Brunswick CorporationÔâµ½¹¥»÷Ëðʧ¸ß´ï8500ÍòÃÀÔª
°ä²¼¹¦·ò 2023-08-041¡¢Brunswick CorporationÔâµ½¹¥»÷Ëðʧ¸ß´ï8500ÍòÃÀÔª
¾ÝýÌå8ÔÂ3ÈÕ±¨Â·£¬´¬²°Ôì×÷¹«Ë¾Brunswick CorporationÔâµ½ÍøÂç¹¥»÷£¬Ëðʧ¸ß´ï8500ÍòÃÀÔª¡£¸Ã¹«Ë¾2021ÄêÊÕÈë½ü60ÒÚÃÀÔª£¬ÒµÎñ±é¼°24¸ö¹ú¶È¡£¹¥»÷²úÉúÔÚ6ÔÂ13ÈÕ£¬Ó°ÏìÁ˸ù«Ë¾µÄϵͳºÍ²¿ÃÅÉèÊ©¡£ÉÐδ֤ʵÕâÊÇÀÕË÷¹¥»÷£¬µ«¸Ã¹«Ë¾°µÊ¾ÆäÔÚijЩ´¦ËùµÄÔËÓª±»ÆÈÖÕ³¡¡£¸Ã¹«Ë¾CEOй©£¬Õâ´Î°²È«ÊÂÎñ¶Ô¹«Ë¾µÚ¶þ¼¾¶ÈµÄ²ÆÕþ×é³ÉÁ¶¯²ÃðÐÔÓ°Ï죬Ôâµ½¹¥»÷ºóÆä»¨Á˾ÅÌìµÄ¹¦·ò²Å¸´ÔÕý³£ÔËÓª¡£Õâ´ÎÖжÏÖØÒªÓ°ÏìÁËÍÆ¶¯Æ÷ºÍ·¢Æð»úÁãÅä¼þÁìÓò£¬ÓÉÓÚÁÚ½ü¼¾¶ÈÄ©£¬Í¬ÆÚÄÚÆëÈ«¸´ÔµÄ»úÓöÓÐÏÞ¡£
https://therecord.media/marine-industry-giant-brunswick-lost-millions
2¡¢MicrosoftÅû¶NobeliumÀûÓÃTeamsÐÂÎŵĴ¹µö¹¥»÷»î¶¯
MicrosoftÔÚ8ÔÂ2ÈÕÅû¶Á˽üÆÚ¶íÂÞ˹ºÚ¿ÍÍÅ»ïNobelium£¨APT29£©ÓÐÕë¶ÔÐԵĴ¹µö¹¥»÷»î¶¯¡£¸Ã»î¶¯´Ó5ÔÂÏÂÑ®ÆðÍ·£¬Ó°ÏìÁ˲»µ½40¸öÆóÒµ£¬Éæ¼°µ±¾Ö¡¢·Çµ±¾Ö×éÖ¯(NGO)¡¢IT·þÎñ¡¢¼¼Êõ¡¢Ôì×÷ºÍýÌåÐÐÒµ¡£ÔÚÕâ´Î»î¶¯ÖУ¬¹¥»÷ÕßÀûÓÃÇÔÈ¡µÄMicrosoft 365×â»§À´´´½¨ÐµÄÓò£¬ÕâЩÓòÃû¿´ÆðÀ´ÏñÊǼ¼ÊõÖ§³ÖʵÌå¡£¶øºóÀûÓÃTeamsÐÂÎÅ·¢Ë͵ö¶ü£¬ÓÕʹָ±êÓû§ºË×¼¶à³É·ÖÉí·ÝÑéÖ¤£¨MFA£©£¬×îÖÕÖ¼ÔÚÇÔȡָ±ê×éÖ¯µÄƾ֤¡£
https://www.microsoft.com/en-us/security/blog/2023/08/02/midnight-blizzard-conducts-targeted-social-engineering-over-microsoft-teams/
3¡¢ºº±¤Íõ·¨¹ú·Ö¹«Ë¾ÒòÍøÕ¾ÅäÖÃÃýÎóµ¼ÖÂÍ´´¦µÈÐÅϢй¶
ýÌå8ÔÂ3Èճƣ¬ºº±¤Íõ·¨¹ú·Ö¹«Ë¾ÒòÍøÕ¾ÅäÖÃÃýÎ󣬵¼ÖÂÍ´´¦µÈÐÅϢй¶¡£6ÔÂ1ÈÕ£¬×êÑÐÍŶӷ¢ÏÖÁËÊôÓÚºº±¤Íõ·¨¹úÍøÕ¾µÄ¿É¹«¿ª½Ó¼ûµÄ»·¾³Îļþ(.env)£¬ÆäÖÐÔ̺¬¸÷ÀàÍ´´¦£¬¸ÃÎļþÍйÜÔÚÓÃÓÚ°ä²¼¹¤×÷»úÓöµÄ×ÓÓòÉÏ¡£Ö»¹Üй¶µÄÊý¾Ý²»¼°ÒÔÆëÈ«½ÚÔìÍøÕ¾£¬µ«ËüÄܹ»¼ò»¯¹¥»÷Õß½Ù³ÖÍøÕ¾µÄ¹ý³Ì¡£Ä¿Ç°£¬¸Ã¹«Ë¾ÒѾ½â¾öÁËÕâ¸öÎÊÌâ¡£2019Ä꣬ÓÉÓÚÀàËÆµÄÅäÖÃÃýÎ󣬷¨¹ú·Ö¹«Ë¾ÔøÐ¹Â¶Á˲ɰ캺±¤ÍõµÄ¶ùͯµÄPIIÐÅÏ¢¡£
