SECÖ¸¿ØICEÎ¥·´Áª°î¹æÔò²¢·£¿î1000ÍòÃÀÔª

Ðû²¼Ê±¼ä 2024-05-24
1. SECÖ¸¿ØICEÎ¥·´Áª°î¹æÔò²¢·£¿î1000ÍòÃÀÔª


5ÔÂ23ÈÕ£¬ÃÀ¹ú֤ȯ½»Ò×ίԱ»á£¨SEC£©Ö¸¿ØÖ޼ʽ»Ò×Ëù£¨ICE£©Î´Äܼ°Ê±ÏòÆä¾Å¼ÒÈ«×Ê×Ó¹«Ë¾Í¨±¨ 2021 Äê 4 Ô 15 ÈÕ·¢ÉúµÄÍøÂç¹¥»÷£¬µ¼ÖÂÆäÎ¥·´Áª°î¹æÔò ¡£ÃÀ¹ú֤ȯ½»Ò×ίԱ»áÖÜÈýÐû²¼ÁË 1000 ÍòÃÀÔªµÄ·£¿î£¬²¢ÌåÏÖ ICE ¼°Æä×Ó¹«Ë¾¼È²»ÈÏ¿ÉÒ²²»·ñÈÏÃÀ¹ú֤ȯ½»Ò×ίԱ»áµÄÊÓ²ì½á¹û ¡£ICE ³ÂË߳ƣ¬2024ÄêµÚÒ»¼¾¶ÈµÄ¾»ÊÕÈëΪ 23 ÒÚÃÀÔª£¬³ýÁËÓµÓн»Ò×ËùÍ⣬»¹Ìṩ½ðÈÚ¼¼ÊõºÍÊý¾Ý·þÎñ ¡£SEC ³Æ£¬ÊÓ²ìÏÔʾ£¬ÔÚʼþ·¢ÉúÆڼ䣬ICE Á¢¼´ÖªµÀºÚ¿Í¡°½«¶ñÒâ´úÂë²åÈëÓÃÓÚÔ¶³Ì·ÃÎÊ ICE ¹«Ë¾ÍøÂçµÄ VPN É豸¡±£¬µ«¼¸Ììºó²Å֪ͨŦԼ֤ȯ½»Ò×ËùºÍÆäËû×Ó¹«Ë¾ ¡£SEC ³Æ£¬ÑÓ³Ù³ÂËß²»½öÎ¥·´ÁËÁª°î¹æÔò£¬Ò²Î¥·´ÁË ICE ×Ô¼ºµÄ·¨Ê½ ¡£ 


https://therecord.media/sec-penalty-intercontinental-exchange-cybersecurity-incident


2. Êý°ÙÍòÃÀ¹úÈË·¸×ï¼Ç¼Êý¾Ý¿â±»Ð¹Â¶µ½ÍøÉÏ


5ÔÂ22ÈÕ£¬Ò»¸öÒÔ EquationCorp ºÍ USDoD ΪÃûµÄÍøÂç·¸×ï·Ö×ÓÐû²¼ÁËÒ»¸öÅÓ´óµÄÊý¾Ý¿â£¬ÆäÖаüÂÞÊý°ÙÍòÃÀ¹úÈ˵ķ¸×ï¼Ç¼ ¡£¾Ý˵¸ÃÊý¾Ý¿â°üÂÞ 7000 ÍòÐÐÊý¾Ý ¡£¾Ý³Æ£¬Ð¹Â¶µÄÊý¾Ý¿â°üÂÞÈ«Ãû¡¢³öÉúÈÕÆÚ¡¢ÒÑÖª±ðÃû¡¢µØÖ·¡¢´þ²¶ºÍÖÎ×ïÈÕÆÚ¡¢ÐÌÆÚµÈ ¡£¾Ý±¨µÀ£¬ÈÕÆÚ·¶Î§´Ó 2020 Äêµ½ 2024 Äê ¡£¸ÃÊý¾Ý¿âµÄ¾ßÌåÀ´Ô´Ä¿Ç°Éв»Çå³þ ¡£ÎãÓ¹ÖÃÒÉ£¬·¸×ïÐÅϢй¶½«·¢Éú¾Þ´óÓ°Ï죬²»½ö¶ÔÃûµ¥ÉϵĸöÈË£¬¶øÇÒ¶Ô˾·¨ÏµÍ³Ò²ÊÇÈç´Ë ¡£


https://www.malwarebytes.com/blog/news/2024/05/criminal-record-database-of-millions-of-americans-dumped-online


3. Ñо¿ÈËÔ±·¢ÏÖ¼ÓÃܽٳֹ¥»÷¿É½ûÓö˵ã±£»¤


5ÔÂ23ÈÕ£¬Ñо¿ÈËÔ±ÌåÏÖ£¬×î½üÔÚÒ°·¢ÏֵĶñÒâÈí¼þʹÓÃÅÓ´óµÄ´ëÊ©À´½ûÓ÷À²¡¶¾±£»¤£¬Ïú»ÙѬȾ֤¾Ý£¬²¢Ê¹ÓüÓÃÜ»õ±ÒÍÚ¾òÈí¼þÓÀ¾ÃѬȾ»úÆ÷ ¡£ÈÃÕâ¸öÒì³£ÅÓ´óµÄ¶ñÒâÈí¼þϵͳÔËÐеÄÒªº¦ÊÇÖ÷ÔغÉÖеÄÒ»ÏЧ£¬ÃûΪ GhostEngine£¬Ëü¿ÉÒÔ½ûÓà Microsoft Defender »òÄ¿±ê¼ÆËã»úÉÏ¿ÉÄÜÔËÐеÄÈκÎÆäËû·À²¡¶¾»ò¶Ëµã±£»¤Èí¼þ ¡£Ëü»¹Òþ²ØÁËÈκα»ÈëÇÖµÄÖ¤¾Ý ¡£GhostEngine ¶ñÒâÈí¼þµÄÊ×ҪĿ±êÊÇʹ¶ËµãÄþ¾²½â¾ö·½°¸Ê§Ð§²¢½ûÓÃÌض¨µÄ Windows ʼþÈÕÖ¾£¬ÀýÈç¼Ç¼½ø³Ì´´½¨ºÍ·þÎñ×¢²áµÄÄþ¾²ºÍϵͳÈÕÖ¾ ¡£


https://arstechnica.com/security/2024/05/researchers-spot-cryptojacking-attack-that-disables-endpoint-protections/


4. OmniVisionÔÚ2023ÄêÀÕË÷¹¥»÷ºóÅû¶Êý¾Ýй¶Ê¼þ


5ÔÂ22ÈÕ£¬OmniVision Technologies ÊÇÒ»¼ÒרÃÅ¿ª·¢ÏȽøÊý×Ö³ÉÏñ½â¾ö·½°¸µÄ¹«Ë¾ ¡£2023 Ä꣬OmniVision ÓµÓÐ 2,200 ÃûÔ±¹¤£¬ÄêÊÕÈëΪ 14 ÒÚÃÀÔª ¡£OmniVision Technologies Inc. ÊÇÖйú°ëµ¼ÌåÆ÷¼þºÍ»ìºÏÐźż¯³Éµç·Éè¼Æ¹«Ë¾Î¤¶û°ëµ¼ÌåµÄÃÀ¹ú×Ó¹«Ë¾ ¡£¸Ã¹«Ë¾Éè¼ÆºÍ¿ª·¢ÓÃÓÚÊÖ»ú¡¢Ìõ¼Ç±¾µçÄÔ¡¢ÉÏÍø±¾ºÍÍøÂçÉãÏñÍ·¡¢Äþ¾²ºÍ¼à¿ØÉãÏñÍ·¡¢ÓéÀÖ¡¢Æû³µºÍÒ½ÁƳÉÏñϵͳµÄÊý×Ö³ÉÏñ²úÎï ¡£2023 Ä꣬Õâ¼ÒͼÏñ´«¸ÐÆ÷ÖÆÔìÉÌÔâÊÜÁËCactus ÀÕË÷Èí¼þ¹¥»÷ ¡£Ä¿Ç°Éв»Çå³þÊÜÓ°ÏìÈËÊý ¡£2023 Äê 10 Ô£¬Cactus ÀÕË÷Èí¼þ×éÖ¯ÔÚÆä Tor й©ÍøÕ¾ÉϽ« OmniVision Ìí¼Óµ½Êܺ¦ÕßÃûµ¥ÖÐ ¡£×÷ΪÊý¾Ý鶵ÄÖ¤¾Ý£¬¸ÃÀÕË÷×éÖ¯Ðû²¼ÁËÊý¾ÝÑù±¾£¬°üÂÞ»¤ÕÕͼÏñ¡¢±£ÃÜЭÒé¡¢ºÏͬºÍÆäËûÎļþ ¡£Ëæºó£¬ÔÚËùνµÄ̸ÅÐʧ°Üºó£¬¸ÃÍÅ»ïÃâ·ÑÐû²¼ÁËËùÓб»µÁÊý¾Ý£¬²»Í⣬OmniVision Ä¿Ç°ÒѲ»ÔÙÁÐÔÚ Cactus Êê½ðйÃÜÍøÕ¾ÉÏ ¡£


