CloudSEK͸¶Áè¼Ý1500¸öÒÆ¶¯Ó¦ÓÃй¶Algolia APIÃÜÔ¿

Ðû²¼Ê±¼ä 2022-11-23
1¡¢CloudSEK͸¶Áè¼Ý1500¸öÒÆ¶¯Ó¦ÓÃй¶Algolia APIÃÜÔ¿

¾ÝýÌå11ÔÂ21ÈÕ±¨µÀ £¬CloudSEKµÄÑо¿ÈËÔ±·¢ÏÖ1550¸öÒÆ¶¯Ó¦ÓÃй¶ÁËAlgolia APIÃÜÔ¿ºÍÓ¦Ó÷¨Ê½ ID £¬´æÔÚδ¾­ÊÚȨ·ÃÎÊÄÚ²¿ÐÅÏ¢µÄ·çÏÕ¡£ÔÚÕâЩӦÓÃÖÐ £¬ÓÐ32¸öй¶Á˹ÜÀí»úÃÜ £¬°üÂÞ57¸öΨһµÄ¹ÜÀíÃÜÔ¿ £¬¹¥»÷Õß¿ÉÒÔÓÃÀ´·ÃÎÊÓû§ÐÅÏ¢»òÐÞ¸ÄÓ¦ÓÃË÷Òý¼Ç¼ºÍÉèÖà £¬¿ÉÄÜ»áÔì³ÉÉÌÒµËðʧ¡£¹ûÈ»Algolia Admin APIÃÜÔ¿µÄÓ¦ÓÃԼĪÓÐ3250000¸ö £¬×îÈÝÒ×̻¶ÃÜÔ¿µÄÊǹºÎïÓ¦Óà £¬×ܹ²±»ÏÂÔØÁË230Íò´Î £¬ÆäËüÀà±ðÓ¦ÓÃ×ÜÏÂÔØÁ¿Áè¼Ý950000´Î¡£

https://www.bleepingcomputer.com/news/security/apps-with-over-3-million-installs-leak-admin-search-api-keys/

2¡¢»¨À­¹«Ô°Ò½ÔºÒòй¶»¼ÕßµÄÒ½ÁÆÐÅÏ¢±»·£¿î58000ÐÂÔª

¾ÝýÌå11ÔÂ21ÈÕ³Æ £¬»¨À­¹«Ô°Ò½ÔºÒòй¶½ü2000È˵ÄÒ½ÁÆÐÅÏ¢±»·£¿î58000ÐÂÔª¡£Ð¹Â©Ê¼þ·¢ÉúÔÚ2018Äê3ÔÂ8ÈÕµ½2019Äê10ÔÂ25ÈÕ £¬Ò½ÔºÔÚ2019Äê10ÔÂÊÕµ½Í¶Ëߺó £¬ÓÚ2020Äê7ÔÂÏòͨ±¨ÁËÕâһʼþ¡£¾ÝϤ £¬¹²ÓÐ9271·âÓʼþ´ÓÁ½ÃûÒ½ÔºÔ±¹¤µÄOffice 365ÊÂÇéÓʼþÕÊ»§ÖÐ×Ô¶¯×ª·¢µ½µÚÈý·½µç×ÓÓʼþµØÖ· £¬Ð¹Â¶ÐÅÏ¢Éæ¼°»¼ÕßÐÕÃû¡¢ÐÔ±ð¡¢Éí·ÝÖ¤ºÅÂë¡¢»¤ÕÕÏêϸÐÅÏ¢¡¢ÁªÏµµç»°ºÍÒ½ÁÆÐÅÏ¢µÈ¡£

https://www.databreaches.net/farrer-park-hospital-fined-s58000-over-data-breach-affecting-medical-information-of-2000-people/

3¡¢Ñо¿ÍŶӷ¢ÏÖÕë¶ÔCoinbaseµÈ×éÖ¯µÄ´ó¹æÄ£µöÓã»î¶¯

ýÌå11ÔÂ21ÈÕ³Æ £¬PIXM·¢ÏÖÁËÒ»ÆðÕýÔÚ½øÐеĵöÓã»î¶¯ £¬Ö¼ÔÚÈÆ¹ý¶àÒòËØÉí·ÝÑéÖ¤²¢ÇÔÈ¡¼ÓÃÜ»õ±Ò¡£´Ë´Î»î¶¯Ö÷ÒªÕë¶ÔCoinbase¡¢MetaMask¡¢Crypto.comºÍKuCoin £¬¹¥»÷ÕßÀûÓÃMicrosoft Azure Web Apps·þÎñÀ´ÍйܵöÓãÍøÕ¾ £¬²¢Í¨¹ýÄ£ÄâÐé¼Ù½»Ò×È·ÈÏÇëÇó»ò¿ÉÒɻ¼ì²âµÄµöÓãÏûÏ¢À´ÓÕʹĿ±ê½øÈëÍøÕ¾¡£Ö®ºó £¬»áÀûÓÃαÔìµÄµÇ¼±íµ¥ÇÔȡĿ±êµÄ2FA´úÂë¡£ÎÞÂÛ2FA´úÂëÊÇ·ñÓÐЧ £¬¶¼Êд¥·¢ÏÂÒ»¸ö¹¥»÷½×¶Î £¬¼´Æô¶¯Ö§³ÖÁÄÌì £¬¶øÇÒ¹¥»÷Õß»áÖ±½ÓÔÚÁÄÌìÖÐÌáʾÓû§ÊäÈëÓû§Ãû¡¢ÃÜÂëºÍ2FA´úÂë¡£

https://pixmsecurity.com/blog/phish/cybercrime-group-expands-cryptocurrency-phishing-operation/

