CrowdStrikeÐû²¼¡¶2020ÄêÈ«ÇòÍþв±¨¸æ¡·£»£»£» £»Ó¢¹úÊý¾Ýî¿Ïµ»ú¹¹¶Ô¹úÌ©º½¿Õ´¦ÒÔ50ÍòÓ¢°÷·£¿ £¿ £¿î

Ðû²¼Ê±¼ä 2020-03-05

1.CrowdStrikeÐû²¼¡¶2020ÄêÈ«ÇòÍþв±¨¸æ¡·

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

CrowdStrikeµÄ¡¶2020ÄêÈ«ÇòÍþв±¨¸æ¡·¶ÔÒÑÍùÒ»ÄêÖж¥¼¶ÍøÂçÍþвÇ÷ÊÆ¾ÙÐÐÁËÉîÈëÆÊÎö£¬£¬ £¬£¬ £¬£¬£¬¸Ã±¨¸æµÄÒªµã°üÀ¨£º´óÐ͹¥»÷»î¶¯£¨BGH£©Ò»Ö±Éý¼¶£¬£¬ £¬£¬ £¬£¬£¬Êê½ðÒªÇóì­ÉýÖÁÊý°ÙÍò£¬£¬ £¬£¬ £¬£¬£¬²¢ÇÒÔì³É¼«´óµÄÆÆË𣻣»£» £»ÍøÂç·¸·¨·Ö×ÓÕýÔÚʹÃô¸ÐÊý¾ÝÎäÆ÷»¯£¬£¬ £¬£¬ £¬£¬£¬ÒÔÔöÌí¶ÔÀÕË÷Èí¼þÊܺ¦ÕßµÄѹÁ¦£»£»£» £»eCrimeÉú̬ϵͳһֱÉú³¤£¬£¬ £¬£¬ £¬£¬£¬±äµÃ³ÉÊìºÍרҵ»¯Ë®Æ½Ò»Ö±Ìá¸ß£»£»£» £»ÔÚBGHÖ®Í⣬£¬ £¬£¬ £¬£¬£¬Õë¶ÔÈ«Çò½ðÈÚ»ú¹¹µÄeCrime»î¶¯ÓÐËùÔöÌí£»£»£» £»³¯ÏòÎÞ¶ñÒâÈí¼þÕ½ÂÔµÄÇ÷ÊÆÕýÔÚ¼ÓËÙ£»£»£» £»¹ú¼Ò×ÊÖúµÄÓÐÕë¶ÔÐÔµÄÈëÇֻ¼ÌÐøÕë¶Ô֪ʶ²úȨ/¾ºÕùÇ鱨£¬£¬ £¬£¬ £¬£¬£¬Ôö½øÉçÇøÄÚ²¿µÄÆÆË飬£¬ £¬£¬ £¬£¬£¬²¢ÊӲ쵽ÁËÓëÏȽøeCrime¹¥»÷ÕßµÄÏàÖú¡£¡£ ¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.crowdstrike.com/resources/reports/2020-crowdstrike-global-threat-report/


2.Ó¢¹úNCSCÐû²¼ÓйØÖÇÄÜ¼à¿ØÉãÏñÍ·µÄÇå¾²Ö¸ÄÏ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ó¢¹ú¹ú¼ÒÍøÂçÇå¾²ÖÐÐÄ£¨NCSC£©Ðû²¼ÓйØÔõÑù׼ȷÉèÖÃÖÇÄÜÇå¾²ÉãÏñÍ·ºÍÓ¤¶ù¼àÊÓÆ÷µÄÖ¸ÄÏ£¬£¬ £¬£¬ £¬£¬£¬ÒÔ×èÖ¹Óû§Êܵ½¹¥»÷ÕߵĹ¥»÷¡£¡£ ¡£¡£¡£¡£¡£NCSCÌåÏÖ¡°ÖÇÄÜÉãÏñ»ú£¨ÓÃÓÚ¼àÊÓºâÓîÄÚºÍÖÜΧ»î¶¯µÄÇå¾²ÉãÏñ»úºÍÓ¤¶ù¼àÊÓÆ÷£©Í¨³£Ê¹ÓüÒÍ¥Wi-FiÅþÁ¬µ½»¥ÁªÍø£¬£¬ £¬£¬ £¬£¬£¬ÔÚÉÙÉÙÊýÇéÐÎÏ£¬£¬ £¬£¬ £¬£¬£¬Î´¾­ÊÚȨµÄ¹¥»÷Õß¿ÉÒÔ»á¼ûÖÇÄÜÉãÏñ»úµÄʵʱÁ÷»òͼÏñ£¬£¬ £¬£¬ £¬£¬£¬Õâ»áʹÄúµÄÒþ˽Êܵ½Íþв¡£¡£ ¡£¡£¡£¡£¡£¡±ÎªÁ˵ÖÓù´ËÀ๥»÷£¬£¬ £¬£¬ £¬£¬£¬NCSC½¨ÒéʹÓÃÇ¿Á¦µÄ¡¢»ùÓÚÃÜÂë¶ÌÓïµÄÃÜÂë¸ü¸Ä×°±¸µÄĬÈÏÃÜÂ룬£¬ £¬£¬ £¬£¬£¬¸ÃÃÜÂë¿ÉÒÔʹÓÃÓû§Äܹ»¼Ç×ŵÄÈý¸öËæ»úµ¥´Ê¹¹½¨£¬£¬ £¬£¬ £¬£¬£¬²¢ÇÒ¼á³ÖÇå¾²ÉãÏñÍ·µÄ¹Ì¼þΪ×îкͽûÓò»ÐëÒªµÄÔ¶³ÌÉó²é¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/uk-ncsc-releases-tips-on-securing-smart-security-cameras/


