GoogleÐû²¼chromeÇå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´WebGLÖдúÂëÖ´ÐÐÎó²î£»£»£»£»£»£»£»LazarusʹÓÃLinkedInÕÐÆ¸¹ã¸æ¹¥»÷¼ÓÃÜÇ®±Ò¹«Ë¾

Ðû²¼Ê±¼ä 2020-08-26

1.GoogleÐû²¼chromeÇå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´WebGLÖдúÂëÖ´ÐÐÎó²î


1.jpg


GoogleÐû²¼chromeÇå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´ÆäWebGLÖдúÂëÖ´ÐÐÎó²î¡£¡£ ¡£¡£¸ÃÎó²îÓÉ˼¿ÆTalosµÄÑо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬£¬£¬ÆäλÓÚOpenGLºÍChromeä¯ÀÀÆ÷¼°ÆäËûÏîÄ¿ÔÚWindowsÉÏʹÓõÄDirect3DÖ®¼äµÄ¼æÈݲãANGLEÖУ¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÊʵ±µÄÄÚ´æ½á¹¹ºóʹÓøÃÎó²î£¬£¬£¬£¬£¬£¬ÔÚä¯ÀÀÆ÷ÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£ ¡£¡£¸ÃÎó²î±»×·×ÙΪCVE-2020-6492£¬£¬£¬£¬£¬£¬CVSSv3ÆÀ·ÖΪ8.3£¬£¬£¬£¬£¬£¬Ó°ÏìÁËGoogle Chrome 81.0.4044.138£¨Stable£©£¬£¬£¬£¬£¬£¬84.0.4136.5£¨Dev£©ºÍ84.0.4143.7£¨Canary£©£¬£¬£¬£¬£¬£¬ÏÖÔÚÒѱ»GoogleÐÞ¸´¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/google-chrome-85-fixes-webgl-code-execution-vulnerability/


2.ÒÁÀʺڿÍͨ¹ý¹¥»÷̻¶µÄRDPЧÀÍÆ÷À´×°ÖÃÀÕË÷Èí¼þDharma


2.jpg


ÒÁÀÊеĺڿÍ×é֯ͨ¹ý¹¥»÷̻¶µÄRDPЧÀÍÆ÷À´×°ÖÃÀÕË÷Èí¼þDharma£¬£¬£¬£¬£¬£¬Õë¶Ô¶íÂÞ˹¡¢Ó¡¶È¡¢ÖйúºÍÈÕ±¾¹«Ë¾¡£¡£ ¡£¡£ËûÃÇͨ¹ý¿ªÔ´¶Ë¿ÚɨÃèÆ÷MasscanɨÃèInternetÉϵÄIPµØµãÒÔ²éÕÒ̻¶µÄÔ¶³Ì×ÀÃæÅþÁ¬£¨RDP£©£¬£¬£¬£¬£¬£¬Ö¼ÔÚÕÒµ½ºÏÊʵÄÊܺ¦Õß¡£¡£ ¡£¡£Ö®ºó»áʹÓÃNLBruteÆô¶¯±©Á¦ÆÆ½â³ÌÐòÆÆ½âRDPÃÜÂë¡£¡£ ¡£¡£ÀֳɽøÈëºó£¬£¬£¬£¬£¬£¬ËûÃÇ»áʹÓÃWindows 7ÖÁ10ÖеľÉÎó²î£¨CVE-2017-0213£©¾ÙÐÐÌáȨ¡£¡£ ¡£¡£¸Ã×éÖ¯µÄÊê½ðÒªÇóÔÚ1-5±ÈÌØ±ÒÖ®¼ä£¨$ 11,700-$ 59,000£©£¬£¬£¬£¬£¬£¬ÓëÆäËûÀÕË÷Èí¼þ×éÖ¯Ïà±È½ð¶î½ÏС¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/iranian-hackers-attack-exposed-rdp-servers-to-deploy-dharma-ransomware/


3.LazarusʹÓÃLinkedInÕÐÆ¸¹ã¸æ¹¥»÷¼ÓÃÜÇ®±Ò¹«Ë¾


3.jpg


F-SecureµÄÍøÂçÇå¾²Ñо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬£¬£¬APT×éÖ¯LazarusʹÓÃLinkedInÕÐÆ¸¹ã¸æ¹¥»÷¼ÓÃÜÇ®±Ò¹«Ë¾¡£¡£ ¡£¡£Ôڴ˴ι¥»÷»î¶¯ÖУ¬£¬£¬£¬£¬£¬LazarusÏòÄ¿µÄ¹«Ë¾µÄϵͳÖÎÀíԱСÎÒ˽¼ÒLinkedInÕÊ»§Öз¢ËÍÕÐÆ¸¹ã¸æ£¬£¬£¬£¬£¬£¬ËµÃ÷Ò»¼ÒÇø¿éÁ´ÊÖÒÕ¹«Ë¾ÕýÔÚ×·ÇóеÄsysadmin¡£¡£ ¡£¡£¸Ã¹ã¸æ½«ÓÕʹÊܺ¦Õ߯ôÓú꣬£¬£¬£¬£¬£¬ÒÔ½¨ÉèÒ»¸ö.LNKÎļþ£¬£¬£¬£¬£¬£¬¸ÃÎļþÖ¼ÔÚÖ´ÐÐÒ»¸öÃûΪmshta.exeµÄÎļþ£¬£¬£¬£¬£¬£¬²¢Å²ÓÃÅþÁ¬µ½VBScriptµÄbit.lyÁ´½Ó£¬£¬£¬£¬£¬£¬²¢½«²Ù×÷ÐÅÏ¢·¢Ë͵½C2ЧÀÍÆ÷¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/lazarus-group-strikes-cryptocurrency-firm-through-linkedin-job-adverts/


