AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2020.11.02-2020.11.08£©
2020-11-09
Ò»¡¢ Íþвͨ¸æ
Weblogic ¶à¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-14825¡¢CVE-2020-14841¡¢CVE-2020-14859……£©
¡¾Ðû²¼Ê±¼ä¡¿2020-11-02 20:00:00 GMT
¡¾¸ÅÊö¡¿
10 ÔÂ21 ÈÕ£¬AG¹«Ë¾¿Æ¼¼¼à²âµ½Oracle ¹Ù·½Ðû²¼2020 Äê10 ÔÂÒªº¦²¹¶¡¸üУ¨Critical Patch Update£©£¬ÐÞ¸´ÁË402 ¸öΣº¦Ë®Æ½²î±ðµÄÇå¾²Îó²î¡£ÆäÖаüÀ¨5 ¸öWebLogic µÄÑÏÖØÎó²î£¨CVE-2020-14825¡¢CVE-2020-14841¡¢CVE-2020-14859¡¢CVE-2020-14882¡¢CVE-2019-17267£©£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿Éͨ¹ý´Ë´ÎµÄÎó²îʵÏÖÔ¶³Ì´úÂëÖ´ÐС£CVSS ÆÀ·Ö¾ùΪ9.8£¬Ê¹ÓÃÖØÆ¯ºóµÍ¡£½¨ÒéÓû§¾¡¿ì½ÓÄɲ½·¥£¬¶ÔÉÏÊöÎó²î¾ÙÐзÀ»¤¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
VMware ESXi Ô¶³Ì´úÂëÖ´ÐÐÎó²îͨ¸æ£¨CVE-2020-3992£©
¡¾Ðû²¼Ê±¼ä¡¿2020-11-02 20:00:00 GMT
¡¾¸ÅÊö¡¿
10 ÔÂ21 ÈÕ£¬AG¹«Ë¾¿Æ¼¼¼à²âµ½VMware ¹Ù·½Ðû²¼Ç徲ͨ¸æÐÞ¸´ÁËÒ»¸öVMware ESXi Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-3992£©¡£Îó²îȪԴÓÚESXi ÖÐʹÓõÄOpenSLP ±£´æ“use-after-free”ÊͷźóÖØÊ¹ÓÃÎÊÌ⣬µ±¹¥»÷ÕßÔÚÖÎÀíÍøÂ磨management network£©ÖÐʱ£¬¿ÉÒÔͨ¹ý»á¼ûESXi ËÞÖ÷»úµÄ427 ¶Ë¿Ú´¥·¢OpenSLP ·þÎñµÄuser-after-free£¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£CVSS ÆÀ·ÖΪ9.8£¬ÇëÏà¹ØÓû§½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
Windows Kernel cng.sysȨÏÞÌáÉý0-dayÎó²îͨ¸æ£¨CVE-2020-17087£©
¡¾Ðû²¼Ê±¼ä¡¿2020-11-02 20:00:00 GMT
