˼¿Æ°ä²¼¶àÖÖ²úÆ·µÄ°²È«¸üУ¬½¨¸´´úÂëÖ´Ðзì϶£»Ghost Squad¹¥»÷Å·ÖÞº½Ìì¾Ö(ESA)£¬ÍøÕ¾ÁÙʱÎÞ·¨½Ó¼û

°ä²¼¹¦·ò 2020-07-17

1.˼¿Æ°ä²¼¶àÖÖ²úÆ·µÄ°²È«¸üУ¬½¨¸´´úÂëÖ´Ðзì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


˼¿Æ°ä²¼Á˰²È«¸üУ¬½¨¸´Ó°Ïì¶à¸ö²úÆ·µÄ·ì϶£¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÀûÓÃÆäÖеÄijЩ·ì϶À´½ÚÔìÊÜÓ°Ïìϵͳ ¡£Õâ´Î½¨¸´µÄ½ÏΪÑϳÁµÄ·ì϶Ô̺¬Ó×ÐÍÆóÒµ·À»ðǽRV110W Wireless-N VPN¾²Ì¬Ä¬ÈÏÍ´´¦·ì϶£¨CVE-2020-3330£©¡¢Ó×ÐÍÆóҵ·ÓÉÆ÷RV110W¡¢RV130¡¢RV130WºÍRV215WÖÎÀí½Ó¿ÚÔ¶³ÌºÅÁîÖ´Ðзì϶£¨CVE-2020-3323£©¡¢RV110W¡¢RV130¡¢RV130WºÍRV215W·ÓÉÆ÷Éí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2020-3144£©¡¢RV110WºÍRV215WϵÁзÓÉÆ÷ËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2020-3331£©£¬ÒÔ¼°Cisco Prime License ManagerÌØÈ¨Éý¼¶·ì϶£¨CVE-2020-3140£© ¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/07/15/cisco-releases-security-updates-multiple-products


2.Ghost Squad¹¥»÷Å·ÖÞº½Ìì¾Ö(ESA)£¬ÍøÕ¾ÁÙʱÎÞ·¨½Ó¼û


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ºÚ¿Í×éÖ¯Ghost Squad Hackers¹¥»÷ÁËÅ·ÖÞº½Ìì¾Ö(ESA)£¬²¢µ¼ÖÂÆäÍøÕ¾ÁÙʱÎÞ·¨½Ó¼û ¡£ÔÚÕâ´Î¹¥»÷ÖУ¬ºÚ¿ÍÀûÓ÷þÎñÆ÷ÖеķþÎñÆ÷¶ËÒªÇóαÔ죨SSRF£©Ô¶³Ì´úÂëÖ´Ðзì϶£¬»ñµÃÁ˶Ôbusiness.esa.intÓòµÄ½Ó¼ûȨ²¢¶ÔÆä½øÐÐÁË·ÛËé ¡£¸Ã×éÖ¯³ÉÔ±s1ege°µÊ¾£¬ËûÃÇÊǺڿÍÖ÷ÒåÕߣ¬Í¨³£»áÒò¼¤½øÖ÷ÒåµÄÔ­ÒòÌáÒé¹¥»÷£¬¶øÕâ´Î¹¥»÷´¿ÕýÊdzöÓÚÓéÀÖÖ÷ÕÅ ¡£¸Ã×éÖ¯ÔÚ½ü¼¸ÄêÒѾ­ÈëÇÖÁ˺ܶà×éÖ¯ºÍµ±¾Ö»ú¹¹£¬Ô̺¬ÃÀ¾ü¡¢Å·ÃË¡¢»ªÊ¢¶ÙÌØÇø¡¢ÒÔÉ«Áйú·À¾ü¡¢Ó¡¶Èµ±¾ÖºÍһЩÖÐÑëÒøÐÐ ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/105918/hacktivism/european-space-agency-esa-site-defacement.html?utm_source=rss&utm_medium=rss&utm_campaign=european-space-agency-esa-site-defacement


