¿¨°Í˹»ùÐû²¼Linux°æ±¾RansomExxµÄÆÊÎö±¨¸æ£»£»£»£»£»£»£»ÐÂOffice 365´¹Âڻ¿ÉÈÆ¹ýɱ¶¾Èí¼þµÄ¼ì²â

Ðû²¼Ê±¼ä 2020-11-09
1.¿¨°Í˹»ùÐû²¼Linux°æ±¾RansomExxµÄÆÊÎö±¨¸æ


1.jpg


¿¨°Í˹»ùÐû²¼Ò»·Ýб¨¸æÏÈÈÝÁËLinux°æ±¾µÄRansomExxÀÕË÷Èí¼þ£¬£¬ £¬£¬£¬£¬Ò²³ÆÎªDefray777¡£¡£¡£±¨¸æ³Æ£¬£¬ £¬£¬£¬£¬RansomExxÔÚÕë¶ÔLinuxЧÀÍÆ÷ʱ£¬£¬ £¬£¬£¬£¬»áÏȰ²ÅÅÒ»¸öÃûΪsvc-newµÄELF¿ÉÖ´ÐÐÎļþ£¬£¬ £¬£¬£¬£¬ÓÃÓÚ¼ÓÃÜÊܺ¦ÕßµÄЧÀÍÆ÷¡£¡£¡£±ðµÄ£¬£¬ £¬£¬£¬£¬ÓëWindows°æ±¾²î±ð£¬£¬ £¬£¬£¬£¬Defray777²»°üÀ¨ÈκÎÓÃÓÚÖÕÖ¹Àú³ÌµÄ´úÂ루ÀýÈçÇå¾²Èí¼þ£©£¬£¬ £¬£¬£¬£¬²»»áÏñWindows°æ±¾ÄÇÑù²Á³ý¿ÉÓÿռ䣬£¬ £¬£¬£¬£¬Ò²²»¿ÉÓëÏÂÁîºÍ¿ØÖÆÐ§ÀÍÆ÷ͨѶ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ransomexx-ransomware-also-encrypts-linux-systems/


2.McAfeeÐû²¼2020ÄêQ2ÍøÂç·¸·¨»î¶¯µÄÆÊÎö±¨¸æ


2.jpg


Âõ¿Ë·Æ£¨McAfee£©Ðû²¼±¨¸æ£¬£¬ £¬£¬£¬£¬ÆÊÎöÁËÓë¶ñÒâÈí¼þÓйصÄÍøÂç·¸·¨»î¶¯ÒÔ¼°2020ÄêµÚ¶þ¼¾¶ÈµÄÍøÂçÍþв¡£¡£¡£ÆÊÎö·¢Ã÷£¬£¬ £¬£¬£¬£¬ÔÚ´Ëʱ´úжñÒâÈí¼þÑù±¾×ÜÊýÔöÌíÁË11.5£¥£¬£¬ £¬£¬£¬£¬Ã¿·ÖÖÓÆ½¾ùÓÐ419¸öÐÂÍþв£¬£¬ £¬£¬£¬£¬±ÈÉÏÒ»¼¾¶ÈÔöÌí½ü12£¥¡£¡£¡£±ðµÄ£¬£¬ £¬£¬£¬£¬±¨¸æÏÔʾÓëÉÏÒ»¼¾¶ÈÏà±È£¬£¬ £¬£¬£¬£¬PowerShell¶ñÒâÈí¼þÔöÌíÁË117£¥£¬£¬ £¬£¬£¬£¬ÐÂMicrosoft Office¶ñÒâÈí¼þµÄÔöÌí103£¥£¬£¬ £¬£¬£¬£¬ÍÚ¿ó¶ñÒâÈí¼þ±ÈÔöÌíÁË25£¥£¬£¬ £¬£¬£¬£¬ÎïÁªÍø¶ñÒâÈí¼þÔöÌíÁË7£¥£¬£¬ £¬£¬£¬£¬¶øÒƶ¯¶ñÒâÈí¼þÑù±¾Ï½µÁË15£¥£¬£¬ £¬£¬£¬£¬Óнü750Íò´Î¶ÔÔÆÓû§ÕÊ»§µÄ¹¥»÷¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2020/11/06/q2-2020-threats/


3.LuxotticaÔâµ½¹¥»÷ÖÂÓû§Ð¡ÎÒ˽¼ÒÊý¾ÝºÍ¿µ½¡ÐÅϢй¶


3.jpg


È«Çò×î´óµÄÑÛ¾µ¹«Ë¾LuxotticaÔâµ½¹¥»÷ÖÂÓû§Ð¡ÎÒ˽¼ÒÊý¾ÝºÍ¿µ½¡ÐÅϢй¶¡£¡£¡£Luxottica³ÆÆäÔ¤Ô¼Ó¦ÓÃÔÚ2020Äê8ÔÂ5ÈÕÔâµ½ºÚ¿Í¹¥»÷ºóµ¼ÖÂÊý¾Ýй¶£¬£¬ £¬£¬£¬£¬²¢ÓÚ8ÔÂ28ÈÕÈ·¶¨¹¥»÷Õß¿ÉÒÔ»á¼û»¼ÕßµÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£´Ë´Îй¶ÁËÓû§Ð¡ÎÒ˽¼ÒÊý¾Ý£¨PII£©ºÍÊܱ£»£»£»£»£»£»£»¤µÄ¿µ½¡ÐÅÏ¢£¨PHI£©£¬£¬ £¬£¬£¬£¬°üÀ¨¿Í»§ÐÕÃû¡¢ÁªÏµÐÅÏ¢¡¢Ô¤Ô¼ÈÕÆÚºÍʱ¼ä¡¢¿µ½¡°ü¹Ü±£µ¥ºÅ¡¢ÖÎÁÆ´¦·½¡¢Ò½ÁÆ×´Ì¬ºÍ²¡Ê·µÈ£¬£¬ £¬£¬£¬£¬ÉÐÓв¿·ÖÓû§µÄÐÅÓÿ¨ºÅºÍÉç»á°ü¹ÜºÅ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/luxottica-data-breach-exposes-lenscrafters-eyemed-patient-info/


