Ñо¿ÍŶӳƽüÆÚÀÕË÷Èí¼þ¹¥»÷Ò»Á¬¼¤Ôö£¬£¬£¬£¬£¬£¬£¬£¬Í¬±ÈÔöÌí93%£»£»£» £»£» £»Ñо¿Ö°Ô±Åû¶¸Ä¶¯¿ÉÖ´ÐоµÏñµÄ¹¥»÷Process Ghosting

Ðû²¼Ê±¼ä 2021-06-22

1.Ñо¿ÍŶӳƽüÆÚÀÕË÷Èí¼þ¹¥»÷Ò»Á¬¼¤Ôö£¬£¬£¬£¬£¬£¬£¬£¬Í¬±ÈÔöÌí93%


1.jpg


Check Point ResearchÑо¿ÍŶӳƽüÆÚÀÕË÷Èí¼þ¹¥»÷Ò»Á¬¼¤Ôö¡£¡£¡£ ¡£¡£2021Äê6ÔÂÿÖÜÊÜÀÕË÷Èí¼þÓ°ÏìµÄ×éÖ¯ÊýÄ¿ÒÑÔöÖÁ1210¸ö£¬£¬£¬£¬£¬£¬£¬£¬×ÔÄêÍ·ÒÔÀ´£¬£¬£¬£¬£¬£¬£¬£¬ÀÕË÷Èí¼þ¹¥»÷´ÎÊýÔöÌíÁË41%£¬£¬£¬£¬£¬£¬£¬£¬Í¬±ÈÔöÌíÁË93%¡£¡£¡£ ¡£¡£ÆäÖÐÀ­¶¡ÃÀÖÞµÄÀÕË÷Èí¼þ¹¥»÷ʵÑéÔöÌí×îΪÏÔ×Å£¬£¬£¬£¬£¬£¬£¬£¬ÔöÌíÁË62%£¬£¬£¬£¬£¬£¬£¬£¬Æä´ÎÊÇÅ·ÖÞÔöÌíÁË59%£¬£¬£¬£¬£¬£¬£¬£¬·ÇÖÞÔöÌíÁË34%£¬£¬£¬£¬£¬£¬£¬£¬±±ÃÀÔöÌíÁË32%¡£¡£¡£ ¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬Õë¶Ô½ÌÓýÐÐÒµµÄ¹¥»÷ÔöÌíËÙÂÊ×î¿ì£¨ÓëÈ¥ÄêͬÆÚÏà±ÈÔöÌíÁË347%£©£¬£¬£¬£¬£¬£¬£¬£¬Æä´ÎΪÔËÊäÐÐÒµ£¨186%£©¡¢ÁãÊÛºÍÅú¿¯ÐÐÒµ£¨162%£©ÒÔ¼°Ò½ÁƱ£½¡ÐÐÒµ£¨159%£©¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.checkpoint.com/2021/06/14/ransomware-attacks-continue-to-surge-hitting-a-93-increase-year-over-year/


