Zoom macOS¿Í»§¶ËÁ½¸ö0day£»£»£»£»£»£»£»Î¢ÈíÖÒÑÔÕë¶ÔÒ½ÔºVPNºÍÍø¹Ø×°±¸µÄÀÕË÷Èí¼þ¹¥»÷

Ðû²¼Ê±¼ä 2020-04-03

1.΢ÈíÖÒÑÔÕë¶ÔÒ½ÔºVPNºÍÍø¹Ø×°±¸µÄÀÕË÷Èí¼þ¹¥»÷


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


΢ÈíÏòÊýÊ®¼ÒÒ½Ôº·¢ËÍÓйØÀÕË÷Èí¼þÕë¶ÔÐÔ¹¥»÷µÄÖÒÑÔ¡£ ¡£¡£¡£¡£Æ¾Ö¤Æä¶ÔÀÕË÷Èí¼þ¹¥»÷»î¶¯µÄ¸ú×Ù£¬£¬£¬£¬ £¬£¬£¬Î¢ÈíÊӲ쵽ÀÕË÷Èí¼þREvil£¨Sodinokibi£©Ö÷ÒªÕë¶ÔVPN×°±¸ºÍÍø¹Ø×°±¸ÖеÄÎó²î£¬£¬£¬£¬ £¬£¬£¬ÀýÈçPulse VPN×°±¸¡£ ¡£¡£¡£¡£Î¢Èí·¢Ã÷ÕâЩҽԺµÄ»ù´¡ÉèÊ©±£´æÒ×Êܹ¥»÷µÄÍø¹ØºÍVPN×°±¸£¬£¬£¬£¬ £¬£¬£¬ÆäÖÐÐí¶àÒ½Ôº³äÂú²¡»¼¡£ ¡£¡£¡£¡£Í¨¹ýÕâЩÕë¶ÔÐÔ¹¥»÷¾¯±¨£¬£¬£¬£¬ £¬£¬£¬Ò½ÁƱ£½¡×éÖ¯¿ÉÒÔÔÚÃæÏò¹«ÖÚµÄ×°±¸ÉÏ×Ô¶¯×°ÖÃÇå¾²¸üУ¬£¬£¬£¬ £¬£¬£¬ÒÔ×èÖ¹¹¥»÷ÕßµÄDZÔÚÍþв¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-is-alerting-hospitals-vulnerable-to-ransomware-attacks/


2.Magecart Group 7×îй¥»÷»î¶¯Ñ¬È¾19¸öÍøÕ¾


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


RiskIQÑо¿Ö°Ô±·¢Ã÷Ò»¸öеÄMagecart¹¥»÷»î¶¯£¬£¬£¬£¬ £¬£¬£¬¸Ã»î¶¯ÒѾ­Ñ¬È¾ÁË19¸ö²î±ðµÄµç×ÓÉÌÎñÍøÕ¾¡£ ¡£¡£¡£¡£¸ÃƲÔüÆ÷¾ç±¾Ê״α»·¢Ã÷ÓÚ1ÔÂ24ÈÕ£¬£¬£¬£¬ £¬£¬£¬ÓÉÓÚÆäʹÓÃÁËiframeÀ´ÍøÂçÓû§µÄÖ§¸¶Êý¾Ý£¬£¬£¬£¬ £¬£¬£¬Ñо¿Ö°Ô±½«ÆäÃüÃûΪMakeFrame¡£ ¡£¡£¡£¡£ÔÚijЩÇéÐÎÏ£¬£¬£¬£¬ £¬£¬£¬Ñо¿Ö°Ô±ÊӲ쵽MakeFrameµÄËùÓÐÈý¸ö¹¦Ð§¶¼Ê¹ÓÃÁËÊÜѬȾµÄÕ¾µã - ÍÐ¹ÜÆ²ÔüÆ÷´úÂë×Ô¼º¡¢½«Æ²ÔüÆ÷¼ÓÔØµ½ÆäËûÊÜѬȾµÄÍøÕ¾ÉÏÒÔ¼°ÇÔÈ¡Êý¾Ý¡£ ¡£¡£¡£¡£Í¨¹ý¶ÔÆä´úÂë¾ÙÐÐÆÊÎö£¬£¬£¬£¬ £¬£¬£¬Ñо¿Ö°Ô±½«¸Ã¶ñÒâ»î¶¯¹éÒòÓÚMagecart Group 7¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.riskiq.com/blog/labs/magecart-makeframe/


