Sumo LogicµÄAWSÕÊ»§Ôâµ½ÈëÇÖ½¨Òé¿Í»§ÖØÖÃAPIÃÜÔ¿

Ðû²¼Ê±¼ä 2023-11-10

1¡¢Sumo LogicµÄAWSÕÊ»§Ôâµ½ÈëÇÖ½¨Òé¿Í»§ÖØÖÃAPIÃÜÔ¿


 ¾ÝýÌå11ÔÂ8ÈÕ±¨µÀ£¬Äþ¾²ºÍÊý¾Ý·ÖÎö¹«Ë¾Sumo Logic·¢ÏÖÆäAWSÕÊ»§Ôâµ½ÈëÇÖ£¬½¨Òé¿Í»§ÖØÖÃAPIÃÜÔ¿¡£¸Ã¹«Ë¾ÌåÏÖ£¬ËûÃÇÓÚ11ÔÂ3ÈÕ·¢ÏÖ¹¥»÷ÕßʹÓÃÇÔÈ¡µÄƾ֤»ñµÃÁËSumo Logic AWSÕË»§µÄ·ÃÎÊȨÏÞ£¬Ä¿Ç°»¹Ã»Óз¢ÏÖÆäÍøÂç»òϵͳÊܵ½Ó°Ï죬¿Í»§Êý¾ÝÒ²ÒѼÓÃÜ¡£ÎªÁËÓ¦¶Ô´ËÊ£¬¸Ã¹«Ë¾Ëø¶¨ÁËÊÜÓ°ÏìµÄ»ù´¡ÉèÊ©£¬²¢ÖØÖÃÁËÆä»ù´¡ÉèÊ©µÄËùÓпÉÄÜ̻¶µÄƾ֤¡£´ËÍ⣬Sumo Logic½¨Òé¿Í»§ÖØÖÃÓÃÓÚ·ÃÎÊÆä·þÎñµÄƾ¾Ý»òÓëSumo Logic¹²ÏíµÄÓÃÓÚ·ÃÎÊÆäËüϵͳµÄƾ¾Ý¡£


https://securityaffairs.com/153882/security/sumo-logic-security-breach.html


2¡¢ChatGPT·¢Éú¹ÊÕÏå´»úÊýСʱ¸Ã¹«Ë¾µÄAPIÒ²Êܵ½Ó°Ïì


¾Ý11ÔÂ8ÈÕ±¨µÀ£¬OpenAIµÄChatGPTÒòÑÏÖØµÄ¹ÊÕϹرÕ£¬Öжϻ¹Ó°ÏìÁ˸ù«Ë¾µÄÓ¦Ó÷¨Ê½±à³Ì½Ó¿Ú(API)¡£ÊÜÓ°ÏìµÄ¿Í»§»á¿´µ½¡°Ëƺõ¶éÂäÁË¡±µÄ´íÎóÌáʾ£¬ÒÔ¼°²éѯʱÏÔʾ¡°Éú³É»Ø¸´Ê±·ºÆð´íÎ󡱡£11ÔÂ8ÈÕ11:05£¬OpenAIÌåÏÖÊÜÓ°ÏìµÄ·þÎñÒѻָ´ÉÏÏß¡£¾Ý11ÔÂ9ÈÕµÄ×îÐÂÏûÏ¢£¬OpenAI֤ʵÖÜÈýµÄChatGPT¼°ÆäAPI·¢ÉúµÄÖжÏÊÇDDoS¹¥»÷µ¼ÖµÄ¡£Anonymous SudanÔÚTelegramÉÏÉù³Æ¶Ô´Ë´Î¹¥»÷ÂôÁ¦¡£


https://www.bleepingcomputer.com/news/technology/chatgpt-down-after-major-outage-impacting-openai-systems/


3¡¢¾©´ÉAVX͸¶ÀÕË÷¹¥»÷µ¼ÖÂ39000È˵ÄÐÅϢй¶


11ÔÂ9ÈÕ±¨µÀ³Æ£¬Kyocera AVX Components Corporation(KAVX)ÕýÔÚ·¢ËÍÀÕË÷¹¥»÷µ¼ÖµÄÊý¾Ýй¶µÄ֪ͨ¡£Í¨ÖªÖÐÌåÏÖ£¬ËüÓÚ10ÔÂ10ÈÕ·¢ÏÖºÚ¿ÍÔÚ2ÔÂ16ÈÕÖÁ3ÔÂ30ÈÕ·ÃÎÊÁËÆäϵͳ£¬µ¼Ö²¿ÃÅϵͳ±»¼ÓÃܺÍijЩ·þÎñÔÝʱÖжÏ¡£KAVXÊӲ췢ÏÖ39111È˵ÄÐÅϢй¶£¬²¢½«ÎªËûÃÇÌṩ12¸öÔµİµÍø¼à¿ØºÍÃÜÂëй¶·þÎñ¡£LockBitÔøÉù³ÆÓÚ5ÔÂ26ÈÕÈëÇÖÁËKAVX£¬²¢¹ûÈ»Á˶à¸ö±»µÁÊý¾ÝÑù±¾£¬°üÂÞ»¤ÕÕɨÃè¡¢²ÆÕþÎļþºÍ±£ÃÜЭÒéµÈ¡£


https://www.bleepingcomputer.com/news/security/kyocera-avx-says-ransomware-attack-impacted-39-000-individuals/


