Microsoft Teams ±»ÓÃÀ´´«²¼ DarkGate ¶ñÒâÈí¼þ

°ä²¼¹¦·ò 2024-02-01

1¡¢Microsoft Teams ±»ÓÃÀ´´«²¼ DarkGate ¶ñÒâÈí¼þ


1ÔÂ30ÈÕ£¬£¬£¬ £¬£¬AT&T ÍøÂ簲ȫ¹«Ë¾µÄÍøÂ簲ȫר¼Ò·¢ÏÖÁËÒ»¸öÁîÈËÓÇÓôµÄÇ÷Ïò£º¿í·ºÊ¹ÓõĺÏ×÷ƽ̨Microsoft Teams±»ÓÃ×÷ÍøÂç´¹µöÚ¿Æ­ºÍ¶ñÒâÈí¼þ¹¥»÷µÄÔØÌå¡£¡£¡£¡£¡£¹ÌȻͨ¹ýµç×ÓÓʼþ½øÐеĴ«Í³ÍøÂç´¹µöÒÀÈ»ÊÇÒ»ÖÔìÕ±éµÄÍþв£¬£¬£¬ £¬£¬µ« Microsoft Teams ÖÐ±í²¿½Ó¼ûµÄ¼¯³ÉΪ¶ñÒâÐÐΪÕ߯ô·¢ÁËеÄÀûÓÃÁìÓò¡£¡£¡£¡£¡£¹©Äú²Î¿¼£¬£¬£¬ £¬£¬±í²¿½Ó¼ûÄܹ»Ê¹Óà Teams¡¢Skype for Business »ò Skype Óë×éÖ¯±í²¿µÄÓ×ÎÒ¼ò»¯Í¨Ñ¶ºÍºÏ×÷¡£¡£¡£¡£¡£DarkGate ¶ñÒâÈí¼þ³õ´Î³öÏÖÓÚ 2017 Äê 12 Ô 25 ÈÕ£¬£¬£¬ £¬£¬×î³õµÄÖ°ÄÜÊÇÃÜÂëÇÔÈ¡·¨Ê½ºÍ¼ÓÃÜÇ®±ÒÍÚ¾ò·¨Ê½£¬£¬£¬ £¬£¬ÖØÒªÍ¨¹ý Torrent Îļþ´«²¼¡£¡£¡£¡£¡£¸Ã²¡¶¾ÊÇÓÉ enSilo ×êÑÐÔ± Adi Zeligson ·¢Ïֵ쬣¬£¬ £¬£¬Ëû¹Û²ìµ½¸Ã²¡¶¾Õë¶ÔµÄÊÇ Windows ¹¤×÷Õ¾¡£¡£¡£¡£¡£µ÷²éµÄ¹Ø¼üÊǼø±ð Teams »·¾³ÖеĿÉÒɻ¡£¡£¡£¡£¡£³¬¹ý 1,000 ¸ö Microsoft Teams ÊÂÎñÒѱ»ÏóÕ÷£¬£¬£¬ £¬£¬Åú×¢ÍøÂç´¹µö³¢ÊÔµÄÁìÓò¡£¡£¡£¡£¡£Í¨¹ýÀûÓà Microsoft 365×â»§ ID ²¢×Ðϸ¸ú×Ù̸Ìì½»»¥£¬£¬£¬ £¬£¬MDR SOC ÍŶӳɹ¦²éÁËÈ»ÊÜËðµÄÕÊ»§ºÍ×ʲúÒÔ½øÐн¨¸´¡£¡£¡£¡£¡£


