Å·ÖÞÍøÂçÇå¾²¾ÖENISAÐû²¼2021ÄêÍþÐ²Ì¬ÊÆÆÊÎö±¨¸æ

Ðû²¼Ê±¼ä 2021-11-04

Ñо¿ÍŶӷ¢Ã÷ÏÕЩÍþвËùÓдúÂëµÄÎó²îTrojan Source


Ñо¿ÍŶӷ¢Ã÷ÏÕЩÍþвËùÓдúÂëµÄÎó²îTrojan Source.png


½£ÇÅ´óѧµÄÑо¿Ö°Ô±ÔÚ11ÔÂ1ÈÕ¹ûÕæÁËÒ»¸öÓ°Ïì´ó´ó¶¼ÅÌËã»ú´úÂë±àÒëÆ÷ºÍÐí¶àÈí¼þ¿ª·¢ÇéÐεÄÎó²îTrojan Source¡£¡£¡£¡£¡£¸ÃÎó²î±£´æÓÚUnicodeÖУ¬£¬£¬£¬£¬ÓÐÁ½ÖÖʹÓÃÒªÁ죺ÆäÒ»ÊÇʹÓÃUnicodeµÄBidiËã·¨£¨CVE-2021-42574£©£¬£¬£¬£¬£¬¶Ô×Ö·û¾ÙÐÐÊÓ¾õÉϵÄÖØÐÂÅÅÐò£¬£¬£¬£¬£¬Ê¹Æä·ºÆðÓë±àÒëÆ÷Ï¢ÕùÊÍÆ÷Ëù²î±ðµÄÂß¼­Ë³Ðò£»£»£» £»£»ÁíÒ»ÖÖÊÇͬÐÎÎÄ×Ö¹¥»÷(CVE-2021-42694)£¬£¬£¬£¬£¬¼´Ê¹ÓÃÔÚÊÓ¾õÉÏ¿´ÆðÀ´ÏàËÆµÄ²î±ð×Ö·û¡£¡£¡£¡£¡£¸ÃÎó²îÊÊÓÃÓÚC¡¢C++¡¢C#¡¢JavaScript¡¢JavaµÈÆÕ±éʹÓõÄÓïÑÔ£¬£¬£¬£¬£¬¿ÉÓÃÓÚ¹©Ó¦Á´¹¥»÷¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.trojansource.codes/



Ö鱦ÉÌGraffÔâµ½ContiÀÕË÷¹¥»÷£¬£¬£¬£¬£¬ÌØÀÊÆÕµÈÈËÐÅϢй¶


Ö鱦ÉÌGraffÔâµ½ContiÀÕË÷¹¥»÷£¬£¬£¬£¬£¬ÌØÀÊÆÕµÈÈËÐÅϢй¶.png


10ÔÂ31ÈÕ£¬£¬£¬£¬£¬ÖðÈÕÓʱ¨±¨µÀÀÕË÷ÍÅ»ïConti¹¥»÷ÁËÖ鱦ÉÌGraff²¢ÇÔÈ¡´ó×ÚÊý¾Ý¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬¹¥»÷ÕßÒÑÔÚ°µÍøÉϹûÕæÁËÉæ¼°ÌÆÄɵ¡¤ÌØÀÊÆÕ¡¢°ÂÆÕÀ­¡¤Î¸¥ÈðºÍ´óÎÀ¡¤±´¿ËººÄ·µÄ69000·ÝÉñÃØÎļþ£¬£¬£¬£¬£¬×÷ΪÑù±¾Êý¾Ý¡£¡£¡£¡£¡£²¢Éù³ÆÏÖÔÚ¹ûÕæµÄÐÅÏ¢Éæ¼°Á˸ù«Ë¾Ô¼11000¸ö¿Í»§£¬£¬£¬£¬£¬½öÕ¼ÆäÇÔÈ¡µÄËùÓÐÊý¾ÝµÄ1%¡£¡£¡£¡£¡£ContiµÄÊê½ðºÜÊǸߣ¬£¬£¬£¬£¬Ô¼Õ¼Êܺ¦ÕßÄêÊÕÈëµÄ10%£¬£¬£¬£¬£¬¶øGraffÔÚ2019ÄêµÄÊÕÈëΪ4.5ÒÚÓ¢°÷¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/123980/cyber-crime/conti-ransomware-graff-jeweller.html



ÃÀ¹úÒ½ÁƱ£½¡Ð§À͹«Ë¾PHMÈ·ÈÏÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷


ÃÀ¹úÒ½ÁƱ£½¡Ð§À͹«Ë¾PHMÈ·ÈÏÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷.png


ÃÀ¹úÒ½ÁƱ£½¡Ð§À͹«Ë¾Professional Healthcare Management(PHM)ÔÚ10ÔÂ31ÈÕÈ·ÈÏÆäÔâµ½ÁËÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¹¥»÷±¬·¢ÔÚ9ÔÂ14ÈÕ£¬£¬£¬£¬£¬Ð¹Â¶Á˿ͻ§µÄÐÕÃû¡¢Éç»áÇå¾²ºÅÂë¡¢¿µ½¡°ü¹ÜÐÅÏ¢¡¢´¦·½Ãû³ÆºÍÕï¶Ï´úÂëµÈÐÅÏ¢¡£¡£¡£¡£¡£PHM³Æ·¢Ã÷¹¥»÷ºóÁ¬Ã¦½ÓÄɲ½·¥±£»£»£» £»£»¤Æäϵͳ²¢»Ö¸´ÔËÓª£¬£¬£¬£¬£¬ÏÖÔÚÕýÔÚ֪ͨÄÇЩ¿ÉÄÜÊÜ´ËÓ°ÏìµÄ¿Í»§£¬£¬£¬£¬£¬²¢½«ÎªÆäÌṩÃâ·ÑµÄÉí·Ý¼à¿ØºÍ±£»£»£» £»£»¤Ð§ÀÍ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/tn-professional-healthcare-management-discloses-ransomware-incident/



