PayPalÒòй¶3.5Íò¿Í»§µÄÓ×ÎҺͲÆÕþÐÅÏ¢±»¸æ×´
°ä²¼¹¦·ò 2023-03-071¡¢PayPalÒòй¶3.5Íò¿Í»§µÄÓ×ÎҺͲÆÕþÐÅÏ¢±»¸æ×´
ýÌå3ÔÂ4Èճƣ¬£¬£¬£¬£¬£¬£¬PayPalÒòй¶½ü35000¿Í»§µÄÓ×ÎҺͲÆÕþÐÅÏ¢Ãæ¶Ô¼¯ÌåËßËÏ¡£¡£¡£¡£¡£¡£¡£Ô¸æAshley PillardºÍDestiny RuckerÌá¸æ×´ËÏ£¬£¬£¬£¬£¬£¬£¬³Æ¸Ã¹«Ë¾µÄºöÂÔµ¼ÖÂÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬£¬£¬£¬£¬£¬PayPalÔÚ2023Äê1ÔÂ19ÈÕÆðÍ·ÁªÏµÓû§²¢·¢ËÍÊý¾Ýй¶֪ͨ£¬£¬£¬£¬£¬£¬£¬Ú¹ÊÍ˵ËûÃǵÄÕË»§ÔÚ2022Äê12ÔÂ6ÈÕÖÁ8ÈÕÔâµ½¹¥»÷¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝËßËÏ£¬£¬£¬£¬£¬£¬£¬PayPalδÄÜÖ´Ðиù»ùµÄ°²È«´ëÊ©»ò×ñÊØÁª¹úÒµÎñίԱ»áÔì¶©µÄÐÐÒµÊý¾Ý±£»£»£»£»£»£»£»¤³ß¶ÈºÍÖ¸ÄÏ£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÐÕÃûºÍÉç»á°²È«ºÅÂëµÈÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£¸ÃËßËÏÒÑÓÚÉÏÖÜËÄÔÚÃÀ¹ú¼ÓÀû¸£ÄáÑÇÖݱ±Çø´¦Ëù·¨ÔºÌáÆð¡£¡£¡£¡£¡£¡£¡£
https://www.hackread.com/paypal-sued-over-data-breach/
2¡¢×êÑÐÈËÔ±·¢ÏÖÕë¶ÔÆóÒµ¼¶Â·ÓÉÆ÷µÄжñÒâÈí¼þHiatusRAT
Lumen Black Lotus LabsÔÚ3ÔÂ6ÈÕÅû¶ÁËÕë¶ÔÆóÒµ¼¶Â·ÓÉÆ÷µÄ¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬£¬Éæ¼°À¶¡ÃÀÖÞ¡¢Å·Ö޺ͱ±ÃÀµÈµØÓò¡£¡£¡£¡£¡£¡£¡£¸Ã»î¶¯±»³ÆÎªHiatus£¬£¬£¬£¬£¬£¬£¬Ëü»áϰȾ¼¶Â·ÓÉÆ÷²¢×°ÖÃÁ½¸ö¶ñÒâ¶þ½øÔìÎļþ£¬£¬£¬£¬£¬£¬£¬Ô¶³Ì½Ó¼ûľÂíHiatusRATÒÔ¼°ÔÚÖ¸±êÉ豸Éϲ¶»ñÊý¾Ý°üµÄtcpdump±äÌå¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÖØÒªÕë¶ÔÔËÐÐi386¼Ü¹¹µÄEoL DrayTek VigorÐͺÅ2960ºÍ3900£¬£¬£¬£¬£¬£¬£¬½ØÖÁ2023Äê2ÔÂÖÐÑ®£¬£¬£¬£¬£¬£¬£¬Ô¼100̨·ÓÉÆ÷Òѱ»ÈëÇÖ¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄÐͺÅÊǸߴø¿í·ÓÉÆ÷£¬£¬£¬£¬£¬£¬£¬Äܹ»Ö§³ÖÊý°ÙÃûÔ¶³ÌÔ±¹¤µÄVPNÏνӡ£¡£¡£¡£¡£¡£¡£Òò¶ø´§Ä¦¹¥»÷ÕßϰȾָ±êÒÔÍøÂçÊý¾Ý£¬£¬£¬£¬£¬£¬£¬²¢³ÉÁ¢Òñ±ÎµÄ´úÀíÍøÂç¡£¡£¡£¡£¡£¡£¡£
https://thehackernews.com/2023/03/new-hiatusrat-malware-targets-business.html
