Microsoft Teams ±»ÓÃÀ´Á÷´« DarkGate ¶ñÒâÈí¼þ

Ðû²¼Ê±¼ä 2024-02-01

1¡¢Microsoft Teams ±»ÓÃÀ´Á÷´« DarkGate ¶ñÒâÈí¼þ


1ÔÂ30ÈÕ £¬AT&T ÍøÂçÄþ¾²¹«Ë¾µÄÍøÂçÄþ¾²×¨¼Ò·¢ÏÖÁËÒ»¸öÁîÈ˵£ÓǵÄÇ÷ÊÆ£º¹ã·ºÊ¹ÓõÄЭ×÷ƽ̨Microsoft Teams±»ÓÃ×÷ÍøÂçµöÓãÕ©Æ­ºÍ¶ñÒâÈí¼þ¹¥»÷µÄÔØÌå¡£ËäȻͨ¹ýµç×ÓÓʼþ½øÐеĴ«Í³ÍøÂçµöÓãÈÔÈ»ÊÇÒ»ÖÖÆÕ±éµÄÍþв £¬µ« Microsoft Teams ÖÐÍⲿ·ÃÎʵļ¯³ÉΪ¶ñÒâÐÐΪÕß¿ª±ÙÁËеÄÀûÓÃÁìÓò¡£¹©Äú²Î¿¼ £¬Íⲿ·ÃÎÊ¿ÉÒÔʹÓà Teams¡¢Skype for Business »ò Skype Óë×éÖ¯ÍⲿµÄ¸öÈ˼ò»¯Í¨ÐźÍЭ×÷¡£DarkGate ¶ñÒâÈí¼þÊ״ηºÆðÓÚ 2017 Äê 12 Ô 25 ÈÕ £¬×î³õµÄ¹¦Ð§ÊÇÃÜÂëÇÔÈ¡·¨Ê½ºÍ¼ÓÃÜ»õ±ÒÍÚ¾ò·¨Ê½ £¬Ö÷Ҫͨ¹ý Torrent ÎļþÁ÷´«¡£¸Ã²¡¶¾ÊÇÓÉ enSilo Ñо¿Ô± Adi Zeligson ·¢ÏÖµÄ £¬ËûÊӲ쵽¸Ã²¡¶¾Õë¶ÔµÄÊÇ Windows ÊÂÇéÕ¾¡£ÊÓ²ìµÄÒªº¦ÊÇʶ±ð Teams »·¾³ÖеĿÉÒɻ¡£Áè¼Ý 1,000 ¸ö Microsoft Teams ʼþÒѱ»±êÖ¾ £¬±íÃ÷ÍøÂçµöÓãʵÑéµÄ·¶Î§¡£Í¨¹ýÀûÓà Microsoft 365×⻧ ID ²¢×Ðϸ¸ú×ÙÁÄÌì½»»¥ £¬MDR SOC ÍŶÓÀֳɲéÃ÷ÁËÊÜËðµÄÕÊ»§ºÍ×ʲúÒÔ½øÐÐÐÞ¸´¡£


