ÃÀ¹ú²ÆÕþ²¿µÈ²¿ÃÅÔâµ½ÓëFireEyeÒ»ÑùµÄ¹©¸øÁ´¹¥»÷£»GoogleÈ«Çò·þÎñÖжÏ£¬YouTubeºÍGmailµÅצÓÃÊÜÓ°Ïì

°ä²¼¹¦·ò 2020-12-15

1.ÃÀ¹ú²ÆÕþ²¿µÈ²¿ÃÅÔâµ½ÓëFireEyeÒ»ÑùµÄ¹©¸øÁ´¹¥»÷


1.jpg


ÃÀ¹ú²ÆÕþ²¿ºÍÉÌÎñ²¿¹ú¶ÈµçÐÅÓëÐÅÏ¢ÖÎÀí¾Ö£¨NTIA£©Ôâµ½ÓëFireEyeÒ»ÑùµÄ¹©¸øÁ´¹¥»÷¡£°²È«¹«Ë¾FireEye½ñÌ찵ʾ£¬µ±¾ÖÖ§³ÖµÄºÚ¿Í¹¥»÷ÁËÈí¼þÌṩÉÌSolarWinds£¬¶øºóΪÆäOrionÈí¼þ²¿ÊðÁ˶ñÒâ¸üз¨Ê½£¬ÒÔϰȾ¶à¸öÃÀ¹ú¹«Ë¾ºÍµ±¾ÖÍøÂ磬FireEye֮ǰҲÔâµ½ÁËÐÎͬµÄ¹¥»÷¡£SolarWindsÈ·ÈÏÆäÔÚ2020Äê3ÔÂÖÁ6ÔÂÖ®¼ä°ä²¼µÄOrion¸üа汾2019.4ÖÁ2020.2.1Òѱ»¶ñÒâÈí¼þϰȾ¡£¾ÝÐÅ£¬Õâ´Î¹¥»÷»î¶¯Óë¶íÂÞ˹±í¹úµý±¨¾Ö£¨SVR£©ÓйصĺڿÍ×éÖ¯APT29ÓйØ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/microsoft-fireeye-confirm-solarwinds-supply-chain-attack/


2.GoogleÈ«Çò·þÎñÖжÏ£¬YouTubeºÍGmailµÅצÓÃÊÜÓ°Ïì


2.jpg


GoogleÈ«Çò·þÎñÖжÏ£¬Óû§ÎÞ·¨½Ó¼ûGmail¡¢YouTube¡¢GoogleÔÆ¶ËÓ²ÅÌ¡¢GoogleµØÍ¼ºÍGoogleÈÕÀúµÈGoogle·þÎñ¡£Æ¾¾ÝDownDetectorͳ¼Æ£¬Õâ´ÎÖжÏÖØÒª²úÉúÔÚÃÀ¹úºÍÅ·Ö޵ȵØÓò¡£Óû§ÔÚ³¢ÊÔ½Ó¼ûYouTubeʱ»á¿´µ½¼ÓÔØÆÁÄ»ºÍ¡°·þÎñÆ÷´æÔÚÎÊÌ⣨503£©-µã»÷ÒÔ³ÁÊÔ¡±µÄÃýÎóÐÂÎÅ£¬Ò²ÎÞ·¨Ê¹ÓÃAndroidºÍiOSµÄGmail·¢ËÍ»ò½Ó¼ûµç×ÓÓʼþ¡£GoogleËæºó½â¾öÁ˸ÃÎÊÌ⣬²¢³ÆÓÉÓÚÄÚ²¿´æ´¢Åä¶îÎÊÌ⣬µ¼ÖÂGoogleÉí·ÝÑé֤ϵͳÖжÏÁËԼĪ45·ÖÖÓ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/google/google-outage-affecting-youtube-gmail-and-more/


3.CheckPointÅû¶SteamÖдæÔÚ¶à¸ö¿ÉÊÕÊÜÍÆËã»úµÄ·ì϶


3.jpg


CheckPointµÄ×êÑÐÈËÔ±Eyal ItkinÅû¶SteamÖдæÔÚ¶à¸ö·ì϶£¬¿É±»ÓÃÀ´ÈëÇÖ²¢Ô¶³Ì½ÚÔìÊýÊ®ÍòÌ¨ÍÆËã»ú¡£Itkin³ÆÕâЩ·ì϶¶¼´æÔÚÓÚʵÏÖÓÎÏ·ÍøÂçÌ×½Ó×Ö£¨GNS£©¿âµÄ¹ý³ÌÖУ¬±ðÀëΪ¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐеÄÄÚ´æ°Ü»µ·ì϶£¨CVE-2020-6016¡¢CVE-2020-6017ºÍCVE-2020-6018£©£¬ÒÔ¼°ÎÞ·¨ÕýÈ·´¦Öú¯Êýµ¼ÖµÄlibprotobufÒì³£ºÍ±ÀÀ££¨CVE-2020-6019£©¡£¹¥»÷Õß¿ÉÀûÓÃÕâЩ·ì϶Զ³ÌÇÔÈ¡Êܺ¦ÕߵĵǼƾ֤µÈÓ×ÎÒÊý¾Ý¡¢·ÛËéValveÓÎÏ··þÎñÆ÷¡¢·ÛËéµÐÊÖµÄÓÎÏ·¿Í»§¶ËÒÔ¼°¶ÔµÚÈý·½ÓÎÏ··þÎñÆ÷Ö´ÐÐËÁÒâ´úÂë¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/steam-vulnerabilities-remote-take-over-users-computers/


