ºÚ¿ÍÔÚ°µÍøÐ¹Â¶³¬¹ý50Íǫ̀É豸µÄTelnetÍ´´¦£»Citrix°ä²¼´úÂëÖ´Ðзì϶CVE-2019-19781µÄ½¨¸´²¹¶¡
°ä²¼¹¦·ò 2020-01-20
1.ºÚ¿ÍÔÚ°µÍøÐ¹Â¶³¬¹ý50Íǫ̀É豸µÄTelnetÍ´´¦
ºÚ¿ÍÔÚÒ»¸ö°µÍøÂÛ̳ÉÏй¶Á˳¬¹ý51.5Íǫ̀·þÎñÆ÷¡¢¼ÒÓ÷ÓÉÆ÷ºÍIoTÉ豸µÄTelnetÍ´´¦ÁÐ±í£¬ÁбíÖÐÔ̺¬Ã¿¸öÉ豸µÄIPµØÖ·ÒÔ¼°ÆäTelnet·þÎñµÄÓû§ÃûºÍÃÜÂë¡£ÕâÊÇÆù½ñΪֹÒÑÖªµÄ×î´óTelnetÃÜÂëй©¡£¾ÝZDNetÏàʶ£¬¸ÃÁбíÊÇÓÉDDoS³ö×â·þÎñµÄÔËÓªÕßÔÚÏß°ä²¼µÄ£¬¹¥»÷Õßͨ¹ýɨÃèÕû¸öInternetÀ´²éÕÒTelnet¶Ë¿Ú¶³öµÄÉ豸£¬²¢ÇÒ³¢ÊÔʹÓã¨1£©³ö³§ÉèÖõÄĬÈÏÓû§ÃûºÍÃÜÂë»ò£¨2£©×Ô½ç˵µ«Ò×Óڲ²âµÄÃÜÂë×éºÏ½øÐб¬ÆÆ¼ÙÔìÁ˸ÃÁÐ±í¡£ÁбíÖÐËùÓÐÌõ¿î±êÈÕÆÚΪ2019Äê10ÔÂÖÁ11Ô£¬ÆäÖÐһЩÉ豸¿ÉÄÜÒѾ¸ü»»ÁËIPµØÖ·»òÍ´´¦¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/hacker-leaks-passwords-for-more-than-500000-servers-routers-and-iot-devices/
2.ÎÚ¿ËÀ¼µ±¾Ö¹¤×÷ÃÅ»§ÍøÕ¾Ð¹Â¶²¿ÃŹ«ÃñµÄÓ×ÎÒÊý¾Ý
¾Ý·͸É籨·£¬ÎÚ¿ËÀ¼¹ú¶È×î¸ß°²È«»ú¹¹ÉÏÖÜÎåÈϿɲ¿ÃŹ«ÃñµÄÓ×ÎÒÊý¾ÝÔÚµ±¾Ö¹¤×÷ÃÅ»§ÍøÕ¾ÖÐй¶¡£¹ú¶È°²È«ºÍ¹ú·ÀίԱ»áûÓÐ֤ʵй©ÊÇ·ñÊÇÍøÂç¹¥»÷µÄÁ˾֣¬Ò²Ã»ÓÐй©Óм¸¶àÊý¾ÝÊܵ½Ó°ÏìºÍÊÂÎñÓÉËÕÆ¹Ü£¬µ«°µÊ¾ÒѾ¡°È·¶¨ÁË·ì϶¡±²¢ÇÒÃÅ»§ÍøÕ¾ÒѾµÃµ½±£»¤¡£Ä¿Ç°ÉÐÎÞ¸ü¶àϸ½ÚÅû¶¡£
ÔÎÄÁ´½Ó£º
https://in.reuters.com/article/ukraine-cyber-leak/ukraine-says-personal-data-leaked-from-government-jobs-portal-idINKBN1ZG1OP
3.Õë¶Ô±±´ï¿ÆËûÖݵ±¾ÖµÄÍøÂç¹¥»÷¼¤ÔöÖÁÿÔÂ1500Íò´Î
¾Ý¡¶Grand Forks Herald¡·±¨Â·£¬2019ÄêÕë¶Ô±±´ï¿ÆËûÖݵ±¾ÖµÄÍøÂç¹¥»÷³¢ÊÔÏÕЩ·ÁËÈý±¶¡£±±´ï¿ÆËûÖÝÊ×ϯÐÅÏ¢¹Ù¼æÐÅÏ¢¼¼Êõ²¿ÃÅÕÆ¹ÜÈËФ¶÷¡¤À·û£¨Shawn Riley£©°µÊ¾£¬2019ÄêÿÔÂÓг¬¹ý1500Íò´ÎÕë¶Ô¸ÃÖݵ±¾ÖµÄÍøÂç¹¥»÷£¬×Ô2018ÄêÒÔÀ´Ôö³¤ÁË300£¥¡£ÔÚ2018Ä꣬ÿÔÂÔ¼ÓÐ500Íò´ÎδËìµÄÍøÂç¹¥»÷¡£È«¹ú¸÷µØµÄ´¦Ëùµ±¾Ö¶¼·¢ÏÖÍøÂç¹¥»÷ÓÐËùÔö³¤£¬µ«±±´ï¿ÆËûÖݵÄÇ÷ÏòÒª±ÈÆäËü×éÖ¯ÑϳÁһЩ£¬×ÜÌå¶øÑÔ£¬Ôö³¤Ï൱¿É¹Û¡£
ÔÎÄÁ´½Ó£º
https://thehill.com/policy/cybersecurity/478936-cyber-attacks-against-north-dakota-state-government-skyrocket-to-15m-a
4.µç×ÓÉÌÎñƽ̨Zen Cart×¢Èë¹¥»÷£¬ÇÔÈ¡PayPalÕÊ»§ÃÜÂë
