·¨¹úµçÐŹ«Ë¾La Poste MobileÔâµ½LockbitµÄÀÕË÷¹¥»÷

°ä²¼¹¦·ò 2022-07-12

1¡¢·¨¹úµçÐŹ«Ë¾La Poste MobileÔâµ½LockbitµÄÀÕË÷¹¥»÷


ýÌå7ÔÂ10ÈÕ±¨Â·³Æ£¬£¬£¬£¬£¬·¨¹úµçÐÅÔËÓªÉÌLa Poste MobileÔâµ½ÁËLockbitÍÅ»ïµÄÀÕË÷¹¥»÷¡£¡£ ¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚÆäÍøÕ¾Éϰ䲼µÄÒ»·ÝÉêÃ÷ÖÐд·£¬£¬£¬£¬£¬¹¥»÷ʼÓÚ7ÔÂ4ÈÕ£¬£¬£¬£¬£¬Ó°ÏìÁËÆäÐÐÕþºÍÖÎÀí·þÎñ¡£¡£ ¡£¡£¡£¡£ËûÃÇÔÚ»ñϤ´Ë¹ýºóÁ¢¼´²ÉÈ¡±ØÒªµÄ´ëÊ©£¬£¬£¬£¬£¬¹Ø¹ØÁËÓйØÍÆËã»úϵͳ£¬£¬£¬£¬£¬Ô̺¬ÍøÕ¾ºÍ¿Í»§Çø¡£¡£ ¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬Ô±¹¤ÍÆËã»úÖеIJ¿ÃÅÎļþй¶£¬£¬£¬£¬£¬¿ÉÄÜÉæ¼°Ó×ÎÒÊý¾Ý¡£¡£ ¡£¡£¡£¡£ÉÏÖÜÎ壬£¬£¬£¬£¬LockBitÍÅ»ïÒѽ«La Poste MobileÔö³¤µ½ÆäÊý¾ÝÐ¹Â¶ÍøÕ¾¡£¡£ ¡£¡£¡£¡£


https://securityaffairs.co/wordpress/133080/cyber-crime/la-poste-mobile-ransomware.html


2¡¢ALPHVÍÅ»ïÐû³ÆÒÑÈëÇÖÈÕ±¾µÄÓÎÏ·¿¯ÐÐÉÌÍò´úÄÏÃι¬


¾ÝVGCÔÚ7ÔÂ11Èյı¨Â·£¬£¬£¬£¬£¬ALPHVÍÅ»ïÐû³ÆÒѾ­ÀÕË÷¹¥»÷ÁËÍò´úÄÏÃ鬣¨Bandai Namco£©¡£¡£ ¡£¡£¡£¡£Íò´úÄÏÃι¬ÊÇÈÕ±¾³ÛÃûµÄÓÎÏ·¿¯ÐÐÉÌ£¬£¬£¬£¬£¬ÒÔ¡¶³Ô¶¹ÈË¡·¡¢¡¶ÌúÈ­¡·ºÍ¡¶ÒõÓôÖ®»ê¡·µÅ×ÎÏ·¶øÎÅÃû¡£¡£ ¡£¡£¡£¡£¸ÃÐÂÎÅÓÉvx-undergroundÓÚ±¾ÖÜÒ»°ä²¼ÔÚTwitterÉÏ£¬£¬£¬£¬£¬Ä¿Ç°£¬£¬£¬£¬£¬VGCÒÑÁªÏµÍò´úÄÏÃι¬¶Ô´Ëʰ䷢ÆÀÂÛ¡£¡£ ¡£¡£¡£¡£ÓÎÏ·¹¤×÷ÊÒCD Projekt RedÔÚÈ¥ÄêÒ²Ôâµ½ÁËÀÕË÷¹¥»÷£¬£¬£¬£¬£¬µ¼ÖÂÈü²©Åó¿Ë2077ºÍÎ×ʦ3µÄÔ´´úÂ룬£¬£¬£¬£¬ÒÔ¼°Ô±¹¤µÄ¾ßÌåÐÅϢй¶¡£¡£ ¡£¡£¡£¡£


https://www.videogameschronicle.com/news/elden-ring-publisher-bandai-namco-reportedly-targeted-in-a-ransomware-attack/


