LockBit³ÆÒÑÈëÇÖXeinadin²¢ÍþвÐû²¼1.5TB±»µÁÊý¾Ý

Ðû²¼Ê±¼ä 2023-12-25

1¡¢LockBit³ÆÒÑÈëÇÖXeinadin²¢ÍþвÐû²¼1.5TB±»µÁÊý¾Ý


¾ÝýÌå12ÔÂ23ÈÕ±¨µÀ£¬ £¬£¬£¬£¬LockBitÉù³Æ¶Ô»á¼ÆÊ¦ÊÂÎñËùXeinadinÔâµ½µÄ¹¥»÷ÈÏÕæ£¬ £¬£¬£¬£¬²¢ÍþвҪÅû¶±»µÁÊý¾Ý¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïÌåÏÖÍøÂçÁË1.5 TBµÄXeinadin¿Í»§Êý¾Ý£¬ £¬£¬£¬£¬°üÀ¨ËùÓÐÄÚ²¿Êý¾Ý¿â¡¢¿Í»§²ÆÎñÐÅÏ¢¡¢»¤ÕÕ¡¢ÕË»§Óà¶î¡¢¿Í»§Ð¡ÎÒ˽¼ÒÕË»§»á¼ûȨÏ޺Ϳͻ§Ö´·¨ÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïÍþв£¬ £¬£¬£¬£¬ÈôÊÇXeinadin²»ÔÚ12ÔÂ25ÈÕµÄ֮ǰÁªÏµËûÃÇ£¬ £¬£¬£¬£¬ËûÃǽ«Ðû²¼ÕâЩÊý¾Ý¡£¡£¡£¡£¡£¡£LockBit»¹Ðû²¼ÁË3ÕŽØÍ¼£¬ £¬£¬£¬£¬ÏÔʾÁËÊý¾Ý¿â¼Æ»®ºÍ±»ÈëÇÖ»ù´¡ÉèÊ©µÄ´æ´¢½á¹¹¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/156303/cyber-crime/lockbit-gang-xeinadin.html


2¡¢Mint Mobile͸¶¿Í»§ÐÅϢй¶¿ÉÄܵ¼ÖÂSIM½»Á÷¹¥»÷


¾Ý12ÔÂ22ÈÕ±¨µÀ£¬ £¬£¬£¬£¬Òƶ¯ÐéÄâÍøÂçÔËÓªÉÌ(MVNO)Mint MobileÅû¶ÁËÒ»Æð¿Í»§Êý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÓÚ22ÈÕ×îÏÈͨ¹ýÎÊÌâΪ¡°ÓйØÄúÕÊ»§µÄÖ÷ÒªÐÅÏ¢¡±µÄÓʼþ֪ͨ¿Í»§£¬ £¬£¬£¬£¬³ÆºÚ¿Í»ñÈ¡Á˿ͻ§ÐÅÏ¢¡£¡£¡£¡£¡£¡£Ð¹Â¶ÐÅÏ¢°üÀ¨ÐÕÃû¡¢µç»°ºÅÂë¡¢ÓʼþµØµãÒÔ¼°SIMÐòÁкźÍIMEIºÅµÈ£¬ £¬£¬£¬£¬ÕâЩÐÅÏ¢×ãÒÔ±»¹¥»÷ÕßÓÃÀ´ÕßÖ´ÐÐSIM½»Á÷¹¥»÷¡£¡£¡£¡£¡£¡£ËäÈ»MintÉÐδÅû¶Óйع¥»÷ÏêϸÐÅÏ¢£¬ £¬£¬£¬£¬µ«7Ô·ÝÓб¨¸æ³Æ£¬ £¬£¬£¬£¬¹¥»÷ÕßÊÔͼÔÚºÚ¿ÍÂÛ̳ÉϳöÊÛMint MobileºÍUltra MobileµÄÊý¾Ý¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/mint-mobile-discloses-new-data-breach-exposing-customer-data/


