Atlas°ä²¼2021ÄêH1·ì϶·ÖÎö»ã±¨£ºWindows WPBTÖеÄзì϶ӰÏìWin8

°ä²¼¹¦·ò 2021-09-28

Windows WPBTÖеÄзì϶ӰÏìWin8¼°Ö®ºóËùÓÐϵͳ


Windows WPBTÖеÄзì϶ӰÏìWin8¼°Ö®ºóËùÓÐϵͳ.png


Eclypsium×êÑÐÍŶӷ¢ÏÖMicrosoft Windowsƽ̨¶þ½øÔì±í(WPBT)ÖдæÔÚÒ»¸ö·ì϶£¬¿ÉÓÃÀ´ÔÚϵͳÉÏ×°ÖÃRootkit¡£¸Ã·ì϶ӰÏìÁË2012ÄêÖ®ºó¿¯ÐеÄWindows 8¼°¸ü¸ß°æ±¾µÄËùÓÐϵͳ£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚϵͳÆô¶¯Ê±ÒÔÄÚºËȨÏÞÔËÐжñÒâ´úÂ롣΢ÈíÌá³öµÄ»º½â´ëÊ©Ô̺¬Ê¹ÓÃWindows DefenderÀûÓ÷¨Ê½½ÚÔ죨WDAC£©Õ½ÊõÀ´½ÚÔìÔÚϵͳÖÐÔËÐеĶþ½øÔìÎļþ£¬»òʹÓÃAppLockerÕ½ÊõÀ´½ÚÔìÔÊÐíÔËÐеÄÀûÓá£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-wpbt-flaw-lets-hackers-install-rootkits-on-windows-devices/


Å·ÖÞºô½ÐÖÐÐĹ©¸øÉÌGSSÔâµ½ContiÍÅ»ïµÄÀÕË÷¹¥»÷


Å·ÖÞºô½ÐÖÐÐĹ©¸øÉÌGSSÔâµ½ContiÍÅ»ïµÄÀÕË÷¹¥»÷.png


Covisian½²»°È˳Æ£¬ÆäÎ÷°àÑÀºÍÀ­¶¡ÃÀÖÞ·Ö²¿GSSÓÚ9ÔÂ18ÈÕÔâµ½ÁËContiÍÅ»ïµÄÀÕË÷¹¥»÷¡£CovisianÊÇÅ·ÖÞ×î´óµÄ¿Í»§·þÎñºÍºô½ÐÖÐÐĹ©¸øÉÌÖ®Ò»£¬Õâ´Î¹¥»÷µ¼ÖÂÆä´ó²¿ÃÅϵͳÖжÏ£¬Ó°ÏìÁËVodafone Spain¡¢MasMovil ISP¡¢ÂíµÂÀïµÄ¹©Ë®¹«Ë¾ºÍµçÊǪ́µÈ¹«Ë¾ºÍ×éÖ¯¡£²»¾Ãǰ£¬ÃÀ¹úµÄºô½ÐÖÐÐĺͿͻ§Ö§³Ö·þÎñ¹©¸øÉÌTTECÒ²Ôâµ½ÁËÀÕË÷¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/122570/cyber-crime/gss-ransomware-attack.html



·ÇÖÞÒøÐÐÒòºÏ×÷ͬ°éÔâµ½¹¥»÷µ¼Ö²¿Ãſͻ§ÐÅϢй¶


·ÇÖÞÒøÐÐÒòºÏ×÷ͬ°éÔâµ½¹¥»÷µ¼Ö²¿Ãſͻ§ÐÅϢй¶.png


·ÇÖÞÒøÐÐÔÚÉÏÖÜÈýÈ·ÈÏÒòÆäÕ®Îñ×·»ØºÏ×÷ͬ°éDebt-INÔâµ½¹¥»÷£¬µ¼Ö²¿Ãſͻ§ÐÅϢй¶¡£Debt-InÔøÔÚ½ñÄê4Ô·ÝÔâµ½ÀÕË÷¹¥»÷£¬Æäʱ×êÑÐÈËÔ±¸ø³öµÄ½áÂÛÊÇûÓÐÖ¤¾ÝÅú×¢´æÔÚÊý¾Ýй¶ÎÊÌ⡣Ȼ¶ø£¬Debt-In´Ë¿ÌÒâʶµ½²¿Ãſͻ§µÄÐÅÏ¢ÒÑй¶£¬Ô̺¬·ÇÖÞÒøÐеĴû¿î¿Í»§£¬µ«2021Äê4ÔÂ1ÈÕÖ®ºóµÄÊý¾Ý²¢Î´Êܵ½Ó°Ïì¡£¸ÃÒøÐгÆ£¬ÈôÊǿͻ§ÒÔΪÐÅÏ¢Òѱ»µÁÓ㬿ÉÏòÄÏ·ÇڲƭԤ·À·þÎñÖÐÐÄ(SAFPS)ÉêÇëÃâ·ÑµÄ±£»¤·þÎñ¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2021/09/african-bank-alerts-of-data-breach-with.html



