ºÚ¿ÍÕë¶Ô FCC ºÍ¼ÓÃÜÇ®±Ò¹«Ë¾ÌáÒé¸ß¼¶ Okta ÍøÂç´¹µö¹¥»÷

°ä²¼¹¦·ò 2024-03-04
1. ºÚ¿ÍÕë¶Ô FCC ºÍ¼ÓÃÜÇ®±Ò¹«Ë¾ÌáÒé¸ß¼¶ Okta ÍøÂç´¹µö¹¥»÷


3ÔÂ2ÈÕ£¬Ò»ÖÖÃûΪ CryptoChameleon µÄÐÂÍøÂç´¹µö¹¤¾ß°ü±»ÓÃÓÚÕë´ºÁª¹úͨѶίԱ»á (FCC) Ô±¹¤£¬¸Ã¹¤¾ß°üʹÓÃרÃÅΪ Okta Ôì×÷µÄµ¥µãµÇ¼ (SSO) Ò³Ãæ£¬ÕâÐ©Ò³ÃæÓëÔ­Ê¼Ò³Ãæ¼«¶ÈÀàËÆ¡£¸Ã»î¶¯»¹Õë¶Ô Binance¡¢Coinbase¡¢Kraken ºÍ Gemini µÈ¼ÓÃÜÇ®±Òƽ̨µÄÓû§ºÍÔ±¹¤£¬Ê¹ÓüÙÒâ Okta¡¢Gmail¡¢iCloud¡¢Outlook¡¢Twitter¡¢Yahoo ºÍ AOL µÄÍøÂç´¹µöÒ³Ãæ¡£¹¥»÷Õß¾«ÐIJ߶¯Á˸´ÔÓµÄÍøÂç´¹µöºÍÉç»á¹¤³Ì¹¥»÷£¬Ô̺¬µç×ÓÓʼþ¡¢¶ÌÐźÍÓïÒôÍøÂç´¹µö£¬ÒÔºýŪÊܺ¦ÕßÔÚÍøÂç´¹µöÒ³ÃæÉÏÊäÈëÃô¸ÐÐÅÏ¢£¬ÀýÈçÓû§Ãû¡¢ÃÜÂ룬ÔÚijЩÇé¿öÏÂÉõÖÁÔ̺¬´øÕÕÆ¬µÄÉí·ÝÖ¤¼þ¡£Lookout×êÑÐÈËÔ±·¢ÏÖµÄÍøÂç´¹µö²Ù×÷ ÓëScattered SpiderºÚ¿Í×éÖ¯ÔÚ 2022 Äê ½øÐÐµÄ Oktapus »î¶¯ ÀàËÆ  £¬µ«Ã»ÓÐ×ã¹»µÄÖ¤¾ÝÖ¤Ã÷Æä¹éÊô¡£


https://www.bleepingcomputer.com/news/security/hackers-target-fcc-crypto-firms-in-advanced-okta-phishing-attacks/


