Otelier¾Æµê¹ÜÀíƽ̨ÔâÓö´ó¹æÄ£Êý¾Ýй¶

Ðû²¼Ê±¼ä 2025-01-20

1. Otelier¾Æµê¹ÜÀíƽ̨ÔâÓö´ó¹æÄ£Êý¾Ýй¶


1ÔÂ17ÈÕ£¬2024Äê7ÔÂÖÁ10ÔÂÆڼ䣬¾Æµê¹ÜÀíƽ̨Otelier£¨Ç°ÉíΪMyDigitalOffice£©ÔâÓöÁËÑÏÖصÄÊý¾Ýй¶Ê¼þ¡£ÍþвÐÐΪÕßÀÖ³ÉÈëÇÖÆäAmazon S3ÔÆ´æ´¢£¬ÇÔÈ¡ÁËÊý°ÙÍò¿ÍÈ˵ĸöÈËÐÅÏ¢ÒÔ¼°ÍòºÀ¡¢Ï£¶û¶Ù¡¢¿­ÔõÈÖªÃû¾ÆµêÆ·ÅƵÄÔ¤¶©ÐÅÏ¢£¬×ÜÁ¿½ü8TB¡£OtelierÒÑÈ·ÈÏ´Ë´ÎÈëÇÖ£¬²¢ÕýÓëÊÜÓ°Ïì¿Í»§Ïàͬ£¬Í¬Ê±Æ¸ÇëÁ˶¥¼âÍøÂçÄþ¾²×¨¼ÒÍŶӽøÐÐÈ«ÃæÈ¡Ö¤·ÖÎöºÍϵͳÑéÖ¤¡£Îª·ÀÖ¹ÀàËÆʼþÔٴη¢Éú£¬OtelierÒѽûÓÃÏà¹ØÕË»§²¢¼ÓÇ¿ÍøÂçÄþ¾²Ð­Òé¡£¾ÝÍþвÕß͸¶£¬ËûÃÇ×î³õͨ¹ýÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ»ñÈ¡ÁËÒ»ÃûÔ±¹¤µÄµÇ¼ÐÅÏ¢£¬½ø¶øÈëÇÖÁËAtlassian·þÎñÆ÷£¬²¢ÀûÓÃÕâЩƾ֤»ñÈ¡Á˸ü¶àÊý¾Ý£¬°üÂÞS3´æ´¢Í°µÄ·ÃÎÊȨÏÞ¡£ÍòºÀ¾ÆµêÒÑ֤ʵÆäÊܵ½Ó°Ï죬²¢ÔÝÍ£ÁËOtelierÌṩµÄ×Ô¶¯»¯·þÎñ£¬µ«Ç¿µ÷ÆäϵͳδÔڴ˴ι¥»÷ÖÐÔâµ½ÈëÇÖ¡£È»¶ø£¬Ð¹Â¶µÄÊý¾ÝÑù±¾ÏÔʾ£¬¾Æµê¿ÍÈ˵ÄÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂëºÍµç×ÓÓʼþµØÖ·µÈ¸öÈËÐÅÏ¢Òѱ»ÍµÈ¡£¬²¢±»Ìí¼Óµ½¡°Have I Been Pwned¡±ÍøÕ¾ÉϹ©È˲éѯ¡£¾¡¹ÜÃÜÂëºÍÕ˵¥ÐÅϢδ±»µÁ£¬µ«Óû§ÈÔÐ辯ÌèÕë¶Ô´Ë©¶´µÄ¿ÉÒɵç×ÓÓʼþºÍÍøÂçµöÓã¹¥»÷¡£


https://www.bleepingcomputer.com/news/security/otelier-data-breach-exposes-info-hotel-reservations-of-millions/


