AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2020.07.06-2020.07.12£©
2020-07-15
Ò»¡¢ Íþвͨ¸æ
F5 BIG-IP TMUIÔ¶³Ì´úÂëÖ´ÐÐÎó²î
¡¾Ðû²¼Ê±¼ä¡¿2020-07-12 13:00:00 GMT
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬AG¹«Ë¾¿Æ¼¼¼à²âµ½F5¹Ù·½¶ÔÁ÷Á¿ÖÎÀíÓû§½çÃæ£¨TMUI£©Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-20 20-5902£©µÄÇ徲ͨ¸æ¾ÙÐÐÁ˸üС£ÊÜÓ°ÏìµÄ15.x°æ±¾±ä»»Îª15.0.0-15.1.0£¬¸üÐÂÁ˿ɱ»ÈƹýµÄÔÝʱ»º½â²½·¥¼°ÑéÖ¤ÒªÁ죻δ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýBIG-IPÖÎÀí¶Ë¿Ú»ò×ÔÉíIP»á¼ûTMUI£¬¿É½á¹¹¶ñÒâÇëÇó»ñȡĿµÄ·þÎñÆ÷ȨÏÞ£¬CVSSÆÀ·ÖΪ10·Ö¡£
¡¾Á´½Ó¡¿
http://blog.nsfocus.net/f5-big-ip-tmui-0705/
Citrix¶à¸ö¸ßΣÎó²î
¡¾Ðû²¼Ê±¼ä¡¿2020-07-12 14:00:00 GMT
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬CitrixÐû²¼Çå¾²¸üÐÂͨ¸æ£¬ÌåÏÖÒÑÐÞ¸´ÆäCitrix ADC(ÒÔǰ³ÆÎªNetScaler ADC)¡¢Citrix Gateway?(ÒÔǰ³ÆÎªNetScaler Gateway)ºÍCitrix SD-WAN WANOP×°±¸ÖеĹ²11¸öÎó²î¡£
¡¾Á´½Ó¡¿
http://blog.nsfocus.net/citrix-0712/
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. Evilnum×éÖ¯Õë¶Ô½ðÈڿƼ¼¹«Ë¾
¡¾¸ÅÊö¡¿
Evilnum×é֯ͨ¹ýÖ¸Ïò°üÀ¨ÔÚGoogleÔÆ¶ËÓ²ÅÌÖеÄZIPÎļþµÄÁ´½ÓµÄÓã²æÊ½µç×ÓÓʼþÀ´Èö²¥¶ñÒâÈí¼þ£¬¸Ã×éÖ¯µÄÖ÷ҪĿµÄÊǼàÊÓijЩ½ðÈڿƼ¼¹«Ë¾²¢´ÓÄ¿µÄ¹«Ë¾¼°Æä¿Í»§ÄÇÀï»ñÈ¡²ÆÎñÐÅÏ¢£¬Èç´øÓпͻ§Çåµ¥¡¢Í¶×ʺÍÉúÒâ²Ù×÷µÄµç×Ó±í¸ñºÍÎĵµ£¬À´×Ôä¯ÀÀÆ÷µÄCookies¡¢»á»°ÐÅÏ¢¡¢¿Í»§ÐÅÓÿ¨ÐÅÏ¢ºÍµØµã/Éí·Ý֤ʵÎļþµÈ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.welivesecurity.com/2020/07/09/more-evil-deep-look-evilnum-toolset/
