Positive TechnologiesÐû²¼RootkitÑݱäÇ÷ÊÆ³ÂËß

Ðû²¼Ê±¼ä 2021-11-10

Robinhoodƽ̨³ÆÒòÔâµ½¹¥»÷700Íò¿Í»§ÐÅϢй¶


Robinhoodƽ̨³ÆÒòÔâµ½¹¥»÷700Íò¿Í»§ÐÅϢй¶.png


¹ÉƱ½»Òׯ½Ì¨RobinhoodÔÚ11ÔÂ8ÈÕÐû²¼Í¨¸æ£¬Éù³ÆÆäÔâµ½ÁËÍøÂç¹¥»÷¡£¹¥»÷·¢ÉúÔÚ11ÔÂ3ÈÕ£¬¹¥»÷Õßͨ¹ýÉç»á¹¤³Ì¹¥»÷»ñµÃÁ˿ͻ§Ö§³ÖϵͳµÄ·ÃÎÊȨÏÞ£¬¿ÉÄÜÒѾ­·ÃÎÊÁËÔ¼700Íò¿Í»§µÄÊý¾Ý£¬Éæ¼°ÐÕÃû¡¢ÓʼþµØÖ·¡¢³öÉúÈÕÆÚºÍÓÊÕþ±àÂëµÈÐÅÏ¢¡£´ËÍ⣬RobinHoodÌåÏÖËûÃÇ»¹Ôâµ½ÁËÀÕË÷£¬µ«²¢Î´ÌṩÓйØÀÕË÷ÒªÇóµÄϸ½ÚÐÅÏ¢¡£Ä¿Ç°£¬¸Ã¹«Ë¾ÕýÔÚÄþ¾²¹«Ë¾MandiantµÄЭÖú϶ԴËÊÂÕ¹¿ªÊӲ졣


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/robinhood-discloses-data-breach-impacting-7-million-customers/


¶à¹úÖ´·¨²¿ÃÅÕ¹¿ªµÄCycloneÐж¯Àֳɹ¥»÷ClopÍÅ»ï


¶à¹úÖ´·¨²¿ÃÅÕ¹¿ªµÄCycloneÐж¯Àֳɹ¥»÷ClopÍÅ»ï.png


ÉÏÖÜÎ壬Ïà¹Ø²¿ÃŹûÈ»Á˹ØÓÚCycloneÐж¯µÄ×îÐÂÏûÏ¢¡£ÕâÊÇΪÆÚ30¸öÔµĹú¼ÊÖ´·¨Ðж¯£¬Óɹú¼ÊÐ̾¯×é֯Эµ÷£¬²¢ÁªºÏÁËÎÚ¿ËÀ¼ºÍÃÀ¹úÖ´·¨²¿ÃÅ¡£Ðж¯µÄÖ÷ҪĿ±êÊÇClop£¬ËüÔø¶à´Î¹¥»÷Á˺«¹úµÄ¹«Ë¾ºÍÃÀ¹úµÄѧÊõ»ú¹¹¡£CycloneÐж¯»ñµÃÁËCDI¡¢Kaspersky¡¢FortinetºÍGroup-IBµÈ¹«Ë¾µÄ×ÊÖú£¬ÔÚÎÚ¿ËÀ¼´þ²¶ÁË6ÃûÏÓÒÉÈË£¬²¢Ã»ÊÕÁË185000ÃÀÔªµÄÏÖ½ð¡£Èç¹û×ïÃû½¨Á¢£¬Õâ6¸öÏÓÒÉÈ˽«ÃæÁÙ×î¸ß°ËÄêµÄ¼à½û¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/operation-cyclone-deals-blow-to-clop-ransomware-operation/


unit42Åû¶ÀûÓé¶´CVE-2021-40539µÄ¹¥»÷ϸ½Ú


unit42Åû¶ÀûÓé¶´CVE-2021-40539µÄ¹¥»÷ϸ½Ú.png


unit42ÔÚ11ÔÂ7ÈÕÅû¶ÁËÀûÓÃManageEngine ADSelfService PlusÖЩ¶´CVE-2021-40539µÄ¹¥»÷ϸ½Ú¡£9ÔÂ16ÈÕ£¬CISAÔøÐû²¼¾¯±¨³ÆAPT×éÖ¯ÕýÔÚÀûÓøÃ©¶´¹¥»÷Êý°Ù¸öÒ×Êܹ¥»÷µÄ×éÖ¯¡£¹¥»÷¿ªÊ¼ÓÚ9ÔÂ22ÈÕ£¬Õë¶ÔÈ«Çò·¶Î§ÄڵĹú·À¡¢Ò½ÁƱ£½¡¡¢ÄÜÔ´ºÍ½ÌÓýÐÐÒµµÈÖÁÉÙÓоŸöÐÐÒµ¡£ÔÚ©¶´ÀûÓÃÀÖ³ÉÖ®ºó£¬¹¥»÷Õ߻ᰲװGodzilla webshell¡£Ä¿Ç°£¬Éв»Çå³þ»î¶¯±³ºóµÄ¹¥»÷ÍŻµ«»òÐíÓëAPT27£¨Emissary Panda£©ÓйØ¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/manageengine-godzilla-nglite-kdcsponge/


