AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2020.11.16-2020.11.22£©
2020-11-29
Ò»¡¢ Íþвͨ¸æ
Citrix SD-WANÇå¾²Îó²îÇ徲ͨ¸æ£¨CVE-2020-8271¡¢CVE-2020-8272¡¢CVE-2020-8273£©
¡¾Ðû²¼Ê±¼ä¡¿2020-11-18 12:00:00 GMT
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬Citrix SD-WANÐû²¼Ç徲ͨ¸æ³ÆÐÞ¸´ÁËSD-WANÖеÄ3¸öÇå¾²Îó²î:CVE-2020-8271,CVE-2020-8272,CVE-2020-8273¡£ÔÚ¿ÉÒÔ»á¼ûSD-WAN CenterÍøÂçµÄÇéÐÎÏ£¬Î´ÊÚȨµÄ¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²îÒÔrootȨÏÞÖ´ÐÐí§Òâ´úÂë¡£ÏÖÔÚÒÑÓÐÏà¹ØÎó²îµÄϸ½ÚÆÊÎöÄÚÈÝÓëCVE-2020-8271µÄPOC¡£
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. ±¨¸æ£ºCISAÈÏÕæÈËÆÚÍû°×¹¬¿ª³ýËû
¡¾¸ÅÊö¡¿
ÃÀ¹úµÚÒ»ÈκÍÏÖÈÎÍøÂçÇå¾²×ܼà¿ËÀï˹·¿ËÀײ¼Ë¹£¨Chris Krebs£©ÌåÏÖ£¬ÌØÀÊÆÕÕþ¸®¶ÔËû¶ÔÑ¡¾Ù³ÌÐòµÄ±£»¤¸ÐÓ¦ÄÕÅ¡£ÌØÀÊÆÕ×Üͳһֱ¼á³ÖÒÔΪ£¬Ö»¹Üȱ·¦Ö¤¾Ý£¬µ«Ñ¡¾Ùʱ´úÆÕ±é±¬·¢Ñ¡ÃñÚ²ÆÐÐΪ£¬²¢ÔÚÐí¶àÖÝÌáÆðËßËÏÒÔÖÊÒÉÑ¡¾ÙЧ¹û¡£Â·Í¸É籨µÀ˵£¬ÓÉÓÚ CISAÖ§³Ö¹«ÕýµÄÑ¡¾Ù³ÌÐò£¬Ô¤¼Æ°×¹¬½«ÒªÇó¿ËÀײ¼Ë¹¸æÍË¡£
¡¾²Î¿¼Á´½Ó¡¿
https://threatpost.com/report-cisa-chief-expects-white-house-to-fire-him/161185/
2. ´òÂëÆ½Ì¨±³ºó£¬Ñªº¹¹¤³§ÏµĴòÂ빤ÈË
¡¾¸ÅÊö¡¿
ÑéÖ¤Âë¾ÍÏñ»¥ÁªÍøÌìϵÄÊØÎÀ£¬×èµ²ºÚ²ú¶ñÒâ¹¥»÷£¬ÊØ»¤46ÒÚÍøÃñ°²Î££¬¿ÉÊÇÓÐÒ»Ì죬³ÇÄÚÍøÃñƹýÊØÎÀ£¬¿ªÁ˺óÃÅ£¬ºÚ²úÐÛʦӿÈë³ÇÄÚ£¬¸÷·ţ¹íÉßÉñ£¬ÖÖÖÖ¿ÓÃÉÓÕÆÍµ¡£´òÂëÆ½Ì¨£¬ÓÖ±»³Æ×÷CAPTCHA farms£¬Ö¸ÔÚ¾ÙÐÐÑéÖ¤ÂëÈË»ú²âÊÔʱ£¬½«¸ÃÇëÇó·¢Ë͵½´òÂëÆ½Ì¨£¬ÓÉÕæÊµµÄÈËÀ´Íê³É¡£´Ó¶øÍ¨¹ýÈËÈâÖÚ°üµÄÐÎʽ£¬×ÊÖúºÚ²úÍÅ»ïÈÆ¹ýÑéÖ¤Âë¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.freebuf.com/news/254659.html
3. ÑÇÂíÑ·ÆðËßInstagram£¬TikTokÓ°ÏìÕß
¡¾¸ÅÊö¡¿
¹º´ËÉÌÆ·£¬»ñÈ¡´ËÉÌÆ·”£ºÉ罻ýÌåÓ°ÏìÕßÊÇÑÇÂíÑ·Õýµ±µÄÊ®×Ö×¼Ïߣ¬ÓÃÓÚÐû´«ÑÇÂíÑ·µÄÒ»Ñùƽ³£ÉÌÆ·£¬²¢ÔÊÐí½«»ñµÃեȡµÄð³äÉÝ³ÞÆ·¡£ÔÚÑÇÂíÑ·ÌáÆðµÄËßËÏÖУ¬ InstagramºÍTikTokÉ罻ýÌåÓ°ÏìÕßKelly FitzpatrickºÍSabrina Kelly-KrejciÊÇ13Ãû±»¸æ £¬ËûÃÇÉù³ÆËûÃǼÓÈëÁËÒ»¸öÔÚÏßȦÌ×£¬ÏúÊÛð³äÉÝ³ÞÆ·¡£
¡¾²Î¿¼Á´½Ó¡¿
https://threatpost.com/amazon-sues-instagram-tiktok-knockoff-scam/161233/
4. ÍøÂç·¸·¨×ªÒƵ½ÔÆÖÐÒÔ¼ÓËÙÊý¾ÝÔÓÂÒ
¡¾¸ÅÊö¡¿
Ò»·Ý¹ØÓÚµØÏ¾¼ÃµÄ±¨¸æ·¢Ã÷£¬¶ñÒâÐÐΪÕßÕýÔÚÌṩ»ùÓÚÔÆµÄ´ó×ÚÇÔÈ¡Êý¾Ý£¬¿Éͨ¹ýÀû±ãµÄ¹¤¾ß¾ÙÐлá¼ûÒÔ¶ÔËùÌṩµÄÄÚÈݾÙÐÐÇÐÆ¬ºÍÇп顣
¡¾²Î¿¼Á´½Ó¡¿
https://threatpost.com/cybercrime-cloud-accelerate-attacks-data-glut/161243/
5. ÆÊÎöʦÖÒÑÔ£ºDDoS¹¥»÷¿ÉÄܼ¤Ôö
¡¾¸ÅÊö¡¿
ÂþÑÜʽ¾Ü¾ø·þÎñ¹¥»÷½ñÄêûÓÐÒýÆðÌ«¶à¹Ø×¢¡£¿ÉÊÇÆÊÎöÈËʿ˵£¬´ËÀ๥»÷¿ÉÄÜÔÚδÀ´¼¸¸öÔÂÄÚ¼¤Ôö£¬²¢ÇÒÓпÉÄÜÓëÀÕË÷Èí¼þºÍÆäËûÀàÐ͵ÄÍøÂçÍþвһÑùÔì³ÉÆÆËð¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.inforisktoday.com/analysts-warn-ddos-attacks-likely-to-surge-a-15365
6. ×ÝÈ»ÔÚΣ»úʱÆÚ£¬ÎÒÃÇÒ²±ØÐè±£»¤ÎÒÃǵÄÒþ˽
¡¾¸ÅÊö¡¿
ÔÚCOVID-19Ö®ºó£¬ïÔÌ×ÔÓÉ¿ÉÄÜÊÇÎÒÃÇΪÌá¸ßÇå¾²ÐÔËù±ØÐèÖ§¸¶µÄ¼ÛÇ®¡£Ëæ×Ÿ÷¹ú·Å¿íÕë¶Ô¹Ú×´²¡¶¾¶øÊ©¼ÓµÄËø¶¨ÏÞÖÆ£¬×ÔÓɵÄȨºâÈ¡Éá¿ÉÄÜÊÇÔöÌíÁËÃñÓÃÊý¾ÝµÄ¿É»á¼ûÐÔ¡£ÔÚÖÁÉÙ¶þÊ®Èý¸ö¹ú¼ÒÖУ¬ÊýÊ®¸ö“Êý×ÖÁªÏµÈ˸ú×Ù”Ó¦ÓóÌÐòÒѱ»ÏÂÔØÁè¼ÝÎåÍòÍò´Î¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.forbes.com/sites/nikitamalik/2020/11/16/we-must--protect-our-privacy-even-during-times-of-crisis/
