Ó¢¹ú´¦Öóͷ£Å·ÃËÓÀ¾Ó¼Æ»®Ê±ÖÁÉÙÎ¥·´ÁË100´ÎGDPR£»£»£»£»APT34й¥»÷»î¶¯Karkoff 2020
Ðû²¼Ê±¼ä 2020-03-041.Ó¢¹ú´¦Öóͷ£Å·ÃËÓÀ¾Ó¼Æ»®Ê±ÖÁÉÙÎ¥·´ÁË100´ÎGDPR
Ó¢º£ÄÚÕþ²¿ÔÚ´¦Öóͷ£Å·ÃËÓÀ¾Ó¼Æ»®£¨EUSS£©Ê±ÖÁÉÙÎ¥·´ÁË100´ÎGDPR¡£¡£¡£Ê×ϯ½çÏߺÍÒÆÃñ¼ì²é¹Ù£¨David Ilt£©ÔÚÒÆÃñî¿Ïµ»ú¹¹¾ÙÐеÄÒ»·Ý±¨¸æÖÐÌåÏÖ£¬£¬£¬Ö»¹ÜGDPRÒªÇó¶ÔÔ±¹¤¾ÙÐÐÒâʶÅàѵ£¬£¬£¬µ«ÈԼͼµ½¶ÔGDPRµÄÑÏÖØÎ¥·´¡£¡£¡£Æ¾Ö¤¸Ã±¨¸æ£¬£¬£¬×èÖ¹2019Äê8ÔÂ⣬£¬£¬ÄÚÕþ²¿£¨EUSSµÄ¼àÊÓÕߣ©ÊÕµ½ÁË130Íò·ÝÉêÇ룬£¬£¬²¢ÇÒÒѾÓÐÉϰÙÍòÈË»ñµÃÅú×¼¡£¡£¡£µ«ÔÚ2019Äê3ÔÂ30ÈÕÖÁ8ÔÂ31ÈÕʱ´ú£¬£¬£¬Õþ¸®Î¥·´ÁËGDPRµÄÊÂÎñÓÐ100Æð¡£¡£¡£ÕâЩÊÂÎñ°üÀ¨½«Éí·ÝÖ¤¿¨Æ¬·¢ËÍÖÁ¹ýʧµÄÉêÇëÈ˺͵ص㣻£»£»£»Ðí¶à»¤ÕÕɥʧÁË£¬£¬£¬Éí·Ý֤ʵÎļþ±»ÓÊÕþ²¿·ÖºÍEUSS·Å´íÁ˵ط½£»£»£»£»Î´¾Ô޳ɱãÓëµÚÈý·½¹²ÏíÉêÇëÈ˵ÄÐÅÏ¢µÈ¡£¡£¡£ÄÚÕþ²¿ÌåÏֻᰴÆÚÉó²éËùÓÐÁ÷³ÌºÍ³ÌÐò£¬£¬£¬ÒÔ¼õÇáÊý¾Ýй¶µÄΣº¦¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/uk-home-office-breached-gdpr-100-times-through-botched-handling-of-eu-settlement-scheme/
2.Checkpoint½¨Éè¶ñÒâÈí¼þÈÆÌ«¹ýÎöµÄÊÖÒյİٿÆÈ«Êé
Checkpoint½¨ÉèÁ˹ØÓÚ¶ñÒâÈí¼þÓÃÀ´ÌӱܯÊÎöµÄÖÖÖÖÊÖÒյİٿÆÈ«Êé¡£¡£¡£¸Ã°Ù¿ÆÈ«Ê麸ÇÁËÓëÎļþϵͳ¡¢×¢²á±í¡¢Í¨ÓÃOSÅÌÎÊ¡¢È«¾ÖOS¹¤¾ß¡¢Óû§½çÃæ¡¢OS¹¦Ð§¡¢Àú³Ì¡¢ÍøÂç¡¢CPU¡¢¹Ì¼þ±í¡¢¹³×Ó¡¢Ó²¼þÒÔ¼°MacOSÌØ¶¨µÄɳÏäÓйصÄÌÓ±ÜÊÖÒÕ¡£¡£¡£Ã¿Ò»¸öÖֱ𶼰üÀ¨ÊÖÒÕÐÎò¡¢´úÂëʾÀý¡¢ÓÃÓÚ¸ú×Ù¸ÃÊÖÒÕµÄÊðÃû½¨Òé¡¢¿É¼ì²âÇéÐÎÀàÐ͵ıí¸ñÒÔ¼°¶Ô²ß¡£¡£¡£Checkpoint»¹ÍýÏëÔöÌíÓë¼ÆÊ±¡¢Windows Management Instrumentation£¨WMI£©ºÍÈËÀàÐÐΪÒòËØÓйصÄÌÓ±ÜÊÖÒÕ¡£¡£¡£Ïà¹ØÁìÓòµÄר¼Ò¿ÉÒÔÔÚGithubÒ³ÃæÉÏΪ¸Ã°Ù¿ÆÈ«Êé×ö³öТ˳¡£¡£¡£Ò»Ð©ÑÝʾ¹æ±ÜÊÖÒյŤ¾ßÊÇ¿ªÔ´µÄ£¬£¬£¬Í¬Ê±Checkpoint»¹Ðû²¼ÁË×Ô¼ºµÄÃûΪInviZzzibleµÄ¿ªÔ´¹¤¾ß¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/checkpoint-creates-encyclopedia-malware-evasion-techniques
3.Ó¢¹úTravelex¹«Ë¾Ô¤¼ÆÒòÍøÂç¹¥»÷Ëðʧ2500ÍòÓ¢°÷
¾Ý·͸É籨µÀ£¬£¬£¬ÓÉÓÚ12ÔÂÏÂÑ®µÄÀÕË÷Èí¼þ¹¥»÷ÊÂÎñ£¬£¬£¬Íâ±Ò¶Ò»»¹«Ë¾TravelexÔ¤¼ÆÆäµÚÒ»¼¾¶ÈµÄ½¹µãÊÕÈëËðʧΪ2500ÍòÓ¢°÷£¨ºÏ3200ÍòÃÀÔª£©¡£¡£¡£¸Ã¹«Ë¾»¹ÌåÏÖÒѻָ´ÁËËùÓÐÃæÏò¿Í»§µÄϵͳ¡£¡£¡£Travelexͨ¹ýÆä×Ô¶¯¶©µ¥Ð§ÀÍΪ»ã·áÒøÐС¢°Í¿ËÀ³ÒøÐС¢Î¬ÕäÇ®±ÒÒÔ¼°Ó¢¹úÁãÊÛÉÌTescoºÍSainsburyµÄÒøÐв¿·Ö¿Í»§ÌṩÍâ»ãЧÀÍ¡£¡£¡£TravelexÌåÏִ˴ι¥»÷²»»á¶ÔËæºó¼¸¸ö¼¾¶ÈµÄÉúÒâÔì³ÉÈκÎʵÖÊÐÔÓ°Ïì¡£¡£¡£¸Ã¹«Ë¾»¹³Æ¹Ú×´²¡¶¾µÄ±¬·¢¶ÔÆäÓªÒµÔì³ÉÁËÁíÍâÒ»¸ö¸ºÃæÓ°Ï죬£¬£¬µ«Î´Ô¤¼Æ¸Ã²¡¶¾»á´øÀ´Èκξ¼ÃËðʧ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://uk.finance.yahoo.com/news/travelex-expects-25-million-hit-093953943.html
4.Let's Encrypt³·»ØÁè¼Ý300Íò¸öTLSÖ¤Êé
