¶íÂÞ˹ÎÀÐÇͨÐÅÉÌDozor-Teleport±»ºÚÔÝʱÎÞ·¨·ÃÎÊ

Ðû²¼Ê±¼ä 2023-07-04

1¡¢¶íÂÞ˹ÎÀÐÇͨÐÅÉÌDozor-Teleport±»ºÚÔÝʱÎÞ·¨·ÃÎÊ


¾ÝýÌå6ÔÂ30ÈÕ±¨µÀ£¬Ä³ºÚ¿ÍÍÅ»ïÉù³Æ¶Ô¶íÂÞ˹ÎÀÐÇͨÐÅÌṩÉÌDozor-TeleportÔâµ½µÄ¹¥»÷ÂôÁ¦¡£¸ÃÌṩÉÌΪÄÜÔ´¹«Ë¾ÒÔ¼°¸Ã¹úµÄ¹ú·ÀºÍÄþ¾²»ú¹¹ËùÓá£×ÔÃÀ¹ú¶«²¿Ê±¼äÉÏÖÜÈýÍíÉÏ10µãÒÔÀ´£¬¸Ã¹«Ë¾µÄÍøÂçÒ»Ö±´¦ÓÚÖжÏ״̬£¬ÍøÕ¾Ò²ÒѹرÕ¡£´ËÍ⣬DozorµÄĸ¹«Ë¾Amtel SvyazÒ²ÔÚÉÏÖÜÈýÍí¼ä·¢ÉúÁËÑÏÖصÄÖжÏ¡£´Ë´Î¹¥»÷±³ºóµÄ×éÖ¯Éù³ÆÓëWagner GroupÓйØ£¬µ«ºóÕߵĹٷ½TelegramÖÐûÓÐÌá¼°´Ë´Î¹¥»÷»î¶¯¡£ºÚ¿Í³ÆÈëÇÖÁ˲¿ÃÅÎÀÐÇÖնˣ¬ÇÔÈ¡ÁË·þÎñÆ÷ÉϵĻúÃÜÐÅÏ¢£¬²¢¹ûÈ»ÁË700¸öÎļþ£¬°üÂÞÎĵµºÍͼÏñ¡£


https://therecord.media/hackers-take-down-russian-satellite-provider


2¡¢ÃÀ¹úרÀûÉ̱ê¾ÖÅäÖôíÎóй¶Լ6Íò¸öÉêÇëÈ˵ÄÐÅÏ¢


¾Ý6ÔÂ28ÈÕ±¨µÀ£¬ÃÀ¹úרÀûÉ̱ê¾Ö (USPTO) й¶ÁËÔ¼61000¸öÉêÇëÈ˵ÄÐÅÏ¢¡£¸ÃÎÊÌâÊÇÔÚÒ»¸öAPIÖз¢Ïֵģ¬µ¼Ö´ÓÉêÇëÈËÄÇÀïÊÕ¼¯µÄµØÖ·ÐÅϢй¶¡£¾ÝϤ£¬´Ë´Îй¶Ê¼þÓ°ÏìÁË2020Äê2ÔÂÖÁ2023Äê3ÔÂÌá½»µÄÔ¼3%µÄÉêÇëÈË¡£USPTO³Æ£¬ËûÃÇ·¢ÏÖÕâ¸öÎÊÌâºó£¬Á¢¼´×èÖ¹Á˶ÔËùÓÐUSPTO·ÇÒªº¦APIµÄ·ÃÎÊ£¬²¢Ï¼ÜÁËÊÜÓ°ÏìµÄÅúÁ¿Êý¾Ý²úÎֱµ½¿ÉÒÔÓÀ¾ÃÐÞ¸´¡£


https://techcrunch.com/2023/06/28/uspto-trademark-data-api-leak/


3¡¢Akamai¼ì²âµ½ÀûÓÃSSH·þÎñÆ÷µÄÐÂÊðÀí½Ù³Ö¹¥»÷»î¶¯


AkamaiÔÚ6ÔÂ29ÈÕ³ÆÆä¼ì²âµ½Ò»¸öÊðÀí½Ù³Ö»î¶¯£¬Ö÷ÒªÕë¶ÔÒ×Êܹ¥»÷µÄSSH·þÎñÆ÷¡£AkamaiÓÚ6ÔÂ8ÈÕÊ״η¢ÏÖÕâЩ¹¥»÷¡£Ò»µ©Á¬½Óµ½SSH·þÎñÆ÷£¬¹¥»÷Õ߾ͻᰲװһ¸öBase64±àÂëµÄBash½Å±¾£¬½«±»¹¥»÷µÄϵͳÌí¼Óµ½HoneygainºÍPeer2ProfitµÈP2PÊðÀíÍøÂçÖС£´ËÍ⣬Ëü»¹»áËÑË÷²¢ÖÕÖ¹ÔËÐдø¿í¹²Ïí·¨Ê½µÄ¾ºÕùʵÀý£¬È»ºóÆô¶¯Docker·þÎñ£¬ÀûÓÃÄ¿±êµÄ´ø¿í»ñÈ¡ÀûÈ󡣶ÔÍøÂç·þÎñÆ÷µÄ½øÒ»²½·ÖÎö·¢ÏÖ£¬Ëü»¹±»ÓÃÀ´ÍйܼÓÃÜ»õ±ÒÍÚ¿ó·¨Ê½£¬Õâ±íÃ÷¹¥»÷ÕßÕýÔÚÉæ×ã¼ÓÃܽٳֺÍÊðÀí½Ù³Ö¹¥»÷¡£


https://www.akamai.com/blog/security-research/proxyjacking-new-campaign-cybercriminal-side-hustle


