·áÌïÔÆÐ§ÀÍÉèÖùýʧй¶ÑÇÖ޺ʹóÑóÖÞ¿Í»§ÐÅÏ¢Ô¼ÆßÄê

Ðû²¼Ê±¼ä 2023-06-02

1¡¢·áÌïÔÆÐ§ÀÍÉèÖùýʧй¶ÑÇÖ޺ʹóÑóÖÞ¿Í»§ÐÅÏ¢Ô¼ÆßÄê


¾Ý5ÔÂ31ÈÕ±¨µÀ£¬ £¬£¬£¬£¬£¬·áÌïÆû³µ·¢Ã÷ÁËÁíÍâÁ½¸öÉèÖùýʧµÄÔÆÐ§ÀÍ£¬ £¬£¬£¬£¬£¬Ð¹Â¶Á˳µÖ÷µÄСÎÒ˽¼ÒÐÅÏ¢Áè¼ÝÆßÄê¡£¡£¡£¡£¡£ ¡£¡£µÚÒ»¸öÔÆÐ§ÀÍÔÚ2016Äê10ÔÂÖÁ2023Äê5ÔÂʱ´úй¶ÁËÑÇÖ޺ʹóÑóÖÞ·áÌï¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢£¬ £¬£¬£¬£¬£¬¸ÃÆû³µÖÆÔìÉÌÉÐδ˵Ã÷Óм¸¶à¿Í»§Êܵ½´Ë´ÎÊÂÎñµÄÓ°Ïì¡£¡£¡£¡£¡£ ¡£¡£µÚ¶þ¸öÔÆÐ§ÀÍÔÚ2015Äê2ÔÂ9ÈÕÖÁ2023Äê5ÔÂ12ÈÕʱ´ú̻¶£¬ £¬£¬£¬£¬£¬°üÀ¨ÈÕ±¾Ô¼260000¸ö¿Í»§µÄÆû³µµ¼º½ÏµÍ³Ïà¹ØµÄÐÅÏ¢¡£¡£¡£¡£¡£ ¡£¡£ÊÜÓ°ÏìµÄ³µÁ¾ÊÇ·áÌï×ÓÆ·ÅÆÀ׿ËÈøË¹µÄ³µÐÍ¡£¡£¡£¡£¡£ ¡£¡£·áÌïÌåÏÖ£¬ £¬£¬£¬£¬£¬ËüÒѾ­ÊµÑéÁËÒ»¸öϵͳ£¬ £¬£¬£¬£¬£¬¿ÉÒÔ°´ÆÚ¼à¿ØÆäËùÓÐÇéÐÎÖеÄÔÆÉèÖúÍÊý¾Ý¿âÉèÖ㬠£¬£¬£¬£¬£¬ÒÔ±ÜÃâδÀ´ÔٴηºÆð´ËÀàÎÊÌâ¡£¡£¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/toyota-finds-more-misconfigured-servers-leaking-customer-info/


2¡¢ÉúÎïÊÖÒÕ¹«Ë¾Enzo Biochem½ü250ÍòÈ˵ÄÁÙ´²Êý¾Ý±»µÁ


¾ÝýÌå6ÔÂ1ÈÕ±¨µÀ£¬ £¬£¬£¬£¬£¬ÉúÎïÊÖÒÕ¹«Ë¾Enzo BiochemÔâµ½ÀÕË÷¹¥»÷£¬ £¬£¬£¬£¬£¬µ¼ÖÂÔ¼2470000È˵ÄÁÙ´²²âÊÔÐÅϢй¶¡£¡£¡£¡£¡£ ¡£¡£EnzoÖÆÔìºÍÏúÊÛ»ùÓÚDNAµÄ²âÊÔÒÔ¼ì²â²¡¶¾ºÍϸ¾ú¼²²¡£¬ £¬£¬£¬£¬£¬°üÀ¨COVID-19ºÍ°©Ö¢¡£¡£¡£¡£¡£ ¡£¡£¸Ã¹«Ë¾ÔÚ4ÔÂ11ÈÕ·¢Ã÷¿Í»§ÐÕÃûºÍ²âÊÔÐÅÏ¢£¬ £¬£¬£¬£¬£¬ÒÔ¼°Ô¼600000¸öÉç»áÇå¾²ºÅÂë±»»á¼û£¬ £¬£¬£¬£¬£¬ÏÖÔÚûÓÐÀÕË÷ÍÅ»ïÌåÏֶԴ˴ι¥»÷ÈÏÕæ¡£¡£¡£¡£¡£ ¡£¡£Enzo³ÆÒѽ«ÆäϵͳÓ뻥ÁªÍø¶Ï¿ªÅþÁ¬£¬ £¬£¬£¬£¬£¬ÏÖÔÚÈÔÔÚÊÓ²ì´ËÊÂÎñ¡£¡£¡£¡£¡£ ¡£¡£


