ºÚ¿Í¹ûÕæµç×ÓÒÕ½çEAµÄÊý¾Ý£¬£¬ £¬£¬ £¬°üÀ¨FIFA 21ÓÎÏ·Ô´Â룻£»£»£»£»£»PythonÐû²¼Çå¾²¸üУ¬£¬ £¬£¬ £¬ÐÞ¸´PyPI´æ´¢¿âÖжà¸öÎó²î

Ðû²¼Ê±¼ä 2021-08-02

1.ºÚ¿Í¹ûÕæµç×ÓÒÕ½çEAµÄÊý¾Ý£¬£¬ £¬£¬ £¬°üÀ¨FIFA 21ÓÎÏ·Ô´Âë


1.jpg


7ÔÂ26ÈÕÐÇÆÚÒ»£¬£¬ £¬£¬ £¬ºÚ¿ÍÔÚ°µÍø¹ûÕæµç×ÓÒÕ½çEAµÄÊý¾Ý£¬£¬ £¬£¬ £¬°üÀ¨FIFA 21ÓÎÏ·Ô´Âë¡¢FrostBiteÓÎÏ·ÒýÇæºÍµ÷ÊÔ¹¤¾ßÔ´´úÂëµÈÐÅÏ¢¡£¡£ ¡£¡£¡£¡£¸ÃÊÂÎñ×î³õÓÚ6ÔÂ10ÈÕÅû¶£¬£¬ £¬£¬ £¬ÆäʱºÚ¿ÍÉù³ÆÇÔÈ¡Á˸ù«Ë¾780GBµÄÊý¾Ý£¬£¬ £¬£¬ £¬²¢Ô¸ÒâÒÔ2800ÍòÃÀÔªµÄ¼ÛÇ®³öÊÛ¡£¡£ ¡£¡£¡£¡£µ«ÓÉÓÚ±»µÁÊý¾Ý´ó¶àÊÇÔ´´úÂë¶ÔÍøÂç·¸·¨ÍÅ»ïÀ´ËµÃ»ÓÐÈκμÛÖµ£¬£¬ £¬£¬ £¬Òò´Ë²¢Î´ÕÒµ½Âò¼Ò¡£¡£ ¡£¡£¡£¡£Ö®ºóºÚ¿ÍÊÔͼÀÕË÷EA£¬£¬ £¬£¬ £¬ÔÚ7ÔÂ14ÈÕÐû²¼ÁË1.3GBµÄFIFAÔ´´úÂë×÷ΪÑù±¾£¬£¬ £¬£¬ £¬²¢ÔÚ2ÖÜЧ¹ûÕæÁËËùÓÐÊý¾Ý¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/hackers-leak-full-ea-data-after-failed-extortion-attempt/


2.Ñо¿ÍŶӳÆDarkSide»òÒÔBlackMatterÖ®ÃûÖØÐ»عé


2.jpg


Ñо¿ÍŶӳÆÀÕË÷ÍÅ»ïDarkSide¿ÉÄÜÒÑÖØÐÂÃüÃûΪеÄBlackMatterÖØÐ»عé¡£¡£ ¡£¡£¡£¡£DarkSideÔÚ¹¥»÷ÃÀ¹ú×î´óµÄȼÁϹܵÀColonial Pipelineºó£¬£¬ £¬£¬ £¬ÓÚ½ñÄê5ÔÂͻȻ¹Ø±Õ¡£¡£ ¡£¡£¡£¡£ÉÏÖÜ£¬£¬ £¬£¬ £¬Ñо¿Ö°Ô±·¢Ã÷еÄÀÕË÷Èí¼þBlackMatter¡£¡£ ¡£¡£¡£¡£ÆÊÎö·¢Ã÷£¬£¬ £¬£¬ £¬¶þÕßʹÓõļÓÃܳÌÐòÏÕЩÏàͬ£¬£¬ £¬£¬ £¬°üÀ¨DarkSideËùÌØÓеÄ×Ô½ç˵Salsa20¾ØÕ󡣡£ ¡£¡£¡£¡£±ðµÄ£¬£¬ £¬£¬ £¬¶þÕß¶¼Ê¹ÓÃÁËDarkSide¶ÀÍ̵ÄRSA-1024ʵÏÖ¡¢½ÓÄÉÁËÏàͬµÄ¼ÓÃÜËã·¨²¢ÇÒÊý¾ÝÐ¹Â¶ÍøÕ¾¶¼Ê¹ÓÃÁËÀàËÆµÄÓïÑÔ¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/darkside-ransomware-gang-returns-as-new-blackmatter-operation/


