ÒÔÉ«ÁÐÊ×¶¼ÌØÀ­Î¬·òµÄµØÌúµÄÍøÂçÔâµ½´ó¹æÄ£¹¥»÷

°ä²¼¹¦·ò 2022-07-07

1¡¢ÒÔÉ«ÁÐÊ×¶¼ÌØÀ­Î¬·òµÄµØÌúµÄÍøÂçÔâµ½´ó¹æÄ£¹¥»÷


ÒÁÀÊ·¨¶û˹ͨѶÉ磨Fars News Agency£©7ÔÂ4ÈÕ±¨Â·³Æ £¬£¬£¬£¬£¬£¬ÒÔÉ«ÁÐÊ×¶¼ÌØÀ­Î¬·òµÄµØÌúµÄ²Ù×÷ϵͳºÍ·þÎñÆ÷Ôâµ½ÁË´ó¹æÄ£ÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¡£¸Ã»ú¹¹ºóÀ´ÓÖ³Æ £¬£¬£¬£¬£¬£¬Õâ´Î¹¥»÷ÏÖʵÉÏÊÇÕë¶ÔÒ»¼Ò²Î¼ÓÌØÀ­Î¬·òµØÌúϵͳ½¨ÉèµÄ¹«Ë¾¡£¡£¡£¡£¡£¡£¡£°ÍÀÕ˹̹×éÖ¯Sabareenͨ¹ýÆäTelegramƵ·Ðû³Æ½øÐÐÁ˹¥»÷ £¬£¬£¬£¬£¬£¬Æ¾¾Ý¸ÃÍÅ»ïµÄTelegramÖÐÆäËüµÄ±¨Â· £¬£¬£¬£¬£¬£¬ÒÁÀ­¿ËºÚ¿ÍÍÅ»ïAl-TaheraÒ²¶Ô×¼ÁËÒÔÉ«ÁÐÊý×Öµý±¨»ú¹¹¡£¡£¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/132897/hacking/tel-aviv-metro-company-attacked.html


2¡¢IT·þÎñ¹«Ë¾SHI³ÆÆäÔ⵽רҵµÄ¶ñÒâÈí¼þ¹¥»÷


¾ÝýÌå7ÔÂ6ÈÕ±¨Â· £¬£¬£¬£¬£¬£¬Î»ÓÚÐÂÔóÎ÷ÖݵÄÐÅÏ¢¼¼ÊõIT²úÆ·ºÍ·þÎñÌṩÉÌSHI International³Æ £¬£¬£¬£¬£¬£¬ÆäÔÚÉÏÖÜÄ©Ôâµ½ÁËÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¡£SHI×Ô³ÆÊDZ±ÃÀ×î´óµÄIT·þÎñ¹«Ë¾Ö®Ò» £¬£¬£¬£¬£¬£¬2021ÄêµÄÊÕÈëΪ123ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£¡£¹¥»÷²úÉúÔÚ7ÔÂ4ÈÕ £¬£¬£¬£¬£¬£¬Ö®ºóSHIÔÚÆäÍøÕ¾ÉÏÔö³¤ÁËÒ»ÌõÐÂÎÅ³Æ £¬£¬£¬£¬£¬£¬ÓÉÓÚ³ÖÐøÖÐ¶Ï £¬£¬£¬£¬£¬£¬ÆäÐÅϢϵͳÔÚ½øÐÐÊØ»¤¡£¡£¡£¡£¡£¡£¡£×Ô¹¥»÷ÒÔÀ´ £¬£¬£¬£¬£¬£¬²¿ÃÅÍøÕ¾»á·µ»ØÃýÎó¡°Amazon CloudFront/S3 SHI¡±¡£¡£¡£¡£¡£¡£¡£Îªµ÷²é´ËÊÂÎñ £¬£¬£¬£¬£¬£¬SHI½«ÆäÍøÕ¾ºÍµç×ÓÓʼþµÈϵͳ¹Ø¹Ø £¬£¬£¬£¬£¬£¬Ö±µ½ÖÜÈýÔçÉϲŸ´Ô­¡£¡£¡£¡£¡£¡£¡£SHI»¹°µÊ¾ £¬£¬£¬£¬£¬£¬Æä¹©¸øÁ´ÖеĵÚÈý·½ÏµÍ³Ã»ÓÐÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/it-services-giant-shi-hit-by-professional-malware-attack/


