T-MobileÒòÈ¥ÄêÊý¾Ýй¶ÊÂÎñÅâ³¥ÆäÓû§3.5ÒÚÃÀÔª

°ä²¼¹¦·ò 2022-07-26

1¡¢T-MobileÒòÈ¥ÄêÊý¾Ýй¶ÊÂÎñÅâ³¥ÆäÓû§3.5ÒÚÃÀÔª

      

¾Ý7ÔÂ24ÈÕ±¨Â·£¬£¬£¬ £¬ £¬£¬£¬T-MobileÒÑÔÞ³ÉÏò½ü7700ÍòÓû§Å⸶3.5ÒÚÃÀÔª£¬£¬£¬ £¬ £¬£¬£¬ÒÔ½â¾ö¹ØÓڸù«Ë¾2021ÄêÊý¾Ýй¶ÊÂÎñµÄ¼¯ÌåËßËÏ ¡£¡£¡£¡£¡£¡£¡£¡£È¥Äê8Ô·ݣ¬£¬£¬ £¬ £¬£¬£¬¸Ã¹«Ë¾µÄϵͳÔâµ½ºÚ¿ÍÈëÇÖ£¬£¬£¬ £¬ £¬£¬£¬Óû§µÄÉç»á°²È«ºÅÂë¡¢ÐÕÃû¡¢µØÖ·ºÍ¼ÝÊ»ÅÆÕÕµÈÐÅϢй¶ ¡£¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝÉÏÖÜÎåµÄÎļþ£¬£¬£¬ £¬ £¬£¬£¬3.5×ʽð½«ÓÃÓÚÖ§¸¶ÊÜÓ°ÏìÓû§µÄË÷Åâ¡¢Ô­¸æÂÉʦµÄ˾·¨ÓöÈÒÔ¼°ÖÎÀíºÍ½âµÄÓÃ¶È ¡£¡£¡£¡£¡£¡£¡£¡£T-Mobile»¹°µÊ¾½«ÔÚ2022ÄêºÍ2023ÄêÆÆ·Ñ1.5ÒÚÃÀÔªÀ´¼ÓÇ¿ÆäÊý¾Ý°²È«ºÍÆäËü¼¼Êõ ¡£¡£¡£¡£¡£¡£¡£¡£


https://www.securityweek.com/t-mobile-settles-pay-350m-customers-data-breach


2¡¢ÀÕË÷ÍÅ»ïLockBitÐû³ÆÒÑÇÔÈ¡Òâ´óÀû˰Îñ»ú¹¹78 GBÊý¾Ý

      

ýÌå7ÔÂ25ÈÕ±¨Â·£¬£¬£¬ £¬ £¬£¬£¬Òâ´óÀûÔÚµ÷²éÆä˰Îñ»ú¹ØÔâµ½ÀÕË÷¹¥»÷µÄÊÂÎñ ¡£¡£¡£¡£¡£¡£¡£¡£ÉÏÖÜÄ©£¬£¬£¬ £¬ £¬£¬£¬LockBit½«¸Ã»ú¹¹Ôö³¤µ½ÆäÊý¾ÝÐ¹Â¶ÍøÕ¾£¬£¬£¬ £¬ £¬£¬£¬Ðû³ÆÒÑÇÔÈ¡78 GBÊý¾Ý£¬£¬£¬ £¬ £¬£¬£¬²¢¸øÁ˸ûú¹¹Ô¼Äª6ÌìµÄ¹¦·ò×ö³ö»ØÓ¦ ¡£¡£¡£¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬ £¬ £¬£¬£¬¸ÃÍŻォ½ØÖ¹ÈÕÆÚµ¢¸éÖÁ8ÔÂ1ÈÕ£¬£¬£¬ £¬ £¬£¬£¬²¢Ðû³ÆÆäÒÑ»ñµÃ100 GBÊý¾Ý ¡£¡£¡£¡£¡£¡£¡£¡£L'Agenzia delle EntrateÔÚÖÜÒ»°ä·¢ÉêÃ÷³Æ£¬£¬£¬ £¬ £¬£¬£¬ËüÒªÇ󾭼úͲÆÕþ²¿µÄIT¹«Ë¾Sogeiµ÷²éÕâÆðËùνµÄÀÕË÷¹¥»÷ÊÂÎñ ¡£¡£¡£¡£¡£¡£¡£¡£ 

