Mixin Network±»ºÚËðʧ¸ß´ï2ÒÚÃÀÔª²¢ÔÝÍ£ÔËÓª
Ðû²¼Ê±¼ä 2023-09-261¡¢Mixin Network±»ºÚËðʧ¸ß´ï2ÒÚÃÀÔª²¢ÔÝÍ£ÔËÓª
¾Ý9ÔÂ25ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬Î»ÓÚÖйúÏã¸ÛµÄ¼ÓÃÜÇ®±Ò¹«Ë¾Mixin NetworkÔâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬£¬Ëðʧ¸ß´ï2ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÊÂÎñ±¬·¢ÔÚ9ÔÂ23ÈÕÆÆÏþ£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾Á¬Ã¦ÔÝÍ£ÁË´æ¿îºÍÈ¡¿î¡£¡£¡£¡£¡£¡£¡£¾Ý³Æ¹¥»÷Õß¿ÉÒÔ»á¼ûMixin NetworkÔÆÐ§ÀÍÌṩÉ̵ÄÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬ÇÔÈ¡Ö÷ÍøÉϵIJ¿·Ö×ʲú¡£¡£¡£¡£¡£¡£¡£PeckShieldµÈÇø¿éÁ´×·×ÙÆ÷ÒÑʶ±ð³öÔ¼1.41ÒÚÃÀÔªµÄ±»µÁ×ʲú£¬£¬£¬£¬£¬£¬£¬ÆäÖÐ9350ÍòÃÀԪΪETH£¬£¬£¬£¬£¬£¬£¬2350ÍòÃÀԪΪDAI£¨´ÓUSDT»»À´£©£¬£¬£¬£¬£¬£¬£¬2330ÍòÃÀԪΪBTC¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/mixin-network-suspends-operations-following-200-million-hack/
2¡¢°Ä´óÀûÑÇTissuPathÒò¹©Ó¦É̱»¹¥»÷446 GBÊý¾Ýй¶
¾ÝýÌå9ÔÂ21ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬°Ä´óÀûÑÇרҵ²¡Àíѧ¹«Ë¾TissuPathÔâµ½¹¥»÷µ¼ÖÂÊý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñ±¬·¢ÓÚ8ÔÂ24ÈÕ£¬£¬£¬£¬£¬£¬£¬Ô´ÓÚTissuPathµÄÒ»¼ÒµÚÈý·½¹©Ó¦ÉÌÔâµ½¹©Ó¦Á´¹¥»÷¡£¡£¡£¡£¡£¡£¡£ÊӲ췢Ã÷£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚÔ¶³Ì»á¼û¹¤¾ß°ü(RAT)±£´æÎó²î£¬£¬£¬£¬£¬£¬£¬¹©Ó¦É̵ÄϵͳºÍÓû§ÕÊ»§±»ÈëÇÖ¡£¡£¡£¡£¡£¡£¡£ÕâЩÕýµ±µÄÖÎÀíÔ±ÕË»§±»Ä£Ä⣬£¬£¬£¬£¬£¬£¬ÒÔ½øÈëTissuPathµÄϵͳ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜ»ñµÃÁË2011ÄêÖÁ2020ÄêÏòTissuPath·¢³öµÄ²¡Àíת½é¡£¡£¡£¡£¡£¡£¡£9ÔÂ2ÈÕ£¬£¬£¬£¬£¬£¬£¬AlphVÉù³Æ¶Ô´Ë´Î¹¥»÷ÈÏÕæ£¬£¬£¬£¬£¬£¬£¬²¢ÔÚ9ÔÂ5ÈÕ³Æ446 GBºÍ735414¸öÎļþÒѱ»Ð¹Â¶¡£¡£¡£¡£¡£¡£¡£
https://www.databreaches.net/tissupaths-data-breach-notice-provides-details-about-how-they-were-attacked-and-their-incident-response/
3¡¢Google³ÆAppleºÍChromeÎó²î±»ÓÃÓÚ×°ÖÃPredator
ýÌå9ÔÂ22ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬Google͸¶AppleÔÚÉÏÖÜËÄÐÞ¸´µÄÈý¸öÎó²îÒѱ»ÀÄÓ㬣¬£¬£¬£¬£¬£¬×÷ΪװÖÃÌØ¹¤Èí¼þPredatorµÄÎó²îʹÓÃÁ´µÄÒ»²¿·Ö¡£¡£¡£¡£¡£¡£¡£½ñÄê5ÔÂÖÁ9Ô£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÕâЩÎó²î£¨CVE-2023-41991¡¢CVE-2023-41992ºÍCVE-2023-41993£©£¬£¬£¬£¬£¬£¬£¬Í¨¹ýÓÕ¶ü¶ÌÐźÍWhatsAppÐÂÎÅ£¬£¬£¬£¬£¬£¬£¬Õë¶Ô°£¼°Ç°¹ú¾Û»áÔ±Ahmed EltantawyÖ´Ðй¥»÷¡£¡£¡£¡£¡£¡£¡£Google TAG»¹ÊӲ쵽ChromeÎó²î£¨CVE-2023-4762£©Ò²±»ÓÃÓÚÕë¶Ô°£¼°µÄAndroid×°±¸×°ÖÃPredator¡£¡£¡£¡£¡£¡£¡£Apple³ÆiOSËø¶¨Ä£Ê½¿ÉÒÔ·ÀÓù´ËÀ๥»÷¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/recently-patched-apple-chrome-zero-days-exploited-in-spyware-attacks/