2. PyPIÏÖ¡°pycord-self¡±¶ñÒâ°ü£¬Õë¶ÔDiscord¿ª·¢ÈËÔ±ÇÔÈ¡ÁîÅÆÖ²ÈëºóÃÅ


1ÔÂ17ÈÕ£¬Python°üË÷Òý£¨PyPI£©ÉÏ·ºÆðÁËÒ»¿îÃûΪ¡°pycord-self¡±µÄ¶ñÒâÈí¼þ°ü£¬ËüÕë¶ÔµÄÊÇDiscord¿ª·¢ÈËÔ±¡£Õâ¿î¶ñÒâ°üÄ£·ÂÁ˹ãÊÜ»¶Ó­µÄ¡°discord.py-self¡±°ü£¬Òѱ»ÏÂÔØÔ¼885´Î¡£¾¡¹ÜËüÌṩÁ˺Ϸ¨ÏîÄ¿µÄ¹¦Ð§£¬µ«ÊµÔò°üÂÞÖ´ÐÐÁ½ÏîÖ÷Òª¶ñÒâ²Ù×÷µÄ´úÂ룺һÊÇÇÔÈ¡DiscordÉí·ÝÑéÖ¤ÁîÅƲ¢½«Æä·¢Ë͵½ÍⲿURL£¬¼´Ê¹Ë«ÒòËØÉí·ÝÑéÖ¤±£»¤´¦Óڻ״̬£¬¹¥»÷ÕßÒ²ÄÜʹÓÃÕâЩÁîÅƽٳֿª·¢ÈËÔ±µÄDiscordÕÊ»§£»¶þÊÇͨ¹ý¶Ë¿Ú6969ÓëÔ¶³Ì·þÎñÆ÷½¨Á¢³Ö¾ÃÁ¬½Ó£¬½¨Á¢ºóÃÅ»úÖÆ£¬Èù¥»÷ÕßÄܹ»Á¬Ðø·ÃÎÊÊܺ¦ÕßµÄϵͳ¡£SocketÑо¿ÈËÔ±¶Ô´Ë½øÐÐÁËÏêϸ·ÖÎö¡£Òò´Ë£¬½¨ÒéÈí¼þ¿ª·¢ÈËÔ±ÔÚ°²×°Èí¼þ°üʱ£¬Îñ±ØÑéÖ¤´úÂëÊÇ·ñÀ´×Ô¹Ù·½×÷Õߣ¬²¢¼ì²éÈí¼þ°üµÄÃû³Æ£¬ÒÔ½µµÍ³ÉΪÊܺ¦ÕߵķçÏÕ¡£Í¬Ê±£¬Ê¹ÓÿªÔ´¿âʱ£¬½¨Òé¼ì²é´úÂëÖÐÊÇ·ñ´æÔÚ¿ÉÒɺ¯Êý£¬²¢ÀûÓÃɨÃ蹤¾ß¼ì²âºÍ×èÖ¹¶ñÒâÈí¼þ°ü¡£


https://www.bleepingcomputer.com/news/security/malicious-pypi-package-steals-discord-auth-tokens-from-devs/


3. Lazarus×éÖ¯Õë¶Ô¿ª·¢ÈËÔ±Ìᳫ¡°99ºÅÐж¯¡±ÇÔÈ¡Ãô¸ÐÊý¾Ý


1ÔÂ17ÈÕ£¬³¯ÏÊÕþ¸®Ö§³ÖµÄLazarus×éÖ¯ÕýÔÚ¿ªÕ¹ÃûΪ¡°99ºÅÐж¯¡±µÄÁ¬Ðø¹¥»÷»î¶¯£¬Õë¶ÔÈí¼þ¿ª·¢ÈËÔ±ÇÔÈ¡Ãô¸ÐÊý¾Ý¡£´Ë´Î»î¶¯±êÖ¾×ÅLazarus×éÖ¯¹¥»÷¼ÆıµÄÑݱ䣬´Ó¹ã·ºµÄÍøÂçµöÓã¹¥»÷תÏòÕë¶Ô¼¼Êõ¹©Ó¦Á´ÖеĿª·¢ÈËÔ±½øÐÐÓÐÕë¶ÔÐԵĹ¥»÷¡£¹¥»÷Õßð³äÕÐƸÈËÔ±ÔÚLinkedInµÈƽ̨ÉÏÁªÏµÄ¿±ê£¬ÓÕµ¼Êܺ¦Õß¿Ë¡¶ñÒâGitHub´æ´¢¿â£¬Ö´ÐÐÆäÖеĴúÂëºóÁ¬½Óµ½Óɹ¥»÷Õß¿ØÖƵÄÃüÁîºÍ¿ØÖÆ·þÎñÆ÷¡£¸Ã·þÎñÆ÷ʹÓø߶ȻìÏýµÄPython½ÅÔ­À´Ìӱܼì²â£¬²¢Õë¶ÔÌض¨Ä¿±ê¶¯Ì¬¶¨ÖƶñÒâÈí¼þ¡£¸Ã»î¶¯²¿ÊðÁ˾ßÓÐÄ £¿é»¯×é¼þµÄ¶à½×¶Î¶ñÒâÈí¼þϵͳ£¬ÒÔÇÔÈ¡¿ª·¢ÈËÔ±µÄÔ´´úÂë¡¢»úÃÜ¡¢ÅäÖÃÎļþÒÔ¼°¼ÓÃÜ»õ±ÒÇ®°üÃÜÔ¿µÈÃô¸ÐÊý¾Ý¡£SecurityScorecard¶Ø´Ù¿ª·¢ÈËÔ±½ÓÄÉÖ÷¶¯µÄÄþ¾²´ëÊ©£¬ÈçÔöÇ¿´úÂë´æ´¢¿âÑéÖ¤¡¢Ê¹Óø߼¶¶ËµãÄþ¾²½â¾ö·½°¸¼ì²âÒì³£»î¶¯¡¢ÔÚƽ̨ÉÏÑéÖ¤ÕÐƸÈËÔ±ºÍÊÂÇé»ú»á£¬²¢ÕÆÎÕʶ±ðΣÏÕÐźŵÄ֪ʶ¡£


