µçÉÌÆ½Ì¨Mercari³ÆÆäÊܵ½Codecov¹©¸øÁ´¹¥»÷Ó°Ïì £»Ó¢¹úOne CallϰȾDarkSide£¬±»ÀÕË÷1500ÍòÓ¢°÷

°ä²¼¹¦·ò 2021-05-24

1.µçÉÌÆ½Ì¨Mercari³ÆÆäÊܵ½Codecov¹©¸øÁ´¹¥»÷Ó°Ïì


1.jpg


µçÉÌÆ½Ì¨Mercari³ÆÆäÊܵ½Codecov¹©¸øÁ´¹¥»÷µÄÓ°Ï죬´óÁ¿¿Í»§ÐÅϢй¶¡£MercariÊÇÒ»¼ÒÈÕ±¾ÉÏÊй«Ë¾£¬½ØÖÁ2017Ä꣬ÆäÀûÓ÷¨Ê½ÔÚÈ«ÇòµÄÏÂÔØÁ¿Òѳ¬¹ý1ÒڴΡ£Õâ´ÎÊÂÎñй¶ÁË17085ÌõÉæ¼°¿Í»§ÕÊ»§µÄÐÅÏ¢£¬Ô̺¬ÒøÐдúÂë¡¢·ÖÐдúÂë¡¢ÕʺźͳÖÓÐÈËµÈ £»7966ÌõMercariºÍMerpayºÏ×÷ͬ°éµÄÐÅÏ¢£¬Ô̺¬ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢´ÓÊô¹ØÏµºÍÓʼþµØÖ·µÈ £»ÒÔ¼°2615ÌõÔ±¹¤ÐÅÏ¢µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/e-commerce-giant-suffers-major-data-breach-in-codecov-incident/


2.Ó¡¶ÈÄáÎ÷Ñǵ±¾ÖÏÖÈ·ÈÏÆä²¿ÃŹ«ÃñµÄÉç±£ÐÅÏ¢ÒÑй¶


2.jpg


ÉÏÖÜ£¬Ò»¸öÃûΪKotzµÄºÚ¿ÍÔÚ°µÍø¹«¿ªÁ˲¿ÃÅÓ¡ÄṫÃñµÄÊý¾Ý£¬²¢Ðû³ÆÆäÕ¼ÓÐÒ»¸öËùÓÐ2.7ÒÚ¹«ÃñµÄÊý¾Ý¡£ºÚ¿Í¹«¿ªµÄÊý¾ÝÔ̺¬100Íò¸öÓ¡ÄṫÃñµÄÐÕÃû¡¢Éí·ÝºÅÂë¡¢¾ÓסµØÖ·ºÍµç»°ºÅÂëµÈ¡£Ä¿Ç°£¬Ó¡¶ÈÄáÎ÷ÑǵÄͨѶºÍÐÅÏ¢²¿È·ÈÏÆä²¿ÃŹ«ÃñµÄÉç±£ÐÅÏ¢ÒÑй¶£¬µ«¼á³ÆÐ¹Â¶ÐÅÏ¢µÄ¹æÄ£±ÈºÚ¿ÍÐû³ÆµÄÒªÓ׵öà¡£¸Ã¹úµ±¾Ö°µÊ¾ÒѲÉÈ¡´ëʩԤ·À±»µÁÊý¾ÝµÄÀ©É¢£¬²¢ÒÑ×ÅÊÖÓÚй¶ԴͷµÄµ÷²é¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/118148/data-breach/indonesia-social-security-data-breach.html


3.DominoÔÙ´ÎÔâµ½¹¥»÷£¬1.8ÒÚ¶©µ¥µÄÐÅÏ¢±»¹«¿ª


3.jpg


×êÑÐÈËÔ±Rajshekhar Rajaharia³ÆºÚ¿ÍÔÚ°µÍø´´½¨ÁËÒ»¸öËÑË÷ÒýÇæ£¬¹«¿ªÁËDomino's India 1.8ÒÚ¶©µ¥µÄÐÅÏ¢¡£Õâ´Î¹«¿ªµÄÐÅÏ¢Ô̺¬¿Í»§ÐÕÃû¡¢µç×ÓÓʼþ¡¢µç»°ºÅÂëºÍGPSµØÎ»µÈ¡£Jubilant¹«Ë¾Ö¤ÊµÁËÕâ´Îй©ÊÂÎñ£¬²¢°µÊ¾Ã»ÓÐÈκβÆÕþÐÅϢй¶£¬¸ÃÊÂÎñҲδ¶ÔÆäÒµÎñÔËÓªÔì³ÉÓ°Ïì¡£ÕâÊÇDominoÔÚ´ÓǰµÄÁ½¸öÔÂÄÚ²úÉúµÄµÚ¶þ´ÎÊý¾Ýй¶£¬ÔçÔÚ4Ô³õ£¬Ä³ºÚ¿Í¾ÍÇÔÈ¡ÁËDominos 13TBµÄÊý¾Ý¡£


Ô­ÎÄÁ´½Ó£º

https://www.moneycontrol.com/news/technology/dominos-india-suffers-data-breach-details-of-18-crore-orders-on-sale-6926731.html


