ICAOÊÓ²ìDZÔÚÐÅÏ¢Çå¾²ÊÂÎñ £¬Éæ¼°42,000·ÝÎļþй¶

Ðû²¼Ê±¼ä 2025-01-09

1. ICAOÊÓ²ìDZÔÚÐÅÏ¢Çå¾²ÊÂÎñ £¬Éæ¼°42,000·ÝÎļþй¶


1ÔÂ7ÈÕ £¬ÍŽá¹ú¹ú¼ÊÃñÓú½¿Õ×éÖ¯£¨ICAO£©Ðû²¼ÕýÔÚÊÓ²ìÒ»ÆðDZÔÚµÄÐÅÏ¢Çå¾²ÊÂÎñ¡£¸Ã×éÖ¯ÊÇÒ»¸ö½¨ÉèÓÚ1944ÄêµÄÕþ¸®¼ä×éÖ¯ £¬Óë193¸ö¹ú¼ÒÏàÖú £¬ÖÂÁ¦ÓÚÖÆ¶©Ï໥ÈϿɵÄÊÖÒÕ±ê×¼¡£¾Ý³Æ £¬´Ë´ÎÊÂÎñÓëÒ»¸öÕë¶Ô¹ú¼Ê×éÖ¯µÄÍþвÐÐΪÕßÓйØ¡£Ö»¹ÜICAOδÌṩÏêϸϸ½Ú £¬µ«´ËÉùÃ÷ÊÇÔÚÒ»¸öÃûΪ¡°natohub¡±µÄÍþвÐÐΪÕßÔÚºÚ¿ÍÂÛ̳ÉÏй¶Á˾ݳƴÓICAOÇÔÈ¡µÄ42,000·ÝÎļþÁ½ÌìºóÐû²¼µÄ¡£±»µÁÎļþ¾Ý³Æ°üÀ¨Ð¡ÎÒ˽¼ÒÉí·ÝÐÅÏ¢ £¬ÈçÐÕÃû¡¢³öÉúÈÕÆÚ¡¢µØµã¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØµãÒÔ¼°½ÌÓýºÍ¾ÍÒµÐÅÏ¢¡£´Ëǰ £¬ÍŽá¹úÆäËû»ú¹¹Ò²ÔâÊܹýÍøÂç¹¥»÷ºÍÊý¾Ýй¶ÊÂÎñ £¬ÀýÈçÍŽá¹úÉú³¤ÍýÏëÊð£¨UNDP£©ºÍÍŽá¹úÇéÐÎÍýÏëÊð£¨UNEP£©¡£ÍŽá¹úÍøÂçÒ²Ôø¶à´ÎÔâµ½¹¥»÷ £¬µ¼ÖÂÔ±¹¤¼Í¼¡¢¿µ½¡°ü¹ÜºÍÉÌÒµÌõÔ¼µÈÊý¾Ýй¶¡£´Ë´ÎICAOµÄÉùÃ÷Åú×¢ £¬¸Ã×éÖ¯ÕýÔÚÆð¾¢Ó¦¶ÔDZÔÚµÄÐÅÏ¢Çå¾²Íþв £¬²¢½ÓÄÉÐëÒªµÄÇå¾²²½·¥¡£


https://www.bleepingcomputer.com/news/security/un-aviation-agency-investigating-potential-security-breach/


