ºÚ¿ÍÔÚÈȵãºÚ¿ÍÂÛÌÓð»¯ù³Æ¿ÇÅÆÊý¾ÝÔ⵽й¶
°ä²¼¹¦·ò 2024-05-315ÔÂ30ÈÕ£¬£¬£¬£¬£¬ÁîÈËÕ𾪵ÄÊÇ£¬£¬£¬£¬£¬Ò»ÃûÍþвÐÐΪÕßÉæÏÓй¶ÁËÊÀ½çµ±ÏÈÄÜÔ´¹«Ë¾Ö®Ò»¿ÇÅÆµÄÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£Æ¾¾Ý Data Web Informer µÄÍÆÎÄ£¬£¬£¬£¬£¬2024 Äê 5 ÔµÄÊý¾Ý±»°ä²¼ÔÚÒ»¸öÊ¢ÐеĺڿÍÂÛ̳ÉÏ£¬£¬£¬£¬£¬Òý·¢ÁËÈËÃǶÔÍøÂ簲ȫºÍÊý¾ÝÒþÖÔµÄÑϳÁÓÇÓô¡£¡£¡£¡£¡£¾Ý±¨Â·£¬£¬£¬£¬£¬Ð¹Â¶µÄÐÅÏ¢Ô̺¬´óÁ¿Ó×ÎÒÐÅÏ¢ºÍÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£Ð¹Â¶µÄÊý¾ÝÔ̺¬£º¹ºÎïÕß´úÂë¡¢Ãû×Ö¡¢ÐÕÊÏ¡¢×´Ì¬¡¢¹ºÎïÕßµç×ÓÓʼþ¡¢ÁªÏµÊÖ»ú¡¢ÓÊÕþ±àÂë¡¢»¨ÃÛ¡¢½¼Çø¡¢ÖÝ¡¢Õ¾µãµØÖ·¡¢½¼Çø 1¡¢¹ú¶È¡¢Õ¾µãÃû³Æ¡¢ÉϴεǼ¡¢¸¶¿îºÍлá±àºÅ¡£¡£¡£¡£¡£Õâ´ÎйÃÜÊÂÎñ¿ÉÄÜ»á¶Ô¿ÇÅÆ¼°Æä¿Í»§Ôì³ÉÑϳÁÓ°Ïì¡£¡£¡£¡£¡£Ð¹Â¶Èç´Ë¾ßÌåµÄÓ×ÎÒÐÅÏ¢¿ÉÄܻᵼÖÂÉí·Ý͵ÇÔ¡¢½ðÈÚÚ²ÆºÍÆäËû¶ñÒâ»î¶¯¡£¡£¡£¡£¡£½¨Òé¿Í»§Ç×êÇ¼à¿ØËûÃǵÄÕË»§²¢Á¢¼´»ã±¨¿ÉÒɻ¡£¡£¡£¡£¡£½ØÖÁĿǰ£¬£¬£¬£¬£¬¿ÇÅÆÉÐδ¾ÍÕâ´ÎйÃÜÊÂÎñ°ä·¢¹Ù·½ÉêÃ÷¡£¡£¡£¡£¡£²»Í⣬£¬£¬£¬£¬¸Ã¹«Ë¾Ô¤¼Æ½«Æô¶¯ÄÚ²¿µ÷²é£¬£¬£¬£¬£¬²¢ÓëÍøÂ簲ȫר¼ÒºÏ×÷£¬£¬£¬£¬£¬ÆÀ¹ÀÎ¥¹æµÄˮƽ²¢¼õÇáÈκÎDZÔÚÇÖº¦¡£¡£¡£¡£¡£
https://gbhackers.com/claiming-shell-data-breach/
2. TicketmasterÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬³¬¹ý5 ÒÚÓû§Êý¾ÝÐÅϢй¶
