·¨º½ºÍºÉº½Í¨ÖªFlying Blue¿Í»§ÆäÓ×ÎÒÐÅÏ¢ÒÑй¶
°ä²¼¹¦·ò 2023-01-09
¾ÝýÌå1ÔÂ6ÈÕ±¨Â·£¬·¨º½ºÍºÉº½ÒÑ֪ͨFlying Blue¿Í»§£¬ÆäÓ×ÎÒÐÅÏ¢ÒѾй¶¡£ºÉº½¹Ù·½ÍÆÌØÕ˺Å֤ʵÁËÕâ´Î¹¥»÷£¬³Æ¹¥»÷±»ÊµÊ±×èÖ¹£¬Óû§Àï³ÌûÓÐÊÜÓ°Ï죬µ«Êǽ¨Òé¿Í»§Í¨¹ýFlying BlueÍøÕ¾¸ü¸ÄÃÜÂë¡£¾ÝϤ£¬¿ÉÄÜй¶µÄÊý¾ÝÔ̺¬ÐÕÃû¡¢ÓʼþµØÖ·¡¢µç»°¡¢ÂòÂô¼Í¼ºÍ·ÉÐÐÐÅÏ¢µÈ£¬¿Í»§µÄÐÅÓþ¿¨»ò¸¶¿îÐÅÏ¢²¢Î´Ð¹Â¶¡£Ä¿Ç°£¬ºÉº½ºÍ·¨º½Ã»Óлظ´×êÑÐÈËÔ±µÄÖÃÆÀÒªÇó¡£
https://www.bleepingcomputer.com/news/security/air-france-and-klm-notify-customers-of-account-hacks/
2¡¢ÀÕË÷ÍÅ»ïHive¹«¿ªConsulate Health CareµÄ550GBÊý¾Ý
ýÌå1ÔÂ7Èճƣ¬ÀÕË÷ÍÅ»ïHiveй¶ÁËConsulate Health CareµÄ550GBÊý¾Ý¡£¸ÃÍŻﰵʾ£¬¹¥»÷²úÉúÔÚ2022Äê12ÔÂ3ÈÕ£¬²¢ÓÚ2023Äê1ÔÂ6ÈÕÅû¶¡£Æð³õ£¬¹¥»÷Õß°ä²¼Á˱»µÁÊý¾ÝµÄÑù±¾£¬²¢Ðû³ÆÇÔÈ¡Á˺Ïͬ¡¢NDAºÍÆäËüºÍ̸Îļþ¡¢¹«Ë¾ÐÅÏ¢¡¢Ô±¹¤ÐÅÏ¢ºÍ¿Í»§ÐÅÏ¢µÈ¡£ºóÀ´£¬×êÑÐÈËÔ±·¢ÏÖ¸ÃÍÅ»ïй¶ÁË´ÓConsulate Health CareÇÔÈ¡µÄ550GBÊý¾Ý£¬Ô̺¬¿Í»§ºÍÔ±¹¤µÄPII¡£¾Ý´§Ä¦£¬ÓÉÓÚ½»ÉæÊ§°ÜÁË£¬ÀÕË÷ÍÅ»ïûÓбȼ°´òËãµÄ½ØÖ¹ÈÕÆÚ¾Í¹«¿ªÁËËùº±¼û¾Ý¡£
https://securityaffairs.com/140452/cyber-crime/consulate-health-care-hive-ransomware.html
3¡¢ÃÀ¹úÁ¬ËøµêChick-fil-Aµ÷²éÆä²¿Ãſͻ§ÕË»§±»ºÚµÄÎÊÌâ
¾Ý1ÔÂ6ÈÕ±¨Â·£¬ÃÀ¹ú¿ì²ÍÁ¬ËøµêChick-fil-AÔÚµ÷²éÓëÆä²¿Ãſͻ§ÕË»§ÓйصĿÉÒɻ¡£¾ÝϤ£¬±»½Ù³ÖµÄÕË»§ÓëÒ»´ÎÐÔµç×ÓÓʼþµØÖ·Ò»Â·±»ÓÃÀ´ÔÚ¹¥»÷ÖвɰìʳƷ¡£Ò»Ð©±»µÁÕË»§ÒÔ2ÖÁ200ÃÀÔªµÄ¼ÛÖµ±»ÏúÊÛ£¬ÕâÈ¡¾öÓÚÕË»§Óà¶î¡¢Á´½ÓµÄÖ§¸¶·½Ê½»òChick-fil-A One»ý·ÖÓà¶î¡£»¹Óпͻ§»ã±¨ËµËûÃǵÄÕË»§±»ºÚ£¬»ý·Ö±»Çå¿Õ¡£Ä¿Ç°£¬Chick-Fil-AÒÑÔÝÍ£´´½¨ÐÂÕÊ»§²¢²»ÈÝʹÓÃÒ»´ÎÐÔµç×ÓÓʼþµØÖ·£¬½¨Òé¿Í»§µ±¼´³ÁÖÃÆäÕÊ»§ÃÜÂë¡£
https://www.bleepingcomputer.com/news/security/chick-fil-a-investigates-reports-of-hacked-customer-accounts/
4¡¢¸ßͨ°ä²¼2023Äê1Ô·ݰ²È«¸üн¨¸´Æä¹Ì¼þÖеÄ22¸ö·ì϶
