Î÷ÃÅ×Ó¶à¿î¹¤Òµ×°±¸ÊÜLinuxÄÚºËÎó²îSegmentSmackÓ°Ï죻£»£»£»£»£»£»Å·ÖÞÄÜÔ´¹«Ë¾EDPѬȾRagnarLocker

Ðû²¼Ê±¼ä 2020-04-16

1.Î÷ÃÅ×Ó¶à¿î¹¤Òµ×°±¸ÊÜLinuxÄÚºËÎó²îSegmentSmackÓ°Ïì


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Î÷ÃÅ×ÓÐû²¼4Ô²¹¶¡¸üУ¬£¬£¬£¬£¬ £¬ £¬ ÆäÖÐ3ÌõÐÂͨ¸æÍ¨Öª¿Í»§Æä¶à¿î¹¤Òµ×°±¸Êܵ½LinuxÄÚºËÎó²îSegmentSmackÓ°Ïì¡£¡£¡£¡£¡£¡£¡£SegmentSmackºÍFragmentSmack£¨»®·Ö±»¸ú×ÙΪCVE-2018-5390ºÍCVE-2018-5391£©ÊÇÑо¿ÈËJuha-Matti TilliÔÚ2018Äê·¢Ã÷µÄÁ½¸öLinuxÄÚºËÎó²î£¬£¬£¬£¬£¬ £¬ £¬¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÄ¿µÄϵͳ·¢ËͶñÒâÊý¾Ý°üÀ´ÌᳫDoS¹¥»÷¡£¡£¡£¡£¡£¡£¡£ÔÚµÚÒ»·Ýͨ¸æÖÐÎ÷ÃÅ×Ó³ÆSegmentSmackºÍFragmentSmackÓ°ÏìÁËËüµÄIE/PB-Link×°±¸¡¢RUGGEDCOM·ÓÉÆ÷¡¢»ùÓÚROXµÄVPNÖն˺ͷÀ»ðǽ¡¢SCALANCE·ÓÉÆ÷ºÍ·À»ðǽ¡¢SIMATICͨѶ´¦Öóͷ£Æ÷ºÍSinema Remote Connect¡£¡£¡£¡£¡£¡£¡£µÚ¶þ·Ýͨ¸æÖÐÎ÷ÃÅ×ÓÅû¶ÓëSegmentSmackÓйصÄDoSÎó²î£¨CVE-2019-19301£©£¬£¬£¬£¬£¬ £¬ £¬¸ÃÎó²îÓ°ÏìÁËSIMATICͨѶģ¿£¿£¿£¿é¡¢SCALANCE X½»Á÷»úºÍSIPLUS×°±¸¡£¡£¡£¡£¡£¡£¡£µÚÈý·Ýͨ¸æÔòÅû¶ÁËÓ°ÏìÎ÷ÃÅ×ÓSIDOORÃÅÖÎÀíϵͳ¡¢SIMATIC×°±¸¡¢SINAMICSת»»Æ÷ºÍSIPLUS²úÆ·µÄDoSÎó²î£¨CVE-2019-19300£©¡£¡£¡£¡£¡£¡£¡£



Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/siemens-industrial-devices-affected-segmentsmack-linux-kernel-flaw




2.Ó¢ÌØ¶ûÐû²¼4ÔÂÇå¾²¸üУ¬£¬£¬£¬£¬ £¬ £¬ÐÞ¸´¶à¿î²úÆ·ÖеÄ9¸öÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ó¢ÌØ¶ûÔÚ4Ô²¹¶¡¸üÐÂÖÐÐÞ¸´ÁË9¸öÎó²î£¬£¬£¬£¬£¬ £¬ £¬ÕâЩÎó²î¾ùΪÖиßΣÎó²î£¬£¬£¬£¬£¬ £¬ £¬Ó°Ïì¶à¸öÈí¼þ¡¢¹Ì¼þ¼°Æ½Ì¨¡£¡£¡£¡£¡£¡£¡£Ó¢ÌضûÐÞ¸´ÁËPROSet/ÎÞÏßWiFi²úÆ·ÔÚWindows 10ÉϵÄÁ½¸öÎó²î-¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÓÉÓÚ²»Çå¾²µÄ¼ÌÐøÈ¨ÏÞ¶ø¿ÉÄÜͨ¹ýÍâµØ»á¼û¾ÙÐÐÌØÈ¨Éý¼¶£¨CVE-2020-0557£©£»£»£»£»£»£»£»ÓÉÓÚÄÚºËÇý¶¯³ÌÐòÖеĻº³åÇøÏÞÖÆ²»µ±£¬£¬£¬£¬£¬ £¬ £¬ÎÞÌØÈ¨µÄ¹¥»÷Õß¿ÉÄÜͨ¹ýÏàÁÚÍøÂç»á¼ûÀ´µ¼Ö¾ܾøÐ§ÀÍ£¨CVE-2020-0558£©¡£¡£¡£¡£¡£¡£¡£Ó¢Ìضû»¹ÐÞ¸´ÁËNUC mini PCµÄϵͳ¹Ì¼þÖкÍÄ£¿£¿£¿£¿é»¯Ð§ÀÍÆ÷MFS2600KISPPÅÌËãÄ£¿£¿£¿£¿éÖеÄÁ½¸öÎó²î£¬£¬£¬£¬£¬ £¬ £¬°üÀ¨²»×¼È·µÄ»º³åÇøÏÞÖÆµ¼ÖµÄLPEÎó²î£¨CVE-2020-0600£©ºÍÌõ¼þ¼ì²é²»µ±µ¼ÖµÄÌáȨÎó²î£¨CVE-2020-0578£©¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/intel-april-platform-update-fixes-high-severity-security-issues/


