ºÚ¿ÍÈëÇÖÌØÀÊÆÕ¾ºÑ¡ÍøÕ¾²¢´«²¼ÐéαÐÅÏ¢£»£»£»£» £»£» £»ACTI³Æ¶íºÚ¿Í×éÖ¯TurlaÈëÇÖÅ·ÖÞÒ»¸öµ±¾Ö×éÖ¯

°ä²¼¹¦·ò 2020-10-29
1.ºÚ¿ÍÈëÇÖÌØÀÊÆÕ¾ºÑ¡ÍøÕ¾²¢´«²¼ÐéαÐÅÏ¢


1.jpg


µ±¾Ö¹ÙÔ±°µÊ¾£¬£¬£¬ £¬£¬ºÚ¿ÍÔÚÑ¡¾ÙÈÕǰһÖܵÄÐÇÆÚ¶þÈëÇÖÁËÌÆÄɵ¡¤ÌØÀÊÆÕµÄ¾ºÑ¡ÍøÕ¾¡£¡£¡£¡£¡£¡£¡£donaldjtrump.comÍøÕ¾±»¡°Õâ¸öÍøÕ¾±»²é·âÁË¡±ÐÂÎÅËùÈ¡´ú£¬£¬£¬ £¬£¬²¢°µÊ¾¡°ÊÀ½çÒѾ­Êܹ»ÁËÌÆÄɵ¡¤J¡¤ÌØÀÊÆÕ×ÜͳÿÌìÉ¢²¥µÄ¼ÙÐÂÎÅ¡±¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬ £¬£¬ºÚ¿Í»¹ºôÓõÍøÃñ¾èÔùMoneroÊý×ÖÇ®±ÒÒÔÖ§³Ö»ò·ñ¾öй¶ÓëÌØÀÊÆÕÓйصÄÖ¤¾Ý¡£¡£¡£¡£¡£¡£¡£ÌØÀÊÆÕ¾ºÑ¡½²»°ÈËTim Murtaugh°µÊ¾£¬£¬£¬ £¬£¬¸ÃÍøÕ¾ºÜ¿ìµÃµ½½¨¸´²¢Ã»ÓÐÈκÎÃô¸ÐÊý¾Ýй¶£¬£¬£¬ £¬£¬Õâ´Î¹¥»÷µÄÆðÔ´»¹ÔÚµ÷²éÖС£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/trump-campaign-website-broken-hackers


2.ACTI³Æ¶íºÚ¿Í×éÖ¯TurlaÈëÇÖÅ·ÖÞÒ»¸öµ±¾Ö×éÖ¯


2.jpg


ƾ¾Ý°£É­ÕÜÍøÂçÍþвµý±¨£¨ACTI£©µÄ×îл㱨£¬£¬£¬ £¬£¬¶íÂÞ˹µÄºÚ¿Í×éÖ¯TurlaÈëÇÖÁËÒ»¸öδ¹«¿ªÃû³ÆµÄÅ·ÖÞµ±¾Ö×éÖ¯µÄϵͳ¡£¡£¡£¡£¡£¡£¡£ÎªÁËÈëÇÖ×éÖ¯ÍøÂ磬£¬£¬ £¬£¬¹¥»÷ÕßʹÓÃÁË×î½ü¸üеÄÔ¶³ÌÖÎÀíľÂí£¨RAT£©ºÍ»ùÓÚÔ¶³Ì¹ý³ÌŲÓã¨RPC£©µÄºóÃÅ·¨Ê½£¬£¬£¬ £¬£¬ÆäÖÐÔ̺¬HyperStack¡£¡£¡£¡£¡£¡£¡£ACTI°µÊ¾£¬£¬£¬ £¬£¬Õâ´Î¹¥»÷ÆëÈ«ÇкÏTurla´Óʼäµý»î¶¯µÄ¶¯»ú£¬£¬£¬ £¬£¬Ä¿Ç°ËüÒѾ­·ÛËéÁËÀ´×Ô100¶à¸ö¹ú¶ÈÈ·µ±¾Ö¡¢´óʹ¹ÝÒÔ¼°½ÌÓýºÍ×êÑлú¹¹µÄÊýǧ¸öϵͳ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/russian-turla-hackers-breach-european-government-organization/


3.Microsoft°ä²¼KB4577586¸üУ¬£¬£¬ £¬£¬ÖÕ³¡Ê¹ÓÃAdobe Flash


3.jpg


Microsoft°ä²¼ÁËKB4577586¸üУ¬£¬£¬ £¬£¬ÒÔÖÕ³¡Ê¹ÓÃWindowsÉϵÄAdobe Flash¡£¡£¡£¡£¡£¡£¡£Õâ´Î¸üнö¿Éͨ¹ýMicrosoft Catalog»ñµÃ¡£¡£¡£¡£¡£¡£¡£MicrosoftÉêÃ÷¸Ã¸üн«×Ô¶¯É¾³ýAdobe Flash Player£¬£¬£¬ £¬£¬µ«Éв»Ã÷ÏÔÈ·ÇÐɾ³ýµÄÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£¾­¹ý²âÊÔ£¬£¬£¬ £¬£¬´Ë¸üÐÂɾ³ýÁËWindows 10Öа󸿵ÄFlash Player£¨32룩°æ±¾£¬£¬£¬ £¬£¬µ«²»»áɾ³ýÈκζÀÁ¢°æ±¾µÄAdobe Flash Player¡£¡£¡£¡£¡£¡£¡£MicrosoftÔò°µÊ¾»á2021ËêÊ×Flashµ½ÆÚºó¶ÔFlash Player½øÐдó¹æÄ£É¾³ý¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-update-to-remove-adobe-flash-from-windows/


