TikTok¿ÉÄÜÒòδÄܱ£»£»£»£»£»£»¤¶ùͯÒþË½ÃæÁÙ2700ÍòÓ¢°÷µÄ·£¿£¿£¿£¿£¿£¿£¿î

Ðû²¼Ê±¼ä 2022-09-28
1¡¢TikTok¿ÉÄÜÒòδÄܱ£»£»£»£»£»£»¤¶ùͯÒþË½ÃæÁÙ2700ÍòÓ¢°÷µÄ·£¿£¿£¿£¿£¿£¿£¿î

      

¾Ý9ÔÂ26ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬£¬Ó¢¹úÒþ˽î¿Ïµ»ú¹¹Ðû²¼ÓÐÒâ¶ÔÎ¥·´¸Ã¹úÊý¾Ý±£»£»£»£»£»£»¤·¨µÄTikTok´¦ÒÔ2700ÍòÓ¢°÷µÄ·£¿£¿£¿£¿£¿£¿£¿î¡£¡£¡£ÐÅϢרԱ°ì¹«ÊÒ(ICO)ÒÑÏòÉ罻ýÌåÆ½Ì¨TikTok·¢³ö¡°ÒâÏò֪ͨ¡±¡£¡£¡£Æ¾Ö¤Í¨Öª£¬£¬£¬£¬£¬£¬£¬£¬TikTokÔÚ2018Äê5ÔÂÖÁ2020Äê7ÔÂʱ´ú¿ÉÄÜδ¾­âïÊÑÔ޳ɴ¦Öóͷ£13ËêÒÔ϶ùͯµÄÊý¾Ý£»£»£»£»£»£»Î´ÄÜÒÔ¾«Á·¡¢Í¸Ã÷ºÍÒ×ÓÚÃ÷È·µÄ·½·¨ÏòÓû§ÌṩÐÅÏ¢£»£»£»£»£»£»ÒÔ¼°ÔÚûÓÐÖ´·¨ÒÀ¾ÝµÄÇéÐÎÏ´¦Öóͷ£ÌØÊâÖÖ±ðÊý¾Ý£¨°üÀ¨ÖÖ×åºÍÖÖ×å¡¢ÒÅ´«¡¢¿µ½¡ºÍÉúÎïÌØÕ÷Êý¾ÝµÈ£©¡£¡£¡£ICOÌåÏÖ£¬£¬£¬£¬£¬£¬£¬£¬ÊÓ²ìÊÇÆðÔ´µÄ£¬£¬£¬£¬£¬£¬£¬£¬Í¨ÖªÒ²ÊÇÔÝʱµÄ£¬£¬£¬£¬£¬£¬£¬£¬Ëü½«ÔÚ×Ðϸ˼Á¿TikTokµÄ³ÂÊöºóÔÙ×ö¾öÒé¡£¡£¡£


https://therecord.media/tiktok-could-face-27-million-fine-for-failing-to-protect-uk-childrens-privacy/


2¡¢ÒÔÉ«Áйú·À³Ð°üÉÌElbitÃÀ¹ú·Ö¹«Ë¾Ô±¹¤µÄСÎÒ˽¼ÒÐÅϢй¶

      

¾ÝýÌå9ÔÂ27Èճƣ¬£¬£¬£¬£¬£¬£¬£¬ÒÔÉ«Áйú·À³Ð°üÉÌElbitµÄÃÀ¹ú·Ö¹«Ë¾Elbit Systems of AmericaÔâµ½¹¥»÷ºóÊý¾Ýй¶¡£¡£¡£6ÔÂÏÂÑ®£¬£¬£¬£¬£¬£¬£¬£¬ÀÕË÷ÍÅ»ïBlack BastaÔøÉù³ÆÈëÇÖÁËElbit Systems of America£¬£¬£¬£¬£¬£¬£¬£¬²¢½«¸Ã¹«Ë¾Ìí¼Óµ½ÆäTorÍøÕ¾ÉÏ¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾È·ÈÏÓÚ6ÔÂ8ÈÕ±¬·¢ÁËÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁË369СÎÒ˽¼Ò¡£¡£¡£Ð¹Â¶µÄÊý¾Ý°üÀ¨ÐÕÃû¡¢µØµã¡¢Éç»áÇå¾²ºÅÂë¡¢³öÉúÈÕÆÚ¡¢Ö±½Ó´æ¿îÐÅÏ¢ºÍÖÖ×åÐÅÏ¢µÈ¡£¡£¡£¸Ã¹«Ë¾ÒѾ­Í¨ÖªÊÜÓ°ÏìµÄÈË£¬£¬£¬£¬£¬£¬£¬£¬²¢½«ÎªËûÃÇÌṩ12¸öÔµÄÉí·Ý±£»£»£»£»£»£»¤ºÍÐÅÓÃ¼à¿ØÐ§ÀÍ¡£¡£¡£


