ºÚ¿ÍDataÔÚ°µÍø³öÊÛÔ¼3.5ÒÚÌõAsk.FMÓû§µÄ¼Ç¼

Ðû²¼Ê±¼ä 2022-09-22
1¡¢ºÚ¿ÍDataÔÚ°µÍø³öÊÛÔ¼3.5ÒÚÌõAsk.FMÓû§µÄ¼Ç¼

      

¾ÝýÌå9ÔÂ20ÈÕ±¨µÀ£¬ÃûΪDataµÄºÚ¿ÍÔÚ°µÍø³öÊÛÉç½»ÍøÕ¾Ask.FM(ASKfm)µÄÓû§Êý¾Ý ¡£DataÌåÏÖ£¬Âò¼Ò¿ÉÒÔ»ñµÃ607¸ö´æ´¢¿âÒÔ¼°ËûÃǵÄGitlab¡¢Jira¡¢ConfluenceÊý¾Ý¿â£¬Êý¾Ý¿âÖÐÓÐÔ¼3.5ÒÚÌõ¼Ç¼£¬ÆäÖÐÔ¼4500ÍòÌõʹÓõ¥µãµÇ¼½øÐеǼ ¡£¾ÝϤ£¬¹¥»÷ÕßÔÚ2019ÄêÊ״ηÃÎÊ·þÎñÆ÷£¬ÔÚ2020Äê3ÔÂ14ÈÕ»ñÈ¡ÁËÊý¾Ý¿â ¡£Data»¹ÌṩÁ˹¥»÷µÄ¼¼Êõϸ½Ú£¬²¢ÌåÏÖAsk.FMÈÔÈ»ºÜ´àÈõ ¡£


https://www.databreaches.net/ask-fm-user-database-with-350m-user-records-has-shown-up-for-sale/


2¡¢Malwarebytes×èÖ¹Óû§·ÃÎÊÍйÜÔÚGoogleµÄ·þÎñ

      

¾Ý9ÔÂ21ÈÕ±¨µÀ£¬Malwarebytes½â¾öÁËÒ»¸öÎÊÌ⣬¸ÃÎÊÌâ»á×èÖ¹Óû§·ÃÎÊÍйÜÔÚGoogleÉϵÄÍøÕ¾ºÍ·þÎñ£¬°üÂÞGoogleËÑË÷ºÍYoutube ¡£MalwarebytesÔÚÍÆÎÄÖнâÊÍ˵£¬ÕâÊÇÓÉÓ°Ï칫˾Äþ¾²²úÎïÖеÄWeb¹ýÂË×é¼þÄ£¿éµÄÎÊÌâµ¼ÖµÄ ¡£¸Ã¹«Ë¾ÌṩÁËÒ»ÖÖ½â¾öÒªÁ죬Óû§¿ÉÒÔ´ò¿ªMalwarebytes²¢¹Ø±Õʵʱ±£»¤¿¨ÖеÄWeb±£»¤Ñ¡ÏîÀ´½ûÓôíÎóÄ£¿é ¡£ÔÚһСʱºó£¬¸Ã¹©Ó¦ÉÌ͸¶Òѽâ¾öÎÊÌ⣬ËùÓÐÓû§µÄÈí¼þ½«×ÔÐиüв¢ÐÞ¸´Îó±¨ÎÊÌâ ¡£


https://www.bleepingcomputer.com/news/technology/malwarebytes-mistakenly-blocks-google-youtube-for-malware/


3¡¢ÀÕË÷ÍÅ»ïHivÉù³Æ¶ÔŦԼÈüÂíЭ»á(NYRA)µÄ¹¥»÷ÂôÁ¦

      

ýÌå9ÔÂ20ÈÕ±¨µÀ£¬ÀÕË÷ÍÅ»ïHiveÉù³Æ¶ÔŦԼÈüÂíЭ»á(NYRA)µÄ¹¥»÷ÂôÁ¦ ¡£NYRAÊÇŦԼÈý¸ö×î´óµÄ´¿ÖÖÈüÂí³¡µÄÔËÓªÉÌ£¬´ËÇ°ÔøÅû¶ÆäÓÚ2022Äê6ÔÂ30ÈÕÔâµ½¹¥»÷£¬Ó°ÏìÁËITÔËÓªºÍÍøÕ¾ ¡£´ËÍ⣬Óû§µÄÉç»áÄþ¾²ºÅÂë¡¢¼ÝʻִÕÕʶ±ðºÅÂë¡¢½¡¿µ¼Ç¼ºÍ½¡¿µ±£ÏÕÐÅÏ¢¿ÉÄÜÒѾ­Ð¹Â¶ ¡£¹¥»÷ÕßÓÚ9ÔÂ19ÈÕÔÚÆäÍøÕ¾Ðû²¼Á˾ݳÆÊÇ´ÓNYRAÇÔÈ¡µÄËùÓÐÎļþ£¬Ñо¿ÈËÔ±ÍÆ²âÊê½ð̸ÅÐÒѾ­½áÊø ¡£NYRA½«ÎªÊÜÓ°ÏìÓû§ÌṩΪÆÚ24¸öÔµÄExperianÉí·Ý±£»¤·þÎñ ¡£


https://www.bleepingcomputer.com/news/security/hive-ransomware-claims-attack-on-new-york-racing-association/


4¡¢2K GamesÓÎϷƽ̨Ôâµ½¹¥»÷²¢±»ÓÃÀ´·Ö·¢RedLine

      

