Ê׸öÀÄÓÃDNS over HTTPSЭÒéµÄ¶ñÒâÈí¼þGodlua£»£»£»£»£»£»Chrome V8ÒýÇæÖеÄÄÚ´æËð»µÎó²î£¬£¬£¬£¬£¬¿Éµ¼ÖÂRCE

Ðû²¼Ê±¼ä 2019-07-04
1¡¢Ñо¿Ö°Ô±·¢Ã÷Ê׸öÀÄÓÃDNS over HTTPSЭÒéµÄ¶ñÒâÈí¼þGodlua

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
Ñо¿Ö°Ô±·¢Ã÷Ê׸öÀÄÓÃDNS over HTTPS£¨DoH£©Ð­ÒéµÄ¶ñÒâÈí¼þGodlua£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÊÇÒ»¸öÓÃLua±àдµÄ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬Æä×÷ÓÃÀàËÆÓÚºóÃÅ¡£¡£¡£¹¥»÷ÕßʹÓÃÎó²î£¨CVE-2019-3396£©À´Ñ¬È¾LinuxЧÀÍÆ÷¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷µÄÁ½¸öGodluaÑù±¾¶¼Ê¹ÓÃDNS over HTTPSÇëÇóÀ´»ñÈ¡ÓòÃûTXT£¬£¬£¬£¬£¬ÆäÖд洢ÁËC£¦CЧÀÍÆ÷µÄURL¡£¡£¡£ÕâÖÖ´ÓDNSÎı¾¼Í¼ÖмìË÷µÚ¶þ/µÚÈý½×¶ÎC£¦CЧÀÍÆ÷URLµØµãµÄÊÖÒÕ²¢²»ÐÂÏÊ£¬£¬£¬£¬£¬µ«Ê¹ÓÃDoHÇëÇó¶ø²»ÊǹŰåµÄDNSÇëÇóΪÊ״ηºÆð¡£¡£¡£DoH£¨DNS£©ÇëÇó¶ÔµÚÈý·½ÊÓ²ìÕß¼ÓÃÜÇÒ²»¿É¼û£¬£¬£¬£¬£¬Õâ°üÀ¨ÒÀÀµ±»¶¯DNS¼à¿ØÀ´×èÖ¹¶ÔÒÑÖª¶ñÒâÓòÇëÇóµÄÍøÂçÇå¾²Èí¼þ¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/first-ever-malware-strain-spotted-abusing-new-doh-dns-over-https-protocol/

2¡¢WannaLockerбäÌå°üÀ¨ÈýÖØÍþв£¬£¬£¬£¬£¬Ãé×¼°ÍÎ÷ËļÒÒøÐÐ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
AvastÑо¿Ö°Ô±Nikolaos Chrysaidos·¢Ã÷ÊÖ»úÀÕË÷Èí¼þWannaLockerµÄбäÌå°üÀ¨ÈýÖØÍþв£¬£¬£¬£¬£¬Ö÷ÒªÕë¶Ô°ÍÎ÷µÄËļÒÒøÐС£¡£¡£Æ¾Ö¤ChrysaidosµÄÊÓ²ìЧ¹û£¬£¬£¬£¬£¬WannaLockerбäÌåÊÇWannaCryµÄÄ£ÄâÕߣ¬£¬£¬£¬£¬¸Ã±äÌå½«ÌØ¹¤Èí¼þ¡¢RATºÍÒøÐÐľÂíÀ¦°óÔÚÒ»¸öÀÕË÷Èí¼þ°üÖС£¡£¡£¸Ã±äÌå¿ÉÍøÂçÎı¾ÐÅÏ¢¡¢Í¨»°¼Í¼¡¢µç»°ºÅÂëºÍÐÅÓÿ¨ÐÅÏ¢¡£¡£¡£Ñо¿Ö°Ô±Éв»ÇåÎú¸Ã±äÌåÈëÇÖÊÖ»úµÄѬȾÏòÁ¿£¬£¬£¬£¬£¬µ«ÏÓÒÉËü¿ÉÄÜÊÇͨ¹ý¶ñÒâÁ´½Ó»òµÚÈý·½ÊÐËÁ¾ÙÐÐÈö²¥¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://blog.avast.com/wannalocker-targets-banks-in-brazil

3¡¢·¸·¨ÍÅ»ïSilence Group´ÓÃϼÓÀ­¹úÈý¼ÒÒøÐÐÇÔÈ¡300ÍòÃÀÔª

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
´ÓÃϼÓÀ­¹úÒøÐÐÇÔÈ¡ÖÁÉÙ300ÍòÃÀÔªµÄ¹¥»÷¿ÉÄÜÊÇ·¸·¨ÍÅ»ïSilence GroupËùΪ¡£¡£¡£¸ÃÍÅ»ïÖÁÉÙ´Ó2016Äê×îÏÈ»îÔ¾£¬£¬£¬£¬£¬Çå¾²³§ÉÌGroup-IBÒÔΪ¸ÃÍÅ»ïµÄ½¹µãÊÇÁ½Ãû¶íÓï·¸·¨Õß¡£¡£¡£5Ô·ÝÃϼÓÀ­¹úµÄÈý¼Ò˽ÈËÒøÐУ¨DBBLÒøÐС¢NCCÒøÐкÍPrimeÒøÐУ©ÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬ËðʧÁè¼Ý300ÍòÃÀÔª¡£¡£¡£Æ¾Ö¤Ïà¹ØÖ¤¾Ý£¬£¬£¬£¬£¬Group-IBÒÔΪ¸Ã¹¥»÷ÊÂÎñÊÇÓÉSilence GroupËùΪ¡£¡£¡£Group-IB·¢Ã÷DBBLµÄÖ÷»úÓëSilence GroupµÄC2ЧÀÍÆ÷¾ÙÐÐͨѶ£¬£¬£¬£¬£¬¸ÃͨѶÖÁÉÙ´Ó2019Äê2Ô·ݾÍÒÑ×îÏÈ¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/silence-group-likely-behind-recent-3m-bangladesh-bank-heist/

