±Ê¼Ç±¾Ôì×÷ÉÌÈʱ¦Ï°È¾DoppelPaymer£¬±»ÀÕË÷1700ÍòÃÀÔª£»Î¢Èí°ä²¼Öܶþ°²È«¸üУ¬×ܼƽ¨¸´112¸ö·ì϶

°ä²¼¹¦·ò 2020-11-11
1.±Ê¼Ç±¾Ôì×÷ÉÌÈʱ¦Ï°È¾DoppelPaymer£¬±»ÀÕË÷1700ÍòÃÀÔª


1.jpg


±Ê¼Ç±¾Ôì×÷ÉÌÈʱ¦Ôâµ½DoppelPaymerÀÕË÷Èí¼þ¹¥»÷£¬±»ÀÕË÷1700ÍòÃÀÔª¡£Èʱ¦£¨Compal£©ÊÇÈ«ÇòµÚ¶þ´óÔ­´´Éè¼Æ(ODM)±Ê¼Ç±¾µçÄÔÔì×÷ÉÌ£¬ÓëÆ»¹û¡¢»ÝÆÕ¡¢´÷¶û¡¢åÚÏëºÍºê³žµÈ³ÛÃû¹«Ë¾ºÏ×÷¡£¸Ã¹«Ë¾°µÊ¾ÆäÖ»Êǰ칫×Ô¶¯»¯ÏµÍ³³öÏÖÒì³££¬²¢Î´Ïñ±í½çËù±¨Â·µÄÄÇÑù±»ºÚ¿ÍÀÕË÷£¬Ä¿Ç°³ö²úÖÐËùÓÐÕý³£¡£µ«¾ÝÐÂÎÅÍøÕ¾BleepingComputer³ÆÆäÒÑ»ñµÃÊê½ð¼Í¼£¬ÆäÖкڿÍÍÅ»ïÒªÇóÖ§¸¶1100±ÈÌØ±Ò£¨16725500ÃÀÔª£©¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/laptop-maker-compal-hit-by-ransomware-17-million-demanded/


2.΢Èí°ä²¼Öܶþ°²È«¸üУ¬×ܼƽ¨¸´112¸ö·ì϶


2.jpg


΢Èí°ä²¼11ÔµÄÖܶþ°²È«¸üУ¬×ܼƽ¨¸´112¸ö·ì϶¡£Õâ´Î½¨¸´µÄ½ÏΪÑϳÁµÄ·ì϶Ô̺¬WindowsÄÚºËÃÜÂëÇý¶¯·¨Ê½£¨cng.sys£©ÖеÄÌáȨ0day£¨CVE-2020-17087£©¡¢Azure SphereÌØÈ¨ÌáÉý·ì϶£¨CVE-2020-16988£©¡¢Microsoftä¯ÀÀÆ÷ÄÚ´æ°Ü»µ·ì϶£¨CVE-2020-17058£©¡¢Chakra¾ç±¾ÒýÇæÄÚ´æ°Ü»µ·ì϶£¨CVE-2020-17048£©¡¢Internet ExplorerÄÚ´æ°Ü»µ·ì϶£¨CVE-2020-17053£©ºÍWindows Print SpoolerÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2020-17042£©µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-november-2020-patch-tuesday-fixes-112-vulnerabilities/


3.еÄÒøÐÐľÂíGhimob¿É¼à¿Ø153¸öAndroidÀûÓÃ


3.jpg


°²È«¹«Ë¾kaspersky·¢ÏÖеÄÒøÐÐľÂíGhimob¿É¼à¿Ø153¸öAndroidÀûÓá£Ghimob²¢Î´Í¨¹ý¹Ù·½PlayÉ̵꿯ÐУ¬¶øÊÇʹÓõç×ÓÓʼþ»ò¶ñÒâÍøÕ¾½«Óû§³Á¶¨Ïòµ½ÆäËûAndroidÀûÓõÄÐû´«ÍøÕ¾£¬ÕâЩÀûÓüÙÒâÁ˹ٷ½ÀûÓ÷¨Ê½£¬´øÓÐGoogle Defender¡¢Google DocsµÈ×ÖÑù¡£Ò»µ©Óû§³É¹¦×°Ö㬸öñÒâÀûÓý«ÒªÇó½Ó¼ûAccessibility·þÎñ¡£ÔÊÐíÒªÇóºóÆä»áÔÚÓû§ÊÖ»úÖÐËÑË÷153¸öÀûÓ㬲¢ÏÔʾαÔìµÄµÄµÇÂ¼Ò³Ãæ£¬ÒÔÇÔÈ¡Óû§µÄÍ´´¦¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/new-ghimob-malware-can-spy-on-153-android-mobile-applications/


