ºÚ¿ÍÔÚGitHub´æ´¢¿âÖй«¿ªCobalt StrikeÔ´´úÂ룻ºÚÝ®·¢ÏÖкڿ͹ÍÓ¶¾üCostaRicto£¬ÖØÒªÕë¶ÔÄÏÑÇ×éÖ¯

°ä²¼¹¦·ò 2020-11-13
1.ºÚ¿ÍÔÚGitHub´æ´¢¿âÖй«¿ªCobalt StrikeÔ´´úÂë


1.png


ºÚ¿ÍÔÚGitHub´æ´¢¿âÖй«¿ªCobalt Strike¹¤¾ß°üµÄÔ´´úÂë¡£Cobalt StrikeÊǺϷ¨µÄÉøÈë²âÊÔ¹¤¾ß°ü£¬¿ÉÔÚÖ¸±êÉ豸Éϲ¿ÊðÐű꣬À´Ô¶³Ì´´½¨Shell²¢Ö´ÐÐPowerShell¾ç±¾¡£Ó¢Ìضû×êÑÐÈËÔ±Éó²éÔ´´úÂëºóÒÔΪJava´úÂëÊÇÊÖ¶¯·´±àÒëµÄ£¬ºÚ¿Í½¨¸´ÁËËùÓÐÒÀÀµ¹ØÏµ²¢É¾³ýÁËÐí¿ÉÖ¤²é³­£¬ÒÔ±ã¶ÔÆä½øÐбàÒë¡£×Ô°ä²¼ÒÔÀ´£¬¸Ã´æ´¢¿âÒѱ»forked 172´Î£¬ÕâʹµÃÔ´´úÂëµÄ´«²¼Ô½·¢ÄÑÒÔ½ÚÔì¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/alleged-source-code-of-cobalt-strike-toolkit-shared-online/


2.ºÚ¿ÍÔÚ°µÍøÏúÊÛAnimal Jam 4600Íò¸öÓû§µÄÊý¾Ý


2.png


ºÚ¿ÍÔÚ°µÍøÏúÊÛAnimal Jam 4600Íò¸öÓû§µÄÊý¾Ý¡£Animal JamÊÇWildWorks´´½¨µÄÐé¹¹ÊÀ½ç£¬Îª¹ãÊÜÓ­½ÓµÄ¶ùͯÔÚÏßÓÎÀÖ³¡¡£Ä¿Ç°ºÚ¿ÍÔÚ°µÍø¹²ÏíÁËÁ½¸ö¾Ý³ÆÊÇ´ÓShinyHunters»ñµÃµÄÊôÓÚAnimal JamµÄÊý¾Ý¿â£¬Ãû³Æ±ðÀëΪgame_accountsºÍusers£¬Ô̺¬ÁËԼĪ4600Íò¸ö±»µÁÓû§¼Í¼¡£Æ¾¾ÝÑù±¾¼Í¼ÉϵŦ·ò´Á¼Ç£¬¸ÃÊý¾Ý¿âºÜ¿ÉÄÜÔÚ2020Äê10ÔÂ12ÈÕ±»µÁµÄ¡£WildWorksͨ¹ýµ÷²é·¢ÏÖ£¬ºÚ¿Í¿ÉÄÜÔÚ·ÛËéÁ˹«Ë¾µÄSlack·þÎñÆ÷ºó»ñµÃÁËWildWorkµÄAWSÃÜÔ¿¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/animal-jam-kids-virtual-world-hit-by-data-breach-impacts-46m-accounts/


3.΢Èí°ä²¼Office°²È«¸üУ¬½¨¸´7¿î²úÆ·ÖеĶà¸ö·ì϶


3.png


΢Èí°ä²¼ÁË11ÔÂOffice°²È«¸üУ¬½¨¸´7¿î²úÆ·ÖеÄ14¸ö·ì϶¡£Õâ´Î½¨¸´µÄ×îΪÑϳÁµÄ·ì϶ÊÇMicrosoft SharePointÖеÄÔ¶³ÌÖ´ÐдúÂ루RCE£©·ì϶£¨CVE-2020-17061£©£¬¹¥»÷ÕßÄܹ»ÀûÓõÍÓû§È¨ÏÞÔ¶³ÌÀûÓô˷ì϶¶øÎÞÐèÓëÓû§½»»¥¡£´Ë±í»¹½¨¸´ÁËMicrosoft ExcelÖеĶà¸öÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2020-17065¡¢CVE-2020-17064¡¢CVE-2020-17066ºÍCVE-2020-17019£©ºÍ AccessÏνÓÒýÇæÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2020-17062£©µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/office-november-security-updates-fix-remote-code-execution-bugs/


4.NVIDIA½¨¸´GeForce NOWÔÆÓÎÏ··þÎñÖеĴúÂëÖ´Ðзì϶


4.png


NVIDIAΪGeForce NowÔÆÓÎÏ··þÎñ°ä²¼ÁËÒ»¸ö°²È«¸üУ¬ÒÔ½¨¸´¿ÉÄܵ¼ÖÂËÁÒâ´úÂëÖ´ÐлòÌØÈ¨ÌáÉýµÄ·ì϶¡£GeForce NowÊÇ»ùÓÚÔÆµÄÓÎÏ·Á÷ýÌå·þÎñ£¬ËüÔÊÐíÓû§´ÓNVIDIA·þÎñÆ÷ÉÏÍйܵÄÊý°Ù¸öÓÎÏ·¿âÖлñÈ¡ÓÎÏ·¡£¸Ã·ì϶±»×·×ÙΪCVE?2020?5992£¬´æÔÚÓÚÆä¿ªÔ´Èí¼þÒÀÀµÏîOpenSSL¿âÖУ¬Ò×Êܵ½±¾µØÓû§µÄ¶þ½øÔì×¢Èë¹¥»÷£¬¿Éµ¼Ö´úÂëÖ´ÐлòÌØÈ¨Éý¼¶¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/nvidia-fixes-severe-flaw-in-geforce-now-cloud-gaming-service/


5.½©Ê¬ÍøÂçMuhstikÐÂÔöOracle WebLogicºÍDrupal·ì϶


5.png


×êÑÐÈËÔ±·¢ÏÖ½©Ê¬ÍøÂçMuhstikÐÂÔöOracle WebLogicºÍDrupal·ì϶¡£Muhstik½©Ê¬ÍøÂ磨Ҳ³ÆÎªMushtik£©Ò»Ö¹Øë¶ÔÔÆ»ù´¡ÉèÊ©ºÍÎïÁªÍø£¬Í¨¹ýʹÓÃXMRigºÍcgminerµÈ¿ªÔ´¹¤¾ßÍÚ¾ò¼ÓÃÜÇ®±ÒÀ´»ñÀû¡£Ôư²È«¹«Ë¾Lacework·¢ÏÔìäÒÑÆðÍ·ÀûÓÃOracle WebLogic Server·ì϶£¨CVE-2019-2725ºÍCVE-2017-10271£©ºÍDrupal RCE·ì϶£¨CVE-2018-7600£©¡£´Ë±í£¬×êÑз¢ÏÖMuhstikʹÓÃMiraiÔ´´úÂëͨ¹ýµ¥×Ö½ÚXOR¼ÓÃÜÀ´¼ÓÃÜÆäÓÐЧ¸ºÔغÍɨÃèÄ£¿éµÄÅäÖá£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/110763/uncategorized/muhstik-botnet-weblogic-drupal.html


6.ºÚÝ®·¢ÏÖкڿ͹ÍÓ¶¾üCostaRicto£¬ÖØÒªÕë¶ÔÄÏÑÇ×éÖ¯


6.png


ºÚÝ®°ä²¼ÁËÓйØÐµĺڿ͹ÍÓ¶¾ü×éÖ¯CostaRictoµÄ¾ßÌåÐÅÏ¢£¬ÖØÒªÕë¶ÔÄÏÑÇ×éÖ¯¡£¸Ã×éÖ¯¾«ÐIJ߶¯Á˱鼰ŷÖÞ¡¢ÃÀÖÞ¡¢ÑÇÖÞ¡¢°Ä´óÀûÑǺͷÇÖÞµÄ·ÖÆç¹ú¶ÈµÄ¹¥»÷£¬µ«Êܺ¦Õ߶༯ÖÐÓÚÄÏÑÇ£¬ÓÈÆäÊÇÓ¡¶È¡¢ÃϼÓÀ­¹úºÍÐÂ¼ÓÆÂ£¬²¢ÇÒ´ó²¿ÃÅÊôÓÚ½ðÈÚÐÐÒµ¡£ÕâÊǽñÄê·¢ÏֵĵÚÎå¸öºÚ¿Í¹ÍÓ¶×éÖ¯£¬ÆäËûËĸö±ðÀëΪBellTrox (ÓÖ³ÆDark Basin)¡¢DeathStalker (ÓÖ³ÆDeceptikons) ¡¢BahamutºÍUnnamed group¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/blackberry-discovers-new-costaricto-hacker-for-hire-group/