¼ÒµÃ±¦È·ÈϵÚÈý·½Êý¾Ý鶵¼ÖÂÆäÔ±¹¤ÐÅϢй¶

Ðû²¼Ê±¼ä 2024-04-09
1. ¼ÒµÃ±¦È·ÈϵÚÈý·½Êý¾Ý鶵¼ÖÂÆäÔ±¹¤ÐÅϢй¶


4ÔÂ7ÈÕ£¬Home Depot ÒÑÈ·ÈÏ£¬ÆäÒ»¼Ò SaaS ¹©Ó¦É̹ýʧµØй¶ÁËһС²¿·ÖÓÐÏÞµÄÔ±¹¤Êý¾ÝÑù±¾£¬ÕâЩÊý¾Ý¿ÉÄܻᱻÓÃÓÚÓÐÕë¶ÔÐÔµÄÍøÂç´¹ÂÚ¹¥»÷£¬Òò´Ë¸Ã¹«Ë¾ÔâÊÜÁËÊý¾Ýй¶¡£Home Depot ÊÇ×î´óµÄ¼Ò¾Ó×°ÐÞÁãÊÛÉÌ£¬ÔÚ±±ÃÀÓµÓÐ 2,300 ¶à¼ÒÊÐËÁºÍÁè¼Ý 475,000 ÃûÔ±¹¤¡£Ò»¸öÃûΪ IntelBroker µÄÍþвÐÐΪÕßÔÚºÚ¿ÍÂÛ̳ÉϹûÕæÁËԼĪ 10,000 Ãû¼ÒµÃ±¦Ô±¹¤µÄÊý¾Ý¡£ËäÈ»ÕâЩÊý¾Ý²¢²»¸ß¶ÈÃô¸Ð£¬½ö̻¶¹«Ë¾ ID¡¢ÐÕÃûºÍµç×ÓÓʼþµØµã£¬µ«ÍþвÐÐΪÕß¿ÉÄÜ»áʹÓÃÕâЩÊý¾Ý¶Ô Home Depot Ô±¹¤¾ÙÐÐÓÐÕë¶ÔÐÔµÄÍøÂç´¹ÂÚ¹¥»÷¡£ÕâЩÍøÂç´¹ÂÚ¹¥»÷¿ÉÄÜÖ¼ÔÚÍøÂç¸üÃô¸ÐµÄÐÅÏ¢£¬ÀýÈç¼ÒµÃ±¦Æ¾Ö¤£¬È»ºó½«Æä³öÊÛ¸øÆäËûÍþв¼ÓÈëÕß»òÓÃÓÚÆÆËð¹«Ë¾ÍøÂçÒÔÇÔÈ¡¹«Ë¾Êý¾Ý»ò°²ÅÅÀÕË÷Èí¼þ¡£


https://www.bleepingcomputer.com/news/security/home-depot-confirms-third-party-data-breach-exposed-employee-info/


