Apple°ä²¼°²È«¸üн¨¸´50¶à·ì϶£»McAfee·¢ÏÖ £¬µÚÒ»¼¾¶ÈÕë¶ÔÔÆÕÊ»§µÄ¹¥»÷Ôö³¤ÁË630£¥

°ä²¼¹¦·ò 2020-05-29

1.Apple°ä²¼°²È«¸üР£¬½¨¸´macOSºÍSafariÖÐ50¶à·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Apple±¾Öܰ䲼Á˰²È«¸üР£¬½¨¸´ÁËmacOSºÍSafariÖÐ×ܼÆ50¶à¸ö·ì϶¡£ÆäÖÐΪmacOS Catalina 10.15.5¿¯Ðа潨¸´ÁË44¸ö·ì϶ £¬ÕâЩ·ì϶¿ÉÄܵ¼Ö»ؾø·þÎñ¡¢¶ã±ÜɳÏäÏÞ¶È¡¢Ð¹Â©¸öÈËÐÅÏ¢¡¢ËÁÒâ´úÂëÖ´ÐÓ×¢Óû§ÐÅϢй¶¡¢ÌØÈ¨ÌáÉý¡¢É³ÏäתÒå¡¢ÄÚ´æÐ¹Â©¡¢Ö´ÐÐËÁÒâshellºÅÁîÒÔ¼°ÒþÖÔÊ×Ñ¡ÏîÈÆ¹ýµÈÎÊÌâ¡£»¹½¨¸´ÁËSafari 13.1.1ÖеÄ10¸ö·ì϶ £¬ÆäÖв¿Ãű»Ô̺¬ÔÚmacOS CatalinaÖÐ £¬¿ÉÄܻᵼÖÂËÁÒâ´úÂëÖ´ÐÓ×¢¿çÕ¾µã¾ç±¾¹¥»÷»ò¹ý³ÌÄÚ´æÐ¹Â©¡£Õâ´Î¸üл¹ÎªWindows°æiCloud½¨¸´ÁË12¸ö·ì϶ £¬Ô̺¬ËÁÒâ´úÂëÖ´ÐÓ×¢»Ø¾ø·þÎñºÍ¿çÕ¾µã¾ç±¾µÈÎÊÌâ¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/apple-patches-over-40-vulnerabilities-macos-catalina


2.McAfee·¢ÏÖ £¬µÚÒ»¼¾¶ÈÕë¶ÔÔÆÕÊ»§µÄ¹¥»÷Ôö³¤ÁË630£¥


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


McAfee»ã±¨·¢ÏÖ £¬COVID-19´óÊ¢ÐÐÆÚ¼ä £¬Ëæ×ÅÔÆ·þÎñºÍÔÆºÏ×÷¹¤¾ß£¨ÀýÈçCisco WebEx¡¢Zoom¡¢Microsoft TeamsºÍSlack£©Ê¹ÓÃÂʵÄÔö³¤ £¬Õë¶ÔÔÆÕÊ»§µÄ¹¥»÷Ôö³¤ÁË630£¥¡£ÕâЩ¹¥»÷ÖÐ £¬´óÎÞÊýÕë¶ÔµÄÊÇMicrosoft 365µÈÔÆºÏ×÷¹¤¾ß £¬²¢ÇÒÊÇ´ó¹æÄ£µØ½Ó¼ûÍ´´¦±»µÁµÄÔÆÕÊ»§¡£ÔÚµ÷²éÖÐ £¬ÆóÒµ¶ÔÔÆ·þÎñµÄʹÓÃÂÊÃÍÔöÁË50£¥ £¬ÆäÖÐÔ̺¬Ôì×÷ÒµºÍ½ðÈÚ·þÎñµÈÐÐÒµ £¬ÕâЩÐÐҵͨ³£±ÈÆäËûÐÐÒµ¸üÒÀÀµÓÚ±¾µØÀûÓ÷¨Ê½¡¢ÍøÂçºÍ°²È«ÐÔ¡£¶ø¶ÔÓÚÔÆºÏ×÷¹¤¾ßµÄʹÓÃÂÊÔòÔö³¤Á˸ߴï600£¥ £¬ÆäÖнÌÓý²¿ÃÅÔö³¤×î¿ì £¬ÓÉÓÚÔ½À´Ô½¶àµÄѧÉú±ØÒª½øÐÐÔ¶³Ì½ø½¨¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2020/05/28/external-attacks-on-cloud-accounts/


