ŲÍþµ±¾Öй©Æä12¸ö²¿Î¯Ê¹ÓõÄICTƽ̨Ôâµ½ºÚ¿Í¹¥»÷
°ä²¼¹¦·ò 2023-07-261¡¢Å²Íþµ±¾Öй©Æä12¸ö²¿Î¯Ê¹ÓõÄICTƽ̨Ôâµ½ºÚ¿Í¹¥»÷
¾ÝýÌå7ÔÂ25ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬Å²Íþµ±¾Ö12¸ö²¿Î¯Ê¹ÓõÄICTƽ̨Ôâµ½ºÚ¿Í¹¥»÷¡£¡£¡£¡£¡£¸Ã¹¥»÷²¢Î´Ó°ÏìŲÍþÊ×Ïà°ì¹«ÊÒ¡¢¹ú·À²¿¡¢Ë¾·¨²¿ºÍ±í½»²¿¡£¡£¡£¡£¡£Å²Íþ°²È«Óë·þÎñ×éÖ¯(DSS)ÔÚ·¢ÏÖ¹¥»÷ÊÂÎñºó֪ͨÁ˹ú¶È°²È«¾Ö(NSM)£¬£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°µ÷²éÔÚ½øÐÐÖС£¡£¡£¡£¡£Å²ÍþÊý¾Ý±£»£»£»£»£»£»¤¾ÖÅú×¢£¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿Í¿ÉÄÜÒѾ½Ó¼û²¢ÇÔÈ¡ICTϵͳÖеÄÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£Ö»¹Ü±»¹¥»÷µÄƽ̨ÔÚÈÕ³£ÔË×÷ÖвûÑï×ųÁÒª×÷Ó㬣¬£¬£¬£¬£¬£¬£¬µ«Õâ´Î¹¥»÷²»»áµ¼Ö¹¤×÷»î¶¯ÖÕ³¡£¬£¬£¬£¬£¬£¬£¬£¬µ±²¿ÃÅÃŽ«³ÖÐøÕý³£¹¤×÷¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßËÆºõÀûÓÃÁËIvanti Endpoint Manager Mobile(EPMM)½â¾ö¹æ»®Öеķì϶£¬£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°·ì϶Òѱ»½¨¸´¡£¡£¡£¡£¡£
https://securityaffairs.com/148778/hacking/norwegian-ministries-cyber-attack.html
2¡¢ÑÅÂí¹þ¼ÓÄôó·Ö¹«Ë¾Ôâµ½Black ByteºÍAkiraµÄ¹¥»÷
¾Ý7ÔÂ25ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬ÑÅÂí¹þ¼ÓÄôó·Ö¹«Ë¾ÈÏ¿ÉÆäÔâµ½Ò»´ÎÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÁËδ¾ÊÚȨµÄ½Ó¼ûºÍÊý¾Ýй¶¡£¡£¡£¡£¡£¸Ã¹«Ë¾°µÊ¾ÆäѸËÙ²ÉÈ¡´ëÊ©¶ôÔì¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬²¢Í¨ÖªÁËÊÜÓ°ÏìµÄÓ×ÎÒ¡£¡£¡£¡£¡£6ÔÂ14ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾±»ÁÐÈëBlack ByteÀÕË÷ÍÅ»ïµÄ±»¹¥»÷ÕßÁÐ±í¡£¡£¡£¡£¡£ÉÏÖÜÎ壬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾Óֳʴ˿ÌAkiraÀÕË÷ÍÅ»ïµÄÍøÕ¾ÉÏ¡£¡£¡£¡£¡£×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬£¬£¬£¬×éÖ¯±»Á½¸ö·ÖÆçµÄÀÕË÷ÍÅ»ïÁгöµÄÇé¿öÔ½À´Ô½³£¼û£¬£¬£¬£¬£¬£¬£¬£¬ÕâÊǽñÄêµÄÒ»¸öÖØÒªÇ÷Ïò¡£¡£¡£¡£¡£
https://therecord.media/yamaha-confirms-cyberattack-after-multiple-ransomware-gangs-claim
3¡¢×êÑÐÈËÔ±·¢ÏÖTETRAÎÞÏßµç³ß¶ÈÖеķì϶TETRA:BURST
ýÌå7ÔÂ25Èճƣ¬£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÁ˵ØÃ漯ȺÎÞÏßµç(TETRA)³ß¶ÈÖб»Í³³ÆÎªTETRA:BURSTµÄ5¸ö·ì϶¡£¡£¡£¡£¡£ÕâЩ·ì϶±ðÀëΪCVE-2022-24400¡¢CVE-2022-24401¡¢CVE-2022-24402¡¢CVE-2022-24403ºÍCVE-2022-24404¡£¡£¡£¡£¡£ÆäÖÐ×îÑϳÁµÄÊÇCVE-2022-24401£¬£¬£¬£¬£¬£¬£¬£¬ÕâÊÇÒ»ÖÖoracle½âÃܹ¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Äܹ»ÔÚ²»ÖªÂ·¼ÓÃÜÃÜÔ¿µÄÇé¿öÏÂй¶Îı¾¡¢ÓïÒô»òÊý¾ÝͨѶ¡£¡£¡£¡£¡£Æä´ÎÊÇCVE-2022-24402£¬£¬£¬£¬£¬£¬£¬£¬Ëü¿É±»ÓÃÀ´×¢Èë¼à¿Ø¹¤ÒµÉ豸µÄÊý¾ÝÁ÷Á¿¡£¡£¡£¡£¡£×êÑÐÈËÔ±´òËãÔÚ¼´½«½øÐеÄBlack Hat USA 2023ÉÏÅû¶¹ØÓÚ·ì϶µÄ¸ü¶àÐÅÏ¢¡£¡£¡£¡£¡£
