·¨º½ºÍºÉº½Í¨ÖªFlying Blue¿Í»§ÆäСÎÒ˽¼ÒÐÅÏ¢ÒÑй¶

Ðû²¼Ê±¼ä 2023-01-09
1¡¢·¨º½ºÍºÉº½Í¨ÖªFlying Blue¿Í»§ÆäСÎÒ˽¼ÒÐÅÏ¢ÒѾ­Ð¹Â¶

      

¾ÝýÌå1ÔÂ6ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬£¬·¨º½ºÍºÉº½ÒÑ֪ͨFlying Blue¿Í»§£¬£¬£¬£¬£¬£¬£¬£¬ÆäСÎÒ˽¼ÒÐÅÏ¢ÒѾ­Ð¹Â¶¡£¡£¡£¡£¡£ºÉº½¹Ù·½ÍÆÌØÕ˺Å֤ʵÁËÕâ´Î¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬³Æ¹¥»÷±»ÊµÊ±×èÖ¹£¬£¬£¬£¬£¬£¬£¬£¬Óû§Àï³ÌûÓÐÊÜÓ°Ï죬£¬£¬£¬£¬£¬£¬£¬¿ÉÊǽ¨Òé¿Í»§Í¨¹ýFlying BlueÍøÕ¾¸ü¸ÄÃÜÂë¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄÜй¶µÄÊý¾Ý°üÀ¨ÐÕÃû¡¢ÓʼþµØµã¡¢µç»°¡¢ÉúÒâ¼Í¼ºÍº½ÐÐÐÅÏ¢µÈ£¬£¬£¬£¬£¬£¬£¬£¬¿Í»§µÄÐÅÓÿ¨»ò¸¶¿îÐÅÏ¢²¢Î´Ð¹Â¶¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬£¬ºÉº½ºÍ·¨º½Ã»Óлظ´Ñо¿Ö°Ô±µÄÖÃÆÀÇëÇ󡣡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/air-france-and-klm-notify-customers-of-account-hacks/


2¡¢ÀÕË÷ÍÅ»ïHive¹ûÕæConsulate Health CareµÄ550GBÊý¾Ý

      

ýÌå1ÔÂ7Èճƣ¬£¬£¬£¬£¬£¬£¬£¬ÀÕË÷ÍÅ»ïHiveй¶ÁËConsulate Health CareµÄ550GBÊý¾Ý¡£¡£¡£¡£¡£¸ÃÍÅ»ïÌåÏÖ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷±¬·¢ÔÚ2022Äê12ÔÂ3ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÓÚ2023Äê1ÔÂ6ÈÕÅû¶¡£¡£¡£¡£¡£ÔçÏÈ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÐû²¼Á˱»µÁÊý¾ÝµÄÑù±¾£¬£¬£¬£¬£¬£¬£¬£¬²¢Éù³ÆÇÔÈ¡ÁËÌõÔ¼¡¢NDAºÍÆäËüЭÒéÎļþ¡¢¹«Ë¾ÐÅÏ¢¡¢Ô±¹¤ÐÅÏ¢ºÍ¿Í»§ÐÅÏ¢µÈ¡£¡£¡£¡£¡£ØÊºó£¬£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷¸ÃÍÅ»ïй¶ÁË´ÓConsulate Health CareÇÔÈ¡µÄ550GBÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨¿Í»§ºÍÔ±¹¤µÄPII¡£¡£¡£¡£¡£¾ÝÍÆ²â£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ̸ÅÐʧ°ÜÁË£¬£¬£¬£¬£¬£¬£¬£¬ÀÕË÷ÍÅ»ïûÓбȼ°ÍýÏëµÄ×èÖ¹ÈÕÆÚ¾Í¹ûÕæÁËËùÓÐÊý¾Ý¡£¡£¡£¡£¡£


https://securityaffairs.com/140452/cyber-crime/consulate-health-care-hive-ransomware.html


3¡¢ÃÀ¹úÁ¬ËøµêChick-fil-AÊÓ²ìÆä²¿·Ö¿Í»§ÕË»§±»ºÚµÄÎÊÌâ

      

¾Ý1ÔÂ6ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬£¬ÃÀ¹ú¿ì²ÍÁ¬ËøµêChick-fil-AÕýÔÚÊÓ²ìÓëÆä²¿·Ö¿Í»§ÕË»§Ïà¹ØµÄ¿ÉÒɻ¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬£¬£¬±»Ð®ÖƵÄÕË»§ÓëÒ»´ÎÐÔµç×ÓÓʼþµØµãÒ»Æð±»ÓÃÀ´ÔÚ¹¥»÷ÖйºÖÃʳÎï¡£¡£¡£¡£¡£Ò»Ð©±»µÁÕË»§ÒÔ2ÖÁ200ÃÀÔªµÄ¼ÛÇ®±»³öÊÛ£¬£¬£¬£¬£¬£¬£¬£¬ÕâÈ¡¾öÓÚÕË»§Óà¶î¡¢Á´½ÓµÄÖ§¸¶·½·¨»òChick-fil-A One»ý·ÖÓà¶î¡£¡£¡£¡£¡ £»£»£ÉÐÓпͻ§±¨¸æËµËûÃǵÄÕË»§±»ºÚ£¬£¬£¬£¬£¬£¬£¬£¬»ý·Ö±»Çå¿Õ¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬£¬Chick-Fil-AÒÑÔÝÍ£½¨ÉèÐÂÕÊ»§²¢Õ¥È¡Ê¹ÓÃÒ»´ÎÐÔµç×ÓÓʼþµØµã£¬£¬£¬£¬£¬£¬£¬£¬½¨Òé¿Í»§Á¬Ã¦ÖØÖÃÆäÕÊ»§ÃÜÂë¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/chick-fil-a-investigates-reports-of-hacked-customer-accounts/


