McLaren Health CareÔâµ½¹¥»÷220ÍòÈ˵ÄÐÅϢй¶

°ä²¼¹¦·ò 2023-11-13
1¡¢McLaren Health CareÔâµ½¹¥»÷220ÍòÈ˵ÄÐÅϢй¶


¾Ý11ÔÂ10ÈÕ±¨Â·£¬£¬£¬£¬£¬McLaren Health Care(Âõ¿­Â×)Åû¶ÁË7ÔÂÖÁ8Ô²úÉúµÄһ·Êý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬Ó°ÏìÁË2192515È˵ÄÐÅÏ¢¡£¡£¡£¡£¡£Âõ¿­Â×ÓÚ8ÔÂ22ÈÕ·¢ÏÖÁËÒì³£»£»£»£»£»£»£»£»î¶¯£¬£¬£¬£¬£¬µ÷²éÏÔʾ¹¥»÷Õß7ÔÂ28ÈÕÖÁ8ÔÂ23ÈÕδ¾­ÊÚȨ½Ó¼ûÁËÆäÍøÂç¡£¡£¡£¡£¡£ÓÐÖ¤¾ÝÅú×¢£¬£¬£¬£¬£¬8ÔÂ31ÈÕ¹¥»÷Õß½Ó¼ûÁËÊý¾Ý£¬£¬£¬£¬£¬²¢Ö±µ½10ÔÂ10ÈÕÈ·ÈÏй¶Êý¾ÝµÄÀàÐÍ¡£¡£¡£¡£¡£Ö»¹Ü¸Ã»ú¹¹Ã»ÓÐй©Óйع¥»÷µÄ¸ü¶àϸ½Ú£¬£¬£¬£¬£¬µ«ALPHVÐû³Æ¶ÔÂõ¿­Â׵Ĺ¥»÷ÕÆ¹Ü¡£¡£¡£¡£¡£ËûÃÇ»¹°ä²¼Á˱»µÁÊý¾ÝÑù±¾£¬£¬£¬£¬£¬²¢ÍþвҪÅÄÂôÓ°Ïì250ÍòÈ˵ÄÊý¾Ý¿â¡£¡£¡£¡£¡£


https://securityaffairs.com/154014/data-breach/mclaren-health-care-data-breach.html


2¡¢CloudflareÍøÕ¾Ôâµ½Anonymous SudanµÄDDoS¹¥»÷


¾ÝýÌå11ÔÂ9ÈÕ±¨Â·£¬£¬£¬£¬£¬CloudflareÍøÕ¾Ôâµ½Anonymous SudanµÄDDoS¹¥»÷¡£¡£¡£¡£¡£CloudflareÍøÕ¾å´»ú£¬£¬£¬£¬£¬ÏÔʾ¡°ÎÒÃǺܱ§À¢......µ«ÄúµÄÍÆËã»ú»òÍøÂç¿ÉÄÜÔÚ·¢ËÍ×Ô¶¯²éÎÊ¡£¡£¡£¡£¡£ÎªÁ˱£»£»£»£»£»£»£»£»¤8827Ì«Ñô¼¯ÍÅÓû§£¬£¬£¬£¬£¬ÎÒÃÇ´Ë¿ÌÎÞ·¨´¦ÖÃÄúµÄÒªÇó¡±ÒÔ¼°Ò»¸ö¿´ÆðÀ´¡°Óе㲻ºÏ¾¢¡±µÄGoogle»Õ±ê¡£¡£¡£¡£¡£Cloudflare°µÊ¾DDoS¹¥»÷µ¼ÖÂwww.cloudflare.com³öÏÖÁ˼¸·ÖÖÓµÄÏνÓÎÊÌâ¡£¡£¡£¡£¡£µ«ÊÇûÓÐÓ°ÏìCloudflareµÄÈκηþÎñ»ò²úÆ·Ö°ÄÜ£¬£¬£¬£¬£¬Ò²Ã»Óпͻ§Êܵ½Ó°Ïì¡£¡£¡£¡£¡£Anonymous SudanÐû³Æ¶Ô´ËÊÂÕÆ¹Ü£¬£¬£¬£¬£¬²¢³Æ¹¥»÷³ÖÐø¹¦·òΪ1Ó×ʱ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/technology/cloudflare-website-downed-by-ddos-attack-claimed-by-anonymous-sudan/


