¶àÂ×¶à½ÌÓý¾ÖÔâLockBitÀÕË÷Èí¼þ¹¥»÷£¬Ñ§ÉúÐÅϢй¶

°ä²¼¹¦·ò 2024-09-03
1. ¶àÂ×¶à½ÌÓý¾ÖÔâLockBitÀÕË÷Èí¼þ¹¥»÷£¬Ñ§ÉúÐÅϢй¶


8ÔÂ31ÈÕ£¬¶àÂ×¶àµØÓò½ÌÓý¾Ö£¨TDSB£©±¾ÖÜÈ·ÈÏÁË6Ô·ݲúÉúµÄÒ»´ÎÀÕË÷Èí¼þ¹¥»÷ÊÂÎñ£¬¸ÃÊÂÎñÉæ¼°Ñ§ÉúÐÅÏ¢µÄй¶¡£Ö»¹Ü×î³õ½ÌÓý¾Ö°µÊ¾¹¥»÷½öÕë¶ÔÒ»¸ö¼¼Êõ²âÊÔ»·¾³£¬Óë¹Ù·½ÍøÂç¸ôÀ룬µ«ºóÐøÖ¤Êµ2023/2024ѧÄêÖв¿ÃÅѧÉúµÄÓ×ÎÒÐÅÏ¢£¬Ô̺¬ÐÕÃû¡¢Ñ§ÌÃÏêÇé¡¢Äê¼¶¡¢ÓÊÏ䵨ַ¡¢Ñ§ºÅ¼°µ®ÉúÈÕÆÚµÈ£¬È·ÇÐʵ²âÊÔ»·¾³Öб»Ð¹Â¶¡£½ÌÓý¾ÖÇ¿µ÷£¬¾­ÍøÂ簲ȫÍÅ¶ÓºÍ±í²¿×¨¼ÒÆÀ¹À£¬Ñ§ÉúÃæ¶ÔµÄ·çÏÕ¡°ºÜµÍ¡±£¬ÇÒδ·¢ÏÖÊý¾Ý¹«¿ªÅû¶µÄÇé¿ö¡£È»¶ø£¬LockBitÀÕË÷Èí¼þÍÅ»ïËæºóÈÏ¿ÉÁËÕâ´Î¹¥»÷£¬²¢ÔÚÆäйÃÜÍøÕ¾Éϸø½ÌÓý¾ÖÉ趨ÁËÖ§¸¶Êê½ðµÄÆÚÏÞ£¬µ«Î´¹«¿ª¾ßÌåÊê½ðÊý¶î¡£TDSBÉÐδ¾ÍLockBitµÄÉêÃ÷×÷³ö»ØÓ¦£¬µ«ÒÑÖÂÐżҳ¤×¢Ã÷Çé¿ö£¬²¢Ç¿µ÷ÒѲÉÈ¡¶àÏî´ëÊ©¼ÓǿѧÉúÐÅÏ¢°²È«£¬Í¬Ê±¹²Í¬·¨Âɲ¿Ãŵ÷²é¡£Õâ´ÎÊÂÎñ²úÉúÔÚLockBitÍÅ»ïÖÙ´º·ÝÔâ½ø¹¥ºóÊÔͼ¸´³öµÄ²¼¾°Ï£¬Æä°ä²¼µÄÊܺ¦ÕßÐÅÏ¢ÖдæÔÚ²»ÉÙÃýÎó»ò³Á¸´Ìõ¿î£¬Òý·¢×¨¼ÒÖÊÒÉ¡£


