CISAºÍFBIÐû²¼Õë¶ÔKaseya¹©Ó¦Á´¹¥»÷Êܺ¦ÕßµÄÖ¸ÄÏ £»Ñо¿ÍŶÓÅû¶Ð½©Ê¬ÍøÂçmirai_pteaµÄDDoS¹¥»÷»î¶¯

Ðû²¼Ê±¼ä 2021-07-07

1.CISAºÍFBIÐû²¼Õë¶ÔKaseya¹©Ó¦Á´¹¥»÷Êܺ¦ÕßµÄÖ¸ÄÏ


1.jpg


CISAºÍFBIÁªºÏÐû²¼ÁËÕë¶ÔÊܵ½Kaseya¹©Ó¦Á´¹¥»÷Ó°ÏìµÄÊܺ¦ÕßµÄÖ¸ÄÏ¡£ÕâÁ½¸ö»ú¹¹½¨Òé×é֯ʹÓÃKaseyaÌṩµÄ¼ì²â¹¤¾ßÀ´¼ì²éËûÃǵÄϵͳÊÇ·ñ´æÔÚÈëÇÖ¼£Ï󣬲¢ÆôÓöàÒòËØÉí·ÝÑéÖ¤(MFA)¡£´ËÍ⣬×éÖ¯»¹Ó¦Ê¹Óð×Ãûµ¥À´ÍⲿÏÞÖÆ¶ÔÆäÄÚ²¿×ʲúµÄ·ÃÎÊ£¬²¢Ê¹Ó÷À»ðǽ»òVPN± £»¤ÆäÔ¶³Ì¼à¿Ø¹¤¾ßµÄ¹ÜÀí½çÃæ¡£¶øÊÜÓ°ÏìµÄMSP¿Í»§ÐèҪȷ±£±¸·ÝÊÇ×îеÄ£¬¶øÇÒÁ¢¼´°²×°¹©Ó¦ÉÌÌṩµÄ×îеIJ¹¶¡¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/119728/cyber-crime/cisa-fbi-guidance-kaseya-attack.html


2.¹ú¼ÊÐ̾¯×éÖ¯LyrebirdÐж¯´þ²¶Ä«Î÷¸çºÚ¿ÍDr HeX


2.jpg


¹ú¼ÊÐ̾¯×éÖ¯ÌᳫµÄLyrebirdÐж¯´þ²¶ÁËÄ«Î÷¸çºÚ¿ÍDr HeX¡£Dr HeX×Ô2009ÄêÒÔÀ´¿ªÊ¼»îÔ¾£¬½øÐйý¶àÖÖÍøÂç·¸×ï»î¶¯£¬°üÂÞÍøÂçµöÓã¡¢¶ñÒâÈí¼þ¿ª·¢ºÍÆÛÕ©µÈ¡£ÔÚ´Ë´ÎÐж¯ÖУ¬Group-IBͨ¹ýÕë¶Ô·¨¹úÄ³ÒøÐеÄÍøÂçµöÓ㹤¾ß°üʶ±ð³öÁ˸ÃÍøÂç·¸×ï·Ö×Ó¡£´ËÍ⣬¸ÃºÚ¿Í»¹ÌرðÍÆ¹ãÁËËùνµÄZombi Bot£¬¾Ý³ÆÆäÖаüÂÞ814¸ö©¶´£¬ÓÐ72¸öδ¹ûÈ»µÄ©¶´¡¢Ò»¸ö±©Á¦ÆÆ½â·¨Ê½¡¢webshellºÍºóÃÅɨÃ跨ʽ£¬»¹¿ÉÒÔÓÃÀ´Ö´ÐÐDDoS¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/07/interpol-arrests-hacker-in-morocco-who.html


3.Ñо¿ÍŶÓÅû¶Ð½©Ê¬ÍøÂçmirai_pteaµÄDDoS¹¥»÷»î¶¯


3.jpg


Ñо¿ÍŶÓÅû¶ÁËÊÜMiraiÆô·¢µÄн©Ê¬ÍøÂçmirai_ptea£¬ÀûÓÃKGUARDÌṩµÄÊý×ÖÊÓÆµÂ¼Ïñ»ú(DVR)ÖеÄÒ»¸öδ¹ûÈ»µÄ©¶´À´ÌᳫÂþÑÜʽ¾Ü¾ø·þÎñ(DDoS)¹¥»÷¡£Ñо¿ÈËÔ±ÓÚ2021Äê3ÔÂ23ÈÕÊ×´ÎÊÓ²ìÁ˸ù¥»÷»î¶¯£¬ºóÓÖÓÚ2021Äê6ÔÂ22ÈÕÔٴμì²âµ½Á˹¥»÷ʵÑé¡£Ñо¿ÍŶӳƽ©Ê¬Ô´IPµÄµØÀíÂþÑÜÖ÷Òª¼¯ÖÐÔÚÃÀ¹ú¡¢º«¹úºÍ°ÍÎ÷£¬¶øÊܺ¦Õ߱鲼ŷÖÞ¡¢ÑÇÖÞ¡¢°Ä´óÀûÑÇ¡¢±±ÃÀºÍÄÏÃÀ£¬ÒÔ¼°·ÇÖÞ²¿ÃŵØÓò¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2021/07/newly-discovered-mirai-botnet-is.html