3¡¢MandiantÅû¶Sandworm¹¥»÷ÎÚ¿ËÀ¼µçÁ¦ÏµÍ³µÄÏêÇé


MandiantÔÚ11ÔÂ9ÈÕÅû¶ÁËSandwormÀûÓÃÕë¶ÔOTµÄÐÂÐ͹¥»÷Ó°ÏìÎÚ¿ËÀ¼µçÁ¦¹©¸øµÄ»î¶¯¡£¡£¡£¡£¡£¸ÃÊÂÎñ²úÉúÓÚ2022Äêµ×£¬£¬£¬£¬£¬Mandiant°µÊ¾ÕâÊÇÒ»´Î¶àÊÂÎñÍøÂç¹¥»÷£¬£¬£¬£¬£¬ÀûÓÃÁËÓ°ÏìICS/OTµÄз½Ê½¡£¡£¡£¡£¡£¹¥»÷ÕßÊ×ÏÈʹÓÃOT¼¶´ËÍâLotL¹¥»÷£¬£¬£¬£¬£¬¿ÉÄܻᴥ·¢Ö¸±ê±äµçÕ¾¶Ï·Æ÷£¬£¬£¬£¬£¬µ¼ÖÂÒâ±íÍ£µç£¬£¬£¬£¬£¬Í¬Ê±¶ÔÎÚ¿ËÀ¼¸÷µØµÄ¹Ø¼ü»ù´¡ÉèʩִÐдó¹æÄ£µ¼µ¯¹¥»÷¡£¡£¡£¡£¡£SandwormËæºóÔÚÖ¸±êµÄITϵͳÖÐ×°ÖÃÁËCADDYWIPERµÄбäÖÖ£¬£¬£¬£¬£¬´Ó¶øÖ´Ðеڶþ´Î·ÛËéÐÔ¹¥»÷¡£¡£¡£¡£¡£ 


https://www.mandiant.com/resources/blog/sandworm-disrupts-power-ukraine-operational-technology


4¡¢Imperial Kitten¹¥»÷Öж«µØÓòÔËÊä¡¢ÎïÁ÷ºÍ¿Æ¼¼¹«Ë¾


11ÔÂ9ÈÕ£¬£¬£¬£¬£¬CrowdStrike¹«¿ªÁËImperial KittenÕë¶ÔÖж«µØÓòÔËÊä¡¢ÎïÁ÷ºÍ¿Æ¼¼¹«Ë¾µÄµÄÐÂÒ»Âֻ¡£¡£¡£¡£¡£10Ô·ݣ¬£¬£¬£¬£¬¹¥»÷Õ߯ðÍ··Ö·¢ÒÔ¡°¹¤×÷ÕÐÆ¸¡±Ö÷Ì⣬£¬£¬£¬£¬Ô̺¬¶ñÒâExcel¸½¼þµÄ´¹µöÓʼþ¡£¡£¡£¡£¡£´ò¿ªºó¶ñÒâºê´úÂë»áÌáÈ¡Á½¸öÅú´¦ÖÃÎļþ£¬£¬£¬£¬£¬ËüÃÇ´´½¨ÓƾÃÐÔ²¢ÔËÐÐpayloadÀ´½øÐз´Ïòshell½Ó¼û¡£¡£¡£¡£¡£¶øºó£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃPAExecµÈ¹¤¾ßºáÏòÒÆ¶¯ÒÔÔ¶³Ìִǰ¹ý³Ì£¬£¬£¬£¬£¬Ê¹ÓÃNetScan¿úËÅÍøÂ磬£¬£¬£¬£¬Ê¹ÓÃProcDump´ÓϵͳÄÚ´æÖлñȡʹ´¦£¬£¬£¬£¬£¬Ê¹ÓÃ×Ô½ç˵¶ñÒâÈí¼þIMAPLoaderºÍStandardKeyboardÓëC2·þÎñÆ÷ͨѶ¡£¡£¡£¡£¡£


