ºÉÀ¼º½Ô˹«Ë¾Royal DirkzwagerÔâµ½PlayµÄÀÕË÷¹¥»÷

Ðû²¼Ê±¼ä 2023-03-21

1¡¢ºÉÀ¼º½Ô˹«Ë¾Royal DirkzwagerÔâµ½PlayµÄÀÕË÷¹¥»÷


¾Ý3ÔÂ20ÈÕ±¨µÀ£¬£¬ £¬£¬£¬ºÉÀ¼º½Ô˹«Ë¾Royal DirkzwagerÔâµ½ÀÕË÷ÍÅ»ïPlayµÄ¹¥»÷¡£¡£¡£¡£¡£ÀÕË÷ÍŻォ¸Ã¹«Ë¾Ìí¼Óµ½ÆäÍøÕ¾ÉÏ£¬£¬ £¬£¬£¬²¢Ðû²¼ÇÔÈ¡ÁËÔ±¹¤ ID¡¢»¤ÕÕºÍÌõÔ¼µÈÉñÃØÊý¾Ý¡£¡£¡£¡£¡£¸ÃÍÅ»ï×î³õ¹ûÕæÁËÒ»¸ö5 GBµÄÎļþ×÷Ϊ¹¥»÷Ö¤¾Ý£¬£¬ £¬£¬£¬²¢Íþв˵£¬£¬ £¬£¬£¬ÈôÊǹ«Ë¾²»¸¶Êê½ð¾Í¹ûÕæËùÓеÄÊý¾Ý¡£¡£¡£¡£¡£¸Ãº½Ô˹«Ë¾ÌåÏÖ£¬£¬ £¬£¬£¬¹¥»÷»î¶¯²¢Î´Ó°Ï칫˾µÄÔËÓª£¬£¬ £¬£¬£¬²¢Ö¤Êµ¹¥»÷ÕßÒѾ­´ÓÆä»ù´¡ÉèÊ©ÖÐÇÔÈ¡ÁËÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¸Ã¹«Ë¾Òѽ«´ËÊÂ֪ͨÁ˺ÉÀ¼Êý¾Ý±£»£»£»£»¤¾Ö£¬£¬ £¬£¬£¬²¢ÕýÔÚÓëÀÕË÷ÍÅ»ï¾ÙÐÐ̸ÅС£¡£¡£¡£¡£


https://securityaffairs.com/143714/cyber-crime/play-ransomware-royal-dirkzwager.html


2¡¢Ñо¿ÍŶӷ¢Ã÷ÒøÐÐľÂíMispaduµÄ´ó¹æÄ£¹¥»÷»î¶¯


¾ÝýÌå3ÔÂ20Èճƣ¬£¬ £¬£¬£¬Ñо¿ÍŶӷ¢Ã÷ÁË20¸öÕë¶ÔÖÇÀû¡¢Ä«Î÷¸ç¡¢ÃØÂ³ºÍÆÏÌÑÑÀµÄ´ó¹æÄ£À¬»øÓʼþ»î¶¯¡£¡£¡£¡£¡£»£»£»£»î¶¯ÓÚ2022Äê8ÔÂ×óÓÒ×îÏÈ£¬£¬ £¬£¬£¬×èÖ¹2023Äê3ÔÂÉÏÑ®ÈÔÈ»»îÔ¾¡£¡£¡£¡£¡£ÕâЩ»î¶¯ÒÀÀµÓÚÒøÐÐľÂíMispadu£¬£¬ £¬£¬£¬ÊÓ²ìЧ¹ûÏÔʾ£¬£¬ £¬£¬£¬¹¥»÷ÕßÒÑ´Ó×ܹ²17595¸öÆæÒìÍøÕ¾ÖÐÇÔÈ¡ÁË90518¸öƾ֤¡£¡£¡£¡£¡£Mispadu½ÓÄÉÁËÔö½øÑ¬È¾ºÍ¼á³Ö³¤ÆÚÐÔµÄÐÂÊÖÒÕ£¬£¬ £¬£¬£¬°üÀ¨ÓÃÓÚ»ìÏý³õʼ½×¶Î¶ñÒâÈí¼þµÄαÔìÖ¤ÊéºÍÒ»¸öеĻùÓÚ.NETµÄºóÃÅ¡£¡£¡£¡£¡£


