ºÚ¿ÍÈëÇÖÌØÀÊÆÕ¾ºÑ¡ÍøÕ¾²¢Èö²¥ÐéαÐÅÏ¢£»£»£»£»£»£»ACTI³Æ¶íºÚ¿Í×éÖ¯TurlaÈëÇÖÅ·ÖÞÒ»¸öÕþ¸®×éÖ¯

Ðû²¼Ê±¼ä 2020-10-29
1.ºÚ¿ÍÈëÇÖÌØÀÊÆÕ¾ºÑ¡ÍøÕ¾²¢Èö²¥ÐéαÐÅÏ¢


1.jpg


Õþ¸®¹ÙÔ±ÌåÏÖ£¬£¬ºÚ¿ÍÔÚÑ¡¾ÙÈÕǰһÖܵÄÐÇÆÚ¶þÈëÇÖÁËÌÆÄɵ¡¤ÌØÀÊÆÕµÄ¾ºÑ¡ÍøÕ¾¡£¡£donaldjtrump.comÍøÕ¾±»¡°Õâ¸öÍøÕ¾±»²é·âÁË¡±ÐÂÎÅËùÈ¡´ú£¬£¬²¢ÌåÏÖ¡°ÌìÏÂÒѾ­Êܹ»ÁËÌÆÄɵ¡¤J¡¤ÌØÀÊÆÕ×ÜͳÌìÌìÉ¢²¥µÄ¼ÙÐÂÎÅ¡±¡£¡£±ðµÄ£¬£¬ºÚ¿Í»¹ºôÓõÍøÃñ¾èÔùMoneroÊý×ÖÇ®±ÒÒÔÖ§³Ö»ò×赲й¶ÓëÌØÀÊÆÕÓйصÄÖ¤¾Ý¡£¡£ÌØÀÊÆÕ¾ºÑ¡½²»°ÈËTim MurtaughÌåÏÖ£¬£¬¸ÃÍøÕ¾ºÜ¿ì»ñµÃÐÞ¸´²¢Ã»ÓÐÈκÎÃô¸ÐÊý¾Ýй¶£¬£¬´Ë´Î¹¥»÷µÄȪԴ»¹ÔÚÊÓ²ìÖС£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/trump-campaign-website-broken-hackers


2.ACTI³Æ¶íºÚ¿Í×éÖ¯TurlaÈëÇÖÅ·ÖÞÒ»¸öÕþ¸®×éÖ¯


2.jpg


ƾ֤°£É­ÕÜÍøÂçÍþвÇ鱨£¨ACTI£©µÄ×îб¨¸æ£¬£¬¶íÂÞ˹µÄºÚ¿Í×éÖ¯TurlaÈëÇÖÁËÒ»¸öδ¹ûÕæÃû³ÆµÄÅ·ÖÞÕþ¸®×éÖ¯µÄϵͳ¡£¡£ÎªÁËÈëÇÖ×éÖ¯ÍøÂ磬£¬¹¥»÷ÕßʹÓÃÁË×î½ü¸üеÄÔ¶³ÌÖÎÀíľÂí£¨RAT£©ºÍ»ùÓÚÔ¶³ÌÀú³ÌŲÓã¨RPC£©µÄºóÃųÌÐò£¬£¬ÆäÖаüÀ¨HyperStack¡£¡£ACTIÌåÏÖ£¬£¬Õâ´Î¹¥»÷ÍêÈ«ÇкÏTurla´ÓÊÂÌØ¹¤»î¶¯µÄÄîÍ·£¬£¬ÏÖÔÚËüÒѾ­ÆÆËðÁËÀ´×Ô100¶à¸ö¹ú¼ÒµÄÕþ¸®¡¢´óʹ¹ÝÒÔ¼°½ÌÓýºÍÑо¿»ú¹¹µÄÊýǧ¸öϵͳ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/russian-turla-hackers-breach-european-government-organization/


3.MicrosoftÐû²¼KB4577586¸üУ¬£¬×èֹʹÓÃAdobe Flash


3.jpg


MicrosoftÐû²¼ÁËKB4577586¸üУ¬£¬ÒÔ×èֹʹÓÃWindowsÉϵÄAdobe Flash¡£¡£´Ë´Î¸üнö¿Éͨ¹ýMicrosoft Catalog»ñµÃ¡£¡£MicrosoftÉùÃ÷¸Ã¸üн«×Ô¶¯É¾³ýAdobe Flash Player£¬£¬µ«Éв»ÇåÎúÈ·ÇÐɾ³ýµÄÄÚÈÝ¡£¡£¾­ÓɲâÊÔ£¬£¬´Ë¸üÐÂɾ³ýÁËWindows 10ÖÐÀ¦°óµÄFlash Player£¨32룩°æ±¾£¬£¬µ«²»»áɾ³ýÈκÎ×ÔÁ¦°æ±¾µÄAdobe Flash Player¡£¡£MicrosoftÔòÌåÏÖ»á2021ÄêÍ·Flashµ½ÆÚºó¶ÔFlash Player¾ÙÐдó¹æÄ£É¾³ý¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-update-to-remove-adobe-flash-from-windows/


