°®¶ûÀ¼¹ú¼Ò¾¯¾ÖµÄ³Ð°üÉÌй¶50ÍòÌõ¿ÛѺ³µÁ¾µÄ¼Í¼

Ðû²¼Ê±¼ä 2023-10-25

1¡¢°®¶ûÀ¼¹ú¼Ò¾¯¾ÖµÄ³Ð°üÉÌй¶50ÍòÌõ¿ÛѺ³µÁ¾µÄ¼Í¼


¾Ý10ÔÂ23ÈÕ±¨µÀ£¬£¬ £¬£¬ £¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸ö¹ûÕæµÄÊý¾Ý¿â£¬£¬ £¬£¬ £¬£¬£¬°üÀ¨Áè¼Ý50ÍòÌõÓë°®¶ûÀ¼¹ú¼Ò¾¯¾ÖGarda S¨ªoch¨¢na¿ÛѺ³µÁ¾Ïà¹ØµÄ¼Í¼¡£¡£¡£¡£ ¡£¡£¡£Îĵµ×ÜÊýΪ521043¸ö£¬£¬ £¬£¬ £¬£¬£¬¾ÞϸΪ271.8 GB¡£¡£¡£¡£ ¡£¡£¡£Æ¾Ö¤°®¶ûÀ¼Ö´·¨£¬£¬ £¬£¬ £¬£¬£¬µ±³µÁ¾±»¿ÛѺʱ£¬£¬ £¬£¬ £¬£¬£¬³µÖ÷Ðë³öʾÉí·Ý֤ʵºÍ°ü¹ÜÎļþµÈ¶à·ÝÎļþ£¬£¬ £¬£¬ £¬£¬£¬Òò´Ëй¶µÄ50Íò·ÝÎĵµ¿ÉÄÜÓ°ÏìÁËÔ¼15ÍòÃû³µÖ÷¡£¡£¡£¡£ ¡£¡£¡£½øÒ»³ÌÐò²éÏÔʾ£¬£¬ £¬£¬ £¬£¬£¬¸ÃÊý¾Ý¿âÊôÓÚ°®¶ûÀ¼ÀûĬÀï¿ËµÄÒ»¼Ò˽ÈËÊÖÒճаüÉÌ¡£¡£¡£¡£ ¡£¡£¡£ÏÖÔÚ£¬£¬ £¬£¬ £¬£¬£¬Ð¹Â¶Êý¾ÝÒѱ»± £» £»£»£»¤ÆðÀ´¡£¡£¡£¡£ ¡£¡£¡£


https://www.hackread.com/contractor-data-breach-irish-national-police-vehicle-seizure/


2¡¢ºÚ¿ÍÒÔ8ÍòÃÀÔª¼ÛÇ®³öÊÛ8.15ÒÚÌõÓ¡¶È¹«ÃñµÄPII¼Í¼


ýÌå10ÔÂ24Èճƣ¬£¬ £¬£¬ £¬£¬£¬ºÚ¿ÍÔÚ°µÍø³öÊÛÊýÒÚÌõÓ¡¶È¹«ÃñµÄPII¼Í¼£¬£¬ £¬£¬ £¬£¬£¬°üÀ¨Aadhaar¿¨¡£¡£¡£¡£ ¡£¡£¡£AadhaarÊÇÒ»¸ö12λµÄСÎÒ˽¼Òʶ±ðÂ룬£¬ £¬£¬ £¬£¬£¬ÓÉÓ¡¶ÈΨһÉí·Ýʶ±ð»ú¹¹´ú±íÓ¡¶ÈÕþ¸®½ÒÏþ¡£¡£¡£¡£ ¡£¡£¡£10ÔÂ9ÈÕ£¬£¬ £¬£¬ £¬£¬£¬ÃûΪpwn0001µÄºÚ¿ÍÔÚ°µÍøÐû²¼ÁËÒ»¸öÌû×Ó£¬£¬ £¬£¬ £¬£¬£¬³ÆÓµÓÐ8.15ÒÚÓ¡¶È¹«ÃñAadhaarºÍ»¤Õռͼ£¬£¬ £¬£¬ £¬£¬£¬²¢Ô¸ÒâÒÔ80000ÃÀÔªµÄ¼ÛÇ®³öÊÛÕû¸öÊý¾Ý¿â¡£¡£¡£¡£ ¡£¡£¡£Í¬Ê±£¬£¬ £¬£¬ £¬£¬£¬pwn0001»¹¹ûÕæÁË4¸öÑù±¾£¬£¬ £¬£¬ £¬£¬£¬ÆäÖÐÒ»¸öÑù±¾°üÀ¨100000ÌõÓ¡¶ÈסÃñµÄPII¡£¡£¡£¡£ ¡£¡£¡£