DetectifyÐÂÑо¿·¢ÏÖSSLÖ¤Êé¿ÉÄÜ»áй¶Ãô¸ÐÐÅÏ¢


DetectifyÐÂÑо¿·¢ÏÖSSLÖ¤Êé¿ÉÄÜ»áй¶Ãô¸ÐÐÅÏ¢.png


Detectify 11ÔÂ4ÈÕµÄ×îÐÂÑо¿·¢ÏÖ£¬SSLÖ¤Êé¿ÉÄÜ»áй¶Ãô¸ÐÐÅÏ¢¡£×Ô7Ô·ÝÒÔÀ´£¬DetectifyÒѾ­ÊÕ¼¯ºÍ·ÖÎöÁËÁè¼Ý9ÒÚ¸ö¹«¹²SSL/TLSÖ¤Ê飬²¢·¢ÏÖÆäÖдæÔڵġ°ÏÝÚ塱¿ÉÄÜ»áй¶¹«Ë¾µÄ»úÃÜÐÅÏ¢¡£¾ø´ó¶àÊýÐÂÈÏÖ¤µÄÓò¶¼±»¸³ÓèÁËÃèÊöÐÔÃû³Æ£¬Èç¹ûÖ¤ÊéÊÇÔÚ¹ûȻǰµÄ¿ª·¢½×¶Î·¢±íµÄ£¬¿ÉÄÜÈþºÕù¶ÔÊÖÓÐʱ¼äÔÚвúÎï½øÈëÊг¡Ö®Ç°½øÐÐÆÆ»µ¡£´ËÍ⣬ͨÅä·ûÖ¤Êé¿ÉÄÜ»áÊܵ½ALPACA¹¥»÷µÄÓ°Ïì¡£


Ô­ÎÄÁ´½Ó£º

https://blog.detectify.com/2021/11/04/new-research-are-ssl-certificates-leaking-company-secrets/


Intel 471Ðû²¼Õë¶Ô½»Í¨ÔËÊäÐÐÒµµÄ¹¥»÷µÄ·ÖÎö³ÂËß


Intel 471Ðû²¼Õë¶Ô½»Í¨ÔËÊäÐÐÒµµÄ¹¥»÷µÄ·ÖÎö³ÂËß.png


Intel 471ÔÚ11ÔÂ2ÈÕÐû²¼ÁËÕë¶Ô½»Í¨ÔËÊäÐÐÒµµÄ¹¥»÷µÄ·ÖÎö³ÂËß¡£Ñо¿ÈËÔ±·¢ÏÖ£¬´óÁ¿ºÚ¿ÍÔÚ°µÍø³öÊÛÔËÊäºÍÎïÁ÷×éÖ¯µÄ·ÃÎÊȨÏÞ£¬²¢ÍƶÏËûÃÇÊÇÀûÓÃÔ¶³Ì·ÃÎʽâ¾ö·½°¸£¨°üÂÞÔ¶³Ì×ÀÃæÐ­ÒéRDP¡¢VPN¡¢CitrixºÍSonicWallµÈ£©ÖеÄ©¶´»ñµÃµÄ¡£³ÂËßÖ¸³ö£¬ÎïÁ÷ÐÐÒµÖð½¥³ÉΪ¹¥»÷Ä¿±ê£¬¹¥»÷¿ÉÄÜ»á¶ÔÈ«Çò¾­¼ÃÔì³ÉÑÏÖØµÄÁ¬Ëø·´Ó³£¬Ò»´ÎÀֳɵĹ¥»÷¿ÉÄÜ»áʹÕû¸öÐÐҵͣÖÍ£¬Òò´ËÏà¹Ø×éÖ¯ÒªÖ÷¶¯ÐÞ¸´Â©¶´ÒÔÖÆÖ¹´ËÀ๥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://intel471.com/blog/shipping-companies-ransomware-credentials


Positive TechnologiesÐû²¼RootkitÑݱäÇ÷ÊÆ³ÂËß


Positive TechnologiesÐû²¼RootkitÑݱäÇ÷ÊÆ³ÂËß.png


Positive TechnologiesÔÚ11ÔÂ3ÈÕÐû²¼ÁËRootkitµÄÑݱäÇ÷ÊÆºÍµ±Ç°ÍþвµÄ·ÖÎö³ÂËß¡£Ñо¿ÈËÔ±·ÖÎöÁ˽ü10Äê×îÖøÃûµÄ16¸örootkit¼Ò×壬·¢ÏÖÆäÖеÄ44%ÓÃÓÚ¹¥»÷Õþ¸®»ú¹¹£¬ 77%±»ÓÃÓÚÍøÂç¼äµý»î¶¯¡£´ËÍ⣬rootkitºÜÄÑ¿ª·¢£¬ÐèÒª»¨·ÑºÜ¶àʱ¼äºÍ½ðÇ®£¬Òò´Ë´ó¶àÊý»ùÓÚrootkitµÄ¹¥»÷¶¼ÓëAPT×éÖ¯ÓйØ¡£ËùÓеÄrootkitÖÐ38%ÊôÓÚÄÚºËģʽ£¬31%ÊÇÓû§Ä£Ê½£¬31%ÊÇ×éºÏÀàÐÍ£¬ÇÒ´ó²¿ÃÅÕë¶ÔWindowsϵͳ¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.ptsecurity.com/ww-en/analytics/rootkits-evolution-and-detection-methods/