2. ÌïÄÉÎ÷Öݬɪ¸£ÏØÑ§Ð£ÔâÍøÂç¹¥»÷ £¬Ãô¸ÐÊý¾Ýй¶


1ÔÂ7ÈÕ £¬ÌïÄÉÎ÷Öݬɪ¸£ÏØÑ§Ð£½üÆÚÔâÓöÁËÍøÂç¹¥»÷ÊÂÎñ¡£ÏÈÊÇ10ÔÂ19ÈÕ £¬Black SuitÀÕË÷Èí¼þ×éÖ¯Éù³ÆÏ®»÷Á˸ÃѧУ £¬µ«ËæºóѧУ·½Ãæ·ñ¶¨ÁËÕâÒ»Ö¸¿Ø £¬ÌåÏÖÊܹ¥»÷µÄÊÇÁíÒ»ËùѧУ¡£È»¶ø £¬Á½¸ö¶àÔºó £¬Rhysida×éÖ¯Ðû²¼È·ÊµÏ®»÷Áˬɪ¸£ÏØÑ§Ð£ £¬²¢Ð¹Â¶Á˰üÀ¨Ñ§ÉúºÍÔ±¹¤Ãô¸ÐÐÅÏ¢µÄ1.2TBÊý¾ÝÖеÄ60%¡£Ð¹Â¶µÄÊý¾ÝÉæ¼°¿µ½¡¼Í¼¡¢ÌØÊâ½ÌÓý¼Í¼ÒÔ¼°ÈËÁ¦×ÊÔ´²¿Îļþ £¬°üÀ¨´ó×ÚСÎÒ˽¼ÒÉí·ÝÐÅÏ¢ £¬ÈçÉç»áÇå¾²ºÅÂë¡¢Éí·ÝÖ¤ºÍЧ¹ûµ¥µÈ £¬¸øÑ§Éú¡¢¼Ò³¤ºÍÔ±¹¤´øÀ´ÁËÖØ´óÀ§ÈÅ¡£ÏÖÔÚÉв»ÇåÎúÍþвÐÐΪÕßÊÇ·ñ³öÊÛÁËÊý¾Ý»òÊÇ·ñ»áй¶¸ü¶à¡£Õë¶Ô´ËÇéÐÎ £¬ÌáÐѹ«ÖÚ×¢ÖØ±£»¤Ð¡ÎÒ˽¼ÒÒþ˽ £¬ÌØÊâÊÇÄêÂú18ËêµÄǰѧÉú¡¢ÏÖÈÎѧÉú¡¢¼Ò³¤ÒÔ¼°ÏÖÈκÍǰÈÎÔ±¹¤ £¬Ó¦Á¬Ã¦¶ÔÐÅÓñ¨¸æ¾ÙÐÐÇå¾²¶³½á¡£Í¬Ê± £¬ËùÓÐÈËӦ˼Á¿Ïò¾¯·½±¨°¸ £¬²¢Í¨ÖªÒøÐкÍÐÅÓÿ¨¿¯ÐÐÉÌÐÅϢй¶ÇéÐΡ£¸ÃÑ§ÇøÓÚ11ÔÂ25ÈÕÊ״η¢Ã÷ÍøÂçÎó²î £¬ÏÖÔÚÒÑÔÚµÚÈý·½ÍøÂçÇ徲ר¼ÒµÄЭÖúÏÂÕö¿ªÊÓ²ì £¬²¢½«Æ¾Ö¤ÊÊÓÃÖ´·¨Í¨ÖªÊÜÓ°ÏìµÄСÎÒ˽¼Ò¡£


https://databreaches.net/2025/01/07/two-ransomware-groups-claimed-they-attacked-rutherford-county-schools-one-leaked-sensitive-records/


