McLaren Health CareÔâµ½¹¥»÷220ÍòÈ˵ÄÐÅϢй¶

°ä²¼¹¦·ò 2023-11-13
1¡¢McLaren Health CareÔâµ½¹¥»÷220ÍòÈ˵ÄÐÅϢй¶


¾Ý11ÔÂ10ÈÕ±¨Â· £¬McLaren Health Care(Âõ¿­Â×)Åû¶ÁË7ÔÂÖÁ8Ô²úÉúµÄһ·Êý¾Ýй¶ÊÂÎñ £¬Ó°ÏìÁË2192515È˵ÄÐÅÏ¢¡£Âõ¿­Â×ÓÚ8ÔÂ22ÈÕ·¢ÏÖÁËÒì³£»î¶¯ £¬µ÷²éÏÔʾ¹¥»÷Õß7ÔÂ28ÈÕÖÁ8ÔÂ23ÈÕδ¾­ÊÚȨ½Ó¼ûÁËÆäÍøÂç¡£ÓÐÖ¤¾ÝÅú×¢ £¬8ÔÂ31ÈÕ¹¥»÷Õß½Ó¼ûÁËÊý¾Ý £¬²¢Ö±µ½10ÔÂ10ÈÕÈ·ÈÏй¶Êý¾ÝµÄÀàÐÍ¡£Ö»¹Ü¸Ã»ú¹¹Ã»ÓÐй©Óйع¥»÷µÄ¸ü¶àϸ½Ú £¬µ«ALPHVÐû³Æ¶ÔÂõ¿­Â׵Ĺ¥»÷ÕÆ¹Ü¡£ËûÃÇ»¹°ä²¼Á˱»µÁÊý¾ÝÑù±¾ £¬²¢ÍþвҪÅÄÂôÓ°Ïì250ÍòÈ˵ÄÊý¾Ý¿â¡£


https://securityaffairs.com/154014/data-breach/mclaren-health-care-data-breach.html


2¡¢CloudflareÍøÕ¾Ôâµ½Anonymous SudanµÄDDoS¹¥»÷


¾ÝýÌå11ÔÂ9ÈÕ±¨Â· £¬CloudflareÍøÕ¾Ôâµ½Anonymous SudanµÄDDoS¹¥»÷¡£CloudflareÍøÕ¾å´»ú £¬ÏÔʾ¡°ÎÒÃǺܱ§À¢......µ«ÄúµÄÍÆËã»ú»òÍøÂç¿ÉÄÜÔÚ·¢ËÍ×Ô¶¯²éÎÊ¡£ÎªÁ˱£»¤±¦ÔËÀ³¹Ù·½ÍøÕ¾Óû§ £¬ÎÒÃÇ´Ë¿ÌÎÞ·¨´¦ÖÃÄúµÄÒªÇó¡±ÒÔ¼°Ò»¸ö¿´ÆðÀ´¡°Óе㲻ºÏ¾¢¡±µÄGoogle»Õ±ê¡£Cloudflare°µÊ¾DDoS¹¥»÷µ¼ÖÂwww.cloudflare.com³öÏÖÁ˼¸·ÖÖÓµÄÏνÓÎÊÌâ¡£µ«ÊÇûÓÐÓ°ÏìCloudflareµÄÈκηþÎñ»ò²úÆ·Ö°ÄÜ £¬Ò²Ã»Óпͻ§Êܵ½Ó°Ïì¡£Anonymous SudanÐû³Æ¶Ô´ËÊÂÕÆ¹Ü £¬²¢³Æ¹¥»÷³ÖÐø¹¦·òΪ1Ó×ʱ¡£


https://www.bleepingcomputer.com/news/technology/cloudflare-website-downed-by-ddos-attack-claimed-by-anonymous-sudan/


3¡¢MandiantÅû¶Sandworm¹¥»÷ÎÚ¿ËÀ¼µçÁ¦ÏµÍ³µÄÏêÇé


MandiantÔÚ11ÔÂ9ÈÕÅû¶ÁËSandwormÀûÓÃÕë¶ÔOTµÄÐÂÐ͹¥»÷Ó°ÏìÎÚ¿ËÀ¼µçÁ¦¹©¸øµÄ»î¶¯¡£¸ÃÊÂÎñ²úÉúÓÚ2022Äêµ× £¬Mandiant°µÊ¾ÕâÊÇÒ»´Î¶àÊÂÎñÍøÂç¹¥»÷ £¬ÀûÓÃÁËÓ°ÏìICS/OTµÄз½Ê½¡£¹¥»÷ÕßÊ×ÏÈʹÓÃOT¼¶´ËÍâLotL¹¥»÷ £¬¿ÉÄܻᴥ·¢Ö¸±ê±äµçÕ¾¶Ï·Æ÷ £¬µ¼ÖÂÒâ±íÍ£µç £¬Í¬Ê±¶ÔÎÚ¿ËÀ¼¸÷µØµÄ¹Ø¼ü»ù´¡ÉèʩִÐдó¹æÄ£µ¼µ¯¹¥»÷¡£SandwormËæºóÔÚÖ¸±êµÄITϵͳÖÐ×°ÖÃÁËCADDYWIPERµÄбäÖÖ £¬´Ó¶øÖ´Ðеڶþ´Î·ÛËéÐÔ¹¥»÷¡£ 


https://www.mandiant.com/resources/blog/sandworm-disrupts-power-ukraine-operational-technology


