¶ñÒâÈí¼þAlina»Ø¹é£¬ÀûÓÃDNSËí·ÇÔÊØÐÅÓþ¿¨Êý¾Ý£»CiscoÖÒ¸æÓ×ÐÍÆóÒµ»¥»»»ú´æÔÚ·ì϶£¬¿É½Ó¼ûÖÎÀí½çÃæ
°ä²¼¹¦·ò 2020-07-031.¶ñÒâÈí¼þAlina»Ø¹é£¬ÀûÓÃDNSËí·ÇÔÊØÐÅÓþ¿¨Êý¾Ý
Black Lotus Labs×êÑÐÈËÔ±·¢ÏÖPOS¶ñÒâÈí¼þAlina»Ø¹é£¬ÀûÓÃDNSËí·ÇÔÊØÐÅÓþ¿¨Êý¾Ý¡£ÔÚÐÅÓþ¿¨ÂòÂôÆÚ¼ä£¬Êý¾Ýͨ³£»á±»½âÃÜ£¬²¢ÒÔδ¼ÓÃܵĴó¾Öһʱ´æ´¢ÔÚPOS´æ´¢Æ÷ÖС£¸Ã¶ñÒâÈí¼þ»áÔÚPOSÉ豸µÄRAMÖÐËÑË÷´Ëδ¼ÓÃܵÄÐÅÓþ¿¨ÐÅÏ¢£¬²¢½«Æä·¢ËÍ»ØC2·þÎñÆ÷¡£ÎªÁËÈ·±£ÔÚÄÜÕÒµ½ÕæÊµµÄÐÅÓþ¿¨Êý¾Ý£¬¶ñÒâÈí¼þ»¹»áʹÓÃLuhnУÑéºÍËã·¨ÑéÖ¤¿¨ºÅµÄ×îºóһλÊÇ·ñΪÕýÈ·µÄУÑéλ¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/alina-point-sale-malware-ongoing-campaign/157087/
2.ÃÀ¹úCISA°ä²¼·ÀÓùÀ´×ÔTorÄäÃûÍøÂçµÄ¹¥»÷µÄÖ¸ÄÏ
ÃÀ¹úCISA°ä²¼ÁËÆäÓëFBIºÏ×÷±àдµÄÓйر£»¤ÍøÂçÃâÊÜÀ´×ÔTorÄäÃûÍøÂçÌáÒéµÄÍøÂç¹¥»÷µÄÖ¸ÄÏ£¬½éÉÜÁ˺ڿÍÔÚ¹¥»÷»î¶¯ÖÐʹÓÃTor½øÐÐÄäÃûµÄ¼¼Êõϸ½Ú¡£¸ÃÖ¸ÄÏÖеÄʾÀýÔ̺¬Ö´ÐпúËÅ¡¢ÉøÈëϵͳ¡¢ÇÔÈ¡ºÍ°Ñ³ÖÊý¾Ý¡¢ÒÔ¼°Í¨¹ý»Ø¾ø·þÎñ¹¥»÷ºÍÀÕË÷Èí¼þÓÐÐ§ÔØºÉµÄ´«µÝʹ·þÎñÍÑ»ú¡£´Ë±í£¬CISAºÍFBI½¨Ò鹫˾ºÍ×é֯ͨ¹ýÆÀ¹ÀËûÃÇÒòTorÔì³ÉµÄÓ×ÎÒ·çÏÕ·çÏÕ£¬À´²ÉÈ¡Êʵ±µÄ»º½â´ëÊ©£¬ÒÔ×èÖ¹»ò¼à¶½À´×ÔÒÑÖªTor½ÚµãµÄÈëÕ¾ºÍ³öÕ¾Á÷Á¿¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/us-govt-shares-tips-on-defending-against-cyberattacks-via-tor/
3.ÃÀ¹úNSA°ä²¼Óйر£»¤IPsecÐ鹹רÓÃÍøÂçµÄÖ¸ÄÏ