2.ŲÍþ¾¯·½È·ÈÏÆäÔÚ2018ÄêÔâµ½µÄºÚ¿Í¹¥»÷ÓëAPT31ÓйØ


2.jpg


ŲÍþ¾¯Ô±Çå¾²¾Ö (PST) ÌåÏÖ£¬£¬£¬£¬£¬£¬£¬£¬ÆäÔÚ2018ÄêÔâµ½µÄÍøÂç¹¥»÷ÓëºÚ¿Í×éÖ¯APT31ÓйØ¡£¡£¡£ ¡£¡£¾ÝÊÓ²ìÏÔʾ£¬£¬£¬£¬£¬£¬£¬£¬Ôڴ˴ι¥»÷ÖкڿÍÒÑÀֳɻñµÃÖÎÀíԱȨÏÞ£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔ»á¼û¸Ã¹úËùÓйú¼ÒÐÐÕþ°ì¹«ÊÒʹÓõÄÖÐÑëÅÌËã»úϵͳ£¬£¬£¬£¬£¬£¬£¬£¬»¹ÀֳɵشӰ칫ÊÒϵͳÇÔÈ¡ÁËһЩÊý¾Ý¡£¡£¡£ ¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±³Æ£¬£¬£¬£¬£¬£¬£¬£¬APT31»¹±»ÒÔΪÊÇ2020Äê12ÔÂÕë¶Ô·ÒÀ¼Òé»áµÄÍøÂç¹¥»÷µÄÄ»ºóºÚÊÖ£¬£¬£¬£¬£¬£¬£¬£¬Ôڴ˴ι¥»÷ÖкڿÍÀÖ³ÉÈëÇÖÁËһЩÒé»áÏà¹Øµç×ÓÓʼþµÄÕÊ»§¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/119161/apt/norway-blames-china-apt31.html


3.ÈÕ±¾Sports Club NASºÍIto Yogyo³ÆÔâµ½ÀÕË÷¹¥»÷


3.jpg


½üÆÚ£¬£¬£¬£¬£¬£¬£¬£¬Á½¼ÒÈÕ±¾¹«Ë¾Sports Club NASºÍIto Yogyo¾ùÉù³ÆÔâµ½ÀÕË÷¹¥»÷¡£¡£¡£ ¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬£¬£¬½¡Éí¾ãÀÖ²¿NASÌåÏÖ¹¥»÷±¬·¢ÔÚ4ÔÂ2ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶ÁËÔ¼15Íò»áÔ±ºÍÔ±¹¤µÄСÎÒ˽¼ÒÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨ÐÕÃû¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢ÐԱ𡢵绰ºÅÂë¡¢»áÔ±ºÅÂë¡¢µç×ÓÓʼþµØµã¡¢½ôÆÈÁªÏµ·½·¨¡¢ÐÅÓÿ¨ÐÅÏ¢ºÍÕË»§ÐÅÏ¢µÈ¡£¡£¡£ ¡£¡£»£»£» £»£» £»ìÄýÍÁÖÆÔìÉÌIto YogyoÌåÏÖ¹¥»÷±¬·¢ÔÚ6ÔÂ10ÈÕÆÆÏþ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÔÚ·¢Ã÷¹¥»÷ºóÁ¬Ã¦¹Ø±ÕÁË¿ÉÄÜÊܵ½Ó°ÏìµÄЧÀÍÆ÷ºÍµçÄÔ£¬£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÊÂÎñÈÔÔÚÊÓ²ìÖУ¬£¬£¬£¬£¬£¬£¬£¬ÉÐδȷ¶¨ÊÇ·ñ±£´æÊý¾Ýй¶µÄÇéÐΡ£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/jp-sports-club-nas-and-concrete-manufacturer-ito-yogyo-both-report-ransomware-incidents/


4.NVIDIAÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÆäJetsonоƬϵÁÐÖеÄ9¸öÎó²î


4.jpg


NVIDIAÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËNVIDIA Jetson AGX XavierϵÁС¢Jetson Xavier NX¡¢Jetson TX1¡¢Jetson TX2ϵÁкÍJetson NanoÖеÄ9¸öÎó²î¡£¡£¡£ ¡£¡£´Ë´ÎÐÞ¸´µÄ×îΪÑÏÖØµÄÎó²îÊÇJetson¿ò¼ÜÖеĻº³åÇøÒç³öÎó²î£¨CVE?2021?34372£©£¬£¬£¬£¬£¬£¬£¬£¬±£´æÓÚNVIDIA OTEЭÒéÐÂÎÅÆÊÎö´úÂëÖУ¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÐÅϢй¶¡¢È¨ÏÞÌáÉýºÍ¾Ü¾øÐ§ÀÍ(DoS)¡£¡£¡£ ¡£¡£Æä´ÎΪNVIDIA TLKÖеĶÑÒç³öÎó²î£¨CVE?2021?34373£©ºÍ¶à¸ö¿É´¥·¢DoS¹¥»÷µÄÎó²î£¨CVE-2021-34379ºÍCVE-2021-34380£©µÈ¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/nvidia-jetson-chipset-dos-data-theft/167093/


