¶àÂ×¶à½ÌÓý¾ÖÔâLockBitÀÕË÷Èí¼þ¹¥»÷ £¬Ñ§ÉúÐÅϢй¶

°ä²¼¹¦·ò 2024-09-03
1. ¶àÂ×¶à½ÌÓý¾ÖÔâLockBitÀÕË÷Èí¼þ¹¥»÷ £¬Ñ§ÉúÐÅϢй¶


8ÔÂ31ÈÕ £¬¶àÂ×¶àµØÓò½ÌÓý¾Ö£¨TDSB£©±¾ÖÜÈ·ÈÏÁË6Ô·ݲúÉúµÄÒ»´ÎÀÕË÷Èí¼þ¹¥»÷ÊÂÎñ £¬¸ÃÊÂÎñÉæ¼°Ñ§ÉúÐÅÏ¢µÄй¶ ¡£Ö»¹Ü×î³õ½ÌÓý¾Ö°µÊ¾¹¥»÷½öÕë¶ÔÒ»¸ö¼¼Êõ²âÊÔ»·¾³ £¬Óë¹Ù·½ÍøÂç¸ôÀë £¬µ«ºóÐøÖ¤Êµ2023/2024ѧÄêÖв¿ÃÅѧÉúµÄÓ×ÎÒÐÅÏ¢ £¬Ô̺¬ÐÕÃû¡¢Ñ§ÌÃÏêÇé¡¢Äê¼¶¡¢ÓÊÏ䵨ַ¡¢Ñ§ºÅ¼°µ®ÉúÈÕÆÚµÈ £¬È·ÇÐʵ²âÊÔ»·¾³Öб»Ð¹Â¶ ¡£½ÌÓý¾ÖÇ¿µ÷ £¬¾­ÍøÂ簲ȫÍÅ¶ÓºÍ±í²¿×¨¼ÒÆÀ¹À £¬Ñ§ÉúÃæ¶ÔµÄ·çÏÕ¡°ºÜµÍ¡± £¬ÇÒδ·¢ÏÖÊý¾Ý¹«¿ªÅû¶µÄÇé¿ö ¡£È»¶ø £¬LockBitÀÕË÷Èí¼þÍÅ»ïËæºóÈÏ¿ÉÁËÕâ´Î¹¥»÷ £¬²¢ÔÚÆäйÃÜÍøÕ¾Éϸø½ÌÓý¾ÖÉ趨ÁËÖ§¸¶Êê½ðµÄÆÚÏÞ £¬µ«Î´¹«¿ª¾ßÌåÊê½ðÊý¶î ¡£TDSBÉÐδ¾ÍLockBitµÄÉêÃ÷×÷³ö»ØÓ¦ £¬µ«ÒÑÖÂÐżҳ¤×¢Ã÷Çé¿ö £¬²¢Ç¿µ÷ÒѲÉÈ¡¶àÏî´ëÊ©¼ÓǿѧÉúÐÅÏ¢°²È« £¬Í¬Ê±¹²Í¬·¨Âɲ¿Ãŵ÷²é ¡£Õâ´ÎÊÂÎñ²úÉúÔÚLockBitÍÅ»ïÖÙ´º·ÝÔâ½ø¹¥ºóÊÔͼ¸´³öµÄ²¼¾°Ï £¬Æä°ä²¼µÄÊܺ¦ÕßÐÅÏ¢ÖдæÔÚ²»ÉÙÃýÎó»ò³Á¸´Ìõ¿î £¬Òý·¢×¨¼ÒÖÊÒÉ ¡£


