ºÚ¿ÍÔÚ°µÍøÏúÊÛ¼ÓÄôóÔËÓªÉÌRogersµÄ3¸öADÊý¾Ý¿â
°ä²¼¹¦·ò 2023-04-111¡¢ºÚ¿ÍÔÚ°µÍøÏúÊÛ¼ÓÄôóÔËÓªÉÌRogersµÄ3¸öADÊý¾Ý¿â
¾ÝýÌå4ÔÂ7ÈÕ±¨Â·£¬¹¥»÷ÕßÔÚÒ»¸ö¶íÓïµÄºÚ¿ÍÂÛ̳Éϰ䲼ÁËÒ»Ôò¸æ°×£¬Ðû³ÆÒªÏúÊÛ¼ÓÄôóÍøÂçÔËÓªÉÌRogers CommunicationsµÄÊý¾Ý¿â¡£ÆäÖÐÔ̺¬RogersµÄ3¸ö»î¶¯Ä¿Â¼£¨AD£©Êý¾Ý¿â£ºusers¡¢groupsºÍdevices¡£Í¨³££¬ADÔ̺¬Óйع«Ë¾»·¾³µÄ¹Ø¼üÊý¾Ý¡£Rogers֤ʵ£¬¸Ã¹«Ë¾µÄ²¿ÃÅÊý¾ÝÔÚ°µÍøÉÏй¶£¬È»¶øÐ¹Â¶µÄÊý¾Ý¿âÖнöÔ̺¬Ô±¹¤Êý¾Ý£¬Ã»Óпͻ§µÄ¾ßÌåÐÅÏ¢¡£Õâ3¸öÊý¾Ý¿âµÄ±ê¼ÛΪ14000ÃÀÔª£¬Ã»ÓоßÌå×¢Ã÷Êý¾Ý¿âµÄ´óÓ×»òËüËù¹«¿ªµÄ¹«Ë¾Óû§ÊýÁ¿¡£
https://cybernews.com/news/rogers-communications-data-breach/
2¡¢SD WorxÔâµ½¹¥»÷±»ÆÈ¹Ø¹ØÆäÓ¢¹úºÍ°®¶ûÀ¼µÄ»ù´¡ÉèÊ©
ýÌå4ÔÂ10Èճƣ¬±ÈÀûʱÈËÁ¦×ÊÔ´¹«Ë¾SD WorxÔâµ½ÍøÂç¹¥»÷£¬±»ÆÈ¹Ø¹ØÆäÓ¢¹úºÍ°®¶ûÀ¼µÄIT»ù´¡ÉèÊ©¡£SD Worx¸øÓ¢¹úºÍ°®¶ûÀ¼¿Í»§µÄ֪ͨ³Æ£¬ËûÃÇÔÚÍйÜÊý¾ÝÖÐÐÄ·¢ÏÖ¶ñÒâ»î¶¯£¬ÒѲÉÈ¡Ðж¯²¢¸ôÀëÁËËùÓÐϵͳºÍ·þÎñÆ÷¡£¸Ã¹«Ë¾Õë¶ÔÆäËüÅ·ÖÞ¹ú¶ÈµÄµÇÂ¼ÍøÕ¾ÒÀÈ»ÔËÐÐÕý³££¬µ«Ó¢¹úµÄÍøÕ¾ÎÞ·¨½Ó¼û¡£Ã»ÓйØÓÚÕâ´Î¹¥»÷ÀàÐ͵ľßÌåÐÅÏ¢£¬ÓÐÈ˲»°²Ãô¸ÐÊý¾ÝÔÚ¹¥»÷ÆÚ¼ä±»µÁ¡£×÷Ϊһ¼ÒÈËÁ¦×ÊÔ´ºÍн×ʹ«Ë¾£¬SD WorxΪÆä¿Í»§µÄÔ±¹¤ÖÎÀí×Å´óÁ¿Ãô¸ÐÊý¾Ý£¬Èç˰ÎñÐÅÏ¢¡¢Éí·ÝÖ¤ºÅÂëºÍÒøÐÐÕʺŵȡ£
https://securityaffairs.com/144629/hacking/sd-worx-suffered-cyberattack.html
3¡¢ÈûÆÖ·˹ʢ¿ª´óѧOUCÔâµ½ÀÕË÷ÍÅ»ïMedusaµÄ¹¥»÷
¾Ý4ÔÂ6ÈÕ±¨Â·£¬ÀÕË÷ÍÅ»ïMedusaÐû³Æ¹¥»÷ÁËÈûÆÖ·˹ʢ¿ª´óѧ(OUC)¡£OUCÊÇλÓÚÈûÆÖ·˹Äá¿ÆÎ÷ÑǵÄÒ»µØµãÏß´óѧ£¬ÌṩԶ³Ì½ø½¨¡£ÉÏÖÜ£¬¸Ã´óѧ°ä²¼ÁËÒ»·Ý¹ØÓÚ3ÔÂ27ÈÕ²úÉúµÄÍøÂç¹¥»÷µÄ²¼¸æ£¬Õâ´Î¹¥»÷µ¼Ö¶à¸öÖÐÑë·þÎñºÍ¹Ø¼üϵͳ崻ú¡£4ÔÂ6ÈÕ£¬MedusaÔÚÍøÕ¾ÉÏÁгöÁËOUC²¢ÀÕË÷100000ÃÀÔª£¬Áô¸ø¸Ã»ú¹¹14ÌìµÄ¹¦·ò¡£¸ÃÍŻﻹ°ä²¼Á˱»µÁÊý¾ÝÑù±¾£¬É漰ѧÉúÃûµ¥ºÍ³Ð°üÉ̵IJÆÕþϸ½ÚµÈ¡£
https://www.bleepingcomputer.com/news/security/medusa-ransomware-claims-attack-on-open-university-of-cyprus/
4¡¢SucuriÅû¶Õë¶ÔWPÍøÕ¾µÄ´ó¹æÄ£Balad Injector»î¶¯
