Mixin Network±»ºÚËðʧ¸ß´ï2ÒÚÃÀÔª²¢ÔÝÍ£ÔËÓª
°ä²¼¹¦·ò 2023-09-261¡¢Mixin Network±»ºÚËðʧ¸ß´ï2ÒÚÃÀÔª²¢ÔÝÍ£ÔËÓª
¾Ý9ÔÂ25ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬Î»ÓÚÖйúÏã¸ÛµÄ¼ÓÃÜÇ®±Ò¹«Ë¾Mixin NetworkÔâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Ëðʧ¸ß´ï2ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£¡£Õâ´ÎÊÂÎñ²úÉúÔÚ9ÔÂ23ÈÕÁ賿£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾Á¢¼´ÔÝÍ£ÁË´æ¿îºÍÈ¡¿î¡£¡£¡£¡£¡£¡£¡£¾Ý³Æ¹¥»÷ÕßÄܹ»½Ó¼ûMixin NetworkÔÆ·þÎñÌṩÉ̵ÄÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬£¬ÇÔÈ¡Ö÷ÍøÉϵIJ¿ÃÅ×ʲú¡£¡£¡£¡£¡£¡£¡£PeckShieldµÈÇø¿éÁ´×·×ÙÆ÷ÒѼø±ð³öÔ¼1.41ÒÚÃÀÔªµÄ±»µÁ×ʲú£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐ9350ÍòÃÀԪΪETH£¬£¬£¬£¬£¬£¬£¬£¬2350ÍòÃÀԪΪDAI£¨´ÓUSDT»»À´£©£¬£¬£¬£¬£¬£¬£¬£¬2330ÍòÃÀԪΪBTC¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/mixin-network-suspends-operations-following-200-million-hack/
2¡¢°Ä´óÀûÑÇTissuPathÒò¹©¸øÉ̱»¹¥»÷446 GBÊý¾Ýй¶
¾ÝýÌå9ÔÂ21ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬°Ä´óÀûÑÇרҵ²¡Àíѧ¹«Ë¾TissuPathÔâµ½¹¥»÷µ¼ÖÂÊý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñ²úÉúÓÚ8ÔÂ24ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Ô´ÓÚTissuPathµÄÒ»¼ÒµÚÈý·½¹©¸øÉÌÔâµ½¹©¸øÁ´¹¥»÷¡£¡£¡£¡£¡£¡£¡£µ÷²é·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚÔ¶³Ì½Ó¼û¹¤¾ß°ü(RAT)´æÔÚ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬¹©¸øÉ̵ÄϵͳºÍÓû§ÕÊ»§±»ÈëÇÖ¡£¡£¡£¡£¡£¡£¡£ÕâЩºÏ·¨µÄÖÎÀíÔ¹ØË»§±»·ÂÕÕ£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ½øÈëTissuPathµÄϵͳ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜ»ñµÃÁË2011ÄêÖÁ2020ÄêÏòTissuPath·¢³öµÄ²¡Àíת½é¡£¡£¡£¡£¡£¡£¡£9ÔÂ2ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬AlphVÐû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü£¬£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ9ÔÂ5ÈÕ³Æ446 GBºÍ735414¸öÎļþÒѱ»Ð¹Â¶¡£¡£¡£¡£¡£¡£¡£
https://www.databreaches.net/tissupaths-data-breach-notice-provides-details-about-how-they-were-attacked-and-their-incident-response/
3¡¢Google³ÆAppleºÍChrome·ì϶±»ÓÃÓÚ×°ÖÃPredator
ýÌå9ÔÂ22ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬Googleй©AppleÔÚÉÏÖÜËĽ¨¸´µÄÈý¸ö·ì϶Òѱ»ÀÄÓ㬣¬£¬£¬£¬£¬£¬£¬×÷ΪװÖüäµýÈí¼þPredatorµÄ·ì϶ÀûÓÃÁ´µÄÒ»²¿ÃÅ¡£¡£¡£¡£¡£¡£¡£½ñÄê5ÔÂÖÁ9Ô£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓÃÕâЩ·ì϶£¨CVE-2023-41991¡¢CVE-2023-41992ºÍCVE-2023-41993£©£¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ýµö¶ü¶ÌÐźÍWhatsAppÐÂÎÅ£¬£¬£¬£¬£¬£¬£¬£¬Õë¶Ô°£¼°Ç°¹ú»áÒéÔ±Ahmed EltantawyÖ´Ðй¥»÷¡£¡£¡£¡£¡£¡£¡£Google TAG»¹¹Û²ìµ½Chrome·ì϶£¨CVE-2023-4762£©Ò²±»ÓÃÓÚÕë¶Ô°£¼°µÄAndroidÉ豸װÖÃPredator¡£¡£¡£¡£¡£¡£¡£Apple³ÆiOSËø¶¨Ä£Ê½Äܹ»·ÀÓù´ËÀ๥»÷¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/recently-patched-apple-chrome-zero-days-exploited-in-spyware-attacks/
