Ó¢¹ú´¦ÖÃÅ·ÃËÓÀ¾Ó¹æ»®Ê±ÖÁÉÙÎ¥·´ÁË100´ÎGDPR£»APT34й¥»÷»î¶¯Karkoff 2020
°ä²¼¹¦·ò 2020-03-041.Ó¢¹ú´¦ÖÃÅ·ÃËÓÀ¾Ó¹æ»®Ê±ÖÁÉÙÎ¥·´ÁË100´ÎGDPR
Ó¢¹úÄÚÕþ²¿ÔÚ´¦ÖÃÅ·ÃËÓÀ¾Ó¹æ»®£¨EUSS£©Ê±ÖÁÉÙÎ¥·´ÁË100´ÎGDPR¡£Ê×ϯÌìǵºÍÒÆÃñ²é³¹Ù£¨David Ilt£©ÔÚÒÆÃñ¼à¹Ü»ú¹¹½øÐеÄÒ»·Ý»ã±¨ÖаµÊ¾£¬Ö»¹ÜGDPRÒªÇó¶ÔÔ±¹¤½øÐÐÒâʶÅàѵ£¬µ«ÈԼͼµ½¶ÔGDPRµÄÑϳÁÎ¥·´¡£Æ¾¾Ý¸Ã»ã±¨£¬½ØÖÁ2019Äê8Ôµף¬ÄÚÕþ²¿£¨EUSSµÄ¼à¶½Õߣ©ÊÕµ½ÁË130Íò·ÝÉêÇ룬²¢ÇÒÒѾÓÐÉϰÙÍòÈË»ñµÃºË×¼¡£µ«ÔÚ2019Äê3ÔÂ30ÈÕÖÁ8ÔÂ31ÈÕÆÚ¼ä£¬µ±¾ÖÎ¥·´ÁËGDPRµÄÊÂÎñÓÐ100Æð¡£ÕâЩÊÂÎñÔ̺¬½«Éí·ÝÖ¤¿¨Æ¬·¢ËÍÖÁÃýÎóµÄÉêÇëÈ˺͵ØÖ·£»ºÜ¶à»¤ÕÕÃÔʧÁË£¬Éí·ÝÖ¤Ã÷Îļþ±»ÓÊÕþ²¿ÃźÍEUSS·Å´íÁË´¦Ëù£»Î´¾Ô޳ɱãÓëµÚÈý·½¹²ÏíÉêÇëÈ˵ÄÐÅÏ¢µÈ¡£ÄÚÕþ²¿°µÊ¾»á¶¨ÆÚÉó²éËùÓÐÁ÷³ÌºÍ·¨Ê½£¬ÒÔ¼õÇáÊý¾Ýй¶µÄ·çÏÕ¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/uk-home-office-breached-gdpr-100-times-through-botched-handling-of-eu-settlement-scheme/
2.Checkpoint´´½¨¶ñÒâÈí¼þÈÆ¹ý¶ÈÎöµÄ¼¼ÊõµÄ°Ù¿ÆÈ«Êé
Checkpoint´´½¨Á˹ØÓÚ¶ñÒâÈí¼þÓÃÀ´ÌӱܷÖÎöµÄ¸÷À༼ÊõµÄ°Ù¿ÆÈ«Êé¡£¸Ã°Ù¿ÆÈ«Ê麸ÇÁËÓëÎļþϵͳ¡¢×¢²á±í¡¢Í¨ÓÃOS²éÎÊ¡¢È«¾ÖOS¶ÔÏó¡¢Óû§½çÃæ¡¢OSÖ°ÄÜ¡¢¹ý³Ì¡¢ÍøÂç¡¢CPU¡¢¹Ì¼þ±í¡¢¹³×Ó¡¢Ó²¼þÒÔ¼°MacOSÌØ¶¨µÄɳÏäÓйصÄÌӱܼ¼Êõ¡£Ã¿Ò»¸öÀà±ð¶¼Ô̺¬¼¼ÊõÃèÊö¡¢´úÂëʾÀý¡¢ÓÃÓÚ¸ú×ٸü¼ÊõµÄÊðÃû½¨Òé¡¢¿É¼ì²â»·¾³ÀàÐ͵ıí¸ñÒÔ¼°¶Ô²ß¡£Checkpoint»¹´òËãÔö³¤Óë¼ÆÊ±¡¢Windows Management Instrumentation£¨WMI£©ºÍÈËÀàÐÐΪ³É·ÖÓйصÄÌӱܼ¼Êõ¡£ÓйØÁìÓòµÄר¼ÒÄܹ»ÔÚGithubÒ³ÃæÉÏΪ¸Ã°Ù¿ÆÈ«Êé×ö³ö¹±Ïס£Ò»Ð©ÑÝʾ¶ã±Ü¼¼ÊõµÄ¹¤¾ßÊÇ¿ªÔ´µÄ£¬Í¬Ê±Checkpoint»¹°ä²¼ÁË×Ô¼ºµÄÃûΪInviZzzibleµÄ¿ªÔ´¹¤¾ß¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/checkpoint-creates-encyclopedia-malware-evasion-techniques
