ºÚ¿ÍÈëÇÖÌØÀÊÆÕ¾ºÑ¡ÍøÕ¾²¢´«²¼ÐéαÐÅÏ¢£»ACTI³Æ¶íºÚ¿Í×éÖ¯TurlaÈëÇÖÅ·ÖÞÒ»¸öµ±¾Ö×éÖ¯

°ä²¼¹¦·ò 2020-10-29
1.ºÚ¿ÍÈëÇÖÌØÀÊÆÕ¾ºÑ¡ÍøÕ¾²¢´«²¼ÐéαÐÅÏ¢


1.jpg


µ±¾Ö¹ÙÔ±°µÊ¾£¬ºÚ¿ÍÔÚÑ¡¾ÙÈÕǰһÖܵÄÐÇÆÚ¶þÈëÇÖÁËÌÆÄɵ¡¤ÌØÀÊÆÕµÄ¾ºÑ¡ÍøÕ¾¡£donaldjtrump.comÍøÕ¾±»¡°Õâ¸öÍøÕ¾±»²é·âÁË¡±ÐÂÎÅËùÈ¡´ú£¬²¢°µÊ¾¡°ÊÀ½çÒѾ­Êܹ»ÁËÌÆÄɵ¡¤J¡¤ÌØÀÊÆÕ×ÜͳÿÌìÉ¢²¥µÄ¼ÙÐÂÎÅ¡±¡£´Ë±í£¬ºÚ¿Í»¹ºôÓõÍøÃñ¾èÔùMoneroÊý×ÖÇ®±ÒÒÔÖ§³Ö»ò·ñ¾öй¶ÓëÌØÀÊÆÕÓйصÄÖ¤¾Ý¡£ÌØÀÊÆÕ¾ºÑ¡½²»°ÈËTim Murtaugh°µÊ¾£¬¸ÃÍøÕ¾ºÜ¿ìµÃµ½½¨¸´²¢Ã»ÓÐÈκÎÃô¸ÐÊý¾Ýй¶£¬Õâ´Î¹¥»÷µÄÆðÔ´»¹ÔÚµ÷²éÖС£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/trump-campaign-website-broken-hackers


2.ACTI³Æ¶íºÚ¿Í×éÖ¯TurlaÈëÇÖÅ·ÖÞÒ»¸öµ±¾Ö×éÖ¯


2.jpg


ƾ¾Ý°£É­ÕÜÍøÂçÍþвµý±¨£¨ACTI£©µÄ×îл㱨£¬¶íÂÞ˹µÄºÚ¿Í×éÖ¯TurlaÈëÇÖÁËÒ»¸öδ¹«¿ªÃû³ÆµÄÅ·ÖÞµ±¾Ö×éÖ¯µÄϵͳ¡£ÎªÁËÈëÇÖ×éÖ¯ÍøÂ磬¹¥»÷ÕßʹÓÃÁË×î½ü¸üеÄÔ¶³ÌÖÎÀíľÂí£¨RAT£©ºÍ»ùÓÚÔ¶³Ì¹ý³ÌŲÓã¨RPC£©µÄºóÃÅ·¨Ê½£¬ÆäÖÐÔ̺¬HyperStack¡£ACTI°µÊ¾£¬Õâ´Î¹¥»÷ÆëÈ«ÇкÏTurla´Óʼäµý»î¶¯µÄ¶¯»ú£¬Ä¿Ç°ËüÒѾ­·ÛËéÁËÀ´×Ô100¶à¸ö¹ú¶ÈÈ·µ±¾Ö¡¢´óʹ¹ÝÒÔ¼°½ÌÓýºÍ×êÑлú¹¹µÄÊýǧ¸öϵͳ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/russian-turla-hackers-breach-european-government-organization/


3.Microsoft°ä²¼KB4577586¸üУ¬ÖÕ³¡Ê¹ÓÃAdobe Flash


3.jpg


Microsoft°ä²¼ÁËKB4577586¸üУ¬ÒÔÖÕ³¡Ê¹ÓÃWindowsÉϵÄAdobe Flash¡£Õâ´Î¸üнö¿Éͨ¹ýMicrosoft Catalog»ñµÃ¡£MicrosoftÉêÃ÷¸Ã¸üн«×Ô¶¯É¾³ýAdobe Flash Player£¬µ«Éв»Ã÷ÏÔÈ·ÇÐɾ³ýµÄÄÚÈÝ¡£¾­¹ý²âÊÔ£¬´Ë¸üÐÂɾ³ýÁËWindows 10Öа󸿵ÄFlash Player£¨32룩°æ±¾£¬µ«²»»áɾ³ýÈκζÀÁ¢°æ±¾µÄAdobe Flash Player¡£MicrosoftÔò°µÊ¾»á2021ËêÊ×Flashµ½ÆÚºó¶ÔFlash Player½øÐдó¹æÄ£É¾³ý¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-update-to-remove-adobe-flash-from-windows/


