F5 BIG-IP·ì϶CVE-2020-5902Òѱ»ÀûÓ㬽¨Ò龡¿ìÉý¼¶ £».NET Core¿âÖзì϶¿É±»ÀûÓñܿªÉ±¶¾Èí¼þ¼ì²â

°ä²¼¹¦·ò 2020-07-06

1.F5 BIG-IP·ì϶CVE-2020-5902ÒÑÔâµ½ÀûÓ㬽¨ÒéÓû§¾¡¿ìÉý¼¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


NCCµÄ°²È«×êÑÐÔ±·¢ÏÖ£¬ºÚ¿ÍÒѾ­ÆðÍ·ÀûÓÃF5 BIG-IPÖеķì϶£¨CVE-2020-5902£©ÌáÒé¹¥»÷£¬Ö¼ÔÚ´Ó±»ÈëÇÖµÄÉ豸ÖÐÇÔÈ¡ÖÎÀíÔ±ÃÜÂë¡£ÉÏÖÜÈý¸Ã·ì϶¹«¿ªºó£¬ÍøÂ簲ȫר¼Òµ±¼´·¢³öÓйش¹Î£½¨²¹´Ë·ì϶µÄ¾¯±¨£¬ÓÉÓÚÈκγɹ¦µÄ¹¥»÷¶¼½«Ê¹¹¥»÷Õ߯ëÈ«½Ó¼ûÊÀ½çÉÏ×î³ÁÒªµÄITÍøÂç¡£Warren³Æ£¬ÔÚÃÀ¹úÍøÂç˾ÁµÄÖÒ¸æÍÆÎİ䲼¼¸Ó×ʱºó£¬ËûÔÚBIG-IPÃÛ¹ÞÖмì²âµ½À´×ÔÎå¸ö·ÖÆçIPµØÖ·µÄ¶ñÒâ¹¥»÷¡£ÔÚ¹²ÏíµÄÈÕÖ¾ÖУ¬WarrenÖ¸³öÁËÕâЩ¹¥»÷µÄÆðÔ´£¬²¢Äܹ»È·ÈÏËüÃÇÊǶñÒâµÄ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hackers-are-trying-to-steal-admin-passwords-from-f5-big-ip-devices/


2..NET Core¿âÖдæÔÚ·ì϶£¬¿É±»ÀûÓñܿªÉ±¶¾Èí¼þµÄ¼ì²â


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Context Information SecurityµÄPaulLa?n¨¦·¢ÏÖ.NET Core¿âÖдæÔÚ·ì϶£¬ÔÊÐí¹¥»÷Õ߱ܿªÉ±¶¾Èí¼þµÄ¼ì²âÀ´Ö´ÐжñÒâ´úÂë¡£¸Ã·ì϶ӰÏìÁË.NET Core µÄ×îв»±ä°æ±¾£¨3.1.x°æ±¾£©£¬ÊÇÓÉMicrosoft .NET Core¿âÖеÄõè¾¶±éÀú·ì϶ÒýÆðµÄ£¬ÆäÔÊÐíÓµÓеÍÌØÈ¨µÄÓû§¼ÓÔØ¶ñÒâÀ¬»ø»ØÊÕDLL¡£µ«ÊÇ£¬¹¥»÷Õß±ØÒªÓµÓп϶¨µÄ½Ó¼ûȨÏÞÄÜÁ¦ÉèÖû·¾³±äÁ¿À´ÀûÓô˷ì϶£¬ÕâÒâζן÷ì϶±ØÒªÓëÏÖÓзì϶½áºÏʹÓá£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/net-core-vulnerability-lets-attackers-evade-malware-detection/


