Ìõ¼Ç±¾ÖÆÔìÉÌÈʱ¦Ñ¬È¾DoppelPaymer£¬£¬£¬£¬±»ÀÕË÷1700ÍòÃÀÔª£»£»£»£»£»£»Î¢ÈíÐû²¼ÖܶþÇå¾²¸üУ¬£¬£¬£¬×ܼÆÐÞ¸´112¸öÎó²î

Ðû²¼Ê±¼ä 2020-11-11
1.Ìõ¼Ç±¾ÖÆÔìÉÌÈʱ¦Ñ¬È¾DoppelPaymer£¬£¬£¬£¬±»ÀÕË÷1700ÍòÃÀÔª


1.jpg


Ìõ¼Ç±¾ÖÆÔìÉÌÈʱ¦Ôâµ½DoppelPaymerÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬±»ÀÕË÷1700ÍòÃÀÔª¡£¡£¡£¡£¡£Èʱ¦£¨Compal£©ÊÇÈ«ÇòµÚ¶þ´óÔ­´´Éè¼Æ(ODM)Ìõ¼Ç±¾µçÄÔÖÆÔìÉÌ£¬£¬£¬£¬ÓëÆ»¹û¡¢»ÝÆÕ¡¢´÷¶û¡¢åÚÏëºÍºê³žµÈ×ÅÃû¹«Ë¾ÏàÖú¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖÆäÖ»Êǰ칫×Ô¶¯»¯ÏµÍ³·ºÆðÒì³££¬£¬£¬£¬²¢Î´ÏñÍâ½çËù±¨µÀµÄÄÇÑù±»ºÚ¿ÍÀÕË÷£¬£¬£¬£¬ÏÖÔÚÉú²úÖÐÒ»ÇÐÕý³£¡£¡£¡£¡£¡£µ«¾ÝÐÂÎÅÍøÕ¾BleepingComputer³ÆÆäÒÑ»ñµÃÊê½ð¼Í¼£¬£¬£¬£¬ÆäÖкڿÍÍÅ»ïÒªÇóÖ§¸¶1100±ÈÌØ±Ò£¨16725500ÃÀÔª£©¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/laptop-maker-compal-hit-by-ransomware-17-million-demanded/


2.΢ÈíÐû²¼ÖܶþÇå¾²¸üУ¬£¬£¬£¬×ܼÆÐÞ¸´112¸öÎó²î


2.jpg


΢ÈíÐû²¼11ÔµÄÖܶþÇå¾²¸üУ¬£¬£¬£¬×ܼÆÐÞ¸´112¸öÎó²î¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄ½ÏΪÑÏÖØµÄÎó²î°üÀ¨WindowsÄÚºËÃÜÂëÇý¶¯³ÌÐò£¨cng.sys£©ÖеÄÌáȨ0day£¨CVE-2020-17087£©¡¢Azure SphereÌØÈ¨ÌáÉýÎó²î£¨CVE-2020-16988£©¡¢Microsoftä¯ÀÀÆ÷ÄÚ´æËð»µÎó²î£¨CVE-2020-17058£©¡¢Chakra¾ç±¾ÒýÇæÄÚ´æËð»µÎó²î£¨CVE-2020-17048£©¡¢Internet ExplorerÄÚ´æËð»µÎó²î£¨CVE-2020-17053£©ºÍWindows Print SpoolerÔ¶³ÌÖ´ÐдúÂëÎó²î£¨CVE-2020-17042£©µÈ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-november-2020-patch-tuesday-fixes-112-vulnerabilities/


3.еÄÒøÐÐľÂíGhimob¿É¼à¿Ø153¸öAndroidÓ¦ÓÃ


3.jpg


Çå¾²¹«Ë¾kaspersky·¢Ã÷еÄÒøÐÐľÂíGhimob¿É¼à¿Ø153¸öAndroidÓ¦Óᣡ£¡£¡£¡£Ghimob²¢Î´Í¨¹ý¹Ù·½PlayÊÐËÁ¿¯ÐУ¬£¬£¬£¬¶øÊÇʹÓõç×ÓÓʼþ»ò¶ñÒâÍøÕ¾½«Óû§Öض¨Ïòµ½ÆäËûAndroidÓ¦ÓõÄÐû´«ÍøÕ¾£¬£¬£¬£¬ÕâЩӦÓÃð³äÁ˹ٷ½Ó¦ÓóÌÐò£¬£¬£¬£¬´øÓÐGoogle Defender¡¢Google DocsµÈ×ÖÑù¡£¡£¡£¡£¡£Ò»µ©Óû§ÀÖ³É×°Ö㬣¬£¬£¬¸Ã¶ñÒâÓ¦Óý«ÇëÇó»á¼ûAccessibilityЧÀÍ¡£¡£¡£¡£¡£ÔÊÐíÇëÇóºóÆä»áÔÚÓû§ÊÖ»úÖÐËÑË÷153¸öÓ¦Ó㬣¬£¬£¬²¢ÏÔʾαÔìµÄµÄµÇÂ¼Ò³Ãæ£¬£¬£¬£¬ÒÔÇÔÈ¡Óû§µÄƾ֤¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/new-ghimob-malware-can-spy-on-153-android-mobile-applications/


