ºÚ¿ÍÈëÇÖÌØÀÊÆÕ¾ºÑ¡ÍøÕ¾²¢Èö²¥ÐéαÐÅÏ¢£»£»£»£»£»£»ACTI³Æ¶íºÚ¿Í×éÖ¯TurlaÈëÇÖÅ·ÖÞÒ»¸öÕþ¸®×éÖ¯
Ðû²¼Ê±¼ä 2020-10-29Õþ¸®¹ÙÔ±ÌåÏÖ£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍÔÚÑ¡¾ÙÈÕǰһÖܵÄÐÇÆÚ¶þÈëÇÖÁËÌÆÄɵ¡¤ÌØÀÊÆÕµÄ¾ºÑ¡ÍøÕ¾¡£¡£¡£donaldjtrump.comÍøÕ¾±»¡°Õâ¸öÍøÕ¾±»²é·âÁË¡±ÐÂÎÅËùÈ¡´ú£¬£¬£¬£¬£¬£¬£¬²¢ÌåÏÖ¡°ÌìÏÂÒѾÊܹ»ÁËÌÆÄɵ¡¤J¡¤ÌØÀÊÆÕ×ÜͳÌìÌìÉ¢²¥µÄ¼ÙÐÂÎÅ¡±¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬ºÚ¿Í»¹ºôÓõÍøÃñ¾èÔùMoneroÊý×ÖÇ®±ÒÒÔÖ§³Ö»ò×赲й¶ÓëÌØÀÊÆÕÓйصÄÖ¤¾Ý¡£¡£¡£ÌØÀÊÆÕ¾ºÑ¡½²»°ÈËTim MurtaughÌåÏÖ£¬£¬£¬£¬£¬£¬£¬¸ÃÍøÕ¾ºÜ¿ì»ñµÃÐÞ¸´²¢Ã»ÓÐÈκÎÃô¸ÐÊý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬´Ë´Î¹¥»÷µÄȪԴ»¹ÔÚÊÓ²ìÖС£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/trump-campaign-website-broken-hackers
2.ACTI³Æ¶íºÚ¿Í×éÖ¯TurlaÈëÇÖÅ·ÖÞÒ»¸öÕþ¸®×éÖ¯
ƾ֤°£ÉÕÜÍøÂçÍþвÇ鱨£¨ACTI£©µÄ×îб¨¸æ£¬£¬£¬£¬£¬£¬£¬¶íÂÞ˹µÄºÚ¿Í×éÖ¯TurlaÈëÇÖÁËÒ»¸öδ¹ûÕæÃû³ÆµÄÅ·ÖÞÕþ¸®×éÖ¯µÄϵͳ¡£¡£¡£ÎªÁËÈëÇÖ×éÖ¯ÍøÂ磬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÁË×î½ü¸üеÄÔ¶³ÌÖÎÀíľÂí£¨RAT£©ºÍ»ùÓÚÔ¶³ÌÀú³ÌŲÓã¨RPC£©µÄºóÃųÌÐò£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨HyperStack¡£¡£¡£ACTIÌåÏÖ£¬£¬£¬£¬£¬£¬£¬Õâ´Î¹¥»÷ÍêÈ«ÇкÏTurla´ÓÊÂÌØ¹¤»î¶¯µÄÄîÍ·£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚËüÒÑ¾ÆÆËðÁËÀ´×Ô100¶à¸ö¹ú¼ÒµÄÕþ¸®¡¢´óʹ¹ÝÒÔ¼°½ÌÓýºÍÑо¿»ú¹¹µÄÊýǧ¸öϵͳ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/russian-turla-hackers-breach-european-government-organization/
3.MicrosoftÐû²¼KB4577586¸üУ¬£¬£¬£¬£¬£¬£¬×èֹʹÓÃAdobe Flash
MicrosoftÐû²¼ÁËKB4577586¸üУ¬£¬£¬£¬£¬£¬£¬ÒÔ×èֹʹÓÃWindowsÉϵÄAdobe Flash¡£¡£¡£´Ë´Î¸üнö¿Éͨ¹ýMicrosoft Catalog»ñµÃ¡£¡£¡£MicrosoftÉùÃ÷¸Ã¸üн«×Ô¶¯É¾³ýAdobe Flash Player£¬£¬£¬£¬£¬£¬£¬µ«Éв»ÇåÎúÈ·ÇÐɾ³ýµÄÄÚÈÝ¡£¡£¡£¾ÓɲâÊÔ£¬£¬£¬£¬£¬£¬£¬´Ë¸üÐÂɾ³ýÁËWindows 10ÖÐÀ¦°óµÄFlash Player£¨32룩°æ±¾£¬£¬£¬£¬£¬£¬£¬µ«²»»áɾ³ýÈκÎ×ÔÁ¦°æ±¾µÄAdobe Flash Player¡£¡£¡£MicrosoftÔòÌåÏÖ»á2021ÄêÍ·Flashµ½ÆÚºó¶ÔFlash Player¾ÙÐдó¹æÄ£É¾³ý¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-update-to-remove-adobe-flash-from-windows/
4.Enel GroupÔÙ´ÎѬȾÀÕË÷Èí¼þ£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶5TBµÄÊý¾Ý
