¶íÂÞ˹ÄÜÔ´¹«Ë¾GazpromÔ¼1.5 GBµÄÊý¾Ýй¶
Ðû²¼Ê±¼ä 2023-02-02
¾ÝýÌå1ÔÂ31ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬IT Army of UkraineÉù³ÆÒѾÈëÇÖÁ˶íÂÞ˹ÄÜÔ´¹«Ë¾GazpromµÄ»ù´¡ÉèÊ©£¬£¬£¬£¬£¬£¬£¬²¢»ñµÃÁË1.5 GBµÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÊý¾ÝÉæ¼°Óë½ðÈں;¼Ã»î¶¯Ïà¹ØµÄÐÅÏ¢¡¢²âÊÔºÍ×ê̽±¨¸æÒÔ¼°¿ÆÎ¬¿Ë͢˹»ù¾®×Ô¶¯»¯ÏµÍ³µÄʵÑéºÍµ÷½â¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬¸ÃÍŻﻹÐû²¼ÁËÒ»·Ý°üÀ¨ÔÚGazpromÐÒéÖеı£ÃÜÉùÃ÷¡£¡£¡£¡£¡£¡£¡£2022Äê4Ô£¬£¬£¬£¬£¬£¬£¬Çå¾²Ñо¿Ö°Ô±Jeff CarrÔøÍ¸Â¶£¬£¬£¬£¬£¬£¬£¬ ÎÚ¿ËÀ¼¹ú·À²¿Ç鱨×ܾÖ(GURMOÒ»Ö±ÔÚÕë¶ÔGazprom¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/141640/hacktivism/it-army-of-ukraine-hacked-gazprom.html
2¡¢Å·ÖÞÆû³µÁãÊÛÉÌArnold ClarkÔâµ½PlayÀÕË÷¹¥»÷
ýÌå2ÔÂ1Èճƣ¬£¬£¬£¬£¬£¬£¬Æû³µÁãÊÛÉÌArnold ClarkÕýÔÚ֪ͨ²¿·Ö¿Í»§¹ØÓÚPlayÀÕË÷¹¥»÷µ¼ÖµÄÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾×Ô³ÆÎªÅ·ÖÞ×î´óµÄ×ÔÁ¦Æû³µÁãÊÛÉÌ£¬£¬£¬£¬£¬£¬£¬Æä±¾ÖܶþÔÚ·¢Ë͸ø±»Ó°Ïì¿Í»§µÄ֪ͨ͸¶£¬£¬£¬£¬£¬£¬£¬±»µÁÊý¾Ý°üÀ¨Ð¡ÎÒ˽¼ÒÉí·ÝÐÅÏ¢ºÍÒøÐÐÕÊ»§ÏêϸÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¹¥»÷±¬·¢ÔÚ2022Äê12ÔÂ23ÈÕ£¬£¬£¬£¬£¬£¬£¬ÆäÓÚ12ÔÂ24ÈÕÉÏÎç¶Ï¿ªÁËϵͳµÄÍøÂçÀ´ÇжϹ¥»÷ÕߵĻá¼û¡£¡£¡£¡£¡£¡£¡£´ÓÄÇʱÆð£¬£¬£¬£¬£¬£¬£¬Arnold ClarkÒ»Ö±ÔÚÖÂÁ¦ÓÚ»Ö¸´ÊÜËðϵͳ¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Òѽ«´Ëʼû¸æÖ´·¨²¿·ÖºÍÏà¹ØÕþ¸®£¬£¬£¬£¬£¬£¬£¬²¢ÌáÐѿͻ§Ð¡ÐÄDZÔڵĴ¹Âڻ¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/arnold-clark-customer-data-stolen-in-attack-claimed-by-play-ransomware/
3¡¢EclypsiumÅû¶AMI MegaRAC BMCÈí¼þÖеĶà¸öÎó²î
EclypsiumÔÚ1ÔÂ30ÈÕÅû¶ÁËAMI MegaRAC»ù°åÖÎÀí¿ØÖÆÆ÷(BMC)Èí¼þÖеÄÁ½¸öÎó²î¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±×î³õ·¢Ã÷ÁËÎå¸öÎó²î²¢½«ËüÃÇͳ³ÆÎªBMC&C£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÈý¸öÒÑÓÚ2022Äê12Ô·ÝÅû¶£¬£¬£¬£¬£¬£¬£¬ÁíÍâÁ½¸ö±£´æµ½ÏÖÔÚÊÇΪAMIÌṩ¸ü¶àʱ¼äÀ´Éè¼ÆÊʵ±µÄ»º½â²½·¥¡£¡£¡£¡£¡£¡£¡£ÕâÁ½¸öÎó²î»®·ÖΪͨ¹ýAPI¾ÙÐÐÃÜÂëÖØÖÃ×èµ²µÄÎó²î£¨CVE-2022-26872£©ºÍRedfishºÍAPIµÄÈõÃÜÂëhashÎó²î£¨CVE-2022-40258£©¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬¼¼¼Î¡¢»ÝÆÕ¡¢Ó¢ÌضûºÍåÚÏë¶¼Ðû²¼Á˸üУ¬£¬£¬£¬£¬£¬£¬NVIDIAÔ¤¼Æ»áÔÚ5ÔÂÐû²¼ÐÞ¸´³ÌÐò¡£¡£¡£¡£¡£¡£¡£
https://eclypsium.com/2022/12/05/supply-chain-vulnerabilities-put-server-ecosystem-at-risk/
4¡¢Ñо¿Ö°Ô±·¢Ã÷¶à¸öð³äChatGPTµÄÓ¦ÓÃÖ¼ÔÚÇÔÊØÐÅÏ¢
¾Ý1ÔÂ31ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÔÚiOSºÍPlay Store·¢Ã÷Á˶à¸öð³äµÄChatGPT¿Ë¡ӦÓ㬣¬£¬£¬£¬£¬£¬»áÍøÂçÓû§Êý¾Ý²¢·¢Ë͵½Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£ChatGPTÊÇOpenAIÓÚ2022Äê11ÔÂÍÆ³öµÄ̸Ìì»úеÈË£¬£¬£¬£¬£¬£¬£¬²¢Ã»ÓÐÊÊÓÃÓÚiOS»òPlay StoreµÄ¹Ù·½Ó¦ÓóÌÐò¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÆÊÎöÁËÈí¼þÉ̳ÇÖÐÅÅÃû×î¸ßµÄÊ®¸ö¿Ë¡ӦÓ㬣¬£¬£¬£¬£¬£¬ËüÃǶ¼ÔÚÍøÂçºÍ¹²ÏíÒþ˽±£»£»£»£»£»£»¤²»¼ÑµÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£ÌØÊâÊÇÆäÖеÄÒ»¸öAndroidÓ¦Ó㬣¬£¬£¬£¬£¬£¬ÏÂÔØÁ¿ÒÑÁè¼Ý100000£¬£¬£¬£¬£¬£¬£¬»á¸ú×Ù²¢Óë×Ö½ÚÌø¶¯ºÍÑÇÂíÑ·µÈ¹«Ë¾¹²ÏíλÖÃÊý¾Ý¡£¡£¡£¡£¡£¡£¡£
https://www.hackread.com/chatgpt-clone-apps-collect-ios-play-store/
5¡¢Ó¢¹úPlanet IceµÄϵͳ±»ºÚÁè¼Ý24ÍòÈ˵ÄÐÅϢй¶
ýÌå2ÔÂ1ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬Ó¢¹úPlanet Ice³ÆºÚ¿ÍÈëÇÖÆäϵͳ²¢ÇÔÈ¡ÁË240488¸ö¿Í»§µÄÏêϸÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÉÏÖܳõ£¬£¬£¬£¬£¬£¬£¬Óû§ÔÚÍøÉ϶©Æ±Ê±ÊÕµ½ÁËÒ»Ìõ¼ò¶ÌµÄÐÂÎÅ£¬£¬£¬£¬£¬£¬£¬Ú¹ÊÍ˵Planet IceµÄЧÀÍÆ÷ÕýÔÚÂÄÀúÍýÏëÍâµÄÍ£»£»£»£»£»£»ú¡£¡£¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬£¬²¿·Ö¿Í»§ÊÕµ½À´×ÔPlanet IceµÄÓʼþ£¬£¬£¬£¬£¬£¬£¬Í¸Â¶ËüµÄIce AccountϵͳÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬Î´¾ÊÚȨµÄ¸÷·½¿É»á¼ûϵͳµÄ·Ç²ÆÎñÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Òѽ«´Ë´ÎÎ¥¹æÊÂÎñ֪ͨICO£¬£¬£¬£¬£¬£¬£¬²¢¶ÔÆäÕö¿ªÊӲ졣¡£¡£¡£¡£¡£¡£
https://www.bitdefender.com/blog/hotforsecurity/planet-ice-hacked-240-000-skating-fans-details-stolen/
6¡¢ESETÐû²¼¹ØÓÚ2022ÄêT3 APT¹¥»÷»î¶¯µÄÆÊÎö±¨¸æ
1ÔÂ31ÈÕ£¬£¬£¬£¬£¬£¬£¬ESETÐû²¼2022ÄêT3 APT»î¶¯ÆÊÎö±¨¸æ£¬£¬£¬£¬£¬£¬£¬×ܽáÁË´Ó2022Äê9ÔÂÖÁ12ÔÂβÊӲ졢ÊÓ²ìºÍÆÊÎöµÄÌØ¶¨APT×éÖ¯µÄ»î¶¯¡£¡£¡£¡£¡£¡£¡£ÔÚ¼à²âµÄʱ¼äÄڵĻ°üÀ¨£¬£¬£¬£¬£¬£¬£¬Õë¶ÔÎÚ¿ËÀ¼°²ÅÅÆÆËðÐÔµÄÊý¾Ý²Á³ý³ÌÐòºÍÀÕË÷Èí¼þµÄ»î¶¯¡¢Õë¶ÔÈÕ±¾ÕþÖÎ×éÖ¯µÄMirrorFaceÓã²æÊ½´¹Âڻ¡¢POLONIUM¹¥»÷ÒÔÉ«Áй«Ë¾µÄÍâ¹ú×Ó¹«Ë¾ÒÔ¼°Ó볯ÏÊÏà¹ØµÄ×é֯ʹÓþÉÎó²îÀ´ÈëÇÖ¼ÓÃÜÇ®±Ò¹«Ë¾ºÍÉúÒâËùµÈ»î¶¯¡£¡£¡£¡£¡£¡£¡£
https://www.welivesecurity.com/wp-content/uploads/2023/01/eset_apt_activity_report_t32022.pdf