¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190214
°ä²¼¹¦·ò 2019-02-14
°²È«×êÑÐÔ±Chris Moberly·¢ÏÖCanonical snapdÊØ»¤¹ý³ÌµÄREST APIÖдæÔÚзì϶Dirty_Sock£¬¸Ã·ì϶¿ÉÔÊÐí¹¥»÷ÕßÔÚLinuxϵͳÉÏ»ñµÃrootȨÏÞ¡£¸Ã·ì϶»áÓ°Ïìµ½ÈκÎʹÓÃsnapdµÄLinuxϵͳ£¬µ«·ì϶ÀûÓÿÉÄÜ»áÓÐËù·ÖÆç¡£CanonicalÒÑÔÚа汾Snapd 2.37.1Öн¨¸´ÁË´Ë·ì϶£¬½¨ÒéÖÎÀíÔ±¾¡¿ì×°ÖøüС£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/canonical-snapd-vulnerability-gives-root-access-in-linux/2¡¢Adobe°ä²¼2Ô°²È«¸üУ¬½¨¸´44¸ö¸ßΣ·ì϶
Adobe°ä²¼2Ô°²È«¸üУ¬¹²½¨¸´44¸ö¸ßΣ·ì϶¡£½ÏΪÑϳÁµÄ·ì϶Ô̺¬Flash PlayerÖеÄÔ½½ç¶Á·ì϶£¨CVE-2019-7090£¬¿Éµ¼ÖÂÐÅϢй¶£©¡¢ColdFusionÖеķ´ÐòÁл¯·ì϶£¨CVE-2019-7091£¬¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐУ©ºÍxss·ì϶£¨CVE-2019-7092£¬¿Éµ¼ÖÂÐÅϢй¶£©ÒÔ¼°Cloud DesktopÖеÄDLL½Ù³Ö·ì϶£¨CVE-2019-7093£¬¿Éµ¼ÖÂÌáȨ£©¡£½¨ÒéÓû§¾¡¿ì¸üС£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/adobes-massive-patch-update-fixes-critical-acrobat-reader-bugs/3¡¢×êÑÐÈËÔ±ÑÝʾÈôºÎÔÚIntel SGXÖÐÖ²Èë¶ñÒâÈí¼þ
×êÑÐÈËÔ±ÑÝʾÈôºÎÔÚIntel SGXÖаµ²Ø¶ñÒâ´úÂë¡£Intel SGXÊÇSkylake´¦ÖÃÆ÷ÖÐÒýÈëµÄÐÂÖ°ÄÜ£¬Ö¼ÔÚ±£»¤Èí¼þµÄ´úÂëºÍÓйØÊý¾Ý£¬È·±£Æä»úÃÜÐÔºÍÆëÈ«ÐÔ¡£×êÑÐÈËÔ±°µÊ¾ËûÃǵÄPoCÀûÓÃÁËTSXºÍASLRµÈ£¬²¢Ö¸³öÆëÈ«µÄ·ì϶ÀûÓùý³ÌºÄʱ20.8Ãë¡£Õë¶Ô´ËÀ๥»÷µÄ»º½â´ëÊ©¿ÉÄÜÔÚ½«À´¼¸´úÓ¢ÌØ¶ûCPUÖÐÖ´ÐС£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/02/intel-sgx-malware-hacking.html4¡¢AstarothľÂíбäÌå£¬ÖØÒªÕë¶Ô°ÍÎ÷ºÍÅ·ÖÞ
CybereasonµÄNocturnus×êÑÐÍŶӷ¢ÏÖAstarothľÂíµÄбäÌ壬¸Ã±äÌåÖØÒªÕë¶Ô°ÍÎ÷ºÍÅ·ÖÞ£¬²¢Í¨¹ýÀ¬»øÓʼþ·Ö·¢¡£Æäpayload»áÌìÉú¶ñÒâµÄwmic.exe¹ý³Ì£¬²¢ÏòC2·þÎñÆ÷·¢ËÍÖ¸±êÍÆËã»úµÄÓйØÐÅÏ¢¡£¸ÃľÂí»¹»áÔÚAvast·À²¡¶¾Èí¼þµÄaswrundll.exeÔËÐÐʱDLLÖÐ×¢Èë¶ñÒâÄ£¿é£¬²¢ÀûÓÃËüÀ´ÍøÂçϵͳÐÅÏ¢ºÍ¼ÓÔØ¶î±íµÄÄ£¿é¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-astaroth-trojan-variant-exploits-anti-malware-software-to-steal-info/5¡¢ÒøÐÐľÂíTrickBotбäÌ壬¿ÉÇÔÈ¡RDP¡¢VNCºÍPuTTYÍ´´¦
Ç÷Ïò¿Æ¼¼µÄ×êÑÐÈËÔ±·¢ÏÖÒøÐÐľÂíTrickbotµÄÒ»¸öбäÌ壬¸Ã±äÌåΪÃÜÂëÇÔȡģ¿éÐÂÔöÁËÈý¸öÖ°ÄÜ£¬Ö¼ÔÚÇÔÈ¡Óû§µÄRDP¡¢VNCºÍPuTTYÍ´´¦¡£¸Ã±äÌåÊÇ»ùÓÚ2018Äê11Ôµİ汾£¬Í¨¹ýÒÔ˰ÊÕ¼¤ÀøÍ¨ÖªÎªÖ÷ÌâµÄÀ¬»øÓʼþ½øÐд«²¼£¬Æä¶ñÒ⸽¼þΪXLSMÌåʽµÄexcelÎļþ¡£TrickBot×Ô2016Äê10Ô³öÏÖÒÔÀ´£¬Ò»ÏòÔÚ²»ÐݽøÐиüС£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/trickbot-banking-trojan-now-steals-rdp-vnc-and-putty-credentials/6¡¢AZORultľÂíй¥»÷»î¶¯£¬ÖØÒªÕë¶ÔÒâ´óÀû

Cybaze-Yori ZLAB·¢ÏÖAZORultľÂíµÄй¥»÷»î¶¯£¬ÖØÒªÕë¶ÔÒâ´óÀû¡£¸ÃľÂíбäÌåͨ¹ý¼Ù×°³ÉDHL¿ìµÝ֪ͨµÄÓʼþ½øÐд«²¼£¬µ±Óû§´ò¿ª¶ñÒâµÄѹËõÎĵµ¸½¼þºó£¬¾Í»áÏÂÔØ²¢ÔËÐиÃľÂí¡£¸ÃľÂíÄܹ»ÇÔÈ¡Webä¯ÀÀÆ÷ÒÔ¼°Óʼþ¿Í»§¶ËÖб£ÁôµÄÕË»§ºÍÍ´´¦£¬²¢Äܹ»×°ÖÃÆäËüµÄpayload¡£ÆäC2·þÎñÆ÷Ϊgoogodsgld[.]comºÍdriverconnectsearch[.]info¡£¸Ã±äÌåµÄÐÐΪÀàËÆÓÚBrushloader¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/specially-crafted-dhl-express-courier-emails-leveraged-to-distribute-a-variant-of-azorult-trojan-f9ea2931ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