ºÚ¿ÍÐû³ÆÒѾ­ÈëÇÖÃÀ¹úÁª¹ú³Ð°üÉÌ Acuity²¢ÏúÊÛ ICE ºÍ USCIS µÄÊý¾Ý

°ä²¼¹¦·ò 2024-03-11
1. ºÚ¿ÍÐû³ÆÒѾ­ÈëÇÖÃÀ¹úÁª¹ú³Ð°üÉÌ Acuity²¢ÏúÊÛ ICE ºÍ USCIS µÄÊý¾Ý


3ÔÂ9ÈÕ £¬³ôÃûÔ¶ÑïµÄºÚ¿ÍIntelBrokerÐû³Æ¶Ô×î½ü²úÉúµÄһ·Êý¾Ýй¶ÊÂÎñÕÆ¹Ü £¬¾Ý³Æ¸ÃÊÂÎñµÄÖ¸±êÊÇλÓÚ¸¥¼ªÄáÑÇÖÝÀ×˹¶ÙµÄÁª¹ú³Ð°üÉÌ Acuity Inc.¡£Õâ´Îй¶µ¼ÖÂÃÀ¹úÁ½¸ö³ÛÃûµÐÔÖʵÌåµÄÃô¸ÐÊý¾ÝºÍÎļþ±»µÁ£ºÃÀ¹úÒÆÃñºÍº£¹Ø·¨ÂÉ¾Ö (ICE) ÒÔ¼°ÃÀ¹ú¹«ÃñºÍÒÆÃñ·þÎñ¾Ö (USCIS)¡£ £¬Acuity Inc . ÊÇÒ»¼ÒÁª¹ú¼¼ÊõÕ÷ѯ¹«Ë¾ £¬×ܲ¿Î»ÓÚ¸¥¼ªÄáÑÇÖÝÀ×˹¶Ù¡£ËûÃÇΪÁª¹ú»ú¹¹ £¬³ö¸ñÊÇÄÇЩרһÓÚ¹ú¶È°²È«ºÍ¹«¹²°²È«µÄ»ú¹¹ÌṩÉîºñµÄÐÐҵרҵ֪ʶ¡£¸Ã¹«Ë¾°µÊ¾ £¬ËûÃǵÄÖ÷ÌâʹÃüÊÇÔ®ÊÖÕâЩ»ú¹¹¹æ»®½«À´ £¬Ìá¸ßΪ¹«Ãñ·þÎñµÄÄÜÁ¦ £¬²¢Í¨¹ý´´Ðµļ¼Êõ½â¾ö¹æ»®ºÍ¾­¹ýÑéÖ¤µÄÖÎÀí¼¼ÊõÌṩ¿ÉºâÁ¿µÄ³É¾Í¡£ÕâЩÁîÈËÕ𾪵Ä˵·¨³Ê´Ë¿Ì³ôÃûÔ¶ÑïµÄÍøÂç·¸×ïºÍºÚ¿ÍÂÛ̳Breach Forums×î½üµÄһƪÌû×ÓÖС£Hackread.com ¶À¼Ò֤ʵ £¬±»µÁÊý¾ÝĿǰÔÚÂÛ̳ÉÏÒÔ½ö 3,000 ÃÀÔªµÄÃÅÂÞ±Ò (XMR) ¼ÓÃÜÇ®±ÒÏúÊÛ¡£


