ºÚ¿ÍÕë¶Ô FCC ºÍ¼ÓÃÜÇ®±Ò¹«Ë¾Ìᳫ¸ß¼¶ Okta ÍøÂç´¹ÂÚ¹¥»÷

Ðû²¼Ê±¼ä 2024-03-04
1. ºÚ¿ÍÕë¶Ô FCC ºÍ¼ÓÃÜÇ®±Ò¹«Ë¾Ìᳫ¸ß¼¶ Okta ÍøÂç´¹ÂÚ¹¥»÷


3ÔÂ2ÈÕ£¬£¬£¬£¬£¬£¬Ò»ÖÖÃûΪ CryptoChameleon µÄÐÂÍøÂç´¹ÂÚ¹¤¾ß°ü±»ÓÃÓÚÕë´ºÁª°îͨѶίԱ»á (FCC) Ô±¹¤£¬£¬£¬£¬£¬£¬¸Ã¹¤¾ß°üʹÓÃרÃÅΪ Okta ÖÆ×÷µÄµ¥µãµÇ¼ (SSO) Ò³Ãæ£¬£¬£¬£¬£¬£¬ÕâÐ©Ò³ÃæÓëÔ­Ê¼Ò³ÃæºÜÊÇÏàËÆ¡£¡£¡£ ¡£¡£¡£¡£¸Ã»î¶¯»¹Õë¶Ô Binance¡¢Coinbase¡¢Kraken ºÍ Gemini µÈ¼ÓÃÜÇ®±Òƽ̨µÄÓû§ºÍÔ±¹¤£¬£¬£¬£¬£¬£¬Ê¹ÓÃð³ä Okta¡¢Gmail¡¢iCloud¡¢Outlook¡¢Twitter¡¢Yahoo ºÍ AOL µÄÍøÂç´¹ÂÚÒ³Ãæ¡£¡£¡£ ¡£¡£¡£¡£¹¥»÷ÕßÈ«ÐIJ߻®ÁËÖØ´óµÄÍøÂç´¹ÂÚºÍÉç»á¹¤³Ì¹¥»÷£¬£¬£¬£¬£¬£¬°üÀ¨µç×ÓÓʼþ¡¢¶ÌÐźÍÓïÒôÍøÂç´¹ÂÚ£¬£¬£¬£¬£¬£¬ÒÔÓÕÆ­Êܺ¦ÕßÔÚÍøÂç´¹ÂÚÒ³ÃæÉÏÊäÈëÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬ÀýÈçÓû§Ãû¡¢ÃÜÂ룬£¬£¬£¬£¬£¬ÔÚijЩÇéÐÎÏÂÉõÖÁ°üÀ¨´øÕÕÆ¬µÄÉí·ÝÖ¤¼þ¡£¡£¡£ ¡£¡£¡£¡£LookoutÑо¿Ö°Ô±·¢Ã÷µÄÍøÂç´¹ÂÚ²Ù×÷ ÓëScattered SpiderºÚ¿Í×éÖ¯ÔÚ 2022 Äê ¾ÙÐÐµÄ Oktapus »î¶¯ ÀàËÆ  £¬£¬£¬£¬£¬£¬µ«Ã»ÓÐ×ã¹»µÄÖ¤¾Ý֤ʵÆä¹éÊô¡£¡£¡£ ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/hackers-target-fcc-crypto-firms-in-advanced-okta-phishing-attacks/


