ÃÀ¹ú×î´ó²úȨ±£ÏÕ¹«Ë¾FNF±»AlphV¹¥»÷ϵÍÂäÙʱ¹Ø¹Ø
°ä²¼¹¦·ò 2023-11-271¡¢ÃÀ¹ú×î´ó²úȨ±£ÏÕ¹«Ë¾FNF±»AlphV¹¥»÷ϵÍÂäÙʱ¹Ø¹Ø
¾ÝýÌå11ÔÂ24ÈÕ±¨Â·£¬ÃÀ¹ú×î´óµÄ²úȨ±£ÏÕ¹«Ë¾Fidelity National Financial(FNF)Ôâµ½AlphV(BlackCat) µÄ¹¥»÷¡£ÉÏÖÜÈý£¬AlphV°ä·¢ËûÃǹ¥»÷ÁËFNF£¬»¹½«FNFûÓн»Êê½ðµÄÔÒò¹é×ïÓÚMandiant¡£Ä¿Ç°£¬AlphVûÓа䲼ÈκθÉÓÚ¹¥»÷µÄÖ¤Ã÷¡£FNFÍøÕ¾ÉÏҲûÓÐÈκμ£ÏóÅú×¢´æÔÚÊý¾Ýй¶ÎÊÌ⣬µ«ÊÇËü¹Ø¹ØÁ˺ܶàÔÚÏß·þÎñ£¬²¢°µÊ¾ËûÃÇ֪·ijЩϵͳÒѱ»½Ó¼û¡£
https://www.databreaches.net/fidelity-national-financial-ransomware-incident-impacts-real-estate-closings/
2¡¢Í¨ÓÃµçÆøµÄ½Ó¼ûȨÏ޺ʹóÁ¿Êý¾ÝÔÚºÚ¿ÍÂÛ̳±»ÏúÊÛ
¾Ý11ÔÂ25ÈÕ±¨Â·£¬ÃÀ¹ú¿ç¹ú¹«Ë¾Í¨ÓÃµçÆø(GE)ÔÚµ÷²éÆäÊý¾Ý±»µÁµÄÎÊÌâ¡£±¾ÔÂÔçЩʱ³½£¬ºÚ¿ÍIntelBrokerÔÚ°µÍøÒÔ500ÃÀÔªµÄ¼ÛÖµÏúÊÛGEµÄ½Ó¼ûȨÏÞ¡£¶øºó£¬¹¥»÷ÕßÔٴη¢Ìû³Æ£¬ËûÃÇ´Ë¿ÌͬʱÏúÊÛÍøÂç½Ó¼ûȨÏÞ£¨SSHºÍSVNµÈ£©ºÍ±»µÁÊý¾Ý£¬ÆäÖб»µÁÊý¾ÝÔ̺¬´óÁ¿ÓëDARPAÓйصľüÊÂÐÅÏ¢¡¢Îļþ¡¢SQLÎļþºÍÎĵµµÈ¡£×÷Ϊй¶֤¾Ý£¬¹¥»÷Õß¹«¿ªÁËÊý¾Ý½ØÍ¼£¬Ô̺¬GE AviationsµÄÒ»¸öÊý¾Ý¿â£¬Éæ¼°¾üÊÂÏîÖ÷ÕÅÐÅÏ¢¡£GE°µÊ¾ÒÑ»ñϤ´ËÊÂÎñ£¬²¢ÔÚ½øÐе÷²é¡£
https://www.bleepingcomputer.com/news/security/general-electric-investigates-claims-of-cyber-attack-data-theft/
3¡¢ITÌṩÉÌCTSÔâµ½ÀÕË÷¹¥»÷Ó¢¹úÊý°Ù¼ÒÂÉËùµÄÒµÎñÊÜÓ°Ïì
11ÔÂ24ÈÕ±¨Â·³Æ£¬ÎªÓ¢¹úÂÉʦÊÂÎñËùÌṩÍйܷþÎñµÄÌṩÉÌ(MSP)CTSÔâµ½ÍøÂç¹¥»÷¡£Õâ¼ÒIT·þÎñÌṩÉÌÔÚÉÏÖÜÎå°ä²¼ÉêÃ÷³Æ£¬ËûÃÇÔÚ¾ÀúÒ»´Î·þÎñÖжϣ¬Ó°ÏìÁËÏò²¿Ãſͻ§ÌṩµÄ·þÎñ¡£¹ÌÈ»CTSÉÐδй©ÊÜÓ°Ïì¿Í»§µÄÊýÁ¿ºÍ¹¥»÷ÐÔÖÊ£¬µ«Ä¿Ç°µÄÐÅÏ¢Åú×¢ÕâÊÇÒ»´ÎÀÕË÷¹¥»÷¡£±¾µØÃ½Ì屨·£¬Ô¼80ÖÁ200¼ÒÂÉʦÊÂÎñËù¿ÉÄÜÊܵ½Ó°Ïì¡£ÔÚÕâÒ»ÖÜÀÓÉÓÚ·þÎñÖжϣ¬ÈËÃÇÎÞ·¨²É°ì»òÏúÊÛ·¿²ú¡£¸Ã¹«Ë¾°µÊ¾£¬ÓÐÐÅÄî¿ÉÄܸ´Ô·þÎñ£¬µ«ÎÞ·¨È·¶¨¡°È«Ã渴ԡ±µÄ¹¦·ò¡£
https://therecord.media/uk-cyberattack-msp-cts-law-firms
4¡¢°²È«»ú¹¹Åû¶LazarusÀûÓÃMagicLine4NX·ì϶µÄ¹©¸øÁ´¹¥»÷
