Brunswick CorporationÔâµ½¹¥»÷Ëðʧ¸ß´ï8500ÍòÃÀÔª
Ðû²¼Ê±¼ä 2023-08-041¡¢Brunswick CorporationÔâµ½¹¥»÷Ëðʧ¸ß´ï8500ÍòÃÀÔª
¾ÝýÌå8ÔÂ3ÈÕ±¨µÀ£¬´¬²°ÖÆÔ칫˾Brunswick CorporationÔâµ½ÍøÂç¹¥»÷£¬Ëðʧ¸ß´ï8500ÍòÃÀÔª¡£¸Ã¹«Ë¾2021ÄêÊÕÈë½ü60ÒÚÃÀÔª£¬ÓªÒµÆÕ±é24¸ö¹ú¼Ò¡£¹¥»÷±¬·¢ÔÚ6ÔÂ13ÈÕ£¬Ó°ÏìÁ˸ù«Ë¾µÄϵͳºÍ²¿·ÖÉèÊ©¡£ÉÐδ֤ʵÕâÊÇÀÕË÷¹¥»÷£¬µ«¸Ã¹«Ë¾ÌåÏÖÆäÔÚijЩµØ·½µÄÔËÓª±»ÆÈ×èÖ¹¡£¸Ã¹«Ë¾CEO͸¶£¬´Ë´ÎÇå¾²ÊÂÎñ¶Ô¹«Ë¾µÚ¶þ¼¾¶ÈµÄ²ÆÎñ×é³ÉÁËɱ¾øÐÔÓ°Ï죬Ôâµ½¹¥»÷ºóÆ仨Á˾ÅÌìµÄʱ¼ä²Å»Ö¸´Õý³£ÔËÓª¡£´Ë´ÎÖÐÖ¹Ö÷ÒªÓ°ÏìÁËÍƽøÆ÷ºÍ·¢ÄîÍ·ÁãÅä¼þÁìÓò£¬ÓÉÓÚÁÚ½ü¼¾¶ÈÄ©£¬Í¬ÆÚÄÚÍêÈ«»Ö¸´µÄʱ»úÓÐÏÞ¡£
https://therecord.media/marine-industry-giant-brunswick-lost-millions
2¡¢MicrosoftÅû¶NobeliumʹÓÃTeamsÐÂÎŵĴ¹ÂÚ¹¥»÷Ô˶¯
MicrosoftÔÚ8ÔÂ2ÈÕÅû¶Á˽üÆÚ¶íÂÞ˹ºÚ¿ÍÍÅ»ïNobelium£¨APT29£©ÓÐÕë¶ÔÐԵĴ¹ÂÚ¹¥»÷Ô˶¯¡£¸ÃÔ˶¯´Ó5ÔÂÏÂÑ®×îÏÈ£¬Ó°ÏìÁ˲»µ½40¸öÆóÒµ£¬Éæ¼°Õþ¸®¡¢·ÇÕþ¸®×éÖ¯(NGO)¡¢IT·þÎñ¡¢ÊÖÒÕ¡¢ÖÆÔìºÍýÌåÐÐÒµ¡£ÔÚ´Ë´ÎÔ˶¯ÖУ¬¹¥»÷ÕßʹÓÃÇÔÈ¡µÄMicrosoft 365×⻧À´½¨ÉèеÄÓò£¬ÕâЩÓòÃû¿´ÆðÀ´ÏñÊÇÊÖÒÕÖ§³ÖʵÌ塣ȻºóʹÓÃTeamsÐÂÎÅ·¢ËÍÓÕ¶ü£¬ÓÕʹĿµÄÓû§Åú×¼¶àÒòËØÉí·ÝÑéÖ¤£¨MFA£©£¬×îÖÕÖ¼ÔÚÇÔÈ¡Ä¿µÄ×éÖ¯µÄƾ֤¡£
https://www.microsoft.com/en-us/security/blog/2023/08/02/midnight-blizzard-conducts-targeted-social-engineering-over-microsoft-teams/
3¡¢ºº±¤Íõ·¨¹ú·Ö¹«Ë¾ÒòÍøÕ¾ÉèÖùýʧµ¼ÖÂƾ֤µÈÐÅϢй¶
ýÌå8ÔÂ3Èճƣ¬ºº±¤Íõ·¨¹ú·Ö¹«Ë¾ÒòÍøÕ¾ÉèÖùýʧ£¬µ¼ÖÂƾ֤µÈÐÅϢй¶¡£6ÔÂ1ÈÕ£¬Ñо¿ÍŶӷ¢Ã÷ÁËÊôÓÚºº±¤Íõ·¨¹úÍøÕ¾µÄ¿É¹ûÕæ»á¼ûµÄÇéÐÎÎļþ(.env)£¬ÆäÖаüÀ¨ÖÖÖÖƾ֤£¬¸ÃÎļþÍйÜÔÚÓÃÓÚÐû²¼ÊÂÇéʱ»úµÄ×ÓÓòÉÏ¡£Ö»¹Ü鶵ÄÊý¾Ýȱ·¦ÒÔÍêÈ«¿ØÖÆÍøÕ¾£¬µ«Ëü¿ÉÒÔ¼ò»¯¹¥»÷ÕßЮÖÆÍøÕ¾µÄÀú³Ì¡£ÏÖÔÚ£¬¸Ã¹«Ë¾ÒѾ½â¾öÁËÕâ¸öÎÊÌâ¡£2019Ä꣬ÓÉÓÚÀàËƵÄÉèÖùýʧ£¬·¨¹ú·Ö¹«Ë¾Ôøй¶Á˹ºÖúº±¤ÍõµÄ¶ùͯµÄPIIÐÅÏ¢¡£
