ÃÀ¹úPJ&A³ÆÍøÂç¹¥»÷µ¼ÖÂÆä½ü900Íò»¼ÕßµÄÐÅϢй¶

°ä²¼¹¦·ò 2023-11-17
1¡¢ÃÀ¹úPJ&A³ÆÍøÂç¹¥»÷µ¼ÖÂÆä½ü900Íò»¼ÕßµÄÐÅϢй¶


¾Ý11ÔÂ15ÈÕ±¨Â·£¬PJ&A(Perry Johnson & Associates)й©£¬½ñÄê3ÔµÄÒ»´ÎÍøÂç¹¥»÷й¶Á˽ü900Íò»¼ÕßµÄÐÅÏ¢¡£PJ&AΪÃÀ¹úµÄÒ½ÁÆ»ú¹¹ÌṩҽÁÆ×ªÂ¼·þÎñ£¬¸Ã¹«Ë¾°µÊ¾¹¥»÷ÕßÈëÇÖÁËËûÃǵÄϵͳ£¬²¢ÔÚ3ÔÂ27ÈÕÖÁ5ÔÂ2ÈÕÆÚ¼ä½øÐÐÁ˽Ӽû¡£Ð¹Â¶Êý¾ÝÔ̺¬ÐÕÃû¡¢²¡ÀúºÅ¡¢Éç»á°²È«ºÅÂë(SSN)¡¢±£ÏÕÐÅÏ¢ºÍÒ½ÁÆ×ªÂ¼ÎļþµÈ£¬Ó°ÏìÁË8952212Ãû»¼Õß¡£14ÈÕ£¬Å¦Ô¼×î´óµÄÒ½ÁÆÌṩÉÌNorthwell Health³Æ£¬ PJ&AÔâµ½¹¥»÷µ¼ÖÂÆäÊý¾ÝÔÚ4ÔÂ7ÈÕÖÁ19ÈÕ±»µÁ£¬Éæ¼°³¬¹ý380ÍòÈË¡£


https://www.bleepingcomputer.com/news/security/pj-and-a-says-cyberattack-exposed-data-of-nearly-9-million-patients/


2¡¢Ô½ÄÏÓÊÕþ¹«Ë¾ÅäÖÃÃýÎóµ¼ÖÂÔ¼1.2TBÊý¾Ýй¶


ýÌå11ÔÂ16Èճƣ¬×êÑÐÍŶӷ¢ÏÖÁËÒ»¸öÊôÓÚÔ½ÄÏÓÊÕþ¹«Ë¾µÄÊ¢¿ªKibanaÊ·ý¡£KibanaÊÇÒ»¸öÓÃÓÚÊý¾ÝËÑË÷ºÍ·ÖÎöµÄ¿ÉÊÓ»¯½ÚÔìÃæ°å£¬Ô®ÊÔìóÒµ´¦ÖôóÁ¿Êý¾Ý¡£ÔÚ·¢ÏÖʱ£¬Êý¾Ý´æ´¢Ô̺¬2.26ÒÚ¸ö¼Í¼ÊÂÎñ£¬¹²²úÉúÁË1.2TBÊý¾Ý£¬²¢ÇÒÔÚʵʱ¸üС£Ð¹Â¶ÐÅÏ¢Ô̺¬°²È«ÈÕÖ¾£¬ÒÔ¼°Ô±¹¤µÄÐÕÃûºÍµç×ÓÓʼþ¡£Ä¿Ç°£¬¸Ã¹«Ë¾Òѽ«ÕâЩÊý¾Ý±£»¤ÆðÀ´¡£


https://securityaffairs.com/154271/data-breach/vietnam-post-data-leak.html


3¡¢ºÚ¿ÍÐû³ÆÒÑÈëÇÖPlume¹«Ë¾²¢ÍøÂ糬¹ý1500ÍòÐÐÊý¾Ý


¾ÝýÌå11ÔÂ15ÈÕ±¨Â·£¬¹¥»÷ÕßÐû³ÆÇÔÈ¡ÁËÖÇÄÜWiFiÌṩÉÌPlume³¬¹ý20GBµÄÊý¾Ý¿â£¬ÆäÖÐÔ̺¬³¬¹ý1500ÍòÐÐÊý¾Ý¡£PlumeÉÐδ֤ʵÕâÒ»ÐÂÎÅ£¬°µÊ¾ÒÑÏàʶ¹¥»÷ÕßµÄ˵·¨£¬²¢·¢Õ¹µ÷²éÒÔºËʵÕâЩ˵·¨¡£ÓÉÓÚ¶ÔPlumeµÄ»ØÓ¦²»Âú£¬ºÚ¿Í°ä²¼ÁËÁ½¸öCSVÎļþ£¬Ô̺¬´óÁ¿¿Í»§ºÍÔ±¹¤µÄÐÅÏ¢¡£´Ë±í£¬ºÚ¿Í»¹Ð¹Â©Õâ´Îй¶ÊÂÎñÊÇÓÉPlumeµÄÒ»ÃûǰԱ¹¤´Ù³ÉµÄ£¬ËûÓÚ2023ÄêÍÑÀ빫˾£¬µ«ÒÀȻռÓнӼûȨÏÞ¡£¹¥»÷Õ߸øÁ˸ù«Ë¾48Ó×ʱÀ´Âú×ãËûÃǵÄÒªÇ󣬲»È»½«Ð¹Â¶¸üÎÞÊý¾Ý¡£


