T-MobileÒòÈ¥ÄêÊý¾Ýй¶ÊÂÎñÅâ³¥ÆäÓû§3.5ÒÚÃÀÔª

Ðû²¼Ê±¼ä 2022-07-26

1¡¢T-MobileÒòÈ¥ÄêÊý¾Ýй¶ÊÂÎñÅâ³¥ÆäÓû§3.5ÒÚÃÀÔª

      

¾Ý7ÔÂ24ÈÕ±¨µÀ £¬£¬£¬£¬£¬£¬T-MobileÒÑÔÞ³ÉÏò½ü7700ÍòÓû§Å⸶3.5ÒÚÃÀÔª £¬£¬£¬£¬£¬£¬ÒÔ½â¾ö¹ØÓڸù«Ë¾2021ÄêÊý¾Ýй¶ÊÂÎñµÄÕûÌåËßËÏ¡£¡£¡£¡£¡£¡£¡£¡£È¥Äê8ÔÂ·Ý £¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾µÄϵͳÔâµ½ºÚ¿ÍÈëÇÖ £¬£¬£¬£¬£¬£¬Óû§µÄÉç»áÇå¾²ºÅÂë¡¢ÐÕÃû¡¢µØµãºÍ¼ÝʻִÕÕµÈÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤ÉÏÖÜÎåµÄÎļþ £¬£¬£¬£¬£¬£¬3.5×ʽð½«ÓÃÓÚÖ§¸¶ÊÜÓ°ÏìÓû§µÄË÷Åâ¡¢Ô­¸æ×´Ê¦µÄÖ´·¨ÓöÈÒÔ¼°ÖÎÀíÏ¢ÕùµÄÓöȡ£¡£¡£¡£¡£¡£¡£¡£T-Mobile»¹ÌåÏÖ½«ÔÚ2022ÄêºÍ2023ÄêÆÆ·Ñ1.5ÒÚÃÀÔªÀ´ÔöÇ¿ÆäÊý¾ÝÇå¾²ºÍÆäËüÊÖÒÕ¡£¡£¡£¡£¡£¡£¡£¡£


https://www.securityweek.com/t-mobile-settles-pay-350m-customers-data-breach


2¡¢ÀÕË÷ÍÅ»ïLockBitÉù³ÆÒÑÇÔÈ¡Òâ´óÀû˰Îñ»ú¹¹78 GBÊý¾Ý

      

ýÌå7ÔÂ25ÈÕ±¨µÀ £¬£¬£¬£¬£¬£¬Òâ´óÀûÕýÔÚÊÓ²ìÆä˰Îñ»ú¹ØÔâµ½ÀÕË÷¹¥»÷µÄÊÂÎñ¡£¡£¡£¡£¡£¡£¡£¡£ÉÏÖÜÄ© £¬£¬£¬£¬£¬£¬LockBit½«¸Ã»ú¹¹Ìí¼Óµ½ÆäÊý¾ÝÐ¹Â¶ÍøÕ¾ £¬£¬£¬£¬£¬£¬Éù³ÆÒÑÇÔÈ¡78 GBÊý¾Ý £¬£¬£¬£¬£¬£¬²¢¸øÁ˸ûú¹¹Ô¼Äª6ÌìµÄʱ¼ä×ö³ö»ØÓ¦¡£¡£¡£¡£¡£¡£¡£¡£Ö®ºó £¬£¬£¬£¬£¬£¬¸ÃÍŻォ×èÖ¹ÈÕÆÚÑÓÉìÖÁ8ÔÂ1ÈÕ £¬£¬£¬£¬£¬£¬²¢Éù³ÆÆäÒÑ»ñµÃ100 GBÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£L'Agenzia delle EntrateÔÚÖÜÒ»½ÒÏþÉùÃ÷³Æ £¬£¬£¬£¬£¬£¬ËüÒªÇ󾭼úͲÆÎñ²¿µÄIT¹«Ë¾SogeiÊÓ²ìÕâÆðËùνµÄÀÕË÷¹¥»÷ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£¡£ 

