AtlasÐû²¼2021ÄêH1Îó²îÆÊÎö±¨¸æ£ºWindows WPBTÖеÄÐÂÎó²îÓ°ÏìWin8

Ðû²¼Ê±¼ä 2021-09-28

Windows WPBTÖеÄÐÂÎó²îÓ°ÏìWin8¼°Ö®ºóËùÓÐϵͳ


Windows WPBTÖеÄÐÂÎó²îÓ°ÏìWin8¼°Ö®ºóËùÓÐϵͳ.png


EclypsiumÑо¿ÍŶӷ¢Ã÷Microsoft Windowsƽ̨¶þ½øÖƱí(WPBT)Öб£´æÒ»¸öÎó²î£¬£¬ £¬ £¬¿ÉÓÃÀ´ÔÚϵͳÉÏ×°ÖÃRootkit¡£¡£¡£ ¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÁË2012ÄêÖ®ºó¿¯ÐеÄWindows 8¼°¸ü¸ß°æ±¾µÄËùÓÐϵͳ£¬£¬ £¬ £¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚϵͳÆô¶¯Ê±ÒÔÄÚºËȨÏÞÔËÐжñÒâ´úÂë¡£¡£¡£ ¡£¡£¡£¡£Î¢ÈíÌá³öµÄ»º½â²½·¥°üÀ¨Ê¹ÓÃWindows DefenderÓ¦ÓóÌÐò¿ØÖÆ£¨WDAC£©Õ½ÂÔÀ´¿ØÖÆÔÚϵͳÖÐÔËÐеĶþ½øÖÆÎļþ£¬£¬ £¬ £¬»òʹÓÃAppLockerÕ½ÂÔÀ´¿ØÖÆÔÊÐíÔËÐеÄÓ¦Óᣡ£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-wpbt-flaw-lets-hackers-install-rootkits-on-windows-devices/


Å·ÖÞºô½ÐÖÐÐũӦÉÌGSSÔâµ½ContiÍÅ»ïµÄÀÕË÷¹¥»÷


Å·ÖÞºô½ÐÖÐÐũӦÉÌGSSÔâµ½ContiÍÅ»ïµÄÀÕË÷¹¥»÷.png


Covisian½²»°È˳Æ£¬£¬ £¬ £¬ÆäÎ÷°àÑÀºÍÀ­¶¡ÃÀÖÞ·Ö²¿GSSÓÚ9ÔÂ18ÈÕÔâµ½ÁËContiÍÅ»ïµÄÀÕË÷¹¥»÷¡£¡£¡£ ¡£¡£¡£¡£CovisianÊÇÅ·ÖÞ×î´óµÄ¿Í»§Ð§Àͺͺô½ÐÖÐÐũӦÉÌÖ®Ò»£¬£¬ £¬ £¬´Ë´Î¹¥»÷µ¼ÖÂÆä´ó²¿·ÖϵͳÖÐÖ¹£¬£¬ £¬ £¬Ó°ÏìÁËVodafone Spain¡¢MasMovil ISP¡¢ÂíµÂÀïµÄ¹©Ë®¹«Ë¾ºÍµçÊǪ́µÈ¹«Ë¾ºÍ×éÖ¯¡£¡£¡£ ¡£¡£¡£¡£²»¾Ãǰ£¬£¬ £¬ £¬ÃÀ¹úµÄºô½ÐÖÐÐĺͿͻ§Ö§³ÖЧÀ͹©Ó¦ÉÌTTECÒ²Ôâµ½ÁËÀÕË÷¹¥»÷¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/122570/cyber-crime/gss-ransomware-attack.html



·ÇÖÞÒøÐÐÒòÏàÖúͬ°éÔâµ½¹¥»÷µ¼Ö²¿·Ö¿Í»§ÐÅϢй¶


·ÇÖÞÒøÐÐÒòÏàÖúͬ°éÔâµ½¹¥»÷µ¼Ö²¿·Ö¿Í»§ÐÅϢй¶.png


·ÇÖÞÒøÐÐÔÚÉÏÖÜÈýÈ·ÈÏÒòÆäÕ®Îñ×·»ØÏàÖúͬ°éDebt-INÔâµ½¹¥»÷£¬£¬ £¬ £¬µ¼Ö²¿·Ö¿Í»§ÐÅϢй¶¡£¡£¡£ ¡£¡£¡£¡£Debt-InÔøÔÚ½ñÄê4Ô·ÝÔâµ½ÀÕË÷¹¥»÷£¬£¬ £¬ £¬ÆäʱÑо¿Ö°Ô±¸ø³öµÄ½áÂÛÊÇûÓÐÖ¤¾ÝÅú×¢±£´æÊý¾Ýй¶ÎÊÌâ¡£¡£¡£ ¡£¡£¡£¡£È»¶ø£¬£¬ £¬ £¬Debt-InÏÖÔÚÒâʶµ½²¿·Ö¿Í»§µÄÐÅÏ¢ÒÑй¶£¬£¬ £¬ £¬°üÀ¨·ÇÖÞÒøÐеĴû¿î¿Í»§£¬£¬ £¬ £¬µ«2021Äê4ÔÂ1ÈÕÖ®ºóµÄÊý¾Ý²¢Î´Êܵ½Ó°Ïì¡£¡£¡£ ¡£¡£¡£¡£¸ÃÒøÐгÆ£¬£¬ £¬ £¬ÈôÊǿͻ§ÒÔΪÐÅÏ¢Òѱ»µÁÓ㬣¬ £¬ £¬¿ÉÏòÄÏ·ÇڲƭԤ·ÀЧÀÍÖÐÐÄ(SAFPS)ÉêÇëÃâ·ÑµÄ±£»£»£»¤Ð§ÀÍ¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2021/09/african-bank-alerts-of-data-breach-with.html



