PayPalÒòй¶3.5Íò¿Í»§µÄ¸öÈ˺ͲÆÕþÐÅÏ¢±»ÆðËß

Ðû²¼Ê±¼ä 2023-03-07

1¡¢PayPalÒòй¶3.5Íò¿Í»§µÄ¸öÈ˺ͲÆÕþÐÅÏ¢±»ÆðËß


ýÌå3ÔÂ4Èճƣ¬PayPalÒòй¶½ü35000¿Í»§µÄ¸öÈ˺ͲÆÕþÐÅÏ¢ÃæÁÙ¼¯ÌåËßËÏ¡£Ô­¸æAshley PillardºÍDestiny RuckerÌáÆðËßËÏ£¬³Æ¸Ã¹«Ë¾µÄÊèºöµ¼ÖÂÊý¾Ýй¶Ê¼þ¡£ÖµµÃ×¢ÒâµÄÊÇ£¬PayPalÔÚ2023Äê1ÔÂ19ÈÕ¿ªÊ¼ÁªÏµÓû§²¢·¢ËÍÊý¾Ýй¶֪ͨ£¬½âÊÍ˵ËûÃǵÄÕË»§ÔÚ2022Äê12ÔÂ6ÈÕÖÁ8ÈÕÔâµ½¹¥»÷¡£Æ¾¾ÝËßËÏ£¬PayPalδÄÜʵʩ»ù±¾µÄÄþ¾²´ëÊ©»ò×ñÊØÁª°îóÒ×ίԱ»áÖÆ¶¨µÄÐÐÒµÊý¾Ý±£»¤³ß¶ÈºÍÖ¸ÄÏ£¬µ¼ÖÂÐÕÃûºÍÉç»áÄþ¾²ºÅÂëµÈÐÅϢй¶¡£¸ÃËßËÏÒÑÓÚÉÏÖÜËÄÔÚÃÀ¹ú¼ÓÀû¸£ÄáÑÇÖݱ±ÇøµØÒªÁìÔºÌáÆð¡£


https://www.hackread.com/paypal-sued-over-data-breach/


2¡¢Ñо¿ÈËÔ±·¢ÏÖÕë¶ÔÆóÒµ¼¶Â·ÓÉÆ÷µÄжñÒâÈí¼þHiatusRAT


Lumen Black Lotus LabsÔÚ3ÔÂ6ÈÕÅû¶ÁËÕë¶ÔÆóÒµ¼¶Â·ÓÉÆ÷µÄ¹¥»÷»î¶¯£¬Éæ¼°À­¶¡ÃÀÖÞ¡¢Å·Ö޺ͱ±ÃÀµÈµØÓò¡£¸Ã»î¶¯±»³ÆÎªHiatus£¬Ëü»áѬȾ¼¶Â·ÓÉÆ÷²¢°²×°Á½¸ö¶ñÒâ¶þ½øÖÆÎļþ£¬Ô¶³Ì·ÃÎÊľÂíHiatusRATÒÔ¼°ÔÚÄ¿±êÉ豸Éϲ¶×½Êý¾Ý°üµÄtcpdump±äÌå¡£¹¥»÷ÕßÖ÷ÒªÕë¶ÔÔËÐÐi386¼Ü¹¹µÄEoL DrayTek VigorÐͺÅ2960ºÍ3900£¬½ØÖÁ2023Äê2ÔÂÖÐÑ®£¬Ô¼100̨·ÓÉÆ÷Òѱ»ÈëÇÖ¡£ÊÜÓ°ÏìµÄÐͺÅÊǸߴø¿í·ÓÉÆ÷£¬¿ÉÒÔÖ§³ÖÊý°ÙÃûÔ¶³ÌÔ±¹¤µÄVPNÁ¬½Ó¡£Òò´ËÍÆ²â¹¥»÷ÕßѬȾĿ±êÒÔÊÕ¼¯Êý¾Ý£¬²¢½¨Á¢Òþ±ÎµÄÊðÀíÍøÂç¡£


https://thehackernews.com/2023/03/new-hiatusrat-malware-targets-business.html


3¡¢»ªÊ¢¶Ù¹«½»¹«Ë¾Pierce Transit±»LockBitÀÕË÷200ÍòÃÀÔª


¾Ý3ÔÂ3ÈÕ±¨µÀ£¬»ªÊ¢¶ÙÖݵÄÒ»¼Ò¹«¹²½»Í¨ÔËÓªÉÌPierce TransitÔâµ½LockBitµÄ¹¥»÷£¬±»ÀÕË÷200ÍòÃÀÔª¡£¹¥»÷¿ªÊ¼ÓÚ2023Äê2ÔÂ14ÈÕ¿ªÊ¼£¬¸Ã¹«Ë¾²»µÃ²»ÊµÊ©ÁÙʱ±äͨ´ëÊ©£¬ÒÔά³ÖÿÌìµÄ¹«½»·þÎñ¡£2ÔÂ28ÈÕ£¬LockBitÐû²¼ÁËPierce Transit¹¥»÷ʼþµÄÏêÇ飬Éù³ÆÇÔÈ¡Á˺Ïͬ¡¢¿Í»§ÐÅÏ¢¡¢±£ÃÜЭÒéºÍÐżþµÈÐÅÏ¢£¬ÕâЩÊý¾ÝÏÖÔÚ¶¼ÔÚ³öÊÛ¡£Ä¿Ç°£¬Pierce TransitµÄ´ó²¿ÃÅÔËÓªÒÑÍêÈ«»Ö¸´£¬ÆäÌåÏּƻ®ÊµÊ©ÐµÄÍøÂçÄþ¾²¼à¿Ø¹¤¾ßºÍÄþ¾²´ëÊ©¡£


https://www.malwarebytes.com/blog/news/2023/03/public-transportation-service-pierce-transit-struck-by-lockbit-ransomware


