Kaspersky°ä²¼Q3·ÖÎö»ã±¨£ºApple°ä²¼°²È«¸üн¨¸´iOS·ì϶

°ä²¼¹¦·ò 2021-10-29

ÀÕË÷ÔËÓªÍÅ»ïGrief³ÆÒÑÈëÇÖÃÀ¹ú²½Ç¹Ð­»áNRAµÄϵͳ


ÀÕË÷ÔËÓªÍÅ»ïGrief³ÆÒÑÈëÇÖÃÀ¹ú²½Ç¹Ð­»áNRAµÄϵͳ.png


10ÔÂ27ÈÕ£¬£¬£¬£¬£¬£¬£¬ÀÕË÷ÔËÓªÍÅ»ïGriefÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾Éϰ䷢ÒÑÈëÇÖÃÀ¹ú²½Ç¹Ð­»áNRAµÄϵͳ¡£¡£¡£¡£¡£¹¥»÷Õß¹«¿ªÁËÒ»¸ö2.7 MBµÄÎļþNational Grants.zip×÷ΪÑù±¾£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÉæ¼°NRA²¦¿îÉêÇëµÈÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°Ô̺¬ÁË˰ÎñÐÅÏ¢ºÍͶ×ʽð¶îExcel±í¸ñµÄ½ØÍ¼¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬NRA²¢Î´¶Ô´ËÊÂ×÷³öÆÀÂÛ¡£¡£¡£¡£¡£¾ÝÐÅ£¬£¬£¬£¬£¬£¬£¬GriefÍÅ»ïÓë¶íÂÞ˹Evil CorpÓйØ£¬£¬£¬£¬£¬£¬£¬ºóÕßΪÁËÌÓ±ÜÔì²ÃʹÓÃÁËWastedLocker¡¢HadesºÍPhoenix LockerµÈ¶à¸öÀÕË÷Èí¼þ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/123849/cyber-crime/grief-ransomware-hit-nra.html


Abnormal·¢ÏÖ½üÆÚÀûÓÃQRÂëÈÆ¹ýURL¼ì²âµÄ´¹µö»î¶¯


Abnormal·¢ÏÖ½üÆÚÀûÓÃQRÂëÈÆ¹ýURL¼ì²âµÄ´¹µö»î¶¯.png


Abnormal×êÑÐÍŶÓÓÚ10ÔÂ26ÈÕÅû¶ÁËÖ¼ÔÚÍøÂçMicrosoftÍ´´¦µÄ´¹µö»î¶¯¡£¡£¡£¡£¡£Õâ´Î»î¶¯²úÉúÔÚ2021Äê9ÔÂ15ÈÕÖÁ10ÔÂ13ÈÕÆÚ¼ä£¬£¬£¬£¬£¬£¬£¬Æä¹ÖÒìÖ®´¦ÔÚÓÚ£¬£¬£¬£¬£¬£¬£¬´¹µöÓʼþ¶¼Ê¹ÓÃÁËQRÂëÀ´Èƹý°²È«ÓʼþÍø¹ØÖÐÕë¶ÔÓʼþ¸½¼þURLµÄɨÃèÖ°ÄÜ¡£¡£¡£¡£¡£²¢ÇÒ£¬£¬£¬£¬£¬£¬£¬ËùÓÐQRÂë¶¼ÊÇÔÚ·¢Ë͵±Ìì´´½¨µÄ£¬£¬£¬£¬£¬£¬£¬ÕâʹµÃÕâ´Î»î¶¯ºÜÄѱ»¼ì²âµ½»ò±»×èÖ¹ÁÐ±í¼ø±ð¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÁËÆóÒµµ÷²é·þÎñÒÔ¼°ÑÇÂíÑ·ºÍ¹È¸è·þÎñÀ´Íйܴ¹µöÒ³Ãæ£¬£¬£¬£¬£¬£¬£¬»¹Ê¹ÓÃÁ˺Ϸ¨µÄOutlookÕÊ»§À´Èƹý¼ì²â¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://abnormalsecurity.com/blog/qr-code-campaign-bypass-security


кڿÍÍÅ»ïTA2722¼ÙÒâ·ÆÂɱö¹Ù·½×éÖ¯·Ö·¢¶à¸öRAT


кڿÍÍÅ»ïTA2722¼ÙÒâ·ÆÂɱö¹Ù·½×éÖ¯·Ö·¢¶à¸öRAT.png


ProofpointÔÚ10ÔÂ27ÈÕ·¢ÏÖÁËÒ»¸öеĺڿÍÍÅ»ïTA2722£¨Óֳƣ¬£¬£¬£¬£¬£¬£¬Balikbayan Foxes£©¡£¡£¡£¡£¡£ÔÚ2021ÄêµÄ»î¶¯ÖУ¬£¬£¬£¬£¬£¬£¬Ëü¼ÙÒâÁ˶à¸ö·ÆÂɱö¹Ù·½×éÖ¯£¬£¬£¬£¬£¬£¬£¬Ô̺¬ÎÀÉú²¿¡¢·ÆÂɱöº£±í¾ÍÒµÖÎÀí¾Ö(POEA)ºÍº£¹Ø¾ÖµÈ£¬£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶Ô±±ÃÀ¡¢Å·Ö޺Ͷ«ÄÏÑǵĺ½ÔË¡¢ÎïÁ÷¡¢Ôì×÷¡¢Ã³Ò×·þÎñ¡¢ÔìÒ©¡¢ÄÜÔ´ºÍ½ðÈÚµÈÐÐÒµ¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬ÕâЩ»î¶¯¶¼·Ö·¢ÁËÔ¶³Ì½Ó¼ûľÂíRemcosºÍNanoCore¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.proofpoint.com/us/blog/threat-insight/new-threat-actor-spoofs-philippine-government-covid-19-health-data-widespread


