³¯ºÚ¿ÍÀûÓÃαÔìµÄÉ罻ýÌåÕÊ»§½«Äþ¾²Ñо¿ÈËÔ±×÷ΪĿ±ê£»ÒÁÀÊTA453µÄÐÂÐж¯BadBloodÖ¼ÔÚÇÔȡҽѧÑо¿ÕߵĽá¹û

Ðû²¼Ê±¼ä 2021-04-02

1.Ó¡¶ÈECU WorldwideѬȾMount Locker£¬2TBÊý¾Ýй¶


1.jpg


ECU WorldwideÊÇÎÞÓªÔË´¬µÄ¹«¹²³ÐÔËÈË(NVOCC)£¬Ö÷Òª´Óʼ¯×°ÏäµÄÆ´ÏäÔËÊä(LCL)£¬ÊÇÓ¡¶È×î´óµÄÉÏÊй«Ë¾Ö®Ò»¡£¸Ã¹«Ë¾ÔÚ2ÔÂ16ÈÕ³ÂË߯äÔâµ½ÁËÍøÂç¹¥»÷£¬µ¼Ö²¿ÃÅÔÚÏ߯½Ì¨ºÍµç×ÓÓʼþϵͳÔÝʱÖжÏ¡£ÀÕË÷Èí¼þÍÅ»ïMount LockerÓÚÉÏÖÜÈÕÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾·¢Ìû³ÆËûÃÇ´ÓECUÇÔÈ¡ÁË2TBµÄÊý¾Ý£¬µ«ÈÔδ¹ûÈ»ÓйØÕâЩÊý¾ÝµÄÈκÎÐÅÏ¢£¬Òò´ËÉв»Çå³þй¶Êý¾ÝµÄÀàÐÍ¡£


Ô­ÎÄÁ´½Ó£º

https://www.freightwaves.com/news/hackers-threaten-shipping-firm-ecu-worldwide-with-data-leak


2.Òâ´óÀûBoggi MilanoÔâµ½Ragnarok¹¥»÷£¬40GBÊý¾Ý±»ÇÔ


2.jpg


Òâ´óÀûÄÐ×°Æ·ÅÆBoggi MilanoÔâµ½ºÚ¿Í×éÖ¯RagnarokµÄ¹¥»÷£¬40GBÊý¾Ý±»ÇÔ¡£¹¥»÷·¢ÉúÔÚ±¾ÖÜÈý£¬¸Ã¹«Ë¾Ä¿Ç°ÕýÔÚÓëÓйز¿ÃźÏ×÷¶Ô´ËÊÂÕ¹¿ªÊӲ졣RagnarokÍÅ»ïÌåÏÖËûÃÇÒÑÇÔȡԼ40 GBµÄÊý¾Ý£¬ÆäÖаüÂÞÖîÈçн×ÊÐÅÏ¢Ö®ÀàµÄÈËÁ¦×ÊÔ´Îļþ¡£ÄÚ²¿ÈËʿ֤ʵ£¬Õâ¿ÉÄÜÊÇÒ»´ÎÀÕË÷Èí¼þ¹¥»÷¡£FBIÔ¤¼Æ£¬´Ó2013Äêµ½2019ÄêÊܺ¦ÕßÒÑÏòºÚ¿ÍÖ§¸¶ÖÁÉÙ1.435ÒÚÃÀÔªµÄÊê½ð¡£


Ô­ÎÄÁ´½Ó£º

https://www.bloomberg.com/news/articles/2021-03-31/hackers-target-italian-menswear-boggi-milano-with-ransomware


3.GoogleÄþ¾²¸üУ¬ÐÞ¸´ChromeÖеÄɳÏäÌÓÒݵÈ8¸ö©¶´


3.jpg


GoogleÓÚ±¾ÖÜÐû²¼ÁËÄþ¾²¸üУ¬ÐÞ¸´ÁËChromeÖаüÂÞɳÏäÌÓÒÝÔÚÄÚµÄ8¸ö©¶´¡£´Ë´ÎÐÞ¸´µÄ×îΪÑÏÖØµÄ©¶´ÊǽØÍ¼·¨Ê½ÖÐÊͷźóʹÓé¶´£¨CVE-2021-21194£©£¬¿Éµ¼ÖÂChromeɳÏäÌÓÒÝ£¬¹¥»÷Õß½«¸Ã©¶´ÓëäÖȾÆ÷ÖЩ¶´½áºÏʹÓÿÉÒÔÔÚÄ¿±êÉ豸ÖÐÖ´ÐÐÈÎÒâ´úÂë¡£´ËÍ⣬´Ë´Î¸üл¹ÐÞ¸´ÁËV8ÖеÄÊͷźóʹÓé¶´£¨CVE-2021-21195£©¡¢TabStripÖеĶѻº³åÇøÒç³ö©¶´£¨CVE-2021-21196ºÍCVE-2021-21197£©ÒÔ¼°IPCÖеÄÔ½½ç¶ÁÈ¡£¨CVE-2021-21198£©µÈ©¶´¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/116165/security/chrome-sandbox-escape.html


