Ç÷Ïò¿Æ¼¼ATTK¹¤¾ß°ü´æÔÚËÁÒâ´úÂëÖ´Ðзì϶£»¶à¼ÒVPN¹©¸øÉÌÔâºÚ¿Í¹¥»÷£¬·þÎñÆ÷˽Կ±»µÁ

°ä²¼¹¦·ò 2019-10-23
1¡¢Ç÷Ïò¿Æ¼¼ATTK¹¤¾ß°ü´æÔÚËÁÒâ´úÂëÖ´Ðзì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

×êÑÐÈËÔ±·¢ÏÖÇ÷Ïò¿Æ¼¼·ÀÍþв¹¤¾ß°ü£¨ATTK£©´æÔÚÒ»¸öËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2019-9491£©£¬¹¥»÷Õß¿ÉÀûÓô˷ì϶ÔÚÖ¸±êWindowsϵͳÉÏÔËÐжñÒâÈí¼þ¡£Æ¾¾ÝÇ÷Ïò¿Æ¼¼°ä²¼µÄ°²È«²¼¸æ£¬ÈôÊǶñÒâÈí¼þ×÷Õß´ÕÇɽ«¶ñÒâÈí¼þ¶¨ÃûΪcmd.exe»òregedit.exe£¬ÄÇôATTK½«»á¼ÓÔØ²¢ÔËÐиÃexeÎļþ¡£ÓÉÓÚATTKÊÇÓɾ­¹ýÑéÖ¤µÄ¿¯Ðз½ÊðÃûµÄ£¬Òò¶ø¿ÉÈÆ¹ýÈκÎMOTW°²È«ÖҸ棬¹¥»÷ÕßÉõÖÁÄܹ»½«ATTK×÷ΪһÖÖÓÆ¾ÃÐÔ»úÔì¡£Ç÷Ïò¿Æ¼¼ÏÖÒѽ«ËùÓÐATTK ¸üÐÂÖÁ1.62.0.1223°æ±¾£¬µ«ÉÐδ°ä²¼¼¼Êõϸ½Ú¡£ 

   

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/92818/hacking/trend-micro-anti-threat-toolkit-flaw.html

2¡¢¶à¼ÒVPN¹©¸øÉÌÔâºÚ¿Í¹¥»÷£¬·þÎñÆ÷˽Կ±»µÁ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ô̺¬NordVPN¡¢TorGuard VPNºÍVikingVPNÔÚÄڵĶà¼ÒVPN¹©¸øÉÌÔâºÚ¿Í¹¥»÷£¬ÓÃÓÚ±£»¤ÆäWeb·þÎñÆ÷ºÍVPNÅäÖÃÎļþµÄÖ¤Êé¼°ÓйØË½Ô¿±»µÁ¡£¹¥»÷Õß¿ÉÄÜÀûÓøÃÖ¤Êé´´½¨´¹µöÕ¾µã»òÌáÒéÖÐÑëÈ˹¥»÷¡£³ýÁËVikingVPNÖ®±í£¬NordVPNºÍTorGuard¾ùÒѰ䲼ÉêÃ÷¡£NordVPNÈ·ÈÏй¶ÊÂÎñ²úÉúÔÚ2018Äê3Ô£¬Î´¾­ÊÚȨµÄ¹¥»÷Õß½Ó¼ûÁËÆä·ÒÀ¼Êý¾ÝÖÐÐIJ¢ÇÔÈ¡ÁËTLSÃÜÔ¿£¬ÓÉÓÚ¸ÃTLSÃÜÔ¿ÒѾ­¹ýÆÚ£¬Òò¶øÎÞ·¨½âÃÜÈκÎVPNÁ÷Á¿¡£TorGuardÔòÖ¸³öÓÉÓÚËûÃÇʹÓÃÁ˰²È«µÄPKIÖÎÀí²¢ÇÒCAÃÜԿûÓб»µÁ£¬Òò¶øÃ»ÓÐVPNÓû§Êܵ½Ó°Ïì¡£

  

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/92808/hacking/nordvpn-torguard-vikingvpn-hack.html

3¡¢µÂ¹úÔì×÷ÉÌPilzÔÚÔâµ½ÀÕË÷Èí¼þ¹¥»÷Ò»ÖܺóÈÔδ¸´Ô­

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

µÂ¹ú×Ô¶¯»¯¹¤¾ß³§ÉÌÆ¤¶û×È£¨Pilz£©ÔÚÔâ·êÀÕË÷Èí¼þBitPaymerϰȾºóÒѾ­å´»úÁ˳¬¹ýÒ»ÖܵŦ·ò¡£Æ¾¾Ý¸Ã¹«Ë¾µÄÍøÕ¾ÐÂÎÅ£¬×Ô2019Äê10ÔÂ13ÈÕÒÔÀ´£¬¸Ã¹«Ë¾ÔÚÈ«ÇòÁìÓòÄÚµÄËùÓзþÎñÆ÷ºÍPC¹¤×÷Õ¾£¬Ô̺¬Í¨Ñ¶ÉèÊ©£¬¶¼Êܵ½ÁËÓ°Ï졣ΪԤ·ÀÆð¼û£¬¸Ã¹«Ë¾´ÓÍøÂçÖÐɾ³ýÁËËùÓÐÍÆËã»úϵͳ²¢×èÖ¹Á˶Թ«Ë¾ÍøÂçµÄ½Ó¼û¡£PilzÔ±¹¤»¨ÁËÈýÌ칦·ò²Å¸´Ô­µç×ÓÓʼþ·þÎñµÄ½Ó¼û£¬ÓÖ»¨ÁËÈýÌì²Å¸´Ô­Æä¹ú¼Êµç×ÓÓʼþ·þÎñ£¬Ö±µ½21ÈղŸ´Ô­¶Ô²úÆ·¶©µ¥ºÍ½»»õϵͳµÄ½Ó¼û¡£¸Ã¹«Ë¾µÄ³ö²úÄÜÁ¦Ã»ÓÐÊܵ½Ó°Ïì¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/major-german-manufacturer-still-down-a-week-after-getting-hit-by-ransomware/