4.×êÑÐÈËÔ±Åû¼ûÀ¹ú¹ú·À²¿ÄÚÍø¿É½Ù³ÖDODÕ˺ŵķì϶


4.jpg


°²È«¹«Ë¾Silent BreachµÄ×êÑÐÔ±Jeff SteinburgÅû¼ûÀ¹ú¹ú·À²¿ÄÚÍø¿É½Ù³ÖDODÕ˺ŵķì϶¡£½öͨ¹ýÅú¸Ä·¢Ë͵½DOD·þÎñÆ÷µÄWebÒªÇóÖеÄһЩ²ÎÊý±ãÄܹ»ÀûÓø÷ì϶£¬À´½Ù³ÖDODÕÊ»§¡£ÓÉÓÚÖ»Ðè×îµÍµÄ¼¼Êõˮƽ¾ÍÄÜÀûÓúͽٳÖËÁÒâ¹ú·À²¿ÕʺÅ£¬Òò¶øÆäÑϳÁˮƽ±»ÆÀΪÑϳÁ(9 ~ 10)¡£Ä¿Ç°ÃÀ¹ú¹ú·À²¿ÒѾ­½¨¸´Á˸÷ì϶¡£¶øSteinburgÒ²»ñµÃÁËDODµÄÔ¶È×êÑÐÈËÔ±½±¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/bug-hunter-wins-researcher-of-the-month-award-for-dod-account-takeover-bug/


5.ºÚ¿ÍÀûÓÃαÔìµÄTeams¸üзַ¢Cobalt Strike


5.jpg


ºÚ¿ÍÀûÓÃαÔìµÄTeams¸üзַ¢Cobalt Strike£¬ÖØÒªÕë¶Ô½ÌÓý²¿ÃÅ¡£¹¥»÷ÕßÀûÓÃZeroLogon£¨CVE-2020-1472£©·ì϶»ñÈ¡ÖÎÀíÔ±½Ó¼ûȨÏÞ£¬¶øºóͨ¹ýËÑË÷ÒýÇæÁ˾ֻòÔÚÏß¶ñÒâ¸æ°×£¬Ö²ÈëÐéα¸æ°×À´ÓÕʹÓû§×°ÖøüС£Ö®ºó¹¥»÷Õß½«×°ÖÃCobalt Strike£¬ÒÔЭÖúÆäÔÚÊܺ¦ÕßÍøÂçÖÐÔÚÍøÂçÖкáÏòÒÆ¶¯¡£´Ë±í£¬¸Ã¹¥»÷»¹»á×°ÖÃMicrosoft TeamsµÄºÏ·¨¸±±¾£¬ÒÔÔ¤·ÀÊܺ¦Õß¾õ²ìµ½Õâ´Î¹¥»÷¡£

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fake-microsoft-teams-updates-lead-to-cobalt-strike-deployment/


6.kaspersky°ä²¼2020ÄêÀÕË÷Èí¼þµÄÌ¬ÊÆ·ÖÎö»ã±¨


6.jpg


kaspersky°ä²¼2020ÄêÀÕË÷Èí¼þµÄÌ¬ÊÆ·ÖÎö»ã±¨¡£»ã±¨Ö¸³öƾ¾ÝÉϰëÄê²úÉúµÄ¼¸ÆðÊÂÎñ£¬Åú×¢ÀÕË÷Èí¼þµÄ¹æÄ£ÔÚ²»ÐÝÀ©´ó¡£2Ô·ݵ¤Âó¹«Ë¾ISSµÄÊýÊ®ÍòÃûÔ±¹¤ÒòÀÕË÷Èí¼þ¹¥»÷Ó빫˾·þÎñ¶Ï¿ª£¬Ôì³É7500Íò- 1.14ÒÚÃÀÔªËðʧ£»IT¹«Ë¾CognizantÒò¸ÃÀ๥»÷µ¼ÖÂ5000Íò-7000ÍòÃÀÔªËðʧ¡£¸Ã»ã±¨Ö¸³ö±ØÒªÍ¨¹ýÀ¬»øÓʼþ¹ýÂËÆ÷£¬¶¨ÆÚ¸üÐÂËùÓйؼüÒµÎñÐÅÏ¢µÄ±¸·Ý£¬½«±¸·Ý´æ´¢ÔÚ°²È«µÄÔÆÖеȷ½Ê½À´Ô¤·À´ËÀ๥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.kaspersky.com/blog/ransomware-incidents-2020/37589/