DevolutionsÐû²¼2021ÄêÖÐСÐÍÆóÒµÄþ¾²Ì¬ÊƵijÂËß

Ðû²¼Ê±¼ä 2021-11-24

RedCurlÍÅ»ï»Ø¹é  £¬ÐµĹ¥»÷Ä¿±êÉæ¼°¸÷Ðи÷Òµ


RedCurlÍÅ»ï»Ø¹é£¬ÐµĹ¥»÷Ä¿±êÉæ¼°¸÷Ðи÷Òµ.png


Group-IBÔÚ11ÔÂ18ÈÕÅû¶Á˺ڿÍÍÅ»ïRedCurlµÄл¡£ÍøÂç¼äµýºÚ¿Í×éÖ¯RedCurlÔÚ2018ÄêÖÁ2020ÄêÆÚ¼ä  £¬ÌᳫÁËÖÁÉÙ26´Î¹¥»÷  £¬Éæ¼°Ó¢¹ú¡¢µÂ¹ú¡¢¼ÓÄôó¡¢Å²Íþ¡¢¶íÂÞ˹ºÍÎÚ¿ËÀ¼µÈµØÓòµÄ½¨Öþ¡¢½ðÈÚ¡¢×Éѯ¡¢ÁãÊÛ¡¢±£ÏÕºÍÖ´·¨ÐÐÒµµÄ¹«Ë¾¡£¸ÃÍÅ»ïÔÚÖжÏ7¸öÔºó¾íÍÁÖØÀ´  £¬×Ô2021Äê³õÒÔÀ´Õë¶Ô4¼Ò¹«Ë¾ÌᳫÁËÐµĹ¥»÷  £¬ÆäÖаüÂÞ¶íÂÞ˹×î´óµÄÅú·¢É̵ê¡£Group-IB³Æ  £¬RedCurlÔÚÿ´Î¹¥»÷Öж¼ÊÐʹÓÃÆä×Ô½ç˵¶ñÒâÈí¼þÈÆ¹ý¼ì²â¡£


Ô­ÎÄÁ´½Ó£º

https://www.group-ib.com/media/red-curl-threat-report/


Ñо¿ÈËÔ±ÑÝʾеÄSAD DNS»º´æÖж¾¹¥»÷ģʽ


Ñо¿ÈËÔ±ÑÝʾеÄSAD DNS»º´æÖж¾¹¥»÷ģʽ.png


¼ÓÖÝ´óѧÑо¿ÈËÔ±ÔÚ11ÔÂ18ÈÕÑÝʾÁËÒ»ÖÖеÄSAD DNS»º´æÖж¾¹¥»÷ģʽ¡£SAD DNS£¨Side channel AttackeD DNS£©ÓÚ2020Äê11ÔÂÊ×´ÎÅû¶  £¬ËüÒÀÀµICMPµÄ¡°port unreachable¡±ÏûÏ¢À´ÍƶÏʹÓÃÄĸöÁÙʱ¶Ë¿Ú¡£ÀûÓô˹¥»÷ģʽ¿É½«¶ñÒâµÄDNS¼Ç¼עÈëDNS»º´æ  £¬È»ºó½«Ä¿±êÁ÷Á¿Öض¨Ïòµ½¹¥»÷ÕߵķþÎñÆ÷ÖÐ  £¬½øÐÐÖмäÈË(MITM)¹¥»÷¡£Ñо¿ÈËÔ±³Æ  £¬´ËÖÖ¹¥»÷´æÔÚÓÚLinuxÉÏÔËÐеÄBIND¡¢UnboundºÍdnsmasqµÈDNSÈí¼þÖÐ  £¬Ó°ÏìÔ¼38%µÄÓòÃû½âÎöÆ÷¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/11/new-side-channel-attacks-re-enable.html


ÃÀ¹ú֤ȯ½»Ò×ίԱ»á·¢ÏÖð³äÆäÔ±¹¤µÄµöÓã»î¶¯


ÃÀ¹ú֤ȯ½»Ò×ίԱ»á·¢ÏÖð³äÆäÔ±¹¤µÄµöÓã»î¶¯.png


ÃÀ¹ú֤ȯ½»Ò×ίԱ»á(SEC)Ͷ×ÊÕß½ÌÓýºÍÐû´«°ì¹«ÊÒ(OIEA)ÓÚ11ÔÂ19ÈÕÐû²¼¾¯±¨  £¬³Æ·¢ÏÖð³äSECÔ±¹¤µÄ»î¶¯¡£¹¥»÷Õßͨ¹ýµç»°¡¢ÓïÒôÓʼþ¡¢µç×ÓÓʼþºÍÐżþ  £¬¾¯¸æÊÕ¼þÈËÆä»îÆÚ´æ¿î»ò¼ÓÃÜ»õ±ÒµÄÕË»§ÖдæÔÚδ¾­ÊÚȨµÄ½»Ò×»òÆäËû¿ÉÒɻ  £¬²¢Ë÷ÒªÆä¹ÉȨ¡¢Õʺš¢PINÂë¡¢ÃÜÂëµÈÐÅÏ¢¡£OIEA½¨ÒéÓû§ÔÚ·¢Ë͸öÈËÐÅϢ֮ǰ  £¬Ó¦ÏÈͨ¹ýÓʼþ»òÖµçSECÈ·¶¨·¢¼þÈ˵ÄÉí·Ý¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-sec-warns-investors-of-ongoing-govt-impersonation-attacks/