2. ÃÀ¹úÍøÂçºÍÖ´·¨»ú¹¹¶Ô PHOBOS ÀÕË÷Èí¼þ¹¥»÷·¢³öÖÒÑÔ


3ÔÂ2ÈÕ£¬£¬£¬£¬£¬£¬ÃÀ¹ú CISA¡¢FBI ºÍ MS-ISAC Ðû²¼ÁªºÏÍøÂçÇ徲ͨ¸æ (CSA)£¬£¬£¬£¬£¬£¬ÖÒÑÔÉæ¼°Backmydata¡¢Devos¡¢Eight¡¢Elking ºÍ Faust µÈPhobos ÀÕË÷Èí¼þ±äÖֵĹ¥»÷¡£¡£¡£ ¡£¡£¡£¡£ÕâЩ¹¥»÷×î½ü±¬·¢ÔÚ 2024 Äê 2 Ô£¬£¬£¬£¬£¬£¬Ä¿µÄÊÇÕþ¸®¡¢½ÌÓý¡¢½ôÆÈЧÀÍ¡¢Ò½ÁƱ£½¡ºÍÆäËûÒªº¦»ù´¡ÉèÊ©²¿·Ö¡£¡£¡£ ¡£¡£¡£¡£Phobos ²Ù×÷½ÓÄÉÀÕË÷Èí¼þ¼´Ð§ÀÍ (RaaS) ģʽ£¬£¬£¬£¬£¬£¬×Ô 2019 Äê 5 ÔÂÒÔÀ´Ò»Ö±»îÔ¾¡£¡£¡£ ¡£¡£¡£¡£Æ¾Ö¤¹ûÕæÈªÔ´µÄÐÅÏ¢£¬£¬£¬£¬£¬£¬ÓÉÓÚÊӲ쵽սÊõ¡¢ÊÖÒպͳÌÐò (TTP) ·½ÃæµÄÏàËÆÐÔ£¬£¬£¬£¬£¬£¬Õþ¸®×¨¼Ò½«¶à¸ö Phobos ÀÕË÷Èí¼þ±äÌåÓë Phobos ÈëÇÖÁªÏµÆðÀ´¡£¡£¡£ ¡£¡£¡£¡£Phobos ÈëÇÖ»¹É漰ʹÓÃÖÖÖÖ¿ªÔ´¹¤¾ß£¬£¬£¬£¬£¬£¬°üÀ¨ Smokeloader¡¢Cobalt StrikeºÍ Bloodhound¡£¡£¡£ ¡£¡£¡£¡£ÕâЩ¹¤¾ßÔÚ²î±ðµÄ²Ù×÷ÇéÐÎÖÐÆÕ±é¿ÉÓÃÇÒÓû§ÓѺ㬣¬£¬£¬£¬£¬ÓÐÖúÓÚ Phobos ¼°ÆäÏà¹Ø±äÌåÔÚÖÖÖÖÍþв¼ÓÈëÕßÖеÄÊ¢ÐС£¡£¡£ ¡£¡£¡£¡£¾ÝÊӲ죬£¬£¬£¬£¬£¬Phobos ¹¥»÷±³ºóµÄÍþв¼ÓÈëÕßͨ¹ýʹÓÃÍøÂç´¹Âڻ»ñµÃÁ˶ÔÒ×Êܹ¥»÷ÍøÂçµÄ³õʼ»á¼ûȨÏÞ¡£¡£¡£ ¡£¡£¡£¡£ËûÃÇÑïÆúÒþ²ØµÄÓÐÓøºÔØ»òʹÓû¥ÁªÍøÐ­Òé (IP) ɨÃ蹤¾ß£¨ÀýÈç Angry IP Scanner£©À´ËÑË÷Ò×Êܹ¥»÷µÄÔ¶³Ì×ÀÃæÐ­Òé (RDP) ¶Ë¿Ú»òÔÚ Microsoft Windows ÇéÐÎÖÐʹÓà RDP¡£¡£¡£ ¡£¡£¡£¡£Phobos ʹÓà Windows Æô¶¯Îļþ¼ÐºÍÔËÐÐ×¢²á±íÏîÔÚÊÜѬȾµÄÇéÐÎÖмá³Ö³¤ÆÚÐÔ¡£¡£¡£ ¡£¡£¡£¡£Íþв¼ÓÈëÕßʹÓà Bloodhound¡¢Sharphound¡¢Mimikatz¡¢NirSoft ºÍ Remote Desktop Passview µÈ¿ªÔ´¹¤¾ßÀ´Ã¶¾Ù»î¶¯Ä¿Â¼²¢ÍøÂçÆ¾Ö¤¡£¡£¡£ ¡£¡£¡£¡£Phobos ÔËÓªÉÌʹÓà WinSCP ºÍ Mega.io ½«Êý¾Ýй¶µ½ FTP ЧÀÍÆ÷»òÔÆ´æ´¢¡£¡£¡£ ¡£¡£¡£¡£


https://securityaffairs.com/159822/cyber-crime/cisa-phobos-ransomware-attacks.html


