·áÌï½ðÈÚ·þÎñ¹«Ë¾Ôâµ½Medusa¹¥»÷²¢±»ÀÕË÷800ÍòÃÀÔª

Ðû²¼Ê±¼ä 2023-11-20
1¡¢·áÌï½ðÈÚ·þÎñ¹«Ë¾Ôâµ½Medusa¹¥»÷²¢±»ÀÕË÷800ÍòÃÀÔª


¾ÝýÌå11ÔÂ16ÈÕ±¨µÀ £¬·áÌï½ðÈÚ·þÎñ¹«Ë¾(TFS)Ôâµ½¹¥»÷ £¬ÆäÔÚÅ·Ö޺ͷÇÖÞµÄϵͳÉϼì²âµ½Î´¾­ÊÚȨµÄ·ÃÎÊ ¡£ÀÕË÷ÍÅ»ïMedusaÒѽ«TFSÁÐÈëÆäÍøÕ¾ £¬²¢ÀÕË÷800ÍòÃÀÔªÒÔɾ³ýÊý¾Ý ¡£¹¥»÷Õß»¹¸øÁË·áÌï10ÌìµÄʱ¼ä×ö³ö»ØÓ¦ £¬²¢¿ÉÒÔÑ¡ÔñÑÓºã¾ÃÏÞ £¬Ö»ÒªÃ¿ÌìÖ§¸¶10000ÃÀÔª ¡£ÎªÁËÖ¤Ã÷ÈëÇÖ £¬ºÚ¿ÍMedusaÐû²¼Á˰üÂÞ²ÆÕþÎļþ¡¢µç×Ó±í¸ñºÍ¹ºÖ÷¢Æ±µÈÊý¾ÝµÄÑù±¾ ¡£´ó¶àÊýÎļþ¶¼ÊǵÂÓï £¬±íÃ÷ºÚ¿ÍÀֳɷÃÎÊÁË·áÌïÖÐÅ·ÒµÎñµÄϵͳ ¡£Ñо¿ÈËԱ͸¶ £¬´Ë´Î¹¥»÷¿ÉÄÜÓëCitrix GatewayµÄ©¶´ÓÐ¹Ø ¡£


https://securityaffairs.com/154319/data-breach/toyota-financial-services-medusa-ransomware.html


2¡¢ÑÅÂí¹þ·ÆÂɱö·Ö¹«Ë¾±»INC¹¥»÷Ô¼37GBµÄÊý¾Ýй¶


¾Ý11ÔÂ17ÈÕ±¨µÀ £¬ÑÅÂí¹þÆû³µ·ÆÂɱöĦÍгµÖÆÔì·Ö¹«Ë¾(YMPH)Ôâµ½¹¥»÷ £¬²¿ÃÅÔ±¹¤ÐÅϢй¶ ¡£YMPHÓÚ10ÔÂ25ÈÕÊ״η¢ÏÖÎÊÌâ £¬Æäһ̨·þÎñÆ÷Ô⵽δ¾­ÊÚȨµÄ·ÃÎÊ £¬Ä¿Ç°ÕýÔÚÆÀ¹À´Ë´Î¹¥»÷Ó°ÏìµÄ·¶Î§ ¡£ÀÕË÷ÍÅ»ïINCÉù³Æ¶Ô´ËÊÂÂôÁ¦ £¬ÓÚ11ÔÂ15ÈÕ½«¸Ã¹«Ë¾Ìí¼Óµ½ÆäÍøÕ¾ ¡£½ñºóÐû²¼Á˶à¸öÎļþ £¬ÆäÖаüÂÞԼĪ37GBµÄÊý¾Ý £¬Éæ¼°Ô±¹¤IDÐÅÏ¢¡¢±¸·ÝÎļþÒÔ¼°¹«Ë¾ºÍÏúÊÛÐÅÏ¢µÈ ¡£


https://www.bleepingcomputer.com/news/security/yamaha-motor-confirms-ransomware-attack-on-philippines-subsidiary/ 


3¡¢BGRSºÍSIRVAÔâ¹¥»÷µ¼Ö¼ÓÄôóÊÐÕþ»ú¹¹´óÁ¿Ô±¹¤ÐÅϢй¶


¼ÓÄôóÕþ¸®ÔÚ11ÔÂ19ÈÕÅû¶Á˽üÆÚµÄÒ»´ÎÊý¾Ýй¶Ê¼þ £¬Ó°ÏìÁËÏÖÈκÍǰÈι«¹²·þÎñ²¿ÃÅÔ±¹¤ÒÔ¼°¼ÓÄôó»Ê¼ÒÆï¾¯ºÍ¼ÓÄôóÎä×°¶ÓÎé³ÉÔ± ¡£Ä¿Ç°È·¶¨ £¬ÎªÔ±¹¤Ìṩ°áǨ·þÎñµÄBrookfield Global Relocation Services(BGRS)ºÍSIRVA Worldwide Relocation & Moving ServicesÊÇ´Ë´ÎÊý¾Ýй¶Ê¼þµÄÔ´Í· ¡£¾ÝϤ £¬Ô±¹¤×Ô1999ÄêÒÔÀ´ÏòÕâЩ¹«Ë¾ÌṩµÄ¸öÈ˺ͲÆÕþÐÅÏ¢¿ÉÄÜÒѾ­Ð¹Â¶ ¡£10ÔÂ6ÈÕ £¬LockBit3.0½«SIRVAÌí¼Óµ½ÁËÆäÍøÕ¾ £¬²¢ÓÚ11ÔÂ19ÈÕ¹ûÈ»Á˱»µÁÊý¾Ý ¡£BGRSÍøÕ¾×Ô9ÔÂ29ÈÕÆðÒ»Ö±´¦ÓÚÀëÏß״̬ ¡£


https://www.databreaches.net/canadian-government-announces-data-breach-urges-public-service-employees-to-take-action/


4¡¢Google³ÆZimbra©¶´CVE-2023-37580±»4¸öÍÅ»ïÀûÓÃ


11ÔÂ16ÈÕ £¬Google TAGÅû¶ÁË4ÆðÀûÓÃZimbraÖеÄXSS©¶´£¨CVE-2023-37580£©µÄ¹¥»÷»î¶¯ ¡£µÚÒ»´Î»î¶¯·¢ÉúÓÚ6ÔÂµ× £¬Õë¶ÔµÄÊÇÏ£À°Ä³Õþ¸®»ú¹¹ £¬·¢ÏÖ©¶´ºóZimbraÔÚGitHubÉÏÍÆËÍÁËÒ»¸ö½ô¼±ÐÞ¸´·¨Ê½ ¡£Winter VivernÓÚ7ÔÂ11ÈÕÀûÓøÃ©¶´¹¥»÷ÁËĦ¶û¶àÍߺÍÍ»Äá˹µÄÕþ¸®»ú¹¹ £¬ZimbraÔÚ7ÔÂ13ÈÕÐû²¼Äþ¾²Í¨¸æ½¨ÒéÓû§½ÓÄÉ»º½â´ëÊ© ¡£7ÔÂ20ÈÕ £¬Î´ÖªºÚ¿Í¹¥»÷ÁËÔ½ÄÏijÕþ¸®»ú¹¹ £¬ÎåÌìºóZimbraÐû²¼Á˸é¶´µÄ¹Ù·½²¹¶¡ ¡£8ÔÂ25 £¬TAG·¢ÏÖÁ˵Ú4´ÎÀûÓøÃ©¶´µÄ¹¥»÷»î¶¯ £¬Õë¶Ô°Í»ù˹̹Õþ¸®»ú¹¹ ¡£


https://blog.google/threat-analysis-group/zimbra-0-day-used-to-target-international-government-organizations/


5¡¢8BaseÍÅ»ïͨ¹ýSmokeLoader·Ö·¢ÐµÄPhobos±äÌå


CiscoÔÚ11ÔÂ18ÈÕ³Æ £¬8Base½üÆÚµÄ»î¶¯ÓÐËùÔö¼Ó £¬ËüʹÓÃÀÕË÷Èí¼þPhobosµÄ±äÌåºÍÆäËü¹ûÈ»¿ÉÓõŤ¾ßÖ´Ðй¥»÷ ¡£¸ÃÍÅ»ï´ó¶àÊýPhobos±äÌå¶¼ÊÇÓɺóÃÅSmokeLoader·Ö·¢µÄ ¡£ÔÚ8Base»î¶¯ÖÐ £¬ËüÔÚ¼ÓÃܵÄpayloadÖÐǶÈëÁËÀÕË÷Èí¼þ×é¼þ £¬È»ºó½«Æä½âÃܲ¢¼ÓÔØµ½SmokeLoader½ø³ÌµÄÄÚ´æÖÐ ¡£´ËÍâ £¬Phobos¶Ô1.5MBÒÔϵÄÎļþÍêÈ«¼ÓÃÜ £¬¶ÔÁè¼ÝãÐÖµµÄÎļþ²¿ÃżÓÃÜ £¬ÒÔÌá¸ßËÙ¶È ¡£


https://blog.talosintelligence.com/deep-dive-into-phobos-ransomware/


6¡¢AvastÐû²¼2023ÄêµÚÈý¼¾¶ÈµÄÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß


11ÔÂ16ÈÕ £¬AvastÐû²¼ÁË2023ÄêµÚÈý¼¾¶ÈµÄÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß ¡£µÚÈý¼¾¶È £¬Avastƽ¾ùÿÔÂÀ¹½ØµÄ¶ñÒâÈí¼þ¹¥»÷Áè¼Ý10ÒÚ´Î £¬ÍøÂçÍþв£¨ÓÈÆäÊÇÉ繤¹¥»÷ºÍ¶ñÒâ¹ã¸æ£©µÄ´ó·ùÔö¼ÓÍÆ¶¯ÁËÕâÒ»Ôö³¤ ¡£¹¥»÷Õß¶ÔÈ˹¤ÖÇÄܵÄÀûÓÃÕýÔÚ¼ÓËÙ £¬ÓÈÆäÊÇÔÚÉî¶ÈαÔì½ðÈÚÕ©Æ­»î¶¯ÖÐ ¡£¹ã¸æÈí¼þÏÔÖøÉý¼¶ £¬ÌرðÊÇÄÏÃÀ¡¢·ÇÖÞ¡¢¶«ÄÏÅ·ºÍ¶«ÑǵØÓò ¡£ÐÅÏ¢ÇÔÈ¡·¨Ê½µÄÍþвÔö¼Ó £¬ÆäÖÐÎÚ¿ËÀ¼£¨44%£©¡¢ÃÀ¹ú£¨21%£©ºÍÓ¡¶È£¨16%£©µÄÔö·ù×îÃ÷ÏÔ ¡£RAT¼ÌÐø³ÊÔö³¤Ç÷ÊÆ £¬ÆÏÌÑÑÀ£¨148%£©¡¢²¨À¼£¨55%£©ºÍ˹Âå·¥¿Ë£¨43%£©µÈ¹úµÄÔö·ù×îÃ÷ÏÔ ¡£


https://decoded.avast.io/threatresearch/avast-q3-2023-threat-report/