ÆÏÌÑÑÀ×î´óµÄýÌ幫˾ImpresaÔâµ½Lapsus$ÀÕË÷¹¥»÷

Ðû²¼Ê±¼ä 2022-01-05

ÆÏÌÑÑÀ×î´óµÄýÌ幫˾ImpresaÔâµ½Lapsus$ÀÕË÷¹¥»÷


 ÆÏÌÑÑÀ×î´óµÄýÌ幫˾ImpresaÔâµ½Lapsus$ÀÕË÷¹¥»÷.png


¾Ý1ÔÂ2ÈÕ±¨µÀ£¬ÆÏÌÑÑÀ×î´óµÄýÌ幫˾ImpresaÔâµ½Lapsus$µÄÀÕË÷¹¥»÷¡£´Ë´Î¹¥»÷·¢ÉúÓÚÔªµ©¼ÙÆÚÆÚ¼ä£¬Ó°ÏìÁ˸ù«Ë¾µÄIT·þÎñÆ÷»ù´¡ÉèÊ©£¬µ¼Ö¸ùú×îÖ÷ÒªµÄµçÊÓÆµµÀSICºÍÖܱ¨Expresso·þÎñÔÝʱÖжÏ¡£Lapsus$ÍÅ»ïÔÚImpressaµÄËùÓÐÍøÕ¾ÁôÏÂÀÕË÷Êê½ðÒªÇ󣬲¢Éù³ÆÒÑ»ñµÃ¶ÔImpresaµÄAmazon Web ServicesÕÊ»§µÄ·ÃÎÊȨÏÞ¡£1ÔÂ2ÈÕ£¬¸Ã¹«Ë¾µÄËùÓÐÍøÕ¾´¦ÓÚά»¤×´Ì¬£¬¹¥»÷Õß»¹ÀûÓÃExpressoµÄTwitterÕÊ»§·¢·¢ÎijÆËûÃÇÈÔ¿É·ÃÎʹ«Ë¾×ÊÔ´¡£


https://therecord.media/lapsus-ransomware-gang-hits-sic-portugals-largest-tv-channel/



Unit 42·¢ÏÖÕë¶Ô·¿µØ²úÍøÕ¾µÄWeb Skimmer»î¶¯


¾ÝUnit 42ÔÚ1ÔÂ3ÈÕÐû²¼µÄ³ÂË߳ƣ¬Ò»¸öеÄWeb Skimmer»î¶¯Õýͨ¹ý¹¥»÷·Ö·¢ÔÆÊÓÆµµÄ¹©Ó¦Á´À´Ãé×¼·¿µØ²úÍøÕ¾¡£´Ë´ÎÑо¿¹²¼ì²âµ½100¶à¸öÊܵ½ÏàͬSkimmer¹¥»÷µÄÍøÕ¾£¬¾­·ÖÎö·¢ÏÖËùÓй¥»÷¶¼Ô´×ÔÒ»¼Ò¹«Ë¾£ºÕâЩ±»ÈëÇÖµÄÍøÕ¾¶¼´ÓÒ»¸öÔÆÊÓÆµÆ½Ì¨µ¼ÈëÏàͬµÄÊÓÆµ£¬¶ø¸ÃÊÓÆµÖаüÂÞ¶ñÒâ½Å±¾¡£Ñо¿ÈËÔ±»¹Õ¹Ê¾Á˴˴λÊÇÈçºÎ·Ö·¢¶ñÒâÈí¼þ£¬ÒÔ¼°SkimmerÈçºÎÇÔȡĿ±êÐÅÏ¢¡£


https://unit42.paloaltonetworks.com/web-skimmer-video-distribution/


ÃÀ¹úÔÚÏßÉ̵êPulseTVй¶Áè¼Ý20ÍòÓû§µÄÖ§¸¶ÐÅÏ¢


¾ÝýÌå12ÔÂ31ÈÕ±¨µÀ£¬ÃÀ¹úÔÚÏßÉ̵êPulseTVй¶Áè¼Ý20ÍòÓû§µÄÖ§¸¶ÐÅÏ¢¡£Æ¾¾Ý¹Ù·½Í¨Öªº¯£¬VISAÒÑÓÚ2021Äê3ÔÂ8ÈÕ֪ͨ¸Ã¹«Ë¾£¬ÆäÍøÕ¾£¨www.pulsetv.com£©¿ÉÄÜ´æÔÚÊý¾Ýй¶ÎÊÌâ¡£¾­¹ýÄþ¾²¼ì²é²¢Î´·¢ÏÖÈκÎй¶¼£Ï󡣸ù«Ë¾ÔÚ7ÔÂÔÙ´ÎÊÕµ½VISA¾¯±¨£¬Ö±µ½11ÔÂ18ÈÕ£¬¸ÃÍøÕ¾Òѱ»È·¶¨Îª¶àÆðMasterCardÐÅÓÿ¨½»Ò׻µÄ½»µã¡£PulseTVÔÚ12ÔÂ30ÈÕ֪ͨÓû§£¬²¢³ÆÖ»ÓÐ2019Äê11ÔÂ1ÈÕÖÁ2021Äê8ÔÂ31ÈÕʹÓÃÐÅÓÿ¨µÄÓû§Êܵ½Ó°Ïì¡£


https://www.bleepingcomputer.com/news/security/pulsetv-discloses-potential-compromise-of-200-000-credit-cards/


