LabHost ¿Éµ¼ÖÂÈκÎÈ˶ԼÓÄôóÒøÐÐÓû§½øÐÐÍøÂçµöÓã

Ðû²¼Ê±¼ä 2024-02-29

1. LabHost ¿Éµ¼ÖÂÈκÎÈ˶ԼÓÄôóÒøÐÐÓû§½øÐÐÍøÂçµöÓã


2ÔÂ27ÈÕ £¬ÍøÂçµöÓã (PhaaS) ƽ̨¡°LabHost¡±Ò»Ö±ÔÚ×ÊÖúÍøÂç·¸×ï·Ö×ÓÃé×¼±±ÃÀÒøÐÐ £¬ÌرðÊǼÓÄôóµÄ½ðÈÚ»ú¹¹ £¬µ¼Ö»ÏÔ×ÅÔö¼Ó¡£PhaaS ƽ̨ΪÍøÂç·¸×ï·Ö×ÓÌṩ½»Ô¿³×ÍøÂçµöÓãÌ×¼þ¡¢ÍйÜÒ³ÃæµÄ»ù´¡ÉèÊ©¡¢µç×ÓÓʼþÄÚÈÝÉú³ÉºÍ»î¶¯¸ÅÊö·þÎñ £¬ÒÔ»»È¡Ã¿Ô¶©ÔÄ¡£LabHost ²¢²»ÊÇÒ»¼ÒÐÂÌṩÉÌ £¬µ«ÔÚ 2023 ÄêÉÏ°ëÄêΪ¼ÓÄôóÒøÐÐÍƳö¶¨ÖÆÍøÂçµöÓ㹤¾ß°üºó £¬ÆäÊÜ»¶Ó­Ë®Æ½ì­Éý¡£ÍøÂçµöÓã¼´·þÎñƽ̨ʹ²»ÊìÁ·µÄºÚ¿Í¸üÈÝÒ×ʵʩÍøÂç·¸×ï £¬´Ó¶øÏÔ×ÅÀ©´óÁËÍþвÐÐΪÕߵķ¶Î§ £¬²¢ÔÚ¸ü¹ã·ºµÄ·¶Î§ÄÚÓ°ÏìÍøÂçÄþ¾²¡£Ñо¿ÈËÔ±×î½ü¾¯¸æµÄÆäËûÖøÃû PhaaS ƽ̨°üÂÞ¡° Greatness ¡±ºÍ¡° Robin Banks ¡± £¬ËüÃǾùÓÚ 2022 ÄêÖÐÆÚÍƳö £¬¾ßÓÐ MFA Èƹý¡¢×Ô½ç˵ÍøÂçµöÓ㹤¾ß°üºÍ¹ÜÀíÃæ°å¡£


https://www.bleepingcomputer.com/news/security/labhost-cybercrime-service-lets-anyone-phish-canadian-bank-users/