4¡¢Akamai·¢Ã÷ʹÓÃÐéαBookingÍøÕ¾µÄÖØ´ó´¹Âڻ
AkamaiÔÚ9ÔÂ21ÈճƷ¢Ã÷ÁËÕë¶ÔÂùÝÐÐÒµµÄÖØ´óµÄ´¹Âڻ¡£¡£¡£¡£¡£¡£¡£ÔÚÔʼĿµÄ£¨Âùݣ©ÉÏÖ´ÐÐÐÅÏ¢ÇÔÈ¡³ÌÐòºó£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ»á¼ûÓë¿Í»§Ö®¼äµÄÐÂÎÅ¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÓë×îÖÕÄ¿µÄÖ®¼ä½¨Éè¿ÉÐŵÄͨѶÇþµÀºó£¬£¬£¬£¬£¬£¬£¬¾Íαװ³ÉÂùݡ¢Ô¤¶©Ð§ÀÍ»òÂÃÐÐÉç·¢ËÍ´¹ÂÚÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÒªÇó¾ÙÐÐÌØÁíÍâÐÅÓÿ¨ÑéÖ¤¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹½ÓÄÉÁ˶àÖÖÇå¾²ÑéÖ¤ºÍ·´ÆÊÎöÊÖÒÕ£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÄ¿µÄͨ¹ýÕâЩ²âÊÔ£¬£¬£¬£¬£¬£¬£¬½«»á¿´µ½Ò»¸öαװ³ÉBooking.com¸¶¿îÒ³ÃæµÄ´¹ÂÚÍøÕ¾£¬£¬£¬£¬£¬£¬£¬ÇëÇóÐÅÓÿ¨ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹ÔöÌíÁËÖÇÄÜ̸ÌìÖ§³ÖÇþµÀ£¬£¬£¬£¬£¬£¬£¬ÒÔÈ·±£´¹ÂڻµÄ¿ÉÐŶȡ£¡£¡£¡£¡£¡£¡£
https://www.akamai.com/blog/security-research/sophisticated-phishing-campaign-targeting-hospitality
5¡¢ESETÅû¶OilRigÕë¶ÔÒÔÉ«ÁеÄÁ½´Î¹¥»÷»î¶¯µÄϸ½Ú
9ÔÂ22ÈÕ£¬£¬£¬£¬£¬£¬£¬ESETÅû¶ÁËOilRigÕë¶ÔÒÔÉ«ÁÐʵÌåµÄÁ½´Î¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬£¬¼´Outer Space(2021Äê)ºÍJuicy Mix(2022Äê)¡£¡£¡£¡£¡£¡£¡£ÕâÁ½´Î¹¥»÷»î¶¯Ê¹ÓÃÁËÏàͬµÄÕ½ÂÔ£ºOilRigÊ×ÏÈÈëÇÖÒ»¸öÕýµ±ÍøÕ¾ÓÃ×÷C&CЧÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬È»ºóʹÓÃVBS droppers·Ö·¢C# /.NETºóÃÅ£¬£¬£¬£¬£¬£¬£¬Í¬Ê±»¹°²ÅÅÁËÖÖÖÖÓÃÓÚÔÚÄ¿µÄϵͳÉϾÙÐÐÊý¾Ýй¶µÄ¹¤¾ß¡£¡£¡£¡£¡£¡£¡£Outer Space»î¶¯Ê¹ÓÃÁËеĺóÃÅSolarºÍеÄÏÂÔØ³ÌÐòSampleCheck5000£¨»òSC5k£©£¬£¬£¬£¬£¬£¬£¬Juicy Mix»î¶¯¶ÔSolar¾ÙÐÐˢв¢½¨ÉèÁ˺óÃÅMango¡£¡£¡£¡£¡£¡£¡£
https://www.welivesecurity.com/en/eset-research/oilrigs-outer-space-juicy-mix-same-ol-rig-new-drill-pipes/
6¡¢KasperskyÐû²¼2023ÄêÉϰëÄêÎïÁªÍøÍþвµÄÆÊÎö±¨¸æ
9ÔÂ21ÈÕ£¬£¬£¬£¬£¬£¬£¬KasperskyÐû²¼ÁË2023ÄêÉϰëÄêÎïÁªÍøÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£ÎïÁªÍøÑ¬È¾Í¾¾¶Ö÷ÒªÊDZ©Á¦ÆÆ½âºÍʹÓÃÍøÂçЧÀÍÖеÄÎó²î¡£¡£¡£¡£¡£¡£¡£Ã۹޼ͼÏÔʾ£¬£¬£¬£¬£¬£¬£¬2023ÄêÉϰëÄê97.91%µÄ±©Á¦ÆÆ½âʵÑ鼯ÖÐÔÚTelnetÉÏ£¬£¬£¬£¬£¬£¬£¬½ö2.09%Õë¶ÔSSH¡£¡£¡£¡£¡£¡£¡£2023ÄêÉϰëÄ꣬£¬£¬£¬£¬£¬£¬ÖÖÖÖ°µÍøÉÏ×ܹ²Ðû²¼ÁË700¶àÌõÕë¶ÔDDoS¹¥»÷ЧÀÍµÄ¹ã¸æ¡£¡£¡£¡£¡£¡£¡£ÔÚIoT¶ñÒâÈí¼þÁìÓò±£´æ´ó×Ú±äÌ壬£¬£¬£¬£¬£¬£¬ÆäÖÐÐí¶àÔ´×Ô2016 Mira¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£Ð®ÖÆ×°±¸²¢Ê¹ÓÃËüÌᳫÕë¶ÔÖÖÖÖЧÀ͵ÄDoS¹¥»÷µÄľÂíÊÇ×î³£¼ûµÄIoT¶ñÒâÈí¼þÀàÐÍ¡£¡£¡£¡£¡£¡£¡£
https://securelist.com/iot-threat-report-2023/110644/


¾©¹«Íø°²±¸11010802024551ºÅ