3.Å·ÖÞ³öÏÖÐÂÐ͵ÄATMºÚºÐ¹¥»÷£¬Õë¶ÔProCash 2050xe ATMÖÕ¶Ë


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ATMÔì×÷ÉÌDiebold NixdorfÖÒ¸æÒøÐУ¬×î½üÔÚÅ·ÖÞ·¢ÏÖÁËÒ»ÖÖÐÂÐ͵ÄATMºÚºÐ¹¥»÷£¬ÕâÊÇÒ»ÖÖÍ·½±£¨Jackpotting£©¹¥»÷£¬Ôâµ½¹¥»÷µÄATM »áÏñÖÐÁËÍ·½±µÄÀÏ»¢»úÒ»Ñù£¬²»ÐÝͳöÏֽ𠡣´ËÐÂÐ͹¥»÷½öÕë¶ÔProCash 2050xe ATMÖÕ¶Ë£¬¹¥»÷Õßͨ¹ýUSB¶Ë¿ÚÏνӵ½É豸 ¡£ºÚ¿ÍÊ×ÏÈ·ÛË鲿ÃŽṹÒÔ±ã½øÈë»úеÄÚ²¿£¬½ÓÏÂÀ´°ÎµôCMD-V4·ÖÅäÆ÷ºÍרÓõç×ÓÉ豸֮¼äµÄUSBÏߣ¬»òÕßרÓõç×ÓÉ豸ºÍATM PCÖ®¼äµÄÏߣ¬²¢½«ÕâÌõÏßÏνӵ½¹¥»÷ÕߵĺںУ¬ÒÔ·¢ËÍ·¸·¨ºÅÁî ¡£Ä¿Ç°£¬¸Ã¹«Ë¾ÔÚµ÷²éºÚ¿ÍÊÇÈôºÎ»ñµÃÕâЩÁã¼þµÄ ¡£    


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/diebold-nixdorf-warns-of-a-new-class-of-atm-black-box-attacks-across-europe/#ftag=RSSbaffb68


4.кóÃÅBazarÓëTrickbotÓйØ£¬Õë¶ÔµÄÖ¸±êÊÇÃÀ¹úºÍÅ·ÖÞ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Cybereason Nocturnus×êÑÐÓ××é·¢ÏÖÁËкóÃÅBazarÓëTrickbotÓйØ£¬×Ô½ñÄê4ÔÂÒÔÀ´£¬¸ÃºóÃÅÒѱ»ÓÃÓÚ¹¥»÷ÃÀ¹úºÍÅ·ÖÞµÄÖ¸±ê£¬³ö¸ñÊÇÒ½ÁƱ£½¡¡¢IT¡¢Ôì×÷¡¢ÎïÁ÷ºÍÓÎÀÀÐÐÒµµÄ×éÖ¯ ¡£ÔÚ¾àÀëÁ½¸öÔºó£¬6Ô³öÏÖÁ˸úóÃŵÄÐÂÑù±¾£¬ÒÔ¼°¸Ä½øµÄ´úÂëºÍ½¨¸´·¨Ê½ ¡£¸ÃºóÃÅÓëTrickbot¼ÓÔØ·¨Ê½ÓµÓÐÀàËÆµÄ´úÂ룬Ô̺¬Ò»ÑùµÄWinAPI¡¢×Ô½ç˵RC4ʵÏֺͷ±ËöµÄ»ìºÏ ¡£¼ÓÃܵÄBazar»áÖ±½Ó¼ÓÔØµ½ÄÚ´æÖУ¬ÒÔ¶ã±Üɱ¶¾Èí¼þµÄ¼ì²â ¡£Ä¿Ç°Òѱ»¼ì²âµ½µÄBazarÓÐÈý¸ö°æ±¾£¬´¦ÓÚ·ÖÆçµÄ¿ª·¢½×¶Î£¬Ô̺¬ÍøÂçºÍÇÔȡϵͳÊý¾Ý¡¢ÓëÖ¸»Ó½ÚÔì(C2)³ÉÁ¢ÏνÓ£¬ÒÔ¼°Ö´ÐжàÖÖÖ°ÄÜ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/new-bazar-backdoor-linked-to-trickbot-banking-trojan-campaigns/


