ºÚ¿ÍÉù³ÆÒѾÈëÇÖÃÀ¹úÁª°î³Ð°üÉÌ Acuity²¢³öÊÛ ICE ºÍ USCIS µÄÊý¾Ý
Ðû²¼Ê±¼ä 2024-03-113ÔÂ9ÈÕ£¬ÎÛÃûÕÑÖøµÄºÚ¿ÍIntelBrokerÉù³Æ¶Ô×î½ü·¢ÉúµÄÒ»ÆðÊý¾Ýй¶Ê¼þÂôÁ¦£¬¾Ý³Æ¸ÃʼþµÄÄ¿±êÊÇλÓÚ¸¥¼ªÄáÑÇÖÝÀ×˹¶ÙµÄÁª°î³Ð°üÉÌ Acuity Inc.¡£´Ë´Î鶵¼ÖÂÃÀ¹úÁ½¸öÖøÃûÕþ¸®ÊµÌåµÄÃô¸ÐÊý¾ÝºÍÎļþ±»µÁ£ºÃÀ¹úÒÆÃñºÍº£¹ØÖ´·¨¾Ö (ICE) ÒÔ¼°ÃÀ¹ú¹«ÃñºÍÒÆÃñ·þÎñ¾Ö (USCIS)¡££¬Acuity Inc . ÊÇÒ»¼ÒÁª°î¼¼Êõ×Éѯ¹«Ë¾£¬×ܲ¿Î»ÓÚ¸¥¼ªÄáÑÇÖÝÀ×˹¶Ù¡£ËûÃÇΪÁª°î»ú¹¹£¬ÌرðÊÇÄÇЩרעÓÚ¹ú¼ÒÄþ¾²ºÍ¹«¹²Äþ¾²µÄ»ú¹¹ÌṩÉîºñµÄÐÐҵרҵ֪ʶ¡£¸Ã¹«Ë¾ÌåÏÖ£¬ËûÃǵĺËÐÄʹÃüÊÇ×ÊÖúÕâЩ»ú¹¹¹æ»®Î´À´£¬Ìá¸ßΪ¹«Ãñ·þÎñµÄÄÜÁ¦£¬²¢Í¨¹ý´´Ðµļ¼Êõ½â¾ö·½°¸ºÍ¾¹ýÑéÖ¤µÄ¹ÜÀí¼¼ÊõÌṩ¿ÉºâÁ¿µÄ½á¹û¡£ÕâЩÁîÈËÕ𾪵Ä˵·¨·ºÆðÔÚÎÛÃûÕÑÖøµÄÍøÂç·¸×ïºÍºÚ¿ÍÂÛ̳Breach Forums×î½üµÄһƪÌû×ÓÖС£Hackread.com ¶À¼Ò֤ʵ£¬±»µÁÊý¾ÝÄ¿Ç°ÕýÔÚÂÛ̳ÉÏÒÔ½ö 3,000 ÃÀÔªµÄÃÅÂÞ±Ò (XMR) ¼ÓÃÜ»õ±Ò³öÊÛ¡£
https://www.hackread.com/hacker-breach-federal-contractor-acuity-ice-uscis-data/
2. ÃÀ¹ú¶¥¼¶ÍøÂçÄþ¾²»ú¹¹ÔâºÚ¿Í¹¥»÷²¢±»Æȹرղ¿ÃÅϵͳ
3ÔÂ8ÈÕ£¬ÂôÁ¦ÍøÂçÄþ¾²µÄÁª°î»ú¹¹·¢ÑÔÈ˺ÍÊìϤ¸ÃʼþµÄÃÀ¹ú¹ÙÔ±¸æËß CNN£¬¸Ã»ú¹¹ÉϸöÔ·¢ÏÖ×Ô¼ºÔâµ½ºÚ¿Í¹¥»÷£¬²¢±»ÆȹرÕÁ½¸öÒªº¦¼ÆËã»úϵͳ¡£¾ÝÁ˽âÇé¿öµÄÃÀ¹ú¹ÙԱ͸¶£¬ÃÀ¹úÍøÂçÄþ¾²ºÍ»ù´¡ÉèÊ©Äþ¾²¾ÖÊÜÓ°ÏìµÄϵͳ֮һÔËÐÐ×ÅÒ»Ïî¼Æ»®£¬ÔÊÐíÁª°î¡¢Öݺ͵ط½¹ÙÔ±¹²ÏíÍøÂçºÍÎïÀíÄþ¾²ÆÀ¹À¹¤¾ß¡£ÏûÏ¢ÈËÊ¿³Æ£¬ÁíÒ»¸öÕÆÎÕ×Å»¯Ñ§ÉèÊ©Äþ¾²ÆÀ¹ÀµÄÐÅÏ¢¡£Ä¿Ç°Éв»Çå³þËÊǴ˴κڿ͹¥»÷µÄÄ»ºóºÚÊÖ£¬µ«Õâ´ÎºÚ¿Í¹¥»÷ÊÇͨ¹ýÓÌËûÖÝ IT ¹«Ë¾ Ivanti ¿ª·¢µÄÁ÷ÐÐÐéÄâרÓÃÍøÂçÈí¼þÖеÄ©¶´·¢ÉúµÄ¡£¼¸ÖÜÀ´£¬CISA Ò»Ö±¶Ø´ÙÁª°î»ú¹¹ºÍ˽Ӫ¹«Ë¾¸üÐÂÆäÈí¼þ»ò½ÓÄÉÆäËû·ÀÓù´ëÊ©£¬ÒÔÓ¦¶ÔºÚ¿Í¹ã·ºÀûÓà Ivanti ©¶´µÄÇé¿ö¡£ËäÈ»ÕâÓÐһЩ¼¥Ð¦Òâ棬µ«¼´Ê¹ÊÇÍøÂçÄþ¾²»ú¹¹»ò¹ÙÔ±Ò²¿ÉÄܳÉΪºÚ¿Í¹¥»÷µÄÊܺ¦Õß¡£¾¿¾¹£¬ËûÃÇÒÀÀµÓëÆäËûÈËÏàͬµÄ¼¼Êõ¡£
https://edition.cnn.com/2024/03/08/politics/top-us-cybersecurity-agency-cisa-hacked/index.html
3. ¶íÂÞ˹ºÚ¿ÍÈëÇÖ΢Èí£¬ÇÔÈ¡Ãô¸ÐÔ´´úÂëºÍ»úÃÜ
3ÔÂ9ÈÕ£¬Î¢ÈíÌṩÁËÓйضíÂÞ˹¹ú¼ÒÖ§³ÖµÄÃûΪ Midnight Blizzard »ò Nobelium µÄºÚ¿Í×éÖ¯ÌᳫµÄÅÓ´óÇÒÁ¬ÐøµÄÍøÂç¹¥»÷µÄ×îÐÂÐÅÏ¢¡£¸Ã¹¥»÷ÓÚ 2024 Äê 1 ÔÂÊ״μì²âµ½£¬×î½ü¼¸ÖÜ´ó·ùÉý¼¶£¬ÒòΪºÚ¿ÍÊÔͼÀûÓÃÇÔÈ¡µÄÊý¾ÝÆÆ»µ Microsoft µÄÄÚ²¿ÏµÍ³ºÍÔ´´úÂë´æ´¢¿â¡£Î¢ÈíÔÚһƪ²©¿ÍÎÄÕÂÖÐ͸¶£¬Midnight Blizzard ÓÚ 1 Ô 12 ÈÕÉø͸Á˸ù«Ë¾µÄ¹«Ë¾µç×ÓÓʼþϵͳ£¬Ê¹ºÚ¿ÍÄܹ»ÇÔÈ¡Ãô¸ÐÊý¾Ý¡£ËäÈ»ÃæÏò¿Í»§µÄϵͳÉÐδÊܵ½Ë𺦣¬µ«ºÚ¿ÍÕýÔÚÀûÓÃÇÔÈ¡µÄÐÅÏ¢¶Ô΢ÈíµÄϵͳÌᳫԽÀ´Ô½¼¤½øµÄÃÜÂëÅçÉä¹¥»÷¡£ËäÈ»´Ë´Î鶵ÄÈ«²¿·¶Î§ÈÔÔÚÊÓ²ìÖУ¬µ«Î¢ÈíÌåÏÖ£¬ËüÒѾʵʩÁËÔöÇ¿µÄÄþ¾²¿ØÖÆ¡¢¼à¿ØºÍÍþв¼ì²â¹¦Ð§£¬ÒÔÓ¦¶ÔÎçÒ¹±©Ñ©µÄÎÞÇé¹¥»÷¡£Midnight Blizzard ÖÁÉÙ´Ó 2018 Ä꿪ʼ»îÔ¾£¬ÊÇÒ»¸öÊܶíÂÞ˹Íâ¹úÇ鱨»ú¹¹Ö§³ÖµÄÖøÃûºÚ¿Í×éÖ¯¡£ËüÖ÷ÒªÕë¶ÔÃÀ¹úºÍÅ·ÖÞµÄÕþ¸®»ú¹¹¡¢·ÇÕþ¸®×éÖ¯ºÍ¿Æ¼¼¹«Ë¾£¬Ä¿µÄÊǽøÐмäµý»î¶¯ºÍÇ鱨ÊÕ¼¯£¬ÒÔÖ§³Ö¶íÂÞ˹µÄÀûÒæ¡£
https://www.cyberkendra.com/2024/03/russian-hackers-breach-microsoft-steal.html
