ºÚ¿ÍÉù³ÆÒÑ»ñµÃ4ÒÚTwitterÓû§ÐÅÏ¢²¢ÊÔͼ³öÊÛ
Ðû²¼Ê±¼ä 2022-12-27
¾ÝýÌå12ÔÂ25ÈÕ±¨µÀ£¬ÃûΪRyushiµÄ¹¥»÷ÕßÔÚºÚ¿ÍÂÛ̳BreachedÉϳöÊÛ4ÒÚTwitterÓû§µÄÊý¾Ý¡£Âô¼ÒÉù³Æ¸ÃÊý¾Ý¿âÊÇ˽È˵쬲¢ÌṩÁË1000¸öÕÊ»§µÄÐÅÏ¢×÷ΪÑù±¾£¬ÆäÖаüÂÞDonald Trump JRºÍBrian KrebsµÈÈË¡£ºÚ¿Í»¹ÑûÇëTwitterºÍElon Musk¹ºÖÃÕâЩÊý¾Ý£¬ÒÔÖÆÖ¹GDPRµÄ·£¿î¡£Ä¿Ç°ÉÐÎÞ·¨ºËʵÂô¼ÒµÄ˵·¨¡£Êý¾Ý¿âÊÛ¼ÛΪ200000ÃÀÔª£¬¾ÝϤÊÇʹÓÃTwitterÓÚ2022Äê1ÔÂÐÞ¸´µÄAPI©¶´½øÐÐÊÕ¼¯µÄ¡£ÁíÒ»ºÚ¿ÍÒ²³ÆÀûÓôË©¶´×¥È¡ÁË1700ÍòÓû§µÄÊý¾Ý£¬µ«ÊDz»»á³öÊÛ¡£
https://securityaffairs.co/wordpress/139993/data-breach/twitter-400-million-users-leak.html
2¡¢MetaÒÔ7.25ÒÚÃÀÔªºÍ½âCambridge Analytica¼¯ÌåËßËÏ
¾Ý12ÔÂ23ÈÕ±¨µÀ£¬Facebookĸ¹«Ë¾MetaÒÑͬÒâÖ§¸¶7.25ÒÚÃÀÔª£¬ÒԺͽâ¸Ã¹«Ë¾ÔÊÐíµÚÈý·½£¨°üÂÞCambridge Analytica£©·ÃÎÊÓû§¸öÈËÊý¾ÝµÄ¼¯ÌåËßËÏ¡£ÕâÆðËßËÏʼÓÚ2018Ä꣬ÆäʱFacebookÓû§Ö¸Ôð¸ÃÉç½»ÍøÂçÆ½Ì¨Î¥·´Òþ˽¹æÔò£¬ÓëµÚÈý·½¹²ÏíÊý¾Ý¡£ËßËϳƣ¬Cambridge AnalyticaÔÚδ¾Óû§Í¬ÒâµÄÇé¿öÏÂÊÕ¼¯ºÍÀûÓÃÁË8700ÍòFacebookÓû§µÄÊý¾Ý¡£¾Ý³Æ£¬ÕâЩÐÅÏ¢±»ÓÃÀ´¿ª·¢Èí¼þÒýµ¼ÃÀ¹úÑ¡ÃñÖ§³ÖÌØÀÊÆÕ¡£2019Äê7Ô£¬ÃÀ¹úÕþ¸®ÒÔÎóµ¼Óû§ÎªÓɶÔFacebook´¦ÒÔ50ÒÚÃÀÔªµÄ·£¿î¡£Í¬Ô£¬FacebookͬÒâÖ§¸¶1ÒÚÃÀÔªÒÔÁ˽áÖ¸¿Ø¡£
https://therecord.media/meta-to-settle-cambridge-analytica-class-action-for-725-million/
3¡¢Ñо¿ÈËÔ±Åû¶¿ªÔ´²©¿Íƽ̨GhostÖеÄÁ½¸öÄþ¾²Â©¶´
ýÌå12ÔÂ22Èճƣ¬Cisco Talos·¢ÏÖ¿ªÔ´²©¿Íƽ̨GhostÖдæÔÚÁ½¸öÄþ¾²Â©¶´¡£ÆäÖнÏΪÑÏÖØµÄÊÇÉí·ÝÈÆ¹ý©¶´£¨CVE-2022-41654£¬CVSSÆÀ·ÖΪ9.6£©£¬ÔÊÐí·ÇÌØÈ¨Óû§£¨¼´»áÔ±£©¶ÔʱÊÂͨѶÉèÖýøÐÐδ¾ÊÚȨµÄÐ޸ġ£´ËÍâ£¬ÍøÕ¾¹ÜÀíԱĬÈÏÇé¿öÏÂÔÚʱÊÂͨѶÖÐ×¢ÈëJavaScriptµÄÄÜÁ¦¿É±»ÀûÓã¬ÔÚ±à¼Í¨Ñ¶Ê±´¥·¢À´´´½¨ÈÎÒâµÄ¹ÜÀíÔ±ÕË»§¡£ÁíÒ»¸öÊǵǼ¹¦Ð§ÖеÄö¾Ù©¶´£¨CVE-2022-41697£©£¬¿Éµ¼ÖÂÃô¸ÐÐÅϢй¶¡£Ä¿Ç°£¬GhostÒÑÔÚ×îа汾µÄCMSÉϽâ¾öÁËÕâÁ½¸ö©¶´¡£
https://thehackernews.com/2022/12/two-new-security-flaws-reported-in.html
4¡¢±ÈÀûʱÉÌÒµÒøÐÐDegroof Petercam·¢ÉúÊý¾Ýй¶
