Mixin Network±»ºÚËðʧ¸ß´ï2ÒÚÃÀÔª²¢ÔÝÍ£ÔËÓª

Ðû²¼Ê±¼ä 2023-09-26

1¡¢Mixin Network±»ºÚËðʧ¸ß´ï2ÒÚÃÀÔª²¢ÔÝÍ£ÔËÓª


¾Ý9ÔÂ25ÈÕ±¨µÀ £¬Î»ÓÚÖйúÏã¸ÛµÄ¼ÓÃÜ»õ±Ò¹«Ë¾Mixin NetworkÔâµ½ÍøÂç¹¥»÷ £¬Ëðʧ¸ß´ï2ÒÚÃÀÔª¡£´Ë´Îʼþ·¢ÉúÔÚ9ÔÂ23ÈÕÁ賿 £¬¸Ã¹«Ë¾Á¢¼´ÔÝÍ£ÁË´æ¿îºÍÈ¡¿î¡£¾Ý³Æ¹¥»÷Õß¿ÉÒÔ·ÃÎÊMixin NetworkÔÆ·þÎñÌṩÉ̵ÄÊý¾Ý¿â £¬ÇÔÈ¡Ö÷ÍøÉϵIJ¿ÃÅ×ʲú¡£PeckShieldµÈÇø¿éÁ´×·×ÙÆ÷ÒÑʶ±ð³öÔ¼1.41ÒÚÃÀÔªµÄ±»µÁ×ʲú £¬ÆäÖÐ9350ÍòÃÀԪΪETH £¬2350ÍòÃÀԪΪDAI£¨´ÓUSDT»»À´£© £¬2330ÍòÃÀԪΪBTC¡£


https://www.bleepingcomputer.com/news/security/mixin-network-suspends-operations-following-200-million-hack/


2¡¢°Ä´óÀûÑÇTissuPathÒò¹©Ó¦É̱»¹¥»÷446 GBÊý¾Ýй¶


¾ÝýÌå9ÔÂ21ÈÕ±¨µÀ £¬°Ä´óÀûÑÇרҵ²¡Àíѧ¹«Ë¾TissuPathÔâµ½¹¥»÷µ¼ÖÂÊý¾Ýй¶¡£¸Ãʼþ·¢ÉúÓÚ8ÔÂ24ÈÕ £¬Ô´ÓÚTissuPathµÄÒ»¼ÒµÚÈý·½¹©Ó¦ÉÌÔâµ½¹©Ó¦Á´¹¥»÷¡£ÊӲ췢ÏÖ £¬ÓÉÓÚÔ¶³Ì·ÃÎʹ¤¾ß°ü(RAT)´æÔÚ©¶´ £¬¹©Ó¦É̵ÄϵͳºÍÓû§ÕÊ»§±»ÈëÇÖ¡£ÕâЩºÏ·¨µÄ¹ÜÀíÔ±ÕË»§±»Ä£·Â £¬ÒÔ½øÈëTissuPathµÄϵͳ £¬¹¥»÷Õß¿ÉÄÜ»ñµÃÁË2011ÄêÖÁ2020ÄêÏòTissuPath·¢³öµÄ²¡Àíת½é¡£9ÔÂ2ÈÕ £¬AlphVÉù³Æ¶Ô´Ë´Î¹¥»÷ÂôÁ¦ £¬²¢ÔÚ9ÔÂ5ÈÕ³Æ446 GBºÍ735414¸öÎļþÒѱ»Ð¹Â¶¡£


https://www.databreaches.net/tissupaths-data-breach-notice-provides-details-about-how-they-were-attacked-and-their-incident-response/


3¡¢Google³ÆAppleºÍChrome©¶´±»ÓÃÓÚ°²×°Predator


ýÌå9ÔÂ22ÈÕ±¨µÀ £¬Google͸¶AppleÔÚÉÏÖÜËÄÐÞ¸´µÄÈý¸ö©¶´Òѱ»ÀÄÓà £¬×÷Ϊ°²×°¼äµýÈí¼þPredatorµÄ©¶´ÀûÓÃÁ´µÄÒ»²¿ÃÅ¡£½ñÄê5ÔÂÖÁ9Ô £¬¹¥»÷ÕßÀûÓÃÕâЩ©¶´£¨CVE-2023-41991¡¢CVE-2023-41992ºÍCVE-2023-41993£© £¬Í¨¹ýÓÕ¶ü¶ÌÐźÍWhatsAppÏûÏ¢ £¬Õë¶Ô°£¼°Ç°¹ú»áÒéÔ±Ahmed EltantawyÖ´Ðй¥»÷¡£Google TAG»¹ÊӲ쵽Chrome©¶´£¨CVE-2023-4762£©Ò²±»ÓÃÓÚÕë¶Ô°£¼°µÄAndroidÉ豸°²×°Predator¡£Apple³ÆiOSËø¶¨Ä£Ê½¿ÉÒÔ·ÀÓù´ËÀ๥»÷¡£


https://www.bleepingcomputer.com/news/security/recently-patched-apple-chrome-zero-days-exploited-in-spyware-attacks/


