Mozilla°ä²¼À×Äñ°²È«¸üУ¬½¨¸´¶à¸öÑϳÁµÄ·ì϶£»ÐÂThiefQuest±äÌå»ìºÏÖ°ÄÜÃû³Æ£¬×·×ÙÄѶÈÔö³¤
°ä²¼¹¦·ò 2020-07-201.Mozilla°ä²¼À×Äñ°²È«¸üУ¬½¨¸´¶à¸öÑϳÁµÄ·ì϶
MozillaΪÀ×Äñ£¨Thunderbird£©°ä²¼°²È«¸üУ¬½¨¸´¶à¸öÑϳÁµÄ·ì϶¡£Õâ´Î¸üÐÂÖÐÖØÒª½¨¸´µÄ·ì϶ΪAppCacheÇåµ¥Öеķì϶CVE-2020-12415£¬ÓÉURL±àÂëµÄ×Ö·û´¦ÖÃÎÊÌâµ¼Ö£»WebRTC VideoBroadcasterÖеķì϶CVE-2020-12416£¬¿Éµ¼ÖÂʹÓÿªÊͺóÄÚ´æ°Ü»µ£¬ÒÔ¼°Ç±ÔڵĿÉÀûÓñÀÀ££»ÓÉÓÚ¶ÌȱARM64ÉÏValueTagµÄ·ûºÅÀ©´óÃû¶øµ¼ÖµÄÄÚ´æ°Ü»µ·ì϶CVE-2020-12417£»ÐÅϢй¶·ì϶CVE-2020-12418£¬¿Éµ¼ÖÂÔ½½ç¶ÁÈ¡£¬´Ó¶øÊ¹¹ý³ÌÄÚ´æÐ¹Â©¸ø¶ñÒâJavaScript£»nsGlobalWindowInnerÖеĿªÊͺóʹÓ÷ì϶CVE-2020-12419£¬¿Éµ¼ÖÂÄÚ´æ°Ü»µºÍDZÔڵĿÉÀûÓñÀÀ££»STUN·þÎñÆ÷ÖпªÊͺóʹÓÃCVE-2020-12420¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2020/07/17/mozilla-releases-security-update-thunderbird
2.ÐÂThiefQuest±äÌå»ìºÏÖ°ÄÜÃû³Æ£¬×·×ÙÄѶÈÔö³¤
×êÑÐÈËÔ±·¢ÏÖmacOS¶ñÒâÈí¼þThiefQuestµÄбäÌåÐÂÔöÁ˶à¶àÖ°ÄÜ£¬ÀýÈç»ìºÏÖ°ÄÜÃû³Æ£¬Ê¹×·×ÙÄѶÈÔö³¤¡£´Ë±í£¬¸Ãа汾ÒѾ½«ÆäÀÕË÷Èí¼þÐÐΪ£¬ÈçÎļþ¼ÓÃܺÍÀÕË÷ְ֪ͨÄÜɾ³ý¡£ÔÚC£¦C IPÌìÉú·½Ã棬бäÌåŲÓÃei_getip£¨£©ÒÔÌìÉúËæ»úÊýIPµØÖ·£¬²¢³¢ÊÔͨ¹ýhttp_request£¨£©Ïνӣ¬ÈôÊdzɹ¦Ôò½«ËüÓÃ×÷C£¦C·þÎñÆ÷µØÖ·¡£Ëü»¹¸Ä½øÁË¿¹·ÖÎö¼¼Êõ£¬ÔÚº¯Êýis_virtual_mchn£¨£©ÖУ¬Ôö³¤ÁËǰÌá²é³£¬Ô̺¬»ñÈ¡»úеµÄMACµØÖ·¡¢CPU¼ÆÊýºÍÎïÀíÄڴ棬ÔÚÆä×Ö·û´®½âÃܺ¯Êýeip_str£¨£©ÖУ¬»¹Ôö³¤ÁË·´·ÖÎö²é³¡£»¹Ôö³¤ÁËÐÂÖ°ÄÜrun_audioºÍrun_image£¬ÄÜͬʱÔËÐÐͼÏñºÍÉùÒôÎļþ£¬Ö¼ÔÚ½«Ö¸±êÎļþ±ðÀë±£Áôµ½°µ²ØµÄ.m4aÉùÒôÎļþ»ò.jpgͼÏñÎļþÖС£
