2024ÄêÈ«ÇòÊý¾Ýй¶±¾Ç®Ô¤¼Æ½«´ï5ÍòÒÚÃÀÔª£»£»£»¹¥»÷ÕßʹÓÃOrcusºÍRevenge RATÕë¶ÔÕþ¸®ºÍ½ðÈÚ»ú¹¹
Ðû²¼Ê±¼ä 2019-08-30
1.2024ÄêÈ«ÇòÊý¾Ýй¶±¾Ç®Ô¤¼Æ½«´ï5ÍòÒÚÃÀÔª
ƾ֤հ²©ÍøÂçµÄ×îÐÂÕ¹Íû£¬£¬£¬£¬£¬£¬£¬Ëæ×Åî¿Ïµ·£¿£¿£¿£¿£¿£¿£¿îµÄʵÑéÒÔ¼°ÆóÒµÔ½·¢ÒÀÀµÓÚÊý×Öϵͳ£¬£¬£¬£¬£¬£¬£¬µ½2024ÄêÈ«ÇòÊý¾Ýй¶µÄ±¾Ç®Ô¤¼Æ½«ÔöÌíµ½5ÍòÒÚÃÀÔªÒÔÉÏ¡£¡£¡£¡£¡£¡£¡£ÕâÒ»Êý¾ÝÀ´×ÔÓڸù«Ë¾Ðû²¼µÄ×îб¨¸æ¡¶ÍøÂç·¸·¨ºÍÇå¾²µÄδÀ´£º2019-2024ÍþвÆÊÎö¡¢Ó°ÏìÆÀ¹À»ººÍ½âÕ½ÂÔ±¨¸æ¡·¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Éù³Æ£¬£¬£¬£¬£¬£¬£¬ÔÚ±¨¸æÊ±´úÄÚÔ¤¼ÆÊý¾Ýй¶±¾Ç®½«´Ó2019ÄêµÄ3ÍòÒÚÃÀԪÿÄêÔöÌí11%¡£¡£¡£¡£¡£¡£¡£±¨¸æÖл¹³ÆËäÈ»´ó¹æÄ£µÄÊý¾Ýй¶¿ÉÄܳÉΪͷÌõÐÂÎÅ£¬£¬£¬£¬£¬£¬£¬µ«ËüÃDz¢·×Æç¶¨»áÖ±½ÓÓ°Ï챾Ǯ£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ·£¿£¿£¿£¿£¿£¿£¿îºÍÓªÒµËðʧÓëÊý¾Ýй¶µÄ¹æÄ£²¢²»Ï¸ÃÜÏà¹Ø¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/breach-costs-trillion/
2.Google PlayÖÐÁ½¸ö¹ã¸æÓ¦ÓÃÏÂÔØÁ¿³¬150Íò´Î
Ñо¿Ö°Ô±ÔÚGoogle PlayÖз¢Ã÷Á½¸ö¹ã¸æÓ¦Ó㬣¬£¬£¬£¬£¬£¬×ÜÏÂÔØÁ¿Áè¼Ý150Íò´Î¡£¡£¡£¡£¡£¡£¡£µÚÒ»¸öAPPÊÇOCRÎı¾É¨ÃèÒÇ£¬£¬£¬£¬£¬£¬£¬Æä×°ÖÃÊýÄ¿Áè¼Ý100Íò£¬£¬£¬£¬£¬£¬£¬ÁíÒ»¸öÊÇÒ»¸ö½¡ÉíAPP£¬£¬£¬£¬£¬£¬£¬×°ÖÃÊýÄ¿Áè¼Ý50Íò¡£¡£¡£¡£¡£¡£¡£ËüÃÇÊôÓÚͳһ¿ª·¢ÕßIdea Master¡£¡£¡£¡£¡£¡£¡£¸Ã¹ã¸æÈí¼þʹÓÃAndroid Notification Manager·¢³öÐÂÎÅ£¬£¬£¬£¬£¬£¬£¬µ±Óû§µ¥»÷ÐÂÎÅʱ»á´¥·¢ÏÔʾ´øÓÐ¹ã¸æµÄÒþ²ØÊÓͼ¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿ª·¢ÕßʹÓÃToast֪ͨ¼ÓÔØ¹ã¸æ£¬£¬£¬£¬£¬£¬£¬²¢Í¨¹ý½«Toast¹¤¾ß¶¨Î»ÔÚÆÁÄ»µÄ¿ÉÊÓÇøÓòÖ®Í⣬£¬£¬£¬£¬£¬£¬Ê¹µÃ¹ã¸æ¶ÔÓû§²»¿É¼û¡£¡£¡£¡£¡£¡£¡£ËäÈ»Óû§ÎÞ·¨¿´µ½¹ã¸æ£¬£¬£¬£¬£¬£¬£¬µ«ËûÃǵÄÌåÑé»áÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬°üÀ¨×°±¸ÐÔÄÜϽµ¡¢µçÁ¿ÏûºÄÒÔ¼°ÍøÂçÁ÷Á¿µÄʹÓÃÔöÌí¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/ghost-clicks-boost-ad-revenue-for-android-apps-with-15m-installs/
