Ó¢¹ú´¦Öóͷ£Å·ÃËÓÀ¾Ó¼Æ»®Ê±ÖÁÉÙÎ¥·´ÁË100´ÎGDPR £»£»APT34й¥»÷»î¶¯Karkoff 2020

Ðû²¼Ê±¼ä 2020-03-04

1.Ó¢¹ú´¦Öóͷ£Å·ÃËÓÀ¾Ó¼Æ»®Ê±ÖÁÉÙÎ¥·´ÁË100´ÎGDPR


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Ó¢º£ÄÚÕþ²¿ÔÚ´¦Öóͷ£Å·ÃËÓÀ¾Ó¼Æ»®£¨EUSS£©Ê±ÖÁÉÙÎ¥·´ÁË100´ÎGDPR¡£¡£¡£Ê×ϯ½çÏߺÍÒÆÃñ¼ì²é¹Ù£¨David Ilt£©ÔÚÒÆÃñî¿Ïµ»ú¹¹¾ÙÐеÄÒ»·Ý±¨¸æÖÐÌåÏÖ£¬£¬£¬£¬Ö»¹ÜGDPRÒªÇó¶ÔÔ±¹¤¾ÙÐÐÒâʶÅàѵ£¬£¬£¬£¬µ«ÈԼͼµ½¶ÔGDPRµÄÑÏÖØÎ¥·´¡£¡£¡£Æ¾Ö¤¸Ã±¨¸æ£¬£¬£¬£¬×èÖ¹2019Äê8ÔÂ⣬£¬£¬£¬ÄÚÕþ²¿£¨EUSSµÄ¼àÊÓÕߣ©ÊÕµ½ÁË130Íò·ÝÉêÇ룬£¬£¬£¬²¢ÇÒÒѾ­ÓÐÉϰÙÍòÈË»ñµÃÅú×¼¡£¡£¡£µ«ÔÚ2019Äê3ÔÂ30ÈÕÖÁ8ÔÂ31ÈÕʱ´ú£¬£¬£¬£¬Õþ¸®Î¥·´ÁËGDPRµÄÊÂÎñÓÐ100Æð¡£¡£¡£ÕâЩÊÂÎñ°üÀ¨½«Éí·ÝÖ¤¿¨Æ¬·¢ËÍÖÁ¹ýʧµÄÉêÇëÈ˺͵ص㠣»£»Ðí¶à»¤ÕÕɥʧÁË£¬£¬£¬£¬Éí·Ý֤ʵÎļþ±»ÓÊÕþ²¿·ÖºÍEUSS·Å´íÁ˵ط½ £»£»Î´¾­Ô޳ɱãÓëµÚÈý·½¹²ÏíÉêÇëÈ˵ÄÐÅÏ¢µÈ¡£¡£¡£ÄÚÕþ²¿ÌåÏֻᰴÆÚÉó²éËùÓÐÁ÷³ÌºÍ³ÌÐò£¬£¬£¬£¬ÒÔ¼õÇáÊý¾Ýй¶µÄΣº¦¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/uk-home-office-breached-gdpr-100-times-through-botched-handling-of-eu-settlement-scheme/


