ºÚ¿ÍÐû³ÆÒÑÇÔÈ¡ÐÂ¼ÓÆÂFullerton 40¶àÍò¿Í»§µÄÐÅÏ¢

°ä²¼¹¦·ò 2021-10-27

×êÑÐÍŶÓÅû¶APT×éÖ¯LazarusÌáÒéµÄ¹©¸øÁ´¹¥»÷µÄϸ½Ú


×êÑÐÍŶÓÅû¶APT×éÖ¯LazarusÌáÒéµÄ¹©¸øÁ´¹¥»÷µÄϸ½Ú.png


Kaspersky×êÑÐÍŶÓÓÚ±¾ÖܶþÅû¶ÁËLazarusÔÚ½üÆÚÌáÒéµÄ¹©¸øÁ´¹¥»÷¡£¡£¡£ ¡£¡£¡£¡£APT×éÖ¯Lazarus×Ô2009ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬£¬£¬£¬£¬£¬£¬ÀûÓÃMATA¹¥»÷¸÷¸öÐÐÒµµÄ×éÖ¯¡£¡£¡£ ¡£¡£¡£¡£ÔÚÕâ´Î»î¶¯ÖУ¬£¬£¬£¬£¬£¬£¬¸ÃÍÅ»ïÓÚ5Ô¹¥»÷ÁËÀ­ÍÑάÑǵÄIT¹©¸øÉÌ£¬£¬£¬£¬£¬£¬£¬ÓÖÔÚ6Ô·ÝÀûÓúóÃÅBLINDINGCANµÄбäÌå¹¥»÷Á˺«¹úÖǿ⡣¡£¡£ ¡£¡£¡£¡£×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬£¬£¬×î½üµÄ»î¶¯Õ¹Ê¾ÁËÁ½¸öÇ÷Ïò£ºLazarusÒÀÈ»¶Ô¹ú·ÀÐÐÒµ¸ÐÐËÖ£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ»¹µ«Ô¸Í¨¹ý¹©¸øÁ´¹¥»÷À´À©´óÆä¹¥»÷ÁìÓò¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://usa.kaspersky.com/about/press-releases/2021_apt-actor-lazarus-attacks-defense-industry-develops-supply-chain-attack-capabilities


Avast·¢ÏÖÕë¶ÔÊý°ÙÍòAndroidÓû§µÄڲƭ»î¶¯UltimaSMS


Avast·¢ÏÖÕë¶ÔÊý°ÙÍòAndroidÓû§µÄڲƭ»î¶¯UltimaSMS.png


10ÔÂ25ÈÕ£¬£¬£¬£¬£¬£¬£¬AvastµÄ×êÑÐÈËÔ±·¢ÏÖÁË´ó¹æÄ£µÄڲƭ»î¶¯UltimaSMS¡£¡£¡£ ¡£¡£¡£¡£Õⳡ»î¶¯ÀûÓÃ151¸öAndroidÀûÓ÷¨Ê½£¬£¬£¬£¬£¬£¬£¬×ÜÏÂÔØÁ¿¸ß´ï1050Íò´Î¡£¡£¡£ ¡£¡£¡£¡£ËüÃǼÙ×°³ÉÕÛ¿ÛÀûÓá¢ÓÎÏ·¡¢×Ô½ç˵¼üÅÌ¡¢¶þάÂëɨÃèÆ÷¡¢ºÍÀ¬»øÓʼþÀ¹½ØÆ÷µÈAndroidÀûÓ㬣¬£¬£¬£¬£¬£¬ÏÂÔØºó»áÒªÇóÓû§Ê䶯ÊÖ»úºÅºÍÓʼþµØÖ·À´½Ó¼û·¨Ê½¡£¡£¡£ ¡£¡£¡£¡£» £»£»£»£» £»£»£µÃµ½ÊÖ»úºÅºÍȨÏ޺󣬣¬£¬£¬£¬£¬£¬½«ÎªÖ¸±ê¶©ÔÄÿÔÂ40ÃÀÔªµÄSMS·þÎñ¡£¡£¡£ ¡£¡£¡£¡£Sensor TowerÊý¾ÝÏÔʾ£¬£¬£¬£¬£¬£¬£¬ÊÜÓ°Ïì×îÑϳÁµÄµØÓòÊǰ£¼°¡¢É³Ìذ¢À­²®¡¢°Í»ù˹̹ºÍ°¢ÁªÇõ£¬£¬£¬£¬£¬£¬£¬Êܺ¦Óû§ÊýÁ¿¾ù³¬¹ý100Íò¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/millions-of-android-users-targeted-in-subscription-fraud-campaign/