4¡¢Akamai·¢ÏÖÀûÓÃÐéαBookingÍøÕ¾µÄ¸´ÔÓ´¹µö»î¶¯
AkamaiÔÚ9ÔÂ21ÈճƷ¢ÏÖÁËÕë¶Ô¾ÆµêÐÐÒµµÄ¸´ÔӵĴ¹µö»î¶¯¡£¡£¡£¡£¡£¡£¡£ÔÚÔʼָ±ê£¨¾Æµê£©ÉÏÖ´ÐÐÐÅÏ¢ÇÔÈ¡·¨Ê½ºó£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»½Ó¼ûÓë¿Í»§Ö®¼äµÄÐÂÎÅ¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÓë×îÖÕÖ¸±êÖ®¼ä³ÉÁ¢¿ÉÐŵÄͨѶÇþ·ºó£¬£¬£¬£¬£¬£¬£¬£¬¾Í¼Ù×°³É¾Æµê¡¢Ô¤Ô¼·þÎñ»ò¹Û¹âÉç·¢ËÍ´¹µöÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬ÒªÇó½øÐжî±íµÄÐÅÓþ¿¨ÑéÖ¤¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹Ñ¡È¡Á˶àÖÖ°²È«ÑéÖ¤ºÍ·´·ÖÎö¼¼Êõ£¬£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÖ¸±êͨ¹ýÕâЩ²âÊÔ£¬£¬£¬£¬£¬£¬£¬£¬½«»á¿´µ½Ò»¸ö¼Ù×°³ÉBooking.com¸¶¿îÒ³ÃæµÄ´¹µöÍøÕ¾£¬£¬£¬£¬£¬£¬£¬£¬ÒªÇóÐÅÓþ¿¨ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹Ôö³¤ÁËÖÇÄÜ̸ÌìÖ§³ÖÇþ·£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÈ·±£´¹µö»î¶¯µÄ¿ÉÐŶȡ£¡£¡£¡£¡£¡£¡£
https://www.akamai.com/blog/security-research/sophisticated-phishing-campaign-targeting-hospitality
5¡¢ESETÅû¶OilRigÕë¶ÔÒÔÉ«ÁеÄÁ½´Î¹¥»÷»î¶¯µÄϸ½Ú
9ÔÂ22ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬ESETÅû¶ÁËOilRigÕë¶ÔÒÔÉ«ÁÐʵÌåµÄÁ½´Î¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬£¬£¬¼´Outer Space(2021Äê)ºÍJuicy Mix(2022Äê)¡£¡£¡£¡£¡£¡£¡£ÕâÁ½´Î¹¥»÷»î¶¯Ê¹ÓÃÁËÒ»ÑùµÄÕ½Êõ£ºOilRigÊ×ÏÈÈëÇÖÒ»¸öºÏ·¨ÍøÕ¾ÓÃ×÷C&C·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬£¬¶øºóʹÓÃVBS droppers·Ö·¢C# /.NETºóÃÅ£¬£¬£¬£¬£¬£¬£¬£¬Í¬Ê±»¹²¿ÊðÁ˸÷ÀàÓÃÓÚÔÚÖ¸±êϵͳÉϽøÐÐÊý¾Ýй¶µÄ¹¤¾ß¡£¡£¡£¡£¡£¡£¡£Outer Space»î¶¯Ê¹ÓÃÁËеĺóÃÅSolarºÍеÄÏÂÔØ·¨Ê½SampleCheck5000£¨»òSC5k£©£¬£¬£¬£¬£¬£¬£¬£¬Juicy Mix»î¶¯¶ÔSolar½øÐиĽø²¢´´½¨Á˺óÃÅMango¡£¡£¡£¡£¡£¡£¡£
https://www.welivesecurity.com/en/eset-research/oilrigs-outer-space-juicy-mix-same-ol-rig-new-drill-pipes/
6¡¢Kaspersky°ä²¼2023ÄêÉϰëÄêÎïÁªÍøÍþвµÄ·ÖÎö»ã±¨
9ÔÂ21ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Kaspersky°ä²¼ÁË2023ÄêÉϰëÄêÎïÁªÍøÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£ÎïÁªÍøÏ°È¾õè¾¶ÖØÒªÊDZ©Á¦ÆÆ½âºÍÀûÓÃÍøÂç·þÎñÖеķì϶¡£¡£¡£¡£¡£¡£¡£Ã۹޼ͼÏÔʾ£¬£¬£¬£¬£¬£¬£¬£¬2023ÄêÉϰëÄê97.91%µÄ±©Á¦ÆÆ½â³¢ÊÔ¼¯ÖÐÔÚTelnetÉÏ£¬£¬£¬£¬£¬£¬£¬£¬½ö2.09%Õë¶ÔSSH¡£¡£¡£¡£¡£¡£¡£2023ÄêÉϰëÄ꣬£¬£¬£¬£¬£¬£¬£¬¸÷Àà°µÍøÉÏ×ܹ²°ä²¼ÁË700¶àÌõÕë¶ÔDDoS¹¥»÷·þÎñµÄ¸æ°×¡£¡£¡£¡£¡£¡£¡£ÔÚIoT¶ñÒâÈí¼þÁìÓò´æÔÚ´óÁ¿±äÌ壬£¬£¬£¬£¬£¬£¬£¬ÆäÖкܶàÔ´×Ô2016 Mira¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£½Ù³ÖÉ豸²¢Ê¹ÓÃËüÌáÒéÕë¶Ô¸÷Àà·þÎñµÄDoS¹¥»÷µÄľÂíÊÇ×î³£¼ûµÄIoT¶ñÒâÈí¼þÀàÐÍ¡£¡£¡£¡£¡£¡£¡£
https://securelist.com/iot-threat-report-2023/110644/


¾©¹«Íø°²±¸11010802024551ºÅ