Desorden³ÆÒÑÇÔÈ¡ÂíÀ´Î÷ÑÇABX Express 200GBÊý¾Ý


Desorden³ÆÒÑÇÔÈ¡ÂíÀ´Î÷ÑÇABX Express 200GBÊý¾Ý.png


DesordenÐû³ÆÓÚ9ÔÂ23ÈÕÈëÇÖÁËÂíÀ´Î÷ÑÇABX ExpressµÄ·þÎñÆ÷£¬²¢ÇÔÈ¡ÁË200GBÊý¾Ý¡£Desorden°µÊ¾Õâ´Î»ñµÃÁËÊý°ÙÍòÂíÀ´Î÷ÑÇÈ˵ÄÊý¾Ý¡¢³¬¹ý1500ÍòÌõº½¿ÕÔ˵¥¼Í¼ÒÔ¼°ÓйزÆÕþ¡¢¿Í»§ºÍ¹«Ë¾ÐÅÏ¢µÈ£¬¶øABX¹Ø¹ØÁË·þÎñ²¢³ÆÔÚ×öÏµÍ³ÊØ»¤£¬Ã»Óа䷢Õâ´ÎÊý¾Ýй¶ÊÂÎñ¡£Ä¿Ç°£¬ABX Express¹«Ë¾ÉÐδ¶Ô´ËÊÂ×÷³ö»ØÓ¦£¬¶ø×êÑÐÈËÔ±ÔÚѯÎÊÆäĸ¹«Ë¾Kerry LogisticsºóҲδµÃµ½»ØÓ¦¡£



Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/desorden-group-claims-to-have-stolen-200-gb-of-data-from-abx-express/



Cybereason°ä²¼ÓйØÀÕË÷Èí¼þMagniberµÄ·ÖÎö»ã±¨


Cybereason°ä²¼ÓйØÀÕË÷Èí¼þMagniberµÄ·ÖÎö»ã±¨.png


CybereasonÔÚ9ÔÂ22ÈÕ°ä²¼ÁËÓйØÀÕË÷Èí¼þMagniberµÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬¸ÃÍÅ»ïÖØÒªÊ¹ÓÃÁËPrintNightmare·ì϶£¨CVE-2021-34527ºÍCVE-2021-34481£©¡£Ê×ÏÈÒÔ Windows DLLÎļþµÄ´ó¾Ö·Ö·¢ÀÕË÷Èí¼þ£¬¶øºóÀûÓÃCVE-2021-34527ÔÚÖ¸±êϵͳÉÏ×°ÖúÍÖ´ÐиÃÎļþ¡£´Ë±í£¬ÀÕË÷Èí¼þMagniberÈÔ´¦ÓÚ¿ª·¢ÖУ¬¿ª·¢ÕßÔÚÆµÈԵظü¸Ä´úÂë²¢¸Ä½ø»ìºÏÖ°ÄÜ¡¢ÈƹýÕ½ÊõºÍ¼ÓÃÜ»úÔìµÈ¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.cybereason.com/blog/threat-analysis-report-printnightmare-and-magniber-ransomware



AtlasVPN°ä²¼2021ÄêH1Åû¶µÄ·ì϶µÄ·ÖÎö»ã±¨


AtlasVPN°ä²¼2021ÄêH1Åû¶µÄ·ì϶µÄ·ÖÎö»ã±¨.png


AtlasVPNÔÚ9ÔÂ14ÈÕ°ä²¼ÁË2021ÄêH1Åû¶µÄ·ì϶µÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬Google¡¢MicrosoftºÍOracleÔÚ2021ÄêÉϰëÄêÅû¶µÄ·ì϶×î¶à£¬±ðÀëΪ547¸ö¡¢432¸öºÍ316¸ö·ì϶£¬Æä´ÎΪCisco£¨200¸ö£©ºÍSAP£¨118¸ö£©¡£ÔÚÉϰëÄêÔÚ×ܼƷ¢ÏÖÁË1023¸öCVSSÆÀ·ÖΪ9-10µÄ·ì϶£¬ÀýÈçF5 BIG-IPÖеÄCVE-2021-22986£»927¸öCVSSÆÀ·ÖΪ8-9µÄ·ì϶£¬ÈçDraeger X-DockÖеÄCVE-2021-28111£»ÒÔ¼°2164¸ö7-8·ÖµÄ·ì϶¡£



Ô­ÎÄÁ´½Ó£º

https://atlasvpn.com/blog/google-and-microsoft-accumulated-the-most-vulnerabilities-in-h1-2021