4¡¢¸ßͨÐû²¼2023Äê1Ô·ÝÇå¾²¸üÐÂÐÞ¸´Æä¹Ì¼þÖеÄ22¸öÎó²î

      

1ÔÂ5ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬¸ßͨÐû²¼ÁË2023Äê1ÔµÄÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´Æä¹Ì¼þÖеÄ22¸öÎó²î¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬£¬£¬½ÏΪÑÏÖØµÄÊÇAutomotiveÖеĻº³åÇøÒç³öÎó²î£¨CVE-2022-33219£©£¬£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ9.3£¬£¬£¬£¬£¬£¬£¬£¬ÔÚʹÓù²Ïí»º³åÇø×¢²áмàÌýÆ÷ʱ£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚÕûÊýÒç³öµ½»º³åÇøÒç³öµ¼ÖÂAutomotiveÄÚ´æË𻵡£¡£¡£¡£¡£Æä´ÎÊÇAutomotiveÖеÄÊäÈëÑéÖ¤²»µ±£¨CVE-2022-33218£©ºÍAndroid CoreÖÐÊý×éË÷ÒýµÄÑéÖ¤²»×¼È·£¨CVE-2022-33274£©µÈ¡£¡£¡£¡£¡£ÕâЩÎó²î¿ÉÄÜÓ°ÏìåÚÏ롢΢ÈíºÍÈýÐÇÖÆÔìµÄ×°±¸£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°»ùÓÚARM¼Ü¹¹µÄ΢ÈíSurfaceºÍWindows Dev Kit 2023/Project VolterraÅÌËã»ú¡£¡£¡£¡£¡£


https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2023-bulletin.html


5¡¢Mandiant·¢Ã÷Turla·Ö·¢KOPILUWAKºÍQUIETCANARYµÄ»î¶¯

      

MandiantÔÚ1ÔÂ5ÈÕ³ÆÆä·¢Ã÷ÁËTurlaÍÅ»ïÐ®ÖÆÊ®ÄêǰµÄ¶ñÒâÈí¼þ»ù´¡ÉèÊ©À´·Ö·¢ÐºóÃŵĻ¡£¡£¡£¡£¡£2022Äê9Ô£¬£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷¸ÃÍÅ»ïÖØÐÂ×¢²áÁËÖÁÉÙ3¸öÓâÆÚµÄANDROMEDA C2Óò£¬£¬£¬£¬£¬£¬£¬£¬²¢·Ö·¢Õì̽³ÌÐòKOPILUWAKºÍºóÃÅQUIETCANARY¡£¡£¡£¡£¡£ANDROMEDAÓÚ2010ÄêÔÂ×îÏÈÈö²¥£¬£¬£¬£¬£¬£¬£¬£¬±»¹¥»÷ÕßÐ®ÖÆµÄ°æ±¾ÓÚ2013ÄêÊ×´ÎÉÏ´«µ½VirusTotal£¬£¬£¬£¬£¬£¬£¬£¬²¢Í¨¹ý±»Ñ¬È¾µÄUSBÃÜÔ¿Èö²¥¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÇÔÈ¡ÁË2021Äê1ÔÂ1ÈÕÖ®ºó½¨ÉèµÄÎļþ¡£¡£¡£¡£¡£


https://www.mandiant.com/resources/blog/turla-galaxy-opportunity


6¡¢CheckPointÐû²¼BLINDEAGLEÕë¶Ô¶ò¹Ï¶à¶ûµÄÆÊÎö±¨¸æ

      

1ÔÂ5ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Check PointÐû²¼Á˹ØÓÚBLINDEAGLE¹¥»÷¶ò¹Ï¶à¶ûºÍ¸çÂ×±ÈÑÇµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¹¥»÷ʼÓÚÀ´×Ô¸çÂ×±ÈÑÇÕþ¸®µÄ´¹ÂÚÓʼþ£¬£¬£¬£¬£¬£¬£¬£¬×îÖÕ»á×°ÖÿªÔ´Ä¾ÂíQuasar RAT£¬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚ»ñµÃÄ¿µÄÒøÐÐÕË»§µÄ»á¼ûȨÏÞ¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬»¹»áÆÊÎö´«ÈëHTTPÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬ÒÔ¼ì²éÄ¿µÄÊÇ·ñÀ´×Ô¸çÂ×±ÈÑǾ³Í⣬£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÀ´×Ô¾³ÍâÔòÖÐÖ¹¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬²¢½«ÆäÖØ¶¨Ïòµ½¸çÂ×±ÈÑÇÍâ½»²¿ÒÆÃñ²¿·ÖµÄÕæÊµÍøÕ¾¡£¡£¡£¡£¡£ÁíÒ»¸ö»î¶¯Ã°³äÁ˶ò¹Ï¶à¶û¹ú˰¾Ö£¬£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃÀàËÆµÄÊÖÒÕ¹ýÂ˵ôÀ´×ÔÆäËû¹ú¼ÒµÄÇëÇ󡣡£¡£¡£¡£¹¥»÷ûÓзַ¢RAT£¬£¬£¬£¬£¬£¬£¬£¬¶øÊÇÀÄÓÃÕýµ±µÄmshta.exeÀ´Ö´ÐÐǶÈëÔÚHTMLÎļþÖеÄVBScript£¬£¬£¬£¬£¬£¬£¬£¬×îÖÕÏÂÔØÁ½¸öPython¾ç±¾¡£¡£¡£¡£¡£


https://research.checkpoint.com/2023/blindeagle-targeting-ecuador-with-sharpened-tools/