Ìõ¼Ç±¾ÖÆÔìÉÌÈʱ¦Ñ¬È¾DoppelPaymer£¬£¬£¬±»ÀÕË÷1700ÍòÃÀÔª£»£»£»Î¢ÈíÐû²¼ÖܶþÇå¾²¸üУ¬£¬£¬×ܼÆÐÞ¸´112¸öÎó²î
Ðû²¼Ê±¼ä 2020-11-11Ìõ¼Ç±¾ÖÆÔìÉÌÈʱ¦Ôâµ½DoppelPaymerÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬±»ÀÕË÷1700ÍòÃÀÔª¡£¡£¡£¡£¡£¡£Èʱ¦£¨Compal£©ÊÇÈ«ÇòµÚ¶þ´óÔ´´Éè¼Æ(ODM)Ìõ¼Ç±¾µçÄÔÖÆÔìÉÌ£¬£¬£¬ÓëÆ»¹û¡¢»ÝÆÕ¡¢´÷¶û¡¢åÚÏëºÍºê³žµÈ×ÅÃû¹«Ë¾ÏàÖú¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖÆäÖ»Êǰ칫×Ô¶¯»¯ÏµÍ³·ºÆðÒì³££¬£¬£¬²¢Î´ÏñÍâ½çËù±¨µÀµÄÄÇÑù±»ºÚ¿ÍÀÕË÷£¬£¬£¬ÏÖÔÚÉú²úÖÐÒ»ÇÐÕý³£¡£¡£¡£¡£¡£¡£µ«¾ÝÐÂÎÅÍøÕ¾BleepingComputer³ÆÆäÒÑ»ñµÃÊê½ð¼Í¼£¬£¬£¬ÆäÖкڿÍÍÅ»ïÒªÇóÖ§¸¶1100±ÈÌØ±Ò£¨16725500ÃÀÔª£©¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/laptop-maker-compal-hit-by-ransomware-17-million-demanded/
2.΢ÈíÐû²¼ÖܶþÇå¾²¸üУ¬£¬£¬×ܼÆÐÞ¸´112¸öÎó²î
΢ÈíÐû²¼11ÔµÄÖܶþÇå¾²¸üУ¬£¬£¬×ܼÆÐÞ¸´112¸öÎó²î¡£¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄ½ÏΪÑÏÖØµÄÎó²î°üÀ¨WindowsÄÚºËÃÜÂëÇý¶¯³ÌÐò£¨cng.sys£©ÖеÄÌáȨ0day£¨CVE-2020-17087£©¡¢Azure SphereÌØÈ¨ÌáÉýÎó²î£¨CVE-2020-16988£©¡¢Microsoftä¯ÀÀÆ÷ÄÚ´æËð»µÎó²î£¨CVE-2020-17058£©¡¢Chakra¾ç±¾ÒýÇæÄÚ´æËð»µÎó²î£¨CVE-2020-17048£©¡¢Internet ExplorerÄÚ´æËð»µÎó²î£¨CVE-2020-17053£©ºÍWindows Print SpoolerÔ¶³ÌÖ´ÐдúÂëÎó²î£¨CVE-2020-17042£©µÈ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-november-2020-patch-tuesday-fixes-112-vulnerabilities/
3.еÄÒøÐÐľÂíGhimob¿É¼à¿Ø153¸öAndroidÓ¦ÓÃ
Çå¾²¹«Ë¾kaspersky·¢Ã÷еÄÒøÐÐľÂíGhimob¿É¼à¿Ø153¸öAndroidÓ¦Óᣡ£¡£¡£¡£¡£Ghimob²¢Î´Í¨¹ý¹Ù·½PlayÊÐËÁ¿¯ÐУ¬£¬£¬¶øÊÇʹÓõç×ÓÓʼþ»ò¶ñÒâÍøÕ¾½«Óû§Öض¨Ïòµ½ÆäËûAndroidÓ¦ÓõÄÐû´«ÍøÕ¾£¬£¬£¬ÕâЩӦÓÃð³äÁ˹ٷ½Ó¦ÓóÌÐò£¬£¬£¬´øÓÐGoogle Defender¡¢Google DocsµÈ×ÖÑù¡£¡£¡£¡£¡£¡£Ò»µ©Óû§ÀÖ³É×°Ö㬣¬£¬¸Ã¶ñÒâÓ¦Óý«ÇëÇó»á¼ûAccessibilityЧÀÍ¡£¡£¡£¡£¡£¡£ÔÊÐíÇëÇóºóÆä»áÔÚÓû§ÊÖ»úÖÐËÑË÷153¸öÓ¦Ó㬣¬£¬²¢ÏÔʾαÔìµÄµÄµÇÂ¼Ò³Ãæ£¬£¬£¬ÒÔÇÔÈ¡Óû§µÄƾ֤¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/new-ghimob-malware-can-spy-on-153-android-mobile-applications/
