EverestÈëÇÖÄϷǹúÓеçÁ¦¹«Ë¾ESKOM²¢ÀÕË÷20ÍòÃÀÔª

Ðû²¼Ê±¼ä 2022-10-11
1¡¢EverestÈëÇÖÄϷǹúÓеçÁ¦¹«Ë¾ESKOM²¢ÀÕË÷20ÍòÃÀÔª

      

¾ÝýÌå10ÔÂ9ÈÕ±¨µÀ £¬ºÚ¿ÍÍÅ»ïEverestÈëÇÖÁËÄϷǹúÓеçÁ¦¹«Ë¾ESKOM¡£EverestÔÚ2022Äê3ÔÂÐû²¼ÉùÃ÷³ÆÒÔ12.5ÍòÃÀÔªµÄ¼Û¸ñ³öÊÛÄϷǵçÁ¦¹«Ë¾µÄroot·ÃÎÊȨÏÞ £¬Æäʱ¸Ã¹«Ë¾·ñÈÏ·¢ÉúÁËÄþ¾²Ê¼þ¡£10ÔÂ8ÈÕ £¬Ñо¿ÈËÔ±³ÆESKOM Hld SOC LtdµÄ·þÎñÆ÷Óöµ½ÎÊÌâ¡£Óë´Ëͬʱ £¬EverestÐû²¼Á˹¥»÷ÉùÃ÷ £¬ÌåÏÖ¿ÉÒÔ·ÃÎʹ«Ë¾µÄËùÓзþÎñÆ÷ £¬»¹Ìṩһ¸öÈí¼þ°ü £¬ÆäÖаüÂÞ´øÓйÜÀíÔ±¡¢root¡¢ÓÃÓÚLinuxºÍWindows·þÎñÆ÷µÄϵͳ¹ÜÀíÔ±ÃÜÂëµÄ·þÎñÆ÷µÈ £¬ÒªÇó¸Ã¹«Ë¾Ö§¸¶20ÍòÃÀÔª¡£


https://securityaffairs.co/wordpress/136866/cyber-crime/south-africa-eskom-everest-ransomware.html


2¡¢·áÌï³ÆÆäT-Connect·þÎñÖÐÔ¼29Íò¿Í»§µÄÐÅÏ¢¿ÉÄÜй¶

      

¾Ý·͸Éç10ÔÂ8ÈÕ±¨µÀ £¬·áÌïÆû³µ¹«Ë¾·¢ÏÖÆäT-Connect·þÎñÖÐÔ¼29Íò¿Í»§µÄÐÅÏ¢¿ÉÄÜÒѱ»Ð¹Â¶¡£Toyota T-ConnectÊǸù«Ë¾µÄ¹Ù·½Á¬½ÓÓ¦Óà £¬³µÖ÷¿ÉÀûÓøÃÓ¦Óý«ÖÇÄÜÊÖ»úÓë³µÁ¾µÄÐÅÏ¢ÓéÀÖϵÍÂ䬽ӯðÀ´¡£¸ÃÆû³µÖÆÔìÉÌÌåÏÖ £¬¿ª·¢T-ConnectÍøÕ¾µÄ³Ð°üÉ̲»Ð¡ÐÄÉÏ´«ÁË´øÓй«¹²ÉèÖõIJ¿ÃÅÔ´´úÂë £¬ÆäÖаüÂÞ´æ´¢¿Í»§ÓʼþµØÖ·ºÍ¹ÜÀíºÅÂëµÄÊý¾Ý·þÎñÆ÷µÄ·ÃÎÊÃÜÔ¿¡£ÕâʹµÃδ¾­ÊÚȨµÄµÚÈý·½¿ÉÒÔÔÚ2017Äê12ÔÂÖÁ2022Äê9ÔÂ15ÈÕ·ÃÎÊ296019Ãû¿Í»§µÄÏêϸÐÅÏ¢¡£¸Ã¹«Ë¾ÒÑÔÚ2022Äê9ÔÂ17ÈÕ¸ü¸ÄÁËÊý¾Ý¿âµÄÃÜÔ¿¡£


https://www.reuters.com/technology/toyota-says-information-about-296000-users-its-t-connect-service-leaked-2022-10-07/


3¡¢ÒÁÀʹúÓª¹ã²¥¹«Ë¾ÔÚÖ±²¥ÐÂÎÅʱÔâµ½Edalate AliµÄ¹¥»÷

      

10ÔÂ10ÈÕ±¨µÀ³Æ £¬ÒÁÀʹ㲥¹«Ë¾IRIBÔËÓªµÄIRINNÔÚÉÏÖÜÁùÍíÉϲ¥³öÐÂÎÅͨ¸æÊ±Ôâµ½Á˺ڿ͹¥»÷¡£ÃûΪEdalate AliµÄºÚ¿ÍÉù³Æ¶Ô´ËÊÂÂôÁ¦ £¬¹¥»÷ÊÇÒÔAnonymousÌᳫµÄOpIranÐж¯µÄÃûÒå½øÐеÄ¡£ÖÜÁùÏÂÎç17:30 GMT×óÓÒ £¬¸ÃƵµÀÔÚ²¥·ÅÐÂÎÅʱͻȻÖÐ¶Ï £¬²¢¿ªÊ¼²¥·ÅÀ´×Ժڿ͵ÄÏûÏ¢¡£¸ÃÍÅ»ï»¹ÔøÓÚÈ¥Äê8ÔÂÈëÇÖÁ˵ºÚÀ¼±±²¿¼àÓüµÄϵͳºÍÉãÏñÍ· £¬ÒÔ½Ò¶¼àÓüÖеÄÑÏ¿áÌõ¼þºÍÇּ෸ȨµÄÐÐΪ¡£


https://www.hackread.com/iran-state-run-tv-hacked-edalate-ali-hackers/


4¡¢BidenCashÃâ·ÑÐû²¼Áè¼Ý120ÍòÕÅÐÅÓÿ¨µÄÖ§¸¶ÐÅÏ¢

      

