CISA°ä²¼SolarWinds Orion¹¥»÷ÊÂÎñµÄ²¹³äÖ¸ÄÏ £»Æ»¹û¡¢¹È¸è¡¢Î¢ÈíºÍMozilla½ûÓùþÈø¿Ë˹̹µÄ¸ùÖ¤Êé

°ä²¼¹¦·ò 2020-12-22
1.CISA°ä²¼SolarWinds Orion¹¥»÷ÊÂÎñµÄ²¹³äÖ¸ÄÏ


1.jpg


CISA×î³õÓÚ12ÔÂ17ÈÕ°ä²¼ÁËÓйص±¾Ö»ú¹¹¡¢¹Ø¼ü»ù´¡ÉèÊ©ºÍ¹«Ë¾×éÖ¯µÄAPT¹¥»÷»î¶¯µÄ¾¯±¨£¬Ö®ºóÕë¶Ô¸Ã´¹Î£Ö¸Áî°ä²¼Á˲¹³äÖ¸ÄÏ ¡£²¹³äÖ¸ÄÏÔ̺¬ÊÜÓ°Ïì°æ±¾µÄ¸üС¢Õë¶ÔʹÓõÚÈý·½·þÎñÌṩÉ̵ĴúÀíµÄÖ¸ÄÏÒÔ¼°¶ÔËùÐè´ëÊ©µÄ½øÒ»²½×¢Ã÷ ¡£´Ë±í£¬CISA»¹¸üÐÂÁ˸þ¯±¨£¬ÌṩÁËÐµĻº½â¹æ»®²¢¶©ÕýÁËIOC±í¸ñ ¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/12/19/cisa-updates-alert-and-releases-supplemental-guidance-emergency


2.ÏãÁϹ«Ë¾SymriseϰȾClop£¬500GBδ¼ÓÃܵÄÎļþ±»µÁ


2.jpg


Ï㾫ÏãÁϹ«Ë¾SymriseϰȾÀÕË÷Èí¼þClop£¬500GBδ¼ÓÃܵÄÎļþ±»µÁ£¬½ü1000̨É豸±»¼ÓÃÜ ¡£SymriseÊÇÈ«Çò³¬¹ý3ÍòÖÖ²úÆ·£¨Ô̺¬È¸³²ºÍÊʿڿÉÀÖ£©ÖÐʹÓõÄÏ㾫ÏãÁϵÄÖØÒª¿ª·¢ÉÌ£¬ÓÚÉÏÖÜÔâµ½ÁËÍøÂç¹¥»÷£¬²¢¹Ø¹ØÁËËùÓбØÒªµÄϵͳÒÔÔ¤·À¹¥»÷ÊæÕ¹ ¡£ClopÍÅ»ïÐû³ÆÆäͨ¹ý´¹µö¹¥»÷ÈëÇÖÁËSymriseµÄÍøÂç²¢ÇÔÈ¡ÁË500 GBµÄδ¼ÓÃÜÎļþ£¬ÆäÔÚÊý¾ÝÐ¹Â¶ÍøÕ¾Éϰ䲼µÄ½ØÍ¼ÏÔʾ±»µÁÊý¾ÝÔ̺¬»¤ÕÕ¡¢¹ÜÕÊÆ¾Ö¤¡¢Éó¼Æ»ã±¨¡¢»¯×±Æ·³É·ÖºÍµç×ÓÓʼþµÈ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/flavors-designer-symrise-halts-production-after-clop-ransomware-attack/


3.ClearSky³ÆÒÁÀʺڿÍÀûÓÃPay2Key¶Ô×¼ÒÔÉ«ÁеĹ«Ë¾


3.jpg


Íþвµý±¨¹«Ë¾ClearSky³ÆÒÁÀʺڿÍÀûÓÃPay2Key¶Ô×¼ÒÔÉ«ÁеĹ«Ë¾ ¡£Õâ´Î¹¥»÷»î¶¯²úÉúÓÚ2020Äê11Ôµ½12Ô£¬»òÓëÒÁÀʺڿÍ×éÖ¯Fox KittenÓйØ ¡£Fox KittenÉÆÓÚʹÓø÷À࿪ԴºÍ×ÔÖ÷¿ª·¢µÄ¹¥»÷¹¤¾ß£¬Í¨¹ýÖ¸±êÆóÒµµÄvpnÒÔ¼°F5 NetworksµÄBIG-IPÀûÓ÷¨Ê½½»¸¶½ÚÔìÆ÷(ADC)ÈëÇÖ ¡£ClearSky³ÆºÚ¿ÍÕë¶ÔÒÔÉ«ÁÐÊýÊ®¼Ò¹¤Òµ¡¢±£ÏÕºÍÎïÁ÷¹«Ë¾£¬À´×°ÖÃÀÕË÷Èí¼þÀ´¼ÓÃÜ·þÎñÆ÷ºÍ¹¤×÷Õ¾£¬ÒÔ¼°ÌáÒ鹩¸øÁ´¹¥»÷ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/iranian-hackers-target-israeli-companies-pay2key-ransomware


