°²È«¹«Ë¾CognyteÊý¾Ý¿âÅäÖÃÃýÎóй¶³¬¹ý50Òڱʼͼ£»ÄÜÔ´¹«Ë¾InvenergyÔâµ½REvilÀÕË÷¹¥»÷й¶4TBÊý¾Ý

°ä²¼¹¦·ò 2021-06-16

1.°²È«¹«Ë¾CognyteÊý¾Ý¿âÅäÖÃÃýÎóй¶³¬¹ý50Òڱʼͼ


1.jpg


Comparitech°²È«×êÑÐÈËÔ±·¢ÏÖÁËÍøÂ簲ȫ·ÖÎö¹«Ë¾CognyteδÊܱ£»¤µÄÊý¾Ý¿â¡£¸ÃÊý¾Ý¿â×÷ΪCognyteÍøÂçµý±¨·þÎñµÄÒ»²¿ÃÅ £¬ÓÃÓÚÌáÐÑÆä¿Í»§µÚÈý·½µÄÊý¾Ýй¶¡£ÓµÓг°·íÒâζµÄÊÇ £¬ÓÃÓÚ½»²æ²é³­Ð¹Â¶µÄÓ×ÎÒÐÅÏ¢µÄÊý¾Ý¿â×ÔÉíÒÑй¶¡£¸ÃÊý¾Ý¿â×ܹ²ÓÐ5085132102±Ê¼Í¼ £¬Ô̺¬Ãû³Æ¡¢µç×ÓÓʼþµØÖ·¡¢ÃÜÂëºÍÊý¾ÝÔ´ £¬ÓÚ2021Äê5ÔÂ29ÈÕ±»·¢ÏÖ £¬ºóÓÚ6ÔÂ2ÈÕ±»±£»¤ÆðÀ´¡£Ä¿Ç° £¬Éв»È·¶¨ÕâЩÊý¾ÝÔÚ¶³öÆÚ¼äÊÇ·ñÓб»ÈκεÚÈý·½½Ó¼û¡£


Ô­ÎÄÁ´½Ó£º

https://www.comparitech.com/blog/information-security/breach-database-leak/


2.ÀÕË÷Èí¼þParadiseµÄÔ´´úÂëÔÚºÚ¿ÍÂÛ̳XSSÉϹ«¿ª


2.jpg


Paradise RansomwareµÄ.NET°æ±¾ÆëȫԴ´úÂëÒÑÔÚºÚ¿ÍÂÛ̳XSSÉϹ«¿ª £¬ÍøÂç·¸×ï·Ö×ÓÄܹ»ÓÃÆä¿ª·¢×Ô¼º¶¨ÔìµÄÀÕË÷Èí¼þ¡£ParadiseÓÚ2017Äê9Ô³õ´Î±»·¢ÏÖ £¬ÌṩӵÓÐÀÕË÷Èí¼þ¼´·þÎñ (RaaS) Ä£Ð͵ĶñÒâÈí¼þ¡£Ö®ºó £¬°²È«¹«Ë¾EmsisoftºÍBitdefender±ðÀëÓÚ2019Äê10ÔºÍ2020Äê1Ô°䲼ÁËÁ½¸ö½âÃÜÆ÷¡£×êÑÐÈËÔ±±àÒëÔ´´úÂëºó·¢ÏÖËü´´½¨ÁËÈý¸ö¿ÉÖ´ÐÐÎļþ£ºÀÕË÷Èí¼þÅäÖù¹½¨Æ÷¡¢¼ÓÃÜÆ÷ºÍ½âÃÜÆ÷¡£´Ë±í £¬Ô´´úÂëÖеĶíÓï×¢½âÃ÷ÏÔµØÕ¹Ê¾ÁË¿ª·¢ÈËÔ±µÄĸÓï¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/paradise-ransomware-source-code-released-on-a-hacking-forum/


3.Apple´¹Î£¸üР£¬½¨¸´iOSÖÐÒѱ»ÔÚÒ°ÀûÓõÄ2¸ö0day


3.jpg


Apple°ä²¼´¹Î£¸üР£¬½¨¸´iOS 12.5.3ÖÐÒѱ»ÔÚÒ°ÀûÓõÄ2¸ö0day¡£ÕâÁ½¸ö0dayΪWebKitä¯ÀÀÆ÷ÒýÇæÖеÄÄÚ´æ°Ü»µ·ì϶£¨CVE-2021-30761£©ºÍ¿ªÊͺóʹÓ÷ì϶£¨CVE-2021-30762£© £¬¾ù¿É±»ÓÃÀ´Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£Apple°µÊ¾¸Ã·ì϶¿ÉÄÜÒѱ»»ý¼«ÀûÓà £¬µ«²¢Î´Ð¹Â©ÈκÎÓйشËÀ๥»÷µÄ¾ßÌåÐÅÏ¢¡£´Ë±í £¬Õâ´Î¸üл¹½¨¸´ÁËASN.1½âÂëÆ÷ÖеÄÄÚ´æ°Ü»µ·ì϶(CVE-2021-30737)¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/06/apple-issues-urgent-patches-for-2-zero.html