4.Enel GroupÔÙ´ÎϰȾÀÕË÷Èí¼þ£¬£¬£¬ £¬£¬Ð¹Â¶5TBµÄÊý¾Ý


4.jpg


¿ç¹úÄÜÔ´¹«Ë¾Enel Group½ñÄêÔâµ½µÚ¶þ´ÎÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬ £¬£¬NetwalkerÐû³ÆÆäÇÔÈ¡ÁË5TBµÄÊý¾Ý²¢ÀÕË÷1400ÍòÃÀÔªÊê½ð¡£¡£¡£¡£¡£¡£¡£EnelÊÇÅ·ÖÞÄÜÔ´ÁìÓò×î´óµÄ¹«Ë¾Ö®Ò»£¬£¬£¬ £¬£¬ÔÚ40¸ö¹ú¶ÈºÍµØÓòÕ¼ÓÐ6100Íò¿Í»§¡£¡£¡£¡£¡£¡£¡£½ñÄê6Ô³õ£¬£¬£¬ £¬£¬EnelµÄÄÚ²¿ÍøÂçÔâµ½SnakeÀÕË÷Èí¼þµÄ¹¥»÷£¬£¬£¬ £¬£¬10ÔÂ19ÈÕÓÖÔâµ½NetwalkerÀÕË÷Èí¼þµÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬ £¬£¬NetwalkerÒÑÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾°ä²¼Á˱»µÁÊý¾ÝµÄ½ØÍ¼£¬£¬£¬ £¬£¬²¢°µÊ¾»áÔÚÒ»ÖÜÄÚ¹«¿ªÆäÖеÄÒ»²¿ÃÅ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/enel-group-hit-by-ransomware-again-netwalker-demands-14-million/


5.¼Ò¾ß¹«Ë¾SteelcaseϰȾRyukµ¼ÖÂϵÍÂäÙʱ¹Ø¹Ø


5.jpg


È«Çò×î´óµÄ°ì¹«¼Ò¾ßÔì×÷ÉÌSteelcase³ÆÆäÔÚ10ÔÂ22ÈÕÔâµ½RyukÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬ £¬£¬²¢µ¼ÖÂϵÍÂäÙʱ¹Ø¹Ø¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾°ä²¼ÉêÃ÷³ÆÆäÔÚÐÅÏ¢¼¼ÊõϵͳÉÏ·¢ÏÖÁËÍøÂç¹¥»÷£¬£¬£¬ £¬£¬²¢Ñ¸ËÙ²ÉÈ¡ÁËһϵÁжôÔì´ëÊ©À´½â¾öÕâÖÖÇé¿ö£¬£¬£¬ £¬£¬Ô̺¬ÁÙʱ¹Ø¹ØÊÜÓ°ÏìµÄϵͳºÍÓйزÙ×÷¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬ £¬£¬¹«Ë¾Éв»ÖªÂ·´Ë¹¥»÷µ¼ÖµľßÌåϵͳÊý¾ÝÃÔʧ»ò×ʲúËðʧ£¬£¬£¬ £¬£¬µ«¹«Ë¾Ô¤¼Æ¸ÃÊÂÎñ²»»á¶ÔÆäÒµÎñÔËÓª»ò²ÆÕþÒµ¼¨²úÉú³Á´óÓ°Ïì¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/steelcase-furniture-giant-hit-by-ryuk-ransomware-attack/    


6.Veracode°ä²¼ÀûÓ÷¨Ê½°²È«Ì¬ÊƵķÖÎö»ã±¨


6.jpg


Veracode°ä²¼µÚ11ÆÚÈí¼þ°²È«×´Ì¬»ã±¨£¬£¬£¬ £¬£¬¶ÔÀûÓ÷¨Ê½°²È«Ì¬ÊƽøÐÐÁË·ÖÎö¡£¡£¡£¡£¡£¡£¡£»ã±¨¶Ô130000¸öÀûÓ÷¨Ê½½øÐÐÁË·ÖÎö£¬£¬£¬ £¬£¬·¢ÏÖ76£¥µÄÀûÓÃÖÁÉÙÓµÓÐÒ»¸ö°²È«·ì϶£¬£¬£¬ £¬£¬µ«Ö»ÓÐ24£¥µÄÓ¦Æ÷ÓµÓиßÑϳÁÐÔ·ì϶¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬ £¬£¬¸Ã»ã±¨»¹·¢ÏÖÁËһЩ¿ÉÌá¸ß·ì϶½¨¸´ÂʵIJ½Ö裬£¬£¬ £¬£¬Èç½áºÏʹÓöàÖÖɨÃèÀàÐÍ£¨Ô̺¬¾²Ì¬·ÖÎö£¨SAST£©£¬£¬£¬ £¬£¬¶¯Ì¬·ÖÎö£¨DAST£©ºÍÈí¼þ×é³É·ÖÎö£¨SCA£©£©£¬£¬£¬ £¬£¬Í³¼ÆÅú×¢ÄÇЩͬʱʹÓÃSASTºÍDASTµÄÈËÄܹ»24ÌìÄÚ½¨¸´Ò»°ëµÄȱµã¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.veracode.com/sites/default/files/pdf/sossv11/soss_infographic_v11.pdf