PayPalÒòй¶3.5Íò¿Í»§µÄÓ×ÎҺͲÆÕþÐÅÏ¢±»¸æ×´

°ä²¼¹¦·ò 2023-03-07

1¡¢PayPalÒòй¶3.5Íò¿Í»§µÄÓ×ÎҺͲÆÕþÐÅÏ¢±»¸æ×´


ýÌå3ÔÂ4Èճƣ¬PayPalÒòй¶½ü35000¿Í»§µÄÓ×ÎҺͲÆÕþÐÅÏ¢Ãæ¶Ô¼¯ÌåËßËÏ¡£Ô­¸æAshley PillardºÍDestiny RuckerÌá¸æ×´ËÏ£¬³Æ¸Ã¹«Ë¾µÄºöÂÔµ¼ÖÂÊý¾Ýй¶ÊÂÎñ¡£ÖµÍ×ÌùÐĵÄÊÇ£¬PayPalÔÚ2023Äê1ÔÂ19ÈÕÆðÍ·ÁªÏµÓû§²¢·¢ËÍÊý¾Ýй¶֪ͨ£¬Ú¹ÊÍ˵ËûÃǵÄÕË»§ÔÚ2022Äê12ÔÂ6ÈÕÖÁ8ÈÕÔâµ½¹¥»÷¡£Æ¾¾ÝËßËÏ£¬PayPalδÄÜÖ´Ðиù»ùµÄ°²È«´ëÊ©»ò×ñÊØÁª¹úÒµÎñίԱ»áÔì¶©µÄÐÐÒµÊý¾Ý± £»¤³ß¶ÈºÍÖ¸ÄÏ£¬µ¼ÖÂÐÕÃûºÍÉç»á°²È«ºÅÂëµÈÐÅϢй¶¡£¸ÃËßËÏÒÑÓÚÉÏÖÜËÄÔÚÃÀ¹ú¼ÓÀû¸£ÄáÑÇÖݱ±Çø´¦Ëù·¨ÔºÌáÆð¡£


https://www.hackread.com/paypal-sued-over-data-breach/


2¡¢×êÑÐÈËÔ±·¢ÏÖÕë¶ÔÆóÒµ¼¶Â·ÓÉÆ÷µÄжñÒâÈí¼þHiatusRAT


Lumen Black Lotus LabsÔÚ3ÔÂ6ÈÕÅû¶ÁËÕë¶ÔÆóÒµ¼¶Â·ÓÉÆ÷µÄ¹¥»÷»î¶¯£¬Éæ¼°À­¶¡ÃÀÖÞ¡¢Å·Ö޺ͱ±ÃÀµÈµØÓò¡£¸Ã»î¶¯±»³ÆÎªHiatus£¬Ëü»áϰȾ¼¶Â·ÓÉÆ÷²¢×°ÖÃÁ½¸ö¶ñÒâ¶þ½øÔìÎļþ£¬Ô¶³Ì½Ó¼ûľÂíHiatusRATÒÔ¼°ÔÚÖ¸±êÉ豸Éϲ¶»ñÊý¾Ý°üµÄtcpdump±äÌå¡£¹¥»÷ÕßÖØÒªÕë¶ÔÔËÐÐi386¼Ü¹¹µÄEoL DrayTek VigorÐͺÅ2960ºÍ3900£¬½ØÖÁ2023Äê2ÔÂÖÐÑ®£¬Ô¼100̨·ÓÉÆ÷Òѱ»ÈëÇÖ¡£ÊÜÓ°ÏìµÄÐͺÅÊǸߴø¿í·ÓÉÆ÷£¬Äܹ»Ö§³ÖÊý°ÙÃûÔ¶³ÌÔ±¹¤µÄVPNÏνÓ¡£Òò¶ø´§Ä¦¹¥»÷ÕßϰȾָ±êÒÔÍøÂçÊý¾Ý£¬²¢³ÉÁ¢Òñ±ÎµÄ´úÀíÍøÂç¡£


https://thehackernews.com/2023/03/new-hiatusrat-malware-targets-business.html


3¡¢»ªÊ¢¶Ù¹«½»¹«Ë¾Pierce Transit±»LockBitÀÕË÷200ÍòÃÀÔª


¾Ý3ÔÂ3ÈÕ±¨Â·£¬»ªÊ¢¶ÙÖݵÄÒ»¼Ò¹«¹²½»Í¨ÔËÓªÉÌPierce TransitÔâµ½LockBitµÄ¹¥»÷£¬±»ÀÕË÷200ÍòÃÀÔª¡£¹¥»÷ÆðÍ·ÓÚ2023Äê2ÔÂ14ÈÕÆðÍ·£¬¸Ã¹«Ë¾²»µÃ²»Ö´ÐÐһʱ±äͨ·¨×Ó£¬ÒÔά³ÖÿÌìµÄ¹«½»·þÎñ¡£2ÔÂ28ÈÕ£¬LockBit°ä²¼ÁËPierce Transit¹¥»÷ÊÂÎñµÄÏêÇ飬Ðû³ÆÇÔÈ¡Á˺Ïͬ¡¢¿Í»§ÐÅÏ¢¡¢±£ÃܺÍ̸ºÍº¯¼þµÈÐÅÏ¢£¬ÕâЩÊý¾Ý´Ë¿Ì¶¼ÔÚÏúÊÛ¡£Ä¿Ç°£¬Pierce TransitµÄ´ó²¿ÃÅÔËÓªÒÑÆëÈ«¸´Ô­£¬Æä°µÊ¾´òËãÖ´ÐÐеÄÍøÂ簲ȫ¼à¿Ø¹¤¾ßºÍ°²È«´ëÊ©¡£


https://www.malwarebytes.com/blog/news/2023/03/public-transportation-service-pierce-transit-struck-by-lockbit-ransomware


