Ìá½»ÐèÇó
*
*

*
*
*
Á¢¼´Ìá½»
µã»÷¡±Á¢¼´Ìá½»¡±£¬±íÃ÷ÎÒÀí½â²¢Í¬Òâ ¡¶»Æ½ð³Ç¿Æ¼¼Òþ˽Ìõ¿î¡·

logo

    ²úÆ·Óë·þÎñ
    ½â¾ö·½°¸
    ¼¼ÊõÖ§³Ö
    ºÏ×÷·¢Õ¹
    ¹ØÓڻƽð³Ç

    ÉêÇëÊÔÓÃ
      ÿÖܻƽð³Ç¹ÙÍøËÙµÝ???|BlackCatÀÕË÷Èí¼þ¶Ô¸çÂ×±ÈÑÇÄÜÔ´¹©Ó¦É̽øÐÐÍøÂç¹¥»÷
      ·¢²¼Ê±¼ä£º2022-12-23 ÔĶÁ´ÎÊý£º 881 ´Î
      ±¾ÖÜÈȵãʼþÍþвÇ鱨

      ͼƬ


      1

      BlackCatÀÕË÷Èí¼þ¶Ô¸çÂ×±ÈÑÇÄÜÔ´¹©Ó¦É̽øÐÐÍøÂç¹¥»÷
      ¸çÂ×±ÈÑÇÄÜÔ´¹«Ë¾ Empresas P¨²blicas de Medell¨ªn (EPM) ÖÜÒ»ÔâÊÜÁË BlackCat/ALPHV ÀÕË÷Èí¼þ¹¥»÷£¬¹«Ë¾ÔËÓªÖжÏ£¬ÔÚÏß·þÎñÖжÏ¡£EPM ÊǸçÂ×±ÈÑÇ×î´óµÄ¹«¹²ÄÜÔ´¡¢Ë®ºÍÌìÈ»Æø¹©Ó¦ÉÌÖ®Ò»£¬Îª 123 ¸ö³ÇÊÐÌṩ·þÎñ¡£¸Ã¹«Ë¾ÔÚ 2022 Äê´´ÔìÁ˳¬¹ý 250 ÒÚÃÀÔªµÄÊÕÈ룬¹é¸çÂ×±ÈÑÇÂóµÂÁÖÊÐÕþ¸®ËùÓС£½üÈÕ£¬¹«Ë¾ÒªÇó´óÔ¼ 4,000 ÃûÔ±¹¤ÔÚ¼Ò¹¤×÷£¬IT »ù´¡ÉèÊ©³öÏÖ¹ÊÕÏ£¬¹«Ë¾ÍøÕ¾Ò²²»ÔÙ¿ÉÓá£Ñо¿ÈËÔ±·¢ÏÖ BlackCat ÀÕË÷Èí¼þ²Ù×÷£¨ÓÖÃû ALPHV£©Êǹ¥»÷µÄÄ»ºóºÚÊÖ£¬Éù³ÆÔÚ¹¥»÷ÆÚ¼äÇÔÈ¡Á˹«Ë¾Êý¾Ý¡£
      ͼƬ

      ²Î¿¼Á´½Ó£º

      https://www.bleepingcomputer.com/news/security/colombian-energy-supplier-epm-hit-by-blackcat-ransomware-attack/?&web_view=true


      2

      ÀÕË÷Èí¼þÍÅ»ïʹÓÃеÄMicrosoft Exchange©¶´½øÐÐÍøÂç¹¥»÷

      ÍøÂç»Æ½ð³Ç¹ÙÍø¹«Ë¾CrowdStrikeÔÚµ÷²éPlayÀÕË÷Èí¼þ¹¥»÷ʱ·¢ÏÖ¹¥»÷ÕßÕýÔÚʹÓÃеı»³ÆÎªOWASSRFµÄ©¶´¡£¸Ã©¶´Õë¶ÔMicrosoft Exchange·þÎñÆ÷½øÐй¥»÷£¬Äܹ»ÈƹýProxyNotShell URLÖØÐ´»º½â»úÖÆ£¬¹¥»÷ÕßÔÚǰÆÚÀûÓÃÆäËûÔ¶³Ì´úÂëÖ´ÐÐ(RCE)©¶´»ñµÃȨÏ޺󣬿ÉÀûÓôæÔÚÓÚOutlook Web Access (OWA) Ó¦ÓÃÖеÄOWASSRF©¶´¹¹Ôì³ö©¶´ÀûÓÃÁ´£¬ÔÚÒ×Êܹ¥»÷µÄExchange ·þÎñÆ÷ÉÏÉÏʵÏÖȨÏÞÌáÉý¡£CrowdStrike·¢ÏÖз¢Ïֵĩ¶´ºÜ¿ÉÄÜÊÇCVE-2022-41080£¬ÕâÊÇ΢Èí±ê¼ÇΪÑÏÖØÇÒδÔÚÒ°ÍâÀûÓõĻƽð³Ç¹ÙÍøÂ©¶´¡£