ÓÉÓÚÔÚºó¶Ë´úÂëÖз¢Ã÷ÁËÒ»¸öbug£¬£¬£¬Let's EncryptÏîÄ¿ÍýÏë´ÓÌìϱê׼ʱ¼ä2020Äê3ÔÂ4ÈÕ00:00×îÏÈ×÷·ÏÁè¼Ý300Íò¸öTLSÖ¤Êé¡£¡£¡£ÏêϸÀ´Ëµ£¬£¬£¬¸ÃbugÓ°ÏìÁËBoulder£¬£¬£¬Let's EncryptÏîĿʹÓøÃЧÀÍÆ÷Èí¼þÔÚ¿¯ÐÐTLSÖ¤Êé֮ǰÑéÖ¤Óû§¼°ÆäÓò¡£¡£¡£¸ÃbugÓ°ÏìÁËBoulderÄÚ²¿CAA£¨Ö¤Êé½ÒÏþ»ú¹¹ÊÚȨ£©¹æ·¶µÄʵÑ飬£¬£¬¡°µ±Ò»¸öÖ¤ÊéÇëÇó°üÀ¨N¸öÐèÒª¾ÙÐÐCAAÖØÐ¼ì²éµÄÓòÃûʱ£¬£¬£¬Boulder½«Ñ¡ÔñÒ»¸öÓòÃû²¢¼ì²éN´Î¡£¡£¡£ÕâÏÖʵÉÏÒâζ×ÅÈôÊÇÒ»¸öÓû§ÔÚʱ¼äXÑéÖ¤ÁËÒ»¸öÓòÃû£¬£¬£¬²¢ÇÒ¸ÃÓòÃûÔÚʱ¼äXµÄCAA¼Í¼ÔÊÐíLet's Encrypt¿¯ÐУ¬£¬£¬Ôò¸ÃÓû§¿ÉÒÔÔÚX+30ÌìµÄʱ¼äÀ￯ÐаüÀ¨¸ÃÓòÃûµÄÖ¤Ê飬£¬£¬×ÝȻ֮ºóÓÐÈËÔÚ¸ÃÓòÃûÉÏ×°ÖÃÁËեȡLet's Encrypt¿¯ÐеÄCAA¼Í¼¡±¡£¡£¡£ÔÚÕâ300Íò¸ö×÷·ÏµÄÖ¤ÊéÖУ¬£¬£¬ÓÐ100Íò¸öÊÇͳһÓò/×ÓÓòµÄÖØ¸´Ï£¬£¬Òò´ËÊÜÓ°ÏìÖ¤ÊéµÄÏÖʵÊýĿԼΪ200Íò¸ö¡£¡£¡£ÔÚ3ÔÂ4ÈÕ00:00Ö®ºóËùÓÐÊÜÓ°ÏìµÄÖ¤Êé¶¼½«´¥·¢ä¯ÀÀÆ÷ºÍÆäËûÓ¦ÓóÌÐòÖеĹýʧ£¬£¬£¬ÓòÃûËùÓÐÕß½«±ØÐèÇëÇóеÄTLSÖ¤Êé²¢Ìæ»»¾ÉµÄTLSÖ¤Êé¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/lets-encrypt-to-revoke-3-million-certificates-on-march-4-due-to-bug/
5.APT34й¥»÷»î¶¯Karkoff 2020£¬£¬£¬Õë¶ÔÀè°ÍÄÛÕþ¸®»ú¹¹
Cybaze/Yoroi ZlabµÄר¼Ò·¢Ã÷APT34×éÖ¯µÄÒ»¸öÐÂÑù±¾£¬£¬£¬ËûÃÇÒÔΪ¸ÃÑù±¾ÊÇKarkoffÖ²ÈëÎïµÄ¸üа汾£¬£¬£¬¿ÉÒÔ֤ʵAPT34ÈÔÈ»´¦Óڻ״̬¡£¡£¡£ÔÚÕâ¸öÐµĹ¥»÷»î¶¯ÖÐAPT34¿ÉÄÜÈëÇÖÁËÊôÓÚÀè°ÍÄÛÕþ¸®»ú¹¹µÄMicrosoft Exchange Server¡£¡£¡£ÐÂÑù±¾ÓëÒÑÍùKarkoffÑù±¾µÄÏàËÆÖ®´¦°üÀ¨¾ßÓÐÏàËÆµÄºê½á¹¹¡¢¾ßÓÐÀàËÆÂß¼µÄ.NETÄ£¿£¿£¿é»¯Ö²ÈëÎïÒÔ¼°Ê¹ÓÃMicrosoft Exchange