3.Group-IB°ä²¼»ã±¨ £¬ÀÕË÷Èí¼þÊê½ðÒ»ÄêÄÚÔö³¤ÁË14±¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÍøÂ簲ȫ¹«Ë¾Group-IB °ä²¼»ã±¨ £¬·ÖÎöÁË×Ô2018ÄêÒÔÀ´Ò»ÄêÄÚÀÕË÷Èí¼þ¹¥»÷µÄ±ä¶¯ £¬´ËÀ๥»÷ÊýÁ¿Ôö³¤ÁË40% £¬Êê½ðÔö³¤ÁË14±¶¡£×ÔGandCrabÍÅ»ï2019Äê°ä·¢ÊÕÊÖºó £¬ÀÕË÷Èí¼þ×éÖ¯ÐγÉÁËransomware-as-a-service (RaaS)µÄÐÂģʽ £¬ËûÃÇѡȡÁ˶àÖÖ³õʼ½Ó¼ûý½é £¬Ôö³¤ÁËÊê½ðÒªÇó £¬²¢ÆðÍ·´ÓÊܺ¦ÕßÄÇÀïÇÔÈ¡Îļþ £¬¶øºóÔÙ¼ÓÃÜÒÔ½øÒ»²½Ë÷ÒªÊê½ð¡£»ã±¨ÏÔʾ £¬´ËÀ๥»÷ÔÚ2019ÄêÔö³¤ÁË40£¥ £¬ÀÕË÷¼ÛÖµ´Ó6000ÃÀÔªÌá¸ßµ½ÁË84000ÃÀÔª £¬ÆäÖÐÁ½¸öÊê½ð×î¸ßµÄ×éÖ¯ÊÇRyukºÍREvil¡£¶ø¾ÝCovewareµÄÊý¾ÝÏÔʾ £¬2020ÄêÊê½ð¼ÛÖµÕÇ·ù¸ü´ó £¬µÚÒ»¼¾¶ÈµÄ¾ùÔȼÛÖµ¸ß´ï111605ÃÀÔª¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ransomwares-big-jump-ransoms-grew-14-times-in-one-year/


4.ÃÜЪ¸ùÖÝÁ¢´óѧÔâµ½ºÚ¿ÍÍÅ»ïNetWalkerµÄÀÕË÷Èí¼þ¹¥»÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÀÕË÷Èí¼þÍÅ»ïNetWalkerÓÚ5ÔÂ28ÈÕ°µÊ¾ £¬ËûÃÇÒѾ­³É¹¦Ï°È¾ÁËÃÜЪ¸ùÖÝÁ¢´óѧ£¨MSU£©µÄÍøÂç¡£¸Ã×éÖ¯ÔÚÆäÍøÕ¾Éϰ䲼ÁËÎåÕÅͼƬÀ´Ö¤Ã÷Æä¹¥»÷ £¬±ðÀëÊÇÁ½ÕŸÃѧÌÃÍøÂçĿ¼½á¹¹Í¼Æ¬ £¬Ñ§Éú»¤ÕÕµÄɨÃèͼÏñÒÔ¼°Á½ÕÅÃÜЪ¸ùÖݲÆÕþÎļþµÄɨÃèͼÏñ¡£NetWalkerÒªÇóMSUÒ»ÖÜÄÚÖ§¸¶Êê½ð £¬²»È»½«»á°ÑÕâЩÐÅϢй©µ½ÆäÍøÕ¾ÉÏ¡£Ä¿Ç° £¬ÃÜÎ÷¸ùÖÝÁ¢´óÑ§ÍøÂçµÄÊÜËðÇé¿öÉв»Ã÷ÏÔ £¬¸Ã´óѧҲûÓÐÈκλظ´ÒÔÌṩ¸ü¶àϸ½Ú¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/michigan-state-university-hit-by-ransomware-gang/


