AG¹«Ë¾¿Æ¼¼ÍþвÇ鱨Öܱ¨£¨2020.12.21-2020.12.27£©
2020-12-28
Ò»¡¢ ÈÈÃÅ×ÊѶ
1. FireEyeÔâAPT¹¥»÷
¡¾¸ÅÊö¡¿
È«ÇòÁìÏȵÄAPT·ÀÓùÆóÒµFireEye͸¶ÆäϵͳÔâµ½APT¹¥»÷¡£×÷Ϊ×îÔçÌá³öAPT-1±¨¸æµÄÇå¾²³§ÉÌ£¬FireEye¶à´Îͨ¹ý±¨¸æµÄÐÎʽ£¬Õë¶ÔµØÇøÍøÂçÉú³¤¡¢¹ú¼ÒÍøÂçÕ½ÂÔ¡¢ÐÂÐÍAPT×éÖ¯µÈ·¢Éù¡£¸Ã¹«Ë¾ÌåÏÖ£¬ºÚ¿ÍʹÓÓÐÂÓ±ÊÖÒÕ”ÇÔÈ¡ÁËÉøÍ¸²âÊÔ¹¤¾ß°ü£¬¶øÕâ¿ÉÄÜ»áÔÚÈ«Çò¹æÄ£ÄÚÒý·¢ÐµĹ¥»÷¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.aqniu.com/vendor/71881.html
2. ±±Ô¼ÕýÔÚ¼ì²éÆäϵͳ£¬ÒÔÈ·¶¨SolarWindsºÚ¿Í¹¥»÷µÄÓ°ÏìÖÒÑÔDoppelPaymerÀÕË÷Èí¼þ¹¥»÷¼¤Ôö
¡¾¸ÅÊö¡¿
±±Ô¼Ðû²¼£¬ÔÚSolarWinds¹©Ó¦Á´¹¥»÷ºóÕýÔÚ¼ì²éÆäϵͳ£¬ÒÔÈ·¶¨ËüÃÇÊÇ·ñѬȾÁ˺óÃÅ¡£±±Ô¼ÊÇSolarWindsµÄ¿Í»§Ö®Ò»£¬µ«±±Ô¼×¨¼ÒÁ¬Ã¦Õö¿ªÁ˶Ըù¥»÷µÄÊӲ죬ÒÔÈ·¶¨¶ÔÆä»ù´¡ÉèÊ©µÄDZÔÚÓ°Ïì¡£SolarWindsÈ·ÈÏ£¬´Ë´ÎÏ®»÷Ó°ÏìÁ˰üÀ¨Õþ¸®»ú¹¹ºÍ²Æ²ú500Ç¿¹«Ë¾ÔÚÄڵĶà´ï 18,000¸ö¿Í»§¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securityaffairs.co/wordpress/112464/security/nato-solarwinds-hack.html
3. ÊýÒÔ°ÙÍò¼ÆµÄ×°±¸¿ÉÄܻᱻºÚ¿ÍʹÓôÓFireEye͵À´µÄ¹¤¾ßµÄȱÏݾÙÐй¥»÷
¡¾¸ÅÊö¡¿
QualysµÄÇ徲ר¼ÒÖÒÑÔ˵£¬ÓÐÁè¼Ý750Íǫ̀װ±¸¿ÉÄÜÔâÊÜÍøÂç¹¥»÷£¬ÕâЩ¹¥»÷Õë¶ÔµÄÊÇFireEye¾üе¿âÇÔÈ¡µÄ¹¤¾ßËùʹÓõÄÎó²î¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securityaffairs.co/wordpress/112588/hacking/fireeye-tools-exploits.html
4. ClopÀÕË÷Èí¼þ°ïÅÉ̱»¾ÁËÏ㾫ÏãÁÏÉú²úÉÌSymrise
¡¾¸ÅÊö¡¿
Ï㾫ÏãÁÏÉú²úÉÌSymriseÊÇClopÀÕË÷Èí¼þ°ïÅɵÄ×îºóÊܺ¦Õߣ¬¸Ã°ïÅÉÉù³ÆÍµÇÔÁË500 GBµÄδ¼ÓÃÜÎļþ¡£ÏãÁϺÍÏ㾫µÄÖ÷ÒªÉú²úÉÌSymrise AGÊÜClopÀÕË÷Èí¼þÔËÓªÉ̵Ĺ¥»÷¡£ÍþвÕßÉù³ÆÒÑÇÔÈ¡ÁË500 GBµÄδ¼ÓÃÜÎļþ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://securityaffairs.co/wordpress/112494/malware/clop-ransomware-symrise.html
