CiscoÔâµ½YanluowangÍÅ»ïµÄ¹¥»÷ÇÒ2.8 GBÊý¾Ýй¶

°ä²¼¹¦·ò 2022-08-11
1¡¢CiscoÔâµ½YanluowangÍÅ»ïµÄ¹¥»÷ÇÒ2.8 GBÊý¾Ýй¶

      

¾ÝýÌå8ÔÂ10ÈÕ±¨Â·£¬£¬£¬£¬£¬ºÚ¿ÍÍÅ»ïYanluowangÔÚ½ñÄê5ÔÂÏÂÑ®ÈëÇÖÁËCisco¹«Ë¾µÄÍøÂç²¢ÇÔÈ¡ÁËÄÚ²¿Êý¾Ý¡£¡£¡£¡£¡£¡£Ciscoй©£¬£¬£¬£¬£¬¹¥»÷ÕßÖ»ÄÜ´ÓÓ뱻ϰȾԱ¹¤ÕÊ»§ÓйØÁªµÄBoxÎļþ¼ÐÖÐÇÔÈ¡Êý¾Ý£¬£¬£¬£¬£¬²¢Î´¶ÔÆäÒµÎñÔì³ÉÈκÎÓ°Ïì¡£¡£¡£¡£¡£¡£µ÷²éÏÔʾ£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚ½Ù³ÖÔ±¹¤µÄÓ×ÎÒGoogleÕÊ»§ºó£¬£¬£¬£¬£¬Ê¹Óñ»µÁÍ´´¦»ñµÃÁ˶Ô˼¿ÆÍøÂçµÄ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÐû³ÆÇÔÈ¡ÁË2.75 GBÊý¾Ý£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬Ô¼3100¸öÎļþ£¬£¬£¬£¬£¬Éæ¼°±£ÃܺÍ̸¡¢Êý¾Ýת´¢ºÍ¹¤³ÌͼֽµÈ¡£¡£¡£¡£¡£¡£Cisco»¹°µÊ¾£¬£¬£¬£¬£¬ËüÔÚ¹¥»÷¹ý³ÌÖÐûÓз¢ÏÖÀÕË÷Èí¼þµÄpayload¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/cisco-hacked-by-yanluowang-ransomware-gang-28gb-allegedly-stolen/


2¡¢PyPI´æ´¢¿âÖеÄ10¸ö¶ñÒâPython°ü¿ÉÇÔÈ¡¿ª·¢ÈËԱʹ´¦

      

¾Ý8ÔÂ9ÈÕ±¨Â·£¬£¬£¬£¬£¬Check Point×êÑÐÈËÔ±ÔÚPyPI´æ´¢¿âÖз¢ÏÖÁË10¸ö¶ñÒâPython°ü¡£¡£¡£¡£¡£¡£ÕâЩ¶ñÒâ°üʹÓÃαÔìµÄÓòÃûÀ´¼ÙÒâÊ¢ÐеÄÏîÄ¿²¢ÓÕʹָ±êÏÂÔØËüÃÇ£¬£¬£¬£¬£¬¶øºó×°ÖÃÐÅÏ¢ÇÔÈ¡·¨Ê½£¬£¬£¬£¬£¬Ö¼ÔÚÇÔÈ¡¿ª·¢ÈËÔ±µÄÓ×ÎÒÊý¾ÝºÍÍ´´¦¡£¡£¡£¡£¡£¡£¶ñÒâPyPi°ü±ðÀëΪAscii2text¡¢Pyg-utils¡¢Pymocks¡¢PyProto2¡¢Test-async¡¢Free-net-vpn¡¢Free-net-vpn2¡¢Zlibsrc¡¢BrowserdivºÍWINRPCexploit¡£¡£¡£¡£¡£¡£Ö»¹ÜÈí¼þ°üÒÑ´ÓPyPIÖÐɾ³ý£¬£¬£¬£¬£¬µ«ÒÑÏÂÔØËüÃǵĿª·¢ÈËÔ±ÈÔÃæ¶Ô·çÏÕ¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2022/08/10-credential-stealing-python-libraries.html


