΢Èí°ä²¼´ø±í¸üУ¬½¨¸´Windows 10ÖеĴúÂëÖ´Ðзì϶£»ÐÂÐͶñÒâÈí¼þGluptebaÕë¶ÔWindowsϵͳ

°ä²¼¹¦·ò 2020-07-01

1.΢Èí°ä²¼´ø±í¸üУ¬½¨¸´Windows 10ÖеĴúÂëÖ´Ðзì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Microsoft°ä²¼ÁËÁ½¸ö´ø±í°²È«¸üУ¬ÒÔ½¨¸´Ô¶³Ì´úÂëÖ´Ðзì϶¡£ÕâÁ½¸ö·ì϶±»×·×ÙΪCVE-2020-1425ºÍCVE-2020-1457£¬Ó°ÏìÁ˶à¸öWindows 10ºÍWindows Server°æ±¾£¬Æä¾ùÊÇÓÉMicrosoft Windows Codecs¿â´¦ÖÃÄÚ´æÖжÔÏóµÄ·½Ê½ÒýÆðµÄ¡£ºÚ¿Í³É¹¦ÀûÓÃCVE-2020-1425ºó£¬Äܹ»½øÒ»²½·ÛËéÓû§ÏµÍ³£¬¶ø³É¹¦ÀûÓÃCVE-2020-1457Ôò¿ÉÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒâ´úÂ롣΢Èí°µÊ¾£¬Õë¶ÔÕâÁ½¸ö·ìϼû»Óлº½â´ëÊ©£¬¸üн«ÓÉMicrosoft Store×Ô¶¯×°ÖýøÐС£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-releases-oob-security-updates-for-windows-10-rce-bugs/


2.Sophos·¢ÏÖÐÂÐͶñÒâÈí¼þGlupteba£¬Õë¶ÔWindowsϵͳ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Sophos LabsµÄ×êÑÐÈËÔ±ÔÚÒ°±í·¢ÏÖÁËÒ»ÖÖÕë¶ÔWindowsϵͳµÄÐÂÐͶñÒâÈí¼þGlupteba£¬Ëü¿ÉÔÚÖ¸±êPCÖпª·¢ºóÃÅ£¬²¢½«ÆäϰȾΪ½©Ê¬ÍøÂçµÄÒ»²¿ÃÅ¡£×êÑÐÈËÔ±°µÊ¾£¬GluptebaÓµÓÐÒñ±ÎÐÔ£¬ËüÄܹ»Âñ·üÔÚ¶ñÒâÈí¼þɾ³ý·¨Ê½ÖУ¬²¢ÀûÓÃÆäÏÂÔØ²¢Ö´ÐÐÓÐÐ§ÔØºÉ¡£Gluptebaͨ¹ýÌáȨÀ´Ö´ÐÐrootkit£¬ÇÖº¦Ö¸±êÉ豸µÄ°²È«ÐÔ¡£³ý´ËÖ®±í£¬Glupteba½«ÊÜϰȾµÄÍÆËã»úת±äΪ½©Ê¬ÍøÂçºó£¬»¹»áʹÓøÃÊܺ¦É豸ɨÃèÆäËûÒ×Êܹ¥»÷µÄÉ豸£¬²¢ÀûÓ÷ì϶EternalBlue£¬ÔÚÍøÂçÉϺáÏò´«²¼¡£


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2020/06/29/sneaky-glupteba-malware-creates-backdoor-in-windows-pcs/


3.ºÚ¿ÍÔÚ°µÍøÏúÊÛ14¼Ò¹«Ë¾µÄÊý¾Ý¿â£¬³¬¹ý1.3ÒÚÌõÊý¾Ý


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ºÚ¿ÍÔÚ°µÍøÏúÊÛÔ̺¬14¼Ò¹«Ë¾Óû§¼Í¼µÄÊý¾Ý¿â£¬²¢Ðû³ÆÕâЩ¹«Ë¾¾ùÊÇÔÚ2020Äê±»ºÚ¿ÍÈëÇֵġ£ÕâЩÊý¾Ý¿â×ܹ²Ô̺¬132957579ÌõÓû§¼Í¼£¬Ö»¹Üÿ¸öÊý¾Ý¿âÖеÄÐÅÏ¢·ÖÆç£¬µ«ÊÇËüÃǶ¼Ô̺¬Óû§ÃûºÍ¹þÏ£ÃÜÂë¡£14¼Ò¹«Ë¾±ðÀëΪDarkThrone¡¢Efun¡¢Fluke¡¢Footters¡¢HomeChef¡¢JamesDelivery¡¢KitchHike¡¢KreditPlus¡¢Minted¡¢Playwings¡¢Revelo¡¢Tokopedia¡¢YoteprestoºÍZoosk£¬ÆäÖÐÓÐ4¼Ò¹«Ë¾µÄÊý¾Ý¿âÔÚ´Óǰ¾Í±»Ð¹Â¶¹ý¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/seller-floods-hacker-forum-with-data-stolen-from-14-companies/


4.¼ÓÖÝ´óѧ¾É½ðɽ·ÖУÒÑÏòNetwalkerÖ§¸¶114ÍòÃÀÔªÊê½ð


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¼ÓÖÝ´óѧ¾É½ðɽ·ÖУ£¨UCSF£©°µÊ¾£¬ÆäÒÑÏòÀÕË÷Èí¼þ×éÖ¯NetwalkerÖ§¸¶ÁË114ÍòÃÀÔªµÄÊê½ð¡£NetwalkerÓÚ6ÔÂ3ÈÕÔÚÆäÊý¾ÝÐ¹Â©ÍøÕ¾Éϰ䲼ÐÂÎÅ£¬Ðû³ÆËüÒÑÈëÇÖÁËUCSFµÄÍøÂç²¢µÁÈ¡ÁËÎļþ£¬Ô̺¬´øÓÐÉç»á°²È«ºÅÂëµÄѧÉúÉêÇë¡¢Ô̺¬Ô±¹¤ÐÅÏ¢µÄÎļþ¼Ð£¬Ò½Ñ§×êÑкͲÆÕþÐÅÏ¢µÈ¡£UCSF°µÊ¾£¬ÆäITÈËÔ±ÔÚ6ÔÂ1ÈÕ¼ì²âµ½Á˸ÃÊÂÎñ£¬²¢¸ôÀëÁËҽѧԺÄڵöITϵͳ£¬µ«²¿ÃÅҽѧԺϵͳµÄÊý¾Ý»¹ÊDZ»¼ÓÃÜ¡£ÓÉÓÚ±»¼ÓÃܵÄÊý¾Ý¶Ô¸Ã´óѧµÄѧÊõ¹¤×÷À´Ëµ¼«¶È³ÁÒª£¬Òò¶øÆä¾ö¶¨Ö§¸¶Êê½ðÒÔ»ñµÃ½âÃܹ¤¾ß¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/uc-san-francisco-pays-114-million-for-ransomware-decryptor/


5.ESETͳ¼Æ£¬ÒßÇéÆÚ¼äRDP¾ùÔÈÿÌìÔâµ½³¬¹ý10Íò´Î¹¥»÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ESETͳ¼Æ£¬ÒßÇéÆÚ¼äºÚ¿Í¶ÔWindowsÔ¶³Ì×ÀÃæ·þÎñµÄ¹¥»÷´ÎÊýÏÕЩÔö³¤ÁËÒ»±¶£¬¾ùÔÈÿÌ쳬¹ý10Íò´Î¡£ÍøÂ簲ȫ¹«Ë¾ESET×Ô2019Äê12ÔÂ1ÈÕÒÔÀ´¼Í¼µÄÒ£²âÊý¾ÝÏÔʾ£¬Ã¿Ìì¶ÔRDPµÄ±©Á¦¹¥»÷´ÎÊý¼±¾çÔö³¤¡£´Ó2019Äê12Ôµ½2020Äê2Ô£¬Ã¿Ìì»á²úÉú40000µ½70000´Î¹¥»÷¡£×Ô2Ô·ݹ¥»÷´ÎÊýÆðÍ·ÉÏÉý£¬ÓÉÖðÈÕ80000´ÎÆðÍ·£¬µ½4ÔºÍ5Ô·ݴﵽ²»±ä£¬¾ùÔÈÖðÈÕ³¬¹ý100000´Î¹¥»÷¡£Æ¾¾ÝESETµÄµ÷²é£¬ÕâЩ¹¥»÷´ó¶àÀ´×ÔÃÀ¹ú¡¢Öйú¡¢¶íÂÞ˹¡¢µÂ¹úºÍ·¨¹úµÄIPµØÖ·£¬¶øÖ¸±êIPµØÖ·Î»ÓÚ¶íÂÞ˹¡¢µÂ¹ú¡¢°ÍÎ÷ºÍÐÙÑÀÀû¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/over-100k-daily-brute-force-attacks-on-rdp-in-pandemic-lockdown/


6.Abnormal·¢ÏÖ£¬Õë¶Ô·¢Æ±»ò¸¶¿îڲƭµÄBEC¹¥»÷Ôö³¤200£¥


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Abnormal Security·¢ÏÖ£¬´Ó2020Äê4Ôµ½2020Äê5Ô£¬Õë¶Ô·¢Æ±»ò¸¶¿îڲƭµÄBEC¹¥»÷ÒÑÔö³¤ÁË200£¥¡£¹¥»÷Õßͨ¹ý¼ÙÒ⹩¸øÉÌ»ò¿Í»§£¬Í¨¹ýÀûÓõç»ãڲƭ»ò½Ù³Ö¹©¸øÉ̶Ի°µÈ³Á¶¨ÏòÕ½ÊõÀ´ÇÔÈ¡×ʽð¡£ÓëÆäËûÀàÐ͵ÄBEC¹¥»÷Ïà±È£¬ÕâЩÀàÐ͵Ĺ¥»÷ËùÉæ¼°µÄ½ð¶îͨ³£Òª´óµÃ¶à£¬ÓÉÓÚËüÃÇÕë¶ÔµÄÊÇÆóÒµ¶ÔÆóÒµµÄÂòÂô¡£Abnormalͨ¹ý¸ú×ÙÕâÀ๥»÷£¬·¢ÏÖÿÖܾùÔȵĹ¥»÷Á¿Ìá¸ß200£¥£¬Ôâµ½´ËÀ๥»÷µÄ×éÖ¯ÊýÁ¿Ôö³¤ÁË36£¥¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2020/06/30/payment-fraud-bec-attacks/