T-MobileÒòÈ¥ÄêÊý¾Ýй¶Ê¼þÅâ³¥ÆäÓû§3.5ÒÚÃÀÔª

Ðû²¼Ê±¼ä 2022-07-26

1¡¢T-MobileÒòÈ¥ÄêÊý¾Ýй¶Ê¼þÅâ³¥ÆäÓû§3.5ÒÚÃÀÔª

      

¾Ý7ÔÂ24ÈÕ±¨µÀ £¬T-MobileÒÑͬÒâÏò½ü7700ÍòÓû§Å⸶3.5ÒÚÃÀÔª £¬ÒÔ½â¾ö¹ØÓڸù«Ë¾2021ÄêÊý¾Ýй¶Ê¼þµÄ¼¯ÌåËßËÏ ¡£È¥Äê8Ô·Ý £¬¸Ã¹«Ë¾µÄϵͳÔâµ½ºÚ¿ÍÈëÇÖ £¬Óû§µÄÉç»áÄþ¾²ºÅÂë¡¢ÐÕÃû¡¢µØÖ·ºÍ¼ÝʻִÕÕµÈÐÅϢй¶ ¡£Æ¾¾ÝÉÏÖÜÎåµÄÎļþ £¬3.5×ʽð½«ÓÃÓÚÖ§¸¶ÊÜÓ°ÏìÓû§µÄË÷Åâ¡¢Ô­¸æÂÉʦµÄÖ´·¨ÓöÈÒÔ¼°¹ÜÀíºÍ½âµÄÓÃ¶È ¡£T-Mobile»¹ÌåÏÖ½«ÔÚ2022ÄêºÍ2023Ä껨·Ñ1.5ÒÚÃÀÔªÀ´¼ÓÇ¿ÆäÊý¾ÝÄþ¾²ºÍÆäËü¼¼Êõ ¡£


https://www.securityweek.com/t-mobile-settles-pay-350m-customers-data-breach


2¡¢ÀÕË÷ÍÅ»ïLockBitÉù³ÆÒÑÇÔÈ¡Òâ´óÀû˰Îñ»ú¹¹78 GBÊý¾Ý

      

ýÌå7ÔÂ25ÈÕ±¨µÀ £¬Òâ´óÀûÕýÔÚÊÓ²ìÆä˰Îñ»ú¹ØÔâµ½ÀÕË÷¹¥»÷µÄʼþ ¡£ÉÏÖÜÄ© £¬LockBit½«¸Ã»ú¹¹Ìí¼Óµ½ÆäÊý¾ÝÐ¹Â¶ÍøÕ¾ £¬Éù³ÆÒÑÇÔÈ¡78 GBÊý¾Ý £¬²¢¸øÁ˸ûú¹¹Ô¼Äª6ÌìµÄʱ¼ä×ö³ö»ØÓ¦ ¡£Ö®ºó £¬¸ÃÍŻォ½ØÖ¹ÈÕÆÚÑÓ³¤ÖÁ8ÔÂ1ÈÕ £¬²¢Éù³ÆÆäÒÑ»ñµÃ100 GBÊý¾Ý ¡£L'Agenzia delle EntrateÔÚÖÜÒ»·¢±íÉùÃ÷³Æ £¬ËüÒªÇ󾭼úͲÆÕþ²¿µÄIT¹«Ë¾SogeiÊÓ²ìÕâÆðËùνµÄÀÕË÷¹¥»÷ʼþ ¡£ 

 

https://therecord.media/italy-investigating-ransomware-attack-on-tax-agency/


3¡¢Î¢Èí³Æ7Ô·ÝWindows¸üпÉÄܵ¼Ö´òÓ¡¹¦Ð§·ºÆðÎÊÌâ


7ÔÂ22ÈÕ±¨µÀ £¬Î¢ÈíÌåÏÖ´Ó±¾ÖܵĿÉѡԤÀÀ¸üпªÊ¼ £¬Ò»ÄêǰΪ½â¾öWindows ServerÔÚ²»¼æÈÝÉ豸ÉÏ´òÓ¡ÎÊÌâ¶øÌṩµÄÁÙʱ»º½â´ëÊ©½«±»ÒƳý £¬Õâ¿ÉÄܻᵼÖ´òÓ¡¹¦Ð§·ºÆðÎÊÌâ ¡£Î¢Èí½âÊͳÆ £¬ÊÜÓ°ÏìµÄÉ豸°üÂÞÖÇÄÜ¿¨Éí·ÝÑéÖ¤´òÓ¡»ú¡¢É¨ÃèÒǺͶ๦ЧÉ豸 £¬ËüÃÇÔÚPKINIT KerberosÈÏÖ¤ÆÚ¼ä²»Ö§³ÖDHÃÜÔ¿½»»» £¬»òÕßÔÚKerberos ASÇëÇóÆÚ¼ä²»Ö§³ÖÈýÖØDES ¡£Óû§ÐèÒª¸üкϹæ»ò¸ü»»²»ºÏ¹æµÄÉ豸 ¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-that-new-windows-updates-may-break-printing/


