AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.01.04-01.10£©
2021-01-11
Ò»¡¢ ÈÈÃÅ×ÊѶ
1. SolarWinds Hack¸æËßÃÀ¹úËüÓÐÒ»¸öÖµµÃ½â¾öµÄÎÊÌâ
¡¾¸ÅÊö¡¿
SolarWindsÍøÂç¹¥»÷Ö»ÊÇһϵÁдóÃñ×å¹ú¼Ò¹¥»÷ÖеÄ×îÐÂÒ»´Î£¬¿ÉÒÔ˵ÊÇËùÓдËÀ๥»÷ÖÐ×îÑÏÖØµÄÒ»´Î£¬ÕâÊǹȸèÓÚ2009ÄêβÐû²¼µÄËùνµÄÖйú“ Aurora” APT¹¥»÷¡£×î³õ£¬ÕâÊǶÔGoogle GmailϵͳµÄÒ»´Î¹¥»÷£¬µ«ºÜ¿ìÎüÒýÁ˳ÉǧÉÏÍòµÄÃÀ¹ú¹«Ë¾£¬ËûÃÇÒâʶµ½ÖйúµÄ¹¤ÒµÔ°Çø¶àÄêÀ´Ò»Ö±ÔÚÇÔÈ¡IP£¬¶øÃ»ÓÐÈË×¢ÖØµ½¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.forbes.com/sites/johndunn/2021/12/31/relax-at-least-the-solarwinds-hack-tells-america-it-has-a-problem-worth-solving/
2. 2020Ä꿵½¡Êý¾Ýй¶Ç÷ÊÆÆÊÎö
¡¾¸ÅÊö¡¿
2020Ä꣬°üÀ¨ÀÕË÷Èí¼þºÍÍøÂç´¹ÂÚ¹¥»÷ÔÚÄڵĺڿÍÊÂÎñÒÔ¼°Éæ¼°¹©Ó¦É̵ÄÇå¾²ÊÂÎñÔÚÁª°îͳ¼ÆÊý¾ÝÖÐÕ¼ÓÐÖ÷µ¼Ö°Î»¡£ÃÀ¹úÎÀÉúºÍ¹«ÖÚ·þÎñ²¿HIPAAÎ¥¹æ±¨¸æ¹¤¾ßÍøÕ¾µÄ¿ìÕÕÏÔʾ£¬µ½2020Ä꣬¹²±¨¸æºÍ±¨¸æÁË619ÆðÖØ´óÎ¥¹æÊÂÎñ£¬Ó°ÏìÁ˽ü2880ÍòÈË¡£ÆäÖÐÓÐ415¸ö£¨»òÈý·ÖÖ®¶þÒÔÉÏ£©±»±¨¸æÎªºÚ¿ÍÈëÇÖÊÂÎñ¡£µ½2020Ä꣬¹²ÓÐ2640ÍòÈËÊܵ½Ó°Ï죬ռÊÜÖØ´ó¿µ½¡Êý¾Ýй¶ӰÏìµÄÈËÊýµÄ90£¥ÒÔÉÏ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.inforisktoday.com/analysis-2020-health-data-breach-trends-a-15694
3. »ùÓÚ¿ÉÐÅÊý×ÖÉí·ÝµÄÇø¿éÁ´Ó¦Ó÷þÎñ°×ƤÊé
¡¾¸ÅÊö¡¿
ÔÚÇø¿éÁ´Çå¾²ÈÕÒæÖ÷ÒªµÄ´óÅä¾°Ï£¬AG¹«Ë¾¿Æ¼¼Ó빫°²²¿µÚÒ»Ñо¿Ëù¡¢ÖйúÐÅϢͨѶÑо¿Ôº¾ÓÉÊýÔµÄÊг¡µ÷ÑкÍÐèÇóÆÊÎö£¬ÍŽáÐû²¼ÁË¡¶»ùÓÚ¿ÉÐÅÊý×ÖÉí·ÝµÄÇø¿éÁ´Ó¦Ó÷þÎñ°×ƤÊé¡·£¨1.0°æ£©¡£
¡¾²Î¿¼Á´½Ó¡¿
