Ó¢¹ú´¦Öóͷ£Å·ÃËÓÀ¾Ó¼Æ»®Ê±ÖÁÉÙÎ¥·´ÁË100´ÎGDPR£»£»£»£»APT34й¥»÷»î¶¯Karkoff 2020
Ðû²¼Ê±¼ä 2020-03-041.Ó¢¹ú´¦Öóͷ£Å·ÃËÓÀ¾Ó¼Æ»®Ê±ÖÁÉÙÎ¥·´ÁË100´ÎGDPR
Ó¢º£ÄÚÕþ²¿ÔÚ´¦Öóͷ£Å·ÃËÓÀ¾Ó¼Æ»®£¨EUSS£©Ê±ÖÁÉÙÎ¥·´ÁË100´ÎGDPR¡£¡£¡£¡£¡£¡£Ê×ϯ½çÏߺÍÒÆÃñ¼ì²é¹Ù£¨David Ilt£©ÔÚÒÆÃñî¿Ïµ»ú¹¹¾ÙÐеÄÒ»·Ý±¨¸æÖÐÌåÏÖ£¬£¬£¬£¬£¬£¬£¬Ö»¹ÜGDPRÒªÇó¶ÔÔ±¹¤¾ÙÐÐÒâʶÅàѵ£¬£¬£¬£¬£¬£¬£¬µ«ÈԼͼµ½¶ÔGDPRµÄÑÏÖØÎ¥·´¡£¡£¡£¡£¡£¡£Æ¾Ö¤¸Ã±¨¸æ£¬£¬£¬£¬£¬£¬£¬×èÖ¹2019Äê8ÔÂ⣬£¬£¬£¬£¬£¬£¬ÄÚÕþ²¿£¨EUSSµÄ¼àÊÓÕߣ©ÊÕµ½ÁË130Íò·ÝÉêÇ룬£¬£¬£¬£¬£¬£¬²¢ÇÒÒѾÓÐÉϰÙÍòÈË»ñµÃÅú×¼¡£¡£¡£¡£¡£¡£µ«ÔÚ2019Äê3ÔÂ30ÈÕÖÁ8ÔÂ31ÈÕʱ´ú£¬£¬£¬£¬£¬£¬£¬Õþ¸®Î¥·´ÁËGDPRµÄÊÂÎñÓÐ100Æð¡£¡£¡£¡£¡£¡£ÕâЩÊÂÎñ°üÀ¨½«Éí·ÝÖ¤¿¨Æ¬·¢ËÍÖÁ¹ýʧµÄÉêÇëÈ˺͵ص㣻£»£»£»Ðí¶à»¤ÕÕɥʧÁË£¬£¬£¬£¬£¬£¬£¬Éí·Ý֤ʵÎļþ±»ÓÊÕþ²¿·ÖºÍEUSS·Å´íÁ˵ط½£»£»£»£»Î´¾Ô޳ɱãÓëµÚÈý·½¹²ÏíÉêÇëÈ˵ÄÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£ÄÚÕþ²¿ÌåÏֻᰴÆÚÉó²éËùÓÐÁ÷³ÌºÍ³ÌÐò£¬£¬£¬£¬£¬£¬£¬ÒÔ¼õÇáÊý¾Ýй¶µÄΣº¦¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/uk-home-office-breached-gdpr-100-times-through-botched-handling-of-eu-settlement-scheme/
2.Checkpoint½¨Éè¶ñÒâÈí¼þÈÆÌ«¹ýÎöµÄÊÖÒյİٿÆÈ«Êé
Checkpoint½¨ÉèÁ˹ØÓÚ¶ñÒâÈí¼þÓÃÀ´ÌӱܯÊÎöµÄÖÖÖÖÊÖÒյİٿÆÈ«Êé¡£¡£¡£¡£¡£¡£¸Ã°Ù¿ÆÈ«Ê麸ÇÁËÓëÎļþϵͳ¡¢×¢²á±í¡¢Í¨ÓÃOSÅÌÎÊ¡¢È«¾ÖOS¹¤¾ß¡¢Óû§½çÃæ¡¢OS¹¦Ð§¡¢Àú³Ì¡¢ÍøÂç¡¢CPU¡¢¹Ì¼þ±í¡¢¹³×Ó¡¢Ó²¼þÒÔ¼°MacOSÌØ¶¨µÄɳÏäÓйصÄÌÓ±ÜÊÖÒÕ¡£¡£¡£¡£¡£¡£Ã¿Ò»¸öÖֱ𶼰üÀ¨ÊÖÒÕÐÎò¡¢´úÂëʾÀý¡¢ÓÃÓÚ¸ú×Ù¸ÃÊÖÒÕµÄÊðÃû½¨Òé¡¢¿É¼ì²âÇéÐÎÀàÐ͵ıí¸ñÒÔ¼°¶Ô²ß¡£¡£¡£¡£¡£¡£Checkpoint»¹ÍýÏëÔöÌíÓë¼ÆÊ±¡¢Windows Management