ÓÎÏ·¹«Ë¾Ubisoft³ÆÉèÖùýʧÎèÁ¦È«¿ªÍæ¼ÒµÄÊý¾Ýй¶
Ðû²¼Ê±¼ä 2021-12-24ÓÎÏ·¹«Ë¾Ubisoft³ÆÉèÖùýʧÎèÁ¦È«¿ªÍæ¼ÒµÄÊý¾Ýй¶
·¨¹úÓÎÏ·¹«Ë¾Óý±Ì£¨Ubisoft£©ÔÚ12ÔÂ21ÈÕÐû²¼Í¨¸æ³Æ£¬£¬£¬£¬ÎèÁ¦È«¿ªÍæ¼ÒµÄÊý¾ÝÒѾй¶¡£¡£¡£¡£¡£´Ë´ÎÊÂÎñÊÇÓÉÓÚÉèÖùýʧµ¼Öµģ¬£¬£¬£¬ÎÊÌâÔÚ·¢Ã÷ºóÁ¬Ã¦»ñµÃÐÞ¸´¡£¡£¡£¡£¡£µ«ÔÚ´Ë֮ǰ£¬£¬£¬£¬Î´¾ÊÚȨµÄСÎÒ˽¼Ò¿ÉÄÜÒѾ»á¼û²¢¸´ÖƲ¿·ÖÍæ¼ÒÊý¾Ý¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬£¬½ö¡°ÊÖÒÕ±êʶ·û¡±Êܵ½Ó°Ï죬£¬£¬£¬°üÀ¨Íæ¼Ò±êÇ©¡¢Ð¡ÎÒ˽¼Ò×ÊÁÏIDºÍ×°±¸ID£¬£¬£¬£¬ÒÔ¼°Â¼ÖƺÍÉÏ´«µÄÊÓÆµµÈ£¬£¬£¬£¬UbisoftµÄÈκÎÕÊ»§¾ùδÊܵ½Ó°Ïì¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/125885/data-breach/ubisoft-data-breach.html
CiscoÅû¶ÃÀ¹úGarettµÄ½ðÊô̽²âÆ÷ÖÐ9¸öÎó²îµÄϸ½Ú
12ÔÂ20ÈÕ£¬£¬£¬£¬Cisco TalosÅû¶Garett²½ÐÐͨ¹ýʽ½ðÊô̽²âÆ÷ÖÐ9¸öÎó²îµÄϸ½Ú¡£¡£¡£¡£¡£GarrettÊÇÃÀ¹úÖøÃûµÄ½ðÊô̽²âÆ÷ÖÆÔìÉÌ£¬£¬£¬£¬Æä²úƷͨ³£°²ÅÅÔÚÖ÷Òª³¡ºÏÖУ¬£¬£¬£¬ÀýÈçÌåÓý³¡¹Ý¡¢»ú³¡¡¢ÒøÐС¢²©Îï¹Ý¡¢Õþ¸®²¿·ÖºÍ·¨ÔºµÈ¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄ½ÏΪÑÏÖØµÄÎó²îÊÇ»ùÓÚ¿ÍÕ»µÄ»º³åÇøÒç³öÎó²î£¨CVE-2021-21901ºÍCVE-2021-21903£©ºÍĿ¼±éÀúÎó²î£¨CVE-2021-21904£©¡£¡£¡£¡£¡£ÕâЩÎó²îÓÚ8ÔÂ17ÈÕ±»Åû¶£¬£¬£¬£¬²¢ÓÚ12ÔÂ13ÈÕÐÞ¸´¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/walk-through-metal-detectors-software-flaws-hackable/
TheAnalyst·¢Ã÷·Ö·¢Ð¶ñÒâÈí¼þDridexµÄ´¹Âڻ
¾ÝýÌå12ÔÂ22ÈÕ±¨µÀ£¬£¬£¬£¬TheAnalyst¹ûÕæÁË·Ö·¢Ð¶ñÒâÈí¼þDridexµÄ´¹Âڻ¡£¡£¡£¡£¡£´Ë´Î»î¶¯ÒÔ¿ª³ýÓʼþΪÓÕ¶ü£¬£¬£¬£¬¼û¸æÊÕ¼þÈËËûÃǽ«ÓÚ12ÔÂ24ÈÕ±»¿ª³ý£¬£¬£¬£¬ÇҴ˾öÒé²»¿É×÷·Ï¡£¡£¡£¡£¡£ÓʼþÖÐÉÐÓÐÒ»¸öExcel±í¸ñTermLetter.xls £¬£¬£¬£¬¾Ý³ÆÆäÖаüÀ¨ÊÕ¼þÈ˱»¿ª³ýµÄÔµ¹ÊÔÓÉ¡£¡£¡£¡£¡£ÊÕ¼þÈË·¿ªExcelÎļþºó»á¿´µ½Ò»¸öÄ£ºý²»ÇåµÄÖ°Ô±±í£¬£¬£¬£¬²¢±»ÒªÇóÆôÓÃÄÚÈÝÀ´×¼È·Éó²éÎļþ¡£¡£¡£¡£¡£ÊÕ¼þÈËÆôÓÃÄÚÈݺó»áµ¯³ö´°¿ÚÏÔʾ¡°Ç×°®µÄÔ±¹¤Ê¥µ®¿ìÀÖ£¡¡±£¬£¬£¬£¬Õâʱ¶ñÒâºêÒѱ»Ö´ÐС£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/dridex-malware-trolls-employees-with-fake-job-termination-emails/
