https://www.infostealers.com/article/massive-moveit-vulnerability-breach-hacker-leaks-employee-data-from-amazon-mcdonalds-hsbc-hp-and-potentially-1000-other-companies/
3.1.2.¡¶ÂéÊ¡Àí¹¤Ñ§Ôº¼¼ÊõÆÀÂÛ¡·ÔâºÚ¿ÍÈëÇÖ£¬½ü30ÍòÓû§Êý¾Ýй¶
11ÔÂ4ÈÕ£¬½üÆÚÃûΪ¡°Intel Broker¡±µÄºÚ¿ÍÉù³ÆÍ¨¹ýµÚÈý·½³Ð°üÉÌÈëÇÖÁË¡¶ÂéÊ¡Àí¹¤Ñ§Ôº¼¼ÊõÆÀÂÛ¡·ÔÓÖ¾£¬²¢ÔÚBreach ForumsÉϹ«¿ªÁ˽ü30ÍòÌõÓû§¼Ç¼¡£ÕâЩÊý¾Ý¿ÉÄÜÔ´×Ô¸ÃÍøÕ¾µÄÐÂÎÅͨѶ¶©ÔÄÕßÃûµ¥£¬°üº¬È«Ãû¡¢µç×ÓÓʼþµØÖ·¡¢»î¶¯ÈÕÆÚ¼°½ÌÓýϸ½ÚµÈ¸öÈËÐÅÏ¢¡£
À´Ô´£º
https://hackread.com/hackers-leak-mit-technology-review-user-records/
3.1.3.Ê©ÄÍµÂµçÆøÔâºÚ¿ÍÈëÇÖ£¬40GBÊý¾Ý±»µÁ
11ÔÂ4ÈÕ£¬Ò»ÃûÃûΪ¡°Grep¡±µÄºÚ¿ÍÉù³ÆÀûÓñ©Â¶µÄƾ֤ÈëÇÖÁËÊ©ÄÍµÂµçÆø¹«Ë¾µÄJIRA·þÎñÆ÷£¬²¢×¥È¡ÁË40ÍòÐÐÓû§Êý¾Ý£¬ÆäÖаüÀ¨75000¸öΨһµç×ÓÓʼþµØÖ·ºÍÈ«Ãû¡£Ê©ÄÍµÂµçÆøÒѾȷÈÏÁË´Ë´ÎйÃÜʼþ£¬´Ë´ÎʼþÉæ¼°ÆäλÓÚ¸ôÀë»·¾³ÖеÄÄÚ²¿ÏîĿִÐиú×ÙÆ½Ì¨Ö®Ò»¡£
À´Ô´£º
https://www.bleepingcomputer.com/news/security/schneider-electric-confirms-dev-platform-breach-after-hacker-steals-data/
3.1.4.ÃÀ¹ú¶íº¥¶íÖݸçÂײ¼ÊÐ50Íò¾ÓÃñÐÅÏ¢ÔâÀÕË÷ÍÅ»ïÇÔÈ¡²¢Ð¹Â¶
11ÔÂ4ÈÕ£¬ÃÀ¹ú¶íº¥¶íÖݸçÂײ¼ÊУ¨È˿ڳ¬¹ý905000£©ÔÚ½ñÄê7ÔÂÔâÊÜRhysidaÀÕË÷Èí¼þÍÅ»ïµÄ¹¥»÷£¬µ¼Ö¹«¹²·þÎñºÍITÁ¬½ÓÖжϡ£¸ÃÍÅ»ïÉù³ÆÇÔÈ¡ÁË6.5TBÊý¾Ý£¬°üÀ¨Ô±¹¤Æ¾Ö¤¡¢³ÇÊÐÉãÏñ»úÔ´µÈÃô¸ÐÐÅÏ¢£¬²¢ÔÚÀÕË÷ʧ°Üºóй¶ÁË45%µÄ±»µÁÊý¾Ý¡£
À´Ô´£º
https://www.bleepingcomputer.com/news/security/city-of-columbus-data-of-500-000-stolen-in-july-ransomware-attack/
