Credit Control CorporationÔ¼28ÍòÓû§µÄÐÅϢй¶

°ä²¼¹¦·ò 2023-05-18

1¡¢Credit Control CorporationÔ¼28ÍòÓû§µÄÐÅϢй¶


¾Ý5ÔÂ17ÈÕ±¨Â· £¬£¬£¬£¬£¬£¬£¬£¬Õ®Îñ´ßÊÕ¹«Ë¾Credit Control Corporation(CCC)Ôâµ½¹¥»÷ £¬£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶ÁË286699¸ö¿Í»§µÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶ÊÂÎñ²úÉúÔÚ3ÔÂ2ÈÕÖÁ7ÈÕ £¬£¬£¬£¬£¬£¬£¬£¬Éæ¼°ÐÕÃû¡¢µØÖ·¡¢Éç»á°²È«ºÅÂëºÍÕÊ»§¾ßÌåÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÓÚ3ÔÂ7ÈÕÔÚÆäÍøÂçÖмì²âµ½Òì³£»£»£»£»£»£»£»£»î¶¯ £¬£¬£¬£¬£¬£¬£¬£¬µ÷²é·¢ÏÖ¹¥»÷Õß»ñµÃÁËÌØ¶¨ÏµÍ³µÄ½Ó¼ûȨÏÞ £¬£¬£¬£¬£¬£¬£¬£¬²¢¸´ÔìÁËÔ̺¬¿Í»§ÐÅÏ¢µÄ¸÷ÀàÎļþ¡£¡£¡£¡£¡£¡£¡£ÕâÒ»ÊÂÎñÖØÒªÓ°ÏìÁËÒÀÀµCCCÊÕÕ®·þÎñµÄÒ½ÁÆ»ú¹¹ £¬£¬£¬£¬£¬£¬£¬£¬ÀýÈçUVAÎÀÉúϵͳ¡¢ValleyÎÀÉúϵͳºÍSentaraÎÀÉúϵͳµÈ¡£¡£¡£¡£¡£¡£¡£


https://www.hackread.com/credit-control-corporation-data-breach/


2¡¢·¨¹úµç×ÓÉ豸Ôì×÷ÉÌLacroixÔâµ½¹¥»÷Èý¸ö¹¤³§ÁÙʱ¹Ø¹Ø    


¾ÝýÌå5ÔÂ16ÈÕ±¨Â· £¬£¬£¬£¬£¬£¬£¬£¬·¨¹úµç×Ó²úÆ·Ôì×÷ÉÌLacroix GroupÔâµ½¹¥»÷ £¬£¬£¬£¬£¬£¬£¬£¬¹Ø¹ØÁË·¨¹ú¡¢µÂ¹úºÍÍ»Äá˹µÄÈý¸ö¹¤³§¡£¡£¡£¡£¡£¡£¡£¹¥»÷²úÉúÔÚ5ÔÂ7ÈÕ £¬£¬£¬£¬£¬£¬£¬£¬LacroixÓÚ5ÔÂ12ÈÕ°ä·¢¹Ø¹ØÕâЩ¹¤³§¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ð¹Â©ÕâÊÇÀÕË÷¹¥»÷ £¬£¬£¬£¬£¬£¬£¬£¬ËûÃÇÒѶԴËÎÊÌâ·¢Õ¹µ÷²é £¬£¬£¬£¬£¬£¬£¬£¬ÒÔÈ·¶¨ÊÇ·ñº±¼û¾Ýй¶¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ²¿Ãű¾µØ»ù´¡ÉèÊ©±»¼ÓÃÜ £¬£¬£¬£¬£¬£¬£¬£¬Lacroix´òËãÓÚ5ÔÂ22ÈÕ¸´Ô­³ö²ú¡£¡£¡£¡£¡£¡£¡£¾ÝϤ £¬£¬£¬£¬£¬£¬£¬£¬ÊÜÓ°Ï칤³§Õ¼¹«Ë¾µÄºÜ´óÒ»²¿ÃÅ £¬£¬£¬£¬£¬£¬£¬£¬Õ¼¼¯ÍÅ2022Äê×ÜÏúÊÛ¶îµÄ19%¡£¡£¡£¡£¡£¡£¡£Ä¿Ç° £¬£¬£¬£¬£¬£¬£¬£¬»¹Ã»ÓÐÀÕË÷ÍÅ»ïÐû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü¡£¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/146335/cyber-crime/lacroix-group-ransomware-attack.html


