AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2021.01.11-2021.01.17£©
2021-01-18
Ò»¡¢ Íþвͨ¸æ
Ìð˯¶àÄêµÄincaseformatÈ䳿²¡¶¾±»½ÐÐÑ
¡¾Ðû²¼Ê±¼ä¡¿2021-01-13 22:00:00 GMT
¡¾¸ÅÊö¡¿
2021Äê1ÔÂ13ÈÕ£¬AG¹«Ë¾¿Æ¼¼Ó¦¼±ÏìÓ¦ÍŶӽӵ½Ìì϶à¸ö¿Í»§·´ÏìѬȾËùνµÄincaseformat²¡¶¾£¬Éæ¼°Õþ¸®¡¢Ò½ÁÆ¡¢½ÌÓý¡¢ÔËÓªÉ̵ȶà¸öÐÐÒµ£¬ÇÒѬȾÖ÷»ú¶àΪ²ÆÎñÖÎÀíÏà¹ØÓ¦ÓÃϵͳ¡£Ñ¬È¾Ö÷»úÌåÏÖΪËùÓзÇϵͳ·ÖÇøÎļþ¾ù±»É¾³ý£¬ÓÉÓÚ±»É¾³ýÎļþ·ÖÇø¸ùĿ¼Ï¾ù±£´æÃûΪincaseformat.logµÄ¿ÕÎļþ£¬Òò´ËÍøÂçÉϽ«´Ë²¡¶¾ÃüÃûΪincaseformat¡£´ÓËÑË÷ÒýÇæÐ§¹ûÀ´¿´£¬¸Ã²¡¶¾×îÔç·ºÆðʱ¼äΪ2009Ä꣬Ö÷Á÷ɱ¶¾Èí¼þ³§É̾ù½«´Ë²¡¶¾ÃüÃûΪWorm.Win32.Autorun£¬´ÓÃû³Æ¿ÉÒÔÅжϸò¡¶¾ÎªWindowsƽ̨ͨ¹ýÒÆ¶¯½éÖÊÈö²¥µÄÈ䳿²¡¶¾¡£²¡¶¾ÎļþÔËÐкó£¬Ê×Ïȸ´ÖÆ×ÔÉíµ½WindowsĿ¼Ï£¨C:\\\\windows\\\\tsay.exe£©£¬Îļþͼ±êαװΪÎļþ¼Ð¡£²¡¶¾Îļþ½«ÔÚÖ÷»úÖØÆôºóÔËÐУ¬²¢×îÏȱéÀúËùÓзÇϵͳ·ÖÇøÏÂĿ¼²¢ÉèÖÃΪÒþ²Ø£¬Í¬Ê±½¨ÉèͬÃûµÄ²¡¶¾Îļþ¡£±ðµÄ»¹»áͨ¹ýÐÞ¸Ä×¢²á±í£¬ÊµÏÖ²»ÏÔʾÒþ²ØÎļþ¼°Òþ²ØÒÑÖªÎļþÀàÐÍÀ©Õ¹Ãû¡£×îºó¶Ô·Çϵͳ·ÖÇøÏÂËùÓÐÎļþÖ´ÐÐɾ³ý²Ù×÷£¬²¢½¨Éèincaseformat.logÎļþ¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. Apache Flink Ŀ¼±éÀúÎó²î
¡¾¸ÅÊö¡¿
2021Äê1ÔÂ06ÈÕ£¬°²Ê¶¿Æ¼¼A-TeamÍŶӼà²âµ½Apache Flink Ðû²¼ÁËĿ¼´©Ô½µÄÎó²îͨ¸æ£¬CVE±àºÅΪCVE-2020-17518£¬CVE-2020-17519¡£Apache FlinkÊÇÒ»¸ö¿ªÔ´Á÷´¦Öóͷ£¿ò¼Ü£¬Æä½¹µãÊÇÓÃJavaºÍScala±àдµÄÂþÑÜʽÁ÷Êý¾ÝÁ÷ÒýÇæ¡£¹¥»÷ÕßʹÓøÃÎó²î¿ÉʵÏÖÔ¶³Ì¶ÁÈ¡·þÎñÆ÷í§ÒâÎļþ£¬Ô¶³ÌдÈëí§ÒâÎļþ£¬±£´æ¼«´óµÄÇå¾²Òþ»¼¡£°²Ê¶¿Æ¼¼½¨Òé¿í´óÓû§ÊµÊ±Éý¼¶Apache Flink×îа汾£¬ÒÔÃâÔâÊÜ´ËÎó²î¹¥»÷¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.secpulse.com/archives/151162.html