4.ÄÜÔ´¹«Ë¾InvenergyÔâµ½REvilÀÕË÷¹¥»÷й¶4TBÊý¾Ý


4.jpg


REvilÍÅ»ïÐû³ÆÆä¹¥»÷ÁËÃÀ¹ú¿ç¹ú¿ÉÔÙÉúÄÜÔ´¹«Ë¾Invenergy LLCµÄÍøÂç £¬²¢ÇÔÈ¡ÁË4 TBµÄÊý¾Ý¡£¸Ã¹«Ë¾ÓÚÉÏÖÜÎ峯Æä¼ì²âµ½Á˹¥»÷ £¬ÔËӪδÊܵ½Ó°Ïì £¬Êý¾ÝҲû±»¼ÓÃÜ £¬²¢ÇÒûÓÐÖ§¸¶Ò²²»³ïËãÖ§¸¶ÈκÎÊê½ð¡£Ö®ºó £¬REvil³ÆÇÔÈ¡ÁË4 TBÊý¾Ý £¬Ô̺¬ÏîÄ¿¡¢ºÏͬºÍ±£ÃܺÍ̸ £¬ÒÔ¼°InvenergyÊ×´´ÈËMichael PolskyµÄÓ×ÎÒÃô¸ÐÐÅÏ¢ £¬ÀýÈçÆäÓ×ÎÒµç×ÓÓʼþÒÔ¼°ËûÓëµÚÒ»ÈÎÀÏÆÅMayaÀë»éµÄϸ½Ú£¨ËûÔÚ2007ÄêµÄÀë»é±»±¨Â·Îªº¹ÇàÉÏ×î°º¹óµÄÀë»é°¸Ö®Ò»£©µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/revil-claims-responsibility-for/


5.Group IB°ä²¼2020-2021ÄêÀÕË÷Èí¼þµÄ·ÖÎö»ã±¨


5.jpg


Group IB°ä²¼ÁË2020-2021ÄêÀÕË÷Èí¼þµÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö £¬ÀÕË÷ÍŻﲻ̫¹ØÇÐÖ¸±êÐÐÒµ £¬¶øÊǸü¹Ø×¢ÁìÓòºÍ¹æÄ£ £¬Æ«²îÓÚ¹¥»÷´óÐÍÆóÒµÒÔ»ñµÃ¾¡¿ÉÄܶàµÄÊê½ð£»2019ÄêµÄ¾ùÔÈÊê½ðԼΪ8ÍòÃÀÔª £¬2020ÄêÔòԼΪ17ÍòÃÀÔª £¬¶øMaze¡¢DoppelPaymerºÍRagnarLockerµÄ¾ùÔÈÊê½ðÒªÇóÔÚ100ÍòÖÁ200ÍòÃÀÔªÖ®¼ä£»ÆóÒµ»·¾³Í¨³£²»½öÔËÐÐWindowsϵͳ £¬»¹ÔËÐÐLinux £¬Òò¶øÒ»Ð©¹¥»÷ÕßÔÚËûÃǵıøÆ÷¿âÖÐÔö³¤ÁËÏàÓ¦µÄ°æ±¾¡£


Ô­ÎÄÁ´½Ó£º

https://www.group-ib.com/resources/threat-research/ransomware-2021.html


6.AT&T Alien°ä²¼½©Ê¬ÍøÂçMoobot¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨


6.jpg


AT&T Alien Labs°ä²¼Óйؽ©Ê¬ÍøÂçMiraiµÄ±äÌåMoobotµÄ¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£3ÔÂµ× £¬×êÑÐÈËÔ±·¢ÏÖTendaÖеÄÔ¶³Ì´úÂëÖ´ÐÐ (RCE) ·ì϶CVE-2020-10987µÄÀûÓó¢ÊÔ¼¤Ôö £¬ÕâÔÚǰ¼¸¸öÔ²¢²»³£¼û¡£Í¨¹ý¶ÔURL½øÐзÖÎö £¬È·¶¨ºÚ¿ÍÔÚÀûÓÃCyberium¶ñÒâÈí¼þÍйÜÓò·Ö·¢ºÜ¶à·ÖÆçµÄMirai±äÌå £¬Ô̺¬MoobotºÍSatori¡£´Ë±í £¬¸Ã»ã±¨»¹ÌṩÁËÓйØÕâ´Î¹¥»÷µÄ»º½â´ëÊ©¡¢¼ì²â²½ÖèºÍIOC¡£


Ô­ÎÄÁ´½Ó£º

https://cybersecurity.att.com/blogs/labs-research/malware-hosting-domain-cyberium-fanning-out-mirai-variants