Otelier¾ÆµêÖÎÀíÆ½Ì¨Ôâ·ê´ó¹æÄ£Êý¾Ýй¶
°ä²¼¹¦·ò 2025-01-201. Otelier¾ÆµêÖÎÀíÆ½Ì¨Ôâ·ê´ó¹æÄ£Êý¾Ýй¶
1ÔÂ17ÈÕ£¬2024Äê7ÔÂÖÁ10ÔÂÆÚ¼ä£¬¾ÆµêÖÎÀíÆ½Ì¨Otelier£¨Ç°ÉíΪMyDigitalOffice£©Ôâ·êÁËÑϳÁµÄÊý¾Ýй¶ÊÂÎñ¡£ÍþвÐÐΪÕ߳ɹ¦ÈëÇÔìäAmazon S3ÔÆ´æ´¢£¬ÇÔÈ¡ÁËÊý°ÙÍò¿ÍÈ˵ÄÓ×ÎÒÐÅÏ¢ÒÔ¼°ÍòºÀ¡¢Ï£¶û¶Ù¡¢¿ÔõȳÛÃû¾ÆµêÆ·ÅÆµÄÔ¤Ô¼ÐÅÏ¢£¬×ÜÁ¿½ü8TB¡£OtelierÒÑÈ·ÈÏÕâ´ÎÈëÇÖ£¬²¢ÕýÓëÊÜÓ°Ïì¿Í»§¹µÍ¨£¬Í¬Ê±ÀñƸÁ˶¥¼âÍøÂ簲ȫר¼ÒÍŶӽøÐÐÈ«ÃæÈ¡Ö¤·ÖÎöºÍϵͳÑéÖ¤¡£ÎªÔ¤·ÀÀàËÆÊÂÎñÔٴβúÉú£¬OtelierÒѽûÓÃÓйØÕË»§²¢¼ÓÇ¿ÍøÂ簲ȫºÍ̸¡£¾ÝÍþвÕßй©£¬ËûÃÇ×î³õͨ¹ýÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ»ñÈ¡ÁËÒ»ÃûÔ±¹¤µÄµÇ¼ÐÅÏ¢£¬½ø¶øÈëÇÖÁËAtlassian·þÎñÆ÷£¬²¢ÀûÓÃÕâЩƾ֤»ñÈ¡Á˸üÎÞÊý¾Ý£¬Ô̺¬S3´æ´¢Í°µÄ½Ó¼ûȨÏÞ¡£ÍòºÀ¾ÆµêÒÑ֤ʵÆäÊܵ½Ó°Ï죬²¢ÔÝÍ£ÁËOtelierÌṩµÄ×Ô¶¯»¯·þÎñ£¬µ«Ç¿µ÷ÆäϵͳδÔÚÕâ´Î¹¥»÷ÖÐÔâµ½ÈëÇÖ¡£È»¶ø£¬Ð¹Â¶µÄÊý¾ÝÑù±¾ÏÔʾ£¬¾Æµê¿ÍÈ˵ÄÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂëºÍµç×ÓÓʼþµØÖ·µÈÓ×ÎÒÐÅÏ¢Òѱ»µÁÈ¡£¬²¢±»Ôö³¤µ½¡°Have I Been Pwned¡±ÍøÕ¾ÉϹ©È˲éÎÊ¡£Ö»¹ÜÃÜÂëºÍÕ˵¥ÐÅϢδ±»µÁ£¬µ«Óû§ÈÔÐ辯ÌèÕë¶Ô´Ë·ì϶µÄ¿ÉÒɵç×ÓÓʼþºÍÍøÂç´¹µö¹¥»÷¡£
https://www.bleepingcomputer.com/news/security/otelier-data-breach-exposes-info-hotel-reservations-of-millions/
