·áÌï½ðÈÚ·þÎñ¹«Ë¾Ôâµ½Medusa¹¥»÷²¢±»ÀÕË÷800ÍòÃÀÔª

°ä²¼¹¦·ò 2023-11-20
1¡¢·áÌï½ðÈÚ·þÎñ¹«Ë¾Ôâµ½Medusa¹¥»÷²¢±»ÀÕË÷800ÍòÃÀÔª


¾ÝýÌå11ÔÂ16ÈÕ±¨Â·£¬·áÌï½ðÈÚ·þÎñ¹«Ë¾(TFS)Ôâµ½¹¥»÷£¬ÆäÔÚÅ·Ö޺ͷÇÖÞµÄϵͳÉϼì²âµ½Î´¾­ÊÚȨµÄ½Ó¼û¡£ÀÕË÷ÍÅ»ïMedusaÒѽ«TFSÁÐÈëÆäÍøÕ¾£¬²¢ÀÕË÷800ÍòÃÀÔªÒÔɾ³ýÊý¾Ý¡£¹¥»÷Õß»¹¸øÁË·áÌï10ÌìµÄ¹¦·ò×ö³ö»ØÓ¦£¬²¢Äܹ»Ñ¡ÔñÑÓ³Ö¾ÃÏÞ£¬Ö»ÓÐÿÌìÖ§¸¶10000ÃÀÔª¡£ÎªÁËÖ¤Ã÷ÈëÇÖ£¬ºÚ¿ÍMedusa°ä²¼ÁËÔ̺¬²ÆÕþÎļþ¡¢µç×Ó±í¸ñºÍ²É°ì·¢Æ±µÈÊý¾ÝµÄÑù±¾¡£´óÎÞÊýÎļþ¶¼ÊǵÂÓÅú×¢ºÚ¿Í³É¹¦½Ó¼ûÁË·áÌïÖÐÅ·ÒµÎñµÄϵͳ¡£×êÑÐÈËԱй©£¬Õâ´Î¹¥»÷¿ÉÄÜÓëCitrix GatewayµÄ·ì϶ÓйØ¡£


https://securityaffairs.com/154319/data-breach/toyota-financial-services-medusa-ransomware.html


2¡¢ÑÅÂí¹þ·ÆÂɱö·Ö¹«Ë¾±»INC¹¥»÷Ô¼37GBµÄÊý¾Ýй¶


¾Ý11ÔÂ17ÈÕ±¨Â·£¬ÑÅÂí¹þÆû³µ·ÆÂɱöĦÍгµÔì×÷·Ö¹«Ë¾(YMPH)Ôâµ½¹¥»÷£¬²¿ÃÅÔ±¹¤ÐÅϢй¶¡£YMPHÓÚ10ÔÂ25ÈÕ³õ´Î·¢ÏÖÎÊÌ⣬Æäһ̨·þÎñÆ÷Ô⵽δ¾­ÊÚȨµÄ½Ó¼û£¬Ä¿Ç°ÔÚÆÀ¹ÀÕâ´Î¹¥»÷Ó°ÏìµÄÁìÓò¡£ÀÕË÷ÍÅ»ïINCÐû³Æ¶Ô´ËÊÂÕÆ¹Ü£¬ÓÚ11ÔÂ15ÈÕ½«¸Ã¹«Ë¾Ôö³¤µ½ÆäÍøÕ¾¡£¶ûºó°ä²¼Á˶à¸öÎļþ£¬ÆäÖÐÔ̺¬Ô¼Äª37GBµÄÊý¾Ý£¬Éæ¼°Ô±¹¤IDÐÅÏ¢¡¢±¸·ÝÎļþÒÔ¼°¹«Ë¾ºÍÏúÊÛÐÅÏ¢µÈ¡£


https://www.bleepingcomputer.com/news/security/yamaha-motor-confirms-ransomware-attack-on-philippines-subsidiary/ 


3¡¢BGRSºÍSIRVAÔâ¹¥»÷µ¼Ö¼ÓÄôóÊÐÕþ»ú¹¹´óÁ¿Ô±¹¤ÐÅϢй¶


¼ÓÄô󵱾ÖÔÚ11ÔÂ19ÈÕÅû¶Á˽üÆÚµÄÒ»´ÎÊý¾Ýй¶ÊÂÎñ£¬Ó°ÏìÁËÏÖÈκÍǰÈι«¹²·þÎñ²¿ÃÅÔ±¹¤ÒÔ¼°¼ÓÄôó»Ê¼ÒÆï¾¯ºÍ¼ÓÄôóÎä×°¶ÓÁгÉÔ±¡£Ä¿Ç°È·¶¨£¬ÎªÔ±¹¤Ìṩ°áǨ·þÎñµÄBrookfield Global Relocation Services(BGRS)ºÍSIRVA Worldwide Relocation & Moving ServicesÊÇÕâ´ÎÊý¾Ýй¶ÊÂÎñµÄÔ´Í·¡£¾ÝϤ£¬Ô±¹¤×Ô1999ÄêÒÔÀ´ÏòÕâЩ¹«Ë¾ÌṩµÄÓ×ÎҺͲÆÕþÐÅÏ¢¿ÉÄÜÒѾ­Ð¹Â¶¡£10ÔÂ6ÈÕ£¬LockBit3.0½«SIRVAÔö³¤µ½ÁËÆäÍøÕ¾£¬²¢ÓÚ11ÔÂ19ÈÕ¹«¿ªÁ˱»µÁÊý¾Ý¡£BGRSÍøÕ¾×Ô9ÔÂ29ÈÕÆðÒ»Ïò´¦ÓÚÀëÏß״̬¡£


https://www.databreaches.net/canadian-government-announces-data-breach-urges-public-service-employees-to-take-action/