3¡¢AkiraÌåÏÖÒѹ¥»÷²¢ÇÔÈ¡ÈÕ²ú°Ä´óÀûÑÇ·Ö¹«Ë¾100GBÎļþ


ýÌå12ÔÂ22Èճƣ¬ £¬£¬£¬£¬AkiraÌåÏÖÒѹ¥»÷Æû³µÖÆÔìÉÌÈÕ²úÆû³µ°Ä´óÀûÑÇ·Ö¹«Ë¾Nissan Australia£¬ £¬£¬£¬£¬²¢´ÓÆäϵͳÖÐÇÔÈ¡ÁËÔ¼100GBµÄÎļþ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾¾Ü¾øÖ§¸¶Êê½ð£¬ £¬£¬£¬£¬ÀÕË÷ÍÅ»ï³ÆÒªÐ¹Â¶¾Ý±»µÁÎļþ£¬ £¬£¬£¬£¬°üÀ¨ÏîÄ¿Êý¾Ý¡¢¿Í»§ºÍÏàÖúͬ°éµÄÐÅÏ¢ÒÔ¼°±£ÃÜЭÒéµÈ¡£¡£¡£¡£¡£¡£ËäÈ»¸Ã¹«Ë¾ÈÔδ¶Ô±¾Ô³õÅû¶µÄ¹¥»÷¹éÒò£¬ £¬£¬£¬£¬µ«¹¥»÷ÕßȷʵÓÚ22ÈÕÔÚÆäÍøÕ¾ÉÏÌí¼ÓÁËеĸüУ¬ £¬£¬£¬£¬Í¸Â¶ÒÑÈëÇÖÁËÆäλÓÚ°Ä´óÀûÑǺÍÐÂÎ÷À¼µÄ²¿·Öϵͳ¡£¡£¡£¡£¡£¡£ÈÕ²úÌåÏÖ£¬ £¬£¬£¬£¬ÈÔÔÚÊÓ²ì¸ÃÊÂÎñµÄÓ°ÏìÒÔ¼°Ð¡ÎÒ˽¼ÒÐÅÏ¢ÊÇ·ñÒѱ»»á¼û£¬ £¬£¬£¬£¬²¢ÔÚÆð¾¢»Ö¸´ÊÜÓ°Ïìϵͳ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/nissan-australia-cyberattack-claimed-by-akira-ransomware-gang/


4¡¢Î¢Èí·¢Ã÷APT33ʹÓÃеÄFalseFont¹¥»÷¹ú·À³Ð°üÉÌ


12ÔÂ22ÈÕ±¨µÀ³Æ£¬ £¬£¬£¬£¬Î¢Èí·¢Ã÷£¬ £¬£¬£¬£¬ÒÁÀʺڿÍÍÅ»ïAPT33£¨Ò²³ÆPeach Sandstorm£©ÕýÔÚʹÓÃ×î½ü·¢Ã÷µÄ¶ñÒâÈí¼þFalseFont¹¥»÷È«ÇòµÄ¹ú·À³Ð°üÉÌ¡£¡£¡£¡£¡£¡£FalseFontÊÇÒ»¸ö×Ô½ç˵ºóÃÅ£¬ £¬£¬£¬£¬¾ßÓÐÆÕ±éµÄ¹¦Ð§£¬ £¬£¬£¬£¬¿ÉÔ¶³Ì»á¼û±»Ñ¬È¾µÄϵͳ¡¢Æô¶¯ÆäËüÎļþ²¢½«ÐÅÏ¢·¢Ë͵½ÆäC2ЧÀÍÆ÷£¬ £¬£¬£¬£¬ÓÚ11Ô³õÊ״α»ÔÚÒ°·¢Ã÷¡£¡£¡£¡£¡£¡£Î¢Èí»¹³Æ£¬ £¬£¬£¬£¬FalseFontµÄ¿ª·¢ºÍʹÓÃÓëÒÔǰÊӲ쵽µÄPeach Sandstorm»î¶¯Ò»Ö£¬ £¬£¬£¬£¬Åú×¢Peach SandstormÕýÔÚ¼ÌÐøË¢ÐÂËûÃǵÄÌØ¹¤ÊÖÒÕ¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2023/12/microsoft-warns-of-new-falsefont.html


