°®¶ûÀ¼¹ú¼Ò¾¯¾ÖµÄ³Ð°üÉÌй¶50ÍòÌõ¿ÛѺ³µÁ¾µÄ¼Í¼

Ðû²¼Ê±¼ä 2023-10-25

1¡¢°®¶ûÀ¼¹ú¼Ò¾¯¾ÖµÄ³Ð°üÉÌй¶50ÍòÌõ¿ÛѺ³µÁ¾µÄ¼Í¼


¾Ý10ÔÂ23ÈÕ±¨µÀ£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸ö¹ûÕæµÄÊý¾Ý¿â£¬£¬£¬£¬°üÀ¨Áè¼Ý50ÍòÌõÓë°®¶ûÀ¼¹ú¼Ò¾¯¾ÖGarda S¨ªoch¨¢na¿ÛѺ³µÁ¾Ïà¹ØµÄ¼Í¼¡£¡£¡£¡£¡£Îĵµ×ÜÊýΪ521043¸ö£¬£¬£¬£¬¾ÞϸΪ271.8 GB¡£¡£¡£¡£¡£Æ¾Ö¤°®¶ûÀ¼Ö´·¨£¬£¬£¬£¬µ±³µÁ¾±»¿ÛѺʱ£¬£¬£¬£¬³µÖ÷Ðë³öʾÉí·Ý֤ʵºÍ°ü¹ÜÎļþµÈ¶à·ÝÎļþ£¬£¬£¬£¬Òò´Ëй¶µÄ50Íò·ÝÎĵµ¿ÉÄÜÓ°ÏìÁËÔ¼15ÍòÃû³µÖ÷¡£¡£¡£¡£¡£½øÒ»³ÌÐò²éÏÔʾ£¬£¬£¬£¬¸ÃÊý¾Ý¿âÊôÓÚ°®¶ûÀ¼ÀûĬÀï¿ËµÄÒ»¼Ò˽ÈËÊÖÒճаüÉÌ¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬Ð¹Â¶Êý¾ÝÒѱ»±£»£»¤ÆðÀ´¡£¡£¡£¡£¡£


https://www.hackread.com/contractor-data-breach-irish-national-police-vehicle-seizure/


2¡¢ºÚ¿ÍÒÔ8ÍòÃÀÔª¼ÛÇ®³öÊÛ8.15ÒÚÌõÓ¡¶È¹«ÃñµÄPII¼Í¼


ýÌå10ÔÂ24Èճƣ¬£¬£¬£¬ºÚ¿ÍÔÚ°µÍø³öÊÛÊýÒÚÌõÓ¡¶È¹«ÃñµÄPII¼Í¼£¬£¬£¬£¬°üÀ¨Aadhaar¿¨¡£¡£¡£¡£¡£AadhaarÊÇÒ»¸ö12λµÄСÎÒ˽¼Òʶ±ðÂ룬£¬£¬£¬ÓÉÓ¡¶ÈΨһÉí·Ýʶ±ð»ú¹¹´ú±íÓ¡¶ÈÕþ¸®½ÒÏþ¡£¡£¡£¡£¡£10ÔÂ9ÈÕ£¬£¬£¬£¬ÃûΪpwn0001µÄºÚ¿ÍÔÚ°µÍøÐû²¼ÁËÒ»¸öÌû×Ó£¬£¬£¬£¬³ÆÓµÓÐ8.15ÒÚÓ¡¶È¹«ÃñAadhaarºÍ»¤Õռͼ£¬£¬£¬£¬²¢Ô¸ÒâÒÔ80000ÃÀÔªµÄ¼ÛÇ®³öÊÛÕû¸öÊý¾Ý¿â¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬pwn0001»¹¹ûÕæÁË4¸öÑù±¾£¬£¬£¬£¬ÆäÖÐÒ»¸öÑù±¾°üÀ¨100000ÌõÓ¡¶ÈסÃñµÄPII¡£¡£¡£¡£¡£


https://securityaffairs.com/152957/security/pii-indian-citizens-dark-web.html


3¡¢BHI EnergyÏêÊöAkiraÔõÑùÈëÇÖÆäϵͳ²¢ÇÔÈ¡Êý¾Ý


¾ÝýÌå10ÔÂ23ÈÕ±¨µÀ£¬£¬£¬£¬ÃÀ¹úÄÜÔ´¹«Ë¾BHI EnergyÅû¶ÁËAkiraÔÚ5ÔÂ30ÈÕÈëÇÖÆäϵͳµÄÏêϸÐÅÏ¢¡£¡£¡£¡£¡£AkiraʹÓÃÇÔÈ¡µÄµÚÈý·½µÄVPNƾ֤»á¼ûBGIµÄÄÚÍø£¬£¬£¬£¬ÔÚÊ״λá¼ûºóµÄÒ»ÖÜÄÚʹÓÃͳһ¸öÕË»§¶ÔÄÚÍø¾ÙÐÐÕì̽¡£¡£¡£¡£¡£6ÔÂ16ÈÕ£¬£¬£¬£¬AkiraÔٴλá¼ûϵͳ£¬£¬£¬£¬Ã¶¾ÙÊý¾Ý£¬£¬£¬£¬²¢ÔÚ6ÔÂ20ÈÕÖÁ29ÈÕÇÔÈ¡ÁË767k¸öÎļþ£¬£¬£¬£¬¹²690 GB£¬£¬£¬£¬°üÀ¨Windows Active DirectoryÊý¾Ý¿â¡£¡£¡£¡£¡£×îºó£¬£¬£¬£¬¹¥»÷ÕßÓÚ6ÔÂ29ÈÕÇÔÈ¡ÁËËùÓÐÊý¾Ýºó£¬£¬£¬£¬ÔÚËùÓÐ×°±¸ÉÏ×°ÖÃÁËAkiraÀÕË÷Èí¼þÀ´¼ÓÃÜÎļþ¡£¡£¡£¡£¡£Õâʱ£¬£¬£¬£¬BHI²ÅÒâʶµ½¹«Ë¾Òѱ»ÈëÇÖ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/us-energy-firm-shares-how-akira-ransomware-hacked-its-systems/


