Î÷ÃÅ×Ó¶à¿î¹¤Òµ×°±¸ÊÜLinuxÄÚºËÎó²îSegmentSmackÓ°Ï죻£»£»£»£»£»£»Å·ÖÞÄÜÔ´¹«Ë¾EDPѬȾRagnarLocker
Ðû²¼Ê±¼ä 2020-04-161.Î÷ÃÅ×Ó¶à¿î¹¤Òµ×°±¸ÊÜLinuxÄÚºËÎó²îSegmentSmackÓ°Ïì
Î÷ÃÅ×ÓÐû²¼4Ô²¹¶¡¸üУ¬£¬£¬£¬£¬£¬£¬ ÆäÖÐ3ÌõÐÂͨ¸æÍ¨Öª¿Í»§Æä¶à¿î¹¤Òµ×°±¸Êܵ½LinuxÄÚºËÎó²îSegmentSmackÓ°Ïì¡£¡£¡£¡£¡£¡£¡£SegmentSmackºÍFragmentSmack£¨»®·Ö±»¸ú×ÙΪCVE-2018-5390ºÍCVE-2018-5391£©ÊÇÑо¿ÈËJuha-Matti TilliÔÚ2018Äê·¢Ã÷µÄÁ½¸öLinuxÄÚºËÎó²î£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÄ¿µÄϵͳ·¢ËͶñÒâÊý¾Ý°üÀ´ÌᳫDoS¹¥»÷¡£¡£¡£¡£¡£¡£¡£ÔÚµÚÒ»·Ýͨ¸æÖÐÎ÷ÃÅ×Ó³ÆSegmentSmackºÍFragmentSmackÓ°ÏìÁËËüµÄIE/PB-Link×°±¸¡¢RUGGEDCOM·ÓÉÆ÷¡¢»ùÓÚROXµÄVPNÖն˺ͷÀ»ðǽ¡¢SCALANCE·ÓÉÆ÷ºÍ·À»ðǽ¡¢SIMATICͨѶ´¦Öóͷ£Æ÷ºÍSinema Remote Connect¡£¡£¡£¡£¡£¡£¡£µÚ¶þ·Ýͨ¸æÖÐÎ÷ÃÅ×ÓÅû¶ÓëSegmentSmackÓйصÄDoSÎó²î£¨CVE-2019-19301£©£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÓ°ÏìÁËSIMATICͨѶģ¿£¿£¿£¿é¡¢SCALANCE X½»Á÷»úºÍSIPLUS×°±¸¡£¡£¡£¡£¡£¡£¡£µÚÈý·Ýͨ¸æÔòÅû¶ÁËÓ°ÏìÎ÷ÃÅ×ÓSIDOORÃÅÖÎÀíϵͳ¡¢SIMATIC×°±¸¡¢SINAMICSת»»Æ÷ºÍSIPLUS²úÆ·µÄDoSÎó²î£¨CVE-2019-19300£©¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/siemens-industrial-devices-affected-segmentsmack-linux-kernel-flaw
2.Ó¢ÌØ¶ûÐû²¼4ÔÂÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´¶à¿î²úÆ·ÖеÄ9¸öÎó²î
Ó¢ÌØ¶ûÔÚ4Ô²¹¶¡¸üÐÂÖÐÐÞ¸´ÁË9¸öÎó²î£¬£¬£¬£¬£¬£¬£¬ÕâЩÎó²î¾ùΪÖиßΣÎó²î£¬£¬£¬£¬£¬£¬£¬Ó°Ïì¶à¸öÈí¼þ¡¢¹Ì¼þ¼°Æ½Ì¨¡£¡£¡£¡£¡£¡£¡£Ó¢ÌضûÐÞ¸´ÁËPROSet/ÎÞÏßWiFi²úÆ·ÔÚWindows 10ÉϵÄÁ½¸öÎó²î-¾ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÓÉÓÚ²»Çå¾²µÄ¼ÌÐøÈ¨ÏÞ¶ø¿ÉÄÜͨ¹ýÍâµØ»á¼û¾ÙÐÐÌØÈ¨Éý¼¶£¨CVE-2020-0557£©£»£»£»£»£»£»£»ÓÉÓÚÄÚºËÇý¶¯³ÌÐòÖеĻº³åÇøÏÞÖÆ²»µ±£¬£¬£¬£¬£¬£¬£¬ÎÞÌØÈ¨µÄ¹¥»÷Õß¿ÉÄÜͨ¹ýÏàÁÚÍøÂç»á¼ûÀ´µ¼Ö¾ܾøÐ§ÀÍ£¨CVE-2020-0558£©¡£¡£¡£¡£¡£¡£¡£Ó¢Ìضû»¹ÐÞ¸´ÁËNUC mini PCµÄϵͳ¹Ì¼þÖкÍÄ£¿£¿£¿£¿é»¯Ð§ÀÍÆ÷MFS2600KISPPÅÌËãÄ£¿£¿£¿£¿éÖеÄÁ½¸öÎó²î£¬£¬£¬£¬£¬£¬£¬°üÀ¨²»×¼È·µÄ»º³åÇøÏÞÖÆµ¼ÖµÄLPEÎó²î£¨CVE-2020-0600£©ºÍÌõ¼þ¼ì²é²»µ±µ¼ÖµÄÌáȨÎó²î£¨CVE-2020-0578£©¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/intel-april-platform-update-fixes-high-severity-security-issues/