2. U-Haul ³ÂËß 67000 Ãû¿Í»§Êܵ½Êý¾Ý鶵ÄÓ°Ïì


2ÔÂ28ÈÕ £¬U-Haul ÊÇÒ»¼ÒλÓÚÑÇÀûÉ£ÄÇÖݵĿ¨³µ¡¢ÍϳµºÍ×ÔÖú²Ö´¢×âÁÞ¹«Ë¾ £¬È¥ÄêÄêµ×ÒÑ¿ªÊ¼Ïò 67,000 Ãû¿Í»§Í¨±¨Êý¾Ýй¶Ê¼þ £¬¸Ãʼþµ¼ÖÂËûÃǵĸöÈËÐÅÏ¢Ô⵽й¶¡£¸Ã©¶´·¢ÉúÔÚ 12 Ô 5 ÈÕ £¬Æäʱδ¾­ÊÚȨµÄ¹¥»÷ÕßÒÔijÖÖ·½Ê½Ê¹ÓúϷ¨Æ¾¾Ý·ÃÎÊU-Haul¾­ÏúÉ̺ÍÍŶӳÉÔ±ÓÃÀ´¸ú×Ù¿Í»§Ô¤¶©ºÍ¼ì²ì¿Í»§¼Ç¼µÄϵͳ¡£U-Haul ·¢ÏÖÕâһʼþºó £¬Á¢¼´Æô¶¯ÁËÏìӦЭÒé £¬²¢ÓëÒ»¼ÒÍøÂçÄþ¾²¹«Ë¾Ò»Æð¶Ô´Ë´Îй¶Ê¼þÕ¹¿ªÁËÊӲ졣ÊÓ²ìÏÔʾ £¬Ä³Ð©¿Í»§¼Ç¼ÔÚ´Ë´Îй¶Öб»·ÃÎÊ £¬°üÂÞ¾ÓסÔÚÃåÒòÖÝµÄ 136 Ãû¸öÈ˵ÄÐÕÃûºÍ¼ÝʻִÕÕÐÅÏ¢¡£U-HaulÔÚ¸øÊÜÓ°Ïì¸öÈ˵Ä֪ͨÐÅÖÐÖ¸³ö £¬´Ë´ÎÎ¥¹æʼþÉæ¼°µÄ¿Í»§¼Ç¼ϵͳδÁ¬½Óµ½Ö§¸¶ÏµÍ³ £¬Òò´ËÍþвÐÐΪÕßûÓзÃÎÊÈκÎÒøÐп¨Êý¾Ý¡£È»¶ø £¬¶ÔÓÚ×âÁÞ¹«Ë¾À´Ëµ £¬ÕâÖÖÎ¥¹æÐÐΪ²¢²»ÊǵÚÒ»´Î¡£


https://www.darkreading.com/cyberattacks-data-breaches/67k-customers-impacted-by-data-breach-according-to-u-haul


3. Õë¶Ô UnitedHealth Optum µÄ¹¥»÷µ¼ÖÂÒ½ÁƱ£½¡¼Æ·ÑÖжÏ


2ÔÂ27ÈÕ £¬È«ÇòÊÕÈë×î´óµÄÒ½ÁƱ£½¡¹«Ë¾ÁªºÏ½¡¿µ¼¯ÍÅ (UnitedHealth Group) ֤ʵ £¬Æä×Ó¹«Ë¾ Optum ×î½üÔÚ Change Healthcare ¼Æ·Ñƽ̨ÉÏÔâÓöÁËÑÏÖصÄÍøÂç¹¥»÷¡£´Ë´Î¹¥»÷µ¼ÖÂÃÀ¹ú¸÷µØÒ½ÁƱ£½¡¼Æ·Ñ·þÎñÑÏÖØÖжÏ £¬¸øÈ«¹ú·¶Î§ÄÚµÄÒ½ÁÆÕïËù¡¢Ò©·¿ºÍ±£ÏÕÌṩÉÌÔì³É»ìÂÒ¡£Æ¾¾Ý UnitedHealth µÄÉùÃ÷ £¬´Ë´Î¹¥»÷ÒÉËÆÓɾ­Ñ鸻ºñµÄÃñ×å¹ú¼ÒºÚ¿ÍËùΪ £¬ËûÃÇÄܹ»Éø͸ Optum µÄϵͳ²¢ÆÈʹ¸Ã¹«Ë¾¹Ø±Õ IT »ù´¡ÉèÊ©ÒÔÍ£Ö¹Íþв¡£Êܵ½¹¥»÷µÄ Change Healthcare ƽ̨¶ÔÓÚ´Ù½øÒ½ÁƱ£½¡ÌṩÕßÖ®¼äµÄÖ§¸¶½»»»ÖÁ¹ØÖØÒª £¬´Ó¶øʵÏÖµç×Ó½¡¿µ¼Ç¼¡¢Ë÷Åâ´¦Öᢻ¤ÀíЭµ÷ºÍÊý¾Ý·ÖÎöµÈÒªº¦¹¦Ð§¡£ÓÉÓÚÎÞ·¨Ê¹Óà Optum µÄ¼Æ·Ñ¹¤¾ß £¬Ðí¶àÒ©·¿¡¢ÕïËùºÍÒ½ÁƼƷѹ«Ë¾¶¼³ÂËßÁËÑÏÖصÄÔËÓªÌôÕ½ºÍÔ¤Ô¼ÖжÏ¡£Õâ´ÎÍ£µçÀ´µÃʵÔÚÊÇÌ«Ôã¸âÁË £¬ÒòΪҽÁƱ£½¡ÌṩÕßÕýÔÚÓ¦¶ÔÒ½ÁÆ·þÎñÐèÇóµÄ¼¤Ôö¡£ÔÚ Optum ÍêÈ«»Ö¸´·þÎñ֮ǰ £¬Ó°ÏìÔ¤¼Æ½«Á¬ÐøÊýÌìÉõÖÁÊýÖÜ¡£


https://securityboulevard.com/2024/02/major-cyberattack-on-unitedhealths-optum-causes-widespread-healthcare-billing-disruption/


