ÂíÀ´Î÷ÑÇË®Îñ¹«Ë¾RanhillÊý¾Ý¿âºÍ±¸·Ý±»DESORDENɾ³ý

Ðû²¼Ê±¼ä 2023-07-28

1¡¢ÂíÀ´Î÷ÑÇË®Îñ¹«Ë¾RanhillÊý¾Ý¿âºÍ±¸·Ý±»DESORDENɾ³ý


¾ÝýÌå7ÔÂ26ÈÕ±¨µÀ£¬DESORDENÍÅ»ïÉù³Æ¹¥»÷ÁËÂíÀ´Î÷ÑÇÖ÷ÒªµÄË®ÎñºÍ¹©µç¹«Ë¾Ranhill Utilities Berhad¡£¹¥»÷Õß³ÆÆä»÷¹¥»÷ÁËRanhillµÄ¼Æ·ÑÒµÎñºÍ¹©Ë®ÒµÎñ£¬Ó°ÏìÁË100¶àÍò¿Í»§¡£²¢Í¸Â¶¹¥»÷ʼÓÚ2021Äê11Ô£¬Ö®ºóDESORDENÒ»Ö±´æÔÚÓÚËûÃǵÄϵͳÖС£½ñÄê7ÔÂ17ÈÕ£¬¹¥»÷ÕßÈëÇÖÁ˸ù«Ë¾µÄʵʱ¼Æ·ÑϵͳLIVE Billing£¬²¢ÓÚ7ÔÂ18ÈÕµ½19ÈÕ£¬ÇÔÈ¡Á˼ƷÑϵͳÖеÄËùÓÐÊý¾Ý¿â£¬²¢É¾³ýÁ˱¸·ÝºÍÊý¾Ý¿â¡£DESORDEN³ÆÒѾ­ÇÔÈ¡Êý°ÙGBµÄÊý¾Ý£¬RanhillÉÐδ¶Ô´Ëʱ×÷³ö»ØÓ¦¡£


https://www.databreaches.net/major-malaysian-water-utilities-company-hit-by-hackers-ranhill-offline-hackers-claim-databases-and-backups-deleted/


2¡¢ÃÀ¹úÕþ¸®·þÎñ³Ð°üÉÌMaximusÁè¼Ý800ÍòÈ˵ÄÐÅϢй¶


¾Ý7ÔÂ26ÈÕ±¨µÀ£¬ÃÀ¹úÕþ¸®·þÎñ³Ð°üÉÌMaximus͸¶800ÖÁ1100ÍòÈ˵ÄÐÅϢй¶¡£MaximusÖ÷ÒªÂôÁ¦¹ÜÀíÃÀ¹úÕþ¸®×ÊÖúµÄÏîÄ¿£¬ÄêÊÕÈëԼΪ42.5ÒÚÃÀÔª£¬ÒµÎñ±é¼°ÃÀ¹ú¡¢¼ÓÄô󡢰ĴóÀûÑǺÍÓ¢¹ú¡£ÊӲ췢ÏÖ£¬ºÚ¿ÍÀûÓÃÁËMOVEit TransferÖеÄ©¶´¡£7ÔÂ25ÈÕ£¬Clop½«MaximusÌí¼Óµ½ÆäÍøÕ¾µÄ±»¹¥»÷Ä¿±êÁбíÖС£MaximusÄ¿Ç°¼Æ»®ÔÚ½ØÖÁ2023Äê6ÔÂ30Èյļ¾¶ÈÖмǼԼ1500ÍòÃÀÔªµÄÓöÈ£¬ÕâÊǸù«Ë¾¶Ô´Ë´ÎʼþÏà¹ØµÄÊÓ²ìºÍµ÷Í£»î¶¯ÓöÈ×ܶîµÄ¹ÀËã¡£


https://www.bleepingcomputer.com/news/security/8-million-people-hit-by-data-breach-at-us-govt-contractor-maximus/


3¡¢Ò½ÁÆÉ豸ÌṩÉÌCardioCommÔâµ½¹¥»÷·þÎñÔÝʱÖжÏ


ýÌå7ÔÂ26Èճƣ¬¼ÓÄôóÏûÐÄÔà¼à²â¼¼ÊõÌṩÉÌCardioComm SolutionsÔâµ½¹¥»÷£¬µ¼Ö·þÎñÔÝʱÖжÏ¡£¸Ã¹«Ë¾ÌåÏÖ£¬ÔÚÆä·þÎñÆ÷·¢ÉúÄþ¾²Ê¼þºó£¬ÒµÎñÔËÓª½«Êܵ½ÊýÌìÉõÖÁ¸ü³¤Ê±¼äµÄÓ°Ï졣Ŀǰ£¬CardioCommÍøÕ¾ÎÞ·¨·ÃÎÊ£¬²¢ÏÔʾ¡°ÎÒÃǵķþÎñÕýÔÚ¾­ÀúÍ£»ú¡±¡£ÆäÐí¶à²úÎïÒ²Ó°Ï죬ÆäÖаüÂÞÒ»¿îÊÖ³ÖʽÐĵçͼ(ECG)¼à²âÒÇHeartCheck CardiBeat£¬Ëü¿Éͨ¹ýÀ¶ÑÀÁ¬½Óµ½Óû§µÄÖÇÄÜÊÖ»ú½«¼ì²â½á¹ûͨ±¨¸øÒ½Éú¡£ÏÖÔÚÉв»Çå³þÖжϷ¶Î§ÒÔ¼°Ê¼þÐÔÖÊ£¬µ«ÆäÕýÔÚŬÁ¦»Ö¸´Êý¾Ý²¢Öؽ¨Æä·þÎñÆ÷»·¾³£¬Õâ±íÃ÷¿ÉÄÜÊÇÀÕË÷¹¥»÷µÈÆÆ»µÐÔ¹¥»÷¡£