      ͼƬ

      ²Î¿¼Á´½Ó£º

      https://www.bleepingcomputer.com/news/security/ransomware-gang-uses-new-microsoft-exchange-exploit-to-breach-servers/


      3

      ΢Èí½«ÓÚ2023Äê1Ô¹رÕExchange Online»ù±¾Éí·ÝÑéÖ¤

      ΢Èí¾¯¸æ³Æ½«´Ó2023Äê1ÔÂÉÏÑ®¿ªÊ¼ÓÀ¾Ã¹Ø±ÕExchange Online·þÎñµÄ»ù±¾Éí·ÝÑéÖ¤¹¦ÄÜ£¬ÒÔÌá¸ß»Æ½ð³Ç¹ÙÍøÐÔ¡£Exchange ÍŶÓÖܶþ±íʾ£¬´Ó1³õ¿ªÊ¼Î¢Èí½«¶ÔÅäÖýøÐиü¸ÄÒÔÓÀ¾Ã½ûÓÃЭÒ鷶ΧÄڵĻù±¾Éí·ÝÑé֤ʹÓã¬ÔÚ´Ëǰ´óÔ¼7ÌìÏòÊÜÓ°Ïì×â»§µÄÏûÏ¢ÖÐÐÄ·¢ËÍÌû×Ó¡£ÔÚ»ù±¾Éí·ÝÑéÖ¤±»ÓÀ¾Ã½ûÓú󲻾ã¬ÈκÎʹÓûù±¾Éí·ÝÑéÖ¤Á¬½Óµ½ÊÜÓ°ÏìЭÒéÖ®Ò»µÄ¿Í»§¶Ë»òÓ¦ÓóÌÐò¶¼½«ÊÕµ½´íÎóµÄÓû§Ãû/ÃÜÂë/HTTP 401´íÎó¡£Microsoft 365×ܾ­ÀíSeth PattonÔÚ9·Ý±íʾ£¬¸ù¾Ý΢Èí×ÔÉíµÄ»Æ½ð³Ç¹ÙÍøÑо¿±¨¸æ£¬ÒÑÖª³¬¹ý99%µÄÃÜÂëÅçÉäÀàÐ͵Ĺ¥»÷Õë¶Ô¸Ã»ù±¾Éí·ÝÑéÖ¤¹¦ÄÜ£¬½ûÓøù¦Äܺó¿Í»§ÔâÊܵÄΣº¦¿É¼õÉÙ67%ÒÔÉÏ¡£

      ͼƬ

      ²Î¿¼Á´½Ó£º

      https://www.bleepingcomputer.com/news/microsoft/microsoft-will-turn-off-exchange-online-basic-auth-in-january/


      4

      Glupteba½©Ê¬ÍøÂç±»µ·»ÙºóÔٴλîÔ¾

      ÔÚ±» Google µ·»ÙÁ˽«½üÒ»ÄêÖ®ºó£¬Glupteba ¶ñÒâÈí¼þ½©Ê¬ÍøÂçÔٴλîÔ¾ÆðÀ´£¬ÔÚÈ«Çò·¶Î§ÄÚ¸ÐȾÉ豸¡£ÓÉÓڹȸèµÄŬÁ¦£¬Í¨¹ý»ñµÃ¿ØÖÆÆä»ù´¡ÉèÊ©µÄ·¨ÔºÃüÁîÒÔ¼°¶ÔÁ½¼Ò¶íÂÞ˹ÔËÓªÉÌÌáÆð·¨ÂÉËßËÏ£¬ÆôÓÃÇø¿éÁ´µÄ½©Ê¬ÍøÂç¿ÉÄÜ»áÔÚ 2021 Äê 12 ÔÂÊܵ½ÑÏÖØÆÆ»µ¡£¸ù¾ÝÑо¿ÈËÔ±µÄ·ÖÎö¡¢Çø¿éÁ´½»Òס¢TLS Ö¤Êé×¢²áºÍÄæÏò¹¤³Ì Glupteba Ñù±¾£¬ÓÐÒ»¸öеĴó¹æÄ£ Glupteba »î¶¯¿ªÊ¼ÓÚ 2022 Äê 5 Ô£¬²¢Ò»Ö±³ÖÐøµ½½ñÌì¡£

      ͼƬ

      ²Î¿¼Á´½Ó£º

      https://www.cysecurity.news/2022/12/glupteba-malware-has-returned-after.html


      Ãâ·ÑÊÔÓÃ
      ·þÎñÈÈÏß

      ÂíÉÏ×Éѯ

      400-811-3777

      »Øµ½¶¥²¿
      ¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