AG¹«Ë¾ÍþвÇ鱨Öܱ¨£¨20200427~20200510£©
2020-05-11
Ò»¡¢Íþвͨ¸æ
- Jenkins²å¼þ¶à¸öÎó²î
¡¾Ðû²¼Ê±¼ä¡¿2020-05-08 18:00:00 GMT
¡¾¸ÅÊö¡¿5ÔÂ6ÈÕ£¬Jenkins¹Ù·½Ðû²¼Ç徲ͨ¸æÐÞ¸´²å¼þÖеÄ9¸öÎó²î£¬ÓÐ5¸ö²å¼þÊܵ½Ó°Ïì¡£ÆäÖÐSCM Filter Jervis²å¼þ±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-2189£©£¬¹Ù·½¶¨¼¶Îª¸ßΣ¡£ÓÉÓÚSCM Filter Jervis²å¼þĬÈϲ»ÉèÖÃYAMLÆÊÎöÆ÷£¬µ¼ÖÂÓû§¿ÉÒÔʹÓùýÂËÆ÷ÉèÖÃÏîÄ¿£¬Ò²¿ÉÒÔ²Ù×÷SCMÒÑ´æ´¢ÉèÖùýµÄÏîÄ¿ÄÚÈÝ¡£Credentials Binding ²å¼þ±£´æÁ½¸öƾ֤й¶Îó²î£¨CVE-2020-2181¡¢CVE-2020-2182£©£¬Copy Artifact ²å¼þ±£´æÈ¨ÏÞУÑé²»µ±Îó²î£¨CVE-2020-2183£©£¬CVS ²å¼þµÄ¿çÕ¾ÇëÇóαÔìÎó²î£¨CVE-2020-2184£©¼°Amazon EC2 ²å¼þÖеÄ4 ¸öÎó²î£¨CVE-2020-2185¡¢CVE-2020-2186¡¢CVE-2020-2187¡¢CVE-2020-2188£©¡£
¡¾Á´½Ó¡¿http://blog.nsfocus.net/jenkins-0508/
¶þ¡¢ÈÈÃÅ×ÊѶ
- SaltStack¶à¸öÎó²î
¡¾¸ÅÊö¡¿¿ËÈÕ£¬·þÎñÆ÷»ù´¡¼Ü¹¹¼¯Öл¯ÖÎÀíÆ½Ì¨SaltStack Salt±»Åû¶±£´æÁ½¸öÇå¾²Îó²î£¨CVE-2020-11651¡¢CVE-2020-11652£©¡£¿ªÔ´ÏîÄ¿SaltÊÇSaltStack¹«Ë¾²úÆ·µÄ½¹µã£¬×÷ΪÖÎÀíÊý¾ÝÖÐÐĺÍÔÆÇéÐÎÖзþÎñÆ÷µÄÉèÖù¤¾ß£¬¹ãÊܽӴý¡£SaltStack Salt±£´æµÄÁ½¸öÎó²î»®·ÖÊÇÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2020-11651£©ºÍĿ¼±éÀúÎó²î£¨ CVE-2020-11652£©¡£
¡¾²Î¿¼Á´½Ó¡¿http://blog.nsfocus.net/saltstack-0504/
- WeblogicÔ¶³Ì´úÂëÖ´ÐÐÎó²î
