SECÖ¸¿ØICEÎ¥·´Áª¹ú¹æ¶¨²¢·£¿î1000ÍòÃÀÔª
°ä²¼¹¦·ò 2024-05-245ÔÂ23ÈÕ£¬ÃÀ¹ú֤ȯÂòÂôίԱ»á£¨SEC£©Ö¸¿ØÖÞ¼ÊÂòÂôËù£¨ICE£©Î´ÄÜʵʱÏòÆä¾Å¼ÒÈ«×Ê×Ó¹«Ë¾´«µÝ 2021 Äê 4 Ô 15 ÈÕ²úÉúµÄÍøÂç¹¥»÷£¬µ¼ÖÂÆäÎ¥·´Áª¹ú¹æ¶¨¡£ÃÀ¹ú֤ȯÂòÂôίԱ»áÖÜÈý°ä·¢ÁË 1000 ÍòÃÀÔªµÄ·£¿î£¬²¢°µÊ¾ ICE ¼°Æä×Ó¹«Ë¾¼È²»ÈÏ¿ÉÒ²²»·ñ¶¨ÃÀ¹ú֤ȯÂòÂôίԱ»áµÄµ÷²éÁ˾֡£ICE »ã±¨³Æ£¬2024ÄêµÚÒ»¼¾¶ÈµÄ¾»ÊÕÈëΪ 23 ÒÚÃÀÔª£¬³ýÁËÕ¼ÓÐÂòÂôËù±í£¬»¹Ìṩ½ðÈÚ¼¼ÊõºÍÊý¾Ý·þÎñ¡£SEC ³Æ£¬µ÷²éÏÔʾ£¬ÔÚÊÂÎñ²úÉúÆÚ¼ä£¬ICE µ±¼´ÖªÂ·ºÚ¿Í¡°½«¶ñÒâ´úÂë²åÈëÓÃÓÚÔ¶³Ì½Ó¼û ICE ¹«Ë¾ÍøÂçµÄ VPN É豸¡±£¬µ«¼¸Ììºó²Å֪ͨŦԼ֤ȯÂòÂôËùºÍÆäËû×Ó¹«Ë¾¡£SEC ³Æ£¬ÑÓ³¤»ã±¨²»½öÎ¥·´ÁËÁª¹úÂÉÀý£¬Ò²Î¥·´ÁË ICE ×Ô¼ºµÄ·¨Ê½¡£
https://therecord.media/sec-penalty-intercontinental-exchange-cybersecurity-incident
2. Êý°ÙÍòÃÀ¹úÈË·¸×ï¼Í¼Êý¾Ý¿â±»Ð¹Â¶µ½ÍøÉÏ
5ÔÂ22ÈÕ£¬Ò»¸öÒÔ EquationCorp ºÍ USDoD ΪÃûµÄÍøÂç·¸×ï·Ö×Ó°ä²¼ÁËÒ»¸öÖØ´óµÄÊý¾Ý¿â£¬ÆäÖÐÔ̺¬Êý°ÙÍòÃÀ¹úÈ˵ķ¸×ï¼Í¼¡£Ìý˵¸ÃÊý¾Ý¿âÔ̺¬ 7000 ÍòÐÐÊý¾Ý¡£¾Ý³Æ£¬Ð¹Â¶µÄÊý¾Ý¿âÔ̺¬È«Ãû¡¢µ®ÉúÈÕÆÚ¡¢ÒÑÖª±ðºÅ¡¢µØÖ·¡¢¿ÛÁôºÍ¶¨×ïÈÕÆÚ¡¢ÐÌÆÚµÈ¡£¾Ý±¨Â·£¬ÈÕÆÚÁìÓò´Ó 2020 Äêµ½ 2024 Äê¡£¸ÃÊý¾Ý¿âµÄ¾ßÌåÆðԴĿǰÉв»Ã÷ÏÔ¡£ÎãÓ¹ÖÃÒÉ£¬·¸×ïÐÅϢй¶½«²úÉú¾Þ´óÓ°Ï죬²»½ö¶ÔÃûµ¥ÉϵÄÓ×ÎÒ£¬²¢ÇÒ¶Ô˾·¨ÏµÍ³Ò²ÊÇÈç´Ë¡£
https://www.malwarebytes.com/blog/news/2024/05/criminal-record-database-of-millions-of-americans-dumped-online
3. ×êÑÐÈËÔ±·¢ÏÖ¼ÓÃܽٳֹ¥»÷¿É½ûÓö˵㱣»¤