https://www.infosecurity-magazine.com/news/lazarus-developers-data-theft/


4. ºÚ¿Í¡°0mid16B¡±Ðû²¼ÈëÇÖMedSave£¬ÇÔÈ¡561GBÊý¾Ý²¢¼Æ»®³öÊÛ


1ÔÂ17ÈÕ£¬ÃûΪ¡°0mid16B¡±µÄºÚ¿ÍÖÜÈýÐû²¼ÒÑÀÖ³ÉÈëÇÖÓ¡¶È´óÐ͵ÚÈý·½¹ÜÀí»ú¹¹MedSave£¬ÇÔÈ¡ÁË561GBµÄÊý¾Ý¿â£¬°üÂÞÁè¼Ý1000ÍòÈ˵ÄÃô¸ÐÐÅÏ¢£¬ÆäÖв»·¦¸ß¹Ü×ÊÁÏ£¬ÇÒÊý¾Ý½ØÖ¹ÖÁ2025Äê1ÔÂ8ÈÕ¡£0mid16Bδ͸¶ÈëÇÖÊֶΣ¬µ«Éù³ÆMedSave³¤Ê±¼äδ²ì¾õÆä´æÔÚ£¬ÇÒÔÚ1ÔÂ12ÈÕÖÁ15ÈÕÆÚ¼äÈý´Î½øÈëϵͳ²¢×ÌÈÅÆäÔË×÷¡£¾¡¹ÜδÏòMedSaveÌá³ö¾ßÌåÀÕË÷½ð¶î£¬0mid16BÅúÆÀÆäÄþ¾²·À»¤µ¥±¡£¬Ö¸³ö¹«Ë¾Î´°²×°·À²¡¶¾Èí¼þ£¬ÇÒÔÚÃ÷֪©¶´´æÔÚµÄÇé¿öÏÂÈÔÖØÆô·þÎñÆ÷£¬Ê¹ÆäµÃÒÔÇáÒ×´«Êä´óÁ¿Êý¾Ý¶øδ´¥·¢¾¯±¨¡£MedSaveÍøվĿǰÎÞ·¨·ÃÎÊ£¬DataBreachesÒÑʵÑéͨ¹ý¶àÇþµÀÁªÏµMedSave¼û¸æÆäÇé¿ö£¬µ«ÉÐδÊÕµ½»Ø¸´¡£0mid16BÌåÏÖÓÐÒâ³öÊÛ²¿ÃÅÊý¾Ý²¢¹ûÈ»·Ç¿Í»§Êý¾Ý£¬´ËÊÂÓдýMedSave½øÒ»²½»ØÓ¦¡£


https://databreaches.net/2025/01/17/medsave-health-insurance-tpa-hacked-firm-has-yet-to-comment-or-respond/


5. Ä£·ÂBlack BastaÊÖ·¨µÄÍøÂç¹¥»÷Ãé×¼SlashNext¿Í»§


1ÔÂ15ÈÕ£¬SlashNextµÄһλ¿Í»§ÔâÓöÁËÄ£·ÂÎÛÃûÕÑÖøµÄBlack BastaÀÕË÷Èí¼þÍÅ»ïÊÖ·¨µÄÍøÂç¹¥»÷¡£Ôڶ̶Ì90·ÖÖÓÄÚ£¬¹¥»÷ÕßÏò22¸öÓû§ÊÕ¼þÏä·¢ËÍÁË1165·â¶ñÒâÓʼþ£¬ÆóͼÓÕÆ­Óû§µã»÷¶ñÒâÁ´½Ó¡£SlashNextµÄÑо¿ÈËÔ±½ÒʾÁËÕâ´Î¹¥»÷ѸËÙÇÒ¾«×¼£¬Ê¹ÓÃÁËÓëBlack BastaÏàËƵÄÊÖ·¨£¬Ö¼ÔÚÈÃÓû§´ëÊÖ²»¼°²¢Èƹý´«Í³Äþ¾²´ëÊ©¡£¹¥»÷ÕßÀûÓÃÀÕË÷Èí¼þÆ­¾Ö£¬Î±×°³ÉÁ÷ÐÐƽ̨·¢ËÍÐé¼ÙÓʼþ£¬Ê¹Óÿ´ËÆÎÞº¦µÄÓòÃûºÍÌØÊâ×Ö·ûµÄÖ÷ÌâÐУ¬Õë¶Ô²îÒìÓû§½ÇÉ«Ìá¸ß¹Ø×¢¶È¡£ËûÃÇͨ¹ý¿´ËƺϷ¨µÄÓʼþÑÍûÊÕ¼þÏ䣬ÖÆÔì»ìÂÒ£¬ÓÕʹÓû§µã»÷Á´½Ó¡£µ±Óû§²»ÖªËù´ëʱ£¬¹¥»÷Õßð³äITÖ§³Ö½éÈ룬ÓÕÆ­Óû§°²×°Ô¶³Ì·ÃÎÊÈí¼þ£¬´Ó¶øÔÚϵͳÖÐÕ¾ÎȽŸú£¬¿ÉÄÜÁ÷´«¶ñÒâÈí¼þ»òÇÔÈ¡Ãô¸ÐÊý¾Ý¡£ÐÒÔ˵ÄÊÇ£¬SlashNextµÄ¼¯³ÉÔÆÓʼþÄþ¾²ÏµÍ³Ñ¸ËÙʶ±ð³öΣÏÕÐźÅ£¬¼°Ê±Ó¦¶Ô¡£Õâһʼþ͹ÏÔÁËÍøÂçÄþ¾²ÍþвµÄÈÕÒæÅÓ´óÐÔ£¬¹¥»÷ÕßʹÓÃÏȽø¼¼Êõ¹æ±Ü´«Í³Äþ¾²´ëÊ©¡£Òò´Ë£¬×éÖ¯Ó¦ÓÅÏÈ¿¼ÂÇÍþв¼ì²âºÍÏìÓ¦£¬¶¨ÆÚ½øÐÐÄþ¾²ÆÀ¹À£¬ÒÔʶ±ð©¶´²¢ÌáÉýÕûÌåÄþ¾²ÐÔ¡£