Apple°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´iOSµÈ¶à¿î²úÆ·Öеķì϶


Apple°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´iOSµÈ¶à¿î²úÆ·Öеķì϶.png


AppleÔÚ10ÔÂ25ºÍ26ÈÕ°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´ÁËiOSµÈ¶à¿î²úÆ·Öеķì϶¡£¡£¡£¡£¡£Õâ´Î½¨¸´µÄ×îΪÑϳÁµÄÊÇApple TV IOMobileFrameBufferÖеÄÄÚ´æ°Ü»µ·ì϶CVE-2021-30883£¬£¬£¬£¬£¬£¬£¬Ëü¿ÉÄÜÒѾ­±»ÔÚÒ°ÀûÓ㬣¬£¬£¬£¬£¬£¬ZecOps°µÊ¾¸Ã·ì϶¿É±»ÓÃÓÚ1-clickºÍË®¿Ó¹¥»÷¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬¸üл¹½¨¸´ÁË´úÂëÖ´Ðзì϶CVE-2021-30919ºÍCVE-2021-30917¡¢ÌáȨ·ì϶CVE-2021-30873ºÍÔ½½ç¶ÁÈ¡·ì϶CVE-2021-30905µÈ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/10/27/apple-releases-security-updates-multiple-products


Google°ä²¼´¹Î£¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´ChromeÒѱ»ÀûÓõÄ0day


Google°ä²¼´¹Î£¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´ChromeÒѱ»ÀûÓõÄ0day.png


GoogleÔÚ10ÔÂ28ÈÕ°ä²¼µÄ´¹Î£¸üн¨¸´ÁËChromeÖеÄ8¸ö·ì϶£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬2¸öÒѱ»ÔÚÒ°ÀûÓõÄ0day¡£¡£¡£¡£¡£Õâ2¸ö0day±ðÀëΪIntentsÖжÔÓÚÊäÈëµÄÑéÖ¤²»¼°·ì϶CVE-2021-38000£¬£¬£¬£¬£¬£¬£¬ºÍChrome V8 JavaScriptÒýÇæÖеÄʵÏÖ²»µ±·ì϶CVE-2021-38003¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬»¹½¨¸´ÁË¿ªÊͺóʹÓ÷ì϶CVE-2021-37997¡¢CVE-2021-37998ºÍCVE-2021-38002£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°V8ÖеÄÀàÐÍ»ìºÏCVE-2021-38001µÈ·ì϶¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/google/emergency-google-chrome-update-fixes-zero-days-used-in-attacks/


Kaspersky°ä²¼2021ÄêQ3 APT¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨


Kaspersky°ä²¼2021ÄêQ3 APT¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨.png


10ÔÂ26ÈÕ£¬£¬£¬£¬£¬£¬£¬KasperskyµÄÈ«Çò×êÑÐÓë·ÖÎöÍŶÓ(GReAT)°ä²¼ÁË2021ÄêQ3 APT¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£»ã±¨Ö¸³öµÚÈý¼¾¶ÈµÄÖØÒªÇ÷ÏòÔ̺¬£¬£¬£¬£¬£¬£¬£¬¹©¸øÁ´¹¥»÷»î¶¯Ê¼ÖÕÔÚ³ÖÐø£¬£¬£¬£¬£¬£¬£¬ÀýÈçSmudgeX¡¢DarkHaloºÍLazarusµÄ¹¥»÷£»£»£» £»£»£»£»£»Éç»á¹¤³ÌѧÒÀÈ»ÊÇÖØÒª¹¥»÷²½Ö裬£¬£¬£¬£¬£¬£¬µ«Ò²Óзì϶ÀûÓû£¬£¬£¬£¬£¬£¬£¬ÈçCloudComputatingºÍOrigami ElephantµÈ¡£¡£¡£¡£¡£»£»£» £»£»£»£»£»¹½éÉÜÁËGamaredon×Ô5ÔÂÒÔÀ´Õë¶ÔÎÚ¿ËÀ¼µ±¾ÖµÄ¶ñÒâ»î¶¯£»£»£» £»£»£»£»£»HoneyMyteÕë¶ÔÄÏÑÇij¹úµÄ¹©¸øÁ´¹¥»÷»î¶¯£»£»£» £»£»£»£»£»ÒÔ¼°LyceumÕë¶ÔÍ»Äá˹º½¿ÕºÍµçÐÅÐÐÒµµÄ»î¶¯µÈ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/apt-trends-report-q3-2021/104708