ĦÂå¸çµ±¾ÖÓÃNSO Group¼äµýÈí¼þ¼à¶½¸Ã¹ú¼ÇÕß;ºÚ¿ÍÓÃGoogle AnalyticsÈÆ¹ýCSPÇÔÊØÐÅÓþ¿¨ÐÅÏ¢
°ä²¼¹¦·ò 2020-06-241.ĦÂå¸çµ±¾Ö»òÔÚÀûÓÃNSO GroupµÄ¼äµýÈí¼þ¼à¶½¸Ã¹ú¼ÇÕß
¹ú¼ÊÌØÉâ×éÖ¯°µÊ¾£¬Æä°²È«ÍŶÓÔÚĦÂå¸ç¼ÇÕßµÄÊÖ»úÉÏ·¢ÏÖÁËNSO Group¿ª·¢µÄ¼äµýÈí¼þ£¬´ËÊ»òÓë¸Ã¹úµ±¾ÖÓйء£Ä¦Âå¸ç¼ÇÕßOmar RadiÔâµ½¼à¶½Èí¼þµÄ¹¥»÷£¬¸ÃÈí¼þ¿ÉÄܸú×ÙÎı¾¡¢µç»°¡¢µç×ÓÓʼþ¡¢ÉãÏñ»úµÈ¡£ºÚ¿Íͨ¹ýÍøÂç×¢Èë¹¥»÷ÒÔÀ¹½ØºÍ²Ù¼«Ö¸±êµÄ»¥ÁªÍøÁ÷Á¿£¬¸Ã²½Öè²»±ØÒªÓëÊܺ¦Õß½»»¥£¬Ö»Ð轫ָ±êä¯ÀÀÆ÷³ÁзÓɵ½Ò»¸ö¶ñÒâÍøÕ¾¡£¹ú¼ÊÌØÉâ×éÖ¯°µÊ¾£¬¹¥»÷ÕßÉí·ÝËäδµÃµ½È·ÈÏ£¬µ«¸÷ÖÖÖ¤¾ÝÅú×¢¼à¶½ÕßΪĦÂå¸çµ±¾Ö£¬ÓÉÓÚNSO¼¯ÍÅÒ»ÔÙ°µÊ¾¸ÃÈí¼þ½ö±»ÏúÊÛ¸øÁ˵±¾Ö¡£
ÔÎÄÁ´½Ó£º
https://www.cyberscoop.com/nso-group-spyware-amnesty-international-omar-radi-morocco/
2.ºÚ¿ÍʹÓÃGoogle AnalyticsÆ½Ì¨ÈÆ¹ýCSPÇÔÊØÐÅÓþ¿¨ÐÅÏ¢
ºÚ¿ÍÔÚʹÓÃGoogle AnalyticsÆ½Ì¨ÈÆ¹ýÄÚÈݰ²È«Õþ²ß£¨CSP£©£¬À´ÇÔÈ¡ÔÚÏßÉ̵êÓû§Ìá½»µÄÐÅÓþ¿¨ÐÅÏ¢¡£ÍøÂ簲ȫ¹«Ë¾SansecºÍPerimeterXµÄ×îÐÂ×êÑÐÅú×¢£¬ÔÚ²¿ÊðÁËGoogle AnalyticsµÄÍøÕ¾ÉÏ£¬Ê¹ÓÃCSPÔ¤·ÀÐÅÓþ¿¨ÇÔÈ¡¹¥»÷ÒѾºÁÎÞÒâ˼¡£ÓÉÓÚCSPÖ÷ÌâÖ°ÄÜÖдæÔÚ·ì϶£¬Ëü²»ÄÜ×èÖ¹»ùÓÚ×¢ÈëµÄ¹¥»÷£¬Òò¶øºÚ¿ÍÄܹ»Í¨¹ýÒ»¸öweb skimmer½ÅÕý±¾ÇÔÈ¡Êý¾Ý²¢½«ÆäÒÔ¼ÓÃܵĴó¾Ö·¢Ëͻع¥»÷Õß¡£SansecµÄÍþв×êÑÐÓ××éй©£¬¹¥»÷ÕßÀûÓÃGoogle AnalyticsÒѾ³É¹¦ÈƹýÊýÊ®¸öµç×ÓÉÌÎñÍøÕ¾ÉϵÄCSP¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hackers-use-google-analytics-to-steal-credit-cards-bypass-csp/
3.ºÚ¿ÍÔÚ°µÍøÏúÊÛÊ¢ÐÐÓÎÏ·StalkerÖг¬¹ý130ÍòÍæ¼ÒÐÅÏ¢
°²È«×êÑÐÈËÔ±·¢ÏÖ£¬ºÚ¿ÍÔÚ°µÍøÏúÊÛÁËÊ¢ÐÐÓÎÏ·StalkerÖг¬¹ý130ÍòÍæ¼ÒÐÅÏ¢£¬Ð¹Â¶ÐÅÏ¢Ô̺¬Óû§Ãû¡¢ÃÜÂë¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂëºÍIPµØÖ·¡£Õâ´ÎÏúÊ۵Ĺ²ÓÐÁ½¸öÊý¾Ý¿â£¬±ðÀëΪ120Íò±Ê¼Í¼ºÍ136000±Ê¼Í¼¡£¸Ã¹«Ë¾°µÊ¾£¬Óû§µÄÃÜÂëÊǾ¹ýMD5¼ÓÃܺͼÓÑδ¦Öõģ¬Õâ¹ÌÈ»Êǰ²È«ÐԽϵ͵ÄËã·¨µ«±ÈÒÔ´¿Îı¾´ó¾Ö±£ÁôÃÜÂë¸üºÃ¡£Ä¿Ç°£¬¸Ã¹«Ë¾ÒÑÓëºÚ¿ÍÔÚÏßÉ̵êµÄµç×ÓÉÌÎñƽ̨ÁªÏµ£¬´Ë¿ÌÒÑÍÑ»ú¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/stalker-online-breach-13-m-user/
