Zoom macOS¿Í»§¶ËÁ½¸ö0day£»Î¢ÈíÖÒ¸æÕë¶ÔÒ½ÔºVPNºÍÍø¹ØÉ豸µÄÀÕË÷Èí¼þ¹¥»÷

°ä²¼¹¦·ò 2020-04-03

1.΢ÈíÖÒ¸æÕë¶ÔÒ½ÔºVPNºÍÍø¹ØÉ豸µÄÀÕË÷Èí¼þ¹¥»÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


΢ÈíÏòÊýÊ®¼ÒÒ½Ôº·¢ËÍÓйØÀÕË÷Èí¼þÕë¶ÔÐÔ¹¥»÷µÄÖҸ档ƾ¾ÝÆä¶ÔÀÕË÷Èí¼þ¹¥»÷»î¶¯µÄ¸ú×Ù£¬Î¢Èí¹Û²ìµ½ÀÕË÷Èí¼þREvil£¨Sodinokibi£©ÖØÒªÕë¶ÔVPNÉ豸ºÍÍø¹ØÉ豸Öеķì϶£¬ÀýÈçPulse VPNÉ豸¡£Î¢Èí·¢ÏÖÕâЩҽԺµÄ»ù´¡ÉèÊ©´æÔÚÒ×Êܹ¥»÷µÄÍø¹ØºÍVPNÉ豸£¬ÆäÖкܶàÒ½Ôº³ä³â²¡»¼¡£Í¨¹ýÕâЩÕë¶ÔÐÔ¹¥»÷¾¯±¨£¬Ò½ÁƱ£½¡×éÖ¯Äܹ»ÔÚÃæÏò¹«¼ÒµÄÉ豸ÉÏ×Ô¶¯×°Öð²È«¸üУ¬ÒÔ×èÖ¹¹¥»÷ÕßµÄDZÔÚÍþв¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-is-alerting-hospitals-vulnerable-to-ransomware-attacks/


2.Magecart Group 7×îй¥»÷»î¶¯Ï°È¾19¸öÍøÕ¾


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


RiskIQ×êÑÐÈËÔ±·¢ÏÖÒ»¸öеÄMagecart¹¥»÷»î¶¯£¬¸Ã»î¶¯ÒѾ­Ï°È¾ÁË19¸ö·ÖÆçµÄµç×ÓÉÌÎñÍøÕ¾¡£¸ÃƲÔüÆ÷¾ç±¾³õ´Î±»·¢ÏÖÓÚ1ÔÂ24ÈÕ£¬ÓÉÓÚÆäÀûÓÃÁËiframeÀ´ÍøÂçÓû§µÄÖ§¸¶Êý¾Ý£¬×êÑÐÈËÔ±½«Æä¶¨ÃûΪMakeFrame¡£ÔÚijЩÇé¿öÏ£¬×êÑÐÈËÔ±¹Û²ìµ½MakeFrameµÄËùÓÐÈý¸öÖ°Äܶ¼ÀûÓÃÁËÊÜϰȾµÄÕ¾µã - ÍÐ¹ÜÆ²ÔüÆ÷´úÂë×ÔÉí¡¢½«Æ²ÔüÆ÷¼ÓÔØµ½ÆäËûÊÜϰȾµÄÍøÕ¾ÉÏÒÔ¼°ÇÔÈ¡Êý¾Ý¡£Í¨¹ý¶ÔÆä´úÂë½øÐзÖÎö£¬×êÑÐÈËÔ±½«¸Ã¶ñÒâ»î¶¯¹éÒòÓÚMagecart Group 7¡£


