TikTokÒòÇÖ·¸¶ùͯÒþ˽±»°®¶ûÀ¼DPC· £¿î3.68ÒÚÃÀÔª

Ðû²¼Ê±¼ä 2023-09-18

1¡¢TikTokÒòÇÖ·¸¶ùͯÒþ˽±»°®¶ûÀ¼DPC· £¿î3.68ÒÚÃÀÔª


¾ÝýÌå9ÔÂ16ÈÕ±¨µÀ £¬°®¶ûÀ¼Êý¾Ý± £»¤Î¯Ô±»á(DPC)¶ÔTikTok´¦ÒÔ3.45ÒÚÅ·Ôª£¨3.68ÒÚÃÀÔª£©µÄ· £¿î £¬Ô­ÒòÊÇËüÔÚ´¦ÖÃ13ÖÁ17Ëê¶ùͯµÄÊý¾ÝʱÇÖ·¸ÁËËûÃǵÄÒþ˽ ¡£TikTok¶ùͯÓû§µÄ¸öÈË×ÊÁÏÉèÖÃĬÈÏΪ¹ûÈ»¿É¼û £¬Æ½Ì¨ÄÚÍâµÄÈκÎÈ˶¼¿ÉÒÔ¿´µ½ËùÓÐÐû²¼µÄÄÚÈÝ ¡£´ËÍâ £¬¡°¼ÒÍ¥Åä¶Ô¡±¹¦Ð§Ò²´æÔÚȱÏÝ £¬¿É±»ÓÃÀ´½«¶ùͯÕË»§Ó롰δ¾­ÑéÖ¤¡±µÄ³ÉÄêÈ˹ØÁªÆðÀ´ ¡£¸Ã¹«Ë¾·¢±íÉùÃ÷³Æ²îÒìÒâÕâÒ»¾ö¶¨ £¬ÓÈÆäÊÇ· £¿îÊý¶î £¬²¢ÔÚÆÀ¹ÀÊÇ·ñ»á¾ÍDPCµÄ²Ã¾öÏò¸ßµÈ·¨ÔºÌá³öÉÏËß ¡£


https://securityaffairs.com/150918/breaking-news/tiktok-fined-e345m-irish-dpc.html


2¡¢RetoolµÄÔ±¹¤Ôâµ½µöÓã¹¥»÷µ¼Ö²¿ÃÅ¿Í»§µÄÕË»§Ð¹Â¶


¾Ý9ÔÂ15ÈÕ±¨µÀ £¬Èí¼þ¹«Ë¾RetoolÔâµ½ÓÐÕë¶ÔÐԵĶà½×¶ÎÉ繤¹¥»÷µ¼ÖÂ27ÃûÔÆ¿Í»§µÄÕÊ»§Ð¹Â¶ ¡£¹¥»÷·¢ÉúÔÚ8ÔÂ27ÈÕ £¬¹¥»÷ÕßÀûÓõöÓã¶ÌÐźÍÉ繤¹¥»÷Èƹý¶àÖØÄþ¾²¿ØÖÆ £¬ÈëÇÖÁËÒ»ÃûITÔ±¹¤µÄOktaÕÊ»§ ¡£µÇ¼ºó £¬¹¥»÷ÕßαÔìÔ±¹¤µÄÉùÒô²¢ÖµçÄ¿±êITÍŶӳÉÔ± £¬ÓÕÆ­ËûÃÇÌṩÌرðµÄMFA´úÂë £¬´Ó¶ø½«¹¥»÷ÕßµÄÉ豸Ìí¼Óµ½Ä¿±êÔ±¹¤µÄOktaÕÊ»§ÖÐ ¡£Retool½«´Ë´Î¹¥»÷¹é¾ÌÓÚGoogle AuthenticatorÖпɽ«2FA´úÂëÓëÆäGoogleÕÊ»§Í¬²½µÄй¦Ð§ ¡£Coindesk½«Retool¹¥»÷Óë9Ô³õFortress TrustµÄ1500ÍòÃÀÔª±»µÁʼþÁªÏµÔÚÒ»Æð ¡£


https://www.bleepingcomputer.com/news/security/retool-blames-breach-on-google-authenticator-mfa-cloud-sync-feature/


3¡¢¸çÂ×±ÈÑÇÔâµ½´ó¹æÄ£¹¥»÷Ó°Ïì¶à¸öÕþ¸®»ú¹¹µÄÍøÕ¾


ýÌå9ÔÂ16ÈÕ³Æ £¬¸çÂ×±ÈÑǶà¸öÖØÒªµÄÕþ¸®»ú¹¹ÕýÔÚÓ¦¶ÔÀÕË÷¹¥»÷ ¡£ÃÀ¹úµÄ¼¼ÊõÌṩÉÌIFX Networks ColumbiaÔâµ½ÀÕË÷¹¥»÷ £¬Ó°ÏìÁ˸çÂ×±ÈÑÇ˾·¨²¿¡¢ÎÀÉú²¿¡¢ÎÄ»¯²¿ÒÔ¼°¼¸¼ÒÒ½ÔºµÈµÄÍøÕ¾ ¡£ÉÏÖÜÈý £¬ÎÀÉú²¿³Æ´ÓÖܶþ¿ªÊ¼ÃæÁÙÎÊÌâ ¡£Ë¾·¨²¿ÔÚÉÏÖÜËijƽ«ÔÝÍ£9ÔÂ14ÈÕÖÁ20ÈÕµÄËùÓÐÌýÖ¤»á ¡£Ä¿Ç° £¬ÉÐÎÞ¹¥»÷ÍÅ»ïÌåÏÖ¶Ô´ËʼþÂôÁ¦ £¬µ«ÓÐÑо¿ÈËÔ±¹ûÈ»ÁËÀÕË÷ÐŵĽØͼ֤Ã÷´Ë´Î¹¥»÷¿ÉÄÜÊÇRansomHouseËùΪ ¡£


