CarlsbadµÄ¹«Ë¾ÔâǰԱ¹¤±¨³ð£¬1200¸öOffice 365ÕÊ»§É¾³ý£»CNAϰȾPhoenix£¬1.5Íǫ̀É豸±»¼ÓÃÜ

°ä²¼¹¦·ò 2021-03-26

1.CarlsbadµÄ¹«Ë¾ÔâǰԱ¹¤±¨³ð£¬1200¸öOffice 365ÕÊ»§±»É¾³ý


1.jpg


ÃÀ¹úCarlsbadµÄITÕ÷ѯ¹«Ë¾Ô⵽ǰԱ¹¤Deepanshu KherµÄ±¨³ð£¬1200¸öOffice 365ÕÊ»§±»É¾³ý¡£KherÓÚ2018Äê5Ô±»Ô­¹«Ë¾¿ª³ý£¬Ö®ºó»Øµ½ÁËÓ¡¶È²¢ÓÚͬÄê8ÔÂ8ÈÕÈëÇÖÁ˸ù«Ë¾£¬É¾³ýÆä1200¶à¸öMicrosoft Office 365ÕÊ»§£¨×ܹ²1500¸ö£©¡£µ¼Ö¹«Ë¾Ô±¹¤ÎÞ·¨Ê¹Óõç×ÓÓʼþ¡¢ÁªÏµÈËÁÐ±í¡¢»áÒéÈÕÀú¡¢Îĵµ¡¢ÊÓÆµºÍÒôƵ»áÒéµÈ·þÎñ£¬¹«Ë¾±»ÆÈ¹Ø¹ØÁ½Ì죬ºóÓÖÆÆ·ÑÊýÔÂÆëÈ«¸´Ô­ÔËÓª£¬ËùÉæÓöȸߴï560000ÃÀÔª¡£KherÓÚ½ñÄê1ÔÂ11ÈÕ±»²¶£¬±»Åд¦2ÄêͽÐÌ£¬·£¿î567084ÃÀÔª¡£    


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/resentful-employee-deletes-1-200-microsoft-office-365-accounts-gets-prison/


2.CNAϰȾPhoenix CryptoLocker£¬1.5Íò¶ą̀É豸±»¼ÓÃÜ


2.png


±£ÏÕ¹«Ë¾CNA³ÆÆäÔ⵽еÄÀÕË÷Èí¼þPhoenix CryptoLockerµÄ¹¥»÷¡£CNA FinancialÊÇÃÀ¹ú×î´óµÄóÒײƸ»ºÍÒâ±íÖÐÉ˱£ÏÕ¹«Ë¾Ö®Ò»¡£¹¥»÷²úÉúÔÚ3ÔÂ21ÈÕ£¬ºÚ¿Í¼ÓÃÜÁËÆä³¬¹ý1.5Íò¶ą̀É豸£¬Ô̺¬Ê¹Óù«Ë¾µÄVPN½øÐÐÔ¶³Ì°ì¹«µÄÔ±¹¤µÄÍÆËã»ú£¬µ¼Ö¹«Ë¾ÔÚÏß·þÎñÖжÏ£¬ÒµÎñÔËÓªÊܵ½Ó°Ïì¡£¾ÝϤ£¬ÐµÄPhoenix Locker¿ÉÄÜÓëEvil Corp£¬¸ÃÍÅ»ïʹÓÃÐÂÀÕË÷Èí¼þ¼Ò×åHadesÒÔÈÆ¹ýÃÀ¹úµÄÔì²Ã¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/insurance-giant-cna-hit-by-new-phoenix-cryptolocker-ransomware/


3.Microsoft°ä²¼²¹¶¡£¬½¨¸´PsExecÀûÓÃÖеÄÌáȨ·ì϶


3.jpg


Microsoft°ä²¼ÁËPsExec v2.33£¬ÒÔ½¨¸´ÆäÖеÄÌáȨ·ì϶¡£PsExecÊÇSysinternalsʵÓ÷¨Ê½£¬ÔÊÐíÖÎÀíÔ±ÔÚÔ¶³ÌÍÆËã»úÉÏÖ´Ðи÷Àà»î¶¯£¬¹¥»÷Õßͨ³£ÀûÓÃÆäÔÚÍøÂçºáÏòÒÆ¶¯²¢×°ÖöñÒâÈí¼þ¡£David WellsÓÚ2020Äê12Ô·¢ÏÖÁËλÓÚ¶¨Ãû¹Ü·ͨѶÖеķì϶£¬±¾µØÓû§¿ÉÀûÓÃÆäÌáÉýµ½SYSTEMȨÏÞ¡£WellsÔÚÉϱ¨¸Ã·ì϶²¢ÆÚ´ý90Ììºó£¬¹«¿ªÁËÆëÈ«µÄPoC¡£Microsoft×îÖÕÓÚ3ÔÂ23ÈÕ£¬ÔÚPsExec v2.33Öа䲼Á˸÷ì϶µÄ²¹¶¡·¨Ê½¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-fixes-windows-psexec-privilege-elevation-vulnerability/


