AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2020.07.13-2020.07.19£©
2020-07-20
Ò»¡¢ Íþвͨ¸æ
Windows DNS·þÎñÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î
¡¾Ðû²¼Ê±¼ä¡¿2020-07-15 12:00:00 GMT
¡¾¸ÅÊö¡¿
2020Äê7ÔÂ15ÈÕ£¬Î¢ÈíÐû²¼7ÔÂÇå¾²¸üв¹¶¡£¬ÆäÖÐÐÞ¸´ÁËÒ»¸öWindowsDNS·þÎñÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-1350£©£¬´úºÅΪSigRed£¬´ËÎó²îÒѱ£´æ17ÄêÖ®¾Ã£¬CVSSÆÀ·ÖΪ10¡£Ä¬ÈÏÉèÖÃÏ£¬Î´ÂÄÀúÖ¤µÄ¹¥»÷Õß¿ÉÒÔÏòWindowsDNS·þÎñÆ÷·¢ËͶñÒâÇëÇóÀ´Ê¹ÓôËÎó²î¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
Weblogic¶à¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î
¡¾Ðû²¼Ê±¼ä¡¿2020-07-15 12:00:00 GMT
¡¾¸ÅÊö¡¿
2020Äê7ÔÂ15ÈÕ£¬Oracle¹Ù·½Ðû²¼2020Äê7ÔÂÒªº¦²¹¶¡¸üУ¨CriticalPatchUpdate£©£¬ÐÞ¸´ÁË443¸öΣº¦Ë®Æ½²î±ðµÄÇå¾²Îó²î¡£ÆäÖаüÀ¨4¸öWebLogicµÄÑÏÖØÎó²î£¨CVE-2020-14625¡¢CVE2020-14644¡¢CVE-2020-14645¡¢CVE-2020-14687£©£¬´Ë4¸öÎó²î¾ùºÍT3¡¢IIOPÐÒéÏà¹Ø£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿Éͨ¹ý´Ë´ÎµÄÎó²îʵÏÖÔ¶³Ì´úÂëÖ´ÐС£CVSSÆÀ·Ö¾ùΪ9.8£¬Ê¹ÓÃÖØÆ¯ºóµÍ¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
΢Èí2020Äê7ÔÂÇå¾²¸üÐÂ
¡¾Ðû²¼Ê±¼ä¡¿2020-07-15 18:00:00 GMT
¡¾¸ÅÊö¡¿
±±¾©Ê±¼ä2020Äê7ÔÂ15ÈÕ£¬Î¢ÈíÐû²¼7ÔÂÇå¾²¸üв¹¶¡£¬ÐÞ¸´ÁË124¸öÇå¾²ÎÊÌâ£¬Éæ¼°Microsoft Windows¡¢InternetExplorer¡¢MicrosoftOffice¡¢MicrosoftEdge¡¢WindowsDefender¡¢Visual StudioµÈÆÕ±éʹÓõIJúÆ·£¬ÆäÖаüÀ¨Ô¶³Ì´úÂëÖ´ÐкÍȨÏÞÌáÉýµÈ¸ßΣÎó²îÀàÐÍ¡£±¾ÔÂ΢ÈíÔ¶ȸüÐÂÐÞ¸´µÄÎó²îÖУ¬ÑÏÖØË®Æ½ÎªÒªº¦£¨Critical£©µÄÎó²î¹²ÓÐ18¸ö£¬Ö÷Òª£¨Important£©Îó²îÓÐ106¸ö¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. SAP NetWeaver AS JavaÑÏÖØÎó²î
