ÃÀ¹úPJ&A³ÆÍøÂç¹¥»÷µ¼ÖÂÆä½ü900Íò»¼ÕßµÄÐÅϢй¶
Ðû²¼Ê±¼ä 2023-11-17¾Ý11ÔÂ15ÈÕ±¨µÀ£¬PJ&A(Perry Johnson & Associates)͸¶£¬½ñÄê3ÔµÄÒ»´ÎÍøÂç¹¥»÷й¶Á˽ü900Íò»¼ÕßµÄÐÅÏ¢¡£PJ&AΪÃÀ¹úµÄÒ½ÁÆ»ú¹¹ÌṩҽÁÆת¼·þÎñ£¬¸Ã¹«Ë¾ÌåÏÖ¹¥»÷ÕßÈëÇÖÁËËûÃǵÄϵͳ£¬²¢ÔÚ3ÔÂ27ÈÕÖÁ5ÔÂ2ÈÕʱ´ú¾ÙÐÐÁË»á¼û¡£Ð¹Â¶Êý¾Ý°üÀ¨ÐÕÃû¡¢²¡ÀúºÅ¡¢Éç»áÇå¾²ºÅÂë(SSN)¡¢°ü¹ÜÐÅÏ¢ºÍÒ½ÁÆת¼ÎļþµÈ£¬Ó°ÏìÁË8952212Ãû»¼Õß¡£14ÈÕ£¬Å¦Ô¼×î´óµÄÒ½ÁÆÌṩÉÌNorthwell Health³Æ£¬ PJ&AÔâµ½¹¥»÷µ¼ÖÂÆäÊý¾ÝÔÚ4ÔÂ7ÈÕÖÁ19ÈÕ±»µÁ£¬Éæ¼°Áè¼Ý380ÍòÈË¡£
https://www.bleepingcomputer.com/news/security/pj-and-a-says-cyberattack-exposed-data-of-nearly-9-million-patients/
2¡¢Ô½ÄÏÓÊÕþ¹«Ë¾ÉèÖùýʧµ¼ÖÂÔ¼1.2TBÊý¾Ýй¶
ýÌå11ÔÂ16Èճƣ¬Ñо¿ÍŶӷ¢Ã÷ÁËÒ»¸öÊôÓÚÔ½ÄÏÓÊÕþ¹«Ë¾µÄ¿ª·ÅKibanaʵÀý¡£KibanaÊÇÒ»¸öÓÃÓÚÊý¾ÝËÑË÷ºÍÆÊÎöµÄ¿ÉÊÓ»¯¿ØÖÆÃæ°å£¬×ÊÖúÆóÒµ´¦Öóͷ£´ó×ÚÊý¾Ý¡£ÔÚ·¢Ã÷ʱ£¬Êý¾Ý´æ´¢°üÀ¨2.26ÒÚ¸ö¼Í¼ÊÂÎñ£¬¹²±¬·¢ÁË1.2TBÊý¾Ý£¬²¢ÇÒÕýÔÚʵʱ¸üС£Ð¹Â¶ÐÅÏ¢°üÀ¨Çå¾²ÈÕÖ¾£¬ÒÔ¼°Ô±¹¤µÄÐÕÃûºÍµç×ÓÓʼþ¡£ÏÖÔÚ£¬¸Ã¹«Ë¾Òѽ«ÕâЩÊý¾Ý±£»¤ÆðÀ´¡£
https://securityaffairs.com/154271/data-breach/vietnam-post-data-leak.html
3¡¢ºÚ¿ÍÉù³ÆÒÑÈëÇÖPlume¹«Ë¾²¢ÍøÂçÁè¼Ý1500ÍòÐÐÊý¾Ý
¾ÝýÌå11ÔÂ15ÈÕ±¨µÀ£¬¹¥»÷ÕßÉù³ÆÇÔÈ¡ÁËÖÇÄÜWiFiÌṩÉÌPlumeÁè¼Ý20GBµÄÊý¾Ý¿â£¬ÆäÖаüÀ¨Áè¼Ý1500ÍòÐÐÊý¾Ý¡£PlumeÉÐδ֤ʵÕâÒ»ÐÂÎÅ£¬ÌåÏÖÒÑÏàʶ¹¥»÷ÕßµÄ˵·¨£¬²¢Õö¿ªÊÓ²ìÒÔºËʵÕâЩ˵·¨¡£ÓÉÓÚ¶ÔPlumeµÄ»ØÓ¦²»Âú£¬ºÚ¿ÍÐû²¼ÁËÁ½¸öCSVÎļþ£¬°üÀ¨´ó×Ú¿Í»§ºÍÔ±¹¤µÄÐÅÏ¢¡£±ðµÄ£¬ºÚ¿Í»¹Í¸Â¶´Ë´Îй¶ÊÂÎñÊÇÓÉPlumeµÄÒ»ÃûÇ°Ô±¹¤´Ù³ÉµÄ£¬ËûÓÚ2023ÄêÍÑÀ빫˾£¬µ«ÈÔȻӵÓлá¼ûȨÏÞ¡£¹¥»÷Õ߸øÁ˸ù«Ë¾48СʱÀ´Öª×ãËûÃǵÄÒªÇ󣬲»È»½«Ð¹Â¶¸ü´ó¶¼¾Ý¡£
https://www.hackread.com/hackers-smart-wi-fi-provider-plume-data-breach/
4¡¢FBIµÈ»ú¹¹ÍŽáÅû¶ÀÕË÷ÍÅ»ïRhysidaµÄTTPµÈÐÅÏ¢
