ŦԼSHIELD·¨°¸ÕýʽÉúЧ£¬ÒªÇóÀ©´óÊý¾Ýй¶֪ͨÁìÓò£»Keepnet Labs ESÊ·ýй¶³¬¹ý50Òڱʼͼ
°ä²¼¹¦·ò 2020-03-231.ŦԼSHIELD·¨°¸ÕýʽÉúЧ£¬ÒªÇóÀ©´óÊý¾Ýй¶֪ͨÁìÓò
3ÔÂ21ÈÕŦԼÖÝSHIELD·¨°¸ÕýʽÉúЧ£¬¸Ã·¨°¸¶ÔŦԼµÄ¡¶Í¨³£Ã³Ò×·¨¡·½øÐÐÁ˶©Õý£¬´ú±íÁËŦԼÏÖ´æÍøÂ簲ȫ¼°Êý¾Ýй¶֪ͨ·¨°¸µÄÀ©´ó°æ±¾¡£¸Ã·¨°¸¶ÔÆóÒµµÄÁ½¸öÖØÒªÓ°ÏìÊÇ£º1¡¢À©´óÊý¾Ýй¶֪ͨҪÇó£»2¡¢ÒªÇóÆóÒµÔÚ±£»¤Å¦Ô¼¾ÓÃñµÄ¡°Ó×ÎÒÐÅÏ¢¡±·½Ãæ²ÉÈ¡¡°ºÏÀíµÄ±£ÏÕ¡±¡£¾ßÌåÀ´Ëµ£¬¸Ã·¨°¸½«Å¦Ô¼ÖݵÄÓ×ÎÒÊý¾Ý½ç˵À©´óµ½ÁËÎÞÐèÆäËüÑéÖ¤ÐÅÏ¢¼´¿É½Ó¼û²ÆÕþÕË»§µÄÕ˺źÍÐÅÓþ¿¨/½è¼Ç¿¨ºÅÂ룬ÒÔ¼°ÓÃÓÚ½øÐÐÉí·ÝÑéÖ¤µÄÖ¸ÎÆ¡¢ÉùÎÆµÈÉúÎï¼ø±ðÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://www.insideprivacy.com/data-security/cybersecurity/new-york-shield-acts-reasonable-safeguard-requirements-became-effective-on-march-21st-is-your-company-ready/
2.Google°ä²¼Chrome°²È«¸üУ¬½¨¸´13¸ö·ì϶
¹È¸è°ä²¼ºÏÓÃÓÚWindows¡¢MacºÍLinuxµÄChrome 80.0.3987.149£¬½¨¸´13¸ö·ì϶¡£ÆäÖÐ×îÑϳÁµÄ·ì϶ÊÇCVE-2020-6422£¬ËüÊÇÒ»¸öÓ°ÏìWebGLµÄuse-after-free£¨UAF£©·ì϶¡£´Ë±í£¬¹È¸è»¹½¨¸´ÁËýÌå×é¼þÖеÄUAF·ì϶£¨CVE-2020-6424£©ºÍÀ©´óÖеÄÕ½ÊõÖ´Ðв»¼°ÎÊÌ⣨CVE-2020-6425£©£¬ÒÔ¼°ÒôƵ×é¼þÖеÄ4¸öUAFÎÊÌ⣨CVE-2020-6427¡¢CVE-2020-6428¡¢CVE-2020-6429ºÍCVE-2020-6449£©¡£ÆäËü·ì϶»¹Ô̺¬usersctplibÖеÄÔ½½ç¶Á·ì϶£¨CVE-2019-20503£©ºÍV8ÒýÇæÖеIJ»Êʵ±µÄʵÏÖÎÊÌ⣨CVE-2020-6426£©¡£¹È¸è»¹°µÊ¾ÓÉÓÚCOVID-19·¢×÷¶øÔÝÍ£ÁËChromeºÍChrome OSµÄ°æ±¾°ä²¼¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/100164/security/google-chrome-bugs.html