2. PyPIÏÖ¡°pycord-self¡±¶ñÒâ°ü£¬Õë¶ÔDiscord¿ª·¢ÈËÔ±ÇÔÈ¡ÁîÅÆÖ²ÈëºóÃÅ
1ÔÂ17ÈÕ£¬Python°üË÷Òý£¨PyPI£©ÉϳöÏÖÁËÒ»¿îÃûΪ¡°pycord-self¡±µÄ¶ñÒâÈí¼þ°ü£¬ËüÕë¶ÔµÄÊÇDiscord¿ª·¢ÈËÔ±¡£Õâ¿î¶ñÒâ°ü·ÂÕÕÁ˹ãÊÜӽӵġ°discord.py-self¡±°ü£¬Òѱ»ÏÂÔØÔ¼885´Î¡£Ö»¹ÜËüÌṩÁ˺Ϸ¨ÏîÖ÷ÕÅÖ°ÄÜ£¬µ«ÊµÔòÔ̺¬Ö´ÐÐÁ½ÏîÖØÒª¶ñÒâ²Ù×÷µÄ´úÂ룺һÊÇÇÔÈ¡DiscordÉí·ÝÑéÖ¤ÁîÅÆ²¢½«Æä·¢Ë͵½±í²¿URL£¬¼´±ãË«³É·ÖÉí·ÝÑéÖ¤±£»¤´¦Óڻ״̬£¬¹¥»÷ÕßÒ²ÄÜʹÓÃÕâЩÁîÅÆ½Ù³Ö¿ª·¢ÈËÔ±µÄDiscordÕÊ»§£»¶þÊÇͨ¹ý¶Ë¿Ú6969ÓëÔ¶³Ì·þÎñÆ÷³ÉÁ¢ÓƾÃÏνӣ¬³ÉÁ¢ºóÃÅ»úÔ죬Èù¥»÷Õß¿ÉÄܳÖÐø½Ó¼ûÊܺ¦ÕßµÄϵͳ¡£Socket×êÑÐÈËÔ±¶Ô´Ë½øÐÐÁ˾ßÌå·ÖÎö¡£Òò¶ø£¬½¨ÒéÈí¼þ¿ª·¢ÈËÔ±ÔÚ×°ÖÃÈí¼þ°üʱ£¬Îñ±ØÑéÖ¤´úÂëÊÇ·ñÀ´×Ô¹Ù·½×÷Õߣ¬²¢²é³Èí¼þ°üµÄÃû³Æ£¬ÒÔ½µµÍ³ÉΪÊܺ¦ÕߵķçÏÕ¡£Í¬Ê±£¬Ê¹ÓÿªÔ´¿âʱ£¬½¨Òé²é³´úÂëÖÐÊÇ·ñ´æÔÚ¿ÉÒɺ¯Êý£¬²¢ÀûÓÃɨÃ蹤¾ß¼ì²âºÍ×èÖ¹¶ñÒâÈí¼þ°ü¡£
https://www.bleepingcomputer.com/news/security/malicious-pypi-package-steals-discord-auth-tokens-from-devs/
3. Lazarus×éÖ¯Õë¶Ô¿ª·¢ÈËÔ±ÌáÒé¡°99ºÅÐж¯¡±ÇÔÈ¡Ãô¸ÐÊý¾Ý
