˼¿Æ°ä²¼¶àÖÖ²úÆ·µÄ°²È«¸üУ¬½¨¸´´úÂëÖ´Ðзì϶£»Ghost Squad¹¥»÷Å·ÖÞº½Ìì¾Ö(ESA)£¬ÍøÕ¾ÁÙʱÎÞ·¨½Ó¼û
°ä²¼¹¦·ò 2020-07-171.˼¿Æ°ä²¼¶àÖÖ²úÆ·µÄ°²È«¸üУ¬½¨¸´´úÂëÖ´Ðзì϶
˼¿Æ°ä²¼Á˰²È«¸üУ¬½¨¸´Ó°Ïì¶à¸ö²úÆ·µÄ·ì϶£¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÀûÓÃÆäÖеÄijЩ·ì϶À´½ÚÔìÊÜÓ°Ïìϵͳ¡£Õâ´Î½¨¸´µÄ½ÏΪÑϳÁµÄ·ì϶Ô̺¬Ó×ÐÍÆóÒµ·À»ðǽRV110W Wireless-N VPN¾²Ì¬Ä¬ÈÏÍ´´¦·ì϶£¨CVE-2020-3330£©¡¢Ó×ÐÍÆóҵ·ÓÉÆ÷RV110W¡¢RV130¡¢RV130WºÍRV215WÖÎÀí½Ó¿ÚÔ¶³ÌºÅÁîÖ´Ðзì϶£¨CVE-2020-3323£©¡¢RV110W¡¢RV130¡¢RV130WºÍRV215W·ÓÉÆ÷Éí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2020-3144£©¡¢RV110WºÍRV215WϵÁзÓÉÆ÷ËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2020-3331£©£¬ÒÔ¼°Cisco Prime License ManagerÌØÈ¨Éý¼¶·ì϶£¨CVE-2020-3140£©¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2020/07/15/cisco-releases-security-updates-multiple-products
2.Ghost Squad¹¥»÷Å·ÖÞº½Ìì¾Ö(ESA)£¬ÍøÕ¾ÁÙʱÎÞ·¨½Ó¼û
ºÚ¿Í×éÖ¯Ghost Squad Hackers¹¥»÷ÁËÅ·ÖÞº½Ìì¾Ö(ESA)£¬²¢µ¼ÖÂÆäÍøÕ¾ÁÙʱÎÞ·¨½Ó¼û¡£ÔÚÕâ´Î¹¥»÷ÖУ¬ºÚ¿ÍÀûÓ÷þÎñÆ÷ÖеķþÎñÆ÷¶ËÒªÇóαÔ죨SSRF£©Ô¶³Ì´úÂëÖ´Ðзì϶£¬»ñµÃÁ˶Ôbusiness.esa.intÓòµÄ½Ó¼ûȨ²¢¶ÔÆä½øÐÐÁË·ÛËé¡£¸Ã×éÖ¯³ÉÔ±s1ege°µÊ¾£¬ËûÃÇÊǺڿÍÖ÷ÒåÕߣ¬Í¨³£»áÒò¼¤½øÖ÷ÒåµÄÔÒòÌáÒé¹¥»÷£¬¶øÕâ´Î¹¥»÷´¿ÕýÊdzöÓÚÓéÀÖÖ÷ÕÅ¡£¸Ã×éÖ¯ÔÚ½ü¼¸ÄêÒѾÈëÇÖÁ˺ܶà×éÖ¯ºÍµ±¾Ö»ú¹¹£¬Ô̺¬ÃÀ¾ü¡¢Å·ÃË¡¢»ªÊ¢¶ÙÌØÇø¡¢ÒÔÉ«Áйú·À¾ü¡¢Ó¡¶Èµ±¾ÖºÍһЩÖÐÑëÒøÐС£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/105918/hacktivism/european-space-agency-esa-site-defacement.html?utm_source=rss&utm_medium=rss&utm_campaign=european-space-agency-esa-site-defacement
