AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2020.07.20-2020.07.26£©
2020-08-17
Ò»¡¢ Íþвͨ¸æ
΢Èí2020Äê8ÔÂÇå¾²¸üжà¸ö²úÆ·¸ßΣÎó²îͨ¸æ
¡¾Ðû²¼Ê±¼ä¡¿2020-08-13 10:30:00 GMT
¡¾¸ÅÊö¡¿
±±¾©Ê±¼ä2020Äê8ÔÂ12ÈÕ£¬Î¢ÈíÐû²¼8ÔÂÇå¾²¸üв¹¶¡£¬ÐÞ¸´ÁË120¸öÇå¾²ÎÊÌâ£¬Éæ¼°Micros oft Windows¡¢InternetExplorer¡¢MicrosoftSQL Server¡¢MicrosoftEdge¡¢ChakraCore¡¢.Net¿ò¼ÜµÈÆÕ±éʹÓõIJúÆ·£¬ÆäÖаüÀ¨Ô¶³Ì´úÂëÖ´ÐкÍȨÏÞÌáÉýµÈ¸ßΣÎó²îÀàÐÍ¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
Apache StrutsÎó²î´¦Öóͷ£ÊÖ²á
¡¾Ðû²¼Ê±¼ä¡¿2020-08-14 22:00:00 GMT
¡¾¸ÅÊö¡¿
2020Äê8Ô 13 ÈÕ£¬Struts ¹Ù·½Ðû²¼Ç徲ͨ¸æÐû²¼ÁË2¸öÇå¾²Îó²î£ºS2-059£¨CVE-2019-0230£©ÊÇÒ» ¸öDZÔÚµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬S2-060£¨CVE-2019-0233£©ÊÇÒ»¸ö¾Ü¾ø·þÎñÎó²î¡£S2-059£¨CVE-20 19-0230£©Ô´ÓÚApacheStruts¿ò¼ÜÔÚ±»Ç¿ÖÆÊ¹ÓÃʱ£¬»á¶ÔijЩ±êÇ©µÄÊôÐÔ¾ÙÐжþ´ÎÇóÖµ£¬Õâ¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¬µ±ÔÚStruts±êÇ©ÊôÐÔÖÐÇ¿ÖÆÊ¹ÓÃOGNL±í´ïʽ²¢¿É±»ÍⲿÊäÈëÐÞ¸Äʱ£¬ ¹¥»÷Õ߿ɽṹ¶ñÒâµÄOGNL±í´ïʽ´¥·¢Îó²î¡£S2-060£¨CVE-2019-0233£©Ô´ÓÚÔÚÉÏ´«Îļþʱ£¬¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹ÌرðµÄÇëÇóÔì³É»á¼ûȨÏ޵Ĺýʧ£¬´Ó¶øµ¼ÖºóÐø²Ù×÷ʧ°Ü²¢±¨´í£¬Ôì³É¾Ü¾ø·þÎñ¹¥»÷¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. Adobe 2020Äê8ÔÂÇå¾²¸üÐÂ
¡¾¸ÅÊö¡¿
ÍâµØÊ±¼ä2020Äê8ÔÂ11ÈÕ£¬Adobe¹Ù·½Ðû²¼ÁË8ÔÂÇå¾²¸üУ¬Ö÷ÒªÐÞ¸´ÁËAdobe Acrobat and ReaderºÍAdobe LightroomÖеĶà¸öÇå¾²ÎÊÌâ¡£
¡¾²Î¿¼Á´½Ó¡¿