4¡¢US RadiologyÒò2021ÄêµÄÀÕË÷¹¥»÷±»·£¿î45ÍòÃÀÔª


ýÌå11ÔÂ9Èճƣ¬ÒòδÐÞ¸´Â©¶´µ¼ÖÂÀÕË÷¹¥»÷£¬US Radiology±»Å¦Ô¼AG·£¿î45ÍòÃÀÔª¡£¾ÝϤ£¬Ë¾·¨²¿³¤Ç¿µ÷©¶´CVE-2021-20016Òѱ»ÀÕË÷ÍÅ»ï¶à´ÎÀûÓá£US RadiologyÎÞ·¨°²×°¹Ì¼þ²¹¶¡ÒòΪÆäÓ²¼þÒÑ´¦ÓÚEOL½×¶Î£¬²»ÔÙ±»Ö§³Ö¡£¸Ã¹«Ë¾¼Æ»®ÓÚ2021Äê7Ô¸ü»»Ó²¼þ£¬µ«×îÖÕ¸ÃÏîÄ¿±»ÍƳÙ¡£ÓÉÓÚ©¶´Î´µÃµ½½â¾ö£¬¸Ã¹«Ë¾ÓÚ2021Äê12ÔÂ8ÈÕÔâµ½ÀÕË÷¹¥»÷£¬µ¼Ö½ü20ÍòÃû»¼ÕßµÄÃô¸ÐÐÅϢй¶¡£³ýÁË·£¿îÍ⣬¸Ã¹«Ë¾»¹±ØÐëÉý¼¶ÆäITϵͳ¡¢Æ¸ÇëרÈ˹ÜÀíÆäÊý¾ÝÄþ¾²¼Æ»®¡¢¼ÓÃÜËùÓÐÃô¸ÐµÄ»¼ÕßÐÅÏ¢²¢¿ª·¢ÉøÍ¸²âÊԼƻ®¡£


https://therecord.media/new-york-attorney-general-fines-radiology-firm-after-ransomware-attack


5¡¢Group-IBÅû¶ÀÕË÷Èí¼þÔËÓªÍÅ»ïFarnetworkµÄÉÌҵģʽ


11ÔÂ9ÈÕ£¬Group-IB¶ÁËÀÕË÷Èí¼þÔËÓªÍÅ»ïFarnetworkµÄÉÌҵģʽ¡£FarnetworkÔÚ2019ÄêÖÁ2021Äê¼ä£¬×ÊÖúJSWORM¡¢Nefilim¡¢KarmaºÍNemty½øÐжñÒâÈí¼þ¿ª·¢ºÍÔËÓª¹ÜÀí£¬²¢ÔÚ2022Ä꽨Á¢ÁËÀÕË÷Èí¼þ¼´·þÎñ(RaaS)Nokoyawa¡£2023Äê2Ô£¬farnetwork¿ªÊ¼ÕÐļNokoyawaµÄÁ¥ÊôÍŻËüÌṩÏֳɵķÃÎÊȨÏÞ¡£¹¥»÷Àֳɺó£¬Á¥ÊôÍÅ»ï»ñµÃ65%µÄÊê½ð£¬½©Ê¬ÍøÂçËùÓÐÕß»ñµÃ20%£¬ÀÕË÷Èí¼þËùÓÐÕß»ñµÃ15%¡£½ØÖÁ½ñÄê10Ô£¬NokoyawaµÄÍøÕ¾Í£Ö¹ÔËÓª£¬×ܹ²ÁгöÁË35¸ö±»¹¥»÷Ä¿±ê¡£


https://www.group-ib.com/blog/farnetwork/


6¡¢Check PointÐû²¼10Ô·ÝÈ«ÇòÍþвָÊýµÄ·ÖÎö³ÂËß


11ÔÂ8ÈÕ£¬Check PointÐû²¼ÁË10Ô·ÝÈ«ÇòÍþвָÊýµÄ·ÖÎö³ÂËß¡£FormbookÊÇ10Ô·Ý×î³£¼ûµÄ¶ñÒâÈí¼þ£¬Ó°ÏìÁËÈ«Çò3%µÄʵÌ壬Æä´ÎÊÇNJRat£¨2%£©£¬´ÓµÚÁùλÉÏÉýÖÁµÚ¶þλ¡£½ÌÓýºÍÑо¿ÐÐÒµÈÔÈ»ÊÇÊܵ½¹¥»÷×îÑÏÖØµÄÐÐÒµ£¬Æä´ÎÊÇͨÐÅÒÔ¼°¾üÕþÐÐÒµ¡£10Ô·Ý×î³£±»ÀûÓõÄ©¶´ÊÇZyxel ZyWALLÃüÁî×¢Èë©¶´(CVE-2023-28771)£¬Ó°ÏìÁËÈ«Çò42%µÄʵÌå¡£×î³£¼ûµÄÒÆ¶¯¶ñÒâÈí¼þÊÇAnubis£¬Æä´ÎÊÇAhMythºÍHiddad¡£


https://blog.checkpoint.com/security/october-2023s-most-wanted-malware-njrat-jumps-to-second-place-while-agenttesla-spreads-through-new-file-sharing-mal-spam-campaign/