µö»î¶¯µÄ¿ÉÐÅ¶È ¡£


https://www.akamai.com/blog/security-research/sophisticated-phishing-campaign-targeting-hospitality


5¡¢ESETÅû¶OilRigÕë¶ÔÒÔÉ«ÁеÄÁ½´Î¹¥»÷»î¶¯µÄϸ½Ú


9ÔÂ22ÈÕ£¬ESETÅû¶ÁËOilRigÕë¶ÔÒÔÉ«ÁÐʵÌåµÄÁ½´Î¹¥»÷»î¶¯£¬¼´Outer Space(2021Äê)ºÍJuicy Mix(2022Äê) ¡£ÕâÁ½´Î¹¥»÷»î¶¯Ê¹ÓÃÁËÒ»ÑùµÄÕ½Êõ£ºOilRigÊ×ÏÈÈëÇÖÒ»¸öºÏ·¨ÍøÕ¾ÓÃ×÷C&C·þÎñÆ÷£¬¶øºóʹÓÃVBS droppers·Ö·¢C# /.NETºóÃÅ£¬Í¬Ê±»¹²¿ÊðÁ˸÷ÀàÓÃÓÚÔÚÖ¸±êϵͳÉϽøÐÐÊý¾Ýй¶µÄ¹¤¾ß ¡£Outer Space»î¶¯Ê¹ÓÃÁËеĺóÃÅSolarºÍеÄÏÂÔØ·¨Ê½SampleCheck5000£¨»òSC5k£©£¬Juicy Mix»î¶¯¶ÔSolar½øÐиĽø²¢´´½¨Á˺óÃÅMango ¡£


https://www.welivesecurity.com/en/eset-research/oilrigs-outer-space-juicy-mix-same-ol-rig-new-drill-pipes/


6¡¢Kaspersky°ä²¼2023ÄêÉϰëÄêÎïÁªÍøÍþвµÄ·ÖÎö»ã±¨


9ÔÂ21ÈÕ£¬Kaspersky°ä²¼ÁË2023ÄêÉϰëÄêÎïÁªÍøÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨ ¡£ÎïÁªÍøÏ°È¾õè¾¶ÖØÒªÊDZ©Á¦ÆÆ½âºÍÀûÓÃÍøÂç·þÎñÖеķì϶ ¡£Ã۹޼ͼÏÔʾ£¬2023ÄêÉϰëÄê97.91%µÄ±©Á¦ÆÆ½â³¢ÊÔ¼¯ÖÐÔÚTelnetÉÏ£¬½ö2.09%Õë¶ÔSSH ¡£2023ÄêÉϰëÄ꣬¸÷Àà°µÍøÉÏ×ܹ²°ä²¼ÁË700¶àÌõÕë¶ÔDDoS¹¥»÷·þÎñµÄ¸æ°× ¡£ÔÚIoT¶ñÒâÈí¼þÁìÓò´æÔÚ´óÁ¿±äÌ壬ÆäÖкܶàÔ´×Ô2016 Mira¶ñÒâÈí¼þ ¡£½Ù³ÖÉ豸²¢Ê¹ÓÃËüÌáÒéÕë¶Ô¸÷Àà·þÎñµÄDoS¹¥»÷µÄľÂíÊÇ×î³£¼ûµÄIoT¶ñÒâÈí¼þÀàÐÍ ¡£


https://securelist.com/iot-threat-report-2023/110644/