PyPIÒÑÔÝÍ£ÐÂÓû§×¢²áºÍÐÂÏîÄ¿ÉÏ´«¹¦Ð§Ö±ÖÁÁíÐÐ֪ͨ
Ðû²¼Ê±¼ä 2023-05-231¡¢PyPIÒÑÔÝÍ£ÐÂÓû§×¢²áºÍÐÂÏîÄ¿ÉÏ´«¹¦Ð§Ö±ÖÁÁíÐÐ֪ͨ
¾Ý5ÔÂ21ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬PyPIÒÑÔÝÍ£ÁËÐÂÓû§×¢²áºÍÐÂÏîÄ¿ÉÏ´«¹¦Ð§£¬£¬£¬£¬£¬£¬Ö±ÖÁÁíÐÐ֪ͨ¡£¡£¡£¡£¡£¡£¡£PyPIÊÇ¿ªÔ´PythonÈí¼þ°üµÄ¹Ù·½µÚÈý·½×¢²áÖÐÐÄ£¬£¬£¬£¬£¬£¬Î¬»¤Ö°Ô±Ñ¡Ôñ½ûÓÃÉÏÊö¹¦Ð§£¬£¬£¬£¬£¬£¬ÊÇÓÉÓÚËûÃÇÒÑÍùÒ»Öܼì²âµ½½¨Éè¶ñÒâÓû§ºÍÏîÄ¿µÄÊýÄ¿¼¤Ôö£¬£¬£¬£¬£¬£¬Áè¼ÝÁË×ÅʵʱÏìÓ¦µÄÄÜÁ¦¡£¡£¡£¡£¡£¡£¡£Í¨¸æ²¢Î´ÌṩÓйع¥»÷µÄÏêϸÐÅÏ¢£¬£¬£¬£¬£¬£¬ÀýÈç¹¥»÷ÕßµÄÉí·Ý¡¢ÄîÍ·ÒÔ¼°¹¥»÷ÖÐʹÓõĶñÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£½ñÄê2Ô£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÔøÔÚPyPI´æ´¢¿âÖмì²âµ½Áè¼Ý451¸ö°üÊÔͼÔÚ¿ª·¢ÕßµÄϵͳÉÏ×°ÖÃclipper¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/146488/cyber-crime/pypi-repository-suspends-sign-ups-package-uploads.html
2¡¢MetaÒò½«Å·ÖÞÓû§Êý¾Ý´«»ØÃÀ¹ú±»Å·ÃË·£¿£¿£¿£¿£¿£¿£¿£¿î13ÒÚÃÀÔª
¾ÝýÌå5ÔÂ22ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬°®¶ûÀ¼Êý¾Ý±£»£»£»£»¤Î¯Ô±»á(DPC)³ÆMetaÎ¥·´ÁËGDPRµÚ46(1)Ìõ£¬£¬£¬£¬£¬£¬¶ÔÆä´¦ÒÔ13ÒÚÃÀÔªµÄ·£¿£¿£¿£¿£¿£¿£¿£¿î¡£¡£¡£¡£¡£¡£¡£ÏêϸÀ´Ëµ£¬£¬£¬£¬£¬£¬Facebook½«¸Ãƽ̨ŷÃËÓû§µÄÊý¾Ý´«»ØÁËÃÀ¹ú£¬£¬£¬£¬£¬£¬¶øÃÀ¹úµÄÊý¾Ý±£»£»£»£»¤¹æÔòÒòÖݶøÒ죬£¬£¬£¬£¬£¬±»ÒÔΪȱ·¦ÒÔ±£»£»£»£»¤Å·ÃËÊý¾ÝÖ÷ÌåµÄȨÁ¦¡£¡£¡£¡£¡£¡£¡£Òò´Ë£¬£¬£¬£¬£¬£¬DPC¶ÔFacebookµÄĸ¹«Ë¾Meta Ireland·£¿£¿£¿£¿£¿£¿£¿£¿î12ÒÚÅ·Ôª£¨13ÒÚÃÀÔª£©£¬£¬£¬£¬£¬£¬²¢ÒªÇóÔÚÎå¸öÔÂÄÚÔÝÍ£ËùÓÐÎ¥·´GDPRµÄÊý¾Ý´«Êä¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬Meta»¹±»ÒªÇóÔÚÁù¸öÔÂÄÚ×èÖ¹´¦Öóͷ£»ò³ÖÓдÓÅ·Ã˲»·¨´«Êäµ½ÃÀ¹úµÄËùÓÐÊý¾Ý¡£¡£¡£¡£¡£¡£¡£