¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181123

°ä²¼¹¦·ò 2018-11-23
1¡¢VMware°ä²¼¸üУ¬½¨¸´Ðé¹¹»úÌÓÒÝ·ì϶CVE-2018-6983

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


VMware½¨¸´Ì츮±­ÉÏÅû¶µÄÐé¹¹»úÌÓÒÝ·ì϶£¨CVE-2018-6983£©£¬¸Ã·ì϶ÊÇÒ»¸öÕûÊýÒç¶Âí½Å£¬³É¹¦ÀûÓø÷ì϶¿Éµ¼ÖÂÐé¹¹»úÌÓÒݲ¢ÔÚËÞÖ÷»úÉÏÖ´ÐдúÂë¡£ÊÜÓ°ÏìµÄ²úÆ·Ô̺¬VMware Workstation¡¢VMware FusionµÈ£¬VMwareÔÚWorkstation°æ±¾ 14.1.2/15.0.2¼°Fusion°æ±¾10.1.5/11.0.2Öн¨¸´Á˸÷ì϶£¬½¨ÒéÓû§¾¡¿ì½øÐиüС£

  

 Ô­ÎÄÁ´½Ó£º

https://www.vmware.com/security/advisories/VMSA-2018-0030.html


2¡¢µÂ¹úÉí·ÝÖ¤RFIDоƬ±»ÆØ´æÔÚ·ì϶£¬¿ÉÓÃÓÚαÔìÉí·Ý

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°²È«³§ÉÌSEC Consult±¾ÖÜÅû¶µÂ¹úRFIDоƬÉí·ÝÖ¤ÖеÄÒ»¸ö°²È«·ì϶£¬¸Ã·ì϶¿ÉÔÊÐí¹¥»÷ÕßαÔì×Ô¼ºµÄÉí·Ý¡£µÂ¹ú´Ó2010ÄêÆðͷʹÓÃÕâÖÖ´øÓÐÉ䯵¼ø±ð£¨RFID£©Ð¾Æ¬µÄÊý×ÖÉí·ÝÖ¤£¬²¢ÔÚоƬÖд洢¹«ÃñµÄÉí·ÝÊý¾Ý£¬Ô̺¬ÐÕÃû¡¢ÉúÈÕ¡¢ÕÕÆ¬µÈ£¬¿Éͨ¹ýÏàÓ¦µÄ¿Í»§¶ËÈí¼þ£¨eID client£©¶ÁȡоƬÊý¾Ý²¢½øÐÐÏßÉÏÈÏÖ¤¡£×êÑÐÈËÔ±Wolfgang Ettlinger·¢´Ë¿ÌÕâ¸ö¹ý³ÌÖÐÄܹ»Ê¹ÓÃαÔìµÄÊý¾ÝÈÆ¹ý·þÎñÆ÷µÄ± £»¤£¬´Ó¶øµ÷»»Éí·Ý¡£GovernikusÒÑÔÚ2018Äê8Ô·ݰ䲼µÄAutent SDK 3.8.1.2Öн¨¸´Á˸÷ì϶¡£

 

 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/german-eid-authentication-flaw-lets-you-change-identity/


3¡¢×êÑÐÍŶӷ¢ÏÖÓÃÓÚ·Ö·¢AzorultľÂíµÄжñÒâ»î¶¯FindMyName

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Palo Alto NetworksµÄUnit42×êÑÐÍŶӴÓ2018Äê10ÔÂ20ÈÕÆð¹Û²ìµ½ÓÃÓÚ·Ö·¢AzorultľÂíбäÌåµÄ¶ñÒâ»î¶¯FindMyName¡£¸Ã»î¶¯µÃÃûÓÚÆäʹÓõÄÓòÃûfindmyname[.]pw¡£¸ÃAzorult±äÌåͨ¹ýFallout EK½øÐзַ¢£¬×êÑÐÈËԱͨ¹ý¶ÈÎö·¢ÏָöñÒâÑù±¾Ê¹ÓÃÁ˸߼¶»ìºÏ¼¼ÊõÒÔÌӱܼì²â¡£´Ë±í£¬×êÑÐÈËÔ±»¹·¢ÏÖAzorultÓÖÓÐËùÑݱ䣬Æä´Ë¿ÌÖ§³Ö´Ó¸ü¶àµÄä¯ÀÀÆ÷¡¢ÀûÓ÷¨Ê½ºÍ¼ÓÃÜÇ®±ÒÇ®°üÖÐÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£

 

 Ô­ÎÄÁ´½Ó£º

https://researchcenter.paloaltonetworks.com/2018/11/unit42-new-wine-old-bottle-new-azorult-variant-found-findmyname-campaign-using-fallout-exploit-kit/