4.ºÚ¿ÍÔÚ°µÍø¹ûÈ»Éç½»ÍøÕ¾GETTR½ü9Íò»áÔ±µÄ¸öÈËÐÅÏ¢


4.jpg


ºÚ¿ÍÔÚ°µÍøÉϹûÈ»ÁËÉç½»ÍøÕ¾GETTR½ü9Íò»áÔ±µÄ¸öÈËÐÅÏ¢¡£GETTRÊÇÒ»¸öеÄÇ×ÌØÀÊÆÕµÄÉ罻ýÌåÆ½Ì¨£¬ÓÉÇ°ÌØÀÊÆÕÕÕÁϽÜÉ­Ã×ÀÕ´´½¨£¬×÷ΪTwitterµÄÌæ´úÆ·¡£Äþ¾²¹«Ë¾Hudson RockÌåÏÖ£¬ºÚ¿ÍÀûÓÃÒ»¸ö²»Äþ¾²µÄAPIץȡ87973ÃûGETTR³ÉÔ±µÄÊý¾Ý£¬°üÂÞµç×ÓÓʼþµØÖ·¡¢êdzơ¢ÐÕÃû¡¢³öÉúÈÕÆÚ¡¢Í·ÏñURL¡¢Å侰ͼƬ¡¢Î»ÖᢸöÈËÍøÕ¾ºÍÆäËûÄÚ²¿ÍøÕ¾Êý¾Ý¡£Ä¿Ç°£¬GETTRÍøÕ¾²¢Î´¶Ô´ËʽøÐлظ´¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hacker-dumps-private-info-of-pro-trump-gettr-social-network-members/


5.GriefÉù³ÆÆä¹¥»÷ŦԼ¿µ¸´Ò½ÔºRSS²¢»ñÈ¡4GBµÄÊý¾Ý


5.jpg


ºÚ¿ÍÍÅ»ïGriefÉù³ÆÆä¹¥»÷ÁËŦԼµÄ¿µ¸´Ò½ÔºRehabilitation Support Services(RSS)²¢»ñÈ¡ÁË4GBµÄÊý¾Ý¡£6ÔÂ2ÈÕ£¬Grief½«¸Ã»ú¹¹¼ÓÈëÊܺ¦ÕßÃûµ¥£¬²¢³ÆÆäÒѾ­ÇÔÈ¡ÁË4GBÊý¾Ý¡£6ÔÂ29ÈÕ£¬GriefÉÏ´«ÁËÇÔÈ¡µÄÊý¾Ý£¬°üÂÞ×ʲúÇ·Õ®±í¡¢Ë°ÊÕ¡¢Ö§Æ±¡¢´æ¿î¡¢ÒøÐжÔÕ˵¥¡¢·¢Æ±¡¢ºÍ×ʱ¾ÏîĿժҪµÈ²ÆÕþÐÅÏ¢ £»Ò½ÁƱ£½¡Ö¤Ã÷¡¢Ò½ÁÆÎļþºÍ´û¿î´û¿îÉêÇ룬ÒÔ¼°²¿Ãſͻ§ºÍÔ±¹¤µÄÉç»áÄþ¾²ºÅÂëºÍ¼ÝÕÕºÅÂëµÈ¸öÈËÐÅÏ¢¡£¸Ã»ú¹¹ÉÐδ¶Ô´ËÊÂ×÷³ö»ØÓ¦¡£


Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/ny-grief-claims-to-have-breached-rehabilitation-support-services/


6.Money.co.ukÐû²¼2021ÄêQ2ÆÛÕ©ºÍÍøÂç·¸×ï·ÖÎö³ÂËß


6.jpg


Money.co.ukÐû²¼ÁË2021ÄêQ2Ó¢¹úÓÐ¹ØÆÛÕ©ºÍÍøÂç·¸×ïµÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬2020ÄêÍø¹ºÏúÊÛ¶îÔö³¤ÁË46%£¬Ôö·ùΪ½üÊ®Äê×î¸ß¡£Òò´Ë£¬ÆÛÕ©»î¶¯Ò²¼±¾çÔö¼Ó£¬2021ÄêÉϰëÄêËðʧÁè¼Ý10ÒÚÓ¢°÷¡£2021ÄêQ2¹²ÓÐ81018ÆðÕ©Æ­ºÍÍøÂç·¸×ï°¸¼þ£¬×ܼÆËðʧΪ3.823ÒÚÓ¢°÷ £»Ïà±È֮ϣ¬2021Äê1ÔÂÖÁ3Ô·¢ÉúÁË137695Æð·¸×ï°¸¼þ£¬Éæ°¸½ð¶îΪ6.256ÒÚÓ¢°÷¡£¶øÔÚ2021Äê4ÔÂÖÁ6ÔÂÆÚ¼ä£¬´ËÀà»î¶¯µÄÊܺ¦Õ߯½¾ùÿÈËËðʧÁË4719Ó¢°÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.money.co.uk/credit-cards/quarterly-fraud-report