Áù¸öÔÂÒÔÀ´Î¢ÈíÈÔ佨¸´Windows10ÖÐÒÑÖª·ì϶£»TrickBot°ä²¼µÚ100¸ö°æ±¾ £¬ÐÂÔöÈÆ¹ý¼ì²âµÄÖ°ÄÜ

°ä²¼¹¦·ò 2020-11-23
1.Áù¸öÔÂÒÔÀ´Î¢ÈíÈÔ佨¸´Windows10ÖÐÒÑÖª·ì϶


1.png


×Ô2020Äê5Ô £¬Microsoft°ä²¼ÁËWindows 10 2004°²È«¸üкó £¬³öÏÖÁËÁ½¸ö·ì϶ £¬µ¼ÖÂSSDÇý¶¯Æ÷µÄ´ÅÅÌË鯬Õû¶Ù¹ýÓÚÆµÈÔ £¬²¢ÔÚ·ÇSSDÇý¶¯Æ÷Éϳ¢ÊÔTRIM²Ù×÷¡£µÚÒ»¸ö·ì϶ʹWin10×Ô¶¯ÊØ»¤Ö°ÄÜÎÞ·¨¼Çס³ÁÆôϵͳʱÇý¶¯Æ÷µÄ×îºóÓÅ»¯¹¦·ò £¬µ¼ÖÂÇý¶¯Æ÷ÔÚÿ´Î³ÁÆôÍÆËã»úʱ¶¼½øÐÐË鯬Õû¶Ù¡£µÚ¶þ¸ö·ì϶µ¼ÖÂWin10µÄÓÅ»¯Çý¶¯Æ÷Ö°ÄÜ»á¶Ô·ÇSSDÇý¶¯Æ÷½øÐÐTRIM £¬Õâ»áµ¼ÖÂÊÂÎñÈÕÖ¾ÖÐÃýÎó¡£Èç½ñ £¬ÔÚ½üÁù¸öÔÂÖ®ºó £¬MicrosoftÈÔ佨¸´¸Ã·ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/windows-10-defrag-trim-bug-still-not-fixed-after-six-months/


2.TrickBot°ä²¼µÚ100¸ö°æ±¾ £¬ÐÂÔöÈÆ¹ý¼ì²âµÄÖ°ÄÜ


2.png


TrickBotÍÅ»ï°ä²¼ÁËÆä¶ñÒâÈí¼þµÄµÚ100¸ö°æ±¾ £¬ÐÂÔöÈÆ¹ý¼ì²âµÄÖ°ÄÜ¡£Intel×êÑÐÈËÔ±·¢ÏÖ £¬¸Ãа汾ÖÐ £¬TrickBotʹÓÃÁËMemoryModuleÖеĴúÂëÖ±½Ó´ÓÄÚ´æÖн«ÆäDLL×¢Èëµ½ºÏ·¨µÄWindows wermgr.exe£¨WindowsÎÊÌâ»ã±¨£©¿ÉÖ´ÐÐÎļþÖС£²¢ÇÒ £¬ÔÚ×¢ÈëDLLʱ £¬Ëü»¹Ê¹ÓÃÁËDoppel Hollowing»ò´¦ÖÃdoppelgangingÒÔÌӱܰ²È«Èí¼þµÄ¼ì²â¡£¿É¼û¸ÃÍŻﲢδÒò»ù´¡ÉèÊ©±»·ÛËé¶øÖÕ³¡ £¬Æä³ÖÐøÔö³¤ÐÂÖ°ÄÜÒÔÈÆ¹ý¼ì²â¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/trickbot-turns-100-latest-malware-released-with-new-features/


3.GoDaddyÔâµ½´¹µö¹¥»÷ £¬Æä6¸öÓòÃû±»½Ù³Ö


3.png


GoDaddyÔâµ½´¹µö¹¥»÷ £¬Æä6¸öÓòÃû±»½Ù³Ö¡£GoDaddyÊÇÈ«Çò×î´óµÄÓòÃû×¢²áÉÌ £¬ÆäÔ±¹¤ÓÚ½ñÄê3ÔÂÔâµ½ÁËÓïÒôÍøÂç´¹µö¹¥»÷ £¬Ê¹¹¥»÷Õß½Ù³ÖÁËÔ̺¬ÂòÂô¾­¼ÍÍøÕ¾escrow.comÔÚÄÚµÄÖÁÉÙÁù¸öÓòÃû¡£Õâ´Î¹¥»÷¿Éʹ¹¥»÷Õß³Á¶¨Ïò¶à¸öƽ̨µÄµç×ÓÓʼþºÍÍøÂçÁ÷Á¿ £¬Íƶ¯ÁË´ÓǰһÖÜÕë¶Ô¶à¸ö¼ÓÃÜÇ®±ÒÂòÂôƽ̨µÄ¹¥»÷¡£Liquid CEO Mike Kayamori³ÆÒòÆäÖ÷ÌâÓòÃûµÄÌṩÉÌGoDaddy½«¶ÔÆäÕÊ»§ºÍÓòµÄ½ÚÔìȨÃýÎóµØ×ªÒƸøÁ˺ڿÍ £¬Ê¹ÆäÄܹ»¸ü¸ÄDNS¼Í¼ £¬²¢»ñµÃ¶ÔÎĵµ´æ´¢µÄ½Ó¼ûȨÏÞ¡£


