Devolutions°ä²¼2021ÄêÖÐÓ×ÐÍÆóÒµ°²È«Ì¬ÊƵĻ㱨

°ä²¼¹¦·ò 2021-11-24

RedCurlÍÅ»ï»Ø¹é£¬ÐµĹ¥»÷Ö¸±êÉæ¼°¸÷Ðи÷Òµ


RedCurlÍÅ»ï»Ø¹é£¬ÐµĹ¥»÷Ö¸±êÉæ¼°¸÷Ðи÷Òµ.png


Group-IBÔÚ11ÔÂ18ÈÕÅû¶Á˺ڿÍÍÅ»ïRedCurlµÄл ¡£ÍøÂç¼äµýºÚ¿Í×éÖ¯RedCurlÔÚ2018ÄêÖÁ2020ÄêÆÚ¼ä£¬ÌáÒéÁËÖÁÉÙ26´Î¹¥»÷£¬Éæ¼°Ó¢¹ú¡¢µÂ¹ú¡¢¼ÓÄôó¡¢Å²Íþ¡¢¶íÂÞ˹ºÍÎÚ¿ËÀ¼µÈµØÓòµÄ¹¹Öþ¡¢½ðÈÚ¡¢Õ÷ѯ¡¢ÁãÊÛ¡¢±£ÏÕºÍ˾·¨ÐÐÒµµÄ¹«Ë¾ ¡£¸ÃÍÅ»ïÔÚÖжÏ7¸öÔºó¾íÍÁ³ÁÀ´£¬×Ô2021ËêÊ×ÒÔÀ´Õë¶Ô4¼Ò¹«Ë¾ÌáÒéÁËÐµĹ¥»÷£¬ÆäÖÐÔ̺¬¶íÂÞ˹×î´óµÄÅú·¢É̵ê ¡£Group-IB³Æ£¬RedCurlÔÚÿ´Î¹¥»÷ÖгÇÊÐʹÓÃÆä×Ô½ç˵¶ñÒâÈí¼þÈÆ¹ý¼ì²â ¡£


Ô­ÎÄÁ´½Ó£º

https://www.group-ib.com/media/red-curl-threat-report/


×êÑÐÈËÔ±ÑÝʾеÄSAD DNS»º´æÖж¾¹¥»÷ģʽ


×êÑÐÈËÔ±ÑÝʾеÄSAD DNS»º´æÖж¾¹¥»÷ģʽ.png


¼ÓÖÝ´óѧ×êÑÐÈËÔ±ÔÚ11ÔÂ18ÈÕÑÝʾÁËÒ»ÖÖеÄSAD DNS»º´æÖж¾¹¥»÷ģʽ ¡£SAD DNS£¨Side channel AttackeD DNS£©ÓÚ2020Äê11Ô³õ´ÎÅû¶£¬ËüÒÀÀµICMPµÄ¡°port unreachable¡±ÐÂÎÅÀ´´§¶ÈʹÓÃÄĸöһʱ¶Ë¿Ú ¡£ÀûÓô˹¥»÷ģʽ¿É½«¶ñÒâµÄDNS¼Í¼עÈëDNS»º´æ£¬¶øºó½«Ö¸±êÁ÷Á¿³Á¶¨Ïòµ½¹¥»÷ÕߵķþÎñÆ÷ÖУ¬½øÐÐÖÐÑëÈË(MITM)¹¥»÷ ¡£×êÑÐÈËÔ±³Æ£¬´ËÖÖ¹¥»÷´æÔÚÓÚLinuxÉÏÔËÐеÄBIND¡¢UnboundºÍdnsmasqµÈDNSÈí¼þÖУ¬Ó°ÏìÔ¼38%µÄÓòÃû½âÎöÆ÷ ¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/11/new-side-channel-attacks-re-enable.html


ÃÀ¹ú֤ȯÂòÂôίԱ»á·¢ÏÖ¼ÙÒâÆäÔ±¹¤µÄ´¹µö»î¶¯


ÃÀ¹ú֤ȯÂòÂôίԱ»á·¢ÏÖ¼ÙÒâÆäÔ±¹¤µÄ´¹µö»î¶¯.png


ÃÀ¹ú֤ȯÂòÂôίԱ»á(SEC)Ͷ×ÊÕß½ÌÓýºÍÐû´«°ì¹«ÊÒ(OIEA)ÓÚ11ÔÂ19ÈÕ°ä²¼¾¯±¨£¬³Æ·¢ÏÖ¼ÙÒâSECÔ±¹¤µÄ»î¶¯ ¡£¹¥»÷Õßͨ¹ýµç»°¡¢ÓïÒôÓʼþ¡¢µç×ÓÓʼþºÍº¯¼þ£¬ÖÒ¸æÊÕ¼þÈËÆä»îÆÚ´æ¿î»ò¼ÓÃÜÇ®±ÒµÄÕË»§ÖдæÔÚδ¾­ÊÚȨµÄÂòÂô»òÆäËû¿ÉÒɻ£¬²¢Ë÷ÒªÆä¹ÉȨ¡¢Õʺš¢PINÂë¡¢ÃÜÂëµÈÐÅÏ¢ ¡£OIEA½¨ÒéÓû§ÔÚ·¢ËÍÓ×ÎÒÐÅϢ֮ǰ£¬Ó¦ÏÈͨ¹ýÓʼþ»òÖµçSECÈ·¶¨·¢¼þÈ˵ÄÉí·Ý ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-sec-warns-investors-of-ongoing-govt-impersonation-attacks/