https://www.hackread.com/hackers-smart-wi-fi-provider-plume-data-breach/


4¡¢FBIµÈ»ú¹¹½áºÏÅû¶ÀÕË÷ÍÅ»ïRhysidaµÄTTPµÈÐÅÏ¢


11ÔÂ15ÈÕ£¬CISA¡¢FBIºÍMS-ISAC°ä²¼Á˹ØÓÚÀÕË÷ÍÅ»ïRhysidaµÄ½áºÏÍøÂ簲ȫÕ÷ѯ(CSA)¡£¸ÃÕ÷ѯÌṩÁ˽ØÖÁ9Ôµĵ÷²éÆÚ¼ä·¢ÏÖµÄIoC¡¢¼ì²âÐÅÏ¢ÒÔ¼°RhysidaµÄÕ½Êõ¡¢¼¼ÊõºÍ·¨Ê½(TTP)¡£Rhysida×Ô½ñÄê5ÔÂÒÔÀ´Ò»Ïò»îÔ¾£¬ÒÑÓÐÖÁÉÙÓÐ62¼Ò¹«Ë¾Ôâµ½Æä¹¥»÷¡£RhysidaÒÔRaaSµÄģʽ¹¥»÷½ÌÓý¡¢Ôì×÷¡¢ÐÅÏ¢¼¼ÊõÐÐÒµºÍµ±¾Ö»ú¹¹¡£´Ë±í£¬Rhysida»¹ÀûÓÃÁËÔ¶³Ì·þÎñ£¨ÈçVPNºÍRDP£©À´»ñµÃ¶Ô³õʼ½Ó¼û²¢Î¬³ÖÓÆ¾ÃÐÔ£¬²¢ÀûÓÃÁË´¹µö¹¥»÷ºÍZerologon·ì϶£¨CVE-2020-1472£©¡£


https://www.cisa.gov/news-events/alerts/2023/11/15/cisa-fbi-and-ms-isac-release-advisory-rhysida-ransomware


5¡¢McAfee·¢ÏÖÕë¶Ôº«¹ú´«²¼¶ñÒâÇÔÈ¡·¨Ê½µÄ´¹µö»î¶¯


11ÔÂ15ÈÕ£¬McAfee³ÆÆä·¢ÏÖÁËͨ¹ý´¹µöÍøÕ¾´«²¼¶ñÒâAndroidºÍiOSÐÅÏ¢ÇÔÈ¡·¨Ê½µÄ»î¶¯¡£¸Ã»î¶¯ÓÚ10Ô³õÆðÍ·»îÔ¾£¬ÒÑϰȾ200¶ą̀É豸£¬ËùÓÐÉ豸¶¼Î»ÓÚº«¹ú¡£¹¥»÷Õß×î³õͨ¹ý¶ÌÐÅ¿¿½üÖ¸±ê£¬²¢»á³¢ÊÔ×ªÒÆµ½LINE Messenger¡£¶øºó·¢ËÍÖ¸Ïò´¹µöÍøÕ¾µÄÁ´½Ó£¬¸ÃÍøÕ¾¼Ù×°³ÉCamtalk£¬ÓÕʹָ±êÏÂÔØ¶ñÒâAndroidºÍiOSÀûÓᣳýÁ˼ÙÒâÉç½»ÀûÓ㬸û»¹ÔÚÆä´¹µöÍøÕ¾ÖÐʹÓÃÁËÆäËüÖ÷Ìâ¡£Õâ´Î»î¶¯ÖØÒªÕë¶Ôº«¹ú£¬ÏÖÒÑ·¢ÏÖ10¸ö´¹µöÍøÕ¾£¬¶ñÒâÈí¼þ»áÇÔȡָ±êµÄµç»°ºÅÂë¡¢¹ØÁªÁªÏµÈ˺ͶÌÐŵÈ¡£


https://www.mcafee.com/blogs/other-blogs/mcafee-labs/fake-android-and-ios-apps-steal-sms-and-contacts-in-south-korea/


6¡¢Malwarebytes°ä²¼10Ô·ÝÀÕË÷Èí¼þÌ¬ÊÆµÄ·ÖÎö»ã±¨


MalwarebytesÔÚ11ÔÂ15ÈÕ°ä²¼ÁË10Ô·ÝÀÕË÷Èí¼þÌ¬ÊÆµÄ·ÖÎö»ã±¨¡£10Ô·Ý£¬ÀÕË÷ÍÅ»ïµÄÍøÕ¾ÉÏÁгöÁË318¸öеı»¹¥»÷Ö¸±ê¡£×î»îÔ¾µÄÊÇLockBit(64¸ö)¡¢NoEscape(40¸ö)ºÍPLAY(36¸ö)¡£ÓÐ3¸öÖØÒªµÄÀÕË÷ÍŻﱻ¹Ø¹Ø£¬±ðÀëÊÇRansomedVC¡¢RagnarºÍTrigona¡£ÕâÒ»¸öÔ³öÏÖÁËÒ»¸öеÄÀÕË÷ÍÅ»ïHunters International£¬ÒÉËÆÊÇHiveµÄ¸ÄÃû¡£Ôâµ½ÀÕË÷¹¥»÷×î¶àµÄ¹ú¶ÈÊÇÃÀ¹ú£¨148Æð£©£¬Æä´ÎÊÇÓ¢¹ú£¨34£©ºÍÒâ´óÀû£¨19£©¡£


https://www.malwarebytes.com/blog/threat-intelligence/2023/11/ransomware-review-november-2023