ÃÀ¹ú¼ÓÖݳ¤Ì²ÊÐÔâµ½ÍøÂç¹¥»÷ÊÐÕþϵͳ¹Ø¹ØÊýÈÕ

°ä²¼¹¦·ò 2023-11-21
1¡¢ÃÀ¹ú¼ÓÖݳ¤Ì²ÊÐÔâµ½ÍøÂç¹¥»÷ÊÐÕþϵͳ¹Ø¹ØÊýÈÕ


¾ÝýÌå11ÔÂ18ÈÕ±¨Â· £¬ÃÀ¹ú¼ÓÀû¸£ÄáÑÇÖݳ¤Ì²ÊÐÔâµ½¹¥»÷ £¬¹Ø¹ØÁ˲¿ÃÅITϵͳÒÔÔ¤·À¹¥»÷´«²¼¡£¹¥»÷²úÉúÓÚ11ÔÂ14ÈÕ £¬²¢Î´Ó°Ï촹Σ·þÎñ £¬µ«¹«¹²ÊÂÒµ½É·ÑµÈ²¿ÃÅÔÚÏß·þÎñÊܵ½Ó°Ïì¡£½ØÖÁÉÏÖÜÎå £¬¸ÃÊÐÔ¤¼Æ¿ÉÄܱØÒª¼¸ÌìµÄ¹¦·ò½øÐи´Ô­¡£Ä¿Ç° £¬³¤Ì²ÊÐÒѰ䷢½øÈ봹Σ״̬¡£¹¥»÷ÈÔÔÚµ÷²éÖÐ £¬Éв»Ã÷ÏÔ¹¥»÷ÀàÐÍÒÔ¼°ÊÇ·ñ´æÔÚÊý¾Ýй¶ £¬Ò²Ã»Óй¥»÷ÕßÐû³Æ¶Ô´ËÊÂÕÆ¹Ü¡£


https://www.databreaches.net/long-beach-declares-local-emergency-after-cyber-incident/


2¡¢³¬¹ý200ÍòÍÁ¶úÆä¹«ÃñµÄÒßÃç½ÓÖּͼ±»¹«¿ªÔÚ°µÍø


¾Ý11ÔÂ20ÈÕ±¨Â· £¬ºÚ¿ÍÔÚ°µÍø¹«¿ªÁ˳¬¹ý200ÍòÍÁ¶úÆä¹«ÃñµÄ¾ßÌåÐÅÏ¢¡£Ð¹Â¶ÐÅÏ¢Ô̺¬Ò½ÉúºÍ»¼ÕßµÄÍÁ¶úÆäÉí·ÝÖ¤ºÅÂ루¼ò³ÆTCKN£©¡¢ÒßÃç½ÓÖÖÈÕÆÚºÍÀàÐÍ¡¢ÆäËüÒßÃç½ÓÖֺ͹©¸øÁ´ÏêÇéµÈ £¬¿ÉÄÜÔ´ÓÚÐÅϢй¶·ì϶¡£¹ÌÈ»Êý¾ÝÊÇ9ÔÂ10ÈÕй¶µÄ £¬µ«×êÑÐÈËÔ±ÒÔΪÊÂÎñ²úÉúÔÚ4ÔÂ4ÈÕ¡£´Ë±í £¬ÓÉÓÚ»¼ÕßµÄTCKN±»²¿ÃÅɾ¼õ £¬¶øÒ½ÉúµÄTCKNÔòÆëÈ«ÏÔʾ £¬ÕâÅú×¢ÕâЩÊý¾Ý¿ÉÄÜÊÇ´ÓÍÁ¶úÆäÒ½ÁÆÌṩÉÌ»òÎÀÉú²¿Ê¹ÓõÄÔÚÏ߯½Ì¨»ò·þÎñÖÐÇÔÈ¡µÄ¡£¸ÃÊÂÎñ¿ÉÄÜй¶Á˸ùúÔ¼70%Ò½ÉúµÄPII¡£


https://www.hackread.com/hacker-leaks-turkish-citizens-vaccination-records/


3¡¢Ä¦¸ùÊ¿µ¤Àû¾ÍÊý¾Ýй¶ÊÂÎñ´ï³ÉºÍ½âÔÞ³ÉÅâ³¥650ÍòÃÀÔª


ýÌå11ÔÂ17ÈÕ³Æ £¬Ä¦¸ùÊ¿µ¤ÀûÓë¸÷ÖݾÍÁ½ÆðÊý¾Ýй¶ÊÂÎñ´ï³ÉºÍ½â £¬Ô¸ÒâÅâ³¥650ÍòÃÀÔª¡£µ¼ÖÂËßËϵÄÊÂÎñ²úÉúÔÚ2016ÄêºÍ2019Äê¡£Õâ¼Ò¹«Ë¾ÀñƸÁËÒ»¼Òûº±¼û¾ÝÏú»Ù¾­ÑéµÄ¹«Ë¾´¦Öñ¨·ÏµÄÉ豸 £¬µ¼ÖÂÊý°ÙÍò¿Í»§µÄÓ×ÎÒÐÅÏ¢Ãæ¶Ô·çÏÕ¡£ÔÚµÚ¶þÆðÊÂÎñÖÐ £¬Ä¦¸ùÊ¿µ¤ÀûÔÚ´¦Öñ¨·ÏÉ豸¹ý³ÌÖз¢ÏÖÁË42̨ÃÔʧµÄ·þÎñÆ÷ £¬ËùÓзþÎñÆ÷¶¼¿ÉÄÜÔ̺¬Î´¼ÓÃܵĿͻ§ÐÅÏ¢¡£´Ë¿Ì £¬Ä¦¸ùÊ¿µ¤ÀûÒªÏò¸÷ÖÝÖ§¸¶650ÍòÃÀÔª £¬²¢²ÉÈ¡±ØÒª´ëÊ©±£»¤¿Í»§Êý¾Ý¡£


