¹¥»÷»î¶¯Duriͨ¹ýHTMLºÍJavaScript·Ö·¢¶ñÒâÈí¼þ £»ÒòÊÔ¾íÎĵµÐ¹Â¶ £¬CRESTÔÝÍ£Ó¢¹úµÄInfosecÈÏÖ¤¿¼ÊÔ

°ä²¼¹¦·ò 2020-08-19

1.¹¥»÷»î¶¯Duriͨ¹ýHTMLºÍJavaScript·Ö·¢¶ñÒâÈí¼þ


1.jpg


ÐµĹ¥»÷»î¶¯DuriÀûÓÃHTML¼Ð´ø¼¼ÊõºÍJavaScript blob·Ö·¢¶ñÒâÈí¼þ £¬²¢ÌÓ±Üɱ¶¾Èí¼þµÄ¼ì²âºÍ·ÖÎö¡£DuriÀûÓÃHTML¼Ð´ø¼¼Êõ £¬ÔÚ¿Í»§¶Ë£¨ä¯ÀÀÆ÷£©É϶¯Ì¬µØÌìÉúÓÐЧ¸ºÔØ £¬¶ø²»ÊÇÖ¸Ïò·þÎñÆ÷µÄÖ±½ÓURL £¬Òò¶ø²»»á´«ÊäÈκÎÊý¾ÝÒÔÔ¤·À±»É³Ïä²é³­¡£´Ë±í £¬×êÑÐÈËÔ±·ÖÎöÁ˸öñÒâÈí¼þÓÐЧ¸ºÔØÖеÄMSIÎļþ £¬·¢ÏÖÁËÒ»¸ö»ìºÏµÄJScript £¬ÒÔÌá¸ß¸Ã¶ñÒâÈí¼þµÄÒñ±ÎÐÔ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/duri-campaign-smuggles-malware-via-html-and-javascript/


2.CISAÖÒ¸æÐµĴ¹µö»î¶¯»á·Ö·¢¶ñÒâÈí¼þKONNI


2.jpg


ÍøÂ簲ȫºÍ»ù´¡½á¹¹°²È«¾Ö£¨CISA£©°ä²¼°²È«¾¯±¨ £¬ÌṩÓйØKONNIÔ¶³Ì½Ó¼ûľÂíÐÂÒ»²¨¹¥»÷µÄ¼¼Êõϸ½Ú¡£CISA·¢ÏÖºÚ¿Íͨ³£ÒÔ´øÓжñÒâVBAºê´úÂëµÄMicrosoft WordÎĵµµÄ´ó¾Öͨ¹ý´¹µöÓʼþÀ´·Ö·¢KONNI¶ñÒâÈí¼þ¡£KONNIÊÇÒ»ÖÖÔ¶³ÌÖÎÀí¹¤¾ß£¨RAT£© £¬¸Ã¹¤¾ß¿É±»ÀûÓÃÇÔÈ¡Îļþ¡¢²¶»ñ»÷¼ü¡¢»ñÈ¡ÆÁÄ»¿ìÕÕÒÔ¼°ÔÚÊÜϰȾµÄÖ÷»úÉÏÖ´ÐÐËÁÒâ´úÂë¡£¸Ã¶ñÒâÈí¼þÖÁÉÙ´Ó2014Äê¾ÍÆðÍ·»îÔ¾ £¬³¬¹ý3Äêδ±»·¢ÏÖ¡£

Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/alerts/aa20-227a


3.Àö×ȾƵê²ÍÒûԤԼϵͳÊý¾Ýй¶ £¬Æä¿Í»§Ôâµ½Ú¿Æ­


3.jpg


8ÔÂ15ÈÕÂ×¶ØÀö×ÈÁ¬Ëø¾Æµê°ä²¼Twitter°µÊ¾ £¬¸Ã¹«Ë¾ÔÚ8ÔÂ12ÈÕ·¢ÏÖËûÃǵIJÍÒûԤԼϵͳÖдæÔÚÊý¾Ýй¶ÎÊÌâ £¬Æä¿Í»§ÐÅÏ¢»òÒѱ»Ð¹Â¶²¢±»ÀûÓýøÐÐÚ¿Æ­»î¶¯¡£¸Ã¾Æµê°µÊ¾ÒѶԴËй¶ÊÂÎñ·¢Õ¹µ÷²é £¬Ã»ÓÐÈκÎÐÅÓþ¿¨¾ßÌåÐÅÏ¢»ò¸¶¿îÐÅϢй¶¡£¾ÝÓ¢¹ú¹ã²¥¹«Ë¾±¨Â· £¬ÒÑÓжàÆðÀûÓÃÕâЩй¶ÐÅÏ¢½øÐеÄÚ¿Æ­»î¶¯ £¬Æ­×Ó¼Ù×°ÊÇÀö×ȵĹÍÔ±¸ø²ÍÌüÔ¤Ô¼Õß´òµç»° £¬ÓëËûÃÇÈ·ÈÏÔ¤Ô¼µÄ¾ßÌåÐÅÏ¢ £¬Í¬Ê±ÒªÇóËûÃÇÌṩÐÅÓþ¿¨Ï¸½Ú¡£ 