https://www.crowdstrike.com/blog/imperial-kitten-deploys-novel-malware-families/


5¡¢Î¢Èí³ÆSysAid·ì϶CVE-2023-47246±»ÓÃÀ´·Ö·¢Clop


ýÌå11ÔÂ9Èճƣ¬£¬£¬£¬£¬¹¥»÷ÕßÔÚÀûÓ÷þÎñÖÎÀíÈí¼þSysAidÖеķì϶½Ó¼ûÆóÒµµÄ·þÎñÆ÷À´ÇÔÈ¡Êý¾Ý£¬£¬£¬£¬£¬²¢²¿ÊðÀÕË÷Èí¼þClop¡£¡£¡£¡£¡£ÕâÊÇÒ»¸öõè¾¶±éÀú·ì϶£¨CVE-2023-47246£©£¬£¬£¬£¬£¬ÔÚºÚ¿ÍÀûÓø÷ì϶ÈëÇÖÄÚ²¿·þÎñÆ÷ºóÓÚ11ÔÂ2ÈÕ±»·¢ÏÖ£¬£¬£¬£¬£¬SysAidÔÚµ÷²éºó¹«¿ªÁ˹¥»÷µÄ¼¼Êõϸ½Ú¡£¡£¡£¡£¡£Î¢Èí´Ë¿ÌÈ·¶¨£¬£¬£¬£¬£¬¸Ã·ì϶±»Lace Tempest£¨ÓÖ³ÆFin11ºÍTA505£©ÓÃÀ´²¿ÊðÀÕË÷Èí¼þClop¡£¡£¡£¡£¡£SysAidÒѰ䲼·ì϶²¹¶¡£¡£¡£¡£¡£¬£¬£¬£¬£¬½¨ÒéËùÓÐЧ»§Á¢¼´×°ÖøüС£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/microsoft-sysaid-zero-day-flaw-exploited-in-clop-ransomware-attacks/


6¡¢Kaspersky°ä²¼¹ØÓÚDucktail¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨


11ÔÂ10ÈÕ£¬£¬£¬£¬£¬Kaspersky°ä²¼Á˹ØÓÚDucktail¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£DucktailÊÇÒ»¸ö¶ñÒâÈí¼þ¼Ò×壬£¬£¬£¬£¬×Ô2021ÄêϰëÄêÒÔÀ´Ò»Ïò»îÔ¾£¬£¬£¬£¬£¬Ö¼ÔÚÇÔÈ¡FacebookÆóÒµÕÊ»§¡£¡£¡£¡£¡£±¾»ã±¨·ÖÎöÁË×î½üµÄÒ»´Î»î¶¯£¬£¬£¬£¬£¬3ÔÂÖÁ10ÔÂÉÏÑ®£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÓªÏúרҵÈËÔ±¡£¡£¡£¡£¡£ÓëÒÔÍùÒÀÀµ.NETÀûÓ÷¨Ê½µÄ»î¶¯·ÖÆç£¬£¬£¬£¬£¬Õâ´Î»î¶¯Ê¹ÓÃÁËDelphi¡£¡£¡£¡£¡£¸Ã»î¶¯·¢ËÍÔ̺¬¹«Ë¾Ð²úƷͼƬºÍ¼Ù×°³ÉPDFµÄ¶ñÒâ¿ÉÖ´ÐÐÎļþµÄÎĵµ£¬£¬£¬£¬£¬Ö¼ÔÚ´«²¼Ð°汾µÄDucktail¡£¡£¡£¡£¡£


https://securelist.com/ducktail-fashion-week/111017/