΢ÈíÖÕÖ¹Windows 7¡¢Server 2008ºÍ2008 R2µÄÖ§³Ö£»Nemty¹«¿ª»Ø¾øÖ§¸¶Êê½ðµÄÊܺ¦ÕßÊý¾Ý

°ä²¼¹¦·ò 2020-01-15


1.΢ÈíÕýʽÖÕÖ¹¶ÔWindows 7¡¢Server 2008ºÍ2008 R2Ìṩ֧³Ö


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


΢ÈíÓÚ1ÔÂ14ÈÕÕýʽÖÕÖ¹¶ÔWindows 7¡¢Server 2008ºÍServer 2008 R2Ìṩ֧³Ö  ¡£ÔÚ´ËÖ®ºóÕâЩ²Ù×÷ϵͳÈԿɳÖÐø¹¤×÷£¬µ«½«²»ÔÙÊÕµ½°²È«¸üР ¡£¶ÔWindows Server 2008µÄÖÕÖ¹Ö§³ÖÒâζ×ÅÆä¶î±íµÄÃâ·Ñ°²È«¸üС¢·Ç°²È«¸üС¢Ãâ·ÑµÄÖ§³Ö·þÎñÒÔ¼°ÔÚÏß¼¼ÊõÄÚÈݸüж¼ÒÑʵÏÖ  ¡£Î¢Èí¶½´ÙÓû§½«Æä²úÆ·ºÍ·þÎñǨáãµ½Azure»òÊÇÉý¼¶µ½×îа汾Server 2016  ¡£ÎÞ·¨ÔÚÖ§³ÖÖÕÖ¹ÆÚÏÞ֮ǰʵÏÖÉý¼¶µÄÈËÄܹ»²É°ìÀ©´ó°²È«¸üУ¬ÒÔ±£»¤·þÎñÆ÷¹¤×÷¸ºÔØÖ±ÖÁÉý¼¶ÎªÖ¹  ¡£


  Ô­ÎÄÁ´½Ó£º

https://www.darkreading.com/risk/microsoft-to-officially-end-support-for-windows-7-server-2008/d/d-id/1336791


2.ÃÀ¹úLimeLeads¹«Ë¾4900ÍòÌõÓû§¼Í¼ÔÚ°µÍøÂÛ̳ÏúÊÛ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¾ÝZDNet±¨Â·£¬ºÚ¿ÍOmnichorusÔÚ°µÍøÂÛ̳ÉÏÏúÊÛÃÀ¹úÊý¾Ý¾­¼ÍÉÌLimeLeadsµÄ4900ÍòÌõÓû§¼Í¼  ¡£°²È«×êÑÐÔ±Bob DiachenkoÈ·ÈÏÕâЩÊý¾ÝÊÇÓɸù«Ë¾µÄÄÚ²¿Elasticsearch·þÎñÆ÷¶³öÔÚInternetÉÏй¶µÄ  ¡£Æ¾¾ÝDiachenkoµÄ˵·¨£¬ÖÁÉÙ´Ó2019Äê7ÔÂ27ÈÕÆðLimeLeadsµÄһ̨·þÎñÆ÷¾Í¿É¹«¿ª½Ó¼û£¬ËûÓÚÈ¥Äê9ÔÂ16ÈÕ֪ͨÁ˸ù«Ë¾£¬¸Ã¹«Ë¾ÔÚµÚ¶þÌìѸ¿ì¶Ô·þÎñÆ÷½øÐÐÁ˱£»¤£¬µ«ÏÔÈ»OmnichorusÒѾ­ÇÔÈ¡ÁËÕâЩÊý¾Ý£¬²¢ÇÒ´ÓÈ¥Äê10ÔÂÒÔÀ´Ò»ÏòÔÚÍøÉÏÏúÊÛ  ¡£Æ¾¾ÝOmnichorus°ä²¼µÄÊý¾ÝÑù±¾£¬ÕâЩÊý¾ÝÔ̺¬Óû§µÄÐÕÃû¡¢Ö°Îñ¡¢µç×ÓÓʼþ¡¢¹ÍÖ÷/¹«Ë¾Ãû³Æ¡¢¹«Ë¾µØÖ·¡¢³ÇÊÓ×¢ÖÝ¡¢ÓÊÕþ±àÂë¡¢µç»°ºÅÂë¡¢ÍøÕ¾URL¡¢¹«Ë¾×ÜÊÕÈëÒÔ¼°¹«Ë¾µÄÔ¤¼ÆÔ±¹¤ÈËÊýµÈÐÅÏ¢  ¡£


 Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/49-million-user-records-from-us-data-broker-limeleads-put-up-for-sale-online/


3.¶íÂÞ˹APT28ÓëÕë¶ÔÎÚ¿ËÀ¼Burisma¹«Ë¾µÄ´¹µö¹¥»÷ÓйØ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾Ý°²È«³§ÉÌArea 1 Security°ä²¼µÄÒ»·Ý»ã±¨£¬¶íÂÞ˹ºÚ¿Í×éÖ¯APT28ÓëÕë¶ÔÎÚ¿ËÀ¼ÌìÈ»Æø¹«Ë¾BurismaµÄÍøÂç´¹µö¹¥»÷ÓÐ¹Ø  ¡£¹¥»÷Õß³ÉÁ¢ÁË·ÂÕÕBurisma¼°Æä×Ó¹«Ë¾¹ÙÍøµÄαÔìÍøÕ¾£¬Ö¼ÔÚÓÕÆ­Ô±¹¤Ìá½»ÆäÓÊÏäÍ´´¦  ¡£Burisma¹«Ë¾±»Ç£³¶µ½Õë¶ÔÃÀ¹ú×ÜÍ³ÌØÀÊÆÕµÄµ¯ÛÀ°¸ÖУ¬Æ¾¾Ý¡¶Å¦Ô¼Ê±±¨¡·µÄ±¨Â·£¬ÍøÂç¹¥»÷²úÉúÔÚÈ¥Äê11Ô·Ý£¬Óë´ËÍ¬Ê±ÌØÀÊÆÕÏòÎÚ¿ËÀ¼×ÜͳÎÖÀ­µÏÃ×¶û¡¤ÔóÂ×˹»ùÊ©¼ÓѹÁ¦£¬ÒªÇóÆäµ÷²éǰ¸±×ÜͳÓë°ÍÀ­¿Ë¡¤°Â°ÍÂí¡¢Ô¼Éª·ò¡¤°ÝµÇ¼°Æä¶ù×ÓºàÌØÖ®¼äµÄ¹ØÏµ  ¡£¡¶Å¦Ô¼Ê±±¨¡·³Æ¶íÂÞ˹ºÚ¿Í¿ÉÄÜÔÚѰÕÒÓëÌØÀÊÆÕÏëÒª»ñµÃµÄÒ»Ñù×ÊÁÏ  ¡£


 Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/phishing-campaign-targeting-ukrainian-firm-burisma-linked-russian-cyberspies


4.ÀÕË÷Èí¼þNemtyÆðÍ·°ä²¼»Ø¾øÖ§¸¶Êê½ðµÄÊܺ¦ÕßÊý¾Ý


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÀÕË÷Èí¼þNemty±³ºóµÄ¹¥»÷ÕßÏòBleepingComputerÅû¶ÁËÆä´´½¨Ò»¸ö²©¿ÍµÄ´òË㣬¸Ã²©¿Í½«ÓÃÓÚ°ä²¼»Ø¾øÖ§¸¶Êê½ðµÄÊܺ¦ÕßÊý¾Ý  ¡£ÕâÊÇÓÉÀÕË÷Èí¼þMazeÆðÍ·µÄÒ»ÖÖй¥»÷Õ½Êõ£¬ÀÕË÷Èí¼þSodinokibi¸ú½øÁËÕâÒ»²½Ö裬´Ë¿ÌNemtyÒ²½«²Î¼ÓÆäÖÐ  ¡£ÈôÊÇÊܺ¦Õ߻ؾøÖ§¸¶Êê½ð£¬¹¥»÷Õß½«Ò»µãÒ»µãµØÐ¹Â¶±»ÇÔÈ¡µÄÊý¾Ý£¬ÏòÊܺ¦ÕßÊ©¼ÓѹÁ¦£¬Ö±µ½Æä¸¶¿î»òÊý¾Ý±»È«Êý¿ªÊÍΪֹ  ¡£McAfeeÔ¤²â³Æ2020ÄêÍøÂç·¸×ï·Ö×Ó½«ÔÚÕë¶ÔÐÔÀÕË÷Èí¼þ¹¥»÷ÖÐÔ½À´Ô½¶àµØÇÔÈ¡¹«Ë¾Êý¾Ý£¬ÒÔͨ¹ýÔÚÏßÏúÊÛ»òÀÕË÷Êܺ¦ÕßÀ´Ôö³¤»ñÀû  ¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/nemty-ransomware-to-start-leaking-non-paying-victims-data/