¡¾¸ÅÊö¡¿
ÍâµØÊ±¼ä2020Äê7ÔÂ13ÈÕ£¬SAPÐû²¼Çå¾²¸üÐÂÌåÏÖ£¬ÐÞ¸´ÁËÒ»¸ö±£´æÓÚSAP NetWeaver AS Java£¨LMÉèÖÃÏòµ¼£©7.30ÖÁ7.50°æ±¾ÖеÄÑÏÖØÎó²îCVE-2020-6287¡£Îó²îÔµÓÚSAP NetWeaver AS for Java Web×é¼þÖÐȱÉÙÉí·ÝÑéÖ¤£¬Òò´ËÔÊÐí¹¥»÷ÕßÔÚÊÜÓ°ÏìµÄSAPϵͳÉϾÙÐиßÌØÈ¨Ô˶¯¡£
¡¾²Î¿¼Á´½Ó¡¿
http://blog.nsfocus.net/sap-netweaver-as-java-0714/
2. Oracleȫϵ²úÆ·2020Äê7ÔÂÒªº¦²¹¶¡¸üÐÂ
¡¾¸ÅÊö¡¿
ÍâµØÊ±¼ä2020Äê7ÔÂ14ÈÕ£¬Oracle¹Ù·½Ðû²¼ÁË2020Äê7ÔÂÒªº¦²¹¶¡¸üÐÂͨ¸æCPU£¨Critical Patch Update£©£¬Ç徲ͨ¸æÒÔ¼°µÚÈý·½Ç徲ͨ¸æµÈͨ¸æÄÚÈÝ£¬ÐÞ¸´ÁË443¸ö²î±ðˮƽµÄÎó²î¡£
¡¾²Î¿¼Á´½Ó¡¿
http://blog.nsfocus.net/oracle-july-0715/
3. Adobe 2020Äê7ÔÂÇå¾²¸üÐÂ
¡¾¸ÅÊö¡¿
ÍâµØÊ±¼ä7ÔÂ14ÈÕ£¬Adobe¹Ù·½Ðû²¼ÁË7ÔÂÇå¾²¸üУ¬ÐÞ¸´ÁËAdobe ¶à¿î²úÆ·ÖеĶà¸öÎó²î£¬°üÀ¨Adobe Creative Cloud Desktop?Application¡¢Adobe Media Encoder¡¢Adobe Genuine Service¡¢Adobe ColdFusion ºÍ Adobe Download Manager¡£
¡¾²Î¿¼Á´½Ó¡¿
http://blog.nsfocus.net/adobe-july-0715/
4. Cisco¶à¿î²úÆ·Ðû²¼Çå¾²¸üÐÂ
¡¾¸ÅÊö¡¿
ÍâµØÊ±¼ä2020Äê7ÔÂ15ÈÕ £¬CiscoΪ¶à¿î²úÆ·Ðû²¼ÁËÇå¾²¸üÐÂͨ¸æ£¬¹²½â¾öÁË5¸öÆÀ·Ö9.8µÄCritical¼¶±ðÎó²î£¨CVE-2020-3330¡¢CVE-2020-3323¡¢CVE-2020-3144¡¢CVE-2020-3331¡¢CVE-2020-3140£©¡£
¡¾²Î¿¼Á´½Ó¡¿
http://blog.nsfocus.net/cisco-0716/
5. APT29Õë¶ÔCOVID-19ÒßÃ翪·¢×éÖ¯µÄ¹¥»÷Ô˶¯
¡¾¸ÅÊö¡¿
APT29×éÖ¯½üÆÚʹÓÃÃûΪWellMessºÍWellMailµÄ×Ô½ç˵¶ñÒâÈí¼þÕë¶Ô¼ÓÄôó¡¢ÃÀ¹úºÍÓ¢¹úµÄ¼ÓÈëCOVID-19ÒßÃ翪·¢µÄ¸÷¸ö×éÖ¯£¬ÇÔÈ¡ÓëCOVID-19ÒßÃçµÄ¿ª·¢ºÍ²âÊÔÓйصÄÐÅÏ¢ºÍ֪ʶ²úȨ¡£APT29(ÓÖÃûCozy Bear¡¢CozyDuke¡¢The DukesºÍYTTRIUM)ÊÇÒ»¸ö¹éÊôÓÚ¶íÂÞ˹Õþ¸®µÄÍþв×éÖ¯£¬ÖÁÉÙ×Ô2008ÄêÒÔÀ´Ò»Ö±»îÔ¾¡£
