΢Èí°ä²¼Õë¶ÔSMBv3·ì϶µÄKB4551762°²È«¸üУ»?ºÉÀ¼µ±¾ÖÃÔʧ³¬¹ý690ÍòÆ÷¹Ù¾èÏ×ÕßÊý¾Ý

°ä²¼¹¦·ò 2020-03-13

1.΢Èí°ä²¼Õë¶ÔSMBv3·ì϶µÄKB4551762°²È«¸üÐÂ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


΢Èí½ñÌìÔçЩʱ³½°ä²¼ÁËÕë¶ÔSMBv3 RCE·ì϶£¨CVE-2020-0796£©µÄ²¹¶¡¸üУ¨KB4551762£© £¬Óû§Äܹ»Í¨¹ýWindows Update²é³­¸üлò´Ó΢Èí²¹¶¡Ä¿Â¼£¨https://www.catalog.update.microsoft.com/Search.aspx?q=KB4551762£©ÉÏÊÖ¶¯ÏÂÔØÊʺÏ×Ô¼ºWindows°æ±¾µÄKB4551762¡£Î¢Èí°µÊ¾¹ÌȻûÓз¢ÏÖÀûÓô˷ì϶µÄ¹¥»÷ £¬µ«½¨ÒéÓû§ÓÅÏÈ×°Öô˸üС£´Ë·ì϶Ҳ±»³ÆÎªSMBGhost»òEternalDarkness £¬½öÓ°ÏìÔËÐÐWindows 10°æ±¾1903ºÍ1909ÒÔ¼°Windows Server Server Core×°Öð汾1903ºÍ1909µÄÉ豸¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-releases-kb4551762-security-update-for-smbv3-vulnerability/


2.Turla APTÐÂË®¿Ó¹¥»÷ £¬ÀûÓÃкóÃÅÕë¶ÔÑÇÃÀÄáÑÇ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ESET×êÑÐÈËÔ±·¢ÏÖ¶íÂÞ˹ºÚ¿ÍÍÅ»ïTurla APTµÄÐÂË®¿Ó¹¥»÷ £¬¸Ã¹¥»÷ÖÁÉÙ´Ó2019ËêÊׯðÍ· £¬ÖÁÉÙÓÐËĸöÑÇÃÀÄáÑÇÍøÕ¾Êܵ½Ï°È¾ £¬Ô̺¬¶íÂÞ˹ÑÇÃÀÄáÑÇ´óʹ¹ÝÁìÊ´¦£¨armconsul[.]ru£©¡¢Artsakh¹²ºÍ¹úÌìÈ»±£»¤ºÍÌìÈ»×ÊÔ´²¿£¨mnp.nkr[.]am£©¡¢ÑÇÃÀÄáÑǹú¼ÊºÍ°²È«ÊÂÎñ×êÑÐËù£¨aiisa[.]am£©ºÍÑÇÃÀÄáÑÇ´æ¿îµ£±£»ù½ð£¨adgf[.]am£©¡£¹¥»÷ÕßÀûÓÃÐéαµÄAdobe Flash¸üзַ¢Á½¸öеĶñÒâÈí¼þ £¬Ô̺¬¶ñÒâÈí¼þ¿ªÊÍÆ÷NetFlashºÍľÂíPyFlash¡£


Ô­ÎÄÁ´½Ó£º

https://www.welivesecurity.com/2020/03/12/tracking-turla-new-backdoor-armenian-watering-holes/


3.Operation Overtrap¹¥»÷»î¶¯ £¬Õë¶ÔÈÕ±¾ÒøÐÐÓû§


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ç÷Ïò¿Æ¼¼·¢ÏÖÕë¶ÔÈÕ±¾ÒøÐÐÓû§µÄй¥»÷»î¶¯¡°Operation Overtrap¡± £¬¸Ã»î¶¯×Ô2019Äê4ÔÂÒÔÀ´Ò»Ïò»îÔ¾ £¬²¢ÇÒʹÓÃÈýÖÖ·ÖÆçµÄ¹¥»÷ý½éÀ´ÇÔÈ¡Êܺ¦ÕßµÄÒøÐÐÆ¾Ö¤£ºÍ¨¹ýÀ¬»øÓʼþ·¢ËͼÙ×°³ÉÒøÐÐÍøÕ¾µÄ´¹µöÁ´½Ó£»Í¨¹ýÀ¬»øÓʼþÒªÇóÊܺ¦Õß´ÓÁ´½ÓµÄÍøÕ¾¸ßµÍÔØ¶ñÒâÈí¼þµÄ¿ÉÖ´ÐÐÎļþ£»Í¨¹ý¶¨ÔìµÄ·ì϶ÀûÓù¤¾ß°ü£¨BottleEK£©´«²¼¶ñÒâÈí¼þ¡£¹¥»÷ÕßÖØÒªÊ¹ÓõĶñÒâÈí¼þÊÇÐÂÒøÐÐľÂíCinobi¡£


Ô­ÎÄÁ´½Ó£º

https://blog.trendmicro.com/trendlabs-security-intelligence/operation-overtrap-targets-japanese-online-banking-users-via-bottle-exploit-kit-and-brand-new-cinobi-banking-trojan/