¡¾¸ÅÊö¡¿ÔÚOracle¹Ù·½Ðû²¼µÄ2020Äê4ÔÂÒªº¦²¹¶¡¸üÐÂͨ¸æCPU£¨Critical Patch Update£©ÖУ¬Á½¸öÕë¶Ô WebLogic Server£¬CVSS 3.0ÆÀ·ÖΪ 9.8µÄÑÏÖØÎó²î£¨CVE-2020-2883¡¢CVE-2020-2884£©£¬ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýT3ÐÒéÍøÂç»á¼û²¢ÆÆËðÒ×Êܹ¥»÷µÄWebLogic Server£¬ÀֳɵÄÎó²îʹÓÿɵ¼ÖÂWebLogic Server±»¹¥»÷Õß½ÓÊÜ£¬´Ó¶øÔì³ÉÔ¶³Ì´úÂëÖ´ÐС£Îó²î±£´æÓÚWebLogic Server½¹µã×é¼þÖУ¬Ê¹ÓÃʱÎÞÐèÉí·ÝÈÏÖ¤¼°ÌØÊâ½»»¥£¬²¢ÇÒÔÚWeblogic¿ØÖÆÌ¨¿ªÆôµÄÇéÐÎÏÂĬÈÏ¿ªÆôT3ÐÒ飬¹ÊÓ°ÏìÃæ½Ï´ó¡£
¡¾²Î¿¼Á´½Ó¡¿http://blog.nsfocus.net/weblogic-solution-0508/
- H2Miner½©Ê¬ÍøÂçʹÓÃSaltStackÎó²îÈëÇÖ·þÎñÆ÷ÍÚ¿ó
¡¾¸ÅÊö¡¿H2MinerÊÇÒ»¸ölinuxϵÄÍÚ¿ó½©Ê¬ÍøÂ磬ͨ¹ýhadoop yarnδÊÚȨ¡¢thinkphp 5 RCE¡¢confluence RCE¡¢dockerºÍRedisδÊÚȨµÈ¶àÖÖÊֶξÙÐÐÈëÇÖ£¬·Ö·¢¶ñÒâ³ÌÐò¾ÙÐÐÍÚ¿ó»ñÈ¡ÀûÒæ¡£¿ËÈÕH2Miner½©Ê¬ÍøÂçʹÓÃSaltStackÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2020-11651£©ºÍĿ¼±éÀúÎó²î£¨ CVE-2020-11652£©ÈëÇÖÆóÒµÖ÷»ú¾ÙÐÐÍÚ¿ó¡£
¡¾²Î¿¼Á´½Ó¡¿https://s.tencent.com/research/report/976.html
- PerSwaysionÔ˶¯ÀÄÓÃMicrosoftÎĵµ¹²Ïí·þÎñ
¡¾¸ÅÊö¡¿½üÆÚ£¬¶à¸öÍøÂç·¸·¨¼¯ÍÅÌᳫһϵÁÐСÐ͵«ÓÐÕë¶ÔÐÔµÄÍøÂç´¹ÂÚ¹¥»÷£¬ÓÉÓÚÆäÀÄÓÃÁËSway·þÎñ£¬Õâ´ÎÐж¯±»³ÆÎªPerSwaysion£¬´Ë´ÎÐж¯Ö÷ÒªÊÇͨ¹ýÀÄÓÃMicrosoftµÄÎļþ¹²Ïí·þÎñÀ´ÊµÏֵ쬹¥»÷»¹½ÓÄÉÖÖÖÖÏ´°×ÊÖÒպͷ´Ç鱨ҪÁìÌӱܼì²â£¬ÆäÄ¿µÄÊÇλÓÚÃÀ¹ú¡¢¼ÓÄô󡢵¹ú¡¢Ó¢¹ú¡¢ºÉÀ¼¡¢Ïã¸ÛºÍÐÂ¼ÓÆÂµÈÈ«ÇòºÍµØÇø½ðÈÚÖÐÐĵÄÖÐСÐͽðÈÚ·þÎñ¹«Ë¾¡¢×´Ê¦ÊÂÎñËùºÍ·¿µØ²ú¼¯ÍÅ¡£
¡¾²Î¿¼Á´½Ó¡¿https://www.group-ib.com/blog/perswaysion
- Naikon×é֯ʹÓÃкóÃÅAria-bodyÕë¶ÔÑÇÌ«µØÇø