¡¾²Î¿¼Á´½Ó¡¿
6. Welcome Chat¶ñÒâÈí¼þÕë¶Ô°¢À²®Óû§
¡¾¸ÅÊö¡¿
Welcome Chat¿´ËÆÒ»¿î¹¦Ð§Ç¿Ê¢µÄ̸ÌìÓ¦ÓóÌÐò£¬ÊµÔòÊÇÌØ¹¤Èí¼þ£¬¿ÉÒÔ¼àÊÓÊܺ¦Õß²¢Ãâ·Ñ»ñµÃÆäÊý¾Ý£¬¸ÃÓ¦ÓóÌÐò¾ßÓйýÂËÒÑ·¢ËͺÍÒÑÎüÊÕµÄSMSÐÂÎÅ¡¢Í¨»°¼Í¼ÀúÊ·¼Í¼¡¢ÁªÏµÈËÁÐ±í¡¢Óû§ÕÕÆ¬¡¢ÒѼͼµÄµç»°¡¢GPS×°±¸µÄλÖÃÒÔ¼°×°±¸ÐÅÏ¢µÄ¹¦Ð§£¬½üÆÚWelcome ChatÖ¼ÔÚ±»¹¥»÷ÕßʹÓÃÕë¶Ô°¢À²®Óû§¡£´Ë´Î¹¥»÷Ô˶¯ÒÉËÆÓëMolerats×éÖ¯Óйء£
¡¾²Î¿¼Á´½Ó¡¿
https://www.welivesecurity.com/2020/07/14/welcome-chat-secure-messaging-app-nothing-further-truth/
7. Turla×é֯ʹÓÃNewPass¶ñÒâÈí¼þÕë¶ÔÍâ½»ÁìÓò
¡¾¸ÅÊö¡¿
NewPassÊÇÒ»¸öÏàµ±ÖØ´óµÄ¶ñÒâÈí¼þ£¬ËüÓɵιܡ¢¼ÓÔØÆ÷¿âºÍ¶þ½øÖÆÎļþ×é³É£¬ÒÀÀµÒ»¸ö±àÂëµÄÎļþÔÚÏ໥֮¼äת´ïÐÅÏ¢ºÍÉèÖᣵιÜÓÃÓÚ°²ÅŶþ½øÖÆÎļþ£¬¼ÓÔØÆ÷¿âÄܹ»½âÂëÌáÈ¡×îºóÒ»¸ö×é¼þµÄ¶þ½øÖÆÎļþ£¬ÈÏÕæÖ´ÐÐÌØ¶¨µÄ²Ù×÷¡£Turla×éÖ¯½üÆÚʹÓÃNewPass¶ñÒâÈí¼þÕë¶ÔÖÁÉÙÒ»¸öÅ·ÓѰî¼ÒµÄÍâ½»ºÍÍâ½»ÊÂÎñ²¿·Ö¡£TurlaÊÇÒ»¸ö×ܲ¿Î»ÓÚ¶íÂÞ˹µÄÍþв×éÖ¯£¬×Ô2004ÄêÒÔÀ´Ò»Ö±»îÔ¾¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.telsy.com/turla-venomous-bear-updates-its-arsenal-newpass-appears-on-the-apt-threat-scene/
8. RATicate×é֯ʹÓÃCloudEyE¼ÓÔØ³ÌÐòʹ¶ñÒâÈí¼þÕýµ±»¯
¡¾¸ÅÊö¡¿
RATicate×éÖ¯ÖÁÉÙ´ÓÈ¥Äê×îÏȾÍÈö²¥Ô¶³ÌÖÎÀí¹¤¾ß£¨RAT£©ºÍÆäËûÇÔÊØÐÅÏ¢µÄ¶ñÒâÈí¼þ¡£½üÆÚRATicate×é֯ʹÓÃCloudEyE¼ÓÔØ³ÌÐòÒÔ¸üÒþ²ØµÄ·½·¨½âѹËõºÍ×°ÖÃRATºÍÐÅÏ¢ÇÔÈ¡³ÌÐòµÄÓÐÓøºÔØ¡£CloudEyEÊÇÒ»¸ö¶à½×¶ÎµÄ¼ÓÔØÆ÷£¬Ò²ÊÇÒ»¸ö¶ñÒâÈí¼þµÄ¼ÓÃÜÆ÷£¬´øÓÐÒÔVisual Basic±àдµÄ°ü×°Æ÷¡£Ëü°üÀ¨Ò»¸öshellcode£¬¸ÃshellcodeÈÏÕæÏÂÔØ¼ÓÃܵÄÓÐÓøºÔز¢½«Æä×¢Èëµ½Ô¶³ÌÀú³ÌÖС£RATicateÊÇÒ»¸öÒÔÇÔÊØÐÅϢΪĿµÄµÄÍþв×éÖ¯£¬Ö÷ÒªÕë¶ÔÅ·ÖÞ¡¢Öж«ºÍÑÇÖÞµØÇø¡£
¡¾²Î¿¼Á´½Ó¡¿
