TikTok¿ÉÄÜÒòδÄܱ£»£» £»£»£»£»¤¶ùͯÒþÖÔÃæ¶Ô2700ÍòÓ¢°÷µÄ·£¿£¿ £¿£¿£¿£¿£¿£¿î

°ä²¼¹¦·ò 2022-09-28
1¡¢TikTok¿ÉÄÜÒòδÄܱ£»£» £»£»£»£»¤¶ùͯÒþÖÔÃæ¶Ô2700ÍòÓ¢°÷µÄ·£¿£¿ £¿£¿£¿£¿£¿£¿î

      

¾Ý9ÔÂ26ÈÕ±¨Â·£¬£¬ £¬£¬£¬£¬£¬£¬Ó¢¹úÒþÖÔ¼à¹Ü»ú¹¹°ä·¢ÓÐÒâ¶ÔÎ¥·´¸Ã¹úÊý¾Ý±£»£» £»£»£»£»¤·¨µÄTikTok´¦ÒÔ2700ÍòÓ¢°÷µÄ·£¿£¿ £¿£¿£¿£¿£¿£¿î¡£¡£¡£¡£¡£ÐÅϢרԱ°ì¹«ÊÒ(ICO)ÒÑÏòÉ罻ýÌåÆ½Ì¨TikTok·¢³ö¡°ÒâÏò֪ͨ¡±¡£¡£¡£¡£¡£Æ¾¾Ý֪ͨ£¬£¬ £¬£¬£¬£¬£¬£¬TikTokÔÚ2018Äê5ÔÂÖÁ2020Äê7ÔÂÆÚ¼ä¿ÉÄÜδ¾­¸¸Ä¸Ô޳ɴ¦ÖÃ13ËêÒÔ϶ùͯµÄÊý¾Ý£»£» £»£»£»£»Î´ÄÜÒÔ¼ò½à¡¢Í¨Ã÷ºÍÒ×ÓÚÀí½âµÄ·½Ê½ÏòÓû§ÌṩÐÅÏ¢£»£» £»£»£»£»ÒÔ¼°ÔÚûÓÐ˾·¨Æ¾¾ÝµÄÇé¿öÏ´¦ÖÃÌØÊâÀà±ðÊý¾Ý£¨Ô̺¬ÖÖ×åºÍÖÖ×å¡¢ÒÅ´«¡¢½¡È«ºÍÉúÎïÌØµãÊý¾ÝµÈ£©¡£¡£¡£¡£¡£ICO°µÊ¾£¬£¬ £¬£¬£¬£¬£¬£¬µ÷²éÊdzõ²½µÄ£¬£¬ £¬£¬£¬£¬£¬£¬Í¨ÖªÒ²ÊÇһʱµÄ£¬£¬ £¬£¬£¬£¬£¬£¬Ëü½«ÔÚ×Ðϸ˼¿¼TikTokµÄ³ÂÊöºóÔÙ×ö¾ö¶¨¡£¡£¡£¡£¡£


https://therecord.media/tiktok-could-face-27-million-fine-for-failing-to-protect-uk-childrens-privacy/


2¡¢ÒÔÉ«Áйú·À³Ð°üÉÌElbitÃÀ¹ú·Ö¹«Ë¾Ô±¹¤µÄÓ×ÎÒÐÅϢй¶

      

¾ÝýÌå9ÔÂ27Èճƣ¬£¬ £¬£¬£¬£¬£¬£¬ÒÔÉ«Áйú·À³Ð°üÉÌElbitµÄÃÀ¹ú·Ö¹«Ë¾Elbit Systems of AmericaÔâµ½¹¥»÷ºóÊý¾Ýй¶¡£¡£¡£¡£¡£6ÔÂÏÂÑ®£¬£¬ £¬£¬£¬£¬£¬£¬ÀÕË÷ÍÅ»ïBlack BastaÔøÐû³ÆÈëÇÖÁËElbit Systems of America£¬£¬ £¬£¬£¬£¬£¬£¬²¢½«¸Ã¹«Ë¾Ôö³¤µ½ÆäTorÍøÕ¾ÉÏ¡£¡£¡£¡£¡£´Ë¿Ì£¬£¬ £¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾È·ÈÏÓÚ6ÔÂ8ÈÕ²úÉúÁËÊý¾Ýй¶ÊÂÎñ£¬£¬ £¬£¬£¬£¬£¬£¬Ó°ÏìÁË369Ó×ÎÒ¡£¡£¡£¡£¡£Ð¹Â¶µÄÊý¾ÝÔ̺¬ÐÕÃû¡¢µØÖ·¡¢Éç»á°²È«ºÅÂë¡¢µ®ÉúÈÕÆÚ¡¢Ö±½Ó´æ¿îÐÅÏ¢ºÍÖÖ×åÐÅÏ¢µÈ¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÒѾ­Í¨ÖªÊÜÓ°ÏìµÄÈË£¬£¬ £¬£¬£¬£¬£¬£¬²¢½«ÎªËûÃÇÌṩ12¸öÔµÄÉí·Ý±£»£» £»£»£»£»¤ºÍÐÅÓþ¼à¿Ø·þÎñ¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/136310/cyber-crime/elbit-systems-of-america-data-breach.html


