°®¶ûÀ¼Ò½ÁÆ»ú¹¹HSEϰȾConti£¬±»ÀÕË÷½ü2000ÍòÃÀÔª£»DarkSideÀÕË÷Èí¼þ·þÎñÆ÷±»²é·â²¢°ä·¢½«ÖÕÖ¹ÔËÓª

°ä²¼¹¦·ò 2021-05-17

1.°®¶ûÀ¼Ò½ÁÆ»ú¹¹HSEϰȾConti£¬±»ÀÕË÷½ü2000ÍòÃÀÔª


1.jpg


°®¶ûÀ¼µÄÒ½ÁÆ·þÎñ»ú¹¹HSE°µÊ¾£¬ÆäÔâµ½ÁËContiÀÕË÷Èí¼þ¹¥»÷£¬²¢±»ÒªÇóÖ§¸¶19999000ÃÀÔªµÄÊê½ð¡£¸Ã»ú¹¹ÔÚ·¢ÏÖ¹¥»÷ºó£¬ÒÑÓÚÉÏÖÜÎ幨¹ØÁËËùÓÐITϵͳ¡£ContiÍÅ»ïÐû³ÆÒѾ­½øÈëHSEµÄÍøÂçÁ½ÖÜÁË£¬ÔÚ´ËÆÚ¼ä£¬ËûÃÇÇÔÈ¡ÁËHSE 700 GBµÄδ¼ÓÃÜÎļþ£¬Ô̺¬»¼ÕßÐÅÏ¢ºÍÔ±¹¤ÐÅÏ¢¡¢ºÏͬ¡¢²ÆÕþ±¨±íºÍ¹¤×ʵ¥µÈ¡£°®¶ûÀ¼×ÜÀíTaoiseach Miche¨¢l MartinÓÚ5ÔÂ14ÈÕÔÚÐÂÎŰ䲼»áÉϰµÊ¾£¬ËûÃǽ«²»Ö§¸¶ÈκÎÊê½ð¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ireland-s-health-services-hit-with-20-million-ransomware-demand/


2.Herff Jones¿Í»§ÐÅÓþ¿¨±»µÁË¢£¬Éæ¼°ÃÀ¹ú´óѧ±ÏÒµÉú


2.jpg


ñ×ӺͺÅÒÂÔì×÷ÉÌHerff Jonesй¶¿Í»§µÄÐÅÓþ¿¨ÐÅÏ¢£¬Ó°ÏìÁËÃÀ¹úÎÞÊý´óѧ±ÏÒµÉú¡£ÔÚÉÏÖÜÈÕ£¬ÃÀ¹ú¼¸Ëù´óѧµÄ±ÏÒµÉú°µÊ¾£¬ËûÃÇÔÚHerff JonesʹÓÃÐÅÓþ¿¨²É°ì±ÏÒµµäºÅÒÂ×°ºó²úÉúÁ˵ÁË¢ÂòÂô¡£´óÎÞÊýÊܺ¦ÕßµÄËðʧÔÚ80µ½1200ÃÀÔªÖ®¼ä£¬Ò²ÓÐÈËËðʧ¸ß´ï4000ÃÀÔª¡£Ö±µ½ÕâЩѧÉúÔÚÉ罻ýÌåÉϱ§Ô¹Õâ´ÎµÄµÁË¢ÊÂÎñ£¬Herff Jones²ÅµÃÖªÁËÐÅÓþ¿¨Ð¹Â¶ÎÊÌ⣬ĿǰÉв»Ã÷ÏÔй¶ÆðÍ·µÄ¹¦·ò£¬µ«×îÔçµÄÂòÂôÈÕÆÚÊÇ´Ó±¾Ô³õÆðÍ·¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/herff-jones-credit-card-breach-impacts-college-students-across-the-us/


3.ºÚ¿ÍÍÅ»ïFIN7ÔÚ×î½üµÄ¹¥»÷ÖÐʹÓÃеÄLizarºóÃÅ


3.jpg


BI.ZONEÍøÂçÍþв×êÑÐÍŶӷ¢ÏÖ£¬ºÚ¿ÍÍÅ»ïFIN7ÔÚ×î½üµÄ¹¥»÷ÖÐʹÓÃеÄLizarºóÃÅ¡£×Ô2015ÄêÖÐÒÔÀ´£¬¶íÂÞ˹ºÚ¿ÍÍÅ»ïFIN7¾Í¶Ô×¼ÁËÃÀ¹úµÄÁãÊÛ¡¢²ÍÒûºÍ¾ÆµêÐÐÒµ¡£ÔÚÕâ´Î¹¥»÷ÖУ¬FIN7¼Ù×°³ÉÏúÊÛ°²È«·ÖÎöƽ̨µÄºÏ·¨¹«Ë¾£¬²¢ÇÒ×Ô½ñÄê2Ô·ÝÒÔÀ´Ò»ÏòʹÓÃеÄLizarºóÃÅ¡£¸Ã¶ñÒâÈí¼þÊÇʹÓÃ.NET¿ò¼Ü±àдµÄ£¬ÔÚÔ¶³ÌLinuxÖ÷»úÉÏÔËÐУ¬Ö§³ÖÓëBot¿Í»§¶ËµÄ¼ÓÃÜͨѶ£¬ÓµÓÐ׳´óµÄÊý¾Ý¼ìË÷ºÍºáÏòÒÆ¶¯Ö°ÄÜ¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2021/05/fin7-is-spreading-backdoor-called-lizar.html


