ÎÚ¿ËÀ¼CERT-UA¼ì²âµ½Õë¶Ôµ±¾Ö»ú¹¹×°ÖÃRemcosµÄ´¹µö»î¶¯

°ä²¼¹¦·ò 2023-02-10
1¡¢ÎÚ¿ËÀ¼CERT-UA¼ì²âµ½Õë¶Ôµ±¾Ö»ú¹¹×°ÖÃRemcosµÄ´¹µö»î¶¯

      

¾ÝýÌå2ÔÂ8ÈÕ±¨Â·£¬£¬£¬£¬£¬ÎÚ¿ËÀ¼ÍÆËã»úÓ¦¼±ÏìÓ¦Ó××é(CERT-UA)·¢ÏÖÕë¶Ôµ±¾Ö»ú¹¹×°ÖÃRemcosµÄÐÂÒ»ÂÖ´¹µö»î¶¯¡£ ¡£¡£¡£¡£ÓʼþÐû³ÆÀ´×ÔÎÚ¿ËÀ¼µçÐŹ«Ë¾Ukrtelecom£¬£¬£¬£¬£¬²¢´øÓеö¶üRARÎĵµ¡£ ¡£¡£¡£¡£Ô̺¬Á½¸öÎļþÖУ¬£¬£¬£¬£¬Ò»¸öÊdz¬¹ý600MBµÄÊÜÃÜÂë±£»£»£»£»£»£»£»£»¤µÄRAR£¬£¬£¬£¬£¬ºÍÒ»¸öÓÃÓÚ´ò¿ªRARÎļþÃÜÂëµÄÎı¾Îļþ¡£ ¡£¡£¡£¡£RARÎĵµÖÐÔ̺¬Ò»¸ö¿ÉÖ´ÐÐÎļþ¡°court letter, information on debt.pdf.exe¡±£¬£¬£¬£¬£¬Ö´Ðкó»á×°ÖÃRemcos¡£ ¡£¡£¡£¡£CERT-UA½«¸Ã»î¶¯¹éÒòÓÚUAC-0050¡£ ¡£¡£¡£¡£


https://securityaffairs.com/141959/cyber-warfare-2/cert-ua-remcos-attacks.html


2¡¢RedditÔâµ½´¹µö¹¥»÷µ¼ÖÂÄÚ²¿ÎļþºÍÔ´´úÂëй¶

      

ýÌå2ÔÂ9Èճƣ¬£¬£¬£¬£¬RedditÔâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬£¬ÒµÎñϵͳ±»ÈëÇÖ£¬£¬£¬£¬£¬ÄÚ²¿ÎļþºÍÔ´´úÂëй¶¡£ ¡£¡£¡£¡£¹¥»÷²úÉúÔÚÉÏÖÜÈÕÍí¼ä£¬£¬£¬£¬£¬¸Ã¹«Ë¾°µÊ¾£¬£¬£¬£¬£¬ºÚ¿ÍʹÓÃÁËÕë¶ÔRedditÔ±¹¤µÄµö¶ü£¬£¬£¬£¬£¬ÓÃÒ»¸öµÇÂ½Ò³Ãæ¼ÙÒâÆäÄÚÍøÍøÕ¾£¬£¬£¬£¬£¬ÊÔͼÇÔȡԱ¹¤Æ¾Ö¤ºÍË«³É·ÖÈÏÖ¤ÁîÅÆ¡£ ¡£¡£¡£¡£Ôڳɹ¦ÇÔȡһÃûÔ±¹¤µÄƾ֤ºó£¬£¬£¬£¬£¬¹¥»÷Õß»ñµÃÁ˶ÔһЩÄÚ²¿Îĵµ¡¢´úÂëÒÔ¼°Ò»Ð©ÄÚ²¿ÏÔÊ¾Ãæ°åºÍÒµÎñϵͳµÄ½Ó¼ûȨÏÞ¡£ ¡£¡£¡£¡£¹ÌÈ»RedditûÓй«¿ª¹ØÓÚ´¹µö¹¥»÷µÄÈκÎϸ½Ú£¬£¬£¬£¬£¬µ«Ìáµ½Á˵ÄÀàËÆÓÚÕë¶ÔRiot GamesµÄ¹¥»÷¡£ ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/hackers-breach-reddit-to-steal-source-code-and-internal-data/


