Devolutions°ä²¼2021ÄêÖÐÓ×ÐÍÆóÒµ°²È«Ì¬ÊƵĻ㱨

°ä²¼¹¦·ò 2021-11-24

RedCurlÍÅ»ï»Ø¹é  £¬ÐµĹ¥»÷Ö¸±êÉæ¼°¸÷Ðи÷Òµ


RedCurlÍÅ»ï»Ø¹é£¬ÐµĹ¥»÷Ö¸±êÉæ¼°¸÷Ðи÷Òµ.png


Group-IBÔÚ11ÔÂ18ÈÕÅû¶Á˺ڿÍÍÅ»ïRedCurlµÄл¡£ÍøÂç¼äµýºÚ¿Í×éÖ¯RedCurlÔÚ2018ÄêÖÁ2020ÄêÆÚ¼ä  £¬ÌáÒéÁËÖÁÉÙ26´Î¹¥»÷  £¬Éæ¼°Ó¢¹ú¡¢µÂ¹ú¡¢¼ÓÄôó¡¢Å²Íþ¡¢¶íÂÞ˹ºÍÎÚ¿ËÀ¼µÈµØÓòµÄ¹¹Öþ¡¢½ðÈÚ¡¢Õ÷ѯ¡¢ÁãÊÛ¡¢±£ÏÕºÍ˾·¨ÐÐÒµµÄ¹«Ë¾¡£¸ÃÍÅ»ïÔÚÖжÏ7¸öÔºó¾íÍÁ³ÁÀ´  £¬×Ô2021ËêÊ×ÒÔÀ´Õë¶Ô4¼Ò¹«Ë¾ÌáÒéÁËÐµĹ¥»÷  £¬ÆäÖÐÔ̺¬¶íÂÞ˹×î´óµÄÅú·¢É̵ê¡£Group-IB³Æ  £¬RedCurlÔÚÿ´Î¹¥»÷ÖгÇÊÐʹÓÃÆä×Ô½ç˵¶ñÒâÈí¼þÈÆ¹ý¼ì²â¡£


Ô­ÎÄÁ´½Ó£º

https://www.group-ib.com/media/red-curl-threat-report/


×êÑÐÈËÔ±ÑÝʾеÄSAD DNS»º´æÖж¾¹¥»÷ģʽ


×êÑÐÈËÔ±ÑÝʾеÄSAD DNS»º´æÖж¾¹¥»÷ģʽ.png


¼ÓÖÝ´óѧ×êÑÐÈËÔ±ÔÚ11ÔÂ18ÈÕÑÝʾÁËÒ»ÖÖеÄSAD DNS»º´æÖж¾¹¥»÷ģʽ¡£SAD DNS£¨Side channel AttackeD DNS£©ÓÚ2020Äê11Ô³õ´ÎÅû¶  £¬ËüÒÀÀµICMPµÄ¡°port unreachable¡±ÐÂÎÅÀ´´§¶ÈʹÓÃÄĸöһʱ¶Ë¿Ú¡£ÀûÓô˹¥»÷ģʽ¿É½«¶ñÒâµÄDNS¼Í¼עÈëDNS»º´æ  £¬¶øºó½«Ö¸±êÁ÷Á¿³Á¶¨Ïòµ½¹¥»÷ÕߵķþÎñÆ÷ÖÐ  £¬½øÐÐÖÐÑëÈË(MITM)¹¥»÷¡£×êÑÐÈËÔ±³Æ  £¬´ËÖÖ¹¥»÷´æÔÚÓÚLinuxÉÏÔËÐеÄBIND¡¢UnboundºÍdnsmasqµÈDNSÈí¼þÖÐ  £¬Ó°ÏìÔ¼38%µÄÓòÃû½âÎöÆ÷¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/11/new-side-channel-attacks-re-enable.html


ÃÀ¹ú֤ȯÂòÂôίԱ»á·¢ÏÖ¼ÙÒâÆäÔ±¹¤µÄ´¹µö»î¶¯


ÃÀ¹ú֤ȯÂòÂôίԱ»á·¢ÏÖ¼ÙÒâÆäÔ±¹¤µÄ´¹µö»î¶¯.png


ÃÀ¹ú֤ȯÂòÂôίԱ»á(SEC)Ͷ×ÊÕß½ÌÓýºÍÐû´«°ì¹«ÊÒ(OIEA)ÓÚ11ÔÂ19ÈÕ°ä²¼¾¯±¨  £¬³Æ·¢ÏÖ¼ÙÒâSECÔ±¹¤µÄ»î¶¯¡£¹¥»÷Õßͨ¹ýµç»°¡¢ÓïÒôÓʼþ¡¢µç×ÓÓʼþºÍº¯¼þ  £¬ÖÒ¸æÊÕ¼þÈËÆä»îÆÚ´æ¿î»ò¼ÓÃÜÇ®±ÒµÄÕË»§ÖдæÔÚδ¾­ÊÚȨµÄÂòÂô»òÆäËû¿ÉÒɻ  £¬²¢Ë÷ÒªÆä¹ÉȨ¡¢Õʺš¢PINÂë¡¢ÃÜÂëµÈÐÅÏ¢¡£OIEA½¨ÒéÓû§ÔÚ·¢ËÍÓ×ÎÒÐÅϢ֮ǰ  £¬Ó¦ÏÈͨ¹ýÓʼþ»òÖµçSECÈ·¶¨·¢¼þÈ˵ÄÉí·Ý¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-sec-warns-investors-of-ongoing-govt-impersonation-attacks/


