KasperskyÅû¶Õë¶Ô¶íÂÞ˹¹¤¿ØÐÐÒµºÍµ±¾Ö»ú¹¹µÄ¹¥»÷

°ä²¼¹¦·ò 2023-10-26
1¡¢KasperskyÅû¶Õë¶Ô¶íÂÞ˹¹¤¿ØÐÐÒµºÍµ±¾Ö»ú¹¹µÄ¹¥»÷


KasperskyÔÚ10ÔÂ24ÈÕÅû¶ÁËÕë¶Ô¶íÂÞ˹¹¤¿ØÐÐÒµºÍµ±¾Ö»ú¹¹µÄ¹¥»÷»î¶¯ ¡£×êÑÐÈËÔ±ÓÚ6Ô³õ´Î¼ì²âµ½¸Ã»î¶¯ £¬¶øÔÚ8ÔÂÖÐÑ®·¢ÏÖÁËа汾µÄºóÃÅ £¬¸ÃºóÃÅÓµÓиü¸´ÔÓµÄÈÆ¹ýÖ°ÄÜ £¬Åú×¢¹¥»÷ÔÚ½øÐÐÓÅ»¯ ¡£¹¥»÷ʼÓÚÒ»¸öÔ̺¬¶ñÒâARJÎļþµÄÓʼþ £¬ÆäÖÐÓÐÒ»¸öµö¶üPDFÎĵµºÍÒ»¸öNSIS¾ç±¾ £¬¸Ã¾ç±¾ÓÃÓÚ»ñÈ¡ÖØÒªpayload²¢Æô¶¯Ëü ¡£Kaspersky³Æ £¬Í³Ò»´¹µö»î¶¯»¹´«²¼ÁËÁ½¸öÃûΪNetrunnerºÍDmcservµÄºóÃÅ £¬ÕâЩÊÇÓµÓÐ·ÖÆçC2·þÎñÆ÷ÅäÖõÄÒ»Ñù¶ñÒâÈí¼þ ¡£


https://securelist.ru/ataki-na-industrialnyj-i-gosudarstvennyj-sektory-rf/108229/


2¡¢·¨¹úÖ°ÒµÇò¶ÓASVELÔâµ½NoEscape¹¥»÷32GBÊý¾Ýй¶


¾ÝýÌå10ÔÂ24ÈÕ±¨Â· £¬·¨¹úÖ°Ò·ºÇò¶ÓLDLC ASVEL(ASVEL)Ôâµ½ÁËÀÕË÷ÍÅ»ïNoEscapeµÄ¹¥»÷ ¡£NoEscapeÔÚ10ÔÂ9ÈÕ½«¸ÃÇò¶Ó²ÎÓëÆäÍøÕ¾ £¬LDLC ASVELÓÚ10ÔÂ12ÈÕͨ¹ýýÌåÊÕµ½Í¨Öª ¡£¹¥»÷ÕßÐû³ÆÇÔÈ¡ÁË32GBÊý¾Ý £¬Ô̺¬ÇòÔ±µÄÓ×ÎÒ×ÊÁÏ¡¢»¤ÕÕºÍÉí·ÝÖ¤ £¬Óë²ÆÕþ¡¢Ë°ÎñºÍ˾·¨ÊÂÎñÓйصÄÎļþ £¬ÒÔ¼°±£ÃܺÍ̸¡¢ºÏͬºÍ»úÃܺ¯¼þµÈ ¡£ÀÕË÷ÍÅ»ïÍþвÈôÊDz»½»Êê½ð £¬¾Í»áÔÚ10ÔÂ20ÈÕ֮ǰ°ä²¼ÕâЩÊý¾Ý ¡£Ä¿Ç° £¬ASVELÒѱ»´ÓNoEscapeµÄÍøÕ¾É¾³ý £¬Åú×¢¶þÕß¿ÉÄÜÔÚ½øÐн»Éæ ¡£


https://www.bleepingcomputer.com/news/security/asvel-basketball-team-confirms-data-breach-after-ransomware-attack/


3¡¢Redcliffe LabsµÄ7TBÊý¾Ýй¶ӰÏìÔ¼1200Íò»¼Õß


ýÌå10ÔÂ25ÈÕ³Æ £¬Ó¡¶È±±·½¹úŵÒÁ´ïµÄÒ½Áƹ«Ë¾Redcliffe LabsµÄ7TBÒ½ÁÆÊý¾Ýй¶ £¬Ó°ÏìÁËÔ¼1200Íò»¼Õß ¡£×î³õ £¬×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸ö²»ÊÜÃÜÂë±£»¤µÄÊý¾Ý¿â £¬×Ü´óÓ×Ϊ7TB £¬Ô̺¬Ô¼12347297±Ê¼Í¼ £¬¾­µ÷²éÕâЩÊý¾Ý¼¯ÊôÓÚRedcliffe Labs ¡£ÆäÖÐ £¬³ýÁËÓдóÁ¿»¼ÕßÓ×ÎÒºÍÒ½ÁÆÊý¾ÝÖ®±í £¬»¹Ô̺¬¸Ã¹«Ë¾Òƶ¯ÀûÓ÷¨Ê½µÄ¿ª·¢Îļþ ¡£Ä¿Ç° £¬¸ÃÊý¾Ý¿âÒѱ»±£»¤ÆðÀ´ £¬Éв»Ã÷ÏÔ¹«¿ªÁ˶à¾Ã ¡£


