ºÚ¿ÍÔÚ°µÍø³öÊÛ¼ÓÄôóÔËÓªÉÌRogersµÄ3¸öADÊý¾Ý¿â

Ðû²¼Ê±¼ä 2023-04-11

1¡¢ºÚ¿ÍÔÚ°µÍø³öÊÛ¼ÓÄôóÔËÓªÉÌRogersµÄ3¸öADÊý¾Ý¿â


¾ÝýÌå4ÔÂ7ÈÕ±¨µÀ £¬ £¬£¬¹¥»÷ÕßÔÚÒ»¸ö¶íÓïµÄºÚ¿ÍÂÛ̳ÉÏÐû²¼ÁËÒ»Ôò¹ã¸æ £¬ £¬£¬Éù³ÆÒª³öÊÛ¼ÓÄôóÍøÂçÔËÓªÉÌRogers CommunicationsµÄÊý¾Ý¿â¡£¡£¡£¡£ ¡£ÆäÖаüÀ¨RogersµÄ3¸ö»î¶¯Ä¿Â¼£¨AD£©Êý¾Ý¿â£ºusers¡¢groupsºÍdevices¡£¡£¡£¡£ ¡£Í¨³£ £¬ £¬£¬AD°üÀ¨Óйع«Ë¾ÇéÐεÄÒªº¦Êý¾Ý¡£¡£¡£¡£ ¡£Rogers֤ʵ £¬ £¬£¬¸Ã¹«Ë¾µÄ²¿·ÖÊý¾ÝÔÚ°µÍøÉÏй¶ £¬ £¬£¬È»¶øÐ¹Â¶µÄÊý¾Ý¿âÖнö°üÀ¨Ô±¹¤Êý¾Ý £¬ £¬£¬Ã»Óпͻ§µÄÏêϸÐÅÏ¢¡£¡£¡£¡£ ¡£Õâ3¸öÊý¾Ý¿âµÄ±ê¼ÛΪ14000ÃÀÔª £¬ £¬£¬Ã»ÓÐÏêϸ˵Ã÷Êý¾Ý¿âµÄ¾Þϸ»òËüËù¹ûÕæµÄ¹«Ë¾Óû§ÊýÄ¿¡£¡£¡£¡£ ¡£


https://cybernews.com/news/rogers-communications-data-breach/


2¡¢SD WorxÔâµ½¹¥»÷±»ÆÈ¹Ø±ÕÆäÓ¢¹úºÍ°®¶ûÀ¼µÄ»ù´¡ÉèÊ©


ýÌå4ÔÂ10ÈÕ³Æ £¬ £¬£¬±ÈÀûʱÈËÁ¦×ÊÔ´¹«Ë¾SD WorxÔâµ½ÍøÂç¹¥»÷ £¬ £¬£¬±»ÆÈ¹Ø±ÕÆäÓ¢¹úºÍ°®¶ûÀ¼µÄIT»ù´¡ÉèÊ©¡£¡£¡£¡£ ¡£SD Worx¸øÓ¢¹úºÍ°®¶ûÀ¼¿Í»§µÄ֪ͨ³Æ £¬ £¬£¬ËûÃÇÔÚÍйÜÊý¾ÝÖÐÐÄ·¢Ã÷¶ñÒâ»î¶¯ £¬ £¬£¬ÒѽÓÄÉÐж¯²¢¸ôÀëÁËËùÓÐϵͳºÍЧÀÍÆ÷¡£¡£¡£¡£ ¡£¸Ã¹«Ë¾Õë¶ÔÆäËüÅ·ÖÞ¹ú¼ÒµÄµÇÂ¼ÍøÕ¾ÈÔÈ»ÔËÐÐÕý³£ £¬ £¬£¬µ«Ó¢¹úµÄÍøÕ¾ÎÞ·¨»á¼û¡£¡£¡£¡£ ¡£Ã»ÓйØÓڴ˴ι¥»÷ÀàÐ͵ÄÏêϸÐÅÏ¢ £¬ £¬£¬ÓÐÈ˵£ÐÄÃô¸ÐÊý¾ÝÔÚ¹¥»÷ʱ´ú±»µÁ¡£¡£¡£¡£ ¡£×÷Ϊһ¼ÒÈËÁ¦×ÊÔ´ºÍн×ʹ«Ë¾ £¬ £¬£¬SD WorxΪÆä¿Í»§µÄÔ±¹¤ÖÎÀí×Å´ó×ÚÃô¸ÐÊý¾Ý £¬ £¬£¬Èç˰ÎñÐÅÏ¢¡¢Éí·ÝÖ¤ºÅÂëºÍÒøÐÐÕʺŵÈ¡£¡£¡£¡£ ¡£