https://www.hackread.com/hacker-breach-federal-contractor-acuity-ice-uscis-data/


2. ÃÀ¹ú¶¥¼¶ÍøÂ簲ȫ»ú¹¹ÔâºÚ¿Í¹¥»÷²¢±»ÆÈ¹Ø¹Ø²¿ÃÅϵͳ


3ÔÂ8ÈÕ £¬ÕƹÜÍøÂ簲ȫµÄÁª¹ú»ú¹¹½²»°È˺ÍÊìϤ¸ÃÊÂÎñµÄÃÀ¹ú¹ÙԱ֪ͨ CNN £¬¸Ã»ú¹¹ÉϸöÔ·¢ÏÖ×Ô¼ºÔâµ½ºÚ¿Í¹¥»÷ £¬²¢±»ÆÈ¹Ø¹ØÁ½¸ö¹Ø¼üÍÆËã»úϵͳ¡£¾ÝÏàʶÇé¿öµÄÃÀ¹ú¹ÙԱй© £¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾ÖÊÜÓ°ÏìµÄϵͳ֮һÔËÐÐ×ÅÒ»Ïî´òËã £¬ÔÊÐíÁª¹ú¡¢Öݺʹ¦Ëù¹ÙÔ±¹²ÏíÍøÂçºÍÎïÀí°²È«ÆÀ¹À¹¤¾ß¡£ÐÂÎÅÈËÊ¿³Æ £¬ÁíÒ»¸ö°ÑÎÕ×Å»¯Ñ§ÉèÊ©°²È«ÆÀ¹ÀµÄÐÅÏ¢¡£Ä¿Ç°Éв»Ã÷ÏÔË­ÊÇÕâ´ÎºÚ¿Í¹¥»÷µÄÄ»ºóºÚÊÖ £¬µ«Õâ´ÎºÚ¿Í¹¥»÷ÊÇͨ¹ýÓÌËûÖÝ IT ¹«Ë¾ Ivanti ¿ª·¢µÄÊ¢ÐÐÐ鹹רÓÃÍøÂçÈí¼þÖеķì϶²úÉúµÄ¡£¼¸ÖÜÀ´ £¬CISA Ò»Ïò¶½´ÙÁª¹ú»ú¹¹ºÍ˽Ӫ¹«Ë¾¸üÐÂÆäÈí¼þ»ò²ÉÈ¡ÆäËû·ÀÓù´ëÊ© £¬ÒÔÓ¦¶ÔºÚ¿Í¿í·ºÀûÓà Ivanti ·ì϶µÄÇé¿ö¡£¹ÌÈ»ÕâÓÐһЩ³°·íÒâζ £¬µ«¼´±ãÊÇÍøÂ簲ȫ»ú¹¹»ò¹ÙÔ±Ò²¿ÉÄܳÉΪºÚ¿Í¹¥»÷µÄÊܺ¦Õß¡£ÖÕÓÚ £¬ËûÃÇÒÀÀµÓëÆäËûÈËÒ»ÑùµÄ¼¼Êõ¡£


https://edition.cnn.com/2024/03/08/politics/top-us-cybersecurity-agency-cisa-hacked/index.html


3. ¶íÂÞ˹ºÚ¿ÍÈëÇÖ΢Èí £¬ÇÔÈ¡Ãô¸ÐÔ´´úÂëºÍ»úÃÜ


3ÔÂ9ÈÕ £¬Î¢ÈíÌṩÁËÓйضíÂÞ˹¹ú¶ÈÖ§³ÖµÄÃûΪ Midnight Blizzard »ò Nobelium µÄºÚ¿Í×éÖ¯ÌáÒéµÄ¸´ÔÓÇÒ³ÖÐøµÄÍøÂç¹¥»÷µÄ×îÐÂÐÅÏ¢¡£¸Ã¹¥»÷ÓÚ 2024 Äê 1 Ô³õ´Î¼ì²âµ½ £¬×î½ü¼¸ÖÜ´ó·ùÉý¼¶ £¬ÓÉÓÚºÚ¿ÍÊÔIJÀûÓÃÇÔÈ¡µÄÊý¾Ý·ÛËé Microsoft µÄÄÚ²¿ÏµÍ³ºÍÔ´´úÂë´æ´¢¿â¡£Î¢ÈíÔÚһƪ²©¿ÍÎÄÕÂÖÐй© £¬Midnight Blizzard ÓÚ 1 Ô 12 ÈÕÉøÈëÁ˸ù«Ë¾µÄ¹«Ë¾µç×ÓÓʼþϵͳ £¬Ê¹ºÚ¿Í¿ÉÄÜÇÔÈ¡Ãô¸ÐÊý¾Ý¡£¹ÌÈ»ÃæÏò¿Í»§µÄϵͳÉÐδÊܵ½ÇÖº¦ £¬µ«ºÚ¿ÍÔÚÀûÓÃÇÔÈ¡µÄÐÅÏ¢¶Ô΢ÈíµÄϵͳÌáÒéÔ½À´Ô½¼¤½øµÄÃÜÂëÅçÉä¹¥»÷¡£¹ÌÈ»Õâ´Îй¶µÄÈ«ÊýÁìÓòÈÔÔÚµ÷²éÖÐ £¬µ«Î¢Èí°µÊ¾ £¬ËüÒѾ­Ö´ÐÐÁ˼ÓÇ¿µÄ°²È«½ÚÔì¡¢¼à¿ØºÍÍþв¼ì²âÖ°ÄÜ £¬ÒÔÓ¦¶ÔÎçÒ¹±©Ñ©µÄÎÞÇé¹¥»÷¡£Midnight Blizzard ÖÁÉÙ´Ó 2018 ÄêÆðÍ·»îÔ¾ £¬ÊÇÒ»¸öÊܶíÂÞ˹±í¹úµý±¨»ú¹¹Ö§³ÖµÄ³ÛÃûºÚ¿Í×éÖ¯¡£ËüÖØÒªÕë¶ÔÃÀ¹úºÍÅ·ÖÞÈ·µ±¾Ö»ú¹¹¡¢·Çµ±¾Ö×éÖ¯ºÍ¿Æ¼¼¹«Ë¾ £¬Ö÷ÕÅÊǽøÐмäµý»î¶¯ºÍµý±¨ÍøÂç £¬ÒÔÖ§³Ö¶íÂÞ˹µÄÀûÒæ¡£


