EverestÈëÇÖÄϷǹúÓеçÁ¦¹«Ë¾ESKOM²¢ÀÕË÷20ÍòÃÀÔª

°ä²¼¹¦·ò 2022-10-11
1¡¢EverestÈëÇÖÄϷǹúÓеçÁ¦¹«Ë¾ESKOM²¢ÀÕË÷20ÍòÃÀÔª

      

¾ÝýÌå10ÔÂ9ÈÕ±¨Â·£¬ºÚ¿ÍÍÅ»ïEverestÈëÇÖÁËÄϷǹúÓеçÁ¦¹«Ë¾ESKOM ¡£EverestÔÚ2022Äê3Ô°䲼ÉêÃ÷³ÆÒÔ12.5ÍòÃÀÔªµÄ¼ÛÖµÏúÊÛÄϷǵçÁ¦¹«Ë¾µÄroot½Ó¼ûȨÏÞ£¬Æäʱ¸Ã¹«Ë¾·ñ¶¨²úÉúÁ˰²È«ÊÂÎñ ¡£10ÔÂ8ÈÕ£¬×êÑÐÈËÔ±³ÆESKOM Hld SOC LtdµÄ·þÎñÆ÷Óöµ½ÎÊÌâ ¡£Óë´Ëͬʱ£¬Everest°ä²¼Á˹¥»÷ÉêÃ÷£¬°µÊ¾Äܹ»½Ó¼û¹«Ë¾µÄËùÓзþÎñÆ÷£¬»¹Ìṩһ¸öÈí¼þ°ü£¬ÆäÖÐÔ̺¬´øÓÐÖÎÀíÔ±¡¢root¡¢ÓÃÓÚLinuxºÍWindows·þÎñÆ÷µÄϵͳÖÎÀíÔ±ÃÜÂëµÄ·þÎñÆ÷µÈ£¬ÒªÇó¸Ã¹«Ë¾Ö§¸¶20ÍòÃÀÔª ¡£


https://securityaffairs.co/wordpress/136866/cyber-crime/south-africa-eskom-everest-ransomware.html


2¡¢·áÌï³ÆÆäT-Connect·þÎñÖÐÔ¼29Íò¿Í»§µÄÐÅÏ¢¿ÉÄÜй¶

      

¾Ý·͸Éç10ÔÂ8ÈÕ±¨Â·£¬·áÌïÆû³µ¹«Ë¾·¢ÏÔìäT-Connect·þÎñÖÐÔ¼29Íò¿Í»§µÄÐÅÏ¢¿ÉÄÜÒѱ»Ð¹Â¶ ¡£Toyota T-ConnectÊǸù«Ë¾µÄ¹Ù·½ÏνÓÀûÓ㬳µÖ÷¿ÉÀûÓøÃÀûÓý«ÖÇÄÜÊÖ»úÓë³µÁ¾µÄÐÅÏ¢ÓéÀÖϵÍÂ䬽ӯðÀ´ ¡£¸ÃÆû³µÔì×÷Ḛ́µÊ¾£¬¿ª·¢T-ConnectÍøÕ¾µÄ³Ð°üÉ̲»Ó×ÐÄÉÏ´«ÁË´øÓй«¹²ÉèÖõIJ¿ÃÅÔ´´úÂ룬ÆäÖÐÔ̺¬´æ´¢¿Í»§ÓʼþµØÖ·ºÍÖÎÀíºÅÂëµÄÊý¾Ý·þÎñÆ÷µÄ½Ó¼ûÃÜÔ¿ ¡£ÕâʹµÃδ¾­ÊÚȨµÄµÚÈý·½Äܹ»ÔÚ2017Äê12ÔÂÖÁ2022Äê9ÔÂ15ÈÕ½Ó¼û296019Ãû¿Í»§µÄ¾ßÌåÐÅÏ¢ ¡£¸Ã¹«Ë¾ÒÑÔÚ2022Äê9ÔÂ17ÈÕ¸ü¸ÄÁËÊý¾Ý¿âµÄÃÜÔ¿ ¡£


https://www.reuters.com/technology/toyota-says-information-about-296000-users-its-t-connect-service-leaked-2022-10-07/


3¡¢ÒÁÀʹúÓª¹ã²¥¹«Ë¾ÔÚÖ±²¥ÐÂÎÅʱÔâµ½Edalate AliµÄ¹¥»÷

      

10ÔÂ10ÈÕ±¨Â·³Æ£¬ÒÁÀʹ㲥¹«Ë¾IRIBÔËÓªµÄIRINNÔÚÉÏÖÜÁùÍíÉϲ¥³öÐÂÎŲ¼¸æÊ±Ôâµ½Á˺ڿ͹¥»÷ ¡£ÃûΪEdalate AliµÄºÚ¿ÍÐû³Æ¶Ô´ËÊÂÕÆ¹Ü£¬¹¥»÷ÊÇÒÔAnonymousÌáÒéµÄOpIranÐж¯µÄÃûÒå½øÐеÄ ¡£ÖÜÁùÏÂÎç17:30 GMT×óÓÒ£¬¸ÃƵ·ÔÚ²¥·ÅÐÂÎÅʱºöÈ»ÖжÏ£¬²¢ÆðÍ·²¥·ÅÀ´×Ժڿ͵ÄÐÂÎÅ ¡£¸ÃÍÅ»ï»¹ÔøÓÚÈ¥Äê8ÔÂÈëÇÖÁ˵ºÚÀ¼±±²¿¼àÓüµÄϵͳºÍÉãÏñÍ·£¬ÒԸ淢¼àÓüÖеÄÑϸñǰÌáºÍ¼Óº¦ÈËȨµÄÐÐΪ ¡£


https://www.hackread.com/iran-state-run-tv-hacked-edalate-ali-hackers/


4¡¢BidenCashÃâ·Ñ°ä²¼³¬¹ý120ÍòÕÅÐÅÓþ¿¨µÄÖ§¸¶ÐÅÏ¢

      

