McGraw HillµÄ´æ´¢Í°ÅäÖôíÎóй¶22TBÊý¾Ý
Ðû²¼Ê±¼ä 2022-12-21
¾Ý12ÔÂ19ÈÕ±¨µÀ£¬Ñо¿ÈËÔ±·¢ÏÖÁËÁ½¸öÅäÖôíÎóµÄAmazon Web Services S3´æ´¢Í°£¬ÆäËùÓÐÕß±»È·¶¨ÎªMcGraw Hill¡£¸Ãƽ̨ÊÇÃÀ¹úÈý´ó½ÌÓýÄÚÈݳöÊéÉÌÖ®Ò»£¬Ò²±»¼ÓÄôó¸÷µØµÄ½ÌÓý»ú¹¹ÓÃÓÚÔÚÏ߿γ̡£´Ë´Îʼþ×ܹ²Ð¹Â¶ÁË1.17ÒÚ¸öÎļþ£¬·Ö±ðΪһ¸ö°üÂÞ10TBÊý¾ÝµÄ·ÇÉú²ú´æ´¢Í°£¬ÒÔ¼°Ò»¸ö°üÂÞ12TBÊý¾ÝµÄÉú²ú´æ´¢Í°£¬ÓÚ2022Äê6ÔÂ12ÈÕÊ״α»·¢ÏÖ¡£Ñо¿ÈËԱ͸¶£¬Ô¼10ÍòÃûѧÉú»áÊܵ½¸ÃʼþµÄÓ°Ï죬Ŀǰ̻¶µÄ´æ´¢Í°Òѱ»±£»¤ÆðÀ´¡£
https://www.hackread.com/american-online-ed-platform-22tb-data-leak/
2¡¢DraftKingsÁè¼Ý6Íò¿Í»§µÄÐÅÏ¢ÒòÔ⵽ײ¿â¹¥»÷й¶
ýÌå12ÔÂ19Èճƣ¬ÌåÓý²©²Ê¹«Ë¾DraftKingsÉÏÖÜ͸¶£¬67995¸ö¿Í»§µÄ¸öÈËÐÅÏ¢ÔÚ11Ô·ݵÄÒ»´Îײ¿â¹¥»÷ÖÐй¶¡£¸Ã¹«Ë¾ÌåÏÖ£¬¹¥»÷Õß´ÓÆäËüµØ·½»ñµÃÁ˵Ǽ¿Í»§ÕÊ»§ËùÐèµÄƾ¾Ý£¬¿Í»§µÄÉç»áÄþ¾²ºÅÂë¡¢¼ÝÕÕºÅÂëºÍ½ðÈÚÕ˺Ų¢Î´Ð¹Â¶¡£DraftKingsÔÚ¼ì²âµ½¹¥»÷ºóÖØÖÃÁËÊÜÓ°ÏìÕÊ»§µÄÃÜÂ룬²¢ÊµÊ©ÁËÌØ±ðµÄÆÛÕ©¾¯±¨¡£OktaÔÚ9Ô·ݳÂË߳ƣ¬½ñÄêµÄÇé¿ö¼±¾ç¶ñ»¯£¬ËüÔÚ2022ÄêǰÈý¸öÔ¾ͼǼÁËÁè¼Ý100ÒÚ´Îײ¿âʼþ¡£
https://www.bleepingcomputer.com/news/security/draftkings-warns-data-of-67k-people-was-exposed-in-account-hacks/
3¡¢Î¢ÈíÔÚMacOSÖз¢ÏÖ¿ÉÈÆ¹ýGatekeeperµÄ©¶´Achilles
12ÔÂ19ÈÕ£¬Î¢ÈíÅû¶ÁËMacOSÖпÉÈÆ¹ýGatekeeperµÄ©¶´Achilles£¨CVE-2022-42821£©¡£GatekeeperÊÇmacOSµÄÒ»ÏîÄþ¾²¹¦Ð§£¬»á×Ô¶¯¼ì²éÏÂÔØµÄÓ¦ÓÃÊÇ·ñ¾¹ý¹«Ö¤ºÍ¿ª·¢ÈËԱǩÃû£¨AppleÅú×¼£©¡£Achilles©¶´¿Éͨ¹ýÌØÖÆµÄpayloadÀûÓÃÂß¼ÎÊÌâÀ´ÉèÖÃÏÞÖÆÐÔACLȨÏÞ£¬´Ó¶ø×èÖ¹ä¯ÀÀÆ÷ºÍ»¥ÁªÍøÏÂÔØÆ÷ΪÏÂÔØµÄZIPÎļþ´æµµµÄpayloadÉèÖÃcom.apple.quarantineÊôÐÔ¡£Òò´Ë£¬°üÂÞÔÚ´æµµpayloadÖеĶñÒâÓ¦ÓûáÔÚÄ¿±êϵͳÉÏÆô¶¯£¬¶ø²»ÊDZ»Gatekeeper×èÖ¹¡£AppleÒÑÔÚ12ÔÂ13ÈÕÐû²¼µÄ¸üÐÂÖÐÐÞ¸´¸Ã©¶´¡£
https://www.microsoft.com/en-us/security/blog/2022/12/19/gatekeepers-achilles-heel-unearthing-a-macos-vulnerability/
