作者信息:2016-11-15 10:06:06 By 360追日团队



//下载: 蔓灵花-BITTER-APT.pdf (1.52 MB, 下载次数: 52)
文件大小:1,598,449 bytes
MD5     : 025C82550045B7A242678E8D836A2B48


2、Windows 10加入勒索软件防护机制
标题:Defending against ransomware with Windows 10 Anniversary Update

作者信息:NOVEMBER 11, 2016 9:05 AM By Rob Lefferts

Ransomware is one of the latest malware threats that is attracting an increasing number of cyber-criminals who are looking to profit from it. In fact, in the last 12 months, the number of ransomware variants have more than doubled. Its premise is deceptively simple: infect users’ devices, and then deny them access to their devices or files unless they pay a ransom. However, the methods and means attackers are using to perpetrate ransomware attacks are increasingly varied, complex and costly.
微软,软件巨人,加入了打击勒索软件的大军中了,而且是拿出了其最新终极武器:Windows 10操作系统(附带其杀毒软件Windows Defender)。

We have made significant improvements in protecting customers from ransomware in the Windows 10 Anniversary Update. To help protect against ransomware and other types of cyber threats, we suggest you:
Update to the Windows 10 Anniversary Update and accept the default security settings within Windows 10.
Keep machines up to date with the very latest updates.
Ensure that a comprehensive backup strategy is implemented and followed.
The Block at First Sight cloud protection feature in Windows Defender is enabled by default. For IT Pros, if it was turned off we recommend turning it back on, and we also recommend incorporating another layer of defense through Windows Defender ATP and Office 365 ATP.  For more information about each of these technologies and techniques and how they work, please download our white paper Ransomware Protection in Windows 10 Anniversary Update.
Cyber threats won’t stop, and neither will we. As long as ransomware remains a threat, we will continue to enhance our defenses to better protect your Windows 10 devices.
微软在其操作系统Windows 10的年度更新升级包中增加了对勒索软件的防护手段。具体的措施可以包括:
1 升级Windows 10操作系统到年度最新版,并接受系统的默认设置(难道默认只采用其Defender?)
2 保持在线更新
3 确认备份策略的正确性以及有效执行
4 默认情况下,Windows Defender的防护设置是打开的,这个设置选项是The Block at First Sight cloud protection.如果不小心关闭了,建议打开。

点评:楼上有APT:高级持续性威胁;此处有ATP:高级威胁防护。另外想起了KB的质疑(详见:20161114 3、俄罗斯调查Windows 10防毒软件垄断问题 http://arstechnica.com/informati ... ntivirus-software/?

作者信息:November 14, 2016 , 2:20 pm by Michael Mimoso

The threat posed by a ransomware family known as CrySis was diminished considerably on Sunday when the master decryption keys were released to the public. Researchers at Kaspersky Lab said they have already folded the keys into the company’s Rakhni decryptor and victims of CrySis versions 2 and 3 now have a means of recovering their lost files.
The key was posted at 1 a.m. Eastern time to the BleepingComputer.com forums by a user known only as crss7777, said founder Lawrence Abrams. Abrams speculates that it could have been the ransomware developer who posted the key on the site’s CrySis support forum page; the post included a Pastebin link to a header file written in C that contains the master decryption keys and instructions on how to use them.

In the meantime, the FBI put out a number of warnings about ransomware, urging businesses to be vigilant about patching software that could be targeted by exploit kits spreading the malware, or about email campaigns spreading these infections. “The inability to access the important data these kinds of organizations keep can be catastrophic in terms of the loss of sensitive or proprietary information, the disruption to regular operations, financial losses incurred to restore systems and files, and the potential harm to an organization’s reputation,” the FBI said in May. In September, the FBI made a public plea to organizations that have been ransomware victims to share incident reports, looking for details on how the infection happened, any losses incurred, the attackers’ Bitcoin wallet address and more.