https://therecord.media/toronto-school-district-board-ransomware


2. ÐÂÐÍÀÕË÷Èí¼þCicada3301»îÔ¾ £¬»òÓëALPHVÓйØÁª


9ÔÂ2ÈÕ £¬ÐÂÐÍÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©Cicada3301½üÆÚÔÚÍþвÁìÓòո¶ͷ½Ç £¬Õë¶Ô¶à¼Ò¹«Ë¾ÌáÒé¹¥»÷ £¬Æä»îÔ¾ÐÔÁîÈËÖõÄ¿ ¡£×Ô6ÔÂÒÔÀ´ £¬Cicada3301ͨ¹ýRAMPÍøÂç·¸×ïÂÛ̳ÕÐļ³ÉÔ± £¬Ñ¡È¡Rust˵»°±àд £¬Ö§³ÖWindows¼°Linux/ESXiϵͳ £¬ÏÔʾ³öÓëÒÑDzɢµÄBlackCat/ALPHV×éÖ¯ÔÚ¼¼ÊõÉϵÄÀàËÆÐÔ £¬Ô̺¬¼ÓÃÜËã·¨¡¢ºÅÁîʹÓúÍÎļþ¶¨ÃûÔ¼¶¨ ¡£Cicada3301ͨ¹ýÇÔÈ¡»ò±©Á¦ÆÆ½âƾ֤µÇ¼ϵͳ £¬Ê¹ÓõÄIPµØÖ·ÓëBrutus½©Ê¬ÍøÂçÓйØÁª £¬¿ÉÄÜÅú×¢Á½Õß¼äµÄijÖÖÁªÏµ ¡£Æä³õʼ¹¥»÷¼¿Á©¶àÑù £¬Ô̺¬Õë¶ÔVMware ESXiϵͳµÄ³ö¸ñ±äÌå ¡£¸ÃÀÕË÷Èí¼þ¾ß±¸¸ß¶È¿ÉÅäÖÃÐÔ £¬ÔÊÐí²Ù×÷Ô±ÔÚÖ´Ðйý³ÌÖе÷ÕûÆäÐÐΪ £¬ÈçÑÓ³¤Ö´ÐÓ×¢ÏÔʾ¼ÓÃܽø¶È¼°ÔÚ¼ÓÃÜESXiÖ÷»úÎļþʱÎÞÐè¹Ø¹ØÐé¹¹»úµÈ £¬ÕâЩְÄܼÓÇ¿ÁËÆäÊÊÓ¦ÐԺͽýÝÐÔ ¡£¼ÓÃܹý³ÌÖÐ £¬Cicada3301ʹÓÃOsRngËæ»úÊýÌìÉúÆ÷ÌìÉú¶Ô³ÆÃÜÔ¿ £¬²¢Í¨¹ýPGP¹«Ô¿¼ÓÃÜÕâЩÃÜÔ¿ £¬Í¬Ê±ÔÚÿ¸ö¼ÓÃÜÎļþ¼ÐÖÐÁôÏÂÊê½ð×¢Ã÷Îļþ ¡£¼ÓÃÜʵÏÖºó £¬ChaCha20ÃÜÔ¿±»RSA¼ÓÃÜ £¬²¢Óë¼ÓÃÜÎļþÀ©´óÃûÒ»Æð¸½¼Óµ½Îļþĩβ £¬ÐÎ³ÉÆëÈ«µÄÀÕË÷ÐÅÏ¢ ¡£


https://securityaffairs.com/167897/cyber-crime/a-new-variant-of-cicada-ransomware-targets-vmware-esxi-systems.html