3.BitdefenderÅû¶Õë¶Ô°Ä´óÀûÑǵÄÌØ¹¤Èí¼þMandrake


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


BitdefenderÅû¶Õë¶Ô°Ä´óÀûÑÇAndroidÓû§µÄÌØ¹¤Èí¼þMandrake£¬£¬£¬£¬ £¬£¬£¬¸Ã¶ñÒâ»î¶¯ÖÁÉÙÒѾ­»îÔ¾ÁË4Äê¡£ ¡£¡£¡£¡£Mandrake¿ÉÕë¶ÔGoogle Chrome¡¢Gmail¡¢°Ä´óÀûÑǰÄÐÂÒøÐС¢°Ä´óÀûÑÇÁª°îÒøÐС¢Ä«¶û±¾ÒøÐС¢SAÒøÐС¢Australian SuperºÍPayPalÓ¦Óᣠ¡£¡£¡£¡£Í¨Ì«¹ýÎöÔÚÁ½¸öÔÂÄÚ²¶»ñµÄÊý¾Ý£¬£¬£¬£¬ £¬£¬£¬Ñо¿ÍŶӷ¢Ã÷ÁË500¸ö°Ä´óÀûÑÇÊܺ¦Õߣ¬£¬£¬£¬ £¬£¬£¬ÏÖʵÊý×Ö¿ÉÄܸü¸ß¡£ ¡£¡£¡£¡£MandrakeµÄµÚÒ»¸öÑù±¾¿É×·Ëݵ½2016Äê1ÔÂ31ÈÕ£¬£¬£¬£¬ £¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓøöñÒâÈí¼þ»á¼ûÊ×Ñ¡Ïî¡¢ÆÁÄ»¼Í¼¡¢×°±¸Ê¹ÓÃÇéÐκͲ»»î¶¯Ê±¼äµÈÐÅÏ¢£¬£¬£¬£¬ £¬£¬£¬»¹¿ÉÒÔµ÷µÍµç»°ÒôÁ¿²¢×èֹͨ»°»ò¶ÌÐÅ£¬£¬£¬£¬ £¬£¬£¬ÒÔ¼°¾ÙÐÐÆ¾Ö¤ÇÔÈ¡¡¢ÐÅϢй¶¡¢»ã¿îºÍÀÕË÷µÈ¶ñÒâ»î¶¯¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/bitdefender-reveals-mandrake-spyware-targeting-aussie-android-users/


4.ÐÂCOVID-19¶ñÒâÈí¼þ¿ÉÁýÕÖµçÄÔÖ÷Ö¸µ¼¼Í¼


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾



Ëæ×ÅCOVID-19ÔÚÈ«Çò¹æÄ£ÄÚËÁŰ£¬£¬£¬£¬ £¬£¬£¬Ò»Ð©¶ñÒâÈí¼þ×÷ÕßÒѾ­¿ª·¢³öÁËͨ¹ý²Á³ýÎļþ»òÁýÕÖMBRÀ´ÆÆËðϵͳµÄ¶ñÒâÈí¼þ¡£ ¡£¡£¡£¡£ÔÚÐÅÏ¢Çå¾²ÉçÇøµÄ×ÊÖúÏ£¬£¬£¬£¬ £¬£¬£¬ZDNetÒѾ­Ê¶±ð³öÖÁÉÙÎåÖÖ¶ñÒâÈí¼þ¾úÖ꣬£¬£¬£¬ £¬£¬£¬ÆäÖв¿·ÖÊÇÔÚÒ°Íâ·¢Ã÷µÄ£¬£¬£¬£¬ £¬£¬£¬ÁíһЩ¿ÉÄÜÖ»ÊÇΪÁ˲âÊÔ»òÍæÐ¦µÄÄ¿µÄ¡£ ¡£¡£¡£¡£MalwareHunterTeam·¢Ã÷Á˵ÚÒ»¸öMBRÖØÐ´Æ÷£¬£¬£¬£¬ £¬£¬£¬ÆäÃû³ÆÎªCOVID-19.exe£¬£¬£¬£¬ £¬£¬£¬SonicWallÔÚÒ»·Ý±¨¸æÖÐ¶ÔÆä¾ÙÐÐÁËÏêϸÏÈÈÝ¡£ ¡£¡£¡£¡£ÁíÒ»¸öÒÔ¹Ú×´²¡¶¾ÎªÖ÷ÌâµÄ¶ñÒâÈí¼þð³ä¡°CoronaVirusÀÕË÷Èí¼þ¡±£¬£¬£¬£¬ £¬£¬£¬µ«ËüµÄÖ÷Òª¹¦Ð§ÏÖʵÉÏÊÇ´ÓÊÜѬȾµÄÖ÷»úÇÔÈ¡ÃÜÂë¡£ ¡£¡£¡£¡£Çå¾²Ñо¿Ô±Karsten Hahn»¹·¢Ã÷Á˸öñÒâÈí¼þµÄÁíÒ»¸ö°æ±¾£¬£¬£¬£¬ £¬£¬£¬ËüÈÔÈ»¿ÉÒÔÁýÕÖMBR£¬£¬£¬£¬ £¬£¬£¬µ«Ê¹ÓÃÆÁÄ»Ëø¶¨³ÌÐòÈ¡´úÁËÊý¾Ý²Á³ý¹¦Ð§¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/theres-now-covid-19-malware-that-will-wipe-your-pc-and-rewrite-your-mbr/


