ÃÀ¹úPJ&A³ÆÍøÂç¹¥»÷µ¼ÖÂÆä½ü900Íò»¼ÕßµÄÐÅϢй¶

Ðû²¼Ê±¼ä 2023-11-17
1¡¢ÃÀ¹úPJ&A³ÆÍøÂç¹¥»÷µ¼ÖÂÆä½ü900Íò»¼ÕßµÄÐÅϢй¶


¾Ý11ÔÂ15ÈÕ±¨µÀ £¬PJ&A(Perry Johnson & Associates)͸¶ £¬½ñÄê3ÔµÄÒ»´ÎÍøÂç¹¥»÷й¶Á˽ü900Íò»¼ÕßµÄÐÅÏ¢¡£PJ&AΪÃÀ¹úµÄÒ½ÁÆ»ú¹¹ÌṩҽÁÆ×ªÂ¼·þÎñ £¬¸Ã¹«Ë¾ÌåÏÖ¹¥»÷ÕßÈëÇÖÁËËûÃǵÄϵͳ £¬²¢ÔÚ3ÔÂ27ÈÕÖÁ5ÔÂ2ÈÕÆÚ¼ä½øÐÐÁË·ÃÎÊ¡£Ð¹Â¶Êý¾Ý°üÂÞÐÕÃû¡¢²¡ÀúºÅ¡¢Éç»áÄþ¾²ºÅÂë(SSN)¡¢±£ÏÕÐÅÏ¢ºÍÒ½ÁÆ×ªÂ¼ÎļþµÈ £¬Ó°ÏìÁË8952212Ãû»¼Õß¡£14ÈÕ £¬Å¦Ô¼×î´óµÄÒ½ÁÆÌṩÉÌNorthwell Health³Æ £¬ PJ&AÔâµ½¹¥»÷µ¼ÖÂÆäÊý¾ÝÔÚ4ÔÂ7ÈÕÖÁ19ÈÕ±»µÁ £¬Éæ¼°Áè¼Ý380ÍòÈË¡£


https://www.bleepingcomputer.com/news/security/pj-and-a-says-cyberattack-exposed-data-of-nearly-9-million-patients/


2¡¢Ô½ÄÏÓÊÕþ¹«Ë¾ÅäÖôíÎóµ¼ÖÂÔ¼1.2TBÊý¾Ýй¶


ýÌå11ÔÂ16ÈÕ³Æ £¬Ñо¿ÍŶӷ¢ÏÖÁËÒ»¸öÊôÓÚÔ½ÄÏÓÊÕþ¹«Ë¾µÄ¿ª·ÅKibanaʵÀý¡£KibanaÊÇÒ»¸öÓÃÓÚÊý¾ÝËÑË÷ºÍ·ÖÎöµÄ¿ÉÊÓ»¯¿ØÖÆÃæ°å £¬×ÊÖúÆóÒµ´¦ÖôóÁ¿Êý¾Ý¡£ÔÚ·¢ÏÖʱ £¬Êý¾Ý´æ´¢°üÂÞ2.26ÒÚ¸ö¼Ç¼Ê¼þ £¬¹²·¢ÉúÁË1.2TBÊý¾Ý £¬¶øÇÒÕýÔÚʵʱ¸üС£Ð¹Â¶ÐÅÏ¢°üÂÞÄþ¾²ÈÕÖ¾ £¬ÒÔ¼°Ô±¹¤µÄÐÕÃûºÍµç×ÓÓʼþ¡£Ä¿Ç° £¬¸Ã¹«Ë¾Òѽ«ÕâЩÊý¾Ý±£»¤ÆðÀ´¡£


https://securityaffairs.com/154271/data-breach/vietnam-post-data-leak.html


3¡¢ºÚ¿ÍÉù³ÆÒÑÈëÇÖPlume¹«Ë¾²¢ÊÕ¼¯Áè¼Ý1500ÍòÐÐÊý¾Ý


¾ÝýÌå11ÔÂ15ÈÕ±¨µÀ £¬¹¥»÷ÕßÉù³ÆÇÔÈ¡ÁËÖÇÄÜWiFiÌṩÉÌPlumeÁè¼Ý20GBµÄÊý¾Ý¿â £¬ÆäÖаüÂÞÁè¼Ý1500ÍòÐÐÊý¾Ý¡£PlumeÉÐδ֤ʵÕâÒ»ÏûÏ¢ £¬ÌåÏÖÒÑÁ˽⹥»÷ÕßµÄ˵·¨ £¬²¢Õ¹¿ªÊÓ²ìÒÔºËʵÕâЩ˵·¨¡£ÓÉÓÚ¶ÔPlumeµÄ»ØÓ¦²»Âú £¬ºÚ¿ÍÐû²¼ÁËÁ½¸öCSVÎļþ £¬°üÂÞ´óÁ¿¿Í»§ºÍÔ±¹¤µÄÐÅÏ¢¡£´ËÍâ £¬ºÚ¿Í»¹Í¸Â¶´Ë´Îй¶Ê¼þÊÇÓÉPlumeµÄÒ»ÃûǰԱ¹¤´Ù³ÉµÄ £¬ËûÓÚ2023ÄêÀ뿪¹«Ë¾ £¬µ«ÈÔȻӵÓзÃÎÊȨÏÞ¡£¹¥»÷Õ߸øÁ˸ù«Ë¾48СʱÀ´Âú×ãËûÃǵÄÒªÇó £¬·ñÔò½«Ð¹Â¶¸ü¶àÊý¾Ý¡£


