ÔËÓªÉÌDP WorldÔâµ½¹¥»÷µ¼Ö°ĴóÀûÑǶà¸ö¸Û¿Ú¹Ø¹Ø

°ä²¼¹¦·ò 2023-11-14

1¡¢ÔËÓªÉÌDP WorldÔâµ½¹¥»÷µ¼Ö°ĴóÀûÑǶà¸ö¸Û¿Ú¹Ø¹Ø


¾ÝýÌå11ÔÂ13ÈÕ±¨Â· £¬ÎïÁ÷¹«Ë¾DP World AustraliaÔâµ½¹¥»÷ £¬µ¼Ö°ĴóÀûÑǵÄ4¸öÖØÒª¸Û¿Ú¹Ø¹Ø¡£DP World´¦ÖðĴóÀûÑÇ40%µÄ¼¯×°ÏäÒµÎñ £¬ÉêÃ÷³Æ £¬11ÔÂ10ÈÕµÄÍøÂç¹¥»÷Ó°ÏìÁËÆä¸Û¿ÚµÄ½·»õÔËÒµÎñ¡£×ÔÉÏÖÜÎåÒÔÀ´ £¬Ô¼30000¸ö¼¯×°ÏäÒ»ÏòûÓб»Òƶ¯ £¬²¢ÇÒÕ¼ÂúÁË¿ÉÓõĴ洢¿Õ¼ä £¬Ô¤¼ÆËðʧ´ïÊý°ÙÍòÃÀÔª¡£Ä¿Ç° £¬ÔËÓªÔÚÖ𲽸´Ô­ £¬ÉÐÎÞ¹¥»÷ÍÅ»ïÐû³Æ¶Ô´ËÊÂÕÆ¹Ü¡£


https://www.bleepingcomputer.com/news/security/dp-world-cyberattack-blocks-thousands-of-containers-in-ports/


2¡¢¹¥»÷ÕßÔÚDollyÖ§¸¶²¿ÃÅÊê½ðºóÈÔÑ¡Ôñ¹«¿ªµÁÈ¡µÄÊý¾Ý


ýÌå11ÔÂ10ÈÕ³Æ £¬ÔÚDolly.comÖ§¸¶²¿ÃÅÊê½ðºó £¬¹¥»÷ÕßÒÀȻѡÔñ¹«¿ªµÁÈ¡µÄÊý¾Ý¡£Dolly.comÔÚ8ÔÂÄ©»ò9Ô³õµÄij¸öʱ³½Ôâµ½ÈëÇÖ £¬ÐÅÓþ¿¨¾ßÌåÐÅÏ¢ºÍDolly.comÄÚ²¿ÏµÍ³µÄÖÎÀíԱƾ֤µÈÃô¸ÐÊý¾Ýй¶¡£¹¥»÷Õߺ͸ù«Ë¾Ö®¼äµÄÒ»·âÈÕÆÚΪ9ÔÂ7ÈÕµÄÓʼþÏÔʾ £¬DollyÔÞ³ÉÖ§¸¶Êê½ð¡£Æ¾¾Ý¹¥»÷ÕßµÄ˵·¨ £¬¸Ã¹«Ë¾µÄÈ·Ö§¸¶ÁËÊê½ð £¬µ«²¢²»¼°ÒÔÂú×ãËûÃǵÄÒªÇ󡣸ÃÍÅ»ïûÓÐÍË»ØÊê½ð £¬²¢ÇÒ¹«¿ªÁËй¶Êý¾Ý¡£Î¨Ò»ÖµµÃÇìÐÒµÄÊÇ £¬¿ÉÏÂÔØµÄÎļþÔÚ°ä²¼Ò»Öܺó±»É¾³ý¡£


https://securityaffairs.com/153975/cyber-crime/dolly-com-pays-ransom.html


3¡¢¼ÓÃÜÂòÂôƽ̨PoloniexÔâµ½¹¥»÷Ëðʧ³¬¹ý1ÒÚÃÀÔª


¾Ý11ÔÂ13ÈÕ±¨Â· £¬ºÚ¿Í´Ó¼ÓÃÜÇ®±ÒÂòÂôƽ̨PoloniexÇÔÈ¡Á˳¬¹ý1ÒÚÃÀÔª¡£¸Ãƽ̨ÔÚÉ罻ýÌåÉÏ֤ʵ £¬ÔÚµ÷²éÕâÆðÊÂÎñ £¬²¢´òËãÈ«¶îÅâ³¥ÊÜÓ°ÏìµÄ¿Í»§¡£Poloniex°µÊ¾½«ÏòºÚ¿ÍÖ§¸¶±»µÁ×ʽðµÄ5%×÷ΪÉͽ𠣬µ«Ô¸ÆäËÍ»¹×ʽð¡£Poloniex³ÆËûÃǵÄÍŶÓÒѳɹ¦¼ø±ð²¢¶³½áÁËÓëºÚ¿ÍµØÖ·ÓйصIJ¿ÃÅ×ʲú¡£Ä¿Ç° £¬ËðʧÔÚ¿É¿ØÁìÓòÄÚ £¬PoloniexµÄ½»Ò×ÊÕÈëÄܹ»Ìí²¹ÕâЩËðʧ¡£°²È«¹«Ë¾Slow Mist°µÊ¾ËðʧԼΪ1.3ÒÚÃÀÔª £¬Beosin¹«Ë¾¹À¼ÆËðʧΪ1.14ÒÚÃÀÔª¡£


