FireEyeÐû²¼½üÊýÄê0dayʹÓÃµÄÆÊÎö±¨¸æ £»£»£»£»£» £»£»COVID-19ʱ´úÕë¶ÔNASAµÄ´¹ÂÚ¹¥»÷´ó·ùÉÏÉý

Ðû²¼Ê±¼ä 2020-04-08

1.ʯÓ͹«Ë¾BerkineÔâMaze¹¥»÷£¬£¬£¬£¬Áè¼Ý500MBÊý¾Ý±»ÇÔ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


4ÔÂ1ÈÕʯÓ͹«Ë¾BerkineÔâµ½ÀÕË÷Èí¼þÍÅ»ïMaze¹¥»÷£¬£¬£¬£¬¹¥»÷ÕßÏë·¨ÇÔÈ¡Á˸ù«Ë¾µÄÊý¾Ý¿â£¬£¬£¬£¬ÆäÖаüÀ¨Áè¼Ý500MBµÄÉñÃØÎĵµ¡£¡£¡£ÕâЩÎĵµÓëÔ¤Ëã¡¢×éÖ¯Õ½ÂÔ¡¢Éú²úÁ¿µÈÃô¸ÐÊý¾ÝÓйء£¡£¡£BerkineÊǰ¢¶û¼°ÀûÑǹúÓÐʯÓ͹«Ë¾SonatrachºÍÃÀ¹úʯÓ͹«Ë¾Anadarko Algeria CompanyµÄºÏ×ÊÆóÒµ¡£¡£¡£Æ¾Ö¤Under BreachµÄ˵·¨£¬£¬£¬£¬Ð¹Â¶µÄÎĵµÓëBerkineµÄ²ÆÎñϸ½ÚºÍͶ×ÊÍýÏëÓйأ¬£¬£¬£¬°üÀ¨BerkineʯÓ͵ÄÿͰ±¾Ç®¼ÛÇ®¡¢2020ÄêµÄ×é֯ĿµÄÒÔ¼°·ÖÅɸøBerkineÁ½Î»ËùÓÐÕßµÄÖÖÖÖʹÃüµÄÔ¤Ëã¡£¡£¡£Êý¾Ý¿âÖл¹°üÀ¨BerkineÔ±¹¤ÁªÏµ·½·¨¼°ÂÃÐÐÖ¤¼þµÄÁÐ±í¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/maze-ransomware-group-hacks-oil-giant-leaks-data/


2.Email.itÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬60ÍòÓû§Êý¾ÝÔÚ°µÍø³öÊÛ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



Òâ´óÀûÓʼþЧÀÍÉÌEmail.itÈ·ÈÏÔâµ½ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬ÏÖÔÚÓÐÁè¼Ý60ÍòÓû§µÄÊý¾ÝÔÚ°µÍø³öÊÛ¡£¡£¡£ºÚ¿ÍÍÅ»ïNN£¨No Name£©Hacking GroupÉù³ÆÈëÇÖÏÖʵ±¬·¢ÔÚÁ½Äê¶àÒÔǰµÄ2018Äê1Ô¡£¡£¡£¸ÃÍÅ»ïÔÚ2ÔÂ1ÈÕÊÔͼÀÕË÷Email.it£¬£¬£¬£¬µ«Email.it¾Ü¾øÖ§¸¶Êê½ð²¢Í¨ÖªÁËÒâ´óÀûÓÊÕþ¾¯Ô±¾Ö£¨CNAIPIC£©¡£¡£¡£ÔÚÀÕË÷ʧ°Üºó£¬£¬£¬£¬¸ÃÍÅ»ïÏÖÔÚÒÔ0.5ÖÁ3±ÈÌØ±Ò£¨3500ÖÁ22000ÃÀÔª£©µÄ¼ÛÇ®³öÊÛÕâЩÊý¾Ý¡£¡£¡£¸ÃÍÅ»ïÉù³ÆÓµÓдÓEmail.itϵͳÖÐÇÔÈ¡µÄ46¸öÊý¾Ý¿â£¬£¬£¬£¬ÆäÖаüÀ¨Ãâ·ÑEmail.itµç×ÓÓʼþÕÊ»§µÄÓû§ÐÅÏ¢¡£¡£¡£ºÚ¿ÍÉù³ÆÊý¾Ý¿âÖаüÀ¨2007ÄêÖÁ2020ÄêÖ®¼ä×¢²áºÍʹÓøÃЧÀ͵Ä60¶àÍòÓû§µÄÃ÷ÎÄÃÜÂë¡¢Çå¾²ÌáÐÑÎÊÌâ¡¢µç×ÓÓʼþÄÚÈݺ͸½¼þ£¬£¬£¬£¬»¹Éù³ÆÓµÓÐͨ¹ýEmail.itµÄSMSЧÀÍ·¢Ë͵Ĵ¿Îı¾SMSÐÂÎÅ£¬£¬£¬£¬ÒÔ¼°ËùÓÐEmail.itÍøÂçÓ¦ÓóÌÐòµÄÔ´´úÂë¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/email-provider-got-hacked-data-of-600000-users-now-sold-on-the-dark-web/


