¶àÂ׶à½ÌÓý¾ÖÔâLockBitÀÕË÷Èí¼þ¹¥»÷£¬Ñ§ÉúÐÅϢй¶

Ðû²¼Ê±¼ä 2024-09-03
1. ¶àÂ׶à½ÌÓý¾ÖÔâLockBitÀÕË÷Èí¼þ¹¥»÷£¬Ñ§ÉúÐÅϢй¶


8ÔÂ31ÈÕ£¬¶àÂ׶àµØÓò½ÌÓý¾Ö£¨TDSB£©±¾ÖÜÈ·ÈÏÁË6Ô·ݷ¢ÉúµÄÒ»´ÎÀÕË÷Èí¼þ¹¥»÷ʼþ£¬¸ÃʼþÉ漰ѧÉúÐÅÏ¢µÄй¶¡£¾¡¹Ü×î³õ½ÌÓý¾ÖÌåÏÖ¹¥»÷½öÕë¶ÔÒ»¸ö¼¼Êõ²âÊÔ»·¾³£¬Óë¹Ù·½ÍøÂç¸ôÀ룬µ«ºóÐø֤ʵ2023/2024ѧÄêÖв¿ÃÅѧÉúµÄ¸öÈËÐÅÏ¢£¬°üÂÞÐÕÃû¡¢Ñ§Ð£ÏêÇé¡¢Ä꼶¡¢ÓÊÏäµØÖ·¡¢Ñ§ºÅ¼°³öÉúÈÕÆڵȣ¬È·ÊµÔÚ²âÊÔ»·¾³Öб»Ð¹Â¶¡£½ÌÓý¾ÖÇ¿µ÷£¬¾­ÍøÂçÄþ¾²ÍŶӺÍÍⲿר¼ÒÆÀ¹À£¬Ñ§ÉúÃæÁٵķçÏÕ¡°ºÜµÍ¡±£¬ÇÒδ·¢ÏÖÊý¾Ý¹ûÈ»Åû¶µÄÇé¿ö¡£È»¶ø£¬LockBitÀÕË÷Èí¼þÍÅ»ïËæºóÈÏ¿ÉÁ˴˴ι¥»÷£¬²¢ÔÚÆäйÃÜÍøÕ¾Éϸø½ÌÓý¾ÖÉ趨ÁËÖ§¸¶Êê½ðµÄÆÚÏÞ£¬µ«Î´¹ûÈ»¾ßÌåÊê½ðÊý¶î¡£TDSBÉÐδ¾ÍLockBitµÄÉùÃ÷×÷³ö»ØÓ¦£¬µ«ÒÑÖÂÐżҳ¤ËµÃ÷Çé¿ö£¬²¢Ç¿µ÷ÒѽÓÄɶàÏî´ëÊ©¼ÓǿѧÉúÐÅÏ¢Äþ¾²£¬Í¬Ê±ÅäºÏÖ´·¨²¿ÃÅÊӲ졣´Ë´Îʼþ·¢ÉúÔÚLockBitÍÅ»ï¶þÔ·ÝÔâ¹¥»÷ºóÊÔͼ¸´³öµÄÅä¾°Ï£¬ÆäÐû²¼µÄÊܺ¦ÕßÐÅÏ¢ÖдæÔÚ²»ÉÙ´íÎó»òÖظ´ÌõÄ¿£¬Òý·¢×¨¼ÒÖÊÒÉ¡£


https://therecord.media/toronto-school-district-board-ransomware


2. ÐÂÐÍÀÕË÷Èí¼þCicada3301»îÔ¾£¬»òÓëALPHVÓйØÁª


9ÔÂ2ÈÕ£¬ÐÂÐÍÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©Cicada3301½üÆÚÔÚÍþвÁìÓòո¶ͷ½Ç£¬Õë¶Ô¶à¼Ò¹«Ë¾Ìᳫ¹¥»÷£¬Æä»îÔ¾ÐÔÁîÈËÖõÄ¿¡£×Ô6ÔÂÒÔÀ´£¬Cicada3301ͨ¹ýRAMPÍøÂç·¸×ïÂÛ̳ÕÐļ³ÉÔ±£¬½ÓÄÉRustÓïÑÔ±àд£¬Ö§³ÖWindows¼°Linux/ESXiϵͳ£¬ÏÔʾ³öÓëÒѽâÉ¢µÄBlackCat/ALPHV×éÖ¯ÔÚ¼¼ÊõÉϵÄÏàËÆÐÔ£¬°üÂÞ¼ÓÃÜËã·¨¡¢ÃüÁîʹÓúÍÎļþÃüÃûÔ¼¶¨¡£Cicada3301ͨ¹ýÇÔÈ¡»ò±©Á¦Æƽâƾ֤µÇ¼ϵͳ£¬Ê¹ÓõÄIPµØÖ·ÓëBrutus½©Ê¬ÍøÂçÏà¹ØÁª£¬¿ÉÄܱíÃ÷Á½Õß¼äµÄijÖÖÁªÏµ¡£Æä³õʼ¹¥»÷ÊֶζàÑù£¬°üÂÞÕë¶ÔVMware ESXiϵͳµÄÌرð±äÌå¡£¸ÃÀÕË÷Èí¼þ¾ß±¸¸ß¶È¿ÉÅäÖÃÐÔ£¬ÔÊÐí²Ù×÷Ô±ÔÚÖ´Ðйý³ÌÖе÷ÕûÆäÐÐΪ£¬ÈçÑÓ³ÙÖ´ÐС¢ÏÔʾ¼ÓÃܽø¶È¼°ÔÚ¼ÓÃÜESXiÖ÷»úÎļþʱÎÞÐè¹Ø±ÕÐéÄâ»úµÈ£¬ÕâЩ¹¦Ð§ÔöÇ¿ÁËÆäÊÊÓ¦ÐÔºÍÁé»îÐÔ¡£¼ÓÃܹý³ÌÖУ¬Cicada3301ʹÓÃOsRngËæ»úÊýÉú³ÉÆ÷Éú³É¶Ô³ÆÃÜÔ¿£¬²¢Í¨¹ýPGP¹«Ô¿¼ÓÃÜÕâЩÃÜÔ¿£¬Í¬Ê±ÔÚÿ¸ö¼ÓÃÜÎļþ¼ÐÖÐÁôÏÂÊê½ð˵Ã÷Îļþ¡£¼ÓÃÜÍê³Éºó£¬ChaCha20ÃÜÔ¿±»RSA¼ÓÃÜ£¬²¢Óë¼ÓÃÜÎļþÀ©Õ¹Ãûһͬ¸½¼Óµ½Îļþĩ⣬ÐγÉÍêÕûµÄÀÕË÷ÐÅÏ¢¡£


https://securityaffairs.com/167897/cyber-crime/a-new-variant-of-cicada-ransomware-targets-vmware-esxi-systems.html


3. Â׶ؽ»Í¨¾ÖÓ¦¶ÔÍøÂç¹¥»÷£¬ÉÐÎÞÖ¤¾ÝÏÔʾ¿Í»§Êý¾Ýй¶


9ÔÂ2ÈÕ£¬Â׶ؽ»Í¨¾Ö£¨TfL£©ÕýÈ«Á¦Ó¦¶ÔÒ»ÆðÕýÔÚ½øÐÐÖеÄÍøÂç¹¥»÷£¬Í¬Ê±Ïò¹«ÖÚ±£Ö¤£¬Ä¿Ç°ÉÐÎÞÈ·ÔäÖ¤¾Ý±íÃ÷¿Í»§¸öÈËÐÅÏ¢ÒÑÒò´Ë´Îʼþ¶øй¶£¬ÇÒTfLµÄ¸÷Ïî·þÎñÔË×÷Õý³££¬Î´ÊÜÃ÷ÏÔÓ°Ïì¡£×÷ΪÂ׶صØÓò½»Í¨ÍøÂçµÄÖ÷Òª¹ÜÀí»ú¹¹£¬TfLѸËÙÏìÓ¦£¬Óë¹ú¼Ò·¸×ï¾Ö£¨NCA£©¼°¹ú¼ÒÍøÂçÄþ¾²ÖÐÐÄ£¨NCSC£©½ôÃܺÏ×÷£¬½ÓÄÉÁËһϵÁÐÄÚ²¿´ëÊ©ÒÔ¼ÓÇ¿ÍøÂçÄþ¾²·À»¤¡£¾ÝÄÚ²¿ÏûϢ͸¶£¬´Ë´Î¹¥»÷Ö÷Òª¼¯ÖÐÓÚTfL×ܲ¿µÄºǫ́ϵͳ£¬´Ùʹ²¿ÃÅÔ±¹¤±»½¨Òé¾Ó¼Ò°ì¹«ÒÔ¼õÉÙDZÔÚ·çÏÕ¡£TfLÊ×ϯ¼¼Êõ¹ÙShashi VermaÇ¿µ÷£¬±£»¤ÏµÍ³Óë¿Í»§Êý¾ÝµÄÄþ¾²ÊÇÊ×ÒªÈÎÎñ£¬ÍŶӽ«Á¬Ðø¼à¿Ø²¢ÆÀ¹ÀÊÂ̬Éú³¤£¬È·±£¹«ÖÚ³öÐÐÄþ¾²ÓëÐÅÈβ»ÊÜË𺦡£×ÜÌå¶øÑÔ£¬¾¡¹ÜÃæÁÙÌôÕ½£¬TfLÕ¹ÏÖ³ö»ý¼«Ó¦¶ÔµÄ̬¶È£¬Á¦Çó½«Ç±ÔÚÓ°Ïì½µÖÁ×îµÍ¡£


https://securityaffairs.com/167946/hacking/transport-for-london-tfl-ongoing-cyberattack.html