3¡¢ºÚ¿ÍIntelBroker¹«¿ªWeee!Ô¼110Íò¿Í»§µÄÓ×ÎÒÐÅÏ¢

      

2ÔÂ8ÈÕ±¨Â·³Æ£¬£¬£¬£¬£¬ÑÇÒáºÍÎ÷°àÑÀÒáËͲͷþÎñWeee!Ô¼110Íò¿Í»§µÄÓ×ÎÒÐÅϢй¶¡£ ¡£¡£¡£¡£±¾ÖÜÒ»£¬£¬£¬£¬£¬ÃûΪIntelBrokerµÄºÚ¿ÍÔÚ°µÍøBreachedÉÏ·¢Ìû³Æ£¬£¬£¬£¬£¬2023Äê2Ô£¬£¬£¬£¬£¬SayweeeµÄ1100Íò¿Í»§µÄÊý¾Ý¿â±»µÁ¡£ ¡£¡£¡£¡£Weee! ÔÚÉêÃ÷ÖаµÊ¾£¬£¬£¬£¬£¬Õâ´ÎÊÂÎñÓ°ÏìÁËÔÚ2021Äê7ÔÂ12ÈÕÖÁ2022Äê7ÔÂ12ÈÕÖ®¼ä϶©µ¥µÄ¿Í»§£¬£¬£¬£¬£¬µ«ÊǸ¶¿îÐÅϢûÓÐй¶¡£ ¡£¡£¡£¡£¹ÌÈ»¹¥»÷Õß°µÊ¾Éæ¼°1100Íò¿Í»§£¬£¬£¬£¬£¬µ«Have I Been Pwned³ÆÐ¹Â¶Êý¾Ý½öÔ̺¬110Íò¸öΨһµÄÓʼþµØÖ·£¬£¬£¬£¬£¬¶î±íµÄ¼Í¼ºÜ¿ÉÄÜÊÇÓÉÓÚͳһ¿Í»§ÏÂÁ˶à¸ö¶©µ¥µ¼Öµġ£ ¡£¡£¡£¡£


hackread.com/weee-grocery-service-hacked/


4¡¢AmerisourceBergenµÄ×Ó¹«Ë¾Ôâµ½LorenzÀÕË÷¹¥»÷

      

¾Ý2ÔÂ8ÈÕ±¨Â·£¬£¬£¬£¬£¬Ò©Æ··ÖÏúÉÌAmerisourceBergen³ÆºÚ¿ÍÈëÇÖÁËÆä×Ó¹«Ë¾µÄITϵͳ¡£ ¡£¡£¡£¡£¸Ã¹«Ë¾°ä²¼ÉêÃ÷³ÆÈëÇÖÒѱ»×èÖ¹£¬£¬£¬£¬£¬ËûÃÇÔÚµ÷²é¸ÃÊÂÎñÊÇ·ñµ¼ÖÂÃô¸ÐÊý¾Ýй¶¡£ ¡£¡£¡£¡£LorenzÔÚÆäÍøÕ¾°ä²¼Á˾ݳƴÓAmerisourceBergenºÍMWI Animal Health£¨¹À¼ÆÊDZ»ÈëÇÖµÄ×Ó¹«Ë¾£©ÇÔÈ¡µÄËùÓÐÎļþ¡£ ¡£¡£¡£¡£¹¥»÷Õß½«°ä²¼ÈÕÆÚÉèÖÃΪ2022Äê11ÔÂ1ÈÕ£¬£¬£¬£¬£¬×¢Ã÷¼´±ãÎļþÊǸոհ䲼µÄ£¬£¬£¬£¬£¬µ«Î¥¹æÐÐΪ¿ÉÄܲúÉúÔÚ¼¸¸öÔÂǰ¡£ ¡£¡£¡£¡£¹ÌȻй¶µÄÎļþ¿´ËÆÕæÊµ£¬£¬£¬£¬£¬µ«AmerisourceBergenÉÐδȷÈÏÕâЩÎļþÊÇ´ÓÆäϵͳÖÐÇÔÈ¡µÄ¡£ ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/drug-distributor-amerisourcebergen-confirms-security-breach/


