ÀÕË÷Èí¼þÍŻ↑ʼ¹ûÈ»²¿ÃÅ Change Healthcare µÄÊý¾Ý

Ðû²¼Ê±¼ä 2024-04-17
1. ÀÕË÷Èí¼þÍŻ↑ʼ¹ûÈ»²¿ÃÅ Change Healthcare µÄÊý¾Ý


4ÔÂ15ÈÕ£¬RansomHub ÀÕË÷ÍÅ»ïÒÑ¿ªÊ¼¹ûÈ»ËûÃÇÉù³Æ´Ó United Health ×Ó¹«Ë¾ Change Healthcare ÇÔÈ¡µÄ¹«Ë¾ºÍ»¼ÕßÊý¾Ý£¬Õâ¶Ô¸Ã¹«Ë¾À´ËµÊÇÒ»¸öÂþ³¤¶øÅÓ´óµÄÀÕË÷¹ý³Ì¡£½ñÄê 2 Ô£¬  Change Healthcare ÔâÊÜÁËÍøÂç¹¥»÷ £¬¶ÔÃÀ¹úÒ½ÁƱ£½¡ÏµÍ³Ôì³ÉÁËÑÏÖØÆÆ»µ£¬µ¼ÖÂÒ©·¿ºÍÒ½ÉúÎÞ·¨Ïò±£ÏÕ¹«Ë¾¿ª¾ßÕ˵¥»òÌá³öË÷Åâ¡£Õâ´Î¹¥»÷×îÖÕ Óë BlackCat/ALPHV ÀÕË÷Èí¼þ²Ù×÷ÓйØ£¬¸ÃÀÕË÷Èí¼þºóÀ´ËµËûÃÇ ÔÚ¹¥»÷ÆÚ¼äÇÔÈ¡ÁË 6 TB Êý¾Ý¡£ÍþвÐÐΪÕß¿ªÊ¼¹ûÈ»ËûÃÇÉù³ÆÔÚ 2 Ô·ÝÀÕË÷Èí¼þ¹¥»÷ÆÚ¼ä´Ó Change Healthcare ÇÔÈ¡µÄÎļþµÄÆÁÄ»½Øͼ¡£ÆÁÄ»½Øͼ°üÂÞ Change Healthcare Óë±£ÏÕÌṩÉÌ£¨°üÂÞ CVS Caremark¡¢Health Net ºÍ Loomis£©Ö®¼äµÄÊý¾Ý¹²ÏíЭÒé¡£ÆäËûÎļþ°üÂÞ»á¼ÆÊý¾Ý£¬°üÂÞÕËÁä³ÂËß¡¢±£ÏÕ¸¶¿î³ÂËߺÍÆäËû²ÆÕþÐÅÏ¢¡£


https://www.bleepingcomputer.com/news/security/ransomware-gang-starts-leaking-alleged-stolen-change-healthcare-data/