3.΢ÈíÐû²¼4ÔÂOfficeÇå¾²¸üУ¬£¬£¬£¬£¬ £¬ £¬ÐÞ¸´55¸öÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


΢ÈíÔÚ4ÔÂOfficeÇå¾²¸üÐÂÖÐÕë¶Ô7¸ö²úÆ·ÐÞ¸´ÁË55¸öÎó²î£¬£¬£¬£¬£¬ £¬ £¬ÆäÖаüÀ¨Ó°ÏìÁËMicrosoft OfficeºÍMicrosoft Office SharePoint²úÆ·µÄ12¸öRCEÎó²î£¬£¬£¬£¬£¬ £¬ £¬ÕâЩÎó²î¾ù±»¹éÀàΪÑÏÖØ»òÖ÷Òª¼¶±ð£¬£¬£¬£¬£¬ £¬ £¬¹¥»÷Õß¿ÉÒÔʹÓÃËüÃÇÔÚSharePointÓ¦ÓóÌÐòºÍSharePointЧÀÍÆ÷ÕÊ»§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£Î¢Èí»¹ÐÞ¸´ÁË10¸öXSSÎó²î£¬£¬£¬£¬£¬ £¬ £¬¹¥»÷Õß¿ÉÄÜʹÓÃÕâЩÎó²îÔÚÄ¿½ñÓû§µÄÇå¾²ÉÏÏÂÎÄÖÐÔËÐо籾²¢Ã°³äÓû§¡¢ÇÔÈ¡Ãô¸ÐÊý¾Ý»òδ¾­ÊÚȨÔĶÁÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬ £¬ £¬Î¢ÈíÐÞ¸´ÁËÁ½¸öÌáȨÎó²îºÍËĸöÓÕÆ­Îó²î¡£¡£¡£¡£¡£¡£¡£ÏêϸÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-office-april-security-updates-fix-critical-rce-bugs/


4.Å·ÖÞÄÜÔ´¹«Ë¾EDPѬȾRagnarLocker£¬£¬£¬£¬£¬ £¬ £¬±»ÀÕË÷½ü1000ÍòÅ·Ôª


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¿ËÈÕÆÏÌÑÑÀ¿ç¹úÄÜÔ´¾ÞÍ·Energias de Portugal£¨EDP£©Ôâµ½ÀÕË÷Èí¼þRagnarLocker¹¥»÷£¬£¬£¬£¬£¬ £¬ £¬±»ÀÕË÷1580 BTCµÄÊê½ð£¨Ô¼ºÏ1090ÍòÃÀÔª»ò990ÍòÅ·Ôª£©¡£¡£¡£¡£¡£¡£¡£EDP¼¯ÍÅÊÇÅ·ÖÞÄÜÔ´ÐÐÒµ£¨×ÔÈ»ÆøºÍµçÁ¦£©×î´óµÄÔËÓªÉÌÖ®Ò»£¬£¬£¬£¬£¬ £¬ £¬Ò²ÊÇÌìϵÚËÄ´ó·çÄÜÉú²úÉÌ¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚÈ«ÇòËĸö´óÖÞµÄ19¸ö¹ú¼Ò/µØÇøÓµÓÐÓªÒµ£¬£¬£¬£¬£¬ £¬ £¬²¢ÇÒÓµÓÐÁè¼Ý11500ÃûÔ±¹¤ºÍΪÁè¼Ý1100Íò¿Í»§ÌṩÄÜÔ´¡£¡£¡£¡£¡£¡£¡£ÔÚ¹¥»÷Àú³ÌÖУ¬£¬£¬£¬£¬ £¬ £¬Ragnar Locker¹¥»÷ÍÅ»ïÉù³ÆÇÔÈ¡ÁËÁè¼Ý10 TBµÄ¹«Ë¾Ãô¸ÐÎļþ£¬£¬£¬£¬£¬ £¬ £¬²¢Íþв³ÆÈôÊǸù«Ë¾¾Ü¾øÖ§¸¶Êê½ð£¬£¬£¬£¬£¬ £¬ £¬ËûÃǽ«Ðû²¼ÍµÈ¡µÄËùÓÐÊý¾Ý¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ragnarlocker-ransomware-hits-edp-energy-giant-asks-for-10m/


