ÆÏÌÑÑÀ×î´óµÄýÌ幫˾ImpresaÔâµ½Lapsus$ÀÕË÷¹¥»÷

Ðû²¼Ê±¼ä 2022-01-05

ÆÏÌÑÑÀ×î´óµÄýÌ幫˾ImpresaÔâµ½Lapsus$ÀÕË÷¹¥»÷


 ÆÏÌÑÑÀ×î´óµÄýÌ幫˾ImpresaÔâµ½Lapsus$ÀÕË÷¹¥»÷.png


¾Ý1ÔÂ2ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬ÆÏÌÑÑÀ×î´óµÄýÌ幫˾ImpresaÔâµ½Lapsus$µÄÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷±¬·¢ÓÚÔªµ©¼ÙÆÚʱ´ú£¬£¬£¬£¬£¬£¬Ó°ÏìÁ˸ù«Ë¾µÄITЧÀÍÆ÷»ù´¡ÉèÊ©£¬£¬£¬£¬£¬£¬µ¼Ö¸ùú×îÖ÷ÒªµÄµçÊÓÆµµÀSICºÍÖܱ¨ExpressoЧÀÍÔÝʱÖÐÖ¹¡£¡£¡£¡£¡£¡£¡£Lapsus$ÍÅ»ïÔÚImpressaµÄËùÓÐÍøÕ¾ÁôÏÂÀÕË÷Êê½ðÒªÇ󣬣¬£¬£¬£¬£¬²¢Éù³ÆÒÑ»ñµÃ¶ÔImpresaµÄAmazon Web ServicesÕÊ»§µÄ»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£1ÔÂ2ÈÕ£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾µÄËùÓÐÍøÕ¾´¦ÓÚά»¤×´Ì¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß»¹Ê¹ÓÃExpressoµÄTwitterÕÊ»§·¢·¢ÎijÆËûÃÇÈÔ¿É»á¼û¹«Ë¾×ÊÔ´¡£¡£¡£¡£¡£¡£¡£


https://therecord.media/lapsus-ransomware-gang-hits-sic-portugals-largest-tv-channel/



Unit 42·¢Ã÷Õë¶Ô·¿µØ²úÍøÕ¾µÄWeb Skimmer»î¶¯


¾ÝUnit 42ÔÚ1ÔÂ3ÈÕÐû²¼µÄ±¨¸æ³Æ£¬£¬£¬£¬£¬£¬Ò»¸öеÄWeb Skimmer»î¶¯Õýͨ¹ý¹¥»÷·Ö·¢ÔÆÊÓÆµµÄ¹©Ó¦Á´À´Ãé×¼·¿µØ²úÍøÕ¾¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÑо¿¹²¼ì²âµ½100¶à¸öÊܵ½ÏàͬSkimmer¹¥»÷µÄÍøÕ¾£¬£¬£¬£¬£¬£¬¾­ÆÊÎö·¢Ã÷ËùÓй¥»÷¶¼Ô´×ÔÒ»¼Ò¹«Ë¾£ºÕâЩ±»ÈëÇÖµÄÍøÕ¾¶¼´ÓÒ»¸öÔÆÊÓÆµÆ½Ì¨µ¼ÈëÏàͬµÄÊÓÆµ£¬£¬£¬£¬£¬£¬¶ø¸ÃÊÓÆµÖаüÀ¨¶ñÒâ¾ç±¾¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±»¹Õ¹Ê¾Á˴˴λÊÇÔõÑù·Ö·¢¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬ÒÔ¼°SkimmerÔõÑùÇÔȡĿµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£


