FireEyeÈ·ÈÏÔâµ½APT¹¥»÷£¬£¬£¬£¬£¬£¬ÒÑÐû²¼ÉùÃ÷²¢¿ªÔ´Ïà¹Ø¹¤¾ß£»£»£»£»£»£»£»¸»Ê¿¿µÑ¬È¾DoppelPaymer£¬£¬£¬£¬£¬£¬±»ÀÕË÷3400ÍòÃÀÔª
Ðû²¼Ê±¼ä 2020-12-091.FireEyeÈ·ÈÏÔâµ½APT¹¥»÷£¬£¬£¬£¬£¬£¬ÒÑÐû²¼ÉùÃ÷²¢¿ªÔ´Ïà¹Ø¹¤¾ß

FireEye³ÆÆäÔâµ½ÁËÓɹú¼ÒÔÞÖúµÄ¸ß¶ÈÖØ´óµÄºÚ¿ÍµÄ¹¥»÷£¬£¬£¬£¬£¬£¬¹¥»÷Õßδ¾ÊÚȨ»á¼ûÆäRed Team¹¤¾ß¡£¡£¡£¡£¡£FireEyeÌåÏÖÕâÊÇÒ»´ÎÓµÓÐÒ»Á÷½ø¹¥ÄÜÁ¦µÄ¹ú¼ÒµÄ¹¥»÷£¬£¬£¬£¬£¬£¬ÓëÒÔÍùÊÂÎñ²î±ð£¬£¬£¬£¬£¬£¬´Ë´Î¹¥»÷רÃÅÕë¶ÔºÍ¹¥»÷FireEye¡£¡£¡£¡£¡£¾ÊӲ죬£¬£¬£¬£¬£¬¹¥»÷Õß»á¼ûÁËÓÃÓÚ²âÊÔ¿Í»§Çå¾²ÐÔµÄRed TeamÆÀ¹À¹¤¾ß£¬£¬£¬£¬£¬£¬µ«ÆäÖв¢Ã»ÓаüÀ¨0dayÎó²î¡£¡£¡£¡£¡£ÏÖÔÚCISAÉÐδÊÕµ½ÓйØÕâЩ¹¤¾ß±»¶ñÒâʹÓõı¨¸æ£¬£¬£¬£¬£¬£¬FireEye¿ª·¢ÁË300¶àÖֶԲߣ¬£¬£¬£¬£¬£¬ÒÔïÔÌ´ËÊÂÎñµÄDZÔÚÓ°Ïì¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.fireeye.com/blog/products-and-services/2020/12/fireeye-shares-details-of-recent-cyber-attack-actions-to-protect-community.html
2.PickPointÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬½üÈýǧ¸ö°ü¹ü´¢Îï¹ñ±»·¿ª

12ÔÂ4ÈÕÏÂÖçĪ˹¿ÆPickPointÔâµ½Á˹¥»÷£¬£¬£¬£¬£¬£¬2732¸ö°ü¹ü¼ÄÎï¹ñµÄÃű»Ç¿ÖÆ·¿ª¡£¡£¡£¡£¡£PickPointÊÇÍâµØ¿ìµÝЧÀ͹«Ë¾£¬£¬£¬£¬£¬£¬ÆäÔÚĪ˹¿ÆºÍÊ¥±ËµÃ±¤Î¬»¤×Å8000¶à¸ö°ü¹ü¹ñµÄÍøÂç¡£¡£¡£¡£¡£Ò»ÃûºÚ¿ÍʹÓÃÉÐδ±»·¢Ã÷µÄÎó²î£¬£¬£¬£¬£¬£¬Ç¿Ðз¿ªÁ˽üÈý·ÖÖ®Ò»µÄPickPoint´¢Îï¹ñµÄÃÅ£¬£¬£¬£¬£¬£¬µ¼ÖÂÉÏÍò¸ö°ü¹ü±»µÁ¡£¡£¡£¡£¡£´Ë´Î¹¥»÷µÄÔµ¹ÊÔÓÉÉÐδ±»²éÃ÷£¬£¬£¬£¬£¬£¬PickPointÌåÏÖÒÑ֪ͨÕþ¸®£¬£¬£¬£¬£¬£¬²¢ÕýÔÚÆð¾¢»Ö¸´ÆäÍøÂç¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/hacker-opens-2732-pickpoint-package-lockers-across-moscow/
3.½ðÁ¢µÄ×Ó¹«Ë¾ÔÚÁè¼Ý2000Íò²¿ÊÖ»úÖÐ×°ÖöñÒâÈí¼þ