5¡¢Check Point°ä²¼2022ÄêÍøÂç¹¥»÷»î¶¯µÄ»ØÊ׻㱨

      

2ÔÂ8ÈÕ£¬£¬£¬£¬£¬Check Point°ä²¼Á˹ØÓÚ2022ÄêÍøÂç¹¥»÷»î¶¯µÄ»ØÊ׻㱨¡£ ¡£¡£¡£¡£»ã±¨»ØÊ×Á˶¯µ´µÄ2022Ä꣬£¬£¬£¬£¬¸ÃÄêÍøÂç¹¥»÷´ïµ½º¹Çà×î¸ßˮƽ¡£ ¡£¡£¡£¡£ÓëÉÏÒ»ÄêÏà±È£¬£¬£¬£¬£¬2022ÄêµÄÍøÂç¹¥»÷Ôö³¤ÁË38%£¬£¬£¬£¬£¬Ã¿¸ö×éÖ¯¾ùÔÈÿÖÜÔâµ½1168´Î¹¥»÷¡£ ¡£¡£¡£¡£½ÌÓýºÍ×êÑÐÒÀÈ»ÊÇÔâµ½¹¥»÷×î¶àµÄÐÐÒµ£¬£¬£¬£¬£¬µ«Õë¶ÔÒ½ÁƱ£½¡ÐÐÒµµÄ¹¥»÷ͬ±ÈÔö³¤ÁË74%¡£ ¡£¡£¡£¡£¸Ã»ã±¨»¹Ç¿µ÷Á˹æÄ£¸üÓס¢¸ü½Ã½ÝµÄºÚ¿ÍºÍÀÕË÷ÍÅ»ïÔÚÀûÓûìºÏ¹¤×÷³¡ËùʹÓõĺϷ¨ºÏ×÷¹¤¾ß·½ÃæËù²ûÑïµÄ×÷Óᣠ¡£¡£¡£¡£


https://blog.checkpoint.com/2023/02/08/check-point-2023-security-report-cyberattacks-reach-an-all-time-high-in-response-to-geo-political-conflict-and-the-rise-of-disruption-and-destruction-malware/


6¡¢ESET°ä²¼¹ØÓÚ2022ÄêT3ÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨

      

ESETÔÚ2ÔÂ8ÈÕ°ä²¼¹ØÓÚ2022ÄêT3ÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£ ¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬Õë¶Ô¶³öµÄRDP·þÎñµÄ±©Á¦¹¥»÷ÔÚ2022Äê³öÏÖÁËÖè½µ£¬£¬£¬£¬£¬½µÂäÔ­Òò³ýÁËÕ½Õù±í£¬£¬£¬£¬£¬»¹¿ÉÄÜÊÇÔ¶³Ì¹¤×÷µÄÏ÷¼õ¡¢¹«Ë¾IT²¿ÃŵÄÉèÖúͶԲߵĸĽøÒÔ¼°Windows 11ÖÐÄÚÖõı©Á¦À¹½ØÖ°ÄÜ¡£ ¡£¡£¡£¡£¼´±ãRDP¹¥»÷ÓÐËù½µÂ䣬£¬£¬£¬£¬ÃÜÂë²Â²âÒÀÈ»ÊÇ2022ÄêT3×îÊÜ»¶Ó­µÄÍøÂç¹¥»÷ÔØÌå¡£ ¡£¡£¡£¡£ÔÚ¼ÓÃÜÇ®±ÒÇÔÈ¡·¨Ê½ºÍ¼ÓÃܿ󹤵ȴ«Í³¶ñÒâÈí¼þÏ÷¼õµÄͬʱ£¬£¬£¬£¬£¬Óë¼ÓÃÜÇ®±ÒÓйصÄÚ¿Æ­Ôڻظ´¡£ ¡£¡£¡£¡£Androidƽ̨ÉϵļäµýÈí¼þÒ²ÔÚÕâÒ»ÄêÖÐÓÐËùÔö³¤¡£ ¡£¡£¡£¡£


https://www.welivesecurity.com/2023/02/08/eset-threat-report-t3-2022/