Palo Alto Networks°ä²¼2020Äê´º¼¾ÔÆÍþв»ã±¨£»ÒÔÉ«ÁÐÕþµ³Ñ¡¾ÙÀûÓÃй¶³¬¹ý640Íò¹«ÃñÊý¾Ý

°ä²¼¹¦·ò 2020-02-10

1.Palo Alto Networks°ä²¼2020Äê´º¼¾ÔÆÍþв»ã±¨


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Palo Alto NetworksµÄUnit 42½üÈÕ°ä²¼Á˰ëÄêÒ»´ÎµÄ¡¶ÔÆÍþв»ã±¨¡·2020Äê´º¼¾°æ¡£ÎªÁËÔÚÔÆÖÐÔ½À´Ô½¶àµØ×Ô¶¯»¯¹¹½¨Á÷³Ì£¬ºÜ¶à×éÖ¯¶¼ÔÚѡȡ»ù´¡¼Ü¹¹¼´´úÂ루IaC£©À´Ô®ÊÖ¼ò»¯ÆäÔËÓª¡£Unit 42·ÖÎöÁ˳ÉǧÉÏÍò¸öIaCÄ£°å£¬ËûÃǵķ¢ÏÖÅú×¢IaCÄ£°åÖÐÓÐ199000¶à¸öDZÔÚ·ì϶£¬×î³ÁÒªµÄÊÇĿǰÓг¬¹ý43£¥µÄÔÆÊý¾Ý¿âδ¼ÓÃÜ£¬²¢ÇÒÖ»ÓÐ60£¥µÄÔÆ´æ´¢·þÎñÒÑÆôÓÃÈÕÖ¾¼Í¼¡£


Ô­ÎÄÁ´½Ó£º

https://start.paloaltonetworks.com/unit-42-cloud-threat-report


2.Êý¾ÝÅú×¢2019ÄêÓÐ4000ÍòÃÀ¹úÈ˵ÄÒ½ÁÆÊý¾Ýй¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝFortified Health SecurityµÄ¡¶2020ÄêÒ½ÁƱ£½¡ÍøÂ簲ȫÇé¿ö»ã±¨¡·£¬2019ÄêÓÐ4000ÍòÃÀ¹úÈËÊܵ½Ò½ÁÆÊý¾Ýй¶µÄÓ°Ïì¨CÓë2018ÄêµÄ1400ÍòÏà±ÈÔö³¤ÁË65£¥¡£¸Ã»ã±¨»ã×ÜÁË2009ÄêÖÁ2019ÄêµÄÄê¶ÈÊý¾Ý£¬·¢ÏÖ2019ÄêÊÇ×Ô2015ÄêÒÔÀ´µÄ×î¸ß¼Í¼¡£¸Ã»ã±¨³ÆÓÐ400¶à¸öÒ½ÁÆ»ú¹¹ÓÐÊ·ÒÔÀ´µÚÒ»´Î»ã±¨ÔÚÒ»ÄêÄÚй¶ÁË500¸ö»¼ÕßÒÔÉϵÄÒ½ÁƼͼ¡£»ã±¨Ö¸³öÖ»¹ÜºÜ¶àÆóÒµ×ö³öÁ˳ÖÐøµÄÖÂÁ¦ÒÔ½øÐиĽø£¬µ«ÓÉÓÚÔ¤ËãÓÐÏÞ¡¢ÈËÁ¦×ÊÔ´²»¼°ºÍ¾¯±¨¹ý¶àµÄÌôÕ½£¬ËûÃÇÒÀÈ»ÄÑÒÔÔÚÍøÂç·¸×ï·Ö×Ó¿ÌÏÂά³Öµ±ÏÈְλ¡£


Ô­ÎÄÁ´½Ó£º

https://www.securitymagazine.com/articles/91679-million-americans-affected-by-health-data-breaches-in-2019


