Î÷ÃÅ×Ó¶à¿î¹¤ÒµÉ豸ÊÜLinuxÄں˷ì϶SegmentSmackÓ°Ï죻ŷÖÞÄÜÔ´¹«Ë¾EDPϰȾRagnarLocker
°ä²¼¹¦·ò 2020-04-161.Î÷ÃÅ×Ó¶à¿î¹¤ÒµÉ豸ÊÜLinuxÄں˷ì϶SegmentSmackÓ°Ïì
Î÷ÃÅ×Ó°ä²¼4Ô²¹¶¡¸üУ¬ ÆäÖÐ3Ìõв¼¸æÍ¨Öª¿Í»§Æä¶à¿î¹¤ÒµÉ豸Êܵ½LinuxÄں˷ì϶SegmentSmackÓ°Ïì¡£SegmentSmackºÍFragmentSmack£¨±ðÀë±»¸ú×ÙΪCVE-2018-5390ºÍCVE-2018-5391£©ÊÇ×êÑÐÈËJuha-Matti TilliÔÚ2018Äê·¢ÏÖµÄÁ½¸öLinuxÄں˷ì϶£¬¹¥»÷ÕßÄܹ»Í¨¹ýÏòÖ¸±êϵͳ·¢ËͶñÒâÊý¾Ý°üÀ´ÌáÒéDoS¹¥»÷¡£ÔÚµÚÒ»·Ý²¼¸æÖÐÎ÷ÃÅ×Ó³ÆSegmentSmackºÍFragmentSmackÓ°ÏìÁËËüµÄIE/PB-LinkÉ豸¡¢RUGGEDCOM·ÓÉÆ÷¡¢»ùÓÚROXµÄVPNÖն˺ͷÀ»ðǽ¡¢SCALANCE·ÓÉÆ÷ºÍ·À»ðǽ¡¢SIMATICͨѶ´¦ÖÃÆ÷ºÍSinema Remote Connect¡£µÚ¶þ·Ý²¼¸æÖÐÎ÷ÃÅ×ÓÅû¶ÓëSegmentSmackÓйصÄDoS·ì϶£¨CVE-2019-19301£©£¬¸Ã·ì϶ӰÏìÁËSIMATICͨѶģ¿é¡¢SCALANCE X»¥»»»úºÍSIPLUSÉ豸¡£µÚÈý·Ý²¼¸æÔòÅû¶ÁËÓ°ÏìÎ÷ÃÅ×ÓSIDOORÃÅÖÎÀíϵͳ¡¢SIMATICÉ豸¡¢SINAMICSת»»Æ÷ºÍSIPLUS²úÆ·µÄDoS·ì϶£¨CVE-2019-19300£©¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/siemens-industrial-devices-affected-segmentsmack-linux-kernel-flaw
2.Ó¢ÌØ¶û°ä²¼4Ô°²È«¸üУ¬½¨¸´¶à¿î²úÆ·ÖеÄ9¸ö·ì϶
Ó¢ÌØ¶ûÔÚ4Ô²¹¶¡¸üÐÂÖн¨¸´ÁË9¸ö·ì϶£¬ÕâЩ·ì϶¾ùΪÖиßΣ·ì϶£¬Ó°Ïì¶à¸öÈí¼þ¡¢¹Ì¼þ¼°Æ½Ì¨¡£Ó¢Ìضû½¨¸´ÁËPROSet/ÎÞÏßWiFi²úÆ·ÔÚWindows 10ÉϵÄÁ½¸ö·ì϶-¾¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÓÉÓÚ²»°²È«µÄ¼Ì³ÐȨÏÞ¶ø¿ÉÄÜͨ¹ý±¾µØ½Ó¼û½øÐÐÌØÈ¨Éý¼¶£¨CVE-2020-0557£©£»ÓÉÓÚÄÚºËÇý¶¯·¨Ê½ÖеĻº³åÇøÏ޶Ȳ»µ±£¬ÎÞÌØÈ¨µÄ¹¥»÷Õß¿ÉÄÜͨ¹ýÏàÁÚÍøÂç½Ó¼ûÀ´µ¼Ö»ؾø·þÎñ£¨CVE-2020-0558£©¡£Ó¢Ìضû»¹½¨¸´ÁËNUC