2. ÃÀ¹úÍøÂçºÍ·¨ÂÉ»ú¹¹¶Ô PHOBOS ÀÕË÷Èí¼þ¹¥»÷·¢³öÖÒ¸æ


3ÔÂ2ÈÕ£¬ÃÀ¹ú CISA¡¢FBI ºÍ MS-ISAC °ä²¼½áºÏÍøÂ簲ȫ²¼¸æ (CSA)£¬ÖÒ¸æÉæ¼°Backmydata¡¢Devos¡¢Eight¡¢Elking ºÍ Faust µÈPhobos ÀÕË÷Èí¼þ±äÖֵĹ¥»÷¡£ÕâЩ¹¥»÷×î½ü²úÉúÔÚ 2024 Äê 2 Ô£¬Ö¸±êÊǵ±¾Ö¡¢½ÌÓý¡¢´¹Î£·þÎñ¡¢Ò½ÁƱ£½¡ºÍÆäËû¹Ø¼ü»ù´¡ÉèÊ©²¿ÃÅ¡£Phobos ²Ù×÷ѡȡÀÕË÷Èí¼þ¼´·þÎñ (RaaS) ģʽ£¬×Ô 2019 Äê 5 ÔÂÒÔÀ´Ò»Ïò»îÔ¾¡£Æ¾¾Ý¹«¿ªÆðÔ´µÄÐÅÏ¢£¬ÓÉÓڹ۲쵽սÊõ¡¢¼¼ÊõºÍ·¨Ê½ (TTP) ·½ÃæµÄÀàËÆÐÔ£¬µ±¾Öר¼Ò½«¶à¸ö Phobos ÀÕË÷Èí¼þ±äÌåÓë Phobos ÈëÇÖÁªÏµÆðÀ´¡£Phobos ÈëÇÖ»¹É漰ʹÓø÷À࿪Դ¹¤¾ß£¬Ô̺¬ Smokeloader¡¢Cobalt StrikeºÍ Bloodhound¡£ÕâЩ¹¤¾ßÔÚ·ÖÆçµÄ²Ù×÷»·¾³ÖÐ¿í·º¿ÉÓÃÇÒÓû§¶ØÄÀ£¬ÓÐÖúÓÚ Phobos ¼°ÆäÓйرäÌåÔÚ¸÷ÀàÍþв²Î¼ÓÕßÖеÄÊ¢ÐС£¾Ý¹Û²ì£¬Phobos ¹¥»÷±³ºóµÄÍþв²Î¼ÓÕßͨ¹ýÀûÓÃÍøÂç´¹µö»î¶¯»ñµÃÁ˶ÔÒ×Êܹ¥»÷ÍøÂçµÄ³õʼ½Ó¼ûȨÏÞ¡£ËûÃÇÅׯú°µ²ØµÄÓÐЧ¸ºÔØ»òʹÓû¥ÁªÍøºÍ̸ (IP) ɨÃ蹤¾ß£¨ÀýÈç Angry IP Scanner£©À´ËÑË÷Ò×Êܹ¥»÷µÄÔ¶³Ì×ÀÃæºÍ̸ (RDP) ¶Ë¿Ú»òÔÚ Microsoft Windows »·¾³ÖÐÀûÓà RDP¡£Phobos ʹÓà Windows Æô¶¯Îļþ¼ÐºÍÔËÐÐ×¢²á±íÏîÔÚÊÜϰȾµÄ»·¾³ÖÐά³ÖÓÆ¾ÃÐÔ¡£Íþв²Î¼ÓÕßʹÓà Bloodhound¡¢Sharphound¡¢Mimikatz¡¢NirSoft ºÍ Remote Desktop Passview µÈ¿ªÔ´¹¤¾ßÀ´Ã¶¾Ù»î¶¯Ä¿Â¼²¢ÍøÂçÍ´´¦¡£Phobos ÔËÓªÉÌʹÓà WinSCP ºÍ Mega.io ½«Êý¾Ýй¶µ½ FTP ·þÎñÆ÷»òÔÆ´æ´¢¡£


https://securityaffairs.com/159822/cyber-crime/cisa-phobos-ransomware-attacks.html


