°®¶ûÀ¼¹ú¼Ò¾¯¾ÖµÄ³Ð°üÉÌй¶50ÍòÌõ¿ÛѺ³µÁ¾µÄ¼Í¼

Ðû²¼Ê±¼ä 2023-10-25

1¡¢°®¶ûÀ¼¹ú¼Ò¾¯¾ÖµÄ³Ð°üÉÌй¶50ÍòÌõ¿ÛѺ³µÁ¾µÄ¼Í¼


¾Ý10ÔÂ23ÈÕ±¨µÀ£¬£¬ £¬Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸ö¹ûÕæµÄÊý¾Ý¿â£¬£¬ £¬°üÀ¨Áè¼Ý50ÍòÌõÓë°®¶ûÀ¼¹ú¼Ò¾¯¾ÖGarda S¨ªoch¨¢na¿ÛѺ³µÁ¾Ïà¹ØµÄ¼Í¼¡£¡£¡£¡£Îĵµ×ÜÊýΪ521043¸ö£¬£¬ £¬¾ÞϸΪ271.8 GB¡£¡£¡£¡£Æ¾Ö¤°®¶ûÀ¼Ö´·¨£¬£¬ £¬µ±³µÁ¾±»¿ÛѺʱ£¬£¬ £¬³µÖ÷Ðë³öʾÉí·Ý֤ʵºÍ°ü¹ÜÎļþµÈ¶à·ÝÎļþ£¬£¬ £¬Òò´Ëй¶µÄ50Íò·ÝÎĵµ¿ÉÄÜÓ°ÏìÁËÔ¼15ÍòÃû³µÖ÷¡£¡£¡£¡£½øÒ»³ÌÐò²éÏÔʾ£¬£¬ £¬¸ÃÊý¾Ý¿âÊôÓÚ°®¶ûÀ¼ÀûĬÀï¿ËµÄÒ»¼Ò˽ÈËÊÖÒճаüÉÌ¡£¡£¡£¡£ÏÖÔÚ£¬£¬ £¬Ð¹Â¶Êý¾ÝÒѱ»±£»£»£»£»£»¤ÆðÀ´¡£¡£¡£¡£


https://www.hackread.com/contractor-data-breach-irish-national-police-vehicle-seizure/


2¡¢ºÚ¿ÍÒÔ8ÍòÃÀÔª¼ÛÇ®³öÊÛ8.15ÒÚÌõÓ¡¶È¹«ÃñµÄPII¼Í¼


ýÌå10ÔÂ24Èճƣ¬£¬ £¬ºÚ¿ÍÔÚ°µÍø³öÊÛÊýÒÚÌõÓ¡¶È¹«ÃñµÄPII¼Í¼£¬£¬ £¬°üÀ¨Aadhaar¿¨¡£¡£¡£¡£AadhaarÊÇÒ»¸ö12λµÄСÎÒ˽¼Òʶ±ðÂ룬£¬ £¬ÓÉÓ¡¶ÈΨһÉí·Ýʶ±ð»ú¹¹´ú±íÓ¡¶ÈÕþ¸®½ÒÏþ¡£¡£¡£¡£10ÔÂ9ÈÕ£¬£¬ £¬ÃûΪpwn0001µÄºÚ¿ÍÔÚ°µÍøÐû²¼ÁËÒ»¸öÌû×Ó£¬£¬ £¬³ÆÓµÓÐ8.15ÒÚÓ¡¶È¹«ÃñAadhaarºÍ»¤Õռͼ£¬£¬ £¬²¢Ô¸ÒâÒÔ80000ÃÀÔªµÄ¼ÛÇ®³öÊÛÕû¸öÊý¾Ý¿â¡£¡£¡£¡£Í¬Ê±£¬£¬ £¬pwn0001»¹¹ûÕæÁË4¸öÑù±¾£¬£¬ £¬ÆäÖÐÒ»¸öÑù±¾°üÀ¨100000ÌõÓ¡¶ÈסÃñµÄPII¡£¡£¡£¡£


https://securityaffairs.com/152957/security/pii-indian-citizens-dark-web.html


3¡¢BHI EnergyÏêÊöAkiraÔõÑùÈëÇÖÆäϵͳ²¢ÇÔÈ¡Êý¾Ý


¾ÝýÌå10ÔÂ23ÈÕ±¨µÀ£¬£¬ £¬ÃÀ¹úÄÜÔ´¹«Ë¾BHI EnergyÅû¶ÁËAkiraÔÚ5ÔÂ30ÈÕÈëÇÖÆäϵͳµÄÏêϸÐÅÏ¢¡£¡£¡£¡£AkiraʹÓÃÇÔÈ¡µÄµÚÈý·½µÄVPNƾ֤»á¼ûBGIµÄÄÚÍø£¬£¬ £¬ÔÚÊ״λá¼ûºóµÄÒ»ÖÜÄÚʹÓÃͳһ¸öÕË»§¶ÔÄÚÍø¾ÙÐÐÕì̽¡£¡£¡£¡£6ÔÂ16ÈÕ£¬£¬ £¬AkiraÔٴλá¼ûϵͳ£¬£¬ £¬Ã¶¾ÙÊý¾Ý£¬£¬ £¬²¢ÔÚ6ÔÂ20ÈÕÖÁ29ÈÕÇÔÈ¡ÁË767k¸öÎļþ£¬£¬ £¬¹²690 GB£¬£¬ £¬°üÀ¨Windows Active DirectoryÊý¾Ý¿â¡£¡£¡£¡£×îºó£¬£¬ £¬¹¥»÷ÕßÓÚ6ÔÂ29ÈÕÇÔÈ¡ÁËËùÓÐÊý¾Ýºó£¬£¬ £¬ÔÚËùÓÐ×°±¸ÉÏ×°ÖÃÁËAkiraÀÕË÷Èí¼þÀ´¼ÓÃÜÎļþ¡£¡£¡£¡£Õâʱ£¬£¬ £¬BHI²ÅÒâʶµ½¹«Ë¾Òѱ»ÈëÇÖ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/us-energy-firm-shares-how-akira-ransomware-hacked-its-systems/


