ÎÚ¿ËÀ¼Óë¶à¹úÕþ¸®ÁªºÏµ·»ÙÀÕË÷Èí¼þClopµÄ»ù´¡ÉèÊ©£»Ñо¿ÍŶÓÅû¶2G¼ÓÃܳ߶ÈËã·¨´æÔÚ¿ÉÇÔÌýÁ÷Á¿µÄ©¶´
Ðû²¼Ê±¼ä 2021-06-181.ÎÚ¿ËÀ¼Óë¶à¹úÕþ¸®ÁªºÏµ·»ÙÀÕË÷Èí¼þClopµÄ»ù´¡ÉèÊ©
ÎÚ¿ËÀ¼¾¯·½Óë¹ú¼ÊÐ̾¯×éÖ¯¡¢º«¹úºÍÃÀ¹úÕþ¸®ÁªºÏ£¬ÔÚ±¾ÖÜÈýÀֳɵ·»ÙÁËÀÕË÷Èí¼þClopµÄ»ù´¡ÉèÊ©¡£ClopÀÕË÷Èí¼þÍÅ»ï×Ô2019ÄêÒÔÀ´¿ªÊ¼»îÔ¾£¬×ܼÆÔì³ÉÁËԼĪ5ÒÚÃÀÔªµÄËðʧ¡£ÎÚ¿ËÀ¼Õþ¸®³ÆÒѹرշַ¢¶ñÒâÈí¼þµÄ»ù´¡ÉèÊ©ºÍ»ñµÃ¼ÓÃÜ»õ±ÒµÄÇþµÀ£¬µ«Ä¿Ç°ClopÓÃÀ´¹ûÈ»±»µÁÊý¾ÝµÄÍøÕ¾£¨CL0P^-LEAKS£©ÈÔÔÚÔËÐС£Äþ¾²¹«Ë¾Intel 471ÌåÏÖ£¬ÎÚ¿ËÀ¼Õþ¸®Ö»´þ²¶ÁËΪClopÍÅ»ïÏ´Ç®µÄÈË£¬ÆäºËÐijÉÔ±¿ÉÄÜסÔÚ¶íÂÞ˹¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/06/ukraine-police-arrest-cyber-criminals.html
2.¼ÎÄ껪ÓÊÂÖ¹«Ë¾³ÆÆäÔâµ½ÍøÂç¹¥»÷µ¼Ö¸öÈËÐÅϢй¶
È«Çò×î´óµÄÓÎÂÖ¼ÎÄ껪£¨Carnival Corporation£©³ÆÆäÔâµ½¹¥»÷µ¼ÖÂÊý¾Ýй¶¡£¸Ã¹«Ë¾ÌåÏÖÆäÔÚ2021Äê3ÔÂ19ÈÕ¼ì²âµ½Î´¾ÊÚȨµÄµÚÈý·½·ÃÎÊÁ˲¿Ãŵç×ÓÓʼþÕÊ»§£¬Ð¹Â¶ÁËÔ±¹¤ºÍ¿ÍÈ˵ĸöÈËÐÅÏ¢£¬°üÂÞÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢»¤ÕÕºÅÂë¡¢³öÉúÈÕÆÚ¡¢½¡¿µÐÅÏ¢¡¢Éç»áÄþ¾²ºÅÂë»òÉí·ÝÖ¤ºÅÂëµÈ¡£¸Ã¹«Ë¾ÔÚÒ»·Ýµç×ÓÓʼþÉùÃ÷ÖÐÌåÏÖ£¬Æä¹É¼ÛϵøÁËÁè¼Ý2%¡£ÔçÔÚÈ¥ÄêµÄ8ÔºÍ12Ô£¬¸Ã¹«Ë¾»¹Ôâµ½ÁËÁ½´ÎÀÕË÷Èí¼þ¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.oann.com/cruise-operator-carnival-discloses-breach-of-crew-guests-personal-data-bloomberg-news/
3.²¨À¼Õþ¸®³ÆÆä¹«ÃñºÍ×éÖ¯»ú¹¹Ô⵽ǰËùδÓеÄÍøÂç¹¥»÷
²¨À¼Õþ¸®ÔÚ±¾Öܶþ³Æ£¬Æä¹«ÃñºÍ×éÖ¯»ú¹¹Ôâµ½ÁËǰËùδÓеÄÍøÂç¹¥»÷¡£ÉÏÖÜ£¬ºÚ¿ÍÈëÇÖÁË×ÜÀí°ì¹«ÊÒÂôÁ¦ÈËMichal DworczykµÄ˽ÈËÓʼþÕÊ»§£¬²¢½«ÓʼþÔÚTelegram¹ûÈ»¡£Õþ¸®·¢ÑÔÈËPiotr MullerÌåÏִ˴ι¥»÷µÄ·¶Î§ºÜ¹ã·º£¬²»½öÉæ¼°Dworczyk£¬»¹Éæ¼°Õþ¸®³ÉÔ±¡¢PiSµ³ºÍÆä¹«Ãñ¡£Ð¹Â¶ÎļþµÄÔªÊý¾ÝÏÔʾ£¬ÕâЩÎļþÊÇÓɽ²¶íÓïµÄÈ˱༵쬵«Õâ²»×ãÒÔ½«´Ë´Î¹¥»÷¹é¾ÌÓÚ¶íÂÞ˹ºÚ¿Í¡£Ä¿Ç°£¬²¨À¼µÄµØ·½Õþ¸®ºÍÄþ¾²¾ÖÈÔÔÚÊÓ²ì´Ë´Î¹¥»÷ʼþ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/119043/hacking/poland-hit-cyber-attacks.html