https://www.infosecurity-magazine.com/news/mispadu-steals-90000-banking/


3¡¢Lowe's MarketϵͳÉèÖùýʧ´ó×ÚÆ¾Ö¤ºÍ¿Í»§ÐÅϢй¶


ýÌå3ÔÂ17ÈÕ͸¶£¬£¬ £¬£¬£¬Ñо¿Ö°Ô±ÔÚLowe's MarketÍøÕ¾ÉÏ·¢Ã÷ÁËÒ»¸ö¿É¹ûÕæ»á¼ûµÄÇéÐÎÎļþ(.env)¡£¡£¡£¡£¡£Õâ¶Ô¹«Ë¾ÏµÍ³µÄÇå¾²×é³ÉÁËΣº¦£¬£¬ £¬£¬£¬ÓÉÓÚËüй¶ÁË´ó×ÚÆ¾Ö¤¡£¡£¡£¡£¡£¸ÃÇéÐÎÎļþй¶ÁËAWS S3ЧÀÍÆ÷µÄ»á¼ûÃÜÔ¿ºÍ´æ´¢Í°Ãû³Æ£¬£¬ £¬£¬£¬Ðí¶àרÓÃÓÚÌØ¶¨ÍøÕ¾¹¦Ð§µÄÓ¦ÓóÌÐò±à³Ì½Ó¿Ú(API)ÃÜÔ¿£¬£¬ £¬£¬£¬ÒÔ¼°Facebook OAuthƾ֤ºÍGithub OAuthÁîÅÆµÈÐÅÏ¢¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖ£¬£¬ £¬£¬£¬Ð¹Â¶µÄƾ֤¿É±»¹¥»÷ÕßÓÃÓÚ¿ØÖƴ󲿷ÖÔÚÏßÊÐËÁµÄ¹¦Ð§£¬£¬ £¬£¬£¬Éó²é¿Í»§ÐÅÏ¢£¬£¬ £¬£¬£¬²¢ÀÄÓø¶·ÑЧÀ͵Ļá¼ûȨÏÞ¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬ £¬£¬£¬¸ÃÎÊÌâÒѾ­±»½â¾ö¡£¡£¡£¡£¡£


https://cybernews.com/security/lowes-market-data-leak/


4¡¢ÈÕÁ¢ÄÜÔ´ÒòµÚÈý·½Èí¼þÌṩÉÌÔâµ½CLOP¹¥»÷Êý¾Ýй¶


3ÔÂ17ÈÕ±¨µÀ£¬£¬ £¬£¬£¬ÈÕÁ¢ÄÜÔ´µÄÉùÃ÷³Æ£¬£¬ £¬£¬£¬µÚÈý·½Èí¼þÌṩÉÌFORTRA GoAnywhere MFTÔâµ½ÁËCLOPµÄÀÕË÷¹¥»÷£¬£¬ £¬£¬£¬¿ÉÄܵ¼ÖÂÔÚijЩ¹ú¼Ò/µØÇøµÄÔ±¹¤Êý¾Ý±»²»·¨»á¼û¡£¡£¡£¡£¡£¸Ã¹¥»÷ÊÇͨ¹ýʹÓÃGoAnywhere MFTÖеÄÎó²î£¨CVE-2023-0669£©ÊµÏֵ쬣¬ £¬£¬£¬¸ÃÎó²îÓÚ2023Äê2ÔÂ3ÈÕÊ×´ÎÅû¶¡£¡£¡£¡£¡£ÈÕÁ¢ÄÜÔ´³ÆÆäÁ¬Ã¦¶Ô¸ÃÊÂÎñ×÷³ö·´Ó¦£¬£¬ £¬£¬£¬¶Ï¿ªÁËÊÜѬȾϵͳµÄÅþÁ¬£¬£¬ £¬£¬£¬²¢Æô¶¯ÄÚ²¿ÊÓ²ìÒÔÈ·¶¨Î¥¹æµÄÓ°Ïì¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ö¸³ö£¬£¬ £¬£¬£¬ÆäÍøÂçÔËÓª»ò¿Í»§Êý¾ÝµÄÇå¾²²¢Î´Êܵ½Ó°Ïì¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/hitachi-energy-confirms-data-breach-after-clop-goanywhere-attacks/


