AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2020.06.1-2020.06.7£©
2020-06-08
Ò»¡¢ Íþвͨ¸æ
WebSphereÔ¶³Ì´úÂëÖ´ÐÐÎó²î
¡¾Ðû²¼Ê±¼ä¡¿2020-06-05 20:00:00 GMT
¡¾¸ÅÊö¡¿
±±¾©Ê±¼ä6ÔÂ5ÈÕ£¬IBM¹Ù·½Ðû²¼Í¨¸æÐÞ¸´ÁË WebSphereApplicationServer£¨WAS£©ÖеÄÔ¶³Ì´úÂëÖ´ÐУ¨CVE-2020-4450£©Îó²î£¬´ËÎó²îÓÉIIOPÐÒéÉϵķ´ÐòÁл¯Ôì³É£¬Î´¾Éí·ÝÈÏÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýIIOPÐÒéÔ¶³Ì¹¥»÷WAS·þÎñÆ÷£¬ÔÚÄ¿µÄ·þÎñ¶ËÖ´ÐÐí§Òâ´úÂ룬»ñȡϵͳȨÏÞ£¬½ø¶ø½ÓÊÜ·þÎñÆ÷¡£CVSSÆÀ·ÖΪ9.8·Ö£¬Îó²îΣº¦½Ï¸ß¡£
¡¾Á´½Ó¡¿
http://blog.nsfocus.net/websphere-cve-2020-4450-0605/
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. Windows SMBv3Ô¶³Ì´úÂëÖ´ÐÐÎó²î·À»¤¼Æ»®
¡¾¸ÅÊö¡¿
±±¾©Ê±¼ä3ÔÂ11ÈÕ£¬Î¢ÈíÐû²¼ÁË3ÔÂÇå¾²²¹¶¡¸üУ¬ÆäÖаüÀ¨Ò»ÌõÇ徲ͨ¸æ³ÆÆäÒѾÏàʶµ½ÔÚMicrosoft Server Message Block 3.1.1(SMBv3)Öб£´æÒ»¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬ÀÖ³ÉʹÓøÃÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚÄ¿µÄSMB·þÎñÆ÷»òSMB¿Í»§¶ËÉÏÖ´ÐдúÂë¡£¸ÃÎó²îÔ´ÓÚSMBv3ÐÒ鹨ÓÚÌØ¶¨ÇëÇóµÄ´¦Öóͷ£·½·¨±£´æ¹ýʧ£¬¹¥»÷Õß¿ÉÒÔÔÚδ¾Éí·ÝÑéÖ¤µÄÇéÐÎÏÂʹÓøÃÎó²î¡£ÈôÒªÕë¶ÔSMBv3·þÎñÆ÷£¬¹¥»÷Õß¿ÉÒÔ½«ÌØÖƵÄÊý¾Ý°ü·¢Ë͵½SMB·þÎñÆ÷À´´¥·¢¡£ÈôÒªÕë¶ÔSMBv3¿Í»§¶Ë£¬¹¥»÷ÕßÐèÒªÉèÖúÃÒ»¸ö¶ñÒâµÄSMB·þÎñÆ÷£¬²¢ÓÕʹÓû§ÅþÁ¬¸Ã·þÎñÆ÷¡£
¡¾²Î¿¼Á´½Ó¡¿
http://blog.nsfocus.net/poc-smbv3-0603/
2. ÓÃÓÑNCÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬º£ÄÚÇå¾²×éÖ¯Ðû²¼Á˹ØÓÚÓÃÓÑNCÔ¶³ÌÏÂÁîÖ´ÐÐÎó²îµÄͨ¸æ¡£¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹Ìض¨µÄHTTPÇëÇóÀ´´¥·¢·´ÐòÁл¯Îó²î£¬ÔÚÄ¿µÄ·þÎñÆ÷ÉÏÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£ÓÃÓÑNCÊÇÒ»¿îÆóÒµ¼¶ÖÎÀíÈí¼þ£¬ÔÚ´óÖÐÐÍÆóÒµÆÕ±éʹÓá£ÊµÏÖ½¨Ä£¡¢¿ª·¢¡¢¼ÌÐø¡¢ÔËÐС¢ÖÎÀíÒ»Ì廯µÄIT½â¾ö¼Æ»®ÐÅÏ¢»¯Æ½Ì¨¡£