ýÌå11ÔÂ25Èճƣ¬°²È«»ú¹¹NCSCºÍNIS½áºÏ°ä²¼¹«¸æ³ÆLazarusÔÚÀûÓÃMagicLine4NXÖеÄodayÖ´Ðй©¸øÁ´¹¥»÷¡£MagicLine4NXÊÇÒ»¿î°²È«ÈÏÖ¤Èí¼þ£¬¹¥»÷²úÉúÓÚ½ñÄê3Ô·ݡ£¹¥»÷Á´Ê¼ÓÚË®¿Ó¹¥»÷£¬¹¥»÷ÕßÈëÇÖÁËÒ»¼ÒýÌåÍøÕ¾£¬²¢½«¶ñÒâ¾ç±¾Ö²È뵽һƪÎÄÕÂÖУ¬ÕâЩ¾ç±¾½öÕë¶ÔÌØ¶¨IPÁìÓòµÄ½Ó¼ûÕß¡£µ±Óû§Ê¹ÓÃMagicLine4NX½Ó¼û±»Ï°È¾ÍøÕ¾Ê±£¬¶ñÒâ´úÂë¾Í»áÖ´ÐдӶøÆëÈ«½ÚÔìϵͳ¡£Ëæºó£¬¹¥»÷ÕßÀûÓÃϵͳ·ì϶´ÓÁªÍøµÄPCÉÏ·¸·¨½Ó¼û·þÎñÆ÷£¬²¢ÀÄÓÃÁªÍøÏµÍ³µÄÊý¾Ýͬ²½Ö°Äܽ«¶ñÒâ´úÂë´«²¼µ½ÒµÎñ¶Ë·þÎñÆ÷£¬×îÖÕÖ¼ÔÚÇÔÊØÐÅÏ¢¡£
https://securityaffairs.com/154765/apt/lazarus-magicline4nx-supply-chain-attack.html
5¡¢Granger Medical ClinicÔâµ½NoEscape¹¥»÷¾Ü¸¶Êê½ð
ýÌå11ÔÂ26ÈÕ±¨Â·³Æ£¬ÀÕË÷ÍÅ»ïNoEscapeÓÚ11ÔÂ24ÈÕ½«ÓÌËûÖݵÄGranger Medical ClinicÔö³¤µ½ÆäÍøÕ¾ÖС£¹¥»÷ÕßÐû³ÆÕ¼Óг¬¹ý35GBµÄÊý¾Ý£¬Ô̺¬±£ÃܺÍ̸ºÍºÏͬ¡¢NDA¡¢SSN¿¨¡¢É󼯡¢»ã±¨¡¢²ÆÕþ¡¢Êý¾Ý¿â¡¢Ô¤ËãºÍÒøÐÐÒµÎñµÈÓйØÎļþ¡£×÷Ϊ֤¾Ý£¬NoEscape»¹ÌṩÁËÎļþÊ÷ºÍÆÁÄ»½ØÍ¼¡£½»ÉæËƺõ·ÖÁÑÁË£¬Granger¾ö¶¨²»¸¶¿î¡£NoEscapeÍþвÔÚ24Ó×ʱÄÚÖ§¸¶70ÍòÃÀÔªÊê½ð£¬²»È»½«¹«¿ªËùº±¼û¾Ý¡£×êÑÐÈËÔ±ÔÚ25Èղ鳷¢ÏÖ£¬¹¥»÷ÕßÒѾй¶Á˳¬¹ý31 GBµÄÎļþ¡£
https://www.databreaches.net/ransomware-group-leaks-data-allegedly-from-granger-medical-clinic/
6¡¢Check Point·¢ÏÖʹÓÃSysJokerºóÃŹ¥»÷ÒÔÉ«ÁеĻ
11ÔÂ23ÈÕ£¬Check PointÅû¶ÁËʹÓÃSysJokerºóÃŹ¥»÷ÒÔÉ«ÁеĻ¡£SysJokerÓÚ2021Äê12Ô³õ´Î±»·¢ÏÖ£¬¸ÃºóÃÅ¿ÉÄÜϰȾWindows¡¢macOSºÍLinuxϵͳ£¬Æäʱ·¢ÏÖµÄÊÇC++°æ±¾¡£Õë¶ÔÒÔÉ«ÁеĹ¥»÷ÖÐʹÓõİ汾ÊÇRust¿ª·¢µÄ£¬ÕâÅú×¢¸Ã¶ñÒâÈí¼þÊÇÖØÐÂÆðÍ·³Áд£¬ÓÚ½ñÄê10ÔÂ12ÈÕ³õ´ÎÌá½»µ½VirusTotal¡£´Ë±í£¬¸Ã¶ñÒâÈí¼þÑ¡È¡Ëæ»ú˯Ãß¾àÀëºÍ¸´ÔÓµÄ×Ô½ç˵¼ÓÃÜ´úÂë×Ö·û´®À´Èƹý¼ì²âºÍ·ÖÎö¡£
https://research.checkpoint.com/2023/israel-hamas-war-spotlight-shaking-the-rust-off-sysjoker/


¾©¹«Íø°²±¸11010802024551ºÅ