µÂ¾¯·½¹Ø±ÕDDoS³ö×âƽ̨Dstat.cc£¬´þ²¶Á½Ãû·¸×ïÏÓÒÉÈË
Ðû²¼Ê±¼ä 2024-11-0511ÔÂ4ÈÕ£¬µÂ¹ú¾¯·½½üÆÚ½ÓÄÉÁËÒ»ÏîÖØ´óÐж¯£¬ÀֳɹرÕÁËDDoS×âÁÞƽ̨Dstat.cc£¬²¢´þ²¶ÁËÁ½ÃûÉæÏÓÔËÓª¸Ãƽ̨²¢·¢¶¯DDoS¹¥»÷µÄÄÐ×Ó¡£ÕâÁ½ÃûÄÐ×Ó·Ö±ðÀ´×Ô´ïÄ·Ê©ËþÌغÍÀ³ÒðÀ¼ÊУ¬ÄêÁä·Ö±ðΪ19ËêºÍ28Ëê¡£³ýÁËDDoS¹¥»÷Í⣬ËûÃÇ»¹ÉæÏÓÔËÓªÁíÒ»¸öÃûΪ¡°Flight RCS¡±µÄÔÚÏßƽ̨£¬¸Ãƽ̨³öÊÛÉè¼ÆÒ©ÎïºÍºÏ³É´óÂéËØ¡£Á½ÈËÒò´ËÃæÁÙÔËÓª·¸×ï½»Ò×ƽ̨½øÐÐÉÌÒµºÍ°ïÅɻµÄÖ¸¿Ø£¬²¢Òѱ»²¶³öÍ¥ÊÜÉó¡£´Ë´ÎÐж¯ÓÉ·¨À¼¿Ë¸£×ܼì²ì³¤°ì¹«ÊÒÖÐÑë¹¥»÷ÍøÂç·¸×ï¾Ö¡¢ºÚÉÖÝÐÌʾ¯²ì¾ÖºÍÁª°îÐÌʾ¯²ì¾Öе÷£¬²¢µÃµ½ÁË·¨¹ú¡¢Ï£À°¡¢±ùµººÍÃÀ¹úÕþ¸®µÄÖ§³Ö¡£¾¯·½ÔÚÐж¯Öв»½ö¹Ø±ÕÁËDstat.ccºÍFlight RCSƽ̨£¬»¹ËѲéÁ˵¹úµÄÆß´¦·¿²ú¡£BKAÖ¸³ö£¬Dstat.ccƽ̨ʹ¹ã·ºµÄÓû§Äܹ»ÌᳫDDoS¹¥»÷£¬°üÂÞÄÇЩûÓÐÉîÈë¼¼Êõ¼¼ÄܵÄÓû§¡£´ËÀàѹÁ¦·þÎñÔÚÍþвÁìÓòÔ½À´Ô½ÊÜ»¶Ó£¬²¢±»ÖîÈç¡°Killnet¡±Ö®ÀàµÄºÚ¿Í×éÖ¯´óÁ¿Ê¹Óᣴ˴ÎÐж¯Êǹú¼ÊÐж¯PowerOffµÄÒ»²¿ÃÅ£¬Ö¼ÔÚ¹¥»÷´óÁ¿¡°DDos-as-a-service¡±Æ½Ì¨¡£´Ë´ÎÐж¯ÕÃÏÔÁ˹ú¼ÊÖ´·¨²¿ÃŹ¥»÷Êý×Ö·¸×ïµÄʵÁ¦¡£
https://securityaffairs.com/170540/cyber-crime/german-police-shut-down-ddos-for-hire-platform-dstat-cc.html
2. ´ó¹æÄ£OpenAIÄ£·ÂµöÓã¹¥»÷£¬Ä¿±êÖ±Ö¸ChatGPTÓû§Æ¾Ö¤
11ÔÂ4ÈÕ£¬Barracuda Networks ½üÈÕ¼à²âµ½Ò»³¡Õë¶Ô ChatGPT Óû§Æ¾Ö¤µÄ´ó¹æÄ£ OpenAI Ä£·Â»î¶¯¡£¹¥»÷Õßͨ¹ý·¢ËÍÍøÂçµöÓãµç×ÓÓʼþ£¬Éù³ÆÊÕ¼þÈË¡°¶Ô ChatGPT µÄ×îж©Ôĸ¶¿îδÀֳɡ±£¬²¢ÓÕµ¼ËûÃǵã»÷Á´½Ó¸üи¶¿îÐÅÏ¢¡£ÕâЩÓʼþ¿´ËÆÀ´×Ô OpenAI Payments£¬µ«Êµ¼ÊÉÏÔ´×ÔÃûΪ topmarinelogistics.com µÄÓòÃû£¬ÇÒÒÑͨ¹ý DKIM ºÍ SPF ¼ì²é£¬Ôö¼ÓÁËÆÛÆÐÔ¡£¾Ý Barracuda ͳ¼Æ£¬ÓÐÁè¼Ý 1,000 ·â´ËÀàÓʼþ´Óµ¥¸öÓòÃû·¢³ö£¬Ä¿±êΪȫÇòÆóÒµ¡£ÓʼþÖ¸ÏòµÄÓòÃû fnjrolpa.com Ä¿Ç°ÒÑÀëÏߣ¬µ«·ÖÎöÏÔʾ£¬¸ÃÍøÕ¾ÔøÍйÜÒ»¸öÓë OpenAI ÏàËƵÄÐé¼ÙµÇ¼ҳÃ棬ּÔÚÇÔÈ¡Óû§Æ¾Ö¤¡£Barracuda ²úÎï¹ÜÀíÍÅ¶ÓµÄ Prebh Singh ÌåÏÖ£¬ÕâÊǹ¥»÷Õß»ñÈ¡ÐÂÕË»§È¨Ï޵ıã½ÝÊֶΣ¬½ø¶øÀûÓÃÕâЩÕË»§ÌᳫеÄÍøÂçµöÓã»î¶¯¡£ÖµµÃ×¢ÒâµÄÊÇ£¬ÍÐ¹Ü ChatGPT ÍøÂçµöÓãÒ³ÃæµÄÓòÃûÓÚ 2023 Äê 12 ÔÂ×¢²á£¬×¢²áµØÖ·À´×ÔÄá²´¶û£¬¶ø·¢¼þÈ˵ÄÓòÃûÔÚ·¨¹ú×¢²á£¨ÏÖÒÑÎÞ·¨·ÃÎÊ£©£¬IP µØÖ·ÔòÊôÓڵ¹ú£¬ÏÔʾ³ö´Ë´ÎÍøÂç¹¥»÷»î¶¯µÄÅÓ´óÐԺͿç¹úÐÔ¡£
https://www.securityweek.com/businesses-worldwide-targeted-in-large-scale-chatgpt-phishing-campaign/
3. ŵ»ùÑÇÊÓ²ìµÚÈý·½¹©Ó¦ÉÌÔâºÚ¿ÍÈëÇÖ£¬Ô´´úÂëÒɱ»µÁ
11ÔÂ4ÈÕ£¬Åµ»ùÑÇÕýÔÚÊÓ²ìÒ»ÆðÉæÏÓÔ´´úÂë±»µÁµÄʼþ£¬¸ÃʼþÉæ¼°µÚÈý·½¹©Ó¦ÉÌÊÇ·ñÔâµ½ÈëÇÖ¡£´ËÇ°£¬Ò»¸öÃûΪIntelBrokerµÄÍþвÐÐΪÕßÉù³ÆÒѾÈëÇÖÁËÓëŵ»ùÑǺÏ×÷µÄµÚÈý·½¹©Ó¦É̵ķþÎñÆ÷£¬²¢ÇÔÈ¡ÁË´óÁ¿Åµ»ùÑÇÔ´´úÂë¡£¾Ý³Æ£¬±»µÁÊý¾Ý°üÂÞSSHÃÜÔ¿¡¢Ô´´úÂë¡¢RSAÃÜÔ¿¡¢BitBucketµÇ¼ÐÅÏ¢¡¢SMTPÕÊ»§¡¢webhookºÍÓ²±àÂëƾ¾ÝµÈÃô¸ÐÐÅÏ¢¡£IntelBrokerÉù³ÆʹÓÃĬÈÏƾ¾Ý·ÃÎÊÁ˵ÚÈý·½¹©Ó¦É̵ÄSonarQube·þÎñÆ÷£¬ÏÂÔØÁË°üÂÞŵ»ùÑÇÔÚÄڵĿͻ§µÄPythonÏîÄ¿¡£BleepingComputerÓëŵ»ùÑÇ·ÖÏíÁ˾ݳƱ»µÁÊý¾ÝµÄÎļþÊ÷£¬µ«ÉÐδÊÕµ½»Ø¸´¡£IntelBrokerÔøÒòÈëÇÖ¶à¸ö×éÖ¯¶øÉùÃûÀǽ壬°üÂÞÂôÁ¦¹ÜÀíÃÀ¹úÖÚÒéÔºÒéÔ±Ò½ÁƱ£½¡¼Æ»®µÄDC Health Link£¬ÒÔ¼°»ÝÆÕÆóÒµºÍWeee!ÔÓ»õ·þÎñµÈ¡£×î½ü£¬¸ÃÍþвÐÐΪÕß»¹Ð¹Â¶ÁË°üÂÞT-Mobile¡¢AMDºÍAppleÔÚÄڵĶà¼Ò¹«Ë¾µÄÊý¾Ý£¬ÕâЩÊý¾ÝÊÇ´ÓµÚÈý·½SaaS¹©Ó¦ÉÌ´¦ÇÔÈ¡µÄ¡£
