ºÚ¿ÍÈëÇÖÌØÀÊÆÕ¾ºÑ¡ÍøÕ¾²¢Èö²¥ÐéαÐÅÏ¢£»£»£»ACTI³Æ¶íºÚ¿Í×éÖ¯TurlaÈëÇÖÅ·ÖÞÒ»¸öÕþ¸®×éÖ¯

Ðû²¼Ê±¼ä 2020-10-29
1.ºÚ¿ÍÈëÇÖÌØÀÊÆÕ¾ºÑ¡ÍøÕ¾²¢Èö²¥ÐéαÐÅÏ¢


1.jpg


Õþ¸®¹ÙÔ±ÌåÏÖ £¬ £¬ºÚ¿ÍÔÚÑ¡¾ÙÈÕǰһÖܵÄÐÇÆÚ¶þÈëÇÖÁËÌÆÄɵ¡¤ÌØÀÊÆÕµÄ¾ºÑ¡ÍøÕ¾¡£ ¡£¡£¡£¡£¡£donaldjtrump.comÍøÕ¾±»¡°Õâ¸öÍøÕ¾±»²é·âÁË¡±ÐÂÎÅËùÈ¡´ú £¬ £¬²¢ÌåÏÖ¡°ÌìÏÂÒѾ­Êܹ»ÁËÌÆÄɵ¡¤J¡¤ÌØÀÊÆÕ×ÜͳÌìÌìÉ¢²¥µÄ¼ÙÐÂÎÅ¡±¡£ ¡£¡£¡£¡£¡£±ðµÄ £¬ £¬ºÚ¿Í»¹ºôÓõÍøÃñ¾èÔùMoneroÊý×ÖÇ®±ÒÒÔÖ§³Ö»ò×赲й¶ÓëÌØÀÊÆÕÓйصÄÖ¤¾Ý¡£ ¡£¡£¡£¡£¡£ÌØÀÊÆÕ¾ºÑ¡½²»°ÈËTim MurtaughÌåÏÖ £¬ £¬¸ÃÍøÕ¾ºÜ¿ì»ñµÃÐÞ¸´²¢Ã»ÓÐÈκÎÃô¸ÐÊý¾Ýй¶ £¬ £¬´Ë´Î¹¥»÷µÄȪԴ»¹ÔÚÊÓ²ìÖС£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/trump-campaign-website-broken-hackers


2.ACTI³Æ¶íºÚ¿Í×éÖ¯TurlaÈëÇÖÅ·ÖÞÒ»¸öÕþ¸®×éÖ¯


2.jpg


ƾ֤°£É­ÕÜÍøÂçÍþвÇ鱨£¨ACTI£©µÄ×îб¨¸æ £¬ £¬¶íÂÞ˹µÄºÚ¿Í×éÖ¯TurlaÈëÇÖÁËÒ»¸öδ¹ûÕæÃû³ÆµÄÅ·ÖÞÕþ¸®×éÖ¯µÄϵͳ¡£ ¡£¡£¡£¡£¡£ÎªÁËÈëÇÖ×éÖ¯ÍøÂç £¬ £¬¹¥»÷ÕßʹÓÃÁË×î½ü¸üеÄÔ¶³ÌÖÎÀíľÂí£¨RAT£©ºÍ»ùÓÚÔ¶³ÌÀú³ÌŲÓã¨RPC£©µÄºóÃųÌÐò £¬ £¬ÆäÖаüÀ¨HyperStack¡£ ¡£¡£¡£¡£¡£ACTIÌåÏÖ £¬ £¬Õâ´Î¹¥»÷ÍêÈ«ÇкÏTurla´ÓÊÂÌØ¹¤»î¶¯µÄÄîÍ· £¬ £¬ÏÖÔÚËüÒѾ­ÆÆËðÁËÀ´×Ô100¶à¸ö¹ú¼ÒµÄÕþ¸®¡¢´óʹ¹ÝÒÔ¼°½ÌÓýºÍÑо¿»ú¹¹µÄÊýǧ¸öϵͳ¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/russian-turla-hackers-breach-european-government-organization/


3.MicrosoftÐû²¼KB4577586¸üР£¬ £¬×èֹʹÓÃAdobe Flash


3.jpg


MicrosoftÐû²¼ÁËKB4577586¸üР£¬ £¬ÒÔ×èֹʹÓÃWindowsÉϵÄAdobe Flash¡£ ¡£¡£¡£¡£¡£´Ë´Î¸üнö¿Éͨ¹ýMicrosoft Catalog»ñµÃ¡£ ¡£¡£¡£¡£¡£MicrosoftÉùÃ÷¸Ã¸üн«×Ô¶¯É¾³ýAdobe Flash Player £¬ £¬µ«Éв»ÇåÎúÈ·ÇÐɾ³ýµÄÄÚÈÝ¡£ ¡£¡£¡£¡£¡£¾­ÓɲâÊÔ £¬ £¬´Ë¸üÐÂɾ³ýÁËWindows 10ÖÐÀ¦°óµÄFlash Player£¨32룩°æ±¾ £¬ £¬µ«²»»áɾ³ýÈκÎ×ÔÁ¦°æ±¾µÄAdobe Flash Player¡£ ¡£¡£¡£¡£¡£MicrosoftÔòÌåÏÖ»á2021ÄêÍ·Flashµ½ÆÚºó¶ÔFlash Player¾ÙÐдó¹æÄ£É¾³ý¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-update-to-remove-adobe-flash-from-windows/


