ŦԼSHIELD·¨°¸ÕýʽÉúЧ£¬£¬£¬ £¬£¬£¬ÒªÇóÀ©´óÊý¾Ýй¶֪ͨ¹æÄ££»£»£»£»£»£»£»Keepnet Labs ESʵÀýй¶Áè¼Ý50ÒÚÌõ¼Í¼

Ðû²¼Ê±¼ä 2020-03-23

1.ŦԼSHIELD·¨°¸ÕýʽÉúЧ£¬£¬£¬ £¬£¬£¬ÒªÇóÀ©´óÊý¾Ýй¶֪ͨ¹æÄ£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


3ÔÂ21ÈÕŦԼÖÝSHIELD·¨°¸ÕýʽÉúЧ£¬£¬£¬ £¬£¬£¬¸Ã·¨°¸¶ÔŦԼµÄ¡¶Ò»Ñùƽ³£ÉÌÒµ·¨¡·¾ÙÐÐÁËÐÞ¶©£¬£¬£¬ £¬£¬£¬´ú±íÁËŦԼÏÖ´æÍøÂçÇå¾²¼°Êý¾Ýй¶֪ͨ·¨°¸µÄÀ©Õ¹°æ±¾¡£¡£¡£¡£¸Ã·¨°¸¶ÔÆóÒµµÄÁ½¸öÖ÷ÒªÓ°ÏìÊÇ£º1¡¢À©´óÊý¾Ýй¶֪ͨҪÇ󣻣»£»£»£»£»£»2¡¢ÒªÇóÆóÒµÔÚ±£»£»£»£»£»£»£»¤Å¦Ô¼×¡ÃñµÄ¡°Ð¡ÎÒ˽¼ÒÐÅÏ¢¡±·½Ãæ½ÓÄÉ¡°ºÏÀíµÄ°ü¹Ü¡±¡£¡£¡£¡£ÏêϸÀ´Ëµ£¬£¬£¬ £¬£¬£¬¸Ã·¨°¸½«Å¦Ô¼ÖݵÄСÎÒ˽¼ÒÊý¾Ý½ç˵À©Õ¹µ½ÁËÎÞÐèÆäËüÑéÖ¤ÐÅÏ¢¼´¿É»á¼û²ÆÎñÕË»§µÄÕ˺źÍÐÅÓÿ¨/½è¼Ç¿¨ºÅÂ룬£¬£¬ £¬£¬£¬ÒÔ¼°ÓÃÓÚ¾ÙÐÐÉí·ÝÑéÖ¤µÄÖ¸ÎÆ¡¢ÉùÎÆµÈÉúÎïʶ±ðÐÅÏ¢¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.insideprivacy.com/data-security/cybersecurity/new-york-shield-acts-reasonable-safeguard-requirements-became-effective-on-march-21st-is-your-company-ready/


2.GoogleÐû²¼ChromeÇå¾²¸üУ¬£¬£¬ £¬£¬£¬ÐÞ¸´13¸öÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¹È¸èÐû²¼ÊÊÓÃÓÚWindows¡¢MacºÍLinuxµÄChrome 80.0.3987.149£¬£¬£¬ £¬£¬£¬ÐÞ¸´13¸öÎó²î¡£¡£¡£¡£ÆäÖÐ×îÑÏÖØµÄÎó²îÊÇCVE-2020-6422£¬£¬£¬ £¬£¬£¬ËüÊÇÒ»¸öÓ°ÏìWebGLµÄuse-after-free£¨UAF£©Îó²î¡£¡£¡£¡£±ðµÄ£¬£¬£¬ £¬£¬£¬¹È¸è»¹ÐÞ¸´ÁËýÌå×é¼þÖеÄUAFÎó²î£¨CVE-2020-6424£©ºÍÀ©Õ¹ÖеÄÕ½ÂÔÖ´ÐÐȱ·¦ÎÊÌ⣨CVE-2020-6425£©£¬£¬£¬ £¬£¬£¬ÒÔ¼°ÒôƵ×é¼þÖеÄ4¸öUAFÎÊÌ⣨CVE-2020-6427¡¢CVE-2020-6428¡¢CVE-2020-6429ºÍCVE-2020-6449£©¡£¡£¡£¡£ÆäËüÎó²î»¹°üÀ¨usersctplibÖеÄÔ½½ç¶ÁÎó²î£¨CVE-2019-20503£©ºÍV8ÒýÇæÖеIJ»Êʵ±µÄʵÏÖÎÊÌ⣨CVE-2020-6426£©¡£¡£¡£¡£¹È¸è»¹ÌåÏÖÓÉÓÚCOVID-19±¬·¢¶øÔÝÍ£ÁËChromeºÍChrome OSµÄ°æ±¾Ðû²¼¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/100164/security/google-chrome-bugs.html


