Otelier¾ÆµêÖÎÀíÆ½Ì¨Ôâ·ê´ó¹æÄ£Êý¾Ýй¶

°ä²¼¹¦·ò 2025-01-20

1. Otelier¾ÆµêÖÎÀíÆ½Ì¨Ôâ·ê´ó¹æÄ£Êý¾Ýй¶


1ÔÂ17ÈÕ£¬£¬£¬£¬£¬ £¬2024Äê7ÔÂÖÁ10ÔÂÆÚ¼ä£¬£¬£¬£¬£¬ £¬¾ÆµêÖÎÀíÆ½Ì¨Otelier£¨Ç°ÉíΪMyDigitalOffice£©Ôâ·êÁËÑϳÁµÄÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£ÍþвÐÐΪÕ߳ɹ¦ÈëÇÔìäAmazon S3ÔÆ´æ´¢£¬£¬£¬£¬£¬ £¬ÇÔÈ¡ÁËÊý°ÙÍò¿ÍÈ˵ÄÓ×ÎÒÐÅÏ¢ÒÔ¼°ÍòºÀ¡¢Ï£¶û¶Ù¡¢¿­ÔõȳÛÃû¾ÆµêÆ·ÅÆµÄÔ¤Ô¼ÐÅÏ¢£¬£¬£¬£¬£¬ £¬×ÜÁ¿½ü8TB¡£¡£¡£¡£¡£OtelierÒÑÈ·ÈÏÕâ´ÎÈëÇÖ£¬£¬£¬£¬£¬ £¬²¢ÕýÓëÊÜÓ°Ïì¿Í»§¹µÍ¨£¬£¬£¬£¬£¬ £¬Í¬Ê±ÀñƸÁ˶¥¼âÍøÂ簲ȫר¼ÒÍŶӽøÐÐÈ«ÃæÈ¡Ö¤·ÖÎöºÍϵͳÑéÖ¤¡£¡£¡£¡£¡£ÎªÔ¤·ÀÀàËÆÊÂÎñÔٴβúÉú£¬£¬£¬£¬£¬ £¬OtelierÒѽûÓÃÓйØÕË»§²¢¼ÓÇ¿ÍøÂ簲ȫºÍ̸¡£¡£¡£¡£¡£¾ÝÍþвÕßй©£¬£¬£¬£¬£¬ £¬ËûÃÇ×î³õͨ¹ýÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ»ñÈ¡ÁËÒ»ÃûÔ±¹¤µÄµÇ¼ÐÅÏ¢£¬£¬£¬£¬£¬ £¬½ø¶øÈëÇÖÁËAtlassian·þÎñÆ÷£¬£¬£¬£¬£¬ £¬²¢ÀûÓÃÕâЩƾ֤»ñÈ¡Á˸üÎÞÊý¾Ý£¬£¬£¬£¬£¬ £¬Ô̺¬S3´æ´¢Í°µÄ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£ÍòºÀ¾ÆµêÒÑ֤ʵÆäÊܵ½Ó°Ï죬£¬£¬£¬£¬ £¬²¢ÔÝÍ£ÁËOtelierÌṩµÄ×Ô¶¯»¯·þÎñ£¬£¬£¬£¬£¬ £¬µ«Ç¿µ÷ÆäϵͳδÔÚÕâ´Î¹¥»÷ÖÐÔâµ½ÈëÇÖ¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬ £¬Ð¹Â¶µÄÊý¾ÝÑù±¾ÏÔʾ£¬£¬£¬£¬£¬ £¬¾Æµê¿ÍÈ˵ÄÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂëºÍµç×ÓÓʼþµØÖ·µÈÓ×ÎÒÐÅÏ¢Òѱ»µÁÈ¡£¡£¡£¡£¡£¬£¬£¬£¬£¬ £¬²¢±»Ôö³¤µ½¡°Have I Been Pwned¡±ÍøÕ¾ÉϹ©È˲éÎÊ¡£¡£¡£¡£¡£Ö»¹ÜÃÜÂëºÍÕ˵¥ÐÅϢδ±»µÁ£¬£¬£¬£¬£¬ £¬µ«Óû§ÈÔÐ辯ÌèÕë¶Ô´Ë·ì϶µÄ¿ÉÒɵç×ÓÓʼþºÍÍøÂç´¹µö¹¥»÷¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/otelier-data-breach-exposes-info-hotel-reservations-of-millions/


