ĦÂå¸çµ±¾ÖÓÃNSO Group¼äµýÈí¼þ¼à¶½¸Ã¹ú¼ÇÕß;ºÚ¿ÍÓÃGoogle AnalyticsÈÆ¹ýCSPÇÔÊØÐÅÓþ¿¨ÐÅÏ¢

°ä²¼¹¦·ò 2020-06-24

1.ĦÂå¸çµ±¾Ö»òÔÚÀûÓÃNSO GroupµÄ¼äµýÈí¼þ¼à¶½¸Ã¹ú¼ÇÕß


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¹ú¼ÊÌØÉâ×éÖ¯°µÊ¾ £¬Æä°²È«ÍŶÓÔÚĦÂå¸ç¼ÇÕßµÄÊÖ»úÉÏ·¢ÏÖÁËNSO Group¿ª·¢µÄ¼äµýÈí¼þ £¬´ËÊ»òÓë¸Ã¹úµ±¾ÖÓйØ¡£Ä¦Âå¸ç¼ÇÕßOmar RadiÔâµ½¼à¶½Èí¼þµÄ¹¥»÷ £¬¸ÃÈí¼þ¿ÉÄܸú×ÙÎı¾¡¢µç»°¡¢µç×ÓÓʼþ¡¢ÉãÏñ»úµÈ¡£ºÚ¿Íͨ¹ýÍøÂç×¢Èë¹¥»÷ÒÔÀ¹½ØºÍ²Ù¼«Ö¸±êµÄ»¥ÁªÍøÁ÷Á¿ £¬¸Ã²½Öè²»±ØÒªÓëÊܺ¦Õß½»»¥ £¬Ö»Ð轫ָ±êä¯ÀÀÆ÷³ÁзÓɵ½Ò»¸ö¶ñÒâÍøÕ¾¡£¹ú¼ÊÌØÉâ×éÖ¯°µÊ¾ £¬¹¥»÷ÕßÉí·ÝËäδµÃµ½È·ÈÏ £¬µ«¸÷ÖÖÖ¤¾ÝÅú×¢¼à¶½ÕßΪĦÂå¸çµ±¾Ö £¬ÓÉÓÚNSO¼¯ÍÅÒ»ÔÙ°µÊ¾¸ÃÈí¼þ½ö±»ÏúÊÛ¸øÁ˵±¾Ö¡£


Ô­ÎÄÁ´½Ó£º

https://www.cyberscoop.com/nso-group-spyware-amnesty-international-omar-radi-morocco/


2.ºÚ¿ÍʹÓÃGoogle AnalyticsÆ½Ì¨ÈÆ¹ýCSPÇÔÊØÐÅÓþ¿¨ÐÅÏ¢


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ºÚ¿ÍÔÚʹÓÃGoogle AnalyticsÆ½Ì¨ÈÆ¹ýÄÚÈݰ²È«Õþ²ß£¨CSP£© £¬À´ÇÔÈ¡ÔÚÏßÉ̵êÓû§Ìá½»µÄÐÅÓþ¿¨ÐÅÏ¢¡£ÍøÂ簲ȫ¹«Ë¾SansecºÍPerimeterXµÄ×îÐÂ×êÑÐÅú×¢ £¬ÔÚ²¿ÊðÁËGoogle AnalyticsµÄÍøÕ¾ÉÏ £¬Ê¹ÓÃCSPÔ¤·ÀÐÅÓþ¿¨ÇÔÈ¡¹¥»÷ÒѾ­ºÁÎÞÒâ˼¡£ÓÉÓÚCSPÖ÷ÌâÖ°ÄÜÖдæÔÚ·ì϶ £¬Ëü²»ÄÜ×èÖ¹»ùÓÚ×¢ÈëµÄ¹¥»÷ £¬Òò¶øºÚ¿ÍÄܹ»Í¨¹ýÒ»¸öweb skimmer½ÅÕý±¾ÇÔÈ¡Êý¾Ý²¢½«ÆäÒÔ¼ÓÃܵĴó¾Ö·¢Ëͻع¥»÷Õß¡£SansecµÄÍþв×êÑÐÓ××éй© £¬¹¥»÷ÕßÀûÓÃGoogle AnalyticsÒѾ­³É¹¦ÈƹýÊýÊ®¸öµç×ÓÉÌÎñÍøÕ¾ÉϵÄCSP¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hackers-use-google-analytics-to-steal-credit-cards-bypass-csp/


3.ºÚ¿ÍÔÚ°µÍøÏúÊÛÊ¢ÐÐÓÎÏ·StalkerÖг¬¹ý130ÍòÍæ¼ÒÐÅÏ¢


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°²È«×êÑÐÈËÔ±·¢ÏÖ £¬ºÚ¿ÍÔÚ°µÍøÏúÊÛÁËÊ¢ÐÐÓÎÏ·StalkerÖг¬¹ý130ÍòÍæ¼ÒÐÅÏ¢ £¬Ð¹Â¶ÐÅÏ¢Ô̺¬Óû§Ãû¡¢ÃÜÂë¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂëºÍIPµØÖ·¡£Õâ´ÎÏúÊ۵Ĺ²ÓÐÁ½¸öÊý¾Ý¿â £¬±ðÀëΪ120Íò±Ê¼Í¼ºÍ136000±Ê¼Í¼¡£¸Ã¹«Ë¾°µÊ¾ £¬Óû§µÄÃÜÂëÊǾ­¹ýMD5¼ÓÃܺͼÓÑδ¦ÖõÄ £¬Õâ¹ÌÈ»Êǰ²È«ÐԽϵ͵ÄËã·¨µ«±ÈÒÔ´¿Îı¾´ó¾Ö±£ÁôÃÜÂë¸üºÃ¡£Ä¿Ç° £¬¸Ã¹«Ë¾ÒÑÓëºÚ¿ÍÔÚÏßÉ̵êµÄµç×ÓÉÌÎñƽ̨ÁªÏµ £¬´Ë¿ÌÒÑÍÑ»ú¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/stalker-online-breach-13-m-user/