Chosun³Æ³¯Ïʶà¸öAPT×éÖ¯ÒÑÔÚ½»Ò×ËùÇÔÈ¡17ÒÚÃÀÔª


ýÌå1ÔÂ2Èճƣ¬Ó볯ÏÊÓйصĶà¸öAPT×éÖ¯ÒÑ´Ó½»Ò×ËùÇÔÈ¡¼ÛÖµÔ¼17ÒÚÃÀÔªµÄ¼ÓÃÜ»õ±Ò¡£CISAÌåÏÖ£¬ÊÀ½çÉÏËùÓеÄÒøÐж¼ÒѳÉΪ³¯ÏʺڿÍÍøÂç¹¥»÷µÄÄ¿±ê¡£¾ÝϤ£¬ÕâЩ¹¥»÷ʹÓÃÃûΪAppleJeusµÄ¶ñÒâÈí¼þÇÔÈ¡¼ÓÃÜ»õ±Ò¡£Åí²©ÉçÌåÏÖ£¬×Ô2018ÄêÒÔÀ´£¬ÒÑÓÐ30¸ö¹ú¼Ò/µØÓòʹÓÃApple Zeus£¬¶ø¹¥»÷ÕßÔÚ2019ÄêÖÁ2020Äê11ÔÂͨ¹ýÓ¦ÓÃÐòÇÔÈ¡3.164ÒÚÃÀÔªµÄ¼ÓÃÜ»õ±Ò¡£


https://securityaffairs.co/wordpress/126225/apt/north-korea-cryptocurrency-exchanges-hacks.html


2021ÄêÃÀ¹úÒ½ÁÆÐÐÒµ10´óÎ¥¹æÊ¼þ×ܼÆÐ¹Â¶1900ÍòÌõ


ýÌå12ÔÂ31ÈÕ±¨µÀ³Æ£¬ÃÀ¹úÎÀÉúÓ빫ÖÚ·þÎñ²¿(HHS)ÒÑÔÚÆäÍøÕ¾Áгö2021ÄêÓ°Ïì×î¹ã·ºµÄ10´óÎ¥¹æÊ¼þ¡£ÆäÖУ¬×îÑÏÖØµÄÊÇ·ðÂÞÀï´ï¶ùͯ½¡¿µÖÐÐÄ£¬Ð¹Â¶350Íò»¼ÕßÊý¾Ý  £»Æä´ÎÊÇ20/20 Eye Care NetworkÔâµ½¹¥»÷£¬µ¼ÖÂÁè¼Ý320ÍòÈ˵ÄÐÅϢй©¡£Ñо¿ÈËÔ±ÌåÏÖ£¬ÕâЩʼþ¹²Éæ¼°1900ÍòÈË£¬ÆäÖдó¶àÊýÊÇÓÉÀÕË÷¹¥»÷µ¼ÖµÄ¡£


https://www.bleepingcomputer.com/news/security/top-10-healthcare-breaches-in-the-us-exposed-data-of-19-million/


ESET¹ûÈ»2021ÄêÖµµÃ×¢ÒâµÄÍøÂçÄþ¾²Í³¼ÆÊý¾ÝÁбí


ESETÔÚ12ÔÂ30ÈÕÐû²¼µÄͳ¼Æ³ÂËßÁгö2021ÄêÖµµÃ×¢ÒâµÄÍøÂçÄþ¾²Í³¼ÆÊý¾Ý¡£³ÂËßÖ¸³ö£¬2021ÄêÊý¾Ýй¶Ôì³ÉµÄËðʧ´Ó386ÍòÃÀÔªÉÏÉýµ½424ÍòÃÀÔª£¬µ½´ï½ü17ÄêÒÔÀ´µÄ·åÖµ  £»½ñÄêÄêÖУ¬Kaseya±»SodinokibiÀÕË÷7000ÍòÃÀÔª£¬ÕâÊÇÆù½ñΪֹ×î¸ßµÄÊê½ð½ð¶î  £»2021Äê12Ô£¬Log4ShellÅû¶ºó²»¾ÃESET¼ì²âµ½ÊýÊ®Íò´Î¹¥»÷ʵÑ飬ÆäÖдó²¿ÃÅλÓÚÃÀ¹úºÍÓ¢¹ú¡£


https://www.welivesecurity.com/2021/12/30/22-cybersecurity-statistics-know-2022/


Äþ¾²¹¤¾ß


ExcelPeek 


ExcelPeek¿ÉÒÔÓÃÀ´ÊÓ²ìDZÔÚ¶ñÒâ Microsoft Excel ÎļþµÄ¹¤¾ß¡£


https://github.com/slaughterjames/excelpeek


Msmailprobe


ÓÃÓÚ Office 365 ºÍ Exchange ö¾Ù¡£


https://www.kitploit.com/2022/01/msmailprobe-office-365-and-exchange.html


Äþ¾²·ÖÎö


CVE-2021-34424£ºÐÅϢй©©¶´


ZoomµÄMMR ·þÎñÆ÷ÖдæÔÚÐÅϢй©©¶´¡£


https://packetstormsecurity.com/files/165419/GS20220103184501.tgz


ÀûÓÃÕë¶ÔSSDµÄ¹¥»÷Ö²Èë¶ñÒâÈí¼þ


Ñо¿ÈËÔ±·¢ÏÖÕë¶ÔijЩ¹Ì̬Çý¶¯Æ÷ (SSD) µÄ¹¥»÷£¬¿É½«¶ñÒâÈí¼þÖ²ÈëÓû§ºÍÄþ¾²½â¾ö·½°¸ÎÞ·¨´¥¼°µÄλÖá£


https://asec.ahnlab.com/en/29885/


Redline Stealer·ÖÎö³ÂËß


AhnLab ASEC³Æ£¬ÔÚWebä¯ÀÀÆ÷ÉÏʹÓÃ×Ô¶¯µÇ¼¹¦Ð§µÄ±ãÀûÐÔÕýÔÚ³ÉΪӰÏì×éÖ¯ºÍ¸öÈËÄþ¾²µÄÖØ´óÎÊÌâ¡£


https://asec.ahnlab.com/en/29885/