CiscoÔâµ½YanluowangÍÅ»ïµÄ¹¥»÷ÇÒ2.8 GBÊý¾Ýй¶
°ä²¼¹¦·ò 2022-08-11
¾ÝýÌå8ÔÂ10ÈÕ±¨Â·£¬ºÚ¿ÍÍÅ»ïYanluowangÔÚ½ñÄê5ÔÂÏÂÑ®ÈëÇÖÁËCisco¹«Ë¾µÄÍøÂç²¢ÇÔÈ¡ÁËÄÚ²¿Êý¾Ý¡£Ciscoй©£¬¹¥»÷ÕßÖ»ÄÜ´ÓÓ뱻ϰȾԱ¹¤ÕÊ»§ÓйØÁªµÄBoxÎļþ¼ÐÖÐÇÔÈ¡Êý¾Ý£¬²¢Î´¶ÔÆäÒµÎñÔì³ÉÈκÎÓ°Ïì¡£µ÷²éÏÔʾ£¬¹¥»÷ÕßÔÚ½Ù³ÖÔ±¹¤µÄÓ×ÎÒGoogleÕÊ»§ºó£¬Ê¹Óñ»µÁÍ´´¦»ñµÃÁ˶Ô˼¿ÆÍøÂçµÄ½Ó¼ûȨÏÞ¡£¹¥»÷ÕßÐû³ÆÇÔÈ¡ÁË2.75 GBÊý¾Ý£¬ÆäÖÐÔ̺¬Ô¼3100¸öÎļþ£¬Éæ¼°±£ÃܺÍ̸¡¢Êý¾Ýת´¢ºÍ¹¤³ÌͼֽµÈ¡£Cisco»¹°µÊ¾£¬ËüÔÚ¹¥»÷¹ý³ÌÖÐûÓз¢ÏÖÀÕË÷Èí¼þµÄpayload¡£
https://www.bleepingcomputer.com/news/security/cisco-hacked-by-yanluowang-ransomware-gang-28gb-allegedly-stolen/
2¡¢PyPI´æ´¢¿âÖеÄ10¸ö¶ñÒâPython°ü¿ÉÇÔÈ¡¿ª·¢ÈËԱʹ´¦
¾Ý8ÔÂ9ÈÕ±¨Â·£¬Check Point×êÑÐÈËÔ±ÔÚPyPI´æ´¢¿âÖз¢ÏÖÁË10¸ö¶ñÒâPython°ü¡£ÕâЩ¶ñÒâ°üʹÓÃαÔìµÄÓòÃûÀ´¼ÙÒâÊ¢ÐеÄÏîÄ¿²¢ÓÕʹָ±êÏÂÔØËüÃÇ£¬¶øºó×°ÖÃÐÅÏ¢ÇÔÈ¡·¨Ê½£¬Ö¼ÔÚÇÔÈ¡¿ª·¢ÈËÔ±µÄÓ×ÎÒÊý¾ÝºÍÍ´´¦¡£¶ñÒâPyPi°ü±ðÀëΪAscii2text¡¢Pyg-utils¡¢Pymocks¡¢PyProto2¡¢Test-async¡¢Free-net-vpn¡¢Free-net-vpn2¡¢Zlibsrc¡¢BrowserdivºÍWINRPCexploit¡£Ö»¹ÜÈí¼þ°üÒÑ´ÓPyPIÖÐɾ³ý£¬µ«ÒÑÏÂÔØËüÃǵĿª·¢ÈËÔ±ÈÔÃæ¶Ô·çÏÕ¡£
https://thehackernews.com/2022/08/10-credential-stealing-python-libraries.html
3¡¢LockBitÍŻ﹥»÷°¢¸ùÍ¢ÎÀÉú·þÎñÍøÕ¾²¢ÀÕË÷30ÍòÃÀÔª
ýÌå8ÔÂ9Èճƣ¬LockBitÍŻ﹥»÷Á˰¢¸ùÍ¢µÄOSDE¡£OSDEÊǰ¢¸ùÍ¢µÄÒ½ÁÆ·þÎñºÍ¹©¸øÉÌÍøÂ磬ĿǰռÓг¬¹ý200Íò»áÔ±¡¢8000¶à¼ÒÒ©µêºÍ½ü400¸öÖÐÐÄ¡£¾ÝϤ£¬Õâ´Î¹¥»÷µ¼ÖÂOSDEÔÚ¼¸¸öÓ×ʱÄÚÎÞ·¨Ê¹Óá£OSDEÔÚ6ÔÂ27ÈÕÈÏ¿ÉÁËÕâ´Î¹¥»÷£¬µ«Ã»ÓÐÈ·ÈÏÕâÊÇһ·ÀÕË÷¹¥»÷ÊÂÎñ¡£7ÔÂ22ÈÕ£¬LockBit½«OSDEÔö³¤µ½ÆäÊý¾ÝÐ¹Â¶ÍøÕ¾£¬²¢ÀÕË÷300000ÃÀÔªÀ´²É°ì»òɾ³ýËùÓб»µÁÊý¾Ý£¬½ØÖ¹ÈÕÆÚΪ8ÔÂ6ÈÕ¡£8ÔÂ8ÈÕ£¬LockBit»Ø¸´ÁËDataBreachesµÄѯÎÊ£¬³ÆÆäÇÔÈ¡ÁË139.07 GBÎļþ¡£
https://www.databreaches.net/argentinian-health-services-plan-hit-by-lockbit/
