Microsoft Teams ±»ÓÃÀ´Èö²¥ DarkGate ¶ñÒâÈí¼þ
Ðû²¼Ê±¼ä 2024-02-011¡¢Microsoft Teams ±»ÓÃÀ´Èö²¥ DarkGate ¶ñÒâÈí¼þ
1ÔÂ30ÈÕ£¬AT&T ÍøÂçÇå¾²¹«Ë¾µÄÍøÂçÇ徲ר¼Ò·¢Ã÷ÁËÒ»¸öÁîÈ˵£ÐĵÄÇ÷ÊÆ£ºÆÕ±éʹÓõÄÐ×÷ƽ̨Microsoft Teams±»ÓÃ×÷ÍøÂç´¹ÂÚթƺͶñÒâÈí¼þ¹¥»÷µÄÔØÌå¡£ËäȻͨ¹ýµç×ÓÓʼþ¾ÙÐеĹŰåÍøÂç´¹ÂÚÈÔÈ»ÊÇÒ»ÖÖÆÕ±éµÄÍþв£¬µ« Microsoft Teams ÖÐÍⲿ»á¼ûµÄ¼¯³ÉΪ¶ñÒâÐÐΪÕß¿ª·¢ÁËеÄʹÓÃÁìÓò¡£¹©Äú²Î¿¼£¬Íⲿ»á¼û¿ÉÒÔʹÓà Teams¡¢Skype for Business »ò Skype Óë×éÖ¯ÍⲿµÄСÎÒ˽¼Ò¼ò»¯Í¨Ñ¶ºÍÐ×÷¡£DarkGate ¶ñÒâÈí¼þÊ״ηºÆðÓÚ 2017 Äê 12 Ô 25 ÈÕ£¬×î³õµÄ¹¦Ð§ÊÇÃÜÂëÇÔÈ¡³ÌÐòºÍ¼ÓÃÜÇ®±ÒÍÚ¾ò³ÌÐò£¬Ö÷Ҫͨ¹ý Torrent ÎļþÈö²¥¡£¸Ã²¡¶¾ÊÇÓÉ enSilo Ñо¿Ô± Adi Zeligson ·¢Ã÷µÄ£¬ËûÊӲ쵽¸Ã²¡¶¾Õë¶ÔµÄÊÇ Windows ÊÂÇéÕ¾¡£ÊÓ²ìµÄÒªº¦ÊÇʶ±ð Teams ÇéÐÎÖеĿÉÒÉÔ˶¯¡£Áè¼Ý 1,000 ¸ö Microsoft Teams ÊÂÎñÒѱ»±ê¼Ç£¬Åú×¢ÍøÂç´¹ÂÚʵÑéµÄ¹æÄ£¡£Í¨¹ýʹÓà Microsoft 365×⻧ ID ²¢×Ðϸ¸ú×Ù̸Ìì½»»¥£¬MDR SOC ÍŶÓÀֳɲéÃ÷ÎúÊÜËðµÄÕÊ»§ºÍ×ʲúÒÔ¾ÙÐÐÐÞ¸´¡£
https://www.hackread.com/microsoft-teams-external-access-darkgate-malware/
2¡¢Òâ´óÀûÊý¾Ý±£»¤»ú¹¹³ÆCHATGPTÎ¥·´Å·ÃËÒþ˽·¨
https://securityaffairs.com/158359/laws-and-regulations/garante-chatgpt-violated-eu-privacy-laws.html
3¡¢¶íÂÞ˹ÔâÓöÌìÏ´ó¹æÄ£»¥ÁªÍøÖÐÖ¹