https://securityaffairs.com/152957/security/pii-indian-citizens-dark-web.html


3¡¢BHI EnergyÏêÊöAkiraÔõÑùÈëÇÖÆäϵͳ²¢ÇÔÈ¡Êý¾Ý


¾ÝýÌå10ÔÂ23ÈÕ±¨µÀ£¬£¬ £¬£¬ £¬£¬£¬ÃÀ¹úÄÜÔ´¹«Ë¾BHI EnergyÅû¶ÁËAkiraÔÚ5ÔÂ30ÈÕÈëÇÖÆäϵͳµÄÏêϸÐÅÏ¢¡£¡£¡£¡£ ¡£¡£¡£AkiraʹÓÃÇÔÈ¡µÄµÚÈý·½µÄVPNƾ֤»á¼ûBGIµÄÄÚÍø£¬£¬ £¬£¬ £¬£¬£¬ÔÚÊ״λá¼ûºóµÄÒ»ÖÜÄÚʹÓÃͳһ¸öÕË»§¶ÔÄÚÍø¾ÙÐÐÕì̽¡£¡£¡£¡£ ¡£¡£¡£6ÔÂ16ÈÕ£¬£¬ £¬£¬ £¬£¬£¬AkiraÔٴλá¼ûϵͳ£¬£¬ £¬£¬ £¬£¬£¬Ã¶¾ÙÊý¾Ý£¬£¬ £¬£¬ £¬£¬£¬²¢ÔÚ6ÔÂ20ÈÕÖÁ29ÈÕÇÔÈ¡ÁË767k¸öÎļþ£¬£¬ £¬£¬ £¬£¬£¬¹²690 GB£¬£¬ £¬£¬ £¬£¬£¬°üÀ¨Windows Active DirectoryÊý¾Ý¿â¡£¡£¡£¡£ ¡£¡£¡£×îºó£¬£¬ £¬£¬ £¬£¬£¬¹¥»÷ÕßÓÚ6ÔÂ29ÈÕÇÔÈ¡ÁËËùÓÐÊý¾Ýºó£¬£¬ £¬£¬ £¬£¬£¬ÔÚËùÓÐ×°±¸ÉÏ×°ÖÃÁËAkiraÀÕË÷Èí¼þÀ´¼ÓÃÜÎļþ¡£¡£¡£¡£ ¡£¡£¡£Õâʱ£¬£¬ £¬£¬ £¬£¬£¬BHI²ÅÒâʶµ½¹«Ë¾Òѱ»ÈëÇÖ¡£¡£¡£¡£ ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/us-energy-firm-shares-how-akira-ransomware-hacked-its-systems/


4¡¢Î÷°àÑÀ¾¯·½µ·»ÙÄ³ÍøÂçÕ©Æ­ÍŻﲢ¾Ð²¶34ÃûÏÓÒÉÈË


10ÔÂ24ÈÕ±¨µÀ£¬£¬ £¬£¬ £¬£¬£¬Î÷°àÑÀ¹ú¼Ò¾¯Ô±¾Öµ·»ÙÁËÒ»¸öÍøÂç·¸·¨ÍŻ¡£¡£¡£ ¡£¡£¡£¸ÃÍÅ»ïÖ´ÐÐÖÖÖÖÅÌËã»úÕ©Æ­£¬£¬ £¬£¬ £¬£¬£¬ÇÔÈ¡ÁËÁè¼Ý400ÍòÈ˵ÄÊý¾Ý£¬£¬ £¬£¬ £¬£¬£¬×¬È¡ÁËÔ¼300ÍòÅ·Ôª¡£¡£¡£¡£ ¡£¡£¡£Ö´·¨²¿·ÖÔÚÂíµÂÀï¡¢ÂíÀ­¼Ó¡¢Î¤¶ûÍß¡¢°¢Àû¿²ÌغÍĶûÎ÷ÑǾÙÐÐÁË16´ÎÓÐÕë¶ÔÐÔµÄËѲ飬£¬ £¬£¬ £¬£¬£¬ÒѾв¶34Ãû·¸·¨ÍÅ»ïµÄ³ÉÔ±¡£¡£¡£¡£ ¡£¡£¡£¾¯·½³Æ£¬£¬ £¬£¬ £¬£¬£¬±»²¶ÕßÓëð³ä¿ìµÝ¹«Ë¾ºÍµçÁ¦¹©Ó¦É̵Ĵ¹ÂڻÓйØ¡£¡£¡£¡£ ¡£¡£¡£¸ÃÍÅ»ïµÄÍ·Ä¿Òѱ»¾Ð²¶£¬£¬ £¬£¬ £¬£¬£¬¶ÔÆäËû³ÉÔ±Éí·ÝµÄÊÓ²ìÈÔÔÚ¾ÙÐÐÖС£¡£¡£¡£ ¡£¡£¡£


