ºÉÀ¼º½Ô˹«Ë¾Royal DirkzwagerÔâµ½PlayµÄÀÕË÷¹¥»÷

Ðû²¼Ê±¼ä 2023-03-21

1¡¢ºÉÀ¼º½Ô˹«Ë¾Royal DirkzwagerÔâµ½PlayµÄÀÕË÷¹¥»÷


¾Ý3ÔÂ20ÈÕ±¨µÀ£¬£¬£¬ºÉÀ¼º½Ô˹«Ë¾Royal DirkzwagerÔâµ½ÀÕË÷ÍÅ»ïPlayµÄ¹¥»÷¡£¡£¡£ ¡£¡£¡£ÀÕË÷ÍŻォ¸Ã¹«Ë¾Ìí¼Óµ½ÆäÍøÕ¾ÉÏ£¬£¬£¬²¢Ðû²¼ÇÔÈ¡ÁËÔ±¹¤ ID¡¢»¤ÕÕºÍÌõÔ¼µÈÉñÃØÊý¾Ý¡£¡£¡£ ¡£¡£¡£¸ÃÍÅ»ï×î³õ¹ûÕæÁËÒ»¸ö5 GBµÄÎļþ×÷Ϊ¹¥»÷Ö¤¾Ý£¬£¬£¬²¢Íþв˵£¬£¬£¬ÈôÊǹ«Ë¾²»¸¶Êê½ð¾Í¹ûÕæËùÓеÄÊý¾Ý¡£¡£¡£ ¡£¡£¡£¸Ãº½Ô˹«Ë¾ÌåÏÖ£¬£¬£¬¹¥»÷»î¶¯²¢Î´Ó°Ï칫˾µÄÔËÓª£¬£¬£¬²¢Ö¤Êµ¹¥»÷ÕßÒѾ­´ÓÆä»ù´¡ÉèÊ©ÖÐÇÔÈ¡ÁËÃô¸ÐÊý¾Ý¡£¡£¡£ ¡£¡£¡£¸Ã¹«Ë¾Òѽ«´ËÊÂ֪ͨÁ˺ÉÀ¼Êý¾Ý±£»£»£»£» £»£»¤¾Ö£¬£¬£¬²¢ÕýÔÚÓëÀÕË÷ÍÅ»ï¾ÙÐÐ̸ÅС£¡£¡£ ¡£¡£¡£


https://securityaffairs.com/143714/cyber-crime/play-ransomware-royal-dirkzwager.html


2¡¢Ñо¿ÍŶӷ¢Ã÷ÒøÐÐľÂíMispaduµÄ´ó¹æÄ£¹¥»÷»î¶¯


¾ÝýÌå3ÔÂ20Èճƣ¬£¬£¬Ñо¿ÍŶӷ¢Ã÷ÁË20¸öÕë¶ÔÖÇÀû¡¢Ä«Î÷¸ç¡¢ÃØÂ³ºÍÆÏÌÑÑÀµÄ´ó¹æÄ£À¬»øÓʼþ»î¶¯¡£¡£¡£ ¡£¡£¡£»£»£»£» £»£»î¶¯ÓÚ2022Äê8ÔÂ×óÓÒ×îÏÈ£¬£¬£¬×èÖ¹2023Äê3ÔÂÉÏÑ®ÈÔÈ»»îÔ¾¡£¡£¡£ ¡£¡£¡£ÕâЩ»î¶¯ÒÀÀµÓÚÒøÐÐľÂíMispadu£¬£¬£¬ÊÓ²ìЧ¹ûÏÔʾ£¬£¬£¬¹¥»÷ÕßÒÑ´Ó×ܹ²17595¸öÆæÒìÍøÕ¾ÖÐÇÔÈ¡ÁË90518¸öƾ֤¡£¡£¡£ ¡£¡£¡£Mispadu½ÓÄÉÁËÔö½øÑ¬È¾ºÍ¼á³Ö³¤ÆÚÐÔµÄÐÂÊÖÒÕ£¬£¬£¬°üÀ¨ÓÃÓÚ»ìÏý³õʼ½×¶Î¶ñÒâÈí¼þµÄαÔìÖ¤ÊéºÍÒ»¸öеĻùÓÚ.NETµÄºóÃÅ¡£¡£¡£ ¡£¡£¡£