4.Ó¢¹úOne CallϰȾDarkSide£¬±»ÀÕË÷1500ÍòÓ¢°÷


4.jpg


Ó¢¹úµÄ±£ÏÕ¹«Ë¾One CallϰȾDarkSide£¬Óʼþϵͳ¡¢ÍøÕ¾ºÍµç»°Ïß·Êܵ½Ó°Ïì¡£¾ÝϤ£¬¹¥»÷²úÉúÔÚ5ÔÂ12ÈÕÍíÉÏ»ò13ÈÕÁ賿£¬Ô±¹¤ÔڵǽϵÁ½È«±¸¹¤×÷ʱ·¢ÏÔìäÍÆËã»úÒѱ»ÀÕË÷Èí¼þϰȾ¡£Êê½ð¼Í¼ҪÇóÖ§¸¶1500ÍòÓ¢°÷£¬²»È»½«¹«¿ª¿Í»§µÄÃÜÂëºÍÒøÐÐÐÅÏ¢µÈ¡£Ö»¹Ü¹¥»÷²úÉúÔÚÒ»¸ö¶àÐÇÆÚǰ£¬µ«One CallÈÔδ°ä·¢ÓйØÉêÃ÷£¬Ö»ÊÇ֪ͨ¿Í»§ËüÓöµ½Á˼¼ÊõÎÊÌâ¡£Ö±µ½ºÚ¿Í½«Ð¹Â¶ÐÅÏ¢µÄ½ØÍ¼¹«¿ªµ½°µÍø£¬Æä¿Í»§²Å»ñϤÁËÕâ´ÎÊÂÎñ¡£


Ô­ÎÄÁ´½Ó£º

https://www.doncasterfreepress.co.uk/news/leaked-one-call-staff-messages-confirm-cyber-security-incident-as-major-crime-unit-called-in-3243731


5.CyberNews·¢ÏÖºÚ¿Í¿ÉÀûÓÃAPIÃÜÔ¿ÇÔÈ¡¼ÓÃÜÇ®±Ò


5.jpg


CyberNews×êÑÐÈËÔ±·¢ÏÖºÚ¿Í¿ÉÀûÓÃAPIÃÜÔ¿£¬ÔÚûÓб»ÊÚÓèÌá¿îµÄÇé¿öÏ´ÓÊܺ¦ÕßµÄÕË»§ÇÔÈ¡¼ÓÃÜÇ®±Ò¡£Ëæ×żÓÃÜÇ®±ÒÊг¡ÔÚ´Óǰ¼¸ÄêµÄ±¬Õ¨Ê½Ôö³¤£¬¹«Ë¾ÆðÍ·Ìṩ¸÷ÀàÀûÓ÷¨Ê½ºÍ·þÎñÀ´Ô®ÊÖÂòÂôÕß¼ò»¯ÂòÂôÁ÷³Ì¡£ÂòÂôÕß¿ÉÊÚȨµÚÈý·½ÀûÓÃͨ¹ýAPIÃÜÔ¿½Ó¼ûËûÃÇÔÚ¼ÓÃÜÇ®±ÒÂòÂôËùµÄÕË»§²¢Ö´Ðи÷Àà²Ù×÷¡£ºÚ¿ÍÄܹ»µÈÏеØÈƹýAPIÃÜÔ¿Éϵġ°½öÂòÂô¡±ÉèÖ㬴ÓÊܺ¦ÕßÕË»§ÖÐÇÔÈ¡×ʽð¡£ÕâÑù×öÉõÖÁÎÞÐè»ñµÃÖ¸±êÕË»§µÄƾ֤»òÌá¿îȨ£¬Ù²È»³ÉΪһÖÖÐÂÐ˵ķ¸×ïóÒ×ģʽ¡£


Ô­ÎÄÁ´½Ó£º

https://cybernews.com/security/report-how-cybercriminals-abuse-api-keys-to-steal-millions/


6.Unit 42°ä²¼ÓйØÀÕË÷Èí¼þ¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨


6.jpg


Unit 42°ä²¼ÁËÓйØÀÕË÷Èí¼þ¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬ÔÚ´ÓǰµÄ¼¸ÄêÖУ¬ÀÕË÷¹¥»÷»î¶¯µÄÊýÁ¿¼±¾çÉÏÉý¡£2020ÄêÖ§¸¶µÄ¾ùÔÈÊê½ð³¬¹ý31.2ÍòÃÀÔª£¬±È2019ÄêÔö³¤ÁË171£¥£¬µ½Ä¿Ç°ÎªÖ¹£¬ÕâÒ»Êý×ÖÓÖÔö³¤Á˽üÁ½±¶£¬´ïµ½85ÍòÃÀÔª¡£¶ø¶ÔÓÚ´óÐÍÆóÒµ£¬Êê½ð½ð¶î¾ùÔÈ¿¿½ü300ÍòÃÀÔª¡£È¥Äê×î¸ßµÄÊê½ð½ð¶î´Ó1500ÍòÃÀÔªÔö³¤µ½3000ÍòÃÀÔª£¬¶ø½ñÄêÔò¸ß´ï5000ÍòÃÀÔª¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/breaking-down-ransomware-attacks/