ÓÌËûÖÝÒ½ÁÆÖÐÐÄUIA½ü60Íò»¼ÕߵĸöÈËÐÅϢй¶


ÓÌËûÖÝÒ½ÁÆÖÐÐÄUIA½ü60Íò»¼ÕߵĸöÈËÐÅϢй¶.png


11ÔÂ18ÈÕ  £¬ÃÀ¹úÓÌËûÖÝ·ÅÉäÖÐÐÄUtah Imaging Associates(UIA)È·ÈÏ582170»¼ÕߵĸöÈËÐÅϢй¶¡£Ð¹Â¶Ê¼þ·¢ÉúÔÚ8ÔÂ29ÈÕ  £¬Êý¾ÝÔÚ̻¶ԼһÖܺó  £¬ÓÚ9ÔÂ4ÈÕ±»·¢ÏÖ²¢ÓÚͬÈÕÐÞ¸´¡£´Ë´Îй¶ÁË»¼ÕßµÄÐÕÃû¡¢µØÖ·¡¢³öÉúÈÕÆÚ¡¢Éç»áÄþ¾²ºÅÂë¡¢½¡¿µ±£ÏÕµ¥ºÅºÍÒ½ÁÆÐÅÏ¢µÈ¡£Ñо¿ÈËÔ±ÌåÏÖ  £¬¹¥»÷ÕßÇãÏòÓÚ¹¥»÷ÏñUIAÕâÑùµÄÒ½ÁÆÖÐÐÄ  £¬ÊÇÒòΪËûÃÇÈÏΪ´ËÀàÊý¾ÝÔÚ°µÍøÖеļÛÖµ¸ü¸ß¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/utah-medical-center-hit-by-data-breach-affecting-582k-patients/


ProdaftÐû²¼¹ØÓÚÀÕË÷ÔËÓªÍÅ»ïContiµÄ·ÖÎö³ÂËß


ProdaftÐû²¼¹ØÓÚÀÕË÷ÔËÓªÍÅ»ïContiµÄ·ÖÎö³ÂËß.png


ProdaftÓÚ11ÔÂ18ÈÕÐû²¼Á˹ØÓÚÀÕË÷ÔËÓªÍÅ»ïContiµÄÉî¶È·ÖÎö³ÂËß¡£ContiÊÇ˽ÓÐRaaS  £¬ÓÚ2019Äê12Ôµ×Ê״ηºÆð  £¬²¢Í¨¹ýTrickBot½øÐÐÁ÷´«¡£³ÂËßÖ¸³ö  £¬×Ô2021Äê7ÔÂÒÔÀ´  £¬Conti´ÓÊê½ðÖлñÀûÖÁÉÙ2550ÍòÃÀÔª  £¬¶øContiÍÅ»ïÔòÉù³ÆÒÑ»ñÀû3ÒÚÃÀÔª¡£´ËÍâ  £¬Prodaft»¹¹ûÈ»ÁËContiµÄÖ§¸¶ÍøÕ¾  £¬Æä·þÎñÆ÷ÍйÜÔÚ217.12.204.135ÉÏ  £¬¸ÃIPµØÖ·ÊôÓÚÎÚ¿ËÀ¼ÍøITL LLC¡£ÔڸóÂËßÐû²¼¼¸Ð¡Ê±ºó  £¬ContiÍÅ»ï¾Í½«ÆäÖ§¸¶ÍøÕ¾¹Ø±Õ¡£


Ô­ÎÄÁ´½Ó£º

https://www.prodaft.com/resource/detail/conti-ransomware-group-depth-analysis


DevolutionsÐû²¼2021ÄêÖÐСÐÍÆóÒµÄþ¾²Ì¬ÊƵijÂËß


DevolutionsÐû²¼2021ÄêÖÐСÐÍÆóÒµÄþ¾²Ì¬ÊƵijÂËß.png


DevolutionsÔÚ11ÔÂ17ÈÕÐû²¼ÁË2021ÄêÖÐСÐÍÆóÒµÄþ¾²Ì¬ÊƵÄÑо¿³ÂËß¡£¸ÃÑо¿¾ÍÎå¸öºËÐÄÖ÷Ì⣺ÖÐСÆóÒµµÄÍøÂç¹¥»÷ºÍÍþв¡¢ÃÜÂë¹ÜÀí¡¢Ê¹ÓõÄÌØÈ¨·ÃÎʹÜÀí¡¢Äþ¾²ÅàѵºÍ¹ÜÀíÒÔ¼°Äþ¾²Í¶×ʽøÐÐÁË·ÖÎö¡£³ÂËßÖ¸³ö  £¬ÓëÈ¥ÄêÏà±È  £¬72%µÄÖÐСÆóҵĿǰԽ·¢ÌåÌùÍøÂçÄþ¾²£»¹ÜÀíÕß×îµ£ÓǵÄÍøÂçÍþвÊÇÀÕË÷Èí¼þ¡¢ÍøÂçµöÓãºÍ¶ñÒâÈí¼þ£»52%µÄÆóÒµÔÚÈ¥ÄêÔâµ½¹ýÍøÂç¹¥»÷£»Ö»ÓÐ13%µÄÆóÒµÓµÓÐÍêÕûµÄPAM½â¾ö·½°¸¡£


Ô­ÎÄÁ´½Ó£º

https://blog.devolutions.net/2021/11/new-now-available-devolutions-state-of-cybersecurity-in-smbs-in-2021-2022-report