BlackCatÉù³ÆÒÑ»ñÈ¡RedditµÄ80GBÊý¾Ý²¢ÀÕË÷450ÍòÃÀÔª

Ðû²¼Ê±¼ä 2023-06-19

1¡¢BlackCatÉù³ÆÒÑ»ñÈ¡RedditµÄ80GBÊý¾Ý²¢ÀÕË÷450ÍòÃÀÔª 


¾ÝýÌå6ÔÂ17ÈÕ±¨µÀ£¬£¬£¬ £¬£¬BlackCat(ALPHV)Éù³Æ¶ÔRedditÔâµ½µÄ¹¥»÷ÈÏÕæ£¬£¬£¬ £¬£¬²¢ÌåÏÖÒÑÇÔÈ¡80 GB£¨Ñ¹Ëõ£©µÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£2ÔÂ9ÈÕ£¬£¬£¬ £¬£¬Reddit͸¶ÆäϵͳÔÚ2ÔÂ5ÈÕ±»ºÚ£¬£¬£¬ £¬£¬ÓÉÓÚÒ»ÃûÔ±¹¤Ôâµ½ÁË´¹ÂÚ¹¥»÷¡£¡£¡£¡£¡£¡£¡£Õâµ¼Ö¹¥»÷ÕßÄܹ»»á¼ûRedditµÄϵͳ£¬£¬£¬ £¬£¬²¢ÇÔÈ¡ÄÚ²¿Îĵµ¡¢Ô´´úÂë¡¢Ô±¹¤ÐÅÏ¢ÒÔ¼°Óйع«Ë¾¹ã¸æÉ̵ÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£BlackCatÍÅ»ïÌåÏÖ£¬£¬£¬ £¬£¬ËûÃÇÔøÔÚ4ÔÂ13ÈÕºÍ6ÔÂ16ÈÕÁ½´ÎÊÔͼÁªÏµReddit£¬£¬£¬ £¬£¬²¢ÒªÇóÆä½»450ÍòÃÀµÄÊê½ð£¬£¬£¬ £¬£¬µ«Ã»ÓÐÊÕµ½»Ø¸´¡£¡£¡£¡£¡£¡£¡£


https://www.databreaches.net/blackcat-claims-they-hacked-reddit-and-will-leak-the-data/


2¡¢ProgressÐÞ¸´MOVEitÖÐÓÖÒ»¸öSQLiÎó²îCVE-2023-35708  


ýÌå6ÔÂ15Èճƣ¬£¬£¬ £¬£¬Progress SoftwareÐÞ¸´ÁËÆäMOVEit TransferÖеĵÚÈý¸öSQL×¢ÈëÎó²î£¨CVE-2023-35708£©¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾³Æ£¬£¬£¬ £¬£¬ËûÃÇÒѾ­½µµÍÁËMOVEit CloudµÄHTTPsÁ÷Á¿£¬£¬£¬ £¬£¬²¢ÒªÇóÓû§ÔÚ½¨ÉèºÍ²âÊÔ²¹¶¡Ê±½µµÍHTTPºÍHTTPsÁ÷Á¿ÒÔ±£»£»£»¤ËûÃǵÄϵͳ¡£¡£¡£¡£¡£¡£¡£ÔÚ×°Öò¹¶¡Ç°£¬£¬£¬ £¬£¬ProgressÇ¿ÁÒ½¨ÒéÐ޸ķÀ»ðǽ¹æÔòÒԾܾø¶Ë¿Ú80ºÍ443ÉϵÄMOVEit TransferµÄHTTPºÍHTTPsÁ÷Á¿£¬£¬£¬ £¬£¬×÷ΪһÖÖÔÝʱ½â¾öÒªÁì¡£¡£¡£¡£¡£¡£¡£ËùÓÐÓû§¶¼±ØÐèÓ¦ÓÃÔÚ6ÔÂ16ÈÕÐû²¼µÄв¹¶¡¡£¡£¡£¡£¡£¡£¡£Õâ¸öÐÂÎó²îµÄϸ½ÚÉÐδ¹ûÕæ£¬£¬£¬ £¬£¬µ«ÒÑÓÐÑо¿Ö°Ô±Ðû²¼PoC¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/moveit-transfer-customers-warned-of-new-flaw-as-poc-info-surfaces/


