Äþ¾²¹«Ë¾CognyteÊý¾Ý¿âÅäÖôíÎóй¶Áè¼Ý50ÒÚÌõ¼Ç¼£»ÄÜÔ´¹«Ë¾InvenergyÔâµ½REvilÀÕË÷¹¥»÷й¶4TBÊý¾Ý

Ðû²¼Ê±¼ä 2021-06-16

1.Äþ¾²¹«Ë¾CognyteÊý¾Ý¿âÅäÖôíÎóй¶Áè¼Ý50ÒÚÌõ¼Ç¼


1.jpg


ComparitechÄþ¾²Ñо¿ÈËÔ±·¢ÏÖÁËÍøÂçÄþ¾²·ÖÎö¹«Ë¾CognyteδÊܱ£»¤µÄÊý¾Ý¿â¡£¸ÃÊý¾Ý¿â×÷ΪCognyteÍøÂçÇ鱨·þÎñµÄÒ»²¿ÃÅ£¬ÓÃÓÚÌáÐÑÆä¿Í»§µÚÈý·½µÄÊý¾Ýй¶¡£¾ßÓм¥Ð¦ÒâζµÄÊÇ£¬ÓÃÓÚ½»²æ¼ì²éй¶µÄ¸öÈËÐÅÏ¢µÄÊý¾Ý¿â×Ô¼ºÒÑй¶¡£¸ÃÊý¾Ý¿â×ܹ²ÓÐ5085132102Ìõ¼Ç¼£¬°üÂÞÃû³Æ¡¢µç×ÓÓʼþµØÖ·¡¢ÃÜÂëºÍÊý¾ÝÔ´£¬ÓÚ2021Äê5ÔÂ29ÈÕ±»·¢ÏÖ£¬ºóÓÚ6ÔÂ2ÈÕ±»±£»¤ÆðÀ´¡£Ä¿Ç°£¬Éв»È·¶¨ÕâЩÊý¾ÝÔÚ̻¶ÆÚ¼äÊÇ·ñÓб»ÈκεÚÈý·½·ÃÎÊ¡£


Ô­ÎÄÁ´½Ó£º

https://www.comparitech.com/blog/information-security/breach-database-leak/


2.ÀÕË÷Èí¼þParadiseµÄÔ´´úÂëÔÚºÚ¿ÍÂÛ̳XSSÉϹûÈ»


2.jpg


Paradise RansomwareµÄ.NET°æ±¾ÍêÕûÔ´´úÂëÒÑÔÚºÚ¿ÍÂÛ̳XSSÉϹûÈ»£¬ÍøÂç·¸×ï·Ö×Ó¿ÉÒÔÓÃÆä¿ª·¢×Ô¼º¶¨ÖƵÄÀÕË÷Èí¼þ¡£ParadiseÓÚ2017Äê9ÔÂÊ״α»·¢ÏÖ£¬Ìṩ¾ßÓÐÀÕË÷Èí¼þ¼´·þÎñ (RaaS) Ä£Ð͵ĶñÒâÈí¼þ¡£Ö®ºó£¬Äþ¾²¹«Ë¾EmsisoftºÍBitdefender·Ö±ðÓÚ2019Äê10ÔºÍ2020Äê1ÔÂÐû²¼ÁËÁ½¸ö½âÃÜÆ÷¡£Ñо¿ÈËÔ±±àÒëÔ´´úÂëºó·¢ÏÖËü´´½¨ÁËÈý¸ö¿ÉÖ´ÐÐÎļþ£ºÀÕË÷Èí¼þÅäÖù¹½¨Æ÷¡¢¼ÓÃÜÆ÷ºÍ½âÃÜÆ÷¡£´ËÍ⣬Դ´úÂëÖеĶíÓï×¢ÊÍÇå³þµØÕ¹Ê¾ÁË¿ª·¢ÈËÔ±µÄĸÓï¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/paradise-ransomware-source-code-released-on-a-hacking-forum/


3.Apple½ô¼±¸üУ¬ÐÞ¸´iOSÖÐÒѱ»ÔÚÒ°ÀûÓõÄ2¸ö0day


3.jpg


AppleÐû²¼½ô¼±¸üУ¬ÐÞ¸´iOS 12.5.3ÖÐÒѱ»ÔÚÒ°ÀûÓõÄ2¸ö0day¡£ÕâÁ½¸ö0dayΪWebKitä¯ÀÀÆ÷ÒýÇæÖеÄÄÚ´æËð»µÂ©¶´£¨CVE-2021-30761£©ºÍÊͷźóʹÓé¶´£¨CVE-2021-30762£©£¬¾ù¿É±»ÓÃÀ´Ô¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£AppleÌåÏָé¶´¿ÉÄÜÒѱ»»ý¼«ÀûÓ㬵«²¢Î´Í¸Â¶ÈκÎÓйشËÀ๥»÷µÄÏêϸÐÅÏ¢¡£´ËÍ⣬´Ë´Î¸üл¹ÐÞ¸´ÁËASN.1½âÂëÆ÷ÖеÄÄÚ´æËð»µÂ©¶´(CVE-2021-30737)¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/06/apple-issues-urgent-patches-for-2-zero.html


