Ó¢¹ú´¦ÖÃÅ·ÃËÓÀ¾Ó¹æ»®Ê±ÖÁÉÙÎ¥·´ÁË100´ÎGDPR£»APT34й¥»÷»î¶¯Karkoff 2020

°ä²¼¹¦·ò 2020-03-04

1.Ó¢¹ú´¦ÖÃÅ·ÃËÓÀ¾Ó¹æ»®Ê±ÖÁÉÙÎ¥·´ÁË100´ÎGDPR


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ó¢¹úÄÚÕþ²¿ÔÚ´¦ÖÃÅ·ÃËÓÀ¾Ó¹æ»®£¨EUSS£©Ê±ÖÁÉÙÎ¥·´ÁË100´ÎGDPR ¡£Ê×ϯÌìǵºÍÒÆÃñ²é³­¹Ù£¨David Ilt£©ÔÚÒÆÃñ¼à¹Ü»ú¹¹½øÐеÄÒ»·Ý»ã±¨ÖаµÊ¾ £¬Ö»¹ÜGDPRÒªÇó¶ÔÔ±¹¤½øÐÐÒâʶÅàѵ £¬µ«ÈԼͼµ½¶ÔGDPRµÄÑϳÁÎ¥·´ ¡£Æ¾¾Ý¸Ã»ã±¨ £¬½ØÖÁ2019Äê8Ôµ× £¬ÄÚÕþ²¿£¨EUSSµÄ¼à¶½Õߣ©ÊÕµ½ÁË130Íò·ÝÉêÇë £¬²¢ÇÒÒѾ­ÓÐÉϰÙÍòÈË»ñµÃºË×¼ ¡£µ«ÔÚ2019Äê3ÔÂ30ÈÕÖÁ8ÔÂ31ÈÕÆÚ¼ä £¬µ±¾ÖÎ¥·´ÁËGDPRµÄÊÂÎñÓÐ100Æð ¡£ÕâЩÊÂÎñÔ̺¬½«Éí·ÝÖ¤¿¨Æ¬·¢ËÍÖÁÃýÎóµÄÉêÇëÈ˺͵ØÖ·£»ºÜ¶à»¤ÕÕÃÔʧÁË £¬Éí·ÝÖ¤Ã÷Îļþ±»ÓÊÕþ²¿ÃźÍEUSS·Å´íÁË´¦Ëù£»Î´¾­Ô޳ɱãÓëµÚÈý·½¹²ÏíÉêÇëÈ˵ÄÐÅÏ¢µÈ ¡£ÄÚÕþ²¿°µÊ¾»á¶¨ÆÚÉó²éËùÓÐÁ÷³ÌºÍ·¨Ê½ £¬ÒÔ¼õÇáÊý¾Ýй¶µÄ·çÏÕ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/uk-home-office-breached-gdpr-100-times-through-botched-handling-of-eu-settlement-scheme/


2.Checkpoint´´½¨¶ñÒâÈí¼þÈÆ¹ý¶ÈÎöµÄ¼¼ÊõµÄ°Ù¿ÆÈ«Êé


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Checkpoint´´½¨Á˹ØÓÚ¶ñÒâÈí¼þÓÃÀ´ÌӱܷÖÎöµÄ¸÷À༼ÊõµÄ°Ù¿ÆÈ«Êé ¡£¸Ã°Ù¿ÆÈ«Ê麭¸ÇÁËÓëÎļþϵͳ¡¢×¢²á±í¡¢Í¨ÓÃOS²éÎÊ¡¢È«¾ÖOS¶ÔÏó¡¢Óû§½çÃæ¡¢OSÖ°ÄÜ¡¢¹ý³Ì¡¢ÍøÂç¡¢CPU¡¢¹Ì¼þ±í¡¢¹³×Ó¡¢Ó²¼þÒÔ¼°MacOSÌØ¶¨µÄɳÏäÓйصÄÌӱܼ¼Êõ ¡£Ã¿Ò»¸öÀà±ð¶¼Ô̺¬¼¼ÊõÃèÊö¡¢´úÂëʾÀý¡¢ÓÃÓÚ¸ú×ٸü¼ÊõµÄÊðÃû½¨Òé¡¢¿É¼ì²â»·¾³ÀàÐ͵ıí¸ñÒÔ¼°¶Ô²ß ¡£Checkpoint»¹´òËãÔö³¤Óë¼ÆÊ±¡¢Windows Management Instrumentation£¨WMI£©ºÍÈËÀàÐÐΪ³É·ÖÓйصÄÌӱܼ¼Êõ ¡£ÓйØÁìÓòµÄר¼ÒÄܹ»ÔÚGithubÒ³ÃæÉÏΪ¸Ã°Ù¿ÆÈ«Êé×ö³ö¹±Ï× ¡£Ò»Ð©ÑÝʾ¶ã±Ü¼¼ÊõµÄ¹¤¾ßÊÇ¿ªÔ´µÄ £¬Í¬Ê±Checkpoint»¹°ä²¼ÁË×Ô¼ºµÄÃûΪInviZzzibleµÄ¿ªÔ´¹¤¾ß ¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/checkpoint-creates-encyclopedia-malware-evasion-techniques


