×êÑÐÍŶӳƽüÆÚÀÕË÷Èí¼þ¹¥»÷³ÖÐø¼¤Ôö£¬Í¬±ÈÔö³¤93%£»×êÑÐÈËÔ±Åû¶´Û¸Ä¿ÉÖ´ÐоµÏñµÄ¹¥»÷Process Ghosting
°ä²¼¹¦·ò 2021-06-221.×êÑÐÍŶӳƽüÆÚÀÕË÷Èí¼þ¹¥»÷³ÖÐø¼¤Ôö£¬Í¬±ÈÔö³¤93%

Check Point Research×êÑÐÍŶӳƽüÆÚÀÕË÷Èí¼þ¹¥»÷³ÖÐø¼¤Ôö¡£2021Äê6ÔÂÿÖÜÊÜÀÕË÷Èí¼þÓ°ÏìµÄ×éÖ¯ÊýÁ¿ÒÑÔöÖÁ1210¸ö£¬×ÔËêÊ×ÒÔÀ´£¬ÀÕË÷Èí¼þ¹¥»÷´ÎÊýÔö³¤ÁË41%£¬Í¬±ÈÔö³¤ÁË93%¡£ÆäÖÐÀ¶¡ÃÀÖÞµÄÀÕË÷Èí¼þ¹¥»÷³¢ÊÔÔö³¤×îΪÏÔ×Å£¬Ôö³¤ÁË62%£¬Æä´ÎÊÇÅ·ÖÞÔö³¤ÁË59%£¬·ÇÖÞÔö³¤ÁË34%£¬±±ÃÀÔö³¤ÁË32%¡£´Ë±í£¬Õë¶Ô½ÌÓýÐÐÒµµÄ¹¥»÷Ôö³¤¿ìÂÊ×î¿ì£¨ÓëÈ¥ÄêͬÆÚÏà±ÈÔö³¤ÁË347%£©£¬Æä´ÎΪÔËÊäÐÐÒµ£¨186%£©¡¢ÁãÊÛºÍÅú¿¯ÐÐÒµ£¨162%£©ÒÔ¼°Ò½ÁƱ£½¡ÐÐÒµ£¨159%£©¡£
ÔÎÄÁ´½Ó£º
https://blog.checkpoint.com/2021/06/14/ransomware-attacks-continue-to-surge-hitting-a-93-increase-year-over-year/
2.ŲÍþ¾¯·½È·ÈÏÆäÔÚ2018ÄêÔâµ½µÄºÚ¿Í¹¥»÷ÓëAPT31ÓйØ

ŲÍþ¾¯Ô±°²È«¾Ö (PST) °µÊ¾£¬ÆäÔÚ2018ÄêÔâµ½µÄÍøÂç¹¥»÷ÓëºÚ¿Í×éÖ¯APT31Óйء£¾Ýµ÷²éÏÔʾ£¬ÔÚÕâ´Î¹¥»÷ÖкڿÍÒѳɹ¦»ñµÃÖÎÀíԱȨÏÞ£¬Äܹ»½Ó¼û¸Ã¹úËùÓйú¶ÈÐÐÕþ°ì¹«ÊÒʹÓõÄÖÐÑëÍÆËã»úϵͳ£¬»¹³É¹¦µØ´Ó°ì¹«ÊÒϵͳÇÔÈ¡ÁËһЩÊý¾Ý¡£´Ë±í£¬×êÑÐÈËÔ±³Æ£¬APT31»¹±»ÒÔΪÊÇ2020Äê12ÔÂÕë¶Ô·ÒÀ¼Òé»áµÄÍøÂç¹¥»÷µÄÄ»ºóºÚÊÖ£¬ÔÚÕâ´Î¹¥»÷Öкڿͳɹ¦ÈëÇÖÁËһЩÒé»áÓйصç×ÓÓʼþµÄÕÊ»§¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/119161/apt/norway-blames-china-apt31.html
3.ÈÕ±¾Sports Club NASºÍIto Yogyo³ÆÔâµ½ÀÕË÷¹¥»÷

½üÆÚ£¬Á½¼ÒÈÕ±¾¹«Ë¾Sports Club NASºÍIto Yogyo¾ùÐû³ÆÔâµ½ÀÕË÷¹¥»÷¡£ÆäÖУ¬½¡Éí¾ãÀÖ²¿NAS°µÊ¾¹¥»÷²úÉúÔÚ4ÔÂ2ÈÕ£¬Ð¹Â¶ÁËÔ¼15Íò»áÔ±ºÍÔ±¹¤µÄÓ×ÎÒÐÅÏ¢£¬Ô̺¬ÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢ÐԱ𡢵绰ºÅÂë¡¢»áÔ±ºÅÂë¡¢µç×ÓÓʼþµØÖ·¡¢´¹Î£ÁªÏµ·½Ê½¡¢ÐÅÓþ¿¨ÐÅÏ¢ºÍÕË»§ÐÅÏ¢µÈ¡£»ìÄýÍÁÔì×÷ÉÌIto Yogyo°µÊ¾¹¥»÷²úÉúÔÚ6ÔÂ10ÈÕÁ賿£¬¸Ã¹«Ë¾ÔÚ·¢ÏÖ¹¥»÷ºóÂíÉϹعØÁË¿ÉÄÜÊܵ½Ó°ÏìµÄ·þÎñÆ÷ºÍµçÄÔ£¬Ä¿Ç°ÊÂÎñÈÔÔÚµ÷²éÖУ¬ÉÐδȷ¶¨ÊÇ·ñ´æÔÚÊý¾Ýй¶µÄÇé¿ö¡£
ÔÎÄÁ´½Ó£º
https://www.databreaches.net/jp-sports-club-nas-and-concrete-manufacturer-ito-yogyo-both-report-ransomware-incidents/
4.NVIDIA°²È«¸üУ¬½¨¸´ÆäJetsonоƬϵÁÐÖеÄ9¸ö·ì϶