https://hackread.com/black-basta-cyberattack-hits-inboxes-with-1165-emails/


6. Star BlizzardеöÓã»î¶¯Ãé×¼WhatsAppÕË»§


1ÔÂ19ÈÕ£¬¶íÂÞ˹Ãñ×å¹ú¼ÒÐÐΪÕßStar Blizzard½üÆÚ¿ªÕ¹ÁËÒ»ÏîеÄÓã²æʽÍøÂçµöÓã»î¶¯£¬×¨ÃŹ¥»÷Õþ¸®¡¢Íâ½»¡¢¹ú·ÀÕþ²ß¡¢¹ú¼Ê¹Øϵ¼°ÎÚ¿ËÀ¼Ô®Öú×éÖ¯µÈÄ¿±êµÄWhatsAppÕË»§¡£¸Ã»î¶¯ÓÚ2024Äê11ÔÂÖÐÑ®±»Î¢ÈíÍþвÇ鱨³ÂËß½Òʾ£¬±êÖ¾×ÅStar BlizzardΪӦ¶Ô¼ÆıºÍ¼¼ÊõÆعâËù×öµÄÕ½Êõת±ä¡£¹¥»÷Õßͨ¹ýµç×ÓÓʼþð³äÃÀ¹úÕþ¸®¹ÙÔ±£¬ÓÕÆ­Ä¿±ê¼ÓÈëÖ§³ÖÎÚ¿ËÀ¼µÄ·ÇÕþ¸®×éÖ¯WhatsAppȺ×飬ÓʼþÖаüÂÞË𻵵ĶþάÂ룬ÈôÊܺ¦Õß»ØÓ¦£¬Ôò»á±»Òýµ¼ÖÁÐé¼ÙÍøÒ³£¬ÒªÇóɨÃèеĶþάÂ룬ʵÔòÊǽ«¹¥»÷ÕßÉ豸Á´½ÓÖÁÊܺ¦ÕßWhatsAppÕË»§¡£Î¢ÈíÖ¸³ö£¬Ò»µ©Êܺ¦Õß²Ù×÷£¬¹¥»÷Õß¼´¿É·ÃÎÊÆäWhatsAppÏûÏ¢£¬²¢ÀûÓòå¼þÇÔÈ¡Êý¾Ý¡£´Ë´Î¹¥»÷ÒÀÀµÉç»á¹¤³Ìѧ£¬²»Éæ¼°¶ñÒâÈí¼þ£¬Óû§Ð辯Ìèδ¾­ÇëÇóµÄͨÐÅ£¬ÌرðÊǼÓÈëȺ×éµÄÑûÇ룬²¢¶¨ÆÚ¼ì²éÓëWhatsAppÕË»§¹ØÁªµÄÉ豸¡£´Ë´Î»î¶¯±íÃ÷£¬¾¡¹ÜStar BlizzardÔÚ2024Äê10ÔµĻÖжϺó²¿ÃÅÓòÃû±»²é·â£¬µ«ÆäÈÔͨ¹ý̽Ë÷й¥»÷ý½é¼ÌÐøÐж¯¡£


https://www.bleepingcomputer.com/news/security/star-blizzard-hackers-abuse-whatsapp-to-target-high-value-diplomats/