¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190125

Ðû²¼Ê±¼ä 2019-01-25
1¡¢Ë¼¿ÆÐÞ¸´Webex¡¢SD-WANµÈ²úÆ·ÖеĶà¸öÇå¾²Îó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


±¾ÖÜÈý˼¿ÆÐû²¼Á˶à¿î²úÆ·µÄÇå¾²¸üР£¬£¬£¬£¬°üÀ¨SD-WAN¡¢Webex¡¢Firepower·À»ðǽÒÔ¼°SMB·ÓÉÆ÷µÈ¡£¡£¡£¡£¡£Ö»ÓÐÒ»¸öÎó²î±»¹éÀàΪcritical £¬£¬£¬£¬¸ÃÎó²î£¨CVE-2019-1651£©Ó°ÏìÁË˼¿ÆSD-WAN½â¾ö¼Æ»®ÖеÄvContainer×é¼þ £¬£¬£¬£¬¿É±»Ô¶³Ì¹¥»÷ÕßʹÓÃÒÔ´¥·¢DoSÒÔ¼°ÒÔrootȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£SD-WANÖÐµÄÆäËüÎó²î°üÀ¨Éí·ÝÑéÖ¤ÈÆ¹ý¡¢ÌáȨºÍí§ÒâÎļþÁýÕֵȡ£¡£¡£¡£¡£¸ü¶àÎó²îÐÅÏ¢Çë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/cisco-patches-flaws-webex-sd-wan-other-products


2¡¢MoxaÐÞ¸´IIoTÍø¹ØThingsPro 2ÖеÄ7¸öÇå¾²Îó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



¿¨°Í˹»ùÑо¿Ö°Ô±ÔÚMoxaµÄ¹¤ÒµÎïÁªÍø£¨IIoT£©Æ½Ì¨Öз¢Ã÷7¸öÑÏÖØÎó²î¡£¡£¡£¡£¡£MoxaµÄThingsPro 2Ì×¼þÊÇÒ»¸öIIoTÍø¹ØºÍ×°±¸ÖÎÃ÷È·¾ö¼Æ»® £¬£¬£¬£¬¿ÉÒÔ×ÊÖúÆóÒµÍøÂçºÍÆÊÎöICSϵͳµÄÊý¾Ý²¢¾ÙÐÐ×ʲúÖÎÀí¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷µÄÎó²î°üÀ¨ÌáȨ¡¢í§ÒâÏÂÁîÖ´ÐС¢»ñÈ¡¹¤ÒµÍøÂç»á¼ûȨÏÞÒÔ¼°×°±¸½ÓÊܵÈ¡£¡£¡£¡£¡£MoxaÒÑÔڹ̼þ°æ±¾2.3ÖÐÐÞ¸´ÁËÕâЩÎó²î¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/flaws-moxa-iiot-product-expose-ics-remote-attacks


3¡¢Ñо¿Ö°Ô±ÔÚ¶à¸öBMC¹Ì¼þÖз¢Ã÷ÐÂÎó²îpantsdown

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


IBM LinuxÊÖÒÕÖÐÐĵÄÈí¼þ¹¤³ÌʦStewart Smith·¢Ã÷Ó°Ïì¶à¸öµ×°åÖÎÀí¿ØÖÆÆ÷£¨BMC£©¹Ì¼þ¿ÍÕ»ºÍÓ²¼þµÄÑÏÖØÎó²î¡£¡£¡£¡£¡£¸ÃÎó²î£¨CVE-2019-6260£©±»³ÆÎª¡°pantsdown¡± £¬£¬£¬£¬Smith³Æ¸ÃÎó²îÖ÷ÒªÓ°ÏìÁËʹÓÃASPEED ast2400ºÍast2500ƬÉÏϵͳ£¨SoC£©µÄ²úÆ· £¬£¬£¬£¬OpenBMC¡¢AMIµÄBMCºÍSuperMicroµÈBMC¹Ì¼þ¿ÍÕ»¾ùÊÜÓ°Ïì¡£¡£¡£¡£¡£IBMµÄOpenPOWERϵͳÒÑÐû²¼Á˸ÃÎó²îµÄÐÞ¸´²¹¶¡¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/bmc-caught-with-pantsdown-over-new-batch-of-security-flaws/


