T-MobileÎ¥¹æÐÐΪµ¼ÖÂGoogle Fi²¿Ãſͻ§Êý¾Ýй¶
Ðû²¼Ê±¼ä 2023-02-03
¾Ý2ÔÂ1ÈÕ±¨µÀ£¬¹È¸èµÄµÄ¹Ù·½Òƶ¯ÐéÄâÍøÂçÔËÓªÉÌ(MVNO)Google Fi͸¶£¬Ö÷ÒªÍøÂçÌṩÉ̵ÄÎ¥¹æÐÐΪµ¼ÖÂÆä²¿Ãſͻ§µÄÊý¾Ýй¶¡£ËäÈ»¹È¸èûÓÐÌáµ½ÔâÍøÂçÌṩÉÌÊÇË£¬µ«¾ÝÐÅËûÃÇÖ¸µÄÊÇT-Mobile¡£1ÔÂ19ÈÕ£¬T-Mobile͸¶ËüÔÚ2022Äê11Ô·¢ÉúÁËÊý¾Ýй¶£¬Éæ¼°Ô¼3700ÍòÓû§µÄÐÅÏ¢¡£´Ë´Îй¶µÄÐÅÏ¢°üÂÞÕÊ»§×´Ì¬¡¢µç»°ºÅÂë¡¢·þÎñ¼Æ»®ÏêϸÐÅÏ¢ºÍSMS¿¨ÐòÁкŵȣ¬ÕâЩÊý¾Ý¿É±»ÓÃÓÚÖ´ÐÐSIM¿¨½»»»¹¥»÷¡£
https://www.hackread.com/google-fi-data-breached-t-mobile-hack/
2¡¢F5ÐÞ¸´ÆäBIG-IPÖеĸñʽ×Ö·û´®Â©¶´CVE-2023-22374
2ÔÂ1ÈÕ£¬F5ÐÞ¸´ÆäBIG-IPÖпɵ¼ÖÂDoSºÍÈÎÒâ´úÂëÖ´ÐеÄ©¶´£¨CVE-2023-22374£©¡£ÕâÊÇiControl SOAPÖеĸñʽ×Ö·û´®Â©¶´£¬¿É±»¾¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÓÃÀ´µ¼ÖÂiControl SOAP CGI½ø³Ì±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£ÔÚÉ豸ģʽBIG-IPÖУ¬ÀÖ³ÉÀûÓôË©¶´¿ÉÒÔ¿çÔ½Äþ¾²½çÏÞ¡£¹©Ó¦ÉÌÖ¸³ö£¬ÒªÀûÓÃÃüÁîÖ´Ðй¥»÷£¬¹¥»÷Õß±ØÐëÊÕ¼¯ÓйØÍйÜÒ×±»¹¥»÷×é¼þµÄÄ¿±ê»·¾³µÄÐÅÏ¢¡£´ËÍ⣬ֻÓпØÖƲãÃæÊܵ½´Ë©¶´µÄÓ°Ï죬Êý¾Ý²ãÃæ²»»áÊܵ½Ó°Ïì¡£
https://securityaffairs.com/141728/security/f5-big-ip-bug.html
3¡¢HeadCrabÒÑѬȾ1200̨Redis·þÎñÆ÷Ö¼ÔÚÍÚ¾òMonero
Aqua SecurityÔÚ2ÔÂ1ÈÕÅû¶ÁËÕë¶ÔRedis·þÎñÆ÷µÄÐÂÐͶñÒâÈí¼þHeadCrab¡£×Ô2021Äê9ÔÂÒÔÀ´£¬HeadCrabÒѾѬȾÁËÖÁÉÙ1200̨·þÎñÆ÷£¬ÒÔ¹¹½¨Ò»¸öÍÚ¾òMonero¼ÓÃÜ»õ±ÒµÄ½©Ê¬ÍøÂç¡£Ñо¿ÈËÔ±³Æ£¬¹¥»÷ÕßÀûÓÃÒ»ÖÖÎÞÊðÀíºÍ´«Í³É±¶¾½â¾ö·½°¸ÎÞ·¨¼ì²âµ½µÄ¶¨ÖƶñÒâÈí¼þ£¬À´ÆÆ»µ´óÁ¿µÄRedis·þÎñÆ÷¡£Æù½ñΪֹ£¬ÔÚÂíÀ´Î÷ÑÇ¡¢Ó¡¶È¡¢µÂ¹ú¡¢Ó¢¹úºÍÃÀ¹ú¾ùÒѼǼµ½´óÁ¿µÄѬȾ£¬¹¥»÷µÄÀ´Ô´Éв»Ã÷È·¡£
https://blog.aquasec.com/headcrab-attacks-servers-worldwide-with-novel-state-of-art-redis-malware