ÃÀ¹ú¹ú¶È°²È«¾Ö£¨NSA£©°ä²¼ÁËÓйØÈôºÎÕýÈ·±£»¤IP°²È«£¨IPsec£©Ð鹹רÓÃÍø£¨VPN£©ÃâÊÜDZÔÚ¹¥»÷µÄÖ¸ÄÏ¡£¸ÃÖ¸ÄϳýÁËΪ×éÖ¯ÌṩÓйØÈôºÎ±£»¤IPsecµÄ½¨Òé±í£¬»¹Ç¿µ÷ÁËʹÓÃ׳´óµÄ¼ÓÃܼ¼Êõ±£»¤Á÷Á¿ÖÐÔ̺¬µÄÃô¸ÐÐÅÏ¢£¬ÒÔ¼°ÔÚÏνӵ½Ô¶³Ì·þÎñÆ÷ʱ±éÀú²»ÊÜÐÅÀµµÄÍøÂçµÄ³ÁÒªÐÔ¡£NSA°µÊ¾VPNÊÇÆôÓÃÔ¶³Ì½Ó¼ûºÍ°²È«ÏνÓÔ¶³ÌÕ¾µãËù±ØÐëµÄ£¬µ«Ã»ÓÐÊʵ±µÄÅäÖᢲ¹¶¡ÖÎÀí¡¢ºÍ¼Ó¹ÌµÄVPNÊÇÈÝÒ×Êܵ½¹¥»÷¡£NSA½¨ÒéÏ÷¼õVPNÍø¹ØµÄ¹¥»÷Ãæ£¬ÑéÖ¤¼ÓÃÜËã·¨ÊÇ·ñÇкϹú¶È°²ÕûϵͳÕþ²ßίԱ»á£¨CNSSP£©15µÄ»®¶¨£¬Ô¤·ÀʹÓÃĬÈϵÄVPNÉèÖã¬É¾³ýδʹÓûò²»ÇкÏÒªÇóµÄ¼ÓÃÜÌ×¼þ£¬ÒÔ¼°ÊµÊ±¸üÐÂVPNÍø¹ØºÍ¿Í»§¶Ë¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/nsa-releases-guidance-on-securing-ipsec-virtual-private-networks/
4.ÃÀ¹úÊýÊ®¸öÐÂÎÅÍøÕ¾Ôâµ½ÀÕË÷Èí¼þWastedLocker¹¥»÷
SymantecÍþвµý±¨×êÑÐÈËԱ֤ʵ£¬Evil CorpÈëÇÖÁË30¶à¼ÒÃÀ¹ú´óÐÍ˽Ӫ¹«Ë¾£¬¶øÕâЩ¹«Ë¾ÆìϵÄÊýÊ®¼ÒÐÂÎÅÍøÕ¾Ò²Ôâµ½Á˹¥»÷¡£ºÚ¿ÍʹÓÃÁË»ùÓÚJavaScriptµÄ¶ñÒâSocGholish¿ò¼Ü½øÐй¥»÷£¬Ê×ÏÈͨ¹ý·¢ËÍαÔìµÄÈí¼þ¸üÐÂÌáÐÑ·Ö·¢¶ñÒâÈí¼þÓÐÐ§ÔØºÉ¡£Ò»µ©¹«Ë¾Ô±¹¤±»Ï°È¾ºó£¬ºÚ¿Í¾Í»áʹÓÃCobalt StrikeÍþв·ÂÕæÈí¼þºÍһЩԶ³Ì¹¤¾ßÇÔȡʹ´¦¡¢ÌáÉýȨÏÞ²¢ÔÚÍøÂçÉÏÒÆ¶¯£¬×îÖÕ×°ÖÃÀÕË÷Èí¼þWastedLocker¡£²¢ÇÒ£¬ÔÚ×°ÖÃÀÕË÷Èí¼þ֮ǰ£¬ËûÃÇ»¹Ê¹ÓÃPowerShell¾ç±¾ºÍºÏ·¨¹¤¾ßÔÚÊܺ¦ÕßµÄÍøÂçÉϽûÓÃWindows Defender¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/dozens-of-us-news-sites-hacked-in-wastedlocker-ransomware-attacks/