4¡¢ViperSoftX¿É°²×°ÇÔÈ¡ÐÅÏ¢µÄChromeÀ©Õ¹VenomSoftX

AvastÓÚ11ÔÂ21ÈÕÅû¶¶ñÒâÈí¼þViperSoftXÕýÔÚ·Ö·¢ÃûΪVenomSoftXµÄÇÔÈ¡ÐÅÏ¢µÄChromeÀ©Õ¹VenomSoftX¡£ViperSoftX×Ô2020ÄêÒÔÀ´Ò»Ö±´æÔÚ £¬×Ô2022Äê³õÒÔÀ´ £¬AvastÒѼì²âµ½93000´ÎViperSoftX¹¥»÷ʵÑé £¬Ö÷ÒªÓ°ÏìÃÀ¹ú¡¢Òâ´óÀû¡¢°ÍÎ÷ºÍÓ¡¶È¡£VenomSoftXαװ³ÉÖÖÖÖÁ÷ÐеÄä¯ÀÀÆ÷À©Õ¹·¨Ê½ £¬Ö÷ҪĿµÄÊÇÇÔÈ¡¼ÓÃÜ»õ±Ò¡£¶ñÒâÀ©Õ¹¿ÉÌṩ¶ÔÄ¿±ê·ÃÎʵÄÿ¸öÒ³ÃæµÄÍêÈ«·ÃÎÊȨÏÞ¡¢Ö´ÐÐä¯ÀÀÆ÷ÖмäÈ˹¥»÷ºÍÖ´ÐмÓÃÜ»õ±ÒµØÖ·½»»»µÈ¡£

https://decoded.avast.io/janrubin/vipersoftx-hiding-in-system-logs-and-spreading-venomsoftx/

5¡¢Ó¡¶È¿²Å¬¶û´óѧµÄ¹Ù·½ÍøÕ¾Ð¹Â¶3Íò¶àѧÉúµÄÐÅÏ¢

11ÔÂ21ÈÕ±¨µÀ³Æ £¬¿ÆÇÕµÄÒ»¼ÒÄþ¾²»ú¹¹·¢ÏÖ £¬Ó¡¶È¿²Å¬¶û´óѧ2018ÄêÖÁ2022Äê×¢²áµÄ3Íò¶àÃûѧÉúµÄÐÅÏ¢±»Ðû²¼ÔÚÒ»¸öºÚ¿ÍÂÛ̳ÉÏ¡£Æ¾¾Ý¿ª¶ËÍÆ²â £¬´Ë´Îй¶Ê¼þÊÇÓÉÓÚ´óѧ¹Ù·½ÍøÕ¾µÄ¼¼Êõ¹ÊÕϵ¼ÖµÄ¡£Ð¹Â¶Êý¾ÝÉæ¼°Ñ§ÉúµÄÐÕÃû¡¢AadhaarºÅÂë¡¢ÕÕÆ¬ºÍµç»°ºÅÂëµÈ¡£Ä¿Ç° £¬¿²Å¬¶û´óѧÒѾʹËʽÓÄÉÐж¯ £¬²¢¾ö¶¨´ÓÆäÊý¾Ý¿âÖÐɾ³ý2018ÄêÖÁ2022ÄêµÄËùÓÐÊý¾Ý¡£

https://english.mathrubhumi.com/news/kerala/personal-information-of-over-30-000-kannur-university-students-leaked-1.8066818

6¡¢SEKOIAÐû²¼¹ØÓÚÐÂÐͶñÒâÈí¼þAuroraµÄ¼¼Êõ·ÖÎö³ÂËß

11ÔÂ21ÈÕ £¬SEKOIAÐû²¼ÁË»ùÓÚGoµÄÐÂÐͶñÒâÈí¼þAuroraµÄ¼¼Êõ·ÖÎö³ÂËß¡£AuroraÓÚ2022Äê4ÔÂÊ×´ÎÔÚ°µÍøÉÏÐû²¼ £¬±»Ðû´«Îª¾ßÓÐÐÅÏ¢ÇÔÈ¡ºÍÔ¶³Ì·ÃÎʹ¦Ð§µÄ½©Ê¬ÍøÂç¡£¶øÔÚ8ÔÂÏÂÑ® £¬Aurora±»Ðû´«ÎªÇÔÈ¡¹¤¾ß¶ø²»Êǽ©Ê¬ÍøÂç¡£Auroraͨ¹ýWMICÔËÐжà¸öÃüÁîÒÔÊÕ¼¯»ù±¾Ö÷»úÐÅÏ¢¡¢ÅÄÉã×ÀÃæÍ¼Ïñ²¢½«ËùÓÐÄÚÈÝ·¢Ë͵½C2 £¬ÆäÖ÷ÒªÇÔÈ¡ä¯ÀÀÆ÷¡¢¼ÓÃÜ»õ±ÒÀ©Õ¹¡¢¼ÓÃÜ»õ±ÒÇ®°ü×ÀÃæÓ¦ÓúÍTelegramÖеÄÊý¾Ý¡£

https://blog.sekoia.io/aurora-a-rising-stealer-flying-under-the-radar/