ºÚ¿Í×éÖ¯µÁÈ¡11¼Ò¹«Ë¾7320ÍòÌõÊý¾Ý²¢ÔÚ°µÍøÏúÊÛ £»ÍÐ¹ÜÆ½Ì¨DigitalOceanй¼ûô¸ÐÐÅÏ¢

°ä²¼¹¦·ò 2020-05-11

1.ºÚ¿Í×éÖ¯µÁÈ¡11¼Ò¹«Ë¾7320ÍòÌõÊý¾Ý £¬ÔÚ°µÍøÏúÊÛ


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ÔÚ´ÓǰµÄÒ»ÖÜÖÐ £¬ºÚ¿Í×éÖ¯Shiny Hunters×ܹ²ÇÔÈ¡ÁË11¼Ò¹«Ë¾Êý¾Ý¿âÖеÄ7320ÍòÓû§¼Í¼ £¬²¢ÔÚ°µÍøÉÏÏúÊÛ¡£Õâ´ÎÊܺ¦µÄ11¼Ò¹«Ë¾±ðÀëΪTokopedia¡¢Homechef¡¢Bhinneka¡¢Minted¡¢Styleshare¡¢Ggumim¡¢Mindful¡¢StarTribune¡¢ChatBooks¡¢The Chronicle Of Higher EducationºÍZoosk £¬±»µÁÊý¾Ý¼ÛÖµÓÉ500ÃÀÔªµ½5000ÃÀÔª²»µÈ¡£Ä¿Ç° £¬BleepingComputerÒÑÓëÕâЩÊÜÓ°ÏìµÄ¹«Ë¾ÁªÏµ £¬µ«ÉÐδµÃµ½»Ø¸´¡£BleepingComputerÌáÐÑÉÏÊö¹«Ë¾µÄÓû§¾¡¿ì¸ü¸ÄÃÜÂë £¬ÈôÊÇÔÚÆäËûÕ¾µãÉÏʹÓÃÒ»ÑùµÄÃÜÂëÒ²±ØÒª¸ü¸Ä¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hacker-group-floods-dark-web-with-data-stolen-from-11-companies/


2.ÍÐ¹ÜÆ½Ì¨DigitalOcean´æÔÚ°²È«ÎÊÌâ £¬Ãô¸ÐÐÅϢй¶


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


½üÈÕ £¬ÍøÂçÍÐ¹ÜÆ½Ì¨DigitalOceanÓÉÓÚ´æÔÚ°²È«ÎÊÌâ £¬ÆäÄÚ²¿Îļþ±©Â©ÔÚ¹«ÍøÉÏ £¬µ¼Ö¹«Ë¾Ä³Ð©¿Í»§µÄÓ×ÎÒ¾ßÌåÐÅϢй¶¡£Õâ´Îй¶Êý¾ÝÔ̺¬¿Í»§µÄÕÊ»§Ãû³Æ¡¢µç×ÓÓʼþµØÖ·¡¢´ø¿íʹÓÃÇé¿ö¡¢Droplet¼ÆÊý £¬2018ÄêÖ§³öÒÔ¼°ÊÛºóºÍÏúÊۼͼ £¬¶ø¸ÃÄÚ²¿ÎĵµÒѱ»½Ó¼ûÖÁÉÙ15´Î¡£DigitalOcean°µÊ¾ £¬¸ÃÎĵµ½öÔ̺¬²»µ½1£¥µÄ¿Í»§µÄÊý¾Ý £¬²¢ÇҸù«Ë¾ÔÚ²ÉÈ¡´ëÊ©ÒÔÔ¤·À½«À´²úÉúÀàËÆÊÂÎñ¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/digitalocean-data-breach-leaves-internal-doc-online/


3.»ð³µÔì×÷ÉÌStadlerÔâÀÕË÷Èí¼þ¹¥»÷ £¬µ¼ÖÂÊý¾Ýй¶


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¹ú¼Ê»ð³µÔì×÷ÉÌStadlerÔÚÉÏÖÜËÄÍíÉϰ䷢ £¬ÆäÔâµ½ÁËË÷Èí¼þ¹¥»÷ £¬»ò½«µ¼Ö¹«Ë¾ºÍÔ±¹¤µÄÊý¾Ýй¶¡£·¢ÏÖ¹¥»÷ºóStadler¹«Ë¾Á¢¿Ì²ÉÈ¡ÁË´ëÊ© £¬ÎªÐ¹Â¶Êý¾Ý±¸·Ý²¢ÖÂÁ¦¸´Ô­ÊÜÓ°ÏìµÄϵͳ¡£Ä¿Ç° £¬¸ÃÊÂÎñµÄ²¼¸æ²¢Î´Ð¹Â©ÊÜÓ°ÏìµÄÁìÓòºÍϵͳµÄÊýÁ¿ £¬µ«ÈðʿýÌ尵ʾ £¬ÔÚÕâ´Î¹¥»÷ÖÐÕû¸öStadler¼¯ÍŶ¼Êܵ½ÁËÓ°Ïì £¬Ô̺¬ÈðÊ¿ºÍ¹ú±íµÄ¹«Ë¾¡£BleepingComputerÒÑÓëStadler½²»°ÈËÁªÏµ £¬µ«Ä¿Ç°ÉÐδµÃµ½»Ø¸´¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/rail-vehicle-manufacturer-stadler-hit-by-cyberattack-blackmailed/


