¹È¸è°ä²¼ÁËÕë¶ÔAndroid OSµÄ°²È«¸üУ¬½¨¸´¶à¸ö·ì϶£»Ô¼¿Ë´óѧÔâºÚ¿Í¹¥»÷£¬¶à¸ö·þÎñÆ÷ºÍ¹¤×÷Õ¾±»·ÛËé
°ä²¼¹¦·ò 2020-05-061.¹È¸è°ä²¼ÁËÕë¶ÔAndroid OSµÄ°²È«¸üУ¬½¨¸´¶à¸ö·ì϶
¹È¸èÓÚ±¾Öܰ䲼ÁË2020Äê5ÔÂÕë¶ÔAndroid²Ù×÷ϵͳµÄ°²È«²¹¶¡£¬×ܹ²½¨¸´ÁË39¸ö·ì϶£¬¸Ã°²È«¸üÐÂ×ܹ²Ô̺¬Á½²¿ÃÅ£¬ÆäÖÐ2020-05-01°²È«²¹¶¡·¨Ê½½¨¸´ÁË15¸ö·ì϶£¬¶ø2020-05-05°²È«²¹¶¡·¨Ê½½¨¸´ÁË24¸ö·ì϶¡£Õâ´Î½¨²¹µÄ·ì϶ÖÐ×îÑϳÁµÄÒ»¸ö·ì϶±»×·×ÙΪCVE-2020-0103£¬ÆäÓ°ÏìÁËAndroid 9ºÍAndroid 10£¬ËüÄÜʹԶ³Ì¹¥»÷ÕßÖ´ÐÐËÁÒâ´úÂë¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/androids-may-2020-patches-fix-critical-system-vulnerability
2.ºÚ¿Í¼Ù×°³ÉFINRA¹ÙÔ±ÌáÒé´¹µö¹¥»÷ÒÔÇÔÈ¡Óû§ÐÅÏ¢
ÃÀ¹ú½ðÈÚÒµ¼à¹Ü¾Ö£¨FINRA£©ÖÒ¸æËµ£¬Ä¿Ç°ÓкڿÍÔÚ¼ÙÒâ¼à¹Ü¾ÖµÄ¹ÙÔ±£¬°ä²¼ÍøÂç´¹µöµç×ÓÓʼþ¡£ÕâЩÓʼþÓòÃû¾ùΪ¡°broker-finra[.]org,¡± £¬²¢ÇÒÓʼþÖÐÒªÇóÊÕ¼þÈ˵ã»÷¡°µ±¼´¹Ø×¢¡±µÄÁ´½Ó£¬ÒÔ½«Êܺ¦Õß³Á¶¨Ïòµ½ÍøÂç´¹µöÍøÕ¾£¬Ö¼ÔÚÇÔÈ¡ÆäMicrosoft Office»òSharePointÃÜÂë¡£FINRAÃ÷È·°µÊ¾ËûÃÇÔÚ½ø¹¥Õâ´Î´¹µö»î¶¯£¬²¢ÖÒ¸æÓû§broker-finra[.]orgÓë¼à¹Ü¾Ö²¢ÎÞ¹ØÏµ£¬¹«Ë¾¸Ãµ±¼´É¾³ý´ËÓòÃûµÄËùÓеç×ÓÓʼþ¡£
ÔÎÄÁ´½Ó£º
https://www.tripwire.com/state-of-security/security-data-protection/digital-fraudsters-masquerading-as-finra-in-phishing-emails/
3.¶ñÒâÈí¼þKaijiͨ¹ýSSH±©Á¦¹¥»÷Õë¶ÔLinux·þÎñÆ÷ºÍIoTÉ豸
°²È«×êÑÐÈËÔ±·¢ÏÖÁËÒ»ÖÖеĶñÒâÈí¼þKaiji£¬¸Ã¶ñÒâÈí¼þͨ¹ýSSH±©Á¦¹¥»÷£¬×¨ÃÅϰȾ»ùÓÚLinuxµÄ·þÎñÆ÷ºÍÖÇÄÜÎïÁªÍø£¨IoT£©É豸£¬¶øºóÀûÓÃÕâЩÉ豸ÌáÒéDDoS¹¥»÷¡£¸Ã¶ñÒâÈí¼þÓëÆäËûIoT¶ñÒâÈí¼þµÄÀàÐÍÓкܴó·ÖÆç£¬ËüÊÇʹÓÃGo±àдµÄ¶ø²»ÊÇC»òC ++¡£Intezer×êÑÐÈËÔ±×êÑз¢ÏÖ£¬¸ÃÈí¼þÊÇͨ¹ýSSH±©Á¦¹¥»÷½øÐд«²¼µÄ£¬¶Ô±©Â©ÁËSSHµÄIoTÉ豸ºÍLinux·þÎñÆ÷Ö´Ðб©Á¦¹¥»÷²¢ÇÒÖ»Õë¶ÔrootÓû§¡£Ä¿Ç°£¬KaijiÒѾÔÚÒ°±í±»ÀûÓ㬲¢ÔÚÊÀ½çÁìÓòÄÚ»ºÂý´«²¼£¬¸ÃÈí¼þ»¹ÔÚ²»ÐÝ¿ª·¢ÖС£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/new-kaiji-malware-targets-iot-devices-via-ssh-brute-force-attacks/
