ÎÚ¿ËÀ¼Óë¶à¹úÕþ¸®ÁªºÏµ·»ÙÀÕË÷Èí¼þClopµÄ»ù´¡ÉèÊ©£»Ñо¿ÍŶÓÅû¶2G¼ÓÃܳ߶ÈËã·¨´æÔÚ¿ÉÇÔÌýÁ÷Á¿µÄ©¶´

Ðû²¼Ê±¼ä 2021-06-18

1.ÎÚ¿ËÀ¼Óë¶à¹úÕþ¸®ÁªºÏµ·»ÙÀÕË÷Èí¼þClopµÄ»ù´¡ÉèÊ©


1.jpg


ÎÚ¿ËÀ¼¾¯·½Óë¹ú¼ÊÐ̾¯×éÖ¯¡¢º«¹úºÍÃÀ¹úÕþ¸®ÁªºÏ£¬ÔÚ±¾ÖÜÈýÀֳɵ·»ÙÁËÀÕË÷Èí¼þClopµÄ»ù´¡ÉèÊ© ¡£ClopÀÕË÷Èí¼þÍÅ»ï×Ô2019ÄêÒÔÀ´¿ªÊ¼»îÔ¾£¬×ܼÆÔì³ÉÁËԼĪ5ÒÚÃÀÔªµÄËðʧ ¡£ÎÚ¿ËÀ¼Õþ¸®³ÆÒѹرշַ¢¶ñÒâÈí¼þµÄ»ù´¡ÉèÊ©ºÍ»ñµÃ¼ÓÃÜ»õ±ÒµÄÇþµÀ£¬µ«Ä¿Ç°ClopÓÃÀ´¹ûÈ»±»µÁÊý¾ÝµÄÍøÕ¾£¨CL0P^-LEAKS£©ÈÔÔÚÔËÐÐ ¡£Äþ¾²¹«Ë¾Intel 471ÌåÏÖ£¬ÎÚ¿ËÀ¼Õþ¸®Ö»´þ²¶ÁËΪClopÍÅ»ïÏ´Ç®µÄÈË£¬ÆäºËÐijÉÔ±¿ÉÄÜסÔÚ¶íÂÞ˹ ¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/06/ukraine-police-arrest-cyber-criminals.html


2.¼ÎÄ껪ÓÊÂÖ¹«Ë¾³ÆÆäÔâµ½ÍøÂç¹¥»÷µ¼Ö¸öÈËÐÅϢй¶


2.jpg


È«Çò×î´óµÄÓÎÂÖ¼ÎÄ껪£¨Carnival Corporation£©³ÆÆäÔâµ½¹¥»÷µ¼ÖÂÊý¾Ýй¶ ¡£¸Ã¹«Ë¾ÌåÏÖÆäÔÚ2021Äê3ÔÂ19ÈÕ¼ì²âµ½Î´¾­ÊÚȨµÄµÚÈý·½·ÃÎÊÁ˲¿Ãŵç×ÓÓʼþÕÊ»§£¬Ð¹Â¶ÁËÔ±¹¤ºÍ¿ÍÈ˵ĸöÈËÐÅÏ¢£¬°üÂÞÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢»¤ÕÕºÅÂë¡¢³öÉúÈÕÆÚ¡¢½¡¿µÐÅÏ¢¡¢Éç»áÄþ¾²ºÅÂë»òÉí·ÝÖ¤ºÅÂëµÈ ¡£¸Ã¹«Ë¾ÔÚÒ»·Ýµç×ÓÓʼþÉùÃ÷ÖÐÌåÏÖ£¬Æä¹É¼ÛϵøÁËÁè¼Ý2% ¡£ÔçÔÚÈ¥ÄêµÄ8ÔºÍ12Ô£¬¸Ã¹«Ë¾»¹Ôâµ½ÁËÁ½´ÎÀÕË÷Èí¼þ¹¥»÷ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.oann.com/cruise-operator-carnival-discloses-breach-of-crew-guests-personal-data-bloomberg-news/


3.²¨À¼Õþ¸®³ÆÆä¹«ÃñºÍ×éÖ¯»ú¹¹Ô⵽ǰËùδÓеÄÍøÂç¹¥»÷


3.jpg


²¨À¼Õþ¸®ÔÚ±¾Öܶþ³Æ£¬Æä¹«ÃñºÍ×éÖ¯»ú¹¹Ôâµ½ÁËǰËùδÓеÄÍøÂç¹¥»÷ ¡£ÉÏÖÜ£¬ºÚ¿ÍÈëÇÖÁË×ÜÀí°ì¹«ÊÒÂôÁ¦ÈËMichal DworczykµÄ˽ÈËÓʼþÕÊ»§£¬²¢½«ÓʼþÔÚTelegram¹ûÈ» ¡£Õþ¸®·¢ÑÔÈËPiotr MullerÌåÏִ˴ι¥»÷µÄ·¶Î§ºÜ¹ã·º£¬²»½öÉæ¼°Dworczyk£¬»¹Éæ¼°Õþ¸®³ÉÔ±¡¢PiSµ³ºÍÆä¹«Ãñ ¡£Ð¹Â¶ÎļþµÄÔªÊý¾ÝÏÔʾ£¬ÕâЩÎļþÊÇÓɽ²¶íÓïµÄÈ˱༭µÄ£¬µ«Õâ²»×ãÒÔ½«´Ë´Î¹¥»÷¹é¾ÌÓÚ¶íÂÞ˹ºÚ¿Í ¡£Ä¿Ç°£¬²¨À¼µÄµØ·½Õþ¸®ºÍÄþ¾²¾ÖÈÔÔÚÊÓ²ì´Ë´Î¹¥»÷ʼþ ¡£ 


