¶ñÒâÈí¼þAlina»Ø¹é £¬ÀûÓÃDNSËí·ÇÔÊØÐÅÓþ¿¨Êý¾Ý £»CiscoÖÒ¸æÓ×ÐÍÆóÒµ»¥»»»ú´æÔÚ·ì϶ £¬¿É½Ó¼ûÖÎÀí½çÃæ

°ä²¼¹¦·ò 2020-07-03

1.¶ñÒâÈí¼þAlina»Ø¹é £¬ÀûÓÃDNSËí·ÇÔÊØÐÅÓþ¿¨Êý¾Ý


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Black Lotus Labs×êÑÐÈËÔ±·¢ÏÖPOS¶ñÒâÈí¼þAlina»Ø¹é £¬ÀûÓÃDNSËí·ÇÔÊØÐÅÓþ¿¨Êý¾Ý¡£ÔÚÐÅÓþ¿¨ÂòÂôÆÚ¼ä £¬Êý¾Ýͨ³ £»á±»½âÃÜ £¬²¢ÒÔδ¼ÓÃܵĴó¾Öһʱ´æ´¢ÔÚPOS´æ´¢Æ÷ÖС£¸Ã¶ñÒâÈí¼þ»áÔÚPOSÉ豸µÄRAMÖÐËÑË÷´Ëδ¼ÓÃܵÄÐÅÓþ¿¨ÐÅÏ¢ £¬²¢½«Æä·¢ËÍ»ØC2·þÎñÆ÷¡£ÎªÁËÈ·±£ÔÚÄÜÕÒµ½ÕæÊµµÄÐÅÓþ¿¨Êý¾Ý £¬¶ñÒâÈí¼þ»¹»áʹÓÃLuhnУÑéºÍËã·¨ÑéÖ¤¿¨ºÅµÄ×îºóһλÊÇ·ñΪÕýÈ·µÄУÑéλ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/alina-point-sale-malware-ongoing-campaign/157087/


2.ÃÀ¹úCISA°ä²¼·ÀÓùÀ´×ÔTorÄäÃûÍøÂçµÄ¹¥»÷µÄÖ¸ÄÏ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹úCISA°ä²¼ÁËÆäÓëFBIºÏ×÷±àдµÄÓйر £»¤ÍøÂçÃâÊÜÀ´×ÔTorÄäÃûÍøÂçÌáÒéµÄÍøÂç¹¥»÷µÄÖ¸ÄÏ £¬½éÉÜÁ˺ڿÍÔÚ¹¥»÷»î¶¯ÖÐʹÓÃTor½øÐÐÄäÃûµÄ¼¼Êõϸ½Ú¡£¸ÃÖ¸ÄÏÖеÄʾÀýÔ̺¬Ö´ÐпúËÅ¡¢ÉøÈëϵͳ¡¢ÇÔÈ¡ºÍ°Ñ³ÖÊý¾Ý¡¢ÒÔ¼°Í¨¹ý»Ø¾ø·þÎñ¹¥»÷ºÍÀÕË÷Èí¼þÓÐÐ§ÔØºÉµÄ´«µÝʹ·þÎñÍÑ»ú¡£´Ë±í £¬CISAºÍFBI½¨Ò鹫˾ºÍ×é֯ͨ¹ýÆÀ¹ÀËûÃÇÒòTorÔì³ÉµÄÓ×ÎÒ·çÏÕ·çÏÕ £¬À´²ÉÈ¡Êʵ±µÄ»º½â´ëÊ© £¬ÒÔ×èÖ¹»ò¼à¶½À´×ÔÒÑÖªTor½ÚµãµÄÈëÕ¾ºÍ³öÕ¾Á÷Á¿¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-govt-shares-tips-on-defending-against-cyberattacks-via-tor/


