Sophos½ôÆÈÐÞ¸´·À»ðǽÖеÄSQL×¢Èë0day£»£»£»£»ºÚ¿Í³öÊÛ»ãÒ½»ÛÓ°COVID-19 AI¸¨Öú¼ì²âÊÖÒÕµÄÔ´´úÂë
Ðû²¼Ê±¼ä 2020-04-271.Sophos½ôÆÈÐÞ¸´·À»ðǽÖеÄSQL×¢Èë0day£¬£¬£¬£¬Òѱ»Ò°ÍâʹÓÃ
ÍøÂçÇå¾²¹«Ë¾SophosÓÚÖÜÁùÐû²¼Á˽ôÆÈ²¹¶¡ÒÔÐÞ¸´ÒѾ±»Ò°ÍâʹÓõÄSQL×¢Èë0day£¬£¬£¬£¬¸ÃÎó²îÓ°ÏìÁËÆäXG Firewall²úÆ·¡£¡£¡£¡£4ÔÂ22ÈÕÍí£¬£¬£¬£¬Sophos¹«Ë¾·¢Ã÷ºÚ¿ÍʹÓÃXG FirewallÖеÄSQL×¢ÈëÎó²îÇÔÈ¡Á˸Ã×°±¸ÖеÄÊý¾Ý£¬£¬£¬£¬°üÀ¨·À»ðǽװ±¸ÖÎÀíÔ±ÕË»§¡¢·À»ðǽÃÅ»§ÍøÕ¾ÖÎÀíÔ±ÕË»§ºÍÔ¶³Ì»á¼û×°±¸ÕË»§ÖеĵÄÓû§ÃûºÍ¹þÏ£ÃÜÂë¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏִ˴θüÐÂÒѾÐÞ¸´Á˸ÃSQL×¢ÈëÎó²î£¬£¬£¬£¬²¢ÇÒмÓÁËÌØÊâÌáÐѹ¦Ð§Ê¹¿Í»§ÖªµÀÆä×°±¸ÊÇ·ñÊܵ½ÁËÍþв¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/hackers-are-exploiting-a-sophos-firewall-zero-day/
2.ºÚ¿Í³öÊÛ»ãÒ½»ÛÓ°COVID-19 AI¸¨Öú¼ì²âÊÖÒÕµÄÔ´´úÂë
Êý¾Ýй¶֪ͨ¹«Ë¾CybleÑо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬ÏÖÔÚºÚ¿ÍÕýÔÚ³öÊÛ»ãÒ½»ÛÓ°COVID-19 AI¸¨Öú¼ì²âÊÖÒÕµÄÔ´´úÂëºÍʵÑéÊý¾Ý¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬»ãÒ½»ÛÓ°ÕýÔÚÓ뻪ΪÏàÖú£¬£¬£¬£¬¿ª·¢Ò»ÖÖ»ùÓÚAIµÄCOVID-19¼ì²âϵͳ£¬£¬£¬£¬¸Ãϵͳ¿ÉÒÔ´ÓÐØ²¿CTµÄDICOMͼÏñ¼ì²âÊÇ·ñ±£´æÑ¬È¾Ö¢×´¡£¡£¡£¡£»£»£»£»ãÒ½»ÛÓ°ÕýÒÔÿÔÂ50000ÃÀÔªµÄ¼ÛÇ®³öÊÛ¸Ãϵͳ¡£¡£¡£¡£¶øºÚ¿ÍÉù³ÆÆäÒÑ»ñµÃCOVID-19¼ì²âÊÖÒÕÔ´´úÂëÒÔ¼°ÑéÊý¾Ý£¬£¬£¬£¬²¢ÒÔ4±ÈÌØ±ÒµÄ¼ÛÇ®ÏòÍâ³öÊÛ¡£¡£¡£¡£±»µÁÊý¾Ý°üÀ¨Óû§ÐÅÏ¢£¨1.5 MB£©¡¢ÊÖÒÕºÍÔ´´úÂ루1GB£©¡¢Covid-19ʵÑéÏà¹ØÄÚÈÝ£¨150 MB£©¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/102270/data-breach/huiying-medical-technology-data-breach.html
