ºÚ¿ÍÐû³ÆÒÑÇÔÈ¡ÐÂ¼ÓÆÂFullerton 40¶àÍò¿Í»§µÄÐÅÏ¢
°ä²¼¹¦·ò 2021-10-27×êÑÐÍŶÓÅû¶APT×éÖ¯LazarusÌáÒéµÄ¹©¸øÁ´¹¥»÷µÄϸ½Ú

Kaspersky×êÑÐÍŶÓÓÚ±¾ÖܶþÅû¶ÁËLazarusÔÚ½üÆÚÌáÒéµÄ¹©¸øÁ´¹¥»÷¡£¡£¡£¡£¡£¡£¡£APT×éÖ¯Lazarus×Ô2009ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬£¬£¬£¬£¬£¬£¬ÀûÓÃMATA¹¥»÷¸÷¸öÐÐÒµµÄ×éÖ¯¡£¡£¡£¡£¡£¡£¡£ÔÚÕâ´Î»î¶¯ÖУ¬£¬£¬£¬£¬£¬£¬¸ÃÍÅ»ïÓÚ5Ô¹¥»÷ÁËÀÍÑάÑǵÄIT¹©¸øÉÌ£¬£¬£¬£¬£¬£¬£¬ÓÖÔÚ6Ô·ÝÀûÓúóÃÅBLINDINGCANµÄбäÌå¹¥»÷Á˺«¹úÖǿ⡣¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬£¬£¬×î½üµÄ»î¶¯Õ¹Ê¾ÁËÁ½¸öÇ÷Ïò£ºLazarusÒÀÈ»¶Ô¹ú·ÀÐÐÒµ¸ÐÐËÖ£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ»¹µ«Ô¸Í¨¹ý¹©¸øÁ´¹¥»÷À´À©´óÆä¹¥»÷ÁìÓò¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://usa.kaspersky.com/about/press-releases/2021_apt-actor-lazarus-attacks-defense-industry-develops-supply-chain-attack-capabilities
Avast·¢ÏÖÕë¶ÔÊý°ÙÍòAndroidÓû§µÄڲƻUltimaSMS

10ÔÂ25ÈÕ£¬£¬£¬£¬£¬£¬£¬AvastµÄ×êÑÐÈËÔ±·¢ÏÖÁË´ó¹æÄ£µÄڲƻUltimaSMS¡£¡£¡£¡£¡£¡£¡£Õⳡ»î¶¯ÀûÓÃ151¸öAndroidÀûÓ÷¨Ê½£¬£¬£¬£¬£¬£¬£¬×ÜÏÂÔØÁ¿¸ß´ï1050Íò´Î¡£¡£¡£¡£¡£¡£¡£ËüÃǼÙ×°³ÉÕÛ¿ÛÀûÓá¢ÓÎÏ·¡¢×Ô½ç˵¼üÅÌ¡¢¶þάÂëɨÃèÆ÷¡¢ºÍÀ¬»øÓʼþÀ¹½ØÆ÷µÈAndroidÀûÓ㬣¬£¬£¬£¬£¬£¬ÏÂÔØºó»áÒªÇóÓû§Ê䶯ÊÖ»úºÅºÍÓʼþµØÖ·À´½Ó¼û·¨Ê½¡£¡£¡£¡£¡£¡£¡£»£»£»£»£»£»£»£µÃµ½ÊÖ»úºÅºÍȨÏ޺󣬣¬£¬£¬£¬£¬£¬½«ÎªÖ¸±ê¶©ÔÄÿÔÂ40ÃÀÔªµÄSMS·þÎñ¡£¡£¡£¡£¡£¡£¡£Sensor TowerÊý¾ÝÏÔʾ£¬£¬£¬£¬£¬£¬£¬ÊÜÓ°Ïì×îÑϳÁµÄµØÓòÊǰ£¼°¡¢É³Ìذ¢À²®¡¢°Í»ù˹̹ºÍ°¢ÁªÇõ£¬£¬£¬£¬£¬£¬£¬Êܺ¦Óû§ÊýÁ¿¾ù³¬¹ý100Íò¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/millions-of-android-users-targeted-in-subscription-fraud-campaign/
ºÚ¿ÍÐû³ÆÒÑÇÔÈ¡ÐÂ¼ÓÆÂFullerton 40¶àÍò¿Í»§µÄÐÅÏ¢

¹¥»÷ÕßÓÚ10ÔÂ11ÈÕÆðÍ·£¬£¬£¬£¬£¬£¬£¬ÔÚ°µÍøÉÏÒÔ600ÃÀÔªµÄ¼ÛÖµÏúÊÛÐÂ¼ÓÆÂÒ½Áƹ«Ë¾FullertonµÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÐû³ÆÒÑ»ñÈ¡ÁË40¶àÍò¿Í»§£¬£¬£¬£¬£¬£¬£¬²¢¹«¿ªÁËÐÕÃû¡¢Éí·ÝÖ¤ºÅÂë¡¢ÒøÐÐÕË»§ºÍ²¡Ê·µÈÐÅÏ¢×÷ΪÑù±¾¡£¡£¡£¡£¡£¡£¡£µ«ÊÇÔÚÉÏÖÜÎ壨10ÔÂ22ÈÕ£©£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õßɾ³ýÁËÓйØÊý¾ÝÏúÊÛµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚ10ÔÂ19Èճƣ¬£¬£¬£¬£¬£¬£¬Õâ´Îй¶ÊÇÓÉÓÚÆä¹©¸øÉÌAgapeǰ²»¾ÃµÄÎ¥¹æÐÐΪµ¼Öµģ¬£¬£¬£¬£¬£¬£¬Ä¿Ç°ÈÔδȷ¶¨ÊÜÓ°ÏìÈËÔ±µÄÊýÁ¿ºÍÉí·Ý¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.straitstimes.com/singapore/courts-crime/fullerton-health-vendor-hacked-personal-details-of-customers-sold-online
¶à¸öÀÕË÷ÍÅ»ïÀûÓÃEntroLink VPNÖÐ0 day½øÐй¥»÷»î¶¯

9ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚ°µÍø°ä²¼ÁËEntroLink VPNÖÐ0 day·ì϶ÀûÓ÷¨Ê½£¬£¬£¬£¬£¬£¬£¬Ö®ºó±»¶à¸öÀÕË÷ÔËÓªÍÅ»ï±øÆ÷»¯¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇÒ»¸öÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁ˺«¹úÊ¢ÐÐEntroLink PPX-AnyLinkÉ豸£¬£¬£¬£¬£¬£¬£¬Ö»Ð輸ÃëÖÓ¼´¿É·ÛËéÉ豸¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬£¬£¬½üÆÚ·¢ÏÖBlackMatterºÍLockBitµÄ·ÖÖ§»ú¹¹¿ÉÄÜÒѾʹÓø÷ì϶ÌáÒé¹¥»÷£¬£¬£¬£¬£¬£¬£¬Õâ³ÉΪÁËĿǰÒÑÖªµÄµÚ54¸ö±»ÀÕË÷ÔËÓªÍÅ»ïÀÄÓõÄÁãÈÕ·ì϶¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://therecord.media/ransomware-gangs-are-abusing-a-zero-day-in-entrolink-vpn-appliances/
Mozilla·¢ÏÖ2¸ö¶ñÒâÀ©´ó×èÖ¹Óû§×°ÖÃFirefox¸üÐÂ

MozillaÔÚ±¾ÖÜÒ»Åû¶£¬£¬£¬£¬£¬£¬£¬ÓÐ455000¸öÓû§×°ÖÃÁ˶ñÒâFirefoxÀ©´ó¡£¡£¡£¡£¡£¡£¡£Õâ2¸öÀ©´ó±ðÀëΪBypassºÍBypass XM£¬£¬£¬£¬£¬£¬£¬¿Éͨ¹ý´úÀíAPIÀ´×èÖ¹Óû§ÏÂÔØ¸üС¢½Ó¼û¸üÐÂÆÁ±ÎÁбíºÍ¸ü¸ÄÔ¶³ÌÅäÖᣡ£¡£¡£¡£¡£¡£³ýÁËɾ³ýÕâÁ½¸öÀ©´óÖ®±í£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾»¹ÍƳöÁËϵͳ¸½¼Ó×é¼þProxy FailoverÒÔ½øÒ»²½»º½âÎÊÌâ¡£¡£¡£¡£¡£¡£¡£Mozilla»¹½¨ÒéÓû§½«ä¯ÀÀÆ÷¸üе½Firefox 93°æ±¾£¬£¬£¬£¬£¬£¬£¬²¢È·±£Microsoft DefenderʼÖÕ´¦ÓÚÔËÐÐ״̬¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/10/malicious-firefox-add-ons-block-browser.html
SEON°ä²¼¹ØÓÚÈ«ÇòÍøÂç·¸×ïÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨

SEONÔÚ10ÔÂ25ÈÕ°ä²¼Á˹ØÓÚÈ«ÇòÍøÂç·¸×ïÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£»ã±¨¶ÔÈ«Çò½ü100¸ö¹ú¶ÈºÍµØÓò½øÐзÖÎö£¬£¬£¬£¬£¬£¬£¬·¢ÏÖÍøÂ簲ȫÐÔ×îÇ¿µÄ¹ú¶ÈÊǵ¤Â󣬣¬£¬£¬£¬£¬£¬Æä´ÎÊǵ¹ú¡¢ÃÀ¹ú¡¢Å²Íþ¡¢Ó¢¹ú¡¢¼ÓÄôó¡¢ÈðµäºÍ°Ä´óÀûÑǵȹú¡£¡£¡£¡£¡£¡£¡£Ïà·´£¬£¬£¬£¬£¬£¬£¬×î²»°²È«µÄ¹ú¶ÈÊÇÃåµé£¬£¬£¬£¬£¬£¬£¬Æä´ÎÊǼíÆÒÕ¯¡¢ºé¶¼À˹¡¢²£ÀûάÑǺÍÃɹŵȹú¡£¡£¡£¡£¡£¡£¡£»ã±¨»¹Ö¸³öÁË2020ÄêÃÀ¹ú×î³£¼ûµÄÍøÂç·¸×ïÀàÐͱðÀëÊÇÍøÂç´¹µöºÍÚ²Æ(32.96%)¡¢Î´¸¶¿î»òδ½»¸¶(14.87%)ºÍÚ²ÆÀÕË÷ (10.48%)¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://seon.io/resources/global-cybercrime-report/


¾©¹«Íø°²±¸11010802024551ºÅ