3. ÂÌÍå°ü×°¹¤¶Ó¹Ù·½ÁãÊÛµêÔâºÚ¿ÍÈëÇÖ £¬¿Í»§Ö§¸¶ÐÅÏ¢ÔâÇÔÈ¡


1ÔÂ7ÈÕ £¬ÂÌÍå°ü×°¹¤¶ÓÃÀʽ×ãÇò¶Ó½üÆÚÔâÓöÍøÂç¹¥»÷ £¬Ò»ÃûÍþвÐÐΪÕßÈëÇÖÁËÆä¹Ù·½ÔÚÏßÁãÊÛµêpackersproshop.com £¬²¢×¢ÈëÁË¿¨Æ¬µÁË¢¾ç±¾ £¬ÒÔÇÔÈ¡¿Í»§µÄСÎÒ˽¼ÒºÍÖ§¸¶ÐÅÏ¢¡£¸Ã¶ÓÔÚ10ÔÂ23ÈÕ·¢Ã÷ÈëÇÖºó £¬Á¬Ã¦½ûÓÃÁËËùÓнáÕ˺͸¶¿î¹¦Ð§ £¬²¢Ô¼ÇëÁËÍâ²¿ÍøÂçÇ徲ר¼Ò¾ÙÐÐÊӲ졣ÊÓ²ìÏÔʾ £¬¶ñÒâ´úÂë¿ÉÄÜÔÚ2024Äê9ÔÂÏÂÑ®ÖÁ10ÔÂÉÏѮʱ´úÇÔÊØÐÅÏ¢ £¬µ«Ê¹ÓÃÌØ¶¨Ö§¸¶·½·¨µÄÐÅϢδ±»×èµ²¡£¾­ÊÓ²ìÈ·ÈÏ £¬¶ñÒâ´úÂë¿ÉÄÜÔÊÐíµÚÈý·½Éó²é»ò»ñÈ¡ÔÚÖ¸¶¨ÈÕÆÚ¹æÄ£ÄÚʹÓÃÓÐÏÞ¸¶¿î·½·¨½áÕËʱÊäÈëµÄijЩ¿Í»§ÐÅÏ¢¡£´Ë´Îй¶ÊÂÎñÉæ¼°µÄСÎÒ˽¼ÒºÍÖ§¸¶Êý¾Ý°üÀ¨ÐÕÃû¡¢µØµã¡¢µç×ÓÓʼþµØµãÒÔ¼°ÐÅÓÿ¨ÏêÇéµÈ¡£°ü×°¹¤¶ÓÉÐδ͸¶ÊÜÓ°Ïì¿Í»§ÊýÄ¿ºÍÈëÇÖ·½·¨ £¬µ«ÎªÊÜÓ°ÏìÓû§ÌṩÈýÄêµÄÐÅÓÃ¼à¿ØºÍÉí·Ý͵ÇÔ»Ö¸´·þÎñ £¬²¢½¨ÒéËûÃÇ¼à¿ØÕË»§±¨±íÒÔ·Àڲƭ¡£´Ëǰ £¬¾É½ðɽ49È˶ÓÒ²ÔøÔâÓöÀàËÆ¹¥»÷ £¬Áè¼Ý20,000ÃûСÎÒ˽¼ÒÐÅÏ¢±»µÁ¡£


https://www.bleepingcomputer.com/news/security/green-bay-packers-online-store-hacked-to-steal-credit-cards/