https://www.hackread.com/microsoft-teams-external-access-darkgate-malware/


2¡¢Òâ´óÀûÊý¾Ý±£»£»£» £»£»£»£»£»¤»ú¹¹³ÆCHATGPTÎ¥·´Å·ÃËÒþÖÔ·¨


1ÔÂ30ÈÕ£¬£¬£¬ £¬£¬Òâ´óÀûÊý¾Ý±£»£»£» £»£»£»£»£»¤¼à¹Ü»ú¹¹¡°Garante per la protezione dei dati personi¡±°ä·¢ÒÑ֪ͨ OpenAI£¬£¬£¬ £¬£¬ChatGPT Î¥·´ÁËÅ·ÃËÊý¾Ý±£»£»£» £»£»£»£»£»¤ÂÉÀý GDPR¡£¡£¡£¡£¡£2023Äê4ÔÂÉÏÑ®£¬£¬£¬ £¬£¬Òâ´óÀûÊý¾Ý±£»£»£» £»£»£»£»£»¤¾Ö Òò·¸·¨ÍøÂçÓ×ÎÒÊý¾ÝÇÒ²»×ãÑé֤δ³ÉÄêÈË´ºÇïµÄϵͳ¶øÁÙʱ²»ÈÝ ChatGPT ¡£¡£¡£¡£¡£ÖÎÀí¾ÖÖ¸³ö£¬£¬£¬ £¬£¬OpenAI ²»»áÌáÐÑÓû§ËüÔÚÍøÂçËûÃǵÄÊý¾Ý¡£¡£¡£¡£¡£Æäʱ£¬£¬£¬ £¬£¬ÒþÖÔ¼à¹Ü»ú¹¹°µÊ¾£¬£¬£¬ £¬£¬Ã»ÓÐ˾·¨Æ¾¾ÝÖ§³Ö´ó¹æÄ£ÍøÂçºÍ´¦ÖÃÓ×ÎÒÊý¾ÝÀ´¡°ÑµÁ·¡±Æ½Ì¨ËùÒÀÀµµÄËã·¨¡£¡£¡£¡£¡£ÖÎÀí¾Ö¶Ô¸Ã·þÎñ½øÐÐÁËһЩ²âÊÔ£¬£¬£¬ £¬£¬²¢È·¶¨ÆäÌṩµÄÐÅÏ¢²¢²»×ÜÊÇÓëÊÂʵÇé¿öÏà·û£¬£¬£¬ £¬£¬Òò¶ø´¦ÖõÄÓ×ÎÒÊý¾Ý²»ÕýÈ·¡£¡£¡£¡£¡£¸Ã»ú¹¹Ðû³Æ£¬£¬£¬ £¬£¬Ö»¹Ü ChatGPT µÄ·þÎñÖ¼ÔÚÏìÓ¦ 13 ËêÒÔÉϵÄÓû§£¬£¬£¬ £¬£¬µ«¸Ã·þÎñÈÔʹδ³ÉÄêÈËÃæ¶ÔÓëÆä´ºÇï²»Ïà·ûµÄÏìÓ¦¡£¡£¡£¡£¡£ÆäʱOpenAIÐû³ÆÒÑÔÚ4ÔÂ30ÈÕµÄ×îºóÆÚÏÞǰÂú×ãÁËÒâ´óÀûÊý¾Ý±£»£»£» £»£»£»£»£»¤»ú¹¹µÄÒªÇ󣬣¬£¬ £¬£¬Òò¶ø¶Ô¸Ã̸Ìì»úеÈ˵ĽûÁî±»½â³ý¡£¡£¡£¡£¡£


https://securityaffairs.com/158359/laws-and-regulations/garante-chatgpt-violated-eu-privacy-laws.html


3¡¢¶íÂÞ˹Ôâ·êÈ«¹ú´óÁìÓò»¥ÁªÍøÖжÏ


1ÔÂ30ÈÕ£¬£¬£¬ £¬£¬¶íÂÞ˹ÕýÃæ¶Ô´óÁìÓòµÄ»¥ÁªÍøÖжϣ¬£¬£¬ £¬£¬È«¹ú¸÷µØµÄÓû§¶¼Êܵ½Ó°Ï죬£¬£¬ £¬£¬±¾µØ .ru ÓòÉϵÄÍøÕ¾½Ó¼ûȨÏÞ½µÂä¡£¡£¡£¡£¡£¶íÂÞ˹Êý×Ö²¿ÖܶþÔÚ Telegram Éϰ䷢ÉêÃ÷³Æ£¬£¬£¬ £¬£¬¸ÃÎÊÌâÓë .ru ÓòÃûµÄÈ«ÇòÓòÃûϵͳ°²È«À©´ó (DNSSEC) µÄ¼¼ÊõÎÊÌâÓйأ¬£¬£¬ £¬£¬¸ÃÀ©´óÓÃÓÚ±£»£»£» £»£»£»£»£»¤»¥ÁªÍøºÍÌ¸ÍøÂçÖл¥»»µÄÊý¾Ý¡£¡£¡£¡£¡£Ô̺¬×îÊÜ»¶Ó­µÄ±¾µØËÑË÷ÒýÇæ Yandex.ru¡¢µç×ÓÉÌÎñµ±ÏÈÕß Ozon.ru ºÍ Wildberry.ru ÔÚÄÚµÄÍøÕ¾ÒÔ¼°¸Ã¹ú×î´óÒøÐÐ Sberbank PJSC ºÍ VTB Group µÄÀûÓ÷¨Ê½¾ùÊܵ½Ó°Ïì¡£¡£¡£¡£¡£½»Í¨¼à¿Ø·þÎñ¡£¡£¡£¡£¡£


https://www.databreaches.net/russia-hit-with-widespread-internet-outage-across-country/


