AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2020.12.14-2020.12.20£©
2020-12-21
Ò»¡¢ Íþвͨ¸æ
΢Èí12ÔÂÇå¾²¸üжà¸ö²úÆ·¸ßΣÎó²îͨ¸æ£¨CVE-2020-17095¡¢CVE-2020-17096¡¢CVE-2020-17121£©
¡¾Ðû²¼Ê±¼ä¡¿2020-12-16 10:00:00 GMT
¡¾¸ÅÊö¡¿
±±¾©Ê±¼ä 12 Ô 09 ÈÕ£¬Î¢ÈíÐû²¼ 12 ÔÂÇå¾²¸üв¹¶¡£¬ÐÞ¸´ÁË 59 ¸öÇå¾²ÎÊÌâ£¬Éæ¼° Microsoft Windows ¡¢ Microsoft Office¡¢Microsoft Exchange Server¡¢Visual Studio µÈÆÕ±éʹÓõIJúÆ·£¬ÆäÖаüÀ¨Ô¶³Ì´úÂëÖ´ÐкÍȨÏÞÌáÉýµÈ¸ßΣÎó²îÀàÐÍ¡£±¾ÔÂ΢ÈíÔ¶ȸüÐÂÐÞ¸´µÄÎó²îÖУ¬ÑÏÖØË®Æ½Îª¹Ø£¨Critical£©µÄÎó²îÓÐ 9 ¸ö£¬Ö÷Òª£¨Important£©Îó²îÓÐ 47 ¸ö£¬2 ¸ö ÖÐΣ£¨Moderate£©¼¶±ðÎó²î¡£ÇëÏà¹ØÓû§ÊµÊ±¸üв¹¶¡¾ÙÐзÀ»¤£¬ÏêϸÎó²îÁбíÇë²Î¿¼¸½Â¼¡£AG¹«Ë¾Ô¶³ÌÇå¾²ÆÀ¹Àϵͳ£¨RSAS£©ÒѾ߱¸Î¢Èí´Ë´Î²¹¶¡¸üÐÂÖдó´ó¶¼Îó²îµÄ¼ì²âÄÜÁ¦£¨°üÀ¨ CVE-2020-17095¡¢CVE-2020-17117¡¢CVE-2020-17118¡¢CVE-2020-17132¡¢CVE-2020-17142¡¢CVE-2020-17121¡¢CVE-2020-17131 µÈ¸ßΣÎó²î£©£¬ÇëÏà¹ØÓû§¹Ø×¢AG¹«Ë¾Ô¶³ÌÇå¾²ÆÀ¹Àϵͳϵͳ²å¼þÉý¼¶°üµÄ¸üУ¬ÊµÊ±Éý¼¶ÖÁ V6.0R02F01.2011£¬¹ÙÍøÁ´½Ó£ºhttp://update.nsfocus.com/update/listRsasDetail/v/vulsys
¡¾Á´½Ó¡¿
https://nti.nsfocus.com/threatWarning
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. ºÚ¿ÍÕÒµ½Èƹý¶àÒòËØÈÏÖ¤µÄÇÉÃîÒªÁì
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬APTºÚ¿Í×é֯ͨ¹ý“ÈÕ±¬¹¥»÷”£¨SUNBURST£©SolarWindsµÄÍøÂçÖÎÀíÈí¼þ£¬ÉøÍ¸µ½Á˰üÀ¨Îå½Ç´óÂ¥ºÍ°×¹¬ÔÚÄÚµÄ1.8Íò¼ÒÆóÒµºÍÕþ¸®»ú¹¹£¬ÔÚÍøÂçÇå¾²Òµ½çÏÆÆðÐùÈ»´ó²¨¡£¾ÝÍøÂçÇå¾²¹«Ë¾Volexity±¨µÀ£¬ÊµÑé“ÈÕ±¬¹¥»÷”µÄAPT×éÖ¯ÒѾÉè¼Æ³öÒ»ÖÖÇÉÃîµÄÒªÁ죬Äܹ»ÈƹýÄ¿µÄÍøÂçµÄ¶àÒòËØÉí·ÝÑé֤ϵͳ¡£