https://therecord.media/toronto-school-district-board-ransomware


2. ÐÂÐÍÀÕË÷Èí¼þCicada3301»îÔ¾£¬»òÓëALPHVÓйØÁª


9ÔÂ2ÈÕ£¬ÐÂÐÍÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©Cicada3301½üÆÚÔÚÍþвÁìÓòո¶ͷ½Ç£¬Õë¶Ô¶à¼Ò¹«Ë¾ÌáÒé¹¥»÷£¬Æä»îÔ¾ÐÔÁîÈËÖõÄ¿¡£×Ô6ÔÂÒÔÀ´£¬Cicada3301ͨ¹ýRAMPÍøÂç·¸×ïÂÛ̳ÕÐļ³ÉÔ±£¬Ñ¡È¡Rust˵»°±àд£¬Ö§³ÖWindows¼°Linux/ESXiϵͳ£¬ÏÔʾ³öÓëÒÑDzɢµÄBlackCat/ALPHV×éÖ¯ÔÚ¼¼ÊõÉϵÄÀàËÆÐÔ£¬Ô̺¬¼ÓÃÜËã·¨¡¢ºÅÁîʹÓúÍÎļþ¶¨ÃûÔ¼¶¨¡£Cicada3301ͨ¹ýÇÔÈ¡»ò±©Á¦ÆÆ½âƾ֤µÇ¼ϵͳ£¬Ê¹ÓõÄIPµØÖ·ÓëBrutus½©Ê¬ÍøÂçÓйØÁª£¬¿ÉÄÜÅú×¢Á½Õß¼äµÄijÖÖÁªÏµ¡£Æä³õʼ¹¥»÷¼¿Á©¶àÑù£¬Ô̺¬Õë¶ÔVMware ESXiϵͳµÄ³ö¸ñ±äÌå¡£¸ÃÀÕË÷Èí¼þ¾ß±¸¸ß¶È¿ÉÅäÖÃÐÔ£¬ÔÊÐí²Ù×÷Ô±ÔÚÖ´Ðйý³ÌÖе÷ÕûÆäÐÐΪ£¬ÈçÑÓ³¤Ö´ÐÓ×¢ÏÔʾ¼ÓÃܽø¶È¼°ÔÚ¼ÓÃÜESXiÖ÷»úÎļþʱÎÞÐè¹Ø¹ØÐé¹¹»úµÈ£¬ÕâЩְÄܼÓÇ¿ÁËÆäÊÊÓ¦ÐԺͽýÝÐÔ¡£¼ÓÃܹý³ÌÖУ¬Cicada3301ʹÓÃOsRngËæ»úÊýÌìÉúÆ÷ÌìÉú¶Ô³ÆÃÜÔ¿£¬²¢Í¨¹ýPGP¹«Ô¿¼ÓÃÜÕâЩÃÜÔ¿£¬Í¬Ê±ÔÚÿ¸ö¼ÓÃÜÎļþ¼ÐÖÐÁôÏÂÊê½ð×¢Ã÷Îļþ¡£¼ÓÃÜʵÏÖºó£¬ChaCha20ÃÜÔ¿±»RSA¼ÓÃÜ£¬²¢Óë¼ÓÃÜÎļþÀ©´óÃûÒ»Æð¸½¼Óµ½Îļþĩ⣬ÐÎ³ÉÆëÈ«µÄÀÕË÷ÐÅÏ¢¡£


https://securityaffairs.com/167897/cyber-crime/a-new-variant-of-cicada-ransomware-targets-vmware-esxi-systems.html


3. Â׶ؽ»Í¨¾ÖÓ¦¶ÔÍøÂç¹¥»÷£¬ÉÐÎÞÖ¤¾ÝÏÔʾ¿Í»§Êý¾Ýй¶


9ÔÂ2ÈÕ£¬Â׶ؽ»Í¨¾Ö£¨TfL£©ÕýÈ«Á¦Ó¦¶Ôһ·ÔÚ½øÐÐÖеÄÍøÂç¹¥»÷£¬Í¬Ê±Ïò¹«¼Ò±£ÕÏ£¬Ä¿Ç°ÉÐÎÞÈ·ÔäÖ¤¾ÝÅú×¢¿Í»§Ó×ÎÒÐÅÏ¢ÒÑÒò¶ø´ÎÊÂÎñ¶øÐ¹Â¶£¬ÇÒTfLµÄ¸÷Ïî·þÎñÔË×÷Õý³££¬Î´ÊÜÏÔÖøÓ°Ïì¡£×÷ΪÂ׶صØÓò½»Í¨ÍøÂçµÄÖØÒªÖÎÀí»ú¹¹£¬TfLѸ¿ìÏìÓ¦£¬Óë¹ú¶È·¸×ï¾Ö£¨NCA£©¼°¹ú¶ÈÍøÂ簲ȫÖÐÐÄ£¨NCSC£©çÇÃܺÏ×÷£¬²ÉÈ¡ÁËһϵÁÐÄÚ²¿´ëÊ©ÒÔ¼ÓÇ¿ÍøÂ簲ȫ·À»¤¡£¾ÝÄÚ²¿ÐÂÎÅй©£¬Õâ´Î¹¥»÷ÖØÒª¼¯ÖÐÓÚTfL×ܲ¿µÄºó¶Üϵͳ£¬´Ùʹ²¿ÃÅÔ±¹¤±»½¨Òé¾Ó¼Ò°ì¹«ÒÔÏ÷¼õDZÔÚ·çÏÕ¡£TfLÊ×ϯ¼¼Êõ¹ÙShashi VermaÇ¿µ÷£¬±£»¤ÏµÍ³Óë¿Í»§Êý¾ÝµÄ°²ÂúÊÇÊ×Òª¹¤×÷£¬ÍŶӽ«³ÖÐø¼à¿Ø²¢ÆÀ¹ÀÊÂ̬·¢Õ¹£¬È·±£¹«¼Ò³öÐа²È«ÓëÐÅÀµ²»ÊÜÇÖº¦¡£×ÜÌå¶øÑÔ£¬Ö»¹ÜÃæ¶ÔÌôÕ½£¬TfLչʾ³ö»ý¼«Ó¦¶ÔµÄ̬¶È£¬Á¦Çó½«Ç±ÔÚÓ°Ïì½µÖÁ×îµÍ¡£


https://securityaffairs.com/167946/hacking/transport-for-london-tfl-ongoing-cyberattack.html


