EmbyÔ¶³Ì¹Ø±Õ²¿·ÖÔâµ½¹¥»÷µÄÓû§Ã½ÌåЧÀÍÆ÷ʵÀý

Ðû²¼Ê±¼ä 2023-05-29

1¡¢EmbyÔ¶³Ì¹Ø±Õ²¿·ÖÔâµ½¹¥»÷µÄÓû§Ã½ÌåЧÀÍÆ÷ʵÀý


¾ÝýÌå5ÔÂ26ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬EmbyÔ¶³Ì¹Ø±ÕÁ˲¿·ÖÔâµ½¹¥»÷µÄÓû§ÍйÜýÌåЧÀÍÆ÷ʵÀý¡£¡£¡£ ¡£¡£¡£¹¥»÷»î¶¯Ê¼ÓÚ5ÔÂÖÐÑ®£¬£¬£¬£¬£¬£¬Æäʱ¹¥»÷ÕßÕë¶Ô̻¶µÄ˽ÈËEmbyЧÀÍÆ÷£¬£¬£¬£¬£¬£¬²¢ÈëÇÖÄÇЩÉèÖÃΪÔÊÐíÖÎÀíÔ±ÔÚÍâµØÍøÂçÉÏÎÞÃÜÂëµÇ¼µÄЧÀÍÆ÷¡£¡£¡£ ¡£¡£¡£ÎªÁË»ñµÃ»á¼ûȨÏÞ£¬£¬£¬£¬£¬£¬¹¥»÷Õß»¹Ê¹ÓÃÁËÒ»¸öÊðÀí±êÍ·Îó²î£¬£¬£¬£¬£¬£¬¸ÃÎó²î×î½üÔÚ²âÊÔ°æÆµµÀÖб»ÐÞ¸´¡£¡£¡£ ¡£¡£¡£¹¥»÷Õß×°ÖÃÁËÒ»¸ö¶ñÒâ²å¼þÀ´Ê¹Óûá¼ûȨÏÞ£¬£¬£¬£¬£¬£¬ÔÚ±»Ñ¬È¾µÄEmbyʵÀý°²ÅźóÃÅ£¬£¬£¬£¬£¬£¬¸Ã²å¼þ¿ÉÍøÂçÓû§Æ¾Ö¤¡£¡£¡£ ¡£¡£¡£Embyδ͸¶±»¹¥»÷ЧÀÍÆÚÊýÄ¿£¬£¬£¬£¬£¬£¬µ«ÍýÏ뾡¿ìÐû²¼Emby Server 4.7.12Çå¾²¸üÐÂÀ´½â¾ö¸ÃÎÊÌâ¡£¡£¡£ ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/emby-shuts-down-user-media-servers-hacked-in-recent-attack/


2¡¢OneMainÒòÍøÂçÇå¾²ÎÊÌⱻŦԼDFS·£¿£¿ £¿£¿£¿î425ÍòÃÀÔª


¾Ý5ÔÂ26ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬OneMain Financial Group±»Å¦Ô¼½ðÈÚЧÀͲ¿(DFS)·£¿£¿ £¿£¿£¿î425ÍòÃÀÔª¡£¡£¡£ ¡£¡£¡£DFSÔÚÒ»·ÝÉùÃ÷ÖÐÌåÏÖ£¬£¬£¬£¬£¬£¬OneMainδÄÜÓÐÓõØÖÎÀíµÚÈý·½Ð§ÀÍÌṩÉ̵ÄΣº¦¡¢ÖÎÆÊÎö¼ûȨÏÞÒÔ¼°Ê¹ÓÃÕýʽµÄÓ¦ÓÃÇå¾²¿ª·¢ÒªÁ죬£¬£¬£¬£¬£¬Õâ´ó´óÔöÌíÁ˸ù«Ë¾ÃæÁÙÍøÂçÇå¾²ÊÂÎñµÄųÈõÐÔ¡£¡£¡£ ¡£¡£¡£ÀýÈ磬£¬£¬£¬£¬£¬OneMainʹÓÃÁËÆäÄÚ²¿¿ª·¢µÄ·ÇÕý¹æÏîÄ¿ÖÎÀí¿ò¼ÜµÈ¡£¡£¡£ ¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬£¬£¬£¬ËüÔç¾Í½â¾öÁËÊÓ²ìÖз¢Ã÷µÄÎÊÌ⣬£¬£¬£¬£¬£¬´Ë´ÎÊÓ²ìËùÉó²éµÄÊÇÆä2017ÄêÖÁ2020ÄêÍ·µÄÕþ²ß¡£¡£¡£ ¡£¡£¡£


