ÃÀ¹úÌØÇÚ¾ÖÖÒÑÔÕë¶ÔÍйÜЧÀÍÌṩÉÌ£¨MSP£©µÄ¹¥»÷Ôö¶à£»£»£»TalosÅû¶ChromeºÍFirefoxÎó²îµÄÊÖÒÕϸ½Ú

Ðû²¼Ê±¼ä 2020-07-07

1.ÃÀ¹úÌØÇÚ¾ÖÖÒÑÔ£¬ £¬£¬£¬£¬£¬Õë¶ÔÍйÜЧÀÍÌṩÉÌ£¨MSP£©µÄ¹¥»÷Ôö¶à


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


ÃÀ¹úÌØÇÚ¾ÖÏòÃÀ¹ú˽Ӫ²¿·ÖºÍÕþ¸®×éÖ¯·¢³öÁËÇå¾²¾¯±¨£¬ £¬£¬£¬£¬£¬ÖÒÑÔÕë¶ÔÖÎÀíЧÀÍÌṩÉÌ£¨MSP£©µÄºÚ¿Í¹¥»÷ÓÐËùÔöÌí¡£¡£¡£¡£¡£¡£¡£ÃÀ¹úÌØÇÚ¾Ö¹ÙÔ±ÌåÏÖ£¬ £¬£¬£¬£¬£¬ËûÃǵÄÊÓ²ìС×é·¢Ã÷Ô½À´Ô½¶àµÄºÚ¿Í¶ÔMSPÌᳫ¹¥»÷£¬ £¬£¬£¬£¬£¬²¢½«ÆäÊÓΪ½øÈ빫˾ÄÚ²¿ÍøÂçµÄÌø°å¡£¡£¡£¡£¡£¡£¡£Ö®ºó£¬ £¬£¬£¬£¬£¬ºÚ¿Í»áͨ¹ý±»ºÚµÄMSPs¶Ô¹«Ë¾ÏµÍ³¾ÙÐй¥»÷£¬ £¬£¬£¬£¬£¬ÊµÑéÉÌÒµµç×ÓÓʼþ¹¥»÷(BEC)£¬ £¬£¬£¬£¬£¬²¢°²ÅÅÀÕË÷Èí¼þ¡£¡£¡£¡£¡£¡£¡£2019Ä걬·¢ÁËÊýÊ®ÆðMSP¹¥»÷ÊÂÎñ£¬ £¬£¬£¬£¬£¬¶øGandCrabºÍREvilµÈÀÕË÷Èí¼þÍÅ»ïÒ²×îÏÈÃé×¼MSP£¬ £¬£¬£¬£¬£¬È»ºóѬȾÆäÊܺ¦Õß¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/us-secret-service-reports-an-increase-in-hacked-managed-service-providers-msps/#ftag=RSSbaffb68


2.SanSecÐû²¼±¨¸æ³Æ³¯ÏÊÓëMagecart¹¥»÷ÓйØ


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


ºÉÀ¼ÍøÂçÇå¾²¹«Ë¾SanSecÔÚ½ñÌìÐû²¼±¨¸æÖÐÌåÏÖ£¬ £¬£¬£¬£¬£¬×Ô2019Äê5ÔÂÒÔÀ´£¬ £¬£¬£¬£¬£¬³¯ÏÊÒ»Ö±ÔÚ¶ÔÍøÉÏÊÐËÁ¾ÙÐÐMagecart¹¥»÷£¬ £¬£¬£¬£¬£¬Êܺ¦Õß°üÀ¨ÔÚ½ñÄê4ÔºÍ6ÔÂÔâµ½ÆÆËðÅä¼þÁ¬ËøµêClaire's¡£¡£¡£¡£¡£¡£¡£SanSec·¢Ã÷×î½üµÄÍøÂçä¯ÀÀ¹¥»÷ÖÐʹÓõÄÓòºÍЧÀÍÆ÷IPµØµãÓëÏÈǰÒÑÖªµÄ³¯ÏÊÕþ¸®×ÊÖúµÄºÚ¿Í»ù´¡ÉèÊ©Óйأ¬ £¬£¬£¬£¬£¬²¢¿ÉÒÔ×·Ëݵ½Æ½ÈÀºÚ¿Í×éÖ¯Hindden Cobra¡£¡£¡£¡£¡£¡£¡£Æ½ÈÀµÄºÚ¿Í²»µ«¼ÓÈëÁËATMÍøÂçÇÀ½Ù£¬ £¬£¬£¬£¬£¬»¹²ß»®Á˼ÓÃÜÇ®±ÒȦÌ×£¬ £¬£¬£¬£¬£¬²¢¹¥»÷Á˼ÓÃÜÇ®±ÒÉúÒâËù¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/north-korean-hackers-linked-to-web-skimming-magecart-attacks-report-says/


