ÎÚ¿ËÀ¼Óë¶à¹úµ±¾Ö½áºÏµ·»ÙÀÕË÷Èí¼þClopµÄ»ù´¡ÉèÊ©£»×êÑÐÍŶÓÅû¶2G¼ÓÃܳ߶ÈËã·¨´æÔÚ¿ÉÇÔÌýÁ÷Á¿µÄ·ì϶

°ä²¼¹¦·ò 2021-06-18

1.ÎÚ¿ËÀ¼Óë¶à¹úµ±¾Ö½áºÏµ·»ÙÀÕË÷Èí¼þClopµÄ»ù´¡ÉèÊ©


1.jpg


ÎÚ¿ËÀ¼¾¯·½Óë¹ú¼ÊÐ̾¯×éÖ¯¡¢º«¹úºÍÃÀ¹úµ±¾Ö½áºÏ£¬ÔÚ±¾ÖÜÈý³É¹¦µ·»ÙÁËÀÕË÷Èí¼þClopµÄ»ù´¡ÉèÊ©¡£ClopÀÕË÷Èí¼þÍÅ»ï×Ô2019ÄêÒÔÀ´ÆðÍ·»îÔ¾£¬×ܼÆÔì³ÉÁËԼĪ5ÒÚÃÀÔªµÄËðʧ¡£ÎÚ¿ËÀ¼µ±¾Ö³ÆÒѹعطַ¢¶ñÒâÈí¼þµÄ»ù´¡ÉèÊ©ºÍ»ñµÃ¼ÓÃÜÇ®±ÒµÄÇþ·£¬µ«Ä¿Ç°ClopÓÃÀ´¹«¿ª±»µÁÊý¾ÝµÄÍøÕ¾£¨CL0P^-LEAKS£©ÈÔÔÚÔËÐС£°²È«¹«Ë¾Intel 471°µÊ¾£¬ÎÚ¿ËÀ¼µ±¾ÖÖ»¿ÛÁôÁËΪClopÍÅ»ïÏ´Ç®µÄÈË£¬ÆäÖ÷Ìâ³ÉÔ±¿ÉÄÜסÔÚ¶íÂÞ˹¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/06/ukraine-police-arrest-cyber-criminals.html


2.¼ÎÄ껪ÓÊÂÖ¹«Ë¾³ÆÆäÔâµ½ÍøÂç¹¥»÷µ¼ÖÂÓ×ÎÒÐÅϢй¶


2.jpg


È«Çò×î´óµÄÓÎÂÖ¼ÎÄ껪£¨Carnival Corporation£©³ÆÆäÔâµ½¹¥»÷µ¼ÖÂÊý¾Ýй¶¡£¸Ã¹«Ë¾°µÊ¾ÆäÔÚ2021Äê3ÔÂ19ÈÕ¼ì²âµ½Î´¾­ÊÚȨµÄµÚÈý·½½Ó¼ûÁ˲¿Ãŵç×ÓÓʼþÕÊ»§£¬Ð¹Â¶ÁËÔ±¹¤ºÍ¿ÍÈ˵ÄÓ×ÎÒÐÅÏ¢£¬Ô̺¬ÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢»¤ÕÕºÅÂë¡¢µ®ÉúÈÕÆÚ¡¢½¡È«ÐÅÏ¢¡¢Éç»á°²È«ºÅÂë»òÉí·ÝÖ¤ºÅÂëµÈ¡£¸Ã¹«Ë¾ÔÚÒ»·Ýµç×ÓÓʼþÉêÃ÷ÖаµÊ¾£¬Æä¹É¼Û×ÅÂäÁ˳¬¹ý2%¡£ÔçÔÚÈ¥ÄêµÄ8ÔºÍ12Ô£¬¸Ã¹«Ë¾»¹Ôâµ½ÁËÁ½´ÎÀÕË÷Èí¼þ¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.oann.com/cruise-operator-carnival-discloses-breach-of-crew-guests-personal-data-bloomberg-news/


3.²¨À¼µ±¾Ö³ÆÆä¹«ÃñºÍ×éÖ¯»ú¹¹Ô⵽ǰËùδÓеÄÍøÂç¹¥»÷


3.jpg


²¨À¼µ±¾ÖÔÚ±¾Öܶþ³Æ£¬Æä¹«ÃñºÍ×éÖ¯»ú¹¹Ôâµ½ÁËǰËùδÓеÄÍøÂç¹¥»÷¡£ÉÏÖÜ£¬ºÚ¿ÍÈëÇÖÁË×ÜÀí°ì¹«ÊÒÕÆ¹ÜÈËMichal DworczykµÄ¸öÈËÓʼþÕÊ»§£¬²¢½«ÓʼþÔÚTelegram¹«¿ª¡£µ±¾Ö½²»°ÈËPiotr Muller°µÊ¾Õâ´Î¹¥»÷µÄÁìÓòºÜ¿í·º£¬²»½öÉæ¼°Dworczyk£¬»¹Éæ¼°µ±¾Ö³ÉÔ±¡¢PiSµ³ºÍÆä¹«Ãñ¡£Ð¹Â¶ÎļþµÄÔªÊý¾ÝÏÔʾ£¬ÕâЩÎļþÊÇÓɽ²¶íÓïµÄÈ˱à×ëµÄ£¬µ«Õâ²»¼°ÒÔ½«Õâ´Î¹¥»÷¹é×ïÓÚ¶íÂÞ˹ºÚ¿Í¡£Ä¿Ç°£¬²¨À¼µÄ´¦Ëùµ±¾ÖºÍ°²È«¾ÖÈÔÔÚµ÷²éÕâ´Î¹¥»÷ÊÂÎñ¡£ 


