ÃÀ¹úÄÜÔ´²¿È·ÈÏSolarWindsÒÑÈëÇֺ˱øÆ÷¾ÖµÄÍøÂç £»Avast½üÆÚ·¢ÏÖ28¿î¶ñÒâµÄä¯ÀÀÆ÷²å¼þ£¬Ó°Ïì300ÍòÓû§

°ä²¼¹¦·ò 2020-12-18
1.ÃÀ¹úÄÜÔ´²¿È·ÈÏSolarWindsÒÑÈëÇֺ˱øÆ÷¾ÖµÄÍøÂç


1.png


ÃÀ¹úÄÜÔ´²¿ÒѾ­È·ÈÏ£¬SolarWinds±³ºóµÄºÚ¿Í×éÖ¯ÈëÇÖÁËÃÀ¹úºË±øÆ÷»ú¹¹NNSAµÄÍøÂç¡£NNSAÊÇÒ»¸ö°ë×ÔÖε±¾Ö»ú¹¹£¬ÕƹÜÊØ»¤ºÍÈ·±£ÃÀ¹úºË±øÆ÷¿â´æ£¬ÒÔ¼°Ó¦¶ÔÃÀ¹ú¹úÄÚ±íµÄºËºÍ·ÅÉ䴹ΣÇé¿ö¡£FBI¡¢CISAºÍODNI°ä²¼½áºÏÉêÃ÷³Æ£¬ºÚ¿ÍÈëÇÖÁ˶à¸öÃÀ¹úµ±¾ÖµÄÍøÂ磬Ô̺¬ÃÀ¹ú²ÆÕþ²¿¡¢ÃÀ¹ú¹úÎñÔº¡¢ÃÀ¹úNTIA¡¢ÃÀ¹ú¹úÁ¢ÎÀÉú×êÑÐÔº¡¢DHS-CISAºÍÃÀ¹úºÓɽ°²È«Êý¡£Ä¿Ç°£¬Microsoft¡¢FireEyeºÍGoDaddyÒÑΪSolarWinds SunburstºóÃÅ´´½¨ÁËÒ»¸ökill switch£¬ÒÔÖÕÖ¹Êܺ¦ÕßÍøÂçÉϵÄϰȾ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/solarwinds-hackers-breach-us-nuclear-weapons-agency/


2.HPEÅû¶Æä·þÎñÆ÷ÖÎÀíÈí¼þÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶


2.png


»ÝÆÕÆóÒµ£¨HPE£©Åû¶ÆäWindowsºÍLinuxµÄHPE Systems Insight Manager£¨SIM£©Èí¼þÖдæÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£HPE SIMÊÇÕë¶Ô¶à¸öHPE·þÎñÆ÷¡¢´æ´¢ºÍÍøÂç²úÆ·µÄÖÎÀíºÍÔ¶³ÌÖ§³Ö×Ô¶¯»¯½â¾ö¹æ»®¡£¸Ã·ì϶±»×·×ÙΪCVE-2020-7200£¬ÑϳÁÐÔÆÀ·ÖΪ9.8£¬¸Ã·ì϶ÊÇÓÉÓÚ¶ÔÓû§ÌṩµÄÊý¾Ý²»×ãÊʵ±µÄÑéÖ¤µ¼Ö²»³ÉÐÅÊý¾ÝµÄ·´ÐòÁл¯£¬´Ó¶øÊ¹¹¥»÷ÕßÓпÉÄÜÀûÓÃÕâЩÊý¾ÝÖ´ÐдúÂ롣Ŀǰ¸Ã·ì϶ÉÐÎÞ°²È«¸üУ¬µ«ÊÇHPEÒÑÌṩWindows»º½â²½Öè¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hpe-discloses-critical-zero-day-in-server-management-software/


3.Avast½üÆÚ·¢ÏÖ28¿î¶ñÒâµÄä¯ÀÀÆ÷²å¼þ£¬Ó°Ïì300ÍòÓû§


3.png


°²È«¹«Ë¾Avast½üÆÚ·¢ÏÖ28¿î¶ñÒâµÄä¯ÀÀÆ÷²å¼þ£¬Ô̺¬15¸öChromeÀ©´óºÍ13¸öEdgeÀ©´ó£¬ÒÑÓ°Ïì300ÍòÓû§¡£Õâ28¿î²å¼þÔ̺¬´óÁ¿ÊµÏÖ¶ñÒâ²Ù×÷µÄ´úÂ룬ÀýÈ罫Óû§Á÷Á¿³Á¶¨Ïòµ½¸æ°×¡¢½«Óû§Á÷Á¿³Á¶¨Ïòµ½ÍøÂç´¹µöÕ¾µã¡¢ÍøÂçÓ×ÎÒÊý¾Ý¡¢ÍøÂçä¯ÀÀ¼Í¼¡¢½«¸ü¶à¶ñÒâÈí¼þÏÂÔØµ½Óû§É豸ÉÏ¡£Ä¿Ç°£¬GoogleÒÑɾ³ýÁË15¸ö¶ñÒâÀ©´ó·¨Ê½ÖеÄ3¸ö£¬¶øMicrosoftÒòÎÞ·¨È·ÈÏAvastµÄ»ã±¨¶øÉÐδ½øÐÐɾ³ý¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/three-million-users-installed-28-malicious-chrome-or-edge-extensions/


