°®¶ûÀ¼Ò½ÁÆ»ú¹¹HSEѬȾConti £¬£¬£¬£¬£¬±»ÀÕË÷½ü2000ÍòÃÀÔª£»£»£»£»£»£»DarkSideÀÕË÷Èí¼þЧÀÍÆ÷±»²é·â²¢Ðû²¼½«ÖÕÖ¹ÔËÓª

Ðû²¼Ê±¼ä 2021-05-17

1.°®¶ûÀ¼Ò½ÁÆ»ú¹¹HSEѬȾConti £¬£¬£¬£¬£¬±»ÀÕË÷½ü2000ÍòÃÀÔª


1.jpg


°®¶ûÀ¼µÄÒ½ÁÆÐ§ÀÍ»ú¹¹HSEÌåÏÖ £¬£¬£¬£¬£¬ÆäÔâµ½ÁËContiÀÕË÷Èí¼þ¹¥»÷ £¬£¬£¬£¬£¬²¢±»ÒªÇóÖ§¸¶19999000ÃÀÔªµÄÊê½ð¡£¡£¡£¡£¡£¸Ã»ú¹¹ÔÚ·¢Ã÷¹¥»÷ºó £¬£¬£¬£¬£¬ÒÑÓÚÉÏÖÜÎ幨±ÕÁËËùÓÐITϵͳ¡£¡£¡£¡£¡£ContiÍÅ»ïÉù³ÆÒѾ­½øÈëHSEµÄÍøÂçÁ½ÖÜÁË £¬£¬£¬£¬£¬ÔÚ´Ëʱ´ú £¬£¬£¬£¬£¬ËûÃÇÇÔÈ¡ÁËHSE 700 GBµÄδ¼ÓÃÜÎļþ £¬£¬£¬£¬£¬°üÀ¨»¼ÕßÐÅÏ¢ºÍÔ±¹¤ÐÅÏ¢¡¢ÌõÔ¼¡¢²ÆÎñ±¨±íºÍÈËΪµ¥µÈ¡£¡£¡£¡£¡£°®¶ûÀ¼×ÜÀíTaoiseach Miche¨¢l MartinÓÚ5ÔÂ14ÈÕÔÚÐÂÎÅÐû²¼»áÉÏÌåÏÖ £¬£¬£¬£¬£¬ËûÃǽ«²»Ö§¸¶ÈκÎÊê½ð¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ireland-s-health-services-hit-with-20-million-ransomware-demand/


2.Herff Jones¿Í»§ÐÅÓÿ¨±»µÁË¢ £¬£¬£¬£¬£¬Éæ¼°ÃÀ¹ú´óѧ½áÒµÉú


2.jpg


ñ×ÓºÍÖÆ·þÖÆÔìÉÌHerff Jonesй¶¿Í»§µÄÐÅÓÿ¨ÐÅÏ¢ £¬£¬£¬£¬£¬Ó°ÏìÁËÃÀ¹ú´ó¶¼´óѧ½áÒµÉú¡£¡£¡£¡£¡£ÔÚÉÏÖÜÈÕ £¬£¬£¬£¬£¬ÃÀ¹ú¼¸Ëù´óѧµÄ½áÒµÉúÌåÏÖ £¬£¬£¬£¬£¬ËûÃÇÔÚHerff JonesʹÓÃÐÅÓÿ¨¹ºÖýáÒµÒÇʽ´ò°çºó±¬·¢Á˵ÁË¢ÉúÒâ¡£¡£¡£¡£¡£´ó´ó¶¼Êܺ¦ÕßµÄËðʧÔÚ80µ½1200ÃÀÔªÖ®¼ä £¬£¬£¬£¬£¬Ò²ÓÐÈËËðʧ¸ß´ï4000ÃÀÔª¡£¡£¡£¡£¡£Ö±µ½ÕâЩѧÉúÔÚÉ罻ýÌåÉÏËß¿à´Ë´ÎµÄµÁË¢ÊÂÎñ £¬£¬£¬£¬£¬Herff Jones²ÅµÃÖªÁËÐÅÓÿ¨Ð¹Â¶ÎÊÌâ £¬£¬£¬£¬£¬ÏÖÔÚÉв»ÇåÎúй¶×îÏȵÄʱ¼ä £¬£¬£¬£¬£¬µ«×îÔçµÄÉúÒâÈÕÆÚÊÇ´Ó±¾Ô³õ×îÏÈ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/herff-jones-credit-card-breach-impacts-college-students-across-the-us/