mini PCµÄϵͳ¹Ì¼þÖкÍÄ£¿é»¯·þÎñÆ÷MFS2600KISPPÍÆËãÄ£¿éÖеÄÁ½¸ö·ì϶£¬Ô̺¬²»ÕýÈ·µÄ»º³åÇøÏ޶ȵ¼ÖµÄLPE·ì϶£¨CVE-2020-0600£©ºÍǰÌá²é³²»µ±µ¼ÖµÄÌáȨ·ì϶£¨CVE-2020-0578£©¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/intel-april-platform-update-fixes-high-severity-security-issues/
3.΢Èí°ä²¼4ÔÂOffice°²È«¸üУ¬½¨¸´55¸ö·ì϶
΢ÈíÔÚ4ÔÂOffice°²È«¸üÐÂÖÐÕë¶Ô7¸ö²úÆ·½¨¸´ÁË55¸ö·ì϶£¬ÆäÖÐÔ̺¬Ó°ÏìÁËMicrosoft OfficeºÍMicrosoft Office SharePoint²úÆ·µÄ12¸öRCE·ì϶£¬ÕâЩ·ì϶¾ù±»¹éÀàΪÑϳÁ»ò³ÁÒª¼¶±ð£¬¹¥»÷ÕßÄܹ»ÀûÓÃËüÃÇÔÚSharePointÀûÓ÷¨Ê½ºÍSharePoint·þÎñÆ÷ÕÊ»§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂ롣΢Èí»¹½¨¸´ÁË10¸öXSS·ì϶£¬¹¥»÷Õß¿ÉÄÜÀûÓÃÕâЩ·ì϶ÔÚµ±Ç°Óû§µÄ°²È«¸ßµÍÎÄÖÐÔËÐо籾²¢¼ÙðÓû§¡¢ÇÔÈ¡Ãô¸ÐÊý¾Ý»òδ¾ÊÚȨÔĶÁÄÚÈÝ¡£´Ë±í£¬Î¢Èí½¨¸´ÁËÁ½¸öÌáȨ·ì϶ºÍËĸöºýŪ·ì϶¡£¾ßÌå·ì϶ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-office-april-security-updates-fix-critical-rce-bugs/
4.Å·ÖÞÄÜÔ´¹«Ë¾EDPϰȾRagnarLocker£¬±»ÀÕË÷½ü1000ÍòÅ·Ôª
½üÈÕÆÏÌÑÑÀ¿ç¹úÄÜÔ´¾ÞÍ·Energias de Portugal£¨EDP£©Ôâµ½ÀÕË÷Èí¼þRagnarLocker¹¥»÷£¬±»ÀÕË÷1580 BTCµÄÊê½ð£¨Ô¼ºÏ1090ÍòÃÀÔª»ò990ÍòÅ·Ôª£©¡£EDP¼¯ÍÅÊÇÅ·ÖÞÄÜÔ´ÐÐÒµ£¨ÌìÈ»ÆøºÍµçÁ¦£©×î´óµÄÔËÓªÉÌÖ®Ò»£¬Ò²ÊÇÊÀ½çµÚËÄ´ó·çÄܳö²úÉÌ¡£¸Ã¹«Ë¾ÔÚÈ«ÇòËĸö´óÖÞµÄ19¸ö¹ú¶È/µØÓòÕ¼ÓÐÒµÎñ£¬²¢ÇÒÕ¼Óг¬¹ý11500ÃûÔ±¹¤ºÍΪ³¬¹ý1100Íò¿Í»§ÌṩÄÜÔ´¡£ÔÚ¹¥»÷¹ý³ÌÖУ¬Ragnar Locker¹¥»÷ÍÅ»ïÐû³ÆÇÔÈ¡Á˳¬¹ý10 TBµÄ¹«Ë¾Ãô¸ÐÎļþ£¬²¢Íþв³ÆÈôÊǸù«Ë¾»Ø¾øÖ§¸¶Êê½ð£¬ËûÃǽ«°ä²¼µÁÈ¡µÄËùº±¼û¾Ý¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/ragnarlocker-ransomware-hits-edp-energy-giant-asks-for-10m/
