°®¶ûÀ¼¹ú¼Ò¾¯¾ÖµÄ³Ð°üÉÌй¶50ÍòÌõ¿ÛѺ³µÁ¾µÄ¼Í¼

Ðû²¼Ê±¼ä 2023-10-25

1¡¢°®¶ûÀ¼¹ú¼Ò¾¯¾ÖµÄ³Ð°üÉÌй¶50ÍòÌõ¿ÛѺ³µÁ¾µÄ¼Í¼


¾Ý10ÔÂ23ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸ö¹ûÕæµÄÊý¾Ý¿â£¬£¬£¬£¬£¬£¬°üÀ¨Áè¼Ý50ÍòÌõÓë°®¶ûÀ¼¹ú¼Ò¾¯¾ÖGarda S¨ªoch¨¢na¿ÛѺ³µÁ¾Ïà¹ØµÄ¼Í¼¡£¡£¡£Îĵµ×ÜÊýΪ521043¸ö£¬£¬£¬£¬£¬£¬¾ÞϸΪ271.8 GB¡£¡£¡£Æ¾Ö¤°®¶ûÀ¼Ö´·¨£¬£¬£¬£¬£¬£¬µ±³µÁ¾±»¿ÛѺʱ£¬£¬£¬£¬£¬£¬³µÖ÷Ðë³öʾÉí·Ý֤ʵºÍ°ü¹ÜÎļþµÈ¶à·ÝÎļþ£¬£¬£¬£¬£¬£¬Òò´Ëй¶µÄ50Íò·ÝÎĵµ¿ÉÄÜÓ°ÏìÁËÔ¼15ÍòÃû³µÖ÷¡£¡£¡£½øÒ»³ÌÐò²éÏÔʾ£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âÊôÓÚ°®¶ûÀ¼ÀûĬÀï¿ËµÄÒ»¼Ò˽ÈËÊÖÒճаüÉÌ¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬Ð¹Â¶Êý¾ÝÒѱ»±£»£»£»£» £»£»¤ÆðÀ´¡£¡£¡£


https://www.hackread.com/contractor-data-breach-irish-national-police-vehicle-seizure/


2¡¢ºÚ¿ÍÒÔ8ÍòÃÀÔª¼ÛÇ®³öÊÛ8.15ÒÚÌõÓ¡¶È¹«ÃñµÄPII¼Í¼


ýÌå10ÔÂ24Èճƣ¬£¬£¬£¬£¬£¬ºÚ¿ÍÔÚ°µÍø³öÊÛÊýÒÚÌõÓ¡¶È¹«ÃñµÄPII¼Í¼£¬£¬£¬£¬£¬£¬°üÀ¨Aadhaar¿¨¡£¡£¡£AadhaarÊÇÒ»¸ö12λµÄСÎÒ˽¼Òʶ±ðÂ룬£¬£¬£¬£¬£¬ÓÉÓ¡¶ÈΨһÉí·Ýʶ±ð»ú¹¹´ú±íÓ¡¶ÈÕþ¸®½ÒÏþ¡£¡£¡£10ÔÂ9ÈÕ£¬£¬£¬£¬£¬£¬ÃûΪpwn0001µÄºÚ¿ÍÔÚ°µÍøÐû²¼ÁËÒ»¸öÌû×Ó£¬£¬£¬£¬£¬£¬³ÆÓµÓÐ8.15ÒÚÓ¡¶È¹«ÃñAadhaarºÍ»¤Õռͼ£¬£¬£¬£¬£¬£¬²¢Ô¸ÒâÒÔ80000ÃÀÔªµÄ¼ÛÇ®³öÊÛÕû¸öÊý¾Ý¿â¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬£¬pwn0001»¹¹ûÕæÁË4¸öÑù±¾£¬£¬£¬£¬£¬£¬ÆäÖÐÒ»¸öÑù±¾°üÀ¨100000ÌõÓ¡¶ÈסÃñµÄPII¡£¡£¡£


https://securityaffairs.com/152957/security/pii-indian-citizens-dark-web.html


3¡¢BHI EnergyÏêÊöAkiraÔõÑùÈëÇÖÆäϵͳ²¢ÇÔÈ¡Êý¾Ý


¾ÝýÌå10ÔÂ23ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬ÃÀ¹úÄÜÔ´¹«Ë¾BHI EnergyÅû¶ÁËAkiraÔÚ5ÔÂ30ÈÕÈëÇÖÆäϵͳµÄÏêϸÐÅÏ¢¡£¡£¡£AkiraʹÓÃÇÔÈ¡µÄµÚÈý·½µÄVPNƾ֤»á¼ûBGIµÄÄÚÍø£¬£¬£¬£¬£¬£¬ÔÚÊ״λá¼ûºóµÄÒ»ÖÜÄÚʹÓÃͳһ¸öÕË»§¶ÔÄÚÍø¾ÙÐÐÕì̽¡£¡£¡£6ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬AkiraÔٴλá¼ûϵͳ£¬£¬£¬£¬£¬£¬Ã¶¾ÙÊý¾Ý£¬£¬£¬£¬£¬£¬²¢ÔÚ6ÔÂ20ÈÕÖÁ29ÈÕÇÔÈ¡ÁË767k¸öÎļþ£¬£¬£¬£¬£¬£¬¹²690 GB£¬£¬£¬£¬£¬£¬°üÀ¨Windows Active DirectoryÊý¾Ý¿â¡£¡£¡£×îºó£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÓÚ6ÔÂ29ÈÕÇÔÈ¡ÁËËùÓÐÊý¾Ýºó£¬£¬£¬£¬£¬£¬ÔÚËùÓÐ×°±¸ÉÏ×°ÖÃÁËAkiraÀÕË÷Èí¼þÀ´¼ÓÃÜÎļþ¡£¡£¡£Õâʱ£¬£¬£¬£¬£¬£¬BHI²ÅÒâʶµ½¹«Ë¾Òѱ»ÈëÇÖ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/us-energy-firm-shares-how-akira-ransomware-hacked-its-systems/


