¼ÓÄôóÁ¬Ëø³¬ÊÐSobeysÔâµ½Black BastaµÄÀÕË÷¹¥»÷

Ðû²¼Ê±¼ä 2022-11-14
1¡¢¼ÓÄôóÁ¬Ëø³¬ÊÐSobeysÔâµ½Black BastaµÄÀÕË÷¹¥»÷

¾ÝýÌå11ÔÂ12ÈÕ±¨µÀ  £¬×ÔÉÏÖÜÄ©ÒÔÀ´  £¬¼ÓÄôóSobeysÆìϵÄÔÓ»õµêºÍÒ©µêµÄITϵͳһֱ´æÔÚÎÊÌâ ¡£SobeysµÄĸ¹«Ë¾Empire͸¶  £¬ËäÈ»ÆäÉ̵êÈÔÔÚÓªÒµ  £¬Ä¿Ç°Ã»ÓзºÆðÑÏÖØÖÐ¶Ï  £¬µ«ÊDz¿ÃŵêÄÚ·þÎñ¿ÉÄÜÊܵ½Ó°Ïì ¡£¾ÝÔ±¹¤Í¸Â¶  £¬ÊÜÓ°ÏìÉ̵êÖеÄËùÓмÆËã»ú¶¼Òѱ»Ëø¶¨  £¬µ«POSºÍÖ§¸¶´¦ÖÃϵͳÈÔÈ»ÔÚÏß  £¬ÒòΪËüÃÇÔÚµ¥¶ÀµÄÍøÂçÉÏ ¡£¾¡¹Ü¸Ã¹«Ë¾ÉÐδÅû¶¹ØÓÚ´Ë´ÎÖжϵÄϸ½ÚÐÅÏ¢  £¬µ«Ñо¿ÈËԱͨ¹ýÊê½ð¼Ç¼ºÍ̸ÅжԻ°ÍƲâ¸Ã¹«Ë¾µÄϵͳѬȾÁËBlack Basta ¡£

https://securityaffairs.co/wordpress/138424/cyber-crime/sobeys-ransomware-attack.html

2¡¢ºÚ¿ÍÉù³ÆÒÑÈëÇÖµÂÒâÖ¾ÒøÐв¢ÔÚÍøÉϳöÊÛÆä·ÃÎÊȨÏÞ

¾Ý11ÔÂ11ÈÕ±¨µÀ  £¬¹¥»÷Õß(0x_dump)Éù³ÆÒÑÈëÇÖ¿ç¹úͶ×ÊÒøÐеÂÒâÖ¾ÒøÐÐ  £¬²¢ÔÚÏßÏúÊÛÆäÍøÂçµÄ·ÃÎÊȨÏÞ ¡£¸ÃIAB£¨initial access broker£©ÌåÏÖ¿ÉÒÔ·ÃÎÊÒøÐÐϵͳÖеÄÔ¼21000̨É豸  £¬ÆäÖдó²¿ÃÅÊÇWindowsϵͳ  £¬Ëû»¹³Æ±»Ñ¬È¾µÄÉ豸ÊÜSymantec EDR½â¾ö·½°¸µÄ±£»¤ ¡£Âô¼Ò˵Ëû¿ÉÒÔ·ÃÎÊÓÃÓÚÄÚ²¿Í¨ÐŵÄÁÄÌì·þÎñ  £¬»¹¿ÉÒÔ·ÃÎʰüÂÞ16 TBÊý¾ÝµÄÎļþ·þÎñÆ÷ ¡£¶ÔµÂÒâÖ¾ÒøÐзÃÎÊȨÏÞµÄÊÛ¼ÛΪ7.5±ÈÌØ±Ò  £¬¼ÛÖµÔ¼156274ÃÀÔª ¡£

https://securityaffairs.co/wordpress/138416/data-breach/deutsche-bank-alleged-data-breach.html

3¡¢Ó¢¹úÓÊÕþ¹«Ë¾Royal MailµÄÍøÕ¾·þÎñÖжÏÁè¼Ý24Сʱ

ýÌå11ÔÂ11ÈÕ³Æ  £¬Ó¢¹ú»Ê¼ÒÓÊÕþµÄTrack&TraceÍøÕ¾ÖжÏÁè¼Ý24Сʱ  £¬Óû§ÎÞ·¨×·×ÙËûÃǵİü¹üºÍÓʼþµÝËÍ ¡£Óû§·ÃÎʸÃÍøÕ¾Ê±»áÊÕµ½¡°·þÎñÔÝʱ²»ÐÐÓá±Ìáʾ  £¬¶øTrack & Trace APIÒ»Ö±ÔÚ·µ»ØHTTP 429״̬´úÂë  £¬Õâ±íÃ÷·þÎñÆ÷½ÓÊÕµ½µÄÇëÇó¹ý¶à ¡£Ñо¿ÈËԱѯÎÊÊÇ·ñÔâµ½ÁËÍøÂç¹¥»÷  £¬¹«Ë¾µÄ·¢ÑÔÈËÌåÏÖÍøÕ¾´æÔÚ¼¼ÊõÎÊÌâ  £¬µ«Óû§¿ÉÒÔÔÚRoyal MailÓ¦ÓÃÉϸú×Ù°ü¹ü ¡£ÉÏÖÜ  £¬Click&DropÍøÕ¾ÉϵĿͻ§ÐÅϢй¶  £¬ÆÈʹ»Ê¼ÒÓÊÕþÔÝʱ¹Ø±ÕÆäÔÚÏßÒµÎñ ¡£

https://www.bleepingcomputer.com/news/security/royal-mail-down-tracking-unavailable-as-outage-exceeds-24-hours/