4. PowerSchoolÔâÓöÍøÂçÇå¾²ÊÂÎñ £¬Ñ§ÉúÎ÷ϯÊý¾ÝÔâÇÔ


1ÔÂ7ÈÕ £¬½ÌÓýÈí¼þ¾ÞÍ·PowerSchoolÔâÓöÁËÒ»ÆðÍøÂçÇå¾²ÊÂÎñ £¬¹¥»÷ÕßʹÓÃÆäPowerSchool SISƽ̨ÇÔÈ¡Á˲¿·ÖÑ§ÇøÑ§ÉúºÍÎ÷ϯµÄСÎÒ˽¼ÒÐÅÏ¢¡£PowerSchoolÊÇÒ»¼ÒΪK-12ѧУºÍÑ§ÇøÌṩȫ·½Î»ÔÆÈí¼þ½â¾ö¼Æ»®µÄ¹«Ë¾ £¬Æä·þÎñ°üÀ¨ÕÐÉú¡¢Í¨Ñ¶¡¢³öÇڵȶà¸ö·½Ãæ¡£´Ë´Î¹¥»÷±¬·¢ÔÚ2024Äê12ÔÂ28ÈÕ £¬¹¥»÷Õßͨ¹ýPowerSchoolµÄ¿Í»§Ö§³Öƽ̨PowerSource £¬Ê¹ÓÃй¶µÄƾ֤»á¼û²¢µ¼³öÁ˰üÀ¨Ñ§ÉúºÍÎ÷ϯÊý¾ÝµÄCSVÎļþ¡£±»µÁÊý¾ÝÖ÷Òª°üÀ¨ÐÕÃû¡¢µØµãµÈÁªÏµ·½·¨ £¬²¿·ÖÑ§ÇøµÄÊý¾Ý»¹¿ÉÄܰüÀ¨Éç»áÇå¾²ºÅÂ롢СÎÒ˽¼ÒÉí·ÝÐÅÏ¢¡¢Ò½ÁÆÐÅÏ¢ºÍЧ¹û¡£PowerSchoolÇ¿µ÷ £¬¿Í»§Æ±Ö¤¡¢Æ¾Ö¤»òÂÛ̳Êý¾ÝδÔÚ´Ë´ÎÊÂÎñÖÐй¶ £¬ÇÒ²¢·ÇËùÓпͻ§¶¼ÊÜÓ°Ï졣ΪӦ¶Ô´ËÊ £¬PowerSchoolÓëµÚÈý·½ÍøÂçÇ徲ר¼ÒÏàÖú £¬ÂÖ»»ÁËËùÓÐPowerSourceÕÊ»§µÄÃÜÂë £¬²¢ÊµÑéÁ˸üÑÏ¿áµÄÃÜÂëÕ½ÂÔ¡£Í¬Ê± £¬PowerSchoolÈ·ÈÏÕâ²»ÊÇÀÕË÷Èí¼þ¹¥»÷ £¬µ«Ö§¸¶ÁËÊê½ðÒÔÈ·±£Êý¾Ý±»É¾³ý £¬²¢ÕýÔÚÒ»Á¬¼à¿Ø°µÍøÒÔÈ·¶¨Ãü¾ÝÊÇ·ñÒÑй¶¡£¹ØÓÚÊÜÓ°ÏìµÄÈË £¬PowerSchoolÌṩÁËÐÅÓÃ¼à¿ØºÍÉí·Ý±£»¤·þÎñ¡£Ö»¹ÜÔâÓöÈëÇÖ £¬PowerSchoolµÄÔËÓª²¢Î´Êܵ½Ó°Ïì £¬·þÎñÈÔÕÕ³£¾ÙÐС£


https://www.bleepingcomputer.com/news/security/powerschool-hack-exposes-student-teacher-data-from-k-12-districts/


5. PayPal»ã¿îÇëÇó¹¦Ð§ÔâÐÂÐÍÍøÂç´¹ÂÚÊÖÒÕʹÓÃ


1ÔÂ8ÈÕ £¬Ò»ÖÖÐÂÐÍÍøÂç´¹ÂÚÊÖÒÕʹÓÃPayPal»ã¿îÇëÇó¹¦Ð§¾ÙÐÐÕ©Æ­ £¬¸ÃÊÖÒÕͨ¹ý·¢ËÍ¿´ËÆÕæÊµµÄÕýµ±PayPal»ã¿îÇëÇóÀ´ÓÕÆ­ÊÕ¿îÈË¡£Õ©Æ­ÕßʹÓÃMicrosoft 365²âÊÔÓò½¨Éè·Ö·¢Áбí £¬²¢Í¨¹ýPayPalÏò¸ÃÁÐ±í·¢Ë͸¶¿îÇëÇó¡£ÓÉÓÚ΢ÈíµÄ·¢¼þÈËÖØÐ´¼Æ»®ºÍPayPalµÄÇå¾²¼ì²é £¬ÕâЩÇëÇóÔÚµç×ÓÓʼþ¡¢URLºÍ·¢¼þÈ˵صãÉ϶¼ÏÔµÃÕýµ±¡£Ò»µ©ÊÕ¼þÈ˵ã»÷Á´½Ó²¢µÇ¼PayPalÕË»§ £¬Õ©Æ­Õß¾ÍÄÜ»ñÈ¡ÕË»§»á¼ûȨÏÞ¡£Oasis SecurityÑо¿Ö÷¹ÜÖ¸³ö £¬ÕâÖÖʹÓù©Ó¦É̹¦Ð§×ª´ïÐÂÎŵķ½·¨Ê¹µÃÓÊÏäÌṩÉÌÄÑÒÔÇø·ÖÕæ¼ÙͨѶ £¬PayPal¿ÉÄܳÉΪΨһÄܹ»»º½â´ËÎÊÌâµÄʵÌ塣ΪÁË·ÀÓù´ËÀàÍþв £¬FortinetÇ¿µ÷ѵÁ·ÓÐËØµÄÈËÈâ·À»ðǽµÄÖ÷ÒªÐÔ £¬½¨Òé½ÌÓýÔ±¹¤×ÐϸÉó²éËùÓÐÒâÍ⸶¿îÇëÇó¡£±ðµÄ £¬Ê¹ÓÃÊý¾Ýɥʧ·À»¤¹æÔòºÍÏȽøµÄÈ˹¤ÖÇÄÜÊÖÒÕÀ´ÆÊÎöÓû§ÐÐΪҲÓÐÖúÓÚ·¢Ã÷ºÍ×èÖ¹ÕâÐ©ÍøÂç´¹ÂÚʵÑé¡£


https://www.infosecurity-magazine.com/news/scammers-exploit-microsoft365/


6. Öж«ÍË¿îÕ©Æ­£ºÍøÂç·¸·¨·Ö×ÓʹÓÃÔ¶³Ì»á¼û¹¤¾ßÇÔÊØÐÅÏ¢


1ÔÂ8ÈÕ £¬Öж«µØÇø½üÆÚ·ºÆðÁËÒ»ÖÖÖØ´óµÄÍøÂçÕ©Æ­ £¬Õ©Æ­Õßð³äÕþ¸®¹ÙÔ± £¬Í¨¹ýµç»°ÁªÏµÄÇÐ©ÔøÏòÕþ¸®·þÎñÃÅ»§ÍøÕ¾ÌύͶËßµÄСÎÒ˽¼Ò £¬ÒÔ×ÊÖúËûÃÇ»ñÈ¡²»Öª×ãµÄ¹ºÎïÍ˿թƭÕßÒªÇóÊܺ¦ÕßÏÂÔØÕýµ±µÄÔ¶³Ì»á¼ûÈí¼þÈçAnyDesk»òTeamViewer £¬²¢ÔÚÊܺ¦Õß²»ÖªÇéµÄÇéÐÎÏ»ñÈ¡Æä×°±¸µÄ»á¼ûȨÏÞ £¬´Ó¶øÇÔȡСÎÒ˽¼ÒºÍ²ÆÎñÐÅÏ¢ £¬°üÀ¨ÐÅÓÿ¨ÏêϸÐÅÏ¢ºÍÒ»´ÎÐÔÃÜÂ루OTP£©¡£¾ÝÔ¤¼Æ £¬Ã¿±ÊÉúÒâµÄƽ¾ùËðʧԼΪ1,300ÃÀÔª £¬ÓÐЩÊܺ¦ÕßÉõÖÁËðʧ¸ß´ï5,000ÃÀÔª¡£¸ÃȦÌ×µÄÓÐÓÃÐÔÅú×¢¿ÉÄÜÓÐÄÚ²¿Ö°Ô±¼ÓÈë £¬ÓÉÓÚÕ©Æ­ÕßËÆºõÄܹ»»á¼ûÕþ¸®Í¶ËßÊý¾Ý¡£ÎªÌá·À´ËÀàÕ©Æ­ £¬Ð¡ÎÒ˽¼ÒÓ¦ÉóÉ÷¿´´ýÕþ¸®¹ÙÔ±µÄδ¾­ÇëÇóµÄµç»° £¬×èÖ¹ÏÂÔØÔ¶³Ì»á¼ûÈí¼þ»ò·ÖÏíÃô¸ÐÐÅÏ¢¡£Í¬Ê± £¬Õþ¸®ºÍ½ðÈÚ»ú¹¹Ò²Ó¦ÔöÇ¿Çå¾²²½·¥ £¬½ÌÓý¹«ÖÚÏàʶÉç»á¹¤³ÌΣº¦¡£AnyDeskºÍTeamViewerµÈ¹¤¾ßËäÔ­±¾ÓÃÓÚÕýµ±Ô®Öú £¬µ«ÂäÈëÕ©Æ­ÕßÊÖÖкó³ÉÎªÖØ´óÍþв £¬Òò´ËÐèÌá¸ßСÐÄ¡£


https://hackread.com/scammers-impersonate-swipe-otps-remote-access-apps/