Symantec°ä²¼2020ÄêµÚ¶þ¼¾¶ÈÍþÐ²Ì¬ÊÆ»ã±¨£»Î¢Èí½¨¸´Azure Sphere IoTƽ̨ÖеÄ4¸ö·ì϶

°ä²¼¹¦·ò 2020-08-27

1.Symantec°ä²¼2020ÄêµÚ¶þ¼¾¶ÈÍþÐ²Ì¬ÊÆ»ã±¨


1.jpg


ÃÀ¹úÍøÂ簲ȫ³§ÉÌSymantec°ä²¼2020ÄêµÚ¶þ¼¾¶ÈÍþÐ²Ì¬ÊÆ»ã±¨ ¡£»ã±¨ÏÔʾ£¬Óëǰ¼¸¸ö¼¾¶ÈÏà±È£¬2020ÄêµÚ¶þ¼¾¶È¼ÓÃܽٳֵÄÊýÁ¿Ôö³¤ÁË163£¥ ¡£¾ÝÐÂÎÅÈËÊ¿³Æ£¬¼ÓÃܽٳֻÊýÁ¿µÄ¼¤ÔöºÜ¿ÉÄÜÊÇÓÉ·ÓÉÆ÷½©Ê¬ÍøÂçÒýÆðµÄ£¬¶ø´ËÀàÊÂÎñÒÔÇ°Ò²ÔøÔÚÀ­¶¡ÃÀÖÞ²úÉú¹ý ¡£ºÚ¿Í×éÖ¯»áÈëÇÖ¼ÒÓ÷ÓÉÆ÷£¬²¢¸ü¸ÄDNSÉèÖÃÒԽٳֺϷ¨µÄÍøÂçÁ÷Á¿£¬½«±»ÈëÇֵķÓÉÆ÷ÓÃ×÷´úÀí»òÀÄÓÃËüÃÇÀ´ÌáÒéDDoS¹¥»÷ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/browser-based-cryptojacking-sees-sudden-spike-in-activity-in-q2-2020/


2.΢Èí½¨¸´Azure Sphere IoTƽ̨ÖеÄ4¸ö·ì϶


2.jpg


΢Èí°ä²¼·ì϶²¹¶¡£¬½¨¸´Azure Sphere IoTƽ̨ÖеÄ4¸ö·ì϶ ¡£Õâ´Î°ä²¼µÄ²¹¶¡·¨Ê½½¨¸´ÁË2¸öÔ¶³Ì´úÂëÖ´Ðзì϶ºÍ2¸öÌáȨ·ì϶£¬ÕâЩ·ì϶¶¼ÊÇÓÉCisco TalosµÄ°²È«×êÑÐÈËÔ±ÓÚ7Ô·ݷ¢ÏÖ ¡£µÚÒ»¸öΪREAD_IMPLIES_EXEC personalityδÊðÃû´úÂëÖ´Ðзì϶£¬µÚ¶þ¸öRCE·ì϶´æÔÚÓÚ/proc/thread-self/ memÖÐ ¡£´Ë±í£¬È¨ÏÞ½Ó¼û½ÚÔìÖ°ÄÜÖдæÔÚÒ»¸öÌáȨ·ì϶£¬¶øµÚ¶þ¸öÌáȨ·ì϶´æÔÚÓÚAzure Sphere 20.06µÄuid_mapÖ°ÄÜÖÐ ¡£Î¢Èí°µÊ¾»áÈ·±£½â¾öÕâЩÎÊÌⲢΪ¿Í»§Ìṩ¸üУ¬µ«Êǻؾø°ä²¼ÈκÎCVEs ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/four-more-bugs-patched-in-microsofts-azure-sphere-iot-platform/158643/


3.CISAµÈ4¼Ò»ú¹¹ÖҸ泯ÏÊBeagleBoyz¶Ô׼ȫÇòÒøÐÐ


3.jpg


CISA¡¢²ÆÕþ²¿¡¢FBIºÍUSCYBERCOM½áºÏ°ä²¼ÖҸ棬³¯ÏʺڿÍ×éÖ¯BeagleBoyz¶Ô׼ȫÇòÒøÐÐ ¡£¾Ý¼¸¼Ò»ú¹¹°ä²¼µÄ½áºÏÕ÷ѯ»ã±¨£¬×Ô2020Äê2ÔÂÒÔÀ´£¬BeagleBoyzÒ»ÏòÔÚʹÓöñÒâÔ¶³Ì½Ó¼û¹¤¾ßͨ¹ý»¥ÁªÍøÂ°ÂÓÒøÐУ¬Ä¿Ç°ÒÑ´ÓÈ«ÇòÒøÐÐÇÔÈ¡ÁËÊý°ÙÍòÃÀÔª ¡£¾ÝÃÀ¹úÍøÂç˾ÁµÄÍÆÎÄ£¬BeagleBoyzĿǰÔÚ½øÐÐÒ»Ïî³ÖÐøµÄÒøÐаÂÓ´òË㣬Õë¶Ô30¶à¸ö¹ú¶ÈµÄÒøÐУ¬ÊÔͼ°ÂÓ20ÒÚÃÀÔª ¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/alerts/aa20-239a


