ÆÏÌÑÑÀ×î´óµÄýÌ幫˾ImpresaÔâµ½Lapsus$ÀÕË÷¹¥»÷

°ä²¼¹¦·ò 2022-01-05

ÆÏÌÑÑÀ×î´óµÄýÌ幫˾ImpresaÔâµ½Lapsus$ÀÕË÷¹¥»÷


 ÆÏÌÑÑÀ×î´óµÄýÌ幫˾ImpresaÔâµ½Lapsus$ÀÕË÷¹¥»÷.png


¾Ý1ÔÂ2ÈÕ±¨Â· £¬£¬£¬ £¬£¬ÆÏÌÑÑÀ×î´óµÄýÌ幫˾ImpresaÔâµ½Lapsus$µÄÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷²úÉúÓÚÔªµ©¼ÙÆÚÆÚ¼ä £¬£¬£¬ £¬£¬Ó°ÏìÁ˸ù«Ë¾µÄIT·þÎñÆ÷»ù´¡ÉèÊ© £¬£¬£¬ £¬£¬µ¼Ö¸ùú×îÖØÒªµÄµçÊÓÆµÂ·SICºÍÖܱ¨Expresso·þÎñÁÙʱÖжϡ£¡£¡£¡£¡£¡£Lapsus$ÍÅ»ïÔÚImpressaµÄËùÓÐÍøÕ¾ÁôÏÂÀÕË÷Êê½ðÒªÇó £¬£¬£¬ £¬£¬²¢Ðû³ÆÒÑ»ñµÃ¶ÔImpresaµÄAmazon Web ServicesÕÊ»§µÄ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£¡£1ÔÂ2ÈÕ £¬£¬£¬ £¬£¬¸Ã¹«Ë¾µÄËùÓÐÍøÕ¾´¦ÓÚÊØ»¤×´Ì¬ £¬£¬£¬ £¬£¬¹¥»÷Õß»¹ÀûÓÃExpressoµÄTwitterÕÊ»§·¢·¢ÎijÆËûÃÇÈԿɽӼû¹«Ë¾×ÊÔ´¡£¡£¡£¡£¡£¡£


https://therecord.media/lapsus-ransomware-gang-hits-sic-portugals-largest-tv-channel/



Unit 42·¢ÏÖÕë¶Ô·¿µØ²úÍøÕ¾µÄWeb Skimmer»î¶¯


¾ÝUnit 42ÔÚ1ÔÂ3ÈÕ°ä²¼µÄ»ã±¨³Æ £¬£¬£¬ £¬£¬Ò»¸öеÄWeb Skimmer»î¶¯Õýͨ¹ý¹¥»÷·Ö·¢ÔÆÊÓÆµµÄ¹©¸øÁ´À´¶Ô×¼·¿µØ²úÍøÕ¾¡£¡£¡£¡£¡£¡£Õâ´Î×êÑй²¼ì²âµ½100¶à¸öÊܵ½Ò»ÑùSkimmer¹¥»÷µÄÍøÕ¾ £¬£¬£¬ £¬£¬¾­·ÖÎö·¢ÏÖËùÓй¥»÷¶¼Ô´×ÔÒ»¼Ò¹«Ë¾£ºÕâЩ±»ÈëÇÖµÄÍøÕ¾¶¼´ÓÒ»¸öÔÆÊÓÆµÆ½Ì¨µ¼ÈëÒ»ÑùµÄÊÓÆµ £¬£¬£¬ £¬£¬¶ø¸ÃÊÓÆµÖÐÔ̺¬¶ñÒâ¾ç±¾¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±»¹Õ¹Ê¾ÁËÕâ´Î»î¶¯ÊÇÈôºÎ·Ö·¢¶ñÒâÈí¼þ £¬£¬£¬ £¬£¬ÒÔ¼°SkimmerÈôºÎÇÔȡָ±êÐÅÏ¢¡£¡£¡£¡£¡£¡£