5.¶ñÒâÈí¼þValak¶Ô×¼Exchange·þÎñÆ÷ÒÔÇÔÈ¡ÆóÒµÊý¾Ý


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Cybereason Nocturnus·¢ÏÖ¶ñÒâÈí¼þValakÒѾ­¸´ÔÓ»¯ £¬²¢×ªÐÍΪÐÅÏ¢ÇÔÈ¡¹¤¾ß £¬Õë¶ÔExchange·þÎñÆ÷ÒÔÇÔÈ¡ÆóÒµÊý¾Ý¡£×î³õValakÊÇ×÷ΪÆäËû¹¥»÷µÄ×°ÔØ»ú´æÔÚµÄ £¬Í¨³£ÓëUrsnifºÍIcedID°ó¸¿ÔÚһ·ÀûÓá£ValakÊ×ÏÈͨ¹ý´¹µöÈí¼þ·Ö·¢Microsoft WordºêÎĵµ £¬¶øºóÏÂÔØÃûΪ¡°U.tmp¡±µÄ.DLLÎļþ £¬Å²ÓÃWinExec APIÏÂÔØJavaScript´úÂë´Ó¶ø´´½¨C2Á´½Ó £¬×îºó²¿ÊðÓÐЧ¸ºÔز¢Ö´ÐÐÓÃÓÚ¿úËźÍÊý¾Ý͵ÇÔµÄÆäËûÄ £¿é¡£×îеÄValak±äÌåÄܹ»ÌáÈ¡Ãô¸ÐÊý¾ÝÒÔ½Ó¼ûÆóÒµÄÚ²¿ÓʼþϵͳµÄÓû§ºÍÆóÒµÓòÖ¤Êé £¬»¹Äܹ»Í¨¹ýsysteminfo¼ø±ð³öÓòÖÎÀíÔ± £¬¶ÔÆóÒ·´Ëµ¼«¶ÈΣÏÕ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/valak-targets-microsoft-exchange-servers-to-steal-enterprise-data-in-active-campaigns/


6.NSA°ä²¼¾¯±¨ £¬¶íºÚ¿Í×éÖ¯Sandworm¹¥»÷EximÓʼþϵͳ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹ú¹ú¶È°²È«¾Ö£¨NSA£©ÓÚ5ÔÂ28ÈÕ°ä²¼ÁËÒ»Ïȫ¾¯±¨ £¬ÖÒ¸æ³Æ¶íÂÞ˹¾üʵý±¨²¿ÃÅGRUÌØÊâ¼¼ÊõÖØÒªÖÐÐÄ£¨GTsST£©µÄ74455µ¥ÔªÒ»ÏòÔÚ¹¥»÷ÔËÐÐEximÓʼþ´«Êä´úÀí£¨MTA£©µÄµç×ÓÓʼþ·þÎñÆ÷¡£¸Ã×éÖ¯Ò²³ÆÎªSandworm £¬ËüÀûÓÃ2019Äê6ÔÂÅû¶µÄ´úºÅΪ¡°Return of the WIZard.¡±µÄ·ì϶£¨CVE-2019-10149£© £¬ÔÚÊܺ¦ÍÆËã»úÏÂÔØ²¢Ö´ÐÐShell¾ç±¾ £¬¸Ã¾ç±¾Äܹ»Ôö³¤ÌØÈ¨Óû§¡¢½ûÓÃÍøÂ簲ȫÉèÖᢸüÐÂSSHÅäÖÃÒÔÆôÓÃÆäËûÔ¶³Ì½Ó¼û¡¢Ö´ÐÐÆäËû¾ç±¾ÒÔÆôÓúóÐøÀûÓá£NSA°ä²¼´Ë¾¯±¨¶½´ÙEximÖÎÀíÔ±½¨¸´Æä·þÎñÆ÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/nsa-warns-of-new-sandworm-attacks-on-email-servers/