Å·ÖÞÍøÂçÇå¾²¾ÖENISAÐû²¼2021ÄêÍþÐ²Ì¬ÊÆÆÊÎö±¨¸æ

Ðû²¼Ê±¼ä 2021-11-04

Ñо¿ÍŶӷ¢Ã÷ÏÕЩÍþвËùÓдúÂëµÄÎó²îTrojan Source


Ñо¿ÍŶӷ¢Ã÷ÏÕЩÍþвËùÓдúÂëµÄÎó²îTrojan Source.png


½£ÇÅ´óѧµÄÑо¿Ö°Ô±ÔÚ11ÔÂ1ÈÕ¹ûÕæÁËÒ»¸öÓ°Ïì´ó´ó¶¼ÅÌËã»ú´úÂë±àÒëÆ÷ºÍÐí¶àÈí¼þ¿ª·¢ÇéÐεÄÎó²îTrojan Source¡£¡£¡£¸ÃÎó²î±£´æÓÚUnicodeÖУ¬£¬£¬ÓÐÁ½ÖÖʹÓÃÒªÁ죺ÆäÒ»ÊÇʹÓÃUnicodeµÄBidiËã·¨£¨CVE-2021-42574£©£¬£¬£¬¶Ô×Ö·û¾ÙÐÐÊÓ¾õÉϵÄÖØÐÂÅÅÐò£¬£¬£¬Ê¹Æä·ºÆðÓë±àÒëÆ÷Ï¢ÕùÊÍÆ÷Ëù²î±ðµÄÂß¼­Ë³Ðò£»£»£»£»£»£»ÁíÒ»ÖÖÊÇͬÐÎÎÄ×Ö¹¥»÷(CVE-2021-42694)£¬£¬£¬¼´Ê¹ÓÃÔÚÊÓ¾õÉÏ¿´ÆðÀ´ÏàËÆµÄ²î±ð×Ö·û¡£¡£¡£¸ÃÎó²îÊÊÓÃÓÚC¡¢C++¡¢C#¡¢JavaScript¡¢JavaµÈÆÕ±éʹÓõÄÓïÑÔ£¬£¬£¬¿ÉÓÃÓÚ¹©Ó¦Á´¹¥»÷¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.trojansource.codes/



Ö鱦ÉÌGraffÔâµ½ContiÀÕË÷¹¥»÷£¬£¬£¬ÌØÀÊÆÕµÈÈËÐÅϢй¶


Ö鱦ÉÌGraffÔâµ½ContiÀÕË÷¹¥»÷£¬£¬£¬ÌØÀÊÆÕµÈÈËÐÅϢй¶.png


10ÔÂ31ÈÕ£¬£¬£¬ÖðÈÕÓʱ¨±¨µÀÀÕË÷ÍÅ»ïConti¹¥»÷ÁËÖ鱦ÉÌGraff²¢ÇÔÈ¡´ó×ÚÊý¾Ý¡£¡£¡£ÏÖÔÚ£¬£¬£¬¹¥»÷ÕßÒÑÔÚ°µÍøÉϹûÕæÁËÉæ¼°ÌÆÄɵ¡¤ÌØÀÊÆÕ¡¢°ÂÆÕÀ­¡¤Î¸¥ÈðºÍ´óÎÀ¡¤±´¿ËººÄ·µÄ69000·ÝÉñÃØÎļþ£¬£¬£¬×÷ΪÑù±¾Êý¾Ý¡£¡£¡£²¢Éù³ÆÏÖÔÚ¹ûÕæµÄÐÅÏ¢Éæ¼°Á˸ù«Ë¾Ô¼11000¸ö¿Í»§£¬£¬£¬½öÕ¼ÆäÇÔÈ¡µÄËùÓÐÊý¾ÝµÄ1%¡£¡£¡£ContiµÄÊê½ðºÜÊǸߣ¬£¬£¬Ô¼Õ¼Êܺ¦ÕßÄêÊÕÈëµÄ10%£¬£¬£¬¶øGraffÔÚ2019ÄêµÄÊÕÈëΪ4.5ÒÚÓ¢°÷¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/123980/cyber-crime/conti-ransomware-graff-jeweller.html



ÃÀ¹úÒ½ÁƱ£½¡Ð§À͹«Ë¾PHMÈ·ÈÏÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷


ÃÀ¹úÒ½ÁƱ£½¡Ð§À͹«Ë¾PHMÈ·ÈÏÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷.png


ÃÀ¹úÒ½ÁƱ£½¡Ð§À͹«Ë¾Professional Healthcare Management(PHM)ÔÚ10ÔÂ31ÈÕÈ·ÈÏÆäÔâµ½ÁËÀÕË÷¹¥»÷¡£¡£¡£¹¥»÷±¬·¢ÔÚ9ÔÂ14ÈÕ£¬£¬£¬Ð¹Â¶Á˿ͻ§µÄÐÕÃû¡¢Éç»áÇå¾²ºÅÂë¡¢¿µ½¡°ü¹ÜÐÅÏ¢¡¢´¦·½Ãû³ÆºÍÕï¶Ï´úÂëµÈÐÅÏ¢¡£¡£¡£PHM³Æ·¢Ã÷¹¥»÷ºóÁ¬Ã¦½ÓÄɲ½·¥±£»£»£»£»£»£»¤Æäϵͳ²¢»Ö¸´ÔËÓª£¬£¬£¬ÏÖÔÚÕýÔÚ֪ͨÄÇЩ¿ÉÄÜÊÜ´ËÓ°ÏìµÄ¿Í»§£¬£¬£¬²¢½«ÎªÆäÌṩÃâ·ÑµÄÉí·Ý¼à¿ØºÍ±£»£»£»£»£»£»¤Ð§ÀÍ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/tn-professional-healthcare-management-discloses-ransomware-incident/



