KasperskyÐû²¼Q3ÆÊÎö±¨¸æ£ºAppleÐû²¼Çå¾²¸üÐÂÐÞ¸´iOSÎó²î

Ðû²¼Ê±¼ä 2021-10-29

ÀÕË÷ÔËÓªÍÅ»ïGrief³ÆÒÑÈëÇÖÃÀ¹ú²½Ç¹Ð­»áNRAµÄϵͳ


ÀÕË÷ÔËÓªÍÅ»ïGrief³ÆÒÑÈëÇÖÃÀ¹ú²½Ç¹Ð­»áNRAµÄϵͳ.png


10ÔÂ27ÈÕ£¬ £¬£¬£¬ £¬£¬ÀÕË÷ÔËÓªÍÅ»ïGriefÔÚÆäÊý¾ÝÐ¹Â¶ÍøÕ¾ÉÏÐû²¼ÒÑÈëÇÖÃÀ¹ú²½Ç¹Ð­»áNRAµÄϵͳ¡£¡£¡£ ¡£¡£¡£¡£¹¥»÷Õß¹ûÕæÁËÒ»¸ö2.7 MBµÄÎļþNational Grants.zip×÷ΪÑù±¾£¬ £¬£¬£¬ £¬£¬ÆäÖÐÉæ¼°NRA²¦¿îÉêÇëµÈÐÅÏ¢£¬ £¬£¬£¬ £¬£¬ÒÔ¼°°üÀ¨ÁË˰ÎñÐÅÏ¢ºÍͶ×ʽð¶îExcel±í¸ñµÄ½ØÍ¼¡£¡£¡£ ¡£¡£¡£¡£ÏÖÔÚ£¬ £¬£¬£¬ £¬£¬NRA²¢Î´¶Ô´ËÊÂ×÷³ö̸ÂÛ¡£¡£¡£ ¡£¡£¡£¡£¾ÝÐÅ£¬ £¬£¬£¬ £¬£¬GriefÍÅ»ïÓë¶íÂÞ˹Evil CorpÓйأ¬ £¬£¬£¬ £¬£¬ºóÕßΪÁËÌÓ±ÜÖÆ²ÃʹÓÃÁËWastedLocker¡¢HadesºÍPhoenix LockerµÈ¶à¸öÀÕË÷Èí¼þ¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/123849/cyber-crime/grief-ransomware-hit-nra.html


Abnormal·¢Ã÷½üÆÚʹÓÃQRÂëÈÆ¹ýURL¼ì²âµÄ´¹Âڻ


Abnormal·¢Ã÷½üÆÚʹÓÃQRÂëÈÆ¹ýURL¼ì²âµÄ´¹Âڻ.png


AbnormalÑо¿ÍŶÓÓÚ10ÔÂ26ÈÕÅû¶ÁËÖ¼ÔÚÍøÂçMicrosoftƾ֤µÄ´¹Âڻ¡£¡£¡£ ¡£¡£¡£¡£´Ë´Î»î¶¯±¬·¢ÔÚ2021Äê9ÔÂ15ÈÕÖÁ10ÔÂ13ÈÕʱ´ú£¬ £¬£¬£¬ £¬£¬ÆäÆæÒìÖ®´¦ÔÚÓÚ£¬ £¬£¬£¬ £¬£¬´¹ÂÚÓʼþ¶¼Ê¹ÓÃÁËQRÂëÀ´ÈƹýÇå¾²ÓʼþÍø¹ØÖÐÕë¶ÔÓʼþ¸½¼þURLµÄɨÃ蹦Ч¡£¡£¡£ ¡£¡£¡£¡£²¢ÇÒ£¬ £¬£¬£¬ £¬£¬ËùÓÐQRÂë¶¼ÊÇÔÚ·¢Ë͵±Ì콨ÉèµÄ£¬ £¬£¬£¬ £¬£¬ÕâʹµÃ´Ë´Î»î¶¯ºÜÄѱ»¼ì²âµ½»ò±»×èÖ¹Áбíʶ±ð¡£¡£¡£ ¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÁËÆóÒµÊÓ²ìЧÀÍÒÔ¼°ÑÇÂíÑ·ºÍ¹È¸èЧÀÍÀ´Íйܴ¹ÂÚÒ³Ãæ£¬ £¬£¬£¬ £¬£¬»¹Ê¹ÓÃÁËÕýµ±µÄOutlookÕÊ»§À´Èƹý¼ì²â¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://abnormalsecurity.com/blog/qr-code-campaign-bypass-security