4.KasperskyÅû¶³¯ÏÊÍÅ»ïAndarielÕë¶Ôº«¹úµÄ¹¥»÷»î¶¯
KasperskyÅû¶Á˳¯ÏʺڿÍÍÅ»ïAndarielÕë¶Ôº«¹úµÄ¹¥»÷»î¶¯¡£Ñо¿ÈËÔ±ÓÚ2021Äê4ÔÂÔÚVirusTotalÉÏ·¢ÏÖÁËÒ»¸ö¿ÉÒɵÄWordÎĵµ£¬·ÖÎö·¢Ïִ˴ι¥»÷»î¶¯ÖÐʹÓõÄWindowsÃüÁîºÍÑ¡ÏîÓë֮ǰµÄAndariel»î¶¯¼¸ºõÏàͬ¡£Andariel×÷ΪLazarusµÄ×Ó¼¯ÍÅ£¬×Ô2016Äê5ÔÂÒÔÀ´Ò»Ö±»îÔ¾£¬Ö¼ÔÚÈëÇÖº«¹úºÍÊÀ½ç¸÷µØ½ðÈÚ»ú¹¹µÄ¼ÆËã»ú¡£ÖµµÃ×¢ÒâµÄÊÇ£¬Õâ´Î¹¥»÷³ýÁ˰²×°ºóÃÅÍ⣬»¹°²×°Á˼ÓÃÜÀÕË÷Èí¼þ£¬Ö÷ÒªÕë¶ÔÖÆÔìÒµ¡¢Ã½ÌåºÍ½¨ÖþÒµµÈÐÐÒµ¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/andariel-evolves-to-target-south-korea-with-ransomware/102811/
5.Ñо¿ÍŶÓÅû¶2G¼ÓÃܳ߶ÈËã·¨´æÔÚ¿ÉÇÔÌýÁ÷Á¿µÄ©¶´
ÔÚÖÜÈý·¢±íµÄһƪÂÛÎÄÖУ¬À´×Ե¹ú¡¢·¨¹úºÍŲÍþµÄÑо¿ÈËÔ±Åû¶ÁË2G£¨GPRS£©Òƶ¯Êý¾Ý¼ÓÃܳ߶ÈÖеÄ©¶´¡£¸Ã©¶´´æÔÚÓÚ¼ÓÃÜËã·¨GEA-1ÖУ¬Õâ¿ÉÄÜʹ¹¥»÷ÕßÄܹ»ÇÔÌýһЩÊý¾ÝÁ÷Á¿³¤´ï20¶àÄê¡£GEA-1Ëã·¨±¾Ó¦ÔÚ2013ÄêÌÔÌ£¬µ«ÔÚÏÖÔÚµÄAndroidºÍiOSÖÇÄÜÊÖ»úÖÐÈÔÄÜ·¢ÏÖËü¡£ËäÈ»´ó¶àÊýÊÖ»ú¶¼Ê¹ÓÃ4GÉõÖÁ5G£¬µ«ÔÚijЩ¹ú¼Ò/µØÓò£¬GPRSÈÔÈ»ÊÇÊý¾ÝÁ¬½ÓµÄºó±¸Ñ¡Ôñ¡£Ä¿Ç°£¬Ñо¿ÈËÔ±ÒÑ֪ͨÊÖ»úÖÆÔìÉ̺ͳ߶È×éÖ¯ÐÞ¸´¸Ã©¶´¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/security-flaw-found-2g-mobile-data-encryption-standard
6.Enable SecurityÅû¶VoIP GUIÖеĿçÕ¾½Å±¾Â©¶´
Enable SecurityÅû¶ÁËVoIP GUIÖеĿçÕ¾½Å±¾Â©¶´¡£¸Ã©¶´´æÔÚÓÚ¹ÜÀíVoIPºô½ÐµÄ»á»°ÌᳫÐÒé (Session Initiation Protocol£¬SIP)ÖУ¬¹¥»÷Õß¿ÉÀûÓøÃ©¶´ÔÚδ¾Éí·ÝÑéÖ¤µÄÇé¿öÏÂÔÚÄ¿±êϵͳÉÏÖ´ÐдúÂë¡£Ñо¿ÈËÔ±ÔÚÉóºËVoIPmonitor GUIʱ·¢ÏÖÁ˸é¶´£¬³Æ¿ÉÒÔͨ¹ý·¢ËͶñÒâSIPÏûÏ¢À´ÍêÈ«¿ØÖÆÏµÍ³¡£Enable SecurityÓÚ2021Äê2ÔÂÁªÏµÁËVoIPmonitorµÄ¿ª·¢ÈËÔ±£¬¸Ã©¶´ÏÖÒÑÐÞ¸´¡£
ÔÎÄÁ´½Ó£º
https://latesthackingnews.com/2021/06/16/xss-vulnerability-in-sip-protocol-risks-rce-attacks-on-voip-software/