AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2020.11.09-2020.11.15£©
2020-11-17
Ò»¡¢ Íþвͨ¸æ
Windows ÍøÂçÎļþϵͳÎó²îͨ¸æ£¨CVE-2020-17051¡¢CVE-2020-17056£©
¡¾Ðû²¼Ê±¼ä¡¿2020-11-11 22:00:00 GMT
¡¾¸ÅÊö¡¿
ÍâµØÊ±¼ä11ÔÂ10ÈÕ£¬Î¢Èí×îеÄÔ¶Ȳ¹¶¡¸üÐÂÖÐÐÞ¸´ÁËÁ½Ã¶±£´æÓÚWindows ÍøÂçÎļþϵͳ£¨Network File System£¬NFS£©ÖеÄÎó²î£¬»®·ÖÊÇ CVE-2020-17051ºÍ CVE-2020-17056¡£CVE-2020-17051 ÊDZ£´æÓÚnfssvr.sysÇý¶¯ÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬¾Ý³Æ¸´ÏÖʱ¿Éµ¼ÖÂÀ¶ÆÁËÀ»ú£¨BSOD£©[3]¡£CVE-2020-17056ÊÇÒ»¸ö±£´æÓÚnfssvr.sysÇý¶¯ÖеÄÔ¶³ÌÔ½½ç¶ÁÈ¡Îó²î£¬¿Éµ¼ÖÂASLR£¨µØµã¿Õ¼ä½á¹¹Ëæ»ú»¯£©±»Èƹý¡£µ±ÕâÁ½¸öÎó²î±»×éºÏʹÓÃʱ£¬¹¥»÷ÕßÔÚWindows·þÎñÆ÷ÉÏÈÆ¹ýÎó²î»º½â²½·¥²¢ÊµÏÖÔ¶³ÌʹÓõĿÉÄÜÐÔ½«´ó´óÔöÌí¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. ǰ΢Èí¹¤³Ìʦ±»ÅÐ9Äêî¿Ïµ
¡¾¸ÅÊö¡¿
¾Ý˾·¨²¿³Æ£¬ÔÚ½ñÄêÔçЩʱ¼äÒòÉæÏÓ18ÏîÐÌÊÂÖ¸¿Ø¶ø±»ÅÐÓÐ×ïºó£¬Ò»Ãûǰ΢ÈíÈí¼þ¹¤³Ìʦ±»Åд¦ÓÐÆÚͽÐÌ9Äê¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.inforisktoday.com/former-microsoft-engineer-sentenced-to-9-years-in-prison-a-15340
2. ºÚ¿Í¿ÉÒÔͨ¹ýÊÓ²ìÄãµÄ¼ç°òÒÆ¶¯À´»ñÈ¡ÃÜÂë
¡¾¸ÅÊö¡¿
Çå¾²Ñо¿Ö°Ô±ÓÀÔ¶Ïë³öеÄÒªÁ죬²¢ÇÒ¾³£ÓÃÁîÈ˾ªÑȵķ½·¨À´ÈëÇÖÄúµÄÊý¾ÝºÍϵͳ¡£ÎÒ×î½ü±¨µÀ˵£¬ÕâÑùµÄÑо¿Ö°Ô±ÔõÑùͨ¹ý½«ÅþÁ¬µ½ÍûÔ¶¾µµÄµç¹â´«¸ÐÆ÷Ãé×¼µÆµ¨À´¼àÊÓԼĪ80Ó¢³ß£¨25Ã×£©Ô¶µÄ¶Ô»°¡£ÈôÊÇÄúÒÔΪÕâÊÇ·ÇͬѰ³£µÄ£¬Çë×öºÃ×¼±¸£ºÑо¿Ö°Ô±ÒÔΪËûÃÇ¿ÉÒÔͨ¹ýÔÚZoomͨ»°Ê±´úÊÓ²ìÄúµÄÉϱÛÐж¯À´»ñÈ¡ÄúµÄÃÜÂë¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.forbes.com/sites/daveywinder/2020/11/07/surprising-new-zoom-hacking-threat-revealed-what-users-need-to-know/
3. ¹È¸è¿ª·¢ÁËÒ»¸öÓ¦ÓóÌÐò£¬ÈôÊÇÓû§ÍÏÇ·¸¶¿î£¬¿ÉÒÔËø¶¨×°±¸
¡¾¸ÅÊö¡¿
ÒøÐкÍÐÅ´û·Å´û»ú¹¹Ò»Ö±ÒÔÀ´¶¼ÓÐÏ൱һ²¿·Ö²»Á¼µÄ¹«¹²ÁýÕÖ£¬ÕâÒª¹é¹¦ÓÚÈôÊÇÈËÃÇÍÏÇ·´û¿î»á±¬·¢Ê²Ã´¡£Google²»»áͨ¹ýÆä×îеÄÓ¦ÓóÌÐòÀ´×·Çó×ÊÖú£¬¸ÃÓ¦ÓóÌÐòÖ¼ÔÚËø¶¨ÄÇЩÎÞ·¨Ê¹ÓÃÖÇÄÜÊÖ»úÈÚ×ʸ¶¿îµÄÓû§µÄ×°±¸¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.hackread.com/google-app-lock-devices-users-default-payment/
