SECÖ¸¿ØICEÎ¥·´Áª°î¹æÔò²¢·£¿£¿£¿£¿î1000ÍòÃÀÔª
Ðû²¼Ê±¼ä 2024-05-245ÔÂ23ÈÕ£¬£¬£¬£¬£¬ÃÀ¹ú֤ȯÉúÒâίԱ»á£¨SEC£©Ö¸¿ØÖÞ¼ÊÉúÒâËù£¨ICE£©Î´ÄÜʵʱÏòÆä¾Å¼ÒÈ«×Ê×Ó¹«Ë¾×ª´ï 2021 Äê 4 Ô 15 ÈÕ±¬·¢µÄÍøÂç¹¥»÷£¬£¬£¬£¬£¬µ¼ÖÂÆäÎ¥·´Áª°î¹æÔò¡£¡£¡£¡£¡£¡£¡£ÃÀ¹ú֤ȯÉúÒâίԱ»áÖÜÈýÐû²¼ÁË 1000 ÍòÃÀÔªµÄ·£¿£¿£¿£¿î£¬£¬£¬£¬£¬²¢ÌåÏÖ ICE ¼°Æä×Ó¹«Ë¾¼È²»ÈÏ¿ÉÒ²²»·ñ¶¨ÃÀ¹ú֤ȯÉúÒâίԱ»áµÄÊÓ²ìЧ¹û¡£¡£¡£¡£¡£¡£¡£ICE ±¨¸æ³Æ£¬£¬£¬£¬£¬2024ÄêµÚÒ»¼¾¶ÈµÄ¾»ÊÕÈëΪ 23 ÒÚÃÀÔª£¬£¬£¬£¬£¬³ýÁËÓµÓÐÉúÒâËùÍ⣬£¬£¬£¬£¬»¹Ìṩ½ðÈÚÊÖÒÕºÍÊý¾ÝЧÀÍ¡£¡£¡£¡£¡£¡£¡£SEC ³Æ£¬£¬£¬£¬£¬ÊÓ²ìÏÔʾ£¬£¬£¬£¬£¬ÔÚÊÂÎñ±¬·¢Ê±´ú£¬£¬£¬£¬£¬ICE Á¬Ã¦ÖªµÀºÚ¿Í¡°½«¶ñÒâ´úÂë²åÈëÓÃÓÚÔ¶³Ì»á¼û ICE ¹«Ë¾ÍøÂçµÄ VPN ×°±¸¡±£¬£¬£¬£¬£¬µ«¼¸Ììºó²Å֪ͨŦԼ֤ȯÉúÒâËùºÍÆäËû×Ó¹«Ë¾¡£¡£¡£¡£¡£¡£¡£SEC ³Æ£¬£¬£¬£¬£¬ÑÓ³Ù±¨¸æ²»µ«Î¥·´ÁËÁª°î¹æÔò£¬£¬£¬£¬£¬Ò²Î¥·´ÁË ICE ×Ô¼ºµÄ³ÌÐò¡£¡£¡£¡£¡£¡£¡£
https://therecord.media/sec-penalty-intercontinental-exchange-cybersecurity-incident
2. Êý°ÙÍòÃÀ¹úÈË·¸·¨¼Í¼Êý¾Ý¿â±»Ð¹Â¶µ½ÍøÉÏ
5ÔÂ22ÈÕ£¬£¬£¬£¬£¬Ò»¸öÒÔ EquationCorp ºÍ USDoD ΪÃûµÄÍøÂç·¸·¨·Ö×ÓÐû²¼ÁËÒ»¸öÖØ´óµÄÊý¾Ý¿â£¬£¬£¬£¬£¬ÆäÖаüÀ¨Êý°ÙÍòÃÀ¹úÈ˵폷¨¼Í¼¡£¡£¡£¡£¡£¡£¡£Ìý˵¸ÃÊý¾Ý¿â°üÀ¨ 7000 ÍòÐÐÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¾Ý³Æ£¬£¬£¬£¬£¬Ð¹Â¶µÄÊý¾Ý¿â°üÀ¨È«Ãû¡¢³öÉúÈÕÆÚ¡¢ÒÑÖªÓÖÃû¡¢µØµã¡¢¾Ð²¶ºÍÖÎ×ïÈÕÆÚ¡¢ÐÌÆÚµÈ¡£¡£¡£¡£¡£¡£¡£¾Ý±¨µÀ£¬£¬£¬£¬£¬ÈÕÆÚ¹æÄ£´Ó 2020 Äêµ½ 2024 Äê¡£¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âµÄÏêϸȪԴÏÖÔÚÉв»ÇåÎú¡£¡£¡£¡£¡£¡£¡£ÎãÓ¹ÖÃÒÉ£¬£¬£¬£¬£¬·¸·¨ÐÅϢй¶½«±¬·¢ÖØ´óÓ°Ï죬£¬£¬£¬£¬²»µ«¶ÔÃûµ¥ÉϵÄСÎÒ˽¼Ò£¬£¬£¬£¬£¬²¢ÇÒ¶Ô˾·¨ÏµÍ³Ò²ÊÇÔÆÔÆ¡£¡£¡£¡£¡£¡£¡£
https://www.malwarebytes.com/blog/news/2024/05/criminal-record-database-of-millions-of-americans-dumped-online
3. Ñо¿Ö°Ô±·¢Ã÷¼ÓÃÜÐ®ÖÆ¹¥»÷¿É½ûÓö˵㱣»£»£»£»£»£»£»¤
