ÈÕ±¾SeikoÔâµ½BlackCat¹¥»÷Éè¼ÆÍ¼µÈÊý¾Ý¿ÉÄÜй¶

Ðû²¼Ê±¼ä 2023-08-23

1¡¢ÈÕ±¾SeikoÔâµ½BlackCat¹¥»÷Éè¼ÆÍ¼µÈÊý¾Ý¿ÉÄÜй¶


¾ÝýÌå8ÔÂ21ÈÕ±¨µÀ £¬ÀÕË÷ÍÅ»ïBlackCatÉù³Æ¶ÔÈÕ±¾ÖÓ±íÖÆÔìÉ̾«¹¤£¨Seiko£©Ôâµ½µÄ¹¥»÷ÂôÁ¦¡£SeikoÊÇÊÀ½çÉÏ×î´óÇÒÀúÊ·×îÓÆ¾ÃµÄÖÆ±íÉÌÖ®Ò» £¬ÄêÊÕÈëÁè¼Ý16ÒÚÃÀÔª¡£¸Ã¹«Ë¾ÔÚ8ÔÂ10ÈÕ͸¶ £¬Î´¾­ÊÚȨµÄµÚÈý·½·ÃÎÊÆä»ù´¡ÉèÊ©²¢¿ÉÄÜÇÔÈ¡ÁËÊý¾Ý¡£21ÈÕ £¬BlackCat³Æ¶Ô´ËÊÂÂôÁ¦ £¬ÌåÏÖSeikoµÄÍøÂçºÍ²úÎïµÄÄþ¾²ÐԽϵÍ¡£¹¥»÷Õßй¶ÁËÉú²ú¼Æ»®¡¢Ô±¹¤»¤ÕÕ¡¢ÐÂÐͺÅÐû²¼¼Æ»®ºÍʵÑéÊÒ²âÊÔ½á¹ûµÈÄÚÈÝ £¬Ñù±¾»¹°üÂÞ¼¼ÊõÔ­ÀíͼºÍ¾«¹¤ÊÖ±íÉè¼ÆÍ¼Ö½¡£Éв»Çå³þºÚ¿ÍÊÇ·ñÇÔÈ¡Á˹«Ë¾»úÃÜ»òרÀûµÈ֪ʶ²úȨ¡£


https://securityaffairs.com/149734/cyber-crime/blackcat-alphv-ransomware-group-seiko.html


2¡¢Ñо¿ÈËÔ±·¢ÏÖ¿Éͨ¹ýTP-LinkÖÇÄܵÆÅÝÇÔÈ¡WiFiÃÜÂë


ýÌå8ÔÂ21ÈÕ±¨µÀ³Æ £¬Ñо¿ÈËÔ±ÔÚTP-Link Tapo L530EÖÇÄܵÆÅݺÍTP-Link TapoÓ¦Ó÷¨Ê½Öз¢ÏÖÁË4¸ö©¶´¡£µÚÒ»¸ö©¶´Éæ¼°Tapo L503EÉí·ÝÑéÖ¤²»Í× £¬¿ÉÔڻỰÃÜÔ¿½»»»²½ÖèÖÐð³äÉ豸¡£µÚ¶þ¸ö©¶´¿Éͨ¹ý±©Á¦ÆÆ½â»ò·´±àÒëTapoÓ¦Ó÷¨Ê½À´»ñÈ¡¸ÃÃÜÔ¿¡£µÚÈý¸ö©¶´Éæ¼°¶Ô³Æ¼ÓÃܹý³ÌÖÐȱ·¦Ëæ»úÐÔ £¬µÚËĸö©¶´¿ÉÓÃÓÚÖØ·ÅÏûÏ¢¡£¹¥»÷Õß¿ÉÀûÓõÚÒ»¸öºÍµÚ¶þ¸ö©¶´Ã°³äµÆÅݲ¢¼ìË÷TapoÕÊ»§ÏêϸÐÅÏ¢ £¬È»ºóͨ¹ý·ÃÎÊTapoÓ¦Óà £¬¿ÉÒÔÌáȡĿ±êµÄWiFi SSIDºÍÃÜÂë £¬²¢·ÃÎÊÁ¬½Óµ½¸ÃÍøÂçµÄÆäËüÉ豸¡£¹©Ó¦ÉÌÌåÏÖ½«ºÜ¿ì¶ÔÓ¦Óú͵ÆÅݹ̼þ½øÐÐÐÞ¸´¡£


https://www.bleepingcomputer.com/news/security/tp-link-smart-bulbs-can-let-hackers-steal-your-wifi-password/


3¡¢MFAÌṩÉÌDuo·þÎñÖжϵ¼ÖÂAzure AuthÉí·ÝÑéÖ¤´íÎó

 

¾Ý8ÔÂ21ÈÕ±¨µÀ £¬CiscoÆìϵÄMFAÌṩÉÌDuo Security·þÎñÖжÏÊýСʱ £¬µ¼ÖÂAzure AuthÉí·ÝÑéÖ¤´íÎó¡£ÊµÑéʹÓÃDuoµÇ¼ʱ»á·ºÆð¡°ÏµÍ³¸ºÔعýÖØ £¬ÇëÉԵȼ¸·ÖÖÓ £¬È»ºóÖØÊÔ¡±µÄÌáʾ¡£Æ¾¾Ý¸Ã¹«Ë¾µÄ×´Ì¬Ò³Ãæ £¬DuoµÄSSOºÍÍÆËÍ·þÎñÊܵ½´Ë¹ÊÕϵÄÓ°Ïì £¬ÆäºËÐÄÉí·ÝÑéÖ¤·þÎñʹÓõÄHTTPS£¨TCP/443£©ºÍLDAP(S)£¨TCP/389£©¶Ëµã½öÊܵ½²¿ÃÅÖжϵÄÓ°Ïì¡£½ØÖÁ21ÈÕ18:01 £¬ÔÚÖжϽü9¸öСʱºó £¬DuoÌåÏÖÉí·ÝÑé֤ʧ°ÜµÄ»ù´¡ÎÊÌâÒѾ­½â¾ö¡£

https://www.bleepingcomputer.com/news/technology/ongoing-duo-outage-causes-azure-auth-authentication-errors/


