°®¶ûÀ¼¹ú¶È¾¯¾ÖµÄ³Ð°üÉÌй¶50ÍòÌõ¿ÛѺ³µÁ¾µÄ¼Í¼

°ä²¼¹¦·ò 2023-10-25

1¡¢°®¶ûÀ¼¹ú¶È¾¯¾ÖµÄ³Ð°üÉÌй¶50ÍòÌõ¿ÛѺ³µÁ¾µÄ¼Í¼


¾Ý10ÔÂ23ÈÕ±¨Â·£¬×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸ö¹«¿ªµÄÊý¾Ý¿â£¬Ô̺¬³¬¹ý50ÍòÌõÓë°®¶ûÀ¼¹ú¶È¾¯¾ÖGarda S¨ªoch¨¢na¿ÛѺ³µÁ¾Óйصļͼ¡£Îĵµ×ÜÊýΪ521043¸ö£¬´óÓ×Ϊ271.8 GB¡£Æ¾¾Ý°®¶ûÀ¼Ë¾·¨£¬µ±³µÁ¾±»¿ÛѺʱ£¬³µÖ÷Ðë³öʾÉí·ÝÖ¤Ã÷ºÍ±£ÏÕÎļþµÈ¶à·ÝÎļþ£¬Òò¶øÐ¹Â¶µÄ50Íò·ÝÎĵµ¿ÉÄÜÓ°ÏìÁËÔ¼15ÍòÃû³µÖ÷¡£½øÒ»´ëÊ©²éÏÔʾ£¬¸ÃÊý¾Ý¿âÊôÓÚ°®¶ûÀ¼ÀûĬÀï¿ËµÄÒ»¼Ò¸öÈ˼¼Êõ³Ð°üÉÌ¡£Ä¿Ç°£¬Ð¹Â¶Êý¾ÝÒѱ»±£»¤ÆðÀ´¡£


https://www.hackread.com/contractor-data-breach-irish-national-police-vehicle-seizure/


2¡¢ºÚ¿ÍÒÔ8ÍòÃÀÔª¼ÛÖµÏúÊÛ8.15ÒÚÌõÓ¡¶È¹«ÃñµÄPII¼Í¼


ýÌå10ÔÂ24Èճƣ¬ºÚ¿ÍÔÚ°µÍøÏúÊÛÊýÒÚÌõÓ¡¶È¹«ÃñµÄPII¼Í¼£¬Ô̺¬Aadhaar¿¨¡£AadhaarÊÇÒ»¸ö12λµÄÓ×ÎÒ¼ø±ðÂ룬ÓÉÓ¡¶ÈΨһÉí·Ý¼ø±ð»ú¹¹´ú±íÓ¡¶Èµ±¾ÖÐû¸æ¡£10ÔÂ9ÈÕ£¬ÃûΪpwn0001µÄºÚ¿ÍÔÚ°µÍø°ä²¼ÁËÒ»¸öÌû×Ó£¬³ÆÕ¼ÓÐ8.15ÒÚÓ¡¶È¹«ÃñAadhaarºÍ»¤Õռͼ£¬²¢Ô¸ÒâÒÔ80000ÃÀÔªµÄ¼ÛÖµÏúÊÛÕû¸öÊý¾Ý¿â¡£Í¬Ê±£¬pwn0001»¹¹«¿ªÁË4¸öÑù±¾£¬ÆäÖÐÒ»¸öÑù±¾Ô̺¬100000ÌõÓ¡¶È¾ÓÃñµÄPII¡£


https://securityaffairs.com/152957/security/pii-indian-citizens-dark-web.html


3¡¢BHI EnergyÏêÊöAkiraÈôºÎÈëÇÔìäϵͳ²¢ÇÔÈ¡Êý¾Ý


¾ÝýÌå10ÔÂ23ÈÕ±¨Â·£¬ÃÀ¹úÄÜÔ´¹«Ë¾BHI EnergyÅû¶ÁËAkiraÔÚ5ÔÂ30ÈÕÈëÇÔìäϵͳµÄ¾ßÌåÐÅÏ¢¡£AkiraʹÓÃÇÔÈ¡µÄµÚÈý·½µÄVPNƾ֤½Ó¼ûBGIµÄÄÚÍø£¬ÔÚ³õ´Î½Ó¼ûºóµÄÒ»ÖÜÄÚʹÓÃͳһ¸öÕË»§¶ÔÄÚÍø½øÐпúËÅ¡£6ÔÂ16ÈÕ£¬AkiraÔٴνӼûϵͳ£¬ÁоÙÊý¾Ý£¬²¢ÔÚ6ÔÂ20ÈÕÖÁ29ÈÕÇÔÈ¡ÁË767k¸öÎļþ£¬¹²690 GB£¬Ô̺¬Windows Active DirectoryÊý¾Ý¿â¡£×îºó£¬¹¥»÷ÕßÓÚ6ÔÂ29ÈÕÇÔÈ¡ÁËÈ«ÊýÊý¾Ýºó£¬ÔÚËùÓÐÉ豸ÉÏ×°ÖÃÁËAkiraÀÕË÷Èí¼þÀ´¼ÓÃÜÎļþ¡£Õâʱ£¬BHI²ÅÒâʶµ½¹«Ë¾Òѱ»ÈëÇÖ¡£


https://www.bleepingcomputer.com/news/security/us-energy-firm-shares-how-akira-ransomware-hacked-its-systems/


