ÃÀ¹ú×î´ó²úȨ°ü¹Ü¹«Ë¾FNF±»AlphV¹¥»÷ϵͳÔÝʱ¹Ø±Õ

Ðû²¼Ê±¼ä 2023-11-27

1¡¢ÃÀ¹ú×î´ó²úȨ°ü¹Ü¹«Ë¾FNF±»AlphV¹¥»÷ϵͳÔÝʱ¹Ø±Õ


¾ÝýÌå11ÔÂ24ÈÕ±¨µÀ£¬ £¬£¬ £¬£¬ÃÀ¹ú×î´óµÄ²úȨ°ü¹Ü¹«Ë¾Fidelity National Financial(FNF)Ôâµ½AlphV(BlackCat) µÄ¹¥»÷¡£¡£¡£¡£¡£ÉÏÖÜÈý£¬ £¬£¬ £¬£¬AlphVÐû²¼ËûÃǹ¥»÷ÁËFNF£¬ £¬£¬ £¬£¬»¹½«FNFûÓн»Êê½ðµÄÔµ¹ÊÔ­Óɹé×ïÓÚMandiant¡£¡£¡£¡£¡£ÏÖÔÚ£¬ £¬£¬ £¬£¬AlphVûÓÐÐû²¼ÈκιØÓÚ¹¥»÷µÄ֤ʵ¡£¡£¡£¡£¡£FNFÍøÕ¾ÉÏҲûÓÐÈκμ£ÏóÅú×¢±£´æÊý¾Ýй¶ÎÊÌ⣬ £¬£¬ £¬£¬¿ÉÊÇËü¹Ø±ÕÁËÐí¶àÔÚÏßЧÀÍ£¬ £¬£¬ £¬£¬²¢ÌåÏÖËûÃÇÖªµÀijЩϵͳÒѱ»»á¼û¡£¡£¡£¡£¡£


https://www.databreaches.net/fidelity-national-financial-ransomware-incident-impacts-real-estate-closings/


2¡¢Í¨ÓÃµçÆøµÄ»á¼ûȨÏ޺ʹó×ÚÊý¾ÝÔÚºÚ¿ÍÂÛ̳±»³öÊÛ


¾Ý11ÔÂ25ÈÕ±¨µÀ£¬ £¬£¬ £¬£¬ÃÀ¹ú¿ç¹ú¹«Ë¾Í¨ÓÃµçÆø(GE)ÕýÔÚÊÓ²ìÆäÊý¾Ý±»µÁµÄÎÊÌâ¡£¡£¡£¡£¡£±¾ÔÂÔçЩʱ¼ä£¬ £¬£¬ £¬£¬ºÚ¿ÍIntelBrokerÔÚ°µÍøÒÔ500ÃÀÔªµÄ¼ÛÇ®³öÊÛGEµÄ»á¼ûȨÏÞ¡£¡£¡£¡£¡£È»ºó£¬ £¬£¬ £¬£¬¹¥»÷ÕßÔٴη¢Ìû³Æ£¬ £¬£¬ £¬£¬ËûÃÇÏÖÔÚͬʱ³öÊÛÍøÂç»á¼ûȨÏÞ£¨SSHºÍSVNµÈ£©ºÍ±»µÁÊý¾Ý£¬ £¬£¬ £¬£¬ÆäÖб»µÁÊý¾Ý°üÀ¨´ó×ÚÓëDARPAÏà¹ØµÄ¾üÊÂÐÅÏ¢¡¢Îļþ¡¢SQLÎļþºÍÎĵµµÈ¡£¡£¡£¡£¡£×÷Ϊй¶֤¾Ý£¬ £¬£¬ £¬£¬¹¥»÷Õß¹ûÕæÁËÊý¾Ý½ØÍ¼£¬ £¬£¬ £¬£¬°üÀ¨GE AviationsµÄÒ»¸öÊý¾Ý¿â£¬ £¬£¬ £¬£¬Éæ¼°¾üÊÂÏîÄ¿µÄÐÅÏ¢¡£¡£¡£¡£¡£GEÌåÏÖÒÑ»ñϤ´ËÊÂÎñ£¬ £¬£¬ £¬£¬²¢ÕýÔÚ¾ÙÐÐÊӲ졣¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/general-electric-investigates-claims-of-cyber-attack-data-theft/


