AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨20200330~20200406£©
2020-04-07
Ò»¡¢Íþвͨ¸æ
- Linux KernelÐÅÏ¢×ß©&ȨÏÞÌáÉýÎó²î
¡¾Ðû²¼Ê±¼ä¡¿2020-03-31 21:00:00 GMT
¡¾¸ÅÊö¡¿3ÔÂ31ÈÕ£¬Manfred PaulÑ¡ÊÖÔÚPwn2Own½ÇÖðÉÏÓÃÓÚÑÝʾLinuxÄÚºËȨÏÞÌáÉýµÄÎó²î±»CVEÊÕ¼£¬Îó²î±àºÅΪCVE-2020-8835¡£´ËÎó²îÓÉÓÚbpfÑé֤ϵͳÔÚLinuxÄÚºËÖÐûÓÐ׼ȷÅÌËãijЩ²Ù×÷µÄ¼Ä´æÆ÷ÏÞÖÆ£¬µ¼ÖÂÍâµØ¹¥»÷Õß¿ÉÒÔʹÓôËȱÏÝÔ½½ç¶ÁÈ¡ÉñÃØÐÅÏ¢(ÄÚºËÄÚ´æ)»ò½«Óû§ÌáÉýΪÖÎÀíȨÏÞ¡£
http://blog.nsfocus.net/cve-2020-8835-0401/
- Vollgar½©Ê¬ÍøÂç
¡¾Ðû²¼Ê±¼ä¡¿2020-04-02 18:00:00 GMT
¡¾¸ÅÊö¡¿4ÔÂ1ÈÕ£¬Guardicore LabsÍŶÓÐû²¼ÁËÒ»·Ýºã¾Ã¹¥»÷Ô˶¯µÄÆÊÎö±¨¸æ£¬´Ë¹¥»÷Ô˶¯Ö÷ÒªÕë¶ÔÔËÐÐMS-SQL·þÎñµÄWindowsϵͳ¡£´Ë¹¥»÷Ô˶¯ÖÁÉÙ´Ó2018Äê5ÔÂ×îÏÈ£¬¹¥»÷Õß»áÕë¶ÔÄ¿µÄµÄMS-SQL¾ÙÐб©Á¦²Â½â£¬ÀֳɵǼĿµÄϵͳºó£¬ÔÙÔÚϵͳÖа²ÅźóÃŲ¢ÔËÐÐÔ¶¿Ø¹¤¾ßµÈ¶ñÒâ³ÌÐò¡£ÕâһϵÁеĹ¥»÷Ô˶¯±»ÃüÃûΪ“Vollgar”¡£
http://blog.nsfocus.net/vollgst-botnet-0402/
¶þ¡¢ÈÈÃÅ×ÊѶ
- ¾³ÍâºÚ¿ÍʹÓÃÉîÐÅ·þSSL VPN¾ÙÐй¥»÷
¡¾¸ÅÊö¡¿¾³ÍâºÚ¿Í×éÖ¯“DarkHotel”ͨ¹ý²»·¨ÊֶοØÖƲ¿·ÖÉîÐÅ·þSSL VPN×°±¸£¬²¢Ê¹Óÿͻ§¶ËÉý¼¶Îó²î£¨±¾´ÎÎó²îΪSSL VPN×°±¸Windows¿Í»§¶ËÉý¼¶Ä£¿éÊðÃûÑéÖ¤»úÖÆµÄȱÏÝ£©Ï·¢¶ñÒâÎļþµ½¿Í»§¶Ë£¬´Ó¶ø¾ÙÐÐAPT¹¥»÷Ô˶¯¡£AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄÒÑÖ§³Ö¶Ô¸ÃÊÂÎñµÄ¼ì²â¡£
https://mp.weixin.qq.com/s/FyZGfe2TLibru3CRgcjFiw
- ÐÂÐÍÀÕË÷Èí¼þWannaRen
¡¾¸ÅÊö¡¿¿ËÈÕ£¬ÍøÂçÉÏ·ºÆðÒ»ÖÖÐÂÐÍÀÕË÷²¡¶¾“WannaRen”²¢ÔÚPCÉÏ×îÏÈÈö²¥¡£¸ÃÀÕË÷Èí¼þ»á¼ÓÃÜWindowsϵͳÖÐÏÕЩÈκÎÎļþ£¬²¢ÇÒÒÔ“.WannaRen”ºó׺ÃüÃû¡£¹¥»÷ÕßÁôϱÈÌØ±ÒÇ®°ü²¢Ë÷È¡0.05±ÈÌØ±Ò¡£ÏÖÔÚ¸ÃÀÕË÷Èí¼þÓ°ÏìWindows 7ÓëWindows 10ϵͳ¡£
http://blog.nsfocus.net/wannaren-0407/
- ºÚ¿ÍʹÓÃnCoV-19ÒßÇéÐÅÏ¢ÔÚÎ÷°àÑÀͶ·ÅSmokeLoader
