ºÚ¿ÍÈëÇÖÌØÀÊÆÕ¾ºÑ¡ÍøÕ¾²¢Èö²¥ÐéαÐÅÏ¢£»ACTI³Æ¶íºÚ¿Í×éÖ¯TurlaÈëÇÖÅ·ÖÞÒ»¸öÕþ¸®×éÖ¯

Ðû²¼Ê±¼ä 2020-10-29
1.ºÚ¿ÍÈëÇÖÌØÀÊÆÕ¾ºÑ¡ÍøÕ¾²¢Èö²¥ÐéαÐÅÏ¢


1.jpg


Õþ¸®¹ÙÔ±ÌåÏÖ£¬ºÚ¿ÍÔÚÑ¡¾ÙÈÕǰһÖܵÄÐÇÆÚ¶þÈëÇÖÁËÌÆÄɵ¡¤ÌØÀÊÆÕµÄ¾ºÑ¡ÍøÕ¾¡£donaldjtrump.comÍøÕ¾±»¡°Õâ¸öÍøÕ¾±»²é·âÁË¡±ÐÂÎÅËùÈ¡´ú£¬²¢ÌåÏÖ¡°ÌìÏÂÒѾ­Êܹ»ÁËÌÆÄɵ¡¤J¡¤ÌØÀÊÆÕ×ÜͳÌìÌìÉ¢²¥µÄ¼ÙÐÂÎÅ¡±¡£±ðµÄ£¬ºÚ¿Í»¹ºôÓõÍøÃñ¾èÔùMoneroÊý×ÖÇ®±ÒÒÔÖ§³Ö»ò×赲й¶ÓëÌØÀÊÆÕÓйصÄÖ¤¾Ý¡£ÌØÀÊÆÕ¾ºÑ¡½²»°ÈËTim MurtaughÌåÏÖ£¬¸ÃÍøÕ¾ºÜ¿ì»ñµÃÐÞ¸´²¢Ã»ÓÐÈκÎÃô¸ÐÊý¾Ýй¶£¬´Ë´Î¹¥»÷µÄȪԴ»¹ÔÚÊÓ²ìÖС£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/trump-campaign-website-broken-hackers


2.ACTI³Æ¶íºÚ¿Í×éÖ¯TurlaÈëÇÖÅ·ÖÞÒ»¸öÕþ¸®×éÖ¯


2.jpg


ƾ֤°£É­ÕÜÍøÂçÍþвÇ鱨£¨ACTI£©µÄ×îб¨¸æ£¬¶íÂÞ˹µÄºÚ¿Í×éÖ¯TurlaÈëÇÖÁËÒ»¸öδ¹ûÕæÃû³ÆµÄÅ·ÖÞÕþ¸®×éÖ¯µÄϵͳ¡£ÎªÁËÈëÇÖ×éÖ¯ÍøÂ磬¹¥»÷ÕßʹÓÃÁË×î½ü¸üеÄÔ¶³ÌÖÎÀíľÂí£¨RAT£©ºÍ»ùÓÚÔ¶³ÌÀú³ÌŲÓã¨RPC£©µÄºóÃųÌÐò£¬ÆäÖаüÀ¨HyperStack¡£ACTIÌåÏÖ£¬Õâ´Î¹¥»÷ÍêÈ«ÇкÏTurla´ÓÊÂÌØ¹¤Ô˶¯µÄÄîÍ·£¬ÏÖÔÚËüÒѾ­ÆÆËðÁËÀ´×Ô100¶à¸ö¹ú¼ÒµÄÕþ¸®¡¢´óʹ¹ÝÒÔ¼°½ÌÓýºÍÑо¿»ú¹¹µÄÊýǧ¸öϵͳ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/russian-turla-hackers-breach-european-government-organization/


3.MicrosoftÐû²¼KB4577586¸üУ¬×èֹʹÓÃAdobe Flash


3.jpg


MicrosoftÐû²¼ÁËKB4577586¸üУ¬ÒÔ×èֹʹÓÃWindowsÉϵÄAdobe Flash¡£´Ë´Î¸üнö¿Éͨ¹ýMicrosoft Catalog»ñµÃ¡£MicrosoftÉùÃ÷¸Ã¸üн«×Ô¶¯É¾³ýAdobe Flash Player£¬µ«Éв»ÇåÎúÈ·ÇÐɾ³ýµÄÄÚÈÝ¡£¾­ÓɲâÊÔ£¬´Ë¸üÐÂɾ³ýÁËWindows 10ÖÐÀ¦°óµÄFlash Player£¨32룩°æ±¾£¬µ«²»»áɾ³ýÈκÎ×ÔÁ¦°æ±¾µÄAdobe Flash Player¡£MicrosoftÔòÌåÏÖ»á2021ÄêÍ·Flashµ½ÆÚºó¶ÔFlash Player¾ÙÐдó¹æÄ£É¾³ý¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-update-to-remove-adobe-flash-from-windows/