3.Ó¢¹úTravelex¹«Ë¾Ô¤¼ÆÒòÍøÂç¹¥»÷Ëðʧ2500ÍòÓ¢°÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¾Ý·͸É籨· £¬ÓÉÓÚ12ÔÂÏÂÑ®µÄÀÕË÷Èí¼þ¹¥»÷ÊÂÎñ £¬±í±Ò¶Ò»»¹«Ë¾Travelex¹À¼ÆÆäµÚÒ»¼¾¶ÈµÄÖ÷ÌâÊÕÈëËðʧΪ2500ÍòÓ¢°÷£¨ºÏ3200ÍòÃÀÔª£© ¡£¸Ã¹«Ë¾»¹°µÊ¾ÒѸ´Ô­ÁËËùÓÐÃæÏò¿Í»§µÄϵͳ ¡£Travelexͨ¹ýÆä×Ô¶¯¶©µ¥·þÎñΪ»ã·áÒøÐÓ×¢°Í¿ËÀ³ÒøÐÓעάÕäÇ®±ÒÒÔ¼°Ó¢¹úÁãÊÛÉÌTescoºÍSainsburyµÄÒøÐв¿Ãſͻ§Ìṩ±í»ã·þÎñ ¡£Travelex°µÊ¾Õâ´Î¹¥»÷²»»á¶ÔËæºó¼¸¸ö¼¾¶ÈµÄÂòÂôÔì³ÉÈκÎÄÚÈÝÐÔÓ°Ïì ¡£¸Ã¹«Ë¾»¹³Æ¹Ú×´²¡¶¾µÄ·¢×÷¶ÔÆäÒµÎñÔì³ÉÁËÁí±íÒ»¸ö¸ºÃæÓ°Ïì £¬µ«Î´Ô¤¼Æ¸Ã²¡¶¾»á´øÀ´Èκξ­¼ÃËðʧ ¡£


Ô­ÎÄÁ´½Ó£º

https://uk.finance.yahoo.com/news/travelex-expects-25-million-hit-093953943.html


4.Let's Encrypt³·»Ø³¬¹ý300Íò¸öTLSÖ¤Êé


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÓÉÓÚÔÚºó¶Ë´úÂëÖз¢ÏÖÁËÒ»¸öbug £¬Let's EncryptÏîÄ¿´òËã´ÓÊÀ½ç±ê¶¨¹¦·ò2020Äê3ÔÂ4ÈÕ00:00ÆðÍ·³·Ïú³¬¹ý300Íò¸öTLSÖ¤Êé ¡£¾ßÌåÀ´Ëµ £¬¸ÃbugÓ°ÏìÁËBoulder £¬Let's EncryptÏîĿʹÓø÷þÎñÆ÷Èí¼þÔÚ¿¯ÐÐTLSÖ¤Êé֮ǰÑéÖ¤Óû§¼°ÆäÓò ¡£¸ÃbugÓ°ÏìÁËBoulderÄÚ²¿CAA£¨Ö¤ÊéÐû¸æ»ú¹¹ÊÚȨ£©¹æ·¶µÄÖ´ÐÐ £¬¡°µ±Ò»¸öÖ¤ÊéÒªÇóÔ̺¬N¸ö±ØÒª½øÐÐCAA³Áв鳭µÄÓòÃûʱ £¬Boulder½«Ñ¡ÔñÒ»¸öÓòÃû²¢²é³­N´Î ¡£ÕâÏÖʵÉÏÒâζ×ÅÈôÊÇÒ»¸öÓû§ÔÚ¹¦·òXÑéÖ¤ÁËÒ»¸öÓòÃû £¬²¢ÇÒ¸ÃÓòÃûÔÚ¹¦·òXµÄCAA¼Í¼ÔÊÐíLet's Encrypt¿¯ÐÐ £¬Ôò¸ÃÓû§Äܹ»ÔÚX+30ÌìµÄ¹¦·òÀ￯ÐÐÔ̺¬¸ÃÓòÃûµÄÖ¤Êé £¬¼´±ãÖ®ºóÓÐÈËÔÚ¸ÃÓòÃûÉÏ×°ÖÃÁ˲»ÈÝLet's Encrypt¿¯ÐеÄCAA¼Í¼¡± ¡£ÔÚÕâ300Íò¸ö³·ÏúµÄÖ¤ÊéÖÐ £¬ÓÐ100Íò¸öÊÇͳһÓò/×ÓÓòµÄ³Á¸´Ïî £¬Òò¶øÊÜÓ°ÏìÖ¤ÊéµÄÏÖʵÊýÁ¿Ô¼Îª200Íò¸ö ¡£ÔÚ3ÔÂ4ÈÕ00:00Ö®ºóËùÓÐÊÜÓ°ÏìµÄÖ¤Êé¶¼½«´¥·¢ä¯ÀÀÆ÷ºÍÆäËûÀûÓ÷¨Ê½ÖеÄÃýÎó £¬ÓòÃûËùÓÐÕß½«±Ø±ØÒªÇóеÄTLSÖ¤Êé²¢´úÌæ¾ÉµÄTLSÖ¤Êé ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/lets-encrypt-to-revoke-3-million-certificates-on-march-4-due-to-bug/