https://cybernews.com/security/burger-king-data-leak/
4¡¢NoName057(16)Ðû³Æ¶ÔÒâ´óÀû¶à¼ÒÒøÐÐÔâµ½µÄ¹¥»÷ÕÆ¹Ü
¾Ý8ÔÂ3ÈÕ±¨Â·£¬ºÚ¿ÍÍÅ»ïNoName057(16)Ðû³Æ¶ÔÒâ´óÀûÒøÐÓ×¢ÆóÒµºÍµ±¾Ö»ú¹¹µÄ¹¥»÷ÕÆ¹Ü¡£Òâ´óÀûÍøÂ簲ȫ»ú¹¹ÔÚ±¾Öܶþ°µÊ¾£¬ÒѼì²âµ½ÖÁÉÙÎå¼ÒÒøÐеÄÍøÕ¾Ôâµ½DDoS¹¥»÷£¬ÆäÖÐÔ̺¬Òâ´óÀû×î´óµÄ½áºÏÊ¥±£ÂÞÒøÐС£NoName057(16)ÓÚ±¾ÖÜÒ»³õ´Î¶ÔÒâ´óÀûÌáÒé¹¥»÷£¬²¢ÓÚ8ÔÂ3ÈÕ³ÖÐø¡£³ýÁËÒøÐÐÖ®±í£¬¸ÃÍŻﻹÐû³ÆÈëÇÖÁËÒ»¼ÒÒâ´óÀû¹©Ë®¹«Ë¾¡¢Ò»¼ÒÈ«¹úÐÔóÒ×±¨Ö½ºÍÒ»¸ö¹«¹²½»Í¨µÄÍøÕ¾¡£½ØÖÁĿǰ£¬ÕâÐ©ÍøÕ¾ÈÔ´¦ÓڹعØ×´Ì¬¡£
https://therecord.media/russian-hackers-claim-attacks-on-italy
5¡¢ºÚ¿ÍÀûÓÃCVE-2023-3519ÔÚÊý°Ų̀Citrix·þÎñÆ÷×°ÖúóÃÅ
8ÔÂ2ÈÕ±¨Â·³Æ£¬Shadowserver Foundation·¢ÏÖÊý°Ų̀Citrix Netscaler ADCºÍGateway·þÎñÆ÷±»ÈëÇÖ²¢×°ÖúóÃÅ¡£CISA½üÆÚ°ä²¼¹«¸æ³Æ£¬¹¥»÷ÕßÔÚÀûÓÃRCE·ì϶£¨CVE-2023-3519£©ÔÚÒ×±»¹¥»÷µÄϵͳÖÐ×°ÖÃWeb shell¡£Shadowserver×î³õ»ã±¨£¬ÖÁÉÙÓÐ15000̨·þÎñÆ÷Ò×±»¹¥»÷£¬ÖØÒªÎ»ÓÚÃÀ¹úºÍµÂ¹ú¡£×îиüÐÂÖÐÏÔʾ£¬½ØÖÁ8ÔÂ1ÈÕ£¬¹¥»÷ÕßÒÑÔÚÖÁÉÙ581̨Citrix·þÎñÆ÷ÉÏ×°ÖÃÁËWebshell¡£CitrixÇ¿ÁÒ½¨ÒéÓû§×°ÖøüС£
https://securityaffairs.com/149083/hacking/phishing-facebook-campaign-salesforce-zero-day.html
6¡¢Group-IB°ä²¼Mysterious Team BangladeshµÄ·ÖÎö»ã±¨
8ÔÂ3ÈÕ£¬Group-IB°ä²¼Á˹ØÓÚºÚ¿ÍÍÅ»ïMysterious Team BangladeshµÄ·ÖÎö»ã±¨¡£¸ÃÍÅ»ï³ÉÁ¢ÓÚ2020Ä꣬×Ô2022Äê6ÔÂÒÔÀ´£¬ÒÑÖ´ÐÐÁ˳¬¹ý750´ÎDDoS¹¥»÷ºÍ78´ÎÍøÕ¾´Û¸Ä¹¥»÷£¬ÆäÊ×´´ÈËÊÇÔÚTelegramÉÏÒ»Ãû´úºÅΪD4RK_TSNµÄÓû§¡£¸ÃÍÅ»ïÖØÒªÕë¶ÔÓ¡¶ÈºÍÒÔÉ«ÁеÄÎïÁ÷¡¢µ±¾ÖºÍ½ðÈÚÐÐÒµ¡£ÔÚÈ«Á¦¹¥»÷֮ǰ£¬Æä»á½øÐжÌÔݵIJâÊÔ¹¥»÷£¬ÒÔ²é³Ö¸±ê¶ÔDDoS¹¥»÷µÄ·ÀÓùÄÜÁ¦¡£ÔÚijЩÇé¿öÏ£¬¸ÃÍÅ»ï¿ÉÄÜͨ¹ýÀûÓÃÒÑÖªµÄ·ì϶»ò°²È«ÐԽϲîµÄÃÜÂëÀ´½Ó¼ûÍøÂç·þÎñÆ÷ºÍÖÎÀíÃæ°å¡£
https://www.group-ib.com/blog/mysterious-team-bangladesh/


¾©¹«Íø°²±¸11010802024551ºÅ