ÎÒ¹úͨ¹ý¡¼ûÜÂë·¨¡·£¬½«ÓÚ2020Äê1ÔÂ1ÈÕÆð³¢ÊÔ£»NCSC°ä²¼2019ÄêÍøÂç°²ÕûÄê¶È»ã±¨

°ä²¼¹¦·ò 2019-10-28
1¡¢ÎÒ¹úͨ¹ý¡¼ûÜÂë·¨¡·£¬½«ÓÚ2020Äê1ÔÂ1ÈÕÆð³¢ÊÔ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

Ê®Èý½ìÈ«¹úÈË´ó³£Î¯»áµÚÊ®ËĴλáÒé26ÈÕ±í¾öͨ¹ý¡¶ÖлªÈËÃñ¹²ºÍ¹úÃÜÂë·¨¡·£¬½«×Ô2020Äê1ÔÂ1ÈÕÆðÖ´ÐС£ÃÜÂë·¨Ö¼Ôڹ淼ûÜÂëÀûÓúÍÖÎÀí£¬ÍƽøÃÜÂëÊÂÒµ·¢Õ¹£¬±£ÏÕÍøÂçÓëÐÅÏ¢°²È«£¬ÌáÉýÃÜÂëÖÎÀí¿ÆÑ§»¯¡¢¹æ·¶»¯¡¢·¨Öλ¯Ë®Æ½£¬ÊÇÎÒ¹úÃÜÂëÁìÓòµÄ×ÛºÏÐÔ¡¢»ù´¡ÐÔ˾·¨¡£ÃÜÂë·¨¹²ÎåÕÂËÄÊ®ËÄÌõ£¬½«ÃÜÂë·ÖΪÖ÷ÌâÃÜÂ롢ͨ³£ÃÜÂëºÍÉÌÓÃÃÜÂ룬²¢¶ÔÓйØÔì¶È¡¢Ë¾·¨ÔðÈμ°È¨±ú²¿ÃŽøÐÐÁË»®¶¨¡£


Ô­ÎÄÁ´½Ó£º

http://www.xinhuanet.com/politics/2019-10/26/c_1125156896.htm

2¡¢Ó¢¹úNCSC°ä²¼2019ÄêÍøÂç°²ÕûÄê¶È»ã±¨


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝÓ¢¹ú¹ú¶ÈÍøÂ簲ȫÖÐÐÄ£¨NCSC£©°ä²¼µÄ2019ÍøÂç°²ÕûÄê¶È»ã±¨£¬2018Äê9ÔÂ1ÈÕÖÁ2019Äê8ÔÂ31ÈÕÆÚ¼äNCSC¹²×èÖ¹ÁË600¶àÆðÍøÂç¹¥»÷ÊÂÎñ£¬ÆäÖдóÎÞÊý¹¥»÷ÊÇÓɺ£±í¹¥»÷ÕßÌáÒéµÄ¡£¸Ã»ã±¨Ö¸³ö£¬´óÎÞÊý¹¥»÷Õë¶Ôµ±¾Ö»ú¹¹¡¢´óѧ¡¢ÐÅÏ¢¼¼Êõ¡¢Ò½ÁƱ£½¡ºÍÔËÊäµÈÐÐÒµ¡£NCSC»¹ÖÒ¸æÁË56¼ÒÒøÐÐÓйØATM͵ÇÔÍþв¡£¸Ã»ã±¨ÖгƶíÂÞ˹¡¢Öйú¡¢ÒÁÀʺͳ¯ÏʳÖÐø¶ÔÓ¢¹ú×é³ÉÕ½ÊõÐÔ¹ú¶È°²È«Íþв¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/93015/intelligence/ncsc-report-cyber-attacks.html

3¡¢7-11¼ÓÓÍAPPÒâ±íй¶²¿ÃÅÓû§Êý¾Ý

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ƾ¾ÝÓ¢¹ú¡¶ÎÀ±¨¡·±¨Â·£¬7-11¼ÓÓÍAPP³öÏÖbug£¬Ê¹µÃÓû§Äܹ»²é¿´ÆäËü¿Í»§µÄÓ×ÎÒÐÅÏ¢£¬Ô̺¬ÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢ÊÖ»úºÅÂëºÍµ®ÉúÈÕÆÚ¡£Ò»Ãû¿Í»§°µÊ¾ËûÔÚÂŴεǼºÍ×¢Ïúºó£¬ÔÙ³ÁеǼ¼´¿É½Ó¼ûÆäËü¿Í»§µÄÐÅÏ¢£¬Ô̺¬ËûÃÇÕË»§ÖеĽð¶î¡£¸ÃAPPµÄÏÂÔØÁ¿Îª200Íò´Î£¬ÔÚ½«¸ÃAPPÏÂÏßÁ˼¸¸öÓ×ʱºó£¬7-11½²»°È˰µÊ¾¸Ã¼¼ÊõÎÊÌâÒѾ­½¨¸´£¬¸Ã¹«Ë¾ÔÚ³ÖÐøµ÷²é²¢Í¨ÖªÓйص±¾Ö¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/drivers-data-exposed-in-7eleven/

