Pendragon»Ø¾øLockBitÍÅ»ï6000ÍòÃÀÔªµÄÊê½ðÒªÇó

°ä²¼¹¦·ò 2022-10-26
1¡¢Pendragon»Ø¾øLockBitÍÅ»ï6000ÍòÃÀÔªµÄÊê½ðÒªÇó

      

ýÌå10ÔÂ24Èճƣ¬ £¬£¬£¬£¬£¬£¬Ó¢¹úÆû³µ¾­ÏúÉÌPendragon GroupÔâµ½LockBitµÄÀÕË÷¹¥»÷¡£¡£¡£¡£ ¡£¡£¸Ã¹«Ë¾°µÊ¾£¬ £¬£¬£¬£¬£¬£¬¹¥»÷²úÉúÔÚԼĪһ¸öÔÂǰ£¬ £¬£¬£¬£¬£¬£¬Î´Ó°ÏìÆäÕý³£ÔËÓª£¬ £¬£¬£¬£¬£¬£¬ËûÃÇÒ»ÏòÔÚÓëºÚ¿ÍÁªÏµ£¬ £¬£¬£¬£¬£¬£¬²¢ÊÕµ½Á˱»µÁÎļþ×÷Ϊ¹¥»÷µÄÖ¤¾Ý£¬ £¬£¬£¬£¬£¬£¬µ«Ã»ÓнøÐн»Éæ¡£¡£¡£¡£ ¡£¡£¾ÝÓ¢¹úýÌ峯£¬ £¬£¬£¬£¬£¬£¬LockBitÒªÇó6000ÍòÃÀÔªÊê½ð£¬ £¬£¬£¬£¬£¬£¬¶øPendragon½²»°È˰µÊ¾ËûÃǶÔÖŲ»ÏòºÚ¿Í¸¶¿îµÄ¾ö¶¨¡£¡£¡£¡£ ¡£¡£Pendragon»¹³ÎÇå·£¬ £¬£¬£¬£¬£¬£¬ÆäITÍŶÓÔÚÔâµ½¹¥»÷ºóÁ¢¼´×ö³öÁË·´Ó³£¬ £¬£¬£¬£¬£¬£¬µ÷²éÏÔʾºÚ¿Í½öÇÔÈ¡ÁË5%µÄÊý¾Ý¿â¡£¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/pendragon-car-dealer-refuses-60-million-lockbit-ransomware-demand/


2¡¢CiscoÌáÐÑAnyConnectÖеÄÁ½¸ö·ì϶Õý±»¿í·ºÀûÓÃ

      

CiscoÔÚ10ÔÂ25ÈÕÌáÐѿͻ§£¬ £¬£¬£¬£¬£¬£¬ºÏÓÃÓÚWindowsµÄCisco AnyConnect°²È«Òƶ¯¿Í»§¶ËÖеÄÁ½¸ö·ì϶Õý±»¿í·ºÀûÓᣡ£¡£¡£ ¡£¡£ÕâЩ·ì϶£¨CVE-2020-3433ºÍCVE-2020-3153£©¿É±»±¾µØ¹¥»÷ÕßÓÃÀ´Ö´ÐÐDLL½Ù³Ö¹¥»÷²¢½«Îļþ¸´Ôìµ½ÓµÓÐϵͳ¼¶È¨ÏÞµÄϵͳĿ¼¡£¡£¡£¡£ ¡£¡£³É¹¦ÀûÓÃºó£¬ £¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÔÚÓµÓÐϵͳȨÏÞµÄÖ¸±êÉ豸ÉÏÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£ ¡£¡£¸Ã¹«Ë¾³Æ£¬ £¬£¬£¬£¬£¬£¬ÔÚ2022Äê10Ô£¬ £¬£¬£¬£¬£¬£¬Æä·¢ÏÖÓÐÈËÊÔIJÀûÓô˷ì϶£¬ £¬£¬£¬£¬£¬£¬²¢Ç¿ÁÒ½¨Òé¿Í»§Éý¼¶¡£¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/cisco-warns-admins-to-patch-anyconnect-flaw-exploited-in-attacks/


3¡¢ÎÚ¿ËÀ¼¾ÍCubaÍÅ»ïÕë¶ÔÆä¹Ø¼ü»ù´¡ÉèÊ©µÄ¹¥»÷·¢³ö¾¯±¨

      

