¼ÒµÃ±¦È·ÈϵÚÈý·½Êý¾Ý鶵¼ÖÂÆäÔ±¹¤ÐÅϢй¶

Ðû²¼Ê±¼ä 2024-04-09
1. ¼ÒµÃ±¦È·ÈϵÚÈý·½Êý¾Ý鶵¼ÖÂÆäÔ±¹¤ÐÅϢй¶


4ÔÂ7ÈÕ£¬Home Depot ÒÑÈ·ÈÏ£¬ÆäÒ»¼Ò SaaS ¹©Ó¦ÉÌ´íÎóµØй¶ÁËһС²¿ÃÅÓÐÏÞµÄÔ±¹¤Êý¾ÝÑù±¾£¬ÕâЩÊý¾Ý¿ÉÄܻᱻÓÃÓÚÓÐÕë¶ÔÐÔµÄÍøÂçµöÓã¹¥»÷£¬Òò´Ë¸Ã¹«Ë¾ÔâÊÜÁËÊý¾Ýй¶¡£Home Depot ÊÇ×î´óµÄ¼Ò¾Ó×°ÐÞÁãÊÛÉÌ£¬ÔÚ±±ÃÀÓµÓÐ 2,300 ¶à¼ÒÉ̵êºÍÁè¼Ý 475,000 ÃûÔ±¹¤¡£Ò»¸öÃûΪ IntelBroker µÄÍþвÐÐΪÕßÔÚºÚ¿ÍÂÛ̳ÉϹûÈ»ÁËԼĪ 10,000 Ãû¼ÒµÃ±¦Ô±¹¤µÄÊý¾Ý¡£ËäÈ»ÕâЩÊý¾Ý²¢²»¸ß¶ÈÃô¸Ð£¬½ö̻¶¹«Ë¾ ID¡¢ÐÕÃûºÍµç×ÓÓʼþµØÖ·£¬µ«ÍþвÐÐΪÕß¿ÉÄÜ»áÀûÓÃÕâЩÊý¾Ý¶Ô Home Depot Ô±¹¤½øÐÐÓÐÕë¶ÔÐÔµÄÍøÂçµöÓã¹¥»÷¡£ÕâЩÍøÂçµöÓã¹¥»÷¿ÉÄÜÖ¼ÔÚÊÕ¼¯¸üÃô¸ÐµÄÐÅÏ¢£¬ÀýÈç¼ÒµÃ±¦Æ¾Ö¤£¬È»ºó½«Æä³öÊÛ¸øÆäËûÍþв¼ÓÈëÕß»òÓÃÓÚÆÆ»µ¹«Ë¾ÍøÂçÒÔÇÔÈ¡¹«Ë¾Êý¾Ý»ò²¿ÊðÀÕË÷Èí¼þ¡£


https://www.bleepingcomputer.com/news/security/home-depot-confirms-third-party-data-breach-exposed-employee-info/