1ÔÂ30ÈÕ£¬¶íÂÞ˹ÕýÃæÁÙ´ó¹æÄ£µÄ»¥ÁªÍøÖÐÖ¹£¬Ììϸ÷µØµÄÓû§¶¼Êܵ½Ó°Ï죬ÍâµØ .ru ÓòÉϵÄÍøÕ¾»á¼ûȨÏÞϽµ¡£¶íÂÞ˹Êý×Ö²¿ÖܶþÔÚ Telegram ÉϽÒÏþÉùÃ÷³Æ£¬¸ÃÎÊÌâÓë .ru ÓòÃûµÄÈ«ÇòÓòÃûϵͳÇå¾²À©Õ¹ (DNSSEC) µÄÊÖÒÕÎÊÌâÓйأ¬¸ÃÀ©Õ¹ÓÃÓÚ±£»¤»¥ÁªÍøÐÒéÍøÂçÖн»Á÷µÄÊý¾Ý¡£°üÀ¨×îÊܽӴýµÄÍâµØËÑË÷ÒýÇæ Yandex.ru¡¢µç×ÓÉÌÎñÁìÏÈÕß Ozon.ru ºÍ Wildberry.ru ÔÚÄÚµÄÍøÕ¾ÒÔ¼°¸Ã¹ú×î´óÒøÐÐ Sberbank PJSC ºÍ VTB Group µÄÓ¦ÓóÌÐò¾ùÊܵ½Ó°Ïì¡£½»Í¨¼à¿Ø·þÎñ¡£
https://www.databreaches.net/russia-hit-with-widespread-internet-outage-across-country/
4¡¢Greatness Õë¶Ô Microsoft 365 µÄÐÂÍøÂçÍþв
1ÔÂ30ÈÕ£¬ÔÚÒ»Ö±ÑݱäµÄÍøÂçÍþвÖУ¬·ºÆðÁËÒ»ÖÖеÄΣÏÕ£¬ËüÒÔ¾ªÈ˵Ĺ¦Ð§Õë¶Ô Microsoft 365 Óû§¡£Trustwave Ö©ÖëʵÑéÊÒÒ»Ö±ÔÚÇ×½ü¼àÊÓ¡°Greatness¡±ÍøÂç´¹ÂÚ¹¤¾ß°üµÄʹÓü¤Ôö£¬ÕâÊÇÒ»¸öÓÉÃûΪ¡°fisherstell¡±µÄÍþвÐÐΪÕß¿ª·¢µÄÖØ´óµÄÍøÂç´¹ÂÚ¼´·þÎñƽ̨¡£×Ô 2022 ÄêÖÐÆÚÒÔÀ´£¬Greatness ÌṩÁËÒ»¸öÓÃÓڲ߻®ÍøÂç´¹ÂÚÔ˶¯µÄ×ۺϹ¤¾ß°ü£¬ÏÖÔÚÒÔÿÔ 120 ÃÀÔªµÄ±ÈÌرҼÛÇ®»ñµÃ£¬ÁîÈËÕ𾪡£Greatness ʹÓÃÁ¿µÄÔöÌí£¬ÌØÊâÊÇ´Ó 2023 Äê 12 Ôµ½ 2024 Äê 1 Ô£¬ÒýÆðÁËÈËÃǵÄÑÏÖص£ÐÄ¡£Êܺ¦Õß¼òÖ±ÇÐÊýÄ¿Éв»ÇåÎú£¬µ«¸Ã¹¤¾ß°üµÄÆÕ±éʹÓúÍÇ¿Ê¢µÄÖ§³Öϵͳ£¨°üÀ¨×¨ÃÅµÄ Telegram ÉçÇø£©Í¹ÏÔÁËÆäDZÔÚÍþв¡£GreatnessµÄÌصãÊÇ°´ÆÚ¸üУ¬ÔöÇ¿ÁËÈƹýÇå¾²²½·¥µÄÄÜÁ¦¡£×îиüÐÂÓÚ 2024 Äê 1 ÔÂÉÏÑ®Ðû²¼£¬²¢¸½ÓÐ Greatness Hub Telegram ƵµÀÉϵÄÏêϸÎĵµ£¬¸ÅÊöÁËÆäй¦Ð§¡¢ÌáÐѺͼ¼ÇÉ¡£
https://securityonline.info/greatness-phishing-kit-the-new-cyber-menace-targeting-microsoft-365/
5¡¢ESET Ðû²¼ GrandoreiroÒøÐÐľÂíµÄÆÊÎö±¨¸æ