3.΢ÈíÐû²¼4ÔÂOfficeÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´55¸öÎó²î
΢ÈíÔÚ4ÔÂOfficeÇå¾²¸üÐÂÖÐÕë¶Ô7¸ö²úÆ·ÐÞ¸´ÁË55¸öÎó²î£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨Ó°ÏìÁËMicrosoft OfficeºÍMicrosoft Office SharePoint²úÆ·µÄ12¸öRCEÎó²î£¬£¬£¬£¬£¬£¬£¬ÕâЩÎó²î¾ù±»¹éÀàΪÑÏÖØ»òÖ÷Òª¼¶±ð£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃËüÃÇÔÚSharePointÓ¦ÓóÌÐòºÍSharePointЧÀÍÆ÷ÕÊ»§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£Î¢Èí»¹ÐÞ¸´ÁË10¸öXSSÎó²î£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜʹÓÃÕâЩÎó²îÔÚÄ¿½ñÓû§µÄÇå¾²ÉÏÏÂÎÄÖÐÔËÐо籾²¢Ã°³äÓû§¡¢ÇÔÈ¡Ãô¸ÐÊý¾Ý»òδ¾ÊÚȨÔĶÁÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬Î¢ÈíÐÞ¸´ÁËÁ½¸öÌáȨÎó²îºÍËĸöÓÕÆÎó²î¡£¡£¡£¡£¡£¡£¡£ÏêϸÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-office-april-security-updates-fix-critical-rce-bugs/
4.Å·ÖÞÄÜÔ´¹«Ë¾EDPѬȾRagnarLocker£¬£¬£¬£¬£¬£¬£¬±»ÀÕË÷½ü1000ÍòÅ·Ôª
¿ËÈÕÆÏÌÑÑÀ¿ç¹úÄÜÔ´¾ÞÍ·Energias de Portugal£¨EDP£©Ôâµ½ÀÕË÷Èí¼þRagnarLocker¹¥»÷£¬£¬£¬£¬£¬£¬£¬±»ÀÕË÷1580 BTCµÄÊê½ð£¨Ô¼ºÏ1090ÍòÃÀÔª»ò990ÍòÅ·Ôª£©¡£¡£¡£¡£¡£¡£¡£EDP¼¯ÍÅÊÇÅ·ÖÞÄÜÔ´ÐÐÒµ£¨×ÔÈ»ÆøºÍµçÁ¦£©×î´óµÄÔËÓªÉÌÖ®Ò»£¬£¬£¬£¬£¬£¬£¬Ò²ÊÇÌìϵÚËÄ´ó·çÄÜÉú²úÉÌ¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚÈ«ÇòËĸö´óÖÞµÄ19¸ö¹ú¼Ò/µØÇøÓµÓÐÓªÒµ£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÓµÓÐÁè¼Ý11500ÃûÔ±¹¤ºÍΪÁè¼Ý1100Íò¿Í»§ÌṩÄÜÔ´¡£¡£¡£¡£¡£¡£¡£ÔÚ¹¥»÷Àú³ÌÖУ¬£¬£¬£¬£¬£¬£¬Ragnar Locker¹¥»÷ÍÅ»ïÉù³ÆÇÔÈ¡ÁËÁè¼Ý10 TBµÄ¹«Ë¾Ãô¸ÐÎļþ£¬£¬£¬£¬£¬£¬£¬²¢Íþв³ÆÈôÊǸù«Ë¾¾Ü¾øÖ§¸¶Êê½ð£¬£¬£¬£¬£¬£¬£¬ËûÃǽ«Ðû²¼ÍµÈ¡µÄËùÓÐÊý¾Ý¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/ragnarlocker-ransomware-hits-edp-energy-giant-asks-for-10m/
