ÃÀ¹ú¼ÓÖݳ¤Ì²ÊÐÔâµ½ÍøÂç¹¥»÷ÊÐÕþϵͳ¹Ø±ÕÊýÈÕ
Ðû²¼Ê±¼ä 2023-11-21¾ÝýÌå11ÔÂ18ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬ÃÀ¹ú¼ÓÀû¸£ÄáÑÇÖݳ¤Ì²ÊÐÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬¹Ø±ÕÁ˲¿·ÖITϵͳÒÔ±ÜÃâ¹¥»÷Èö²¥¡£¡£¡£¡£¡£¡£¡£¹¥»÷±¬·¢ÓÚ11ÔÂ14ÈÕ£¬£¬£¬£¬£¬£¬£¬²¢Î´Ó°Ïì½ôÆÈЧÀÍ£¬£¬£¬£¬£¬£¬£¬µ«¹«¹²ÊÂÒµ½É·ÑµÈ²¿·ÖÔÚÏßЧÀÍÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£×èÖ¹ÉÏÖÜÎ壬£¬£¬£¬£¬£¬£¬¸ÃÊÐÔ¤¼Æ¿ÉÄÜÐèÒª¼¸ÌìµÄʱ¼ä¾ÙÐлָ´¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬³¤Ì²ÊÐÒÑÐû²¼½øÈë½ôÆÈ״̬¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÈÔÔÚÊÓ²ìÖУ¬£¬£¬£¬£¬£¬£¬Éв»ÇåÎú¹¥»÷ÀàÐÍÒÔ¼°ÊÇ·ñ±£´æÊý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬Ò²Ã»Óй¥»÷ÕßÉù³Æ¶Ô´ËÊÂÈÏÕæ¡£¡£¡£¡£¡£¡£¡£
https://www.databreaches.net/long-beach-declares-local-emergency-after-cyber-incident/
2¡¢Áè¼Ý200ÍòÍÁ¶úÆä¹«ÃñµÄÒßÃç½ÓÖּͼ±»¹ûÕæÔÚ°µÍø
¾Ý11ÔÂ20ÈÕ±¨µÀ£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍÔÚ°µÍø¹ûÕæÁËÁè¼Ý200ÍòÍÁ¶úÆä¹«ÃñµÄÏêϸÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶ÐÅÏ¢°üÀ¨Ò½ÉúºÍ»¼ÕßµÄÍÁ¶úÆäÉí·ÝÖ¤ºÅÂ루¼ò³ÆTCKN£©¡¢ÒßÃç½ÓÖÖÈÕÆÚºÍÀàÐÍ¡¢ÆäËüÒßÃç½ÓÖֺ͹©Ó¦Á´ÏêÇéµÈ£¬£¬£¬£¬£¬£¬£¬¿ÉÄÜÔ´ÓÚÐÅϢй¶Îó²î¡£¡£¡£¡£¡£¡£¡£ËäÈ»Êý¾ÝÊÇ9ÔÂ10ÈÕй¶µÄ£¬£¬£¬£¬£¬£¬£¬µ«Ñо¿Ö°Ô±ÒÔΪÊÂÎñ±¬·¢ÔÚ4ÔÂ4ÈÕ¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ»¼ÕßµÄTCKN±»²¿·Öɾ¼õ£¬£¬£¬£¬£¬£¬£¬¶øÒ½ÉúµÄTCKNÔòÍêÕûÏÔʾ£¬£¬£¬£¬£¬£¬£¬ÕâÅú×¢ÕâЩÊý¾Ý¿ÉÄÜÊÇ´ÓÍÁ¶úÆäÒ½ÁÆÌṩÉÌ»òÎÀÉú²¿Ê¹ÓõÄÔÚÏ߯½Ì¨»òЧÀÍÖÐÇÔÈ¡µÄ¡£¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñ¿ÉÄÜй¶Á˸ùúÔ¼70%Ò½ÉúµÄPII¡£¡£¡£¡£¡£¡£¡£
https://www.hackread.com/hacker-leaks-turkish-citizens-vaccination-records/
3¡¢Ä¦¸ùÊ¿µ¤Àû¾ÍÊý¾Ýй¶ÊÂÎñ¸æ¿¢Ï¢ÕùÔÞ³ÉÅâ³¥650ÍòÃÀÔª
ýÌå11ÔÂ17Èճƣ¬£¬£¬£¬£¬£¬£¬Ä¦¸ùÊ¿µ¤ÀûÓë¸÷ÖݾÍÁ½ÆðÊý¾Ýй¶ÊÂÎñ¸æ¿¢Ï¢Õù£¬£¬£¬£¬£¬£¬£¬Ô¸ÒâÅâ³¥650ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£µ¼ÖÂËßËϵÄÊÂÎñ±¬·¢ÔÚ2016ÄêºÍ2019Äê¡£¡£¡£¡£¡£¡£¡£Õâ¼Ò¹«Ë¾Ô¼ÇëÁËÒ»¼ÒûÓÐÊý¾ÝÏú»ÙÂÄÀúµÄ¹«Ë¾´¦Öóͷ£±¨·ÏµÄ×°±¸£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÊý°ÙÍò¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢ÃæÁÙΣº¦¡£¡£¡£¡£¡£¡£¡£ÔÚµÚ¶þÆðÊÂÎñÖУ¬£¬£¬£¬£¬£¬£¬Ä¦¸ùÊ¿µ¤ÀûÔÚ´¦Öóͷ£±¨·Ï×°±¸Àú³ÌÖз¢Ã÷ÁË42̨ɥʧµÄЧÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬ËùÓÐЧÀÍÆ÷¶¼¿ÉÄܰüÀ¨Î´¼ÓÃܵĿͻ§ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬Ä¦¸ùÊ¿µ¤ÀûÒªÏò¸÷ÖÝÖ§¸¶650ÍòÃÀÔª£¬£¬£¬£¬£¬£¬£¬²¢½ÓÄÉÐëÒª²½·¥±£»£»£»¤¿Í»§Êý¾Ý¡£¡£¡£¡£¡£¡£¡£