 

https://therecord.media/italy-investigating-ransomware-attack-on-tax-agency/


3¡¢Î¢Èí³Æ7Ô·ÝWindows¸üпÉÄܵ¼Ö´òÓ¡¹¦Ð§·ºÆðÎÊÌâ


7ÔÂ22ÈÕ±¨µÀ £¬£¬£¬£¬£¬£¬Î¢ÈíÌåÏÖ´Ó±¾ÖܵĿÉѡԤÀÀ¸üÐÂ×îÏÈ £¬£¬£¬£¬£¬£¬Ò»ÄêǰΪ½â¾öWindows ServerÔÚ²»¼æÈÝ×°±¸ÉÏ´òÓ¡ÎÊÌâ¶øÌṩµÄÔÝʱ»º½â²½·¥½«±»ÒƳý £¬£¬£¬£¬£¬£¬Õâ¿ÉÄܻᵼÖ´òÓ¡¹¦Ð§·ºÆðÎÊÌâ¡£¡£¡£¡£¡£¡£¡£¡£Î¢ÈíÚ¹ÊÍ³Æ £¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄ×°±¸°üÀ¨ÖÇÄÜ¿¨Éí·ÝÑéÖ¤´òÓ¡»ú¡¢É¨ÃèÒǺͶ๦Чװ±¸ £¬£¬£¬£¬£¬£¬ËüÃÇÔÚPKINIT KerberosÈÏ֤ʱ´ú²»Ö§³ÖDHÃÜÔ¿½»Á÷ £¬£¬£¬£¬£¬£¬»òÕßÔÚKerberos ASÇëÇóʱ´ú²»Ö§³ÖÈýÖØDES¡£¡£¡£¡£¡£¡£¡£¡£Óû§ÐèÒª¸üкϹæ»òÌæ»»²»¶Ô¹æµÄ×°±¸¡£¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-that-new-windows-updates-may-break-printing/


4¡¢ÎÚ¿ËÀ¼¹ã²¥¹«Ë¾TAVR Media±»¹¥»÷²¢Èö²¥ÐéαÐÅÏ¢

      

ýÌå7ÔÂ22ÈÕ³Æ £¬£¬£¬£¬£¬£¬ÎÚ¿ËÀ¼¹ã²¥¹«Ë¾TAVR MediaÔâµ½¹¥»÷ £¬£¬£¬£¬£¬£¬²¢Èö²¥×ÜͳVolodymyr Zelenskyy²¡ÖصÄÐéαÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£Õâ¼Ò¹«Ë¾ÔËÓª×ÅÎÚ¿ËÀ¼µÄ9¸öÖ÷ÒªµÄ¹ã²¥µç̨ £¬£¬£¬£¬£¬£¬°üÀ¨Hit FM¡¢Radio ROKS¡¢KISS FMºÍRadio RELAXµÈ¡£¡£¡£¡£¡£¡£¡£¡£ÎÚ¿ËÀ¼¹ú¼ÒÌØÊâͨѶºÍÐÅÏ¢±£»£»£»£»£»¤¾Ö£¨SSCIP£©³Æ £¬£¬£¬£¬£¬£¬¹¥»÷Õ߯ÆËðÁËTAVR MediaµÄЧÀÍÆ÷ºÍ¹ã²¥ÏµÍ³À´Ðû²¼ÐéαÐÂÎÅ £¬£¬£¬£¬£¬£¬ËûÃÇÕýÔÚÆð¾¢½â¾ö¸ÃÎÊÌâ¡£¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ £¬£¬£¬£¬£¬£¬¹¥»÷µÄȪԴÉв»ÇåÎú¡£¡£¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2022/07/ukrainian-radio-stations-hacked-to.html


5¡¢TA4563ʹÓúóÃÅEvilNum¹¥»÷Å·Ö޵ĽðÈÚºÍͶ×ÊÐÐÒµ

      

