ÈÕ±¾SeikoÔâµ½BlackCat¹¥»÷Éè¼ÆͼµÈÊý¾Ý¿ÉÄÜй¶
Ðû²¼Ê±¼ä 2023-08-231¡¢ÈÕ±¾SeikoÔâµ½BlackCat¹¥»÷Éè¼ÆͼµÈÊý¾Ý¿ÉÄÜй¶
¾ÝýÌå8ÔÂ21ÈÕ±¨µÀ£¬ÀÕË÷ÍÅ»ïBlackCatÉù³Æ¶ÔÈÕ±¾ÖÓ±íÖÆÔìÉ̾«¹¤£¨Seiko£©Ôâµ½µÄ¹¥»÷ÈÏÕæ¡£SeikoÊÇÌìÏÂÉÏ×î´óÇÒÀúÊ·×îÓƾõÄÖƱíÉÌÖ®Ò»£¬ÄêÊÕÈëÁè¼Ý16ÒÚÃÀÔª¡£¸Ã¹«Ë¾ÔÚ8ÔÂ10ÈÕ͸¶£¬Î´¾ÊÚȨµÄµÚÈý·½»á¼ûÆä»ù´¡ÉèÊ©²¢¿ÉÄÜÇÔÈ¡ÁËÊý¾Ý¡£21ÈÕ£¬BlackCat³Æ¶Ô´ËÊÂÈÏÕ棬ÌåÏÖSeikoµÄÍøÂçºÍ²úÆ·µÄÇå¾²ÐԽϵ͡£¹¥»÷Õßй¶ÁËÉú²úÍýÏë¡¢Ô±¹¤»¤ÕÕ¡¢ÐÂÐͺÅÐû²¼ÍýÏëºÍʵÑéÊÒ²âÊÔЧ¹ûµÈÄÚÈÝ£¬Ñù±¾»¹°üÀ¨ÊÖÒÕÔÀíͼºÍ¾«¹¤ÊÖ±íÉè¼Æͼֽ¡£Éв»ÇåÎúºÚ¿ÍÊÇ·ñÇÔÈ¡Á˹«Ë¾ÉñÃØ»òרÀûµÈ֪ʶ²úȨ¡£
https://securityaffairs.com/149734/cyber-crime/blackcat-alphv-ransomware-group-seiko.html
2¡¢Ñо¿Ö°Ô±·¢Ã÷¿Éͨ¹ýTP-LinkÖÇÄܵƵ¨ÇÔÈ¡WiFiÃÜÂë
ýÌå8ÔÂ21ÈÕ±¨µÀ³Æ£¬Ñо¿Ö°Ô±ÔÚTP-Link Tapo L530EÖÇÄܵƵ¨ºÍTP-Link TapoÓ¦ÓóÌÐòÖз¢Ã÷ÁË4¸öÎó²î¡£µÚÒ»¸öÎó²îÉæ¼°Tapo L503EÉí·ÝÑéÖ¤²»µ±£¬¿ÉÔڻỰÃÜÔ¿½»Á÷°ì·¨ÖÐð³ä×°±¸¡£µÚ¶þ¸öÎó²î¿Éͨ¹ý±©Á¦Æƽâ»ò·´±àÒëTapoÓ¦ÓóÌÐòÀ´»ñÈ¡¸ÃÃÜÔ¿¡£µÚÈý¸öÎó²îÉæ¼°¶Ô³Æ¼ÓÃÜÀú³ÌÖÐȱ·¦Ëæ»úÐÔ£¬µÚËĸöÎó²î¿ÉÓÃÓÚÖØ·ÅÐÂÎÅ¡£¹¥»÷Õß¿ÉʹÓõÚÒ»¸öºÍµÚ¶þ¸öÎó²îð³äµÆµ¨²¢¼ìË÷TapoÕÊ»§ÏêϸÐÅÏ¢£¬È»ºóͨ¹ý»á¼ûTapoÓ¦Ó㬿ÉÒÔÌáÈ¡Ä¿µÄµÄWiFi SSIDºÍÃÜÂ룬²¢»á¼ûÅþÁ¬µ½¸ÃÍøÂçµÄÆäËü×°±¸¡£¹©Ó¦ÉÌÌåÏÖ½«ºÜ¿ì¶ÔÓ¦Óú͵Ƶ¨¹Ì¼þ¾ÙÐÐÐÞ¸´¡£
https://www.bleepingcomputer.com/news/security/tp-link-smart-bulbs-can-let-hackers-steal-your-wifi-password/
3¡¢MFAÌṩÉÌDuo·þÎñÖÐÖ¹µ¼ÖÂAzure AuthÉí·ÝÑéÖ¤¹ýʧ
¾Ý8ÔÂ21ÈÕ±¨µÀ£¬CiscoÆìϵÄMFAÌṩÉÌDuo Security·þÎñÖÐÖ¹ÊýСʱ£¬µ¼ÖÂAzure AuthÉí·ÝÑéÖ¤¹ýʧ¡£ÊµÑéʹÓÃDuoµÇ¼ʱ»á·ºÆð¡°ÏµÍ³¸ºÔعýÖØ£¬ÇëÉԵȼ¸·ÖÖÓ£¬È»ºóÖØÊÔ¡±µÄÌáÐÑ¡£Æ¾Ö¤¸Ã¹«Ë¾µÄ״̬ҳÃ棬DuoµÄSSOºÍÍÆËÍ·þÎñÊܵ½´Ë¹ÊÕϵÄÓ°Ï죬Æä½¹µãÉí·ÝÑéÖ¤·þÎñʹÓõÄHTTPS£¨TCP/443£©ºÍLDAP(S)£¨TCP/389£©¶Ëµã½öÊܵ½²¿·ÖÖÐÖ¹µÄÓ°Ïì¡£×èÖ¹21ÈÕ18:01£¬ÔÚÖÐÖ¹½ü9¸öСʱºó£¬DuoÌåÏÖÉí·ÝÑé֤ʧ°ÜµÄ»ù´¡ÎÊÌâÒѾ½â¾ö¡£
