Ï£À°¹úÓÐÓÊÕþ¹«Ë¾ELTAÒòÔâµ½ÀÕË÷¹¥»÷ËùÓÐЧÀÍÔÝÍ£
Ðû²¼Ê±¼ä 2022-03-25Ï£À°¹úÓÐÓÊÕþ¹«Ë¾ELTAÒòÔâµ½ÀÕË÷¹¥»÷ËùÓÐЧÀÍÔÝÍ£
¾ÝýÌå3ÔÂ22ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬Ï£À°¹úÓÐÓÊÕþ¹«Ë¾ELTAÔâµ½ÁËÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¡£¡£ELTAÔÚÉÏÖÜÈÕ¼ì²âµ½Çå¾²ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬²¢Á¬Ã¦×ö³öÏìÓ¦²¢¶ÔÕû¸öÊý¾ÝÖÐÐľÙÐиôÀë¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾³Æ£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÆäϵͳÖÐÒ»¸öδÐÞ¸´µÄÎó²îÀ´×°ÖöñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þͨ¹ýHTTPS·´Ïòshell»á¼ûÊÂÇéÕ¾¡£¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷µ¼Ö¸Ã×éÖ¯µÄ´ó²¿·Öϵͳ´¦ÓÚÀëÏß״̬£¬£¬£¬£¬£¬£¬£¬ELTA²»¿É¾ÙÐÐÓʼġ¢Õ˵¥Ö§¸¶»ò´¦Öóͷ£½ðÈÚÉúÒâ¶©µ¥£¬£¬£¬£¬£¬£¬£¬ÇÒÉÐδȷ¶¨ºÎʱ¿É»Ö¸´Õý³£ÔËÓª¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/greeces-public-postal-service-offline-due-to-ransomware-attack/
AnonymousÍÅ»ïÉù³ÆÒÑÈëÇÖÈðʿȸ³²¼¯ÍŵÄÄÚÍø
ýÌå3ÔÂ22ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍÍÅ»ïAnonymousÉù³ÆÒÑÈëÇÖÁËÈðʿȸ³²¼¯ÍÅ£¨Nestl¨¨£©µÄÄÚÍø£¬£¬£¬£¬£¬£¬£¬²¢ÇÔÈ¡ÁË10 GBµÄÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£¡£3ÔÂ21ÈÕ£¬£¬£¬£¬£¬£¬£¬AnonymousÐû²¼ÍÆÎÄÏòȸ³²ÐûÕ½£¬£¬£¬£¬£¬£¬£¬ÌåÏÖ½«¶ÔÆä¾ÙÐÐÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¡£3ÔÂ22ÈÕ£¬£¬£¬£¬£¬£¬£¬¸ÃÍÅ»ï³ÆÒÑÇÔÈ¡¹«Ë¾Óʼþ¡¢ÃÜÂëºÍÉÌÒµ¿Í»§Ïà¹ØµÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬²¢¹ûÕæÁËȸ³²µÄ5Íò¸öÆóÒµ¿Í»§µÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬£¬È¸³²·ñ¶¨ÆäÔâµ½Á˹¥»÷£¬£¬£¬£¬£¬£¬£¬²¢³ÆÐ¹Â¶Êý¾ÝÀ´×Ô½ñÄê2Ô·ݣ¬£¬£¬£¬£¬£¬£¬ÆäʱһЩB2BÐÔ×ӵIJâÊÔÊý¾ÝÎÞÒâÖÐÔÚij¸öÉÌÒµ²âÊÔÍøÕ¾ÉÏ»á¼û¡£¡£¡£¡£¡£¡£¡£
https://therecord.media/nestle-denies-cyberattack-says-stolen-data-came-from-business-test-website/
Okta³ÆÆäÔâµ½LAPSUS$µÄ¹¥»÷£¬£¬£¬£¬£¬£¬£¬½ü2.5%¿Í»§ÊÜÓ°Ïì