ProofpointÔÚ7ÔÂ21ÈÕÅû¶ÁËTA4563ʹÓù¥»÷Å·Ö޵ĽðÈÚºÍͶ×ÊÐÐÒµµÄ»î¶¯µÄÏêÇé¡£¡£¡£¡£¡£¡£¡£¡£´Ë´Î»î¶¯Ê¼ÓÚ2021Äêµ× £¬£¬£¬£¬£¬£¬Ê¹ÓÃÁ˶ñÒâÈí¼þEvilNum £¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÖ§³ÖÍâ»ã¡¢¼ÓÃÜÇ®±ÒºÍÈ¥ÖÐÐÄ»¯½ðÈÚ(DeFi)ÓªÒµµÄʵÌå¡£¡£¡£¡£¡£¡£¡£¡£EvilNumÊÇÒ»¸öºóÃÅ £¬£¬£¬£¬£¬£¬¿ÉÇÔÈ¡Êý¾Ý»ò¼ÓÔØÌØÁíÍâpayload¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ°üÀ¨¶à¸öÓÐȤµÄ×é¼þ £¬£¬£¬£¬£¬£¬¿ÉÓÃÓÚÈÆ¹ý¼ì²â²¢Æ¾Ö¤ÒÑʶ±ðµÄɱ¶¾Èí¼þÐÞ¸ÄѬȾ·¾¶¡£¡£¡£¡£¡£¡£¡£¡£¸Ã»î¶¯ÓëZscalerÔÚ2022Äê6Ô¹ûÕæµÄEvilNum»î¶¯Óв¿·ÖÖØµþ¡£¡£¡£¡£¡£¡£¡£¡£


https://www.proofpoint.com/us/blog/threat-insight/buy-sell-steal-evilnum-targets-cryptocurrency-forex-commodities


6¡¢ASEC·¢Ã÷ͨ¹ýISOÎļþ·Ö·¢¶ñÒâÈí¼þIcedIDµÄ»î¶¯

      

7ÔÂ25ÈÕ £¬£¬£¬£¬£¬£¬ASECÐû²¼Á˹ØÓÚͨ¹ýISOÎļþ·Ö·¢IcedIDµÄ»î¶¯µÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£¡£±¨¸æÏÈÈÝÁËÁ½ÖÖ·Ö·¢·½·¨ £¬£¬£¬£¬£¬£¬µÚÒ»ÖÖÊÇʹÓõç×ÓÓʼþÐ®ÖÆÊÖÒÕÀ´Ð®ÖÆÕý³£Óʲ¢ÏòÓû§·¢ËÍ´øÓжñÒ⸽¼þµÄ»Ø¸´ £¬£¬£¬£¬£¬£¬¸ÃÎļþ±»Ñ¹Ëõ £¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨Ò»¸öISOÎļþ¡£¡£¡£¡£¡£¡£¡£¡£ÔËÐÐISOÎļþ»áÔÚDVDÇý¶¯Æ÷Öн¨ÉèÒ»¸ölnkºÍÒ»¸öDLLÎļþ £¬£¬£¬£¬£¬£¬²¢Í¨¹ýlnkÎļþ¼ÓÔØDLL £¬£¬£¬£¬£¬£¬¼ÓÔØµÄDLL¾ÍÊÇIcedID¡£¡£¡£¡£¡£¡£¡£¡£µÚ¶þÖÖISOÎļþÖгýÁËlnkºÍDLLÖ®ÍâÉÐÓÐÆäËüÎļþ £¬£¬£¬£¬£¬£¬lnkÎļþÔËÐÐÎļþ¼ÐthemÄÚµÄworker.cmd £¬£¬£¬£¬£¬£¬Ö®ºóÔËÐÐworker.js¡£¡£¡£¡£¡£¡£¡£¡£worker.jsͨ¹ýrundll32.exe½«then.dat¼ÓÔØµ½Í³Ò»Îļþ¼ÐÖÐ £¬£¬£¬£¬£¬£¬then.datÊÇÒ»¸öDLL£¨IcedID£©¡£¡£¡£¡£¡£¡£¡£¡£


https://asec.ahnlab.com/en/37005/