3.TalosÅû¶×î½üÐÞ¸´µÄChromeºÍFirefoxÎó²îµÄÊÖÒÕϸ½Ú


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


Cisco TalosµÄÑо¿Ö°Ô±Åû¶ÁË×î½üÐÞ¸´µÄChromeºÍFirefox Webä¯ÀÀÆ÷ÖÐÎó²îµÄÊÖÒÕϸ½Ú¡£¡£¡£¡£¡£¡£¡£µÚÒ»¸öÎó²î±»¸ú×ÙΪCVE-2020-6463£¬ £¬£¬£¬£¬£¬ÊÇÒ»¸öÄÚ´æËð»µÎó²î£¬ £¬£¬£¬£¬£¬Ó°ÏìÁËChromeÖеÄPDFium¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ýÓÕÆ­Óû§·­¿ª°üÀ¨JavaScript´úÂëµÄÎĵµÀ´´¥·¢´ËÎó²î£¬ £¬£¬£¬£¬£¬²¢Ê¹ÓÃÆäÔÚä¯ÀÀÆ÷ÖÐÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£Google ÓÚ4ÔÂÐû²¼ÁËChrome 81.0.4044.122°æ±¾ÐÞ¸´Á˸ÃÎó²î¡£¡£¡£¡£¡£¡£¡£µÚ¶þ¸öÎó²îΪ±»¸ú×ÙΪCVE-2020-12418£¬ £¬£¬£¬£¬£¬ÊÇFirefoxÖÐÓëURL mPath¹¦Ð§Ïà¹ØµÄÐÅϢй¶Îó²î£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÓÕʹÊܺ¦Õß»á¼ûÌØÖÆµÄURLÀ´Ê¹ÓøÃÎó²î£¬ £¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÔ½½ç¶ÁÈ¡¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/105547/security/talos-chrome-firefox-flaws.html


4.΢ÈíÖÒÑÔÀÕË÷Èí¼þAvaddonÈÔÔÚʹÓÃExcel 4.0ºêÈö²¥


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


΢ÈíÖÒÑÔ˵£¬ £¬£¬£¬£¬£¬ÀÕË÷Èí¼þAvaddonÒѾ­¾íÍÁÖØÀ´£¬ £¬£¬£¬£¬£¬Æä¹¥»÷ËÆºõ¸ü¾ßÕë¶ÔÐÔ£¬ £¬£¬£¬£¬£¬²¢ÇÒÒÀÈ»ÒÀÀµ¶ñÒâExcel 4.0ºêÈö²¥¡£¡£¡£¡£¡£¡£¡£Microsoft Security IntelligenceÖ¸³ö£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÏÖÔÚÖ÷Ҫ׼¶ÔÒâ´óÀûµÄÌØ¶¨Ä¿µÄ£¬ £¬£¬£¬£¬£¬ËûÃÇͨ¹ý·¢ËÍ´øÓжñÒâExcel 4.0ºêµÄÎĵµµÄµç×ÓÓʼþÌᳫ¹¥»÷¡£¡£¡£¡£¡£¡£¡£ÆäÖУ¬ £¬£¬£¬£¬£¬ÓжñÒâÓʼþαװ³ÉÊǶ¯¼à²ì¾ÖÏòÒ»¼ÒСÆóÒµ·¢³öµÄÓйØÎ£»£»£»úʱÆÚÎ¥·´ÊÂÇé»®¶¨µÄ֪ͨ£¬ £¬£¬£¬£¬£¬²¢ÓÕÆ­Êܺ¦Õß·­¿ª¸½¼þÖÐαװ³É¹Ù·½Í¨ÖªµÄZIPÎļþ¡£¡£¡£¡£¡£¡£¡£Î¢ÈíÌåÏÖ£¬ £¬£¬£¬£¬£¬×î½ü¼¸¸öÔÂÒÔÀ´ÔÚ¶ñÒâÈí¼þ»î¶¯ÖÐʹÓÃExcel 4.0ºê×îÏȱäµÃÔ½À´Ô½Ê¢ÐС£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/avaddon-ransomware-shows-that-excel-40-macros-are-still-effective/