11ÔÂ15ÈÕ£¬CISA¡¢FBIºÍMS-ISACÐû²¼Á˹ØÓÚÀÕË÷ÍÅ»ïRhysidaµÄÍŽáÍøÂçÇå¾²×Éѯ(CSA)¡£¸Ã×ÉѯÌṩÁË×èÖ¹9ÔµÄÊÓ²ìʱ´ú·¢Ã÷µÄIoC¡¢¼ì²âÐÅÏ¢ÒÔ¼°RhysidaµÄÕ½Êõ¡¢ÊÖÒպͳÌÐò(TTP)¡£Rhysida×Ô½ñÄê5ÔÂÒÔÀ´Ò»Ö±»îÔ¾£¬ÒÑÓÐÖÁÉÙÓÐ62¼Ò¹«Ë¾Ôâµ½Æä¹¥»÷¡£RhysidaÒÔRaaSµÄģʽ¹¥»÷½ÌÓý¡¢ÖÆÔì¡¢ÐÅÏ¢ÊÖÒÕÐÐÒµºÍÕþ¸®»ú¹¹¡£±ðµÄ£¬Rhysida»¹Ê¹ÓÃÁËÔ¶³Ì·þÎñ£¨ÈçVPNºÍRDP£©À´»ñµÃ¶Ô³õʼ»á¼û²¢¼á³Ö³¤ÆÚÐÔ£¬²¢Ê¹ÓÃÁË´¹ÂÚ¹¥»÷ºÍZerologonÎó²î£¨CVE-2020-1472£©¡£
https://www.cisa.gov/news-events/alerts/2023/11/15/cisa-fbi-and-ms-isac-release-advisory-rhysida-ransomware
5¡¢McAfee·¢Ã÷Õë¶Ôº«¹úÈö²¥¶ñÒâÇÔÈ¡³ÌÐòµÄ´¹ÂÚÔ˶¯
11ÔÂ15ÈÕ£¬McAfee³ÆÆä·¢Ã÷ÁËͨ¹ý´¹ÂÚÍøÕ¾Èö²¥¶ñÒâAndroidºÍiOSÐÅÏ¢ÇÔÈ¡³ÌÐòµÄÔ˶¯¡£¸ÃÔ˶¯ÓÚ10Ô³õ×îÏÈ»îÔ¾£¬ÒÑѬȾ200¶ą̀װ±¸£¬ËùÓÐ×°±¸¶¼Î»ÓÚº«¹ú¡£¹¥»÷Õß×î³õͨ¹ý¶ÌÐÅ¿¿½üÄ¿µÄ£¬²¢»áʵÑéתÒƵ½LINE Messenger¡£È»ºó·¢ËÍÖ¸Ïò´¹ÂÚÍøÕ¾µÄÁ´½Ó£¬¸ÃÍøվαװ³ÉCamtalk£¬ÓÕʹĿµÄÏÂÔضñÒâAndroidºÍiOSÓ¦ÓᣳýÁËð³äÉç½»Ó¦Ó㬸ÃÔ˶¯»¹ÔÚÆä´¹ÂÚÍøÕ¾ÖÐʹÓÃÁËÆäËüÖ÷Ìâ¡£´Ë´ÎÔ˶¯Ö÷ÒªÕë¶Ôº«¹ú£¬ÏÖÒÑ·¢Ã÷10¸ö´¹ÂÚÍøÕ¾£¬¶ñÒâÈí¼þ»áÇÔÈ¡Ä¿µÄµÄµç»°ºÅÂë¡¢¹ØÁªÁªÏµÈ˺ͶÌÐŵȡ£
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/fake-android-and-ios-apps-steal-sms-and-contacts-in-south-korea/
6¡¢MalwarebytesÐû²¼10Ô·ÝÀÕË÷Èí¼þ̬ÊƵÄÆÊÎö±¨¸æ
MalwarebytesÔÚ11ÔÂ15ÈÕÐû²¼ÁË10Ô·ÝÀÕË÷Èí¼þ̬ÊƵÄÆÊÎö±¨¸æ¡£10Ô·ݣ¬ÀÕË÷ÍÅ»ïµÄÍøÕ¾ÉÏÁгöÁË318¸öеı»¹¥»÷Ä¿µÄ¡£×î»îÔ¾µÄÊÇLockBit(64¸ö)¡¢NoEscape(40¸ö)ºÍPLAY(36¸ö)¡£ÓÐ3¸öÖ÷ÒªµÄÀÕË÷ÍŻﱻ¹Ø±Õ£¬»®·ÖÊÇRansomedVC¡¢RagnarºÍTrigona¡£ÕâÒ»¸öÔ·ºÆðÁËÒ»¸öеÄÀÕË÷ÍÅ»ïHunters International£¬ÒÉËÆÊÇHiveµÄ¸üÃû¡£Ôâµ½ÀÕË÷¹¥»÷×î¶àµÄ¹ú¼ÒÊÇÃÀ¹ú£¨148Æ𣩣¬Æä´ÎÊÇÓ¢¹ú£¨34£©ºÍÒâ´óÀû£¨19£©¡£
https://www.malwarebytes.com/blog/threat-intelligence/2023/11/ransomware-review-november-2023