3¡¢LockBitÍŻ﹥»÷°¢¸ùÍ¢ÎÀÉú·þÎñÍøÕ¾²¢ÀÕË÷30ÍòÃÀÔª

      

ýÌå8ÔÂ9Èճƣ¬£¬£¬£¬£¬LockBitÍŻ﹥»÷Á˰¢¸ùÍ¢µÄOSDE¡£¡£¡£¡£¡£¡£OSDEÊǰ¢¸ùÍ¢µÄÒ½ÁÆ·þÎñºÍ¹©¸øÉÌÍøÂ磬£¬£¬£¬£¬Ä¿Ç°Õ¼Óг¬¹ý200Íò»áÔ±¡¢8000¶à¼ÒÒ©µêºÍ½ü400¸öÖÐÐÄ¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬Õâ´Î¹¥»÷µ¼ÖÂOSDEÔÚ¼¸¸öÓ×ʱÄÚÎÞ·¨Ê¹Óᣡ£¡£¡£¡£¡£OSDEÔÚ6ÔÂ27ÈÕÈÏ¿ÉÁËÕâ´Î¹¥»÷£¬£¬£¬£¬£¬µ«Ã»ÓÐÈ·ÈÏÕâÊÇһ·ÀÕË÷¹¥»÷ÊÂÎñ¡£¡£¡£¡£¡£¡£7ÔÂ22ÈÕ£¬£¬£¬£¬£¬LockBit½«OSDEÔö³¤µ½ÆäÊý¾ÝÐ¹Â¶ÍøÕ¾£¬£¬£¬£¬£¬²¢ÀÕË÷300000ÃÀÔªÀ´²É°ì»òɾ³ýËùÓб»µÁÊý¾Ý£¬£¬£¬£¬£¬½ØÖ¹ÈÕÆÚΪ8ÔÂ6ÈÕ¡£¡£¡£¡£¡£¡£8ÔÂ8ÈÕ£¬£¬£¬£¬£¬LockBit»Ø¸´ÁËDataBreachesµÄѯÎÊ£¬£¬£¬£¬£¬³ÆÆäÇÔÈ¡ÁË139.07 GBÎļþ¡£¡£¡£¡£¡£¡£


https://www.databreaches.net/argentinian-health-services-plan-hit-by-lockbit/


4¡¢CybleÅû¶ÀûÓÃľÂí»¯Signal·Ö·¢DracarysµÄ»î¶¯ÏêÇé

      

CybleÔÚ8ÔÂ9ÈÕÅû¶ÁËBitter APTÀûÓÃľÂí»¯Signal·Ö·¢Android¼äµýÈí¼þDracarysµÄ»î¶¯¡£¡£¡£¡£¡£¡£¸Ã»î¶¯ÖØÒªÕë¶ÔÐÂÎ÷À¼¡¢Ó¡¶È¡¢°Í»ù˹̹ºÍÓ¢¹ú£¬£¬£¬£¬£¬Ê¹ÓÃÁËÓòÃûsignalpremium[.]comÀ´·Ö·¢Ä¾Âí»¯µÄÀûÓᣡ£¡£¡£¡£¡£ÓÉÓÚSignalµÄÔ´´úÂëÊÇ¿ªÔ´µÄ£¬£¬£¬£¬£¬Òò¶ø¹¥»÷ÕßÄܹ»±àÒë³öÓµÓг£ÓøöÐÔºÍÔ¤ÆÚÖ°Äܵİ汾£¬£¬£¬£¬£¬»¹ÔÚ±àÒëʱ½«DracarysÔö³¤µ½ÁËÔ´´úÂëÖС£¡£¡£¡£¡£¡£Æô¶¯Ê±£¬£¬£¬£¬£¬Dracarys½«Ïνӵ½Firebase·þÎñÆ÷À´½Ó¹ÜºÅÁ£¬£¬£¬£¬¶øºó½«ÇÔÈ¡µÄÊý¾ÝÉÏ´«µ½C2¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/hackers-install-dracarys-android-malware-using-modified-signal-app/


