¼ÓÄô󺽿յÄϵͳ±»ÈëÇÖ²¿ÃÅÔ±¹¤µÄÓ×ÎÒÐÅϢй¶
°ä²¼¹¦·ò 2023-09-251¡¢¼ÓÄô󺽿յÄϵͳ±»ÈëÇÖ²¿ÃÅÔ±¹¤µÄÓ×ÎÒÐÅϢй¶
¾ÝýÌå9ÔÂ21ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬¼ÓÄô󺽿ÕÅû¶ÁËһ·°²È«ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬ÆäÖкڿ͡°¶ÌÔݵء±»ñµÃÁËÆäÄÚ²¿ÏµÍ³µÄ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬£¬Õâ´ÎÊÂÎñµ¼ÖÂÔ±¹¤µÄÓ×ÎÒÐÅÏ¢ºÍ²¿ÃżÍ¼й¶¡£¡£¡£¡£¡£µ«ÊǺ½°àÔËӪϵͳºÍÃæÏò¿Í»§µÄϵͳûÓÐÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬¿Í»§ÐÅϢҲûÓб»½Ó¼û¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬ËùÓÐϵͳ¾ùÒÑÈ«ÃæÔËÐС£¡£¡£¡£¡£²»¾Ãǰ£¬£¬£¬£¬£¬£¬£¬ÒòÔâµ½DDoS¹¥»÷£¬£¬£¬£¬£¬£¬£¬¼ÓÄôóÈ«¹ú¸÷µØµÄ±ßÚï²é³Õ¾Öµ»úͤµÄÍÆËã»ú³öÏÖ¹ÊÕÏ£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÈë¾³´î¿Í°ìÀíÊÖÐøµÄËÙ¶ÈÂýÁËÒ»¸ö¶àÓ×ʱ¡£¡£¡£¡£¡£
https://therecord.media/air-canada-limited-employee-info-accessed
2¡¢ALPHV³Æ¶Ô³µÔØÒôÏìÔì×÷ÉÌClarionÔâµ½µÄ¹¥»÷ÕÆ¹Ü
¾Ý9ÔÂ24ÈÕ±¨Â·£¬£¬£¬£¬£¬£¬£¬AlphvÐû³ÆÈëÇÖÁËÒôƵºÍ¶àýÌåÉ豸µÄÈ«ÇòÔì×÷ÉÌClarion¡£¡£¡£¡£¡£¸Ã¹«Ë¾¿ª·¢¡¢Ôì×÷ºÍÏúÊÛ¸÷Àà²úÆ·£¬£¬£¬£¬£¬£¬£¬Ô̺¬Æû³µµ¼º½ÏµÍ³¡¢ÒôƵϵͳ¡¢ÊÓÆµÏµÍ³ºÍºóÊÓÉãÏñÍ·¡£¡£¡£¡£¡£AlphvÔÚ9ÔÂ23ÈÕ½«ClarionÔö³¤µ½ÆäTorÍøÕ¾ÖУ¬£¬£¬£¬£¬£¬£¬³ÆÓйØÒµÎñºÍºÏ×÷ͬ°éµÄ»úÃÜÒѾÊý¾Ýй¶¡£¡£¡£¡£¡£¸ÃÍŻﻹ°µÊ¾Æä»ñµÃÁ˿ͻ§Êý¾Ý£¬£¬£¬£¬£¬£¬£¬²¢ÍþвÔÚ9ÔÂ25ÈÕ֮ǰ½«ÕâЩÊý¾ÝÏúÊÛ¸øµÚÈý·½¡£¡£¡£¡£¡£ºÚ¿Í°ä²¼ÁËһЩ±»µÁÎļþµÄ½ØÍ¼×÷Ϊ¹¥»÷µÄÖ¤¾Ý¡£¡£¡£¡£¡£
https://securityaffairs.com/151299/data-breach/alphv-ransomware-hacked-clarion.html
3¡¢SandmanÍÅ»ïÀûÓÃкóÃÅLuaDreamÖØÒªÕë¶ÔµçÐÅÌṩÉÌ
9ÔÂ21ÈÕ£¬£¬£¬£¬£¬£¬£¬SentinelLabs³ÆSandmanÀûÓÃÄ£¿£¿£¿£¿£¿£¿é»¯ÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þLuaDream¹¥»÷µçÕÛ·þÎñÌṩÉÌ¡£¡£¡£¡£¡£¸Ã»î¶¯ÓÚ8Ô·ݱ»·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÖж«¡¢Î÷Å·ºÍÄÏÑÇ¡£¡£¡£¡£¡£SandmanÀûÓÃLuaJITƽ̨²¿ÊðÁËÐÂÐͺóÃÅLuaDream£¬£¬£¬£¬£¬£¬£¬¸ÃºóÃÅÓÉ34¸ö×é¼þ×é³É£¬£¬£¬£¬£¬£¬£¬Ô̺¬13¸öÖ÷Ìâ×é¼þºÍ21¸öÖ§³Ö×é¼þ£¬£¬£¬£¬£¬£¬£¬ËüÃÇͨ¹ýffi¿âʹÓÃLuaJIT×Ö½ÚÂëºÍWindows API¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þµÄ¿ª·¢ËƺõºÜ»îÔ¾£¬£¬£¬£¬£¬£¬£¬°æ±¾ºÅΪ"12.0.2.5.23.29"£¬£¬£¬£¬£¬£¬£¬×îÔç¿É×·Òäµ½2022Äê6Ô¡£¡£¡£¡£¡£
https://www.sentinelone.com/labs/sandman-apt-a-mystery-group-targeting-telcos-with-a-luajit-toolkit/
