µÂ¹úÁª°î¾¯Ô±¾ÖÖØÖÃEmotet £¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ½«×Ô¶¯Ð¶ÔØ £»£»£» £»£»£»£»»ªÊ¢¶Ù¾¯¾ÖÔâµ½BabukµÄ¹¥»÷ £¬£¬£¬£¬£¬£¬250GBδ¼ÓÃܵÄÎļþй¶

Ðû²¼Ê±¼ä 2021-04-27

1.µÂ¹úÁª°î¾¯Ô±¾ÖÖØÖÃEmotet £¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ½«×Ô¶¯Ð¶ÔØ


1.jpg


µÂ¹úÁª°î¾¯Ô±¾ÖBundeskriminalamtÖØÖÃÁËEmotet £¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ½«ÔÚËùÓÐÊÜѬȾµÄϵͳÖÐ×Ô¶¯Ð¶ÔØ¡£¡£¡£¡£EmotetÊǽüÆÚ×îΣÏÕµÄÀ¬»øÓʼþ½©Ê¬ÍøÂçÖ®Ò» £¬£¬£¬£¬£¬£¬Æä»ù´¡ÉèÊ©ÓÚ½ñÄê1Ô·ÝÓɶà¹úÖ´·¨²¿·ÖÁªºÏµ·»Ù¡£¡£¡£¡£ÔÚ´Ë´ÎÐж¯ÖÐ £¬£¬£¬£¬£¬£¬µÂ¹ú¾¯·½ÈÏÕæ¿ª·¢ºÍÍÆËÍÐ¶ÔØÄ£¿£¿£¿£¿é £¬£¬£¬£¬£¬£¬ÆäΪÁËÍøÂçÖ¤¾ÝºÍÐÅÏ¢¶øÍƳÙÁ˸ÃÐ¶ÔØÄ£¿£¿£¿£¿éµÄÐû²¼¡£¡£¡£¡£¸Ã»ú¹¹Í¨¹ýÆä¿ØÖƵÄC2ЧÀÍÆ÷ £¬£¬£¬£¬£¬£¬½«32λEmotetLoader.dllÐÎʽµÄÐÂEmotetÄ£¿£¿£¿£¿é·Ö·¢¸øËùÓÐÊÜѬȾµÄϵͳ £¬£¬£¬£¬£¬£¬Ê¹ÕâЩϵͳÔÚ2021Äê4ÔÂ25ÈÕ×Ô¶¯Ð¶ÔظöñÒâÈí¼þ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/emotet-malware-nukes-itself-today-from-all-infected-computers-worldwide/


2.»ªÊ¢¶Ù¾¯¾ÖÔâµ½BabukµÄ¹¥»÷ £¬£¬£¬£¬£¬£¬250GBδ¼ÓÃܵÄÎļþй¶


2.jpg


»ªÊ¢¶ÙÌØÇø¾¯Ô±¾ÖMPDÈ·ÈÏÆäÔâµ½ÀÕË÷ÍÅ»ïBabukµÄ¹¥»÷ £¬£¬£¬£¬£¬£¬250 GBδ¼ÓÃܵÄÎļþй¶¡£¡£¡£¡£ÀÕË÷ÍÅ»ï¹ûÕæµÄ±»µÁÎļþ¼ÐµÄ½ØÍ¼ÖеÄʱ¼ä´Á¾ùΪ2021.4.19 £¬£¬£¬£¬£¬£¬Õâ¿ÉÄÜÏÔʾÁ˹¥»÷ÕßÇÔÈ¡Êý¾ÝµÄʱ¼ä¡£¡£¡£¡£±ðµÄ £¬£¬£¬£¬£¬£¬BabukÍÅ»ïÌØÊâÖ¸³öÁËÒ»·ÝÎļþ £¬£¬£¬£¬£¬£¬ÆäËÆºõÓë1ÔÂ6ÈÕÏ®»÷¹ú»á´óÏõĿ¹Òé»î¶¯ÓйØ¡£¡£¡£¡£MPD³ÆÆäÒѾ­ÓëFBIÁªºÏÕö¿ªÁËÖÜÈ«µÄÊÓ²ì £¬£¬£¬£¬£¬£¬¿ÉÊÇÏÖÔÚÉÐδ¹ûÕæÓйش˴ÎÊÂÎñµÄÏêϸÐÅÏ¢¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/dc-police-confirms-cyberattack-after-ransomware-gang-leaks-data/