http://mp.weixin.qq.com/s?__biz=MjM5ODYyMTM4MA===2650409410=1=77ba219bad1d8beca733da035d6020b8=bec9506989bed97f279b2a52120412c6ef8a5210d51a4d803065dde27d735ad0fd7439fe6517#rd
4. ¹È¸èÖÒÑÔAndroidÔ¶³Ì´úÂëÖ´ÐÐÎó²îÑÏÖØ
¡¾¸ÅÊö¡¿
GoogleµÄAndroidÇå¾²¸üнâ¾öÁË43¸öÓ°ÏìAndroidÊÖ»ú£¨°üÀ¨ÈýÐÇÊÖ»ú£©µÄÎó²î¡£GoogleÐÞ¸´ÁËÁ½¸öÓ°ÏìÆäAndroidÊÖ»úµÄÑÏÖØ¹ýʧ¡£Androidϵͳ×é¼þÖб£´æ¸üÑÏÖØµÄȱÏÝ£¬ÕâЩȱÏÝʹԶ³Ì¹¥»÷Õß¿ÉÒÔÖ´ÐÐí§Òâ´úÂë¡£ÕâÁ½¸öÑÏÖØÎó²îÊÇÐÇÆÚÒ»Ðû²¼µÄGoogleÒ»ÔÂAndroidÇ徲ͨ¸æµÄÒ»²¿·Ö¡£¸ÃÇå¾²¸üнâ¾öÁËAndroid²Ù×÷ϵͳµÄ×ܹ²43¸ö¹ýʧ¡£×÷ΪÆäÒ»²¿·Ö£¬ÆäоƬÓÃÓÚAndroid×°±¸µÄ¸ßͨ¹«Ë¾ÐÞ²¹ÁËÓë15¸ö¹ýʧÏà¹ØµÄ¸ßÑÏÖØÐÔÎó²îºÍÑÏÖØÑÏÖØÐÔÎó²î¡£
¡¾²Î¿¼Á´½Ó¡¿
https://threatpost.com/google-warns-of-critical-android-remote-code-execution-bug/162756/
5. ElectroRatÇÔÈ¡ÃÜÂëµÄ¶ñÒâÈí¼þ¹¥»÷MacOS¡¢WindowsºÍLinux×°±¸
¡¾¸ÅÊö¡¿
IntezerµÄITÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»ÖÖеÄRAT£¨Ô¶³Ì»á¼û¹¤¾ß£©£¬¸Ã¹¤¾ßÄܹ»Õë¶ÔWindows£¬LinuxºÍMacOS¡£Ë¼Á¿µ½ËüµÄìÉý¼ÛÖµ£¬ÆäÖ÷ҪĿµÄÊÇÇÔÈ¡¼ÓÃÜÇ®±Ò£¬ÆäÖÐ1±ÈÌØ±ÒÏÖÔÚԼΪ34,000ÃÀÔª¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.hackread.com/electrorat-crypto-stealing-malware-hits-macos-windows-linux-devices/
6. ð³äµÄCyberpunk 2077 AndroidÓ¦ÓÃÕýÔÚÒÆ¶¯ÖÐ
¡¾¸ÅÊö¡¿
Ðж¯½ÇÉ«ÊÎÑÝÊÓÆµÓÎÏ·¡¶Cyberpunk 2077¡·ÊÇåÇÀ´×îÊÜÆÚ´ýµÄÓÎÏ·Ö®Ò»£¬¾Óɶà´ÎÑÓ³Ù£¬¸ÃÓÎÏ·ÖÕÓÚÔÚ2020Äê12ÔÂÐû²¼¡£Ö»¹Ü¸ÃÓÎÏ·ÔÚ×î³õ¿¯ÐÐʱ±£´æ¹ýʧºÍÎÊÌ⣬µ«ÈÔ»ñµÃÁËÆÕ±éµÄ½Ó´ý¡£²¢ÔÚ³õʼÐû²¼´°¿ÚÖйØ×¢¡£ÕâÒýÆðÁËÓÎÏ·Íæ¼ÒºÍ·ÇÓÎÏ·Íæ¼ÒµÄ¹Ø×¢£¬¾ø²»Ï£Ææ£¬¶ñÒâÈí¼þ±àдÕߺÍÕ©ÆÕßÒ²×îÏÈʹÓÃÕâÖÖÊܽӴýˮƽ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securitynews.sonicwall.com/xmlpost/fake-cyberpunk-2077-android-apps-are-on-the-move/
