MetaÒòFacebookÊý¾Ýй¶±»°®¶ûÀ¼DPC·£¿î2.65ÒÚÅ·Ôª
Ðû²¼Ê±¼ä 2022-11-29¾ÝýÌå11ÔÂ28ÈÕ±¨µÀ£¬Meta±»°®¶ûÀ¼Êý¾Ý±£»¤Î¯Ô±»á(DPC)·£¿î2.65ÒÚÅ·Ôª£¨2.755 ÒÚÃÀÔª£©¡£Ôµ¹ÊÔÓÉÊÇ2021ÄêFacebook´ó¹æÄ£Êý¾Ýй¶ÊÂÎñ£¬Éæ¼°È«ÇòÊýÒÚÓû§µÄÐÅÏ¢¡£ÔÚºÚ¿ÍÐû²¼5.33ÒÚFacebookÓû§µÄÊý¾Ýºó£¬DPCÓÚ2021Äê4ÔÂ14ÈÕÆô¶¯Á˶ÔMetaÎ¥·´GDPRµÄÊӲ졣DPCµÄÊÓ²ìµÃ³ö½áÂÛ£¬MetaÎ¥·´ÁËGDPRµÄµÚ25(1)ºÍ25(2)Ìõ¡£
https://www.bleepingcomputer.com/news/security/meta-fined-265m-for-not-protecting-facebook-users-data-from-scrapers/
2¡¢ÒÁÀÊ·¨¶û˹ͨѶÉçµÄÍøÕ¾Ôâµ½¹¥»÷250 TBÊý¾Ý±»É¾³ý
¾Ý11ÔÂ27ÈÕ±¨µÀ£¬ÒÁÀÊ·¨¶û˹ͨѶÉçµÄÍøÕ¾Ôâµ½ºÚ¿Í¹¥»÷¡£ÃûΪBlack RewardµÄºÚ¿ÍÍÅ»ïÉù³Æ¶Ô´Ë´Î¹¥»÷ÈÏÕæ£¬²¢ÌåÏÖÒÑ´Ó¸ÃÍøÕ¾µÄ·þÎñÆ÷ºÍÅÌËã»úÖÐɾ³ýÁ˽ü250 TBµÄÊý¾Ý£¬»¹³ÆÇÔÈ¡Á˸ÃͨѶÉç·¢Ë͸ø¹þ÷ÄÚÒÁ°ì¹«ÊÒµÄÉñÃØÍ¨¸æºÍָʾ¡£È»¶ø£¬·¨¶û˹ͨѶÉç·ñ¶¨Á˺ڿÍËùÐÎòµÄ¹¥»÷ˮƽ£¬³ÆºÚ¿ÍÖ»ÄÜÓ°ÏìÖÜÎåµÄÐÅÏ¢ºÍÐÂÎÅ£¬²¢ÖØÉêÐÂÎÅ»ú¹¹µÄÆäËûÐÅÏ¢ºÍÊý¾Ý¿âûÓб»ÆÆËð¡£
https://www.hackread.com/fars-news-agency-website-iran-hacked/
3¡¢Ragnar Locker¹ûÕæ±ÈÀûʱZwijndrecht¾¯Ô±¾ÖµÄÊý¾Ý
ýÌå11ÔÂ26Èճƣ¬Ragnar Locker¹ûÕæÁËËûÃÇÒÔΪÊÇ´ÓZwijndrechtÊÐÕþÕþ¸®ÇÔÈ¡µÄÊý¾Ý£¬µ«Ð§¹û֤ʵÕâЩÊý¾ÝÊÇ´ÓZwijndrecht¾¯Ô±¾ÖÇÔÈ¡µÄ¡£¾ÝϤ£¬Ð¹Â¶Êý¾Ý°üÀ¨´ó×Ú³µÅÆ¡¢·£¿î¡¢·¸·¨±¨¸æÎļþ¡¢Ö°Ô±ÏêϸÐÅÏ¢ºÍÊӲ챨¸æµÈ¡£´ËÀàÊý¾Ý¿ÉÄÜ»á̻¶¾Ù±¨·¸·¨ÐÐΪµÄÈË£¬²¢Î£¼°ÕýÔÚ¾ÙÐеÄÖ´·¨Ðж¯ºÍÊӲ졣±ÈÀûʱýÌ峯Õâ´ÎÊý¾Ýй¶ÊÇ´ËÀàÊÂÎñÖÐÓ°Ïì¸Ã¹ú¹«¹²·þÎñµÄ×îÑÏÖØÊÂÎñÖ®Ò»£¬Ð¹Â¶ÁËZwijndrecht¾¯·½´Ó2006Äêµ½2022Äê9ÔÂÉúÑĵÄËùÓÐÊý¾Ý¡£
https://www.bleepingcomputer.com/news/security/ransomware-gang-targets-belgian-municipality-hits-police-instead/
4¡¢Õë¶ÔÎÚ¿ËÀ¼µÄÐÂÀÕË÷Èí¼þRansomBoggsÓëSandwormÓйØ
