ICAOµ÷²éDZÔÚÐÅÏ¢°²È«ÊÂÎñ £¬Éæ¼°42,000·ÝÎļþй¶

°ä²¼¹¦·ò 2025-01-09

1. ICAOµ÷²éDZÔÚÐÅÏ¢°²È«ÊÂÎñ £¬Éæ¼°42,000·ÝÎļþй¶


1ÔÂ7ÈÕ £¬½áºÏ¹ú¹ú¼ÊÃñÓú½¿Õ×éÖ¯£¨ICAO£©°ä·¢ÔÚµ÷²éһ·DZÔÚµÄÐÅÏ¢°²È«ÊÂÎñ¡£¸Ã×éÖ¯ÊÇÒ»¸ö³ÉÁ¢ÓÚ1944ÄêÈ·µ±¾ÐÄä×éÖ¯ £¬Óë193¸ö¹ú¶ÈºÏ×÷ £¬ÖÂÁ¦ÓÚÔì¶©Ï໥ÈϿɵļ¼Êõ³ß¶È¡£¾Ý³Æ £¬Õâ´ÎÊÂÎñÓëÒ»¸öÕë¶Ô¹ú¼Ê×éÖ¯µÄÍþвÐÐΪÕßÓйØ¡£Ö»¹ÜICAOδÌṩ¾ßÌåϸ½Ú £¬µ«´ËÉêÃ÷ÊÇÔÚÒ»¸öÃûΪ¡°natohub¡±µÄÍþвÐÐΪÕßÔÚºÚ¿ÍÂÛ̳ÉÏй¶Á˾ݳƴÓICAOÇÔÈ¡µÄ42,000·ÝÎļþÁ½Ììºó°ä²¼µÄ¡£±»µÁÎļþ¾Ý³ÆÔ̺¬Ó×ÎÒÉí·ÝÐÅÏ¢ £¬ÈçÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢µØÖ·¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·ÒÔ¼°½ÌÓýºÍ¾ÍÒµÐÅÏ¢¡£´Ëǰ £¬½áºÏ¹úÆäËû»ú¹¹Ò²Ôâ·ê¹ýÍøÂç¹¥»÷ºÍÊý¾Ýй¶ÊÂÎñ £¬ÀýÈç½áºÏ¹ú·¢Õ¹´òËãÊð£¨UNDP£©ºÍ½áºÏ¹ú»·¾³¹æ»®Êð£¨UNEP£©¡£½áºÏ¹úÍøÂçÒ²ÔøÂÅ´ÎÔâµ½¹¥»÷ £¬µ¼ÖÂÔ±¹¤¼Í¼¡¢½¡È«±£ÏÕºÍóÒ׺ÏÒ»ÖÂÊý¾Ýй¶¡£Õâ´ÎICAOµÄÉêÃ÷Åú×¢ £¬¸Ã×éÖ¯ÔÚ»ý¼«Ó¦¶ÔDZÔÚµÄÐÅÏ¢°²È«Íþв £¬²¢²ÉÈ¡±ØÒªµÄ°²È«´ëÊ©¡£


https://www.bleepingcomputer.com/news/security/un-aviation-agency-investigating-potential-security-breach/