°²È«×êÑÐÔ±Christopher Morrow½üÈÕ·¢ÏÖÕë¶Ô¿ªÔ´µç×ÓÉÌÎñƽ̨Zen CartµÄ×¢Èë¹¥»÷£¬¹¥»÷ÕßÖØÒªÇÔÈ¡Óû§µÄPayPalÕË»§ºÍÃÜÂë¡£Zen Cart×ÔÉíÊǾɰæOsCommerceµÄ·ÖÖ§£¬¸Ãƽ̨ºÜÉÙÔâµ½ÐÅÓþ¿¨Æ²ÔüÆ÷µÄ¹¥»÷£¬ÓÉÓÚÆ¾¾ÝW3µÄ×îÐÂÊý¾Ý£¬Ïà±ÈMagento£¨0.8£¥£©»òPrestashop£¨0.6£¥£©µÈÆäËû¿ªÔ´Æ½Ì¨£¬Zen CartµÄÓû§ÈººÜС£¨0.1£¥£©¡£×êÑÐÈËÔ±·¢ÏֵĶñÒâ´úÂë×¢Èëµ½Zen CartµÄPHPÎļþÖУ¬ËüרÃÅÕë¶ÔPayPal Payments Pro¸¶¿îÄ£¿é£¬²¶»ñÓû§µÄÓ×ÎÒÉí·ÝÐÅÏ¢£¨PII£©ºÍÖ§¸¶¿¨¾ßÌåÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://blog.sucuri.net/2020/01/zen-cart-paypal-skimmer.html
5.×êÑÐÍŶӰ䲼Êý¾Ý²Á³ýÆ÷DustmanµÄ·ÖÎö»ã±¨
2019Äê12Ô£¬IBM X-ForceÍŶӰ䲼ÁËÓйØÕë¶ÔÖж«µØÓòµÄ·ÛËéÐÔ¹¥»÷ÖеÄÊý¾Ý²Á³ý¶ñÒâÈí¼þZeroCleareµÄ·ÖÎö»ã±¨£¬Ô¼Ò»¸öÔºóÉ³ÌØ¹ú¶ÈÍøÂ簲ȫ¾Ö£¨NCA£©»ã±¨ÁËÕë¶ÔͳһµØÓòµÄZeroCleare±äÌ壬¸Ã±äÌå±»³ÆÎªDustman¡£DustmanµÄ×é¼þÓëZeroCleareʹÓõÄ×é¼þÀàËÆ£¬ÕâÔ̺¬Æä´úÂë¿âºÍ¶ÔTurlaÇý¶¯·¨Ê½µÄʹÓã¬ÒÔ¼°ÓÃÓÚ²Á³ýÊÜϰȾ»úе´ÅÅ̵ÄEldoS RawDiskÇý¶¯·¨Ê½ºÍÒ»ÑùµÄEldoSÈí¼þÐí¿ÉÖ¤ÃÜÔ¿¡£ZeroCleareºÍDustmanÖ®¼äµÄÇø±ðÔÚÓÚÎļþÃûºÍ²¿ÊðÁ÷³ÌµÄ΢Óױ䶯¡£
ÔÎÄÁ´½Ó£º
https://securityintelligence.com/posts/enter-dustman-new-wiper-takes-after-zerocleare-targets-organizations-in-saudi-arabia/
6.Citrix°ä²¼´úÂëÖ´Ðзì϶CVE-2019-19781µÄ½¨¸´²¹¶¡
CitrixÕë¶ÔÒѱ»»ý¼«ÀûÓõÄCVE-2019-19781·ì϶°ä²¼ÓÀÔ¶½¨¸´²¹¶¡£¬¸Ã·ì϶ӰÏìÁËCitrix Application Delivery Controller£¨ADC£©¡¢CitrixÍø¹ØºÍCitrix SD-WAN WANOPÉ豸£¬²¢ÇÒÔÊÐíδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÖ´ÐÐËÁÒâ´úÂë¡£CitrixÒѾ°ä²¼ÁËADC°æ±¾11.1ºÍ12.0µÄÓÀÔ¶½¨¸´·¨Ê½£¬ÕâЩ²¹¶¡»¹ºÏÓÃÓÚÍйÜÔÚESX¡¢Hyper-V¡¢KVM¡¢XenServer¡¢Azure¡¢AWS¡¢GCP»òCitrix ADC·þÎñ½»¸¶É豸£¨SDX£©ÉϵÄCitrix ADCºÍCitrix GatewayÐé¹¹É豸£¨VPX£©¡£SDXÉϵÄSVM²»±ØÒª¸üС£³ý´ËÖ®±í£¬Citrix»¹¼Ó¿ìÁ˽«¸Ã²¹¶¡ÍÆË͵½ÆäËüADC°æ±¾ºÍSD-WAN WANOPµÄ¹ý³Ì£¬ÐµĹ̼þ½«ÔÚ1ÔÂ24ÈÕ°ä²¼¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/citrix-patches-cve-2019-19781-flaw-in-citrix-adc-111-and-120/


¾©¹«Íø°²±¸11010802024551ºÅ