¶íÂÞ˹±£ÏÕ¹«Ë¾RosgosstrakhÔâ¹¥»÷400GBÊý¾Ý±»³öÊÛ

Ðû²¼Ê±¼ä 2023-11-06

1¡¢¶íÂÞ˹±£ÏÕ¹«Ë¾RosgosstrakhÔâ¹¥»÷400GBÊý¾Ý±»³öÊÛ


¾ÝýÌå11ÔÂ4ÈÕ±¨µÀ £¬¶íÂÞ˹µÚ¶þ´ó±£ÏÕ¹«Ë¾RosgosstrakhÔâµ½ºÚ¿Í¹¥»÷¡£¾ÝϤ £¬ºÚ¿ÍApathyÔÚ°µÍøÉÏÒÔ5ÍòÃÀÔªµÄ¼Û¸ñ³öÊÛRosgosstrakhµÄÊý¾Ý¿â £¬²¢½ÓÊܱÈÌØ±Ò(BTC)»òÃÅÂÞ±Ò(XMR)µÄ¸¶¿î·½Ê½¡£±»µÁÊý¾Ý°üÂÞ¿É×·Ëݵ½2010ÄêµÄͶ×ʺÍÈËÊÙ±£ÏÕ²¿ÃŵÄÈ«²¿¼Ç¼ £¬Éæ¼°Ô¼300Íò·ÝÒøÐжÔÕ˵¥ £¬ºÍ73ÍòÈ˵ÄÊý¾Ý¡£Ñо¿ÈËÔ±³Æ £¬Õû¸öÊý¾Ý¿â¶à´ï400 GB £¬Ëû»ñµÃÁË22 GBµÄÃ÷ÎĸñʽJSONÊý¾Ý £¬·ÖÎö²¢·¢ÏÖÁË3ÃûGRUÌØ¹¤µÄÐÅÏ¢¡£


https://www.hackread.com/russia-insurer-rosgosstrakh-hacked-data-sold/


2¡¢ALPHVÉù³ÆÒÑÊÕ¼¯Ò½Áƹ«Ë¾Henry Schein 35TBÊý¾Ý


¾Ý11ÔÂ2ÈÕ±¨µÀ £¬ALPHVÉù³ÆÒÑÈëÇÖÒ½Áƹ«Ë¾Henry Schein £¬²¢ÊÕ¼¯ÁË35 TBµÄÊý¾Ý¡£¸Ã¹«Ë¾ÓÚ10ÔÂ15ÈÕÅû¶ £¬ÎªÁ˵ÖÓù14ÈÕÓ°ÏìÆäÖÆÔìºÍ·ÖÏúÒµÎñµÄÍøÂç¹¥»÷ £¬²¿ÃÅϵͳ±»ÆÈ¹Ø±Õ¡£Ô¼ÄªÁ½Öܺó £¬ALPHV½«Henry ScheinÌí¼Óµ½ÆäÍøÕ¾ £¬Éù³ÆÒÑÇÔÈ¡35 TBµÄÎļþ £¬°üÂÞÈËΪÊý¾ÝºÍ¹É¶«ÐÅÏ¢¡£²¢ÌåÏÖ¾ÍÔڸù«Ë¾¼¸ºõÍê³É»Ö¸´ËùÓÐϵͳµÄÊÂÇéʱ £¬ËûÃÇÔٴζԹ«Ë¾µÄÉ豸½øÐÐÁ˼ÓÃÜ £¬ÒòΪÕýÔÚ½øÐеÄ̸ÅÐʧ°ÜÁË¡£Ä¿Ç° £¬ALPHVÔÚÆäÍøÕ¾ÉÏɾ³ýÁËHenry Schein £¬±íÃ÷¸Ã¹«Ë¾½«ÖØÐÂ̸Åлò½»Êê½ð¡£


https://www.bleepingcomputer.com/news/security/blackcat-ransomware-claims-breach-of-healthcare-giant-henry-schein/


3¡¢ÊðÀí½©Ê¬ÍøÂçSocks5SystemzÒÑѬȾԼ10000¸öϵͳ


BitSightÔÚ11ÔÂ2ÈÕÅû¶ÁËÊðÀí½©Ê¬ÍøÂçSocks5SystemzµÄÏêϸÐÅÏ¢¡£Socks5Systemz½©Ê¬·¨Ê½ÓÉPrivateLoaderºÍAmadey·Ö·¢ £¬ÕâЩ¶ñÒâÈí¼þͨ³£Í¨¹ýµöÓã¹¥»÷¡¢Â©¶´ÀûÓù¤¾ß°ü¡¢¶ñÒâ¹ã¸æ¡¢´ÓP2PÍøÂçÏÂÔØµÄľÂí¿ÉÖ´ÐÐÎļþµÈ·½Ê½Á÷´«¡£ÊðÀí·þÎñÔÊÐí¿Í»§Ñ¡Ôñ´Ó1ÃÀÔªµ½4000ÃÀÔª²»µÈµÄÌײÍ £¬²¢Ê¹ÓüÓÃÜ»õ±ÒÈ«¶îÖ§¸¶¡£¸Ã½©Ê¬ÍøÂçÖÁÉÙ×Ô2016ÄêÒÔÀ´¾ÍÒÑ´æÔÚ £¬Ò£²âÊý¾ÝÏÔʾÒÑѬȾȫÇò·¶Î§ÄÚÔ¼10000¸öϵͳ¡£


https://www.bleepingcomputer.com/news/security/socks5systemz-proxy-service-infects-10-000-systems-worldwide/