https://news.sophos.com/en-us/2020/07/14/raticate-rats-as-service-with-commercial-crypter/
9. °ÍÎ÷ÒøÐÐľÂíÀ©Õ¹µ½È«Çò
¡¾¸ÅÊö¡¿
Õë¶Ô°ÍÎ÷µÄËÄ´óÒøÐÐľÂí¼Ò×å°üÀ¨Guildma¡¢Javali¡¢MelcozºÍGrandoreiro£¬½üÆÚËüÃǵÄÄ¿µÄÓû§²»µ«ÊǰÍÎ÷£¬²¢ÇÒÀ©Õ¹µ½À¶¡ÃÀÖÞºÍÅ·ÖÞ¾ÙÐй¥»÷Ô˶¯£¬ÕâÐ©ÒøÐÐľÂí¼Ò×åͨ¹ýʹÓÃDGA¡¢¼ÓÃÜÓÐÓÃÔØºÉ¡¢Àú³Ì¿Õ»¯¡¢Ð®ÖÆDLL¡¢´ó×ÚµÄLoLBins¡¢ÎÞÎļþѬȾºÍÆäËû¼¼ÇÉÌӱܯÊÎöºÍ¼ì²â¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securelist.com/the-tetrade-brazilian-banking-malware/97779/
10. DarkshadesľÂíѬȾAndroid×°±¸
¡¾¸ÅÊö¡¿
DarkshadesÊÇÒ»ÖÖÒÔAndroid×°±¸ÎªÄ¿µÄµÄÔ¶³Ì»á¼ûľÂí¡£Ëü¾ßÓÐÇÔÈ¡ÁªÏµ·½·¨¡¢×¼È·¸ú×ÙλÖá¢ÇÔȡʵʱ¶ÌÐÅ/²ÊÐÅ¡¢»ñÈ¡¿¨Ö¤Êé¡¢²¶»ñ½ØÍ¼¡¢¼ÓÃÜÎļþºÍÌᳫDDOS¹¥»÷µÄ¹¦Ð§¡£DarkshadesľÂí¾ßÓÐÁ½ÖÖ±äÖÖ£¬Çø±ðÔÚÓÚÓÐÎÞ¿¨Æ¾Ö¤×¥È¡¹¦Ð§¡£
¡¾²Î¿¼Á´½Ó¡¿
https://insights.oem.avira.com/in-depth-analysis-of-darkshades-a-rat-infecting-android-devices/
11. SLoad¶ñÒâÈí¼þͨ¹ýÀ¬»øÓʼþÈö²¥
¡¾¸ÅÊö¡¿
½üÆÚ¹¥»÷ÕßÌᳫеĴó¹æÄ£À¬»øÓʼþÔ˶¯Ö¼ÔÚÈö²¥SLoad¶ñÒâÈí¼þ£¬À¬»øÓʼþͨ¹ýÊÜѬȾµÄPECת´ï£¬ÒÔÐéÄⷢƱµÄÐÂÎÅ×÷ΪÓÕ¶ü£¬¸Ã·¢Æ±°üÀ¨¸½¼ÓµÄ¶ñÒâZIP´æµµ£¬ÆäÖаüÀ¨VBSÎļþºÍXML¡£
¡¾²Î¿¼Á´½Ó¡¿
https://cert-agid.gov.it/news/campagna-sload-v-2-9-3-veicolata-via-pec/
12. ÐÂÐÍÒøÐÐľÂíBlackRockµÄ¹¥»÷Ô˶¯
¡¾¸ÅÊö¡¿
½üÆÚÔÚ¹¥»÷Ô˶¯Öз¢Ã÷LokiBotÒøÐÐľÂíµÄбäÖÖBlackRock£¬Æä¹¥»÷Ä¿µÄ°üÀ¨´ó×ÚÉç½»¡¢ÍøÂ硢ͨѶºÍÔ¼»áÓ¦ÓóÌÐò£¬Í¬Ê±¸ÃľÂí¾ßÓÐÁýÕÖ¹¥»÷£¬·¢ËÍÀ¬»øÓʼþºÍÇÔÈ¡SMSÐÂÎÅ¡¢ÆÁÄ»Ëø¶¨¡¢ÇÔÈ¡ºÍÒþ²ØÍ¨Öª¡¢Òþ²ØÓ¦ÓóÌÐòͼ±êºÍ±ÜÃâ±»ÒÆ³ýµÈ¹¦Ð§¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.threatfabric.com/blogs/blackrock_the_trojan_that_wanted_to_get_them_all.html

AG¹«Ë¾ÔÆ







