Å·ÖÞÍøÂçÇå¾²¾ÖENISAÐû²¼2021ÄêÍþÐ²Ì¬ÊÆÆÊÎö±¨¸æ
Ðû²¼Ê±¼ä 2021-11-04Ñо¿ÍŶӷ¢Ã÷ÏÕЩÍþвËùÓдúÂëµÄÎó²îTrojan Source
½£ÇÅ´óѧµÄÑо¿Ö°Ô±ÔÚ11ÔÂ1ÈÕ¹ûÕæÁËÒ»¸öÓ°Ïì´ó´ó¶¼ÅÌËã»ú´úÂë±àÒëÆ÷ºÍÐí¶àÈí¼þ¿ª·¢ÇéÐεÄÎó²îTrojan Source¡£¡£¡£¡£¡£¡£¸ÃÎó²î±£´æÓÚUnicodeÖУ¬£¬£¬ÓÐÁ½ÖÖʹÓÃÒªÁ죺ÆäÒ»ÊÇʹÓÃUnicodeµÄBidiËã·¨£¨CVE-2021-42574£©£¬£¬£¬¶Ô×Ö·û¾ÙÐÐÊÓ¾õÉϵÄÖØÐÂÅÅÐò£¬£¬£¬Ê¹Æä·ºÆðÓë±àÒëÆ÷Ï¢ÕùÊÍÆ÷Ëù²î±ðµÄÂ߼˳Ðò£»£»£»ÁíÒ»ÖÖÊÇͬÐÎÎÄ×Ö¹¥»÷(CVE-2021-42694)£¬£¬£¬¼´Ê¹ÓÃÔÚÊÓ¾õÉÏ¿´ÆðÀ´ÏàËÆµÄ²î±ð×Ö·û¡£¡£¡£¡£¡£¡£¸ÃÎó²îÊÊÓÃÓÚC¡¢C++¡¢C#¡¢JavaScript¡¢JavaµÈÆÕ±éʹÓõÄÓïÑÔ£¬£¬£¬¿ÉÓÃÓÚ¹©Ó¦Á´¹¥»÷¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.trojansource.codes/
Ö鱦ÉÌGraffÔâµ½ContiÀÕË÷¹¥»÷£¬£¬£¬ÌØÀÊÆÕµÈÈËÐÅϢй¶
10ÔÂ31ÈÕ£¬£¬£¬ÖðÈÕÓʱ¨±¨µÀÀÕË÷ÍÅ»ïConti¹¥»÷ÁËÖ鱦ÉÌGraff²¢ÇÔÈ¡´ó×ÚÊý¾Ý¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬¹¥»÷ÕßÒÑÔÚ°µÍøÉϹûÕæÁËÉæ¼°ÌÆÄɵ¡¤ÌØÀÊÆÕ¡¢°ÂÆÕÀ¡¤Î¸¥ÈðºÍ´óÎÀ¡¤±´¿ËººÄ·µÄ69000·ÝÉñÃØÎļþ£¬£¬£¬×÷ΪÑù±¾Êý¾Ý¡£¡£¡£¡£¡£¡£²¢Éù³ÆÏÖÔÚ¹ûÕæµÄÐÅÏ¢Éæ¼°Á˸ù«Ë¾Ô¼11000¸ö¿Í»§£¬£¬£¬½öÕ¼ÆäÇÔÈ¡µÄËùÓÐÊý¾ÝµÄ1%¡£¡£¡£¡£¡£¡£ContiµÄÊê½ðºÜÊǸߣ¬£¬£¬Ô¼Õ¼Êܺ¦ÕßÄêÊÕÈëµÄ10%£¬£¬£¬¶øGraffÔÚ2019ÄêµÄÊÕÈëΪ4.5ÒÚÓ¢°÷¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/123980/cyber-crime/conti-ransomware-graff-jeweller.html
ÃÀ¹úÒ½ÁƱ£½¡Ð§À͹«Ë¾PHMÈ·ÈÏÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷
ÃÀ¹úÒ½ÁƱ£½¡Ð§À͹«Ë¾Professional Healthcare Management(PHM)ÔÚ10ÔÂ31ÈÕÈ·ÈÏÆäÔâµ½ÁËÀÕË÷¹¥»÷¡£¡£¡£¡£¡£¡£¹¥»÷±¬·¢ÔÚ9ÔÂ14ÈÕ£¬£¬£¬Ð¹Â¶Á˿ͻ§µÄÐÕÃû¡¢Éç»áÇå¾²ºÅÂë¡¢¿µ½¡°ü¹ÜÐÅÏ¢¡¢´¦·½Ãû³ÆºÍÕï¶Ï´úÂëµÈÐÅÏ¢¡£¡£¡£¡£¡£¡£PHM³Æ·¢Ã÷¹¥»÷ºóÁ¬Ã¦½ÓÄɲ½·¥±£»£»£»¤Æäϵͳ²¢»Ö¸´ÔËÓª£¬£¬£¬ÏÖÔÚÕýÔÚ֪ͨÄÇЩ¿ÉÄÜÊÜ´ËÓ°ÏìµÄ¿Í»§£¬£¬£¬²¢½«ÎªÆäÌṩÃâ·ÑµÄÉí·Ý¼à¿ØºÍ±£»£»£»¤Ð§ÀÍ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.databreaches.net/tn-professional-healthcare-management-discloses-ransomware-incident/