Ô­ÎÄÁ´½Ó£º

https://www.riskiq.com/blog/labs/magecart-makeframe/


3.BitdefenderÅû¶Õë¶Ô°Ä´óÀûÑǵļäµýÈí¼þMandrake


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


BitdefenderÅû¶Õë¶Ô°Ä´óÀûÑÇAndroidÓû§µÄ¼äµýÈí¼þMandrake£¬¸Ã¶ñÒâ»î¶¯ÖÁÉÙÒѾ­»îÔ¾ÁË4Äê¡£Mandrake¿ÉÕë¶ÔGoogle Chrome¡¢Gmail¡¢°Ä´óÀûÑǰÄÐÂÒøÐÓ×¢°Ä´óÀûÑÇÁª¹úÒøÐÓעī¶û±¾ÒøÐÓ×¢SAÒøÐÓ×¢Australian SuperºÍPayPalÀûÓá£Í¨¹ý¶ÈÎöÔÚÁ½¸öÔÂÄÚ²¶»ñµÄÊý¾Ý£¬×êÑÐÍŶӷ¢ÏÖÁË500¸ö°Ä´óÀûÑÇÊܺ¦Õߣ¬ÏÖʵÊý×Ö¿ÉÄܸü¸ß¡£MandrakeµÄµÚÒ»¸öÑù±¾¿É×·Òäµ½2016Äê1ÔÂ31ÈÕ£¬¹¥»÷ÕßÄܹ»ÀûÓøöñÒâÈí¼þ½Ó¼ûÊ×Ñ¡Ïî¡¢ÆÁÄ»¼Í¼¡¢É豸ʹÓÃÇé¿öºÍ²»»î¶¯¹¦·òµÈÐÅÏ¢£¬»¹Äܹ»µ÷µÍµç»°ÒôÁ¿²¢×èֹͨ»°»ò¶ÌÐÅ£¬ÒÔ¼°½øÐÐÍ´´¦ÇÔÈ¡¡¢ÐÅϢй¶¡¢»ã¿îºÍÀÕË÷µÈ¶ñÒâ»î¶¯¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/bitdefender-reveals-mandrake-spyware-targeting-aussie-android-users/


4.ÐÂCOVID-19¶ñÒâÈí¼þ¿É¸²¸ÇµçÄÔÖ÷Êèµ¼¼Í¼


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



Ëæ×ÅCOVID-19ÔÚÈ«ÇòÁìÓòÄÚËÁŰ£¬Ò»Ð©¶ñÒâÈí¼þ×÷ÕßÒѾ­¿ª·¢³öÁËͨ¹ý²Á³ýÎļþ»ò¸²¸ÇMBRÀ´·ÛËéϵͳµÄ¶ñÒâÈí¼þ¡£ÔÚÐÅÏ¢°²È«ÉçÇøµÄÔ®ÊÖÏ£¬ZDNetÒѾ­¼ø±ð³öÖÁÉÙÎåÖÖ¶ñÒâÈí¼þ¾úÖ꣬ÆäÖв¿ÃÅÊÇÔÚÒ°±í·¢Ïֵģ¬ÁíһЩ¿ÉÄÜÖ»ÊÇΪÁ˲âÊÔ»òÍæÐ¦µÄÖ÷ÕÅ¡£MalwareHunterTeam·¢ÏÖÁ˵ÚÒ»¸öMBR³ÁдÆ÷£¬ÆäÃû³ÆÎªCOVID-19.exe£¬SonicWallÔÚÒ»·Ý»ã±¨ÖÐ¶ÔÆä½øÐÐÁ˾ßÌå½éÉÜ¡£ÁíÒ»¸öÒÔ¹Ú×´²¡¶¾ÎªÖ÷ÌâµÄ¶ñÒâÈí¼þ¼ÙÒâ¡°CoronaVirusÀÕË÷Èí¼þ¡±£¬µ«ËüµÄÖØÒªÖ°ÄÜÏÖʵÉÏÊÇ´ÓÊÜϰȾµÄÖ÷»úÇÔÈ¡ÃÜÂë¡£°²È«×êÑÐÔ±Karsten Hahn»¹·¢ÏÖÁ˸öñÒâÈí¼þµÄÁíÒ»¸ö°æ±¾£¬ËüÒÀÈ»Äܹ»¸²¸ÇMBR£¬µ«ÀûÓÃÆÁÄ»Ëø¶¨·¨Ê½°ü°ìÁËÊý¾Ý²Á³ýÖ°ÄÜ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/theres-now-covid-19-malware-that-will-wipe-your-pc-and-rewrite-your-mbr/