¡¾¸ÅÊö¡¿Naikon×éÖ¯Õë¶ÔÑÇÌ«µØÇø°üÀ¨°Ä´óÀûÑÇ¡¢Ó¡¶ÈÄáÎ÷ÑÇ¡¢·ÆÂɱö¡¢Ô½ÄÏ¡¢Ì©¹ú¡¢ÃåµéºÍÎÄÀ³¼¸¸ö¹ú¼ÒµÄÕþ¸®ÊµÌå¾ÙÐмàÊÓºÍÍøÂçÇ鱨¡£¸Ã×éÖ¯´ÓÊÜѬȾµÄÅÌËã»úºÍÕþ¸®²¿·ÖµÄÍøÂç¡¢¿ÉÒÆ¶¯Çý¶¯Æ÷Öж¨Î»ºÍÍøÂçÌØ¶¨µÄÎļþ¡¢½ØÆÁºÍ¼üÅ̼ͼ£¬»¹Ê¹ÓÃÊÜѬȾ²¿·ÖµÄ·þÎñÆ÷×÷ΪC2·þÎñÆ÷À´ÍøÂ硢ת·¢ºÍ·ÓÉÇÔÈ¡µÄÊý¾Ý¡£´Ë´Î¹¥»÷¸Ã×é֯ʹÓÃÁËÒ»¸öÃûΪAria-bodyµÄкóÃÅ£¬ÒÔ¿ØÖÆÊܺ¦ÕßµÄÍøÂ磬Aria-bodyʹÓÃÌØ¶¨¼ÓÔØÆ÷¼ÓÔØµ½ÅÌËã»úÖУ¬²¢ÔÊÐí¹¥»÷ÕßÍêÈ«¿ØÖÆÊܺ¦ÕßµÄÅÌËã»ú£¬Ö´ÐÐÎļþºÍÀú³Ì²Ù×÷£¬Ö´ÐÐshellÏÂÁÒÔ¼°ÉÏ´«ºÍÏÂÔØÊý¾ÝºÍÆäËû²å¼þ¡£
¡¾²Î¿¼Á´½Ó¡¿https://research.checkpoint.com/2020/naikon-apt-cyber-espionage-reloaded/
- OceanLotus×éÖ¯ÀÄÓÃÕýµ±Ö¤Êéͨ¹ýAndroidÓ¦ÓÃÊг¡Èö²¥¶ñÒâÈí¼þ
¡¾¸ÅÊö¡¿OceanLotus×é֯ͨ¹ý¹Ù·½ºÍµÚÈý·½Êг¡Èö²¥AndroidÓ¦ÓóÌÐòµÄ¶ñÒâÈí¼þµÄÐÐΪ¿ÉÒÔ×·Ëݵ½2014Ä꣬½üÆÚOceanLotus×é֯ʹÓÃÁËÕýµ±µÄÊý×ÖÖ¤Êé¶ÔһЩÑù±¾¾ÙÐÐÁËÊðÃû£¬Ê×ÏÈÉÏ´«Ò»¸öÇå½àµÄ°æ±¾£¬È»ºóÌí¼Ó¶ñÒâÈí¼þ£¬Í¨¹ýGoogle PlayºÍµÚÈý·½Êг¡¾ÙÐÐÈö²¥£¬´Ë´Î¹¥»÷Ô˶¯µÄÄ¿µÄÊܺ¦ÕßÖ÷ÒªÕë¶Ô·ÇÖÞºÍÑÇÖÞµØÇø¡£OceanLotus£¬Ò²±»³ÆÎªAPT32¡¢SeaLotusºÍOcean Buffalo£¬ÊÇÒ»¸öÓëÔ½ÄÏÓйصÄÍþв×éÖ¯¡£
¡¾²Î¿¼Á´½Ó¡¿https://labs.bitdefender.com/2020/05/android-campaign-from-known-oceanlotus-apt-group-potentially-older-than-estimated-abused-legitimate-certificate/
- Lazarus×é֯ͨ¹ý2FAÓ¦ÓóÌÐò·Ö·¢DaclsľÂí
¡¾¸ÅÊö¡¿Lazarus×éÖ¯×Ô2009ÄêÒÔÀ´´ÓÊÂÍøÂçÌØ¹¤ºÍÍøÂç·¸·¨Ô˶¯£¬¾ßÓг¯ÏÊÅä¾°£¬Ò²±»³ÆÎªHidden Cobra¡£DaclsÊÇÒ»ÖÖÔ¶³Ì»á¼ûľÂí£¬ÊÇÒ»ÖÖÕë¶ÔWindowsºÍLinuxƽ̨µÄÈ«¹¦Ð§Òþ²ØÔ¶³Ì»á¼ûľÂí¡£½üÆÚLazarus×é֯ʹÓÃDaclsÔ¶³Ì»á¼ûľÂíµÄбäÖÖ£¬Í¨¹ý2FAÓ¦ÓóÌÐò·Ö·¢£¬Õë¶ÔʹÓÃMac²Ù×÷ϵͳµÄÖйúÓû§¾ÙÐй¥»÷£¬¾ÙÐÐÏÂÁîÖ´ÐС¢ÎļþÖÎÀí¡¢Á÷Á¿ÊðÀíºÍÈ䳿ɍÃèµÈ²Ù×÷¡£