3.RiskIQ·¢Ã÷¶íÂÞ˹Bear TracksÁè¼Ý30¸ö»îÔ¾µÄC2


3.jpg


RiskIQµÄÑо¿Ö°Ô±·¢Ã÷Á˶íÂÞ˹APT29£¨ÓÖ³ÆBear Tracks£©Áè¼Ý30¸ö»îÔ¾µÄC2¡£¡£ ¡£¡£¡£¡£´Ë´ÎÊÓ²ì×îÏÈÓÚ2021Äê6ÔÂ11ÈÕ£¬£¬ £¬£¬ £¬Ñо¿Ö°Ô±·¢Ã÷Óë¶íÂÞ˹µÄÍâ¹úÇ鱨¾Ö(SVR)ÓйصÄAPT×éÖ¯Bear TracksÕýÔÚÆð¾¢µØÊ¹ÓöñÒâÈí¼þWellMessºÍWellMail£¬£¬ £¬£¬ £¬ËüÃÇÔÚÒÔÇ°ÔøÓÃÓÚÕë¶ÔÓ¢¹ú¡¢ÃÀ¹úºÍ¼ÓÄôóCOVID-19Ñо¿µÄÌØ¹¤»î¶¯¡£¡£ ¡£¡£¡£¡£±ðµÄ£¬£¬ £¬£¬ £¬RiskIQ»¹¹ûÕæÁËÕâ30¶ą̀ЧÀÍÆ÷µÄÍêÕûÐÅÏ¢£¬£¬ £¬£¬ £¬²¢Ô¤¼ÆAPT29»áʹÓÃÕâЩЧÀÍÆ÷¼ÌÐøÇÔȡ֪ʶ²úȨ¡£¡£ ¡£¡£¡£¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.riskiq.com/blog/external-threat-management/apt29-bear-tracks/


4.PythonÐû²¼Çå¾²¸üУ¬£¬ £¬£¬ £¬ÐÞ¸´PyPI´æ´¢¿âÖжà¸öÎó²î


4.jpg


PythonÍŶÓÐû²¼Çå¾²¸üУ¬£¬ £¬£¬ £¬ÐÞ¸´ÁËPython Package Index (PyPI)´æ´¢¿âÖеÄ3¸öÎó²î¡£¡£ ¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄÎó²îÖУ¬£¬ £¬£¬ £¬×îÑÏÖØµÄÒ»¸öÔÊÐí¹¥»÷ÕßÔÚPyPIµÄ»ù´¡ÉèÊ©ÉÏÔËÐÐÏÂÁ£¬ £¬£¬ £¬À´ÇÔÈ¡´úÂë¿âÖеÄÁîÅÆ»òÆäËüÃÜÂ룬£¬ £¬£¬ £¬²¢ÇÒÕâЩÁîÅÆ»òÃÜÂ뻹¿É±»ÓÃÀ´»á¼ûºÍ¸Ä¶¯PyPI´úÂë¡£¡£ ¡£¡£¡£¡£ÁíÍâÁ½¸öÎó²îÖУ¬£¬ £¬£¬ £¬Ò»¸öÔÊÐí¹¥»÷Õßɾ³ý²»ÔÚÆä¿ØÖÆÏµÄÏîÄ¿µÄÎĵµ£¬£¬ £¬£¬ £¬¶øÁíÒ»¸öÔÊÐí¹¥»÷Õßɾ³ý²»ÔÚÆä¿ØÖÆÏµÄÏîÄ¿ÖеĽÇÉ«¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/python-team-fixes-bug-that-allowed-takeover-of-pypi-repository/