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/119043/hacking/poland-hit-cyber-attacks.html


4.KasperskyÅû¶³¯ÏÊÍÅ»ïAndarielÕë¶Ôº«¹úµÄ¹¥»÷»î¶¯


4.jpg


KasperskyÅû¶Á˳¯ÏʺڿÍÍÅ»ïAndarielÕë¶Ôº«¹úµÄ¹¥»÷»î¶¯ ¡£Ñо¿ÈËÔ±ÓÚ2021Äê4ÔÂÔÚVirusTotalÉÏ·¢ÏÖÁËÒ»¸ö¿ÉÒɵÄWordÎĵµ£¬·ÖÎö·¢Ïִ˴ι¥»÷»î¶¯ÖÐʹÓõÄWindowsÃüÁîºÍÑ¡ÏîÓë֮ǰµÄAndariel»î¶¯¼¸ºõÏàͬ ¡£Andariel×÷ΪLazarusµÄ×Ó¼¯ÍÅ£¬×Ô2016Äê5ÔÂÒÔÀ´Ò»Ö±»îÔ¾£¬Ö¼ÔÚÈëÇÖº«¹úºÍÊÀ½ç¸÷µØ½ðÈÚ»ú¹¹µÄ¼ÆËã»ú ¡£ÖµµÃ×¢ÒâµÄÊÇ£¬Õâ´Î¹¥»÷³ýÁ˰²×°ºóÃÅÍ⣬»¹°²×°Á˼ÓÃÜÀÕË÷Èí¼þ£¬Ö÷ÒªÕë¶ÔÖÆÔìÒµ¡¢Ã½ÌåºÍ½¨ÖþÒµµÈÐÐÒµ ¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/andariel-evolves-to-target-south-korea-with-ransomware/102811/    


5.Ñо¿ÍŶÓÅû¶2G¼ÓÃܳ߶ÈËã·¨´æÔÚ¿ÉÇÔÌýÁ÷Á¿µÄ©¶´


5.jpg


ÔÚÖÜÈý·¢±íµÄһƪÂÛÎÄÖУ¬À´×Ե¹ú¡¢·¨¹úºÍŲÍþµÄÑо¿ÈËÔ±Åû¶ÁË2G£¨GPRS£©Òƶ¯Êý¾Ý¼ÓÃܳ߶ÈÖеÄ©¶´ ¡£¸Ã©¶´´æÔÚÓÚ¼ÓÃÜËã·¨GEA-1ÖУ¬Õâ¿ÉÄÜʹ¹¥»÷ÕßÄܹ»ÇÔÌýһЩÊý¾ÝÁ÷Á¿³¤´ï20¶àÄê ¡£GEA-1Ëã·¨±¾Ó¦ÔÚ2013ÄêÌÔÌ­£¬µ«ÔÚÏÖÔÚµÄAndroidºÍiOSÖÇÄÜÊÖ»úÖÐÈÔÄÜ·¢ÏÖËü ¡£ËäÈ»´ó¶àÊýÊÖ»ú¶¼Ê¹ÓÃ4GÉõÖÁ5G£¬µ«ÔÚijЩ¹ú¼Ò/µØÓò£¬GPRSÈÔÈ»ÊÇÊý¾ÝÁ¬½ÓµÄºó±¸Ñ¡Ôñ ¡£Ä¿Ç°£¬Ñо¿ÈËÔ±ÒÑ֪ͨÊÖ»úÖÆÔìÉ̺ͳ߶È×éÖ¯ÐÞ¸´¸Ã©¶´ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/security-flaw-found-2g-mobile-data-encryption-standard


6.Enable SecurityÅû¶VoIP GUIÖеĿçÕ¾½Å±¾Â©¶´


6.jpg


Enable SecurityÅû¶ÁËVoIP GUIÖеĿçÕ¾½Å±¾Â©¶´ ¡£¸Ã©¶´´æÔÚÓÚ¹ÜÀíVoIPºô½ÐµÄ»á»°ÌᳫЭÒé (Session Initiation Protocol£¬SIP)ÖУ¬¹¥»÷Õß¿ÉÀûÓøÃ©¶´ÔÚδ¾­Éí·ÝÑéÖ¤µÄÇé¿öÏÂÔÚÄ¿±êϵͳÉÏÖ´ÐдúÂë ¡£Ñо¿ÈËÔ±ÔÚÉóºËVoIPmonitor GUIʱ·¢ÏÖÁ˸é¶´£¬³Æ¿ÉÒÔͨ¹ý·¢ËͶñÒâSIPÏûÏ¢À´ÍêÈ«¿ØÖÆÏµÍ³ ¡£Enable SecurityÓÚ2021Äê2ÔÂÁªÏµÁËVoIPmonitorµÄ¿ª·¢ÈËÔ±£¬¸Ã©¶´ÏÖÒÑÐÞ¸´ ¡£


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2021/06/16/xss-vulnerability-in-sip-protocol-risks-rce-attacks-on-voip-software/