ºÚ¿ÍÈëÇÖÌØÀÊÆÕ¾ºÑ¡ÍøÕ¾²¢Èö²¥ÐéαÐÅÏ¢£»£» £»£»£»£»£»ACTI³Æ¶íºÚ¿Í×éÖ¯TurlaÈëÇÖÅ·ÖÞÒ»¸öÕþ¸®×éÖ¯

Ðû²¼Ê±¼ä 2020-10-29
1.ºÚ¿ÍÈëÇÖÌØÀÊÆÕ¾ºÑ¡ÍøÕ¾²¢Èö²¥ÐéαÐÅÏ¢


1.jpg


Õþ¸®¹ÙÔ±ÌåÏÖ £¬£¬£¬£¬ £¬£¬£¬£¬ºÚ¿ÍÔÚÑ¡¾ÙÈÕǰһÖܵÄÐÇÆÚ¶þÈëÇÖÁËÌÆÄɵ¡¤ÌØÀÊÆÕµÄ¾ºÑ¡ÍøÕ¾¡£¡£¡£ ¡£¡£¡£donaldjtrump.comÍøÕ¾±»¡°Õâ¸öÍøÕ¾±»²é·âÁË¡±ÐÂÎÅËùÈ¡´ú £¬£¬£¬£¬ £¬£¬£¬£¬²¢ÌåÏÖ¡°ÌìÏÂÒѾ­Êܹ»ÁËÌÆÄɵ¡¤J¡¤ÌØÀÊÆÕ×ÜͳÌìÌìÉ¢²¥µÄ¼ÙÐÂÎÅ¡±¡£¡£¡£ ¡£¡£¡£±ðµÄ £¬£¬£¬£¬ £¬£¬£¬£¬ºÚ¿Í»¹ºôÓõÍøÃñ¾èÔùMoneroÊý×ÖÇ®±ÒÒÔÖ§³Ö»ò×赲й¶ÓëÌØÀÊÆÕÓйصÄÖ¤¾Ý¡£¡£¡£ ¡£¡£¡£ÌØÀÊÆÕ¾ºÑ¡½²»°ÈËTim MurtaughÌåÏÖ £¬£¬£¬£¬ £¬£¬£¬£¬¸ÃÍøÕ¾ºÜ¿ì»ñµÃÐÞ¸´²¢Ã»ÓÐÈκÎÃô¸ÐÊý¾Ýй¶ £¬£¬£¬£¬ £¬£¬£¬£¬´Ë´Î¹¥»÷µÄȪԴ»¹ÔÚÊÓ²ìÖС£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/trump-campaign-website-broken-hackers


2.ACTI³Æ¶íºÚ¿Í×éÖ¯TurlaÈëÇÖÅ·ÖÞÒ»¸öÕþ¸®×éÖ¯


2.jpg


ƾ֤°£É­ÕÜÍøÂçÍþвÇ鱨£¨ACTI£©µÄ×îб¨¸æ £¬£¬£¬£¬ £¬£¬£¬£¬¶íÂÞ˹µÄºÚ¿Í×éÖ¯TurlaÈëÇÖÁËÒ»¸öδ¹ûÕæÃû³ÆµÄÅ·ÖÞÕþ¸®×éÖ¯µÄϵͳ¡£¡£¡£ ¡£¡£¡£ÎªÁËÈëÇÖ×éÖ¯ÍøÂç £¬£¬£¬£¬ £¬£¬£¬£¬¹¥»÷ÕßʹÓÃÁË×î½ü¸üеÄÔ¶³ÌÖÎÀíľÂí£¨RAT£©ºÍ»ùÓÚÔ¶³ÌÀú³ÌŲÓã¨RPC£©µÄºóÃųÌÐò £¬£¬£¬£¬ £¬£¬£¬£¬ÆäÖаüÀ¨HyperStack¡£¡£¡£ ¡£¡£¡£ACTIÌåÏÖ £¬£¬£¬£¬ £¬£¬£¬£¬Õâ´Î¹¥»÷ÍêÈ«ÇкÏTurla´ÓÊÂÌØ¹¤»î¶¯µÄÄîÍ· £¬£¬£¬£¬ £¬£¬£¬£¬ÏÖÔÚËüÒѾ­ÆÆËðÁËÀ´×Ô100¶à¸ö¹ú¼ÒµÄÕþ¸®¡¢´óʹ¹ÝÒÔ¼°½ÌÓýºÍÑо¿»ú¹¹µÄÊýǧ¸öϵͳ¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/russian-turla-hackers-breach-european-government-organization/


