Unit 42°ä²¼¶ñÒâÈí¼þAcidBoxµÄ·ÖÎö»ã±¨£»AMDÔ¤¼Æ½«ÓÚ6Ôµ×֮ǰ½¨¸´ÆäCPUÖеÄ3¸öзì϶
°ä²¼¹¦·ò 2020-06-221.Unit 42°ä²¼¶ñÒâÈí¼þAcidBoxµÄ·ÖÎö»ã±¨
°²È«¹«Ë¾Unit 42°ä²¼Á˶ÔAcidBoxµÄ·ÖÎö»ã±¨£¬¸Ã¶ñÒâÈí¼þÓÚ2017Äê¾ÍÒѾ±»ÓÃÀ´½øÐй¥»÷»î¶¯£¬µ«ÊÇÖ±µ½´Ë¿Ì²Å±»ÈË·¢ÏÖ¡£¸Ã¶ñÒâÈí¼þͨ¹ýVirtualBoxÖеķì϶À´½ûÓÃWindowsÖÐÇý¶¯·¨Ê½ÊðÃûµÄÖ´ÐУ¬Ä¿Ç°ÒѾ±»ÓÃÓÚ¹¥»÷ÖÁÉÙÁ½¸ö¶íÂÞ˹×éÖ¯¡£Unit 42»¹ÒÔΪAcidBoxÖ»ÊÇÒ»¸ö¸ü´óµÄºÚ¿Í¹¤¾ßÏäÖеÄÒ»²¿ÃÅ£¬µ«ÊÇĿǰ»¹Ã»ÓÐÕÒµ½Ö¤¾ÝÀ´Ö¤Ã÷ÕâÒ»½áÂÛ¡£
ÔÎÄÁ´½Ó£º
https://unit42.paloaltonetworks.com/acidbox-rare-malware/
2.Sberbank·¢ÏÖºÚ¿ÍÀûÓÃÈËΪÖÇÄÜ¿ª·¢ÐÂÐÍÒøÐÐľÂí
¶íÂÞ˹Áª¹ú´¢ÐîÒøÐÐ(Sberbank)¸±¶Ê³¤Stanislav Kuznetsov°µÊ¾£¬ºÚ¿ÍÔÚÀûÓÃÈËΪÖÇÄÜ´´ÔìÐÂÒ»´úµÄÒøÐÐľÂí£¬Ê¹µÃÒøÐÐľÂí±äµÃÔ½·¢¸´ÔÓ¡¢¸üÄѱ»¼ø±ð¡£Kuznetsov°µÊ¾£¬ÓÉÓںڿ͹¥»÷£¬µ½½ñÄêÄêµ×Ϊֹ¶íÂÞ˹¾¼Ã¿ÉÄÜ»áËðʧԼ3.5ÍòÒÚ¬²¼(500ÒÚÃÀÔª)£¬Ã÷ÄêµÄËðʧ½ð¶î¿ÉÄܻᷱ¶¡£Ëû»¹Ö¸³ö£¬ºÚ¿Í¸ü×óÌ»ÓÚʹÓÃÎïÁªÍøÉ豸£¬ÒÔ¼°¶ÔÃÜÂë³ÖÓÐÖÁÌáÒé¹¥»÷£¬ÆäÖÐ×î³£¼ûµÄ͵ÇÔÇþ·ÊÇÊÖ»úÀûÓÃ(43%)¡¢ÒøÐп¨(42%)¡¢ÍøÂç·þÎñ(7%)£¬»¹ÓÐ×Ô¶¯È¡¿î»ú¡¢posÖն˺ͶÌÐÅÒøÐС£
ÔÎÄÁ´½Ó£º
https://www.ehackingnews.com/2020/06/sberbank-says-cyber-criminals-using.html
3.AMDÔ¤¼Æ½«ÓÚ6Ôµ×֮ǰ½¨¸´ÆäCPUÖеÄ3¸öзì϶
AMD°ä·¢£¬Ô¤¼Æ½«ÓÚ6Ôµ×֮ǰ½¨¸´ÆäCPUÖеÄ3¸öзì϶¡£Õâ3¸ö·ì϶±»AMD³ÆÎªSMM±ê×¢·ì϶£¬Ó°ÏìÁË2016ÄêÖÁ2019ÄêÖ®¼ä°ä²¼µÄÒ»Óײ¿Ãżӿ촦Öõ¥Ôª£¨APU£©¡£°²È«×êÑÐÔ±Danny OdlerÓÚ6ÔÂ13ÈÕÆØ¹âÁËÕâ3¸ö·ì϶£¬²¢°µÊ¾ºÚ¿ÍÄܹ»ÀûÓÃÕâЩ·ì϶½«¶ñÒâ´úÂëÖ²ÈëSMRAM£¨SMMµÄÄÚ²¿Äڴ棩ÖУ¬²¢ÒÔSMMµÄÌØÈ¨ÔËÐÐËü¡£¹¥»÷Õ߳ɹ¦ÈëÇÖSMMºó²»½öÄܹ»½ÚÔì²Ù×÷ϵͳ£¬»¹Äܹ»ÆëÈ«½ÚÔìÍÆËã»úµÄÓ²¼þ¡£Ä¿Ç°£¬AMDÒѾ°ä²¼Á˵ÚÒ»¸ö·ì϶£¨CVE-2020-14032£©µÄ²¹¶¡£¬Ô¤¼ÆÔÚ6Ôµ×֮ǰ½«°ä²¼ÆëÈ«²¹¶¡¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/amd-says-it-will-fix-new-cpu-bug-by-the-end-of-june-2020/
