2.35ÒÚTwitterÓû§µÄСÎÒ˽¼ÒÐÅÏ¢ÔÚºÚ¿ÍÂÛ̳ÉÏÐû²¼
Ðû²¼Ê±¼ä 2023-01-05
¾ÝýÌå1ÔÂ4ÈÕ±¨µÀ£¬£¬£¬£¬£¬Ò»¸ö°üÀ¨Áè¼Ý2ÒÚTwitterÓû§µÄµç×ÓÓʼþµØµãµÄÊý¾Ý¼¯ÔÚºÚ¿ÍÂÛ̳BreachedÉÏÐû²¼£¬£¬£¬£¬£¬½öÐèÖ§¸¶8¸öÂÛ̳Ǯ±Ò»ý·Ö£¨¼ÛÖµÔ¼2ÃÀÔª£©¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÒÑÈ·ÈÏÆäÖÐÁгöµÄÐí¶àÓʼþµØµãµÄÓÐÓÃÐÔ¡£¡£¡£¡£¡£¡£¾Ý³Æ£¬£¬£¬£¬£¬¸ÃÊý¾Ý¼¯Óë11Ô·ÝÈö²¥µÄ4ÒÚÌõÊý¾ÝÏàͬ£¬£¬£¬£¬£¬µ«¾ÓÉÕûÀíºó²»°üÀ¨Öظ´Ï£¬£¬£¬£¬×ÜÊýïÔ̵½Ô¼221608279Ìõ¡£¡£¡£¡£¡£¡£Êý¾ÝÒÔRAR´æµµµÄÐÎʽÐû²¼£¬£¬£¬£¬£¬ÆäÖаüÀ¨6¸öÎı¾Îļþ£¬£¬£¬£¬£¬×ܾÞϸ59GB£¬£¬£¬£¬£¬Éæ¼°ÓʼþµØµã¡¢ÐÕÃû¡¢êdzƺ͹Ø×¢µÈÐÅÏ¢¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/140352/data-breach/twitter-data-leak-235m-users.html
2¡¢ÎÖ¶ûÎÖÔâµ½EnduranceµÄÀÕË÷¹¥»÷200GBÃô¸ÐÊý¾ÝÒÉËÆÐ¹Â¶
1ÔÂ3ÈÕ±¨µÀ³Æ£¬£¬£¬£¬£¬·¨¹úÇå¾²»ú¹¹Anis Haboubi·¢Ã÷ºÚ¿ÍÔÚÂÛ̳ÉÏÒÔ2500ÃÀÔªµÄ¼ÛÇ®³öÊÛ´ÓÎÖ¶ûÎÖÇÔÈ¡µÄÊý¾Ý¡£¡£¡£¡£¡£¡£2022Äê12ÔÂ31ÈÕ£¬£¬£¬£¬£¬ÂÛ̳³ÉÔ±IntelBrokerÉù³ÆÎÖ¶ûÎÖÔâµ½ÁËEnduranceµÄÀÕË÷¹¥»÷£¬£¬£¬£¬£¬¹¥»÷ÕßÇÔÈ¡ÁË200GBµÄÃô¸ÐÊý¾Ý£¬£¬£¬£¬£¬ÕâЩÊý¾ÝÏÖÔÚÕýÔÚ³öÊÛ¡£¡£¡£¡£¡£¡£Âô¼ÒÚ¹ÊÍ˵£¬£¬£¬£¬£¬ËûûÓÐË÷ÒªÊê½ð£¬£¬£¬£¬£¬ÓÉÓÚËûÒÔΪ¸Ã¹«Ë¾²»»á¸¶Êê½ð¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬±»µÁÊý¾Ý°üÀ¨Êý¾Ý¿â»á¼û¡¢CICD»á¼û¡¢Atlassian»á¼û¡¢ÓòÃû»á¼û¡¢WiFiµãºÍµÇ¼¡¢ÊÚȨ³ÐÔØ¡¢API¡¢PACÇå¾²»á¼û¡¢Ô±¹¤Ãûµ¥¡¢Èí¼þÔÊÐíÖ¤ÒÔ¼°ÃÜÔ¿ºÍϵͳÎļþ¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬Éв»ÇåÎúÕâһ˵·¨µÄÕæÊµÐÔ¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/140258/hacking/volvo-cars-data-breach-2.html
3¡¢Qualys·¢Ã÷ÒÔ±»µÁµÄÒøÐÐÊý¾ÝΪÓÕ¶ü·Ö·¢BitRATµÄ»î¶¯
QualysÔÚ1ÔÂ3Èճƣ¬£¬£¬£¬£¬½üÆÚÒ»³¡ÐµĶñÒâÈí¼þ»î¶¯Ê¹Óñ»µÁµÄÒøÐÐÊý¾Ý×÷ΪÓÕ¶ü£¬£¬£¬£¬£¬Ö¼ÔÚ·Ö·¢Ô¶³Ì»á¼ûľÂíBitRAT¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚÊӲ촹ÂÚ¹¥»÷ÖеÄBitRATÓÕ¶üʱ£¬£¬£¬£¬£¬·¢Ã÷Ò»¼Ò¸çÂ×±ÈÑÇÏàÖúÒøÐеÄIT»ù´¡ÉèÊ©Òѱ»¹¥»÷ÕßÐ®ÖÆ£¬£¬£¬£¬£¬418777Ìõ¿Í»§Êý¾Ý±»µÁ¡£¡£¡£¡£¡£¡£¹¥»÷Õß½«Êý¾Ýµ¼³öµ½ÎäÆ÷»¯µÄExcel¶ñÒâÎĵµÖУ¬£¬£¬£¬£¬ÒÔÓÕʹÊÕ¼þÈË·¿ªÎļþ¡£¡£¡£¡£¡£¡£·¿ªÎļþ²¢ÆôÓúêºó£¬£¬£¬£¬£¬½«ÏÂÔØ²¢Ö´Ðеڶþ½×¶ÎDLL payload¡£¡£¡£¡£¡£¡£µÚ¶þ½×¶ÎDLLʹÓÃÖÖÖÖ·´µ÷ÊÔÊÖÒÕ£¬£¬£¬£¬£¬×îÖÕÔÚÄ¿µÄÖ÷»úÉϼìË÷²¢Ö´ÐÐBitRAT¡£¡£¡£¡£¡£¡£
https://blog.qualys.com/vulnerabilities-threat-research/2023/01/03/bitrat-now-sharing-sensitive-bank-data-as-a-lure
4¡¢ÃÀ¹úÌú·ºÍ»ú³µ¹«Ë¾WabtecÔâµ½LockBitµÄÀÕË÷¹¥»÷
ýÌå1ÔÂ3Èճƣ¬£¬£¬£¬£¬ÃÀ¹úÌú·ºÍ»ú³µ¹«Ë¾Wabtec Corporation͸¶ÆäÔâµ½ÀÕË÷¹¥»÷µ¼ÖÂÊý¾Ýй¶¡£¡£¡£¡£¡£¡£ºÚ¿ÍÔçÔÚ2022Äê3ÔÂ15ÈÕ¾ÍÈëÇÖÁËËûÃǵÄÍøÂç²¢ÔÚϵͳÉÏ×°ÖÃÁ˶ñÒâÈí¼þ£¬£¬£¬£¬£¬WabtecÔÚ6ÔÂ26ÈÕ³ÆÔÚÍøÂçÉϼì²âµ½Òì³£»£»£»£»î¶¯¡£¡£¡£¡£¡£¡£¼¸Öܺ󣬣¬£¬£¬£¬LockBitÐû²¼ÁË´ÓWabtecÇÔÈ¡µÄÊý¾ÝÑù±¾£¬£¬£¬£¬£¬²¢×îÖÕÔÚ2022Äê8ÔÂ20ÈÕ¹ûÕæÁËËùÓб»µÁÊý¾Ý¡£¡£¡£¡£¡£¡£Wabtec¶Ô¸ÃÊÂÎñµÄÊÓ²ìÓÚ2022Äê11ÔÂ23ÈÕÍê³É£¬£¬£¬£¬£¬È·ÈÏй¶ÐÅÏ¢°üÀ¨ÐÕÃû¡¢Éí·ÝÖ¤ºÅÂë¡¢Éç»á°ü¹ÜºÅÂë»ò²ÆÎñ´úÂë¡¢»¤ÕÕºÅÂëºÍ¹ÍÖ÷ʶÓÖÃûÂëµÈ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÓÚ2022Äê12ÔÂ30ÈÕ×îÏÈÏòÊÜÓ°ÏìµÄСÎÒ˽¼Ò·¢ËÍ֪ͨ£¬£¬£¬£¬£¬µ«Î´Í¸Â¶È·ÇÐÈËÊý¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/rail-giant-wabtec-discloses-data-breach-after-lockbit-ransomware-attack/
5¡¢Ñо¿Ö°Ô±Åû¶Õë¶ÔÐÅÏ¢Çå¾²ÁìÓòµÄFlipper Zero´¹Âڻ