MetaÒÔΪ·£¿£¿£¿£¿£¿£¿£¿£¿î²»¹«Õý¡¢²»ÐëÒªÇÒ²»Ï൱£¬£¬£¬£¬£¬£¬²¢ÍýÏë¶Ô¸Ã²Ã¾öÌá³öÉÏËß¡£¡£¡£¡£¡£¡£¡£ÕâÊÇ×ÔÅ·ÃËÓÚ2018Äê5ÔÂ25ÈÕͨ¹ýGDPRÒÔÀ´×î´ó½ð¶îµÄ·£¿£¿£¿£¿£¿£¿£¿£¿î¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/technology/eu-slaps-meta-with-13-billion-fine-for-moving-data-to-us-servers/
3¡¢²¨À¼¶à¼ÒÐÂÎÅÍøÕ¾Ôâµ½DDoS¹¥»÷»òÓë¶íÂÞ˹ºÚ¿ÍÓйØ
¾Ý·͸Éç5ÔÂ18ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬Êý¼Ò²¨À¼ÐÂÎÅÍøÕ¾Ôâµ½ÂþÑÜʽ¾Ü¾øÐ§ÀÍ(DDoS)¹¥»÷£¬£¬£¬£¬£¬£¬Õþ¸®³ÆÕâ¿ÉÄÜÊǶíÂÞ˹µÄºÚ¿Í×éÖ¯ËùΪ¡£¡£¡£¡£¡£¡£¡£¾ÝPAP±¨µÀ£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄÍøÕ¾°üÀ¨Gazeta Wyborcza¡¢RzeczpospolitaºÍSuper ExpressµÈÈÕ±¨µÄÍøÕ¾¡£¡£¡£¡£¡£¡£¡£WyborczaÔÚTwitterÉÏÈ·ÈÏËüÔâµ½Á˹¥»÷£¬£¬£¬£¬£¬£¬ÐÂÎÅÍøÕ¾wPolityce.plÒ²ÊÇÔÆÔÆ¡£¡£¡£¡£¡£¡£¡£¶íÂÞ˹Íâ½»²¿Ã»ÓÐÁ¬Ã¦»Ø¸´ÖÃÆÀÇëÇ󡣡£¡£¡£¡£¡£¡£
https://www.reuters.com/world/europe/polish-news-websites-hit-by-ddos-attacks-2023-05-18/
4¡¢Microsoft³Æ2019ÄêÖÁ2022Äê¼äBEC¹¥»÷»î¶¯ÔöÌí38%
MicrosoftÔÚ5ÔÂ19ÈÕÐû²¼Á˵ÚËÄ°æ¡¶ÍøÂçÐźš·£¬£¬£¬£¬£¬£¬ Ç¿µ÷ÁËÎ§ÈÆÆóÒµµç×ÓÓʼþÍ×Ð(BEC)µÄ¹¥»÷»î¶¯¼¤Ôö¡£¡£¡£¡£¡£¡£¡£ÔÚ2019ÄêÖÁ2022Äê¼ä£¬£¬£¬£¬£¬£¬Õë¶ÔÆóÒµµç×ÓÓʼþµÄÍøÂç·¸·¨¼´Ð§ÀÍ(CaaS)ÔöÌíÁË38%¡£¡£¡£¡£¡£¡£¡£2022Ä꣬£¬£¬£¬£¬£¬FBI¶ÔÉæ¼°ÃÀ¹úº£ÄÚÉúÒâµÄ2838ÆðBEC»î¶¯¾ÙÐÐÊӲ죬£¬£¬£¬£¬£¬·¢Ã÷DZÔÚËðʧÁè¼Ý5.9ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£¡£2022Äê4ÔÂÖÁ2023Äê4Ô£¬£¬£¬£¬£¬£¬Î¢Èí·¢Ã÷²¢ÊÓ²ìÁË3500Íò´ÎBECÍýÏ룬£¬£¬£¬£¬£¬Æ½¾ùÖðÈÕ156000´Î¡£¡£¡£¡£¡£¡£¡£BEC¹¥»÷ÈÕÒæÖØ´ó£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÊӲ쵽¹¥»÷ÕßʹÓÃBulletProftLinkµÈƽ̨µÄÇ÷ÊÆ¡£¡£¡£¡£¡£¡£¡£