3¡¢Trend Micro·¢ÏÖWater Orthrus½üÆÚµÄÁ½Ïîл


5ÔÂ15ÈÕ £¬£¬£¬£¬£¬£¬£¬£¬Trend MicroÅû¶ÁËWater Orthrus½üÆÚµÄÁ½Ïîл¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖÁË·Ö·¢Ð¶ñÒâÈí¼þCopperStealthºÍCopperPhishµÄ»î¶¯ £¬£¬£¬£¬£¬£¬£¬£¬ËüÃÇÓëCopperStealerÀàËÆ £¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄÜÀ´×Ôͳһ¸ö¿ª·¢Õß £¬£¬£¬£¬£¬£¬£¬£¬Òò¶øÕâ¿ÉÄÜÊÇWater OrthrusµÄл¡£¡£¡£¡£¡£¡£¡£µÚÒ»¸ö»î¶¯Ê¼ÓÚ3ÔÂ8ÈÕ £¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ýÈí¼þ¹²ÏíÍøÕ¾ÉÏÌṩµÄ×°Ö÷¨Ê½À´·Ö·¢CopperStealth £¬£¬£¬£¬£¬£¬£¬£¬ËüʹÓÃrootkitÔÚÖ¸±êϵͳÉÏ×°ÖöñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£µÚ¶þ¸ö»î¶¯ÔÚ4Ô±»·¢ÏÖ £¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ýÃâ·ÑÄäÃûÎļþ¹²ÏíÍøÕ¾ºóÃæµÄPPIÍøÂç·Ö·¢CopperPhish £¬£¬£¬£¬£¬£¬£¬£¬Ëü¿ÉÇÔÊØÐÅÓþ¿¨ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£


https://www.trendmicro.com/en_us/research/23/e/water-orthrus-new-campaigns-deliver-rootkit-and-phishing-modules.html


4¡¢´óѧµÇ¿ÆÆ½Ì¨Leverage EDUй¶´óÁ¿Ñ§ÉúµÄ»¤ÕÕµÈÐÅÏ¢


ýÌå5ÔÂ17ÈÕ³Æ £¬£¬£¬£¬£¬£¬£¬£¬´óѧµÇ¿ÆÆ½Ì¨Leverage EDUй¶ÁËѧÉúµÄ»¤ÕÕ¡¢²ÆÕþÐÅÏ¢¡¢Ö¤ÊéºÍ¿¼ÊԳɾ͵ÈÊý¾Ý¡£¡£¡£¡£¡£¡£¡£1ÔÂ31ÈÕ £¬£¬£¬£¬£¬£¬£¬£¬×êÑÐÍŶӷ¢ÏÖÁËÒ»¸öÅäÖÃÃýÎó¿É¹«¿ª½Ó¼ûµÄAmazon S3 ´æ´¢Í°¡£¡£¡£¡£¡£¡£¡£¸Ã´æ´¢Í°Ô̺¬´óÁ¿zipÎļþ¼Ð £¬£¬£¬£¬£¬£¬£¬£¬ÆäÖнü240000¸öÎļþй¶ÁËѧÉúµÄÃô¸ÐÊý¾ÝºÍPIIÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢¿É±»¹¥»÷ÕßÓÃÀ´½øÐÐÉí·ÝµÁÓúÍڲƭ¡£¡£¡£¡£¡£¡£¡£Ä¿Ç° £¬£¬£¬£¬£¬£¬£¬£¬¸Ã´æ´¢Í°Òѱ»±£»£»£»£»£»£»£»£»¤ÆðÀ´¡£¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/146329/data-breach/university-admission-platform-leverage-edu-exposed-student-passports.html