3. CutOut.Pro AI¹¤¾ßÊý¾Ýй¶£¬ºÚ¿Íй¶2000ÍòÓû§ÐÅÏ¢


3ÔÂ2ÈÕ£¬CutOut.Pro ÊÇÒ»¸öרÃÅ´ÓÊÂͼÏñºÍÊÓÆµ±à×ëµÄÈËΪÖÇÄÜÆ½Ì¨£¬ÓÚ 2024 Äê 2 Ô 27 ÈÕÃæ¶ÔºÚ¿ÍÐû³ÆµÄÊý¾Ýй¶¡£Ò»Ãû×Ô³Æ KryptonZambie µÄÈËͦÉí¶ø³ö£¬Ðû³ÆËûÃÇÒѾ­³É¹¦¹¥ÆÆÁË CutOut.Pro£¬ÕâÊÇÒ»¼Ò×ܲ¿Î»ÓÚÐÂ¼ÓÆÂµÄÆ½Ì¨£¬ÒÔÆäÈËΪÖÇÄÜÇý¶¯µÄ¹¤¾ß¶øÎÅÃû£¬ÊʺÏÊÓ¾õÉè¼ÆºÍÄÚÈÝ´´×÷£¬³ö¸ñÊÇÔÚͼÏñºÍÊÓÆµ±à×ëÁìÓò¡£´ÓÕâ´Îй¶ÖÐÌáÈ¡µÄÊý¾ÝÒÑÔÚ³ôÃûÔ¶ÑïµÄÍøÂç·¸×ïºÍºÚ¿ÍÂÛ̳£¨Ô̺¬Breach Forums £©ÉÏй¶£¬Ä¿Ç°ÔÚ¶íÓïÂÛ̳Öд«²¼¡£¶ÔÓÚй¶Êý¾ÝµÄÄÚÈÝ£¬Hackread.comÉî¿Ì·ÖÎö·¢ÏÖ£¬¼Í¼Ô̺¬ÒÔÏÂÐÅÏ¢£ºÈ«Ãû¡¢IPµØÖ·¡¢µç×ÓÓʼþµØÖ·¡¢ÃÜÂë¹þÏ£Öµ¡¢ºÍÕÊ»§×¢²áÊý¾Ý¡£ÓëºÚ¿ÍÔÚÁбíÖеÄ˵·¨Ïà·´£¬Hackread ½øÐеķÖÎöÅú×¢£¬Ð¹Â¶µÄÊý¾Ý²»Ô̺¬µç»°ºÅÂë¡¢API ½Ó¼ûȨÏÞ»òÀûÓ÷¨Ê½ÃÜÔ¿¡£Õâ²¢²»ÊÇ CutOut.Pro µÚÒ»´ÎÓÉÓÚÃýÎóµÄÔ­Òò³ÉΪͷÌõÐÂÎÅ¡£2023 Äê 2 Ô£¬ËûÃǵÄһ̨ Elasticsearch ·þÎñÆ÷й¶Á˸ߴï 9 GB µÄ¿Í»§Êý¾Ý¡£ÕâЩÊý¾ÝÖÐÓг¬¹ý 2200 ÍòÌõÈÕÖ¾Ìõ¿î£¬ÆäÖÐÌáµ½ÁËÓ×ÎÒÓû§ºÍÆóÒµÕÊ»§µÄÓû§Ãû¡£


https://www.hackread.com/hacker-cutout-pro-ai-tool-data-breach/


4. ÕÛ¿ÛÁãÊÛ¾ÞÍ· Pepco ÒòÍøÂç·¸×ï·Ö×ÓËðʧ 1500 ÍòÅ·Ôª


2ÔÂ29ÈÕ£¬Õâ¼Ò×ܲ¿Î»ÓÚÓ¢¹úµÄ¹«Ë¾»ã±¨³Æ£¬ÓÉÓÚ¡°¸´ÔÓµÄڲƭÐÔÍøÂç´¹µö¹¥»÷¡±£¬ËðʧÁË 1550 ÍòÅ·Ôª£¨Ô¼ºÏ 1680 ÍòÃÀÔª£©µÄÏֽ𡣵÷²éÒѾ­Æô¶¯£¬Pepco ÔÚÓëÒøÐк;¯·½ºÏ×÷×·»ØÕâ±Ê×ʽ𣬵«¸Ã¹«Ë¾°µÊ¾£¬Ä¿Ç°Éв»Ã÷ÏÔÊÇ·ñÄܹ»×·»Ø×ʽð¡£Pepco ¼¯ÍŰµÊ¾£º¡°Ïֽ׶Σ¬¸ÃÊÂÎñËÆºõ²¢Î´Éæ¼°Èκοͻ§¡¢¹©¸øÉÌ»òͬʵÄÐÅÏ¢»òÊý¾Ý¡£¡±Pepco ¼¯ÍÅÕ¼ÓÐ Pepco¡¢Dealz ºÍ Poundland Æ·ÅÆ¡£Pepco µÄ 3,600 ¼ÒÃŵê±é²¼ 19 ¸öÅ·ÖÞ¹ú¶È£¬Ã¿ÔÂÕ¼Óг¬¹ý 3000 Íò¹Ë¿Í¡£Æ¾¾Ý¸Ã¹«Ë¾¶ÔÊÂÎñµÄ¼òÒªÃèÊöºÍËðʧ½ð¶î£¬¸Ã¹«Ë¾¿ÉÄÜÊÇóÒ×µç×ÓÓʼþй¶ (BEC) ´òËãµÄÖ¸±ê£¬ÔڸôòËãÖУ¬ÍøÂç·¸×ï·Ö×ÓʹÓñ»ºÚ¿ÍÈëÇֵĵç×ÓÓʼþÕÊ»§À´ÓÕÆ­Ö¸±ê×éÖ¯µÄÔ±¹¤½«×ʽðתÈëËûÃǵÄÒøÐÐÕË»§½ÚÔì¡£


