Áù¸öÔÂÒÔÀ´Î¢ÈíÈÔδÐÞ¸´Windows10ÖÐÒÑÖªÎó²î £»£»£»TrickBotÐû²¼µÚ100¸ö°æ±¾£¬ £¬£¬£¬ £¬ÐÂÔöÈÆ¹ý¼ì²âµÄ¹¦Ð§

Ðû²¼Ê±¼ä 2020-11-23
1.Áù¸öÔÂÒÔÀ´Î¢ÈíÈÔδÐÞ¸´Windows10ÖÐÒÑÖªÎó²î


1.png


×Ô2020Äê5Ô£¬ £¬£¬£¬ £¬MicrosoftÐû²¼ÁËWindows 10 2004Çå¾²¸üкó£¬ £¬£¬£¬ £¬·ºÆðÁËÁ½¸öÎó²î£¬ £¬£¬£¬ £¬µ¼ÖÂSSDÇý¶¯Æ÷µÄ´ÅÅÌË鯬ÕûÀí¹ýÓÚÆµÈÔ£¬ £¬£¬£¬ £¬²¢ÔÚ·ÇSSDÇý¶¯Æ÷ÉÏʵÑéTRIM²Ù×÷¡£¡£¡£¡£¡£¡£¡£µÚÒ»¸öÎó²îʹWin10×Ô¶¯Î¬»¤¹¦Ð§ÎÞ·¨¼Ç×ÅÖØÆôϵͳʱÇý¶¯Æ÷µÄ×îºóÓÅ»¯Ê±¼ä£¬ £¬£¬£¬ £¬µ¼ÖÂÇý¶¯Æ÷ÔÚÿ´ÎÖØÆôÅÌËã»úʱ¶¼¾ÙÐÐË鯬ÕûÀí¡£¡£¡£¡£¡£¡£¡£µÚ¶þ¸öÎó²îµ¼ÖÂWin10µÄÓÅ»¯Çý¶¯Æ÷¹¦Ð§»á¶Ô·ÇSSDÇý¶¯Æ÷¾ÙÐÐTRIM£¬ £¬£¬£¬ £¬Õâ»áµ¼ÖÂÊÂÎñÈÕÖ¾Öйýʧ¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬ £¬£¬£¬ £¬ÔÚ½üÁù¸öÔÂÖ®ºó£¬ £¬£¬£¬ £¬MicrosoftÈÔδÐÞ¸´¸ÃÎó²î¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/windows-10-defrag-trim-bug-still-not-fixed-after-six-months/


2.TrickBotÐû²¼µÚ100¸ö°æ±¾£¬ £¬£¬£¬ £¬ÐÂÔöÈÆ¹ý¼ì²âµÄ¹¦Ð§


2.png


TrickBotÍÅ»ïÐû²¼ÁËÆä¶ñÒâÈí¼þµÄµÚ100¸ö°æ±¾£¬ £¬£¬£¬ £¬ÐÂÔöÈÆ¹ý¼ì²âµÄ¹¦Ð§¡£¡£¡£¡£¡£¡£¡£IntelÑо¿Ö°Ô±·¢Ã÷£¬ £¬£¬£¬ £¬¸Ãа汾ÖУ¬ £¬£¬£¬ £¬TrickBotʹÓÃÁËMemoryModuleÖеĴúÂëÖ±½Ó´ÓÄÚ´æÖн«ÆäDLL×¢Èëµ½Õýµ±µÄWindows wermgr.exe£¨WindowsÎÊÌⱨ¸æ£©¿ÉÖ´ÐÐÎļþÖС£¡£¡£¡£¡£¡£¡£²¢ÇÒ£¬ £¬£¬£¬ £¬ÔÚ×¢ÈëDLLʱ£¬ £¬£¬£¬ £¬Ëü»¹Ê¹ÓÃÁËDoppel Hollowing»ò´¦Öóͷ£doppelgangingÒÔÌÓ±ÜÇå¾²Èí¼þµÄ¼ì²â¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿É¼û¸ÃÍŻﲢδÒò»ù´¡ÉèÊ©±»ÆÆËð¶ø×èÖ¹£¬ £¬£¬£¬ £¬Æä¼ÌÐøÔöÌíй¦Ð§ÒÔÈÆ¹ý¼ì²â¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/trickbot-turns-100-latest-malware-released-with-new-features/