4.Enel GroupÔÙ´ÎѬȾÀÕË÷Èí¼þ£¬Ð¹Â¶5TBµÄÊý¾Ý


4.jpg


¿ç¹úÄÜÔ´¹«Ë¾Enel Group½ñÄêÔâµ½µÚ¶þ´ÎÀÕË÷Èí¼þ¹¥»÷£¬NetwalkerÉù³ÆÆäÇÔÈ¡ÁË5TBµÄÊý¾Ý²¢ÀÕË÷1400ÍòÃÀÔªÊê½ð¡£EnelÊÇÅ·ÖÞÄÜÔ´ÁìÓò×î´óµÄ¹«Ë¾Ö®Ò»£¬ÔÚ40¸ö¹ú¼ÒºÍµØÇøÓµÓÐ6100Íò¿Í»§¡£½ñÄê6Ô³õ£¬EnelµÄÄÚ²¿ÍøÂçÔâµ½SnakeÀÕË÷Èí¼þµÄ¹¥»÷£¬10ÔÂ19ÈÕÓÖÔâµ½NetwalkerÀÕË÷Èí¼þµÄ¹¥»÷¡£ÏÖÔÚ£¬NetwalkerÒÑÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾Ðû²¼Á˱»µÁÊý¾ÝµÄ½ØÍ¼£¬²¢ÌåÏÖ»áÔÚÒ»ÖÜÄÚ¹ûÕæÆäÖеÄÒ»²¿·Ö¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/enel-group-hit-by-ransomware-again-netwalker-demands-14-million/


5.¼Ò¾ß¹«Ë¾SteelcaseѬȾRyukµ¼ÖÂϵͳÔÝʱ¹Ø±Õ


5.jpg


È«Çò×î´óµÄ°ì¹«¼Ò¾ßÖÆÔìÉÌSteelcase³ÆÆäÔÚ10ÔÂ22ÈÕÔâµ½RyukÀÕË÷Èí¼þ¹¥»÷£¬²¢µ¼ÖÂϵͳÔÝʱ¹Ø±Õ¡£¸Ã¹«Ë¾Ðû²¼ÉùÃ÷³ÆÆäÔÚÐÅÏ¢ÊÖÒÕϵͳÉÏ·¢Ã÷ÁËÍøÂç¹¥»÷£¬²¢Ñ¸ËÙ½ÓÄÉÁËһϵÁÐ×èÖ¹²½·¥À´½â¾öÕâÖÖÇéÐΣ¬°üÀ¨ÔÝʱ¹Ø±ÕÊÜÓ°ÏìµÄϵͳºÍÏà¹Ø²Ù×÷¡£ÏÖÔÚ£¬¹«Ë¾Éв»ÖªµÀ´Ë¹¥»÷µ¼ÖµÄÏêϸϵͳÊý¾Ýɥʧ»ò×ʲúËðʧ£¬µ«¹«Ë¾Ô¤¼Æ¸ÃÊÂÎñ²»»á¶ÔÆäÓªÒµÔËÓª»ò²ÆÎñÒµ¼¨±¬·¢ÖØ´óÓ°Ïì¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/steelcase-furniture-giant-hit-by-ryuk-ransomware-attack/    


6.VeracodeÐû²¼Ó¦ÓóÌÐòÇå¾²Ì¬ÊÆµÄÆÊÎö±¨¸æ


6.jpg


VeracodeÐû²¼µÚ11ÆÚÈí¼þÇ徲״̬±¨¸æ£¬¶ÔÓ¦ÓóÌÐòÇå¾²Ì¬ÊÆ¾ÙÐÐÁËÆÊÎö¡£±¨¸æ¶Ô130000¸öÓ¦ÓóÌÐò¾ÙÐÐÁËÆÊÎö£¬·¢Ã÷76£¥µÄÓ¦ÓÃÖÁÉÙ¾ßÓÐÒ»¸öÇå¾²Îó²î£¬µ«Ö»ÓÐ24£¥µÄÓ¦ÓþßÓиßÑÏÖØÐÔÎó²î¡£±ðµÄ£¬¸Ã±¨¸æ»¹·¢Ã÷ÁËһЩ¿ÉÌá¸ßÎó²îÐÞ¸´ÂʵÄÒªÁ죬ÈçÍŽáʹÓöàÖÖɨÃèÀàÐÍ£¨°üÀ¨¾²Ì¬ÆÊÎö£¨SAST£©£¬¶¯Ì¬ÆÊÎö£¨DAST£©ºÍÈí¼þ×éÉíÆÊÎö£¨SCA£©£©£¬Í³¼ÆÅú×¢ÄÇЩͬʱʹÓÃSASTºÍDASTµÄÈË¿ÉÒÔ24ÌìÄÚÐÞ¸´Ò»°ëµÄȱÏÝ¡£


Ô­ÎÄÁ´½Ó£º

https://www.veracode.com/sites/default/files/pdf/sossv11/soss_infographic_v11.pdf