https://www.infosecurity-magazine.com/news/mispadu-steals-90000-banking/


3¡¢Lowe's MarketϵͳÉèÖùýʧ´ó×ÚÆ¾Ö¤ºÍ¿Í»§ÐÅϢй¶


ýÌå3ÔÂ17ÈÕ͸¶£¬£¬£¬Ñо¿Ö°Ô±ÔÚLowe's MarketÍøÕ¾ÉÏ·¢Ã÷ÁËÒ»¸ö¿É¹ûÕæ»á¼ûµÄÇéÐÎÎļþ(.env)¡£¡£¡£ ¡£¡£¡£Õâ¶Ô¹«Ë¾ÏµÍ³µÄÇå¾²×é³ÉÁËΣº¦£¬£¬£¬ÓÉÓÚËüй¶ÁË´ó×ÚÆ¾Ö¤¡£¡£¡£ ¡£¡£¡£¸ÃÇéÐÎÎļþй¶ÁËAWS S3ЧÀÍÆ÷µÄ»á¼ûÃÜÔ¿ºÍ´æ´¢Í°Ãû³Æ£¬£¬£¬Ðí¶àרÓÃÓÚÌØ¶¨ÍøÕ¾¹¦Ð§µÄÓ¦ÓóÌÐò±à³Ì½Ó¿Ú(API)ÃÜÔ¿£¬£¬£¬ÒÔ¼°Facebook OAuthƾ֤ºÍGithub OAuthÁîÅÆµÈÐÅÏ¢¡£¡£¡£ ¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖ£¬£¬£¬Ð¹Â¶µÄƾ֤¿É±»¹¥»÷ÕßÓÃÓÚ¿ØÖƴ󲿷ÖÔÚÏßÊÐËÁµÄ¹¦Ð§£¬£¬£¬Éó²é¿Í»§ÐÅÏ¢£¬£¬£¬²¢ÀÄÓø¶·ÑЧÀ͵Ļá¼ûȨÏÞ¡£¡£¡£ ¡£¡£¡£ÏÖÔÚ£¬£¬£¬¸ÃÎÊÌâÒѾ­±»½â¾ö¡£¡£¡£ ¡£¡£¡£


https://cybernews.com/security/lowes-market-data-leak/


4¡¢ÈÕÁ¢ÄÜÔ´ÒòµÚÈý·½Èí¼þÌṩÉÌÔâµ½CLOP¹¥»÷Êý¾Ýй¶


3ÔÂ17ÈÕ±¨µÀ£¬£¬£¬ÈÕÁ¢ÄÜÔ´µÄÉùÃ÷³Æ£¬£¬£¬µÚÈý·½Èí¼þÌṩÉÌFORTRA GoAnywhere MFTÔâµ½ÁËCLOPµÄÀÕË÷¹¥»÷£¬£¬£¬¿ÉÄܵ¼ÖÂÔÚijЩ¹ú¼Ò/µØÇøµÄÔ±¹¤Êý¾Ý±»²»·¨»á¼û¡£¡£¡£ ¡£¡£¡£¸Ã¹¥»÷ÊÇͨ¹ýʹÓÃGoAnywhere MFTÖеÄÎó²î£¨CVE-2023-0669£©ÊµÏֵ쬣¬£¬¸ÃÎó²îÓÚ2023Äê2ÔÂ3ÈÕÊ×´ÎÅû¶¡£¡£¡£ ¡£¡£¡£ÈÕÁ¢ÄÜÔ´³ÆÆäÁ¬Ã¦¶Ô¸ÃÊÂÎñ×÷³ö·´Ó¦£¬£¬£¬¶Ï¿ªÁËÊÜѬȾϵͳµÄÅþÁ¬£¬£¬£¬²¢Æô¶¯ÄÚ²¿ÊÓ²ìÒÔÈ·¶¨Î¥¹æµÄÓ°Ïì¡£¡£¡£ ¡£¡£¡£¸Ã¹«Ë¾Ö¸³ö£¬£¬£¬ÆäÍøÂçÔËÓª»ò¿Í»§Êý¾ÝµÄÇå¾²²¢Î´Êܵ½Ó°Ïì¡£¡£¡£ ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/hitachi-energy-confirms-data-breach-after-clop-goanywhere-attacks/