4¡¢³¬¹ý200ÍòÃû°Í»ù˹̹¹«ÃñµÄÓ×ÎÒÐÅÏ¢±»ºÚ¿ÍÏúÊÛ
9ÔÂ21ÈÕ±¨Â·³Æ£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍÈëÇÖÁ˰ͻù˹̹Êý°Ù¼Ò²ÍÌüʹÓõĸöÈ˹«Ë¾Ôì×÷µÄÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬µ¼Ö³¬¹ý200Íò¹«ÃñÃæ¶Ô×ÅÓ×ÎÒÐÅϢй¶µÄ·çÏÕ¡£¡£¡£¡£¡£¸ÃÊÂÎñÓ°ÏìÁ˲ÍÌüµÄ¿Í»§£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶ÁËÐÅÓþ¿¨¡¢µØÖ·ºÍÒøÐоßÌåÐÅÏ¢µÈÊý¾Ý¡£¡£¡£¡£¡£ºÚ¿ÍÔÚÒÔ2±ÈÌØ±ÒµÄ¼ÛÖµÏúÊÛ±»µÁÊý¾Ý¡£¡£¡£¡£¡£ºÚ¿ÍÔÚµãÃûij¶¥¼¶²ÍÌüʱй©£¬£¬£¬£¬£¬£¬£¬ËûÃÇÒÑÈëÇÖÁË250¶à¼Ò²ÍÌüµÄÊý¾Ý¿â¡£¡£¡£¡£¡£ÁíÒ»·½Ã棬£¬£¬£¬£¬£¬£¬Áª¹úµ÷²éÈËÔ±°µÊ¾£¬£¬£¬£¬£¬£¬£¬ËûÃÇûÓÐÊÕµ½Õâ·½ÃæµÄͶËß¡£¡£¡£¡£¡£
https://en.dailypakistan.com.pk/21-Sep-2023/hackers-put-over-2-million-pakistanis-private-data-for-sale-after-restaurant-software-breach
5¡¢Unit 42Åû¶GelsemiumÕë¶Ô¶«ÄÏÑÇ»ú¹¹µÄ¹¥»÷»î¶¯
Unit 42ÔÚ9ÔÂ22ÈÕÅû¶ÁËGelsemiumÕë¶Ô¶«ÄÏÑǵ±¾Ö»ú¹¹µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¹¥»÷ÕßÔÚ±»Ï°È¾µÄWeb·þÎñÆ÷ÉÏ×°ÖÃÁ˶à¸öWeb shellÀ´»ñµÃϵͳ½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬£¬£¬Ô̺¬¹«¿ª¿ÉÓõÄreGeorg¡¢China ChopperºÍAspxSpy¡£¡£¡£¡£¡£¹¥»÷ÕßÓÃÓÚºáÏòÒÆ¶¯¡¢Êý¾ÝÍøÂçºÍÌáȨµÄ¹¤¾ßÔ̺¬OwlProxy¡¢SessionManager¡¢Cobalt Strike¡¢SpoolFoolºÍEarthWorm¡£¡£¡£¡£¡£×êÑÐÈËԱͨ¹ýOwlProxyºÍSessionManager´§¶ÈÕâ´Î¹¥»÷»î¶¯ÓëGelsemiumÓйء£¡£¡£¡£¡£
https://unit42.paloaltonetworks.com/rare-possible-gelsemium-attack-targets-se-asia/
6¡¢ESET³ÆStealth FalconÀûÓÃDeadglyph¹¥»÷Öж«µÄʵÌå
9ÔÂ22ÈÕ£¬£¬£¬£¬£¬£¬£¬ESET°ä²¼»ã±¨³ÆStealth FalconÀûÓÃDeadglyph¹¥»÷Öж«µÄʵÌå¡£¡£¡£¡£¡£DeadglyphµÄ¼Ü¹¹Óɶà¸öºÏ×÷×é¼þ×é³É£¬£¬£¬£¬£¬£¬£¬Ô̺¬±¾µØx64¶þ½øÔì×é¼þºÍ.NET·¨Ê½¼¯¡£¡£¡£¡£¡£Óë½öʹÓÃÒ»ÖÖ±à³Ì˵»°¿ª·¢µÄ³£¼û¶ñÒâÈí¼þ·ÖÆç£¬£¬£¬£¬£¬£¬£¬DeadglyphʹÓÃÁË·ÖÆçµÄ˵»°¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÒÔ¸½¼ÓÄ£¿£¿£¿£¿£¿£¿éµÄ´ó¾Ö´ÓC2¶¯Ì¬½Ó¹ÜºÅÁ£¬£¬£¬£¬£¬£¬»¹Ö§³Ö¶àÖÖÈÆ¹ýÖ°ÄÜ¡£¡£¡£¡£¡£¸Ã»ã±¨·ÖÎöµÄÊÇÕë¶ÔÖж«Ä³µÐÔÖʵÌåµÄ¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÉÐδȷ¶¨ºóÃŵľßÌå´«²¼·½Ê½¡£¡£¡£¡£¡£
https://www.welivesecurity.com/en/eset-research/stealth-falcon-preying-middle-eastern-skies-deadglyph/


¾©¹«Íø°²±¸11010802024551ºÅ