4.Ñо¿Ö°Ô±Åû¶ÃÀ¹ú¹ú·À²¿ÄÚÍø¿ÉÐ®ÖÆDODÕ˺ŵÄÎó²î


4.jpg


Çå¾²¹«Ë¾Silent BreachµÄÑо¿Ô±Jeff SteinburgÅû¶ÃÀ¹ú¹ú·À²¿ÄÚÍø¿ÉÐ®ÖÆDODÕ˺ŵÄÎó²î¡£¡£¡£¡£¡£½öͨ¹ýÐ޸ķ¢Ë͵½DODЧÀÍÆ÷µÄWebÇëÇóÖеÄһЩ²ÎÊý±ã¿ÉÒÔʹÓøÃÎó²î£¬£¬£¬£¬À´Ð®ÖÆDODÕÊ»§¡£¡£¡£¡£¡£ÓÉÓÚÖ»Ðè×îµÍµÄÊÖÒÕˮƽ¾ÍÄÜʹÓúÍÐ®ÖÆí§Òâ¹ú·À²¿ÕʺÅ£¬£¬£¬£¬Òò´ËÆäÑÏÖØË®Æ½±»ÆÀΪÑÏÖØ(9 ~ 10)¡£¡£¡£¡£¡£ÏÖÔÚÃÀ¹ú¹ú·À²¿ÒѾ­ÐÞ¸´Á˸ÃÎó²î¡£¡£¡£¡£¡£¶øSteinburgÒ²»ñµÃÁËDODµÄÔ¶ÈÑо¿Ö°Ô±½±¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/bug-hunter-wins-researcher-of-the-month-award-for-dod-account-takeover-bug/


5.ºÚ¿ÍʹÓÃαÔìµÄTeams¸üзַ¢Cobalt Strike


5.jpg


ºÚ¿ÍʹÓÃαÔìµÄTeams¸üзַ¢Cobalt Strike£¬£¬£¬£¬Ö÷ÒªÕë¶Ô½ÌÓý²¿·Ö¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃZeroLogon£¨CVE-2020-1472£©Îó²î»ñÈ¡ÖÎÀíÔ±»á¼ûȨÏÞ£¬£¬£¬£¬È»ºóͨ¹ýËÑË÷ÒýÇæÐ§¹û»òÔÚÏß¶ñÒâ¹ã¸æ£¬£¬£¬£¬Ö²ÈëÐéα¹ã¸æÀ´ÓÕʹÓû§×°ÖøüС£¡£¡£¡£¡£Ö®ºó¹¥»÷Õß½«×°ÖÃCobalt Strike£¬£¬£¬£¬ÒÔЭÖúÆäÔÚÊܺ¦ÕßÍøÂçÖÐÔÚÍøÂçÖкáÏòÒÆ¶¯¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬¸Ã¹¥»÷»¹»á×°ÖÃMicrosoft TeamsµÄÕýµ±¸±±¾£¬£¬£¬£¬ÒÔ×èÖ¹Êܺ¦Õß²ì¾õµ½´Ë´Î¹¥»÷¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fake-microsoft-teams-updates-lead-to-cobalt-strike-deployment/


6.kasperskyÐû²¼2020ÄêÀÕË÷Èí¼þµÄÌ¬ÊÆÆÊÎö±¨¸æ


6.jpg


kasperskyÐû²¼2020ÄêÀÕË÷Èí¼þµÄÌ¬ÊÆÆÊÎö±¨¸æ¡£¡£¡£¡£¡£±¨¸æÖ¸³öƾ֤ÉϰëÄ걬·¢µÄ¼¸ÆðÊÂÎñ£¬£¬£¬£¬Åú×¢ÀÕË÷Èí¼þµÄ¹æÄ£ÔÚÒ»Ö±À©´ó¡£¡£¡£¡£¡£2Ô·ݵ¤Âó¹«Ë¾ISSµÄÊýÊ®ÍòÃûÔ±¹¤ÒòÀÕË÷Èí¼þ¹¥»÷Ó빫˾ЧÀͶϿª£¬£¬£¬£¬Ôì³É7500Íò- 1.14ÒÚÃÀÔªËðʧ£»£»£»£»£»£»IT¹«Ë¾CognizantÒò¸ÃÀ๥»÷µ¼ÖÂ5000Íò-7000ÍòÃÀÔªËðʧ¡£¡£¡£¡£¡£¸Ã±¨¸æÖ¸³öÐèҪͨ¹ýÀ¬»øÓʼþ¹ýÂËÆ÷£¬£¬£¬£¬°´ÆÚ¸üÐÂËùÓÐÒªº¦ÓªÒµÐÅÏ¢µÄ±¸·Ý£¬£¬£¬£¬½«±¸·Ý´æ´¢ÔÚÇå¾²µÄÔÆÖеȷ½·¨À´±ÜÃâ´ËÀ๥»÷¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.kaspersky.com/blog/ransomware-incidents-2020/37589/