KasperskyÅû¶Õë¶Ô¶íÂÞ˹¹¤¿ØÐÐÒµºÍÕþ¸®»ú¹¹µÄ¹¥»÷

Ðû²¼Ê±¼ä 2023-10-26
1¡¢KasperskyÅû¶Õë¶Ô¶íÂÞ˹¹¤¿ØÐÐÒµºÍÕþ¸®»ú¹¹µÄ¹¥»÷


KasperskyÔÚ10ÔÂ24ÈÕÅû¶ÁËÕë¶Ô¶íÂÞ˹¹¤¿ØÐÐÒµºÍÕþ¸®»ú¹¹µÄ¹¥»÷»î¶¯¡£Ñо¿ÈËÔ±ÓÚ6ÔÂÊ״μì²âµ½¸Ã»î¶¯£¬¶øÔÚ8ÔÂÖÐÑ®·¢ÏÖÁËа汾µÄºóÃÅ£¬¸ÃºóÞßÓиüÅÓ´óµÄÈÆ¹ý¹¦Ð§£¬±íÃ÷¹¥»÷ÕýÔÚ½øÐÐÓÅ»¯¡£¹¥»÷ʼÓÚÒ»¸ö°üÂÞ¶ñÒâARJÎļþµÄÓʼþ£¬ÆäÖÐÓÐÒ»¸öÓÕ¶üPDFÎĵµºÍÒ»¸öNSIS½Å±¾£¬¸Ã½Å±¾ÓÃÓÚ»ñÈ¡Ö÷Òªpayload²¢Æô¶¯Ëü¡£Kaspersky³Æ£¬Í¬Ò»µöÓã»î¶¯»¹Á÷´«ÁËÁ½¸öÃûΪNetrunnerºÍDmcservµÄºóÃÅ£¬ÕâЩÊǾßÓвîÒìC2·þÎñÆ÷ÅäÖõÄÏàͬ¶ñÒâÈí¼þ¡£


https://securelist.ru/ataki-na-industrialnyj-i-gosudarstvennyj-sektory-rf/108229/


2¡¢·¨¹úÖ°ÒµÇò¶ÓASVELÔâµ½NoEscape¹¥»÷32GBÊý¾Ýй¶


¾ÝýÌå10ÔÂ24ÈÕ±¨µÀ£¬·¨¹úÖ°ÒµÀºÇò¶ÓLDLC ASVEL(ASVEL)Ôâµ½ÁËÀÕË÷ÍÅ»ïNoEscapeµÄ¹¥»÷¡£NoEscapeÔÚ10ÔÂ9ÈÕ½«¸ÃÇò¶Ó¼ÓÈëÆäÍøÕ¾£¬LDLC ASVELÓÚ10ÔÂ12ÈÕͨ¹ýýÌåÊÕµ½Í¨Öª¡£¹¥»÷ÕßÉù³ÆÇÔÈ¡ÁË32GBÊý¾Ý£¬°üÂÞÇòÔ±µÄ¸öÈË×ÊÁÏ¡¢»¤ÕÕºÍÉí·ÝÖ¤£¬Óë²ÆÕþ¡¢Ë°ÎñºÍÖ´·¨ÊÂÎñÏà¹ØµÄÎļþ£¬ÒÔ¼°±£ÃÜЭÒé¡¢ºÏͬºÍ»úÃÜÐżþµÈ¡£ÀÕË÷ÍÅ»ïÍþвÈç¹û²»½»Êê½ð£¬¾Í»áÔÚ10ÔÂ20ÈÕ֮ǰÐû²¼ÕâЩÊý¾Ý¡£Ä¿Ç°£¬ASVELÒѱ»´ÓNoEscapeµÄÍøÕ¾É¾³ý£¬±íÃ÷¶þÕß¿ÉÄÜÕýÔÚ½øÐÐ̸ÅС£


https://www.bleepingcomputer.com/news/security/asvel-basketball-team-confirms-data-breach-after-ransomware-attack/


3¡¢Redcliffe LabsµÄ7TBÊý¾Ýй¶ӰÏìÔ¼1200Íò»¼Õß


ýÌå10ÔÂ25Èճƣ¬Ó¡¶È±±·½°îŵÒÁ´ïµÄÒ½Áƹ«Ë¾Redcliffe LabsµÄ7TBÒ½ÁÆÊý¾Ýй¶£¬Ó°ÏìÁËÔ¼1200Íò»¼Õß¡£×î³õ£¬Ñо¿ÈËÔ±·¢ÏÖÁËÒ»¸ö²»ÊÜÃÜÂë±£»¤µÄÊý¾Ý¿â£¬×ܾÞϸΪ7TB£¬°üÂÞÔ¼12347297Ìõ¼Ç¼£¬¾­ÊÓ²ìÕâЩÊý¾Ý¼¯ÊôÓÚRedcliffe Labs¡£ÆäÖУ¬³ýÁËÓдóÁ¿»¼Õ߸öÈ˺ÍÒ½ÁÆÊý¾ÝÖ®Í⣬»¹°üÂ޸ù«Ë¾Òƶ¯Ó¦Ó÷¨Ê½µÄ¿ª·¢Îļþ¡£Ä¿Ç°£¬¸ÃÊý¾Ý¿âÒѱ»±£»¤ÆðÀ´£¬Éв»Çå³þ¹ûÈ»Á˶à¾Ã¡£