5¡¢KasperskyÐû²¼»ùÓÚContiµÄMeowCorpÀÕË÷Èí¼þ½âÃÜÆ÷


ýÌå3ÔÂ16Èճƣ¬£¬ £¬£¬£¬KasperskyÐû²¼ÁË»ùÓÚContiµÄÀÕË÷Èí¼þMeowCorpµÄÃ⺬»ìÃÜÆ÷¡£¡£¡£¡£¡£2023Äê2ÔÂÏÂÑ®£¬£¬ £¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ÁËÂÛ̳ÉÏÐû²¼µÄÒ»²¿·ÖеÄÊý¾Ý¡£¡£¡£¡£¡£ÆÊÎöºó·¢Ã÷ËüÃÇÓë2022Äê12Ô·¢Ã÷µÄ Conti±äÖÖMeowCorpÓйØ¡£¡£¡£¡£¡£ÔÚ¶Ô°üÀ¨258¸ö˽Կ¡¢Ô´´úÂëºÍһЩԤ±àÒë½âÃÜÆ÷µÄÊý¾Ý¾ÙÐÐÆÊÎöºó£¬£¬ £¬£¬£¬KasperskyÐû²¼ÁËа汾µÄ¹«¹²½âÃÜÆ÷¡£¡£¡£¡£¡£½âÃÜÆ÷¿ÉÒÔ»Ö¸´ÃüÃûģʽºÍÀ©Õ¹ÃûΪ<file_name>.KREMLIN¡¢<file_name>.RUSSIAºÍ<file_name>.PUTINµÄ¼ÓÃÜÎļþ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/conti-based-ransomware-meowcorp-gets-free-decryptor/


6¡¢RedactedÐû²¼¹ØÓÚÀÕË÷ÍÅ»ïBianLianµÄÆÊÎö±¨¸æ


3ÔÂ16ÈÕ£¬£¬ £¬£¬£¬RedactedÐû²¼ÁËÀÕË÷ÍÅ»ïBianLianÉú³¤Ç÷ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£BianLianÓÚ2022Äê7ÔÂÊ×´ÎÔÚÒ°Íâ·ºÆð£¬£¬ £¬£¬£¬AvastÔÚ2023Äê1ÔÂÐû²¼ÁËÃ⺬»ìÃÜÆ÷¡£¡£¡£¡£¡£×èÖ¹2023Äê3ÔÂ13ÈÕ£¬£¬ £¬£¬£¬¸ÃÍÅ»ïÔÚÆäÍøÕ¾ÉÏÁгöÁË×ܹ²118¸ö×éÖ¯£¬£¬ £¬£¬£¬ÆäÖоø´ó´ó¶¼(71%)ÊÇÃÀ¹ú¹«Ë¾¡£¡£¡£¡£¡£ÔÚ×î½üµÄ¹¥»÷ÖеÄÖ÷񻂿±ðÊÇ£¬£¬ £¬£¬£¬BianLianÒѽ«ÆäÖØµã´Ó¼ÓÃÜÄ¿µÄÊý¾Ý×ªÒÆµ½½öÇÔȡϵͳÖÐÊý¾Ý²¢¾ÙÐÐÀÕË÷¡£¡£¡£¡£¡£ÏÖÔÚÉв»ÇåÎúBianLian·ÅÆú¼ÓÃÜÕ½ÂÔÊÇÓÉÓÚAvastµÄ½âÃÜÆ÷£¬£¬ £¬£¬£¬ÕÕ¾ÉÓÉÓÚÒâʶµ½²»ÐèÒªÕâÒ»²¿·ÖÀ´ÀÕË÷Êê½ð¡£¡£¡£¡£¡£


https://redacted.com/blog/bianlian-ransomware-gang-continues-to-evolve/