Ó¢¹ú´¦Öóͷ£Å·ÃËÓÀ¾Ó¼Æ»®Ê±ÖÁÉÙÎ¥·´ÁË100´ÎGDPR £»£»£»£»APT34й¥»÷»î¶¯Karkoff 2020

Ðû²¼Ê±¼ä 2020-03-04

1.Ó¢¹ú´¦Öóͷ£Å·ÃËÓÀ¾Ó¼Æ»®Ê±ÖÁÉÙÎ¥·´ÁË100´ÎGDPR


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ó¢º£ÄÚÕþ²¿ÔÚ´¦Öóͷ£Å·ÃËÓÀ¾Ó¼Æ»®£¨EUSS£©Ê±ÖÁÉÙÎ¥·´ÁË100´ÎGDPR¡£¡£ ¡£¡£¡£¡£Ê×ϯ½çÏߺÍÒÆÃñ¼ì²é¹Ù£¨David Ilt£©ÔÚÒÆÃñî¿Ïµ»ú¹¹¾ÙÐеÄÒ»·Ý±¨¸æÖÐÌåÏÖ£¬ £¬£¬£¬£¬£¬ £¬Ö»¹ÜGDPRÒªÇó¶ÔÔ±¹¤¾ÙÐÐÒâʶÅàѵ£¬ £¬£¬£¬£¬£¬ £¬µ«ÈԼͼµ½¶ÔGDPRµÄÑÏÖØÎ¥·´¡£¡£ ¡£¡£¡£¡£Æ¾Ö¤¸Ã±¨¸æ£¬ £¬£¬£¬£¬£¬ £¬×èÖ¹2019Äê8ÔÂ⣬ £¬£¬£¬£¬£¬ £¬ÄÚÕþ²¿£¨EUSSµÄ¼àÊÓÕߣ©ÊÕµ½ÁË130Íò·ÝÉêÇ룬 £¬£¬£¬£¬£¬ £¬²¢ÇÒÒѾ­ÓÐÉϰÙÍòÈË»ñµÃÅú×¼¡£¡£ ¡£¡£¡£¡£µ«ÔÚ2019Äê3ÔÂ30ÈÕÖÁ8ÔÂ31ÈÕʱ´ú£¬ £¬£¬£¬£¬£¬ £¬Õþ¸®Î¥·´ÁËGDPRµÄÊÂÎñÓÐ100Æð¡£¡£ ¡£¡£¡£¡£ÕâЩÊÂÎñ°üÀ¨½«Éí·ÝÖ¤¿¨Æ¬·¢ËÍÖÁ¹ýʧµÄÉêÇëÈ˺͵ص㠣»£»£»£»Ðí¶à»¤ÕÕɥʧÁË£¬ £¬£¬£¬£¬£¬ £¬Éí·Ý֤ʵÎļþ±»ÓÊÕþ²¿·ÖºÍEUSS·Å´íÁ˵ط½ £»£»£»£»Î´¾­Ô޳ɱãÓëµÚÈý·½¹²ÏíÉêÇëÈ˵ÄÐÅÏ¢µÈ¡£¡£ ¡£¡£¡£¡£ÄÚÕþ²¿ÌåÏֻᰴÆÚÉó²éËùÓÐÁ÷³ÌºÍ³ÌÐò£¬ £¬£¬£¬£¬£¬ £¬ÒÔ¼õÇáÊý¾Ýй¶µÄΣº¦¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/uk-home-office-breached-gdpr-100-times-through-botched-handling-of-eu-settlement-scheme/