5ÔÂ23ÈÕ£¬×êÑÐÈËÔ±°µÊ¾£¬×î½üÔÚÒ°·¢ÏֵĶñÒâÈí¼þʹÓø´ÔӵĴëÊ©À´½ûÓ÷À²¡¶¾±£»¤£¬Ïú»ÙϰȾ֤¾Ý£¬²¢Ê¹ÓüÓÃÜÇ®±ÒÍÚ¾òÈí¼þÓÀԶϰȾ»úе¡£ÈÃÕâ¸öÒì³£¸´ÔӵĶñÒâÈí¼þϵͳÔËÐеĹؼüÊÇÖ÷ÔØºÉÖеÄÒ»ÏîÖ°ÄÜ£¬ÃûΪ GhostEngine£¬ËüÄܹ»½ûÓà Microsoft Defender »òÖ¸±êÍÆËã»úÉÏ¿ÉÄÜÔËÐеÄÈÎºÎÆäËû·À²¡¶¾»ò¶Ëµã±£»¤Èí¼þ¡£Ëü»¹°µ²ØÁËÈκα»ÈëÇÖµÄÖ¤¾Ý¡£GhostEngine ¶ñÒâÈí¼þµÄÊ×ÒªÖ¸±êÊÇʹ¶Ëµã°²È«½â¾ö¹æ»®Ê§Ð§²¢½ûÓÃÌØ¶¨µÄ Windows ÊÂÎñÈÕÖ¾£¬ÀýÈç¼Í¼¹ý³Ì´´½¨ºÍ·þÎñ×¢²áµÄ°²È«ºÍϵͳÈÕÖ¾¡£
https://arstechnica.com/security/2024/05/researchers-spot-cryptojacking-attack-that-disables-endpoint-protections/
4. OmniVisionÔÚ2023ÄêÀÕË÷¹¥»÷ºóÅû¶Êý¾Ýй¶ÊÂÎñ
5ÔÂ22ÈÕ£¬OmniVision Technologies ÊÇÒ»¼ÒרÃÅ¿ª·¢ÏȽøÊý×Ö³ÉÏñ½â¾ö¹æ»®µÄ¹«Ë¾¡£2023 Ä꣬OmniVision Õ¼ÓÐ 2,200 ÃûÔ±¹¤£¬ÄêÊÕÈëΪ 14 ÒÚÃÀÔª¡£OmniVision Technologies Inc. ÊÇÖйú°ëµ¼ÌåÆ÷¼þºÍ»ìºÏÐźż¯³Éµç·Éè¼Æ¹«Ë¾Î¤¶û°ëµ¼ÌåµÄÃÀ¹ú×Ó¹«Ë¾¡£¸Ã¹«Ë¾Éè¼ÆºÍ¿ª·¢ÓÃÓÚÊÖ»ú¡¢±Ê¼Ç±¾µçÄÔ¡¢ÉÏÍø±¾ºÍÍøÂçÉãÏñÍ·¡¢°²È«ºÍ¼à¿ØÉãÏñÍ·¡¢ÓéÀÖ¡¢Æû³µºÍÒ½ÁƳÉÏñϵͳµÄÊý×Ö³ÉÏñ²úÆ·¡£2023 Ä꣬Õâ¼ÒͼÏñ´«¸ÐÆ÷Ôì×÷ÉÌÔâ·êÁËCactus ÀÕË÷Èí¼þ¹¥»÷¡£Ä¿Ç°Éв»Ã÷ÏÔÊÜÓ°ÏìÈËÊý¡£2023 Äê 10 Ô£¬Cactus ÀÕË÷Èí¼þ×éÖ¯ÔÚÆä Tor Ð¹Â©ÍøÕ¾´ó½« OmniVision Ôö³¤µ½Êܺ¦ÕßÃûµ¥ÖС£×÷ΪÊý¾Ýй¶µÄÖ¤¾Ý£¬¸ÃÀÕË÷×éÖ¯°ä²¼ÁËÊý¾ÝÑù±¾£¬Ô̺¬»¤ÕÕͼÏñ¡¢±£ÃܺÍ̸¡¢ºÏͬºÍÆäËûÎļþ¡£Ëæºó£¬ÔÚËùνµÄ½»ÉæÊ§°Üºó£¬¸ÃÍÅ»ïÃâ·Ñ°ä²¼ÁËËùÓб»µÁÊý¾Ý£¬²»Í⣬OmniVision ĿǰÒѲ»ÔÙÁÐÔÚ Cactus Êê½ðйÃÜÍøÕ¾ÉÏ¡£
