DevolutionsÐû²¼2021ÄêÖÐСÐÍÆóÒµÄþ¾²Ì¬ÊƵijÂËß
Ðû²¼Ê±¼ä 2021-11-24RedCurlÍÅ»ï»Ø¹é£¬ÐµĹ¥»÷Ä¿±êÉæ¼°¸÷Ðи÷Òµ
Group-IBÔÚ11ÔÂ18ÈÕÅû¶Á˺ڿÍÍÅ»ïRedCurlµÄл¡£ÍøÂç¼äµýºÚ¿Í×éÖ¯RedCurlÔÚ2018ÄêÖÁ2020ÄêÆÚ¼ä£¬ÌᳫÁËÖÁÉÙ26´Î¹¥»÷£¬Éæ¼°Ó¢¹ú¡¢µÂ¹ú¡¢¼ÓÄôó¡¢Å²Íþ¡¢¶íÂÞ˹ºÍÎÚ¿ËÀ¼µÈµØÓòµÄ½¨Öþ¡¢½ðÈÚ¡¢×Éѯ¡¢ÁãÊÛ¡¢±£ÏÕºÍÖ´·¨ÐÐÒµµÄ¹«Ë¾¡£¸ÃÍÅ»ïÔÚÖжÏ7¸öÔºó¾íÍÁÖØÀ´£¬×Ô2021Äê³õÒÔÀ´Õë¶Ô4¼Ò¹«Ë¾ÌᳫÁËÐµĹ¥»÷£¬ÆäÖаüÂÞ¶íÂÞ˹×î´óµÄÅú·¢É̵ꡣGroup-IB³Æ£¬RedCurlÔÚÿ´Î¹¥»÷Öж¼ÊÐʹÓÃÆä×Ô½ç˵¶ñÒâÈí¼þÈÆ¹ý¼ì²â¡£
ÔÎÄÁ´½Ó£º
https://www.group-ib.com/media/red-curl-threat-report/
Ñо¿ÈËÔ±ÑÝʾеÄSAD DNS»º´æÖж¾¹¥»÷ģʽ
¼ÓÖÝ´óѧÑо¿ÈËÔ±ÔÚ11ÔÂ18ÈÕÑÝʾÁËÒ»ÖÖеÄSAD DNS»º´æÖж¾¹¥»÷ģʽ¡£SAD DNS£¨Side channel AttackeD DNS£©ÓÚ2020Äê11ÔÂÊ×´ÎÅû¶£¬ËüÒÀÀµICMPµÄ¡°port unreachable¡±ÏûÏ¢À´ÍƶÏʹÓÃÄĸöÁÙʱ¶Ë¿Ú¡£ÀûÓô˹¥»÷ģʽ¿É½«¶ñÒâµÄDNS¼Ç¼עÈëDNS»º´æ£¬È»ºó½«Ä¿±êÁ÷Á¿Öض¨Ïòµ½¹¥»÷ÕߵķþÎñÆ÷ÖУ¬½øÐÐÖмäÈË(MITM)¹¥»÷¡£Ñо¿ÈËÔ±³Æ£¬´ËÖÖ¹¥»÷´æÔÚÓÚLinuxÉÏÔËÐеÄBIND¡¢UnboundºÍdnsmasqµÈDNSÈí¼þÖУ¬Ó°ÏìÔ¼38%µÄÓòÃû½âÎöÆ÷¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/11/new-side-channel-attacks-re-enable.html
ÃÀ¹ú֤ȯ½»Ò×ίԱ»á·¢ÏÖð³äÆäÔ±¹¤µÄµöÓã»î¶¯
ÃÀ¹ú֤ȯ½»Ò×ίԱ»á(SEC)Ͷ×ÊÕß½ÌÓýºÍÐû´«°ì¹«ÊÒ(OIEA)ÓÚ11ÔÂ19ÈÕÐû²¼¾¯±¨£¬³Æ·¢ÏÖð³äSECÔ±¹¤µÄ»î¶¯¡£¹¥»÷Õßͨ¹ýµç»°¡¢ÓïÒôÓʼþ¡¢µç×ÓÓʼþºÍÐżþ£¬¾¯¸æÊÕ¼þÈËÆä»îÆÚ´æ¿î»ò¼ÓÃÜ»õ±ÒµÄÕË»§ÖдæÔÚδ¾ÊÚȨµÄ½»Ò×»òÆäËû¿ÉÒɻ£¬²¢Ë÷ÒªÆä¹ÉȨ¡¢Õʺš¢PINÂë¡¢ÃÜÂëµÈÐÅÏ¢¡£OIEA½¨ÒéÓû§ÔÚ·¢Ë͸öÈËÐÅϢ֮ǰ£¬Ó¦ÏÈͨ¹ýÓʼþ»òÖµçSECÈ·¶¨·¢¼þÈ˵ÄÉí·Ý¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/us-sec-warns-investors-of-ongoing-govt-impersonation-attacks/
