McLaren Health CareÔâµ½¹¥»÷220ÍòÈ˵ÄÐÅϢй¶

Ðû²¼Ê±¼ä 2023-11-13
1¡¢McLaren Health CareÔâµ½¹¥»÷220ÍòÈ˵ÄÐÅϢй¶


¾Ý11ÔÂ10ÈÕ±¨µÀ £¬McLaren Health Care(Âõ¿­Â×)Åû¶ÁË7ÔÂÖÁ8Ô±¬·¢µÄÒ»ÆðÊý¾Ýй¶ÊÂÎñ £¬Ó°ÏìÁË2192515È˵ÄÐÅÏ¢¡£Âõ¿­Â×ÓÚ8ÔÂ22ÈÕ·¢Ã÷ÁËÒì³£»î¶¯ £¬ÊÓ²ìÏÔʾ¹¥»÷Õß7ÔÂ28ÈÕÖÁ8ÔÂ23ÈÕδ¾­ÊÚȨ»á¼ûÁËÆäÍøÂç¡£ÓÐÖ¤¾ÝÅú×¢ £¬8ÔÂ31ÈÕ¹¥»÷Õß»á¼ûÁËÊý¾Ý £¬²¢Ö±µ½10ÔÂ10ÈÕÈ·ÈÏй¶Êý¾ÝµÄÀàÐÍ¡£Ö»¹Ü¸Ã»ú¹¹Ã»ÓÐ͸¶Óйع¥»÷µÄ¸ü¶àϸ½Ú £¬µ«ALPHVÉù³Æ¶ÔÂõ¿­Â׵Ĺ¥»÷ÈÏÕæ¡£ËûÃÇ»¹Ðû²¼Á˱»µÁÊý¾ÝÑù±¾ £¬²¢ÍþвҪÅÄÂôÓ°Ïì250ÍòÈ˵ÄÊý¾Ý¿â¡£


https://securityaffairs.com/154014/data-breach/mclaren-health-care-data-breach.html


2¡¢CloudflareÍøÕ¾Ôâµ½Anonymous SudanµÄDDoS¹¥»÷


¾ÝýÌå11ÔÂ9ÈÕ±¨µÀ £¬CloudflareÍøÕ¾Ôâµ½Anonymous SudanµÄDDoS¹¥»÷¡£CloudflareÍøÕ¾å´»ú £¬ÏÔʾ¡°ÎÒÃǺÜÇ¸ØÆ......µ«ÄúµÄÅÌËã»ú»òÍøÂç¿ÉÄÜÕýÔÚ·¢ËÍ×Ô¶¯ÅÌÎÊ¡£ÎªÁ˱£»¤ÎÒÃǵÄÓû§ £¬ÎÒÃÇÏÖÔÚÎÞ·¨´¦Öóͷ£ÄúµÄÇëÇó¡±ÒÔ¼°Ò»¸ö¿´ÆðÀ´¡°Óеã²î³Ø¾¢¡±µÄGoogle»Õ±ê¡£CloudflareÌåÏÖDDoS¹¥»÷µ¼ÖÂwww.cloudflare.com·ºÆðÁ˼¸·ÖÖÓµÄÅþÁ¬ÎÊÌâ¡£¿ÉÊÇûÓÐÓ°ÏìCloudflareµÄÈκηþÎñ»ò²úÆ·¹¦Ð§ £¬Ò²Ã»Óпͻ§Êܵ½Ó°Ïì¡£Anonymous SudanÉù³Æ¶Ô´ËÊÂÈÏÕæ £¬²¢³Æ¹¥»÷Ò»Á¬Ê±¼äΪ1Сʱ¡£


https://www.bleepingcomputer.com/news/technology/cloudflare-website-downed-by-ddos-attack-claimed-by-anonymous-sudan/


3¡¢MandiantÅû¶Sandworm¹¥»÷ÎÚ¿ËÀ¼µçÁ¦ÏµÍ³µÄÏêÇé


MandiantÔÚ11ÔÂ9ÈÕÅû¶ÁËSandwormʹÓÃÕë¶ÔOTµÄÐÂÐ͹¥»÷Ó°ÏìÎÚ¿ËÀ¼µçÁ¦¹©Ó¦µÄ»î¶¯¡£¸ÃÊÂÎñ±¬·¢ÓÚ2022Äêµ× £¬MandiantÌåÏÖÕâÊÇÒ»´Î¶àÊÂÎñÍøÂç¹¥»÷ £¬Ê¹ÓÃÁËÓ°ÏìICS/OTµÄз½·¨¡£¹¥»÷ÕßÊ×ÏÈʹÓÃOT¼¶±ðµÄLotL¹¥»÷ £¬¿ÉÄܻᴥ·¢Ä¿µÄ±äµçÕ¾¶Ï·Æ÷ £¬µ¼ÖÂÒâÍâÍ£µç £¬Í¬Ê±¶ÔÎÚ¿ËÀ¼¸÷µØµÄÒªº¦»ù´¡ÉèʩʵÑé´ó¹æÄ£µ¼µ¯¹¥»÷¡£SandwormËæºóÔÚÄ¿µÄµÄITϵͳÖÐ×°ÖÃÁËCADDYWIPERµÄбäÖÖ £¬´Ó¶øÖ´Ðеڶþ´ÎÆÆËðÐÔ¹¥»÷¡£ 


https://www.mandiant.com/resources/blog/sandworm-disrupts-power-ukraine-operational-technology