Ñо¿ÍŶӷ¢Ã÷ʹÓÃTelegramÈö²¥EchelonµÄ»î¶¯
12ÔÂ23ÈÕ£¬£¬£¬£¬SafeGuard Cyber³ÆÆä·¢Ã÷ÔÚTelegramÖзַ¢ÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þEchelonµÄ»î¶¯¡£¡£¡£¡£¡£¸ÃEchelonÑù±¾ÓÚ10Ô·ÝÊ״α»¼ì²âµ½£¬£¬£¬£¬Ê¹ÓÃSmokes NightµÄÃû³ÆÔÚ¹ØÓÚ¼ÓÃÜÇ®±ÒµÄƵµÀÀï¾ÙÐÐÈö²¥»î¶¯£¬£¬£¬£¬²¢½öÕë¶Ô¸ÃƵµÀµÄÐÂÓû§¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃ.RARÎļþpresent).RAR·Ö·¢Echelon£¬£¬£¬£¬¸ÃÎļþ°üÀ¨pass-123.txt¡¢DotNetZip.dllºÍPresent.exe 3¸öÎļþ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/telegram-steal-crypto-wallet-credentials/177266/
ÃÀ¹úÎ÷¸¥¼ªÄáÑÇÖÝÒ½ÁÆ»ú¹¹MHS³ÆÆäÔâµ½BEC¹¥»÷
ÃÀ¹úÎ÷¸¥¼ªÄáÑÇÖݵÄMonongalia Health System(MHS)ÔÚ12ÔÂ21ÈÕÐû²¼Í¨¸æ£¬£¬£¬£¬³ÆÆäÔâµ½ÁËBEC¹¥»÷¡£¡£¡£¡£¡£MHS×îÏȲ¢²»ÖªµÀÆäÒÑÔâµ½¹¥»÷£¬£¬£¬£¬Ö±µ½Ò»¼Ò¹©Ó¦É̳ÆÔÚ½ñÄê7ÔÂ28ÈÕûÓÐÊÕµ½¸¶¿î£¬£¬£¬£¬¸Ã»ú¹¹²Å×îÏÈÕö¿ªÊӲ졣¡£¡£¡£¡£ÊӲ췢Ã÷£¬£¬£¬£¬¹¥»÷ÕßÔÚ5ÔÂ10ÈÕÖÁ8ÔÂ15ÈÕÈëÇÖÁ˶à¸öMHSÔ±¹¤µÄÓʼþÕÊ»§£¬£¬£¬£¬²¢»á¼ûÁËÓʼþ¼°Æä¸½¼þ£¬£¬£¬£¬È»ºóʹÓÃijMHS³Ð°üÉ̵ÄÕÊ»§Ã°³äMHSÀ´ÆÈ¡×ʽ𡣡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬¹¥»÷»¹Ð¹Â¶Á˲¿·Ö»¼ÕߺÍÔ±¹¤µÄÐÅÏ¢¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/bec-attack-on-monongalia-health-1/
NCC GroupÐû²¼2021Äê11ÔÂÍøÂçÇå¾²Ì¬ÊÆµÄÆÊÎö±¨¸æ
12ÔÂ21ÈÕ£¬£¬£¬£¬NCC GroupÐû²¼2021Äê11ÔÂÍøÂçÇå¾²Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬¹¥»÷ÕßµÄÖØµãÕýÔÚתÏò¹Ù·½×éÖ¯£¬£¬£¬£¬Óë10Ô·ÝÏà±È£¬£¬£¬£¬´ËÀà×éÖ¯Ôâµ½µÄ¹¥»÷ÔöÌíÁË400%£»£»£»±¾ÔÂÀÕË÷¹¥»÷ÔöÌíÁË1.9%£»£»£»±±ÃÀºÍÅ·ÖÞÈÔÈ»ÊÇÊܹ¥»÷×î¶àµÄµØÇø£¬£¬£¬£¬»®·ÖÔâµ½154ºÍ96´Î¹¥»÷¡£¡£¡£¡£¡£11ÔµÄÖ÷ÒªÀÕË÷Èí¼þΪPYSA£¨Ò²±»³ÆÎªMespinoza£©ºÍLockbit£¬£¬£¬£¬ÆäÖÐPYSAµÄ¹¥»÷»î¶¯½ÏÖ®ÉÏÔÂÔöÌí50%£¬£¬£¬£¬ÓâÔ½ÁËConti£¨Ï½µ9.1%£©¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://newsroom.nccgroup.com/news/ncc-group-monthly-threat-pulse-november-2021-439934