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/ritz-london-struck-by-data-breach-fraudsters-pose-as-staff-in-credit-card-data-scam/


4.ÒòÊÔ¾íÎĵµÐ¹Â¶ £¬CRESTÔÝÍ£Ó¢¹úµÄInfosecÈÏÖ¤¿¼ÊÔ

4.jpg


ÒòÊÔ¾íÎĵµÐ¹Â¶ £¬CRESTÈ¡µÞÁËÁ½´ÎÓ¢¹úInfosecÈÏÖ¤¿¼ÊÔ¡£´Ëǰ¸Ã»ú¹¹Åû¶ÁËÒ»·Ý¹«¿ªµÄÎļþ £¬ÆäÖÐÔ̺¬ËƺõÊÇÄÚ²¿²é³­±íµÄÎļþ £¬ÒÔ¼°Óë¹Ø¼üÐÐÒµ²Î¼ÓÕßNCC¼¯ÍÅÓйصÄÎĵµ¡£¾ÝÖªÁµÈËʿй© £¬CRESTÔÝÍ£ÁËËùÓеÄCCT INFºÍCCT APP¿¼ÊÔ³¤´ïÒ»¸öÔ £¬Í¬Ê±Éó²éÆäÄÚÈÝ¡£CRESTµÄ½²»°È˰µÊ¾ £¬ÓÉÓÚÊý¾Ýй¶ £¬ËûÃDZØÒªÈýµ½ÖÜΧµÄ¹¦·òÀ´³ÁбàдÊÔ¾í £¬ÔÚµ÷²é½øÐÐÆÚ¼ä²»»á°ä·¢ÈÎºÎÆÀÂÛ¡£


Ô­ÎÄÁ´½Ó£º

https://www.theregister.com/2020/08/17/crest_halts_infosec_exams/


5.ÓÊÂÖ¹«Ë¾CarnivalϰȾÀÕË÷Èí¼þ £¬²¿ÃÅÊý¾Ý»òÒÑй¶

5.jpg


È«Çò×î´óµÄÓÊÂÖ¹«Ë¾Carnival CorpÔÚ8ÔÂ15ÈÕÔâµ½ÁËÀÕË÷Èí¼þ¹¥»÷ £¬²¿ÃÅÊý¾Ý»òÒÑй¶¡£¸Ã¹«Ë¾°µÊ¾ £¬ºÚ¿Í½Ó¼û²¢¼ÓÃÜÁËÆä·Ö¹«Ë¾µÄÐÅÏ¢¼¼Êõϵͳ £¬²¢ÇÒÇÔÈ¡ÁËÎļþ¡£Æ¾¾Ý¶Ô¸ÃÊÂÎñµÄ³õ²½ÆÀ¹À £¬¼ÎÄ껪ÒÔΪ £¬¹¥»÷Õß¿ÉÄÜÒѾ­½Ó¼ûÁËijЩº£¶«ºÍÔ±¹¤µÄÓ×ÎÒÊý¾Ý¡£µ«ÊÇCarnivalûÓÐй©ÓйشËÊÂÎñµÄ¾ßÌåÐÅÏ¢ £¬ÀýÈçÀÕË÷Èí¼þÃû³Æ £¬»òÆä¹¥»÷Ó°ÏìÁìÓòµÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/worlds-largest-cruise-line-operator-discloses-ransomware-attack/


6.RBS°ä²¼COVID-19¶ÔÊý¾Ýй¶µÄÓ°ÏìµÄ·ÖÎö»ã±¨

6.jpg


RBS°ä²¼COVID-19¶ÔÊý¾Ýй¶µÄÓ°ÏìµÄ·ÖÎö»ã±¨ £¬¸Ã»ã±¨¾ßÌå̽ÇóÁËÓÉCOVID-19ÒýÆðµÄ¹©¸øÁ´Öж϶ÔÊý¾Ýй¶ÎÊÌâ¼°ÆäËûÇ÷ÏòµÄÓ°Ïì¡£¾Ý»ã±¨ £¬2020Ä깫¿ª»ã±¨µÄÊý¾Ýй©ÊÂÎñµÄÊýÁ¿½µÂäÁË52£¥ £¬µ«Ð¹Â¶µÄÊý¾ÝÁ¿È´±ÈÍùÆÚÓâÔ½Ëı¶ÒÔÉÏ¡£´Ë±í £¬ÃýÎóÅäÖõÄÊý¾Ý¿âºÍ·þÎñÒÀÈ»ÊÇÊý¾Ýй¶µÄÖØÒªÆðÔ´ £¬2020ÄêµÚ¶þ¼¾¶È £¬½öÁ½¸ö·ì϶¾Íµ¼ÖÂÁË180ÒÚÌõÊý¾Ýй¶¡£

Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2020/08/18/publicly-reported-data-breaches-down-52-exposed-records-way-up/