MongoDB¹«Ë¾¼ì²âµ½Æäϵͳ±»ºÚ²¿Ãſͻ§µÄÐÅϢй¶

°ä²¼¹¦·ò 2023-12-18
1¡¢MongoDB¹«Ë¾¼ì²âµ½Æäϵͳ±»ºÚ²¿Ãſͻ§µÄÐÅϢй¶


¾ÝýÌå12ÔÂ17ÈÕ±¨Â·£¬ÃÀ¹úÊý¾Ý¿âÈí¼þ¹«Ë¾MongoDBÔâµ½¹¥»÷£¬²¿Ãſͻ§µÄÐÅÏ¢¿ÉÄÜй¶¡£¸Ã¹«Ë¾°µÊ¾£¬ËûÃÇÔÚ12ÔÂ13ÈÕÍíÉϼì²âµ½Æäϵͳ±»ºÚ¿Í¹¥»÷£¬²¢ÆðÍ·µ÷²éÕâÆðÊÂÎñ¡£ÕâÖÖδ¾­ÊÚȨµÄ½Ó¼ûÔÚ±»·¢ÏÖ֮ǰÒѾ­³ÖÐøÁËÒ»¶Î¹¦·ò£¬¿Í»§ÕÊ»§ÔªÊý¾ÝºÍÁªÏµÐÅÏ¢ÒѾ­Ð¹Â¶£¬µ«ÊÇMongoDB AtlasÖд洢µÄ¿Í»§Êý¾ÝûÓб»½Ó¼û¡£16ÈÕÏÂÎç5:25µÄºóÐø¸üÐÂÖУ¬MongoDB»ã±¨³ÆµÇ¼³¢ÊÔ¼¤Ôö£¬µ¼Ö½ӼûMongoDB AtlasºÍSupport PortalµÄ¿Í»§Óöµ½ÎÊÌâ¡£²»ÍâËûÖ¸³öÕâÓ밲ȫÊÂÎñÎ޹أ¬²¢½¨ÒéÓû§ÔÚ¼¸·ÖÖÓºóÔٴγ¢ÊÔ¡£


https://thehackernews.com/2023/12/mongodb-suffers-security-breach.html


2¡¢¼ÓÖÝDelta DentalÅûÂ¶Éæ¼°½ü700Íò¿Í»§µÄй¶ÊÂÎñ


¾Ý12ÔÂ15ÈÕ±¨Â·£¬¼ÓÖÝÑÀ¿Æ±£ÏÕÌṩÉÌDelta Dental½ü700Íò»¼ÕßµÄÐÅϢй¶¡£¸Ã¹«Ë¾Îª15¸öÖݵÄ4500ÍòÈËÌṩ±£ÏÕ£¬Ð¹Â¶ÊÂÎñÔ´ÓÚMOVEit TransferÈí¼þÖеķì϶¡£Delta DentalÓÚ6ÔÂ1ÈÕ»ñϤ¸Ã·ì϶£¬ÎåÌìºó£¬¾­¹ýÄÚ²¿µ÷²é£¬È·ÈÏδ¾­ÊÚȨµÄ¹¥»÷ÕßÔÚ5ÔÂ27ÈÕÖÁ5ÔÂ30ÈÕ½Ó¼û²¢ÇÔÈ¡ÁËÆäϵͳÖеÄÊý¾Ý¡£µÚ¶þ´Îµ÷²éÓÚ11ÔÂ27ÈÕʵÏÖ£¬ÒÔÈ·¶¨ÊÂÎñµÄÓ°ÏìÁìÓò¡£¾ÝϤ£¬½ØÖÁĿǰ£¬¹²6928932Ãû¿Í»§Êܵ½Ó°Ïì£¬Éæ¼°ÐÕÃû²ÆÕþÕʺš¢ÐÅÓþ¿¨/½è¼Ç¿¨ºÅ¼°°²È«´úÂë¡£


https://www.hackread.com/delta-dental-data-breach-moveit-linked-attack/


3¡¢ÔÆ´æ´¢ÌṩÉÌBox²úÉúÖжÏÓû§ÎÞ·¨½Ó¼û´æ´¢µÄÎļþ 


ýÌå12ÔÂ15Èճƣ¬ÔÆ´æ´¢ÌṩÉÌBox²úÉúÖжÏ£¬¿Í»§ÁÙʱÎÞ·¨½Ó¼û´æ´¢µÄÎļþ¡£ÖÐ¶ÏÆðÍ·ÓÚ15ÈÕÉÏÎç9µã×óÓÒ£¬Ó°ÏìÁ˵Ǽ¡¢ÉÏ´«¡¢ÏÂÔØºÍAPIŲÓᣳ¢ÊÔʹÓÃBoxµÄÓû§¿ÉÄܻῴµ½ÃýÎóºÍ³¬Ê±£¬µ«´óÎÞÊýÇé¿öÏ·þÎñ½«ÆëÈ«ÎÞ·¨½Ó¼û¡£µ±Óû§³¢ÊԵǼ»ò½Ó¼û¸Ã·þÎñʱ£¬»áÓöµ½HTTPÃýÎó503£¬Ö¸³ö¡°´ËÒ³ÃæÎÞ·¨Õý³£¹¤×÷¡£account.box.comĿǰÎÞ·¨´¦ÖôËÒªÇ󡣡±½ØÖÁ12ÔÂ15ÈÕÏÂÎç1:21£¬Box°µÊ¾Òѽ¨¸´¸ÃÎÊÌ⣬¿Í»§Äܹ»ÔٴνӼûÔÆ·þÎñ¡£


https://www.bleepingcomputer.com/news/technology/box-cloud-storage-down-amid-critical-outage/