https://cybernews.com/security/burger-king-data-leak/
4¡¢NoName057(16)Éù³Æ¶ÔÒâ´óÀû¶à¼ÒÒøÐÐÔâµ½µÄ¹¥»÷ÈÏÕæ
¾Ý8ÔÂ3ÈÕ±¨µÀ£¬ºÚ¿ÍÍÅ»ïNoName057(16)Éù³Æ¶ÔÒâ´óÀûÒøÐС¢ÆóÒµºÍÕþ¸®»ú¹¹µÄ¹¥»÷ÈÏÕæ¡£Òâ´óÀûÍøÂçÇå¾²»ú¹¹ÔÚ±¾ÖܶþÌåÏÖ£¬ÒѼì²âµ½ÖÁÉÙÎå¼ÒÒøÐеÄÍøÕ¾Ôâµ½DDoS¹¥»÷£¬ÆäÖаüÀ¨Òâ´óÀû×î´óµÄÍŽáÊ¥±£ÂÞÒøÐС£NoName057(16)ÓÚ±¾ÖÜÒ»Ê״ζÔÒâ´óÀûÌᳫ¹¥»÷£¬²¢ÓÚ8ÔÂ3ÈÕ¼ÌÐø¡£³ýÁËÒøÐÐÖ®Í⣬¸ÃÍŻﻹÉù³ÆÈëÇÖÁËÒ»¼ÒÒâ´óÀû¹©Ë®¹«Ë¾¡¢Ò»¼ÒÌìÏÂÐÔÉÌÒµ±¨Ö½ºÍÒ»¸ö¹«¹²½»Í¨µÄÍøÕ¾¡£×èÖ¹ÏÖÔÚ£¬ÕâЩÍøÕ¾ÈÔ´¦ÓڹرÕ״̬¡£
https://therecord.media/russian-hackers-claim-attacks-on-italy
5¡¢ºÚ¿ÍʹÓÃCVE-2023-3519ÔÚÊý°Ų̀Citrix·þÎñÆ÷×°ÖúóÃÅ
8ÔÂ2ÈÕ±¨µÀ³Æ£¬Shadowserver Foundation·¢Ã÷Êý°Ų̀Citrix Netscaler ADCºÍGateway·þÎñÆ÷±»ÈëÇÖ²¢×°ÖúóÃÅ¡£CISA½üÆÚÐû²¼Í¨¸æ³Æ£¬¹¥»÷ÕßÕýÔÚʹÓÃRCEÎó²î£¨CVE-2023-3519£©ÔÚÒ×±»¹¥»÷µÄϵͳÖÐ×°ÖÃWeb shell¡£Shadowserver×î³õ±¨¸æ£¬ÖÁÉÙÓÐ15000̨·þÎñÆ÷Ò×±»¹¥»÷£¬Ö÷ҪλÓÚÃÀ¹úºÍµÂ¹ú¡£×îиüÐÂÖÐÏÔʾ£¬×èÖ¹8ÔÂ1ÈÕ£¬¹¥»÷ÕßÒÑÔÚÖÁÉÙ581̨Citrix·þÎñÆ÷ÉÏ×°ÖÃÁËWebshell¡£CitrixÇ¿ÁÒ½¨ÒéÓû§×°ÖøüС£
https://securityaffairs.com/149083/hacking/phishing-facebook-campaign-salesforce-zero-day.html
6¡¢Group-IBÐû²¼Mysterious Team BangladeshµÄÆÊÎö±¨¸æ
8ÔÂ3ÈÕ£¬Group-IBÐû²¼Á˹ØÓÚºÚ¿ÍÍÅ»ïMysterious Team BangladeshµÄÆÊÎö±¨¸æ¡£¸ÃÍŻィÉèÓÚ2020Ä꣬×Ô2022Äê6ÔÂÒÔÀ´£¬ÒÑÖ´ÐÐÁËÁè¼Ý750´ÎDDoS¹¥»÷ºÍ78´ÎÍøÕ¾¸Ä¶¯¹¥»÷£¬ÆäÊ×´´ÈËÊÇÔÚTelegramÉÏÒ»Ãû´úºÅΪD4RK_TSNµÄÓû§¡£¸ÃÍÅ»ïÖ÷ÒªÕë¶ÔÓ¡¶ÈºÍÒÔÉ«ÁеÄÎïÁ÷¡¢Õþ¸®ºÍ½ðÈÚÐÐÒµ¡£ÔÚÈ«Á¦¹¥»÷֮ǰ£¬Æä»á¾ÙÐжÌÔݵIJâÊÔ¹¥»÷£¬ÒÔ¼ì²éÄ¿µÄ¶ÔDDoS¹¥»÷µÄ·ÀÓùÄÜÁ¦¡£ÔÚijЩÇéÐÎÏ£¬¸ÃÍÅ»ï¿ÉÄÜͨ¹ýʹÓÃÒÑÖªµÄÎó²î»òÇå¾²ÐԽϲîµÄÃÜÂëÀ´»á¼ûÍøÂç·þÎñÆ÷ºÍÖÎÀíÃæ°å¡£
https://www.group-ib.com/blog/mysterious-team-bangladesh/