2. CISCO DUO ¾¯¸æµç»°¹©Ó¦ÉÌÊý¾Ý鶵¼Ö MFA ¶ÌÐÅÈÕ־̻¶


4ÔÂ15ÈÕ£¬Cisco Duo ¾¯¸æÆäÒ»¼Òµç»°¹©Ó¦ÉÌ·¢ÉúÊý¾Ýй¶Ê¼þ£¬µ¼ÖÂͨ¹ý SMS ºÍ VOIP ·¢Ë͸ø¿Í»§µÄ¶àÒòËØÉí·ÝÑéÖ¤ (MFA) ÏûÏ¢Êܵ½Ë𺦡£¸ÃÄþ¾²Â©¶´·¢ÉúÓÚ 2024 Äê 4 Ô 1 ÈÕ£¬ÍþвÐÐΪÕßʹÓÃÁËͨ¹ýÍøÂçµöÓã¹¥»÷·Ç·¨»ñµÃµÄÌṩÉÌÔ±¹¤µÄƾ¾Ý¡£È»ºó£¬ËûÃÇʹÓø÷ÃÎÊȨÏÞÏÂÔØÁËÒ»×éÊôÓÚ¿Í»§ Duo ÕÊ»§µÄ MFA ¶ÌÐÅÈÕÖ¾¡£¸ü¾ßÌåµØ˵£¬ÍþвÐÐΪÕßÏÂÔØÁË 2024 Äê 3 Ô 1 ÈÕÖÁ 2024 Äê 3 Ô 31 ÈÕÆڼ䷢Ë͸øÄú Duo ÕÊ»§ÏµÄijЩÓû§µÄ SMS ÏûÏ¢µÄÏûÏ¢ÈÕÖ¾¡£ÏûÏ¢ÈÕÖ¾²»°üÂÞÈκÎÏûÏ¢ÄÚÈÝ£¬µ«°üÂ޵绰ºÅÂ룬ÿÌõÏûÏ¢·¢Ë͵½µÄµç»°ÔËÓªÉÌ¡¢¹ú¼ÒºÍÖÝ£¬ÒÔ¼°ÆäËûÔªÊý¾Ý£¨ÀýÈçÏûÏ¢µÄÈÕÆÚºÍʱ¼ä¡¢ÏûÏ¢ÀàÐ͵ȣ©¡£ÔĶÁ·¢Ë͸øÊÜÓ°Ïì¸öÈ˵ÄÊý¾Ýй¶֪ͨ¡£¹¥»÷Õß¿ÉÒÔ·ÃÎÊÿÌõÏûÏ¢·¢Ë͵½µÄµç»°ºÅÂë¡¢µç»°ÔËÓªÉÌ¡¢¹ú¼ÒºÍÖÝ¡£¹¥»÷Õß»¹»ñµÃÁËÆäËûÔªÊý¾Ý£¬°üÂÞÏûÏ¢µÄÈÕÆÚºÍʱ¼ä¡¢ÏûÏ¢ÀàÐ͵È¡£·¢ÏÖ´Ëʺ󣬹©Ó¦ÉÌÁ¢¼´Õ¹¿ªÊӲ첢½ÓÄÉ»º½â´ëÊ©¡£


https://securityaffairs.com/161880/cyber-crime/cisco-duo-data-breach.html


3. SteganoAmor ¹¥»÷ʹÓÃÒþдÊõ¹¥»÷È«Çò 320 ¸ö×éÖ¯


4ÔÂ16ÈÕ£¬TA558 ºÚ¿Í×éÖ¯¿ªÕ¹µÄÒ»ÏîлÕýÔÚʹÓÃÒþдÊõ½«¶ñÒâ´úÂëÒþ²ØÔÚͼÏñÄÚ£¬´Ó¶ø½«ÖÖÖÖ¶ñÒâÈí¼þ¹¤¾ßͨ±¨µ½Ä¿±êϵͳÉÏ¡£ÒþдÊõÊÇÒ»ÖÖ½«Êý¾ÝÒþ²ØÔÚ¿´ËÆÎÞº¦µÄÎļþÖеļ¼Êõ£¬Ê¹Óû§ºÍÄþ¾²²úÎïÎÞ·¨¼ì²âµ½ËüÃÇ¡£TA558 ÊÇÒ»¸ö×Ô 2018 ÄêÒÔÀ´Ò»Ö±»îÔ¾µÄÍþв×éÖ¯£¬ÒÔ Õë¶ÔÈ«Çò¾ÆµêºÍÂÃÓÎ×éÖ¯£¨ÓÈÆäÊÇÀ­¶¡ÃÀÖÞ£©¶øÎÅÃû¡£Positive Technologies ·¢ÏÖÁ˸Ã×éÖ¯µÄ×îл£¬ÓÉÓڹ㷺ʹÓÃÒþдÊõ£¬±»³ÆΪ¡°SteganoAmor¡±¡£Ñо¿ÈËÔ±Ôڴ˴λÖз¢ÏÖÁË 320 ¶à´Î¹¥»÷£¬Ó°ÏìÁ˸÷¸ö²¿Ãź͹ú¼Ò¡£ÕâЩ¹¥»÷´Ó°üÂÞ¿´ËÆÎÞº¦µÄÎĵµ¸½¼þ£¨Excel ºÍ Word Îļþ£©µÄ¶ñÒâµç×ÓÓʼþ¿ªÊ¼£¬ÕâЩ¸½¼þÀûÓÃÁË CVE-2017-11882 £¬ÕâÊÇ 2017 ÄêÐÞ¸´µÄÒ»¸ö³£¼ûÄ¿±ê Microsoft Office ¹«Ê½±à¼­Æ÷©¶´¡£


https://www.bleepingcomputer.com/news/security/new-steganoamor-attacks-use-steganography-to-target-320-orgs-globally/