4¡¢Î÷°àÑÀ¾¯·½µ·»ÙÄ³ÍøÂçÕ©Æ­ÍŻﲢ¾Ð²¶34ÃûÏÓÒÉÈË


10ÔÂ24ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬Î÷°àÑÀ¹ú¼Ò¾¯Ô±¾Öµ·»ÙÁËÒ»¸öÍøÂç·¸·¨ÍŻ¡£¡£¸ÃÍÅ»ïÖ´ÐÐÖÖÖÖÅÌËã»úÕ©Æ­£¬£¬£¬£¬£¬£¬ÇÔÈ¡ÁËÁè¼Ý400ÍòÈ˵ÄÊý¾Ý£¬£¬£¬£¬£¬£¬×¬È¡ÁËÔ¼300ÍòÅ·Ôª¡£¡£¡£Ö´·¨²¿·ÖÔÚÂíµÂÀï¡¢ÂíÀ­¼Ó¡¢Î¤¶ûÍß¡¢°¢Àû¿²ÌغÍĶûÎ÷ÑǾÙÐÐÁË16´ÎÓÐÕë¶ÔÐÔµÄËѲ飬£¬£¬£¬£¬£¬ÒѾв¶34Ãû·¸·¨ÍÅ»ïµÄ³ÉÔ±¡£¡£¡£¾¯·½³Æ£¬£¬£¬£¬£¬£¬±»²¶ÕßÓëð³ä¿ìµÝ¹«Ë¾ºÍµçÁ¦¹©Ó¦É̵Ĵ¹ÂڻÓйء£¡£¡£¸ÃÍÅ»ïµÄÍ·Ä¿Òѱ»¾Ð²¶£¬£¬£¬£¬£¬£¬¶ÔÆäËû³ÉÔ±Éí·ÝµÄÊÓ²ìÈÔÔÚ¾ÙÐÐÖС£¡£¡£


https://securityaffairs.com/152946/cyber-crime/spanish-police-dismantled-cybercriminal-group.html


5¡¢Ñо¿Ö°Ô±Ðû²¼VMwarevÎó²îCVE-2023-34051µÄPoC


ýÌå10ÔÂ24Èճƣ¬£¬£¬£¬£¬£¬VMwarevÌáÐÑvRealize Log Insight£¨ÏÖ³ÆÎªVMware Aria Operations for Logs£©ÖÐÎó²îµÄPoCÒÑÐû²¼¡£¡£¡£ÕâÊÇÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2023-34051£©£¬£¬£¬£¬£¬£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔ½«Îļþ×¢ÈëÄ¿µÄϵͳÖУ¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£Horizon3Ðû²¼ÁËPoC£¬£¬£¬£¬£¬£¬ËüʹÓÃIPµØµãÓÕÆ­ºÍÖÖÖÖThrift RPC¶ËµãÀ´ÊµÏÖí§ÒâÎļþдÈë¡£¡£¡£Ñо¿Ö°Ô±½¨ÒéÁ¬Ã¦×°ÖøüС£¡£¡£


https://www.bleepingcomputer.com/news/security/vmware-warns-admins-of-public-exploit-for-vrealize-rce-flaw/


6¡¢KasperskyÐû²¼Triangulation»î¶¯µÄÒþ²ØÐԵı¨¸æ


10ÔÂ23ÈÕ£¬£¬£¬£¬£¬£¬KasperskyÐû²¼Á˹ØÓÚTriangulation»î¶¯µÄÒþ²ØÐÔµÄÆÊÎö±¨¸æ¡£¡£¡£¸Ã±¨¸æÏÈÈÝÁ˴˴ι¥»÷µÄÖÖÖÖÒþÐÎÊÖÒÕ£¬£¬£¬£¬£¬£¬ÒÔ¼°¹¥»÷ÖÐʹÓõÄ×é¼þ¡£¡£¡£ÔÚ°²ÅÅTriangleDB֮ǰ£¬£¬£¬£¬£¬£¬»áʹÓÃÁ½¸öÑéÖ¤Æ÷À´ÍøÂç×°±¸ÐÅÏ¢£¬£¬£¬£¬£¬£¬²¢È·±£´úÂë²»»áÔÚÆÊÎöÇéÐÎÖÐÖ´ÐС£¡£¡£Ëü»¹°üÀ¨Ò»¸öÂó¿Ë·ç¼ÒôÄ£¿£¿ £¿£¿£¿émsu3h£¬£¬£¬£¬£¬£¬Ä¬ÈÏ¿ÉÒÔ¼ÒôÈý¸öСʱ£¬£¬£¬£¬£¬£¬µ«ÈôÊǵçÁ¿µÍÓÚ10%ÇÒ×°±¸ÆÁÄ»ÕýÔÚʹÓý«ÔÝͣ¼Òô¡£¡£¡£¹¥»÷Õß»¹ÊµÑéÁËÌØÁíÍâÔ¿³×´®Ð¹Â¶Ä£¿£¿ £¿£¿£¿é¡¢SQLiteÊý¾Ý¿âÇÔÈ¡¹¦Ð§ÒÔ¼°Î»ÖÃ¼à¿ØÄ£¿£¿ £¿£¿£¿é£¨ÔÚGPS²»¿ÉÓÃʱʹÓÃÍøÂçÔªÊý¾Ý£©¡£¡£¡£


https://securelist.com/triangulation-validators-modules/110847/