3.ÀÕË÷Èí¼þNetwalkerÀûÓÃйڲ¡¶¾´¹µö»î¶¯Ï°È¾Óû§
MalwareHunterTeam·¢ÏÖÀÕË÷Èí¼þNetwalkerÀûÓÃйڲ¡¶¾ÍøÂç´¹µö»î¶¯Ï°È¾Óû§¡£NetwalkerÒÔǰ±»³ÆÎªMailto£¬ÆäÖØÒªÕë¶ÔÆóÒµºÍµ±¾Ö»ú¹¹£¬²¢ÒÔ¹¥»÷Toll¼¯ÍźÍÒÁÀûŵÒÁÖÝÏãéĶò±¾Äɹ«¹²ÎÀÉúÇø£¨CHUPD£©¶øÎÅÃû¡£ÐµÄNetwalker´¹µö»î¶¯ÔÚʹÓÃÃûΪ¡°CORONAVIRUS_COVID-19.vbs¡±µÄ¸½¼þϰȾÓû§£¬SentinelLabsÕÆ¹ÜÈËVitali Kremez°µÊ¾¸Ã°æ±¾µÄNetwalker³ö¸ñÔ¤·ÀÁËÖÕÖ¹Fortinetɱ¶¾Èí¼þ¿Í»§¶Ë£¬´Ë¾Ù¿ÉÄÜÊÇΪÁËÔ¤·À±»·¢ÏÖ¡£Ä¿Ç°¸ÃÀÕË÷Èí¼þÉÐÎÞÃâ·ÑµÄ½âÃܹ¤¾ß¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/netwalker-ransomware-infecting-users-via-coronavirus-phishing/
4.ÐÂÀ¬»øÓʼþ»î¶¯¼ÙÒâÊÀÎÀ×éÖ¯ÕÆ¹ÜÈË·Ö·¢HawkEyeľÂí
IBM X-Force Threat IntelligenceµÄ×êÑÐÈËÔ±·¢ÏÖÒ»¸öеÄÀ¬»øÓʼþ»î¶¯¼Ù×°³ÉÊÀÎÀ×éÖ¯£¨WHO£©ÕƹÜÈË´«²¼¶ñÒâÈí¼þHawkEye¡£¸ÃÀ¬»øÓʼþÐû³ÆÔ̺¬COVID-19Ô¤·ÀºÍ¼±¾çÖÎÓúÒ©ÎïµÄÖ¸ÄÏ£¬»¹³Æ¡°ÕâÊÇÊÀ½çÎÀÉú×éÖ¯µÄÖ¸ÁּÔÚÔ®ÊÔ쥵Ðйڲ¡¶¾¡±£¬ÉõÖÁÒªÇóÊÕ¼þÈ˽«Æäת·¢¸ø¼ÒÈ˺Ͱé¡£×êÑÐÈËÔ±°µÊ¾£¬HawkEyeÖ¼ÔÚ´ÓÊÜϰȾµÄÉ豸ÖÐÇÔÊØÐÅÏ¢£¬µ«Ò²Äܹ»ÓÃ×÷×°ÔØ·¨Ê½£¬ÀûÓÃÆä½©Ê¬ÍøÂ粿ÊðÆäËü¶ñÒâÈí¼þ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/who-chief-impersonated-in-phishing-to-deliver-hawkeye-malware/
5.µÂÖÝAffordacareÕïËùÔâMaze¹¥»÷£¬40GBÊý¾Ý±»µÁ
