AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2020.12.07-2020.12.13£©
2020-12-14
Ò»¡¢ Íþвͨ¸æ
Apache Struts Ô¶³Ì´úÂëÖ´ÐÐÎó²î S2-061ͨ¸æ£¨CVE-2020-17530£©
¡¾Ðû²¼Ê±¼ä¡¿2020-12-09 14:00:00 GMT
¡¾¸ÅÊö¡¿
2020 Äê12 ÔÂ8 ÈÕ£¬Struts ¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬Åû¶ÁËÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²îS2-061£¨CVE-2020-17530£©¡£¸ÃÎó²îÓëS2-059 ÀàËÆ£¬ÎÊÌâÔ´ÓÚµ±¿ª·¢Ö°Ô±Ê¹ÓÃÁË%{…} Óï·¨¾ÙÐÐÇ¿ÖÆOGNL ÆÊÎöʱ£¬Ä³Ð©ÌØÊâµÄTAG ÊôÐÔ¿ÉÄܻᱻ¶þ´ÎÆÊÎö£»¹¥»÷Õ߿ɽṹ¶ñÒâµÄOGNL ±í´ïʽ´¥·¢Îó²î£¬Ôì³ÉÔ¶³Ì´úÂëÖ´ÐС£ Apache Struts ÊÇÓÃÓÚ½¨ÉèJava Web Ó¦ÓóÌÐòµÄ¿ªÔ´µÄ¿ò¼Ü£¬Ó¦ÓúÜÊÇÆÕ±é¡£¸ÃÎó²îÒÑÔÚ2020 Äê12 ÔÂ6 ÈÕÐû²¼µÄStruts 2.5.26 °æ±¾ÖÐÐÞ¸´£¬½¨ÒéÏà¹ØÓû§¾¡¿ìÉý¼¶°æ±¾¾ÙÐзÀ»¤¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
FireEye ÔâÊÜAPT¹¥»÷£¬FireEye ºì¶Ó¹¤¾ßÏä±»µÁ£¨CVE-2014-1812¡¢CVE-2016-0167¡¢CVE-2017-11774£©
¡¾Ðû²¼Ê±¼ä¡¿2020-12-11 15:00:00 GMT
¡¾¸ÅÊö¡¿
ÍâµØÊ±¼ä12 ÔÂ8 ÈÕ£¬Çå¾²¹«Ë¾FireEye Ðû²¼²©¿ÍÌåÏÖ£¬Ä³¸öÓɹú¼ÒÔÞÖúµÄAPT ×é֯͵ȡÁËFireEye µÄºì¶Ó¹¤¾ßÏä¡£ÓÉÓÚÔÝʱÎÞ·¨È·¶¨¹¥»÷Õß»á×Ô¼ºÊ¹Óã¬ÕվɹûÕæÅû¶¹¤¾ßÏ䣬Ϊ°ü¹Ü¸÷Çå¾²ÉçÇøÄÜÌáǰ½ÓÄÉÓ¦¶Ô²½·¥£¬FireEye ¹ûÕæÁ˱»µÁ¹¤¾ßµÄ¼ì²â¹æÔò£¬ÒÔ½µµÍ¶ñÒâÓû§ÀÄÓúì¶Ó¹¤¾ßÏäµÄÍþв¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. ÒÔºì¶ÓÊӽǿ´FireEyeÎäÆ÷×ß©ÊÂÎñ
¡¾¸ÅÊö¡¿