2. MiraiбäÖÖÔöÌíCVE-2020-10173Îó²îʹÓÃ
¡¾¸ÅÊö¡¿
MiraiбäÖÖʹÓõÄÎó²îÓÉоÉÍŽá×é³É£¬¿É×ÊÖú¹¹½¨ÁýÕÖ²î±ðÀàÐÍÅþÁ¬×°±¸µÄÆÕ±éÍøÂç¡£½üÆÚ¹¥»÷Ô˶¯ÖÐʹÓõľŸöÎó²î»áÓ°ÏìIPÉãÏñ»ú¡¢ÖÇÄܵçÊӺͷÓÉÆ÷µÈµÄÌØ¶¨°æ±¾¡£ÖµµÃÒ»ÌáµÄÊÇÆäÖÐCVE-2020-10173ÊÇÔÚComtrend VR-3033·ÓÉÆ÷Öз¢Ã÷µÄ¶àÖØÉí·ÝÑéÖ¤ÏÂÁî×¢ÈëÎó²î£¬Ô¶³Ì¶ñÒâ¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÀ´ÆÆËð·ÓÉÆ÷ÖÎÀíµÄÍøÂç¡£
¡¾²Î¿¼Á´½Ó¡¿
https://blog.trendmicro.com/trendlabs-security-intelligence/new-mirai-variant-expands-arsenal-exploits-cve-2020-10173/
3. Operation Honey Trap:APT36Õë¶ÔÓ¡¶È¹ú·À×éÖ¯
¡¾¸ÅÊö¡¿
APT36Õë¶ÔÓ¡¶È¹ú·À×éÖ¯ºÍÆäËûÕþ¸®×éÖ¯µÄÖ°Ô±·¢¶¯Honey TrapÐж¯£¬Ê¹ÓÃÒýÓÕÐÔµÄÐéα×ÊÁÏÓÕʹĿµÄ¹¤¾ß·¿ªµç×ÓÓʼþ£¬»òÊÇÔÚÐÂÎÅת´ïƽ̨ÉÏ̸Ì죬×îÖÕµ¼ÖÂÄ¿µÄÓû§ÏÂÔØ¶ñÒâÈí¼þ¡£APT36£¬ÓÖÃûProjectM¡¢Transparent TribeºÍTEMP.Lapis£¬ÊÇÒ»¸öÖÁÉÙ´Ó2016Äê»îÔ¾ÖÁ½ñµÄ°Í»ù˹̹Íþв×éÖ¯£¬Ö÷ÒªÕë¶ÔÓ¡¶ÈÕþ¸®¡¢¹ú·À²¿ºÍʹ¹Ý¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.seqrite.com/blog/operation-honey-trap-apt36-targets-defense-organizations-in-india/
4. Lazarus×é֯ʹÓÃMagecart¹¥»÷ÃÀ¹úºÍÅ·ÖÞµçÉÌ
¡¾¸ÅÊö¡¿
Lazarus×é֯ʹÓÃδ¾ÊÚȨµÄ»á¼û½«¶ñÒâ¾ç±¾×¢ÈëÊÐËÁ½áÕÊÒ³Ãæ£¬¿Í»§Íê³ÉÉúÒâºó£¬Í¨¹ýMagecart×èµ²µÄÊý¾Ý½«·¢Ë͵½¹¥»÷Õß¿ØÖƵÄÊÕ¿î·þÎñÆ÷¡£¹¥»÷ÕßʹÓÃÓã²æÊ½¹¥»÷À´»ñÈ¡ÁãÊÛÖ°Ô±µÄÃÜÂ룬ÐÞ¸ÄÔËÐÐÔÚÏßÊÐËÁµÄÅÌËã»ú´úÂëÍê³É¶ÔÉúÒâµÄ×èµ²£¬´Ë´Î¹¥»÷Ô˶¯Ö÷ÒªÕë¶ÔÃÀ¹úºÍÅ·ÖÞµçÉÌ¡£Lazarus Group£¨ÓÖÃûHIDDEN COBRA¡¢Guardians of Peace¡¢ZINCºÍNICKEL ACADEMY£©ÊÇÒ»¸öÍþв×éÖ¯£¬¹éÊôÓÚ³¯ÏÊÕþ¸®£¬¸Ã×éÖ¯ÖÁÉÙ´Ó2009ÄêÒÔÀ´Ò»Ö±»îÔ¾¡£
