WHO¡¢CDC¡¢NIH¼°¸Ç´Ä»ù½ð»áÔ¼2.5ÍòÓÊÏäÆ¾Ö¤Ð¹Â¶£»£»£»£»£»£»£»Ç徲ר¼Ò·¢Ã÷28¸ö·À²¡¶¾²úÆ·±£´æsymlink raceÎó²î

Ðû²¼Ê±¼ä 2020-04-28

1.ÍøÐŰìµÈ12¸ö²¿·ÖÁªºÏÐû²¼¡¶ÍøÂçÇå¾²Éó²é²½·¥¡·


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


4ÔÂ27ÈÕ12ʱ £¬£¬ £¬£¬£¬£¬£¬£¬¹ú¼Ò»¥ÁªÍøÐÅÏ¢°ì¹«ÊÒ¡¢¹ú¼Ò·¢¸ÄίµÈ12¸ö²¿·ÖÁªºÏÐû²¼ÁË¡¶ÍøÂçÇå¾²Éó²é²½·¥¡· £¬£¬ £¬£¬£¬£¬£¬£¬²¢ÍýÏëÓÚ6ÔÂ1ÈÕÕýʽʵÑé¡£¡£¡£¡£¡£¡£ ¡£Ðû²¼ÕâÒ»¡¶²½·¥¡·ÊÇΪÁ˼°Ôç·¢Ã÷²¢×èÖ¹²É¹º²úÆ·ºÍЧÀ͸øÒªº¦ÐÅÏ¢»ù´¡ÉèÊ©ÔËÐдøÀ´Î£º¦ºÍΣº¦ £¬£¬ £¬£¬£¬£¬£¬£¬°ü¹ÜÒªº¦ÐÅÏ¢»ù´¡ÉèÊ©¹©Ó¦Á´Çå¾² £¬£¬ £¬£¬£¬£¬£¬£¬Î¬»¤¹ú¼ÒÇå¾²¡£¡£¡£¡£¡£¡£ ¡£ÍøÂçÇå¾²Éó²éµÄÖØµãÊÇÆÀ¹ÀÒªº¦ÐÅÏ¢»ù´¡ÉèÊ©ÔËÓªÕ߲ɹºÍøÂç²úÆ·ºÍЧÀÍ¿ÉÄÜ´øÀ´µÄ¹ú¼ÒÇ徲Σº¦¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

http://www.cac.gov.cn/2020-04/27/c_1589535450769077.htm


2.ÔÚMicrosoft TeamsÖÐÉó²éGIF¿ÉÄܵ¼ÖÂÕÊ»§Ð®ÖÆ


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


CyberArkµÄÑо¿Ö°Ô±ÓÚ±¾ÖÜÒ»ÌåÏÖ £¬£¬ £¬£¬£¬£¬£¬£¬Microsoft Teams±£´æ×ÓÓòÃû½ÓÊÜÎó²î £¬£¬ £¬£¬£¬£¬£¬£¬¸ÃÎó²î¿ÉÓë¶ñÒâµÄ.GIFÎļþÁ¬ÏµÊ¹Óà £¬£¬ £¬£¬£¬£¬£¬£¬µÖ´ïÇÔÈ¡Óû§Êý¾Ý²¢Ð®ÖÆTeamsÕË»§µÄÄ¿µÄ¡£¡£¡£¡£¡£¡£ ¡£´ËÎó²îÓ°ÏìÁĘ̈ʽ»úºÍWeb°æ±¾µÄMicrosoft Teams¡£¡£¡£¡£¡£¡£ ¡£CyberArkÒѾ­Ðû²¼Á˸ÃÎó²îµÄ¿´·¨ÑéÖ¤´úÂ루PoC£© £¬£¬ £¬£¬£¬£¬£¬£¬ÑÝʾÔõÑùÌᳫ¹¥»÷¡£¡£¡£¡£¡£¡£ ¡£ÏÖÔÚ £¬£¬ £¬£¬£¬£¬£¬£¬MicrosoftÒ²ÒÑÐÞ¸´Á˸ÃÎó²î £¬£¬ £¬£¬£¬£¬£¬£¬²¢ÇÒÐû²¼ÁËÒ»¸ö²¹¶¡³ÌÐòÒÔ±ÜÃâδÀ´·ºÆðÀàËÆÎÊÌâ¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/this-is-how-viewing-a-gif-in-microsoft-teams-triggers-account-hijacking-bug/


