µÂ¹úÁª°î¾¯Ô±¾ÖÖØÖÃEmotet£¬¸Ã¶ñÒâÈí¼þ½«×Ô¶¯Ð¶ÔØ£»»ªÊ¢¶Ù¾¯¾ÖÔâµ½BabukµÄ¹¥»÷£¬250GBδ¼ÓÃܵÄÎļþй¶
Ðû²¼Ê±¼ä 2021-04-271.µÂ¹úÁª°î¾¯Ô±¾ÖÖØÖÃEmotet£¬¸Ã¶ñÒâÈí¼þ½«×Ô¶¯Ð¶ÔØ

µÂ¹úÁª°î¾¯Ô±¾ÖBundeskriminalamtÖØÖÃÁËEmotet£¬¸Ã¶ñÒâÈí¼þ½«ÔÚËùÓÐÊÜѬȾµÄϵͳÖÐ×Ô¶¯Ð¶ÔØ¡£EmotetÊǽüÆÚ×îΣÏÕµÄÀ¬»øÓʼþ½©Ê¬ÍøÂçÖ®Ò»£¬Æä»ù´¡ÉèÊ©ÓÚ½ñÄê1Ô·ÝÓɶà¹úÖ´·¨²¿·ÖÍŽᵷ»Ù¡£ÔÚ´Ë´ÎÐж¯ÖУ¬µÂ¹ú¾¯·½ÈÏÕæ¿ª·¢ºÍÍÆËÍÐ¶ÔØÄ£¿é£¬ÆäΪÁËÍøÂçÖ¤¾ÝºÍÐÅÏ¢¶øÍƳÙÁ˸ÃÐ¶ÔØÄ£¿éµÄÐû²¼¡£¸Ã»ú¹¹Í¨¹ýÆä¿ØÖƵÄC2·þÎñÆ÷£¬½«32λEmotetLoader.dllÐÎʽµÄÐÂEmotetÄ£¿é·Ö·¢¸øËùÓÐÊÜѬȾµÄϵͳ£¬Ê¹ÕâЩϵͳÔÚ2021Äê4ÔÂ25ÈÕ×Ô¶¯Ð¶ÔظöñÒâÈí¼þ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/emotet-malware-nukes-itself-today-from-all-infected-computers-worldwide/
2.»ªÊ¢¶Ù¾¯¾ÖÔâµ½BabukµÄ¹¥»÷£¬250GBδ¼ÓÃܵÄÎļþй¶

»ªÊ¢¶ÙÌØÇø¾¯Ô±¾ÖMPDÈ·ÈÏÆäÔâµ½ÀÕË÷ÍÅ»ïBabukµÄ¹¥»÷£¬250 GBδ¼ÓÃܵÄÎļþй¶¡£ÀÕË÷ÍÅ»ï¹ûÕæµÄ±»µÁÎļþ¼ÐµÄ½ØÍ¼ÖеÄʱ¼ä´Á¾ùΪ2021.4.19£¬Õâ¿ÉÄÜÏÔʾÁ˹¥»÷ÕßÇÔÈ¡Êý¾ÝµÄʱ¼ä¡£±ðµÄ£¬BabukÍÅ»ïÌØÊâÖ¸³öÁËÒ»·ÝÎļþ£¬ÆäËÆºõÓë1ÔÂ6ÈÕÏ®»÷¹ú»á´óÏõĿ¹ÒéÔ˶¯Óйء£MPD³ÆÆäÒѾÓëFBIÍŽáÕö¿ªÁËÖÜÈ«µÄÊӲ죬¿ÉÊÇÏÖÔÚÉÐδ¹ûÕæÓйش˴ÎÊÂÎñµÄÏêϸÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/dc-police-confirms-cyberattack-after-ransomware-gang-leaks-data/
3.Ñо¿ÍŶӷ¢Ã÷ʹÓÃFileZenÖеÄ2¸öÎó²îµÄ¹¥»÷Ô˶¯

Ñо¿ÍŶӷ¢Ã÷ʹÓÃÎļþ¹²Ïí·þÎñÆ÷Soliton FileZenÖеÄ2¸öÎó²îÇÔÈ¡Êý¾ÝµÄ´ó¹æÄ£¹¥»÷Ô˶¯¡£´Ë´ÎÔ˶¯ÖÐʹÓõÄÎó²î»®·ÖΪĿ¼±éÀúÎó²î£¨CVE-2020-5639£©£¬¿É½«Ìض¨ÎļþÉÏÔØµ½Ìض¨Ä¿Â¼Öжøµ¼ÖÂÖ´ÐÐí§ÒâOSÏÂÁÒÔ¼°Ò»¸öí§ÒâOSÏÂÁîÖ´ÐÐÎó²î£¨CVE-2021-20655£©¡£ÔÚÆäÖеÄÒ»´Î¹¥»÷ÖУ¬ÈÕ±¾Ô׺âÄÚ¸ó°ì¹«ÊÒ(Cabinet Office)ÊÂÇéְԱʹÓõÄSolitonÎļþ¹²Ïí´æ´¢Ôâµ½ÁËδ¾ÊÚȨµÄ»á¼û¡£SolitonÒѾ¿¯Ðй̼þ°æ±¾V4.2.8ºÍV5.0.3ÐÞ¸´ÁËFileZenÖеÄÁ½¸öÎó²î¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/117208/hacking/soliton-filezen-file-sharing-servers.html
4.Sophos³ÆÏÖÔÚÓнüÒ»°ëµÄ¶ñÒâÈí¼þʹÓÃTLSÀ´Òþ²ØÍ¨Ñ¶

