CISAºÍFBIÐû²¼Õë¶ÔKaseya¹©Ó¦Á´¹¥»÷Êܺ¦ÕßµÄÖ¸ÄÏ£»£»£»£»Ñо¿ÍŶÓÅû¶Ð½©Ê¬ÍøÂçmirai_pteaµÄDDoS¹¥»÷»î¶¯

Ðû²¼Ê±¼ä 2021-07-07

1.CISAºÍFBIÐû²¼Õë¶ÔKaseya¹©Ó¦Á´¹¥»÷Êܺ¦ÕßµÄÖ¸ÄÏ


1.jpg


CISAºÍFBIÁªºÏÐû²¼ÁËÕë¶ÔÊܵ½Kaseya¹©Ó¦Á´¹¥»÷Ó°ÏìµÄÊܺ¦ÕßµÄÖ¸ÄÏ¡£¡£¡£¡£ÕâÁ½¸ö»ú¹¹½¨Òé×é֯ʹÓÃKaseyaÌṩµÄ¼ì²â¹¤¾ßÀ´¼ì²éËûÃǵÄϵͳÊÇ·ñ±£´æÈëÇÖ¼£Ïó £¬£¬£¬£¬£¬£¬²¢ÆôÓöàÒòËØÉí·ÝÑéÖ¤(MFA)¡£¡£¡£¡£±ðµÄ £¬£¬£¬£¬£¬£¬×éÖ¯»¹Ó¦Ê¹Óð×Ãûµ¥À´ÍⲿÏÞÖÆ¶ÔÆäÄÚ²¿×ʲúµÄ»á¼û £¬£¬£¬£¬£¬£¬²¢Ê¹Ó÷À»ðǽ»òVPN±£»£»£»£»¤ÆäÔ¶³Ì¼à¿Ø¹¤¾ßµÄÖÎÀí½çÃæ¡£¡£¡£¡£¶øÊÜÓ°ÏìµÄMSP¿Í»§ÐèҪȷ±£±¸·ÝÊÇ×îÐ嵀 £¬£¬£¬£¬£¬£¬²¢ÇÒÁ¬Ã¦×°Öù©Ó¦ÉÌÌṩµÄ×îеIJ¹¶¡¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/119728/cyber-crime/cisa-fbi-guidance-kaseya-attack.html


2.¹ú¼ÊÐ̾¯×éÖ¯LyrebirdÐж¯¾Ð²¶Ä«Î÷¸çºÚ¿ÍDr HeX


2.jpg


¹ú¼ÊÐ̾¯×éÖ¯ÌᳫµÄLyrebirdÐж¯¾Ð²¶ÁËÄ«Î÷¸çºÚ¿ÍDr HeX¡£¡£¡£¡£Dr HeX×Ô2009ÄêÒÔÀ´×îÏÈ»îÔ¾ £¬£¬£¬£¬£¬£¬¾ÙÐйý¶àÖÖÍøÂç·¸·¨»î¶¯ £¬£¬£¬£¬£¬£¬°üÀ¨ÍøÂç´¹ÂÚ¡¢¶ñÒâÈí¼þ¿ª·¢ºÍڲƭµÈ¡£¡£¡£¡£ÔÚ´Ë´ÎÐж¯ÖÐ £¬£¬£¬£¬£¬£¬Group-IBͨ¹ýÕë¶Ô·¨¹úÄ³ÒøÐеÄÍøÂç´¹ÂÚ¹¤¾ß°üʶ±ð³öÁ˸ÃÍøÂç·¸·¨·Ö×Ó¡£¡£¡£¡£±ðµÄ £¬£¬£¬£¬£¬£¬¸ÃºÚ¿Í»¹ÌØÊâÍÆ¹ãÁËËùνµÄZombi Bot £¬£¬£¬£¬£¬£¬¾Ý³ÆÆäÖаüÀ¨814¸öÎó²î £¬£¬£¬£¬£¬£¬ÓÐ72¸öδ¹ûÕæµÄÎó²î¡¢Ò»¸ö±©Á¦ÆÆ½â³ÌÐò¡¢webshellºÍºóÃÅɨÃè³ÌÐò £¬£¬£¬£¬£¬£¬»¹¿ÉÒÔÓÃÀ´Ö´ÐÐDDoS¹¥»÷¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/07/interpol-arrests-hacker-in-morocco-who.html


