Ìõ¼Ç±¾ÖÆÔìÉÌÈʱ¦Ñ¬È¾DoppelPaymer£¬£¬£¬±»ÀÕË÷1700ÍòÃÀÔª £»£»£»Î¢ÈíÐû²¼ÖܶþÇå¾²¸üУ¬£¬£¬×ܼÆÐÞ¸´112¸öÎó²î

Ðû²¼Ê±¼ä 2020-11-11
1.Ìõ¼Ç±¾ÖÆÔìÉÌÈʱ¦Ñ¬È¾DoppelPaymer£¬£¬£¬±»ÀÕË÷1700ÍòÃÀÔª


1.jpg


Ìõ¼Ç±¾ÖÆÔìÉÌÈʱ¦Ôâµ½DoppelPaymerÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬±»ÀÕË÷1700ÍòÃÀÔª¡£¡£¡£¡£ ¡£¡£Èʱ¦£¨Compal£©ÊÇÈ«ÇòµÚ¶þ´óÔ­´´Éè¼Æ(ODM)Ìõ¼Ç±¾µçÄÔÖÆÔìÉÌ£¬£¬£¬ÓëÆ»¹û¡¢»ÝÆÕ¡¢´÷¶û¡¢åÚÏëºÍºê³žµÈ×ÅÃû¹«Ë¾ÏàÖú¡£¡£¡£¡£ ¡£¡£¸Ã¹«Ë¾ÌåÏÖÆäÖ»Êǰ칫×Ô¶¯»¯ÏµÍ³·ºÆðÒì³££¬£¬£¬²¢Î´ÏñÍâ½çËù±¨µÀµÄÄÇÑù±»ºÚ¿ÍÀÕË÷£¬£¬£¬ÏÖÔÚÉú²úÖÐÒ»ÇÐÕý³£¡£¡£¡£¡£ ¡£¡£µ«¾ÝÐÂÎÅÍøÕ¾BleepingComputer³ÆÆäÒÑ»ñµÃÊê½ð¼Í¼£¬£¬£¬ÆäÖкڿÍÍÅ»ïÒªÇóÖ§¸¶1100±ÈÌØ±Ò£¨16725500ÃÀÔª£©¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/laptop-maker-compal-hit-by-ransomware-17-million-demanded/


2.΢ÈíÐû²¼ÖܶþÇå¾²¸üУ¬£¬£¬×ܼÆÐÞ¸´112¸öÎó²î


2.jpg


΢ÈíÐû²¼11ÔµÄÖܶþÇå¾²¸üУ¬£¬£¬×ܼÆÐÞ¸´112¸öÎó²î¡£¡£¡£¡£ ¡£¡£´Ë´ÎÐÞ¸´µÄ½ÏΪÑÏÖØµÄÎó²î°üÀ¨WindowsÄÚºËÃÜÂëÇý¶¯³ÌÐò£¨cng.sys£©ÖеÄÌáȨ0day£¨CVE-2020-17087£©¡¢Azure SphereÌØÈ¨ÌáÉýÎó²î£¨CVE-2020-16988£©¡¢Microsoftä¯ÀÀÆ÷ÄÚ´æËð»µÎó²î£¨CVE-2020-17058£©¡¢Chakra¾ç±¾ÒýÇæÄÚ´æËð»µÎó²î£¨CVE-2020-17048£©¡¢Internet ExplorerÄÚ´æËð»µÎó²î£¨CVE-2020-17053£©ºÍWindows Print SpoolerÔ¶³ÌÖ´ÐдúÂëÎó²î£¨CVE-2020-17042£©µÈ¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-november-2020-patch-tuesday-fixes-112-vulnerabilities/


3.еÄÒøÐÐľÂíGhimob¿É¼à¿Ø153¸öAndroidÓ¦ÓÃ


3.jpg


Çå¾²¹«Ë¾kaspersky·¢Ã÷еÄÒøÐÐľÂíGhimob¿É¼à¿Ø153¸öAndroidÓ¦Óᣡ£¡£¡£ ¡£¡£Ghimob²¢Î´Í¨¹ý¹Ù·½PlayÊÐËÁ¿¯ÐУ¬£¬£¬¶øÊÇʹÓõç×ÓÓʼþ»ò¶ñÒâÍøÕ¾½«Óû§Öض¨Ïòµ½ÆäËûAndroidÓ¦ÓõÄÐû´«ÍøÕ¾£¬£¬£¬ÕâЩӦÓÃð³äÁ˹ٷ½Ó¦ÓóÌÐò£¬£¬£¬´øÓÐGoogle Defender¡¢Google DocsµÈ×ÖÑù¡£¡£¡£¡£ ¡£¡£Ò»µ©Óû§ÀÖ³É×°Ö㬣¬£¬¸Ã¶ñÒâÓ¦Óý«ÇëÇó»á¼ûAccessibilityЧÀÍ¡£¡£¡£¡£ ¡£¡£ÔÊÐíÇëÇóºóÆä»áÔÚÓû§ÊÖ»úÖÐËÑË÷153¸öÓ¦Ó㬣¬£¬²¢ÏÔʾαÔìµÄµÄµÇÂ¼Ò³Ãæ£¬£¬£¬ÒÔÇÔÈ¡Óû§µÄƾ֤¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/new-ghimob-malware-can-spy-on-153-android-mobile-applications/