3. Â׶ؽ»Í¨¾ÖÓ¦¶ÔÍøÂç¹¥»÷ £¬ÉÐÎÞÖ¤¾ÝÏÔʾ¿Í»§Êý¾Ýй¶


9ÔÂ2ÈÕ £¬Â׶ؽ»Í¨¾Ö£¨TfL£©ÕýÈ«Á¦Ó¦¶Ôһ·ÔÚ½øÐÐÖеÄÍøÂç¹¥»÷ £¬Í¬Ê±Ïò¹«¼Ò±£ÕÏ £¬Ä¿Ç°ÉÐÎÞÈ·ÔäÖ¤¾ÝÅú×¢¿Í»§Ó×ÎÒÐÅÏ¢ÒÑÒò¶ø´ÎÊÂÎñ¶øÐ¹Â¶ £¬ÇÒTfLµÄ¸÷Ïî·þÎñÔË×÷Õý³£ £¬Î´ÊÜÏÔÖøÓ°Ïì ¡£×÷ΪÂ׶صØÓò½»Í¨ÍøÂçµÄÖØÒªÖÎÀí»ú¹¹ £¬TfLѸËÙÏìÓ¦ £¬Óë¹ú¶È·¸×ï¾Ö£¨NCA£©¼°¹ú¶ÈÍøÂ簲ȫÖÐÐÄ£¨NCSC£©çÇÃܺÏ×÷ £¬²ÉÈ¡ÁËһϵÁÐÄÚ²¿´ëÊ©ÒÔ¼ÓÇ¿ÍøÂ簲ȫ·À»¤ ¡£¾ÝÄÚ²¿ÐÂÎÅй© £¬Õâ´Î¹¥»÷ÖØÒª¼¯ÖÐÓÚTfL×ܲ¿µÄºó¶Üϵͳ £¬´Ùʹ²¿ÃÅÔ±¹¤±»½¨Òé¾Ó¼Ò°ì¹«ÒÔÏ÷¼õDZÔÚ·çÏÕ ¡£TfLÊ×ϯ¼¼Êõ¹ÙShashi VermaÇ¿µ÷ £¬± £»¤ÏµÍ³Óë¿Í»§Êý¾ÝµÄ°²ÂúÊÇÊ×Òª¹¤×÷ £¬ÍŶӽ«³ÖÐø¼à¿Ø²¢ÆÀ¹ÀÊÂ̬·¢Õ¹ £¬È·±£¹«¼Ò³öÐа²È«ÓëÐÅÀµ²»ÊÜÇÖº¦ ¡£×ÜÌå¶øÑÔ £¬Ö»¹ÜÃæ¶ÔÌôÕ½ £¬TfLչʾ³ö»ý¼«Ó¦¶ÔµÄ̬¶È £¬Á¦Çó½«Ç±ÔÚÓ°Ïì½µÖÁ×îµÍ ¡£


https://securityaffairs.com/167946/hacking/transport-for-london-tfl-ongoing-cyberattack.html


4. µØÀí¶¨Î»×·×Ù·þÎñTracelo³¬140ÍòÈËÐÅÏ¢ÔâºÚ¿Íй¶


9ÔÂ2ÈÕ £¬ÖÇÄÜÊÖ»úµØÀí¶¨Î»×·×Ù·þÎñTraceloÔÚ9ÔÂ1ÈÕÔâ·ê³Á´óÊý¾Ýй¶ÊÂÎñ £¬ºÚ¿Í¡°Satanic¡±Ðû³Æ¹¥ÆÆÁËÆäϵͳ £¬²¢ÔÚÍøÂç°µÅÌÉϹ«¿ªÁ˳¬¹ý140ÍòÈ˵ÄÓ×ÎÒÐÅÏ¢ £¬Òý·¢¿í·º¹Ø×¢ ¡£Tracelo×÷ΪÐÂÐË·þÎñ £¬Ëä±ê°ñ·µÂ¹æ·¶µÄ¶¨Î»×·×Ù £¬µ«ÆäÔÚÊý¾ÝÍøÂçÓëÔÞ³ÉÑéÖ¤ÉϵÄͨÃ÷¶È²»¼° £¬Òý·¢ÁËÒþÖÔ± £»¤ÕùÒé ¡£Õâ´Îй¶µÄÊý¾ÝÔ̺¬Óû§È«Ãû¡¢µç»°ºÅÂë¡¢ÎïÀíµØÖ·¡¢µç×ÓÓʼþµÈÃô¸ÐÐÅÏ¢ £¬ÒÔ¼°´óÁ¿¿Í»§µÄGoogle IDºÅ £¬ºóÕß¿ÉÄܽøÒ»²½Â¶³öÓû§µÄÈÕ³ £»î¶¯¹ì¼£ ¡£ÖµÍ×ÌùÐĵÄÊÇ £¬Ö»¹ÜTraceloÖ¼ÔÚÔ®ÊÖÓû§×·×ÙËûÈ˵ØÎ» £¬µ«Ð¹Â¶µÄÊý¾ÝÖв¢Î´Ô̺¬Ö¸±êÓ×ÎÒµÄλÏàÐÅÏ¢ £¬·´¶øÖØÒªÊǿͻ§×ÔÉíµÄ¾ßÌå×ÊÁÏ ¡£ÊÜÓ°ÏìµÄÓû§Ãæ¶ÔÍøÂç´¹µöºÍÓïÒô´¹µöÚ¿Æ­µÄÍþвÔö³¤ £¬Òò¶øÐè¸ß¶È¾¯ÌèÀ´×Ô²»Ã÷ÆðÔ´µÄÓʼþºÍµç»° £¬Ô¤·Àй¶¸ü¶àÓ×ÎÒÐÅÏ¢ ¡£