5.SnakeÔÚ¼ÓÃÜÎļþǰ»á½«Ä¿µÄϵͳ¸ôÀ룬 £¬£¬£¬£¬£¬ÒÔ×èÖ¹±»×ÌÈÅ


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


ÍøÂçÇå¾²¹«Ë¾Deep InstinctµÄ·¢Ã÷ÀÕË÷Èí¼þSnakeÔÚ¼ÓÃÜÎļþǰ»á½«Ä¿µÄϵͳ¸ôÀ룬 £¬£¬£¬£¬£¬ÒÔ×èÖ¹Êܵ½×ÌÈÅ¡£¡£¡£¡£¡£¡£¡£ÔÚ×î½üµÄ¹¥»÷ÖеÄSnakeʾÑù±¾ÊµÏÖÁËÆôÓúͽûÓ÷À»ðǽ£¬ £¬£¬£¬£¬£¬ÒÔ¼°Ê¹ÓÃÌØ¶¨ÃüÁî×èÖ¹ÓëϵͳµÄÓк¦ÅþÁ¬µÄ¹¦Ð§¡£¡£¡£¡£¡£¡£¡£ÔÚ×î½üµÄ¹¥»÷ÖÐʹÓõÄSnakeÑù±¾ÊµÏÖÁËÆôÓúͽûÓ÷À»ðǽµÄÄÜÁ¦£¬ £¬£¬£¬£¬£¬²¢¿ÉÒÔʹÓÃÌØ¶¨ÃüÁî×èÖ¹²»ÐèÒªµÄϽµµÍ¬½Ó¡£¡£¡£¡£¡£¡£¡£SnakeÔÚ×îÏȼÓÃÜ֮ǰ£¬ £¬£¬£¬£¬£¬»áʹÓÃWindows·À»ðǽÀ´×èÖ¹Êܺ¦Õß»úеÉÏûÓÐÉèÖõÄÈκÎÊÕÖ§ÍøÂçÅþÁ¬¡£¡£¡£¡£¡£¡£¡£ÓëÍâ½ç¶Ï¿ªÅþÁ¬ºó£¬ £¬£¬£¬£¬£¬Snake»áɱËÀ¿ÉÄÜ×ÌÈżÓÃܵÄÓ²±àÂëÀú³Ì£¬ £¬£¬£¬£¬£¬°üÀ¨Ó빤ҵÏà¹ØµÄÀú³Ì£¬ £¬£¬£¬£¬£¬ÒÔ¼°Çå¾²ºÍ±¸·Ý½â¾ö¼Æ»®¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/105572/malware/snake-ransomware-isolates-systems.html?utm_source=rss&utm_medium=rss&utm_campaign=snake-ransomware-isolates-systems


6.¶à¸öÔ¼»áÓ¦ÓùýʧÉèÖÃÊý¾Ý¿âй¶Êý°ÙÍòÓû§Ãô¸ÐÊý¾Ý


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


WizCaseµÄITÑо¿Ö°Ô±·¢Ã÷£¬ £¬£¬£¬£¬£¬ÃÀ¹úºÍ¶«ÑǵÄ5¸öÔ¼»áÓ¦ÓóÌÐòÒò¹ýʧÉèÖÃÊý¾Ý¿âµ¼ÖÂÊý°ÙÍòÓû§Ãô¸ÐÊý¾Ýй¶£¬ £¬£¬£¬£¬£¬Ð¹Â¶Êý¾Ý°üÀ¨ÐÕÃû¡¢Õ˵¥µØµã¡¢µç»°ºÅÂ롢СÎÒ˽¼Ò×ÊÁÏ£¬ £¬£¬£¬£¬£¬ÉõÖÁÊÇ˽ÈËÐÂÎŵÈÒþ˽¡£¡£¡£¡£¡£¡£¡£´Ë´Î±¬·¢×ß©ÊÂÎñµÄapp»®·ÖΪÃÀ¹úµÄCatholicSinglesºÍ YESTIKI£¬ £¬£¬£¬£¬£¬º«¹úµÄBlurryºÍCongdaq/Kongdaq£¬ £¬£¬£¬£¬£¬ÈÕ±¾µÄCharinºÍKyuun¡£¡£¡£¡£¡£¡£¡£ÆäÖУ¬ £¬£¬£¬£¬£¬CatholicSingles»¹Ì»Â¶ÁËÓû§µÄ¸¶¿î·½·¨¡£¡£¡£¡£¡£¡£¡£WizCaseÒÔΪ£¬ £¬£¬£¬£¬£¬ÕâЩÊý¾Ý¿ÉÄÜÊÇÔÚWeb ScrappingÀú³Ì±»Ð¹Â¶£¬ £¬£¬£¬£¬£¬¸ÃÀú³Ì»áÍøÂçºÍ´æ´¢Óû§ÌṩµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/5-dating-apps-leak-millions-of-user-data/