2. PyPIÏÖ¡°pycord-self¡±¶ñÒâ°ü£¬£¬£¬£¬£¬ £¬Õë¶ÔDiscord¿ª·¢ÈËÔ±ÇÔÈ¡ÁîÅÆÖ²ÈëºóÃÅ


1ÔÂ17ÈÕ£¬£¬£¬£¬£¬ £¬Python°üË÷Òý£¨PyPI£©ÉϳöÏÖÁËÒ»¿îÃûΪ¡°pycord-self¡±µÄ¶ñÒâÈí¼þ°ü£¬£¬£¬£¬£¬ £¬ËüÕë¶ÔµÄÊÇDiscord¿ª·¢ÈËÔ±¡£¡£¡£¡£¡£Õâ¿î¶ñÒâ°ü·ÂÕÕÁ˹ãÊÜ»¶Ó­µÄ¡°discord.py-self¡±°ü£¬£¬£¬£¬£¬ £¬Òѱ»ÏÂÔØÔ¼885´Î¡£¡£¡£¡£¡£Ö»¹ÜËüÌṩÁ˺Ϸ¨ÏîÖ÷ÕÅÖ°ÄÜ£¬£¬£¬£¬£¬ £¬µ«ÊµÔòÔ̺¬Ö´ÐÐÁ½ÏîÖØÒª¶ñÒâ²Ù×÷µÄ´úÂ룺һÊÇÇÔÈ¡DiscordÉí·ÝÑéÖ¤ÁîÅÆ²¢½«Æä·¢Ë͵½±í²¿URL£¬£¬£¬£¬£¬ £¬¼´±ãË«³É·ÖÉí·ÝÑéÖ¤± £»£»£»£» £»£»£»¤´¦Óڻ״̬£¬£¬£¬£¬£¬ £¬¹¥»÷ÕßÒ²ÄÜʹÓÃÕâЩÁîÅÆ½Ù³Ö¿ª·¢ÈËÔ±µÄDiscordÕÊ»§ £»£»£»£» £»£»£»¶þÊÇͨ¹ý¶Ë¿Ú6969ÓëÔ¶³Ì·þÎñÆ÷³ÉÁ¢ÓƾÃÏνӣ¬£¬£¬£¬£¬ £¬³ÉÁ¢ºóÃÅ»úÔ죬£¬£¬£¬£¬ £¬Èù¥»÷Õß¿ÉÄܳÖÐø½Ó¼ûÊܺ¦ÕßµÄϵͳ¡£¡£¡£¡£¡£Socket×êÑÐÈËÔ±¶Ô´Ë½øÐÐÁ˾ßÌå·ÖÎö¡£¡£¡£¡£¡£Òò¶ø£¬£¬£¬£¬£¬ £¬½¨ÒéÈí¼þ¿ª·¢ÈËÔ±ÔÚ×°ÖÃÈí¼þ°üʱ£¬£¬£¬£¬£¬ £¬Îñ±ØÑéÖ¤´úÂëÊÇ·ñÀ´×Ô¹Ù·½×÷Õߣ¬£¬£¬£¬£¬ £¬²¢²é³­Èí¼þ°üµÄÃû³Æ£¬£¬£¬£¬£¬ £¬ÒÔ½µµÍ³ÉΪÊܺ¦ÕߵķçÏÕ¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬£¬ £¬Ê¹ÓÿªÔ´¿âʱ£¬£¬£¬£¬£¬ £¬½¨Òé²é³­´úÂëÖÐÊÇ·ñ´æÔÚ¿ÉÒɺ¯Êý£¬£¬£¬£¬£¬ £¬²¢ÀûÓÃɨÃ蹤¾ß¼ì²âºÍ×èÖ¹¶ñÒâÈí¼þ°ü¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/malicious-pypi-package-steals-discord-auth-tokens-from-devs/


