ÃÀ¹úPurFoodsÔâµ½ÀÕË÷¹¥»÷Ô¼120ÍòÓû§µÄÐÅϢй¶

°ä²¼¹¦·ò 2023-08-30

1¡¢ÃÀ¹úPurFoodsÔâµ½ÀÕË÷¹¥»÷Ô¼120ÍòÓû§µÄÐÅϢй¶


¾ÝýÌå8ÔÂ28ÈÕ±¨Â· £¬ÃÀ¹ú²ÍÒû¹«Ë¾PurFoods¶ÁËһ·ӰÏ쳬¹ý120ÍòÈ˵ÄÊý¾Ýй¶ÊÂÎñ¡£¸Ã¹«Ë¾³Æ £¬ËüÓÚ2ÔÂ22ÈÕ·¢ÏÔìäÍøÂçÉϵĿÉÒɻ¡£µ÷²éÈ·¶¨ £¬¹¥»÷²úÉúÓÚ1ÔÂ16ÈÕÖÁ2ÔÂ22ÈÕ £¬µ¼Ö²¿ÃÅÎļþ±»¼ÓÃÜ¡£Éî¿Ìµ÷²éÓÚ7ÔÂ10ÈÕʵÏÖ £¬·¢ÏֺڿͽӼûÁ˼ÝÕÕ¡¢Éí·ÝÖ¤ºÅ¡¢½ðÈÚÕË»§ÐÅÏ¢¡¢Ö§¸¶¿¨ÐÅÏ¢ºÍÒ½ÖÎÐÅÏ¢µÈÊý¾Ý¡£Õâ´ÎÊý¾Ýй¶ӰÏìÁ˿ͻ§¡¢Ô±¹¤ÒÔ¼°¶ÀÁ¢³Ð°üÉÌ £¬Éæ¼°1237681ÈË £¬PurFoods½«Í¨¹ýKrollΪËûÃÇÌṩ12¸öÔµÄÐÅÓþ¼à¿ØºÍÉí·Ý±£»¤·þÎñ¡£


https://therecord.media/purfoods-delivery-service-reports-data-breach


2¡¢¶à¹ú½áºÏ·¨ÂÉÐж¯Duck Huntµ·»Ù½©Ê¬ÍøÂçQakbot 


SymantecÔÚ8ÔÂ30ÈÕ³Æ £¬·¨ÂÉÐж¯Duck Hunt³É¹¦µ·»ÙÁ˽©Ê¬ÍøÂçQakbot¡£¸ÃÐж¯ÓÉÃÀ¹úÁª¹úµ÷²é¾ÖºÍ˾·¨²¿Ç£Í· £¬ÒÔ¼°·¨¹ú¡¢µÂ¹ú¡¢ºÉÀ¼¡¢Ó¢¹ú¡¢ÂÞÂíÄáÑǺÍÀ­ÍÑάÑǵȹú²Î¼Ó¡£·¨ÂÉÈËÔ±ÒÑ´Ó³¬¹ý70Íǫ̀±»Ï°È¾µÄÍÆËã»úÖÐɾ³ýÁËQakbot¶ñÒâÈí¼þ £¬²¢²é»ñÁ˼ÛÖµ860ÍòÃÀÔªµÄ¼ÓÃÜÇ®±Ò¡£QakbotÊÇÔËÐй¦·ò×µÄ½©Ê¬ÍøÂçÖ®Ò» £¬ÓÚ2007Äê³õ´Î³öÏÖ £¬½öÔÚ´Óǰ18¸öÔ¾ÍÒÑÔì³ÉÁ˳¬¹ý5800ÍòÃÀÔªµÄËðʧ¡£


https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/qakbot-takedown-disruption


3¡¢¿ÕÖн»Í¨¹ÜÔìϵͳ崻úµ¼ÖÂÓ¢¹úº½°à´óÃæ»ýÈ¡µÞºÍÑÓÎó


¾Ý8ÔÂ28ÈÕ±¨Â· £¬Ó¢¹ú¿ÕÖн»Í¨¹ÜÔìϵͳ崻ú £¬ÊýÊ®Íò´î¿ÍµÄÐгÌÊܵ½Ó°Ïì¡£¹ú¶È¿ÕÖн»Í¨¹ÜÔìÌṩÉÌNATS³ÆËüÓöµ½ÁË¡°¼¼ÊõÎÊÌ⡱ £¬²¢Ö´ÐÐÁ˽»Í¨Á÷Á¿ÏÞ¶ÈÒÔÊØ»¤°²È«¡£¸ÃÎÊÌâµ¼ÖÂÓ¢¹ú¸÷µØº½°à´óÃæ»ýÑÓÎóºÍÈ¡µÞ £¬»¹¶ÔÕû¸öÅ·Ö޵ĺ½°à²úÉúÁËÁ¬Ëø·´Ó³ £¬Ò»Ð©º½¿Õ¹«Ë¾È¡µÞÁËÍù·µÓ¢¹úµÄº½°à¡£NATSÒѾÍÕâ´ÎÖжÏÊÂÎñÖÂǸ £¬²¢°µÊ¾ÔÚÖÂÁ¦ÒÔ¾¡¿ì½â¾öÎÊÌâ¡£