3.1.5.ÃÀ¹úHot TopicµÈÈýÆ·ÅÆÊý¾Ýй¶£¬5690ÍòÕË»§ÐÅÏ¢ÔâÆØ¹â
11ÔÂ11ÈÕ£¬¾ÝHave I Been Pwned¾¯¸æ£¬ÃÀ¹úÁãÊÛÁ¬ËøµêHot Topic¼°ÆìÏÂ×ÓÆ·ÅÆBox Lunch¡¢TorridµÄ¿Í»§¸öÈËÐÅÏ¢Ô⵽й¶£¬Éæ¼°56904909¸öÕË»§¡£Ð¹Â¶ÐÅÏ¢°üÀ¨¿Í»§È«Ãû¡¢µç×ÓÓʼþµØÖ·¡¢³öÉúÈÕÆÚ¡¢µç»°ºÅÂ롢ʵ¼ÊµØÖ·¡¢¹ºÂòÀúÊ·ÒÔ¼°²¿·ÖÐÅÓÿ¨Êý¾Ý¡£
À´Ô´£º
https://www.bleepingcomputer.com/news/security/hibp-notifies-57-million-people-of-hot-topic-data-breach/
3.1.6.³¬1ÒÚÉÌÒµÁªÏµÐÅÏ¢ÔâB2Bƽ̨DemandScienceÊý¾Ýй¶
11ÔÂ13ÈÕÏûÏ¢£¬×Ô2024Äê2ÔÂÒÔÀ´£¬Ò»¸öÃûΪ¡°KryptonZambie¡±µÄºÚ¿ÍÕßÔÚ BreachForumsÂÛ̳ÉϳöÊÛ 1.328ÒÚÌõ¸öÈËÐÅÏ¢¼Ç¼¡£Ä¿Ç°ÒÑ֤ʵ£¬ÕâЩÊý¾ÝÀ´×ÔÃÀ¹úÒ»¼Ò¾ÛºÏÊý¾ÝµÄ B2B ÐèÇóÉú³É¹«Ë¾ DemandScience£¨Ç°ÉíΪ Pure Incubation£©£¬°üÀ¨È«Ãû¡¢µØÖ·¡¢µç×ÓÓʼþ¡¢µç»°ºÅÂ롢ְλºÍÉ罻ýÌåÁ´½ÓµÈ£¬Êý¾ÝÊÇÓɸù«Ë¾´Ó¹«¹²À´Ô´ºÍµÚÈý·½ÊÕ¼¯µÄ¡£
À´Ô´£º
https://www.bleepingcomputer.com/news/security/leaked-info-of-122-million-linked-to-b2b-data-aggregator-breach/
4.1.¹úÄÚÒÆ¶¯»¥ÁªÍø»Æ½ð³Ç¹ÙÍøÈȵã
4.1.1.¹¤ÐŲ¿Í¨±¨ÇÖº¦Óû§È¨ÒæÐÐΪµÄAPP£¨SDK£©
¹¤ÒµºÍÐÅÏ¢»¯²¿¸ß¶ÈÖØÊÓÓû§È¨Òæ±£»¤¹¤×÷£¬ÒÀ¾Ý¡¶¸öÈËÐÅÏ¢±£»¤·¨¡·¡¶ÍøÂç»Æ½ð³Ç¹ÙÍø·¨¡·¡¶µçÐÅÌõÀý¡·¡¶µçÐźͻ¥ÁªÍøÓû§¸öÈËÐÅÏ¢±£»¤¹æ¶¨¡·µÈ·¨ÂÉ·¨¹æ£¬³ÖÐøÕûÖÎAPPÇÖº¦Óû§È¨ÒæµÄÎ¥¹æÐÐΪ¡£½üÆÚ£¬¹¤ÐŲ¿×éÖ¯µÚÈý·½¼ì²â»ú¹¹½øÐгé²é£¬¹²·¢ÏÖ27¿îAPP¼°SDK´æÔÚÇÖº¦Óû§È¨ÒæÐÐΪ£¬ÓèÒÔͨ±¨¡£
À´Ô´£º
https://www.miit.gov.cn/xwfb/gxdt/sjdt/art/2024/art_a20860e438684a039708611ceeadc003.html
