¹¥»÷»î¶¯Duriͨ¹ýHTMLºÍJavaScript·Ö·¢¶ñÒâÈí¼þ£»£»£»£»ÒòÊÔ¾íÎĵµÐ¹Â¶£¬£¬£¬£¬£¬£¬£¬£¬CRESTÔÝÍ£Ó¢¹úµÄInfosecÈÏÖ¤¿¼ÊÔ
Ðû²¼Ê±¼ä 2020-08-191.¹¥»÷»î¶¯Duriͨ¹ýHTMLºÍJavaScript·Ö·¢¶ñÒâÈí¼þ

ÐµĹ¥»÷»î¶¯DuriʹÓÃHTML¼Ð´øÊÖÒÕºÍJavaScript blob·Ö·¢¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÌÓ±Üɱ¶¾Èí¼þµÄ¼ì²âºÍÆÊÎö¡£¡£¡£DuriʹÓÃHTML¼Ð´øÊÖÒÕ£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ¿Í»§¶Ë£¨ä¯ÀÀÆ÷£©É϶¯Ì¬µØÌìÉúÓÐÓøºÔØ£¬£¬£¬£¬£¬£¬£¬£¬¶ø²»ÊÇÖ¸ÏòЧÀÍÆ÷µÄÖ±½ÓURL£¬£¬£¬£¬£¬£¬£¬£¬Òò´Ë²»»á´«ÊäÈκÎÊý¾ÝÒÔ×èÖ¹±»É³Ïä¼ì²é¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÆÊÎöÁ˸öñÒâÈí¼þÓÐÓøºÔØÖеÄMSIÎļþ£¬£¬£¬£¬£¬£¬£¬£¬·¢Ã÷ÁËÒ»¸ö»ìÏýµÄJScript£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÌá¸ß¸Ã¶ñÒâÈí¼þµÄÒþ²ØÐÔ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/duri-campaign-smuggles-malware-via-html-and-javascript/
2.CISAÖÒÑÔеĴ¹Âڻ»á·Ö·¢¶ñÒâÈí¼þKONNI

ÍøÂçÇå¾²ºÍ»ù´¡½á¹¹Çå¾²¾Ö£¨CISA£©Ðû²¼Çå¾²¾¯±¨£¬£¬£¬£¬£¬£¬£¬£¬ÌṩÓйØKONNIÔ¶³Ì»á¼ûľÂíÐÂÒ»²¨¹¥»÷µÄÊÖÒÕϸ½Ú¡£¡£¡£CISA·¢Ã÷ºÚ¿Íͨ³£ÒÔ´øÓжñÒâVBAºê´úÂëµÄMicrosoft WordÎĵµµÄÐÎʽͨ¹ý´¹ÂÚÓʼþÀ´·Ö·¢KONNI¶ñÒâÈí¼þ¡£¡£¡£KONNIÊÇÒ»ÖÖÔ¶³ÌÖÎÀí¹¤¾ß£¨RAT£©£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹¤¾ß¿É±»Ê¹ÓÃÇÔÈ¡Îļþ¡¢²¶»ñ»÷¼ü¡¢»ñÈ¡ÆÁÄ»¿ìÕÕÒÔ¼°ÔÚÊÜѬȾµÄÖ÷»úÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¸Ã¶ñÒâÈí¼þÖÁÉÙ´Ó2014Äê¾Í×îÏÈ»îÔ¾£¬£¬£¬£¬£¬£¬£¬£¬Áè¼Ý3Äêδ±»·¢Ã÷¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/alerts/aa20-227a
3.Àö×ÈÂùݲÍÒûÔ¤¶©ÏµÍ³Êý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬£¬Æä¿Í»§Ôâµ½Õ©Æ

8ÔÂ15ÈÕÂ×¶ØÀö×ÈÁ¬ËøÂùÝÐû²¼TwitterÌåÏÖ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÔÚ8ÔÂ12ÈÕ·¢Ã÷ËûÃǵIJÍÒûÔ¤¶©ÏµÍ³Öб£´æÊý¾Ýй¶ÎÊÌ⣬£¬£¬£¬£¬£¬£¬£¬Æä¿Í»§ÐÅÏ¢»òÒѱ»Ð¹Â¶²¢±»Ê¹ÓþÙÐÐթƻ¡£¡£¡£¸ÃÂùÝÌåÏÖÒѶԴËй¶ÊÂÎñÕö¿ªÊӲ죬£¬£¬£¬£¬£¬£¬£¬Ã»ÓÐÈκÎÐÅÓÿ¨ÏêϸÐÅÏ¢»ò¸¶¿îÐÅϢй¶¡£¡£¡£¾ÝÓ¢¹ú¹ã²¥¹«Ë¾±¨µÀ£¬£¬£¬£¬£¬£¬£¬£¬ÒÑÓжàÆðʹÓÃÕâЩй¶ÐÅÏ¢¾ÙÐеÄթƻ£¬£¬£¬£¬£¬£¬£¬£¬Æ×Óð³äÊÇÀö×ȵĹÍÔ±¸ø²ÍÌüÔ¤¶©Õß´òµç»°£¬£¬£¬£¬£¬£¬£¬£¬ÓëËûÃÇÈ·ÈÏÔ¤¶©µÄÏêϸÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬Í¬Ê±ÒªÇóËûÃÇÌṩÐÅÓÿ¨Ï¸½Ú¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/ritz-london-struck-by-data-breach-fraudsters-pose-as-staff-in-credit-card-data-scam/
4.ÒòÊÔ¾íÎĵµÐ¹Â¶£¬£¬£¬£¬£¬£¬£¬£¬CRESTÔÝÍ£Ó¢¹úµÄInfosecÈÏÖ¤¿¼ÊÔ