4.Enel GroupÔÙ´ÎѬȾÀÕË÷Èí¼þ£¬£¬Ð¹Â¶5TBµÄÊý¾Ý


4.jpg


¿ç¹úÄÜÔ´¹«Ë¾Enel Group½ñÄêÔâµ½µÚ¶þ´ÎÀÕË÷Èí¼þ¹¥»÷£¬£¬NetwalkerÉù³ÆÆäÇÔÈ¡ÁË5TBµÄÊý¾Ý²¢ÀÕË÷1400ÍòÃÀÔªÊê½ð¡£¡£EnelÊÇÅ·ÖÞÄÜÔ´ÁìÓò×î´óµÄ¹«Ë¾Ö®Ò»£¬£¬ÔÚ40¸ö¹ú¼ÒºÍµØÇøÓµÓÐ6100Íò¿Í»§¡£¡£½ñÄê6Ô³õ£¬£¬EnelµÄÄÚ²¿ÍøÂçÔâµ½SnakeÀÕË÷Èí¼þµÄ¹¥»÷£¬£¬10ÔÂ19ÈÕÓÖÔâµ½NetwalkerÀÕË÷Èí¼þµÄ¹¥»÷¡£¡£ÏÖÔÚ£¬£¬NetwalkerÒÑÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾Ðû²¼Á˱»µÁÊý¾ÝµÄ½ØÍ¼£¬£¬²¢ÌåÏÖ»áÔÚÒ»ÖÜÄÚ¹ûÕæÆäÖеÄÒ»²¿·Ö¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/enel-group-hit-by-ransomware-again-netwalker-demands-14-million/


5.¼Ò¾ß¹«Ë¾SteelcaseѬȾRyukµ¼ÖÂϵͳÔÝʱ¹Ø±Õ


5.jpg


È«Çò×î´óµÄ°ì¹«¼Ò¾ßÖÆÔìÉÌSteelcase³ÆÆäÔÚ10ÔÂ22ÈÕÔâµ½RyukÀÕË÷Èí¼þ¹¥»÷£¬£¬²¢µ¼ÖÂϵͳÔÝʱ¹Ø±Õ¡£¡£¸Ã¹«Ë¾Ðû²¼ÉùÃ÷³ÆÆäÔÚÐÅÏ¢ÊÖÒÕϵͳÉÏ·¢Ã÷ÁËÍøÂç¹¥»÷£¬£¬²¢Ñ¸ËÙ½ÓÄÉÁËһϵÁÐ×èÖ¹²½·¥À´½â¾öÕâÖÖÇéÐΣ¬£¬°üÀ¨ÔÝʱ¹Ø±ÕÊÜÓ°ÏìµÄϵͳºÍÏà¹Ø²Ù×÷¡£¡£ÏÖÔÚ£¬£¬¹«Ë¾Éв»ÖªµÀ´Ë¹¥»÷µ¼ÖµÄÏêϸϵͳÊý¾Ýɥʧ»ò×ʲúËðʧ£¬£¬µ«¹«Ë¾Ô¤¼Æ¸ÃÊÂÎñ²»»á¶ÔÆäÓªÒµÔËÓª»ò²ÆÎñÒµ¼¨±¬·¢ÖØ´óÓ°Ïì¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/steelcase-furniture-giant-hit-by-ryuk-ransomware-attack/    


6.VeracodeÐû²¼Ó¦ÓóÌÐòÇå¾²Ì¬ÊÆµÄÆÊÎö±¨¸æ


6.jpg


VeracodeÐû²¼µÚ11ÆÚÈí¼þÇ徲״̬±¨¸æ£¬£¬¶ÔÓ¦ÓóÌÐòÇå¾²Ì¬ÊÆ¾ÙÐÐÁËÆÊÎö¡£¡£±¨¸æ¶Ô130000¸öÓ¦ÓóÌÐò¾ÙÐÐÁËÆÊÎö£¬£¬·¢Ã÷76£¥µÄÓ¦ÓÃÖÁÉÙ¾ßÓÐÒ»¸öÇå¾²Îó²î£¬£¬µ«Ö»ÓÐ24£¥µÄÓ¦ÓþßÓиßÑÏÖØÐÔÎó²î¡£¡£±ðµÄ£¬£¬¸Ã±¨¸æ»¹·¢Ã÷ÁËһЩ¿ÉÌá¸ßÎó²îÐÞ¸´ÂʵÄÒªÁ죬£¬ÈçÁ¬ÏµÊ¹ÓöàÖÖɨÃèÀàÐÍ£¨°üÀ¨¾²Ì¬ÆÊÎö£¨SAST£©£¬£¬¶¯Ì¬ÆÊÎö£¨DAST£©ºÍÈí¼þ×éÉíÆÊÎö£¨SCA£©£©£¬£¬Í³¼ÆÅú×¢ÄÇЩͬʱʹÓÃSASTºÍDASTµÄÈË¿ÉÒÔ24ÌìÄÚÐÞ¸´Ò»°ëµÄȱÏÝ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.veracode.com/sites/default/files/pdf/sossv11/soss_infographic_v11.pdf