2. RyukÀÕË÷Èí¼þÀûÈó1.5ÒÚÃÀÔª
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±Ëµ£¬RyukÀÕË÷Èí¼þ±³ºóµÄÔËÓªÉÌʹÓõļÓÃÜÇ®±ÒÇ®°üºÍ¸ÃÍÅ»ïµÄ·ÖÖ§»ú¹¹³ÖÓÐÁè¼Ý1.5ÒÚÃÀÔª¡£Çå¾²¹«Ë¾HYASµÄÊ×ϯÑо¿Ô±Brian CarterºÍAdvanced IntelligenceµÄÊ×ϯִÐйÙVitali Kremez±¨¸æËµ£¬ËûÃÇÒѾȷ¶¨ÁËRyukÍøÂç·¸·¨ÍŻPÆäÁ¥Êô¹«Ë¾ÓÃÀ´ÎüÊÕÊܺ¦ÕßÀÕË÷Èí¼þ¸¶¿îµÄ61¸ö±ÈÌØ±ÒµØµã¡£Ñо¿Ö°Ô±ÔÚÒ»·Ýб¨¸æÖÐ˵£¬¸Ã¼¯ÍÅÓÃÓÚ×ªÒÆ×ʽðµÄÁ½¸ö±ÈÌØ±ÒÉúÒâËùÊÇ×ܲ¿Î»ÓÚÑÇÖÞµÄHuobiºÍBinance¡£¸ÃС×黹ʹÓÃÏÊΪÈËÖªµÄ½»Á÷·½·¨¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.inforisktoday.com/ryuk-ransomware-profits-150-million-a-15726
3. ÍÆÌØÓÀÊÀÐÔµØÔÝÍ£ÁË×ÜÍ³ÌØÀÊÆÕµÄÕË»§
¡¾¸ÅÊö¡¿
TwitterÓÀÊÀ×èÖ¹ÁËÌÆÄÉµÂ·ÌØÀÊÆÕ×ÜͳµÄÕË»§£¬µ£ÐÄËûµÄÍÆÎÄ¿ÉÄÜÒý·¢ÐÂÒ»²¨±©Á¦¡£ÎªÁË»ØÓ¦¶ÔÃÀ¹ú¹ú»á´óÏõÄÏ®»÷£¬ÖÜÈý×ÜͳµÄÕÊ»§×î³õ±»ÔÝÍ£ÁË12¸öСʱ£¬¸ÃÉ罻ýÌåÆ½Ì¨ÌåÏÖ£¬Æä¾öÒéÊÇÓÉÓÚ“ÑÏÖØÎ¥·´ÎÒÃǵĹ«Ãñ³ÏÐÅÕþ²ß”ÒýÆðµÄ¡£ÔÚ×ÐϸÉó²é@realDonaldTrumpÕÊ»§ÖеÄ×îÐÂTweet¼°ÆäÖÜΧµÄÇéÐΣ¨ÌØÊâÊÇÔõÑùÔÚTwitterÉϺÍÔÚTwitterÖ®ÍâÎüÊÕÏ¢ÕùÊÍËüÃÇ£©Ö®ºó£¬ÓÉÓÚ¿ÉÄÜ»á½øÒ»²½É¿»ó±©Á¦£¬ÎÒÃÇÒÑÓÀÊÀÍ£ÓøÃÕÊ»§¡£¸Ã¹«Ë¾ÔÚÒ»ÌõÍÆÎÄÖÐÐû²¼¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securityaffairs.co/wordpress/113197/social-networks/twitter-donald-trump-account-suspended.html