4¡¢CybleÅû¶ÀûÓÃľÂí»¯Signal·Ö·¢DracarysµÄ»î¶¯ÏêÇé
CybleÔÚ8ÔÂ9ÈÕÅû¶ÁËBitter APTÀûÓÃľÂí»¯Signal·Ö·¢Android¼äµýÈí¼þDracarysµÄ»î¶¯¡£¸Ã»î¶¯ÖØÒªÕë¶ÔÐÂÎ÷À¼¡¢Ó¡¶È¡¢°Í»ù˹̹ºÍÓ¢¹ú£¬Ê¹ÓÃÁËÓòÃûsignalpremium[.]comÀ´·Ö·¢Ä¾Âí»¯µÄÀûÓá£ÓÉÓÚSignalµÄÔ´´úÂëÊÇ¿ªÔ´µÄ£¬Òò¶ø¹¥»÷ÕßÄܹ»±àÒë³öÓµÓг£ÓøöÐÔºÍÔ¤ÆÚÖ°Äܵİ汾£¬»¹ÔÚ±àÒëʱ½«DracarysÔö³¤µ½ÁËÔ´´úÂëÖС£Æô¶¯Ê±£¬Dracarys½«Ïνӵ½Firebase·þÎñÆ÷À´½Ó¹ÜºÅÁ¶øºó½«ÇÔÈ¡µÄÊý¾ÝÉÏ´«µ½C2¡£
https://www.bleepingcomputer.com/news/security/hackers-install-dracarys-android-malware-using-modified-signal-app/
5¡¢UnRARÖÐõè¾¶±éÀú·ì϶CVE-2022-30333Òѱ»»ý¼«ÀûÓÃ
ýÌå8ÔÂ9ÈÕ±¨Â·³Æ£¬LinuxºÍUnixϵͳµÄUnRARÖеÄõè¾¶±éÀú·ì϶£¨CVE-2022-30333£©¿ÉÄÜÒѱ»ÔÚÒ°ÀûÓ᣸÷ì϶ÓÚ6ÔÂÏÂÑ®±»Åû¶£¬¹¥»÷ÕßÄܹ»ÀûÓÃËüÔÚ½âѹ²Ù×÷ÆÚ¼ä½«¶ñÒâÎļþÌáÈ¡µ½ËÁÒâµØÎ»£¬´Ó¶øÔÚÖ¸±êϵͳÉÏ×°ÖöñÒâÎļþ£¬CISAÔÚ±¾Öܶþ½«ÆäÔö³¤µ½ÆäÒѱ»ÀûÓ÷ì϶Ŀ¼ÖС£¹ØÓÚ¹¥»÷µÄÐÔÖÊÖªÖ®ÉõÉÙ£¬µ«Õâ´ÎÅû¶֤ÁËȻһÖÖÈÕÒæÔö³¤µÄÇ÷Ïò£¬¼´¹¥»÷ÕßÔÚ·ì϶±»¹«¿ªºóѸ¿ìɨÃèÒ×Êܹ¥»÷µÄϵͳ£¬²¢½è´Ë»úÓöÌáÒé¹¥»÷¡£
https://thehackernews.com/2022/08/cisa-issues-warning-on-active.html
6¡¢Kaspersky³ÆÀÕË÷Èí¼þMauiÓ볯ÏÊÍÅ»ïAndarielÓйØ
8ÔÂ9ÈÕ£¬Kaspersky°ä²¼Á˹ØÓÚAndariel·Ö·¢DTrackºÍMauiÀÕË÷Èí¼þµÄ·ÖÎö»ã±¨¡£Andariel£¨±ðÃûStonefly£©ÖÁÉÙ´Ó2015ÄêÆðÍ·»îÔ¾£¬¶øMauiÓÚ2021Äê4ÔÂÆðÍ·»îÔ¾¡£»ã±¨Ö¸³ö£¬ÈÕ±¾Ôâµ½Maui¹¥»÷µÄÖ¸±êÔÚ±»¼ÓÃÜǰ¼¸¸öÓ±¾Ç®ÍÔâµ½ÁËDTrackµÄ¹¥»÷£¬¶øËæºóµÄÈÕÖ¾·ÖÎöÏÔʾ£¬¼¸¸öÔÂǰ¸Ã¹«Ë¾µÄÍøÂçÖоʹæÔÚ3Proxy¡£3ProxyÊÇAndariel´ÓǰµÄ»î¶¯ÖÐʹÓõÄÃâ·Ñ¿ªÔ´´úÀí·þÎñÆ÷·¨Ê½£¬¶ø¹¥»÷ʹÓõÄDTrack±äÌåÓëAndarielÓйصÄÑù±¾ÓµÓÐ84%µÄ´úÂëÀàËÆÐÔ¡£´Ë±í£¬×êÑÐÈËÔ±·¢ÏÖÕâЩ¹¥»÷ÖгõÊ¼ÍøÂç¹¥»÷²½Ö軹ӵÓеäÐ͵ÄAndarielÌØµã¡£
https://securelist.com/andariel-deploys-dtrack-and-maui-ransomware/107063/


¾©¹«Íø°²±¸11010802024551ºÅ