4.ZoomЧÀÍÔÙ´ÎÖÐÖ¹£¬£¬£¬£¬£¬£¬Ö÷ÒªÓ°ÏìÃÀ¹ú¶«º£°¶ºÍÓ¢¹úµÄÓû§


4.jpg


ZoomЧÀÍÔÙ´ÎÖÐÖ¹£¬£¬£¬£¬£¬£¬Ö÷ÒªÓ°ÏìÃÀ¹ú¶«º£°¶ºÍÓ¢¹úµÄÓû§¡£¡£ ¡£¡£ZoomÌåÏÖÔÚ´Ë´ÎÖÐÖ¹ÖУ¬£¬£¬£¬£¬£¬Ðí¶àÓû§ÎÞ·¨»á¼ûZoomÍøÕ¾£¨zoom.us£©£¬£¬£¬£¬£¬£¬²¢ÎÞ·¨Æô¶¯ºÍ¼ÓÈëZoom Meetings¡£¡£ ¡£¡£×èÖ¹ÏÖÔÚ£¬£¬£¬£¬£¬£¬ZoomÒÑÈ·¶¨µ¼Ö´˴ιÊÕϵÄÔµ¹ÊÔ­ÓÉ£¬£¬£¬£¬£¬£¬²¢ÒѾÙÐÐÐÞ¸´¡£¡£ ¡£¡£Õâ²¢²»µÚÒ»´Î±¬·¢ÀàËÆ¹ÊÕÏ£¬£¬£¬£¬£¬£¬ÔçÔÚ4Ô£¬£¬£¬£¬£¬£¬ZoomÓû§ÌåÏÖËûÃÇÎÞ·¨Æô¶¯Web¿Í»§¶Ë²¢ÏÔʾ403 Forbidden¹ýʧ£¬£¬£¬£¬£¬£¬¶øÉÏÖÜÓû§Ò²·¢Ã÷ÎÞ·¨Í¨¹ýZoom Web¿Í»§¶ËºÍWebSDK¼ÓÈë¾Û»á¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/technology/zoom-went-down-and-schools-got-a-digital-snow-day/


5.¿¨°Í˹»ùÐû²¼ÓйØÍøÂçÌØ¹¤×éÖ¯DeathStalkerµÄÆÊÎö±¨¸æ


5.jpg


¿¨°Í˹»ù·¢Ã÷Ò»¸öרÃÅ´ÓÊÂÇÔÈ¡ÉÌÒµÉñÃØµÄÍøÂç·¸·¨×éÖ¯Ö¯DeathStalker£¬£¬£¬£¬£¬£¬²¢Ðû²¼Õë¶ÔÆäµÄÆÊÎö±¨¸æ¡£¡£ ¡£¡£¸Ã×éÖ¯×Ô2018Äê»ò¸üÔ磨¿ÉÄÜ×Ô2012Ä꣩¾Í×îÏÈ»îÔ¾£¬£¬£¬£¬£¬£¬Ö÷Òª¶Ô½ðÈڿƼ¼¹«Ë¾¡¢×´Ê¦ÊÂÎñËùºÍ²ÆÎñÕÕÁÏ¡£¡£ ¡£¡£DeathStalker²»»á°²ÅÅÀÕË÷Èí¼þ»òÇÔȡ֧¸¶Êý¾Ý£¬£¬£¬£¬£¬£¬Æä¹Ø×¢µÄÖØµãÊÇÃô¸ÐµÄÓªÒµÊý¾Ý£¬£¬£¬£¬£¬£¬ÕâÒâζ×ÅDeathStalke¿ÉÄÜÌṩÁËºÚ¿ÍÆ¸ÓÃЧÀÍ£¬£¬£¬£¬£¬£¬»òÕ߳䵱Á˽ðÈÚ½çµÄÐÅÏ¢¾­¼ÍÈË¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.kaspersky.com/blog/deathstalker-powersing/36815/


6.Ó¡¶ÈÂÃÓÎÍøÕ¾RailYatriÒòÊý¾Ý¿âÉèÖùýʧй¶3700ÍòÌõ¼Í¼


6.jpg


SafetyDetectives 8ÔÂ10ÈÕÔÚÍøÂçÉÏ·¢Ã÷ÁËRailYatriµÄûÓÐÃÜÂë±£»£»£»£»£»£»£»¤µÄElasticsearchЧÀÍÆ÷£¬£¬£¬£¬£¬£¬Ð¹Â¶3700ÍòÌõ¼Í¼¿Í»§ºÍ¹«Ë¾Êý¾Ý£¬£¬£¬£¬£¬£¬°üÀ¨Óû§µÄÈ«Ãû¡¢ÄêËê¡¢ÐÔ±ð¡¢ÏÖʵºÍµç×ÓÓʼþµØµã¡¢ÊÖ»úºÅÂë¡¢Ô¤¶©ÏêϸÐÅÏ¢¡¢GPSλÖÃÒÔ¼°ÐÕÃû/Ö§¸¶¿¨µÄǰËÄλºÍºóËÄλ¡£¡£ ¡£¡£¶øÔڸù«Ë¾¶ÔÆäÊý¾Ý¾ÙÐб£»£»£»£»£»£»£»¤Ö®Ç°£¬£¬£¬£¬£¬£¬Meow»úеÈËÓÚ8ÔÂ12ÈÕ¶ÔÆä±¬·¢¹¥»÷£¬£¬£¬£¬£¬£¬É¾³ýÁ˳ý1GBÖ®ÍâµÄËùÓÐÊý¾Ý£¨×ܹ²43 GB£©¡£¡£ ¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/travel-site-exposed-37m-records/