Kaspersky·¢Ã÷ʹÓÃÆäAmazon SESÁîÅÆµÄ´¹Âڻ


Kaspersky·¢Ã÷ʹÓÃÆäAmazon SESÁîÅÆµÄ´¹Âڻ.png


Çå¾²¹«Ë¾KasperskyÔÚ±¾ÖÜÒ»Ðû²¼ÁËÒ»·Ýͨ¸æ£¬£¬£¬£¬£¬³ÆÓд¹ÂڻʹÓÃÆäAmazon SESÁîÅÆ¡£¡£¡£¡£¡£´Ë´Î»î¶¯Ê¹ÓÃÁËKasperskyµÄnoreply@sm.kaspersky.comµÈÕýÍâµØµã£¬£¬£¬£¬£¬²¢Ê¹ÓÃÁË´¹ÂÚ¹¤¾ß°üMIRCBOOT£¬£¬£¬£¬£¬Ö¼ÔÚÇÔȡĿµÄµÄOffice 365ƾ֤¡£¡£¡£¡£¡£Ñо¿Ö°Ô±È·¶¨£¬£¬£¬£¬£¬²¿·ÖÓʼþÊÇʹÓÃÕýµ±µÄÑÇÂíÑ·SESÁîÅÆ·¢Ë͵쬣¬£¬£¬£¬´Ë»á¼ûÁîÅÆÊÇÔÚ²âÊÔ2050.earthÍøÕ¾µÄʱ´ú½ÒÏþ¸øµÚÈý·½³Ð°üÉ̵쬣¬£¬£¬£¬¸ÃÍøÕ¾ÏÖÔÚÒ²ÍйÜÔÚÑÇÂíÑ·ÉÏ£¬£¬£¬£¬£¬·¢Ã÷¹¥»÷»î¶¯ºóÁ¬Ã¦×÷·ÏÁË´ËSESÁîÅÆ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/office-365-phishing-campaign-kasperskys-amazon-ses-token/175915/



Cisco TalosÐû²¼2021ÄêQ3Ó¦¼±ÏìÓ¦ÊÂÎñµÄÆÊÎö±¨¸æ


Cisco TalosÐû²¼2021ÄêQ3Ó¦¼±ÏìÓ¦ÊÂÎñµÄÆÊÎö±¨¸æ.png


Cisco TalosÔÚ10ÔÂ28ÈÕÐû²¼ÁË2021ÄêQ3Ó¦¼±ÏìÓ¦ÊÂÎñµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬ÔÚ2021Äê7ÔÂÖÁ10ÔÂʱ´ú£¬£¬£¬£¬£¬ÀÕË÷Èí¼þÒÀÈ»ÊDZ¾¼¾¶È×îÖ÷ÒªµÄÍþв£¬£¬£¬£¬£¬Ô¼Õ¼ËùÓÐÍþвµÄ38%£¬£¬£¬£¬£¬»¹·ºÆðÁËÐí¶àеÄÀÕË÷Èí¼þ¼Ò×åVice Society¡¢Hive¡¢Karma¡¢Grief¡¢CryptBDºÍThanos¡£¡£¡£¡£¡£µç×ÓÓʼþÊÇ×î³£¼ûµÄ³õʼѬȾǰÑÔ£¬£¬£¬£¬£¬¶øÈ±·¦¶àÒòËØÉí·ÝÑéÖ¤(MFA)³ÉΪÆóÒµÇå¾²µÄ×î´óÕϰ­Ö®Ò»¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2021/10/quarterly-report-incident-response.html



Å·ÖÞÍøÂçÇå¾²¾ÖENISAÐû²¼2021ÄêÍþÐ²Ì¬ÊÆÆÊÎö±¨¸æ


Å·ÖÞÍøÂçÇå¾²¾ÖENISAÐû²¼2021ÄêÍþÐ²Ì¬ÊÆÆÊÎö±¨¸æ.png


Å·ÖÞÍøÂçÇå¾²¾ÖENISAÔÚ10ÔÂ27ÈÕÐû²¼ÁË2021ÄêÍþÐ²Ì¬ÊÆÆÊÎö±¨¸æ¡£¡£¡£¡£¡£±¨¸æÈ·¶¨ÁËÖ÷ÒªÍþв¡¢¹¥»÷ÊÖÒÕ¡¢ÖµµÃ×¢ÖØµÄÊÂÎñºÍÏà¹ØÇ÷ÊÆ£¬£¬£¬£¬£¬»¹ÌṩÁ˽µµÍΣº¦µÄ½¨Òé¡£¡£¡£¡£¡£±¾±¨¸æÖ÷ÒªÌÖÂÛÁË9ÖÖÍøÂçÇå¾²ÍþвÖÖ±ð£ºÀÕË÷Èí¼þ¡¢¶ñÒâÈí¼þ¡¢¼ÓÃÜÐ®ÖÆ¡¢µç×ÓÓʼþÏà¹ØÍþв¡¢¶ÔÊý¾ÝµÄÍþв¡¢¶Ô¿ÉÓÃÐÔºÍÍêÕûÐÔµÄÍþв¡¢ÐéαÐÅÏ¢£¨¹ýʧÐÅÏ¢£©¡¢·Ç¶ñÒâÍþв¡¢ºÍ¹©Ó¦Á´¹¥»÷¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬±¨¸æÖ¸³ö£¬£¬£¬£¬£¬ÀÕË÷Èí¼þ¹¥»÷ÒѳÉΪÖ÷ÒªÍþв¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.enisa.europa.eu/publications/enisa-threat-landscape-2021