3.MicrosoftÐû²¼KB4577586¸üР£¬£¬£¬£¬ £¬£¬£¬£¬×èֹʹÓÃAdobe Flash


3.jpg


MicrosoftÐû²¼ÁËKB4577586¸üР£¬£¬£¬£¬ £¬£¬£¬£¬ÒÔ×èֹʹÓÃWindowsÉϵÄAdobe Flash¡£¡£¡£ ¡£¡£¡£´Ë´Î¸üнö¿Éͨ¹ýMicrosoft Catalog»ñµÃ¡£¡£¡£ ¡£¡£¡£MicrosoftÉùÃ÷¸Ã¸üн«×Ô¶¯É¾³ýAdobe Flash Player £¬£¬£¬£¬ £¬£¬£¬£¬µ«Éв»ÇåÎúÈ·ÇÐɾ³ýµÄÄÚÈÝ¡£¡£¡£ ¡£¡£¡£¾­ÓɲâÊÔ £¬£¬£¬£¬ £¬£¬£¬£¬´Ë¸üÐÂɾ³ýÁËWindows 10ÖÐÀ¦°óµÄFlash Player£¨32룩°æ±¾ £¬£¬£¬£¬ £¬£¬£¬£¬µ«²»»áɾ³ýÈκÎ×ÔÁ¦°æ±¾µÄAdobe Flash Player¡£¡£¡£ ¡£¡£¡£MicrosoftÔòÌåÏÖ»á2021ÄêÍ·Flashµ½ÆÚºó¶ÔFlash Player¾ÙÐдó¹æÄ£É¾³ý¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-update-to-remove-adobe-flash-from-windows/


4.Enel GroupÔÙ´ÎѬȾÀÕË÷Èí¼þ £¬£¬£¬£¬ £¬£¬£¬£¬Ð¹Â¶5TBµÄÊý¾Ý


4.jpg


¿ç¹úÄÜÔ´¹«Ë¾Enel Group½ñÄêÔâµ½µÚ¶þ´ÎÀÕË÷Èí¼þ¹¥»÷ £¬£¬£¬£¬ £¬£¬£¬£¬NetwalkerÉù³ÆÆäÇÔÈ¡ÁË5TBµÄÊý¾Ý²¢ÀÕË÷1400ÍòÃÀÔªÊê½ð¡£¡£¡£ ¡£¡£¡£EnelÊÇÅ·ÖÞÄÜÔ´ÁìÓò×î´óµÄ¹«Ë¾Ö®Ò» £¬£¬£¬£¬ £¬£¬£¬£¬ÔÚ40¸ö¹ú¼ÒºÍµØÇøÓµÓÐ6100Íò¿Í»§¡£¡£¡£ ¡£¡£¡£½ñÄê6Ô³õ £¬£¬£¬£¬ £¬£¬£¬£¬EnelµÄÄÚ²¿ÍøÂçÔâµ½SnakeÀÕË÷Èí¼þµÄ¹¥»÷ £¬£¬£¬£¬ £¬£¬£¬£¬10ÔÂ19ÈÕÓÖÔâµ½NetwalkerÀÕË÷Èí¼þµÄ¹¥»÷¡£¡£¡£ ¡£¡£¡£ÏÖÔÚ £¬£¬£¬£¬ £¬£¬£¬£¬NetwalkerÒÑÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾Ðû²¼Á˱»µÁÊý¾ÝµÄ½ØÍ¼ £¬£¬£¬£¬ £¬£¬£¬£¬²¢ÌåÏÖ»áÔÚÒ»ÖÜÄÚ¹ûÕæÆäÖеÄÒ»²¿·Ö¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/enel-group-hit-by-ransomware-again-netwalker-demands-14-million/