5.TA505¼ÌÐøÊ¹ÓÃSDBbot RATѬȾÆóÒµÍøÂ磬£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÅ·ÖÞ
IBM X-ForceÍŶÓÊӲ쵽TA505¼ÌÐøÊ¹ÓÃSDBbot RATѬȾÆóÒµÍøÂç¡£¡£¡£¡£¡£¡£¡£ÔÚ2019Äê11Ô£¬£¬£¬£¬£¬£¬£¬X-Force IRISÊӲ쵽Óй¥»÷ÕßʹÓÃð³äµÄOnehub´¹ÂÚÓʼþ¹¥»÷Å·ÖÞµÄÆóÒµÔ±¹¤£¬£¬£¬£¬£¬£¬£¬¸Ã´¹ÂÚÓʼþÖ¼ÔÚÇÔÈ¡Active Directory£¨AD£©Êý¾Ý¼°Óû§Æ¾Ö¤£¬£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃSDBbot RATѬȾÆóÒµÍøÂçÇéÐΡ£¡£¡£¡£¡£¡£¡£Æ¾Ö¤Ñо¿Ö°Ô±¶Ô¹¥»÷ÕßµÄTTP¡¢C£¦C»ù´¡ÉèÊ©ÒÔ¼°ÏÈǰ¹éÒòÓÚ¸Ã×éÖ¯µÄÌØ¶¨¶ñÒâÈí¼þµÄÆÊÎö£¬£¬£¬£¬£¬£¬£¬X-Force IRISÒÔΪTA505ÊǸù¥»÷»î¶¯±³ºóµÄ¹¥»÷ÍŻ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityintelligence.com/posts/ta505-continues-to-infect-networks-with-sdbbot-rat/
6.¾É½ðɽ»ú³¡¹¥»÷Õß»òΪ¶íÂÞ˹APT×éÖ¯Energetic Bear
ESETÑо¿Ö°Ô±ÒÔΪ£¬£¬£¬£¬£¬£¬£¬¶Ô¾É½ðɽ¹ú¼Ê»ú³¡£¡£¡£¡£¡£¡£¡£¨SFO£©ÍøÕ¾µÄ¹¥»÷ÊÇÓɱ»³ÆÎªEnergetic BearµÄ¶íÂÞË¹ÍøÂçÌØ¹¤×éÖ¯¾ÙÐеġ£¡£¡£¡£¡£¡£¡£¸ÃAPT×éÖ¯×Ô2010ÄêÒÔÀ´Ò»Ö±ºÜ»îÔ¾£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÄÜÔ´ºÍ¹¤ÒµÁìÓòµÄ×éÖ¯¡£¡£¡£¡£¡£¡£¡£SFOµÄ»ú³¡ÐÅÏ¢ÊÖÒպ͵çÐŲ¿·Ö£¨ITT£©ÌåÏÖ¹¥»÷ÕßÔÚ»ú³¡ÍøÕ¾ÉÏÖ²ÈëÁ˶ñÒâ´úÂëÒÔÇÔÈ¡Óû§µÄµÇ¼ƾ֤£¬£¬£¬£¬£¬£¬£¬¿ÉÄÜÊܹ¥»÷Ó°ÏìµÄÓû§°üÀ¨Ê¹ÓÃWindows×°±¸»ò·ÇSFOά»¤µÄ×°±¸Í¨¹ýIEä¯ÀÀÆ÷´Ó»ú³¡ÍøÂçÍⲿ»á¼ûÕâÐ©ÍøÕ¾µÄÓû§¡£¡£¡£¡£¡£¡£¡£SFOµÄITÖ°Ô±ÒѾɾ³ýÁË×¢ÈëÆäÍøÕ¾ÖеĶñÒâ´úÂ룬£¬£¬£¬£¬£¬£¬²¢ÔÚ¹¥»÷±¬·¢ºó½«Á½Õß¶¼¾ÙÐÐÁËÍÑ»ú´¦Öóͷ£¡£¡£¡£¡£¡£¡£¡£ÎªÏìÓ¦´ËÊÂÎñ£¬£¬£¬£¬£¬£¬£¬SFO»ú³¡ÖØÖÃÁËËùÓеĵç×ÓÓʼþºÍÍøÂçÃÜÂë¡£¡£¡£¡£¡£¡£¡£ESET³Æ¹¥»÷ÕßʹÓÃSMB¹¦Ð§ºÍfile£º//ǰ׺À´ÊÕ¾Û»á¼ûÕßµÄWindowsƾ֤£¬£¬£¬£¬£¬£¬£¬°üÀ¨Óû§ÃûºÍNTLM¹þÏ£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/101601/apt/energetic-bear-airport-hack.html