4¡¢Î÷°àÑÀ¾¯·½µ·»ÙÄ³ÍøÂçÕ©Æ­ÍŻﲢ¾Ð²¶34ÃûÏÓÒÉÈË


10ÔÂ24ÈÕ±¨µÀ£¬£¬£¬£¬Î÷°àÑÀ¹ú¼Ò¾¯Ô±¾Öµ·»ÙÁËÒ»¸öÍøÂç·¸·¨ÍŻ¡£¡£¡£¡£¸ÃÍÅ»ïÖ´ÐÐÖÖÖÖÅÌËã»úÕ©Æ­£¬£¬£¬£¬ÇÔÈ¡ÁËÁè¼Ý400ÍòÈ˵ÄÊý¾Ý£¬£¬£¬£¬×¬È¡ÁËÔ¼300ÍòÅ·Ôª¡£¡£¡£¡£¡£Ö´·¨²¿·ÖÔÚÂíµÂÀï¡¢ÂíÀ­¼Ó¡¢Î¤¶ûÍß¡¢°¢Àû¿²ÌغÍĶûÎ÷ÑǾÙÐÐÁË16´ÎÓÐÕë¶ÔÐÔµÄËѲ飬£¬£¬£¬ÒѾв¶34Ãû·¸·¨ÍÅ»ïµÄ³ÉÔ±¡£¡£¡£¡£¡£¾¯·½³Æ£¬£¬£¬£¬±»²¶ÕßÓëð³ä¿ìµÝ¹«Ë¾ºÍµçÁ¦¹©Ó¦É̵Ĵ¹ÂڻÓйØ¡£¡£¡£¡£¡£¸ÃÍÅ»ïµÄÍ·Ä¿Òѱ»¾Ð²¶£¬£¬£¬£¬¶ÔÆäËû³ÉÔ±Éí·ÝµÄÊÓ²ìÈÔÔÚ¾ÙÐÐÖС£¡£¡£¡£¡£


https://securityaffairs.com/152946/cyber-crime/spanish-police-dismantled-cybercriminal-group.html


5¡¢Ñо¿Ö°Ô±Ðû²¼VMwarevÎó²îCVE-2023-34051µÄPoC


ýÌå10ÔÂ24Èճƣ¬£¬£¬£¬VMwarevÌáÐÑvRealize Log Insight£¨ÏÖ³ÆÎªVMware Aria Operations for Logs£©ÖÐÎó²îµÄPoCÒÑÐû²¼¡£¡£¡£¡£¡£ÕâÊÇÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2023-34051£©£¬£¬£¬£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔ½«Îļþ×¢ÈëÄ¿µÄϵͳÖУ¬£¬£¬£¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£Horizon3Ðû²¼ÁËPoC£¬£¬£¬£¬ËüʹÓÃIPµØµãÓÕÆ­ºÍÖÖÖÖThrift RPC¶ËµãÀ´ÊµÏÖí§ÒâÎļþдÈë¡£¡£¡£¡£¡£Ñо¿Ö°Ô±½¨ÒéÁ¬Ã¦×°ÖøüС£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/vmware-warns-admins-of-public-exploit-for-vrealize-rce-flaw/


6¡¢KasperskyÐû²¼Triangulation»î¶¯µÄÒþ²ØÐԵı¨¸æ


10ÔÂ23ÈÕ£¬£¬£¬£¬KasperskyÐû²¼Á˹ØÓÚTriangulation»î¶¯µÄÒþ²ØÐÔµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¸Ã±¨¸æÏÈÈÝÁ˴˴ι¥»÷µÄÖÖÖÖÒþÐÎÊÖÒÕ£¬£¬£¬£¬ÒÔ¼°¹¥»÷ÖÐʹÓõÄ×é¼þ¡£¡£¡£¡£¡£ÔÚ°²ÅÅTriangleDB֮ǰ£¬£¬£¬£¬»áʹÓÃÁ½¸öÑéÖ¤Æ÷À´ÍøÂç×°±¸ÐÅÏ¢£¬£¬£¬£¬²¢È·±£´úÂë²»»áÔÚÆÊÎöÇéÐÎÖÐÖ´ÐС£¡£¡£¡£¡£Ëü»¹°üÀ¨Ò»¸öÂó¿Ë·ç¼ÒôÄ£¿£¿£¿émsu3h£¬£¬£¬£¬Ä¬ÈÏ¿ÉÒÔ¼ÒôÈý¸öСʱ£¬£¬£¬£¬µ«ÈôÊǵçÁ¿µÍÓÚ10%ÇÒ×°±¸ÆÁÄ»ÕýÔÚʹÓý«ÔÝͣ¼Òô¡£¡£¡£¡£¡£¹¥»÷Õß»¹ÊµÑéÁËÌØÁíÍâÔ¿³×´®Ð¹Â¶Ä£¿£¿£¿é¡¢SQLiteÊý¾Ý¿âÇÔÈ¡¹¦Ð§ÒÔ¼°Î»ÖÃ¼à¿ØÄ£¿£¿£¿é£¨ÔÚGPS²»¿ÉÓÃʱʹÓÃÍøÂçÔªÊý¾Ý£©¡£¡£¡£¡£¡£


https://securelist.com/triangulation-validators-modules/110847/