WhatsAppÅû¶ÆäÀûÓÃÖеÄ6¸ö·ì϶£¬ÏÖÒѽ¨¸´£»°¢¸ùÍ¢ÒÆÃñ¾ÖϵͳϰȾNetwalkerµ¼Ö·þÎñÔÝÍ£4Ó×ʱ

°ä²¼¹¦·ò 2020-09-07

1.WhatsAppÅû¶ÆäÀûÓÃÖеÄ6¸ö·ì϶£¬ÏÖÒѽ¨¸´



1.png


WhatsAppÅû¶ÆäÀûÓÃÖдæÔÚµÄ6¸ö·ì϶£¬ÏÖÒѽ¨¸´ ¡£Õâ´Î½¨¸´µÄ·ì϶ÖнÏΪÑϳÁµÄΪ²Ö¿âдÈëÒç¶Âí½Å£¨CVE-2020-1894£©£¬¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐУ¬32λÉ豸´æÔÚµÄдÒç¶Âí½Å£¨CVE-2020-1891£©ºÍURLÑéÖ¤ÎÊÌ⣨CVE-2020-1890£©£¬¿Éµ¼ÖºڿÍÔÚûÓÐÓëÓû§½»»¥µÄÇé¿öÏ´ӷ¢¼þÈ˵ÄURL¼ÓÔØÍ¼Ïñ ¡£ÆäËû·ì϶Ϊ°²È«¼ì²âÈÆ¹ýÎÊÌ⣨CVE-2020-1889µÄ£©¡¢»º³åÇøÒç¶Âí½Å£¨CVE-2020-1886£©ºÍÊäÈëÑéÖ¤ÎÊÌ⣨CVE-2019-11928£© ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/107950/security/whatsapp-undisclosed-flaws.html


2.¿¨°Í˹»ù×êÑÐÏÔʾÕë¶ÔÔÚÏß½ÌÓýµÄDDoS¹¥»÷Ôö³¤350£¥


2.png


¿¨°Í˹»ùµÄ×îÐÂ×êÑÐÏÔʾ£¬2019Äê1ÔÂÖÁ2020Äê6ÔÂÖ®¼ä£¬Õë¶ÔÔÚÏß½ÌÓý×ÊÔ´µÄDDoS¹¥»÷Ôö³¤ÁË350£¥ ¡£ÔÚÈ«ÇòÁìÓòÄÚ£¬Óë2019ÄêµÚÒ»¼¾¶ÈÏà±È£¬2020ÄêµÚÒ»¼¾¶ÈDDoS¹¥»÷µÄ×ÜÊýÔö³¤ÁË80£¥£¬ÆäÖÐÕë¶Ô½ÌÓý×ÊÔ´µÄ¹¥»÷Õ¼ÁËÔö³¤µÄºÜ´óÒ»²¿ÃÅ ¡£¸Ã»ã±¨»¹·¢ÏÖ£¬ÓÐ168550Ãû¿¨°Í˹»ùÓû§Ôâµ½ÁËÒÔ¸÷ÀàÔÚÏß½ø½¨Æ½Ì¨»òÊÓÆµ»áÒéÀûÓ÷¨Ê½Îª»Ï×Ó´«²¼µÄÍþв£¬ÊÜÓ°ÏìµÄƽ̨Ô̺¬Moodle¡¢Zoom¡¢edX¡¢Coursera¡¢Google Meet¡¢Google ClassroomºÍBlackboard ¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/ddos-attacks-on-virtual-education/


3.FBIÔٴΰ䲼ÓйØÀÕË÷Èí¼þProLockÇÔÈ¡Êý¾ÝµÄ¾¯±¨



3.png


FBIÔÚÉÏÖÜÔٴΰ䲼ÁËÓйØÀÕË÷Èí¼þProLockÇÔÈ¡Êý¾ÝµÄ¾¯±¨ ¡£FBIÏÈǰµÄ¾¯±¨ÔøÖҸ湫˾ProLockµÄ½âÃÜÆ÷ÎÞ·¨Õý³£¹¤×÷£¬½âÃܹý³ÌÖг¬¹ý64MBµÄÎļþ¿ÉÄÜ»á°Ü»µ£¬Òò¶ø½«µ¼ÖÂÊý¾ÝÃÔʧ ¡£Æ¾¾ÝFBIµÄÊý¾Ý£¬×Ô2020Äê3ÔÂÆð£¬ÀÕË÷Èí¼þProLock±³ºóµÄ×éÖ¯Ò»ÏòÔÚ´ÓÊܺ¦ÕßµÄÉ豸ÖÐÍøÂçºÍй¶ÐÅÏ¢£¬²¢ÀûÓÃÇÔÈ¡µÄÊý¾ÝÒªÇóÊܺ¦×éÖ¯Ö§¸¶´Ó17.5ÍòÃÀÔªµ½66ÍòÃÀÔª²»µÈµÄÊê½ð ¡£µ½Ä¿Ç°ÎªÖ¹£¬ProLockÒѳɹ¦¹¥»÷ÁËÒ½ÁƱ£½¡¡¢¹¹Öþ¡¢½ðÈÚ¡¢Ë¾·¨µÈÐÐҵʵÌåºÍÃÀ¹úµ±¾Ö»ú¹¹ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fbi-issues-second-alert-about-prolock-ransomware-stealing-data/


