
本站推荐电影
本站推荐电视剧
电影下载排行
电视剧下载排行

一 | A Russian court on Monday ordered a Russian-American journalist who was detained last week on charges of failing to register as a foreign agent to remain in custody until early December, her employer reported.Alsu Kurmasheva, an editor for the U.S. government-funded Radio Free Europe/Radio Liberty's Tatar-Bashkir service, appeared in a closed session in a court in the city of Kazan, the capital of the Tatarstan republic.The radio service said the court ordered her to be held until Dec. 5, rejecting her lawyer's request for preventive measures other than incarceration.She is the second U.S. journalist detained in Russia this year, after Wall Street Journal reporter Evan Gershkovich was arrested on espionage charges in March. Gershkovich remains in custody.The state-run news website Tatar-Inform said Kurmasheva faces charges of failing to register as a “foreign agent” and was collecting information on Russian military activities. Conviction would carry a sentence of up to five years in prison.Kurmasheva, who lives in Prague, was stopped June 2 at Kazan International Airport after traveling to Russia for a family emergency May 20, according to RFE/RL.Airport officials confiscated her U.S. and Russian passports and she was fined for failing to register her U.S. passport. She was waiting for her passports to be returned when the new charge was filed Wednesday, RFE/RL said.RFE/RL was told by Russian authorities in 2017 to register as a foreign agent, but it has challenged Moscow’s use of foreign agent laws in the European Court of Human Rights. The organization has been fined millions of dollars by Russia.The Committee to Protect Journalists called the charges against Kurmasheva “spurious,” saying her detention “is yet more proof that Russia is determined to stifle independent reporting.”Kurmasheva reported on ethnic minority communities in the Tatarstan and Bashkortostan republics in Russia, including projects to preserve the Tatar language and culture, her employer said.Gershkovich and The Wall Street Journal deny the allegations against him, and the U.S. government has declared him to be wrongfully detained.Russian authorities haven’t detailed any evidence to support the charges. Court proceedings against him are closed because prosecutors say details of the case are classified.。 最近引发广泛讨论的“BlackLotus”,属于一款相当全能的固件级 rootkit 恶意软件。特点是能够躲过各种删除操作,以及绕过先进的 Windows 防护措施。此前这类高级攻击能力,仅被拥有深厚背景的机构所拥有,比如情报威胁组织。然而据报道,一款更新、更强大的 UEFT rootkit,正被人挂到暗网论坛上叫卖。

二 | “防护环”示意(图自:Wikipedia / Hertzsprung)卖家宣称 BlackLotus 是一款固件级 rootkit 恶意软件,能够绕过 Windows 防护措施、并在 x86 架构的最底层运行恶意代码。率先曝光此事的安全研究人员指出,单个 rootkit 的许可证费用高达 5000 美元,而后续代码重建则只需 200 美元。不过考虑到卖家罗列出来的功能,即使需要耗费重资,世界各地的网络犯罪分子和黑帽黑客也会趋之若鹜。Scott Scheferman 总结道:BlackLotus 采用了汇编与 C 语言编写,体量仅 80KB(约 81920 字节)。通过在内核级别(ring 0)提供‘代理防护’(agent protection),该 rootkit 能够在 UEFI 固件中长期驻留。此外 BlackLotus 具有反虚拟机、反调试和代码混淆功能,以阻碍研究人员对其展开分析尝试,且附带功能齐备的安装指南 / 常见问题解答。黑市叫卖帖与同类 rootkit 一样,BlackLotus 能够在 Windows 启动前的第一阶段被加载,因而能够绕过 Windows / x86 平台上的诸多安全防护措施。除了无视 Secure Boot、UAC、BitLocker、HVCI 和 Windows Defender,该恶意软件还提供了加载未签名驱动程序的能力。其它高级功能包括功能齐备的文件传输模式、以及易攻破的签名引导加载程序 —— 除非影响当今仍在使用的数百个引导加载程序,否则很难将它斩草除根。Scott Scheferman 还强调了 BlackLotus 可能对基于固件的现代安全防护机制构成威胁。而且新 UEFI rootkit 在易用性、扩展性、可访问性、持久性、规避和破坏潜力方面,都实现了相当大的跨越。此前人们一度认为这类威胁相当罕见,但过去几天不断被打脸的攻击报告,已经指向了截然不同的未来趋势。最后,安全社区将对 BlackLotus 恶意软件的实际样本展开更加细致、深入的分析,以确定传闻的真实性、还是说它只是某人精心编造的一个骗局。
Current article:http://chenzhuaigecoupuhongyuntuizei.sbs/iej/20260826/6550.html
Published on:02:22:34