VMware½¨¸´Fusion¡¢VMRCºÍHorizo??n ClientÖеÄÌáȨ·ì϶£»¼ÓÄôóËÄËù¾üУÔâµ½¹¥»÷µ¼ÖÂÍøÂçÖжÏ
°ä²¼¹¦·ò 2020-07-131.VMware½¨¸´Fusion¡¢VMRCºÍHorizon ClientÖеÄÌáȨ·ì϶
VMware°ä²¼Á˰²È«¸üУ¬½¨¸´ÁËÒ»¸öȨÏÞÌáÉý·ì϶£¬¸Ã·ì϶ӰÏìÁËVMware Fusion¡¢ Mac°æ±¾µÄRemote ConsoleºÍHorizon Client£¬¹¥»÷Õß¿ÉÀûÓô˷ì϶À´½ÚÔìÊÜÓ°Ïìϵͳ¡£¸Ã·ì϶ÊÇÓÉÓÚXPC¿Í»§¶ËÑéÖ¤²»ÕýÈ·µ¼Öµģ¬³É¹¦ÀûÓô˷ì϶¿ÉʹӵÓÐͨ³£Óû§È¨Ï޵Ĺ¥»÷Õß½«ÆäȨÏÞÌáÉýµ½ÏµÍ³ÉϵÄrootÓû§¡£¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ7.8¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2020/07/10/vmware-releases-security-updates-multiple-products
2.¼ÓÄôóËÄËù¾üУÔâµ½¹¥»÷µ¼ÖÂÍøÂçÖжϣ¬¶¯»úÉв»Ã÷È·
¼ÓÄôóËÄËù¾üУÔâµ½¹¥»÷µ¼ÖÂÍøÂçÁÙʱ̱»¾£¬Ä¿Ç°¶¯»úÉв»Ã÷ÏÔ¡£Õâ´ÎÔâµ½¹¥»÷µÄѧÌñðÀëΪ½ð˹¶ØµÄ»Ê¼Ò¾üÊÂѧԺ¡¢¿ý±±¿ËµÄRMC Saint-Jean¡¢¶àÂ×¶àµÄ¼ÓÄôó¶ÓÁÐѧԺºÍÂÞ²®ÌذÂÈüµÂѧԺµÄChief Warrant Officer£¬ÕâЩѧÌõÄÖ÷Ìâϵͳ¾ùÔâµ½Á˹¥»÷¡£Æ¾¾ÝRMC¸±½ÌÊÚGreg PhillipsÔÚ7ÔÂ6ÈÕ°ä·¢µÄ²©¿ÍÎÄÕ£¬Õâ´Î¹¥»÷ÖеĶñÒâÈí¼þÀûÓÃÁ˰²È«·ì϶½øÐÐ×ÔÎÒ×°Ö㬶øºó¶Ô´ÅÅÌÄÚÈݽøÐмÓÃÜ£¬´Ó¶øÊ¹ÆäÎÞ·¨½Ó¼û¡£²¢ÒÔΪ¸ÃÊÂÎñΪÀÕË÷Èí¼þ¹¥»÷£¬µ«»Êºó´óѧ½ÌÊÚSkillicornÔòÒÔΪÊÇÆäËû¹ú¶ÈÊÔͼÈüÓÄô󵱾ÖÄÑ¿°¡£Ä¿Ç°£¬Ñ§ÌÃÍøÂçÒÀÈ»ÔÚ¸´ÔÖС£
ÔÎÄÁ´½Ó£º
https://www.kingstonist.com/news/motives-unclear-as-cyber-attack-shuts-down-rmc-network/
3.¶ñÒâÈí¼þÔö³¤Any.RunɳÏä¼ì²âÖ°ÄÜÒÔÌӱܷÖÎö
°²È«×êÑÐÔ±JAMESWT·¢ÏÖ¶ñÒâÈí¼þÐÂÔöÁËAny.RunɳÏä¼ì²âÖ°ÄÜ£¬ÒÔÌÓ±Ü×êÑÐÈËÔ±µÄ·ÖÎö¡£JAMESWT·¢´Ë¿ÌеÄÀûÓÃÀ¬»øÓʼþ·Ö·¢ÃÜÂëÇÔȡľÂíµÄ»î¶¯ÖУ¬¹¥»÷Õ߻ὫÁ½¸öPowerShell¾ç±¾ÏÂÔØµ½Êܺ¦ÕßµÄÍÆËã»ú¡£¶ñÒâÈí¼þÔÚÔËÐеڶþ¸ö¾ç±¾Ê±£¬Ê×ÏȽ«³¢ÊÔÆô¶¯ÃÜÂëÇÔȡľÂíAzorult£¬ÈôÊǼì²âµ½¸Ã·¨Ê½ÔÚAny.RunÉÏÔËÐУ¬±ã»áÏÔʾÐÂÎÅ¡° Any.run Deteceted£¡¡±£¬¶øºóÍ˳ö¡£Í¨¹ýÕâÖÖ²½Ö裬ºÚ¿Íʹ×êÑÐÈËÔ±Ô½·¢ÄÑÒÔʹÓÃ×Ô¶¯»¯ÏµÍ³À´·ÖÎöÆä¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/malware-adds-anyrun-sandbox-detection-to-evade-analysis/
4.Òò´æÔÚ°²È«·çÏÕ£¬Amazon½¨ÒéÔ±¹¤É¾³ýTikTokÀûÓÃ