http://blog.nsfocus.net/adobe-security-update-0812/
2. Struts2 S2-059,S2-060Îó²î
¡¾¸ÅÊö¡¿
±±¾©Ê±¼ä2020Äê8ÔÂ13ÈÕ£¬Struts¹Ù·½Ðû²¼ÐµÄÇ徲ͨ¸æ£¬Ðû²¼ÁË2¸öÇå¾²Îó²î£ºS2-059£¨CVE-2019-0230£©ÊÇÒ»¸öDZÔÚµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬S2-060£¨CVE-2019-0233£©ÊÇÒ»¸ö¾Ü¾ø·þÎñÎó²î¡£
¡¾²Î¿¼Á´½Ó¡¿
http://blog.nsfocus.net/struts-s2-0813/
3. DARKHOTELÖ®ÖÐÐÄ×é¼þƪ
¡¾¸ÅÊö¡¿
Darkhotel×éÖ¯¹¥»÷Á´ÖÐʹÓõÄ×¢ÈëºÍÖÐÐÄÏÂÔØ×é¼þ£¬Ä¿µÄÊÇΪÁË»ñµÃÏÂÒ»½×¶Î³ÌÐò¡£ÕâÀà×é¼þÀàÐÍ´Ó¿ÉÖ´ÐÐÎļþµ½¾ç±¾²»µÈ£¬Í¨³£°üÀ¨´ó×ÚÇéÐμì²â£¬ÒÔ¶Ô¿¹µ÷ÊÔÇéÐκÍɱÈí¡£Darkhotel»¹Ê¹ÓÃרÃŵÄÉý¼¶¹¤¾ß£¬ÓÃÓÚÉý¼¶¹¥»÷Á´×îºóµÄRATºÍÇÔÃÜ×é¼þ£¬ÕâÓë¹Å°åRAT×ÔÉí¼¯³É¸üй¦Ð§ÓÐËù²î±ð¡£±ðµÄ£¬Ê¹ÓÃѬȾÀàºÍÈö²¥À๤¾ßÒàÊÇDarkhotelµÄÒ»´óÌØÉ«£¬ÕâÖ±½ÓÑÓÉýÁ˸Ã×éÖ¯µÄ¹¥»÷¹æÄ£¡£
¡¾²Î¿¼Á´½Ó¡¿
http://blog.nsfocus.net/darkhotel-2-0813/
4. 20GBÓ¢ÌØ¶ûÄÚ²¿Îļþй¶
¡¾¸ÅÊö¡¿
2020Äê8ÔÂ7ÈÕ£¬ÈðÎ﮹¤³ÌʦTill KottmannÔÚÍÆÌØÉÏÐû²¼ÁËÓ¢ÌØ¶ûÄÚ²¿Îļþй¶µÄÏà¹ØÐÅÏ¢²¢½«¸ÃÆðÊÂÎñÃüÃûΪÉñÃØºþ£¨exconfidential Lake£©£¬ÏÖÔÚ¸ÃÍÆÌØÕ˺ÅÒѱ»¶³½á¡£¸Ã¹¤³ÌʦÉù³ÆÆäÓÚǰһÈÕÊÕµ½ÁËÒ»·âºÚ¿ÍµÄÄäÃûÓʼþ£¬²¢»ñÈ¡µ½Õâ·ÝйÃÜÎļþ¡£¾Ý³Æ×Üй¶Îļþ¾ÞϸԼΪ90GB£¬ÏÖÔÚÍøÂçÉÏÈö²¥µÄ×ÊÁÏΪµÚÒ»²¿·Ö£¨Intel exconfidential Lake drop 1£©16.9GBºÍµÚ¶þ²¿·Ö£¨Intel exconfidential Lake drop 1.5£©412MB£¬Ê£ÓàÎļþÓдý¸üС£
¡¾²Î¿¼Á´½Ó¡¿
http://blog.nsfocus.net/intel-20gb-data-breach-0811/
5. PowerFallÔ˶¯Ê¹ÓÃInternet ExplorerÎó²îºÍWindowsÎó²îÕë¶Ôº«¹ú
¡¾¸ÅÊö¡¿