https://unit42.paloaltonetworks.com/web-skimmer-video-distribution/


ÃÀ¹úÔÚÏßÉ̵êPulseTVй¶³¬¹ý20ÍòÓû§µÄÖ§¸¶ÐÅÏ¢


¾ÝýÌå12ÔÂ31ÈÕ±¨Â· £¬£¬£¬ £¬£¬ÃÀ¹úÔÚÏßÉ̵êPulseTVй¶³¬¹ý20ÍòÓû§µÄÖ§¸¶ÐÅÏ¢¡£¡£¡£¡£¡£¡£Æ¾¾Ý¹Ù·½Í¨Öªº¯ £¬£¬£¬ £¬£¬VISAÒÑÓÚ2021Äê3ÔÂ8ÈÕ֪ͨ¸Ã¹«Ë¾ £¬£¬£¬ £¬£¬ÆäÍøÕ¾£¨www.pulsetv.com£©¿ÉÄÜ´æÔÚÊý¾Ýй¶ÎÊÌâ¡£¡£¡£¡£¡£¡£¾­¹ý°²È«²é³­²¢Î´·¢ÏÖÈκÎй¶¼£Ï󡣡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚ7ÔÂÔÙ´ÎÊÕµ½VISA¾¯±¨ £¬£¬£¬ £¬£¬Ö±µ½11ÔÂ18ÈÕ £¬£¬£¬ £¬£¬¸ÃÍøÕ¾Òѱ»È·¶¨Îª¶àÆðMasterCardÐÅÓþ¿¨ÂòÂô»î¶¯µÄ½»µã¡£¡£¡£¡£¡£¡£PulseTVÔÚ12ÔÂ30ÈÕ֪ͨÓû§ £¬£¬£¬ £¬£¬²¢³ÆÖ»ÓÐ2019Äê11ÔÂ1ÈÕÖÁ2021Äê8ÔÂ31ÈÕʹÓÃÐÅÓþ¿¨µÄÓû§Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/pulsetv-discloses-potential-compromise-of-200-000-credit-cards/


Chosun³Æ³¯Ïʶà¸öAPT×éÖ¯ÒÑÔÚÂòÂôËùÇÔÈ¡17ÒÚÃÀÔª


ýÌå1ÔÂ2ÈÕ³Æ £¬£¬£¬ £¬£¬Ó볯ÏÊÓйصĶà¸öAPT×éÖ¯ÒÑ´ÓÂòÂôËùÇÔÈ¡¼ÛÖµÔ¼17ÒÚÃÀÔªµÄ¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£¡£CISA°µÊ¾ £¬£¬£¬ £¬£¬ÊÀ½çÉÏËùÓеÄÒøÐж¼ÒѳÉΪ³¯ÏʺڿÍÍøÂç¹¥»÷µÄÖ¸±ê¡£¡£¡£¡£¡£¡£¾ÝϤ £¬£¬£¬ £¬£¬ÕâЩ¹¥»÷ʹÓÃÃûΪAppleJeusµÄ¶ñÒâÈí¼þÇÔÈ¡¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£¡£Åí²©É簵ʾ £¬£¬£¬ £¬£¬×Ô2018ÄêÒÔÀ´ £¬£¬£¬ £¬£¬ÒÑÓÐ30¸ö¹ú¶È/µØÓòʹÓÃApple Zeus £¬£¬£¬ £¬£¬¶ø¹¥»÷ÕßÔÚ2019ÄêÖÁ2020Äê11ÔÂͨ¹ýÀûÓÃÐòÇÔÈ¡3.164ÒÚÃÀÔªµÄ¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/126225/apt/north-korea-cryptocurrency-exchanges-hacks.html


2021ÄêÃÀ¹úÒ½ÁÆÐÐÒµ10´óÎ¥¹æÊÂÎñ×ܼÆÐ¹Â¶1900ÍòÌõ


ýÌå12ÔÂ31ÈÕ±¨Â·³Æ £¬£¬£¬ £¬£¬ÃÀ¹úÎÀÉúÓ빫¼Ò·þÎñ²¿(HHS)ÒÑÔÚÆäÍøÕ¾Áгö2021ÄêÓ°Ïì×î¿í·ºµÄ10´óÎ¥¹æÊÂÎñ¡£¡£¡£¡£¡£¡£ÆäÖÐ £¬£¬£¬ £¬£¬×îÑϳÁµÄÊÇ·ðÂÞÀï´ï¶ùͯ½¡È«ÖÐÐÄ £¬£¬£¬ £¬£¬Ð¹Â¶350Íò»¼ÕßÊý¾Ý £»£»£»£»£»Æä´ÎÊÇ20/20 Eye Care NetworkÔâµ½¹¥»÷ £¬£¬£¬ £¬£¬µ¼Ö³¬¹ý320ÍòÈ˵ÄÐÅϢй©¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾ £¬£¬£¬ £¬£¬ÕâЩÊÂÎñ¹²Éæ¼°1900ÍòÈË £¬£¬£¬ £¬£¬ÆäÖдóÎÞÊýÊÇÓÉÀÕË÷¹¥»÷µ¼Öµġ£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/top-10-healthcare-breaches-in-the-us-exposed-data-of-19-million/