4¡¢GunAuction.comÍøÕ¾±»ºÚ56.5Íò¸öÕË»§µÄÐÅϢй¶


¾ÝýÌå3ÔÂ2ÈÕ±¨Â·£¬ºÚ¿ÍÈëÇÖÁËGunAuction.com²¢ÇÔÈ¡ÁËÓû§µÄÓ×ÎÒÐÅÏ¢¡£2022Äêµ×£¬×êÑÐÈËÔ±ÔÚÊôÓںڿ͵ÄÒ»¸öÅäÖÃÃýÎóµÄ·þÎñÆ÷ÉÏ·¢ÏÖÁËÕâЩ±»µÁÊý¾Ý¡£Ð¹Â¶ÐÅÏ¢Éæ¼°ÐÕÃû¡¢×¡Ö·¡¢Ã÷ÎÄÃÜÂëºÍµç»°ºÅÂëµÈ¡£TechCrunch³ÆÆä¿ÉÄÜÑéÖ¤Ñù±¾Êý¾ÝµÄÕæÊµÐÔ£¬µ«Éв»Ã÷ÏÔÕâЩÊý¾ÝÓжàС£HaveIBeenPwned»ã±¨°µÊ¾£¬¹¥»÷²úÉúÔÚÈ¥Äê12Ô£¬Ó°ÏìÁË56.5Íò¸öÕË»§¡£


https://securityaffairs.com/142920/data-breach/gunauction-site-data-breach.html


5¡¢×êÑÐÈËÔ±·¢ÏÖBooking.comÉϿɵ¼ÖÂÕÊ»§½Ù³ÖµÄ·ì϶


Salt SecurityÓÚ3ÔÂ2ÈÕ³ÆÆä·¢ÏÖÁËÔÚÏß¹Û¹âÉçBooking.comÉϵݲȫ·ì϶¡£×êÑÐÈËÔ±·¢Ïֵķì϶¼¯ÖÐBooking.comÖ´ÐÐOAuthµÄ·½Ê½ÉÏ£¬Éæ¼°OAuthÓëFacebookµÄ¼¯³É¡£¹¥»÷Õß¿ÉÓÕʹָ±êµã»÷ÌØÔìÁ´½Ó£¬Í¨¹ýÀÄÓÃOAuthµÇ¼»úÔìÀ´²¶»ñÒѵǼÓû§µÄÉí·ÝÑéÖ¤´úÂë¡£¶øºó¹¥»÷Õß½Ó¼ûËûÃÇ×Ô¼ºµÄÕÊ»§£¬ÔÚÀûÓÃÏòÔ¤Ô¼·þÎñÆ÷·¢Ë͵ÄÉí·ÝÑéÖ¤ÒªÇóÖУ¬½«×Ô¼ºµÄ´úÂë´úÌæÎªÖ¸±êµÄ´úÂë¡£³É¹¦ÀûÓÃÕâЩ·ì϶¿ÉÆëÈ«½ÚÔìÖ¸±êÕÊ»§£¬À´ÇÔÈ¡Ó×ÎÒÐÅÏ¢²¢Ö´ÐÐÈ¡µÞ»òÔ¤Ô¼µÈ²Ù×÷¡£¸ÃÎÊÌ⻹ӰÏìÁËBooking.comµÄæ¢ÃÃÍøÕ¾Kayak.com¡£


https://salt.security/blog/traveling-with-oauth-account-takeover-on-booking-com


6¡¢Lookout°ä²¼2022ÄêÒÆ¶¯ÍøÂç´¹µö¹¥»÷Ì¬ÊÆµÄ·ÖÎö»ã±¨


3ÔÂ1ÈÕ£¬Lookout°ä²¼ÁË2022ÄêÈ«ÇòÒÆ¶¯ÍøÂç´¹µöÌ¬ÊÆµÄ·ÖÎö»ã±¨¡£»ã±¨³Æ£¬2022ÄêÊÇÓÐÊ·ÒÔÀ´Òƶ¯´¹µö¹¥»÷×î¶àµÄÒ»Ä꣬ÿ¸ö¼¾¶È¶¼Óг¬¹ý30%µÄÓ×ÎÒºÍÆóÒµÓû§Ôâµ½¹¥»÷¡£Êܵ½¸ß¶È¼à¹ÜµÄÐÐÒµ£¬Ô̺¬±£ÏÕ¡¢ÒøÐÓע˾·¨¡¢Ò½ÁƱ£½¡ºÍ½ðÈÚ·þÎñ£¬×îÒ×Ôâµ½¹¥»÷¡£·Çµç×ÓÓʼþµÄ´¹µö¹¥»÷Ò²ÔÚ¼¤Ôö£¬ÓïÒô´¹µö¡¢¶ÌÐÅ´¹µöºÍ¶þάÂë´¹µöÔÚ2022ÄêQ2¶ÈÔö³¤ÁËÆß±¶¡£¶ÔÓÚÔâµ½ÒÆ¶¯´¹µö¹¥»÷µÄÆóÒµ¶øÑÔ£¬Ëðʧ¿ÉÄÜÊǾ޴óµÄ¡£LookoutÍÆËãµÃ³ö£¬´ËÀ๥»÷¶ÔÒ»¸öÕ¼ÓÐ5000ÃûÔ±¹¤µÄ×éÖ¯µÄDZÔÚÄê¶È²ÆÕþÓ°ÏìÊǽü400ÍòÃÀÔª¡£


https://www.lookout.com/form/the-global-state-of-mobile-phishing-report