AzureÓû§ÔËÐÐUbuntu 18.04µÄVMÒòsystemd¸üдíÎóÖжÏ
Ðû²¼Ê±¼ä 2022-08-31
¾ÝýÌå8ÔÂ30ÈÕ±¨µÀ£¬Î¢ÈíAzureÓû§µÄÔËÐÐUbuntu 18.04µÄÐéÄâ»ú£¨VM£©Òòsystemd¸üжéÂäµ¼ÖÂÁ¬ÐøÖжϡ£ÖжϿªÊ¼ÓÚ8ÔÂ30ÈÕ06:00 UTC×óÓÒ£¬ÊÜÓ°ÏìµÄÓû§Éý¼¶µ½systemd°æ±¾237-3ubuntu10.54ºó£¬ÐéÄâ»ú¿ªÊ¼·ºÆðDNS´íÎó£¬ÇÒûÓпÉÓõÄDNS½âÎöÆ÷µØÖ·¡£ÊÜ´ËÖжÏÓ°ÏìµÄ·þÎñ°üÂÞAzure Kubernetes Service(AKS)¡¢Azure Monitor¡¢Azure SentinelºÍAzure Container AppsµÈ¡£Î¢ÈíΪÊÜÓ°ÏìµÄAzureÓû§ÌṩÁËÒ»¸öÌØ±ðµÄ½â¾öÒªÁ죬°üÂÞÖØÐÂÆô¶¯ÊÜÓ°ÏìµÄUbuntuÐéÄâ»ú¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-azure-outage-knocks-ubuntu-vms-offline-after-buggy-update/
2¡¢FTCÆðËßKochavaÊÕ¼¯²¢³öÊÛÊýÒÚ²¿ÊÖ»úµÄλÖÃÊý¾Ý
ýÌå8ÔÂ30Èճƣ¬ÃÀ¹úÁª°îóÒ×ίԱ»á(FTC)¶ÔÊý¾ÝÖмäÉÌKochavaÌáÆðËßËÏ£¬Ö¸¿ØÆäÊÕ¼¯ºÍ³öÊÛ´ÓÏû·ÑÕßµÄÒÆ¶¯É豸ÊÕ¼¯µÄµØÀíλÖÃÊý¾Ý¡£ÊÕ¼¯µÄÊý¾Ý»áÒÔ¶©ÔĵÄÐÎʽÌṩӦÓû§£¬Óû§¿ÉÒÔͨ¹ýÔÚÏßÊý¾ÝÊг¡·ÃÎÊ£¬¶©ÔÄÓöÈΪ25000ÃÀÔª¡£FTCÌåÏÖ£¬KochavaÌṩµÄÊý¾Ý¿Éʹ¸öÈËÃæÁÙÐ߳ܡ¢¸ú×Ù¡¢ÆçÊÓ¡¢Ê§ÒµÉõÖÁÉíÌ屩Á¦µÄÍþв¡£Òò´Ë£¬FTCµÄËßËÏÖ¼ÔÚ×èÖ¹Kochava³öÊÛµØÀíλÖÃÊý¾Ý£¬²¢ÒªÇóɾ³ýÆäÒѾÊÕ¼¯µÄÊý¾Ý¡£
https://thehackernews.com/2022/08/ftc-sues-data-broker-over-selling.html
3¡¢Baker&TaylorÔÚÔâµ½ÀÕË÷¹¥»÷ºóŬÁ¦»Ö¸´ÊÜÓ°Ïìϵͳ
¾Ý8ÔÂ29ÈÕ±¨µÀ£¬×Ô³ÆÊÇÈ«Çò×î´óµÄͼÊé¹ÝͼÊé·ÖÏúÉ̵ÄBaker&TaylorÔâµ½ÀÕË÷¹¥»÷¡£¸Ã¹«Ë¾8ÔÂ23ÈÕ͸¶£¬ÔÚÒ»´ÎÓ°Ï칫˾µç»°ÏµÍ³¡¢°ì¹«ÊҺͷþÎñÖÐÐĵĹÊÕÏºó£¬Æä·þÎñÆ÷Öжϡ£Ö®ºó£¬¸Ã¹«Ë¾È·¶¨ÖжÏÔ´ÓÚÖÜÄ©Ôâµ½µÄÀÕË÷¹¥»÷£¬²¢ÌåÏÖËûÃǻᾡ¿ì»Ö¸´ÔËÓª¡£Ä¿Ç°£¬Ã»ÓйØÓڴ˴ι¥»÷±³ºóµÄÀÕË÷ÍÅ»ïµÄÐÅÏ¢£¬µ«¸Ã¹«Ë¾³ÆÆäÈÔÔÚŬÁ¦»Ö¸´ÊÜÓ°ÏìµÄ·þÎñÆ÷£¬ÇÒÃ÷È·ÌåÏÖ²»»á¸¶Êê½ð¡£
https://therecord.media/major-u-s-library-service-confirms-ransomware-attack-struggling-to-restore-affected-systems/
4¡¢Nelnet Servicing±»ÈëÇÖºóй¶250Íò¸öѧÉúµÄ´û¿îÐÅÏ¢
