ºÉÀ¼º½Ô˹«Ë¾Royal DirkzwagerÔâµ½PlayµÄÀÕË÷¹¥»÷

Ðû²¼Ê±¼ä 2023-03-21

1¡¢ºÉÀ¼º½Ô˹«Ë¾Royal DirkzwagerÔâµ½PlayµÄÀÕË÷¹¥»÷


¾Ý3ÔÂ20ÈÕ±¨µÀ£¬£¬£¬£¬ºÉÀ¼º½Ô˹«Ë¾Royal DirkzwagerÔâµ½ÀÕË÷ÍÅ»ïPlayµÄ¹¥»÷¡£¡£¡£¡£¡£¡£ÀÕË÷ÍŻォ¸Ã¹«Ë¾Ìí¼Óµ½ÆäÍøÕ¾ÉÏ£¬£¬£¬£¬²¢Ðû²¼ÇÔÈ¡ÁËÔ±¹¤ ID¡¢»¤ÕÕºÍÌõÔ¼µÈÉñÃØÊý¾Ý¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ï×î³õ¹ûÕæÁËÒ»¸ö5 GBµÄÎļþ×÷Ϊ¹¥»÷Ö¤¾Ý£¬£¬£¬£¬²¢Íþв˵£¬£¬£¬£¬ÈôÊǹ«Ë¾²»¸¶Êê½ð¾Í¹ûÕæËùÓеÄÊý¾Ý¡£¡£¡£¡£¡£¡£¸Ãº½Ô˹«Ë¾ÌåÏÖ£¬£¬£¬£¬¹¥»÷»î¶¯²¢Î´Ó°Ï칫˾µÄÔËÓª£¬£¬£¬£¬²¢Ö¤Êµ¹¥»÷ÕßÒѾ­´ÓÆä»ù´¡ÉèÊ©ÖÐÇÔÈ¡ÁËÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Òѽ«´ËÊÂ֪ͨÁ˺ÉÀ¼Êý¾Ý±£»£»£» £»£»£»£»¤¾Ö£¬£¬£¬£¬²¢ÕýÔÚÓëÀÕË÷ÍÅ»ï¾ÙÐÐ̸ÅС£¡£¡£¡£¡£¡£


https://securityaffairs.com/143714/cyber-crime/play-ransomware-royal-dirkzwager.html


2¡¢Ñо¿ÍŶӷ¢Ã÷ÒøÐÐľÂíMispaduµÄ´ó¹æÄ£¹¥»÷»î¶¯


¾ÝýÌå3ÔÂ20Èճƣ¬£¬£¬£¬Ñо¿ÍŶӷ¢Ã÷ÁË20¸öÕë¶ÔÖÇÀû¡¢Ä«Î÷¸ç¡¢ÃØÂ³ºÍÆÏÌÑÑÀµÄ´ó¹æÄ£À¬»øÓʼþ»î¶¯¡£¡£¡£¡£¡£¡£»£»£» £»£»£»£»î¶¯ÓÚ2022Äê8ÔÂ×óÓÒ×îÏÈ£¬£¬£¬£¬×èÖ¹2023Äê3ÔÂÉÏÑ®ÈÔÈ»»îÔ¾¡£¡£¡£¡£¡£¡£ÕâЩ»î¶¯ÒÀÀµÓÚÒøÐÐľÂíMispadu£¬£¬£¬£¬ÊÓ²ìЧ¹ûÏÔʾ£¬£¬£¬£¬¹¥»÷ÕßÒÑ´Ó×ܹ²17595¸öÆæÒìÍøÕ¾ÖÐÇÔÈ¡ÁË90518¸öƾ֤¡£¡£¡£¡£¡£¡£Mispadu½ÓÄÉÁËÔö½øÑ¬È¾ºÍ¼á³Ö³¤ÆÚÐÔµÄÐÂÊÖÒÕ£¬£¬£¬£¬°üÀ¨ÓÃÓÚ»ìÏý³õʼ½×¶Î¶ñÒâÈí¼þµÄαÔìÖ¤ÊéºÍÒ»¸öеĻùÓÚ.NETµÄºóÃÅ¡£¡£¡£¡£¡£¡£