https://unit42.paloaltonetworks.com/web-skimmer-video-distribution/


ÃÀ¹úÔÚÏßÊÐËÁPulseTVй¶Áè¼Ý20ÍòÓû§µÄÖ§¸¶ÐÅÏ¢


¾ÝýÌå12ÔÂ31ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬ÃÀ¹úÔÚÏßÊÐËÁPulseTVй¶Áè¼Ý20ÍòÓû§µÄÖ§¸¶ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤¹Ù·½Í¨Öªº¯£¬£¬£¬£¬£¬£¬VISAÒÑÓÚ2021Äê3ÔÂ8ÈÕ֪ͨ¸Ã¹«Ë¾£¬£¬£¬£¬£¬£¬ÆäÍøÕ¾£¨www.pulsetv.com£©¿ÉÄܱ£´æÊý¾Ýй¶ÎÊÌâ¡£¡£¡£¡£¡£¡£¡£¾­ÓÉÇå¾²¼ì²é²¢Î´·¢Ã÷ÈκÎй¶¼£Ï󡣡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚ7ÔÂÔÙ´ÎÊÕµ½VISA¾¯±¨£¬£¬£¬£¬£¬£¬Ö±µ½11ÔÂ18ÈÕ£¬£¬£¬£¬£¬£¬¸ÃÍøÕ¾Òѱ»È·¶¨Îª¶àÆðMasterCardÐÅÓÿ¨ÉúÒâ»î¶¯µÄ½»µã¡£¡£¡£¡£¡£¡£¡£PulseTVÔÚ12ÔÂ30ÈÕ֪ͨÓû§£¬£¬£¬£¬£¬£¬²¢³ÆÖ»ÓÐ2019Äê11ÔÂ1ÈÕÖÁ2021Äê8ÔÂ31ÈÕʹÓÃÐÅÓÿ¨µÄÓû§Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/pulsetv-discloses-potential-compromise-of-200-000-credit-cards/


Chosun³Æ³¯Ïʶà¸öAPT×éÖ¯ÒÑÔÚÉúÒâËùÇÔÈ¡17ÒÚÃÀÔª


ýÌå1ÔÂ2Èճƣ¬£¬£¬£¬£¬£¬Ó볯ÏÊÓйصĶà¸öAPT×éÖ¯ÒÑ´ÓÉúÒâËùÇÔÈ¡¼ÛÖµÔ¼17ÒÚÃÀÔªµÄ¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£¡£¡£CISAÌåÏÖ£¬£¬£¬£¬£¬£¬ÌìÏÂÉÏËùÓеÄÒøÐж¼ÒѳÉΪ³¯ÏʺڿÍÍøÂç¹¥»÷µÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬ÕâЩ¹¥»÷ʹÓÃÃûΪAppleJeusµÄ¶ñÒâÈí¼þÇÔÈ¡¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£¡£¡£Åí²©ÉçÌåÏÖ£¬£¬£¬£¬£¬£¬×Ô2018ÄêÒÔÀ´£¬£¬£¬£¬£¬£¬ÒÑÓÐ30¸ö¹ú¼Ò/µØÇøÊ¹ÓÃApple Zeus£¬£¬£¬£¬£¬£¬¶ø¹¥»÷ÕßÔÚ2019ÄêÖÁ2020Äê11ÔÂͨ¹ýÓ¦ÓÃÐòÇÔÈ¡3.164ÒÚÃÀÔªµÄ¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/126225/apt/north-korea-cryptocurrency-exchanges-hacks.html


2021ÄêÃÀ¹úÒ½ÁÆÐÐÒµ10´óÎ¥¹æÊÂÎñ×ܼÆÐ¹Â¶1900ÍòÌõ


ýÌå12ÔÂ31ÈÕ±¨µÀ³Æ£¬£¬£¬£¬£¬£¬ÃÀ¹úÎÀÉúÓ빫ÖÚЧÀͲ¿(HHS)ÒÑÔÚÆäÍøÕ¾Áгö2021ÄêÓ°Ïì×îÆÕ±éµÄ10´óÎ¥¹æÊÂÎñ¡£¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬×îÑÏÖØµÄÊÇ·ðÂÞÀï´ï¶ùͯ¿µ½¡ÖÐÐÄ£¬£¬£¬£¬£¬£¬Ð¹Â¶350Íò»¼ÕßÊý¾Ý£»£»£»£»£»Æä´ÎÊÇ20/20 Eye Care NetworkÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬µ¼ÖÂÁè¼Ý320ÍòÈ˵ÄÐÅÏ¢×ß©¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖ£¬£¬£¬£¬£¬£¬ÕâЩÊÂÎñ¹²Éæ¼°1900ÍòÈË£¬£¬£¬£¬£¬£¬ÆäÖдó´ó¶¼ÊÇÓÉÀÕË÷¹¥»÷µ¼ÖµÄ¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/top-10-healthcare-breaches-in-the-us-exposed-data-of-19-million/