4. ±ÈÌØ±ÒÊÐÖµìÉý´ßÉúGolangÓïÑÔÍÚ¿óľÂíΧ¹¥ÔÆÖ÷»ú
¡¾¸ÅÊö¡¿
ÊܽüÆÚ±ÈÌØ±Ò±©ÕÇ·¢¶¯Êý×ÖÐéÄâ±ÒÕûÌåÊÐÖµìÉýÓ°Ï죬ÍÚ¿óľÂíÊ®·Ö»îÔ¾¡£½üÆÚÒѲ¶»ñ½Ï¶àʹÓÃgolangÓïÑÔ±àдµÄÖÖÖ־籾ľÂí£¬ÕâЩľÂíʹÓöà¸ö²î±ðlinux·þÎñÆ÷×é¼þµÄ¸ßΣÎó²î»òÈõÃÜÂëÈëÇÖÔÆ·þÎñÆ÷ÍÚ¿ó¡£¶ÔÕâЩÍÚ¿óľÂí¾ÙÐÐÆÊÎöËÝÔ´£¬·¢Ã÷·ÖÊô²î±ðµÄºÚ²úÍÅ»ï¿ØÖÆ£¬Óеã“ǧ¾üÍòÂíÒ»ÎÑ·äЯÎó²îÎäÆ÷Èõ¿ÚÁîÎäÆ÷ÇÀÕ¼ÔÆÖ÷»úÍÚ¿óÌÔ½ð”µÄÒâ˼¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.freebuf.com/articles/system/260483.html
5. ÎïÁªÍøÇå¾²£¬»ùÓÚ²î·ÖÒþ˽µÄÊý¾ÝÐû²¼
¡¾¸ÅÊö¡¿
ÎïÁªÍø»á¸ÐÖª´ó×ÚÊý¾Ý£¬¸ÐÖªÊý¾Ýͨ³£ÐèÒªÐû²¼ºÍ¹²Ïí¡£µ«Êý¾ÝÔÚÐû²¼ºÍ¹²ÏíÊ±ÃæÁÙÖØ´óµÄÒþ˽й¶Σº¦¡£Ëæ×ÅÊý¾ÝÍÚ¾òÊÖÒÕµÄÒ»Ö±Ìá¸ß£¬¾ÓÉÒþ˽±£»¤µÄÎïÁªÍøÊý¾ÝÖеÄÃô¸ÐÐÅÏ¢Ò²Ô½À´Ô½ÈÝÒ×±»Êý¾ÝÍÚ¾òÕß»ñÈ¡£¬Òò´Ë£¬ÔõÑù±£»¤Ðû²¼Êý¾ÝÖеÄÒþ˽ÎÊÌ⣬³ÉΪÁËÒ»¸öеÄÑо¿ÈÈÃÅ¡£
¡¾²Î¿¼Á´½Ó¡¿
6. Ò×Êܹ¥»÷µÄÊý¾Ý¿â̻¶ÁËÍŽá¹ú¹ÍÔ±µÄÊý¾Ý
¡¾¸ÅÊö¡¿
Ò»×é×ÔÁ¦µÄÇå¾²Ñо¿Ö°Ô±ÌåÏÖ£¬ÊôÓÚÍŽá¹úÇéÐÎÍýÏëÊð£¨UNEP£©µÄGitHub´æ´¢¿âÖеÄÎó²î̻¶ÁË100,000¶àÌõÔ±¹¤¼Í¼£¬°üÀ¨Ð¡ÎÒ˽¼ÒÉí·ÝÐÅÏ¢£¬ÁªÏµ·½·¨ºÍÆäËûÃô¸ÐÊý¾Ý¡£ÇéÐÎÊðÈÏÕæÐµ÷ÍŽá¹úµÄÇéÐÎÔ˶¯¡£Ò»ÈºÐÂµÄÆ·µÂºÚ¿ÍSakura SamuraiÔÚÆä±¨¸æÖÐÖ¸³ö£¬¸ÃÎó²îÔ´×Ô̻¶ÁËGitHub´æ´¢¿âƾ֤µÄ¶Ëµã¡£“ÕâЩƾ֤ʹÎÒÃÇÄܹ»ÏÂÔØGitHub´æ´¢¿â£¬Ê¶±ð´ó×ÚÓû§Æ¾Ö¤ºÍСÎÒ˽¼ÒÉí·ÝÐÅÏ¢¡£×ܹ²£¬ÎÒÃÇʶ±ðÁË100,000¸öÒÔÉϵÄ˽ְԱ¹¤¼Í¼£¬”Ô¼º²Ñ··½Ü¿ËÑ·£¨John Jackson£©Ëµ£¬ËûÊÇÃÀ¹úÇå¾²Ñо¿Ö°Ô±Ö®Ò»¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.inforisktoday.com/vulnerable-database-exposed-un-employees-data-a-15744