4. µØÀí¶¨Î»×·×Ù·þÎñTracelo³¬140ÍòÈËÐÅÏ¢ÔâºÚ¿Íй¶


9ÔÂ2ÈÕ£¬ÖÇÄÜÊÖ»úµØÀí¶¨Î»×·×Ù·þÎñTraceloÔÚ9ÔÂ1ÈÕÔâÓöÖØ´óÊý¾Ýй¶Ê¼þ£¬ºÚ¿Í¡°Satanic¡±Éù³Æ¹¥ÆÆÁËÆäϵͳ£¬²¢ÔÚÍøÂçºÚÊÐÉϹûÈ»ÁËÁè¼Ý140ÍòÈ˵ĸöÈËÐÅÏ¢£¬Òý·¢¹ã·º¹Ø×¢¡£Tracelo×÷ΪÐÂÐË·þÎñ£¬Ëä±ê°ñµÀµÂ¹æ·¶µÄ¶¨Î»×·×Ù£¬µ«ÆäÔÚÊý¾ÝÊÕ¼¯ÓëͬÒâÑéÖ¤ÉϵÄ͸Ã÷¶È²»×㣬Òý·¢ÁËÒþ˽±£»¤ÕùÒé¡£´Ë´Î鶵ÄÊý¾Ý°üÂÞÓû§È«Ãû¡¢µç»°ºÅÂë¡¢ÎïÀíµØÖ·¡¢µç×ÓÓʼþµÈÃô¸ÐÐÅÏ¢£¬ÒÔ¼°´óÁ¿¿Í»§µÄGoogle IDºÅ£¬ºóÕß¿ÉÄܽøÒ»²½Ì»Â¶Óû§µÄÈÕ³£»î¶¯¹ì¼£¡£ÖµµÃ×¢ÒâµÄÊÇ£¬¾¡¹ÜTraceloÖ¼ÔÚ×ÊÖúÓû§×·×ÙËûÈËλÖ㬵«Ð¹Â¶µÄÊý¾ÝÖв¢Î´°üÂÞÄ¿±ê¸öÈ˵ÄλÖÃÐÅÏ¢£¬·´¶øÖ÷ÒªÊÇ¿Í»§×ÔÉíµÄÏêϸ×ÊÁÏ¡£ÊÜÓ°ÏìµÄÓû§ÃæÁÙÍøÂçµöÓãºÍÓïÒôµöÓãÕ©Æ­µÄÍþвÔö¼Ó£¬Òò´ËÐè¸ß¶È¾¯ÌèÀ´×Ô²»Ã÷À´Ô´µÄÓʼþºÍµç»°£¬ÖÆֹй¶¸ü¶à¸öÈËÐÅÏ¢¡£


https://hackread.com/tracelo-location-tracker-data-breach-user-records-leak/


5. CBIZÊý¾Ýй¶Ê¼þÆع⣬½ü36,000¿Í»§ÐÅÏ¢ÔâÇÔ


9ÔÂ2ÈÕ£¬CBIZ¸£ÀûÓë±£ÏÕ·þÎñ¹«Ë¾Åû¶ÁËÒ»ÆðÑÏÖصÄÊý¾Ýй¶Ê¼þ£¬¸ÃʼþÉæ¼°½ü36,000Ãû¿Í»§µÄÃô¸ÐÐÅÏ¢±»Î´¾­ÊÚȨ·ÃÎÊ¡£¾ÝϤ£¬Ò»ÃûÍþвÐÐΪÕßÀûÓÃCBIZÍøÒ³ÖеÄÄþ¾²Â©¶´£¬ÔÚ6ÔÂ2ÈÕÖÁ21ÈÕÆÚ¼äDZÈëϵͳ²¢ÇÔÈ¡ÁË°üÂÞÐÕÃû¡¢ÁªÏµ·½Ê½¡¢Éç»áÄþ¾²ºÅÂë¡¢³öÉú/ËÀÍöÈÕÆÚ¡¢ÍËÐÝÈËÔ±½¡¿µÐÅÏ¢¼°¸£Àû¼Æ»®ÐÅÏ¢ÔÚÄڵĿͻ§Êý¾Ý¡£CBIZ×÷ΪÃÀ¹úÁìÏȵÄ×ÛºÏÐÔ·þÎñÌṩÉÌ£¬ÒµÎñ·¶Î§º­¸Ç»á¼ÆË°Îñ¡¢±£ÏÕ¡¢ÉÌÒµ×Éѯ¼°ÈËÁ¦×ÊÔ´µÈ¶à¸öÁìÓò£¬ÔÚÈ«¹úÓµÓÐ120¸ö·þÎñ´¦¼°6,700ÃûÔ±¹¤£¬2023ÄêÊÕÈë¸ß´ï15.9ÒÚÃÀÔª¡£¹«Ë¾ÒÑÓÚ6ÔÂ24ÈÕ·¢ÏÖ´Ë´ÎÈëÇÖ£¬²¢Á¢¼´×ÅÊÖÊӲ졣ÊÜÓ°Ïì¿Í»§×Ô8ÔÂ28ÈÕÆð½ÐøÊÕµ½¸öÐÔ»¯Í¨Öª£¬CBIZËäδ·¢ÏÖÊý¾ÝÀÄÓü£Ï󣬵«ÈÔÌṩΪÆÚÁ½ÄêµÄÐÅÓüà¿ØºÍÉí·Ý͵ÇÔ±£»¤·þÎñ£¬²¢½¨Òé¿Í»§½ÓÄÉÌرð´ëÊ©ÈçÐÅÓö³½á¼°Ìí¼ÓÆÛÕ©¾¯±¨£¬ÒÔ½µµÍDZÔÚ·çÏÕ¡£