4.LazarusÍÅ»ïÀûÓÃ2FA App·Ö·¢Dacls RAT £¬Ï°È¾MacÉ豸


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Malwarebytes×êÑÐÈËÔ±·¢ÏÖ £¬Ó볯ÏÊÓÐÁªÏµµÄºÚ¿Í×éÖ¯Lazarus £¬Í¨¹ý»ùÓÚMacϵͳµÄ2FAÀûÓ÷¨Ê½macaOTA·Ö·¢Dacls RATбäÖÖ £¬¸ÃÀûÓ÷¨Ê½ÖØÒªÓÉÖйúÓû§Ê¹Óá£×êÑз¢ÏÖ £¬¹¥»÷ÕßÓÚ4ÔÂ8ÈÕÔÚÏã¸Û½«¿ÉÒÉMacÀûÓ÷¨Ê½µÄTinkaOTPÉÏ´«ÖÁVirusTotalµÄ £¬²¢ÇұܿªÁËËùÓÐÒýÇæµÄ¼ì²â¡£¸ÃбäÌåÄܹ»ÊµÏÖ¸÷ÀàÖ°ÄÜ £¬ÀýÈçºÅÁîÖ´ÐÓ×¢ÎļþÖÎÀí¡¢Á÷Á¿´úÀíºÍÈ䳿ɍÃè £¬×ܹ²Ô̺¬ÓÐ7¸ö²å¼þ £¬²¢ÇÒÀûÓÃWolfSSL¿â½øÐÐSSLͨѶ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/102981/apt/lazarus-apt-mac-dacls-rat.html?utm_source=rss&utm_medium=rss&utm_campaign=lazarus-apt-mac-dacls-rat


5.ÒÁÀʺڿÍÕë¶ÔÒ©ÉÌGilead £¬ÒÔÍøÂçÓйØCOVID-19µÄÐÅÏ¢


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¾Ý·͸É籨· £¬×î½ü¼¸ÖÜ £¬ÓëÒÁÀÊÓйصĺڿͽ«ÃÀ¹úÔìÒ©ÉÌGilead×÷Ϊ¹¥»÷Ö¸±ê £¬Ö¼ÔÚÍøÂçÓйØCOVID-19µÄÐÅÏ¢¡£¾Ýµ÷²é £¬ºÚ¿ÍÓÚ4ÔÂ·Ý £¬¼ÙÒâÐÂÎŹ¤×÷ÕßÏò¸Ã¹«Ë¾ÕƹÜ˾·¨ºÍ¹«Ë¾ÊÂÎñµÄ¸ß¹Ü·¢ËÍÁËÒ»·â´¹µöÓʼþ £¬Ö¼ÔÚ·ÛËéÆäµç×ÓÓʼþÕÊ»§¡£ÒÁÀÊפ½áºÏ¹ú´ú±íÍÅ·ñ¶¨ÆäÓëÏ®»÷ÓÐÈκÎÖêÁ¬ £¬²¢°µÊ¾ÒÁÀʵ±¾Ö²»²Î¼ÓÍøÂçÕ½¡£¶øGilead»Ø¾ø¶Ô´ËÊÂÖÃÆÀ £¬ÓÉÓÚ¹«Ë¾²»»áÉÌÍøÂ簲ȫÎÊÌâµÄÕþ²ß¡£¾Ý·͸Éçµ÷²é £¬½üÆÚÓëÒÁÀÊÓйصĺڿÍÒ²ÊÔͼ¹¥»÷ÊÀ½çÎÀÉú×éÖ¯ £¬¶øÓëÔ½ÄÏÓйصĺڿÍÔòÔÚÕë¶ÔÖйú¡£


Ô­ÎÄÁ´½Ó£º

https://www.reuters.com/article/us-healthcare-coronavirus-gilead-iran-ex/exclusive-iran-linked-hackers-recently-targeted-coronavirus-drugmaker-gilead-sources-idUSKBN22K2EV


6.Atlas VPN·¢ÏÖ £¬4Ô·ÝÈ«Çò¶ñÒâÈí¼þϰȾÁ¿ÔöÖÁ4.04ÒÚ


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Atlas VPN¹«Ë¾Í³¼Æ·¢ÏÖ £¬4Ô·ÝÈ«ÇòÔ¼ÓÐ4.04ÒÚÉ豸ϰȾ¶ñÒâÈí¼þ £¬¶ñÒâÈí¼þ¾ùÔÈÿÌìϰȾ³¬¹ý1000ÍòÉ豸 £¬ÆäÖÐ64£¥µÄ¹¥»÷Õë¶Ô½ÌÓý»ú¹¹¡£Ï°È¾Á¿ÔÚ4ÔÂ16ÈÕ´ïµ½¶¥·å £¬Îª1600ÍòÀý¡£Æ¾¾ÝKasperskyµÄÍøÂçÍþвͼ £¬ÖÐÑÇÊDZ¾µØÍøÂç¹¥»÷µÄÖØÒªÖ¸±ê £¬Ëþ¼ª¿Ë˹̹ºÍÎÚ×ȱð¿Ë˹̹±ðÀëÓÐ32£¥ºÍ31£¥µÄÉ豸ϰȾ £¬¶øÔÚÖйú £¬ÓÐ27£¥µÄÉ豸ϰȾ¡£Î¢Èí·¢ÏÖ £¬½ÌÓý²¿ÃÅÖ®ºó £¬ÆóÒµºÍרҵ·þÎñÐÐҵϰȾÁ¿×î¶à £¬Æä´ÎÊÇÁãÊÛºÍÏû·ÑÆ·¸ñÒµ £¬Ö®ºóÊǽðÈںͱ£ÏÕ·þÎñ²¿ÃÅ¡¢Ò½ÁÆÐÐÒµ¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/400-million-malware-infection-in-april-2020/