3.ÍþÊ¿¼ÉÅÄÂôÍøÕ¾WhiskyAuctioneer±»¹¥»÷ÖÂÅÄÂôÎÞÏÞÑÓÆÚ
Ó¢¹úÍþÊ¿¼ÉÅÄÂôÍøÕ¾WhiskyAuctioneerÓÚ4ÔÂ21ÈÕ22£º30Ðû²¼ÆäÔâµ½Á˶ñÒâ¹¥»÷£¬£¬£¬£¬ÅÄÂô»î¶¯±»ÎÞÏÞÑÓÆÚ¡£¡£¡£¡£¸ÃÊÂÎñ±¬·¢ÓÚ4ÔÂ20ÈÕ£¬£¬£¬£¬¾ºÅĻ±¾¸Ã7µã¿¢Ê£¬£¬£¬£¬µ«ÓÉÓÚÍøÕ¾Òì³££¬£¬£¬£¬»î¶¯±»ÑÓÆÚÁË48Сʱ¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬¸ÃÍøÕ¾·¢Ã÷ÆäÍøÕ¾ºÍÊý¾Ý¿âÔâµ½ÁËÓÐÕë¶ÔÐÔÇÒÖØ´óµÄ¶ñÒâ¹¥»÷¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬¸ÃÍøÕ¾Ò»Ö±´¦ÓÚÍÑ»úά»¤×´Ì¬£¬£¬£¬£¬²¢ÌåÏÖÅÄÂô»î¶¯½«»á±»ÎÞÏÞÑÓÆÚ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.theguardian.com/technology/2020/apr/25/online-auction-of-record-breaking-whisky-collection-hit-by-cyber-attack
4.ÐÂÎÄ×ÖÕ¨µ¯Ê¹ÓÃÐŵÂÓ£¬£¬£¬¿Éµ¼ÖÂiOSºÍmac OS×°±¸Íß½â
Graham Cluley·¢Ã÷£¬£¬£¬£¬×î½üгöÁËÒ»ÖÖ°üÀ¨ÐŵÂÓï×Ö·ûµÄÎÄ×ÖÕ¨µ¯£¬£¬£¬£¬Êܺ¦ÕßÉó²é°üÀ¨¸ÃÎÄ×ÖÕ¨µ¯µÄÎı¾Ê±£¬£¬£¬£¬»áµ¼ÖÂiOSºÍmac OS×°±¸Í߽⡣¡£¡£¡£ÐŵÂÓïÊǰͻù˹̹ʹÓõĹٷ½ÓïÑÔÖ®Ò»£¬£¬£¬£¬¿ÉÊÇmacOSºÍiOSÎÞ·¨Ê¶±ð¸ÃÓïÑÔ±àдµÄUnicode·ûºÅ£¬£¬£¬£¬µ¼Ö²Ù×÷ϵͳÎÞ·¨Õý³£ÔËÐС£¡£¡£¡£¸ÃÎÊÌâ×îÔçÊÇÔÚÉÏÖÜËı»·¢Ã÷µÄ£¬£¬£¬£¬±»³Æ×÷CapturetheFlag£¬£¬£¬£¬²¢ÒѾÔÚTwitterÉÏÈö²¥¿ªÀ´¡£¡£¡£¡£CluleyÖ¸³ö£¬£¬£¬£¬ÖØÐÂÆô¶¯×°±¸¿ÉÒÔ½â¾ö´ËÎÊÌâ¡£¡£¡£¡£Apple×°±¸ÔÚÒÑÍùÒ²ÓÐÀàËÆÎÊÌ⣬£¬£¬£¬2013Äê°¢À²®Óï×Ö·û¡¢2018ÄêÄÏÓ¡¶ÈµÄÈË̩¬¹ÌÓï¶¼¿ÉÒÔʹMacºÍiPhoneÍ߽⡣¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/apple-text-bomb-crashes-iphones-message-notifications/155144/
