BlackCatÉù³ÆÒÑ»ñÈ¡RedditµÄ80GBÊý¾Ý²¢ÀÕË÷450ÍòÃÀÔª

Ðû²¼Ê±¼ä 2023-06-19

1¡¢BlackCatÉù³ÆÒÑ»ñÈ¡RedditµÄ80GBÊý¾Ý²¢ÀÕË÷450ÍòÃÀÔª 


¾ÝýÌå6ÔÂ17ÈÕ±¨µÀ£¬£¬£¬£¬ £¬£¬£¬BlackCat(ALPHV)Éù³Æ¶ÔRedditÔâµ½µÄ¹¥»÷ÈÏÕæ£¬£¬£¬£¬ £¬£¬£¬²¢ÌåÏÖÒÑÇÔÈ¡80 GB£¨Ñ¹Ëõ£©µÄÊý¾Ý¡£¡£¡£¡£2ÔÂ9ÈÕ£¬£¬£¬£¬ £¬£¬£¬Reddit͸¶ÆäϵͳÔÚ2ÔÂ5ÈÕ±»ºÚ£¬£¬£¬£¬ £¬£¬£¬ÓÉÓÚÒ»ÃûÔ±¹¤Ôâµ½ÁË´¹ÂÚ¹¥»÷¡£¡£¡£¡£Õâµ¼Ö¹¥»÷ÕßÄܹ»»á¼ûRedditµÄϵͳ£¬£¬£¬£¬ £¬£¬£¬²¢ÇÔÈ¡ÄÚ²¿Îĵµ¡¢Ô´´úÂë¡¢Ô±¹¤ÐÅÏ¢ÒÔ¼°Óйع«Ë¾¹ã¸æÉ̵ÄÊý¾Ý¡£¡£¡£¡£BlackCatÍÅ»ïÌåÏÖ£¬£¬£¬£¬ £¬£¬£¬ËûÃÇÔøÔÚ4ÔÂ13ÈÕºÍ6ÔÂ16ÈÕÁ½´ÎÊÔͼÁªÏµReddit£¬£¬£¬£¬ £¬£¬£¬²¢ÒªÇóÆä½»450ÍòÃÀµÄÊê½ð£¬£¬£¬£¬ £¬£¬£¬µ«Ã»ÓÐÊÕµ½»Ø¸´¡£¡£¡£¡£


https://www.databreaches.net/blackcat-claims-they-hacked-reddit-and-will-leak-the-data/


2¡¢ProgressÐÞ¸´MOVEitÖÐÓÖÒ»¸öSQLiÎó²îCVE-2023-35708  


ýÌå6ÔÂ15Èճƣ¬£¬£¬£¬ £¬£¬£¬Progress SoftwareÐÞ¸´ÁËÆäMOVEit TransferÖеĵÚÈý¸öSQL×¢ÈëÎó²î£¨CVE-2023-35708£©¡£¡£¡£¡£¸Ã¹«Ë¾³Æ£¬£¬£¬£¬ £¬£¬£¬ËûÃÇÒѾ­½µµÍÁËMOVEit CloudµÄHTTPsÁ÷Á¿£¬£¬£¬£¬ £¬£¬£¬²¢ÒªÇóÓû§ÔÚ½¨ÉèºÍ²âÊÔ²¹¶¡Ê±½µµÍHTTPºÍHTTPsÁ÷Á¿ÒÔ±£»£»£»£»¤ËûÃǵÄϵͳ¡£¡£¡£¡£ÔÚ×°Öò¹¶¡Ç°£¬£¬£¬£¬ £¬£¬£¬ProgressÇ¿ÁÒ½¨ÒéÐ޸ķÀ»ðǽ¹æÔòÒԾܾø¶Ë¿Ú80ºÍ443ÉϵÄMOVEit TransferµÄHTTPºÍHTTPsÁ÷Á¿£¬£¬£¬£¬ £¬£¬£¬×÷ΪһÖÖÔÝʱ½â¾öÒªÁì¡£¡£¡£¡£ËùÓÐÓû§¶¼±ØÐèÓ¦ÓÃÔÚ6ÔÂ16ÈÕÐû²¼µÄв¹¶¡¡£¡£¡£¡£Õâ¸öÐÂÎó²îµÄϸ½ÚÉÐδ¹ûÕæ£¬£¬£¬£¬ £¬£¬£¬µ«ÒÑÓÐÑо¿Ö°Ô±Ðû²¼PoC¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/moveit-transfer-customers-warned-of-new-flaw-as-poc-info-surfaces/


3¡¢ÀÕË÷ÍÅ»ïRhysida¹ûÕæ´ÓÖÇÀû¾ü¶ÓµÄϵͳÖÐÇÔÈ¡µÄÎļþ


¾Ý6ÔÂ15ÈÕ±¨µÀ£¬£¬£¬£¬ £¬£¬£¬ÀÕË÷ÍÅ»ïRhysida¹ûÕæÁË´ÓÖÇÀû¾ü¶Ó(Ej¨¦rcito de Chile)µÄϵͳÖÐÇÔÈ¡µÄÎļþ¡£¡£¡£¡£¾ÝÇå¾²¹«Ë¾CronUp³Æ£¬£¬£¬£¬ £¬£¬£¬ÖÇÀû¾ü¶ÓÓÚ5ÔÂ29ÈÕÈ·ÈÏÆäϵͳÊܵ½ÁËÔÚ5ÔÂ27ÈÕ¼ì²âµ½µÄÇå¾²ÊÂÎñµÄÓ°Ï죬£¬£¬£¬ £¬£¬£¬²¿·ÖÊý¾Ýй¶¡£¡£¡£¡£¹¥»÷ÊÂÎñÅû¶µÄ¼¸Ììºó£¬£¬£¬£¬ £¬£¬£¬ÍâµØÃ½Ì屨µÀ³Æ£¬£¬£¬£¬ £¬£¬£¬Ò»Ãû½¾üÏÂÊ¿Òò¼ÓÈëÀÕË÷¹¥»÷¶ø±»²¶¡£¡£¡£¡£RhysidaÏÖÔÚÐû²¼ÁËԼĪ360000·ÝÖÇÀû¾ü¶ÓµÄÎļþ£¨¾Ý³Æ½öÕ¼ËùÓб»µÁÊý¾ÝµÄ30%£©¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/rhysida-ransomware-leaks-documents-stolen-from-chilean-army/


4¡¢Î¢Èí͸¶½üÆÚAzure¡¢OutlookºÍOneDriveÖÐÖ¹Ô´ÓÚDDoS¹¥»÷


6ÔÂ18ÈÕ±¨µÀ³Æ£¬£¬£¬£¬ £¬£¬£¬Î¢Èí͸¶6ÔÂÉÏÑ®ÆäAzure¡¢OutlookºÍOneDriveЧÀÍÖÐÖ¹ÊÇÕë¶Ô¹«Ë¾Ð§À͵ĵÚ7²ãDDoS¹¥»÷µ¼ÖµÄ¡£¡£¡£¡£´Ë´Î¹¥»÷±»¹éÒòÓÚ΢Èí×·×ÙΪStorm-1359µÄÍŻ£¬£¬£¬ £¬£¬£¬¸ÃÍÅ»ï×Ô³ÆAnonymous Sudan¡£¡£¡£¡£ÕâЩ¹¥»÷¿ÉÄÜÒÀÀµÓÚ»á¼û¶à¸öÐéÄâרÓÃЧÀÍÆ÷(VPS)ÒÔ¼°×âÓõÄÔÆ»ù´¡ÉèÊ©¡¢¿ª·ÅÊðÀíºÍDDoS¹¤¾ß¡£¡£¡£¡£×î³õ£¬£¬£¬£¬ £¬£¬£¬Õâ¼ÒIT¹«Ë¾Ã»ÓÐÌṩÓйØÖÐÖ¹ÊÂÎñµÄÏêϸÐÅÏ¢£¬£¬£¬£¬ £¬£¬£¬µ«ÔÚ6ÔÂ16ÈÕÐû²¼ÁËMicrosoft¶ÔµÚ7²ãDDoS¹¥»÷µÄÏìÓ¦±¨¸æ£¬£¬£¬£¬ £¬£¬£¬Í¸Â¶ÁËÖÐÖ¹µÄÔµ¹ÊÔ­ÓÉ¡£¡£¡£¡£


https://securityaffairs.com/147605/hacking/microsoft-outages-ddos.html


5¡¢Ö´·¨Ðж¯PowerOffµ·»Ù2013Äê×îÏÈ»îÔ¾µÄDDoS³ö×âЧÀÍ


¾Ý6ÔÂ17ÈÕýÌ屨µÀ£¬£¬£¬£¬ £¬£¬£¬¹ú¼ÊÖ´·¨Ðж¯Operation PowerOFFµ·»ÙÁË×Ô2013Äê×îÏÈ»îÔ¾µÄDDoS³ö×âЧÀÍ (ÓÖ³Æbooter»òstresser)¡£¡£¡£¡£DDoS³ö×⣨DDoS-for-hire£©Ð§ÀÍÔÊÐí×¢²áÓû§ÔÚ²»¾ß±¸Ìض¨ÖªÊ¶µÄÇéÐÎÏÂÖ´ÐÐÓÐÐòµÄDDoS¹¥»÷¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬ £¬£¬£¬²¨À¼¾¯·½¾Ð²¶ÁË¸ÃÆ½Ì¨µÄÁ½ÃûÔËÓªÖ°Ô±£¬£¬£¬£¬ £¬£¬£¬²¢´ÓËûÃÇλÓÚÈðÊ¿µÄЧÀÍÆ÷ÖÐÍøÂçµ½ÁËÓмÛÖµµÄÊý¾Ý¡£¡£¡£¡£ÓÐÁè¼Ý35000¸öÓû§ÕÊ»§¡¢76000¸öµÇ¼¼Í¼ºÍÁè¼Ý320000¸öÓëDDoS³ö×âЧÀÍÏà¹ØµÄIPµØµãµÄÐÅÏ¢¡£¡£¡£¡£Operation PowerOFFÊÇÒ»Ïîºã¾ÃÖ´ÐеÄÖ´·¨Ðж¯£¬£¬£¬£¬ £¬£¬£¬ÒѹرÕÁËÊýÊ®¸öÖ÷ÒªµÄDDoS³ö×âÆ½Ì¨¡£¡£¡£¡£ 


https://securityaffairs.com/147564/cyber-crime/ddos-for-eye-service-seized.html


6¡¢ESET·¢Ã÷Android¶ñÒâÈí¼þGravityRATÐÂÒ»ÂÖ¹¥»÷»î¶¯


6ÔÂ15ÈÕ£¬£¬£¬£¬ £¬£¬£¬ESETÅû¶ÁËAndroid¶ñÒâÈí¼þGravityRATµÄÐÂÒ»ÂÖ¹¥»÷»î¶¯¡£¡£¡£¡£¸Ã»î¶¯×Ô2022Äê8ÔÂ×îÏÈ»îÔ¾£¬£¬£¬£¬ £¬£¬£¬Ê¹ÓÃľÂí»¯Ì¸ÌìÓ¦ÓÃBingeChatºÍChaticoÑ¬È¾ÒÆ¶¯×°±¸£¬£¬£¬£¬ £¬£¬£¬²¢ÊÔͼ´ÓÄ¿µÄ×°±¸ÖÐÇÔÈ¡Êý¾Ý¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬ £¬£¬£¬Ê¹ÓÃChaticoµÄ»î¶¯ÒѲ»ÔÙ»îÔ¾¡£¡£¡£¡£¶ñÒâÓ¦Óû¹Ìṩ»ùÓÚ¿ªÔ´OMEMO Instant MessengerÓ¦ÓóÌÐòµÄÕýµ±Ì¸Ì칦Ч¡£¡£¡£¡£Õâ¸öа汾µÄGravityRAT¾ßÓÐÁ½¸öй¦Ð§£¬£¬£¬£¬ £¬£¬£¬¿ÉÎüÊÕɾ³ýÎļþµÄÏÂÁîºÍй¶WhatsApp±¸·ÝÎļþ¡£¡£¡£¡£


https://www.welivesecurity.com/2023/06/15/android-gravityrat-goes-after-whatsapp-backups/