 

https://therecord.media/italy-investigating-ransomware-attack-on-tax-agency/


3¡¢Î¢Èí³Æ7Ô·ÝWindows¸üпÉÄܵ¼Ö´òÓ¡Ö°ÄܳöÏÖÎÊÌâ


7ÔÂ22ÈÕ±¨Â·£¬£¬£¬ £¬ £¬£¬£¬Î¢Èí°µÊ¾´Ó±¾ÖܵĿÉѡԤÀÀ¸üÐÂÆðÍ·£¬£¬£¬ £¬ £¬£¬£¬Ò»ÄêǰΪ½â¾öWindows ServerÔÚ²»¼æÈÝÉ豸ÉÏ´òÓ¡ÎÊÌâ¶øÌṩµÄһʱ»º½â´ëÊ©½«±»ÒƳý£¬£¬£¬ £¬ £¬£¬£¬Õâ¿ÉÄܻᵼÖ´òÓ¡Ö°ÄܳöÏÖÎÊÌâ ¡£¡£¡£¡£¡£¡£¡£¡£Î¢ÈíÚ¹Êͳƣ¬£¬£¬ £¬ £¬£¬£¬ÊÜÓ°ÏìµÄÉ豸Ô̺¬ÖÇÄÜ¿¨Éí·ÝÑéÖ¤´òÓ¡»ú¡¢É¨ÃèÒǺͶàÖ°ÄÜÉ豸£¬£¬£¬ £¬ £¬£¬£¬ËüÃÇÔÚPKINIT KerberosÈÏÖ¤ÆÚ¼ä²»Ö§³ÖDHÃÜÔ¿»¥»»£¬£¬£¬ £¬ £¬£¬£¬»òÕßÔÚKerberos ASÒªÇóÆÚ¼ä²»Ö§³ÖÈý³ÁDES ¡£¡£¡£¡£¡£¡£¡£¡£Óû§±ØÒª¸üкϹæ»ò¸ü»»²»ºÏ¹æµÄÉ豸 ¡£¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-that-new-windows-updates-may-break-printing/


4¡¢ÎÚ¿ËÀ¼¹ã²¥¹«Ë¾TAVR Media±»¹¥»÷²¢´«²¼ÐéαÐÅÏ¢

      

ýÌå7ÔÂ22Èճƣ¬£¬£¬ £¬ £¬£¬£¬ÎÚ¿ËÀ¼¹ã²¥¹«Ë¾TAVR MediaÔâµ½¹¥»÷£¬£¬£¬ £¬ £¬£¬£¬²¢´«²¼×ÜͳVolodymyr Zelenskyy²¡³ÁµÄÐéαÐÅÏ¢ ¡£¡£¡£¡£¡£¡£¡£¡£Õâ¼Ò¹«Ë¾ÔËÓª×ÅÎÚ¿ËÀ¼µÄ9¸öÖØÒªµÄ¹ã²¥µç̨£¬£¬£¬ £¬ £¬£¬£¬Ô̺¬Hit FM¡¢Radio ROKS¡¢KISS FMºÍRadio RELAXµÈ ¡£¡£¡£¡£¡£¡£¡£¡£ÎÚ¿ËÀ¼¹ú¶ÈÌØÊâͨѶºÍÐÅÏ¢±£»£»£»£»£»£»¤¾Ö£¨SSCIP£©³Æ£¬£¬£¬ £¬ £¬£¬£¬¹¥»÷Õß·ÛËéÁËTAVR MediaµÄ·þÎñÆ÷ºÍ¹ã²¥ÏµÍ³À´°ä²¼ÐéαÐÂÎÅ£¬£¬£¬ £¬ £¬£¬£¬ËûÃÇÔÚÖÂÁ¦½â¾ö¸ÃÎÊÌâ ¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬ £¬ £¬£¬£¬¹¥»÷µÄÆðÔ´Éв»Ã÷ÏÔ ¡£¡£¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2022/07/ukrainian-radio-stations-hacked-to.html


5¡¢TA4563ÀûÓúóÃÅEvilNum¹¥»÷Å·Ö޵ĽðÈÚºÍͶ×ÊÐÐÒµ

      