3¡¢ÀÕË÷ÍÅ»ïRhysida¹ûÕæ´ÓÖÇÀû¾ü¶ÓµÄϵͳÖÐÇÔÈ¡µÄÎļþ


¾Ý6ÔÂ15ÈÕ±¨µÀ£¬£¬£¬ £¬£¬ÀÕË÷ÍÅ»ïRhysida¹ûÕæÁË´ÓÖÇÀû¾ü¶Ó(Ej¨¦rcito de Chile)µÄϵͳÖÐÇÔÈ¡µÄÎļþ¡£¡£¡£¡£¡£¡£¡£¾ÝÇå¾²¹«Ë¾CronUp³Æ£¬£¬£¬ £¬£¬ÖÇÀû¾ü¶ÓÓÚ5ÔÂ29ÈÕÈ·ÈÏÆäϵͳÊܵ½ÁËÔÚ5ÔÂ27ÈÕ¼ì²âµ½µÄÇå¾²ÊÂÎñµÄÓ°Ï죬£¬£¬ £¬£¬²¿·ÖÊý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÊÂÎñÅû¶µÄ¼¸Ììºó£¬£¬£¬ £¬£¬ÍâµØÃ½Ì屨µÀ³Æ£¬£¬£¬ £¬£¬Ò»Ãû½¾üÏÂÊ¿Òò¼ÓÈëÀÕË÷¹¥»÷¶ø±»²¶¡£¡£¡£¡£¡£¡£¡£RhysidaÏÖÔÚÐû²¼ÁËԼĪ360000·ÝÖÇÀû¾ü¶ÓµÄÎļþ£¨¾Ý³Æ½öÕ¼ËùÓб»µÁÊý¾ÝµÄ30%£©¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/rhysida-ransomware-leaks-documents-stolen-from-chilean-army/


4¡¢Î¢Èí͸¶½üÆÚAzure¡¢OutlookºÍOneDriveÖÐÖ¹Ô´ÓÚDDoS¹¥»÷


6ÔÂ18ÈÕ±¨µÀ³Æ£¬£¬£¬ £¬£¬Î¢Èí͸¶6ÔÂÉÏÑ®ÆäAzure¡¢OutlookºÍOneDriveЧÀÍÖÐÖ¹ÊÇÕë¶Ô¹«Ë¾Ð§À͵ĵÚ7²ãDDoS¹¥»÷µ¼ÖµÄ¡£¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷±»¹éÒòÓÚ΢Èí×·×ÙΪStorm-1359µÄÍŻ£¬£¬ £¬£¬¸ÃÍÅ»ï×Ô³ÆAnonymous Sudan¡£¡£¡£¡£¡£¡£¡£ÕâЩ¹¥»÷¿ÉÄÜÒÀÀµÓÚ»á¼û¶à¸öÐéÄâרÓÃЧÀÍÆ÷(VPS)ÒÔ¼°×âÓõÄÔÆ»ù´¡ÉèÊ©¡¢¿ª·ÅÊðÀíºÍDDoS¹¤¾ß¡£¡£¡£¡£¡£¡£¡£×î³õ£¬£¬£¬ £¬£¬Õâ¼ÒIT¹«Ë¾Ã»ÓÐÌṩÓйØÖÐÖ¹ÊÂÎñµÄÏêϸÐÅÏ¢£¬£¬£¬ £¬£¬µ«ÔÚ6ÔÂ16ÈÕÐû²¼ÁËMicrosoft¶ÔµÚ7²ãDDoS¹¥»÷µÄÏìÓ¦±¨¸æ£¬£¬£¬ £¬£¬Í¸Â¶ÁËÖÐÖ¹µÄÔµ¹ÊÔ­ÓÉ¡£¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/147605/hacking/microsoft-outages-ddos.html


