GoogleÐû²¼chromeÇå¾²¸üУ¬£¬ £¬£¬£¬ÐÞ¸´WebGLÖдúÂëÖ´ÐÐÎó²î£»£» £» £»£»£»£»LazarusʹÓÃLinkedInÕÐÆ¸¹ã¸æ¹¥»÷¼ÓÃÜÇ®±Ò¹«Ë¾

Ðû²¼Ê±¼ä 2020-08-26

1.GoogleÐû²¼chromeÇå¾²¸üУ¬£¬ £¬£¬£¬ÐÞ¸´WebGLÖдúÂëÖ´ÐÐÎó²î


1.jpg


GoogleÐû²¼chromeÇå¾²¸üУ¬£¬ £¬£¬£¬ÐÞ¸´ÆäWebGLÖдúÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¸ÃÎó²îÓÉ˼¿ÆTalosµÄÑо¿Ö°Ô±·¢Ã÷£¬£¬ £¬£¬£¬ÆäλÓÚOpenGLºÍChromeä¯ÀÀÆ÷¼°ÆäËûÏîÄ¿ÔÚWindowsÉÏʹÓõÄDirect3DÖ®¼äµÄ¼æÈݲãANGLEÖУ¬£¬ £¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÊʵ±µÄÄÚ´æ½á¹¹ºóʹÓøÃÎó²î£¬£¬ £¬£¬£¬ÔÚä¯ÀÀÆ÷ÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¸ÃÎó²î±»×·×ÙΪCVE-2020-6492£¬£¬ £¬£¬£¬CVSSv3ÆÀ·ÖΪ8.3£¬£¬ £¬£¬£¬Ó°ÏìÁËGoogle Chrome 81.0.4044.138£¨Stable£©£¬£¬ £¬£¬£¬84.0.4136.5£¨Dev£©ºÍ84.0.4143.7£¨Canary£©£¬£¬ £¬£¬£¬ÏÖÔÚÒѱ»GoogleÐÞ¸´¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/google-chrome-85-fixes-webgl-code-execution-vulnerability/


2.ÒÁÀʺڿÍͨ¹ý¹¥»÷̻¶µÄRDPЧÀÍÆ÷À´×°ÖÃÀÕË÷Èí¼þDharma


2.jpg


ÒÁÀÊеĺڿÍ×é֯ͨ¹ý¹¥»÷̻¶µÄRDPЧÀÍÆ÷À´×°ÖÃÀÕË÷Èí¼þDharma£¬£¬ £¬£¬£¬Õë¶Ô¶íÂÞ˹¡¢Ó¡¶È¡¢ÖйúºÍÈÕ±¾¹«Ë¾¡£¡£¡£¡£¡£¡£ËûÃÇͨ¹ý¿ªÔ´¶Ë¿ÚɨÃèÆ÷MasscanɨÃèInternetÉϵÄIPµØµãÒÔ²éÕÒ̻¶µÄÔ¶³Ì×ÀÃæÅþÁ¬£¨RDP£©£¬£¬ £¬£¬£¬Ö¼ÔÚÕÒµ½ºÏÊʵÄÊܺ¦Õß¡£¡£¡£¡£¡£¡£Ö®ºó»áʹÓÃNLBruteÆô¶¯±©Á¦ÆÆ½â³ÌÐòÆÆ½âRDPÃÜÂë¡£¡£¡£¡£¡£¡£ÀֳɽøÈëºó£¬£¬ £¬£¬£¬ËûÃÇ»áʹÓÃWindows 7ÖÁ10ÖеľÉÎó²î£¨CVE-2017-0213£©¾ÙÐÐÌáȨ¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯µÄÊê½ðÒªÇóÔÚ1-5±ÈÌØ±ÒÖ®¼ä£¨$ 11,700-$ 59,000£©£¬£¬ £¬£¬£¬ÓëÆäËûÀÕË÷Èí¼þ×éÖ¯Ïà±È½ð¶î½ÏС¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/iranian-hackers-attack-exposed-rdp-servers-to-deploy-dharma-ransomware/


3.LazarusʹÓÃLinkedInÕÐÆ¸¹ã¸æ¹¥»÷¼ÓÃÜÇ®±Ò¹«Ë¾


3.jpg


F-SecureµÄÍøÂçÇå¾²Ñо¿Ö°Ô±·¢Ã÷£¬£¬ £¬£¬£¬APT×éÖ¯LazarusʹÓÃLinkedInÕÐÆ¸¹ã¸æ¹¥»÷¼ÓÃÜÇ®±Ò¹«Ë¾¡£¡£¡£¡£¡£¡£Ôڴ˴ι¥»÷»î¶¯ÖУ¬£¬ £¬£¬£¬LazarusÏòÄ¿µÄ¹«Ë¾µÄϵͳÖÎÀíԱСÎÒ˽¼ÒLinkedInÕÊ»§Öз¢ËÍÕÐÆ¸¹ã¸æ£¬£¬ £¬£¬£¬ËµÃ÷Ò»¼ÒÇø¿éÁ´ÊÖÒÕ¹«Ë¾ÕýÔÚ×·ÇóеÄsysadmin¡£¡£¡£¡£¡£¡£¸Ã¹ã¸æ½«ÓÕʹÊܺ¦Õ߯ôÓú꣬£¬ £¬£¬£¬ÒÔ½¨ÉèÒ»¸ö.LNKÎļþ£¬£¬ £¬£¬£¬¸ÃÎļþÖ¼ÔÚÖ´ÐÐÒ»¸öÃûΪmshta.exeµÄÎļþ£¬£¬ £¬£¬£¬²¢Å²ÓÃÅþÁ¬µ½VBScriptµÄbit.lyÁ´½Ó£¬£¬ £¬£¬£¬²¢½«²Ù×÷ÐÅÏ¢·¢Ë͵½C2ЧÀÍÆ÷¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/lazarus-group-strikes-cryptocurrency-firm-through-linkedin-job-adverts/