3¡¢×êÑÐÍŶÓÅû¶ÐÂÀÕË÷ÍÅ»ïRedAlertµÄ¹¥»÷»î¶¯µÄϸ½Ú


ýÌå7ÔÂ5ÈÕ±¨Â· £¬£¬£¬£¬£¬£¬MalwareHunterTeam·¢ÏÖÁËÒ»¸öеÄÀÕË÷ÍÅ»ïRedAlert£¨»òN13V£©¡£¡£¡£¡£¡£¡£¡£¸ÃÀÕË÷Èí¼þµÄLinux¼ÓÃÜÆ÷ÊÇÕë¶ÔVMware ESXi·þÎñÆ÷¿ª·¢µÄ £¬£¬£¬£¬£¬£¬Ö»½ÓÊÜÃÅÂÞ±Ò½øÐÐÖ§¸¶¡£¡£¡£¡£¡£¡£¡£¼ÓÃÜÎļþʱ»áÀûÓÃNTRUEncrypt¹«Ô¿¼ÓÃÜËã·¨ £¬£¬£¬£¬£¬£¬¸ÃËã·¨Ö§³ÖÌṩ·ÖÆç°²È«¼¶´ËÍâ¸÷Àà²ÎÊý¼¯ £¬£¬£¬£¬£¬£¬ÒÑÖªµÄΨÖðÒ»¸öʹÓô˼ÓÃÜËã·¨µÄÀÕË÷ÍÅ»ïÊÇFiveHands¡£¡£¡£¡£¡£¡£¡£¹ÌÈ»×êÑÐÈËÔ±Ö»ÕÒµ½ÁËÒ»¸öLinux¼ÓÃÜÆ÷ £¬£¬£¬£¬£¬£¬µ«Í¨¹ýÆäÖ§¸¶ÍøÕ¾°µ²ØµÄÔªËØÈ·¶¨Windows½âÃÜÆ÷Ò²´æÔÚ¡£¡£¡£¡£¡£¡£¡£Ä¿Ç° £¬£¬£¬£¬£¬£¬RedAlertÊý¾ÝÐ¹Â¶ÍøÕ¾½öÔ̺¬Ò»¸ö×éÖ¯µÄÊý¾Ý £¬£¬£¬£¬£¬£¬Åú×¢¸ÃÍŻK¶ÈС£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-redalert-ransomware-targets-windows-linux-vmware-esxi-servers/


4¡¢¹¥»÷ÕßÐû³ÆÒÑÇÔÈ¡ÍòºÀÔ̺¬ÐÅÓþ¿¨ÐÅÏ¢ÔÚÄÚµÄ20GBÊý¾Ý


¾ÝýÌå7ÔÂ5ÈÕ³Æ £¬£¬£¬£¬£¬£¬ÍòºÀ¼¯ÍÅÔٴα»ºÚ £¬£¬£¬£¬£¬£¬Ð¹Â¶Ô¼20 GBµÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£DataBreachesÔÚ6ÔÂ28ÈÕÊÕµ½ÁËÒ»·âÀ´×Ôδ֪·¢¼þÈ˵ÄÓʼþ £¬£¬£¬£¬£¬£¬Ö÷ÌâÊÇ¡°ÍòºÀ¾ÆµêµÄÎ¥¹æÐÐΪ£¡ºÜ³ÁÒª£¡¡±¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß³Æ £¬£¬£¬£¬£¬£¬ËûÃÇԼĪһ¸öÔÂǰÈëÇÖÁËÍòºÀ £¬£¬£¬£¬£¬£¬²¢ÇÔÈ¡ÁË20 GBµÄÊý¾Ý £¬£¬£¬£¬£¬£¬Ô̺¬ÐÅÓþ¿¨ÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£¡£¶Ô¹¥»÷ÕßÌṩµÄ¼¸¸öÎļþµÄ²é³­Åú×¢ £¬£¬£¬£¬£¬£¬ËüÃÇÀ´×ÔÂíÀïÀ¼ÖݵÄBWI»ú³¡ÍòºÀ¾Æµê£¨BWIA£©¡£¡£¡£¡£¡£¡£¡£ÍòºÀ°µÊ¾ £¬£¬£¬£¬£¬£¬Õâ´ÎÊÂÎñµÄÔ­ÒòÊÇÆäÒ»ÃûÔ±¹¤Ôâµ½ÁËÉ繤¹¥»÷ £¬£¬£¬£¬£¬£¬µ¼Ö¹¥»÷ÕßÄܹ»½Ó¼û¸ÃÔ±¹¤µÄÍÆËã»ú¡£¡£¡£¡£¡£¡£¡£


https://www.databreaches.net/exclusive-marriott-hacked-again-yes-heres-what-we-know/