4.CISAÖÒ¸æÕë¶ÔÈ«Çò½ðÈÚºÍóÒ××éÖ¯µÄDDoS¹¥»÷»î¶¯



4.png


ÍøÂ簲ȫºÍ»ù´¡¼Ü¹¹°²È«¾Ö£¨CISA£©ÖÒ¸æÕë¶ÔÈ«Çò½ðÈÚºÍóÒ××éÖ¯µÄDDoS¹¥»÷»î¶¯ ¡£¹¥»÷Õßͨ¹ýÏòÖ¸±êÖ÷»ú»òÍøÂç·¢ËÍÁ÷Á¿ÖÂÆäÎÞ·¨ÏìÓ¦»ò±ÀÀ££¬¼´¿É×èÖ¹Ö¸±êÓû§½Ó¼û£¬´Ó¶øÊµÏÖDoS¹¥»÷ ¡£ÔÚDDoS¹¥»÷ÖУ¬´«ÈëÁ÷Á¿À´×Ժܶà·ÖÆçµÄÆðÔ´£¬Òò¶øÎÞ·¨Í¨¹ý×èÖ¹µ¥¸öÆðÔ´À´×èÖ¹¹¥»÷ ¡£Êܺ¦×éÖ¯µÄ×ÊÔ´ºÍ·þÎñ½«ÎÞ·¨½Ó¼û£¬Òò¶ø»ò½«µ¼ÖÂËðʧ¹¦·òºÍ½ðÇ® ¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/09/04/dos-and-ddos-attacks-against-multiple-sectors


5.ÃÀ¹úº£ÎéµÂÏØÑ§ÇøÏ°È¾SunCrypt£¬Ð¹Â¶Î´¼ÓÃܵÄÎļþ


5.png


±±¿¨ÂÞÀ´ÄÉÖݺ£ÎéµÂÏØÑ§ÇøÓÚ2020Äê8ÔÂ24ÈÕÔâµ½ÁËSunCryptÀÕË÷Èí¼þ¹¥»÷£¬Ð¹Â¶Î´¼ÓÃܵÄÎļþ ¡£Õâ´ÎÊÂÎñÖÐй¶ÁË5GBµÄµµ°¸£¬Ô̺¬ºÜ¶àÓëÑ§Çø¡¢Ñ§ÉúºÍ½ÌÔ±ÓйصÄÃô¸ÐÎĵµºÍÓ×ÎÒÐÅÏ¢ ¡£´Ë±í£¬Õâ´Î¹¥»÷»¹µ¼ÖÂѧÌÃϵͳÖеķþÎñÆ÷¡¢»¥ÁªÍøºÍµç»°·þÎñ¹Ø¹Ø ¡£¾­µ÷²é£¬¹¥»÷Õ߯ð³õ´´½¨ÁËÒ»¸öÒÔÊܺ¦ÕßΪÃûµÄPowerShell¾ç±¾£¬²¢½«Æä´æ´¢ÔÚWindowsÓò½ÚÔìÆ÷ÉÏ ¡£Ö®ºó£¬ºÚ¿ÍÒñ±ÎµØÇÔÈ¡ÎļþµÄͬʱ£¬½«ÀÕË÷Èí¼þ·Ö·¢µ½ÆäËûÉ豸 ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/suncrypt-ransomware-shuts-down-north-carolina-school-district/


6.°¢¸ùÍ¢ÒÆÃñ¾ÖϵͳϰȾNetwalkerµ¼Ö·þÎñÔÝÍ£4Ó×ʱ



6.png


°¢¸ùÍ¢µÄ¹Ù·½ÒÆÃñ¾ÖDirecci¨®nNacional de MigracionesÔâµ½ÁËNetwalkerÀÕË÷Èí¼þ¹¥»÷£¬µ¼ÖÂÆä·þÎñÔÝÍ£4Ó×ʱ ¡£Í¨¹ýÆÀ¹ÀÖÐÑëÊý¾ÝÖÐÐĺÍÉ¢²¼Ê½·þÎñÆ÷µÄ»ù´¡½á¹¹Çé¿ö£¬·¢ÏÖÕâ´Î¹¥»÷»î¶¯ÒѾ­Ó°ÏìÁËÆä»ùÓÚMS WindowsµÄϵͳÎļþÒÔ¼°Óû§ÎļþºÍ¹²ÏíÎļþ¼ÐÖдæÔÚµÄMicrosoft OfficeÎļþ ¡£ÎªÔ¤·ÀÀÕË÷Èí¼þϰȾÆäËûÉ豸£¬ÒÆÃñ¾Ö¹Ø¹ØÁËÆäʹÓõÄÍÆËã»úÍøÂ磬ÕâÒ²µ¼Ö±ßÚï¹ý¾³µãµÄ·þÎñÔÝÍ£ÁË4¸öÓ×ʱ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ransomware-attack-halts-argentinian-border-crossing-for-four-hours/