AmazonÏòÆäÔ±¹¤·¢Ë͵ç×ÓÓʼþ£¬ÒªÇó±ØÐëÔÚ7ÔÂ10ÈÕ֮ǰ´ÓÆäÉ豸ÖÐɾ³ýTikTokÀûÓ÷¨Ê½¡£¸Ãµç×ÓÓʼþÖÐÌᵽʹÓÃTikTokÀûÓ÷¨Ê½´æÔÚ°²È«·çÏÕ£¬µ«Î´¾ßÌå×¢Ã÷ÊǺÎÖÖ·çÏÕ¡£ÔÚÕâÖ®ºó£¬7ÔÂ10ÈÕAmazon°µÊ¾¸Ã²»ÈÝʹÓÃTikTokµÄµç×ÓÓʼþÊÇÎ󷢵ģ¬ÈÔ½«ÔÊÐíÔ±¹¤ÔÚÆäÉ豸ÉÏʹÓøÃÀûÓ÷¨Ê½¡£ºÜ¶àÈËÔð¹Ö¸ÃÀûÓ÷¨Ê½´ÓÓû§ÄÇÀïÍøÂçÐÅÏ¢²¢½«Æä´«µÝ¸øÖйúµ±¾Ö£¬µ«¸ÃÐÂÎÅ´ÓδµÃµ½Ö¤Êµ¡£×ÔÈ¥ÄêÒÔÀ´£¬TikTok±»ÃÀ¹ú¾ü·½¡¢Ó¡¶Èµ±¾ÖºÍÓ¡¶È¾ü¶ÓµÈ²»ÈÝʹÓá£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/amazon-tells-employees-to-remove-tiktok-from-their-phones-due-to-security-risk/#ftag=RSSbaffb68
5.×êÑÐÔ±·¢ÏÖ¶ñÒâÈí¼þTrickBot·Ö·¢Æä²âÊÔ°æ±¾
Ó¢ÌØ¶û¹«Ë¾µÄVitali KremezÔÚ·ÖÎöTrickBot¶ñÒâÈí¼þµÄ×îа汾ʱ·¢ÏÖ£¬ºÚ¿ÍÃýÎóµÄ·Ö·¢ÁËÆäÓÃÓÚÇÔÈ¡ÃÜÂëµÄÄ£¿égrabber.dllµÄ²âÊÔ°æ±¾¡£¼ÓÔØºó¸Ã²âÊÔ°æ±¾ºó£¬´ËÄ£¿é½«ÔÚĬÈÏä¯ÀÀÆ÷ÖÐÏÔʾÖҸ棬ָ³ö¸Ã·¨Ê½ÔÚÍøÂçÐÅÏ¢£¬²¢ÌáÐÑÊܺ¦Õ߸õ±¼´Õ÷ѯÆäϵͳÖÎÀíÔ±¡£Kremez°µÊ¾£¬¸Ã²âÊÔÄ£¿éËÆºõÓÉTrickBot¿ª·¢ÈËÔ±¿ª·¢µÄ£¬ÓÉÓÚËüÓëÆäËûÄ£¿é¾ùÊÇÒÔÒ»ÑùµÄ·½Ê½±àÂ룬ËûÒÔΪºÚ¿ÍÔÚ²âÊÔа汾£¬È´½¡ÍüÔÚ°ä²¼ºó½«Æäɾ³ý¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/trickbot-malware-mistakenly-warns-victims-that-they-are-infected/
6.CheckPoint°ä²¼»ã±¨£¬PhorpiexÓ°ÏìÁ¦¼±¾çÔö³¤
CheckPoint°ä²¼ÁËÆä×îеÄ2020Äê6ÔÂÈ«ÇòÍþвָÊý£¬·¢ÏÖPhorpiexÓ°ÏìÁ¦¼±¾çÔö³¤¡£¸Ã½©Ê¬ÍøÂçÒ»ÏòÔÚ·Ö·¢ÐµÄÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©ÀÕË÷Èí¼þAvaddon£¬ÓëÎåÔ·ÝÏà±È£¬ÆäÅÅÃûÉÏÉýÁË13λ£¬Î»ÁжñÒâÈí¼þÅÅÐаñµÄµÚ2룬¶ÔÈ«Çò×éÖ¯µÄÓ°ÏìÁ¦·ÁËÒ»·¬¡£ÔÚ6Ô·ݣ¬Ó°ÏìÁ¦×î´óµÄ¶ñÒâÈí¼þΪ¸ß¼¶RAT Agent Tesla£¬Ó°ÏìÁË3£¥µÄ×éÖ¯£¬Æä´ÎÊǽ©Ê¬ÍøÂçPhorpiexºÍ¿ªÔ´CPUÍÚ¾òÈí¼þXMRig£¬Ó°ÏìÁË2%µÄ×éÖ¯¡£´Ë±í£¬±»ÀûÓÃ×îÑϳÁµÄ·ì϶ΪOpenSSL TLS DTLSÐÄÌøÐÅϢй¶£¬Ó°ÏìÁË45£¥µÄ×éÖ¯£¬Æä´ÎÊÇMVPower DVRÔ¶³Ì´úÂëÖ´Ðзì϶ºÍGit´æ´¢¿âй¶£¬±ðÀëÓ°ÏìÁËÈ«Çò44£¥ºÍ38£¥µÄ×éÖ¯¡£
ÔÎÄÁ´½Ó£º
https://finance.yahoo.com/news/june-2020-most-wanted-malware-100010951.html?&web_view=true


¾©¹«Íø°²±¸11010802024551ºÅ