4.Enel GroupÔÙ´ÎѬȾÀÕË÷Èí¼þ £¬ £¬Ð¹Â¶5TBµÄÊý¾Ý


4.jpg


¿ç¹úÄÜÔ´¹«Ë¾Enel Group½ñÄêÔâµ½µÚ¶þ´ÎÀÕË÷Èí¼þ¹¥»÷ £¬ £¬NetwalkerÉù³ÆÆäÇÔÈ¡ÁË5TBµÄÊý¾Ý²¢ÀÕË÷1400ÍòÃÀÔªÊê½ð¡£ ¡£¡£¡£¡£¡£EnelÊÇÅ·ÖÞÄÜÔ´ÁìÓò×î´óµÄ¹«Ë¾Ö®Ò» £¬ £¬ÔÚ40¸ö¹ú¼ÒºÍµØÇøÓµÓÐ6100Íò¿Í»§¡£ ¡£¡£¡£¡£¡£½ñÄê6Ô³õ £¬ £¬EnelµÄÄÚ²¿ÍøÂçÔâµ½SnakeÀÕË÷Èí¼þµÄ¹¥»÷ £¬ £¬10ÔÂ19ÈÕÓÖÔâµ½NetwalkerÀÕË÷Èí¼þµÄ¹¥»÷¡£ ¡£¡£¡£¡£¡£ÏÖÔÚ £¬ £¬NetwalkerÒÑÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾Ðû²¼Á˱»µÁÊý¾ÝµÄ½ØÍ¼ £¬ £¬²¢ÌåÏÖ»áÔÚÒ»ÖÜÄÚ¹ûÕæÆäÖеÄÒ»²¿·Ö¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/enel-group-hit-by-ransomware-again-netwalker-demands-14-million/


5.¼Ò¾ß¹«Ë¾SteelcaseѬȾRyukµ¼ÖÂϵͳÔÝʱ¹Ø±Õ


5.jpg


È«Çò×î´óµÄ°ì¹«¼Ò¾ßÖÆÔìÉÌSteelcase³ÆÆäÔÚ10ÔÂ22ÈÕÔâµ½RyukÀÕË÷Èí¼þ¹¥»÷ £¬ £¬²¢µ¼ÖÂϵͳÔÝʱ¹Ø±Õ¡£ ¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ðû²¼ÉùÃ÷³ÆÆäÔÚÐÅÏ¢ÊÖÒÕϵͳÉÏ·¢Ã÷ÁËÍøÂç¹¥»÷ £¬ £¬²¢Ñ¸ËÙ½ÓÄÉÁËһϵÁÐ×èÖ¹²½·¥À´½â¾öÕâÖÖÇéÐÎ £¬ £¬°üÀ¨ÔÝʱ¹Ø±ÕÊÜÓ°ÏìµÄϵͳºÍÏà¹Ø²Ù×÷¡£ ¡£¡£¡£¡£¡£ÏÖÔÚ £¬ £¬¹«Ë¾Éв»ÖªµÀ´Ë¹¥»÷µ¼ÖµÄÏêϸϵͳÊý¾Ýɥʧ»ò×ʲúËðʧ £¬ £¬µ«¹«Ë¾Ô¤¼Æ¸ÃÊÂÎñ²»»á¶ÔÆäÓªÒµÔËÓª»ò²ÆÎñÒµ¼¨±¬·¢ÖØ´óÓ°Ïì¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/steelcase-furniture-giant-hit-by-ryuk-ransomware-attack/    


6.VeracodeÐû²¼Ó¦ÓóÌÐòÇå¾²Ì¬ÊÆµÄÆÊÎö±¨¸æ


6.jpg


VeracodeÐû²¼µÚ11ÆÚÈí¼þÇ徲״̬±¨¸æ £¬ £¬¶ÔÓ¦ÓóÌÐòÇå¾²Ì¬ÊÆ¾ÙÐÐÁËÆÊÎö¡£ ¡£¡£¡£¡£¡£±¨¸æ¶Ô130000¸öÓ¦ÓóÌÐò¾ÙÐÐÁËÆÊÎö £¬ £¬·¢Ã÷76£¥µÄÓ¦ÓÃÖÁÉÙ¾ßÓÐÒ»¸öÇå¾²Îó²î £¬ £¬µ«Ö»ÓÐ24£¥µÄÓ¦ÓþßÓиßÑÏÖØÐÔÎó²î¡£ ¡£¡£¡£¡£¡£±ðµÄ £¬ £¬¸Ã±¨¸æ»¹·¢Ã÷ÁËһЩ¿ÉÌá¸ßÎó²îÐÞ¸´ÂʵÄÒªÁì £¬ £¬ÈçÁ¬ÏµÊ¹ÓöàÖÖɨÃèÀàÐÍ£¨°üÀ¨¾²Ì¬ÆÊÎö£¨SAST£© £¬ £¬¶¯Ì¬ÆÊÎö£¨DAST£©ºÍÈí¼þ×éÉíÆÊÎö£¨SCA£©£© £¬ £¬Í³¼ÆÅú×¢ÄÇЩͬʱʹÓÃSASTºÍDASTµÄÈË¿ÉÒÔ24ÌìÄÚÐÞ¸´Ò»°ëµÄȱÏÝ¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.veracode.com/sites/default/files/pdf/sossv11/soss_infographic_v11.pdf