¾Ý3ÔÂ22ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬»á¼ûÖÎÀíϵͳ¹©Ó¦ÉÌOktaÌåÏÖ£¬£¬£¬£¬£¬£¬£¬Ô¼2.5%µÄ¿Í»§Êܵ½ÀÕË÷ÍÅ»ïLapsus$µÄ¹¥»÷µÄÓ°Ïì¡£¡£¡£¡£¡£¡£¡£Okta֤ʵ£¬£¬£¬£¬£¬£¬£¬ËûÃÇÔÚ1Ô·ݱ¬·¢ÁËÒ»ÆðÇå¾²ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚ1ÔÂ16ÈÕÖÁ21ÈÕʱ´úÄÚ¿É»á¼ûÆäÒ»ÃûÖ§³Ö¹¤³ÌʦµÄÌõ¼Ç±¾µçÄÔ£¬£¬£¬£¬£¬£¬£¬¸ÃÌõ¼Ç±¾¿ÉΪ¿Í»§ÖØÖÃÃÜÂë¡£¡£¡£¡£¡£¡£¡£¶øLapsus$»ØÓ¦³Æ£¬£¬£¬£¬£¬£¬£¬ËûÃDz¢Ã»ÓÐÈëÇÖOktaÔ±¹¤µÄÌõ¼Ç±¾µçÄÔ£¬£¬£¬£¬£¬£¬£¬¶øÊÇthin¿Í»§¶Ë¡£¡£¡£¡£¡£¡£¡£²¢¶ÔOktaµÄÉùÃ÷Ìá³öÒìÒ飬£¬£¬£¬£¬£¬£¬³ÆËûÃÇÒѵǼµ½³¬µÈÓû§£¬£¬£¬£¬£¬£¬£¬²¢¿ÉÒÔÖØÖÃÔ¼95%µÄ¿Í»§µÄÃÜÂëºÍMFA¡£¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2022/03/microsoft-and-okta-confirm-breach-by.html
¶íÂÞ˹MiratorgÔ⵽ʹÓÃBitLocker¼ÓÃܵÄÀÕË÷¹¥»÷
ýÌå3ÔÂ22ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬¶íÂÞ˹ÊÞÒ½ºÍÖ²Îï¼ìÒß¼àÊÓ»ú¹¹Rosselkhoznadzorͨ¸æ³Æ£¬£¬£¬£¬£¬£¬£¬×ܲ¿Î»ÓÚĪ˹¿ÆµÄÈâÀàÉú²úÉÌMiratorg Agribusiness HoldingÔâµ½ÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¡£¸Ã»ú¹¹³Æ£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÁËWindowsµÄBitLocker¼ÓÃܹ«Ë¾Îļþ£¬£¬£¬£¬£¬£¬£¬ÕâʵÖÊÉÏÊÇÀÕË÷¹¥»÷£¬£¬£¬£¬£¬£¬£¬µ«¹¥»÷µÄÄ¿µÄËÆºõÊÇ¸ãÆÆËð¶ø·Ç׬Ǯ¡£¡£¡£¡£¡£¡£¡£Í×еãλÓÚVetIS£¬£¬£¬£¬£¬£¬£¬Ò»¸ö¸ÃÁìÓòµÄ¹«Ë¾Ê¹ÓõĹú¼ÒÐÅϢϵͳ£¬£¬£¬£¬£¬£¬£¬ÕâºÜ¿ÉÄÜÊÇÒ»´Î¹©Ó¦Á´¹¥»÷¡£¡£¡£¡£¡£¡£¡£Miratorg½ÒÏþÉùÃ÷£¬£¬£¬£¬£¬£¬£¬³ÆËüÒѾÔÚÆð¾¢»Ö¸´Õý³£ÔËÓª¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/top-russian-meat-producer-hit-with-windows-bitlocker-encryption-attack/
Censys³ÆDeadBoltÔÚÉÏÖÜÒÑѬȾÉÏǧ̨QNAP NAS×°±¸
3ÔÂ21ÈÕ£¬£¬£¬£¬£¬£¬£¬CensysÐû²¼±¨¸æ³ÆQNAP×°±¸³ÉΪÐÂÒ»²¨DeadBoltÀÕË÷¹¥»÷µÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬£¬×îÐµĹ¥»÷×îÏÈÓÚ3ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬£¬Æäʱ×ܹ²373̨װ±¸±»Ñ¬È¾£¬£¬£¬£¬£¬£¬£¬µ½3ÔÂ19ÈÕ¸ÃÊý¾ÝÉÏÉýµ½ÁË1146¸ö¡£¡£¡£¡£¡£¡£¡£¾Ý×îб¨µÀ³Æ£¬£¬£¬£¬£¬£¬£¬3ÔÂ22ÈÕ½ü1500̨NAS×°±¸Òѱ»Ñ¬È¾¡£¡£¡£¡£¡£¡£¡£´Ë´Î»î¶¯Óë½ñÄê1Ô·ݵĵÚÒ»ÂÖ¹¥»÷ÀàËÆ£¬£¬£¬£¬£¬£¬£¬ÈÔÈ»ÊÇÀÕË÷0.03 BTCÊê½ð£¨Ô¼1277ÃÀÔª£©¡£¡£¡£¡£¡£¡£¡£µÚÒ»ÂÖ¹¥»÷ÔÚ1ÔÂ26ÈÕµÖ´ï·åÖµ£¬£¬£¬£¬£¬£¬£¬ÓÐ4988̨ѬȾDeadboltµÄQNAP×°±¸¡£¡£¡£¡£¡£¡£¡£1ÔÂ⣬£¬£¬£¬£¬£¬£¬QNAP¶ÔÆäNAS×°±¸¾ÙÐÐÁËÇ¿ÖÆ¹Ì¼þ¸üÐÂÒÔµÖÓù´ËÀ๥»÷¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.co/wordpress/129373/malware/qnap-nas-deadbolt-ransomware.html