https://securityaffairs.com/152946/cyber-crime/spanish-police-dismantled-cybercriminal-group.html


5¡¢Ñо¿Ö°Ô±Ðû²¼VMwarevÎó²îCVE-2023-34051µÄPoC


ýÌå10ÔÂ24Èճƣ¬£¬ £¬£¬ £¬£¬£¬VMwarevÌáÐÑvRealize Log Insight£¨ÏÖ³ÆÎªVMware Aria Operations for Logs£©ÖÐÎó²îµÄPoCÒÑÐû²¼¡£¡£¡£¡£ ¡£¡£¡£ÕâÊÇÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2023-34051£©£¬£¬ £¬£¬ £¬£¬£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔ½«Îļþ×¢ÈëÄ¿µÄϵͳÖУ¬£¬ £¬£¬ £¬£¬£¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£ ¡£¡£¡£Horizon3Ðû²¼ÁËPoC£¬£¬ £¬£¬ £¬£¬£¬ËüʹÓÃIPµØµãÓÕÆ­ºÍÖÖÖÖThrift RPC¶ËµãÀ´ÊµÏÖí§ÒâÎļþдÈë¡£¡£¡£¡£ ¡£¡£¡£Ñо¿Ö°Ô±½¨ÒéÁ¬Ã¦×°ÖøüС£¡£¡£¡£ ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/vmware-warns-admins-of-public-exploit-for-vrealize-rce-flaw/


6¡¢KasperskyÐû²¼Triangulation»î¶¯µÄÒþ²ØÐԵı¨¸æ


10ÔÂ23ÈÕ£¬£¬ £¬£¬ £¬£¬£¬KasperskyÐû²¼Á˹ØÓÚTriangulation»î¶¯µÄÒþ²ØÐÔµÄÆÊÎö±¨¸æ¡£¡£¡£¡£ ¡£¡£¡£¸Ã±¨¸æÏÈÈÝÁ˴˴ι¥»÷µÄÖÖÖÖÒþÐÎÊÖÒÕ£¬£¬ £¬£¬ £¬£¬£¬ÒÔ¼°¹¥»÷ÖÐʹÓõÄ×é¼þ¡£¡£¡£¡£ ¡£¡£¡£ÔÚ°²ÅÅTriangleDB֮ǰ£¬£¬ £¬£¬ £¬£¬£¬»áʹÓÃÁ½¸öÑéÖ¤Æ÷À´ÍøÂç×°±¸ÐÅÏ¢£¬£¬ £¬£¬ £¬£¬£¬²¢È·±£´úÂë²»»áÔÚÆÊÎöÇéÐÎÖÐÖ´ÐС£¡£¡£¡£ ¡£¡£¡£Ëü»¹°üÀ¨Ò»¸öÂó¿Ë·ç¼ÒôÄ £¿£¿£¿£¿émsu3h£¬£¬ £¬£¬ £¬£¬£¬Ä¬ÈÏ¿ÉÒÔ¼ÒôÈý¸öСʱ£¬£¬ £¬£¬ £¬£¬£¬µ«ÈôÊǵçÁ¿µÍÓÚ10%ÇÒ×°±¸ÆÁÄ»ÕýÔÚʹÓý«ÔÝͣ¼Òô¡£¡£¡£¡£ ¡£¡£¡£¹¥»÷Õß»¹ÊµÑéÁËÌØÁíÍâÔ¿³×´®Ð¹Â¶Ä £¿£¿£¿£¿é¡¢SQLiteÊý¾Ý¿âÇÔÈ¡¹¦Ð§ÒÔ¼°Î»ÖÃ¼à¿ØÄ £¿£¿£¿£¿é£¨ÔÚGPS²»¿ÉÓÃʱʹÓÃÍøÂçÔªÊý¾Ý£©¡£¡£¡£¡£ ¡£¡£¡£


https://securelist.com/triangulation-validators-modules/110847/