Brunswick CorporationÔâµ½¹¥»÷Ëðʧ¸ß´ï8500ÍòÃÀÔª
Ðû²¼Ê±¼ä 2023-08-041¡¢Brunswick CorporationÔâµ½¹¥»÷Ëðʧ¸ß´ï8500ÍòÃÀÔª
¾ÝýÌå8ÔÂ3ÈÕ±¨µÀ£¬´¬²°ÖÆÔ칫˾Brunswick CorporationÔâµ½ÍøÂç¹¥»÷£¬Ëðʧ¸ß´ï8500ÍòÃÀÔª¡£¸Ã¹«Ë¾2021ÄêÊÕÈë½ü60ÒÚÃÀÔª£¬ÒµÎñ±é¼°24¸ö¹ú¼Ò¡£¹¥»÷·¢ÉúÔÚ6ÔÂ13ÈÕ£¬Ó°ÏìÁ˸ù«Ë¾µÄϵͳºÍ²¿ÃÅÉèÊ©¡£ÉÐδ֤ʵÕâÊÇÀÕË÷¹¥»÷£¬µ«¸Ã¹«Ë¾ÌåÏÖÆäÔÚijЩµØ·½µÄÔËÓª±»ÆÈÍ£Ö¹¡£¸Ã¹«Ë¾CEO͸¶£¬´Ë´ÎÄþ¾²Ê¼þ¶Ô¹«Ë¾µÚ¶þ¼¾¶ÈµÄ²ÆÕþ×é³ÉÁË»ÙÃðÐÔÓ°Ï죬Ôâµ½¹¥»÷ºóÆä»¨Á˾ÅÌìµÄʱ¼ä²Å»Ö¸´Õý³£ÔËÓª¡£´Ë´ÎÖжÏÖ÷ÒªÓ°ÏìÁËÍÆ½øÆ÷ºÍ·¢¶¯»úÁãÅä¼þÁìÓò£¬ÓÉÓÚÁÙ½ü¼¾¶ÈÄ©£¬Í¬ÆÚÄÚÍêÈ«»Ö¸´µÄ»ú»áÓÐÏÞ¡£
https://therecord.media/marine-industry-giant-brunswick-lost-millions
2¡¢MicrosoftÅû¶NobeliumÀûÓÃTeamsÏûÏ¢µÄµöÓã¹¥»÷»î¶¯
MicrosoftÔÚ8ÔÂ2ÈÕÅû¶Á˽üÆÚ¶íÂÞ˹ºÚ¿ÍÍÅ»ïNobelium£¨APT29£©ÓÐÕë¶ÔÐԵĵöÓã¹¥»÷»î¶¯¡£¸Ã»î¶¯´Ó5ÔÂÏÂÑ®¿ªÊ¼£¬Ó°ÏìÁ˲»µ½40¸öÆóÒµ£¬Éæ¼°Õþ¸®¡¢·ÇÕþ¸®×éÖ¯(NGO)¡¢IT·þÎñ¡¢¼¼Êõ¡¢ÖÆÔìºÍýÌåÐÐÒµ¡£Ôڴ˴λÖУ¬¹¥»÷ÕßÀûÓÃÇÔÈ¡µÄMicrosoft 365×â»§À´´´½¨ÐµÄÓò£¬ÕâЩÓòÃû¿´ÆðÀ´ÏñÊǼ¼ÊõÖ§³ÖʵÌ塣ȻºóÀûÓÃTeamsÏûÏ¢·¢ËÍÓÕ¶ü£¬ÓÕʹĿ±êÓû§Åú×¼¶àÒòËØÉí·ÝÑéÖ¤£¨MFA£©£¬×îÖÕÖ¼ÔÚÇÔȡĿ±ê×éÖ¯µÄƾ֤¡£
https://www.microsoft.com/en-us/security/blog/2023/08/02/midnight-blizzard-conducts-targeted-social-engineering-over-microsoft-teams/
3¡¢ºº±¤Íõ·¨¹ú·Ö¹«Ë¾ÒòÍøÕ¾ÅäÖôíÎóµ¼ÖÂÆ¾¾ÝµÈÐÅϢй¶
ýÌå8ÔÂ3Èճƣ¬ºº±¤Íõ·¨¹ú·Ö¹«Ë¾ÒòÍøÕ¾ÅäÖôíÎ󣬵¼ÖÂÆ¾¾ÝµÈÐÅϢй¶¡£6ÔÂ1ÈÕ£¬Ñо¿ÍŶӷ¢ÏÖÁËÊôÓÚºº±¤Íõ·¨¹úÍøÕ¾µÄ¿É¹ûÈ»·ÃÎʵĻ·¾³Îļþ(.env)£¬ÆäÖаüÂÞÖÖÖÖÆ¾¾Ý£¬¸ÃÎļþÍйÜÔÚÓÃÓÚÐû²¼ÊÂÇé»ú»áµÄ×ÓÓòÉÏ¡£¾¡¹Üй¶µÄÊý¾Ý²»×ãÒÔÍêÈ«¿ØÖÆÍøÕ¾£¬µ«Ëü¿ÉÒÔ¼ò»¯¹¥»÷Õß½Ù³ÖÍøÕ¾µÄ¹ý³Ì¡£Ä¿Ç°£¬¸Ã¹«Ë¾ÒѾ½â¾öÁËÕâ¸öÎÊÌâ¡£2019Ä꣬ÓÉÓÚÀàËÆµÄÅäÖôíÎ󣬷¨¹ú·Ö¹«Ë¾ÔøÐ¹Â¶Á˹ºÖúº±¤ÍõµÄ¶ùͯµÄPIIÐÅÏ¢¡£
