ÓÎÏ·¹«Ë¾Ubisoft³ÆÅäÖôíÎóÎèÁ¦È«¿ªÍæ¼ÒµÄÊý¾Ýй¶

Ðû²¼Ê±¼ä 2021-12-24

ÓÎÏ·¹«Ë¾Ubisoft³ÆÅäÖôíÎóÎèÁ¦È«¿ªÍæ¼ÒµÄÊý¾Ýй¶


ÓÎÏ·¹«Ë¾Ubisoft³ÆÅäÖôíÎóÎèÁ¦È«¿ªÍæ¼ÒµÄÊý¾Ýй¶.png


·¨¹úÓÎÏ·¹«Ë¾Óý±Ì£¨Ubisoft£©ÔÚ12ÔÂ21ÈÕÐû²¼Í¨¸æ³Æ £¬ÎèÁ¦È«¿ªÍæ¼ÒµÄÊý¾ÝÒѾ­Ð¹Â¶¡£´Ë´ÎʼþÊÇÓÉÓÚÅäÖôíÎóµ¼ÖµÄ £¬ÎÊÌâÔÚ·¢ÏÖºóÁ¢¼´µÃµ½ÐÞ¸´¡£µ«ÔÚ´Ë֮ǰ £¬Î´¾­ÊÚȨµÄ¸öÈË¿ÉÄÜÒѾ­·ÃÎʲ¢¸´ÖƲ¿ÃÅÍæ¼ÒÊý¾Ý¡£¸Ã¹«Ë¾ÌåÏÖ £¬½ö¡°¼¼Êõ±êʶ·û¡±Êܵ½Ó°Ïì £¬°üÂÞÍæ¼Ò±êÇ©¡¢¸öÈË×ÊÁÏIDºÍÉ豸ID £¬ÒÔ¼°Â¼ÖƺÍÉÏ´«µÄÊÓƵµÈ £¬UbisoftµÄÈκÎÕÊ»§¾ùδÊܵ½Ó°Ïì¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/125885/data-breach/ubisoft-data-breach.html



CiscoÅû¶ÃÀ¹úGarettµÄ½ðÊô̽²âÆ÷ÖÐ9¸ö©¶´µÄϸ½Ú


CiscoÅû¶ÃÀ¹úGarettµÄ½ðÊô̽²âÆ÷ÖÐ9¸ö©¶´µÄϸ½Ú.png


12ÔÂ20ÈÕ £¬Cisco TalosÅû¶Garett²½ÐÐͨ¹ýʽ½ðÊô̽²âÆ÷ÖÐ9¸ö©¶´µÄϸ½Ú¡£GarrettÊÇÃÀ¹úÖøÃûµÄ½ðÊô̽²âÆ÷ÖÆÔìÉÌ £¬Æä²úÎïͨ³£²¿ÊðÔÚÖØÒª³¡ËùÖÐ £¬ÀýÈçÌåÓý³¡¹Ý¡¢»ú³¡¡¢ÒøÐС¢²©Îï¹Ý¡¢Õþ¸®²¿Ãźͷ¨ÔºµÈ¡£´Ë´ÎÐÞ¸´µÄ½ÏΪÑÏÖصÄ©¶´ÊÇ»ùÓÚ¶ÑÕ»µÄ»º³åÇøÒç³ö©¶´£¨CVE-2021-21901ºÍCVE-2021-21903£©ºÍĿ¼±éÀú©¶´£¨CVE-2021-21904£©¡£ÕâЩ©¶´ÓÚ8ÔÂ17ÈÕ±»Åû¶ £¬²¢ÓÚ12ÔÂ13ÈÕÐÞ¸´¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/walk-through-metal-detectors-software-flaws-hackable/



TheAnalyst·¢ÏÖ·Ö·¢Ð¶ñÒâÈí¼þDridexµÄµöÓã»î¶¯


TheAnalyst·¢ÏÖ·Ö·¢Ð¶ñÒâÈí¼þDridexµÄµöÓã»î¶¯.png


¾ÝýÌå12ÔÂ22ÈÕ±¨µÀ £¬TheAnalyst¹ûÈ»ÁË·Ö·¢Ð¶ñÒâÈí¼þDridexµÄµöÓã»î¶¯¡£´Ë´Î»î¶¯ÒÔ½â¹ÍÓʼþΪÓÕ¶ü £¬¼û¸æÊÕ¼þÈËËûÃǽ«ÓÚ12ÔÂ24ÈÕ±»½â¹Í £¬ÇҴ˾ö¶¨²»ÐÐÈ¡Ïû¡£ÓʼþÖл¹ÓÐÒ»¸öExcel±í¸ñTermLetter.xls  £¬¾Ý³ÆÆäÖаüÂÞÊÕ¼þÈ˱»½â¹ÍµÄÔ­Òò¡£ÊÕ¼þÈË´ò¿ªExcelÎļþºó»á¿´µ½Ò»¸öÄ£ºý²»ÇåµÄÈËÔ±±í £¬²¢±»ÒªÇóÆôÓÃÄÚÈÝÀ´ÕýÈ·¼ì²ìÎļþ¡£ÊÕ¼þÈËÆôÓÃÄÚÈݺó»áµ¯³ö´°¿ÚÏÔʾ¡°Ç×°®µÄÔ±¹¤Ê¥µ®¿ìÀÖ£¡¡± £¬Õâʱ¶ñÒâºêÒѱ»Ö´ÐС£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/dridex-malware-trolls-employees-with-fake-job-termination-emails/