https://www.hackread.com/microsoft-teams-external-access-darkgate-malware/


2¡¢Òâ´óÀûÊý¾Ý±£»¤»ú¹¹³ÆCHATGPTÎ¥·´Å·ÃËÒþ˽·¨


1ÔÂ30ÈÕ £¬Òâ´óÀûÊý¾Ý±£»¤¼à¹Ü»ú¹¹¡°Garante per la protezione dei dati personi¡±Ðû²¼ÒÑ֪ͨ OpenAI £¬ChatGPT Î¥·´ÁËÅ·ÃËÊý¾Ý±£»¤¹æÔò GDPR¡£2023Äê4ÔÂÉÏÑ® £¬Òâ´óÀûÊý¾Ý±£»¤¾Ö Òò·Ç·¨ÊÕ¼¯¸öÈËÊý¾ÝÇÒȱ·¦Ñé֤δ³ÉÄêÈËÄêÁäµÄϵͳ¶øÔÝʱ½ûÖ¹ ChatGPT ¡£¹ÜÀí¾ÖÖ¸³ö £¬OpenAI ²»»áÌáÐÑÓû§ËüÕýÔÚÊÕ¼¯ËûÃǵÄÊý¾Ý¡£Æäʱ £¬Òþ˽¼à¹Ü»ú¹¹ÌåÏÖ £¬Ã»ÓÐÖ´·¨ÒÀ¾ÝÖ§³Ö´ó¹æÄ£ÊÕ¼¯ºÍ´¦ÖøöÈËÊý¾ÝÀ´¡°ÑµÁ·¡±Æ½Ì¨ËùÒÀÀµµÄËã·¨¡£¹ÜÀí¾Ö¶Ô¸Ã·þÎñ½øÐÐÁËһЩ²âÊÔ £¬²¢È·¶¨ÆäÌṩµÄÐÅÏ¢²¢²»×ÜÊÇÓëÊÂʵÇé¿öÏà·û £¬Òò´Ë´¦ÖõĸöÈËÊý¾Ý½û¾øÈ·¡£¸Ã»ú¹¹Éù³Æ £¬¾¡¹Ü ChatGPT µÄ·þÎñÖ¼ÔÚÏìÓ¦ 13 ËêÒÔÉϵÄÓû§ £¬µ«¸Ã·þÎñÈÔʹδ³ÉÄêÈËÃæÁÙÓëÆäÄêÁä²»Ïà·ûµÄÏìÓ¦¡£ÆäʱOpenAIÐû³ÆÒÑÔÚ4ÔÂ30ÈÕµÄ×îºóÆÚÏÞÇ°Âú×ãÁËÒâ´óÀûÊý¾Ý±£»¤»ú¹¹µÄÒªÇó £¬Òò´Ë¶Ô¸ÃÁÄÌì»úÆ÷È˵ĽûÁî±»½â³ý¡£


https://securityaffairs.com/158359/laws-and-regulations/garante-chatgpt-violated-eu-privacy-laws.html


3¡¢¶íÂÞ˹ÔâÓöÈ«¹ú´ó·¶Î§»¥ÁªÍøÖжÏ


1ÔÂ30ÈÕ £¬¶íÂÞ˹ÕýÃæÁÙ´ó·¶Î§µÄ»¥ÁªÍøÖжÏ £¬È«¹ú¸÷µØµÄÓû§¶¼Êܵ½Ó°Ïì £¬µ±µØ .ru ÓòÉϵÄÍøÕ¾·ÃÎÊȨÏÞϽµ¡£¶íÂÞ˹Êý×Ö²¿ÖܶþÔÚ Telegram ÉÏ·¢±íÉùÃ÷³Æ £¬¸ÃÎÊÌâÓë .ru ÓòÃûµÄÈ«ÇòÓòÃûϵͳÄþ¾²À©Õ¹ (DNSSEC) µÄ¼¼ÊõÎÊÌâÓйØ £¬¸ÃÀ©Õ¹ÓÃÓÚ±£»¤»¥ÁªÍøЭÒéÍøÂçÖн»»»µÄÊý¾Ý¡£°üÂÞ×îÊÜ»¶Ó­µÄµ±µØËÑË÷ÒýÇæ Yandex.ru¡¢µç×ÓÉÌÎñÁìÏÈÕß Ozon.ru ºÍ Wildberry.ru ÔÚÄÚµÄÍøÕ¾ÒÔ¼°¸Ã¹ú×î´óÒøÐÐ Sberbank PJSC ºÍ VTB Group µÄÓ¦Ó÷¨Ê½¾ùÊܵ½Ó°Ïì¡£½»Í¨¼à¿Ø·þÎñ¡£


https://www.databreaches.net/russia-hit-with-widespread-internet-outage-across-country/