4.ÐÂOffice 365´¹Âڻ¿ÉÈÆ¹ýɱ¶¾Èí¼þµÄ¼ì²â


4.jpg


MC GlobalµÄÑо¿Ö°Ô±·¢Ã÷ÁËÒ»¸öеÄOffice 365ÍøÂç´¹Âڻ£¬£¬ £¬£¬£¬£¬Í¨¹ý·´×ªµÇ¼ҳÅ侰ͼÀ´Èƹýɱ¶¾Èí¼þµÄ¼ì²â¡£¡£¡£WMC GlobalÌåÏÖ£¬£¬ £¬£¬£¬£¬ÓÉÓÚͼÏñʶ±ðÈí¼þµÄ׼ȷÂÊÔ½À´Ô½¸ß£¬£¬ £¬£¬£¬£¬ºÚ¿ÍÍÅ»ïͨ¹ýµ¹ÖÃͼÏñµÄÑÕÉ«À´ÓÕÆ­É¨ÃèÒýÇæ£¬£¬ £¬£¬£¬£¬µ¼ÖÂͼÏñ¹þÏ£ÓëԭʼͼÏñ²î±ð£¬£¬ £¬£¬£¬£¬ÒÔ´ËÈÆ¹ýɱ¶¾Èí¼þµÄ¼ì²â¡£¡£¡£±ðµÄ£¬£¬ £¬£¬£¬£¬¸Ã»î¶¯»¹Ê¹Óü¶ÁªÑùʽ±í£¨CSS£©×Ô¶¯»¹Ô­Åä¾°£¬£¬ £¬£¬£¬£¬ÒÔʹÆä¿´ÆðÀ´ÏñÕýµ±Office 365µÇÂ¼Ò³ÃæµÄÅä¾°¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/110554/cyber-crime/office-365-phishing-inverts-images.html


5.»ÝÆÕ³Æ2020ÄêQ3 EmotetľÂíµÄ¹¥»÷¼¤Ôö1200£¥


5.jpg


»ÝÆÕ³ÆÏà½ÏÓÚ2020ÄêQ2£¬£¬ £¬£¬£¬£¬Q3ʹÓÃEmotetľÂíµÄ¹¥»÷¼¤Ôö1200£¥ÒÔÉÏ¡£¡£¡£Emotet¾­³£±»ÓÃ×÷¼ÓÔØÆ÷£¬£¬ £¬£¬£¬£¬ÎªºÚ¿Í×éÖ¯Ìṩ»á¼ûȨÏÞ£¬£¬ £¬£¬£¬£¬ÒÔ°²ÅÅTrickBotºÍQakBotºÍ×°ÖÃÀÕË÷Èí¼þ¡£¡£¡£Æ¾Ö¤¶Ô¶ñÒâÈí¼þ·¢Ë͵½µÄ¶¥¼¶ÓòÃûµÄÆÊÎö£¬£¬ £¬£¬£¬£¬ÈÕ±¾ºÍ°Ä´óÀûÑÇÊܵ½µÄÓ°ÏìÓÈÆäÑÏÖØ£¬£¬ £¬£¬£¬£¬»®·ÖÕ¼ÎüÊÕÓû§µÄ32%ºÍ20%¡£¡£¡£¹¥»÷Õßͨ³£Í¨¹ýÏß³ÌÐ®ÖÆÀ´ÈëÇÖ²¢¼à¿ØÓû§µÄÊÕ¼þÏ䣬£¬ £¬£¬£¬£¬Ê¹Emotet¿É»Ø¸´´øÓжñÒ⸽¼þ»òÁ´½ÓµÄÕýµ±µç×ÓÓʼþ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/ransomware-alert-as-emotet/


6.CybleÔÚ°µÍø·¢Ã÷2000ÍòBigbasketÓû§µÄÏêϸÐÅÏ¢


6.jpg


ÍøÂçÇ鱨¹«Ë¾CybleÔÚ°µÍø·¢Ã÷2000ÍòÓ¡¶ÈÔÚÏßÊÐËÁBigbasketÓû§µÄÏêϸÐÅÏ¢¡£¡£¡£¸ÃÎļþ¾ÞϸΪ15 GB£¬£¬ £¬£¬£¬£¬°üÀ¨2000ÍòÌõÓû§¼Í¼£¬£¬ £¬£¬£¬£¬ÒÔÁè¼Ý40000ÃÀÔªµÄ¼ÛÇ®ÔÚ°µÍøÉϳöÊÛ¡£¡£¡£¸ÃÊý¾Ý¿â°üÀ¨Óû§Ãû³Æ¡¢µç×ÓÓʼþID¡¢ÃÜÂë¹þÏ££¨¿ÉÄÜÊÇÉ¢ÁеÄOTP£©¡¢ÁªÏµ·½·¨£¨ÊÖ»ú+µç»°£©¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢Î»Öú͵ǼIPµØµãµÈ¡£¡£¡£Ð¹Â¶¿ÉÄܱ¬·¢ÔÚ2020Äê10ÔÂ14ÈÕ£¬£¬ £¬£¬£¬£¬ÏÖÔڸù«Ë¾Òѽ«´ËÊÂÉϱ¨¸øÍâµØ¾¯·½£¬£¬ £¬£¬£¬£¬²¢ÒÑÕö¿ªÊӲ졣¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/110543/data-breach/bigbasket-details-dark-web.html