BlackCatÀÕË÷Èí¼þ¶Ô¸çÂ×±ÈÑÇÄÜÔ´¹©Ó¦É̽øÐÐÍøÂç¹¥»÷
¸çÂ×±ÈÑÇÄÜÔ´¹«Ë¾ Empresas P¨²blicas de Medell¨ªn (EPM) ÖÜÒ»ÔâÊÜÁË BlackCat/ALPHV ÀÕË÷Èí¼þ¹¥»÷£¬¹«Ë¾ÔËÓªÖжϣ¬ÔÚÏß·þÎñÖжϡ£EPM ÊǸçÂ×±ÈÑÇ×î´óµÄ¹«¹²ÄÜÔ´¡¢Ë®ºÍÌìÈ»Æø¹©Ó¦ÉÌÖ®Ò»£¬Îª 123 ¸ö³ÇÊÐÌṩ·þÎñ¡£¸Ã¹«Ë¾ÔÚ 2022 Äê´´ÔìÁ˳¬¹ý 250 ÒÚÃÀÔªµÄÊÕÈ룬¹é¸çÂ×±ÈÑÇÂóµÂÁÖÊÐÕþ¸®ËùÓС£½üÈÕ£¬¹«Ë¾ÒªÇó´óÔ¼ 4,000 ÃûÔ±¹¤ÔÚ¼Ò¹¤×÷£¬IT »ù´¡ÉèÊ©³öÏÖ¹ÊÕÏ£¬¹«Ë¾ÍøÕ¾Ò²²»ÔÙ¿ÉÓá£Ñо¿ÈËÔ±·¢ÏÖ BlackCat ÀÕË÷Èí¼þ²Ù×÷£¨ÓÖÃû ALPHV£©Êǹ¥»÷µÄÄ»ºóºÚÊÖ£¬Éù³ÆÔÚ¹¥»÷ÆÚ¼äÇÔÈ¡Á˹«Ë¾Êý¾Ý¡£
²Î¿¼Á´½Ó£º
https://www.bleepingcomputer.com/news/security/colombian-energy-supplier-epm-hit-by-blackcat-ransomware-attack/?&web_view=true
ÀÕË÷Èí¼þÍÅ»ïʹÓÃеÄMicrosoft Exchange©¶´½øÐÐÍøÂç¹¥»÷
ÍøÂç»Æ½ð³Ç¹ÙÍø¹«Ë¾CrowdStrikeÔÚµ÷²éPlayÀÕË÷Èí¼þ¹¥»÷ʱ·¢ÏÖ¹¥»÷ÕßÕýÔÚʹÓÃеı»³ÆÎªOWASSRFµÄ©¶´¡£¸Ã©¶´Õë¶ÔMicrosoft Exchange·þÎñÆ÷½øÐй¥»÷£¬Äܹ»ÈƹýProxyNotShell URLÖØÐ´»º½â»úÖÆ£¬¹¥»÷ÕßÔÚǰÆÚÀûÓÃÆäËûÔ¶³Ì´úÂëÖ´ÐÐ(RCE)©¶´»ñµÃȨÏ޺󣬿ÉÀûÓôæÔÚÓÚOutlook Web Access (OWA) Ó¦ÓÃÖеÄOWASSRF©¶´¹¹Ôì³ö©¶´ÀûÓÃÁ´£¬ÔÚÒ×Êܹ¥»÷µÄExchange ·þÎñÆ÷ÉÏÉÏʵÏÖȨÏÞÌáÉý¡£CrowdStrike·¢ÏÖз¢Ïֵĩ¶´ºÜ¿ÉÄÜÊÇCVE-2022-41080£¬ÕâÊÇ΢Èí±ê¼ÇΪÑÏÖØÇÒδÔÚÒ°ÍâÀûÓõĻƽð³Ç¹ÙÍøÂ©¶´¡£