7. ͨ¹ýÌØÀÊÆÕΪÖ÷ÌâµÄÊÓÆµ×÷ΪÓÕ¶üÀ´Èö²¥QRatľÂí
¡¾¸ÅÊö¡¿
¾ÝÇå¾²¹«Ë¾Trustwave SpiderLabs³Æ£¬×î½ü·¢Ã÷µÄÍøÂç´¹ÂÚÔ˶¯Ê¹ÓÃÌÆÄÉµÂ·ÌØÀÊÆÕ×ÜͳµÄÊÓÆµ×÷ΪÓÕ¶üÀ´Èö²¥QRatľÂí£¬¸ÃľÂí¿ÉÒÔÇÔÈ¡ÃÜÂ룬½ØÈ¡ÆÁÄ»½ØÍ¼²¢Ê¹¹¥»÷ÕßÄܹ»ÎüÊÕÊÜѬȾµÄWindows×°±¸¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.inforisktoday.com/trump-themed-phishing-campaign-spread-trojan-a-15720
8. WhatsAppÇ¿ÖÆÒªÇóÓëFacebook¹²ÏíÊý¾Ý
¡¾¸ÅÊö¡¿
1ÔÂ7ÈÕ£¬ÔÚÆä×°±¸ÉÏ·¿ªÐÂÎſͻ§¶ËµÄWhatsAppÓû§»áÊÕµ½Ò»¸öÓ¦ÓóÌÐòÄÚ֪ͨ£¬¸Ã֪ͨ»á½«Æä¸üеÄÌõ¿îºÍÒþ˽Õþ²ß֪ͨÓû§¡£WhatsAppÕýÔÚ¸üÐÂÆäÌõ¿îºÍÒþ˽Õþ²ß£¬Ëü»áÔĶÁ²¢ÁгöÁ½¸ö»òÈý¸öÒªº¦µã£¬²¢ÌṩָÏòÌõ¿îºÍÒþ˽Õþ²ßµÄÁ´½Ó¡£ÌṩÁ˽ÓÊܸüеÄÌõ¿îºÍÒþ˽Õþ²ßµÄÑ¡ÏÒÔ¼°ÍƳپöÒéµÄÑ¡Ïî¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.ghacks.net/2021/01/07/whatsapp-makes-data-sharing-with-facebook-mandatory/
9. ÃÀ¹úÕþ¸®Æô¶¯Á˺ڿͽ¾ü3.0Îó²îÐüÉÍÍýÏë
¡¾¸ÅÊö¡¿
ÃÀ¹úÕþ¸®ÓëHackerOneƽ̨ÏàÖúÍÆ³öÁ˵ÚÈý°æµÄÎó²îÉͽðÍýÏëHack the Army 3.0¡£µÚ¶þ¸ö Hack the Army BugÉͽðÍýÏëÓÚ2019Äê10ÔÂ9ÈÕÖÁ11ÔÂ15ÈÕÖ®¼äͨ¹ýHackerOneƽ̨ÔËÐС£ÓÉÃÀ¹ú¹ú·À²¿Êý×Ö·þÎñ¾Ö£¨Defense Digital Service£©ºÍÃÀ¹ú¹ú·À²¿£¨DoD£©ÅäºÏÔËÓªµÄÎó²îÉͽðÍýÏëÒÑÖ§¸¶ÁËÁè¼Ý27.5ÍòÃÀÔªµÄ½±Àø£¬²¢ÇÒ¹²±¨¸æÁË146¸öÓÐÓÃÎó²î¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securityaffairs.co/wordpress/113116/security/hack-the-army-3-0.html

AG¹«Ë¾ÔÆ