¿ç¹úÄÜÔ´¹«Ë¾Enel Group½ñÄêÔâµ½µÚ¶þ´ÎÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬£¬NetwalkerÉù³ÆÆäÇÔÈ¡ÁË5TBµÄÊý¾Ý²¢ÀÕË÷1400ÍòÃÀÔªÊê½ð¡£¡£¡£EnelÊÇÅ·ÖÞÄÜÔ´ÁìÓò×î´óµÄ¹«Ë¾Ö®Ò»£¬£¬£¬£¬£¬£¬£¬ÔÚ40¸ö¹ú¼ÒºÍµØÇøÓµÓÐ6100Íò¿Í»§¡£¡£¡£½ñÄê6Ô³õ£¬£¬£¬£¬£¬£¬£¬EnelµÄÄÚ²¿ÍøÂçÔâµ½SnakeÀÕË÷Èí¼þµÄ¹¥»÷£¬£¬£¬£¬£¬£¬£¬10ÔÂ19ÈÕÓÖÔâµ½NetwalkerÀÕË÷Èí¼þµÄ¹¥»÷¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬NetwalkerÒÑÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾Ðû²¼Á˱»µÁÊý¾ÝµÄ½ØÍ¼£¬£¬£¬£¬£¬£¬£¬²¢ÌåÏÖ»áÔÚÒ»ÖÜÄÚ¹ûÕæÆäÖеÄÒ»²¿·Ö¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/enel-group-hit-by-ransomware-again-netwalker-demands-14-million/
5.¼Ò¾ß¹«Ë¾SteelcaseѬȾRyukµ¼ÖÂϵͳÔÝʱ¹Ø±Õ
È«Çò×î´óµÄ°ì¹«¼Ò¾ßÖÆÔìÉÌSteelcase³ÆÆäÔÚ10ÔÂ22ÈÕÔâµ½RyukÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬£¬²¢µ¼ÖÂϵͳÔÝʱ¹Ø±Õ¡£¡£¡£¸Ã¹«Ë¾Ðû²¼ÉùÃ÷³ÆÆäÔÚÐÅÏ¢ÊÖÒÕϵͳÉÏ·¢Ã÷ÁËÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬£¬²¢Ñ¸ËÙ½ÓÄÉÁËһϵÁÐ×èÖ¹²½·¥À´½â¾öÕâÖÖÇéÐΣ¬£¬£¬£¬£¬£¬£¬°üÀ¨ÔÝʱ¹Ø±ÕÊÜÓ°ÏìµÄϵͳºÍÏà¹Ø²Ù×÷¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬¹«Ë¾Éв»ÖªµÀ´Ë¹¥»÷µ¼ÖµÄÏêϸϵͳÊý¾Ýɥʧ»ò×ʲúËðʧ£¬£¬£¬£¬£¬£¬£¬µ«¹«Ë¾Ô¤¼Æ¸ÃÊÂÎñ²»»á¶ÔÆäÓªÒµÔËÓª»ò²ÆÎñÒµ¼¨±¬·¢ÖØ´óÓ°Ïì¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/steelcase-furniture-giant-hit-by-ryuk-ransomware-attack/
6.VeracodeÐû²¼Ó¦ÓóÌÐòÇå¾²Ì¬ÊÆµÄÆÊÎö±¨¸æ
VeracodeÐû²¼µÚ11ÆÚÈí¼þÇ徲״̬±¨¸æ£¬£¬£¬£¬£¬£¬£¬¶ÔÓ¦ÓóÌÐòÇå¾²Ì¬ÊÆ¾ÙÐÐÁËÆÊÎö¡£¡£¡£±¨¸æ¶Ô130000¸öÓ¦ÓóÌÐò¾ÙÐÐÁËÆÊÎö£¬£¬£¬£¬£¬£¬£¬·¢Ã÷76£¥µÄÓ¦ÓÃÖÁÉÙ¾ßÓÐÒ»¸öÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬µ«Ö»ÓÐ24£¥µÄÓ¦ÓþßÓиßÑÏÖØÐÔÎó²î¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬¸Ã±¨¸æ»¹·¢Ã÷ÁËһЩ¿ÉÌá¸ßÎó²îÐÞ¸´ÂʵÄÒªÁ죬£¬£¬£¬£¬£¬£¬ÈçÁ¬ÏµÊ¹ÓöàÖÖɨÃèÀàÐÍ£¨°üÀ¨¾²Ì¬ÆÊÎö£¨SAST£©£¬£¬£¬£¬£¬£¬£¬¶¯Ì¬ÆÊÎö£¨DAST£©ºÍÈí¼þ×éÉíÆÊÎö£¨SCA£©£©£¬£¬£¬£¬£¬£¬£¬Í³¼ÆÅú×¢ÄÇЩͬʱʹÓÃSASTºÍDASTµÄÈË¿ÉÒÔ24ÌìÄÚÐÞ¸´Ò»°ëµÄȱÏÝ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.veracode.com/sites/default/files/pdf/sossv11/soss_infographic_v11.pdf