5.Ó¡Äṫ˾BhinnekaÔâµ½¹¥»÷£¬Ð¹Â¶³¬¹ý100Íò¸öÕÊ»§ÐÅÏ¢


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Hackread.com·¢ÏÖ£¬Ó¡ÄáÔÚÏßÉ̳ÇBhinnekaÔâµ½¹¥»÷й¶³¬¹ý100Íò¸öÕÊ»§ÐÅÏ¢ ¡£¾ÝϤ£¬Õâ´ÎÊÂÎñй¶ÁËÁ½¸öSQLÎļþ£¬×ܹ²Ô̺¬Ô¼Äª1262300¸öÕÊ»§µÄ¼Í¼ÐÅÏ¢ ¡£Ð¹Â¶ÐÅÏ¢Ô̺¬Î¨Ò»µÄID¡¢È«Ãû¡¢µç×ÓÓʼþµØÖ·¡¢ÐÔ±ð¡¢ÁªÏµµç»°¡¢ÃÜÂë¡¢¾ßÌ嵨ַ¡¢µ®ÉúÈÕÆÚ¡¢É罻ýÌåID¡¢ÈÕÖ¾¾ßÌåÐÅÏ¢¡¢Óû§Éí·Ý£¨ÊÇÖÎÀíÔ±»¹Êǹ¤×÷ÈËÔ±£©£¬»¹¿ÉÄÜÔ̺¬Ô±¹¤¾ßÌåÐÅÏ¢ ¡£¾ÝϤ£¬Õâ´Î¹¥»÷²úÉúÓÚ½ñÄê1ÔÂ27ÈÕ£¬ºÚ¿Í×î³õÊÔͼͨ¹ýÀÕË÷Êê½ð»òÏúÊÛÒÔ»ñÈ¡ÀûÒæ£¬µ«²»Öª³öÓÚºÎÖÖÔ­Òò£¬ºÚ¿Í×îºó½«ÆäÃâ·Ñ¹«¿ªÔÚÁËÍøÂçÉÏ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/indonesia-bhinneka-database-dumped-1-million-accounts/


6.Kaspersky»ã±¨£¬4¿î°ÍÎ÷ÒøÐÐľÂíÕë¶ÔÈ«Çò½ðÈÚ»ú¹¹


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Kaspersky»ã±¨£¬½éÉÜÁËÕë¶ÔÈ«Çò½ðÈÚ»ú¹¹µÄ4¿î°ÍÎ÷ÒøÐÐľÂí ¡£ÕâЩľÂíÔ̺¬Guildma¡¢Javali¡¢MelcozºÍGrandoreiro£¬ËüÃÇÒѾ­½ø»¯³öÁ˳äÈκóÃŵÄÄÜÁ¦£¬²¢Ñ¡È¡Á˸÷Àà»ìºÏ¼¼ÊõÀ´°µ²ØÆä¶ñÒâ»î¶¯£¬Ê¹Æä²»±»°²È«Èí¼þ·¢ÏÖ ¡£Kaspersky×êÑÐÈËÔ±½«ËüÃÇͳ³ÆÎªTetrade£¬²¢Ö¸³öÆä¿ÉÄÜÒѾö¶¨½«¹¥»÷À©´óÖÁº£±í ¡£GuildmaºÍJavali¾ùѡȡ¶à½×¶Î¶ñÒâÈí¼þ²¿Êð¹ý³Ì£¬Ê¹ÓÃÍøÂç´¹µöµç×ÓÓʼþ×÷Ϊ·Ö·¢³õʼÓÐÐ§ÔØºÉµÄ»úÔì ¡£MelcozÊÇ¿ªÔ´RATÔ¶³Ì½Ó¼ûPCµÄÒ»ÖÖ±äÌ壬ÇÔÈ¡ÃÜÂëºÍ±ÈÌØ±ÒÇ®°ü ¡£Grandoreiro»áʹÓÃÓòÌìÉúËã·¨£¨DGA£©°µ²Ø¹¥»÷¹ý³ÌÖÐʹÓõÄC2µØÖ·£¬²¢½«ÆäÍйÜÔÚGoogleÕ¾µãÒ³ÃæÉÏ£¬Í¨¹ýÊÜϰȾµÄÍøÕ¾ºÍGoogle Ads£¬»òÓã²æÊ½ÍøÂç´¹µö½øÐзַ¢ ¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/the-tetrade-brazilian-banking-malware/97779/