2024ÄêÈ«ÇòÊý¾Ýй¶±¾Ç®Ô¤¼Æ½«´ï5ÍòÒÚÃÀÔª£»£»£»£»£»£»¹¥»÷ÕßʹÓÃOrcusºÍRevenge RATÕë¶ÔÕþ¸®ºÍ½ðÈÚ»ú¹¹

Ðû²¼Ê±¼ä 2019-08-30

1.2024ÄêÈ«ÇòÊý¾Ýй¶±¾Ç®Ô¤¼Æ½«´ï5ÍòÒÚÃÀÔª


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ƾ֤հ²©ÍøÂçµÄ×îÐÂÕ¹Íû£¬£¬£¬£¬Ëæ×Åî¿Ïµ·£¿£¿£¿£¿ £¿£¿îµÄʵÑéÒÔ¼°ÆóÒµÔ½·¢ÒÀÀµÓÚÊý×Öϵͳ£¬£¬£¬£¬µ½2024ÄêÈ«ÇòÊý¾Ýй¶µÄ±¾Ç®Ô¤¼Æ½«ÔöÌíµ½5ÍòÒÚÃÀÔªÒÔÉÏ¡£¡£¡£¡£¡£¡£¡£¡£ÕâÒ»Êý¾ÝÀ´×ÔÓڸù«Ë¾Ðû²¼µÄ×îб¨¸æ¡¶ÍøÂç·¸·¨ºÍÇå¾²µÄδÀ´£º2019-2024ÍþвÆÊÎö¡¢Ó°ÏìÆÀ¹À»ººÍ½âÕ½ÂÔ±¨¸æ¡·¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Éù³Æ£¬£¬£¬£¬ÔÚ±¨¸æÊ±´úÄÚÔ¤¼ÆÊý¾Ýй¶±¾Ç®½«´Ó2019ÄêµÄ3ÍòÒÚÃÀԪÿÄêÔöÌí11%¡£¡£¡£¡£¡£¡£¡£¡£±¨¸æÖл¹³ÆËäÈ»´ó¹æÄ£µÄÊý¾Ýй¶¿ÉÄܳÉΪͷÌõÐÂÎÅ£¬£¬£¬£¬µ«ËüÃDz¢·×Æç¶¨»áÖ±½ÓÓ°Ï챾Ǯ£¬£¬£¬£¬ÓÉÓÚ·£¿£¿£¿£¿ £¿£¿îºÍÓªÒµËðʧÓëÊý¾Ýй¶µÄ¹æÄ£²¢²»Ï¸ÃÜÏà¹Ø¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/breach-costs-trillion/


2.Google PlayÖÐÁ½¸ö¹ã¸æÓ¦ÓÃÏÂÔØÁ¿³¬150Íò´Î


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Ñо¿Ö°Ô±ÔÚGoogle PlayÖз¢Ã÷Á½¸ö¹ã¸æÓ¦Ó㬣¬£¬£¬×ÜÏÂÔØÁ¿Áè¼Ý150Íò´Î¡£¡£¡£¡£¡£¡£¡£¡£µÚÒ»¸öAPPÊÇOCRÎı¾É¨ÃèÒÇ£¬£¬£¬£¬Æä×°ÖÃÊýÄ¿Áè¼Ý100Íò£¬£¬£¬£¬ÁíÒ»¸öÊÇÒ»¸ö½¡ÉíAPP£¬£¬£¬£¬×°ÖÃÊýÄ¿Áè¼Ý50Íò¡£¡£¡£¡£¡£¡£¡£¡£ËüÃÇÊôÓÚͳһ¿ª·¢ÕßIdea Master¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹ã¸æÈí¼þʹÓÃAndroid Notification Manager·¢³öÐÂÎÅ£¬£¬£¬£¬µ±Óû§µ¥»÷ÐÂÎÅʱ»á´¥·¢ÏÔʾ´øÓÐ¹ã¸æµÄÒþ²ØÊÓͼ¡£¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿ £¿£¿ª·¢ÕßʹÓÃToast֪ͨ¼ÓÔØ¹ã¸æ£¬£¬£¬£¬²¢Í¨¹ý½«Toast¹¤¾ß¶¨Î»ÔÚÆÁÄ»µÄ¿ÉÊÓÇøÓòÖ®Í⣬£¬£¬£¬Ê¹µÃ¹ã¸æ¶ÔÓû§²»¿É¼û¡£¡£¡£¡£¡£¡£¡£¡£ËäÈ»Óû§ÎÞ·¨¿´µ½¹ã¸æ£¬£¬£¬£¬µ«ËûÃǵÄÌåÑé»áÊܵ½Ó°Ï죬£¬£¬£¬°üÀ¨×°±¸ÐÔÄÜϽµ¡¢µçÁ¿ÏûºÄÒÔ¼°ÍøÂçÁ÷Á¿µÄʹÓÃÔöÌí¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ghost-clicks-boost-ad-revenue-for-android-apps-with-15m-installs/


