McLaren Health CareÔâµ½¹¥»÷220ÍòÈ˵ÄÐÅϢй¶
Ðû²¼Ê±¼ä 2023-11-13¾Ý11ÔÂ10ÈÕ±¨µÀ£¬McLaren Health Care(Âõ¿Â×)Åû¶ÁË7ÔÂÖÁ8Ô·¢ÉúµÄÒ»ÆðÊý¾Ýй¶Ê¼þ£¬Ó°ÏìÁË2192515È˵ÄÐÅÏ¢¡£Âõ¿Â×ÓÚ8ÔÂ22ÈÕ·¢ÏÖÁËÒì³£»î¶¯£¬ÊÓ²ìÏÔʾ¹¥»÷Õß7ÔÂ28ÈÕÖÁ8ÔÂ23ÈÕδ¾ÊÚȨ·ÃÎÊÁËÆäÍøÂç¡£ÓÐÖ¤¾Ý±íÃ÷£¬8ÔÂ31ÈÕ¹¥»÷Õß·ÃÎÊÁËÊý¾Ý£¬²¢Ö±µ½10ÔÂ10ÈÕÈ·ÈÏй¶Êý¾ÝµÄÀàÐÍ¡£¾¡¹Ü¸Ã»ú¹¹Ã»ÓÐ͸¶Óйع¥»÷µÄ¸ü¶àϸ½Ú£¬µ«ALPHVÉù³Æ¶ÔÂõ¿Â׵Ĺ¥»÷ÂôÁ¦¡£ËûÃÇ»¹Ðû²¼Á˱»µÁÊý¾ÝÑù±¾£¬²¢ÍþвҪÅÄÂôÓ°Ïì250ÍòÈ˵ÄÊý¾Ý¿â¡£
https://securityaffairs.com/154014/data-breach/mclaren-health-care-data-breach.html
2¡¢CloudflareÍøÕ¾Ôâµ½Anonymous SudanµÄDDoS¹¥»÷
¾ÝýÌå11ÔÂ9ÈÕ±¨µÀ£¬CloudflareÍøÕ¾Ôâµ½Anonymous SudanµÄDDoS¹¥»÷¡£CloudflareÍøÕ¾å´»ú£¬ÏÔʾ¡°ÎÒÃǺÜÇ¸ØÆ......µ«ÄúµÄ¼ÆËã»ú»òÍøÂç¿ÉÄÜÕýÔÚ·¢ËÍ×Ô¶¯²éѯ¡£ÎªÁ˱£»¤ÎÒÃǵÄÓû§£¬ÎÒÃÇÏÖÔÚÎÞ·¨´¦ÖÃÄúµÄÇëÇó¡±ÒÔ¼°Ò»¸ö¿´ÆðÀ´¡°Óеã²î³Ø¾¢¡±µÄGoogle»Õ±ê¡£CloudflareÌåÏÖDDoS¹¥»÷µ¼ÖÂwww.cloudflare.com·ºÆðÁ˼¸·ÖÖÓµÄÁ¬½ÓÎÊÌâ¡£µ«ÊÇûÓÐÓ°ÏìCloudflareµÄÈκηþÎñ»ò²úÎ﹦Ч£¬Ò²Ã»Óпͻ§Êܵ½Ó°Ïì¡£Anonymous SudanÉù³Æ¶Ô´ËÊÂÂôÁ¦£¬²¢³Æ¹¥»÷Á¬ÐøÊ±¼äΪ1Сʱ¡£
https://www.bleepingcomputer.com/news/technology/cloudflare-website-downed-by-ddos-attack-claimed-by-anonymous-sudan/
3¡¢MandiantÅû¶Sandworm¹¥»÷ÎÚ¿ËÀ¼µçÁ¦ÏµÍ³µÄÏêÇé
MandiantÔÚ11ÔÂ9ÈÕÅû¶ÁËSandwormÀûÓÃÕë¶ÔOTµÄÐÂÐ͹¥»÷Ó°ÏìÎÚ¿ËÀ¼µçÁ¦¹©Ó¦µÄ»î¶¯¡£¸Ãʼþ·¢ÉúÓÚ2022Äêµ×£¬MandiantÌåÏÖÕâÊÇÒ»´Î¶àʼþÍøÂç¹¥»÷£¬ÀûÓÃÁËÓ°ÏìICS/OTµÄз½Ê½¡£¹¥»÷ÕßÊ×ÏÈʹÓÃOT¼¶´ËÍâLotL¹¥»÷£¬¿ÉÄܻᴥ·¢Ä¿±ê±äµçÕ¾¶Ï·Æ÷£¬µ¼ÖÂÒâÍâÍ£µç£¬Í¬Ê±¶ÔÎÚ¿ËÀ¼¸÷µØµÄÒªº¦»ù´¡Éèʩʵʩ´ó¹æÄ£µ¼µ¯¹¥»÷¡£SandwormËæºóÔÚÄ¿±êµÄITϵͳÖа²×°ÁËCADDYWIPERµÄбäÖÖ£¬´Ó¶øÖ´Ðеڶþ´ÎÆÆ»µÐÔ¹¥»÷¡£
https://www.mandiant.com/resources/blog/sandworm-disrupts-power-ukraine-operational-technology