3.ºÚ¿ÍÍÅ»ïFIN7ÔÚ×î½üµÄ¹¥»÷ÖÐʹÓÃеÄLizarºóÃÅ


3.jpg


BI.ZONEÍøÂçÍþвÑо¿ÍŶӷ¢Ã÷ £¬£¬£¬£¬£¬ºÚ¿ÍÍÅ»ïFIN7ÔÚ×î½üµÄ¹¥»÷ÖÐʹÓÃеÄLizarºóÃÅ¡£¡£¡£¡£¡£×Ô2015ÄêÖÐÒÔÀ´ £¬£¬£¬£¬£¬¶íÂÞ˹ºÚ¿ÍÍÅ»ïFIN7¾ÍÃé×¼ÁËÃÀ¹úµÄÁãÊÛ¡¢²ÍÒûºÍÂùÝÐÐÒµ¡£¡£¡£¡£¡£Ôڴ˴ι¥»÷ÖÐ £¬£¬£¬£¬£¬FIN7αװ³ÉÏúÊÛÇå¾²ÆÊÎöƽ̨µÄÕýµ±¹«Ë¾ £¬£¬£¬£¬£¬²¢ÇÒ×Ô½ñÄê2Ô·ÝÒÔÀ´Ò»Ö±Ê¹ÓÃеÄLizarºóÃÅ¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÊÇʹÓÃ.NET¿ò¼Ü±àдµÄ £¬£¬£¬£¬£¬ÔÚÔ¶³ÌLinuxÖ÷»úÉÏÔËÐÐ £¬£¬£¬£¬£¬Ö§³ÖÓëBot¿Í»§¶ËµÄ¼ÓÃÜͨѶ £¬£¬£¬£¬£¬¾ßÓÐǿʢµÄÊý¾Ý¼ìË÷ºÍºáÏòÒÆ¶¯¹¦Ð§¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2021/05/fin7-is-spreading-backdoor-called-lizar.html


4.DarkSideÀÕË÷Èí¼þЧÀÍÆ÷±»²é·â²¢Ðû²¼½«ÖÕÖ¹ÔËÓª


4.jpg


DarkSideÊÇÒ»¸öÀÕË÷Èí¼þЧÀÍÆ÷ÍŻRaaS£© £¬£¬£¬£¬£¬Ò»ÖÜǰ¹¥»÷ÁËColonial Pipeline Co.²¢ÀÕË÷500ÍòÃÀÔª¡£¡£¡£¡£¡£¸ÃÍÅ»ïÓÚ2021Äê5ÔÂ13ÈÕÐû²¼ÉùÃ÷³Æ £¬£¬£¬£¬£¬ÓÉÓÚÖ´·¨Ðж¯ £¬£¬£¬£¬£¬ËûÃÇÏÖÔÚÒѾ­ÎÞ·¨Í¨¹ýSSH»á¼ûÆä¹«¹²Êý¾ÝÐ¹Â¶ÍøÕ¾¡¢Ö§¸¶Ð§ÀÍÆ÷ºÍCDNЧÀÍÆ÷ £¬£¬£¬£¬£¬ÒÔ¼°Ö÷»ú½çÃæ¡£¡£¡£¡£¡£Òò´Ë½«ÎªËùÓÐÉÐδ¸¶¿îµÄ¹«Ë¾Ìṩ½âÃܹ¤¾ß £¬£¬£¬£¬£¬²¢ÔÊÐíÔÚ2021Äê5ÔÂ23ÈÕ֮ǰËÍ»¹ËùÓÐδ³¥Õ®Îñ¡£¡£¡£¡£¡£¸ÃÉùÃ÷»¹Ö¸³öÓÉÓÚÀ´×ÔÃÀ¹úµÄѹÁ¦ £¬£¬£¬£¬£¬Æä½«ÖÕÖ¹ÀÕË÷»î¶¯¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.intel471.com/blog/darkside-ransomware-shut-down-revil-avaddon-cybercrime


