Ó¢¹ú¿ìµÝ¹«Ë¾Yodel³ÆÆäÔâµ½¹¥»÷£¬·þÎñÒÑÖжÏÊýÈÕ

°ä²¼¹¦·ò 2022-06-23
1¡¢Ó¢¹ú¿ìµÝ¹«Ë¾Yodel³ÆÆäÔâµ½¹¥»÷£¬·þÎñÒÑÖжÏÊýÈÕ


¾ÝýÌå6ÔÂ21ÈÕ±¨Â·£¬Ó¢¹úµÄ¿ìµÝ·þÎñ¹«Ë¾YodelÔâµ½ÍøÂç¹¥»÷£¬µ¼Ö°ü¹üÅÉËͺͶ©µ¥¸ú×Ù³öÏÖÑÓ³¤ ¡£Æä¿Í»§°µÊ¾£¬ÔÚÉÏÖÜÄ©¿ìµÝ·þÎñ³öÏÖÎÊÌ⣬ÆäÖв¿ÃÅÈ˳ÆËûÃÇÒѾ­ÖÁÉÙËÄÌìûÓаü¹üÐÅÏ¢ ¡£Óд«ÑÔ³ÆYodelÔâµ½ÁËÀÕË÷¹¥»÷£¬Ë¼¿¼µ½¹¥»÷Õßͨ³£²»»áÔÚ¹¤×÷ÈÕ¼ÓÃÜÖ¸±êÍÆËã»ú£¬Òò¶øÕâÒ²ÊÇÒ»¸öºÏÀíµÄ´§¶È ¡£¸Ã¹«Ë¾Ã»Óа䲼ÓйظÃÊÂÎñµÄÈκÎϸ½Ú£¬µ«°µÊ¾¿Í»§µÄÖ§¸¶ÐÅϢûÓÐÊܵ½Ó°Ïì ¡£¸Ã¹«Ë¾ÔÚ¹ÙÍøÉϰ䲼µÄ²¼¸æ×¢Ã÷£¬·þÎñÖжÏÊÇÓÉÓÚÍøÂçÊÂÎñÔì³ÉµÄ£¬²¢Í¨ÖªÓû§°ü¹ü¿ÉÄÜ»á±ÈÔ¤ÆÚ¸üÍí´ïµ½ ¡£


https://www.bleepingcomputer.com/news/security/yodel-parcel-company-confirms-cyberattack-is-disrupting-delivery/


2¡¢RIG Exploit Kit»î¶¯ÖÐRaccoon Stealer±»Dridex´úÌæ 


BitdefenderÔÚ6ÔÂ21ÈÕй©£¬RIG Exploit Kit±³ºóÔËÓªÍÅ»ïʹÓõÄRaccoon StealerÒѱ»Dridex´úÌæ ¡£½ñÄê2Ô·Ý£¬Raccoon StealerµÄÒ»ÃûÖØÒª¿ª·¢ÈËÔ±ÔÚ¶íÎÚÕ½ÕùÖÐÉíÍö£¬µ¼Ö¸ÃÏîÄ¿ÖÕ³¡ ¡£¼ì²âÊý¾ÝÏÔʾ£¬ÔÚ2ÔÂ20ÈÕ×óÓÒ·Ö·¢µÄpayloadÊýÁ¿ÓÐËù½µÂä ¡£RIG»î¶¯µÄÔËÓªÍÅ»ïѸ¿ì×ö³öÓ¦¶Ô£¬ÓÃDridex´úÌæRaccoon ¡£DridexÄܹ»ÏÂÔØ¶î±íµÄpayload¡¢ÉøÈëµ½ä¯ÀÀÆ÷ÖÐÇÔÈ¡¿Í»§ÔÚÒøÐÐÍøÕ¾ÉÏÊäÈëµÄµÇ¼ÐÅÏ¢¡¢×½ÄÃÆÁÄ»½ØÍ¼ºÍ¼Í¼¼üÅ̵È£¬ÆäÖ°ÄÜÄܹ»Í¨¹ý·ÖÆçµÄÄ£¿éÇáÒ×À©´ó ¡£


