Sumo LogicµÄAWSÕÊ»§Ôâµ½ÈëÇÖ½¨Òé¿Í»§³ÁÖÃAPIÃÜÔ¿

°ä²¼¹¦·ò 2023-11-10

1¡¢Sumo LogicµÄAWSÕÊ»§Ôâµ½ÈëÇÖ½¨Òé¿Í»§³ÁÖÃAPIÃÜÔ¿


 ¾ÝýÌå11ÔÂ8ÈÕ±¨Â· £¬°²È«ºÍÊý¾Ý·ÖÎö¹«Ë¾Sumo Logic·¢ÏÔìäAWSÕÊ»§Ôâµ½ÈëÇÖ £¬½¨Òé¿Í»§³ÁÖÃAPIÃÜÔ¿¡£¸Ã¹«Ë¾°µÊ¾ £¬ËûÃÇÓÚ11ÔÂ3ÈÕ·¢ÏÖ¹¥»÷ÕßʹÓÃÇÔÈ¡µÄƾ֤»ñµÃÁËSumo Logic AWSÕË»§µÄ½Ó¼ûȨÏÞ £¬Ä¿Ç°»¹Ã»Óз¢ÏÔìäÍøÂç»òϵͳÊܵ½Ó°Ïì £¬¿Í»§Êý¾ÝÒ²ÒѼÓÃÜ¡£ÎªÁËÓ¦¶Ô´ËÊ £¬¸Ã¹«Ë¾Ëø¶¨ÁËÊÜÓ°ÏìµÄ»ù´¡ÉèÊ© £¬²¢³ÁÖÃÁËÆä»ù´¡ÉèÊ©µÄËùÓпÉÄܶ³öµÄƾ֤¡£´Ë±í £¬Sumo Logic½¨Òé¿Í»§³ÁÖÃÓÃÓÚ½Ó¼ûÆä·þÎñµÄÍ´´¦»òÓëSumo Logic¹²ÏíµÄÓÃÓÚ½Ó¼ûÆäËüϵͳµÄÍ´´¦¡£


https://securityaffairs.com/153882/security/sumo-logic-security-breach.html


2¡¢ChatGPT²úÉú¹ÊÕÏå´»úÊýÓ×ʱ¸Ã¹«Ë¾µÄAPIÒ²Êܵ½Ó°Ïì


¾Ý11ÔÂ8ÈÕ±¨Â· £¬OpenAIµÄChatGPTÒòÑϳÁµÄ¹ÊÕÏ¹Ø¹Ø £¬Öжϻ¹Ó°ÏìÁ˸ù«Ë¾µÄÀûÓ÷¨Ê½±à³Ì½Ó¿Ú(API)¡£ÊÜÓ°ÏìµÄ¿Í»§»á¿´µ½¡°Ëƺõ·¸´íÁË¡±µÄÃýÎóÌáÐÑ £¬ÒÔ¼°²éÎÊʱÏÔʾ¡°ÌìÉú»Ø¸´Ê±³öÏÖÃýÎ󡱡£11ÔÂ8ÈÕ11:05 £¬OpenAI°µÊ¾ÊÜÓ°ÏìµÄ·þÎñÒѸ´Ô­ÉÏÏß¡£¾Ý11ÔÂ9ÈÕµÄ×îÐÂÐÂÎÅ £¬OpenAI֤ʵÖÜÈýµÄChatGPT¼°ÆäAPI²úÉúµÄÖжÏÊÇDDoS¹¥»÷µ¼ÖµÄ¡£Anonymous SudanÔÚTelegramÉÏÐû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü¡£


https://www.bleepingcomputer.com/news/technology/chatgpt-down-after-major-outage-impacting-openai-systems/


3¡¢¾©´ÉAVXй©ÀÕË÷¹¥»÷µ¼ÖÂ39000È˵ÄÐÅϢй¶


11ÔÂ9ÈÕ±¨Â·³Æ £¬Kyocera AVX Components Corporation(KAVX)ÔÚ·¢ËÍÀÕË÷¹¥»÷µ¼ÖµÄÊý¾Ýй¶µÄ֪ͨ¡£Í¨ÖªÖаµÊ¾ £¬ËüÓÚ10ÔÂ10ÈÕ·¢ÏÖºÚ¿ÍÔÚ2ÔÂ16ÈÕÖÁ3ÔÂ30ÈÕ½Ó¼ûÁËÆäϵͳ £¬µ¼Ö²¿ÃÅϵͳ±»¼ÓÃܺÍijЩ·þÎñÁÙʱÖжÏ¡£KAVXµ÷²é·¢ÏÖ39111È˵ÄÐÅϢй¶ £¬²¢½«ÎªËûÃÇÌṩ12¸öÔµİµÍø¼à¿ØºÍÃÜÂëй¶·þÎñ¡£LockBitÔøÐû³ÆÓÚ5ÔÂ26ÈÕÈëÇÖÁËKAVX £¬²¢¹«¿ªÁ˶à¸ö±»µÁÊý¾ÝÑù±¾ £¬Ô̺¬»¤ÕÕɨÃè¡¢²ÆÕþÎļþºÍ±£ÃܺÍ̸µÈ¡£


https://www.bleepingcomputer.com/news/security/kyocera-avx-says-ransomware-attack-impacted-39-000-individuals/