Operation PowerFallÕ½ÕùÖй¥»÷ÕßʹÓÃÁ½¸ö0dayÎó²îÕë¶Ôº«¹ú¾ÙÐй¥»÷£¬ÕâÁ½¸öÎó²î»®·Ö£ºInternet ExplorerµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2020-1380)£¬¸ÃÎó²îÔÚJavaScriptÒýÇæÖй¥»÷ÕßÄܹ»Ô¶³ÌÖ´ÐÐí§Òâ´úÂ룻WindowsÌØÈ¨ÌáÉýÎó²î(CVE-2020-0986)£¬¸ÃÎó²îÔÚ²Ù×÷ϵͳ·þÎñÖб»¼ì²âµ½£¬¹¥»÷Õß¿ÉÒÔÌáÉýÌØÈ¨²¢Ö´ÐÐδ¾ÊÚȨµÄ²Ù×÷¡£´Ë´Î¹¥»÷Ô˶¯ÒÔWindows10µÄ×îа汾ΪĿµÄ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securelist.com/ie-and-windows-zero-day-operation-powerfall/97976/
6. ÀÕË÷Èí¼þDharmaÕë¶ÔÖÐСÆóÒµµÄ¹¥»÷Ô˶¯
¡¾¸ÅÊö¡¿
ÀÕË÷Èí¼þDharmaÓÚ2016ÄêÊ״α»·¢Ã÷£¬¾ßÓжà¸ö±äÖÖ£¬Æä±äÖÖÒѳÉΪÀÕË÷Èí¼þ¼´·þÎñRaaSÔËÓªµÄ»ù´¡£¬¸ÃÀÕË÷Èí¼þÌṩÉÌÌṩÊÖÒÕרҵ֪ʶºÍÖ§³Ö£¬²Ù×÷Ö§³ÖÀÕË÷Èí¼þ¹¥»÷µÄºó¶Ëϵͳ£¬ÍøÂç·¸·¨·Ö×ÓΪRaaSµÄʹÓø¶·Ñ£¬²¢Ê¹Óñê×¼¹¤¾ß°ü×ÔÐоÙÐÐÕë¶ÔÐԵĹ¥»÷¡£RDP¹¥»÷ÊÇÔ¼85£¥Dharma¹¥»÷ÀֳɵÄÒòÓÉ¡£½üÆÚ¹¥»÷ÕßʹÓÃDharmaÀÕË÷Èí¼þÕë¶ÔÖÐСÆóÒµÌᳫ¹¥»÷Ô˶¯¡£
¡¾²Î¿¼Á´½Ó¡¿
7. ÐÂÌØ¹¤×éÖ¯RedCurlÒÔÇÔÊØÐÅϢΪĿµÄ
¡¾¸ÅÊö¡¿
½üÆÚ·¢Ã÷Ò»¸öеĽ²¶íÓïµÄÌØ¹¤×éÖ¯RedCurl£¬Ä¿µÄÊÇÈ«Çò¹æÄ£ÇÔÈ¡¹«Ë¾ÉÌÒµÉñÃØºÍÔ±¹¤Ð¡ÎÒ˽¼ÒÐÅÏ¢£¬ÒÑ·¢Ã÷ÆäÕë¶Ô14¸öÄ¿µÄµÄ¹¥»÷Ô˶¯£¬×îÔç¿É×·Ëݵ½2018Ä꣬Êܺ¦ÈËÔÚ¸÷¸ö¹ú¼ÒºÍÐÐÒµÖи÷²»Ïàͬ£¬°üÀ¨À´×Ô¶íÂÞ˹¡¢ÎÚ¿ËÀ¼¡¢¼ÓÄô󡢵¹ú¡¢Å²ÍþºÍÓ¢¹úµÈ¹ú¼ÒµÄÐÞ½¨¹«Ë¾¡¢ÁãÊÛÉÌ¡¢ÂÃÐÐÉç¡¢°ü¹Ü¹«Ë¾¡¢ÒøÐС¢Ö´·¨ºÍ×Éѯ¹«Ë¾¡£RedCurl×éÖ¯ÔÚ¹¥»÷Ô˶¯Öв¢Î´Ê¹ÓÃÖØ´óµÄ¹¤¾ßºÍÊÖÒÕ£¬¶øÊÇÑÏÖØÒÀÀµÓÚÓã²æÊ½ÍøÂç´¹ÂÚ¾ÙÐгõʼ»á¼û¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.group-ib.com/resources/threat-research/red-curl.html
8. Operation DreamJob- Lazarus×éÖ¯Õë¶ÔÒÔÉ«Áйú·ÀÕþ¸®µÄÐж¯