3.·¸·¨ÍÅ»ïMoleratsй¥»÷»î¶¯£¬£¬ £¬£¬ £¬£¬£¬Õë¶ÔÕþ¸®ºÍµçÐÅÐÐÒµ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Palo Alto NetworksµÄUnit42ÍŶÓÔÚ2019Äê10Ôµ½2019Äê12ÔÂÊӲ쵽¶à¸öÓë·¸·¨ÍÅ»ïMoleratsÓйصĴ¹ÂÚ¹¥»÷»î¶¯¡£¡£ ¡£¡£¡£¡£¡£¹¥»÷ÕßµÄÄ¿µÄº­¸ÇÕþ¸®¡¢µçÐÅ¡¢°ü¹ÜºÍÁãÊÛÐÐÒµ£¬£¬ £¬£¬ £¬£¬£¬Éæ¼°6¸ö¹ú¼ÒµÄ8¸ö×éÖ¯¡£¡£ ¡£¡£¡£¡£¡£ËùÓÐÕâЩ¹¥»÷¶¼Éæ¼°µ½Ê¹Óô¹ÂÚÓʼþת´ï¶ñÒâÎĵµ£¬£¬ £¬£¬ £¬£¬£¬²¢Ê¹ÓÃÉç½»¹¤³ÌÊÖÒÕÒªÇóÊÕ¼þÈËÖ´ÐÐijЩ²Ù×÷£¬£¬ £¬£¬ £¬£¬£¬ÀýÈçÆôÓúê»òµã»÷Á´½ÓµÈ¡£¡£ ¡£¡£¡£¡£¡£´ó´ó¶¼´ËÀ๥»÷ÖеÄÓÐÓøºÔØÊÇSparkºóÃÅ£¬£¬ £¬£¬ £¬£¬£¬¸ÃºóÃÅÔÊÐí¹¥»÷ÕßÔÚÊÜѬȾµÄϵͳÉÏ·­¿ªÓ¦ÓóÌÐò²¢ÔËÐÐÏÂÁî¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/molerats-delivers-spark-backdoor/


4.Ó¢¹úÊý¾Ýî¿Ïµ»ú¹¹¶Ô¹úÌ©º½¿Õ´¦ÒÔ50ÍòÓ¢°÷·£¿ £¿ £¿î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ó¢¹úÐÅϢרԱ°ì¹«ÊÒÒò2018Äê940ÍòÂÿÍÊý¾Ýй¶ÊÂÎñ¶Ô¹úÌ©º½¿Õ¹«Ë¾´¦ÒÔ50ÍòÓ¢°÷µÄ·£¿ £¿ £¿î¡£¡£ ¡£¡£¡£¡£¡£¸Ã¹¥»÷ÒÉËÆ±¬·¢ÔÚ2018Äê3Ô·Ý£¬£¬ £¬£¬ £¬£¬£¬²¢ÓÚ5Ô·ݻñµÃÈ·ÈÏ£¬£¬ £¬£¬ £¬£¬£¬Æäʱ¹úÌ©º½¿ÕµÄÊý¾Ý¿âÔâµ½Á˱©Á¦ÆÆ½â¹¥»÷¡£¡£ ¡£¡£¡£¡£¡£ICOÊÓ²ì³Æ¹úÌ©µÄϵͳÊܵ½ÁËÊý¾ÝÍøÂçÀà¶ñÒâÈí¼þµÄÓ°Ï죬£¬ £¬£¬ £¬£¬£¬²¢·¢Ã÷¹úÌ©ÔÚÇå¾²ÐÔ·½ÃæµÄһЩȱ·¦£¬£¬ £¬£¬ £¬£¬£¬°üÀ¨²»ÊÜÃÜÂë±£»£»£» £»¤µÄ±¸·ÝÎļþ¡¢Î´´ò²¹¶¡µÄWebЧÀÍÆ÷¡¢ÒѹýʱµÄ²Ù×÷ϵͳºÍȱ·¦·À²¡¶¾±£»£»£» £»¤µÈ¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.theregister.co.uk/2020/03/04/ico_fines_cathay_pacific_500000/


