ÓÎÏ·¹«Ë¾Ubisoft³ÆÅäÖÃÃýÎóÎèÁ¦È«¿ªÍæ¼ÒµÄÊý¾Ýй¶
°ä²¼¹¦·ò 2021-12-24ÓÎÏ·¹«Ë¾Ubisoft³ÆÅäÖÃÃýÎóÎèÁ¦È«¿ªÍæ¼ÒµÄÊý¾Ýй¶

·¨¹úÓÎÏ·¹«Ë¾Óý±Ì£¨Ubisoft£©ÔÚ12ÔÂ21ÈÕ°ä²¼²¼¸æ³Æ£¬ÎèÁ¦È«¿ªÍæ¼ÒµÄÊý¾ÝÒѾй¶¡£Õâ´ÎÊÂÎñÊÇÓÉÓÚÅäÖÃÃýÎóµ¼Öµģ¬ÎÊÌâÔÚ·¢ÏÖºóµ±¼´µÃµ½½¨¸´¡£µ«ÔÚ´Ë֮ǰ£¬Î´¾ÊÚȨµÄÓ×ÎÒ¿ÉÄÜÒѾ½Ó¼û²¢¸´Ô첿ÃÅÍæ¼ÒÊý¾Ý¡£¸Ã¹«Ë¾°µÊ¾£¬½ö¡°¼¼Êõ±êʶ·û¡±Êܵ½Ó°Ï죬Ô̺¬Íæ¼Ò±êÇ©¡¢Ó×ÎÒ×ÊÁÏIDºÍÉ豸ID£¬ÒÔ¼°Â¼ÔìºÍÉÏ´«µÄÊÓÆµµÈ£¬UbisoftµÄÈκÎÕÊ»§¾ùδÊܵ½Ó°Ïì¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/125885/data-breach/ubisoft-data-breach.html
CiscoÅû¼ûÀ¹úGarettµÄ½ðÊô̽²âÆ÷ÖÐ9¸ö·ì϶µÄϸ½Ú

12ÔÂ20ÈÕ£¬Cisco TalosÅû¶Garett²½ÐÐͨ¹ýʽ½ðÊô̽²âÆ÷ÖÐ9¸ö·ì϶µÄϸ½Ú¡£GarrettÊÇÃÀ¹ú³ÛÃûµÄ½ðÊô̽²âÆ÷Ôì×÷ÉÌ£¬Æä²úƷͨ³£²¿ÊðÔÚ³ÁÒª³¡ËùÖУ¬ÀýÈçÔ˶¯³¡¹Ý¡¢»ú³¡¡¢ÒøÐÓ×¢²©Îï¹Ý¡¢µ±²¿ÃÅÃźͷ¨ÔºµÈ¡£Õâ´Î½¨¸´µÄ½ÏΪÑϳÁµÄ·ì϶ÊÇ»ùÓÚ²Ö¿âµÄ»º³åÇøÒç¶Âí½Å£¨CVE-2021-21901ºÍCVE-2021-21903£©ºÍĿ¼±éÀú·ì϶£¨CVE-2021-21904£©¡£ÕâЩ·ì϶ÓÚ8ÔÂ17ÈÕ±»Åû¶£¬²¢ÓÚ12ÔÂ13ÈÕ½¨¸´¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/walk-through-metal-detectors-software-flaws-hackable/
TheAnalyst·¢ÏÖ·Ö·¢Ð¶ñÒâÈí¼þDridexµÄ´¹µö»î¶¯

¾ÝýÌå12ÔÂ22ÈÕ±¨Â·£¬TheAnalyst¹«¿ªÁË·Ö·¢Ð¶ñÒâÈí¼þDridexµÄ´¹µö»î¶¯¡£Õâ´Î»î¶¯ÒÔ¿ª³ýÓʼþΪµö¶ü£¬·î¸æÊÕ¼þÈËËûÃǽ«ÓÚ12ÔÂ24ÈÕ±»¿ª³ý£¬ÇҴ˾ö¶¨²»³É³·Ïú¡£ÓʼþÖл¹ÓÐÒ»¸öExcel±í¸ñTermLetter.xls £¬¾Ý³ÆÆäÖÐÔ̺¬ÊÕ¼þÈ˱»¿ª³ýµÄÔÒò¡£ÊÕ¼þÈË´ò¿ªExcelÎļþºó»á¿´µ½Ò»¸öÍÌͲ»ÇåµÄÈËÔ±±í£¬²¢±»ÒªÇóÆôÓÃÄÚÈÝÀ´ÕýÈ·²é¿´Îļþ¡£ÊÕ¼þÈËÆôÓÃÄÚÈݺó»áµ¯³ö´°¿ÚÏÔʾ¡°Ðİ®µÄÔ±¹¤Ê¥µ®»¶ÀÖ£¡¡±£¬Õâʱ¶ñÒâºêÒѱ»Ö´ÐС£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/dridex-malware-trolls-employees-with-fake-job-termination-emails/
×êÑÐÍŶӷ¢ÏÖÀûÓÃTelegram´«²¼EchelonµÄ»î¶¯