2.Checkpoint½¨Éè¶ñÒâÈí¼þÈÆÌ«¹ýÎöµÄÊÖÒյİٿÆÈ«Êé


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Checkpoint½¨ÉèÁ˹ØÓÚ¶ñÒâÈí¼þÓÃÀ´ÌӱܯÊÎöµÄÖÖÖÖÊÖÒյİٿÆÈ«Êé¡£¡£ ¡£¡£¡£¡£¸Ã°Ù¿ÆÈ«Ê麭¸ÇÁËÓëÎļþϵͳ¡¢×¢²á±í¡¢Í¨ÓÃOSÅÌÎÊ¡¢È«¾ÖOS¹¤¾ß¡¢Óû§½çÃæ¡¢OS¹¦Ð§¡¢Àú³Ì¡¢ÍøÂç¡¢CPU¡¢¹Ì¼þ±í¡¢¹³×Ó¡¢Ó²¼þÒÔ¼°MacOSÌØ¶¨µÄɳÏäÓйصÄÌÓ±ÜÊÖÒÕ¡£¡£ ¡£¡£¡£¡£Ã¿Ò»¸öÖֱ𶼰üÀ¨ÊÖÒÕÐÎò¡¢´úÂëʾÀý¡¢ÓÃÓÚ¸ú×Ù¸ÃÊÖÒÕµÄÊðÃû½¨Òé¡¢¿É¼ì²âÇéÐÎÀàÐ͵ıí¸ñÒÔ¼°¶Ô²ß¡£¡£ ¡£¡£¡£¡£Checkpoint»¹ÍýÏëÔöÌíÓë¼ÆÊ±¡¢Windows Management Instrumentation£¨WMI£©ºÍÈËÀàÐÐΪÒòËØÓйصÄÌÓ±ÜÊÖÒÕ¡£¡£ ¡£¡£¡£¡£Ïà¹ØÁìÓòµÄר¼Ò¿ÉÒÔÔÚGithubÒ³ÃæÉÏΪ¸Ã°Ù¿ÆÈ«Êé×ö³öТ˳¡£¡£ ¡£¡£¡£¡£Ò»Ð©ÑÝʾ¹æ±ÜÊÖÒյŤ¾ßÊÇ¿ªÔ´µÄ£¬ £¬£¬£¬£¬£¬ £¬Í¬Ê±Checkpoint»¹Ðû²¼ÁË×Ô¼ºµÄÃûΪInviZzzibleµÄ¿ªÔ´¹¤¾ß¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/checkpoint-creates-encyclopedia-malware-evasion-techniques


3.Ó¢¹úTravelex¹«Ë¾Ô¤¼ÆÒòÍøÂç¹¥»÷Ëðʧ2500ÍòÓ¢°÷


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¾Ý·͸É籨µÀ£¬ £¬£¬£¬£¬£¬ £¬ÓÉÓÚ12ÔÂÏÂÑ®µÄÀÕË÷Èí¼þ¹¥»÷ÊÂÎñ£¬ £¬£¬£¬£¬£¬ £¬Íâ±Ò¶Ò»»¹«Ë¾TravelexÔ¤¼ÆÆäµÚÒ»¼¾¶ÈµÄ½¹µãÊÕÈëËðʧΪ2500ÍòÓ¢°÷£¨ºÏ3200ÍòÃÀÔª£©¡£¡£ ¡£¡£¡£¡£¸Ã¹«Ë¾»¹ÌåÏÖÒѻָ´ÁËËùÓÐÃæÏò¿Í»§µÄϵͳ¡£¡£ ¡£¡£¡£¡£Travelexͨ¹ýÆä×Ô¶¯¶©µ¥Ð§ÀÍΪ»ã·áÒøÐС¢°Í¿ËÀ³ÒøÐС¢Î¬ÕäÇ®±ÒÒÔ¼°Ó¢¹úÁãÊÛÉÌTescoºÍSainsburyµÄÒøÐв¿·Ö¿Í»§ÌṩÍâ»ãЧÀÍ¡£¡£ ¡£¡£¡£¡£TravelexÌåÏִ˴ι¥»÷²»»á¶ÔËæºó¼¸¸ö¼¾¶ÈµÄÉúÒâÔì³ÉÈκÎʵÖÊÐÔÓ°Ïì¡£¡£ ¡£¡£¡£¡£¸Ã¹«Ë¾»¹³Æ¹Ú×´²¡¶¾µÄ±¬·¢¶ÔÆäÓªÒµÔì³ÉÁËÁíÍâÒ»¸ö¸ºÃæÓ°Ï죬 £¬£¬£¬£¬£¬ £¬µ«Î´Ô¤¼Æ¸Ã²¡¶¾»á´øÀ´Èκξ­¼ÃËðʧ¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://uk.finance.yahoo.com/news/travelex-expects-25-million-hit-093953943.html


