Ó¢¹ú¿ìµÝ¹«Ë¾Yodel³ÆÆäÔâµ½¹¥»÷£¬£¬£¬£¬£¬·þÎñÒÑÖжÏÊýÈÕ

°ä²¼¹¦·ò 2022-06-23
1¡¢Ó¢¹ú¿ìµÝ¹«Ë¾Yodel³ÆÆäÔâµ½¹¥»÷£¬£¬£¬£¬£¬·þÎñÒÑÖжÏÊýÈÕ


¾ÝýÌå6ÔÂ21ÈÕ±¨Â·£¬£¬£¬£¬£¬Ó¢¹úµÄ¿ìµÝ·þÎñ¹«Ë¾YodelÔâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬£¬µ¼Ö°ü¹üÅÉËͺͶ©µ¥¸ú×Ù³öÏÖÑÓ³¤¡£¡£¡£¡£¡£Æä¿Í»§°µÊ¾£¬£¬£¬£¬£¬ÔÚÉÏÖÜÄ©¿ìµÝ·þÎñ³öÏÖÎÊÌ⣬£¬£¬£¬£¬ÆäÖв¿ÃÅÈ˳ÆËûÃÇÒѾ­ÖÁÉÙËÄÌìûÓаü¹üÐÅÏ¢¡£¡£¡£¡£¡£Óд«ÑÔ³ÆYodelÔâµ½ÁËÀÕË÷¹¥»÷£¬£¬£¬£¬£¬Ë¼¿¼µ½¹¥»÷Õßͨ³£²»»áÔÚ¹¤×÷ÈÕ¼ÓÃÜÖ¸±êÍÆËã»ú£¬£¬£¬£¬£¬Òò¶øÕâÒ²ÊÇÒ»¸öºÏÀíµÄ´§¶È¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ã»Óа䲼ÓйظÃÊÂÎñµÄÈκÎϸ½Ú£¬£¬£¬£¬£¬µ«°µÊ¾¿Í»§µÄÖ§¸¶ÐÅϢûÓÐÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚ¹ÙÍøÉϰ䲼µÄ²¼¸æ×¢Ã÷£¬£¬£¬£¬£¬·þÎñÖжÏÊÇÓÉÓÚÍøÂçÊÂÎñÔì³ÉµÄ£¬£¬£¬£¬£¬²¢Í¨ÖªÓû§°ü¹ü¿ÉÄÜ»á±ÈÔ¤ÆÚ¸üÍí´ïµ½¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/yodel-parcel-company-confirms-cyberattack-is-disrupting-delivery/


2¡¢RIG Exploit Kit»î¶¯ÖÐRaccoon Stealer±»Dridex´úÌæ 


BitdefenderÔÚ6ÔÂ21ÈÕй©£¬£¬£¬£¬£¬RIG Exploit Kit±³ºóÔËÓªÍÅ»ïʹÓõÄRaccoon StealerÒѱ»Dridex´úÌæ¡£¡£¡£¡£¡£½ñÄê2Ô·ݣ¬£¬£¬£¬£¬Raccoon StealerµÄÒ»ÃûÖØÒª¿ª·¢ÈËÔ±ÔÚ¶íÎÚÕ½ÕùÖÐÉíÍö£¬£¬£¬£¬£¬µ¼Ö¸ÃÏîÄ¿ÖÕ³¡¡£¡£¡£¡£¡£¼ì²âÊý¾ÝÏÔʾ£¬£¬£¬£¬£¬ÔÚ2ÔÂ20ÈÕ×óÓÒ·Ö·¢µÄpayloadÊýÁ¿ÓÐËù½µÂä¡£¡£¡£¡£¡£RIG»î¶¯µÄÔËÓªÍÅ»ïѸËÙ×ö³öÓ¦¶Ô£¬£¬£¬£¬£¬ÓÃDridex´úÌæRaccoon¡£¡£¡£¡£¡£DridexÄܹ»ÏÂÔØ¶î±íµÄpayload¡¢ÉøÈëµ½ä¯ÀÀÆ÷ÖÐÇÔÈ¡¿Í»§ÔÚÒøÐÐÍøÕ¾ÉÏÊäÈëµÄµÇ¼ÐÅÏ¢¡¢×½ÄÃÆÁÄ»½ØÍ¼ºÍ¼Í¼¼üÅ̵ȣ¬£¬£¬£¬£¬ÆäÖ°ÄÜÄܹ»Í¨¹ý·ÖÆçµÄÄ£¿£¿£¿£¿£¿£¿£¿£¿éÇáÒ×À©´ó¡£¡£¡£¡£¡£