4.APT×éÖ¯MoleRatsÀûÓÃFacebookºÍDropbox½øÐмäµý»î¶¯


4.jpg


Cybereason×êÑÐÈËÔ±·¢ÏÖAPT×éÖ¯MoleRats¿ª·¢ÁËÁ½¸öеÄSharpStageºóÃźÍDropBookºóÃÅ£¬ÀûÓÃFacebookºÍDropbox½øÐмäµý»î¶¯¡£MoleRatsÊǼÓɳµÄºÚ¿Í×éÖ¯£¬×îÐµĹ¥»÷»î¶¯ÖØÒªÕë¶Ô°£¼°¡¢°ÍÀÕ˹̹ÁìÍÁ¡¢ÍÁ¶úÆäºÍ°¢ÁªÇõµÄ¸ß¼¶ÕþÖÎÈËÎïºÍµ±¾Ö¹ÙÔ±¡£×êÑÐÈËÔ±·ÖÎö·¢ÏÖ£¬DropBookºóÃÅʹÓÃÁËαÔìµÄFacebookÕÊ»§ºÍSimplenote×÷ΪC2£¬²¢ÇÒÕâÁ½¸öºóÃŶ¼Ê¹ÓÃÁËDropbox¿Í»§¶ËÀ´ÇÔÈ¡±»µÁÊý¾Ý²¢´æ´¢Æä¼äµý¹¤¾ß¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/molerats-apt-espionage-facebook-dropbox/162162/


5.kaspersky°ä²¼ÓйØÚ²Æ­Ô¤·ÀµÄ·ÖÎö»ã±¨


5.jpg


kaspersky°ä²¼ÓйØÚ²Æ­Ô¤·ÀµÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬µ½2020Ä꣬¹¥»÷Õß×ʹÓÃÊÜϰȾÕÊ»§£¨ÔÚ36£¥£©»òͨ¹ýÓöñÒâÈí¼þϰȾÉ豸£¨31£¥£©À´½øÐÐδ¾­ÊÚȨµÄ»ã¿î¡£ÔÚ2019Ä꣬¶ñÒâÈí¼þ¹¥»÷ÊýÁ¿×î¶à£¬Îª¼Í¼µÄ×ÜÊýµÄ63£¥£¬¶ø½ñÄ꣬ÓëÏ´Ç®ÓйصݸÀýÕ¼±ÈÀýÔö³¤ÁËËı¶£¬´ïµ½12£¥¡£ºÚ¿ÍʹÓø´ÔӵĶà½×¶ÎÏ´Ç®¹æ»®£¬ËûÃÇÂŴθü¸ÄÕË»§¡¢¹«Ë¾¡¢±¨±í¡¢Ç®±ÒºÍ˾·¨¹ÜϽȨ¡£Îª´Ë£¬½ðÈÚ»ú¹¹±ØÒª¹¹½¨ÍøÂç°²Õû¸öϵ£¬½«ºÚ¿Í¹¥»÷µÄ¿ÉÄÜÐÔ½µµ½×îµÍ£¬²¢ÊµÊ±¼à¿ØÈκη¸·¨ÐÐΪ¡£


Ô­ÎÄÁ´½Ó£º

https://media.kaspersky.com/en/business-security/enterprise/Kaspersky-fraud-prevention-automated-analytics-en.pdf


6.WatchGuard°ä²¼2020ÄêQ3»¥ÁªÍø°²È«µÄ·ÖÎö»ã±¨


6.jpg


WatchGuard°ä²¼2020ÄêQ3»¥ÁªÍø°²È«µÄ·ÖÎö»ã±¨¡£¸Ã»ã±¨²ûÁËÈ»COVID-19ÍþвÇ÷Ïò¡¢²»ÐÝÔö³¤µÄÍøÂç¹¥»÷ÒÔ¼°Õë¶ÔÃÀ¹úSCADAϵͳµÄ¶ñÒâÈí¼þµÈ¡£»ã±¨Ö¸³ö£¬ÍøÂç¹¥»÷ºÍ¹ÖÒì¼ì²â¾ù´ïµ½Á½ÄêÀ´µÄ×î¸ßˮƽ£¬µÚÈý¼¾¶ÈÍøÂç¹¥»÷ÊýÁ¿¼¤ÔöÖÁ330ÍòÒÔÉÏ£¬±ÈÉÏÒ»¼¾¶ÈÔö³¤90£¥£¬¹ÖÒìµÄÍøÂç¹¥»÷ÌØµãÒ²³ÖÐøÉÏÉý¡£´Ë±í£¬COVID-19Ú¿Æ­·è¿ñ£¬ÆóÒµµã»÷ÁË´óÁ¿µÄ´¹µö¹¥»÷ºÍ¶ñÒâÁ´½Ó£¬WatchGuardµÄDNSWatch·þÎñ×ܹ²×èÖ¹ÁË2764736¸ö¶ñÒâÓòÃûÏνÓ¡£


Ô­ÎÄÁ´½Ó£º

https://www.globenewswire.com/news-release/2020/12/09/2141868/0/en/WatchGuard-Report-Details-COVID-19-Impact-on-Security-Threat-Landscape.html