4.Ñо¿Ö°Ô±Åû¶ÃÀ¹ú¹ú·À²¿ÄÚÍø¿ÉÐ®ÖÆDODÕ˺ŵÄÎó²î


4.jpg


Çå¾²¹«Ë¾Silent BreachµÄÑо¿Ô±Jeff SteinburgÅû¶ÃÀ¹ú¹ú·À²¿ÄÚÍø¿ÉÐ®ÖÆDODÕ˺ŵÄÎó²î¡£¡£¡£¡£ ¡£¡£½öͨ¹ýÐ޸ķ¢Ë͵½DODЧÀÍÆ÷µÄWebÇëÇóÖеÄһЩ²ÎÊý±ã¿ÉÒÔʹÓøÃÎó²î£¬£¬£¬À´Ð®ÖÆDODÕÊ»§¡£¡£¡£¡£ ¡£¡£ÓÉÓÚÖ»Ðè×îµÍµÄÊÖÒÕˮƽ¾ÍÄÜʹÓúÍÐ®ÖÆí§Òâ¹ú·À²¿ÕʺÅ£¬£¬£¬Òò´ËÆäÑÏÖØË®Æ½±»ÆÀΪÑÏÖØ(9 ~ 10)¡£¡£¡£¡£ ¡£¡£ÏÖÔÚÃÀ¹ú¹ú·À²¿ÒѾ­ÐÞ¸´Á˸ÃÎó²î¡£¡£¡£¡£ ¡£¡£¶øSteinburgÒ²»ñµÃÁËDODµÄÔ¶ÈÑо¿Ö°Ô±½±¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/bug-hunter-wins-researcher-of-the-month-award-for-dod-account-takeover-bug/


5.ºÚ¿ÍʹÓÃαÔìµÄTeams¸üзַ¢Cobalt Strike


5.jpg


ºÚ¿ÍʹÓÃαÔìµÄTeams¸üзַ¢Cobalt Strike£¬£¬£¬Ö÷ÒªÕë¶Ô½ÌÓý²¿·Ö¡£¡£¡£¡£ ¡£¡£¹¥»÷ÕßʹÓÃZeroLogon£¨CVE-2020-1472£©Îó²î»ñÈ¡ÖÎÀíÔ±»á¼ûȨÏÞ£¬£¬£¬È»ºóͨ¹ýËÑË÷ÒýÇæÐ§¹û»òÔÚÏß¶ñÒâ¹ã¸æ£¬£¬£¬Ö²ÈëÐéα¹ã¸æÀ´ÓÕʹÓû§×°ÖøüС£¡£¡£¡£ ¡£¡£Ö®ºó¹¥»÷Õß½«×°ÖÃCobalt Strike£¬£¬£¬ÒÔЭÖúÆäÔÚÊܺ¦ÕßÍøÂçÖÐÔÚÍøÂçÖкáÏòÒÆ¶¯¡£¡£¡£¡£ ¡£¡£±ðµÄ£¬£¬£¬¸Ã¹¥»÷»¹»á×°ÖÃMicrosoft TeamsµÄÕýµ±¸±±¾£¬£¬£¬ÒÔ×èÖ¹Êܺ¦Õß²ì¾õµ½´Ë´Î¹¥»÷¡£¡£¡£¡£ ¡£¡£

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fake-microsoft-teams-updates-lead-to-cobalt-strike-deployment/


6.kasperskyÐû²¼2020ÄêÀÕË÷Èí¼þµÄÌ¬ÊÆÆÊÎö±¨¸æ


6.jpg


kasperskyÐû²¼2020ÄêÀÕË÷Èí¼þµÄÌ¬ÊÆÆÊÎö±¨¸æ¡£¡£¡£¡£ ¡£¡£±¨¸æÖ¸³öƾ֤ÉϰëÄ걬·¢µÄ¼¸ÆðÊÂÎñ£¬£¬£¬Åú×¢ÀÕË÷Èí¼þµÄ¹æÄ£ÔÚÒ»Ö±À©´ó¡£¡£¡£¡£ ¡£¡£2Ô·ݵ¤Âó¹«Ë¾ISSµÄÊýÊ®ÍòÃûÔ±¹¤ÒòÀÕË÷Èí¼þ¹¥»÷Ó빫˾ЧÀͶϿª£¬£¬£¬Ôì³É7500Íò- 1.14ÒÚÃÀÔªËðʧ £»£»£»IT¹«Ë¾CognizantÒò¸ÃÀ๥»÷µ¼ÖÂ5000Íò-7000ÍòÃÀÔªËðʧ¡£¡£¡£¡£ ¡£¡£¸Ã±¨¸æÖ¸³öÐèҪͨ¹ýÀ¬»øÓʼþ¹ýÂËÆ÷£¬£¬£¬°´ÆÚ¸üÐÂËùÓÐÒªº¦ÓªÒµÐÅÏ¢µÄ±¸·Ý£¬£¬£¬½«±¸·Ý´æ´¢ÔÚÇå¾²µÄÔÆÖеȷ½·¨À´±ÜÃâ´ËÀ๥»÷¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.kaspersky.com/blog/ransomware-incidents-2020/37589/