ºÚ¿ÍÉù³ÆÒÑÇÔÈ¡ÐÂ¼ÓÆÂFullerton 40¶àÍò¿Í»§µÄÐÅÏ¢

Ðû²¼Ê±¼ä 2021-10-27

Ñо¿ÍŶÓÅû¶APT×éÖ¯LazarusÌᳫµÄ¹©Ó¦Á´¹¥»÷µÄϸ½Ú


Ñо¿ÍŶÓÅû¶APT×éÖ¯LazarusÌᳫµÄ¹©Ó¦Á´¹¥»÷µÄϸ½Ú.png


KasperskyÑо¿ÍŶÓÓÚ±¾ÖܶþÅû¶ÁËLazarusÔÚ½üÆÚÌᳫµÄ¹©Ó¦Á´¹¥»÷¡£¡£¡£¡£¡£¡£¡£APT×éÖ¯Lazarus×Ô2009ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬£¬ £¬£¬Ê¹ÓÃMATA¹¥»÷¸÷¸öÐÐÒµµÄ×éÖ¯¡£¡£¡£¡£¡£¡£¡£Ôڴ˴λÖУ¬£¬ £¬£¬¸ÃÍÅ»ïÓÚ5Ô¹¥»÷ÁËÀ­ÍÑάÑǵÄIT¹©Ó¦ÉÌ£¬£¬ £¬£¬ÓÖÔÚ6Ô·ÝʹÓúóÃÅBLINDINGCANµÄбäÌå¹¥»÷Á˺«¹úÖǿ⡣¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬ £¬£¬×î½üµÄ»î¶¯Õ¹ÏÖÁËÁ½¸öÇ÷ÊÆ£ºLazarusÈÔÈ»¶Ô¹ú·ÀÐÐÒµ¸ÐÐËȤ£¬£¬ £¬£¬²¢ÇÒ»¹Ï£Íûͨ¹ý¹©Ó¦Á´¹¥»÷À´À©Õ¹Æä¹¥»÷¹æÄ£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://usa.kaspersky.com/about/press-releases/2021_apt-actor-lazarus-attacks-defense-industry-develops-supply-chain-attack-capabilities


Avast·¢Ã÷Õë¶ÔÊý°ÙÍòAndroidÓû§µÄڲƭ»î¶¯UltimaSMS


Avast·¢Ã÷Õë¶ÔÊý°ÙÍòAndroidÓû§µÄڲƭ»î¶¯UltimaSMS.png


10ÔÂ25ÈÕ£¬£¬ £¬£¬AvastµÄÑо¿Ö°Ô±·¢Ã÷ÁË´ó¹æÄ£µÄڲƭ»î¶¯UltimaSMS¡£¡£¡£¡£¡£¡£¡£Õⳡ»î¶¯Ê¹ÓÃ151¸öAndroidÓ¦ÓóÌÐò£¬£¬ £¬£¬×ÜÏÂÔØÁ¿¸ß´ï1050Íò´Î¡£¡£¡£¡£¡£¡£¡£ËüÃÇαװ³ÉÕÛ¿ÛÓ¦Óá¢ÓÎÏ·¡¢×Ô½ç˵¼üÅÌ¡¢¶þάÂëɨÃèÆ÷¡¢ºÍÀ¬»øÓʼþ×èµ²Æ÷µÈAndroidÓ¦Ó㬣¬ £¬£¬ÏÂÔØºó»áÒªÇóÓû§ÊäÈëÊÖ»úºÅºÍÓʼþµØµãÀ´»á¼û³ÌÐò¡£¡£¡£¡£¡£¡£¡£»£»£»£»ñµ½ÊÖ»úºÅºÍȨÏ޺󣬣¬ £¬£¬½«ÎªÄ¿µÄ¶©ÔÄÿÔÂ40ÃÀÔªµÄSMSЧÀÍ¡£¡£¡£¡£¡£¡£¡£Sensor TowerÊý¾ÝÏÔʾ£¬£¬ £¬£¬ÊÜÓ°Ïì×îÑÏÖØµÄµØÇøÊǰ£¼°¡¢É³Ìذ¢À­²®¡¢°Í»ù˹̹ºÍ°¢ÁªÇõ£¬£¬ £¬£¬Êܺ¦Óû§ÊýÄ¿¾ùÁè¼Ý100Íò¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/millions-of-android-users-targeted-in-subscription-fraud-campaign/