5.TA505³ÖÐøÀûÓÃSDBbot RATϰȾÆóÒµÍøÂç£¬ÖØÒªÕë¶ÔÅ·ÖÞ
IBM X-ForceÍŶӹ۲쵽TA505³ÖÐøÀûÓÃSDBbot RATϰȾÆóÒµÍøÂç¡£ÔÚ2019Äê11Ô£¬X-Force IRIS¹Û²ìµ½Óй¥»÷ÕßÀûÓüÙðµÄOnehub´¹µöÓʼþ¹¥»÷Å·ÖÞµÄÆóÒµÔ±¹¤£¬¸Ã´¹µöÓʼþÖ¼ÔÚÇÔÈ¡Active Directory£¨AD£©Êý¾Ý¼°Óû§Í´´¦£¬²¢Ê¹ÓÃSDBbot RATϰȾÆóÒµÍøÂç»·¾³¡£Æ¾¾Ý×êÑÐÈËÔ±¶Ô¹¥»÷ÕßµÄTTP¡¢C£¦C»ù´¡ÉèÊ©ÒÔ¼°ÏÈǰ¹éÒòÓÚ¸Ã×éÖ¯µÄÌØ¶¨¶ñÒâÈí¼þµÄ·ÖÎö£¬X-Force IRISÒÔΪTA505ÊǸù¥»÷»î¶¯±³ºóµÄ¹¥»÷ÍŻ
ÔÎÄÁ´½Ó£º
https://securityintelligence.com/posts/ta505-continues-to-infect-networks-with-sdbbot-rat/
6.¾É½ðɽ»ú³¡¹¥»÷Õß»òΪ¶íÂÞ˹APT×éÖ¯Energetic Bear
ESET×êÑÐÈËÔ±ÒÔΪ£¬¶Ô¾É½ðɽ¹ú¼Ê»ú³¡£¨SFO£©ÍøÕ¾µÄ¹¥»÷ÊÇÓɱ»³ÆÎªEnergetic BearµÄ¶íÂÞË¹ÍøÂç¼äµý×éÖ¯½øÐеġ£¸ÃAPT×éÖ¯×Ô2010ÄêÒÔÀ´Ò»ÏòºÜ»îÔ¾£¬ÖØÒªÕë¶ÔÄÜÔ´ºÍ¹¤ÒµÁìÓòµÄ×éÖ¯¡£SFOµÄ»ú³¡ÐÅÏ¢¼¼ÊõºÍµçÐŲ¿ÃÅ£¨ITT£©°µÊ¾¹¥»÷ÕßÔÚ»ú³¡ÍøÕ¾ÉÏÖ²ÈëÁ˶ñÒâ´úÂëÒÔÇÔÈ¡Óû§µÄµÇ¼ʹ´¦£¬¿ÉÄÜÊܹ¥»÷Ó°ÏìµÄÓû§Ô̺¬Ê¹ÓÃWindowsÉ豸»ò·ÇSFOÊØ»¤µÄÉ豸ͨ¹ýIEä¯ÀÀÆ÷´Ó»ú³¡ÍøÂç±í²¿½Ó¼ûÕâÐ©ÍøÕ¾µÄÓû§¡£SFOµÄITÈËÔ±ÒѾɾ³ýÁË×¢ÈëÆäÍøÕ¾ÖеĶñÒâ´úÂ룬²¢ÔÚ¹¥»÷²úÉúºó½«Á½Õß¶¼½øÐÐÁËÍÑ»ú´¦Öá£ÎªÏìÓ¦´ËÊÂÎñ£¬SFO»ú³¡³ÁÖÃÁËËùÓеĵç×ÓÓʼþºÍÍøÂçÃÜÂë¡£ESET³Æ¹¥»÷ÕßÀûÓÃSMBÖ°ÄܺÍfile£º//ǰ׺À´ÍøÂç½Ó¼ûÕßµÄWindowsÍ´´¦£¬Ô̺¬Óû§ÃûºÍNTLM¹þÏ£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/101601/apt/energetic-bear-airport-hack.html


¾©¹«Íø°²±¸11010802024551ºÅ