CNCERT°ä²¼¡¶2020ÄêÉϰëÄêÎÒ¹ú»¥ÁªÍøÍøÂ簲ȫ¼à²âÊý¾Ý·ÖÎö»ã±¨¡·£»ÐÙÑÀÀûÒøÐк͵çÐÅÒµÔâµ½DDoS¹¥»÷µ¼Ö·þÎñÁÙʱÖжÏ

°ä²¼¹¦·ò 2020-09-28

1.CNCERT°ä²¼¡¶2020ÄêÉϰëÄêÎÒ¹ú»¥ÁªÍøÍøÂ簲ȫ¼à²âÊý¾Ý·ÖÎö»ã±¨¡·


1.jpg


ÎªÈ«Ãæ·´Ó³2020ÄêÉϰëÄêÎÒ¹ú»¥ÁªÍøÔÚ¶ñÒⷨʽ´«²¼¡¢·ì϶·çÏÕ¡¢DDoS¹¥»÷¡¢ÍøÕ¾°²È«µÈ·½ÃæµÄÇé¿ö£¬CNCERT¶ÔÉϰëÄê¼à²âÊý¾Ý½øÐÐÁËÊáÀí£¬²¢Ðγɼà²âÊý¾Ý·ÖÎö»ã±¨¡£»ã±¨ÏÔʾ£¬2020ÄêÉϰëÄ꣬²¶»ñÍÆËã»ú¶ñÒⷨ״ò±¾ÊýÁ¿Ô¼1815Íò¸ö£¬ÈÕ¾ù´«²¼´ÎÊý´ï483ÍòÓà´Î£¬Éæ¼°ÍÆËã»ú¶ñÒⷨʽ¼Ò×åÔ¼1.1ÍòÓà¸ö¡£ÒÀÕÕ´«²¼ÆðԴͳ¼Æ£¬¾³±í¶ñÒâ·¨Ê½ÖØÒªÀ´×ÔÃÀ¹ú¡¢ÈûÉà¶ûºÍ¼ÓÄôóµÈ£¬£»¾³ÄڵĶñÒâ·¨Ê½ÖØÒªÀ´×ÔÕã½­Ê¡¡¢¹ã¶«Ê¡ºÍ±±¾©ÊеÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.cert.org.cn/publish/main/46/2020/20200926085042652505447/20200926085042652505447_.html


2.ÐÙÑÀÀûÒøÐк͵çÐÅÒµÔâµ½DDoS¹¥»÷µ¼Ö·þÎñÁÙʱÖжÏ


2.jpg


Ò»³¡×³´óµÄDDoS¹¥»÷Ï®»÷ÁËÐÙÑÀÀûµÄÒ»Ð©ÒøÐк͵çÕÛ·þÎñ£¬µ¼ÖÂÆä·þÎñÖжÏ¡£¾ÝMagyarµçÐŹ«Ë¾³Æ£¬Õâ´Î¹¥»÷²úÉúÔÚÖÜËÄ£¬¶íÂÞ˹ºÍÔ½ÄϵȹúµÄºÚ¿ÍÊÔͼ¶ÔÐÙÑÀÀû½ðÈÚ»ú¹¹ÌáÒéDDoS¹¥»÷£¬ËûÃÇͬʱҲ·ÛËéÁËMagyarµçÐŹ«Ë¾µÄÍøÂç¡£´Ë±í£¬Õâ´Î¹¥»÷ÖеÄÊý¾ÝÁ÷Á¿±Èͨ³£ÔÚDDoSÊÂÎñÖп´µ½µÄÁ÷Á¿¸ß10±¶£¬ÕâÒâζ×Å¾ÍÆä¹æÄ£ºÍ¸´ÔÓÐÔ¶øÑÔ£¬ÕâÊÇÐÙÑÀÀûÓÐÊ·ÒÔÀ´×î´óµÄºÚ¿Í¹¥»÷Ö®Ò»¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/108788/hacking/ddos-attack-hungarian-orgs.html


3.Tesorion·¢ÏÖThunderXÖзì϶£¬¿ÉÃâ·Ñ¸´Ô­±»ËøÎļþ


3.jpg


ÍøÂ簲ȫ¹«Ë¾Tesorion·¢ÏÖThunderXÖзì϶£¬ÒÔ´Ë¿ª·¢²¢°ä²¼ÁËThunderXÀÕË÷Èí¼þµÄ½âÃÜ·¨Ê½£¬Ê¹Êܺ¦ÕßÄܹ»Ãâ·Ñ¸´Ô­ÆäÎļþ¡£¸Ã½âÃÜÆ÷Äܹ»½âÃÜÓµÓÐ.tx_lockedÀ©´óÃûµÄ±»¼ÓÃܵÄÎļþ£¬Ö»ÐèÉÏ´«Ò»·Ýreadme.txtÊê½ð×¢Ã÷µÄ¸±±¾ºÍÒ»¸ö¼ÓÃܵÄÎļþ£¬±ãÄܹ»ÌìÉú½âÃÜÃÜÔ¿¡£Ö®ºó£¬ÏÂÔØTesorionµÄThunderX Ransomware½âÃÜ·¨Ê½±ãÄܹ»½øÐнâÃܲÙ×÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/thunderx-ransomware-silenced-with-release-of-a-free-decryptor/