4¡¢ÃÀ¹úµÖѺ´û¿î¹«Ë¾Mr.Cooper±»¹¥»÷ÔËÓªÊܵ½Ó°Ïì


11ÔÂ3ÈÕ±¨µÀ³Æ £¬ÃÀ¹úµÖѺ´û¿î¹«Ë¾Mr. CooperÔâµ½¹¥»÷ £¬°üÂÞÖ§¸¶ÔÚÄÚµÄÒµÎñÊܵ½Ó°Ïì¡£¸Ã´û¿î»ú¹¹ÒѳÉΪÃÀ¹ú×î´óµÄ·þÎñ»ú¹¹ £¬Îª9370ÒÚÃÀÔªµÄ´û¿îÌṩ·þÎñ¡£¹¥»÷·¢ÉúÔÚ10ÔÂ31ÈÕ £¬Î´¾­ÊÚȨµÄµÚÈý·½·ÃÎÊÁ˲¿ÃÅϵͳ¡£¼ì²âµ½Ê¼þºó £¬¸Ã¹«Ë¾Æô¶¯ÁËÏìÓ¦´ëÊ© £¬°üÂ޹رղ¿ÃÅϵͳ¡£ÏµÍ³å´»úµ¼Ö¿ͻ§ÎÞ·¨Ö§¸¶µÖѺ´û¿î £¬µ«ÊÇMr.CooperÔÊÐíÔÚ»Ö¸´ÏµÍ³µÄ¹ý³ÌÖв»»áÒòÓâÆÚ·¢ÉúÓöȡ¢·£¿î»ò¸ºÃæÐÅÓóÂËß¡£¸Ã¹«Ë¾ÈÔÔÚÊÓ²ì¿Í»§Êý¾ÝÊÇ·ñ±»µÁ £¬Ã»ÓÐ͸¶ÕâÊÇ·ñÊÇÀÕË÷¹¥»÷ £¬µ«ËüµÄËùÓм£Ïó±íÃ÷ÕâÊÇÀÕË÷¹¥»÷¡£


https://www.securityweek.com/mortgage-giant-mr-cooper-shuts-down-systems-following-cyberattack/


5¡¢OktaµÄ¹©Ó¦ÉÌÔâµ½¹¥»÷µ¼ÖÂÆäÊýǧÃûÔ±¹¤µÄÐÅϢй¶


 Ã½Ìå11ÔÂ2ÈÕ³Æ £¬Okta͸¶ÒòΪµÚÈý·½¹©Ó¦ÉÌRightway HealthcareÔâµ½¹¥»÷ £¬Æä½üÊýǧÃûÔ±¹¤µÄÐÅϢй¶¡£Õë¶ÔRightwayµÄ¹¥»÷·¢ÉúÓÚ9ÔÂ23ÈÕ £¬¹¥»÷Õß·ÃÎÊÁËΪÇкÏÌõ¼þµÄÈËÌṩ±£Ïպ͸£Àû¶øÎ¬»¤µÄ×ʸñÈË¿ÚÆÕ²éÎļþ¡£OktaÓÚ10ÔÂ12ÈÕµÃÖªÁË´Ë´Îй¶Ê¼þ £¬²¢È·¶¨´Ë´ÎÎ¥¹æÊ¼þ×ܹ²Ó°ÏìÁË4961ÃûÔ±¹¤ £¬À´×Ô2019Äê4ÔÂÖÁ2020ÄêµÄÎļþ¡£¸Ã¹«Ë¾½«ÎªÊÜÓ°ÏìµÄ¸öÈËÌṩÁ½ÄêµÄExperianÐÅÓÃ¼à¿Ø¡¢Éí·Ý͵ÇÔ±£»¤ºÍÆÛÕ©±£»¤·þÎñ¡£


https://therecord.media/okta-employees-impacted-by-third-party-breach


6¡¢Deep InstinctÅû¶MuddyWaterÕë¶ÔÒÔÉ«ÁеĵöÓã¹¥»÷


11ÔÂ2ÈÕ £¬Deep InstinctÐû²¼³ÂËß³Æ £¬MuddyWaterÕýÔÚÖ´ÐÐÐÂÒ»ÂÖµÄÓã²æÊ½µöÓã¹¥»÷ £¬Õë¶ÔÒÔÉ«ÁеĹ«Ë¾¡£10ÔÂ30ÈÕ £¬Ñо¿ÈËÔ±·¢ÏÖÁË¡°Storyblok¡±ÉÏÍйܵÄÁ½¸öµµ°¸ £¬ÆäÖаüÂÞеĶà½×¶ÎÑ¬È¾ÔØÌå¡£Ëü°üÂÞÒþ²ØÎļþ¡¢Æô¶¯Ñ¬È¾µÄLNKÎļþÒÔ¼°Ö¼ÔÚÔÚÖ´ÐÐAdvanced Monitoring Agent£¨Ò»ÖÖÔ¶³Ì¹ÜÀí¹¤¾ß£©µÄ¿ÉÖ´ÐÐÎļþ¡£Ñо¿ÈËÔ±³Æ £¬ÕâÊÇÒÁÀÊAPTÍÅ»ïÊ×´ÎʹÓÃN-ableµÄÔ¶³Ì¼à¿ØÈí¼þ¡£


https://www.deepinstinct.com/blog/muddywater-en-able-spear-phishing-with-new-ttps