12ÔÂ8ÈÕ£¬ÃÀ¹ú¶¥¼¶Çå¾²¹«Ë¾FireEye£¨ÖÐÎÄÃû£º»ðÑÛ£©Ðû²¼Ò»Ôòͨ¸æ³ÆÆäÄÚ²¿ÍøÂ类ij¸ö“ÓµÓÐÒ»Á÷ÍøÂç¹¥»÷ÄÜÁ¦µÄ¹ú¼Ò”ËùÍ»ÆÆ¡£ÏÖÔÚ£¬FireEyeÕýÔÚÓëÁª°îÊÓ²ì¾ÖºÍ°üÀ¨MicrosoftÔÚÄ򵀮äËûÖ÷ÒªÏàÖúͬ°é¾ÙÐÐÆð¾¢µÄÊÓ²ìÏàÖú¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.freebuf.com/news/257194.html
2. COVID-19ÒßÃç·¸·¨ÍÅ»ï
¡¾¸ÅÊö¡¿
Ëæ×Å·Ö·¢COVID-19ÒßÃçµÄʱ¼äÔ½À´Ô½½ü£¬Ììϸ÷µØµÄÖ´·¨»ú¹¹¶¼ÔÚÖÒÑÔÓÐ×éÖ¯·¸·¨Íþв£¬°üÀ¨ÔÚºÚÍøÉÏÏúÊÛ¼ÙÒßÃçµÄÍýÏëÒÔ¼°Õë¶Ô¹©Ó¦Á´¹«Ë¾µÄÎïÀíºÍÐéÄâ¹¥»÷¡£Å·ÃËÖ´·¨»ú¹¹Å·ÖÞÐ̾¯×éÖ¯£¨Europol£©ÖÜÎå·¢³öÖÒÑÔ£¬ÖÒÑÔÓÐ×éÖ¯·¸·¨ÍÅ»ï“ÒÑѸËÙ½ÓÄÉÐж¯£¬ÒÔʹÆäÒªÁìºÍ²úÆ·ÌṩÒÔ˳ӦCOVID-19´óÊ¢ÐД¡£EuropolÖ¸³ö£¬µ±COVID-19ÒßÃçÉÏÊк󣬿ÉÄܽ«ÎÞ·¨ÔÚÏßÏúÊÛ¡£Å·ÖÞÐ̾¯×éÖ¯ÖÒÑÔ˵£º“¿ÉÊÇ£¬¾Ý³ÆÒÔÖÎÁÆ»òÔ¤·ÀCOVID-19µÄÃûÒåÐû´«µÄÚ²ÆÐÔÒ½Ò©²úÆ·ÒѾÔÚÏßϺÍÔÚÏßÏúÊÛ¡£” ¾¯±¨Ôö²¹Ëµ£¬·¸·¨·Ö×Ó¿ÉÄÜ»áÉ¢²¼ÓйØÒßÃçµÄÐéαÐÅÏ¢£¬ÒÔÓÕÆÐ¡ÎÒ˽¼ÒºÍ¹«Ë¾¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.inforisktoday.com/europol-warns-covid-19-vaccine-crime-gangs-a-15536
3. E-LandÔâClopÀÕË÷Èí¼þ¹¥»÷£¬±»ÍµÈ¡ÁË200ÍòÕÅÐÅÓÿ¨Êý¾Ý
¡¾¸ÅÊö¡¿
¾ÝÍâý±¨µÀ£¬¿ËÈÕE-Land RetailÔâÓöÀÕË÷Èí¼þ¹¥»÷£¬ClopÀÕË÷Èí¼þÔËÓªÉÌÉù³ÆÒѾ´Ó¸Ã¹«Ë¾ÇÔÈ¡ÁË200ÍòÕÅÐÅÓÿ¨Êý¾Ý¡£E-Land RetailÊÇÒ»¼Òº«¹úÆóÒµ¼¯ÍÅ£¬×ܲ¿ÉèÔÚº«¹úÊ×¶ûµÄ³¤Ìï¶´ÂéÆÖÇø¡£E-Land¼¯ÍÅÉæ×ãÁãÊÛêaê_¡¢²ÍÌü¡¢Ö÷Ì⹫԰¡¢ÂùݺÍÐÞ½¨ÓªÒµ£¬ÒÔ¼°Æä»ù´¡ÓªÒµ——´ò°çÓªÒµ¡£Ëüͨ¹ý×Ó¹«Ë¾E-Land WorldÔÚÈ«Çò¿ªÕ¹ÓªÒµ¡£ClopÀÕË÷Èí¼þÉù³ÆÔÚÒÑÍùµÄ12¸öÔÂÀï´ÓE-Land Retail¹«Ë¾¹²ÍµÁË200ÍòÕÅÐÅÓÿ¨Êý¾Ý¡£