3.GoDaddyÔâµ½´¹ÂÚ¹¥»÷£¬ £¬£¬£¬ £¬Æä6¸öÓòÃû±»Ð®ÖÆ


3.png


GoDaddyÔâµ½´¹ÂÚ¹¥»÷£¬ £¬£¬£¬ £¬Æä6¸öÓòÃû±»Ð®ÖÆ¡£¡£¡£¡£¡£¡£¡£GoDaddyÊÇÈ«Çò×î´óµÄÓòÃû×¢²áÉÌ£¬ £¬£¬£¬ £¬ÆäÔ±¹¤ÓÚ½ñÄê3ÔÂÔâµ½ÁËÓïÒôÍøÂç´¹ÂÚ¹¥»÷£¬ £¬£¬£¬ £¬Ê¹¹¥»÷ÕßÐ®ÖÆÁ˰üÀ¨ÉúÒâ¾­¼ÍÍøÕ¾escrow.comÔÚÄÚµÄÖÁÉÙÁù¸öÓòÃû¡£¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷¿Éʹ¹¥»÷ÕßÖØ¶¨Ïò¶à¸öƽ̨µÄµç×ÓÓʼþºÍÍøÂçÁ÷Á¿£¬ £¬£¬£¬ £¬Íƶ¯ÁËÒÑÍùÒ»ÖÜÕë¶Ô¶à¸ö¼ÓÃÜÇ®±ÒÉúÒâÆ½Ì¨µÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£Liquid CEO Mike Kayamori³ÆÒòÆä½¹µãÓòÃûµÄÌṩÉÌGoDaddy½«¶ÔÆäÕÊ»§ºÍÓòµÄ¿ØÖÆÈ¨¹ýʧµØ×ªÒƸøÁ˺ڿÍ£¬ £¬£¬£¬ £¬Ê¹Æä¿ÉÒÔ¸ü¸ÄDNS¼Í¼£¬ £¬£¬£¬ £¬²¢»ñµÃ¶ÔÎĵµ´æ´¢µÄ»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://krebsonsecurity.com/2020/11/godaddy-employees-used-in-attacks-on-multiple-cryptocurrency-services/


4.·¨¹ú±¨ÉçParis-NormandieѬȾÀÕË÷Èí¼þÖ¹ÙÍøÖÐÖ¹


4.png


·¨¹ú±¨ÉçParis-NormandieÓÚÉÏÖÜÈýÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬ £¬£¬£¬ £¬µ¼Ö¹ÙÍøÖÐÖ¹£¬ £¬£¬£¬ £¬Ö½ÖʰæÒ²Êܵ½×ÌÈÅ¡£¡£¡£¡£¡£¡£¡£¸Ã±¨ÉçÓÚÖÜËÄÉÏÎçÐû²¼Twitter³Æ£¬ £¬£¬£¬ £¬´ÓÖܶþÍíÉϵ½ÖÜÈýÍíÉÏ£¬ £¬£¬£¬ £¬¸Ã¹«Ë¾Ôâµ½ÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷Ó°ÏìÁËÆäËùÓÐÅÌËã»úϵͳ£¬ £¬£¬£¬ £¬µ¼ÖÂ×ÔÖÜÈýÏÂÖç1µãÆð£¬ £¬£¬£¬ £¬¸Ã±¨Éç¾ÍÎÞ·¨¸üÐÂÍøÕ¾£¬ £¬£¬£¬ £¬¶øÖÜËÄÒ²Ö»¿¯ÐÐÁËÒ»¸öµØÇøÐÔ°æ±¾£¬ £¬£¬£¬ £¬²¢·Çͨ³£µÄÈý¸ö°æ±¾¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾²¢Î´»ØÓ¦ÊÇ·ñΪÀÕË÷Èí¼þ¹¥»÷£¬ £¬£¬£¬ £¬µ«Á½Î»ÄäÃû¼ÇÕß֤ʵÓÐÊÕµ½Êê½ðÒªÇ󡣡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.lemonde.fr/actualite-medias/article/2020/11/19/le-quotidien-paris-normandie-vise-par-une-cyberattaque_6060387_3236.html