Desorden³ÆÒÑÇÔÈ¡ÂíÀ´Î÷ÑÇABX Express 200GBÊý¾Ý


Desorden³ÆÒÑÇÔÈ¡ÂíÀ´Î÷ÑÇABX Express 200GBÊý¾Ý.png


DesordenÉù³ÆÓÚ9ÔÂ23ÈÕÈëÇÖÁËÂíÀ´Î÷ÑÇABX ExpressµÄЧÀÍÆ÷£¬£¬ £¬ £¬²¢ÇÔÈ¡ÁË200GBÊý¾Ý¡£¡£¡£ ¡£¡£¡£¡£DesordenÌåÏִ˴λñµÃÁËÊý°ÙÍòÂíÀ´Î÷ÑÇÈ˵ÄÊý¾Ý¡¢Áè¼Ý1500ÍòÌõº½¿ÕÔ˵¥¼Í¼ÒÔ¼°ÓйزÆÎñ¡¢¿Í»§ºÍ¹«Ë¾ÐÅÏ¢µÈ£¬£¬ £¬ £¬¶øABX¹Ø±ÕÁËЧÀͲ¢³ÆÔÚ×öϵͳά»¤£¬£¬ £¬ £¬Ã»ÓÐÐû²¼´Ë´ÎÊý¾Ýй¶ÊÂÎñ¡£¡£¡£ ¡£¡£¡£¡£ÏÖÔÚ£¬£¬ £¬ £¬ABX Express¹«Ë¾ÉÐδ¶Ô´ËÊÂ×÷³ö»ØÓ¦£¬£¬ £¬ £¬¶øÑо¿Ö°Ô±ÔÚѯÎÊÆäĸ¹«Ë¾Kerry LogisticsºóҲδ»ñµÃ»ØÓ¦¡£¡£¡£ ¡£¡£¡£¡£



Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/desorden-group-claims-to-have-stolen-200-gb-of-data-from-abx-express/



CybereasonÐû²¼ÓйØÀÕË÷Èí¼þMagniberµÄÆÊÎö±¨¸æ


CybereasonÐû²¼ÓйØÀÕË÷Èí¼þMagniberµÄÆÊÎö±¨¸æ.png


CybereasonÔÚ9ÔÂ22ÈÕÐû²¼ÁËÓйØÀÕË÷Èí¼þMagniberµÄÆÊÎö±¨¸æ¡£¡£¡£ ¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬ £¬ £¬¸ÃÍÅ»ïÖ÷ҪʹÓÃÁËPrintNightmareÎó²î£¨CVE-2021-34527ºÍCVE-2021-34481£©¡£¡£¡£ ¡£¡£¡£¡£Ê×ÏÈÒÔ Windows DLLÎļþµÄÐÎʽ·Ö·¢ÀÕË÷Èí¼þ£¬£¬ £¬ £¬È»ºóʹÓÃCVE-2021-34527ÔÚÄ¿µÄϵͳÉÏ×°ÖúÍÖ´ÐиÃÎļþ¡£¡£¡£ ¡£¡£¡£¡£±ðµÄ£¬£¬ £¬ £¬ÀÕË÷Èí¼þMagniberÈÔ´¦ÓÚ¿ª·¢ÖУ¬£¬ £¬ £¬¿ª·¢ÕßÔÚÆµÈԵظü¸Ä´úÂ벢ˢлìÏý¹¦Ð§¡¢ÈƹýÕ½ÂԺͼÓÃÜ»úÖÆµÈ¡£¡£¡£ ¡£¡£¡£¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.cybereason.com/blog/threat-analysis-report-printnightmare-and-magniber-ransomware



AtlasVPNÐû²¼2021ÄêH1Åû¶µÄÎó²îµÄÆÊÎö±¨¸æ


AtlasVPNÐû²¼2021ÄêH1Åû¶µÄÎó²îµÄÆÊÎö±¨¸æ.png


AtlasVPNÔÚ9ÔÂ14ÈÕÐû²¼ÁË2021ÄêH1Åû¶µÄÎó²îµÄÆÊÎö±¨¸æ¡£¡£¡£ ¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬ £¬ £¬Google¡¢MicrosoftºÍOracleÔÚ2021ÄêÉϰëÄêÅû¶µÄÎó²î×î¶à£¬£¬ £¬ £¬»®·ÖΪ547¸ö¡¢432¸öºÍ316¸öÎó²î£¬£¬ £¬ £¬Æä´ÎΪCisco£¨200¸ö£©ºÍSAP£¨118¸ö£©¡£¡£¡£ ¡£¡£¡£¡£ÔÚÉϰëÄêÔÚ×ܼƷ¢Ã÷ÁË1023¸öCVSSÆÀ·ÖΪ9-10µÄÎó²î£¬£¬ £¬ £¬ÀýÈçF5 BIG-IPÖеÄCVE-2021-22986£»£»£»927¸öCVSSÆÀ·ÖΪ8-9µÄÎó²î£¬£¬ £¬ £¬ÈçDraeger X-DockÖеÄCVE-2021-28111£»£»£»ÒÔ¼°2164¸ö7-8·ÖµÄÎó²î¡£¡£¡£ ¡£¡£¡£¡£



Ô­ÎÄÁ´½Ó£º

https://atlasvpn.com/blog/google-and-microsoft-accumulated-the-most-vulnerabilities-in-h1-2021