5.ExtraHop³Æ67£¥µÄ¹«Ë¾ÈÔÒ×Ôâµ½WannaCryµÄ¹¥»÷


5.jpg


Ô­ÉúÔÆÍøÂç¼ì²âºÍÏìÓ¦¹«Ë¾ExtraHop³Æ67£¥µÄ¹«Ë¾ÈÔÔÚÔËÐв»Çå¾²µÄWindowsЭÒéSMBv1 £¬£¬£¬£¬£¬Ò×Ôâµ½WannaCryºÍNotPetyaµÄ¹¥»÷¡£¡£¡£¡£¡£±ðµÄ £¬£¬£¬£¬£¬Ñо¿»¹·¢Ã÷70£¥µÄÇéÐÎÈÔÔÚÔËÐÐLLMNR £¬£¬£¬£¬£¬¸ÃЭÒé¿É±»ÓÃÀ´»á¼ûÓû§Æ¾Ö¤µÄ¹þÏ££»£»£»£»£»£»34£¥µÄÆóҵʹÓÃÔËÐÐÁËNTLMv1µÄ¿Í»§¶Ë £¬£¬£¬£¬£¬µ«Microsoft½¨Òé×é֯ʹÓÃÔ½·¢Çå¾²µÄKerberosÉí·ÝÑé֤ЭÒ飻£»£»£»£»£»81£¥µÄÆóҵʹÓò»Çå¾²µÄHTTP´«Êä´¿Îı¾Æ¾Ö¤¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.extrahop.com/company/press-releases/2021/insecure-protocols/


6.VerizonÐû²¼2021ÄêÊý¾ÝÎ¥¹æÊÓ²ìÆÊÎö±¨¸æ£¨DBIR£©


6.jpg


VerizonÐû²¼ÁË2021ÄêÊý¾ÝÎ¥¹æÊÓ²ìÆÊÎö±¨¸æ£¨DBIR£©¡£¡£¡£¡£¡£¸Ã±¨¸æ¹²ÆÊÎöÁË29207ÆðÊÂÎñ £¬£¬£¬£¬£¬ÆäÖÐ5258Æð±»È·ÒÔΪÊý¾ÝÎ¥¹æÊÂÎñ¡£¡£¡£¡£¡£±¨¸æÖ¸³ö £¬£¬£¬£¬£¬ÍøÂç´¹ÂÚ¹¥»÷ÔöÌíÁË11£¥ £¬£¬£¬£¬£¬ÀÕË÷Èí¼þ¹¥»÷ÔöÌíÁË6£¥ £¬£¬£¬£¬£¬±ÈÈ¥ÄêÔöÌíÁË15±¶£»£»£»£»£»£»85£¥µÄй¶ÊÂÎñÉæ¼°ÈËΪÒòËØ £¬£¬£¬£¬£¬¶øÁè¼Ý80£¥µÄй¶ÊÂÎñÊÇÓÉÍⲿ¸÷·½·¢Ã÷µÄ£»£»£»£»£»£»Ò»´Îй¶ÊÂÎñµÄƽ¾ùËðʧΪ21659ÃÀÔª £¬£¬£¬£¬£¬ÆäÖÐ95£¥µÄÊÂÎñµÄËðʧ½éÓÚ826ÃÀÔªÖÁ653587ÃÀÔªÖ®¼ä¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.verizon.com/business/resources/reports/dbir/2021/masters-guide/