µÂ¹úÁª¹ú¾¯Ô±¾Ö³ÁÖÃEmotet£¬¸Ã¶ñÒâÈí¼þ½«×Ô¶¯Ð¶ÔØ£»»ªÊ¢¶Ù¾¯¾ÖÔâµ½BabukµÄ¹¥»÷£¬250GBδ¼ÓÃܵÄÎļþй¶
°ä²¼¹¦·ò 2021-04-271.µÂ¹úÁª¹ú¾¯Ô±¾Ö³ÁÖÃEmotet£¬¸Ã¶ñÒâÈí¼þ½«×Ô¶¯Ð¶ÔØ

µÂ¹úÁª¹ú¾¯Ô±¾ÖBundeskriminalamt³ÁÖÃÁËEmotet£¬¸Ã¶ñÒâÈí¼þ½«ÔÚËùÓÐÊÜϰȾµÄϵͳÖÐ×Ô¶¯Ð¶ÔØ¡£EmotetÊǽüÆÚ×îΣÏÕµÄÀ¬»øÓʼþ½©Ê¬ÍøÂçÖ®Ò»£¬Æä»ù´¡ÉèÊ©ÓÚ½ñÄê1Ô·ÝÓɶà¹ú·¨Âɲ¿ÃŽáºÏµ·»Ù¡£ÔÚÕâ´ÎÐж¯ÖУ¬µÂ¹ú¾¯·½Õƹܿª·¢ºÍÍÆËÍÐ¶ÔØÄ£¿é£¬ÆäΪÁËÍøÂçÖ¤¾ÝºÍÐÅÏ¢¶øÍƳÙÁ˸ÃÐ¶ÔØÄ£¿éµÄ°ä²¼¡£¸Ã»ú¹¹Í¨¹ýÆä½ÚÔìµÄC2·þÎñÆ÷£¬½«32λEmotetLoader.dll´ó¾ÖµÄÐÂEmotetÄ£¿é·Ö·¢¸øËùÓÐÊÜϰȾµÄϵͳ£¬Ê¹ÕâЩϵͳÔÚ2021Äê4ÔÂ25ÈÕ×Ô¶¯Ð¶ÔظöñÒâÈí¼þ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/emotet-malware-nukes-itself-today-from-all-infected-computers-worldwide/
2.»ªÊ¢¶Ù¾¯¾ÖÔâµ½BabukµÄ¹¥»÷£¬250GBδ¼ÓÃܵÄÎļþй¶

»ªÊ¢¶ÙÌØÇø¾¯Ô±¾ÖMPDÈ·ÈÏÆäÔâµ½ÀÕË÷ÍÅ»ïBabukµÄ¹¥»÷£¬250 GBδ¼ÓÃܵÄÎļþй¶¡£ÀÕË÷ÍŻ﹫¿ªµÄ±»µÁÎļþ¼ÐµÄ½ØÍ¼ÖеŦ·ò´Á¾ùΪ2021.4.19£¬Õâ¿ÉÄÜÏÔʾÁ˹¥»÷ÕßÇÔÈ¡Êý¾ÝµÄ¹¦·ò¡£´Ë±í£¬BabukÍÅ»ï³ö¸ñÖ¸³öÁËÒ»·ÝÎļþ£¬ÆäËÆºõÓë1ÔÂ6ÈÕÏ®»÷¹ú»á´óÏõĿ¹Òé»î¶¯Óйء£MPD³ÆÆäÒѾÓëFBI½áºÏ·¢Õ¹ÁËÈ«ÃæµÄµ÷²é£¬µ«ÊÇĿǰÉÐδ¹«¿ªÓйØÕâ´ÎÊÂÎñµÄ¾ßÌåÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/dc-police-confirms-cyberattack-after-ransomware-gang-leaks-data/
3.×êÑÐÍŶӷ¢ÏÖÀûÓÃFileZenÖеÄ2¸ö·ì϶µÄ¹¥»÷»î¶¯

×êÑÐÍŶӷ¢ÏÖÀûÓÃÎļþ¹²Ïí·þÎñÆ÷Soliton FileZenÖеÄ2¸ö·ì϶ÇÔÈ¡Êý¾ÝµÄ´ó¹æÄ£¹¥»÷»î¶¯¡£Õâ´Î»î¶¯ÖÐÀûÓõķì϶±ðÀëΪĿ¼±éÀú·ì϶£¨CVE-2020-5639£©£¬¿É½«Ìض¨ÎļþÉÏÔØµ½Ìض¨Ä¿Â¼Öжøµ¼ÖÂÖ´ÐÐËÁÒâOSºÅÁÒÔ¼°Ò»¸öËÁÒâOSºÅÁîÖ´Ðзì϶£¨CVE-2021-20655£©¡£ÔÚÆäÖеÄÒ»´Î¹¥»÷ÖУ¬ÈÕ±¾Ê×ÏàÄÚ¸ó°ì¹«ÊÒ(Cabinet Office)¹¤×÷ÈËԱʹÓõÄSolitonÎļþ¹²Ïí´æ´¢Ôâµ½ÁËδ¾ÊÚȨµÄ½Ó¼û¡£SolitonÒѾ¿¯Ðй̼þ°æ±¾V4.2.8ºÍV5.0.3½¨¸´ÁËFileZenÖеÄÁ½¸ö·ì϶¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/117208/hacking/soliton-filezen-file-sharing-servers.html
4.Sophos³Æ´Ë¿ÌÓнüÒ»°ëµÄ¶ñÒâÈí¼þʹÓÃTLSÀ´°µ²ØÍ¨Ñ¶

