AzureÓû§ÔËÐÐUbuntu 18.04µÄVMÒòsystemd¸üÐÂÃýÎóÖжÏ
°ä²¼¹¦·ò 2022-08-31
¾ÝýÌå8ÔÂ30ÈÕ±¨Â·£¬Î¢ÈíAzureÓû§µÄÔËÐÐUbuntu 18.04µÄÐé¹¹»ú£¨VM£©Òòsystemd¸üз¸´íµ¼Ö³ÖÐøÖжϡ£ÖÐ¶ÏÆðÍ·ÓÚ8ÔÂ30ÈÕ06:00 UTC×óÓÒ£¬ÊÜÓ°ÏìµÄÓû§Éý¼¶µ½systemd°æ±¾237-3ubuntu10.54ºó£¬Ðé¹¹»úÆðÍ·³öÏÖDNSÃýÎó£¬ÇÒûÓпÉÓõÄDNS½âÎöÆ÷µØÖ·¡£ÊÜÆäÖжÏÓ°ÏìµÄ·þÎñÔ̺¬Azure Kubernetes Service(AKS)¡¢Azure Monitor¡¢Azure SentinelºÍAzure Container AppsµÈ¡£Î¢ÈíΪÊÜÓ°ÏìµÄAzureÓû§ÌṩÁËÒ»¸ö¶î±íµÄ½â¾ö²½Ö裬Ô̺¬³ÁÐÂÆô¶¯ÊÜÓ°ÏìµÄUbuntuÐé¹¹»ú¡£
https://www.bleepingcomputer.com/news/microsoft/microsoft-azure-outage-knocks-ubuntu-vms-offline-after-buggy-update/
2¡¢FTC¸æ×´KochavaÍøÂç²¢ÏúÊÛÊýÒÚ²¿ÊÖ»úµÄµØÎ»Êý¾Ý
ýÌå8ÔÂ30Èճƣ¬ÃÀ¹úÁª¹úÒµÎñίԱ»á(FTC)¶ÔÊý¾ÝÖÐÑëÉÌKochavaÌá¸æ×´ËÏ£¬Ö¸¿ØÆäÍøÂçºÍÏúÊÛ´ÓÏû·ÑÕßµÄÒÆ¶¯Éè±¸ÍøÂçµÄµØÀíµØÎ»Êý¾Ý¡£ÍøÂçµÄÊý¾Ý»áÒÔ¶©ÔĵĴó¾ÖÌṩ¸øÓû§£¬Óû§Äܹ»Í¨¹ýÔÚÏßÊý¾ÝÊг¡½Ó¼û£¬¶©ÔÄÓöÈΪ25000ÃÀÔª¡£FTC°µÊ¾£¬KochavaÌṩµÄÊý¾Ý¿ÉʹÓ×ÎÒÃæ¶ÔÐ߳ܡ¢¸ú×Ù¡¢ÆçÊÓ¡¢Ê§ÒµÉõÖÁÉí¶Î±©Á¦µÄÍþв¡£Òò¶ø£¬FTCµÄËßËÏÖ¼ÔÚ×èÖ¹KochavaÏúÊÛµØÀíµØÎ»Êý¾Ý£¬²¢ÒªÇóɾ³ýÆäÒÑ¾ÍøÂçµÄÊý¾Ý¡£
https://thehackernews.com/2022/08/ftc-sues-data-broker-over-selling.html
3¡¢Baker&TaylorÔÚÔâµ½ÀÕË÷¹¥»÷ºóÖÂÁ¦¸´ÔÊÜÓ°Ïìϵͳ
¾Ý8ÔÂ29ÈÕ±¨Â·£¬×Ô³ÆÊÇÈ«Çò×î´óµÄͼÊé¹ÝͼÊé·ÖÏúÉ̵ÄBaker&TaylorÔâµ½ÀÕË÷¹¥»÷¡£¸Ã¹«Ë¾8ÔÂ23ÈÕй©£¬ÔÚÒ»´ÎÓ°Ï칫˾µç»°ÏµÍ³¡¢°ì¹«ÊҺͷþÎñÖÐÐĵĹÊÕÏºó£¬Æä·þÎñÆ÷Öжϡ£Ö®ºó£¬¸Ã¹«Ë¾È·¶¨ÖжÏÔ´ÓÚÖÜÄ©Ôâµ½µÄÀÕË÷¹¥»÷£¬²¢°µÊ¾ËûÃǻᾡ¿ì¸´ÔÔËÓª¡£Ä¿Ç°£¬Ã»ÓйØÓÚÕâ´Î¹¥»÷±³ºóµÄÀÕË÷ÍÅ»ïµÄÐÅÏ¢£¬µ«¸Ã¹«Ë¾³ÆÆäÈÔÔÚÖÂÁ¦¸´ÔÊÜÓ°ÏìµÄ·þÎñÆ÷£¬ÇÒÃ÷È·°µÊ¾²»»á¸¶Êê½ð¡£
https://therecord.media/major-u-s-library-service-confirms-ransomware-attack-struggling-to-restore-affected-systems/
4¡¢Nelnet Servicing±»ÈëÇÖºóй¶250Íò¸öѧÉúµÄ´û¿îÐÅÏ¢