3.¹¥»÷ÕßʹÓÃOrcusºÍRevenge RATÕë¶ÔÕþ¸®ºÍ½ðÈÚ»ú¹¹


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


˼¿ÆTalosÑо¿Ö°Ô±·¢Ã÷¹¥»÷ÕßÕýÔÚʹÓÃRevenge RATºÍOrcus RATÕë¶ÔÕþ¸®»ú¹¹¡¢½ðÈÚЧÀÍÆóÒµ¡¢ÐÅÏ¢ÊÖÒÕЧÀ͹©Ó¦É̺Í×Éѯ¹«Ë¾µÈ¡£¡£¡£¡£¡£¡£¡£¡£Revenge RATÊÇ2016ÄêÔÚDev PointºÚ¿ÍÂÛ̳ÉϹûÕæÐû²¼µÄRAT£¬£¬£¬£¬Ëü¿ÉÒÔ·­¿ªÔ¶³Ìshell£¬£¬£¬£¬ÔÊÐí¹¥»÷ÕßÖÎÀíϵͳÎļþ¡¢Àú³Ì¡¢×¢²á±íºÍЧÀÍ¡¢¼Í¼°´¼ü¡¢ÍøÂçÃÜÂëÒÔ¼°»á¼ûÉãÏñÍ·µÈ¡£¡£¡£¡£¡£¡£¡£¡£Orcus×Ô2016ÄêÍ·ÒÔÀ´±»Ðû´«ÎªÔ¶³ÌÖÎÀí¹¤¾ß£¬£¬£¬£¬µ«¼øÓÚËü»¹¾ßÓÐÔ¶¿ØÄ¾Âí¹¦Ð§£¬£¬£¬£¬ÏÖÔÚËüÒ²±»ÒÔΪÊÇÒ»ÖÖÄܹ»¼ÓÔØ×Ô½ç˵²å¼þµÄ¶ñÒ⹤¾ß¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ¹¥»÷»î¶¯µÄÔËÓªÕßʹÓö¯Ì¬ÓòÃûϵͳ£¨DDNS£©À´Òþ²ØËûÃǵÄC2ЧÀÍÆ÷£¬£¬£¬£¬Ë¼¿ÆTalosÔÚ±¨¸æÖÐÏêϸÁгöÁ˶ñÒâÑù±¾¹þÏ£¡¢¹¥»÷ÓòÃûÒÔ¼°IPµØµãµÈ¹¥»÷Ö¸±ê£¨IOC£©¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/attackers-target-govt-and-financial-orgs-with-orcus-revenge-rats/


4.Ñо¿Ö°Ô±ÔÚ¶à¸öWordPress²å¼þÖз¢Ã÷9¸öSQL×¢ÈëÎó²î


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


FortinetÔÚ9¸öÊ¢ÐеÄWordPress²å¼þÖз¢Ã÷9¸öSQL×¢ÈëÎó²î¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ²å¼þµÄ¹æÄ£º­¸Ç¹ã¸æ¡¢¾èÔù¡¢Í¼¿â¡¢±í¸ñ¡¢ÐÂÎÅͨѶºÍÊÓÆµ²¥·ÅÆ÷µÈ£¬£¬£¬£¬ÊýÒÔÊ®Íò¼ÆµÄWordPressÍøÕ¾ÕýÔÚÆð¾¢Ê¹ÓÃÕâЩ²å¼þ£¬£¬£¬£¬ÆäÖÐÒ»Ð©ÍøÕ¾ÔÚÆäÏìÓ¦µÄÖÖ±ðÖÐÅÅÃûµÚÒ»¡£¡£¡£¡£¡£¡£¡£¡£ËùÓÐ9¸öÎó²î¶¼±»·ÖÅÉÁËCVE±êʶ£¬£¬£¬£¬²¢ÇÒ±»FortiGuardÆÀΪÑÏÖØ¼¶±ðºÍ»ñµÃÁËCVSSÆÀ·Ö9.0·Ö¡£¡£¡£¡£¡£¡£¡£¡£Õâ9¸öÎó²îÖÐÓÐ8¸öÎó²îʹÓÃÁËÏàͬµÄ¼òÆÓ´úÂëģʽ¡£¡£¡£¡£¡£¡£¡£¡£¸÷²å¼þ¹©Ó¦É̶¼ÒѾ­Ðû²¼ÁËÐÞ¸´²¹¶¡ºÍ¸üС£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.fortinet.com/blog/threat-research/wordpress-plugin-sql-injection-vulnerability.html