3.Å·ÖÞ³öÏÖÐÂÐ͵ÄATMºÚºÐ¹¥»÷£¬Õë¶ÔProCash 2050xe ATMÖÕ¶Ë
ATMÔì×÷ÉÌDiebold NixdorfÖÒ¸æÒøÐУ¬×î½üÔÚÅ·ÖÞ·¢ÏÖÁËÒ»ÖÖÐÂÐ͵ÄATMºÚºÐ¹¥»÷£¬ÕâÊÇÒ»ÖÖÍ·½±£¨Jackpotting£©¹¥»÷£¬Ôâµ½¹¥»÷µÄATM »áÏñÖÐÁËÍ·½±µÄÀÏ»¢»úÒ»Ñù£¬²»ÐÝͳöÏֽ𡣴ËÐÂÐ͹¥»÷½öÕë¶ÔProCash 2050xe ATMÖÕ¶Ë£¬¹¥»÷Õßͨ¹ýUSB¶Ë¿ÚÏνӵ½É豸¡£ºÚ¿ÍÊ×ÏÈ·ÛË鲿ÃŽṹÒÔ±ã½øÈë»úеÄÚ²¿£¬½ÓÏÂÀ´°ÎµôCMD-V4·ÖÅäÆ÷ºÍרÓõç×ÓÉ豸֮¼äµÄUSBÏߣ¬»òÕßרÓõç×ÓÉ豸ºÍATM PCÖ®¼äµÄÏߣ¬²¢½«ÕâÌõÏßÏνӵ½¹¥»÷ÕߵĺںУ¬ÒÔ·¢ËÍ·¸·¨ºÅÁĿǰ£¬¸Ã¹«Ë¾ÔÚµ÷²éºÚ¿ÍÊÇÈôºÎ»ñµÃÕâЩÁã¼þµÄ¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/diebold-nixdorf-warns-of-a-new-class-of-atm-black-box-attacks-across-europe/#ftag=RSSbaffb68
4.кóÃÅBazarÓëTrickbotÓйأ¬Õë¶ÔµÄÖ¸±êÊÇÃÀ¹úºÍÅ·ÖÞ
Cybereason Nocturnus×êÑÐÓ××é·¢ÏÖÁËкóÃÅBazarÓëTrickbotÓйأ¬×Ô½ñÄê4ÔÂÒÔÀ´£¬¸ÃºóÃÅÒѱ»ÓÃÓÚ¹¥»÷ÃÀ¹úºÍÅ·ÖÞµÄÖ¸±ê£¬³ö¸ñÊÇÒ½ÁƱ£½¡¡¢IT¡¢Ôì×÷¡¢ÎïÁ÷ºÍÓÎÀÀÐÐÒµµÄ×éÖ¯¡£ÔÚ¾àÀëÁ½¸öÔºó£¬6Ô³öÏÖÁ˸úóÃŵÄÐÂÑù±¾£¬ÒÔ¼°¸Ä½øµÄ´úÂëºÍ½¨¸´·¨Ê½¡£¸ÃºóÃÅÓëTrickbot¼ÓÔØ·¨Ê½ÓµÓÐÀàËÆµÄ´úÂ룬Ô̺¬Ò»ÑùµÄWinAPI¡¢×Ô½ç˵RC4ʵÏֺͷ±ËöµÄ»ìºÏ¡£¼ÓÃܵÄBazar»áÖ±½Ó¼ÓÔØµ½ÄÚ´æÖУ¬ÒÔ¶ã±Üɱ¶¾Èí¼þµÄ¼ì²â¡£Ä¿Ç°Òѱ»¼ì²âµ½µÄBazarÓÐÈý¸ö°æ±¾£¬´¦ÓÚ·ÖÆçµÄ¿ª·¢½×¶Î£¬Ô̺¬ÍøÂçºÍÇÔȡϵͳÊý¾Ý¡¢ÓëÖ¸»Ó½ÚÔì(C2)³ÉÁ¢Ïνӣ¬ÒÔ¼°Ö´ÐжàÖÖÖ°ÄÜ¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/new-bazar-backdoor-linked-to-trickbot-banking-trojan-campaigns/
