ÃÀ¹úÄÜÔ´²¿È·ÈÏSolarWindsÒÑÈëÇÖºËÎäÆ÷¾ÖµÄÍøÂ磻£»£»£»£»Avast½üÆÚ·¢Ã÷28¿î¶ñÒâµÄä¯ÀÀÆ÷²å¼þ£¬ £¬£¬£¬£¬£¬£¬Ó°Ïì300ÍòÓû§

Ðû²¼Ê±¼ä 2020-12-18
1.ÃÀ¹úÄÜÔ´²¿È·ÈÏSolarWindsÒÑÈëÇÖºËÎäÆ÷¾ÖµÄÍøÂç


1.png


ÃÀ¹úÄÜÔ´²¿ÒѾ­È·ÈÏ£¬ £¬£¬£¬£¬£¬£¬SolarWinds±³ºóµÄºÚ¿Í×éÖ¯ÈëÇÖÁËÃÀ¹úºËÎäÆ÷»ú¹¹NNSAµÄÍøÂç¡£ ¡£¡£¡£NNSAÊÇÒ»¸ö°ë×ÔÖÎÕþ¸®»ú¹¹£¬ £¬£¬£¬£¬£¬£¬ÈÏÕæÎ¬»¤ºÍÈ·±£ÃÀ¹úºËÎäÆ÷¿â´æ£¬ £¬£¬£¬£¬£¬£¬ÒÔ¼°Ó¦¶ÔÃÀ¹úº£ÄÚÍâµÄºËºÍ·ÅÉä½ôÆÈÇéÐΡ£ ¡£¡£¡£FBI¡¢CISAºÍODNIÐû²¼ÁªºÏÉùÃ÷³Æ£¬ £¬£¬£¬£¬£¬£¬ºÚ¿ÍÈëÇÖÁ˶à¸öÃÀ¹úÕþ¸®µÄÍøÂ磬 £¬£¬£¬£¬£¬£¬°üÀ¨ÃÀ¹ú²ÆÎñ²¿¡¢ÃÀ¹ú¹úÎñÔº¡¢ÃÀ¹úNTIA¡¢ÃÀ¹ú¹úÁ¢ÎÀÉúÑо¿Ôº¡¢DHS-CISAºÍÃÀ¹úÁìÍÁÇå¾²²¿¡£ ¡£¡£¡£ÏÖÔÚ£¬ £¬£¬£¬£¬£¬£¬Microsoft¡¢FireEyeºÍGoDaddyÒÑΪSolarWinds SunburstºóÃŽ¨ÉèÁËÒ»¸ökill switch£¬ £¬£¬£¬£¬£¬£¬ÒÔÖÕÖ¹Êܺ¦ÕßÍøÂçÉϵÄѬȾ¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/solarwinds-hackers-breach-us-nuclear-weapons-agency/


2.HPEÅû¶ÆäЧÀÍÆ÷ÖÎÀíÈí¼þÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î


2.png


»ÝÆÕÆóÒµ£¨HPE£©Åû¶ÆäWindowsºÍLinuxµÄHPE Systems Insight Manager£¨SIM£©Èí¼þÖб£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£ ¡£¡£¡£HPE SIMÊÇÕë¶Ô¶à¸öHPEЧÀÍÆ÷¡¢´æ´¢ºÍÍøÂç²úÆ·µÄÖÎÀíºÍÔ¶³ÌÖ§³Ö×Ô¶¯»¯½â¾ö¼Æ»®¡£ ¡£¡£¡£¸ÃÎó²î±»×·×ÙΪCVE-2020-7200£¬ £¬£¬£¬£¬£¬£¬ÑÏÖØÐÔÆÀ·ÖΪ9.8£¬ £¬£¬£¬£¬£¬£¬¸ÃÎó²îÊÇÓÉÓÚ¶ÔÓû§ÌṩµÄÊý¾Ýȱ·¦Êʵ±µÄÑéÖ¤µ¼Ö²»¿ÉÐÅÊý¾ÝµÄ·´ÐòÁл¯£¬ £¬£¬£¬£¬£¬£¬´Ó¶øÊ¹¹¥»÷ÕßÓпÉÄÜʹÓÃÕâЩÊý¾ÝÖ´ÐдúÂë¡£ ¡£¡£¡£ÏÖÔÚ¸ÃÎó²îÉÐÎÞÇå¾²¸üУ¬ £¬£¬£¬£¬£¬£¬¿ÉÊÇHPEÒÑÌṩWindows»º½âÒªÁì¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hpe-discloses-critical-zero-day-in-server-management-software/


