T-MobileÎ¥¹æÐÐΪµ¼ÖÂGoogle Fi²¿Ãſͻ§Êý¾Ýй¶

°ä²¼¹¦·ò 2023-02-03
1¡¢T-MobileÎ¥¹æÐÐΪµ¼ÖÂGoogle Fi²¿Ãſͻ§Êý¾Ýй¶

      

¾Ý2ÔÂ1ÈÕ±¨Â·£¬¹È¸èµÄµÄ¹Ù·½Òƶ¯Ðé¹¹ÍøÂçÔËÓªÉÌ(MVNO)Google Fiй©£¬ÖØÒªÍøÂçÌṩÉ̵ÄÎ¥¹æÐÐΪµ¼ÖÂÆä²¿Ãſͻ§µÄÊý¾Ýй¶¡£¹ÌÈ»¹È¸èûÓÐÌáµ½ÔâÍøÂçÌṩÉÌÊÇË­£¬µ«¾ÝÐÅËûÃÇÖ¸µÄÊÇT-Mobile¡£1ÔÂ19ÈÕ£¬T-Mobileй©ËüÔÚ2022Äê11Ô²úÉúÁËÊý¾Ýй¶£¬Éæ¼°Ô¼3700ÍòÓû§µÄÐÅÏ¢¡£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬ÕÊ»§×´Ì¬¡¢µç»°ºÅÂë¡¢·þÎñ´òËã¾ßÌåÐÅÏ¢ºÍSMS¿¨ÐòÁкŵÈ£¬ÕâЩÊý¾Ý¿É±»ÓÃÓÚÖ´ÐÐSIM¿¨»¥»»¹¥»÷¡£


https://www.hackread.com/google-fi-data-breached-t-mobile-hack/


2¡¢F5½¨¸´ÆäBIG-IPÖеÄÌåʽ×Ö·û´®·ì϶CVE-2023-22374

      

2ÔÂ1ÈÕ£¬F5½¨¸´ÆäBIG-IPÖпɵ¼ÖÂDoSºÍËÁÒâ´úÂëÖ´Ðеķì϶£¨CVE-2023-22374£©¡£ÕâÊÇiControl SOAPÖеÄÌåʽ×Ö·û´®·ì϶£¬¿É±»¾­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÓÃÀ´µ¼ÖÂiControl SOAP CGI¹ý³Ì±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£ÔÚÉ豸ģʽBIG-IPÖУ¬³É¹¦ÀûÓô˷ì϶Äܹ»ÓâÔ½°²È«Ììǵ¡£¹©¸øÉÌÖ¸³ö£¬ÒªÀûÓúÅÁîÖ´Ðй¥»÷£¬¹¥»÷Õß±ØÐëÍøÂçÓйØÍйÜÒ×±»¹¥»÷×é¼þµÄÖ¸±ê»·¾³µÄÐÅÏ¢¡£´Ë±í£¬Ö»ÓнÚÔì²ãÃæÊܵ½´Ë·ì϶µÄÓ°Ï죬Êý¾Ý²ãÃæ²»»áÊܵ½Ó°Ïì¡£


https://securityaffairs.com/141728/security/f5-big-ip-bug.html


3¡¢HeadCrabÒÑϰȾ1200̨Redis·þÎñÆ÷Ö¼ÔÚÍÚ¾òMonero

      

Aqua SecurityÔÚ2ÔÂ1ÈÕÅû¶ÁËÕë¶ÔRedis·þÎñÆ÷µÄÐÂÐͶñÒâÈí¼þHeadCrab¡£×Ô2021Äê9ÔÂÒÔÀ´£¬HeadCrabÒѾ­Ï°È¾ÁËÖÁÉÙ1200̨·þÎñÆ÷£¬ÒÔ¹¹½¨Ò»¸öÍÚ¾òMonero¼ÓÃÜÇ®±ÒµÄ½©Ê¬ÍøÂç¡£×êÑÐÈËÔ±³Æ£¬¹¥»÷ÕßÀûÓÃÒ»ÖÖÎÞ´úÀíºÍ´«Í³É±¶¾½â¾ö¹æ»®ÎÞ·¨¼ì²âµ½µÄ¶¨Ôì¶ñÒâÈí¼þ£¬À´·ÛËé´óÁ¿µÄRedis·þÎñÆ÷¡£Æù½ñΪֹ£¬ÔÚÂíÀ´Î÷ÑÇ¡¢Ó¡¶È¡¢µÂ¹ú¡¢Ó¢¹úºÍÃÀ¹ú¾ùÒѼͼµ½´óÁ¿µÄϰȾ£¬¹¥»÷µÄÆðÔ´Éв»Ã÷È·¡£


https://blog.aquasec.com/headcrab-attacks-servers-worldwide-with-novel-state-of-art-redis-malware


4¡¢DDoSaaSƽ̨Passion±»ÓÃÓÚ¹¥»÷Å·ÃÀµØÓòµÄÒ½ÁÆ»ú¹¹

      