ýÌå10ÔÂ9Èճƣ¬BidenCash°ä²¼ÁË1221551ÕÅÐÅÓþ¿¨µÄÐÅÏ¢£¬ÈκÎÈ˶¼Äܹ»Ãâ·ÑÏÂÔØËüÃÇÀ´½øÐнðÈÚÚ¿Æ­ ¡£BidenCashÊÇÒ»¸öÂòÂô±»µÁÐÅÓþ¿¨µÄÊг¡£¬ÓÚ2022Äê6ÔÂÍÆ³ö£¬ËüЧ·ÂÁËÀàËÆÆ½Ì¨All World CardsÔÚ2021Äê8Ô²ÉÈ¡µÄ·½Ê½£¬ÒÔ´ó¹æÄ£Íƹã¸ÃÍøÕ¾ ¡£Õâ´Î°ä²¼µÄÎļþÔ̺¬À´×ÔÊÀ½ç¸÷µØµÄÓÐЧÆÚΪ2023ÄêÖÁ2026ÄêµÄÐÅÓþ¿¨¼¯ÖУ¬´óÎÞÊýËÆºõÀ´×ÔÃÀ¹ú£¬ÆäÖÐÉæ¼°¿¨ºÅ¡¢½ØÖ¹ÈÕÆÚ¡¢CVVºÅÂë¡¢³ÖÓÐÈËÐÕÃûºÍÒøÐÐÃû³ÆµÈÐÅÏ¢ ¡£


https://www.bleepingcomputer.com/news/security/darkweb-market-bidencash-gives-away-12-million-credit-cards-for-free/


5¡¢¹þ·ðóÒ׳ö°æÉçÔÚÍÁ¶úÆäµÄÐí¿É¹«Ë¾Ôâµ½ÀÕË÷¹¥»÷

      

ýÌå10ÔÂ10ÈÕ±¨Â·£¬¹þ·ðóÒ׳ö°æÉçÔÚÍÁ¶úÆäµÄÐí¿É¹«Ë¾Ôâµ½ÁËÀÕË÷¹¥»÷ ¡£9ÔÂ16ÈÕ£¬Cybernews×êÑÐÈËÔ±·¢ÏÖÁËinfomag.com.trµÄÒ»¸öÊ¢¿ªµÄMongoDBÊ·ý£¬InfomagÒÔÍÁ¶úÆäÓï³ö°æ¡¶Åí²©Ã³Ò×ÖÜ¿¯¡·ºÍ¡¶¹þ·ðóÒׯÀÂÛ¡· ¡£¸ÃÊý¾Ý¿âÍйÜÔÚÍÁ¶úÆä£¬Ô¼Îª3.9GB£¬Óг¬¹ý1950Íò±Ê¼Í¼£¬152000ÌõÓë¿Í»§ÓйصÄÐÅÏ¢£¬×îÔçÄܹ»×·Òäµ½2017Äê ¡£9ÔÂ19ÈÕ£¬Cybernews³ÁнӼû¸ÃÊý¾Ý¿â²é¿´ËüÊÇ·ñ¹Ø¹ØÊ±£¬µÃÖªËüÔâµ½ÁËÀÕË÷¹¥»÷ ¡£¹¥»÷ÕßÀÕË÷0.01±ÈÌØ±Ò£¬²¢ÒÔÎ¥·´GDPRÃæ¶Ô¾Þ¶î·  £¿îΪÍþв£¬InfomagÈçͬ²¢Î´¸¶Êê½ð ¡£


https://securityaffairs.co/wordpress/136860/cyber-crime/harvard-business-publishing-licensee-hit-by-ransomware.html


6¡¢Trellix°ä²¼BazarCallÉ繤¹¥»÷Õ½ÊõÑݱäµÄ·ÖÎö»ã±¨

      

10ÔÂ6ÈÕ£¬Trellix°ä²¼Á˹ØÓÚBazarCallÉ繤¹¥»÷Õ½ÊõÑݱäµÄ·ÖÎö»ã±¨ ¡£Æ¾¾Ý·ÖÎö£¬Trellix¸ÅÊöÁËBazarCall»î¶¯µÄ¹¥»÷Á÷³Ì£¬²¢½«Æä·ÖΪÈý¸ö½×¶Î£¬»¹½ÒʾÁËÉ繤¹¥»÷Õ½ÊõµÄÑݱä ¡£´ËÀ๥»÷ÓÚ2021Äê3Ô³õ´Î³öÏÖ£¬×îÐÂµÄ»î¶¯ÖØÒªÕë¶ÔÃÀ¹ú¡¢¼ÓÄôó¡¢Ó¢¹ú¡¢Ó¡¶ÈºÍÈÕ±¾µÈ¹ú¶ÈµÄÓû§£¬ÆäÖдóÎÞÊý¶¼ÔÚÍÆËÍÃûΪsupport.Client.exeµÄClickOnce¿ÉÖ´ÐÐÎļþ£¬¸ÃÎļþ»áÔÚÆô¶¯Ê±»á×°ÖÃÔ¶³Ì½Ó¼û¹¤¾ßScreenConnect ¡£


https://www.trellix.com/en-us/about/newsroom/stories/research/evolution-of-bazarcall-social-engineering-tactics.html