4¡¢Akamai·¢ÏÖÀûÓÃÐé¼ÙBookingÍøÕ¾µÄÅÓ´óµöÓã»î¶¯


AkamaiÔÚ9ÔÂ21ÈճƷ¢ÏÖÁËÕë¶Ô¾ÆµêÐÐÒµµÄÅÓ´óµÄµöÓã»î¶¯¡£ÔÚԭʼĿ±ê£¨¾Æµê£©ÉÏÖ´ÐÐÐÅÏ¢ÇÔÈ¡·¨Ê½ºó £¬¹¥»÷Õß¿ÉÒÔ·ÃÎÊÓë¿Í»§Ö®¼äµÄÏûÏ¢¡£¹¥»÷ÕßÓë×îÖÕÄ¿±êÖ®¼ä½¨Á¢¿ÉÐŵÄͨÐÅÇþµÀºó £¬¾Íαװ³É¾Æµê¡¢Ô¤¶©·þÎñ»òÂÃÐÐÉç·¢Ë͵öÓãÐÅÏ¢ £¬ÒªÇó½øÐÐÌØ±ðµÄÐÅÓÿ¨ÑéÖ¤¡£¹¥»÷Õß»¹½ÓÄÉÁ˶àÖÖÄþ¾²ÑéÖ¤ºÍ·´·ÖÎö¼¼Êõ £¬Èç¹ûÄ¿±êͨ¹ýÕâЩ²âÊÔ £¬½«»á¿´µ½Ò»¸öαװ³ÉBooking.com¸¶¿îÒ³ÃæµÄµöÓãÍøÕ¾ £¬ÇëÇóÐÅÓÿ¨ÐÅÏ¢¡£¹¥»÷Õß»¹Ôö¼ÓÁËÖÇÄÜÁÄÌìÖ§³ÖÇþµÀ £¬ÒÔÈ·±£µöÓã»î¶¯µÄ¿ÉÐŶÈ¡£


https://www.akamai.com/blog/security-research/sophisticated-phishing-campaign-targeting-hospitality


5¡¢ESETÅû¶OilRigÕë¶ÔÒÔÉ«ÁеÄÁ½´Î¹¥»÷»î¶¯µÄϸ½Ú


9ÔÂ22ÈÕ £¬ESETÅû¶ÁËOilRigÕë¶ÔÒÔÉ«ÁÐʵÌåµÄÁ½´Î¹¥»÷»î¶¯ £¬¼´Outer Space(2021Äê)ºÍJuicy Mix(2022Äê)¡£ÕâÁ½´Î¹¥»÷»î¶¯Ê¹ÓÃÁËÏàͬµÄ¼ÆÄ±£ºOilRigÊ×ÏÈÈëÇÖÒ»¸öºÏ·¨ÍøÕ¾ÓÃ×÷C&C·þÎñÆ÷ £¬È»ºóʹÓÃVBS droppers·Ö·¢C# /.NETºóÃÅ £¬Í¬Ê±»¹²¿ÊðÁËÖÖÖÖÓÃÓÚÔÚÄ¿±êϵͳÉϽøÐÐÊý¾Ýй¶µÄ¹¤¾ß¡£Outer Space»î¶¯Ê¹ÓÃÁËеĺóÃÅSolarºÍеÄÏÂÔØ·¨Ê½SampleCheck5000£¨»òSC5k£© £¬Juicy Mix»î¶¯¶ÔSolar½øÐиïв¢´´½¨Á˺óÃÅMango¡£


https://www.welivesecurity.com/en/eset-research/oilrigs-outer-space-juicy-mix-same-ol-rig-new-drill-pipes/


6¡¢KasperskyÐû²¼2023ÄêÉϰëÄêÎïÁªÍøÍþвµÄ·ÖÎö³ÂËß


9ÔÂ21ÈÕ £¬KasperskyÐû²¼ÁË2023ÄêÉϰëÄêÎïÁªÍøÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß¡£ÎïÁªÍøÑ¬È¾Í¾¾¶Ö÷ÒªÊDZ©Á¦ÆÆ½âºÍÀûÓÃÍøÂç·þÎñÖеÄ©¶´¡£Ã۹޼ǼÏÔʾ £¬2023ÄêÉϰëÄê97.91%µÄ±©Á¦ÆÆ½âʵÑ鼯ÖÐÔÚTelnetÉÏ £¬½ö2.09%Õë¶ÔSSH¡£2023ÄêÉϰëÄê £¬ÖÖÖÖ°µÍøÉÏ×ܹ²Ðû²¼ÁË700¶àÌõÕë¶ÔDDoS¹¥»÷·þÎñµÄ¹ã¸æ¡£ÔÚIoT¶ñÒâÈí¼þÁìÓò´æÔÚ´óÁ¿±äÌå £¬ÆäÖÐÐí¶àÔ´×Ô2016 Mira¶ñÒâÈí¼þ¡£½Ù³ÖÉ豸²¢Ê¹ÓÃËüÌᳫÕë¶ÔÖÖÖÖ·þÎñµÄDoS¹¥»÷µÄľÂíÊÇ×î³£¼ûµÄIoT¶ñÒâÈí¼þÀàÐÍ¡£


https://securelist.com/iot-threat-report-2023/110644/