4.1.2.ÃÀèÖ¡¢±¦±¦Ê÷µÈAppÆ½Ì¨ÍÆËÍÉæ»Æ¶ÌÐÅ£¿¹Ù·½»ØÓ¦£ºÊý¾Ý¿â»Æ½ð³Ç¹ÙÍø£¬Æô¶¯×Ô²é
½üÈÕ£¬¶àλÓû§ÔÚÉ罻ýÌå·¢Îijƣ¬×¼°Ö°Ö×¢²áĸӤAPPÃÀèÖºó£¬»áÆµ·±½Óµ½Éæ»Æ¶ÌÐÅ£¬¶ø´ËǰûÓгöÏÖ´ËÖÖÇé¿ö¡£³ýÁËÃÀèÖ£¬ÁíÒ»¿îĸӤAPP±¦±¦Ê÷ÔÐÓýÒ²±»Ö¸Ð¹Â¶Óû§Òþ˽¡£Ëæºó£¬ÃÀèֺͱ¦±¦Ê÷ÔÐÓýÏȺ󷢲¼¹Ù·½ÉùÃ÷»ØÓ¦£¬±íʾÉÐδ·¢ÏÖÓû§ÐÅϢй©µÈÎ¥·¨Î¥¹æÇé¿ö£¬¹«Ë¾Ä¿Ç°ÒÑ¿ªÕ¹ÄÚ²¿µ÷²é¡£
https://finance.sina.com.cn/roll/2024-11-18/doc-incwnnhp0320951.shtml
4.1.3.¹ú¼Ò¼ÆËã»ú²¡¶¾Ó¦¼±´¦ÀíÖÐÐļà²â·¢ÏÖ13¿îApp´æÔÚÒþ˽²»ºÏ¹æÐÐΪ
¹ú¼Ò¼ÆËã»ú²¡¶¾Ó¦¼±´¦ÀíÖÐÐÄÒÀ¾Ý¡¶ÍøÂç»Æ½ð³Ç¹ÙÍø·¨¡·¡¶¸öÈËÐÅÏ¢±£»¤·¨¡·¡¶AppÎ¥·¨Î¥¹æÊÕ¼¯Ê¹ÓøöÈËÐÅÏ¢ÐÐΪÈ϶¨·½·¨¡·µÈ·¨ÂÉ·¨¹æ¼°Ïà¹Ø¹ú¼Ò±ê×¼ÒªÇ󣬽üÆÚͨ¹ý»¥ÁªÍø¼à²â·¢ÏÖ13¿îÒÆ¶¯App´æÔÚÒþ˽²»ºÏ¹æÐÐΪ£¬Éæ¼°µçÉ̵ÈÁìÓò¡£
À´Ô´£º
https://news.cctv.com/2024/11/12/ARTIZ9G9Ok4GcMxqSmLBGT5P241112.shtml
4.1.4.ºþÄÏÊ¡ÍøÐŰìÖ´·¨Ô¼Ì¸10¼ÒÎ¥¹æÊÕ¼¯Ê¹ÓøöÈËÐÅÏ¢App¸ºÔðÈË
½üÆÚ£¬°´ÕÕ¡°ÁÁ½£ºþÏæ¡¤Ïû·ÑÁìÓò¸öÈËÐÅÏ¢È¨Òæ±£»¤¡±×¨ÏîÖ´·¨Ðж¯¹¤×÷²¿Ê𣬺þÄÏÊ¡ÍøÐŰì×éÖ¯¼¼ÊõÖ§³Åµ¥Î»£¬¾Û½¹²ÍÒûÍâÂô¡¢·¿ÎÝ×âÊÛ¡¢É̳¬¹ºÎͣ³µÔ¼³µµÈÉç»á¹Ø×¢¶È½Ï¸ß¡¢¸öÈËÐÅÏ¢±»ÀÄÓú͹ý¶ÈË÷È¡ÂÒÏóÍ»³öµÄËÄÀàÏû·Ñ³¡¾°£¬·¢ÏÖÁËÒ»ÅúÎ¥·¨Î¥¹æÊÕ¼¯Ê¹ÓøöÈËÐÅÏ¢µÄÎÊÌâ¡£ÏÂÒ»²½£¬ºþÄÏÊ¡ÍøÐŰ콫½øÒ»²½ÂäʵÊôµØ¹ÜÍøÖ°Ôð£¬ÑÏÀ÷²é´¦ÍøÂçÎ¥·¨Î¥¹æÐÐΪ£¬²»¶¨ÆÚÏòÉç»á¹«²¼×¨ÏîÖ´·¨Ðж¯³É¹ûºÍµäÐͰ¸Àý£¬¼ÓÇ¿¶ÔÏû·ÑÁìÓòÆóÒµµÄºÏ¹æÖ¸ÒýºÍ¶ÔÏû·ÑÕߵľ¯Ê¾ÌáÐÑ£¬»ý¼«»ØÓ¦ÈËÃñȺÖÚ¶Ô¸öÈËÐÅÏ¢±£»¤µÄ¹ØÇУ¬´Ù½ø»¥ÁªÍøÐÐÒµ½¡¿µÓÐÐò·¢Õ¹¡£