ºÚ¿ÍÐû³ÆÒÑÇÔÈ¡ÐÂ¼ÓÆÂFullerton 40¶àÍò¿Í»§µÄÐÅÏ¢


ºÚ¿ÍÐû³ÆÒÑÇÔÈ¡ÐÂ¼ÓÆÂFullerton 40¶àÍò¿Í»§µÄÐÅÏ¢.png


¹¥»÷ÕßÓÚ10ÔÂ11ÈÕÆðÍ·£¬£¬£¬£¬£¬£¬£¬ÔÚ°µÍøÉÏÒÔ600ÃÀÔªµÄ¼ÛÖµÏúÊÛÐÂ¼ÓÆÂÒ½Áƹ«Ë¾FullertonµÄÊý¾Ý¡£¡£¡£ ¡£¡£¡£¡£¹¥»÷ÕßÐû³ÆÒÑ»ñÈ¡ÁË40¶àÍò¿Í»§£¬£¬£¬£¬£¬£¬£¬²¢¹«¿ªÁËÐÕÃû¡¢Éí·ÝÖ¤ºÅÂë¡¢ÒøÐÐÕË»§ºÍ²¡Ê·µÈÐÅÏ¢×÷ΪÑù±¾¡£¡£¡£ ¡£¡£¡£¡£µ«ÊÇÔÚÉÏÖÜÎ壨10ÔÂ22ÈÕ£©£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õßɾ³ýÁËÓйØÊý¾ÝÏúÊÛµÄÐÅÏ¢¡£¡£¡£ ¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚ10ÔÂ19Èճƣ¬£¬£¬£¬£¬£¬£¬Õâ´Îй¶ÊÇÓÉÓÚÆä¹©¸øÉÌAgapeǰ²»¾ÃµÄÎ¥¹æÐÐΪµ¼ÖµÄ£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°ÈÔδȷ¶¨ÊÜÓ°ÏìÈËÔ±µÄÊýÁ¿ºÍÉí·Ý¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.straitstimes.com/singapore/courts-crime/fullerton-health-vendor-hacked-personal-details-of-customers-sold-online


¶à¸öÀÕË÷ÍÅ»ïÀûÓÃEntroLink VPNÖÐ0 day½øÐй¥»÷»î¶¯


¶à¸öÀÕË÷ÍÅ»ïÀûÓÃEntroLink VPNÖÐ0 day½øÐй¥»÷»î¶¯.png


9ÔÂ13ÈÕ£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚ°µÍø°ä²¼ÁËEntroLink VPNÖÐ0 day·ì϶ÀûÓ÷¨Ê½£¬£¬£¬£¬£¬£¬£¬Ö®ºó±»¶à¸öÀÕË÷ÔËÓªÍÅ»ï±øÆ÷»¯¡£¡£¡£ ¡£¡£¡£¡£¸Ã·ì϶ÊÇÒ»¸öÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁ˺«¹úÊ¢ÐÐEntroLink PPX-AnyLinkÉ豸£¬£¬£¬£¬£¬£¬£¬Ö»Ð輸ÃëÖÓ¼´¿É·ÛËéÉ豸¡£¡£¡£ ¡£¡£¡£¡£×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬£¬£¬½üÆÚ·¢ÏÖBlackMatterºÍLockBitµÄ·ÖÖ§»ú¹¹¿ÉÄÜÒѾ­Ê¹Óø÷ì϶ÌáÒé¹¥»÷£¬£¬£¬£¬£¬£¬£¬Õâ³ÉΪÁËĿǰÒÑÖªµÄµÚ54¸ö±»ÀÕË÷ÔËÓªÍÅ»ïÀÄÓõÄÁãÈÕ·ì϶¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/ransomware-gangs-are-abusing-a-zero-day-in-entrolink-vpn-appliances/