4¡¢US RadiologyÒò2021ÄêµÄÀÕË÷¹¥»÷±»·£¿î45ÍòÃÀÔª


ýÌå11ÔÂ9ÈÕ³Æ £¬Òò佨¸´·ì϶µ¼ÖÂÀÕË÷¹¥»÷ £¬US Radiology±»Å¦Ô¼AG·£¿î45ÍòÃÀÔª¡£¾ÝϤ £¬Ë¾·¨²¿³¤Ç¿µ÷·ì϶CVE-2021-20016Òѱ»ÀÕË÷ÍÅ»ïÂÅ´ÎÀûÓá£US RadiologyÎÞ·¨×°Öù̼þ²¹¶¡ÓÉÓÚÆäÓ²¼þÒÑ´¦ÓÚEOL½×¶Î £¬²»ÔÙ±»Ö§³Ö¡£¸Ã¹«Ë¾´òËãÓÚ2021Äê7Ô¸ü»»Ó²¼þ £¬µ«×îÖÕ¸ÃÏîÄ¿±»ÍƳÙ¡£ÓÉÓÚ·ì϶δµÃµ½½â¾ö £¬¸Ã¹«Ë¾ÓÚ2021Äê12ÔÂ8ÈÕÔâµ½ÀÕË÷¹¥»÷ £¬µ¼Ö½ü20ÍòÃû»¼ÕßµÄÃô¸ÐÐÅϢй¶¡£³ýÁË·£¿î±í £¬¸Ã¹«Ë¾»¹±ØÐëÉý¼¶ÆäITϵͳ¡¢ÀñƸרÈËÖÎÀíÆäÊý¾Ý°²È«´òËã¡¢¼ÓÃÜËùÓÐÃô¸ÐµÄ»¼ÕßÐÅÏ¢²¢¿ª·¢ÉøÈë²âÊÔ´òËã¡£


https://therecord.media/new-york-attorney-general-fines-radiology-firm-after-ransomware-attack


5¡¢Group-IBÅû¶ÀÕË÷Èí¼þÔËÓªÍÅ»ïFarnetworkµÄóÒ×ģʽ


11ÔÂ9ÈÕ £¬Group-IB¶ÁËÀÕË÷Èí¼þÔËÓªÍÅ»ïFarnetworkµÄóÒ×ģʽ¡£FarnetworkÔÚ2019ÄêÖÁ2021Äê¼ä £¬Ô®ÊÖJSWORM¡¢Nefilim¡¢KarmaºÍNemty½øÐжñÒâÈí¼þ¿ª·¢ºÍÔËÓªÖÎÀí £¬²¢ÔÚ2022Äê³ÉÁ¢ÁËÀÕË÷Èí¼þ¼´·þÎñ(RaaS)Nokoyawa¡£2023Äê2Ô £¬farnetworkÆðÍ·ÕÐļNokoyawaµÄ´ÓÊôÍÅ»ï £¬ËüÌṩÏֳɵĽӼûȨÏÞ¡£¹¥»÷³É¹¦ºó £¬´ÓÊôÍÅ»ï»ñµÃ65%µÄÊê½ð £¬½©Ê¬ÍøÂçËùÓÐÕß»ñµÃ20% £¬ÀÕË÷Èí¼þËùÓÐÕß»ñµÃ15%¡£½ØÖÁ½ñÄê10Ô £¬NokoyawaµÄÍøÕ¾ÖÕ³¡ÔËÓª £¬×ܹ²ÁгöÁË35¸ö±»¹¥»÷Ö¸±ê¡£


https://www.group-ib.com/blog/farnetwork/


6¡¢Check Point°ä²¼10Ô·ÝÈ«ÇòÍþвָÊýµÄ·ÖÎö»ã±¨


11ÔÂ8ÈÕ £¬Check Point°ä²¼ÁË10Ô·ÝÈ«ÇòÍþвָÊýµÄ·ÖÎö»ã±¨¡£FormbookÊÇ10Ô·Ý×î³£¼ûµÄ¶ñÒâÈí¼þ £¬Ó°ÏìÁËÈ«Çò3%µÄʵÌå £¬Æä´ÎÊÇNJRat£¨2%£© £¬´ÓµÚÁùλÉÏÉýÖÁµÚ¶þλ¡£½ÌÓýºÍ×êÑÐÐÐÒµÒÀÈ»ÊÇÊܵ½¹¥»÷×îÑϳÁµÄÐÐÒµ £¬Æä´ÎÊÇͨѶÒÔ¼°¾üÕþÐÐÒµ¡£10Ô·Ý×î³£±»ÀûÓõķì϶ÊÇZyxel ZyWALLºÅÁî×¢Èë·ì϶(CVE-2023-28771) £¬Ó°ÏìÁËÈ«Çò42%µÄʵÌå¡£×î³£¼ûµÄÒÆ¶¯¶ñÒâÈí¼þÊÇAnubis £¬Æä´ÎÊÇAhMythºÍHiddad¡£


https://blog.checkpoint.com/security/october-2023s-most-wanted-malware-njrat-jumps-to-second-place-while-agenttesla-spreads-through-new-file-sharing-mal-spam-campaign/