¡¾²Î¿¼Á´½Ó¡¿
http://mp.weixin.qq.com/s?__biz=MzI4MjA1MzkyNA==&mid=2655313865&idx=2&sn=09eabfc31e7e55837bf1f3b49699c753&chksm=f02fa382c7582a946c41d0237f6be0ae2fc2e9b13f58176af72b63f323c6ed69b750856d1003#rd
4. DoppelPaymerÀÕË÷Èí¼þÍÅ»ïÏ®»÷¸»Ê¿¿µµç×Ó¾ÞÍ·
¡¾¸ÅÊö¡¿
BleepingComputer±¨µÀÁËÕâ´Î¹¥»÷µÄÐÂÎÅ£¬ÏÖÔÚDoppelPaymerÀÕË÷Èí¼þÔÚÆä×ß©վµãÉÏÐû²¼ÁËÊôÓÚ¸»Ê¿¿µNAµÄÎļþ¡£ºÚ¿ÍÉù³ÆÔÚ¼ÓÃÜÄ¿µÄϵͳ֮ǰÒѾÇÔÈ¡ÁËδ¼ÓÃܵÄÎļþ¡£¸»Ê¿¿µÎªÃÀ¹ú£¬¼ÓÄôó£¬Öйú£¬·ÒÀ¼ºÍÈÕ±¾µÄÖ÷Òª¹«Ë¾Éú²úµç×Ó²úÆ·¡£Õâ¼Òµç×ÓÖÆÔì¾ÞÍ·ÔÚÈ«ÇòÓµÓÐ80ÍòÃûÔ±¹¤£¬2019ÄêµÄÊÕÈëΪ1,720ÒÚÃÀÔª¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securityaffairs.co/wordpress/112033/cyber-crime/foxconn-doppelpaymer-ransomware.html
5. ÀÕË÷Èí¼þµÄÍ´¿à¶ÔÒ½Ôº¹¥»÷×î´ó
¡¾¸ÅÊö¡¿
Ö»¹ÜÔÚ´óÊ¢ÐÐʱ´úÒ½Ôº´¦ÓÚµÚÒ»Ïߣ¬µ«²»Á¼ÐÐΪÕßÈÔ¼ÌÐøÒÔÀÕË÷Èí¼þΪĿµÄ¡£³ýÁËÔÚ×µÄÇéÐÎÏÂÆÆËðÒ½ÁÆ»ú¹¹µÄÔËÓªÁ÷³ÌÍ⣬¹¥»÷»¹ÑݱäΪÍþв»¼ÕßÇå¾²¡£
¡¾²Î¿¼Á´½Ó¡¿
https://threatpost.com/ransomware-hits-hospitals-hardest/162096/
6. ˼¿ÆÇ°¹¤³ÌʦÒòºÚ¿Í¹¥»÷±»ÅÐ2Äêî¿Ïµ
¡¾¸ÅÊö¡¿
ÃÀ¹ú˾·¨²¿ÖÜÈýÐû²¼£¬Ò»Ãûǰ˼¿Æ¹¤³Ìʦ±»¿Ø·¸ÓкڿÍÈëÇÖÆäǰ¹«Ë¾µÄ×ïÐУ¬²¢Ôì³É140ÍòÃÀÔªµÄËðʧ£¬Ëû±»Åд¦Á½ÄêͽÐÌ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.inforisktoday.com/ex-cisco-engineer-sentenced-to-2-years-in-prison-for-hacking-a-15564