Instrumentation£¨WMI£©ºÍÈËÀàÐÐΪÒòËØÓйصÄÌÓ±ÜÊÖÒÕ¡£¡£¡£¡£¡£¡£Ïà¹ØÁìÓòµÄר¼Ò¿ÉÒÔÔÚGithubÒ³ÃæÉÏΪ¸Ã°Ù¿ÆÈ«Êé×ö³öТ˳¡£¡£¡£¡£¡£¡£Ò»Ð©ÑÝʾ¹æ±ÜÊÖÒյŤ¾ßÊÇ¿ªÔ´µÄ£¬£¬£¬£¬£¬£¬£¬Í¬Ê±Checkpoint»¹Ðû²¼ÁË×Ô¼ºµÄÃûΪInviZzzibleµÄ¿ªÔ´¹¤¾ß¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/checkpoint-creates-encyclopedia-malware-evasion-techniques
3.Ó¢¹úTravelex¹«Ë¾Ô¤¼ÆÒòÍøÂç¹¥»÷Ëðʧ2500ÍòÓ¢°÷
¾Ý·͸É籨µÀ£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ12ÔÂÏÂÑ®µÄÀÕË÷Èí¼þ¹¥»÷ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬Íâ±Ò¶Ò»»¹«Ë¾TravelexÔ¤¼ÆÆäµÚÒ»¼¾¶ÈµÄ½¹µãÊÕÈëËðʧΪ2500ÍòÓ¢°÷£¨ºÏ3200ÍòÃÀÔª£©¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾»¹ÌåÏÖÒѻָ´ÁËËùÓÐÃæÏò¿Í»§µÄϵͳ¡£¡£¡£¡£¡£¡£Travelexͨ¹ýÆä×Ô¶¯¶©µ¥Ð§ÀÍΪ»ã·áÒøÐС¢°Í¿ËÀ³ÒøÐС¢Î¬ÕäÇ®±ÒÒÔ¼°Ó¢¹úÁãÊÛÉÌTescoºÍSainsburyµÄÒøÐв¿·Ö¿Í»§ÌṩÍâ»ãЧÀÍ¡£¡£¡£¡£¡£¡£TravelexÌåÏִ˴ι¥»÷²»»á¶ÔËæºó¼¸¸ö¼¾¶ÈµÄÉúÒâÔì³ÉÈκÎʵÖÊÐÔÓ°Ïì¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾»¹³Æ¹Ú×´²¡¶¾µÄ±¬·¢¶ÔÆäÓªÒµÔì³ÉÁËÁíÍâÒ»¸ö¸ºÃæÓ°Ï죬£¬£¬£¬£¬£¬£¬µ«Î´Ô¤¼Æ¸Ã²¡¶¾»á´øÀ´Èκξ¼ÃËðʧ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://uk.finance.yahoo.com/news/travelex-expects-25-million-hit-093953943.html
4.Let's Encrypt³·»ØÁè¼Ý300Íò¸öTLSÖ¤Êé
ÓÉÓÚÔÚºó¶Ë´úÂëÖз¢Ã÷ÁËÒ»¸öbug£¬£¬£¬£¬£¬£¬£¬Let's EncryptÏîÄ¿ÍýÏë´ÓÌìϱê׼ʱ¼ä2020Äê3ÔÂ4ÈÕ00:00×îÏÈ×÷·ÏÁè¼Ý300Íò¸öTLSÖ¤Êé¡£¡£¡£¡£¡£¡£ÏêϸÀ´Ëµ£¬£¬£¬£¬£¬£¬£¬¸ÃbugÓ°ÏìÁËBoulder£¬£¬£¬£¬£¬£¬£¬Let's