4.Ó¡¶ÈÒ©ÉÌFKOLÒòÏú»ÙÊý¾Ý±»ÃÀ¹úFDA·£¿î5000ÍòÃÀÔª


4.jpg


Ó¡¶Èresenius KabiÁöѧÓÐÏÞ¹«Ë¾£¨FKOL£©µÄÒ»¼ÒÔìÒ©³§ÒòÏú»ÙÊý¾Ý£¬±»ÃÀ¹úʳƷºÍÒ©ÎïÖÎÀí¾Ö£¨FDA£©·£¿î5000ÍòÃÀÔª¡£¸Ã¹¤³§ÖØÒª³ö²úÃÀ¹ú¾øÖ¢»¼ÕßʹÓõļ¸ÖÖ·ÖÆç°©Ö¢Ò©ÎïµÄ»îÐÔÒ©Îï³É·Ö(api)¡£¸Ã¹«Ë¾Ô­¶¨ÓÚ2013Äê1Ô½ÓÊÜFDA²é³­£¬µ«ÃÀ¹ú˾·¨²¿°µÊ¾£¬¸Ã¹«Ë¾Ô±¹¤´Ó¹¤³§ÖÐ×ªÒÆÁËÍÆËã»ú¡¢Ö½ÖÊÎļþºÍÆäËû×ÊÁÏ£¬²¢É¾³ýÁËÓйظó§Î¥¹æÐÐΪ֤¾ÝµÄ¼Í¼¡£3ÔÂ23ÈÕ£¬FKOL±»ÃÀ¹ú´¦Ëù·¨ÔºÅз£¿î3000ÍòÃÀÔª²¢³ä¹«2000ÍòÃÀÔªµÄ´¦·£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/drug-maker-to-pay-50m-for/


5.ºÚ¿ÍÔÚÒÔÉ«ÁдóѡǰһÌ칫¿ª³¬¹ý600Íò¸öÑ¡ÃñµÄÐÅÏ¢


5.jpg


ÔÚÒÔÉ«Áдóѡǰ²»µ½24Ó×ʱ£¬ºÚ¿Í¹«¿ªÁ˳¬¹ý650Íò¸öÑ¡ÃñµÄÐÅÏ¢¡£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬6528565ÃûÑ¡ÃñµÄÐÕÃûºÍѡƱºÅÂ룬ÒÔ¼°³¬¹ý300ÍòÒÔÉ«Áй«ÃñµÄÐÕÃû¡¢µç»°ºÅÂë¡¢Éí·ÝÖ¤ºÅÂë¡¢¼ÒÍ¥µØÖ·¡¢ÐԱ𡢴ºÇïºÍÕþÖÎÆ«ºÃµÈÓ×ÎÒÐÅÏ¢¡£¾ÝϤ£¬Õâ´ÎÊÂÎñÊÇÓÉÓÚÈí¼þ¹«Ë¾Elector SoftwareΪÒÔÉ«ÁÐÕþµ³Likud¿ª·¢µÄÀûÓ÷¨Ê½ElectorÖдæÔÚ·ì϶£¬Ä¿Ç°Éв»Ã÷ÏÔй¶µÄÊý¾ÝÊÇ·ñÒѱ»½Ó¼û¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/115918/hacking/israeli-voters-leak.html


6.±í»ãÂòÂôÉÌFBSй¶½ü20TB³¬¹ý160ÒÚÌõ¿Í»§µÄÂòÂô¼Í¼


6.jpg


WizCase×êÑÐÈËÔ±·¢ÏÖ±í»ãÂòÂôÉÌFBSÒòElasticsearch·þÎñÆ÷ÅäÖÃÃýÎó£¬Ð¹Â¶Á˽ü20TB³¬¹ý160ÒÚÌõ¿Í»§µÄÂòÂô¼Í¼¡£FBSÊÇÊÀ½çÉÏ×îæÂҵıí»ã£¨forex£©ÂòÂôÔÚÏ߯½Ì¨Ö®Ò»£¬ÔÚÈ«ÇòÕ¼Óжà´ï1600ÍòÓû§¡£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬Óû§ÐÕÃû¡¢µç×ÓÓʼþºÍÕ˵¥µØÖ·¡¢µç»°ºÅÂë¡¢IPµØÖ·¡¢»¤ÕÕºÅÂë¡¢É罻ýÌåID¡¢Éí·ÝÖ¤¡¢¼ÝÊ»ÅÆÕÕ¡¢ÒøÐÐÕË»§¶ÔÕʵ¥¡¢Ë®µç·ÑÕ˵¥ºÍÐÅÓþ¿¨µÈ£¬ÒÔ¼°Óû§ID¡¢Î´¼ÓÃܵÄÃÜÂë¡¢µÇ¼º¹Çà¼Í¼¡¢»áÔ±Êý¾ÝºÍÃÜÂë³ÁÖÃÁ´½ÓµÈÊý¾Ý¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/forex-leaks-millions-customer/