McLaren Health CareÔâµ½¹¥»÷220ÍòÈ˵ÄÐÅϢй¶
°ä²¼¹¦·ò 2023-11-13¾Ý11ÔÂ10ÈÕ±¨Â·£¬McLaren Health Care(Âõ¿Â×)Åû¶ÁË7ÔÂÖÁ8Ô²úÉúµÄһ·Êý¾Ýй¶ÊÂÎñ£¬Ó°ÏìÁË2192515È˵ÄÐÅÏ¢¡£Âõ¿Â×ÓÚ8ÔÂ22ÈÕ·¢ÏÖÁËÒì³£»î¶¯£¬µ÷²éÏÔʾ¹¥»÷Õß7ÔÂ28ÈÕÖÁ8ÔÂ23ÈÕδ¾ÊÚȨ½Ó¼ûÁËÆäÍøÂç¡£ÓÐÖ¤¾ÝÅú×¢£¬8ÔÂ31ÈÕ¹¥»÷Õß½Ó¼ûÁËÊý¾Ý£¬²¢Ö±µ½10ÔÂ10ÈÕÈ·ÈÏй¶Êý¾ÝµÄÀàÐÍ¡£Ö»¹Ü¸Ã»ú¹¹Ã»ÓÐй©Óйع¥»÷µÄ¸ü¶àϸ½Ú£¬µ«ALPHVÐû³Æ¶ÔÂõ¿Â׵Ĺ¥»÷ÕÆ¹Ü¡£ËûÃÇ»¹°ä²¼Á˱»µÁÊý¾ÝÑù±¾£¬²¢ÍþвҪÅÄÂôÓ°Ïì250ÍòÈ˵ÄÊý¾Ý¿â¡£
https://securityaffairs.com/154014/data-breach/mclaren-health-care-data-breach.html
2¡¢CloudflareÍøÕ¾Ôâµ½Anonymous SudanµÄDDoS¹¥»÷
¾ÝýÌå11ÔÂ9ÈÕ±¨Â·£¬CloudflareÍøÕ¾Ôâµ½Anonymous SudanµÄDDoS¹¥»÷¡£CloudflareÍøÕ¾å´»ú£¬ÏÔʾ¡°ÎÒÃǺܱ§À¢......µ«ÄúµÄÍÆËã»ú»òÍøÂç¿ÉÄÜÔÚ·¢ËÍ×Ô¶¯²éÎÊ¡£ÎªÁ˱£»¤GA»Æ½ð¼×Óû§£¬ÎÒÃÇ´Ë¿ÌÎÞ·¨´¦ÖÃÄúµÄÒªÇó¡±ÒÔ¼°Ò»¸ö¿´ÆðÀ´¡°Óе㲻ºÏ¾¢¡±µÄGoogle»Õ±ê¡£Cloudflare°µÊ¾DDoS¹¥»÷µ¼ÖÂwww.cloudflare.com³öÏÖÁ˼¸·ÖÖÓµÄÏνÓÎÊÌâ¡£µ«ÊÇûÓÐÓ°ÏìCloudflareµÄÈκηþÎñ»ò²úÆ·Ö°ÄÜ£¬Ò²Ã»Óпͻ§Êܵ½Ó°Ïì¡£Anonymous SudanÐû³Æ¶Ô´ËÊÂÕÆ¹Ü£¬²¢³Æ¹¥»÷³ÖÐø¹¦·òΪ1Ó×ʱ¡£
https://www.bleepingcomputer.com/news/technology/cloudflare-website-downed-by-ddos-attack-claimed-by-anonymous-sudan/
3¡¢MandiantÅû¶Sandworm¹¥»÷ÎÚ¿ËÀ¼µçÁ¦ÏµÍ³µÄÏêÇé
MandiantÔÚ11ÔÂ9ÈÕÅû¶ÁËSandwormÀûÓÃÕë¶ÔOTµÄÐÂÐ͹¥»÷Ó°ÏìÎÚ¿ËÀ¼µçÁ¦¹©¸øµÄ»î¶¯¡£¸ÃÊÂÎñ²úÉúÓÚ2022Äêµ×£¬Mandiant°µÊ¾ÕâÊÇÒ»´Î¶àÊÂÎñÍøÂç¹¥»÷£¬ÀûÓÃÁËÓ°ÏìICS/OTµÄз½Ê½¡£¹¥»÷ÕßÊ×ÏÈʹÓÃOT¼¶´ËÍâLotL¹¥»÷£¬¿ÉÄܻᴥ·¢Ö¸±ê±äµçÕ¾¶Ï·Æ÷£¬µ¼ÖÂÒâ±íÍ£µç£¬Í¬Ê±¶ÔÎÚ¿ËÀ¼¸÷µØµÄ¹Ø¼ü»ù´¡ÉèʩִÐдó¹æÄ£µ¼µ¯¹¥»÷¡£SandwormËæºóÔÚÖ¸±êµÄITϵͳÖÐ×°ÖÃÁËCADDYWIPERµÄбäÖÖ£¬´Ó¶øÖ´Ðеڶþ´Î·ÛËéÐÔ¹¥»÷¡£
https://www.mandiant.com/resources/blog/sandworm-disrupts-power-ukraine-operational-technology
