NB65³ÆÒÑÇÔÈ¡¶íÂÞ˹֧¸¶´¦ÖÃƽ̨Qiwi 10.5TBÊý¾Ý
Ðû²¼Ê±¼ä 2022-05-10¾ÝýÌå5ÔÂ9ÈÕ±¨µÀ£¬AnonymousÁ¥Êô»ú¹¹NB65Éù³ÆÒÑÇÔÈ¡¶íÂÞ˹֧¸¶´¦ÖÃƽ̨Qiwi 10.5 TBµÄÊý¾Ý¡£´Ë´Î鶵ÄÐÅÏ¢°üÂÞ3000ÍòÌõÖ§¸¶¼Ç¼£¬ÆäÖÐÉæ¼°1250ÍòÕÅÐÅÓÿ¨¡£¸ÃÍŻﻹÐû²¼ÁËÒ»·ÝÉùÃ÷£¬ÌåÏִ˴ι¥»÷Ö¼ÔÚÈÅÂÒ¶íÂÞ˹½ðÈÚÌåϵ¡£´ËÍ⣬¹¥»÷Õß»¹Ê¹ÓÃÀÕË÷Èí¼þ¼ÓÃÜÁËƽ̨µÄϵͳ£¬²¢ÍþвҪÔÚ3ÌìÆÚÏÞ¹ýºó£¬Ã¿ÌìÐû²¼100ÍòÌõ¼Ç¼¡£5ÔÂ5ÈÕ£¬NB65ÒѹûÈ»ÁË700ÍòÕÅÖ§¸¶¿¨Êý¾Ý£¬×÷Ϊ¹¥»÷µÄÖ¤¾Ý¡£Qiwi·ñÈÏÁËÔâµ½Á˹¥»÷£¬»¹ÌåÏÖÆäÖ§¸¶·þÎñÔËÐÐÕý³££¬¿Í»§Êý¾ÝÒ²ºÜÄþ¾²¡£
https://www.hackread.com/anonymous-nb65-hacki-russia-payment-processor-qiwi/
2¡¢Ó¢Î°´ïÒòδÅû¶¼ÓÃܻ¶ÔÓÎÏ·ÒµÎñµÄÓ°Ïì±»·£¿î550ÍòÃÀÔª
¾Ý5ÔÂ6ÈÕ±¨µÀ£¬Ó¢Î°´ï£¨NVIDIA£©±»ÃÀ¹ú֤ȯ½»Ò×ίԱ»á(SEC)·£¿î550ÍòÃÀÔª¡£´Ë´Î´¦·£µÄÀíÓÉΪδ³äʵÅû¶¼ÓÃÜ»õ±Ò¶ÔÆäÓÎÏ·ÒµÎñµÄÓ°Ïì¡£´Ó2017Ä꿪ʼ£¬¿Í»§Ô½À´Ô½¶àµØʹÓÃNVIDIA GPUÍÚ¾ò¼ÓÃÜ»õ±Ò¡£SEC·¢ÏÖ£¬NVIDIAÔÚ2018²ÆÄêÁ¬ÐøµÄ¼¸¸ö¼¾¶ÈÖУ¬Î´ÄÜÅû¶¼ÓÃÜÍÚ¿óÊÇÆäÏúÊÛΪÓÎÏ·Éè¼ÆµÄGPU´øÀ´µÄʵÖÊÐÔÊÕÈëÔö³¤µÄÖØÒªÒòËØ¡£Ä¿Ç°£¬NVIDIAͬÒâ²¢Ö§¸¶ÁË550ÍòÃÀÔªµÄ·£¿î¡£
https://www.bleepingcomputer.com/news/technology/nvidia-fined-for-failure-to-disclose-cryptomining-sales-boost/
3¡¢Uptycs·¢ÏÖ½üÆÚÕë¶ÔDocker API¶Ë¿Ú2375µÄ¶ñÒâ»î¶¯
UptycsÔÚ5ÔÂ5ÈÕÐû²¼³ÂËߣ¬³ÆÆä·¢ÏÖ½üÆÚÕë¶ÔDocker API¶Ë¿Ú2375µÄ¶ñÒâ»î¶¯¡£ÕâЩ¹¥»÷Óë¼ÓÃÜ¿ó¹¤Óйأ¬²¢ÔÚÄ¿±ê·þÎñÆ÷ÉÏʹÓÃcmdlineÖеÄbase64±àÂëÃüÁî½øÐз´Ïòshell£¬Ö¼ÔÚÈƹý·ÀÓù»úÖÆ¡£Ñо¿ÈËÔ±×ܹ²·¢ÏÖÁË3ÖÖÀàÐ͵Ĺ¥»÷£¬·Ö±ðΪ¿ó¹¤¹¥»÷¡¢·´Ïòshell¹¥»÷ºÍKinsing¶ñÒâÈí¼þ¹¥»÷¡£³ÂËßÖ¸³ö£¬Ã»ÓнÓÄÉÊʵ±±£»¤´ëÊ©µÄDockerÒ×±»¹¥»÷ÕßÀûÓá£
https://www.uptycs.com/blog/vulnerable-docker-installations-are-a-playhouse-for-malware-attacks?hs_preview=roycVWho-72459548548