5.Check PointÐÞ¸´Endpoint SecurityÖеÄÌáȨÎó²î


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Check PointÐÞ¸´ÆäEndpoint Security¿Í»§¶ËÈí¼þÖеÄÌáȨÎó²î£¬£¬£¬£¬¸ÃÎó²î£¨CVE-2019-8461£©ÔÊÐíDZÔڵĹ¥»÷ÕßÌáÉýÆäȨÏÞÖÁSYSTEM²¢Ö´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£¡£SafeBreach LabsÇå¾²Ñо¿Ô±Peleg Hadar·¢Ã÷Á˸ÃÎÊÌ⣬£¬£¬£¬¼´¿Éͨ¹ý½«í§ÒâδÊðÃûµÄDLL¼ÓÔØµ½Check Point Endpoint SecurityÈí¼þʹÓõÄWindowsЧÀÍÖ®Ò»À´ÊµÏÖȨÏÞÌáÉýºÍ³¤ÆÚÐÔ¡£¡£¡£¡£¡£¡£¡£¡£Check PointÔÚ8ÔÂ27ÈÕÐû²¼°æ±¾¸üÐÂÐÞ¸´ÁË´ËÎó²î¡£¡£¡£¡£¡£¡£¡£¡£ÕâÊÇHadarÔÚ8Ô·ÝÏòÇå¾²³§É̱¨¸æµÄµÚÈý¸öÍâµØÌáȨÎó²î£¬£¬£¬£¬Ç°Á½¸öÊÇÇ÷ÊÆ¿Æ¼¼¼°BitdefenderÖеÄÀàËÆÎó²î£¨CVE-2019-14684ºÍCVE-2019-15295£©¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/check-point-patches-privilege-escalation-flaw-in-endpoint-client/


6.ÃÀ¹úÊý°Ù¼ÒÑÀ¿ÆÕïËùÔâÀÕË÷Èí¼þSodinokibi¹¥»÷


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


8ÔÂ26ÈÕÃÀ¹úÊý°Ù¼ÒÑÀ¿ÆÕïËùÔâÀÕË÷Èí¼þSodinokibi¹¥»÷£¬£¬£¬£¬»¼ÕßÐÅÏ¢±»¼ÓÃÜ¡£¡£¡£¡£¡£¡£¡£¡£ÕâÊǹ¥»÷Õßͨ¹ýÈëÇÖÈí¼þ¹©Ó¦É̲¢Ê¹ÓÃÆä²úÆ·ÔÚ¿Í»§ÏµÍ³ÉÏÖ²ÈëÀÕË÷Èí¼þµÄÁíÒ»¸ö°¸Àý¡£¡£¡£¡£¡£¡£¡£¡£ÔÚ±¾ÆðÊÂÎñÖУ¬£¬£¬£¬Èí¼þ¹©Ó¦ÉÌÊÇThe Digital Dental RecordºÍPerCSoft£¬£¬£¬£¬ËûÃÇÏàÖú¿ª·¢ÁËÒ½ÁƼͼÉúÑĺͱ¸·ÝÈí¼þDDS Safe¡£¡£¡£¡£¡£¡£¡£¡£ÉÏÖÜÄ©ºÚ¿ÍÍÅ»ïÈëÇÖÁ˸ÃÈí¼þ±³ºóµÄ»ù´¡ÉèÊ©£¬£¬£¬£¬²¢Ê¹ÓÃËüÔÚÊý°Ù¸öÑÀÒ½ÕïËùµÄÅÌËã»úÉϰ²ÅÅÁËÀÕË÷Èí¼þSodinokibi¡£¡£¡£¡£¡£¡£¡£¡£ÕâÁ½¼Ò¹«Ë¾Ñ¡ÔñÖ§¸¶Êê½ð»ñÈ¡½âÃÜÆ÷£¬£¬£¬£¬µ«ÏÖÔÚ»Ö¸´½ø¶È»ºÂý£¬£¬£¬£¬Ò»Ð©ÑÀ¿ÆÕïËùÉù³Æ½âÃÜÆ÷Ҫô²»Æð×÷Ó㬣¬£¬£¬ÒªÃ´Ã»Óлָ´ËùÓÐÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/ransomware-hits-hundreds-of-dentist-offices-in-the-us/