¼ÓÄôóÁ¬Ëø³¬ÊÐSobeysÔâµ½Black BastaµÄÀÕË÷¹¥»÷

Ðû²¼Ê±¼ä 2022-11-14
1¡¢¼ÓÄôóÁ¬Ëø³¬ÊÐSobeysÔâµ½Black BastaµÄÀÕË÷¹¥»÷

¾ÝýÌå11ÔÂ12ÈÕ±¨µÀ£¬£¬£¬ £¬£¬£¬×ÔÉÏÖÜÄ©ÒÔÀ´£¬£¬£¬ £¬£¬£¬¼ÓÄôóSobeysÆìϵÄÔÓ»õµêºÍÒ©µêµÄITϵͳһֱ±£´æÎÊÌâ¡£¡£¡£ ¡£SobeysµÄĸ¹«Ë¾Empire͸¶£¬£¬£¬ £¬£¬£¬ËäÈ»ÆäÊÐËÁÈÔÔÚÓªÒµ£¬£¬£¬ £¬£¬£¬ÏÖÔÚûÓзºÆðÑÏÖØÖÐÖ¹£¬£¬£¬ £¬£¬£¬¿ÉÊDz¿·ÖµêÄÚЧÀÍ¿ÉÄÜÊܵ½Ó°Ïì¡£¡£¡£ ¡£¾ÝÔ±¹¤Í¸Â¶£¬£¬£¬ £¬£¬£¬ÊÜÓ°ÏìÊÐËÁÖеÄËùÓÐÅÌËã»ú¶¼Òѱ»Ëø¶¨£¬£¬£¬ £¬£¬£¬µ«POSºÍÖ§¸¶´¦Öóͷ£ÏµÍ³ÈÔÈ»ÔÚÏߣ¬£¬£¬ £¬£¬£¬ÓÉÓÚËüÃÇÔÚµ¥¶ÀµÄÍøÂçÉÏ¡£¡£¡£ ¡£Ö»¹Ü¸Ã¹«Ë¾ÉÐδÅû¶¹ØÓÚ´Ë´ÎÖÐÖ¹µÄϸ½ÚÐÅÏ¢£¬£¬£¬ £¬£¬£¬µ«Ñо¿Ö°Ô±Í¨¹ýÊê½ð¼Í¼ºÍ̸ÅжԻ°ÍƲâ¸Ã¹«Ë¾µÄϵͳѬȾÁËBlack Basta¡£¡£¡£ ¡£

https://securityaffairs.co/wordpress/138424/cyber-crime/sobeys-ransomware-attack.html

2¡¢ºÚ¿ÍÉù³ÆÒÑÈëÇÖµÂÒâÖ¾ÒøÐв¢ÔÚÍøÉϳöÊÛÆä»á¼ûȨÏÞ

¾Ý11ÔÂ11ÈÕ±¨µÀ£¬£¬£¬ £¬£¬£¬¹¥»÷Õß(0x_dump)Éù³ÆÒÑÈëÇÖ¿ç¹úͶ×ÊÒøÐеÂÒâÖ¾ÒøÐУ¬£¬£¬ £¬£¬£¬²¢ÔÚÏßÏúÊÛÆäÍøÂçµÄ»á¼ûȨÏÞ¡£¡£¡£ ¡£¸ÃIAB£¨initial access broker£©ÌåÏÖ¿ÉÒÔ»á¼ûÒøÐÐϵͳÖеÄÔ¼21000̨װ±¸£¬£¬£¬ £¬£¬£¬ÆäÖд󲿷ÖÊÇWindowsϵͳ£¬£¬£¬ £¬£¬£¬Ëû»¹³Æ±»Ñ¬È¾µÄ×°±¸ÊÜSymantec EDR½â¾ö¼Æ»®µÄ±£»£»£»£»£»£»¤¡£¡£¡£ ¡£Âô¼Ò˵Ëû¿ÉÒÔ»á¼ûÓÃÓÚÄÚ²¿Í¨Ñ¶µÄ̸ÌìЧÀÍ£¬£¬£¬ £¬£¬£¬»¹¿ÉÒÔ»á¼û°üÀ¨16 TBÊý¾ÝµÄÎļþЧÀÍÆ÷¡£¡£¡£ ¡£¶ÔµÂÒâÖ¾ÒøÐлá¼ûȨÏÞµÄÊÛ¼ÛΪ7.5±ÈÌØ±Ò£¬£¬£¬ £¬£¬£¬¼ÛÖµÔ¼156274ÃÀÔª¡£¡£¡£ ¡£

https://securityaffairs.co/wordpress/138416/data-breach/deutsche-bank-alleged-data-breach.html