https://www.hackread.com/uk-air-traffic-control-system-collapses-travel-chaos/


4¡¢Sophos³ÆÀûÓ÷ì϶CVE-2023-3519µÄ¹¥»÷ÓëFIN8ÓйØ


8ÔÂ28ÈÕ±¨Â· £¬ÓëFIN8ÓйصĹ¥»÷ÕßÀûÓÃÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2023-3519£©¹¥»÷Citrix NetScaler¡£8ÔÂ2ÈÕ £¬Óл㱨³ÆÔÚCitrix·þÎñÆ÷Öз¢ÏÖÁË640¸öWebshell £¬Á½Öܺó £¬ÕâÒ»Êý×ÖÔö³¤µ½1952¸ö¡£Sophos³Æ £¬STAC4663ÔÚÀûÓø÷ì϶ £¬²¢ÒÔΪÕâÊDZ¾ÔÂÔçЩʱ³½±¨Â·µÄͳһ»î¶¯µÄÒ»²¿ÃÅ¡£Sophos´§¶È £¬¸Ã»î¶¯ÓëFIN8Óп϶¨¹ØÁª £¬ÕâÒ»´§¶È»ùÓÚÓòÃûµÄ¿úËÅ¡¢plink¡¢BlueVPSÍйܡ¢²»Ñ°³£µÄPowerShell¾ç±¾ºÍPuTTY°²È«¸´Ôì¡£

  

https://www.bleepingcomputer.com/news/security/attacks-on-citrix-netscaler-systems-linked-to-ransomware-actor/


5¡¢×êÑÐÈËÔ±·¢ÏÖÄܹ»Í¨¹ýSkypeÀûÓÃÈ·¶¨Ö¸±êµÄIPµØÖ·


ýÌå8ÔÂ28ÈÕ³Æ £¬×êÑÐÈËÔ±Yossi·¢ÏÖÄܹ»Í¨¹ýSkypeÒÆ¶¯ÀûÓ÷¢ËÍÁ´½ÓÀ´»ñȡָ±êµÄIPµØÖ·¡£¹¥»÷Ö»±ØÒªÖ¸±ê´ò¿ªÐÂÎż´¿É £¬²»±ØÖصã»÷Á´½Ó»òÒÔÆäËü·½Ê½Óë¹¥»÷Õß½»»¥¡£YossiÓÚ±¾Ô³õÏò΢Èí»ã±¨Á˸÷ì϶ £¬µ«Î¢Èí×î³õµ­»¯Á˸ÃÎÊÌâ £¬²¢Ã»ÓаµÊ¾½«½¨¸´¸Ã·ì϶¡£°²È«¼ÇÕß²âÊÔ·¢ÏÖ £¬µ±Ê¹ÓÃVPNÏνӵ½Skypeʱ £¬ÒÔ¼°ÔÚ²»Ê¹ÓÃVPNµÄÇé¿öÏÂÏνӵ½¹«¹²Wi-FiÍøÂçʱ £¬¸Ã¼¼Êõ¶¼ÓÐЧ¡£ÔÙ´ÎÁªÏµÎ¢Èíºó £¬¸Ã¹«Ë¾°µÊ¾´òËãÔÚ¼´½«°ä²¼µÄ¸üÐÂÖнâ¾ö¸ÃÎÊÌâ


https://securityaffairs.com/150000/hacking/grabbing-ip-addr-via-skype-mobile-app.html


6¡¢Trend Micro°ä²¼ÐÂAndroid¶ñÒâÈí¼þMMRatµÄ·ÖÎö»ã±¨


8ÔÂ29ÈÕ £¬Trend Micro°ä²¼Á˹ØÓÚеÄAndroid¶ñÒâÈí¼þMMRatµÄ·ÖÎö»ã±¨¡£MMRatÓÚ6ÔÂÏÂÑ®³õ´Î±»·¢ÏÖ £¬ÖØÒªÕë¶Ô¶«ÄÏÑǵØÓò £¬²¢ÇÒÔÚVirusTotalµÈɱ¶¾É¨Ãè·þÎñÖÐÈÔδ±»·¢ÏÖ¡£ËüÄܹ»ÇÔÈ¡Óû§ÊäÈëºÍÆÁÄ»ÄÚÈÝ £¬»¹Äܹ»Í¨¹ý¸÷À༼ÊõÔ¶³Ì½ÚÔìÖ¸±êÉ豸 £¬²¢Ö´ÐÐÒøÐÐڲƭ¡£´Ë±í £¬¸Ã¶ñÒâÈí¼þʹÓÃÁË»ùÓÚºÍ̸»º³åÇø£¨±ðÃûProtobuf£©µÄÌØÊâϵ½ç˵C&CºÍ̸ £¬¿ÉÌá¸ßÆäÔÚ´«Êä´óÁ¿Êý¾ÝʱµÄ»úÄÜ¡£Éв»È·¶¨¶ñÒâÈí¼þ×î³õÊÇÈôºÎ´«²¼µÄ £¬µ«ËüÊÇͨ¹ý¼Ù×°³É¹Ù·½ÀûÓÃÉ̵êµÄÍøÕ¾·Ö·¢µÄ¡£


https://www.trendmicro.com/en_us/research/23/h/mmrat-carries-out-bank-fraud-via-fake-app-stores.html