À´Ô´£º
https://www.cnr.cn/hunan/gstjhunan/20241102/t20241102_526962078.shtml
4.1.5.¿ìÊÖ¹«Ë¾±»¹«°²»ú¹Ø¾¯¸æ´¦·££¬Òòδ¼°Ê±´¦ÖýûÖ¹·¢²¼»ò´«ÊäÐÅÏ¢¡¢ÂäʵÇàÉÙÄêģʽ²»µ½Î»µÈÎÊÌâ
2024Äê11ÔÂ22ÈÕ£¬¾Ý¡°¹ú¼ÒÍøÂç»Æ½ð³Ç¹ÙÍøÍ¨±¨ÖÐÐÄ¡±½üÈÕÕë¶Ô¿ìÊÖ¹«Ë¾¶ÌÊÓÆµÖдæÔÚÎ¥·¨ÐÅÏ¢µÈÎÊÌ⣬¹«°²»ú¹ØÒÀ¾Ý¡¶ÍøÂç»Æ½ð³Ç¹ÙÍø·¨¡·¹æ¶¨£¬ÒÀ·¨¸øÓè¿ìÊÖ¹«Ë¾¾¯¸æ´¦·£¡£¾²é£¬¿ìÊÖ¹«Ë¾´æÔÚ¶Ô·¨ÂÉ¡¢ÐÐÕþ·¨¹æ½ûÖ¹·¢²¼»òÕß´«ÊäµÄÐÅϢδ¼°Ê±´¦Öã¬ÒÔ¼°ÂäʵÇàÉÙÄêģʽ²»µ½Î»µÈÇé¿ö£¬µ¼ÖÂÎ¥·¨ÐÅÏ¢À©É¢£¬Î£º¦Î´³ÉÄêÈËÉíÐĽ¡¿µ£¬Î¥·´ÁË¡¶ÍøÂç»Æ½ð³Ç¹ÙÍø·¨¡·Ïà¹Ø¹æ¶¨¡£¹«°²»ú¹ØÒÀ·¨¶Ô¿ìÊÖ¹«Ë¾¸øÓèÐÐÕþ´¦·££¬ÔðÁîÆäÈ«ÃæÂäʵÇàÉÙÄêģʽ£¬È«ÃæÅŲéÇåÀíÎ¥·¨ÐÅÏ¢£¬²¢ÒÀ·¨ÒÀ¹æ´¦ÖÃÎ¥·¨Î¥¹æÕ˺š£
À´Ô´£º
http://news.china.com.cn/2024-11/22/content_117564448.shtml
4.2.¹úÍâÒÆ¶¯»¥ÁªÍø»Æ½ð³Ç¹ÙÍøÈȵã
4.2.1.¼ÓÄôóÕþ¸®ÒÔ¹ú¼Ò»Æ½ð³Ç¹ÙÍøÎªÓÉÏÂÁîTikTok¹Ø±ÕÔÚ¼ÓÒµÎñ
¼ÓÄôó´´Ð¡¢¿ÆÑ§ºÍ¹¤Òµ²¿³¤Fran?ois-Philippe ChampagneÓÚ11ÔÂ7ÈÕÐû²¼£¬»ùÓÚ¹ú¼Ò»Æ½ð³Ç¹ÙÍø·çÏÕ¿¼ÂÇ£¬¼ÓÄôóÕþ¸®ÒÑÕýʽҪÇó×Ö½ÚÌø¶¯ÆìϵÄTikTokÖÕÖ¹ÆäÔÚ¼ÓÄôóµÄÒµÎñÔËÓª¡£ÕâÒ»¾ö¶¨Êǽ¨Á¢ÔÚ¼ÓÄÃ´ó»Æ½ð³Ç¹ÙÍøÇ鱨²¿ÃÅºÍÆäËûÕþ¸®ºÏ×÷»ï°éµÄ½¨Òé»ù´¡Ö®ÉÏ£¬¾¹ýÈ«ÃæÉó²éºó×ö³öµÄ¡£ÕâÏîÃüÁδ½ûÖ¹¼ÓÄôóÃñÖÚʹÓÃTikTokÓ¦ÓóÌÐò»ò´´×÷ÄÚÈÝ¡£¼ÓÄôóÕþ¸®±íʾ£¬Ê¹ÓÃÉ罻ýÌåÓ¦ÓÃÊǸöÈËÑ¡Ôñ¡£²»¹ýÕþ¸®Í¬Ê±ÌáÐѹ«ÃñÔÚʹÓÃÉ罻ýÌåÆ½Ì¨Ê±ÐèҪעÒâÍøÂç»Æ½ð³Ç¹ÙÍøÊµ¼ù£¬ÌرðÊÇÆÀ¹ÀÍâ¹ú»ú¹¹ÈçºÎ»ñÈ¡¡¢¹ÜÀí¡¢Ê¹Óú͹²Ïí¸öÈËÐÅÏ¢¿ÉÄÜ´øÀ´µÄDZÔÚ·çÏÕ¡£
À´Ô´£º
https://thehackernews.com/2024/11/canada-orders-tiktok-to-shut-down.html