https://securityaffairs.com/144629/hacking/sd-worx-suffered-cyberattack.html


3¡¢ÈûÆÖ·˹¿ª·Å´óѧOUCÔâµ½ÀÕË÷ÍÅ»ïMedusaµÄ¹¥»÷


¾Ý4ÔÂ6ÈÕ±¨µÀ £¬ £¬£¬ÀÕË÷ÍÅ»ïMedusaÉù³Æ¹¥»÷ÁËÈûÆÖ·˹¿ª·Å´óѧ(OUC)¡£¡£¡£¡£ ¡£OUCÊÇλÓÚÈûÆÖ·˹Äá¿ÆÎ÷ÑǵÄÒ»ËùÔÚÏß´óѧ £¬ £¬£¬ÌṩԶ³Ìѧϰ¡£¡£¡£¡£ ¡£ÉÏÖÜ £¬ £¬£¬¸Ã´óѧÐû²¼ÁËÒ»·Ý¹ØÓÚ3ÔÂ27ÈÕ±¬·¢µÄÍøÂç¹¥»÷µÄͨ¸æ £¬ £¬£¬´Ë´Î¹¥»÷µ¼Ö¶àÆäÖÐÑëЧÀͺÍÒªº¦ÏµÍ³å´»ú¡£¡£¡£¡£ ¡£4ÔÂ6ÈÕ £¬ £¬£¬MedusaÔÚÍøÕ¾ÉÏÁгöÁËOUC²¢ÀÕË÷100000ÃÀÔª £¬ £¬£¬Áô¸ø¸Ã»ú¹¹14ÌìµÄʱ¼ä¡£¡£¡£¡£ ¡£¸ÃÍŻﻹÐû²¼Á˱»µÁÊý¾ÝÑù±¾ £¬ £¬£¬É漰ѧÉúÃûµ¥ºÍ³Ð°üÉ̵IJÆÎñϸ½ÚµÈ¡£¡£¡£¡£ ¡£


https://www.bleepingcomputer.com/news/security/medusa-ransomware-claims-attack-on-open-university-of-cyprus/


4¡¢SucuriÅû¶Õë¶ÔWPÍøÕ¾µÄ´ó¹æÄ£Balad Injector»î¶¯


SucuriÔÚ4ÔÂ6ÈÕÅû¶ÁË×Ô2017ÄêÒÔÀ´Ò»Ö±¹¥»÷WordPressÍøÕ¾µÄ´ó¹æÄ£Balada Injector»î¶¯¡£¡£¡£¡£ ¡£Sucuri³Æ £¬ £¬£¬Balada Injector¹¥»÷ԼĪÿÔ±¬·¢Ò»´Î £¬ £¬£¬Ã¿´Î¹¥»÷¶¼Ê¹ÓÃÐÂ×¢²áµÄÓòÃûÀ´Èƹý×èµ²Ãûµ¥¡£¡£¡£¡£ ¡£Í¨³£ £¬ £¬£¬¶ñÒâÈí¼þ»áʹÓÃËùÓÐÒÑÖªºÍ×î½ü·¢Ã÷µÄÖ÷ÌâºÍ²å¼þÎó²î £¬ £¬£¬Ö÷ҪעÈëLinuxºóÃÅ¡£¡£¡£¡£ ¡£SucuriÊӲ쵽µÄ×¢ÈëÒªÁì°üÀ¨siteurl hack¡¢HTML×¢Èë¡¢Êý¾Ý¿â×¢ÈëºÍí§ÒâÎļþÉÏ´«¡£¡£¡£¡£ ¡£Ñо¿Ö°Ô±Ô¤¼Æ £¬ £¬£¬Áè¼Ý100Íò¸öWordPressÍøÕ¾Òѱ»´Ë»î¶¯Ñ¬È¾¡£¡£¡£¡£ ¡£


https://blog.sucuri.net/2023/04/balada-injector-synopsis-of-a-massive-ongoing-wordpress-malware-campaign.html