кڿÍÍÅ»ïTA2722ð³ä·ÆÂɱö¹Ù·½×éÖ¯·Ö·¢¶à¸öRAT


кڿÍÍÅ»ïTA2722ð³ä·ÆÂɱö¹Ù·½×éÖ¯·Ö·¢¶à¸öRAT.png


ProofpointÔÚ10ÔÂ27ÈÕ·¢Ã÷ÁËÒ»¸öеĺڿÍÍÅ»ïTA2722£¨Óֳƣ¬ £¬£¬£¬ £¬£¬Balikbayan Foxes£©¡£¡£¡£ ¡£¡£¡£¡£ÔÚ2021ÄêµÄ»î¶¯ÖУ¬ £¬£¬£¬ £¬£¬Ëüð³äÁ˶à¸ö·ÆÂɱö¹Ù·½×éÖ¯£¬ £¬£¬£¬ £¬£¬°üÀ¨ÎÀÉú²¿¡¢·ÆÂɱöÍâÑó¾ÍÒµÖÎÀí¾Ö(POEA)ºÍº£¹Ø¾ÖµÈ£¬ £¬£¬£¬ £¬£¬Ö÷ÒªÕë¶Ô±±ÃÀ¡¢Å·Ö޺Ͷ«ÄÏÑǵĺ½ÔË¡¢ÎïÁ÷¡¢ÖÆÔì¡¢ÉÌҵЧÀÍ¡¢ÖÆÒ©¡¢ÄÜÔ´ºÍ½ðÈÚµÈÐÐÒµ¡£¡£¡£ ¡£¡£¡£¡£±ðµÄ£¬ £¬£¬£¬ £¬£¬ÕâЩ»î¶¯¶¼·Ö·¢ÁËÔ¶³Ì»á¼ûľÂíRemcosºÍNanoCore¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.proofpoint.com/us/blog/threat-insight/new-threat-actor-spoofs-philippine-government-covid-19-health-data-widespread


AppleÐû²¼Çå¾²¸üУ¬ £¬£¬£¬ £¬£¬ÐÞ¸´iOSµÈ¶à¿î²úÆ·ÖеÄÎó²î


AppleÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´iOSµÈ¶à¿î²úÆ·ÖеÄÎó²î.png


AppleÔÚ10ÔÂ25ºÍ26ÈÕÐû²¼Çå¾²¸üУ¬ £¬£¬£¬ £¬£¬ÐÞ¸´ÁËiOSµÈ¶à¿î²úÆ·ÖеÄÎó²î¡£¡£¡£ ¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄ×îΪÑÏÖØµÄÊÇApple TV IOMobileFrameBufferÖеÄÄÚ´æËð»µÎó²îCVE-2021-30883£¬ £¬£¬£¬ £¬£¬Ëü¿ÉÄÜÒѾ­±»ÔÚҰʹÓ㬠£¬£¬£¬ £¬£¬ZecOpsÌåÏÖ¸ÃÎó²î¿É±»ÓÃÓÚ1-clickºÍË®¿Ó¹¥»÷¡£¡£¡£ ¡£¡£¡£¡£±ðµÄ£¬ £¬£¬£¬ £¬£¬¸üл¹ÐÞ¸´ÁË´úÂëÖ´ÐÐÎó²îCVE-2021-30919ºÍCVE-2021-30917¡¢ÌáȨÎó²îCVE-2021-30873ºÍÔ½½ç¶ÁÈ¡Îó²îCVE-2021-30905µÈ¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/10/27/apple-releases-security-updates-multiple-products