3.Ó¢¹úTravelex¹«Ë¾Ô¤¼ÆÒòÍøÂç¹¥»÷Ëðʧ2500ÍòÓ¢°÷
¾Ý·͸É籨·£¬ÓÉÓÚ12ÔÂÏÂÑ®µÄÀÕË÷Èí¼þ¹¥»÷ÊÂÎñ£¬±í±Ò¶Ò»»¹«Ë¾Travelex¹À¼ÆÆäµÚÒ»¼¾¶ÈµÄÖ÷ÌâÊÕÈëËðʧΪ2500ÍòÓ¢°÷£¨ºÏ3200ÍòÃÀÔª£©¡£¸Ã¹«Ë¾»¹°µÊ¾ÒѸ´ÔÁËËùÓÐÃæÏò¿Í»§µÄϵͳ¡£Travelexͨ¹ýÆä×Ô¶¯¶©µ¥·þÎñΪ»ã·áÒøÐÓ×¢°Í¿ËÀ³ÒøÐÓעάÕäÇ®±ÒÒÔ¼°Ó¢¹úÁãÊÛÉÌTescoºÍSainsburyµÄÒøÐв¿Ãſͻ§Ìṩ±í»ã·þÎñ¡£Travelex°µÊ¾Õâ´Î¹¥»÷²»»á¶ÔËæºó¼¸¸ö¼¾¶ÈµÄÂòÂôÔì³ÉÈκÎÄÚÈÝÐÔÓ°Ïì¡£¸Ã¹«Ë¾»¹³Æ¹Ú×´²¡¶¾µÄ·¢×÷¶ÔÆäÒµÎñÔì³ÉÁËÁí±íÒ»¸ö¸ºÃæÓ°Ï죬µ«Î´Ô¤¼Æ¸Ã²¡¶¾»á´øÀ´Èκξ¼ÃËðʧ¡£
ÔÎÄÁ´½Ó£º
https://uk.finance.yahoo.com/news/travelex-expects-25-million-hit-093953943.html
4.Let's Encrypt³·»Ø³¬¹ý300Íò¸öTLSÖ¤Êé
ÓÉÓÚÔÚºó¶Ë´úÂëÖз¢ÏÖÁËÒ»¸öbug£¬Let's EncryptÏîÄ¿´òËã´ÓÊÀ½ç±ê¶¨¹¦·ò2020Äê3ÔÂ4ÈÕ00:00ÆðÍ·³·Ïú³¬¹ý300Íò¸öTLSÖ¤Êé¡£¾ßÌåÀ´Ëµ£¬¸ÃbugÓ°ÏìÁËBoulder£¬Let's EncryptÏîĿʹÓø÷þÎñÆ÷Èí¼þÔÚ¿¯ÐÐTLSÖ¤Êé֮ǰÑéÖ¤Óû§¼°ÆäÓò¡£¸ÃbugÓ°ÏìÁËBoulderÄÚ²¿CAA£¨Ö¤ÊéÐû¸æ»ú¹¹ÊÚȨ£©¹æ·¶µÄÖ´ÐУ¬¡°µ±Ò»¸öÖ¤ÊéÒªÇóÔ̺¬N¸ö±ØÒª½øÐÐCAA³Áв鳵ÄÓòÃûʱ£¬Boulder½«Ñ¡ÔñÒ»¸öÓòÃû²¢²é³N´Î¡£ÕâÏÖʵÉÏÒâζ×ÅÈôÊÇÒ»¸öÓû§ÔÚ¹¦·òXÑéÖ¤ÁËÒ»¸öÓòÃû£¬²¢ÇÒ¸ÃÓòÃûÔÚ¹¦·òXµÄCAA¼Í¼ÔÊÐíLet's Encrypt¿¯ÐУ¬Ôò¸ÃÓû§Äܹ»ÔÚX+30ÌìµÄ¹¦·òÀ￯ÐÐÔ̺¬¸ÃÓòÃûµÄÖ¤Ê飬¼´±ãÖ®ºóÓÐÈËÔÚ¸ÃÓòÃûÉÏ×°ÖÃÁ˲»ÈÝLet's Encrypt¿¯ÐеÄCAA¼Í¼¡±¡£ÔÚÕâ300Íò¸ö³·ÏúµÄÖ¤ÊéÖУ¬ÓÐ100Íò¸öÊÇͳһÓò/×ÓÓòµÄ³Á¸´ÏÒò¶øÊÜÓ°ÏìÖ¤ÊéµÄÏÖʵÊýÁ¿Ô¼Îª200Íò¸ö¡£ÔÚ3ÔÂ4ÈÕ00:00Ö®ºóËùÓÐÊÜÓ°ÏìµÄÖ¤Êé¶¼½«´¥·¢ä¯ÀÀÆ÷ºÍÆäËûÀûÓ÷¨Ê½ÖеÄÃýÎó£¬ÓòÃûËùÓÐÕß½«±Ø±ØÒªÇóеÄTLSÖ¤Êé²¢´úÌæ¾ÉµÄTLSÖ¤Êé¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/lets-encrypt-to-revoke-3-million-certificates-on-march-4-due-to-bug/
