Ç÷Ïò¿Æ¼¼ATTK¹¤¾ß°ü´æÔÚËÁÒâ´úÂëÖ´Ðзì϶£»¶à¼ÒVPN¹©¸øÉÌÔâºÚ¿Í¹¥»÷£¬·þÎñÆ÷˽Կ±»µÁ
°ä²¼¹¦·ò 2019-10-23
×êÑÐÈËÔ±·¢ÏÖÇ÷Ïò¿Æ¼¼·ÀÍþв¹¤¾ß°ü£¨ATTK£©´æÔÚÒ»¸öËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2019-9491£©£¬¹¥»÷Õß¿ÉÀûÓô˷ì϶ÔÚÖ¸±êWindowsϵͳÉÏÔËÐжñÒâÈí¼þ¡£Æ¾¾ÝÇ÷Ïò¿Æ¼¼°ä²¼µÄ°²È«²¼¸æ£¬ÈôÊǶñÒâÈí¼þ×÷Õß´ÕÇɽ«¶ñÒâÈí¼þ¶¨ÃûΪcmd.exe»òregedit.exe£¬ÄÇôATTK½«»á¼ÓÔØ²¢ÔËÐиÃexeÎļþ¡£ÓÉÓÚATTKÊÇÓɾ¹ýÑéÖ¤µÄ¿¯Ðз½ÊðÃûµÄ£¬Òò¶ø¿ÉÈÆ¹ýÈκÎMOTW°²È«ÖҸ棬¹¥»÷ÕßÉõÖÁÄܹ»½«ATTK×÷ΪһÖÖÓÆ¾ÃÐÔ»úÔì¡£Ç÷Ïò¿Æ¼¼ÏÖÒѽ«ËùÓÐATTK ¸üÐÂÖÁ1.62.0.1223°æ±¾£¬µ«ÉÐδ°ä²¼¼¼Êõϸ½Ú¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/92818/hacking/trend-micro-anti-threat-toolkit-flaw.html2¡¢¶à¼ÒVPN¹©¸øÉÌÔâºÚ¿Í¹¥»÷£¬·þÎñÆ÷˽Կ±»µÁ
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/92808/hacking/nordvpn-torguard-vikingvpn-hack.html3¡¢µÂ¹úÔì×÷ÉÌPilzÔÚÔâµ½ÀÕË÷Èí¼þ¹¥»÷Ò»ÖܺóÈÔδ¸´Ô
µÂ¹ú×Ô¶¯»¯¹¤¾ß³§ÉÌÆ¤¶û×È£¨Pilz£©ÔÚÔâ·êÀÕË÷Èí¼þBitPaymerϰȾºóÒѾ崻úÁ˳¬¹ýÒ»ÖܵŦ·ò¡£Æ¾¾Ý¸Ã¹«Ë¾µÄÍøÕ¾ÐÂÎÅ£¬×Ô2019Äê10ÔÂ13ÈÕÒÔÀ´£¬¸Ã¹«Ë¾ÔÚÈ«ÇòÁìÓòÄÚµÄËùÓзþÎñÆ÷ºÍPC¹¤×÷Õ¾£¬Ô̺¬Í¨Ñ¶ÉèÊ©£¬¶¼Êܵ½ÁËÓ°Ï졣ΪԤ·ÀÆð¼û£¬¸Ã¹«Ë¾´ÓÍøÂçÖÐɾ³ýÁËËùÓÐÍÆËã»úϵͳ²¢×èÖ¹Á˶Թ«Ë¾ÍøÂçµÄ½Ó¼û¡£PilzÔ±¹¤»¨ÁËÈýÌ칦·ò²Å¸´Ôµç×ÓÓʼþ·þÎñµÄ½Ó¼û£¬ÓÖ»¨ÁËÈýÌì²Å¸´ÔÆä¹ú¼Êµç×ÓÓʼþ·þÎñ£¬Ö±µ½21ÈղŸ´Ô¶Ô²úÆ·¶©µ¥ºÍ½»»õϵͳµÄ½Ó¼û¡£¸Ã¹«Ë¾µÄ³ö²úÄÜÁ¦Ã»ÓÐÊܵ½Ó°Ïì¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/major-german-manufacturer-still-down-a-week-after-getting-hit-by-ransomware/4¡¢Ó¢¹úHome GroupÔâºÚ¿Í¹¥»÷£¬½ü4000¿Í»§ÐÅϢй¶
Ó¢¹ú×î´óµÄס·¿Ð»áÖ®Ò»Home GroupÒÑÏòÔ¼4000Ãû¿Í»§°ä²¼ÖҸ棬ÆäÓ×ÎÒÐÅÏ¢Ôڸù«Ë¾Ôâ·êÊý¾Ýй¶֮ºó¿ÉÄܱ»µÁ¡£Æ¾¾ÝBBCµÄ±¨Â·£¬ÊÜÓ°ÏìµÄÐÅÏ¢Ô̺¬¿Í»§µÄÐÕÃû¡¢µØÖ·ºÍÁªÏµÐÅÏ¢£¬µ«²»Ô̺¬²ÆÕþÊý¾Ý¡£¸Ã¹«Ë¾Ú¹Êͳƣ¬ÊÂÎñÊÇÓɵÚÈý·½°²È«×¨¼Ò·¢Ïֵģ¬Ó°ÏìÁËÓ¢¸ñÀ¼¶«±±¡¢Î÷±±¼°Ô¼¿Ë¿¤µÄ¿Í»§¡£Ä¿Ç°Éв»Ã÷ÏÔÊÂÎñ²úÉúµÄ¾ßÌåÔÒò£¬µ«Home Group½²»°È˳ƸÃÎÊÌâÔÚ90·ÖÖÓÄڵõ½½â¾ö¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/home-group-data-breach/
5¡¢ÐÂÀ¬»øÓʼþ»î¶¯ÀûÓÃÀÕË÷Èí¼þBuran¶Ô×¼µÂ¹ú
ÔÎÄÁ´½Ó£º
https://www.tripwire.com/state-of-security/security-data-protection/malspam-campaign-targeted-german-organizations-with-buran-ransomware/
6¡¢ºÚ¿ÍÈëÇÖÃÀ¹ú¸ßµµ·¨ÔºÏµÍ³²¢·¢ËÍÔ¼200Íò·âÀ¬»øÓʼþ
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/us-superior-court-systems-hacked-to-spread-phishing-emails/


¾©¹«Íø°²±¸11010802024551ºÅ