Íйܹ«Ë¾CloudNordicÔâÀÕË÷¹¥»÷ËùÓпͻ§Êý¾Ý¶ªÊ§
Ðû²¼Ê±¼ä 2023-08-241¡¢Íйܹ«Ë¾CloudNordicÔâÀÕË÷¹¥»÷ËùÓпͻ§Êý¾Ý¶ªÊ§
¾Ý8ÔÂ23ÈÕ±¨µÀ£¬µ¤ÂóÍйܹ«Ë¾CloudNordicºÍAzeroCloudÔâµ½ÀÕË÷¹¥»÷£¬´ó²¿Ãſͻ§µÄÊý¾Ý¶ªÊ§¡£ÕâÁ½¸öÆ·ÅÆÊôÓÚͬһ¼Ò¹«Ë¾£¬¹¥»÷·¢ÉúÔÚ8ÔÂ18ÈÕÁ賿¡£¸Ã¹«Ë¾³ÎÇå²»»áÏò¹¥»÷Õß½»Êê½ð£¬µ«²»ÐÒµÄÊÇ£¬ÏµÍ³ºÍÊý¾Ý»Ö¸´¹ý³Ì²¢²»Ë³Àû£¬CloudNordic¶ªÊ§ÁË´ó¶àÊý¿Í»§µÄËùÓÐÊý¾Ý¡£¾ÝϤ£¬Õâ´Î¹¥»÷½ö¼ÓÃÜÁËÊý¾Ý£¬Ã»ÓÐÈκÎÊý¾Ý±»·ÃÎÊ»òй¶¡£´Ë´Î¹¥»÷Ó°ÏìÁËÊý°Ù¼Òµ¤ÂóµÄ¹«Ë¾£¬ËûÃǶªÊ§ÁË´æ´¢ÔÚÔÆÖеÄËùÓÐÄÚÈÝ£¬°üÂÞÍøÕ¾¡¢µç×ÓÓʼþºÍÎĵµµÈ¡£Ä¿Ç°£¬¸Ã¹«Ë¾µÄÔËÓªÈÔ´æÔںܴóÎÊÌâ¡£
https://www.bleepingcomputer.com/news/security/hosting-firm-says-it-lost-all-customer-data-after-ransomware-attack/
2¡¢DuoLingo 260ÍòÓû§µÄÊý¾ÝÔÚBreachedÂÛ̳¹ûÈ»
¾ÝýÌå8ÔÂ22ÈÕ±¨µÀ£¬260ÍòDuoLingoÓû§µÄÊý¾ÝÔÚºÚ¿ÍÂÛ̳BreachedÉÏй¶¡£1Ô·ݣ¬ÓÐÈËÔøÔÚÒѹرյÄBreachedÉÏÒÔ1500ÃÀÔªµÄ¼Û¸ñ³öÊÛ260ÍòDuoLingoÓû§µÄÊý¾Ý£¬ÆäÖаüÂ޵ǼÃû¡¢ÕæÊµÐÕÃû¡¢ÓʼþµØÖ·ºÍDuoLingo·þÎñÏà¹ØµÄÄÚ²¿ÐÅÏ¢µÈ·Ç¹ûÈ»ÐÅÏ¢¡£8ÔÂ21ÈÕ£¬260ÍòÓû§Êý¾ÝÓÖ±»¹ûÈ»ÔÚаæBreachedÉÏ£¬½öÐè8¸öÕ¾µã»ý·Ö£¬¼ÛֵΪ2.13ÃÀÔª¡£ÕâЩÊý¾ÝÊÇͨ¹ýAPIץȡµÄ£¬¸Ã½Ó¿ÚÖÁÉÙ×Ô3ÔÂÆð¾ÍÒѹûÈ»¡£
https://www.bleepingcomputer.com/news/security/scraped-data-of-26-million-duolingo-users-released-on-hacking-forum/
3¡¢ÃÀ¹ú¹ú·À¹«Ë¾BelcanÅäÖôíÎ󳬼¶¹ÜÀíԱƾ¾Ýй¶
ýÌå8ÔÂ23Èճƣ¬ÃÀ¹úÕþ¸®ºÍ¹ú·À³Ð°üÉÌBelcanµÄ³¬¼¶¹ÜÀíԱƾ¾Ýй¶¡£5ÔÂ15ÈÕ£¬Ñо¿ÍŶӷ¢ÏÖÁËÒ»¸ö¿ª·ÅµÄKibanaʵÀý£¬Éæ¼°Belcan¼°ÆäÔ±¹¤ºÍ»ù´¡ÉèÊ©µÄÃô¸ÐÐÅÏ¢¡£Ð¹Â¶ÐÅÏ¢°üÂÞ¹ÜÀíÔ±µç×ÓÓʼþ¡¢¹ÜÀíÔ±ÃÜÂ루ʹÓÃbcrypt´¦Öã©¡¢¹ÜÀíÔ±Óû§Ãû¡¢¹ÜÀíÔ±½ÇÉ«ºÍÄÚ²¿ÍøÂçµØÖ·µÈ¡£ÕâЩÐÅÏ¢¿ÉÓÃÀ´Ê¶±ð´æÔÚ©¶´µÄÒ×±»¹¥»÷ϵͳ£¬²¢Ìṩ½Ï¸ßȨÏÞµÄÕÊ»§Æ¾¾Ý£¬½«¸øÕû¸ö¹©Ó¦Á´´øÀ´·çÏÕ¡£Ä¿Ç°£¬¸ÃÎÊÌâÒѱ»½â¾ö¡£