https://www.hackread.com/hackers-smart-wi-fi-provider-plume-data-breach/


4¡¢FBIµÈ»ú¹¹ÁªºÏÅû¶ÀÕË÷ÍÅ»ïRhysidaµÄTTPµÈÐÅÏ¢


11ÔÂ15ÈÕ £¬CISA¡¢FBIºÍMS-ISACÐû²¼Á˹ØÓÚÀÕË÷ÍÅ»ïRhysidaµÄÁªºÏÍøÂçÄþ¾²×Éѯ(CSA)¡£¸Ã×ÉѯÌṩÁ˽ØÖÁ9ÔµÄÊÓ²ìÆÚ¼ä·¢ÏÖµÄIoC¡¢¼ì²âÐÅÏ¢ÒÔ¼°RhysidaµÄÕ½Êõ¡¢¼¼ÊõºÍ·¨Ê½(TTP)¡£Rhysida×Ô½ñÄê5ÔÂÒÔÀ´Ò»Ö±»îÔ¾ £¬ÒÑÓÐÖÁÉÙÓÐ62¼Ò¹«Ë¾Ôâµ½Æä¹¥»÷¡£RhysidaÒÔRaaSµÄģʽ¹¥»÷½ÌÓý¡¢ÖÆÔì¡¢ÐÅÏ¢¼¼ÊõÐÐÒµºÍÕþ¸®»ú¹¹¡£´ËÍâ £¬Rhysida»¹ÀûÓÃÁËÔ¶³Ì·þÎñ£¨ÈçVPNºÍRDP£©À´»ñµÃ¶Ô³õʼ·ÃÎʲ¢±£³Ö³Ö¾ÃÐÔ £¬²¢ÀûÓÃÁ˵öÓã¹¥»÷ºÍZerologon©¶´£¨CVE-2020-1472£©¡£


https://www.cisa.gov/news-events/alerts/2023/11/15/cisa-fbi-and-ms-isac-release-advisory-rhysida-ransomware


5¡¢McAfee·¢ÏÖÕë¶Ôº«¹úÁ÷´«¶ñÒâÇÔÈ¡·¨Ê½µÄµöÓã»î¶¯


11ÔÂ15ÈÕ £¬McAfee³ÆÆä·¢ÏÖÁËͨ¹ýµöÓãÍøÕ¾Á÷´«¶ñÒâAndroidºÍiOSÐÅÏ¢ÇÔÈ¡·¨Ê½µÄ»î¶¯¡£¸Ã»î¶¯ÓÚ10Ô³õ¿ªÊ¼»îÔ¾ £¬ÒÑѬȾ200¶ą̀É豸 £¬ËùÓÐÉ豸¶¼Î»ÓÚº«¹ú¡£¹¥»÷Õß×î³õͨ¹ý¶ÌÐŽӽüÄ¿±ê £¬²¢»áʵÑé×ªÒÆµ½LINE Messenger¡£È»ºó·¢ËÍÖ¸ÏòµöÓãÍøÕ¾µÄÁ´½Ó £¬¸ÃÍøÕ¾Î±×°³ÉCamtalk £¬ÓÕʹĿ±êÏÂÔØ¶ñÒâAndroidºÍiOSÓ¦ÓᣳýÁËð³äÉç½»Ó¦Óà £¬¸Ã»î¶¯»¹ÔÚÆäµöÓãÍøÕ¾ÖÐʹÓÃÁËÆäËüÖ÷Ìâ¡£´Ë´Î»î¶¯Ö÷ÒªÕë¶Ôº«¹ú £¬ÏÖÒÑ·¢ÏÖ10¸öµöÓãÍøÕ¾ £¬¶ñÒâÈí¼þ»áÇÔȡĿ±êµÄµç»°ºÅÂë¡¢¹ØÁªÁªÏµÈ˺ͶÌÐŵȡ£


https://www.mcafee.com/blogs/other-blogs/mcafee-labs/fake-android-and-ios-apps-steal-sms-and-contacts-in-south-korea/


6¡¢MalwarebytesÐû²¼10Ô·ÝÀÕË÷Èí¼þÌ¬ÊÆµÄ·ÖÎö³ÂËß


MalwarebytesÔÚ11ÔÂ15ÈÕÐû²¼ÁË10Ô·ÝÀÕË÷Èí¼þÌ¬ÊÆµÄ·ÖÎö³ÂËß¡£10ÔÂ·Ý £¬ÀÕË÷ÍÅ»ïµÄÍøÕ¾ÉÏÁгöÁË318¸öеı»¹¥»÷Ä¿±ê¡£×î»îÔ¾µÄÊÇLockBit(64¸ö)¡¢NoEscape(40¸ö)ºÍPLAY(36¸ö)¡£ÓÐ3¸öÖ÷ÒªµÄÀÕË÷ÍŻﱻ¹Ø±Õ £¬·Ö±ðÊÇRansomedVC¡¢RagnarºÍTrigona¡£ÕâÒ»¸öÔ·ºÆðÁËÒ»¸öеÄÀÕË÷ÍÅ»ïHunters International £¬ÒÉËÆÊÇHiveµÄ¸üÃû¡£Ôâµ½ÀÕË÷¹¥»÷×î¶àµÄ¹ú¼ÒÊÇÃÀ¹ú£¨148Æð£© £¬Æä´ÎÊÇÓ¢¹ú£¨34£©ºÍÒâ´óÀû£¨19£©¡£


https://www.malwarebytes.com/blog/threat-intelligence/2023/11/ransomware-review-november-2023