ÃÀ¹úÊý°Ù¸öÐÂÎÅÍøÕ¾Ôâµ½¹©¸øÁ´¹¥»÷²¢×°ÖÃSocGholish
°ä²¼¹¦·ò 2022-11-04
ýÌå11ÔÂ2Èճƣ¬£¬£¬£¬£¬£¬£¬TA569ÍÅ»ïÀûÓÃijýÌ幫˾±»ÈëÇֵĻù´¡ÉèÊ©£¬£¬£¬£¬£¬£¬£¬ÔÚÃÀ¹ú250¶à¼ÒÐÂÎÅýÌåµÄÍøÕ¾ÉÏ×°ÖÃSocGholish JavaScript¶ñÒâÈí¼þ¿ò¼Ü£¨Ò²³ÆÎªFakeUpdates£©¡£¡£¡£¡£¡£¹¥»÷ÕßÊ×ÏȽ«¶ñÒâ´úÂë×¢Èëµ½ÍøÕ¾¼ÓÔØµÄJavaScriptÎļþÖУ¬£¬£¬£¬£¬£¬£¬¸ÃÎļþ±»ÓÃÀ´×°ÖÃSocGholish£¬£¬£¬£¬£¬£¬£¬Ëü½«Í¨¹ýαÔìµÄ¸üÐÂÌáÐÑ£¬£¬£¬£¬£¬£¬£¬°Ñ¶ñÒâÈí¼þpayload¼Ù×°³ÉÐéαµÄä¯ÀÀÆ÷¸üÐÂÎļþ£¨ÈçChrom§Ö.U§âdat§Ö.zip¡¢ºÍFirefo§ç.U§âdat§Ö.zipµÈ£©Ï°È¾½Ó¼ûÍøÕ¾µÄÓû§¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/hundreds-of-us-news-sites-push-malware-in-supply-chain-attack/
2¡¢×êÑÐÍŶӷ¢ÏÖÊýÊ®¸öÊÔͼ·Ö·¢¶ñÒâÈí¼þW4SPµÄPyPI°ü
Phylum 11ÔÂ1ÈÕ³ÆÆäÔÚPyPI×¢²á±íÖз¢ÏÖÁË29¸öPython°ü£¬£¬£¬£¬£¬£¬£¬ËüÃÇ·ÂÕÕÊ¢ÐеĿ⣬£¬£¬£¬£¬£¬£¬²¢ÔÚϰȾָ±êºó·Ö·¢ÇÔÊØÐÅÏ¢µÄ¶ñÒâÈí¼þW4SP¡£¡£¡£¡£¡£Phylum×êÑÐÈËԱй©£¬£¬£¬£¬£¬£¬£¬Æ¾¾ÝPepy.techµÄͳ¼ÆÊý¾Ý£¬£¬£¬£¬£¬£¬£¬ÕâЩÈí¼þ°üÒѱ»ÏÂÔØÁ˳¬¹ý5700´Î¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±Hauke L¨¹bbers·¢ÏÖÁËPyPI°üpystileºÍthreadingsÔ̺¬×Ô³ÆÎªGyruzPIPµÄ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ»ùÓÚÒ»¸ö¿ªÔ´ÏîÄ¿evil-pip¡£¡£¡£¡£¡£L¨¹bbersÒѽ«ÕâЩ°ü»ã±¨¸øPyPIÖÎÀíÔ±¡£¡£¡£¡£¡£
https://blog.phylum.io/phylum-discovers-dozens-more-pypi-packages-attempting-to-deliver-w4sp-stealer-in-ongoing-supply-chain-attack
3¡¢ÎÖ´ï·áÒâ´óÀû¹«Ë¾Åû¶Æä¾ÏúÉ̱»ºÚµ¼ÖµÄÊý¾Ýй¶ÊÂÎñ
