¿¨°Í˹»ù°ä²¼Linux°æ±¾RansomExxµÄ·ÖÎö»ã±¨£»ÐÂOffice 365´¹µö»î¶¯¿ÉÈÆ¹ýɱ¶¾Èí¼þµÄ¼ì²â

°ä²¼¹¦·ò 2020-11-09
1.¿¨°Í˹»ù°ä²¼Linux°æ±¾RansomExxµÄ·ÖÎö»ã±¨


1.jpg


¿¨°Í˹»ù°ä²¼Ò»·Ýл㱨½éÉÜÁËLinux°æ±¾µÄRansomExxÀÕË÷Èí¼þ£¬Ò²³ÆÎªDefray777¡£»ã±¨³Æ£¬RansomExxÔÚÕë¶ÔLinux·þÎñÆ÷ʱ£¬»áÏȲ¿ÊðÒ»¸öÃûΪsvc-newµÄELF¿ÉÖ´ÐÐÎļþ£¬ÓÃÓÚ¼ÓÃÜÊܺ¦ÕߵķþÎñÆ÷¡£´Ë±í£¬ÓëWindows°æ±¾·ÖÆç£¬Defray777²»Ô̺¬ÈκÎÓÃÓÚÖÕÖ¹¹ý³ÌµÄ´úÂ루ÀýÈ簲ȫÈí¼þ£©£¬²»»áÏñWindows°æ±¾ÄÇÑù²Á³ý¿ÉÓÿռ䣬Ҳ²»ÄÜÓëºÅÁîºÍ½ÚÔì·þÎñÆ÷ͨѶ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ransomexx-ransomware-also-encrypts-linux-systems/


2.McAfee°ä²¼2020ÄêQ2ÍøÂç·¸×ï»î¶¯µÄ·ÖÎö»ã±¨


2.jpg


Âõ¿Ë·Æ£¨McAfee£©°ä²¼»ã±¨£¬·ÖÎöÁËÓë¶ñÒâÈí¼þÓйصÄÍøÂç·¸×ï»î¶¯ÒÔ¼°2020ÄêµÚ¶þ¼¾¶ÈµÄÍøÂçÍþв¡£·ÖÎö·¢ÏÖ£¬ÔÚ´ËÆÚ¼äжñÒâÈí¼þÑù±¾×ÜÊýÔö³¤ÁË11.5£¥£¬Ã¿·ÖÖÓ¾ùÔÈÓÐ419¸öÐÂÍþв£¬±ÈÉÏÒ»¼¾¶ÈÔö³¤½ü12£¥¡£´Ë±í£¬»ã±¨ÏÔʾÓëÉÏÒ»¼¾¶ÈÏà±È£¬PowerShell¶ñÒâÈí¼þÔö³¤ÁË117£¥£¬ÐÂMicrosoft Office¶ñÒâÈí¼þµÄÔö³¤103£¥£¬ÍÚ¿ó¶ñÒâÈí¼þ±ÈÔö³¤ÁË25£¥£¬ÎïÁªÍø¶ñÒâÈí¼þÔö³¤ÁË7£¥£¬¶øÒƶ¯¶ñÒâÈí¼þÑù±¾½µÂäÁË15£¥£¬Óнü750Íò´Î¶ÔÔÆÓû§ÕÊ»§µÄ¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2020/11/06/q2-2020-threats/


3.LuxotticaÔâµ½¹¥»÷ÖÂÓû§Ó×ÎÒÊý¾ÝºÍ½¡È«ÐÅϢй¶


3.jpg


È«Çò×î´óµÄÑÛ¾µ¹«Ë¾LuxotticaÔâµ½¹¥»÷ÖÂÓû§Ó×ÎÒÊý¾ÝºÍ½¡È«ÐÅϢй¶¡£Luxottica³ÆÆäÔ¤Ô¼ÀûÓÃÔÚ2020Äê8ÔÂ5ÈÕÔâµ½ºÚ¿Í¹¥»÷ºóµ¼ÖÂÊý¾Ýй¶£¬²¢ÓÚ8ÔÂ28ÈÕÈ·¶¨¹¥»÷ÕßÄܹ»½Ó¼û»¼ÕßµÄÓ×ÎÒÐÅÏ¢¡£Õâ´Îй¶ÁËÓû§Ó×ÎÒÊý¾Ý£¨PII£©ºÍÊܱ£»¤µÄ½¡È«ÐÅÏ¢£¨PHI£©£¬Ô̺¬¿Í»§ÐÕÃû¡¢ÁªÏµÐÅÏ¢¡¢Ô¤Ô¼ÈÕÆÚºÍ¹¦·ò¡¢½¡È«±£ÏÕ±£µ¥ºÅ¡¢Ò½Öδ¦·½¡¢Ò½ÁÆÇé¿öºÍ²¡Ê·µÈ£¬»¹Óв¿ÃÅÓû§µÄÐÅÓþ¿¨ºÅºÍÉç»á±£Ïպš£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/luxottica-data-breach-exposes-lenscrafters-eyemed-patient-info/


4.ÐÂOffice 365´¹µö»î¶¯¿ÉÈÆ¹ýɱ¶¾Èí¼þµÄ¼ì²â


4.jpg


MC GlobalµÄ×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸öеÄOffice 365ÍøÂç´¹µö»î¶¯£¬Í¨¹ý»Ø×ªµÇ¼ҳ²¼¾°Í¼À´Èƹýɱ¶¾Èí¼þµÄ¼ì²â¡£WMC Global°µÊ¾£¬ÓÉÓÚͼÏñ¼ø±ðÈí¼þµÄÕýÈ·ÂÊÔ½À´Ô½¸ß£¬ºÚ¿ÍÍÅ»ïͨ¹ýµßµ¹Í¼ÏñµÄÉ«²ÊÀ´ºýŪɨÃèÒýÇæ£¬µ¼ÖÂͼÏñ¹þÏ£ÓëԭʼͼÏñ·ÖÆç£¬ÒÔ´ËÈÆ¹ýɱ¶¾Èí¼þµÄ¼ì²â¡£´Ë±í£¬¸Ã»î¶¯»¹Ê¹Óü¶ÁªÐÎ×´±í£¨CSS£©×Ô¶¯»¹Ô­²¼¾°£¬ÒÔʹÆä¿´ÆðÀ´ÏñºÏ·¨Office 365µÇÂ¼Ò³ÃæµÄ²¼¾°¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/110554/cyber-crime/office-365-phishing-inverts-images.html


5.»ÝÆÕ³Æ2020ÄêQ3 EmotetľÂíµÄ¹¥»÷¼¤Ôö1200£¥


5.jpg


»ÝÆÕ³ÆÏà½ÏÓÚ2020ÄêQ2£¬Q3ʹÓÃEmotetľÂíµÄ¹¥»÷¼¤Ôö1200£¥ÒÔÉÏ¡£Emotetʱʱ±»ÓÃ×÷¼ÓÔØÆ÷£¬ÎªºÚ¿Í×éÖ¯Ìṩ½Ó¼ûȨÏÞ£¬ÒÔ²¿ÊðTrickBotºÍQakBotºÍ×°ÖÃÀÕË÷Èí¼þ¡£Æ¾¾Ý¶Ô¶ñÒâÈí¼þ·¢Ë͵½µÄ¶¥¼¶ÓòÃûµÄ·ÖÎö£¬ÈÕ±¾ºÍ°Ä´óÀûÑÇÊܵ½µÄÓ°ÏìÓÈÆäÑϳÁ£¬±ðÀëÕ¼½Ó¹ÜÓû§µÄ32%ºÍ20%¡£¹¥»÷Õßͨ³£Í¨¹ýÏ߳̽ٳÖÀ´ÈëÇÖ²¢¼à¿ØÓû§µÄÊÕ¼þÏ䣬ʹEmotet¿É»Ø¸´´øÓжñÒ⸽¼þ»òÁ´½ÓµÄºÏ·¨µç×ÓÓʼþ¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/ransomware-alert-as-emotet/


6.CybleÔÚ°µÍø·¢ÏÖ2000ÍòBigbasketÓû§µÄ¾ßÌåÐÅÏ¢


6.jpg


ÍøÂçµý±¨¹«Ë¾CybleÔÚ°µÍø·¢ÏÖ2000ÍòÓ¡¶ÈÔÚÏßÉ̵êBigbasketÓû§µÄ¾ßÌåÐÅÏ¢¡£¸ÃÎļþ´óÓ×Ϊ15 GB£¬Ô̺¬2000ÍòÌõÓû§¼Í¼£¬ÒÔ³¬¹ý40000ÃÀÔªµÄ¼ÛÖµÔÚ°µÍøÉÏÏúÊÛ¡£¸ÃÊý¾Ý¿âÔ̺¬Óû§Ãû³Æ¡¢µç×ÓÓʼþID¡¢ÃÜÂë¹þÏ££¨¿ÉÄÜÊÇÉ¢ÁеÄOTP£©¡¢ÁªÏµ·½Ê½£¨ÊÖ»ú+µç»°£©¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢µØÎ»ºÍµÇ¼IPµØÖ·µÈ¡£Ð¹Â¶¿ÉÄܲúÉúÔÚ2020Äê10ÔÂ14ÈÕ£¬Ä¿Ç°¸Ã¹«Ë¾Òѽ«´ËÊÂÉϱ¨¸ø±¾µØ¾¯·½£¬²¢ÒÑ·¢Õ¹µ÷²é¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/110543/data-breach/bigbasket-details-dark-web.html