3.¹¥»÷ÕßʹÓÃOrcusºÍRevenge RATÕë¶ÔÕþ¸®ºÍ½ðÈÚ»ú¹¹
˼¿ÆTalosÑо¿Ö°Ô±·¢Ã÷¹¥»÷ÕßÕýÔÚʹÓÃRevenge RATºÍOrcus RATÕë¶ÔÕþ¸®»ú¹¹¡¢½ðÈÚЧÀÍÆóÒµ¡¢ÐÅÏ¢ÊÖÒÕЧÀ͹©Ó¦É̺Í×Éѯ¹«Ë¾µÈ¡£¡£¡£¡£¡£¡£¡£Revenge RATÊÇ2016ÄêÔÚDev PointºÚ¿ÍÂÛ̳ÉϹûÕæÐû²¼µÄRAT£¬£¬£¬£¬£¬£¬£¬Ëü¿ÉÒÔ·¿ªÔ¶³Ìshell£¬£¬£¬£¬£¬£¬£¬ÔÊÐí¹¥»÷ÕßÖÎÀíϵͳÎļþ¡¢Àú³Ì¡¢×¢²á±íºÍЧÀÍ¡¢¼Í¼°´¼ü¡¢ÍøÂçÃÜÂëÒÔ¼°»á¼ûÉãÏñÍ·µÈ¡£¡£¡£¡£¡£¡£¡£Orcus×Ô2016ÄêÍ·ÒÔÀ´±»Ðû´«ÎªÔ¶³ÌÖÎÀí¹¤¾ß£¬£¬£¬£¬£¬£¬£¬µ«¼øÓÚËü»¹¾ßÓÐÔ¶¿ØÄ¾Âí¹¦Ð§£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚËüÒ²±»ÒÔΪÊÇÒ»ÖÖÄܹ»¼ÓÔØ×Ô½ç˵²å¼þµÄ¶ñÒ⹤¾ß¡£¡£¡£¡£¡£¡£¡£ÕâЩ¹¥»÷»î¶¯µÄÔËÓªÕßʹÓö¯Ì¬ÓòÃûϵͳ£¨DDNS£©À´Òþ²ØËûÃǵÄC2ЧÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬Ë¼¿ÆTalosÔÚ±¨¸æÖÐÏêϸÁгöÁ˶ñÒâÑù±¾¹þÏ£¡¢¹¥»÷ÓòÃûÒÔ¼°IPµØµãµÈ¹¥»÷Ö¸±ê£¨IOC£©¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/attackers-target-govt-and-financial-orgs-with-orcus-revenge-rats/
4.Ñо¿Ö°Ô±ÔÚ¶à¸öWordPress²å¼þÖз¢Ã÷9¸öSQL×¢ÈëÎó²î
FortinetÔÚ9¸öÊ¢ÐеÄWordPress²å¼þÖз¢Ã÷9¸öSQL×¢ÈëÎó²î¡£¡£¡£¡£¡£¡£¡£ÕâЩ²å¼þµÄ¹æÄ£º¸Ç¹ã¸æ¡¢¾èÔù¡¢Í¼¿â¡¢±í¸ñ¡¢ÐÂÎÅͨѶºÍÊÓÆµ²¥·ÅÆ÷µÈ£¬£¬£¬£¬£¬£¬£¬ÊýÒÔÊ®Íò¼ÆµÄWordPressÍøÕ¾ÕýÔÚÆð¾¢Ê¹ÓÃÕâЩ²å¼þ£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÒ»Ð©ÍøÕ¾ÔÚÆäÏìÓ¦µÄÖÖ±ðÖÐÅÅÃûµÚÒ»¡£¡£¡£¡£¡£¡£¡£ËùÓÐ9¸öÎó²î¶¼±»·ÖÅÉÁËCVE±êʶ£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ±»FortiGuardÆÀΪÑÏÖØ¼¶±ðºÍ»ñµÃÁËCVSSÆÀ·Ö9.0·Ö¡£¡£¡£¡£¡£¡£¡£Õâ9¸öÎó²îÖÐÓÐ8¸öÎó²îʹÓÃÁËÏàͬµÄ¼òÆÓ´úÂëģʽ¡£¡£¡£¡£¡£¡£¡£¸÷²å¼þ¹©Ó¦É̶¼ÒѾÐû²¼ÁËÐÞ¸´²¹¶¡ºÍ¸üС£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.fortinet.com/blog/threat-research/wordpress-plugin-sql-injection-vulnerability.html