https://securityaffairs.com/163506/data-breach/omnivision-data-breach.html


5. ConfluenceÔ¶³Ì´úÂëÖ´ÐЩ¶´CVE-2024-21683


5ÔÂ22ÈÕ£¬¹ã·ºÊ¹ÓõÄÍŶÓÊÂÇéÇøÆóÒµ wiki Confluence ±»·¢ÏÖ´æÔÚÑÏÖصÄÔ¶³Ì´úÂëÖ´ÐЩ¶´ ¡£¸Ã©¶´±»±ê־Ϊ CVE-2024-21683£¬ÑÏÖØÐÔΪ 8.3£¨¸ß£© ¡£¸Ã©¶´Ó°Ïì Confluence Êý¾ÝÖÐÐĺͷþÎñÆ÷µÄ¶à¸ö°æ±¾£¬°üÂÞÊý¾ÝÖÐÐÄ°æ±¾ 8.9.0 ºÍ·þÎñÆ÷°æ±¾ 8.5.0 ÖÁ 8.5.8 LTS ¡£²»Íâ¸Ã©¶´ÒѾ­ÔÚConfluence Data CenterºÍServerµÄ×îа汾ÖÐÐÞ¸´ ¡£´Ë©¶´ÔÊÐí¾­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÔÚϵͳÖÐÖ´ÐÐÈÎÒâ´úÂ룬Õâ¿ÉÄÜ»á¶Ô CIA £¨»úÃÜÐÔ¡¢ÍêÕûÐԺͿÉÓÃÐÔ£©Ôì³ÉÑÏÖØÓ°Ïì ¡£´ËÍ⣬´Ë©¶´²»ÐèÒªÈκÎÓû§½»»¥¼´¿ÉÀÖ³É ¡£


https://gbhackers.com/critical-confluence-server-flaw/


6. London DrugsÒ©µêÈ·ÈÏÔâµ½ÀÕË÷¹¥»÷µ«²»Ö§¸¶Êê½ð


5ÔÂ22ÈÕ£¬ÄôóÁ¬ËøÒ©µêÂ׶ØÒ©µê (London Drugs) ÒÑÈ·ÈÏÀÕË÷Èí¼þ·¸×ï·Ö×ÓÇÔÈ¡ÁËÆ䲿ÃÅ°üÂÞÔ±¹¤ÐÅÏ¢µÄ¹«Ë¾Îļþ£¬²¢ÌåÏÖ¡°²»Ô¸ÒâÒ²ÎÞ·¨ÏòÕâЩÍøÂç·¸×ï·Ö×ÓÖ§¸¶Êê½ð¡± ¡£Õâ¼Ò×ܲ¿Î»ÓÚ²»Áе߸çÂ×±ÈÑǵĹ«Ë¾ÔÚ¸øThe RegisterµÄÒ»·ÝÉùÃ÷ÖгÆ£¬4 Ô 28 ÈÕµÄÈëÇÖʼþÊÇ¡°ÓÉһȺÀÏÁ·µÄÈ«ÇòÍøÂç·¸×ï·Ö×Ó¾«ÐijïıµÄ¹¥»÷¡±£¬¶ø¸Ã¹«Ë¾´ËÇ°Ôø³ÆÆäΪ¡°ÍøÂçÄþ¾²Ê¼þ¡± ¡£ ´Ë´ÎÊý×ÖÈëÇÖʼþÆÈʹÂ׶ØÒ©µêÔÚ²»Áе߸çÂ×±ÈÑÇÊ¡¡¢°¢¶û²®ËþÊ¡¡¢Èø˹¿¦³¹ÎÂÊ¡ºÍÂíÄáÍаÍÊ¡µÄ 79 ¼ÒÃŵê¹Ø±ÕÖÁ 5 Ô 7 ÈÕ£¬µ«Ò©·¿ÊÂÇéÈËÔ±ÈÔÔÚµêÍâáÝáåÒÔÅäÖÆÖØÒª´¦·½ ¡£


https://www.theregister.com/2024/05/22/london_drugs_ransomware/