ESET¹«¿ª2021ÄêÖµÍ×ÌùÐĵÄÍøÂ簲ȫͳ¼ÆÊý¾ÝÁбí


ESETÔÚ12ÔÂ30ÈÕ°ä²¼µÄͳ¼Æ»ã±¨Áгö2021ÄêÖµÍ×ÌùÐĵÄÍøÂ簲ȫͳ¼ÆÊý¾Ý¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö £¬£¬£¬ £¬£¬2021ÄêÊý¾Ýй¶Ôì³ÉµÄËðʧ´Ó386ÍòÃÀÔªÉÏÉýµ½424ÍòÃÀÔª £¬£¬£¬ £¬£¬´ïµ½½ü17ÄêÒÔÀ´µÄ·åÖµ £»£»£»£»£»½ñÄêÄêÖÐ £¬£¬£¬ £¬£¬Kaseya±»SodinokibiÀÕË÷7000ÍòÃÀÔª £¬£¬£¬ £¬£¬ÕâÊÇÆù½ñΪֹ×î¸ßµÄÊê½ð½ð¶î £»£»£»£»£»2021Äê12Ô £¬£¬£¬ £¬£¬Log4ShellÅû¶ºó²»¾ÃESET¼ì²âµ½ÊýÊ®Íò´Î¹¥»÷³¢ÊÔ £¬£¬£¬ £¬£¬ÆäÖдó²¿ÃÅλÓÚÃÀ¹úºÍÓ¢¹ú¡£¡£¡£¡£¡£¡£


https://www.welivesecurity.com/2021/12/30/22-cybersecurity-statistics-know-2022/


°²È«¹¤¾ß


ExcelPeek 


ExcelPeekÄܹ»ÓÃÀ´µ÷²éDZÔÚ¶ñÒâ Microsoft Excel ÎļþµÄ¹¤¾ß¡£¡£¡£¡£¡£¡£


https://github.com/slaughterjames/excelpeek


Msmailprobe


ÓÃÓÚ Office 365 ºÍ Exchange ö¾Ù¡£¡£¡£¡£¡£¡£


https://www.kitploit.com/2022/01/msmailprobe-office-365-and-exchange.html


°²È«·ÖÎö


CVE-2021-34424£ºÐÅϢй©·ì϶


ZoomµÄMMR ·þÎñÆ÷ÖдæÔÚÐÅϢй©·ì϶¡£¡£¡£¡£¡£¡£


https://packetstormsecurity.com/files/165419/GS20220103184501.tgz


ÀûÓÃÕë¶ÔSSDµÄ¹¥»÷Ö²Èë¶ñÒâÈí¼þ


×êÑÐÈËÔ±·¢ÏÖÕë¶ÔijЩ¹Ì̬Çý¶¯Æ÷ (SSD) µÄ¹¥»÷ £¬£¬£¬ £¬£¬¿É½«¶ñÒâÈí¼þÖ²ÈëÓû§ºÍ°²È«½â¾ö¹æ»®ÎÞ·¨´¥¼°µÄµØÎ»¡£¡£¡£¡£¡£¡£


https://asec.ahnlab.com/en/29885/


Redline Stealer·ÖÎö»ã±¨


AhnLab ASEC³Æ £¬£¬£¬ £¬£¬ÔÚWebä¯ÀÀÆ÷ÉÏʹÓÃ×Ô¶¯µÇ¼ְÄܵķ½±ãÐÔÔÚ³ÉΪӰÏì×éÖ¯ºÍÓ×ÎÒ°²È«µÄ³Á´óÎÊÌâ¡£¡£¡£¡£¡£¡£


https://asec.ahnlab.com/en/29885/