΢Èí°ä²¼8Ô·ÝÖܶþ²¹¶¡£¬×ܼƽ¨¸´121¸ö°²È«·ì϶
°ä²¼¹¦·ò 2022-08-10
8ÔÂ9ÈÕ£¬ ΢Èí°ä²¼Á˱¾ÔµÄÖܶþ²¹¶¡£¬×ܼƽ¨¸´ÁË121¸ö·ì϶¡£Õâ´Î¸üн¨¸´ÁËÁ½¸ö0 day£¬±ðÀëΪMicrosoft WindowsÖ§³ÖÕï¶Ï¹¤¾ß(MSDT)ÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶¡°DogWalk¡±£¨CVE-2022-34713£©ºÍMicrosoft ExchangeÖеÄÐÅϢй¶·ì϶£¨CVE-2022-30134£©£¬ÆäÖÐDogWalkÒÑÔÚ¹¥»÷Öб»»ý¼«ÀûÓá£´Ë±í£¬»¹½¨¸´ÁËActive DirectoryÓò·þÎñÌáȨ·ì϶£¨CVE-2022-34691£©ºÍWindows Hyper-VÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2022-34696£©µÈ½ÏΪÑϳÁµÄ·ì϶¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-august-2022-patch-tuesday-fixes-exploited-zero-day-121-flaws/
2¡¢µ¤Âó7-11µÄÖ§¸¶ÏµÍ³Ôâµ½¹¥»÷£¬È«¹úÃŵêÁÙʱ¹Ø¹Ø
¾ÝýÌå8ÔÂ8ÈÕ±¨Â·£¬µ¤Âó7-11µÄÖ§¸¶ÏµÍ³Ôâµ½¹¥»÷ºó£¬È«¹úÁìÓòÄÚµÄËùÓÐÃŵêÁÙʱ¹Ø¹Ø¡£¹¥»÷²úÉúÔÚ8ÔÂ8ÈÕÔçÉÏ£¬¸Ã¹«Ë¾ÔÚFacebookÉÏ·¢Ìû³ÆËûÃÇ¿ÉÄÜÔâµ½Á˺ڿ͹¥»÷£¬Ö§¸¶ºÍ½áÕËϵͳÎÞ·¨Ê¹Óá£7-11Ô±¹¤ÔÚRedditÉÏй©³Æ£¬ÓÉÓÚÈ«¹úµÄ7-11¶¼Ê¹ÓÃÁËÒ»ÑùµÄϵͳ£¬ËùÒÔµ¤ÂóËùÓÐ7-11Ãŵê´Ë¿Ì¶¼Òѹعء£Ä¿Ç°£¬»¹Ã»ÓйØÓÚÕâ´Î¹¥»÷µÄ½øÒ»²½Ï¸½Ú£¬ÀýÈç¹¥»÷ÊÇ·ñÉæ¼°ÀÕË÷Èí¼þ¡£
https://www.bleepingcomputer.com/news/security/7-eleven-stores-in-denmark-closed-due-to-a-cyberattack/
3¡¢Twilioй©ÆäÔ±¹¤Ôâµ½´¹µö¹¥»÷£¬µ¼Ö¿ͻ§Êý¾Ýй¶
ýÌå8ÔÂ8Èճƣ¬ÔÆÍ¨Ñ¶¹«Ë¾Twilio²¿Ãſͻ§µÄÊý¾ÝÒѾй¶¡£Twilio°µÊ¾£¬ËûÃÇÔÚ8ÔÂ4ÈÕ·¢ÏÔìäÔ±¹¤Ôâµ½Á˸´ÔӵĴ¹µö¹¥»÷ºóÍ´´¦Ð¹Â¶£¬¶øºó¹¥»÷ÕßÀûÓÃÇÔÈ¡µÄÍ´´¦½Ó¼ûÁ˹«Ë¾µÄÄÚ²¿ÏµÍ³£¬ÒÔ¼°²¿Ãſͻ§µÄÊý¾Ý¡£¹¥»÷Õß¼ÙÒâTwilioµÄIT²¿ÃÅ£¬ÒªÇóÖ¸±êµã»÷Ô̺¬Twilio¡¢OktaºÍSSO¹Ø¼ü×ÖµÄURL£¬²¢½«ËûÃdzÁ¶¨Ïòµ½Î±ÔìµÄTwilioµÇÂ¼Ò³Ãæ¡£TwilioÒѳ·ÏúÁ˹¥»÷ÆÚ¼ä±»µÁµÄÔ±¹¤ÕË»§£¬µ«ÉÐδȷ¶¨¹¥»÷ÕßÉí·Ý£¬Ä¿Ç°ÔÚÓë·¨Âɲ¿ÃźÏ×÷¶Ô´ËÊ·¢Õ¹µ÷²é¡£
https://securityaffairs.co/wordpress/134147/data-breach/twilio-discloses-data-breach.html