5.APT34й¥»÷»î¶¯Karkoff 2020£¬Õë¶ÔÀè°ÍÄÛµ±¾Ö»ú¹¹
Cybaze/Yoroi ZlabµÄר¼Ò·¢ÏÖAPT34×éÖ¯µÄÒ»¸öÐÂÑù±¾£¬ËûÃÇÒÔΪ¸ÃÑù±¾ÊÇKarkoffÖ²ÈëÎïµÄ¸üа汾£¬Äܹ»Ö¤Ã÷APT34ÒÀÈ»´¦Óڻ״̬¡£ÔÚÕâ¸öÐµĹ¥»÷»î¶¯ÖÐAPT34¿ÉÄÜÈëÇÖÁËÊôÓÚÀè°ÍÄÛµ±¾Ö»ú¹¹µÄMicrosoft Exchange Server¡£ÐÂÑù±¾Óë´ÓǰKarkoffÑù±¾µÄÀàËÆÖ®´¦Ô̺¬ÓµÓÐÀàËÆµÄºê½á¹¹¡¢ÓµÓÐÀàËÆÂß¼µÄ.NETÄ£¿é»¯Ö²ÈëÎïÒÔ¼°ÀûÓÃMicrosoft Exchange Server×÷ΪͨѶÇþ·¡£´Ë±í£¬ÐÂKarkoffÖ²ÈëÎïʵÏÖÁËеĿúËÅÂß¼£¬ÒÔ±ã½ö½«×îÖÕµÄÓÐЧºÉÔØ¿ªÊ͵½Ìض¨Ö¸±ê£¬²¢ÇÒÍøÂçϵͳÐÅÏ¢¡¢ÓòÃû¡¢Ö÷»úÃûºÍÔÚÔËÐеIJÙ×÷ϵͳµÈÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/98802/uncategorized/karkoff-malware-lebanon.html
6.ÐÂPwndLockerÀÕË÷Èí¼þÖØÒªÕë¶ÔÃÀ¹úÊÐÕþµ±¾ÖºÍÆóÒµÍøÂç
°²È«×êÑÐÈËÔ±·¢ÏÖÕë¶ÔÊÐÕþµ±¾ÖºÍÆóÒµÍøÂçµÄÐÂÀÕË÷Èí¼þ¼Ò×å¡°PwndLocker¡±£¬¸Ã¼Ò×å×Ô2019Äêµ×ÒÔÀ´Ò»Ïò»îÔ¾£¬²¢ÔÚÕâ¶Î¹¦·òÄÚ¹¥»÷ÁËÃÀ¹ú¶à¸ö³ÇÊкÍ×éÖ¯¡£PwndLockerÓë½üÆÚÕë¶ÔÒÁÀûŵÒÁÖÝÀÈø¶ûÏØµÄ¹¥»÷Óйأ¬¹¥»÷ÕßÒªÇó50¸ö±ÈÌØ±Ò£¨Ô¼ºÏ44.2ÍòÃÀÔª£©µÄÊê½ð£¬²¢ÇÒ³ÆÔÚ¼ÓÃÜ֮ǰÒѾÇÔÈ¡Á˸ÃÏØµÄÊý¾Ý¡£±¾µØÃ½ÌåÖ¸³ö£¬ÀÈø¶ûÏØÎÞÒâÖ§¸¶Êê½ð¡£Æ¾¾Ý×êÑÐÈËÔ±µÄ·ÖÎö£¬PwndLockerÀûÓá°net stop¡±ºÅÁî½ûÓÃÁ˶à¸öWindows·þÎñ£¬ÀýÈçMicrosoft SQL Server¡¢MySQLºÍExchange£¬²¢ÇÒ¼ì²âºÍɱËÀÓëFirefox¡¢Word¡¢Excel¡¢AccessÒÔ¼°Ó밲ȫÈí¼þ¡¢±¸·ÝÀûÓ÷¨Ê½ºÍÊý¾Ý¿â·þÎñÆ÷ÓйصĹý³Ì¡£Æä¼ÓÃÜÎļþµÄÀ©´óÃûΪ¡°.key¡±»ò¡° .pwnd¡±¡£PwndLocker²¢²»ÊǵÚÒ»¸öÕë¶ÔÆóÒµÍøÂçµÄÀÕË÷Èí¼þ£¬Ö®Ç°×êÑÐÈËÔ±»¹·¢ÏÖÁËÕë¶ÔÆóÒµÍøÂçµÄSNAKEºÍAko¼Ò×å¡£
ÔÎÄÁ´½Ó£º
https://www.tripwire.com/state-of-security/security-data-protection/pwndlocker-ransomware-targeting-municipalities-enterprise-networks/


¾©¹«Íø°²±¸11010802024551ºÅ