CarlsbadµÄ¹«Ë¾ÔâǰԱ¹¤±¨³ð £¬1200¸öOffice 365ÕÊ»§É¾³ý£»CNAϰȾPhoenix £¬1.5Íǫ̀É豸±»¼ÓÃÜ

°ä²¼¹¦·ò 2021-03-26

1.CarlsbadµÄ¹«Ë¾ÔâǰԱ¹¤±¨³ð £¬1200¸öOffice 365ÕÊ»§±»É¾³ý


1.jpg


ÃÀ¹úCarlsbadµÄITÕ÷ѯ¹«Ë¾Ô⵽ǰԱ¹¤Deepanshu KherµÄ±¨³ð £¬1200¸öOffice 365ÕÊ»§±»É¾³ý¡£KherÓÚ2018Äê5Ô±»Ô­¹«Ë¾¿ª³ý £¬Ö®ºó»Øµ½ÁËÓ¡¶È²¢ÓÚͬÄê8ÔÂ8ÈÕÈëÇÖÁ˸ù«Ë¾ £¬É¾³ýÆä1200¶à¸öMicrosoft Office 365ÕÊ»§£¨×ܹ²1500¸ö£©¡£µ¼Ö¹«Ë¾Ô±¹¤ÎÞ·¨Ê¹Óõç×ÓÓʼþ¡¢ÁªÏµÈËÁÐ±í¡¢»áÒéÈÕÀú¡¢Îĵµ¡¢ÊÓÆµºÍÒôƵ»áÒéµÈ·þÎñ £¬¹«Ë¾±»ÆÈ¹Ø¹ØÁ½Ìì £¬ºóÓÖÆÆ·ÑÊýÔÂÆëÈ«¸´Ô­ÔËÓª £¬ËùÉæÓöȸߴï560000ÃÀÔª¡£KherÓÚ½ñÄê1ÔÂ11ÈÕ±»²¶ £¬±»Åд¦2ÄêͽÐÌ £¬·£¿î567084ÃÀÔª¡£    


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/resentful-employee-deletes-1-200-microsoft-office-365-accounts-gets-prison/


2.CNAϰȾPhoenix CryptoLocker £¬1.5Íò¶ą̀É豸±»¼ÓÃÜ


2.png


±£ÏÕ¹«Ë¾CNA³ÆÆäÔ⵽еÄÀÕË÷Èí¼þPhoenix CryptoLockerµÄ¹¥»÷¡£CNA FinancialÊÇÃÀ¹ú×î´óµÄóÒײƸ»ºÍÒâ±íÖÐÉ˱£ÏÕ¹«Ë¾Ö®Ò»¡£¹¥»÷²úÉúÔÚ3ÔÂ21ÈÕ £¬ºÚ¿Í¼ÓÃÜÁËÆä³¬¹ý1.5Íò¶ą̀É豸 £¬Ô̺¬Ê¹Óù«Ë¾µÄVPN½øÐÐÔ¶³Ì°ì¹«µÄÔ±¹¤µÄÍÆËã»ú £¬µ¼Ö¹«Ë¾ÔÚÏß·þÎñÖжÏ £¬ÒµÎñÔËÓªÊܵ½Ó°Ïì¡£¾ÝϤ £¬ÐµÄPhoenix Locker¿ÉÄÜÓëEvil Corp £¬¸ÃÍÅ»ïʹÓÃÐÂÀÕË÷Èí¼þ¼Ò×åHadesÒÔÈÆ¹ýÃÀ¹úµÄÔì²Ã¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/insurance-giant-cna-hit-by-new-phoenix-cryptolocker-ransomware/


3.Microsoft°ä²¼²¹¶¡ £¬½¨¸´PsExecÀûÓÃÖеÄÌáȨ·ì϶


3.jpg


Microsoft°ä²¼ÁËPsExec v2.33 £¬ÒÔ½¨¸´ÆäÖеÄÌáȨ·ì϶¡£PsExecÊÇSysinternalsʵÓ÷¨Ê½ £¬ÔÊÐíÖÎÀíÔ±ÔÚÔ¶³ÌÍÆËã»úÉÏÖ´Ðи÷Àà»î¶¯ £¬¹¥»÷Õßͨ³£ÀûÓÃÆäÔÚÍøÂçºáÏòÒÆ¶¯²¢×°ÖöñÒâÈí¼þ¡£David WellsÓÚ2020Äê12Ô·¢ÏÖÁËλÓÚ¶¨Ãû¹Ü·ͨѶÖеķì϶ £¬±¾µØÓû§¿ÉÀûÓÃÆäÌáÉýµ½SYSTEMȨÏÞ¡£WellsÔÚÉϱ¨¸Ã·ì϶²¢ÆÚ´ý90Ììºó £¬¹«¿ªÁËÆëÈ«µÄPoC¡£Microsoft×îÖÕÓÚ3ÔÂ23ÈÕ £¬ÔÚPsExec v2.33Öа䲼Á˸÷ì϶µÄ²¹¶¡·¨Ê½¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-fixes-windows-psexec-privilege-elevation-vulnerability/