4¡¢Ó¢¹úHome GroupÔâºÚ¿Í¹¥»÷£¬½ü4000¿Í»§ÐÅϢй¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ó¢¹ú×î´óµÄס·¿Ð­»áÖ®Ò»Home GroupÒÑÏòÔ¼4000Ãû¿Í»§°ä²¼ÖҸ棬ÆäÓ×ÎÒÐÅÏ¢Ôڸù«Ë¾Ôâ·êÊý¾Ýй¶֮ºó¿ÉÄܱ»µÁ¡£Æ¾¾ÝBBCµÄ±¨Â·£¬ÊÜÓ°ÏìµÄÐÅÏ¢Ô̺¬¿Í»§µÄÐÕÃû¡¢µØÖ·ºÍÁªÏµÐÅÏ¢£¬µ«²»Ô̺¬²ÆÕþÊý¾Ý¡£¸Ã¹«Ë¾Ú¹ÊͳÆ£¬ÊÂÎñÊÇÓɵÚÈý·½°²È«×¨¼Ò·¢Ïֵģ¬Ó°ÏìÁËÓ¢¸ñÀ¼¶«±±¡¢Î÷±±¼°Ô¼¿Ë¿¤µÄ¿Í»§¡£Ä¿Ç°Éв»Ã÷ÏÔÊÂÎñ²úÉúµÄ¾ßÌåÔ­Òò£¬µ«Home Group½²»°È˳ƸÃÎÊÌâÔÚ90·ÖÖÓÄڵõ½½â¾ö¡£

Ô­ÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/home-group-data-breach/

5¡¢ÐÂÀ¬»øÓʼþ»î¶¯ÀûÓÃÀÕË÷Èí¼þBuran¶Ô×¼µÂ¹ú

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


×êÑÐÈËÔ±·¢ÏÖÒ»¸öÖØÒªÕë¶ÔµÂ¹úµÄÀ¬»øÓʼþ¶ñÒâ»î¶¯£¬¹¥»÷ÕßÖØÒª·Ö·¢ÀÕË÷Èí¼þBuran¡£10Ô³õ£¬Bromium¹Û²ìµ½¼ÙÒâÔÚÏß´«Õæ·þÎñeFaxµÄÀ¬»øÓʼþ»î¶¯£¬ÓʼþÖÐÔ̺¬Ö¸ÏòÌṩ¶ñÒâWordÎĵµµÄPHPÒ³Ãæ³¬Á´½Ó£¬ÕâÄܹ»ÌÓ±ÜÓʼþ°²È«Íø¹ØµÄ¼ì²â¡£ÕâЩWordÎĵµ»áͨ¹ýVBAºêÏÂÔØ²¢Ö´ÐÐBuran¡£¸ÃÀÕË÷Èí¼þ»¹»áÏòhxxp://geoiptool[.]com·¢ËÍHTTP GetÒªÇóÀ´¶ÔÊܺ¦ÕßµÄϵͳ½øÐеØÀí¶¨Î»¡£

Ô­ÎÄÁ´½Ó£º
https://www.tripwire.com/state-of-security/security-data-protection/malspam-campaign-targeted-german-organizations-with-buran-ransomware/

6¡¢ºÚ¿ÍÈëÇÖÃÀ¹ú¸ßµµ·¨ÔºÏµÍ³²¢·¢ËÍÔ¼200Íò·âÀ¬»øÓʼþ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


µÃ¿ËÈøË¹ÖÝÒ»ÃûÄÐ×Ó£¨Oriyomi Sadiq Aloba£©ÒòÈëÇÖÂåÉ¼í¶¸ßµµ·¨Ôº£¨LASC£©µÄÍÆËã»úϵͳ²¢Ê¹ÓÃÆä·þÎñÆ÷·¢ËÍÔ¼200Íò·âÀ¬»øÓʼþ¶ø±»ÅÐÈëÓü145¸öÔºÍÅâ³¥4.7ÍòÃÀÔª¡£AlobaÖØÒªÍ¨¹ý´¹µö¹¥»÷ÔÚ2017Äê7Ô»ñÈ¡ÁËLASCÔ±¹¤µÄÓÊÏäÕË»§Í´´¦£¬²¢ÀûÓÃÕâЩʹ´¦µÇ¼µ½LASC·þÎñÆ÷ºÍ·¢ËÍÁ˳¬¹ý200Íò·â´¹µöÓʼþ¡£ÕâЩÓʼþ¼ÙÒâ³ÉÃÀ¹úÔËͨ£¨American Express£©ºÍ¸»¹úÒøÐУ¨Wells Fargo£©µÈ¹«Ë¾¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-superior-court-systems-hacked-to-spread-phishing-emails/