Devolutions°ä²¼2021ÄêÖÐÓ×ÐÍÆóÒµ°²È«Ì¬ÊƵĻ㱨

°ä²¼¹¦·ò 2021-11-24

RedCurlÍÅ»ï»Ø¹é£¬£¬£¬£¬£¬ £¬£¬ÐµĹ¥»÷Ö¸±êÉæ¼°¸÷Ðи÷Òµ


RedCurlÍÅ»ï»Ø¹é£¬£¬£¬£¬£¬£¬£¬ÐµĹ¥»÷Ö¸±êÉæ¼°¸÷Ðи÷Òµ.png


Group-IBÔÚ11ÔÂ18ÈÕÅû¶Á˺ڿÍÍÅ»ïRedCurlµÄл¡£¡£¡£¡£ ¡£¡£ÍøÂç¼äµýºÚ¿Í×éÖ¯RedCurlÔÚ2018ÄêÖÁ2020ÄêÆÚ¼ä£¬£¬£¬£¬£¬ £¬£¬ÌáÒéÁËÖÁÉÙ26´Î¹¥»÷£¬£¬£¬£¬£¬ £¬£¬Éæ¼°Ó¢¹ú¡¢µÂ¹ú¡¢¼ÓÄôó¡¢Å²Íþ¡¢¶íÂÞ˹ºÍÎÚ¿ËÀ¼µÈµØÓòµÄ¹¹Öþ¡¢½ðÈÚ¡¢Õ÷ѯ¡¢ÁãÊÛ¡¢±£ÏÕºÍ˾·¨ÐÐÒµµÄ¹«Ë¾¡£¡£¡£¡£ ¡£¡£¸ÃÍÅ»ïÔÚÖжÏ7¸öÔºó¾íÍÁ³ÁÀ´£¬£¬£¬£¬£¬ £¬£¬×Ô2021ËêÊ×ÒÔÀ´Õë¶Ô4¼Ò¹«Ë¾ÌáÒéÁËÐµĹ¥»÷£¬£¬£¬£¬£¬ £¬£¬ÆäÖÐÔ̺¬¶íÂÞ˹×î´óµÄÅú·¢É̵ꡣ¡£¡£¡£ ¡£¡£Group-IB³Æ£¬£¬£¬£¬£¬ £¬£¬RedCurlÔÚÿ´Î¹¥»÷ÖгÇÊÐʹÓÃÆä×Ô½ç˵¶ñÒâÈí¼þÈÆ¹ý¼ì²â¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.group-ib.com/media/red-curl-threat-report/


×êÑÐÈËÔ±ÑÝʾеÄSAD DNS»º´æÖж¾¹¥»÷ģʽ


×êÑÐÈËÔ±ÑÝʾеÄSAD DNS»º´æÖж¾¹¥»÷ģʽ.png


¼ÓÖÝ´óѧ×êÑÐÈËÔ±ÔÚ11ÔÂ18ÈÕÑÝʾÁËÒ»ÖÖеÄSAD DNS»º´æÖж¾¹¥»÷ģʽ¡£¡£¡£¡£ ¡£¡£SAD DNS£¨Side channel AttackeD DNS£©ÓÚ2020Äê11Ô³õ´ÎÅû¶£¬£¬£¬£¬£¬ £¬£¬ËüÒÀÀµICMPµÄ¡°port unreachable¡±ÐÂÎÅÀ´´§¶ÈʹÓÃÄĸöһʱ¶Ë¿Ú¡£¡£¡£¡£ ¡£¡£ÀûÓô˹¥»÷ģʽ¿É½«¶ñÒâµÄDNS¼Í¼עÈëDNS»º´æ£¬£¬£¬£¬£¬ £¬£¬¶øºó½«Ö¸±êÁ÷Á¿³Á¶¨Ïòµ½¹¥»÷ÕߵķþÎñÆ÷ÖУ¬£¬£¬£¬£¬ £¬£¬½øÐÐÖÐÑëÈË(MITM)¹¥»÷¡£¡£¡£¡£ ¡£¡£×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬ £¬£¬´ËÖÖ¹¥»÷´æÔÚÓÚLinuxÉÏÔËÐеÄBIND¡¢UnboundºÍdnsmasqµÈDNSÈí¼þÖУ¬£¬£¬£¬£¬ £¬£¬Ó°ÏìÔ¼38%µÄÓòÃû½âÎöÆ÷¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/11/new-side-channel-attacks-re-enable.html