¾Ý11ÔÂ2ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬ÎÖ´ï·áÒâ´óÀû¹«Ë¾£¨Vodafone Italia£©Í¨ÖªÆä¿Í»§¹ØÓÚ¾ÏúÉÌFourB SpA±»ºÚµ¼ÖµÄÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£¹¥»÷²úÉúÔÚ9ÔµĵÚÒ»ÖÜ£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶ÁËÓû§µÄ¾ßÌåÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬Èç¶©ÔÄÐÅÏ¢¡¢Éí·ÝÖ¤¼þºÍÁªÏµ·½Ê½µÈ¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬FourBÒѾ¹Ø¹ØÁ˶Ա»ÈëÇÖ·þÎñÆ÷µÄ½Ó¼û£¬£¬£¬£¬£¬£¬£¬²¢Ö´ÐÐÁ˸ü¸ß¼¶´ËÍⰲȫսÊõ¡£¡£¡£¡£¡£2022Äê9ÔÂ3ÈÕ£¬£¬£¬£¬£¬£¬£¬×Ô³ÆKelvinSecurityÍÅ»ïÔøÐû³Æ¹¥»÷ÁËVodafone Italia²¢ÇÔÈ¡ÁË295000¸öÎļþ£¬£¬£¬£¬£¬£¬£¬×ܼÆ310 GBµÄÊý¾Ý¡£¡£¡£¡£¡£Æäʱ£¬£¬£¬£¬£¬£¬£¬ÎÖ´ï·á»ØÓ¦³ÆÆä¹«Ë¾ÄÚ²¿ITϵͳ²¢Î´Ô⵽δ¾ÊÚȨµÄ½Ó¼û£¬£¬£¬£¬£¬£¬£¬µ«½«³ÖÐøµ÷²é¡£¡£¡£¡£¡£Éв»Ã÷ÏÔ¸ÃÊÂÎñÊÇ·ñÓëÕâ´ÎÅû¶µÄй¶ÊÂÎñÓйء£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/vodafone-italy-discloses-data-breach-after-reseller-hacked/
4¡¢OPERA1ERÍÅ»ïÒÑ´ÓÒøÐк͵çÐŹ«Ë¾ÇÔÈ¡³¬¹ý1100ÍòÃÀÔª
¾ÝGroup-IB 11ÔÂ3Èճƣ¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍÍÅ»ïOPERA1ERÀûÓÃÏֳɵĺڿ͹¤¾ß£¬£¬£¬£¬£¬£¬£¬ÒÑ´ÓÒøÐк͵çÕÛ·þÎñÌṩÉÌÇÔÈ¡ÁËÖÁÉÙ1100ÍòÃÀÔª¡£¡£¡£¡£¡£³ýÁËÖØÒªÕë¶Ô·ÇÖ޵Ĺ«Ë¾±í£¬£¬£¬£¬£¬£¬£¬¸ÃÍŻﻹ¹¥»÷Á˰¢¸ùÍ¢¡¢°ÍÀ¹çºÍÃϼÓÀ¹úµÄ×éÖ¯¡£¡£¡£¡£¡£´Ó2018Äêµ½2022Ä꣬£¬£¬£¬£¬£¬£¬ºÚ¿Í×ܹ²ÌáÒéÁ˳¬¹ý35´Î³É¹¦µÄ¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ¼Èý·ÖÖ®Ò»ÊÇÔÚ2020Äê½øÐеġ£¡£¡£¡£¡£OPERA1ERÀûÓÃÓã²æÊ½´¹µö¹¥»÷»ñµÃ³õʼ½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬£¬£¬ÖØÒªÒÀ¸½¿ªÔ´¹¤¾ß¡¢ÉÌÆ·¶ñÒâÈí¼þÒÔ¼°MetasploitºÍCobalt StrikeµÈ¿ò¼ÜÀ´ÈëÇÖ¹«Ë¾µÄ·þÎñÆ÷¡£¡£¡£¡£¡£
https://blog.group-ib.com/opera1er-apt