https://www.microsoft.com/en-us/security/blog/2023/05/19/cyber-signals-shifting-tactics-fuel-surge-in-business-email-compromise/
5¡¢ÂÉËùBuckley King LPA±»BlackBasta¹¥»÷²¢Ô޳ɽ»Êê½ð
¾Ý5ÔÂ18ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬ÂÉËùBuckley King LPAÔâµ½ÁËBlackBastaµÄÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¡£¡£È¥Äê4Ô£¬£¬£¬£¬£¬£¬BlackBastaͨ¹ýÉ繤¹¥»÷ÈëÇÖÁËÂÉËùµÄϵͳ£¬£¬£¬£¬£¬£¬¾Ý³ÆÂÉËùµÄÒ»ÃûÔ±¹¤Ö´ÐÐÁËÓʼþÖеĶñÒ⸽¼þ¡£¡£¡£¡£¡£¡£¡£ºÚ¿ÍÍÅ»ïÔÚ̸ÅÐÖгƣ¬£¬£¬£¬£¬£¬ËûÃÇÇÔÈ¡ÁË110 GBµÄÎļþ£¬£¬£¬£¬£¬£¬²¢ÒªÇó¸Ã¹«Ë¾½»400000ÃÀÔªµÄÊê½ð£¬£¬£¬£¬£¬£¬À´É¾³ýÊý¾Ý¡¢»ñµÃ½âÃÜÆ÷ÒÔ¼°Çå¾²±¨¸æ¡£¡£¡£¡£¡£¡£¡£¾Óɶà´Î̸Åк󣬣¬£¬£¬£¬£¬Buckley King LPAÔÞ³ÉÁË150000ÃÀÔªµÄÊê½ðÒªÇ󡣡£¡£¡£¡£¡£¡£
https://www.databreaches.net/oh-buckley-king-law-firm-hit-by-blackbasta/
6¡¢Ñо¿Ö°Ô±¼ì²âµ½Á½¸öÄ£ÄâNodeJSµÄnpm°ü·Ö·¢TurkoRAT
5ÔÂ18ÈÕ£¬£¬£¬£¬£¬£¬ReversingLabs·¢Ã÷Á˶à¸öÒÔNodeJS¿âÃüÃûµÄnpm°ü£¬£¬£¬£¬£¬£¬ËüÃÇÉõÖÁ´ò°üÁËÒ»¸öÀàËÆÓÚNodeJSµÄWindows¿ÉÖ´ÐÐÎļþ£¬£¬£¬£¬£¬£¬µ«È´·Ö·¢Ä¾Âí¡£¡£¡£¡£¡£¡£¡£ÕâЩÈí¼þ°ü¼«¾ßÒþ²ØÐÔÇÒ¼ì²âÂʼ«µÍ£¬£¬£¬£¬£¬£¬ÔÚ±»·¢Ã÷֮ǰÒѾÓÚnpmÖÐDZÔÚÁËÁ½¸ö¶àÔ¡£¡£¡£¡£¡£¡£¡£ÆäÖÐnodejs-encrypt-agent¿´ËÆÊÇÒ»¸öÕýµ±°ü£¬£¬£¬£¬£¬£¬µ«°üÀ¨Ò»¸ö¶ñÒâPEÎļþlib.exe£¬£¬£¬£¬£¬£¬»áÔËÐÐTurkoRAT¡£¡£¡£¡£¡£¡£¡£nodejs-cookie-proxy-agentÒ²»á×°ÖÃÕâ¸öľÂí£¬£¬£¬£¬£¬£¬µ«ËüûÓÐÖ±½Ó°üÀ¨lib.exe£¬£¬£¬£¬£¬£¬¶øÊǽ«axios-proxyÁÐΪһ¸öÒÀÀµÏ£¬£¬£¬£¬£¬ºóÕß°üÀ¨Á˶ñÒâµÄ¿ÉÖ´ÐгÌÐò¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬ËùÓжñÒâ°ü¶¼Òѱ»´Ónpm×¢²á±íÖÐɾ³ý¡£¡£¡£¡£¡£¡£¡£
https://www.reversinglabs.com/blog/rats-found-hiding-in-the-npm-attic


¾©¹«Íø°²±¸11010802024551ºÅ