3.ÃÀ¹úNSA°ä²¼Óйر £»¤IPsecÐ鹹רÓÃÍøÂçµÄÖ¸ÄÏ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹ú¹ú¶È°²È«¾Ö£¨NSA£©°ä²¼ÁËÓйØÈôºÎÕýÈ·± £»¤IP°²È«£¨IPsec£©Ð鹹רÓÃÍø£¨VPN£©ÃâÊÜDZÔÚ¹¥»÷µÄÖ¸ÄÏ¡£¸ÃÖ¸ÄϳýÁËΪ×éÖ¯ÌṩÓйØÈôºÎ± £»¤IPsecµÄ½¨Òé±í £¬»¹Ç¿µ÷ÁËʹÓÃ׳´óµÄ¼ÓÃܼ¼Êõ± £»¤Á÷Á¿ÖÐÔ̺¬µÄÃô¸ÐÐÅÏ¢ £¬ÒÔ¼°ÔÚÏνӵ½Ô¶³Ì·þÎñÆ÷ʱ±éÀú²»ÊÜÐÅÀµµÄÍøÂçµÄ³ÁÒªÐÔ¡£NSA°µÊ¾VPNÊÇÆôÓÃÔ¶³Ì½Ó¼ûºÍ°²È«ÏνÓÔ¶³ÌÕ¾µãËù±ØÐëµÄ £¬µ«Ã»ÓÐÊʵ±µÄÅäÖᢲ¹¶¡ÖÎÀí¡¢ºÍ¼Ó¹ÌµÄVPNÊÇÈÝÒ×Êܵ½¹¥»÷¡£NSA½¨ÒéÏ÷¼õVPNÍø¹ØµÄ¹¥»÷Ãæ £¬ÑéÖ¤¼ÓÃÜËã·¨ÊÇ·ñÇкϹú¶È°²ÕûϵͳÕþ²ßίԱ»á£¨CNSSP£©15µÄ»®¶¨ £¬Ô¤·ÀʹÓÃĬÈϵÄVPNÉèÖà £¬É¾³ýδʹÓûò²»ÇкÏÒªÇóµÄ¼ÓÃÜÌ×¼þ £¬ÒÔ¼°ÊµÊ±¸üÐÂVPNÍø¹ØºÍ¿Í»§¶Ë¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/nsa-releases-guidance-on-securing-ipsec-virtual-private-networks/


4.ÃÀ¹úÊýÊ®¸öÐÂÎÅÍøÕ¾Ôâµ½ÀÕË÷Èí¼þWastedLocker¹¥»÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


SymantecÍþвµý±¨×êÑÐÈËԱ֤ʵ £¬Evil CorpÈëÇÖÁË30¶à¼ÒÃÀ¹ú´óÐÍ˽Ӫ¹«Ë¾ £¬¶øÕâЩ¹«Ë¾ÆìϵÄÊýÊ®¼ÒÐÂÎÅÍøÕ¾Ò²Ôâµ½Á˹¥»÷¡£ºÚ¿ÍʹÓÃÁË»ùÓÚJavaScriptµÄ¶ñÒâSocGholish¿ò¼Ü½øÐй¥»÷ £¬Ê×ÏÈͨ¹ý·¢ËÍαÔìµÄÈí¼þ¸üÐÂÌáÐÑ·Ö·¢¶ñÒâÈí¼þÓÐÐ§ÔØºÉ¡£Ò»µ©¹«Ë¾Ô±¹¤±»Ï°È¾ºó £¬ºÚ¿Í¾Í»áʹÓÃCobalt StrikeÍþв·ÂÕæÈí¼þºÍһЩԶ³Ì¹¤¾ßÇÔȡʹ´¦¡¢ÌáÉýȨÏÞ²¢ÔÚÍøÂçÉÏÒÆ¶¯ £¬×îÖÕ×°ÖÃÀÕË÷Èí¼þWastedLocker¡£²¢ÇÒ £¬ÔÚ×°ÖÃÀÕË÷Èí¼þ֮ǰ £¬ËûÃÇ»¹Ê¹ÓÃPowerShell¾ç±¾ºÍºÏ·¨¹¤¾ßÔÚÊܺ¦ÕßµÄÍøÂçÉϽûÓÃWindows Defender¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/dozens-of-us-news-sites-hacked-in-wastedlocker-ransomware-attacks/