3¡¢Emsisoft°ä²¼AstraLockerºÍYashmaµÄÃâ·Ñ½âÃÜÆ÷


¾ÝýÌå7ÔÂ8ÈÕ±¨Â·£¬£¬£¬£¬£¬ÐÂÎ÷À¼°²È«¹«Ë¾Emsisoft°ä²¼ÁËÀÕË÷Èí¼þAstraLockerºÍYashmaµÄÃâ·Ñ½âÃܹ¤¾ß¡£¡£ ¡£¡£¡£¡£Emsisoft³Æ£¬£¬£¬£¬£¬AstraLocker½âÃÜÆ÷ºÏÓÃÓÚʹÓÃ.Astra»ò.babykÀ©´óÃû²¢»ùÓÚBabukµÄ½âÃÜÆ÷£¬£¬£¬£¬£¬ËûÃÇ×ܹ²°ä²¼ÁË8¸öÃÜÔ¿£»£»£»£»£»£»£»£»Yashma½âÃÜÆ÷ºÏÓÃÓÚʹÓÃ.AstraLocker»òËæ»ú.[a-z0-9]{4}À©´óÃû²¢»ùÓÚChaosµÄ½âÃÜÆ÷£¬£¬£¬£¬£¬ËûÃÇ×ܹ²°ä²¼ÁË3¸öÃÜÔ¿¡£¡£ ¡£¡£¡£¡£Emsisoft»¹½¨Òéͨ¹ýWindowsÔ¶³Ì×ÀÃæ±»ÈëÇÖµÄϵͳ¸ü¸ÄËùÓÐÓµÓÐȨԶ³ÌµÇ¼ȨÏÞµÄÓû§µÄÍ´´¦£¬£¬£¬£¬£¬²¢ÕÒ³ö¹¥»÷Õß¿ÉÄÜÔö³¤µÄÆäËû±¾µØÕÊ»§¡£¡£ ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/free-decryptor-released-for-astralocker-yashma-ransomware-victims/


4¡¢×êÑÐÈËÔ±·¢ÏÖÐÂÀÕË÷Èí¼þ0megaÕë¶ÔÈ«ÇòÁìÓòÄÚµÄ×éÖ¯


ýÌå7ÔÂ8Èճƣ¬£¬£¬£¬£¬ÃûΪ0megaµÄÐÂÀÕË÷ÍÅ»ïÕë¶ÔÈ«ÇòÁìÓòÄÚµÄ×éÖ¯½øÐÐË«³ÁÀÕË÷¹¥»÷£¬£¬£¬£¬£¬²¢ÀÕË÷Êý°ÙÍòÃÀÔªµÄÊê½ð¡£¡£ ¡£¡£¡£¡£0mega×Ô2022Äê5ÔÂÆðÍ·»îÔ¾£¬£¬£¬£¬£¬×êÑÐÈËÔ±ÉÐδÕÒµ½ÆäÀÕË÷Èí¼þÑù±¾£¬£¬£¬£¬£¬Òò¶øÃ»ÓÐÌ«¶à¹ØÓÚÎļþÈôºÎ±»¼ÓÃܵľßÌåÐÅÏ¢¡£¡£ ¡£¡£¡£¡£¸ÃÍÅ»ïÔËÓª×ÅÒ»¸öÊý¾ÝÐ¹Â¶ÍøÕ¾£¬£¬£¬£¬£¬Ä¿Ç°ÍйÜ×Å152 GBÊý¾Ý£¬£¬£¬£¬£¬¾Ý³ÆÊÇ5ÔµĹ¥»÷»î¶¯ÖдÓÒ»¼Òµç×Óά½¨¹«Ë¾ÇÔÈ¡µÄ¡£¡£ ¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ÉÏÖÜÓÐÒ»¸ö±»¹¥»÷Ö¸±êÒѱ»´ÓÖÐÒÆ³ý£¬£¬£¬£¬£¬ÕâÅú×¢¸Ã¹«Ë¾¿ÉÄÜÒѾ­Ö§¸¶ÁËÊê½ð¡£¡£ ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-0mega-ransomware-targets-businesses-in-double-extortion-attacks/


