¼ÓÃÜ»õ±Ò½»Ò×ËùFTXÉêÇëÆƲúÔ¤¼ÆËðʧ¸ß´ï6ÒÚÃÀÔª
Ðû²¼Ê±¼ä 2022-11-15¾ÝýÌå11ÔÂ13ÈÕ±¨µÀ£¬¼ÓÃÜ»õ±Ò½»Ò×ËùFTXÔâµ½¹¥»÷£¬Óд«ÑԳƹ¥»÷ÕßÒÑÇÔÈ¡6ÒÚÃÀÔª¡£¹«Ë¾Ö´·¨ÕÕÁÏRyne Miller֤ʵÁ˴˴ι¥»÷ʼþ£¬²¢ÌåÏÖFTX USºÍFTX[dot]comÒѽ«ËùÓÐ×ʲúתÒƵ½ÀäÇ®°üÖУ¬²¢ÊÓ²ìÁË¿ÉÒɵĽ»Òס£ÔÚ´óÁ¿¿Í»§Ìá¿îºó£¬¸Ã¼ÓÃÜ»õ±Ò½»Ò×ËùÓÚÉÏÖÜÎåÉêÇëÆƲú¡£¾Ý·͸Éç͸¶£¬ÖÁÉÙÓÐ10ÒÚÃÀÔªµÄ×ʽð´ÓÕâ¼Òµ¹±ÕµÄ¼ÓÃÜ»õ±Ò½»Ò×ËùÁ÷³ö¡£
https://securityaffairs.co/wordpress/138449/digital-id/ftx-alleged-hack.html
2¡¢ºÚ¿ÍÔÚ°µÍø³öÊÛ¶íÂÞ˹Whoosh 720Íò¿Í»§µÄÏêϸÐÅÏ¢
ýÌå11ÔÂ14Èճƣ¬¶íÂÞ˹³öÐзþÎñƽ̨Whoosh 720Íò¿Í»§µÄÐÅÏ¢ÒѾй¶¡£ÉÏÖÜÎ壬ºÚ¿ÍÔÚ°µÍø³öÊÛ±»µÁÊý¾Ý£¬ÆäÖаüÂÞ¿ÉÃâ·Ñ·ÃÎʸ÷þÎñµÄ´ÙÏú´úÂ룬ÒÔ¼°Óû§µÄ¸öÈ˺ÍÖ§¸¶¿¨ÐÅÏ¢¡£¸Ã¹«Ë¾ÔÚ±¾ÔÂÔçЩʱºòÈ·Èϴ˴ι¥»÷£¬Æäʱ³ÆÒÑÀÖ³É×èÖ¹Á˹¥»÷¡£Ö®ºóÓÖÓÚ11ÔÂ14ÈÕÐû²¼Ò»·ÝÐÂÉùÃ÷£¬ÈÏ¿É´æÔÚÊý¾Ýй¶ÎÊÌ⣬²¢ÒѽÓÄÉ´ëÊ©×èÖ¹Êý¾ÝµÄ·Ö·¢¡£Âô¼ÒÌåÏÖËûÃÇÖ»Ïò5¸öÂò¼Ò³öÊÛÕâЩÊý¾Ý£¬Ã¿¸ö4200ÃÀÔª£¬Ä¿Ç°»¹Ã»ÓÐÈ˹ºÖøÃÊý¾Ý¿â¡£
https://www.bleepingcomputer.com/news/security/whoosh-confirms-data-breach-after-hackers-sell-72m-user-records/
3¡¢Ó¢¹úÈü³µ³¡Silverstone CircuitÔâµ½RoyalµÄÀÕË÷¹¥»÷
¾Ý11ÔÂ10ÈÕ±¨µÀ£¬Ó¢¹ú×îÊÜ»¶ÓµÄÈü³µ³¡ÒøʯÈüµÀ£¨Silverstone Circuit£©¿ÉÄÜÔâµ½ÁËÀÕË÷ÍÅ»ïRoyalµÄ¹¥»÷¡£ÒøʯÈüµÀÊÇ×Ô1950ÄêÒÔÀ´Ó¢¹ú´ó½±ÈüµÄÖ÷³¡£¬ÓÉÓ¢¹úÈü³µÊÖ¾ãÀÖ²¿(BRDC)ÔËÓª¡£¹¥»÷ÕßÓÚ11ÔÂ8ÈÕÔÚRoyalÀÕË÷Èí¼þµÄÍøÕ¾ÁгöÁËSilverstone£¬µ«²¢Î´¾ßÌå˵Ã÷»ñÈ¡ÁËÄÄЩÀàÐ͵ÄÐÅÏ¢¡£Óë´Ëͬʱ£¬¸Ã¹«Ë¾Í¸Â¶ÆäÕýÔÚÊÓ²ì¸Ãʼþ¡£RoyalÊÇÒ»¸öÏà¶Ô½ÏеĺڿÍÍŻÆäÊê½ð´Ó25Íòµ½200ÍòÃÀÔª²»µÈ¡£
https://therecord.media/popular-uk-motor-racing-circuit-investigating-ransomware-attack/