5¡¢KasperskyÐû²¼»ùÓÚContiµÄMeowCorpÀÕË÷Èí¼þ½âÃÜÆ÷


ýÌå3ÔÂ16Èճƣ¬£¬£¬KasperskyÐû²¼ÁË»ùÓÚContiµÄÀÕË÷Èí¼þMeowCorpµÄÃ⺬»ìÃÜÆ÷¡£¡£¡£ ¡£¡£¡£2023Äê2ÔÂÏÂÑ®£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ÁËÂÛ̳ÉÏÐû²¼µÄÒ»²¿·ÖеÄÊý¾Ý¡£¡£¡£ ¡£¡£¡£ÆÊÎöºó·¢Ã÷ËüÃÇÓë2022Äê12Ô·¢Ã÷µÄ Conti±äÖÖMeowCorpÓйØ¡£¡£¡£ ¡£¡£¡£ÔÚ¶Ô°üÀ¨258¸ö˽Կ¡¢Ô´´úÂëºÍһЩԤ±àÒë½âÃÜÆ÷µÄÊý¾Ý¾ÙÐÐÆÊÎöºó£¬£¬£¬KasperskyÐû²¼ÁËа汾µÄ¹«¹²½âÃÜÆ÷¡£¡£¡£ ¡£¡£¡£½âÃÜÆ÷¿ÉÒÔ»Ö¸´ÃüÃûģʽºÍÀ©Õ¹ÃûΪ<file_name>.KREMLIN¡¢<file_name>.RUSSIAºÍ<file_name>.PUTINµÄ¼ÓÃÜÎļþ¡£¡£¡£ ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/conti-based-ransomware-meowcorp-gets-free-decryptor/


6¡¢RedactedÐû²¼¹ØÓÚÀÕË÷ÍÅ»ïBianLianµÄÆÊÎö±¨¸æ


3ÔÂ16ÈÕ£¬£¬£¬RedactedÐû²¼ÁËÀÕË÷ÍÅ»ïBianLianÉú³¤Ç÷ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£ ¡£¡£¡£BianLianÓÚ2022Äê7ÔÂÊ×´ÎÔÚÒ°Íâ·ºÆð£¬£¬£¬AvastÔÚ2023Äê1ÔÂÐû²¼ÁËÃ⺬»ìÃÜÆ÷¡£¡£¡£ ¡£¡£¡£×èÖ¹2023Äê3ÔÂ13ÈÕ£¬£¬£¬¸ÃÍÅ»ïÔÚÆäÍøÕ¾ÉÏÁгöÁË×ܹ²118¸ö×éÖ¯£¬£¬£¬ÆäÖоø´ó´ó¶¼(71%)ÊÇÃÀ¹ú¹«Ë¾¡£¡£¡£ ¡£¡£¡£ÔÚ×î½üµÄ¹¥»÷ÖеÄÖ÷񻂿±ðÊÇ£¬£¬£¬BianLianÒѽ«ÆäÖØµã´Ó¼ÓÃÜÄ¿µÄÊý¾Ý×ªÒÆµ½½öÇÔȡϵͳÖÐÊý¾Ý²¢¾ÙÐÐÀÕË÷¡£¡£¡£ ¡£¡£¡£ÏÖÔÚÉв»ÇåÎúBianLian·ÅÆú¼ÓÃÜÕ½ÂÔÊÇÓÉÓÚAvastµÄ½âÃÜÆ÷£¬£¬£¬ÕÕ¾ÉÓÉÓÚÒâʶµ½²»ÐèÒªÕâÒ»²¿·ÖÀ´ÀÕË÷Êê½ð¡£¡£¡£ ¡£¡£¡£


https://redacted.com/blog/bianlian-ransomware-gang-continues-to-evolve/