4¡¢ÂíÀ´Î÷ÑÇÑ¡¾ÙίԱ»áµÄÊý¾Ý¿âй¶½ü80ÍòÑ¡ÃñµÄÐÅÏ¢

11ÔÂ11ÈÕ±¨µÀ³Æ  £¬ÂíÀ´Î÷ÑÇÔ¼80ÍòÃûÑ¡ÃñµÄ¸öÈËÐÅϢй¶ ¡£¾Ý³Æ  £¬Ð¹Â¶µÄ67 GBÊý¾Ýй¿à´×ÔÑ¡¾ÙίԱ»áµÄÊý¾Ý¿â  £¬¸ÃÊý¾Ý¿âĿǰÔÚÒ»¸ö°µÍøÊг¡ÉÏÒÔ2000ÃÀÔªµÄ¼Û¸ñ³öÊÛ ¡£11ÔÂ10ÈÕ  £¬Ñо¿ÈËÔ±ÔÚlowyat.net·¢ÏÖÁ˳öÊÛµÄÐÅÏ¢  £¬Éæ¼°¾ÓÃñµÄÐÕÃû¡¢Éí·ÝÖ¤ºÅÂë¡¢ÓʼþµØÖ·¡¢³öÉúÈÕÆÚºÍ¼ÒͥסַµÈ ¡£¾Ý³Æ  £¬ÕâЩÊý¾ÝÊÇ´ÓÑ¡¾ÙίԱ»áµÄMySPRÍøÕ¾ÉÏÇÔÈ¡µÄ ¡£Õâһй¶Ê¼þ·¢ÉúÔÚ11ÔÂ19ÈÕÈ«¹úͶƱǰһÖÜ  £¬ÒýÆðÁËÂíÀ´Î÷ÑǾÓÃñµÄµ£ÓÇ ¡£

https://www.nst.com.my/news/crime-courts/2022/11/849700/personal-info-800000-voters-compromised-alleged-breach-ec-database

5¡¢Zscaler·¢ÏÖGoogle PlayÖзַ¢XenomorphľÂíµÄÓ¦ÓÃ

ZscalerÔÚ11ÔÂ10ÈÕ͸¶ÆäÔÚGoogle PlayÉ̵êµÄÓ¦ÓÃÖз¢ÏÖÁËÒøÐÐľÂíXenomorph ¡£XenomorphÓëAlienÓÐËùÖØµþ  £¬µ«ËüÃǵĹ¦Ð§ÍêÈ«²îÒì  £¬Ñо¿ÈËÔ±ÍÆ²âÕâÁ½ÖÖ¶ñÒâÈí¼þ¿ÉÄÜÊÇÓÉͬһ¿ª·¢ÈËÔ±¿ª·¢ ¡£¸Ã¶ñÒâÓ¦ÓÃÃûΪTodo: Day manager  £¬ÏÂÔØÁ¿Áè¼Ý1000´Î ¡£Zscaler»¹·¢ÏÖÁíÒ»¸öÓ¦Óá°½U·Ñ¥­©`¥Ñ©`¡±£¨Expense Keeper£©Ò²ÌåÏÖ³öÁËÀàËÆµÄÐÐΪ  £¬µ«ÊÇ´ËÓ¦Óò»»á¼ìË÷payloadµÄdropper URL ¡£

https://www.zscaler.com/blogs/security-research/rise-banking-trojan-dropper-google-play-0

6¡¢LookoutÐû²¼¹ØÓÚBadBazaarºÍMOONSHINEµÄ·ÖÎö³ÂËß

11ÔÂ10ÈÕ  £¬LookoutÐû²¼Á˹ØÓÚ¶ñÒâÈí¼þBadBazaarºÍMOONSHINEµÄ·ÖÎö³ÂËß ¡£×Ô2018ÄêÒÔÀ´  £¬BadBazaar¼äµýÈí¼þÒÑʹÓÃÖÁÉÙ111¸ö²îÒìµÄÓ¦Ó÷¨Ê½Ñ¬È¾Ä¿±ê  £¬Èç×ֵ䡢µç³ØÓÅ»¯¹¤¾ßºÍÊÓÆµ²¥·ÅÆ÷µÈ  £¬²¢ÔÚÌØ¶¨µÄͨÐÅÇþµÀÉϽøÐÐÐû´« ¡£´Ó2022Äê7Ô¿ªÊ¼  £¬Lookout¾ÍÊӲ쵽һÆðеĻ  £¬ÀûÓÃ50¸öÓ¦ÓÃÏòÄ¿±êÍÆËÍа汾µÄMoonshine  £¬Ëü¿ÉÒÔ¼àÊÓÄ¿±êµÄÍøÂç»î¶¯¡¢IP µØÖ·ºÍÓ²¼þÐÅÏ¢µÈ ¡£

https://www.lookout.com/blog/uyghur-surveillance-campaign-badbazaar-moonshine