5¡¢Fortinet°ä²¼°²È«¸üУ¬£¬£¬£¬£¬½¨¸´¶à¸ö²úÆ·Öеķì϶


ýÌå7ÔÂ9ÈÕ±¨Â·³Æ£¬£¬£¬£¬£¬Fortinet½¨¸´ÁËÆä¶à¿î²úÆ·Öеķì϶¡£¡£ ¡£¡£¡£¡£ÊÜÓ°ÏìµÄ²úÆ·Ô̺¬FortiADC¡¢FortiAnalyzer¡¢FortiManager¡¢FortiOSºÍFortiProxyµÈ¡£¡£ ¡£¡£¡£¡£Õâ´Î½¨¸´µÄ½ÏΪÑϳÁµÄÊÇFortiNACÖпÕÃÜÂëȱµã£¨CVE-2022-26117£©£¬£¬£¬£¬£¬¿ÉÓÃÀ´Í¨¹ýCLI½Ó¼ûMySQLÊý¾Ý¿â£»£»£»£»£»£»£»£»»ùÓÚ²Ö¿âµÄ»º³åÇøÒç¶Âí½Å£¨CVE-2021-43072£©£¬£¬£¬£¬£¬¿Éͨ¹ýÌØÔìµÄCLIÖ´ÐкÅÁ£»£»£»£»£»£»£»õè¾¶±éÀú·ì϶£¨CVE-2022-30302£©£¬£¬£¬£¬£¬¿Éͨ¹ýÌØÔìµÄWebÒªÇó´Óµ×²ãÎļþϵͳÖмìË÷ºÍɾ³ýËÁÒâÎļþ£»£»£»£»£»£»£»£»ÒÔ¼°Ä¿Â¼±éÀú·ì϶£¨CVE-2021-41031£©£¬£¬£¬£¬£¬¿É½«È¨ÏÞÌáÉýµ½SYSTEM¡£¡£ ¡£¡£¡£¡£


https://securityaffairs.co/wordpress/133059/security/fortinet-multiple-issues-several-products.html


6¡¢CheckmarxÅû¶CuteBoiÀûÓÃNPM°üµÄ´ó¹æÄ£ÍÚ¿ó»î¶¯


7ÔÂ6ÈÕ£¬£¬£¬£¬£¬CheckmarxÅû¶ÁËÕë¶ÔNPM JavaScript°ü´æ´¢¿âµÄÐÂÒ»ÂֵĴó¹æÄ£ÍÚ¿ó»î¶¯¡£¡£ ¡£¡£¡£¡£¸Ã»î¶¯¹éÒòÓÚ¹¥»÷ÍÅ»ïCuteBoi£¬£¬£¬£¬£¬Éæ¼°1283¸önpm°ü£¬£¬£¬£¬£¬ÕâЩ°üÄܹ»×Ô¶¯´Ó1000¶à¸ö·ÖÆçµÄÓû§ÕÊ»§Öа䲼¡£¡£ ¡£¡£¡£¡£ËùÓÐÕâЩ°ü¶¼ÓµÓÐÏÕЩһÑùµÄeazyminer°üµÄ´úÂ븱±¾£¬£¬£¬£¬£¬eazyminerÊÇXMRigµÄJS  wrapper£¬£¬£¬£¬£¬Ö¼ÔÚÀûÓÃÍÆËã»úÉÏδʹÓõÄ×ÊÔ´£¬£¬£¬£¬£¬Èçci/cdºÍweb·þÎñÆ÷¡£¡£ ¡£¡£¡£¡£×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬CuteBoiÊǽñÄêµÚ¶þ¸ö×Ô¶¯»¯¶ÔNPMÌáÒé´ó¹æÄ£¹¥»÷µÄÍŻ£¬£¬£¬£¬²¢Ô¤¼Æ½«À´½«¿´µ½¸ü¶à´ËÀ๥»÷¡£¡£ ¡£¡£¡£¡£


https://checkmarx.com/blog/cuteboi-detected-preparing-a-large-scale-crypto-mining-campaign-on-npm-users/