¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190214

°ä²¼¹¦·ò 2019-02-14
1¡¢Linux Snapd´æÔÚDirty_Sock·ì϶£¬¿É»ñÈ¡rootȨÏÞ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

°²È«×êÑÐÔ±Chris Moberly·¢ÏÖCanonical snapdÊØ»¤¹ý³ÌµÄREST APIÖдæÔÚзì϶Dirty_Sock£¬¸Ã·ì϶¿ÉÔÊÐí¹¥»÷ÕßÔÚLinuxϵͳÉÏ»ñµÃrootȨÏÞ¡£¸Ã·ì϶»áÓ°Ïìµ½ÈκÎʹÓÃsnapdµÄLinuxϵͳ£¬µ«·ì϶ÀûÓÿÉÄÜ»áÓÐËù·ÖÆç¡£CanonicalÒÑÔÚа汾Snapd 2.37.1Öн¨¸´ÁË´Ë·ì϶£¬½¨ÒéÖÎÀíÔ±¾¡¿ì×°ÖøüС£

  

 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/canonical-snapd-vulnerability-gives-root-access-in-linux/

2¡¢Adobe°ä²¼2Ô°²È«¸üУ¬½¨¸´44¸ö¸ßΣ·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

Adobe°ä²¼2Ô°²È«¸üУ¬¹²½¨¸´44¸ö¸ßΣ·ì϶¡£½ÏΪÑϳÁµÄ·ì϶Ô̺¬Flash PlayerÖеÄÔ½½ç¶Á·ì϶£¨CVE-2019-7090£¬¿Éµ¼ÖÂÐÅϢй¶£©¡¢ColdFusionÖеķ´ÐòÁл¯·ì϶£¨CVE-2019-7091£¬¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐУ©ºÍxss·ì϶£¨CVE-2019-7092£¬¿Éµ¼ÖÂÐÅϢй¶£©ÒÔ¼°Cloud DesktopÖеÄDLL½Ù³Ö·ì϶£¨CVE-2019-7093£¬¿Éµ¼ÖÂÌáȨ£©¡£½¨ÒéÓû§¾¡¿ì¸üС£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/adobes-massive-patch-update-fixes-critical-acrobat-reader-bugs/

3¡¢×êÑÐÈËÔ±ÑÝʾÈôºÎÔÚIntel SGXÖÐÖ²Èë¶ñÒâÈí¼þ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

×êÑÐÈËÔ±ÑÝʾÈôºÎÔÚIntel SGXÖаµ²Ø¶ñÒâ´úÂë¡£Intel SGXÊÇSkylake´¦ÖÃÆ÷ÖÐÒýÈëµÄÐÂÖ°ÄÜ£¬Ö¼ÔÚ±£»¤Èí¼þµÄ´úÂëºÍÓйØÊý¾Ý£¬È·±£Æä»úÃÜÐÔºÍÆëÈ«ÐÔ¡£×êÑÐÈËÔ±°µÊ¾ËûÃǵÄPoCÀûÓÃÁËTSXºÍASLRµÈ£¬²¢Ö¸³öÆëÈ«µÄ·ì϶ÀûÓùý³ÌºÄʱ20.8Ãë¡£Õë¶Ô´ËÀ๥»÷µÄ»º½â´ëÊ©¿ÉÄÜÔÚ½«À´¼¸´úÓ¢ÌØ¶ûCPUÖÐÖ´ÐС£

  

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/02/intel-sgx-malware-hacking.html

4¡¢AstarothľÂíбäÌå£¬ÖØÒªÕë¶Ô°ÍÎ÷ºÍÅ·ÖÞ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

CybereasonµÄNocturnus×êÑÐÍŶӷ¢ÏÖAstarothľÂíµÄбäÌ壬¸Ã±äÌåÖØÒªÕë¶Ô°ÍÎ÷ºÍÅ·ÖÞ£¬²¢Í¨¹ýÀ¬»øÓʼþ·Ö·¢¡£Æäpayload»áÌìÉú¶ñÒâµÄwmic.exe¹ý³Ì£¬²¢ÏòC2·þÎñÆ÷·¢ËÍÖ¸±êÍÆËã»úµÄÓйØÐÅÏ¢¡£¸ÃľÂí»¹»áÔÚAvast·À²¡¶¾Èí¼þµÄaswrundll.exeÔËÐÐʱDLLÖÐ×¢Èë¶ñÒâÄ£¿é£¬²¢ÀûÓÃËüÀ´ÍøÂçϵͳÐÅÏ¢ºÍ¼ÓÔØ¶î±íµÄÄ£¿é¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-astaroth-trojan-variant-exploits-anti-malware-software-to-steal-info/

5¡¢ÒøÐÐľÂíTrickBotбäÌ壬¿ÉÇÔÈ¡RDP¡¢VNCºÍPuTTYÍ´´¦

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

Ç÷Ïò¿Æ¼¼µÄ×êÑÐÈËÔ±·¢ÏÖÒøÐÐľÂíTrickbotµÄÒ»¸öбäÌ壬¸Ã±äÌåΪÃÜÂëÇÔȡģ¿éÐÂÔöÁËÈý¸öÖ°ÄÜ£¬Ö¼ÔÚÇÔÈ¡Óû§µÄRDP¡¢VNCºÍPuTTYÍ´´¦¡£¸Ã±äÌåÊÇ»ùÓÚ2018Äê11Ôµİ汾£¬Í¨¹ýÒÔ˰ÊÕ¼¤ÀøÍ¨ÖªÎªÖ÷ÌâµÄÀ¬»øÓʼþ½øÐд«²¼£¬Æä¶ñÒ⸽¼þΪXLSMÌåʽµÄexcelÎļþ¡£TrickBot×Ô2016Äê10Ô³öÏÖÒÔÀ´£¬Ò»ÏòÔÚ²»ÐݽøÐиüС£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/trickbot-banking-trojan-now-steals-rdp-vnc-and-putty-credentials/

6¡¢AZORultľÂíй¥»÷»î¶¯£¬ÖØÒªÕë¶ÔÒâ´óÀû

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

Cybaze-Yori ZLAB·¢ÏÖAZORultľÂíµÄй¥»÷»î¶¯£¬ÖØÒªÕë¶ÔÒâ´óÀû¡£¸ÃľÂíбäÌåͨ¹ý¼Ù×°³ÉDHL¿ìµÝ֪ͨµÄÓʼþ½øÐд«²¼£¬µ±Óû§´ò¿ª¶ñÒâµÄѹËõÎĵµ¸½¼þºó£¬¾Í»áÏÂÔØ²¢ÔËÐиÃľÂí¡£¸ÃľÂíÄܹ»ÇÔÈ¡Webä¯ÀÀÆ÷ÒÔ¼°Óʼþ¿Í»§¶ËÖб£ÁôµÄÕË»§ºÍÍ´´¦£¬²¢Äܹ»×°ÖÃÆäËüµÄpayload¡£ÆäC2·þÎñÆ÷Ϊgoogodsgld[.]comºÍdriverconnectsearch[.]info¡£¸Ã±äÌåµÄÐÐΪÀàËÆÓÚBrushloader¡£

  

Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/specially-crafted-dhl-express-courier-emails-leveraged-to-distribute-a-variant-of-azorult-trojan-f9ea2931


ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù