Å·ÖÞÍøÂçÄþ¾²¾ÖENISAÐû²¼2021ÄêÍþÐ²Ì¬ÊÆ·ÖÎö³ÂËß
Ðû²¼Ê±¼ä 2021-11-04Ñо¿ÍŶӷ¢ÏÖ¼¸ºõÍþвËùÓдúÂëµÄ©¶´Trojan Source
½£ÇÅ´óѧµÄÑо¿ÈËÔ±ÔÚ11ÔÂ1ÈÕ¹ûÈ»ÁËÒ»¸öÓ°Ïì´ó¶àÊý¼ÆËã»ú´úÂë±àÒëÆ÷ºÍÐí¶àÈí¼þ¿ª·¢»·¾³µÄ©¶´Trojan Source¡£¸Ã©¶´´æÔÚÓÚUnicodeÖУ¬ÓÐÁ½ÖÖÀûÓÃÒªÁ죺ÆäÒ»ÊÇʹÓÃUnicodeµÄBidiËã·¨£¨CVE-2021-42574£©£¬¶Ô×Ö·û½øÐÐÊÓ¾õÉϵÄÖØÐÂÅÅÐò£¬Ê¹Æä·ºÆðÓë±àÒëÆ÷ºÍ½âÊÍÆ÷Ëù²îÒìµÄÂ߼˳Ðò£»ÁíÒ»ÖÖÊÇͬÐÎÎÄ×Ö¹¥»÷(CVE-2021-42694)£¬¼´ÀûÓÃÔÚÊÓ¾õÉÏ¿´ÆðÀ´ÏàËÆµÄ²îÒì×Ö·û¡£¸Ã©¶´ÊÊÓÃÓÚC¡¢C++¡¢C#¡¢JavaScript¡¢JavaµÈ¹ã·ºÊ¹ÓõÄÓïÑÔ£¬¿ÉÓÃÓÚ¹©Ó¦Á´¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.trojansource.codes/
Ö鱦ÉÌGraffÔâµ½ContiÀÕË÷¹¥»÷£¬ÌØÀÊÆÕµÈÈËÐÅϢй¶
10ÔÂ31ÈÕ£¬Ã¿ÈÕÓʱ¨±¨µÀÀÕË÷ÍÅ»ïConti¹¥»÷ÁËÖ鱦ÉÌGraff²¢ÇÔÈ¡´óÁ¿Êý¾Ý¡£Ä¿Ç°£¬¹¥»÷ÕßÒÑÔÚ°µÍøÉϹûÈ»ÁËÉæ¼°ÌÆÄɵ¡¤ÌØÀÊÆÕ¡¢°ÂÆÕÀ¡¤Î¸¥ÈðºÍ´óÎÀ¡¤±´¿ËººÄ·µÄ69000·Ý»úÃÜÎļþ£¬×÷ΪÑù±¾Êý¾Ý¡£²¢Éù³ÆÄ¿Ç°¹ûÈ»µÄÐÅÏ¢Éæ¼°Á˸ù«Ë¾Ô¼11000¸ö¿Í»§£¬½öÕ¼ÆäÇÔÈ¡µÄÈ«²¿Êý¾ÝµÄ1%¡£ContiµÄÊê½ð·Ç³£¸ß£¬Ô¼Õ¼Êܺ¦ÕßÄêÊÕÈëµÄ10%£¬¶øGraffÔÚ2019ÄêµÄÊÕÈëΪ4.5ÒÚÓ¢°÷¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/123980/cyber-crime/conti-ransomware-graff-jeweller.html
ÃÀ¹úÒ½ÁƱ£½¡·þÎñ¹«Ë¾PHMÈ·ÈÏÆäÔâµ½ÀÕË÷Èí¼þ¹¥»÷
ÃÀ¹úÒ½ÁƱ£½¡·þÎñ¹«Ë¾Professional Healthcare Management(PHM)ÔÚ10ÔÂ31ÈÕÈ·ÈÏÆäÔâµ½ÁËÀÕË÷¹¥»÷¡£¹¥»÷·¢ÉúÔÚ9ÔÂ14ÈÕ£¬Ð¹Â¶Á˿ͻ§µÄÐÕÃû¡¢Éç»áÄþ¾²ºÅÂë¡¢½¡¿µ±£ÏÕÐÅÏ¢¡¢´¦·½Ãû³ÆºÍÕï¶Ï´úÂëµÈÐÅÏ¢¡£PHM³Æ·¢ÏÖ¹¥»÷ºóÁ¢¼´½ÓÄÉ´ëÊ©±£»¤Æäϵͳ²¢»Ö¸´ÔËÓª£¬Ä¿Ç°ÕýÔÚ֪ͨÄÇЩ¿ÉÄÜÊÜ´ËÓ°ÏìµÄ¿Í»§£¬²¢½«ÎªÆäÌṩÃâ·ÑµÄÉí·Ý¼à¿ØºÍ±£»¤·þÎñ¡£
ÔÎÄÁ´½Ó£º
https://www.databreaches.net/tn-professional-healthcare-management-discloses-ransomware-incident/
Kaspersky·¢ÏÖÀûÓÃÆäAmazon SESÁîÅÆµÄµöÓã»î¶¯
Äþ¾²¹«Ë¾KasperskyÔÚ±¾ÖÜÒ»Ðû²¼ÁËÒ»·Ýͨ¸æ£¬³ÆÓеöÓã»î¶¯ÀûÓÃÆäAmazon SESÁîÅÆ¡£´Ë´Î»î¶¯ÀûÓÃÁËKasperskyµÄnoreply@sm.kaspersky.comµÈºÏ·¨µØÖ·£¬²¢Ê¹ÓÃÁ˵öÓ㹤¾ß°üMIRCBOOT£¬Ö¼ÔÚÇÔȡĿ±êµÄOffice 365ƾ¾Ý¡£Ñо¿ÈËԱȷ¶¨£¬²¿ÃÅÓʼþÊÇʹÓúϷ¨µÄÑÇÂíÑ·SESÁîÅÆ·¢Ë͵ģ¬´Ë·ÃÎÊÁîÅÆÊÇÔÚ²âÊÔ2050.earthÍøÕ¾µÄÆÚ¼ä·¢±í¸øµÚÈý·½³Ð°üÉ̵쬏ÃÍøÕ¾Ä¿Ç°Ò²ÍйÜÔÚÑÇÂíÑ·ÉÏ£¬·¢ÏÖ¹¥»÷»î¶¯ºóÁ¢¼´È¡ÏûÁË´ËSESÁîÅÆ¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/office-365-phishing-campaign-kasperskys-amazon-ses-token/175915/
Cisco TalosÐû²¼2021ÄêQ3Ó¦¼±ÏìӦʼþµÄ·ÖÎö³ÂËß
Cisco TalosÔÚ10ÔÂ28ÈÕÐû²¼ÁË2021ÄêQ3Ó¦¼±ÏìӦʼþµÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬ÔÚ2021Äê7ÔÂÖÁ10ÔÂÆÚ¼ä£¬ÀÕË÷Èí¼þÒÀÈ»ÊDZ¾¼¾¶È×îÖ÷ÒªµÄÍþв£¬Ô¼Õ¼ËùÓÐÍþвµÄ38%£¬»¹·ºÆðÁËÐí¶àеÄÀÕË÷Èí¼þ¼Ò×åVice Society¡¢Hive¡¢Karma¡¢Grief¡¢CryptBDºÍThanos¡£µç×ÓÓʼþÊÇ×î³£¼ûµÄ³õʼѬȾý½é£¬¶øÈ±·¦¶àÒòËØÉí·ÝÑéÖ¤(MFA)³ÉΪÆóÒµÄþ¾²µÄ×î´óÕϰ֮һ¡£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2021/10/quarterly-report-incident-response.html
Å·ÖÞÍøÂçÄþ¾²¾ÖENISAÐû²¼2021ÄêÍþÐ²Ì¬ÊÆ·ÖÎö³ÂËß
Å·ÖÞÍøÂçÄþ¾²¾ÖENISAÔÚ10ÔÂ27ÈÕÐû²¼ÁË2021ÄêÍþÐ²Ì¬ÊÆ·ÖÎö³ÂËß¡£³ÂËßÈ·¶¨ÁËÖ÷ÒªÍþв¡¢¹¥»÷¼¼Êõ¡¢ÖµµÃ×¢ÒâµÄʼþºÍÏà¹ØÇ÷ÊÆ£¬»¹ÌṩÁ˽µµÍ·çÏյĽ¨Òé¡£±¾³ÂËßÖ÷ÒªÌÖÂÛÁË9ÖÖÍøÂçÄþ¾²ÍþвÀà±ð£ºÀÕË÷Èí¼þ¡¢¶ñÒâÈí¼þ¡¢¼ÓÃܽٳ֡¢µç×ÓÓʼþÏà¹ØÍþв¡¢¶ÔÊý¾ÝµÄÍþв¡¢¶Ô¿ÉÓÃÐÔºÍÍêÕûÐÔµÄÍþв¡¢Ðé¼ÙÐÅÏ¢£¨´íÎóÐÅÏ¢£©¡¢·Ç¶ñÒâÍþв¡¢ºÍ¹©Ó¦Á´¹¥»÷¡£´ËÍ⣬³ÂËßÖ¸³ö£¬ÀÕË÷Èí¼þ¹¥»÷ÒѳÉΪÖ÷ÒªÍþв¡£
ÔÎÄÁ´½Ó£º
https://www.enisa.europa.eu/publications/enisa-threat-landscape-2021