4.Ó¡¶ÈÒ©ÉÌFKOLÒòÏú»ÙÊý¾Ý±»ÃÀ¹úFDA·£¿î5000ÍòÃÀÔª


4.jpg


Ó¡¶Èresenius KabiÁöѧÓÐÏÞ¹«Ë¾£¨FKOL£©µÄÒ»¼ÒÔìÒ©³§ÒòÏú»ÙÊý¾Ý £¬±»ÃÀ¹úʳƷºÍÒ©ÎïÖÎÀí¾Ö£¨FDA£©·£¿î5000ÍòÃÀÔª¡£¸Ã¹¤³§ÖØÒª³ö²úÃÀ¹ú¾øÖ¢»¼ÕßʹÓõļ¸ÖÖ·ÖÆç°©Ö¢Ò©ÎïµÄ»îÐÔÒ©Îï³É·Ö(api)¡£¸Ã¹«Ë¾Ô­¶¨ÓÚ2013Äê1Ô½ÓÊÜFDA²é³­ £¬µ«ÃÀ¹ú˾·¨²¿°µÊ¾ £¬¸Ã¹«Ë¾Ô±¹¤´Ó¹¤³§ÖÐ×ªÒÆÁËÍÆËã»ú¡¢Ö½ÖÊÎļþºÍÆäËû×ÊÁÏ £¬²¢É¾³ýÁËÓйظó§Î¥¹æÐÐΪ֤¾ÝµÄ¼Í¼¡£3ÔÂ23ÈÕ £¬FKOL±»ÃÀ¹ú´¦Ëù·¨ÔºÅз£¿î3000ÍòÃÀÔª²¢³ä¹«2000ÍòÃÀÔªµÄ´¦·£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/drug-maker-to-pay-50m-for/


5.ºÚ¿ÍÔÚÒÔÉ«ÁдóѡǰһÌ칫¿ª³¬¹ý600Íò¸öÑ¡ÃñµÄÐÅÏ¢


5.jpg


ÔÚÒÔÉ«Áдóѡǰ²»µ½24Ó×ʱ £¬ºÚ¿Í¹«¿ªÁ˳¬¹ý650Íò¸öÑ¡ÃñµÄÐÅÏ¢¡£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬6528565ÃûÑ¡ÃñµÄÐÕÃûºÍѡƱºÅÂë £¬ÒÔ¼°³¬¹ý300ÍòÒÔÉ«Áй«ÃñµÄÐÕÃû¡¢µç»°ºÅÂë¡¢Éí·ÝÖ¤ºÅÂë¡¢¼ÒÍ¥µØÖ·¡¢ÐԱ𡢴ºÇïºÍÕþÖÎÆ«ºÃµÈÓ×ÎÒÐÅÏ¢¡£¾ÝϤ £¬Õâ´ÎÊÂÎñÊÇÓÉÓÚÈí¼þ¹«Ë¾Elector SoftwareΪÒÔÉ«ÁÐÕþµ³Likud¿ª·¢µÄÀûÓ÷¨Ê½ElectorÖдæÔÚ·ì϶ £¬Ä¿Ç°Éв»Ã÷ÏÔй¶µÄÊý¾ÝÊÇ·ñÒѱ»½Ó¼û¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/115918/hacking/israeli-voters-leak.html


6.±í»ãÂòÂôÉÌFBSй¶½ü20TB³¬¹ý160ÒÚÌõ¿Í»§µÄÂòÂô¼Í¼


6.jpg


WizCase×êÑÐÈËÔ±·¢ÏÖ±í»ãÂòÂôÉÌFBSÒòElasticsearch·þÎñÆ÷ÅäÖÃÃýÎó £¬Ð¹Â¶Á˽ü20TB³¬¹ý160ÒÚÌõ¿Í»§µÄÂòÂô¼Í¼¡£FBSÊÇÊÀ½çÉÏ×îæÂҵıí»ã£¨forex£©ÂòÂôÔÚÏ߯½Ì¨Ö®Ò» £¬ÔÚÈ«ÇòÕ¼Óжà´ï1600ÍòÓû§¡£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬Óû§ÐÕÃû¡¢µç×ÓÓʼþºÍÕ˵¥µØÖ·¡¢µç»°ºÅÂë¡¢IPµØÖ·¡¢»¤ÕÕºÅÂë¡¢É罻ýÌåID¡¢Éí·ÝÖ¤¡¢¼ÝÊ»ÅÆÕÕ¡¢ÒøÐÐÕË»§¶ÔÕʵ¥¡¢Ë®µç·ÑÕ˵¥ºÍÐÅÓþ¿¨µÈ £¬ÒÔ¼°Óû§ID¡¢Î´¼ÓÃܵÄÃÜÂë¡¢µÇ¼º¹Çà¼Í¼¡¢»áÔ±Êý¾ÝºÍÃÜÂë³ÁÖÃÁ´½ÓµÈÊý¾Ý¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/forex-leaks-millions-customer/