µÂ¿ËÈøË¹ÖÝ´¹Î£»¤ÀíÕïËùAffordacareÔâµ½ÀÕË÷Èí¼þMaze¹¥»÷£¬¹¥»÷ÍÅ»ïÐû³ÆÈôÊǸÃÕïËù²»Ö§¸¶Êê½ð£¬Ôò»áй¶Æä»¼ÕßÊý¾Ý¡£AffordacareÌṩ³£¼û¼²²¡ºÍÖÐÉ˵ÄÒ½ÁÆ·þÎñ£¬µ«¸ÃÕïËùûÓÐй©ÊÇ·ñÌṩCOVID-19¼ì²â·þÎñ¡£Æ¾¾ÝDatabreaches.netµÄÊý¾Ý£¬AffordaCareÓÚ2ÔÂ1ÈÕϰȾMaze£¬µ«ÔÚÕâÖ®ºó¸ÃºÚ¿ÍÍÅ»ïÇÔÈ¡Á˳¬¹ý40GBÊý¾Ý£¬ÆäÖÐÔ̺¬»¼ÕßµÄÈ«Ãû¡¢Éç»á°²È«ºÅÂë¡¢µ®ÉúÈÕÆÚ¡¢Õï¶Ï´úÂë¡¢Ò½ÖδúÂë¡¢»¼ÕßµØÖ·ºÍµç»°ºÅÂë¡¢Óйز¡Ê·ºÍ¾ÍÕïÔÒò¡¢Õ˵¥ÐÅÏ¢¡¢±£ÏÕÕþ²ßÐÅÏ¢µÈ£¬»¹Ô̺¬AffordaCareÔ±¹¤µÄÅâ³¥ÎļþºÍÔ±¹¤Ð½×ÊÐÅÏ¢¡£¸ÃÕïËùÉÐδȷÈÏÈëÇÖÊÂÎñ£¬µ«MazeÍÅ»ïÒÑÔÚÆäÍøÕ¾ÉϹ«¿ªÁËÈëÇÖÐÐΪ£¬²¢Íþв½«°ä²¼Êý¾ÝµÄÑù±¾¡£
ÔÎÄÁ´½Ó£º
https://hotforsecurity.bitdefender.com/blog/maze-ransomware-continues-to-hit-healthcare-units-amid-coronavirus-covid-19-outbreak-22654.html
6.Keepnet Labs ESÊ·ýй¶³¬¹ý50Òڱʼͼ£¬¾ùΪÒÔǰй¶
Ó¢¹ú°²È«³§ÉÌKeepnet LabsµÄÒ»¸öElasticsearchÊ·ýй¶Á˳¬¹ý50ÒÚÌõÊý¾Ý¼Í¼£¬ÕâЩ¼Í¼ÊÇ2012ÄêÖÁ2019ÄêÖ®¼ä²úÉúµÄй¶ÊÂÎñÖеļͼ¡£¸ÃÊý¾Ý¿âÓÉÁ½¸ö¼¯ÖÐ×é³É£¬Ò»¸öÔ̺¬50.88Òڱʼͼ£¬¶øÁíÒ»¸öʵʱ¸üеļ¯ÖÐÔòÔ̺¬³¬¹ý1500Íò±Ê¼Í¼¡£Ð¹Â¶µÄ¼Í¼Ô̺¬¹þÏ£ÀàÐÍ¡¢Ð¹Â¶Äê·Ý¡¢ÃÜÂ루¹þÏ£¡¢¼ÓÃÜ»òÃ÷ÎÄÌåʽ£©¡¢µç×ÓÓʼþ¡¢µç×ÓÓʼþÓòÃûÒÔ¼°Ð¹Â¶Ô´£¨Ô̺¬Adobe¡¢Last.fm¡¢Twitter¡¢LinkedIn¡¢TumblrºÍVKµÈ£©¡£Keepnet Labs°µÊ¾Êý¾Ý¿âÊÇÔÚÆä¹©¸øÉ̽«Ë÷ÒýǨáãÖÁÁíһ̨ES·þÎñÆ÷ʱ¶³öµÄ£¬ÔÚǨáã¹ý³ÌÖзÀ»ðǽһʱ½ûÓÃÁËÔ¼10·ÖÖÓ£¬Ê¹µÃËÑË÷ÒýÇæ¿ÉÒÔΪÊý¾Ý¿â³ÉÁ¢Ë÷Òý¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/100198/data-breach/keepnet-labs-data-leak.html


¾©¹«Íø°²±¸11010802024551ºÅ