5. ¹È¸èÕ¹ÏÖÁË΢ÈíAPIÖÐδÐÞ²¹µÄ0dayÎó²î
¡¾¸ÅÊö¡¿
×îз¢Ã÷£¬¹È¸èÒѹûÕæÐû²¼ÁË΢ÈíδʵʱÐÞ²¹µÄÁãÈÕÎó²îµÄÏêϸÐÅÏ¢¡£ÔÚºǫ́£¬Ò»Î»ÄäÃûÑо¿Ö°Ô±Ïò΢Èí±¨¸æÁ˸ÃÎó²î£¬¸ÃÎó²îÓëÈ¥Äê12ÔÂËûÃǵÄWindows Print Spooler APIÓйء£¸ÃÎó²îÔÊÐíÍþв¼ÓÈëÕßÒÔÄÚºËģʽִÐÐí§Òâ´úÂ룬ȻºóÕâЩ´úÂë¿ÉÓÃÓÚÔÚÊܺ¦ÕßÅÌËã»úÉÏÔËÐжñÒâÈí¼þ£¬´Ó¶øÎ£º¦ÆäÇå¾²¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.hackread.com/google-unpatched-0day-microsoft-api-vulnerability/
6. Facebook bug̻¶ÁËInstagramÓû§µÄµç×ÓÓʼþµØµã
¡¾¸ÅÊö¡¿
Äá²´¶ûµÄÒ»ÃûITÇå¾²Ñо¿Ô±Saugat Pokharel·¢Ã÷ÁËÒ»¸öFacebook¹ýʧ£¬¸Ã¹ýʧ̻¶ÁËInstagramÓû§µÄ˽ÈËÊý¾Ý£¬°üÀ¨ËûÃǵĵç×ÓÓʼþµØµãºÍÉúÈÕ¡£¾ßÓм¥Ð¦ÒâζµÄÊÇ£¬¸Ã·þÎñÏòÓû§ÔÊÐí£¬ÔÚ×¢²áʱ²»»á½«´ËÀàÐÅÏ¢¹ûÕæ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.hackread.com/facebook-bug-exposed-instagram-user-email-addresses/
7. ð³äÑÇÂíÑ·ÀñÎ│½»¸¶DridexÌØÂåÒÁľÂí
¡¾¸ÅÊö¡¿
Çå¾²¹«Ë¾Cybereason±¨µÀ£¬ÍøÂç·¸·¨·Ö×ÓÕýÔÚʹÓÃαÔìµÄÑÇÂíÑ·ÀñÎ│ÔÚÃÀ¹úºÍÎ÷Å·µÄÔÚÏß¹ºÎïÕßÉÏÄ¿µÄ£¬ÕâЩÀñÎ│ÌṩÁËDridexÒøÐÐľÂí¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.inforisktoday.com/fake-amazon-gift-cards-deliver-dridex-trojan-a-15663
8. 5GÇå¾²·ÀÕչ˻¤Ê¿Äî
¡¾¸ÅÊö¡¿
×÷ÎªÒÆ¶¯Í¨Ñ¶ÊÖÒÕÉú³¤Àú³ÌÖÐÖ÷ÒªµÄÀï³Ì±®½Úµã£¬5GÃæÁÙ×Åǰ¼¸´úÒÆ¶¯Í¨Ñ¶ÊÖÒÕËù¹ÌÓеÄÇ徲Σº¦£¬ÀýÈ磺Öն˵ķÇÊÚȨ½ÓÈë¡¢Á´Â·´«ÊäµÄ±£ÃÜÐÔÎÊÌâ¡¢µçÐÅÓªÒµ²ãÃæµÄµç»°¿¨ÀÄÓûòµçÐÅթƵȡ£
¡¾²Î¿¼Á´½Ó¡¿