²Î¿¼Á´½Ó£º
https://www.bleepingcomputer.com/news/security/ransomware-gang-uses-new-microsoft-exchange-exploit-to-breach-servers/
΢Èí½«ÓÚ2023Äê1Ô¹رÕExchange Online»ù±¾Éí·ÝÑéÖ¤
΢Èí¾¯¸æ³Æ½«´Ó2023Äê1ÔÂÉÏÑ®¿ªÊ¼ÓÀ¾Ã¹Ø±ÕExchange Online·þÎñµÄ»ù±¾Éí·ÝÑéÖ¤¹¦ÄÜ£¬ÒÔÌá¸ß»Æ½ð³Ç¹ÙÍøÐÔ¡£Exchange ÍŶÓÖܶþ±íʾ£¬´Ó1³õ¿ªÊ¼Î¢Èí½«¶ÔÅäÖýøÐиü¸ÄÒÔÓÀ¾Ã½ûÓÃÐÒ鷶ΧÄڵĻù±¾Éí·ÝÑé֤ʹÓã¬ÔÚ´Ëǰ´óÔ¼7ÌìÏòÊÜÓ°Ïì×â»§µÄÏûÏ¢ÖÐÐÄ·¢ËÍÌû×Ó¡£ÔÚ»ù±¾Éí·ÝÑéÖ¤±»ÓÀ¾Ã½ûÓú󲻾ã¬ÈκÎʹÓûù±¾Éí·ÝÑéÖ¤Á¬½Óµ½ÊÜÓ°ÏìÐÒéÖ®Ò»µÄ¿Í»§¶Ë»òÓ¦ÓóÌÐò¶¼½«ÊÕµ½´íÎóµÄÓû§Ãû/ÃÜÂë/HTTP 401´íÎó¡£Microsoft 365×ܾÀíSeth PattonÔÚ9·Ý±íʾ£¬¸ù¾Ý΢Èí×ÔÉíµÄ»Æ½ð³Ç¹ÙÍøÑо¿±¨¸æ£¬ÒÑÖª³¬¹ý99%µÄÃÜÂëÅçÉäÀàÐ͵Ĺ¥»÷Õë¶Ô¸Ã»ù±¾Éí·ÝÑéÖ¤¹¦ÄÜ£¬½ûÓøù¦Äܺó¿Í»§ÔâÊܵÄΣº¦¿É¼õÉÙ67%ÒÔÉÏ¡£

²Î¿¼Á´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/microsoft-will-turn-off-exchange-online-basic-auth-in-january/
Glupteba½©Ê¬ÍøÂç±»µ·»ÙºóÔٴλîÔ¾
ÔÚ±» Google µ·»ÙÁ˽«½üÒ»ÄêÖ®ºó£¬Glupteba ¶ñÒâÈí¼þ½©Ê¬ÍøÂçÔٴλîÔ¾ÆðÀ´£¬ÔÚÈ«Çò·¶Î§ÄÚ¸ÐȾÉ豸¡£ÓÉÓڹȸèµÄŬÁ¦£¬Í¨¹ý»ñµÃ¿ØÖÆÆä»ù´¡ÉèÊ©µÄ·¨ÔºÃüÁîÒÔ¼°¶ÔÁ½¼Ò¶íÂÞ˹ÔËÓªÉÌÌáÆð·¨ÂÉËßËÏ£¬ÆôÓÃÇø¿éÁ´µÄ½©Ê¬ÍøÂç¿ÉÄÜ»áÔÚ 2021 Äê 12 ÔÂÊܵ½ÑÏÖØÆÆ»µ¡£¸ù¾ÝÑо¿ÈËÔ±µÄ·ÖÎö¡¢Çø¿éÁ´½»Òס¢TLS Ö¤Êé×¢²áºÍÄæÏò¹¤³Ì Glupteba Ñù±¾£¬ÓÐÒ»¸öеĴó¹æÄ£ Glupteba »î¶¯¿ªÊ¼ÓÚ 2022 Äê 5 Ô£¬²¢Ò»Ö±³ÖÐøµ½½ñÌì¡£

²Î¿¼Á´½Ó£º
https://www.cysecurity.news/2022/12/glupteba-malware-has-returned-after.html