4.³¬¹ý20Íò¸öʹÓÃFortinet VPNµÄÆóÒµÒ×ÊÜMitM¹¥»÷


4.png


ÍøÂ簲ȫƽ̨ÌṩÉÌ SAM Seamless Network³Æ£¬³¬¹ý20Íò¸öʹÓÃFortinet VPNµÄÆóÒµÒ×ÊÜMitM¹¥»÷¡£ÔÚFortigate VPNµÄĬÈÏÉèÖÃÖУ¬Fortigate SSL-VPN¿Í»§¶Ë½öÑéÖ¤CAÊÇÓÉFortigate»¹ÊÇÓÉÁíÒ»¸öÊÜÐÅÀµµÄCAÐû¸æµÄ£¬Õâʹ¹¥»÷ÕßÄܹ»³öʾÐû¸æ¸øÆäËûFortigate·ÓÉÆ÷µÄÖ¤ÊéÀ´Ö´ÐÐÖÐÑëÈ˹¥»÷¡£²»ÐÒµÄÊÇ£¬Ä¿Ç°Fortinet²¢Ã»ÓдòËã½â¾ö¸Ã·ì϶£¬Ëü½¨ÒéÓû§ÊÖ¶¯´úÌæÄ¬ÈÏÖ¤Ê飬ÒÔÔ¤·ÀMitM¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/108737/hacking/fortigate-vpn-attacks.html


5.TylerÖÒ¸æÆäÓû§Ô¶³Ì½Ó¼ûÃÜÂë»òÒѱ»ÀûÓ㬽¨Òéµ±¼´Åú¸Ä


5.png


µ±¾ÐļÊõ·þÎñÌṩÉÌTyler TechnologiesÖÒ¸æÆäÓû§Ô¶³Ì½Ó¼ûÃÜÂë»òÒѱ»ºÚ¿ÍÀûÓ㬽¨Òéµ±¼´Åú¸Ä¡£¸Ã¹«Ë¾µÄCIO Matt Bieri°µÊ¾£¬Æä×î½ü·¢ÏÖÓÐÁ½¸ö¿Í»§¶Ë»ã±¨ÁËʹÓÃTylerÔ¶³Ì½Ó¼ûÍ´´¦½øÐеĿÉÒɵǼ¡£Ä¿Ç°Éв»Ã÷ÏÔÕâЩ¿ÉÒɻÊÇ·ñÓëÆäÉÏÖÜÈÕÔâµ½µÄÀÕË÷Èí¼þ¹¥»÷ÓйØ£¬µ«ÊÇΪÁ˰²È«Æð¼û£¬ËûÃǽ¨ÒéÆä¿Í»§¸ü¸ÄTyler TechnologiesʹÓõÄÕÊ»§µÄËùÓÐÃÜÂë¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/tyler-technologies-warns-clients-to-change-remote-support-passwords/


6.Google´ÓPlayÉ̵êÖÐɾ³ý17ÖÖϰȾJokerµÄAndroidÀûÓÃ


6.png


Google±¾ÖÜ´Ó¹Ù·½PlayÉ̵êÖÐɾ³ýÁË17ÖÖϰȾÁËJokerµÄAndroidÀûÓ÷¨Ê½¡£¼äµýÈí¼þJokerÖ¼ÔÚÇÔÈ¡SMSÐÂÎÅ¡¢ÁªÏµÁбíºÍÉ豸ÐÅÏ¢£¬²¢ÒÔ¾²Ä¬·½Ê½Ç©ÊðÊܺ¦Õߵĸ߼¶ÎÞÏßÀûÓúÍ̸£¨WAP£©·þÎñ¡£Õâ17¸ö¶ñÒâÀûÓÃÓÚ±¾ÔÂÔÚPlayÉ̵êÉϼÜ£¬ÔÚ±»·¢ÏÖ֮ǰÒÑÏÂÔØÁË12Íò´ÎÒÔÉÏ¡£ÕâÒÑÊǽü¼¸¸öÔÂÄڹȸ谲ȫÍŶӽøÐеĵÚÈý´ÎÕë¶ÔϰȾJokerµÄÀûÓõĶϸù»î¶¯£¬ÔÚ±¾Ô³õ£¬¹È¸è¾Íɾ³ýÁË6¸ö´ËÀàÀûÓ÷¨Ê½¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/google-removes-17-android-apps-doing-wap-billing-fraud-from-the-play-store/