http://mp.weixin.qq.com/s?__biz=MjM5ODYyMTM4MA==&mid=2650409128&idx=1&sn=b748727a6e67d0b973994362ed9e03a2&chksm=bec9510389bed8155c3d4d3e6f834de77ce1c767829ca14e98426064296246a6dc1be377f5e7#rd
9. AG¹«Ë¾¿Æ¼¼³öϯ2020ÖйúÍøÂçÇ徲Ʒ¼¶±£»¤ºÍÒªº¦ÐÅÏ¢»ù´¡ÉèÊ©±£»¤´ó»á
¡¾¸ÅÊö¡¿
12ÔÂ20ÈÕ£¬2020ÖйúÍøÂçÇ徲Ʒ¼¶±£»¤ºÍÒªº¦ÐÅÏ¢»ù´¡ÉèÊ©±£»¤´ó»á£¨ÒÔϼò³Æ´ó»á£©ÔÚÄÏÄþÊ¢´óÕÙ¿ª¡£±¾´Î´ó»áÓɹ«°²²¿ÍøÂçÇå¾²ÊØÎÀ¾Ö¡¢¹ú¼ÒÃÜÂëÖÎÀí¾ÖÉÌÃܰ졢Öйú¿ÆÑ§Ôº°ì¹«ÌüÖ¸µ¼£¬¹«°²²¿µÚÒ»Ñо¿ËùÖ÷Àí£¬AG¹«Ë¾¿Æ¼¼µÈ10¼ÒÍøÂçÇå¾²Æóҵ͎á³Ð°ì£¬Ö¼ÔÚÍÆ¶¯Ôö½øÍøÂçÇ徲Ʒ¼¶±£»¤ºÍÒªº¦ÐÅÏ¢»ù´¡ÉèÊ©Çå¾²±£»¤ÊÂÇ飬ÔöǿӪҵ½»Á÷ºÍÂÄÀú·ÖÏí£¬½¡ÌìϼÒÍøÂçÇå¾²×ۺϷÀ¿ØÏµÍ³¡£
¡¾²Î¿¼Á´½Ó¡¿
http://mp.weixin.qq.com/s?__biz=MjM5ODYyMTM4MA==&mid=2650409040&idx=1&sn=d8954c5d93c82b3b98be803f51992b59&chksm=bec951fb89bed8ed27b83116cbe8dfcce3c1cdf11eedcbbf9a3062a55f6814647e593206dc15#rd
10. ·ÀÓù¹ú¼ÒºÍ¹ú¼Ò×ÊÖúµÄÍþвÐÐΪÌå
¡¾¸ÅÊö¡¿
GuruculµÄSaryu NayyarÌÖÂÛÁ˹ú¼ÒºÍ¹ú¼ÒÔÞÖúµÄÍþв¼ÓÈëÕߣ¬¼´ÍøÂçÇå¾²ÌìÏµĶ¥¼¶ÂÓ¶áÕß¡£×Ô´Ó½çËµÍøÂçÇå¾²ÁìÓòÒÔÀ´£¬¾ÍÒ»Ö±±£´æÀ´×Ô¹ú¼ÒºÍ¹ú¼ÒÔÞÖú·½µÄÇå¾²Íþв¡£ËûÃÇÏÖÔÚÒѾÉú³¤µ½ÍøÂç¿Õ¼ä£¬²¢Îª·ÀÓùÕßÌá³öÁËÆæÒìµÄÌôÕ½¡£Ö»¹ÜάȨÈËÊ¿ºÍ·¸·¨Ô˶¯ÓëÄÇЩֱ½ÓΪÖ÷Ȩ´ó¹ú£¨»òÔÚÆäĬÐíÏ£©¾ÙÐÐÔ˶¯µÄÈËÖ®¼ä±£´æ¸ùÌìÐÔ²î±ð£¬µ«ÆäÒé³ÌºÍÊÖÒÕÍùÍù±£´æÖØ´óÖØµþ¡£¿ÉÊÇÒ²ÓкܴóµÄ²î±ð-ÆäÖÐ×îÖ÷ÒªµÄÊÇ×ÊÔ´¡£ÔÚάȨÈËÊ¿ºÍСÐÍ·¸·¨ÍÅ»ï¿ÉÄÜÓµÓÐÓÐÏÞÊÖÒÕ×ÊÔ´µÄµØ·½£¬ÖݺÍÖÝÔÞÖúµÄÐÐΪÕßûÓÐÕâÖÖÏÞÖÆ¡£¹ú¼ÒÐÐΪÕß¿ÉÒÔʹÓÃÆä¹ú¼ÒÇ鱨½çµÄÊÖÒÕºÍ×ÊÔ´£¬¶ø¹ú¼Ò×ÊÖúµÄÐÐΪÕßËäÈ»ÏÖʵÉϲ»Êǹú¼Ò×éÖ¯µÄÒ»²¿·Ö£¬µ«ÈÔ¿ÉÒÔʹÓÃÆäÔÞÖúÕߵIJÆÎñºÍÊÖÒÕ×ʲú¡£
¡¾²Î¿¼Á´½Ó¡¿
https://threatpost.com/defending-against-state-threat-actors/162518/

AG¹«Ë¾ÔÆ