4. LoanDepot³ÆÔ¼ 1700 Íò¿Í»§µÄÐÅÏ¢ÔÚÍøÂç¹¥»÷Æڼ䱻µÁ


2ÔÂ26ÈÕ £¬LoanDepot ÒÑ֤ʵ £¬½ü 1700 Íò LoanDepot ¿Í»§µÄÃô¸Ð¸öÈËÐÅÏ¢£¨°üÂÞÉç»áÄþ¾²ºÅÂ룩ÔÚ 1 Ô·ݵÄÀÕË÷Èí¼þ¹¥»÷Öб»µÁ¡£Õâ¼Ò´û¿îºÍµÖѺ´û¿î¾ÞÍ·¹«Ë¾ÔÚÏòÃåÒòÖÝ×ܼì²ì³¤°ì¹«ÊÒÌá½»µÄÊý¾Ýй¶֪ͨÖÐÌåÏÖ £¬±»µÁµÄ LoanDepot ¿Í»§Êý¾Ý°üÂÞÐÕÃû¡¢³öÉúÈÕÆÚ¡¢µç×ÓÓʼþºÍÓÊÕþµØÖ·¡¢²ÆÕþÕʺź͵绰ºÅÂë¡£±»µÁÊý¾Ý»¹°üÂÞ LoanDepot ´Ó¿Í»§ÄÇÀïÊÕ¼¯µÄÉç»áÄþ¾²ºÅÂë¡£ÊÜÓ°ÏìµÄ LoanDepot ¿Í»§ÊýÁ¿½ÏÉϸöÔÂ×î³õÏòÁª°î¼à¹Ü»ú¹¹Åû¶µÄ1660 ÍòÓÐËùÔö¼Ó £¬Áª°î¼à¹Ü»ú¹¹²¢Î´Í¸Â¶¾ßÌåÄÄЩ¿Í»§Êý¾Ý±»µÁ¡£´Ë´ÎÍøÂç¹¥»÷µ¼Ö LoanDepot µÄÊý°ÙÍò¿Í»§ÔÚ½ÓÏÂÀ´µÄ¼¸ÖÜÄÚÎÞ·¨¸¶¿î»ò·ÃÎÊÆäÔÚÏßÕË»§¡£LoanDepot Êǽü¼¸¸öÔÂÀ´Ôâµ½¶ñÒâºÚ¿Í¹¥»÷µÄ¼¸¼Ò´û¿îºÍµÖѺ´û¿î¹«Ë¾Ö®Ò»¡£


https://techcrunch.com/2024/02/26/loandepot-millions-sensitive-personal-data-ransomware/?&web_view=true