https://thehackernews.com/2022/06/rig-exploit-kit-now-infects-victims-pcs.html


3¡¢ToddyCatÍÅ»ïÕë¶ÔλÓÚÑÇÖÞºÍÅ·ÖÞµÄExchange·þÎñÆ÷


KasperskyÔÚ6ÔÂ21ÈÕ°ä²¼»ã±¨£¬£¬£¬£¬£¬Åû¶ÁËAPT×éÖ¯ToddyCatÔÚ½üÆÚµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£Õâ´Î»î¶¯ÖÁÉÙ´Ó2020Äê12ÔÂÆðÍ·£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔλÓÚÑÇÖÞºÍÅ·ÖÞµÄMicrosoft Exchange·þÎñÆ÷¡£¡£¡£¡£¡£¹¥»÷ÕßµÄÖ¸±êÊǵ±¾ÖºÍ¾üÊÂÓйØ×éÖ¯£¬£¬£¬£¬£¬µÚÒ»²¨¹¥»÷£¨2020Äê12ÔÂÖÁ2021Äê2Ô£©Õë¶ÔÔ½ÄϺÍÖйų́ÍåµÄÉÙÊý×éÖ¯£» £»£»£»£»µÚ¶þ²¨¹¥»÷£¨2021Äê2ÔÂÖÁ5Ô£©Éæ¼°µ½¶íÂÞ˹¡¢Ó¡¶È¡¢ÒÁÀʺÍÓ¢¹ú£» £»£»£»£»µÚÈý²¨¹¥»÷£¨Ö±µ½2022Äê2Ô£©ÐÂÔöÓ¡¶ÈÄáÎ÷ÑÇ¡¢ÎÚ×ȱð¿Ë˹̹ºÍ¼ª¶û¼ªË¹Ë¹Ì¹¡£¡£¡£¡£¡£×êÑÐÈËÔ±»¹·¢ÏÖÁ˹¥»÷ÕßʹÓõÄкóÃÅSamuraiºÍľÂíNinja Trojan£¬£¬£¬£¬£¬¶þÕß¶¼¿ÉÓÃÀ´½ÚÔìÖ¸±êϵͳ²¢ÔÚÍøÂçÖкáÏòÒÆ¶¯¡£¡£¡£¡£¡£  


https://securelist.com/toddycat/106799/


4¡¢¶íÂÞ˹APT28ÀÄÓÃFollina·ì϶·Ö·¢¶ñÒâÈí¼þCredoMap


6ÔÂ21ÈÕ£¬£¬£¬£¬£¬Malwarebytes°ä²¼Á˹ØÓÚ¶íÂÞ˹APT28ÐÂÒ»ÂÖ´¹µö¹¥»÷µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£» £»£»£»£»î¶¯ÖØÒªÕë¶ÔÎÚ¿ËÀ¼£¬£¬£¬£¬£¬Ê¹ÓÃÁËÃûΪ¡°Nuclear Terrorism A Very Real Threat.rtf.¡±µÄ¶ñÒâÎļþ£¬£¬£¬£¬£¬ÀûÓÃÖ¸±ê¶ÔDZÔں˹¥»÷µÄÕð¾ªÓÕʹÆä´ò¿ªÎļþ¡£¡£¡£¡£¡£¸ÃRTFÎļþÊÔIJÀûÓÃCVE-2022-30190£¨Follina£©ÔÚÖ¸±êÉ豸¸ßµÍÔØ²¢Æô¶¯CredoMap¶ñÒâÈí¼þ(docx.exe)£¬£¬£¬£¬£¬×îÖÕÖ¼ÔÚÇÔÈ¡´æ´¢ÔÚChrome¡¢EdgeºÍFirefoxä¯ÀÀÆ÷ÖеÄÐÅÏ¢£¬£¬£¬£¬£¬ÈçÕÊ»§Í´´¦ºÍcookieµÈ¡£¡£¡£¡£¡£


https://blog.malwarebytes.com/threat-intelligence/2022/06/russias-apt28-uses-fear-of-nuclear-war-to-spread-follina-docs-in-ukraine/