https://therecord.media/colombia-government-ministries-cyberattack


4¡¢Sophos³ÆBlackCatÀûÓÃÐÂSphynxÀ´¼ÓÃÜAzureÔÆ´æ´¢


9ÔÂ16ÈÕ±¨µÀ³Æ £¬ÀÕË÷Èí¼þBlackCatÏÖÔÚ¿ªÊ¼ÀûÓñ»µÁµÄMicrosoftÕÊ»§ºÍеÄSphynx±äÌåÀ´¹¥»÷Azure´æ´¢ ¡£¹¥»÷ÕßʹÓñ»µÁµÄOTP»ñµÃSophos CentralÕÊ»§µÄ·ÃÎÊȨÏÞºó £¬½ûÓÃÁË·À¸Ä¶¯¹¦Ð§²¢ÐÞ¸ÄÁËÄþ¾²¼Æı ¡£Ëæºó £¬ËûÃǼÓÃÜÁËÄ¿±êµÄϵͳºÍÔ¶³ÌAzureÔÆ´æ´¢ £¬²¢½«Ìí¼ÓÁËÀ©Õ¹Ãû.zk09cvt ¡£ÀÕË÷ÍÅ»ïÀֳɼÓÃÜÁË39¸öAzure´æ´¢ÕË»§ ¡£ÔÚÕû¸öÈëÇÖ¹ý³ÌÖÐ £¬¹¥»÷Õß»¹Ê¹ÓÃÁËAnyDesk¡¢SplashtopºÍAteraµÈ¶àÖÖÔ¶³Ì¼à¿ØºÍ¹ÜÀí(RMM)¹¤¾ß ¡£ 


https://www.bleepingcomputer.com/news/security/blackcat-ransomware-hits-azure-storage-with-sphynx-encryptor/


5¡¢Nuance±»Clop¹¥»÷µ¼Ö±±¿¨ÂÞÀ´ÄÉÖݶà¼ÒÒ½ÔºÊý¾Ýй¶


¾Ý9ÔÂ17ÈÕ±¨µÀ £¬Î¢ÈíÆìϵÄÒ½ÁƼ¼Êõ¹«Ë¾NuanceÔâµ½ÁËClopµÄ¹¥»÷ £¬µ¼Ö±±¿¨ÂÞÀ´ÄÉÖݶà¼ÒÒ½ÔººÍÒ½ÁƱ£½¡ÌṩÉ̵ĸöÈËÐÅϢй¶ ¡£´Ë´Î¹¥»÷Ó°ÏìÁËAtrium Health¡¢Catawba Valley Medical CenterºÍCharlotte RadiologyµÈ»ú¹¹ £¬Ð¹Â¶ÁËÈËÃǽÓÊܵķþÎñ¼°ÈË¿Úͳ¼ÆÐÅÏ¢ ¡£¾ÝϤ £¬ÕâÊÇÀûÓÃProgress MOVEit TransferÖЩ¶´µÄ¹¥»÷»î¶¯µÄÒ»²¿ÃÅ ¡£¸Ã©¶´ÓÚ5ÔÂ31ÈÕ±»ÐÞ¸´ £¬NuanceÌåÏÖ²¹¶¡Ò»¾­ÍƳö¾ÍÁ¢¼´°²×°ÁË ¡£


https://securityaffairs.com/150949/cyber-crime/north-carolina-hospitals-data-breach.html


6¡¢Î¢ÈíÐû²¼Peach SandstormÃÜÂëÅçÈ÷»î¶¯µÄ·ÖÎö³ÂËß


9ÔÂ14ÈÕ £¬Î¢ÈíÐû²¼³ÂËß³Æ×Ô2Ô·ÝÒÔÀ´ £¬ÒÁÀÊÍÅ»ïPeach Sandstorm(HOLMIUM)ÒѶÔÈ«ÇòÊýǧ¸öÄ¿±êÌᳫÁËÃÜÂëÅçÈ÷¹¥»÷ ¡£¸ÃÍÅ»ï×î½üÖ÷ÒªÕë¶ÔÎÀÐÇ¡¢¹ú·ÀºÍÖÆÒ©ÁìÓòµÄÆóÒµ ¡£¹¥»÷ÕßʵÑéͨ¹ýµ¥¸öÃÜÂë»ò³£ÓÃÃÜÂëÁбíµÇ¼¶à¸öÕÊ»§ £¬ÕâÖÖ¼ÆıÓëʹÓÃÒ»³¤´®ÃÜÂëÀ´Õë¶Ôµ¥¸öÕÊ»§µÄ±©Á¦¹¥»÷²îÒì ¡£¹¥»÷Õß»¹ÀûÓÃÕë¶ÔδÐÞ¸´µÄConfluenceºÍManageEngineÉ豸µÄ©¶´À´ÈëÇÖÄ¿±êÍøÂç ¡£Àֳɺó £¬¹¥»÷ÕßʹÓÃAzureHound»òRoadtools¿ªÔ´Äþ¾²¿ò¼ÜÔÚÄ¿±êµÄAzure Active DirectoryÖÐÕì²ì £¬²¢´ÓÆäÔÆ»·¾³ÖлñÈ¡Êý¾Ý ¡£


https://www.microsoft.com/en-us/security/blog/2023/09/14/peach-sandstorm-password-spray-campaigns-enable-intelligence-collection-at-high-value-targets/