EmbyÔ¶³Ì¹Ø±Õ²¿·ÖÔâµ½¹¥»÷µÄÓû§Ã½Ìå·þÎñÆ÷ʵÀý
Ðû²¼Ê±¼ä 2023-05-291¡¢EmbyÔ¶³Ì¹Ø±Õ²¿·ÖÔâµ½¹¥»÷µÄÓû§Ã½Ìå·þÎñÆ÷ʵÀý
¾ÝýÌå5ÔÂ26ÈÕ±¨µÀ£¬EmbyÔ¶³Ì¹Ø±ÕÁ˲¿·ÖÔâµ½¹¥»÷µÄÓû§ÍйÜýÌå·þÎñÆ÷ʵÀý¡£¹¥»÷Ô˶¯Ê¼ÓÚ5ÔÂÖÐÑ®£¬Æäʱ¹¥»÷ÕßÕë¶Ô̻¶µÄ˽ÈËEmby·þÎñÆ÷£¬²¢ÈëÇÖÄÇЩÉèÖÃΪÔÊÐíÖÎÀíÔ±ÔÚÍâµØÍøÂçÉÏÎÞÃÜÂëµÇ¼µÄ·þÎñÆ÷¡£ÎªÁË»ñµÃ»á¼ûȨÏÞ£¬¹¥»÷Õß»¹Ê¹ÓÃÁËÒ»¸öÊðÀí±êÍ·Îó²î£¬¸ÃÎó²î×î½üÔÚ²âÊÔ°æƵµÀÖб»ÐÞ¸´¡£¹¥»÷Õß×°ÖÃÁËÒ»¸ö¶ñÒâ²å¼þÀ´Ê¹Óûá¼ûȨÏÞ£¬ÔÚ±»Ñ¬È¾µÄEmbyʵÀý°²ÅźóÃÅ£¬¸Ã²å¼þ¿ÉÍøÂçÓû§Æ¾Ö¤¡£Embyδ͸¶±»¹¥»÷·þÎñÆÚÊýÄ¿£¬µ«ÍýÏ뾡¿ìÐû²¼Emby Server 4.7.12Çå¾²¸üÐÂÀ´½â¾ö¸ÃÎÊÌâ¡£
https://www.bleepingcomputer.com/news/security/emby-shuts-down-user-media-servers-hacked-in-recent-attack/
2¡¢OneMainÒòÍøÂçÇå¾²ÎÊÌⱻŦԼDFS·£¿î425ÍòÃÀÔª
¾Ý5ÔÂ26ÈÕ±¨µÀ£¬OneMain Financial Group±»Å¦Ô¼½ðÈÚ·þÎñ²¿(DFS)·£¿î425ÍòÃÀÔª¡£DFSÔÚÒ»·ÝÉùÃ÷ÖÐÌåÏÖ£¬OneMainδÄÜÓÐÓõØÖÎÀíµÚÈý·½·þÎñÌṩÉ̵ÄΣº¦¡¢ÖÎÆÊÎö¼ûȨÏÞÒÔ¼°Ê¹ÓÃÕýʽµÄÓ¦ÓÃÇå¾²¿ª·¢ÒªÁ죬Õâ´ó´óÔöÌíÁ˸ù«Ë¾ÃæÁÙÍøÂçÇå¾²ÊÂÎñµÄųÈõÐÔ¡£ÀýÈ磬OneMainʹÓÃÁËÆäÄÚ²¿¿ª·¢µÄ·ÇÕý¹æÏîÄ¿ÖÎÀí¿ò¼ÜµÈ¡£¸Ã¹«Ë¾ÌåÏÖ£¬ËüÔç¾Í½â¾öÁËÊÓ²ìÖз¢Ã÷µÄÎÊÌ⣬´Ë´ÎÊÓ²ìËùÉó²éµÄÊÇÆä2017ÄêÖÁ2020ÄêÍ·µÄÕþ²ß¡£
https://therecord.media/one-main-fined-ny-for-cybersecurity-lapses
3¡¢Ñо¿ÍŶӳÆMagalenhaÐж¯¹¥»÷30¶à¼ÒÆÏÌÑÑÀ½ðÈÚ»ú¹¹
5ÔÂ25ÈÕ£¬SentinelLabs³ÆÆäÊӲ쵽ÃûΪMagalenhaÐж¯µÄ¹¥»÷Ô˶¯£¬×Ô2021ÄêÒÔÀ´Ò»Ö±Õë¶Ô30¶à¼ÒÆÏÌÑÑÀ½ðÈÚ»ú¹¹ÇÔÊØÐÅÏ¢¡£¸ÃÔ˶¯¿ÉÄÜÓë°ÍÎ÷µÄ¹¥»÷ÍÅ»ïÓйأ¬Ê¼ÓÚ»ìÏýµÄVB¾ç±¾£¬¿É»ñÈ¡²¢Ö´ÐжñÒâÈí¼þ¼ÓÔسÌÐò£¬²¢ÔÚÎåÃëÖÓµÄÑӳٺ󣬽«ºóÃÅPeepingTitleµÄÁ½¸ö±äÌå¼ÓÔص½Ä¿µÄϵͳÖС£PeepingTitleÊÇÒ»¸öDelphi¿ª·¢µÄ¶ñÒâÈí¼þ£¬±àÒëÈÕÆÚΪ4Ô·ݡ£¹¥»÷Õß·Ö·¢Á½¸ö±äÌåµÄÔµ¹ÊÔÓÉÊÇ£¬Ò»¸öÓÃÓÚ²¶»ñÆÁÄ»£¬ÁíÒ»¸öÓÃÓÚ¼àÊÓ´°¿ÚÒÔ¼°Óû§ÓëÕâЩ±äÌåµÄ½»»¥¡£
https://www.sentinelone.com/labs/operation-magalenha-long-running-campaign-pursues-portuguese-credentials-and-pii/