3.Ñо¿ÍŶÓÅû¶Ð½©Ê¬ÍøÂçmirai_pteaµÄDDoS¹¥»÷»î¶¯


3.jpg


Ñо¿ÍŶÓÅû¶ÁËÊÜMiraiÆô·¢µÄн©Ê¬ÍøÂçmirai_ptea £¬£¬£¬£¬£¬£¬Ê¹ÓÃKGUARDÌṩµÄÊý×ÖÊÓÆµÂ¼Ïñ»ú(DVR)ÖеÄÒ»¸öδ¹ûÕæµÄÎó²îÀ´ÌᳫÂþÑÜʽ¾Ü¾øÐ§ÀÍ(DDoS)¹¥»÷¡£¡£¡£¡£Ñо¿Ö°Ô±ÓÚ2021Äê3ÔÂ23ÈÕÊ×´ÎÊÓ²ìÁ˸ù¥»÷»î¶¯ £¬£¬£¬£¬£¬£¬ºóÓÖÓÚ2021Äê6ÔÂ22ÈÕÔٴμì²âµ½Á˹¥»÷ʵÑé¡£¡£¡£¡£Ñо¿ÍŶӳƽ©Ê¬Ô´IPµÄµØÀíÂþÑÜÖ÷Òª¼¯ÖÐÔÚÃÀ¹ú¡¢º«¹úºÍ°ÍÎ÷ £¬£¬£¬£¬£¬£¬¶øÊܺ¦Õ߱鲼ŷÖÞ¡¢ÑÇÖÞ¡¢°Ä´óÀûÑÇ¡¢±±ÃÀºÍÄÏÃÀ £¬£¬£¬£¬£¬£¬ÒÔ¼°·ÇÖÞ²¿·ÖµØÇø¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2021/07/newly-discovered-mirai-botnet-is.html


4.ºÚ¿ÍÔÚ°µÍø¹ûÕæÉç½»ÍøÕ¾GETTR½ü9Íò»áÔ±µÄСÎÒ˽¼ÒÐÅÏ¢


4.jpg


ºÚ¿ÍÔÚ°µÍøÉϹûÕæÁËÉç½»ÍøÕ¾GETTR½ü9Íò»áÔ±µÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£GETTRÊÇÒ»¸öеÄÇ×ÌØÀÊÆÕµÄÉ罻ýÌåÆ½Ì¨ £¬£¬£¬£¬£¬£¬ÓÉÇ°ÌØÀÊÆÕÕÕÁϽÜÉ­Ã×ÀÕ½¨Éè £¬£¬£¬£¬£¬£¬×÷ΪTwitterµÄÌæ»»Æ·¡£¡£¡£¡£Çå¾²¹«Ë¾Hudson RockÌåÏÖ £¬£¬£¬£¬£¬£¬ºÚ¿ÍʹÓÃÒ»¸ö²»Çå¾²µÄAPIץȡ87973ÃûGETTR³ÉÔ±µÄÊý¾Ý £¬£¬£¬£¬£¬£¬°üÀ¨µç×ÓÓʼþµØµã¡¢êdzơ¢ÐÕÃû¡¢³öÉúÈÕÆÚ¡¢Í·ÏñURL¡¢Å侰ͼƬ¡¢Î»Öá¢Ð¡ÎÒ˽¼ÒÍøÕ¾ºÍÆäËûÄÚ²¿ÍøÕ¾Êý¾Ý¡£¡£¡£¡£ÏÖÔÚ £¬£¬£¬£¬£¬£¬GETTRÍøÕ¾²¢Î´¶Ô´ËʾÙÐлظ´¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hacker-dumps-private-info-of-pro-trump-gettr-social-network-members/