4¡¢Ñо¿ÈËÔ±³Æ½öÐè6´ÎʵÑé¾Í¿ÉÈƹýÓïÒôÉí·ÝÑéÖ¤


ýÌå6ÔÂ30Èճƣ¬»¬Ìú¬´óѧµÄÑо¿ÈËÔ±·¢ÏÖÁËÒ»ÖÖ¿ÉÒÔÈƹýÓïÒôÉí·ÝÑéÖ¤µÄ¼¼Êõ£¬²¢ÌåÏÖÖ»ÐèÁù´ÎʵÑéÀÖ³ÉÂʾ͸ߴï99%¡£Ñо¿ÈËԱȷ¶¨ÁËdeepfakeÒôƵÖбíÃ÷ËüÊÇÓɼÆËã»úÉú³ÉµÄ±êÖ¾£¬²¢¿ª·¢ÁËÒ»¸ö·¨Ê½À´É¾³ýÕâЩ±êÖ¾£¬Ê¹ÆäÓëÕæʵÒôƵÎÞ·¨Çø·Ö¡£ÔÚÕë¶ÔAmazon ConnectÓïÒôÉí·ÝÑé֤ϵͳµÄ²âÊÔÖУ¬Ñо¿ÈËÔ±ÔÚ4ÃëµÄ¹¥»÷ÖÐÈ¡µÃÁË10%µÄÀÖ³ÉÂÊ£¬ÔÚʵÑé6´ÎºóÀÖ³ÉÂʸߴï99%¡£


https://www.malwarebytes.com/blog/news/2023/06/new-technique-can-defeat-voice-authentication-in-just-6-attempts


5¡¢AhnLab³ÆÀÕË÷ÍÅ»ïCrysisͨ¹ýRDP°²×°VenusÀÕË÷Èí¼þ


7ÔÂ3ÈÕ±¨µÀ³Æ£¬AhnLab½üÆÚ·¢ÏÖÀÕË÷ÍÅ»ïCrysisÔÚ¹¥»÷ÖÐҲʹÓÃÁËVenusÀÕË÷Èí¼þ¡£CrysisºÍVenus¶¼ÊÇÕë¶Ô̻¶µÄÔ¶³Ì×ÀÃæ·þÎñµÄÖ÷ÒªÀÕË÷Èí¼þ¡£¹¥»÷Õß¿ÉÄÜʹÓÃRDP×÷Ϊ¹¥»÷ý½é£¬ÏÈʵÑéʹÓÃCrysis¼ÓÃÜϵͳ£¬ÔÚʧ°Üºó£¬ÔÙ´ÎʵÑéʹÓÃVenus½øÐмÓÃÜ¡£³ýÁËÁ½¸öÀÕË÷Èí¼þÖ®Í⣬¹¥»÷Õß»¹°²×°ÁËÖÖÖÖÆäËü¹¤¾ß£¬ÀýÈç¶Ë¿ÚɨÃèÆ÷ºÍMimikatz¡£ÒòΪ¹¥»÷ÕßÔÚ³õʼÈëÇֺͺáÏòÒƶ¯ÖÐһֱʹÓÃRDP£¬½¨ÒéÓû§ÔÚ²»Ê¹ÓÃʱͣÓÃRDP£¬»òʹÓÃÅÓ´óµÄÕË»§ÃÜÂë²¢¶¨ÆÚ¸ü¸Ä£¬À´·ÀÓù´ËÀ๥»÷¡£


https://asec.ahnlab.com/en/54937/


6¡¢SekoiaÐû²¼¹ØÓÚDDoS¹¥»÷¹¤¾ß°üDDoSiaµÄ·ÖÎö³ÂËß


6ÔÂ29ÈÕ£¬SekoiaÐû²¼¹ØÓÚDDoSiaÏîÄ¿µÄ·ÖÎö³ÂËß¡£DDoSiaÊÇÒ»¸öDDoS¹¥»÷¹¤¾ß°ü£¬ÓÉÓë¶íÂÞ˹Ïà¹ØµÄ×éÖ¯NoName057(16)¿ª·¢ºÍʹÓá£DDoSiaÏîÄ¿ÓÚ2022Äê³õÔÚTelegramÉÏÆô¶¯£¬½ØÖÁ½ñÄê6Ô£¬Æä³ÉÔ±Áè¼Ý10000ÈË¡£SekoiaÊÕ¼¯ÁËDDoSiaµÄC2ÔÚ5ÔÂ8ÈÕÖÁ6ÔÂ26ÈÕ·¢Ë͵ÄһЩµÄÊý¾Ý£¬·¢ÏÖÖ÷ÒªÕë¶ÔÁ¢ÌÕÍð¡¢ÎÚ¿ËÀ¼ºÍ²¨À¼£¬Õ¼×ܻµÄ39%¡£ÔÚ´ËÆڼ䣬DDoSia×ܹ²¹¥»÷ÁË486¸öÍøÕ¾¡£


https://blog.sekoia.io/following-noname05716-ddosia-projects-targets/