3¡¢»ªÊ¢¶Ù¹«½»¹«Ë¾Pierce Transit±»LockBitÀÕË÷200ÍòÃÀÔª
¾Ý3ÔÂ3ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬»ªÊ¢¶ÙÖݵÄÒ»¼Ò¹«¹²½»Í¨ÔËÓªÉÌPierce TransitÔâµ½LockBitµÄ¹¥»÷£¬£¬£¬£¬£¬£¬£¬±»ÀÕË÷200ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÆðÍ·ÓÚ2023Äê2ÔÂ14ÈÕÆðÍ·£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾²»µÃ²»Ö´ÐÐһʱ±äͨ·¨×Ó£¬£¬£¬£¬£¬£¬£¬ÒÔά³ÖÿÌìµÄ¹«½»·þÎñ¡£¡£¡£¡£¡£¡£¡£2ÔÂ28ÈÕ£¬£¬£¬£¬£¬£¬£¬LockBit°ä²¼ÁËPierce Transit¹¥»÷ÊÂÎñµÄÏêÇ飬£¬£¬£¬£¬£¬£¬Ðû³ÆÇÔÈ¡Á˺Ïͬ¡¢¿Í»§ÐÅÏ¢¡¢±£ÃܺÍ̸ºÍº¯¼þµÈÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÕâЩÊý¾Ý´Ë¿Ì¶¼ÔÚÏúÊÛ¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬Pierce TransitµÄ´ó²¿ÃÅÔËÓªÒÑÆëÈ«¸´Ô£¬£¬£¬£¬£¬£¬£¬Æä°µÊ¾´òËãÖ´ÐÐеÄÍøÂ簲ȫ¼à¿Ø¹¤¾ßºÍ°²È«´ëÊ©¡£¡£¡£¡£¡£¡£¡£
https://www.malwarebytes.com/blog/news/2023/03/public-transportation-service-pierce-transit-struck-by-lockbit-ransomware
4¡¢GunAuction.comÍøÕ¾±»ºÚ56.5Íò¸öÕË»§µÄÐÅϢй¶
¾ÝýÌå3ÔÂ2ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍÈëÇÖÁËGunAuction.com²¢ÇÔÈ¡ÁËÓû§µÄÓ×ÎÒÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£2022Äêµ×£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±ÔÚÊôÓںڿ͵ÄÒ»¸öÅäÖÃÃýÎóµÄ·þÎñÆ÷ÉÏ·¢ÏÖÁËÕâЩ±»µÁÊý¾Ý¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶ÐÅÏ¢Éæ¼°ÐÕÃû¡¢×¡Ö·¡¢Ã÷ÎÄÃÜÂëºÍµç»°ºÅÂëµÈ¡£¡£¡£¡£¡£¡£¡£TechCrunch³ÆÆä¿ÉÄÜÑéÖ¤Ñù±¾Êý¾ÝµÄÕæÊµÐÔ£¬£¬£¬£¬£¬£¬£¬µ«Éв»Ã÷ÏÔÕâЩÊý¾ÝÓжàС£¡£¡£¡£¡£¡£¡£HaveIBeenPwned»ã±¨°µÊ¾£¬£¬£¬£¬£¬£¬£¬¹¥»÷²úÉúÔÚÈ¥Äê12Ô£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁË56.5Íò¸öÕË»§¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/142920/data-breach/gunauction-site-data-breach.html