2.Checkpoint½¨Éè¶ñÒâÈí¼þÈÆÌ«¹ýÎöµÄÊÖÒյİٿÆÈ«Êé


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Checkpoint½¨ÉèÁ˹ØÓÚ¶ñÒâÈí¼þÓÃÀ´ÌӱܯÊÎöµÄÖÖÖÖÊÖÒյİٿÆÈ«Êé¡£¡£¡£¸Ã°Ù¿ÆÈ«Ê麭¸ÇÁËÓëÎļþϵͳ¡¢×¢²á±í¡¢Í¨ÓÃOSÅÌÎÊ¡¢È«¾ÖOS¹¤¾ß¡¢Óû§½çÃæ¡¢OS¹¦Ð§¡¢Àú³Ì¡¢ÍøÂç¡¢CPU¡¢¹Ì¼þ±í¡¢¹³×Ó¡¢Ó²¼þÒÔ¼°MacOSÌØ¶¨µÄɳÏäÓйصÄÌÓ±ÜÊÖÒÕ¡£¡£¡£Ã¿Ò»¸öÖֱ𶼰üÀ¨ÊÖÒÕÐÎò¡¢´úÂëʾÀý¡¢ÓÃÓÚ¸ú×Ù¸ÃÊÖÒÕµÄÊðÃû½¨Òé¡¢¿É¼ì²âÇéÐÎÀàÐ͵ıí¸ñÒÔ¼°¶Ô²ß¡£¡£¡£Checkpoint»¹ÍýÏëÔöÌíÓë¼ÆÊ±¡¢Windows Management Instrumentation£¨WMI£©ºÍÈËÀàÐÐΪÒòËØÓйصÄÌÓ±ÜÊÖÒÕ¡£¡£¡£Ïà¹ØÁìÓòµÄר¼Ò¿ÉÒÔÔÚGithubÒ³ÃæÉÏΪ¸Ã°Ù¿ÆÈ«Êé×ö³öТ˳¡£¡£¡£Ò»Ð©ÑÝʾ¹æ±ÜÊÖÒյŤ¾ßÊÇ¿ªÔ´µÄ£¬£¬£¬£¬Í¬Ê±Checkpoint»¹Ðû²¼ÁË×Ô¼ºµÄÃûΪInviZzzibleµÄ¿ªÔ´¹¤¾ß¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/checkpoint-creates-encyclopedia-malware-evasion-techniques


3.Ó¢¹úTravelex¹«Ë¾Ô¤¼ÆÒòÍøÂç¹¥»÷Ëðʧ2500ÍòÓ¢°÷


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


¾Ý·͸É籨µÀ£¬£¬£¬£¬ÓÉÓÚ12ÔÂÏÂÑ®µÄÀÕË÷Èí¼þ¹¥»÷ÊÂÎñ£¬£¬£¬£¬Íâ±Ò¶Ò»»¹«Ë¾TravelexÔ¤¼ÆÆäµÚÒ»¼¾¶ÈµÄ½¹µãÊÕÈëËðʧΪ2500ÍòÓ¢°÷£¨ºÏ3200ÍòÃÀÔª£©¡£¡£¡£¸Ã¹«Ë¾»¹ÌåÏÖÒѻָ´ÁËËùÓÐÃæÏò¿Í»§µÄϵͳ¡£¡£¡£Travelexͨ¹ýÆä×Ô¶¯¶©µ¥Ð§ÀÍΪ»ã·áÒøÐС¢°Í¿ËÀ³ÒøÐС¢Î¬ÕäÇ®±ÒÒÔ¼°Ó¢¹úÁãÊÛÉÌTescoºÍSainsburyµÄÒøÐв¿·Ö¿Í»§ÌṩÍâ»ãЧÀÍ¡£¡£¡£TravelexÌåÏִ˴ι¥»÷²»»á¶ÔËæºó¼¸¸ö¼¾¶ÈµÄÉúÒâÔì³ÉÈκÎʵÖÊÐÔÓ°Ïì¡£¡£¡£¸Ã¹«Ë¾»¹³Æ¹Ú×´²¡¶¾µÄ±¬·¢¶ÔÆäÓªÒµÔì³ÉÁËÁíÍâÒ»¸ö¸ºÃæÓ°Ï죬£¬£¬£¬µ«Î´Ô¤¼Æ¸Ã²¡¶¾»á´øÀ´Èκξ­¼ÃËðʧ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://uk.finance.yahoo.com/news/travelex-expects-25-million-hit-093953943.html