Kaspersky·¢Ã÷ʹÓÃÆäAmazon SESÁîÅÆµÄ´¹Âڻ
Çå¾²¹«Ë¾KasperskyÔÚ±¾ÖÜÒ»Ðû²¼ÁËÒ»·Ýͨ¸æ£¬£¬£¬³ÆÓд¹ÂڻʹÓÃÆäAmazon SESÁîÅÆ¡£¡£¡£¡£¡£¡£´Ë´Î»î¶¯Ê¹ÓÃÁËKasperskyµÄnoreply@sm.kaspersky.comµÈÕýÍâµØµã£¬£¬£¬²¢Ê¹ÓÃÁË´¹ÂÚ¹¤¾ß°üMIRCBOOT£¬£¬£¬Ö¼ÔÚÇÔȡĿµÄµÄOffice 365ƾ֤¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±È·¶¨£¬£¬£¬²¿·ÖÓʼþÊÇʹÓÃÕýµ±µÄÑÇÂíÑ·SESÁîÅÆ·¢Ë͵쬣¬£¬´Ë»á¼ûÁîÅÆÊÇÔÚ²âÊÔ2050.earthÍøÕ¾µÄʱ´ú½ÒÏþ¸øµÚÈý·½³Ð°üÉ̵쬣¬£¬¸ÃÍøÕ¾ÏÖÔÚÒ²ÍйÜÔÚÑÇÂíÑ·ÉÏ£¬£¬£¬·¢Ã÷¹¥»÷»î¶¯ºóÁ¬Ã¦×÷·ÏÁË´ËSESÁîÅÆ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/office-365-phishing-campaign-kasperskys-amazon-ses-token/175915/
Cisco TalosÐû²¼2021ÄêQ3Ó¦¼±ÏìÓ¦ÊÂÎñµÄÆÊÎö±¨¸æ
Cisco TalosÔÚ10ÔÂ28ÈÕÐû²¼ÁË2021ÄêQ3Ó¦¼±ÏìÓ¦ÊÂÎñµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬ÔÚ2021Äê7ÔÂÖÁ10ÔÂʱ´ú£¬£¬£¬ÀÕË÷Èí¼þÒÀÈ»ÊDZ¾¼¾¶È×îÖ÷ÒªµÄÍþв£¬£¬£¬Ô¼Õ¼ËùÓÐÍþвµÄ38%£¬£¬£¬»¹·ºÆðÁËÐí¶àеÄÀÕË÷Èí¼þ¼Ò×åVice Society¡¢Hive¡¢Karma¡¢Grief¡¢CryptBDºÍThanos¡£¡£¡£¡£¡£¡£µç×ÓÓʼþÊÇ×î³£¼ûµÄ³õʼѬȾǰÑÔ£¬£¬£¬¶øÈ±·¦¶àÒòËØÉí·ÝÑéÖ¤(MFA)³ÉΪÆóÒµÇå¾²µÄ×î´óÕϰ֮һ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2021/10/quarterly-report-incident-response.html
Å·ÖÞÍøÂçÇå¾²¾ÖENISAÐû²¼2021ÄêÍþÐ²Ì¬ÊÆÆÊÎö±¨¸æ
Å·ÖÞÍøÂçÇå¾²¾ÖENISAÔÚ10ÔÂ27ÈÕÐû²¼ÁË2021ÄêÍþÐ²Ì¬ÊÆÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£±¨¸æÈ·¶¨ÁËÖ÷ÒªÍþв¡¢¹¥»÷ÊÖÒÕ¡¢ÖµµÃ×¢ÖØµÄÊÂÎñºÍÏà¹ØÇ÷ÊÆ£¬£¬£¬»¹ÌṩÁ˽µµÍΣº¦µÄ½¨Òé¡£¡£¡£¡£¡£¡£±¾±¨¸æÖ÷ÒªÌÖÂÛÁË9ÖÖÍøÂçÇå¾²ÍþвÖÖ±ð£ºÀÕË÷Èí¼þ¡¢¶ñÒâÈí¼þ¡¢¼ÓÃÜÐ®ÖÆ¡¢µç×ÓÓʼþÏà¹ØÍþв¡¢¶ÔÊý¾ÝµÄÍþв¡¢¶Ô¿ÉÓÃÐÔºÍÍêÕûÐÔµÄÍþв¡¢ÐéαÐÅÏ¢£¨¹ýʧÐÅÏ¢£©¡¢·Ç¶ñÒâÍþв¡¢ºÍ¹©Ó¦Á´¹¥»÷¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬±¨¸æÖ¸³ö£¬£¬£¬ÀÕË÷Èí¼þ¹¥»÷ÒѳÉΪÖ÷ÒªÍþв¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.enisa.europa.eu/publications/enisa-threat-landscape-2021