ÃÀ¹úÄÜÔ´²¿È·ÈÏSolarWindsÒÑÈëÇÖºËÎäÆ÷¾ÖµÄÍøÂ磻£»£»£»£»£»£»£»Avast½üÆÚ·¢Ã÷28¿î¶ñÒâµÄä¯ÀÀÆ÷²å¼þ£¬£¬£¬£¬£¬Ó°Ïì300ÍòÓû§

Ðû²¼Ê±¼ä 2020-12-18
1.ÃÀ¹úÄÜÔ´²¿È·ÈÏSolarWindsÒÑÈëÇÖºËÎäÆ÷¾ÖµÄÍøÂç


1.png


ÃÀ¹úÄÜÔ´²¿ÒѾ­È·ÈÏ£¬£¬£¬£¬£¬SolarWinds±³ºóµÄºÚ¿Í×éÖ¯ÈëÇÖÁËÃÀ¹úºËÎäÆ÷»ú¹¹NNSAµÄÍøÂç¡£¡£¡£ ¡£¡£¡£¡£NNSAÊÇÒ»¸ö°ë×ÔÖÎÕþ¸®»ú¹¹£¬£¬£¬£¬£¬ÈÏÕæÎ¬»¤ºÍÈ·±£ÃÀ¹úºËÎäÆ÷¿â´æ£¬£¬£¬£¬£¬ÒÔ¼°Ó¦¶ÔÃÀ¹úº£ÄÚÍâµÄºËºÍ·ÅÉä½ôÆÈÇéÐΡ£¡£¡£ ¡£¡£¡£¡£FBI¡¢CISAºÍODNIÐû²¼ÁªºÏÉùÃ÷³Æ£¬£¬£¬£¬£¬ºÚ¿ÍÈëÇÖÁ˶à¸öÃÀ¹úÕþ¸®µÄÍøÂ磬£¬£¬£¬£¬°üÀ¨ÃÀ¹ú²ÆÎñ²¿¡¢ÃÀ¹ú¹úÎñÔº¡¢ÃÀ¹úNTIA¡¢ÃÀ¹ú¹úÁ¢ÎÀÉúÑо¿Ôº¡¢DHS-CISAºÍÃÀ¹úÁìÍÁÇå¾²²¿¡£¡£¡£ ¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬Microsoft¡¢FireEyeºÍGoDaddyÒÑΪSolarWinds SunburstºóÃŽ¨ÉèÁËÒ»¸ökill switch£¬£¬£¬£¬£¬ÒÔÖÕÖ¹Êܺ¦ÕßÍøÂçÉϵÄѬȾ¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/solarwinds-hackers-breach-us-nuclear-weapons-agency/


2.HPEÅû¶ÆäЧÀÍÆ÷ÖÎÀíÈí¼þÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î


2.png


»ÝÆÕÆóÒµ£¨HPE£©Åû¶ÆäWindowsºÍLinuxµÄHPE Systems Insight Manager£¨SIM£©Èí¼þÖб£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£ ¡£¡£¡£¡£HPE SIMÊÇÕë¶Ô¶à¸öHPEЧÀÍÆ÷¡¢´æ´¢ºÍÍøÂç²úÆ·µÄÖÎÀíºÍÔ¶³ÌÖ§³Ö×Ô¶¯»¯½â¾ö¼Æ»®¡£¡£¡£ ¡£¡£¡£¡£¸ÃÎó²î±»×·×ÙΪCVE-2020-7200£¬£¬£¬£¬£¬ÑÏÖØÐÔÆÀ·ÖΪ9.8£¬£¬£¬£¬£¬¸ÃÎó²îÊÇÓÉÓÚ¶ÔÓû§ÌṩµÄÊý¾Ýȱ·¦Êʵ±µÄÑéÖ¤µ¼Ö²»¿ÉÐÅÊý¾ÝµÄ·´ÐòÁл¯£¬£¬£¬£¬£¬´Ó¶øÊ¹¹¥»÷ÕßÓпÉÄÜʹÓÃÕâЩÊý¾ÝÖ´ÐдúÂë¡£¡£¡£ ¡£¡£¡£¡£ÏÖÔÚ¸ÃÎó²îÉÐÎÞÇå¾²¸üУ¬£¬£¬£¬£¬¿ÉÊÇHPEÒÑÌṩWindows»º½âÒªÁì¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hpe-discloses-critical-zero-day-in-server-management-software/