4.Mid-Michigan´óѧÔâºÚ¿ÍÈëÇÖ£¬Ð¹Â¶³¬¹ý1.6ÍòÈËÐÅÏ¢
ÔÚÉÏÖÜËÄ£¬Mid-Michigan°ä²¼Á˹«¿ªÃ÷Öª£¬°µÊ¾Æäµç×ÓÓʼþϵͳÔâµ½ÁËÈëÇÖ£¬ºÚ¿Í½Ù³ÖÁË10ÃûÔ±¹¤µÄÕË»§£¬»ò½«µÁÈ¡1.6ÍòÈËÐÅÏ¢¡£¸Ã´óѧ°µÊ¾£¬ÆäϵͳÈÔÔÚÕý³£ÔËÐУ¬Ò²Ã»ÓÐÊÕµ½Êê½ðÒªÇó¡£Õâ´Îй¶Êý¾ÝÔ̺¬Éç»á°²È«ºÅÂëºÍÆäËûÓ×ÎÒÐÅÏ¢£¬Ó°ÏìÁ˸ÃУµÄºÜ¶à³ÉÔ±£¬Ô̺¬½ÌÈËÔ±¹¤¡¢Ñ§ÉúºÍÒѾ±ÏÒµµÄУÓѵÈÈË¡£¸ÃУ¹ÙÔ¹ØýÔÚÓëÂÉʦÊÂÎñËùHonigmanµÄÍøÂ簲ȫÊýÃźÏ×÷£¬ÒÔµ÷²é¾ßÌåÔÒò¼°Ð¹Â¶Êý¾Ý¡£
ÔÎÄÁ´½Ó£º
https://www.themorningsun.com/news/data-breach-at-mid-michigan-college-endangers-personal-data-of-up-to-16-000/article_6d01cae4-b25c-11ea-89cd-1f4b9b41c0de.html
5.ºÚ¿ÍÔÚ°µÍøÏúÊÛ³¬¹ý23ÍòÓ¡ÄáCOVID-19»¼ÕߵIJ¡Àú
Íþвµý±¨¹«Ë¾CybleµÄ°²È«×êÑÐÈËÔ±ÔÚ°µÍøÉÏ·¢ÏÖÁ˳¬¹ý23Íò¶àÃûÓ¡¶ÈÄáÎ÷ÑÇCOVID-19»¼ÕߵIJ¡Àý¡£Õâ´Îй¶µÄÊý¾ÝÔ̺¬ÐÕÃû¡¢µØÖ·¡¢ÏÖסµØÖ·¡¢µç»°ºÅÂë¡¢¹«ÃñÉí·Ý¡¢Õï¶ÏÈÕÆÚ¡¢Á˾֡¢Á˾ÖÈÕÆÚµÈ¡£Cybleͨ¹ý¶ÈÎöÊý¾ÝÒÑÈ·ÈÏÆäÕæÊµÐÔ£¬²¢ÔÚÆäÊý¾Ýй¶¼à¶½ºÍ֪ͨ·þÎñAmiBreached.comÖжÔÁ˸üͼ³ÉÁ¢ÁËË÷Òý¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/105043/deep-web/indonesian-covid-19-patients-leak.html?utm_source=rss&utm_medium=rss&utm_campaign=indonesian-covid-19-patients-leak
6.ºÚ¿Í×éÖ¯NetWalkerÔÚÏúÊÛÃÀ¹úÒ½ÁÆ»ú¹¹Êý¾Ý
Crozer-KeystoneÒ½ÁÆ»ú¹¹Ôâµ½ÁËÀÕË÷Èí¼þ×éÖ¯NetWalkerµÄ¹¥»÷£¬²¢±»µÁÈ¡Êý¾Ý¡£Ä¿Ç°£¬ºÚ¿Í×éÖ¯ÔÚ¹ýÆäÍøÕ¾DarknetÅÄÂôCrozer-KeystoneµÄÊý¾Ý£¬²¢°µÊ¾ÈôÊǸÃҽԺδÔÚÁùÌìÄڲɰ죬ËûÃǽ«»áй©ÕâЩÊý¾Ý¡£¾ÝϤ£¬±»µÁÊý¾ÝÖØÒªÎª²ÆÕþÇé¿öÓйØÐÅÏ¢£¬Ó뻼ÕߵIJ¡ÀúÎ޹ء£Æ¾¾Ý¶ñÒâÈí¼þ³¢ÊÔÊÒEmsisoftµÄͳ¼Æ£¬ÔÚ2019Ä꣬ÓÐÖÁÉÙ764¼ÒÃÀ¹úÒ½ÁƱ£½¡¹«Ë¾Ôâµ½ÁËÀÕË÷Èí¼þµÄÓ°Ïì¡£
ÔÎÄÁ´½Ó£º
https://cointelegraph.com/news/ransomware-gang-auctions-off-us-healthcare-data-for-bitcoin


¾©¹«Íø°²±¸11010802024551ºÅ