OtelierÂùÝÖÎÀíÆ½Ì¨ÔâÓö´ó¹æÄ£Êý¾Ýй¶
Ðû²¼Ê±¼ä 2025-01-201. OtelierÂùÝÖÎÀíÆ½Ì¨ÔâÓö´ó¹æÄ£Êý¾Ýй¶
1ÔÂ17ÈÕ£¬£¬£¬£¬2024Äê7ÔÂÖÁ10ÔÂʱ´ú£¬£¬£¬£¬ÂùÝÖÎÀíÆ½Ì¨Otelier£¨Ç°ÉíΪMyDigitalOffice£©ÔâÓöÁËÑÏÖØµÄÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£ÍþвÐÐΪÕßÀÖ³ÉÈëÇÖÆäAmazon S3ÔÆ´æ´¢£¬£¬£¬£¬ÇÔÈ¡ÁËÊý°ÙÍò¿ÍÈ˵ÄСÎÒ˽¼ÒÐÅÏ¢ÒÔ¼°ÍòºÀ¡¢Ï£¶û¶Ù¡¢¿ÔõÈ×ÅÃûÂÃ¹ÝÆ·ÅƵÄÔ¤¶©ÐÅÏ¢£¬£¬£¬£¬×ÜÁ¿½ü8TB¡£¡£¡£¡£¡£OtelierÒÑÈ·ÈÏ´Ë´ÎÈëÇÖ£¬£¬£¬£¬²¢ÕýÓëÊÜÓ°Ïì¿Í»§Ïàͬ£¬£¬£¬£¬Í¬Ê±Ô¼ÇëÁ˶¥¼âÍøÂçÇ徲ר¼ÒÍŶӾÙÐÐÖÜȫȡ֤ÆÊÎöºÍϵͳÑéÖ¤¡£¡£¡£¡£¡£Îª±ÜÃâÀàËÆÊÂÎñÔٴα¬·¢£¬£¬£¬£¬OtelierÒѽûÓÃÏà¹ØÕË»§²¢ÔöÇ¿ÍøÂçÇå¾²ÐÒé¡£¡£¡£¡£¡£¾ÝÍþвÕß͸¶£¬£¬£¬£¬ËûÃÇ×î³õͨ¹ýÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ»ñÈ¡ÁËÒ»ÃûÔ±¹¤µÄµÇ¼ÐÅÏ¢£¬£¬£¬£¬½ø¶øÈëÇÖÁËAtlassianЧÀÍÆ÷£¬£¬£¬£¬²¢Ê¹ÓÃÕâЩƾ֤»ñÈ¡Á˸ü´ó¶¼¾Ý£¬£¬£¬£¬°üÀ¨S3´æ´¢Í°µÄ»á¼ûȨÏÞ¡£¡£¡£¡£¡£ÍòºÀÂùÝÒÑ֤ʵÆäÊܵ½Ó°Ï죬£¬£¬£¬²¢ÔÝÍ£ÁËOtelierÌṩµÄ×Ô¶¯»¯Ð§ÀÍ£¬£¬£¬£¬µ«Ç¿µ÷ÆäϵͳδÔڴ˴ι¥»÷ÖÐÔâµ½ÈëÇÖ¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬Ð¹Â¶µÄÊý¾ÝÑù±¾ÏÔʾ£¬£¬£¬£¬ÂùݿÍÈ˵ÄÐÕÃû¡¢µØµã¡¢µç»°ºÅÂëºÍµç×ÓÓʼþµØµãµÈСÎÒ˽¼ÒÐÅÏ¢Òѱ»ÍµÈ¡£¬£¬£¬£¬²¢±»Ìí¼Óµ½¡°Have I Been Pwned¡±ÍøÕ¾ÉϹ©ÈËÅÌÎÊ¡£¡£¡£¡£¡£Ö»¹ÜÃÜÂëºÍÕ˵¥ÐÅϢδ±»µÁ£¬£¬£¬£¬µ«Óû§ÈÔÐèСÐÄÕë¶Ô´ËÎó²îµÄ¿ÉÒɵç×ÓÓʼþºÍÍøÂç´¹ÂÚ¹¥»÷¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/otelier-data-breach-exposes-info-hotel-reservations-of-millions/
