ÈÕ±¾SeikoÔâµ½BlackCat¹¥»÷Éè¼ÆÍ¼µÈÊý¾Ý¿ÉÄÜй¶

°ä²¼¹¦·ò 2023-08-23

1¡¢ÈÕ±¾SeikoÔâµ½BlackCat¹¥»÷Éè¼ÆÍ¼µÈÊý¾Ý¿ÉÄÜй¶


¾ÝýÌå8ÔÂ21ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬ £¬ÀÕË÷ÍÅ»ïBlackCatÐû³Æ¶ÔÈÕ±¾ÖÓ±íÔì×÷É̾«¹¤£¨Seiko£©Ôâµ½µÄ¹¥»÷ÕÆ¹Ü¡£¡£¡£¡£¡£¡£SeikoÊÇÊÀ½çÉÏ×î´óÇÒº¹Çà×îÓÆ¾ÃµÄÔì±íÉÌÖ®Ò»£¬£¬£¬£¬£¬£¬£¬ £¬ÄêÊÕÈ볬¹ý16ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚ8ÔÂ10ÈÕй©£¬£¬£¬£¬£¬£¬£¬ £¬Î´¾­ÊÚȨµÄµÚÈý·½½Ó¼ûÆä»ù´¡ÉèÊ©²¢¿ÉÄÜÇÔÈ¡ÁËÊý¾Ý¡£¡£¡£¡£¡£¡£21ÈÕ£¬£¬£¬£¬£¬£¬£¬ £¬BlackCat³Æ¶Ô´ËÊÂÕÆ¹Ü£¬£¬£¬£¬£¬£¬£¬ £¬°µÊ¾SeikoµÄÍøÂçºÍ²úÆ·µÄ°²È«ÐԽϵÍ¡£¡£¡£¡£¡£¡£¹¥»÷Õßй¶Á˳ö²ú´òËã¡¢Ô±¹¤»¤ÕÕ¡¢ÐÂÐͺŰ䲼´òËãºÍ³¢ÊÔÊÒ²âÊÔÁ˾ֵÈÄÚÈÝ£¬£¬£¬£¬£¬£¬£¬ £¬Ñù±¾»¹Ô̺¬¼¼ÊõµÀÀíͼºÍ¾«¹¤Íó±íÉè¼ÆÍ¼Ö½¡£¡£¡£¡£¡£¡£Éв»Ã÷ÏÔºÚ¿ÍÊÇ·ñÇÔÈ¡Á˹«Ë¾»úÃÜ»òרÀûµÈ֪ʶ²úȨ¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/149734/cyber-crime/blackcat-alphv-ransomware-group-seiko.html


2¡¢×êÑÐÈËÔ±·¢ÏÖ¿Éͨ¹ýTP-LinkÖÇÄܵÆÅÝÇÔÈ¡WiFiÃÜÂë


ýÌå8ÔÂ21ÈÕ±¨Â·³Æ£¬£¬£¬£¬£¬£¬£¬ £¬×êÑÐÈËÔ±ÔÚTP-Link Tapo L530EÖÇÄܵÆÅݺÍTP-Link TapoÀûÓ÷¨Ê½Öз¢ÏÖÁË4¸ö·ì϶¡£¡£¡£¡£¡£¡£µÚÒ»¸ö·ìÏ¶Éæ¼°Tapo L503EÉí·ÝÑéÖ¤²»µ±£¬£¬£¬£¬£¬£¬£¬ £¬¿ÉÔڻỰÃÜÔ¿»¥»»²½ÖèÖмÙÒâÉ豸¡£¡£¡£¡£¡£¡£µÚ¶þ¸ö·ì϶¿Éͨ¹ý±©Á¦ÆÆ½â»ò·´±àÒëTapoÀûÓ÷¨Ê½À´»ñÈ¡¸ÃÃÜÔ¿¡£¡£¡£¡£¡£¡£µÚÈý¸ö·ìÏ¶Éæ¼°¶Ô³Æ¼ÓÃܹý³ÌÖв»×ãËæ»úÐÔ£¬£¬£¬£¬£¬£¬£¬ £¬µÚËĸö·ì϶¿ÉÓÃÓÚ³Á·ÅÐÂÎÅ¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÀûÓõÚÒ»¸öºÍµÚ¶þ¸ö·ì϶¼ÙÒâµÆÅݲ¢¼ìË÷TapoÕÊ»§¾ßÌåÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ £¬¶øºóͨ¹ý½Ó¼ûTapoÀûÓ㬣¬£¬£¬£¬£¬£¬ £¬Äܹ»Ìáȡָ±êµÄWiFi SSIDºÍÃÜÂ룬£¬£¬£¬£¬£¬£¬ £¬²¢½Ó¼ûÏνӵ½¸ÃÍøÂçµÄÆäËüÉ豸¡£¡£¡£¡£¡£¡£¹©¸øḚ́µÊ¾½«ºÜ¿ì¶ÔÀûÓú͵ÆÅݹ̼þ½øÐн¨¸´¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/tp-link-smart-bulbs-can-let-hackers-steal-your-wifi-password/