https://hackread.com/tracelo-location-tracker-data-breach-user-records-leak/


5. CBIZÊý¾Ýй¶ÊÂÎñÆØ¹â £¬½ü36,000¿Í»§ÐÅÏ¢ÔâÇÔ


9ÔÂ2ÈÕ £¬CBIZ¸£ÀûÓë±£ÏÕ·þÎñ¹«Ë¾Åû¶ÁËһ·ÑϳÁµÄÊý¾Ýй¶ÊÂÎñ £¬¸ÃÊÂÎñÉæ¼°½ü36,000Ãû¿Í»§µÄÃô¸ÐÐÅÏ¢±»Î´¾­ÊÚȨ½Ó¼û ¡£¾ÝϤ £¬Ò»ÃûÍþвÐÐΪÕßÀûÓÃCBIZÍøÒ³Öеݲȫ·ì϶ £¬ÔÚ6ÔÂ2ÈÕÖÁ21ÈÕÆÚ¼äDZÈëϵͳ²¢ÇÔÈ¡ÁËÔ̺¬ÐÕÃû¡¢ÁªÏµ·½Ê½¡¢Éç»á°²È«ºÅÂë¡¢µ®Éú/éæÃüÈÕÆÚ¡¢ÍËÐÝÈËÔ±½¡È«ÐÅÏ¢¼°¸£Àû´òËãÐÅÏ¢ÔÚÄڵĿͻ§Êý¾Ý ¡£CBIZ×÷ΪÃÀ¹úµ±ÏȵÄ×ÛºÏÐÔ·þÎñÌṩÉÌ £¬ÒµÎñÁìÓòº­¸Ç¹ÜÕÊ˰Îñ¡¢±£ÏÕ¡¢Ã³Ò×Õ÷ѯ¼°ÈËÁ¦×ÊÔ´µÈ¶à¸öÁìÓò £¬ÔÚÈ«¹úÕ¼ÓÐ120¸ö´¦Ê´¦¼°6,700ÃûÔ±¹¤ £¬2023ÄêÊÕÈë¸ß´ï15.9ÒÚÃÀÔª ¡£¹«Ë¾ÒÑÓÚ6ÔÂ24ÈÕ·¢ÏÖÕâ´ÎÈëÇÖ £¬²¢Á¢¼´×ÅÊÖµ÷²é ¡£ÊÜÓ°Ïì¿Í»§×Ô8ÔÂ28ÈÕÆðÂ½ÐøÊÕµ½¸öÐÔ»¯Í¨Öª £¬CBIZËäδ·¢ÏÖÊý¾ÝÀÄÓü£Ïó £¬µ«ÈÔÌṩΪÆÚÁ½ÄêµÄÐÅÓþ¼à¿ØºÍÉí·Ý͵ÇÔ± £»¤·þÎñ £¬²¢½¨Òé¿Í»§²ÉÈ¡¶î±í´ëÊ©ÈçÐÅÓþ¶³½á¼°Ôö³¤Ú²Æ­¾¯±¨ £¬ÒÔ½µµÍDZÔÚ·çÏÕ ¡£


https://www.bleepingcomputer.com/news/security/business-services-giant-cbiz-discloses-customer-data-breach/