4¡¢ÃÀ¹úÍøÂç˾ÁÐû²¼ÓйØÊ¹ÓÃOutlookÎó²îµÄ¹¥»÷»î¶¯µÄ¾¯±¨

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
ÃÀ¹úÍøÂç˾ÁÔÚTwitterÉÏÐû²¼¹ØÓÚʹÓÃ΢ÈíOutlookÖÐÒÑÖªÎó²îµÄ¾¯±¨¡£¡£¡£¸ÃÎó²î±»¸ú×ÙΪCVE-2017-11774£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓôËÎó²îÔÚÕþ¸®ÍøÂçÉϰ²ÅŶñÒâÈí¼þ¡£¡£¡£¸ÃÎó²îÓÉSensePostÇå¾²Ñо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÈÆ¹ýOutlookɳÏä²¢ÔÚϵͳÉÏÔËÐжñÒâ´úÂë¡£¡£¡£APT33ÔøÔÚ2018ÄêʹÓøÃÎó²îÏòÄ¿µÄϵͳÉϰ²ÅŶñÒâÈí¼þ¡£¡£¡£¸ÃÎó²îµÄÐÞ¸´²¹¶¡ÔÚ2017Äê10ÔÂÐû²¼£¬£¬£¬£¬£¬½¨Ò黹δװÖò¹¶¡µÄÓû§¾¡¿ì¸üС£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/us-cyber-command-issues-alert-about-attack-campaign-exploiting-outlook-vulnerability-fbcb95bf

5¡¢Ñо¿ÍŶÓÅû¶Chrome V8ÒýÇæÖеÄÄÚ´æËð»µÎó²î£¬£¬£¬£¬£¬¿Éµ¼ÖÂRCE

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
˼¿ÆTalosÅû¶Google ChromeµÄV8 JavaScriptÒýÇæÖеÄÄÚ´æËð»µÎó²î£¨CVE-2019-5831£©£¬£¬£¬£¬£¬¸ÃÎó²î¿ÉÔÊÐí¹¥»÷ÕßÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£Æ¾Ö¤TalosµÄ±íÊö£¬£¬£¬£¬£¬¶ñÒâJavaScript´úÂë¿ÉÄÜ»áÔÚV8 7.3.492.17Öд¥·¢ÄÚ´æË𻵣¬£¬£¬£¬£¬µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£ÎªÁË´¥·¢´ËÎó²î£¬£¬£¬£¬£¬Êܺ¦ÕßÐèÒª»á¼û¶ñÒâÍøÒ³¡£¡£¡£¸ÃÎó²îµÄCVSSÆÀ·ÖΪ7.5£¬£¬£¬£¬£¬¹È¸èÒÑÔÚ3Ô·ÝÐÞ¸´ÁËÕâ¸öÎó²î¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://blog.talosintelligence.com/2019/07/vulnerability-spotlight-Google-V8-June-19.html

6¡¢Áè¼Ý30¸öVMware²úÆ·Êܵ½Linux SACKÎó²îÓ°Ïì

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
VMwareÈ·ÈÏSACK PanicºÍSACK SlownessÎó²îÓ°ÏìÆä¶à¸ö²úÆ·¡£¡£¡£¸Ã¹«Ë¾Òѽ«SACK PanicÆÀ¼¶ÎªÖ÷Òª²¢¸¶Óë7.5µÄCVSSÆÀ·Ö£¬£¬£¬£¬£¬SACK SlownessΪÖеȺÍCVSSÆÀ·Ö5.3¡£¡£¡£Æ¾Ö¤VMwareÐû²¼µÄÇ徲ͨ¸æ£¬£¬£¬£¬£¬ÀÖ³ÉʹÓÃÕâЩÎó²î¿ÉÄܻᵼÖÂÄ¿µÄϵͳ±ÀÀ£»£»£»£»£»£»òÑÏÖØ½µµÍÐÔÄÜ¡£¡£¡£ÊÜÓ°ÏìµÄ²úÆ·°üÀ¨vCenter Server Appliance¡¢vCloud¡¢vRealizeºÍvSphereµÈ¡£¡£¡£VMwareÕýÔÚΪÿ¸öÊÜÓ°ÏìµÄ²úÆ·¿ª·¢²¹¶¡£¬£¬£¬£¬£¬µ«µ½ÏÖÔÚΪֹËü½öÐû²¼ÁËSD-WANÈí¼þ¡¢Unified Access GatewayºÍvCenter Server ApplianceµÄ¸üС£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.securityweek.com/many-vmware-products-affected-sack-linux-vulnerabilities