΢ÈíÓ¡¶ÈXÕË»§±» Roaring Kitty ¼ÓÃÜÇ®±ÒȦÌ×Ð®ÖÆ

Ðû²¼Ê±¼ä 2024-06-05
1. ΢ÈíÓ¡¶ÈXÕË»§±» Roaring Kitty ¼ÓÃÜÇ®±ÒȦÌ×Ð®ÖÆ


6ÔÂ3ÈÕ£¬£¬ÓµÓÐÁè¼Ý 211,000 Ãû¹Ø×¢ÕßµÄ΢ÈíÓ¡¶È¹Ù·½ Twitter Õ˺ű»¼ÓÃÜÇ®±ÒÆ­×ÓÐ®ÖÆ£¬£¬²¢Ã°³äÎÛÃûÕÑÖøµÄÄ£Òò¹ÉƱÉúÒâÔ± Keith Gill ʹÓõÄÓû§Ãû Roaring Kitty¡£¡£Î¢ÈíÓ¡¶ÈµÄ X ÕË»§×÷Ϊ¸Ãƽ̨ÉϹٷ½ÈÏÖ¤µÄ×éÖ¯£¬£¬ÓµÓлƽð֧Ʊ£¬£¬ÕâʹµÃÐ®ÖÆÕßµÄÌû×Ó¸ü¾ßÕýµ±ÐÔ¡£¡£ÍþвÐÐΪÕßʹÓà Gill ×î½üµÄ¸´³öÀ´ÒýÓÕDZÔÚÊܺ¦Õߣ¬£¬²¢ÓüÓÃÜÇ®±ÒÇ®°üºÄ¾¡¶ñÒâÈí¼þѬȾËûÃÇ¡£¡£ËûÃÇÏÖÔÚʹÓñ»Ð®ÖƵÄ΢ÈíÓ¡¶ÈÕË»§»Ø¸´ÍÆÎÄ£¬£¬ÓÕÆ­¸Ã¹«Ë¾µÄ¹Ø×¢ÕßºÍ X ÉÏµÄÆäËûÈ˽øÈëÒ»¸ö¶ñÒâÍøÕ¾ (presaIe-roaringkitty[.]com)£¬£¬¾Ý³Æ¸ÃÍøÕ¾ÔÊÐíËûÃǹºÖà GameStop (GME) ¼ÓÃÜÇ®±Ò×÷ΪËùνԤÊÛµÄÒ»²¿·Ö¡£¡£È»¶ø£¬£¬ÍþвÐÐΪÕß»áÇÔÈ¡Èκν«¼ÓÃÜÇ®±ÒÇ®°üÅþÁ¬µ½¸ÃÍøÕ¾²¢ÊÚȨºÄ¾¡Ð§À;ÙÐÐÉúÒâµÄÈ˵Ä×ʲú¡£¡£Ðí¶à»úеÈËÕË»§ÏÖÔÚÒ²ÔÚת·¢±»Ð®ÖÆÕË»§µÄÍÆÎÄ£¬£¬ÕâÖÖÕ½ÂÔÖ¼ÔÚÈËΪµØÔöÌí¶ñÒâÌû×ÓµÄÁýÕÖÃæ²¢ÓÕ²¶¸ü¶àÊܺ¦Õß¡£¡£


https://www.bleepingcomputer.com/news/security/microsoft-indias-x-account-hijacked-in-roaring-kitty-crypto-scam-to-push-wallet-drainers/