ÔÎÄÁ´½Ó£º
https://blog.trendmicro.com/trendlabs-security-intelligence/updates-on-thiefquest-the-quickly-evolving-macos-malware/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Anti-MalwareBlog+%28Trendlabs+Security+Intelligence+Blog%29
3.Ghost SquadÒ»ÖÜÖ®ÄÚµÚ¶þ´Î¹¥»÷ESAÕ¾µã
¼ÌÉÏÖÜGhost Squad Hackers¹¥»÷²¢ÎÛËðÁËÅ·ÖÞº½Ìì¾Ö£¨ESA£©ÍøÕ¾https://business.esa.int/ºó£¬¸Ã×éÖ¯ÔÚÒ»ÖÜÄÚÓÖµÚ¶þ´Î¶ÔÅ·ÖÞº½Ìì¾Ö£¨ESA£©ÌáÒéÁ˹¥»÷£¬Õë¶ÔÆäÁíÒ»¸öÓòhttps://space4rail.esa.int/index.htmlµÄ¡£ºÚ¿Í°µÊ¾ËûÃÇÔÚESAµÄ·þÎñÆ÷ÉÏ·¢ÏÖÁËÓëÉϴι¥»÷Ò»ÑùµÄ·ì϶£¬µ¼ÖÂRCE (SSRFµ½RCE)£¬²¢ÀûÓÃÆä³É¹¦µÄ¹¥»÷ÁËÁíÒ»¸öÓò¡£¾ÝºÚ¿Í³Æ£¬ESAר¼ÒÉÐ佨¸´¸Ã·ì϶£¬ËûÃÇÖ»ÊÇɾ³ýÁËCMS²¢Ôö³¤ÁËÊØ»¤Ë÷Òý£¬¸Ã·ì϶²¢²»´æÔÚÓÚCMS/webÀûÓ÷¨Ê½ÖУ¬¶øÊÇÓ°ÏìÁË·þÎñÆ÷ÉÏÔÚÖ´ÐеķþÎñ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/106111/hacking/esa-site-defaced-again.html?utm_source=rss&utm_medium=rss&utm_campaign=esa-site-defaced-again
4.ÔÆ·þÎñÉÌBlackbaudÔâÀÕË÷Èí¼þ¹¥»÷£¬²¢ÒÑÖ§¸¶Êê½ð
ÔÆ·þÎñÉÌBlackbaudÔÚÉÏÖÜËݵʾ£¬ÆäÓÚ2020Äê5ÔÂÔâµ½ÁËÀÕË÷Èí¼þ¹¥»÷£¬±ØÐëÖ§¸¶Êê½ðÒÔ±£»¤¿Í»§Êý¾ÝµÄ°²È«¡£Blackbaud˵£¬ºÚ¿Í·ÛËéÁËÆäÍøÂ磬²¢ÊÔͼװÖÃÀÕË÷Èí¼þÒÔËø¶¨·þÎñÆ÷ºÍÓû§Êý¾Ý£¬ËûÃǵݲȫÍŶÓÔÚ·¢ÏÖ¹¥»÷ºóÂíÉÏ×ö³öÁËÏàÓ¦´ëÊ©¡£µ«ÊÇ£¬ºÚ¿ÍÔÚ±»ÇýÖð³öÍøÂç֮ǰ£¬»¹ÊÇÉè·¨´Ó¿Í»§±£ÁôÎļþµÄ×ÔÍйܻ·¾³ÖÐÇÔÈ¡ÁËÒ»²¿ÃÅÊý¾Ý¡£Blackbaud°µÊ¾£¬±£»¤¿Í»§µÄÊý¾ÝÊÇËûÃǵÄÊ×Òª¹¤×÷£¬ËùÒÔËûÃÇÏòÍøÂç×ï·¸Ö§¸¶ÁËÊê½ð£¬²¢È·Èϸ±±¾Òѱ»Ïú»Ù¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/cloud-provider-stopped-ransomware-attack-but-had-to-pay-ransom-demand-anyway/#ftag=RSSbaffb68
