΢Èí°ä²¼´¹Î£¸üУ¬½¨¸´OfficeºÍPaint 3DÖжà¸ö·ì϶£»ÃÀ¹úSBA¹ÙÍø´æÔÚ·ì϶й¶8000¼ÒÆóÒµµÄÃô¸ÐÐÅÏ¢
°ä²¼¹¦·ò 2020-04-241.΢Èí°ä²¼´¹Î£¸üУ¬½¨¸´OfficeºÍPaint 3DÖжà¸ö·ì϶
Microsoft°ä²¼ÁË´¹Î£°²È«¸üУ¬ÒÔ½¨¸´Ê¹ÓÃÁËAutodesk FBX¿âµÄMicrosoft²úÆ·£¬Ô̺¬¶à¸ö°æ±¾µÄMicrosoft OfficeºÍWindows 10ÀûÓ÷¨Ê½Paint 3D¡£±¾´Î½¨¸´µÄ·ì϶ΪFBX¿âÖеÄÔ¶³ÌÖ´ÐдúÂë·ì϶£¬¹¥»÷ÕßÀûÓô˷ì϶Äܹ»»ñµÃÓë±¾µØÓû§Ò»ÑùµÄȨÏÞ£¬AutodeskÔÚ4ÔÂ15ÈÕÍÆ³öÁËÕë¶Ô´Ë·ì϶µÄ²¹¶¡·¨Ê½¡£Microsoft°µÊ¾£¬ºÚ¿Í±ØÐëÓÕʹÓû§´ò¿ªÆäÌØÔìµÄ3DÎļþÄÜÁ¦¹»³É¹¦ÀûÓô˷ì϶£¬Òò¶ø£¬ÔÚ°²È«¸üÐÂ֮ǰÓû§±ØÒªÔ¶ÀëÄÇЩ¿ÉÒÉÎļþÒÔ±£Õϰ²È«¡£
ÔÎÄÁ´½Ó£º
https://news.softpedia.com/news/microsoft-releases-emergency-update-for-windows-10-app-microsoft-office-529800.shtml
2.ÃÀ¹úSBA¹ÙÍø´æÔÚ·ì϶й¶8000¼ÒÆóÒµµÄÃô¸ÐÐÅÏ¢
ÃÀ¹úÓ×ÐÍÆóÒµÖÎÀí¾Ö£¨SBA£©¹ÙÍø´æÔÚ·ì϶£¬Ð¹Â¶ÁË8000¼ÒÆóÒµµÄÃô¸ÐÐÅÏ¢£¬½«µ¼ÖÂÆäÕÆ¹ÜµÄ¾¼ÃÖÐÉË¿àÄÑ´û¿î£¨EIDL£©µÄ·Ö·¢ÑÓ³¤¡£Õâ´ÎÊý¾Ýй¶ÊÇÓÉÓÚµ±²¿ÃÅÊðÍøÕ¾Ê±´æÔÚÎÊÌ⣬µ¼ÖÂÓû§ÔÚÉêÇë´û¿îµÄÒ³Ãæ³¢ÊÔºóÍËʱ£¬±ãÄܹ»¿´µ½ÆäËûÆóÒµµÄÐÅÏ¢¡£Ð¹Â¶µÄÊý¾ÝÔ̺¬ÐÕÃû¡¢Éç»á°²È«ºÅÂ롢˰ºÅ¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢µç×ÓÓʼþ¡¢µç»°ºÅÂë¡¢»éÒöºÍ¹«Ãñ¹ØÏµ¡¢¼ÒÍ¥ÈËÊý¡¢ÊÕÈë¡¢Åû¶²éÎÊÒÔ¼°½ðÈںͱ£ÏÕÐÅÏ¢¡£ÐÂÎÅýÌåCNBC°µÊ¾£¬µ±¾ÖΪÁËÅâ³¥Êܵ½Ó°ÏìµÄÆóÒµ£¬½«ÎªÆäÌṩΪÆÚÒ»ÄêµÄÉí·Ý͵ÇÔ±£»¤·þÎñ¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/small-businesses-covid-19-loans-data-exposure/155013/