¡¾²Î¿¼Á´½Ó¡¿
https://sansec.io/research/north-korea-magecart#fn:hiddencobra
5. LampionľÂíбäÖÖÕë¶ÔÆÏÌÑÑÀ
¡¾¸ÅÊö¡¿
LampionľÂíбäÌåͨ¹ý¼òÆÓµÄµç×ÓÓʼþÄ£°å·Ö·¢£¬Óû§Í¨¹ýÓʼþÔÚÆäÖÐÏÂÔØÁËÄÚ²¿°üÀ¨VBSÏÂÔØÆ÷µÄZIPÎļþ¡£¹¥»÷ÕßʹÓÃαÔìµÄÍøÒ³·Ö·¢ÁËÒ»¸öMSIÎļþ£¬¸ÃÎļþʹÓÃÁËÄ£ÄâÆÏÌÑÑÀÕþ¸®µÄÖ÷ÌâCOVID-19£¬²¢ÔÚ±»Ö´ÐкóÆô¶¯VBSÎļþÏÂÔØ¶ñÒâÈí¼þ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://seguranca-informatica.pt/new-release-of-lampion-trojan-spreads-in-portugal-with-some-improvements-on-the-vbs-downloader/#.XwPiOigzbIU
6. JokerбäÌåαװ³ÉÕýµ±Ó¦ÓÃʹÓÃGoogle PlayÈö²¥
¡¾¸ÅÊö¡¿
½üÆÚÑо¿Ö°Ô±ÔÚGoogle PlayÉÏ·¢Ã÷Joker DropperºÍPremium DialerÌØ¹¤Èí¼þµÄбäÌ壬ÆäÖÐJokerбäÌåÄܹ»½«ÆäËû¶ñÒâÈí¼þÏÂÔØµ½×°±¸ÉÏ£¬´Ó¶øÔÚÓû§²»ÖªÇé»òδÔ޳ɵÄÇéÐÎÏÂÏòÓû§¶©ÔÄÁ˸߼¶·þÎñ¡£JokerÊÇAndroidÉÏ×îÖøÃûµÄ¶ñÒâÈí¼þÖ®Ò»£¬Ð±äÌ彫¶ñÒâdexÎļþÒþ²ØÎªBase64±àÂëµÄ×Ö·û´®£¬ÒÔ×èÖ¹±»Google¼ì²âµ½£¬Í¬Ê±Ê¹ÓÃNotification Listener·þÎñºÍ¶¯Ì¬dexÎļþÖ´ÐÐ×¢²áʵÏÖÔÚδÕ÷µÃÆäÓû§ÖªÇé»òÔ޳ɵÄÇéÐÎÏÂÏòÓ¦ÓóÌÐòÓû§¶©Ôĸ߼¶·þÎñµÄ¹¦Ð§¡£
¡¾²Î¿¼Á´½Ó¡¿
https://research.checkpoint.com/2020/new-joker-variant-hits-google-play-with-an-old-trick/
7. ¹¥»÷ÕßÕë¶ÔÆÏÌÑÑÀ·¢¶¯ÍøÂç´¹ÂÚÔ˶¯
¡¾¸ÅÊö¡¿
½üÆÚÕë¶ÔÆÏÌÑÑÀµÄÍøÂç´¹ÂÚÔ˶¯ÖУ¬¹¥»÷Õß·Ö·¢´¹ÂÚÓʼþÒÔÕË»§±»ÆÁÕÏ»òÕßÕË»§·ÖÀ಻¶ÔÀíΪÓÕ¶üÖ¸µ¼Êܺ¦Õßµã»÷³¬Á´½Ó£¬´Ó¶ø½«ÆäÖ¸µ¼µ½ÏìÓ¦µÄÔ˶¯Éϰ¶Ò³Ã棬´Ë´Î¹¥»÷Ô˶¯Ö¼ÔÚÍøÂçÆÏÌÑÑÀÊܺ¦ÕßµÄСÎÒ˽¼ÒÊý¾ÝºÍÐÅÓÿ¨ÐÅÏ¢¡£
¡¾²Î¿¼Á´½Ó¡¿