4¡¢Imperial Kitten¹¥»÷Öж«µØÓòÔËÊä¡¢ÎïÁ÷ºÍ¿Æ¼¼¹«Ë¾
11ÔÂ9ÈÕ£¬CrowdStrike¹ûÈ»ÁËImperial KittenÕë¶ÔÖж«µØÓòÔËÊä¡¢ÎïÁ÷ºÍ¿Æ¼¼¹«Ë¾µÄµÄÐÂÒ»Âֻ¡£10Ô·ݣ¬¹¥»÷Õß¿ªÊ¼·Ö·¢ÒÔ¡°ÊÂÇéÕÐÆ¸¡±Ö÷Ì⣬°üÂÞ¶ñÒâExcel¸½¼þµÄµöÓãÓʼþ¡£´ò¿ªºó¶ñÒâºê´úÂë»áÌáÈ¡Á½¸öÅú´¦ÖÃÎļþ£¬ËüÃÇ´´½¨³Ö¾ÃÐÔ²¢ÔËÐÐpayloadÀ´½øÐз´Ïòshell·ÃÎÊ¡£È»ºó£¬¹¥»÷ÕßʹÓÃPAExecµÈ¹¤¾ßºáÏòÒÆ¶¯ÒÔÔ¶³ÌÖ´Ðнø³Ì£¬Ê¹ÓÃNetScanÕì²ìÍøÂ磬ʹÓÃProcDump´ÓϵͳÄÚ´æÖлñȡƾ¾Ý£¬Ê¹ÓÃ×Ô½ç˵¶ñÒâÈí¼þIMAPLoaderºÍStandardKeyboardÓëC2·þÎñÆ÷ͨÐÅ¡£
https://www.crowdstrike.com/blog/imperial-kitten-deploys-novel-malware-families/
5¡¢Î¢Èí³ÆSysAid©¶´CVE-2023-47246±»ÓÃÀ´·Ö·¢Clop
ýÌå11ÔÂ9Èճƣ¬¹¥»÷ÕßÕýÔÚÀûÓ÷þÎñ¹ÜÀíÈí¼þSysAidÖеÄ©¶´·ÃÎÊÆóÒµµÄ·þÎñÆ÷À´ÇÔÈ¡Êý¾Ý£¬²¢²¿ÊðÀÕË÷Èí¼þClop¡£ÕâÊÇÒ»¸ö·¾¶±éÀú©¶´£¨CVE-2023-47246£©£¬ÔÚºÚ¿ÍÀûÓøÃ©¶´ÈëÇÖÄÚ²¿·þÎñÆ÷ºóÓÚ11ÔÂ2ÈÕ±»·¢ÏÖ£¬SysAidÔÚÊÓ²ìºó¹ûÈ»Á˹¥»÷µÄ¼¼Êõϸ½Ú¡£Î¢ÈíÏÖÔÚÈ·¶¨£¬¸Ã©¶´±»Lace Tempest£¨ÓÖ³ÆFin11ºÍTA505£©ÓÃÀ´²¿ÊðÀÕË÷Èí¼þClop¡£SysAidÒÑÐû²¼Â©¶´²¹¶¡£¬½¨ÒéËùÓÐÓû§Á¢¼´°²×°¸üС£
https://www.bleepingcomputer.com/news/security/microsoft-sysaid-zero-day-flaw-exploited-in-clop-ransomware-attacks/
6¡¢KasperskyÐû²¼¹ØÓÚDucktail¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß
11ÔÂ10ÈÕ£¬KasperskyÐû²¼Á˹ØÓÚDucktail¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß¡£DucktailÊÇÒ»¸ö¶ñÒâÈí¼þ¼Ò×壬×Ô2021ÄêϰëÄêÒÔÀ´Ò»Ö±»îÔ¾£¬Ö¼ÔÚÇÔÈ¡FacebookÆóÒµÕÊ»§¡£±¾³ÂËß·ÖÎöÁË×î½üµÄÒ»´Î»î¶¯£¬3ÔÂÖÁ10ÔÂÉÏÑ®£¬Ö÷ÒªÕë¶ÔÓªÏúרҵÈËÔ±¡£ÓëÒÔÍùÒÀÀµ.NETÓ¦Ó÷¨Ê½µÄ»î¶¯²îÒ죬Õâ´Î»î¶¯Ê¹ÓÃÁËDelphi¡£¸Ã»î¶¯·¢ËͰüÂÞ¹«Ë¾Ð²úÎïͼƬºÍαװ³ÉPDFµÄ¶ñÒâ¿ÉÖ´ÐÐÎļþµÄÎĵµ£¬Ö¼ÔÚÁ÷´«Ð°汾µÄDucktail¡£
https://securelist.com/ducktail-fashion-week/111017/