3¡¢ITÌṩÉÌCTSÔâµ½ÀÕË÷¹¥»÷Ó¢¹úÊý°Ù¼ÒÂÉËùµÄÓªÒµÊÜÓ°Ïì


11ÔÂ24ÈÕ±¨µÀ³Æ£¬ £¬£¬ £¬£¬ÎªÓ¢¹ú״ʦÊÂÎñËùÌṩÍйÜЧÀ͵ÄÌṩÉÌ(MSP)CTSÔâµ½ÍøÂç¹¥»÷¡£¡£¡£¡£¡£Õâ¼ÒITЧÀÍÌṩÉÌÔÚÉÏÖÜÎåÐû²¼ÉùÃ÷³Æ£¬ £¬£¬ £¬£¬ËûÃÇÕýÔÚÂÄÀúÒ»´ÎЧÀÍÖÐÖ¹£¬ £¬£¬ £¬£¬Ó°ÏìÁËÏò²¿·Ö¿Í»§ÌṩµÄЧÀÍ¡£¡£¡£¡£¡£ËäÈ»CTSÉÐδ͸¶ÊÜÓ°Ïì¿Í»§µÄÊýÄ¿ºÍ¹¥»÷ÐÔ×Ó£¬ £¬£¬ £¬£¬µ«ÏÖÔÚµÄÐÅÏ¢Åú×¢ÕâÊÇÒ»´ÎÀÕË÷¹¥»÷¡£¡£¡£¡£¡£ÍâµØÃ½Ì屨µÀ£¬ £¬£¬ £¬£¬Ô¼80ÖÁ200¼Ò״ʦÊÂÎñËù¿ÉÄÜÊܵ½Ó°Ïì¡£¡£¡£¡£¡£ÔÚÕâÒ»ÖÜÀ £¬£¬ £¬£¬ÓÉÓÚЧÀÍÖÐÖ¹£¬ £¬£¬ £¬£¬ÈËÃÇÎÞ·¨¹ºÖûò³öÊÛ·¿²ú¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬ £¬£¬ £¬£¬ÓÐÐÅÐÄÄܹ»»Ö¸´Ð§ÀÍ£¬ £¬£¬ £¬£¬µ«ÎÞ·¨È·¶¨¡°ÖÜÈ«»Ö¸´¡±µÄʱ¼ä¡£¡£¡£¡£¡£


https://therecord.media/uk-cyberattack-msp-cts-law-firms


4¡¢Çå¾²»ú¹¹Åû¶LazarusʹÓÃMagicLine4NXÎó²îµÄ¹©Ó¦Á´¹¥»÷


ýÌå11ÔÂ25Èճƣ¬ £¬£¬ £¬£¬Çå¾²»ú¹¹NCSCºÍNISÁªºÏÐû²¼Í¨¸æ³ÆLazarusÕýÔÚʹÓÃMagicLine4NXÖеÄodayÖ´Ðй©Ó¦Á´¹¥»÷¡£¡£¡£¡£¡£MagicLine4NXÊÇÒ»¿îÇå¾²ÈÏÖ¤Èí¼þ£¬ £¬£¬ £¬£¬¹¥»÷±¬·¢ÓÚ½ñÄê3Ô·Ý¡£¡£¡£¡£¡£¹¥»÷Á´Ê¼ÓÚË®¿Ó¹¥»÷£¬ £¬£¬ £¬£¬¹¥»÷ÕßÈëÇÖÁËÒ»¼ÒýÌåÍøÕ¾£¬ £¬£¬ £¬£¬²¢½«¶ñÒâ¾ç±¾Ö²È뵽һƪÎÄÕÂÖУ¬ £¬£¬ £¬£¬ÕâЩ¾ç±¾½öÕë¶ÔÌØ¶¨IP¹æÄ£µÄ»á¼ûÕß¡£¡£¡£¡£¡£µ±Óû§Ê¹ÓÃMagicLine4NX»á¼û±»Ñ¬È¾ÍøÕ¾Ê±£¬ £¬£¬ £¬£¬¶ñÒâ´úÂë¾Í»áÖ´ÐдӶøÍêÈ«¿ØÖÆÏµÍ³¡£¡£¡£¡£¡£Ëæºó£¬ £¬£¬ £¬£¬¹¥»÷ÕßʹÓÃϵͳÎó²î´ÓÁªÍøµÄPCÉϲ»·¨»á¼ûЧÀÍÆ÷£¬ £¬£¬ £¬£¬²¢ÀÄÓÃÁªÍøÏµÍ³µÄÊý¾Ýͬ²½¹¦Ð§½«¶ñÒâ´úÂëÈö²¥µ½ÓªÒµ¶ËЧÀÍÆ÷£¬ £¬£¬ £¬£¬×îÖÕÖ¼ÔÚÇÔÊØÐÅÏ¢¡£¡£¡£¡£¡£


https://securityaffairs.com/154765/apt/lazarus-magicline4nx-supply-chain-attack.html