4.ºÚ¿Í½«ÀÕË÷Èí¼þSystemBC×÷ΪTor´úÀíºÍÔ¶³Ì½ÚÔ칤¾ß


4.png


ºÚ¿Í½«ÀÕË÷Èí¼þSystemBC×÷ΪTor´úÀíºÍÔ¶³Ì½ÚÔ칤¾ß¡£SystemBCÓÚ2019Äê³õ´Î³öÏÖ£¬ÊÇÒ»ÖÖ´úÀíºÍÔ¶³ÌÖÎÀí¹¤¾ß¡£Ëü¼È³äÈÎÒþʽͨѶµÄÍøÂç´úÀí£¬ÓÖ³äÈÎÔ¶³ÌÖÎÀí¹¤¾ß£¨RAT£©£¬¿ÉÄÜÖ´ÐÐWindowsºÅÁî²¢½»¸¶ºÍÖ´Ðо籾¡¢¶ñÒâ¿ÉÖ´ÐÐÎļþºÍ¶¯Ì¬Á´½Ó¿â£¨DLL£©£¬»¹Äܹ»Ìá¹©ÓÆ¾ÃµÄºóÃÅ¡£SystemBCµÄ×îÐÂÑù±¾ÖÐÔ̺¬µÄ´úÂëûÓÐͨ¹ýSOCKS5´úÀí³äÈÎÐ鹹˽ÓÐÍøÂ磬¶øÊÇʹÓÃTorÄäÃûÍøÂç¼ÓÃܲ¢°µ²ØºÅÁîºÍ½ÚÔìÁ÷Á¿µÄÖ÷ÕŵØ¡£


Ô­ÎÄÁ´½Ó£º

https://news.sophos.com/en-us/2020/12/16/systembc/


5.еÄRubyGems¶ñÒâÈí¼þ°üÕë¶Ô¼ÓÃÜÇ®±Ò¹©¸øÁ´


5.png


°²È«¹«Ë¾Sonatype·¢ÏÖеÄRubyGems¶ñÒâÈí¼þ°üÕë¶Ô¼ÓÃÜÇ®±Ò¹©¸øÁ´£¬ÒÔÇÔÈ¡¼ÓÃÜÇ®±Ò¡£Sonatype»ã±¨³Æ£¬Á½¸ö¶ñÒâÈí¼þ°üpretty_color-0.8.1.gemºÍ ruby-bitcoin-0.0.20.gem£¬¼Ù×°³É±ÈÌØ±Ò¿âºÍÓÃÓÚÏÔʾ·ÖÆçÉ«²Ê³ÉЧµÄ×Ö·û´®µÄ¿â£¬×°ÖÃÁËÒ»¸ö¼ôÌù°åÇÔÈ¡¹¤¾ß¡£ËüÃÇÄܹ»¼à¶½Windows¼ôÌù°åµÄ¼ÓÃÜÇ®±ÒµØÖ·£¬ÈôÊǼì²âµ½¼ÓÃÜÇ®±ÒµØÖ·£¬½«»á°ÑËü´úÌæÎª¹¥»÷ÕߵĵØÖ·£¬ÒÔÇÔÈ¡¼ÓÃÜÇ®±Ò¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/malicious-rubygems-packages-used-in-cryptocurrency-supply-chain-attack/


6.FBI³ÆDoppelPaymerÓõ绰¿ÖÏžܸ¶Êê½ðµÄÊܺ¦Õß


6.png


FBI³ÆÀÕË÷Èí¼þÍÅ»ïDoppelPaymerÓôòµç»°µÄ·½Ê½¿ÖÏžܸ¶Êê½ðµÄÊܺ¦Õß¡£FBI°µÊ¾£¬ÕâЩÊÂÎñ×Ô2020Äê2ÔÂÒÔÀ´Ò»ÏòÔÚ²úÉú£¬²¢ÇÒÆäËûËĸöÀÕË÷Èí¼þ×éÖ¯Sekhmet ¡¢ Maze ¡¢ContiºÍRyukÒ²ÊÇÓùýÀàËÆµÄÕ½Êõ¡£´Ë±í£¬¸Ã»ú¹¹»¹¾ßÌå˵ÁËȻһ¸öÌØ¶¨°¸Àý£¬ÆäÖÐÍþв´ÓÊܹ¥»÷µÄ¹«Ë¾À©´óµ½ÆäÔ±¹¤ÉõÖÁÊÇÇׯÝ£¬³ÆÒª°ÑÒ»Ó×ÎÒË͵½Ò»ÃûÔ±¹¤µÄ¼ÒÀï¡£µ«FBI°µÊ¾£¬ÔÚÕâÖÖÇé¿öÏ£¬±©Á¦Íþвͨ³£ÊǸ¡·ºµÄ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/fbi-says-doppelpaymer-ransomware-gang-is-harassing-victims-who-refuse-to-pay/