Mozilla·¢ÏÖ2¸ö¶ñÒâÀ©´ó×èÖ¹Óû§×°ÖÃFirefox¸üÐÂ


Mozilla·¢ÏÖ2¸ö¶ñÒâÀ©´ó×èÖ¹Óû§×°ÖÃFirefox¸üÐÂ.png


MozillaÔÚ±¾ÖÜÒ»Åû¶£¬£¬£¬£¬£¬£¬£¬ÓÐ455000¸öÓû§×°ÖÃÁ˶ñÒâFirefoxÀ©´ó¡£¡£¡£ ¡£¡£¡£¡£Õâ2¸öÀ©´ó±ðÀëΪBypassºÍBypass XM£¬£¬£¬£¬£¬£¬£¬¿Éͨ¹ý´úÀíAPIÀ´×èÖ¹Óû§ÏÂÔØ¸üС¢½Ó¼û¸üÐÂÆÁ±ÎÁбíºÍ¸ü¸ÄÔ¶³ÌÅäÖᣡ£¡£ ¡£¡£¡£¡£³ýÁËɾ³ýÕâÁ½¸öÀ©´óÖ®±í£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾»¹ÍƳöÁËϵͳ¸½¼Ó×é¼þProxy FailoverÒÔ½øÒ»²½»º½âÎÊÌâ¡£¡£¡£ ¡£¡£¡£¡£Mozilla»¹½¨ÒéÓû§½«ä¯ÀÀÆ÷¸üе½Firefox 93°æ±¾£¬£¬£¬£¬£¬£¬£¬²¢È·±£Microsoft DefenderʼÖÕ´¦ÓÚÔËÐÐ״̬¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/10/malicious-firefox-add-ons-block-browser.html


SEON°ä²¼¹ØÓÚÈ«ÇòÍøÂç·¸×ïÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨


SEON°ä²¼¹ØÓÚÈ«ÇòÍøÂç·¸×ïÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨.png


SEONÔÚ10ÔÂ25ÈÕ°ä²¼Á˹ØÓÚÈ«ÇòÍøÂç·¸×ïÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£ ¡£¡£¡£¡£»ã±¨¶ÔÈ«Çò½ü100¸ö¹ú¶ÈºÍµØÓò½øÐзÖÎö£¬£¬£¬£¬£¬£¬£¬·¢ÏÖÍøÂ簲ȫÐÔ×îÇ¿µÄ¹ú¶ÈÊǵ¤Â󣬣¬£¬£¬£¬£¬£¬Æä´ÎÊǵ¹ú¡¢ÃÀ¹ú¡¢Å²Íþ¡¢Ó¢¹ú¡¢¼ÓÄôó¡¢ÈðµäºÍ°Ä´óÀûÑǵȹú¡£¡£¡£ ¡£¡£¡£¡£Ïà·´£¬£¬£¬£¬£¬£¬£¬×î²»°²È«µÄ¹ú¶ÈÊÇÃåµé£¬£¬£¬£¬£¬£¬£¬Æä´ÎÊǼíÆÒÕ¯¡¢ºé¶¼À­Ë¹¡¢²£ÀûάÑǺÍÃɹŵȹú¡£¡£¡£ ¡£¡£¡£¡£»ã±¨»¹Ö¸³öÁË2020ÄêÃÀ¹ú×î³£¼ûµÄÍøÂç·¸×ïÀàÐͱðÀëÊÇÍøÂç´¹µöºÍڲƭ(32.96%)¡¢Î´¸¶¿î»òδ½»¸¶(14.87%)ºÍڲƭÀÕË÷ (10.48%)¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://seon.io/resources/global-cybercrime-report/