4.FBI¶úÄ¿Åû¶¼¼ÊõÖ§³¶à¿Æ­ÍÅ»ïµÄÄÚ²¿ÔË×÷Çé¿ö


4.jpg


FBI¶úÄ¿Åû¶¼¼ÊõÖ§³¶à¿Æ­ÍÅ»ïµÄÄÚ²¿ÔË×÷Çé¿ö ¡£¸ÃÃû¶úÖ÷ÕŽÇɫΪ¾­¼ÍÈË£¬ÖØÒªÕƹÜÏúÊÛºô½ÐÁ÷Á¿£¬Îª¸Ã´ËÀàȦÌ׵ĵڶþ½×¶ÎÕÆ¹ÜÈË ¡£µÚÒ»½×¶ÎΪ°ä²¼ÉÌ£¬ÆäÊ×ÏÈ»áÔÚFacebookÖ®ÀàµÄƽ̨ÉÏÕë¶Ô¸÷ÀàÖ÷Ì⣨ÀýÈç¹Û¹âµÈ£©Í¶·ÅÔÚÏ߸æ°×£¬²¢ÓÕʹÊܺ¦Õßµã»÷¸Ã¸æ°×ÒÔ½«Æä³Á¶¨Ïòµ½¶ñÒâÍøÕ¾ ¡£¾­¼ÍÈËÔòÊdzäÈΰ䲼É̺ͺô½ÐÖÐÐÄÖ®¼äÖн飬½«ºô½ÐÁ÷Á¿ÏúÊÛ¸øÔ¸Òâ²É°ìËüµÄºô½ÐÖÐÐÄ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/fbi-informant-provides-a-glimpse-into-the-inner-workings-of-tech-support-scams/


5.¶íÂÞ˹ÖÊÁ¿ÏµÍ³Åû¶WhatsAppÖеÄÐÂÐÍÚ¿Æ­·½Ê½


5.jpg

¶íÂÞ˹ÖÊÁ¿ÏµÍ³£¨Roskachestvo£©Åû¶WhatsAppÖеÄÐÂÐÍÚ¿Æ­·½Ê½ ¡£Roskachestvo¸±Ö÷¹ÜIlya Loevsky°µÊ¾£¬WhatsAppÖеľø´óÎÞÊýڲƭÐÐΪ¶¼ÊÇͨ¹ýÉç»á¹¤³Ì²úÉúµÄ£¬ºÚ¿Í»áͨ³£ÒÔGoogle¡¢Æ»¹û¡¢FacebookµÈ¹«Ë¾µÄÃûÒ壬ÀûÓÃCOVID-19Ö®ÀàµÄÈȵ㻰Ìâ»òÓÐÀû¿ÉͼµÄ²úÆ·£¬ÓÕʹÓû§µã»÷ÊÜϰȾµÄÁ´½Ó»òÏÂÔØ¿ÉÒÉÎļþ ¡£Êܺ¦ÕßÒ»µ©µã»÷¶ñÒâÁ´½Óºó£¬Ôò¿ÉÄÜ»á²úÉúÈκÎʼþ£¬´ÓÇÔÈ¡Ó×ÎÒÊý¾Ýµ½ÇÔÈ¡ÆäÐÅÓþ¿¨ÖÐ×ʽð ¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2020/08/the-russian-quality-system-roskachestvo.html


6.Conti´î½¨¹«¿ªÊý¾Ý¿â£¬²Éȡ˫ÏòÀÕË÷Õ½Êõ


6.jpg

ÀÕË÷Èí¼þ×éÖ¯Conti´î½¨¹«¿ªÊý¾Ý¿â£¬²¢²Éȡ˫ÏòÀÕË÷Õ½Êõ ¡£´Ë¿Ì£¬ºÜ¶à´óÐÍÀÕË÷Èí¼þ×éÖ¯²ÉÈ¡ÁË´ËÀàÕ½Êõ£¬ÈôÊÇÊܺ¦Õß²»ÔÞ³ÉÖ§¸¶Êê½ð£¬ÎÞÂÛËûÃÇÊÇ·ñ¸´Ô­Á˱»¼ÓÃܵÄԭʼÎļþ£¬¸Ã×éÖ¯¶¼½«Ð¹Â©Ô̺¬ÆäÎļþ ¡£ÐµĺڿÍ×éÖ¯ContiÔڴÊý¾Ý¿âºó£¬ÒѾ­ÁгöÁË26¼ÒÔâµ½¹¥»÷ÇһؾøÖ§¸¶Êê½ðµÄ¹«Ë¾£¬²¢ÒѾ­Ð¹Â©ÁËÕâЩ¹«Ë¾µÄÎļþ ¡£¾Ý³Æ£¬ContiÓë³ÛÃûµÄRyukÊÇÓÉͳһ×éÖ¯ÔËÓªµÄ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/conti-ryuk-joins-the-ranks-of-ransomware-gangs-operating-data-leak-sites/