LOCKBIT ¾íÍÁ³ÁÀ´£¬£¬£¬£¬£¬£¬Íþв¶Ô×¼¸ü¶àµ±¾Ö×éÖ¯
°ä²¼¹¦·ò 2024-02-271. LOCKBIT ¾íÍÁ³ÁÀ´£¬£¬£¬£¬£¬£¬Íþв¶Ô×¼¸ü¶àµ±¾Ö×éÖ¯
2ÔÂ26ÈÕ£¬£¬£¬£¬£¬£¬ÔÚ·¨Âɲ¿ÃÅ×¥»ñ LockBit ÍÅ»ïµÄ²¿ÃųÉÔ±ºó£¬£¬£¬£¬£¬£¬LockBit ÍÅ»ï¾íÍÁ³ÁÀ´²¢³ÉÁ¢ÁËеĻù´¡ÉèÊ©¡£¡£¡£¡£¡£¡£¡£NCA ¼°ÆäÈ«ÇòºÏ×÷ͬ°éÒÑ»ñµÃ 1,000 ¶à¸ö½âÃÜÃÜÔ¿£¬£¬£¬£¬£¬£¬ÕâЩÃÜÔ¿½«ÔÊÐí¸ÃÍÅ»ïµÄÊܺ¦ÕßÃâ·Ñ¸´ÔËûÃǵÄÎļþ¡£¡£¡£¡£¡£¡£¡£NCA ½«ÔÚ½«À´¼¸Ìì»ò¼¸ÖÜÄÚÁªÏµÓ¢¹úµÄÊܺ¦Õߣ¬£¬£¬£¬£¬£¬Ìṩ֧³ÖÒÔÔ®ÊÖËûÃǸ´Ô¼ÓÃÜÊý¾Ý¡£¡£¡£¡£¡£¡£¡£LockBitÍŻﲢ²»ÊÇÊÔͼ³ÁÐÂÆô¶¯Æä RaaS ÒµÎñ£¬£¬£¬£¬£¬£¬¶øÊÇÒѾ³ÉÁ¢ÁËеĻù´¡ÉèÊ©£¬£¬£¬£¬£¬£¬²¢ÍþвҪ¶Ôµ±²¿ÃÅÃŽøÐÐÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïÔÚÆäÍøÕ¾ÉÏÔö³¤ÁË 12 ÃûÊܺ¦Õߣ¬£¬£¬£¬£¬£¬ÆäÖÐ 5 ÃûÊܺ¦ÕߵĽØÖ¹ÈÕÆÚÒѵ½¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/159584/cyber-crime/lockbit-gang-resumed-raas.html
2. ºÚ¿Í´Ó Axie Infinity ½áºÏÊ×´´È˵ÄÓ×ÎÒÕË»§ÇÔÈ¡½ü 1000 ÍòÃÀÔª
2ÔÂ24ÈÕ£¬£¬£¬£¬£¬£¬ÊÓÆµÓÎÏ· Axie Infinity ºÍÓÐ¹Ø Ronin Network µÄ½áºÏÊ×´´ÈËÖ®Ò»µÄÓ×ÎÒÕË»§Öнü 1000 ÍòÃÀÔªµÄ¼ÓÃÜÇ®±Ò±»µÁ¡£¡£¡£¡£¡£¡£¡£±¨Â·³Æ£¬£¬£¬£¬£¬£¬Jeff ¡°Jihoz¡± Zirlin µÄÇ®°ü±»ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬ËðʧÁË 3,248 ¸öÒÔÌ«±Ò£¬£¬£¬£¬£¬£¬Ô¼ºÏ 970 ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£ÖÜËÄÍí£¬£¬£¬£¬£¬£¬ÆëÁÖÔÚÉ罻ýÌåÉÏ֤ʵ£¬£¬£¬£¬£¬£¬ËûµÄÁ½¸öÕË»§Ô⵽й¶¡£¡£¡£¡£¡£¡£¡£Ronin Network ÊÇAxie InfinityµÄ»ù´¡£¬£¬£¬£¬£¬£¬Axie Infinity Õ¼ÓлùÓÚÒÔÌ«·»µÄ¼´Í漴׬¾¼Ã¡£¡£¡£¡£¡£¡£¡£ËüÔÚ¶«ÄÏÑdzö¸ñÊÜ»¶Ó¡£¡£¡£¡£¡£¡£¡£2022 Äê 3 Ô£¬£¬£¬£¬£¬£¬ºÚ¿Í´Ó¸ÃϵͳÖÐÇÔÈ¡ÁË 6 ÒÚÃÀÔªµÄ¼ÓÃÜÇ®±Ò£¬£¬£¬£¬£¬£¬ÃÀ¹ú¼ì²ì¹ÙËæºó½«Õâ´Î¹¥»÷¹é×ïÓÚ³¯Ïʹú¶ÈÖ§³ÖµÄÍøÂç·¸×ï×éÖ¯ Lazarus Group¡£¡£¡£¡£¡£¡£¡£·ÖÎöʦ׷×Ùµ½´Ó Zirlin ÕË»§±»µÁµÄ×ʽðÀ´×Ô Tornado Cash µÄ»î¶¯£¬£¬£¬£¬£¬£¬Tornado Cash ÊÇÒ»¸öÖ¼ÔÚ°µ²Ø¼ÓÃÜÇ®±ÒÆðÔ´µÄ»ìºÏÆ÷¡£¡£¡£¡£¡£¡£¡£¾ÝÃÀ¹úµ±¾Ö³Æ£¬£¬£¬£¬£¬£¬Lazarus ʹÓûìºÏÆ÷Ï´Ç® 2022 ÄêºÚ¿Í¹¥»÷ÖеÄ×ʽ𣬣¬£¬£¬£¬£¬²¢µ¥¶ÀÔì²ÃÁËTornado Cash¡£¡£¡£¡£¡£¡£¡£
https://therecord.media/hackers-steal-millions-from-axie-infinity-founder-personal-accounts?&web_view=true
3. Linux¹¥»÷ÖÐʹÓõÄNood RAT£¨Gh0st RATµÄ±äÖÖ£©µÄ·ÖÎö
2ÔÂ26ÈÕ£¬£¬£¬£¬£¬£¬AhnLab °²È«µý±¨ÖÐÐÄ (ASEC) ×î½ü·¢ÏÖ Nood RAT ±»ÓÃÓÚ¶ñÒâÈí¼þ¹¥»÷¡£¡£¡£¡£¡£¡£¡£Nood RAT ÊÇÔÚ Linux ÉÏÔËÐÐµÄ Gh0st RAT µÄ±äÌå¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜÓë Windows µÄ Gh0st RAT Ïà±È£¬£¬£¬£¬£¬£¬Linux µÄ Gh0st RAT ÊýÁ¿½ÏÉÙ£¬£¬£¬£¬£¬£¬µ« Linux µÄ Gh0st RAT °¸ÀýÈÔÔÚ²»ÐÝÍøÂç¡£¡£¡£¡£¡£¡£¡£Æ¾¾Ý´úÂëÓë Gh0st RAT [1]֮ǰ´úÂëµÄÀàËÆÐÔ£¬£¬£¬£¬£¬£¬Nood RAT ±»¹éÀàΪ Gh0st RAT µÄ±äÌå¡£¡£¡£¡£¡£¡£¡£ÕÒµ½ÁË×îпª·¢ÖÐʹÓõĹ¹½¨Æ÷£¬£¬£¬£¬£¬£¬²¢½«Æä¶¨ÃûΪNood RAT£¬£¬£¬£¬£¬£¬ÓÉÓÚ×÷Õß½«Æä¶¨ÃûΪNood¡£¡£¡£¡£¡£¡£¡£×Ô2018ÄêÒÔÀ´£¬£¬£¬£¬£¬£¬Nood RATÒѱ»ÓÃÓÚ¸÷Àà·ì϶¹¥»÷¡£¡£¡£¡£¡£¡£¡£¹ÌÈ»×î½üûÓз¢ÏÖ¾ßÌåµÄ·ì϶¹¥»÷°¸Àý£¬£¬£¬£¬£¬£¬µ«Æ¾¾ÝVirusTotalÍøÕ¾µÄÊý¾Ý£¬£¬£¬£¬£¬£¬°¸ÀýÔÚ²»ÐÝ·¢ÏÖ¡£¡£¡£¡£¡£¡£¡£±¾ÎijÁµã½éÉÜÁË´Óǰ¼¸Äê·¢ÏֵĶñÒâÈí¼þ±äÌ壬£¬£¬£¬£¬£¬²¢Óë¹¹½¨Õßһ·¶ÔÆä½øÐÐÁË·ÖÎö¡£¡£¡£¡£¡£¡£¡£
https://asec.ahnlab.com/en/62144/
4. ¼ÓÄôó»Ê¼ÒÆï¾¯ (RCMP) ¹ÙÍøÔâ·êÍøÂç¹¥»÷