¡¾²Î¿¼Á´½Ó¡¿https://blog.malwarebytes.com/threat-analysis/2020/05/new-mac-variant-of-lazarus-dacls-rat-distributed-via-trojanized-2fa-app/
- жñÒâÈí¼þKaijiͨ¹ýSSH±©Á¦ÆÆ½âÈö²¥
¡¾¸ÅÊö¡¿½üÆÚÒ»¸öеĽ©Ê¬ÍøÂçÔ˶¯Ê¹ÓÃ×Ô½ç˵ֲÈ빤¾ßKaiji£¬¸Ã¶ñÒâÈí¼þÓëÖйúÓйأ¬Õâ¸ö½©Ê¬ÍøÂçʹÓÃGolang±à³ÌÓïÑÔ´ÓÁã×îÏȹ¹½¨£¬²¢Í¨¹ýSSH±©Á¦ÆÆ½âÄ¿µÄ·þÎñÆ÷ºÍÎïÁªÍø×°±¸¡£
¡¾²Î¿¼Á´½Ó¡¿https://intezer.com/blog/research/kaiji-new-chinese-linux-malware-turning-to-golang/
- EVILNUM¶ñÒâÈí¼þÕë¶ÔÈ«Çò½ðÈÚÒµµÄ¹¥»÷Ô˶¯
¡¾¸ÅÊö¡¿EVILNUM¶ñÒâÈí¼þÕë¶ÔÈ«Çò½ðÈÚÒµ£¬Í¨¹ýʹÓÃαװ³ÉpdfºÍjpegµÄľÂíÎļþ¾ÙÐÐÈö²¥¡£µ±Îļþ±»·¿ªÊ±£¬°üÀ¨ÐÅÓÿ¨¡¢¼ÝÕÕ¡¢»¤ÕÕºÍË®µç·ÑµÄÓÕÆÍ¼Ïñ±»ÏÔʾ¸øÓû§£¬Í¬Ê±ÆáºÚŲÓÃÒ»¸öÓÃheadless Javascript±àдµÄÊðÀí£¬Õâ¸öÊðÀíÕë¶ÔWindows²Ù×÷ϵͳ£¬ÔÊÐí¹¥»÷ÕßÉÏ´«ÏÂÔØÎļþ¡¢ÔËÐÐÏÂÁî¡¢ÇÔÈ¡cookieºÍ»á¼ûÆäËûÊܱ£»¤µÄÊý¾Ý¡£
¡¾²Î¿¼Á´½Ó¡¿https://blog.prevailion.com/2020/05/phantom-in-command-shell5.html
- ÐÂAggahÀ¬»øÓʼþÔ˶¯·Ö·¢¶à¸öÔ¶³Ì»á¼ûľÂí
¡¾¸ÅÊö¡¿½üÆÚAggahÔ˶¯½ÏÁ¿»îÔ¾£¬¹¥»÷ÕßʹÓÃÃâ·Ñ»ù´¡Éèʩͨ¹ý¶ñÒâÀ¬»øÓʼþ(malspam)¸½´ø¶ñÒâMicrosoft OfficeÎĵµ£¬ÏòÄ¿µÄÓû§µÄÖÕ¶Ë·Ö·¢¶à½×¶ÎѬȾ£¬Ñ¬È¾µÄ×îÖÕÓÐÓøºÔذüÀ¨¶à¸öÔ¶³Ì»á¼û¹¤¾ß£¬Agent Tesla¡¢njRATºÍNanocore RAT¡£
¡¾²Î¿¼Á´½Ó¡¿https://blog.talosintelligence.com/2020/04/upgraded-aggah-malspam-campaign.html

AG¹«Ë¾ÔÆ