5¡¢×êÑÐÈËÔ±¼ì²âµ½¶à¸ö¶ñÒâMicrosoft VSCodeÀ©´ó


Check PointÔÚ5ÔÂ16ÈÕ³Æ £¬£¬£¬£¬£¬£¬£¬£¬Æä¼à²âµ½ÁË3¸ö¶ñÒâMicrosoft VSCodeÀ©´ó £¬£¬£¬£¬£¬£¬£¬£¬Òѱ»Windows¿ª·¢ÈËÔ±ÏÂÔØÁË46600´Î¡£¡£¡£¡£¡£¡£¡£µÚÒ»¸öÀ©´óÊÇTheme Darcula dark £¬£¬£¬£¬£¬£¬£¬£¬Ëü±»ÓÃÓÚÇÔÈ¡Óйؿª·¢ÈËԱϵͳµÄ¸ù»ùÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£µÚ¶þ¸öÃûΪpython-vscode £¬£¬£¬£¬£¬£¬£¬£¬ËüÊÇÒ»¸öC# shell×¢È뷨ʽ £¬£¬£¬£¬£¬£¬£¬£¬Äܹ»ÔÚÖ¸±êϵͳִÐдúÂë»òºÅÁî¡£¡£¡£¡£¡£¡£¡£×îºóÒ»¸öÊÇprettiest java £¬£¬£¬£¬£¬£¬£¬£¬¿É´Óä¯ÀÀÆ÷ÇÔȡʹ´¦»òÉí·ÝÑéÖ¤ÁîÅÆ £¬£¬£¬£¬£¬£¬£¬£¬²¢Í¨¹ýDiscord webhook·¢Ë͸ø¹¥»÷Õß¡£¡£¡£¡£¡£¡£¡£ÕâЩÀ©´óÓÚ5ÔÂ4ÈÕ±»·¢ÏÖ £¬£¬£¬£¬£¬£¬£¬£¬²¢5ÔÂ14ÈÕ´ÓVSCodeÖÐɾ³ý¡£¡£¡£¡£¡£¡£¡£


https://blog.checkpoint.com/securing-the-cloud/malicious-vscode-extensions-with-more-than-45k-downloads-steal-pii-and-enable-backdoors/


6¡¢Kaspersky°ä²¼2022ÄêÍøÂç¹¥»÷ÊÂÎñµÄ·ÖÎö»ã±¨


5ÔÂ16ÈÕ £¬£¬£¬£¬£¬£¬£¬£¬Kaspersky°ä²¼Á˹ØÓÚ2022ÄêÍøÂç¹¥»÷ÊÂÎñµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£2022Äê £¬£¬£¬£¬£¬£¬£¬£¬Ôâµ½ÍøÂç¹¥»÷ÊÂÎñµÄ×éÖ¯ÖÐ £¬£¬£¬£¬£¬£¬£¬£¬ÓÐ45.9%λÓÚ¶íÂÞ˹ºÍCISµØÓò £¬£¬£¬£¬£¬£¬£¬£¬Æä´ÎÊÇÖж«(22.5%)¡¢ÃÀÖÞ(14.3%)ºÍÅ·ÖÞ(13.3%)¡£¡£¡£¡£¡£¡£¡£´ÓÐÐÒµ½Ç¶ÈÀ´¿´ £¬£¬£¬£¬£¬£¬£¬£¬µ±¾Ö£¨19.39%£©¡¢½ðÈÚ£¨18.37%£©ºÍ¹¤Òµ£¨17.35%£©ÓйØ×éÖ¯Ôâµ½µÄ¹¥»÷×î¶à¡£¡£¡£¡£¡£¡£¡£2022Äê £¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß×ͨ¹ýÀûÓÃÃæÏò¹«¼ÒµÄÀûÓÃÖеĸ÷Àà·ì϶(42.9%)À´ÈëÇÖ×éÖ¯µÄ»ù´¡ÉèÊ©¡£¡£¡£¡£¡£¡£¡£39.8%µÄÊÂÎñÓëÀÕË÷¹¥»÷Óйء£¡£¡£¡£¡£¡£¡£


https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2023/05/12154213/The_nature_of_cyberincidents_2022.pdf