2ÔÂ25ÈÕ£¬£¬£¬£¬£¬£¬¼ÓÄôóÁª¹úºÍ¹ú¶È·¨ÂÉ»ú¹¹¼ÓÄôó»Ê¼ÒÆï¾¯ (RCMP) Ôâ·êÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¡£»£»£»£»£»Ê¼ÒÆï¾¯»¹Í¨ÖªÁËÒþÖÔרԱ°ì¹«ÊÒ (OPC)¡£¡£¡£¡£¡£¡£¡£¼ÓÄôó»Ê¼ÒÆï¾¯½²»°ÈËÔÚÏò¼ÓÄôó¹ã²¥¹«Ë¾ÐÂÎŰ䷢µÄÒ»·ÝÉêÃ÷ÖаµÊ¾£º¡°Çé¿öÔÚѸËÙ·¢Õ¹£¬£¬£¬£¬£¬£¬µ«Ä¿Ç°£¬£¬£¬£¬£¬£¬¼ÓÄôó»Ê¼ÒÆï¾¯µÄÐж¯Ã»ÓÐÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬¼ÓÄôóÈ˵ݲȫҲûÓÐÊܵ½ÈκÎÒÑÖªµÄÍþв¡£¡£¡£¡£¡£¡£¡£¡± ¡°¹ÌÈ»Èç´ËÑϳÁµÄÎ¥¹æÐÐΪÁîÈËÕ𾪣¬£¬£¬£¬£¬£¬µ«¼±¾çµÄ¹¤×÷ºÍ²ÉÈ¡µÄ»º½âÕ½ÊõÅú×¢¼ÓÄôó»Ê¼ÒÆï¾¯Îª¼ì²âºÍÔ¤·À´ËÀàÍþвËù²ÉÈ¡µÄ³ÁÒª²½Öè¡£¡£¡£¡£¡£¡£¡£¡±»Ê¼ÒÆï¾¯°µÊ¾£¬£¬£¬£¬£¬£¬²»ÖªÂ·¶Ô±í¹ú¾¯Ô±ºÍµý±¨²¿ÃÅÓÐÈκÎÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¼ÓÄôó·¨ÂÉ»ú¹¹Ã»ÓÐÌṩÓйØÍøÂç¹¥»÷µÄ¾ßÌåÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£2023 Äê 11 Ô£¬£¬£¬£¬£¬£¬¼ÓÄô󵱾ÖÔÚÍþвÐÐΪÕßÈëÇÔìäÁ½Ãû³Ð°üÉ̺ó Åû¶ÁËһ·Êý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£¼ÓÄô󵱾ְ䷢£¬£¬£¬£¬£¬£¬ÆäÁ½¼Ò³Ð°üÉÌ Brookfield Global Relocation Services (BGRS) ºÍ SIRVA Worldwide Relocation & Moving Services Ôâµ½ºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬µ¼ÖÂÊôÓÚÊýÁ¿²»ÏêÈ·µ±¾Ö¹ÍÔ±µÄÃô¸ÐÐÅÏ¢±»Ð¹Â¶¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/159568/hacking/cyber-attack-hit-royal-canadian-mounted-police.html
5. ÀûÓà ScreenConnect ·ì϶²¿Êð¶ñÒâÈí¼þ
2ÔÂ25ÈÕ£¬£¬£¬£¬£¬£¬Sophos X-Ops ³Áµã¹Ø×¢ÁË ConnectWise ScreenConnect ×°Öã¨Ò»ÖÖ¿í·ºÊ¹ÓõÄÔ¶³Ì¼à¿ØºÍÖÎÀíÈí¼þ£©Öзì϶ÀûÓõÄÁîÈËÓÇÓôµÄÇ÷Ïò¡£¡£¡£¡£¡£¡£¡£×î½üÅû¶µÄScreenConnect·ì϶£¨CVE-2024-1709¡¢CVE-2024-1708£©±ØÒªÁ¢¼´²ÉÈ¡Ðж¯¡£¡£¡£¡£¡£¡£¡£Õë¶Ô±¾µØ×°ÖÃµÄ¿í·ºÀûÓñØÒª¼±¾ç½¨²¹¡¢×Ô¶¯ÍþвËÑË÷ºÍ¼ÓÇ¿µÄÍøÂç·ÀÓù¡£¡£¡£¡£¡£¡£¡£2024 Äê 2 Ô 19 ÈÕ£¬£¬£¬£¬£¬£¬ConnectWise ¾ÍÓ°ÏìÆä ScreenConnect Èí¼þ¾É°æ±¾µÄÁ½¸öÑϳÁ·ì϶·¢³ö¾¯±¨¡£¡£¡£¡£¡£¡£¡£ÈôÊDz»½¨²¹ÕâЩ·ì϶£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜ»á»ñµÃÖ´ÐÐÔ¶³Ì´úÂë»ò½Ó¼û»úÃÜÊý¾ÝµÄÄÜÁ¦¡£¡£¡£¡£¡£¡£¡£ÕâЩȱµã±»Ö¸¶¨Îª CVE-2024-1709 ºÍ CVE-2024-1708£¬£¬£¬£¬£¬£¬Éæ¼°·þÎñÆ÷Èí¼þÖеÄÉí·ÝÑéÖ¤ÈÆ¹ýºÍõè¾¶±éÀúÎÊÌ⣬£¬£¬£¬£¬£¬¶ÔʹÓÃÊÜÓ°ÏìÈí¼þ°æ±¾µÄ×éÖ¯×é³ÉÑϳÁÍþв¡£¡£¡£¡£¡£¡£¡£Õë¶ÔÕâЩ·ì϶£¬£¬£¬£¬£¬£¬ConnectWiseÒѰ䲼ScreenConnect²¹¶¡£¬£¬£¬£¬£¬£¬½¨ÒéËùÓÐЧ»§Éý¼¶µ½23.9.8»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£¡£¡£
https://securityonline.info/screenconnect-vulnerabilities-exploited-to-deploy-malware/
6. PyPI Èí¼þ°üdjango-log-tracker±»ÓÃÀ´´«²¼ Nova Sentinel ¶ñÒâÈí¼þ
2ÔÂ23ÈÕ£¬£¬£¬£¬£¬£¬Python °üË÷Òý (PyPI) ´æ´¢¿âÉϵÄÒ»¸öÐÝÃß°üÔÚ½üÁ½Äêºó½øÐÐÁ˸üУ¬£¬£¬£¬£¬£¬ÒÔ´«²¼ÃûΪ Nova Sentinel µÄÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£¾ÝÈí¼þ¹©¸øÁ´°²È«¹«Ë¾ Phylum ³Æ£¬£¬£¬£¬£¬£¬¸ÃÈí¼þ°üÃûΪdjango-log-tracker £¬£¬£¬£¬£¬£¬ÓÚ 2022 Äê 4 Ô³õ´Î°ä²¼µ½ PyPI£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÓÚ 2024 Äê 2 Ô 21 ÈÕ¼ì²âµ½¸Ã¿âµÄÒì³£¸üС£¡£¡£¡£¡£¡£¡£¹ÌÈ»Á´½ÓµÄ GitHub ´æ´¢¿â×Ô 2022 Äê 4 Ô 10 ÈÕÒÔÀ´Ò»ÏòûÓиüУ¬£¬£¬£¬£¬£¬µ«¶ñÒâ¸üеÄÒýÈëÅú×¢ÊôÓÚ¿ª·¢ÈËÔ±µÄ PyPI ÕÊ»§¿ÉÄÜÊܵ½ÇÖº¦¡£¡£¡£¡£¡£¡£¡£Django-log-trackerÆù½ñΪֹÒѱ»ÏÂÔØ 3,866 ´Î£¬£¬£¬£¬£¬£¬ÆäÖÐµØÆ¦°æ±¾ (1.0.4) ÔÚ°ä²¼Ö®ÈÕÏÂÔØÁË 107 ´Î¡£¡£¡£¡£¡£¡£¡£¸ÃÈí¼þ°ü²»ÔÙÄܹ»´Ó PyPI ÏÂÔØ¡£¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2024/02/dormant-pypi-package-compromised-to.html?&web_view=true


¾©¹«Íø°²±¸11010802024551ºÅ