5.¹È¸èÐû²¼3ÔÂAndroidÇå¾²¸üУ¬£¬ £¬£¬ £¬£¬£¬ÐÞ¸´70¶à¸öÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¹È¸èÐû²¼2020Äê3ÔÂAndroidÇå¾²¸üУ¬£¬ £¬£¬ £¬£¬£¬¹²ÐÞ¸´70¶à¸öÎó²î£¬£¬ £¬£¬ £¬£¬£¬ÆäÖÐ×îÑÏÖØµÄÎó²îÊÇýÌå¿ò¼Ü×é¼þÖеĴúÂëÖ´ÐÐÎó²î£¨CVE-2020-0032£©£¬£¬ £¬£¬ £¬£¬£¬¸ÃÎó²î¿ÉÄÜʹԶ³Ì¹¥»÷ÕßʹÓöñÒâÎļþÔÚÌØÈ¨Àú³ÌµÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂ룬£¬ £¬£¬ £¬£¬£¬¸ÃÎó²îÓ°ÏìÁËÔËÐÐAndroid 8.0¡¢8.1¡¢9ºÍ10°æ±¾µÄ×°±¸¡£¡£ ¡£¡£¡£¡£¡£±ðµÄ£¬£¬ £¬£¬ £¬£¬£¬¹È¸è»¹ÐÞ¸´ÁËýÌå¿ò¼ÜÖеÄÁíÍâÁ½¸öÑÏÖØÎó²î£¬£¬ £¬£¬ £¬£¬£¬°üÀ¨ÌØÈ¨ÌáÉýÎó²î£¨CVE-2020-0033£©ºÍÐÅϢй¶Îó²î£¨CVE-2020-0034£©¡£¡£ ¡£¡£¡£¡£¡£´Ë´Î¸üÐÂÐÞ¸´Á˸ßͨ±ÕÔ´×é¼þÖеÄ40¸öÎó²î£¬£¬ £¬£¬ £¬£¬£¬ÆäÖÐ16¸ö±»ÆÀΪÑÏÖØ¼¶±ð¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/98901/mobile-2/googles-march-2020-security-updates-android.html


6.¼ÎÄ껪ÓÎÂÖ¼¯ÍÅÔâºÚ¿ÍÈëÇÖ£¬£¬ £¬£¬ £¬£¬£¬¿Í»§Êý¾Ý¿ÉÄÜй¶


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


È«Çò×î´óµÄÓÎÂÖÔËÓªÉ̼ÎÄ껪ÓÎÂÖ¼¯ÍÅ£¨Carnival Corporation£¦plc£©ÔâºÚ¿ÍÈëÇÖ£¬£¬ £¬£¬ £¬£¬£¬¿Í»§Êý¾Ý¿ÉÄÜй¶¡£¡£ ¡£¡£¡£¡£¡£Æ¾Ö¤¸Ã¹«Ë¾µÄת´ï£¬£¬ £¬£¬ £¬£¬£¬ÔÚ2019Äê4ÔÂ11ÈÕÖÁ7ÔÂ23ÈÕÖ®¼äδ¾­ÊÚȨµÄ¹¥»÷Õß»á¼ûÁËijЩ°üÀ¨¿Í»§ÐÅÏ¢µÄÔ±¹¤ÓÊÏäÕË»§£¬£¬ £¬£¬ £¬£¬£¬¿ÉÄÜй¶µÄÐÅÏ¢°üÀ¨¿Í»§µÄÐÕÃû¡¢µØµã¡¢Éç»áÇå¾²ºÅÂë¡¢Õþ¸®Ê¶ÓÖÃûÂ루ÀýÈ绤ÕÕID»ò¼ÝÕÕID£©¡¢ÐÅÓÿ¨ºÍÒøÐÐÕË»§ÐÅÏ¢ÒÔ¼°Ó뿵½¡×´Ì¬Ïà¹ØµÄÐÅÏ¢¡£¡£ ¡£¡£¡£¡£¡£¼ÎÄ껪»¹³ÆÄ¿½ñûÓÐÖ¤¾ÝÅú×¢ÊÂÎñ±¬·¢ºóÊÜÓ°Ïì¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢±»ÀÄÓᣡ£ ¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/carnival-cruise-line-operator-discloses-potential-data-breach/