¹¥»÷»î¶¯Duriͨ¹ýHTMLºÍJavaScript·Ö·¢¶ñÒâÈí¼þ£»ÒòÊÔ¾íÎĵµÐ¹Â¶£¬CRESTÔÝÍ£Ó¢¹úµÄInfosecÈÏÖ¤¿¼ÊÔ
°ä²¼¹¦·ò 2020-08-191.¹¥»÷»î¶¯Duriͨ¹ýHTMLºÍJavaScript·Ö·¢¶ñÒâÈí¼þ

ÐµĹ¥»÷»î¶¯DuriÀûÓÃHTML¼Ð´ø¼¼ÊõºÍJavaScript blob·Ö·¢¶ñÒâÈí¼þ£¬²¢ÌÓ±Üɱ¶¾Èí¼þµÄ¼ì²âºÍ·ÖÎö¡£DuriÀûÓÃHTML¼Ð´ø¼¼Êõ£¬ÔÚ¿Í»§¶Ë£¨ä¯ÀÀÆ÷£©É϶¯Ì¬µØÌìÉúÓÐЧ¸ºÔØ£¬¶ø²»ÊÇÖ¸Ïò·þÎñÆ÷µÄÖ±½ÓURL£¬Òò¶ø²»»á´«ÊäÈκÎÊý¾ÝÒÔÔ¤·À±»É³Ïä²é³¡£´Ë±í£¬×êÑÐÈËÔ±·ÖÎöÁ˸öñÒâÈí¼þÓÐЧ¸ºÔØÖеÄMSIÎļþ£¬·¢ÏÖÁËÒ»¸ö»ìºÏµÄJScript£¬ÒÔÌá¸ß¸Ã¶ñÒâÈí¼þµÄÒñ±ÎÐÔ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/duri-campaign-smuggles-malware-via-html-and-javascript/
2.CISAÖÒ¸æÐµĴ¹µö»î¶¯»á·Ö·¢¶ñÒâÈí¼þKONNI

ÍøÂ簲ȫºÍ»ù´¡½á¹¹°²È«¾Ö£¨CISA£©°ä²¼°²È«¾¯±¨£¬ÌṩÓйØKONNIÔ¶³Ì½Ó¼ûľÂíÐÂÒ»²¨¹¥»÷µÄ¼¼Êõϸ½Ú¡£CISA·¢ÏÖºÚ¿Íͨ³£ÒÔ´øÓжñÒâVBAºê´úÂëµÄMicrosoft WordÎĵµµÄ´ó¾Öͨ¹ý´¹µöÓʼþÀ´·Ö·¢KONNI¶ñÒâÈí¼þ¡£KONNIÊÇÒ»ÖÖÔ¶³ÌÖÎÀí¹¤¾ß£¨RAT£©£¬¸Ã¹¤¾ß¿É±»ÀûÓÃÇÔÈ¡Îļþ¡¢²¶»ñ»÷¼ü¡¢»ñÈ¡ÆÁÄ»¿ìÕÕÒÔ¼°ÔÚÊÜϰȾµÄÖ÷»úÉÏÖ´ÐÐËÁÒâ´úÂë¡£¸Ã¶ñÒâÈí¼þÖÁÉÙ´Ó2014Äê¾ÍÆðÍ·»îÔ¾£¬³¬¹ý3Äêδ±»·¢ÏÖ¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/alerts/aa20-227a
3.Àö×ȾƵê²ÍÒûԤԼϵͳÊý¾Ýй¶£¬Æä¿Í»§Ôâµ½Ú¿Æ

8ÔÂ15ÈÕÂ×¶ØÀö×ÈÁ¬Ëø¾Æµê°ä²¼Twitter°µÊ¾£¬¸Ã¹«Ë¾ÔÚ8ÔÂ12ÈÕ·¢ÏÖËûÃǵIJÍÒûԤԼϵͳÖдæÔÚÊý¾Ýй¶ÎÊÌ⣬Æä¿Í»§ÐÅÏ¢»òÒѱ»Ð¹Â¶²¢±»ÀûÓýøÐÐڿƻ¡£¸Ã¾Æµê°µÊ¾ÒѶԴËй¶ÊÂÎñ·¢Õ¹µ÷²é£¬Ã»ÓÐÈκÎÐÅÓþ¿¨¾ßÌåÐÅÏ¢»ò¸¶¿îÐÅϢй¶¡£¾ÝÓ¢¹ú¹ã²¥¹«Ë¾±¨Â·£¬ÒÑÓжàÆðÀûÓÃÕâЩй¶ÐÅÏ¢½øÐеÄڿƻ£¬Æ×Ó¼Ù×°ÊÇÀö×ȵĹÍÔ±¸ø²ÍÌüÔ¤Ô¼Õß´òµç»°£¬ÓëËûÃÇÈ·ÈÏÔ¤Ô¼µÄ¾ßÌåÐÅÏ¢£¬Í¬Ê±ÒªÇóËûÃÇÌṩÐÅÓþ¿¨Ï¸½Ú¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/ritz-london-struck-by-data-breach-fraudsters-pose-as-staff-in-credit-card-data-scam/
4.ÒòÊÔ¾íÎĵµÐ¹Â¶£¬CRESTÔÝÍ£Ó¢¹úµÄInfosecÈÏÖ¤¿¼ÊÔ