5.GriefÉù³ÆÆä¹¥»÷ŦԼ¿µ¸´Ò½ÔºRSS²¢»ñÈ¡4GBµÄÊý¾Ý


5.jpg


ºÚ¿ÍÍÅ»ïGriefÉù³ÆÆä¹¥»÷ÁËŦԼµÄ¿µ¸´Ò½ÔºRehabilitation Support Services(RSS)²¢»ñÈ¡ÁË4GBµÄÊý¾Ý¡£¡£¡£¡£6ÔÂ2ÈÕ £¬£¬£¬£¬£¬£¬Grief½«¸Ã»ú¹¹¼ÓÈëÊܺ¦ÕßÃûµ¥ £¬£¬£¬£¬£¬£¬²¢³ÆÆäÒѾ­ÇÔÈ¡ÁË4GBÊý¾Ý¡£¡£¡£¡£6ÔÂ29ÈÕ £¬£¬£¬£¬£¬£¬GriefÉÏ´«ÁËÇÔÈ¡µÄÊý¾Ý £¬£¬£¬£¬£¬£¬°üÀ¨×ʲúÇ·Õ®±í¡¢Ë°ÊÕ¡¢Ö§Æ±¡¢´æ¿î¡¢ÒøÐжÔÕ˵¥¡¢·¢Æ±¡¢ºÍ×ÊÔ´ÏîĿժҪµÈ²ÆÎñÐÅÏ¢£»£»£»£»Ò½ÁƱ£½¡Ö¤Êµ¡¢Ò½ÁÆÎļþºÍ´û¿î´û¿îÉêÇë £¬£¬£¬£¬£¬£¬ÒÔ¼°²¿·Ö¿Í»§ºÍÔ±¹¤µÄÉç»áÇå¾²ºÅÂëºÍ¼ÝÕÕºÅÂëµÈСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¸Ã»ú¹¹ÉÐδ¶Ô´ËÊÂ×÷³ö»ØÓ¦¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/ny-grief-claims-to-have-breached-rehabilitation-support-services/


6.Money.co.ukÐû²¼2021ÄêQ2ڲƭºÍÍøÂç·¸·¨ÆÊÎö±¨¸æ


6.jpg


Money.co.ukÐû²¼ÁË2021ÄêQ2Ó¢¹úÓйØÚ²Æ­ºÍÍøÂç·¸·¨µÄÆÊÎö±¨¸æ¡£¡£¡£¡£±¨¸æÖ¸³ö £¬£¬£¬£¬£¬£¬2020ÄêÍø¹ºÏúÊÛ¶îÔöÌíÁË46% £¬£¬£¬£¬£¬£¬Ôö·ùΪ½üÊ®Äê×î¸ß¡£¡£¡£¡£Òò´Ë £¬£¬£¬£¬£¬£¬Ú²Æ­»î¶¯Ò²¼±¾çÔöÌí £¬£¬£¬£¬£¬£¬2021ÄêÉϰëÄêËðʧÁè¼Ý10ÒÚÓ¢°÷¡£¡£¡£¡£2021ÄêQ2¹²ÓÐ81018ÆðÕ©Æ­ºÍÍøÂç·¸·¨°¸¼þ £¬£¬£¬£¬£¬£¬×ܼÆËðʧΪ3.823ÒÚÓ¢°÷£»£»£»£»Ïà±È֮Ϡ£¬£¬£¬£¬£¬£¬2021Äê1ÔÂÖÁ3Ô±¬·¢ÁË137695Æð·¸·¨°¸¼þ £¬£¬£¬£¬£¬£¬Éæ°¸½ð¶îΪ6.256ÒÚÓ¢°÷¡£¡£¡£¡£¶øÔÚ2021Äê4ÔÂÖÁ6ÔÂʱ´ú £¬£¬£¬£¬£¬£¬´ËÀà»î¶¯µÄÊܺ¦Õ߯½¾ùÿÈËËðʧÁË4719Ó¢°÷¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.money.co.uk/credit-cards/quarterly-fraud-report