4. µØÀí¶¨Î»×·×Ù·þÎñTracelo³¬140ÍòÈËÐÅÏ¢ÔâºÚ¿Íй¶


9ÔÂ2ÈÕ£¬ÖÇÄÜÊÖ»úµØÀí¶¨Î»×·×Ù·þÎñTraceloÔÚ9ÔÂ1ÈÕÔâ·ê³Á´óÊý¾Ýй¶ÊÂÎñ£¬ºÚ¿Í¡°Satanic¡±Ðû³Æ¹¥ÆÆÁËÆäϵͳ£¬²¢ÔÚÍøÂç°µÅÌÉϹ«¿ªÁ˳¬¹ý140ÍòÈ˵ÄÓ×ÎÒÐÅÏ¢£¬Òý·¢¿í·º¹Ø×¢¡£Tracelo×÷ΪÐÂÐË·þÎñ£¬Ëä±ê°ñ·µÂ¹æ·¶µÄ¶¨Î»×·×Ù£¬µ«ÆäÔÚÊý¾ÝÍøÂçÓëÔÞ³ÉÑéÖ¤ÉϵÄͨÃ÷¶È²»¼°£¬Òý·¢ÁËÒþÖÔ±£»¤ÕùÒé¡£Õâ´Îй¶µÄÊý¾ÝÔ̺¬Óû§È«Ãû¡¢µç»°ºÅÂë¡¢ÎïÀíµØÖ·¡¢µç×ÓÓʼþµÈÃô¸ÐÐÅÏ¢£¬ÒÔ¼°´óÁ¿¿Í»§µÄGoogle IDºÅ£¬ºóÕß¿ÉÄܽøÒ»²½Â¶³öÓû§µÄÈÕ³£»î¶¯¹ì¼£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬Ö»¹ÜTraceloÖ¼ÔÚÔ®ÊÖÓû§×·×ÙËûÈ˵ØÎ»£¬µ«Ð¹Â¶µÄÊý¾ÝÖв¢Î´Ô̺¬Ö¸±êÓ×ÎÒµÄλÏàÐÅÏ¢£¬·´¶øÖØÒªÊǿͻ§×ÔÉíµÄ¾ßÌå×ÊÁÏ¡£ÊÜÓ°ÏìµÄÓû§Ãæ¶ÔÍøÂç´¹µöºÍÓïÒô´¹µöÚ¿Æ­µÄÍþвÔö³¤£¬Òò¶øÐè¸ß¶È¾¯ÌèÀ´×Ô²»Ã÷ÆðÔ´µÄÓʼþºÍµç»°£¬Ô¤·Àй¶¸ü¶àÓ×ÎÒÐÅÏ¢¡£


https://hackread.com/tracelo-location-tracker-data-breach-user-records-leak/


5. CBIZÊý¾Ýй¶ÊÂÎñÆØ¹â£¬½ü36,000¿Í»§ÐÅÏ¢ÔâÇÔ


9ÔÂ2ÈÕ£¬CBIZ¸£ÀûÓë±£ÏÕ·þÎñ¹«Ë¾Åû¶ÁËһ·ÑϳÁµÄÊý¾Ýй¶ÊÂÎñ£¬¸ÃÊÂÎñÉæ¼°½ü36,000Ãû¿Í»§µÄÃô¸ÐÐÅÏ¢±»Î´¾­ÊÚȨ½Ó¼û¡£¾ÝϤ£¬Ò»ÃûÍþвÐÐΪÕßÀûÓÃCBIZÍøÒ³Öеݲȫ·ì϶£¬ÔÚ6ÔÂ2ÈÕÖÁ21ÈÕÆÚ¼äDZÈëϵͳ²¢ÇÔÈ¡ÁËÔ̺¬ÐÕÃû¡¢ÁªÏµ·½Ê½¡¢Éç»á°²È«ºÅÂë¡¢µ®Éú/éæÃüÈÕÆÚ¡¢ÍËÐÝÈËÔ±½¡È«ÐÅÏ¢¼°¸£Àû´òËãÐÅÏ¢ÔÚÄڵĿͻ§Êý¾Ý¡£CBIZ×÷ΪÃÀ¹úµ±ÏȵÄ×ÛºÏÐÔ·þÎñÌṩÉÌ£¬ÒµÎñÁìÓòº­¸Ç¹ÜÕÊ˰Îñ¡¢±£ÏÕ¡¢Ã³Ò×Õ÷ѯ¼°ÈËÁ¦×ÊÔ´µÈ¶à¸öÁìÓò£¬ÔÚÈ«¹úÕ¼ÓÐ120¸ö´¦Ê´¦¼°6,700ÃûÔ±¹¤£¬2023ÄêÊÕÈë¸ß´ï15.9ÒÚÃÀÔª¡£¹«Ë¾ÒÑÓÚ6ÔÂ24ÈÕ·¢ÏÖÕâ´ÎÈëÇÖ£¬²¢µ±¼´×ÅÊÖµ÷²é¡£ÊÜÓ°Ïì¿Í»§×Ô8ÔÂ28ÈÕÆðÂ½ÐøÊÕµ½¸öÐÔ»¯Í¨Öª£¬CBIZËäδ·¢ÏÖÊý¾ÝÀÄÓü£Ï󣬵«ÈÔÌṩΪÆÚÁ½ÄêµÄÐÅÓþ¼à¿ØºÍÉí·Ý͵ÇÔ±£»¤·þÎñ£¬²¢½¨Òé¿Í»§²ÉÈ¡¶î±í´ëÊ©ÈçÐÅÓþ¶³½á¼°Ôö³¤Ú²Æ­¾¯±¨£¬ÒÔ½µµÍDZÔÚ·çÏÕ¡£