Kaspersky·¢Ã÷ʹÓÃÆäAmazon SESÁîÅÆµÄ´¹Âڻ


Kaspersky·¢Ã÷ʹÓÃÆäAmazon SESÁîÅÆµÄ´¹Âڻ.png


Çå¾²¹«Ë¾KasperskyÔÚ±¾ÖÜÒ»Ðû²¼ÁËÒ»·Ýͨ¸æ£¬£¬£¬³ÆÓд¹ÂڻʹÓÃÆäAmazon SESÁîÅÆ¡£¡£¡£´Ë´Î»î¶¯Ê¹ÓÃÁËKasperskyµÄnoreply@sm.kaspersky.comµÈÕýÍâµØµã£¬£¬£¬²¢Ê¹ÓÃÁË´¹ÂÚ¹¤¾ß°üMIRCBOOT£¬£¬£¬Ö¼ÔÚÇÔȡĿµÄµÄOffice 365ƾ֤¡£¡£¡£Ñо¿Ö°Ô±È·¶¨£¬£¬£¬²¿·ÖÓʼþÊÇʹÓÃÕýµ±µÄÑÇÂíÑ·SESÁîÅÆ·¢Ë͵Ä£¬£¬£¬´Ë»á¼ûÁîÅÆÊÇÔÚ²âÊÔ2050.earthÍøÕ¾µÄʱ´ú½ÒÏþ¸øµÚÈý·½³Ð°üÉ̵Ä£¬£¬£¬¸ÃÍøÕ¾ÏÖÔÚÒ²ÍйÜÔÚÑÇÂíÑ·ÉÏ£¬£¬£¬·¢Ã÷¹¥»÷»î¶¯ºóÁ¬Ã¦×÷·ÏÁË´ËSESÁîÅÆ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/office-365-phishing-campaign-kasperskys-amazon-ses-token/175915/



Cisco TalosÐû²¼2021ÄêQ3Ó¦¼±ÏìÓ¦ÊÂÎñµÄÆÊÎö±¨¸æ


Cisco TalosÐû²¼2021ÄêQ3Ó¦¼±ÏìÓ¦ÊÂÎñµÄÆÊÎö±¨¸æ.png


Cisco TalosÔÚ10ÔÂ28ÈÕÐû²¼ÁË2021ÄêQ3Ó¦¼±ÏìÓ¦ÊÂÎñµÄÆÊÎö±¨¸æ¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬ÔÚ2021Äê7ÔÂÖÁ10ÔÂʱ´ú£¬£¬£¬ÀÕË÷Èí¼þÒÀÈ»ÊDZ¾¼¾¶È×îÖ÷ÒªµÄÍþв£¬£¬£¬Ô¼Õ¼ËùÓÐÍþвµÄ38%£¬£¬£¬»¹·ºÆðÁËÐí¶àеÄÀÕË÷Èí¼þ¼Ò×åVice Society¡¢Hive¡¢Karma¡¢Grief¡¢CryptBDºÍThanos¡£¡£¡£µç×ÓÓʼþÊÇ×î³£¼ûµÄ³õʼѬȾǰÑÔ£¬£¬£¬¶øÈ±·¦¶àÒòËØÉí·ÝÑéÖ¤(MFA)³ÉΪÆóÒµÇå¾²µÄ×î´óÕϰ­Ö®Ò»¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2021/10/quarterly-report-incident-response.html



Å·ÖÞÍøÂçÇå¾²¾ÖENISAÐû²¼2021ÄêÍþÐ²Ì¬ÊÆÆÊÎö±¨¸æ


Å·ÖÞÍøÂçÇå¾²¾ÖENISAÐû²¼2021ÄêÍþÐ²Ì¬ÊÆÆÊÎö±¨¸æ.png


Å·ÖÞÍøÂçÇå¾²¾ÖENISAÔÚ10ÔÂ27ÈÕÐû²¼ÁË2021ÄêÍþÐ²Ì¬ÊÆÆÊÎö±¨¸æ¡£¡£¡£±¨¸æÈ·¶¨ÁËÖ÷ÒªÍþв¡¢¹¥»÷ÊÖÒÕ¡¢ÖµµÃ×¢ÖØµÄÊÂÎñºÍÏà¹ØÇ÷ÊÆ£¬£¬£¬»¹ÌṩÁ˽µµÍΣº¦µÄ½¨Òé¡£¡£¡£±¾±¨¸æÖ÷ÒªÌÖÂÛÁË9ÖÖÍøÂçÇå¾²ÍþвÖÖ±ð£ºÀÕË÷Èí¼þ¡¢¶ñÒâÈí¼þ¡¢¼ÓÃÜÐ®ÖÆ¡¢µç×ÓÓʼþÏà¹ØÍþв¡¢¶ÔÊý¾ÝµÄÍþв¡¢¶Ô¿ÉÓÃÐÔºÍÍêÕûÐÔµÄÍþв¡¢ÐéαÐÅÏ¢£¨¹ýʧÐÅÏ¢£©¡¢·Ç¶ñÒâÍþв¡¢ºÍ¹©Ó¦Á´¹¥»÷¡£¡£¡£±ðµÄ£¬£¬£¬±¨¸æÖ¸³ö£¬£¬£¬ÀÕË÷Èí¼þ¹¥»÷ÒѳÉΪÖ÷ÒªÍþв¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.enisa.europa.eu/publications/enisa-threat-landscape-2021