¾Ý10ÔÂ24ÈÕ±¨Â·£¬ £¬£¬£¬£¬£¬£¬ÎÚ¿ËÀ¼ÍÆËã»úÓ¦¼±ÏìÓ¦Ó××é(CERT-UA)ÒѾÍÀÕË÷ÍÅ»ïCuba¶ÔÆä¹Ø¼ü¼ü»ù´¡ÉèÊ©µÄ¹¥»÷·¢³ö¾¯±¨¡£¡£¡£¡£ ¡£¡£´Ó10ÔÂ21ÈÕÆðÍ·£¬ £¬£¬£¬£¬£¬£¬CERT-UA¾Í¼ì²âµ½ÐÂÒ»²¨´¹µöÓʼþ£¬ £¬£¬£¬£¬£¬£¬¼ÙÒâÁËÎÚ¿ËÀ¼Îä×°¶ÓÁÐ×ÜÕÕ·÷²¿ÐÂÎÅ·þÎñ²¿£¬ £¬£¬£¬£¬£¬£¬ÓÕʹÊÕ¼þÈ˵ã»÷ÆäÖеÄǶÈëʽÁ´½Ó£¬ £¬£¬£¬£¬£¬£¬×îÖÕ»á×°ÖÃROMCOM RAT¡£¡£¡£¡£ ¡£¡£¸Ã»ú¹¹°µÊ¾£¬ £¬£¬£¬£¬£¬£¬Ë¼¿¼µ½RomComºóÃŵÄʹÓÃÒÔ¼°ÓйØÎļþµÄÆäËûÌØµã£¬ £¬£¬£¬£¬£¬£¬´§Ä¦Õâ´Î»î¶¯ÓëTropical Scorpius(UNC2596)Óйأ¬ £¬£¬£¬£¬£¬£¬¸ÃÍÅ»ïÕÆ¹Ü·Ö·¢CubaÀÕË÷Èí¼þ¡£¡£¡£¡£ ¡£¡£


https://securityaffairs.co/wordpress/137567/cyber-warfare-2/cuba-ransomware-cert-ua.html


4¡¢Ðµĸæ°×»î¶¯Dormant Colors·Ö·¢¶ñÒâChromeÀ©´ó

      

10ÔÂ23ÈÕ£¬ £¬£¬£¬£¬£¬£¬Guardio LabsÅû¶ÁËÐÂÒ»ÂֵĶñÒâ¸æ°×»î¶¯Dormant Colors¡£¡£¡£¡£ ¡£¡£µ½2022Äê10ÔÂÖÐÑ®£¬ £¬£¬£¬£¬£¬£¬ÔÚChromeºÍEdgeÍøÂçÉ̵êÖж¼ÓÐ30¸öä¯ÀÀÆ÷À©´óµÄ±äÖÖ£¬ £¬£¬£¬£¬£¬£¬ÀۼƳ¬¹ý100ÍòµÄ×°ÖÃÁ¿¡£¡£¡£¡£ ¡£¡£¸Ã»î¶¯µÄÖ÷ÌâÓëÉ«²ÊÓйأ¬ £¬£¬£¬£¬£¬£¬Ê¼ÓÚ¶ñÒâ¸æ°×»î¶¯£¬ £¬£¬£¬£¬£¬£¬ÒÔÐÂÏʵIJ½ÖèÔÚûÈ˰ÑÎȵÄÇé¿öϲà¼ÓÔØÕæÕýµÄ¶ñÒâ´úÂë¡£¡£¡£¡£ ¡£¡£×îºó£¬ £¬£¬£¬£¬£¬£¬²»½öÇÔȡָ±êËÑË÷ºÍä¯ÀÀÊý¾Ý£¬ £¬£¬£¬£¬£¬£¬²¢Îª10000¸öÍøÕ¾ÒýÁ÷£¬ £¬£¬£¬£¬£¬£¬Óû§ÔÚÕâÐ©ÍøÕ¾ÉϽøÐеÄÈκβɰìÐÐΪ³ÇÊÐΪ¹¥»÷Õß´øÀ´Ó¶½ð¡£¡£¡£¡£ ¡£¡£


https://guardiosecurity.medium.com/dormant-colors-live-campaign-with-over-1m-data-stealing-extensions-installed-9a9a459b5849