7. ¹¥»÷ÕßÕë¶Ô“ Malmoke” Zloader¹¥»÷ÖеIJ»·¨ÍøÕ¾¹ÛÖÚ
¡¾¸ÅÊö¡¿
ÔÚÖÖÖÖ²»·¨ÍøÕ¾ÉÏ·¢Ã÷µÄÐéαJava¸üÐÂÏÖʵÉÏÏÂÔØÁËÖøÃûµÄZloader¶ñÒâÈí¼þ¡£ÍøÂç×ï·¸ÓÕÆ³ÉÈËÍøÕ¾»á¼ûÕߣ¬°üÀ¨bravoporn.comºÍxhamster.comµÈÍøÕ¾£¬¾ÙÐжñÒâ¹¥»÷£¬½«Êܺ¦ÕßÖØ¶¨Ïòµ½Ìṩ¶ñÒâÈí¼þµÄ¶ñÒâÍøÕ¾¡£
¡¾²Î¿¼Á´½Ó¡¿
https://threatpost.com/attackers-porn-malsmoke-zloader-attack/161277/
8. CapcomÀÕË÷Èí¼þ¹¥»÷£ºÓÎÏ·ÏêϸÐÅÏ¢×ß©£»Ã»ÓÐÖ§¸¶Êê½ð
¡¾¸ÅÊö¡¿
ÈÕ±¾×ÅÃûÊÓÆµÓÎÏ·¹«Ë¾CapcomÔÚÐÂΟåÖÐ֤ʵ£¬ËüÒѳÉΪ11Ô³õÀÕË÷Èí¼þ¹¥»÷µÄÊܺ¦Õß¡£ÏÓÒÉÊÇRagnar Locker GangÈÏÕæÁËÕâ´ÎÏ®»÷¡£ ¸Ã¹«Ë¾»¹È·ÈÏ£¬ÓÉÓÚ¹¥»÷Õß¿ÉÒÔ»á¼û9ÃûÏÖÈκÍǰ¹ÍÔ±µÄСÎÒ˽¼ÒÊý¾Ý£¬ÉñÃØÏúÊÛ±¨¸æÒÔ¼°Æä¿Í»§µÄ²ÆÎñÐÅÏ¢£¬Òò´ËÏÖÔÚ¿ÉÄÜÓÐ35Íò¸öСÎÒ˽¼ÒÐÅÏ¢Êܵ½Íþв¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.hackread.com/capcom-ransomware-attack-no-ransom-paid/
9. ÈüÃÅÌú¿Ë2021ÄêÍøÂçÇå¾²Õ¹Íû–Õ¹ÍûδÀ´
¡¾¸ÅÊö¡¿
ÓÐÒ»¸ö´ÊÐÎòÁË2020ÄêµÄÍþÐ²Ì¬ÊÆ¡£ËÈË´Ê£ºÀÕË÷Èí¼þ¡£¹ØÓÚÆóÒµ»ò×éÖ¯¶øÑÔ£¬Ã»Óиü´óµÄÍþв£¬»òÕß¹ØÓÚ2020ÄêµÄÍøÂç×ï·¸¶øÑÔ£¬ÈκοÉ׬ǮµÄ¶¼Ã»ÓС£ÕâÊÇÓÐÒ»¸ö¼òÆÓµÄÔµ¹ÊÔÓÉ¡£ÀÕË÷ÊÇÓÐÀû¿ÉͼµÄ¡£ÍøÂç·¸·¨·Ö×ÓÕýÔÚÆð¾¢Ê¹ÕâЩÀûÈó×î´ó»¯¡£¸Ã²©¿Í×ÅÑÛÓÚδÀ´ÒÔ¼°¶ÔδÀ´µÄÕ¹Íû¡£ÒÑÍùÔÚÕâЩչÍûÖÐʩչÁËÖ÷Òª×÷ÓÃÒ²¾Íȱ·¦ÎªÆæÁË¡£Ö»¹ÜÎÒÃDz¢·ÇËùÓеÄÕ¹Íû¶¼×¨ÃÅÕë¶ÔÀÕË÷Èí¼þ£¬µ«ËüÃǶ¼Êܵ½ÀÕË÷Èí¼þÇý¶¯ÍþÐ²Ì¬ÊÆµÄÆ«ÏòµÄÑÏÖØÓ°Ïì¡£
