McLaren Health CareÔâµ½¹¥»÷220ÍòÈ˵ÄÐÅϢй¶
Ðû²¼Ê±¼ä 2023-11-13¾Ý11ÔÂ10ÈÕ±¨µÀ£¬£¬McLaren Health Care(Âõ¿Â×)Åû¶ÁË7ÔÂÖÁ8Ô±¬·¢µÄÒ»ÆðÊý¾Ýй¶ÊÂÎñ£¬£¬Ó°ÏìÁË2192515È˵ÄÐÅÏ¢¡£¡£¡£¡£¡£¡£Âõ¿Â×ÓÚ8ÔÂ22ÈÕ·¢Ã÷ÁËÒì³£»£»£»£»£»î¶¯£¬£¬ÊÓ²ìÏÔʾ¹¥»÷Õß7ÔÂ28ÈÕÖÁ8ÔÂ23ÈÕδ¾ÊÚȨ»á¼ûÁËÆäÍøÂç¡£¡£¡£¡£¡£¡£ÓÐÖ¤¾ÝÅú×¢£¬£¬8ÔÂ31ÈÕ¹¥»÷Õß»á¼ûÁËÊý¾Ý£¬£¬²¢Ö±µ½10ÔÂ10ÈÕÈ·ÈÏй¶Êý¾ÝµÄÀàÐÍ¡£¡£¡£¡£¡£¡£Ö»¹Ü¸Ã»ú¹¹Ã»ÓÐ͸¶Óйع¥»÷µÄ¸ü¶àϸ½Ú£¬£¬µ«ALPHVÉù³Æ¶ÔÂõ¿Â׵Ĺ¥»÷ÈÏÕæ¡£¡£¡£¡£¡£¡£ËûÃÇ»¹Ðû²¼Á˱»µÁÊý¾ÝÑù±¾£¬£¬²¢ÍþвҪÅÄÂôÓ°Ïì250ÍòÈ˵ÄÊý¾Ý¿â¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/154014/data-breach/mclaren-health-care-data-breach.html
2¡¢CloudflareÍøÕ¾Ôâµ½Anonymous SudanµÄDDoS¹¥»÷
¾ÝýÌå11ÔÂ9ÈÕ±¨µÀ£¬£¬CloudflareÍøÕ¾Ôâµ½Anonymous SudanµÄDDoS¹¥»÷¡£¡£¡£¡£¡£¡£CloudflareÍøÕ¾å´»ú£¬£¬ÏÔʾ¡°ÎÒÃǺÜÇ¸ØÆ......µ«ÄúµÄÅÌËã»ú»òÍøÂç¿ÉÄÜÕýÔÚ·¢ËÍ×Ô¶¯ÅÌÎÊ¡£¡£¡£¡£¡£¡£ÎªÁ˱£»£»£»£»£»¤ÈËÉú¾ÍÊDz©Óû§£¬£¬ÎÒÃÇÏÖÔÚÎÞ·¨´¦Öóͷ£ÄúµÄÇëÇó¡±ÒÔ¼°Ò»¸ö¿´ÆðÀ´¡°Óеã²î³Ø¾¢¡±µÄGoogle»Õ±ê¡£¡£¡£¡£¡£¡£CloudflareÌåÏÖDDoS¹¥»÷µ¼ÖÂwww.cloudflare.com·ºÆðÁ˼¸·ÖÖÓµÄÅþÁ¬ÎÊÌâ¡£¡£¡£¡£¡£¡£¿ÉÊÇûÓÐÓ°ÏìCloudflareµÄÈκÎЧÀÍ»ò²úÆ·¹¦Ð§£¬£¬Ò²Ã»Óпͻ§Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£Anonymous SudanÉù³Æ¶Ô´ËÊÂÈÏÕæ£¬£¬²¢³Æ¹¥»÷Ò»Á¬Ê±¼äΪ1Сʱ¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/technology/cloudflare-website-downed-by-ddos-attack-claimed-by-anonymous-sudan/
3¡¢MandiantÅû¶Sandworm¹¥»÷ÎÚ¿ËÀ¼µçÁ¦ÏµÍ³µÄÏêÇé
MandiantÔÚ11ÔÂ9ÈÕÅû¶ÁËSandwormʹÓÃÕë¶ÔOTµÄÐÂÐ͹¥»÷Ó°ÏìÎÚ¿ËÀ¼µçÁ¦¹©Ó¦µÄ»î¶¯¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñ±¬·¢ÓÚ2022Äêµ×£¬£¬MandiantÌåÏÖÕâÊÇÒ»´Î¶àÊÂÎñÍøÂç¹¥»÷£¬£¬Ê¹ÓÃÁËÓ°ÏìICS/OTµÄз½·¨¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÊ×ÏÈʹÓÃOT¼¶±ðµÄLotL¹¥»÷£¬£¬¿ÉÄܻᴥ·¢Ä¿µÄ±äµçÕ¾¶Ï·Æ÷£¬£¬µ¼ÖÂÒâÍâÍ£µç£¬£¬Í¬Ê±¶ÔÎÚ¿ËÀ¼¸÷µØµÄÒªº¦»ù´¡ÉèʩʵÑé´ó¹æÄ£µ¼µ¯¹¥»÷¡£¡£¡£¡£¡£¡£SandwormËæºóÔÚÄ¿µÄµÄITϵͳÖÐ×°ÖÃÁËCADDYWIPERµÄбäÖÖ£¬£¬´Ó¶øÖ´Ðеڶþ´ÎÆÆËðÐÔ¹¥»÷¡£¡£¡£¡£¡£¡£