¡¾¸ÅÊö¡¿×Ôcovid-19·ÎÑײ¡¶¾ÔÚÌìϹæÄ£ÄÚ±¬·¢ÒÔÀ´£¬AG¹«Ë¾¿Æ¼¼·üӰʵÑéÊÒÇ×½ü¹Ø×¢¸ÃÊ±ÊÆ»°ÌâÔںڿ͹¤ÒµÁ´ÖеÄʹÓÃÇéÐΡ£½üÆÚ£¬·üӰʵÑéÊÒ·¢Ã÷ÁËеÄʹÓÃÒßÇé»°ÌâÈö²¥µÄÓʼþľÂí£¬Òþ²ØÔÚÆäÖеĹ¥»÷Á÷³ÌÏÔʾºÚ¿ÍÒѽ«Ïֽ׶εÄÖ÷Á÷¹¥»÷ÊÖ·¨ÓëÒßÇéÓÕ¶üÍŽáÆðÀ´£¬¸øÒßÇéÓÕ¶üÓʼþµÄ´ó¹æÄ£Èö²¥ÖÆÔìÁËÌõ¼þ¡£
http://blog.nsfocus.net/smokeloader-0407/
- VollgarÔ˶¯-Õë¶ÔÔËÐÐMS-SQL·þÎñµÄWindowsϵͳ
¡¾¸ÅÊö¡¿½üÆÚ·¢Ã÷Ò»¸öºã¾ÃÔËÐеĹ¥»÷Ô˶¯Vollgar£¬¸ÃÔ˶¯Ö¼ÔÚѬȾÔËÐÐMS-SQL·þÎñÆ÷µÄWindowsÅÌËã»ú£¬Ê¹ÓÃÃÜÂ뱩Á¦ÆÆ½âÊܺ¦ÕßÅÌËã»ú£¬°²ÅŶà¸öºóÃŲ¢Ö´Ðжà¸ö¶ñÒâÄ£¿é£¬Êܺ¦ÕßÂþÑÜÔÚÖйú¡¢Ó¡¶È¡¢º«¹ú¡¢ÍÁ¶úÆäºÍÃÀ¹úµÈ¹ú¼Ò£¬ÊÜÓ°ÏìµÄÐÐÒµº¸ÇÒ½ÁÆ¡¢º½¿Õ¡¢IT¡¢µçÐÅ¡¢½ÌÓýµÈ¶à¸öÁìÓò¡£
https://www.guardicore.com/2020/04/vollgar-ms-sql-servers-under-attack/
- ¹¥»÷ÕßʹÓÃZoomÊÓÆµ¾Û»áÓ¦ÓÃÈö²¥¶ñÒâÈí¼þ
¡¾¸ÅÊö¡¿½üÆÚ·¢Ã÷¹¥»÷Õß½«¶ñÒâÈí¼þαװ³ÉÕýµ±ZoomÊÓÆµ¾Û»áÈí¼þ£¬Ö÷ÒªÕë¶ÔÓÉÓÚ¹Ú×´²¡¶¾±¬·¢¶øÔÚ¼ÒÊÂÇéµÄÓû§¡£¶ñÒâ³ÌÐò²»µ«ÂþÑÜÔÚGoogle PlayÉÏ£¬»¹Õë¶ÔÔÚDroidsÉϼÓÔØÓ¦ÓóÌÐòµÄÓû§¡£ÆäÖл¹·¢Ã÷רÃÅÕë¶ÔÖйúÓû§µÄZoom APK£¬¸Ã¶ñÒâÈí¼þ»áÔÚÆô¶¯Ê±Ñ¯Îʵ绰¡¢Î»ÖúÍÕÕÆ¬È¨ÏÞ¡£
https://labs.bitdefender.com/2020/03/infected-zoom-apps-for-android-target-work-from-home-users/
- RaccoonÐÅÏ¢ÇÔÈ¡Æ÷ÀÄÓùȸèÔÆ·þÎñ
¡¾¸ÅÊö¡¿Raccoon¶ñÒâÈí¼þÓÚ2019Äê4ÔÂÊ״α»·¢Ã÷£¬¾ßÓÐÐÅÏ¢ÇÔÈ¡¹¦Ð§£¬Äܹ»ÇÔÈ¡µÇ¼ƾ֤¡¢ÐÅÓÿ¨ÐÅÏ¢¡¢¼ÓÃÜÇ®±ÒÇ®°üºÍä¯ÀÀÆ÷ÐÅÏ¢¡£½üÆÚ·¢Ã÷RaccoonʹÓÃÎó²îʹÓù¥»÷°üFalloutºÍRigµÄ¹¥»÷Ô˶¯£¬¹¥»÷ÕßÀÄÓùȸèÔÆ·þÎñʹRaccoon¹æ±Ü¼ì²â£¬ÊÜÓ°Ïì¹ú¼Ò°üÀ¨Ó¡¶È¡¢ÈÕ±¾¡¢¸çÂ×±ÈÑÇ¡¢¼ÓÄôóºÍÃÀ¹úµÈ¡£
https://blog.trendmicro.com/trendlabs-security-intelligence/raccoon-stealers-abuse-of-google-cloud-services-and-multiple-delivery-techniques/
- Holy water:Õë¶ÔÑÇÖÞµÄË®¿Ó¹¥»÷Ô˶¯
¡¾¸ÅÊö¡¿½üÆÚ·¢Ã÷Ò»¸öÕë¶ÔÑÇÖÞ×ڽ̻ú¹¹ºÍ×éÖ¯µÄË®¿Ó¹¥»÷Ô˶¯£¬¸ÃÔ˶¯ÖÁÉÙ×Ô2019Äê5ÔÂÒÔÀ´Ò»Ö±»îÔ¾£¬¹¥»÷ÕßʹÓÃÐéαAdobe Flash¸üÐÂÒÔ·Ö·¢¶ñÒâÈí¼þ¡£
https://securelist.com/holy-water-ongoing-targeted-water-holing-attack-in-asia/96311/

AG¹«Ë¾ÔÆ