¡¾²Î¿¼Á´½Ó¡¿
https://symantec-enterprise-blogs.security.com/blogs/feature-stories/symantec-2021-cyber-security-predictions-looking-toward-future
10. Android¶ËFirefoxÒýÇæÖеÄÎó²îÆÊÎö
¡¾¸ÅÊö¡¿
ÕýºÃÇ¡·êа汾°²×¿¶Ë»ðºüä¯ÀÀÆ÷µÄÎÊÊÀ£¬GitLabsµÄÇå¾²ºì¶ÓÑо¿Ö°Ô±¿ËÀï˹·Äª²®Àû£¨Chris Moberly£©±¨¸æÁËÒÔϼ¸¸ö¾É°æ±¾ä¯ÀÀÆ÷Öб£´æµÄÇå¾²Îó²î¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.anquanke.com/post/id/222389
11. Æ»¹û±»ÆØÖØ´óϵͳÎó²î£ºrootȨÏÞÃë»ñÈ¡£¬Ð¿îMacBook¡¢iPhone 12Ò»Çв¨¼°£¡
¡¾¸ÅÊö¡¿
11ÔÂ18ÈÕÐÂÎÅ£¬Æ»¹û»»Ð¾ÁË£¬Çå¾²Îó²îÒ²À´ÁË¡£ÌÚѶÇå¾²ÐþÎäʵÑéÊÒ¶ÔÍâÐû²¼ÁËËûÃǽüÆÚ·¢Ã÷µÄÒ»¸öÆ»¹ûµÄÇå¾²Îó²î¡£¾ÝϤ£¬Õâ¸öÎó²î²»µ«Ó°Ïì×îеĻùÓÚM1оƬµÄ MacBook Air¡¢MacBook Pro£¬Ò²»áÓ°Ïì½ñÄêÐÂÍÆ³öµÄ iPhone 12¡¢iPhone 12 Pro ϵÁвúÆ·¡£Í¬Ê±ÕâÒ²ÊǵÚÒ»¸ö¹ûÕæµÄÄÜÓ°ÏìÆ»¹û Apple Silicon оƬװ±¸µÄÇå¾²Îó²î¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.freebuf.com/vuls/255362.html
12. ÎÒÃÇÉøÍ¸ÁËÒ»¸öIRC½©Ê¬ÍøÂç¡£ÕâÊÇÎÒÃÇ·¢Ã÷µÄ
¡¾¸ÅÊö¡¿
Cyber??News.comÊÓ²ìС×éÕë¶ÔIRC½©Ê¬ÍøÂç¾ÙÐÐÁËÉøÍ¸²Ù×÷£¬²¢½«Æä±¨¸æ¸øCERTÔ½ÄÏÒÔ×ÊÖú½«Æäɾ³ý¡£ÎªÁËÍøÂçÓйØIRC½©Ê¬ÍøÂçÔ˶¯µÄÓмÛÖµµÄÐÅÏ¢£¬ÎÒÃǼÓÈëÁËÆä“Ö¸»ÓÓë¿ØÖÆ”ÇþµÀ£¬ÔÚÄÇÀïÎÒÃÇÓöµ½ÁËÈÏÕæÔËÐÐÊÜѬȾϵͳµÄÕû¸öÍøÂçµÄbotmaster¡£ÎÒÃÇ»¹Ê¹ÓÃÕâ´ÎÉøÍ¸Ê±»úÀ´Ñ§Ï°botÖÎÀíÔ±µÄÄîÍ·ºÍIRC½©Ê¬ÍøÂçµÄ¿ÉÄÜÄ¿µÄ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securityaffairs.co/wordpress/111170/malware/irc-botnet-hack.html

AG¹«Ë¾ÔÆ