4.Let's Encrypt³·»ØÁè¼Ý300Íò¸öTLSÖ¤Êé


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÓÉÓÚÔÚºó¶Ë´úÂëÖз¢Ã÷ÁËÒ»¸öbug£¬ £¬£¬£¬£¬£¬ £¬Let's EncryptÏîÄ¿ÍýÏë´ÓÌìϱê׼ʱ¼ä2020Äê3ÔÂ4ÈÕ00:00×îÏÈ×÷·ÏÁè¼Ý300Íò¸öTLSÖ¤Êé¡£¡£ ¡£¡£¡£¡£ÏêϸÀ´Ëµ£¬ £¬£¬£¬£¬£¬ £¬¸ÃbugÓ°ÏìÁËBoulder£¬ £¬£¬£¬£¬£¬ £¬Let's EncryptÏîĿʹÓøÃЧÀÍÆ÷Èí¼þÔÚ¿¯ÐÐTLSÖ¤Êé֮ǰÑéÖ¤Óû§¼°ÆäÓò¡£¡£ ¡£¡£¡£¡£¸ÃbugÓ°ÏìÁËBoulderÄÚ²¿CAA£¨Ö¤Êé½ÒÏþ»ú¹¹ÊÚȨ£©¹æ·¶µÄʵÑ飬 £¬£¬£¬£¬£¬ £¬¡°µ±Ò»¸öÖ¤ÊéÇëÇó°üÀ¨N¸öÐèÒª¾ÙÐÐCAAÖØÐ¼ì²éµÄÓòÃûʱ£¬ £¬£¬£¬£¬£¬ £¬Boulder½«Ñ¡ÔñÒ»¸öÓòÃû²¢¼ì²éN´Î¡£¡£ ¡£¡£¡£¡£ÕâÏÖʵÉÏÒâζ×ÅÈôÊÇÒ»¸öÓû§ÔÚʱ¼äXÑéÖ¤ÁËÒ»¸öÓòÃû£¬ £¬£¬£¬£¬£¬ £¬²¢ÇÒ¸ÃÓòÃûÔÚʱ¼äXµÄCAA¼Í¼ÔÊÐíLet's Encrypt¿¯ÐУ¬ £¬£¬£¬£¬£¬ £¬Ôò¸ÃÓû§¿ÉÒÔÔÚX+30ÌìµÄʱ¼äÀ￯ÐаüÀ¨¸ÃÓòÃûµÄÖ¤Ê飬 £¬£¬£¬£¬£¬ £¬×ÝȻ֮ºóÓÐÈËÔÚ¸ÃÓòÃûÉÏ×°ÖÃÁËեȡLet's Encrypt¿¯ÐеÄCAA¼Í¼¡±¡£¡£ ¡£¡£¡£¡£ÔÚÕâ300Íò¸ö×÷·ÏµÄÖ¤ÊéÖУ¬ £¬£¬£¬£¬£¬ £¬ÓÐ100Íò¸öÊÇͳһÓò/×ÓÓòµÄÖØ¸´Ï £¬£¬£¬£¬£¬ £¬Òò´ËÊÜÓ°ÏìÖ¤ÊéµÄÏÖʵÊýĿԼΪ200Íò¸ö¡£¡£ ¡£¡£¡£¡£ÔÚ3ÔÂ4ÈÕ00:00Ö®ºóËùÓÐÊÜÓ°ÏìµÄÖ¤Êé¶¼½«´¥·¢ä¯ÀÀÆ÷ºÍÆäËûÓ¦ÓóÌÐòÖеĹýʧ£¬ £¬£¬£¬£¬£¬ £¬ÓòÃûËùÓÐÕß½«±ØÐèÇëÇóеÄTLSÖ¤Êé²¢Ìæ»»¾ÉµÄTLSÖ¤Êé¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/lets-encrypt-to-revoke-3-million-certificates-on-march-4-due-to-bug/


5.APT34й¥»÷»î¶¯Karkoff 2020£¬ £¬£¬£¬£¬£¬ £¬Õë¶ÔÀè°ÍÄÛÕþ¸®»ú¹¹


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Cybaze/Yoroi ZlabµÄר¼Ò·¢Ã÷APT34×éÖ¯µÄÒ»¸öÐÂÑù±¾£¬ £¬£¬£¬£¬£¬ £¬ËûÃÇÒÔΪ¸ÃÑù±¾ÊÇKarkoffÖ²ÈëÎïµÄ¸üа汾£¬ £¬£¬£¬£¬£¬ £¬¿ÉÒÔ֤ʵAPT34ÈÔÈ»´¦Óڻ״̬¡£¡£ ¡£¡£¡£¡£ÔÚÕâ¸öÐµĹ¥»÷»î¶¯ÖÐAPT34¿ÉÄÜÈëÇÖÁËÊôÓÚÀè°ÍÄÛÕþ¸®»ú¹¹µÄMicrosoft Exchange Server¡£¡£ ¡£¡£¡£¡£ÐÂÑù±¾ÓëÒÑÍùKarkoffÑù±¾µÄÏàËÆÖ®´¦°üÀ¨¾ßÓÐÏàËÆµÄºê½á¹¹¡¢¾ßÓÐÀàËÆÂß¼­µÄ.NETÄ£¿£¿ £¿£¿£¿é»¯Ö²ÈëÎïÒÔ¼°Ê¹ÓÃMicrosoft Exchange Server×÷ΪͨѶÇþµÀ¡£¡£ ¡£¡£¡£¡£±ðµÄ£¬ £¬£¬£¬£¬£¬ £¬ÐÂKarkoffÖ²ÈëÎïʵÏÖÁËеÄÕì̽Âß¼­£¬ £¬£¬£¬£¬£¬ £¬ÒÔ±ã½ö½«×îÖÕµÄÓÐÓúÉÔØÊͷŵ½Ìض¨Ä¿µÄ£¬ £¬£¬£¬£¬£¬ £¬²¢ÇÒÍøÂçϵͳÐÅÏ¢¡¢ÓòÃû¡¢Ö÷»úÃûºÍÕýÔÚÔËÐеIJÙ×÷ϵͳµÈÐÅÏ¢¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/98802/uncategorized/karkoff-malware-lebanon.html