GoogleÐû²¼½ôÆÈ¸üУ¬ £¬£¬£¬ £¬£¬ÐÞ¸´ChromeÒѱ»Ê¹ÓõÄ0day


GoogleÐû²¼½ôÆÈ¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´ChromeÒѱ»Ê¹ÓõÄ0day.png


GoogleÔÚ10ÔÂ28ÈÕÐû²¼µÄ½ôÆÈ¸üÐÂÐÞ¸´ÁËChromeÖеÄ8¸öÎó²î£¬ £¬£¬£¬ £¬£¬ÆäÖаüÀ¨2¸öÒѱ»ÔÚҰʹÓõÄ0day¡£¡£¡£ ¡£¡£¡£¡£Õâ2¸ö0day»®·ÖΪIntentsÖйØÓÚÊäÈëµÄÑé֤ȱ·¦Îó²îCVE-2021-38000£¬ £¬£¬£¬ £¬£¬ºÍChrome V8 JavaScriptÒýÇæÖеÄʵÏÖ²»µ±Îó²îCVE-2021-38003¡£¡£¡£ ¡£¡£¡£¡£±ðµÄ£¬ £¬£¬£¬ £¬£¬»¹ÐÞ¸´ÁËÊͷźóʹÓÃÎó²îCVE-2021-37997¡¢CVE-2021-37998ºÍCVE-2021-38002£¬ £¬£¬£¬ £¬£¬ÒÔ¼°V8ÖеÄÀàÐÍ»ìÏýCVE-2021-38001µÈÎó²î¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/google/emergency-google-chrome-update-fixes-zero-days-used-in-attacks/


KasperskyÐû²¼2021ÄêQ3 APT¹¥»÷»î¶¯µÄÆÊÎö±¨¸æ


KasperskyÐû²¼2021ÄêQ3 APT¹¥»÷»î¶¯µÄÆÊÎö±¨¸æ.png


10ÔÂ26ÈÕ£¬ £¬£¬£¬ £¬£¬KasperskyµÄÈ«ÇòÑо¿ÓëÆÊÎöÍŶÓ(GReAT)Ðû²¼ÁË2021ÄêQ3 APT¹¥»÷»î¶¯µÄÆÊÎö±¨¸æ¡£¡£¡£ ¡£¡£¡£¡£±¨¸æÖ¸³öµÚÈý¼¾¶ÈµÄÖ÷ÒªÇ÷ÊÆ°üÀ¨£¬ £¬£¬£¬ £¬£¬¹©Ó¦Á´¹¥»÷»î¶¯Ê¼ÖÕÔÚÒ»Á¬£¬ £¬£¬£¬ £¬£¬ÀýÈçSmudgeX¡¢DarkHaloºÍLazarusµÄ¹¥»÷£»£»£»£»£»£»Éç»á¹¤³ÌѧÈÔÈ»ÊÇÖ÷Òª¹¥»÷ÒªÁ죬 £¬£¬£¬ £¬£¬µ«Ò²ÓÐÎó²îʹÓû£¬ £¬£¬£¬ £¬£¬ÈçCloudComputatingºÍOrigami ElephantµÈ¡£¡£¡£ ¡£¡£¡£¡£»£»£»£»£»£»¹ÏÈÈÝÁËGamaredon×Ô5ÔÂÒÔÀ´Õë¶ÔÎÚ¿ËÀ¼Õþ¸®µÄ¶ñÒâ»î¶¯£»£»£»£»£»£»HoneyMyteÕë¶ÔÄÏÑÇij¹úµÄ¹©Ó¦Á´¹¥»÷»î¶¯£»£»£»£»£»£»ÒÔ¼°LyceumÕë¶ÔÍ»Äá˹º½¿ÕºÍµçÐÅÐÐÒµµÄ»î¶¯µÈ¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/apt-trends-report-q3-2021/104708