Ô­ÎÄÁ´½Ó£º

https://krebsonsecurity.com/2020/11/godaddy-employees-used-in-attacks-on-multiple-cryptocurrency-services/


4.·¨¹ú±¨ÉçParis-NormandieϰȾÀÕË÷Èí¼þÖ¹ÙÍøÖжÏ


4.png


·¨¹ú±¨ÉçParis-NormandieÓÚÉÏÖÜÈýÔâµ½ÀÕË÷Èí¼þ¹¥»÷ £¬µ¼Ö¹ÙÍøÖжÏ £¬Ö½ÖʰæÒ²Êܵ½×ÌÈÅ¡£¸Ã±¨ÉçÓÚÖÜËÄÉÏÎç°ä²¼Twitter³Æ £¬´ÓÖܶþÍíÉϵ½ÖÜÈýÍíÉÏ £¬¸Ã¹«Ë¾Ôâµ½ÍøÂç¹¥»÷¡£Õâ´Î¹¥»÷Ó°ÏìÁËÆäËùÓÐÍÆËã»úϵͳ £¬µ¼ÖÂ×ÔÖÜÈýÏÂÎç1µãÆð £¬¸Ã±¨Éç¾ÍÎÞ·¨¸üÐÂÍøÕ¾ £¬¶øÖÜËÄÒ²Ö»¿¯ÐÐÁËÒ»¸öµØÓòÐÔ°æ±¾ £¬²¢·Çͨ³£µÄÈý¸ö°æ±¾¡£¸Ã¹«Ë¾²¢Î´»ØÓ¦ÊÇ·ñΪÀÕË÷Èí¼þ¹¥»÷ £¬µ«Á½Î»ÄäÃû¼ÇÕß֤ʵÓÐÊÕµ½Êê½ðÒªÇó¡£


Ô­ÎÄÁ´½Ó£º

https://www.lemonde.fr/actualite-medias/article/2020/11/19/le-quotidien-paris-normandie-vise-par-une-cyberattaque_6060387_3236.html


5.Drupal°²È«¸üР£¬½¨¸´CVE-2020-13671·ì϶


5.png


DrupalÄÚÈÝÖÎÀíϵͳ£¨CMS£©°ä²¼Á˰²È«¸üР£¬ÒÔ½¨¸´CVE-2020-13671·ì϶¡£DrupalÊÇĿǰ»¥ÁªÍøÉÏʹÓÃÂÊ×î¸ßµÄCMS £¬½ö´ÎÓÚWordPress¡¢ShopifyºÍJoomla¡£¸Ã·ì϶Ϊ´úÂëÖ´Ðзì϶ £¬¹¥»÷ÕßÄܹ»ÔÚ¶ñÒâÎļþÖÐÔö³¤µÚ¶þ¸öÀ©´óÃû £¬Í¨¹ýÊ¢¿ªµÄÉÏ´«×ֶν«ÆäÉÏ´«µ½DrupalÕ¾µã¡£ÓÉÓÚWindowsĬÈÏÇé¿öÏ»ᰵ²Ø×îºóÒ»¸öÎļþÀ©´óÃû £¬Òò¶øÐÂÔöµÄEXEÀ©´óÃû»á±»°µ²Ø £¬¶ø½öÏÔʾµÚÒ»¸öÎļþÀ©´óÃû¡£´Ó¶øÊ¹Óû§ÎóÒÔΪËûÃÇÔÚ´ò¿ªÎļþ £¬µ«ÏÖʵÉÏÊÇÔÚÔËÐжñÒⷨʽ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/drupal-sites-vulnerable-to-double-extension-attacks/


6.FireEye Mandiant°ä²¼2021ÄêÍøÂ簲ȫԶ¾°·ÖÎö»ã±¨


6.png


FireEye Mandiant°ä²¼ÁË2021ÄêÍøÂ簲ȫԶ¾°·ÖÎö»ã±¨ £¬Ì½ÇóÁËÓйØÔ¶³Ì¹¤×÷ºÍÈ«Çò´óÊ¢ÐеÄÓ°Ïì¡¢ÀÕË÷Èí¼þ¡¢Ãñ×å¹ú¶È»î¶¯¡¢Ôư²È«ºÍ°²È«ÑéÖ¤ÓйصÄÖ÷Ìâ¡£»ã±¨Ö¸³ö £¬ÀÕË÷Èí¼þ½«³ÖÐø·¢Õ¹ºÍÀ©´ó £¬ÆäÖð²½ÓÐÁËÕæÕýµÄÕ½Êõ £¬ÓÉ·ÖÆçµÄºÚ¿Í½áºÏÔÚһ·ʹ¹¥»÷¹ý³ÌÔ½·¢×¨Òµ»¯¡£²¿ÃųÉÔ±¿ª·¢ÀÕË÷Èí¼þ £¬²¿ÃųÉԱרÃÅ»ñµÃ³õʼ½Ó¼ûȨÏ޺͹¥»÷ºóµÄÒç³ö £¬ÒÔ¼°ÈÕÒæÔö³¤µÄË«³ÁÀÕË÷»î¶¯ £¬¶¼½«µ¼ÖÂÀÕË÷¹¥»÷µÄÔö³¤¡£


Ô­ÎÄÁ´½Ó£º

https://content.fireeye.com/predictions/rpt-security-predictions-2021