5ÔÂ23ÈÕ£¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÌåÏÖ£¬£¬£¬£¬£¬×î½üÔÚÒ°·¢Ã÷µÄ¶ñÒâÈí¼þʹÓÃÖØ´óµÄ²½·¥À´½ûÓ÷À²¡¶¾±£»£»£»£»£»£»£»¤£¬£¬£¬£¬£¬Ïú»ÙѬȾ֤¾Ý£¬£¬£¬£¬£¬²¢Ê¹ÓüÓÃÜÇ®±ÒÍÚ¾òÈí¼þÓÀÊÀѬȾ»úе¡£¡£¡£¡£¡£¡£¡£ÈÃÕâ¸öÒì³£ÖØ´óµÄ¶ñÒâÈí¼þϵͳÔËÐеÄÒªº¦ÊÇÖ÷ÔØºÉÖеÄÒ»ÏЧ£¬£¬£¬£¬£¬ÃûΪ GhostEngine£¬£¬£¬£¬£¬Ëü¿ÉÒÔ½ûÓà Microsoft Defender »òÄ¿µÄÅÌËã»úÉÏ¿ÉÄÜÔËÐеÄÈÎºÎÆäËû·À²¡¶¾»ò¶Ëµã±£»£»£»£»£»£»£»¤Èí¼þ¡£¡£¡£¡£¡£¡£¡£Ëü»¹Òþ²ØÁËÈκα»ÈëÇÖµÄÖ¤¾Ý¡£¡£¡£¡£¡£¡£¡£GhostEngine ¶ñÒâÈí¼þµÄÖ÷ҪĿµÄÊÇʹ¶ËµãÇå¾²½â¾ö¼Æ»®Ê§Ð§²¢½ûÓÃÌØ¶¨µÄ Windows ÊÂÎñÈÕÖ¾£¬£¬£¬£¬£¬ÀýÈç¼Í¼Àú³Ì½¨ÉèºÍЧÀÍ×¢²áµÄÇå¾²ºÍϵͳÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£
https://arstechnica.com/security/2024/05/researchers-spot-cryptojacking-attack-that-disables-endpoint-protections/
4. OmniVisionÔÚ2023ÄêÀÕË÷¹¥»÷ºóÅû¶Êý¾Ýй¶ÊÂÎñ
5ÔÂ22ÈÕ£¬£¬£¬£¬£¬OmniVision Technologies ÊÇÒ»¼ÒרÃÅ¿ª·¢ÏȽøÊý×Ö³ÉÏñ½â¾ö¼Æ»®µÄ¹«Ë¾¡£¡£¡£¡£¡£¡£¡£2023 Ä꣬£¬£¬£¬£¬OmniVision ÓµÓÐ 2,200 ÃûÔ±¹¤£¬£¬£¬£¬£¬ÄêÊÕÈëΪ 14 ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£¡£OmniVision Technologies Inc. ÊÇÖйú°ëµ¼ÌåÆ÷¼þºÍ»ìÏýÐźż¯³Éµç·Éè¼Æ¹«Ë¾Î¤¶û°ëµ¼ÌåµÄÃÀ¹ú×Ó¹«Ë¾¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Éè¼ÆºÍ¿ª·¢ÓÃÓÚÊÖ»ú¡¢Ìõ¼Ç±¾µçÄÔ¡¢ÉÏÍø±¾ºÍÍøÂçÉãÏñÍ·¡¢Çå¾²ºÍ¼à¿ØÉãÏñÍ·¡¢ÓéÀÖ¡¢Æû³µºÍÒ½ÁƳÉÏñϵͳµÄÊý×Ö³ÉÏñ²úÆ·¡£¡£¡£¡£¡£¡£¡£2023 Ä꣬£¬£¬£¬£¬Õâ¼ÒͼÏñ´«¸ÐÆ÷ÖÆÔìÉÌÔâÊÜÁËCactus ÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚÉв»ÇåÎúÊÜÓ°ÏìÈËÊý¡£¡£¡£¡£¡£¡£¡£2023 Äê 10 Ô£¬£¬£¬£¬£¬Cactus ÀÕË÷Èí¼þ×éÖ¯ÔÚÆä Tor ×ßÂ©ÍøÕ¾ÉϽ« OmniVision Ìí¼Óµ½Êܺ¦ÕßÃûµ¥ÖС£¡£¡£¡£¡£¡£¡£×÷ΪÊý¾Ýй¶µÄÖ¤¾Ý£¬£¬£¬£¬£¬¸ÃÀÕË÷×éÖ¯Ðû²¼ÁËÊý¾ÝÑù±¾£¬£¬£¬£¬£¬°üÀ¨»¤ÕÕͼÏñ¡¢±£ÃÜÐÒé¡¢ÌõÔ¼ºÍÆäËûÎļþ¡£¡£¡£¡£¡£¡£¡£Ëæºó£¬£¬£¬£¬£¬ÔÚËùνµÄ̸ÅÐʧ°Üºó£¬£¬£¬£¬£¬¸ÃÍÅ»ïÃâ·ÑÐû²¼ÁËËùÓб»µÁÊý¾Ý£¬£¬£¬£¬£¬²»¹ý£¬£¬£¬£¬£¬OmniVision ÏÖÔÚÒѲ»ÔÙÁÐÔÚ Cactus Êê½ðйÃÜÍøÕ¾ÉÏ¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/163506/data-breach/omnivision-data-breach.html