5.TrickBotÍÅ»ïÔÚд¹ÂÚ¹¥»÷Öзַ¢BazarBackdoorºóÃÅ
Ñо¿Ö°Ô±·¢Ã÷TrickBotÍÅ»ïÕýÔÚʹÓÃд¹ÂÚ¹¥»÷·Ö·¢BazarBackdoorºóÃÅ£¬£¬£¬£¬ÒÔÆÆËð²¢»ñµÃÆóÒµÍøÂçµÄÍêÈ«»á¼ûȨÏÞ¡£¡£¡£¡£¹¥»÷ÕßÊ×ÏÈÒÔ¿Í»§Í¶Ëß¡¢COVID-19Ö÷ÌâÈËΪ±¨¸æµÈÐÅϢΪÓÕ¶ü£¬£¬£¬£¬ÓÕʹÊܺ¦Õß·¿ªÎ±×°³ÉWordÎĵµ¡¢Excelµç×Ó±í¸ñ»òPDFµÄºóÃżÓÔØ³ÌÐòBazaLoader¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬BazarLoaderͨ¹ýEmercoinÊèɢʽDNSÆÊÎöЧÀÍÀ´ÆÊÎöʹÓà bazarÓòµÄÖÖÖÖÖ÷»úÃû¡£¡£¡£¡£ÆÊÎöµ½C2 IPµØµãºó£¬£¬£¬£¬¼ÓÔØ³ÌÐòÊ×ÏÈÅþÁ¬µ½Ò»¸öC2²¢Ö´ÐÐ×¢²á£¬£¬£¬£¬ÔÙʹÓÃÁíÒ»¸öC2ÇëÇóÏÂÔØXOR¼ÓÃܵÄBazarBackdoor£¬£¬£¬£¬½¨ÉèºóÃÅ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/bazarbackdoor-trickbot-gang-s-new-stealthy-network-hacking-malware/
6.Facebook 1400¶à¸öÓû§³ÉÎªÌØ¹¤Èí¼þPegasusÄ¿µÄ
Facebook¶ÔÒÔÉ«ÁÐNSO GroupÌáÆðËßËÏ£¬£¬£¬£¬Ö¸¿ØÆäʹÓÃÌØ¹¤Èí¼þPegasusÕë¶Ô1400¶à¸öÓû§¡£¡£¡£¡£ÊÂÎñ±¬·¢ÔÚ2019Äê´º¼¾£¬£¬£¬£¬NSO GroupʹÓÃÁËWhatsApp VoIP¹¦Ð§ÖеÄÎó²î£¨ CVE-2019-3568£©Ö²ÈëÁËÌØ¹¤Èí¼þPegasus£¬£¬£¬£¬¶ÔWhatsAppÓû§ÌᳫÁËÖÁÉÙ720´Î¹¥»÷¡£¡£¡£¡£´Ë´ÎÊÂÎñµÄÊܺ¦ÕßΪ1400¶àÃûÓû§£¬£¬£¬£¬ÆäÖаüÀ¨¼ÇÕß¡¢ÈËȨ»î¶¯¼Ò¡¢ÕþÖÎÒìÒéÈËÊ¿¡¢Íâ½»¹Ù¡¢×´Ê¦ºÍÕþ¸®¹ÙÔ±¡£¡£¡£¡£½ñÄê4Ô£¬£¬£¬£¬NSO GroupÌá³öÁËÉêËߣ¬£¬£¬£¬ÀíÓÉÊǸù«Ë¾ÎªÍâ¹úÆóÒµ£¬£¬£¬£¬¼ÓÖÝ·¨ÔºÃ»ÓÐͳÁìȨÀ´Ö÷³Ö´Ë°¸£¬£¬£¬£¬µ«FacebookÖ´·¨ÍŶÓÈ´×èµ²Õâһ˵·¨£¬£¬£¬£¬ÌåÏÖNSO Group²»Ó¦¸Ã±»¿íÃâ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/102260/laws-and-regulations/facebook-nso-group-lawsuit.html