5¡¢Ö´·¨Ðж¯PowerOffµ·»Ù2013Äê×îÏÈ»îÔ¾µÄDDoS³ö×âЧÀÍ


¾Ý6ÔÂ17ÈÕýÌ屨µÀ£¬£¬£¬ £¬£¬¹ú¼ÊÖ´·¨Ðж¯Operation PowerOFFµ·»ÙÁË×Ô2013Äê×îÏÈ»îÔ¾µÄDDoS³ö×âЧÀÍ (ÓÖ³Æbooter»òstresser)¡£¡£¡£¡£¡£¡£¡£DDoS³ö×⣨DDoS-for-hire£©Ð§ÀÍÔÊÐí×¢²áÓû§ÔÚ²»¾ß±¸Ìض¨ÖªÊ¶µÄÇéÐÎÏÂÖ´ÐÐÓÐÐòµÄDDoS¹¥»÷¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬ £¬£¬²¨À¼¾¯·½¾Ð²¶ÁË¸ÃÆ½Ì¨µÄÁ½ÃûÔËÓªÖ°Ô±£¬£¬£¬ £¬£¬²¢´ÓËûÃÇλÓÚÈðÊ¿µÄЧÀÍÆ÷ÖÐÍøÂçµ½ÁËÓмÛÖµµÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£ÓÐÁè¼Ý35000¸öÓû§ÕÊ»§¡¢76000¸öµÇ¼¼Í¼ºÍÁè¼Ý320000¸öÓëDDoS³ö×âЧÀÍÏà¹ØµÄIPµØµãµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£Operation PowerOFFÊÇÒ»Ïîºã¾ÃÖ´ÐеÄÖ´·¨Ðж¯£¬£¬£¬ £¬£¬ÒѹرÕÁËÊýÊ®¸öÖ÷ÒªµÄDDoS³ö×âÆ½Ì¨¡£¡£¡£¡£¡£¡£¡£ 


https://securityaffairs.com/147564/cyber-crime/ddos-for-eye-service-seized.html


6¡¢ESET·¢Ã÷Android¶ñÒâÈí¼þGravityRATÐÂÒ»ÂÖ¹¥»÷»î¶¯


6ÔÂ15ÈÕ£¬£¬£¬ £¬£¬ESETÅû¶ÁËAndroid¶ñÒâÈí¼þGravityRATµÄÐÂÒ»ÂÖ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¸Ã»î¶¯×Ô2022Äê8ÔÂ×îÏÈ»îÔ¾£¬£¬£¬ £¬£¬Ê¹ÓÃľÂí»¯Ì¸ÌìÓ¦ÓÃBingeChatºÍChaticoÑ¬È¾ÒÆ¶¯×°±¸£¬£¬£¬ £¬£¬²¢ÊÔͼ´ÓÄ¿µÄ×°±¸ÖÐÇÔÈ¡Êý¾Ý¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬ £¬£¬Ê¹ÓÃChaticoµÄ»î¶¯ÒѲ»ÔÙ»îÔ¾¡£¡£¡£¡£¡£¡£¡£¶ñÒâÓ¦Óû¹Ìṩ»ùÓÚ¿ªÔ´OMEMO Instant MessengerÓ¦ÓóÌÐòµÄÕýµ±Ì¸Ì칦Ч¡£¡£¡£¡£¡£¡£¡£Õâ¸öа汾µÄGravityRAT¾ßÓÐÁ½¸öй¦Ð§£¬£¬£¬ £¬£¬¿ÉÎüÊÕɾ³ýÎļþµÄÏÂÁîºÍй¶WhatsApp±¸·ÝÎļþ¡£¡£¡£¡£¡£¡£¡£


https://www.welivesecurity.com/2023/06/15/android-gravityrat-goes-after-whatsapp-backups/