4¡¢Imperial Kitten¹¥»÷Öж«µØÇøÔËÊä¡¢ÎïÁ÷ºÍ¿Æ¼¼¹«Ë¾


11ÔÂ9ÈÕ £¬CrowdStrike¹ûÕæÁËImperial KittenÕë¶ÔÖж«µØÇøÔËÊä¡¢ÎïÁ÷ºÍ¿Æ¼¼¹«Ë¾µÄµÄÐÂÒ»Âֻ¡£10Ô·Ý £¬¹¥»÷Õß×îÏÈ·Ö·¢ÒÔ¡°ÊÂÇéÕÐÆ¸¡±Ö÷Ìâ £¬°üÀ¨¶ñÒâExcel¸½¼þµÄ´¹ÂÚÓʼþ¡£·­¿ªºó¶ñÒâºê´úÂë»áÌáÈ¡Á½¸öÅú´¦Öóͷ£Îļþ £¬ËüÃǽ¨É賤ÆÚÐÔ²¢ÔËÐÐpayloadÀ´¾ÙÐз´Ïòshell»á¼û¡£È»ºó £¬¹¥»÷ÕßʹÓÃPAExecµÈ¹¤¾ßºáÏòÒÆ¶¯ÒÔÔ¶³ÌÖ´ÐÐÀú³Ì £¬Ê¹ÓÃNetScanÕìÌ½ÍøÂç £¬Ê¹ÓÃProcDump´ÓϵͳÄÚ´æÖлñȡƾ֤ £¬Ê¹ÓÃ×Ô½ç˵¶ñÒâÈí¼þIMAPLoaderºÍStandardKeyboardÓëC2·þÎñÆ÷ͨѶ¡£


https://www.crowdstrike.com/blog/imperial-kitten-deploys-novel-malware-families/


5¡¢Î¢Èí³ÆSysAidÎó²îCVE-2023-47246±»ÓÃÀ´·Ö·¢Clop


ýÌå11ÔÂ9ÈÕ³Æ £¬¹¥»÷ÕßÕýÔÚʹÓ÷þÎñ¹ÜÀíÈí¼þSysAidÖеÄÎó²î»á¼ûÆóÒµµÄ·þÎñÆ÷À´ÇÔÈ¡Êý¾Ý £¬²¢°²ÅÅÀÕË÷Èí¼þClop¡£ÕâÊÇÒ»¸ö·¾¶±éÀúÎó²î£¨CVE-2023-47246£© £¬ÔÚºÚ¿ÍʹÓøÃÎó²îÈëÇÖÄÚ²¿·þÎñÆ÷ºóÓÚ11ÔÂ2ÈÕ±»·¢Ã÷ £¬SysAidÔÚÊÓ²ìЧ¹ûÕæÁ˹¥»÷µÄÊÖÒÕϸ½Ú¡£Î¢ÈíÏÖÔÚÈ·¶¨ £¬¸ÃÎó²î±»Lace Tempest£¨ÓÖ³ÆFin11ºÍTA505£©ÓÃÀ´°²ÅÅÀÕË÷Èí¼þClop¡£SysAidÒÑÐû²¼Îó²î²¹¶¡ £¬½¨ÒéËùÓÐÓû§Á¬Ã¦×°ÖøüС£


https://www.bleepingcomputer.com/news/security/microsoft-sysaid-zero-day-flaw-exploited-in-clop-ransomware-attacks/


6¡¢KasperskyÐû²¼¹ØÓÚDucktail¹¥»÷»î¶¯µÄÆÊÎö±¨¸æ


11ÔÂ10ÈÕ £¬KasperskyÐû²¼Á˹ØÓÚDucktail¹¥»÷»î¶¯µÄÆÊÎö±¨¸æ¡£DucktailÊÇÒ»¸ö¶ñÒâÈí¼þ¼Ò×å £¬×Ô2021ÄêϰëÄêÒÔÀ´Ò»Ö±»îÔ¾ £¬Ö¼ÔÚÇÔÈ¡FacebookÆóÒµÕÊ»§¡£±¾±¨¸æÆÊÎöÁË×î½üµÄÒ»´Î»î¶¯ £¬3ÔÂÖÁ10ÔÂÉÏÑ® £¬Ö÷ÒªÕë¶ÔÓªÏúרҵְԱ¡£ÓëÒÔÍùÒÀÀµ.NETÓ¦ÓóÌÐòµÄ»î¶¯²î±ð £¬Õâ´Î»î¶¯Ê¹ÓÃÁËDelphi¡£¸Ã»î¶¯·¢ËͰüÀ¨¹«Ë¾Ð²úƷͼƬºÍαװ³ÉPDFµÄ¶ñÒâ¿ÉÖ´ÐÐÎļþµÄÎĵµ £¬Ö¼ÔÚÈö²¥Ð°汾µÄDucktail¡£


https://securelist.com/ducktail-fashion-week/111017/