4¡¢¼ÙÒâWPÍйÜÉÌKinstaµÄ´¹µö»î¶¯Ö¼ÔÚÇÔÈ¡MyKinstaÍ´´¦


12ÔÂ17ÈÕ±¨Â·³Æ£¬WordPressÍйÜÌṩÉÌKinsta·¢ÏÖÁËÀûÓÃGoogle AdµÄ´¹µö»î¶¯£¬Ö¼ÔÚÇÔÈ¡ÆäÍÐ¹ÜÆ¾Ö¤¡£Kinsta°µÊ¾£¬¹¥»÷ÕßÀûÓÃGoogle Ads£¬Õë¶ÔÒÔǰ½Ó¼û¹ýKinsta¹Ù·½ÍøÕ¾µÄÓ×ÎÒ¡£ÕâЩ¹¥»÷Õß´´½¨ÁËÓëKinsta¼«¶ÈÀàËÆµÄÍøÕ¾£¬À´ÓÕÆ­Óû§µã»÷ËüÃÇ£¬×îÖÕ»áÍøÂçMyKinstaµÇ¼ʹ´¦¡£ÎªÁËÓ¦¶ÔÕâЩÍþв£¬KinstaÔÚ»ý¼«¼ø±ð²¢¹Ø¹Ø´¹µöÍøÕ¾£¬µ«½¨ÒéÓû§²ÉÈ¡×Ô¶¯´ëÊ©À´± £»¤×Ô¼ºµÄÕÊ»§¡£


https://www.bleepingcomputer.com/news/security/wordpress-hosting-service-kinsta-targeted-by-google-phishing-ads/


5¡¢Kaspersky·¢ÏÖÀûÓÃNKNºÍ̸µÄ¶àƽ̨¶ñÒâÈí¼þNKAbuse


KasperskyÔÚ12ÔÂ14ÈÕ³ÆÆä·¢ÏÖÁËÒ»ÖÖÃûΪNKAbuseµÄÐÂÐÍ¶àÆ½Ì¨¶ñÒâÈí¼þ¡£ËüѡȡGo˵»°¿ª·¢£¬ÊǵÚÒ»¸öÒÀÀµNKN¼¼ÊõÔÚ½ÚµãÖ®¼ä½øÐÐÊý¾Ý»¥»»µÄ¶ñÒâÈí¼þ¡£¶ñÒâÈí¼þ³äÈÎÖ²È뷨ʽ£¬²¢½¨ÉèºéË®¹¥»÷ºÍºóÃÅÖ°ÄÜ£¬Äܹ»ÌìÉúÓë¸÷Àà¼Ü¹¹¼æÈݵĶþ½øÔìÎļþ¡£·ÖÎöÅú×¢NKAbuseÖØÒªÕë¶ÔLinux×ÀÃæ£¬µ«¼øÓÚÆäϰȾMISPºÍARMϵͳµÄÄÜÁ¦£¬Ò²¶ÔÎïÁªÍøÉ豸×é³ÉÁËÍþв¡£Ò£²âÊý¾ÝÏÔʾ£¬¸çÂ×±ÈÑÇ¡¢Ä«Î÷¸çºÍÔ½ÄÏÒѳöÏÖ±»¹¥»÷Ö¸±ê¡£


https://securelist.com/unveiling-nkabuse/111512/


6¡¢Zimperium°ä²¼2023ÄêÊÖ»úÒøÐжñÒâÈí¼þµÄ·ÖÎö»ã±¨


12ÔÂ14ÈÕ£¬Zimperium°ä²¼ÁË2023ÄêÊÖ»úÒøÐжñÒâÈí¼þµÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬½ñÄê³öÏÖÁË10¸öеÄAndroidÒøÐжñÒâÈí¼þ¼Ò×壬Õë¶Ô61¸ö¹ú¶È/µØÓò½ðÈÚ»ú¹¹µÄ985¸öÒøÐкͽðÈڿƼ¼/ÂòÂôÀûÓᣳýÁËÕâ10¸öÐÂľÂíÖ®±í£¬2022ÄêµÄ19¸öľÂí¼Ò×åÒ²½øÐÐÁËÅú¸Ä¡£½ñÄêÔÚÒøÐжñÒâÈí¼þÖй۲쵽µÄÐÂÖ°ÄÜÔ̺¬£º×Ô¶¯×ªÕËϵͳ(ATS)¡¢»ùÓڵ绰µÄ¹¥»÷½»¸¶(TOAD)¡¢ÆÁÄ»¹²ÏíÒÔ¼°¶ñÒâÈí¼þ¼´·þÎñ (MaaS)¡£ÎªÁË·À±¸´ËÀ๥»÷£¬½¨ÒéÓû§²»Òª´Ó¹Ù·½Çþ·֮±íÏÂÔØAPK¡£


https://www.zimperium.com/resources/zimperiums-2023-mobile-banking-heists-report-finds-29-malware-families-targeted-1800-banking-apps-across-61-countries-in-the-last-year/