https://www.cyberkendra.com/2024/03/russian-hackers-breach-microsoft-steal.html


4. Bifrost ľÂíµÄ Linux ±äÌåͨ¹ýÓòÃûÇÀ×¢Ìӱܼì²â


3ÔÂ7ÈÕ £¬Ò»ÖÖÒÑÓÐ 20 Ä꺹ÇàµÄÌØÂåÒÁľÂí×î½ü³ÁгöÏÖ £¬ÆäбäÖÖÒÔ Linux Ϊָ±ê £¬²¢¼ÙÒâÊÜÐÅÀµµÄÍйÜÓòÀ´Ìӱܼì²â¡£Palo Alto Networks µÄ×êÑÐÈËÔ±·¢ÏÖÁËBifrost£¨±ðÃû Bifrose£©¶ñÒâÈí¼þµÄРLinux ±äÌå £¬¸Ã±äÌåʹÓÃÒ»ÖÖ³ÆÎª¡°ÓòÃûÇÀ×¢¡±µÄºýŪÐÔ×ö·¨À´·ÂÕպϷ¨µÄ VMware Óò £¬´Ó¶øÊ¹¶ñÒâÈí¼þ¿ÉÄÜÔÚÀ×´ïÏÂÔËÐС£BifrostÊÇÒ»ÖÖÔ¶³Ì½Ó¼ûÌØÂåÒÁľÂí (RAT) £¬×Ô 2004 ÄêÒÔÀ´Ò»Ïò»îÔ¾ £¬²¢´ÓÊÜϰȾµÄÏµÍ³ÍøÂçÃô¸ÐÐÅÏ¢ £¬ÀýÈçÖ÷»úÃûºÍ IP µØÖ·¡£×êÑÐÈËÔ±Ö¸³ö £¬¹¥»÷Õßͨ³£Í¨¹ýµç×ÓÓʼþ¸½¼þ»ò¶ñÒâÍøÕ¾·Ö·¢ Bifrost £¬µ«ËûÃÇûÓоßÌå×¢Ã÷гöÏÖµÄ Linux ±äÌåµÄ³õʼ¹¥»÷ÏòÁ¿¡£Ö»¹Ü Bifrost RAT ¿ÉÄÜÊǶñÒâÈí¼þµÄÀÏǰ±² £¬µ«ËüÒÀÈ»¶ÔÓ×ÎÒºÍ×éÖ¯×é³É³Á´óÇÒ²»ÐÝÑݱäµÄÍþв £¬³ö¸ñÊÇѡȡÓòÃû·ÂðÀ´Ìӱܼì²âµÄбäÖÖ¡£


https://www.darkreading.com/cloud-security/stealthy-bifrost-rat-linux-variants-use-typosquatting-to-evade-detection-