¡¾²Î¿¼Á´½Ó¡¿
http://blog.nsfocus.net/yonyou-nc-0605/
3. ÄäÃûÕߺڿÍ×éÖ¯ÏòÃÀ¹ú¾¯¾Ö±¬·¢ÉùÃ÷
¡¾¸ÅÊö¡¿
Ò»¶Î¾Ý³ÆÀ´×ÔºÚ¿Í×éÖ¯“ÄäÃûÕß”µÄÊÓÆµÌåÏÖ£¬½«¶ÔÇÇÖη¸¥ÂåÒÁµÂ(George Floyd)ÔÚ±»²¶Ê±´úÔâ°×È˾¯Ô±“ѹ¾±”ºóéæÃüÕâÒ»ÊÂÎñ¾ÙÐÐÅê»÷¡£ÍâµØÊ±¼äÉÏÖÜÁùÍíЩʱ¼ä£¬Ã÷Äá°¢²¨Àû˹¾¯Ô±¾ÖÍøÕ¾ÓÐÔâµ½ºÚ¿Í¹¥»÷µÄ¼£Ïó¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.freebuf.com/news/238492.html
4. Cycldek×é֯ʹÓÃUSBCulprit¹¤¾ßÕë¶Ô¶«ÄÏÑǹú¼Ò
¡¾¸ÅÊö¡¿
½üÆÚCycldek×é֯ʹÓÃUSBCulrpitÕë¶Ô¶«ÄÏÑÇͨ¹ýÍøÂç´¹ÂÚÓʼþ¾ÙÐÐÈö²¥£¬USBCulrpit¶ñÒâÈí¼þÊÇCycldek¹¤¾ß¼¯ÖÐ×îÄÜ˵Ã÷Êý¾ÝÇÔÈ¡ºÍºáÏòÒÆ¶¯¹¦Ð§µÄʾÀýÖ®Ò»£¬ËüÄܹ»É¨ÃèÊܺ¦»úеÖеÄÖÖÖÖ·¾¶£¬ÍøÂç¾ßÓÐÌØ¶¨À©Õ¹ÃûµÄÎĵµ£¬¸´ÖÆ×ÔÉí²¢×ª´ï¸øUSBÇý¶¯Æ÷¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securelist.com/cycldek-bridging-the-air-gap/97157/
5. LinuxÍÚ¿óľÂíͨ¹ýKubernetes×é¼þÈëÇÖ
¡¾¸ÅÊö¡¿
KubernetesÊÇÒ»¸öÍêÕûµÄÂþÑÜʽϵͳ֧³Öƽ̨£¬¹¹½¨ÔÚdockerÖ®ÉÏ£¬ÌṩӦÓð²ÅÅ¡¢Î¬»¤¡¢À©Õ¹»úÖÆµÈ¹¦Ð§¡£½üÆÚ·¢Ã÷LinuxÍÚ¿óľÂíÒÉËÆÍ¨¹ýµÍ°æ±¾Kubernetes×é¼þÈëÇÖ£¬ÈëÇÖÀֳɺóÔÚ»úеÄÚÖ´ÐжñÒâsh¾ç±¾£¬¾ÙÐÐͬÀàľÂíÕûÀí£¬Í¬Ê±ÀÈ¡¿ó»ú¾ÙÐв»·¨ÍÚ¿ó¡£
¡¾²Î¿¼Á´½Ó¡¿
https://s.tencent.com/research/report/1003.html
6. Mustang Panda×é֯ʹÓÃDll-SideloadÊÖÒÕ¼ÓÔØPlugXľÂí
¡¾¸ÅÊö¡¿
Mustang Panda×é֯ʹÓÃDll-SideloadÊÖÒÕÓëÕýµ±µÄ¶þ½øÖÆÎļþ¾ÙÐÐÈö²¥£¬Í¨¹ýÒ»¸öºÜÊÇСµÄDLL£¬¼ÓÔØÒ»¸ö¼ÓÃܵÄÎļþ£¬ÔÚ±»½âÃܺó°üÀ¨Ò»¸ö²å¼þľÂíPlugX£¬¸Ã¶ñÒâÈí¼þ¿ÉÒÔÔ¶³ÌÖ´ÐжàÖÖÏÂÁÒÔ¼ìË÷ÅÌËã»úÐÅÏ¢¡¢²¶»ñÆÁÄ»¡¢ÖÎÀí·þÎñºÍÖÎÀíÀú³Ì¡£
