µçÉÌÆ½Ì¨Mercari³ÆÆäÊܵ½Codecov¹©Ó¦Á´¹¥»÷Ó°Ï죻Ӣ¹úOne CallѬȾDarkSide£¬±»ÀÕË÷1500ÍòÓ¢°÷
Ðû²¼Ê±¼ä 2021-05-241.µçÉÌÆ½Ì¨Mercari³ÆÆäÊܵ½Codecov¹©Ó¦Á´¹¥»÷Ó°Ïì
µçÉÌÆ½Ì¨Mercari³ÆÆäÊܵ½Codecov¹©Ó¦Á´¹¥»÷µÄÓ°Ï죬´óÁ¿¿Í»§ÐÅϢй¶¡£MercariÊÇÒ»¼ÒÈÕ±¾ÉÏÊй«Ë¾£¬½ØÖÁ2017Ä꣬ÆäÓ¦Ó÷¨Ê½ÔÚÈ«ÇòµÄÏÂÔØÁ¿ÒÑÁè¼Ý1ÒڴΡ£´Ë´Îʼþй¶ÁË17085ÌõÉæ¼°¿Í»§ÕÊ»§µÄÐÅÏ¢£¬°üÂÞÒøÐдúÂë¡¢·ÖÐдúÂë¡¢ÕʺźͳÖÓÐÈ˵ȣ»7966ÌõMercariºÍMerpayºÏ×÷»ï°éµÄÐÅÏ¢£¬°üÂÞÐÕÃû¡¢³öÉúÈÕÆÚ¡¢Á¥Êô¹ØÏµºÍÓʼþµØÖ·µÈ£»ÒÔ¼°2615ÌõÔ±¹¤ÐÅÏ¢µÈ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/e-commerce-giant-suffers-major-data-breach-in-codecov-incident/
2.Ó¡¶ÈÄáÎ÷ÑÇÕþ¸®ÏÖÈ·ÈÏÆä²¿ÃŹ«ÃñµÄÉç±£ÐÅÏ¢ÒÑй¶
ÉÏÖÜ£¬Ò»¸öÃûΪKotzµÄºÚ¿ÍÔÚ°µÍø¹ûÈ»Á˲¿ÃÅÓ¡ÄṫÃñµÄÊý¾Ý£¬²¢Éù³ÆÆäÓµÓÐÒ»¸öËùÓÐ2.7ÒÚ¹«ÃñµÄÊý¾Ý¡£ºÚ¿Í¹ûÈ»µÄÊý¾Ý°üÂÞ100Íò¸öÓ¡ÄṫÃñµÄÐÕÃû¡¢Éí·ÝºÅÂë¡¢¾ÓסµØÖ·ºÍµç»°ºÅÂëµÈ¡£Ä¿Ç°£¬Ó¡¶ÈÄáÎ÷ÑǵÄͨÐźÍÐÅÏ¢²¿È·ÈÏÆä²¿ÃŹ«ÃñµÄÉç±£ÐÅÏ¢ÒÑй¶£¬µ«¼á³ÆÐ¹Â¶ÐÅÏ¢µÄ¹æÄ£±ÈºÚ¿ÍÉù³ÆµÄҪСµÃ¶à¡£¸Ã¹úÕþ¸®ÌåÏÖÒѽÓÄÉ´ëÊ©·ÀÖ¹±»µÁÊý¾ÝµÄÀ©É¢£¬²¢ÒÑ×ÅÊÖÓÚй¶ԴͷµÄÊӲ졣
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/118148/data-breach/indonesia-social-security-data-breach.html
3.DominoÔÙ´ÎÔâµ½¹¥»÷£¬1.8ÒÚ¶©µ¥µÄÐÅÏ¢±»¹ûÈ»
Ñо¿ÈËÔ±Rajshekhar Rajaharia³ÆºÚ¿ÍÔÚ°µÍø´´½¨ÁËÒ»¸öËÑË÷ÒýÇæ£¬¹ûÈ»ÁËDomino's India 1.8ÒÚ¶©µ¥µÄÐÅÏ¢¡£´Ë´Î¹ûÈ»µÄÐÅÏ¢°üÂÞ¿Í»§ÐÕÃû¡¢µç×ÓÓʼþ¡¢µç»°ºÅÂëºÍGPSλÖõȡ£Jubilant¹«Ë¾Ö¤ÊµÁË´Ë´Îй©Ê¼þ£¬²¢ÌåÏÖûÓÐÈκβÆÕþÐÅϢй¶£¬¸ÃʼþҲδ¶ÔÆäÒµÎñÔËÓªÔì³ÉÓ°Ïì¡£ÕâÊÇDominoÔÚ¹ýÈ¥µÄÁ½¸öÔÂÄÚ·¢ÉúµÄµÚ¶þ´ÎÊý¾Ýй¶£¬ÔçÔÚ4Ô³õ£¬Ä³ºÚ¿Í¾ÍÇÔÈ¡ÁËDominos 13TBµÄÊý¾Ý¡£
ÔÎÄÁ´½Ó£º
https://www.moneycontrol.com/news/technology/dominos-india-suffers-data-breach-details-of-18-crore-orders-on-sale-6926731.html