ýÌå9ÔÂ20Èճƣ¬ÃÀ¹úÊÓÆµÓÎÏ·¿¯ÐÐÉÌ2K GamesÔâµ½¹¥»÷£¬±»ÓÃÀ´·Ö·¢¶ñÒâÈí¼þRedLine ¡£±¾Öܶþ¿ªÊ¼£¬Ðí¶à2K¿Í»§ÊÕµ½À´×ÔSupportϵͳµÄµç×ÓÓʼþ£¬Óʼþ°üÂÞÒ»¸öÃûΪ2K Launcher.zipµÄ¸½¼þ£¬¸ÃÎļþÍйÜÔÚ2ksupport.zendesk.comÉÏ£¬Î±×°³ÉÁËÒ»¸öеÄÓÎÏ·Æô¶¯Æ÷ ¡£ÏÂÔØµÄ´æµµ°üÂÞ107 MBµÄ¿ÉÖ´ÐÐÎļþ2K Launcher.exe£¬VirusTotalºÍAny.RunÌåÏÖ£¬ÕâÊÇÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þRedLine ¡£Ä¿Ç°£¬2KËÆºõÒѽ«ÆäSupportϵͳ¹Ø±Õ£¬Óû§ÎÞ·¨Ê¹ÓõǼƾ¾Ý·ÃÎÊÆäÆ±Ö¤ ¡£


https://www.bleepingcomputer.com/news/security/2k-game-support-hacked-to-email-redline-info-stealing-malware/


5¡¢Ñо¿ÈËÔ±Åû¶OracleÔÆ»ù´¡ÉèÊ©ÖеÄ©¶´AttachMe

      

Ñо¿ÈËÔ±ÔÚ9ÔÂ20ÈÕÅû¶ÁËOracleÔÆ»ù´¡ÉèÊ©(OCI)ÖеÄÒ»¸öЩ¶´AttachMe ¡£Ñо¿ÈËÔ±³Æ£¬Ö»Òª¹¥»÷ÕßÓµÓÐÆäOracleÔÆ±êʶ·û(OCID)£¬¾Í¿ÉÒÔ¶ÔÈκÎδ¸½¼ÓµÄ´æ´¢¾í»òÔÊÐí¶à¸½¼þµÄ¸½¼Ó´æ´¢¾í½øÐжÁд£¬À´ÇÔÈ¡Ãô¸ÐÊý¾Ý»òͨ¹ý¿ÉÖ´ÐÐÎļþÌᳫ¸ü¾ßÆÆ»µÐԵĹ¥»÷ ¡£¸Ã©¶´¿ÉÄܵ¼ÖÂȨÏÞÌáÉýºÍ¿ç×â»§·ÃÎÊ£¬Ò²ÌåÏÖÁËÔÆ×â»§¸ôÀëÔÚÔÆ»ù´¡ÉèÊ©ÖеÄÖØÒªÐÔ ¡£ÔÚÊÕµ½Â©¶´³ÂËߺóµÄ24СʱÄÚ£¬OracleΪËùÓÐOCIÓû§ÐÞ¸´Á˸é¶´£¬¶øÎÞÐèÓû§½ÓÄÉÈκδëÊ© ¡£


https://www.wiz.io/blog/attachme-oracle-cloud-vulnerability-allows-unauthorized-cross-tenant-volume-access


6¡¢¼ÓÃÜ»õ±Ò¹«Ë¾WintermuteÔâµ½¹¥»÷ËðʧԼ1.6ÒÚÃÀÔª 

      

9ÔÂ20ÈÕ±¨µÀ³Æ£¬¼ÓÃÜ»õ±Ò¹«Ë¾WintermuteÒѱ»ºÚ¿ÍÈëÇÖ£¬²¢ÔÚDeFiÒµÎñÖÐËðʧÁË1.622ÒÚÃÀÔª ¡£¸Ã¹«Ë¾²¢Î´ÌṩÇÔÈ¡×ʽðµÄÏêϸÐÅÏ¢£¬µ«Ñо¿ÈËÔ±ÈÏΪ£¬¹¥»÷Õß¿ÉÄÜÀûÓÃÁËProfanityÖеÄ©¶´ ¡£WintermuteÊǼÓÃÜ»õ±Òƽ̨µÄ¡°×öÊÐÉÌ¡±£¬ÈÔÈ»Óг¥¸¶ÄÜÁ¦£¬³ÖÓÐÁ½±¶ÓÚ±»µÁÊý¶îµÄ¹ÉȨ ¡£²»Í⣬Ԥ¼Æ½ÓÏÂÀ´µÄ¼¸Ìì·þÎñ»áÖжÏ£¬ÒòΪ¸Ãƽ̨ÈÔÔÚŬÁ¦»Ö¸´ÒµÎñ ¡£¹«Ë¾CEO GaevoyÌåÏÖ£¬Ô¸Ò⽫´ËÊÂÊÓΪ°×ñʼþ£¬ÕâÒâζ×ÅËûÃÇÔ¸ÒâÌṩÉͽðÇÒûÓÐÈκÎÖ´·¨ºó¹û£¬µ«²»ÖªµÀ¹¥»÷ÕßÊÇ·ñ»á½«±»µÁ×ʽ𷵻¹¸øWintermute ¡£


https://therecord.media/cryptocurrency-company-wintermute-says-hackers-stole-160-million/