5.KasperskyÐû²¼2021ÄêQ2 DDoS¹¥»÷Ì¬ÊÆµÄÆÊÎö±¨¸æ


5.jpg


KasperskyÐû²¼ÁË2021ÄêQ2 DDoS¹¥»÷Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£ ¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬ £¬£¬ £¬Q2Ïà¶Ô½ÏÁ¿Çå¾²£¬£¬ £¬£¬ £¬ÓëÉÏÒ»¼¾¶ÈÏà±ÈDDoS¹¥»÷×ÜÊýÂÔÓÐϽµ£¬£¬ £¬£¬ £¬Ô¤¼ÆÕâÒ»Ç÷ÊÆ»áÒ»Á¬µ½Q3¡£¡£ ¡£¡£¡£¡£±ðµÄ£¬£¬ £¬£¬ £¬Q2 DDoS¹¥»÷Ò»Á¬µÄʱ¼äÒ²¿¿½ü³£Ì¬£¬£¬ £¬£¬ £¬²î±ðʱÆÚÖ®¼äµÄ²¨¶¯·ù¶È²»Áè¼Ý30%¡£¡£ ¡£¡£¡£¡£Q2Ôâµ½DDoS¹¥»÷×î¶àµÄÊÇÃÀ¹ú£¨36%£©£¬£¬ £¬£¬ £¬Æä´ÎÊÇÖйú£¨10.28%£©ºÍ²¨À¼£¨6.34%£©¡£¡£ ¡£¡£¡£¡£DDoS¹¥»÷×î»îÔ¾µÄÒ»ÌìÊÇ6ÔÂ2ÈÕ£¬£¬ £¬£¬ £¬±¬·¢ÁË1164´Î¹¥»÷£»£»£»£»£»£»×µÄÒ»´Î¹¥»÷Ò»Á¬ÁË776Сʱ£¨Áè¼Ý32Ì죩£»£»£»£»£»£»60%µÄDDoS¹¥»÷ʹÓÃÁËUDPºé·º£»£»£»£»£»£»½©Ê¬ÍøÂçC&CЧÀÍÆ÷×î¶àµÄÊÇÃÀ¹ú£¨47.95%£©¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/ddos-attacks-in-q2-2021/103424/


6.KasperskyÐû²¼2021ÄêQ2 APT¹¥»÷Ì¬ÊÆµÄÆÊÎö±¨¸æ


6.jpg


KasperskyÐû²¼ÁË2021ÄêQ2 APT¹¥»÷Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£ ¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬ £¬£¬ £¬×î½ü¼¸¸öÔ±¬·¢Á˶àÆð¹©Ó¦Á´¹¥»÷£¬£¬ £¬£¬ £¬ÆäÖв»·¦¹¥»÷ÊÖÒÕº¬Á¿µÍµ«Í¬ÑùÀֳɣ¬£¬ £¬£¬ £¬ÀýÈçBountyGlad¡¢CoughingDownºÍÕë¶ÔCodecovµÄ¹¥»÷¡£¡£ ¡£¡£¡£¡£APTÍÅ»ïÖ÷ҪʹÓÃÉç»á¹¤³Ì¹¥»÷ÆðÔ´ÈëÇÖÄ¿µÄÍøÂ磬£¬ £¬£¬ £¬Ò²Óв¿·Ö×é֯ʹÓÃÁãÈÕÎó²î¹¥»÷ÍøÂç¡£¡£ ¡£¡£¡£¡£APT×éÖ¯»¹»áһֱˢк͸üÐÂËûÃǵŤ¾ß¼¯£º²»µ«°üÀ¨ÐÂÆ½Ì¨£¬£¬ £¬£¬ £¬»¹°üÀ¨Ê¹ÓÃµÄÆäËüÓïÑÔ¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/apt-trends-report-q2-2021/103517/