4¡¢Google³ÆZimbra·ì϶CVE-2023-37580±»4¸öÍÅ»ïÀûÓÃ


11ÔÂ16ÈÕ£¬Google TAGÅû¶ÁË4ÆðÀûÓÃZimbraÖеÄXSS·ì϶£¨CVE-2023-37580£©µÄ¹¥»÷»î¶¯¡£µÚÒ»´Î»î¶¯²úÉúÓÚ6Ôµ×£¬Õë¶ÔµÄÊÇÏ£À°Ä³µ±¾Ö»ú¹¹£¬·¢ÏÖ·ì϶ºóZimbraÔÚGitHubÉÏÍÆËÍÁËÒ»¸ö´¹Î£½¨¸´·¨Ê½¡£Winter VivernÓÚ7ÔÂ11ÈÕÀûÓø÷ì϶¹¥»÷ÁËĦ¶û¶àÍߺÍÍ»Äá˹ȷµ±¾Ö»ú¹¹£¬ZimbraÔÚ7ÔÂ13ÈÕ°ä²¼°²È«²¼¸æ½¨ÒéÓû§²ÉÈ¡»º½â´ëÊ©¡£7ÔÂ20ÈÕ£¬Î´ÖªºÚ¿Í¹¥»÷ÁËÔ½ÄÏijµ±¾Ö»ú¹¹£¬ÎåÌìºóZimbra°ä²¼Á˸÷ì϶µÄ¹Ù·½²¹¶¡¡£8ÔÂ25£¬TAG·¢ÏÖÁ˵Ú4´ÎÀûÓø÷ì϶µÄ¹¥»÷»î¶¯£¬Õë¶Ô°Í»ù˹̹µ±¾Ö»ú¹¹¡£


https://blog.google/threat-analysis-group/zimbra-0-day-used-to-target-international-government-organizations/


5¡¢8BaseÍÅ»ïͨ¹ýSmokeLoader·Ö·¢ÐµÄPhobos±äÌå


CiscoÔÚ11ÔÂ18Èճƣ¬8Base½üÆÚµÄ»î¶¯ÓÐËùÔö³¤£¬ËüʹÓÃÀÕË÷Èí¼þPhobosµÄ±äÌåºÍÆäËü¹«¿ª¿ÉÓõŤ¾ßÖ´Ðй¥»÷¡£¸ÃÍÅ»ï´óÎÞÊýPhobos±äÌå¶¼ÊÇÓɺóÃÅSmokeLoader·Ö·¢µÄ¡£ÔÚ8Base»î¶¯ÖУ¬ËüÔÚ¼ÓÃܵÄpayloadÖÐǶÈëÁËÀÕË÷Èí¼þ×é¼þ£¬¶øºó½«Æä½âÃܲ¢¼ÓÔØµ½SmokeLoader¹ý³ÌµÄÄÚ´æÖС£´Ë±í£¬Phobos¶Ô1.5MBÒÔϵÄÎļþÆëÈ«¼ÓÃÜ£¬¶Ô³¬¹ýãÐÖµµÄÎļþ²¿ÃżÓÃÜ£¬ÒÔÌá¸ß¿ìÂÊ¡£


https://blog.talosintelligence.com/deep-dive-into-phobos-ransomware/


6¡¢Avast°ä²¼2023ÄêµÚÈý¼¾¶ÈµÄÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨


11ÔÂ16ÈÕ£¬Avast°ä²¼ÁË2023ÄêµÚÈý¼¾¶ÈµÄÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£µÚÈý¼¾¶È£¬Avast¾ùÔÈÿÔÂÀ¹½ØµÄ¶ñÒâÈí¼þ¹¥»÷³¬¹ý10ÒڴΣ¬ÍøÂçÍþв£¨ÓÈÆäÊÇÉ繤¹¥»÷ºÍ¶ñÒâ¸æ°×£©µÄ´ó·ùÔö³¤Íƶ¯ÁËÕâÒ»Ôö³¤¡£¹¥»÷Õß¶ÔÈËΪÖÇÄܵÄÀûÓÃÔڼӿ죬ÓÈÆäÊÇÔÚÉî¶ÈαÔì½ðÈÚÚ¿Æ­»î¶¯ÖС£¸æ°×Èí¼þÏÔÖøÉý¼¶£¬³ö¸ñÊÇÄÏÃÀ¡¢·ÇÖÞ¡¢¶«ÄÏÅ·ºÍ¶«ÑǵØÓò¡£ÐÅÏ¢ÇÔÈ¡·¨Ê½µÄÍþвÔö³¤£¬ÆäÖÐÎÚ¿ËÀ¼£¨44%£©¡¢ÃÀ¹ú£¨21%£©ºÍÓ¡¶È£¨16%£©µÄÔö·ù×îÏÔÖø¡£RAT³ÖÐø³ÊÔö³¤Ç÷Ïò£¬ÆÏÌÑÑÀ£¨148%£©¡¢²¨À¼£¨55%£©ºÍ˹Âå·¥¿Ë£¨43%£©µÈ¹úµÄÔö·ù×îÏÔÖø¡£


https://decoded.avast.io/threatresearch/avast-q3-2023-threat-report/