https://www.securityweek.com/discount-retail-giant-pepco-loses-e15-million-to-cybercriminals/


5. Ð嵀 Silver SAML ¹¥»÷¿É¶ã±ÜÉí·ÝϵͳÖÐµÄ Golden SAML ·ÀÓù


2ÔÂ29ÈÕ£¬ÍøÂ簲ȫ×êÑÐÈËÔ±Åû¶ÁËÒ»ÖÖÃûΪSilver SAMLµÄй¥»÷¼¼Êõ£¬¼´±ãÔÚÕë¶Ô Golden SAML ¹¥»÷²ÉÈ¡»º½â´ëÊ©µÄÇé¿öÏ£¬¸Ã¼¼ÊõÒ²Äܳɹ¦¡£Semperis ×êÑÐÈËÔ± Tomer Nahum ºÍ Eric Woodruff ÔÚÓë The Hacker News ·ÖÏíµÄÒ»·Ý»ã±¨ÖаµÊ¾£¬Silver SAML¡°Ê¹µÃ Entra ID µÈÉí·ÝÌṩÉÌ¿ÉÄÜÀûÓà SAML ¶ÔÅäÖÃΪʹÓà SAML ½øÐÐÉí·ÝÑéÖ¤µÄÀûÓ÷¨Ê½£¨ÀýÈç Salesforce£©ÌáÒé¹¥»÷¡± ¡£Golden SAML£¨°²È«¶ÏÑÔÏóÕ÷˵»°µÄËõд£©ÓÉ Cyber Ark ÓÚ 2017 Äê³õ´Î¼Í¼¡£¼ò¶øÑÔÖ®£¬¸Ã¹¥»÷ý½é±ØÒªÀÄÓÿɻ¥²Ù×÷µÄÉí·ÝÑéÖ¤³ß¶ÈÀ´¼ÙÒâ×éÖ¯ÖеÄÏÕЩÈκÎÉí·Ý¡£ËüÒ²ÀàËÆÓÚ½ðÆ±¹¥»÷£¬ÓÉÓÚËüʹ¹¥»÷Õß¿ÉÄÜÒÔÈκÎȨÏÞδ¾­ÊÚȨµØ½Ó¼û½áºÏÖеÄÈκηþÎñ£¬²¢ÒÔÒþÃØµÄ·½Ê½Ôڸû·¾³ÖÐά³ÖÓÆ¾ÃÐÔ¡£ÀûÓøò½ÖèµÄÏÖʵ¹¥»÷ºÜÉÙ¼û£¬µÚÒ»¸ö ÓмͼµÄ¹¥»÷ÊÇͨ¹ýʹÓÃÊÜËðµÄ SAML ÁîÅÆÊðÃûÖ¤ÊéαÔì SAML ÁîÅÆÀ´ÇÖº¦ SolarWinds »ù´¡ÉèÊ©£¬´Ó¶ø»ñµÃÖÎÀí½Ó¼ûȨÏÞ ¡£Î¢ÈíÔÚ 2023 Äê 9 ÔÂй©£¬Golden SAML »¹±»´úºÅΪPeach SandstormµÄÒÁÀÊÍþвÐÐΪÕßÔÚ 2023 Äê 3 ÔµÄÒ»´ÎÈëÇÖÖбøÆ÷»¯£¬ÎÞÐèÈκÎÃÜÂë¼´¿É½Ó¼û䶨ÃûÖ¸±êµÄÔÆ×ÊÔ´¡£