4¡¢Greatness Õë¶Ô Microsoft 365 µÄÐÂÍøÂçÍþв


1ÔÂ30ÈÕ £¬ÔÚ²»Í£ÑݱäµÄÍøÂçÍþвÖÐ £¬·ºÆðÁËÒ»ÖÖеÄΣÏÕ £¬ËüÒÔ¾ªÈ˵Ĺ¦Ð§Õë¶Ô Microsoft 365 Óû§¡£Trustwave Ö©ÖëʵÑéÊÒÒ»Ö±ÔÚÃÜÇмàÊÓ¡°Greatness¡±ÍøÂçµöÓ㹤¾ß°üµÄʹÓü¤Ôö £¬ÕâÊÇÒ»¸öÓÉÃûΪ¡°fisherstell¡±µÄÍþвÐÐΪÕß¿ª·¢µÄÅÓ´óµÄÍøÂçµöÓã¼´·þÎñƽ̨¡£×Ô 2022 ÄêÖÐÆÚÒÔÀ´ £¬Greatness ÌṩÁËÒ»¸öÓÃÓÚ³ïıÍøÂçµöÓã»î¶¯µÄ×ۺϹ¤¾ß°ü £¬ÏÖÔÚÒÔÿÔ 120 ÃÀÔªµÄ±ÈÌرҼ۸ñ»ñµÃ £¬ÁîÈËÕ𾪡£Greatness ʹÓÃÁ¿µÄÔö¼Ó £¬ÌرðÊÇ´Ó 2023 Äê 12 Ôµ½ 2024 Äê 1 Ô £¬ÒýÆðÁËÈËÃǵÄÑÏÖص£ÓÇ¡£Êܺ¦Õß¼òÖ±ÇÐÊýÁ¿Éв»Çå³þ £¬µ«¸Ã¹¤¾ß°üµÄ¹ã·ºÊ¹ÓúÍÇ¿´óµÄÖ§³Öϵͳ£¨°üÂÞרÃÅµÄ Telegram ÉçÇø£©Í¹ÏÔÁËÆäDZÔÚÍþв¡£GreatnessµÄÌصãÊǶ¨ÆÚ¸üР£¬ÔöÇ¿ÁËÈƹýÄþ¾²´ëÊ©µÄÄÜÁ¦¡£×îиüÐÂÓÚ 2024 Äê 1 ÔÂÉÏÑ®Ðû²¼ £¬²¢¸½ÓÐ Greatness Hub Telegram ƵµÀÉϵÄÏêϸÎĵµ £¬¸ÅÊöÁËÆäй¦Ð§¡¢ÌáʾºÍ¼¼ÇÉ¡£


https://securityonline.info/greatness-phishing-kit-the-new-cyber-menace-targeting-microsoft-365/