3.¹È¸èÐû²¼4ÔÂAndroidÇå¾²¸üУ¬£¬£¬£¬ÐÞ¸´50¶à¸öÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¹È¸èÐû²¼4ÔÂAndroidÇå¾²¸üУ¬£¬£¬£¬ÐÞ¸´50¶à¸öÎó²î£¬£¬£¬£¬ÆäÖаüÀ¨ÏµÍ³×é¼þÖеÄ4¸öÑÏÖØÎó²î¡£¡£¡£Õâ4¸öÎó²î°üÀ¨CVE-2020-0070¡¢CVE-2020-0071¡¢CVE-2020-0072ºÍCVE-2020-0073£¬£¬£¬£¬¶¼¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬²¢ÇÒ¶¼Ó°ÏìAndroid 8.0¡¢8.1¡¢9ºÍ10£¬£¬£¬£¬Æä²¹¶¡°üÀ¨ÔÚÇå¾²²¹¶¡³ÌÐò¼¶±ð2020-04-01ÖС£¡£¡£±ðµÄ£¬£¬£¬£¬¹È¸è»¹ÔÚÇå¾²²¹¶¡³ÌÐò¼¶±ð2020-04-05ÖÐÐÞ¸´ÁË43¸öÎó²î£¬£¬£¬£¬°üÀ¨¿ò¼Ü×é¼þÖеÄ1¸öÐÅϢй¶Îó²î¡¢ÄÚºË×é¼þÖеÄ3¸öÌáȨÎó²î¡¢FPC×é¼þÖеÄ1¸öÌáȨºÍ2¸öÐÅϢй¶Îó²î¡¢¸ßͨ×é¼þÖеÄ6¸öÎó²îÒÔ¼°¸ßͨ±ÕÔ´×é¼þÖеÄ30¸öÎó²î¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/google-patches-critical-rce-vulnerabilities-androids-system-component


4.FireEyeÐû²¼×î½üÊýÄê0dayʹÓÃÇéÐÎµÄÆÊÎö±¨¸æ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


FireEye MandiantÍþвÇ鱨ÍŶӼͼµÄ2019Äê0dayʹÓÃÁ¿±ÈǰÈýÄêÖеÄÈκÎÒ»Äê¶¼Òª¶à¡£¡£¡£Ö»¹Ü²¢²»¿É½«Ã¿Ò»¸ö0dayʹÓö¼¹éÒòµ½Ìض¨µÄ¹¥»÷Õߣ¬£¬£¬£¬µ«Ñо¿Ö°Ô±×¢Öص½Ô½À´Ô½¶àµÄ¹¥»÷Õß»ñµÃÁË0dayʹÓõÄÄÜÁ¦¡£¡£¡£FireEyeÒÔΪ£¬£¬£¬£¬ÕâÖÖ¼¤ÔöÖÁÉÙ²¿·ÖÊÇÓÉÓÚÒ»Ö±Éú³¤µÄ¹ÍÓ¶ºÚ¿ÍÐÐÒµÉú³¤ÆðÀ´µÄ£¬£¬£¬£¬ÕâЩÐÐÒµ¿ª·¢0dayʹÓù¤¾ß²¢½«Æä³öÊÛ¸øÌìϸ÷µØµÄÇ鱨»ú¹¹¡£¡£¡£¹¥»÷ÕßÓë0dayʹÓÃÖ®¼äµÄ×î´óÕϰ­²»ÊÇÊÖÒÕ£¬£¬£¬£¬¶øÊÇÏֽ𡣡£¡£ÏêϸÀ´Ëµ£¬£¬£¬£¬FireEyeÖ¸³öNSO Group¡¢Gamma GroupºÍHacking TeamÊÇÕâÀà³Ð°üÉÌ£¬£¬£¬£¬ÕâЩ³Ð°üÉÌʹһÅúеĹú¼Ò/µØÇøÄܹ»¹ºÖÃ0dayʹÓᣡ£¡£