https://therecord.media/one-main-fined-ny-for-cybersecurity-lapses


3¡¢Ñо¿ÍŶӳÆMagalenhaÐж¯¹¥»÷30¶à¼ÒÆÏÌÑÑÀ½ðÈÚ»ú¹¹


5ÔÂ25ÈÕ£¬£¬£¬£¬£¬£¬SentinelLabs³ÆÆäÊӲ쵽ÃûΪMagalenhaÐж¯µÄ¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬×Ô2021ÄêÒÔÀ´Ò»Ö±Õë¶Ô30¶à¼ÒÆÏÌÑÑÀ½ðÈÚ»ú¹¹ÇÔÊØÐÅÏ¢¡£¡£¡£ ¡£¡£¡£¸Ã»î¶¯¿ÉÄÜÓë°ÍÎ÷µÄ¹¥»÷ÍÅ»ïÓйأ¬£¬£¬£¬£¬£¬Ê¼ÓÚ»ìÏýµÄVB¾ç±¾£¬£¬£¬£¬£¬£¬¿É»ñÈ¡²¢Ö´ÐжñÒâÈí¼þ¼ÓÔØ³ÌÐò£¬£¬£¬£¬£¬£¬²¢ÔÚÎåÃëÖÓµÄÑӳٺ󣬣¬£¬£¬£¬£¬½«ºóÃÅPeepingTitleµÄÁ½¸ö±äÌå¼ÓÔØµ½Ä¿µÄϵͳÖС£¡£¡£ ¡£¡£¡£PeepingTitleÊÇÒ»¸öDelphi¿ª·¢µÄ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬±àÒëÈÕÆÚΪ4Ô·Ý¡£¡£¡£ ¡£¡£¡£¹¥»÷Õß·Ö·¢Á½¸ö±äÌåµÄÔµ¹ÊÔ­ÓÉÊÇ£¬£¬£¬£¬£¬£¬Ò»¸öÓÃÓÚ²¶»ñÆÁÄ»£¬£¬£¬£¬£¬£¬ÁíÒ»¸öÓÃÓÚ¼àÊÓ´°¿ÚÒÔ¼°Óû§ÓëÕâЩ±äÌåµÄ½»»¥¡£¡£¡£ ¡£¡£¡£


https://www.sentinelone.com/labs/operation-magalenha-long-running-campaign-pursues-portuguese-credentials-and-pii/


4¡¢BlackByteÉù³Æ¶ÔÃÀ¹ú°Â¹Å˹ËþÊÐÔâµ½µÄ¹¥»÷ÈÏÕæ


5ÔÂ26ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬ÀÕË÷ÍÅ»ïBlackByteÉù³Æ¶ÔÃÀ¹ú×ôÖÎÑÇÖݰ¹Å˹ËþÊÐÔâµ½µÄ¹¥»÷ÈÏÕæ¡£¡£¡£ ¡£¡£¡£¸ÃÊÐÔÚÆäÍøÕ¾ÉÏÚ¹ÊÍ˵£¬£¬£¬£¬£¬£¬Ëü´Ó5ÔÂ21ÈÕ×îÏÈÓöµ½ÊÖÒÕÄÑÌ⣬£¬£¬£¬£¬£¬µ¼Ö²¿·ÖϵͳÖÐÖ¹¡£¡£¡£ ¡£¡£¡£» £»£»£»£»£»¹³ÎÇåµ½£¬£¬£¬£¬£¬£¬ÕâÆðÊÂÎñÓë֮ǰ±¬·¢µÄITϵͳÖÐÖ¹Î޹ء£¡£¡£ ¡£¡£¡£BlackByteÔÚÆäÍøÕ¾Éϳƣ¬£¬£¬£¬£¬£¬ÒѴӰ¹Å˹ËþµÄÅÌËã»úÉÏÇÔÈ¡ÁË´ó×ÚÊý¾Ý£¬£¬£¬£¬£¬£¬²¢¹ûÕæÁË8.1 GBµÄÑù±¾Êý¾Ý×÷Ϊ֤¾Ý¡£¡£¡£ ¡£¡£¡£¸ÃÍÅ»ïÀÕË÷40ÍòÃÀÔªÀ´É¾³ýÊý¾Ý£¬£¬£¬£¬£¬£¬²¢Ìá³öÒÔ30ÍòÃÀÔªµÄ¼ÛÇ®½«Êý¾Ý³öÊÛ¸ø¸ÐÐËȤµÄµÚÈý·½¡£¡£¡£ ¡£¡£¡£