1ÔÂ30ÈÕ£¬ESET ÒÑÓë°ÍÎ÷Áª°î¾¯Ô±ÏàÖú£¬ÊÔͼÆÆËð Grandoreiro ½©Ê¬ÍøÂç¡£ESET ͨ¹ýÌṩÊÖÒÕÆÊÎö¡¢Í³¼ÆÐÅÏ¢ÒÔ¼°ÒÑÖªµÄÏÂÁîºÍ¿ØÖÆ (C&C) ·þÎñÆ÷ÓòÃûºÍ IP µØµãΪ¸ÃÏîÄ¿×ö³öÁËТ˳¡£ÓÉÓÚ Grandoreiro ÍøÂçÐÒéµÄÉè¼ÆȱÏÝ£¬ESET Ñо¿Ö°Ô±»¹Äܹ»Ò»¶ÃÊܺ¦ÕßµÄÇéÐΡ£ESET ×Ô¶¯»¯ÏµÍ³ÒÑ´¦Öóͷ£ÊýÒÔÍò¼ÆµÄ Grandoreiro Ñù±¾¡£¸Ã¶ñÒâÈí¼þ×Ô 2020 Äê 10 ÔÂ×óÓÒ×îÏÈʹÓõÄÓòÌìÉúËã·¨ (DGA) ÌìÌ춼»áÌìÉúÒ»¸öÖ÷Óò£¬²¢¿ÉÑ¡ÔñÌìÉú¶à¸ö¹ÊÕÏÇå¾²Óò¡£DGA ÊÇ Grandoreiro ÖªµÀÔõÑùÏò C&C ·þÎñÆ÷±¨¸æµÄΨһ·½·¨¡£³ýÁËÄ¿½ñÈÕÆÚÖ®Í⣬DGA »¹½ÓÊܾ²Ì¬ÉèÖà - ×èֹ׫д±¾ÎÄʱ£¬ÎÒÃÇÒѾÊӲ쵽 105 ¸ö´ËÀàÉèÖá£
https://www.welivesecurity.com/en/eset-research/eset-takes-part-global-operation-disrupt-grandoreiro-banking-trojan/
6¡¢¹ú¼Ê½ðÈڿƼ¼¹«Ë¾ Direct Trading Technologies й¶Áè¼Ý 30 ÍòÓû§Êý¾Ý
1ÔÂ31ÈÕ£¬Direct Trading Technologies (DTT) ÊÇÒ»¼Ò¹ú¼Ê½ðÈڿƼ¼¹«Ë¾£¬ËäÈ»Ö÷Òª¿Í»§Î»ÓÚɳÌØ°¢À²®£¬µ«¸Ã¹«Ë¾ÔÚÓ¢¹ú¡¢Á¢ÌÕÍð¡¢°¢ÁªÇõ¡¢¿ÆÍþÌØ¡¢¸çÂ×±ÈÑÇ¡¢ÍÁ¶úÆä¡¢°ÍÁÖ¡¢Àè°ÍÄÛºÍÍßŬ°¢Í¼¹²ºÍ¹úÉèÓзþÎñ´¦¡£·¢Ã÷µÄĿ¼°üÀ¨¶à¸öÊý¾Ý¿â±¸·Ý£¬Ã¿¸ö±¸·Ý¶¼°üÀ¨Óйع«Ë¾Óû§ºÍÏàÖúͬ°éµÄ´ó×ÚÃô¸ÐÐÅÏ¢¡£´Ë´ÎйÃÜÊÂÎñ´øÀ´Á˶àÖÖΣº¦£¬´ÓÉí·Ý͵ÇÔµ½ÉúÒâÕßÕË»§µÄ½ÓÊܺͶÒÏÖ¡£Ð¹Â¶µÄÊý¾Ý°üÀ¨ÒÑÍùÁùÄêÁè¼Ý 30 ÍòÓû§µÄÉúÒâÔ˶¯£¬ÒÔ¼°ÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢¹«Ë¾·¢Ë͵ĵç×ÓÓʼþºÍ IP µØµã¡£³ÖÓй«Ë¾µç×ÓÓʼþµØµãµÄÓû§£¨¿ÉÄÜÊÇÔ±¹¤£©µÄÃÜÂëÒÔÃ÷ÎÄÐÎʽ̻¶¡£ÓÃÓÚ»á¼û DTT ÉúÒâƽ̨Óû§ÕÊ»§µÄ¹þÏ£ÃÜÂëÒ²±»Ð¹Â¶¡£Ò»Ð©¿Í»§µÄ¼Òͥסַ¡¢µç»°ºÅÂëºÍ²¿·ÖÐÅÓÿ¨ÐÅÏ¢±»Ð¹Â¶¡£
https://securityaffairs.com/158384/security/data-leak-at-fintech-direct-trading-technologies.html