EmbyÔ¶³Ì¹Ø±Õ²¿ÃÅÔâµ½¹¥»÷µÄÓû§Ã½Ìå·þÎñÆ÷ʵÀý
Ðû²¼Ê±¼ä 2023-05-291¡¢EmbyÔ¶³Ì¹Ø±Õ²¿ÃÅÔâµ½¹¥»÷µÄÓû§Ã½Ìå·þÎñÆ÷ʵÀý
¾ÝýÌå5ÔÂ26ÈÕ±¨µÀ£¬EmbyÔ¶³Ì¹Ø±ÕÁ˲¿ÃÅÔâµ½¹¥»÷µÄÓû§ÍйÜýÌå·þÎñÆ÷ʵÀý¡£¹¥»÷»î¶¯Ê¼ÓÚ5ÔÂÖÐÑ®£¬Æäʱ¹¥»÷ÕßÕë¶Ô̻¶µÄ˽ÈËEmby·þÎñÆ÷£¬²¢ÈëÇÖÄÇЩÅäÖÃΪÔÊÐí¹ÜÀíÔ±ÔÚµ±µØÍøÂçÉÏÎÞÃÜÂëµÇ¼µÄ·þÎñÆ÷¡£ÎªÁË»ñµÃ·ÃÎÊȨÏÞ£¬¹¥»÷Õß»¹ÀûÓÃÁËÒ»¸öÊðÀí±êͷ©¶´£¬¸Ã©¶´×î½üÔÚ²âÊÔ°æÆµµÀÖб»ÐÞ¸´¡£¹¥»÷Õß°²×°ÁËÒ»¸ö¶ñÒâ²å¼þÀ´ÀûÓ÷ÃÎÊȨÏÞ£¬ÔÚ±»Ñ¬È¾µÄEmbyʵÀý²¿ÊðºóÃÅ£¬¸Ã²å¼þ¿ÉÊÕ¼¯Óû§Æ¾¾Ý¡£Embyδ͸¶±»¹¥»÷·þÎñÆÚÊýÁ¿£¬µ«¼Æ»®¾¡¿ìÐû²¼Emby Server 4.7.12Äþ¾²¸üÐÂÀ´½â¾ö¸ÃÎÊÌâ¡£
https://www.bleepingcomputer.com/news/security/emby-shuts-down-user-media-servers-hacked-in-recent-attack/
2¡¢OneMainÒòÍøÂçÄþ¾²ÎÊÌⱻŦԼDFS·£¿î425ÍòÃÀÔª
¾Ý5ÔÂ26ÈÕ±¨µÀ£¬OneMain Financial Group±»Å¦Ô¼½ðÈÚ·þÎñ²¿(DFS)·£¿î425ÍòÃÀÔª¡£DFSÔÚÒ»·ÝÉùÃ÷ÖÐÌåÏÖ£¬OneMainδÄÜÓÐЧµØ¹ÜÀíµÚÈý·½·þÎñÌṩÉ̵ķçÏÕ¡¢¹ÜÀí·ÃÎÊȨÏÞÒÔ¼°Ê¹ÓÃÕýʽµÄÓ¦ÓÃÄþ¾²¿ª·¢ÒªÁ죬Õâ´ó´óÔö¼ÓÁ˸ù«Ë¾Ãæ¶ÔÍøÂçÄþ¾²Ê¼þµÄ´àÈõÐÔ¡£ÀýÈ磬OneMainʹÓÃÁËÆäÄÚ²¿¿ª·¢µÄ·ÇÕý¹æÏîÄ¿¹ÜÀí¿ò¼ÜµÈ¡£¸Ã¹«Ë¾ÌåÏÖ£¬ËüÔç¾Í½â¾öÁËÊÓ²ìÖз¢ÏÖµÄÎÊÌ⣬´Ë´ÎÊÓ²ìËùÉó²éµÄÊÇÆä2017ÄêÖÁ2020Äê³õµÄÕþ²ß¡£
https://therecord.media/one-main-fined-ny-for-cybersecurity-lapses
3¡¢Ñо¿ÍŶӳÆMagalenhaÐж¯¹¥»÷30¶à¼ÒÆÏÌÑÑÀ½ðÈÚ»ú¹¹
5ÔÂ25ÈÕ£¬SentinelLabs³ÆÆäÊӲ쵽ÃûΪMagalenhaÐж¯µÄ¹¥»÷»î¶¯£¬×Ô2021ÄêÒÔÀ´Ò»Ö±Õë¶Ô30¶à¼ÒÆÏÌÑÑÀ½ðÈÚ»ú¹¹ÇÔÈ¡ÐÅÏ¢¡£¸Ã»î¶¯¿ÉÄÜÓë°ÍÎ÷µÄ¹¥»÷ÍÅ»ïÓйأ¬Ê¼ÓÚ»ìÏýµÄVB½Å±¾£¬¿É»ñÈ¡²¢Ö´ÐжñÒâÈí¼þ¼ÓÔØ·¨Ê½£¬²¢ÔÚÎåÃëÖÓµÄÑӳٺ󣬽«ºóÃÅPeepingTitleµÄÁ½¸ö±äÌå¼ÓÔØµ½Ä¿±êϵͳÖС£PeepingTitleÊÇÒ»¸öDelphi¿ª·¢µÄ¶ñÒâÈí¼þ£¬±àÒëÈÕÆÚΪ4Ô·ݡ£¹¥»÷Õß·Ö·¢Á½¸ö±äÌåµÄÔÒòÊÇ£¬Ò»¸öÓÃÓÚ²¶×½ÆÁÄ»£¬ÁíÒ»¸öÓÃÓÚ¼àÊÓ´°¿ÚÒÔ¼°Óû§ÓëÕâЩ±äÌåµÄ½»»¥¡£
https://www.sentinelone.com/labs/operation-magalenha-long-running-campaign-pursues-portuguese-credentials-and-pii/