https://securityaffairs.com/146717/hacking/city-of-augusta-cyberattack.html


5¡¢Mandiant·¢Ã÷ʹÓÃICSЭÒé¹¥»÷µçÍøµÄCOSMICENERGY


MandiantÔÚ5ÔÂ26ÈÕ͸¶£¬£¬£¬£¬£¬£¬Æä·¢Ã÷ÁËеĶñÒâÈí¼þCOSMICENERGY£¬£¬£¬£¬£¬£¬Ê¹ÓÃICSЭÒéÀ´ÆÆËðµçÍø¡£¡£¡£ ¡£¡£¡£ËüÊÇÓɶíÂÞ˹µÄ¹¥»÷ÕßÓÚ2021Äê12ÔÂÉÏ´«µ½VirusTotalµÄ£¬£¬£¬£¬£¬£¬ÏÖÔÚûÓÐÔÚÒ°ÍⱻʹÓᣡ£¡£ ¡£¡£¡£MandiantÌåÏÖ£¬£¬£¬£¬£¬£¬Õâ¿ÉÄÜÊǶíÂÞ˹µçÐŹ«Ë¾Rostelecom-Solar¿ª·¢µÄÒ»ÖÖºì¶Ó¹¤¾ß£¬£¬£¬£¬£¬£¬ÓÃÓÚÄ£Äâ2021Äê10ÔµĵçÁ¦ÖÐÖ¹ºÍÓ¦¼±ÏìÓ¦ÑÝϰ¡£¡£¡£ ¡£¡£¡£COSMICENERGYµÄ¹¦Ð§¿ÉÒÔÓëIndustroyerÏàæÇÃÀ£¬£¬£¬£¬£¬£¬ÓÉÓÚËüÄܹ»Ê¹Óù¤ÒµÍ¨Ñ¶Ð­ÒéIEC-104ÏòRTU·¢³öÖ¸Áî¡£¡£¡£ ¡£¡£¡£Ê¹ÓÃÕâÖÖ»á¼ûȨÏÞ£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ·¢ËÍÔ¶³ÌÏÂÁîÀ´Ó°ÏìµçÁ¦Ïß¿ª¹ØºÍ¶Ï·Æ÷µÄÆô¶¯£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖµçÁ¦ÖÐÖ¹¡£¡£¡£ ¡£¡£¡£


https://www.mandiant.com/resources/blog/cosmicenergy-ot-malware-russian-response


6¡¢Ñо¿Ö°Ô±·¢Ã÷ʹÓÃWin10д×Ö°åDLLÐ®ÖÆÎó²îµÄQBot»î¶¯ 


ýÌå5ÔÂ27ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ÐÂÒ»ÂÖQBot¹¥»÷»î¶¯¡£¡£¡£ ¡£¡£¡£¸Ã»î¶¯Ê¹ÓÃÁËWindows 10д×Ö°åÖеÄDLLÐ®ÖÆÎó²îѬȾÅÌËã»ú£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃÕýµ±³ÌÐòÈÆ¹ýÇå¾²Èí¼þµÄ¼ì²â¡£¡£¡£ ¡£¡£¡£Ä¿µÄµã»÷´¹ÂÚÓʼþÖеÄÁ´½Óʱ£¬£¬£¬£¬£¬£¬»áÏÂÔØÒ»¸öËæ»úÃüÃûµÄZIP´æµµ£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨Win10д×Ö°å¿ÉÖ´ÐÐÎļþdocument.exeºÍDLLÎļþedputil.dll¡£¡£¡£ ¡£¡£¡£¼ÓÔØ¶ñÒâ°æ±¾µÄedputil.dllºó£¬£¬£¬£¬£¬£¬»á´ÓÔ¶³ÌÖ÷»úÏÂÔØÎ±×°³ÉPNGµÄDLL£¬£¬£¬£¬£¬£¬È»ºóʹÓÃrundll32.exeÖ´ÐдËPNG¡£¡£¡£ ¡£¡£¡£Õâʱ£¬£¬£¬£¬£¬£¬QBot½«ÔÚºǫ́Çå¾²µØÔËÐС£¡£¡£ ¡£¡£¡£  


https://www.bleepingcomputer.com/news/security/qbot-malware-abuses-windows-wordpad-exe-to-infect-devices/