6.ÐÂPwndLockerÀÕË÷Èí¼þÖ÷ÒªÕë¶ÔÃÀ¹úÊÐÕþÕþ¸®ºÍÆóÒµÍøÂç


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Çå¾²Ñо¿Ö°Ô±·¢Ã÷Õë¶ÔÊÐÕþÕþ¸®ºÍÆóÒµÍøÂçµÄÐÂÀÕË÷Èí¼þ¼Ò×å¡°PwndLocker¡±£¬ £¬£¬£¬£¬£¬ £¬¸Ã¼Ò×å×Ô2019Äêµ×ÒÔÀ´Ò»Ö±»îÔ¾£¬ £¬£¬£¬£¬£¬ £¬²¢ÔÚÕâ¶Îʱ¼äÄÚ¹¥»÷ÁËÃÀ¹ú¶à¸ö¶¼»áºÍ×éÖ¯¡£¡£ ¡£¡£¡£¡£PwndLockerÓë½üÆÚÕë¶ÔÒÁÀûŵÒÁÖÝÀ­Èø¶ûÏØµÄ¹¥»÷ÓйØ£¬ £¬£¬£¬£¬£¬ £¬¹¥»÷ÕßÒªÇó50¸ö±ÈÌØ±Ò£¨Ô¼ºÏ44.2ÍòÃÀÔª£©µÄÊê½ð£¬ £¬£¬£¬£¬£¬ £¬²¢ÇÒ³ÆÔÚ¼ÓÃÜ֮ǰÒѾ­ÇÔÈ¡Á˸ÃÏØµÄÊý¾Ý¡£¡£ ¡£¡£¡£¡£ÍâµØÃ½ÌåÖ¸³ö£¬ £¬£¬£¬£¬£¬ £¬À­Èø¶ûÏØÎÞÒâÖ§¸¶Êê½ð¡£¡£ ¡£¡£¡£¡£Æ¾Ö¤Ñо¿Ö°Ô±µÄÆÊÎö£¬ £¬£¬£¬£¬£¬ £¬PwndLockerʹÓá°net stop¡±ÏÂÁî½ûÓÃÁ˶à¸öWindowsЧÀÍ£¬ £¬£¬£¬£¬£¬ £¬ÀýÈçMicrosoft SQL Server¡¢MySQLºÍExchange£¬ £¬£¬£¬£¬£¬ £¬²¢ÇÒ¼ì²âºÍɱËÀÓëFirefox¡¢Word¡¢Excel¡¢AccessÒÔ¼°ÓëÇå¾²Èí¼þ¡¢±¸·ÝÓ¦ÓóÌÐòºÍÊý¾Ý¿âЧÀÍÆ÷ÓйصÄÀú³Ì¡£¡£ ¡£¡£¡£¡£Æä¼ÓÃÜÎļþµÄÀ©Õ¹ÃûΪ¡°.key¡±»ò¡° .pwnd¡±¡£¡£ ¡£¡£¡£¡£PwndLocker²¢²»ÊǵÚÒ»¸öÕë¶ÔÆóÒµÍøÂçµÄÀÕË÷Èí¼þ£¬ £¬£¬£¬£¬£¬ £¬Ö®Ç°Ñо¿Ö°Ô±»¹·¢Ã÷ÁËÕë¶ÔÆóÒµÍøÂçµÄSNAKEºÍAko¼Ò×å¡£¡£ ¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.tripwire.com/state-of-security/security-data-protection/pwndlocker-ransomware-targeting-municipalities-enterprise-networks/