2. Æ­×ÓÍþвй¶´ÓÅä¾°ÊӲ칫˾ÇÔÈ¡µÄÊýÒÚÌõ¼Í¼


6ÔÂ3ÈÕ£¬£¬¾Ý³Æ£¬£¬·ðÂÞÀï´ïÖÝÒ»¼ÒÈÏÕæÅä¾°ÊÓ²ìºÍÆäËûСÎÒ˽¼ÒÐÅÏ¢ÇëÇóµÄ¹«Ë¾»ñÈ¡ÁËÊýÊ®ÒڷݼͼÈËÃÇСÎÒ˽¼ÒÐÅÏ¢µÄ¼Í¼£¬£¬ÕâЩ¼Í¼¿ÉÄܺܿì¾Í»á±»Ð¹Â¶µ½ÍøÉÏ¡£¡£Ò»¸ö×Ô³Æ USDoD µÄ·¸·¨ÍÅ»ïÓÚ 4 ÔÂÔÚµØÏÂÂÛ̳ÉÏÒÔ350 ÍòÃÀÔªµÄ¼ÛÇ®³öÊÛ¸ÃÊý¾Ý¿â£¬£¬²¢ÁîÈËÄÑÒÔÖÃÐŵÄÊÇÉù³Æ¸ÃÊý¾Ý¿â°üÀ¨ 29 ÒÚÌõÃÀ¹ú¡¢¼ÓÄôóºÍÓ¢¹ú¹«ÃñµÄ¼Í¼¡£¡£¾ÝÐÅ£¬£¬Ò»Ãû»ò¶àÃû×Ô³Æ SXUL µÄ·¸·¨ÍÅ»ï¶Ô´Ë´ÎËùνµÄÊý¾Ýй¶ÊÂÎñ¸ºÓÐÔðÈΣ¬£¬ËûÃǽ«Êý¾Ýй¶ÊÂÎñ½»¸øÁ˳䵱ÖÐÐÄÈ赀 USDoD¡£¡£¾Ý³Æ£¬£¬±»µÁÐÅÏ¢°üÀ¨Ð¡ÎÒ˽¼ÒÈ«Ãû¡¢µØµãºÍÖÁÉÙ 30 ÄêǰµÄµØµãÀúÊ·¡¢Éç»áÇå¾²ºÅÂëÒÔ¼°ÈËÃǵÄâïÊÑ¡¢ÐֵܽãÃúÍÇׯÝ£¬£¬ÆäÖÐһЩÈËÒѾ­È¥ÊÀ½ü 20 Äê¡£¡£¾ÝÃÀ¹ú¹ú·À²¿³Æ£¬£¬ÕâЩÐÅÏ¢²¢·Ç´Ó¹«¹²ÈªÔ´×¥È¡µÄ£¬£¬Ö»¹ÜÊý¾Ý¿âÖпÉÄܱ£´æÖظ´µÄÌõÄ¿¡£¡£


https://www.theregister.com/2024/06/03/usdod_data_dump/


3. Telegram ÉÏй¶µÄ 3.61 ÒÚ¸ö±»µÁÕË»§±»Ìí¼Óµ½ HIBP


6ÔÂ3ÈÕ£¬£¬´ó×Ú 3.61 ÒÚ¸öµç×ÓÓʼþµØµã±»Ìí¼Óµ½ Have I Been Pwned Êý¾Ýй¶֪ͨЧÀÍÖУ¬£¬ÕâЩµØµãÀ´×Ôͨ¹ýÃÜÂëÇÔÈ¡¶ñÒâÈí¼þ¡¢Æ¾Ö¤Ìî³ä¹¥»÷ºÍÊý¾Ýй¶ÇÔÈ¡µÄƾ֤£¬£¬ÈκÎÈ˶¼¿ÉÒÔ¼ì²éËûÃǵÄÕÊ»§ÊÇ·ñÒѱ»Ð¹Â¶¡£¡£ÍøÂçÇå¾²Ñо¿Ö°Ô±´ÓÖÚ¶à Telegram ÍøÂç·¸·¨ÆµµÀÍøÂçÁËÕâЩƾ֤£¬£¬ÕâЩ±»µÁÊý¾Ýͨ³£±»Ð¹Â¶¸øÆµµÀµÄÓû§ÒÔ½¨ÉèÉùÓþºÍ¶©ÔÄÕß¡£¡£±»µÁÊý¾Ýͨ³£ÒÔÓû§ÃûºÍÃÜÂë×éºÏ£¨Í¨³£Í¨¹ýƾ֤Ìî³ä¹¥»÷»òÊý¾Ýй¶ÇÔÈ¡£¡£©¡¢Óû§ÃûºÍÃÜÂëÒÔ¼°ÓëÖ®Ïà¹ØµÄ URL£¨Í¨¹ýÇÔÈ¡ÃÜÂëµÄ¶ñÒâÈí¼þÇÔÈ¡£¡£©ºÍԭʼ cookie£¨Í¨¹ýÇÔÈ¡ÃÜÂëµÄ¶ñÒâÈí¼þÇÔÈ¡£¡£©µÄÐÎʽй¶¡£¡£¸ÃÑо¿Ö°Ô±ÒªÇó BleepingComputer ¼á³ÖÄäÃû£¬£¬ËûÃÇÓë Have I Been Pwned µÄËùÓÐÕß Troy Hunt ·ÖÏíÁË´Ó¶à¸ö Telegram ƵµÀÍøÂçµÄ 122 GB ƾ֤¡£¡£ÕâЩÊý¾ÝºÜÊÇÖØ´ó£¬£¬°üÀ¨ 3.61 ÒÚ¸öΨһµÄµç×ÓÓʼþµØµã£¬£¬ÆäÖÐ 1.51 ÒÚ¸öµØµãÒÔǰ´Óδ±»Êý¾Ýй¶֪ͨЧÀͼû¹ý¡£¡£