4¡¢Ã°³äSentinelOne SDKµÄ¶ñÒâPyPI°üÇÔÈ¡¿ª·¢ÈËÔ±Êý¾Ý
ReversingLabsÔÚ12ÔÂ19ÈÕ³ÆÆä·¢ÏÖÒ»¸ö¶ñÒâPython°üð³äÄþ¾²¹«Ë¾SentinelOneµÄÈí¼þ¿ª·¢¹¤¾ß°ü(SDK)¡£¸ÃÈí¼þ°üÓëSentinelOne¹«Ë¾Ã»ÓÐÈκιØÏµ£¬ÓÚ2022Äê12ÔÂ11ÈÕÊ×´ÎÉÏ´«µ½ PyPI£¬½ñºó¸üÐÂÁË20´Î£¬×îа汾Ϊ1.2.1£¬ÓÚ12ÔÂ13ÈÕÉÏ´«¡£¶ñÒâ°üÖаüÂÞ´øÓжñÒâ´úÂëµÄapi.pyÎļþ£¬´Ë¶ñÒâ´úÂë³äµ±ÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ£¬´ÓÉè±¹ØÁ¬ÄËùÓÐÖ÷Ŀ¼µ¼³öÖÖÖÖÓ뿪·¢ÈËÔ±Ïà¹ØµÄÊý¾Ý£¬°üÂÞBashºÍZshÀúÊ·¼Ç¼¡¢SSH ÃÜÔ¿ºÍ.gitconfigµÈÎļþ¡£Ä¿Ç°£¬Î±ÔìµÄSentinelOne°üÒѱ»É¾³ý¡£
https://blog.reversinglabs.com/blog/sentinelsneak-malicious-pypi-module-poses-as-security-sdk
5¡¢Î÷°àÑÀÒøÐÐAbancaÒòÑÓ³Ù³ÂËßÍøÂç¹¥»÷±»·£¿î310ÍòÅ·Ôª
¾ÝýÌå12ÔÂ16ÈÕ±¨µÀ£¬Å·ÖÞÖÐÑëÒøÐÐÌåÏÖ£¬ÒѶÔÎ÷°àÑÀÒøÐÐAbanca´¦ÒÔ310ÍòÅ·Ôª£¨329ÍòÃÀÔª£©µÄ·£¿î¡£ÔÒòÊǸÃÒøÐÐÑÓ³Ù³ÂËßÍøÂç¹¥»÷ʼþ£¬ÆÈʹÆäÔÚ2019ÄêÔÝÍ£ÆäÖ÷ÒªµÄÖ§¸¶·½Ê½¡£Å·ÖÞÑëÐгƣ¬¸ÃÒøÐеÄÊèºö¹ÊÕÏÁËÅ·ÖÞÑëÐÐÕýÈ·ÆÀ¹ÀAbancaµÄÉóÉ÷×´¿ö£¬ÒÔ¼°¼°Ê±Ó¦¶ÔÆäËûÒøÐÐÃæÁÙµÄDZÔÚÍþвµÄÄÜÁ¦¡£
https://www.usnews.com/news/technology/articles/2022-12-16/ecb-fines-spains-abanca-for-delay-in-reporting-cyber-hack
6¡¢ÎÚ¿ËÀ¼Í¸Â¶UAC-0142ÍÅ»ïµöÓã¹¥»÷ÆäDelta¾üÊÂÇ鱨ϵͳ
ÎÚ¿ËÀ¼CERT-UAÔÚ12ÔÂ18ÈÕÐû²¼Í¨¸æ£¬ÌáÐÑAPTÍÅ»ïUAC-0142Õë¶ÔÆäDelta¾üÊÂÇ鱨ϵͳµÄ¹¥»÷»î¶¯¡£µöÓãÐÅÏ¢ÊÇ´Ó¹ú·À²¿Ò»Ãû¹ÍÔ±µÄ±»ÈëÇÖÓÊÏäºÍmessenger·¢Ë͵쬏ÃÏûÏ¢¶Ø´ÙÊÕ¼þÈ˸üÐÂDELTAϵͳÖеÄÖ¤Ê飬Ëü»¹°üÂÞÒ»¸ö¸½¼ÓµÄPDFÎļþ£¬Ä£·ÂÁËZaporizhzhia¾¯²ì¾ÖISTAR²¿ÃŵĺϷ¨ÕªÒª¡£ÔÚÖ´Ðд浵ÖеÄcertificates_rootCA.exeºó£¬½«°²×°Á½¸ö¶ñÒâÈí¼þ£¬·Ö±ðΪÇÔÈ¡µç×ÓÓʼþ¡¢Êý¾Ý¿â¡¢½Å±¾ºÍÎļþµÈÊý¾ÝµÄÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þFateGrab£¬¼°ÇÔÈ¡ä¯ÀÀÆ÷Êý¾ÝµÄ¶ñÒâÈí¼þStealDeal¡£
https://securityaffairs.co/wordpress/139859/intelligence/ukraine-delta-military-intelligence-attack.html