Sophosͨ¹ý¶ÈÎö·¢ÏÖ£¬½üÆÚÓнüÒ»°ëµÄ¶ñÒâÈí¼þʹÓÃTLSÀ´°µ²ØÍ¨Ñ¶¡£ÔÚ´ÓǰµÄÊ®ÄêÖУ¬HTTPSµÄʹÓÃÂÊ´Ó2014ÄêÕ¼ËùÓÐÍøÒ³½Ó¼ûÁ¿µÄ40£¥ÒÔÉÏÔö³¤µ½2021Äê3ÔµÄ98£¥¡£¶ø¶ñÒâÈí¼þÒ²³öÓÚÒ»ÑùµÄÔÒòѡȡTLS£¬2020Äê¼ì²âµ½23£¥µÄ¶ñÒâÈí¼þʹÓÃTLSÓëÔ¶³Ìϵͳ½øÐÐͨѶ£¬µ½´Ë¿ÌÕâÒ»±ÈÀýÒÑ¿¿½ü46£¥¡£GoogleÔÆ·þÎñÊÇ9£¥µÄ¶ñÒâTLSÒªÇóµÄÖ¸±ê£¬Æä´ÎÊÇÓ¡¶ÈµÄBSNL£¬ËùÓеĶñÒâTLSͨѶÖÐÏÕЩÓÐÒ»°ëÁ÷ÏòÁËÃÀ¹úºÍÓ¡¶ÈµÄ·þÎñÆ÷¡£
ÔÎÄÁ´½Ó£º
https://news.sophos.com/en-us/2021/04/21/nearly-half-of-malware-now-use-tls-to-conceal-communications/
5.Mimecast°ä²¼Óйصç×ÓÓʼþ°²È«Ì¬ÊƵķÖÎö»ã±¨

Mimecast°ä²¼ÁËÓйصç×ÓÓʼþ°²È«Ì¬ÊƵķÖÎö»ã±¨¡£¸Ã»ã±¨»ùÓÚ¶ÔÈ«Çò1225λ¾ö²ßÕߵĵ÷²é£¬ÆäÖÐ79£¥µÄÊÜ·ÃÕß°µÊ¾ÓÉÓÚ²»×㰲ȫ·½ÃæµÄ³ï±¸£¬ËûÃǵĹ«Ë¾ÔÚ2020Äê¾ÀúÁËÒµÎñÖжϡ¢²ÆÕþËðʧ»òÆäËûÎÊÌ⣻61£¥µÄ¹«Ë¾ÔÚ2020ÄêÊܵ½ÀÕË÷Èí¼þµÄÓ°Ï죬±ÈÈ¥ÄêÔö³¤ÁË20£¥£»52£¥µÄÀÕË÷Èí¼þÊܺ¦ÕßÖ§¸¶ÁËÊê½ð£¬µ«ÊÇËûÃÇÖÐÖ»ÓÐ66£¥µÄÈ˸´ÔÁËÊý¾Ý£¬Áí±í34£¥µÄ¹«Ë¾Ö§¸¶ÁËÊê½ðÈ´ÒÀȻûÓеõ½ËûÃǵÄÊý¾Ý¡£
ÔÎÄÁ´½Ó£º
https://www.mimecast.com/state-of-email-security/
6.OpenText°ä²¼2020ÄêµÄÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨

OpenText°ä²¼ÁË2020ÄêµÄÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬½ö´Ó2020Äê1Ôµ½2Ô£¬ÍøÂç´¹µöµÄ¹¥»÷´ÎÊý¾ÍÔö³¤ÁË510£¥£¬¹¥»÷Ö¸±êÖØÒªÊÇÖ¸±êÊÇeBay¡¢Apple¡¢Microsoft¡¢FacebookºÍGoogle¡£ÈÕ±¾µÄPCϰȾÂÊ×îµÍ£¬Îª2.3%£¬Æä´ÎÊÇÓ¢¹ú(2.7%)¡¢´óÑóÖÞ(3.2%)ºÍ±±ÃÀ(3.7%)¡£ÔÚÅ·ÖÞ£¬¼ÒÓÃÉ豸±»Ï°È¾µÄ¿ÉÄÜÐÔ£¨17.4%£©ÊÇÉÌÓÃÉ豸µÄÈý±¶¶à(5.3%)¡£2020ÄêÔÚAndroid?É豸Éϼì²âµ½µÄÌØÂåÒÁľÂíºÍ¶ñÒâÈí¼þÕ¼Íþв×ÜÊýµÄ95.9£¥£¬¸ßÓÚ2019ÄêµÄ92.2£¥¡£
ÔÎÄÁ´½Ó£º
https://mypage.webroot.com/2021-threat-report.html


¾©¹«Íø°²±¸11010802024551ºÅ