https://www.bleepingcomputer.com/news/security/business-services-giant-cbiz-discloses-customer-data-breach/


6. Prasarana Malaysia BhdÔâÀÕË÷¹¥»÷£¬³¬300GBÊý¾Ýй¶


8ÔÂ30ÈÕ£¬ÂíÀ´Î÷Ñǹ«¹²½»Í¨¾ÞÍ·¹ú¼Ò»ù½¨¹«Ë¾£¨Prasarana Malaysia Bhd£©½üÈÕÈ·ÈÏÁËÉ罻ýÌåÉÏÁ÷´«µÄÒ»ÔòÍøÂçÄþ¾²Ê¼þ±¨µÀµÄÕæʵÐÔ£¬Ö¸³öÆäÄÚ²¿ÏµÍ³È·ÒÑÔâÊÜδÊÚȨ·ÃÎÊ¡£¾¡¹Ü´Ë´ÎʼþÉÐδ¶Ô¹«Ë¾µÄÈÕ³£ÔËÓªÔì³ÉÓ°Ï죬µ«¹«Ë¾ÒÑѸËÙ½ÓÄÉÐж¯£¬ÁªºÏÍøÂçÄþ¾²×¨¼ÒÕ¹¿ªÈ«ÃæÊӲ죬²¢×ÅÊÖ»º½âDZÔÚÍþв¡£Í¬Ê±£¬¹ú¼Ò»ù½¨¹«Ë¾ÒÑÓëÂíÀ´Î÷Ñǹú¼ÒÍøÂçÄþ¾²¾Ö£¨Nacsa£©¼°ÍøÂçÄþ¾²»ú¹¹£¨CyberSecurity Malaysia£©½ôÃܺÏ×÷£¬ÅäºÏÖƶ¨²¢ÊµÊ©È«ÃæµÄÄþ¾²·ÀÓù¼Æı£¬ÒÔ±£ÕÏÆ佻ͨ·þÎñϵͳµÄÄþ¾²Îȶ¨ÔËÐС£×÷ΪÂíÀ´Î÷Ñǹ«¹²½»Í¨ÏµÍ³µÄÖØÒª×é³É²¿ÃÅ£¬¹ú¼Ò»ù½¨¹«Ë¾²»½öÔËÓªRapidKLÆìϵÄÇá¹ì¡¢½ÝÔË¡¢°ÍÊ¿¿ìËÙ½»Í¨ÏµÍ³£¬»¹¹ÜÀí¼ªÂ¡Æµ¥¹ìÁгµ¼°ÅÓ´óµÄ¹«½»³µ¶Ó¡£ÕâÒ»ÉùÃ÷Ö¼ÔÚ»ØÓ¦Íâ½ç¹ØÓÚ¹«Ë¾ÍøÕ¾¿ÉÄÜÔâÊÜÀÕË÷Èí¼þ¹¥»÷£¬µ¼ÖÂ316GBÊý¾Ýй¶µÄ´«ÑÔ¡£¾ÝϤ£¬ÀÕË÷Èí¼þ×éÖ¯RansomHubÒÑ·¢³öÍþв£¬Éù³Æ½«ÔÚÁùµ½ÆßÌìÄÚ¹ûÈ»¹ú¼Ò»ù½¨¹«Ë¾µÄÃô¸ÐÊý¾Ý¡£


https://www.freemalaysiatoday.com/category/nation/2024/08/26/prasarana-confirms-cybersecurity-incident/