4.ºÏÇڿƼ¼ÍøÂçÖÎÀíÈí¼þ16¸ö·ì϶ £¬³§ÉÌÉÐ佨¸´


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



×êÑÐÈËÔ±ÔÚºÏÇڿƼ¼£¨Zyxel£©µÄÍøÂçÖÎÀíÈí¼þCloudCNM SecuManagerÖз¢ÏÖ16¸ö°²È«·ì϶ £¬ÕâЩ·ì϶Ô̺¬¶à¸öºóÃźÍÓ²±àÂëµÄĬÈÏÍ´´¦¡¢ÃÜÔ¿µÈ¡£×êÑÐÈËÔ±³ÆÊÜÓ°ÏìµÄ°æ±¾Ô̺¬CloudCNM SecuManager 3.1.0ºÍ3.1.1 £¬¶øËüÃǵÄ×îиüÐÂÈÕÆÚΪ2018Äê11Ô¡£Zyxel Gateway SBUµÄ¸ß¼¶¸±×ܲÃNathan Yen°µÊ¾¸Ã¹«Ë¾´Ë¿ÌÒÑÒâʶµ½ÎÊÌâ £¬²¢ÔÚÖÂÁ¦Ñ¸¿ì½¨¸´·ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/flaws-zyxels-network-management-software/153554/


5.AvastɱÈíÔÚÆØ³öÑϳÁ·ì϶ºó½ûÓÃJavaScriptɨÃèÒýÇæ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¹È¸è°²È«×êÑÐÈËÔ±Ëþά˹¡¤°ÂÂüµÏ£¨Tavis Ormandy£©·¢ÏÖAvastɱ¶¾Èí¼þ´æÔÚ·ì϶ £¬¿ÉÔÊÐíºÚ¿ÍÔÚÓû§ÍÆËã»úÉÏÔ¶³ÌÖ´ÐжñÒâ´úÂë¡£AvastÔÚÒ»ÖÜǰ¾Í½Óµ½Á˸÷ì϶µÄ»ã±¨ £¬µ«ÈÔδ½â¾ö¸ÃÎÊÌâ £¬¸Ã¹«Ë¾¾ö¶¨ÁÙʱ½ûÓÃɱÈíÖеÄJavaScriptɨÃèÒýÇæ¡£Ormandy°µÊ¾¸Ã·ì϶ºÜÈÝÒ×±»ÀûÓà £¬¹¥»÷ÕßÖ»Ðèͨ¹ýµç×ÓÓʼþ·¢ËͶñÒâJavaScript»òWSHÎļþ £¬»òÓÕʹÓû§´ò¿ªÔ̺¬¶ñÒâJavaScriptµÄÎļþ £¬¼´Äܹ»ÏµÍ³¼¶½Ó¼ûȨÏÞÖ´ÐжñÒâ²Ù×÷ £¬ÀýÈç×°ÖöñÒâÈí¼þ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/avast-disables-javascript-engine-in-its-antivirus-following-major-bug/


6.ºÉÀ¼µ±¾ÖÃÔʧ³¬¹ý690ÍòÆ÷¹Ù¾èÏ×ÕßÊý¾Ý £¬Õ¼×ÜÈ˶¡½üÒ»°ë


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ºÉÀ¼µ±¾Ö°µÊ¾ÃÔʧÁËÁ½¸ö´æÓÐ690ÍòÆ÷¹Ù¾èÔùÕßÊý¾ÝµÄÓ²ÅÌ £¬ÕâЩÊý¾ÝÊÇ1998Äê2ÔÂÖÁ2010Äê6ÔÂÆÚ¼äÏòºÉÀ¼¾èÔùÕߵǼǴ¦Ìá½»µÄËùÓоèÔùÕß±í¸ñµÄ±¸·Ý¡£ÕâЩӲÅ̵Ä×îºóʹÓù¦·òÊÇ2016Äê £¬ËæºóËüÃDZ»¸éÖÃÔÚÒ»¸ö°²È«µÄ±£Ë¾¿âÖС£µ«ÔÚ½ñÄêÔçЩʱ³½µ±¾Ö·¢ÏÖÓ²ÅÌÃÔʧ £¬²¢ÇÒ´Ë¿ÌÒÀÈ»ÎÞ·¨ÕÒµ½¡£Ó²ÅÌÖд洢µÄÐÅÏ¢Ô̺¬×¢²á¾èÔùÕßµÄÐÕÃû¡¢ÐԱ𡢵®ÉúÈÕÆÚ¡¢µØÖ·¡¢Æ÷¹Ù¾èÔùµÄÑ¡Ôñ¡¢IDÒÔ¼°ÊðÃû¡£ºÉÀ¼µÄ×ÜÈ˶¡Îª1740Íò×óÓÒ £¬ÆäÖнüÒ»°ë±»ÒÔΪÊÇ×¢²á¾èÔùÕß¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/dutch-government-loses-hard-drives-with-data-of-6-9-million-registered-donors/