ESET·¢Ã÷Mustang PandaʹÓÃеÄHodurµÄ¹¥»÷»î¶¯
3ÔÂ23ÈÕ£¬£¬£¬£¬£¬£¬£¬ESETÐû²¼Á˹ØÓÚAPT×éÖ¯Mustang Panda¹¥»÷»î¶¯µÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£´Ë´Î»î¶¯Ö÷ÒªÕë¶Ô¶«ÑǺͶ«ÄÏÑÇ£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°²¿·ÖÅ·Ö޺ͷÇÖÞµØÇø£¬£¬£¬£¬£¬£¬£¬ÒÑÖªµÄÄ¿µÄÐÐ񵃾¼°Ñо¿»ú¹¹¡¢»¥ÁªÍøÐ§ÀÍÌṩÉÌ(ISP)ºÍλÓÚ¶«ÑǺͶ«ÄÏÑǵÄÅ·ÖÞÍ⽻ʹÍÅ¡£¡£¡£¡£¡£¡£¡£¹¥»÷»î¶¯×îÔç¿ÉÒÔ×·Ëݵ½2021Äê8Ô£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃÁËÓëÅ·ÖÞ×îÐÂÊ±ÊÆÏà¹ØµÄÓÕ¶ü¡£¡£¡£¡£¡£¡£¡£×îÖÕÖ¼ÔÚ×°ÖÃÒ»¸öÃûΪHodurµÄкóÃÅ£¬£¬£¬£¬£¬£¬£¬ËüÓëÈ¥Äê7ÔÂÅû¶µÄPlugX£¨ÓÖÃûKorplug£©±äÌåTHORÏàËÆ¡£¡£¡£¡£¡£¡£¡£
https://www.welivesecurity.com/2022/03/23/mustang-panda-hodur-old-tricks-new-korplug-variant/
Çå¾²¹¤¾ß
PSRansom
ÊǾßÓÐ C2 ЧÀÍÆ÷¹¦Ð§µÄ PowerShell ÀÕË÷Èí¼þÄ£ÄâÆ÷¡£¡£¡£¡£¡£¡£¡£
https://github.com/JoelGMSec/PSRansom
RDWA recon
ÓÃÓÚ´Ó Microsoft Ô¶³Ì×ÀÃæ Web »á¼û (RDWA) Ó¦ÓóÌÐòÖÐÌáÊØÐÅÏ¢µÄ python ¾ç±¾¡£¡£¡£¡£¡£¡£¡£
https://github.com/p0dalirius/RDWArecon
Cloak
ÊÇÒ»Öֿɲå°Î´«Ê䣬£¬£¬£¬£¬£¬£¬¿ÉÔöÇ¿ OpenVPN µÈ¹Å°åÊðÀí¹¤¾ß£¬£¬£¬£¬£¬£¬£¬ÒÔ¹æ±ÜÖØ´óµÄÉó²éºÍÊý¾ÝÅб𡣡£¡£¡£¡£¡£¡£
https://github.com/cbeuw/Cloak
Zscan
Intranet¶Ë¿ÚɨÃèÒÇ¡¢±¬ÆÆ¹¤¾ßºÍÆäËûÊÊÓóÌÐòµÄ¿ªÔ´ÜöÝÍ¡£¡£¡£¡£¡£¡£¡£
https://github.com/zyylhn/zscan/
Çå¾²ÆÊÎö
Windows 10 KB5011543 ¸üÐÂÐû²¼
https://www.bleepingcomputer.com/news/microsoft/windows-10-kb5011543-update-released-with-search-highlights-feature/
°×¹¬·ÖÏíÇåµ¥ÒÔÓ¦¶Ô¶íÂÞË¹ÍøÂç¹¥»÷
https://www.bleepingcomputer.com/news/security/white-house-shares-checklist-to-counter-russian-cyberattacks/
DEV-0537 Õë¶Ô×éÖ¯¾ÙÐÐÊý¾Ýй¶ºÍÆÆËðµÄ·¸·¨·Ö×Ó
https://www.microsoft.com/security/blog/2022/03/22/dev-0537-criminal-actor-targeting-organizations-for-data-exfiltration-and-destruction/
FIDO ÕýÔÚÌáÒé¶Ô WebAuthn ¾ÙÐе÷½â
https://threatpost.com/fido-knife-murder-passwords/179031/
2022 ÄêÈõÃÜÂ뱨¸æ¶Ô IT Çå¾²µÄÒâÒåµÄǰ 5¼þÊÂ
https://www.bleepingcomputer.com/news/security/the-top-5-things-the-2022-weak-password-report-means-for-it-security/


¾©¹«Íø°²±¸11010802024551ºÅ