https://www.bleepingcomputer.com/news/security/nokia-investigates-breach-after-hacker-claims-to-steal-source-code/
4. ¡¶ÂéÊ¡Àí¹¤Ñ§Ôº¼¼ÊõÆÀÂÛ¡·ÔâºÚ¿ÍÈëÇÖ£¬½ü30ÍòÓû§Êý¾Ýй¶
11ÔÂ4ÈÕ£¬½üÆÚÃûΪ¡°Intel Broker¡±µÄºÚ¿ÍÉù³Æͨ¹ýµÚÈý·½³Ð°üÉÌÈëÇÖÁË¡¶ÂéÊ¡Àí¹¤Ñ§Ôº¼¼ÊõÆÀÂÛ¡·ÔÓÖ¾£¬²¢ÔÚBreach ForumsÉϹûÈ»Á˽ü30ÍòÌõÓû§¼Ç¼¡£ÕâЩÊý¾Ý¿ÉÄÜÔ´×Ô¸ÃÍøÕ¾µÄÐÂÎÅͨѶ¶©ÔÄÕßÃûµ¥£¬°üÂÞÈ«Ãû¡¢µç×ÓÓʼþµØÖ·¡¢»î¶¯ÈÕÆÚ¼°½ÌÓýϸ½ÚµÈ¸öÈËÐÅÏ¢£¬¾¡¹ÜδÉæ¼°ÃÜÂë¡¢Éç»á±£ÏպŻò²ÆÕþÊý¾ÝµÈ¸ß¶ÈÃô¸ÐÄÚÈÝ£¬µ«ÈÔÃæÁÙÍøÂçµöÓãºÍÕë¶ÔÐÔթƵķçÏÕ¡£¡¶ÂéÊ¡Àí¹¤¼¼ÊõÆÀÂÛ¡·×÷ΪÂéÊ¡Àí¹¤Ñ§ÔºµÄÒ»·ÝÖøÃû¿¯Î´Ë´ÎÊý¾Ýй¶Ê¼þÎÞÒɽ«Ëðº¦ÆäÉùÓþ£¬²¢Òý·¢Óû§¶ÔÆäÒþ˽±£»¤µÄµ£ÓÇ¡£Intel BrokerÒò½üÆÚ¶Ô¶à¼ÒÖªÃû×éÖ¯Ìᳫ¹¥»÷¶øÉùÃûÀǽ塣Ŀǰ£¬¡¶ÂéÊ¡Àí¹¤Ñ§Ôº¼¼ÊõÆÀÂÛ¡·ÉÐδ¶Ô´Ë´ÎÊý¾Ýй¶Ê¼þ×÷³ö»ØÓ¦£¬¹«ÖÚÕýÃÜÇйØ×¢ÊÂ̬Éú³¤¡£
https://hackread.com/hackers-leak-mit-technology-review-user-records/
5. Ê©Ä͵µçÆøÔâºÚ¿ÍÈëÇÖ£¬40GBÊý¾Ý±»µÁ
11ÔÂ4ÈÕ£¬Ê©Ä͵µçÆøÔâÓöÁËÒ»ÆðÍøÂçÄþ¾²Ê¼þ£¬Ò»ÃûÃûΪ¡°Grep¡±µÄÍþвÐÐΪÕßÉù³Æ´Ó¸Ã¹«Ë¾µÄJIRA·þÎñÆ÷ÇÔÈ¡ÁË40GBµÄÊý¾Ý¡£¾ÝÊ©Ä͵µçÆø͸¶£¬´Ë´ÎʼþÉ漰δ¾ÊÚȨ·ÃÎÊÆäλÓÚ¸ôÀë»·¾³ÖеÄÄÚ²¿ÏîÄ¿Ö´Ðиú×Ùƽ̨֮һ£¬µ«¹«Ë¾µÄ²úÎïºÍ·þÎñ²¢Î´Êܵ½Ó°Ïì¡£GrepÉù³ÆÀûÓÃ̻¶µÄƾ֤ÈëÇÖÁËÊ©Ä͵µçÆøµÄJira·þÎñÆ÷£¬²¢×¥È¡ÁË40ÍòÐÐÓû§Êý¾Ý£¬ÆäÖаüÂÞ75,000¸öΨһµç×ÓÓʼþµØÖ·ºÍÈ«Ãû¡£ÔÚ°µÍøÌû×ÓÖУ¬Grep¿ªÍæЦµØË÷Òª¼ÛÖµ125,000ÃÀÔªµÄ¡°Baguettes¡±ÒÔ±£Ö¤²»Ð¹Â¶Êý¾Ý£¬²¢·ÖÏíÁ˸ü¶àÓйر»µÁÊý¾ÝµÄϸ½Ú¡£´ËÍ⣬Grep»¹ÌåÏÖËûÃÇ×î½ü½¨Á¢ÁËÒ»¸öеĺڿÍ×éÖ¯£¬¹ú¼ÊºÏͬ»ú¹¹(ICA)£¬²¢Éù³ÆÈç¹û¹«Ë¾ÔÚ48СʱÄÚ²»ÈÏ¿ÉÊܵ½¹¥»÷£¬ËûÃǾͻáй¶Èκα»µÁÊý¾Ý¡£Ê©Ä͵µçÆøÒѾȷÈÏÁË´Ë´ÎйÃÜʼþ£¬µ«Éв»Çå³þÍþвÐÐΪÕßÊÇ·ñ»á¼ÌÐø鶻ò³öÊÛ±»µÁÊý¾Ý¡£
https://www.bleepingcomputer.com/news/security/schneider-electric-confirms-dev-platform-breach-after-hacker-steals-data/
6. ¶íº¥¶íÖݸçÂײ¼ÊÐ50Íò¾ÓÃñÐÅÏ¢ÔâÀÕË÷ÍÅ»ïÇÔÈ¡²¢Ð¹Â¶
11ÔÂ4ÈÕ£¬¶íº¥¶íÖݸçÂײ¼ÊУ¨ÈË¿ÚÁè¼Ý905,000£©ÔÚ½ñÄê7ÔÂÔâÊÜRhysidaÀÕË÷Èí¼þÍÅ»ïµÄ¹¥»÷£¬µ¼Ö¹«¹²·þÎñºÍITÁ¬½ÓÖжϡ£¸ÃÍÅ»ïÉù³ÆÇÔÈ¡ÁË6.5TBÊý¾Ý£¬°üÂÞÔ±¹¤Æ¾Ö¤¡¢¶¼ÊÐÉãÏñ»úÔ´µÈÃô¸ÐÐÅÏ¢¡£¾¡¹ÜÊÐÕþ¸®¹ÙÔ±×î³õÌåÏÖϵͳδ±»¼ÓÃÜ£¬µ«RhysidaÔÚÀÕË÷ʧ°Üºóй¶ÁË45%µÄ±»µÁÊý¾Ý¡£¸çÂײ¼ÊÐÊг¤°²µÂ³¡¤½ðɪÉù³Æ鶵ÄÊý¾ÝÒѼÓÃÜ»òË𻵣¬µ«Äþ¾²Ñо¿Ô±David Leroy Ross£¨Connor Goodwolf£©Ìá³öÒìÒ飬²¢·ÖÏíÁËδ¼ÓÃܵĸöÈËÐÅÏ¢Ñù±¾¡£ÊÐÕþ¸®¶ÔGoodwolfÌáÆðËßËÏ£¬Ö¸¿ØÆäÁ÷´«±»µÁÊý¾Ý£¬²¢Ðû²¼ÁËÁÙʱÏÞÖÆÁȻ¶ø£¬Æ¾¾ÝÌá½»¸øÃåÒòÖÝ×ܼì²ì³¤°ì¹«ÊÒµÄÎ¥¹æ֪ͨÐÅ£¬ÊÐÕþ¸®ÔÚ10Ô³õ֪ͨÁË50ÍòÈË£¬³Æ¹¥»÷ÕßÇÔÈ¡²¢Ðû²¼ÁËËûÃǵĸöÈËÐÅÏ¢ºÍ²ÆÕþÐÅÏ¢¡£¾¡¹ÜÉÐδ·¢ÏÖÊý¾ÝÀÄÓÃÖ¤¾Ý£¬ÊÐÕþ¸®ÈÔ½¨ÒéÊÜÓ°Ïì¸öÈ˼à¿ØÐÅÓóÂËߺͽðÈÚÕË»§£¬²¢Ìṩ24¸öÔµÄÃâ·ÑÐÅÓüà¿ØºÍÉí·Ý»Ö¸´·þÎñ¡£
https://www.bleepingcomputer.com/news/security/city-of-columbus-data-of-500-000-stolen-in-july-ransomware-attack/