2. Solar Spider ¿ª·¢Ð¶ñÒâÈí¼þ¹¥»÷Öж«µÄ½ðÈÚÐÐÒµ


4ÔÂ8ÈÕ£¬ÍøÂçÄþ¾²·þÎñ¹«Ë¾ Resecurity ÔÚ±¾ÖÜÐû²¼µÄÒ»·Ý³ÂËßÖÐдµÀ£¬¸Ã¹«Ë¾·ÖÎöÁ˶àÆðʼþµÄ¼¼Êõϸ½Ú£¬ÕâЩʼþÉæ¼°Õë¶Ô½ðÈÚ¿Í»§µÄ JSOutProx ¶ñÒâÈí¼þ£¬Èç¹ûÕë¶ÔÆóÒµ£¬ÔòÌṩÐé¼ÙµÄ SWIFT ¸¶¿î֪ͨ£»Èç¹ûÕë¶Ô˽È˹«Ãñ£¬ÔòÌṩ MoneyGram Ä£°å¡£¸ÃÍþв×éÖ¯µÄÄ¿±êÊÇÓ¡¶ÈÒÔ¼°·ÆÂɱö¡¢ÀÏÎΡ¢Ð¼ÓÆ¡¢ÂíÀ´Î÷ÑÇ¡¢Ó¡¶ÈµÄ½ðÈÚ×éÖ¯£¬ÏÖÔÚ»¹ÓÐɳÌØ°¢À­²®µÄ½ðÈÚ×éÖ¯¡£Resecurity Ê×ϯִÐй٠Gene Yoo ÌåÏÖ£¬´Ó¿ª·¢½Ç¶ÈÀ´¿´£¬×îа汾µÄ JSOutProx ÊÇÒ»¸ö·Ç³£Áé»îÇÒ×éÖ¯Á¼ºÃµÄ·¨Ê½£¬ÔÊÐí¹¥»÷Õßƾ¾ÝÊܺ¦ÕßµÄÌض¨»·¾³¶¨Öƹ¦Ð§¡£Æ¾¾Ý Visa µÄÍþв³ÂËߣ¬¹¥»÷Õ߾ͻáÊÕ¼¯ÐÅÏ¢£¬ÀýÈçÖ÷Õ˺źÍÓû§Æ¾¾Ý£¬È»ºóÕë¶ÔÊܺ¦ÕßʵʩÖÖÖÖ¶ñÒâÐÐΪ¡£


https://www.darkreading.com/threat-intelligence/solar-spider-spins-up-new-malware-to-entrap-saudi-arabian-banks


3. ¹È¸èÆðËßÓ¦Ó÷¨Ê½¿ª·¢ÉÌÐé¼Ù¼ÓÃÜ»õ±ÒͶ×ÊÓ¦Ó÷¨Ê½Õ©Æ­


4ÔÂ8ÈÕ£¬¹È¸èÒѶÔÁ½¼ÒÓ¦Ó÷¨Ê½¿ª·¢ÉÌÌáÆðËßËÏ£¬Ö¸¿ØÆä¼ÓÈë¡°¹ú¼ÊÔÚÏßÏû·ÑÕßͶ×ÊÆÛÕ©¼Æ»®¡±£¬¸Ã¼Æ»®ÆÛÆ­Óû§´Ó Google Play É̵êºÍÆäËûÀ´Ô´ÏÂÔØÐé¼Ù Android Ó¦Ó÷¨Ê½£¬²¢ÒÔÔÊÐí¸ü¸ß»Ø±¨Îª»Ï×ÓÇÔÈ¡ËûÃǵÄ×ʽ𡣾ݳƣ¬ÖÁÉÙ×Ô 2019 ÄêÒÔÀ´£¬±»¸æÒÑÏò Play É̵êÉÏ´«ÁËÔ¼ 87 ¸ö¼ÓÃÜÓ¦Ó÷¨Ê½£¬ÒÔʵʩÉç»á¹¤³ÌÆ­¾Ö£¬ÒÑÓÐÁè¼Ý 10 ÍòÓû§ÏÂÔØÕâЩӦÓ÷¨Ê½£¬²¢µ¼ÖÂÁ˾޴óµÄ¾­¼ÃËðʧ¡£ÕâÖÖÆÛÕ©¼Æ»®ÒªÇóÕ©Æ­Õßͨ¹ýÉ罻ýÌå»òÔ¼»áƽ̨£¬Ê¹Óþ«ÐÄÉè¼ÆµÄÐé¹¹½ÇÉ«À´Ãé×¼ºÁÎÞ½äÐĵĸöÈË£¬ÒÔÁµ°®¹ØϵµÄÇ°¾°ÒýÓÕËûÃǽ¨Á¢ÐÅÈΣ¬²¢Ëµ·þËûÃÇͶ×ʼÓÃÜ»õ±ÒͶ×Ê×éºÏ£¬ÕâЩͶ×Ê×éºÏÖ¼ÔÚÔÚ¶Ìʱ¼äÄÚÌṩ¸ß¶îÀûÈóÄ¿µÄÊÇÇÔÈ¡ËûÃǵÄ×ʽð¡£