¾ÝýÌå8ÔÂ29Èճƣ¬ÔÚºÚ¿ÍÈëÇÖ¼¼Êõ·þÎñÌṩÉÌNelnet ServicingµÄϵͳºó£¬¶í¿ËÀºÉÂíÖÝѧÉú´û¿îÖÎÀí¾Ö(OSLA)ºÍEdFinancialµÄѧÉú´û¿îÊý¾Ýй¶¡£OSLAºÍEdFinancialʹÓÃNelnet ServicingµÄ¼¼Êõ·þÎñÓÃÓÚÔÚÏß´û¿îµÄѧÉú½Ó¼ûÆä´û¿îÕË»§¡£¹¥»÷ÕßÔÚ6Ô·ÝÈëÇÖÁËNelnet Servicing£¬²¢Ò»Ïò´æÔÚµ½7ÔÂ22ÈÕ¡£¾ÝϤ£¬¹¥»÷Õß¿ÉÄÜÊÇÀûÓ÷ì϶ÈëÇÖÁ˹«Ë¾µÄÍøÂ磬Լ2501324ÈËÊܵ½Ó°Ï졣Ŀǰ£¬EdFinancialºÍOSLA¶¼Í¨¹ýExperianΪÊÜÓ°ÏìµÄÓû§Ãâ·ÑÌṩ24¸öÔµÄÉí·Ý͵ÇÔ±£»¤·þÎñ¡£
https://www.bleepingcomputer.com/news/security/nelnet-servicing-breach-exposes-data-of-25m-student-loan-accounts/
5¡¢CheckPoint¼ì²âµ½¼Ù×°³É¹È¸è·ÒëµÅצÓõÄÍÚ¿ó¶ñÒâÈí¼þ
8ÔÂ29ÈÕ£¬Check Point³ÆÆä¼ì²âµ½¼Ù×°³É¹È¸è·Òë×ÀÃæÀûÓõȺϷ¨ÀûÓ÷¨Ê½µÄÍÚ¿ó¶ñÒâÈí¼þ¡£¸Ã»î¶¯ÓëÍÁ¶úÆäÈí¼þ¿ª·¢ÉÌNitrokodÓйأ¬Ëü×Ô2019ÄêÆðÍ·»îÔ¾£¬Ðû³ÆÌṩÃâ·ÑÇÒ°²È«µÄÈí¼þ¡£¸Ã»î¶¯Í¨¹ýÊýÊ®¸öÃâ·ÑÈí¼þÍøÕ¾µÄÊ¢ÐÐÈí¼þ·Ö·¢¶ñÒâÈí¼þ£¬ÒÑϰȾ11¸ö¹ú¶ÈµÄÊýǧ̨É豸¡£´Ë±í£¬ÔÚ³õʼÈí¼þ×°ÖÃÖ®ºó£¬¹¥»÷Õß½«Ï°È¾¹ý³ÌÍÆ³ÙÁËÊýÖÜ£¬²¢É¾³ýÁËÔʼװÖõĺۼ££¬Ê¹µÃ¸Ã»î¶¯¿ÉÄÜÈÆ¹ý°²È«¼ì²â²¢³É¹¦ÔËÓª¶àÄê¡£
https://research.checkpoint.com/2022/check-point-research-detects-crypto-miner-malware-disguised-as-google-translate-desktop-and-other-legitimate-applications/amp/
6¡¢ºÚ¿ÍÔÚ°µÍøÏúÊÛÌ©¹úҽѧ¿ÆÑ§²¿µÄCOVID-19»¼ÕßÐÅÏ¢
¾ÝResecurity 8ÔÂ25ÈÕ±¨Â·£¬ºÚ¿ÍÔÚ°µÍøÉÏÏúÊÛ´ÓÌ©¹úҽѧ¿ÆÑ§²¿ÇÔÈ¡µÄCOVID-19»¼ÕßÐÅÏ¢¡£½øÒ»´ëÊ©²éÈ·ÈÏ£¬¹¥»÷ÕßÈëÇÖÁËÌ©¹úҽѧ¿ÆÑ§²¿µÄWEBÀûÓ÷¨Ê½£¨https://longcovidcheckin.dms.go.th£©£¬ÆäÓÃÓÚÔÚÏßµ÷²éºÍÍøÂ繫ÃñºÍÓοͽӼû¸Ã¹úµÄCOVID-19Êý¾Ý¡£ÓÉÓÚWEBÀûÓ÷¨Ê½µÄÊÚȨģ¿éÖдæÔÚSQL×¢Èë·ì϶£¬Òò¶ø¸Ã½Ó¼ûÊÇ¿ÉÄܵġ£¹¥»÷Õß¿ÉÄÜÒѾ½Ó¼ûÁËÖÁÉÙ5151±Ê¼Í¼£¬Ç±ÔÚй¶×ÜÊýΪ15000Ìõ¡£Ä¿Ç°£¬ResecurityÒѽ«´ËÊ»㱨¸ø·¨Âɲ¿ÃźÍÌ©¹úCERT¡£
https://resecurity.com/blog/article/covid-19-data-put-for-sale-in-dark-web


¾©¹«Íø°²±¸11010802024551ºÅ