https://www.bleepingcomputer.com/news/security/361-million-stolen-accounts-leaked-on-telegram-added-to-hibp/


4. ÍþвÕßÉù³Æ³öÊÛ°üÀ¨1700ÍòÓû§¼Í¼µÄPandabuyÊý¾Ý¿â


6ÔÂ3ÈÕ£¬£¬¾Ý±¨µÀ£¬£¬±»µÁÊý¾Ý¿â°üÀ¨¶à´ï 1700 ÍòÐÐÓû§¼Í¼£¬£¬º­¸ÇÃû×Ö¡¢ÐÕÊÏ¡¢Óû§ ID¡¢µç×ÓÓʼþ¡¢¶©µ¥Êý¾Ý¡¢IP µØµã¡¢¹ú¼Ò¡¢ÃÜÂëµÈÃô¸ÐÐÅÏ¢¡£¡£ÍþвÕß Sanggiero ÒÑ¾ÍÆäÒâͼ½ÒÏþÉùÃ÷¡£¡£ËûÃÇÉù³Æ£¬£¬ÓÃÓÚÆÆËð Pandabuy ·ÀÓùϵͳµÄÎó²î£¨¾Ý³Æ¸Ã¹«Ë¾ÉÐδ½â¾ö£©½«ºÜ¿ìÔÚÆä²©¿ÍÍøÕ¾ÉÏÐû²¼¡£¡£±ðµÄ£¬£¬ËûÃÇ»¹Ðû²¼ÍýÏëÅû¶ Pandabuy Ô±¹¤µÄÐÕÃûºÍÃÜÂ룬£¬Ö»¹ÜÊÇÒÔʹÓà base-64 ¼ÓÃܵıàÂëÐÎʽ¡£¡£ÍþвÕßÖÒÑÔ Pandabuy ÈÔÓпÉÄܾÙÐÐ̸ÅУ¬£¬µ«Ê±¼äδ¼¸ÁË¡£¡£ËûÃÇΪ±»µÁÊý¾Ý¿â¿ª³öÁË 40,000 ÃÀÔªµÄ¸ß¼Û£¬£¬Åú×¢ËûÃÇ×¼±¸½«ÇÔÈ¡µÄÊý¾ÝÂô¸ø³ö¼Û×î¸ßµÄÈË¡£¡£


https://dailydarkweb.net/threat-actor-claims-to-sell-pandabuy-database-with-17-million-user-records/


5. Discord¶ñÒâÈí¼þ¹¥»÷¼¤Ôö£¬£¬·¢Ã÷50000¸ö¶ñÒâÁ´½Ó


6ÔÂ3ÈÕ£¬£¬ÔÚ×î½üÁù¸öÔÂµÄÆÊÎöÖУ¬£¬ÍøÂçÇå¾²¹«Ë¾ Bitdefender ·¢Ã÷ÁËÒ»¸öÁîÈ˵£ÐĵÄÇ÷ÊÆ£ºÍøÂç·¸·¨·Ö×ÓÕýÔÚʹÓÃÊ¢ÐеÄͨѶƽ̨ Discord À´Èö²¥¶ñÒâÈí¼þ²¢Ö´ÐÐÍøÂç´¹Âڻ¡£¡£Bitdefender ÔÚ 2024 Äê 29 ÈÕÐÇÆÚÈýÐû²¼Ö®Ç°Óë Hackread.com ·ÖÏíÁ˸ñ¨¸æ£¬£¬ÆäÖÐÖØµãÏÈÈÝÁË Discord ÉÏ·¢Ã÷µÄ 50,000 ¶à¸ö¶ñÒâÁ´½Ó£¬£¬ÏÔʾ³ö¸Ãƽ̨ԽÀ´Ô½ÈÝÒ×Êܵ½ÍøÂçÍþв¡£¡£¶ñÒâÈí¼þºÍÍøÂç´¹ÂÚÁ´½ÓÕ¼¼ì²âµ½µÄ¶ñÒâÁ´½ÓµÄ 39%¡£¡£ÕâЩ¹¥»÷ͨ³£Éæ¼°ÓÕÆ­ÊֶΣ¬£¬ÓÕÆ­Óû§ÏÂÔØÓк¦Èí¼þ»òÌṩÃô¸ÐÐÅÏ¢¡£¡£ÃÀ¹úÓû§ÓÈÆäÈÝÒ×Êܵ½¹¥»÷£¬£¬Õ¼ÍþвµÄ 16.2%¡£¡£ÕâʹËûÃdzÉΪ×îÈÝÒ×Êܵ½¹¥»÷µÄȺÌ壬£¬²¢ÇÒÕ¼±ÈÏÔÖø¡£¡£Í¨¹ý Discord Ìᳫ¶ñÒâ¹¥»÷µÄÆäËû¹ú¼Ò»¹°üÀ¨·¨¹ú¡¢ÂÞÂíÄáÑÇ¡¢Ó¢¹úºÍµÂ¹ú¡£¡£