4¡¢FRwLÍÅ»ïʹÓÃÐÂÀÕË÷Èí¼þSomnia¹¥»÷ÎÚ¿ËÀ¼µÄ¶à¸ö×éÖ¯
ÎÚ¿ËÀ¼¼ÆËã»úÓ¦¼±Ð¡×飨CERT-UA£©11ÔÂ11ÈÕÅû¶ÁËFRwL£¨ÓÖÃûZ-Team£©ÐÂÒ»ÂֵĹ¥»÷»î¶¯¡£¹¥»÷ÕßʹÓÃÁËð³äAdvanced IP ScannerÈí¼þµÄÍøÕ¾À´ÓÕʹĿ±êÏÂÔØ°²×°·¨Ê½¡£Êµ¼ÊÉÏ£¬°²×°·¨Ê½»áʹÓÃVidarÇÔÈ¡·¨Ê½Ñ¬È¾ÏµÍ³£¬²¢ÇÔÈ¡Telegram»á»°Êý¾ÝÀ´¿ØÖÆËûÃǵÄÕÊ»§¡£È»ºó£¬Ëû»áÀûÓÃÄ¿±êµÄTelegramÕÊ»§À´ÇÔÈ¡VPNÁ¬½ÓÊý¾Ý£¬Ö´ÐÐÖÖÖÖ¼àÊÓºÍÔ¶³Ì·ÃÎʻ¡£¸Ã»ú¹¹»¹Ö¸³ö£¬ÕâЩ¹¥»÷ÖÐʹÓÃÁËеÄSomniaÀÕË÷Èí¼þ¡£
https://cert.gov.ua/article/2724253
5¡¢ºÚ¿ÍÍÅ»ïWorokͨ¹ýÒþ²ØÔÚPNGͼÏñÖеĺóÃÅÇÔÈ¡Êý¾Ý
AvastÓÚ11ÔÂ10ÈÕ³ÆÆä·¢ÏÖºÚ¿ÍÍÅ»ïWorok½«¶ñÒâÈí¼þÒþ²ØÔÚ¿´ËÆÎÞº¦µÄPNGͼÏñÎļþ¡£Ñо¿ÈËÔ±ÌåÏÖ£¬¾ßÌåµÄ³õʼ¹¥»÷ý½éÈÔȻδ֪£¬µ«ËûÃÇÔÚ±»Ñ¬È¾É豸Öз¢ÏÖÁË4¸öDLL£¬ÆäÖаüÂÞCLRLoader¡£ÔÚºáÏòÔ˶¯ÖУ¬¹¥»÷Õß½«½Ù³ÖµÄDLLÎļþ·ÅÈë%SYSTEMROOT%\System32²¢Ô¶³ÌÆô¶¯ÏàÓ¦µÄ·þÎñ¡£ÖµµÃ×¢ÒâµÄÊÇ£¬¹¥»÷ÕßʹÓÃDropBox´æ´¢¿â´ÓÄ¿±êÖÐÊÕ¼¯Êý¾Ý£¬²¢ÔÚ×îºó½×¶ÎʹÓÃDropBox API½øÐÐͨÐÅ¡£
https://decoded.avast.io/martinchlumecky/png-steganography/
6¡¢KasperskyÐû²¼2022ÄêÇ°Èý¼¾¶È¼ÓÃܽٳÖ̬ÊƵķÖÎö³ÂËß
11ÔÂ10ÈÕ£¬KasperskyÐû²¼ÁË2022ÄêÇ°Èý¼¾¶È¼ÓÃܽٳÖ̬ÊƵķÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬2022ÄêQ3£¬¼¸ºõÿ6¸öÀûÓÃÖªÃû©¶´µÄ°¸ÀýÖоÍÓÐÒ»¸öÅãͬ×Å¿ó¹¤Èí¼þµÄѬȾ¡£Óë2021ÄêQ3Ïà±È£¬2022ÄêQ3¶ñÒâ¿ó¹¤Ð±äÖÖµÄÊýÁ¿Ôö³¤ÁËÈý±¶¶à£¬Áè¼ÝÁË15Íò¡£2022ÄêQ1£¬ÊܶñÒâ¿ó¹¤Èí¼þÓ°ÏìµÄÓû§ÊýÁ¿×î¶à£¨Áè¼Ý500000£©£¬¶øеĶñÒâ¿ó¹¤±äÖÖÊýÁ¿×îÉÙ¡£Ôâµ½´ËÀ๥»÷Óû§ÊýÁ¿×î¶àµÄ¹ú¼ÒÊÇ°£Èû¶í±ÈÑÇ£¬¸Ã¹ú¹Ù·½½ûֹʹÓüÓÃÜ»õ±Ò¡£Monero(XMR)ÊǶñÒâÍÚ¿óÖÐ×îÁ÷ÐеļÓÃÜ»õ±Ò¡£
https://securelist.com/cryptojacking-report-2022/107898/