3¡¢MFAÌṩÉÌDuo·þÎñÖжϵ¼ÖÂAzure AuthÉí·ÝÑéÖ¤ÃýÎó

 

¾Ý8ÔÂ21ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬ £¬CiscoÆìϵÄMFAÌṩÉÌDuo Security·þÎñÖжÏÊýÓ×ʱ£¬£¬£¬£¬£¬£¬£¬ £¬µ¼ÖÂAzure AuthÉí·ÝÑéÖ¤ÃýÎ󡣡£¡£¡£¡£¡£³¢ÊÔʹÓÃDuoµÇ¼ʱ»á³öÏÖ¡°ÏµÍ³¸ºÔعý³Á£¬£¬£¬£¬£¬£¬£¬ £¬ÇëÉԵȼ¸·ÖÖÓ£¬£¬£¬£¬£¬£¬£¬ £¬¶øºó³ÁÊÔ¡±µÄÌáÐÑ¡£¡£¡£¡£¡£¡£Æ¾¾Ý¸Ã¹«Ë¾µÄ×´Ì¬Ò³Ãæ£¬£¬£¬£¬£¬£¬£¬ £¬DuoµÄSSOºÍÍÆËÍ·þÎñÊܵ½´Ë¹ÊÕϵÄÓ°Ï죬£¬£¬£¬£¬£¬£¬ £¬ÆäÖ÷ÌâÉí·ÝÑéÖ¤·þÎñʹÓõÄHTTPS£¨TCP/443£©ºÍLDAP(S)£¨TCP/389£©¶Ëµã½öÊܵ½²¿ÃÅÖжϵÄÓ°Ïì¡£¡£¡£¡£¡£¡£½ØÖÁ21ÈÕ18:01£¬£¬£¬£¬£¬£¬£¬ £¬ÔÚÖжϽü9¸öÓ×ʱºó£¬£¬£¬£¬£¬£¬£¬ £¬Duo°µÊ¾Éí·ÝÑé֤ʧ°ÜµÄµ××ÓÎÊÌâÒѾ­½â¾ö¡£¡£¡£¡£¡£¡£

https://www.bleepingcomputer.com/news/technology/ongoing-duo-outage-causes-azure-auth-authentication-errors/


4¡¢·¨¹úÈøÌØÂ³Î¬¶ûÊÐÔâµ½MedusaµÄ¹¥»÷ĿǰÈÔÔÚ¸´Ô­ÖÐ

 

ýÌå8ÔÂ22Èճƣ¬£¬£¬£¬£¬£¬£¬ £¬·¨¹úÈøÌØÂ³Î¬¶ûÊÐÕý´ÓÉÏÖܵÄÍøÂç¹¥»÷ÖÐÖ𲽸´Ô­¡£¡£¡£¡£¡£¡£¹¥»÷²úÉúÓÚ8ÔÂ17ÈÕ£¬£¬£¬£¬£¬£¬£¬ £¬Õë¶ÔÊÐÕþÌüµÄ²¿ÃÅ·þÎñÆ÷¡£¡£¡£¡£¡£¡£¸ÃÊÐûÓÐ×¢Ã÷ÊÇ·ñÊÇÀÕË÷¹¥»÷£¬£¬£¬£¬£¬£¬£¬ £¬µ«°µÊ¾ËûÃǵı¸·ÝϵͳʹÆä¿ÉÄܼӿ츴ԭ¹ý³Ì¡£¡£¡£¡£¡£¡£Medusa³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü£¬£¬£¬£¬£¬£¬£¬ £¬²¢Ð¹Â©Æä»ñµÃÁ˸ÃÊеIJÆÕþÐÅÏ¢¡¢Ô¤Ëã¡¢ÒøÐоßÌåÐÅÏ¢¡¢Ò½ÁƼͼºÍ±¾µØÑ§ÌõÄÊý¾Ý¡£¡£¡£¡£¡£¡£×îÏȱ¨Â·ÕâÒ»ÊÂÎñµÄLe ParisienҲ֤ʵ£¬£¬£¬£¬£¬£¬£¬ £¬ÊÐÕþÔ±¹¤ÔÚËûÃǵÄϵͳÉÏ·¢ÏÖÁËMedusaÀÕË÷Èí¼þ¡£¡£¡£¡£¡£¡£