3.ºÚ¿ÍαÔìNHS¹ÙÍøÀ´Èö²¥Êý¾ÝÇÔÈ¡¶ñÒâÈí¼þ


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ITÇå¾²¹«Ë¾¿¨°Í˹»ù£¨Kaspersky£©·¢Ã÷ºÚ¿ÍαÔìÁËÓ¢¹ú¹ú¼ÒÎÀÉú¾Ö£¨NHS£©¹ÙÍø £¬£¬ £¬£¬£¬£¬£¬£¬ÒÔÈö²¥Êý¾ÝÇÔÈ¡¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£ ¡£¸ÃÐéÎ±ÍøÕ¾ÖÐÓÐһЩαװ³É¿µ½¡Ïà¹Ø½¨ÒéµÄ¶ñÒâÁ´½Ó £¬£¬ £¬£¬£¬£¬£¬£¬Ò»µ©Óû§µã»÷Éó²é £¬£¬ £¬£¬£¬£¬£¬£¬±ã»áÏÂÔØÒ»¸öÃûΪCOVID19µÄÎļþ¡£¡£¡£¡£¡£¡£ ¡£¸ÃÎļþÏÖʵÉÏÊÇÒ»¸öÊý¾ÝÇÔÈ¡¶ñÒâÈí¼þ £¬£¬ £¬£¬£¬£¬£¬£¬»áÇÔÈ¡Óû§µÄÃÜÂë¡¢ÅÌËã»úÖеÄÎļþ¡¢ä¯ÀÀÆ÷ÖеÄCookieºÍ¸¶¿îÐÅÏ¢¡¢ÒÔ¼°±ÈÌØ±ÒÇ®°üÎļþ¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/hackers-setup-fake-nhs-website-spread-malware/


4.Zscaler·¢Ã÷COVID-19Ïà¹Ø´¹ÂÚ¹¥»÷ÔöÌíÁË300±¶


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ZscalerÑо¿Ö°Ô±ÔÚ3Ô·ݼì²âµ½ÁË38Íò´ÎÒÔCOVID-19ΪÖ÷ÌâµÄÍøÂç´¹ÂÚ¹¥»÷ £¬£¬ £¬£¬£¬£¬£¬£¬ÓëÄêÍ·£¨1200´Î£©Ïà±ÈÔöÌíÁË30000£¥¡£¡£¡£¡£¡£¡£ ¡£ÔÚÕâЩ¹¥»÷ÖÐ £¬£¬ £¬£¬£¬£¬£¬£¬Õë¶ÔÔ¶³ÌÆóÒµÓû§µÄ´¹ÂÚ¹¥»÷ÔöÌíÁË85£¥ £¬£¬ £¬£¬£¬£¬£¬£¬¶ñÒâÍøÕ¾ºÍ¶ñÒâÈí¼þµÄÊýÄ¿ÔöÌíÁË25£¥ £¬£¬ £¬£¬£¬£¬£¬£¬Õë¶ÔÆóÒµÓû§µÄ¹¥»÷ÔöÌíÁË17£¥¡£¡£¡£¡£¡£¡£ ¡£Ñо¿Ö°Ô±»¹¼ì²âµ½×ÔCOVID-19±¬·¢ÒÔÀ´ £¬£¬ £¬£¬£¬£¬£¬£¬×ܹ²ÓÐ13Íò¶à¸ö°üÀ¨ÓÐCOVID-19Òªº¦×Ö£¨ÀýÈç £¬£¬ £¬£¬£¬£¬£¬£¬²âÊÔ £¬£¬ £¬£¬£¬£¬£¬£¬¿ÚÕÖ £¬£¬ £¬£¬£¬£¬£¬£¬Î人 £¬£¬ £¬£¬£¬£¬£¬£¬ÊÔ¼ÁºÐµÈ£©µÄ¿ÉÒɵÄÐÂ×¢²áÓò£¨NRD£©¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/102244/hacking/coronavirus-themed-attacks-spike.html


