EverestÈëÇÖÄϷǹúÓеçÁ¦¹«Ë¾ESKOM²¢ÀÕË÷20ÍòÃÀÔª
°ä²¼¹¦·ò 2022-10-11
¾ÝýÌå10ÔÂ9ÈÕ±¨Â·£¬ºÚ¿ÍÍÅ»ïEverestÈëÇÖÁËÄϷǹúÓеçÁ¦¹«Ë¾ESKOM¡£EverestÔÚ2022Äê3Ô°䲼ÉêÃ÷³ÆÒÔ12.5ÍòÃÀÔªµÄ¼ÛÖµÏúÊÛÄϷǵçÁ¦¹«Ë¾µÄroot½Ó¼ûȨÏÞ£¬Æäʱ¸Ã¹«Ë¾·ñ¶¨²úÉúÁ˰²È«ÊÂÎñ¡£10ÔÂ8ÈÕ£¬×êÑÐÈËÔ±³ÆESKOM Hld SOC LtdµÄ·þÎñÆ÷Óöµ½ÎÊÌâ¡£Óë´Ëͬʱ£¬Everest°ä²¼Á˹¥»÷ÉêÃ÷£¬°µÊ¾Äܹ»½Ó¼û¹«Ë¾µÄËùÓзþÎñÆ÷£¬»¹Ìṩһ¸öÈí¼þ°ü£¬ÆäÖÐÔ̺¬´øÓÐÖÎÀíÔ±¡¢root¡¢ÓÃÓÚLinuxºÍWindows·þÎñÆ÷µÄϵͳÖÎÀíÔ±ÃÜÂëµÄ·þÎñÆ÷µÈ£¬ÒªÇó¸Ã¹«Ë¾Ö§¸¶20ÍòÃÀÔª¡£
https://securityaffairs.co/wordpress/136866/cyber-crime/south-africa-eskom-everest-ransomware.html
2¡¢·áÌï³ÆÆäT-Connect·þÎñÖÐÔ¼29Íò¿Í»§µÄÐÅÏ¢¿ÉÄÜй¶
¾Ý·͸Éç10ÔÂ8ÈÕ±¨Â·£¬·áÌïÆû³µ¹«Ë¾·¢ÏÔìäT-Connect·þÎñÖÐÔ¼29Íò¿Í»§µÄÐÅÏ¢¿ÉÄÜÒѱ»Ð¹Â¶¡£Toyota T-ConnectÊǸù«Ë¾µÄ¹Ù·½ÏνÓÀûÓ㬳µÖ÷¿ÉÀûÓøÃÀûÓý«ÖÇÄÜÊÖ»úÓë³µÁ¾µÄÐÅÏ¢ÓéÀÖϵÍÂ䬽ӯðÀ´¡£¸ÃÆû³µÔì×÷Ḛ́µÊ¾£¬¿ª·¢T-ConnectÍøÕ¾µÄ³Ð°üÉ̲»Ó×ÐÄÉÏ´«ÁË´øÓй«¹²ÉèÖõIJ¿ÃÅÔ´´úÂ룬ÆäÖÐÔ̺¬´æ´¢¿Í»§ÓʼþµØÖ·ºÍÖÎÀíºÅÂëµÄÊý¾Ý·þÎñÆ÷µÄ½Ó¼ûÃÜÔ¿¡£ÕâʹµÃδ¾ÊÚȨµÄµÚÈý·½Äܹ»ÔÚ2017Äê12ÔÂÖÁ2022Äê9ÔÂ15ÈÕ½Ó¼û296019Ãû¿Í»§µÄ¾ßÌåÐÅÏ¢¡£¸Ã¹«Ë¾ÒÑÔÚ2022Äê9ÔÂ17ÈÕ¸ü¸ÄÁËÊý¾Ý¿âµÄÃÜÔ¿¡£
https://www.reuters.com/technology/toyota-says-information-about-296000-users-its-t-connect-service-leaked-2022-10-07/
3¡¢ÒÁÀʹúÓª¹ã²¥¹«Ë¾ÔÚÖ±²¥ÐÂÎÅʱÔâµ½Edalate AliµÄ¹¥»÷
10ÔÂ10ÈÕ±¨Â·³Æ£¬ÒÁÀʹ㲥¹«Ë¾IRIBÔËÓªµÄIRINNÔÚÉÏÖÜÁùÍíÉϲ¥³öÐÂÎŲ¼¸æÊ±Ôâµ½Á˺ڿ͹¥»÷¡£ÃûΪEdalate AliµÄºÚ¿ÍÐû³Æ¶Ô´ËÊÂÕÆ¹Ü£¬¹¥»÷ÊÇÒÔAnonymousÌáÒéµÄOpIranÐж¯µÄÃûÒå½øÐеġ£ÖÜÁùÏÂÎç17:30 GMT×óÓÒ£¬¸ÃƵ·ÔÚ²¥·ÅÐÂÎÅʱºöÈ»Öжϣ¬²¢ÆðÍ·²¥·ÅÀ´×Ժڿ͵ÄÐÂÎÅ¡£¸ÃÍÅ»ï»¹ÔøÓÚÈ¥Äê8ÔÂÈëÇÖÁ˵ºÚÀ¼±±²¿¼àÓüµÄϵͳºÍÉãÏñÍ·£¬ÒԸ淢¼àÓüÖеÄÑϸñǰÌáºÍ¼Óº¦ÈËȨµÄÐÐΪ¡£
https://www.hackread.com/iran-state-run-tv-hacked-edalate-ali-hackers/
4¡¢BidenCashÃâ·Ñ°ä²¼³¬¹ý120ÍòÕÅÐÅÓþ¿¨µÄÖ§¸¶ÐÅÏ¢