4.ZoomЧÀÍÔÙ´ÎÖÐÖ¹£¬£¬ £¬£¬£¬Ö÷ÒªÓ°ÏìÃÀ¹ú¶«º£°¶ºÍÓ¢¹úµÄÓû§


4.jpg


ZoomЧÀÍÔÙ´ÎÖÐÖ¹£¬£¬ £¬£¬£¬Ö÷ÒªÓ°ÏìÃÀ¹ú¶«º£°¶ºÍÓ¢¹úµÄÓû§¡£¡£¡£¡£¡£¡£ZoomÌåÏÖÔÚ´Ë´ÎÖÐÖ¹ÖУ¬£¬ £¬£¬£¬Ðí¶àÓû§ÎÞ·¨»á¼ûZoomÍøÕ¾£¨zoom.us£©£¬£¬ £¬£¬£¬²¢ÎÞ·¨Æô¶¯ºÍ¼ÓÈëZoom Meetings¡£¡£¡£¡£¡£¡£×èÖ¹ÏÖÔÚ£¬£¬ £¬£¬£¬ZoomÒÑÈ·¶¨µ¼Ö´˴ιÊÕϵÄÔµ¹ÊÔ­ÓÉ£¬£¬ £¬£¬£¬²¢ÒѾÙÐÐÐÞ¸´¡£¡£¡£¡£¡£¡£Õâ²¢²»µÚÒ»´Î±¬·¢ÀàËÆ¹ÊÕÏ£¬£¬ £¬£¬£¬ÔçÔÚ4Ô£¬£¬ £¬£¬£¬ZoomÓû§ÌåÏÖËûÃÇÎÞ·¨Æô¶¯Web¿Í»§¶Ë²¢ÏÔʾ403 Forbidden¹ýʧ£¬£¬ £¬£¬£¬¶øÉÏÖÜÓû§Ò²·¢Ã÷ÎÞ·¨Í¨¹ýZoom Web¿Í»§¶ËºÍWebSDK¼ÓÈë¾Û»á¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/technology/zoom-went-down-and-schools-got-a-digital-snow-day/


5.¿¨°Í˹»ùÐû²¼ÓйØÍøÂçÌØ¹¤×éÖ¯DeathStalkerµÄÆÊÎö±¨¸æ


5.jpg


¿¨°Í˹»ù·¢Ã÷Ò»¸öרÃÅ´ÓÊÂÇÔÈ¡ÉÌÒµÉñÃØµÄÍøÂç·¸·¨×éÖ¯Ö¯DeathStalker£¬£¬ £¬£¬£¬²¢Ðû²¼Õë¶ÔÆäµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯×Ô2018Äê»ò¸üÔ磨¿ÉÄÜ×Ô2012Ä꣩¾Í×îÏÈ»îÔ¾£¬£¬ £¬£¬£¬Ö÷Òª¶Ô½ðÈڿƼ¼¹«Ë¾¡¢×´Ê¦ÊÂÎñËùºÍ²ÆÎñÕÕÁÏ¡£¡£¡£¡£¡£¡£DeathStalker²»»á°²ÅÅÀÕË÷Èí¼þ»òÇÔȡ֧¸¶Êý¾Ý£¬£¬ £¬£¬£¬Æä¹Ø×¢µÄÖØµãÊÇÃô¸ÐµÄÓªÒµÊý¾Ý£¬£¬ £¬£¬£¬ÕâÒâζ×ÅDeathStalke¿ÉÄÜÌṩÁËºÚ¿ÍÆ¸ÓÃЧÀÍ£¬£¬ £¬£¬£¬»òÕ߳䵱Á˽ðÈÚ½çµÄÐÅÏ¢¾­¼ÍÈË¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.kaspersky.com/blog/deathstalker-powersing/36815/


6.Ó¡¶ÈÂÃÓÎÍøÕ¾RailYatriÒòÊý¾Ý¿âÉèÖùýʧй¶3700ÍòÌõ¼Í¼


6.jpg


SafetyDetectives 8ÔÂ10ÈÕÔÚÍøÂçÉÏ·¢Ã÷ÁËRailYatriµÄûÓÐÃÜÂë±£»£» £» £»£»£»£»¤µÄElasticsearchЧÀÍÆ÷£¬£¬ £¬£¬£¬Ð¹Â¶3700ÍòÌõ¼Í¼¿Í»§ºÍ¹«Ë¾Êý¾Ý£¬£¬ £¬£¬£¬°üÀ¨Óû§µÄÈ«Ãû¡¢ÄêËê¡¢ÐÔ±ð¡¢ÏÖʵºÍµç×ÓÓʼþµØµã¡¢ÊÖ»úºÅÂë¡¢Ô¤¶©ÏêϸÐÅÏ¢¡¢GPSλÖÃÒÔ¼°ÐÕÃû/Ö§¸¶¿¨µÄǰËÄλºÍºóËÄλ¡£¡£¡£¡£¡£¡£¶øÔڸù«Ë¾¶ÔÆäÊý¾Ý¾ÙÐб£»£» £» £»£»£»£»¤Ö®Ç°£¬£¬ £¬£¬£¬Meow»úеÈËÓÚ8ÔÂ12ÈÕ¶ÔÆä±¬·¢¹¥»÷£¬£¬ £¬£¬£¬É¾³ýÁ˳ý1GBÖ®ÍâµÄËùÓÐÊý¾Ý£¨×ܹ²43 GB£©¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/travel-site-exposed-37m-records/