4¡¢ÐÂÀÕË÷Èí¼þFuxSocy¼ÙÒâCerber½øÐд«²¼


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÐÂÀÕË÷Èí¼þFuxSocy±»·¢ÏÖ·ÂÕÕÁË´Ë¿ÌÒѲ»¸´´æÔÚµÄÀÕË÷Èí¼þCerber¡£¸ÃÀÕË÷Èí¼þÓÉMalwareHunterTeam·¢ÏÖ£¬ÒÔµçÊÓ¾çMr. RobotÖз¸×ïÍÅ»ïFSocietyµÄÃû×Ö½øÐж¨Ãû¡£ÄæÏò¹¤³ÌʦVitali Kremez·¢ÏÖFuxSocyÔÚ±í¹ÛÓëÄÚ²¿¶¼ºÍCerberÓµÓÐÀàËÆÖ®´¦£¬ÀýÈç¼ÓÃÜÎļþʱFuxSocy½«Ìø¹ýÎļþõè¾¶Ô̺¬Ä³Ð©×Ö·û´®µÄÎļþ£¬ÆäÖкܶà×Ö·û´®Ö±½ÓÈ¡×ÔCerberµÄÁбí£»´Ë±í£¬FuxSocy»¹ÒÔÀàËÆÓÚCerberµÄ·½Ê½¶Ô¼ÓÃÜÎļþµÄÃû×ÖºÍÀ©´óÃû½øÐÐÉ趨£»×îºó£¬ÔÚ¼ÓÃÜϵͳºó£¬FuxSocy½«Windows×ÀÃæ²¼¾°¸ü¸ÄΪÓëCerberʹÓõÄÏÕЩһÑùµÄ²¼¾°¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-fuxsocy-ransomware-impersonates-the-notorious-cerber/

5¡¢Ð¶ñÒâÈí¼þBlueFace¶Ô×¼Windows DiscordÓû§

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


MalwareHunterTeam·¢ÏÖжñÒâÈí¼þͨ¹ýÅú¸ÄWindows Discord¿Í»§¶ËÀ´Õë¶ÔDiscordÓû§£¬ÖØÒªÇÔÈ¡Óû§ÐÅÏ¢ºÍ³äÈκóÃÅ·¨Ê½¡£¸Ã¶ñÒâÈí¼þ±»³ÆÎªBlueFace£¬»áÔÚÊÜϰȾµÄϵͳÉÏÔö³¤×Ô¼ºµÄ¶ñÒâJavaScript£¬¸Ã¾ç±¾½«Ö´Ðи÷ÀàDiscord APIºÅÁîºÍJavaScriptº¯Êý£¬ÍøÂçÓйØÓû§µÄ¸÷ÀàÐÅÏ¢£¬×îºóͨ¹ýDiscord Webhook½«ÕâЩÐÅÏ¢·¢Ë͸ø¹¥»÷Õß¡£ÓÉÓÚËü»áÍøÂç¼ôÌù°åµÄÄÚÈÝ£¬Òò¶ø¿ÉÄÜ»áÇÔÈ¡Óû§µÄÃÜÂë¡¢Ó×ÎÒÐÅÏ¢»òÆäËüÃô¸ÐÊý¾Ý¡£¸Ã¶ñÒâÈí¼þ»¹»áÖ´ÐÐfightdio£¨£©º¯Êý³äÈκóÃÅ¡£Ä¿Ç°ÆäÔÚVirusTotalÉϵļì²âÂʽöΪ24/65 ¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/discord-turned-into-an-info-stealing-backdoor-by-new-malware/

6¡¢×êÑÐÈËÔ±·¢ÏÖNukeSped RATÓ볯ÏÊLazarus APTÓйØ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Fortinet°²È«×¨¼Ò·ÖÎöÁ˶ñÒâÈí¼þNukeSpedµÄÑù±¾£¬·¢ÏÔìäÓ볯ÏÊAPT×éÖ¯Lazarus´æÔÚ¹ØÁª¡£Í¨¹ý¶Ô¶ñÒâÈí¼þµÄÖ°ÄܽøÐзÖÎö£¬×êÑÐÈËԱȷ¶¨ËüÊǶ¯Ì¬½âÎöÖ°ÄܵÄ£¬ÏÖʵÉÏ£¬¶ñÒâ´úÂë½öŲÓÃÁËÉÙÁ¿API¡£NukeSped Ñù±¾»¹¼ÓÃÜÁËAPIÃû³ÆÒÔ×èÖ¹¾²Ì¬·ÖÎö£¬Ëüͨ¹ýÔö³¤×¢²á±íÏîÀ´»ñµÃÓÆ¾ÃÐÔ£¬²¢ÇÒÔÚijЩÇé¿öÏ»Ὣ×Ô¼º×÷Ϊ·þÎñ×°Ö᣸öñÒâÈí¼þµÄÖØÒªÖ°ÄÜÊÇΪ¹¥»÷ÕßÌṩ¶ÔÊÜϰȾÖ÷»úµÄÔ¶³ÌÖÎÀí¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/92916/malware/nukesped-rat-north-korea.html