4¡¢·¨¹úÈøÌØÂ³Î¬¶ûÊÐÔâµ½MedusaµÄ¹¥»÷ĿǰÈÔÔÚ»Ö¸´ÖÐ

 

ýÌå8ÔÂ22ÈÕ³Æ £¬·¨¹úÈøÌØÂ³Î¬¶ûÊÐÕý´ÓÉÏÖܵÄÍøÂç¹¥»÷ÖÐÖð²½»Ö¸´¡£¹¥»÷·¢ÉúÓÚ8ÔÂ17ÈÕ £¬Õë¶ÔÊÐÕþÌüµÄ²¿ÃÅ·þÎñÆ÷¡£¸ÃÊÐûÓÐ˵Ã÷ÊÇ·ñÊÇÀÕË÷¹¥»÷ £¬µ«ÌåÏÖËûÃǵı¸·ÝϵͳʹÆäÄܹ»¼Ó¿ì»Ö¸´¹ý³Ì¡£Medusa³Æ¶Ô´Ë´Î¹¥»÷ÂôÁ¦ £¬²¢Í¸Â¶Æä»ñµÃÁ˸ÃÊеIJÆÕþÐÅÏ¢¡¢Ô¤Ëã¡¢ÒøÐÐÏêϸÐÅÏ¢¡¢Ò½ÁƼǼºÍµ±µØÑ§Ð£µÄÊý¾Ý¡£×îÏȱ¨µÀÕâһʼþµÄLe ParisienҲ֤ʵ £¬ÊÐÕþÔ±¹¤ÔÚËûÃǵÄϵͳÉÏ·¢ÏÖÁËMedusaÀÕË÷Èí¼þ¡£


https://therecord.media/french-town-hit-by-cyberattack


5¡¢¶ò¹Ï¶à¶û¹ú¼ÒÑ¡¾Ù»ú¹¹±»¹¥»÷µ¼ÖÂÔÚÏßͶƱ·ºÆðÎÊÌâ


¾Ý8ÔÂ21ÈÕ±¨µÀ £¬¶ò¹Ï¶à¶û¹ú¼ÒÑ¡¾Ù»ú¹¹±»¹¥»÷ £¬µ¼ÖÂסÔÚ¹úÍâµÄ¹«ÃñÔÚÈ«¹úÑ¡¾ÙÖÐÎÞ·¨Í¶Æ±¡£¶ò¹Ï¶à¶ûÔÚÉÏÖÜÈÕ¾ÙÐÐÁËÈ«¹úÑ¡¾Ù £¬Í¶Æ±µ±Ìì £¬È±Ï¯Ñ¡ÃñÓ¿ÈëÉ罻ýÌåÆ½Ì¨ £¬ÌåÏÖËûÃÇÎÞ·¨Í¨¹ýÕþ¸®¿ª·¢µÄÔÚÏßϵͳͶƱ¡£È«¹úÑ¡¾ÙίԱ»áÖ÷ϯ½«¸ÃÎÊÌâ¹é¾ÌÓÚÍøÂç¹¥»÷ £¬µ«Ã»ÓÐ͸¶¹¥»÷µÄÐÔÖÊ¡£»¹ÌåÏÖ £¬Ô¶³ÌÐÅÏ¢´¦ÖÃͶƱƽ̨Ôâµ½ÁËÀ´×ÔÓ¡¶È¡¢ÃϼÓÀ­¹úºÍ°Í»ù˹̹µÈ7¸ö¹ú¼ÒµÄ¹¥»÷ £¬Å·ÖÞÑ¡ÃñÊܵ½µÄÓ°ÏìÓÈΪÑÏÖØ¡£


https://therecord.media/ecuador-election-cyberattacks-absen


6¡¢SentinelOneÐû²¼XLoaderµÄmacOSбäÌåµÄ·ÖÎö³ÂËß


8ÔÂ21ÈÕ £¬SentinelOneÐû²¼Á˹ØÓÚXLoaderµÄmacOSбäÌåµÄ·ÖÎö³ÂËß¡£XLoaderÊÇÒ»ÖÖMaaSÇÔÈ¡·¨Ê½ºÍ½©Ê¬ÍøÂç £¬×Ô2015ÄêÒÔÀ´Ò»Ö±´æÔÚ¡£Ð°汾µÄXLoaderαװ³É°ì¹«Éú²úÁ¦Ó¦ÓÃOfficeNote £¬À¦°óÔÚApple´ÅÅ̾µÏñOfficeNote.dmgÖÐ £¬Ê¹ÓÃÁËApple¿ª·¢ÈËÔ±µÄÇ©Ãû¡£Ç©ÃûÓÚ7ÔÂ17ÈÕÇ©Ê𠣬ºóÀ´±»AppleÈ¡Ïû¡£Ô­À´µÄmacOS±äÌåÐèÒªJavaÔËÐÐʱ»·¾³ £¬µ«AppleÊ®¶àÄêǰ¾ÍÍ£Ö¹ÔÚMacÉÏÌṩJRE £¬Òò´Ëа汾Çл»µ½ÁËCºÍObjective CÀ´Ó¦¶Ô´ËÏÞÖÆ¡£


https://www.sentinelone.com/blog/xloaders-latest-trick-new-macos-variant-disguised-as-signed-officenote-app/