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/119043/hacking/poland-hit-cyber-attacks.html


4.KasperskyÅû¶³¯ÏÊÍÅ»ïAndarielÕë¶Ôº«¹úµÄ¹¥»÷»î¶¯


4.jpg


KasperskyÅû¶Á˳¯ÏʺڿÍÍÅ»ïAndarielÕë¶Ôº«¹úµÄ¹¥»÷»î¶¯¡£×êÑÐÈËÔ±ÓÚ2021Äê4ÔÂÔÚVirusTotalÉÏ·¢ÏÖÁËÒ»¸ö¿ÉÒɵÄWordÎĵµ£¬·ÖÎö·¢ÏÖÕâ´Î¹¥»÷»î¶¯ÖÐʹÓõÄWindowsºÅÁîºÍÑ¡ÏîÓë֮ǰµÄAndariel»î¶¯ÏÕЩһÑù¡£Andariel×÷ΪLazarusµÄ×Ó¼¯ÍÅ£¬×Ô2016Äê5ÔÂÒÔÀ´Ò»Ïò»îÔ¾£¬Ö¼ÔÚÈëÇÖº«¹úºÍÊÀ½ç¸÷µØ½ðÈÚ»ú¹¹µÄÍÆËã»ú¡£ÖµÍ×ÌùÐĵÄÊÇ£¬Õâ´Î¹¥»÷³ýÁË×°ÖúóÃűí£¬»¹×°ÖÃÁ˼ÓÃÜÀÕË÷Èí¼þ£¬ÖØÒªÕë¶ÔÔì×÷Òµ¡¢Ã½ÌåºÍ¹¹ÖþÒµµÈÐÐÒµ¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/andariel-evolves-to-target-south-korea-with-ransomware/102811/    


5.×êÑÐÍŶÓÅû¶2G¼ÓÃܳ߶ÈËã·¨´æÔÚ¿ÉÇÔÌýÁ÷Á¿µÄ·ì϶


5.jpg


ÔÚÖÜÈý°ä·¢µÄһƪÂÛÎÄÖУ¬À´×Ե¹ú¡¢·¨¹úºÍŲÍþµÄ×êÑÐÈËÔ±Åû¶ÁË2G£¨GPRS£©Òƶ¯Êý¾Ý¼ÓÃܳ߶ÈÖеķì϶¡£¸Ã·ì϶´æÔÚÓÚ¼ÓÃÜËã·¨GEA-1ÖУ¬Õâ¿ÉÄÜʹ¹¥»÷Õß¿ÉÄÜÇÔÌýһЩÊý¾ÝÁ÷Á¿³¤´ï20¶àÄê¡£GEA-1Ëã·¨±¾Ó¦ÔÚ2013Äê²Ã¼õ£¬µ«Ôڴ˿̵ÄAndroidºÍiOSÖÇÄÜÊÖ»úÖÐÈÔÄÜ·¢ÏÖËü¡£¹ÌÈ»´óÎÞÊýÊÖ»ú¶¼Ê¹ÓÃ4GÉõÖÁ5G£¬µ«ÔÚijЩ¹ú¶È/µØÓò£¬GPRSÒÀÈ»ÊÇÊý¾ÝÏνӵĺó±¸Ñ¡Ôñ¡£Ä¿Ç°£¬×êÑÐÈËÔ±ÒÑ֪ͨÊÖ»úÔì×÷É̺ͳ߶È×éÖ¯½¨¸´¸Ã·ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/security-flaw-found-2g-mobile-data-encryption-standard


6.Enable SecurityÅû¶VoIP GUIÖеĿçÕ¾¾ç±¾·ì϶


6.jpg


Enable SecurityÅû¶ÁËVoIP GUIÖеĿçÕ¾¾ç±¾·ì϶¡£¸Ã·ì϶´æÔÚÓÚÖÎÀíVoIPºô½ÐµÄ»á»°ÌáÒéºÍ̸ (Session Initiation Protocol£¬SIP)ÖУ¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚδ¾­Éí·ÝÑéÖ¤µÄÇé¿öÏÂÔÚÖ¸±êϵͳÉÏÖ´ÐдúÂë¡£×êÑÐÈËÔ±ÔÚÉóºËVoIPmonitor GUIʱ·¢ÏÖÁ˸÷ì϶£¬³ÆÄܹ»Í¨¹ý·¢ËͶñÒâSIPÐÂÎÅÀ´ÆëÈ«½ÚÔìϵͳ¡£Enable SecurityÓÚ2021Äê2ÔÂÁªÏµÁËVoIPmonitorµÄ¿ª·¢ÈËÔ±£¬¸Ã·ì϶ÏÖÒѽ¨¸´¡£


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2021/06/16/xss-vulnerability-in-sip-protocol-risks-rce-attacks-on-voip-software/