ÓÌËûÖÝÒ½ÁÆÖÐÐÄUIA½ü60Íò»¼ÕߵĸöÈËÐÅϢй¶
11ÔÂ18ÈÕ£¬ÃÀ¹úÓÌËûÖÝ·ÅÉäÖÐÐÄUtah Imaging Associates(UIA)È·ÈÏ582170»¼ÕߵĸöÈËÐÅϢй¶¡£Ð¹Â¶Ê¼þ·¢ÉúÔÚ8ÔÂ29ÈÕ£¬Êý¾ÝÔÚ̻¶ԼһÖܺó£¬ÓÚ9ÔÂ4ÈÕ±»·¢ÏÖ²¢ÓÚͬÈÕÐÞ¸´¡£´Ë´Îй¶ÁË»¼ÕßµÄÐÕÃû¡¢µØÖ·¡¢³öÉúÈÕÆÚ¡¢Éç»áÄþ¾²ºÅÂë¡¢½¡¿µ±£ÏÕµ¥ºÅºÍÒ½ÁÆÐÅÏ¢µÈ¡£Ñо¿ÈËÔ±ÌåÏÖ£¬¹¥»÷ÕßÇãÏòÓÚ¹¥»÷ÏñUIAÕâÑùµÄÒ½ÁÆÖÐÐÄ£¬ÊÇÒòΪËûÃÇÈÏΪ´ËÀàÊý¾ÝÔÚ°µÍøÖеļÛÖµ¸ü¸ß¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/utah-medical-center-hit-by-data-breach-affecting-582k-patients/
ProdaftÐû²¼¹ØÓÚÀÕË÷ÔËÓªÍÅ»ïContiµÄ·ÖÎö³ÂËß
ProdaftÓÚ11ÔÂ18ÈÕÐû²¼Á˹ØÓÚÀÕË÷ÔËÓªÍÅ»ïContiµÄÉî¶È·ÖÎö³ÂËß¡£ContiÊÇ˽ÓÐRaaS£¬ÓÚ2019Äê12Ôµ×Ê״ηºÆð£¬²¢Í¨¹ýTrickBot½øÐÐÁ÷´«¡£³ÂËßÖ¸³ö£¬×Ô2021Äê7ÔÂÒÔÀ´£¬Conti´ÓÊê½ðÖлñÀûÖÁÉÙ2550ÍòÃÀÔª£¬¶øContiÍÅ»ïÔòÉù³ÆÒÑ»ñÀû3ÒÚÃÀÔª¡£´ËÍ⣬Prodaft»¹¹ûÈ»ÁËContiµÄÖ§¸¶ÍøÕ¾£¬Æä·þÎñÆ÷ÍйÜÔÚ217.12.204.135ÉÏ£¬¸ÃIPµØÖ·ÊôÓÚÎÚ¿ËÀ¼ÍøITL LLC¡£ÔڸóÂËßÐû²¼¼¸Ð¡Ê±ºó£¬ContiÍÅ»ï¾Í½«ÆäÖ§¸¶ÍøÕ¾¹Ø±Õ¡£
ÔÎÄÁ´½Ó£º
https://www.prodaft.com/resource/detail/conti-ransomware-group-depth-analysis
DevolutionsÐû²¼2021ÄêÖÐСÐÍÆóÒµÄþ¾²Ì¬ÊƵijÂËß
DevolutionsÔÚ11ÔÂ17ÈÕÐû²¼ÁË2021ÄêÖÐСÐÍÆóÒµÄþ¾²Ì¬ÊƵÄÑо¿³ÂËß¡£¸ÃÑо¿¾ÍÎå¸öºËÐÄÖ÷Ì⣺ÖÐСÆóÒµµÄÍøÂç¹¥»÷ºÍÍþв¡¢ÃÜÂë¹ÜÀí¡¢Ê¹ÓõÄÌØÈ¨·ÃÎʹÜÀí¡¢Äþ¾²ÅàѵºÍ¹ÜÀíÒÔ¼°Äþ¾²Í¶×ʽøÐÐÁË·ÖÎö¡£³ÂËßÖ¸³ö£¬ÓëÈ¥ÄêÏà±È£¬72%µÄÖÐСÆóҵĿǰԽ·¢ÌåÌùÍøÂçÄþ¾²£»¹ÜÀíÕß×îµ£ÓǵÄÍøÂçÍþвÊÇÀÕË÷Èí¼þ¡¢ÍøÂçµöÓãºÍ¶ñÒâÈí¼þ£»52%µÄÆóÒµÔÚÈ¥ÄêÔâµ½¹ýÍøÂç¹¥»÷£»Ö»ÓÐ13%µÄÆóÒµÓµÓÐÍêÕûµÄPAM½â¾ö·½°¸¡£
ÔÎÄÁ´½Ó£º
https://blog.devolutions.net/2021/11/new-now-available-devolutions-state-of-cybersecurity-in-smbs-in-2021-2022-report