ÃÀ¹ú֤ȯÂòÂôίԱ»á·¢ÏÖ¼ÙÒâÆäÔ±¹¤µÄ´¹µö»î¶¯


ÃÀ¹ú֤ȯÂòÂôίԱ»á·¢ÏÖ¼ÙÒâÆäÔ±¹¤µÄ´¹µö»î¶¯.png


ÃÀ¹ú֤ȯÂòÂôίԱ»á(SEC)Ͷ×ÊÕß½ÌÓýºÍÐû´«°ì¹«ÊÒ(OIEA)ÓÚ11ÔÂ19ÈÕ°ä²¼¾¯±¨£¬£¬£¬£¬£¬ £¬£¬³Æ·¢ÏÖ¼ÙÒâSECÔ±¹¤µÄ»î¶¯¡£¡£¡£¡£ ¡£¡£¹¥»÷Õßͨ¹ýµç»°¡¢ÓïÒôÓʼþ¡¢µç×ÓÓʼþºÍº¯¼þ£¬£¬£¬£¬£¬ £¬£¬ÖÒ¸æÊÕ¼þÈËÆä»îÆÚ´æ¿î»ò¼ÓÃÜÇ®±ÒµÄÕË»§ÖдæÔÚδ¾­ÊÚȨµÄÂòÂô»òÆäËû¿ÉÒɻ£¬£¬£¬£¬£¬ £¬£¬²¢Ë÷ÒªÆä¹ÉȨ¡¢Õʺš¢PINÂë¡¢ÃÜÂëµÈÐÅÏ¢¡£¡£¡£¡£ ¡£¡£OIEA½¨ÒéÓû§ÔÚ·¢ËÍÓ×ÎÒÐÅϢ֮ǰ£¬£¬£¬£¬£¬ £¬£¬Ó¦ÏÈͨ¹ýÓʼþ»òÖµçSECÈ·¶¨·¢¼þÈ˵ÄÉí·Ý¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-sec-warns-investors-of-ongoing-govt-impersonation-attacks/


ÓÌËûÖÝÒ½ÁÆÖÐÐÄUIA½ü60Íò»¼ÕßµÄÓ×ÎÒÐÅϢй¶


ÓÌËûÖÝÒ½ÁÆÖÐÐÄUIA½ü60Íò»¼ÕßµÄÓ×ÎÒÐÅϢй¶.png


11ÔÂ18ÈÕ£¬£¬£¬£¬£¬ £¬£¬ÃÀ¹úÓÌËûÖÝ·ÅÉäÖÐÐÄUtah Imaging Associates(UIA)È·ÈÏ582170»¼ÕßµÄÓ×ÎÒÐÅϢй¶¡£¡£¡£¡£ ¡£¡£Ð¹Â¶ÊÂÎñ²úÉúÔÚ8ÔÂ29ÈÕ£¬£¬£¬£¬£¬ £¬£¬Êý¾ÝÔÚ¶³öÔ¼Ò»Öܺ󣬣¬£¬£¬£¬ £¬£¬ÓÚ9ÔÂ4ÈÕ±»·¢ÏÖ²¢ÓÚͬÈÕ½¨¸´¡£¡£¡£¡£ ¡£¡£Õâ´Îй¶ÁË»¼ÕßµÄÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢Éç»á°²È«ºÅÂë¡¢½¡È«±£ÏÕµ¥ºÅºÍÒ½ÁÆÐÅÏ¢µÈ¡£¡£¡£¡£ ¡£¡£×êÑÐÈËÔ±°µÊ¾£¬£¬£¬£¬£¬ £¬£¬¹¥»÷Õ߯«²îÓÚ¹¥»÷ÏñUIAÕâÑùµÄÒ½ÁÆÖÐÐÄ£¬£¬£¬£¬£¬ £¬£¬ÊÇÓÉÓÚËûÃÇÒÔΪ´ËÀàÊý¾ÝÔÚ°µÍøÖеļÛÖµ¸ü¸ß¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/utah-medical-center-hit-by-data-breach-affecting-582k-patients/