5.Ó¡Äṫ˾BhinnekaÔâµ½¹¥»÷£¬Ð¹Â¶³¬¹ý100Íò¸öÕÊ»§ÐÅÏ¢
Hackread.com·¢ÏÖ£¬Ó¡ÄáÔÚÏßÉ̳ÇBhinnekaÔâµ½¹¥»÷й¶³¬¹ý100Íò¸öÕÊ»§ÐÅÏ¢¡£¾ÝϤ£¬Õâ´ÎÊÂÎñй¶ÁËÁ½¸öSQLÎļþ£¬×ܹ²Ô̺¬Ô¼Äª1262300¸öÕÊ»§µÄ¼Í¼ÐÅÏ¢¡£Ð¹Â¶ÐÅÏ¢Ô̺¬Î¨Ò»µÄID¡¢È«Ãû¡¢µç×ÓÓʼþµØÖ·¡¢ÐÔ±ð¡¢ÁªÏµµç»°¡¢ÃÜÂë¡¢¾ßÌ嵨ַ¡¢µ®ÉúÈÕÆÚ¡¢É罻ýÌåID¡¢ÈÕÖ¾¾ßÌåÐÅÏ¢¡¢Óû§Éí·Ý£¨ÊÇÖÎÀíÔ±»¹Êǹ¤×÷ÈËÔ±£©£¬»¹¿ÉÄÜÔ̺¬Ô±¹¤¾ßÌåÐÅÏ¢¡£¾ÝϤ£¬Õâ´Î¹¥»÷²úÉúÓÚ½ñÄê1ÔÂ27ÈÕ£¬ºÚ¿Í×î³õÊÔͼͨ¹ýÀÕË÷Êê½ð»òÏúÊÛÒÔ»ñÈ¡ÀûÒæ£¬µ«²»Öª³öÓÚºÎÖÖÔÒò£¬ºÚ¿Í×îºó½«ÆäÃâ·Ñ¹«¿ªÔÚÁËÍøÂçÉÏ¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/indonesia-bhinneka-database-dumped-1-million-accounts/
6.Kaspersky»ã±¨£¬4¿î°ÍÎ÷ÒøÐÐľÂíÕë¶ÔÈ«Çò½ðÈÚ»ú¹¹
Kaspersky»ã±¨£¬½éÉÜÁËÕë¶ÔÈ«Çò½ðÈÚ»ú¹¹µÄ4¿î°ÍÎ÷ÒøÐÐľÂí¡£ÕâЩľÂíÔ̺¬Guildma¡¢Javali¡¢MelcozºÍGrandoreiro£¬ËüÃÇÒѾ½ø»¯³öÁ˳äÈκóÃŵÄÄÜÁ¦£¬²¢Ñ¡È¡Á˸÷Àà»ìºÏ¼¼ÊõÀ´°µ²ØÆä¶ñÒâ»î¶¯£¬Ê¹Æä²»±»°²È«Èí¼þ·¢ÏÖ¡£Kaspersky×êÑÐÈËÔ±½«ËüÃÇͳ³ÆÎªTetrade£¬²¢Ö¸³öÆä¿ÉÄÜÒѾö¶¨½«¹¥»÷À©´óÖÁº£±í¡£GuildmaºÍJavali¾ùѡȡ¶à½×¶Î¶ñÒâÈí¼þ²¿Êð¹ý³Ì£¬Ê¹ÓÃÍøÂç´¹µöµç×ÓÓʼþ×÷Ϊ·Ö·¢³õʼÓÐÐ§ÔØºÉµÄ»úÔì¡£MelcozÊÇ¿ªÔ´RATÔ¶³Ì½Ó¼ûPCµÄÒ»ÖÖ±äÌ壬ÇÔÈ¡ÃÜÂëºÍ±ÈÌØ±ÒÇ®°ü¡£Grandoreiro»áʹÓÃÓòÌìÉúËã·¨£¨DGA£©°µ²Ø¹¥»÷¹ý³ÌÖÐʹÓõÄC2µØÖ·£¬²¢½«ÆäÍйÜÔÚGoogleÕ¾µãÒ³ÃæÉÏ£¬Í¨¹ýÊÜϰȾµÄÍøÕ¾ºÍGoogle Ads£¬»òÓã²æÊ½ÍøÂç´¹µö½øÐзַ¢¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/the-tetrade-brazilian-banking-malware/97779/


¾©¹«Íø°²±¸11010802024551ºÅ