5.¼Ò¾ß¹«Ë¾SteelcaseѬȾRyukµ¼ÖÂϵͳÔÝʱ¹Ø±Õ


5.jpg


È«Çò×î´óµÄ°ì¹«¼Ò¾ßÖÆÔìÉÌSteelcase³ÆÆäÔÚ10ÔÂ22ÈÕÔâµ½RyukÀÕË÷Èí¼þ¹¥»÷ £¬£¬£¬£¬ £¬£¬£¬£¬²¢µ¼ÖÂϵͳÔÝʱ¹Ø±Õ¡£¡£¡£ ¡£¡£¡£¸Ã¹«Ë¾Ðû²¼ÉùÃ÷³ÆÆäÔÚÐÅÏ¢ÊÖÒÕϵͳÉÏ·¢Ã÷ÁËÍøÂç¹¥»÷ £¬£¬£¬£¬ £¬£¬£¬£¬²¢Ñ¸ËÙ½ÓÄÉÁËһϵÁÐ×èÖ¹²½·¥À´½â¾öÕâÖÖÇéÐÎ £¬£¬£¬£¬ £¬£¬£¬£¬°üÀ¨ÔÝʱ¹Ø±ÕÊÜÓ°ÏìµÄϵͳºÍÏà¹Ø²Ù×÷¡£¡£¡£ ¡£¡£¡£ÏÖÔÚ £¬£¬£¬£¬ £¬£¬£¬£¬¹«Ë¾Éв»ÖªµÀ´Ë¹¥»÷µ¼ÖµÄÏêϸϵͳÊý¾Ýɥʧ»ò×ʲúËðʧ £¬£¬£¬£¬ £¬£¬£¬£¬µ«¹«Ë¾Ô¤¼Æ¸ÃÊÂÎñ²»»á¶ÔÆäÓªÒµÔËÓª»ò²ÆÎñÒµ¼¨±¬·¢ÖØ´óÓ°Ïì¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/steelcase-furniture-giant-hit-by-ryuk-ransomware-attack/    


6.VeracodeÐû²¼Ó¦ÓóÌÐòÇå¾²Ì¬ÊÆµÄÆÊÎö±¨¸æ


6.jpg


VeracodeÐû²¼µÚ11ÆÚÈí¼þÇ徲״̬±¨¸æ £¬£¬£¬£¬ £¬£¬£¬£¬¶ÔÓ¦ÓóÌÐòÇå¾²Ì¬ÊÆ¾ÙÐÐÁËÆÊÎö¡£¡£¡£ ¡£¡£¡£±¨¸æ¶Ô130000¸öÓ¦ÓóÌÐò¾ÙÐÐÁËÆÊÎö £¬£¬£¬£¬ £¬£¬£¬£¬·¢Ã÷76£¥µÄÓ¦ÓÃÖÁÉÙ¾ßÓÐÒ»¸öÇå¾²Îó²î £¬£¬£¬£¬ £¬£¬£¬£¬µ«Ö»ÓÐ24£¥µÄÓ¦ÓþßÓиßÑÏÖØÐÔÎó²î¡£¡£¡£ ¡£¡£¡£±ðµÄ £¬£¬£¬£¬ £¬£¬£¬£¬¸Ã±¨¸æ»¹·¢Ã÷ÁËһЩ¿ÉÌá¸ßÎó²îÐÞ¸´ÂʵÄÒªÁì £¬£¬£¬£¬ £¬£¬£¬£¬ÈçÁ¬ÏµÊ¹ÓöàÖÖɨÃèÀàÐÍ£¨°üÀ¨¾²Ì¬ÆÊÎö£¨SAST£© £¬£¬£¬£¬ £¬£¬£¬£¬¶¯Ì¬ÆÊÎö£¨DAST£©ºÍÈí¼þ×éÉíÆÊÎö£¨SCA£©£© £¬£¬£¬£¬ £¬£¬£¬£¬Í³¼ÆÅú×¢ÄÇЩͬʱʹÓÃSASTºÍDASTµÄÈË¿ÉÒÔ24ÌìÄÚÐÞ¸´Ò»°ëµÄȱÏÝ¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.veracode.com/sites/default/files/pdf/sossv11/soss_infographic_v11.pdf