https://www.hackread.com/database-mess-up-7tb-healthcare-data-leak/


4¡¢ÎÚ¿ËÀ¼NCS§³§³³ÆSmokeloader¶ñÒâÈí¼þ¹¥»î¶¯¼¤Ôö 


10ÔÂ25ÈÕ±¨µÀ³Æ£¬ÎÚ¿ËÀ¼¹ú¼ÒÍøÂçÄþ¾²Ð­µ÷ÖÐÐÄ(NCS§³§³)³Æ£¬ÀûÓöñÒâÈí¼þSmokeloaderµÄ¹¥»÷»î¶¯¼¤Ôö¡£NCS§³§³Ñо¿ÏÔʾ£¬×Ô5ÔÂÒÔÀ´£¬¶ñÒâÈí¼þÔËÓªÍÅ»ïÕë¶ÔÎÚ¿ËÀ¼µÄʵÌåÌᳫÁË´ó¹æÄ£µöÓã¹¥»÷£¬Ö¼ÔÚÈëÇÖϵͳ²¢ÇÔÈ¡ÐÅÏ¢¡£ÔÚ×î½üµÄ»î¶¯ÖУ¬ºÚ¿ÍʹÓÃSmokeloader¹¥»÷Õþ¸®»ú¹¹ºÍ½ðÈÚʵÌ壬ÌرðÊÇ»á¼ÆÐÐÒµ¡£ËûÃÇͨ¹ý½ðÈÚÖ÷ÌâµÄµöÓãÓʼþÀ´ÓÕʹĿ±êÏÂÔØ¶ñÒâÈí¼þ£¬È»ºóÇÔÈ¡ÐÅÏ¢¡£´ËÍ⣬¹¥»÷Õß»¹»áÆÆ»µ»ã¿îÁ÷³Ì£¬Í¨¹ýÌæ»»ºÏ·¨ÕÊ»§µÄÏêϸÐÅÏ¢À´½«×ʽðÖØ¶¨Ïòµ½×Ô¼ºµÄÕÊ»§£¬ÕâÍ»ÏÔÁ˹¥»÷Õß²»Í£±ä»¯µÄ¼ÆÄ±¡£


https://therecord.media/surge-in-smokeloader-malware-attacks-targeting-ukrainian-financial-gov-orgs


5¡¢Salt Security¹ûÈ»¹ØÓÚOAuthЭÒéʵÏÖAPIµÄ©¶´


10ÔÂ24ÈÕ£¬Salt SecurityÐû²¼ÁËеÄÑо¿£¬½ÒʾÁËGrammarly¡¢VidioºÍBukalapakµÈÔÚÏ߯½Ì¨µÄOAuthЭÒéʵÏÖÖÐAPIµÄ©¶´¡£ÕâЩ©¶´ÓпÉÄÜй¶Óû§Æ¾¾Ý²¢µ¼ÖÂÕÊ»§±»ÍêÈ«½Ó¹Ü£¬´Ó¶øÓ°ÏìÊýÊ®ÒÚÓû§£¬ÏÖÒѵõ½½â¾ö¡£¸ÃÑо¿ÖÐ×îÍ»³öµÄÒ»µãÊÇ£¬OAuth×÷Ϊsocial-login±³ºóµÄÖ÷Òª¼¼Êõ£¬Æäʵ±»Éè¼ÆµÃºÜºÃ£¬Ã»ÓÐÃ÷ÏÔÎÊÌâ¡£²»Í⣬Ñо¿ÈËÔ±·¢ÏֵĴó¶àÊýÎÊÌâ¶¼ÓëʹÓÃOAuthµÄ¸÷·½ÓÃÀ´ÊµÏÖOAuthµÄ·½Ê½ÓйØ¡£


https://salt.security/blog/oh-auth-abusing-oauth-to-take-over-millions-of-accounts


6¡¢NCC GroupÐû²¼2023Äê9Ô·ÝÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß


10ÔÂ24ÈÕ£¬NCC GroupÐû²¼ÁË2023Äê9Ô·ÝÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß¡£¼Ì8Ô·ݵÄÏà¶Ôƽ¾²ºó£¬9Ô·ݵÄÀÕË÷»î¶¯µ½´ïÁËǰËùδÓеÄˮƽ£¬¶à´ï514¸öÄ¿±êÔâµ½¹¥»÷£¬½Ï2022Äêͬ±ÈÔö³¤153%¡£Ö÷ÒªµÄ¹¥»÷ÍÅ»ïÊÇLockBit 3.0£¨Ìᳫ79´Î¹¥»÷£©¡¢LostTrust£¨53´Î£©ºÍBlackCat£¨47´Î£©¡£±±ÃÀµØÓòÔâµ½µÄ¹¥»÷×î¶à£¨Õ¼50%£©£¬Æä´ÎÊÇÅ·ÖÞ£¨30%£©ºÍÑÇÖÞ£¨9%£©¡£Õë¶ÔÒ½ÁƱ£½¡ÐÐÒµµÄÀÕË÷¹¥»÷´ó·ùÔö¼Ó£¬½Ï8Ô»·±ÈÔö³¤86%¡£


https://newsroom.nccgroup.com/news/ncc-group-monthly-threat-pulse-september-2023-474190