2. ÌïÄÉÎ÷Öݬɪ¸£ÏØÑ§ÌÃÔâÍøÂç¹¥»÷ £¬Ãô¸ÐÊý¾Ýй¶


1ÔÂ7ÈÕ £¬ÌïÄÉÎ÷Öݬɪ¸£ÏØÑ§ÌýüÆÚÔâ·êÁËÍøÂç¹¥»÷ÊÂÎñ¡£ÏÈÊÇ10ÔÂ19ÈÕ £¬Black SuitÀÕË÷Èí¼þ×éÖ¯Ðû³ÆÏ®»÷Á˸ÃѧÌà £¬µ«ËæºóѧÌ÷½Ãæ·ñ¶¨ÁËÕâÒ»Ö¸¿Ø £¬°µÊ¾Êܹ¥»÷µÄÊÇÁíÒ»ËùѧÌá£È»¶ø £¬Á½¸ö¶àÔºó £¬Rhysida×éÖ¯°ä·¢µÄÈ·Ï®»÷Áˬɪ¸£ÏØÑ§Ìà £¬²¢Ð¹Â¶ÁËÔ̺¬Ñ§ÉúºÍÔ±¹¤Ãô¸ÐÐÅÏ¢µÄ1.2TBÊý¾ÝÖеÄ60%¡£Ð¹Â¶µÄÊý¾ÝÉæ¼°½¡È«¼Í¼¡¢ÌØÊâ½ÌÓý¼Í¼ÒÔ¼°ÈËÁ¦×ÊÔ´²¿Îļþ £¬Ô̺¬´óÁ¿Ó×ÎÒÉí·ÝÐÅÏ¢ £¬ÈçÉç»á°²È«ºÅÂë¡¢Éí·ÝÖ¤ºÍ³É¾Íµ¥µÈ £¬¸øÑ§Éú¡¢¼Ò³¤ºÍÔ±¹¤´øÀ´Á˾޴óÀ§ÈÅ¡£Ä¿Ç°Éв»Ã÷ÏÔÍþвÐÐΪÕßÊÇ·ñÏúÊÛÁËÊý¾Ý»òÊÇ·ñ»áй¶¸ü¶à¡£Õë¶Ô´ËÇé¿ö £¬ÌáÐѹ«¼Ò°ÑÎȱ£»¤Ó×ÎÒÒþÖÔ £¬³ö¸ñÊÇÄêÂú18ËêµÄǰѧÉú¡¢ÏÖÈÎѧÉú¡¢¼Ò³¤ÒÔ¼°ÏÖÈκÍǰÈÎÔ±¹¤ £¬¸Ãµ±¼´¶ÔÐÅÓþ»ã±¨½øÐа²È«¶³½á¡£Í¬Ê± £¬ËùÓÐÈËÓ¦ÊÔÂÇÏò¾¯·½±¨°¸ £¬²¢Í¨ÖªÒøÐкÍÐÅÓþ¿¨¿¯ÐÐÉÌÐÅϢй¶Çé¿ö¡£¸ÃÑ§ÇøÓÚ11ÔÂ25ÈÕ³õ´Î·¢ÏÖÍøÂç·ì϶ £¬Ä¿Ç°ÒÑÔÚµÚÈý·½ÍøÂ簲ȫר¼ÒµÄЭÖúÏ·¢Õ¹µ÷²é £¬²¢½«Æ¾¾ÝºÏÓÃ˾·¨Í¨ÖªÊÜÓ°ÏìµÄÓ×ÎÒ¡£


https://databreaches.net/2025/01/07/two-ransomware-groups-claimed-they-attacked-rutherford-county-schools-one-leaked-sensitive-records/