7. θ绪µØÌúÒòEgregorÀÕË÷Èí¼þÖÐÖ¹
¡¾¸ÅÊö¡¿
Õâ´Î¹¥»÷×èÖ¹ÁËTranslinkÓû§Ê¹ÓÃÆäµØÌú¿¨»òÔÚ×ÔÖúͤ¹ºÖÃÃÅÆ±£¬ÕâÊDZ¾Öܶà²úÍþв×éÖ¯µÄµÚ¶þ´Î¹¥»÷¡£EgregorÀÕË÷Èí¼þ±³ºóµÄÍþв¼ÓÈëÕßÔÚÔ˶¯µÄ×î³õ¼¸¸öÔÂÖÐÌåÏÖ³öºÜ¸ßµÄˮƽ¡£ÔÚÃé×¼ÏÝÈëÄæ¾³µÄÃÀ¹úÁãÊÛÉÌKmartÖ®ºó£¬EgregorÍŻﻹͨ¹ýÀÕË÷Èí¼þ¹¥»÷ÆÆËðÁËθ绪µØÌúϵͳ¡£¼ÓÄô󶼻ṫ¹²½»Í¨ÍøÂçTranslinkÖÜËÄͨ¹ýÆäÊ×ϯִÐйÙKevin DesmondÔÚTwitterÉϵÄÉùÃ÷È·ÈÏ£¬“ÕâÊÇ“¶ÔÎÒÃÇijЩIT»ù´¡ÉèÊ©µÄÀÕË÷Èí¼þ¹¥»÷µÄÄ¿µÄ””£¬ÆäÖаüÀ¨“ͨ¹ý´òÓ¡µÄÐÂÎÅÓëTranslink¾ÙÐÐͨѶ¡£”
¡¾²Î¿¼Á´½Ó¡¿
https://threatpost.com/vancouver-metro-egregor-ransomware/161892/
8. ¾¯·½¾Ð²¶ÁËÁ½Ãû͵ÇÔ¹ú·À¾ÞÍ·Ãô¸ÐÊý¾ÝµÄÈË
¡¾¸ÅÊö¡¿
Òâ´óÀû¾¯·½¾Ð²¶ÁËÁ½ÈË£¬ËûÃDZ»Ö¸¿Ø´Ó¹ú·À¹«Ë¾Leonardo SpAÇÔÈ¡ÁË10 GBµÄÉñÃØÊý¾ÝºÍ¾üÊÂÉñÃØ¡£À³°ºÄɶàÊÇÒ»¼Ò¹úÓпç¹ú¹«Ë¾£¬Ò²ÊÇÌìÏÂÉÏ×î´óµÄ¹ú·À³Ð°üÉÌÖ®Ò»¡£ Òâ´óÀû¾¯·½Ðû²¼µÄÐÂÎŏ峯£¬Á½È˶ÔÀ³°ºÄɶ๫˾µÄ·É»ú½á¹¹²¿·ÖºÍ·É»ú²¿·ÖµÄIT½á¹¹¾ÙÐÐÁËÑÏÖØ¹¥»÷¡£ÕâÁ½Ð¡ÎÒ˽¼ÒÊÇLeonardo SpAµÄITÇå¾²ÖÎÀí²¿·ÖµÄǰ¹ÍÔ±£¬ÏÖÔÚÕýÔÚÀÎÓüµÄArturo D\'EliaºÍLeonardo CERT£¨ÍøÂçÓ¦¼±×¼±¸Ð¡×飩ÈÏÕæÈËAntonio RossiµÄÐÐΪ£¬Ô¤·ÀÐԵļÒÍ¥¼à»¤²½·¥¡£À³°ºÄɶàµÄÍøÂç½ôÆÈÍŶÓÈÏÕæÈËÒòÉæÏÓÍáÇú¹¥»÷¹æÄ£²¢¹ÊÕÏÊÓ²ì¶ø±»Èí½û¡£Éó²é¹ÙÖ¸³ö£¬À³°ºÄɶàµÄÇ徲ϵͳδ¼ì²âµ½¾Ý³ÆÊDz»ÖÒÔ±¹¤Ê¹ÓõĶñÒâÈí¼þ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securityaffairs.co/wordpress/111965/cyber-crime/leonardo-data-theft.html

AG¹«Ë¾ÔÆ