5¡¢×êÑÐÈËÔ±·¢ÏÖBooking.comÉϿɵ¼ÖÂÕÊ»§½Ù³ÖµÄ·ì϶
Salt SecurityÓÚ3ÔÂ2ÈÕ³ÆÆä·¢ÏÖÁËÔÚÏß¹Û¹âÉçBooking.comÉϵݲȫ·ì϶¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢Ïֵķì϶¼¯ÖÐBooking.comÖ´ÐÐOAuthµÄ·½Ê½ÉÏ£¬£¬£¬£¬£¬£¬£¬Éæ¼°OAuthÓëFacebookµÄ¼¯³É¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÓÕʹָ±êµã»÷ÌØÔìÁ´½Ó£¬£¬£¬£¬£¬£¬£¬Í¨¹ýÀÄÓÃOAuthµÇ¼»úÔìÀ´²¶»ñÒѵǼÓû§µÄÉí·ÝÑéÖ¤´úÂë¡£¡£¡£¡£¡£¡£¡£¶øºó¹¥»÷Õß½Ó¼ûËûÃÇ×Ô¼ºµÄÕÊ»§£¬£¬£¬£¬£¬£¬£¬ÔÚÀûÓÃÏòÔ¤Ô¼·þÎñÆ÷·¢Ë͵ÄÉí·ÝÑéÖ¤ÒªÇóÖУ¬£¬£¬£¬£¬£¬£¬½«×Ô¼ºµÄ´úÂë´úÌæÎªÖ¸±êµÄ´úÂë¡£¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓÃÕâЩ·ì϶¿ÉÆëÈ«½ÚÔìÖ¸±êÕÊ»§£¬£¬£¬£¬£¬£¬£¬À´ÇÔÈ¡Ó×ÎÒÐÅÏ¢²¢Ö´ÐÐÈ¡µÞ»òÔ¤Ô¼µÈ²Ù×÷¡£¡£¡£¡£¡£¡£¡£¸ÃÎÊÌ⻹ӰÏìÁËBooking.comµÄæ¢ÃÃÍøÕ¾Kayak.com¡£¡£¡£¡£¡£¡£¡£
https://salt.security/blog/traveling-with-oauth-account-takeover-on-booking-com
6¡¢Lookout°ä²¼2022ÄêÒÆ¶¯ÍøÂç´¹µö¹¥»÷Ì¬ÊÆµÄ·ÖÎö»ã±¨
3ÔÂ1ÈÕ£¬£¬£¬£¬£¬£¬£¬Lookout°ä²¼ÁË2022ÄêÈ«ÇòÒÆ¶¯ÍøÂç´¹µöÌ¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£»ã±¨³Æ£¬£¬£¬£¬£¬£¬£¬2022ÄêÊÇÓÐÊ·ÒÔÀ´Òƶ¯´¹µö¹¥»÷×î¶àµÄÒ»Ä꣬£¬£¬£¬£¬£¬£¬Ã¿¸ö¼¾¶È¶¼Óг¬¹ý30%µÄÓ×ÎÒºÍÆóÒµÓû§Ôâµ½¹¥»÷¡£¡£¡£¡£¡£¡£¡£Êܵ½¸ß¶È¼à¹ÜµÄÐÐÒµ£¬£¬£¬£¬£¬£¬£¬Ô̺¬±£ÏÕ¡¢ÒøÐÓע˾·¨¡¢Ò½ÁƱ£½¡ºÍ½ðÈÚ·þÎñ£¬£¬£¬£¬£¬£¬£¬×îÒ×Ôâµ½¹¥»÷¡£¡£¡£¡£¡£¡£¡£·Çµç×ÓÓʼþµÄ´¹µö¹¥»÷Ò²ÔÚ¼¤Ôö£¬£¬£¬£¬£¬£¬£¬ÓïÒô´¹µö¡¢¶ÌÐÅ´¹µöºÍ¶þάÂë´¹µöÔÚ2022ÄêQ2¶ÈÔö³¤ÁËÆß±¶¡£¡£¡£¡£¡£¡£¡£¶ÔÓÚÔâµ½ÒÆ¶¯´¹µö¹¥»÷µÄÆóÒµ¶øÑÔ£¬£¬£¬£¬£¬£¬£¬Ëðʧ¿ÉÄÜÊǾ޴óµÄ¡£¡£¡£¡£¡£¡£¡£LookoutÍÆËãµÃ³ö£¬£¬£¬£¬£¬£¬£¬´ËÀ๥»÷¶ÔÒ»¸öÕ¼ÓÐ5000ÃûÔ±¹¤µÄ×éÖ¯µÄDZÔÚÄê¶È²ÆÕþÓ°ÏìÊǽü400ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£
https://www.lookout.com/form/the-global-state-of-mobile-phishing-report


¾©¹«Íø°²±¸11010802024551ºÅ