https://therecord.media/french-town-hit-by-cyberattack


5¡¢¶ò¹Ï¶à¶û¹ú¶ÈÑ¡¾Ù»ú¹¹±»¹¥»÷µ¼ÖÂÔÚÏßͶƱ³öÏÖÎÊÌâ


¾Ý8ÔÂ21ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬ £¬¶ò¹Ï¶à¶û¹ú¶ÈÑ¡¾Ù»ú¹¹±»¹¥»÷£¬£¬£¬£¬£¬£¬£¬ £¬µ¼ÖÂסÔÚ¹ú±íµÄ¹«ÃñÔÚÈ«¹úÑ¡¾ÙÖÐÎÞ·¨Í¶Æ±¡£¡£¡£¡£¡£¡£¶ò¹Ï¶à¶ûÔÚÉÏÖÜÈÕ½øÐÐÁËÈ«¹úÑ¡¾Ù£¬£¬£¬£¬£¬£¬£¬ £¬Í¶Æ±µ±Ì죬£¬£¬£¬£¬£¬£¬ £¬È±Ï¯Ñ¡ÃñÓ¿ÈëÉ罻ýÌåÆ½Ì¨£¬£¬£¬£¬£¬£¬£¬ £¬°µÊ¾ËûÃÇÎÞ·¨Í¨¹ýµ±¾Ö¿ª·¢µÄÔÚÏßϵͳͶƱ¡£¡£¡£¡£¡£¡£È«¹úÑ¡¾ÙίԱ»áÖ÷ϯ½«¸ÃÎÊÌâ¹é×ïÓÚÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬£¬ £¬µ«Ã»ÓÐй©¹¥»÷µÄÐÔÖÊ¡£¡£¡£¡£¡£¡£»£»£»£»£» £»¹°µÊ¾£¬£¬£¬£¬£¬£¬£¬ £¬Ô¶³ÌÐÅÏ¢´¦ÖÃͶƱƽ̨Ôâµ½ÁËÀ´×ÔÓ¡¶È¡¢ÃϼÓÀ­¹úºÍ°Í»ù˹̹µÈ7¸ö¹ú¶ÈµÄ¹¥»÷£¬£¬£¬£¬£¬£¬£¬ £¬Å·ÖÞÑ¡ÃñÊܵ½µÄÓ°ÏìÓÈΪÑϳÁ¡£¡£¡£¡£¡£¡£


https://therecord.media/ecuador-election-cyberattacks-absen


6¡¢SentinelOne°ä²¼XLoaderµÄmacOSбäÌåµÄ·ÖÎö»ã±¨


8ÔÂ21ÈÕ£¬£¬£¬£¬£¬£¬£¬ £¬SentinelOne°ä²¼Á˹ØÓÚXLoaderµÄmacOSбäÌåµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£XLoaderÊÇÒ»ÖÖMaaSÇÔÈ¡·¨Ê½ºÍ½©Ê¬ÍøÂ磬£¬£¬£¬£¬£¬£¬ £¬×Ô2015ÄêÒÔÀ´Ò»Ïò´æÔÚ¡£¡£¡£¡£¡£¡£Ð°汾µÄXLoader¼Ù×°³É°ì¹«³ö²úÁ¦ÀûÓÃOfficeNote£¬£¬£¬£¬£¬£¬£¬ £¬°ó¸¿ÔÚApple´ÅÅ̾µÏñOfficeNote.dmgÖУ¬£¬£¬£¬£¬£¬£¬ £¬Ê¹ÓÃÁËApple¿ª·¢ÈËÔ±µÄÊðÃû¡£¡£¡£¡£¡£¡£ÊðÃûÓÚ7ÔÂ17ÈÕÇ©Ê𣬣¬£¬£¬£¬£¬£¬ £¬ºóÀ´±»Apple³·Ïú¡£¡£¡£¡£¡£¡£Ô­À´µÄmacOS±äÌå±ØÒªJavaÔËÐÐʱ»·¾³£¬£¬£¬£¬£¬£¬£¬ £¬µ«AppleÊ®¶àÄêǰ¾ÍÖÕ³¡ÔÚMacÉÏÌṩJRE£¬£¬£¬£¬£¬£¬£¬ £¬Òò¶øÐ°汾Çл»µ½ÁËCºÍObjective CÀ´Ó¦¶Ô´ËÏÞ¶È¡£¡£¡£¡£¡£¡£


https://www.sentinelone.com/blog/xloaders-latest-trick-new-macos-variant-disguised-as-signed-officenote-app/