3.Avast½üÆÚ·¢Ã÷28¿î¶ñÒâµÄä¯ÀÀÆ÷²å¼þ£¬£¬£¬£¬£¬Ó°Ïì300ÍòÓû§


3.png


Çå¾²¹«Ë¾Avast½üÆÚ·¢Ã÷28¿î¶ñÒâµÄä¯ÀÀÆ÷²å¼þ£¬£¬£¬£¬£¬°üÀ¨15¸öChromeÀ©Õ¹ºÍ13¸öEdgeÀ©Õ¹£¬£¬£¬£¬£¬ÒÑÓ°Ïì300ÍòÓû§¡£¡£¡£ ¡£¡£¡£¡£Õâ28¿î²å¼þ°üÀ¨´ó×ÚʵÏÖ¶ñÒâ²Ù×÷µÄ´úÂ룬£¬£¬£¬£¬ÀýÈ罫Óû§Á÷Á¿Öض¨Ïòµ½¹ã¸æ¡¢½«Óû§Á÷Á¿Öض¨Ïòµ½ÍøÂç´¹ÂÚÕ¾µã¡¢ÍøÂçСÎÒ˽¼ÒÊý¾Ý¡¢ÍøÂçä¯ÀÀ¼Í¼¡¢½«¸ü¶à¶ñÒâÈí¼þÏÂÔØµ½Óû§×°±¸ÉÏ¡£¡£¡£ ¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬GoogleÒÑɾ³ýÁË15¸ö¶ñÒâÀ©Õ¹³ÌÐòÖеÄ3¸ö£¬£¬£¬£¬£¬¶øMicrosoftÒòÎÞ·¨È·ÈÏAvastµÄ±¨¸æ¶øÉÐδ¾ÙÐÐɾ³ý¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/three-million-users-installed-28-malicious-chrome-or-edge-extensions/


4.ºÚ¿Í½«ÀÕË÷Èí¼þSystemBC×÷ΪTorÊðÀíºÍÔ¶³Ì¿ØÖƹ¤¾ß


4.png


ºÚ¿Í½«ÀÕË÷Èí¼þSystemBC×÷ΪTorÊðÀíºÍÔ¶³Ì¿ØÖƹ¤¾ß¡£¡£¡£ ¡£¡£¡£¡£SystemBCÓÚ2019ÄêÊ״ηºÆð£¬£¬£¬£¬£¬ÊÇÒ»ÖÖÊðÀíºÍÔ¶³ÌÖÎÀí¹¤¾ß¡£¡£¡£ ¡£¡£¡£¡£Ëü¼È³äµ±ÒþʽͨѶµÄÍøÂçÊðÀí£¬£¬£¬£¬£¬Óֳ䵱Զ³ÌÖÎÀí¹¤¾ß£¨RAT£©£¬£¬£¬£¬£¬Äܹ»Ö´ÐÐWindowsÏÂÁî²¢½»¸¶ºÍÖ´Ðо籾¡¢¶ñÒâ¿ÉÖ´ÐÐÎļþºÍ¶¯Ì¬Á´½Ó¿â£¨DLL£©£¬£¬£¬£¬£¬»¹¿ÉÒÔÌṩ³¤ÆÚµÄºóÃÅ¡£¡£¡£ ¡£¡£¡£¡£SystemBCµÄ×îÐÂÑù±¾ÖаüÀ¨µÄ´úÂëûÓÐͨ¹ýSOCKS5ÊðÀí³äµ±ÐéÄâ˽ÓÐÍøÂ磬£¬£¬£¬£¬¶øÊÇʹÓÃTorÄäÃûÍøÂç¼ÓÃܲ¢Òþ²ØÏÂÁîºÍ¿ØÖÆÁ÷Á¿µÄÄ¿µÄµØ¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://news.sophos.com/en-us/2020/12/16/systembc/