3. Lazarus×éÖ¯Õë¶Ô¿ª·¢ÈËÔ±ÌáÒé¡°99ºÅÐж¯¡±ÇÔÈ¡Ãô¸ÐÊý¾Ý


1ÔÂ17ÈÕ£¬£¬£¬£¬£¬ £¬³¯Ïʵ±¾ÖÖ§³ÖµÄLazarus×éÖ¯ÔÚ·¢Õ¹ÃûΪ¡°99ºÅÐж¯¡±µÄ³ÖÐø¹¥»÷»î¶¯£¬£¬£¬£¬£¬ £¬Õë¶ÔÈí¼þ¿ª·¢ÈËÔ±ÇÔÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£¡£¡£Õâ´Î»î¶¯±ê־ȡLazarus×éÖ¯¹¥»÷Õ½ÊõµÄÑݱ䣬£¬£¬£¬£¬ £¬´Ó¿í·ºµÄÍøÂç´¹µö¹¥»÷תÏòÕë¶Ô¼¼Êõ¹©¸øÁ´ÖеĿª·¢ÈËÔ±½øÐÐÓÐÕë¶ÔÐԵĹ¥»÷¡£¡£¡£¡£¡£¹¥»÷Õß¼ÙÒâÕÐÆ¸ÈËÔ±ÔÚLinkedInµÈƽ̨ÉÏÁªÏµÖ¸±ê£¬£¬£¬£¬£¬ £¬ÓÕµ¼Êܺ¦Õ߿ˡ¶ñÒâGitHub´æ´¢¿â£¬£¬£¬£¬£¬ £¬Ö´ÐÐÆäÖеĴúÂëºóÏνӵ½Óɹ¥»÷Õß½ÚÔìµÄºÅÁîºÍ½ÚÔì·þÎñÆ÷¡£¡£¡£¡£¡£¸Ã·þÎñÆ÷ʹÓø߶ȻìºÏµÄPython½ÅÕý±¾Ìӱܼì²â£¬£¬£¬£¬£¬ £¬²¢Õë¶ÔÌØ¶¨Ö¸±ê¶¯Ì¬¶¨Ôì¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¸Ã»î¶¯²¿ÊðÁËÓµÓÐÄ£¿£¿£¿£¿£¿£¿é»¯×é¼þµÄ¶à½×¶Î¶ñÒâÈí¼þϵͳ£¬£¬£¬£¬£¬ £¬ÒÔÇÔÈ¡¿ª·¢ÈËÔ±µÄÔ´´úÂë¡¢»úÃÜ¡¢ÅäÖÃÎļþÒÔ¼°¼ÓÃÜÇ®±ÒÇ®°üÃÜÔ¿µÈÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£SecurityScorecard¶½´Ù¿ª·¢ÈËÔ±²ÉÈ¡×Ô¶¯µÄ°²È«´ëÊ©£¬£¬£¬£¬£¬ £¬Èç¼ÓÇ¿´úÂë´æ´¢¿âÑéÖ¤¡¢Ê¹Óø߼¶¶Ëµã°²È«½â¾ö¹æ»®¼ì²âÒì³ £»£»£»£» £»£»£»î¶¯¡¢ÔÚÆ½Ì¨ÉÏÑéÖ¤ÕÐÆ¸ÈËÔ±ºÍ¹¤×÷»úÓö£¬£¬£¬£¬£¬ £¬²¢°ÑÎÕ¼ø±ðΣÏÕÐźŵÄ֪ʶ¡£¡£¡£¡£¡£