4.Æ»¹û¡¢¹È¸è¡¢Î¢ÈíºÍMozilla½ûÓùþÈø¿Ë˹̹µÄ¸ùÖ¤Êé


4.jpg


Æ»¹û¡¢¹È¸è¡¢Î¢ÈíºÍMozilla½ûÓùþÈø¿Ë˹̹µÄMitM HTTPSÖ¤Êé ¡£¸ÃÖ¤Êé×Ô2020Äê12ÔÂ6ÈÕÆðͷʹÓ㬹þÈø¿Ë˹̹µ±¾ÖÇ¿Ôì×°Öô˸ùÖ¤ÊéÒÔÀ¹½ØºÍ¼à¶½¸Ã¹úÊ×¶¼Å¬¶ûËÕµ¤¾ÓÃñµÄHTTPSÁ÷Á¿ ¡£´Ë½ûÁî°ä²¼ºó£¬¼´±ãÓû§ÒÑ×°ÖÃÖ¤Ê飬ÈÔÎÞ·¨½Ó¼ûChrome¡¢Edge¡¢MozillaºÍSafariµÈä¯ÀÀÆ÷£¬´Ó¶ø×èÖ¹¹þÈø¿Ë˹̹¹ÙÔ±À¹½ØÓû§Êý¾Ý ¡£ÕâÊÇËļҳ§É̵ڶþ´Î½ûÓùþÈø¿Ë˹̹µ±¾ÖÇ¿Ôì×°ÖõÄMitM HTTPSÖ¤Êé ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/apple-google-microsoft-and-mozilla-ban-kazakhstans-mitm-https-certificate/


5.Dell Wyse Thin¿Í»§¶Ë´æÔÚÁ½¸ö´úÂëÖ´Ðзì϶


5.jpg


Dell Wyse Thin¿Í»§¶Ë´æÔÚÁ½¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¬CVSSÑϳÁÐÔÆÀ·Ö¾ùΪ10 ¡£ÆäÖÐÒ»¸ö·ì϶±»×·×ÙΪCVE-2020-29491£¬ÓÉÓÚ¶¨ÆÚping·þÎñÆ÷ÒÔ»ñÈ¡×îÐÂÅäÖ㬲¢ÎÞÐèÉí·ÝÑéÖ¤£¬Òò¶øËùÓÐÈ˶¼¿É½Ó¼ûÕâЩ¿ÉÄÜÔ̺¬Ô¶³Ì½Ó¼ûÍ´´¦µÄÅäÖÃÎļþ ¡£ÁíÒ»¸ö·ì϶±»×·×ÙΪCVE-2020-29492£¬ÓÉÓÚ´æ´¢ÕâЩÅäÖõķþÎñÆ÷ÔÊÐí¶ÔÆäÅäÖÃÎļþ½øÐжÁд½Ó¼û£¬Òò¶øÈκÎÈ˶¼Äܹ»Ê¹ÓÃFTP¶ÁÈ¡ºÍ¸ü¸ÄËüÃÇ ¡£Ä¿Ç°£¬ÕâÁ½¸ö·ì϶ÒѾ­±»½¨¸´ ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/critical-bugs-dell-wyse-thin-clients/162452/


6.Verizon°ä²¼2020ÄêÊý¾Ýй¶µÄµ÷²é·ÖÎö»ã±¨


6.jpg


Verizon°ä²¼ÁË2020ÄêÊý¾Ýй¶µÄµ÷²é·ÖÎö»ã±¨£¬×ܹ²·ÖÎöÁË157525ÆðÊÂÎñ£¬Éæ¼°µ½16¸ö´¹Ö±ÐÐÒµ ¡£»ã±¨Ö¸³ö£¬ÔÚµ¼ÖÂÊý¾Ýй¶µÄ¹¥»÷·½Ê½ÖУ¬ÍøÂç´¹µö¡¢Ê¹Óñ»µÁÍ´´¦ºÍÅäÖÃÃýÎóµÄÕ¼±È×î´ó£¬¶øµ¼ÖÂÊý¾Ýй¶×î¶àµÄ¶ñÒâÈí¼þÀàÐÍΪÃÜÂëת´¢·¨Ê½¡¢´¹µöµç×ÓÓʼþºÍÖ±½Ó×°ÖÃÇÔÈ¡·¨Ê½ ¡£´Ë±í£¬2020ÄêÓг¬¹ý80%µÄºÚ¿ÍÈëÇÖ»î¶¯Éæ¼°µ½±©Á¦¹¥»÷»òʹÓÃÃÔʧºÍ±»µÁµÄƾ֤ ¡£


Ô­ÎÄÁ´½Ó£º

https://enterprise.verizon.com/resources/reports/dbir/2020/introduction/