4¡¢Greatness Õë¶Ô Microsoft 365 µÄÐÂÍøÂçÍþв


1ÔÂ30ÈÕ£¬£¬£¬ £¬£¬ÔÚ²»ÐÝÑݱäµÄÍøÂçÍþвÖУ¬£¬£¬ £¬£¬³öÏÖÁËÒ»ÖÖеÄΣÏÕ£¬£¬£¬ £¬£¬ËüÒÔ¾ªÈ˵Ĺ¦Ð§Õë¶Ô Microsoft 365 Óû§¡£¡£¡£¡£¡£Trustwave Ö©Öë³¢ÊÔÊÒÒ»ÏòÔÚÇ×êǼල¡°Greatness¡±ÍøÂç´¹µö¹¤¾ß°üµÄʹÓü¤Ôö£¬£¬£¬ £¬£¬ÕâÊÇÒ»¸öÓÉÃûΪ¡°fisherstell¡±µÄÍþвÐÐΪÕß¿ª·¢µÄ¸´ÔÓµÄÍøÂç´¹µö¼´·þÎñƽ̨¡£¡£¡£¡£¡£×Ô 2022 ÄêÖÐÆÚÒÔÀ´£¬£¬£¬ £¬£¬Greatness ÌṩÁËÒ»¸öÓÃÓڲ߶¯ÍøÂç´¹µö»î¶¯µÄ×ۺϹ¤¾ß°ü£¬£¬£¬ £¬£¬´Ë¿ÌÒÔÿÔ 120 ÃÀÔªµÄ±ÈÌØ±Ò¼ÛÖµ»ñµÃ£¬£¬£¬ £¬£¬ÁîÈËÕ𾪡£¡£¡£¡£¡£Greatness ʹÓÃÁ¿µÄÔö³¤£¬£¬£¬ £¬£¬³ö¸ñÊÇ´Ó 2023 Äê 12 Ôµ½ 2024 Äê 1 Ô£¬£¬£¬ £¬£¬ÒýÆðÁËÈËÃǵÄÑϳÁÓÇÓô¡£¡£¡£¡£¡£Êܺ¦Õß¼òÖ±ÇÐÊýÁ¿Éв»Ã÷ÏÔ£¬£¬£¬ £¬£¬µ«¸Ã¹¤¾ß°üµÄ¿í·ºÊ¹ÓúÍ׳´óµÄÖ§³Öϵͳ£¨Ô̺¬×¨ÃÅµÄ Telegram ÉçÇø£©Í¹ÏÔÁËÆäDZÔÚÍþв¡£¡£¡£¡£¡£GreatnessµÄÌØµãÊǶ¨ÆÚ¸üУ¬£¬£¬ £¬£¬¼ÓÇ¿ÁËÈÆ¹ý°²È«´ëÊ©µÄÄÜÁ¦¡£¡£¡£¡£¡£×îиüÐÂÓÚ 2024 Äê 1 ÔÂÉÏÑ®°ä²¼£¬£¬£¬ £¬£¬²¢¸½ÓÐ Greatness Hub Telegram Ƶ·ÉϵľßÌåÎĵµ£¬£¬£¬ £¬£¬¸ÅÊöÁËÆäÐÂÖ°ÄÜ¡¢ÌáÐѺͼ¼ÇÉ¡£¡£¡£¡£¡£


https://securityonline.info/greatness-phishing-kit-the-new-cyber-menace-targeting-microsoft-365/