5.CiscoÖÒ¸æÆäÓ×ÐÍÆóÒµ»¥»»»ú´æÔÚ·ì϶£¬¿É½Ó¼ûÖÎÀí½çÃæ
Cisco SystemsÖÒ¸æ³Æ£¬Ò»¸öÑϳÁµÄ·ì϶ӰÏìÁËÆä7¿îÓ×ÐÍÆóÒµ»¥»»»ú£¬¸Ã·ì϶¿Éʹδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß»ñµÃCiscoÓ×ÐÍÆóÒµ»¥»»»úµÄÖÎÀíȨÏÞ¡£¸Ã·ì϶£¨CVE-2020-3297£©²úÉúµÄÔÒòÔÚÓÚʹÓÃÈõìØÌìÉú»á»°±êʶ·ûÖµ¡£Ë¼¿ÆµÄ´«µÝ³Æ£¬¹¥»÷ÕßÄܹ»Í¨¹ý±©Á¦¹¥»÷ÀûÓô˷ì϶À´È·¶¨µ±Ç°»á»°±êʶ·û£¬¶øºó³ÁÓøûỰ±êʶ·ûÀ´ÊÕÊÜÔÚ½øÐеĻỰ¡£ÊÜ´Ë·ì϶ӰÏìµÄ²úÆ·ÓУºCisco 250ϵÁÐÖÇÄÜ»¥»»»ú¡¢350ϵÁÐÖÎÀíÐÍ»¥»»»ú¡¢350XϵÁпɶѵþÖÎÀíÐÍ»¥»»»ú¡¢550XϵÁпɶѵþÖÎÀíÐÍ»¥»»»ú¡¢Small Business 200ϵÁÐÖÇÄÜ»¥»»»ú¡¢Small Business 300ϵÁÐÖÎÀíÐÍ»¥»»»úºÍSmall Business 500ϵÁпɶѵþÖÎÀíÐÍ¿ª¹Ø¡£Ë¼¿ÆÔڹ̼þ°æ±¾2.5.5.47Öн¨¸´ÁËÕâ¸ö·ì϶¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/cisco-warns-high-severity-bug-small-business-switch/157090/
6.¾Ýͳ¼Æ£¬2020 Q1 DDoS¹¥»÷±ÈÈ¥Äêͬ±ÈÔö³¤278£¥
ƾ¾ÝNexusguardµÄÊý¾Ý£¬2020ÄêµÚÒ»¼¾¶ÈµÄDDoS¹¥»÷ÊýÁ¿Óë2019ÄêµÚÒ»¼¾¶ÈÏà±ÈÔö³¤ÁË278£¥ÒÔÉÏ£¬ÓëÉÏÒ»¼¾¶ÈÏà±ÈÔö³¤ÁË542£¥ÒÔÉÏ¡£µ÷²éÁ˾ÖÅú×¢£¬Ë鯬¹¥»÷ÔÚ³ÖÐøÉøÈ봫ͳµÄãÐÖµ¼ì²â£¬ÕâЩ¹¥»÷µÄÁ˾ÖÊǽ«´óÁ¿À¬»øÁ÷Á¿»ãÈëÒ»¸ö´óµÄIP³Ø£¬µ±·ÖÆçIPÆðÍ·ÀÛ»ýʱ£¬ÕâЩÀ¬»øÁ÷Á¿»á×èÈûÖ¸±ê¡£¸Ã»ã±¨Åú×¢£¬90%µÄ¹¥»÷ʹÓõÄÊǵ¥Ê¸Á¿¹¥»÷£¬ÕâÓë´ÓǰʢÐеĶàʸÁ¿¹¥»÷ÓÐËù·ÖÆç¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2020/07/02/q1-2020-ddos-attacks/


¾©¹«Íø°²±¸11010802024551ºÅ