4¡¢GunAuction.comÍøÕ¾±»ºÚ56.5Íò¸öÕË»§µÄÐÅϢй¶


¾ÝýÌå3ÔÂ2ÈÕ±¨µÀ£¬ºÚ¿ÍÈëÇÖÁËGunAuction.com²¢ÇÔÈ¡ÁËÓû§µÄ¸öÈËÐÅÏ¢¡£2022Äêµ×£¬Ñо¿ÈËÔ±ÔÚÊôÓںڿ͵ÄÒ»¸öÅäÖôíÎóµÄ·þÎñÆ÷ÉÏ·¢ÏÖÁËÕâЩ±»µÁÊý¾Ý¡£Ð¹Â¶ÐÅÏ¢Éæ¼°ÐÕÃû¡¢×¡Ö·¡¢Ã÷ÎÄÃÜÂëºÍµç»°ºÅÂëµÈ¡£TechCrunch³ÆÆäÄܹ»ÑéÖ¤Ñù±¾Êý¾ÝµÄÕæÊµÐÔ£¬µ«Éв»Çå³þÕâЩÊý¾ÝÓжàС£HaveIBeenPwned³ÂËßÌåÏÖ£¬¹¥»÷·¢ÉúÔÚÈ¥Äê12Ô£¬Ó°ÏìÁË56.5Íò¸öÕË»§¡£


https://securityaffairs.com/142920/data-breach/gunauction-site-data-breach.html


5¡¢Ñо¿ÈËÔ±·¢ÏÖBooking.comÉϿɵ¼ÖÂÕÊ»§½Ù³ÖµÄ©¶´


Salt SecurityÓÚ3ÔÂ2ÈÕ³ÆÆä·¢ÏÖÁËÔÚÏßÂÃÐÐÉçBooking.comÉϵÄÄþ¾²Â©¶´¡£Ñо¿ÈËÔ±·¢Ïֵĩ¶´¼¯ÖÐBooking.comʵʩOAuthµÄ·½Ê½ÉÏ£¬Éæ¼°OAuthÓëFacebookµÄ¼¯³É¡£¹¥»÷Õß¿ÉÓÕʹĿ±êµã»÷ÌØÖÆÁ´½Ó£¬Í¨¹ýÀÄÓÃOAuthµÇ¼»úÖÆÀ´²¶×½ÒѵǼÓû§µÄÉí·ÝÑéÖ¤´úÂ롣Ȼºó¹¥»÷Õß·ÃÎÊËûÃÇ×Ô¼ºµÄÕÊ»§£¬ÔÚÓ¦ÓÃÏòÔ¤¶©·þÎñÆ÷·¢Ë͵ÄÉí·ÝÑéÖ¤ÇëÇóÖУ¬½«×Ô¼ºµÄ´úÂëÌæ»»ÎªÄ¿±êµÄ´úÂë¡£ÀÖ³ÉÀûÓÃÕâЩ©¶´¿ÉÍêÈ«¿ØÖÆÄ¿±êÕÊ»§£¬À´ÇÔÈ¡¸öÈËÐÅÏ¢²¢Ö´ÐÐÈ¡Ïû»òÔ¤¶¨µÈ²Ù×÷¡£¸ÃÎÊÌ⻹ӰÏìÁËBooking.comµÄæ¢ÃÃÍøÕ¾Kayak.com¡£


https://salt.security/blog/traveling-with-oauth-account-takeover-on-booking-com


6¡¢LookoutÐû²¼2022ÄêÒÆ¶¯ÍøÂçµöÓã¹¥»÷Ì¬ÊÆµÄ·ÖÎö³ÂËß


3ÔÂ1ÈÕ£¬LookoutÐû²¼ÁË2022ÄêÈ«ÇòÒÆ¶¯ÍøÂçµöÓãÌ¬ÊÆµÄ·ÖÎö³ÂËß¡£³ÂË߳ƣ¬2022ÄêÊÇÓÐÊ·ÒÔÀ´Òƶ¯µöÓã¹¥»÷×î¶àµÄÒ»Ä꣬ÿ¸ö¼¾¶È¶¼ÓÐÁè¼Ý30%µÄ¸öÈËºÍÆóÒµÓû§Ôâµ½¹¥»÷¡£Êܵ½¸ß¶È¼à¹ÜµÄÐÐÒµ£¬°üÂÞ±£ÏÕ¡¢ÒøÐС¢Ö´·¨¡¢Ò½ÁƱ£½¡ºÍ½ðÈÚ·þÎñ£¬×îÒ×Ôâµ½¹¥»÷¡£·Çµç×ÓÓʼþµÄµöÓã¹¥»÷Ò²ÔÚ¼¤Ôö£¬ÓïÒôµöÓã¡¢¶ÌÐŵöÓãºÍ¶þάÂëµöÓãÔÚ2022ÄêQ2¶ÈÔö¼ÓÁËÆß±¶¡£¶ÔÓÚÔâµ½ÒÆ¶¯µöÓã¹¥»÷µÄÆóÒµ¶øÑÔ£¬Ëðʧ¿ÉÄÜÊǾ޴óµÄ¡£Lookout¼ÆËãµÃ³ö£¬´ËÀ๥»÷¶ÔÒ»¸öÓµÓÐ5000ÃûÔ±¹¤µÄ×éÖ¯µÄDZÔÚÄê¶È²ÆÕþÓ°ÏìÊǽü400ÍòÃÀÔª¡£


https://www.lookout.com/form/the-global-state-of-mobile-phishing-report