3¡¢Ó¢¹úÓÊÕþ¹«Ë¾Royal MailµÄÍøÕ¾Ð§ÀÍÖÐÖ¹Áè¼Ý24Сʱ

ýÌå11ÔÂ11Èճƣ¬£¬£¬ £¬£¬£¬Ó¢¹ú»Ê¼ÒÓÊÕþµÄTrack&TraceÍøÕ¾ÖÐÖ¹Áè¼Ý24Сʱ£¬£¬£¬ £¬£¬£¬Óû§ÎÞ·¨×·×ÙËûÃǵİü¹üºÍÓʼþµÝËÍ¡£¡£¡£ ¡£Óû§»á¼û¸ÃÍøÕ¾Ê±»áÊÕµ½¡°Ð§ÀÍÔÝʱ²»¿ÉÓá±ÌáÐÑ£¬£¬£¬ £¬£¬£¬¶øTrack & Trace APIÒ»Ö±ÔÚ·µ»ØHTTP 429״̬´úÂ룬£¬£¬ £¬£¬£¬ÕâÅúעЧÀÍÆ÷ÎüÊÕµ½µÄÇëÇó¹ý¶à¡£¡£¡£ ¡£Ñо¿Ö°Ô±Ñ¯ÎÊÊÇ·ñÔâµ½ÁËÍøÂç¹¥»÷£¬£¬£¬ £¬£¬£¬¹«Ë¾µÄ½²»°ÈËÌåÏÖÍøÕ¾±£´æÊÖÒÕÎÊÌ⣬£¬£¬ £¬£¬£¬µ«Óû§¿ÉÒÔÔÚRoyal MailÓ¦ÓÃÉϸú×Ù°ü¹ü¡£¡£¡£ ¡£ÉÏÖÜ£¬£¬£¬ £¬£¬£¬Click&DropÍøÕ¾ÉϵĿͻ§ÐÅϢй¶£¬£¬£¬ £¬£¬£¬ÆÈʹ»Ê¼ÒÓÊÕþÔÝʱ¹Ø±ÕÆäÔÚÏßÓªÒµ¡£¡£¡£ ¡£

https://www.bleepingcomputer.com/news/security/royal-mail-down-tracking-unavailable-as-outage-exceeds-24-hours/

4¡¢ÂíÀ´Î÷ÑÇÑ¡¾ÙίԱ»áµÄÊý¾Ý¿âй¶½ü80ÍòÑ¡ÃñµÄÐÅÏ¢

11ÔÂ11ÈÕ±¨µÀ³Æ£¬£¬£¬ £¬£¬£¬ÂíÀ´Î÷ÑÇÔ¼80ÍòÃûÑ¡ÃñµÄСÎÒ˽¼ÒÐÅϢй¶¡£¡£¡£ ¡£¾Ý³Æ£¬£¬£¬ £¬£¬£¬Ð¹Â¶µÄ67 GBÊý¾Ýй¿à´×ÔÑ¡¾ÙίԱ»áµÄÊý¾Ý¿â£¬£¬£¬ £¬£¬£¬¸ÃÊý¾Ý¿âÏÖÔÚÔÚÒ»¸ö°µÍøÊг¡ÉÏÒÔ2000ÃÀÔªµÄ¼ÛÇ®³öÊÛ¡£¡£¡£ ¡£11ÔÂ10ÈÕ£¬£¬£¬ £¬£¬£¬Ñо¿Ö°Ô±ÔÚlowyat.net·¢Ã÷Á˳öÊÛµÄÐÅÏ¢£¬£¬£¬ £¬£¬£¬É漰סÃñµÄÐÕÃû¡¢Éí·ÝÖ¤ºÅÂë¡¢ÓʼþµØµã¡¢³öÉúÈÕÆÚºÍ¼ÒͥסַµÈ¡£¡£¡£ ¡£¾Ý³Æ£¬£¬£¬ £¬£¬£¬ÕâЩÊý¾ÝÊÇ´ÓÑ¡¾ÙίԱ»áµÄMySPRÍøÕ¾ÉÏÇÔÈ¡µÄ¡£¡£¡£ ¡£Õâһй¶ÊÂÎñ±¬·¢ÔÚ11ÔÂ19ÈÕÌìÏÂͶƱǰһÖÜ£¬£¬£¬ £¬£¬£¬ÒýÆðÁËÂíÀ´Î÷ÑÇסÃñµÄµ£ÐÄ¡£¡£¡£ ¡£