https://thehackernews.com/2024/02/new-silver-saml-attack-evades-golden.html


6. ÂÉʦÊÂÎñËùHouser LLP»ã±¨Êý¾Ýй¶ӰÏ쳬¹ý 325000 ÈË


2ÔÂ29ÈÕ£¬×¨ÃÅΪ³ÛÃû½ðÈÚ»ú¹¹Ìṩ·þÎñµÄÃÀ¹úÂÉʦÊÂÎñËù Houser LLP °µÊ¾£¬2023 Äê 5 Ô·¢ÏÖµÄÒ»´Îϵͳ·ì϶¶³öÁ˳¬¹ý 325,000 È˵ÄÓ×ÎÒÊý¾Ý£¬¿ÉÄÜÔ̺¬ÐÅÓþ¿¨ºÅµÈÃô¸ÐÐÅÏ¢¡£ÔÚÃåÒòÖÝ×ܼì²ì³¤ÖÜÈý°ä²¼µÄÒ»·Ý¼à¹ÜÎļþÖУ¬¸Ã¹«Ë¾°µÊ¾£¬Ä³Ð©ÎļþÔÚÊÂÎñÆÚ¼ä±»¼ÓÃÜ£¬²¢¡°´ÓÍøÂçÖи´ÔìºÍ»ñÈ¡¡±¡£ºÀɪ˵£¬ÕâЩÊý¾ÝÔ̺¬ÐÕÃû¡°ÒÔ¼°Éç»á°²È«ºÅÂë¡¢¼ÝÊ»ÅÆÕÕºÅÂë¡¢Ó×ÎÒÄÉ˰¼ø±ðºÅÂë¡¢½ðÈÚÕË»§ÐÅÏ¢ºÍÒ½ÁÆÐÅÏ¢ÖеÄÒ»Ïî»ò¶àÏ¡£¸Ã¹«Ë¾»¹Ïò¼ÓÖÝ×ܼì²ì³¤Ìá½»ÁË֪ͨ¡£¸Ã¹«Ë¾°µÊ¾£¬Ò»¼Òδ¾ßÌå×¢Ã÷µÄµÚÈý·½¹«Ë¾ºóÀ´È·¶¨£¬5 Ô 7 ÈÕÖÁ 9 ÈÕÆÚ¼ä£¬Houser µÄÍøÂç´æÔÚ¡°Î´¾­ÊÚȨµÄ½Ó¼û¡±¡£¼à¹ÜÎļþ³Æ£¬ºÀɪºÜ¿ì¾ÍÓë¹¥»÷Õß»ñµÃÁËÁªÏµ£¬µ«Ã»ÓÐÚ¹ÊÍͨѶµÄÐÔÖÊ¡£Recorded Future News ÒÑÁªÏµ¸Ã¹«Ë¾ÒÔ»ñÈ¡¸ü¶àÐÅÏ¢¡£¸Ã¹«Ë¾°µÊ¾£¬ÔÚ 2023 Äê 6 ÔµÄij¸öʱ³½£¬¡°Î´¾­ÊÚȨµÄÐÐΪÕß֪ͨ Houser£¬ËûÃÇɾ³ýÁËÈκα»µÁÊý¾ÝµÄ¸±±¾£¬²¢ÇÒ²»»á·Ö·¢Èκα»µÁÎļþ¡±¡£Îļþ³Æ£¬µÚÈý·½¹©¸øÉÌÓÚ½ñÄê 1 Ô 18 ÈÕʵÏÖÁËÉó²é¡£


https://therecord.media/houser-law-firm-reports-data-breach