Landmark PropertiesÔâMorpheus¹¥»÷ £¬³¬1TBÊý¾Ýй¶

°ä²¼¹¦·ò 2025-05-23

1. Landmark PropertiesÔâMorpheus¹¥»÷ £¬³¬1TBÊý¾Ýй¶


5ÔÂ21ÈÕ £¬·¿µØ²ú¿ª·¢ÉÌLandmark PropertiesÔâMorpheusÀÕË÷Èí¼þÍŻ﹥»÷ £¬³¬1TBÊý¾Ý±»ÇÔ¡£¸ÃÊÂÎñÔ´ÓÚMorpheusÀÕË÷Èí¼þÍÅ»ïÔÚ°µÍøÐ¹ÃÜÍøÕ¾Éϰ䲼Ìû×Ó £¬Ðû³Æ´ÓLandmark PropertiesÇÔÈ¡ÁË1.2TBÊý¾Ý £¬Ô̺¬²ÆÕþÎļþ¡¢¿Í»§¾ßÌåÐÅÏ¢¡¢»úÃܺÍ̸ºÍ»îÔ¾ÂòÂôµÈ¡£°µÍøÉϵÄÊý¾ÝÑù±¾ÏÔʾ £¬²¿ÃÅ»¤ÕÕ¸´Ó¡¼þÒѹýÆÚ £¬¶øÆäËû²ÆÕþÎļþÔò±»ÏóÕ÷Ϊ¡°»úÃÜ¡±¡£Ò»µ©È·ÈϹ¥»÷ £¬½«Î£¼°Êý¾Ýй¶µÄÓ×ÎÒºÍʵÌå £¬¿ÉÄܵ¼ÖÂÉí·Ý͵ÇÔ¡¢½ðÈÚڲƭµÈ·çÏÕ¡£×êÑÐÈËÔ±Ö¸³ö £¬¿Í»§Êý¾Ý¡¢²ÆÕþÎļþºÍÄÚ²¿ÔËÓªµÄй¶¿ÉÄÜÒý·¢Ë¾·¨Ë÷Åâ¡¢Éó²éºÍÃûÓþÇÖº¦¡£»úÃܺÍ̸¡¢ÈËÁ¦×ÊÔ´¼Í¼ºÍ»îÔ¾ÂòÂôÊý¾ÝµÄй¶²»½öΣ¼°Ó×ÎÒ°²È« £¬»¹»áÇÖº¦¿Í»§ÐÅÀµ¡¢¾ºÕùÓÅÊÆºÍóÒ×½»Éæ¡£Landmark Properties×÷ΪÃÀ¹ú×î´óµÄѧÉú¹«Ô¢¿ª·¢ÉÌÖ®Ò» £¬ÖÎÀí×ų¬¹ý115¸öסլÉçÇø £¬×ʲú¼ÛÖµ³¬150ÒÚÃÀÔª £¬Õâ´Î¹¥»÷¶ÔÆäÓ°Ïì²»ÈÝÓ×êĻºóºÚÊÖMorpheusÊÇÒ»¸öÏà¶Ô½ÏеÄ×éÖ¯ £¬ÓÚ2024Äêµ×³öÏÖ £¬²¢ÓëÁíÒ»¸öÍøÂç·¸×OÍÅHellCatÓÐÁªÏµ¡£