ProofpointÔÚ7ÔÂ21ÈÕÅû¶ÁËTA4563ÀûÓù¥»÷Å·Ö޵ĽðÈÚºÍͶ×ÊÐÐÒµµÄ»î¶¯µÄÏêÇé ¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î»î¶¯Ê¼ÓÚ2021Äêµ×£¬£¬£¬ £¬ £¬£¬£¬ÀûÓÃÁ˶ñÒâÈí¼þEvilNum£¬£¬£¬ £¬ £¬£¬£¬ÖØÒªÕë¶ÔÖ§³Ö±í»ã¡¢¼ÓÃÜÇ®±ÒºÍÈ¥ÖÐÐÄ»¯½ðÈÚ(DeFi)ÒµÎñµÄʵÌå ¡£¡£¡£¡£¡£¡£¡£¡£EvilNumÊÇÒ»¸öºóÃÅ£¬£¬£¬ £¬ £¬£¬£¬¿ÉÇÔÈ¡Êý¾Ý»ò¼ÓÔØ¶î±íµÄpayload ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÔ̺¬¶à¸öÓÐȤµÄ×é¼þ£¬£¬£¬ £¬ £¬£¬£¬¿ÉÓÃÓÚÈÆ¹ý¼ì²â²¢Æ¾¾ÝÒÑʶ´ËÍâɱ¶¾Èí¼þÅú¸ÄϰȾõè¾¶ ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã»î¶¯ÓëZscalerÔÚ2022Äê6Ô¹«¿ªµÄEvilNum»î¶¯Óв¿ÃųÁµþ ¡£¡£¡£¡£¡£¡£¡£¡£


https://www.proofpoint.com/us/blog/threat-insight/buy-sell-steal-evilnum-targets-cryptocurrency-forex-commodities


6¡¢ASEC·¢ÏÖͨ¹ýISOÎļþ·Ö·¢¶ñÒâÈí¼þIcedIDµÄ»î¶¯

      

7ÔÂ25ÈÕ£¬£¬£¬ £¬ £¬£¬£¬ASEC°ä²¼Á˹ØÓÚͨ¹ýISOÎļþ·Ö·¢IcedIDµÄ»î¶¯µÄ·ÖÎö»ã±¨ ¡£¡£¡£¡£¡£¡£¡£¡£»ã±¨½éÉÜÁËÁ½ÖÖ·Ö·¢·½Ê½£¬£¬£¬ £¬ £¬£¬£¬µÚÒ»ÖÖÊÇÀûÓõç×ÓÓʼþ½Ù³Ö¼¼ÊõÀ´½Ù³ÖÕý³£Óʲ¢ÏòÓû§·¢ËÍ´øÓжñÒ⸽¼þµÄ»Ø¸´£¬£¬£¬ £¬ £¬£¬£¬¸ÃÎļþ±»Ñ¹Ëõ£¬£¬£¬ £¬ £¬£¬£¬ÆäÖÐÔ̺¬Ò»¸öISOÎļþ ¡£¡£¡£¡£¡£¡£¡£¡£ÔËÐÐISOÎļþ»áÔÚDVDÇý¶¯Æ÷Öд´½¨Ò»¸ölnkºÍÒ»¸öDLLÎļþ£¬£¬£¬ £¬ £¬£¬£¬²¢Í¨¹ýlnkÎļþ¼ÓÔØDLL£¬£¬£¬ £¬ £¬£¬£¬¼ÓÔØµÄDLL¾ÍÊÇIcedID ¡£¡£¡£¡£¡£¡£¡£¡£µÚ¶þÖÖISOÎļþÖгýÁËlnkºÍDLLÖ®±í»¹ÓÐÆäËüÎļþ£¬£¬£¬ £¬ £¬£¬£¬lnkÎļþÔËÐÐÎļþ¼ÐthemÄÚµÄworker.cmd£¬£¬£¬ £¬ £¬£¬£¬Ö®ºóÔËÐÐworker.js ¡£¡£¡£¡£¡£¡£¡£¡£worker.jsͨ¹ýrundll32.exe½«then.dat¼ÓÔØµ½Í³Ò»Îļþ¼ÐÖУ¬£¬£¬ £¬ £¬£¬£¬then.datÊÇÒ»¸öDLL£¨IcedID£© ¡£¡£¡£¡£¡£¡£¡£¡£


https://asec.ahnlab.com/en/37005/