https://www.infosecurity-magazine.com/news/mispadu-steals-90000-banking/


3¡¢Lowe's MarketϵͳÉèÖùýʧ´ó×ÚÆ¾Ö¤ºÍ¿Í»§ÐÅϢй¶


ýÌå3ÔÂ17ÈÕ͸¶£¬£¬£¬£¬Ñо¿Ö°Ô±ÔÚLowe's MarketÍøÕ¾ÉÏ·¢Ã÷ÁËÒ»¸ö¿É¹ûÕæ»á¼ûµÄÇéÐÎÎļþ(.env)¡£¡£¡£¡£¡£¡£Õâ¶Ô¹«Ë¾ÏµÍ³µÄÇå¾²×é³ÉÁËΣº¦£¬£¬£¬£¬ÓÉÓÚËüй¶ÁË´ó×ÚÆ¾Ö¤¡£¡£¡£¡£¡£¡£¸ÃÇéÐÎÎļþй¶ÁËAWS S3ЧÀÍÆ÷µÄ»á¼ûÃÜÔ¿ºÍ´æ´¢Í°Ãû³Æ£¬£¬£¬£¬Ðí¶àרÓÃÓÚÌØ¶¨ÍøÕ¾¹¦Ð§µÄÓ¦ÓóÌÐò±à³Ì½Ó¿Ú(API)ÃÜÔ¿£¬£¬£¬£¬ÒÔ¼°Facebook OAuthƾ֤ºÍGithub OAuthÁîÅÆµÈÐÅÏ¢¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖ£¬£¬£¬£¬Ð¹Â¶µÄƾ֤¿É±»¹¥»÷ÕßÓÃÓÚ¿ØÖƴ󲿷ÖÔÚÏßÊÐËÁµÄ¹¦Ð§£¬£¬£¬£¬Éó²é¿Í»§ÐÅÏ¢£¬£¬£¬£¬²¢ÀÄÓø¶·ÑЧÀ͵Ļá¼ûȨÏÞ¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬¸ÃÎÊÌâÒѾ­±»½â¾ö¡£¡£¡£¡£¡£¡£


https://cybernews.com/security/lowes-market-data-leak/


4¡¢ÈÕÁ¢ÄÜÔ´ÒòµÚÈý·½Èí¼þÌṩÉÌÔâµ½CLOP¹¥»÷Êý¾Ýй¶


3ÔÂ17ÈÕ±¨µÀ£¬£¬£¬£¬ÈÕÁ¢ÄÜÔ´µÄÉùÃ÷³Æ£¬£¬£¬£¬µÚÈý·½Èí¼þÌṩÉÌFORTRA GoAnywhere MFTÔâµ½ÁËCLOPµÄÀÕË÷¹¥»÷£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÔÚijЩ¹ú¼Ò/µØÇøµÄÔ±¹¤Êý¾Ý±»²»·¨»á¼û¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷ÊÇͨ¹ýʹÓÃGoAnywhere MFTÖеÄÎó²î£¨CVE-2023-0669£©ÊµÏֵ쬣¬£¬£¬¸ÃÎó²îÓÚ2023Äê2ÔÂ3ÈÕÊ×´ÎÅû¶¡£¡£¡£¡£¡£¡£ÈÕÁ¢ÄÜÔ´³ÆÆäÁ¬Ã¦¶Ô¸ÃÊÂÎñ×÷³ö·´Ó¦£¬£¬£¬£¬¶Ï¿ªÁËÊÜѬȾϵͳµÄÅþÁ¬£¬£¬£¬£¬²¢Æô¶¯ÄÚ²¿ÊÓ²ìÒÔÈ·¶¨Î¥¹æµÄÓ°Ïì¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ö¸³ö£¬£¬£¬£¬ÆäÍøÂçÔËÓª»ò¿Í»§Êý¾ÝµÄÇå¾²²¢Î´Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/hitachi-energy-confirms-data-breach-after-clop-goanywhere-attacks/