4.Let's Encrypt³·»ØÁè¼Ý300Íò¸öTLSÖ¤Êé


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ÓÉÓÚÔÚºó¶Ë´úÂëÖз¢Ã÷ÁËÒ»¸öbug£¬£¬£¬£¬Let's EncryptÏîÄ¿ÍýÏë´ÓÌìϱê׼ʱ¼ä2020Äê3ÔÂ4ÈÕ00:00×îÏÈ×÷·ÏÁè¼Ý300Íò¸öTLSÖ¤Êé¡£¡£¡£ÏêϸÀ´Ëµ£¬£¬£¬£¬¸ÃbugÓ°ÏìÁËBoulder£¬£¬£¬£¬Let's EncryptÏîĿʹÓøÃЧÀÍÆ÷Èí¼þÔÚ¿¯ÐÐTLSÖ¤Êé֮ǰÑéÖ¤Óû§¼°ÆäÓò¡£¡£¡£¸ÃbugÓ°ÏìÁËBoulderÄÚ²¿CAA£¨Ö¤Êé½ÒÏþ»ú¹¹ÊÚȨ£©¹æ·¶µÄʵÑ飬£¬£¬£¬¡°µ±Ò»¸öÖ¤ÊéÇëÇó°üÀ¨N¸öÐèÒª¾ÙÐÐCAAÖØÐ¼ì²éµÄÓòÃûʱ£¬£¬£¬£¬Boulder½«Ñ¡ÔñÒ»¸öÓòÃû²¢¼ì²éN´Î¡£¡£¡£ÕâÏÖʵÉÏÒâζ×ÅÈôÊÇÒ»¸öÓû§ÔÚʱ¼äXÑéÖ¤ÁËÒ»¸öÓòÃû£¬£¬£¬£¬²¢ÇÒ¸ÃÓòÃûÔÚʱ¼äXµÄCAA¼Í¼ÔÊÐíLet's Encrypt¿¯ÐУ¬£¬£¬£¬Ôò¸ÃÓû§¿ÉÒÔÔÚX+30ÌìµÄʱ¼äÀ￯ÐаüÀ¨¸ÃÓòÃûµÄÖ¤Ê飬£¬£¬£¬×ÝȻ֮ºóÓÐÈËÔÚ¸ÃÓòÃûÉÏ×°ÖÃÁËեȡLet's Encrypt¿¯ÐеÄCAA¼Í¼¡±¡£¡£¡£ÔÚÕâ300Íò¸ö×÷·ÏµÄÖ¤ÊéÖУ¬£¬£¬£¬ÓÐ100Íò¸öÊÇͳһÓò/×ÓÓòµÄÖØ¸´Ï£¬£¬£¬Òò´ËÊÜÓ°ÏìÖ¤ÊéµÄÏÖʵÊýĿԼΪ200Íò¸ö¡£¡£¡£ÔÚ3ÔÂ4ÈÕ00:00Ö®ºóËùÓÐÊÜÓ°ÏìµÄÖ¤Êé¶¼½«´¥·¢ä¯ÀÀÆ÷ºÍÆäËûÓ¦ÓóÌÐòÖеĹýʧ£¬£¬£¬£¬ÓòÃûËùÓÐÕß½«±ØÐèÇëÇóеÄTLSÖ¤Êé²¢Ìæ»»¾ÉµÄTLSÖ¤Êé¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/lets-encrypt-to-revoke-3-million-certificates-on-march-4-due-to-bug/