5¡¢UnRARÖÐõè¾¶±éÀú·ì϶CVE-2022-30333Òѱ»»ý¼«ÀûÓÃ

      

ýÌå8ÔÂ9ÈÕ±¨Â·³Æ£¬£¬£¬£¬£¬LinuxºÍUnixϵͳµÄUnRARÖеÄõè¾¶±éÀú·ì϶£¨CVE-2022-30333£©¿ÉÄÜÒѱ»ÔÚÒ°ÀûÓᣡ£¡£¡£¡£¡£¸Ã·ì϶ÓÚ6ÔÂÏÂÑ®±»Åû¶£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÀûÓÃËüÔÚ½âѹ²Ù×÷ÆÚ¼ä½«¶ñÒâÎļþÌáÈ¡µ½ËÁÒâµØÎ»£¬£¬£¬£¬£¬´Ó¶øÔÚÖ¸±êϵͳÉÏ×°ÖöñÒâÎļþ£¬£¬£¬£¬£¬CISAÔÚ±¾Öܶþ½«ÆäÔö³¤µ½ÆäÒѱ»ÀûÓ÷ì϶Ŀ¼ÖС£¡£¡£¡£¡£¡£¹ØÓÚ¹¥»÷µÄÐÔÖÊÖªÖ®ÉõÉÙ£¬£¬£¬£¬£¬µ«Õâ´ÎÅû¶֤ÁËȻһÖÖÈÕÒæÔö³¤µÄÇ÷Ïò£¬£¬£¬£¬£¬¼´¹¥»÷ÕßÔÚ·ì϶±»¹«¿ªºóѸËÙɨÃèÒ×Êܹ¥»÷µÄϵͳ£¬£¬£¬£¬£¬²¢½è´Ë»úÓöÌáÒé¹¥»÷¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2022/08/cisa-issues-warning-on-active.html


6¡¢Kaspersky³ÆÀÕË÷Èí¼þMauiÓ볯ÏÊÍÅ»ïAndarielÓйØ

      

8ÔÂ9ÈÕ£¬£¬£¬£¬£¬Kaspersky°ä²¼Á˹ØÓÚAndariel·Ö·¢DTrackºÍMauiÀÕË÷Èí¼þµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£Andariel£¨±ðÃûStonefly£©ÖÁÉÙ´Ó2015ÄêÆðÍ·»îÔ¾£¬£¬£¬£¬£¬¶øMauiÓÚ2021Äê4ÔÂÆðÍ·»îÔ¾¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬ÈÕ±¾Ôâµ½Maui¹¥»÷µÄÖ¸±êÔÚ±»¼ÓÃÜǰ¼¸¸öÓ±¾Ç®ÍÔâµ½ÁËDTrackµÄ¹¥»÷£¬£¬£¬£¬£¬¶øËæºóµÄÈÕÖ¾·ÖÎöÏÔʾ£¬£¬£¬£¬£¬¼¸¸öÔÂǰ¸Ã¹«Ë¾µÄÍøÂçÖоʹæÔÚ3Proxy¡£¡£¡£¡£¡£¡£3ProxyÊÇAndariel´ÓǰµÄ»î¶¯ÖÐʹÓõÄÃâ·Ñ¿ªÔ´´úÀí·þÎñÆ÷·¨Ê½£¬£¬£¬£¬£¬¶ø¹¥»÷ʹÓõÄDTrack±äÌåÓëAndarielÓйصÄÑù±¾ÓµÓÐ84%µÄ´úÂëÀàËÆÐÔ¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÕâЩ¹¥»÷ÖгõÊ¼ÍøÂç¹¥»÷²½Ö軹ӵÓеäÐ͵ÄAndarielÌØµã¡£¡£¡£¡£¡£¡£


https://securelist.com/andariel-deploys-dtrack-and-maui-ransomware/107063/