ShutterflyÔâµ½ContiµÄÀÕË÷¹¥»÷ Êýǧ̨É豸±»¼ÓÃÜ

°ä²¼¹¦·ò 2021-12-28

ShutterflyÔâµ½ContiµÄÀÕË÷¹¥»÷£¬£¬£¬£¬ £¬Êýǧ̨É豸±»¼ÓÃÜ


ShutterflyÔâµ½ContiµÄÀÕË÷¹¥»÷£¬£¬£¬£¬£¬Êýǧ̨É豸±»¼ÓÃÜ.png


¾ÝýÌåÓÚ12ÔÂ27Èճƣ¬£¬£¬£¬ £¬Shutterfly¹«Ë¾Ôâµ½ÁËContiÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¡£¡£¹¥»÷²úÉúÔÚÁ½ÖÜǰ£¬£¬£¬£¬ £¬µ¼ÖÂShutterflyÆìϵÄLifetouch¡¢BorrowLenesesºÍGroovebook·þÎñÖжϡ£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬ £¬ContiÐû³ÆÒѼÓÃܸù«Ë¾µÄ4000¶ą̀É豸ºÍ120̨VMware ESXi·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬ £¬¹¥»÷ÕßÒªÇóÖ§¸¶Êý°ÙÍòÃÀÔªµÄÊê½ð£¬£¬£¬£¬ £¬²¢ÒÑÇÔÈ¡´óÁ¿»úÃÜÐÅÏ¢£¬£¬£¬£¬ £¬Ô̺¬Ë¾·¨ºÍ̸¡¢ÒøÐÐÕË»§ÐÅÏ¢¡¢¹«Ë¾µÇ¼ʹ´¦ÒÔ¼°ShutterflyÉ̵êµÄÔ´ÂëµÈ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/shutterfly-services-disrupted-by-conti-ransomware-attack/


Cyble·¢ÏÖеÄsincronizadorÕë¶Ô°ÍÎ÷Ita¨² Unibanco


Cyble·¢ÏÖеÄsincronizadorÕë¶Ô°ÍÎ÷Ita¨² Unibanco.png


12ÔÂ23ÈÕ£¬£¬£¬£¬ £¬Cyble°ä²¼Á˹ØÓÚÐÂAndroidÒøÐÐľÂísincronizadorµÄ×êÑл㱨¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¼ÙÒâÓë°ÍÎ÷ÒøÐÐIta¨² UnibancoÓйصĺϷ¨ÀûÓ㬣¬£¬£¬ £¬ÒÔsincronizador.apkΪÃûÍйÜÔÚÒ»¸öαÔìµÄGoogle PlayÉ̵êÉÏ£¬£¬£¬£¬ £¬²¢ÏÔʾÏÂÔØÁ¿³¬¹ý189Íò´Î¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾£¬£¬£¬£¬ £¬¸Ã¶ñÒâÀûÓû᳢ÊÔ´Û¸ÄÓû§µÄÊäÈë×ֶΣ¬£¬£¬£¬ £¬²¢ÔںϷ¨µÄIta¨² UnibancoÀûÓÃÉϽøÐÐڲƭÂòÂô¡£¡£¡£¡£¡£¡£¡£  


Ô­ÎÄÁ´½Ó£º

https://blog.cyble.com/2021/12/23/malicious-app-targets-major-brazilian-bank-itau-unibanco/


×êÑÐÍŶӷ¢ÏÖÒÔOmicronΪÖ÷ÌâµÄ´¹µö»î¶¯·Ö·¢Dridex


Dridex.png


¾ÝýÌåÔÚ12ÔÂ24ÈÕ±¨Â·£¬£¬£¬£¬ £¬MalwareHunterTeamºÍ604Kuzushi·¢ÏÖд¹µö»î¶¯ÒÔOmicronΪÖ÷Ìâ·Ö·¢Dridex¡£¡£¡£¡£¡£¡£¡£¹¥»÷Ðû³ÆÊÕ¼þÈ˽Ӵ¥µÄÒ»¸öͬÊÂCOVID-19 OMICRON¼ì²â³ÊÑôÐÔ£¬£¬£¬£¬ £¬±ØÒª´ò¿ª¸½¼þµÄExcel±í¸ñ²é¿´ÏêÇé¡£¡£¡£¡£¡£¡£¡£µ±Ö¸±êÆôÓúêÇÒÆäÉ豸±»Ï°È¾ºó£¬£¬£¬£¬ £¬»áÓÐÒ»¸öµ¯´°ÌáÐÑCOVID-19ÔáÀñÔöÔ®ÈÈÏߵ绰ºÅÂëÀ´³°·íÓû§¡£¡£¡£¡£¡£¡£¡£ÔçÔÚÒ»ÖÜǰ£¬£¬£¬£¬ £¬ÔøÓÐÒÔ¿ª³ýÐÅϢΪÖ÷ÌâµÄ´¹µö»î¶¯·Ö·¢Dridex¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/125976/cyber-crime/dridex-covid-19-omicron-campaign.html