4¡¢BlackByteÉù³Æ¶ÔÃÀ¹ú°Â¹Å˹ËþÊÐÔâµ½µÄ¹¥»÷ÂôÁ¦
5ÔÂ26ÈÕ±¨µÀ£¬ÀÕË÷ÍÅ»ïBlackByteÉù³Æ¶ÔÃÀ¹ú×ôÖÎÑÇÖݰ¹Å˹ËþÊÐÔâµ½µÄ¹¥»÷ÂôÁ¦¡£¸ÃÊÐÔÚÆäÍøÕ¾ÉϽâÊÍ˵£¬Ëü´Ó5ÔÂ21ÈÕ¿ªÊ¼Óöµ½¼¼ÊõÀ§ÄÑ£¬µ¼Ö²¿ÃÅϵͳÖжϡ£»¹³ÎÇåµ½£¬ÕâÆðʼþÓë֮ǰ·¢ÉúµÄITϵͳÖжÏÎ޹ء£BlackByteÔÚÆäÍøÕ¾Éϳƣ¬ÒѴӰ¹Å˹ËþµÄ¼ÆËã»úÉÏÇÔÈ¡ÁË´óÁ¿Êý¾Ý£¬²¢¹ûÈ»ÁË8.1 GBµÄÑù±¾Êý¾Ý×÷Ϊ֤¾Ý¡£¸ÃÍÅ»ïÀÕË÷40ÍòÃÀÔªÀ´É¾³ýÊý¾Ý£¬²¢Ìá³öÒÔ30ÍòÃÀÔªµÄ¼Û¸ñ½«Êý¾Ý³öÊÛ¸ø¸ÐÐËȤµÄµÚÈý·½¡£
https://securityaffairs.com/146717/hacking/city-of-augusta-cyberattack.html
5¡¢Mandiant·¢ÏÖÀûÓÃICSÐÒé¹¥»÷µçÍøµÄCOSMICENERGY
MandiantÔÚ5ÔÂ26ÈÕ͸¶£¬Æä·¢ÏÖÁËеĶñÒâÈí¼þCOSMICENERGY£¬ÀûÓÃICSÐÒéÀ´ÆÆ»µµçÍø¡£ËüÊÇÓɶíÂÞ˹µÄ¹¥»÷ÕßÓÚ2021Äê12ÔÂÉÏ´«µ½VirusTotalµÄ£¬Ä¿Ç°Ã»ÓÐÔÚÒ°Íâ±»ÀûÓá£MandiantÌåÏÖ£¬Õâ¿ÉÄÜÊǶíÂÞ˹µçÐŹ«Ë¾Rostelecom-Solar¿ª·¢µÄÒ»ÖÖºì¶Ó¹¤¾ß£¬ÓÃÓÚÄ£Äâ2021Äê10ÔµĵçÁ¦ÖжϺÍÓ¦¼±ÏìÓ¦ÑÝϰ¡£COSMICENERGYµÄ¹¦Ð§¿ÉÒÔÓëIndustroyerÏàæÇÃÀ£¬ÒòΪËüÄܹ»ÀûÓù¤ÒµÍ¨ÐÅÐÒéIEC-104ÏòRTU·¢³öÖ¸Áî¡£ÀûÓÃÕâÖÖ·ÃÎÊȨÏÞ£¬¹¥»÷Õß¿ÉÒÔ·¢ËÍÔ¶³ÌÃüÁîÀ´Ó°ÏìµçÁ¦Ïß¿ª¹ØºÍ¶Ï·Æ÷µÄÆô¶¯£¬´Ó¶øµ¼ÖµçÁ¦Öжϡ£
https://www.mandiant.com/resources/blog/cosmicenergy-ot-malware-russian-response
6¡¢Ñо¿ÈËÔ±·¢ÏÖÀûÓÃWin10д×Ö°åDLL½Ù³Ö©¶´µÄQBot»î¶¯
ýÌå5ÔÂ27ÈÕ±¨µÀ£¬Ñо¿ÈËÔ±·¢ÏÖÐÂÒ»ÂÖQBot¹¥»÷»î¶¯¡£¸Ã»î¶¯ÀûÓÃÁËWindows 10д×Ö°åÖеÄDLL½Ù³Ö©¶´Ñ¬È¾¼ÆËã»ú£¬²¢ÀûÓúϷ¨·¨Ê½ÈƹýÄþ¾²Èí¼þµÄ¼ì²â¡£Ä¿±êµã»÷µöÓãÓʼþÖеÄÁ´½Óʱ£¬»áÏÂÔØÒ»¸öËæ»úÃüÃûµÄZIP´æµµ£¬ÆäÖаüÂÞWin10д×Ö°å¿ÉÖ´ÐÐÎļþdocument.exeºÍDLLÎļþedputil.dll¡£¼ÓÔØ¶ñÒâ°æ±¾µÄedputil.dllºó£¬»á´ÓÔ¶³ÌÖ÷»úÏÂÔØÎ±×°³ÉPNGµÄDLL£¬È»ºóʹÓÃrundll32.exeÖ´ÐдËPNG¡£Õâʱ£¬QBot½«ÔÚºǫ́ƽ¾²µØÔËÐС£
https://www.bleepingcomputer.com/news/security/qbot-malware-abuses-windows-wordpad-exe-to-infect-devices/