ÀÕË÷ÍÅ»ïZiggyÐû²¼Í˳ö£¬£¬£¬£¬ £¬²¢Ðû²¼Æä½âÃÜÃÜÔ¿£»£»£» £» £» £»ÏÂÔØÁè¼Ý200Íò´ÎµÄChromeÀ©Õ¹Great Suspender°üÀ¨¶ñÒâ´úÂë

Ðû²¼Ê±¼ä 2021-02-08

1.MozillaÐû²¼FirefoxÇå¾²¸üУ¬£¬£¬£¬ £¬ÐÞ¸´NTFSËð»µÎÊÌâ


1.png


MozillaÐû²¼ÁËFirefox 85.0.1£¬£¬£¬£¬ £¬ÐÞ¸´Á˿ɴ¥·¢NTFSË𻵵ÄÎÊÌâ¡£¡£¡£¡£¡£¡£¡£Windows 10ºÍWindows XPÖб£´æÔÊÐí·ÇÌØÈ¨Óû§½«NTFS·ÖÇø±ê¼ÇΪ¡°ÔࡱµÄÎó²î£¬£¬£¬£¬ £¬Õâ»áµ¼ÖÂÇý¶¯Æ÷Ë𻵲¢ÐèÒªÓû§ÖØÐÂÆô¶¯ÒÔÐÞ¸´¡£¡£¡£¡£¡£¡£¡£Firefox¿ÉÒÔͨ¹ý»á¼ûÌØÖÆÂ·¾¶À´´¥·¢NTFSËð»µÎÊÌ⣬£¬£¬£¬ £¬ÏÖÔڸ÷¾¶Òѱ»Õ¥È¡¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ £¬´Ë´ÎÇå¾²¸üл¹ÐÞ¸´Á˶à¸öÎó²î£¬£¬£¬£¬ £¬ÈçmacOS×°±¸ÉÏʹÓÃSPNEGO¶ÔÍøÕ¾¾ÙÐÐÉí·ÝÑé֤ʱµÄÍß½âÎÊÌâµÈ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/software/mozilla-fixes-windows-10-ntfs-corruption-bug-in-firefox/


2.ÏÂÔØÁè¼Ý200Íò´ÎµÄChromeÀ©Õ¹Great Suspender°üÀ¨¶ñÒâ´úÂë


2.png


Ê¢ÐеÄChromeÀ©Õ¹The Great Suspender°üÀ¨¶ñÒâ´úÂ룬£¬£¬£¬ £¬Òѱ»ÏÂÔØÁè¼Ý200Íò´Î¡£¡£¡£¡£¡£¡£¡£¸ÃÀ©Õ¹ÓÃÓÚÔÝͣδʹÓõÄÑ¡Ï£¬£¬£¬£¬ £¬²¢½«ÔÝÍ£µÄÒ³ÃæÌæ»»Îª¿ÕÈ±Ò³ÃæÖ±µ½Óû§ÔÙ´ÎʹÓÃΪֹ£¬£¬£¬£¬ £¬Ö¼ÔÚ½ÚÔ¼×ÊÔ´¡£¡£¡£¡£¡£¡£¡£GoogleÑо¿Ö°Ô±·¢Ã÷¿ª·¢ÕßÌí¼ÓÁËй¦Ð§£¬£¬£¬£¬ £¬¿É´ÓÔ¶³ÌЧÀÍÆ÷Ö´ÐÐí§Òâ´úÂ룬£¬£¬£¬ £¬ÕâÄܱ»ÓÃÀ´¾ÙÐÐ¹ã¸æÚ²Æ­ºÍ¸ú×ٵȶñÒâ»î¶¯¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬ £¬GoogleÒÑÓÚÉÏÖÜËĽ«¸ÃÀ©Õ¹´ÓÍøÉÏÊÐËÁÖÐɾ³ý£¬£¬£¬£¬ £¬»¹½«Æä´ÓÓû§µÄÅÌËã»úÖнûÓᣡ£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/the-great-suspender-chrome-extension-malware/


3.WordPressµÄ²å¼þÖÐδÐÞ¸´µÄXSSÎó²î¿ÉÓ°ÏìÊýÍò¸öÍøÕ¾


3.png


WordPressµÄ²å¼þContact Form 7 StyleÖÐδÐÞ¸´µÄXSSÎó²î¿ÉÓ°ÏìÁè¼Ý5Íò¸öÍøÕ¾¡£¡£¡£¡£¡£¡£¡£¸Ã²å¼þÓÃÓÚ½¨ÉèÍøÕ¾Ê¹ÓõÄÁªÏµ±íµ¥£¬£¬£¬£¬ £¬ÔÊÐíÓû§×Ô½çËµÍøÕ¾µÄ¼¶ÁªÑùʽ±í(CSS)´úÂëÀ´Ö¸¶¨wordpressµÄÍøÕ¾µÄÍâ¹Û¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îµÄCVSSÆÀ·ÖΪ8.8£¬£¬£¬£¬ £¬ÊÇÓÉÓÚ×Ô½ç˵CSS´úÂëµÄ¹¦Ð§È±ÉÙ¶ÔÊý¾ÝµÄÕûÀíºÍ¶ÔËæ»úÊýµÄ±£»£»£» £» £» £»¤»úÖÆ£¬£¬£¬£¬ £¬Ê¹¹¥»÷Õß¿ÉÒÔÌá½»ÏòÍøÕ¾×¢Èë¶ñÒâJavaScriptµÄÇëÇ󡣡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬ £¬»¹Î´Ðû²¼Õë¶Ô¸ÃÎó²îµÄ²¹¶¡³ÌÐò¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/unpatched-wordpress-plugin-code-injection/163706/


