PyPIÒÑÔÝÍ£ÐÂÓû§×¢²áºÍÐÂÏîÄ¿ÉÏ´«¹¦Ð§Ö±ÖÁÁíÐÐ֪ͨ

Ðû²¼Ê±¼ä 2023-05-23

1¡¢PyPIÒÑÔÝÍ£ÐÂÓû§×¢²áºÍÐÂÏîÄ¿ÉÏ´«¹¦Ð§Ö±ÖÁÁíÐÐ֪ͨ


¾Ý5ÔÂ21ÈÕ±¨µÀ £¬PyPIÒÑÔÝÍ£ÁËÐÂÓû§×¢²áºÍÐÂÏîÄ¿ÉÏ´«¹¦Ð§ £¬Ö±ÖÁÁíÐÐ֪ͨ¡£PyPIÊÇ¿ªÔ´PythonÈí¼þ°üµÄ¹Ù·½µÚÈý·½×¢²áÖÐÐÄ £¬Î¬»¤ÈËԱѡÔñ½ûÓÃÉÏÊö¹¦Ð§ £¬ÊÇÒòΪËûÃǹýÈ¥Ò»Öܼì²âµ½´´½¨¶ñÒâÓû§ºÍÏîÄ¿µÄÊýÁ¿¼¤Ôö £¬Áè¼ÝÁËÆ估ʱÏìÓ¦µÄÄÜÁ¦¡£Í¨¸æ²¢Î´ÌṩÓйع¥»÷µÄÏêϸÐÅÏ¢ £¬ÀýÈç¹¥»÷ÕßµÄÉí·Ý¡¢¶¯»úÒÔ¼°¹¥»÷ÖÐʹÓõĶñÒâ´úÂë¡£½ñÄê2Ô £¬Ñо¿ÈËÔ±ÔøÔÚPyPI´æ´¢¿âÖмì²âµ½Áè¼Ý451¸ö°üÊÔͼÔÚ¿ª·¢ÕßµÄϵͳÉÏ°²×°clipper¶ñÒâÈí¼þ¡£


https://securityaffairs.com/146488/cyber-crime/pypi-repository-suspends-sign-ups-package-uploads.html


2¡¢MetaÒò½«Å·ÖÞÓû§Êý¾Ý´«»ØÃÀ¹ú±»Å·ÃË·£¿î13ÒÚÃÀÔª


¾ÝýÌå5ÔÂ22ÈÕ±¨µÀ £¬°®¶ûÀ¼Êý¾Ý±£»¤Î¯Ô±»á(DPC)³ÆMetaÎ¥·´ÁËGDPRµÚ46(1)Ìõ £¬¶ÔÆä´¦ÒÔ13ÒÚÃÀÔªµÄ·£¿î¡£¾ßÌåÀ´Ëµ £¬Facebook½«¸Ãƽ̨ŷÃËÓû§µÄÊý¾Ý´«»ØÁËÃÀ¹ú £¬¶øÃÀ¹úµÄÊý¾Ý±£»¤¹æÔòÒòÖݶøÒì £¬±»ÈÏΪ²»×ãÒÔ±£»¤Å·ÃËÊý¾ÝÖ÷ÌåµÄȨÀû¡£Òò´Ë £¬DPC¶ÔFacebookµÄĸ¹«Ë¾Meta Ireland·£¿î12ÒÚÅ·Ôª£¨13ÒÚÃÀÔª£© £¬²¢ÒªÇóÔÚÎå¸öÔÂÄÚÔÝÍ£ËùÓÐÎ¥·´GDPRµÄÊý¾Ý´«Êä¡£´ËÍâ £¬Meta»¹±»ÒªÇóÔÚÁù¸öÔÂÄÚÍ£Ö¹´¦Öûò³ÖÓдÓÅ·ÃË·Ç·¨´«Êäµ½ÃÀ¹úµÄËùÓÐÊý¾Ý¡£MetaÈÏΪ·£¿î²»¹«Õý¡¢²»ÐëÒªÇÒ²»Ïà³Æ £¬²¢¼Æ»®¶Ô¸Ã²Ã¾öÌá³öÉÏËß¡£ÕâÊÇ×ÔÅ·ÃËÓÚ2018Äê5ÔÂ25ÈÕͨ¹ýGDPRÒÔÀ´×î´ó½ð¶îµÄ·£¿î¡£


https://www.bleepingcomputer.com/news/technology/eu-slaps-meta-with-13-billion-fine-for-moving-data-to-us-servers/


3¡¢²¨À¼¶à¼ÒÐÂÎÅÍøÕ¾Ôâµ½DDoS¹¥»÷»òÓë¶íÂÞ˹ºÚ¿ÍÓйØ


¾Ý·͸Éç5ÔÂ18ÈÕ±¨µÀ £¬Êý¼Ò²¨À¼ÐÂÎÅÍøÕ¾Ôâµ½ÂþÑÜʽ¾Ü¾ø·þÎñ(DDoS)¹¥»÷ £¬Õþ¸®³ÆÕâ¿ÉÄÜÊǶíÂÞ˹µÄºÚ¿Í×éÖ¯ËùΪ¡£¾ÝPAP±¨µÀ £¬ÊÜÓ°ÏìµÄÍøÕ¾°üÂÞGazeta Wyborcza¡¢RzeczpospolitaºÍSuper ExpressµÈÈÕ±¨µÄÍøÕ¾¡£WyborczaÔÚTwitterÉÏÈ·ÈÏËüÔâµ½Á˹¥»÷ £¬ÐÂÎÅÍøÕ¾wPolityce.plÒ²ÊÇÈç´Ë¡£¶íÂÞ˹Íâ½»²¿Ã»ÓÐÁ¢¼´»Ø¸´ÖÃÆÀÇëÇó¡£


https://www.reuters.com/world/europe/polish-news-websites-hit-by-ddos-attacks-2023-05-18/


