ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ44ÖÜ
Ðû²¼Ê±¼ä 2020-11-02> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
2020Äê10ÔÂ26ÈÕÖÁ11ÔÂ01ÈÕ¹²ÊÕ¼Çå¾²Îó²î59¸ö£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇRuckus Networks Ruckus vRioT /service/v1/createUser endpoint´úÂëÖ´ÐÐÎó²î£»£»£»£»Winston PrivacyÏÂÁî×¢ÈëÎó²î£»£»£»£»NVIDIA DGX Server BMC firmwareÓ²±àÂëÎó²î£»£»£»£»Synology Router Managerí§ÒâÏÂÁîÖ´ÐÐÎó²î£»£»£»£»Google chrome Freetype¶ÑÒç³ö´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇд¹Âڻð³äMicrosoft TeamsÕë¶ÔOffice 365Óû§£»£»£»£»ImpervaÐû²¼ÓйØKashmirBlack½©Ê¬ÍøÂçµÄÆÊÎö±¨¸æ£»£»£»£»AvastÐû²¼ÓйØGoogle PlayÉ϶ñÒâÈí¼þµÄÆÊÎö±¨¸æ£»£»£»£»ºÚ¿ÍÈëÇÖÌØÀÊÆÕ¾ºÑ¡ÍøÕ¾²¢Èö²¥ÐéαÐÅÏ¢£»£»£»£»CISAºÍCNMFÐû²¼Ð¶ñÒâÈí¼þ±äÌåZebrocyµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£¡£
> Ö÷ÒªÇå¾²Îó²îÁбí
1.Ruckus Networks Ruckus vRioT /service/v1/createUser endpoint´úÂëÖ´ÐÐÎó²î
Ruckus Networks Ruckus vRioT /service/v1/createUser endpoint±£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿Éͨ¹ýweb.pyÒÔrootȨÏÞÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£
https://support.ruckuswireless.com/security_bulletins/305
2.Winston PrivacyÏÂÁî×¢ÈëÎó²î
Winston Privacy×°±¸ÖÎÀíAPI±£´æÏÂÁî×¢ÈëÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿É¾ÙÐÐí§Òâ´úÂëÖ´Ðй¥»÷£¬£¬£¬£¬£¬Èçͨ¹ý/api/advanced_settings¸ü¸Ä×°±¸¡£¡£¡£¡£¡£¡£¡£
https://labs.bishopfox.com/advisories/winston-privacy-version-1.5.4#CI
3.NVIDIA DGX Server BMC firmwareÓ²±àÂëÎó²î
NVIDIA DGX Server BMC firmware±£´æÓ²±àÂëÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿ÉδÊÚȨ»á¼ûЧÀÍ×°±¸¡£¡£¡£¡£¡£¡£¡£
https://nvidia.custhelp.com/app/answers/detail/a_id/5010
4.Synology Router Managerí§ÒâÏÂÁîÖ´ÐÐÎó²î
Synology Router Manager 7786/7787¶Ë¿Ú±£´æ²»×¼È·»á¼û¿ØÖÆÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿ÉÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£