¾ÝýÌå8ÔÂ29Èճƣ¬ÔÚºÚ¿ÍÈëÇÖ¼¼Êõ·þÎñÌṩÉÌNelnet ServicingµÄϵͳºó£¬¶í¿ËÀºÉÂíÖÝѧÉú´û¿î¹ÜÀí¾Ö(OSLA)ºÍEdFinancialµÄѧÉú´û¿îÊý¾Ýй¶¡£OSLAºÍEdFinancialʹÓÃNelnet ServicingµÄ¼¼Êõ·þÎñÓÃÓÚÔÚÏß´û¿îµÄѧÉú·ÃÎÊÆä´û¿îÕË»§¡£¹¥»÷ÕßÔÚ6Ô·ÝÈëÇÖÁËNelnet Servicing£¬²¢Ò»Ö±´æÔÚµ½7ÔÂ22ÈÕ¡£¾ÝϤ£¬¹¥»÷Õß¿ÉÄÜÊÇÀûÓé¶´ÈëÇÖÁ˹«Ë¾µÄÍøÂ磬Լ2501324ÈËÊܵ½Ó°Ï졣Ŀǰ£¬EdFinancialºÍOSLA¶¼Í¨¹ýExperianΪÊÜÓ°ÏìµÄÓû§Ãâ·ÑÌṩ24¸öÔµÄÉí·Ý͵ÇÔ±£»¤·þÎñ¡£
https://www.bleepingcomputer.com/news/security/nelnet-servicing-breach-exposes-data-of-25m-student-loan-accounts/
5¡¢CheckPoint¼ì²âµ½Î±×°³É¹È¸è·ÒëµÈÓ¦ÓõÄÍÚ¿ó¶ñÒâÈí¼þ
8ÔÂ29ÈÕ£¬Check Point³ÆÆä¼ì²âµ½Î±×°³É¹È¸è·Òë×ÀÃæÓ¦ÓõȺϷ¨Ó¦Ó÷¨Ê½µÄÍÚ¿ó¶ñÒâÈí¼þ¡£¸Ã»î¶¯ÓëÍÁ¶úÆäÈí¼þ¿ª·¢ÉÌNitrokodÓйأ¬Ëü×Ô2019Ä꿪ʼ»îÔ¾£¬Éù³ÆÌṩÃâ·ÑÇÒÄþ¾²µÄÈí¼þ¡£¸Ã»î¶¯Í¨¹ýÊýÊ®¸öÃâ·ÑÈí¼þÍøÕ¾µÄÁ÷ÐÐÈí¼þ·Ö·¢¶ñÒâÈí¼þ£¬ÒÑѬȾ11¸ö¹ú¼ÒµÄÊýǧ̨É豸¡£´ËÍ⣬ÔÚ³õʼÈí¼þ°²×°Ö®ºó£¬¹¥»÷Õß½«Ñ¬È¾¹ý³ÌÍÆ³ÙÁËÊýÖÜ£¬²¢É¾³ýÁËÔʼ°²×°µÄºÛ¼££¬Ê¹µÃ¸Ã»î¶¯Äܹ»ÈƹýÄþ¾²¼ì²â²¢ÀÖ³ÉÔËÓª¶àÄê¡£
https://research.checkpoint.com/2022/check-point-research-detects-crypto-miner-malware-disguised-as-google-translate-desktop-and-other-legitimate-applications/amp/
6¡¢ºÚ¿ÍÔÚ°µÍø³öÊÛÌ©¹úҽѧ¿ÆÑ§²¿µÄCOVID-19»¼ÕßÐÅÏ¢
¾ÝResecurity 8ÔÂ25ÈÕ±¨µÀ£¬ºÚ¿ÍÔÚ°µÍøÉϳöÊÛ´ÓÌ©¹úҽѧ¿ÆÑ§²¿ÇÔÈ¡µÄCOVID-19»¼ÕßÐÅÏ¢¡£½øÒ»·¨Ê½²éÈ·ÈÏ£¬¹¥»÷ÕßÈëÇÖÁËÌ©¹úҽѧ¿ÆÑ§²¿µÄWEBÓ¦Ó÷¨Ê½£¨https://longcovidcheckin.dms.go.th£©£¬ÆäÓÃÓÚÔÚÏßÊÓ²ìºÍÊÕ¼¯¹«ÃñºÍÓοͷÃÎʸùúµÄCOVID-19Êý¾Ý¡£ÓÉÓÚWEBÓ¦Ó÷¨Ê½µÄÊÚȨģ¿éÖдæÔÚSQL×¢Èë©¶´£¬Òò´Ë¸Ã·ÃÎÊÊÇ¿ÉÄܵġ£¹¥»÷Õß¿ÉÄÜÒѾ·ÃÎÊÁËÖÁÉÙ5151Ìõ¼Ç¼£¬Ç±ÔÚй¶×ÜÊýΪ15000Ìõ¡£Ä¿Ç°£¬ResecurityÒѽ«´ËʳÂË߸øÖ´·¨²¿ÃźÍÌ©¹úCERT¡£
https://resecurity.com/blog/article/covid-19-data-put-for-sale-in-dark-web