4¡¢Imperial Kitten¹¥»÷Öж«µØÓòÔËÊä¡¢ÎïÁ÷ºÍ¿Æ¼¼¹«Ë¾
11ÔÂ9ÈÕ£¬CrowdStrike¹«¿ªÁËImperial KittenÕë¶ÔÖж«µØÓòÔËÊä¡¢ÎïÁ÷ºÍ¿Æ¼¼¹«Ë¾µÄµÄÐÂÒ»Âֻ¡£10Ô·ݣ¬¹¥»÷Õ߯ðÍ··Ö·¢ÒÔ¡°¹¤×÷ÕÐÆ¸¡±Ö÷Ì⣬Ô̺¬¶ñÒâExcel¸½¼þµÄ´¹µöÓʼþ¡£´ò¿ªºó¶ñÒâºê´úÂë»áÌáÈ¡Á½¸öÅú´¦ÖÃÎļþ£¬ËüÃÇ´´½¨ÓƾÃÐÔ²¢ÔËÐÐpayloadÀ´½øÐз´Ïòshell½Ó¼û¡£¶øºó£¬¹¥»÷ÕßʹÓÃPAExecµÈ¹¤¾ßºáÏòÒÆ¶¯ÒÔÔ¶³Ìִǰ¹ý³Ì£¬Ê¹ÓÃNetScan¿úËÅÍøÂ磬ʹÓÃProcDump´ÓϵͳÄÚ´æÖлñȡʹ´¦£¬Ê¹ÓÃ×Ô½ç˵¶ñÒâÈí¼þIMAPLoaderºÍStandardKeyboardÓëC2·þÎñÆ÷ͨѶ¡£
https://www.crowdstrike.com/blog/imperial-kitten-deploys-novel-malware-families/
5¡¢Î¢Èí³ÆSysAid·ì϶CVE-2023-47246±»ÓÃÀ´·Ö·¢Clop
ýÌå11ÔÂ9Èճƣ¬¹¥»÷ÕßÔÚÀûÓ÷þÎñÖÎÀíÈí¼þSysAidÖеķì϶½Ó¼ûÆóÒµµÄ·þÎñÆ÷À´ÇÔÈ¡Êý¾Ý£¬²¢²¿ÊðÀÕË÷Èí¼þClop¡£ÕâÊÇÒ»¸öõè¾¶±éÀú·ì϶£¨CVE-2023-47246£©£¬ÔÚºÚ¿ÍÀûÓø÷ì϶ÈëÇÖÄÚ²¿·þÎñÆ÷ºóÓÚ11ÔÂ2ÈÕ±»·¢ÏÖ£¬SysAidÔÚµ÷²éºó¹«¿ªÁ˹¥»÷µÄ¼¼Êõϸ½Ú¡£Î¢Èí´Ë¿ÌÈ·¶¨£¬¸Ã·ì϶±»Lace Tempest£¨ÓÖ³ÆFin11ºÍTA505£©ÓÃÀ´²¿ÊðÀÕË÷Èí¼þClop¡£SysAidÒѰ䲼·ì϶²¹¶¡£¬½¨ÒéËùÓÐЧ»§µ±¼´×°ÖøüС£
https://www.bleepingcomputer.com/news/security/microsoft-sysaid-zero-day-flaw-exploited-in-clop-ransomware-attacks/
6¡¢Kaspersky°ä²¼¹ØÓÚDucktail¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨
11ÔÂ10ÈÕ£¬Kaspersky°ä²¼Á˹ØÓÚDucktail¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£DucktailÊÇÒ»¸ö¶ñÒâÈí¼þ¼Ò×壬×Ô2021ÄêϰëÄêÒÔÀ´Ò»Ïò»îÔ¾£¬Ö¼ÔÚÇÔÈ¡FacebookÆóÒµÕÊ»§¡£±¾»ã±¨·ÖÎöÁË×î½üµÄÒ»´Î»î¶¯£¬3ÔÂÖÁ10ÔÂÉÏÑ®£¬ÖØÒªÕë¶ÔÓªÏúרҵÈËÔ±¡£ÓëÒÔÍùÒÀÀµ.NETÀûÓ÷¨Ê½µÄ»î¶¯·ÖÆç£¬Õâ´Î»î¶¯Ê¹ÓÃÁËDelphi¡£¸Ã»î¶¯·¢ËÍÔ̺¬¹«Ë¾Ð²úƷͼƬºÍ¼Ù×°³ÉPDFµÄ¶ñÒâ¿ÉÖ´ÐÐÎļþµÄÎĵµ£¬Ö¼ÔÚ´«²¼Ð°汾µÄDucktail¡£
https://securelist.com/ducktail-fashion-week/111017/


¾©¹«Íø°²±¸11010802024551ºÅ