1ÔÂ17ÈÕ£¬³¯Ïʵ±¾ÖÖ§³ÖµÄLazarus×éÖ¯ÔÚ·¢Õ¹ÃûΪ¡°99ºÅÐж¯¡±µÄ³ÖÐø¹¥»÷»î¶¯£¬Õë¶ÔÈí¼þ¿ª·¢ÈËÔ±ÇÔÈ¡Ãô¸ÐÊý¾Ý¡£Õâ´Î»î¶¯±ê־ȡLazarus×éÖ¯¹¥»÷Õ½ÊõµÄÑݱ䣬´Ó¿í·ºµÄÍøÂç´¹µö¹¥»÷תÏòÕë¶Ô¼¼Êõ¹©¸øÁ´ÖеĿª·¢ÈËÔ±½øÐÐÓÐÕë¶ÔÐԵĹ¥»÷¡£¹¥»÷Õß¼ÙÒâÕÐÆ¸ÈËÔ±ÔÚLinkedInµÈƽ̨ÉÏÁªÏµÖ¸±ê£¬ÓÕµ¼Êܺ¦Õ߿ˡ¶ñÒâGitHub´æ´¢¿â£¬Ö´ÐÐÆäÖеĴúÂëºóÏνӵ½Óɹ¥»÷Õß½ÚÔìµÄºÅÁîºÍ½ÚÔì·þÎñÆ÷¡£¸Ã·þÎñÆ÷ʹÓø߶ȻìºÏµÄPython½ÅÕý±¾Ìӱܼì²â£¬²¢Õë¶ÔÌØ¶¨Ö¸±ê¶¯Ì¬¶¨Ôì¶ñÒâÈí¼þ¡£¸Ã»î¶¯²¿ÊðÁËÓµÓÐÄ£¿é»¯×é¼þµÄ¶à½×¶Î¶ñÒâÈí¼þϵͳ£¬ÒÔÇÔÈ¡¿ª·¢ÈËÔ±µÄÔ´´úÂë¡¢»úÃÜ¡¢ÅäÖÃÎļþÒÔ¼°¼ÓÃÜÇ®±ÒÇ®°üÃÜÔ¿µÈÃô¸ÐÊý¾Ý¡£SecurityScorecard¶½´Ù¿ª·¢ÈËÔ±²ÉÈ¡×Ô¶¯µÄ°²È«´ëÊ©£¬Èç¼ÓÇ¿´úÂë´æ´¢¿âÑéÖ¤¡¢Ê¹Óø߼¶¶Ëµã°²È«½â¾ö¹æ»®¼ì²âÒì³£»î¶¯¡¢ÔÚÆ½Ì¨ÉÏÑéÖ¤ÕÐÆ¸ÈËÔ±ºÍ¹¤×÷»úÓö£¬²¢°ÑÎÕ¼ø±ðΣÏÕÐźŵÄ֪ʶ¡£
https://www.infosecurity-magazine.com/news/lazarus-developers-data-theft/
4. ºÚ¿Í¡°0mid16B¡±°ä·¢ÈëÇÖMedSave£¬ÇÔÈ¡561GBÊý¾Ý²¢´òËãÏúÊÛ
1ÔÂ17ÈÕ£¬ÃûΪ¡°0mid16B¡±µÄºÚ¿ÍÖÜÈý°ä·¢Òѳɹ¦ÈëÇÖÓ¡¶È´óÐ͵ÚÈý·½ÖÎÀí»ú¹¹MedSave£¬ÇÔÈ¡ÁË561GBµÄÊý¾Ý¿â£¬Ô̺¬³¬¹ý1000ÍòÈ˵ÄÃô¸ÐÐÅÏ¢£¬ÆäÖв»·¦¸ß¹Ü×ÊÁÏ£¬ÇÒÊý¾Ý½ØÖ¹ÖÁ2025Äê1ÔÂ8ÈÕ¡£0mid16Bδй©ÈëÇÖ¼¿Á©£¬µ«Ðû³ÆMedSave³¤¹¦·òδ¾õ²ìÆä´æÔÚ£¬ÇÒÔÚ1ÔÂ12ÈÕÖÁ15ÈÕÆÚ¼äÈý´Î½øÈëϵͳ²¢×ÌÈÅÆäÔË×÷¡£Ö»¹ÜδÏòMedSaveÌá³ö¾ßÌåÀÕË÷½ð¶î£¬0mid16BÆ·ÆÀÆä°²È«·À»¤ÓÄ΢£¬Ö¸³ö¹«Ë¾Î´×°Ö÷À²¡¶¾Èí¼þ£¬ÇÒÔÚÃ÷Öª·ì϶´æÔÚµÄÇé¿öÏÂÈÔ³ÁÆô·þÎñÆ÷£¬