4¡¢BlackByteÉù³Æ¶ÔÃÀ¹ú°Â¹Å˹ËþÊÐÔâµ½µÄ¹¥»÷ÈÏÕæ
5ÔÂ26ÈÕ±¨µÀ£¬ÀÕË÷ÍÅ»ïBlackByteÉù³Æ¶ÔÃÀ¹ú×ôÖÎÑÇÖݰ¹Å˹ËþÊÐÔâµ½µÄ¹¥»÷ÈÏÕæ¡£¸ÃÊÐÔÚÆäÍøÕ¾ÉÏÚ¹ÊÍ˵£¬Ëü´Ó5ÔÂ21ÈÕ×îÏÈÓöµ½ÊÖÒÕÄÑÌ⣬µ¼Ö²¿·ÖϵͳÖÐÖ¹¡£»¹³ÎÇåµ½£¬ÕâÆðÊÂÎñÓë֮ǰ±¬·¢µÄITϵͳÖÐÖ¹Î޹ء£BlackByteÔÚÆäÍøÕ¾Éϳƣ¬ÒѴӰ¹Å˹ËþµÄÅÌËã»úÉÏÇÔÈ¡ÁË´ó×ÚÊý¾Ý£¬²¢¹ûÕæÁË8.1 GBµÄÑù±¾Êý¾Ý×÷Ϊ֤¾Ý¡£¸ÃÍÅ»ïÀÕË÷40ÍòÃÀÔªÀ´É¾³ýÊý¾Ý£¬²¢Ìá³öÒÔ30ÍòÃÀÔªµÄ¼ÛÇ®½«Êý¾Ý³öÊÛ¸ø¸ÐÐËȤµÄµÚÈý·½¡£
https://securityaffairs.com/146717/hacking/city-of-augusta-cyberattack.html
5¡¢Mandiant·¢Ã÷ʹÓÃICSÐÒé¹¥»÷µçÍøµÄCOSMICENERGY
MandiantÔÚ5ÔÂ26ÈÕ͸¶£¬Æä·¢Ã÷ÁËеĶñÒâÈí¼þCOSMICENERGY£¬Ê¹ÓÃICSÐÒéÀ´ÆÆËðµçÍø¡£ËüÊÇÓɶíÂÞ˹µÄ¹¥»÷ÕßÓÚ2021Äê12ÔÂÉÏ´«µ½VirusTotalµÄ£¬ÏÖÔÚûÓÐÔÚÒ°ÍⱻʹÓá£MandiantÌåÏÖ£¬Õâ¿ÉÄÜÊǶíÂÞ˹µçÐŹ«Ë¾Rostelecom-Solar¿ª·¢µÄÒ»ÖÖºì¶Ó¹¤¾ß£¬ÓÃÓÚÄ£Äâ2021Äê10ÔµĵçÁ¦ÖÐÖ¹ºÍÓ¦¼±ÏìÓ¦ÑÝÏ°¡£COSMICENERGYµÄ¹¦Ð§¿ÉÒÔÓëIndustroyerÏàæÇÃÀ£¬ÓÉÓÚËüÄܹ»Ê¹Óù¤ÒµÍ¨Ñ¶ÐÒéIEC-104ÏòRTU·¢³öÖ¸ÁʹÓÃÕâÖÖ»á¼ûȨÏÞ£¬¹¥»÷Õß¿ÉÒÔ·¢ËÍÔ¶³ÌÏÂÁîÀ´Ó°ÏìµçÁ¦Ïß¿ª¹ØºÍ¶Ï·Æ÷µÄÆô¶¯£¬´Ó¶øµ¼ÖµçÁ¦ÖÐÖ¹¡£
https://www.mandiant.com/resources/blog/cosmicenergy-ot-malware-russian-response
6¡¢Ñо¿Ö°Ô±·¢Ã÷ʹÓÃWin10д×Ö°åDLLЮÖÆÎó²îµÄQBotÔ˶¯
ýÌå5ÔÂ27ÈÕ±¨µÀ£¬Ñо¿Ö°Ô±·¢Ã÷ÐÂÒ»ÂÖQBot¹¥»÷Ô˶¯¡£¸ÃÔ˶¯Ê¹ÓÃÁËWindows 10д×Ö°åÖеÄDLLЮÖÆÎó²îѬȾÅÌËã»ú£¬²¢Ê¹ÓÃÕýµ±³ÌÐòÈƹýÇå¾²Èí¼þµÄ¼ì²â¡£Ä¿µÄµã»÷´¹ÂÚÓʼþÖеÄÁ´½Óʱ£¬»áÏÂÔØÒ»¸öËæ»úÃüÃûµÄZIP´æµµ£¬ÆäÖаüÀ¨Win10д×Ö°å¿ÉÖ´ÐÐÎļþdocument.exeºÍDLLÎļþedputil.dll¡£¼ÓÔضñÒâ°æ±¾µÄedputil.dllºó£¬»á´ÓÔ¶³ÌÖ÷»úÏÂÔØαװ³ÉPNGµÄDLL£¬È»ºóʹÓÃrundll32.exeÖ´ÐдËPNG¡£Õâʱ£¬QBot½«ÔÚºǫ́Çå¾²µØÔËÐС£
https://www.bleepingcomputer.com/news/security/qbot-malware-abuses-windows-wordpad-exe-to-infect-devices/