3.Avast½üÆÚ·¢Ã÷28¿î¶ñÒâµÄä¯ÀÀÆ÷²å¼þ£¬ £¬£¬£¬£¬£¬£¬Ó°Ïì300ÍòÓû§


3.png


Çå¾²¹«Ë¾Avast½üÆÚ·¢Ã÷28¿î¶ñÒâµÄä¯ÀÀÆ÷²å¼þ£¬ £¬£¬£¬£¬£¬£¬°üÀ¨15¸öChromeÀ©Õ¹ºÍ13¸öEdgeÀ©Õ¹£¬ £¬£¬£¬£¬£¬£¬ÒÑÓ°Ïì300ÍòÓû§¡£ ¡£¡£¡£Õâ28¿î²å¼þ°üÀ¨´ó×ÚʵÏÖ¶ñÒâ²Ù×÷µÄ´úÂ룬 £¬£¬£¬£¬£¬£¬ÀýÈ罫Óû§Á÷Á¿Öض¨Ïòµ½¹ã¸æ¡¢½«Óû§Á÷Á¿Öض¨Ïòµ½ÍøÂç´¹ÂÚÕ¾µã¡¢ÍøÂçСÎÒ˽¼ÒÊý¾Ý¡¢ÍøÂçä¯ÀÀ¼Í¼¡¢½«¸ü¶à¶ñÒâÈí¼þÏÂÔØµ½Óû§×°±¸ÉÏ¡£ ¡£¡£¡£ÏÖÔÚ£¬ £¬£¬£¬£¬£¬£¬GoogleÒÑɾ³ýÁË15¸ö¶ñÒâÀ©Õ¹³ÌÐòÖеÄ3¸ö£¬ £¬£¬£¬£¬£¬£¬¶øMicrosoftÒòÎÞ·¨È·ÈÏAvastµÄ±¨¸æ¶øÉÐδ¾ÙÐÐɾ³ý¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/three-million-users-installed-28-malicious-chrome-or-edge-extensions/


4.ºÚ¿Í½«ÀÕË÷Èí¼þSystemBC×÷ΪTorÊðÀíºÍÔ¶³Ì¿ØÖƹ¤¾ß


4.png


ºÚ¿Í½«ÀÕË÷Èí¼þSystemBC×÷ΪTorÊðÀíºÍÔ¶³Ì¿ØÖƹ¤¾ß¡£ ¡£¡£¡£SystemBCÓÚ2019ÄêÊ״ηºÆð£¬ £¬£¬£¬£¬£¬£¬ÊÇÒ»ÖÖÊðÀíºÍÔ¶³ÌÖÎÀí¹¤¾ß¡£ ¡£¡£¡£Ëü¼È³äµ±ÒþʽͨѶµÄÍøÂçÊðÀí£¬ £¬£¬£¬£¬£¬£¬Óֳ䵱Զ³ÌÖÎÀí¹¤¾ß£¨RAT£©£¬ £¬£¬£¬£¬£¬£¬Äܹ»Ö´ÐÐWindowsÏÂÁî²¢½»¸¶ºÍÖ´Ðо籾¡¢¶ñÒâ¿ÉÖ´ÐÐÎļþºÍ¶¯Ì¬Á´½Ó¿â£¨DLL£©£¬ £¬£¬£¬£¬£¬£¬»¹¿ÉÒÔÌṩ³¤ÆÚµÄºóÃÅ¡£ ¡£¡£¡£SystemBCµÄ×îÐÂÑù±¾ÖаüÀ¨µÄ´úÂëûÓÐͨ¹ýSOCKS5ÊðÀí³äµ±ÐéÄâ˽ÓÐÍøÂ磬 £¬£¬£¬£¬£¬£¬¶øÊÇʹÓÃTorÄäÃûÍøÂç¼ÓÃܲ¢Òþ²ØÏÂÁîºÍ¿ØÖÆÁ÷Á¿µÄÄ¿µÄµØ¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://news.sophos.com/en-us/2020/12/16/systembc/