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬Google Project ZeroÍŶÓÐû²¼ÁËһƪ¹ØÓÚWindowscng.sysÌáȨÎó²î£¨CVE-2020-17087£©µÄÎÄÕ¡£¸ÃÎó²îÔÊÐí¹¥»÷ÕßÔÚδÊÚȨµÄÇéÐÎÏ£¬Í¨¹ýÓÕʹÓû§ÔËÐÐÈ«ÐÄÖÆ×÷µÄ¶ñÒâ³ÌÐò£¬´Ó¶øµÖ´ïȨÏÞÌáÉýµÄЧ¹û¡£ÏÖÔÚ¸ÃÎó²îÒѾÓÐÔÚҰʹÓõÄÐÐΪ·ºÆð£¬²¢ÇÒ΢Èí¹Ù·½ÔÝʱûÓÐÐû²¼Ïà¹Ø²¹¶¡¾ÙÐÐÐÞ¸´¡£½¨ÒéÓû§¼á³Ö¹Ø×¢£¬Í¬Ê±×èÖ¹ÔËÐÐȪԴ²»Ã÷µÄ³ÌÐò¡£²Î¿¼Á´½Ó£ºhttps://bugs.chromium.org/p/project-zero/issues/detail?id=2104
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
SaltStack¶à¸öÇå¾²Îó²îÇ徲ͨ¸æ£¨CVE-2020-16846¡¢CVE-2020-17490¡¢CVE-2020-25592£©
¡¾Ðû²¼Ê±¼ä¡¿2020-11-04 22:00:00 GMT
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬SaltStack¹Ù·½Ðû²¼Ç徲ͨ¸æ³ÆÐÞ¸´Á˶à¸öÇå¾²Îó²î£¬CVE-2020-16846,CVE-2020-17490,CVE-2020-25592¡£ÕâЩÎó²î¿ÉÔì³ÉÈÏÖ¤ÈÆ¹ýºÍÏÂÁîÖ´ÐУ¬SaltStack½¨ÒéÓû§¾¡¿ìÉý¼¶¾ÙÐзÀ»¤¡£SaltÊÇÓÃPython±àдµÄ¿ªÔ´IT»ù´¡¼Ü¹¹ÖÎÃ÷È·¾ö¼Æ»®£¬Òѱ»È«ÌìϵÄÊý¾ÝÖÐÐÄÆÕ±éʹÓá£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. Ñ¡¾ÙºóµÄÈÕ×Ó£ºÃÀ¹úСÐĺڿ͹¥»÷£¬¹ýʧÐÅÏ¢
¡¾¸ÅÊö¡¿
ÔÚ½¹ÂÇÒ»Á¬ÁËÊýÖÜÖ®ºó£¬´óÑ¡ÈÕÔÚÃÀ¹ú¾ÙÐУ¬Ã»ÓйûÕæ¼£ÏóÅú×¢ÓÐÈ˸ÉÔ¤¡£¿ÉÊÇר¼Ò˵£¬¹ýʧµÄÐÅÏ¢Ô˶¯ÈÔÈ»¿ÉÄܱ¬·¢£¬²¢ÇÒËæ×Å¼ÆÆ±µÄ¾ÙÐУ¬Óдó×ÚµÄʱ¼ä¾ÙÐжñÒâÔ˶¯¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.inforisktoday.com/post-election-day-us-on-guard-for-hacking-misinformation-a-15300
2. ÃÀ¹úÐû²¼¶íÂÞ˹ºÚ¿ÍÓÃÓÚ¹¥»÷Òé»á¡¢´óʹ¹ÝµÄ¶ñÒâÈí¼þÐÅÏ¢
¡¾¸ÅÊö¡¿