4. BLACKJACKʹÓÃICS¶ñÒâÈí¼þFUXNET¹¥»÷¶íÂÞ˹µÄÄ¿±ê


4ÔÂ15ÈÕ£¬¹¤ÒµºÍÆóÒµÎïÁªÍøÍøÂçÄþ¾²¹«Ë¾ Claroty ³ÂË߳ƣ¬ÎÚ¿ËÀ¼ Blackjack ºÚ¿Í×éÖ¯Éù³ÆʹÓÃÃûΪ Fuxnet µÄÆÆ»µÐÔ ICS ¶ñÒâÈí¼þÆÆ»µÁËĪ˹¿Æ¼°¶íÂÞ˹Ê׶¼ÒÔÍâµØÓòµÄ½ô¼±¼ì²âºÍÏìÓ¦ÄÜÁ¦¡£¾ÝÐÅ£¬ Blackjack ×éÖ¯ÓëÎÚ¿ËÀ¼Ç鱨»ú¹¹ÓйØÁª£¬¸Ã»ú¹¹¶Ô¶íÂÞ˹Ŀ±ê½øÐÐÁËÆäËû¹¥»÷£¬°üÂÞ »¥ÁªÍøÌṩÉÌ ºÍ ¾üÊ»ù´¡ÉèÊ©¡£¸Ã×éÖ¯Éù³ÆÏ®»÷ÁË×ܲ¿Î»ÓÚĪ˹¿ÆµÄ Moscollector ¹«Ë¾£¬¸Ã¹«Ë¾ÂôÁ¦µØÏÂË®¡¢ÎÛË®ºÍͨÐÅ»ù´¡ÉèÊ©µÄ½¨ÉèºÍ¼à²â¡£ruexfil.comÍøÕ¾ÌṩÁËÓÐ¹Ø Moscollector ¹¥»÷µÄÏêϸÐÅÏ¢£¬ºÚ¿Í»¹Ðû²¼ÁËËûÃÇÉù³ÆÊܵ½Ë𺦵ļà¿Øϵͳ¡¢·þÎñÆ÷ºÍÊý¾Ý¿âµÄÆÁÄ»½Øͼ¡£


https://securityaffairs.com/161865/hacking/blackjack-ics-malware-fuxnet.html


5. ºÚ¿Í¶¨ÖÆ LockBit 3.0 ÀÕË÷Èí¼þÀ´¹¥»÷È«Çò×éÖ¯


4ÔÂ16ÈÕ£¬¿¨°Í˹»ùʵÑéÊÒµÄÍøÂçÄþ¾²Ñо¿ÈËÔ±·¢ÏÖÁËÖ¤¾Ý£¬±íÃ÷ÍøÂç·¸×ïÍÅ»ïÕýÔÚ¶¨ÖƶñÒâµÄ LockBit 3.0 ÀÕË÷Èí¼þ£¬ÒÔÕë¶ÔÈ«Çò×éÖ¯½øÐÐÓÐÕë¶ÔÐԵĹ¥»÷¡£ÕâʹµÃÍþвÐÐΪÕßÄܹ»¶¨ÖƶñÒâÈí¼þ£¬ÒÔÕë¶ÔÌض¨Ä¿±ê·¢Éú×î´óµÄÓ°ÏìºÍÓÐЧÐÔ¡£ÕâЩ·¢ÏÖÀ´×ÔÑо¿ÈËÔ±¶Ô鶵ÄLockBit 3.0¹¹½¨Æ÷µÄ·ÖÎö£¬¸Ã¹¹½¨Æ÷ÓÚ 2022 ÄêÊ״ηºÆðÔÚµØÏÂÂÛ̳ÉÏ¡£¸Ã¹¹½¨Æ÷ʹ·¸×ï·Ö×ÓÄܹ»Í¨¹ýÅäÖÃÍøÂçÁ÷´«¹¦Ð§ºÍ½ûÓ÷ÀÓùµÈÑ¡ÏîÀ´Éú³ÉÀÕË÷Èí¼þµÄ¶¨ÖÆ°æ±¾¡£ÊÓ²ìÈËÔ±·¢ÏÖ¹¥»÷ÕßÒÑÀÖ³ÉÇÔÈ¡´¿Îı¾¹ÜÀíԱƾ¾Ý¡£È»ºó£¬ËûÃÇʹÓà LockBit ¹¹½¨Æ÷Éú³É¶¨ÖƵÄÀÕË÷Èí¼þ±äÌ壬Äܹ»ÀûÓÃÕâЩ±»µÁµÄȨÏÞÔÚÍøÂçÉÏ¿ìËÙÁ÷´«¡£¶¨ÖƵĶñÒâÈí¼þÔÚ¶ÔÊÜѬȾϵͳÖеÄÊý¾Ý½øÐмÓÃÜ֮ǰ£¬»áÆÆ»µ Windows Defender ±£»¤²¢É¾³ýʼþÈÕÖ¾ÒÔÑÚ¸ÇÆä×Ù¼£¡£