https://www.infosecurity-magazine.com/news/lazarus-developers-data-theft/


4. ºÚ¿Í¡°0mid16B¡±°ä·¢ÈëÇÖMedSave£¬£¬£¬£¬£¬ £¬ÇÔÈ¡561GBÊý¾Ý²¢´òËãÏúÊÛ


1ÔÂ17ÈÕ£¬£¬£¬£¬£¬ £¬ÃûΪ¡°0mid16B¡±µÄºÚ¿ÍÖÜÈý°ä·¢Òѳɹ¦ÈëÇÖÓ¡¶È´óÐ͵ÚÈý·½ÖÎÀí»ú¹¹MedSave£¬£¬£¬£¬£¬ £¬ÇÔÈ¡ÁË561GBµÄÊý¾Ý¿â£¬£¬£¬£¬£¬ £¬Ô̺¬³¬¹ý1000ÍòÈ˵ÄÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬ £¬ÆäÖв»·¦¸ß¹Ü×ÊÁÏ£¬£¬£¬£¬£¬ £¬ÇÒÊý¾Ý½ØÖ¹ÖÁ2025Äê1ÔÂ8ÈÕ¡£¡£¡£¡£¡£0mid16Bδй©ÈëÇÖ¼¿Á©£¬£¬£¬£¬£¬ £¬µ«Ðû³ÆMedSave³¤¹¦·òδ¾õ²ìÆä´æÔÚ£¬£¬£¬£¬£¬ £¬ÇÒÔÚ1ÔÂ12ÈÕÖÁ15ÈÕÆÚ¼äÈý´Î½øÈëϵͳ²¢×ÌÈÅÆäÔË×÷¡£¡£¡£¡£¡£Ö»¹ÜδÏòMedSaveÌá³ö¾ßÌåÀÕË÷½ð¶î£¬£¬£¬£¬£¬ £¬0mid16BÆ·ÆÀÆä°²È«·À»¤ÓÄ΢£¬£¬£¬£¬£¬ £¬Ö¸³ö¹«Ë¾Î´×°Ö÷À²¡¶¾Èí¼þ£¬£¬£¬£¬£¬ £¬ÇÒÔÚÃ÷Öª·ì϶´æÔÚµÄÇé¿öÏÂÈÔ³ÁÆô·þÎñÆ÷£¬£¬£¬£¬£¬ £¬Ê¹ÆäµÃÒÔµÈÏд«Êä´óÁ¿Êý¾Ý¶øÎ´´¥·¢¾¯±¨¡£¡£¡£¡£¡£MedSaveÍøÕ¾Ä¿Ç°ÎÞ·¨½Ó¼û£¬£¬£¬£¬£¬ £¬DataBreachesÒѳ¢ÊÔͨ¹ý¶àÇþ·ÁªÏµMedSave·î¸æÆäÇé¿ö£¬£¬£¬£¬£¬ £¬µ«ÉÐδÊÕµ½»Ø¸´¡£¡£¡£¡£¡£0mid16B°µÊ¾ÓÐÒâÏúÊÛ²¿ÃÅÊý¾Ý²¢¹«¿ª·Ç¿Í»§Êý¾Ý£¬£¬£¬£¬£¬ £¬´ËÊÂÓдýMedSave½øÒ»²½»ØÓ¦¡£¡£¡£¡£¡£


https://databreaches.net/2025/01/17/medsave-health-insurance-tpa-hacked-firm-has-yet-to-comment-or-respond/