5.Zoom macOS¿Í»§¶ËÁ½¸ö0day¿Éµ¼ÖÂÌáÉýȨÏÞ


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Ñо¿Ö°Ô±ÔÚZoomµÄmacOS¿Í»§¶ËÖз¢Ã÷Á½¸ö0day£¬£¬£¬£¬ £¬£¬£¬Îó²î¿ÉÄÜÔÊÐíÍâµØ¡¢ÎÞÌØÈ¨¹¥»÷Õß»ñµÃrootÌØÈ¨£¬£¬£¬£¬ £¬£¬£¬²¢ÔÊÐíËûÃÇ»á¼ûÊܺ¦ÕßµÄÂó¿Ë·çºÍÉãÏñÍ·¡£ ¡£¡£¡£¡£JamfÊ×ϯÇå¾²Ñо¿Ô±Patrick Wardle·¢Ã÷ÁËÕâÁ½¸öÎó²î£¬£¬£¬£¬ £¬£¬£¬µÚÒ»¸öÎó²îÔ´ÓÚZoom×°ÖóÌÐòʹÓÃAuthorizationExecuteWithPrivileges APIÔÚÎÞÓû§½»»¥µÄÇéÐÎϾÙÐÐ×°Ö㬣¬£¬£¬ £¬£¬£¬µ«¸ÃAPIÓÉÓÚûÓÐÑéÖ¤ÔÚ¸ùĿ¼ÏÂÖ´ÐеĶþ½øÖÆÎļþ£¬£¬£¬£¬ £¬£¬£¬ÏÖʵÉÏÒѾ­±»AppleÆúÓᣠ¡£¡£¡£¡£ÍâµØÎÞÌØÈ¨µÄ¹¥»÷Õß»ò¶ñÒâÈí¼þ¿ÉÄÜʹÓøÃÎó²îÌáȨÖÁroot¡£ ¡£¡£¡£¡£µÚ¶þ¸öÎó²îÓëZoomÔÊÐíµÚÈý·½¿â×¢Èë´úÂëÓйØ£¬£¬£¬£¬ £¬£¬£¬¹¥»÷Õ߿ɽ«¶ñÒâµÄµÚÈý·½¿â¼ÓÔØµ½ZoomµÄÀú³Ì/µØµã¿Õ¼äÖУ¬£¬£¬£¬ £¬£¬£¬´Ó¶ø×Ô¶¯¼ÌÐøËùÓÐZooms»á¼ûȨÏÞ²¢×îÖÕ»ñµÃÉãÏñÍ·ºÍÂó¿Ë·çµÄ¿ØÖÆÈ¨ÏÞ¡£ ¡£¡£¡£¡£×èÖ¹ÖÜËÄZoomÌåÏÖÒѾ­ÐÞ¸´ÁËÕâÁ½¸öÎó²î¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/two-zoom-zero-day-flaws-uncovered/154337/


6.OGUsersÂÛ̳Ôٴα»ÈëÇÖ£¬£¬£¬£¬ £¬£¬£¬Áè¼Ý20ÍòÓû§ÐÅϢй¶


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ºÚ¿ÍÂÛ̳OGUsersÔÚÒ»ÄêÄÚµÚ¶þ´ÎÔâµ½ºÚ¿ÍÈëÇÖ¡£ ¡£¡£¡£¡£ÂÛ̳ÖÎÀíÔ±AceÌåÏÖ£¬£¬£¬£¬ £¬£¬£¬¹¥»÷Õßͨ¹ýÉÏ´«ÖÁÂÛ̳ͷÏñÖеÄshellÈëÇÖÁËÂÛ̳ЧÀÍÆ÷£¬£¬£¬£¬ £¬£¬£¬²¢ÇÒÄܹ»»á¼û×èÖ¹2020Äê4ÔÂ2ÈÕµÄÊý¾Ý¿â¡£ ¡£¡£¡£¡£¾Ý³ÆÁè¼Ý20ÍòÓû§µÄÐÅÏ¢±»ÇÔ¡£ ¡£¡£¡£¡£ÔڹرոÃÍøÕ¾Ö®Ç°£¬£¬£¬£¬ £¬£¬£¬ÖÎÀíÔ±ÌåÏÖËûÃÇÒѾ­ÖØÉèÁËÃÜÂë²¢±Þ²ßÓû§¶ÔÆäÕË»§ÆôÓÃ2FAÈÏÖ¤¡£ ¡£¡£¡£¡£¸ÃÂÛÌ³ÔøÓÚ2019Äê5ÔÂÔâµ½ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬ £¬£¬£¬Æäʱ¹¥»÷ÕßÇÔÈ¡ÁË11.3ÍòÓû§µÄÐÅÏ¢²¢ÇÒ²Á³ýÁËÂÛ̳µÄÓ²ÅÌ¡£ ¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hacking-forum-gets-hacked-for-the-second-time-in-a-year/