¡¾²Î¿¼Á´½Ó¡¿
https://lab52.io/blog/mustang-panda-recent-activity-dll-sideloading-trojans-with-temporal-c2-servers/
7. Higaisa×éÖ¯·Ö·¢¼òÀúºÍ¿¼ÊÔµÈÖ÷ÌâµÄ´¹ÂÚÓʼþ
¡¾¸ÅÊö¡¿
HigaisaÊÇÒ»¸öÓ볯Ïʰ뵺ÓйصÄ×éÖ¯£¬ÆäÄ¿µÄ°üÀ¨Õþ¸®¹ÙÔ±ºÍÈËȨ×éÖ¯£¬ÒÔ¼°Ó볯ÏÊÓÐ¹ØµÄÆäËû×éÖ¯»ú¹¹¡£½üÆÚ£¬¹¥»÷ÕßʹÓÃαװ³É¼òÀúºÍ¹ú¼ÊÓ¢ÓïÓïÑÔ²âÊÔϵͳ¿¼ÊÔЧ¹ûµÄ¶ñÒâLNKÎļþ£¬Óë´æµµÎļþÀ¦°óÔÚÒ»Æð£¬Í¨¹ýÓã²æÊ½ÍøÂç´¹ÂÚÓʼþ¾ÙÐзַ¢¡£
¡¾²Î¿¼Á´½Ó¡¿
https://blog.malwarebytes.com/threat-analysis/2020/06/higaisa/
8. TycoonÀÕË÷Èí¼þÕë¶Ô½ÌÓýºÍÈí¼þÐÐÒµ
¡¾¸ÅÊö¡¿
TycoonÊÇÕë¶ÔWindowsϵͳºÍLinuxϵͳµÄ¶àƽ̨ÀÕË÷Èí¼þ£¬ÓÉJavaÓïÑÔд³É£¬¹¥»÷ÕßʹÓÃÒ»ÖÖ³ÆÎª“ ͼÏñÎļþÖ´ÐÐÑ¡Ïî”×¢ÈëµÄÊÖÒÕÔÚÊܺ¦ÕߵĻúеÉÏʵÏÖ³¤ÆÚÐÔ£¬²¢ÇÒʹÓ÷ǶԳÆRSAËã·¨¶ÔÇå¾²ÌìÉúµÄAESÃÜÔ¿¾ÙÐмÓÃÜ¡£¸Ã¶ñÒâÈí¼þÕë¶Ô½ÌÓýºÍÈí¼þÐÐÒµ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://blogs.blackberry.com/en/2020/06/threat-spotlight-tycoon-ransomware-targets-education-and-software-sectors
9. MetamorfoÒøÐÐľÂíÐ®ÖÆÊÜÐÅÍеÄÓ¦ÓóÌÐòÒÔÔËÐжñÒâÈí¼þ
¡¾¸ÅÊö¡¿
MetamorfoÊÇÒ»¸öÒøÐÐľÂíÈí¼þ£¬Ö÷ÒªÕë¶Ô°ÍÎ÷ͨ¹ýÀ¬»øÓʼþ¸½¼þÖÐ×°ÓкêµÄOfficeÎļþ¾ÙÐзַ¢£¬ÆäÖ÷Òª¹¦Ð§ÊÇÇÔÈ¡Óû§µÄÒøÐÐÐÅÏ¢ºÍÆäËûСÎÒ˽¼ÒÊý¾Ý²¢½«ÆäÀ©É¢µ½C2·þÎñÆ÷¡£MetamorfoÄ¿½ñʹÓÃÒ»ÖÖ³ÆÎªDLLÐ®ÖÆµÄÊÖÒÕÀ´Òþ²ØÔÚϵͳÖУ¬²¢ÔöÌíÁËÔÚÄ¿µÄÅÌËã»úÉϵÄȨÏÞ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securityboulevard.com/2020/06/banking-trojan-metamorfo-hijacks-trusted-apps-to-run-malware/

AG¹«Ë¾ÔÆ