https://www.nst.com.my/news/crime-courts/2022/11/849700/personal-info-800000-voters-compromised-alleged-breach-ec-database

5¡¢Zscaler·¢Ã÷Google PlayÖзַ¢XenomorphľÂíµÄÓ¦ÓÃ

ZscalerÔÚ11ÔÂ10ÈÕ͸¶ÆäÔÚGoogle PlayÊÐËÁµÄÓ¦ÓÃÖз¢Ã÷ÁËÒøÐÐľÂíXenomorph¡£¡£¡£ ¡£XenomorphÓëAlienÓÐËùÖØµþ£¬£¬£¬ £¬£¬£¬µ«ËüÃǵĹ¦Ð§ÍêÈ«²î±ð£¬£¬£¬ £¬£¬£¬Ñо¿Ö°Ô±ÍƲâÕâÁ½ÖÖ¶ñÒâÈí¼þ¿ÉÄÜÊÇÓÉͳһ¿ª·¢Ö°Ô±¿ª·¢¡£¡£¡£ ¡£¸Ã¶ñÒâÓ¦ÓÃÃûΪTodo: Day manager£¬£¬£¬ £¬£¬£¬ÏÂÔØÁ¿Áè¼Ý1000´Î¡£¡£¡£ ¡£Zscaler»¹·¢Ã÷ÁíÒ»¸öÓ¦Óá°½U·Ñ¥­©`¥Ñ©`¡±£¨Expense Keeper£©Ò²ÌåÏÖ³öÁËÀàËÆµÄÐÐΪ£¬£¬£¬ £¬£¬£¬¿ÉÊÇ´ËÓ¦Óò»»á¼ìË÷payloadµÄdropper URL¡£¡£¡£ ¡£

https://www.zscaler.com/blogs/security-research/rise-banking-trojan-dropper-google-play-0

6¡¢LookoutÐû²¼¹ØÓÚBadBazaarºÍMOONSHINEµÄÆÊÎö±¨¸æ

11ÔÂ10ÈÕ£¬£¬£¬ £¬£¬£¬LookoutÐû²¼Á˹ØÓÚ¶ñÒâÈí¼þBadBazaarºÍMOONSHINEµÄÆÊÎö±¨¸æ¡£¡£¡£ ¡£×Ô2018ÄêÒÔÀ´£¬£¬£¬ £¬£¬£¬BadBazaarÌØ¹¤Èí¼þÒÑʹÓÃÖÁÉÙ111¸ö²î±ðµÄÓ¦ÓóÌÐòѬȾĿµÄ£¬£¬£¬ £¬£¬£¬Èç×ֵ䡢µç³ØÓÅ»¯¹¤¾ßºÍÊÓÆµ²¥·ÅÆ÷µÈ£¬£¬£¬ £¬£¬£¬²¢ÔÚÌØ¶¨µÄͨѶÇþµÀÉϾÙÐÐÐû´«¡£¡£¡£ ¡£´Ó2022Äê7ÔÂ×îÏÈ£¬£¬£¬ £¬£¬£¬Lookout¾ÍÊӲ쵽һÆðеĻ£¬£¬£¬ £¬£¬£¬Ê¹ÓÃ50¸öÓ¦ÓÃÏòÄ¿µÄÍÆËÍа汾µÄMoonshine£¬£¬£¬ £¬£¬£¬Ëü¿ÉÒÔ¼àÊÓÄ¿µÄµÄÍøÂç»î¶¯¡¢IP µØµãºÍÓ²¼þÐÅÏ¢µÈ¡£¡£¡£ ¡£

https://www.lookout.com/blog/uyghur-surveillance-campaign-badbazaar-moonshine