ºÚ¿Í¹ûÕæµç×ÓÒÕ½çEAµÄÊý¾Ý£¬ £¬£¬£¬°üÀ¨FIFA 21ÓÎÏ·Ô´Â룻£»£»£»PythonÐû²¼Çå¾²¸üУ¬ £¬£¬£¬ÐÞ¸´PyPI´æ´¢¿âÖжà¸öÎó²î

Ðû²¼Ê±¼ä 2021-08-02

1.ºÚ¿Í¹ûÕæµç×ÓÒÕ½çEAµÄÊý¾Ý£¬ £¬£¬£¬°üÀ¨FIFA 21ÓÎÏ·Ô´Âë


1.jpg


7ÔÂ26ÈÕÐÇÆÚÒ»£¬ £¬£¬£¬ºÚ¿ÍÔÚ°µÍø¹ûÕæµç×ÓÒÕ½çEAµÄÊý¾Ý£¬ £¬£¬£¬°üÀ¨FIFA 21ÓÎÏ·Ô´Âë¡¢FrostBiteÓÎÏ·ÒýÇæºÍµ÷ÊÔ¹¤¾ßÔ´´úÂëµÈÐÅÏ¢¡£¡£¡£¡£¡£¸ÃÊÂÎñ×î³õÓÚ6ÔÂ10ÈÕÅû¶£¬ £¬£¬£¬ÆäʱºÚ¿ÍÉù³ÆÇÔÈ¡Á˸ù«Ë¾780GBµÄÊý¾Ý£¬ £¬£¬£¬²¢Ô¸ÒâÒÔ2800ÍòÃÀÔªµÄ¼ÛÇ®³öÊÛ¡£¡£¡£¡£¡£µ«ÓÉÓÚ±»µÁÊý¾Ý´ó¶àÊÇÔ´´úÂë¶ÔÍøÂç·¸·¨ÍÅ»ïÀ´ËµÃ»ÓÐÈκμÛÖµ£¬ £¬£¬£¬Òò´Ë²¢Î´ÕÒµ½Âò¼Ò¡£¡£¡£¡£¡£Ö®ºóºÚ¿ÍÊÔͼÀÕË÷EA£¬ £¬£¬£¬ÔÚ7ÔÂ14ÈÕÐû²¼ÁË1.3GBµÄFIFAÔ´´úÂë×÷ΪÑù±¾£¬ £¬£¬£¬²¢ÔÚ2ÖÜЧ¹ûÕæÁËËùÓÐÊý¾Ý¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/hackers-leak-full-ea-data-after-failed-extortion-attempt/


2.Ñо¿ÍŶӳÆDarkSide»òÒÔBlackMatterÖ®ÃûÖØÐ»عé


2.jpg


Ñо¿ÍŶӳÆÀÕË÷ÍÅ»ïDarkSide¿ÉÄÜÒÑÖØÐÂÃüÃûΪеÄBlackMatterÖØÐ»ع顣¡£¡£¡£¡£DarkSideÔÚ¹¥»÷ÃÀ¹ú×î´óµÄȼÁϹܵÀColonial Pipelineºó£¬ £¬£¬£¬ÓÚ½ñÄê5ÔÂͻȻ¹Ø±Õ¡£¡£¡£¡£¡£ÉÏÖÜ£¬ £¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷еÄÀÕË÷Èí¼þBlackMatter¡£¡£¡£¡£¡£ÆÊÎö·¢Ã÷£¬ £¬£¬£¬¶þÕßʹÓõļÓÃܳÌÐòÏÕЩÏàͬ£¬ £¬£¬£¬°üÀ¨DarkSideËùÌØÓеÄ×Ô½ç˵Salsa20¾ØÕ󡣡£¡£¡£¡£±ðµÄ£¬ £¬£¬£¬¶þÕß¶¼Ê¹ÓÃÁËDarkSide¶ÀÍ̵ÄRSA-1024ʵÏÖ¡¢½ÓÄÉÁËÏàͬµÄ¼ÓÃÜËã·¨²¢ÇÒÊý¾ÝÐ¹Â¶ÍøÕ¾¶¼Ê¹ÓÃÁËÀàËÆµÄÓïÑÔ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/darkside-ransomware-gang-returns-as-new-blackmatter-operation/


3.RiskIQ·¢Ã÷¶íÂÞ˹Bear TracksÁè¼Ý30¸ö»îÔ¾µÄC2


3.jpg


RiskIQµÄÑо¿Ö°Ô±·¢Ã÷Á˶íÂÞ˹APT29£¨ÓÖ³ÆBear Tracks£©Áè¼Ý30¸ö»îÔ¾µÄC2¡£¡£¡£¡£¡£´Ë´ÎÊÓ²ì×îÏÈÓÚ2021Äê6ÔÂ11ÈÕ£¬ £¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷Óë¶íÂÞ˹µÄÍâ¹úÇ鱨¾Ö(SVR)ÓйصÄAPT×éÖ¯Bear TracksÕýÔÚÆð¾¢µØÊ¹ÓöñÒâÈí¼þWellMessºÍWellMail£¬ £¬£¬£¬ËüÃÇÔÚÒÔÇ°ÔøÓÃÓÚÕë¶ÔÓ¢¹ú¡¢ÃÀ¹úºÍ¼ÓÄôóCOVID-19Ñо¿µÄÌØ¹¤»î¶¯¡£¡£¡£¡£¡£±ðµÄ£¬ £¬£¬£¬RiskIQ»¹¹ûÕæÁËÕâ30¶ą̀ЧÀÍÆ÷µÄÍêÕûÐÅÏ¢£¬ £¬£¬£¬²¢Ô¤¼ÆAPT29»áʹÓÃÕâЩЧÀÍÆ÷¼ÌÐøÇÔȡ֪ʶ²úȨ¡£¡£¡£¡£¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.riskiq.com/blog/external-threat-management/apt29-bear-tracks/