ÒòÊÔ¾íÎĵµÐ¹Â¶£¬CRESTÈ¡µÞÁËÁ½´ÎÓ¢¹úInfosecÈÏÖ¤¿¼ÊÔ¡£´Ëǰ¸Ã»ú¹¹Åû¶ÁËÒ»·Ý¹«¿ªµÄÎļþ£¬ÆäÖÐÔ̺¬ËƺõÊÇÄÚ²¿²é³±íµÄÎļþ£¬ÒÔ¼°Óë¹Ø¼üÐÐÒµ²Î¼ÓÕßNCC¼¯ÍÅÓйصÄÎĵµ¡£¾ÝÖªÁµÈËʿй©£¬CRESTÔÝÍ£ÁËËùÓеÄCCT INFºÍCCT APP¿¼ÊÔ³¤´ïÒ»¸öÔ£¬Í¬Ê±Éó²éÆäÄÚÈÝ¡£CRESTµÄ½²»°È˰µÊ¾£¬ÓÉÓÚÊý¾Ýй¶£¬ËûÃDZØÒªÈýµ½ÖÜΧµÄ¹¦·òÀ´³ÁбàдÊÔ¾í£¬ÔÚµ÷²é½øÐÐÆÚ¼ä²»»á°ä·¢ÈÎºÎÆÀÂÛ¡£
ÔÎÄÁ´½Ó£º
https://www.theregister.com/2020/08/17/crest_halts_infosec_exams/
5.ÓÊÂÖ¹«Ë¾CarnivalϰȾÀÕË÷Èí¼þ£¬²¿ÃÅÊý¾Ý»òÒÑй¶

È«Çò×î´óµÄÓÊÂÖ¹«Ë¾Carnival CorpÔÚ8ÔÂ15ÈÕÔâµ½ÁËÀÕË÷Èí¼þ¹¥»÷£¬²¿ÃÅÊý¾Ý»òÒÑй¶¡£¸Ã¹«Ë¾°µÊ¾£¬ºÚ¿Í½Ó¼û²¢¼ÓÃÜÁËÆä·Ö¹«Ë¾µÄÐÅÏ¢¼¼Êõϵͳ£¬²¢ÇÒÇÔÈ¡ÁËÎļþ¡£Æ¾¾Ý¶Ô¸ÃÊÂÎñµÄ³õ²½ÆÀ¹À£¬¼ÎÄ껪ÒÔΪ£¬¹¥»÷Õß¿ÉÄÜÒѾ½Ó¼ûÁËijЩÀ´±öºÍÔ±¹¤µÄÓ×ÎÒÊý¾Ý¡£µ«ÊÇCarnivalûÓÐй©ÓйشËÊÂÎñµÄ¾ßÌåÐÅÏ¢£¬ÀýÈçÀÕË÷Èí¼þÃû³Æ£¬»òÆä¹¥»÷Ó°ÏìÁìÓòµÈ¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/worlds-largest-cruise-line-operator-discloses-ransomware-attack/
6.RBS°ä²¼COVID-19¶ÔÊý¾Ýй¶µÄÓ°ÏìµÄ·ÖÎö»ã±¨

RBS°ä²¼COVID-19¶ÔÊý¾Ýй¶µÄÓ°ÏìµÄ·ÖÎö»ã±¨£¬¸Ã»ã±¨¾ßÌå̽ÇóÁËÓÉCOVID-19ÒýÆðµÄ¹©¸øÁ´Öж϶ÔÊý¾Ýй¶ÎÊÌâ¼°ÆäËûÇ÷ÏòµÄÓ°Ïì¡£¾Ý»ã±¨£¬2020Ä깫¿ª»ã±¨µÄÊý¾Ýй©ÊÂÎñµÄÊýÁ¿½µÂäÁË52£¥£¬µ«Ð¹Â¶µÄÊý¾ÝÁ¿È´±ÈÍùÆÚÓâÔ½Ëı¶ÒÔÉÏ¡£´Ë±í£¬ÃýÎóÅäÖõÄÊý¾Ý¿âºÍ·þÎñÒÀÈ»ÊÇÊý¾Ýй¶µÄÖØÒªÆðÔ´£¬2020ÄêµÚ¶þ¼¾¶È£¬½öÁ½¸ö·ì϶¾Íµ¼ÖÂÁË180ÒÚÌõÊý¾Ýй¶¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2020/08/18/publicly-reported-data-breaches-down-52-exposed-records-way-up/


¾©¹«Íø°²±¸11010802024551ºÅ