4. Bifrost ľÂíµÄ Linux ±äÌåͨ¹ýÓòÃûÇÀ×¢Ìӱܼì²â
3ÔÂ7ÈÕ£¬Ò»ÖÖÒÑÓÐ 20 ÄêÀúÊ·µÄÌØÂåÒÁľÂí×î½üÖØзºÆð£¬ÆäбäÖÖÒÔ Linux ΪĿ±ê£¬²¢Ã°³äÊÜÐÅÈεÄÍйÜÓòÀ´Ìӱܼì²â¡£Palo Alto Networks µÄÑо¿ÈËÔ±·¢ÏÖÁËBifrost£¨ÓÖÃû Bifrose£©¶ñÒâÈí¼þµÄРLinux ±äÌ壬¸Ã±äÌåʹÓÃÒ»ÖÖ³ÆΪ¡°ÓòÃûÇÀ×¢¡±µÄÆÛÆÐÔ×ö·¨À´Ä£·ÂºÏ·¨µÄ VMware Óò£¬´Ó¶øʹ¶ñÒâÈí¼þÄܹ»ÔÚÀ×´ïÏÂÔËÐС£BifrostÊÇÒ»ÖÖÔ¶³Ì·ÃÎÊÌØÂåÒÁľÂí (RAT)£¬×Ô 2004 ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬²¢´ÓÊÜѬȾµÄϵͳÊÕ¼¯Ãô¸ÐÐÅÏ¢£¬ÀýÈçÖ÷»úÃûºÍ IP µØÖ·¡£Ñо¿ÈËÔ±Ö¸³ö£¬¹¥»÷Õßͨ³£Í¨¹ýµç×ÓÓʼþ¸½¼þ»ò¶ñÒâÍøÕ¾·Ö·¢ Bifrost£¬µ«ËûÃÇûÓÐÏêϸ˵Ã÷зºÆðµÄ Linux ±äÌåµÄ³õʼ¹¥»÷ÏòÁ¿¡£¾¡¹Ü Bifrost RAT ¿ÉÄÜÊǶñÒâÈí¼þµÄÀÏÇ°±²£¬µ«ËüÈÔÈ»¶Ô¸öÈ˺Í×éÖ¯×é³ÉÖØ´óÇÒ²»Í£ÑݱäµÄÍþв£¬ÌرðÊǽÓÄÉÓòÃû·ÂðÀ´Ìӱܼì²âµÄбäÖÖ¡£
https://www.darkreading.com/cloud-security/stealthy-bifrost-rat-linux-variants-use-typosquatting-to-evade-detection-
5. ±ÈÀûʱơ¾Æ´«Ææ¶Åά¶ûµÄÆ¡¾Æ³§ÒòÀÕË÷Èí¼þÍ£Ö¹Éú²ú
3ÔÂ7ÈÕ£¬±ÈÀûʱơ¾ÆÄðÔìÉÌ Duvel ÌåÏÖ£¬ÀÕË÷Èí¼þ¹¥»÷Òѵ¼ÖÂÆäÉèÊ©ÏÝÈë̱»¾£¬¶øÆä IT ÍŶÓÕýÔÚŬÁ¦ÐÞ¸´Ë𻵡£ÓйظÃʼþµÄÏêϸÐÅϢͨ³£ºÜÉÙ£¬ÒòΪ¸Ã¹«Ë¾³ýÁËÏòýÌå·¢±íÁ˼ò¶ÌÉùÃ÷Í⣬ÉÐδ¹ûÈ»´Ë´ÎÍ»Èëʼþ¡£Ä¿Ç°Éв»Çå³þ´Ë´ÎÏ®»÷ÊÇÄĸö×éÖ¯ËùΪ¡£Duvel Moortgat ²»½ö½« Duvel ´øµ½ÁËÉ̵ê»õ¼Ü¡¢²ÍÌüºÍ¾Æ°É£¬»¹ÎªÆäËûÊÜ»¶ÓµÄ¾ÆÆ·´øÀ´ÁË La Chouffe¡¢Vedett¡¢Firestone Walker