4. ÀÕË÷Èí¼þ¼¯ÍÅתÏòFacebook¹ã¸æ
¡¾¸ÅÊö¡¿
ÕâÒѾºÜÔã¸âÁË£¬Ðí¶àÀÕË÷Èí¼þ°ïÅÉÏÖÔÚÓµÓв©¿Í£¬ËûÃÇÔÚÆäÖÐÐû²¼´Ó¾Ü¾øÀÕË÷¿î×ӵĹ«Ë¾ÄÇÀïÇÔÈ¡µÄÊý¾Ý¡£ÏÖÔÚ£¬Ò»¸ö·¸·¨¼¯ÍÅÒÑ×îÏÈʹÓñ»ºÚ¿ÍÈëÇÖµÄFacebookÕÊ»§¹ûÕæÔËÐÐ¹ã¸æ£¬ÆÈʹÆäÀÕË÷Èí¼þÊܺ¦Õ߸¶¿î¡£
¡¾²Î¿¼Á´½Ó¡¿
https://krebsonsecurity.com/2020/11/ransomware-group-turns-to-facebook-ads/
5. ÖйúºÚ¿Í¼¯ÍÅʹÓÃÐÂÏÊDLL¾ÙÐвàÔØ¹¥»÷
¡¾¸ÅÊö¡¿
Çå¾²¹«Ë¾SophosµÄÒ»·Ý±¨¸æÖ¸³ö£¬×î½ü·¢Ã÷µÄÒ»ÆäÖйúºÚ¿Í×éÖ¯ÕýÔÚʹÓöàÖÖ¶¯Ì¬Á´½Ó¿â¹¥»÷ÊÖÒÕÀ´Õë¶Ô¶«ÄÏÑǵķÇÕþ¸®×éÖ¯£¬ÓÈÆäÊÇÃåµé¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.inforisktoday.com/chinese-hacking-group-using-fresh-dll-side-loading-attack-a-15320
6. ÃÀ¹ú˾·¨²¿¿ÛѺÁË10ÒÚÃÀÔªÓëË¿³ñ֮·Êг¡Ïà¹ØµÄ±ÈÌØ±Ò
¡¾¸ÅÊö¡¿
ÃÀ¹ú˾·¨²¿£¨DoJ£©Ðû²¼Ã»ÊÕÁË10ÒÚÃÀÔªµÄ±ÈÌØ±ÒºÍÆäËû¼ÓÃÜÇ®±Ò¡£ÃÀ¹ú˾·¨²¿Éù³Æ£¬ÕâЩ×ʽðÓëÏÖÔÚÔËת²»Á¼µÄ°µÍøÊг¡Ë¿³ñ֮·Óйء£
¡¾²Î¿¼Á´½Ó¡¿
https://www.hackread.com/1-billion-silk-road-marketplace-bitcoin-seized/
7. °ÝµÇµÄÍøÂçÇ徲ʹÃü£ºÖØÕñÊÆÍ·
¡¾¸ÅÊö¡¿
ÍøÂçÇå¾²ÓÐÍû³ÉΪ½Ï¸ß°×¹¬ÓÅÏȼ¶Ê±ÈÎ×ÜͳÖÐÑ¡È˰ݵÇÉÏÈΡ£Ô¤¼ÆËû½«Óë¹¥»÷ÍøÂç¹¥»÷ÐøÔ¼ËùÐèµÄÒªº¦¹ú¼Ê¹ØÏµ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.inforisktoday.com/blogs/bidens-cybersecurity-mission-regain-momentum-p-2966
8. Game Over£¿Capcom±»ÀÕË÷1100ÍòÃÀÔª
¡¾¸ÅÊö¡¿
ÀÏÅÆÊÓÆµÓÎÏ·¿¯ÐÐÉÌCapcom½¨ÉèÓÚ1979Ä꣬ÊÇÌìÏÂÉÏÉúÑÄ×îÓÆ¾ÃµÄÊÓÆµÓÎÏ·ÖÆÔìÉÌÖ®Ò»¡£CapcomÔÚÃÀ¹ú£¬Å·Ö޺Ͷ«ÑǶ¼ÓÐÓªÒµ£¬×îÖøÃûµÄÓÎÏ·°üÀ¨¡¶Éú»¯Î£»ú¡·¡¢¡¶Ä°Í·°ÔÍõ¡·¡¢¡¶¹íÆü¡·¡¢¡¶¹ÖÎïÁÔÈË¡·¡¢¡¶ÍõÅÆ×´Ê¦¡·ºÍ¡¶Âå¿ËÈË¡·¡£ÔÚ11ÔÂ4ÈÕµÄÒ»·ÝÐÂΟåÖÐCapcom͸¶ÔâÓöÀÕË÷Èí¼þ¹¥»÷£¬±»ÆÈ×èÖ¹Á˲¿·ÖÔËÓª£¬¸ÃÊÂÎñÓ°ÏìÁËÆäµç×ÓÓʼþºÍÎļþ·þÎñÆ÷ÒÔ¼°ÆäËûϵͳ¡£CapcomÉù³ÆÃ»Óз¢Ã÷Ö¤¾ÝÅú×¢¿Í»§ÐÅÏ¢Êܵ½ÁËË𺦡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.aqniu.com/threat-alert/71121.html