2. PyPIÏÖ¡°pycord-self¡±¶ñÒâ°ü£¬£¬£¬£¬Õë¶ÔDiscord¿ª·¢Ö°Ô±ÇÔÈ¡ÁîÅÆÖ²ÈëºóÃÅ
1ÔÂ17ÈÕ£¬£¬£¬£¬Python°üË÷Òý£¨PyPI£©ÉÏ·ºÆðÁËÒ»¿îÃûΪ¡°pycord-self¡±µÄ¶ñÒâÈí¼þ°ü£¬£¬£¬£¬ËüÕë¶ÔµÄÊÇDiscord¿ª·¢Ö°Ô±¡£¡£¡£¡£¡£Õâ¿î¶ñÒâ°üÄ£ÄâÁ˹ãÊܽӴýµÄ¡°discord.py-self¡±°ü£¬£¬£¬£¬Òѱ»ÏÂÔØÔ¼885´Î¡£¡£¡£¡£¡£Ö»¹ÜËüÌṩÁËÕýµ±ÏîÄ¿µÄ¹¦Ð§£¬£¬£¬£¬µ«ÊµÔò°üÀ¨Ö´ÐÐÁ½ÏîÖ÷Òª¶ñÒâ²Ù×÷µÄ´úÂ룺һÊÇÇÔÈ¡DiscordÉí·ÝÑéÖ¤ÁîÅÆ²¢½«Æä·¢Ë͵½ÍⲿURL£¬£¬£¬£¬×ÝȻ˫ÒòËØÉí·ÝÑéÖ¤±£»£»£»£»¤´¦Óڻ״̬£¬£¬£¬£¬¹¥»÷ÕßÒ²ÄÜʹÓÃÕâЩÁîÅÆÐ®ÖÆ¿ª·¢Ö°Ô±µÄDiscordÕÊ»§£»£»£»£»¶þÊÇͨ¹ý¶Ë¿Ú6969ÓëÔ¶³ÌЧÀÍÆ÷½¨É賤ÆÚÅþÁ¬£¬£¬£¬£¬½¨ÉèºóÃÅ»úÖÆ£¬£¬£¬£¬Èù¥»÷ÕßÄܹ»Ò»Á¬»á¼ûÊܺ¦ÕßµÄϵͳ¡£¡£¡£¡£¡£SocketÑо¿Ö°Ô±¶Ô´Ë¾ÙÐÐÁËÏêϸÆÊÎö¡£¡£¡£¡£¡£Òò´Ë£¬£¬£¬£¬½¨ÒéÈí¼þ¿ª·¢Ö°Ô±ÔÚ×°ÖÃÈí¼þ°üʱ£¬£¬£¬£¬Îñ±ØÑéÖ¤´úÂëÊÇ·ñÀ´×Ô¹Ù·½×÷Õߣ¬£¬£¬£¬²¢¼ì²éÈí¼þ°üµÄÃû³Æ£¬£¬£¬£¬ÒÔ½µµÍ³ÉΪÊܺ¦ÕßµÄΣº¦¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬Ê¹ÓÿªÔ´¿âʱ£¬£¬£¬£¬½¨Òé¼ì²é´úÂëÖÐÊÇ·ñ±£´æ¿ÉÒɺ¯Êý£¬£¬£¬£¬²¢Ê¹ÓÃɨÃ蹤¾ß¼ì²âºÍ×èÖ¹¶ñÒâÈí¼þ°ü¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/malicious-pypi-package-steals-discord-auth-tokens-from-devs/
3. Lazarus×éÖ¯Õë¶Ô¿ª·¢Ö°Ô±Ìᳫ¡°99ºÅÐж¯¡±ÇÔÈ¡Ãô¸ÐÊý¾Ý
1ÔÂ17ÈÕ£¬£¬£¬£¬³¯ÏÊÕþ¸®Ö§³ÖµÄLazarus×éÖ¯ÕýÔÚ¿ªÕ¹ÃûΪ¡°99ºÅÐж¯¡±µÄÒ»Á¬¹¥»÷»î¶¯£¬£¬£¬£¬Õë¶ÔÈí¼þ¿ª·¢Ö°Ô±ÇÔÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£¡£¡£´Ë´Î»î¶¯±ê¼Ç×ÅLazarus×éÖ¯¹¥»÷Õ½ÂÔµÄÑݱ䣬£¬£¬£¬´ÓÆÕ±éµÄÍøÂç´¹ÂÚ¹¥»÷תÏòÕëµÐÊÖÒÕ¹©Ó¦Á´ÖеĿª·¢Ö°Ô±¾ÙÐÐÓÐÕë¶ÔÐԵĹ¥»÷¡£¡£¡£¡£¡£¹¥»÷Õßð³äÕÐÆ¸Ö°Ô±ÔÚLinkedInµÈƽ̨ÉÏÁªÏµÄ¿µÄ£¬£¬£¬£¬ÓÕµ¼Êܺ¦Õ߿ˡ¶ñÒâGitHub´æ´¢¿â£¬£¬£¬£¬Ö´ÐÐÆäÖеĴúÂëºóÅþÁ¬µ½Óɹ¥»÷Õß¿ØÖƵÄÏÂÁîºÍ¿ØÖÆÐ§ÀÍÆ÷¡£¡£¡£¡£¡£¸ÃЧÀÍÆ÷ʹÓø߶ȻìÏýµÄPython½ÅÔÀ´Ìӱܼì²â£¬£¬£¬£¬²¢Õë¶ÔÌØ¶¨Ä¿µÄ¶¯Ì¬¶¨ÖƶñÒâÈí¼þ¡£¡£¡£¡£¡£¸Ã»î¶¯°²ÅÅÁ˾ßÓÐÄ£¿£¿£¿é»¯×é¼þµÄ¶à½×¶Î¶ñÒâÈí¼þϵͳ£¬£¬£¬£¬ÒÔÇÔÈ¡¿ª·¢Ö°Ô±µÄÔ´´úÂë¡¢ÉñÃØ¡¢ÉèÖÃÎļþÒÔ¼°¼ÓÃÜÇ®±ÒÇ®°üÃÜÔ¿µÈÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£SecurityScorecard±Þ²ß¿ª·¢Ö°Ô±½ÓÄÉ×Ô¶¯µÄÇå¾²²½·¥£¬£¬£¬£¬ÈçÔöÇ¿´úÂë´æ´¢¿âÑéÖ¤¡¢Ê¹Óø߼¶¶ËµãÇå¾²½â¾ö¼Æ»®¼ì²âÒì³£»£»£»£»î¶¯¡¢ÔÚÆ½Ì¨ÉÏÑéÖ¤ÕÐÆ¸Ö°Ô±ºÍÊÂÇéʱ»ú£¬£¬£¬£¬²¢ÕÆÎÕʶ±ðΣÏÕÐźŵÄ֪ʶ¡£¡£¡£¡£¡£
https://www.infosecurity-magazine.com/news/lazarus-developers-data-theft/
4. ºÚ¿Í¡°0mid16B¡±Ðû²¼ÈëÇÖMedSave£¬£¬£¬£¬ÇÔÈ¡561GBÊý¾Ý²¢ÍýÏë³öÊÛ
1ÔÂ17ÈÕ£¬£¬£¬£¬ÃûΪ¡°0mid16B¡±µÄºÚ¿ÍÖÜÈýÐû²¼ÒÑÀÖ³ÉÈëÇÖÓ¡¶È´óÐ͵ÚÈý·½ÖÎÀí»ú¹¹MedSave£¬£¬£¬£¬ÇÔÈ¡ÁË561GBµÄÊý¾Ý¿â£¬£¬£¬£¬°üÀ¨Áè¼Ý1000ÍòÈ˵ÄÃô¸ÐÐÅÏ¢£¬£¬£¬£¬ÆäÖв»·¦¸ß¹Ü×ÊÁÏ£¬£¬£¬£¬ÇÒÊý¾Ý×èÖ¹ÖÁ2025Äê1ÔÂ8ÈÕ¡£¡£¡£¡£¡£0mid16Bδ͸¶ÈëÇÖÊֶΣ¬£¬£¬£¬µ«Éù³ÆMedSave³¤Ê±¼äδ²ì¾õÆä±£´æ£¬£¬£¬£¬ÇÒÔÚ1ÔÂ12ÈÕÖÁ15ÈÕʱ´úÈý´Î½øÈëϵͳ²¢×ÌÈÅÆäÔË×÷¡£¡£¡£¡£¡£Ö»¹ÜδÏòMedSaveÌá³öÏêϸÀÕË÷½ð¶î£¬£¬£¬£¬0mid16BÆ·ÆÀÆäÇå¾²·À»¤±¡Èõ£¬£¬£¬£¬Ö¸³ö¹«Ë¾Î´×°Ö÷À²¡¶¾Èí¼þ£¬£¬£¬£¬ÇÒÔÚÃ÷ÖªÎó²î±£´æµÄÇéÐÎÏÂÈÔÖØÆôЧÀÍÆ÷£¬£¬£¬£¬Ê¹ÆäµÃÒÔÈÝÒ×´«Êä´ó×ÚÊý¾Ý¶øÎ´´¥·¢¾¯±¨¡£¡£¡£¡£¡£MedSaveÍøÕ¾ÏÖÔÚÎÞ·¨»á¼û£¬£¬£¬£¬DataBreachesÒÑʵÑéͨ¹ý¶àÇþµÀÁªÏµMedSave¼û¸æÆäÇéÐΣ¬£¬£¬£¬µ«ÉÐδÊÕµ½»Ø¸´¡£¡£¡£¡£¡£0mid16BÌåÏÖÓÐÒâ³öÊÛ²¿·ÖÊý¾Ý²¢¹ûÕæ·Ç¿Í»§Êý¾Ý£¬£¬£¬£¬´ËÊÂÓдýMedSave½øÒ»²½»ØÓ¦¡£¡£¡£¡£¡£
