¶íÂÞ˹°ü¹Ü¹«Ë¾RosgosstrakhÔâ¹¥»÷400GBÊý¾Ý±»³öÊÛ
Ðû²¼Ê±¼ä 2023-11-061¡¢¶íÂÞ˹°ü¹Ü¹«Ë¾RosgosstrakhÔâ¹¥»÷400GBÊý¾Ý±»³öÊÛ
¾ÝýÌå11ÔÂ4ÈÕ±¨µÀ£¬¶íÂÞ˹µÚ¶þ´ó°ü¹Ü¹«Ë¾RosgosstrakhÔâµ½ºÚ¿Í¹¥»÷¡£¾ÝϤ£¬ºÚ¿ÍApathyÔÚ°µÍøÉÏÒÔ5ÍòÃÀÔªµÄ¼ÛÇ®³öÊÛRosgosstrakhµÄÊý¾Ý¿â£¬²¢½ÓÊܱÈÌرÒ(BTC)»òÃÅÂÞ±Ò(XMR)µÄ¸¶¿î·½·¨¡£±»µÁÊý¾Ý°üÀ¨¿É×·Ëݵ½2010ÄêµÄͶ×ʺÍÈËÊÙ°ü¹Ü²¿·ÖµÄËùÓмͼ£¬Éæ¼°Ô¼300Íò·ÝÒøÐжÔÕ˵¥£¬ºÍ73ÍòÈ˵ÄÊý¾Ý¡£Ñо¿Ö°Ô±³Æ£¬Õû¸öÊý¾Ý¿â¶à´ï400 GB£¬Ëû»ñµÃÁË22 GBµÄÃ÷ÎÄÃûÌÃJSONÊý¾Ý£¬ÆÊÎö²¢·¢Ã÷ÁË3ÃûGRUÌع¤µÄÐÅÏ¢¡£
https://www.hackread.com/russia-insurer-rosgosstrakh-hacked-data-sold/
2¡¢ALPHVÉù³ÆÒÑÍøÂçÒ½Áƹ«Ë¾Henry Schein 35TBÊý¾Ý
¾Ý11ÔÂ2ÈÕ±¨µÀ£¬ALPHVÉù³ÆÒÑÈëÇÖÒ½Áƹ«Ë¾Henry Schein£¬²¢ÍøÂçÁË35 TBµÄÊý¾Ý¡£¸Ã¹«Ë¾ÓÚ10ÔÂ15ÈÕÅû¶£¬ÎªÁ˵ÖÓù14ÈÕÓ°ÏìÆäÖÆÔìºÍ·ÖÏúÓªÒµµÄÍøÂç¹¥»÷£¬²¿·Öϵͳ±»Æȹرա£Ô¼ÄªÁ½Öܺó£¬ALPHV½«Henry ScheinÌí¼Óµ½ÆäÍøÕ¾£¬Éù³ÆÒÑÇÔÈ¡35 TBµÄÎļþ£¬°üÀ¨ÈËΪÊý¾ÝºÍ¹É¶«ÐÅÏ¢¡£²¢ÌåÏÖ¾ÍÔڸù«Ë¾ÏÕЩÍê³É»Ö¸´ËùÓÐϵͳµÄÊÂÇéʱ£¬ËûÃÇÔٴζԹ«Ë¾µÄ×°±¸¾ÙÐÐÁ˼ÓÃÜ£¬ÓÉÓÚÕýÔÚ¾ÙÐеÄ̸ÅÐʧ°ÜÁË¡£ÏÖÔÚ£¬ALPHVÔÚÆäÍøÕ¾ÉÑþ³ØýÁËHenry Schein£¬Åú×¢¸Ã¹«Ë¾½«ÖØÐÂ̸Åлò½»Êê½ð¡£
https://www.bleepingcomputer.com/news/security/blackcat-ransomware-claims-breach-of-healthcare-giant-henry-schein/
3¡¢ÊðÀí½©Ê¬ÍøÂçSocks5SystemzÒÑѬȾԼ10000¸öϵͳ
BitSightÔÚ11ÔÂ2ÈÕÅû¶ÁËÊðÀí½©Ê¬ÍøÂçSocks5SystemzµÄÏêϸÐÅÏ¢¡£Socks5Systemz½©Ê¬³ÌÐòÓÉPrivateLoaderºÍAmadey·Ö·¢£¬ÕâЩ¶ñÒâÈí¼þͨ³£Í¨¹ý´¹ÂÚ¹¥»÷¡¢Îó²îʹÓù¤¾ß°ü¡¢¶ñÒâ¹ã¸æ¡¢´ÓP2PÍøÂçÏÂÔصÄľÂí¿ÉÖ´ÐÐÎļþµÈ·½·¨Èö²¥¡£ÊðÀí·þÎñÔÊÐí¿Í»§Ñ¡Ôñ´Ó1ÃÀÔªµ½4000ÃÀÔª²»µÈµÄÌײͣ¬²¢Ê¹ÓüÓÃÜÇ®±ÒÈ«¶îÖ§¸¶¡£¸Ã½©Ê¬ÍøÂçÖÁÉÙ×Ô2016ÄêÒÔÀ´¾ÍÒѱ£´æ£¬Ò£²âÊý¾ÝÏÔʾÒÑѬȾȫÇò¹æÄ£ÄÚÔ¼10000¸öϵͳ¡£
https://www.bleepingcomputer.com/news/security/socks5systemz-proxy-service-infects-10-000-systems-worldwide/