https://securityaffairs.com/163506/data-breach/omnivision-data-breach.html
5. ConfluenceÔ¶³Ì´úÂëÖ´Ðзì϶CVE-2024-21683
5ÔÂ22ÈÕ£¬¿í·ºÊ¹ÓõÄÍŶӹ¤×÷ÇøÆóÒµ wiki Confluence ±»·¢ÏÖ´æÔÚÑϳÁµÄÔ¶³Ì´úÂëÖ´Ðзì϶¡£¸Ã·ì϶±»ÏóÕ÷Ϊ CVE-2024-21683£¬ÑϳÁÐÔΪ 8.3£¨¸ß£©¡£¸Ã·ì϶ӰÏì Confluence Êý¾ÝÖÐÐĺͷþÎñÆ÷µÄ¶à¸ö°æ±¾£¬Ô̺¬Êý¾ÝÖÐÐİ汾 8.9.0 ºÍ·þÎñÆ÷°æ±¾ 8.5.0 ÖÁ 8.5.8 LTS¡£²»Íâ¸Ã·ì϶ÒѾÔÚConfluence Data CenterºÍServerµÄ×îа汾Öн¨¸´¡£´Ë·ì϶ÔÊÐí¾¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÔÚϵͳÖÐÖ´ÐÐËÁÒâ´úÂ룬Õâ¿ÉÄÜ»á¶Ô CIA £¨»úÃÜÐÔ¡¢ÆëÈ«ÐԺͿÉÓÃÐÔ£©Ôì³ÉÑϳÁÓ°Ïì¡£´Ë±í£¬´Ë·ì϶²»±ØÒªÈκÎÓû§½»»¥¼´¿É³É¹¦¡£
https://gbhackers.com/critical-confluence-server-flaw/
6. London DrugsÒ©µêÈ·ÈÏÔâµ½ÀÕË÷¹¥»÷µ«²»Ö§¸¶Êê½ð
5ÔÂ22ÈÕ£¬ÄôóÁ¬ËøÒ©µêÂ×¶ØÒ©µê (London Drugs) ÒÑÈ·ÈÏÀÕË÷Èí¼þ·¸×ï·Ö×ÓÇÔÈ¡ÁËÆä²¿ÃÅÔ̺¬Ô±¹¤ÐÅÏ¢µÄ¹«Ë¾Îļþ£¬²¢°µÊ¾¡°²»Ô¸ÒâÒ²ÎÞ·¨ÏòÕâÐ©ÍøÂç·¸×ï·Ö×ÓÖ§¸¶Êê½ð¡±¡£Õâ¼Ò×ܲ¿Î»ÓÚ²»Áе߸çÂ×±ÈÑǵĹ«Ë¾ÔÚ¸øThe RegisterµÄÒ»·ÝÉêÃ÷Öгƣ¬4 Ô 28 ÈÕµÄÈëÇÖÊÂÎñÊÇ¡°ÓÉһȺ¸ÉÁ·µÄÈ«ÇòÍøÂç·¸×ï·Ö×Ó¾«ÐIJ߶¯µÄ¹¥»÷¡±£¬¶ø¸Ã¹«Ë¾´ËÇ°Ôø³ÆÆäΪ¡°ÍøÂ簲ȫÊÂÎñ¡±¡£ Õâ´ÎÊý×ÖÈëÇÖÊÂÎñÆÈʹÂ×¶ØÒ©µêÔÚ²»Áе߸çÂ×±ÈÑÇÊ¡¡¢°¢¶û²®ËþÊ¡¡¢ÈøË¹¿¦³¹ÎÂÊ¡ºÍÂíÄáÍаÍÊ¡µÄ 79 ¼ÒÃÅµê¹Ø¹ØÖÁ 5 Ô 7 ÈÕ£¬µ«Ò©·¿¹¤×÷ÈËÔ±ÈÔÔÚµê±íÅÇ»²ÒÔÅäÔì³ÁÒª´¦·½¡£
https://www.theregister.com/2024/05/22/london_drugs_ransomware/


¾©¹«Íø°²±¸11010802024551ºÅ