https://www.databreaches.net/states-settle-with-morgan-stanley-for-6-5-million-over-data-security-incidents/
4¡¢FortinetÅû¶FortiSIEMÖеÄÎó²îCVE-2023-36553
11ÔÂ17ÈÕ±¨µÀ³Æ£¬£¬£¬£¬£¬£¬£¬FortinetÅû¶ÁËFortiSIEM±¨¸æÐ§ÀÍÆ÷ÖеÄϵͳÏÂÁî×¢ÈëÎó²î£¨CVE-2023-36553£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·Ö9.3£©¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÊÇÌØÊâÔªËØÖкͲ»µ±µ¼Öµģ¬£¬£¬£¬£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²î£¬£¬£¬£¬£¬£¬£¬Í¨¹ý·¢ËÍÌØÖÆµÄAPIÇëÇóÀ´Ö´ÐÐÏÂÁî¡£¡£¡£¡£¡£¡£¡£ÕâÊÇÊÇÄÚ²¿·¢Ã÷µÄÁíÒ»¸öÎó²î£¨CVE-2023-34992£©µÄ±äÌ壬£¬£¬£¬£¬£¬£¬¹«Ë¾ÓÚ10Ô³õÐÞ¸´Á˸ÃÎó²î¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚÉв»ÇåÎú¸ÃÎó²îÊÇ·ñÒѱ»Ê¹Óᣡ£¡£¡£¡£¡£¡£
https://securityaffairs.com/154301/security/fortinet-fortisiem-os-command-injection.html
5¡¢Unit 42Ðû²¼Stately Taurus¹¥»÷»î¶¯µÄÆÊÎö±¨¸æ
11ÔÂ17ÈÕ£¬£¬£¬£¬£¬£¬£¬Unit 42Ðû²¼ÁËÔÚ8Ô·ÝÊӲ쵽ÈýÆðStately Taurus¹¥»÷»î¶¯µÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£µÚÒ»¸ö»î¶¯±¬·¢ÔÚ8ÔÂ1ÈÕ£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ÁËÍйÜÔÚGoogle DriveÉϵÄStately Taurus£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß½«¶ñÒâÈí¼þ°üÉèÖÃΪZIPÎļþ230728 meeting minutes.zip¡£¡£¡£¡£¡£¡£¡£8ÔÂ3ÈÕ·¢Ã÷Á˵ڶþ¸ö»î¶¯£¬£¬£¬£¬£¬£¬£¬¶ñÒâÈí¼þ°üÃûΪNUG'sForeignPolicyStrategy.zip¡£¡£¡£¡£¡£¡£¡£µÚÈý¸ö»î¶¯ÔڽṹÉÏÓëµÚÒ»¸ö»î¶¯Ïàͬ£¬£¬£¬£¬£¬£¬£¬½¨ÉèÓÚ8ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬£¬¿ÉÊÇÆäZIPºÍEXEµÄÎļþÃûÊÇLabor Statement.zip¡£¡£¡£¡£¡£¡£¡£
https://unit42.paloaltonetworks.com/stately-taurus-targets-philippines-government-cyberespionage/
6¡¢SentinelLabsÐû²¼Ó¡¶È¹ÍÓ¶ºÚ¿ÍÍÅ»ïAppinµÄ±¨¸æ
11ÔÂ16ÈÕ£¬£¬£¬£¬£¬£¬£¬SentinelLabsÐû²¼Á˹ØÓÚÓ¡¶È¹ÍÓ¶ºÚ¿ÍÍÅ»ïAppin Software SecurityµÄ±¨¸æ¡£¡£¡£¡£¡£¡£¡£ËüµÄ·ÇÕýʽÃû³ÆÎªAppin Security Group (ASG)£¬£¬£¬£¬£¬£¬£¬ÓëÓ¡¶ÈÄ¿½ñµÄAPT»î¶¯Óкܴó¹ØÏµ£¬£¬£¬£¬£¬£¬£¬ÖÁÉÙ´Ó2009ÄêÆð¾Í¿ªÕ¹ÁËÐж¯¡£¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïµÄÄ¿µÄ¹æÄ£±é²¼È«Çò£¬£¬£¬£¬£¬£¬£¬°üÀ¨ÃÀ¹ú¡¢¼ÓÄôó¡¢Ó¡¶È¡¢Ãåµé¡¢¿ÆÍþÌØ¡¢ÃϼÓÀ¹ú¡¢°¢À²®ÁªºÏÇõ³¤¹úºÍ°Í»ù˹̹µÈ¡£¡£¡£¡£¡£¡£¡£³ýÁËʹÓÃÀ´×ÔµÚÈý·½µÄ´óÐÍ»ù´¡ÉèÊ©¾ÙÐÐÊý¾Ýй¶¡¢C2¡¢´¹ÂÚ¹¥»÷ºÍÉèÖÃÓÕ¶üÍøÕ¾Í⣬£¬£¬£¬£¬£¬£¬Ìý˵Ëü»¹ÒÀÀµVervata¡¢VupenºÍCore SecurityµÈ˽Ӫ¹©Ó¦ÉÌÌṩµÄÌØ¹¤Èí¼þºÍÎó²îʹÓÃЧÀÍ¡£¡£¡£¡£¡£¡£¡£
https://www.sentinelone.com/labs/elephant-hunting-inside-an-indian-hack-for-hire-group/


¾©¹«Íø°²±¸11010802024551ºÅ