5¡¢KasperskyÐû²¼»ùÓÚContiµÄMeowCorpÀÕË÷Èí¼þ½âÃÜÆ÷


ýÌå3ÔÂ16Èճƣ¬£¬£¬£¬KasperskyÐû²¼ÁË»ùÓÚContiµÄÀÕË÷Èí¼þMeowCorpµÄÃ⺬»ìÃÜÆ÷¡£¡£¡£¡£¡£¡£2023Äê2ÔÂÏÂÑ®£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ÁËÂÛ̳ÉÏÐû²¼µÄÒ»²¿·ÖеÄÊý¾Ý¡£¡£¡£¡£¡£¡£ÆÊÎöºó·¢Ã÷ËüÃÇÓë2022Äê12Ô·¢Ã÷µÄ Conti±äÖÖMeowCorpÓйء£¡£¡£¡£¡£¡£ÔÚ¶Ô°üÀ¨258¸ö˽Կ¡¢Ô´´úÂëºÍһЩԤ±àÒë½âÃÜÆ÷µÄÊý¾Ý¾ÙÐÐÆÊÎöºó£¬£¬£¬£¬KasperskyÐû²¼ÁËа汾µÄ¹«¹²½âÃÜÆ÷¡£¡£¡£¡£¡£¡£½âÃÜÆ÷¿ÉÒÔ»Ö¸´ÃüÃûģʽºÍÀ©Õ¹ÃûΪ<file_name>.KREMLIN¡¢<file_name>.RUSSIAºÍ<file_name>.PUTINµÄ¼ÓÃÜÎļþ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/conti-based-ransomware-meowcorp-gets-free-decryptor/


6¡¢RedactedÐû²¼¹ØÓÚÀÕË÷ÍÅ»ïBianLianµÄÆÊÎö±¨¸æ


3ÔÂ16ÈÕ£¬£¬£¬£¬RedactedÐû²¼ÁËÀÕË÷ÍÅ»ïBianLianÉú³¤Ç÷ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£BianLianÓÚ2022Äê7ÔÂÊ×´ÎÔÚÒ°Íâ·ºÆð£¬£¬£¬£¬AvastÔÚ2023Äê1ÔÂÐû²¼ÁËÃ⺬»ìÃÜÆ÷¡£¡£¡£¡£¡£¡£×èÖ¹2023Äê3ÔÂ13ÈÕ£¬£¬£¬£¬¸ÃÍÅ»ïÔÚÆäÍøÕ¾ÉÏÁгöÁË×ܹ²118¸ö×éÖ¯£¬£¬£¬£¬ÆäÖоø´ó´ó¶¼(71%)ÊÇÃÀ¹ú¹«Ë¾¡£¡£¡£¡£¡£¡£ÔÚ×î½üµÄ¹¥»÷ÖеÄÖ÷񻂿±ðÊÇ£¬£¬£¬£¬BianLianÒѽ«ÆäÖØµã´Ó¼ÓÃÜÄ¿µÄÊý¾Ý×ªÒÆµ½½öÇÔȡϵͳÖÐÊý¾Ý²¢¾ÙÐÐÀÕË÷¡£¡£¡£¡£¡£¡£ÏÖÔÚÉв»ÇåÎúBianLian·ÅÆú¼ÓÃÜÕ½ÂÔÊÇÓÉÓÚAvastµÄ½âÃÜÆ÷£¬£¬£¬£¬ÕÕ¾ÉÓÉÓÚÒâʶµ½²»ÐèÒªÕâÒ»²¿·ÖÀ´ÀÕË÷Êê½ð¡£¡£¡£¡£¡£¡£


https://redacted.com/blog/bianlian-ransomware-gang-continues-to-evolve/