https://therecord.media/clinical-test-data-of-enzio-biochem-stolen


3¡¢ÑÇÂíÑ·ÒòRingºÍAlexaÇÖÕ¼ÒþË½ÃæÁÙ3000ÍòÃÀÔª·£¿ £¿£¿£¿î


 Ã½Ìå5ÔÂ31Èճƣ¬ £¬£¬£¬£¬£¬ÑÇÂíÑ·½«Ö§¸¶3000ÍòÃÀÔªµÄ·£¿ £¿£¿£¿î£¬ £¬£¬£¬£¬£¬ÒÔ½â¾öÃÀ¹úFTC¶ÔÆäRingºÍAlexaÏà¹ØµÄÇÖÕ¼Òþ˽µÄÖ¸¿Ø¡£¡£¡£¡£¡£ ¡£¡£Í¶Ë߳ƣ¬ £¬£¬£¬£¬£¬RingÊÚÓèÆäÔ±¹¤ºÍ³Ð°üÉÌ»á¼û˽ÈËÊÓÆµµÄȨÏÞ£¬ £¬£¬£¬£¬£¬ÕâÇÖÕ¼Á˿ͻ§µÄÒþ˽¡£¡£¡£¡£¡£ ¡£¡£Ëü»¹Ã»ÓÐʵÑé»ù±¾µÄÒþ˽ºÍÇå¾²²½·¥£¬ £¬£¬£¬£¬£¬ºÚ¿Í¿ÉÈëÇÖÕÊ»§À´¿ØÖÆÏûºÄÕßµÄÏà»úºÍÊÓÆµ¡£¡£¡£¡£¡£ ¡£¡£Æ¾Ö¤ÄâÒéµÄÏÂÁ £¬£¬£¬£¬£¬Ring±ØÐèÏòÏûºÄÕßÖ§¸¶580ÍòÃÀÔªµÄÍ˿¡£¡£¡£¡£ ¡£¡£ÔÚÁíÒ»Æð°¸¼þÖУ¬ £¬£¬£¬£¬£¬FTCºÍDOJÖ¸¿ØÑÇÂíÑ·Î¥·´¶ùͯÒþ˽·¨£¬ £¬£¬£¬£¬£¬Î´ÄÜÓ¦âïÊѵÄÒªÇóɾ³ýËûÃǵļÒôºÍµØÀíλÖÃÐÅÏ¢¡£¡£¡£¡£¡£ ¡£¡£Æ¾Ö¤ÄâÒéµÄÏÂÁ £¬£¬£¬£¬£¬ÑÇÂíÑ·±ØÐèÖ§¸¶2500ÍòÃÀÔª¡£¡£¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/technology/amazon-faces-30-million-fine-over-ring-alexa-privacy-violations/


4¡¢BlackCatÉù³Æ¶ÔÖ´·¨ÊÖÒÕÆ½Ì¨CasepointµÄ¹¥»÷ÈÏÕæ


6ÔÂ1ÈÕ±¨µÀ³Æ£¬ £¬£¬£¬£¬£¬ÀÕË÷ÍÅ»ïBlackCatÔÚÆäÍøÕ¾ÁгöÁËCasepoint¡£¡£¡£¡£¡£ ¡£¡£CasepointÌṩÁËÒ»¸öÖ´·¨ÊÖÒÕÆ½Ì¨£¬ £¬£¬£¬£¬£¬±»¶à¸öÃÀ¹ú»ú¹¹Ê¹Ó㬠£¬£¬£¬£¬£¬°üÀ¨SEC¡¢FBIºÍÃÀÍõ·¨Ôº¡£¡£¡£¡£¡£ ¡£¡£¸ÃÍÅ»ï³ÆÒÑÇÔÈ¡2TBµÄÃô¸ÐÊý¾Ý£¬ £¬£¬£¬£¬£¬É漰״ʦ¡¢SEC¡¢DoD¡¢FBIºÍ¾¯Ô±µÈ¡£¡£¡£¡£¡£ ¡£¡£¸ÃºÚ¿ÍÍÅ»ï¹ûÕæÁ˱»ÈëÇÖ»ù´¡ÉèÊ©µÄ²¿·Ö×ÊÔ´µÄƾ֤ÒÔ¼°¾Ý³ÆÊDZ»µÁÎļþµÄһЩͼƬ£¬ £¬£¬£¬£¬£¬ÒÔ´ß´ÙCasepoint×îÏÈ̸ÅС£¡£¡£¡£¡£ ¡£¡£BlackCat×Ô2021Äê11ÔÂ×îÏÈ»îÔ¾£¬ £¬£¬£¬£¬£¬Êê½ðÒªÇó´Ó¼¸ÍòÃÀÔªµ½ÊýÍòÍòÃÀÔª²»µÈ¡£¡£¡£¡£¡£ ¡£¡£


https://securityaffairs.com/146915/cyber-crime/blackcat-ransomware-casepoint.html


5¡¢Group-IB³ÆDark Pink¼ÌÐøÕë¶ÔÑÇÌ«µØÇøµÄ¾üÕþµÈÐÐÒµ


5ÔÂ31ÈÕ£¬ £¬£¬£¬£¬£¬Group-IBÅû¶ÁËDark Pink½üÆÚÐÂÒ»ÂֵĹ¥»÷»î¶¯¡£¡£¡£¡£¡£ ¡£¡£¸ÃÍÅ»ï×Ô2021ÄêÖÐÒÔÀ´Ò»Ö±»îÔ¾£¬ £¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÑÇÌ«µØÇøµÄ×éÖ¯¡£¡£¡£¡£¡£ ¡£¡£Æ¾Ö¤×îÐÂÊÓ²ìЧ¹û£¬ £¬£¬£¬£¬£¬Group-IBÈ·ÈÏÁË5¸öеı»¹¥»÷×éÖ¯£¬ £¬£¬£¬£¬£¬°üÀ¨ÎÄÀ³¡¢Ó¡¶ÈÄáÎ÷ÑÇ¡¢Ì©¹úºÍÔ½ÄϵÄÕþ¸®¡¢¾ü¶ÓºÍ·ÇÓªÀû×éÖ¯£¬ £¬£¬£¬£¬£¬ÒÔ¼°±ÈÀûʱµÄ½ÌÓý×éÖ¯¡£¡£¡£¡£¡£ ¡£¡£¹¥»÷ʼÓÚ´¹ÂÚÓʼþÖеÄISOÎĵµ£¬ £¬£¬£¬£¬£¬ËüʹÓÃDLL²à¼ÓÔØÀ´Æô¶¯ºóÃÅTelePowerBotºÍKamiKakaBot¡£¡£¡£¡£¡£ ¡£¡£±ðµÄ£¬ £¬£¬£¬£¬£¬Ö²Èë³ÌÐò´ÓÄÚ´æÖмÓÔØ£¬ £¬£¬£¬£¬£¬²»½Ó´¥´ÅÅÌ£¬ £¬£¬£¬£¬£¬ÕâÓÐÖúÓÚÈÆ¹ý¼ì²â¡£¡£¡£¡£¡£ ¡£¡£ÔÚ×î½üµÄÒ»´Î¹¥»÷ÖУ¬ £¬£¬£¬£¬£¬Dark PinkʹÓÃЧÀÍWebhookͨ¹ýHTTPЭÒéй¶±»µÁÊý¾Ý¡£¡£¡£¡£¡£ ¡£¡£


https://www.group-ib.com/blog/dark-pink-episode-2/


6¡¢AT&T·¢Ã÷еÄSeroXen RATÖ÷Òª±»ÓÃÓÚ¹¥»÷ÓÎÏ·ÉçÇø


5ÔÂ30ÈÕ£¬ £¬£¬£¬£¬£¬AT&TÐû²¼Á˹ØÓÚеÄSeroXen RATµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£ ¡£¡£¸Ã¶ñÒâÈí¼þÓÚ2022Äêµ×·ºÆð£¬ £¬£¬£¬£¬£¬´ò×ÅWin 11ºÍWin 10Õýµ±Ô¶³Ì»á¼û¹¤¾ßµÄ»Ï×Ó³öÊÛ£¬ £¬£¬£¬£¬£¬µ«ÔÚºÚ¿ÍÂÛ̳Éϱ»Ðû´«ÎªÔ¶³Ì»á¼ûľÂí¡£¡£¡£¡£¡£ ¡£¡£SeroXen»ùÓÚÖÖÖÖ¿ªÔ´ÏîÄ¿£¬ £¬£¬£¬£¬£¬°üÀ¨Quasar RAT¡¢r77 rootkitºÍNirCmdÏÂÁîÐй¤¾ß¡£¡£¡£¡£¡£ ¡£¡£Ñо¿Ö°Ô±³Æ£¬ £¬£¬£¬£¬£¬×Ô½¨ÉèÒÔÀ´ÒѾ­·ºÆðÁËÊý°Ù¸öÑù±¾£¬ £¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÓÎÏ·ÉçÇø£¬ £¬£¬£¬£¬£¬µ«Ëæ×Ÿù¤¾ßÔ½À´Ô½ÊܽӴý£¬ £¬£¬£¬£¬£¬Ä¿µÄ¹æÄ£¿ÉÄÜ»áÀ©´óµ½°üÀ¨´óÐ͹«Ë¾ºÍ×éÖ¯¡£¡£¡£¡£¡£ ¡£¡£


https://cybersecurity.att.com/blogs/labs-research/seroxen-rat-for-sale