¹¥»÷»î¶¯Duriͨ¹ýHTMLºÍJavaScript·Ö·¢¶ñÒâÈí¼þ£»£»£»£»£»£»£»ÒòÊÔ¾íÎĵµÐ¹Â¶£¬£¬£¬£¬£¬£¬CRESTÔÝÍ£Ó¢¹úµÄInfosecÈÏÖ¤¿¼ÊÔ
°ä²¼¹¦·ò 2020-08-191.¹¥»÷»î¶¯Duriͨ¹ýHTMLºÍJavaScript·Ö·¢¶ñÒâÈí¼þ

ÐµĹ¥»÷»î¶¯DuriÀûÓÃHTML¼Ð´ø¼¼ÊõºÍJavaScript blob·Ö·¢¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬²¢ÌÓ±Üɱ¶¾Èí¼þµÄ¼ì²âºÍ·ÖÎö¡£¡£¡£¡£¡£DuriÀûÓÃHTML¼Ð´ø¼¼Êõ£¬£¬£¬£¬£¬£¬ÔÚ¿Í»§¶Ë£¨ä¯ÀÀÆ÷£©É϶¯Ì¬µØÌìÉúÓÐЧ¸ºÔØ£¬£¬£¬£¬£¬£¬¶ø²»ÊÇÖ¸Ïò·þÎñÆ÷µÄÖ±½ÓURL£¬£¬£¬£¬£¬£¬Òò¶ø²»»á´«ÊäÈκÎÊý¾ÝÒÔÔ¤·À±»É³Ïä²é³¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±·ÖÎöÁ˸öñÒâÈí¼þÓÐЧ¸ºÔØÖеÄMSIÎļþ£¬£¬£¬£¬£¬£¬·¢ÏÖÁËÒ»¸ö»ìºÏµÄJScript£¬£¬£¬£¬£¬£¬ÒÔÌá¸ß¸Ã¶ñÒâÈí¼þµÄÒñ±ÎÐÔ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/duri-campaign-smuggles-malware-via-html-and-javascript/
2.CISAÖÒ¸æÐµĴ¹µö»î¶¯»á·Ö·¢¶ñÒâÈí¼þKONNI

ÍøÂ簲ȫºÍ»ù´¡½á¹¹°²È«¾Ö£¨CISA£©°ä²¼°²È«¾¯±¨£¬£¬£¬£¬£¬£¬ÌṩÓйØKONNIÔ¶³Ì½Ó¼ûľÂíÐÂÒ»²¨¹¥»÷µÄ¼¼Êõϸ½Ú¡£¡£¡£¡£¡£CISA·¢ÏÖºÚ¿Íͨ³£ÒÔ´øÓжñÒâVBAºê´úÂëµÄMicrosoft WordÎĵµµÄ´ó¾Öͨ¹ý´¹µöÓʼþÀ´·Ö·¢KONNI¶ñÒâÈí¼þ¡£¡£¡£¡£¡£KONNIÊÇÒ»ÖÖÔ¶³ÌÖÎÀí¹¤¾ß£¨RAT£©£¬£¬£¬£¬£¬£¬¸Ã¹¤¾ß¿É±»ÀûÓÃÇÔÈ¡Îļþ¡¢²¶»ñ»÷¼ü¡¢»ñÈ¡ÆÁÄ»¿ìÕÕÒÔ¼°ÔÚÊÜϰȾµÄÖ÷»úÉÏÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÖÁÉÙ´Ó2014Äê¾ÍÆðÍ·»îÔ¾£¬£¬£¬£¬£¬£¬³¬¹ý3Äêδ±»·¢ÏÖ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/alerts/aa20-227a
3.Àö×ȾƵê²ÍÒûԤԼϵͳÊý¾Ýй¶£¬£¬£¬£¬£¬£¬Æä¿Í»§Ôâµ½Ú¿Æ

8ÔÂ15ÈÕÂ×¶ØÀö×ÈÁ¬Ëø¾Æµê°ä²¼Twitter°µÊ¾£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÔÚ8ÔÂ12ÈÕ·¢ÏÖËûÃǵIJÍÒûԤԼϵͳÖдæÔÚÊý¾Ýй¶ÎÊÌ⣬£¬£¬£¬£¬£¬Æä¿Í»§ÐÅÏ¢»òÒѱ»Ð¹Â¶²¢±»ÀûÓýøÐÐڿƻ¡£¡£¡£¡£¡£¸Ã¾Æµê°µÊ¾ÒѶԴËй¶ÊÂÎñ·¢Õ¹µ÷²é£¬£¬£¬£¬£¬£¬Ã»ÓÐÈκÎÐÅÓþ¿¨¾ßÌåÐÅÏ¢»ò¸¶¿îÐÅϢй¶¡£¡£¡£¡£¡£¾ÝÓ¢¹ú¹ã²¥¹«Ë¾±¨Â·£¬£¬£¬£¬£¬£¬ÒÑÓжàÆðÀûÓÃÕâЩй¶ÐÅÏ¢½øÐеÄڿƻ£¬£¬£¬£¬£¬£¬Æ×Ó¼Ù×°ÊÇÀö×ȵĹÍÔ±¸ø²ÍÌüÔ¤Ô¼Õß´òµç»°£¬£¬£¬£¬£¬£¬ÓëËûÃÇÈ·ÈÏÔ¤Ô¼µÄ¾ßÌåÐÅÏ¢£¬£¬£¬£¬£¬£¬Í¬Ê±ÒªÇóËûÃÇÌṩÐÅÓþ¿¨Ï¸½Ú¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/ritz-london-struck-by-data-breach-fraudsters-pose-as-staff-in-credit-card-data-scam/
4.ÒòÊÔ¾íÎĵµÐ¹Â¶£¬£¬£¬£¬£¬£¬CRESTÔÝÍ£Ó¢¹úµÄInfosecÈÏÖ¤¿¼ÊÔ