https://cybernews.com/security/burger-king-data-leak/
4¡¢NoName057(16)Éù³Æ¶ÔÒâ´óÀû¶à¼ÒÒøÐÐÔâµ½µÄ¹¥»÷ÂôÁ¦
¾Ý8ÔÂ3ÈÕ±¨µÀ£¬ºÚ¿ÍÍÅ»ïNoName057(16)Éù³Æ¶ÔÒâ´óÀûÒøÐС¢ÆóÒµºÍÕþ¸®»ú¹¹µÄ¹¥»÷ÂôÁ¦¡£Òâ´óÀûÍøÂçÄþ¾²»ú¹¹ÔÚ±¾ÖܶþÌåÏÖ£¬ÒѼì²âµ½ÖÁÉÙÎå¼ÒÒøÐеÄÍøÕ¾Ôâµ½DDoS¹¥»÷£¬ÆäÖаüÂÞÒâ´óÀû×î´óµÄÁªºÏÊ¥±£ÂÞÒøÐС£NoName057(16)ÓÚ±¾ÖÜÒ»Ê״ζÔÒâ´óÀûÌᳫ¹¥»÷£¬²¢ÓÚ8ÔÂ3ÈÕ¼ÌÐø¡£³ýÁËÒøÐÐÖ®Í⣬¸ÃÍŻﻹÉù³ÆÈëÇÖÁËÒ»¼ÒÒâ´óÀû¹©Ë®¹«Ë¾¡¢Ò»¼ÒÈ«¹úÐÔÉÌÒµ±¨Ö½ºÍÒ»¸ö¹«¹²½»Í¨µÄÍøÕ¾¡£½ØÖÁĿǰ£¬ÕâÐ©ÍøÕ¾ÈÔ´¦ÓڹرÕ״̬¡£
https://therecord.media/russian-hackers-claim-attacks-on-italy
5¡¢ºÚ¿ÍÀûÓÃCVE-2023-3519ÔÚÊý°Ų̀Citrix·þÎñÆ÷°²×°ºóÃÅ
8ÔÂ2ÈÕ±¨µÀ³Æ£¬Shadowserver Foundation·¢ÏÖÊý°Ų̀Citrix Netscaler ADCºÍGateway·þÎñÆ÷±»ÈëÇÖ²¢°²×°ºóÃÅ¡£CISA½üÆÚÐû²¼Í¨¸æ³Æ£¬¹¥»÷ÕßÕýÔÚÀûÓÃRCE©¶´£¨CVE-2023-3519£©ÔÚÒ×±»¹¥»÷µÄϵͳÖа²×°Web shell¡£Shadowserver×î³õ³ÂËߣ¬ÖÁÉÙÓÐ15000̨·þÎñÆ÷Ò×±»¹¥»÷£¬Ö÷ҪλÓÚÃÀ¹úºÍµÂ¹ú¡£×îиüÐÂÖÐÏÔʾ£¬½ØÖÁ8ÔÂ1ÈÕ£¬¹¥»÷ÕßÒÑÔÚÖÁÉÙ581̨Citrix·þÎñÆ÷Éϰ²×°ÁËWebshell¡£CitrixÇ¿ÁÒ½¨ÒéÓû§°²×°¸üС£
https://securityaffairs.com/149083/hacking/phishing-facebook-campaign-salesforce-zero-day.html
6¡¢Group-IBÐû²¼Mysterious Team BangladeshµÄ·ÖÎö³ÂËß
8ÔÂ3ÈÕ£¬Group-IBÐû²¼Á˹ØÓÚºÚ¿ÍÍÅ»ïMysterious Team BangladeshµÄ·ÖÎö³ÂËß¡£¸ÃÍŻィÁ¢ÓÚ2020Ä꣬×Ô2022Äê6ÔÂÒÔÀ´£¬ÒÑÖ´ÐÐÁËÁè¼Ý750´ÎDDoS¹¥»÷ºÍ78´ÎÍøÕ¾¸Ä¶¯¹¥»÷£¬ÆäÊ×´´ÈËÊÇÔÚTelegramÉÏÒ»Ãû´úºÅΪD4RK_TSNµÄÓû§¡£¸ÃÍÅ»ïÖ÷ÒªÕë¶ÔÓ¡¶ÈºÍÒÔÉ«ÁеÄÎïÁ÷¡¢Õþ¸®ºÍ½ðÈÚÐÐÒµ¡£ÔÚÈ«Á¦¹¥»÷֮ǰ£¬Æä»á½øÐжÌÔݵIJâÊÔ¹¥»÷£¬ÒÔ¼ì²éÄ¿±ê¶ÔDDoS¹¥»÷µÄ·ÀÓùÄÜÁ¦¡£ÔÚijЩÇé¿öÏ£¬¸ÃÍÅ»ï¿ÉÄÜͨ¹ýÀûÓÃÒÑÖªµÄ©¶´»òÄþ¾²ÐԽϲîµÄÃÜÂëÀ´·ÃÎÊÍøÂç·þÎñÆ÷ºÍ¹ÜÀíÃæ°å¡£
https://www.group-ib.com/blog/mysterious-team-bangladesh/