4.PythonÐû²¼Çå¾²¸üУ¬ £¬£¬£¬ÐÞ¸´PyPI´æ´¢¿âÖжà¸öÎó²î


4.jpg


PythonÍŶÓÐû²¼Çå¾²¸üУ¬ £¬£¬£¬ÐÞ¸´ÁËPython Package Index (PyPI)´æ´¢¿âÖеÄ3¸öÎó²î¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄÎó²îÖУ¬ £¬£¬£¬×îÑÏÖØµÄÒ»¸öÔÊÐí¹¥»÷ÕßÔÚPyPIµÄ»ù´¡ÉèÊ©ÉÏÔËÐÐÏÂÁ £¬£¬£¬À´ÇÔÈ¡´úÂë¿âÖеÄÁîÅÆ»òÆäËüÃÜÂ룬 £¬£¬£¬²¢ÇÒÕâЩÁîÅÆ»òÃÜÂ뻹¿É±»ÓÃÀ´»á¼ûºÍ¸Ä¶¯PyPI´úÂë¡£¡£¡£¡£¡£ÁíÍâÁ½¸öÎó²îÖУ¬ £¬£¬£¬Ò»¸öÔÊÐí¹¥»÷Õßɾ³ý²»ÔÚÆä¿ØÖÆÏµÄÏîÄ¿µÄÎĵµ£¬ £¬£¬£¬¶øÁíÒ»¸öÔÊÐí¹¥»÷Õßɾ³ý²»ÔÚÆä¿ØÖÆÏµÄÏîÄ¿ÖеĽÇÉ«¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/python-team-fixes-bug-that-allowed-takeover-of-pypi-repository/


5.KasperskyÐû²¼2021ÄêQ2 DDoS¹¥»÷Ì¬ÊÆµÄÆÊÎö±¨¸æ


5.jpg


KasperskyÐû²¼ÁË2021ÄêQ2 DDoS¹¥»÷Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬ £¬£¬£¬Q2Ïà¶Ô½ÏÁ¿Çå¾²£¬ £¬£¬£¬ÓëÉÏÒ»¼¾¶ÈÏà±ÈDDoS¹¥»÷×ÜÊýÂÔÓÐϽµ£¬ £¬£¬£¬Ô¤¼ÆÕâÒ»Ç÷ÊÆ»áÒ»Á¬µ½Q3¡£¡£¡£¡£¡£±ðµÄ£¬ £¬£¬£¬Q2 DDoS¹¥»÷Ò»Á¬µÄʱ¼äÒ²¿¿½ü³£Ì¬£¬ £¬£¬£¬²î±ðʱÆÚÖ®¼äµÄ²¨¶¯·ù¶È²»Áè¼Ý30%¡£¡£¡£¡£¡£Q2Ôâµ½DDoS¹¥»÷×î¶àµÄÊÇÃÀ¹ú£¨36%£©£¬ £¬£¬£¬Æä´ÎÊÇÖйú£¨10.28%£©ºÍ²¨À¼£¨6.34%£©¡£¡£¡£¡£¡£DDoS¹¥»÷×î»îÔ¾µÄÒ»ÌìÊÇ6ÔÂ2ÈÕ£¬ £¬£¬£¬±¬·¢ÁË1164´Î¹¥»÷£»£»£»£»×µÄÒ»´Î¹¥»÷Ò»Á¬ÁË776Сʱ£¨Áè¼Ý32Ì죩£»£»£»£»60%µÄDDoS¹¥»÷ʹÓÃÁËUDPºé·º£»£»£»£»½©Ê¬ÍøÂçC&CЧÀÍÆ÷×î¶àµÄÊÇÃÀ¹ú£¨47.95%£©¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/ddos-attacks-in-q2-2021/103424/


6.KasperskyÐû²¼2021ÄêQ2 APT¹¥»÷Ì¬ÊÆµÄÆÊÎö±¨¸æ


6.jpg


KasperskyÐû²¼ÁË2021ÄêQ2 APT¹¥»÷Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬ £¬£¬£¬×î½ü¼¸¸öÔ±¬·¢Á˶àÆð¹©Ó¦Á´¹¥»÷£¬ £¬£¬£¬ÆäÖв»·¦¹¥»÷ÊÖÒÕº¬Á¿µÍµ«Í¬ÑùÀֳɣ¬ £¬£¬£¬ÀýÈçBountyGlad¡¢CoughingDownºÍÕë¶ÔCodecovµÄ¹¥»÷¡£¡£¡£¡£¡£APTÍÅ»ïÖ÷ҪʹÓÃÉç»á¹¤³Ì¹¥»÷ÆðÔ´ÈëÇÖÄ¿µÄÍøÂ磬 £¬£¬£¬Ò²Óв¿·Ö×é֯ʹÓÃÁãÈÕÎó²î¹¥»÷ÍøÂç¡£¡£¡£¡£¡£APT×éÖ¯»¹»áһֱˢк͸üÐÂËûÃǵŤ¾ß¼¯£º²»µ«°üÀ¨ÐÂÆ½Ì¨£¬ £¬£¬£¬»¹°üÀ¨Ê¹ÓÃµÄÆäËüÓïÑÔ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/apt-trends-report-q2-2021/103517/