ýÌå10ÔÂ9ÈÕ³Æ £¬BidenCashÐû²¼ÁË1221551ÕÅÐÅÓÿ¨µÄÐÅÏ¢ £¬ÈκÎÈ˶¼¿ÉÒÔÃâ·ÑÏÂÔØËüÃÇÀ´½øÐнðÈÚÕ©Æ­¡£BidenCashÊÇÒ»¸ö½»Ò×±»µÁÐÅÓÿ¨µÄÊг¡ £¬ÓÚ2022Äê6ÔÂÍÆ³ö £¬ËüЧ·ÂÁËÀàËÆÆ½Ì¨All World CardsÔÚ2021Äê8Ô½ÓÄɵķ½Ê½ £¬ÒÔ´ó¹æÄ£Íƹã¸ÃÍøÕ¾¡£´Ë´ÎÐû²¼µÄÎļþ°üÂÞÀ´×ÔÊÀ½ç¸÷µØµÄÓÐЧÆÚΪ2023ÄêÖÁ2026ÄêµÄÐÅÓÿ¨¼¯ºÏ £¬´ó¶àÊýËÆºõÀ´×ÔÃÀ¹ú £¬ÆäÖÐÉæ¼°¿¨ºÅ¡¢½ØÖ¹ÈÕÆÚ¡¢CVVºÅÂë¡¢³ÖÓÐÈËÐÕÃûºÍÒøÐÐÃû³ÆµÈÐÅÏ¢¡£


https://www.bleepingcomputer.com/news/security/darkweb-market-bidencash-gives-away-12-million-credit-cards-for-free/


5¡¢¹þ·ðÉÌÒµ³öÊéÉçÔÚÍÁ¶úÆäµÄÐí¿É¹«Ë¾Ôâµ½ÀÕË÷¹¥»÷

      

ýÌå10ÔÂ10ÈÕ±¨µÀ £¬¹þ·ðÉÌÒµ³öÊéÉçÔÚÍÁ¶úÆäµÄÐí¿É¹«Ë¾Ôâµ½ÁËÀÕË÷¹¥»÷¡£9ÔÂ16ÈÕ £¬CybernewsÑо¿ÈËÔ±·¢ÏÖÁËinfomag.com.trµÄÒ»¸ö¿ª·ÅµÄMongoDBʵÀý £¬InfomagÒÔÍÁ¶úÆäÓï³öÊé¡¶Åí²©ÉÌÒµÖÜ¿¯¡·ºÍ¡¶¹þ·ðÉÌÒµÆÀÂÛ¡·¡£¸ÃÊý¾Ý¿âÍйÜÔÚÍÁ¶úÆä £¬Ô¼Îª3.9GB £¬ÓÐÁè¼Ý1950ÍòÌõ¼Ç¼ £¬152000ÌõÓë¿Í»§ÓйصÄÐÅÏ¢ £¬×îÔç¿ÉÒÔ×·Ëݵ½2017Äê¡£9ÔÂ19ÈÕ £¬CybernewsÖØÐ·ÃÎʸÃÊý¾Ý¿â¼ì²ìËüÊÇ·ñ¹Ø±Õʱ £¬µÃÖªËüÔâµ½ÁËÀÕË÷¹¥»÷¡£¹¥»÷ÕßÀÕË÷0.01±ÈÌØ±Ò £¬²¢ÒÔÎ¥·´GDPRÃæÁÙ¾Þ¶î·£¿îΪÍþв £¬InfomagºÃÏñ²¢Î´¸¶Êê½ð¡£


https://securityaffairs.co/wordpress/136860/cyber-crime/harvard-business-publishing-licensee-hit-by-ransomware.html


6¡¢TrellixÐû²¼BazarCallÉ繤¹¥»÷¼ÆÄ±ÑݱäµÄ·ÖÎö³ÂËß

      

10ÔÂ6ÈÕ £¬TrellixÐû²¼Á˹ØÓÚBazarCallÉ繤¹¥»÷¼ÆÄ±ÑݱäµÄ·ÖÎö³ÂËß¡£Æ¾¾Ý·ÖÎö £¬Trellix¸ÅÊöÁËBazarCall»î¶¯µÄ¹¥»÷Á÷³Ì £¬²¢½«Æä·ÖΪÈý¸ö½×¶Î £¬»¹½ÒʾÁËÉ繤¹¥»÷¼ÆÄ±µÄÑݱä¡£´ËÀ๥»÷ÓÚ2021Äê3ÔÂÊ״ηºÆð £¬×îеĻÖ÷ÒªÕë¶ÔÃÀ¹ú¡¢¼ÓÄôó¡¢Ó¢¹ú¡¢Ó¡¶ÈºÍÈÕ±¾µÈ¹ú¼ÒµÄÓû§ £¬ÆäÖдó¶àÊý¶¼ÔÚÍÆËÍÃûΪsupport.Client.exeµÄClickOnce¿ÉÖ´ÐÐÎļþ £¬¸ÃÎļþ»áÔÚÆô¶¯Ê±»á°²×°Ô¶³Ì·ÃÎʹ¤¾ßScreenConnect¡£


https://www.trellix.com/en-us/about/newsroom/stories/research/evolution-of-bazarcall-social-engineering-tactics.html