3. ÂÌÍå°ü×°¹¤¶Ó¹Ù·½ÁãÊÛµêÔâºÚ¿ÍÈëÇÖ £¬¿Í»§Ö§¸¶ÐÅÏ¢ÔâÇÔÈ¡


1ÔÂ7ÈÕ £¬ÂÌÍå°ü×°¹¤¶ÓÃÀʽ×ãÇò¶Ó½üÆÚÔâ·êÍøÂç¹¥»÷ £¬Ò»ÃûÍþвÐÐΪÕßÈëÇÖÁËÆä¹Ù·½ÔÚÏßÁãÊÛµêpackersproshop.com £¬²¢×¢ÈëÁË¿¨Æ¬µÁË¢¾ç±¾ £¬ÒÔÇÔÈ¡¿Í»§µÄÓ×ÎÒºÍÖ§¸¶ÐÅÏ¢¡£¸Ã¶ÓÔÚ10ÔÂ23ÈÕ·¢ÏÖÈëÇÖºó £¬µ±¼´½ûÓÃÁËËùÓнáÕ˺͸¶¿îÖ°ÄÜ £¬²¢ÀñƸÁË±í²¿ÍøÂ簲ȫר¼Ò½øÐе÷²é¡£µ÷²éÏÔʾ £¬¶ñÒâ´úÂë¿ÉÄÜÔÚ2024Äê9ÔÂÏÂÑ®ÖÁ10ÔÂÉÏÑ®ÆÚ¼äÇÔÊØÐÅÏ¢ £¬µ«Ê¹ÓÃÌØ¶¨Ö§¸¶·½Ê½µÄÐÅϢδ±»À¹½Ø¡£¾­µ÷²éÈ·ÈÏ £¬¶ñÒâ´úÂë¿ÉÄÜÔÊÐíµÚÈý·½²é¿´»ò»ñÈ¡ÔÚÖ¸¶¨ÈÕÆÚÁìÓòÄÚʹÓÃÓÐÏÞ¸¶¿î·½Ê½½áÕËʱÊäÈëµÄijЩ¿Í»§ÐÅÏ¢¡£Õâ´Îй¶ÊÂÎñÉæ¼°µÄÓ×ÎÒºÍÖ§¸¶Êý¾ÝÔ̺¬ÐÕÃû¡¢µØÖ·¡¢µç×ÓÓʼþµØÖ·ÒÔ¼°ÐÅÓþ¿¨ÏêÇéµÈ¡£°ü×°¹¤¶ÓÉÐδй©ÊÜÓ°Ïì¿Í»§ÊýÁ¿ºÍÈëÇÖ·½Ê½ £¬µ«ÎªÊÜÓ°ÏìÓû§ÌṩÈýÄêµÄÐÅÓþ¼à¿ØºÍÉí·Ý͵ÇÔ¸´Ô­·þÎñ £¬²¢½¨ÒéËûÃÇ¼à¿ØÕË»§±¨±íÒÔ·Àڲƭ¡£´Ëǰ £¬¾É½ðɽ49È˶ÓÒ²ÔøÔâ·êÀàËÆ¹¥»÷ £¬³¬¹ý20,000ÃûÓ×ÎÒÐÅÏ¢±»µÁ¡£


https://www.bleepingcomputer.com/news/security/green-bay-packers-online-store-hacked-to-steal-credit-cards/


4. PowerSchoolÔâ·êÍøÂ簲ȫÊÂÎñ £¬Ñ§ÉúÀÏʦÊý¾ÝÔâÇÔ


1ÔÂ7ÈÕ £¬½ÌÓýÈí¼þ¾ÞÍ·PowerSchoolÔâ·êÁËÒ»Â·ÍøÂ簲ȫÊÂÎñ £¬¹¥»÷ÕßÀûÓÃÆäPowerSchool SISƽ̨ÇÔÈ¡Á˲¿ÃÅÑ§ÇøÑ§ÉúºÍÀÏʦµÄÓ×ÎÒÐÅÏ¢¡£PowerSchoolÊÇÒ»¼ÒΪK-12ѧÌúÍÑ§ÇøÌṩȫ·½Î»ÔÆÈí¼þ½â¾ö¹æ»®µÄ¹«Ë¾ £¬Æä·þÎñÔ̺¬ÕÐÉú¡¢Í¨Ñ¶¡¢³öÇڵȶà¸ö·½Ãæ¡£Õâ´Î¹¥»÷²úÉúÔÚ2024Äê12ÔÂ28ÈÕ £¬¹¥»÷Õßͨ¹ýPowerSchoolµÄ¿Í»§Ö§³Ôì½Ì¨PowerSource £¬Ê¹ÓÃй¶µÄƾ֤½Ó¼û²¢µ¼³öÁËÔ̺¬Ñ§ÉúºÍÀÏʦÊý¾ÝµÄCSVÎļþ¡£±»µÁÊý¾ÝÖØÒªÔ̺¬ÐÕÃû¡¢µØÖ·µÈÁªÏµ·½Ê½ £¬²¿ÃÅÑ§ÇøµÄÊý¾Ý»¹¿ÉÄÜÔ̺¬Éç»á°²È«ºÅÂë¡¢Ó×ÎÒÉí·ÝÐÅÏ¢¡¢Ò½ÁÆÐÅÏ¢ºÍ³É¾Í¡£PowerSchoolÇ¿µ÷ £¬¿Í»§Æ±Ö¤¡¢Æ¾Ö¤»òÂÛ̳Êý¾ÝδÔÚÕâ´ÎÊÂÎñÖÐй¶ £¬ÇÒ²¢·ÇËùÓпͻ§¶¼ÊÜÓ°Ï졣ΪӦ¶Ô´ËÊ £¬PowerSchoolÓëµÚÈý·½ÍøÂ簲ȫר¼ÒºÏ×÷ £¬ÂÖ»»ÁËËùÓÐPowerSourceÕÊ»§µÄÃÜÂë £¬²¢Ö´ÐÐÁ˸üÑϸñµÄÃÜÂëÕ½Êõ¡£Í¬Ê± £¬PowerSchoolÈ·ÈÏÕâ²»ÊÇÀÕË÷Èí¼þ¹¥»÷ £¬µ«Ö§¸¶ÁËÊê½ðÒÔÈ·±£Êý¾Ý±»É¾³ý £¬²¢ÔÚ³ÖÐø¼à¿Ø°µÍøÒÔÈ·¶¨Êý¾ÝÊÇ·ñÒÑй¶¡£¶ÔÓÚÊÜÓ°ÏìµÄÈË £¬PowerSchoolÌṩÁËÐÅÓþ¼à¿ØºÍÉí·Ý±£»¤·þÎñ¡£Ö»¹ÜÔâ·êÈëÇÖ £¬PowerSchoolµÄÔËÓª²¢Î´Êܵ½Ó°Ïì £¬·þÎñÈÔÕÕ³£½øÐС£