ºÚ¿ÍÉù³ÆÒÑÇÔÈ¡ÐÂ¼ÓÆÂFullerton 40¶àÍò¿Í»§µÄÐÅÏ¢


ºÚ¿ÍÉù³ÆÒÑÇÔÈ¡ÐÂ¼ÓÆÂFullerton 40¶àÍò¿Í»§µÄÐÅÏ¢.png


¹¥»÷ÕßÓÚ10ÔÂ11ÈÕ×îÏÈ£¬£¬ £¬£¬ÔÚ°µÍøÉÏÒÔ600ÃÀÔªµÄ¼ÛÇ®³öÊÛÐÂ¼ÓÆÂÒ½Áƹ«Ë¾FullertonµÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÉù³ÆÒÑ»ñÈ¡ÁË40¶àÍò¿Í»§£¬£¬ £¬£¬²¢¹ûÕæÁËÐÕÃû¡¢Éí·ÝÖ¤ºÅÂë¡¢ÒøÐÐÕË»§ºÍ²¡Ê·µÈÐÅÏ¢×÷ΪÑù±¾¡£¡£¡£¡£¡£¡£¡£¿ÉÊÇÔÚÉÏÖÜÎ壨10ÔÂ22ÈÕ£©£¬£¬ £¬£¬¹¥»÷Õßɾ³ýÁËÓйØÊý¾Ý³öÊÛµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚ10ÔÂ19Èճƣ¬£¬ £¬£¬´Ë´Îй¶ÊÇÓÉÓÚÆä¹©Ó¦ÉÌAgapeǰ²»¾ÃµÄÎ¥¹æÐÐΪµ¼ÖµÄ£¬£¬ £¬£¬ÏÖÔÚÈÔδȷ¶¨ÊÜÓ°ÏìÖ°Ô±µÄÊýÄ¿ºÍÉí·Ý¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.straitstimes.com/singapore/courts-crime/fullerton-health-vendor-hacked-personal-details-of-customers-sold-online


¶à¸öÀÕË÷ÍÅ»ïʹÓÃEntroLink VPNÖÐ0 day¾ÙÐй¥»÷»î¶¯


¶à¸öÀÕË÷ÍÅ»ïʹÓÃEntroLink VPNÖÐ0 day¾ÙÐй¥»÷»î¶¯.png


9ÔÂ13ÈÕ£¬£¬ £¬£¬¹¥»÷ÕßÔÚ°µÍøÐû²¼ÁËEntroLink VPNÖÐ0 dayÎó²îʹÓóÌÐò£¬£¬ £¬£¬Ö®ºó±»¶à¸öÀÕË÷ÔËÓªÍÅ»ïÎäÆ÷»¯¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÊÇÒ»¸öÊäÈëÑéÖ¤Îó²î£¬£¬ £¬£¬Ó°ÏìÁ˺«¹úÊ¢ÐÐEntroLink PPX-AnyLink×°±¸£¬£¬ £¬£¬Ö»Ð輸ÃëÖÓ¼´¿ÉÆÆËð×°±¸¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬ £¬£¬½üÆÚ·¢Ã÷BlackMatterºÍLockBitµÄ·ÖÖ§»ú¹¹¿ÉÄÜÒѾ­Ê¹ÓøÃÎó²îÌᳫ¹¥»÷£¬£¬ £¬£¬Õâ³ÉΪÁËÏÖÔÚÒÑÖªµÄµÚ54¸ö±»ÀÕË÷ÔËÓªÍÅ»ïÀÄÓõÄÁãÈÕÎó²î¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/ransomware-gangs-are-abusing-a-zero-day-in-entrolink-vpn-appliances/