9. ÌØÀÊÆÕµÄ¾ºÑ¡ËßËÏÖ¤¾ÝÍøÂçÍøÕ¾±¬·¢Êý¾Ýй¶
¡¾¸ÅÊö¡¿
ÌØÀÊÆÕ¾ºÑ¡ÍŶӏՏկô¶¯µÄDontTouchTheGreenButton.comÍøÕ¾±¬·¢ÁËÑ¡ÃñÊý¾Ýй¶ÊÂÎñ¡£Ôâй¶µÄÊý¾Ý°üÀ¨Ñ¡ÃñÐÕÃû£¬µØµãºÍΨһ±êʶ·û¡£Óб¨µÀ³Æ¸ÃÍøÕ¾±£´æSQL×¢ÈëÎó²î£¬ÒÔÊǺڿͿÉÒÔÍøÂçÑ¡ÃñµÄSSNºÍ³öÉúÈÕÆÚ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.freebuf.com/news/254290.html
10. Microsoft StoreÓÎÏ·ÌáȨÎó²îÆÊÎö£¨CVE-2020-16877£©
¡¾¸ÅÊö¡¿
±¾ÎÄÐÎòÁËWindowsÌØÈ¨ÌáÉýÎó²î£¨CVE-2020-16877£©£¬ÎÒÔÚ6ÔÂÏò΢Èí±¨¸æÁËÕâÒ»ÎÊÌ⣬¸ÃÎÊÌâÔÚ10Ô¾ÙÐÐÁËÐÞ¸´¡£Í¨¹ýÕâÒ»Îó²î£¬¹¥»÷Õß¿ÉÒÔÖ±½ÓʹÓÃWindows´¦Öóͷ£Microsoft StoreÓÎÏ·Àú³ÌÖеÄȱÏÝʵÏÖ¹¥»÷£¬×îÖÕÔÚWindows 10ϵͳÉÏ´ÓͨË×Óû§ÌáÉýµ½Local SystemȨÏÞ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.anquanke.com/post/id/221818
11. Õë¶ÔLinuxµÄÀÕË÷Èí¼þľÂíÏÖÉí£¬ÊôÓÚRansomEXX±äÖÖ
¡¾¸ÅÊö¡¿
¿ËÈÕ¿¨°Í˹»ù£¨Kaspersky£©·¢Ã÷ijÒÑÖªÀÕË÷Èí¼þ°ïÅɰ²ÅÅÁËÒ»ÖÖÕë¶ÔLinuxµÄÎļþ¼ÓÃÜľÂí¡£¿¨°Í˹»ùÇå¾²Ñо¿Ô±Ö¸³ö£º“ÕâÊÇÒ»¸öȫеÄÎļþ¼ÓÃÜľÂí£¬ÊôÓÚELF¿ÉÖ´ÐÐÎļþ£¬Äܹ»¶ÔLinuxµçÄÔÉϵÄÊý¾Ý¾ÙÐмÓÃÜ¡£¸ÃľÂíÀàËÆÓÚÏÖÓеÄRansomEXXľÂí£¬ºóÕßÔÚÉÏÖܸոձ»ÓÃÓÚ¹¥»÷°ÍÎ÷·¨ÔºÒÔ¼°ÃÀ¹úºÍÆäËûµØÇøµÄÄ¿µÄ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.aqniu.com/threat-alert/71148.html
12. CVE-2020-14882£ºWeblogic Console ȨÏÞÈÆ¹ýÉîÈëÆÊÎö
¡¾¸ÅÊö¡¿
2020Äê10ÔÂ29ÈÕ£¬360CERT¼à²â·¢Ã÷ Weblogic ConSole HTTP ÐÒé´úÂëÖ´ÐÐÎó²î Ïà¹Ø POCÒѾ¹ûÕæ£¬Ïà¹ØÎó²î±àºÅΪ CVE-2020-14882,CVE-2020-14883 £¬Îó²îÆ·¼¶£ºÑÏÖØ£¬Îó²îÆÀ·Ö£º9.8¡£Ô¶³Ì¹¥»÷Õß¿ÉÒÔ½á¹¹ÌØÊâµÄHTTPÇëÇó£¬ÔÚδ¾Éí·ÝÑéÖ¤µÄÇéÐÎϽÓÊÜ WebLogic Server Console £¬²¢Ö´ÐÐí§Òâ´úÂë¡£¶Ô´Ë£¬360CERT½¨Òé¿í´óÓû§ÊµÊ±½« Weblogic Éý¼¶µ½×îа汾¡£Óë´Ëͬʱ£¬Çë×öºÃ×ʲú×Ô²éÒÔ¼°Ô¤·ÀÊÂÇ飬ÒÔÃâÔâÊܺڿ͹¥»÷¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.anquanke.com/post/id/221752

AG¹«Ë¾ÔÆ







