IE RCE 0day¼°Defender DoS·ì϶£»2019ÄêÍøÂç¹¥»÷±¨´ð³É·Ö»ã±¨£»D-Link DNS-320 RCE·ì϶
°ä²¼¹¦·ò 2019-09-24
΢Èí°ä²¼´¹Î£°²È«¸üУ¬½¨¸´IEÖеÄRCE 0day¼°Windows DefenderÖеÄDoS·ì϶¡£ÆäÖÐIE 0dayΪ¹È¸è×êÑÐÈËÔ±Cl¨¦mentLecigne·¢Ïֵľ籾ÒýÇæÄÚ´æ°Ü»µ·ì϶£¨CVE-2019-1367£©£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë¡£¸Ã·ì϶Äܹ»Í¨¹ý½«Ö¸±êÓû§³Á¶¨ÏòÖÁ¶ñÒâÍøÕ¾À´ÀûÓã¬ÊÜÓ°ÏìµÄ°æ±¾Ô̺¬IE9¡¢10ºÍ11¡£ÁíÒ»¸ö·ì϶ÊÇWindows DefenderÖеĻؾø·þÎñ·ì϶£¨CVE-2019-1255£©£¬¸Ã·ì϶ÓëDefender´¦ÖÃÎļþµÄ·½Ê½Óйأ¬¹¥»÷Õß¿ÉÀûÓø÷ì϶×èÖ¹ºÏ·¨ÕË»§Ö´ÐкϷ¨µÄϵͳÎļþ¡£ÊÜÓ°ÏìµÄDefender°æ±¾Îª1.1.16300.1£¬²¢ÒÑÔÚ1.1.16400.2Öн¨¸´¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/microsoft-releases-out-of-band-security-update-to-fix-ie-zero-day-defender-bug/2.×êÑÐÈËÔ±Åû¶D-Link DNS-320É豸ÖеÄRCE·ì϶
ÔÎÄÁ´½Ó£º
https://blog.cystack.net/d-link-dns-320-rce/3.Proofpoint°ä²¼¡¶2019ÄêÍøÂç¹¥»÷Öеı¨´ð³É·Ö¡··ÖÎö»ã±¨
ƾ¾ÝProofpointµÄ¡¶2019ÄêÍøÂç¹¥»÷Öеı¨´ð³É·Ö¡··ÖÎö»ã±¨£¬ÔÚ´Óǰ¼¸ÄêÖй¥»÷Õß½«´¹µö¹¥»÷ÌáÉýµ½ÁËÒ»¸öȫеÄˮƽ£¬ËûÃÇ»ý¼«ÀûÓÃÏû·ÑÕߵĸÐÇ飬ÔÚÈËÃDz»ÖªÇéµÄÇé¿öÏÂÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£Êг¡ÓªÏúÐÐÒµÊÇ2018ÄêÖÁ2019ÄêµÄÖØÒª¹¥»÷Ö¸±êÖ®Ò»¡£ÕâЩ¹«Ë¾Õ¼ÓÐÓë¿Í»§ÓйصĴóÁ¿Ãô¸ÐÐÅÏ¢£¬Ô̺¬ÐÕÃû¡¢µØµãµØÒÔ¼°¹¤×÷ϰ¹ßµÈ£¬ÕâʹµÃËüÃdzÉΪ·¸×ï·Ö×ÓÓмÛÖµµÄÖ¸±ê¡£³ýÁ˸߹ÜÖ®±í£¬Éç½»¹¤³Ì¹¥»÷µÄÖ¸±ê»¹Ô̺¬ÆóÒµÖеļ¼ÊõÖ§³ÖÍŶӡ¢HRÒÔ¼°²ÆÕþ¹ÜÕʵȡ£¸Ã»ã±¨»¹Ç¿µ÷³Æ£¬·¸×ï·Ö×ÓҲͨ¹ýÔÚÉ罻ýÌåÉϳÉÁ¢×Ô¼ºµÄÆ·ÅÆ¡¢ÐÎÏóµÅ×ÕÆ¸ü¶àµÄÊܺ¦Õß¡£
ÔÎÄÁ´½Ó£º
https://www.proofpoint.com/us/resources/threat-reports/human-factor4.ÐÂMac¶ñÒâÈí¼þGMERA.A¼Ù×°³ÉÂòÂôÈí¼þÇÔÈ¡Óû§ÐÅÏ¢
Ç÷Ïò¿Æ¼¼×êÑÐÈËÔ±·¢ÏÖÒ»¸ö¼Ù×°³ÉMacƽ̨ºÏ·¨ÂòÂôÈí¼þStockfolioµÄ¶ñÒâÈí¼þ¼Ò×åGMERA£¬¸Ã¼Ò×åÔ̺¬Á½¸ö±äÌ壬±ðÀëΪTrojan.MacOS.GMERA.AºÍTrojan.MacOS.GMERA.B£¬µÚÒ»¸ö±äÌåÊÇÒ»¸öZIP´æµµÎļþ£¬ÆäÖÐÔ̺¬Ò»¸ö°ó¸¿°üStockfoli.appºÍÒ»¸ö°µ²ØµÄ¼ÓÃÜÎļþ.app¡£¸ÃStockfoli.app¾¹ý¶ñÒâÈí¼þ¿ª·¢ÕßµÄÊý×ÖÖ¤ÊéÊðÃû£¬Apple°µÊ¾´ËÖ¤ÊéÒÑÓÚ2019Äê7Ô±»³·³ý¡£µÚ¶þ¸ö±äÌåζÔÚ¶Ë¿Ú25733-25736ÉÏ´´½¨ÏνÓÖÁC£¦C·þÎñÆ÷µÄ·´Ïòshell£¬´Ó¶øÊ¹¹¥»÷Õß¿ÉÔÚÖ¸±ê»úеÉÏÖ´ÐÐshellºÅÁî¡£
ÔÎÄÁ´½Ó£º
https://blog.trendmicro.com/trendlabs-security-intelligence/mac-malware-that-spoofs-trading-app-steals-user-information-uploads-it-to-website/
5.ÃÀTCADÔâÀÕË÷Èí¼þ¹¥»÷£¬µç»°ºÍµç×ÓÓʼþµÈ·þÎñÖжÏ
ÔÎÄÁ´½Ó£º
https://www.traviscad.org/wp-content/uploads/2019/09/Cyber-Attack-FAQs.pdf
6.PhishLabs·¢ÏÖ¼Ù×°³É·çͶºÍ˽ļµÄд¹µö¹¥»÷
ÔÎÄÁ´½Ó£º
https://info.phishlabs.com/blog/spear-phishing-campaign-impersonates-vcs-and-pe-firms


¾©¹«Íø°²±¸11010802024551ºÅ