5.ÊÓÆµÆ½Ì¨SeaChangeÔâÀÕË÷ÍÅ»ïSodinokibi¹¥»÷


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


4ÔÂ23ÈÕ £¬£¬ £¬£¬£¬£¬£¬£¬BadPackets±¨µÀµ½¿ç¹úÊÓÆµÆ½Ì¨SeaChangeÔâµ½ÀÕË÷Èí¼þÍÅ»ïSodinokibi¹¥»÷ £¬£¬ £¬£¬£¬£¬£¬£¬¿ÉÄܻᵼÖÂÊý¾Ýй¶ÎÊÌâ¡£¡£¡£¡£¡£¡£ ¡£BadPackets·¢Ã÷ £¬£¬ £¬£¬£¬£¬£¬£¬´Ó2019Äê4ÔÂ24ÈÕµ½2020Äê3ÔÂ24ÈÕ £¬£¬ £¬£¬£¬£¬£¬£¬SeaChangeµÄPulse Secure VPNЧÀÍÆ÷Ò»Ö±±£´æÎó²î£¨CVE-2019-11510£©¡£¡£¡£¡£¡£¡£ ¡£SodinokibiÍÅ»ïʹÓôËÎó²î͵ȡµÄÊý¾Ý°üÀ¨SeaChangeЧÀÍÆ÷ÖÐÎļþ¼Ð¡¢°ü¹ÜÖ¤Êé¡¢¼ÝʻִÕÕÒÔ¼°ÇóÖ°Ðŵȡ£¡£¡£¡£¡£¡£ ¡£ÏÖÔÚÉв»ÇåÎú¸ÃÍÅ»ïÏò¹«Ë¾Ë÷ÒªµÄÊê½ðÊý¶î £¬£¬ £¬£¬£¬£¬£¬£¬¿ÉÊǸÃÍÅ»ïÌåÏÖÖ»½ÓÊÜMonero¼ÓÃÜÇ®±Ò¶ø²»½ÓÊܱÈÌØ±Ò £¬£¬ £¬£¬£¬£¬£¬£¬ÓÉÓÚͨ¹ýTorÄäÃûÍøÂç¾ÙÐÐÉúÒâ¿ÉÒÔÔöÌí×ʽð×·×ÙµÄÄѶȡ£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/102177/cyber-crime/seachange-sodinokibi-ransomware.html


6.Å·ÃËÍøÕ¾GDPR.EU±£´æÎó²î £¬£¬ £¬£¬£¬£¬£¬£¬µ¼ÖÂÊý¾Ýй¶


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


¿ËÈÕ £¬£¬ £¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»¸ö¹ûÕæµÄ.gitÎļþ¼Ð £¬£¬ £¬£¬£¬£¬£¬£¬¸ÃÎļþ¼ÐÖаüÀ¨ÓÐGDPR.EUÍøÕ¾µÄÃÜÂëÒÔ¼°ÆäËûÏêϸÐÅÏ¢¡£¡£¡£¡£¡£¡£ ¡£GDPR.EU ÊÇÅ·ÃËΪʵÑ顶ͨÓÃÊý¾Ý±£»£»£»£»£»£»£»¤ÌõÀý¡·£¨GDPR£©µÄ×éÖ¯Ìṩ×ÉѯµÄÍøÕ¾ £¬£¬ £¬£¬£¬£¬£¬£¬ÓÉProton Technologies AGÔËÓª¡£¡£¡£¡£¡£¡£ ¡£Pen Test PartnersÑо¿Ö°Ô±ÌåÏÖ £¬£¬ £¬£¬£¬£¬£¬£¬´Ë´ÎÊý¾Ýй¶ÊÇÓÉÓÚÍøÕ¾ÉèÖÃÎÊÌâ £¬£¬ £¬£¬£¬£¬£¬£¬ÍøÕ¾¿ª·¢Ö°Ô±Ê¹ÓÃÁË¿ªÔ´µÄGit¿ª·¢¹¤¾ßÀ´´î½¨ÆäÒ³Ãæ £¬£¬ £¬£¬£¬£¬£¬£¬¿ÉÊÇûÓжÔ.gitÎļþ¼Ð¾ÙÐб£»£»£»£»£»£»£»¤ £¬£¬ £¬£¬£¬£¬£¬£¬µ¼Ö¸ÃÎļþÔÚÌìϹæÄ£ÄڵĹ«¹²ÍøÂçÉϿɶÁ¡£¡£¡£¡£¡£¡£ ¡£´Ë´Îй¶µÄÊý¾Ý°üÀ¨Ô´´úÂ롢ЧÀÍÆ÷»á¼ûÃÜÂë¡¢Êý¾Ý¿âÃÜÂë¡¢ÍйÜÎļþ¡¢¼ÓÃÜÑεȡ£¡£¡£¡£¡£¡£ ¡£¾ÝϤ £¬£¬ £¬£¬£¬£¬£¬£¬Proton Technologies¹«Ë¾ÒѾ­ÔÚ·¢Ã÷Îó²îµÄËÄÌìºóÐÞ¸´Á˸ÃÎó²î £¬£¬ £¬£¬£¬£¬£¬£¬²¢ÇÒɾ³ýÁËGitĿ¼ÒÔÌá¸ßÆäÇå¾²ÐÔ¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/data-leak-gdpr-advice-site/155199/