ýÌå2ÔÂ1Èճƣ¬ÔÚ½üÆÚÕë¶ÔÃÀ¹úºÍÅ·ÖÞµÄÒ½ÁÆ»ú¹¹µÄ¹¥»÷ÖУ¬·¢ÏÖÁËÒ»ÖÖÃûΪPassionµÄÐÂDDoS¼´·þÎñ(DDoSaaS)ƽ̨¡£PassionÓÚ1Ô³õ³õ´Î±»ÍƳö£¬¶ÔÈÕ±¾ºÍÄϷǵÄ×éÖ¯ÍøÕ¾Ö´ÐÐÁËÂŴι¥»÷¡£PassionÌṩʮÖÖ¹¥»÷ý½éµÄÑ¡ÏÔÊÐíÓû§Æ¾¾Ý±ØÒª¶¨Ôì¹¥»÷£¬ÉõÖÁ×éºÏý½éÒÔÈÆ¹ýÖ¸±êµÄ»º½â´ëÊ©¡£Radwareй©£¬ÔÚ1ÔÂ27ÈյĹ¥»÷»î¶¯ÖУ¬Passion±»ÓÃÓÚÕë¶ÔÊÇÃÀ¹ú¡¢ÆÏÌÑÑÀ¡¢Î÷°àÑÀ¡¢µÂ¹ú¡¢²¨À¼¡¢·ÒÀ¼¡¢Å²Íþ¡¢ºÉÀ¼ºÍÓ¢¹úµÄÒ½ÁÆ»ú¹¹¡£


https://www.bleepingcomputer.com/news/security/new-ddos-as-a-service-platform-used-in-recent-attacks-on-hospitals/


5¡¢×êÑÐÈËÔ±·¢ÏÖIce BreakerÕë¶ÔÓÎÏ·¹«Ë¾µÄ¹¥»÷»î¶¯

      

¾ÝýÌå2ÔÂ1ÈÕ±¨Â·£¬Security Joes·¢ÏÖÁËIce BreakerÕë¶ÔÓÎÏ·¹«Ë¾µÄ¹¥»÷»î¶¯¡£¸Ã»î¶¯ÖÁÉÙ´Ó2022Äê9ÔÂÆðÍ·£¬¹¥»÷Õß¼ÙÒâ¿Í»§£¬ÒÔÕÊ»§×¢²áÎÊÌâΪ½è¿ÚÓëÓÎÏ·¹«Ë¾µÄÖ§³Ö´úÀí½øÐжԻ°£¬¶øºó¶½´ÙÆä´ò¿ªDropboxÉÏÍÐ¹ÜµÄÆÁÄ»½ØÍ¼¡£µã»÷½ØÍ¼Á´½Ó»áµ¼Ö¼ìË÷LNK payload£¬»òÕß×÷Ϊ±¸·ÝÑ¡ÏîµÄVBScriptÎļþ£¬Ç°Õß±»ÅäÖÃΪÏÂÔØ²¢ÔËÐÐÔ̺¬Node.jsÖ²È뷨ʽµÄMSI°ü£¬VBS»áÏÂÔØHoudini RAT¡£


https://thehackernews.com/2023/02/experts-warn-of-ice-breaker.html


6¡¢Resecurity°ä²¼¹ØÓÚÐÂÀÕË÷Èí¼þNevadaµÄ·ÖÎö»ã±¨

      

1ÔÂ30ÈÕ£¬Resecurity°ä²¼Á˹ØÓÚÐÂÀÕË÷Èí¼þNevadaµÄ·ÖÎö»ã±¨¡£NevadaÓÚ2022Äê12ÔÂ10ÈÕÆðÍ·ÔÚRAMPÂÛ̳ÉÏÍÆ¹ã£¬ÓµÓлùÓÚRustµÄlocker¡¢ÊµÊ±½»ÉæÌ¸ÌìÃÅ»§ÒÔ¼°ÔÚTorÍøÂçÖÐΪ·ÖÖ§×éÖ¯ºÍÖ¸±êÌṩµÄ¶ÀÁ¢Óò¡£Õë¶ÔWindowsµÄNevada±äÌåͨ¹ý½ÚÔįִ̀ÐУ¬ÆälockerʹÓÃSalsa20Ëã·¨¶Ô´óÓÚ512KBµÄÎļþ½øÐмäЪ¼ÓÃÜ¡£Linux/VMware ESXi°æ±¾Ê¹ÓÃÓëWindowsÒ»ÑùµÄ¼ÓÃÜËã·¨£¨Salsa20£©£¬µ«¿ÉÄÜ´æÔÚBug£¬Ëü»áÌø¹ýËùÓдóÓ×ÔÚ512KBµ½1.25MBÖ®¼äµÄÎļþ¡£


https://resecurity.com/blog/article/nevada-ransomware-waiting-for-the-next-dark-web-jackpot