Server×÷ΪͨѶÇþµÀ¡£¡£¡£±ðµÄ£¬£¬£¬ÐÂKarkoffÖ²ÈëÎïʵÏÖÁËеÄÕì̽Âß¼£¬£¬£¬ÒÔ±ã½ö½«×îÖÕµÄÓÐÓúÉÔØÊͷŵ½Ìض¨Ä¿µÄ£¬£¬£¬²¢ÇÒÍøÂçϵͳÐÅÏ¢¡¢ÓòÃû¡¢Ö÷»úÃûºÍÕýÔÚÔËÐеIJÙ×÷ϵͳµÈÐÅÏ¢¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/98802/uncategorized/karkoff-malware-lebanon.html
6.ÐÂPwndLockerÀÕË÷Èí¼þÖ÷ÒªÕë¶ÔÃÀ¹úÊÐÕþÕþ¸®ºÍÆóÒµÍøÂç
Çå¾²Ñо¿Ö°Ô±·¢Ã÷Õë¶ÔÊÐÕþÕþ¸®ºÍÆóÒµÍøÂçµÄÐÂÀÕË÷Èí¼þ¼Ò×å¡°PwndLocker¡±£¬£¬£¬¸Ã¼Ò×å×Ô2019Äêµ×ÒÔÀ´Ò»Ö±»îÔ¾£¬£¬£¬²¢ÔÚÕâ¶Îʱ¼äÄÚ¹¥»÷ÁËÃÀ¹ú¶à¸ö¶¼»áºÍ×éÖ¯¡£¡£¡£PwndLockerÓë½üÆÚÕë¶ÔÒÁÀûŵÒÁÖÝÀÈø¶ûÏØµÄ¹¥»÷Óйأ¬£¬£¬¹¥»÷ÕßÒªÇó50¸ö±ÈÌØ±Ò£¨Ô¼ºÏ44.2ÍòÃÀÔª£©µÄÊê½ð£¬£¬£¬²¢ÇÒ³ÆÔÚ¼ÓÃÜ֮ǰÒѾÇÔÈ¡Á˸ÃÏØµÄÊý¾Ý¡£¡£¡£ÍâµØÃ½ÌåÖ¸³ö£¬£¬£¬ÀÈø¶ûÏØÎÞÒâÖ§¸¶Êê½ð¡£¡£¡£Æ¾Ö¤Ñо¿Ö°Ô±µÄÆÊÎö£¬£¬£¬PwndLockerʹÓá°net stop¡±ÏÂÁî½ûÓÃÁ˶à¸öWindowsЧÀÍ£¬£¬£¬ÀýÈçMicrosoft SQL Server¡¢MySQLºÍExchange£¬£¬£¬²¢ÇÒ¼ì²âºÍɱËÀÓëFirefox¡¢Word¡¢Excel¡¢AccessÒÔ¼°ÓëÇå¾²Èí¼þ¡¢±¸·ÝÓ¦ÓóÌÐòºÍÊý¾Ý¿âЧÀÍÆ÷ÓйصÄÀú³Ì¡£¡£¡£Æä¼ÓÃÜÎļþµÄÀ©Õ¹ÃûΪ¡°.key¡±»ò¡° .pwnd¡±¡£¡£¡£PwndLocker²¢²»ÊǵÚÒ»¸öÕë¶ÔÆóÒµÍøÂçµÄÀÕË÷Èí¼þ£¬£¬£¬Ö®Ç°Ñо¿Ö°Ô±»¹·¢Ã÷ÁËÕë¶ÔÆóÒµÍøÂçµÄSNAKEºÍAko¼Ò×å¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.tripwire.com/state-of-security/security-data-protection/pwndlocker-ransomware-targeting-municipalities-enterprise-networks/


¾©¹«Íø°²±¸11010802024551ºÅ