4.2.2.ÐÂÐͰ²×¿¶ñÒâÈí¼þToxicPandaÀ´Ï®£¬³¬1500Ì¨ÒøÐÐÉ豸ÒÑÂÙÏÝ
»Æ½ð³Ç¹ÙÍøÑо¿»ú¹¹CleafyÈÕǰÅû¶£¬ÐÂÐÍAndroid¶ñÒâÈí¼þ"ToxicPanda"Ö÷ÒªÕë¶ÔÁãÊÛÒøÐпͻ§£¬ÒÑÔÚÒâ´óÀû¡¢ÆÏÌÑÑÀ¡¢Î÷°àÑÀºÍ²¿·ÖÀÃÀµØÇø¸ÐȾ³¬¹ý1500̨É豸£¬ÆäÖÐÒâ´óÀûÕ¼±È³¬¹ý50%¡£ToxicPandaĿǰÉд¦ÓÚ·¢Õ¹½×¶Î£¬Æä´úÂëÖÐȱ·¦»ìÏý¼¼ÊõºÍµ÷ÊÔÎļþ£¬ÕâÒâζןöñÒâÈí¼þºÜ¿ÉÄÜ»á½øÒ»²½Éý¼¶¡£
À´Ô´£º
https://www.infosecurity-magazine.com/news/toxicpanda-malware-banking-android/
4.2.3.¸ßͨоƬ×鯨ÑÏÖØ»Æ½ð³Ç¹ÙÍøÈ±ÏÝ£¬»òÓ°ÏìÊý°ÙÍòAndroidÉ豸
ÈÕǰ£¬¹È¸è¹«Ë¾ÔÚ×îеÄAndroid»Æ½ð³Ç¹ÙÍø¹«¸æÖйٷ½Åû¶ÁËÁ½¸öÕýÔÚ±»ºÚ¿Í»ý¼«ÀûÓõÄÁãÈջƽð³Ç¹ÙÍøÈ±ÏÝ£¬²¢ºôÓõÓû§Á¢¼´¸üÐÂÉ豸ϵͳ¡£ÆäÖÐÒ»¸öȱÏÝ£¨CVE-2024-43047£©ÊÇÒ»¸öÓ°Ïì¸ßͨоƬ×éµÄ¸ßΣ©¶´¡£Õâ¸ö´æÔÚÓÚ¸ßͨFastRPCÇý¶¯³ÌÐòÖеÄÊͷźóʹÓã¨use-after-free£©Â©¶´¿ÉÄܱ»¹¥»÷ÕßÀûÓÃÀ´Ö´ÐÐÈÎÒâ´úÂ룬½ø¶øÊµÏÖδÊÚȨ·ÃÎʺÍȨÏÞÌáÉý¡£¸Ã©¶´Ó°Ïì°üÀ¨æçÁú8£¨µÚÒ»´ú£©ÔÚÄÚµÄÊýÊ®¿î¸ßͨоƬ×飬²¨¼°Ä¦ÍÐÂÞÀ¡¢ÈýÐÇ¡¢OnePlus¡¢OPPO¡¢Ð¡Ã׺ÍÖÐÐËµÈÆ·ÅƵÄÖÚ¶àAndroidÊÖ»ú¡£
À´Ô´£º
https://cybersecuritynews.com/android-zero-day-flaws-actively-exploited/
4.2.4.FakeCall°²×¿¶ñÒâÈí¼þбäÖÖ³öÏÖ£¬Ãé×¼AndroidÎÞÕϰ·þÎñ
½üÈÕ£¬Zimperium zLabs»Æ½ð³Ç¹ÙÍøÑо¿ÈËÔ±·¢ÏÖÁËFakeCal°²×¿¶ñÒâÈí¼þµÄÒ»¸öбäÖÖ£¬¸ÃÈí¼þ¾ß±¸¸üÇ¿´óµÄ¹¦ÄÜ£¬¿É¶ÔÊܺ¦ÕßÉ豸ʵʩ¸üÈ«ÃæµÄ¿ØÖÆ£¬´Ó¶ø½øÐÐÆÛÕ©ºÍÍøÂç¼äµý»î¶¯¡£
À´Ô´£º
https://www.darkreading.com/cyberattacks-data-breaches/vishing-mishing-fakecall-android-malware