https://www.bleepingcomputer.com/news/security/business-services-giant-cbiz-discloses-customer-data-breach/


6. Prasarana Malaysia BhdÔâÀÕË÷¹¥»÷£¬³¬300GBÊý¾Ýй¶


8ÔÂ30ÈÕ£¬ÂíÀ´Î÷Ñǹ«¹²½»Í¨¾ÞÍ·¹ú¶È»ù½¨¹«Ë¾£¨Prasarana Malaysia Bhd£©½üÈÕÈ·ÈÏÁËÉ罻ýÌåÉÏÁ÷´«µÄÒ»ÔòÍøÂ簲ȫÊÂÎñ±¨Â·µÄÕæÊµÐÔ£¬Ö¸³öÆäÄÚ²¿ÏµÍ³È·ÒÑÔâ·êδÊÚȨ½Ó¼û¡£Ö»¹ÜÕâ´ÎÊÂÎñÉÐδ¶Ô¹«Ë¾µÄÈÕ³£ÔËÓªÔì³ÉÓ°Ï죬µ«¹«Ë¾ÒÑѸ¿ì²ÉÈ¡Ðж¯£¬½áºÏÍøÂ簲ȫר¼Ò·¢Õ¹È«Ãæµ÷²é£¬²¢×ÅÊÖ»º½âDZÔÚÍþв¡£Í¬Ê±£¬¹ú¶È»ù½¨¹«Ë¾ÒÑÓëÂíÀ´Î÷Ñǹú¶ÈÍøÂ簲ȫ¾Ö£¨Nacsa£©¼°ÍøÂ簲ȫ»ú¹¹£¨CyberSecurity Malaysia£©çÇÃܺÏ×÷£¬¹²Í¬Ôì¶©²¢Ö´ÐÐÈ«ÃæµÄ°²È«·ÀÓùÕ½Êõ£¬ÒÔ±£ÏÕÆä½»Í¨·þÎñϵͳµÄ°²È«²»±äÔËÐС£×÷ΪÂíÀ´Î÷Ñǹ«¹²½»Í¨ÏµÍ³µÄ³ÁÒª×é³É²¿ÃÅ£¬¹ú¶È»ù½¨¹«Ë¾²»½öÔËÓªRapidKLÆìϵÄÇá¹ì¡¢½ÝÔË¡¢°ÍÊ¿¼±¾ç½»Í¨ÏµÍ³£¬»¹ÖÎÀí¼ªÂ¡ÆÂµ¥¹ìÁгµ¼°ÖØ´óµÄ¹«½»³µ¶Ó¡£ÕâÒ»ÉêÃ÷Ö¼ÔÚ»ØÓ¦±í½ç¹ØÓÚ¹«Ë¾ÍøÕ¾¿ÉÄÜÔâ·êÀÕË÷Èí¼þ¹¥»÷£¬µ¼ÖÂ316GBÊý¾Ýй¶µÄ´«ÑÔ¡£¾ÝϤ£¬ÀÕË÷Èí¼þ×éÖ¯RansomHubÒÑ·¢³öÍþв£¬Ðû³Æ½«ÔÚÁùµ½ÆßÌìÄÚ¹«½¨¹ú¶È»ù½¨¹«Ë¾µÄÃô¸ÐÊý¾Ý¡£


https://www.freemalaysiatoday.com/category/nation/2024/08/26/prasarana-confirms-cybersecurity-incident/