5.TA505¼ÌÐøÊ¹ÓÃSDBbot RATѬȾÆóÒµÍøÂ磬£¬£¬£¬£¬ £¬ £¬Ö÷ÒªÕë¶ÔÅ·ÖÞ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


IBM X-ForceÍŶÓÊӲ쵽TA505¼ÌÐøÊ¹ÓÃSDBbot RATѬȾÆóÒµÍøÂç¡£¡£¡£¡£¡£¡£¡£ÔÚ2019Äê11Ô£¬£¬£¬£¬£¬ £¬ £¬X-Force IRISÊӲ쵽Óй¥»÷ÕßʹÓÃð³äµÄOnehub´¹ÂÚÓʼþ¹¥»÷Å·ÖÞµÄÆóÒµÔ±¹¤£¬£¬£¬£¬£¬ £¬ £¬¸Ã´¹ÂÚÓʼþÖ¼ÔÚÇÔÈ¡Active Directory£¨AD£©Êý¾Ý¼°Óû§Æ¾Ö¤£¬£¬£¬£¬£¬ £¬ £¬²¢Ê¹ÓÃSDBbot RATѬȾÆóÒµÍøÂçÇéÐΡ£¡£¡£¡£¡£¡£¡£Æ¾Ö¤Ñо¿Ö°Ô±¶Ô¹¥»÷ÕßµÄTTP¡¢C£¦C»ù´¡ÉèÊ©ÒÔ¼°ÏÈǰ¹éÒòÓÚ¸Ã×éÖ¯µÄÌØ¶¨¶ñÒâÈí¼þµÄÆÊÎö£¬£¬£¬£¬£¬ £¬ £¬X-Force IRISÒÔΪTA505ÊǸù¥»÷»î¶¯±³ºóµÄ¹¥»÷ÍŻ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityintelligence.com/posts/ta505-continues-to-infect-networks-with-sdbbot-rat/


6.¾É½ðɽ»ú³¡¹¥»÷Õß»òΪ¶íÂÞ˹APT×éÖ¯Energetic Bear


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ESETÑо¿Ö°Ô±ÒÔΪ£¬£¬£¬£¬£¬ £¬ £¬¶Ô¾É½ðɽ¹ú¼Ê»ú³¡£¡£¡£¡£¡£¡£¡£¨SFO£©ÍøÕ¾µÄ¹¥»÷ÊÇÓɱ»³ÆÎªEnergetic BearµÄ¶íÂÞË¹ÍøÂçÌØ¹¤×éÖ¯¾ÙÐеÄ¡£¡£¡£¡£¡£¡£¡£¸ÃAPT×éÖ¯×Ô2010ÄêÒÔÀ´Ò»Ö±ºÜ»îÔ¾£¬£¬£¬£¬£¬ £¬ £¬Ö÷ÒªÕë¶ÔÄÜÔ´ºÍ¹¤ÒµÁìÓòµÄ×éÖ¯¡£¡£¡£¡£¡£¡£¡£SFOµÄ»ú³¡ÐÅÏ¢ÊÖÒպ͵çÐŲ¿·Ö£¨ITT£©ÌåÏÖ¹¥»÷ÕßÔÚ»ú³¡ÍøÕ¾ÉÏÖ²ÈëÁ˶ñÒâ´úÂëÒÔÇÔÈ¡Óû§µÄµÇ¼ƾ֤£¬£¬£¬£¬£¬ £¬ £¬¿ÉÄÜÊܹ¥»÷Ó°ÏìµÄÓû§°üÀ¨Ê¹ÓÃWindows×°±¸»ò·ÇSFOά»¤µÄ×°±¸Í¨¹ýIEä¯ÀÀÆ÷´Ó»ú³¡ÍøÂçÍⲿ»á¼ûÕâÐ©ÍøÕ¾µÄÓû§¡£¡£¡£¡£¡£¡£¡£SFOµÄITÖ°Ô±ÒѾ­É¾³ýÁË×¢ÈëÆäÍøÕ¾ÖеĶñÒâ´úÂ룬£¬£¬£¬£¬ £¬ £¬²¢ÔÚ¹¥»÷±¬·¢ºó½«Á½Õß¶¼¾ÙÐÐÁËÍÑ»ú´¦Öóͷ£¡£¡£¡£¡£¡£¡£¡£ÎªÏìÓ¦´ËÊÂÎñ£¬£¬£¬£¬£¬ £¬ £¬SFO»ú³¡ÖØÖÃÁËËùÓеĵç×ÓÓʼþºÍÍøÂçÃÜÂë¡£¡£¡£¡£¡£¡£¡£ESET³Æ¹¥»÷ÕßʹÓÃSMB¹¦Ð§ºÍfile£º//ǰ׺À´ÊÕ¾Û»á¼ûÕßµÄWindowsƾ֤£¬£¬£¬£¬£¬ £¬ £¬°üÀ¨Óû§ÃûºÍNTLM¹þÏ£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/101601/apt/energetic-bear-airport-hack.html