CiscoÔâµ½YanluowangÍÅ»ïµÄ¹¥»÷ÇÒ2.8 GBÊý¾Ýй¶

°ä²¼¹¦·ò 2022-08-11
1¡¢CiscoÔâµ½YanluowangÍÅ»ïµÄ¹¥»÷ÇÒ2.8 GBÊý¾Ýй¶

      

¾ÝýÌå8ÔÂ10ÈÕ±¨Â·£¬ºÚ¿ÍÍÅ»ïYanluowangÔÚ½ñÄê5ÔÂÏÂÑ®ÈëÇÖÁËCisco¹«Ë¾µÄÍøÂç²¢ÇÔÈ¡ÁËÄÚ²¿Êý¾Ý ¡£Ciscoй©£¬¹¥»÷ÕßÖ»ÄÜ´ÓÓ뱻ϰȾԱ¹¤ÕÊ»§ÓйØÁªµÄBoxÎļþ¼ÐÖÐÇÔÈ¡Êý¾Ý£¬²¢Î´¶ÔÆäÒµÎñÔì³ÉÈκÎÓ°Ïì ¡£µ÷²éÏÔʾ£¬¹¥»÷ÕßÔÚ½Ù³ÖÔ±¹¤µÄÓ×ÎÒGoogleÕÊ»§ºó£¬Ê¹Óñ»µÁÍ´´¦»ñµÃÁ˶Ô˼¿ÆÍøÂçµÄ½Ó¼ûȨÏÞ ¡£¹¥»÷ÕßÐû³ÆÇÔÈ¡ÁË2.75 GBÊý¾Ý£¬ÆäÖÐÔ̺¬Ô¼3100¸öÎļþ£¬Éæ¼°±£ÃܺÍ̸¡¢Êý¾Ýת´¢ºÍ¹¤³ÌͼֽµÈ ¡£Cisco»¹°µÊ¾£¬ËüÔÚ¹¥»÷¹ý³ÌÖÐûÓз¢ÏÖÀÕË÷Èí¼þµÄpayload ¡£


https://www.bleepingcomputer.com/news/security/cisco-hacked-by-yanluowang-ransomware-gang-28gb-allegedly-stolen/


2¡¢PyPI´æ´¢¿âÖеÄ10¸ö¶ñÒâPython°ü¿ÉÇÔÈ¡¿ª·¢ÈËԱʹ´¦

      

¾Ý8ÔÂ9ÈÕ±¨Â·£¬Check Point×êÑÐÈËÔ±ÔÚPyPI´æ´¢¿âÖз¢ÏÖÁË10¸ö¶ñÒâPython°ü ¡£ÕâЩ¶ñÒâ°üʹÓÃαÔìµÄÓòÃûÀ´¼ÙÒâÊ¢ÐеÄÏîÄ¿²¢ÓÕʹָ±êÏÂÔØËüÃÇ£¬¶øºó×°ÖÃÐÅÏ¢ÇÔÈ¡·¨Ê½£¬Ö¼ÔÚÇÔÈ¡¿ª·¢ÈËÔ±µÄÓ×ÎÒÊý¾ÝºÍÍ´´¦ ¡£¶ñÒâPyPi°ü±ðÀëΪAscii2text¡¢Pyg-utils¡¢Pymocks¡¢PyProto2¡¢Test-async¡¢Free-net-vpn¡¢Free-net-vpn2¡¢Zlibsrc¡¢BrowserdivºÍWINRPCexploit ¡£Ö»¹ÜÈí¼þ°üÒÑ´ÓPyPIÖÐɾ³ý£¬µ«ÒÑÏÂÔØËüÃǵĿª·¢ÈËÔ±ÈÔÃæ¶Ô·çÏÕ ¡£


https://thehackernews.com/2022/08/10-credential-stealing-python-libraries.html


3¡¢LockBitÍŻ﹥»÷°¢¸ùÍ¢ÎÀÉú·þÎñÍøÕ¾²¢ÀÕË÷30ÍòÃÀÔª

      

ýÌå8ÔÂ9Èճƣ¬LockBitÍŻ﹥»÷Á˰¢¸ùÍ¢µÄOSDE ¡£OSDEÊǰ¢¸ùÍ¢µÄÒ½ÁÆ·þÎñºÍ¹©¸øÉÌÍøÂ磬ĿǰռÓг¬¹ý200Íò»áÔ±¡¢8000¶à¼ÒÒ©µêºÍ½ü400¸öÖÐÐÄ ¡£¾ÝϤ£¬Õâ´Î¹¥»÷µ¼ÖÂOSDEÔÚ¼¸¸öÓ×ʱÄÚÎÞ·¨Ê¹Óà ¡£OSDEÔÚ6ÔÂ27ÈÕÈÏ¿ÉÁËÕâ´Î¹¥»÷£¬µ«Ã»ÓÐÈ·ÈÏÕâÊÇһ·ÀÕË÷¹¥»÷ÊÂÎñ ¡£7ÔÂ22ÈÕ£¬LockBit½«OSDEÔö³¤µ½ÆäÊý¾ÝÐ¹Â¶ÍøÕ¾£¬²¢ÀÕË÷300000ÃÀÔªÀ´²É°ì»òɾ³ýËùÓб»µÁÊý¾Ý£¬½ØÖ¹ÈÕÆÚΪ8ÔÂ6ÈÕ ¡£8ÔÂ8ÈÕ£¬LockBit»Ø¸´ÁËDataBreachesµÄѯÎÊ£¬³ÆÆäÇÔÈ¡ÁË139.07 GBÎļþ ¡£


https://www.databreaches.net/argentinian-health-services-plan-hit-by-lockbit/


4¡¢CybleÅû¶ÀûÓÃľÂí»¯Signal·Ö·¢DracarysµÄ»î¶¯ÏêÇé

      