5ÔÂ30ÈÕ£¬£¬£¬£¬£¬¾Ý±¨Â·£¬£¬£¬£¬£¬±¾ÖÜÔÚµ÷²éµÄÒ»Â·ÍøÂçÊÂÎñÖУ¬£¬£¬£¬£¬³¬¹ý 5 ÒÚ Ticketmaster Óû§µÄÓ×ÎÒºÍÐÅÓþ¿¨Êý¾ÝÔ⵽й¶¡£¡£¡£¡£¡£¾Ý±¨Â·£¬£¬£¬£¬£¬°Ä´óÀûÑǵ±¾ÖÔÚÓë Live Nation ºÍ Ticketmaster ºÏ×÷½â¾ö´ËÊÂÎñ£¬£¬£¬£¬£¬µ«½ØÖÁÖÜÈýÉÏÎ磬£¬£¬£¬£¬Åû¶µÄϸ½ÚÓÐÏÞ¡£¡£¡£¡£¡£¾Ý¸ÃÐÂÎÅýÌ屨·£¬£¬£¬£¬£¬°Ä´óÀûÑÇÄÚÕþ²¿Í¨Öª ABC£¬£¬£¬£¬£¬ËûÃÇÔÚÓë Ticketmaster ºÏ×÷Ïàʶ´ËÊ¡£¡£¡£¡£¡£Ticketmaster »òÆäĸ¹«Ë¾ÉÐδ¾Í´Ëʰ䷢ÈκÎÉêÃ÷¡£¡£¡£¡£¡£ºÚ¿Í×éÖ¯ ShinyHunters Ðû³ÆÒÑÆÆ½â Ticketmaster ϵͳ²¢»ñÈ¡ÁËÔ¼ 1.3 TB µÄÊý¾Ý£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬ÐÕÃû¡¢µØÖ·¡¢ÐÅÓþ¿¨ºÅ¡¢µç»°ºÅÂëºÍ¸¶¿î¾ßÌåÐÅÏ¢¡£¡£¡£¡£¡£Ìý˵ÕâЩÐÅÏ¢ÔÚ°µÍøÉÏÏúÊÛ£¬£¬£¬£¬£¬Òª¼Û 50 ÍòÃÀÔª¡£¡£¡£¡£¡£ÔçÆÚ»ã±¨ÏÔʾ£¬£¬£¬£¬£¬Óû§Êý¾ÝÉæ¼°È«Çò 5.6 ÒÚ¿Í»§£¬£¬£¬£¬£¬µ«Éв»Ã÷ÏÔÄÄЩÊг¡Êܵ½Ó°Ï죨»òÊÜÓ°ÏìµÄÏû·ÑÕßÖÐÓм¸¶àÀ´×ÔÄÄЩÊг¡£¡£¡£¡£¡£©¡£¡£¡£¡£¡£ÏÔÈ»£¬£¬£¬£¬£¬Ë¼¿¼µ½Éæ¼°µÄ¸ß¶ÈÃô¸ÐÊý¾Ý£¬£¬£¬£¬£¬ÈκÎÊÜÓ°ÏìµÄÏû·ÑÕߵķçÏÕ¶¼¼«¶È¸ß¡£¡£¡£¡£¡£
https://www.ticketnews.com/2024/05/ticketmaster-hack-data-of-half-a-billion-users-up-for-ransom/
3. XWorm v5.6 ¶ñÒâÈí¼þͨ¹ý Webhards ½øÐд«²¼
5ÔÂ30ÈÕ£¬£¬£¬£¬£¬°²³¢ÊÔÊÒ°²È«µý±¨ÖÐÐÄ£¨ASEC£©ÔÚ¼à¿Øº«¹ú¶ñÒâÈí¼þµÄ´«²¼Ô´Ê±£¬£¬£¬£¬£¬×î½ü·¢ÏÖ¼Ù×°³É³ÉÈËÓÎÏ·µÄXWorm v5.6¶ñÒâÈí¼þÔÚͨ¹ýÍøÂçÓ²Å̽øÐд«²¼¡£¡£¡£¡£¡£ÍøÂçÓ²Å̺ÍÖÖ×ÓÊǺ«¹ú¶ñÒâÈí¼þ´«²¼µÄ³£ÓÃÆ½Ì¨¡£¡£¡£¡£¡£¹¥»÷Õßͨ³£Ê¹ÓÃÈÝÒ×»ñµÃµÄ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬ÀýÈç njRAT ºÍ UDP RAT£¬£¬£¬£¬£¬²¢½«Æä¼Ù×°³ÉÔ̺¬ÓÎÏ·»ò³ÉÈËÄÚÈÝÔÚÄÚµÄÕý³£·¨Ê½½øÐзַ¢¡£¡£¡£¡£¡£XWorm v5.6 Ò²Äܹ»´Ó GitHub µÈƽ̨ÇáËÉ»ñÈ¡¡£¡£¡£¡£¡£ÏÂÔØ²¢½âѹÓÎÏ·Îļþºó£¬£¬£¬£¬£¬»áµÃµ½ Start.exe¡£¡£¡£¡£¡£¹ÌÈ»¿´ÆðÀ´ÏñÊǺϷ¨µÄÓÎÏ·Æô¶¯Æ÷Îļþ£¬£¬£¬£¬£¬µ«Ö´ÐÐÓÎÏ·µÄ .exe ÎļþÊǵ¥¶ÀÌìÉú²¢ÔËÐе쬣¬£¬£¬£¬²¢ÇÒ¼Ù×°³É SoundP2.muc µÄ¼ÓÔØ·¨Ê½¶ñÒâÈí¼þÒ²»á±»Ö´ÐС£¡£¡£¡£¡£Ö´ÐÐ Start.exe ²»»áÁ¢¼´ÔËÐжñÒâÈí¼þ»òÓÎÏ·£»£»£»£»£»£»£»ËüÃÇ»áÔÚÄú°´Ï¡°ÆðÍ·ÓÎÏ·£¡¡±°´Å¥Ê±Ö´ÐС£¡£¡£¡£¡£ÕâÖÖÕ½ÊõËÆºõÊÇΪÁËÈÆ¹ýɳºÐģʽ¡£¡£¡£¡£¡£SoundP2.muc Ò²±»¸´Ôì²¢Õ³Ìùµ½ Windows Îļþ¼ÐÖУ¬£¬£¬£¬£¬²¢Ôö³¤µ½×¢²á±íÖÐÒÔ±ã×Ô¶¯Ö´ÐС£¡£¡£¡£¡£
https://asec.ahnlab.com/en/66099/
4. PyPI¶ñÒâÈí¼þPytoileurÇÔÈ¡¼ÓÃÜÇ®±Ò²¢Èƹý¼ì²â
5ÔÂ31ÈÕ£¬£¬£¬£¬£¬ÍøÂ簲ȫ×êÑÐÈËÔ±·¢ÏÖÁË Python Èí¼þ°üË÷Òý£¨PyPI£©ÉϵĶñÒâÈí¼þ°üpytoileur¡£¡£¡£¡£¡£¸ÃÈí¼þ°ü¼Ù×°³ÉÓà Python ±àдµÄ API ÖÎÀí¹¤¾ß£¬£¬£¬£¬£¬°µ²ØÁËÏÂÔØºÍ×°ÖÃľÂí Windows ¶þ½øÔìÎļþµÄ´úÂë¡£¡£¡£¡£¡£ÕâЩ¶þ½øÔìÎļþ¿ÉÄܽøÐмල¡¢ÊµÏÖÓÆ¾ÃÐÔ²¢ÇÔÈ¡¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£¸ÃÈí¼þ°ü±» Sonatype µÄ×Ô¶¯¶ñÒâÈí¼þ¼ì²âϵͳ·¢ÏÖ£¬£¬£¬£¬£¬²¢ÔÚ±»ÏóÕ÷ºóѸËÙ±»É¾³ý¡£¡£¡£¡£¡£pytoileur Èí¼þ°üÔÚ±»ÒƳýǰÒѱ»ÏÂÔØ 264 ´Î£¬£¬£¬£¬£¬ËüʹÓÃÁ˺ýŪÐÔ¼¼ÊõÀ´Ô¤·À±»¼ì²âµ½¡£¡£¡£¡£¡£ËüµÄÔªÊý¾Ý½«ÆäÃèÊöΪ¡°¿áìÅÈí¼þ°ü¡±£¬£¬£¬£¬£¬Ê¹ÓÃÒ»ÖÖÕ½Êõ£¬£¬£¬£¬£¬¼´¸øÈí¼þ°üÌùÉÏÎüÒýÈ˵ÄÍÌÍÂÃèÊö±êÇ©£¬£¬£¬£¬£¬ÒÔÓÕʹ¿ª·¢ÈËÔ±ÏÂÔØËüÃÇ¡£¡£¡£¡£¡£Sonatype ½ñÌì°ä²¼µÄÒ»·ÝÕ÷ѯ»ã±¨ÖÐÃèÊöÁ˽øÒ»²½µÄ²é³£¬£¬£¬£¬£¬·¢ÏÖÈí¼þ°ü×°ÖÃÎļþÖаµ²Ø×Å´óÁ¿¿Õ¸ñËù¸²¸ÇµÄ´úÂë¡£¡£¡£¡£¡£¸Ã´úÂëÖ´ÐÐÁËÒ»¸ö base64 ±àÂëµÄÓÐЧ¸ºÔØ£¬£¬£¬£¬£¬¸Ã¸ºÔØ´Ó±í²¿·þÎñÆ÷¼ìË÷Á˶ñÒâ¿ÉÖ´ÐÐÎļþ¡£¡£¡£¡£¡£ÏÂÔØµÄ¶þ½øÔìÎļþ¡°Runtime.exe¡±ÀûÓà PowerShell ºÍ VBScript ºÅÁî½øÐÐ×ÔÎÒ×°Ö㬣¬£¬£¬£¬È·±£ÔÚÊÜϰȾµÄϵͳÖÐÓÆ¾Ã´æÔÚ¡£¡£¡£¡£¡£Ëüѡȡ¸÷Àà·´¼ì²â´ëÊ©À´Ìӱܰ²È«×êÑÐÈËÔ±µÄ·ÖÎö¡£¡£¡£¡£¡£
https://www.infosecurity-magazine.com/news/pypi-malware-pytoileur-steals/
5. °ÍÎ÷ÒøÐгÉΪ AllaKore RAT бäÖÖ AllaSenha µÄÖ¸±ê
5ÔÂ29ÈÕ£¬£¬£¬£¬£¬°ÍÎ÷ÒøÐлú×é³ÉΪлµÄÖ¸±ê£¬£¬£¬£¬£¬¸Ã»î¶¯·Ö·¢»ùÓÚ Windows µÄAllaKoreÔ¶³Ì½Ó¼ûľÂí (RAT)µÄ¶¨Ôì±äÖÖAllaSenha¡£¡£¡£¡£¡£·¨¹úÍøÂ簲ȫ¹«Ë¾ HarfangLabÔÚÒ»·Ý¼¼Êõ·ÖÎöÖаµÊ¾£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ¡°×¨ÃÅÓÃÓÚÇÔÈ¡½Ó¼û°ÍÎ÷ÒøÐÐÕË»§ËùÐèµÄƾ֤£¬£¬£¬£¬£¬²¢ÀûÓà Azure ÔÆ×÷ΪºÅÁîºÍ½ÚÔì (C2) »ù´¡ÉèÊ©¡±¡£¡£¡£¡£¡£Õâ´Î¹¥»÷µÄÖ¸±êÔ̺¬°ÍÎ÷ÒøÐÓ×¢Bradesco¡¢Èø·òÀÒøÐÓ×¢Caixa Econ?mica Federal¡¢Ita¨² Unibanco¡¢Sicoob ºÍ Sicredi µÈÒøÐС£¡£¡£¡£¡£¹ÌÈ»ÉÐδµÃµ½Ã÷ȷ֤ʵ£¬£¬£¬£¬£¬µ«×î³õµÄ½Ó¼ûÔØÌåÖ¸ÏòÁË´¹µöÓʼþÖÐʹÓöñÒâÁ´½Ó¡£¡£¡£¡£¡£¹¥»÷µÄÆðµãÊÇÒ»¸ö¶ñÒâµÄ Windows ¿ì½Ý·½Ê½ (LNK) Îļþ£¬£¬£¬£¬£¬¸ÃÎļþ¼Ù×°³É PDF