5.Check PointÐÞ¸´Endpoint SecurityÖеÄÌáȨÎó²î
Check PointÐÞ¸´ÆäEndpoint Security¿Í»§¶ËÈí¼þÖеÄÌáȨÎó²î£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²î£¨CVE-2019-8461£©ÔÊÐíDZÔڵĹ¥»÷ÕßÌáÉýÆäȨÏÞÖÁSYSTEM²¢Ö´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£SafeBreach LabsÇå¾²Ñо¿Ô±Peleg Hadar·¢Ã÷Á˸ÃÎÊÌ⣬£¬£¬£¬£¬£¬£¬¼´¿Éͨ¹ý½«í§ÒâδÊðÃûµÄDLL¼ÓÔØµ½Check Point Endpoint SecurityÈí¼þʹÓõÄWindowsЧÀÍÖ®Ò»À´ÊµÏÖȨÏÞÌáÉýºÍ³¤ÆÚÐÔ¡£¡£¡£¡£¡£¡£¡£Check PointÔÚ8ÔÂ27ÈÕÐû²¼°æ±¾¸üÐÂÐÞ¸´ÁË´ËÎó²î¡£¡£¡£¡£¡£¡£¡£ÕâÊÇHadarÔÚ8Ô·ÝÏòÇå¾²³§É̱¨¸æµÄµÚÈý¸öÍâµØÌáȨÎó²î£¬£¬£¬£¬£¬£¬£¬Ç°Á½¸öÊÇÇ÷ÊÆ¿Æ¼¼¼°BitdefenderÖеÄÀàËÆÎó²î£¨CVE-2019-14684ºÍCVE-2019-15295£©¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/check-point-patches-privilege-escalation-flaw-in-endpoint-client/
6.ÃÀ¹úÊý°Ù¼ÒÑÀ¿ÆÕïËùÔâÀÕË÷Èí¼þSodinokibi¹¥»÷
8ÔÂ26ÈÕÃÀ¹úÊý°Ù¼ÒÑÀ¿ÆÕïËùÔâÀÕË÷Èí¼þSodinokibi¹¥»÷£¬£¬£¬£¬£¬£¬£¬»¼ÕßÐÅÏ¢±»¼ÓÃÜ¡£¡£¡£¡£¡£¡£¡£ÕâÊǹ¥»÷Õßͨ¹ýÈëÇÖÈí¼þ¹©Ó¦É̲¢Ê¹ÓÃÆä²úÆ·ÔÚ¿Í»§ÏµÍ³ÉÏÖ²ÈëÀÕË÷Èí¼þµÄÁíÒ»¸ö°¸Àý¡£¡£¡£¡£¡£¡£¡£ÔÚ±¾ÆðÊÂÎñÖУ¬£¬£¬£¬£¬£¬£¬Èí¼þ¹©Ó¦ÉÌÊÇThe Digital Dental RecordºÍPerCSoft£¬£¬£¬£¬£¬£¬£¬ËûÃÇÏàÖú¿ª·¢ÁËÒ½ÁƼͼÉúÑĺͱ¸·ÝÈí¼þDDS Safe¡£¡£¡£¡£¡£¡£¡£ÉÏÖÜÄ©ºÚ¿ÍÍÅ»ïÈëÇÖÁ˸ÃÈí¼þ±³ºóµÄ»ù´¡ÉèÊ©£¬£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃËüÔÚÊý°Ù¸öÑÀÒ½ÕïËùµÄÅÌËã»úÉϰ²ÅÅÁËÀÕË÷Èí¼þSodinokibi¡£¡£¡£¡£¡£¡£¡£ÕâÁ½¼Ò¹«Ë¾Ñ¡ÔñÖ§¸¶Êê½ð»ñÈ¡½âÃÜÆ÷£¬£¬£¬£¬£¬£¬£¬µ«ÏÖÔÚ»Ö¸´½ø¶È»ºÂý£¬£¬£¬£¬£¬£¬£¬Ò»Ð©ÑÀ¿ÆÕïËùÉù³Æ½âÃÜÆ÷Ҫô²»Æð×÷Ó㬣¬£¬£¬£¬£¬£¬ÒªÃ´Ã»Óлָ´ËùÓÐÊý¾Ý¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/ransomware-hits-hundreds-of-dentist-offices-in-the-us/


¾©¹«Íø°²±¸11010802024551ºÅ