https://cybernews.com/security/landmark-properties-ransomware-attack-suspected/


2. CCBCÔâºÚ¿ÍÈëÇÖ £¬½ü4.6ÍòÈËÃô¸Ð½¡È«ÐÅϢй¶


5ÔÂ20ÈÕ £¬È¥Äê £¬²¼Àï˹ÍжûÏØÉçÇøÕ÷ѯÖÐÐÄ£¨CCBC£©Ôâ·êºÚ¿ÍÈëÇÖ £¬µ¼Ö´óÁ¿Ãô¸Ð½¡È«ÐÅÏ¢±»µÁ¡£CCBCÊÇλÓÚÂíÈøÖîÈûÖݵÄÒ»¼ÒÐÐΪ½¡È«ÖÐÐÄ £¬ÖØÒªÌṩÉúÀí½¡È«ºÍÎïÖÊʹÓÃ×è°­µÄÒ½ÖΡ¢Ô¤·À¼°¿µ¸´·þÎñ £¬´¦ÖõÄÐÅÏ¢Éæ¼°¶à¶àÐÄÁ齡ȫºÍÒ©ÎïÀÄÓû¼Õß £¬ÕâЩÐÅÏ¢¼«ÎªË½ÃÜ¡£Æ¾¾ÝÎ¥¹æÍ¨ÖªÐÅ £¬¹¥»÷ÕßÔÚ2024Äê5ÔÂÏÂÑ®ÈëÇÖÁ˸ÃÕïËù £¬²¢ÔÚϵͳÖÐÓε´Á½Ìì £¬ÆÚ¼ä½Ó¼ûÁË´æ´¢ÓÐÊܱ£»¤½¡È«ÐÅÏ¢ºÍÓ×ÎÒÉí·ÝÐÅÏ¢µÄÎļþ¡£ÁîÈ˲»°²µÄÊÇ £¬ÊÜÓ°ÏìÓ×ÎÒÔÚ¹¥»÷²úÉúÒ»Äêºó²ÅÊÕµ½Êý¾Ýй¶֪ͨ £¬Õâ¸øÁ˹¥»÷Õß³ä×㹦·òÀûÓÃÕâЩÐÅÏ¢¡£Õâ´Î¹¥»÷Ó°ÏìÁ˽ü4.6ÍòÈË £¬Éæ¼°Ó×ÎÒÉí·ÝÐÅÏ¢£¨PII£©ºÍ½¡È«ÐÅÏ¢µÄй¶ £¬¸ø»¼Õß´øÀ´ÁËÑϳÁµÄÒþÖÔ·çÏÕ¡£ÀíÂÛÉÏ £¬ÍþвÐÐΪÕß¿ÉÄÜÀûÓÃÕâЩÐÅÏ¢½øÐÐÉí·Ý͵ÇÔ¡¢±£ÏÕڲƭ¼°ÓÐÕë¶ÔÐÔµÄÍøÂç´¹µö¹¥»÷¡£ÎªÓ¦¶ÔÕâ´ÎÊý¾Ýй¶ÊÂÎñ £¬CBCC°ä·¢½«ÎªÊÜÓ°ÏìµÄÓ×ÎÒÌṩÃâ·ÑµÄÉí·Ý±£»¤ºÍÐÅÓþ¼à¿Ø·þÎñ £¬²¢½¨ÒéËûÃÇÉó²éºÍ¼à¿Ø²ÆÕþÕË»§±¨±í¼°ÐÅÓþ»ã±¨ £¬ÒÔ·À±¸Ç±ÔÚ·çÏÕ¡£