7. TikTok½«ÇàÉÙÄêÕË»§±£ÃÜ
¡¾¸ÅÊö¡¿
¸Ã¹«Ë¾Ðû²¼£¬ÄêËêÔÚ13ÖÁ15ËêÖ®¼äµÄÕÊ»§½«Ä¬ÈÏʹÓÃÒþ˽ÉèÖã¬ÒÔ¼°ÆäËûÇå¾²²½·¥¡£Ê¢ÐеÄÊÓÆµ¹²ÏíÉ罻ýÌ幫˾TikTokÒѾöÒéÌá¸ßÕë¶Ôδ³ÉÄêÈ˵ÄÒþ˽±£»¤²½·¥¡£TikTokµÄÊܽӴýˮƽÊÇÓÉÇàÉÙÄêÍÆ¶¯µÄ-¸Ã¹«Ë¾ÔÚ2019Ä걨¸æ³Æ£¬Æä26.5¸öÔ¶ÈÓû§ÖÐÔ¼ÓÐ60£¥ÄêËêÔÚ16ËêÖÁ24ËêÖ®¼ä£¬¶øÕâЩ×îв½·¥ÊÇΪÁËÈÃÆä×îСµÄÓû§¸üÇå¾²µØÊ¹ÓÃ¸ÃÆ½Ì¨¡£
¡¾²Î¿¼Á´½Ó¡¿
https://threatpost.com/tiktok-teen-accounts-private/163040/
8. COVID-19ÒßÃçÎļþй¶
¡¾¸ÅÊö¡¿
ÉϸöÔÂÔÚÅ·ÖÞÒ©Æ·ÖÎÀí¾ÖµÄÒ»´ÎÍøÂç¹¥»÷Öб»µÁµÄÓйØCOVID-19ÒßÃçºÍÒ©Æ·µÄÎļþ£¨°üÀ¨Ò»Ð©°üÀ¨Ð¡ÎÒ˽¼ÒÐÅÏ¢µÄÎļþ£©ÒÑÔÚ»¥ÁªÍøÉÏй¶¡£¸Ã»ú¹¹Î»ÓÚºÉÀ¼£¬ÈÏÕæÆÀ¹ÀºÍÊÚȨŷÃ˵ÄÒ©ÎïºÍÒßÃç-°üÀ¨ÓÃÓÚCOVID-19µÄÒ©ÎïºÍÒßÃç¡£EMAÔÚÖܶþÐû²¼µÄ×îÐÂÉùÃ÷ÖÐ˵£¬Ò»ÏîÊÓ²ìÒÑÈ·¶¨“һЩÓëµÚÈý·½ÓµÓеÄCOVID-19Ò©Æ·ºÍÒßÃçÓйصIJ»·¨»á¼ûÎļþÒѾÔÚ»¥ÁªÍøÉÏ×ß©”¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.inforisktoday.com/covid-19-vaccine-documents-personal-data-leaked-a-15754
9. “SolarLeaks”ÍøÕ¾Éù³ÆÌṩ¹¥»÷Êܺ¦ÕßµÄÊý¾Ý
¡¾¸ÅÊö¡¿
Ò»¸öеÄ×ß©վµãÉù³ÆÕýÔÚ³öÊÛÀ´×ÔCisco£¬FireEye£¬MicrosoftºÍSolarWindsµÄÊý¾Ý£¬ÕâЩÊý¾ÝÊÇͨ¹ýSolarWinds¹©Ó¦Á´¹¥»÷±»µÁµÄ¡£ËäÈ»ÕâËĸö×éÖ¯¶¼ÊÇÊܺ¦ÈË£¬µ«Ç徲ר¼ÒÖÊÒɸÃÌáÒéÊÇ·ñÕýµ±£¬²¢Ö¸³ö£¬¸ÃÌáÒéÓë°üÀ¨¶íÂÞ˹ÔÚÄÚµÄÏÈǰּÔÚ×èÖ¹ºÚ¿Í¹¥»÷¹éÒòµÄÆð¾¢ÏàÆ½ÐС£
¡¾²Î¿¼Á´½Ó¡¿
https://www.inforisktoday.com/solarleaks-site-claims-to-offer-attack-victims-data-a-15751

AG¹«Ë¾ÔÆ