5¡¢SideWinderÀûÓÃкóÃÅWarHawk¹¥»÷°Í»ù˹̹µÄ×éÖ¯

      

¾ÝýÌå10ÔÂ24ÈÕ±¨Â·£¬ £¬£¬£¬£¬£¬£¬ZscalerÅû¶Á˺ڿÍÍÅ»ïSideWinderµÄкóÃÅWarHawk¡£¡£¡£¡£ ¡£¡£SideWinderÒÉËÆÓëÓ¡¶Å×йأ¬ £¬£¬£¬£¬£¬£¬×Ô2012ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬ £¬£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÑÇÖÞµÝÈ¥£¬ £¬£¬£¬£¬£¬£¬ÓÈÆäÊǰͻù˹̹ȷµ±¾Ö¡¢¾ü¶ÓºÍÆóÒµ×éÖ¯¡£¡£¡£¡£ ¡£¡£½ñÄê9Ô£¬ £¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±ÔÚ°Í»ù˹̹¹ú¶ÈµçÁ¦¼à¹Ü¾ÖµÄºÏ·¨ÍøÕ¾nepra[.]org[.]pk·¢ÏÖÒ»¸ö±øÆ÷»¯ISOÎļþ£¬ £¬£¬£¬£¬£¬£¬À´¼¤»îÓÃÀ´×°ÖÃWarHawkµÄkillchain¡£¡£¡£¡£ ¡£¡£WarHawkÔò¼Ù×°³ÉASUS Update SetupºÍRealtek HD Audio ManagerµÈºÏ·¨ÀûÓ㬠£¬£¬£¬£¬£¬£¬Ëü·Ö·¢Cobalt Strike×÷Ϊ×îÖÕpayload¡£¡£¡£¡£ ¡£¡£


https://thehackernews.com/2022/10/sidewinder-apt-using-new-warhawk.html


6¡¢¹¹Öþ¹«Ë¾InterserveÒòÔâµ½ÀÕË÷¹¥»÷±»·£¿£¿£¿£¿£¿£¿£¿î440ÍòÓ¢°÷


10ÔÂ24ÈÕ±¨Â·³Æ£¬ £¬£¬£¬£¬£¬£¬Ó¢¹ú¹¹Öþ¹«Ë¾InterserveÒòÀÕË÷¹¥»÷й¶113000ÃûÔ±¹¤µÄÊý¾Ý£¬ £¬£¬£¬£¬£¬£¬±»Ó¢¹úÊý¾Ý±£»£»£»£»£»£»¤¼à¹Ü»ú¹¹·£¿£¿£¿£¿£¿£¿£¿î440ÍòÓ¢°÷¡£¡£¡£¡£ ¡£¡£ÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©°µÊ¾£¬ £¬£¬£¬£¬£¬£¬Interserve GroupδÄܲÉÈ¡Êʵ±µÄ°²È«´ëÊ©À´·À±¸ÍøÂç¹¥»÷¡£¡£¡£¡£ ¡£¡£ICOÚ¹ÊÍ·£¬ £¬£¬£¬£¬£¬£¬¹¥»÷ʼÓÚ´¹µöÓʼþ£¬ £¬£¬£¬£¬£¬£¬Ä³Ô±¹¤´ò¿ªºóÎÞÒâÖÐÏÂÔØÁ˶ñÒâÈí¼þ£¬ £¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾µÄAVÈí¼þÒÑ·¢Ë;¯±¨¡£¡£¡£¡£ ¡£¡£µ«ºóÐøµ÷²é²»¹»³¹µ×£¬ £¬£¬£¬£¬£¬£¬µ¼Ö¹¥»÷Õß½Ó¼ûÁË283¸öϵͳºÍ16¸öÕË»§£¬ £¬£¬£¬£¬£¬£¬²¢Ð¶ÔØÁ˹«Ë¾µÄAVÈí¼þ¡£¡£¡£¡£ ¡£¡£Interserve ÒѾͷ£¿£¿£¿£¿£¿£¿£¿îÏòICOÌá³öÉÏËߣ¬ £¬£¬£¬£¬£¬£¬µ«×îÖÕ·£¿£¿£¿£¿£¿£¿£¿î²¢Î´Ï÷¼õ¡£¡£¡£¡£ ¡£¡£


https://therecord.media/british-company-fined-4-4-million-over-ransomware-attack/