https://therecord.media/poloniex-cryptocurrency-platform-millions-stolen


4¡¢Medusa³ÆÒÑÈëÇÖ¼ÓÄôó½ðÈڿƼ¼¹«Ë¾Moneris²¢ÀÕË÷600ÍòÃÀÔª


11ÔÂ14ÈÕ±¨Â· £¬ÀÕË÷ÍÅ»ïMedusaÔÚÖÜÒ»Ðû³ÆËûÃǹ¥»÷ÁËMoneris £¬²¢¸ø¸Ã¹«Ë¾9ÌìµÄ¹¦·òÖ§¸¶600ÍòÃÀÔªµÄÊê½ð¡£MonerisÊǼÓÄôóÁ½¼Ò×î´óµÄÒøÐд´½¨µÄÒ»¼Ò¿Æ¼¼¹«Ë¾ £¬Ëü°µÊ¾Òѳɹ¦ÕмÜÁË×î½üµÄÀÕË÷¹¥»÷¡£¹Ø¼üÊý¾ÝûÓб»½Ó¼û £¬Ò²Ã»ÓÐÊê½ðÒªÇó¡£Moneris½²»°ÈË˵ £¬µÄÈ·ÓÐ±í²¿ÈËÔ±ÊÔͼÈëÇÖMonerisµÄϵͳ £¬µ«ËûÃǵÄÍŶӶÔÕâÒ»ÊÂÎñ½øÐÐÁËÈ«ÃæµÄÉó¼ÆºÍ·ÖÎö £¬µÃ³öµÄ½áÂÛÊÇûÓд¥·¢ÆäÊý×ÖÃÔʧ·À»¤Õþ²ß¡£MonerisÔøÔÚ9Ô·ݲúÉúϵͳÖжÏ £¬Ó°ÏìÁ˼ÓÄôó¸÷µØµÄÊýÊ®¼ÒÆóÒµ¡£


https://therecord.media/moneris-canada-ransomware-attack-prevented


5¡¢×êÑÐÈËÔ±·¢ÏÖÀûÓÃGoogle Ads·Ö·¢Ä¾Âí»¯CPU-ZµÄ»î¶¯


MalwarebytesÔÚ11ÔÂ8ÈÕÅû¶Á˹¥»÷ÕßÀÄÓÃGoogle Ads·Ö·¢Ä¾Âí»¯CPU-ZµÄ»î¶¯¡£Ä¾Âí»¯CPU-ZµÄ¶ñÒâ¹È¸è¸æ°×ÍйÜÔںϷ¨WindowsÐÂÎÅÍøÕ¾WindowsReportµÄ¿Ë¡¸±±¾ÉÏ £¬½Ó¼ûÕßµã»÷¸æ°×ºó»á±»³Á¶¨Ïòµ½¶ñÒâÍøÕ¾¡£¶ñÒâÍøÕ¾ÉÏÍйܾ­¹ýÊý×ÖÊðÃûµÄCPU-Z×°Ö÷¨Ê½£¨MSIÎļþ£© £¬ÆäÖÐÔ̺¬¶ñÒâÈí¼þ¼ÓÔØ·¨Ê½FakeBatµÄPowerShell¾ç±¾¡£¼ÓÔØ·¨Ê½´ÓÔ¶³ÌURL»ñÈ¡Redline Stealer payload £¬²¢ÔÚÖ¸±êÍÆËã»úÉÏÆô¶¯Ëü¡£


https://www.malwarebytes.com/blog/threat-intelligence/2023/11/malvertiser-copies-pc-news-site-to-deliver-infostealer


6¡¢Blackberry°ä²¼¹ØÓÚBiBi-Linux WiperµÄ·ÖÎö»ã±¨


11ÔÂ10ÈÕ £¬Blackberry°ä²¼Á˹ØÓÚBiBi-Linux WiperµÄ·ÖÎö»ã±¨¡£×êÑÐÈËÔ±Ö®Ç°ÔøÔÚÕë¶ÔÒÔÉ«Áй«Ë¾µÄ¹¥»÷Öз¢ÏÖÁËÐÂÐͲÁ³ý¶ñÒâÈí¼þBiBi-Linux Wiper £¬Ö®ºóBlackBerry·¢ÏÖÁËÒ»¸öÕë¶ÔWindowsϵͳµÄ±äÌå £¬²¢³ÆÎªBiBi-Windows Wiper¡£¸Ã±äÌå¾Ý³Æ±àÒëÓÚ10ÔÂ21ÈÕ £¬ÓëLinux±äÌåµÄÀàËÆÖ®´¦ÊǶàÏß³ÌÖ°ÄÜ £¬ËüÔËÐÐ12¸öÏ̺߳Í8¸ö´¦ÖÃÆ÷Äںˡ£Õâ¸öWindows±äÌå֤ʵÁË¿ª·¢²Á³ý·¨Ê½µÄ¹¥»÷ÕßÈÔÔÚ³ÖÐø¹¹½¨¶ñÒâÈí¼þ £¬²¢Åú×¢¹¥»÷ÁìÓòÀ©´óµ½ÁËÖÕ¶ËÓû§ÍÆËã»úºÍÀûÓ÷þÎñÆ÷¡£


https://blogs.blackberry.com/en/2023/11/bibi-wiper-used-in-the-israel-hamas-war-now-runs-on-windows