¾Ý1ÔÂ3ÈÕ±¨µÀ£¬£¬£¬£¬£¬Dominic AlvieriÅû¶ÁËÕë¶ÔÇå¾²Ñо¿Ö°Ô±µÄFlipper Zero´¹Âڻ¡£¡£¡£¡£¡£¡£Flipper ZeroÊÇÒ»¿î±ãЯʽ¶à¹¦Ð§ÍøÂçÇå¾²¹¤¾ß£¬£¬£¬£¬£¬ÆäÔÚÈ¥Äê·ºÆðÉú²úÎÊÌâµ¼Ö¹©Ó¦Ç·È±£¬£¬£¬£¬£¬ÎÞ·¨Öª×ãÈÔÔÚÔöÌíµÄÐèÇ󡣡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÈËÃǶÔFlipper ZeroµÄÐËȤ¼°Æä¹©Ó¦Ç·È±£¬£¬£¬£¬£¬½¨ÉèÊÐËÁð³ä³öÊÛËü¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷ÁËαÔìµÄÈý¸öTwitterÕË»§ºÍÁ½¸öÊÐËÁ¡£¡£¡£¡£¡£¡£½áÕËʱÂò¼Ò»á½øÈë´¹ÂÚÒ³Ãæ£¬£¬£¬£¬£¬²¢±»ÒªÇóÊäÈëÓʼþµØµã¡¢ÐÕÃûºÍËÍ»õµØµã£¬£¬£¬£¬£¬È»ºóÑ¡ÔñʹÓÃÒÔÌ«·»»ò±ÈÌØ±Ò¸¶¿î¡£¡£¡£¡£¡£¡£´Ë´¦ÁгöµÄÇ®°üµØµãûÓÐÊÕµ½Èκθ¶¿î£¬£¬£¬£¬£¬ÒÔÊÇҪôÊǸÃÊÐËÁûÓÐÆµ½ÈκÎÈË£¬£¬£¬£¬£¬ÒªÃ´ÊÇÔÚÿ´ÎÉúÒâºó¶¼Ê¹ÓÃеÄÇ®°ü¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/ongoing-flipper-zero-phishing-attacks-target-infosec-community/
6¡¢Security JoesÐû²¼Raspberry RobinлµÄ±¨¸æ
1ÔÂ3ÈÕ£¬£¬£¬£¬£¬Security JoesÐû²¼±¨¸æ³ÆRaspberry Robin×îÏÈÕë¶ÔÅ·Ö޵ĽðÈںͰü¹ÜÐÐÒµ¡£¡£¡£¡£¡£¡£¶ÔÒ»´Î´ËÀ๥»÷µÄȡ֤ÊÓ²ìÏÔʾ£¬£¬£¬£¬£¬ËüʹÓÃÁËÒ»¸ö7-ZipÎļþ£¬£¬£¬£¬£¬¸ÃÎļþÊÇͨ¹ýÉ繤¹¥»÷ͨ¹ýÄ¿µÄµÄä¯ÀÀÆ÷ÏÂÔØµÄ£¬£¬£¬£¬£¬°üÀ¨Ò»¸öMSI×°ÖóÌÐòÎļþ£¬£¬£¬£¬£¬Ö¼ÔÚ·Ö·¢¶à¸öÄ£¿£¿£¿é¡£¡£¡£¡£¡£¡£ÔÚÁíÒ»¸ö°¸ÀýÖУ¬£¬£¬£¬£¬Ä¿µÄÊÇͨ¹ýÍйÜÔÚ·Ö·¢¹ã¸æÈí¼þµÄÓòÉϵÄÚ²ÆÐÔ¹ã¸æÏÂÔØµÄZIPÎļþ¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ͳһ¸öQNAPЧÀÍÆ÷±»ÓÃÓÚ¶àÂÖ¹¥»÷£¬£¬£¬£¬£¬Ä¿µÄµÄÊý¾Ý²»ÔÙÊÇ´¿Îı¾ÐÎʽ£¬£¬£¬£¬£¬¶øÊÇRC4¼ÓÃܵġ£¡£¡£¡£¡£¡£
https://www.securityjoes.com/post/raspberry-robin-detected-itw-targeting-insurance-financial-institutes-in-europe


¾©¹«Íø°²±¸11010802024551ºÅ