4.ÄÜÔ´¹«Ë¾InvenergyÔâµ½REvilÀÕË÷¹¥»÷й¶4TBÊý¾Ý


4.jpg


REvilÍÅ»ïÉù³ÆÆä¹¥»÷ÁËÃÀ¹ú¿ç¹ú¿ÉÔÙÉúÄÜÔ´¹«Ë¾Invenergy LLCµÄÍøÂ磬²¢ÇÔÈ¡ÁË4 TBµÄÊý¾Ý¡£¸Ã¹«Ë¾ÓÚÉÏÖÜÎ峯Æä¼ì²âµ½Á˹¥»÷£¬ÔËӪδÊܵ½Ó°Ï죬Êý¾ÝҲû±»¼ÓÃÜ£¬¶øÇÒûÓÐÖ§¸¶Ò²²»¼Æ»®Ö§¸¶ÈκÎÊê½ð¡£Ö®ºó£¬REvil³ÆÇÔÈ¡ÁË4 TBÊý¾Ý£¬°üÂÞÏîÄ¿¡¢ºÏͬºÍ±£ÃÜЭÒ飬ÒÔ¼°InvenergyÊ×´´ÈËMichael PolskyµÄ¸öÈËÃô¸ÐÐÅÏ¢£¬ÀýÈçÆä¸öÈ˵ç×ÓÓʼþÒÔ¼°ËûÓëµÚÒ»ÈÎÆÞ×ÓMayaÀë»éµÄϸ½Ú£¨ËûÔÚ2007ÄêµÄÀë»é±»±¨µÀΪÀúÊ·ÉÏ×î°º¹óµÄÀë»é°¸Ö®Ò»£©µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/revil-claims-responsibility-for/


5.Group IBÐû²¼2020-2021ÄêÀÕË÷Èí¼þµÄ·ÖÎö³ÂËß


5.jpg


Group IBÐû²¼ÁË2020-2021ÄêÀÕË÷Èí¼þµÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬ÀÕË÷ÍŻﲻ̫ÌåÌùÄ¿±êÐÐÒµ£¬¶øÊǸü¹Ø×¢·¶Î§ºÍ¹æÄ££¬ÇãÏòÓÚ¹¥»÷´óÐÍÆóÒµÒÔ»ñµÃ¾¡¿ÉÄܶàµÄÊê½ð£»2019ÄêµÄƽ¾ùÊê½ðԼΪ8ÍòÃÀÔª£¬2020ÄêÔòԼΪ17ÍòÃÀÔª£¬¶øMaze¡¢DoppelPaymerºÍRagnarLockerµÄƽ¾ùÊê½ðÒªÇóÔÚ100ÍòÖÁ200ÍòÃÀÔªÖ®¼ä£»ÆóÒµ»·¾³Í¨³£²»½öÔËÐÐWindowsϵͳ£¬»¹ÔËÐÐLinux£¬Òò´ËһЩ¹¥»÷ÕßÔÚËûÃǵÄÎäÆ÷¿âÖÐÌí¼ÓÁËÏàÓ¦µÄ°æ±¾¡£


Ô­ÎÄÁ´½Ó£º

https://www.group-ib.com/resources/threat-research/ransomware-2021.html


6.AT&T AlienÐû²¼½©Ê¬ÍøÂçMoobot¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß


6.jpg


AT&T Alien LabsÐû²¼Óйؽ©Ê¬ÍøÂçMiraiµÄ±äÌåMoobotµÄ¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß¡£3Ôµ×£¬Ñо¿ÈËÔ±·¢ÏÖTendaÖеÄÔ¶³Ì´úÂëÖ´ÐÐ (RCE) ©¶´CVE-2020-10987µÄÀûÓÃʵÑ鼤Ôö£¬ÕâÔÚǰ¼¸¸öÔ²¢²»³£¼û¡£Í¨¹ý¶ÔURL½øÐзÖÎö£¬È·¶¨ºÚ¿ÍÔÚÀûÓÃCyberium¶ñÒâÈí¼þÍйÜÓò·Ö·¢Ðí¶à²îÒìµÄMirai±äÌ壬°üÂÞMoobotºÍSatori¡£´ËÍ⣬¸Ã³ÂËß»¹ÌṩÁËÓйش˴ι¥»÷µÄ»º½â´ëÊ©¡¢¼ì²âÒªÁìºÍIOC¡£


Ô­ÎÄÁ´½Ó£º

https://cybersecurity.att.com/blogs/labs-research/malware-hosting-domain-cyberium-fanning-out-mirai-variants