EncryptÏîĿʹÓøÃЧÀÍÆ÷Èí¼þÔÚ¿¯ÐÐTLSÖ¤Êé֮ǰÑéÖ¤Óû§¼°ÆäÓò¡£¡£¡£¡£¡£¡£¸ÃbugÓ°ÏìÁËBoulderÄÚ²¿CAA£¨Ö¤Êé½ÒÏþ»ú¹¹ÊÚȨ£©¹æ·¶µÄʵÑ飬£¬£¬£¬£¬£¬£¬¡°µ±Ò»¸öÖ¤ÊéÇëÇó°üÀ¨N¸öÐèÒª¾ÙÐÐCAAÖØÐ¼ì²éµÄÓòÃûʱ£¬£¬£¬£¬£¬£¬£¬Boulder½«Ñ¡ÔñÒ»¸öÓòÃû²¢¼ì²éN´Î¡£¡£¡£¡£¡£¡£ÕâÏÖʵÉÏÒâζ×ÅÈôÊÇÒ»¸öÓû§ÔÚʱ¼äXÑéÖ¤ÁËÒ»¸öÓòÃû£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ¸ÃÓòÃûÔÚʱ¼äXµÄCAA¼Í¼ÔÊÐíLet's Encrypt¿¯ÐУ¬£¬£¬£¬£¬£¬£¬Ôò¸ÃÓû§¿ÉÒÔÔÚX+30ÌìµÄʱ¼äÀ￯ÐаüÀ¨¸ÃÓòÃûµÄÖ¤Ê飬£¬£¬£¬£¬£¬£¬×ÝȻ֮ºóÓÐÈËÔÚ¸ÃÓòÃûÉÏ×°ÖÃÁËեȡLet's Encrypt¿¯ÐеÄCAA¼Í¼¡±¡£¡£¡£¡£¡£¡£ÔÚÕâ300Íò¸ö×÷·ÏµÄÖ¤ÊéÖУ¬£¬£¬£¬£¬£¬£¬ÓÐ100Íò¸öÊÇͳһÓò/×ÓÓòµÄÖØ¸´Ï£¬£¬£¬£¬£¬£¬Òò´ËÊÜÓ°ÏìÖ¤ÊéµÄÏÖʵÊýĿԼΪ200Íò¸ö¡£¡£¡£¡£¡£¡£ÔÚ3ÔÂ4ÈÕ00:00Ö®ºóËùÓÐÊÜÓ°ÏìµÄÖ¤Êé¶¼½«´¥·¢ä¯ÀÀÆ÷ºÍÆäËûÓ¦ÓóÌÐòÖеĹýʧ£¬£¬£¬£¬£¬£¬£¬ÓòÃûËùÓÐÕß½«±ØÐèÇëÇóеÄTLSÖ¤Êé²¢Ìæ»»¾ÉµÄTLSÖ¤Êé¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/lets-encrypt-to-revoke-3-million-certificates-on-march-4-due-to-bug/
5.APT34й¥»÷»î¶¯Karkoff 2020£¬£¬£¬£¬£¬£¬£¬Õë¶ÔÀè°ÍÄÛÕþ¸®»ú¹¹
Cybaze/Yoroi ZlabµÄר¼Ò·¢Ã÷APT34×éÖ¯µÄÒ»¸öÐÂÑù±¾£¬£¬£¬£¬£¬£¬£¬ËûÃÇÒÔΪ¸ÃÑù±¾ÊÇKarkoffÖ²ÈëÎïµÄ¸üа汾£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔ֤ʵAPT34ÈÔÈ»´¦Óڻ״̬¡£¡£¡£¡£¡£¡£ÔÚÕâ¸öÐµĹ¥»÷»î¶¯ÖÐAPT34¿ÉÄÜÈëÇÖÁËÊôÓÚÀè°ÍÄÛÕþ¸®»ú¹¹µÄMicrosoft Exchange Server¡£¡£¡£¡£¡£¡£ÐÂÑù±¾ÓëÒÑÍùKarkoffÑù±¾µÄÏàËÆÖ®´¦°üÀ¨¾ßÓÐÏàËÆµÄºê½á¹¹¡¢¾ßÓÐÀàËÆÂß¼µÄ.NETÄ£¿£¿£¿£¿£¿é»¯Ö²ÈëÎïÒÔ¼°Ê¹ÓÃMicrosoft Exchange