https://thehackernews.com/2024/04/google-sues-app-developers-over-fake.html


4. ÒÔÉ«ÁÐÍøÂç¼äµý²¿ÃÅÂôÁ¦ÈËÒò×Ô¼ºµÄÒþ˽´íÎó¶ø±»Æعâ


4ÔÂ8ÈÕ£¬ÕâÃû¼äµýÃû½Ð Yossi Sariel£¬¾Ý³ÆÊÇÒÔÉ«ÁÐ8200 ¶ÓÎéµÄÂôÁ¦ÈË£¬ÕâÊÇÒ»Ö§ÓÉÆƽâÐÅÏ¢Äþ¾²×¨¼Ò×é³ÉµÄÍŶÓ£¬¿ÉÓëÃÀ¹ú¹ú¼ÒÄþ¾²¾Ö»òÓ¢¹úÕþ¸®Í¨ÐÅ×ܲ¿ÏàæÇÃÀ¡£ÏÖÔÚ£¬ËûÒѱ»È·ÈÏΪ 2021 Äê³öÊéµÄ¡¶ÈË»úÍŶӡ·Ò»ÊéµÄ×÷Õߣ¬¸ÃÊé½²ÊöÁ˽«ÈËÀàÊðÀíÓëÏȽøÈ˹¤ÖÇÄÜÅä¶ÔµÄÖÇÄÜÓÅÊÆ¡£ÈøÀï¶û£¨Sariel£©ÒԷdz£ÄäÃûµÄ±ÊÃû¡°YS×¼½«¡±Ð´ÁËÕâ±¾Ê飬ÔÚ¡¶ÎÀ±¨¡·½øÐÐÊÓ²ìºó·¸ÁËÒ»¸öÑÏÖصĴíÎ󣬸ÃÊӲ췢ÏÖÑÇÂíÑ·ÉÏÓÐÈøÀï¶ûµÄÊéµÄµç×Ó¸±±¾¡°ÆäÖаüÂÞÒ»·âÄäÃûµç×ÓÓʼþ£¬¿ÉÒÔÇáËÉ¿ÉÒÔ×·×Ùµ½ Sariel µÄÃû×ÖºÍ Google ÕÊ»§¡£¡±¸Ã±¨ËæºóÏòÒÔÉ«Áйú·À¾üÏûÏ¢À´Ô´Ö¤Êµ£¬¸ÃÕË»§ÓëÈøÀï¶ûÓйØ£¬²¢Ö¸³ö¶à¸öÏûÏ¢À´Ô´ÒÑ֤ʵËûÊÇ×÷Õß¡£