ESET¹ûÕæ2021ÄêÖµµÃ×¢ÖØµÄÍøÂçÇ徲ͳ¼ÆÊý¾ÝÁбí


ESETÔÚ12ÔÂ30ÈÕÐû²¼µÄͳ¼Æ±¨¸æÁгö2021ÄêÖµµÃ×¢ÖØµÄÍøÂçÇ徲ͳ¼ÆÊý¾Ý¡£¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬2021ÄêÊý¾Ýй¶Ôì³ÉµÄËðʧ´Ó386ÍòÃÀÔªÉÏÉýµ½424ÍòÃÀÔª£¬£¬£¬£¬£¬£¬µÖ´ï½ü17ÄêÒÔÀ´µÄ·åÖµ£»£»£»£»£»½ñÄêÄêÖУ¬£¬£¬£¬£¬£¬Kaseya±»SodinokibiÀÕË÷7000ÍòÃÀÔª£¬£¬£¬£¬£¬£¬ÕâÊÇÆù½ñΪֹ×î¸ßµÄÊê½ð½ð¶î£»£»£»£»£»2021Äê12Ô£¬£¬£¬£¬£¬£¬Log4ShellÅû¶ºó²»¾ÃESET¼ì²âµ½ÊýÊ®Íò´Î¹¥»÷ʵÑ飬£¬£¬£¬£¬£¬ÆäÖд󲿷ÖλÓÚÃÀ¹úºÍÓ¢¹ú¡£¡£¡£¡£¡£¡£¡£


https://www.welivesecurity.com/2021/12/30/22-cybersecurity-statistics-know-2022/


Çå¾²¹¤¾ß


ExcelPeek 


ExcelPeek¿ÉÒÔÓÃÀ´ÊÓ²ìDZÔÚ¶ñÒâ Microsoft Excel ÎļþµÄ¹¤¾ß¡£¡£¡£¡£¡£¡£¡£


https://github.com/slaughterjames/excelpeek


Msmailprobe


ÓÃÓÚ Office 365 ºÍ Exchange ö¾Ù¡£¡£¡£¡£¡£¡£¡£


https://www.kitploit.com/2022/01/msmailprobe-office-365-and-exchange.html


Çå¾²ÆÊÎö


CVE-2021-34424£ºÐÅÏ¢×ß©Îó²î


ZoomµÄMMR ЧÀÍÆ÷Öб£´æÐÅÏ¢×ß©Îó²î¡£¡£¡£¡£¡£¡£¡£


https://packetstormsecurity.com/files/165419/GS20220103184501.tgz


ʹÓÃÕë¶ÔSSDµÄ¹¥»÷Ö²Èë¶ñÒâÈí¼þ


Ñо¿Ö°Ô±·¢Ã÷Õë¶ÔijЩ¹Ì̬Çý¶¯Æ÷ (SSD) µÄ¹¥»÷£¬£¬£¬£¬£¬£¬¿É½«¶ñÒâÈí¼þÖ²ÈëÓû§ºÍÇå¾²½â¾ö¼Æ»®ÎÞ·¨´¥¼°µÄλÖᣡ£¡£¡£¡£¡£¡£


https://asec.ahnlab.com/en/29885/


Redline StealerÆÊÎö±¨¸æ


AhnLab ASEC³Æ£¬£¬£¬£¬£¬£¬ÔÚWebä¯ÀÀÆ÷ÉÏʹÓÃ×Ô¶¯µÇ¼¹¦Ð§µÄ±ãµ±ÐÔÕýÔÚ³ÉΪӰÏì×éÖ¯ºÍСÎÒ˽¼ÒÇå¾²µÄÖØ´óÎÊÌâ¡£¡£¡£¡£¡£¡£¡£


https://asec.ahnlab.com/en/29885/