4.Group-IBÅû¶Õë¶ÔÓ¡Äá½ðÈÚ»ú¹¹µÄÕ©Æ­»î¶¯£¬Éæ¼°200Íò¿Í»§


4.jpg


Group-IBÅû¶Õë¶ÔÓ¡¶ÈÄáÎ÷ÑÇ´óÐͽðÈÚ»ú¹¹µÄÕ©Æ­»î¶¯£¬Éæ¼°Áè¼Ý200Íò¿Í»§¡£¹¥»÷ÕßÔÚTwitterÉÏαװ³ÉÒøÐдú±í»ò¿Í»§¼¼ÊõÖ§³ÖÀ´½Ó´¥Êܺ¦Õߣ¬×îÖÕÄ¿±êÊÇ͵ȡÆäÒøÐÐÖеÄ×ʽ𡣸ûÒѶÔÖÁÉÙÓÐÆß¼Ò×éÖ¯Ìᳫ¹¥»÷£¬Õë¶ÔÁè¼Ý200ÍòÓ¡ÄáÒøÐеĿͻ§¡£´ËÍ⣬´Ó1Ô³õµÄ600¸öαÔìTwitterÕ˺ŵ½3Ô·ݵÄ1600¸ö£¬¸Ã»î¶¯µÄ·¶Î§À©´óÁË2.5±¶£¬Æ½¾ùÿÌì¶¼Êд´½¨ÊýÊ®¸öÕÊ»§¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/116173/cyber-crime/5-star-customer-service-fraudsters-launch-massive-campaign-against-indonesias-major-banks-on-twitter.html


5.³¯ºÚ¿ÍÀûÓÃαÔìµÄÉ罻ýÌåÕÊ»§½«Äþ¾²Ñо¿ÈËÔ±×÷ΪĿ±ê


5.jpg


GoogleµÄÍþв·ÖÎöС×飨TAG£©·¢ÏÖ£¬³¯ÏʺڿÍÀûÓÃαÔìµÄÉ罻ýÌåÕÊ»§½«Äþ¾²Ñо¿ÈËÔ±×÷ΪĿ±ê¡£ºÚ¿Í´´½¨ÁËÃûΪSecuriElite¹«Ë¾µÄÍøÕ¾£¬²¢Éù³ÆÕâÊÇλÓÚÍÁ¶úÆäµÄÒ»¼ÒÄþ¾²¹«Ë¾£¬Ìá¹©ÉøÍ¸²âÊÔ¡¢Èí¼þÄþ¾²ÆÀ¹ÀºÍ©¶´ÀûÓõȷþÎñ¡£¹¥»÷Õß»¹½¨Á¢ÁËÐé¼ÙµÄTwitterºÍLinkedInÕ˺Å£¬ÒÔÓëDZÔÚÄ¿±ê½øÐл¥¶¯¡£SecuriEliteÍøÕ¾Ò³Ãæµ×²¿Ò²ÓÐÖ¸Ïò¸Ã×éÖ¯PGP¹«Ô¿µÄÁ´½Ó£¬Äþ¾²Ñо¿Ô±Ò»µ©µã»÷¸ÃÁ´½Ó¾Í»áѬȾ¶ñÒâÈí¼þ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/google-north-korean-hackers-target-security-researchers-again/


6.ÒÁÀÊTA453µÄÐÂÐж¯BadBloodÖ¼ÔÚÇÔȡҽѧÑо¿ÕߵĽá¹û


6.jpg


Proofpoint·¢ÏÖÒÁÀʵÄAPT×éÖ¯TA453£¨Ò²³ÆÎªCharming Kitten£©µÄÐÂÐж¯BadBloodÖ¼ÔÚÇÔȡҽѧÑо¿ÕߵĽá¹û¡£¸Ã»î¶¯Ö÷Òª·¢ÉúÓÚ2020ÄêϰëÄ꣬TA453ÀûÓÃÍøÂçµöÓã¹¥»÷£¬×¨ÃÅÕë¶ÔÃÀ¹úºÍÒÔÉ«ÁдÓÊ»ùÒò¡¢Éñ¾­²¡Ñ§ºÍÖ×ÁöѧÑо¿µÄ¸ß¼¶Ò½Ñ§×¨ÒµÈËÊ¿¡£ÔÚÈ¥Äê12ÔµÄÒ»´Î¹¥»÷ÖУ¬ºÚ¿Íαװ³ÉÒÔÉ«ÁÐÖøÃûµÄÎïÀíѧ¼Ò£¬·¢ËÍÒÔºËÎäÆ÷ΪÖ÷ÌâµÄÓʼþÀ´ÇÔȡĿ±êÓû§µÄMicrosoftƾ¾Ý¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/charming-kitten-pounces-on-researchers/165129/