https://www.theregister.com/2024/04/08/infosec_news_roundup/


5. TargusµÄÎļþ·þÎñÆ÷ÔâÊÜÍøÂç¹¥»÷ÔËÓªÔÝʱÖжÏ


4ÔÂ8ÈÕ£¬Targus ÊÇÒ»¼ÒÒƶ¯Åä¼þ¹«Ë¾£¬ÒÔʱÉеÄÌõ¼Ç±¾µçÄÔ°üºÍÊÖÌáÏä¶øÎÅÃû¡£¸Ã¹«Ë¾»¹ÏúÊÛƽ°åµçÄÔ±£»¤¿Ç¡¢À©Õ¹Îë¡¢¼üÅÌ¡¢Êó±êºÍÂÃÐÐÅä¼þ¡£ÔÚÖÜÒ»ÍíÉÏÏò SEC Ìá½»µÄ FORM 8-K ÎļþÖУ¬Targus µÄĸ¹«Ë¾ B. Riley Financial, INC. Åû¶£¬Õâ¼ÒÌõ¼Ç±¾µçÄÔ°üÖÆÔìÉÌÓÚ 2024 Äê 4 Ô 5 ÈÕÔÚÆäÍøÂçÉϼì²âµ½¹¥»÷¡£Targus Á¢¼´Æô¶¯ÁËʼþÏìÓ¦ºÍÒµÎñÁ¬ÐøÐÔЭÒéÀ´ÊӲ졢ֹͣºÍµ÷Í£¸Ãʼþ¡£Targus ÌåÏÖ£¬¸ÃʼþÒѵõ½¿ØÖÆ£¬ËûÃÇÕýÔÚÍⲿÍøÂçÄþ¾²×¨¼ÒµÄ×ÊÖúÏ»ָ´ÄÚ²¿ÏµÍ³¡£¹«Ë¾Í¨³£»á¹Ø±Õ IT ϵͳÒÔÓ¦¶ÔÍøÂç¹¥»÷£¬ÒÔ·ÀÖ¹¹¥»÷ÂûÑÓµ½ÆäËû·þÎñÆ÷ºÍÉ豸¡£È»¶ø£¬ÕâÒ²×èÖ¹Á˶ÔÄÚ²¿Ó¦Ó÷¨Ê½ºÍÊý¾ÝµÄºÏ·¨·ÃÎÊ£¬ÔÝʱÖжÏÁËÒµÎñÔËÓª£¬Í¬Ê±·þÎñÆ÷ºÍÊÂÇéվƾ¾ÝÐèÒª½øÐÐÁ˻ָ´¡£¸Ã¹«Ë¾ÉÐδ͸¶¹«Ë¾Êý¾ÝÊÇ·ñ±»µÁ£¬µ«ÓÉÓÚºÚ¿ÍÊ×ÏÈÊÇÔÚ¹«Ë¾ÓÃÓÚ´æ´¢ÎļþºÍÊý¾ÝµÄÎļþϵͳÉÏ·¢Ïֵģ¬Òò´ËÊý¾ÝÓпÉÄܱ»Ð¹Â¶¡£


https://www.bleepingcomputer.com/news/security/targus-discloses-cyberattack-after-hackers-detected-on-file-servers/


6. ÍþвÐÐΪÕßͨ¹ý YouTube ÊÓƵÓÎϷ©¶´Á÷´«¶ñÒâÈí¼þ


4ÔÂ8ÈÕ£¬ÍþвÐÐΪÕßÀûÓà Vidar¡¢StealC ºÍ Lumma Stealer µÈÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þÃé×¼¼ÒÍ¥Óû§£¬ÕâЩ¶ñÒâÈí¼þ½«¶ñÒâÈí¼þαװ³É YouTube ÊÓƵÖеĵÁ°æÈí¼þºÍÊÓƵÓÎÏ·Æƽâ°æ¡£ÕâЩÊÓƵËƺõÖ¸µ¼Óû§»ñÈ¡Ãâ·ÑÈí¼þ»òÓÎÏ·Éý¼¶¡£¾¡¹ÜÈç´Ë£¬ÃèÊöÖеÄÁ´½ÓÈԻᵼÖ¶ñÒâÈí¼þ£¬¹¥»÷Õß»áÆÆ»µºÏ·¨ÕÊ»§»òרÃÅ´´½¨ÐÂÕÊ»§À´·Ö·¢¶ñÒâÈí¼þ¡£ÕâÖÖ·½Ö´·¨È˵£ÓÇ£¬ÒòΪËüÕë¶ÔµÄÊÇÄêÇáÓû§£¬ÍæµÄÊǶùͯÖÐÁ÷ÐеÄÓÎÏ·£¬¶øÕâЩÓû§²»Ì«¿ÉÄÜʶ±ð³ö¶ñÒâÄÚÈÝ£¬ÒòΪÒѾ­·¢ÏÖÁËÁè¼Ý¶þÊ®¸ö´ËÀàÕÊ»§ºÍÊÓƵ£¬²¢½«Æä³ÂË߸øYouTube½øÐÐɾ³ý¡£ 


https://gbhackers.com/hackers-deliver-malware-via-youtube-video-game-cracks/