4¡¢ÎÚ¿ËÀ¼¹ã²¥¹«Ë¾TAVR Media±»¹¥»÷²¢Á÷´«Ðé¼ÙÐÅÏ¢

      

ýÌå7ÔÂ22ÈÕ³Æ £¬ÎÚ¿ËÀ¼¹ã²¥¹«Ë¾TAVR MediaÔâµ½¹¥»÷ £¬²¢Á÷´«×ÜͳVolodymyr Zelenskyy²¡ÖصÄÐé¼ÙÐÅÏ¢ ¡£Õâ¼Ò¹«Ë¾ÔËÓª×ÅÎÚ¿ËÀ¼µÄ9¸öÖ÷ÒªµÄ¹ã²¥µç̨ £¬°üÂÞHit FM¡¢Radio ROKS¡¢KISS FMºÍRadio RELAXµÈ ¡£ÎÚ¿ËÀ¼¹ú¼ÒÌØÊâͨÐźÍÐÅÏ¢±£»¤¾Ö£¨SSCIP£©³Æ £¬¹¥»÷ÕßÆÆ»µÁËTAVR MediaµÄ·þÎñÆ÷ºÍ¹ã²¥ÏµÍ³À´Ðû²¼Ðé¼ÙÏûÏ¢ £¬ËûÃÇÕýÔÚŬÁ¦½â¾ö¸ÃÎÊÌâ ¡£Ä¿Ç° £¬¹¥»÷µÄÀ´Ô´Éв»Çå³þ ¡£


https://thehackernews.com/2022/07/ukrainian-radio-stations-hacked-to.html


5¡¢TA4563ÀûÓúóÃÅEvilNum¹¥»÷Å·Ö޵ĽðÈÚºÍͶ×ÊÐÐÒµ

      

ProofpointÔÚ7ÔÂ21ÈÕÅû¶ÁËTA4563ÀûÓù¥»÷Å·Ö޵ĽðÈÚºÍͶ×ÊÐÐÒµµÄ»î¶¯µÄÏêÇé ¡£´Ë´Î»î¶¯Ê¼ÓÚ2021Äêµ× £¬ÀûÓÃÁ˶ñÒâÈí¼þEvilNum £¬Ö÷ÒªÕë¶ÔÖ§³ÖÍâ»ã¡¢¼ÓÃÜ»õ±ÒºÍÈ¥ÖÐÐÄ»¯½ðÈÚ(DeFi)ÒµÎñµÄʵÌå ¡£EvilNumÊÇÒ»¸öºóÃÅ £¬¿ÉÇÔÈ¡Êý¾Ý»ò¼ÓÔØÌØ±ðµÄpayload ¡£¸Ã¶ñÒâÈí¼þ°üÂÞ¶à¸öÓÐȤµÄ×é¼þ £¬¿ÉÓÃÓÚÈÆ¹ý¼ì²â²¢Æ¾¾ÝÒÑʶ´ËÍâɱ¶¾Èí¼þÐÞ¸ÄѬȾ·¾¶ ¡£¸Ã»î¶¯ÓëZscalerÔÚ2022Äê6Ô¹ûÈ»µÄEvilNum»î¶¯Óв¿ÃÅÖØµþ ¡£


https://www.proofpoint.com/us/blog/threat-insight/buy-sell-steal-evilnum-targets-cryptocurrency-forex-commodities


6¡¢ASEC·¢ÏÖͨ¹ýISOÎļþ·Ö·¢¶ñÒâÈí¼þIcedIDµÄ»î¶¯

      

7ÔÂ25ÈÕ £¬ASECÐû²¼Á˹ØÓÚͨ¹ýISOÎļþ·Ö·¢IcedIDµÄ»î¶¯µÄ·ÖÎö³ÂËß ¡£³ÂËß½éÉÜÁËÁ½ÖÖ·Ö·¢·½Ê½ £¬µÚÒ»ÖÖÊÇÀûÓõç×ÓÓʼþ½Ù³Ö¼¼ÊõÀ´½Ù³ÖÕý³£Óʲ¢ÏòÓû§·¢ËÍ´øÓжñÒ⸽¼þµÄ»Ø¸´ £¬¸ÃÎļþ±»Ñ¹Ëõ £¬ÆäÖаüÂÞÒ»¸öISOÎļþ ¡£ÔËÐÐISOÎļþ»áÔÚDVDÇý¶¯Æ÷Öд´½¨Ò»¸ölnkºÍÒ»¸öDLLÎļþ £¬²¢Í¨¹ýlnkÎļþ¼ÓÔØDLL £¬¼ÓÔØµÄDLL¾ÍÊÇIcedID ¡£µÚ¶þÖÖISOÎļþÖгýÁËlnkºÍDLLÖ®Í⻹ÓÐÆäËüÎļþ £¬lnkÎļþÔËÐÐÎļþ¼ÐthemÄÚµÄworker.cmd £¬Ö®ºóÔËÐÐworker.js ¡£worker.jsͨ¹ýrundll32.exe½«then.dat¼ÓÔØµ½Í¬Ò»Îļþ¼ÐÖÐ £¬then.datÊÇÒ»¸öDLL£¨IcedID£© ¡£


https://asec.ahnlab.com/en/37005/