MongoDB¹«Ë¾¼ì²âµ½Æäϵͳ±»ºÚ²¿·Ö¿Í»§µÄÐÅϢй¶
Ðû²¼Ê±¼ä 2023-12-18¾ÝýÌå12ÔÂ17ÈÕ±¨µÀ£¬ÃÀ¹úÊý¾Ý¿âÈí¼þ¹«Ë¾MongoDBÔâµ½¹¥»÷£¬²¿·Ö¿Í»§µÄÐÅÏ¢¿ÉÄÜй¶¡£¸Ã¹«Ë¾ÌåÏÖ£¬ËûÃÇÔÚ12ÔÂ13ÈÕÍíÉϼì²âµ½Æäϵͳ±»ºÚ¿Í¹¥»÷£¬²¢×îÏÈÊÓ²ìÕâÆðÊÂÎñ¡£ÕâÖÖδ¾ÊÚȨµÄ»á¼ûÔÚ±»·¢Ã÷֮ǰÒѾһÁ¬ÁËÒ»¶Îʱ¼ä£¬¿Í»§ÕÊ»§ÔªÊý¾ÝºÍÁªÏµÐÅÏ¢ÒѾй¶£¬¿ÉÊÇMongoDB AtlasÖд洢µÄ¿Í»§Êý¾ÝûÓб»»á¼û¡£16ÈÕÏÂÖç5:25µÄºóÐø¸üÐÂÖУ¬MongoDB±¨¸æ³ÆµÇ¼ʵÑ鼤Ôö£¬µ¼Ö»á¼ûMongoDB AtlasºÍSupport PortalµÄ¿Í»§Óöµ½ÎÊÌâ¡£²»¹ýËûÖ¸³öÕâÓëÇå¾²ÊÂÎñÎ޹أ¬²¢½¨ÒéÓû§ÔÚ¼¸·ÖÖÓºóÔÙ´ÎʵÑé¡£
https://thehackernews.com/2023/12/mongodb-suffers-security-breach.html
2¡¢¼ÓÖÝDelta DentalÅû¶Éæ¼°½ü700Íò¿Í»§µÄй¶ÊÂÎñ
¾Ý12ÔÂ15ÈÕ±¨µÀ£¬¼ÓÖÝÑÀ¿Æ°ü¹ÜÌṩÉÌDelta Dental½ü700Íò»¼ÕßµÄÐÅϢй¶¡£¸Ã¹«Ë¾Îª15¸öÖݵÄ4500ÍòÈËÌṩ°ü¹Ü£¬Ð¹Â¶ÊÂÎñÔ´ÓÚMOVEit TransferÈí¼þÖеÄÎó²î¡£Delta DentalÓÚ6ÔÂ1ÈÕ»ñϤ¸ÃÎó²î£¬ÎåÌìºó£¬¾ÓÉÄÚ²¿ÊӲ죬ȷÈÏδ¾ÊÚȨµÄ¹¥»÷ÕßÔÚ5ÔÂ27ÈÕÖÁ5ÔÂ30ÈÕ»á¼û²¢ÇÔÈ¡ÁËÆäϵͳÖеÄÊý¾Ý¡£µÚ¶þ´ÎÊÓ²ìÓÚ11ÔÂ27ÈÕÍê³É£¬ÒÔÈ·¶¨ÊÂÎñµÄÓ°Ïì¹æÄ£¡£¾ÝϤ£¬×èÖ¹ÏÖÔÚ£¬¹²6928932Ãû¿Í»§Êܵ½Ó°Ï죬Éæ¼°ÐÕÃû²ÆÎñÕʺš¢ÐÅÓÿ¨/½è¼Ç¿¨ºÅ¼°Çå¾²´úÂë¡£
https://www.hackread.com/delta-dental-data-breach-moveit-linked-attack/
3¡¢ÔÆ´æ´¢ÌṩÉÌBox±¬·¢ÖÐÖ¹Óû§ÎÞ·¨»á¼û´æ´¢µÄÎļþ
ýÌå12ÔÂ15Èճƣ¬ÔÆ´æ´¢ÌṩÉÌBox±¬·¢ÖÐÖ¹£¬¿Í»§ÔÝʱÎÞ·¨»á¼û´æ´¢µÄÎļþ¡£ÖÐÖ¹×îÏÈÓÚ15ÈÕÉÏÎç9µã×óÓÒ£¬Ó°ÏìÁ˵Ǽ¡¢ÉÏ´«¡¢ÏÂÔغÍAPIŲÓá£ÊµÑéʹÓÃBoxµÄÓû§¿ÉÄܻῴµ½¹ýʧºÍ³¬Ê±£¬µ«´ó´ó¶¼ÇéÐÎÏ·þÎñ½«ÍêÈ«ÎÞ·¨»á¼û¡£µ±Óû§ÊµÑéµÇ¼»ò»á¼û¸Ã·þÎñʱ£¬»áÓöµ½HTTP¹ýʧ503£¬Ö¸³ö¡°´ËÒ³ÃæÎÞ·¨Õý³£ÊÂÇé¡£account.box.comÏÖÔÚÎÞ·¨´¦Öóͷ£´ËÇëÇ󡣡±×èÖ¹12ÔÂ15ÈÕÏÂÖç1:21£¬BoxÌåÏÖÒÑÐÞ¸´¸ÃÎÊÌ⣬¿Í»§¿ÉÒÔÔٴλá¼ûÔÆ·þÎñ¡£
https://www.bleepingcomputer.com/news/technology/box-cloud-storage-down-amid-critical-outage/