3.ÀÕË÷Èí¼þNetwalkerʹÓÃйڲ¡¶¾´¹ÂڻѬȾÓû§


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


MalwareHunterTeam·¢Ã÷ÀÕË÷Èí¼þNetwalkerʹÓÃйڲ¡¶¾ÍøÂç´¹ÂڻѬȾÓû§¡£¡£¡£¡£NetwalkerÒÔǰ±»³ÆÎªMailto£¬£¬£¬ £¬£¬£¬ÆäÖ÷ÒªÕë¶ÔÆóÒµºÍÕþ¸®»ú¹¹£¬£¬£¬ £¬£¬£¬²¢ÒÔ¹¥»÷Toll¼¯ÍźÍÒÁÀûŵÒÁÖÝÏãéĶò±¾Äɹ«¹²ÎÀÉúÇø£¨CHUPD£©¶øÖøÃû¡£¡£¡£¡£ÐµÄNetwalker´¹ÂڻÕýÔÚʹÓÃÃûΪ¡°CORONAVIRUS_COVID-19.vbs¡±µÄ¸½¼þѬȾÓû§£¬£¬£¬ £¬£¬£¬SentinelLabsÈÏÕæÈËVitali KremezÌåÏָð汾µÄNetwalkerÌØÊâ×èÖ¹ÁËÖÕÖ¹Fortinetɱ¶¾Èí¼þ¿Í»§¶Ë£¬£¬£¬ £¬£¬£¬´Ë¾Ù¿ÉÄÜÊÇΪÁË×èÖ¹±»·¢Ã÷¡£¡£¡£¡£ÏÖÔÚ¸ÃÀÕË÷Èí¼þÉÐÎÞÃâ·ÑµÄ½âÃܹ¤¾ß¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/netwalker-ransomware-infecting-users-via-coronavirus-phishing/


4.ÐÂÀ¬»øÓʼþ»î¶¯Ã°³äÊÀÎÀ×éÖ¯ÈÏÕæÈË·Ö·¢HawkEyeľÂí


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


IBM X-Force Threat IntelligenceµÄÑо¿Ö°Ô±·¢Ã÷Ò»¸öеÄÀ¬»øÓʼþ»î¶¯Î±×°³ÉÊÀÎÀ×éÖ¯£¨WHO£©ÈÏÕæÈËÈö²¥¶ñÒâÈí¼þHawkEye¡£¡£¡£¡£¸ÃÀ¬»øÓʼþÉù³Æ°üÀ¨COVID-19Ô¤·ÀºÍ¿ìËÙÖÎÓúÒ©ÎïµÄÖ¸ÄÏ£¬£¬£¬ £¬£¬£¬»¹³Æ¡°ÕâÊÇÌìÏÂÎÀÉú×éÖ¯µÄÖ¸Á£¬£¬ £¬£¬£¬Ö¼ÔÚ×ÊÖú¶Ô¿¹Ð¹ڲ¡¶¾¡±£¬£¬£¬ £¬£¬£¬ÉõÖÁÒªÇóÊÕ¼þÈ˽«Æäת·¢¸ø¼ÒÈ˺ÍÅóÙ­¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖ£¬£¬£¬ £¬£¬£¬HawkEyeÖ¼ÔÚ´ÓÊÜѬȾµÄ×°±¸ÖÐÇÔÊØÐÅÏ¢£¬£¬£¬ £¬£¬£¬µ«Ò²¿ÉÒÔÓÃ×÷×°ÔØ³ÌÐò£¬£¬£¬ £¬£¬£¬Ê¹ÓÃÆä½©Ê¬ÍøÂç°²ÅÅÆäËü¶ñÒâÈí¼þ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/who-chief-impersonated-in-phishing-to-deliver-hawkeye-malware/


5.µÂÖÝAffordacareÕïËùÔâMaze¹¥»÷£¬£¬£¬ £¬£¬£¬40GBÊý¾Ý±»µÁ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