https://www.bleepingcomputer.com/news/security/powerschool-hack-exposes-student-teacher-data-from-k-12-districts/


5. PayPal»ã¿îÒªÇóÖ°ÄÜÔâÐÂÐÍÍøÂç´¹µö¼¼ÊõÀûÓÃ


1ÔÂ8ÈÕ £¬Ò»ÖÖÐÂÐÍÍøÂç´¹µö¼¼ÊõÀûÓÃPayPal»ã¿îÒªÇóÖ°ÄܽøÐÐÚ¿Æ­ £¬¸Ã¼¼Êõͨ¹ý·¢ËÍ¿´ËÆÕæÊµµÄºÏ·¨PayPal»ã¿îÒªÇóÀ´ÓÕÆ­ÊÕ¿îÈË¡£Ú¿Æ­ÕßÀûÓÃMicrosoft 365²âÊÔÓò´´½¨·Ö·¢Áбí £¬²¢Í¨¹ýPayPalÏò¸ÃÁÐ±í·¢Ë͸¶¿îÒªÇó¡£ÓÉÓÚ΢ÈíµÄ·¢¼þÈ˳Áд¹æ»®ºÍPayPalµÄ°²È«²é³­ £¬ÕâЩҪÇóÔÚµç×ÓÓʼþ¡¢URLºÍ·¢¼þÈ˵ØÖ·É϶¼ÏԵúϷ¨¡£Ò»µ©ÊÕ¼þÈ˵ã»÷Á´½Ó²¢µÇ¼PayPalÕË»§ £¬Ú¿Æ­Õß¾ÍÄÜ»ñÈ¡ÕË»§½Ó¼ûȨÏÞ¡£Oasis Security×êÑÐÖ÷¹ÜÖ¸³ö £¬ÕâÖÖÀûÓù©¸øÉÌÖ°ÄÜ´«µÝÐÂÎŵķ½Ê½Ê¹µÃÓÊÏäÌṩÉÌÄÑÒÔ·Ö±æÕæ¼ÙͨѶ £¬PayPal¿ÉÄܳÉΪΨһ¿ÉÄÜ»º½â´ËÎÊÌâµÄʵÌ塣ΪÁË·ÀÓù´ËÀàÍþв £¬FortinetÇ¿µ÷ѵÁ·ÓÐËØµÄÈËÈâ·À»ðǽµÄ³ÁÒªÐÔ £¬½¨Òé½ÌÓýÔ±¹¤×ÐϸÉó²éËùÓÐÒâ±í¸¶¿îÒªÇó¡£´Ë±í £¬Ê¹ÓÃÊý¾ÝÃÔʧ·À»¤¹æ¶¨ºÍÏȽøµÄÈËΪÖÇÄܼ¼ÊõÀ´·ÖÎöÓû§ÐÐΪҲÓÐÖúÓÚ·¢ÏÖºÍ×èÖ¹ÕâÐ©ÍøÂç´¹µö³¢ÊÔ¡£