6. Prasarana Malaysia BhdÔâÀÕË÷¹¥»÷ £¬³¬300GBÊý¾Ýй¶


8ÔÂ30ÈÕ £¬ÂíÀ´Î÷Ñǹ«¹²½»Í¨¾ÞÍ·¹ú¶È»ù½¨¹«Ë¾£¨Prasarana Malaysia Bhd£©½üÈÕÈ·ÈÏÁËÉ罻ýÌåÉÏÁ÷´«µÄÒ»ÔòÍøÂ簲ȫÊÂÎñ±¨Â·µÄÕæÊµÐÔ £¬Ö¸³öÆäÄÚ²¿ÏµÍ³È·ÒÑÔâ·êδÊÚȨ½Ó¼û ¡£Ö»¹ÜÕâ´ÎÊÂÎñÉÐδ¶Ô¹«Ë¾µÄÈÕ³£ÔËÓªÔì³ÉÓ°Ïì £¬µ«¹«Ë¾ÒÑѸËÙ²ÉÈ¡Ðж¯ £¬½áºÏÍøÂ簲ȫר¼Ò·¢Õ¹È«Ãæµ÷²é £¬²¢×ÅÊÖ»º½âDZÔÚÍþв ¡£Í¬Ê± £¬¹ú¶È»ù½¨¹«Ë¾ÒÑÓëÂíÀ´Î÷Ñǹú¶ÈÍøÂ簲ȫ¾Ö£¨Nacsa£©¼°ÍøÂ簲ȫ»ú¹¹£¨CyberSecurity Malaysia£©çÇÃܺÏ×÷ £¬¹²Í¬Ôì¶©²¢Ö´ÐÐÈ«ÃæµÄ°²È«·ÀÓùÕ½Êõ £¬ÒÔ±£ÏÕÆä½»Í¨·þÎñϵͳµÄ°²È«²»±äÔËÐÐ ¡£×÷ΪÂíÀ´Î÷Ñǹ«¹²½»Í¨ÏµÍ³µÄ³ÁÒª×é³É²¿ÃÅ £¬¹ú¶È»ù½¨¹«Ë¾²»½öÔËÓªRapidKLÆìϵÄÇá¹ì¡¢½ÝÔË¡¢°ÍÊ¿¼±¾ç½»Í¨ÏµÍ³ £¬»¹ÖÎÀí¼ªÂ¡ÆÂµ¥¹ìÁгµ¼°ÖØ´óµÄ¹«½»³µ¶Ó ¡£ÕâÒ»ÉêÃ÷Ö¼ÔÚ»ØÓ¦±í½ç¹ØÓÚ¹«Ë¾ÍøÕ¾¿ÉÄÜÔâ·êÀÕË÷Èí¼þ¹¥»÷ £¬µ¼ÖÂ316GBÊý¾Ýй¶µÄ´«ÑÔ ¡£¾ÝϤ £¬ÀÕË÷Èí¼þ×éÖ¯RansomHubÒÑ·¢³öÍþв £¬Ðû³Æ½«ÔÚÁùµ½ÆßÌìÄÚ¹«½¨¹ú¶È»ù½¨¹«Ë¾µÄÃô¸ÐÊý¾Ý ¡£


https://www.freemalaysiatoday.com/category/nation/2024/08/26/prasarana-confirms-cybersecurity-incident/