5¡¢ESET Ðû²¼ GrandoreiroÒøÐÐľÂíµÄ·ÖÎö³ÂËß


1ÔÂ30ÈÕ £¬ESET ÒÑÓë°ÍÎ÷Áª°î¾¯²ìºÏ×÷ £¬ÊÔͼÆÆ»µ Grandoreiro ½©Ê¬ÍøÂç¡£ESET ͨ¹ýÌṩ¼¼Êõ·ÖÎö¡¢Í³¼ÆÐÅÏ¢ÒÔ¼°ÒÑÖªµÄÃüÁîºÍ¿ØÖÆ (C&C) ·þÎñÆ÷ÓòÃûºÍ IP µØַΪ¸ÃÏîÄ¿×ö³öÁËТ¾´¡£ÓÉÓÚ Grandoreiro ÍøÂçЭÒéµÄÉè¼ÆȱÏÝ £¬ESET Ñо¿ÈËÔ±»¹Äܹ»Ò»¶ÃÊܺ¦ÕßµÄÇé¿ö¡£ESET ×Ô¶¯»¯ÏµÍ³ÒÑ´¦ÖÃÊýÒÔÍò¼ÆµÄ Grandoreiro Ñù±¾¡£¸Ã¶ñÒâÈí¼þ×Ô 2020 Äê 10 ÔÂ×óÓÒ¿ªÊ¼Ê¹ÓõÄÓòÉú³ÉËã·¨ (DGA) ÿÌ춼ÊÐÉú³ÉÒ»¸öÖ÷Óò £¬²¢¿ÉÑ¡ÔñÉú³É¶à¸ö¹ÊÕÏÄþ¾²Óò¡£DGA ÊÇ Grandoreiro ÖªµÀÈçºÎÏò C&C ·þÎñÆ÷³ÂËßµÄΨһ·½Ê½¡£³ýÁ˵±Ç°ÈÕÆÚÖ®Íâ £¬DGA »¹½ÓÊܾ²Ì¬ÅäÖà - ½ØÖÁ׫д±¾ÎÄʱ £¬ÎÒÃÇÒѾ­ÊӲ쵽 105 ¸ö´ËÀàÅäÖá£


https://www.welivesecurity.com/en/eset-research/eset-takes-part-global-operation-disrupt-grandoreiro-banking-trojan/


6¡¢¹ú¼Ê½ðÈڿƼ¼¹«Ë¾ Direct Trading Technologies й¶Áè¼Ý 30 ÍòÓû§Êý¾Ý


1ÔÂ31ÈÕ £¬Direct Trading Technologies (DTT) ÊÇÒ»¼Ò¹ú¼Ê½ðÈڿƼ¼¹«Ë¾ £¬ËäÈ»Ö÷Òª¿Í»§Î»ÓÚɳÌØ°¢À­²® £¬µ«¸Ã¹«Ë¾ÔÚÓ¢¹ú¡¢Á¢ÌÕÍð¡¢°¢ÁªÇõ¡¢¿ÆÍþÌØ¡¢¸çÂ×±ÈÑÇ¡¢ÍÁ¶úÆä¡¢°ÍÁÖ¡¢Àè°ÍÄÛºÍÍßŬ°¢Í¼¹²ºÍ¹úÉèÓзþÎñ´¦¡£·¢ÏÖµÄĿ¼°üÂÞ¶à¸öÊý¾Ý¿â±¸·Ý £¬Ã¿¸ö±¸·Ý¶¼°üÂÞÓйع«Ë¾Óû§ºÍºÏ×÷»ï°éµÄ´óÁ¿Ãô¸ÐÐÅÏ¢¡£´Ë´ÎйÃÜʼþ´øÀ´Á˶àÖÖ·çÏÕ £¬´ÓÉí·Ý͵ÇÔµ½½»Ò×ÕßÕË»§µÄ½Ó¹ÜºÍ¶ÒÏÖ¡£Ð¹Â¶µÄÊý¾Ý°üÂÞ¹ýÈ¥ÁùÄêÁè¼Ý 30 ÍòÓû§µÄ½»Ò׻ £¬ÒÔ¼°ÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢¹«Ë¾·¢Ë͵ĵç×ÓÓʼþºÍ IP µØÖ·¡£³ÖÓй«Ë¾µç×ÓÓʼþµØÖ·µÄÓû§£¨¿ÉÄÜÊÇÔ±¹¤£©µÄÃÜÂëÒÔÃ÷ÎÄÐÎʽ̻¶¡£ÓÃÓÚ·ÃÎÊ DTT ½»Ò×ƽ̨Óû§ÕÊ»§µÄ¹þÏ£ÃÜÂëÒ²±»Ð¹Â¶¡£Ò»Ð©¿Í»§µÄ¼Òͥסַ¡¢µç»°ºÅÂëºÍ²¿ÃÅÐÅÓÿ¨ÐÅÏ¢±»Ð¹Â¶¡£


https://securityaffairs.com/158384/security/data-leak-at-fintech-direct-trading-technologies.html