5.APT34й¥»÷»î¶¯Karkoff 2020£¬£¬£¬£¬Õë¶ÔÀè°ÍÄÛÕþ¸®»ú¹¹


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Cybaze/Yoroi ZlabµÄר¼Ò·¢Ã÷APT34×éÖ¯µÄÒ»¸öÐÂÑù±¾£¬£¬£¬£¬ËûÃÇÒÔΪ¸ÃÑù±¾ÊÇKarkoffÖ²ÈëÎïµÄ¸üа汾£¬£¬£¬£¬¿ÉÒÔ֤ʵAPT34ÈÔÈ»´¦Óڻ״̬¡£¡£¡£ÔÚÕâ¸öÐµĹ¥»÷»î¶¯ÖÐAPT34¿ÉÄÜÈëÇÖÁËÊôÓÚÀè°ÍÄÛÕþ¸®»ú¹¹µÄMicrosoft Exchange Server¡£¡£¡£ÐÂÑù±¾ÓëÒÑÍùKarkoffÑù±¾µÄÏàËÆÖ®´¦°üÀ¨¾ßÓÐÏàËÆµÄºê½á¹¹¡¢¾ßÓÐÀàËÆÂß¼­µÄ.NETÄ£¿£¿£¿£¿é»¯Ö²ÈëÎïÒÔ¼°Ê¹ÓÃMicrosoft Exchange Server×÷ΪͨѶÇþµÀ¡£¡£¡£±ðµÄ£¬£¬£¬£¬ÐÂKarkoffÖ²ÈëÎïʵÏÖÁËеÄÕì̽Âß¼­£¬£¬£¬£¬ÒÔ±ã½ö½«×îÖÕµÄÓÐÓúÉÔØÊͷŵ½Ìض¨Ä¿µÄ£¬£¬£¬£¬²¢ÇÒÍøÂçϵͳÐÅÏ¢¡¢ÓòÃû¡¢Ö÷»úÃûºÍÕýÔÚÔËÐеIJÙ×÷ϵͳµÈÐÅÏ¢¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/98802/uncategorized/karkoff-malware-lebanon.html


6.ÐÂPwndLockerÀÕË÷Èí¼þÖ÷ÒªÕë¶ÔÃÀ¹úÊÐÕþÕþ¸®ºÍÆóÒµÍøÂç


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Çå¾²Ñо¿Ö°Ô±·¢Ã÷Õë¶ÔÊÐÕþÕþ¸®ºÍÆóÒµÍøÂçµÄÐÂÀÕË÷Èí¼þ¼Ò×å¡°PwndLocker¡±£¬£¬£¬£¬¸Ã¼Ò×å×Ô2019Äêµ×ÒÔÀ´Ò»Ö±»îÔ¾£¬£¬£¬£¬²¢ÔÚÕâ¶Îʱ¼äÄÚ¹¥»÷ÁËÃÀ¹ú¶à¸ö¶¼»áºÍ×éÖ¯¡£¡£¡£PwndLockerÓë½üÆÚÕë¶ÔÒÁÀûŵÒÁÖÝÀ­Èø¶ûÏØµÄ¹¥»÷Óйأ¬£¬£¬£¬¹¥»÷ÕßÒªÇó50¸ö±ÈÌØ±Ò£¨Ô¼ºÏ44.2ÍòÃÀÔª£©µÄÊê½ð£¬£¬£¬£¬²¢ÇÒ³ÆÔÚ¼ÓÃÜ֮ǰÒѾ­ÇÔÈ¡Á˸ÃÏØµÄÊý¾Ý¡£¡£¡£ÍâµØÃ½ÌåÖ¸³ö£¬£¬£¬£¬À­Èø¶ûÏØÎÞÒâÖ§¸¶Êê½ð¡£¡£¡£Æ¾Ö¤Ñо¿Ö°Ô±µÄÆÊÎö£¬£¬£¬£¬PwndLockerʹÓá°net stop¡±ÏÂÁî½ûÓÃÁ˶à¸öWindowsЧÀÍ£¬£¬£¬£¬ÀýÈçMicrosoft SQL Server¡¢MySQLºÍExchange£¬£¬£¬£¬²¢ÇÒ¼ì²âºÍɱËÀÓëFirefox¡¢Word¡¢Excel¡¢AccessÒÔ¼°ÓëÇå¾²Èí¼þ¡¢±¸·ÝÓ¦ÓóÌÐòºÍÊý¾Ý¿âЧÀÍÆ÷ÓйصÄÀú³Ì¡£¡£¡£Æä¼ÓÃÜÎļþµÄÀ©Õ¹ÃûΪ¡°.key¡±»ò¡° .pwnd¡±¡£¡£¡£PwndLocker²¢²»ÊǵÚÒ»¸öÕë¶ÔÆóÒµÍøÂçµÄÀÕË÷Èí¼þ£¬£¬£¬£¬Ö®Ç°Ñо¿Ö°Ô±»¹·¢Ã÷ÁËÕë¶ÔÆóÒµÍøÂçµÄSNAKEºÍAko¼Ò×å¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.tripwire.com/state-of-security/security-data-protection/pwndlocker-ransomware-targeting-municipalities-enterprise-networks/