4.ÐÂÀÕË÷Èí¼þVCryptͨ¹ý7zip¼ÓÃÜÎļþ£¬Õë¶Ô·¨¹úÓû§
BleepingComputer·¢ÏÖÁËÒ»ÖÖеÄÃûΪVCryptµÄÀÕË÷Èí¼þ£¬Ëüͨ¹ýÀûÓÃ7zipºÅÁîÐз¨Ê½À´¼ÓÃÜÎļþ£¬²¢ÇÒÕë¶ÔµÄÊÇ·¨¹úÊܺ¦Õß¡£¸ÃÀÕË÷Èí¼þ½«É¾³ýÊܺ¦ÕßWindowsÎļþ¼ÐÖÐËùÓеÄÎļþ£¬¶øºó´´½¨ÒÔ¸ÃÎļþ¼ÐÃû¶¨ÃûµÄ¼ÓÃÜÎļþ£¬ÕâЩ¼ÓÃܵÄÎļþÊÇÒÔusername_foldername.vxcryptµÄÌåʽ¶¨ÃûµÄ¡£´Ë±í£¬ÀÕË÷Èí¼þÆô¶¯ºó£¬Internet ExplorerÖлáÏÔʾÓ÷¨Óï±àдµÄÃûΪhelp.htmlµÄÀÕË÷ÐÅÏ¢¡£Ä¿Ç°£¬Éв»Ã÷ÏÔÕâ´Î¹¥»÷ÊÇÈôºÎ·Ö·¢¸ÃÀÕË÷Èí¼þ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-vcrypt-ransomware-locks-files-in-password-protected-7zips/
5.Florentine BankerÍÅ»ïÀûÓô¹µö¹¥»÷µÁÈ¡ÁË50¶àÍòÓ¢°÷
·ðÂÞÂ×ÈøÒøÄÚÐм¯ÍÅ£¨Florentine Banker£©ÒÔÓ¢¹úºÍÒÔÉ«ÁнðÈÚÒµµÄÈý¸ö´óÐÍ×éÖ¯×÷Ϊָ±ê£¬ÀûÓÃÁËÆóÒµµç×ÓÓʼþÍ×У¨BEC£©Ú²ÆµÄ·½Ê½£¬µÁÈ¡Á˳¬¹ý50ÍòÓ¢°÷¡£Ê×ÏÈ£¬¸Ã´¹µö»î¶¯Õë¶ÔµÄÊÇÖ¸±ê»ú¹¹ÖеÄÊ×ϯִÐй١¢Ê×ϯ²ÆÕþ¹ÙºÍÆäËûÓÐȨ´ú±í¸Ã×éÖ¯½øÐÐ×ʽð×ªÒÆµÄÓ×ÎÒ¡£¶øºó¹¥»÷Õßͨ¹ý×êÑÐÊܺ¦Õߵĵç×ÓÓʼþ£¬ÒÔÏàʶÕâЩ×éÖ¯ÖеĻã¿îÁ÷³Ì¡£×îºó£¬¸ÃÍÅ»ï½øÐÐÁËËÄ´ÎÂòÂô³¢ÊÔ£¬ÊÔͼ½«110ÍòÓ¢°÷תÈëËûÃǵÄÒøÐÐÕÊ»§¡£×îÖÕ£¬±»µÁ½ð¶îÖÐÖ»ÓÐ57ÍòÓ¢°÷±»×·»Ø£¬Õâ´Î¹¥»÷¸øÕâЩ×éÖ¯Ôì³ÉÔ¼60ÍòÓ¢°÷µÄËðʧ¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/the-florentine-banker-group-tricks-banks-in-a-half-million-gbp-heist-01a5ba79/?web_view=true
6.Ô¼¿Ë´óѧÔâºÚ¿Í¹¥»÷£¬¶à¸ö·þÎñÆ÷ºÍ¹¤×÷Õ¾±»·ÛËé
Ô¼¿Ë´óѧÔÚÒ»·ÝÉêÃ÷ÖÐ˵£¬ÆäѧÌÃÓÚÉÏÖÜÎåÍíÉÏÔâµ½Á˺ڿ͵Ĺ¥»÷£¬ÆäºÜ¶à·þÎñÆ÷ºÍ¹¤×÷Õ¾±»·ÛËé¡£¶ø¸Ã´óѧÔÚ¹¥»÷ÆðÍ·ºó£¬Ñ¸¿ì¶Â½ØÁËѧÌõĻ¥ÁªÍø²¢¹Ø¹ØÁ˺ܶàÔÚÏß·¨Ê½£¬ÒÔ¼õÇá¹¥»÷µÄÁìÓòºÍÑϳÁÐÔ¡£½ØÖÁ±¾ÖÜÒ»ÏÂÎ磬ÆäÖÐһЩϵͳÈÔ´¦ÓÚÀëÏß״̬£¬Ô̺¬Ñ§ÌõÄÃÅ»§ÍøÕ¾¡£Ô¼¿Ë´óѧ°µÊ¾£¬ÔÚµ÷²é´ËÊÂÎñ£¬Ò²ÔÚÖÂÁ¦ÒÔ¾¡¿ì¸´ÔÔ¼¿Ë´óѧµÄÔÚÏßϵͳ£¬²¢½¨ÒéϵͳÓû§³ÁÐÂÉèÖÃÃÜÂë¡£
ÔÎÄÁ´½Ó£º
https://www.cbc.ca/news/canada/toronto/york-university-cyber-attack-1.5555106


¾©¹«Íø°²±¸11010802024551ºÅ