ÓÌËûÖÝÒ½ÁÆÖÐÐÄUIA½ü60Íò»¼ÕßµÄÓ×ÎÒÐÅϢй¶


ÓÌËûÖÝÒ½ÁÆÖÐÐÄUIA½ü60Íò»¼ÕßµÄÓ×ÎÒÐÅϢй¶.png


11ÔÂ18ÈÕ£¬ÃÀ¹úÓÌËûÖÝ·ÅÉäÖÐÐÄUtah Imaging Associates(UIA)È·ÈÏ582170»¼ÕßµÄÓ×ÎÒÐÅϢй¶ ¡£Ð¹Â¶ÊÂÎñ²úÉúÔÚ8ÔÂ29ÈÕ£¬Êý¾ÝÔÚ¶³öÔ¼Ò»Öܺó£¬ÓÚ9ÔÂ4ÈÕ±»·¢ÏÖ²¢ÓÚͬÈÕ½¨¸´ ¡£Õâ´Îй¶ÁË»¼ÕßµÄÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢Éç»á°²È«ºÅÂë¡¢½¡È«±£ÏÕµ¥ºÅºÍÒ½ÁÆÐÅÏ¢µÈ ¡£×êÑÐÈËÔ±°µÊ¾£¬¹¥»÷Õ߯«²îÓÚ¹¥»÷ÏñUIAÕâÑùµÄÒ½ÁÆÖÐÐÄ£¬ÊÇÓÉÓÚËûÃÇÒÔΪ´ËÀàÊý¾ÝÔÚ°µÍøÖеļÛÖµ¸ü¸ß ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/utah-medical-center-hit-by-data-breach-affecting-582k-patients/


Prodaft°ä²¼¹ØÓÚÀÕË÷ÔËÓªÍÅ»ïContiµÄ·ÖÎö»ã±¨


Prodaft°ä²¼¹ØÓÚÀÕË÷ÔËÓªÍÅ»ïContiµÄ·ÖÎö»ã±¨.png


ProdaftÓÚ11ÔÂ18ÈÕ°ä²¼Á˹ØÓÚÀÕË÷ÔËÓªÍÅ»ïContiµÄÉî¶È·ÖÎö»ã±¨ ¡£ContiÊÇ˽ÓÐRaaS£¬ÓÚ2019Äê12Ôµ׳õ´Î³öÏÖ£¬²¢Í¨¹ýTrickBot½øÐд«²¼ ¡£»ã±¨Ö¸³ö£¬×Ô2021Äê7ÔÂÒÔÀ´£¬Conti´ÓÊê½ðÖлñÀûÖÁÉÙ2550ÍòÃÀÔª£¬¶øContiÍÅ»ïÔòÐû³ÆÒÑ»ñÀû3ÒÚÃÀÔª ¡£´Ë±í£¬Prodaft»¹¹«¿ªÁËContiµÄÖ§¸¶ÍøÕ¾£¬Æä·þÎñÆ÷ÍйÜÔÚ217.12.204.135ÉÏ£¬¸ÃIPµØÖ·ÊôÓÚÎÚ¿ËÀ¼ÍøITL LLC ¡£Ôڸû㱨°ä²¼¼¸Ó×ʱºó£¬ContiÍÅ»ï¾Í½«ÆäÖ§¸¶ÍøÕ¾¹Ø¹Ø ¡£


Ô­ÎÄÁ´½Ó£º

https://www.prodaft.com/resource/detail/conti-ransomware-group-depth-analysis


Devolutions°ä²¼2021ÄêÖÐÓ×ÐÍÆóÒµ°²È«Ì¬ÊƵĻ㱨


Devolutions°ä²¼2021ÄêÖÐÓ×ÐÍÆóÒµ°²È«Ì¬ÊƵĻ㱨.png


DevolutionsÔÚ11ÔÂ17ÈÕ°ä²¼ÁË2021ÄêÖÐÓ×ÐÍÆóÒµ°²È«Ì¬ÊƵÄ×êÑл㱨 ¡£¸Ã×êÑоÍÎå¸öÖ÷ÌâÖ÷Ì⣺ÖÐÓׯóÒµµÄÍøÂç¹¥»÷ºÍÍþв¡¢ÃÜÂëÖÎÀí¡¢Ê¹ÓõÄÌØÈ¨½Ó¼ûÖÎÀí¡¢°²È«ÅàѵºÍÖÎÀíÒÔ¼°°²È«Í¶×ʽøÐÐÁË·ÖÎö ¡£»ã±¨Ö¸³ö£¬ÓëÈ¥ÄêÏà±È£¬72%µÄÖÐÓׯóҵĿǰԽ·¢¹ØÇÐÍøÂ簲ȫ £»ÖÎÀíÕß×î²»°²µÄÍøÂçÍþвÊÇÀÕË÷Èí¼þ¡¢ÍøÂç´¹µöºÍ¶ñÒâÈí¼þ £»52%µÄÆóÒµÔÚÈ¥ÄêÔâµ½¹ýÍøÂç¹¥»÷ £»Ö»ÓÐ13%µÄÆóÒµÕ¼ÓÐÆëÈ«µÄPAM½â¾ö¹æ»® ¡£


Ô­ÎÄÁ´½Ó£º

https://blog.devolutions.net/2021/11/new-now-available-devolutions-state-of-cybersecurity-in-smbs-in-2021-2022-report