https://securityaffairs.co/wordpress/136310/cyber-crime/elbit-systems-of-america-data-breach.html


3¡¢Fancy BearʹÓÃPPTµÄÊó±êÐüÍ£·Ö·¢¶ñÒâÈí¼þGraphite

      

Cluster25ÔÚ9ÔÂ23ÈÕÅû¶ÁËAPT28£¨Fancy Bear£©Ê¹ÓÃÐÂÊÖÒÕÀ´·Ö·¢¶ñÒâÈí¼þGraphiteµÄ»î¶¯¡£¡£¡£¹¥»÷ÕßʹÓÃPowerPointÎļþ×÷ΪÓÕ¶ü£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨Á½ÕÅ»ÃµÆÆ¬£¬£¬£¬£¬£¬£¬£¬£¬¾ùÒÔÓ¢Îĺͷ¨ÎÄÌṩÁËʹÓÃZoomÊÓÆµ¾Û»áÓ¦ÓóÌÐòÖеÄÚ¹ÊÍÑ¡ÏîµÄ˵Ã÷¡£¡£¡£µ±Ä¿µÄÒÔÑÝʾģʽ·­¿ªÓÕ¶üÎĵµ²¢ÇÒ½«Êó±êÐüÍ£ÔÚ³¬Á´½ÓÉÏʱ£¬£¬£¬£¬£¬£¬£¬£¬»á¼¤»î¶ñÒâPowerShell½ÅÔ­À´´ÓMicrosoft OneDriveÕÊ»§ÏÂÔØJPEGÎļþ¡£¡£¡£JPEGÊÇÒ»¸ö¼ÓÃܵÄDLLÎļþ(lmapi2.dll)£¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ýrundll32.exeÖ´ÐС£¡£¡£½ÓÏÂÀ´£¬£¬£¬£¬£¬£¬£¬£¬lmapi2.dllÔÚ֮ǰÓÉDLL½¨ÉèµÄÐÂÏß³ÌÉÏ»ñÈ¡²¢½âÃܵڶþ¸öJPEG¡£¡£¡£ 


https://blog.cluster25.duskrise.com/2022/09/23/in-the-footsteps-of-the-fancy-bear-powerpoint-graphite/


4¡¢SentinelLabs³ÆMetadorÍÅ»ïÒÑÔÚISPÍøÂçÖÐDZÔÚÊýÔÂ

      

ýÌå9ÔÂ25ÈÕ±¨µÀ³Æ£¬£¬£¬£¬£¬£¬£¬£¬SentinelLabs·¢Ã÷кڿÍÍÅ»ïMetadorÍÅ»ïÒÑÈëÇÖÁ˵çÐÅ¡¢»¥ÁªÍøÐ§ÀÍÌṩÉÌ(ISP)ºÍ´óѧԼÁ½ÄêµÄʱ¼ä¡£¡£¡£MetadorÖ÷ÒªÕë¶ÔÖж«ºÍ·ÇÖÞµÄ×éÖ¯£¬£¬£¬£¬£¬£¬£¬£¬Ä¿µÄËÆºõÊǺã¾Ã´ÓÊÂÌØ¹¤»î¶¯¡£¡£¡£¸Ã×é֯ʹÓÃÁ½ÖÖ»ùÓÚWindowsµÄ¶ñÒâÈí¼þ¿ò¼Ü£¬£¬£¬£¬£¬£¬£¬£¬metaMainºÍMafalda£¬£¬£¬£¬£¬£¬£¬£¬Ëü½öÔÚϵͳÄÚ´æÖÐÔËÐУ¬£¬£¬£¬£¬£¬£¬£¬²»»áÔÚ±»Ñ¬È¾Ö÷»úÉÏÁôÏÂδ¼ÓÃܵĺۼ£¡£¡£¡£MafaldaÊÇÒ»Öֶ๦ЧµÄÖ²Èë³ÌÐò£¬£¬£¬£¬£¬£¬£¬£¬×î¶à¿ÉÒÔ½ÓÊÜ67¸öÏÂÁ£¬£¬£¬£¬£¬£¬£¬Æä¶à²ã»ìÏý¿ÉÒÔÈÆ¹ýÇå¾²ÆÊÎö¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-hacking-group-metador-lurking-in-isp-networks-for-months/