https://www.synology.com/zh-cn/security/advisory/Synology_SA_20_14
5.Google chrome Freetype¶ÑÒç³ö´úÂëÖ´ÐÐÎó²î
Google chrome Freetype±£´æ¶ÑÒç³öÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇ󣬣¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬¿É¾ÙÐоܾøÐ§À͹¥»÷»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.html
> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢Ð´¹Âڻð³äMicrosoft TeamsÕë¶ÔOffice 365Óû§
Abnormal Security·¢Ã÷д¹Âڻð³äMicrosoft TeamsÕë¶ÔOffice 365Óû§¡£¡£¡£¡£¡£¡£¡£ÕâЩ´¹ÂÚÓʼþÊÇÒÔTeamsÖÐÓÐлΪÖ÷Ìâ·¢Ë͵쬣¬£¬£¬£¬¿´ÆðÀ´ÏñÊÇMicrosoft TeamsµÄ×Ô¶¯Í¨Öª£¬£¬£¬£¬£¬ÓÃÀ´¼û¸æÊܺ¦ÕßÓдí¹ýµÄ̸Ìì¡£¡£¡£¡£¡£¡£¡£ÓʼþÓÕʹÊܺ¦Õßµã»÷Team»Ø¸´Á´½Ó£¬£¬£¬£¬£¬ÒÔÖØ¶¨Ïòµ½´¹ÂÚÍøÕ¾£¬£¬£¬£¬£¬À´ÇÔÈ¡Office 365Óû§µÄƾ֤¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÊӲ쵽£¬£¬£¬£¬£¬¹¥»÷ÕßÒѾʹÓøÃÔ˶¯¹¥»÷ÁË15000ÖÁ50000¸öOffice 365Óû§¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/109938/cyber-crime/microsoft-teams-phishing-attacks.html
2¡¢ImpervaÐû²¼ÓйØKashmirBlack½©Ê¬ÍøÂçµÄÆÊÎö±¨¸æ
ImpervaÐû²¼ÁËÓйØKashmirBlack½©Ê¬ÍøÂçµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£¸Ã±¨¸æÐÎòÁËKashmirBlack½©Ê¬ÍøÂç±³ºóµÄ·¸·¨²Ù×÷£¬£¬£¬£¬£¬ÌÖÂÛÁËÆäÄ¿µÄÒÔ¼°Ñо¿ÒªÁì¡£¡£¡£¡£¡£¡£¡£KashmirBlackÖ÷ÒªÕë¶ÔÊ¢ÐеÄCMSƽ̨¡£¡£¡£¡£¡£¡£¡£ËüʹÓÃÁËÄ¿µÄЧÀÍÆ÷ÉϵÄÊýÊ®¸öÒÑÖªÎó²î£¬£¬£¬£¬£¬Æ½¾ùÌìÌì¶ÔÈ«Çò30¶à¸ö²î±ð¹ú¼ÒµÄÊýǧÃûÊܺ¦Õß¾ÙÐÐÊý°ÙÍò´Î¹¥»÷¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬ÆäÔËÐкÜÊÇÖØ´ó£¬£¬£¬£¬£¬ÓÉһ̨C&CЧÀÍÆ÷ÖÎÀí£¬£¬£¬£¬£¬²¢Ê¹ÓÃÁË60¶ą̀ЧÀÍÆ÷×÷ΪÆä»ù´¡ÉèÊ©µÄÒ»²¿·Ö¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿É´¦Öóͷ£Êý°Ù¸ö½©Ê¬³ÌÐò£¬£¬£¬£¬£¬Ö´Ðб©Á¦¹¥»÷¡¢×°ÖúóÃÅ¡¢²¢À©´ó½©Ê¬ÍøÂçµÄ¹æÄ£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.imperva.com/blog/crimeops-of-the-kashmirblack-botnet-part-i/