4.Ó¢¹úOne CallѬȾDarkSide£¬±»ÀÕË÷1500ÍòÓ¢°÷
Ó¢¹úµÄ±£ÏÕ¹«Ë¾One CallѬȾDarkSide£¬Óʼþϵͳ¡¢ÍøÕ¾ºÍµç»°Ïß·Êܵ½Ó°Ïì¡£¾ÝϤ£¬¹¥»÷·¢ÉúÔÚ5ÔÂ12ÈÕÍíÉÏ»ò13ÈÕÁ賿£¬Ô±¹¤Ôڵǽϵͳ׼±¸ÊÂÇéʱ·¢Ï֯伯Ëã»úÒѱ»ÀÕË÷Èí¼þѬȾ¡£Êê½ð¼Ç¼ҪÇóÖ§¸¶1500ÍòÓ¢°÷£¬·ñÔò½«¹ûÈ»¿Í»§µÄÃÜÂëºÍÒøÐÐÐÅÏ¢µÈ¡£¾¡¹Ü¹¥»÷·¢ÉúÔÚÒ»¸ö¶àÐÇÆÚǰ£¬µ«One CallÈÔδ·¢±íÏà¹ØÉùÃ÷£¬Ö»ÊǸæË߿ͻ§ËüÓöµ½Á˼¼ÊõÎÊÌâ¡£Ö±µ½ºÚ¿Í½«Ð¹Â¶ÐÅÏ¢µÄ½ØÍ¼¹ûÈ»µ½°µÍø£¬Æä¿Í»§²Å»ñϤÁË´Ë´Îʼþ¡£
ÔÎÄÁ´½Ó£º
https://www.doncasterfreepress.co.uk/news/leaked-one-call-staff-messages-confirm-cyber-security-incident-as-major-crime-unit-called-in-3243731
5.CyberNews·¢ÏÖºÚ¿Í¿ÉÀûÓÃAPIÃÜÔ¿ÇÔÈ¡¼ÓÃÜ»õ±Ò
CyberNewsÑо¿ÈËÔ±·¢ÏÖºÚ¿Í¿ÉÀûÓÃAPIÃÜÔ¿£¬ÔÚûÓб»ÊÚÓèÌá¿îµÄÇé¿öÏ´ÓÊܺ¦ÕßµÄÕË»§ÇÔÈ¡¼ÓÃÜ»õ±Ò¡£Ëæ×żÓÃÜ»õ±ÒÊг¡ÔÚ¹ýÈ¥¼¸ÄêµÄ±¬Õ¨Ê½Ôö³¤£¬¹«Ë¾¿ªÊ¼ÌṩÖÖÖÖÓ¦Ó÷¨Ê½ºÍ·þÎñÀ´×ÊÖú½»Ò×Õß¼ò»¯½»Ò×Á÷³Ì¡£½»Ò×Õß¿ÉÊÚȨµÚÈý·½Ó¦ÓÃͨ¹ýAPIÃÜÔ¿·ÃÎÊËûÃÇÔÚ¼ÓÃÜ»õ±Ò½»Ò×ËùµÄÕË»§²¢Ö´ÐÐÖÖÖÖ²Ù×÷¡£ºÚ¿Í¿ÉÒÔÇáÒ×µØÈƹýAPIÃÜÔ¿Éϵġ°½ö½»Òס±ÉèÖ㬴ÓÊܺ¦ÕßÕË»§ÖÐÇÔÈ¡×ʽð¡£ÕâÑù×öÉõÖÁÎÞÐè»ñµÃÄ¿±êÕË»§µÄƾ֤»òÌá¿îȨ£¬Ù²È»³ÉΪһÖÖÐÂÐ˵ķ¸×ïÉÌҵģʽ¡£
ÔÎÄÁ´½Ó£º
https://cybernews.com/security/report-how-cybercriminals-abuse-api-keys-to-steal-millions/
6.Unit 42Ðû²¼ÓйØÀÕË÷Èí¼þ¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß
Unit 42Ðû²¼ÁËÓйØÀÕË÷Èí¼þ¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬ÔÚ¹ýÈ¥µÄ¼¸ÄêÖУ¬ÀÕË÷¹¥»÷»î¶¯µÄÊýÁ¿¼±¾çÉÏÉý¡£2020ÄêÖ§¸¶µÄƽ¾ùÊê½ðÁè¼Ý31.2ÍòÃÀÔª£¬±È2019ÄêÔö³¤ÁË171£¥£¬µ½Ä¿Ç°ÎªÖ¹£¬ÕâÒ»Êý×ÖÓÖÔö³¤Á˽üÁ½±¶£¬µ½´ï85ÍòÃÀÔª¡£¶ø¶ÔÓÚ´óÐÍÆóÒµ£¬Êê½ð½ð¶îƽ¾ù½Ó½ü300ÍòÃÀÔª¡£È¥Äê×î¸ßµÄÊê½ð½ð¶î´Ó1500ÍòÃÀÔªÔö¼Óµ½3000ÍòÃÀÔª£¬ÏÖÔÚÄêÔò¸ß´ï5000ÍòÃÀÔª¡£
ÔÎÄÁ´½Ó£º
https://unit42.paloaltonetworks.com/breaking-down-ransomware-attacks/