5. ConfluenceÔ¶³Ì´úÂëÖ´ÐÐÎó²îCVE-2024-21683
5ÔÂ22ÈÕ£¬£¬£¬£¬£¬ÆÕ±éʹÓõÄÍŶÓÊÂÇéÇøÆóÒµ wiki Confluence ±»·¢Ã÷±£´æÑÏÖØµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î±»±ê¼ÇΪ CVE-2024-21683£¬£¬£¬£¬£¬ÑÏÖØÐÔΪ 8.3£¨¸ß£©¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÓ°Ïì Confluence Êý¾ÝÖÐÐĺÍЧÀÍÆ÷µÄ¶à¸ö°æ±¾£¬£¬£¬£¬£¬°üÀ¨Êý¾ÝÖÐÐİ汾 8.9.0 ºÍЧÀÍÆ÷°æ±¾ 8.5.0 ÖÁ 8.5.8 LTS¡£¡£¡£¡£¡£¡£¡£²»¹ý¸ÃÎó²îÒѾÔÚConfluence Data CenterºÍServerµÄ×îа汾ÖÐÐÞ¸´¡£¡£¡£¡£¡£¡£¡£´ËÎó²îÔÊÐí¾ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÔÚϵͳÖÐÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬Õâ¿ÉÄÜ»á¶Ô CIA £¨ÉñÃØÐÔ¡¢ÍêÕûÐԺͿÉÓÃÐÔ£©Ôì³ÉÑÏÖØÓ°Ïì¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬´ËÎó²î²»ÐèÒªÈκÎÓû§½»»¥¼´¿ÉÀֳɡ£¡£¡£¡£¡£¡£¡£
https://gbhackers.com/critical-confluence-server-flaw/
6. London DrugsÒ©µêÈ·ÈÏÔâµ½ÀÕË÷¹¥»÷µ«²»Ö§¸¶Êê½ð
5ÔÂ22ÈÕ£¬£¬£¬£¬£¬ÄôóÁ¬ËøÒ©µêÂ×¶ØÒ©µê (London Drugs) ÒÑÈ·ÈÏÀÕË÷Èí¼þ·¸·¨·Ö×ÓÇÔÈ¡ÁËÆä²¿·Ö°üÀ¨Ô±¹¤ÐÅÏ¢µÄ¹«Ë¾Îļþ£¬£¬£¬£¬£¬²¢ÌåÏÖ¡°²»¿ÏÒâÒ²ÎÞ·¨ÏòÕâÐ©ÍøÂç·¸·¨·Ö×ÓÖ§¸¶Êê½ð¡±¡£¡£¡£¡£¡£¡£¡£Õâ¼Ò×ܲ¿Î»ÓÚ²»Áе߸çÂ×±ÈÑǵĹ«Ë¾ÔÚ¸øThe RegisterµÄÒ»·ÝÉùÃ÷Öгƣ¬£¬£¬£¬£¬4 Ô 28 ÈÕµÄÈëÇÖÊÂÎñÊÇ¡°ÓÉһȺÀÏÁ·µÄÈ«ÇòÍøÂç·¸·¨·Ö×ÓÈ«ÐIJ߻®µÄ¹¥»÷¡±£¬£¬£¬£¬£¬¶ø¸Ã¹«Ë¾´ËÇ°Ôø³ÆÆäΪ¡°ÍøÂçÇå¾²ÊÂÎñ¡±¡£¡£¡£¡£¡£¡£¡£ ´Ë´ÎÊý×ÖÈëÇÖÊÂÎñÆÈʹÂ×¶ØÒ©µêÔÚ²»Áе߸çÂ×±ÈÑÇÊ¡¡¢°¢¶û²®ËþÊ¡¡¢ÈøË¹¿¦³¹ÎÂÊ¡ºÍÂíÄáÍаÍÊ¡µÄ 79 ¼ÒÃÅµê¹Ø±ÕÖÁ 5 Ô 7 ÈÕ£¬£¬£¬£¬£¬µ«Ò©·¿ÊÂÇéÖ°Ô±ÈÔÔÚµêÍâáÝáåÒÔÅäÖÆÖ÷Òª´¦·½¡£¡£¡£¡£¡£¡£¡£
https://www.theregister.com/2024/05/22/london_drugs_ransomware/


¾©¹«Íø°²±¸11010802024551ºÅ