3.Ó¢¹úµçÉÌRobert DyasÔâ¹¥»÷£¬Ô¼2Íò¿Í»§Ö§¸¶ÐÅÏ¢±»ÇÔ
3ÔÂ7ÈÕÖÁ30ÈÕ£¬Ó¢¹úµçÉ̹«Ë¾Robert DyasµÄÍøÕ¾Ôâµ½ÐÅÓþ¿¨ÇÔÈ¡¶ñÒâ¾ç±¾µÄ¹¥»÷£¬Ð¹Â¶Á˸ù«Ë¾Ô¼2ÍòÃû¿Í»§µÄÖ§¸¶ÐÅÏ¢£¬Ô̺¬¿Í»§ÐÕÃû¡¢µØÖ·¡¢ÐÅÓþ¿¨¿¨ºÅ¡¢ÓÐЧÆÚºÍ°²È«´úÂ루CVV£©µÈ¡£Äܹ»È·ÐŵÄÊÇÕâ´Î¹¥»÷ΪÐÅÓþ¿¨ÇÔÈ¡¶ñÒâÈí¼þ¹¥»÷£¬µ«ÓÉÓÚÐÅÏ¢²»¼°Ä¿Ç°ÎÞ·¨È·¶¨¸Ã¶ñÒâÈí¼þÊÇ·ñΪMagecart¡£ÕâÀ๥»÷ͨ³£ÊÇÕë¶Ô¹©¸øÁ´µÄ£¬Í¨¹ý·ÛËéÖ§¸¶Ò³ÃæÖеĵÚÈý·½ÍøÕ¾½«¶ñÒâJavascript×¢Èëµ½¸¶¿îÒ³ÃæÖС£Robert Dyas¹«Ë¾°µÊ¾£¬×Ô3ÔÂ30ÈÕ·¢ÏÖ¹¥»÷ºó£¬ËûÃǵÚÒ»¹¦·ò²ÉÈ¡ÁË´ëÊ©£¬²¢±£ÕÏ×Ô3ÔÂ31ÈÕÆðÍøÕ¾±ãÄܹ»°²È«ÔËÐС£
ÔÎÄÁ´½Ó£º
https://www.theregister.co.uk/2020/04/22/robert_dyas_card_skimmer/
4.Tag BarnakleÈëÇÔìóÒµ¸æ°×·þÎñÆ÷Revive´«²¼¶ñÒâ¸æ°×
¾Ý¸æ°×°²È«¹«Ë¾Confiant±¨Â·£¬Tag BarnakleºÚ¿Í×éÖ¯Èë¶Ô×¼ÁËÆóÒµµÄ¿ªÔ´×ÔÍйܸæ°×·þÎñÆ÷ReviveÒÔ´«²¼¶ñÒâ¸æ°×£¬½ü¼¸¸öÔÂÒѾÓм¸Ê®Ì¨·þÎñÆ÷±»¹¥»÷£¬Ô̺¬ÄÇЩ°ä²¼É̺͸æ°×¹«Ë¾×ÔÓªµÄ¸æ°×·þÎñÆ÷¡£Tag BarnakleÍÅ»ïÊÇͨ¹ýÏòÍøÕ¾×¢Èë¶ñÒâJavaScript´úÂëʵÏÖ¹¥»÷µÄ£¬ÕâЩ´úÂëÄܹ»¼ì²âÖ¸±ê»úеÊÇ·ñ´ò¿ªÁËFirebug»òä¯ÀÀÆ÷µÄ¿ª·¢ÈËÔ±½ÚÔį̀£¬ÈôÊÇδ´ò¿ª£¬Ôò½«Óû§³Á¶¨Ïòµ½·Ö·¢ÐéαAdobe Flash¸üеĶñÒâÍøÕ¾¡£Confiantµ÷²é·¢ÏÖTag Barnakle¹¥»÷Á˳¬¹ý360¸öÍøÕ¾¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/revive-ad-servers-being-hacked-to-distribute-malicious-ads/
5.×êÑÐÈËÔ±·¢ÏÖ3¿îÖÇÄܼҾÓϵͳ´æÔÚ¶à¸ö°²È«·ì϶