Îĵµ£¨¡°NotaFiscal.pdf.lnk¡±£©£¬£¬£¬£¬£¬ÖÁÉÙ×Ô 2024 Äê 3 ÔÂÆðÍйÜÔÚ WebDAV ·þÎñÆ÷ÉÏ¡£¡£¡£¡£¡£»£»£»£»£»£»£»¹ÓÐÖ¤¾ÝÅú×¢£¬£¬£¬£¬£¬¸Ã»î¶¯±³ºóµÄÍþвÐÐΪÕßÖ®Ç°ÔøÀÄÓà Autodesk A360 Drive ºÍ GitHub µÈºÏ·¨·þÎñÀ´ÍйÜÓÐЧ¸ºÔØ¡£¡£¡£¡£¡£
https://thehackernews.com/2024/05/brazilian-banks-targeted-by-new.html
6. ÀûÓÃDora RATÕë¶Ôº«¹úÆóÒµ£¨Andariel Group£©µÄAPT¹¥»÷
5ÔÂ30ÈÕ£¬£¬£¬£¬£¬AhnLab °²È«µý±¨ÖÐÐÄ (ASEC) ×î½ü·¢ÏÖÁËÕë¶Ôº«¹ú¹«Ë¾ºÍ»ú¹¹µÄ Andariel APT ¹¥»÷°¸Àý¡£¡£¡£¡£¡£Ö¸±ê×éÖ¯Ô̺¬º«¹úµÄ½ÌÓý»ú¹¹ÒÔ¼°Ôì×÷ºÍ¹¹ÖþÆóÒµ¡£¡£¡£¡£¡£¹¥»÷ʹÓÃÁ˺óÃÁ÷ÅÉļüÅ̼ͼÆ÷¡¢ÐÅÏ¢ÇÔÈ¡·¨Ê½ºÍ´úÀí¹¤¾ß¡£¡£¡£¡£¡£ÍþвÐÐΪÕß¿ÉÄÜʹÓÃÕâЩ¶ñÒâÈí¼þÀ´½ÚÔìºÍÇÔÈ¡ÊÜϰȾϵͳµÄÊý¾Ý¡£¡£¡£¡£¡£Õâ´Î¹¥»÷ʹÓÃÁË Andariel ¼¯ÍÅ´Óǰ°¸ÀýÖз¢ÏֵĶñÒâÈí¼þ£¬£¬£¬£¬£¬ÆäÖÐ×îÒýÈËÖõÖ÷ÕÅÊÇ Nestdoor£¬£¬£¬£¬£¬ÕâÊDZ¾ÎÄÖÐÌáµ½µÄºóÃÅ¡£¡£¡£¡£¡£ÆäËû°¸ÀýÔ̺¬Ôö³¤ Web Shell¡£¡£¡£¡£¡£Lazarus ¼¯ÍÅÏÈǰ¹¥»÷Öз¢ÏֵĴúÀí¹¤¾ßÒ²±»Ê¹Ó㬣¬£¬£¬£¬Ö»¹ÜËüÃǵÄÎļþÓ뵱ǰ°¸Àý²¢²»Ò»Ñù¡£¡£¡£¡£¡£ÔÚ¹¥»÷¹ý³ÌÖеĶà¶àÖ¤¾ÝÖУ¬£¬£¬£¬£¬Ò»¸öÏÖʵ±»Ö¤ÊµµÄ°¸ÀýÉæ¼°Ê¹ÓÃÔËÐÐ Apache Tomcat ·þÎñÆ÷µÄ Web ·þÎñÆ÷·Ö·¢¶ñÒâÈí¼þ¡£¡£¡£¡£¡£ÓÉÓÚÓÐÎÊÌâµÄϵͳÔËÐеÄÊÇ 2013 °æ Apache Tomcat£¬£¬£¬£¬£¬Òò¶øÈÝÒ×Êܵ½¸÷Àà·ì϶¹¥»÷¡£¡£¡£¡£¡£ÍþвÐÐΪÕßʹÓøà Web ·þÎñÆ÷×°ÖúóÃÅ¡¢´úÀí¹¤¾ßµÈ¡£¡£¡£¡£¡£
https://asec.ahnlab.com/en/66088/


¾©¹«Íø°²±¸11010802024551ºÅ