ÒòÊÔ¾íÎĵµÐ¹Â¶£¬£¬£¬£¬£¬£¬CRESTÈ¡µÞÁËÁ½´ÎÓ¢¹úInfosecÈÏÖ¤¿¼ÊÔ¡£¡£¡£¡£¡£´Ëǰ¸Ã»ú¹¹Åû¶ÁËÒ»·Ý¹«¿ªµÄÎļþ£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬ËƺõÊÇÄÚ²¿²é³±íµÄÎļþ£¬£¬£¬£¬£¬£¬ÒÔ¼°Óë¹Ø¼üÐÐÒµ²Î¼ÓÕßNCC¼¯ÍÅÓйصÄÎĵµ¡£¡£¡£¡£¡£¾ÝÖªÁµÈËʿй©£¬£¬£¬£¬£¬£¬CRESTÔÝÍ£ÁËËùÓеÄCCT INFºÍCCT APP¿¼ÊÔ³¤´ïÒ»¸öÔ£¬£¬£¬£¬£¬£¬Í¬Ê±Éó²éÆäÄÚÈÝ¡£¡£¡£¡£¡£CRESTµÄ½²»°È˰µÊ¾£¬£¬£¬£¬£¬£¬ÓÉÓÚÊý¾Ýй¶£¬£¬£¬£¬£¬£¬ËûÃDZØÒªÈýµ½ÖÜΧµÄ¹¦·òÀ´³ÁбàдÊÔ¾í£¬£¬£¬£¬£¬£¬ÔÚµ÷²é½øÐÐÆÚ¼ä²»»á°ä·¢ÈÎºÎÆÀÂÛ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.theregister.com/2020/08/17/crest_halts_infosec_exams/
5.ÓÊÂÖ¹«Ë¾CarnivalϰȾÀÕË÷Èí¼þ£¬£¬£¬£¬£¬£¬²¿ÃÅÊý¾Ý»òÒÑй¶

È«Çò×î´óµÄÓÊÂÖ¹«Ë¾Carnival CorpÔÚ8ÔÂ15ÈÕÔâµ½ÁËÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬²¿ÃÅÊý¾Ý»òÒÑй¶¡£¡£¡£¡£¡£¸Ã¹«Ë¾°µÊ¾£¬£¬£¬£¬£¬£¬ºÚ¿Í½Ó¼û²¢¼ÓÃÜÁËÆä·Ö¹«Ë¾µÄÐÅÏ¢¼¼Êõϵͳ£¬£¬£¬£¬£¬£¬²¢ÇÒÇÔÈ¡ÁËÎļþ¡£¡£¡£¡£¡£Æ¾¾Ý¶Ô¸ÃÊÂÎñµÄ³õ²½ÆÀ¹À£¬£¬£¬£¬£¬£¬¼ÎÄ껪ÒÔΪ£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜÒѾ½Ó¼ûÁËijЩº£¶«ºÍÔ±¹¤µÄÓ×ÎÒÊý¾Ý¡£¡£¡£¡£¡£µ«ÊÇCarnivalûÓÐй©ÓйشËÊÂÎñµÄ¾ßÌåÐÅÏ¢£¬£¬£¬£¬£¬£¬ÀýÈçÀÕË÷Èí¼þÃû³Æ£¬£¬£¬£¬£¬£¬»òÆä¹¥»÷Ó°ÏìÁìÓòµÈ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/worlds-largest-cruise-line-operator-discloses-ransomware-attack/
6.RBS°ä²¼COVID-19¶ÔÊý¾Ýй¶µÄÓ°ÏìµÄ·ÖÎö»ã±¨

RBS°ä²¼COVID-19¶ÔÊý¾Ýй¶µÄÓ°ÏìµÄ·ÖÎö»ã±¨£¬£¬£¬£¬£¬£¬¸Ã»ã±¨¾ßÌå̽ÇóÁËÓÉCOVID-19ÒýÆðµÄ¹©¸øÁ´Öж϶ÔÊý¾Ýй¶ÎÊÌâ¼°ÆäËûÇ÷ÏòµÄÓ°Ïì¡£¡£¡£¡£¡£¾Ý»ã±¨£¬£¬£¬£¬£¬£¬2020Ä깫¿ª»ã±¨µÄÊý¾Ýй©ÊÂÎñµÄÊýÁ¿½µÂäÁË52£¥£¬£¬£¬£¬£¬£¬µ«Ð¹Â¶µÄÊý¾ÝÁ¿È´±ÈÍùÆÚÓâÔ½Ëı¶ÒÔÉÏ¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬ÃýÎóÅäÖõÄÊý¾Ý¿âºÍ·þÎñÒÀÈ»ÊÇÊý¾Ýй¶µÄÖØÒªÆðÔ´£¬£¬£¬£¬£¬£¬2020ÄêµÚ¶þ¼¾¶È£¬£¬£¬£¬£¬£¬½öÁ½¸ö·ì϶¾Íµ¼ÖÂÁË180ÒÚÌõÊý¾Ýй¶¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2020/08/18/publicly-reported-data-breaches-down-52-exposed-records-way-up/


¾©¹«Íø°²±¸11010802024551ºÅ