¡¾¸ÅÊö¡¿
Operation DreamJobÔ˶¯ÔÚ2020Äê6Ôµ½8ÔÂʱ´úÒ»Ö±»îÔ¾£¬ÏÖÔÚÒÑÀֳɹ¥»÷ÒÔÉ«ÁÐÒÔÖÂÈ«ÇòÊýÊ®¼Ò¹«Ë¾ºÍ×éÖ¯£¬Ö÷ҪĿµÄÊǹú·À²¿¡¢Õþ¸®»ú¹¹ÒÔ¼°Ìض¨ÆóÒµÔ±¹¤£¬Ä¿µÄϵͳµÄѬȾºÍÉøÍ¸Í¨¹ýÉç»á¹¤³Ìѧ¾ÙÐУ¬ÆäÖаüÀ¨Õì̽¡¢½¨ÉèÐéÄâµÄLinkedInСÎÒ˽¼Ò×ÊÁÏ¡¢ÏòÄ¿µÄµÄСÎÒ˽¼ÒµØµã·¢Ë͵ç×ÓÓʼþÒÔ¼°Ö±½ÓÓëÄ¿µÄ¾ÙÐÐWhatsApp¶Ô»°Ôڵ绰£¬ËæºóÍøÂçÊܺ¦ÆóÒµ»ò×éÖ¯Ïà¹ØÔ˶¯ºÍ²ÆÎñ״̬µÄÇ鱨¡£Lazarus Group£¨ÓÖÃûHIDDEN COBRA¡¢Guardians of Peace¡¢ZINCºÍNICKEL ACADEMY£©ÊÇÒ»¸öÍþв×éÖ¯£¬¹éÊôÓÚ³¯ÏÊÕþ¸®£¬¸Ã×éÖ¯ÖÁÉÙ´Ó2009ÄêÒÔÀ´Ò»Ö±»îÔ¾¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.clearskysec.com/operation-dream-job/
9. ÒøÐÐľÂíMekotioÕë¶ÔÀ¶¡ÃÀÖÞÒøÐкͽðÈÚ»ú¹¹
¡¾¸ÅÊö¡¿
MekotioÊÇÒ»¸öÖÁÉÙ´Ó2015Äê×îÏÈ»îÔ¾µÄÒøÐÐľÂí£¬Ö÷ÒªÕë¶Ô°ÍÎ÷¡¢ÖÇÀû¡¢Ä«Î÷¸ç¡¢Î÷°àÑÀ¡¢ÃØÂ³ºÍÆÏÌÑÑÀ£¬¸ÃľÂí¼Ò×åµÄ×îбäÖÖÖÐ×îÏÔÖøµÄ¹¦Ð§ÊÇʹÓÃSQLÊý¾Ý¿â×÷ΪC&C·þÎñÆ÷¡£½üÆÚMekotioľÂíÔÚ¹¥»÷Ô˶¯ÖÐʹÓÃ×îй¦Ð§Õë¶ÔÀ¶¡ÃÀÖÞÒøÐÐºÍÆäËû½ðÈÚ»ú¹¹Ìᳫ¹¥»÷Ô˶¯£¬Í¨¹ýʹÓÃÔËÐмü»òÔÚÆô¶¯Îļþ¼ÐÖн¨ÉèLNKÎļþÀ´È·¼á³¤ÆÚÐÔ£¬ÏòÊܺ¦ÕßÏÔʾαÔìµÄµ¯³ö´°¿Ú¾ÙÐй¥»÷£¬À´ÓÕʹËûÃÇй¶Ãô¸ÐÐÅÏ¢£¬°üÀ¨·À»ðǽÉèÖá¢ÊÇ·ñ¾ßÓÐÖÎÀíÌØÈ¨¡¢×°ÖÃWindows²Ù×÷ϵͳµÄ°æ±¾¡¢ÒÑ×°Ö÷´¶ñÒâÈí¼þ½â¾ö¼Æ»®ÁбíµÈ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.welivesecurity.com/2020/08/13/mekotio-these-arent-the-security-updates-youre-looking-for/
10. BisonalºóÃÅÕë¶Ô¶«Å·µÄ½ðÈں;üÊÂ×éÖ¯
¡¾¸ÅÊö¡¿