2. Solar Spider ¿ª·¢Ð¶ñÒâÈí¼þ¹¥»÷Öж«µÄ½ðÈÚÐÐÒµ


4ÔÂ8ÈÕ£¬ÍøÂçÇå¾²·þÎñ¹«Ë¾ Resecurity ÔÚ±¾ÖÜÐû²¼µÄÒ»·Ý±¨¸æÖÐдµÀ£¬¸Ã¹«Ë¾ÆÊÎöÁ˶àÆðÊÂÎñµÄÊÖÒÕϸ½Ú£¬ÕâЩÊÂÎñÉæ¼°Õë¶Ô½ðÈÚ¿Í»§µÄ JSOutProx ¶ñÒâÈí¼þ£¬ÈôÊÇÕë¶ÔÆóÒµ£¬ÔòÌṩÐéαµÄ SWIFT ¸¶¿î֪ͨ£»ÈôÊÇÕë¶Ô˽È˹«Ãñ£¬ÔòÌṩ MoneyGram Ä£°å¡£¸ÃÍþв×éÖ¯µÄÄ¿µÄÊÇÓ¡¶ÈÒÔ¼°·ÆÂɱö¡¢ÀÏÎΡ¢Ð¼ÓÆ¡¢ÂíÀ´Î÷ÑÇ¡¢Ó¡¶ÈµÄ½ðÈÚ×éÖ¯£¬ÏÖÔÚÉÐÓÐɳÌØ°¢À­²®µÄ½ðÈÚ×éÖ¯¡£Resecurity Ê×ϯִÐй٠Gene Yoo ÌåÏÖ£¬´Ó¿ª·¢½Ç¶ÈÀ´¿´£¬×îа汾µÄ JSOutProx ÊÇÒ»¸öºÜÊÇÎÞаÇÒ×éÖ¯ÓÅÒìµÄ³ÌÐò£¬ÔÊÐí¹¥»÷Õßƾ֤Êܺ¦ÕßµÄÌض¨ÇéÐζ¨Öƹ¦Ð§¡£Æ¾Ö¤ Visa µÄÍþв±¨¸æ£¬¹¥»÷Õ߾ͻáÍøÂçÐÅÏ¢£¬ÀýÈçÖ÷Õ˺źÍÓû§Æ¾Ö¤£¬È»ºóÕë¶ÔÊܺ¦ÕßʵÑéÖÖÖÖ¶ñÒâÐÐΪ¡£


https://www.darkreading.com/threat-intelligence/solar-spider-spins-up-new-malware-to-entrap-saudi-arabian-banks


3. ¹È¸èÆðËßÓ¦ÓóÌÐò¿ª·¢ÉÌÐéα¼ÓÃÜÇ®±ÒͶ×ÊÓ¦ÓóÌÐòÕ©Æ­


4ÔÂ8ÈÕ£¬¹È¸èÒѶÔÁ½¼ÒÓ¦ÓóÌÐò¿ª·¢ÉÌÌáÆðËßËÏ£¬Ö¸¿ØÆä¼ÓÈë¡°¹ú¼ÊÔÚÏßÏûºÄÕßͶ×ÊڲƭÍýÏ롱£¬¸ÃÍýÏëÓÕÆ­Óû§´Ó Google Play ÊÐËÁºÍÆäËûȪԴÏÂÔØÐéα Android Ó¦ÓóÌÐò£¬²¢ÒÔÔÊÐí¸ü¸ß»Ø±¨Îª»Ï×ÓÇÔÈ¡ËûÃǵÄ×ʽ𡣾ݳƣ¬ÖÁÉÙ×Ô 2019 ÄêÒÔÀ´£¬±»¸æÒÑÏò Play ÊÐËÁÉÏ´«ÁËÔ¼ 87 ¸ö¼ÓÃÜÓ¦ÓóÌÐò£¬ÒÔʵÑéÉç»á¹¤³ÌȦÌ×£¬ÒÑÓÐÁè¼Ý 10 ÍòÓû§ÏÂÔØÕâЩӦÓóÌÐò£¬²¢µ¼ÖÂÁËÖØ´óµÄ¾­¼ÃËðʧ¡£ÕâÖÖڲƭÍýÏëÒªÇóÕ©Æ­Õßͨ¹ýÉ罻ýÌå»òÔ¼»áƽ̨£¬Ê¹ÓÃÈ«ÐÄÉè¼ÆµÄÐé¹¹½ÇÉ«À´Ãé×¼ºÁÎÞ½äÐĵÄСÎÒ˽¼Ò£¬ÒÔÁµ°®¹ØϵµÄÔ¶¾°ÒýÓÕËûÃǽ¨ÉèÐÅÍУ¬²¢Ëµ·þËûÃÇͶ×ʼÓÃÜÇ®±ÒͶ×Ê×éºÏ£¬ÕâЩͶ×Ê×éºÏÖ¼ÔÚÔÚ¶Ìʱ¼äÄÚÌṩ¸ß¶îÀûÈóÄ¿µÄÊÇÇÔÈ¡ËûÃǵÄ×ʽð¡£