//下载: CrySis-master decryption keys.rar (78.43 KB, 下载次数: 45)
文件名:CrySis-master decryption keys.rar
文件大小:80,310 bytes
MD5     : D243894DDB2B42579BCC069231F86EEB

点评:宣传还是很有力量的,勒索者迫于压力公开了解密方法!继续! 不过,对付勒索软件还得未雨绸缪:备份备份再备份。

标题:The hacker Kapustkiy continues to target embassies and universities

作者信息:November 14, 2016  By Pierluigi Paganini

The hacker Kapustkiy is back and breached another embassy and two universities. He leaked data on Pastebin.

Records belonging to the hacked embassy include also phone numbers, let me highlight once again that such kind of information is a precious commodity for nation-state hackers that intend to launch a spear phishing campaign against diplomats.
Kapustkiy explained to have leaked the data because the administrators of the targeted entities ignore his warning via email.
It is likely Kapustkiy exploited SQli injection flaws in the last string of data breaches.
Who is the next one?

//下载: EmbassyUniversity.rar (13.21 KB, 下载次数: 57)
文件大小:13,527 bytes
MD5     : 6DEC76BC42C79517F7A1AEA52392AEF2


标题:Shazam app on Apple Computers is always listening, even when turned off

作者信息:November 15, 2016 9:50am By Matthew Dunn

SHAZAM is a godsend when wanting to instantly identify that unknown song playing in the background, but it has a very creepy secret.
When looking at Shazam on Apple computers, a security researcher discovered the microphone remains on in the background even when the application is turned off.
Patrick Wardle discovered the issue after reverse engineering the Shazam app after receiving an email from a source.
“I’m conflicted on whether or not this is a big deal. On one hand, even when you click ‘OFF’ Shazam continues to consume audio off the internal microphone. On the other hand, they don’t appear to process or use this data in any way,” he wrote in a blog.

“Since there is no bug and no privacy issue associated with the current functionality, we do not have reasons to change the existing behaviour.”
While claiming this configuration of the Mac app gives users the best experience and doesn’t pose a security risk, Mr Wardle tells a different story.
“Due to their actions, we could get creative and easily design a piece of malware that steals this recording without having to initiate a recording itself,” he said.
So with Shazam saying it is not going to change the existing behaviour, it might be worth removing the app if you are concerned.


6、Linux LUKS漏洞可被本地远程攻击
标题:Major Linux security hole gapes open
An old Linux security 'feature' script, which activates LUKS disk encryption, has been hiding a major security hole in plain sight.

作者信息:November 15, 2016 -- 01:50 GMT (09:50 GMT+08:00) By Steven J. Vaughan-Nichols  

Sometimes Linux users can be smug about their system's security. And sometimes a major hole that's been hiding in Linux since about version 2.6 opens up and in you fall.
The security hole this time is with how almost all Linux distributions implement Linux Unified Key Setup-on-disk-format (LUKS). LUKS is the standard mechanism for implementing Linux hard disk encryption. LUKS is often put into action with Cryptsetup. It's in Cryptsetup default configuration file that the problem lies and it's a nasty one. Known Linux distributions with this bug include Debian, Ubuntu, Fedora, Red Hat Enterpise Linux (RHEL), and SUSE Linux Enterprise Server (SLES).
LUKS:是Linux Unified Key Setup-on-disk-format的缩写。
漏洞就出现在这个几乎所有的Linux版本都会采用的硬盘加密机制中,它常常和Cryptsetup配合使用,漏洞的利用就出现在Cryptsetup的默认配置文件中。受影响的操作系统包括:Debian, Ubuntu, Fedora, Red Hat Enterpise Linux (RHEL)和SUSE Linux Enterprise Server (SLES)等。

The Linux distributors will soon have this fixed. But, in the meantime, we've got another security headache. Savvy Linux administrators shouldn't wait. They should patch the configuration file.
The hole was found by Hector Marco Gisbert, a computer science lecturer at the University of the West of Scotland. He presented a speech, "Abusing LUKS to Hack the System" at the DeepSec 2016 security conference.
补丁很快就会推出的。但是几乎同时可能又会出现另外一个严重的安全漏洞,维护人员应该及时给组态文件打补丁。该漏洞是由一个西苏格兰大学的计算机教授发现的,并在今年的安全大会上发表过演讲,题目就是利用LUKS攻击系统 Abusing LUKS to Hack the System。