3.KELA·¢ÏÖºÚ¿ÍÔÚ°µÍøÏúÊÛ³¬¹ý38ÍòÓ¢¹ú±¦Âí³µÖ÷ÐÅÏ¢


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°µÍøÍþвµý±¨¹«Ë¾KELA°µÊ¾£¬ºÚ¿Í×éÖ¯KelvinSecurity TeamÔÚ°µÍøÉÏÏúÊÛÓ¢¹ú384319Ãû±¦Âí³µÖ÷µÄÊý¾Ý£¬Ô̺¬ÐÕÃûµÄÊ××ÖĸºÍÐÕÊÏ¡¢µç×ÓÓʼþ¡¢µØÖ·¡¢³µÁ¾±àºÅ¡¢¾­ÏúÉÌÃû³ÆÒÔ¼°ÆäËûÐÅÏ¢¡£ºÚ¿ÍÐû³ÆÕâЩÊý¾ÝÀ´×ÔÓÃÓÚÖÎÀí·ÖÆçÆû³µ¹©¸øÉ̿ͻ§µÄºô½ÐÖÐÐÄ£¬¸ÃÊý¾Ý¿âÔ̺¬ÁË2016ÄêÖÁ2018ÄêµÄ½ü50Íò·Ý¿Í»§¼Í¼£¬Ò²Ó°ÏìÁËÆäËûÆ·ÅÆµÄÓ¢¹ú³µÖ÷£¬Ô̺¬Ã·ÈüµÂ˹¡¢Î÷ÑÅÌØ¡¢±¾ÌïºÍÏÖ´úµÈ¡£KELA°µÊ¾¸ÃºÚ¿Í×éÖ¯ÔÚ°µÍøÉϷdz £»îÔ¾£¬½öÔÚ2020Äê6Ô¾ÍÏúÊÛÁË16¸öÊý¾Ý¿â£¬ÆäÖÐÔ̺¬ÓëÃÀ¹úµ±¾Ö³Ð°üÉ̺ͶíÂÞ˹¾üʱøÆ÷¿ª·¢ÓйصÄÊý¾Ý¡£


Ô­ÎÄÁ´½Ó£º

https://www.scmagazine.com/home/security-news/bmw-customer-database-for-sale-on-dark-web/?web_view=true


4.DuckDuckGoδ¾­Ô޳ɼ´¸ú×ÙÍøÂçÓû§ä¯ÀÀÊý¾Ý


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


TwitterÉϵÄÒ»Ãû·µÂºÚ¿Í°µÊ¾£¬DuckDuckGoδ¾­Ô޳ɼ´¸ú×ÙÍøÂçÓû§ä¯ÀÀÊý¾Ý¡£¸ÃÎÊÌâʼÓÚËÑËØÒýÇæÔÚicons.duckduckgo.comµÄÒ»¸ö·þÎñÆ÷ÉÏ´æ´¢ÁËÍøÕ¾µÄͼ±ê¡£Òò¶ø£¬Èç¹ûÓû§Ç¡ÇɽӼûÁ˸ÃÍøÕ¾£¬DuckDuckGoµÄAndroidä¯ÀÀÆ÷»áÒªÇóÆä·þÎñÆ÷½«Óû§µÄä¯ÀÀÊý¾Ý´«Ë͵½¸Ã·þÎñÆ÷£¬¶øÎÞÐèѯÎÊÓû§¡£ÕâÒâζ×ÅÓû§Äܹ»±»È·ÈÏÆä½Ó¼ûÁËij¸öÌØ¶¨ÍøÕ¾£¬´Ó¶øÓ°ÏìÁËËûÃǵÄÄäÃûÐÔ¡£Ä¿Ç°£¬ DuckDuckGoÒѽâ¾ö´ËÎÊÌ⣬´Ë¿ÌÄܹ»Ö±½Ó´ÓÍøÕ¾ÉÏ»ñȡͼ±ê¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/duckduckgo-collects-user-without-browsing-data/


