AtlasÐû²¼2021ÄêH1©¶´·ÖÎö³ÂËߣºWindows WPBTÖеÄЩ¶´Ó°ÏìWin8

Ðû²¼Ê±¼ä 2021-09-28

Windows WPBTÖеÄЩ¶´Ó°ÏìWin8¼°Ö®ºóËùÓÐϵͳ


Windows WPBTÖеÄЩ¶´Ó°ÏìWin8¼°Ö®ºóËùÓÐϵͳ.png


EclypsiumÑо¿ÍŶӷ¢ÏÖMicrosoft Windowsƽ̨¶þ½øÖƱí(WPBT)ÖдæÔÚÒ»¸ö©¶´£¬¿ÉÓÃÀ´ÔÚϵͳÉϰ²×°Rootkit¡£¸Ã©¶´Ó°ÏìÁË2012ÄêÖ®ºó¿¯ÐеÄWindows 8¼°¸ü¸ß°æ±¾µÄËùÓÐϵͳ£¬¹¥»÷Õß¿ÉÀûÓøÃ©¶´ÔÚϵͳÆô¶¯Ê±ÒÔÄÚºËȨÏÞÔËÐжñÒâ´úÂ롣΢ÈíÌá³öµÄ»º½â´ëÊ©°üÂÞʹÓÃWindows DefenderÓ¦Ó÷¨Ê½¿ØÖÆ£¨WDAC£©¼ÆÄ±À´¿ØÖÆÔÚϵͳÖÐÔËÐеĶþ½øÖÆÎļþ£¬»òʹÓÃAppLocker¼ÆÄ±À´¿ØÖÆÔÊÐíÔËÐеÄÓ¦Óá£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-wpbt-flaw-lets-hackers-install-rootkits-on-windows-devices/


Å·ÖÞºô½ÐÖÐÐũӦÉÌGSSÔâµ½ContiÍÅ»ïµÄÀÕË÷¹¥»÷


Å·ÖÞºô½ÐÖÐÐũӦÉÌGSSÔâµ½ContiÍÅ»ïµÄÀÕË÷¹¥»÷.png


Covisian·¢ÑÔÈ˳Æ£¬ÆäÎ÷°àÑÀºÍÀ­¶¡ÃÀÖÞ·Ö²¿GSSÓÚ9ÔÂ18ÈÕÔâµ½ÁËContiÍÅ»ïµÄÀÕË÷¹¥»÷¡£CovisianÊÇÅ·ÖÞ×î´óµÄ¿Í»§·þÎñºÍºô½ÐÖÐÐũӦÉÌÖ®Ò»£¬´Ë´Î¹¥»÷µ¼ÖÂÆä´ó²¿ÃÅϵͳÖжÏ£¬Ó°ÏìÁËVodafone Spain¡¢MasMovil ISP¡¢ÂíµÂÀïµÄ¹©Ë®¹«Ë¾ºÍµçÊǪ́µÈ¹«Ë¾ºÍ×éÖ¯¡£²»¾Ãǰ£¬ÃÀ¹úµÄºô½ÐÖÐÐĺͿͻ§Ö§³Ö·þÎñ¹©Ó¦ÉÌTTECÒ²Ôâµ½ÁËÀÕË÷¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/122570/cyber-crime/gss-ransomware-attack.html



·ÇÖÞÒøÐÐÒòºÏ×÷»ï°éÔâµ½¹¥»÷µ¼Ö²¿Ãſͻ§ÐÅϢй¶


·ÇÖÞÒøÐÐÒòºÏ×÷»ï°éÔâµ½¹¥»÷µ¼Ö²¿Ãſͻ§ÐÅϢй¶.png


·ÇÖÞÒøÐÐÔÚÉÏÖÜÈýÈ·ÈÏÒòÆäÕ®Îñ×·»ØºÏ×÷»ï°éDebt-INÔâµ½¹¥»÷£¬µ¼Ö²¿Ãſͻ§ÐÅϢй¶¡£Debt-InÔøÔÚ½ñÄê4Ô·ÝÔâµ½ÀÕË÷¹¥»÷£¬ÆäʱÑо¿ÈËÔ±¸ø³öµÄ½áÂÛÊÇûÓÐÖ¤¾Ý±íÃ÷´æÔÚÊý¾Ýй¶ÎÊÌ⡣Ȼ¶ø£¬Debt-InÏÖÔÚÒâʶµ½²¿Ãſͻ§µÄÐÅÏ¢ÒÑй¶£¬°üÂÞ·ÇÖÞÒøÐеĴû¿î¿Í»§£¬µ«2021Äê4ÔÂ1ÈÕÖ®ºóµÄÊý¾Ý²¢Î´Êܵ½Ó°Ïì¡£¸ÃÒøÐгÆ£¬Èç¹û¿Í»§ÈÏΪÐÅÏ¢Òѱ»µÁÓ㬿ÉÏòÄÏ·ÇÆÛÕ©Ô¤·À·þÎñÖÐÐÄ(SAFPS)ÉêÇëÃâ·ÑµÄ±£»¤·þÎñ¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2021/09/african-bank-alerts-of-data-breach-with.html