4¡¢ÒøÐÐľÂíRedamanжñÒâ»î¶¯ £¬£¬£¬£¬Ö÷ÒªÕë¶Ô¶íÂÞË¹ÒøÐÐ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Palo Alto NetworksµÄUnit 42Ñо¿ÍŶÓÊÓ²ìµ½ÒøÐÐľÂíRedamanÔÚ2018ÄêϰëÄêÆð¾¢¾ÙÐй¥»÷»î¶¯¡£¡£¡£¡£¡£´Ó2018Äê9Ôµ½12Ô £¬£¬£¬£¬¸ÃľÂíÆð¾¢Í¨¹ýÀ¬»øÓʼþÈö²¥ £¬£¬£¬£¬Ö÷ÒªÕë¶Ô¶íÂÞ˹½ðÈÚ»ú¹¹ £¬£¬£¬£¬²¢Í¨¹ýαװ³ÉPDFÎĵµµÄWindows¿ÉÖ´ÐÐÎļþ½»¸¶payload¡£¡£¡£¡£¡£ÕâЩ¶ñÒ⸽¼þµÄÎļþÃûÌÃÒ»Ö±ÔÚת±ä £¬£¬£¬£¬2018Äê9ÔÂÊÇ.zipÎļþ £¬£¬£¬£¬10ÔÂÊÇ.zip¡¢.7zºÍ.rarÎļþ £¬£¬£¬£¬11ÔÂÊÇ.rarÎļþ £¬£¬£¬£¬12ÔÂÓÖÄð³ÉÁË.gzÎļþ¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÒÔΪ´Ë¾Ù¿ÉÄÜÊÇΪÁËÌӱܼì²â¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/redaman-spams-russian-banking-customers-with-rotating-tactics/141129/


5¡¢ÒøÐÐľÂíUrsnifжñÒâ»î¶¯ £¬£¬£¬£¬Ê¹ÓÃÎÞÎļþÊÖÒÕÌӱܼì²â

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Cisco Talos·¢Ã÷ÒøÐÐľÂíUrsnifµÄÒ»¸öжñÒâ»î¶¯ £¬£¬£¬£¬¸Ã»î¶¯ÖÐʹÓÃÁËPowerShellÀ´Èö²¥UrsnifÒÔʵÏÖÎÞÎļþѬȾ¡£¡£¡£¡£¡£UrsnifÒ²±»³ÆÎªGozi ISFB £¬£¬£¬£¬ÊÇÒøÐÐľÂíGoziµÄ×ÓÅ® £¬£¬£¬£¬GoziµÄÔ´ÂëÔÚ2014Äêй¶ºó £¬£¬£¬£¬ÔÚÆä»ù´¡ÉϽµÉúÁËÐí¶àÆäËüµÄÒøÐÐľÂí¼Ò×å £¬£¬£¬£¬ÀýÈçGozNym¡£¡£¡£¡£¡£¸ÃжñÒâ»î¶¯Í¨¹ýWordÎĵµÖеĶñÒâVBAºêÀ´·Ö·¢payload £¬£¬£¬£¬Ñо¿Ö°Ô±ÔÚ±¨¸æÖÐÁгöÁ˸öñÒâ»î¶¯µÄÏêϸIoCÖ¸±ê £¬£¬£¬£¬°üÀ¨¹þÏ£Öµ¡¢C2ЧÀÍÆ÷ÓòÃûÒÔ¼°payloadÃû³ÆµÈ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-ursnif-malware-campaign-uses-fileless-infection-to-avoid-detection/


6¡¢ÃÀ°¢À­Ë¹¼ÓÖݹ«¹²Ô®Öú²¿·ÖÊý¾Ýй¶ £¬£¬£¬£¬Ó°ÏìÔ¼8.7ÍòÈË

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



¾ÝÍâý±¨µÀ £¬£¬£¬£¬ÃÀ¹ú°¢À­Ë¹¼ÓÖݵĹ«¹²Ô®Öú²¿·Ö±¬·¢Êý¾Ýй¶ÊÂÎñ £¬£¬£¬£¬Ô¼ÓÐ8.7Íò°¢À­Ë¹¼ÓסÃñÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¸ÃÊÂÎñÔ´ÓÚ2018Äê4ÔÂβ¸Ã²¿·ÖµÄÅÌËã»úѬȾÁËÒ»ÖÖ²¡¶¾ £¬£¬£¬£¬Ê¹µÃÊý¾Ý¿â¿ÉÄÜÔâµ½¹¥»÷ÕßµÄδÊÚȨ»á¼û¡£¡£¡£¡£¡£Êý¾Ý¿âÖаüÀ¨°¢À­Ë¹¼ÓסÃñµÄСÎÒ˽¼ÒÐÅÏ¢ £¬£¬£¬£¬ÈçÐÕÃû¡¢Éç»áÇå¾²ºÅÂë¡¢ÆÜÉíµØµãºÍÒ½ÁÆÐÅÏ¢µÈ¡£¡£¡£¡£¡£¹Ù·½ÒѾ­Ïò¿ÉÄÜÊܵ½Ó°ÏìµÄÓû§·¢ËÍÁËÓʼþ֪ͨ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.usnews.com/news/best-states/alaska/articles/2019-01-24/alaska-notifies-87-000-people-after-computer-security-breach


ÉùÃ÷£º±¾×ÊѶÓɼøºÚµ£±£ÍøÎ¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí