Hetzner±¬·¢Ó²¼þ¹ÊÕϵ¼Ö²¿·Ö¿Í»§µÄÊý¾ÝÓÀÊÀÐÔɥʧ

Ðû²¼Ê±¼ä 2022-04-19
1¡¢Hetzner±¬·¢Ó²¼þ¹ÊÕϵ¼Ö²¿·Ö¿Í»§µÄÊý¾ÝÓÀÊÀÐÔɥʧ


¾ÝýÌå4ÔÂ14ÈÕ±¨µÀ£¬£¬£¬£¬ £¬£¬µÂ¹úÔÆÐ§ÀÍÌṩÉÌHetzner Online GmbH²¿·Ö¿Í»§µÄÊý¾Ýɥʧ¡£¡£¡£ ¡£Æ¾Ö¤Æä֪ͨ£¬£¬£¬£¬ £¬£¬HetznerµÄÔÆÐ§ÀÍͨ¹ý½«¿ìÕÕ¸´ÖƵ½Èý¸öÓ²ÅÌÀ´ÊµÏÖÊý¾ÝÇå¾²£¬£¬£¬£¬ £¬£¬Òò´Ë×ÝÈ»Á½¸öÓ²Å̱¬·¢¹ÊÕÏ£¬£¬£¬£¬ £¬£¬Êý¾ÝÈÔÈ»¿ÉÓᣡ£¡£ ¡£µ«½üÆÚ±¬·¢ÁËһϵÁÐÊÂÎñ£¬£¬£¬£¬ £¬£¬µ¼Ö¶à¸ö´ÅÅÌÒ»Á¬·ºÆð¹ÊÕÏ£¬£¬£¬£¬ £¬£¬²¿·ÖÊý¾Ýɥʧ²¢ÇÒÎÞ·¨»Ö¸´¡£¡£¡£ ¡£¾ÝϤ£¬£¬£¬£¬ £¬£¬´Ë´ÎÊÂÎñ×ܹ²É¥Ê§ÁË1500¸ö¿ìÕÕ£¬£¬£¬£¬ £¬£¬HetznerΪÊÜÓ°ÏìÕÊ»§ÌṩÁ˼ÛÖµ20Å·ÔªµÄÔÆ»ý·Ö×÷ΪÅâ³¥£¬£¬£¬£¬ £¬£¬ÏÖÔÚ¹ÊÕÏÔµ¹ÊÔ­ÓÉÈÔȻδ֪¡£¡£¡£ ¡£


https://www.bleepingcomputer.com/news/security/hetzner-lost-customer-data-and-gave-20-as-compensation/


2¡¢Âóµ±À͸ç˹´ïÀè¼Ó·Ö¹«Ë¾³ÆÆä¿Í»§Êý¾ÝÔâµ½²»·¨»á¼û


¾Ý4ÔÂ16Èյı¨µÀ³Æ£¬£¬£¬£¬ £¬£¬Âóµ±À͸ç˹´ïÀè¼Ó·Ö¹«Ë¾¿Í»§µÄÊý¾Ý¿ÉÄÜÒѾ­Ð¹Â¶¡£¡£¡£ ¡£¸Ã¹«Ë¾³Æ£¬£¬£¬£¬ £¬£¬Ò»¸ö¹¥»÷Õßͨ¹ýÆäµÚÈý·½Ð§ÀÍÌṩÉÌÖÎÀíµÄÊý¾Ý¿â£¬£¬£¬£¬ £¬£¬»á¼ûÁËÂóµ±ÀͿͻ§µÄÊý¾Ý¡£¡£¡£ ¡£ÏÖÔÚ£¬£¬£¬£¬ £¬£¬¹¥»÷ÕßÔõÑù»á¼û¸ÃÊý¾Ý¿âÈÔ²»µÃ¶øÖª£¬£¬£¬£¬ £¬£¬µ«Âóµ±ÀÍÌåÏÖ£¬£¬£¬£¬ £¬£¬¿Í»§ÐÕÃû¡¢»éÒö״̬¡¢µØµã¡¢µç×ÓÓʼþ¡¢ÎļþʶÓÖÃûºÍµç»°ºÅÂëµÈÐÅÏ¢ÒÑй¶¡£¡£¡£ ¡£Âóµ±ÀÍÏÖÒÑÉϱ¨ÍâµØÖ´·¨²¿·Ö£¬£¬£¬£¬ £¬£¬²¢×îÏÈ֪ͨÊÜÓ°Ïì¿Í»§£¬£¬£¬£¬ £¬£¬ÌáÐÑËûÃÇ×¢ÖØÇ±ÔڵĴ¹ÂÚ¹¥»÷»î¶¯¡£¡£¡£ ¡£


https://techdator.net/mcdonalds-costa-rica-data-breach/


3¡¢Ñо¿Ö°Ô±·¢Ã÷ContiºÍKarakurtÍÅ»ïÖ®¼ä±£´æÁªÏµ


4ÔÂ15ÈÕ£¬£¬£¬£¬ £¬£¬Çå¾²¹«Ë¾Arctic WolfÐû²¼±¨¸æÕ¹ÏÖÁËContiºÍKarakurtÍÅ»ïÖ®¼ä±£´æµÄÁªÏµ¡£¡£¡£ ¡£×Ô2021Äê8ÔÂÊ״λÒÔÀ´£¬£¬£¬£¬ £¬£¬KarakurtÒѹ¥»÷Á˶à¸öÐÐÒµ£¬£¬£¬£¬ £¬£¬Éæ¼°°Ë¸ö¹ú¼ÒºÍµØÇøµÄ×éÖ¯¡£¡£¡£ ¡£¸Ã±¨¸æ³Æ£¬£¬£¬£¬ £¬£¬ÔÚÊÓ²ìÔøÏòContiÖ§¸¶Êê½ðÀ´½âËøÊý¾ÝµÄ¿Í»§Ê±£¬£¬£¬£¬ £¬£¬·¢Ã÷¸Ã¿Í»§ØÊºó±»Karakurtͨ¹ýConti×°ÖõÄCobalt StrikeºóÃÅÈëÇÖ¡£¡£¡£ ¡£Ñо¿Ö°Ô±»¹·¢Ã÷Á˶à´Î´ÓKarakurtÇ®°üÏòContiÇ®°ü·¢ËͼÓÃÜÇ®±ÒµÄÇéÐΡ£¡£¡£ ¡£±ðµÄ£¬£¬£¬£¬ £¬£¬Infinitum ITÊÓ²ìÁËContiµÄ¶à¸öProtonmailºÍMega UploadÕÊ»§£¬£¬£¬£¬ £¬£¬·¢Ã÷Conti³ÉÔ±ÓÃÀ´ÉÏ´«ºÍÏÂÔØ±»µÁÊý¾ÝµÄIPµØµã»¹ÍйÜÁËKarakurtÓÃÀ´Ð¹Â¶Êý¾ÝµÄÍøÕ¾¡£¡£¡£ ¡£


https://arcticwolf.com/resources/blog/karakurt-web


4¡¢Ñо¿ÍŶӳÆÔÚWin 11×°ÖÃGoogle Play¿ÉÄÜ»áѬȾľÂí


¾Ý4ÔÂ14ÈÕ±¨µÀ³Æ£¬£¬£¬£¬ £¬£¬ÔÚWindows 11×°ÖÃGoogle Play¿ÉÄÜ»áѬȾľÂí¡£¡£¡£ ¡£È¥Äê10ÔÂÐû²¼Windows 11ʱ£¬£¬£¬£¬ £¬£¬Î¢ÈíÐû²¼½«ÔÊÐíÓû§Ö±½ÓÔÚWindowsÖÐÔËÐÐÔ­ÉúAndroidÓ¦Óᣡ£¡£ ¡£µ«µ±½ñÄê2ÔÂÐû²¼Android×Óϵͳʱ£¬£¬£¬£¬ £¬£¬Óû§·¢Ã÷ËûÃDz»¿ÉʹÓÃGoogle Play¡£¡£¡£ ¡£ÔÚË­ÈËʱ¼ä£¬£¬£¬£¬ £¬£¬ÓÐÈËÔÚGitHubÉÏÐû²¼ÁËÒ»¸öй¤¾ßWindows Toolbox£¬£¬£¬£¬ £¬£¬¿ÉΪAndroid×ÓϵͳװÖÃGoogle Play¡£¡£¡£ ¡£Ö±µ½ÉÏÖÜ£¬£¬£¬£¬ £¬£¬Ñо¿ÍŶӷ¢Ã÷Windows ToolboxÏÖʵÉÏÊÇÒ»¸öľÂí£¬£¬£¬£¬ £¬£¬Ëü¿ÉÒÔÖ´ÐÐһϵÁжñÒâPowerShell¾ç±¾£¬£¬£¬£¬ £¬£¬ÒÔÔÚÄ¿µÄ×°±¸ÉÏ×°ÖÃtrojan clickerºÍÆäËü¶ñÒâÈí¼þ¡£¡£¡£ ¡£


https://www.bleepingcomputer.com/news/security/windows-11-tool-to-add-google-play-secretly-installed-malware/