https://thehackernews.com/2022/06/rig-exploit-kit-now-infects-victims-pcs.html


3¡¢ToddyCatÍÅ»ïÕë¶ÔλÓÚÑÇÖÞºÍÅ·ÖÞµÄExchange·þÎñÆ÷


KasperskyÔÚ6ÔÂ21ÈÕ°ä²¼»ã±¨£¬Åû¶ÁËAPT×éÖ¯ToddyCatÔÚ½üÆÚµÄ¹¥»÷»î¶¯ ¡£Õâ´Î»î¶¯ÖÁÉÙ´Ó2020Äê12ÔÂÆðÍ·£¬ÖØÒªÕë¶ÔλÓÚÑÇÖÞºÍÅ·ÖÞµÄMicrosoft Exchange·þÎñÆ÷ ¡£¹¥»÷ÕßµÄÖ¸±êÊǵ±¾ÖºÍ¾üÊÂÓйØ×éÖ¯£¬µÚÒ»²¨¹¥»÷£¨2020Äê12ÔÂÖÁ2021Äê2Ô£©Õë¶ÔÔ½ÄϺÍÖйų́ÍåµÄÉÙÊý×éÖ¯£»µÚ¶þ²¨¹¥»÷£¨2021Äê2ÔÂÖÁ5Ô£©Éæ¼°µ½¶íÂÞ˹¡¢Ó¡¶È¡¢ÒÁÀʺÍÓ¢¹ú£»µÚÈý²¨¹¥»÷£¨Ö±µ½2022Äê2Ô£©ÐÂÔöÓ¡¶ÈÄáÎ÷ÑÇ¡¢ÎÚ×ȱð¿Ë˹̹ºÍ¼ª¶û¼ªË¹Ë¹Ì¹ ¡£×êÑÐÈËÔ±»¹·¢ÏÖÁ˹¥»÷ÕßʹÓõÄкóÃÅSamuraiºÍľÂíNinja Trojan£¬¶þÕß¶¼¿ÉÓÃÀ´½ÚÔìÖ¸±êϵͳ²¢ÔÚÍøÂçÖкáÏòÒÆ¶¯ ¡£  


https://securelist.com/toddycat/106799/


4¡¢¶íÂÞ˹APT28ÀÄÓÃFollina·ì϶·Ö·¢¶ñÒâÈí¼þCredoMap


6ÔÂ21ÈÕ£¬Malwarebytes°ä²¼Á˹ØÓÚ¶íÂÞ˹APT28ÐÂÒ»ÂÖ´¹µö¹¥»÷µÄ·ÖÎö»ã±¨ ¡£»î¶¯ÖØÒªÕë¶ÔÎÚ¿ËÀ¼£¬Ê¹ÓÃÁËÃûΪ¡°Nuclear Terrorism A Very Real Threat.rtf.¡±µÄ¶ñÒâÎļþ£¬ÀûÓÃÖ¸±ê¶ÔDZÔں˹¥»÷µÄÕð¾ªÓÕʹÆä´ò¿ªÎļþ ¡£¸ÃRTFÎļþÊÔIJÀûÓÃCVE-2022-30190£¨Follina£©ÔÚÖ¸±êÉ豸¸ßµÍÔØ²¢Æô¶¯CredoMap¶ñÒâÈí¼þ(docx.exe)£¬×îÖÕÖ¼ÔÚÇÔÈ¡´æ´¢ÔÚChrome¡¢EdgeºÍFirefoxä¯ÀÀÆ÷ÖеÄÐÅÏ¢£¬ÈçÕÊ»§Í´´¦ºÍcookieµÈ ¡£


https://blog.malwarebytes.com/threat-intelligence/2022/06/russias-apt28-uses-fear-of-nuclear-war-to-spread-follina-docs-in-ukraine/