https://techcrunch.com/2023/07/26/cardiocomm-ecg-monitoring-cyberattack/


4¡¢Sophos·¢ÏÖÕë¶Ô±±ÃÀ¿Æ¼¼ºÍ·ÇÓªÀû×éÖ¯µÄNitrogen»î¶¯


SophosÔÚ7ÔÂ26ÈÕÅû¶ÁËÖ÷ÒªÕë¶Ô±±ÃÀ¿Æ¼¼ºÍ·ÇÓªÀû×éÖ¯µÄNitrogen³õʼ·ÃÎʶñÒâÈí¼þ»î¶¯µÄϸ½Ú¡£¸Ã»î¶¯ÀûÓÃGoogleºÍBingËÑË÷¹ã¸æÀ´ÍƹãαÔìµÄÈí¼þÍøÕ¾£¬Ö¼ÔÚ»ñµÃÆóҵϵͳµÄ·ÃÎÊȨÏÞ²¢²¿ÊðCobalt StrikeºÍºÍÀÕË÷Èí¼þµÈ¹¤¾ß¡£Nitrogen»î¶¯µÄÓÕ¶üÈí¼þ°üÂÞAnyDesk¡¢WinSCP¡¢Cisco AnyConnectºÍTreeSize Free¡£Ä¿Ç°ÉÐδȷ¶¨¹¥»÷ÕßµÄÄ¿µÄ£¬µ«Ñ¬È¾Á´ËµÃ÷¿ÉÄÜÓÃÓÚ²¿ÊðÀÕË÷Èí¼þ¡£Trend MicroÔø±¨µÀ¸Ã¹¥»÷Á´ÖÁÉÙÔÚÒ»¸ö¹¥»÷°¸ÀýÖа²×°ÁËBlackCat¡£Google·¢ÑÔÈ˳ÆÒѾ­¼ì²âµ½¶ñÒâ»î¶¯£¬²¢É¾³ýÁËÎ¥·´ÆäÕþ²ßµÄ¹ã¸æ¡£


https://news.sophos.com/en-us/2023/07/26/into-the-tank-with-nitrogen/


5¡¢Metabase QÅû¶Õë¶ÔÀ­¶¡ÃÀÖ޵Ľ©Ê¬ÍøÂçFenixµÄ¹¥»÷


7ÔÂ26ÈÕ±¨µÀ³Æ£¬Metabase Q·¢ÏÖÁËн©Ê¬ÍøÂçFenixµÄ¹¥»÷»î¶¯£¬Ö÷ÒªÕë¶ÔÄ«Î÷¸çºÍÖÇÀû·ÃÎÊÕþ¸®·þÎñµÄÓû§¡£¸Ã»î¶¯Ã°³äÁËÄ«Î÷¸çServicio de Administraci¨®n Tributaria(SAT)ºÍÖÇÀûServicio de Impuestos Internos(SII)µÄ¹Ù·½ÃÅ»§ÍøÕ¾£¬²¢½«Ä¿±êÖض¨Ïòµ½ÕâЩÍøÕ¾¡£ÕâЩαÔìµÄÍøÕ¾ÌáʾÓû§ÏÂÔØËùνµÄÄþ¾²¹¤¾ß£¬Õâʵ¼ÊÉÏ°²×°Á˶ñÒâÈí¼þµÄ³õʼ½×¶Î£¬×îÖջᵼÖÂƾ¾ÝµÈÃô¸ÐÐÅϢй¶¡£


https://www.metabaseq.com/fenix-botnet/


6¡¢NetenrichÐû²¼»ùÓÚAIµÄºÚ¿Í¹¤¾ßFraudGPTµÄ·ÖÎö³ÂËß


7ÔÂ25ÈÕ£¬NetenrichÐû²¼ÁËÓÖÒ»¸ö»ùÓÚAIµÄкڿ͹¤¾ßFraudGPTµÄ·ÖÎö³ÂËß¡£ÕâÊÇÒ»¸öÈ˹¤ÖÇÄÜ»úÆ÷ÈË£¬ÓÃÓÚ´´½¨Óã²æʽµöÓãÓʼþ¡¢Æƽ⹤¾ßÒÔ¼°Ë¢¿¨µÈ¡£¸Ã¹¤¾ßÖÁÉÙ×Ô7ÔÂ22ÈÕÆð¾Í¿ªÊ¼ÔÚÖÖÖÖ°µÍøÊг¡ºÍTelegramƽ̨ÉϳöÊÛ£¬¶©ÔÄÓöÈΪÿÔÂ200ÃÀÔª£¬»òÒ»Äê1700ÃÀÔª¡£¿ª·¢Õß»¹ÌåÏÖ£¬¸Ã¹¤¾ß¾ßÓпª·¢¶ñÒâ´úÂë¡¢¿ª·¢ÎÞ·¨¼ì²âµÄ¶ñÒâÈí¼þºÍ²éÕÒ©¶´µÈ¹¦Ð§¡£ÓëFraudGPTÀàËƵÄWormGPTÓÚ7ÔÂ13ÈÕ±»ÍƳö¡£


https://netenrich.com/blog/fraudgpt-the-villain-avatar-of-chatgpt