5.OrangeÈ·ÈÏÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬¿Í»§Êý¾Ýй¶
·¨¹úµçÐŹ«Ë¾OrangeÈ·ÈÏÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬²¢Ð¹Â¶Á˿ͻ§Êý¾Ý¡£2020Äê7ÔÂ15ÈÕ£¬Nefilim Ransomware ½«OrangeÔö³¤µ½ÆäÊý¾Ýй©վµã£¬²¢°µÊ¾ËûÃÇͨ¹ýÆäOrange Business Solutions²¿ÃŹ¥»÷Á˸ù«Ë¾£¬Õâ´Î¹¥»÷ÖÐNefilimÍÅ»ïÇÔÈ¡ÁË20¸öOrange Pro / SME¿Í»§Êý¾Ý¡£ºÚ¿Í°ä²¼ÁËÒ»¸ö339MBµÄÃûΪ Orange_leak_part1.rarµÄ´æµµÎļþ£¬Ô̺¬´ÓOrangeÇÔÈ¡µÄÊý¾Ý¡¢µç×ÓÓʼþ¡¢·É»úʾÒâͼºÍ·¨¹ú·É»úÔì×÷ÉÌATR AircraftµÄÎļþ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/orange-confirms-ransomware-attack-exposing-business-customers-data/
6.Gartner°ä²¼2020ÄêÍøÂç¼ì²âºÍÏìÓ¦£¨NDR£©Êг¡Ö¸ÄÏ
Gartner°ä²¼ÁË¡¶2020ÄêÍøÂç¼ì²âºÍÏìÓ¦£¨NDR£©Êг¡Ö¸ÄÏ¡·£¬ÆäÖÐ˼¿Æ±»Â¼ÓÃΪ´ú±í¹©¸øÉÌ¡£Gartner°µÊ¾£¬ÔÚ2019Ä꣬Gartner³ÆÖ®ÎªÍøÂçÁ÷Á¿·ÖÎö£¬¶ø½ñÄ꽫Æä³Á¶¨ÃûÎªÍøÂç¼ì²âºÍÏìÓ¦£¬ÓÉÓÚ¸ÃÊõÓï¸üÕýÈ·µØ·´Ó³ÁËÕâЩ½â¾ö¹æ»®µÄÖ°ÄÜ¡£Gartner»¹¶ÔNDR¸ø³öÁ˽ç˵£¬NDR½â¾ö¹æ»®ÖØÒªÊ¹Ó÷ǻùÓÚÊðÃûµÄ¼¼Êõ£¨ÀýÈ磬»úе½ø½¨»òÆäËû·ÖÎö¼¼Êõ£©À´¼ì²âÆóÒµÍøÂçÉϵĿÉÒÉÁ÷Á¿¡£NDR¹¤¾ßÂ½Ðø·ÖÎöÔʼÁ÷Á¿ºÍ/»òÁ÷Á¿¼Í¼£¨ÀýÈçNetFlow£©ÒÔ¹¹½¨·´Ó³Õý³£ÍøÂçÐÐΪµÄÄ£ÐÍ¡£
ÔÎÄÁ´½Ó£º
https://blogs.cisco.com/security/cisco-named-a-representative-vendor-in-the-gartner-market-guide-for-ndr


¾©¹«Íø°²±¸11010802024551ºÅ