4¡¢DDoSaaSƽ̨Passion±»ÓÃÓÚ¹¥»÷Å·ÃÀµØÓòµÄÒ½ÁÆ»ú¹¹
ýÌå2ÔÂ1Èճƣ¬ÔÚ½üÆÚÕë¶ÔÃÀ¹úºÍÅ·ÖÞµÄÒ½ÁÆ»ú¹¹µÄ¹¥»÷ÖУ¬·¢ÏÖÁËÒ»ÖÖÃûΪPassionµÄÐÂDDoS¼´·þÎñ(DDoSaaS)ƽ̨¡£PassionÓÚ1Ô³õÊ״α»ÍƳö£¬¶ÔÈÕ±¾ºÍÄϷǵÄ×éÖ¯ÍøÕ¾Ö´ÐÐÁ˶à´Î¹¥»÷¡£PassionÌṩʮÖÖ¹¥»÷ý½éµÄÑ¡ÏÔÊÐíÓû§Æ¾¾ÝÐèÒª¶¨Öƹ¥»÷£¬ÉõÖÁ×éºÏý½éÒÔÈÆ¹ýÄ¿±êµÄ»º½â´ëÊ©¡£Radware͸¶£¬ÔÚ1ÔÂ27ÈյĹ¥»÷»î¶¯ÖУ¬Passion±»ÓÃÓÚÕë¶ÔÊÇÃÀ¹ú¡¢ÆÏÌÑÑÀ¡¢Î÷°àÑÀ¡¢µÂ¹ú¡¢²¨À¼¡¢·ÒÀ¼¡¢Å²Íþ¡¢ºÉÀ¼ºÍÓ¢¹úµÄÒ½ÁÆ»ú¹¹¡£
https://www.bleepingcomputer.com/news/security/new-ddos-as-a-service-platform-used-in-recent-attacks-on-hospitals/
5¡¢Ñо¿ÈËÔ±·¢ÏÖIce BreakerÕë¶ÔÓÎÏ·¹«Ë¾µÄ¹¥»÷»î¶¯
¾ÝýÌå2ÔÂ1ÈÕ±¨µÀ£¬Security Joes·¢ÏÖÁËIce BreakerÕë¶ÔÓÎÏ·¹«Ë¾µÄ¹¥»÷»î¶¯¡£¸Ã»î¶¯ÖÁÉÙ´Ó2022Äê9Ô¿ªÊ¼£¬¹¥»÷Õßð³ä¿Í»§£¬ÒÔÕÊ»§×¢²áÎÊÌâΪ½è¿ÚÓëÓÎÏ·¹«Ë¾µÄÖ§³ÖÊðÀí½øÐжԻ°£¬È»ºó¶Ø´ÙÆä´ò¿ªDropboxÉÏÍÐ¹ÜµÄÆÁÄ»½ØÍ¼¡£µã»÷½ØÍ¼Á´½Ó»áµ¼Ö¼ìË÷LNK payload£¬»òÕß×÷Ϊ±¸·ÝÑ¡ÏîµÄVBScriptÎļþ£¬Ç°Õß±»ÅäÖÃΪÏÂÔØ²¢ÔËÐаüÂÞNode.jsÖ²È뷨ʽµÄMSI°ü£¬VBS»áÏÂÔØHoudini RAT¡£
https://thehackernews.com/2023/02/experts-warn-of-ice-breaker.html
6¡¢ResecurityÐû²¼¹ØÓÚÐÂÀÕË÷Èí¼þNevadaµÄ·ÖÎö³ÂËß
1ÔÂ30ÈÕ£¬ResecurityÐû²¼Á˹ØÓÚÐÂÀÕË÷Èí¼þNevadaµÄ·ÖÎö³ÂËß¡£NevadaÓÚ2022Äê12ÔÂ10ÈÕ¿ªÊ¼ÔÚRAMPÂÛ̳ÉÏÍÆ¹ã£¬¾ßÓлùÓÚRustµÄlocker¡¢ÊµÊ±Ì¸ÅÐÁÄÌìÃÅ»§ÒÔ¼°ÔÚTorÍøÂçÖÐΪ·ÖÖ§×éÖ¯ºÍÄ¿±êÌṩµÄ¶ÀÁ¢Óò¡£Õë¶ÔWindowsµÄNevada±äÌåͨ¹ý¿ØÖÆÌ¨Ö´ÐУ¬ÆälockerʹÓÃSalsa20Ëã·¨¶Ô´óÓÚ512KBµÄÎļþ½øÐмäЪ¼ÓÃÜ¡£Linux/VMware ESXi°æ±¾Ê¹ÓÃÓëWindowsÏàͬµÄ¼ÓÃÜËã·¨£¨Salsa20£©£¬µ«¿ÉÄÜ´æÔÚBug£¬Ëü»áÌø¹ýËùÓоÞϸÔÚ512KBµ½1.25MBÖ®¼äµÄÎļþ¡£
https://resecurity.com/blog/article/nevada-ransomware-waiting-for-the-next-dark-web-jackpot