4¡¢Ð½©Ê¬ÍøÂçOrchardÀûÓÃÖб¾´ÏµÄÕË»§ÐÅÏ¢À´ÌìÉúDGAÓò
¾Ý8ÔÂ8ÈÕ±¨Â·£¬×êÑÐÍŶӷ¢ÏÖÁËÒ»¸öÃûΪOrchardµÄн©Ê¬ÍøÂ磬ʹÓñÈÌØ±Ò´´½¨ÕßSatoshi NakamotoµÄÕË»§ÂòÂôÐÅÏ¢ÌìÉúDGAÓòÀ´°µ²ØÆäC2»ù´¡ÉèÊ©¡£×Ô2021Äê2ÔÂÒÔÀ´£¬Orchard¾ÀúÁËÈý´Î¸üС£¸Ã½©Ê¬ÍøÂçѡȡÁËÓ²±àÂëÓò+DGAµÄÈßÓàC2»úÔ죬×êÑÐÈËÔ±·¢ÏÖÿ¸ö°æ±¾¶¼Ô̺¬Ò»¸öΨһµÄÓ²±àÂëDuckDNS¶¯Ì¬ÓòÃû×÷ΪC2¡£ËüµÄÈý¸ö°æ±¾¸ù»ùÖ§³ÖÒ»ÑùµÄÖ°ÄÜ£¬Ô̺¬ÉÏ´«É豸ºÍÓû§ÐÅÏ¢¡¢Ï챨ºÅÁî»òÏÂÔØÖ´ÐÐÄ£¿éµÄÏÂÒ»¸ö½×¶ÎÒÔ¼°Ï°È¾USB´æ´¢É豸¡£
https://thehackernews.com/2022/08/new-orchard-botnet-uses-bitcoin.html
5¡¢KasperskyÅû¶TA428Õë¶Ô¾ü¹¤ÆóÒµºÍµ±¾Ö»ú¹¹µÄ¹¥»÷
¾ÝKaspersky 8ÔÂ8ÈÕ±¨Â·£¬ÆäÔÚ1Ô·ݼì²âµ½Ò»²¨Õë¶Ô¶«Å·¶à¸ö¹ú¶ÈµÄ¾ü¹¤ÆóÒµºÍ¹«¹²»ú¹¹µÄ¶¨Ïò¹¥»÷¡£¹¥»÷ÕßÒѳɹ¦ÈëÇÖÁËÊýÊ®¸öÖ¸±ê£¬ÖØÒªÎª°×¶íÂÞ˹¡¢¶íÂÞ˹ÎÚ¿ËÀ¼ºÍ°¢¸»º¹µÈ¹ú¶ÈµÄ¹¤Òµ¹¤³§¡¢Éè¼Æ¾Ö¡¢×êÑлú¹¹ºÍµ±¾Ö»ú¹¹µÈ¡£¹¥»÷»î¶¯ÀûÓÃÁËMicrosoft Office·ì϶£¨CVE-2017-11882£©À´×°ÖöñÒâÈí¼þPortDoor£¬²¢ÔÚ½ÓÏÂÀ´µÄ¹¥»÷½×¶Î×°ÖÃÁË5¸ö¶î±íµÄºóÃÅnccTrojan¡¢Logtu¡¢Cotx¡¢DNSepºÍCotSam£¬Ö¼ÔÚÇÔȡϵͳÐÅÏ¢ºÍÎļþ¡£×êÑз¢ÏÖ£¬¸Ã»î¶¯ÓëAPT TA428»î¶¯µÄTTP´æÔÚÏÔÖø³Áµþ¡£
https://securelist.com/targeted-attack-on-industrial-enterprises-and-public-institutions/107054/
6¡¢Group-IB°ä²¼¹ØÓÚڿƻClassiscamµÄ·ÖÎö»ã±¨
8ÔÂ8ÈÕ£¬Group-IB°ä²¼Á˹ØÓÚڿƻClassiscamµÄ·ÖÎö»ã±¨¡£ClassiscamÊÇÒ»ÖÖ¸´ÔÓµÄڿƼ´·þÎñÒµÎñ£¨scam-as-a-service£©£¬ÒÑÓÚ2022Äê3ÔÂÉøÈëµ½ÐÂ¼ÓÆÂ¡£¸Ã»î¶¯×î³õÓÚ2020Äê±»·¢ÏÖ£¬¹¥»÷Õß¼ÙÒâºÏ·¨Âò¼Ò¿¿½üÂô¼Ò£¬ÒªÇó´ÓËûÃǵÄÇåµ¥ÖвɰìÉÌÆ·£¬À´ÇÔȡ֧¸¶Êý¾Ý¡£¸ÃڿƻÒѾ±é¼°Å·ÖÞ¡¢CISºÍÖж«µÄ64¸ö¹ú¶È£¬2020Äê4Ôµ½2022Äê2ÔÂÒÑΪ¹¥»÷ÕßIJÀûÖÁÉÙ2950ÍòÃÀÔª¡£
https://www.group-ib.com/media/classiscam-singapore-global-scam-operation/


¾©¹«Íø°²±¸11010802024551ºÅ