T-MobileÒòÈ¥ÄêÊý¾Ýй¶Ê¼þÅâ³¥ÆäÓû§3.5ÒÚÃÀÔª
Ðû²¼Ê±¼ä 2022-07-261¡¢T-MobileÒòÈ¥ÄêÊý¾Ýй¶Ê¼þÅâ³¥ÆäÓû§3.5ÒÚÃÀÔª
¾Ý7ÔÂ24ÈÕ±¨µÀ£¬T-MobileÒÑͬÒâÏò½ü7700ÍòÓû§Å⸶3.5ÒÚÃÀÔª£¬ÒÔ½â¾ö¹ØÓڸù«Ë¾2021ÄêÊý¾Ýй¶Ê¼þµÄ¼¯ÌåËßËÏ¡£È¥Äê8Ô·ݣ¬¸Ã¹«Ë¾µÄϵͳÔâµ½ºÚ¿ÍÈëÇÖ£¬Óû§µÄÉç»áÄþ¾²ºÅÂë¡¢ÐÕÃû¡¢µØÖ·ºÍ¼ÝʻִÕÕµÈÐÅϢй¶¡£Æ¾¾ÝÉÏÖÜÎåµÄÎļþ£¬3.5×ʽð½«ÓÃÓÚÖ§¸¶ÊÜÓ°ÏìÓû§µÄË÷Åâ¡¢Ô¸æÂÉʦµÄÖ´·¨ÓöÈÒÔ¼°¹ÜÀíºÍ½âµÄÓöȡ£T-Mobile»¹ÌåÏÖ½«ÔÚ2022ÄêºÍ2023Ä껨·Ñ1.5ÒÚÃÀÔªÀ´¼ÓÇ¿ÆäÊý¾ÝÄþ¾²ºÍÆäËü¼¼Êõ¡£
https://www.securityweek.com/t-mobile-settles-pay-350m-customers-data-breach
2¡¢ÀÕË÷ÍÅ»ïLockBitÉù³ÆÒÑÇÔÈ¡Òâ´óÀû˰Îñ»ú¹¹78 GBÊý¾Ý
ýÌå7ÔÂ25ÈÕ±¨µÀ£¬Òâ´óÀûÕýÔÚÊÓ²ìÆä˰Îñ»ú¹ØÔâµ½ÀÕË÷¹¥»÷µÄʼþ¡£ÉÏÖÜÄ©£¬LockBit½«¸Ã»ú¹¹Ìí¼Óµ½ÆäÊý¾ÝÐ¹Â¶ÍøÕ¾£¬Éù³ÆÒÑÇÔÈ¡78 GBÊý¾Ý£¬²¢¸øÁ˸ûú¹¹Ô¼Äª6ÌìµÄʱ¼ä×ö³ö»ØÓ¦¡£Ö®ºó£¬¸ÃÍŻォ½ØÖ¹ÈÕÆÚÑÓ³¤ÖÁ8ÔÂ1ÈÕ£¬²¢Éù³ÆÆäÒÑ»ñµÃ100 GBÊý¾Ý¡£L'Agenzia delle EntrateÔÚÖÜÒ»·¢±íÉùÃ÷³Æ£¬ËüÒªÇó¾¼ÃºÍ²ÆÕþ²¿µÄIT¹«Ë¾SogeiÊÓ²ìÕâÆðËùνµÄÀÕË÷¹¥»÷ʼþ¡£
https://therecord.media/italy-investigating-ransomware-attack-on-tax-agency/
3¡¢Î¢Èí³Æ7Ô·ÝWindows¸üпÉÄܵ¼Ö´òÓ¡¹¦Ð§·ºÆðÎÊÌâ
7ÔÂ22ÈÕ±¨µÀ£¬Î¢ÈíÌåÏÖ´Ó±¾ÖܵĿÉѡԤÀÀ¸üпªÊ¼£¬Ò»ÄêǰΪ½â¾öWindows ServerÔÚ²»¼æÈÝÉ豸ÉÏ´òÓ¡ÎÊÌâ¶øÌṩµÄÁÙʱ»º½â´ëÊ©½«±»ÒƳý£¬Õâ¿ÉÄܻᵼÖ´òÓ¡¹¦Ð§·ºÆðÎÊÌ⡣΢Èí½âÊͳƣ¬ÊÜÓ°ÏìµÄÉ豸°üÂÞÖÇÄÜ¿¨Éí·ÝÑéÖ¤´òÓ¡»ú¡¢É¨ÃèÒǺͶ๦ЧÉ豸£¬ËüÃÇÔÚPKINIT KerberosÈÏÖ¤ÆÚ¼ä²»Ö§³ÖDHÃÜÔ¿½»»»£¬»òÕßÔÚKerberos ASÇëÇóÆÚ¼ä²»Ö§³ÖÈýÖØDES¡£Óû§ÐèÒª¸üкϹæ»ò¸ü»»²»ºÏ¹æµÄÉ豸¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-that-new-windows-updates-may-break-printing/
4¡¢ÎÚ¿ËÀ¼¹ã²¥¹«Ë¾TAVR Media±»¹¥»÷²¢Á÷´«Ðé¼ÙÐÅÏ¢