4¡¢°²È«³§ÉÌ·¢ÏÖ¿ÉÕë¶ÔLinux·þÎñÆ÷µÄMirai±äÌåBotmasters

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ArborµÄASERT×êÑÐÍŶӷ¢ÏÖÒ»¸öеÄMirai±äÌå´Ë¿ÌÄܹ»Ï°È¾Linux·þÎñÆ÷ÁË£¬¸Ã±äÌåÊÇBotmasters£¬Í¨¹ý½«¹¥»÷Ö¸±ê´ÓIoTÉ豸ת±äΪÉÌÓÃLinux·þÎñÆ÷£¬Botmasters²»ÔÙ±ØÒªÎª·ÖÆçµÄ¼Ü¹¹½øÐвüô£¬¶øÊÇÄܹ»¼Ù¶¨¹¥»÷Ö¸±êΪx86ƽ̨¡£Ò»Ð©¹¥»÷ÕßÔÚʹÓö¨ÔìµÄ¹¤¾ßͨ¹ýHadoop YARN·ì϶·Ö·¢¸Ã¶ñÒâÈí¼þ¡£ÓÉÓÚÉÌÓÃLinux·þÎñÆ÷µÄ´ø¿íÒª±ÈIoTÉ豸Ҫ´óµÃ¶à£¬Òò¶ø¸Ã¶ñÒâÈí¼þ¿É¹¹½¨Ð§Äܸü¸ßµÄDDoS½©Ê¬ÍøÂ磬Æä·çÏÕ²»ÈÝÓ×êï¡£

  

Ô­ÎÄÁ´½Ó£º

https://asert.arbornetworks.com/mirai-not-just-for-iot-anymore/


5¡¢×êÑÐÍŶӷ¢ÏÖÖØÒªÕë¶Ô¶íÂÞ˹µÄÐÂRotexyľÂí

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¿¨°Í˹»ù³¢ÊÔÊÒ·¢ÏÖÖØÒªÕë¶Ô¶íÂÞ˹µÄRotexyľÂíбäÌ壬ÔÚ2018Äê8ÔÂÖÁ10ÔµÄÈý¸öÔÂÄÚ£¬¸Ã±äÌå×ܹ²Ïò¶íÂÞ˹Óû§ÌáÒéÁË7ÍòÂŴι¥»÷¡£RotexyľÂí¼Ò×åµÄÒ»¸öÓÐÈ¤ÌØµãÊÇͬʱʹÓÃÁËÈýÖÖºÅÁîÔ´£¬Ô̺¬¹È¸èÔÆÍÆËÍ·þÎñ£¨GCM£©-ÓÃÓÚ½«JSONÌåʽµÄÐÅÏ¢·¢ËÍÖÁÒÆ¶¯É豸¡¢C&C·þÎñÆ÷ÒÔ¼°¶ÌÐÅ¡£ÕâÊǸÃľÂí¼Ò×åµÄÒ»¸öÌØÉ«¡£RotexyµÄбäÌå×ÛºÏÁËÒøÐÐľÂíºÍÀÕË÷Èí¼þµÄÖ°ÄÜ£¬ËüÒÔAvitoPay.apkµÄÃû³Æ´«²¼£¬´Óyoula9d6h.tk¡¢prodam8n9.tk¡¢prodamfkz.ml¡¢avitoe0ys.tkµÈÍøÕ¾ÏÂÔØ¡£

  

Ô­ÎÄÁ´½Ó£º

https://securelist.com/the-rotexy-mobile-trojan-banker-and-ransomware/88893/


6¡¢×êÑÐÍŶӷ¢ÏÖÐÂÔöPoS¶ñÒâÄ£¿éµÄTrickBotбäÌå

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ç÷Ïò¿Æ¼¼µÄ×êÑÐÍŶӷ¢ÏÖÒøÐÐľÂíTrickBotÐÂÔöÁËÒ»¸öPoS¶ñÒâÄ£¿é£¬Ê¹Æä±äµÃÔ½·¢Î£ÏÕ¡£¸ÃÄ£¿éÓÃÓÚɨÃèÊÜϰȾµÄÍÆËã»úÊÇ·ñÏνӵ½ÈκÎÖ§³ÖPoS·þÎñµÄÉ豸ºÍÍøÂ磬²¢ÍøÂçÓйØÐÅÏ¢¡£×êÑÐÈËÔ±»¹ÔÚµ÷²é¹¥»÷ÕßÈôºÎÀûÓÃÕâЩÐÅÏ¢£¬µ«¿ÉÄܵÄÇé¿öÊǹ¥»÷ÕßÔÚÍøÂçÐÅÏ¢ÒÔΪ½«À´µÄÈëÇÖ×ö³ï±¸¡£

  

Ô­ÎÄÁ´½Ó£º

https://blog.trendmicro.com/trendlabs-security-intelligence/trickbots-bigger-bag-of-tricks/


ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù