·áÌïÔÆÐ§ÀÍÉèÖùýʧй¶ÑÇÖ޺ʹóÑóÖÞ¿Í»§ÐÅÏ¢Ô¼ÆßÄê

Ðû²¼Ê±¼ä 2023-06-02

1¡¢·áÌïÔÆÐ§ÀÍÉèÖùýʧй¶ÑÇÖ޺ʹóÑóÖÞ¿Í»§ÐÅÏ¢Ô¼ÆßÄê


¾Ý5ÔÂ31ÈÕ±¨µÀ£¬£¬ £¬ £¬£¬£¬·áÌïÆû³µ·¢Ã÷ÁËÁíÍâÁ½¸öÉèÖùýʧµÄÔÆÐ§ÀÍ£¬£¬ £¬ £¬£¬£¬Ð¹Â¶Á˳µÖ÷µÄСÎÒ˽¼ÒÐÅÏ¢Áè¼ÝÆßÄê¡£¡£ ¡£¡£¡£¡£µÚÒ»¸öÔÆÐ§ÀÍÔÚ2016Äê10ÔÂÖÁ2023Äê5ÔÂʱ´úй¶ÁËÑÇÖ޺ʹóÑóÖÞ·áÌï¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢£¬£¬ £¬ £¬£¬£¬¸ÃÆû³µÖÆÔìÉÌÉÐδ˵Ã÷Óм¸¶à¿Í»§Êܵ½´Ë´ÎÊÂÎñµÄÓ°Ïì¡£¡£ ¡£¡£¡£¡£µÚ¶þ¸öÔÆÐ§ÀÍÔÚ2015Äê2ÔÂ9ÈÕÖÁ2023Äê5ÔÂ12ÈÕʱ´ú̻¶£¬£¬ £¬ £¬£¬£¬°üÀ¨ÈÕ±¾Ô¼260000¸ö¿Í»§µÄÆû³µµ¼º½ÏµÍ³Ïà¹ØµÄÐÅÏ¢¡£¡£ ¡£¡£¡£¡£ÊÜÓ°ÏìµÄ³µÁ¾ÊÇ·áÌï×ÓÆ·ÅÆÀ׿ËÈøË¹µÄ³µÐÍ¡£¡£ ¡£¡£¡£¡£·áÌïÌåÏÖ£¬£¬ £¬ £¬£¬£¬ËüÒѾ­ÊµÑéÁËÒ»¸öϵͳ£¬£¬ £¬ £¬£¬£¬¿ÉÒÔ°´ÆÚ¼à¿ØÆäËùÓÐÇéÐÎÖеÄÔÆÉèÖúÍÊý¾Ý¿âÉèÖ㬣¬ £¬ £¬£¬£¬ÒÔ±ÜÃâδÀ´ÔٴηºÆð´ËÀàÎÊÌâ¡£¡£ ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/toyota-finds-more-misconfigured-servers-leaking-customer-info/


2¡¢ÉúÎïÊÖÒÕ¹«Ë¾Enzo Biochem½ü250ÍòÈ˵ÄÁÙ´²Êý¾Ý±»µÁ


¾ÝýÌå6ÔÂ1ÈÕ±¨µÀ£¬£¬ £¬ £¬£¬£¬ÉúÎïÊÖÒÕ¹«Ë¾Enzo BiochemÔâµ½ÀÕË÷¹¥»÷£¬£¬ £¬ £¬£¬£¬µ¼ÖÂÔ¼2470000È˵ÄÁÙ´²²âÊÔÐÅϢй¶¡£¡£ ¡£¡£¡£¡£EnzoÖÆÔìºÍÏúÊÛ»ùÓÚDNAµÄ²âÊÔÒÔ¼ì²â²¡¶¾ºÍϸ¾ú¼²²¡£¡£ ¡£¡£¡£¡£¬£¬ £¬ £¬£¬£¬°üÀ¨COVID-19ºÍ°©Ö¢¡£¡£ ¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚ4ÔÂ11ÈÕ·¢Ã÷¿Í»§ÐÕÃûºÍ²âÊÔÐÅÏ¢£¬£¬ £¬ £¬£¬£¬ÒÔ¼°Ô¼600000¸öÉç»áÇå¾²ºÅÂë±»»á¼û£¬£¬ £¬ £¬£¬£¬ÏÖÔÚûÓÐÀÕË÷ÍÅ»ïÌåÏֶԴ˴ι¥»÷ÈÏÕæ¡£¡£ ¡£¡£¡£¡£Enzo³ÆÒѽ«ÆäϵͳÓ뻥ÁªÍø¶Ï¿ªÅþÁ¬£¬£¬ £¬ £¬£¬£¬ÏÖÔÚÈÔÔÚÊÓ²ì´ËÊÂÎñ¡£¡£ ¡£¡£¡£¡£


https://therecord.media/clinical-test-data-of-enzio-biochem-stolen


3¡¢ÑÇÂíÑ·ÒòRingºÍAlexaÇÖÕ¼ÒþË½ÃæÁÙ3000ÍòÃÀÔª· £¿£¿£¿£¿£¿£¿î


 Ã½Ìå5ÔÂ31Èճƣ¬£¬ £¬ £¬£¬£¬ÑÇÂíÑ·½«Ö§¸¶3000ÍòÃÀÔªµÄ· £¿£¿£¿£¿£¿£¿î£¬£¬ £¬ £¬£¬£¬ÒÔ½â¾öÃÀ¹úFTC¶ÔÆäRingºÍAlexaÏà¹ØµÄÇÖÕ¼Òþ˽µÄÖ¸¿Ø¡£¡£ ¡£¡£¡£¡£Í¶Ë߳ƣ¬£¬ £¬ £¬£¬£¬RingÊÚÓèÆäÔ±¹¤ºÍ³Ð°üÉÌ»á¼û˽ÈËÊÓÆµµÄȨÏÞ£¬£¬ £¬ £¬£¬£¬ÕâÇÖÕ¼Á˿ͻ§µÄÒþ˽¡£¡£ ¡£¡£¡£¡£Ëü»¹Ã»ÓÐʵÑé»ù±¾µÄÒþ˽ºÍÇå¾²²½·¥£¬£¬ £¬ £¬£¬£¬ºÚ¿Í¿ÉÈëÇÖÕÊ»§À´¿ØÖÆÏûºÄÕßµÄÏà»úºÍÊÓÆµ¡£¡£ ¡£¡£¡£¡£Æ¾Ö¤ÄâÒéµÄÏÂÁ£¬ £¬ £¬£¬£¬Ring±ØÐèÏòÏûºÄÕßÖ§¸¶580ÍòÃÀÔªµÄÍ˿¡£ ¡£¡£¡£¡£ÔÚÁíÒ»Æð°¸¼þÖУ¬£¬ £¬ £¬£¬£¬FTCºÍDOJÖ¸¿ØÑÇÂíÑ·Î¥·´¶ùͯÒþ˽·¨£¬£¬ £¬ £¬£¬£¬Î´ÄÜÓ¦âïÊѵÄÒªÇóɾ³ýËûÃǵļÒôºÍµØÀíλÖÃÐÅÏ¢¡£¡£ ¡£¡£¡£¡£Æ¾Ö¤ÄâÒéµÄÏÂÁ£¬ £¬ £¬£¬£¬ÑÇÂíÑ·±ØÐèÖ§¸¶2500ÍòÃÀÔª¡£¡£ ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/technology/amazon-faces-30-million-fine-over-ring-alexa-privacy-violations/


4¡¢BlackCatÉù³Æ¶ÔÖ´·¨ÊÖÒÕÆ½Ì¨CasepointµÄ¹¥»÷ÈÏÕæ


6ÔÂ1ÈÕ±¨µÀ³Æ£¬£¬ £¬ £¬£¬£¬ÀÕË÷ÍÅ»ïBlackCatÔÚÆäÍøÕ¾ÁгöÁËCasepoint¡£¡£ ¡£¡£¡£¡£CasepointÌṩÁËÒ»¸öÖ´·¨ÊÖÒÕÆ½Ì¨£¬£¬ £¬ £¬£¬£¬±»¶à¸öÃÀ¹ú»ú¹¹Ê¹Ó㬣¬ £¬ £¬£¬£¬°üÀ¨SEC¡¢FBIºÍÃÀÍõ·¨Ôº¡£¡£ ¡£¡£¡£¡£¸ÃÍÅ»ï³ÆÒÑÇÔÈ¡2TBµÄÃô¸ÐÊý¾Ý£¬£¬ £¬ £¬£¬£¬É漰״ʦ¡¢SEC¡¢DoD¡¢FBIºÍ¾¯Ô±µÈ¡£¡£ ¡£¡£¡£¡£¸ÃºÚ¿ÍÍÅ»ï¹ûÕæÁ˱»ÈëÇÖ»ù´¡ÉèÊ©µÄ²¿·Ö×ÊÔ´µÄƾ֤ÒÔ¼°¾Ý³ÆÊDZ»µÁÎļþµÄһЩͼƬ£¬£¬ £¬ £¬£¬£¬ÒÔ´ß´ÙCasepoint×îÏÈ̸ÅС£¡£ ¡£¡£¡£¡£BlackCat×Ô2021Äê11ÔÂ×îÏÈ»îÔ¾£¬£¬ £¬ £¬£¬£¬Êê½ðÒªÇó´Ó¼¸ÍòÃÀÔªµ½ÊýÍòÍòÃÀÔª²»µÈ¡£¡£ ¡£¡£¡£¡£


https://securityaffairs.com/146915/cyber-crime/blackcat-ransomware-casepoint.html


5¡¢Group-IB³ÆDark Pink¼ÌÐøÕë¶ÔÑÇÌ«µØÇøµÄ¾üÕþµÈÐÐÒµ


5ÔÂ31ÈÕ£¬£¬ £¬ £¬£¬£¬Group-IBÅû¶ÁËDark Pink½üÆÚÐÂÒ»ÂֵĹ¥»÷»î¶¯¡£¡£ ¡£¡£¡£¡£¸ÃÍÅ»ï×Ô2021ÄêÖÐÒÔÀ´Ò»Ö±»îÔ¾£¬£¬ £¬ £¬£¬£¬Ö÷ÒªÕë¶ÔÑÇÌ«µØÇøµÄ×éÖ¯¡£¡£ ¡£¡£¡£¡£Æ¾Ö¤×îÐÂÊÓ²ìЧ¹û£¬£¬ £¬ £¬£¬£¬Group-IBÈ·ÈÏÁË5¸öеı»¹¥»÷×éÖ¯£¬£¬ £¬ £¬£¬£¬°üÀ¨ÎÄÀ³¡¢Ó¡¶ÈÄáÎ÷ÑÇ¡¢Ì©¹úºÍÔ½ÄϵÄÕþ¸®¡¢¾ü¶ÓºÍ·ÇÓªÀû×éÖ¯£¬£¬ £¬ £¬£¬£¬ÒÔ¼°±ÈÀûʱµÄ½ÌÓý×éÖ¯¡£¡£ ¡£¡£¡£¡£¹¥»÷ʼÓÚ´¹ÂÚÓʼþÖеÄISOÎĵµ£¬£¬ £¬ £¬£¬£¬ËüʹÓÃDLL²à¼ÓÔØÀ´Æô¶¯ºóÃÅTelePowerBotºÍKamiKakaBot¡£¡£ ¡£¡£¡£¡£±ðµÄ£¬£¬ £¬ £¬£¬£¬Ö²Èë³ÌÐò´ÓÄÚ´æÖмÓÔØ£¬£¬ £¬ £¬£¬£¬²»½Ó´¥´ÅÅÌ£¬£¬ £¬ £¬£¬£¬ÕâÓÐÖúÓÚÈÆ¹ý¼ì²â¡£¡£ ¡£¡£¡£¡£ÔÚ×î½üµÄÒ»´Î¹¥»÷ÖУ¬£¬ £¬ £¬£¬£¬Dark PinkʹÓÃЧÀÍWebhookͨ¹ýHTTPЭÒéй¶±»µÁÊý¾Ý¡£¡£ ¡£¡£¡£¡£


https://www.group-ib.com/blog/dark-pink-episode-2/


6¡¢AT&T·¢Ã÷еÄSeroXen RATÖ÷Òª±»ÓÃÓÚ¹¥»÷ÓÎÏ·ÉçÇø


5ÔÂ30ÈÕ£¬£¬ £¬ £¬£¬£¬AT&TÐû²¼Á˹ØÓÚеÄSeroXen RATµÄÆÊÎö±¨¸æ¡£¡£ ¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÓÚ2022Äêµ×·ºÆð£¬£¬ £¬ £¬£¬£¬´ò×ÅWin 11ºÍWin 10Õýµ±Ô¶³Ì»á¼û¹¤¾ßµÄ»Ï×Ó³öÊÛ£¬£¬ £¬ £¬£¬£¬µ«ÔÚºÚ¿ÍÂÛ̳Éϱ»Ðû´«ÎªÔ¶³Ì»á¼ûľÂí¡£¡£ ¡£¡£¡£¡£SeroXen»ùÓÚÖÖÖÖ¿ªÔ´ÏîÄ¿£¬£¬ £¬ £¬£¬£¬°üÀ¨Quasar RAT¡¢r77 rootkitºÍNirCmdÏÂÁîÐй¤¾ß¡£¡£ ¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬ £¬ £¬£¬£¬×Ô½¨ÉèÒÔÀ´ÒѾ­·ºÆðÁËÊý°Ù¸öÑù±¾£¬£¬ £¬ £¬£¬£¬Ö÷ÒªÕë¶ÔÓÎÏ·ÉçÇø£¬£¬ £¬ £¬£¬£¬µ«Ëæ×Ÿù¤¾ßÔ½À´Ô½ÊܽӴý£¬£¬ £¬ £¬£¬£¬Ä¿µÄ¹æÄ£¿ÉÄÜ»áÀ©´óµ½°üÀ¨´óÐ͹«Ë¾ºÍ×éÖ¯¡£¡£ ¡£¡£¡£¡£


https://cybersecurity.att.com/blogs/labs-research/seroxen-rat-for-sale