5. ·ÂÕÕBlack BastaÊÖ·¨µÄÍøÂç¹¥»÷¶Ô×¼SlashNext¿Í»§


1ÔÂ15ÈÕ£¬£¬£¬£¬£¬ £¬SlashNextµÄһλ¿Í»§Ôâ·êÁË·ÂÕÕ³ôÃûÔ¶ÑïµÄBlack BastaÀÕË÷Èí¼þÍÅ»ïÊÖ·¨µÄÍøÂç¹¥»÷¡£¡£¡£¡£¡£Ôڶ̶Ì90·ÖÖÓÄÚ£¬£¬£¬£¬£¬ £¬¹¥»÷ÕßÏò22¸öÓû§ÊÕ¼þÏä·¢ËÍÁË1165·â¶ñÒâÓʼþ£¬£¬£¬£¬£¬ £¬Ì°Í¼ÓÕÆ­Óû§µã»÷¶ñÒâÁ´½Ó¡£¡£¡£¡£¡£SlashNextµÄ×êÑÐÈËÔ±½ÒʾÁËÕâ´Î¹¥»÷ѸËÙÇÒ¾«×¼£¬£¬£¬£¬£¬ £¬Ê¹ÓÃÁËÓëBlack BastaÀàËÆµÄÊÖ·¨£¬£¬£¬£¬£¬ £¬Ö¼ÔÚÈÃÓû§´ëÊÖ²»¼°²¢Èƹý´«Í³°²È«´ëÊ©¡£¡£¡£¡£¡£¹¥»÷ÕßÀûÓÃÀÕË÷Èí¼þȦÌ×£¬£¬£¬£¬£¬ £¬¼Ù×°³ÉÊ¢ÐÐÆ½Ì¨·¢ËÍÐéαÓʼþ£¬£¬£¬£¬£¬ £¬Ê¹Óÿ´ËÆÎÞº¦µÄÓòÃûºÍÌØÊâ×Ö·ûµÄÖ÷ÌâÐУ¬£¬£¬£¬£¬ £¬Õë¶Ô·ÖÆçÓû§½ÇÉ«Ìá¸ß¹Ø×¢¶È¡£¡£¡£¡£¡£ËûÃÇͨ¹ý¿´ËƺϷ¨µÄÓʼþ¸²³ä¹«¼þÏ䣬£¬£¬£¬£¬ £¬Ôì×÷»ìÂÒ£¬£¬£¬£¬£¬ £¬ÓÕʹÓû§µã»÷Á´½Ó¡£¡£¡£¡£¡£µ±Óû§¾ª»Ìʧ´ëʱ£¬£¬£¬£¬£¬ £¬¹¥»÷Õß¼ÙÒâITÖ§³ÖȾָ£¬£¬£¬£¬£¬ £¬ÓÕÆ­Óû§×°ÖÃÔ¶³Ì½Ó¼ûÈí¼þ£¬£¬£¬£¬£¬ £¬´Ó¶øÔÚϵͳÖÐÕ¾ÎȽŸú£¬£¬£¬£¬£¬ £¬¿ÉÄÜ´«²¼¶ñÒâÈí¼þ»òÇÔÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£¡£¡£ÐÒÔ˵ÄÊÇ£¬£¬£¬£¬£¬ £¬SlashNextµÄ¼¯³ÉÔÆÓʼþ°²ÕûϵͳѸËÙ¼ø±ð³öΣÏÕÐźţ¬£¬£¬£¬£¬ £¬ÊµÊ±Ó¦¶Ô¡£¡£¡£¡£¡£ÕâÒ»ÊÂÎñ͹ÏÔÁËÍøÂ簲ȫÍþвµÄÈÕÒæ¸´ÔÓÐÔ£¬£¬£¬£¬£¬ £¬¹¥»÷ÕßʹÓÃÏȽø¼¼Êõ¶ã±Ü´«Í³°²È«´ëÊ©¡£¡£¡£¡£¡£Òò¶ø£¬£¬£¬£¬£¬ £¬×éÖ¯Ó¦ÓÅÏÈ˼¿¼Íþв¼ì²âºÍÏìÓ¦£¬£¬£¬£¬£¬ £¬¶¨ÆÚ½øÐа²È«ÆÀ¹À£¬£¬£¬£¬£¬ £¬ÒÔ¼ø±ð·ì϶²¢ÌáÉýÕûÌ尲ȫÐÔ¡£¡£¡£¡£¡£