µÂ¿ËÈøË¹ÖݽôÆÈÕչ˻¤Ê¿ÕïËùAffordacareÔâµ½ÀÕË÷Èí¼þMaze¹¥»÷£¬£¬£¬ £¬£¬£¬¹¥»÷ÍÅ»ïÉù³ÆÈôÊǸÃÕïËù²»Ö§¸¶Êê½ð£¬£¬£¬ £¬£¬£¬Ôò»áй¶Æä»¼ÕßÊý¾Ý¡£¡£¡£¡£AffordacareÌṩ³£¼û¼²²¡ºÍΣÏÕµÄÒ½ÁÆÐ§ÀÍ£¬£¬£¬ £¬£¬£¬µ«¸ÃÕïËùûÓÐ͸¶ÊÇ·ñÌṩCOVID-19¼ì²âЧÀÍ¡£¡£¡£¡£Æ¾Ö¤Databreaches.netµÄÊý¾Ý£¬£¬£¬ £¬£¬£¬AffordaCareÓÚ2ÔÂ1ÈÕѬȾMaze£¬£¬£¬ £¬£¬£¬µ«ÔÚÕâÖ®ºó¸ÃºÚ¿ÍÍÅ»ïÇÔÈ¡ÁËÁè¼Ý40GBÊý¾Ý£¬£¬£¬ £¬£¬£¬ÆäÖаüÀ¨»¼ÕßµÄÈ«Ãû¡¢Éç»áÇå¾²ºÅÂë¡¢³öÉúÈÕÆÚ¡¢Õï¶Ï´úÂë¡¢ÖÎÁÆ´úÂë¡¢»¼ÕߵصãºÍµç»°ºÅÂë¡¢Ïà¹Ø²¡Ê·ºÍ¾ÍÕïÔµ¹ÊÔ­ÓÉ¡¢Õ˵¥ÐÅÏ¢¡¢°ü¹ÜÕþ²ßÐÅÏ¢µÈ£¬£¬£¬ £¬£¬£¬»¹°üÀ¨AffordaCareÔ±¹¤µÄÅâ³¥ÎļþºÍÔ±¹¤Ð½×ÊÐÅÏ¢¡£¡£¡£¡£¸ÃÕïËùÉÐδȷÈÏÈëÇÖÊÂÎñ£¬£¬£¬ £¬£¬£¬µ«MazeÍÅ»ïÒÑÔÚÆäÍøÕ¾ÉϹûÕæÁËÈëÇÖÐÐΪ£¬£¬£¬ £¬£¬£¬²¢Íþв½«Ðû²¼Êý¾ÝµÄÑù±¾¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://hotforsecurity.bitdefender.com/blog/maze-ransomware-continues-to-hit-healthcare-units-amid-coronavirus-covid-19-outbreak-22654.html


6.Keepnet Labs ESʵÀýй¶Áè¼Ý50ÒÚÌõ¼Í¼£¬£¬£¬ £¬£¬£¬¾ùΪÒÔǰй¶


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ó¢¹úÇå¾²³§ÉÌKeepnet LabsµÄÒ»¸öElasticsearchʵÀýй¶ÁËÁè¼Ý50ÒÚÌõÊý¾Ý¼Í¼£¬£¬£¬ £¬£¬£¬ÕâЩ¼Í¼ÊÇ2012ÄêÖÁ2019ÄêÖ®¼ä±¬·¢µÄй¶ÊÂÎñÖеļͼ¡£¡£¡£¡£¸ÃÊý¾Ý¿âÓÉÁ½¸öÜöÝÍ×é³É£¬£¬£¬ £¬£¬£¬Ò»¸ö°üÀ¨50.88ÒÚÌõ¼Í¼£¬£¬£¬ £¬£¬£¬¶øÁíÒ»¸öʵʱ¸üеÄÜöÝÍÔò°üÀ¨Áè¼Ý1500ÍòÌõ¼Í¼¡£¡£¡£¡£Ð¹Â¶µÄ¼Í¼°üÀ¨¹þÏ£ÀàÐÍ¡¢Ð¹Â¶Äê·Ý¡¢ÃÜÂ루¹þÏ£¡¢¼ÓÃÜ»òÃ÷ÎÄÃûÌã©¡¢µç×ÓÓʼþ¡¢µç×ÓÓʼþÓòÃûÒÔ¼°Ð¹Â¶Ô´£¨°üÀ¨Adobe¡¢Last.fm¡¢Twitter¡¢LinkedIn¡¢TumblrºÍVKµÈ£©¡£¡£¡£¡£Keepnet LabsÌåÏÖÊý¾Ý¿âÊÇÔÚÆä¹©Ó¦É̽«Ë÷ÒýǨáãÖÁÁíһ̨ESЧÀÍÆ÷ʱ̻¶µÄ£¬£¬£¬ £¬£¬£¬ÔÚǨáãÀú³ÌÖзÀ»ðǽÔÝʱ½ûÓÃÁËÔ¼10·ÖÖÓ£¬£¬£¬ £¬£¬£¬Ê¹µÃËÑË÷ÒýÇæ¿ÉÒÔΪÊý¾Ý¿â½¨ÉèË÷Òý¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/100198/data-breach/keepnet-labs-data-leak.html