4¡¢Microsoft³Æ2019ÄêÖÁ2022Äê¼äBEC¹¥»÷»î¶¯Ôö¼Ó38%


MicrosoftÔÚ5ÔÂ19ÈÕÐû²¼Á˵ÚËİ桶ÍøÂçÐźš· £¬ Ç¿µ÷ÁËΧÈÆÆóÒµµç×ÓÓʼþÍ×Э(BEC)µÄ¹¥»÷»î¶¯¼¤Ôö¡£ÔÚ2019ÄêÖÁ2022Äê¼ä £¬Õë¶ÔÆóÒµµç×ÓÓʼþµÄÍøÂç·¸×ï¼´·þÎñ(CaaS)Ôö¼ÓÁË38%¡£2022Äê £¬FBI¶ÔÉæ¼°ÃÀ¹ú¹úÄÚ½»Ò×µÄ2838ÆðBEC»î¶¯½øÐÐÊÓ²ì £¬·¢ÏÖDZÔÚËðʧÁè¼Ý5.9ÒÚÃÀÔª¡£2022Äê4ÔÂÖÁ2023Äê4Ô £¬Î¢Èí·¢ÏÖ²¢ÊÓ²ìÁË3500Íò´ÎBECÆóͼ £¬Æ½¾ùÿÈÕ156000´Î¡£BEC¹¥»÷ÈÕÒæÅÓ´ó £¬Ñо¿ÈËÔ±ÊӲ쵽¹¥»÷ÕßʹÓÃBulletProftLinkµÈƽ̨µÄÇ÷ÊÆ¡£


https://www.microsoft.com/en-us/security/blog/2023/05/19/cyber-signals-shifting-tactics-fuel-surge-in-business-email-compromise/


5¡¢ÂÉËùBuckley King LPA±»BlackBasta¹¥»÷²¢Í¬Òâ½»Êê½ð


¾Ý5ÔÂ18ÈÕ±¨µÀ £¬ÂÉËùBuckley King LPAÔâµ½ÁËBlackBastaµÄÀÕË÷¹¥»÷¡£È¥Äê4Ô £¬BlackBastaͨ¹ýÉ繤¹¥»÷ÈëÇÖÁËÂÉËùµÄϵͳ £¬¾Ý³ÆÂÉËùµÄÒ»ÃûÔ±¹¤Ö´ÐÐÁËÓʼþÖеĶñÒ⸽¼þ¡£ºÚ¿ÍÍÅ»ïÔÚ̸ÅÐÖгÆ £¬ËûÃÇÇÔÈ¡ÁË110 GBµÄÎļþ £¬²¢ÒªÇó¸Ã¹«Ë¾½»400000ÃÀÔªµÄÊê½ð £¬À´É¾³ýÊý¾Ý¡¢»ñµÃ½âÃÜÆ÷ÒÔ¼°Äþ¾²³ÂËß¡£¾­¹ý¶à´Î̸Åкó £¬Buckley King LPAͬÒâÁË150000ÃÀÔªµÄÊê½ðÒªÇó¡£


https://www.databreaches.net/oh-buckley-king-law-firm-hit-by-blackbasta/


6¡¢Ñо¿ÈËÔ±¼ì²âµ½Á½¸öÄ£·ÂNodeJSµÄnpm°ü·Ö·¢TurkoRAT


5ÔÂ18ÈÕ £¬ReversingLabs·¢ÏÖÁ˶à¸öÒÔNodeJS¿âÃüÃûµÄnpm°ü £¬ËüÃÇÉõÖÁ´ò°üÁËÒ»¸öÀàËÆÓÚNodeJSµÄWindows¿ÉÖ´ÐÐÎļþ £¬µ«È´·Ö·¢Ä¾Âí¡£ÕâЩÈí¼þ°ü¼«¾ßÒþ±ÎÐÔÇÒ¼ì²âÂʼ«µÍ £¬ÔÚ±»·¢ÏÖ֮ǰÒѾ­ÓÚnpmÖÐDZ·üÁËÁ½¸ö¶àÔ¡£ÆäÖÐnodejs-encrypt-agent¿´ËÆÊÇÒ»¸öºÏ·¨°ü £¬µ«°üÂÞÒ»¸ö¶ñÒâPEÎļþlib.exe £¬»áÔËÐÐTurkoRAT¡£nodejs-cookie-proxy-agentÒ²»á°²×°Õâ¸öľÂí £¬µ«ËüûÓÐÖ±½Ó°üÂÞlib.exe £¬¶øÊǽ«axios-proxyÁÐΪһ¸öÒÀÀµÏî £¬ºóÕß°üÂÞÁ˶ñÒâµÄ¿ÉÖ´Ðз¨Ê½¡£Ä¿Ç° £¬ËùÓжñÒâ°ü¶¼Òѱ»´Ónpm×¢²á±íÖÐɾ³ý¡£


https://www.reversinglabs.com/blog/rats-found-hiding-in-the-npm-attic