5¡¢BidenCashÔÚºÚ¿ÍÂÛ̳¹ûÕæ190ÍòÕÅÐÅÓÿ¨µÄÐÅÏ¢


¾Ý12ÔÂ22ÈÕ±¨µÀ£¬ £¬£¬£¬£¬BidenCashÔÚºÚ¿ÍÂÛ̳¹ûÕæ190ÍòÕÅÐÅÓÿ¨µÄÐÅÏ¢¡£¡£¡£¡£¡£¡£BidenCashÓÚ2022ÄêÍ·ÍÆ³ö£¬ £¬£¬£¬£¬×÷Ϊ°µÍøºÍÃ÷ÍøµÄÐÂÊг¡£¬ £¬£¬£¬£¬ÏúÊÛͨ¹ýµçÉÌÍøÕ¾ÉϵĴ¹ÂÚ»òÇÔÈ¡³ÌÐòÇÔÈ¡µÄÐÅÓÿ¨ºÍ½è¼Ç¿¨¡£¡£¡£¡£¡£¡£×îÐÂй¶µÄÐÅÏ¢°üÀ¨´¿Îı¾ÐÎʽµÄÍêÕû¿¨ºÅ¡¢ÓÐÓÃÆÚºÍCVVºÅÂ룬 £¬£¬£¬£¬µ«Óë¸ÃÍøÕ¾Ö®Ç°µÄй¶²î±ð£¬ £¬£¬£¬£¬Ëü²»°üÀ¨³Ö¿¨È˵ÄÐÕÃû»òÓʼþµØµã¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÒøÐп¨ÏêϸÐÅÏ¢×ÜÊýΪ1912969ÕÅ£¬ £¬£¬£¬£¬µ«É¾³ýÖØ¸´Êý¾Ýºó£¬ £¬£¬£¬£¬Îª1169843ÕÅ¡£¡£¡£¡£¡£¡£


https://www.hackread.com/bidencash-market-leaks-credit-card-details/


6¡¢Deep InstinctÅû¶UAC-0099Õë¶ÔÎÚ¿ËÀ¼µÄ¹¥»÷»î¶¯


Deep InstinctÓÚ12ÔÂ22ÈÕÅû¶ÁËUAC-0099Õë¶ÔÎÚ¿ËÀ¼µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¹¥»÷Á´Ê¹ÓÃÁ˰üÀ¨HTA¡¢RARºÍLNKÎļþ¸½¼þµÄ´¹ÂÚÓʼþ·Ö·¢LONEPAGE£¬ £¬£¬£¬£¬ÕâÊÇÒ»ÖÖVBS¶ñÒâÈí¼þ£¬ £¬£¬£¬£¬Äܹ»ÓëC2ЧÀÍÆ÷ͨѶ£¬ £¬£¬£¬£¬¼ìË÷¼üÅ̼ͼ³ÌÐò¡¢ÇÔÈ¡³ÌÐòºÍÆÁÄ»½ØÍ¼¶ñÒâÈí¼þµÈÆäËüpayload¡£¡£¡£¡£¡£¡£Ê¹ÓÃHTA¸½¼þÖ»ÊÇ3ÖÖ²î±ðѬȾÁ´ÖеÄÒ»ÖÖ£¬ £¬£¬£¬£¬ÁíÍâÁ½ÖÖѬȾÁ´Ê¹ÓõÄÊÇSFXѹËõÎļþºÍZIPÎļþ¡£¡£¡£¡£¡£¡£ZIPÎļþʹÓÃÁËWinRARÎó²î£¨CVE-2023-38831£©À´Èö²¥LONEPAGE¡£¡£¡£¡£¡£¡£


https://www.deepinstinct.com/blog/threat-actor-uac-0099-continues-to-target-ukraine