SucuriÔÚ4ÔÂ6ÈÕÅû¶ÁË×Ô2017ÄêÒÔÀ´Ò»Ïò¹¥»÷WordPressÍøÕ¾µÄ´ó¹æÄ£Balada Injector»î¶¯¡£Sucuri³Æ£¬Balada Injector¹¥»÷ԼĪÿÔ²úÉúÒ»´Î£¬Ã¿´Î¹¥»÷¶¼Ê¹ÓÃÐÂ×¢²áµÄÓòÃûÀ´ÈƹýÀ¹½ØÃûµ¥¡£Í¨³££¬¶ñÒâÈí¼þ»áÀûÓÃËùÓÐÒÑÖªºÍ×î½ü·¢ÏÖµÄÖ÷ÌâºÍ²å¼þ·ì϶£¬ÖØÒª×¢ÈëLinuxºóÃÅ¡£Sucuri¹Û²ìµ½µÄ×¢Èë²½ÖèÔ̺¬siteurl hack¡¢HTML×¢Èë¡¢Êý¾Ý¿â×¢ÈëºÍËÁÒâÎļþÉÏ´«¡£×êÑÐÈËÔ±¹À¼Æ£¬³¬¹ý100Íò¸öWordPressÍøÕ¾Òѱ»´Ë»î¶¯Ï°È¾¡£
https://blog.sucuri.net/2023/04/balada-injector-synopsis-of-a-massive-ongoing-wordpress-malware-campaign.html
5¡¢Microsoft°ä²¼MERCURYÓëDEV-1084ºÏ×÷¹¥»÷µÄ»ã±¨
4ÔÂ7ÈÕ£¬Microsoft°ä²¼Á˹ØÓÚMERCURYÓëDEV-1084ºÏ×÷¹¥»÷µÄ·ÖÎö»ã±¨¡£Microsoft¼ì²âµ½ÁËÓëÒÁÀÊÓйصÄMERCURYµÄ¹¥»÷»î¶¯¡£ÒÔǰµÄMERCURY¹¥»÷ÊÇÕë¶Ô±¾µØ»·¾³£¬È»¶ø£¬Õâ´Î¹¥»÷»¹Õë¶ÔÔÆ×ÊÔ´¡£MicrosoftÒÔΪ£¬Ëü¿ÉÄÜÓëDEV-1084ºÏ×÷£¬ºóÕßÔÚMERCURY³É¹¦½øÈëÖ¸±ê»·¾³ºóÖ´Ðй¥»÷¡£MERCURY¿ÉÄÜÀûÓÃ佨¸´ÀûÓÃÖеķì϶½øÐгõʼ½Ó¼û£¬Ö®ºó½«½Ó¼ûȨÏÞÒÆ½»¸øDEV-1084£¬¶øºóÖ´ÐпúËÅ¡¢³ÉÁ¢ÓƾÃÐÔ²¢ºáÏòÒÆ¶¯£¬Í¨³£±ØÒªÆÚ´ýÊýÖÜÉõÖÁÊýÔÂÄÜÁ¦½øÈëÏÂÒ»½×¶Î¡£
https://www.microsoft.com/en-us/security/blog/2023/04/07/mercury-and-dev-1084-destructive-attack-on-hybrid-environment/
6¡¢Cyfirma°ä²¼¹ØÓÚARES LeaksÔËÓª¡¢·¢Õ¹ºÍÄÜÁ¦µÄ·ÖÎö
ýÌå4ÔÂ8ÈÕ±¨Â·£¬Cyfirma°ä²¼¹ØÓÚÐÂÍþв×éÖ¯ARES LeaksµÄ·ÖÎö»ã±¨¡£×ÔBreachedForum¹Ø¹ØÒÔÀ´£¬ARES Leaks»î¶¯ÓÐËùÔö³¤£¬Åú×¢ÔÚ²»¾ÃµÄ½«À´ËüÓпÉÄܳÉΪ±¸Ñ¡¹æ»®Ö®Ò»¡£OSINTËÑË÷·¢ÏÖARES GroupµÄÖÎÀíÔ±ÏúÊÛÁãÈÕ·ì϶£¬Åú×¢¸Ã×éÖ¯ÔÚÀûÓ÷ì϶À´¹¥»÷»µÏµÍ³¡£¸Ã×éÖ¯ÓÉÉøÈë²âÊÔÈËÔ±ºÍ¶ñÒâÈí¼þ¿ª·¢ÕßµÈ×ÊÔ´×é³É¡£³ýÁËÊý¾Ýй¶±í£¬Ëü»¹Ìṩ½©Ê¬ÍøÂçºÍDDoS·þÎñ¡£ARES»¹²û·¢³öÀàËÆcartelµÄÐÐΪ£¬»ý¼«×·ÇóÓëÆäËû¹¥»÷ÕßµÄÁªÏµ¡£
https://www.cyfirma.com/outofband/ares-leaks-emerging-cyber-crime-cartel/


¾©¹«Íø°²±¸11010802024551ºÅ