5¡¢Lookout°ä²¼2022ÄêÃÀ¹úµ±¾Ö»ú¹¹ÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨
11ÔÂ2ÈÕ£¬£¬£¬£¬£¬£¬£¬Lookout°ä²¼Á˹ØÓÚ2022ÄêÃÀ¹úµ±¾Ö»ú¹¹ÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¸Ã»ã±¨»ùÓÚ¶Ô2021ÄêÖÁ2022ÄêϰëÄêµÄ2ÒŲ́É豸ºÍ1.75ÒÚ¸öÀûÓ÷¨Ê½½øÐзÖÎö£¬£¬£¬£¬£¬£¬£¬·¢ÏÖÃÀ¹úµ±¾ÖÔ±¹¤Ê¹ÓõÄAndroidÊÖ»úÖУ¬£¬£¬£¬£¬£¬£¬½üÒ»°ëÔËÐеÄÊǹýÆÚµÄ²Ù×÷ϵͳ°æ±¾¡£¡£¡£¡£¡£Õë¶ÔÒÆ¶¯Óû§×î³£¼ûµÄ¹¥»÷ÊǶñÒâÈí¼þµÄ´«²¼£¬£¬£¬£¬£¬£¬£¬Ô¼Õ¼75%£¬£¬£¬£¬£¬£¬£¬¶øÆ¾Ö¤ÇÔÈ¡ÔòÕ¼Ôü×Ò±ÈÀýµÄ´ó²¿ÃÅ¡£¡£¡£¡£¡£2022Ä꣬£¬£¬£¬£¬£¬£¬Lookout¼à¿ØµÄ11Ãûµ±¾ÖÔ±¹¤ÖÐÓÐ1ÈËÔâµ½´¹µö¹¥»÷¡£¡£¡£¡£¡£ÄÇЩµã»÷¶ñÒâÁ´½Ó²¢±»ÖÒ¸æµÄÈËÖУ¬£¬£¬£¬£¬£¬£¬57%ûÓÐÔÙ³Á¸´ËûÃǵÄÃýÎ󣬣¬£¬£¬£¬£¬£¬19%µÄÈ˵ã»÷ÁËÁ½´Î£¬£¬£¬£¬£¬£¬£¬24%µÄÈ˵ã»÷ÁËÈý´ÎÒÔÉÏ¡£¡£¡£¡£¡£
https://www.lookout.com/form/threats-government-threat-report-lp
6¡¢Deep Instinct°ä²¼2022ÄêÖÐÆÚÍøÂçÍþÐ²Ì¬ÊÆµÄ»ã±¨
¾ÝýÌå11ÔÂ1Èճƣ¬£¬£¬£¬£¬£¬£¬Deep Instinct°ä²¼ÁË2022ÄêÖÐÆÚÍøÂçÍþÐ²Ì¬ÊÆµÄ»ã±¨¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬£¬£¬RaaSÍÅ»ïLockBitÕ¼2022ÄêËùÓÐÀÕË÷¹¥»÷µÄ44%£¬£¬£¬£¬£¬£¬£¬Æä´ÎÊÇConti(23%)¡¢Hive(21%)¡¢Black Cat(7%)ºÍConti Splinters(5%)¡£¡£¡£¡£¡£Ëæ×Å΢ÈíÔÚOfficeÎļþÖÐĬÈϽûÓú꣬£¬£¬£¬£¬£¬£¬Ê¹ÓÃÎĵµµÄ¶ñÒâÈí¼þ×÷ÎªÔØÌåµÄÇé¿öÏ÷¼õÁË£¬£¬£¬£¬£¬£¬£¬È¡¶ø´úÖ®µÄÊÇLNK¡¢HTMLºÍ´æµµµç×ÓÓʼþ¸½¼þ¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬»ã±¨»¹Ìáµ½ÁËÏñSpoolFool¡¢FollinaºÍDirtyPipeÕâÑùµÄ·ì϶͹ÆðÁËWindowsºÍLinuxϵͳµÄ¿ÉÀûÓÃÐÔ£¬£¬£¬£¬£¬£¬£¬ÅúעÿÈýµ½ËĸöÔ±»ÀûÓõķì϶ÊýÁ¿¾Í»á¼¤Ôö¡£¡£¡£¡£¡£
https://www.infosecurity-magazine.com/news/lockbit-dominates-ransomware/


¾©¹«Íø°²±¸11010802024551ºÅ