3. CutOut.Pro AI¹¤¾ßÊý¾Ýй¶£¬£¬£¬£¬£¬£¬ºÚ¿Íй¶2000ÍòÓû§ÐÅÏ¢


3ÔÂ2ÈÕ£¬£¬£¬£¬£¬£¬CutOut.Pro ÊÇÒ»¸öרÃÅ´ÓÊÂͼÏñºÍÊÓÆµ±à¼­µÄÈ˹¤ÖÇÄÜÆ½Ì¨£¬£¬£¬£¬£¬£¬ÓÚ 2024 Äê 2 Ô 27 ÈÕÃæÁÙºÚ¿ÍÉù³ÆµÄÊý¾Ýй¶¡£¡£¡£ ¡£¡£¡£¡£Ò»Ãû×Ô³Æ KryptonZambie µÄÈË×Ô¸æ·ÜÓ£¬£¬£¬£¬£¬£¬Éù³ÆËûÃÇÒѾ­Àֳɹ¥ÆÆÁË CutOut.Pro£¬£¬£¬£¬£¬£¬ÕâÊÇÒ»¼Ò×ܲ¿Î»ÓÚÐÂ¼ÓÆÂµÄÆ½Ì¨£¬£¬£¬£¬£¬£¬ÒÔÆäÈ˹¤ÖÇÄÜÇý¶¯µÄ¹¤¾ß¶øÖøÃû£¬£¬£¬£¬£¬£¬ÊʺÏÊÓ¾õÉè¼ÆºÍÄÚÈÝ´´×÷£¬£¬£¬£¬£¬£¬ÌØÊâÊÇÔÚͼÏñºÍÊÓÆµ±à¼­ÁìÓò¡£¡£¡£ ¡£¡£¡£¡£ÒÔºó´Îй¶ÖÐÌáÈ¡µÄÊý¾ÝÒÑÔÚÎÛÃûÕÑÖøµÄÍøÂç·¸·¨ºÍºÚ¿ÍÂÛ̳£¨°üÀ¨Breach Forums £©ÉÏй¶£¬£¬£¬£¬£¬£¬ÏÖÔÚÕýÔÚ¶íÓïÂÛ̳ÖÐÈö²¥¡£¡£¡£ ¡£¡£¡£¡£¹ØÓÚй¶Êý¾ÝµÄÄÚÈÝ£¬£¬£¬£¬£¬£¬Hackread.comÉîÈëÆÊÎö·¢Ã÷£¬£¬£¬£¬£¬£¬¼Í¼°üÀ¨ÒÔÏÂÐÅÏ¢£ºÈ«Ãû¡¢IPµØµã¡¢µç×ÓÓʼþµØµã¡¢ÃÜÂë¹þÏ£Öµ¡¢ºÍÕÊ»§×¢²áÊý¾Ý¡£¡£¡£ ¡£¡£¡£¡£ÓëºÚ¿ÍÔÚÁбíÖеÄ˵·¨Ïà·´£¬£¬£¬£¬£¬£¬Hackread ¾ÙÐÐµÄÆÊÎöÅú×¢£¬£¬£¬£¬£¬£¬Ð¹Â¶µÄÊý¾Ý²»°üÀ¨µç»°ºÅÂë¡¢API »á¼ûȨÏÞ»òÓ¦ÓóÌÐòÃÜÔ¿¡£¡£¡£ ¡£¡£¡£¡£Õâ²¢²»ÊÇ CutOut.Pro µÚÒ»´ÎÓÉÓÚ¹ýʧµÄÔµ¹ÊÔ­ÓɳÉΪͷÌõÐÂÎÅ¡£¡£¡£ ¡£¡£¡£¡£2023 Äê 2 Ô£¬£¬£¬£¬£¬£¬ËûÃǵÄһ̨ Elasticsearch ЧÀÍÆ÷й¶Á˸ߴï 9 GB µÄ¿Í»§Êý¾Ý¡£¡£¡£ ¡£¡£¡£¡£ÕâЩÊý¾ÝÖÐÓÐÁè¼Ý 2200 ÍòÌõÈÕÖ¾ÌõÄ¿£¬£¬£¬£¬£¬£¬ÆäÖÐÌáµ½ÁËСÎÒ˽¼ÒÓû§ºÍÆóÒµÕÊ»§µÄÓû§Ãû¡£¡£¡£ ¡£¡£¡£¡£