5.Ñо¿Ö°Ô±Åû¶¸Ä¶¯¿ÉÖ´ÐоµÏñµÄ¹¥»÷Process Ghosting


5.jpg


Ñо¿Ö°Ô±Åû¶Á˸͝¿ÉÖ´ÐоµÏñµÄ¹¥»÷·½·¨Process Ghosting£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÈÆ¹ýWindowsϵͳÉϵı£»£»£» £»£» £»¤²½·¥Ö´ÐжñÒâ´úÂë¡£¡£¡£ ¡£¡£ElasticµÄÑо¿Ö°Ô±³Æ£¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ýÕâÖÖ·½·¨£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÒÔÒ»ÖÖÄÑÒÔɨÃè»òɾ³ýµÄ·½·¨½«¶ñÒâÈí¼þдÈë´ÅÅÌ£¬£¬£¬£¬£¬£¬£¬£¬È»ºóÏñÖ´ÐÐͨË×ÎļþÒ»ÑùÖ´ÐÐÒѱ»É¾³ýµÄ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬ÕâÖÖÊÖÒÕ²»Éæ¼°´úÂë×¢Èë¡¢Àú³Ì¿Õ»¯»òÊÂÎñÐÔNTFS(TxF)¡£¡£¡£ ¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬Process GhostingÀ©Õ¹ÁËÒÔǰËù¼Í¼µÄÖÕ¶ËÈÆ¹ýÒªÁ죬£¬£¬£¬£¬£¬£¬£¬´Ó¶ø¿ÉÒÔÈÆ¹ýɱ¶¾Èí¼þµÄ·ÀÓùºÍ¼ì²âÀ´Òþ²ØµØÖ´ÐжñÒâ´úÂë¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/06/researchers-uncover-process-ghosting.html


6.NuspireÐû²¼2021ÄêµÚÒ»¼¾¶ÈµÄÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ


6.jpg


NuspireÐû²¼ÁË2021ÄêµÚÒ»¼¾¶ÈµÄÍþÐ²Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£ ¡£¡£¸Ã±¨¸æÆÊÎöÁËÆä900ÒÚÌõÈÕÖ¾£¬£¬£¬£¬£¬£¬£¬£¬¸ÅÊöÁËеÄÍøÂç·¸·¨»î¶¯ºÍÕ½ÂÔ¡¢ÊÖÒպͳÌÐò (TTP)¡£¡£¡£ ¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ2021ÄêQ1£¬£¬£¬£¬£¬£¬£¬£¬Õë¶ÔFortinetµÄSSL-VPNµÄ¹¥»÷ÔöÌíÁË1916%£¬£¬£¬£¬£¬£¬£¬£¬Õë¶ÔPulse Connect Secure VPNµÄ¹¥»÷ÔöÌíÁË1527%¡£¡£¡£ ¡£¡£ÓÉÓÚVPNºÍRDPÎó²îÏÔ×ÅÔöÌí£¬£¬£¬£¬£¬£¬£¬£¬¶ñÒâÈí¼þ¡¢½©Ê¬ÍøÂçºÍÎó²îʹÓûÓë2020ÄêQ4Ïà±ÈÓÐËùϽµ¡£¡£¡£ ¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬½©Ê¬ÍøÂçZeroAccessµÄ»î¶¯ÔÚÒ»¸öÐÇÆÚÄÚ¼¤ÔöÁË619460%£¬£¬£¬£¬£¬£¬£¬£¬È»ºóÔÚ±¾¼¾¶ÈÄ©»ØÂä¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.nuspire.com/resources/q1-2021-threat-report