4.Enel GroupÔÙ´ÎϰȾÀÕË÷Èí¼þ£¬Ð¹Â¶5TBµÄÊý¾Ý


4.jpg


¿ç¹úÄÜÔ´¹«Ë¾Enel Group½ñÄêÔâµ½µÚ¶þ´ÎÀÕË÷Èí¼þ¹¥»÷£¬NetwalkerÐû³ÆÆäÇÔÈ¡ÁË5TBµÄÊý¾Ý²¢ÀÕË÷1400ÍòÃÀÔªÊê½ð¡£EnelÊÇÅ·ÖÞÄÜÔ´ÁìÓò×î´óµÄ¹«Ë¾Ö®Ò»£¬ÔÚ40¸ö¹ú¶ÈºÍµØÓòÕ¼ÓÐ6100Íò¿Í»§¡£½ñÄê6Ô³õ£¬EnelµÄÄÚ²¿ÍøÂçÔâµ½SnakeÀÕË÷Èí¼þµÄ¹¥»÷£¬10ÔÂ19ÈÕÓÖÔâµ½NetwalkerÀÕË÷Èí¼þµÄ¹¥»÷¡£Ä¿Ç°£¬NetwalkerÒÑÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾°ä²¼Á˱»µÁÊý¾ÝµÄ½ØÍ¼£¬²¢°µÊ¾»áÔÚÒ»ÖÜÄÚ¹«¿ªÆäÖеÄÒ»²¿ÃÅ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/enel-group-hit-by-ransomware-again-netwalker-demands-14-million/


5.¼Ò¾ß¹«Ë¾SteelcaseϰȾRyukµ¼ÖÂϵÍÂäÙʱ¹Ø¹Ø


5.jpg


È«Çò×î´óµÄ°ì¹«¼Ò¾ßÔì×÷ÉÌSteelcase³ÆÆäÔÚ10ÔÂ22ÈÕÔâµ½RyukÀÕË÷Èí¼þ¹¥»÷£¬²¢µ¼ÖÂϵÍÂäÙʱ¹Ø¹Ø¡£¸Ã¹«Ë¾°ä²¼ÉêÃ÷³ÆÆäÔÚÐÅÏ¢¼¼ÊõϵͳÉÏ·¢ÏÖÁËÍøÂç¹¥»÷£¬²¢Ñ¸¿ì²ÉÈ¡ÁËһϵÁжôÔì´ëÊ©À´½â¾öÕâÖÖÇé¿ö£¬Ô̺¬ÁÙʱ¹Ø¹ØÊÜÓ°ÏìµÄϵͳºÍÓйزÙ×÷¡£Ä¿Ç°£¬¹«Ë¾Éв»ÖªÂ·´Ë¹¥»÷µ¼ÖµľßÌåϵͳÊý¾ÝÃÔʧ»ò×ʲúËðʧ£¬µ«¹«Ë¾Ô¤¼Æ¸ÃÊÂÎñ²»»á¶ÔÆäÒµÎñÔËÓª»ò²ÆÕþÒµ¼¨²úÉú³Á´óÓ°Ïì¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/steelcase-furniture-giant-hit-by-ryuk-ransomware-attack/    


6.Veracode°ä²¼ÀûÓ÷¨Ê½°²È«Ì¬ÊƵķÖÎö»ã±¨


6.jpg


Veracode°ä²¼µÚ11ÆÚÈí¼þ°²È«×´Ì¬»ã±¨£¬¶ÔÀûÓ÷¨Ê½°²È«Ì¬ÊƽøÐÐÁË·ÖÎö¡£»ã±¨¶Ô130000¸öÀûÓ÷¨Ê½½øÐÐÁË·ÖÎö£¬·¢ÏÖ76£¥µÄÀûÓÃÖÁÉÙÓµÓÐÒ»¸ö°²È«·ì϶£¬µ«Ö»ÓÐ24£¥µÄÓ¦Æ÷ÓµÓиßÑϳÁÐÔ·ì϶¡£´Ë±í£¬¸Ã»ã±¨»¹·¢ÏÖÁËһЩ¿ÉÌá¸ß·ì϶½¨¸´ÂʵIJ½Ö裬Èç½áºÏʹÓöàÖÖɨÃèÀàÐÍ£¨Ô̺¬¾²Ì¬·ÖÎö£¨SAST£©£¬¶¯Ì¬·ÖÎö£¨DAST£©ºÍÈí¼þ×é³É·ÖÎö£¨SCA£©£©£¬Í³¼ÆÅú×¢ÄÇЩͬʱʹÓÃSASTºÍDASTµÄÈËÄܹ»24ÌìÄÚ½¨¸´Ò»°ëµÄȱµã¡£


Ô­ÎÄÁ´½Ó£º

https://www.veracode.com/sites/default/files/pdf/sossv11/soss_infographic_v11.pdf