https://www.midnightblue.nl/tetraburst
4¡¢Ivanti´¹Î£¸üн¨¸´EPMMÖб»ÀûÓõÄÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶
7ÔÂ25ÈÕ±¨Â·³Æ£¬£¬£¬£¬£¬£¬£¬£¬Ivanti°ä²¼´¹Î£¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´ÆäEndpoint Manager Mobile(EPMM)ÒÆ¶¯É豸ÖÎÀíÈí¼þ£¨ÒÔǰ³ÆMobileIron Core£©Öб»ÀûÓõķì϶¡£¡£¡£¡£¡£ÕâÊÇÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2023-35078£©£¬£¬£¬£¬£¬£¬£¬£¬Î´¾ÊÚȨµÄÓû§¿ÉÔÚδÉí·ÝÑéÖ¤µÄÇé¿öϽӼûÀûÓ÷¨Ê½µÄÖ°ÄÜ»ò×ÊÔ´¡£¡£¡£¡£¡£CISA³Æ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß»¹Äܹ»ÀûÓø÷ì϶½øÐÐÆäËüÅäÖøü¸Ä£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬´´½¨EPMMÖÎÀíÕÊ»§¡£¡£¡£¡£¡£Õâ¼ÒÈí¼þ¹«Ë¾°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶Òѱ»»ý¼«ÀûÓ㬣¬£¬£¬£¬£¬£¬£¬µ«Ã»ÓÐй©Óйع¥»÷ÐÔÖÊ»ò¹¥»÷ÕßÉí·ÝµÄ¸ü¶àϸ½Ú¡£¡£¡£¡£¡£
https://thehackernews.com/2023/07/ivanti-releases-urgent-patch-for-epmm.html
5¡¢¹ú¼ÊÂÉËùOrrickй¶Óû§Êý¾ÝÓ°Ï쳬¹ý15Íò¸ö¿Í»§
¾Ý7ÔÂ24ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬¹ú¼ÊÂÉËùOrrickÔÚÏò½ü153000ÈË´«µÝһ·°²È«ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÊÂÎñµ¼Ö¶à¸ö¿Í»§Îļþй¶¡£¡£¡£¡£¡£OrrickÔÚÉêÃ÷Öгƣ¬£¬£¬£¬£¬£¬£¬£¬ËûÃÇÔÚ3ÔÂ13ÈÕ·¢ÏÖÁ˹¥»÷ÕßÕë¶ÔÆä±£Áô²¿Ãſͻ§¶ËÎļþµÄÎļþ´æ´¢É豸µÄ¹¥»÷¡£¡£¡£¡£¡£µ÷²éÈ·¶¨£¬£¬£¬£¬£¬£¬£¬£¬Î´¾ÊÚȨµÄ¹¥»÷ÕßÔÚ2ÔÂ28ÈÕÖÁ3ÔÂ7ÈÕ½Ó¼ûÁËÔ̺¬½¡È«ÐÅÏ¢ºÍÓ×ÎÒÉí·ÝÐÅÏ¢µÄ¿Í»§Îļþ¡£¡£¡£¡£¡£¸ÃÊÂÎñ²¢Î´µ¼ÖÂÈκοͻ§·þÎñ»òÔËÓªÖжϣ¬£¬£¬£¬£¬£¬£¬£¬Ò²Ã»Óз¢ÏÖÓëÕâ´Î¹¥»÷ÓйصÄÀÕË÷Èí¼þ¡£¡£¡£¡£¡£
https://www.bankinfosecurity.com/law-firm-hack-affects-victims-earlier-breach-again-a-22633
6¡¢ºÚ¿ÍÍÅ»ïSiegedSec¹«¿ª½ü1GBÓë±±Ô¼ÓйصÄÎļþ
ýÌå7ÔÂ25ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍÍÅ»ïSiegedSecÐû³Æ¹¥»÷Á˱±Ô¼£¬£¬£¬£¬£¬£¬£¬£¬²¢Ð¹Â¶Á˽ü1 GBµÄÊý¾Ý¡£¡£¡£¡£¡£SiegedSec³ÆÒÑÈëÇÖ±±Ô¼COIÃÅ»§ÍøÕ¾£¬£¬£¬£¬£¬£¬£¬£¬Ëæºó¹«¿ªÁËÊý°Ù·Ý¹©±±Ô¼¹ú¶ÈºÍºÏ×÷ͬ°éʹÓõÄÃô¸ÐÎļþ¡£¡£¡£¡£¡£ÆäÖк¬ÖÁÉÙ70Ãû±±Ô¼¹ÙÔ±µÄÐÕÃû¡¢ÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢°ì¹«µØÖ·ºÍ¾üÏεȡ£¡£¡£¡£¡£¾Ý³Æ£¬£¬£¬£¬£¬£¬£¬£¬¶Ô±±Ô¼COIÃÅ»§ÍøÕ¾µÄ¹¥»÷±ê־ȡSiegedSecÕ½ÊõµÄ²»ÐÝÉý¼¶¡£¡£¡£¡£¡£Ö»¹Ü±±Ô¼¹ÙÔ±ÉÐδ֤ʵÕâ´ÎÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬£¬µ«Ð¹Â¶µÄÎļþÔ̺¬Á˱±Ô¼¹ú¶È¼°ÆäºÏ×÷ͬ°éµÄ³ÁÒªÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬Òý·¢Á˶԰²È«Ó°ÏìµÄÓÇÓô¡£¡£¡£¡£¡£
https://www.hackread.com/siegedsec-hacktivist-hack-nato-data-leak/


¾©¹«Íø°²±¸11010802024551ºÅ