https://www.bleepingcomputer.com/news/technology/ongoing-duo-outage-causes-azure-auth-authentication-errors/
4¡¢·¨¹úÈøÌØ³ά¶ûÊÐÔâµ½MedusaµÄ¹¥»÷ÏÖÔÚÈÔÔÚ»Ö¸´ÖÐ
ýÌå8ÔÂ22Èճƣ¬·¨¹úÈøÌØ³ά¶ûÊÐÕý´ÓÉÏÖܵÄÍøÂç¹¥»÷ÖÐÖð²½»Ö¸´¡£¹¥»÷±¬·¢ÓÚ8ÔÂ17ÈÕ£¬Õë¶ÔÊÐÕþÌüµÄ²¿·Ö·þÎñÆ÷¡£¸ÃÊÐûÓÐ˵Ã÷ÊÇ·ñÊÇÀÕË÷¹¥»÷£¬µ«ÌåÏÖËûÃǵı¸·ÝϵͳʹÆäÄܹ»¼ÓËÙ»Ö¸´Àú³Ì¡£Medusa³Æ¶Ô´Ë´Î¹¥»÷ÈÏÕ棬²¢Í¸Â¶Æä»ñµÃÁ˸ÃÊеIJÆÎñÐÅÏ¢¡¢Ô¤Ëã¡¢ÒøÐÐÏêϸÐÅÏ¢¡¢Ò½ÁƼͼºÍÍâµØѧУµÄÊý¾Ý¡£×îÏȱ¨µÀÕâÒ»ÊÂÎñµÄLe ParisienҲ֤ʵ£¬ÊÐÕþÔ±¹¤ÔÚËûÃǵÄϵͳÉÏ·¢Ã÷ÁËMedusaÀÕË÷Èí¼þ¡£
https://therecord.media/french-town-hit-by-cyberattack
5¡¢¶ò¹Ï¶à¶û¹ú¼ÒÑ¡¾Ù»ú¹¹±»¹¥»÷µ¼ÖÂÔÚÏßͶƱ·ºÆðÎÊÌâ
¾Ý8ÔÂ21ÈÕ±¨µÀ£¬¶ò¹Ï¶à¶û¹ú¼ÒÑ¡¾Ù»ú¹¹±»¹¥»÷£¬µ¼ÖÂסÔÚÍâÑóµÄ¹«ÃñÔÚÌìÏÂÑ¡¾ÙÖÐÎÞ·¨Í¶Æ±¡£¶ò¹Ï¶à¶ûÔÚÉÏÖÜÈÕ¾ÙÐÐÁËÌìÏÂÑ¡¾Ù£¬Í¶Æ±µ±Ì죬ȱϯѡÃñÓ¿ÈëÉ罻ýÌåƽ̨£¬ÌåÏÖËûÃÇÎÞ·¨Í¨¹ýÕþ¸®¿ª·¢µÄÔÚÏßϵͳͶƱ¡£ÌìÏÂÑ¡¾ÙίԱ»áÖ÷ϯ½«¸ÃÎÊÌâ¹é×ïÓÚÍøÂç¹¥»÷£¬µ«Ã»ÓÐ͸¶¹¥»÷µÄÐÔ×Ó¡£»¹ÌåÏÖ£¬Ô¶³ÌÐÅÏ¢´¦Öóͷ£Í¶Æ±Æ½Ì¨Ôâµ½ÁËÀ´×ÔÓ¡¶È¡¢ÃϼÓÀ¹úºÍ°Í»ù˹̹µÈ7¸ö¹ú¼ÒµÄ¹¥»÷£¬Å·ÖÞÑ¡ÃñÊܵ½µÄÓ°ÏìÓÈΪÑÏÖØ¡£
https://therecord.media/ecuador-election-cyberattacks-absen
6¡¢SentinelOneÐû²¼XLoaderµÄmacOSбäÌåµÄÆÊÎö±¨¸æ
8ÔÂ21ÈÕ£¬SentinelOneÐû²¼Á˹ØÓÚXLoaderµÄmacOSбäÌåµÄÆÊÎö±¨¸æ¡£XLoaderÊÇÒ»ÖÖMaaSÇÔÈ¡³ÌÐòºÍ½©Ê¬ÍøÂ磬×Ô2015ÄêÒÔÀ´Ò»Ö±±£´æ¡£Ð°汾µÄXLoaderαװ³É°ì¹«Éú²úÁ¦Ó¦ÓÃOfficeNote£¬À¦°óÔÚApple´ÅÅ̾µÏñOfficeNote.dmgÖУ¬Ê¹ÓÃÁËApple¿ª·¢Ö°Ô±µÄÊðÃû¡£ÊðÃûÓÚ7ÔÂ17ÈÕÇ©Êð£¬Øʺó±»Apple×÷·Ï¡£ÔÀ´µÄmacOS±äÌåÐèÒªJavaÔËÐÐʱÇéÐΣ¬µ«AppleÊ®¶àÄêÇ°¾Í×èÖ¹ÔÚMacÉÏÌṩJRE£¬Òò´Ëа汾Çл»µ½ÁËCºÍObjective CÀ´Ó¦¶Ô´ËÏÞÖÆ¡£
https://www.sentinelone.com/blog/xloaders-latest-trick-new-macos-variant-disguised-as-signed-officenote-app/