Server×÷ΪͨѶÇþµÀ¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬ÐÂKarkoffÖ²ÈëÎïʵÏÖÁËеÄÕì̽Âß¼£¬£¬£¬£¬£¬£¬£¬ÒÔ±ã½ö½«×îÖÕµÄÓÐÓúÉÔØÊͷŵ½Ìض¨Ä¿µÄ£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÍøÂçϵͳÐÅÏ¢¡¢ÓòÃû¡¢Ö÷»úÃûºÍÕýÔÚÔËÐеIJÙ×÷ϵͳµÈÐÅÏ¢¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/98802/uncategorized/karkoff-malware-lebanon.html
6.ÐÂPwndLockerÀÕË÷Èí¼þÖ÷ÒªÕë¶ÔÃÀ¹úÊÐÕþÕþ¸®ºÍÆóÒµÍøÂç
Çå¾²Ñо¿Ö°Ô±·¢Ã÷Õë¶ÔÊÐÕþÕþ¸®ºÍÆóÒµÍøÂçµÄÐÂÀÕË÷Èí¼þ¼Ò×å¡°PwndLocker¡±£¬£¬£¬£¬£¬£¬£¬¸Ã¼Ò×å×Ô2019Äêµ×ÒÔÀ´Ò»Ö±»îÔ¾£¬£¬£¬£¬£¬£¬£¬²¢ÔÚÕâ¶Îʱ¼äÄÚ¹¥»÷ÁËÃÀ¹ú¶à¸ö¶¼»áºÍ×éÖ¯¡£¡£¡£¡£¡£¡£PwndLockerÓë½üÆÚÕë¶ÔÒÁÀûŵÒÁÖÝÀÈø¶ûÏØµÄ¹¥»÷Óйأ¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÒªÇó50¸ö±ÈÌØ±Ò£¨Ô¼ºÏ44.2ÍòÃÀÔª£©µÄÊê½ð£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ³ÆÔÚ¼ÓÃÜ֮ǰÒѾÇÔÈ¡Á˸ÃÏØµÄÊý¾Ý¡£¡£¡£¡£¡£¡£ÍâµØÃ½ÌåÖ¸³ö£¬£¬£¬£¬£¬£¬£¬ÀÈø¶ûÏØÎÞÒâÖ§¸¶Êê½ð¡£¡£¡£¡£¡£¡£Æ¾Ö¤Ñо¿Ö°Ô±µÄÆÊÎö£¬£¬£¬£¬£¬£¬£¬PwndLockerʹÓá°net stop¡±ÏÂÁî½ûÓÃÁ˶à¸öWindowsЧÀÍ£¬£¬£¬£¬£¬£¬£¬ÀýÈçMicrosoft SQL Server¡¢MySQLºÍExchange£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ¼ì²âºÍɱËÀÓëFirefox¡¢Word¡¢Excel¡¢AccessÒÔ¼°ÓëÇå¾²Èí¼þ¡¢±¸·ÝÓ¦ÓóÌÐòºÍÊý¾Ý¿âЧÀÍÆ÷ÓйصÄÀú³Ì¡£¡£¡£¡£¡£¡£Æä¼ÓÃÜÎļþµÄÀ©Õ¹ÃûΪ¡°.key¡±»ò¡° .pwnd¡±¡£¡£¡£¡£¡£¡£PwndLocker²¢²»ÊǵÚÒ»¸öÕë¶ÔÆóÒµÍøÂçµÄÀÕË÷Èí¼þ£¬£¬£¬£¬£¬£¬£¬Ö®Ç°Ñо¿Ö°Ô±»¹·¢Ã÷ÁËÕë¶ÔÆóÒµÍøÂçµÄSNAKEºÍAko¼Ò×å¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.tripwire.com/state-of-security/security-data-protection/pwndlocker-ransomware-targeting-municipalities-enterprise-networks/