4¡¢OpenSeaµÄDiscord·þÎñÆ÷±»ºÚ²¢±»ÓÃÀ´Ðû²¼Ðé¼Ùͨ¸æ
ýÌå5ÔÂ7Èճƣ¬OpenSeaµÄDiscord·þÎñÆ÷±»ºÚ²¢±»ÓÃÀ´Ðû²¼Ðé¼Ùͨ¸æ¡£OpenSeaÊÇÒ»¸öNFTÂòÂôÊг¡£¬ËüÔÚ5ÔÂ6ÈÕÐû²¼ÁËÒ»ÕŽØͼ£¬ÊǹØÓÚºÏ×÷»ï°é¹ØϵµÄÐé¼Ùͨ¸æ£¬ÆäÖл¹°üÂÞÖ¸ÏòµöÓãÍøÕ¾µÄÁ´½Ó¡£OpenSea³Æ£¬ÆäDiscord·þÎñÆ÷ÓÚÉÏÖÜÎåÔçÉÏÔâµ½¹¥»÷£¬ËûÃǽ¨ÒéÓû§²»Òª¹ØעƵµÀÉÏÐû²¼µÄÈκÎÁ´½Ó¡£¾ÝϤ£¬¹¥»÷ÕßÀûÓÃÁËWebhook·ÃÎÊ·þÎñÆ÷¿Ø¼þÀ´ÈëÇÖÆäÍøÂ磬²¢½øÐеöÓã¹¥»÷¡£µ½Ä¿Ç°ÎªÖ¹£¬ÒÑÓÐ13¸öÇ®°ü±»µÁ¡£
https://insidebitcoins.com/news/opensea-discord-server-hacked-increasing-the-risk-of-phishing-scams
5¡¢Î¢ÈíÐû²¼AzureÖÐRCE©¶´CVE-2022-29972µÄ²¹¶¡
5ÔÂ9ÈÕ£¬Î¢ÈíÐû²¼ÁËAzureÖеÄRCE©¶´£¨CVE-2022-29972£©µÄ²¹¶¡¡£¸Ã©¶´Ò²±»³ÆΪSynLapse£¬Ó°ÏìÁËAzure SynapseºÍAzure Data Factory¹ÜµÀ£¬ÒÑÓÚ4ÔÂ15Èյõ½»º½â£¬ÔÚ²¹¶¡Ðû²¼Ö®Ç°²¢Î´±»ÀûÓá£Orca Security³Æ£¬¹¥»÷Õß¿ÉÒÔÀûÓôË©¶´·ÃÎʺͿØÖÆÆäËû¿Í»§µÄSynapseÊÂÇéÇø£¬ÒÔÇÔÈ¡Ãô¸ÐÊý¾Ý£¨°üÂÞAzureµÄ·þÎñÃÜÔ¿¡¢APIÁîÅƺÍÃÜÂëµÈ£©¡£Î¢ÈíÔö²¹µÀ£¬¸Ã©¶´¿É±»ÓÃÓÚ¿çIR»ù´¡ÉèÊ©Ö´ÐÐÔ¶³ÌÃüÁîÖ´ÐС£
https://www.bleepingcomputer.com/news/security/microsoft-releases-fixes-for-azure-flaw-allowing-rce-attacks/
6¡¢Ñо¿ÍŶÓÐû²¼ÐÅÓÿ¨ÇÔÈ¡¶ñÒâÈí¼þCaramelµÄ·ÖÎö³ÂËß
5ÔÂ5ÈÕ£¬Domain ToolsÐû²¼Á˹ØÓÚÐÅÓÿ¨ÇÔÈ¡¶ñÒâÈí¼þCaramelµÄ·ÖÎö³ÂËß¡£CaramelÊÇÒ»ÖÖskimmer-as-a-service£¬ÓɶíÂÞ˹ÍÅ»ïCaramelCorpÔËÓª¡£¸Ã·þÎñµÄÖÕÉí¶©ÔÄÓöÈΪ2000ÃÀÔª£¬½öÃæÏò½²¶íÓïµÄ¹ºÖÃÕß¡£¹¦Ð§´óÖ°üÂÞ²¿Êð¡¢ÊÕ¼¯¡¢¹ÜÀíºÍÈƹý¼ì²â£¬¾Ý³ÆËü¿ÉÒÔÈƹýCloudflare¡¢AkamaiºÍIncapsulaµÈ¹«Ë¾µÄ±£»¤·þÎñ¡£Ñо¿ÈËÔ±»¹·¢ÏÖÁ˸÷þÎñµÄ¹ÜÀíÃæ°å´æÔÚ¼¸¸öÓëÉí·ÝÑéÖ¤Ïà¹ØµÄ¼¼Êõ´íÎó¡£
https://www.domaintools.com/resources/blog/a-sticky-situation-part-1-the-pervasive-nature-of-credit-card-skimmers