5¡¢Microsoft 365·þÎñÖжÏ£¬³ÁÖ÷Óɺó¸´Ô­Õý³£


¾Ý6ÔÂ21ÈÕ±¨Â·£¬´óÁ¿µÄMicrosoft 365¿Í»§»ã±¨·þÎñÑÓ³¤¡¢µÇ¼ʧ°ÜºÍ½Ó¼ûÕÊ»§³öÏÖÎÊÌâ ¡£ÖÐ¶ÏÆðÍ·ÓÚUTC¹¦·ò6ÔÂ20ÈÕÍíÉÏ11:00£¬Óû§ÔÚ½Ó¼ûijЩM365·þÎñʱ¿ÉÄÜ»á²úÉúÑÓ³¤ºÍʧ°Ü ¡£ÔÚ³ÁÆôÊÜÓ°ÏìµÄ·þÎñÆ÷²¢³ÁÖ÷Óɺó£¬ËùÓÐÊÜÓ°ÏìµÄ²úÆ·¶¼¸´Ô­Õý³£ ¡£Ä¿Ç°£¬Æ¾¾Ý΢Èí°ä²¼µÄ×îиüУ¬Õâ´ÎÊÂÎñµÄµ××ÓÔ­ÒòÊÇ»ù´¡ÉèÊ©¶Ïµç£¬µ¼ÖÂÔÚÎ÷ŷΪÓû§Ìṩ·þÎñµÄMicrosoft 365Á÷Á¿ÖÎÀíϵͳ±ØÐë½øÐйÊÕÏ×ªÒÆ£¬µ«´Ë²Ù×÷δÄÜÕýȷʵÏÖ£¬µ¼Ö¶à¸öMicrosoft 365·þÎñµÄÑÓ³¤ºÍ½Ó¼ûʧ°Ü ¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-365-outage-affects-microsoft-teams-and-exchange-online/


6¡¢MEGA°ä²¼°²È«¸üн¨¸´¿ÉÓÃÀ´½âÃÜÓû§Êý¾ÝµÄ·ì϶


ýÌå6ÔÂ22Èճƣ¬MEGA°ä²¼ÁËÒ»¸ö°²È«¸üУ¬½¨¸´¿ÉÄÜй¶Óû§Êý¾ÝµÄÒ»×éÑϳÁµÄ·ì϶ ¡£MEGAÊÇÔÆ´æ´¢ºÍÎļþÍйܷþÎñ£¬Õ¼ÓÐ2.5ÒÚ×¢²áÓû§£¬×ܹ²ÉÏ´«ÁË1200ÒÚ¸öÎļþ£¬´óÓ׸ߴï1000 PB ¡£MEGAµÄÖ°ÄÜÖ®Ò»ÊǶÔÊý¾Ý½øÐж˵½¶Ë¼ÓÃÜ£¬Ö»ÓÐЧ»§Äܹ»½Ó¼û½âÃÜÃÜÔ¿ ¡£µ«×êÑÐÈËÔ±Åú×¢¼ÓÃÜËã·¨Öеķì϶¿ÉÓÃÀ´½Ó¼ûÓû§µÄ¼ÓÃÜÊý¾Ý£¬²¢·¢ÏÖÁË5ÖÖDZÔڵĹ¥»÷·½Ê½£ºRSAÃÜÔ¿¸´Ô­¡¢Ã÷Îĸ´Ô­¡¢¿ò¼Ü¹¥»÷¡¢ÆëÈ«ÐÔ¹¥»÷ºÍGaP Bleichenbacher¹¥»÷ ¡£MEGAÒѾ­½¨¸´ÁËǰÁ½¸öÎÊÌ⣬»º½âÁ˵ÚÈý¸öÎÊÌ⣬²¢½«ÔÚºóÐø¸üÐÂÖн¨¸´Ôü×ÒµÄÁ½¸öÎÊÌâ ¡£


https://www.bleepingcomputer.com/news/security/mega-fixes-critical-flaws-that-allowed-the-decryption-of-user-data/