https://www.hackread.com/database-mess-up-7tb-healthcare-data-leak/


4¡¢ÎÚ¿ËÀ¼NCS§³§³³ÆSmokeloader¶ñÒâÈí¼þ¹¥»î¶¯¼¤Ôö 


10ÔÂ25ÈÕ±¨Â·³Æ £¬ÎÚ¿ËÀ¼¹ú¶ÈÍøÂ簲ȫЭµ÷ÖÐÐÄ(NCS§³§³)³Æ £¬ÀûÓöñÒâÈí¼þSmokeloaderµÄ¹¥»÷»î¶¯¼¤Ôö ¡£NCS§³§³×êÑÐÏÔʾ £¬×Ô5ÔÂÒÔÀ´ £¬¶ñÒâÈí¼þÔËÓªÍÅ»ïÕë¶ÔÎÚ¿ËÀ¼µÄʵÌåÌáÒéÁË´ó¹æÄ£´¹µö¹¥»÷ £¬Ö¼ÔÚÈëÇÖϵͳ²¢ÇÔÊØÐÅÏ¢ ¡£ÔÚ×î½üµÄ»î¶¯ÖÐ £¬ºÚ¿ÍʹÓÃSmokeloader¹¥»÷µ±¾Ö»ú¹¹ºÍ½ðÈÚʵÌå £¬³ö¸ñÊǹÜÕÊÐÐÒµ ¡£ËûÃÇͨ¹ý½ðÈÚÖ÷ÌâµÄ´¹µöÓʼþÀ´ÓÕʹָ±êÏÂÔØ¶ñÒâÈí¼þ £¬¶øºóÇÔÊØÐÅÏ¢ ¡£´Ë±í £¬¹¥»÷Õß»¹»á·ÛËé»ã¿îÁ÷³Ì £¬Í¨¹ý´úÌæºÏ·¨ÕÊ»§µÄ¾ßÌåÐÅÏ¢À´½«×ʽð³Á¶¨Ïòµ½×Ô¼ºµÄÕÊ»§ £¬ÕâÍ»ÏÔÁ˹¥»÷Õß²»Ðݱ䶯µÄÕ½Êõ ¡£


https://therecord.media/surge-in-smokeloader-malware-attacks-targeting-ukrainian-financial-gov-orgs


5¡¢Salt Security¹«¿ª¹ØÓÚOAuthºÍ̸ʵÏÖAPIµÄ·ì϶


10ÔÂ24ÈÕ £¬Salt Security°ä²¼ÁËеÄ×êÑÐ £¬½ÒʾÁËGrammarly¡¢VidioºÍBukalapakµÈÔÚÏ߯½Ì¨µÄOAuthºÍ̸ʵÏÖÖÐAPIµÄ·ì϶ ¡£ÕâЩ·ì϶ÓпÉÄÜй¶Óû§Í´´¦²¢µ¼ÖÂÕÊ»§±»ÆëÈ«ÊÕÊÜ £¬´Ó¶øÓ°ÏìÊýÊ®ÒÚÓû§ £¬ÏÖÒѵõ½½â¾ö ¡£¸Ã×êÑÐÖÐ×î͹ÆðµÄÒ»µãÊÇ £¬OAuth×÷Ϊsocial-login±³ºóµÄÖØÒª¼¼Êõ £¬Æäʵ±»Éè¼ÆµÃºÜºÃ £¬Ã»ÓÐÏÔÖøÎÊÌâ ¡£²»Íâ £¬×êÑÐÈËÔ±·¢ÏֵĴóÎÞÊýÎÊÌâ¶¼ÓëʹÓÃOAuthµÄ¸÷·½ÓÃÀ´ÊµÏÖOAuthµÄ·½Ê½ÓйØ ¡£


https://salt.security/blog/oh-auth-abusing-oauth-to-take-over-millions-of-accounts


6¡¢NCC Group°ä²¼2023Äê9Ô·ÝÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨


10ÔÂ24ÈÕ £¬NCC Group°ä²¼ÁË2023Äê9Ô·ÝÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨ ¡£¼Ì8Ô·ݵÄÏà¶Ô³Á¾²ºó £¬9Ô·ݵÄÀÕË÷»î¶¯´ïµ½ÁËǰËùδÓеÄˮƽ £¬¶à´ï514¸öÖ¸±êÔâµ½¹¥»÷ £¬½Ï2022Äêͬ±ÈÔö³¤153% ¡£ÖØÒªµÄ¹¥»÷ÍÅ»ïÊÇLockBit 3.0£¨ÌáÒé79´Î¹¥»÷£©¡¢LostTrust£¨53´Î£©ºÍBlackCat£¨47´Î£© ¡£±±ÃÀµØÓòÔâµ½µÄ¹¥»÷×î¶à£¨Õ¼50%£© £¬Æä´ÎÊÇÅ·ÖÞ£¨30%£©ºÍÑÇÖÞ£¨9%£© ¡£Õë¶ÔÒ½ÁƱ£½¡ÐÐÒµµÄÀÕË÷¹¥»÷´ó·ùÔö³¤ £¬½Ï8Ô»·±ÈÔö³¤86% ¡£


https://newsroom.nccgroup.com/news/ncc-group-monthly-threat-pulse-september-2023-474190