Mozilla·¢Ã÷2¸ö¶ñÒâÀ©Õ¹×èÖ¹Óû§×°ÖÃFirefox¸üÐÂ


Mozilla·¢Ã÷2¸ö¶ñÒâÀ©Õ¹×èÖ¹Óû§×°ÖÃFirefox¸üÐÂ.png


MozillaÔÚ±¾ÖÜÒ»Åû¶£¬£¬ £¬£¬ÓÐ455000¸öÓû§×°ÖÃÁ˶ñÒâFirefoxÀ©Õ¹¡£¡£¡£¡£¡£¡£¡£Õâ2¸öÀ©Õ¹»®·ÖΪBypassºÍBypass XM£¬£¬ £¬£¬¿Éͨ¹ýÊðÀíAPIÀ´×èÖ¹Óû§ÏÂÔØ¸üС¢»á¼û¸üÐÂÆÁÕÏÁбíºÍ¸ü¸ÄÔ¶³ÌÉèÖᣡ£¡£¡£¡£¡£¡£³ýÁËɾ³ýÕâÁ½¸öÀ©Õ¹Ö®Í⣬£¬ £¬£¬¸Ã¹«Ë¾»¹ÍƳöÁËϵͳ¸½¼Ó×é¼þProxy FailoverÒÔ½øÒ»²½»º½âÎÊÌâ¡£¡£¡£¡£¡£¡£¡£Mozilla»¹½¨ÒéÓû§½«ä¯ÀÀÆ÷¸üе½Firefox 93°æ±¾£¬£¬ £¬£¬²¢È·±£Microsoft DefenderʼÖÕ´¦ÓÚÔËÐÐ״̬¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/10/malicious-firefox-add-ons-block-browser.html


SEONÐû²¼¹ØÓÚÈ«ÇòÍøÂç·¸·¨ÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ


SEONÐû²¼¹ØÓÚÈ«ÇòÍøÂç·¸·¨ÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ.png


SEONÔÚ10ÔÂ25ÈÕÐû²¼Á˹ØÓÚÈ«ÇòÍøÂç·¸·¨ÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£±¨¸æ¶ÔÈ«Çò½ü100¸ö¹ú¼ÒºÍµØÇø¾ÙÐÐÆÊÎö£¬£¬ £¬£¬·¢Ã÷ÍøÂçÇå¾²ÐÔ×îÇ¿µÄ¹ú¼ÒÊǵ¤Â󣬣¬ £¬£¬Æä´ÎÊǵ¹ú¡¢ÃÀ¹ú¡¢Å²Íþ¡¢Ó¢¹ú¡¢¼ÓÄôó¡¢ÈðµäºÍ°Ä´óÀûÑǵȹú¡£¡£¡£¡£¡£¡£¡£Ïà·´£¬£¬ £¬£¬×î²»Çå¾²µÄ¹ú¼ÒÊÇÃåµé£¬£¬ £¬£¬Æä´ÎÊǼíÆÒÕ¯¡¢ºé¶¼À­Ë¹¡¢²£ÀûάÑǺÍÃɹŵȹú¡£¡£¡£¡£¡£¡£¡£±¨¸æ»¹Ö¸³öÁË2020ÄêÃÀ¹ú×î³£¼ûµÄÍøÂç·¸·¨ÀàÐÍ»®·ÖÊÇÍøÂç´¹ÂÚºÍڲƭ(32.96%)¡¢Î´¸¶¿î»òδ½»¸¶(14.87%)ºÍڲƭÀÕË÷ (10.48%)¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://seon.io/resources/global-cybercrime-report/