https://www.mandiant.com/resources/blog/sandworm-disrupts-power-ukraine-operational-technology
4¡¢Imperial Kitten¹¥»÷Öж«µØÇøÔËÊä¡¢ÎïÁ÷ºÍ¿Æ¼¼¹«Ë¾
11ÔÂ9ÈÕ£¬£¬CrowdStrike¹ûÕæÁËImperial KittenÕë¶ÔÖж«µØÇøÔËÊä¡¢ÎïÁ÷ºÍ¿Æ¼¼¹«Ë¾µÄµÄÐÂÒ»Âֻ¡£¡£¡£¡£¡£¡£10Ô·ݣ¬£¬¹¥»÷Õß×îÏÈ·Ö·¢ÒÔ¡°ÊÂÇéÕÐÆ¸¡±Ö÷Ì⣬£¬°üÀ¨¶ñÒâExcel¸½¼þµÄ´¹ÂÚÓʼþ¡£¡£¡£¡£¡£¡£·¿ªºó¶ñÒâºê´úÂë»áÌáÈ¡Á½¸öÅú´¦Öóͷ£Îļþ£¬£¬ËüÃǽ¨É賤ÆÚÐÔ²¢ÔËÐÐpayloadÀ´¾ÙÐз´Ïòshell»á¼û¡£¡£¡£¡£¡£¡£È»ºó£¬£¬¹¥»÷ÕßʹÓÃPAExecµÈ¹¤¾ßºáÏòÒÆ¶¯ÒÔÔ¶³ÌÖ´ÐÐÀú³Ì£¬£¬Ê¹ÓÃNetScanÕìÌ½ÍøÂ磬£¬Ê¹ÓÃProcDump´ÓϵͳÄÚ´æÖлñȡƾ֤£¬£¬Ê¹ÓÃ×Ô½ç˵¶ñÒâÈí¼þIMAPLoaderºÍStandardKeyboardÓëC2ЧÀÍÆ÷ͨѶ¡£¡£¡£¡£¡£¡£
https://www.crowdstrike.com/blog/imperial-kitten-deploys-novel-malware-families/
5¡¢Î¢Èí³ÆSysAidÎó²îCVE-2023-47246±»ÓÃÀ´·Ö·¢Clop
ýÌå11ÔÂ9Èճƣ¬£¬¹¥»÷ÕßÕýÔÚʹÓÃЧÀÍÖÎÀíÈí¼þSysAidÖеÄÎó²î»á¼ûÆóÒµµÄЧÀÍÆ÷À´ÇÔÈ¡Êý¾Ý£¬£¬²¢°²ÅÅÀÕË÷Èí¼þClop¡£¡£¡£¡£¡£¡£ÕâÊÇÒ»¸ö·¾¶±éÀúÎó²î£¨CVE-2023-47246£©£¬£¬ÔÚºÚ¿ÍʹÓøÃÎó²îÈëÇÖÄÚ²¿Ð§ÀÍÆ÷ºóÓÚ11ÔÂ2ÈÕ±»·¢Ã÷£¬£¬SysAidÔÚÊÓ²ìЧ¹ûÕæÁ˹¥»÷µÄÊÖÒÕϸ½Ú¡£¡£¡£¡£¡£¡£Î¢ÈíÏÖÔÚÈ·¶¨£¬£¬¸ÃÎó²î±»Lace Tempest£¨ÓÖ³ÆFin11ºÍTA505£©ÓÃÀ´°²ÅÅÀÕË÷Èí¼þClop¡£¡£¡£¡£¡£¡£SysAidÒÑÐû²¼Îó²î²¹¶¡£¬£¬½¨ÒéËùÓÐÓû§Á¬Ã¦×°ÖøüС£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/microsoft-sysaid-zero-day-flaw-exploited-in-clop-ransomware-attacks/
6¡¢KasperskyÐû²¼¹ØÓÚDucktail¹¥»÷»î¶¯µÄÆÊÎö±¨¸æ
11ÔÂ10ÈÕ£¬£¬KasperskyÐû²¼Á˹ØÓÚDucktail¹¥»÷»î¶¯µÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£DucktailÊÇÒ»¸ö¶ñÒâÈí¼þ¼Ò×壬£¬×Ô2021ÄêϰëÄêÒÔÀ´Ò»Ö±»îÔ¾£¬£¬Ö¼ÔÚÇÔÈ¡FacebookÆóÒµÕÊ»§¡£¡£¡£¡£¡£¡£±¾±¨¸æÆÊÎöÁË×î½üµÄÒ»´Î»î¶¯£¬£¬3ÔÂÖÁ10ÔÂÉÏÑ®£¬£¬Ö÷ÒªÕë¶ÔÓªÏúרҵְԱ¡£¡£¡£¡£¡£¡£ÓëÒÔÍùÒÀÀµ.NETÓ¦ÓóÌÐòµÄ»î¶¯²î±ð£¬£¬Õâ´Î»î¶¯Ê¹ÓÃÁËDelphi¡£¡£¡£¡£¡£¡£¸Ã»î¶¯·¢ËͰüÀ¨¹«Ë¾Ð²úƷͼƬºÍαװ³ÉPDFµÄ¶ñÒâ¿ÉÖ´ÐÐÎļþµÄÎĵµ£¬£¬Ö¼ÔÚÈö²¥Ð°汾µÄDucktail¡£¡£¡£¡£¡£¡£
https://securelist.com/ducktail-fashion-week/111017/


¾©¹«Íø°²±¸11010802024551ºÅ