¡¾²Î¿¼Á´½Ó¡¿
http://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651095228&idx=2&sn=2c1b31a5a6b61025d54ce57a45694e53&chksm=bd14306f8a63b9796299b4774737ecb9f3fe0a456bc4a293fe9ccbb8832c04c2340c88afc8d4#rd
2. Lookout·¢Ã÷ÁËÐÔÇÖÕ¼ÕßÓÃÀ´ÀÕË÷iOSºÍAndroidÓû§µÄÐÂÌØ¹¤Èí¼þ
¡¾¸ÅÊö¡¿
LookoutÍþвÇ鱨ÍŶӷ¢Ã÷ÁËÒ»ÖÖÕë¶ÔÖÐÎĹú¼Ò£¬º«¹úºÍÈÕ±¾µÄiOSºÍAndroidÓû§µÄÐÂÐÍÒÆ¶¯Ó¦ÓóÌÐòÍþв¡£ÎÒÃǽ«ÆäÃüÃûΪGoontactµÄÌØ¹¤Èí¼þÕë¶Ôͨ³£Ìṩ»¤ËÍ·þÎñµÄ²»·¨Õ¾µãµÄÓû§£¬²¢´ÓÆäÒÆ¶¯×°±¸ÖÐÇÔȡСÎÒ˽¼ÒÐÅÏ¢¡£ÓÃÓÚ·Ö·¢ÕâЩ¶ñÒâÓ¦ÓóÌÐòµÄÍøÕ¾ÀàÐͺÍй¶µÄÐÅÏ¢Åú×¢£¬×îÖÕÄ¿µÄÊÇÀÕË÷»òÀÕË÷¡£
¡¾²Î¿¼Á´½Ó¡¿
https://blog.lookout.com/lookout-discovers-new-spyware-goontact-used-by-sextortionists-for-blackmail
3. ÍøÂçÇå¾²ÀͶ¯Á¦Ç·È±ïÔÌ
¡¾¸ÅÊö¡¿
ÃÀ¹ú·ÇÓªÀûÐÔлᣨISC£©²Ê×ϯִÐйÙClar RossoÌåÏÖ£¬ÊܹýÅàѵµÄÍøÂçÇå¾²ÊÂÇéÕßµÄǷȱÔÚ½ñÄêÒѾ´ó´óïÔÌ£¬ÕâÊÇΪÃÀ¹úÍøÂçÇ徲רҵְԱÌṩÅàѵµÄ·ÇÓªÀûÐÔлᣨISC£©²µÄÖ´Ðг¤¡£ÔÚ£¨ISC£©²2020ÍøÂçÇå¾²ÈËÁ¦Ñо¿Åú×¢£¬350ÍòСÎÒ˽¼ÒÏÖÔÚÈ«ÇòÔÚ¸ÃÁìÓòµÄÊÂÇ飬ͬ±ÈÔöÌí25£¥£¬ÓÉÈ¥Äê¡£¸ÃÑо¿»¹Åú×¢£¬È«ÇòÀͶ¯Á¦Ç·È±Õ÷ÏóÓÐËùïÔÌ£¬ÏÖÔÚÒÑ´ÓÈ¥Ä걨¸æµÄ407ÍòǷȱïÔ̵½ÁË312ÍòÈË-ÓÉÓÚËæ×ÅÀͶ¯Á¦µÄÔöÌí£¬¶ÔÇ徲רҵְԱµÄÐèÇóϽµÁË¡£¸ÃÑо¿Åú×¢£¬ÎªÁËÌî²¹È˲Åȱ¿Ú£¬ÏÖÔÚ¸ÃÁìÓòµÄ¾ÍÒµÐèÒªÔÚÃÀ¹úºÍÈ«Çò»®·ÖÔöÌíÔ¼41£¥ºÍ89£¥¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.inforisktoday.com/cybersecurity-workforce-shortage-diminishes-a-15611
4. SolarWinds¹©Ó¦Á´¹¥»÷ÊÂÎñÆÊÎö
¡¾¸ÅÊö¡¿