5.CiscoÖÒ¸æÆäÓ×ÐÍÆóÒµ»¥»»»ú´æÔÚ·ì϶ £¬¿É½Ó¼ûÖÎÀí½çÃæ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Cisco SystemsÖÒ¸æ³Æ £¬Ò»¸öÑϳÁµÄ·ì϶ӰÏìÁËÆä7¿îÓ×ÐÍÆóÒµ»¥»»»ú £¬¸Ã·ì϶¿Éʹδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß»ñµÃCiscoÓ×ÐÍÆóÒµ»¥»»»úµÄÖÎÀíȨÏÞ¡£¸Ã·ì϶£¨CVE-2020-3297£©²úÉúµÄÔ­ÒòÔÚÓÚʹÓÃÈõìØÌìÉú»á»°±êʶ·ûÖµ¡£Ë¼¿ÆµÄ´«µÝ³Æ £¬¹¥»÷ÕßÄܹ»Í¨¹ý±©Á¦¹¥»÷ÀûÓô˷ì϶À´È·¶¨µ±Ç°»á»°±êʶ·û £¬¶øºó³ÁÓøûỰ±êʶ·ûÀ´ÊÕÊÜÔÚ½øÐеĻỰ¡£ÊÜ´Ë·ì϶ӰÏìµÄ²úÆ·ÓУºCisco 250ϵÁÐÖÇÄÜ»¥»»»ú¡¢350ϵÁÐÖÎÀíÐÍ»¥»»»ú¡¢350XϵÁпɶѵþÖÎÀíÐÍ»¥»»»ú¡¢550XϵÁпɶѵþÖÎÀíÐÍ»¥»»»ú¡¢Small Business 200ϵÁÐÖÇÄÜ»¥»»»ú¡¢Small Business 300ϵÁÐÖÎÀíÐÍ»¥»»»úºÍSmall Business 500ϵÁпɶѵþÖÎÀíÐÍ¿ª¹Ø¡£Ë¼¿ÆÔڹ̼þ°æ±¾2.5.5.47Öн¨¸´ÁËÕâ¸ö·ì϶¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/cisco-warns-high-severity-bug-small-business-switch/157090/


6.¾Ýͳ¼Æ £¬2020 Q1 DDoS¹¥»÷±ÈÈ¥Äêͬ±ÈÔö³¤278£¥


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝNexusguardµÄÊý¾Ý £¬2020ÄêµÚÒ»¼¾¶ÈµÄDDoS¹¥»÷ÊýÁ¿Óë2019ÄêµÚÒ»¼¾¶ÈÏà±ÈÔö³¤ÁË278£¥ÒÔÉÏ £¬ÓëÉÏÒ»¼¾¶ÈÏà±ÈÔö³¤ÁË542£¥ÒÔÉÏ¡£µ÷²éÁ˾ÖÅú×¢ £¬Ë鯬¹¥»÷ÔÚ³ÖÐøÉøÈ봫ͳµÄãÐÖµ¼ì²â £¬ÕâЩ¹¥»÷µÄÁ˾ÖÊǽ«´óÁ¿À¬»øÁ÷Á¿»ãÈëÒ»¸ö´óµÄIP³Ø £¬µ±·ÖÆçIPÆðÍ·ÀÛ»ýʱ £¬ÕâЩÀ¬»øÁ÷Á¿»á×èÈûÖ¸±ê¡£¸Ã»ã±¨Åú×¢ £¬90%µÄ¹¥»÷ʹÓõÄÊǵ¥Ê¸Á¿¹¥»÷ £¬ÕâÓë´ÓǰʢÐеĶàʸÁ¿¹¥»÷ÓÐËù·ÖÆç¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2020/07/02/q1-2020-ddos-attacks/