WHO¡¢CDC¡¢NIH¼°¸Ç´Ä»ù½ð»áÔ¼2.5ÍòÓÊÏäÆ¾Ö¤Ð¹Â¶£»°²È«×¨¼Ò·¢ÏÖ28¸ö·À²¡¶¾²úÆ·´æÔÚsymlink race·ì϶
°ä²¼¹¦·ò 2020-04-281.ÍøÐŰìµÈ12¸ö²¿ÃŽáºÏ°ä²¼¡¶ÍøÂ簲ȫÉó²é·¨×Ó¡·
4ÔÂ27ÈÕ12ʱ£¬¹ú¶È»¥ÁªÍøÐÅÏ¢°ì¹«ÊÒ¡¢¹ú¶È·¢¸ÄίµÈ12¸ö²¿ÃŽáºÏ°ä²¼ÁË¡¶ÍøÂ簲ȫÉó²é·¨×Ó¡·£¬²¢´òËãÓÚ6ÔÂ1ÈÕÕýʽִÐС£°ä²¼ÕâÒ»¡¶·¨×Ó¡·ÊÇΪÁ˼°Ôç·¢ÏÖ²¢Ô¤·À²É¹º²úÆ·ºÍ·þÎñ¸ø¹Ø¼üÐÅÏ¢»ù´¡ÉèÊ©ÔËÐдøÀ´·çÏÕ΢·çÏÕ£¬±£¾þÇͺ¦ÐÅÏ¢»ù´¡ÉèÊ©¹©¸øÁ´°²È«£¬ÊØ»¤¹ú¶È°²È«¡£ÍøÂ簲ȫÉó²éµÄ³ÁµãÊÇÆÀ¹À¹Ø¼üÐÅÏ¢»ù´¡ÉèÊ©ÔËÓªÕ߲ɹºÍøÂç²úÆ·ºÍ·þÎñ¿ÉÄÜ´øÀ´µÄ¹ú¶È°²È«·çÏÕ¡£
ÔÎÄÁ´½Ó£º
http://www.cac.gov.cn/2020-04/27/c_1589535450769077.htm
2.ÔÚMicrosoft TeamsÖв鿴GIF¿ÉÄܵ¼ÖÂÕÊ»§½Ù³Ö
CyberArkµÄ×êÑÐÈËÔ±ÓÚ±¾ÖÜÒ»°µÊ¾£¬Microsoft Teams´æÔÚ×ÓÓòÃûÊÕÊÜ·ì϶£¬¸Ã·ì϶¿ÉÓë¶ñÒâµÄ.GIFÎļþ½áºÏÀûÓ㬴ﵽÇÔÈ¡Óû§Êý¾Ý²¢½Ù³ÖTeamsÕË»§µÄÖ÷ÕÅ¡£´Ë·ì϶ӰÏìÁĘ̈ʽ»úºÍWeb°æ±¾µÄMicrosoft Teams¡£CyberArkÒѾ°ä²¼Á˸÷ì϶µÄ¸ÅÏëÑéÖ¤´úÂ루PoC£©£¬ÑÝʾÈôºÎÌáÒé¹¥»÷¡£Ä¿Ç°£¬MicrosoftÒ²Òѽ¨¸´Á˸÷ì϶£¬²¢ÇÒ°ä²¼ÁËÒ»¸ö²¹¶¡·¨Ê½ÒÔÔ¤·À½«À´³öÏÖÀàËÆÎÊÌâ¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/this-is-how-viewing-a-gif-in-microsoft-teams-triggers-account-hijacking-bug/
3.ºÚ¿ÍαÔìNHS¹ÙÍøÀ´´«²¼Êý¾ÝÇÔÈ¡¶ñÒâÈí¼þ
IT°²È«¹«Ë¾¿¨°Í˹»ù£¨Kaspersky£©·¢ÏÖºÚ¿ÍαÔìÁËÓ¢¹ú¹ú¶ÈÎÀÉú¾Ö£¨NHS£©¹ÙÍø£¬ÒÔ´«²¼Êý¾ÝÇÔÈ¡¶ñÒâÈí¼þ¡£¸ÃÐéÎ±ÍøÕ¾ÖÐÓÐһЩ¼Ù×°³É½¡È«Óйؽ¨ÒéµÄ¶ñÒâÁ´½Ó£¬Ò»µ©Óû§µã»÷²é¿´£¬±ã»áÏÂÔØÒ»¸öÃûΪCOVID19µÄÎļþ¡£¸ÃÎļþÏÖʵÉÏÊÇÒ»¸öÊý¾ÝÇÔÈ¡¶ñÒâÈí¼þ£¬»áÇÔÈ¡Óû§µÄÃÜÂë¡¢ÍÆËã»úÖеÄÎļþ¡¢ä¯ÀÀÆ÷ÖеÄCookieºÍ¸¶¿îÐÅÏ¢¡¢ÒÔ¼°±ÈÌØ±ÒÇ®°üÎļþ¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/hackers-setup-fake-nhs-website-spread-malware/
4.Zscaler·¢ÏÖCOVID-19Óйش¹µö¹¥»÷Ôö³¤ÁË300±¶
Zscaler×êÑÐÈËÔ±ÔÚ3Ô·ݼì²âµ½ÁË38Íò´ÎÒÔCOVID-19ΪÖ÷ÌâµÄÍøÂç´¹µö¹¥»÷£¬ÓëËêÊ×£¨1200´Î£©Ïà±ÈÔö³¤ÁË30000£¥¡£ÔÚÕâЩ¹¥»÷ÖУ¬Õë¶ÔÔ¶³ÌÆóÒµÓû§µÄ´¹µö¹¥»÷Ôö³¤ÁË85£¥£¬¶ñÒâÍøÕ¾ºÍ¶ñÒâÈí¼þµÄÊýÁ¿Ôö³¤ÁË25£¥£¬Õë¶ÔÆóÒµÓû§µÄ¹¥»÷Ôö³¤ÁË17£¥¡£×êÑÐÈËÔ±»¹¼ì²âµ½×ÔCOVID-19·¢×÷ÒÔÀ´£¬×ܹ²ÓÐ13Íò¶à¸öÔ̺¬ÓÐCOVID-19¹Ø¼ü×Ö£¨ÀýÈ磬²âÊÔ£¬¿ÚÕÖ£¬Î人£¬ÊÔ¼ÁºÐµÈ£©µÄ¿ÉÒɵÄÐÂ×¢²áÓò£¨NRD£©¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/102244/hacking/coronavirus-themed-attacks-spike.html
5.ÊÓÆµÆ½Ì¨SeaChangeÔâÀÕË÷ÍÅ»ïSodinokibi¹¥»÷
4ÔÂ23ÈÕ£¬BadPackets±¨Â·µ½¿ç¹úÊÓÆµÆ½Ì¨SeaChangeÔâµ½ÀÕË÷Èí¼þÍÅ»ïSodinokibi¹¥»÷£¬¿ÉÄܻᵼÖÂÊý¾Ýй¶ÎÊÌâ¡£BadPackets·¢ÏÖ£¬´Ó2019Äê4ÔÂ24ÈÕµ½2020Äê3ÔÂ24ÈÕ£¬SeaChangeµÄPulse Secure VPN·þÎñÆ÷Ò»Ïò´æÔÚ·ì϶£¨CVE-2019-11510£©¡£SodinokibiÍÅ»ïÀûÓô˷ì϶µÁÈ¡µÄÊý¾ÝÔ̺¬SeaChange·þÎñÆ÷ÖÐÎļþ¼Ó×¢±£ÏÕÖ¤Êé¡¢¼ÝÊ»ÅÆÕÕÒÔ¼°ÇóÖ°Ðŵȡ£Ä¿Ç°Éв»Ã÷ÏÔ¸ÃÍÅ»ïÏò¹«Ë¾Ë÷ÒªµÄÊê½ðÊý¶î£¬µ«ÊǸÃÍŻﰵʾֻ½ÓÊÜMonero¼ÓÃÜÇ®±Ò¶ø²»½ÓÊܱÈÌØ±Ò£¬ÓÉÓÚͨ¹ýTorÄäÃûÍøÂç½øÐÐÂòÂôÄܹ»Ôö³¤×ʽð×·×ÙµÄÄѶȡ£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/102177/cyber-crime/seachange-sodinokibi-ransomware.html
6.Å·ÃËÍøÕ¾GDPR.EU´æÔÚ·ì϶£¬µ¼ÖÂÊý¾Ýй¶
½üÈÕ£¬×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸ö¹«¿ªµÄ.gitÎļþ¼Ð£¬¸ÃÎļþ¼ÐÖÐÔ̺¬ÓÐGDPR.EUÍøÕ¾µÄÃÜÂëÒÔ¼°ÆäËû¾ßÌåÐÅÏ¢¡£GDPR.EU ÊÇÅ·ÃËΪʩÐÓ׶ͨÓÃÊý¾Ý±£»¤ÌõÀý¡·£¨GDPR£©µÄ×éÖ¯ÌṩÕ÷ѯµÄÍøÕ¾£¬ÓÉProton Technologies AGÔËÓª¡£Pen Test Partners×êÑÐÈËÔ±°µÊ¾£¬Õâ´ÎÊý¾Ýй¶ÊÇÓÉÓÚÍøÕ¾ÅäÖÃÎÊÌâ£¬ÍøÕ¾¿ª·¢ÈËԱʹÓÃÁË¿ªÔ´µÄGit¿ª·¢¹¤¾ßÀ´´î½¨ÆäÒ³Ãæ£¬µ«ÊÇûÓжÔ.gitÎļþ¼Ð½øÐб£»¤£¬µ¼Ö¸ÃÎļþÔÚÊÀ½çÁìÓòÄڵĹ«¹²ÍøÂçÉϿɶÁ¡£Õâ´Îй¶µÄÊý¾ÝÔ̺¬Ô´´úÂë¡¢·þÎñÆ÷½Ó¼ûÃÜÂë¡¢Êý¾Ý¿âÃÜÂë¡¢ÍйÜÎļþ¡¢¼ÓÃÜÑεȡ£¾ÝϤ£¬Proton Technologies¹«Ë¾ÒѾÔÚ·¢ÏÖ·ì϶µÄËÄÌìºó½¨¸´Á˸÷ì϶£¬²¢ÇÒɾ³ýÁËGitĿ¼ÒÔÌá¸ßÆä°²È«ÐÔ¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/data-leak-gdpr-advice-site/155199/


¾©¹«Íø°²±¸11010802024551ºÅ