5¡¢KasperskyÐû²¼ÀÕË÷Èí¼þYanluowangµÄÃ⺬»ìÃÜÆ÷


KasperskyÔÚ4ÔÂ18Èյı¨¸æÖÐ³ÆÆäÐû²¼ÁËÀÕË÷Èí¼þYanluowangµÄÃ⺬»ìÃÜÆ÷¡£¡£¡£ ¡£¸ÃÀÕË÷Èí¼þÏà¶Ô½ÏУ¬£¬£¬£¬ £¬£¬Òѹ¥»÷ÁËÃÀ¹ú¡¢°ÍÎ÷ºÍÍÁ¶úÆäµÈ¶à¸ö¹ú¼ÒµÄÄ¿µÄ¡£¡£¡£ ¡£KasperskyÆÊÎöÀÕË÷Èí¼þºó·¢Ã÷ÁËÆäÖеÄÒ»¸öÎó²î£¬£¬£¬£¬ £¬£¬¿ÉÓÃÀ´Í¨¹ýÒÑÖªÃ÷ÎĹ¥»÷½âÃܱ»¹¥»÷Óû§µÄÎļþ¡£¡£¡£ ¡£¸Ã¹«Ë¾ÒÑÔÚÆäRannohDecryptorÓ¦ÓÃÖÐÔöÌíÁ˶Ա»Yanluowang¼ÓÃܵÄÎļþµÄÖ§³Ö¡£¡£¡£ ¡£ÓÉÓÚ¸ÃÀÕË÷Èí¼þ¶Ô´óÓÚ3GBºÍСÓÚ3GBµÄÎļþµÄ¼ÓÃÜ·½·¨²î±ð£¬£¬£¬£¬ £¬£¬Òò´Ëµ±Óû§ÌṩµÄԭʼÎļþ´óÓÚ3 GB£¬£¬£¬£¬ £¬£¬¿ÉÒÔ½âÃÜËùÓÐÎļþ£¬£¬£¬£¬ £¬£¬µ±Ô­Ê¼ÎļþСÓÚ3 GB£¬£¬£¬£¬ £¬£¬Ö»ÄܽâÃÜСÎļþ¡£¡£¡£ ¡£


https://securelist.com/how-to-recover-files-encrypted-by-yanlouwang/106332/


6¡¢CiscoÐû²¼¹ØÓÚжñÒâÈí¼þZingoStealerµÄÆÊÎö±¨¸æ


4ÔÂ14ÈÕ£¬£¬£¬£¬ £¬£¬Cisco TalosÐû²¼Á˹ØÓÚжñÒâÈí¼þZingoStealerµÄÆÊÎö±¨¸æ¡£¡£¡£ ¡£2022Äê3ÔÂÉÏÑ®£¬£¬£¬£¬ £¬£¬Ñо¿Ö°Ô±ÔÚ¼à¿ØHaskers Gang³ÉÔ±Ö®¼äµÄͨѶʱ£¬£¬£¬£¬ £¬£¬·¢Ã÷ÆäÐû²¼ÁËÒ»¸öÃûΪZingoStealerµÄÐÂÐÅÏ¢ÇÔÈ¡³ÌÐò£¬£¬£¬£¬ £¬£¬¿É¹©¸ÃÍÅ»ïTelegramÉçÇøµÄ³ÉÔ±Ãâ·ÑʹÓᣡ£¡£ ¡£¸Ã¶ñÒâÈí¼þÏÖÔÚÈÔÔÚÆð¾¢¿ª·¢ÖУ¬£¬£¬£¬ £¬£¬×î½üÒѼì²âµ½Æä¶à¸öа汾¡£¡£¡£ ¡£Haskers GangʹÓÃTelegramºÍDiscordµÈЭ×÷ƽ̨À´Ðû²¼¸üС¢¹²Ïí¹¤¾ßºÍЭµ÷»î¶¯¡£¡£¡£ ¡£ÔÚÐí¶àÇéÐÎÏ£¬£¬£¬£¬ £¬£¬ZingoStealer»¹»á·Ö·¢ÌØÁíÍâ¶ñÒâÈí¼þ£¬£¬£¬£¬ £¬£¬ÈçRedLine StealerºÍXMRigµÈ¡£¡£¡£ ¡£Ö»¹Ü¿ÉÒÔ±»¶à¸ö¹¥»÷ÕßʹÓ㬣¬£¬£¬ £¬£¬µ«¸Ã¶ñÒâÈí¼þÖ÷ÒªÒÔÓÎÏ·×÷±×Æ÷¡¢ÃÜÔ¿ÌìÉúÆ÷ºÍµÁ°æÈí¼þΪÓÕ¶ü£¬£¬£¬£¬ £¬£¬Õë¶Ô½²¶íÓïµÄÄ¿µÄ¡£¡£¡£ ¡£


https://blog.talosintelligence.com/2022/04/haskers-gang-zingostealer.html