ºÚ¿ÍUSDoDÔÚ°µÍø¹ûÈ»3500ÍòÌõLinkedInÓû§Êý¾Ý
Ðû²¼Ê±¼ä 2023-11-09¾ÝýÌå11ÔÂ7ÈÕ±¨µÀ£¬ºÚ¿ÍUSDoDÔÚBreach ForumsÉÏй¶ÁËÁè¼Ý3500ÍòLinkedInÓû§µÄÐÅÏ¢¡£Ð¹Â¶µÄÊý¾Ý¿â·ÖΪÁ½²¿ÃÅ£¬Ò»²¿ÃÅ°üÂÞ500ÍòÌõÓû§¼Ç¼£¬µÚ¶þ²¿ÃÅ°üÂÞ3500ÍòÌõ¼Ç¼¡£¸ÃºÚ¿ÍÌåÏÖ£¬×îеÄLinkedInÊý¾Ý¿âÊÇͨ¹ýÍøÂçץȡ»ñµÃµÄ¡£ÆäÖаüÂÞÓû§ÐÕÃûºÍ¸öÈË×ÊÁϵÈÐÅÏ¢£¬»¹ÓÐһЩÓʼþµØÖ·ÊôÓÚÃÀ¹úÕþ¸®µÄ¸ß¼¶¹ÙÔ±ºÍ»ú¹¹¡£Í¬Ò»ºÚ¿ÍÔÚÈ¥ÄêÔøÈëÇÖÁËFBIÄþ¾²Æ½Ì¨InfraGard£¬²¢Ð¹Â¶ÁË87000ÃûÓû§µÄÐÅÏ¢¡£
https://www.hackread.com/hacker-leaks-scraped-linkedin-user-records/
2¡¢¶íÂÞ˹µÄ¹úÓд¢ÐîÒøÐÐSberbankÔâµ½DDoS¹¥»÷
¾Ý11ÔÂ8ÈÕ±¨µÀ£¬¶íÂÞ˹Áª°î´¢ÐîÒøÐУ¨Sberbank£©Ôâµ½ÁË´ó¹æÄ£DDoS¹¥»÷¡£SberbankÊÇÒ»¼Ò¹úÓÐÒøÐкͽðÈÚ·þÎñ¹«Ë¾£¬Ò²ÊǶíÂÞ˹×î´óµÄ½ðÈÚ»ú¹¹£¬³ÖÓиùúÔ¼Èý·ÖÖ®Ò»µÄ×ʲú¡£¶íÂÞ˹ýÌåInterfax³Æ£¬¹¥»÷ԼĪÔÚÁ½ÖÜÇ°£¬µ½´ïÁËÿÃë100Íò¸öÇëÇó(RPS)£¬ÕâԼĪÊǸÃÒøÐÐÆù½ñΪֹÔâµ½µÄ×î´ó¹æÄ£DDoS¹¥»÷µÄËı¶¡£¸Ã»ú¹¹»¹Í¸Â¶ÕâÊÇһЩеĺڿͣ¬Ò²¾ÍÊÇ˵£¬Ä¿Ç°·ºÆðÁËһЩÐµĹ¥»÷ÍŻËûÃÇ¿ªÊ¼ÏµÍ³ÐԵع¥»÷¶íÂÞ˹×î´óµÄÒøÐС£
https://www.bleepingcomputer.com/news/security/russian-state-owned-sberbank-hit-by-1-million-rps-ddos-attack/
3¡¢Ñо¿ÈËÔ±Åû¶BlueNorOffÀûÓÃÐÂObjCShellzµÄ¹¥»÷
JamfÔÚ11ÔÂ7ÈÕÅû¶BlueNorOffÍÅ»ïÀûÓÃÐÂmacOS¶ñÒâÈí¼þObjCShellzµÄ¹¥»÷»î¶¯¡£Ñо¿ÈËÔ±Ê×ÏÈ·¢ÏÖÁËÒ»¸öMach-OͨÓöþ½øÖÆÎļþÓëËûÃÇ֮ǰ¹éÀàΪ¶ñÒâµÄÓò½øÐÐͨÐÅ£¬±»·¢ÏÖʱËüÔÚVirusTotalÉϵļì²âÂÊΪÁã¡£ObjCShellzÊÇ»ùÓÚObjective-CµÄ¶ñÒâÈí¼þ£¬³äµ±Ô¶³Ìshell£¬ÓÃÓÚÔÚ±»Ñ¬È¾µÄϵͳÉÏÖ´ÐÐÃüÁĿǰÉв»Çå³þ¹¥»÷µÄ³õʼ·ÃÎÊÔØÌ壬µ«¸Ã¶ñÒâÈí¼þºÜ¿ÉÄÜÔÚ¹¥»÷ºóÆÚÓÃÓÚÔÚÈëÇÖϵͳºóÊÖ¶¯Ö´ÐÐÃüÁî¡£
https://www.jamf.com/blog/bluenoroff-strikes-again-with-new-macos-malware/