5¡¢Microsoft 365·þÎñÖжϣ¬£¬£¬£¬£¬³ÁÖ÷Óɺó¸´Ô­Õý³£


¾Ý6ÔÂ21ÈÕ±¨Â·£¬£¬£¬£¬£¬´óÁ¿µÄMicrosoft 365¿Í»§»ã±¨·þÎñÑÓ³¤¡¢µÇ¼ʧ°ÜºÍ½Ó¼ûÕÊ»§³öÏÖÎÊÌâ¡£¡£¡£¡£¡£ÖÐ¶ÏÆðÍ·ÓÚUTC¹¦·ò6ÔÂ20ÈÕÍíÉÏ11:00£¬£¬£¬£¬£¬Óû§ÔÚ½Ó¼ûijЩM365·þÎñʱ¿ÉÄÜ»á²úÉúÑÓ³¤ºÍʧ°Ü¡£¡£¡£¡£¡£ÔÚ³ÁÆôÊÜÓ°ÏìµÄ·þÎñÆ÷²¢³ÁÖ÷Óɺ󣬣¬£¬£¬£¬ËùÓÐÊÜÓ°ÏìµÄ²úÆ·¶¼¸´Ô­Õý³£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬Æ¾¾Ý΢Èí°ä²¼µÄ×îиüУ¬£¬£¬£¬£¬Õâ´ÎÊÂÎñµÄµ××ÓÔ­ÒòÊÇ»ù´¡ÉèÊ©¶Ïµç£¬£¬£¬£¬£¬µ¼ÖÂÔÚÎ÷ŷΪÓû§Ìṩ·þÎñµÄMicrosoft 365Á÷Á¿ÖÎÀíϵͳ±ØÐë½øÐйÊÕÏ×ªÒÆ£¬£¬£¬£¬£¬µ«´Ë²Ù×÷δÄÜÕýȷʵÏÖ£¬£¬£¬£¬£¬µ¼Ö¶à¸öMicrosoft 365·þÎñµÄÑÓ³¤ºÍ½Ó¼ûʧ°Ü¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-365-outage-affects-microsoft-teams-and-exchange-online/


6¡¢MEGA°ä²¼°²È«¸üн¨¸´¿ÉÓÃÀ´½âÃÜÓû§Êý¾ÝµÄ·ì϶


ýÌå6ÔÂ22Èճƣ¬£¬£¬£¬£¬MEGA°ä²¼ÁËÒ»¸ö°²È«¸üУ¬£¬£¬£¬£¬½¨¸´¿ÉÄÜй¶Óû§Êý¾ÝµÄÒ»×éÑϳÁµÄ·ì϶¡£¡£¡£¡£¡£MEGAÊÇÔÆ´æ´¢ºÍÎļþÍйܷþÎñ£¬£¬£¬£¬£¬Õ¼ÓÐ2.5ÒÚ×¢²áÓû§£¬£¬£¬£¬£¬×ܹ²ÉÏ´«ÁË1200ÒÚ¸öÎļþ£¬£¬£¬£¬£¬´óÓ׸ߴï1000 PB¡£¡£¡£¡£¡£MEGAµÄÖ°ÄÜÖ®Ò»ÊǶÔÊý¾Ý½øÐж˵½¶Ë¼ÓÃÜ£¬£¬£¬£¬£¬Ö»ÓÐЧ»§Äܹ»½Ó¼û½âÃÜÃÜÔ¿¡£¡£¡£¡£¡£µ«×êÑÐÈËÔ±Åú×¢¼ÓÃÜËã·¨Öеķì϶¿ÉÓÃÀ´½Ó¼ûÓû§µÄ¼ÓÃÜÊý¾Ý£¬£¬£¬£¬£¬²¢·¢ÏÖÁË5ÖÖDZÔڵĹ¥»÷·½Ê½£ºRSAÃÜÔ¿¸´Ô­¡¢Ã÷Îĸ´Ô­¡¢¿ò¼Ü¹¥»÷¡¢ÆëÈ«ÐÔ¹¥»÷ºÍGaP Bleichenbacher¹¥»÷¡£¡£¡£¡£¡£MEGAÒѾ­½¨¸´ÁËǰÁ½¸öÎÊÌ⣬£¬£¬£¬£¬»º½âÁ˵ÚÈý¸öÎÊÌ⣬£¬£¬£¬£¬²¢½«ÔÚºóÐø¸üÐÂÖн¨¸´Ôü×ÒµÄÁ½¸öÎÊÌâ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/mega-fixes-critical-flaws-that-allowed-the-decryption-of-user-data/