https://cybernews.com/privacy/mental-health-clinic-data-breach-massachusetts/


3. ÊʿڿÉÀÖ¼°CCEPÔâÁ½Íþв×éÖ¯ÍøÂç¹¥»÷Ë÷Åâ


5ÔÂ22ÈÕ £¬ÊʿڿÉÀÖ¼°Æä×°Æ¿ºÏ×÷ͬ°éÊʿڿÉÀÖÅ·ÖÞÉýƽÑóºÏ×÷ͬ°é£¨CCEP£©ÕýÃæ¶ÔÍøÂç¹¥»÷Ë÷Åâ £¬¹¥»÷±ðÀëÀ´×ÔEverestÀÕË÷Èí¼þÍÅ»ïºÍGehenna£¨±ðÃûGHNA£©×éÖ¯¡£EverestÀÕË÷Èí¼þ×éÖ¯ÔÚ°µÍøÐ¹ÃÜÍøÕ¾½«ÊʿڿÉÀÖÁÐΪÊܺ¦Õß £¬·ÖÏíµÄ½ØÍ¼ÏÔʾÆä¿É½Ó¼û959ÃûÔ±¹¤µÄÄÚ²¿ÎļþºÍÓ×ÎÒÐÅÏ¢ £¬º­¸Çǩ֤¡¢»¤ÕÕɨÃè¼þ¡¢Ð½×ÊÊý¾ÝµÈÈËÁ¦×ÊÔ´Óйؼͼ¡£Õâ´ÎÈëÇÖÒÉËÆ¶ÔÊʿڿÉÀÖÖж«ÒµÎñÔì³ÉÓ°Ïì £¬µÏ°Ý»ú³¡×ÔÓÉÇøµÏ°Ý´¦Ê´¦¿ÉÄÜÊÇÌØ¶¨¹¥»÷Ö¸±ê¡£Ð¹Â¶ÎļþÉæ¼°Ó×ÎÒÉí·ÝÐÅÏ¢£¨PII£© £¬ColorTokensÊ×ϯÐÅÏ¢°²È«¹ÙÕ÷ѯ¸±×ܲðµÊ¾ £¬Èô¹¥»÷Êôʵ £¬Òâζ×ÅÊʿڿÉÀÖÔÚÍøÂ簲ȫ·½ÃæµÄͶ×Ê¿ÉÄÜ´æÔÚ²»¼°¡£GehennaºÚ¿Í×éÖ¯ÔòÐû³Æ±¾Ô³õÈëÇÖÁËCCEPµÄSalesforceÒDZí°å £¬ÇÔÈ¡Á˳¬2300ÍòÌõ¿É×·ÒäÖÁ2016ÄêµÄ¼Í¼ £¬Ô̺¬Ãô¸ÐµÄ¿Í»§¹ØÏµÖÎÀí£¨CRM£©Êý¾Ý £¬ÈçSalesforceÕÊ»§¼Í¼¡¢¿Í»§·þÎñ°¸Àý¡¢ÁªÏµÈËÌõ¿îºÍ²úÆ·¼Í¼µÈ¡£¸Ã×éÖ¯ÔÚ¹«¹²Êý¾Ýй¶ÂÛ̳·ÖÏíÁËÑù±¾ £¬»¹ÏòCCEPÔ±¹¤°ä²¼ÐÂÎÅ £¬³Æ¡°Ô¸Òâ½ÓÊÜÈκα¨¼Û¡± £¬²¢ÖҸ滹Óиü¶à¡°±¨¼Û¡±¡£½ØÖÁĿǰ £¬ÊʿڿÉÀÖºÍCCEPÉÐδ¹«¿ªÈ·ÈÏÊÇ·ñ´æÔÚÎ¥¹æÐÐΪ¡£


https://hackread.com/coca-cola-bottling-partner-ransomware-data-breach/


4. DanaBot¶ñÒâÈí¼þÐж¯ÔÚÈ«Çò½ø¹¥Ðж¯Öб»²é»ñ


5ÔÂ22ÈÕ £¬ÃÀ¹ú˾·¨²¿ÖÜËİ䷢ £¬ÓÉÈ«Çò¸öÈ˱绤È˺ͷ¨ÂÉ»ú¹¹×é³ÉµÄ½áºÏ¶ÓÁÐÔÚ½ø¹¥ÍøÂç·¸×ï×´¶¯ÖлñµÃнøÕ¹ £¬Ð­Í¬²é·â²¢²ð³ýÁËDanaBotµÄºÅÁîºÍ½ÚÔì·þÎñÆ÷ £¬·ÛËéÁ˸öñÒâÈí¼þ¼´·þÎñµÄÔËÓª¡£Áª¹ú¹ÙÔ±°ä²¼¸æ×´ÊéºÍÐÌÊÂÉêÊö £¬Ö¸¿Ø16ÈËÉæÏӲμÓDanaBotµÄ¿ª·¢ºÍ²¿Ê𡣸öñÒâÈí¼þ×î³õÎªÒøÐÐľÂí £¬ºóÑݱäΪÐÅÏ¢ÇÔÈ¡·¨Ê½ºÍ¶ñÒâÈí¼þ¼ÓÔØ·¨Ê½ £¬Æä½ÚÔìµÄ¶íÂÞË¹ÍøÂç·¸×ï×é֯ϰȾÁËÈ«Çò30¶àÍòÌ¨ÍÆËã»ú £¬Ôì³ÉÖÁÉÙ5000ÍòÃÀÔªËðʧ¡£Õâ´ÎÐж¯ÊÇ¡°ÖÕ¾ÖÐж¯¡±µÄÒ»²¿ÃÅ £¬¸ÃÐж¯Ö¼ÔÚÍß½âºÍ¸æ×´ÍøÂç·¸×ï×éÖ¯¡£µ±¾ÖÒѰ䲼16ÃûÉæÏÓÔËÓªDanaBotµÄ±»¸æÖеÄÁ½Ãû £¬¶þÈ˾ù¾ÓסÔÚ¶íÂÞ˹ÐÂÎ÷²®ÀûÑÇ £¬Ä¿Ç°ÉÐδ±»¿ÛÁô¡£×¨¼Ò³ÆDanaBotÖ°ÄܶàÑù £¬¿É½Ù³ÖÒøÐлỰ¡¢ÇÔÈ¡Êý¾Ý £¬»¹ÓÃÓÚÔ¶³Ì½Ó¼ûÊܺ¦ÍÆËã»ú¡£ÆäµÚ¶þ¸ö°æ±¾Õë¶Ô¾üÊ¡¢µ±¾ÖºÍ±í½»Ðж¯ÖеÄÍÆËã»ú £¬Ö¸±êΪ±±ÃÀºÍÅ·ÖÞÓйØÈËÔ±¡£Íþв×êÑÐÈËÔ±Ö¸³ö £¬DanaBotµÄ¼äµý»î¶¯ÓëÍøÂç·¸×ï½áºÏ £¬Ê¹ÆäÓбðÓÚµäÐ;­¼ÃÖ÷ÕÅÐж¯ £¬»ò´ú±í¶íÂÞ˹µ±¾ÖÀûÒæÐÐÊ¡£