µÈ¡£AartsÌåÏÖ£¬·ÛË¿ÃDz»±Øµ£Óǹ©Ó¦ÎÊÌ⣬ÒòΪ Breendonk ¹¤³§¿â´æ¸»×㣬¶øÇҸù«Ë¾²¢²»µ£ÓÇÍøÕ¾ÔÝʱͣ»úʱµÄ¶©µ¥ÂÄÐÐÇé¿ö¡£ÆäËûÔâÊÜÀÕË÷Èí¼þ¹¥»÷µÄÖÆÔì×é֯ͨ³£Ã»ÓÐÄÇôÐÒÔË£¬ÈκÎÀàÐ͵ÄÍ£»ú¶¼¿ÉÄܶÔÔËÓªºÍ²ÆÕþÔì³ÉË𺦡£Õâ¾ÍÊÇΪʲô¸ÃÐÐÒµ³ÉΪÀÕË÷Èí¼þ·¸×ï·Ö×ӵij£¼ûÄ¿±ê£¬ÒòΪËûÃÇÖªµÀ´ÓÀíÂÛÉϽ²£¬ÖÆÔìÉ̸üÓж¯Á¦¿ìËÙÖ§¸¶Êê½ð£¬´Ó¶ø×î´óÏ޶ȵؼõÉÙ´ú¼Û¸ß°ºµÄÍ£»úʱ¼ä¡£
https://www.theregister.com/2024/03/07/no_piss_up_in_duvels/
6. 2023 ÄêÍøÂç·¸×ïËðʧÁè¼Ý 125 ÒÚÃÀÔª
3ÔÂ7ÈÕ£¬FBIÍøÂç·¸×ïͶËßÖÐÐÄ£¨IC3£©Ðû²¼ÁË2023ÄêÄê¶È³ÂËߣ¬³ÂËßÏÔʾ£¬¸Ã»ú¹¹ÊÕµ½µÄÍøÂç·¸×ïͶËßÊýÁ¿ÓëÉÏÒ»ÄêÏà±ÈÔö¼ÓÁ˽ü10%¡£2023 Ä꣬ÃÀ¹úÍøÂç·¸×ïÊܺ¦ÕßÏò FBI Ìá³öÁËÁè¼Ý 88 ÍòÆðͶËߣ¬³ÂËßËðʧ×ܶîÁè¼Ý 125 ÒÚÃÀÔª£¬±È 2022 ÄêÔö¼ÓÁË 22%¡£¹ýÈ¥ÎåÄִ꣬·¨»ú¹¹ÊÕµ½½ü 380 ÍòÆðͶËߣ¬Ëðʧ×ܶî´ï 374 ÒÚÃÀÔª¡£ÍøÂçµöÓãÈÔȻռͶËßµÄ×î¸ß±ÈÀý£¬Æä´ÎÊǸöÈËÊý¾Ýй¶¡¢²»¸¶¿î»ò²»ËÍ»õÕ©Æ¡¢ÀÕË÷ºÍ¼¼ÊõÖ§³ÖÕ©Æ¡£¾ÍËðʧ¶øÑÔ£¬Í¶×ÊÆÛÕ©Ëðʧ×îΪ²ÒÖØ£¬2023 ÄêËðʧ´ï 45.7 ÒÚÃÀÔª£¬¸ßÓÚ 2022 ÄêµÄ 33.1 ÒÚÃÀÔª¡£Æä´ÎÊÇÉÌÒµµç×ÓÓʼþй¶ (BEC)£¬Êܺ¦ÕßÉù³Æ×ܹ²ËðʧÁË 29 ÒÚÃÀÔª¡£¼¼ÊõÖ§³ÖÕ©Æ¡¢¸öÈËÊý¾Ýй¶¡¢Áµ°®Õ©Æ¡¢Êý¾Ýй¶¡¢Õþ¸®Ã°³äÒÔ¼°²»¸¶¿î/²»½»¸¶¼Æ»®¾ùÔì³ÉÊýÒÚÃÀÔªµÄËðʧ¡£ÔÚÀÕË÷Èí¼þ·½Ã棬FBI ÊÕµ½ÁË 2800 ¶àÆðͶËߣ¬Ëðʧ×ܼƽü 6000 ÍòÃÀÔª¡£×îÊܹ¥»÷µÄÐÐÒµÊÇÒ½ÁƱ£½¡¡¢Òªº¦ÖÆÔì¡¢Õþ¸®ÉèÊ©¡¢IT ºÍ½ðÈÚ·þÎñ¡£
https://www.securityweek.com/fbi-cybercrime-losses-exceeded-12-5-billion-in-2023/