4¡¢Î÷°àÑÀ¾¯·½µ·»ÙÄ³ÍøÂçÕ©Æ­ÍŻﲢ¾Ð²¶34ÃûÏÓÒÉÈË


10ÔÂ24ÈÕ±¨µÀ£¬£¬ £¬Î÷°àÑÀ¹ú¼Ò¾¯Ô±¾Öµ·»ÙÁËÒ»¸öÍøÂç·¸·¨ÍŻ¡£¡£¡£¸ÃÍÅ»ïÖ´ÐÐÖÖÖÖÅÌËã»úÕ©Æ­£¬£¬ £¬ÇÔÈ¡ÁËÁè¼Ý400ÍòÈ˵ÄÊý¾Ý£¬£¬ £¬×¬È¡ÁËÔ¼300ÍòÅ·Ôª¡£¡£¡£¡£Ö´·¨²¿·ÖÔÚÂíµÂÀï¡¢ÂíÀ­¼Ó¡¢Î¤¶ûÍß¡¢°¢Àû¿²ÌغÍĶûÎ÷ÑǾÙÐÐÁË16´ÎÓÐÕë¶ÔÐÔµÄËѲ飬£¬ £¬ÒѾв¶34Ãû·¸·¨ÍÅ»ïµÄ³ÉÔ±¡£¡£¡£¡£¾¯·½³Æ£¬£¬ £¬±»²¶ÕßÓëð³ä¿ìµÝ¹«Ë¾ºÍµçÁ¦¹©Ó¦É̵Ĵ¹ÂڻÓйØ¡£¡£¡£¡£¸ÃÍÅ»ïµÄÍ·Ä¿Òѱ»¾Ð²¶£¬£¬ £¬¶ÔÆäËû³ÉÔ±Éí·ÝµÄÊÓ²ìÈÔÔÚ¾ÙÐÐÖС£¡£¡£¡£


https://securityaffairs.com/152946/cyber-crime/spanish-police-dismantled-cybercriminal-group.html


5¡¢Ñо¿Ö°Ô±Ðû²¼VMwarevÎó²îCVE-2023-34051µÄPoC


ýÌå10ÔÂ24Èճƣ¬£¬ £¬VMwarevÌáÐÑvRealize Log Insight£¨ÏÖ³ÆÎªVMware Aria Operations for Logs£©ÖÐÎó²îµÄPoCÒÑÐû²¼¡£¡£¡£¡£ÕâÊÇÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2023-34051£©£¬£¬ £¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔ½«Îļþ×¢ÈëÄ¿µÄϵͳÖУ¬£¬ £¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£Horizon3Ðû²¼ÁËPoC£¬£¬ £¬ËüʹÓÃIPµØµãÓÕÆ­ºÍÖÖÖÖThrift RPC¶ËµãÀ´ÊµÏÖí§ÒâÎļþдÈë¡£¡£¡£¡£Ñо¿Ö°Ô±½¨ÒéÁ¬Ã¦×°ÖøüС£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/vmware-warns-admins-of-public-exploit-for-vrealize-rce-flaw/


6¡¢KasperskyÐû²¼Triangulation»î¶¯µÄÒþ²ØÐԵı¨¸æ


10ÔÂ23ÈÕ£¬£¬ £¬KasperskyÐû²¼Á˹ØÓÚTriangulation»î¶¯µÄÒþ²ØÐÔµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¸Ã±¨¸æÏÈÈÝÁ˴˴ι¥»÷µÄÖÖÖÖÒþÐÎÊÖÒÕ£¬£¬ £¬ÒÔ¼°¹¥»÷ÖÐʹÓõÄ×é¼þ¡£¡£¡£¡£ÔÚ°²ÅÅTriangleDB֮ǰ£¬£¬ £¬»áʹÓÃÁ½¸öÑéÖ¤Æ÷À´ÍøÂç×°±¸ÐÅÏ¢£¬£¬ £¬²¢È·±£´úÂë²»»áÔÚÆÊÎöÇéÐÎÖÐÖ´ÐС£¡£¡£¡£Ëü»¹°üÀ¨Ò»¸öÂó¿Ë·ç¼ÒôÄ £¿£¿émsu3h£¬£¬ £¬Ä¬ÈÏ¿ÉÒÔ¼ÒôÈý¸öСʱ£¬£¬ £¬µ«ÈôÊǵçÁ¿µÍÓÚ10%ÇÒ×°±¸ÆÁÄ»ÕýÔÚʹÓý«ÔÝͣ¼Òô¡£¡£¡£¡£¹¥»÷Õß»¹ÊµÑéÁËÌØÁíÍâÔ¿³×´®Ð¹Â¶Ä £¿£¿é¡¢SQLiteÊý¾Ý¿âÇÔÈ¡¹¦Ð§ÒÔ¼°Î»ÖÃ¼à¿ØÄ £¿£¿é£¨ÔÚGPS²»¿ÉÓÃʱʹÓÃÍøÂçÔªÊý¾Ý£©¡£¡£¡£¡£


https://securelist.com/triangulation-validators-modules/110847/