5.еÄRubyGems¶ñÒâÈí¼þ°üÕë¶Ô¼ÓÃÜÇ®±Ò¹©Ó¦Á´


5.png


Çå¾²¹«Ë¾Sonatype·¢Ã÷еÄRubyGems¶ñÒâÈí¼þ°üÕë¶Ô¼ÓÃÜÇ®±Ò¹©Ó¦Á´£¬£¬£¬£¬£¬ÒÔÇÔÈ¡¼ÓÃÜÇ®±Ò¡£¡£¡£ ¡£¡£¡£¡£Sonatype±¨¸æ³Æ£¬£¬£¬£¬£¬Á½¸ö¶ñÒâÈí¼þ°üpretty_color-0.8.1.gemºÍ ruby-bitcoin-0.0.20.gem£¬£¬£¬£¬£¬Î±×°³É±ÈÌØ±Ò¿âºÍÓÃÓÚÏÔʾ²î±ðÑÕɫЧ¹ûµÄ×Ö·û´®µÄ¿â£¬£¬£¬£¬£¬×°ÖÃÁËÒ»¸ö¼ôÌù°åÇÔÈ¡¹¤¾ß¡£¡£¡£ ¡£¡£¡£¡£ËüÃÇ¿ÉÒÔ¼àÊÓWindows¼ôÌù°åµÄ¼ÓÃÜÇ®±ÒµØµã£¬£¬£¬£¬£¬ÈôÊǼì²âµ½¼ÓÃÜÇ®±ÒµØµã£¬£¬£¬£¬£¬½«»á°ÑËüÌæ»»Îª¹¥»÷Õߵĵص㣬£¬£¬£¬£¬ÒÔÇÔÈ¡¼ÓÃÜÇ®±Ò¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/malicious-rubygems-packages-used-in-cryptocurrency-supply-chain-attack/


6.FBI³ÆDoppelPaymerÓõ绰ÏÅ»£¾Ü¸¶Êê½ðµÄÊܺ¦Õß


6.png


FBI³ÆÀÕË÷Èí¼þÍÅ»ïDoppelPaymerÓôòµç»°µÄ·½·¨ÏÅ»£¾Ü¸¶Êê½ðµÄÊܺ¦Õß¡£¡£¡£ ¡£¡£¡£¡£FBIÌåÏÖ£¬£¬£¬£¬£¬ÕâЩÊÂÎñ×Ô2020Äê2ÔÂÒÔÀ´Ò»Ö±ÔÚ±¬·¢£¬£¬£¬£¬£¬²¢ÇÒÆäËûËĸöÀÕË÷Èí¼þ×éÖ¯Sekhmet ¡¢ Maze ¡¢ContiºÍRyukÒ²ÊÇÓùýÀàËÆµÄÕ½ÂÔ¡£¡£¡£ ¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬¸Ã»ú¹¹»¹Ïêϸ˵Ã÷ÎúÒ»¸öÌØ¶¨°¸Àý£¬£¬£¬£¬£¬ÆäÖÐÍþв´ÓÊܹ¥»÷µÄ¹«Ë¾À©Õ¹µ½ÆäÔ±¹¤ÉõÖÁÊÇÇ×ÆÝ£¬£¬£¬£¬£¬³ÆÒª°ÑһСÎÒ˽¼ÒË͵½Ò»ÃûÔ±¹¤µÄ¼ÒÀï¡£¡£¡£ ¡£¡£¡£¡£µ«FBIÌåÏÖ£¬£¬£¬£¬£¬ÔÚÕâÖÖÇéÐÎÏ£¬£¬£¬£¬£¬±©Á¦Íþвͨ³£ÊÇÆÓªµÄ¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/fbi-says-doppelpaymer-ransomware-gang-is-harassing-victims-who-refuse-to-pay/