5¡¢MandiantÅû¶¶íÂÞ˹GRUÓë3¸öºÚ¿ÍÍÅ»ïЭͬ¹¥»÷µÄÖ¤¾Ý

      

MandiantÔÚ9ÔÂ23Èճƣ¬£¬£¬£¬£¬£¬£¬£¬ÖÁÉÙ3¸öºÚ¿ÍÍÅ»ïÓë¶íÂÞ˹¾üÊÂÇ鱨»ú¹¹(GRU)µÄÍøÂçÈëÇֻ֮¼ä±£´æÏÔ×ŵÄЭ×÷¡£¡£¡£ÕâЩÍŻﻮ·ÖΪXakNet Team¡¢InfoccentrºÍCyberArmyofRussia_Reborn£¬£¬£¬£¬£¬£¬£¬£¬Ñо¿ÆÊÎö·¢Ã÷Á˽«ÕâЩ×éÖ¯Óë¶íÂÞ˹Õþ¸®ÁªÏµÆðÀ´µÄÐÂÖ¤¾Ý£¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨¶ÔÎÚ¿ËÀ¼µÄ×éÖ¯ÈëÇÖºÍйÃܵÄʱ¼äÏ߯ÊÎö¡£¡£¡£Mandiant»¹È·¶¨ÁËXakNetÓëKillNetÖ®¼äµÄÁªÏµ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÍƶÏÕâÁ½¸ö×éÖ¯Ö±½ÓЭͬÁ˲¿·Ö»î¶¯¡£¡£¡£


https://www.mandiant.com/resources/blog/gru-rise-telegram-minions


6¡¢KasperskyÐû²¼¹ØÓÚ¶ñÒâÈí¼þNullMixerµÄÆÊÎö±¨¸æ

      

9ÔÂ26ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬KasperskyÐû²¼¹ØÓÚжñÒâÈí¼þ·Ö·¢¹¤¾ßNullMixerµÄÆÊÎö±¨¸æ¡£¡£¡£¹¥»÷ÕßʹÓÃÁËSEOÊÖÒÕÔÚGoogleËÑË÷Ч¹ûµÄÏÔʾÖÐÍÆ¹ã¼ÙµÄÓÎÏ·ÆÆ½âºÍµÁ°æÈí¼þ¼¤»îÆ÷µÄÍøÕ¾£¬£¬£¬£¬£¬£¬£¬£¬ÐéÎ±ÍøÕ¾»á½«Ä¿µÄÖØ¶¨Ïòµ½¶ñÒâÍøÕ¾²¢ÏÂÔØNullMixer¸±±¾¡£¡£¡£¸Ã¹¤¾ß»á·Ö·¢Ê®¼¸¸ö¶ñÒâÈí¼þ¼Ò×壬£¬£¬£¬£¬£¬£¬£¬°üÀ¨Redline Stealer¡¢DanabotºÍRaccoon StealerµÈ¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬£¬NullMixerÒÑÊÔͼѬȾÃÀ¹ú¡¢µÂ¹ú¡¢·¨¹ú¡¢Òâ´óÀû¡¢Ó¡¶È¡¢¶íÂÞ˹¡¢°ÍÎ÷¡¢ÍÁ¶úÆäºÍ°£¼°µÄ47778¸öÓû§¡£¡£¡£


https://securelist.com/nullmixer-oodles-of-trojans-in-a-single-dropper/107498/