12ÔÂ23ÈÕ£¬SafeGuard Cyber³ÆÆä·¢´Ë¿ÌTelegramÖзַ¢ÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þEchelonµÄ»î¶¯¡£¸ÃEchelonÑù±¾ÓÚ10Ô·ݳõ´Î±»¼ì²âµ½£¬ÀûÓÃSmokes NightµÄÃû³ÆÔÚ¹ØÓÚ¼ÓÃÜÇ®±ÒµÄƵ·Àï½øÐд«²¼»î¶¯£¬²¢½öÕë¶Ô¸ÃƵ·µÄÐÂÓû§¡£¹¥»÷ÕßÀûÓÃ.RARÎļþpresent).RAR·Ö·¢Echelon£¬¸ÃÎļþÔ̺¬pass-123.txt¡¢DotNetZip.dllºÍPresent.exe 3¸öÎļþ¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/telegram-steal-crypto-wallet-credentials/177266/
ÃÀ¹úÎ÷¸¥¼ªÄáÑÇÖÝÒ½ÁÆ»ú¹¹MHS³ÆÆäÔâµ½BEC¹¥»÷

ÃÀ¹úÎ÷¸¥¼ªÄáÑÇÖݵÄMonongalia Health System(MHS)ÔÚ12ÔÂ21ÈÕ°ä²¼¹«¸æ£¬³ÆÆäÔâµ½ÁËBEC¹¥»÷¡£MHSÆðÍ·²¢²»ÖªÂ·ÆäÒÑÔâµ½¹¥»÷£¬Ö±µ½Ò»¼Ò¹©¸øÉ̳ÆÔÚ½ñÄê7ÔÂ28ÈÕûÓÐÊÕµ½¸¶¿î£¬¸Ã»ú¹¹²ÅÆðÍ··¢Õ¹µ÷²é¡£µ÷²é·¢ÏÖ£¬¹¥»÷ÕßÔÚ5ÔÂ10ÈÕÖÁ8ÔÂ15ÈÕÈëÇÖÁ˶à¸öMHSÔ±¹¤µÄÓʼþÕÊ»§£¬²¢½Ó¼ûÁËÓʼþ¼°Æä¸½¼þ£¬¶øºóʹÓÃijMHS³Ð°üÉ̵ÄÕÊ»§¼ÙÒâMHSÀ´ÆÈ¡×Ê½ð¡£´Ë±í£¬¹¥»÷»¹Ð¹Â¶Á˲¿ÃÅ»¼ÕߺÍÔ±¹¤µÄÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/bec-attack-on-monongalia-health-1/
NCC Group°ä²¼2021Äê11ÔÂÍøÂç°²È«Ì¬ÊÆµÄ·ÖÎö»ã±¨

12ÔÂ21ÈÕ£¬NCC Group°ä²¼2021Äê11ÔÂÍøÂç°²È«Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£»ã±¨Ö¸³ö£¬¹¥»÷ÕߵijÁµãÔÚתÏò¹Ù·½×éÖ¯£¬Óë10Ô·ÝÏà±È£¬´ËÀà×éÖ¯Ôâµ½µÄ¹¥»÷Ôö³¤ÁË400%£»±¾ÔÂÀÕË÷¹¥»÷Ôö³¤ÁË1.9%£»±±ÃÀºÍÅ·ÖÞÒÀÈ»ÊÇÊܹ¥»÷×î¶àµÄµØÓò£¬±ðÀëÔâµ½154ºÍ96´Î¹¥»÷¡£11ÔµÄÖØÒªÀÕË÷Èí¼þΪPYSA£¨Ò²±»³ÆÎªMespinoza£©ºÍLockbit£¬ÆäÖÐPYSAµÄ¹¥»÷»î¶¯½ÏÖ®ÉÏÔÂÔö³¤50%£¬³¬¹ýÁËConti£¨½µÂä9.1%£©¡£
ÔÎÄÁ´½Ó£º
https://newsroom.nccgroup.com/news/ncc-group-monthly-threat-pulse-november-2021-439934


¾©¹«Íø°²±¸11010802024551ºÅ