Microsoft 365Ôٴη¢Éú·þÎñÖжÏÖ÷ÒªÓ°ÏìÅ·ÃÀµØÓò

Ðû²¼Ê±¼ä 2023-05-24

1¡¢Microsoft 365Ôٴη¢Éú·þÎñÖжÏÖ÷ÒªÓ°ÏìÅ·ÃÀµØÓò


¾ÝýÌå5ÔÂ22ÈÕ±¨µÀ£¬MicrosoftÕýÔÚÊÓ²ìÓû§ÎÞ·¨·ÃÎÊÆäMicrosoft 365ÕÊ»§ºÍÒÑ°²×°Ó¦Ó÷¨Ê½µÄÎÊÌâ¡£ÊÜÓ°ÏìµÄ¿Í»§³ÆÔÚ·ÃÎÊOutlookÓÊÏäʱÓöµ½ÎÊÌ⣬¶øÇÒÎÞ·¨Á¬½Óµ½Microsoft 365·þÎñÆ÷¡£¸Ã¹«Ë¾ÔÚͨ¸æÖÐÌåÏÖ£¬Ö÷Ó°ÏìÁ˱±ÃÀ¡¢²¨À¼ºÍÓ¢¹úµÄÓû§£¬µ«ÆäËüµØÓòµÄÓû§Ò²¿ÉÄÜÊܵ½Ó°Ï졣Ŀǰ£¬ÎÊÌâÒѾ­µÃµ½Á˽â¾ö¡£ÉϸöÔ£¬ÁíÒ»ÆðMicrosoft 365·þÎñÖжÏʼþµ¼Ö±±ÃÀÓû§ÎÞ·¨·ÃÎÊExchange Online¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-365-hit-by-new-outage-causing-connectivity-issues/


2¡¢µÂ¹ú¾ü»ð¹«Ë¾RheinmetallÔâµ½Black BastaµÄ¹¥»÷


¾Ý5ÔÂ23ÈÕ±¨µÀ£¬µÂ¹úÆû³µºÍÎäÆ÷ÖÆÔìÉÌRheinmetall AG³Æ£¬ËüÔâµ½ÁËBlackBastaµÄÀÕË÷¹¥»÷£¬ÃñÓÃÒµÎñÊܵ½Ó°Ïì¡£5ÔÂ20ÈÕ£¬BlackBastaÔÚÆäÍøÕ¾Ðû²¼ÁË´ÓRheinmetallÇÔÈ¡µÄÊý¾ÝÑù±¾£¬ÆäÖаüÂÞ±£ÃÜЭÒé¡¢¼¼ÊõʾÒâͼ¡¢»¤ÕÕɨÃè¼þºÍ²É¹º¶©µ¥µÈ¡£¸Ã¹«Ë¾Í¸Â¶£¬ËûÃÇÔÚ4ÔÂ14ÈÕ·¢ÏÖ¹¥»÷»î¶¯£¬ÓÉÓÚ¼¯ÍÅÄÚ²¿µÄIT»ù´¡ÉèÊ©ÊÇÑϸñÊèÉ¢µÄ£¬Òò´ËÆä¾üÊÂÒµÎñδÊܵ½´Ë´Î¹¥»÷µÄÓ°Ïì¡£


https://therecord.media/rheinmetall-confirms-black-basta-ransomware-group-behind-cyberattack


3¡¢½¡¿µ±£ÏÕ¹«Ë¾Point32HealthÔâµ½ÀÕË÷¹¥»÷»¼ÕßÐÅϢй¶


ýÌå5ÔÂ23Èճƣ¬½¡¿µ±£ÏÕ¹«Ë¾Point32HealthÕýÔÚ֪ͨ»¼ÕßËûÃǵÄÐÅÏ¢¿ÉÄÜÒÑй¶¡£Point32HealthÊÇTufts Health PlanºÍHarvard Pilgrim Health Careĸ¹«Ë¾£¬¹¥»÷ÕßÔÚ3ÔÂ28ÈÕÖÁ4ÔÂ17ÈÕÆڼ䣬´ÓHarvard PilgrimµÄϵͳÖи´ÖƲ¢ÇÔÈ¡ÁËÊý¾Ý¡£Ä¿Ç°ÊÓ²ìÈÔÔÚ½øÐÐÖУ¬Éв»È·¶¨Óм¸¶àÈËÊܵ½Ó°Ï죬µ«¿ÉÄÜ»áÓ°Ïì´Ó2012Äê3ÔÂ28ÈÕÖÁ½ñ×¢²áµÄÓû§¡£±£ÏÕ¹«Ë¾µÄ·¢ÑÔÈËûÓÐ͸¶ÊÇ·ñ½»ÁËÊê½ð¡£


https://www.databreaches.net/after-ransomware-attack-states-second-largest-health-insurer-says-patient-data-were-stolen/