4.°ÄÖÞACCC°ä²¼»ã±¨£¬¸Ã¹úÈ¥ÄêÓг¬¹ý2.5ÍòÆð´¹µö¹¥»÷ÊÂÎñ
°Ä´óÀûÑÇACCCÏÂÊôµÄScamwatch°ä²¼ÁËScamwatch Targeting scams£º×Ô2009ÄêÒÔÀ´¶ÔڲƻµÄ»ØÊ׻㱨£¬Í³¼Æ2019Äê¸Ã¹ú²úÉúÁ˳¬¹ý2.5ÍòÆð´¹µö¹¥»÷ÊÂÎñ¡£ÔÚ2019Äê£¬ÍøÂç´¹µöÊÇ×î³£¼ûµÄڲƼ¿Á©£¬×ܹ²»ã±¨ÁËÓÐ25168ÆðÊÂÎñ£¬ÔÚËù»ã±¨ÖÐÓÐ513ÆðÔì³ÉÁ˲ÆÕþËðʧ£¬×ܼÆ150Íò°ÄÔª¡£¶øÔì³ÉËðʧ×î´óµÄ¹¥»÷ÀàÐÍΪÆóÒµµç×ÓÓʼþй¶£¨BEC£©Ú¿Æ£¬Ëðʧ1.32ÒÚ°ÄÔª£¬Æä´ÎΪÔì³ÉÁË1.26ÒÚ°ÄÔªËðʧµÄͶ×ÊڿƺÍ8300Íò°ÄÔªµÄÔ¼»áÚ¿Æ¡£¶øÚ¿ÆµÄÖØÒªõè¾¶ÒÀȻΪµç»°£¨69522Æð£©£¬Æä´ÎÊǵç×ÓÓʼþ£¨40277Æð£©£¬¶ÌÐÅ£¨27894Æð£©ºÍ»¥ÁªÍø£¨11776Æð£©¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/australians-reported-25000-phishing-scams-to-the-accc-last-year/
5.Apache Dubbo·´ÐòÁл¯Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-1948£©
2020Äê6ÔÂ23ÈÕApache¹Ù·½°ä²¼¹«¸æ£¬½¨¸´ÁËÒ»¸öApache DubboÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-1948£©¡£¸Ã·ì϶ԴÓÚApache Dubbo Provider´æÔÚ·´ÐòÁл¯·ì϶£¬¹¥»÷ÕßÄܹ»·¢ËÍ´øÓÐÎÞ·¨Ê¶´ËÍâ·þÎñÃû»ò²½ÖèÃû¼°Ä³Ð©¶ñÒâ²ÎÊý¸ºÔصÄRPCÒªÇ󣬵±¶ñÒâ²ÎÊý±»·´ÐòÁл¯Ê±½«µ¼Ö¶ñÒâ´úÂëÖ´ÐС£¸Ã·ì϶ӰÏìÁËËùÓÐʹÓÃ2.7.6»ò¸üµÍ°æ±¾µÄDubboÓû§¡£
ÔÎÄÁ´½Ó£º
https://github.com/apache/dubbo/releases/tag/dubbo-2.7.7
6.ÀÕË÷Èí¼þREvilɨÃèÊܺ¦ÕßϵͳÖеÄPoSÒÔѰеĻñÀû·½Ê½
SymantecÍþвµý±¨ÍŶӵÄ×êÑÐÈËÔ±·¢ÏÖºÚ¿ÍÔÚеÄÀÕË÷»î¶¯ÖÐʹÓÃREvilɨÃèÊܺ¦ÕßϵͳÖеÄÐÅÓþ¿¨»òPoint of Sale£¨PoS£©Êý¾Ý£¬»òÔÚѰÕÒеĻñÀû·½Ê½¡£µý±¨·ÖÎöʦJon DiMaggio°µÊ¾£¬ÈôÊÇËûÃÇɨÃèµ½ÁËPoSϵͳ£¬±ãÄܹ»×°ÖÃPOS¶ñÒâɨÃèÈí¼þÇÔÊØÐÅÓþ¿¨¾ßÌåÐÅÏ¢¡£Symantec·ÖÎö·£¬²¿ÃÅÊܺ¦¹«Ë¾¹æÄ£½ÏÓ×£¬ÎÞ·¨Ö§¸¶Êê½ð£¬Òò¶ø¸ÃºÚ¿ÍÍÅ»ïɨÃèPoSϵͳÖеÄÐÅÓþ¿¨Êý¾Ý¿ÉÄÜÊÇΪÁËÊý¾Ý͵ÇÔ£¬»òÖ»ÊÇΪÁËʹ¼ÓÃܵÄÊý¾Ý¸üÓмÛÖµÒÔÒªÇóÊܺ¦ÕßÖ§¸¶Êê½ð¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/revil-ransomware-scans-victims-network-for-point-of-sale-systems/


¾©¹«Íø°²±¸11010802024551ºÅ