3¡¢AvastÐû²¼ÓйØGoogle PlayÉ϶ñÒâÈí¼þµÄÆÊÎö±¨¸æ
ɱ¶¾Èí¼þÖÆÔìÉÌAvastÐû²¼ÓйØGoogle PlayÉ϶ñÒâÈí¼þµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£¸Ã±¨¸æ³ÆGoogle PlayÊÐËÁÖÐÓÐ21¸öѬȾÁËHiddenAds¶ñÒâÈí¼þµÄAndroidÓ¦ÓóÌÐò£¬£¬£¬£¬£¬GoogleÒÑÓÚÖÜĩɾ³ýÁËÆäÖеÄ15¸ö¡£¡£¡£¡£¡£¡£¡£Avast¶ñÒâÈí¼þÆÊÎöʦÌåÏÖ£¬£¬£¬£¬£¬ÕâЩӦÓÃÄ£ÄâÁËÊ¢ÐеÄÓÎÏ·£¬£¬£¬£¬£¬Ò»µ©Óû§×°ÖÃÁËÕâЩӦÓ㬣¬£¬£¬£¬HiddenAds¾Í»áÒþ²Ø¸ÃÓ¦ÓóÌÐòµÄͼ±êʹÓû§ÄÑÒÔ¾ÙÐÐɾ³ý£¬£¬£¬£¬£¬È»ºó×îÏÈÓÃ¹ã¸æºäÕ¨Óû§¡£¡£¡£¡£¡£¡£¡£AvastÌåÏÖ£¬£¬£¬£¬£¬×èÖ¹ÉÏÖÜÕâЩӦÓóÌÐòÒÑ´ï700Íò´ÎÏÂÔØÁ¿¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.avast.com/new-malware-apps-on-google-play-avast
4¡¢ºÚ¿ÍÈëÇÖÌØÀÊÆÕ¾ºÑ¡ÍøÕ¾²¢Èö²¥ÐéαÐÅÏ¢
Õþ¸®¹ÙÔ±ÌåÏÖ£¬£¬£¬£¬£¬ºÚ¿ÍÔÚÑ¡¾ÙÈÕǰһÖܵÄÐÇÆÚ¶þÈëÇÖÁËÌÆÄɵ¡¤ÌØÀÊÆÕµÄ¾ºÑ¡ÍøÕ¾¡£¡£¡£¡£¡£¡£¡£donaldjtrump.comÍøÕ¾±»¡°Õâ¸öÍøÕ¾±»²é·âÁË¡±ÐÂÎÅËùÈ¡´ú£¬£¬£¬£¬£¬²¢ÌåÏÖ¡°ÌìÏÂÒѾÊܹ»ÁËÌÆÄɵ¡¤J¡¤ÌØÀÊÆÕ×ÜͳÌìÌìÉ¢²¥µÄ¼ÙÐÂÎÅ¡±¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬ºÚ¿Í»¹ºôÓõÍøÃñ¾èÔùMoneroÊý×ÖÇ®±ÒÒÔÖ§³Ö»ò×赲й¶ÓëÌØÀÊÆÕÓйصÄÖ¤¾Ý¡£¡£¡£¡£¡£¡£¡£ÌØÀÊÆÕ¾ºÑ¡½²»°ÈËTim MurtaughÌåÏÖ£¬£¬£¬£¬£¬¸ÃÍøÕ¾ºÜ¿ì»ñµÃÐÞ¸´²¢Ã»ÓÐÈκÎÃô¸ÐÊý¾Ýй¶£¬£¬£¬£¬£¬´Ë´Î¹¥»÷µÄȪԴ»¹ÔÚÊÓ²ìÖС£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/trump-campaign-website-broken-hackers
5¡¢CISAºÍCNMFÐû²¼Ð¶ñÒâÈí¼þ±äÌåZebrocyµÄÆÊÎö±¨¸æ
ÍøÂçÇå¾²ºÍ»ù´¡ÉèÊ©Çå¾²¾Ö£¨CISA£©ºÍ¹ú·À²¿£¨DOD£©ÍøÂç¹ú¼ÒÐû½Ì²½¶Ó£¨CNMF£©·¢Ã÷еĶñÒâÈí¼þ±äÌåZebrocy¡£¡£¡£¡£¡£¡£¡£¸Ã±äÌåÊÇÒ»¸ö32λµÄWindows¿ÉÖ´ÐÐÎļþ£¬£¬£¬£¬£¬Ê¹ÓÃGolang±à³ÌÓïÑÔ±àд£¬£¬£¬£¬£¬½ÓÄɵIJÎÊýӦΪÒì»ò£¨XOR£©ºÍÊ®Áù½øÖƱàÂëµÄͳһ×ÊÔ´±êʶ·û£¨URI£©£¬£¬£¬£¬£¬»òÕß¿ÉÒÔʹÓô¿Îı¾URIÔËÐС£¡£¡£¡£¡£¡£¡£Ö´ÐÐʱ£¬£¬£¬£¬£¬Ëü½«Ê¹Óø߼¶¼ÓÃܱê×¼£¨AES£©-128µç×ÓÃÜÂë²¾£¨ECB£©Ëã·¨¶ÔURI¾ÙÐмÓÃÜ£¬£¬£¬£¬£¬²¢Ê¹ÓôÓÊܺ¦ÕßµÄÖ÷»úÃûÌìÉúµÄÃÜÔ¿£¬£¬£¬£¬£¬±ðµÄ»¹»áÍøÂçÓйØÊÜÄ¿µÄϵͳµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2020/10/29/cisa-and-cnmf-identify-new-malware-variant-zebrocy