ÂíÀ´Î÷ÑǵçÐŹ«Ë¾RedOneÔâµ½DESORDENÍÅ»ïµÄ¹¥»÷
Ðû²¼Ê±¼ä 2022-09-29
¾ÝýÌå9ÔÂ27ÈÕ±¨µÀ£¬ÂíÀ´Î÷ÑǵçÐŹ«Ë¾RedOneÔâµ½ÁËDESORDENµÄ¹¥»÷¡£9ÔÂ19ÈÕ£¬DESORDENÉù³ÆÒѾÈëÇָõçÐŹ«Ë¾¡£ÔÚredONEûÓлØÓ¦DESORDENµÄÒªÇóºó£¬DESORDENÓÚ9ÔÂ21ÈÕ×óÓÒÓÖ½øÐÐÁ˵ڶþ´Î¹¥»÷£¬ÈëÇÖÁËËûÃǵÄredCARDºÍredCARE·¨Ê½¡£Ð¹Â¶µÄÐÅÏ¢Éæ¼°redONEÊý¾Ý¿âºÍÔ´´úÂ룬°üÂÞ¿Í»§ÐÕÃû¡¢NRIC£¨¹úÃñÉí·ÝÖ¤ºÅÂ룩¡¢µØÖ·¡¢µç»°ºÍµç×ÓÓʼþµÈ¡£Ä¿Ç°£¬redONEÉÐδ¶Ô´ËÊÂ×÷³ö»ØÓ¦¡£
https://www.databreaches.net/malaysian-telecom-redone-hit-by-desorden/
2¡¢Okta×Ó¹«Ë¾Auth0͸¶Æä²¿ÃÅÔ´´úÂë´æ´¢¿âÒѾй¶
ýÌå9ÔÂ28Èճƣ¬Okta×Ó¹«Ë¾Éí·ÝÑéÖ¤·þÎñÌṩÉÌAuth0³ÆÆä²¿ÃÅÔ´´úÂë´æ´¢¿âÒѾй¶¡£Auth0µÄÈÏ֤ƽ̨ÿÌìÓÃÓÚÈÏÖ¤30¸ö¹ú¼ÒµÄ2000¶à¼ÒÆóÒµ¿Í»§µÄ4200¶àÍò´ÎµÇ¼£¬ÆäÖаüÂÞAMD¡¢Î÷ÃÅ×Ó¡¢»ÔÈð¡¢Âí×Ô´ïºÍ˹°Í³µÈ¹«Ë¾¡£8Ôµף¬Ä³µÚÈý·½Í¨ÖªOkta£¬ËûÃÇÓµÓÐ2020Äê10Ô¼°¸üÔçµÄAuth0´úÂë¿âµÄ¸±±¾¡£Ö®ºó£¬¸Ã¹«Ë¾Á¢¼´ÊÓ²ìÊý¾ÝÊÇÈçºÎ±»Ð¹Â¶µÄ£¬µ«Ö±µ½ÏÖÔÚ£¬»¹Ã»ÓÐÕÒµ½ÈκÎÎ¥¹æµÄÖ¤¾Ý¡£Auth0»¹ÌåÏÖ£¬´Ëʼþδ¶Ô¿Í»§Ôì³ÉÓ°Ï죬Òò´ËËûÃÇÎÞÐè½ÓÄÉÈκÎÐж¯¡£
https://www.bleepingcomputer.com/news/security/auth0-warns-that-some-source-code-repos-may-have-been-stolen/
3¡¢LazarusÒÔCrypto.comÊÂÇé»ú»áΪÓÕ¶ü·Ö·¢¶ñÒâÈí¼þ
SentinelOneÔÚ9ÔÂ26ÈÕÅû¶Á˳¯ÏÊLazarusÍÅ»ïÐÂÒ»ÂֵĹ¥»÷»î¶¯¡£ÓëÍù³£Ò»Ñù£¬¹¥»÷Õßͨ³£ÀûÓÃLinkedIn½Ó½üÄ¿±ê£¬·¢ËÍÒ»¸öαװ³ÉPDFµÄmacOS¶þ½øÖÆÎļþ£¬ÆäÖаüÂÞCrypto.comµÄÕÐÆ¸Ö°Î»¡£ÔÚºǫ́£¬Mach-O¶þ½øÖÆÎļþ»áÔÚÓû§µÄ¿âĿ¼Öд´½¨Ò»¸öÎļþ¼Ð²¢·Ö·¢µÚ¶þ½×¶ÎºÍµÚÈý½×¶ÎµÄÎļþ¡£ÓÉÓÚC2ÔÚÊÓ²ìʱһֱ´¦ÓÚÀëÏß״̬£¬Ñо¿ÈËÔ±ÎÞ·¨¼ìË÷×îÖÕpayload²¢½øÐзÖÎö¡£
https://www.sentinelone.com/blog/lazarus-operation-interception-targets-macos-users-dreaming-of-jobs-in-crypto/