https://www.hackread.com/hacker-cutout-pro-ai-tool-data-breach/


4. ÕÛ¿ÛÁãÊÛ¾ÞÍ· Pepco ÒòÍøÂç·¸·¨·Ö×ÓËðʧ 1500 ÍòÅ·Ôª


2ÔÂ29ÈÕ£¬£¬£¬£¬£¬£¬Õâ¼Ò×ܲ¿Î»ÓÚÓ¢¹úµÄ¹«Ë¾±¨¸æ³Æ£¬£¬£¬£¬£¬£¬ÓÉÓÚ¡°ÖØ´óµÄڲƭÐÔÍøÂç´¹ÂÚ¹¥»÷¡±£¬£¬£¬£¬£¬£¬ËðʧÁË 1550 ÍòÅ·Ôª£¨Ô¼ºÏ 1680 ÍòÃÀÔª£©µÄÏֽ𡣡£¡£ ¡£¡£¡£¡£ÊÓ²ìÒѾ­Æô¶¯£¬£¬£¬£¬£¬£¬Pepco ÕýÔÚÓëÒøÐк;¯·½ÏàÖú×·»ØÕâ±Ê×ʽ𣬣¬£¬£¬£¬£¬µ«¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬£¬£¬£¬ÏÖÔÚÉв»ÇåÎúÊÇ·ñ¿ÉÒÔ×·»Ø×ʽ𡣡£¡£ ¡£¡£¡£¡£Pepco ¼¯ÕûÌåÏÖ£º¡°Ïֽ׶Σ¬£¬£¬£¬£¬£¬¸ÃÊÂÎñËÆºõ²¢Î´Éæ¼°Èκοͻ§¡¢¹©Ó¦ÉÌ»òͬʵÄÐÅÏ¢»òÊý¾Ý¡£¡£¡£ ¡£¡£¡£¡£¡±Pepco ¼¯ÍÅÓµÓÐ Pepco¡¢Dealz ºÍ Poundland Æ·ÅÆ¡£¡£¡£ ¡£¡£¡£¡£Pepco µÄ 3,600 ¼ÒÃŵê±é²¼ 19 ¸öÅ·ÖÞ¹ú¼Ò£¬£¬£¬£¬£¬£¬Ã¿ÔÂÓµÓÐÁè¼Ý 3000 ÍòÖ÷¹Ë¡£¡£¡£ ¡£¡£¡£¡£Æ¾Ö¤¸Ã¹«Ë¾¶ÔÊÂÎñµÄ¼òÒªÐÎòºÍËðʧ½ð¶î£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾¿ÉÄÜÊÇÉÌÒµµç×ÓÓʼþй¶ (BEC) ÍýÏëµÄÄ¿µÄ£¬£¬£¬£¬£¬£¬ÔÚ¸ÃÍýÏëÖУ¬£¬£¬£¬£¬£¬ÍøÂç·¸·¨·Ö×ÓʹÓñ»ºÚ¿ÍÈëÇֵĵç×ÓÓʼþÕÊ»§À´ÓÕÆ­Ä¿µÄ×éÖ¯µÄÔ±¹¤½«×ʽðתÈëËûÃǵÄÒøÐÐÕË»§¿ØÖÆ¡£¡£¡£ ¡£¡£¡£¡£


https://www.securityweek.com/discount-retail-giant-pepco-loses-e15-million-to-cybercriminals/