4¡¢ÃÀ¹úµäÖÊ´û¿î¹«Ë¾Mr.Cooper±»¹¥»÷ÔËÓªÊܵ½Ó°Ïì
11ÔÂ3ÈÕ±¨µÀ³Æ£¬ÃÀ¹úµäÖÊ´û¿î¹«Ë¾Mr. CooperÔâµ½¹¥»÷£¬°üÀ¨Ö§¸¶ÔÚÄÚµÄÓªÒµÊܵ½Ó°Ïì¡£¸Ã´û¿î»ú¹¹ÒѳÉΪÃÀ¹ú×î´óµÄ·þÎñ»ú¹¹£¬Îª9370ÒÚÃÀÔªµÄ´û¿îÌṩ·þÎñ¡£¹¥»÷±¬·¢ÔÚ10ÔÂ31ÈÕ£¬Î´¾ÊÚȨµÄµÚÈý·½»á¼ûÁ˲¿·Öϵͳ¡£¼ì²âµ½ÊÂÎñºó£¬¸Ã¹«Ë¾Æô¶¯ÁËÏìÓ¦²½·¥£¬°üÀ¨¹Ø±Õ²¿·Öϵͳ¡£ÏµÍ³å´»úµ¼Ö¿ͻ§ÎÞ·¨Ö§¸¶µäÖÊ´û¿î£¬¿ÉÊÇMr.CooperÔÊÐíÔÚ»Ö¸´ÏµÍ³µÄÀú³ÌÖв»»áÒòÓâÆÚ±¬·¢Óöȡ¢·£¿î»ò¸ºÃæÐÅÓñ¨¸æ¡£¸Ã¹«Ë¾ÈÔÔÚÊÓ²ì¿Í»§Êý¾ÝÊÇ·ñ±»µÁ£¬Ã»ÓÐ͸¶ÕâÊÇ·ñÊÇÀÕË÷¹¥»÷£¬µ«ËüµÄËùÓм£ÏóÅú×¢ÕâÊÇÀÕË÷¹¥»÷¡£
https://www.securityweek.com/mortgage-giant-mr-cooper-shuts-down-systems-following-cyberattack/
5¡¢OktaµÄ¹©Ó¦ÉÌÔâµ½¹¥»÷µ¼ÖÂÆäÊýǧÃûÔ±¹¤µÄÐÅϢй¶
ýÌå11ÔÂ2Èճƣ¬Okta͸¶ÓÉÓÚµÚÈý·½¹©Ó¦ÉÌRightway HealthcareÔâµ½¹¥»÷£¬Æä½üÊýǧÃûÔ±¹¤µÄÐÅϢй¶¡£Õë¶ÔRightwayµÄ¹¥»÷±¬·¢ÓÚ9ÔÂ23ÈÕ£¬¹¥»÷Õß»á¼ûÁËΪÇкÏÌõ¼þµÄÈËÌṩ°ü¹ÜºÍ¸£Àû¶øά»¤µÄ×ʸñÉú³ÝÆÕ²éÎļþ¡£OktaÓÚ10ÔÂ12ÈÕµÃÖªÁË´Ë´Îй¶ÊÂÎñ£¬²¢È·¶¨´Ë´ÎÎ¥¹æÊÂÎñ×ܹ²Ó°ÏìÁË4961ÃûÔ±¹¤£¬À´×Ô2019Äê4ÔÂÖÁ2020ÄêµÄÎļþ¡£¸Ã¹«Ë¾½«ÎªÊÜÓ°ÏìµÄСÎÒ˽¼ÒÌṩÁ½ÄêµÄExperianÐÅÓüà¿Ø¡¢Éí·Ý͵ÇÔ±£»¤ºÍڲƱ£»¤·þÎñ¡£
https://therecord.media/okta-employees-impacted-by-third-party-breach
6¡¢Deep InstinctÅû¶MuddyWaterÕë¶ÔÒÔÉ«ÁеĴ¹ÂÚ¹¥»÷
11ÔÂ2ÈÕ£¬Deep InstinctÐû²¼±¨¸æ³Æ£¬MuddyWaterÕýÔÚÖ´ÐÐÐÂÒ»ÂÖµÄÓã²æʽ´¹ÂÚ¹¥»÷£¬Õë¶ÔÒÔÉ«ÁеĹ«Ë¾¡£10ÔÂ30ÈÕ£¬Ñо¿Ö°Ô±·¢Ã÷ÁË¡°Storyblok¡±ÉÏÍйܵÄÁ½¸öµµ°¸£¬ÆäÖаüÀ¨ÐµĶà½×¶ÎѬȾÔØÌå¡£Ëü°üÀ¨Òþ²ØÎļþ¡¢Æô¶¯Ñ¬È¾µÄLNKÎļþÒÔ¼°Ö¼ÔÚÔÚÖ´ÐÐAdvanced Monitoring Agent£¨Ò»ÖÖÔ¶³ÌÖÎÀí¹¤¾ß£©µÄ¿ÉÖ´ÐÐÎļþ¡£Ñо¿Ö°Ô±³Æ£¬ÕâÊÇÒÁÀÊAPTÍÅ»ïÊ×´ÎʹÓÃN-ableµÄÔ¶³Ì¼à¿ØÈí¼þ¡£
https://www.deepinstinct.com/blog/muddywater-en-able-spear-phishing-with-new-ttps