5.еÄRubyGems¶ñÒâÈí¼þ°üÕë¶Ô¼ÓÃÜÇ®±Ò¹©Ó¦Á´


5.png


Çå¾²¹«Ë¾Sonatype·¢Ã÷еÄRubyGems¶ñÒâÈí¼þ°üÕë¶Ô¼ÓÃÜÇ®±Ò¹©Ó¦Á´£¬ £¬£¬£¬£¬£¬£¬ÒÔÇÔÈ¡¼ÓÃÜÇ®±Ò¡£ ¡£¡£¡£Sonatype±¨¸æ³Æ£¬ £¬£¬£¬£¬£¬£¬Á½¸ö¶ñÒâÈí¼þ°üpretty_color-0.8.1.gemºÍ ruby-bitcoin-0.0.20.gem£¬ £¬£¬£¬£¬£¬£¬Î±×°³É±ÈÌØ±Ò¿âºÍÓÃÓÚÏÔʾ²î±ðÑÕɫЧ¹ûµÄ×Ö·û´®µÄ¿â£¬ £¬£¬£¬£¬£¬£¬×°ÖÃÁËÒ»¸ö¼ôÌù°åÇÔÈ¡¹¤¾ß¡£ ¡£¡£¡£ËüÃÇ¿ÉÒÔ¼àÊÓWindows¼ôÌù°åµÄ¼ÓÃÜÇ®±ÒµØµã£¬ £¬£¬£¬£¬£¬£¬ÈôÊǼì²âµ½¼ÓÃÜÇ®±ÒµØµã£¬ £¬£¬£¬£¬£¬£¬½«»á°ÑËüÌæ»»Îª¹¥»÷Õߵĵص㣬 £¬£¬£¬£¬£¬£¬ÒÔÇÔÈ¡¼ÓÃÜÇ®±Ò¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/malicious-rubygems-packages-used-in-cryptocurrency-supply-chain-attack/


6.FBI³ÆDoppelPaymerÓõ绰ÏÅ»£¾Ü¸¶Êê½ðµÄÊܺ¦Õß


6.png


FBI³ÆÀÕË÷Èí¼þÍÅ»ïDoppelPaymerÓôòµç»°µÄ·½·¨ÏÅ»£¾Ü¸¶Êê½ðµÄÊܺ¦Õß¡£ ¡£¡£¡£FBIÌåÏÖ£¬ £¬£¬£¬£¬£¬£¬ÕâЩÊÂÎñ×Ô2020Äê2ÔÂÒÔÀ´Ò»Ö±ÔÚ±¬·¢£¬ £¬£¬£¬£¬£¬£¬²¢ÇÒÆäËûËĸöÀÕË÷Èí¼þ×éÖ¯Sekhmet ¡¢ Maze ¡¢ContiºÍRyukÒ²ÊÇÓùýÀàËÆµÄÕ½ÂÔ¡£ ¡£¡£¡£±ðµÄ£¬ £¬£¬£¬£¬£¬£¬¸Ã»ú¹¹»¹Ïêϸ˵Ã÷ÎúÒ»¸öÌØ¶¨°¸Àý£¬ £¬£¬£¬£¬£¬£¬ÆäÖÐÍþв´ÓÊܹ¥»÷µÄ¹«Ë¾À©Õ¹µ½ÆäÔ±¹¤ÉõÖÁÊÇÇ×ÆÝ£¬ £¬£¬£¬£¬£¬£¬³ÆÒª°ÑһСÎÒ˽¼ÒË͵½Ò»ÃûÔ±¹¤µÄ¼ÒÀï¡£ ¡£¡£¡£µ«FBIÌåÏÖ£¬ £¬£¬£¬£¬£¬£¬ÔÚÕâÖÖÇéÐÎÏ£¬ £¬£¬£¬£¬£¬£¬±©Á¦Íþвͨ³£ÊÇÆÓªµÄ¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/fbi-says-doppelpaymer-ransomware-gang-is-harassing-victims-who-refuse-to-pay/