5.APT34й¥»÷»î¶¯Karkoff 2020 £¬Õë¶ÔÀè°ÍÄÛµ±¾Ö»ú¹¹


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Cybaze/Yoroi ZlabµÄר¼Ò·¢ÏÖAPT34×éÖ¯µÄÒ»¸öÐÂÑù±¾ £¬ËûÃÇÒÔΪ¸ÃÑù±¾ÊÇKarkoffÖ²ÈëÎïµÄ¸üа汾 £¬Äܹ»Ö¤Ã÷APT34ÒÀÈ»´¦Óڻ״̬ ¡£ÔÚÕâ¸öÐµĹ¥»÷»î¶¯ÖÐAPT34¿ÉÄÜÈëÇÖÁËÊôÓÚÀè°ÍÄÛµ±¾Ö»ú¹¹µÄMicrosoft Exchange Server ¡£ÐÂÑù±¾Óë´ÓǰKarkoffÑù±¾µÄÀàËÆÖ®´¦Ô̺¬ÓµÓÐÀàËÆµÄºê½á¹¹¡¢ÓµÓÐÀàËÆÂß¼­µÄ.NETÄ £¿é»¯Ö²ÈëÎïÒÔ¼°ÀûÓÃMicrosoft Exchange Server×÷ΪͨѶÇþ· ¡£´Ë±í £¬ÐÂKarkoffÖ²ÈëÎïʵÏÖÁËеĿúËÅÂß¼­ £¬ÒÔ±ã½ö½«×îÖÕµÄÓÐЧºÉÔØ¿ªÊ͵½Ìض¨Ö¸±ê £¬²¢ÇÒÍøÂçϵͳÐÅÏ¢¡¢ÓòÃû¡¢Ö÷»úÃûºÍÔÚÔËÐеIJÙ×÷ϵͳµÈÐÅÏ¢ ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/98802/uncategorized/karkoff-malware-lebanon.html


6.ÐÂPwndLockerÀÕË÷Èí¼þÖØÒªÕë¶ÔÃÀ¹úÊÐÕþµ±¾ÖºÍÆóÒµÍøÂç


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°²È«×êÑÐÈËÔ±·¢ÏÖÕë¶ÔÊÐÕþµ±¾ÖºÍÆóÒµÍøÂçµÄÐÂÀÕË÷Èí¼þ¼Ò×å¡°PwndLocker¡± £¬¸Ã¼Ò×å×Ô2019Äêµ×ÒÔÀ´Ò»Ïò»îÔ¾ £¬²¢ÔÚÕâ¶Î¹¦·òÄÚ¹¥»÷ÁËÃÀ¹ú¶à¸ö³ÇÊкÍ×éÖ¯ ¡£PwndLockerÓë½üÆÚÕë¶ÔÒÁÀûŵÒÁÖÝÀ­Èø¶ûÏØµÄ¹¥»÷ÓйØ £¬¹¥»÷ÕßÒªÇó50¸ö±ÈÌØ±Ò£¨Ô¼ºÏ44.2ÍòÃÀÔª£©µÄÊê½ð £¬²¢ÇÒ³ÆÔÚ¼ÓÃÜ֮ǰÒѾ­ÇÔÈ¡Á˸ÃÏØµÄÊý¾Ý ¡£±¾µØÃ½ÌåÖ¸³ö £¬À­Èø¶ûÏØÎÞÒâÖ§¸¶Êê½ð ¡£Æ¾¾Ý×êÑÐÈËÔ±µÄ·ÖÎö £¬PwndLockerÀûÓá°net stop¡±ºÅÁî½ûÓÃÁ˶à¸öWindows·þÎñ £¬ÀýÈçMicrosoft SQL Server¡¢MySQLºÍExchange £¬²¢ÇÒ¼ì²âºÍɱËÀÓëFirefox¡¢Word¡¢Excel¡¢AccessÒÔ¼°Ó밲ȫÈí¼þ¡¢±¸·ÝÀûÓ÷¨Ê½ºÍÊý¾Ý¿â·þÎñÆ÷ÓйصĹý³Ì ¡£Æä¼ÓÃÜÎļþµÄÀ©´óÃûΪ¡°.key¡±»ò¡° .pwnd¡± ¡£PwndLocker²¢²»ÊǵÚÒ»¸öÕë¶ÔÆóÒµÍøÂçµÄÀÕË÷Èí¼þ £¬Ö®Ç°×êÑÐÈËÔ±»¹·¢ÏÖÁËÕë¶ÔÆóÒµÍøÂçµÄSNAKEºÍAko¼Ò×å ¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.tripwire.com/state-of-security/security-data-protection/pwndlocker-ransomware-targeting-municipalities-enterprise-networks/