ÍâµØÊ±¼ä29ÈÕ£¬ÃÀ¹úÍøÂç˾Á·ÖÏíÁ˶íÂÞ˹ºÚ¿Í×éÖ¯ÔÚÕë¶ÔÍâ½»²¿£¬¹úÃñÒé»áºÍʹ¹Ý¶à¸ö²¿·ÖµÄ¹¥»÷ÖÐʹÓõĶñÒâÈí¼þÐÅÏ¢¡£¸Ã¶ñÒâÈí¼þÑù±¾ÓÉÃÀ¹úÍøÂç˾ÁµÄÍøÂç¹ú¼ÒʹÃü²½¶Ó£¨CNMF£©ÒÔ¼°ÍøÂçÇå¾²ºÍ»ù´¡ÉèÊ©Çå¾²¾Ö£¨CISA£©Ê¶±ð£¬²¢ÓÚ×òÈÕÉÏ´«ÖÁVirus TotalÔÚÏß²¡¶¾É¨ÃèÆ½Ì¨¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.freebuf.com/articles/253572.html
3. ·ÒÀ¼µÄÊê½ðºÚ¿ÍÕýÔÚʹרÐÄÀíÖÎÁƲ¡Àú×÷Ϊµ¯Ò©
¡¾¸ÅÊö¡¿
“³ý·ÇÄúÔÚ48СʱÄÚÏòÎÒÖ§¸¶ÁË500Å·ÔªµÄ¼ÓÃÜÇ®±Ò£¬²»È»ÄúµÄÐÄÀíÖÎÁÆ»¼Õ߼ͼ½«±»Ðû²¼”¡£ÔÚÒÑÍùÁ½ÖÜÄÚ£¬Ö»Óв»µ½1£¥µÄ·ÒÀ¼Éú³ÝÊÕµ½ÁËÕâÒ»ÐèÇó¡£¶à¸öDZÔÚÎ޹صÄÈËÒѾ½øÈë“ Vastaamo”ÐÄÀíÖÎÁÆÖÐÐÄ£¬¸ÃÖÐÐÄÖ÷ÒªÔڰ¬ºÍ̹ÅåÀ×ÖÎÁÆÁËÔ¼40.000Ãû»¼Õß¡£ºÚ¿ÍʹÓÃÁË2018ÄêºÍ2019ÄêÍ·µÄÇå¾²Îó²î£¬ËƺõÉÐδÏòÕþ¸®»ò¹«ÖÚÆÕ±é±¨µÀ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.forbes.com/sites/michalgromek/2020/10/31/ransom-hackers-in-finland-are-using-psychotherapy-medical-records-as-ammunition/
4. Code42 IncydrϵÁУºÎªÊ²Ã´´ó´ó¶¼¹«Ë¾ÎÞ·¨×èֹȥְԱ¹¤Êý¾Ý͵ÇÔ
¡¾¸ÅÊö¡¿
ƾ֤Code42µÄÊý¾Ý̻¶±¨¸æ£¬ÓÐ63£¥µÄÔ±¹¤ÌåÏÖËûÃǽ«Êý¾Ý´ÓÒÔǰµÄ¹ÍÖ÷´øµ½ÁËÄ¿½ñµÄ¹ÍÖ÷¡£ÕâÊÇÄÚ²¿ÈËΣº¦µÄ×îÏÔ×ŵļ£Ïó£ºÔ±¹¤µÄ¸æÍËÐÅ¡£Æ¾Ö¤¡¶ÐÅÏ¢Çå¾²ÔÓÖ¾¡·£¨Infosecurity Magazine£©µÄÒ»Ïî2019ÄêÑо¿·¢Ã÷£¬ÓÐ72£¥µÄÔ±¹¤ÔÚȥְʱ»áʹÓù«Ë¾Êý¾Ý¡£
¡¾²Î¿¼Á´½Ó¡¿
https://threatpost.com/code42-incydr-series-why-most-companies-cant-stop-departing-employee-data-theft/160879/
5. еÄAPTʹÓÃDLL²àÔØµ½“ KilllSomeOne”
¡¾¸ÅÊö¡¿
×î½ü£¬ÎÒÃÇÊӲ쵽Á˼¸ÖÖÇéÐΣ¬ÆäÖÐDLL²à¼ÓÔØÓÃÓÚÖ´ÐжñÒâ´úÂë¡£ÅÔ¼ÓÔØÊÇʹÓöñÒâDLLÓÕÆÕýµ±µÄDLL£¬ÒÀÀµÕýµ±µÄWindows¿ÉÖ´ÐÐÎļþ¼ÓÔØºÍÖ´ÐжñÒâ´úÂë¡£
¡¾²Î¿¼Á´½Ó¡¿
https://news.sophos.com/en-us/2020/11/04/a-new-apt-uses-dll-side-loads-to-killlsomeone/