https://www.infosecurity-magazine.com/news/scammers-exploit-microsoft365/


6. Öж«ÍË¿îÚ¿Æ­£ºÍøÂç·¸×ï·Ö×ÓÀûÓÃÔ¶³Ì½Ó¼û¹¤¾ßÇÔÊØÐÅÏ¢


1ÔÂ8ÈÕ £¬Öж«µØÓò½üÆÚ³öÏÖÁËÒ»ÖÖ¸´ÔÓµÄÍøÂçÚ¿Æ­ £¬Ú¿Æ­Õß¼ÙÒâµ±¾Ö¹ÙÔ± £¬Í¨¹ýµç»°ÁªÏµÄÇÐ©ÔøÏòµ±¾Ö·þÎñÃÅ»§ÍøÕ¾ÌύͶËßµÄÓ×ÎÒ £¬ÒÔÔ®ÊÖËûÃÇ»ñÈ¡²»ÖÐÒâµÄ¹ºÎïÍ˿ڿƭÕßÒªÇóÊܺ¦ÕßÏÂÔØºÏ·¨µÄÔ¶³Ì½Ó¼ûÈí¼þÈçAnyDesk»òTeamViewer £¬²¢ÔÚÊܺ¦Õß²»ÖªÇéµÄÇé¿öÏ»ñÈ¡ÆäÉ豸µÄ½Ó¼ûȨÏÞ £¬´Ó¶øÇÔÈ¡Ó×ÎҺͲÆÕþÐÅÏ¢ £¬Ô̺¬ÐÅÓþ¿¨¾ßÌåÐÅÏ¢ºÍÒ»´ÎÐÔÃÜÂ루OTP£©¡£¾Ý¹À¼Æ £¬Ã¿±ÊÂòÂôµÄ¾ùÔÈËðʧԼΪ1,300ÃÀÔª £¬ÓÐЩÊܺ¦ÕßÉõÖÁËðʧ¸ß´ï5,000ÃÀÔª¡£¸ÃȦÌ×µÄÓÐЧÐÔÅú×¢¿ÉÄÜÓÐÄÚ²¿ÈËÔ±²Î¼Ó £¬ÓÉÓÚÚ¿Æ­ÕßËÆºõ¿ÉÄܽӼûµ±¾ÖͶËßÊý¾Ý¡£Îª·À±¸´ËÀàÚ¿Æ­ £¬Ó×ÎÒÓ¦ÉóÉ÷¶Ô´ýµ±¾Ö¹ÙÔ±µÄδ¾­ÒªÇóµÄµç»° £¬Ô¤·ÀÏÂÔØÔ¶³Ì½Ó¼ûÈí¼þ»ò·ÖÏíÃô¸ÐÐÅÏ¢¡£Í¬Ê± £¬µ±¾ÖºÍ½ðÈÚ»ú¹¹Ò²Ó¦¼ÓÇ¿°²È«´ëÊ© £¬½ÌÓý¹«¼ÒÏàʶÉç»á¹¤³Ì·çÏÕ¡£AnyDeskºÍTeamViewerµÈ¹¤¾ßËäÕý±¾ÓÃÓںϷ¨ÔöÔ® £¬µ«ÂäÈëÚ¿Æ­ÕßÊÖÖкó³ÉΪ³Á´óÍþв £¬Òò¶øÐèÌá¸ß¾¯Ìè¡£


https://hackread.com/scammers-impersonate-swipe-otps-remote-access-apps/