ESET IoT Research×êÑÐÈËÔ±ÔÚ3¿î·ÖÆçµÄÖÇÄܼҾÓϵͳFibaro Home Center Lite¡¢Homematic Central Control Unit (CCU2) ºÍ eLAN-RF-003Öз¢ÏÖÁ˶à¸ö°²È«·ì϶£¬ÕâЩ·ì϶¿ÉÄܵ¼ÖÂÃô¸ÐÊý¾Ýй¶¡¢Ô¶³Ì´úÂëÖ´ÐкÍÖÐÑëÈ˹¥»÷µÈ¡£Fibaro²úÆ·ÓÉÓÚ¶Ìȱ֤ÊéÑé֤ʹµÃÆäTLSÁ´½ÓÈÝÒ×Êܵ½ÖÐÑëÈ˹¥»÷£¬´Ó¶øÊ¹¹¥»÷Õß»ñµÃrootÓû§½Ó¼ûȨÏÞ¡£eQ?3µÄ²úÆ·CCU2´æÔÚRCE·ì϶£¬Ê¹¹¥»÷ÕßÄܹ»Í¨¹ý´óÁ¿shellºÅÁîÀ´ÀûÓÃRCE·ì϶£¬ÒÔrootÓû§Éí·ÝÖ´ÐÐδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì´úÂë¡£ELKO EPµÄ²úÆ·eLAN-RF-003 ÓÉÓÚ´æÔÚһЩ·ì϶£¬µ¼ÖÂÆä´æÔÚÃô¸ÐÐÅϢй©¡¢Ò×ÊܼͼºÍ³Á·Å¹¥»÷µÄÎÊÌâ¡£ESET IoT Research°µÊ¾£¬¼¸¼ÒÉ豸Ôì×÷É̾ùÔÚ½ÓÊܻ㱨ºóµÄ90ÌìÄÚ½¨¸´ÁËÕâЩ·ì϶¡£
ÔÎÄÁ´½Ó£º
https://www.welivesecurity.com/2020/04/22/serious-flaws-smart-home-hubs-is-your-device-among-them/
6.ºÚ¿ÍÀûÓÃGoogleµÄ.app gTLD´¹µö¹¥»÷£¬ÇÔÈ¡Óû§Skypeƾ֤
CofenseÍøÂ簲ȫ¹«Ë¾·¢ÏÖºÚ¿Íͨ¹ýÓÉGoogleÖÎÀíµÄ.APPͨÓö¥¼¶Óò£¨gTLD£©¶ÔÔ¶³Ì¹¤×÷ÈËÔ±ÌáÒéÁËÍøÂç´¹µö¹¥»÷£¬ÒÔÇÔÈ¡ÆäSkypeƾ֤¡£ºÚ¿Í¾«ÐÄÉè¼ÆÁËÍøÂç´¹µöÒ³Ãæ¼°ÆäÁ´½Ó£¬Í¨¹ýʹÓÃGoogleµÄ.APPͨÓö¥¼¶Óò£¨gTLD£©ÖеÄÁ´½Ó½øÐгõʼ³Á¶¨Ïò£¬Ê¹ÆäÖ¸ÏòαÔìµÄÍøÂç´¹µöÒ³Ãæ¡£ºÚ¿ÍʹÓÃÁË.APP gTLD³É¹¦µÄÈÆ¹ýÍøÂç´¹µöÓʼþµÄ¼ì²â£¬²¢ÇÒÔÚαÔìÒ³ÃæÉÏÏÔʾÁËÊܺ¦Õß¹«Ë¾µÄ»Õ±êºÍ°²È«ÌáÐÑ£¬Ê¹µÃÕâ´Î¹¥»÷¿´ÆðÀ´Ô½·¢ÕæÊµ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/creative-skype-phishing-campaign-uses-googles-app-gtld/


¾©¹«Íø°²±¸11010802024551ºÅ