4¡¢²¿ÃÅOutlookÓû§ÔÚ·¢ËÍ°üÂÞ¸½¼þµÄÓʼþʱ»á±¨´í
11ÔÂ7ÈÕ±¨µÀ³Æ£¬Î¢ÈíÌáÐÑOutlook.comÓû§ÔÚ·¢ËÍ°üÂÞ¸½¼þµÄµç×ÓÓʼþʱ¿ÉÄÜ»áÓöµ½ÎÊÌâ¡£ÊܸÃÎÊÌâÓ°ÏìµÄÓû§ÔÚʵÑé·¢Ë͵ç×ÓÓʼþʱ»áÊÕµ½´íÎóÌáʾ"Error code 550 5.7.520 Message blocked"¡£Î¢ÈíÌṩÁËÒ»ÖÖÁÙʱ½â¾öÒªÁ죬ʹÊÜÓ°ÏìµÄÓû§Äܹ»¹²ÏíÎļþ£º½«ÎļþÉÏ´«µ½OneDrive²¢ÓëÊÕ¼þÈ˹²ÏíÁ´½Ó¡£7Ô·ݣ¬Î¢ÈíÔø½â¾öÁËÌáʾ401Òì³£´íÎó²¢×èÖ¹OutlookÓû§ËÑË÷ÓʼþµÄÎÊÌâ¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-some-outlookcom-users-cant-send-emails-with-attachments/
5¡¢SideCopyÀûÓÃ×îеÄWinRAR©¶´¹¥»÷Ó¡¶ÈµÄ¾üÕþ»ú¹¹
11ÔÂ6ÈÕ£¬SEQRITE Labs APT-Team³ÆÆä·¢ÏÖÁËÔÚ¹ýÈ¥¼¸¸öÔÂÕë¶ÔÓ¡¶ÈÕþ¸®ºÍ¹ú·À»ú¹¹µÄ¶à¸öSideCopy¹¥»÷»î¶¯¡£SideCopyÖÁÉÙ´Ó2019Ä꿪ʼ»îÔ¾£¬±»»³ÒÉÊÇTransparent TribeµÄÒ»¸ö×ÓÍŻ¸ÃÍÅ»ïÄ¿Ç°ÕýÔÚÀûÓÃ×îеÄWinRAR©¶´£¨CVE-2023-38831£©À´·Ö·¢AllaKore RAT¡¢DRatºÍÆäËüpayload¡£SEQRITE³ÆÕâÊǶàƽ̨¹¥»÷»î¶¯£¬Ëü»¹Í¨¹ý¼æÈÝ°æ±¾µÄAres RATÈëÇÖLinuxϵͳ¡£
https://www.seqrite.com/blog/sidecopys-multi-platform-onslaught-leveraging-winrar-zero-day-and-linux-variant-of-ares-rat/
6¡¢IBMÐû²¼GootloaderбäÌåGootBotµÄ·ÖÎö³ÂËß
11ÔÂ6ÈÕ£¬IBM X-ForceÐû²¼Á˹ØÓÚGootloaderбäÌåGootBotµÄ·ÖÎö³ÂËß¡£¹¥»÷Õß¿ª·¢ÁËÒ»ÖÖÐÂÐÍC2ºÍºáÏòÒƶ¯¹¤¾ßGootBot£¬ÓÃÓÚÈ¡´úCobaltStrikeµÈÆäËü´«Í³µÄÀûÓÿò¼Ü¡£Ä¿Ç°ÊӲ쵽µÄ»î¶¯ÀûÓÃSEOÖж¾½øÐзַ¢¡£Ñ¬È¾ºó£¬´óÁ¿GootBotÖ²È뷨ʽ»áÔÚÕû¸öÆóÒµ»·¾³ÖÐÁ÷´«£¬Ã¿¸öÖ²È뷨ʽ¶¼°üÂÞ²îÒìµÄÓ²±àÂëC2·þÎñÆ÷£¬Òò´ËºÜÄѱ»×èÖ¹¡£GootBotÔÚVirusTotalÉϵļì²âÂÊΪÁã¡£Gootloader»¹³äµ±³õʼ·ÃÎÊÌṩÕߣ¬¿ÉÄÜ»á·Ö·¢ÀÕË÷Èí¼þ¡£
https://securityintelligence.com/x-force/gootbot-gootloaders-new-approach-to-post-exploitation/