https://hackread.com/discord-malware-attacks-as-50000-malicious-links/


6. ÔÆ´æ´¢ Hudson Rock ÆðËßÐÅÏ¢Çå¾²»ú¹¹ Snowflake


6ÔÂ4ÈÕ£¬£¬ÐÅÏ¢Çå¾²»ú¹¹±¨¸æ³Æ£¬£¬·¸·¨·Ö×ÓʹÓÃÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ»ñÈ¡ÁË Snowflake Ô±¹¤µÄÊÂÇ鯾֤£¬£¬²¢Ê¹ÓøÃÌØÈ¨»á¼ûȨÏÞ´Ó Snowflake µÄ¿Í»§ÔÆÕÊ»§ÖÐÇÔÈ¡ÁË´ó×ÚÊý¾Ý¡£¡£Snowflake ÌåÏÖ£¬£¬ÕâÖÖÇéÐβ¢Ã»Óб¬·¢¡£¡£ÖÁÉÙTicketmasterºÍSantander ÒøÐеÄÐÅϢȷʵ±»µÁÁË£¬£¬Ö»¹Ü¹Ù·½ÉÐδ֪ÏþÏêϸÊÇÔõÑù±»µÁµÄ£¬£¬ÒÔ¼°´ÓÄÇÀï±»µÁµÄ£»£»£» £»ÕâÁ½¼ÒÒøÐж¼ÊÇ Snowflake µÄ¿Í»§¡£¡£¾Ý±¨µÀ£¬£¬Ticketmaster µÄһλýÌå´ú±í¸æËßTechCrunch£¬£¬Æä±»µÁÊý¾ÝÓÉ Snowflake ÍйÜ¡£¡£Snowflake ÌåÏÖ£¬£¬ÈôÊÇÓÐÈκοͻ§Êý¾Ý´ÓÆäЧÀÍÆ÷Öб»ÇÔÈ¡£¬£¬ÄÇôÕâЩÊý¾Ý¿ÉÄÜÊDZ»ÇÔÔôͨ¹ýÓÐÕë¶ÔÐÔµÄÍøÂç´¹ÂÚ¡¢ÆäËûйÃÜ»ò¶ñÒâÈí¼þµÈ·½·¨»ñÈ¡ÁËСÎÒ˽¼Ò¿Í»§µÄÕË»§Æ¾Ö¤¶ø»ñµÃµÄ£¬£¬¶ø²»ÊÇͨ¹ý¶Ô Snowflake Çå¾²ÐÔµÄÆÕ±éÆÆËð¶ø»ñµÃµÄ¡£¡£ÊÂʵÉÏ£¬£¬Snowflake ÒÔΪ£¬£¬Æä¡°ÓÐÏÞ¡±ÊýÄ¿ÉÐδ͸¶ÐÕÃûµÄ¿Í»§µÄÊý¾Ý¿ÉÄÜȷʵ±»ÇÔÈ¡µÄÕË»§Æ¾Ö¤»á¼û£¬£¬¶øÕâЩÕË»§²¢Ã»ÓÐÆôÓÃË«ÒòËØÉí·ÝÑéÖ¤¡£¡£


https://www.theregister.com/2024/06/04/snowflake_report_pulled/