5¡¢Granger Medical ClinicÔâµ½NoEscape¹¥»÷¾Ü¸¶Êê½ð


ýÌå11ÔÂ26ÈÕ±¨µÀ³Æ£¬ £¬£¬ £¬£¬ÀÕË÷ÍÅ»ïNoEscapeÓÚ11ÔÂ24ÈÕ½«ÓÌËûÖݵÄGranger Medical ClinicÌí¼Óµ½ÆäÍøÕ¾ÖС£¡£¡£¡£¡£¹¥»÷ÕßÉù³ÆÓµÓÐÁè¼Ý35GBµÄÊý¾Ý£¬ £¬£¬ £¬£¬°üÀ¨±£ÃÜЭæÅºÍÌõÔ¼¡¢NDA¡¢SSN¿¨¡¢É󼯡¢±¨¸æ¡¢²ÆÎñ¡¢Êý¾Ý¿â¡¢Ô¤ËãºÍÒøÐÐÓªÒµµÈÏà¹ØÎļþ¡£¡£¡£¡£¡£×÷Ϊ֤¾Ý£¬ £¬£¬ £¬£¬NoEscape»¹ÌṩÁËÎļþÊ÷ºÍÆÁÄ»½ØÍ¼¡£¡£¡£¡£¡£Ì¸ÅÐËÆºõÆÆËéÁË£¬ £¬£¬ £¬£¬Granger¾öÒé²»¸¶¿î¡£¡£¡£¡£¡£NoEscapeÍþвÔÚ24СʱÄÚÖ§¸¶70ÍòÃÀÔªÊê½ð£¬ £¬£¬ £¬£¬²»È»½«¹ûÕæËùÓÐÊý¾Ý¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚ25ÈÕ¼ì²é·¢Ã÷£¬ £¬£¬ £¬£¬¹¥»÷ÕßÒѾ­Ð¹Â¶ÁËÁè¼Ý31 GBµÄÎļþ¡£¡£¡£¡£¡£


https://www.databreaches.net/ransomware-group-leaks-data-allegedly-from-granger-medical-clinic/


6¡¢Check Point·¢Ã÷ʹÓÃSysJokerºóÃŹ¥»÷ÒÔÉ«ÁеĻ


11ÔÂ23ÈÕ£¬ £¬£¬ £¬£¬Check PointÅû¶ÁËʹÓÃSysJokerºóÃŹ¥»÷ÒÔÉ«ÁеĻ¡£¡£¡£¡£¡£SysJokerÓÚ2021Äê12ÔÂÊ״α»·¢Ã÷£¬ £¬£¬ £¬£¬¸ÃºóÃÅÄܹ»Ñ¬È¾Windows¡¢macOSºÍLinuxϵͳ£¬ £¬£¬ £¬£¬Æäʱ·¢Ã÷µÄÊÇC++°æ±¾¡£¡£¡£¡£¡£Õë¶ÔÒÔÉ«ÁеĹ¥»÷ÖÐʹÓõİ汾ÊÇRust¿ª·¢µÄ£¬ £¬£¬ £¬£¬ÕâÅú×¢¸Ã¶ñÒâÈí¼þÊÇÖØÐÂ×îÏÈÖØÐ´£¬ £¬£¬ £¬£¬ÓÚ½ñÄê10ÔÂ12ÈÕÊ×´ÎÌá½»µ½VirusTotal¡£¡£¡£¡£¡£±ðµÄ£¬ £¬£¬ £¬£¬¸Ã¶ñÒâÈí¼þ½ÓÄÉËæ»ú˯Ãß¾àÀëºÍÖØ´óµÄ×Ô½ç˵¼ÓÃÜ´úÂë×Ö·û´®À´Èƹý¼ì²âºÍÆÊÎö¡£¡£¡£¡£¡£


https://research.checkpoint.com/2023/israel-hamas-war-spotlight-shaking-the-rust-off-sysjoker/