https://thehackernews.com/2024/04/google-sues-app-developers-over-fake.html


4. ÒÔÉ«ÁÐÍøÂçÌع¤²¿·ÖÈÏÕæÈËÒò×Ô¼ºµÄÒþ˽¹ýʧ¶ø±»Æعâ


4ÔÂ8ÈÕ£¬ÕâÃûÌع¤Ãû½Ð Yossi Sariel£¬¾Ý³ÆÊÇÒÔÉ«ÁÐ8200 ²½¶ÓµÄÈÏÕæÈË£¬ÕâÊÇÒ»Ö§ÓÉÆƽâÐÅÏ¢Ç徲ר¼Ò×é³ÉµÄÍŶÓ£¬¿ÉÓëÃÀ¹ú¹ú¼ÒÇå¾²¾Ö»òÓ¢¹úÕþ¸®Í¨Ñ¶×ܲ¿ÏàæÇÃÀ¡£ÏÖÔÚ£¬ËûÒѱ»È·ÒÔΪ 2021 Äê³öÊéµÄ¡¶ÈË»úÍŶӡ·Ò»ÊéµÄ×÷Õߣ¬¸ÃÊé½²ÊöÁ˽«ÈËÀàÊðÀíÓëÏȽøÈ˹¤ÖÇÄÜÅä¶ÔµÄÖÇÄÜÓÅÊÆ¡£ÈøÀï¶û£¨Sariel£©ÒÔºÜÊÇÄäÃûµÄ±ÊÃû¡°YS×¼½«¡±Ð´ÁËÕâ±¾Ê飬ÔÚ¡¶ÎÀ±¨¡·¾ÙÐÐÊÓ²ìºó·¸ÁËÒ»¸öÑÏÖصĹýʧ£¬¸ÃÊӲ췢Ã÷ÑÇÂíÑ·ÉÏÓÐÈøÀï¶ûµÄÊéµÄµç×Ó¸±±¾¡°ÆäÖаüÀ¨Ò»·âÄäÃûµç×ÓÓʼþ£¬¿ÉÒÔÇáËÉ¿ÉÒÔ×·×Ùµ½ Sariel µÄÃû×ÖºÍ Google ÕÊ»§¡£¡±¸Ã±¨ËæºóÏòÒÔÉ«Áйú·À¾üÐÂÎÅȪԴ֤ʵ£¬¸ÃÕË»§ÓëÈøÀï¶ûÓйØ£¬²¢Ö¸³ö¶à¸öÐÂÎÅȪԴÒÑ֤ʵËûÊÇ×÷Õß¡£