3.Wacom»­Í¼°å±»·¢ÏÖ¸ú×ÙÓû§´ò¿ªµÄÀûÓÃÐÅÏ¢


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Èí¼þ¹¤³ÌʦÂÞ²®ÌØ¡¤Ï£¶Ù£¨Robert Heaton£©·¢ÏÖWacom»­Í¼°å¸ú×ÙÓû§´ò¿ªµÄÿһ¸öÀûÓ÷¨Ê½£¬ÒɼӺ¦Óû§ÒþÖÔ¡£WacomµÄ¹Ù·½Çý¶¯·¨Ê½ÒþÖÔÕ½Êõ½ÏΪÍÌÍ£¬ÈôÊÇÓû§½ÓÊܸÃÕ½Êõ£¬Ëü½«ÆðÍ·¸ú×ÙÓû§ÔÚÆäÉ豸ÉÏ´ò¿ªµÄÀûÓ÷¨Ê½¡£Æ¾¾ÝHeatonµÄµ÷²é£¬Ëùº±¼û¾Ý¶¼ÊÇʹÓÃGoogle Analytics£¨·ÖÎö£©ÕÊ»§ÍøÂçµÄ¡£ºÃÐÂÎÅÊǸÃÒþÖÔÕ½Êõ²»ÊÇÇ¿ÔìÐԵģ¬WacomÓû§Äܹ»»Ø¾ø½ÓÊܸÃÕ½Êõ£¬²¢ÇÒÇý¶¯·¨Ê½ÈÔ»á×°Öá£´Ë±í£¬ÒѾ­×°ÖÃÁËÇý¶¯·¨Ê½µÄÓû§Äܹ»ËæÊ±Ñ¡ÔñÍ˳ö¸ÃÕ½Êõ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/wacom-drawing-tablets-track-every-app-you-open/


4.AnubisľÂíÕë¶Ô250¶à¸öAndroidÀûÓ㬿ɽٳÖÓû§É豸


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Cofense×êÑÐÈËÔ±Marcel Feller·¢ÏÖÒ»¸öеĴ¹µö¹¥»÷»î¶¯£¬¹¥»÷ÕßÖØÒª·Ö·¢ÒøÐÐľÂíAnubis£¬¸Ã¶ñÒâÈí¼þÄܹ»ÆëÈ«½Ù³ÖAndroidÒÆ¶¯É豸ÒÔÇÔÈ¡Óû§Í´´¦¡¢×°ÖüüÅ̼ͼ·¨Ê½ÉõÖÁ±£ÁôÉ豸Êý¾ÝÒÔÀÕË÷Êê½ð¡£×êÑÐÈËÔ±°µÊ¾¸Ã¶ñÒâÈí¼þÕë¶Ô250¶à¸öAndroidÀûÓ÷¨Ê½£¬Ô̺¬ÓµÓж¨ÔìµÄµÇ¼¸²¸ÇÆÁÄ»£¨ÓÃÓÚ²¶»ñÊäÈëµ½ÀûÓ÷¨Ê½ÖеÄÍ´´¦£©¡£¶ñÒâÈí¼þÖØÒªÍ¨¹ýµäÐ͵Ĵ¹µöÓʼþ·Ö·¢£¬ÓʼþÖÐÒªÇóÓû§ÏÂÔØ·¢Æ±£¬µ«ÏÖʵÉÏ»áÏÂÔØÒ»¸öAPKÎļþ£¨Fattura002873.apk£©£¬¸ÃÎļþ»áÏÔʾÐéαµÄGoogle Play Protect£¬ÎªÀûÓ÷¨Ê½ÌṩËùÐèµÄËùÓÐȨÏÞͬʱ½ûÓÃÁËÏÖʵµÄGoogle Play ProtectÖ°ÄÜ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/phishing-campaign-targets-250-android-apps-with-anubis-malware/152666/