5. ±ÈÀûʱơ¾Æ´«Ææ¶Åά¶ûµÄÆ¡¾Æ³§ÒòÀÕË÷Èí¼þÖÕ³¡³ö²ú


3ÔÂ7ÈÕ £¬±ÈÀûʱơ¾ÆÄðÔìÉÌ Duvel °µÊ¾ £¬ÀÕË÷Èí¼þ¹¥»÷Òѵ¼ÖÂÆäÉèÊ©ÏÝÈë̱»¾ £¬¶øÆä IT ÍŶÓÔÚÖÂÁ¦½¨¸´°Ü»µ¡£ÓйظÃÊÂÎñµÄ¾ßÌåÐÅϢͨ³£ºÜÉÙ £¬ÓÉÓڸù«Ë¾³ýÁËÏòýÌå°ä·¢Á˼ò¶ÌÉêÃ÷±í £¬ÉÐδ¹«¿ªÕâ´Î´³ÈëÊÂÎñ¡£Ä¿Ç°Éв»Ã÷ÏÔÕâ´ÎÏ®»÷ÊÇÄĸö×éÖ¯ËùΪ¡£Duvel Moortgat ²»½ö½« Duvel ´øµ½ÁËÉ̵ê»õ¼Ü¡¢²ÍÌüºÍ¾Æ°É £¬»¹ÎªÆäËûÊÜÓ­½ÓµÄ¾ÆÆ·´øÀ´ÁË La Chouffe¡¢Vedett¡¢Firestone Walker µÈ¡£Aarts°µÊ¾ £¬·ÛË¿ÃDz»Óò»°²¹©¸øÎÊÌâ £¬ÓÉÓÚ Breendonk ¹¤³§¿â´æ³ä×ã £¬²¢ÇҸù«Ë¾²¢²»²»°²ÍøÕ¾ÁÙʱÍ £»úʱµÄ¶©µ¥ÍƹãÇé¿ö¡£ÆäËûÔâ·êÀÕË÷Èí¼þ¹¥»÷µÄÔì×÷×é֯ͨ³£Ã»ÓÐÄÇôÐÒÔË £¬ÈκÎÀàÐ͵ÄÍ £»ú¶¼¿ÉÄܶÔÔËÓªºÍ²ÆÕþÔì³ÉÇÖº¦¡£Õâ¾ÍÊÇΪʲô¸ÃÐÐÒµ³ÉΪÀÕË÷Èí¼þ·¸×ï·Ö×ӵij£¼ûÖ¸±ê £¬ÓÉÓÚËûÃÇ֪·´ÓÀíÂÛÉϽ² £¬Ôì×÷É̸üÓж¯Á¦¼±¾çÖ§¸¶Êê½ð £¬´Ó¶ø×î´óÏ޶ȵØÏ÷¼õ¼ÛÖµ¸ß°ºµÄÍ £»ú¹¦·ò¡£


https://www.theregister.com/2024/03/07/no_piss_up_in_duvels/


6. 2023 ÄêÍøÂç·¸×ïËðʧ³¬¹ý 125 ÒÚÃÀÔª


3ÔÂ7ÈÕ £¬FBIÍøÂç·¸×ïͶËßÖÐÐÄ£¨IC3£©°ä²¼ÁË2023ÄêÄê¶È»ã±¨ £¬»ã±¨ÏÔʾ £¬¸Ã»ú¹¹ÊÕµ½µÄÍøÂç·¸×ïͶËßÊýÁ¿ÓëÉÏÒ»ÄêÏà±ÈÔö³¤Á˽ü10%¡£2023 Äê £¬ÃÀ¹úÍøÂç·¸×ïÊܺ¦ÕßÏò FBI Ìá³öÁ˳¬¹ý 88 ÍòÆðͶËß £¬»ã±¨Ëðʧ×ܶ¹ý 125 ÒÚÃÀÔª £¬±È 2022 ÄêÔö³¤ÁË 22%¡£´ÓǰÎåÄê £¬·¨ÂÉ»ú¹¹ÊÕµ½½ü 380 ÍòÆðͶËß £¬Ëðʧ×ܶî´ï 374 ÒÚÃÀÔª¡£ÍøÂç´¹µöÒÀȻռͶËßµÄ×î¸ß±ÈÀý £¬Æä´ÎÊÇÓ×ÎÒÊý¾Ýй¶¡¢²»¸¶¿î»ò²»ËÍ»õÚ¿Æ­¡¢ÀÕË÷ºÍ¼¼ÊõÖ§³¶à¿Æ­¡£¾ÍËðʧ¶øÑÔ £¬Í¶×ÊڲƭËðʧ×îΪ²Ò³Á £¬2023 ÄêËðʧ´ï 45.7 ÒÚÃÀÔª £¬¸ßÓÚ 2022 ÄêµÄ 33.1 ÒÚÃÀÔª¡£Æä´ÎÊÇóÒ×µç×ÓÓʼþй¶ (BEC) £¬Êܺ¦ÕßÐû³Æ×ܹ²ËðʧÁË 29 ÒÚÃÀÔª¡£¼¼ÊõÖ§³¶à¿Æ­¡¢Ó×ÎÒÊý¾Ýй¶¡¢°®ÇéÚ¿Æ­¡¢Êý¾Ýй¶¡¢µ±¾ÐÄÙÒâÒÔ¼°²»¸¶¿î/²»½»¸¶´òËã¾ùÔì³ÉÊýÒÚÃÀÔªµÄËðʧ¡£ÔÚÀÕË÷Èí¼þ·½Ãæ £¬FBI ÊÕµ½ÁË 2800 ¶àÆðͶËß £¬Ëðʧ×ܼƽü 6000 ÍòÃÀÔª¡£×îÊܹ¥»÷µÄÐÐÒµÊÇÒ½ÁƱ£½¡¡¢¹Ø¼üÔì×÷¡¢µ±¾ÖÉèÊ©¡¢IT ºÍ½ðÈÚ·þÎñ¡£


https://www.securityweek.com/fbi-cybercrime-losses-exceeded-12-5-billion-in-2023/