Desorden³ÆÒÑÇÔÈ¡ÂíÀ´Î÷ÑÇABX Express 200GBÊý¾Ý


Desorden³ÆÒÑÇÔÈ¡ÂíÀ´Î÷ÑÇABX Express 200GBÊý¾Ý.png


DesordenÉù³ÆÓÚ9ÔÂ23ÈÕÈëÇÖÁËÂíÀ´Î÷ÑÇABX ExpressµÄ·þÎñÆ÷£¬²¢ÇÔÈ¡ÁË200GBÊý¾Ý¡£DesordenÌåÏִ˴λñµÃÁËÊý°ÙÍòÂíÀ´Î÷ÑÇÈ˵ÄÊý¾Ý¡¢Áè¼Ý1500ÍòÌõº½¿ÕÔ˵¥¼Ç¼ÒÔ¼°ÓйزÆÕþ¡¢¿Í»§ºÍ¹«Ë¾ÐÅÏ¢µÈ£¬¶øABX¹Ø±ÕÁË·þÎñ²¢³ÆÔÚ×öϵͳά»¤£¬Ã»ÓÐÐû²¼´Ë´ÎÊý¾Ýй¶Ê¼þ¡£Ä¿Ç°£¬ABX Express¹«Ë¾ÉÐδ¶Ô´ËÊÂ×÷³ö»ØÓ¦£¬¶øÑо¿ÈËÔ±ÔÚѯÎÊÆäĸ¹«Ë¾Kerry LogisticsºóҲδµÃµ½»ØÓ¦¡£



Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/desorden-group-claims-to-have-stolen-200-gb-of-data-from-abx-express/



CybereasonÐû²¼ÓйØÀÕË÷Èí¼þMagniberµÄ·ÖÎö³ÂËß


CybereasonÐû²¼ÓйØÀÕË÷Èí¼þMagniberµÄ·ÖÎö³ÂËß.png


CybereasonÔÚ9ÔÂ22ÈÕÐû²¼ÁËÓйØÀÕË÷Èí¼þMagniberµÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬¸ÃÍÅ»ïÖ÷ҪʹÓÃÁËPrintNightmare©¶´£¨CVE-2021-34527ºÍCVE-2021-34481£©¡£Ê×ÏÈÒÔ Windows DLLÎļþµÄÐÎʽ·Ö·¢ÀÕË÷Èí¼þ£¬È»ºóÀûÓÃCVE-2021-34527ÔÚÄ¿±êϵͳÉϰ²×°ºÍÖ´ÐиÃÎļþ¡£´ËÍ⣬ÀÕË÷Èí¼þMagniberÈÔ´¦ÓÚ¿ª·¢ÖУ¬¿ª·¢ÕßÔÚÆµ·±µØ¸ü¸Ä´úÂë²¢¸ïлìÏý¹¦Ð§¡¢Èƹý¼ÆÄ±ºÍ¼ÓÃÜ»úÖÆµÈ¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.cybereason.com/blog/threat-analysis-report-printnightmare-and-magniber-ransomware



AtlasVPNÐû²¼2021ÄêH1Åû¶µÄ©¶´µÄ·ÖÎö³ÂËß


AtlasVPNÐû²¼2021ÄêH1Åû¶µÄ©¶´µÄ·ÖÎö³ÂËß.png


AtlasVPNÔÚ9ÔÂ14ÈÕÐû²¼ÁË2021ÄêH1Åû¶µÄ©¶´µÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬Google¡¢MicrosoftºÍOracleÔÚ2021ÄêÉϰëÄêÅû¶µÄ©¶´×î¶à£¬·Ö±ðΪ547¸ö¡¢432¸öºÍ316¸ö©¶´£¬Æä´ÎΪCisco£¨200¸ö£©ºÍSAP£¨118¸ö£©¡£ÔÚÉϰëÄêÔÚ×ܼƷ¢ÏÖÁË1023¸öCVSSÆÀ·ÖΪ9-10µÄ©¶´£¬ÀýÈçF5 BIG-IPÖеÄCVE-2021-22986£»927¸öCVSSÆÀ·ÖΪ8-9µÄ©¶´£¬ÈçDraeger X-DockÖеÄCVE-2021-28111£»ÒÔ¼°2164¸ö7-8·ÖµÄ©¶´¡£



Ô­ÎÄÁ´½Ó£º

https://atlasvpn.com/blog/google-and-microsoft-accumulated-the-most-vulnerabilities-in-h1-2021