Prodaft°ä²¼¹ØÓÚÀÕË÷ÔËÓªÍÅ»ïContiµÄ·ÖÎö»ã±¨


Prodaft°ä²¼¹ØÓÚÀÕË÷ÔËÓªÍÅ»ïContiµÄ·ÖÎö»ã±¨.png


ProdaftÓÚ11ÔÂ18ÈÕ°ä²¼Á˹ØÓÚÀÕË÷ÔËÓªÍÅ»ïContiµÄÉî¶È·ÖÎö»ã±¨¡£¡£¡£¡£ ¡£¡£ContiÊÇ˽ÓÐRaaS£¬£¬£¬£¬£¬ £¬£¬ÓÚ2019Äê12Ôµ׳õ´Î³öÏÖ£¬£¬£¬£¬£¬ £¬£¬²¢Í¨¹ýTrickBot½øÐд«²¼¡£¡£¡£¡£ ¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬ £¬£¬×Ô2021Äê7ÔÂÒÔÀ´£¬£¬£¬£¬£¬ £¬£¬Conti´ÓÊê½ðÖлñÀûÖÁÉÙ2550ÍòÃÀÔª£¬£¬£¬£¬£¬ £¬£¬¶øContiÍÅ»ïÔòÐû³ÆÒÑ»ñÀû3ÒÚÃÀÔª¡£¡£¡£¡£ ¡£¡£´Ë±í£¬£¬£¬£¬£¬ £¬£¬Prodaft»¹¹«¿ªÁËContiµÄÖ§¸¶ÍøÕ¾£¬£¬£¬£¬£¬ £¬£¬Æä·þÎñÆ÷ÍйÜÔÚ217.12.204.135ÉÏ£¬£¬£¬£¬£¬ £¬£¬¸ÃIPµØÖ·ÊôÓÚÎÚ¿ËÀ¼ÍøITL LLC¡£¡£¡£¡£ ¡£¡£Ôڸû㱨°ä²¼¼¸Ó×ʱºó£¬£¬£¬£¬£¬ £¬£¬ContiÍÅ»ï¾Í½«ÆäÖ§¸¶ÍøÕ¾¹Ø¹Ø¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.prodaft.com/resource/detail/conti-ransomware-group-depth-analysis


Devolutions°ä²¼2021ÄêÖÐÓ×ÐÍÆóÒµ°²È«Ì¬ÊƵĻ㱨


Devolutions°ä²¼2021ÄêÖÐÓ×ÐÍÆóÒµ°²È«Ì¬ÊƵĻ㱨.png


DevolutionsÔÚ11ÔÂ17ÈÕ°ä²¼ÁË2021ÄêÖÐÓ×ÐÍÆóÒµ°²È«Ì¬ÊƵÄ×êÑл㱨¡£¡£¡£¡£ ¡£¡£¸Ã×êÑоÍÎå¸öÖ÷ÌâÖ÷Ì⣺ÖÐÓׯóÒµµÄÍøÂç¹¥»÷ºÍÍþв¡¢ÃÜÂëÖÎÀí¡¢Ê¹ÓõÄÌØÈ¨½Ó¼ûÖÎÀí¡¢°²È«ÅàѵºÍÖÎÀíÒÔ¼°°²È«Í¶×ʽøÐÐÁË·ÖÎö¡£¡£¡£¡£ ¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬ £¬£¬ÓëÈ¥ÄêÏà±È£¬£¬£¬£¬£¬ £¬£¬72%µÄÖÐÓׯóҵĿǰԽ·¢¹ØÇÐÍøÂ簲ȫ£»£»£»£»£» £»£»£»ÖÎÀíÕß×î²»°²µÄÍøÂçÍþвÊÇÀÕË÷Èí¼þ¡¢ÍøÂç´¹µöºÍ¶ñÒâÈí¼þ£»£»£»£»£» £»£»£»52%µÄÆóÒµÔÚÈ¥ÄêÔâµ½¹ýÍøÂç¹¥»÷£»£»£»£»£» £»£»£»Ö»ÓÐ13%µÄÆóÒµÕ¼ÓÐÆëÈ«µÄPAM½â¾ö¹æ»®¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.devolutions.net/2021/11/new-now-available-devolutions-state-of-cybersecurity-in-smbs-in-2021-2022-report