Ô­ÎÄÁ´½Ó£º

https://www.fireeye.com/blog/threat-research/2020/04/zero-day-exploitation-demonstrates-access-to-money-not-skill.html


5.¸çÂ×±ÈÑǹٷ½COVID-19 App±£´æÎó²îй¶Óû§Êý¾Ý


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ZeroFOXµÄAlphaÍŶӷ¢Ã÷¸çÂ×±ÈÑÇÕþ¸®ÕýʽÅú×¼µÄCOVID-19 APP°üÀ¨Îó²î£¬£¬£¬£¬¿Éµ¼ÖÂÓû§Êý¾Ýй¶¡£¡£¡£¸ÃAPPΪCoronApp-Columbia£¬£¬£¬£¬ÓÃÓÚ×ÊÖú¸çÂ×±ÈÑÇÈË·¢ËÍ¿µ½¡×´Ì¬¸üв¢ÎüÊÕ¹Ú×´²¡¶¾ÐÂÎÅ¡£¡£¡£¸ÃAPPÓµÓÐÁè¼Ý10Íò¸öÓû§¡£¡£¡£ZeroFOXÍþвÇ鱨×ܼàZack AllenÌåÏÖ£¬£¬£¬£¬CoronApp-ColumbiaÓ¦ÓÃÒÔÃ÷ÎÄÐÎʽ·¢ËÍСÎÒ˽¼Ò¿µ½¡ÐÅÏ¢£¨PHI£©ºÍСÎÒ˽¼ÒÉí·ÝÐÅÏ¢£¨PII£©Êý¾Ý£¬£¬£¬£¬Õâ°üÀ¨»¤ÕÕºÅÂë¡¢ÃÜÂëºÍ×ÔÎÒÅû¶µÄ¿µ½¡ÐÅÏ¢¡£¡£¡£ÕâÒýÆðÁËÈËÃǶԹٷ½Åú×¼/½¨ÉèµÄCOVID-19 APPÇå¾²ÐԵĵ£ÐÄ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/vulnerabilities-covid19-app/


6.COVID-19ʱ´úÕë¶ÔNASAµÄ´¹ÂÚ¹¥»÷´ó·ùÉÏÉý


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


NASA³ÆCOVID-19ʱ´úÃñ×å¹ú¼ÒºÚ¿ÍºÍÍøÂç·¸·¨·Ö×ÓÕë¶Ôº½Ìì¾ÖϵͳºÍÔڼҰ칫Ա¹¤µÄ¶ñÒâ»î¶¯ÏÔÖøÔöÌí¡£¡£¡£NASAÇå¾²ÔËÓªÖÐÐÄ£¨SOC£©±¨¸æµÄÍøÂç´¹ÂÚ¹¥»÷´ÎÊý·­ÁËÒ»·¬£¬£¬£¬£¬¶ñÒâÈí¼þ¹¥»÷³ÊÖ¸Êý¼¶ÔöÌí£¬£¬£¬£¬±»×èÖ¹µÄ¶ñÒâÕ¾µãÊýĿҲ·­ÁËÒ»·¬¡£¡£¡£ÃÀ¹úÓ¾Ö°ì¹«ÊÒÏòËùÓÐNASAÖ°Ô±Ðû²¼µÄ±¸Íü¼Öгƣ¬£¬£¬£¬¹ú¼ÒºÍÍøÂç×ï·¸ÕýÔÚÆð¾¢Ê¹ÓÃCOVID-19µÄÊ¢ÐÐÀ´Õë¶ÔNASAµç×Ó×°±¸¡¢ÍøÂçºÍСÎÒ˽¼Ò×°±¸£¬£¬£¬£¬ËûÃǵÄÄ¿µÄ°üÀ¨»á¼ûÃô¸ÐÐÅÏ¢¡¢Óû§ÃûºÍÃÜÂë¡¢¾ÙÐоܾøÐ§À͹¥»÷¡¢É¢²¼ÐéαÐÅÏ¢ÒÔ¼°¾ÙÐÐڲƭ¡£¡£¡£NASAÇ徲ר¼Ò»¹·¢Ã÷£¬£¬£¬£¬Ä³Ð©¹¥»÷²»µ«Õë¶Ǫ̂ʽ»ú£¬£¬£¬£¬²¢ÇÒ»¹Õë¶ÔÒÆ¶¯ÏµÍ³£¬£¬£¬£¬ÊÔͼÓÕÆ­Êܺ¦Õßй¶Ãô¸ÐÐÅÏ¢¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/nasa-under-significantly-increasing-hacking-phishing-attacks/