Ê¹ÆäµÃÒÔµÈÏд«Êä´óÁ¿Êý¾Ý¶øÎ´´¥·¢¾¯±¨¡£MedSaveÍøÕ¾Ä¿Ç°ÎÞ·¨½Ó¼û£¬DataBreachesÒѳ¢ÊÔͨ¹ý¶àÇþ·ÁªÏµMedSave·î¸æÆäÇé¿ö£¬µ«ÉÐδÊÕµ½»Ø¸´¡£0mid16B°µÊ¾ÓÐÒâÏúÊÛ²¿ÃÅÊý¾Ý²¢¹«¿ª·Ç¿Í»§Êý¾Ý£¬´ËÊÂÓдýMedSave½øÒ»²½»ØÓ¦¡£
https://databreaches.net/2025/01/17/medsave-health-insurance-tpa-hacked-firm-has-yet-to-comment-or-respond/
5. ·ÂÕÕBlack BastaÊÖ·¨µÄÍøÂç¹¥»÷¶Ô×¼SlashNext¿Í»§
1ÔÂ15ÈÕ£¬SlashNextµÄһλ¿Í»§Ôâ·êÁË·ÂÕÕ³ôÃûÔ¶ÑïµÄBlack BastaÀÕË÷Èí¼þÍÅ»ïÊÖ·¨µÄÍøÂç¹¥»÷¡£Ôڶ̶Ì90·ÖÖÓÄÚ£¬¹¥»÷ÕßÏò22¸öÓû§ÊÕ¼þÏä·¢ËÍÁË1165·â¶ñÒâÓʼþ£¬Ì°Í¼ÓÕÆÓû§µã»÷¶ñÒâÁ´½Ó¡£SlashNextµÄ×êÑÐÈËÔ±½ÒʾÁËÕâ´Î¹¥»÷Ѹ¿ìÇÒ¾«×¼£¬Ê¹ÓÃÁËÓëBlack BastaÀàËÆµÄÊÖ·¨£¬Ö¼ÔÚÈÃÓû§´ëÊÖ²»¼°²¢Èƹý´«Í³°²È«´ëÊ©¡£¹¥»÷ÕßÀûÓÃÀÕË÷Èí¼þȦÌ×£¬¼Ù×°³ÉÊ¢ÐÐÆ½Ì¨·¢ËÍÐéαÓʼþ£¬Ê¹Óÿ´ËÆÎÞº¦µÄÓòÃûºÍÌØÊâ×Ö·ûµÄÖ÷ÌâÐУ¬Õë¶Ô·ÖÆçÓû§½ÇÉ«Ìá¸ß¹Ø×¢¶È¡£ËûÃÇͨ¹ý¿´ËƺϷ¨µÄÓʼþ¸²³ä¹«¼þÏ䣬Ôì×÷»ìÂÒ£¬ÓÕʹÓû§µã»÷Á´½Ó¡£µ±Óû§¾ª»Ìʧ´ëʱ£¬¹¥»÷Õß¼ÙÒâITÖ§³ÖȾָ£¬ÓÕÆÓû§×°ÖÃÔ¶³Ì½Ó¼ûÈí¼þ£¬´Ó¶øÔÚϵͳÖÐÕ¾ÎȽŸú£¬¿ÉÄÜ´«²¼¶ñÒâÈí¼þ»òÇÔÈ¡Ãô¸ÐÊý¾Ý¡£ÐÒÔ˵ÄÊÇ£¬SlashNextµÄ¼¯³ÉÔÆÓʼþ°²ÕûϵͳѸ¿ì¼ø±ð³öΣÏÕÐźţ¬ÊµÊ±Ó¦¶Ô¡£ÕâÒ»ÊÂÎñ͹ÏÔÁËÍøÂ簲ȫÍþвµÄÈÕÒæ¸´ÔÓÐÔ£¬¹¥»÷ÕßʹÓÃÏȽø¼¼Êõ¶ã±Ü´«Í³°²È«´ëÊ©¡£Òò¶ø£¬×éÖ¯Ó¦ÓÅÏÈ˼¿¼Íþв¼ì²âºÍÏìÓ¦£¬¶¨ÆÚ½øÐа²È«ÆÀ¹À£¬ÒÔ¼ø±ð·ì϶²¢ÌáÉýÕûÌ尲ȫÐÔ¡£