3¡¢Fancy BearÀûÓÃPPTµÄÊó±êÐüÍ£·Ö·¢¶ñÒâÈí¼þGraphite

      

Cluster25ÔÚ9ÔÂ23ÈÕÅû¶ÁËAPT28£¨Fancy Bear£©ÀûÓÃм¼ÊõÀ´·Ö·¢¶ñÒâÈí¼þGraphiteµÄ»î¶¯¡£¡£¡£¡£¡£¹¥»÷ÕßÀûÓÃPowerPointÎļþ×÷Ϊµö¶ü£¬£¬ £¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬Á½ÕÅ»ÃµÆÆ¬£¬£¬ £¬£¬£¬£¬£¬£¬¾ùÒÔÓ¢Îĺͷ¨ÎÄÌṩÁËʹÓÃZoomÊÓÆµ»áÒéÀûÓ÷¨Ê½ÖеÄÚ¹ÊÍÑ¡ÏîµÄ×¢Ã÷¡£¡£¡£¡£¡£µ±Ö¸±êÒÔÑÝʾģʽ´ò¿ªµö¶üÎĵµ²¢ÇÒ½«Êó±êÐüÍ£ÔÚ³¬Á´½ÓÉÏʱ£¬£¬ £¬£¬£¬£¬£¬£¬»á¼¤»î¶ñÒâPowerShell½ÅÕý±¾´ÓMicrosoft OneDriveÕÊ»§ÏÂÔØJPEGÎļþ¡£¡£¡£¡£¡£JPEGÊÇÒ»¸ö¼ÓÃܵÄDLLÎļþ(lmapi2.dll)£¬£¬ £¬£¬£¬£¬£¬£¬Í¨¹ýrundll32.exeÖ´ÐС£¡£¡£¡£¡£½ÓÏÂÀ´£¬£¬ £¬£¬£¬£¬£¬£¬lmapi2.dllÔÚ֮ǰÓÉDLL´´½¨µÄÐÂÏß³ÌÉÏ»ñÈ¡²¢½âÃܵڶþ¸öJPEG¡£¡£¡£¡£¡£ 


https://blog.cluster25.duskrise.com/2022/09/23/in-the-footsteps-of-the-fancy-bear-powerpoint-graphite/


4¡¢SentinelLabs³ÆMetadorÍÅ»ïÒÑÔÚISPÍøÂçÖÐÂñ·üÊýÔÂ

      

ýÌå9ÔÂ25ÈÕ±¨Â·³Æ£¬£¬ £¬£¬£¬£¬£¬£¬SentinelLabs·¢ÏÖкڿÍÍÅ»ïMetadorÍÅ»ïÒÑÈëÇÖÁ˵çÐÅ¡¢»¥ÁªÍø·þÎñÌṩÉÌ(ISP)ºÍ´óѧԼÁ½ÄêµÄ¹¦·ò¡£¡£¡£¡£¡£MetadorÖØÒªÕë¶ÔÖж«ºÍ·ÇÖÞµÄ×éÖ¯£¬£¬ £¬£¬£¬£¬£¬£¬Ö÷ÕÅËÆºõÊdz־ôÓʼäµý»î¶¯¡£¡£¡£¡£¡£¸Ã×é֯ʹÓÃÁ½ÖÖ»ùÓÚWindowsµÄ¶ñÒâÈí¼þ¿ò¼Ü£¬£¬ £¬£¬£¬£¬£¬£¬metaMainºÍMafalda£¬£¬ £¬£¬£¬£¬£¬£¬Ëü½öÔÚϵͳÄÚ´æÖÐÔËÐУ¬£¬ £¬£¬£¬£¬£¬£¬²»»áÔÚ±»Ï°È¾Ö÷»úÉÏÁôÏÂδ¼ÓÃܵĺۼ£¡£¡£¡£¡£¡£MafaldaÊÇÒ»ÖÖ¶àÖ°ÄܵÄÖ²È뷨ʽ£¬£¬ £¬£¬£¬£¬£¬£¬×î¶àÄܹ»½ÓÊÜ67¸öºÅÁ£¬ £¬£¬£¬£¬£¬£¬Æä¶à²ã»ìºÏÄܹ»Èƹý°²È«·ÖÎö¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-hacking-group-metador-lurking-in-isp-networks-for-months/