https://www.databreaches.net/states-settle-with-morgan-stanley-for-6-5-million-over-data-security-incidents/


4¡¢FortinetÅû¶FortiSIEMÖеķì϶CVE-2023-36553


11ÔÂ17ÈÕ±¨Â·³Æ £¬FortinetÅû¶ÁËFortiSIEM»ã±¨·þÎñÆ÷ÖеÄϵͳºÅÁî×¢Èë·ì϶£¨CVE-2023-36553 £¬CVSSÆÀ·Ö9.3£©¡£¸Ã·ì϶ÊÇÌØÊâÔªËØÖкͲ»µ±µ¼Ö嵀 £¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶ £¬Í¨¹ý·¢ËÍÌØÔìµÄAPIÒªÇóÀ´Ö´ÐкÅÁî¡£ÕâÊÇÊÇÄÚ²¿·¢ÏÖµÄÁíÒ»¸ö·ì϶£¨CVE-2023-34992£©µÄ±äÌå £¬¹«Ë¾ÓÚ10Ô³õ½¨¸´Á˸÷ì϶¡£Ä¿Ç°Éв»Ã÷ÏԸ÷ì϶ÊÇ·ñÒѱ»ÀûÓá£

https://securityaffairs.com/154301/security/fortinet-fortisiem-os-command-injection.html


5¡¢Unit 42°ä²¼Stately Taurus¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨


11ÔÂ17ÈÕ £¬Unit 42°ä²¼ÁËÔÚ8Ô·ݹ۲쵽ÈýÆðStately Taurus¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£µÚÒ»¸ö»î¶¯²úÉúÔÚ8ÔÂ1ÈÕ £¬×êÑÐÈËÔ±·¢ÏÖÁËÍйÜÔÚGoogle DriveÉϵÄStately Taurus £¬¹¥»÷Õß½«¶ñÒâÈí¼þ°üÅäÖÃΪZIPÎļþ230728 meeting minutes.zip¡£8ÔÂ3ÈÕ·¢ÏÖÁ˵ڶþ¸ö»î¶¯ £¬¶ñÒâÈí¼þ°üÃûΪNUG'sForeignPolicyStrategy.zip¡£µÚÈý¸ö»î¶¯ÔڽṹÉÏÓëµÚÒ»¸ö»î¶¯Ò»Ñù £¬´´½¨ÓÚ8ÔÂ16ÈÕ £¬µ«ÊÇÆäZIPºÍEXEµÄÎļþÃûÊÇLabor Statement.zip¡£


https://unit42.paloaltonetworks.com/stately-taurus-targets-philippines-government-cyberespionage/


6¡¢SentinelLabs°ä²¼Ó¡¶È¹ÍÓ¶ºÚ¿ÍÍÅ»ïAppinµÄ»ã±¨

 

11ÔÂ16ÈÕ £¬SentinelLabs°ä²¼Á˹ØÓÚÓ¡¶È¹ÍÓ¶ºÚ¿ÍÍÅ»ïAppin Software SecurityµÄ»ã±¨¡£ËüµÄ·ÇÕýʽÃû³ÆÎªAppin Security Group (ASG) £¬ÓëÓ¡¶Èµ±Ç°µÄAPT»î¶¯Óкܴó¹ØÏµ £¬ÖÁÉÙ´Ó2009ÄêÆð¾Í·¢Õ¹ÁËÐж¯¡£¸ÃÍÅ»ïµÄÖ¸±êÁìÓò±é²¼È«Çò £¬Ô̺¬ÃÀ¹ú¡¢¼ÓÄôó¡¢Ó¡¶È¡¢Ãåµé¡¢¿ÆÍþÌØ¡¢ÃϼÓÀ­¹ú¡¢°¢À­²®½áºÏÇõ³¤¹úºÍ°Í»ù˹̹µÈ¡£³ýÁËÀûÓÃÀ´×ÔµÚÈý·½µÄ´óÐÍ»ù´¡ÉèÊ©½øÐÐÊý¾Ýй¶¡¢C2¡¢´¹µö¹¥»÷ºÍÉèÖõö¶üÍøÕ¾±í £¬Ìý˵Ëü»¹ÒÀÀµVervata¡¢VupenºÍCore SecurityµÈ˽Ӫ¹©¸øÉÌÌṩµÄ¼äµýÈí¼þºÍ·ì϶ÀûÓ÷þÎñ¡£


https://www.sentinelone.com/labs/elephant-hunting-inside-an-indian-hack-for-hire-group/