Ñо¿ÍŶӷ¢ÏÖÀûÓÃTelegramÁ÷´«EchelonµÄ»î¶¯


Ñо¿ÍŶӷ¢ÏÖÀûÓÃTelegramÁ÷´«EchelonµÄ»î¶¯.png


12ÔÂ23ÈÕ £¬SafeGuard Cyber³ÆÆä·¢ÏÖÔÚTelegramÖзַ¢ÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þEchelonµÄ»î¶¯¡£¸ÃEchelonÑù±¾ÓÚ10Ô·ÝÊ״α»¼ì²âµ½ £¬ÀûÓÃSmokes NightµÄÃû³ÆÔÚ¹ØÓÚ¼ÓÃÜ»õ±ÒµÄƵµÀÀï½øÐÐÁ÷´«»î¶¯ £¬²¢½öÕë¶Ô¸ÃƵµÀµÄÐÂÓû§¡£¹¥»÷ÕßÀûÓÃ.RARÎļþpresent).RAR·Ö·¢Echelon £¬¸ÃÎļþ°üÂÞpass-123.txt¡¢DotNetZip.dllºÍPresent.exe 3¸öÎļþ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/telegram-steal-crypto-wallet-credentials/177266/



ÃÀ¹úÎ÷¸¥¼ªÄáÑÇÖÝÒ½ÁÆ»ú¹¹MHS³ÆÆäÔâµ½BEC¹¥»÷


ÃÀ¹úÎ÷¸¥¼ªÄáÑÇÖÝÒ½ÁÆ»ú¹¹MHS³ÆÆäÔâµ½BEC¹¥»÷.png


ÃÀ¹úÎ÷¸¥¼ªÄáÑÇÖݵÄMonongalia Health System(MHS)ÔÚ12ÔÂ21ÈÕÐû²¼Í¨¸æ £¬³ÆÆäÔâµ½ÁËBEC¹¥»÷¡£MHS¿ªÊ¼²¢²»ÖªµÀÆäÒÑÔâµ½¹¥»÷ £¬Ö±µ½Ò»¼Ò¹©Ó¦É̳ÆÔÚ½ñÄê7ÔÂ28ÈÕûÓÐÊÕµ½¸¶¿î £¬¸Ã»ú¹¹²Å¿ªÊ¼Õ¹¿ªÊӲ졣ÊӲ췢ÏÖ £¬¹¥»÷ÕßÔÚ5ÔÂ10ÈÕÖÁ8ÔÂ15ÈÕÈëÇÖÁ˶à¸öMHSÔ±¹¤µÄÓʼþÕÊ»§ £¬²¢·ÃÎÊÁËÓʼþ¼°Æ丽¼þ £¬È»ºóʹÓÃijMHS³Ð°üÉ̵ÄÕÊ»§Ã°³äMHSÀ´Æ­È¡×ʽð¡£´ËÍâ £¬¹¥»÷»¹Ð¹Â¶Á˲¿ÃÅ»¼ÕߺÍÔ±¹¤µÄÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/bec-attack-on-monongalia-health-1/



NCC GroupÐû²¼2021Äê11ÔÂÍøÂçÄþ¾²Ì¬ÊƵķÖÎö³ÂËß


NCC GroupÐû²¼2021Äê11ÔÂÍøÂçÄþ¾²Ì¬ÊƵķÖÎö³ÂËß.png


12ÔÂ21ÈÕ £¬NCC GroupÐû²¼2021Äê11ÔÂÍøÂçÄþ¾²Ì¬ÊƵķÖÎö³ÂËß¡£³ÂËßÖ¸³ö £¬¹¥»÷ÕßµÄÖصãÕýÔÚתÏò¹Ù·½×éÖ¯ £¬Óë10Ô·ÝÏà±È £¬´ËÀà×éÖ¯Ôâµ½µÄ¹¥»÷Ôö¼ÓÁË400%£»±¾ÔÂÀÕË÷¹¥»÷Ôö¼ÓÁË1.9%£»±±ÃÀºÍÅ·ÖÞÈÔÈ»ÊÇÊܹ¥»÷×î¶àµÄµØÓò £¬·Ö±ðÔâµ½154ºÍ96´Î¹¥»÷¡£11ÔµÄÖ÷ÒªÀÕË÷Èí¼þΪPYSA£¨Ò²±»³ÆΪMespinoza£©ºÍLockbit £¬ÆäÖÐPYSAµÄ¹¥»÷»î¶¯½ÏÖ®ÉÏÔÂÔö³¤50% £¬ÓâÔ½ÁËConti£¨Ï½µ9.1%£©¡£      


Ô­ÎÄÁ´½Ó£º

https://newsroom.nccgroup.com/news/ncc-group-monthly-threat-pulse-november-2021-439934