ÓÌËûÖÝÒ½ÁÆÖÐÐÄUIA½ü60Íò»¼ÕßµÄÓ×ÎÒÐÅϢй¶


ÓÌËûÖÝÒ½ÁÆÖÐÐÄUIA½ü60Íò»¼ÕßµÄÓ×ÎÒÐÅϢй¶.png


11ÔÂ18ÈÕ  £¬ÃÀ¹úÓÌËûÖÝ·ÅÉäÖÐÐÄUtah Imaging Associates(UIA)È·ÈÏ582170»¼ÕßµÄÓ×ÎÒÐÅϢй¶¡£Ð¹Â¶ÊÂÎñ²úÉúÔÚ8ÔÂ29ÈÕ  £¬Êý¾ÝÔÚ¶³öÔ¼Ò»Öܺó  £¬ÓÚ9ÔÂ4ÈÕ±»·¢ÏÖ²¢ÓÚͬÈÕ½¨¸´¡£Õâ´Îй¶ÁË»¼ÕßµÄÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢Éç»á°²È«ºÅÂë¡¢½¡È«±£ÏÕµ¥ºÅºÍÒ½ÁÆÐÅÏ¢µÈ¡£×êÑÐÈËÔ±°µÊ¾  £¬¹¥»÷Õ߯«²îÓÚ¹¥»÷ÏñUIAÕâÑùµÄÒ½ÁÆÖÐÐÄ  £¬ÊÇÓÉÓÚËûÃÇÒÔΪ´ËÀàÊý¾ÝÔÚ°µÍøÖеļÛÖµ¸ü¸ß¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/utah-medical-center-hit-by-data-breach-affecting-582k-patients/


Prodaft°ä²¼¹ØÓÚÀÕË÷ÔËÓªÍÅ»ïContiµÄ·ÖÎö»ã±¨


Prodaft°ä²¼¹ØÓÚÀÕË÷ÔËÓªÍÅ»ïContiµÄ·ÖÎö»ã±¨.png


ProdaftÓÚ11ÔÂ18ÈÕ°ä²¼Á˹ØÓÚÀÕË÷ÔËÓªÍÅ»ïContiµÄÉî¶È·ÖÎö»ã±¨¡£ContiÊÇ˽ÓÐRaaS  £¬ÓÚ2019Äê12Ôµ׳õ´Î³öÏÖ  £¬²¢Í¨¹ýTrickBot½øÐд«²¼¡£»ã±¨Ö¸³ö  £¬×Ô2021Äê7ÔÂÒÔÀ´  £¬Conti´ÓÊê½ðÖлñÀûÖÁÉÙ2550ÍòÃÀÔª  £¬¶øContiÍÅ»ïÔòÐû³ÆÒÑ»ñÀû3ÒÚÃÀÔª¡£´Ë±í  £¬Prodaft»¹¹«¿ªÁËContiµÄÖ§¸¶ÍøÕ¾  £¬Æä·þÎñÆ÷ÍйÜÔÚ217.12.204.135ÉÏ  £¬¸ÃIPµØÖ·ÊôÓÚÎÚ¿ËÀ¼ÍøITL LLC¡£Ôڸû㱨°ä²¼¼¸Ó×ʱºó  £¬ContiÍÅ»ï¾Í½«ÆäÖ§¸¶ÍøÕ¾¹Ø¹Ø¡£


Ô­ÎÄÁ´½Ó£º

https://www.prodaft.com/resource/detail/conti-ransomware-group-depth-analysis


Devolutions°ä²¼2021ÄêÖÐÓ×ÐÍÆóÒµ°²È«Ì¬ÊƵĻ㱨


Devolutions°ä²¼2021ÄêÖÐÓ×ÐÍÆóÒµ°²È«Ì¬ÊƵĻ㱨.png


DevolutionsÔÚ11ÔÂ17ÈÕ°ä²¼ÁË2021ÄêÖÐÓ×ÐÍÆóÒµ°²È«Ì¬ÊƵÄ×êÑл㱨¡£¸Ã×êÑоÍÎå¸öÖ÷ÌâÖ÷Ì⣺ÖÐÓׯóÒµµÄÍøÂç¹¥»÷ºÍÍþв¡¢ÃÜÂëÖÎÀí¡¢Ê¹ÓõÄÌØÈ¨½Ó¼ûÖÎÀí¡¢°²È«ÅàѵºÍÖÎÀíÒÔ¼°°²È«Í¶×ʽøÐÐÁË·ÖÎö¡£»ã±¨Ö¸³ö  £¬ÓëÈ¥ÄêÏà±È  £¬72%µÄÖÐÓׯóҵĿǰԽ·¢¹ØÇÐÍøÂ簲ȫ£»ÖÎÀíÕß×î²»°²µÄÍøÂçÍþвÊÇÀÕË÷Èí¼þ¡¢ÍøÂç´¹µöºÍ¶ñÒâÈí¼þ£»52%µÄÆóÒµÔÚÈ¥ÄêÔâµ½¹ýÍøÂç¹¥»÷£»Ö»ÓÐ13%µÄÆóÒµÕ¼ÓÐÆëÈ«µÄPAM½â¾ö¹æ»®¡£


Ô­ÎÄÁ´½Ó£º

https://blog.devolutions.net/2021/11/new-now-available-devolutions-state-of-cybersecurity-in-smbs-in-2021-2022-report