ÒòÊÔ¾íÎĵµÐ¹Â¶£¬£¬£¬£¬£¬£¬£¬£¬CREST×÷·ÏÁËÁ½´ÎÓ¢¹úInfosecÈÏÖ¤¿¼ÊÔ¡£¡£¡£´Ëǰ¸Ã»ú¹¹Åû¶ÁËÒ»·Ý¹ûÕæµÄÎļþ£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨ËƺõÊÇÄÚ²¿¼ì²é±íµÄÎļþ£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°ÓëÒªº¦ÐÐÒµ¼ÓÈëÕßNCC¼¯ÍÅÓйصÄÎĵµ¡£¡£¡£¾ÝÖªÇéÈËʿ͸¶£¬£¬£¬£¬£¬£¬£¬£¬CRESTÔÝÍ£ÁËËùÓеÄCCT INFºÍCCT APP¿¼ÊÔ³¤´ïÒ»¸öÔ£¬£¬£¬£¬£¬£¬£¬£¬Í¬Ê±Éó²éÆäÄÚÈÝ¡£¡£¡£CRESTµÄ½²»°ÈËÌåÏÖ£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚÊý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬£¬ËûÃÇÐèÒªÈýµ½ÖÜΧµÄʱ¼äÀ´ÖØÐ±àдÊÔ¾í£¬£¬£¬£¬£¬£¬£¬£¬ÔÚÊÓ²ì¾ÙÐÐʱ´ú²»»á½ÒÏþÈκÎ̸ÂÛ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.theregister.com/2020/08/17/crest_halts_infosec_exams/
5.ÓÊÂÖ¹«Ë¾CarnivalѬȾÀÕË÷Èí¼þ£¬£¬£¬£¬£¬£¬£¬£¬²¿·ÖÊý¾Ý»òÒÑй¶

È«Çò×î´óµÄÓÊÂÖ¹«Ë¾Carnival CorpÔÚ8ÔÂ15ÈÕÔâµ½ÁËÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬²¿·ÖÊý¾Ý»òÒÑй¶¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿Í»á¼û²¢¼ÓÃÜÁËÆä·Ö¹«Ë¾µÄÐÅÏ¢ÊÖÒÕϵͳ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÇÔÈ¡ÁËÎļþ¡£¡£¡£Æ¾Ö¤¶Ô¸ÃÊÂÎñµÄÆðÔ´ÆÀ¹À£¬£¬£¬£¬£¬£¬£¬£¬¼ÎÄ껪ÒÔΪ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜÒѾ»á¼ûÁËijЩÀ´±öºÍÔ±¹¤µÄСÎÒ˽¼ÒÊý¾Ý¡£¡£¡£¿ÉÊÇCarnivalûÓÐ͸¶ÓйشËÊÂÎñµÄÏêϸÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬ÀýÈçÀÕË÷Èí¼þÃû³Æ£¬£¬£¬£¬£¬£¬£¬£¬»òÆä¹¥»÷Ó°Ïì¹æÄ£µÈ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/worlds-largest-cruise-line-operator-discloses-ransomware-attack/
6.RBSÐû²¼COVID-19¶ÔÊý¾Ýй¶µÄÓ°ÏìµÄÆÊÎö±¨¸æ

RBSÐû²¼COVID-19¶ÔÊý¾Ýй¶µÄÓ°ÏìµÄÆÊÎö±¨¸æ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã±¨¸æÏêϸ̽ÌÖÁËÓÉCOVID-19ÒýÆðµÄ¹©Ó¦Á´ÖÐÖ¹¶ÔÊý¾Ýй¶ÎÊÌâ¼°ÆäËûÇ÷ÊÆµÄÓ°Ïì¡£¡£¡£¾Ý±¨¸æ£¬£¬£¬£¬£¬£¬£¬£¬2020Äê¹ûÕæ±¨¸æµÄÊý¾Ý×ß©ÊÂÎñµÄÊýĿϽµÁË52£¥£¬£¬£¬£¬£¬£¬£¬£¬µ«Ð¹Â¶µÄÊý¾ÝÁ¿È´±ÈÍùÆÚºá¿çËı¶ÒÔÉÏ¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬¹ýʧÉèÖõÄÊý¾Ý¿âºÍЧÀÍÒÀÈ»ÊÇÊý¾Ýй¶µÄÖ÷ҪȪԴ£¬£¬£¬£¬£¬£¬£¬£¬2020ÄêµÚ¶þ¼¾¶È£¬£¬£¬£¬£¬£¬£¬£¬½öÁ½¸öÎó²î¾Íµ¼ÖÂÁË180ÒÚÌõÊý¾Ýй¶¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2020/08/18/publicly-reported-data-breaches-down-52-exposed-records-way-up/


¾©¹«Íø°²±¸11010802024551ºÅ