ÎÚ¿ËÀ¼Óë¶à¹úµ±¾Ö½áºÏµ·»ÙÀÕË÷Èí¼þClopµÄ»ù´¡ÉèÊ©£»×êÑÐÍŶÓÅû¶2G¼ÓÃܳ߶ÈËã·¨´æÔÚ¿ÉÇÔÌýÁ÷Á¿µÄ·ì϶

°ä²¼¹¦·ò 2021-06-18

1.ÎÚ¿ËÀ¼Óë¶à¹úµ±¾Ö½áºÏµ·»ÙÀÕË÷Èí¼þClopµÄ»ù´¡ÉèÊ©


1.jpg


ÎÚ¿ËÀ¼¾¯·½Óë¹ú¼ÊÐ̾¯×éÖ¯¡¢º«¹úºÍÃÀ¹úµ±¾Ö½áºÏ £¬ÔÚ±¾ÖÜÈý³É¹¦µ·»ÙÁËÀÕË÷Èí¼þClopµÄ»ù´¡ÉèÊ© ¡£ClopÀÕË÷Èí¼þÍÅ»ï×Ô2019ÄêÒÔÀ´ÆðÍ·»îÔ¾ £¬×ܼÆÔì³ÉÁËԼĪ5ÒÚÃÀÔªµÄËðʧ ¡£ÎÚ¿ËÀ¼µ±¾Ö³ÆÒѹعطַ¢¶ñÒâÈí¼þµÄ»ù´¡ÉèÊ©ºÍ»ñµÃ¼ÓÃÜÇ®±ÒµÄÇþ· £¬µ«Ä¿Ç°ClopÓÃÀ´¹«¿ª±»µÁÊý¾ÝµÄÍøÕ¾£¨CL0P^-LEAKS£©ÈÔÔÚÔËÐÐ ¡£°²È«¹«Ë¾Intel 471°µÊ¾ £¬ÎÚ¿ËÀ¼µ±¾ÖÖ»¿ÛÁôÁËΪClopÍÅ»ïÏ´Ç®µÄÈË £¬ÆäÖ÷Ìâ³ÉÔ±¿ÉÄÜסÔÚ¶íÂÞ˹ ¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/06/ukraine-police-arrest-cyber-criminals.html


2.¼ÎÄ껪ÓÊÂÖ¹«Ë¾³ÆÆäÔâµ½ÍøÂç¹¥»÷µ¼ÖÂÓ×ÎÒÐÅϢй¶


2.jpg


È«Çò×î´óµÄÓÎÂÖ¼ÎÄ껪£¨Carnival Corporation£©³ÆÆäÔâµ½¹¥»÷µ¼ÖÂÊý¾Ýй¶ ¡£¸Ã¹«Ë¾°µÊ¾ÆäÔÚ2021Äê3ÔÂ19ÈÕ¼ì²âµ½Î´¾­ÊÚȨµÄµÚÈý·½½Ó¼ûÁ˲¿Ãŵç×ÓÓʼþÕÊ»§ £¬Ð¹Â¶ÁËÔ±¹¤ºÍ¿ÍÈ˵ÄÓ×ÎÒÐÅÏ¢ £¬Ô̺¬ÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢»¤ÕÕºÅÂë¡¢µ®ÉúÈÕÆÚ¡¢½¡È«ÐÅÏ¢¡¢Éç»á°²È«ºÅÂë»òÉí·ÝÖ¤ºÅÂëµÈ ¡£¸Ã¹«Ë¾ÔÚÒ»·Ýµç×ÓÓʼþÉêÃ÷ÖаµÊ¾ £¬Æä¹É¼Û×ÅÂäÁ˳¬¹ý2% ¡£ÔçÔÚÈ¥ÄêµÄ8ÔºÍ12Ô £¬¸Ã¹«Ë¾»¹Ôâµ½ÁËÁ½´ÎÀÕË÷Èí¼þ¹¥»÷ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.oann.com/cruise-operator-carnival-discloses-breach-of-crew-guests-personal-data-bloomberg-news/


3.²¨À¼µ±¾Ö³ÆÆä¹«ÃñºÍ×éÖ¯»ú¹¹Ô⵽ǰËùδÓеÄÍøÂç¹¥»÷


3.jpg


²¨À¼µ±¾ÖÔÚ±¾Öܶþ³Æ £¬Æä¹«ÃñºÍ×éÖ¯»ú¹¹Ôâµ½ÁËǰËùδÓеÄÍøÂç¹¥»÷ ¡£ÉÏÖÜ £¬ºÚ¿ÍÈëÇÖÁË×ÜÀí°ì¹«ÊÒÕÆ¹ÜÈËMichal DworczykµÄ¸öÈËÓʼþÕÊ»§ £¬²¢½«ÓʼþÔÚTelegram¹«¿ª ¡£µ±¾Ö½²»°ÈËPiotr Muller°µÊ¾Õâ´Î¹¥»÷µÄÁìÓòºÜ¿í·º £¬²»½öÉæ¼°Dworczyk £¬»¹Éæ¼°µ±¾Ö³ÉÔ±¡¢PiSµ³ºÍÆä¹«Ãñ ¡£Ð¹Â¶ÎļþµÄÔªÊý¾ÝÏÔʾ £¬ÕâЩÎļþÊÇÓɽ²¶íÓïµÄÈ˱à×ëµÄ £¬µ«Õâ²»¼°ÒÔ½«Õâ´Î¹¥»÷¹é×ïÓÚ¶íÂÞ˹ºÚ¿Í ¡£Ä¿Ç° £¬²¨À¼µÄ´¦Ëùµ±¾ÖºÍ°²È«¾ÖÈÔÔÚµ÷²éÕâ´Î¹¥»÷ÊÂÎñ ¡£ 


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/119043/hacking/poland-hit-cyber-attacks.html


4.KasperskyÅû¶³¯ÏÊÍÅ»ïAndarielÕë¶Ôº«¹úµÄ¹¥»÷»î¶¯


4.jpg


KasperskyÅû¶Á˳¯ÏʺڿÍÍÅ»ïAndarielÕë¶Ôº«¹úµÄ¹¥»÷»î¶¯ ¡£×êÑÐÈËÔ±ÓÚ2021Äê4ÔÂÔÚVirusTotalÉÏ·¢ÏÖÁËÒ»¸ö¿ÉÒɵÄWordÎĵµ £¬·ÖÎö·¢ÏÖÕâ´Î¹¥»÷»î¶¯ÖÐʹÓõÄWindowsºÅÁîºÍÑ¡ÏîÓë֮ǰµÄAndariel»î¶¯ÏÕЩһÑù ¡£Andariel×÷ΪLazarusµÄ×Ó¼¯ÍÅ £¬×Ô2016Äê5ÔÂÒÔÀ´Ò»Ïò»îÔ¾ £¬Ö¼ÔÚÈëÇÖº«¹úºÍÊÀ½ç¸÷µØ½ðÈÚ»ú¹¹µÄÍÆËã»ú ¡£ÖµÍ×ÌùÐĵÄÊÇ £¬Õâ´Î¹¥»÷³ýÁË×°ÖúóÃűí £¬»¹×°ÖÃÁ˼ÓÃÜÀÕË÷Èí¼þ £¬ÖØÒªÕë¶ÔÔì×÷Òµ¡¢Ã½ÌåºÍ¹¹ÖþÒµµÈÐÐÒµ ¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/andariel-evolves-to-target-south-korea-with-ransomware/102811/    


5.×êÑÐÍŶÓÅû¶2G¼ÓÃܳ߶ÈËã·¨´æÔÚ¿ÉÇÔÌýÁ÷Á¿µÄ·ì϶


5.jpg


ÔÚÖÜÈý°ä·¢µÄһƪÂÛÎÄÖÐ £¬À´×Ե¹ú¡¢·¨¹úºÍŲÍþµÄ×êÑÐÈËÔ±Åû¶ÁË2G£¨GPRS£©Òƶ¯Êý¾Ý¼ÓÃܳ߶ÈÖеķì϶ ¡£¸Ã·ì϶´æÔÚÓÚ¼ÓÃÜËã·¨GEA-1ÖÐ £¬Õâ¿ÉÄÜʹ¹¥»÷Õß¿ÉÄÜÇÔÌýһЩÊý¾ÝÁ÷Á¿³¤´ï20¶àÄê ¡£GEA-1Ëã·¨±¾Ó¦ÔÚ2013Äê²Ã¼õ £¬µ«Ôڴ˿̵ÄAndroidºÍiOSÖÇÄÜÊÖ»úÖÐÈÔÄÜ·¢ÏÖËü ¡£¹ÌÈ»´óÎÞÊýÊÖ»ú¶¼Ê¹ÓÃ4GÉõÖÁ5G £¬µ«ÔÚijЩ¹ú¶È/µØÓò £¬GPRSÒÀÈ»ÊÇÊý¾ÝÏνӵĺó±¸Ñ¡Ôñ ¡£Ä¿Ç° £¬×êÑÐÈËÔ±ÒÑ֪ͨÊÖ»úÔì×÷É̺ͳ߶È×éÖ¯½¨¸´¸Ã·ì϶ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/security-flaw-found-2g-mobile-data-encryption-standard


6.Enable SecurityÅû¶VoIP GUIÖеĿçÕ¾¾ç±¾·ì϶


6.jpg


Enable SecurityÅû¶ÁËVoIP GUIÖеĿçÕ¾¾ç±¾·ì϶ ¡£¸Ã·ì϶´æÔÚÓÚÖÎÀíVoIPºô½ÐµÄ»á»°ÌáÒéºÍ̸ (Session Initiation Protocol £¬SIP)ÖÐ £¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚδ¾­Éí·ÝÑéÖ¤µÄÇé¿öÏÂÔÚÖ¸±êϵͳÉÏÖ´ÐдúÂë ¡£×êÑÐÈËÔ±ÔÚÉóºËVoIPmonitor GUIʱ·¢ÏÖÁ˸÷ì϶ £¬³ÆÄܹ»Í¨¹ý·¢ËͶñÒâSIPÐÂÎÅÀ´ÆëÈ«½ÚÔìϵͳ ¡£Enable SecurityÓÚ2021Äê2ÔÂÁªÏµÁËVoIPmonitorµÄ¿ª·¢ÈËÔ± £¬¸Ã·ì϶ÏÖÒѽ¨¸´ ¡£


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2021/06/16/xss-vulnerability-in-sip-protocol-risks-rce-attacks-on-voip-software/