https://gbhackers.com/hacker-customize-lockbit-3-0-ransomware-to-attack-orgs-worldwide/


6. »ìÂÒµÄ Libra ½«ÖصãתÏòSaaSºÍÔÆÒÔ½øÐÐÀÕË÷¹¥»÷


4ÔÂ15ÈÕ£¬¾ÝÊӲ죬±»³ÆΪMuddled LibraµÄ¹¥»÷Õß»ý¼«Õë¶ÔÈí¼þ¼´·þÎñ (SaaS) Ó¦Ó÷¨Ê½ºÍÔÆ·þÎñÌṩÉÌ (CSP) »·¾³£¬ÒÔÇÔÈ¡Ãô¸ÐÊý¾Ý¡£ÍþвÐÐΪÕßÒѾ­¿ªÊ¼ÊµÑéÀûÓÃÆäÖÐһЩÊý¾ÝÀ´Ð­ÖúËûÃǵĹ¥»÷½øÕ¹£¬²¢ÔÚÊÔͼͨ¹ýËûÃǵÄÊÂÇé»ñÀûʱÓÃÓÚÀÕË÷¡£Muddled Libra£¬Ò²³ÆΪ Starfraud¡¢UNC3944¡¢Scatter Swine ºÍ Scattered Spider£¬ÊÇÒ»¸öÎÛÃûÕÑÖøµÄÍøÂç·¸×ï×éÖ¯£¬ÀûÓÃÅÓ´óµÄÉç»á¹¤³Ì¼¼ÊõÀ´»ñµÃ¶ÔÄ¿±êÍøÂçµÄ³õʼ·ÃÎÊȨÏÞ¡£¹¥»÷Õß»¹ÔøÒÔ¶àÖÖ·½Ê½Í¨¹ý·ÃÎÊÊܺ¦ÕßÍøÂçÀ´»ñÀû£¬°üÂÞͨ¹ýÀÕË÷Èí¼þºÍÊý¾Ý͵ÇÔ½øÐÐÀÕË÷¡£ÍþвÐÐΪÕßÕ½ÊõÑݱäµÄÒ»¸öÒªº¦·½ÃæÊÇ£¬ÔÚð³ä×ÊÖų́ÊÂÇéÈËԱͨ¹ýµç»°»ñÈ¡ÃÜÂëʱ£¬Ê¹ÓÃÕì²ì¼¼ÊõÀ´Ê¶±ðÄ¿±ê¹ÜÀíÓû§¡£Õì²ì½×¶Î»¹ÑÓÉìµ½ Muddled Libra ½øÐй㷺µÄÑо¿£¬ÒÔ²éÕÒÓйØÄ¿±ê×é֯ʹÓõÄÓ¦Ó÷¨Ê½ºÍÔÆ·þÎñÌṩÉ̵ÄÐÅÏ¢¡£


https://thehackernews.com/2024/04/muddled-libra-shifts-focus-to-saas-and.html?&web_view=true