5.FaketokenÀûÓÃÊÜϰȾÉ豸·¢Ëͺ£±í¶ÌÐÅ£¬ÒÑϰȾ5000¶àÓû§


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¿¨°Í˹»ù×êÑÐÈËÔ±½üÆÚ¹Û²ìµ½AndroidÒøÐÐľÂíFaketokenÒÑϰȾÁ˳¬¹ý5000̨É豸  ¡£Faketoken×îÔç³öÏÖÓÚ2014Ä꣬´Ë¿Ì¸ÃľÂíÒÑÑÝÔì³É³ÉÊìµÄÒøÐÐľÂí  ¡£ÒøÐÐľÂíͨ³£½«×Ô¼º¼Ù×°³ÉĬÈϵÄSMSÀûÓã¬ÒÔÀ¹½ØÓû§µÄÑéÖ¤Â룬µ«FaketokenÈ´ÀûÓÃÓû§µÄÉ豸À´Ïò¹ú±íºÅÂë·¢ËͶÌÐÅ£¬²¢ÇÒÆäÓöÈÓÉÓû§Ö§¸¶  ¡£ÔÚ·¢ËÍÈκÎÐÂÎÅ֮ǰ£¬Faketoken»¹»áÈ·ÈÏÊܺ¦ÕßµÄÒøÐÐÕÊ»§ÖÐÓÐ×ã¹»µÄ×ʽð£¬ÈôÊǸÃÕË»§ÖÐÓÐÏÖ½ð£¬ÔòFaketoken»áÔÚ³ÖÐø·¢ËÍ֮ǰÀûÓøÃÕË»§ÎªÊÖ»úºÅÂë³äÖµ  ¡£Ä¿Ç°×êÑÐÈËÔ±»¹²»ÄÜÈ·ÈÏÕâÊÇÒ»´ÎÐԵĹ¥»÷»î¶¯»¹ÊÇÒ»ÖÖ¹¥»÷Ç÷ÏòµÄÆðÍ·  ¡£


 Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/this-trojan-hijacks-your-smartphone-to-send-offensive-text-messages/


6.΢Èí°ä²¼2020Äê1Ô°²È«¸üУ¬½¨¸´49¸ö·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚ2020Äê1Ô°²È«¸üÐÂÖÐ΢Èí°ä²¼ÁË49¸ö·ì϶µÄ½¨¸´²¹¶¡£¬ÆäÖÐ7¸ö·ì϶±»¹éÀàΪÑϳÁ¼¶±ð£¬41¸öΪ³ÁÒª£¬1¸öΪÖÐµÈ  ¡£Î¢Èí½¨¸´ÁËÊ׸öÃÀ¹úNSA¹«¿ª·¢ÏÖµÄWindows·ì϶£¬¸Ã·ì϶£¨CVE-2020-0601£©ÎªWindows CryptoAPIºýŪ·ì϶£¬ÊÇWindows CryptoAPI£¨Crypt32.dll£©ÔÚÑéÖ¤ÍÖÔ²ÇúÏß¼ÓÃÜËã·¨£¨ECC£©Ö¤Êé¹ý³ÌÖеķì϶£¬¹¥»÷Õß¿ÉÄÜÀûÓø÷ì϶αÔìÊý×ÖÖ¤Êé»òÌáÒéÖÐÑëÈ˹¥»÷£¬ÊÜÓ°ÏìµÄϵͳÔ̺¬Windows 10¡¢Windows Server 2016ºÍWindows Server 2019  ¡£´Ë±í£¬Î¢Èí»¹½¨¸´ÁËWindowsÔ¶³Ì×ÀÃæÍø¹ØÖеÄÈý¸ö·ì϶£¬Ô̺¬Á½¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-0609ºÍCVE-2020-0610£©ºÍÒ»¸öDoS·ì϶£¨CVE-2020-0612£©  ¡£¸ü¶à·ì϶ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó  ¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/microsofts-january-2020-patch-tuesday-fixes-49-vulnerabilities/