1ÔÂ5ÈÕ£¬¸ßͨ°ä²¼ÁË2023Äê1Եݲȫ¸üУ¬½¨¸´Æä¹Ì¼þÖеÄ22¸ö·ì϶¡£ÆäÖУ¬½ÏΪÑϳÁµÄÊÇAutomotiveÖеĻº³åÇøÒç¶Âí½Å£¨CVE-2022-33219£©£¬CVSSÆÀ·ÖΪ9.3£¬ÔÚʹÓù²Ïí»º³åÇø×¢²áмàÌýÆ÷ʱ£¬ÓÉÓÚÕûÊýÒç³öµ½»º³åÇøÒç³öµ¼ÖÂAutomotiveÄÚ´æ°Ü»µ¡£Æä´ÎÊÇAutomotiveÖеÄÊäÈëÑéÖ¤²»µ±£¨CVE-2022-33218£©ºÍAndroid CoreÖÐÊý×éË÷ÒýµÄÑéÖ¤²»ÕýÈ·£¨CVE-2022-33274£©µÈ¡£ÕâЩ·ì϶¿ÉÄÜÓ°ÏìåÚÏ롢΢ÈíºÍÈýÐÇÔì×÷µÄÉ豸£¬ÒÔ¼°»ùÓÚARM¼Ü¹¹µÄ΢ÈíSurfaceºÍWindows Dev Kit 2023/Project VolterraÍÆËã»ú¡£
https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2023-bulletin.html
5¡¢Mandiant·¢ÏÖTurla·Ö·¢KOPILUWAKºÍQUIETCANARYµÄ»î¶¯
MandiantÔÚ1ÔÂ5ÈÕ³ÆÆä·¢ÏÖÁËTurlaÍÅ»ï½Ù³ÖÊ®ÄêǰµÄ¶ñÒâÈí¼þ»ù´¡ÉèÊ©À´·Ö·¢ÐºóÃŵĻ¡£2022Äê9Ô£¬×êÑÐÈËÔ±·¢ÏÖ¸ÃÍÅ»ï³ÁÐÂ×¢²áÁËÖÁÉÙ3¸ö¹ýÆÚµÄANDROMEDA C2Óò£¬²¢·Ö·¢¿úËÅ·¨Ê½KOPILUWAKºÍºóÃÅQUIETCANARY¡£ANDROMEDAÓÚ2010Äê´úÆðÍ·´«²¼£¬±»¹¥»÷Õ߽ٳֵİ汾ÓÚ2013Äê³õ´ÎÉÏ´«µ½VirusTotal£¬²¢Í¨¹ý±»Ï°È¾µÄUSBÃÜÔ¿´«²¼¡£´Ë±í£¬¹¥»÷ÕßÇÔÈ¡ÁË2021Äê1ÔÂ1ÈÕÖ®ºó´´½¨µÄÎļþ¡£
https://www.mandiant.com/resources/blog/turla-galaxy-opportunity
6¡¢CheckPoint°ä²¼BLINDEAGLEÕë¶Ô¶ò¹Ï¶à¶ûµÄ·ÖÎö»ã±¨
1ÔÂ5ÈÕ£¬Check Point°ä²¼Á˹ØÓÚBLINDEAGLE¹¥»÷¶ò¹Ï¶à¶ûºÍ¸çÂ×±ÈÑǵķÖÎö»ã±¨¡£¹¥»÷ʼÓÚÀ´×Ô¸çÂ×±ÈÑǵ±¾ÖµÄ´¹µöÓʼþ£¬×îÖÕ»á×°ÖÿªÔ´Ä¾ÂíQuasar RAT£¬Ö¼ÔÚ»ñµÃÖ¸±êÒøÐÐÕË»§µÄ½Ó¼ûȨÏÞ¡£´Ë±í£¬»¹»á·ÖÎö´«ÈëHTTPÒªÇó£¬ÒÔ²é³Ö¸±êÊÇ·ñÀ´×Ô¸çÂ×±ÈÑǾ³±í£¬ÈôÊÇÀ´×Ô¾³±íÔò¶ôÖÆ¹¥»÷£¬²¢½«Æä³Á¶¨Ïòµ½¸çÂ×±ÈÑÇ±í½»²¿ÒÆÃñ²¿ÃŵÄÕæÊµÍøÕ¾¡£ÁíÒ»¸ö»î¶¯¼ÙÒâÁ˶ò¹Ï¶à¶û¹ú˰¾Ö£¬ÀûÓÃÀàËÆµÄ¼¼Êõ¹ýÂ˵ôÀ´×ÔÆäËû¹ú¶ÈµÄÒªÇó¡£¹¥»÷ûÓзַ¢RAT£¬¶øÊÇÀÄÓúϷ¨µÄmshta.exeÀ´Ö´ÐÐǶÈëÔÚHTMLÎļþÖеÄVBScript£¬×îÖÕÏÂÔØÁ½¸öPython¾ç±¾¡£
https://research.checkpoint.com/2023/blindeagle-targeting-ecuador-with-sharpened-tools/


¾©¹«Íø°²±¸11010802024551ºÅ