IE RCE 0day¼°Defender DoS·ì϶£»2019ÄêÍøÂç¹¥»÷±¨´ð³É·Ö»ã±¨£»D-Link DNS-320 RCE·ì϶

°ä²¼¹¦·ò 2019-09-24
1.΢Èí´¹Î£½¨¸´IEÖеÄRCE 0day¼°DefenderÖеÄDoS·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

΢Èí°ä²¼´¹Î£°²È«¸üУ¬½¨¸´IEÖеÄRCE 0day¼°Windows DefenderÖеÄDoS·ì϶¡£ÆäÖÐIE 0dayΪ¹È¸è×êÑÐÈËÔ±Cl¨¦mentLecigne·¢Ïֵľ籾ÒýÇæÄÚ´æ°Ü»µ·ì϶£¨CVE-2019-1367£©£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë¡£¸Ã·ì϶Äܹ»Í¨¹ý½«Ö¸±êÓû§³Á¶¨ÏòÖÁ¶ñÒâÍøÕ¾À´ÀûÓã¬ÊÜÓ°ÏìµÄ°æ±¾Ô̺¬IE9¡¢10ºÍ11¡£ÁíÒ»¸ö·ì϶ÊÇWindows DefenderÖеĻؾø·þÎñ·ì϶£¨CVE-2019-1255£©£¬¸Ã·ì϶ÓëDefender´¦ÖÃÎļþµÄ·½Ê½ÓйØ£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶×èÖ¹ºÏ·¨ÕË»§Ö´ÐкϷ¨µÄϵͳÎļþ¡£ÊÜÓ°ÏìµÄDefender°æ±¾Îª1.1.16300.1£¬²¢ÒÑÔÚ1.1.16400.2Öн¨¸´¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/microsoft-releases-out-of-band-security-update-to-fix-ie-zero-day-defender-bug/

2.×êÑÐÈËÔ±Åû¶D-Link DNS-320É豸ÖеÄRCE·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


CyStack Security×êÑÐÈËÔ±·¢ÏÖD-Link DNS-320 ShareCenterÉ豸´æÔÚÒ»¸öºÅÁî×¢Èë·ì϶£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶Զ³Ì½ÚÔìÉ豸²¢½Ó¼ûÉ豸ÉÏ´æ´¢µÄÎļþ¡£¸Ã·ì϶£¨CVE-2019-16057£©µÄCVSSÆÀ·ÖΪ10·Ö£¬ËüÓ°ÏìÁ˹̼þ°æ±¾Îª2.05b10¼°¸üµÍµÄDNS-320É豸¡£Æ¾¾Ý×êÑÐÈËÔ±µÄ»ã±¨£¬¸Ã·ì϶ÓëDNS-320ÖÎÀí½çÃæµÄµÇ¼Ä£¿éÓйØ£¬ÊÜÓ°ÏìµÄÄ£¿é/cgi/login_mgr.cgiÔ̺¬Ò»¸ö¿ÉÄܱ»ÀûÓõIJÎÊýport£¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚrootȨÏÞÏÂÖ´ÐÐËÁÒâºÅÁ´Ó¶øµ¼ÖÂÉ豸±»ÊÕÊÜ¡£

  

Ô­ÎÄÁ´½Ó£º

https://blog.cystack.net/d-link-dns-320-rce/

3.Proofpoint°ä²¼¡¶2019ÄêÍøÂç¹¥»÷Öеı¨´ð³É·Ö¡··ÖÎö»ã±¨

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ƾ¾ÝProofpointµÄ¡¶2019ÄêÍøÂç¹¥»÷Öеı¨´ð³É·Ö¡··ÖÎö»ã±¨£¬ÔÚ´Óǰ¼¸ÄêÖй¥»÷Õß½«´¹µö¹¥»÷ÌáÉýµ½ÁËÒ»¸öȫеÄˮƽ£¬ËûÃÇ»ý¼«ÀûÓÃÏû·ÑÕߵĸÐÇ飬ÔÚÈËÃDz»ÖªÇéµÄÇé¿öÏÂÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£Êг¡ÓªÏúÐÐÒµÊÇ2018ÄêÖÁ2019ÄêµÄÖØÒª¹¥»÷Ö¸±êÖ®Ò»¡£ÕâЩ¹«Ë¾Õ¼ÓÐÓë¿Í»§ÓйصĴóÁ¿Ãô¸ÐÐÅÏ¢£¬Ô̺¬ÐÕÃû¡¢µØµãµØÒÔ¼°¹¤×÷ϰ¹ßµÈ£¬ÕâʹµÃËüÃdzÉΪ·¸×ï·Ö×ÓÓмÛÖµµÄÖ¸±ê¡£³ýÁ˸߹ÜÖ®±í£¬Éç½»¹¤³Ì¹¥»÷µÄÖ¸±ê»¹Ô̺¬ÆóÒµÖеļ¼ÊõÖ§³ÖÍŶӡ¢HRÒÔ¼°²ÆÕþ¹ÜÕʵÈ¡£¸Ã»ã±¨»¹Ç¿µ÷³Æ£¬·¸×ï·Ö×ÓҲͨ¹ýÔÚÉ罻ýÌåÉϳÉÁ¢×Ô¼ºµÄÆ·ÅÆ¡¢ÐÎÏóµÅ×ÕÆ­¸ü¶àµÄÊܺ¦Õß¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.proofpoint.com/us/resources/threat-reports/human-factor