https://cyberscoop.com/danabot-malware-botnet-seizure-takedown/


5. ÃÀ¸æ×´¶í¹«ÃñGallyamov£ºÆäÁìÏÎQakbotÍøÂçÖ¾޶îËðʧ


5ÔÂ22ÈÕ £¬ÃÀ¹úµ±¾ÖÒѶԶíÂÞ˹¹«ÃñRustam Rafailevich GallyamovÌá¸æ×´ËÏ £¬ËûÉæÏÓ¸¨µ¼Qakbot½©Ê¬ÍøÂç¶ñÒâÈí¼þÐж¯¡£¸ÃÐж¯×Ô2008ÄêÆðÓÉGallyamov¿ª·¢ £¬²¢Öð²½ÑÝÔì³ÉÒ»¸öÓÉÊýǧ̨ÊÜÏ°È¾ÍÆËã»ú×é³ÉµÄÍøÂç¡£ÔÚGallyamovµÄ¸¨µ¼Ï £¬²»½öQakbot²»ÐÝ·¢Õ¹ £¬»¹´ßÉúÁËÆäËû¶ñÒâÈí¼þ¡£½üÊ®ÄêÀ´ £¬Qakbot±»ÓÃ×÷ÓµÓжàÖÖÖ°ÄܵÄÒøÐÐľÂí £¬Ô̺¬¼Í¼»÷¼üµÈ¡£×Ô2019ÄêÆð £¬Ëü¸üÊdzÉΪ¶à¸ö³ôÃûÔ¶ÑïµÄÀÕË÷Èí¼þÍÅ»ïÌáÒé¹¥»÷µÄ³õʼϰȾý½é¡£GallyamovÒòÌṩ³õʼ½Ó¼ûȨÏÞ¶ø»ñµÃ²¿ÃÅÊê½ð £¬½ð¶îÒòÓë¸÷ÀÕË÷Èí¼þ×éÖ¯µÄºÍ̸¶øÒì¡£QakbotϰȾµ¼ÖÂÈ«ÇòÊý°ÙÃûÀÕË÷Èí¼þÊܺ¦ÕßËðʧ²Ò³Á £¬½ö18¸öÔÂÄÚ¾­¼ÃËðʧ¾Í³¬¹ý5800ÍòÃÀÔª¡£2023Äê £¬ÃÀ¹úÁª¹úµ÷²é¾Öµ·»ÙÁËQakbot½©Ê¬ÍøÂçµÄ²¿ÃÅ»ù´¡ÉèÊ© £¬µ«GallyamovÈÔ³ÖÐø½øÐжñÒâ²Ù×÷ £¬ÉõÖÁ²ß¶¯ÁËÕë¶ÔÃÀ¹úÊܺ¦ÕßµÄÀ¬»øÓʼþÕ¨µ¯¹¥»÷¡£Ë¾·¨²¿¶Ô»»²éÆÚ¼ä´Ó¼ÓÀûÑÇĪ·òÊÖÖнɻñµÄ¼ÛÖµ³¬¹ý2400ÍòÃÀÔªµÄ¼ÓÃÜÇ®±ÒÌáÆðÁ˳乫ËßËÏ¡£´Ë±í £¬ÉϸöÔÂÁª¹úµ÷²é¾Ö»¹²é»ñÁ˸ü¶à·¸·¨×ʲú¡£