6. ʹÓÃÃÀ¹ú´óÑ¡²»È·¶¨ÐÔͨ¹ýmalspamÔ˶¯½»¸¶µÄQBotÌØÂåÒÁľÂí³ÌÐò
¡¾¸ÅÊö¡¿
2020ÄêÃÀ¹ú´óÑ¡ÊÇÔÚÈ«Çò´óÊ¢ÐÐÖоÙÐеÄͬʱ£¬Êܵ½ÑÏ¿áÉó²éºÍÇéÐ÷¹Ø×¢µÄÖ÷Ìâ¡£Ëæ×ÅÑ¡¾ÙÖ®Ò¹µÄ¿¢ÊÂÒÔ¼°¶ÔЧ¹ûµÄ²»È·¶¨ÐÔ×îÏÈÉìÕÅ£¬ÍþвÐж¯ÕßÒ²¾öÒé¼ÓÈë½øÀ´¡£ÄÇЩ׷×ÙÍþÐ²Ì¬ÊÆµÄÈ˶¼ºÜÊÇÇåÎú£¬ÖØ´óÌìÏÂÊÂÎñ²¢Ã»Óб»·¸·¨·Ö×ÓËùºöÊÓ¡£ÔÚÕâÖÖÇéÐÎÏ£¬ÎÒÃÇ×îÏÈÊӲ쵽һ¸öеÄÀ¬»øÓʼþÔ˶¯£¬¸ÃÔ˶¯×ª´ïÁ˶ñÒ⸽¼þ£¬ÕâЩ¸½¼þʹÓÃÁ˶ÔÑ¡¾ÙÀú³ÌµÄÏÓÒÉ¡£QBotÒøÐÐľÂíÔËÓªÉÌʹÓÃÏàͬµÄÐ®ÖÆµç×ÓÓʼþÏß³ÌÊÖÒÕ£¬ÔÙ´ÎÒý·¢ÁËÖ÷ÌâΪÀ¬»øÓʼþµÄÀ˳±£¬ÓÕʹÊܺ¦ÕßÊܵ½¶ñÒâÑ¡¾Ù×ÌÈŸ½¼þµÄ¹¥»÷¡£
¡¾²Î¿¼Á´½Ó¡¿
https://blog.malwarebytes.com/cybercrime/2020/11/qbot-delivered-via-malspam-campaign-exploiting-us-election-uncertainties/
7. ¶íÂÞË¹ÍøÂç·¸·¨·Ö×ÓAleksandr Brovko±»ÅÐÈëÓü8Äê
¡¾¸ÅÊö¡¿
¶íÂÞË¹ÍøÂç·¸·¨·Ö×ÓÑÇÀúɽ´ó·²¼ÂÞ·ò¿Æ£¨Aleksandr Brovko£©ÒòÆäÔÚ½©Ê¬ÍøÂçÍýÏëÖеÄ×÷Óöø±»ÅÐÈëÓü°ËÄ꣬¸ÃÍýÏëÔì³ÉÖÁÉÙ1ÒÚÃÀÔªµÄ¾¼ÃËðʧ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securityaffairs.co/wordpress/110358/cyber-crime/aleksandr-brovko-sentenced-jail.html
8. ÃÀ¹ú´óÑ¡Èç»ðÈçݱ£¬ÍøÂçÇå¾²Õ½¾Ö¼´½«ÖØËÜ£¿
¡¾¸ÅÊö¡¿
ÌØÀÊÆÕÕþ¸®µÄ¹ú¼ÒÍøÂçÕ½ÂÔºôÓõʹÓþ¼ÃµÄʵÁ¦Íƶ¯Õû¸öÐÐÒµµÄÍøÂçÇå¾²¸ÄÉÆ£¬²¢ÔÚÐÂÐËÁìÓòÖÆ¶©ºÍʵÑé±ê×¼£¬ºÃ±È¿¹Á¿×Ó¹«Ô¿ÃÜÂëÊõ¡£°ÝµÇ˵£¬ÍøÂçÍþв¶ÔÃÀ¹úµÄ¹ú¼ÒÇå¾²¡¢Ñ¡¾ÙÇåÁ®ºÍ¹ú¼ÒÃñÖ÷µÄ¿µ½¡×é³ÉÔ½À´Ô½´óµÄÌôÕ½¡£Óë´Ëͬʱ£¬ËûÒÔΪÕþ¸®Ó¦¸ÃÏò¿Æ¼¼¹«Ë¾Ê©Ñ¹£¬Ë¢ÐÂËûÃÇÔÚÒþ˽¡¢¼àÊÓºÍÄÕºÞÑÔÂÛ·½ÃæµÄ×ö·¨¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.freebuf.com/articles/neopoints/254098.html

AG¹«Ë¾ÔÆ