5. Äþ¾²»ú¹¹¾¯¸æ Ubiquiti EdgeRouter Óû§×¢Òâ APT28 µÄÍþв


2ÔÂ28ÈÕ £¬ÔÚÒ»·ÝеÄÁªºÏ×ÉѯÖÐ £¬ÃÀ¹úºÍÆäËû¹ú¼ÒµÄÍøÂçÄþ¾²ºÍÇ鱨»ú¹¹¶Ø´Ù Ubiquiti EdgeRouter Óû§½ÓÄɱ£»¤´ëÊ© £¬¼¸ÖÜÇ°Ö´·¨²¿ÃÅÔÚ´úºÅΪ¡° Dying Ember¡±µÄÐж¯ÖдݻÙÁËÒ»¸öÓÉÊÜѬȾ·ÓÉÆ÷×é³ÉµÄ½©Ê¬ÍøÂç¡£¾Ý³Æ £¬¸Ã½©Ê¬ÍøÂçÃûΪ MooBot £¬±»Óë¶íÂÞ˹ÓÐ¹ØµÄ APT28 Íþв×éÖ¯ÓÃÀ´¹¥»÷»î¶¯ £¬²¢Í¶·Å×Ô½ç˵¶ñÒâÈí¼þÒÔ¹©ºóÐøÀûÓ᣾ÝÁ˽â £¬APT28 Á¥ÊôÓÚ¶íÂÞ˹×ÜÕÕÁϲ¿ (GRU) £¬ÖÁÉÙ×Ô 2007 ÄêÒÔÀ´¾ÍÒ»Ö±»îÔ¾¡£MooBot ¹¥»÷ÐèÒªÒÔĬÈÏ»òÈõƾ¾ÝµÄ·ÓÉÆ÷ΪĿ±êÀ´²¿Êð OpenSSH ľÂí £¬APT28 »ñÈ¡´Ë·ÃÎÊȨÏÞÒÔÌṩ bash ½Å±¾ºÍÆäËû ELF ¶þ½øÖÆÎļþÀ´ÊÕ¼¯Æ¾¾Ý¡¢ÊðÀíÍøÂçÁ÷Á¿¡¢Ö÷»úÍøÂçµöÓãÒ³ÃæºÍÆäËû¹¤¾ß¡£ÆäÖаüÂÞÓÃÓÚÉÏ´«ÊôÓÚÌض¨Ä¿±êÍøÂçÓʼþÓû§µÄÕÊ»§Æ¾¾ÝµÄ Python ½Å±¾ £¬ÕâЩƾ¾ÝÊÇͨ¹ý¿çÕ¾µã½Å±¾ºÍä¯ÀÀÆ÷ÖеÄä¯ÀÀÆ÷ ( BitB ) Óã²æʽÍøÂçµöÓã»î¶¯ÊÕ¼¯µÄ¡£


https://thehackernews.com/2024/02/cybersecurity-agencies-warn-ubiquiti.html


6. ¿ªÔ´ Xeno RAT ľÂí³ÉΪ GitHub ÉϵÄDZÔÚÍþв


2ÔÂ27ÈÕ £¬Ò»ÖÖÃûΪXeno RATµÄ¡°¾«ÐÄÉè¼Æ¡±µÄÔ¶³Ì·ÃÎÊľÂí (RAT)ÒÑÔÚ GitHub ÉÏÐû²¼ £¬ÆäËû¼ÓÈëÕßÎÞÐèÌر𸶷Ѽ´¿ÉʹÓøÃľÂí¡£¸Ã¿ªÔ´ RAT ½ÓÄÉ C# ±àд £¬Óë Windows 10 ºÍ Windows 11 ²Ù×÷ϵͳ¼æÈÝ £¬Å䱸ÁË¡°ÓÃÓÚÔ¶³Ìϵͳ¹ÜÀíµÄÈ«Ã湦Ч¡± £¬Æ俪·¢ÈËÔ±£¨ÆäÃû³ÆΪ moom825£©ÌåÏÖ¡£Ëü°üÂÞ SOCKS5 ·´ÏòÊðÀíºÍ¼ÖÆʵʱÒôƵµÄ¹¦Ð§ £¬²¢½áºÏDarkVNC µÄÒþ²ØÐéÄâÍøÂç¼ÆËã (hVNC) Ä£¿é £¬Ê¹¹¥»÷ÕßÄܹ»Ô¶³Ì·ÃÎÊÊÜѬȾµÄ¼ÆËã»ú¡£ÖµµÃ×¢ÒâµÄÊÇ £¬moom825 Ò²ÊÇÁíÒ»ÖÖÃûΪDiscordRAT 2.0µÄ»ùÓÚ C# µÄ RAT µÄ¿ª·¢Õß £¬¸Ã RAT ÒÑÓÉÍþвÐÐΪÕßÔÚÃûΪ node-hide-console-windows µÄ¶ñÒâ npm °üÖзַ¢ £¬ÕýÈçReversingLabs ÓÚ 2023 Äê 10 ÔÂÅû¶µÄÄÇÑù¡£


https://thehackernews.com/2024/02/open-source-xeno-rat-trojan-emerges-as.html?&web_view=true