https://www.theregister.com/2024/04/08/infosec_news_roundup/


5. TargusµÄÎļþ·þÎñÆ÷ÔâÊÜÍøÂç¹¥»÷ÔËÓªÔÝʱÖÐÖ¹


4ÔÂ8ÈÕ£¬Targus ÊÇÒ»¼ÒÒƶ¯Åä¼þ¹«Ë¾£¬ÒÔʱÉеÄÌõ¼Ç±¾µçÄÔ°üºÍÊÖÌáÏä¶øÖøÃû¡£¸Ã¹«Ë¾»¹ÏúÊÛƽ°åµçÄÔ±£»¤¿Ç¡¢À©Õ¹Îë¡¢¼üÅÌ¡¢Êó±êºÍÂÃÐÐÅä¼þ¡£ÔÚÖÜÒ»ÍíÉÏÏò SEC Ìá½»µÄ FORM 8-K ÎļþÖУ¬Targus µÄĸ¹«Ë¾ B. Riley Financial, INC. Åû¶£¬Õâ¼ÒÌõ¼Ç±¾µçÄÔ°üÖÆÔìÉÌÓÚ 2024 Äê 4 Ô 5 ÈÕÔÚÆäÍøÂçÉϼì²âµ½¹¥»÷¡£Targus Á¬Ã¦Æô¶¯ÁËÊÂÎñÏìÓ¦ºÍÓªÒµÒ»Á¬ÐÔЭÒéÀ´ÊӲ졢×èÖ¹ºÍµ÷½â¸ÃÊÂÎñ¡£Targus ÌåÏÖ£¬¸ÃÊÂÎñÒÑ»ñµÃ¿ØÖÆ£¬ËûÃÇÕýÔÚÍⲿÍøÂçÇ徲ר¼ÒµÄ×ÊÖúÏ»ָ´ÄÚ²¿ÏµÍ³¡£¹«Ë¾Í¨³£»á¹Ø±Õ IT ϵͳÒÔÓ¦¶ÔÍøÂç¹¥»÷£¬ÒÔ±ÜÃâ¹¥»÷ÉìÕŵ½ÆäËû·þÎñÆ÷ºÍ×°±¸¡£È»¶ø£¬ÕâÒ²×èÖ¹Á˶ÔÄÚ²¿Ó¦ÓóÌÐòºÍÊý¾ÝµÄÕýµ±»á¼û£¬ÔÝʱÖÐÖ¹ÁËÓªÒµÔËÓª£¬Í¬Ê±·þÎñÆ÷ºÍÊÂÇéվƾ֤ÐèÒª¾ÙÐÐÁ˻ָ´¡£¸Ã¹«Ë¾ÉÐδ͸¶¹«Ë¾Êý¾ÝÊÇ·ñ±»µÁ£¬µ«ÓÉÓÚºÚ¿ÍÊ×ÏÈÊÇÔÚ¹«Ë¾ÓÃÓÚ´æ´¢ÎļþºÍÊý¾ÝµÄÎļþϵͳÉÏ·¢Ã÷µÄ£¬Òò´ËÊý¾ÝÓпÉÄܱ»Ð¹Â¶¡£


https://www.bleepingcomputer.com/news/security/targus-discloses-cyberattack-after-hackers-detected-on-file-servers/


6. ÍþвÐÐΪÕßͨ¹ý YouTube ÊÓƵÓÎÏ·Îó²îÈö²¥¶ñÒâÈí¼þ


4ÔÂ8ÈÕ£¬ÍþвÐÐΪÕßʹÓà Vidar¡¢StealC ºÍ Lumma Stealer µÈÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þÃé×¼¼ÒÍ¥Óû§£¬ÕâЩ¶ñÒâÈí¼þ½«¶ñÒâÈí¼þαװ³É YouTube ÊÓƵÖеĵÁ°æÈí¼þºÍÊÓƵÓÎÏ·Æƽâ°æ¡£ÕâЩÊÓƵËƺõÖ¸µ¼Óû§»ñÈ¡Ãâ·ÑÈí¼þ»òÓÎÏ·Éý¼¶¡£Ö»¹ÜÔÆÔÆ£¬ÐÎòÖеÄÁ´½ÓÈԻᵼÖ¶ñÒâÈí¼þ£¬¹¥»÷Õß»áÆÆËðÕýµ±ÕÊ»§»òרÃŽ¨ÉèÐÂÕÊ»§À´·Ö·¢¶ñÒâÈí¼þ¡£ÕâÖÖ·½Ö´·¨È˵£ÐÄ£¬ÓÉÓÚËüÕë¶ÔµÄÊÇÄêÇáÓû§£¬ÍæµÄÊǶùͯÖÐÊ¢ÐеÄÓÎÏ·£¬¶øÕâЩÓû§²»Ì«¿ÉÄÜʶ±ð³ö¶ñÒâÄÚÈÝ£¬ÓÉÓÚÒѾ­·¢Ã÷ÁËÁè¼Ý¶þÊ®¸ö´ËÀàÕÊ»§ºÍÊÓƵ£¬²¢½«Æ䱨¸æ¸øYouTube¾ÙÐÐɾ³ý¡£ 


https://gbhackers.com/hackers-deliver-malware-via-youtube-video-game-cracks/