NVIDIA°ä²¼°²È«¸üУ¬½¨¸´ÁËNVIDIA Jetson AGX XavierϵÁÓ×¢Jetson Xavier NX¡¢Jetson TX1¡¢Jetson TX2ϵÁкÍJetson NanoÖеÄ9¸ö·ì϶¡£Õâ´Î½¨¸´µÄ×îΪÑϳÁµÄ·ì϶ÊÇJetson¿ò¼ÜÖеĻº³åÇøÒç¶Âí½Å£¨CVE?2021?34372£©£¬´æÔÚÓÚNVIDIA OTEºÍ̸ÐÂÎŽâÎö´úÂëÖУ¬¿ÉÄܵ¼ÖÂÐÅϢй¶¡¢È¨ÏÞÌáÉýºÍ»Ø¾ø·þÎñ(DoS)¡£Æä´ÎΪNVIDIA TLKÖеĶÑÒç¶Âí½Å£¨CVE?2021?34373£©ºÍ¶à¸ö¿É´¥·¢DoS¹¥»÷µÄ·ì϶£¨CVE-2021-34379ºÍCVE-2021-34380£©µÈ¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/nvidia-jetson-chipset-dos-data-theft/167093/
5.×êÑÐÈËÔ±Åû¶´Û¸Ä¿ÉÖ´ÐоµÏñµÄ¹¥»÷Process Ghosting

×êÑÐÈËÔ±Åû¶Á˴۸ĿÉÖ´ÐоµÏñµÄ¹¥»÷·½Ê½Process Ghosting£¬¿ÉÈÆ¹ýWindowsϵͳÉϵı£»¤´ëʩִÐжñÒâ´úÂë¡£ElasticµÄ×êÑÐÈËÔ±³Æ£¬Í¨¹ýÕâÖÖ·½Ê½£¬¹¥»÷ÕßÄܹ»ÒÔÒ»ÖÖÄÑÒÔɨÃè»òɾ³ýµÄ·½Ê½½«¶ñÒâÈí¼þдÈë´ÅÅÌ£¬¶øºóÏñÖ´ÐÐͨ³£ÎļþÒ»ÑùÖ´ÐÐÒѱ»É¾³ýµÄ¶ñÒâÈí¼þ£¬ÕâÖÖ¼¼Êõ²»Éæ¼°´úÂë×¢Èë¡¢¹ý³Ì¿Õ»¯»òÊÂÎñÐÔNTFS(TxF)¡£´Ë±í£¬Process GhostingÀ©´óÁËÒÔǰËù¼Í¼µÄÖÕ¶ËÈÆ¹ý²½Ö裬´Ó¶øÄܹ»Èƹýɱ¶¾Èí¼þµÄ·ÀÓùºÍ¼ì²âÀ´Òñ±ÎµØÖ´ÐжñÒâ´úÂë¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/06/researchers-uncover-process-ghosting.html
6.Nuspire°ä²¼2021ÄêµÚÒ»¼¾¶ÈµÄÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨

Nuspire°ä²¼ÁË2021ÄêµÚÒ»¼¾¶ÈµÄÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¸Ã»ã±¨·ÖÎöÁËÆä900ÒÚÌõÈÕÖ¾£¬¸ÅÊöÁËеÄÍøÂç·¸×ï»î¶¯ºÍÕ½Êõ¡¢¼¼ÊõºÍ·¨Ê½ (TTP)¡£»ã±¨Ö¸³ö£¬ÔÚ2021ÄêQ1£¬Õë¶ÔFortinetµÄSSL-VPNµÄ¹¥»÷Ôö³¤ÁË1916%£¬Õë¶ÔPulse Connect Secure VPNµÄ¹¥»÷Ôö³¤ÁË1527%¡£ÓÉÓÚVPNºÍRDP·ì϶ÏÔ×ÅÔö³¤£¬¶ñÒâÈí¼þ¡¢½©Ê¬ÍøÂçºÍ·ì϶ÀûÓûÓë2020ÄêQ4Ïà±Å×ÐËù½µÂä¡£´Ë±í£¬½©Ê¬ÍøÂçZeroAccessµÄ»î¶¯ÔÚÒ»¸öÐÇÆÚÄÚ¼¤ÔöÁË619460%£¬¶øºóÔÚ±¾¼¾¶ÈÄ©»ØÂä¡£
ÔÎÄÁ´½Ó£º
https://www.nuspire.com/resources/q1-2021-threat-report


¾©¹«Íø°²±¸11010802024551ºÅ