4.°ÄÖÞACCC°ä²¼»ã±¨ £¬¸Ã¹úÈ¥ÄêÓг¬¹ý2.5ÍòÆð´¹µö¹¥»÷ÊÂÎñ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°Ä´óÀûÑÇACCCÏÂÊôµÄScamwatch°ä²¼ÁËScamwatch Targeting scams£º×Ô2009ÄêÒÔÀ´¶Ôڲƭ»î¶¯µÄ»ØÊ׻㱨 £¬Í³¼Æ2019Äê¸Ã¹ú²úÉúÁ˳¬¹ý2.5ÍòÆð´¹µö¹¥»÷ÊÂÎñ¡£ÔÚ2019Äê £¬ÍøÂç´¹µöÊÇ×î³£¼ûµÄڲƭ¼¿Á© £¬×ܹ²»ã±¨ÁËÓÐ25168ÆðÊÂÎñ £¬ÔÚËù»ã±¨ÖÐÓÐ513ÆðÔì³ÉÁ˲ÆÕþËðʧ £¬×ܼÆ150Íò°ÄÔª¡£¶øÔì³ÉËðʧ×î´óµÄ¹¥»÷ÀàÐÍΪÆóÒµµç×ÓÓʼþй¶£¨BEC£©Ú¿Æ­ £¬Ëðʧ1.32ÒÚ°ÄÔª £¬Æä´ÎΪÔì³ÉÁË1.26ÒÚ°ÄÔªËðʧµÄͶ×ÊÚ¿Æ­ºÍ8300Íò°ÄÔªµÄÔ¼»áÚ¿Æ­¡£¶øÚ¿Æ­µÄÖØÒªõè¾¶ÒÀȻΪµç»°£¨69522Æð£© £¬Æä´ÎÊǵç×ÓÓʼþ£¨40277Æð£© £¬¶ÌÐÅ£¨27894Æð£©ºÍ»¥ÁªÍø£¨11776Æð£©¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/australians-reported-25000-phishing-scams-to-the-accc-last-year/


5.Apache Dubbo·´ÐòÁл¯Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-1948£©


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

2020Äê6ÔÂ23ÈÕApache¹Ù·½°ä²¼¹«¸æ £¬½¨¸´ÁËÒ»¸öApache DubboÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-1948£©¡£¸Ã·ì϶ԴÓÚApache Dubbo Provider´æÔÚ·´ÐòÁл¯·ì϶ £¬¹¥»÷ÕßÄܹ»·¢ËÍ´øÓÐÎÞ·¨Ê¶´ËÍâ·þÎñÃû»ò²½ÖèÃû¼°Ä³Ð©¶ñÒâ²ÎÊý¸ºÔصÄRPCÒªÇó £¬µ±¶ñÒâ²ÎÊý±»·´ÐòÁл¯Ê±½«µ¼Ö¶ñÒâ´úÂëÖ´ÐС£¸Ã·ì϶ӰÏìÁËËùÓÐʹÓÃ2.7.6»ò¸üµÍ°æ±¾µÄDubboÓû§¡£


Ô­ÎÄÁ´½Ó£º

https://github.com/apache/dubbo/releases/tag/dubbo-2.7.7


6.ÀÕË÷Èí¼þREvilɨÃèÊܺ¦ÕßϵͳÖеÄPoSÒÔѰеĻñÀû·½Ê½


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


SymantecÍþвµý±¨ÍŶӵÄ×êÑÐÈËÔ±·¢ÏÖºÚ¿ÍÔÚеÄÀÕË÷»î¶¯ÖÐʹÓÃREvilɨÃèÊܺ¦ÕßϵͳÖеÄÐÅÓþ¿¨»òPoint of Sale£¨PoS£©Êý¾Ý £¬»òÔÚѰÕÒеĻñÀû·½Ê½¡£µý±¨·ÖÎöʦJon DiMaggio°µÊ¾ £¬ÈôÊÇËûÃÇɨÃèµ½ÁËPoSϵͳ £¬±ãÄܹ»×°ÖÃPOS¶ñÒâɨÃèÈí¼þÇÔÊØÐÅÓþ¿¨¾ßÌåÐÅÏ¢¡£Symantec·ÖÎö· £¬²¿ÃÅÊܺ¦¹«Ë¾¹æÄ£½ÏÓ× £¬ÎÞ·¨Ö§¸¶Êê½ð £¬Òò¶ø¸ÃºÚ¿ÍÍÅ»ïɨÃèPoSϵͳÖеÄÐÅÓþ¿¨Êý¾Ý¿ÉÄÜÊÇΪÁËÊý¾Ý͵ÇÔ £¬»òÖ»ÊÇΪÁËʹ¼ÓÃܵÄÊý¾Ý¸üÓмÛÖµÒÔÒªÇóÊܺ¦ÕßÖ§¸¶Êê½ð¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/revil-ransomware-scans-victims-network-for-point-of-sale-systems/