4.ÀÕË÷ÍÅ»ïZiggyÐû²¼Í˳ö£¬£¬£¬£¬ £¬²¢Ðû²¼Æä½âÃÜÃÜÔ¿


4.png


ÖÜÄ©£¬£¬£¬£¬ £¬ÀÕË÷ÍÅ»ïZiggyÔÚTelegramÉÏÐû²¼Æä½«Í˳ö£¬£¬£¬£¬ £¬²¢Ðû²¼ËùÓнâÃÜÃÜÔ¿¡£¡£¡£¡£¡£¡£¡£2ÔÂ7ÈÕ£¬£¬£¬£¬ £¬ZiggyÍÅ»ïÐû²¼ÁËÒ»¸ö°üÀ¨ÁË922¸ö½âÃÜÃÜÔ¿µÄSQLÎļþºÍÓë½âÃÜÃÜÔ¿Ò»ÆðʹÓõĽâÃÜÆ÷¡£¡£¡£¡£¡£¡£¡£³ý´ËÖ®Í⣬£¬£¬£¬ £¬Ziggy»¹Ðû²¼ÁËÀëÏߵĽâÃÜÃÜÔ¿ºÍ²î±ð½âÃÜÆ÷µÄÔ´´úÂ룬£¬£¬£¬ £¬ÓÃÓÚÒòÔâµ½¹¥»÷¶øÎÞ·¨ÅþÁ¬µ½Internet»òC&CÎÞ·¨»á¼ûµÄÊܺ¦Õß¾ÙÐнâÃÜ¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ×î½üµ·»ÙEmotetºÍNetwalkerÐж¯¿ÉÄÜ»áʹ¸ü¶àÍÅ»ï¸ÐӦΣÏÕ²¢Í˳ö£¬£¬£¬£¬ £¬EmsisoftÒ²¼´½«Ðû²¼Æä½âÃÜÆ÷¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ziggy-ransomware-shuts-down-and-releases-victims-decryption-keys/


5.CovewareÐû²¼2020ÄêQ4µÄÀÕË÷Èí¼þÌ¬ÊÆµÄÆÊÎö±¨¸æ


5.png


Çå¾²¹«Ë¾CovewareÐû²¼ÁË2020ÄêQ4µÄÀÕË÷Èí¼þÌ¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬ £¬Æ½¾ùÊê½ðÒªÇó´Ó2020ÄêQ3µÄ233817ÃÀÔªïÔÌ­ÖÁ154108ÃÀÔª£¬£¬£¬£¬ £¬Í¬±ÈïÔÌ­ÁË34£¥£¬£¬£¬£¬ £¬Ö§¸¶µÄƽ¾ù½ð¶îÒ²´Ó110532ÃÀÔªïÔÌ­ÖÁ49450ÃÀÔª£¬£¬£¬£¬ £¬½µ·ùΪ55%£¬£¬£¬£¬ £¬½ð¶î´ó·ùïÔÌ­µÄÔµ¹ÊÔ­ÓÉ¿ÉÄÜΪ´ó×ÚÊܺ¦ÕßÑ¡Ôñ²»¸¶¿î¡£¡£¡£¡£¡£¡£¡£³£¼ûµÄÀÕË÷Èí¼þΪSodinokibi£¨Õ¼±È17.5%£©¡¢Egregor£¨12.3%£©¡¢Ryuk£¨8.7%£©¡¢Netwalker£¨6.0%£©¡¢Maze£¨5.2%£©¡¢Conti v2£¨4.8%£©¡¢DopplePaymer£¨4.0%£©ºÍConti£¨2.4%£©µÈ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.coveware.com/blog/ransomware-marketplace-report-q4-2020


6.KasperskyÐû²¼2020ÄêÕÊ»§½ÓÊܹ¥»÷ÊÂÎñµÄ»ØÊ×±¨¸æ


6.png


KasperskyÐû²¼ÁËÓйØ2020ÄêÕÊ»§½ÓÊܹ¥»÷ÊÂÎñµÄ»ØÊ×±¨¸æ¡£¡£¡£¡£¡£¡£¡£±¨¸æÏÔʾ£¬£¬£¬£¬ £¬ÕË»§½ÓÊÜÊÂÎñÕ¼½ðÈÚЧÀÍÐÐҵڲƭ»î¶¯µÄ±ÈÀýÉÏÉýÁË19%£¬£¬£¬£¬ £¬´Ó2019ÄêµÄ34£¥¼¤ÔöÖÁ2020ÄêµÄ54£¥¡£¡£¡£¡£¡£¡£¡£³ýÁË½Ó»á¼Æ»§Ö®Í⣬£¬£¬£¬ £¬¹¥»÷Õß»¹ÀÄÓÃÖîÈçTeamViewerÖ®ÀàµÄÕýµ±Ô¶³ÌÖÎÀí¹¤¾ß£¨RAT£©À´ÊµÑé»á¼ûÓû§ÕÊ»§¡£¡£¡£¡£¡£¡£¡£Kaspersky½¨Òé×é֯ͨ¹ýÏÞÖÆÉúÒâµÄʵÑé´ÎÊý¡¢¾ÙÐÐÄê¶ÈÇå¾²ÉóºËºÍÉøÍ¸²âÊÔÒÔ¼°ÊµÑé¶àÒòËØÉí·ÝÑéÖ¤µÄ·½·¨À´Ô¤·À´ËÀ๥»÷¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.kaspersky.com/about/press-releases/2021_share-of-account-takeover-incidents-increased-by-20-percentage-points