https://www.bleepingcomputer.com/news/security/us-indicts-leader-of-qakbot-botnet-linked-to-ransomware-attacks/


6. iOS¡°Ë¯ÃßÖ®Âá±ÀûÓÃÒòÅäÖÃÃýÎóй¶ÊýÍòÓû§Ó×ÎÒÐÅÏ¢


5ÔÂ22ÈÕ £¬Ò»¿îÖ¼ÔÚÔ®ÊÖÓû§Æ¥µÐʧÃßµÄiOSÀûÓá°Ë¯ÃßÖ®ÂãºÊ§Ã߸±ÊÖ¡±±»ÆØ³ö´æÔÚÑϳÁÊý¾Ýй¶ÎÊÌâ¡£¸ÃÀûÓÃÓÉÈûÆÖ·˹¹«Ë¾Fitsia Holdings LimitedÏúÊÛ £¬ÒòÃýÎóÅäÖÃFirebase·þÎñÆ÷ £¬µ¼Ö³¬¹ý2.5ÍòÃûÓû§µÄÓ×ÎÒÐÅϢй¶¡£Ð¹Â¶Êý¾Ýº­¸ÇÓû§ÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢µ®ÉúÈÕÆÚ¡¢ÐÔ±ð¡¢Ë¯ÃßÊý¾Ý¡¢Òû¾Æ¼°ÎüʳÄá¹Å¶¡Ï°¹ß¡¢Ë¯Ç°»î¶¯ÒÔ¼°Ò©ÎïʹÓõÈÃô¸ÐÐÅÏ¢¡£ÓÉÓÚFirebase½öΪһʱÊý¾Ý¿â £¬ÏÖʵй¶Êý¾ÝÁ¿¿ÉÄÜÔ¶³¬´ËÊý¡£ÕâЩй¶µÄÓ×ÎÒÊý¾ÝºÍ½¡È«ÐÅÏ¢¶ÔÍøÂç·¸×ï·Ö×Ó¼«¾ßÎüÒýÁ¦ £¬ËûÃÇ¿ÉÄÜÀûÓÃÕâЩÐÅÏ¢ÌáÒéÍøÂç´¹µö¡¢À¬»øÓʼþ¡¢Éç»á¹¤³Ì¹¥»÷ £¬ÉõÖÁ½øÐÐÆ¾Ö¤Ìî³ä¹¥»÷¡£´Ë±í £¬¸ÃÀûÓÿͻ§¶ËµÄÖî¶à»úÃÜÒ²±»Ð¹Â¶ £¬Ô̺¬APIÃÜÔ¿¡¢¿Í»§¶ËID¡¢Êý¾Ý¿âURL¡¢GoogleÀûÓÃID¡¢ÏîÄ¿ID¡¢·´Ïò¿Í»§¶ËID¼°´æ´¢Í°Æ¾Ö¤µÈ £¬Õâ¿ÉÄÜʹ¹¥»÷Õß»ñÈ¡Óû§É豸¸ß¼¶½Ó¼ûȨÏÞ £¬ÈƹýÉí·ÝÑé֤ϵͳ £¬½Ó¼ûÃô¸Ð¿Í»§Êý¾Ý £¬²¢°Ñ³Ö·þÎñ¡£Õâ´ÎÊÂÎñ͹ÏÔÁËÒÆ¶¯ÀûÓð²È«µÄ³ÁÒªÐÔ¡£


https://cybernews.com/security/ios-sleep-journey-app-data-leak/