Sophos̫ͨ¹ýÎö·¢Ã÷£¬½üÆÚÓнüÒ»°ëµÄ¶ñÒâÈí¼þʹÓÃTLSÀ´Òþ²ØÍ¨Ñ¶¡£ÔÚÒÑÍùµÄÊ®ÄêÖУ¬HTTPSµÄʹÓÃÂÊ´Ó2014ÄêÕ¼ËùÓÐÍøÒ³»á¼ûÁ¿µÄ40£¥ÒÔÉÏÔöÌíµ½2021Äê3ÔµÄ98£¥¡£¶ø¶ñÒâÈí¼þÒ²³öÓÚÏàͬµÄÔµ¹ÊÔÓɽÓÄÉTLS£¬2020Äê¼ì²âµ½23£¥µÄ¶ñÒâÈí¼þʹÓÃTLSÓëÔ¶³Ìϵͳ¾ÙÐÐͨѶ£¬µ½ÏÖÔÚÕâÒ»±ÈÀýÒÑ¿¿½ü46£¥¡£GoogleÔÆ·þÎñÊÇ9£¥µÄ¶ñÒâTLSÇëÇóµÄÄ¿µÄ£¬Æä´ÎÊÇÓ¡¶ÈµÄBSNL£¬ËùÓеĶñÒâTLSͨѶÖÐÏÕЩÓÐÒ»°ëÁ÷ÏòÁËÃÀ¹úºÍÓ¡¶ÈµÄ·þÎñÆ÷¡£
ÔÎÄÁ´½Ó£º
https://news.sophos.com/en-us/2021/04/21/nearly-half-of-malware-now-use-tls-to-conceal-communications/
5.MimecastÐû²¼Óйصç×ÓÓʼþÇå¾²Ì¬ÊÆµÄÆÊÎö±¨¸æ

MimecastÐû²¼ÁËÓйصç×ÓÓʼþÇå¾²Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¸Ã±¨¸æ»ùÓÚ¶ÔÈ«Çò1225λ¾öÒéÕßµÄÊӲ죬ÆäÖÐ79£¥µÄÊÜ·ÃÕßÌåÏÖÓÉÓÚȱ·¦Çå¾²·½ÃæµÄ×¼±¸£¬ËûÃǵĹ«Ë¾ÔÚ2020ÄêÂÄÀúÁËÓªÒµÖÐÖ¹¡¢²ÆÎñËðʧ»òÆäËûÎÊÌ⣻61£¥µÄ¹«Ë¾ÔÚ2020ÄêÊܵ½ÀÕË÷Èí¼þµÄÓ°Ï죬±ÈÈ¥ÄêÔöÌíÁË20£¥£»52£¥µÄÀÕË÷Èí¼þÊܺ¦ÕßÖ§¸¶ÁËÊê½ð£¬¿ÉÊÇËûÃÇÖÐÖ»ÓÐ66£¥µÄÈ˻ָ´ÁËÊý¾Ý£¬ÁíÍâ34£¥µÄ¹«Ë¾Ö§¸¶ÁËÊê½ðÈ´ÒÀȻûÓлñµÃËûÃǵÄÊý¾Ý¡£
ÔÎÄÁ´½Ó£º
https://www.mimecast.com/state-of-email-security/
6.OpenTextÐû²¼2020ÄêµÄÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ

OpenTextÐû²¼ÁË2020ÄêµÄÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£±¨¸æÖ¸³ö£¬½ö´Ó2020Äê1Ôµ½2Ô£¬ÍøÂç´¹ÂڵĹ¥»÷´ÎÊý¾ÍÔöÌíÁË510£¥£¬¹¥»÷Ä¿µÄÖ÷ÒªÊÇÄ¿µÄÊÇeBay¡¢Apple¡¢Microsoft¡¢FacebookºÍGoogle¡£ÈÕ±¾µÄPCѬȾÂÊ×îµÍ£¬Îª2.3%£¬Æä´ÎÊÇÓ¢¹ú(2.7%)¡¢´óÑóÖÞ(3.2%)ºÍ±±ÃÀ(3.7%)¡£ÔÚÅ·ÖÞ£¬¼ÒÓÃ×°±¸±»Ñ¬È¾µÄ¿ÉÄÜÐÔ£¨17.4%£©ÊÇÉÌÓÃ×°±¸µÄÈý±¶¶à(5.3%)¡£2020ÄêÔÚAndroid?×°±¸Éϼì²âµ½µÄÌØÂåÒÁľÂíºÍ¶ñÒâÈí¼þÕ¼Íþв×ÜÊýµÄ95.9£¥£¬¸ßÓÚ2019ÄêµÄ92.2£¥¡£
ÔÎÄÁ´½Ó£º
https://mypage.webroot.com/2021-threat-report.html


¾©¹«Íø°²±¸11010802024551ºÅ