CybleÔÚ8ÔÂ9ÈÕÅû¶ÁËBitter APTÀûÓÃľÂí»¯Signal·Ö·¢Android¼äµýÈí¼þDracarysµÄ»î¶¯ ¡£¸Ã»î¶¯ÖØÒªÕë¶ÔÐÂÎ÷À¼¡¢Ó¡¶È¡¢°Í»ù˹̹ºÍÓ¢¹ú£¬Ê¹ÓÃÁËÓòÃûsignalpremium[.]comÀ´·Ö·¢Ä¾Âí»¯µÄÀûÓà ¡£ÓÉÓÚSignalµÄÔ´´úÂëÊÇ¿ªÔ´µÄ£¬Òò¶ø¹¥»÷ÕßÄܹ»±àÒë³öÓµÓг£ÓøöÐÔºÍÔ¤ÆÚÖ°Äܵİ汾£¬»¹ÔÚ±àÒëʱ½«DracarysÔö³¤µ½ÁËÔ´´úÂëÖÐ ¡£Æô¶¯Ê±£¬Dracarys½«Ïνӵ½Firebase·þÎñÆ÷À´½Ó¹ÜºÅÁ¶øºó½«ÇÔÈ¡µÄÊý¾ÝÉÏ´«µ½C2 ¡£


https://www.bleepingcomputer.com/news/security/hackers-install-dracarys-android-malware-using-modified-signal-app/


5¡¢UnRARÖÐõè¾¶±éÀú·ì϶CVE-2022-30333Òѱ»»ý¼«ÀûÓÃ

      

ýÌå8ÔÂ9ÈÕ±¨Â·³Æ£¬LinuxºÍUnixϵͳµÄUnRARÖеÄõè¾¶±éÀú·ì϶£¨CVE-2022-30333£©¿ÉÄÜÒѱ»ÔÚÒ°ÀûÓà ¡£¸Ã·ì϶ÓÚ6ÔÂÏÂÑ®±»Åû¶£¬¹¥»÷ÕßÄܹ»ÀûÓÃËüÔÚ½âѹ²Ù×÷ÆÚ¼ä½«¶ñÒâÎļþÌáÈ¡µ½ËÁÒâµØÎ»£¬´Ó¶øÔÚÖ¸±êϵͳÉÏ×°ÖöñÒâÎļþ£¬CISAÔÚ±¾Öܶþ½«ÆäÔö³¤µ½ÆäÒѱ»ÀûÓ÷ì϶Ŀ¼ÖÐ ¡£¹ØÓÚ¹¥»÷µÄÐÔÖÊÖªÖ®ÉõÉÙ£¬µ«Õâ´ÎÅû¶֤ÁËȻһÖÖÈÕÒæÔö³¤µÄÇ÷Ïò£¬¼´¹¥»÷ÕßÔÚ·ì϶±»¹«¿ªºóѸ¿ìɨÃèÒ×Êܹ¥»÷µÄϵͳ£¬²¢½è´Ë»úÓöÌáÒé¹¥»÷ ¡£


https://thehackernews.com/2022/08/cisa-issues-warning-on-active.html


6¡¢Kaspersky³ÆÀÕË÷Èí¼þMauiÓ볯ÏÊÍÅ»ïAndarielÓйØ

      

8ÔÂ9ÈÕ£¬Kaspersky°ä²¼Á˹ØÓÚAndariel·Ö·¢DTrackºÍMauiÀÕË÷Èí¼þµÄ·ÖÎö»ã±¨ ¡£Andariel£¨±ðÃûStonefly£©ÖÁÉÙ´Ó2015ÄêÆðÍ·»îÔ¾£¬¶øMauiÓÚ2021Äê4ÔÂÆðÍ·»îÔ¾ ¡£»ã±¨Ö¸³ö£¬ÈÕ±¾Ôâµ½Maui¹¥»÷µÄÖ¸±êÔÚ±»¼ÓÃÜǰ¼¸¸öÓ±¾Ç®ÍÔâµ½ÁËDTrackµÄ¹¥»÷£¬¶øËæºóµÄÈÕÖ¾·ÖÎöÏÔʾ£¬¼¸¸öÔÂǰ¸Ã¹«Ë¾µÄÍøÂçÖоʹæÔÚ3Proxy ¡£3ProxyÊÇAndariel´ÓǰµÄ»î¶¯ÖÐʹÓõÄÃâ·Ñ¿ªÔ´´úÀí·þÎñÆ÷·¨Ê½£¬¶ø¹¥»÷ʹÓõÄDTrack±äÌåÓëAndarielÓйصÄÑù±¾ÓµÓÐ84%µÄ´úÂëÀàËÆÐÔ ¡£´Ë±í£¬×êÑÐÈËÔ±·¢ÏÖÕâЩ¹¥»÷ÖгõÊ¼ÍøÂç¹¥»÷²½Ö軹ӵÓеäÐ͵ÄAndarielÌØµã ¡£


https://securelist.com/andariel-deploys-dtrack-and-maui-ransomware/107063/