4¡¢Ã°³äWPÍйÜÉÌKinstaµÄ´¹ÂÚÔ˶¯Ö¼ÔÚÇÔÈ¡MyKinstaƾ֤
12ÔÂ17ÈÕ±¨µÀ³Æ£¬WordPressÍйÜÌṩÉÌKinsta·¢Ã÷ÁËʹÓÃGoogle AdµÄ´¹ÂÚÔ˶¯£¬Ö¼ÔÚÇÔÈ¡ÆäÍйÜƾ֤¡£KinstaÌåÏÖ£¬¹¥»÷ÕßʹÓÃGoogle Ads£¬Õë¶ÔÒÔÇ°»á¼û¹ýKinsta¹Ù·½ÍøÕ¾µÄСÎÒ˽¼Ò¡£ÕâЩ¹¥»÷Õß½¨ÉèÁËÓëKinstaºÜÊÇÏàËƵÄÍøÕ¾£¬À´ÓÕÆÓû§µã»÷ËüÃÇ£¬×îÖÕ»áÍøÂçMyKinstaµÇ¼ƾ֤¡£ÎªÁËÓ¦¶ÔÕâЩÍþв£¬KinstaÕýÔÚÆð¾¢Ê¶±ð²¢¹Ø±Õ´¹ÂÚÍøÕ¾£¬µ«½¨ÒéÓû§½ÓÄÉ×Ô¶¯²½·¥À´±£»¤×Ô¼ºµÄÕÊ»§¡£
https://www.bleepingcomputer.com/news/security/wordpress-hosting-service-kinsta-targeted-by-google-phishing-ads/
5¡¢Kaspersky·¢Ã÷ʹÓÃNKNÐÒéµÄ¶àƽ̨¶ñÒâÈí¼þNKAbuse
KasperskyÔÚ12ÔÂ14ÈÕ³ÆÆä·¢Ã÷ÁËÒ»ÖÖÃûΪNKAbuseµÄÐÂÐͶàƽ̨¶ñÒâÈí¼þ¡£Ëü½ÓÄÉGoÓïÑÔ¿ª·¢£¬ÊǵÚÒ»¸öÒÀÀµNKNÊÖÒÕÔÚ½ÚµãÖ®¼ä¾ÙÐÐÊý¾Ý½»Á÷µÄ¶ñÒâÈí¼þ¡£¶ñÒâÈí¼þ³äµ±Ö²Èë³ÌÐò£¬²¢Å䱸ºéË®¹¥»÷ºÍºóÃŹ¦Ð§£¬¿ÉÒÔÌìÉúÓëÖÖÖּܹ¹¼æÈݵĶþ½øÖÆÎļþ¡£ÆÊÎöÅú×¢NKAbuseÖ÷ÒªÕë¶ÔLinux×ÀÃ棬µ«¼øÓÚÆäѬȾMISPºÍARMϵͳµÄÄÜÁ¦£¬Ò²¶ÔÎïÁªÍø×°±¸×é³ÉÁËÍþв¡£Ò£²âÊý¾ÝÏÔʾ£¬¸çÂ×±ÈÑÇ¡¢Ä«Î÷¸çºÍÔ½ÄÏÒÑ·ºÆð±»¹¥»÷Ä¿µÄ¡£
https://securelist.com/unveiling-nkabuse/111512/
6¡¢ZimperiumÐû²¼2023ÄêÊÖ»úÒøÐжñÒâÈí¼þµÄÆÊÎö±¨¸æ
12ÔÂ14ÈÕ£¬ZimperiumÐû²¼ÁË2023ÄêÊÖ»úÒøÐжñÒâÈí¼þµÄÆÊÎö±¨¸æ¡£±¨¸æÖ¸³ö£¬½ñÄê·ºÆðÁË10¸öеÄAndroidÒøÐжñÒâÈí¼þ¼Ò×壬Õë¶Ô61¸ö¹ú¼Ò/µØÇø½ðÈÚ»ú¹¹µÄ985¸öÒøÐкͽðÈڿƼ¼/ÉúÒâÓ¦ÓᣳýÁËÕâ10¸öÐÂľÂíÖ®Í⣬2022ÄêµÄ19¸öľÂí¼Ò×åÒ²¾ÙÐÐÁËÐ޸ġ£½ñÄêÔÚÒøÐжñÒâÈí¼þÖÐÊӲ쵽µÄй¦Ð§°üÀ¨£º×Ô¶¯×ªÕËϵͳ(ATS)¡¢»ùÓڵ绰µÄ¹¥»÷½»¸¶(TOAD)¡¢ÆÁÄ»¹²ÏíÒÔ¼°¶ñÒâÈí¼þ¼´·þÎñ (MaaS)¡£ÎªÁËÌá·À´ËÀ๥»÷£¬½¨ÒéÓû§²»Òª´Ó¹Ù·½ÇþµÀÖ®ÍâÏÂÔØAPK¡£
https://www.zimperium.com/resources/zimperiums-2023-mobile-banking-heists-report-finds-29-malware-families-targeted-1800-banking-apps-across-61-countries-in-the-last-year/