5¡¢MandiantÅû¶¶íÂÞ˹GRUÓë3¸öºÚ¿ÍÍÅ»ïЭͬ¹¥»÷µÄÖ¤¾Ý

      

MandiantÔÚ9ÔÂ23Èճƣ¬£¬ £¬£¬£¬£¬£¬£¬ÖÁÉÙ3¸öºÚ¿ÍÍÅ»ïÓë¶íÂÞ˹¾üʵý±¨»ú¹¹(GRU)µÄÍøÂçÈëÇֻ֮¼ä´æÔÚÏÔÖøµÄºÏ×÷¡£¡£¡£¡£¡£ÕâЩÍÅ»ï±ðÀëΪXakNet Team¡¢InfoccentrºÍCyberArmyofRussia_Reborn£¬£¬ £¬£¬£¬£¬£¬£¬×êÑзÖÎö·¢ÏÖÁ˽«ÕâЩ×éÖ¯Óë¶íÂÞ˹µ±¾ÖÁªÏµÆðÀ´µÄÐÂÖ¤¾Ý£¬£¬ £¬£¬£¬£¬£¬£¬Ô̺¬¶ÔÎÚ¿ËÀ¼µÄ×éÖ¯ÈëÇÖºÍйÃܵŦ·òÏß·ÖÎö¡£¡£¡£¡£¡£Mandiant»¹È·¶¨ÁËXakNetÓëKillNetÖ®¼äµÄÁªÏµ£¬£¬ £¬£¬£¬£¬£¬£¬²¢´§¶ÈÕâÁ½¸ö×éÖ¯Ö±½ÓЭͬÁ˲¿ÃŻ¡£¡£¡£¡£¡£


https://www.mandiant.com/resources/blog/gru-rise-telegram-minions


6¡¢Kaspersky°ä²¼¹ØÓÚ¶ñÒâÈí¼þNullMixerµÄ·ÖÎö»ã±¨

      

9ÔÂ26ÈÕ£¬£¬ £¬£¬£¬£¬£¬£¬Kaspersky°ä²¼¹ØÓÚжñÒâÈí¼þ·Ö·¢¹¤¾ßNullMixerµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¹¥»÷ÕßÀûÓÃÁËSEO¼¼ÊõÔÚGoogleËÑË÷Á˾ֵÄÏÔʾÖÐÍÆ¹ã¼ÙµÄÓÎÏ·ÆÆ½âºÍµÁ°æÈí¼þ¼¤»îÆ÷µÄÍøÕ¾£¬£¬ £¬£¬£¬£¬£¬£¬ÐéÎ±ÍøÕ¾»á½«Ö¸±ê³Á¶¨Ïòµ½¶ñÒâÍøÕ¾²¢ÏÂÔØNullMixer¸±±¾¡£¡£¡£¡£¡£¸Ã¹¤¾ß»á·Ö·¢Ê®¼¸¸ö¶ñÒâÈí¼þ¼Ò×壬£¬ £¬£¬£¬£¬£¬£¬Ô̺¬Redline Stealer¡¢DanabotºÍRaccoon StealerµÈ¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬ £¬£¬£¬£¬£¬£¬NullMixerÒÑÊÔͼϰȾÃÀ¹ú¡¢µÂ¹ú¡¢·¨¹ú¡¢Òâ´óÀû¡¢Ó¡¶È¡¢¶íÂÞ˹¡¢°ÍÎ÷¡¢ÍÁ¶úÆäºÍ°£¼°µÄ47778¸öÓû§¡£¡£¡£¡£¡£


https://securelist.com/nullmixer-oodles-of-trojans-in-a-single-dropper/107498/