4¡¢Unit 42ÊӲ쵽ÀûÓöàÓïÑÔCHMÎļþÎļþÁ÷´«IcedIDµÄ»î¶¯
9ÔÂ27ÈÕ£¬Unit 42³ÆÆäÔÚ½üÆÚÊӲ쵽һ¸ö¶àÓïÑÔMicrosoft±àÒëHTML×ÊÖú(CHM)Îļþ±»ÓÃÓÚ·Ö·¢ÇÔÈ¡ÐÅÏ¢µÄ¶ñÒâÈí¼þIcedID¡£Ñо¿ÈËÔ±ÔÚ2022Äê8ÔÂÉÏÑ®·¢ÏÖÁËÕâ¸öÌØÊâµÄ¹¥»÷Á´£¬¸Ã¼¼Êõ¿ÉÒÔÖÆÖ¹Ê¹Óó¤ÐдúÂ룬Õâʹ¶ñÒâÎļþ¸üÈÝÒ×ÈÆ¹ýÄþ¾²²úÎïµÄ¼ì²â¡£¹¥»÷Õß¿ÉÒÔÀûÓöàÓïÑÔÎļþÀ´ÈƹýÒÀÀµÎļþ¸ñʽʶ´ËÍâ·´¶ñÒâÈí¼þϵͳ¡£´ËÍ⣬¸Ã¼¼ÊõÔÚѬȾ¹ý³ÌÖлá¶Ôͬһ¸öCHMÎļþÖ´ÐÐÁ½´Î£¬µÚÒ»´ÎÖ´Ðп´ÆðÀ´ÊǺϷ¨»î¶¯£¬¶øµÚ¶þ´ÎÖ´ÐÐÔòÒþ±ÎµØ½øÐжñÒâ»î¶¯¡£
https://unit42.paloaltonetworks.com/polyglot-file-icedid-payload/
5¡¢ProofpointÅû¶ÀûÓÃMicrosoft SwayµÄµöÓã»î¶¯µÄϸ½Ú
9ÔÂ26ÈÕ£¬ProofpointÅû¶Á˽üÆÚÀûÓÃMicrosoft Sway¿ªÕ¹µÄµöÓã»î¶¯¡£SwayÊÇMicrosoft 365Ì×¼þÖв»Ì«³£Óõķ¨Ê½Ö®Ò»£¬±»ÓÃÓÚ½«Îı¾ºÍýÌå½áºÏÆðÀ´´´½¨Ò»¸öÃÀ¹ÛµÄÍøÕ¾¡£Microsoft½öÔÊÐíÔÚSwayÒ³ÃæÖÐÉÏ´«Ã½ÌåÎļþ£¬²¢»áÖ÷¶¯×èÖ¹ÉÏ´«¿ÉÖ´ÐÐÎļþ¡£µ«ÊÇ£¬¹¥»÷ÕßÈÔÈ»¿ÉÒÔͨ¹ý½«ÍйܶñÒâÈí¼þǶÈëSwayÖÐÀ´Ê¹ÓÃSway·Ö·¢¶ñÒâ¿ÉÖ´ÐÐÎļþ¡£ÎªÁ˽µµÍ·çÏÕ£¬Proofpoint½¨ÒéÓû§ÔÚÐëҪʱÏÞÖÆSwayÔÚÔÆ»·¾³ÖеÄʹÓá£
https://www.proofpoint.com/us/blog/cloud-security/proofpoint-analyzes-potentially-dangerous-functionality-microsoft-sway-enables
6¡¢NETSCOUTÐû²¼2022Äê1H DDoS¹¥»÷Ì¬ÊÆµÄ·ÖÎö³ÂËß
¾Ý9ÔÂ27ÈÕ±¨µÀ£¬NETSCOUTÐû²¼ÁË2022Äê1H DDoS¹¥»÷Ì¬ÊÆµÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬2022Äê1HµÄ¹¥»÷×ÜÊýΪ6019888£¬±È2021Äê2H¼õÉÙÁË2%£»×î´ó´ø¿íΪ957.9 Gbps£¬±È2021Äê2HÔö³¤ÁË57%£»×î´óÍÌÍÂÁ¿Îª284.4 Mpps£¬½Ï2021Äê2H¼õÉÙÁË37%¡£´ËÍ⣬¹¥»÷ÕßÔÚ²»Í£´´ÐºÍ̽Ë÷еġ¢¸üÇ¿´óµÄDDoS¹¥»÷ý½é£»½©Ê¬ÍøÂçÈÔÔÚ¼ÌÐøÒÔ¾ªÈ˵ÄËÙ¶ÈÀ©É¢£»¾ßÓÐÕ½Õù¡¢×ڽ̺ÍÕþÖÎÒòËØµÄDDoS¹¥»÷»î¶¯Ôö¶à¡£
https://www.netscout.com/threatreport