CarlsbadµÄ¹«Ë¾ÔâǰԱ¹¤Åê»÷£¬1200¸öOffice 365ÕÊ»§É¾³ý£»CNAѬȾPhoenix£¬1.5Íǫ̀É豸±»¼ÓÃÜ

Ðû²¼Ê±¼ä 2021-03-26

1.CarlsbadµÄ¹«Ë¾ÔâǰԱ¹¤Åê»÷£¬1200¸öOffice 365ÕÊ»§±»É¾³ý


1.jpg


ÃÀ¹úCarlsbadµÄIT×Éѯ¹«Ë¾Ô⵽ǰԱ¹¤Deepanshu KherµÄÅê»÷£¬1200¸öOffice 365ÕÊ»§±»É¾³ý¡£KherÓÚ2018Äê5Ô±»Ô­¹«Ë¾½â¹Í£¬Ö®ºó»Øµ½ÁËÓ¡¶È²¢ÓÚͬÄê8ÔÂ8ÈÕÈëÇÖÁ˸ù«Ë¾£¬É¾³ýÆä1200¶à¸öMicrosoft Office 365ÕÊ»§£¨×ܹ²1500¸ö£©¡£µ¼Ö¹«Ë¾Ô±¹¤ÎÞ·¨Ê¹Óõç×ÓÓʼþ¡¢ÁªÏµÈËÁÐ±í¡¢»áÒéÈÕÀú¡¢Îĵµ¡¢ÊÓÆµºÍÒôƵ»áÒéµÈ·þÎñ£¬¹«Ë¾±»ÆÈ¹Ø±ÕÁ½Ì죬ºóÓÖ»¨·ÑÊýÔÂÍêÈ«»Ö¸´ÔËÓª£¬ËùÉæÓöȸߴï560000ÃÀÔª¡£KherÓÚ½ñÄê1ÔÂ11ÈÕ±»²¶£¬±»Åд¦2ÄêͽÐÌ£¬·£¿î567084ÃÀÔª¡£    


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/resentful-employee-deletes-1-200-microsoft-office-365-accounts-gets-prison/


2.CNAѬȾPhoenix CryptoLocker£¬1.5Íò¶ą̀É豸±»¼ÓÃÜ


2.png


±£ÏÕ¹«Ë¾CNA³ÆÆäÔ⵽еÄÀÕË÷Èí¼þPhoenix CryptoLockerµÄ¹¥»÷¡£CNA FinancialÊÇÃÀ¹ú×î´óµÄÉÌÒµ¹¤ÒµºÍÒâÍâÉ˺¦±£ÏÕ¹«Ë¾Ö®Ò»¡£¹¥»÷·¢ÉúÔÚ3ÔÂ21ÈÕ£¬ºÚ¿Í¼ÓÃÜÁËÆäÁè¼Ý1.5Íò¶ą̀É豸£¬°üÂÞʹÓù«Ë¾µÄVPN½øÐÐÔ¶³Ì°ì¹«µÄÔ±¹¤µÄ¼ÆËã»ú£¬µ¼Ö¹«Ë¾ÔÚÏß·þÎñÖжÏ£¬ÒµÎñÔËÓªÊܵ½Ó°Ïì¡£¾ÝϤ£¬ÐµÄPhoenix Locker¿ÉÄÜÓëEvil Corp£¬¸ÃÍÅ»ïʹÓÃÐÂÀÕË÷Èí¼þ¼Ò×åHadesÒÔÈÆ¹ýÃÀ¹úµÄÖÆ²Ã¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/insurance-giant-cna-hit-by-new-phoenix-cryptolocker-ransomware/


3.MicrosoftÐû²¼²¹¶¡£¬ÐÞ¸´PsExecÓ¦ÓÃÖеÄÌáȨ©¶´


3.jpg


MicrosoftÐû²¼ÁËPsExec v2.33£¬ÒÔÐÞ¸´ÆäÖеÄÌáȨ©¶´¡£PsExecÊÇSysinternalsʵÓ÷¨Ê½£¬ÔÊÐí¹ÜÀíÔ±ÔÚÔ¶³Ì¼ÆËã»úÉÏÖ´ÐÐÖÖÖֻ£¬¹¥»÷Õßͨ³£ÀûÓÃÆäÔÚÍøÂçºáÏòÒÆ¶¯²¢°²×°¶ñÒâÈí¼þ¡£David WellsÓÚ2020Äê12Ô·¢ÏÖÁËλÓÚÃüÃû¹ÜµÀͨÐÅÖеÄ©¶´£¬µ±µØÓû§¿ÉÀûÓÃÆäÌáÉýµ½SYSTEMȨÏÞ¡£WellsÔÚÉϱ¨¸Ã©¶´²¢ÆÚ´ý90Ììºó£¬¹ûÈ»ÁËÍêÕûµÄPoC¡£Microsoft×îÖÕÓÚ3ÔÂ23ÈÕ£¬ÔÚPsExec v2.33ÖÐÐû²¼Á˸é¶´µÄ²¹¶¡·¨Ê½¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-fixes-windows-psexec-privilege-elevation-vulnerability/