4.Ñо¿Ö°Ô±Åû¶ÃÀ¹ú¹ú·À²¿ÄÚÍø¿ÉÐ®ÖÆDODÕ˺ŵÄÎó²î
Çå¾²¹«Ë¾Silent BreachµÄÑо¿Ô±Jeff SteinburgÅû¶ÃÀ¹ú¹ú·À²¿ÄÚÍø¿ÉÐ®ÖÆDODÕ˺ŵÄÎó²î¡£¡£¡£¡£¡£¡£½öͨ¹ýÐ޸ķ¢Ë͵½DODЧÀÍÆ÷µÄWebÇëÇóÖеÄһЩ²ÎÊý±ã¿ÉÒÔʹÓøÃÎó²î£¬£¬£¬À´Ð®ÖÆDODÕÊ»§¡£¡£¡£¡£¡£¡£ÓÉÓÚÖ»Ðè×îµÍµÄÊÖÒÕˮƽ¾ÍÄÜʹÓúÍÐ®ÖÆí§Òâ¹ú·À²¿Õʺţ¬£¬£¬Òò´ËÆäÑÏÖØË®Æ½±»ÆÀΪÑÏÖØ(9 ~ 10)¡£¡£¡£¡£¡£¡£ÏÖÔÚÃÀ¹ú¹ú·À²¿ÒѾÐÞ¸´Á˸ÃÎó²î¡£¡£¡£¡£¡£¡£¶øSteinburgÒ²»ñµÃÁËDODµÄÔ¶ÈÑо¿Ö°Ô±½±¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/bug-hunter-wins-researcher-of-the-month-award-for-dod-account-takeover-bug/
5.ºÚ¿ÍʹÓÃαÔìµÄTeams¸üзַ¢Cobalt Strike
ºÚ¿ÍʹÓÃαÔìµÄTeams¸üзַ¢Cobalt Strike£¬£¬£¬Ö÷ÒªÕë¶Ô½ÌÓý²¿·Ö¡£¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃZeroLogon£¨CVE-2020-1472£©Îó²î»ñÈ¡ÖÎÀíÔ±»á¼ûȨÏÞ£¬£¬£¬È»ºóͨ¹ýËÑË÷ÒýÇæÐ§¹û»òÔÚÏß¶ñÒâ¹ã¸æ£¬£¬£¬Ö²ÈëÐéα¹ã¸æÀ´ÓÕʹÓû§×°ÖøüС£¡£¡£¡£¡£¡£Ö®ºó¹¥»÷Õß½«×°ÖÃCobalt Strike£¬£¬£¬ÒÔÐÖúÆäÔÚÊܺ¦ÕßÍøÂçÖÐÔÚÍøÂçÖкáÏòÒÆ¶¯¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬¸Ã¹¥»÷»¹»á×°ÖÃMicrosoft TeamsµÄÕýµ±¸±±¾£¬£¬£¬ÒÔ×èÖ¹Êܺ¦Õß²ì¾õµ½´Ë´Î¹¥»÷¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/fake-microsoft-teams-updates-lead-to-cobalt-strike-deployment/
6.kasperskyÐû²¼2020ÄêÀÕË÷Èí¼þµÄÌ¬ÊÆÆÊÎö±¨¸æ
kasperskyÐû²¼2020ÄêÀÕË÷Èí¼þµÄÌ¬ÊÆÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³öƾ֤ÉϰëÄ걬·¢µÄ¼¸ÆðÊÂÎñ£¬£¬£¬Åú×¢ÀÕË÷Èí¼þµÄ¹æÄ£ÔÚÒ»Ö±À©´ó¡£¡£¡£¡£¡£¡£2Ô·ݵ¤Âó¹«Ë¾ISSµÄÊýÊ®ÍòÃûÔ±¹¤ÒòÀÕË÷Èí¼þ¹¥»÷Ó빫˾ЧÀͶϿª£¬£¬£¬Ôì³É7500Íò- 1.14ÒÚÃÀÔªËðʧ£»£»£»IT¹«Ë¾CognizantÒò¸ÃÀ๥»÷µ¼ÖÂ5000Íò-7000ÍòÃÀÔªËðʧ¡£¡£¡£¡£¡£¡£¸Ã±¨¸æÖ¸³öÐèҪͨ¹ýÀ¬»øÓʼþ¹ýÂËÆ÷£¬£¬£¬°´ÆÚ¸üÐÂËùÓÐÒªº¦ÓªÒµÐÅÏ¢µÄ±¸·Ý£¬£¬£¬½«±¸·Ý´æ´¢ÔÚÇå¾²µÄÔÆÖеȷ½·¨À´±ÜÃâ´ËÀ๥»÷¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.kaspersky.com/blog/ransomware-incidents-2020/37589/