https://cybernews.com/security/belcan-leaks-admin-password-flaws/
4¡¢SnatchÉù³ÆÒÑÈëÇÖÄϷǹú·À²¿²¢»ñÈ¡1.6 TBµÄÊý¾Ý
8ÔÂ22ÈÕ±¨µÀ³Æ£¬ÀÕË÷ÍÅ»ïSnatch½«ÄϷǹú·À²¿Ìí¼Óµ½ÆäÊý¾ÝÐ¹Â¶ÍøÕ¾¡£¸ÃÍÅ»ïÉù³ÆÇÔÈ¡Á˾üʺÏͬ¡¢ÄÚ²¿ºôºÅºÍ¸öÈËÐÅÏ¢µÈ£¬×ܼÆ1.6TBÊý¾Ý¡£Èç¹û´Ë´Î¹¥»÷µÃµ½Ö¤Êµ£¬»úÃÜÐÅÏ¢µÄй¶½«¶Ô¼ÓÈëËùͬµÄ×éÖ¯×é³ÉÑÏÖØ·çÏÕ¡£½ØÖÁĿǰ£¬¸ÃÊý¾ÝÐ¹Â¶ÍøÕ¾ÒÑÎÞ·¨·ÃÎÊ¡£2022Äê10Ô£¬SnatchÔøÉù³ÆÈëÇÖÁË·¨¹úHENSOLDT France£¬ÕâÊÇÒ»¼ÒרÃÅ´Óʾüʺ͹ú·Àµç×Ó²úÎïµÄ¹«Ë¾¡£
https://securityaffairs.com/149760/cyber-crime/snatch-ransomware-department-of-defence-south-africa.html
5¡¢SymantecÅû¶CarderbeeÕë¶ÔÖйúÏã¸ÛµÄ¹¥»÷»î¶¯
8ÔÂ22ÈÕ£¬SymantecÅû¶ÁËCarderbeeÕë¶ÔÖйúÏã¸ÛµÄ¹¥»÷»î¶¯¡£Ñо¿ÈËÔ±ÓÚ4Ô·¢ÏÖÁËCarderbeeµÄµÚÒ»¸ö»î¶¯¼£Ï󣬵«¹¥»÷»î¶¯»ò¿ÉÒÔ×·Ëݵ½2021Äê9Ô¡£¹¥»÷ÕßʹÓúϷ¨µÄCobra DocGuardÈí¼þÖ´Ðй©Ó¦Á´¹¥»÷£¬Ä¿µÄÊÇÔÚÄ¿±ê¼ÆËã»úÉϰ²×°ºóÃÅKorplug£¨ÓÖÃûPlugX£©¡£¹¥»÷»î¶¯»¹Ê¹ÓÃÁ˺Ϸ¨µÄMicrosoftÖ¤ÊéÇ©ÃûµÄ¶ñÒâÈí¼þ¡£¸Ã»î¶¯µÄ´ó¶àÊýÄ¿±êλÓÚÖйúÏã¸Û£¬Ò²ÓÐÒ»²¿ÃÅλÓÚÑÇÖÞµÄÆäËüµØÓò¡£Ñо¿ÈËÔ±ÌåÏÖ£¬¹ØÓÚCarderbee»î¶¯ÈÔÓÐһЩδ½âÖ®ÃÕ£¬ºÃ±ÈÈ·ÇеÄÄ¿±ê·¶Î§ÈÔ²»Çå³þ¡£
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/carderbee-software-supply-chain-certificate-abuse
6¡¢Ó¢¹úIT¹«Ë¾Swan RetailÔâµ½¹¥»÷Ó°ÏìÊý°Ù¼ÒÁãÊÛÉÌ
ýÌå8ÔÂ22ÈÕ±¨µÀ£¬Ó¢¹úIT¹«Ë¾Swan RetailÔâµ½ÍøÂç¹¥»÷£¬Ó°ÏìÁËÔ¼300¼ÒÁãÊÛÉÌ¡£8ÔÂ13ÈÕ£¬Õâ¼ÒÁãÊÛ¹ÜÀíºÍEPOS½â¾ö·½°¸ÌṩÉÌ·¢ÏÖ¶à¸öºǫ́ϵͳ·ºÆð¼¼ÊõÎÊÌ⣬µ¼Ö·þÎñÖжϡ£ÆäÐû²¼ÉùÃ÷ÌåÏÖÔâµ½ÁËÍøÂç¹¥»÷²¢ÒÑѸËÙ×ö³ö·´Ó³£¬µ«ÊÇûÓÐ˵Ã÷¹¥»÷ÀàÐÍ¡£´Ë´Î¹¥»÷Ó°ÏìÁ˼¸ºõËùÓÐÐÐÒµµÄ¶ÀÁ¢ÁãÊÛÉÌ£¬²¢¸øÐí¶à¹©Ó¦ÉÌ´øÀ´ÑÏÖØµÄ¾¼ÃËðʧ¡£¸Ã¹«Ë¾µÄ·þÎñ×ÔÖÜÈÕÒÔÀ´Ò»Ö±´¦ÓÚÔÝͣ״̬£¬Ä¿Ç°ÕýÔÚ»Ö¸´ÖС£
https://www.hackread.com/cyberattack-uk-swan-retail-affects-retailers/