4.Ó¡¶ÈÒ©ÉÌFKOLÒòÏú»ÙÊý¾Ý±»ÃÀ¹úFDA·£¿î5000ÍòÃÀÔª


4.jpg


Ó¡¶Èresenius KabiÁöѧÓÐÏÞ¹«Ë¾£¨FKOL£©µÄÒ»¼ÒÖÆÒ©³§ÒòÏú»ÙÊý¾Ý£¬±»ÃÀ¹úʳƷºÍÒ©Îï¹ÜÀí¾Ö£¨FDA£©·£¿î5000ÍòÃÀÔª¡£¸Ã¹¤³§Ö÷ÒªÉú²úÃÀ¹ú¾øÖ¢»¼ÕßʹÓõļ¸ÖÖ²îÒì°©Ö¢Ò©ÎïµÄ»îÐÔÒ©ÎïÉí·Ö(api)¡£¸Ã¹«Ë¾Ô­¶¨ÓÚ2013Äê1Ô½ÓÊÜFDA¼ì²é£¬µ«ÃÀ¹ú˾·¨²¿ÌåÏÖ£¬¸Ã¹«Ë¾Ô±¹¤´Ó¹¤³§ÖÐ×ªÒÆÁ˼ÆËã»ú¡¢Ö½ÖÊÎļþºÍÆäËûÖÊÁÏ£¬²¢É¾³ýÁËÓйظó§Î¥¹æÐÐΪ֤¾ÝµÄ¼Ç¼¡£3ÔÂ23ÈÕ£¬FKOL±»ÃÀ¹úµØÒªÁìÔºÅз£¿î3000ÍòÃÀÔª²¢Ã»ÊÕ2000ÍòÃÀÔªµÄ´¦·£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/drug-maker-to-pay-50m-for/


5.ºÚ¿ÍÔÚÒÔÉ«ÁдóѡǰһÌì¹ûÈ»Áè¼Ý600Íò¸öÑ¡ÃñµÄÐÅÏ¢


5.jpg


ÔÚÒÔÉ«Áдóѡǰ²»µ½24Сʱ£¬ºÚ¿Í¹ûÈ»ÁËÁè¼Ý650Íò¸öÑ¡ÃñµÄÐÅÏ¢¡£´Ë´Îй¶µÄÐÅÏ¢°üÂÞ6528565ÃûÑ¡ÃñµÄÐÕÃûºÍѡƱºÅÂ룬ÒÔ¼°Áè¼Ý300ÍòÒÔÉ«Áй«ÃñµÄÐÕÃû¡¢µç»°ºÅÂë¡¢Éí·ÝÖ¤ºÅÂë¡¢¼ÒÍ¥µØÖ·¡¢ÐÔ±ð¡¢ÄêÁäºÍÕþÖÎÆ«ºÃµÈ¸öÈËÐÅÏ¢¡£¾ÝϤ£¬´Ë´ÎʼþÊÇÓÉÓÚÈí¼þ¹«Ë¾Elector SoftwareΪÒÔÉ«ÁÐÕþµ³Likud¿ª·¢µÄÓ¦Ó÷¨Ê½ElectorÖдæÔÚ©¶´£¬Ä¿Ç°Éв»Çå³þй¶µÄÊý¾ÝÊÇ·ñÒѱ»·ÃÎÊ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/115918/hacking/israeli-voters-leak.html


6.Íâ»ã½»Ò×ÉÌFBSй¶½ü20TBÁè¼Ý160ÒÚÌõ¿Í»§µÄ½»Ò׼Ǽ


6.jpg


WizCaseÑо¿ÈËÔ±·¢ÏÖÍâ»ã½»Ò×ÉÌFBSÒòElasticsearch·þÎñÆ÷ÅäÖôíÎó£¬Ð¹Â¶Á˽ü20TBÁè¼Ý160ÒÚÌõ¿Í»§µÄ½»Ò׼Ǽ¡£FBSÊÇÊÀ½çÉÏ×æµÄÍâ»ã£¨forex£©½»Ò×ÔÚÏ߯½Ì¨Ö®Ò»£¬ÔÚÈ«ÇòÓµÓжà´ï1600ÍòÓû§¡£´Ë´Îй¶µÄÐÅÏ¢°üÂÞÓû§ÐÕÃû¡¢µç×ÓÓʼþºÍÕ˵¥µØÖ·¡¢µç»°ºÅÂë¡¢IPµØÖ·¡¢»¤ÕÕºÅÂë¡¢É罻ýÌåID¡¢Éí·ÝÖ¤¡¢¼ÝʻִÕÕ¡¢ÒøÐÐÕË»§¶ÔÕʵ¥¡¢Ë®µç·ÑÕ˵¥ºÍÐÅÓÿ¨µÈ£¬ÒÔ¼°Óû§ID¡¢Î´¼ÓÃܵÄÃÜÂë¡¢µÇ¼ÀúÊ·¼Ç¼¡¢»áÔ±Êý¾ÝºÍÃÜÂëÖØÖÃÁ´½ÓµÈÊý¾Ý¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/forex-leaks-millions-customer/