5.DrupalÇå¾²¸üУ¬ £¬£¬£¬ £¬ÐÞ¸´CVE-2020-13671Îó²î


5.png


DrupalÄÚÈÝÖÎÀíϵͳ£¨CMS£©Ðû²¼ÁËÇå¾²¸üУ¬ £¬£¬£¬ £¬ÒÔÐÞ¸´CVE-2020-13671Îó²î¡£¡£¡£¡£¡£¡£¡£DrupalÊÇÏÖÔÚ»¥ÁªÍøÉÏʹÓÃÂÊ×î¸ßµÄCMS£¬ £¬£¬£¬ £¬½ö´ÎÓÚWordPress¡¢ShopifyºÍJoomla¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îΪ´úÂëÖ´ÐÐÎó²î£¬ £¬£¬£¬ £¬¹¥»÷Õß¿ÉÒÔÔÚ¶ñÒâÎļþÖÐÌí¼ÓµÚ¶þ¸öÀ©Õ¹Ãû£¬ £¬£¬£¬ £¬Í¨¹ý¿ª·ÅµÄÉÏ´«×ֶν«ÆäÉÏ´«µ½DrupalÕ¾µã¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚWindowsĬÈÏÇéÐÎÏ»áÒþ²Ø×îºóÒ»¸öÎļþÀ©Õ¹Ãû£¬ £¬£¬£¬ £¬Òò´ËÐÂÔöµÄEXEÀ©Õ¹Ãû»á±»Òþ²Ø£¬ £¬£¬£¬ £¬¶ø½öÏÔʾµÚÒ»¸öÎļþÀ©Õ¹Ãû¡£¡£¡£¡£¡£¡£¡£´Ó¶øÊ¹Óû§ÎóÒÔΪËûÃÇÕýÔÚ·­¿ªÎļþ£¬ £¬£¬£¬ £¬µ«ÏÖʵÉÏÊÇÔÚÔËÐжñÒâ³ÌÐò¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/drupal-sites-vulnerable-to-double-extension-attacks/


6.FireEye MandiantÐû²¼2021ÄêÍøÂçÇå¾²Ô¶¾°ÆÊÎö±¨¸æ


6.png


FireEye MandiantÐû²¼ÁË2021ÄêÍøÂçÇå¾²Ô¶¾°ÆÊÎö±¨¸æ£¬ £¬£¬£¬ £¬Ì½ÌÖÁËÓйØÔ¶³ÌÊÂÇéºÍÈ«Çò´óÊ¢ÐеÄÓ°Ïì¡¢ÀÕË÷Èí¼þ¡¢Ãñ×å¹ú¼Ò»î¶¯¡¢ÔÆÇå¾²ºÍÇå¾²ÑéÖ¤ÓйصÄÖ÷Ìâ¡£¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬ £¬£¬£¬ £¬ÀÕË÷Èí¼þ½«¼ÌÐøÉú³¤ºÍÀ©Õ¹£¬ £¬£¬£¬ £¬ÆäÖð½¥ÓÐÁËÕæÕýµÄÕ½ÂÔ£¬ £¬£¬£¬ £¬Óɲî±ðµÄºÚ¿ÍÁ¬ÏµÔÚÒ»Æðʹ¹¥»÷Àú³ÌÔ½·¢×¨Òµ»¯¡£¡£¡£¡£¡£¡£¡£²¿·Ö³ÉÔ±¿ª·¢ÀÕË÷Èí¼þ£¬ £¬£¬£¬ £¬²¿·Ö³ÉԱרÃÅ»ñµÃ³õʼ»á¼ûȨÏ޺͹¥»÷ºóµÄÒç³ö£¬ £¬£¬£¬ £¬ÒÔ¼°ÈÕÒæÔöÌíµÄË«ÖØÀÕË÷»î¶¯£¬ £¬£¬£¬ £¬¶¼½«µ¼ÖÂÀÕË÷¹¥»÷µÄÔöÌí¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://content.fireeye.com/predictions/rpt-security-predictions-2021