4.ÐÂMac¶ñÒâÈí¼þGMERA.A¼Ù×°³ÉÂòÂôÈí¼þÇÔÈ¡Óû§ÐÅÏ¢


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ç÷Ïò¿Æ¼¼×êÑÐÈËÔ±·¢ÏÖÒ»¸ö¼Ù×°³ÉMacƽ̨ºÏ·¨ÂòÂôÈí¼þStockfolioµÄ¶ñÒâÈí¼þ¼Ò×åGMERA£¬¸Ã¼Ò×åÔ̺¬Á½¸ö±äÌ壬±ðÀëΪTrojan.MacOS.GMERA.AºÍTrojan.MacOS.GMERA.B£¬µÚÒ»¸ö±äÌåÊÇÒ»¸öZIP´æµµÎļþ£¬ÆäÖÐÔ̺¬Ò»¸ö°ó¸¿°üStockfoli.appºÍÒ»¸ö°µ²ØµÄ¼ÓÃÜÎļþ.app¡£¸ÃStockfoli.app¾­¹ý¶ñÒâÈí¼þ¿ª·¢ÕßµÄÊý×ÖÖ¤ÊéÊðÃû£¬Apple°µÊ¾´ËÖ¤ÊéÒÑÓÚ2019Äê7Ô±»³·³ý¡£µÚ¶þ¸ö±äÌåζÔÚ¶Ë¿Ú25733-25736ÉÏ´´½¨ÏνÓÖÁC£¦C·þÎñÆ÷µÄ·´Ïòshell£¬´Ó¶øÊ¹¹¥»÷Õß¿ÉÔÚÖ¸±ê»úеÉÏÖ´ÐÐshellºÅÁî¡£

Ô­ÎÄÁ´½Ó£º
https://blog.trendmicro.com/trendlabs-security-intelligence/mac-malware-that-spoofs-trading-app-steals-user-information-uploads-it-to-website/

5.ÃÀTCADÔâÀÕË÷Èí¼þ¹¥»÷£¬µç»°ºÍµç×ÓÓʼþµÈ·þÎñÖжÏ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹úÌØÀ­Î¬Ë¹ÏØÖÐÑëÆÀ¹ÀÇø£¨TCAD£©ÓÚ9ÔÂ19ÈÕÈ·ÈϳÆÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬µ¼Ö¶àÏî·þÎñÖжÏ¡£TCADÕÆ¹Ü¶Ô¸ÃÏØµÄ·¿µØ²ú½øÐÐÆÀ¹À£¬¸Ã»ú¹¹È·ÈϹ¥»÷ÊÂÎñ²úÉúÔÚ9ÔÂ11ÈÕÍíÉÏ9:30£¬¸Ã¹¥»÷Ó°ÏìÁËÍøÕ¾µÄ·¿²úËÑË÷Ö°ÄÜÒÔ¼°µç×ÓÓʼþ¡¢µç»°ºÍÍÆËã»ú¸¨ÖúÆÀ¹Àϵͳ£¬µ«¿Í»§·þÎñºÍÆÀ¹ÀÉê±çµÈÈÕ³£²Ù×÷²»ÊÜÓ°Ïì¡£·þÎñÆ÷ÉϵĺܶàÎļþ±»ÀÕË÷²¡¶¾¼ÓÃÜ£¬µ¼Ö¸ûú¹¹µÄ²¿ÃÅ·þÎñÖжÏ¡£¸Ã»ú¹¹»Ø¾øÖ§¸¶Êê½ð£¬²¢ÔÚÓëר¼ÒºÏ×÷ÒÔ´Ó±¸·ÝÊý¾ÝÖи´Ô­ÔËÓª¡£

Ô­ÎÄÁ´½Ó£º
https://www.traviscad.org/wp-content/uploads/2019/09/Cyber-Attack-FAQs.pdf

6.PhishLabs·¢ÏÖ¼Ù×°³É·çͶºÍ˽ļµÄд¹µö¹¥»÷

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


PhishLabs×êÑÐÈËÔ±·¢ÏÖ·¸×ï·Ö×ÓÔÚ¼ÙÒâ˽ļ¹«Ë¾Crossplane CapitalºÍEdgemont PartnersµÄÔ±¹¤À´ÓÕÆ­Êܺ¦Õß¡£ÎªÁËÓªÔìÕæÊµÐԺͽôÆÈ¸Ð£¬·¸×ï·Ö×ÓʹÓÃÁËÕæÊµÔ±¹¤¡¢PE»òVCµÄÃû×Ö£¬²¢ÇÒÔ̺¬Ò»¸öÒÑÊðÃûµÄ±£ÃܺÍ̸£¨NDA£©¡£¸ÃNDAλÓÚÒ»¸öͼƬÁ´½Óºó£¬ÆäURLʹÓÃÁË×î½ü×¢²áµÄ·ÂÕÕÁËÕæÊµË½Ä¼¹«Ë¾µÄαÔìÓòÃû£¬²¢×îÖÕ½«Êܺ¦Õß³Á¶¨ÏòÖÁhxxps://serversecuredhttp[.]com¡£¸ÃÍøÕ¾ÒªÇóÊܺ¦ÕߵǼÆäOffice 365ÕÊ»§ÒÔÏÂÔØÎĵµ£¬ÕâÒ²ÕýÊÇ·¸×ï·Ö×ӵĴ¹µöÖ¸±ê¡£

  

Ô­ÎÄÁ´½Ó£º

https://info.phishlabs.com/blog/spear-phishing-campaign-impersonates-vcs-and-pe-firms