11ÔÂ25ÈÕ±¨µÀ³Æ£¬Õë¶ÔÎÚ¿ËÀ¼×éÖ¯µÄÐÂÐÍÀÕË÷Èí¼þRansomBoggsÓëºÚ¿ÍÍÅ»ïSandwormÓйء£RansomBoggsÓÚ½ñÄê11ÔÂ21ÈÕÊ״α»ESET¼ì²âµ½£¬¸Ã¹«Ë¾Ö¸³ö£¬ËäÈ»ÓÃ.NET±àдµÄ¶ñÒâÈí¼þÊÇÐµģ¬µ«ËüµÄ·Ö·¢ÀàËÆÓÚ֮ǰ¹éÒòÓÚSandwormµÄ¹¥»÷Ô˶¯¡£ÆäÓÃÓÚ´ÓÓò¿ØÖÆÆ÷·Ö·¢.NETÀÕË÷Èí¼þµÄPowerShell¾ç±¾ÏÕЩÓëÈ¥Äê4ÔÂÔÚIndustroyer2¹¥»÷ÄÜÔ´×é֯ʱ´úµÄ½ÅÄÚÇéͬ¡£Ò»µ©½øÈëÄ¿µÄÍøÂ磬RansomBoggs»áÌìÉúÒ»¸öËæÉñÃØÔ¿£¬ÔÚCBCģʽÏÂʹÓÃAES-256¼ÓÃÜÎļþ£¬²¢¸½¼Ó.chschÀ©Õ¹Ãû¡£
https://thehackernews.com/2022/11/russia-based-ransomboggs-ransomware.html
5¡¢Ñо¿ÍŶӷ¢Ã÷CrysisµÄ±äÖÖWikiÔÚº«¹ú·Ö·¢µÄÔ˶¯
AhnLabÓÚ11ÔÂ25ÈÕÅû¶ÁËÀÕË÷Èí¼þWikiÔÚº«¹ú·Ö·¢µÄÔ˶¯¡£¸ÃÀÕË÷Èí¼þÒѱ»È·¶¨ÎªCrysisµÄ±äÖÖ£¬Î±×°³ÉÕý³£³ÌÐò¡£ÔÚÖ´ÐÐÏÖʵ¼ÓÃÜ֮ǰ£¬Wiki½«×Ô¼º¸´ÖƵ½%AppData%»ò%windir%\system32·¾¶£¬²¢Ìí¼Óµ½×¢²á±íÖÐ×¢²áΪÆô¶¯³ÌÐòÖ®Ò»¡£±ðµÄ£¬Ëü»¹»á½âÂëÒªÔÚÄÚ´æÖÐÖÕÖ¹µÄÓëÊý¾Ý¿âÏà¹ØµÄ·þÎñºÍÀú³ÌÃû³Æ£¬²¢²éÕÒÄ¿½ñÕýÔÚÔËÐеķþÎñºÍÀú³Ì²¢ÖÕÖ¹ËüÃÇ¡£ÓÉÓÚCrysisÀàÐ͵ÄÀÕË÷Èí¼þͨ³£Í¨¹ýRDP·Ö·¢£¬Ñо¿Ö°Ô±½¨Òé×¢ÖØRDPÅþÁ¬ÇéÐΡ£
https://asec.ahnlab.com/en/42507/
6¡¢FortiGuardÐû²¼¹ØÓÚÀÕË÷Èí¼þCryptonitµÄÆÊÎö±¨¸æ
11ÔÂ23ÈÕ£¬FortiGuardÐû²¼Á˹ØÓÚÀÕË÷Èí¼þCryptonitµÄÆÊÎö±¨¸æ¡£CryptoniteÊÇÒ»¸öÒÔFOSSÐÎʽ±£´æµÄÀÕË÷Èí¼þ¹¤¾ß°ü£¬ÓÉPython¿ª·¢£¬Ê¹ÓÃPyInstaller¾ÙÐдò°ü¡£CryptoniteÓÃÓÚ¼ÓÃÜÎļþµÄÒªÁìÊÇͨ¹ýPython¼ÓÃÜÄ£¿é£¬ËüʹÓÃFernetµÄʵÏÖÀ´ÌṩÕë¶ÔÕû¸öÄ¿µÄÎļþµÄ128λAES£¬¼ÓÃÜÎļþµÄÀ©Õ¹ÃûĬÈϸü¸ÄΪ.cryptn8¡£Ò»µ©ËùÓÐÎļþ¶¼±»¼ÓÃÜ£¬Cryptonite¾Í»áʵÑéʹÓÃipinfo.io´ÓÄ¿µÄµÄIPµØµãʶ±ðÆäλÖ㬲¢ËûµÄ¸ø¼ÒÀï´òµç»°¡£
https://www.fortinet.com/blog/threat-research/Ransomware-Roundup-Cryptonite-Ransomware


¾©¹«Íø°²±¸11010802024551ºÅ