https://hackread.com/black-basta-cyberattack-hits-inboxes-with-1165-emails/


6. Star Blizzardд¹µö»î¶¯¶Ô×¼WhatsAppÕË»§


1ÔÂ19ÈÕ£¬£¬£¬£¬£¬ £¬¶íÂÞ˹Ãñ×å¹ú¶ÈÐÐΪÕßStar Blizzard½üÆÚ·¢Õ¹ÁËÒ»ÏîеÄÓã²æÊ½ÍøÂç´¹µö»î¶¯£¬£¬£¬£¬£¬ £¬×¨ÃŹ¥»÷µ±¾Ö¡¢±í½»¡¢¹ú·ÀÕþ²ß¡¢¹ú¼Ê¹ØÏµ¼°ÎÚ¿ËÀ¼ÔöÔ®×éÖ¯µÈÖ¸±êµÄWhatsAppÕË»§¡£¡£¡£¡£¡£¸Ã»î¶¯ÓÚ2024Äê11ÔÂÖÐÑ®±»Î¢ÈíÍþвµý±¨»ã±¨½Òʾ£¬£¬£¬£¬£¬ £¬±ê־ȡStar BlizzardΪӦ¶ÔÕ½ÊõºÍ¼¼ÊõÆØ¹âËù×öµÄÕ½Êõת±ä¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýµç×ÓÓʼþ¼ÙÒâÃÀ¹úµ±¾Ö¹ÙÔ±£¬£¬£¬£¬£¬ £¬ÓÕÆ­Ö¸±ê²ÎÓëÖ§³ÖÎÚ¿ËÀ¼µÄ·Çµ±¾Ö×éÖ¯WhatsAppȺ×飬£¬£¬£¬£¬ £¬ÓʼþÖÐÔ̺¬°Ü»µµÄ¶þάÂ룬£¬£¬£¬£¬ £¬ÈôÊܺ¦Õß»ØÓ¦£¬£¬£¬£¬£¬ £¬Ôò»á±»Êèµ¼ÖÁÐéÎ±ÍøÒ³£¬£¬£¬£¬£¬ £¬ÒªÇóɨÃèеĶþάÂ룬£¬£¬£¬£¬ £¬ÊµÔòÊǽ«¹¥»÷ÕßÉ豸Á´½ÓÖÁÊܺ¦ÕßWhatsAppÕË»§¡£¡£¡£¡£¡£Î¢ÈíÖ¸³ö£¬£¬£¬£¬£¬ £¬Ò»µ©Êܺ¦Õß²Ù×÷£¬£¬£¬£¬£¬ £¬¹¥»÷Õß¼´¿É½Ó¼ûÆäWhatsAppÐÂÎÅ£¬£¬£¬£¬£¬ £¬²¢ÀûÓòå¼þÇÔÈ¡Êý¾Ý¡£¡£¡£¡£¡£Õâ´Î¹¥»÷ÒÀÀµÉç»á¹¤³Ìѧ£¬£¬£¬£¬£¬ £¬²»Éæ¼°¶ñÒâÈí¼þ£¬£¬£¬£¬£¬ £¬Óû§Ð辯Ìèδ¾­ÒªÇóµÄͨѶ£¬£¬£¬£¬£¬ £¬³ö¸ñÊDzÎÓëȺ×éµÄÔ¼Ç룬£¬£¬£¬£¬ £¬²¢¶¨ÆÚ²é³­ÓëWhatsAppÕË»§¹ØÁªµÄÉ豸¡£¡£¡£¡£¡£Õâ´Î»î¶¯Åú×¢£¬£¬£¬£¬£¬ £¬Ö»¹ÜStar BlizzardÔÚ2024Äê10ÔµĻÖжϺó²¿ÃÅÓòÃû±»²é·â£¬£¬£¬£¬£¬ £¬µ«ÆäÈÔͨ¹ýË÷Çóй¥»÷ý½é³ÖÐøÐж¯¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/star-blizzard-hackers-abuse-whatsapp-to-target-high-value-diplomats/