https://databreaches.net/2025/01/17/medsave-health-insurance-tpa-hacked-firm-has-yet-to-comment-or-respond/
5. Ä£ÄâBlack BastaÊÖ·¨µÄÍøÂç¹¥»÷Ãé×¼SlashNext¿Í»§
1ÔÂ15ÈÕ£¬£¬£¬£¬SlashNextµÄһλ¿Í»§ÔâÓöÁËÄ£ÄâÎÛÃûÕÑÖøµÄBlack BastaÀÕË÷Èí¼þÍÅ»ïÊÖ·¨µÄÍøÂç¹¥»÷¡£¡£¡£¡£¡£Ôڶ̶Ì90·ÖÖÓÄÚ£¬£¬£¬£¬¹¥»÷ÕßÏò22¸öÓû§ÊÕ¼þÏä·¢ËÍÁË1165·â¶ñÒâÓʼþ£¬£¬£¬£¬ÍýÏëÓÕÆÓû§µã»÷¶ñÒâÁ´½Ó¡£¡£¡£¡£¡£SlashNextµÄÑо¿Ö°Ô±Õ¹ÏÖÁËÕâ´Î¹¥»÷ѸËÙÇÒ¾«×¼£¬£¬£¬£¬Ê¹ÓÃÁËÓëBlack BastaÏàËÆµÄÊÖ·¨£¬£¬£¬£¬Ö¼ÔÚÈÃÓû§´ëÊÖȱ·¦²¢Èƹý¹Å°åÇå¾²²½·¥¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÀÕË÷Èí¼þȦÌ×£¬£¬£¬£¬Î±×°³ÉÊ¢ÐÐÆ½Ì¨·¢ËÍÐéαÓʼþ£¬£¬£¬£¬Ê¹Óÿ´ËÆÎÞº¦µÄÓòÃûºÍÌØÊâ×Ö·ûµÄÖ÷ÌâÐУ¬£¬£¬£¬Õë¶Ô²î±ðÓû§½ÇÉ«Ìá¸ß¹Ø×¢¶È¡£¡£¡£¡£¡£ËûÃÇͨ¹ý¿´ËÆÕýµ±µÄÓʼþÑÍûÊÕ¼þÏ䣬£¬£¬£¬ÖÆÔìÔÓÂÒ£¬£¬£¬£¬ÓÕʹÓû§µã»÷Á´½Ó¡£¡£¡£¡£¡£µ±Óû§²»ÖªËù´ëʱ£¬£¬£¬£¬¹¥»÷Õßð³äITÖ§³Ö½éÈ룬£¬£¬£¬ÓÕÆÓû§×°ÖÃÔ¶³Ì»á¼ûÈí¼þ£¬£¬£¬£¬´Ó¶øÔÚϵͳÖÐÕ¾ÎȽŸú£¬£¬£¬£¬¿ÉÄÜÈö²¥¶ñÒâÈí¼þ»òÇÔÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£¡£¡£ÐÒÔ˵ÄÊÇ£¬£¬£¬£¬SlashNextµÄ¼¯³ÉÔÆÓʼþÇ徲ϵͳѸËÙʶ±ð³öΣÏÕÐźţ¬£¬£¬£¬ÊµÊ±Ó¦¶Ô¡£¡£¡£¡£¡£ÕâÒ»ÊÂÎñ͹ÏÔÁËÍøÂçÇå¾²ÍþвµÄÈÕÒæÖØ´óÐÔ£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÏȽøÊÖÒÕ¹æ±Ü¹Å°åÇå¾²²½·¥¡£¡£¡£¡£¡£Òò´Ë£¬£¬£¬£¬×éÖ¯Ó¦ÓÅÏÈ˼Á¿Íþв¼ì²âºÍÏìÓ¦£¬£¬£¬£¬°´ÆÚ¾ÙÐÐÇå¾²ÆÀ¹À£¬£¬£¬£¬ÒÔʶ±ðÎó²î²¢ÌáÉýÕûÌåÇå¾²ÐÔ¡£¡£¡£¡£¡£