¾ÝLe Soir 12ÔÂ22ÈÕ±¨µÀ£¬±ÈÀûʱÉÌÒµÒøÐÐDegroof Petercam·¢ÉúÊý¾Ýй¶£¬Ó°ÏìÁËÊý°Ù¼Ò±ÈÀûʱµÄ¹«Ë¾¡£¾ÝϤ£¬¸ÃÒøÐеÄÒ»ÃûÔ±¹¤ÀÄÓÃÆä¶Ô¿Í»§ÐÅÏ¢µÄ·ÃÎÊȨ·Ç·¨ÏÂÔØÁ˿ͻ§Îļþ¡£Le SoirµÄ½ãÃÃÆµµÀRTLÓÚ12ÔÂ9ÈÕÊÕµ½ÒøÐеÄ֪ͨ£¬³ÆÆäÊý¾ÝÒÑй¶¡£Degroof PetercamÒ²ÒѾȷÈÏ´Ë´Îй¶Ê¼þ¡£¾Ý¸ÃÒøÐз¢ÑÔÈ˳ƣ¬Ö»ÓÐרҵµÄ¹ÉƱÆÚȨ¼Æ»®(SOP) ÕË»§»áÊܵ½¸ÃʼþµÄÓ°Ï죬µ«¾Ý³ÆÊý°Ù¼ÒÖÖÖÖ¹æÄ£µÄ±ÈÀûʱ¹«Ë¾¶¼Êܵ½ÁËÓ°Ïì¡£
https://www.databreaches.net/data-leak-at-degroof-petercam-affects-hundreds-of-belgian-companies/
5¡¢Prodaft·¢ÏÖFIN7ʹÓÃ×Ô¶¯¹¥»÷ƽ̨CheckmarksµÄ»î¶¯
ProdaftÔÚ12ÔÂ22ÈÕ³ÆÆä·¢ÏÖFIN7ʹÓÃÒ»¸ö×Ô¶¯¹¥»÷ƽ̨Checkmarks£¬À´ÈëÇÖ¹«Ë¾ÍøÂç¡¢ÇÔÈ¡Êý¾Ý²¢Æ¾¾Ý²ÆÕþ¹æÄ£Ñ¡ÔñÀÕË÷¹¥»÷µÄÄ¿±ê¡£CheckmarksÀûÓÃÁËMicrosoft ExchangeºÍSQL ×¢Èë©¶´£¬´Ó2021Äê6Ô¿ªÊ¼¾Í±»ÓÃÓÚ×Ô¶¯Õì²ì¹«Ë¾ÍøÂçÖÐÒ×±»¹¥»÷µÄ¶Ëµã£¬È»ºóͨ¹ýPowerShell·Ö·¢web shellÀ´»ñÈ¡·ÃÎÊȨÏÞ¡£´ËÍ⣬Ñо¿ÈËÔ±·¢ÏÖFIN7ÓëDarkside¡¢REvilºÍLockBitµÈ¶à¸öÀÕË÷ÍÅ»ïÓйأ¬²¢Ê¹ÓÃÁËÐÂSSHºóÃÅ£¬Í¨¹ýOnionÓòʹÓ÷´ÏòSSHÁ¬½Ó(SFTP)´ÓÄ¿±êÉ豸ÖÐÇÔÈ¡Îļþ¡£
https://www.bleepingcomputer.com/news/security/fin7-hackers-create-auto-attack-platform-to-breach-exchange-servers/
6¡¢SentinelOneÐû²¼¹ØÓÚVice SocietyÍÅ»ïµÄ·ÖÎö³ÂËß
12ÔÂ22ÈÕ£¬SentinelOneÐû²¼³ÂË߳ƣ¬Vice Society¿ªÊ¼Ê¹ÓÃеÄ×Ô½ç˵¼ÓÃÜ·¨Ê½¡£Ñо¿ÈËÔ±ÔÚ¸ÃÍÅ»ï×î½üµÄÒ»´Î¹¥»÷Öз¢ÏÖÁËÐÂÀÕË÷Èí¼þPolyVice£¬Ëü½ÓÄÉ»ìºÏ¼ÓÃÜ·½°¸£¬½«·Ç¶Ô³Æ¼ÓÃÜÓëNTRUEncryptËã·¨Ïà½áºÏ£¬¶Ô³Æ¼ÓÃÜÓëChaCha20-Poly1305Ëã·¨Ïà½áºÏ¡£Ñо¿ÈËÔ±ÍÆ²â£¬Õâ¿ÉÄÜÊÇVice Society´ÓÒ»¼ÒΪÆäËûÀÕË÷ÍÅ»ïÌṩÀàËÆ¹¤¾ßµÄ×éÖ¯´¦²É¹ºµÄ¡£¸Ã±äÌåÓÚ2022Äê7ÔÂ13ÈÕÊ×´ÎÔÚÒ°Íâ·ºÆð£¬µ«Ö±µ½ºÜ¾ÃÒÔºó²Å±»¸Ã×éÖ¯ÍêÈ«½ÓÄÉ¡£·ÖÎö±íÃ÷£¬PolyViceÓëChillyºÍSunnyDayµÄ´úÂë¾ßÓÐÏàËÆÐÔ£¬¹¦Ð§100%Æ¥Å䣬ֻÓÐһЩϸ½Ú²îÒì¡£
https://www.sentinelone.com/labs/custom-branded-ransomware-the-vice-society-group-and-the-threat-of-outsourced-development/