ýÌå10ÔÂ9Èճƣ¬BidenCash°ä²¼ÁË1221551ÕÅÐÅÓþ¿¨µÄÐÅÏ¢£¬ÈκÎÈ˶¼Äܹ»Ãâ·ÑÏÂÔØËüÃÇÀ´½øÐнðÈÚÚ¿Æ¡£BidenCashÊÇÒ»¸öÂòÂô±»µÁÐÅÓþ¿¨µÄÊг¡£¬ÓÚ2022Äê6ÔÂÍÆ³ö£¬ËüЧ·ÂÁËÀàËÆÆ½Ì¨All World CardsÔÚ2021Äê8Ô²ÉÈ¡µÄ·½Ê½£¬ÒÔ´ó¹æÄ£Íƹã¸ÃÍøÕ¾¡£Õâ´Î°ä²¼µÄÎļþÔ̺¬À´×ÔÊÀ½ç¸÷µØµÄÓÐЧÆÚΪ2023ÄêÖÁ2026ÄêµÄÐÅÓþ¿¨¼¯ÖУ¬´óÎÞÊýËÆºõÀ´×ÔÃÀ¹ú£¬ÆäÖÐÉæ¼°¿¨ºÅ¡¢½ØÖ¹ÈÕÆÚ¡¢CVVºÅÂë¡¢³ÖÓÐÈËÐÕÃûºÍÒøÐÐÃû³ÆµÈÐÅÏ¢¡£
https://www.bleepingcomputer.com/news/security/darkweb-market-bidencash-gives-away-12-million-credit-cards-for-free/
5¡¢¹þ·ðóÒ׳ö°æÉçÔÚÍÁ¶úÆäµÄÐí¿É¹«Ë¾Ôâµ½ÀÕË÷¹¥»÷
ýÌå10ÔÂ10ÈÕ±¨Â·£¬¹þ·ðóÒ׳ö°æÉçÔÚÍÁ¶úÆäµÄÐí¿É¹«Ë¾Ôâµ½ÁËÀÕË÷¹¥»÷¡£9ÔÂ16ÈÕ£¬Cybernews×êÑÐÈËÔ±·¢ÏÖÁËinfomag.com.trµÄÒ»¸öÊ¢¿ªµÄMongoDBÊ·ý£¬InfomagÒÔÍÁ¶úÆäÓï³ö°æ¡¶Åí²©Ã³Ò×ÖÜ¿¯¡·ºÍ¡¶¹þ·ðóÒׯÀÂÛ¡·¡£¸ÃÊý¾Ý¿âÍйÜÔÚÍÁ¶úÆä£¬Ô¼Îª3.9GB£¬Óг¬¹ý1950Íò±Ê¼Í¼£¬152000ÌõÓë¿Í»§ÓйصÄÐÅÏ¢£¬×îÔçÄܹ»×·Òäµ½2017Äê¡£9ÔÂ19ÈÕ£¬Cybernews³ÁнӼû¸ÃÊý¾Ý¿â²é¿´ËüÊÇ·ñ¹Ø¹ØÊ±£¬µÃÖªËüÔâµ½ÁËÀÕË÷¹¥»÷¡£¹¥»÷ÕßÀÕË÷0.01±ÈÌØ±Ò£¬²¢ÒÔÎ¥·´GDPRÃæ¶Ô¾Þ¶î·£¿îΪÍþв£¬InfomagÈçͬ²¢Î´¸¶Êê½ð¡£
https://securityaffairs.co/wordpress/136860/cyber-crime/harvard-business-publishing-licensee-hit-by-ransomware.html
6¡¢Trellix°ä²¼BazarCallÉ繤¹¥»÷Õ½ÊõÑݱäµÄ·ÖÎö»ã±¨
10ÔÂ6ÈÕ£¬Trellix°ä²¼Á˹ØÓÚBazarCallÉ繤¹¥»÷Õ½ÊõÑݱäµÄ·ÖÎö»ã±¨¡£Æ¾¾Ý·ÖÎö£¬Trellix¸ÅÊöÁËBazarCall»î¶¯µÄ¹¥»÷Á÷³Ì£¬²¢½«Æä·ÖΪÈý¸ö½×¶Î£¬»¹½ÒʾÁËÉ繤¹¥»÷Õ½ÊõµÄÑݱ䡣´ËÀ๥»÷ÓÚ2021Äê3Ô³õ´Î³öÏÖ£¬×îÐÂµÄ»î¶¯ÖØÒªÕë¶ÔÃÀ¹ú¡¢¼ÓÄôó¡¢Ó¢¹ú¡¢Ó¡¶ÈºÍÈÕ±¾µÈ¹ú¶ÈµÄÓû§£¬ÆäÖдóÎÞÊý¶¼ÔÚÍÆËÍÃûΪsupport.Client.exeµÄClickOnce¿ÉÖ´ÐÐÎļþ£¬¸ÃÎļþ»áÔÚÆô¶¯Ê±»á×°ÖÃÔ¶³Ì½Ó¼û¹¤¾ßScreenConnect¡£
https://www.trellix.com/en-us/about/newsroom/stories/research/evolution-of-bazarcall-social-engineering-tactics.html


¾©¹«Íø°²±¸11010802024551ºÅ