5. Ð嵀 Silver SAML ¹¥»÷¿É¹æ±ÜÉí·ÝϵͳÖÐµÄ Golden SAML ·ÀÓù


2ÔÂ29ÈÕ£¬£¬£¬£¬£¬£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±Åû¶ÁËÒ»ÖÖÃûΪSilver SAMLµÄй¥»÷ÊÖÒÕ£¬£¬£¬£¬£¬£¬×ÝÈ»ÔÚÕë¶Ô Golden SAML ¹¥»÷½ÓÄÉ»º½â²½·¥µÄÇéÐÎÏ£¬£¬£¬£¬£¬£¬¸ÃÊÖÒÕÒ²ÄÜÀֳɡ£¡£¡£ ¡£¡£¡£¡£Semperis Ñо¿Ö°Ô± Tomer Nahum ºÍ Eric Woodruff ÔÚÓë The Hacker News ·ÖÏíµÄÒ»·Ý±¨¸æÖÐÌåÏÖ£¬£¬£¬£¬£¬£¬Silver SAML¡°Ê¹µÃ Entra ID µÈÉí·ÝÌṩÉÌÄܹ»Ê¹Óà SAML ¶ÔÉèÖÃΪʹÓà SAML ¾ÙÐÐÉí·ÝÑéÖ¤µÄÓ¦ÓóÌÐò£¨ÀýÈç Salesforce£©Ìᳫ¹¥»÷¡± ¡£¡£¡£ ¡£¡£¡£¡£Golden SAML£¨Çå¾²¶ÏÑÔ±ê¼ÇÓïÑÔµÄËõд£©ÓÉ Cyber Ark ÓÚ 2017 ÄêÊ״μͼ¡£¡£¡£ ¡£¡£¡£¡£¼ò¶øÑÔÖ®£¬£¬£¬£¬£¬£¬¸Ã¹¥»÷ǰÑÔÐèÒªÀÄÓÿɻ¥²Ù×÷µÄÉí·ÝÑéÖ¤±ê×¼À´Ã°³ä×éÖ¯ÖеÄÏÕЩÈκÎÉí·Ý¡£¡£¡£ ¡£¡£¡£¡£ËüÒ²ÀàËÆÓÚ½ðÆ±¹¥»÷£¬£¬£¬£¬£¬£¬ÓÉÓÚËüʹ¹¥»÷ÕßÄܹ»ÒÔÈκÎȨÏÞδ¾­ÊÚȨµØ»á¼ûÁªºÏÖеÄÈκÎЧÀÍ£¬£¬£¬£¬£¬£¬²¢ÒÔÒþÃØµÄ·½·¨ÔÚ¸ÃÇéÐÎÖмá³Ö³¤ÆÚÐÔ¡£¡£¡£ ¡£¡£¡£¡£Ê¹ÓøÃÒªÁìµÄÏÖʵ¹¥»÷ºÜÉÙ¼û£¬£¬£¬£¬£¬£¬µÚÒ»¸ö ÓмͼµÄ¹¥»÷ÊÇͨ¹ýʹÓÃÊÜËðµÄ SAML ÁîÅÆÊðÃûÖ¤ÊéαÔì SAML ÁîÅÆÀ´Ë𺦠SolarWinds »ù´¡ÉèÊ©£¬£¬£¬£¬£¬£¬´Ó¶ø»ñµÃÖÎÆÊÎö¼ûȨÏÞ ¡£¡£¡£ ¡£¡£¡£¡£Î¢ÈíÔÚ 2023 Äê 9 ÔÂ͸¶£¬£¬£¬£¬£¬£¬Golden SAML »¹±»´úºÅΪPeach SandstormµÄÒÁÀÊÍþвÐÐΪÕßÔÚ 2023 Äê 3 ÔµÄÒ»´ÎÈëÇÖÖÐÎäÆ÷»¯£¬£¬£¬£¬£¬£¬ÎÞÐèÈκÎÃÜÂë¼´¿É»á¼ûδÃüÃûÄ¿µÄµÄÔÆ×ÊÔ´¡£¡£¡£ ¡£¡£¡£¡£