5¡¢MicrosoftÐû²¼MERCURYÓëDEV-1084Э×÷¹¥»÷µÄ±¨¸æ


4ÔÂ7ÈÕ £¬ £¬£¬MicrosoftÐû²¼Á˹ØÓÚMERCURYÓëDEV-1084Э×÷¹¥»÷µÄÆÊÎö±¨¸æ¡£¡£¡£¡£ ¡£Microsoft¼ì²âµ½ÁËÓëÒÁÀÊÏà¹ØµÄMERCURYµÄ¹¥»÷»î¶¯¡£¡£¡£¡£ ¡£ÒÔǰµÄMERCURY¹¥»÷ÊÇÕë¶ÔÍâµØÇéÐÎ £¬ £¬£¬È»¶ø £¬ £¬£¬´Ë´Î¹¥»÷»¹Õë¶ÔÔÆ×ÊÔ´¡£¡£¡£¡£ ¡£MicrosoftÒÔΪ £¬ £¬£¬Ëü¿ÉÄÜÓëDEV-1084ÏàÖú £¬ £¬£¬ºóÕßÔÚMERCURYÀֳɽøÈëÄ¿µÄÇéÐκóÖ´Ðй¥»÷¡£¡£¡£¡£ ¡£MERCURY¿ÉÄÜʹÓÃδÐÞ¸´Ó¦ÓÃÖеÄÎó²î¾ÙÐгõʼ»á¼û £¬ £¬£¬Ö®ºó½«»á¼ûȨÏÞÒÆ½»¸øDEV-1084 £¬ £¬£¬È»ºóÖ´ÐÐÕì̽¡¢½¨É賤ÆÚÐÔ²¢ºáÏòÒÆ¶¯ £¬ £¬£¬Í¨³£ÐèÒªÆÚ´ýÊýÖÜÉõÖÁÊýÔ²Żª½øÈëÏÂÒ»½×¶Î¡£¡£¡£¡£ ¡£


https://www.microsoft.com/en-us/security/blog/2023/04/07/mercury-and-dev-1084-destructive-attack-on-hybrid-environment/


6¡¢CyfirmaÐû²¼¹ØÓÚARES LeaksÔËÓª¡¢Éú³¤ºÍÄÜÁ¦µÄÆÊÎö


ýÌå4ÔÂ8ÈÕ±¨µÀ £¬ £¬£¬CyfirmaÐû²¼¹ØÓÚÐÂÍþв×éÖ¯ARES LeaksµÄÆÊÎö±¨¸æ¡£¡£¡£¡£ ¡£×ÔBreachedForum¹Ø±ÕÒÔÀ´ £¬ £¬£¬ARES Leaks»î¶¯ÓÐËùÔöÌí £¬ £¬£¬Åú×¢ÔÚ²»¾ÃµÄδÀ´ËüÓпÉÄܳÉΪ±¸Ñ¡¼Æ»®Ö®Ò»¡£¡£¡£¡£ ¡£OSINTËÑË÷·¢Ã÷ARES GroupµÄÖÎÀíÔ±³öÊÛÁãÈÕÎó²î £¬ £¬£¬Åú×¢¸Ã×éÖ¯ÕýÔÚʹÓÃÎó²îÀ´¹¥»÷»µÏµÍ³¡£¡£¡£¡£ ¡£¸Ã×éÖ¯ÓÉÉøÍ¸²âÊÔÖ°Ô±ºÍ¶ñÒâÈí¼þ¿ª·¢ÕßµÈ×ÊÔ´×é³É¡£¡£¡£¡£ ¡£³ýÁËÊý¾Ýй¶Íâ £¬ £¬£¬Ëü»¹Ìṩ½©Ê¬ÍøÂçºÍDDoSЧÀÍ¡£¡£¡£¡£ ¡£ARES»¹ÌåÏÖ³öÀàËÆcartelµÄÐÐΪ £¬ £¬£¬Æð¾¢×·ÇóÓëÆäËû¹¥»÷ÕßµÄÁªÏµ¡£¡£¡£¡£ ¡£


https://www.cyfirma.com/outofband/ares-leaks-emerging-cyber-crime-cartel/