5¡¢CloudSEK·¢ÏÖ¼ÙÒâ°¢ÁªÇõµ±¾ÖÖ°Äܲ¿ÃŵĴ¹µö»î¶¯


7ÔÂ4ÈÕ £¬£¬£¬£¬£¬£¬CloudSEKÅû¶Á˼ÙÒâ°¢ÁªÇõµ±¾ÖÖ°Äܲ¿ÃŵĴ¹µö»î¶¯µÄϸ½Ú¡£¡£¡£¡£¡£¡£¡£´ËÂÖ¹¥»÷ÖØÒªÕë¶Ô½ðÈÚ¡¢ÓÎÀÀ¡¢Ò½Ôº¡¢Ë¾·¨¡¢Ê¯ÓͺÍÌìÈ»ÆøÒÔ¼°Õ÷ѯÐÐÒµµÄ¸÷À൱¾ÖºÍÆóҵʵÌå¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß´´½¨ÁËÒ»¸öαÔìµÄÍøÕ¾www.mohregov-ae[.]com£¨ºÏ·¨ÍøÕ¾Îªwww[.]mohre[.]gov[.]ae£©¡£¡£¡£¡£¡£¡£¡£Í¨¹ýµ÷²é¸ÃÍøÕ¾µÄ×¢²áÐÅÏ¢ £¬£¬£¬£¬£¬£¬·¢ÏÖÁË43¸öʹÓÃÒ»Ñù×¢²áÐÅÏ¢µÄÓò £¬£¬£¬£¬£¬£¬ÕâЩÓò±»ÓÃÓÚÕë¶ÔÔÚÖж«µØÓòѰÕÒ¹¤×÷µÄÒÆÃñ¹¤È˵Ĺ¥»÷ £¬£¬£¬£¬£¬£¬ÒÔ¼°Õë¶ÔÆóÒµµÄBECÚ¿Æ­¡£¡£¡£¡£¡£¡£¡£


https://www.cloudsek.com/threatintelligence/advanced-phishing-scams-target-individuals-businesses-in-the-middle-east/


6¡¢Microsoft°ä²¼¹ØÓÚÀÕË÷Èí¼þHiveµÄ¼¼Êõ·ÖÎö»ã±¨


MicrosoftÔÚ7ÔÂ5ÈÕ°ä²¼Á˹ØÓÚÀÕË÷Èí¼þHiveµÄ¼¼Êõ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö £¬£¬£¬£¬£¬£¬HiveµÄ×îбäÖÖ½øÐÐÁ˶àÏî³Á´óÉý¼¶ £¬£¬£¬£¬£¬£¬×îÏÔÖøµÄ±ä¶¯ÊÇÔ̺¬£ºÆëÈ«µÄ´úÂëǨáãµ½ÁíÒ»ÖÖ±à³ÌÓï £¬£¬£¬£¬£¬£¬Ð±äÌåÓÉÔ­À´µÄGoLang±àдת±äΪÓÃRust±àд £¬£¬£¬£¬£¬£¬ÊǼÌBlackCatÖ®ºóµÚ¶þ¸öÓøÃ˵»°±àдµÄÀÕË÷Èí¼þ£»£»£»£»£»£»ÐµıäÌåʹÓÃÒ»Ì×·ÖÆçµÄ¼ÓÃÜËã·¨ £¬£¬£¬£¬£¬£¬ÍÖÔ²ÇúÏßDiffie-Hellmann£¨ECDH£© £¬£¬£¬£¬£¬£¬ÇÒËü²»ÊÇÔÚ¼ÓÃܵÄÿ¸öÎļþÖÐǶÈëÒ»¸ö¼ÓÃÜÃÜÔ¿ £¬£¬£¬£¬£¬£¬¶øÊÇÔÚÄÚ´æÖÐÌìÉúÁ½Ì×ÃÜÔ¿À´¼ÓÃÜÎļþ £¬£¬£¬£¬£¬£¬¶øºó½«ÕâÁ½Ì×ÃÜÔ¿¼ÓÃܲ¢Ð´ÈëËüËù¼ÓÃܵÄÇý¶¯Æ÷µÄrootÖС£¡£¡£¡£¡£¡£¡£


https://www.microsoft.com/security/blog/2022/07/05/hive-ransomware-gets-upgrades-in-rust/