CactusPete£¬Ò²±»³ÆÎªKarma PandaºÍTonto Team£¬ÊÇÒ»¸öÖÁÉÙ´Ó2013Äê»îÔ¾ÖÁ½ñµÄÍþв×éÖ¯£¬ºã¾ÃÄ¿µÄÕë¶ÔÑÇÖ޺Ͷ«Å·µÄ¾üÊ¡¢Íâ½»ºÍ»ù´¡ÉèÊ©¡£½üÆÚCactusPete×é֯ʹÓÃBisonalºóÃÅбäÖÖÃé×¼¶«Å·µÄ½ðÈں;üʲ¿·Ö£¬¸Ã×é֯ͨ¹ý´øÓжñÒ⸽¼þµÄÓã²æÊ½ÍøÂç´¹ÂÚÓʼþµÄ·½·¨À´×ª´ï¶ñÒâÈí¼þBisonal£¬¸Ã¶ñÒâÈí¼þÒÔ»ñÈ¡Êܺ¦ÕßµÄÃô¸ÐÊý¾ÝµÄ»á¼ûȨÏÞΪĿµÄ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securelist.com/cactuspete-apt-groups-updated-bisonal-backdoor/97962/
11. »ùÓھ籾µÄ¶ñÒâÈí¼þÕë¶ÔWindows²Ù×÷ϵͳÓû§
¡¾¸ÅÊö¡¿
½üÆÚÑо¿Ö°Ô±Í¨¹ýInternet Explorerä¯ÀÀÆ÷Îó²î¼ì²âµ½ÖØ´ó»ùÓھ籾µÄ¶ñÒâÈí¼þ£¬ÕâЩ¶ñÒâÈí¼þÕë¶ÔWindows²Ù×÷ϵͳÓû§£¬¶ñÒâ¾ç±¾Ê¹ÓÃÁËCVE-2019-0752Îó²î£¬ÆäÖÐÒ»¸öJScriptÔ¶³Ì»á¼ûľÂí¿ÉÒÔÈ·±£ÔÚÄ¿µÄϵͳÉϵij¤ÆÚÐÔ£¬È»ºóÅþÁ¬µ½Ô¶³Ì·þÎñÆ÷£¬¹¥»÷Õß¿ÉÒÔÔÚÄ¿µÄÅÌËãÉÏÖ´ÐÐí§ÒâÏÂÁÒѾÙÐÐÍêÈ«¿ØÖÆ£¬µÚ¶þ¸öAutoITÏÂÔØÆ÷ʹÓÃÍøÂçÅþÁ¬ºÍ¾ç±¾¹¦Ð§À´ÏÂÔØºÍÖ´ÐжñÒâÈí¼þ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://unit42.paloaltonetworks.com/script-based-malware/
12. ʹÓÃCOVID-19ΪÓÕ¶üµÄ´¹ÂÚ¹¥»÷Ô˶¯ÒÀÈ»»îÔ¾
¡¾¸ÅÊö¡¿
½üÆÚʹÓÃÐÂÐ͹Ú×´²¡¶¾COVID-19Ö÷Ìâ×÷ΪÓÕ¶üµÄ´¹ÂÚ¹¥»÷Ô˶¯ÒÀÈ»»îÔ¾£¬ÆäÖÐÓй¥»÷Õßͨ¹ýʹÓÃÖ÷ÌâΪ"Covid-19»ù½ð¾ÈÔ®½±"£¬»òÕßÀÄÓÃÍŽá¹úµÄ±ê¼ÇÀ´ÓÕµ¼Êܺ¦Õߣ»ÓеĹ¥»÷Ô˶¯ÒÔ±ÈÌØ±ÒÇÔȡΪĿµÄ£¬Í¨¹ý½«Êܺ¦ÕßÖ¸µ¼ÖÁ´¹ÂÚÒ³ÃæÒÔÇÔÈ¡±ÈÌØ±ÒÇ®°üÒÔ¼°ÕË»§Æ¾Ö¤£»ÉÐÓз¢Ã÷ÒÔ"ÓÉÓÚÐÂÐ͹Ú×´²¡¶¾µ¼ÖÂÑÓ³Ù¸¶¿î"ΪÖ÷Ì⣬ÓÕʹÊܺ¦Õß·¿ª¸½¼þ£¬È»ºó¶ñÒâÎļþ½«½âѹËõ²¢´ÓGoogleÔÆÅÌÏÂÔØÓÐÓøºÔØNetWire¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.fortinet.com/blog/threat-research/latest-covid-19-variants-from-the-ridiculous-to-the-malicious

AG¹«Ë¾ÔÆ