5.EmotetÈ䳿ÈëÇÖ×ó½üµÄWi-FiÍøÂçÒÔ´«²¼¸øÐµÄÊܺ¦Õß


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Binary DefenseµÄ×êÑÐÈËÔ±³Æ£¬×î½ü·¢ÏÖµÄEmotet±äÖÖÓµÓÐÒ»¸öWi-FiÈ䳿Ä£¿é£¬¸ÃÄ£¿éÔÊÐíEmotetÈëÇÖ×ó½üµÄWi-FiÍøÂçÒÔ´«²¼¸øÐÂÊܺ¦Õß¡£¸Ã±äÖÖͨ¹ýʹÓÃwlanAPI.dllŲÓÃÀ´·¢ÏÖÒÑÏ°È¾ÍÆËã»úÖÜΧµÄÎÞÏßÍøÂ磬²¢³¢ÊÔͨ¹ý±©Á¦ÆÆ½â·½Ê½ÈëÇÖ¡£Ò»µ©³É¹¦Ïνӵ½ÁíÒ»¸öÎÞÏßÍøÂ磬¸ÃÈ䳿½«ÆðÍ·²éÕÒÓµÓзǰµ²Ø¹²ÏíÎļþ¼ÐµÄÆäËûWindowsÉ豸£¬½ÓÏÂÀ´Ëü½«É¨ÃèÕâЩÉ豸ÉϵÄËùÓÐÕÊ»§£¬²¢³¢ÊÔÕë¶ÔÖÎÀíÔ¹ØÊ»§ºÍËùÓÐÆäËüÓû§ÕË»§½øÐб©Á¦¹¥»÷£¬³É¹¦ºóÒÔservice.exe¶þ½øÔìÎļþµÄ´ó¾Ö½«¶ñÒâpayload¿ªÊ͵½Êܺ¦ÕßµÄÍÆËã»úÉÏ£¬²¢×°ÖÃÃûΪ¡°Windows Defenderϵͳ·þÎñ¡±µÄзþÎñÒÔÔÚϵͳÉÏά³ÖÓÆ¾ÃÐÔ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/emotet-hacks-nearby-wi-fi-networks-to-spread-to-new-victims/


6.ÒÔÉ«ÁÐÕþµ³Ñ¡¾ÙÀûÓÃй¶³¬¹ý640Íò¹«ÃñÊý¾Ý


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


×êÑÐÈËÔ±·¢ÏÖElector SoftwareΪÒÔÉ«ÁÐÕþµ³Likud¿ª·¢µÄÑ¡¾ÙÀûÓÃElector´æÔÚAPIÅäÖÃÃýÎ󣬵¼Ö³¬¹ý640Íò¹«ÃñÊý¾Ýй¶¡£LikudÊÇÓɸùúÏÖÈÎ×ÜÀí±¾½ÜÃ÷¡¤ÄÚËþÄáÑǺú£¨Benjamin Netanyahu£©¸¨µ¼µÄÕþµ³¡£¸ÃÊÂÎñÊÇÓÉ×êÑÐÈËÔ±Ran Bar-Zik¶ÔElector½øÐÐÉó¼ÆÊ±·¢Ïֵģ¬Ä¿Ç°Éв»Ã÷ÏÔ¶³öµÄ·þÎñÆ÷ºÍÊý¾ÝÊÇ·ñÒѱ»Î´ÊÚȨ½Ó¼û¡£Bar-Zik°µÊ¾¸ÃÍøÕ¾µÄ¿ª·¢ÈËÔ±½«API¶³öÔÚÍøÉÏ£¬²¢ÇÒûÓÐÃÜÂë±£»¤£¬Ê¹µÃÈκÎÈ˶¼Äܹ»²éÎÊÊý¾Ý¿âÖеĹ«ÃñÊý¾Ý£¬Ô̺¬ÐÕÃû¡¢µç»°ºÅÂë¡¢Éí·ÝÖ¤ºÅÂë¡¢¼Òͥסַ¡¢ÐԱ𡢴ºÇïºÍÕþÖÎÆ«ºÃµÈÐÅÏ¢£¬¸ÃAPI»¹Äܹ»·µ»ØÕ¾µãÖÎÀíÔ±µÄ¾ßÌåÐÅÏ¢£¬Ô̺¬Ã÷ÎÄÃÜÂë¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/netanyahus-party-exposes-data-on-over-6-4-million-israelis/