SolarWindsÊÇÒ»¼Ò¹ú¼ÊITÖÎÀíÈí¼þ¹©Ó¦ÉÌ£¬ÆäOrionÈí¼þ¸üзþÎñÆ÷Éϱ£´æÒ»¸ö±»Ñ¬È¾µÄ¸üгÌÐò£¬Õâµ¼ÖÂÃÀ¹ú¶à¼ÒÆóÒµ¼°Õþ¸®µ¥Î»ÍøÂçÊܵ½Ñ¬È¾£¬Æ¾Ö¤Èí¼þ×°»úÁ¿À´¿´£¬ÏÖÔÚ¸ÃÊÂÎñ¶Ôº£ÄÚÓ°Ïì½ÏС¡£´Ë´Î¹©Ó¦Á´¹¥»÷ÊÂÎñÒý·¢µÄ¹ØÁªÊÂÎñÊÇ12ÔÂ8ÈÕFireEyeÐû²¼±»ºÚ¿Í¹¥»÷ͨ¸æ£¬¿ÉÄÜй¶ÁËһϵÁÐÓÃÓÚÆÀ¹ÀµÄÍøÂçÇå¾²²âÊÔ¹¤¾ß¡£
¡¾²Î¿¼Á´½Ó¡¿
http://mp.weixin.qq.com/s?__biz=MjM5ODYyMTM4MA==&mid=2650408915&idx=2&sn=114723aaf5d74764acdb7b7c5feb140a&chksm=bec95e7889bed76e0e05f2c97c18f3a740ed49df18ec0b5818de34bf693f19b0472d0b827240#rd
5. “×ÝÉî·ÀÓù”ϵÄÒ½ÁÆ»ú¹¹µÈ±£ÏµÍ³½¨Éè
¡¾¸ÅÊö¡¿
½üÄêÀ´£¬Ëæ×ÅÍøÂçÓëÐÅÏ¢ÊÖÒյĸßËÙÉú³¤£¬Òƶ¯»¥ÁªÍø¡¢ÔÆÅÌËã¡¢´óÊý¾Ý¡¢È˹¤ÖÇÄܵÈÐÂÐÍ»ù´¡ÉèÊ©¡¢Ó¦ÓÃÒ»Ö±·ºÆð¡£ÎªÁ˸üºÃµØË³Ó¦Ê±´úÉú³¤£¬Ò½ÁÆ»ú¹¹Ó¦Æ¾Ö¤“Æ·¼¶±£»¤2.0±ê×¼”µÄÏà¹Ø±ê×¼ÒªÇ󣬿ªÕ¹Ïà¹ØÊÂÇ飬ΪºóÐøÍøÂçÇå¾²½¨ÉèÆðµ½Ê÷Ä£ºÍÖ¸µ¼×÷Óá£
¡¾²Î¿¼Á´½Ó¡¿
http://mp.weixin.qq.com/s?__biz=MjM5ODYyMTM4MA==&mid=2650408877&idx=2&sn=b3423bc5a7d702f9f02e8c83b23b1678&chksm=bec95e0689bed710d778a5bfeb701eba7348e6be52c277b434585883f098c5317b07f2598a72#rd
6. ÍøÉÏÆØ¹âµÄÊý°ÙÍò²¡È˵ÄҽѧɨÃè
¡¾¸ÅÊö¡¿
ÔÚÃæÏò»¥ÁªÍøµÄ²»Êܱ£»¤µÄ·þÎñÆ÷ÉÏ·¢Ã÷ÁËÁè¼Ý4500Íò·Ý°üÀ¨XÉäÏߺÍCTɨÃèÔÚÄÚµÄҽѧ³ÉÏñÎļþ£¬ÈκÎÈ˶¼¿ÉÒÔÉó²é¡£ CybelAngelµÄ Ñо¿Ð¡×é?¶Ô?ÍøÂ總¼Ó´æ´¢£¨NAS£©ºÍҽѧÊý×Ö³ÉÏñºÍͨѶ£¨DICOM£©¾ÙÐÐÁËΪÆÚÁù¸öÔµÄÊӲ죬Ч¹ûÊÇ´ÓÈ«Çò¸÷µØµÄÒ½ÔººÍÒ½ÁÆÖÐÐÄ·¢Ã÷×ß©µÄÊý¾Ý ¡£¸ÃÊӲ췢Ã÷Êý°ÙÍò´æ´¢Êý¾Ý°üÀ¨67¸ö¹ú¼Ò£¬ÆäÖÐÃÀ¹ú£¬Ó¢¹úÁè¼Ý2,140δÊܱ£»¤µÄ·þÎñÆ÷ÆæÒìµÄͼÏñºÍµÂ¹ú£¬ µÈµÈ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.welivesecurity.com/2020/12/15/medical-scans-exposed-online/