½ðÁ¢£¨Gionee£©µÄ×Ó¹«Ë¾ÖÇÆÕ¿Æ¼¼ÔÚÁè¼Ý2000Íò²¿ÊÖ»úÖÐ×°ÖöñÒâÈí¼þ¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÊÇÔÚ2018Äê12ÔÂÖÁ2019Äê10ÔÂʱ´ú×°Öõ쬣¬£¬£¬£¬£¬¸Ã¹«Ë¾Ê¹ÓÃÁËÒ»¿îÃûΪStory Lock ScreenµÄαÔìµÄÓ¦ÓóÌÐòѬȾװ±¸£¬£¬£¬£¬£¬£¬ÒÔ±ãͨ¹ýÍÆËÍ¹ã¸æµÈ²»·¨ÊÖ¶Î׬Ǯ£¬£¬£¬£¬£¬£¬Ó°ÏìÁ˽ü2175Íǫ̀װ±¸¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾»¹Ê¹ÓÃÃûΪDark HorseµÄ³ÌÐòÔÚÊÜÓ°ÏìµÄ½ðÁ¢ÊÖ»úÉÏ×°Öú͸üжñÒâÈí¼þ£¬£¬£¬£¬£¬£¬²¢ÒÔ´Ë׬Ǯ¸ß´ï420ÍòÃÀÔª¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/gionee-implanted-malware-20-million-phones/
4.CiscoÇå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´Ó°ÏìCSMµÄ¶à¸öRCEÎó²î

CiscoÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´Ó°ÏìCisco Security Manager£¨CSM£©µÄ¶à¸öRCEÎó²î¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄÎó²î±»×·×ÙΪCVE-2020-27125 ºÍ CVE-2020-27130£¬£¬£¬£¬£¬£¬Î»ÓÚCSMµÄJava·´ÐòÁл¯¹¦Ð§ÖУ¬£¬£¬£¬£¬£¬ÊÇÓÉÊÜÓ°ÏìµÄÈí¼þ¶ÔÓû§ÌṩµÄÄÚÈݾÙÐв»Çå¾²µÄ·´ÐòÁл¯µ¼Öµġ£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý½«¶ñÒâµÄÐòÁл¯Java¹¤¾ß·¢Ë͸øÊÜÓ°ÏìµÄϵͳÉϵÄÌØ¶¨ÕìÌýÆ÷À´Ê¹ÓÃÕâЩÎó²î£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÀÖ³ÉʹÓúó¿ÉÔÚWindowsÖ÷»úÉÏÒÔNT AUTHORITY\SYSTEMµÄÌØÈ¨ÔÚ×°±¸ÉÏÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/112023/security/cisco-security-manager-flaws.html
5.PS Now WindowsÓ¦Óñ£´æí§Òâ´úÂëÖ´ÐÐÎó²î

Parsia Hakimian·¢Ã÷PlayStation Now£¨PS Now£©µÄWindowsÓ¦ÓóÌÐòÖб£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬¿É±»ÓÃÀ´Ö´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£Hakimian³Æ¹¥»÷Õß¿ÉÒÔͨ¹ýpsnowlauncher.exeÔÚ¶Ë¿Ú1235ÉÏÆô¶¯ÍâµØµÄWebSocketЧÀÍÆ÷£¬£¬£¬£¬£¬£¬ ²¢Ê¹ÓÃÆäÔÚÆô¶¯ºóÌìÉúµÄAGL ElectronÓ¦ÓÃÔÚPS NOWÓû§µÄÅÌËã»úÉÏÔËÐжñÒâ´úÂë¡£¡£¡£¡£¡£ÓÉÓÚAGL¼ÓÔØµÄJavaScript½«Äܹ»ÔÚ»úеÉÏÌìÉúÀú³Ì²¢²»¼ì²é¼ÓÔØµÄURL£¬£¬£¬£¬£¬£¬Õâ¿ÉÄܵ¼ÖÂí§Òâ´úÂëµÄÖ´ÐС£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/playstation-now-bugs-let-sites-run-malicious-code-on-windows-pcs/
6.¸»Ê¿¿µÑ¬È¾DoppelPaymer£¬£¬£¬£¬£¬£¬±»ÀÕË÷3400ÍòÃÀÔªÊê½ð

¸»Ê¿¿µÔÚÄ«Î÷¸çµÄ·Ö¹«Ë¾Óڸж÷½ÚµÄÖÜÄ©Ôâµ½ÁËDoppelPaymerÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬±»ÀÕË÷3400ÍòÃÀÔªÊê½ð¡£¡£¡£¡£¡£ÐÂÎÅȪԴ֤ʵ£¬£¬£¬£¬£¬£¬Î»ÓÚÄ«Î÷¸ç»ªÀ×˹³ÇµÄ¸»Ê¿¿µCTBG MXÓÚ11ÔÂ29ÈÕǰºóÔâµ½Á˹¥»÷£¬£¬£¬£¬£¬£¬¸Ã¹¤³§ÓÚ½¨ÓÚ2005Ä꣬£¬£¬£¬£¬£¬Ö÷ÒªÏòÄÏÃÀÖ޺ͱ±ÃÀÖÞµÄËùÓеØÇø×é×°ºÍÔËÊäµç×Ó×°±¸¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬¸Ã¹¥»÷Ô´ÓÚÄÚ²¿Ô±¹¤Ôâµ½´¹ÂÚÓʼþ¹¥»÷¡£¡£¡£¡£¡£DoppelPaymerÔÚÆäÐ¹Â¶ÍøÕ¾ÉÏÐû²¼Á˸»Ê¿¿µNAµÄͨÀýÓªÒµÎĵµºÍ±¨¸æ£¬£¬£¬£¬£¬£¬²¢ÀÕË÷1804.0955 BTC£¨Ô¼Îª34686000ÃÀÔª£©¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/foxconn-electronics-giant-hit-by-ransomware-34-million-ransom/


¾©¹«Íø°²±¸11010802024551ºÅ