SophosLabsÅû¶AvosLockerÐÂÒ»ÂÖ¹¥»÷»î¶¯µÄϸ½Ú


SophosLabsÅû¶AvosLockerÐÂÒ»ÂÖ¹¥»÷»î¶¯µÄϸ½Ú.png


12ÔÂ22ÈÕ£¬£¬£¬£¬ £¬SophosLabs°ä²¼Á˹ØÓÚAvosLockerµÄ×îÐÂ×êÑÓ×£¡£¡£¡£¡£¡£¡£AvosLockerÊ×ÏÈ»áÀûÓúϷ¨µÄ×Ô¶¯»¯²¹¶¡ÖÎÀí¹¤¾ßPDQ Deploy½«¶à¸öWindowsÅú´¦Öþ籾װÖõ½Ö¸±êÉ豸ÉÏ£¬£¬£¬£¬ £¬ÕâЩ¾ç±¾¿É´Û¸Ä»òɾ³ýÌØ¶¨°²È«¹¤¾ßµÄ×¢²á±íÏ£¬£¬£¬ £¬²¢´´½¨Ò»¸öÃûΪnewadminµÄÖÎÀíÔ¹ØË»§£¬£¬£¬£¬ £¬¶øºó×°ÖöñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬ £¬¹¥»÷Õß»¹½«É豸½«»úеÉèΪ°²È«Ä£Ê½£¬£¬£¬£¬ £¬À´½ûÓÃÔÚÔËÐеݲȫ¹¤¾ß¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://news.sophos.com/en-us/2021/12/22/avos-locker-remotely-accesses-boxes-even-running-in-safe-mode/


ÎïÁ÷¹«Ë¾DW Morgan´æ´¢Í°ÅäÖÃÃýÎóй¶100GBµÄÊý¾Ý


ÎïÁ÷¹«Ë¾DW Morgan´æ´¢Í°ÅäÖÃÃýÎóй¶100GBµÄÊý¾Ý.png


ýÌå12ÔÂ27ÈÕ±¨Â·£¬£¬£¬£¬ £¬Website Planetй©ÎïÁ÷¹«Ë¾DW Morganй¶³¬¹ý100 GBµÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£Õâ´Îй¶ÊÂÎñÊÇÓÉAmazon S3´æ´¢Í°ÅäÖÃÃýÎóµ¼Ö£¬£¬£¬£¬ £¬ÓÚ11ÔÂ12ÈÕ±»·¢ÏÖ£¬£¬£¬£¬ £¬¹²Ô̺¬³¬¹ý250Íò¸öÓë»õÔ˺Ϳͻ§ÓйصÄÎļþ£¬£¬£¬£¬ £¬Éæ¼°°®Á¢ÐźÍ˼¿ÆµÈ¶à¸ö¹«Ë¾¡£¡£¡£¡£¡£¡£¡£DW MorganÔÚÊÕµ½Ð¹Â¶¾¯±¨ºóµÄ4ÌìÄÚ½«Êý¾Ý¿â± £»£»£»£»£»£»£»£»¤ÆðÀ´£¬£¬£¬£¬ £¬Ä¿Ç°Éв»Ã÷ÏÔ¸ÃÊý¾Ý¿âÊÇ·ñ±»½Ó¼û¹ý¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/logistics-giant-d-w-morgan-exposed-clients-data/


Intel 471°ä²¼2021ÄêQ3ÀÕË÷Èí¼þÌ¬ÊÆµÄ·ÖÎö»ã±¨


Intel 471°ä²¼2021ÄêQ3ÀÕË÷Èí¼þÌ¬ÊÆµÄ·ÖÎö»ã±¨.png


12ÔÂ16ÈÕ£¬£¬£¬£¬ £¬Intel 471°ä²¼ÁË2021ÄêµÚÈý¼¾¶ÈÀÕË÷Èí¼þÌ¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬ £¬2021Äê7Ôµ½9Ô£¬£¬£¬£¬ £¬¹²¼ì²âµ½612´ÎÀÕË÷¹¥»÷»î¶¯£¬£¬£¬£¬ £¬¿É¹éÒòÓÚ35¸ö·ÖÆçµÄÀÕË÷Èí¼þ±äÌå¡£¡£¡£¡£¡£¡£¡£ÔÚÕâЩ¹¥»÷ÖУ¬£¬£¬£¬ £¬Ô¼60%µÄ»î¶¯Óë4¸ö±äÌåÓйأºLockBit 2.0£¨Õ¼±È33%£©¡¢Conti£¨15.2%£©¡¢BlackMatter£¨6.9%£©ºÍHive£¨6%£©¡£¡£¡£¡£¡£¡£¡£ÕâÒ»¼¾¶È£¬£¬£¬£¬ £¬ÊÜÓ°Ïì×î´óµÄÐÐÒµÊÇÔì×÷¡¢Ïû·ÑÆ·ºÍ¹¤Òµ²úÆ·¡¢×¨Òµ·þÎñºÍÕ÷ѯÒÔ¼°·¿µØ²úÐÐÒµ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://intel471.com/blog/ransomware-attacks-2021-lockbit-hive-conti-clop-revil-blackmatter