3.Ñо¿ÍŶӷ¢Ã÷ʹÓÃFileZenÖеÄ2¸öÎó²îµÄ¹¥»÷»î¶¯


3.jpg


Ñо¿ÍŶӷ¢Ã÷ʹÓÃÎļþ¹²ÏíЧÀÍÆ÷Soliton FileZenÖеÄ2¸öÎó²îÇÔÈ¡Êý¾ÝµÄ´ó¹æÄ£¹¥»÷»î¶¯¡£¡£¡£¡£´Ë´Î»î¶¯ÖÐʹÓõÄÎó²î»®·ÖΪĿ¼±éÀúÎó²î£¨CVE-2020-5639£© £¬£¬£¬£¬£¬£¬¿É½«Ìض¨ÎļþÉÏÔØµ½Ìض¨Ä¿Â¼Öжøµ¼ÖÂÖ´ÐÐí§ÒâOSÏÂÁî £»£»£» £»£»£»£»ÒÔ¼°Ò»¸öí§ÒâOSÏÂÁîÖ´ÐÐÎó²î£¨CVE-2021-20655£©¡£¡£¡£¡£ÔÚÆäÖеÄÒ»´Î¹¥»÷ÖÐ £¬£¬£¬£¬£¬£¬ÈÕ±¾Ô׺âÄÚ¸ó°ì¹«ÊÒ(Cabinet Office)ÊÂÇéְԱʹÓõÄSolitonÎļþ¹²Ïí´æ´¢Ôâµ½ÁËδ¾­ÊÚȨµÄ»á¼û¡£¡£¡£¡£SolitonÒѾ­¿¯Ðй̼þ°æ±¾V4.2.8ºÍV5.0.3ÐÞ¸´ÁËFileZenÖеÄÁ½¸öÎó²î¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/117208/hacking/soliton-filezen-file-sharing-servers.html


4.Sophos³ÆÏÖÔÚÓнüÒ»°ëµÄ¶ñÒâÈí¼þʹÓÃTLSÀ´Òþ²ØÍ¨Ñ¶


4.jpg


Sophos̫ͨ¹ýÎö·¢Ã÷ £¬£¬£¬£¬£¬£¬½üÆÚÓнüÒ»°ëµÄ¶ñÒâÈí¼þʹÓÃTLSÀ´Òþ²ØÍ¨Ñ¶¡£¡£¡£¡£ÔÚÒÑÍùµÄÊ®ÄêÖÐ £¬£¬£¬£¬£¬£¬HTTPSµÄʹÓÃÂÊ´Ó2014ÄêÕ¼ËùÓÐÍøÒ³»á¼ûÁ¿µÄ40£¥ÒÔÉÏÔöÌíµ½2021Äê3ÔµÄ98£¥¡£¡£¡£¡£¶ø¶ñÒâÈí¼þÒ²³öÓÚÏàͬµÄÔµ¹ÊÔ­ÓɽÓÄÉTLS £¬£¬£¬£¬£¬£¬2020Äê¼ì²âµ½23£¥µÄ¶ñÒâÈí¼þʹÓÃTLSÓëÔ¶³Ìϵͳ¾ÙÐÐͨѶ £¬£¬£¬£¬£¬£¬µ½ÏÖÔÚÕâÒ»±ÈÀýÒÑ¿¿½ü46£¥¡£¡£¡£¡£GoogleÔÆÐ§ÀÍÊÇ9£¥µÄ¶ñÒâTLSÇëÇóµÄÄ¿µÄ £¬£¬£¬£¬£¬£¬Æä´ÎÊÇÓ¡¶ÈµÄBSNL £¬£¬£¬£¬£¬£¬ËùÓеĶñÒâTLSͨѶÖÐÏÕЩÓÐÒ»°ëÁ÷ÏòÁËÃÀ¹úºÍÓ¡¶ÈµÄЧÀÍÆ÷¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://news.sophos.com/en-us/2021/04/21/nearly-half-of-malware-now-use-tls-to-conceal-communications/