4.DarkSideÀÕË÷Èí¼þ·þÎñÆ÷±»²é·â²¢°ä·¢½«ÖÕÖ¹ÔËÓª


4.jpg


DarkSideÊÇÒ»¸öÀÕË÷Èí¼þ·þÎñÆ÷ÍŻRaaS£©£¬Ò»ÖÜǰ¹¥»÷ÁËColonial Pipeline Co.²¢ÀÕË÷500ÍòÃÀÔª¡£¸ÃÍÅ»ïÓÚ2021Äê5ÔÂ13ÈÕ°ä²¼ÉêÃ÷³Æ£¬ÓÉÓÚ·¨ÂÉÐж¯£¬ËûÃÇĿǰÒѾ­ÎÞ·¨Í¨¹ýSSH½Ó¼ûÆä¹«¹²Êý¾ÝÐ¹Â¶ÍøÕ¾¡¢Ö§¸¶·þÎñÆ÷ºÍCDN·þÎñÆ÷£¬ÒÔ¼°Ö÷»ú½çÃæ¡£Òò¶ø½«ÎªËùÓÐÉÐδ¸¶¿îµÄ¹«Ë¾Ìṩ½âÃܹ¤¾ß£¬²¢³ÐŵÔÚ2021Äê5ÔÂ23ÈÕ֮ǰ³¥»¹ËùÓÐδ³¥Õ®Îñ¡£¸ÃÉêÃ÷»¹Ö¸³öÓÉÓÚÀ´×ÔÃÀ¹úµÄѹÁ¦£¬Æä½«ÖÕÖ¹ÀÕË÷»î¶¯¡£


Ô­ÎÄÁ´½Ó£º

https://www.intel471.com/blog/darkside-ransomware-shut-down-revil-avaddon-cybercrime


5.ExtraHop³Æ67£¥µÄ¹«Ë¾ÈÔÒ×Ôâµ½WannaCryµÄ¹¥»÷


5.jpg


Ô­ÉúÔÆÍøÂç¼ì²âºÍÏìÓ¦¹«Ë¾ExtraHop³Æ67£¥µÄ¹«Ë¾ÈÔÔÚÔËÐв»°²È«µÄWindowsºÍ̸SMBv1£¬Ò×Ôâµ½WannaCryºÍNotPetyaµÄ¹¥»÷¡£´Ë±í£¬×êÑл¹·¢ÏÖ70£¥µÄ»·¾³ÈÔÔÚÔËÐÐLLMNR£¬¸ÃºÍ̸¿É±»ÓÃÀ´½Ó¼ûÓû§Í´´¦µÄ¹þÏ££»34£¥µÄÆóҵʹÓÃÔËÐÐÁËNTLMv1µÄ¿Í»§¶Ë£¬µ«Microsoft½¨Òé×é֯ʹÓÃÔ½·¢°²È«µÄKerberosÉí·ÝÑéÖ¤ºÍ̸£»81£¥µÄÆóҵʹÓò»°²È«µÄHTTP´«Êä´¿Îı¾Í´´¦¡£


Ô­ÎÄÁ´½Ó£º

https://www.extrahop.com/company/press-releases/2021/insecure-protocols/


6.Verizon°ä²¼2021ÄêÊý¾ÝÎ¥¹æµ÷²é·ÖÎö»ã±¨£¨DBIR£©


6.jpg


Verizon°ä²¼ÁË2021ÄêÊý¾ÝÎ¥¹æµ÷²é·ÖÎö»ã±¨£¨DBIR£©¡£¸Ã»ã±¨¹²·ÖÎöÁË29207ÆðÊÂÎñ£¬ÆäÖÐ5258Æð±»È·ÒÔΪÊý¾ÝÎ¥¹æÊÂÎñ¡£»ã±¨Ö¸³ö£¬ÍøÂç´¹µö¹¥»÷Ôö³¤ÁË11£¥£¬ÀÕË÷Èí¼þ¹¥»÷Ôö³¤ÁË6£¥£¬±ÈÈ¥ÄêÔö³¤ÁË15±¶£»85£¥µÄй¶ÊÂÎñÉæ¼°±¨´ð³É·Ö£¬¶ø³¬¹ý80£¥µÄй¶ÊÂÎñÊÇÓÉ±í²¿¸÷·½·¢Ïֵģ»Ò»´Îй¶ÊÂÎñµÄ¾ùÔÈËðʧΪ21659ÃÀÔª£¬ÆäÖÐ95£¥µÄÊÂÎñµÄËðʧ½éÓÚ826ÃÀÔªÖÁ653587ÃÀÔªÖ®¼ä¡£


Ô­ÎÄÁ´½Ó£º

https://www.verizon.com/business/resources/reports/dbir/2021/masters-guide/