https://seguranca-informatica.pt/diversas-campanhas-de-phishing-em-curso-em-portugal-com-o-objetivo-de-exfiltrar-detalhes-dos-cartoes-de-credito-das-vitimas/#.XwaN5SgzbIU
8. ʹÓÃSaltStackÎó²îÌᳫµÄ¶ñÒâÍÚ¿óÔ˶¯
¡¾¸ÅÊö¡¿
¹¥»÷ÕßʹÓÃSaltStackÉÏÔËÐеÄZeroMQÐÒéÖеÄCVE-2020-11651ºÍCVE-2020-11652Îó²î¾ÙÐй¥»÷Ô˶¯£¬ÕâЩÎó²î½«ÔÊÐíÒÔrootÓû§Éí·ÝÖ±½ÓÔÚÄ¿µÄϵͳÉÏÖ´ÐÐÔ¶³Ì´úÂ룬´Ó¶øÒÔ×î¸ßµÄÏµÍ³ÌØÈ¨ÀÖ³ÉÏÂÔØ²¢Ö´Ðо籾£¬¾ç±¾»áɨ³ýÐí¶àÏÈǰ±£´æµÄÍÚ¿óÈí¼þºÍÒÑÖªµÄÇå¾²¹¤¾ßºÍÈí¼þ£¬È»ºóÏÂÔØ×ÔÉí¶ñÒâÍÚ¿óÈí¼þ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.darktrace.com/en/blog/speed-of-weaponization-from-vulnerability-disclosure-to-crypto-mining-campaign-in-a-week/
9. CracxStealerÇÔÃÜľÂíÀÄÓÃÈí¼þÆÆ½â²¹¶¡Èö²¥
¡¾¸ÅÊö¡¿
CracxStealerÇÔÃÜľÂí½üÆÚͨ¹ý¾³ÍâÈí¼þÆÆ½â²¹¶¡ÏÂÔØÍøÕ¾£¨cracx[.]com£©Èö²¥£¬¸ÃľÂí±»Ö²ÈëÍøÕ¾ÌṩÏÂÔØµÄϵͳ¹¤¾ß¡¢Ã½ÌåÈí¼þ¡¢°ì¹«Èí¼þ¡¢´óÐÍÓÎÏ·¡¢ÒÔ¼°Éè¼ÆÀàµÈÉÌÒµÈí¼þµÄÆÆ½â²¹¶¡°üÖУ¬Ò»µ©±»Ñ¬È¾£¬Óû§µÄµÇ¼ƾ֤¡¢ä¯ÀÀÆ÷ÉèÖÃÎļþ¡¢¼ÓÃÜÇ®±ÒÇ®°üÕ˺ŵÈÃô¸ÐÐÅÏ¢»á±»´ò°ü·¢ËÍÖÁ¹¥»÷ÕßµÄÏÂÁîºÍ¿ØÖÆ·þÎñÆ÷¡£
¡¾²Î¿¼Á´½Ó¡¿
https://s.tencent.com//research/report/1034.html
10. CerberusÒøÐÐľÂíÕë¶ÔÎ÷°àÑÀAndroidÓû§
¡¾¸ÅÊö¡¿
½üÆÚCerberusľÂíÔÚGoogle PlayÉÏαװ³ÉÕýµ±Ó¦ÓóÌÐòCalculadora de Moneda£¨Î÷°àÑÀÇ®±Òת»»Æ÷£©£¬ÒÔÎ÷°àÑÀAndroidÓû§ÎªÄ¿µÄ£¬²¢±»ÏÂÔØÁË10,000´ÎÒÔÉÏ¡£CerberusľÂí¿É»á¼ûÓû§µÄÒøÐÐÓªÒµÏêϸÐÅÏ¢¡¢ÔĶÁ¶ÌÐÅ¡¢Ë«ÒòËØÉí·ÝÑéÖ¤ÏêϸÐÅÏ¢µÈ£¬²¢ÇÔÈ¡ËùÓлá¼ûÊý¾Ý¡£
¡¾²Î¿¼Á´½Ó¡¿
https://blog.avast.com/avast-finds-banking-trojan-cerberus-on-google-play-avast

AG¹«Ë¾ÔÆ