5.Zoom macOS¿Í»§¶ËÁ½¸ö0day¿Éµ¼ÖÂÌáÉýȨÏÞ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


×êÑÐÈËÔ±ÔÚZoomµÄmacOS¿Í»§¶ËÖз¢ÏÖÁ½¸ö0day£¬·ì϶¿ÉÄÜÔÊÐí±¾µØ¡¢ÎÞÌØÈ¨¹¥»÷Õß»ñµÃrootÌØÈ¨£¬²¢ÔÊÐíËûÃǽӼûÊܺ¦ÕßµÄÂó¿Ë·çºÍÉãÏñÍ·¡£JamfÊ×ϯ°²È«×êÑÐÔ±Patrick Wardle·¢ÏÖÁËÕâÁ½¸ö·ì϶£¬µÚÒ»¸ö·ì϶ԴÓÚZoom×°Ö÷¨Ê½Ê¹ÓÃAuthorizationExecuteWithPrivileges APIÔÚÎÞÓû§½»»¥µÄÇé¿öϽøÐÐ×°Ö㬵«¸ÃAPIÓÉÓÚûÓÐÑéÖ¤ÔÚ¸ùĿ¼ÏÂÖ´ÐеĶþ½øÔìÎļþ£¬ÏÖʵÉÏÒѾ­±»AppleÆúÓᣱ¾µØÎÞÌØÈ¨µÄ¹¥»÷Õß»ò¶ñÒâÈí¼þ¿ÉÄÜÀûÓø÷ì϶ÌáȨÖÁroot¡£µÚ¶þ¸ö·ì϶ÓëZoomÔÊÐíµÚÈý·½¿â×¢Èë´úÂëÓйØ£¬¹¥»÷Õ߿ɽ«¶ñÒâµÄµÚÈý·½¿â¼ÓÔØµ½ZoomµÄ¹ý³Ì/µØÖ·¿Õ¼äÖУ¬´Ó¶ø×Ô¶¯¼Ì³ÐËùÓÐZooms½Ó¼ûȨÏÞ²¢×îÖÕ»ñµÃÉãÏñÍ·ºÍÂó¿Ë·çµÄ½ÚÔìȨÏÞ¡£½ØÖÁÖÜËÄZoom°µÊ¾ÒѾ­½¨¸´ÁËÕâÁ½¸ö·ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/two-zoom-zero-day-flaws-uncovered/154337/


6.OGUsersÂÛ̳Ôٴα»ÈëÇÖ£¬³¬¹ý20ÍòÓû§ÐÅϢй¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ºÚ¿ÍÂÛ̳OGUsersÔÚÒ»ÄêÄÚµÚ¶þ´ÎÔâµ½ºÚ¿ÍÈëÇÖ¡£ÂÛ̳ÖÎÀíÔ±Ace°µÊ¾£¬¹¥»÷Õßͨ¹ýÉÏ´«ÖÁÂÛ̳ͷÏñÖеÄshellÈëÇÖÁËÂÛ̳·þÎñÆ÷£¬²¢ÇÒ¿ÉÄܽӼû½ØÖÁ2020Äê4ÔÂ2ÈÕµÄÊý¾Ý¿â¡£¾Ý³Æ³¬¹ý20ÍòÓû§µÄÐÅÏ¢±»ÇÔ¡£ÔڹعظÃÍøÕ¾Ö®Ç°£¬ÖÎÀíÔ±°µÊ¾ËûÃÇÒѾ­³ÁÉèÁËÃÜÂë²¢¶½´ÙÓû§¶ÔÆäÕË»§ÆôÓÃ2FAÈÏÖ¤¡£¸ÃÂÛÌ³ÔøÓÚ2019Äê5ÔÂÔâµ½ºÚ¿ÍÈëÇÖ£¬Æäʱ¹¥»÷ÕßÇÔÈ¡ÁË11.3ÍòÓû§µÄÐÅÏ¢²¢ÇÒ²Á³ýÁËÂÛ̳µÄÓ²ÅÌ¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hacking-forum-gets-hacked-for-the-second-time-in-a-year/