5.MimecastÐû²¼Óйصç×ÓÓʼþÇå¾²Ì¬ÊÆµÄÆÊÎö±¨¸æ


5.jpg


MimecastÐû²¼ÁËÓйصç×ÓÓʼþÇå¾²Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¸Ã±¨¸æ»ùÓÚ¶ÔÈ«Çò1225λ¾öÒéÕßµÄÊÓ²ì £¬£¬£¬£¬£¬£¬ÆäÖÐ79£¥µÄÊÜ·ÃÕßÌåÏÖÓÉÓÚȱ·¦Çå¾²·½ÃæµÄ×¼±¸ £¬£¬£¬£¬£¬£¬ËûÃǵĹ«Ë¾ÔÚ2020ÄêÂÄÀúÁËÓªÒµÖÐÖ¹¡¢²ÆÎñËðʧ»òÆäËûÎÊÌâ £»£»£» £»£»£»£»61£¥µÄ¹«Ë¾ÔÚ2020ÄêÊܵ½ÀÕË÷Èí¼þµÄÓ°Ïì £¬£¬£¬£¬£¬£¬±ÈÈ¥ÄêÔöÌíÁË20£¥ £»£»£» £»£»£»£»52£¥µÄÀÕË÷Èí¼þÊܺ¦ÕßÖ§¸¶ÁËÊê½ð £¬£¬£¬£¬£¬£¬¿ÉÊÇËûÃÇÖÐÖ»ÓÐ66£¥µÄÈ˻ָ´ÁËÊý¾Ý £¬£¬£¬£¬£¬£¬ÁíÍâ34£¥µÄ¹«Ë¾Ö§¸¶ÁËÊê½ðÈ´ÒÀȻûÓлñµÃËûÃǵÄÊý¾Ý¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.mimecast.com/state-of-email-security/


6.OpenTextÐû²¼2020ÄêµÄÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ


6.jpg


OpenTextÐû²¼ÁË2020ÄêµÄÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¡£±¨¸æÖ¸³ö £¬£¬£¬£¬£¬£¬½ö´Ó2020Äê1Ôµ½2Ô £¬£¬£¬£¬£¬£¬ÍøÂç´¹ÂڵĹ¥»÷´ÎÊý¾ÍÔöÌíÁË510£¥ £¬£¬£¬£¬£¬£¬¹¥»÷Ä¿µÄÖ÷ÒªÊÇÄ¿µÄÊÇeBay¡¢Apple¡¢Microsoft¡¢FacebookºÍGoogle¡£¡£¡£¡£ÈÕ±¾µÄPCѬȾÂÊ×îµÍ £¬£¬£¬£¬£¬£¬Îª2.3% £¬£¬£¬£¬£¬£¬Æä´ÎÊÇÓ¢¹ú(2.7%)¡¢´óÑóÖÞ(3.2%)ºÍ±±ÃÀ(3.7%)¡£¡£¡£¡£ÔÚÅ·ÖÞ £¬£¬£¬£¬£¬£¬¼ÒÓÃ×°±¸±»Ñ¬È¾µÄ¿ÉÄÜÐÔ£¨17.4%£©ÊÇÉÌÓÃ×°±¸µÄÈý±¶¶à(5.3%)¡£¡£¡£¡£2020ÄêÔÚAndroid?×°±¸Éϼì²âµ½µÄÌØÂåÒÁľÂíºÍ¶ñÒâÈí¼þÕ¼Íþв×ÜÊýµÄ95.9£¥ £¬£¬£¬£¬£¬£¬¸ßÓÚ2019ÄêµÄ92.2£¥¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://mypage.webroot.com/2021-threat-report.html