ýÌå7ÔÂ22Èճƣ¬ÎÚ¿ËÀ¼¹ã²¥¹«Ë¾TAVR MediaÔâµ½¹¥»÷£¬²¢Á÷´«×ÜͳVolodymyr Zelenskyy²¡ÖصÄÐé¼ÙÐÅÏ¢¡£Õâ¼Ò¹«Ë¾ÔËÓª×ÅÎÚ¿ËÀ¼µÄ9¸öÖ÷ÒªµÄ¹ã²¥µç̨£¬°üÂÞHit FM¡¢Radio ROKS¡¢KISS FMºÍRadio RELAXµÈ¡£ÎÚ¿ËÀ¼¹ú¼ÒÌØÊâͨÐźÍÐÅÏ¢±£»¤¾Ö£¨SSCIP£©³Æ£¬¹¥»÷ÕßÆÆ»µÁËTAVR MediaµÄ·þÎñÆ÷ºÍ¹ã²¥ÏµÍ³À´Ðû²¼Ðé¼ÙÏûÏ¢£¬ËûÃÇÕýÔÚŬÁ¦½â¾ö¸ÃÎÊÌ⡣Ŀǰ£¬¹¥»÷µÄÀ´Ô´Éв»Çå³þ¡£
https://thehackernews.com/2022/07/ukrainian-radio-stations-hacked-to.html
5¡¢TA4563ÀûÓúóÃÅEvilNum¹¥»÷Å·Ö޵ĽðÈÚºÍͶ×ÊÐÐÒµ
ProofpointÔÚ7ÔÂ21ÈÕÅû¶ÁËTA4563ÀûÓù¥»÷Å·Ö޵ĽðÈÚºÍͶ×ÊÐÐÒµµÄ»î¶¯µÄÏêÇé¡£´Ë´Î»î¶¯Ê¼ÓÚ2021Äêµ×£¬ÀûÓÃÁ˶ñÒâÈí¼þEvilNum£¬Ö÷ÒªÕë¶ÔÖ§³ÖÍâ»ã¡¢¼ÓÃÜ»õ±ÒºÍÈ¥ÖÐÐÄ»¯½ðÈÚ(DeFi)ÒµÎñµÄʵÌå¡£EvilNumÊÇÒ»¸öºóÃÅ£¬¿ÉÇÔÈ¡Êý¾Ý»ò¼ÓÔØÌØ±ðµÄpayload¡£¸Ã¶ñÒâÈí¼þ°üÂÞ¶à¸öÓÐȤµÄ×é¼þ£¬¿ÉÓÃÓÚÈÆ¹ý¼ì²â²¢Æ¾¾ÝÒÑʶ´ËÍâɱ¶¾Èí¼þÐÞ¸ÄѬȾ·¾¶¡£¸Ã»î¶¯ÓëZscalerÔÚ2022Äê6Ô¹ûÈ»µÄEvilNum»î¶¯Óв¿ÃÅÖØµþ¡£
https://www.proofpoint.com/us/blog/threat-insight/buy-sell-steal-evilnum-targets-cryptocurrency-forex-commodities
6¡¢ASEC·¢ÏÖͨ¹ýISOÎļþ·Ö·¢¶ñÒâÈí¼þIcedIDµÄ»î¶¯
7ÔÂ25ÈÕ£¬ASECÐû²¼Á˹ØÓÚͨ¹ýISOÎļþ·Ö·¢IcedIDµÄ»î¶¯µÄ·ÖÎö³ÂËß¡£³ÂËß½éÉÜÁËÁ½ÖÖ·Ö·¢·½Ê½£¬µÚÒ»ÖÖÊÇÀûÓõç×ÓÓʼþ½Ù³Ö¼¼ÊõÀ´½Ù³ÖÕý³£Óʲ¢ÏòÓû§·¢ËÍ´øÓжñÒ⸽¼þµÄ»Ø¸´£¬¸ÃÎļþ±»Ñ¹Ëõ£¬ÆäÖаüÂÞÒ»¸öISOÎļþ¡£ÔËÐÐISOÎļþ»áÔÚDVDÇý¶¯Æ÷Öд´½¨Ò»¸ölnkºÍÒ»¸öDLLÎļþ£¬²¢Í¨¹ýlnkÎļþ¼ÓÔØDLL£¬¼ÓÔØµÄDLL¾ÍÊÇIcedID¡£µÚ¶þÖÖISOÎļþÖгýÁËlnkºÍDLLÖ®Í⻹ÓÐÆäËüÎļþ£¬lnkÎļþÔËÐÐÎļþ¼ÐthemÄÚµÄworker.cmd£¬Ö®ºóÔËÐÐworker.js¡£worker.jsͨ¹ýrundll32.exe½«then.dat¼ÓÔØµ½Í¬Ò»Îļþ¼ÐÖУ¬then.datÊÇÒ»¸öDLL£¨IcedID£©¡£
https://asec.ahnlab.com/en/37005/