https://hackread.com/black-basta-cyberattack-hits-inboxes-with-1165-emails/
6. Star Blizzardд¹ÂڻÃé×¼WhatsAppÕË»§
1ÔÂ19ÈÕ£¬£¬£¬£¬¶íÂÞ˹Ãñ×å¹ú¼ÒÐÐΪÕßStar Blizzard½üÆÚ¿ªÕ¹ÁËÒ»ÏîеÄÓã²æÊ½ÍøÂç´¹Âڻ£¬£¬£¬£¬×¨ÃŹ¥»÷Õþ¸®¡¢Íâ½»¡¢¹ú·ÀÕþ²ß¡¢¹ú¼Ê¹ØÏµ¼°ÎÚ¿ËÀ¼Ô®Öú×éÖ¯µÈÄ¿µÄµÄWhatsAppÕË»§¡£¡£¡£¡£¡£¸Ã»î¶¯ÓÚ2024Äê11ÔÂÖÐÑ®±»Î¢ÈíÍþвÇ鱨±¨¸æÕ¹ÏÖ£¬£¬£¬£¬±ê¼Ç×ÅStar BlizzardΪӦ¶ÔÕ½ÂÔºÍÊÖÒÕÆØ¹âËù×öµÄÕ½Êõת±ä¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýµç×ÓÓʼþð³äÃÀ¹úÕþ¸®¹ÙÔ±£¬£¬£¬£¬ÓÕÆÄ¿µÄ¼ÓÈëÖ§³ÖÎÚ¿ËÀ¼µÄ·ÇÕþ¸®×éÖ¯WhatsAppȺ×飬£¬£¬£¬ÓʼþÖаüÀ¨Ë𻵵ĶþάÂ룬£¬£¬£¬ÈôÊܺ¦Õß»ØÓ¦£¬£¬£¬£¬Ôò»á±»Ö¸µ¼ÖÁÐéÎ±ÍøÒ³£¬£¬£¬£¬ÒªÇóɨÃèеĶþάÂ룬£¬£¬£¬ÊµÔòÊǽ«¹¥»÷Õß×°±¸Á´½ÓÖÁÊܺ¦ÕßWhatsAppÕË»§¡£¡£¡£¡£¡£Î¢ÈíÖ¸³ö£¬£¬£¬£¬Ò»µ©Êܺ¦Õß²Ù×÷£¬£¬£¬£¬¹¥»÷Õß¼´¿É»á¼ûÆäWhatsAppÐÂÎÅ£¬£¬£¬£¬²¢Ê¹Óòå¼þÇÔÈ¡Êý¾Ý¡£¡£¡£¡£¡£´Ë´Î¹¥»÷ÒÀÀµÉç»á¹¤³Ìѧ£¬£¬£¬£¬²»Éæ¼°¶ñÒâÈí¼þ£¬£¬£¬£¬Óû§ÐèСÐÄδ¾ÇëÇóµÄͨѶ£¬£¬£¬£¬ÌØÊâÊǼÓÈëȺ×éµÄÔ¼Ç룬£¬£¬£¬²¢°´ÆÚ¼ì²éÓëWhatsAppÕË»§¹ØÁªµÄ×°±¸¡£¡£¡£¡£¡£´Ë´Î»î¶¯Åú×¢£¬£¬£¬£¬Ö»¹ÜStar BlizzardÔÚ2024Äê10ÔµĻÖÐÖ¹ºó²¿·ÖÓòÃû±»²é·â£¬£¬£¬£¬µ«ÆäÈÔͨ¹ý̽Ë÷й¥»÷ǰÑÔ¼ÌÐøÐж¯¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/star-blizzard-hackers-abuse-whatsapp-to-target-high-value-diplomats/


¾©¹«Íø°²±¸11010802024551ºÅ