4¡¢Trend MicroÅû¶BlackCat½üÆÚ¹¥»÷ÖÐÈƹý¼ì²âµÄÒªÁì


5ÔÂ22ÈÕ£¬Trend MicroÅû¶ÁËBlackCatÔÚ½üÆڵĹ¥»÷ÖÐʹÓÃÇ©ÃûµÄWindowsÄÚºËÇý¶¯·¨Ê½À´Èƹý¼ì²âµÄÒªÁì¡£¸ÃÇý¶¯·¨Ê½ÊÇÈ¥ÄêÄêµ×Åû¶µÄ¶ñÒâÈí¼þPOORTRYµÄ¸ïа汾¡£¹¥»÷ÕßÊ×ÏÈÊÔͼʹÓÃMicrosoft Ç©ÃûµÄPOORTRYÇý¶¯·¨Ê½£¬µ«ÆäÇ©Ãû±»È¡Ïûºó¼ì²âÂʺܸß¡£Òò´Ë£¬¹¥»÷ÕßʹÓÃÁËÒ»¸öPOORTRYÄÚºËÇý¶¯µÄ¸ïа汾£¬²¢Ê¹Óñ»µÁ»òй¶µÄ½»²æÇ©ÃûÖ¤Êé½øÐÐÇ©Ãû¡£´ËÍ⣬¸ÃÇý¶¯·¨Ê½Ê¹ÓÃSafengine Protector v2.4.0.0¹¤¾ß½øÐлìÏýÒÔÈƹý¾²Ì¬·ÖÎö¡£


https://www.trendmicro.com/en_us/research/23/e/blackcat-ransomware-deploys-new-signed-kernel-driver.html


5¡¢Fortinet·¢ÏÖÕë¶ÔÖж«µÄÐÂÄÚºËÇý¶¯·¨Ê½WINTAPIX


FortinetÔÚ5ÔÂ22ÈÕ³ÆÆä·¢ÏÖÁËÕë¶ÔÖж«¹ú¼ÒµÄÐÂÄÚºËÇý¶¯·¨Ê½WINTAPIX(WinTapix.sys)¡£Ò£²âÊý¾Ý±íÃ÷£¬¸Ã»î¶¯Ö÷ÒªÕë¶ÔɳÌØ°¢À­²®¡¢Ô¼µ©¡¢¿¨Ëþ¶ûºÍ°¢À­²®ÁªºÏÇõ³¤¹ú¡£WinTapix.sys±¾ÖÊÉÏÊÇÒ»¸ö¼ÓÔØ·¨Ê½£¬Ö÷ҪĿµÄÊÇÉú³ÉºÍÖ´ÐÐÏÂÒ»½×¶ÎµÄ¹¥»÷¡£Ò»µ©±»¼ÓÔص½ÄÚºËÖУ¬WinTapix.sys¾Í»á½«Ç¶Èëʽshellcode×¢Èëµ½Êʵ±µÄÓû§Ä£Ê½½ø³ÌÖУ¬¶ø¸Ã½ø³ÌÓÖ»áÖ´ÐмÓÃܵÄ.NET payload¡£.NET¶ñÒâÈí¼þ¾ßÓкóÃźÍÊðÀí¹¦Ð§£¬¿ÉÒÔÖ´ÐÐÃüÁϺÍÉÏ´«Îļþ£¬ÒÔ¼°³äµ±ÊðÀíÔÚÁ½¸öͨÐŶ˵ãÖ®¼äͨ±¨Êý¾Ý¡£


https://www.fortinet.com/blog/threat-research/wintapix-kernal-driver-middle-east-countries


6¡¢Ñо¿ÍŶӳÆGUI-vilÍÅ»ïÀûÓÃAWS EC2ʵÀýÀ´ÍÚ¿ó


5ÔÂ22ÈÕ£¬Permiso P0 Labs³ÆÓ¡¶ÈÄáÎ÷ÑǺڿÍÍÅ»ïGUI-vilÀûÓÃAWS EC2ʵÀýÀ´Íڿ󡣸Ã×éÖ¯ÓÚ2021Äê11ÔÂÊ״α»¼ì²âµ½£¬×î½üÒ»´ÎµÄ»î¶¯·¢ÉúÔÚ½ñÄê4Ô·Ý¡£¸ÃÍÅ»ïÆ«ºÃʹÓÃͼÐÎÓû§½çÃæ(GUI) ¹¤¾ß£¬ÌرðÊǽϾɰ汾µÄS3ä¯ÀÀÆ÷¡£GUI-vilÊ×ÏÈËÑË÷̻¶µÄAWSÃÜÔ¿ºÍɨÃè´æÔÚ©¶´£¨ÈçCVE-2021-22205£©µÄGitLabʵÀý£¬À´»ñµÃ³õʼ·ÃÎÊȨÏÞ¡£ÀÖ³ÉÈëÇÖºóÊÇȨÏÞÌáÉýºÍÄÚ²¿Õì²ì£¬ÆäÖ÷ÒªÈÎÎñÊÇ´´½¨EC2ʵÀý£¬ÒÔ½øÐмÓÃÜ»õ±ÒÍÚ¿ó»î¶¯¡£


https://permiso.io/blog/s/unmasking-guivil-new-cloud-threat-actor/