5.ÐÂÀÕË÷Èí¼þTry2Cryͨ¹ýϰȾUSBÉÁ´æÇý¶¯Æ÷´«²¼


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


G2 DATA¶ñÒâÈí¼þ·ÖÎöʦKarsten Hahn·¢ÏÖÁËÐÂÀÕË÷Èí¼þTry2Cry£¬ÆäÕýÊÔͼͨ¹ýϰȾUSBÉÁ´æÇý¶¯Æ÷ÔÚWindowsÍÆËã»úÉÏ´«²¼¡£Try2CryÊÇ.NETÀÕË÷Èí¼þ£¬ÊÇHannÔÚ·ÖÎöÁËDNGuard´úÂë± £»¤¹¤¾ß»ìºÏµÄÑù±¾ºó·¢ÏֵĿªÔ´ÀÕË÷Èí¼þStupid¼Ò×åµÄÁíÒ»¸ö±äÖÖ¡£¸ÃÀÕË÷Èí¼þϰȾÉ豸ºó£¬½«Ê¹ÓöԳÆÃÜÔ¿¼ÓÃÜËã·¨RijndaelºÍÓ²±àÂë¼ÓÃÜÃÜÔ¿£¬¶Ô.doc¡¢.ppt¡¢.jpg¡¢.xls¡¢.pdf¡¢.docx¡¢.pptx¡¢.xlsºÍ.xlsxÎļþ½øÐмÓÃÜ£¬²¢ÔÚËùÓмÓÃÜÎļþºó¸½¼Ó.Try2CryÀ©´óÃû¡£¸ÃÀÕË÷Èí¼þ»¹ÓµÓйÊÕϱ £»¤Ö°ÄÜ£¬ÔÚÍÆËã»úÃû³ÆÎªDESKTOP-PQ6NSM4»òIK-PC2µÄϵͳÉÏÌø¹ý¼ÓÃÜ·¨Ê½£¬ÒÔ±£ÕÏ¿ª·¢ÕßÔÚ×Ô¼ºµÄÉ豸ÉϲâÊÔÀÕË÷Èí¼þʱ²»»áÎÞÒâÖÐËø¶¨×Ô¼ºµÄÎļþ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/try2cry-ransomware-tries-to-worm-its-way-to-other-windows-systems/


6.SodinokibiϰȾ°ÍÎ÷µçÁ¦¹«Ë¾Light SA£¬Ë÷Òª1400ÍòÃÀÔªÊê½ð


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÀÕË÷Èí¼þSodinokibiϰȾÁ˰ÍÎ÷µçÁ¦¹«Ë¾Light SA£¬²¢Ë÷Òª1400ÍòÃÀÔªÊê½ð¡£AppGateµÄ×êÑÐÈËÔ±·ÖÎöÁ˶ñÒâÈí¼þµÄÑù±¾£¬È·ÈϸÃÑùÕý±¾×ÔÒ»¸öÃûΪSodinokibi£¨±ðÃûREvil£©µÄ¼Ò×å¡£¸¶¿îÒ³ÃæÍйÜÔÚTorÍøÂçÉÏ£¬ºÚ¿ÍÒªÇóÊܺ¦ÕßÔÚ6ÔÂ19ÈÕ֮ǰ֧¸¶106870.19 XMR£¨Monero£©µÄÊê½ð£¬ÆÚÏÞÒѵ½£¬Êê½ð½ð¶î·­ÁËÒ»·¬(215882.8 XMR)£¬Ô¼ÄªÎª1400ÍòÃÀÔª¡£×êÑÐÈËÔ±°µÊ¾£¬Õû¸ö¹¥»÷¿´ÆðÀ´¼«¶Èרҵ£¬ÍøÒ³ÉõÖÁÔ̺¬Ì¸ÌìÖ§³Ö£¬Êܺ¦ÕßÄܹ»Ö±½ÓÓë¹¥»÷Õß½»Ì¸¡£SodinokibiµÄÔË×÷ģʽÊÇRaaS£¬¶ø¸ÃÐж¯±³ºóµÄ×éÖ¯ËÆºõ´ÓÊôÓÚPinchy Spider¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/105477/cyber-crime/sodinokibi-ransomware-light-s-a.html