https://hackread.com/black-basta-cyberattack-hits-inboxes-with-1165-emails/
6. Star Blizzardд¹µö»î¶¯¶Ô×¼WhatsAppÕË»§
1ÔÂ19ÈÕ£¬¶íÂÞ˹Ãñ×å¹ú¶ÈÐÐΪÕßStar Blizzard½üÆÚ·¢Õ¹ÁËÒ»ÏîеÄÓã²æÊ½ÍøÂç´¹µö»î¶¯£¬×¨ÃŹ¥»÷µ±¾Ö¡¢±í½»¡¢¹ú·ÀÕþ²ß¡¢¹ú¼Ê¹ØÏµ¼°ÎÚ¿ËÀ¼ÔöÔ®×éÖ¯µÈÖ¸±êµÄWhatsAppÕË»§¡£¸Ã»î¶¯ÓÚ2024Äê11ÔÂÖÐÑ®±»Î¢ÈíÍþвµý±¨»ã±¨½Òʾ£¬±ê־ȡStar BlizzardΪӦ¶ÔÕ½ÊõºÍ¼¼ÊõÆØ¹âËù×öµÄÕ½Êõת±ä¡£¹¥»÷Õßͨ¹ýµç×ÓÓʼþ¼ÙÒâÃÀ¹úµ±¾Ö¹ÙÔ±£¬ÓÕÆÖ¸±ê²ÎÓëÖ§³ÖÎÚ¿ËÀ¼µÄ·Çµ±¾Ö×éÖ¯WhatsAppȺ×飬ÓʼþÖÐÔ̺¬°Ü»µµÄ¶þάÂ룬ÈôÊܺ¦Õß»ØÓ¦£¬Ôò»á±»Êèµ¼ÖÁÐéÎ±ÍøÒ³£¬ÒªÇóɨÃèеĶþάÂ룬ʵÔòÊǽ«¹¥»÷ÕßÉ豸Á´½ÓÖÁÊܺ¦ÕßWhatsAppÕË»§¡£Î¢ÈíÖ¸³ö£¬Ò»µ©Êܺ¦Õß²Ù×÷£¬¹¥»÷Õß¼´¿É½Ó¼ûÆäWhatsAppÐÂÎÅ£¬²¢ÀûÓòå¼þÇÔÈ¡Êý¾Ý¡£Õâ´Î¹¥»÷ÒÀÀµÉç»á¹¤³Ìѧ£¬²»Éæ¼°¶ñÒâÈí¼þ£¬Óû§Ð辯Ìèδ¾ÒªÇóµÄͨѶ£¬³ö¸ñÊDzÎÓëȺ×éµÄÔ¼Ç룬²¢¶¨ÆÚ²é³ÓëWhatsAppÕË»§¹ØÁªµÄÉ豸¡£Õâ´Î»î¶¯Åú×¢£¬Ö»¹ÜStar BlizzardÔÚ2024Äê10ÔµĻÖжϺó²¿ÃÅÓòÃû±»²é·â£¬µ«ÆäÈÔͨ¹ýË÷Çóй¥»÷ý½é³ÖÐøÐж¯¡£
https://www.bleepingcomputer.com/news/security/star-blizzard-hackers-abuse-whatsapp-to-target-high-value-diplomats/


¾©¹«Íø°²±¸11010802024551ºÅ