4¡¢Î÷°àÑÀ¾¯·½µ·»ÙÄ³ÍøÂçÚ¿Æ­ÍŻﲢ¿ÛÁô34ÃûÏÓÒÉÈË


10ÔÂ24ÈÕ±¨Â·£¬Î÷°àÑÀ¹ú¶È¾¯Ô±¾Öµ·»ÙÁËÒ»¸öÍøÂç·¸×ïÍŻ¸ÃÍÅ»ïÖ´Ðи÷ÀàÍÆËã»úÚ¿Æ­£¬ÇÔÈ¡Á˳¬¹ý400ÍòÈ˵ÄÊý¾Ý£¬×¬È¡ÁËÔ¼300ÍòÅ·Ôª¡£·¨Âɲ¿ÃÅÔÚÂíµÂÀï¡¢ÂíÀ­¼Ó¡¢Î¤¶ûÍß¡¢°¢Àû¿²ÌغÍĶûÎ÷ÑǽøÐÐÁË16´ÎÓÐÕë¶ÔÐÔµÄËѲ飬ÒÑ¿ÛÁô34Ãû·¸×ïÍÅ»ïµÄ³ÉÔ±¡£¾¯·½³Æ£¬±»²¶ÕßÓë¼ÙÒâ¿ìµÝ¹«Ë¾ºÍµçÁ¦¹©¸øÉ̵Ĵ¹µö»î¶¯ÓйØ¡£¸ÃÍÅ»ïµÄÍ·×ÓÒѱ»¿ÛÁô£¬¶ÔÆäËû³ÉÔ±Éí·ÝµÄµ÷²éÈÔÔÚ½øÐÐÖС£


https://securityaffairs.com/152946/cyber-crime/spanish-police-dismantled-cybercriminal-group.html


5¡¢×êÑÐÈËÔ±°ä²¼VMwarev·ì϶CVE-2023-34051µÄPoC


ýÌå10ÔÂ24Èճƣ¬VMwarevÌáÐÑvRealize Log Insight£¨ÏÖ³ÆÎªVMware Aria Operations for Logs£©Öзì϶µÄPoCÒѰ䲼¡£ÕâÊÇÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2023-34051£©£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»½«Îļþ×¢ÈëÖ¸±êϵͳÖУ¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£Horizon3°ä²¼ÁËPoC£¬ËüÀûÓÃIPµØÖ·ºýŪºÍ¸÷ÀàThrift RPC¶ËµãÀ´ÊµÏÖËÁÒâÎļþдÈë¡£×êÑÐÈËÔ±½¨Òéµ±¼´×°ÖøüС£


https://www.bleepingcomputer.com/news/security/vmware-warns-admins-of-public-exploit-for-vrealize-rce-flaw/


6¡¢Kaspersky°ä²¼Triangulation»î¶¯µÄÒñ±ÎÐԵĻ㱨


10ÔÂ23ÈÕ£¬Kaspersky°ä²¼Á˹ØÓÚTriangulation»î¶¯µÄÒñ±ÎÐԵķÖÎö»ã±¨¡£¸Ã»ã±¨½éÉÜÁËÕâ´Î¹¥»÷µÄ¸÷ÀàÒþÐμ¼Êõ£¬ÒÔ¼°¹¥»÷ÖÐʹÓõÄ×é¼þ¡£ÔÚ²¿ÊðTriangleDB֮ǰ£¬»áʹÓÃÁ½¸öÑéÖ¤Æ÷À´ÍøÂçÉ豸ÐÅÏ¢£¬²¢È·±£´úÂë²»»áÔÚ·ÖÎö»·¾³ÖÐÖ´ÐС£Ëü»¹Ô̺¬Ò»¸öÂó¿Ë·ç¹àÒôÄ £¿émsu3h£¬Ä¬ÈÏÄܹ»¹àÒôÈý¸öÓ×ʱ£¬µ«ÈôÊǵçÁ¿µÍÓÚ10%ÇÒÉ豸ÆÁÄ»ÔÚʹÓý«ÔÝÍ£¹àÒô¡£¹¥»÷Õß»¹Ö´ÐÐÁ˶î±íµÄÔ¿³×´®Ð¹Â¶Ä £¿é¡¢SQLiteÊý¾Ý¿âÇÔȡְÄÜÒÔ¼°µØÎ»¼à¿ØÄ £¿é£¨ÔÚGPS²»³ÉÓÃʱʹÓÃÍøÂçÔªÊý¾Ý£©¡£


https://securelist.com/triangulation-validators-modules/110847/