7. PyMICROPSIA:AridViperµÄÐÂÐÅÏ¢ÇÔȡľÂí
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±Ò»Ö±ÔÚ×·×ÙÍþв×éAridViper£¬¸Ã×éÖ¯Ò»Ö±Ãé×¼Öж«µØÇø¡£×÷ΪÕâÏîÑо¿µÄÒ»²¿·Ö£¬ÒѾȷ¶¨ÁËÒ»ÖÖеÄÓëMICROPSIA¶ñÒâÈí¼þ¼Ò×åÓйصÄÐÅÏ¢ÇÔȡľÂí£¬Åú×¢¸ÃÐÐΪÕß¼á³ÖÁ˷dz£»îÔ¾µÄÉú³¤¸Å¿ö£¬½¨ÉèÁËеÄÖ²ÈëÎÊÔÍ¼ÈÆ¹ýÆäÄ¿µÄµÄ·ÀÓù¡£ÎÒÃǽ«ÆäÃüÃûΪPyMICROPSIA£¬ÊÇÓÉÓÚËüÊÇʹÓÃPython¹¹½¨µÄ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://unit42.paloaltonetworks.com/pymicropsia/
8. 190ÍòÖйú¹²²úµ³Ô±µÄÏêϸ×ÊÁϱ»Ð¹Â¶
¡¾¸ÅÊö¡¿
ÔÚͨÀýµÄDark web¼àÊÓʱ´ú£¬CybleµÄר¼ÒÔÚÒ»¸ö¶íÓïÂÛ̳ÉÏÕÒµ½ÁËÒ»¸öÌû×Ó£¬ÆäÖÐÌṩÁË190ÍòÖйú¹²²úµ³Ô±µÄÏêϸÐÅÏ¢¡£293 MB CSVÎļþµÄ´ó×ÚÊý¾ÝÊÇÃâ·ÑÌṩµÄ¡£Ì»Â¶µÄ¼Í¼°üÀ¨ÐÕÃû£¬ÐÔ±ð£¬ÖÖ×壬×éÖ¯£¬¼ÒÏ磬ID£¬µØµã£¬ÊÖ»úºÅÂ룬µç»°ºÅÂ룬½ÌÓýˮƽ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securityaffairs.co/wordpress/112290/data-breach/chinese-communist-party-data-leak.html
9. Facebook½«OceanLotusºÚ¿ÍµÄÔ˶¯ÓëÔ½ÄϵÄIT¹«Ë¾ÁªÏµÆðÀ´
¡¾¸ÅÊö¡¿
FacebookÇå¾²Õþ²ßÖ÷¹ÜNathaniel GleicherºÍ¸Ã¹«Ë¾µÄÍøÂçÍþвÇ鱨˾ÀíMike DvilyanskiÖÜËÄÐû²¼£¬ËûÃÇÒѾÕë¶ÔÁ½¸ö²î±ðµÄºÚ¿ÍȺÌå½ÓÄÉÁËÐж¯¡£Ò»¸öС×éÉèÔÚÃϼÓÀ¹ú£¬ÁíÒ»¸öС×éÉèÔÚÔ½ÄÏ£¬µ«ÕâÁ½¸ö¶¼ÊÇÎÞÁªÏµµÄС×飬ËüÃÇʹÓöàÖÖÕ½ÂÔ½«FacebookºÍÍøÂçÆäËûµØ·½µÄÖ°Ô±×÷ΪĿµÄ¡£ ¸ÃÉç½»ÍøÂçÏÔʾ£¬ÕâЩ×éµÄFacebookÒ³ÃæºÍÕÊ»§Òѱ»É¾³ý£¬ÓйØÕâЩ×éµÄÐÅÏ¢½«ÓëÐÐÒµÏàÖúͬ°é¹²Ïí¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.hackread.com/facebook-links-oceanlotus-hackers-it-firm-vietnam/

AG¹«Ë¾ÔÆ