https://thehackernews.com/2024/02/new-silver-saml-attack-evades-golden.html


6. ״ʦÊÂÎñËùHouser LLP±¨¸æÊý¾Ýй¶ӰÏìÁè¼Ý 325000 ÈË


2ÔÂ29ÈÕ£¬£¬£¬£¬£¬£¬×¨ÃÅΪ×ÅÃû½ðÈÚ»ú¹¹ÌṩЧÀ͵ÄÃÀ¹ú״ʦÊÂÎñËù Houser LLP ÌåÏÖ£¬£¬£¬£¬£¬£¬2023 Äê 5 Ô·¢Ã÷µÄÒ»´ÎϵͳÎó²î̻¶ÁËÁè¼Ý 325,000 È˵ÄСÎÒ˽¼ÒÊý¾Ý£¬£¬£¬£¬£¬£¬¿ÉÄܰüÀ¨ÐÅÓÿ¨ºÅµÈÃô¸ÐÐÅÏ¢¡£¡£¡£ ¡£¡£¡£¡£ÔÚÃåÒòÖÝ×ÜÉó²é³¤ÖÜÈýÐû²¼µÄÒ»·Ýî¿ÏµÎļþÖУ¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬£¬£¬£¬Ä³Ð©ÎļþÔÚÊÂÎñʱ´ú±»¼ÓÃÜ£¬£¬£¬£¬£¬£¬²¢¡°´ÓÍøÂçÖи´ÖƺͻñÈ¡¡±¡£¡£¡£ ¡£¡£¡£¡£ºÀɪ˵£¬£¬£¬£¬£¬£¬ÕâЩÊý¾Ý°üÀ¨ÐÕÃû¡°ÒÔ¼°Éç»áÇå¾²ºÅÂë¡¢¼ÝʻִÕÕºÅÂ롢СÎÒ˽¼ÒÄÉ˰ʶÓÖÃûÂë¡¢½ðÈÚÕË»§ÐÅÏ¢ºÍÒ½ÁÆÐÅÏ¢ÖеÄÒ»Ïî»ò¶àÏ¡£¡£¡£ ¡£¡£¡£¡£¸Ã¹«Ë¾»¹Ïò¼ÓÖÝ×ÜÉó²é³¤Ìá½»ÁË֪ͨ¡£¡£¡£ ¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬£¬£¬£¬Ò»¼ÒδÏêϸ˵Ã÷µÄµÚÈý·½¹«Ë¾ØÊºóÈ·¶¨£¬£¬£¬£¬£¬£¬5 Ô 7 ÈÕÖÁ 9 ÈÕʱ´ú£¬£¬£¬£¬£¬£¬Houser µÄÍøÂç±£´æ¡°Î´¾­ÊÚȨµÄ»á¼û¡±¡£¡£¡£ ¡£¡£¡£¡£î¿ÏµÎļþ³Æ£¬£¬£¬£¬£¬£¬ºÀɪºÜ¿ì¾ÍÓë¹¥»÷ÕßÈ¡µÃÁËÁªÏµ£¬£¬£¬£¬£¬£¬µ«Ã»ÓÐÚ¹ÊÍͨѶµÄÐÔ×Ó¡£¡£¡£ ¡£¡£¡£¡£Recorded Future News ÒÑÁªÏµ¸Ã¹«Ë¾ÒÔ»ñÈ¡¸ü¶àÐÅÏ¢¡£¡£¡£ ¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬£¬£¬£¬ÔÚ 2023 Äê 6 ÔµÄij¸öʱ¼ä£¬£¬£¬£¬£¬£¬¡°Î´¾­ÊÚȨµÄÐÐΪÕß֪ͨ Houser£¬£¬£¬£¬£¬£¬ËûÃÇɾ³ýÁËÈκα»µÁÊý¾ÝµÄ¸±±¾£¬£¬£¬£¬£¬£¬²¢ÇÒ²»»á·Ö·¢Èκα»µÁÎļþ¡±¡£¡£¡£ ¡£¡£¡£¡£Îļþ³Æ£¬£¬£¬£¬£¬£¬µÚÈý·½¹©Ó¦ÉÌÓÚ½ñÄê 1 Ô 18 ÈÕÍê³ÉÁËÉó²é¡£¡£¡£ ¡£¡£¡£¡£


https://therecord.media/houser-law-firm-reports-data-breach