4¡¢Imperial Kitten¹¥»÷Öж«µØÓòÔËÊä¡¢ÎïÁ÷ºÍ¿Æ¼¼¹«Ë¾


11ÔÂ9ÈÕ £¬CrowdStrike¹«¿ªÁËImperial KittenÕë¶ÔÖж«µØÓòÔËÊä¡¢ÎïÁ÷ºÍ¿Æ¼¼¹«Ë¾µÄµÄÐÂÒ»Âֻ¡£10ÔÂ·Ý £¬¹¥»÷Õ߯ðÍ··Ö·¢ÒÔ¡°¹¤×÷ÕÐÆ¸¡±Ö÷Ìâ £¬Ô̺¬¶ñÒâExcel¸½¼þµÄ´¹µöÓʼþ¡£´ò¿ªºó¶ñÒâºê´úÂë»áÌáÈ¡Á½¸öÅú´¦ÖÃÎļþ £¬ËüÃÇ´´½¨ÓƾÃÐÔ²¢ÔËÐÐpayloadÀ´½øÐз´Ïòshell½Ó¼û¡£¶øºó £¬¹¥»÷ÕßʹÓÃPAExecµÈ¹¤¾ßºáÏòÒÆ¶¯ÒÔÔ¶³Ìִǰ¹ý³Ì £¬Ê¹ÓÃNetScan¿úËÅÍøÂç £¬Ê¹ÓÃProcDump´ÓϵͳÄÚ´æÖлñȡʹ´¦ £¬Ê¹ÓÃ×Ô½ç˵¶ñÒâÈí¼þIMAPLoaderºÍStandardKeyboardÓëC2·þÎñÆ÷ͨѶ¡£


https://www.crowdstrike.com/blog/imperial-kitten-deploys-novel-malware-families/


5¡¢Î¢Èí³ÆSysAid·ì϶CVE-2023-47246±»ÓÃÀ´·Ö·¢Clop


ýÌå11ÔÂ9ÈÕ³Æ £¬¹¥»÷ÕßÔÚÀûÓ÷þÎñÖÎÀíÈí¼þSysAidÖеķì϶½Ó¼ûÆóÒµµÄ·þÎñÆ÷À´ÇÔÈ¡Êý¾Ý £¬²¢²¿ÊðÀÕË÷Èí¼þClop¡£ÕâÊÇÒ»¸öõè¾¶±éÀú·ì϶£¨CVE-2023-47246£© £¬ÔÚºÚ¿ÍÀûÓø÷ì϶ÈëÇÖÄÚ²¿·þÎñÆ÷ºóÓÚ11ÔÂ2ÈÕ±»·¢ÏÖ £¬SysAidÔÚµ÷²éºó¹«¿ªÁ˹¥»÷µÄ¼¼Êõϸ½Ú¡£Î¢Èí´Ë¿ÌÈ·¶¨ £¬¸Ã·ì϶±»Lace Tempest£¨ÓÖ³ÆFin11ºÍTA505£©ÓÃÀ´²¿ÊðÀÕË÷Èí¼þClop¡£SysAidÒѰ䲼·ì϶²¹¶¡ £¬½¨ÒéËùÓÐЧ»§Á¢¼´×°ÖøüС£


https://www.bleepingcomputer.com/news/security/microsoft-sysaid-zero-day-flaw-exploited-in-clop-ransomware-attacks/


6¡¢Kaspersky°ä²¼¹ØÓÚDucktail¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨


11ÔÂ10ÈÕ £¬Kaspersky°ä²¼Á˹ØÓÚDucktail¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£DucktailÊÇÒ»¸ö¶ñÒâÈí¼þ¼Ò×å £¬×Ô2021ÄêϰëÄêÒÔÀ´Ò»Ïò»îÔ¾ £¬Ö¼ÔÚÇÔÈ¡FacebookÆóÒµÕÊ»§¡£±¾»ã±¨·ÖÎöÁË×î½üµÄÒ»´Î»î¶¯ £¬3ÔÂÖÁ10ÔÂÉÏÑ® £¬ÖØÒªÕë¶ÔÓªÏúרҵÈËÔ±¡£ÓëÒÔÍùÒÀÀµ.NETÀûÓ÷¨Ê½µÄ»î¶¯·ÖÆç £¬Õâ´Î»î¶¯Ê¹ÓÃÁËDelphi¡£¸Ã»î¶¯·¢ËÍÔ̺¬¹«Ë¾Ð²úƷͼƬºÍ¼Ù×°³ÉPDFµÄ¶ñÒâ¿ÉÖ´ÐÐÎļþµÄÎĵµ £¬Ö¼ÔÚ´«²¼Ð°汾µÄDucktail¡£


https://securelist.com/ducktail-fashion-week/111017/