5¡¢ESET °ä²¼ GrandoreiroÒøÐÐľÂíµÄ·ÖÎö»ã±¨


1ÔÂ30ÈÕ£¬£¬£¬ £¬£¬ESET ÒÑÓë°ÍÎ÷Áª¹ú¾¯Ô±ºÏ×÷£¬£¬£¬ £¬£¬ÊÔͼ·ÛËé Grandoreiro ½©Ê¬ÍøÂç¡£¡£¡£¡£¡£ESET ͨ¹ýÌṩ¼¼Êõ·ÖÎö¡¢Í³¼ÆÐÅÏ¢ÒÔ¼°ÒÑÖªµÄºÅÁîºÍ½ÚÔì (C&C) ·þÎñÆ÷ÓòÃûºÍ IP µØÖ·Îª¸ÃÏîÄ¿×ö³öÁ˹±Ïס£¡£¡£¡£¡£ÓÉÓÚ Grandoreiro ÍøÂçºÍ̸µÄÉè¼ÆÈ±µã£¬£¬£¬ £¬£¬ESET ×êÑÐÈËÔ±»¹¿ÉÄÜÒ»¼ûÊܺ¦ÕßµÄÇé¿ö¡£¡£¡£¡£¡£ESET ×Ô¶¯»¯ÏµÍ³ÒÑ´¦ÖÃÊýÒÔÍò¼ÆµÄ Grandoreiro Ñù±¾¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ×Ô 2020 Äê 10 ÔÂ×óÓÒÆðͷʹÓõÄÓòÌìÉúËã·¨ (DGA) ÿÌì³ÇÊÐÌìÉúÒ»¸öÖ÷Óò£¬£¬£¬ £¬£¬²¢¿ÉÑ¡ÔñÌìÉú¶à¸ö¹ÊÕϰ²È«Óò¡£¡£¡£¡£¡£DGA ÊÇ Grandoreiro ֪·ÈôºÎÏò C&C ·þÎñÆ÷»ã±¨µÄΨһ·½Ê½¡£¡£¡£¡£¡£³ýÁ˵±Ç°ÈÕÆÚÖ®±í£¬£¬£¬ £¬£¬DGA »¹½ÓÊܾ²Ì¬ÅäÖà - ½ØÖÁ׫д±¾ÎÄʱ£¬£¬£¬ £¬£¬ÎÒÃÇÒѾ­¹Û²ìµ½ 105 ¸ö´ËÀàÅäÖᣡ£¡£¡£¡£


https://www.welivesecurity.com/en/eset-research/eset-takes-part-global-operation-disrupt-grandoreiro-banking-trojan/


6¡¢¹ú¼Ê½ðÈڿƼ¼¹«Ë¾ Direct Trading Technologies й¶³¬¹ý 30 ÍòÓû§Êý¾Ý


1ÔÂ31ÈÕ£¬£¬£¬ £¬£¬Direct Trading Technologies (DTT) ÊÇÒ»¼Ò¹ú¼Ê½ðÈڿƼ¼¹«Ë¾£¬£¬£¬ £¬£¬¹ÌÈ»ÖØÒª¿Í»§Î»ÓÚÉ³ÌØ°¢À­²®£¬£¬£¬ £¬£¬µ«¸Ã¹«Ë¾ÔÚÓ¢¹ú¡¢Á¢ÌÕÍð¡¢°¢ÁªÇõ¡¢¿ÆÍþÌØ¡¢¸çÂ×±ÈÑÇ¡¢ÍÁ¶úÆä¡¢°ÍÁÖ¡¢Àè°ÍÄÛºÍÍßŬ°¢Í¼¹²ºÍ¹úÉèÓд¦Ê´¦¡£¡£¡£¡£¡£·¢ÏÖµÄĿ¼Ô̺¬¶à¸öÊý¾Ý¿â±¸·Ý£¬£¬£¬ £¬£¬Ã¿¸ö±¸·Ý¶¼Ô̺¬Óйع«Ë¾Óû§ºÍºÏ×÷ͬ°éµÄ´óÁ¿Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£Õâ´ÎйÃÜÊÂÎñ´øÀ´Á˶àÖÖ·çÏÕ£¬£¬£¬ £¬£¬´ÓÉí·Ý͵ÇÔµ½ÂòÂôÕßÕË»§µÄÊÕÊܺͶÒÏÖ¡£¡£¡£¡£¡£Ð¹Â¶µÄÊý¾ÝÔ̺¬´ÓǰÁùÄ곬¹ý 30 ÍòÓû§µÄÂòÂô»î¶¯£¬£¬£¬ £¬£¬ÒÔ¼°ÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢¹«Ë¾·¢Ë͵ĵç×ÓÓʼþºÍ IP µØÖ·¡£¡£¡£¡£¡£³ÖÓй«Ë¾µç×ÓÓʼþµØÖ·µÄÓû§£¨¿ÉÄÜÊÇÔ±¹¤£©µÄÃÜÂëÒÔÃ÷ÎÄ´ó¾Ö¶³ö¡£¡£¡£¡£¡£ÓÃÓÚ½Ó¼û DTT ÂòÂôƽ̨Óû§ÕÊ»§µÄ¹þÏ£ÃÜÂëÒ²±»Ð¹Â¶¡£¡£¡£¡£¡£Ò»Ð©¿Í»§µÄ¼Òͥסַ¡¢µç»°ºÅÂëºÍ²¿ÃÅÐÅÓþ¿¨ÐÅÏ¢±»Ð¹Â¶¡£¡£¡£¡£¡£


https://securityaffairs.com/158384/security/data-leak-at-fintech-direct-trading-technologies.html