΢Èí³ÆÒѼì²âµ½ÀûÓÃZerologon·ì϶ÌáÒéµÄ×Ô¶¯¹¥»÷£»ÐµĶñÒâÈí¼þAlien¿ÉÇÔÈ¡226¿îAndroidÀûÓõÄÓû§ÃÜÂë

°ä²¼¹¦·ò 2020-09-25

1.΢Èí³ÆÒѼì²âµ½ÀûÓÃZerologon·ì϶ÌáÒéµÄ×Ô¶¯¹¥»÷


1.png


΢Èí°²È«µý±¨ÍŶӰµÊ¾£¬ÆäÒѼì²âµ½ÀûÓÃZerologon·ì϶£¨CVE-2020-1472 £©ÌáÒéµÄ×Ô¶¯¹¥»÷¡£×ÔºÉÀ¼°²È«¹«Ë¾Secura BVÔÚ9ÔÂ14ÈÕÅû¶ÁËÓйØZerologon·ì϶µÄ¾ßÌåÐÅÏ¢ºó£¬ÒÑÓжà¸ö±øÆ÷»¯µÄPoC¿ª·¢´úÂëÔÚÍøÉϹ«¿ª¡£Î¢Èí²¢Ã»Óа䲼ÓйØÕâ´Î¹¥»÷µÄϸ½Ú£¬µ«Êǰ䲼ÁËÓÃÓÚ¹¥»÷µÄÎļþÉ¢ÁС£Òò¶ø°²È«×¨¼Ò¾Í½¨Ò飬ÄÇЩÓòÃû½ÚÔìÆ÷¶³öµÄ¹«Ë¾Ó¦¾¡¿ìÈÃϵͳÀëÏߣ¬ÒÔ±ã¶ÔÆä½øÐв¹¶¡¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/microsoft-says-it-detected-active-attacks-leveraging-zerologon-vulnerability/


2.еĶñÒâÈí¼þAlien¿ÉÇÔÈ¡226¿îAndroidÀûÓõÄÓû§ÃÜÂë


2.png


°²È«×êÑÐÈËÔ±·¢ÏÖÁËÒ»ÖÖеÄAndroid¶ñÒâÈí¼þAlien£¬ÆäÓµÓжàÖÖÖ°ÄÜ£¬¿É´Ó226¸öÀûÓ÷¨Ê½ÖÐÇÔȡʹ´¦¡£Alien»ùÓÚ¶ñÒâ¶ñÒâÈí¼þCerberusµÄÔ´´úÂ룬µ«ÊÇÏà±ÈºóÕßËü¸üÏȽø¡£¸ÃľÂíÒ²Òѽ«Ô¶³Ì½Ó¼ûÖ°Äܼ¯³Éµ½Æä´úÂë¿âÖУ¬Ëü²»½öÄܹ»ÏÔʾαÔìµÄµÇ¼½çÃæ²¢ÍøÂç¸÷ÀàÀûÓ÷¨Ê½ºÍ·þÎñµÄÃÜÂ룬»¹Äܹ»ÊÚÓèºÚ¿Í½Ó¼ûÉ豸ÒÔʹÓÃËùÊöÍ´´¦ÉõÖÁÖ´ÐÐÆäËû²Ù×÷µÄȨÏÞ¡£×êÑÐÈËÔ±·ÖÎö·¢ÏÖ£¬Alien¿ÉÏÔʾ226¿îAndroidÀûÓõÄαÔìµÇÂ¼Ò³Ãæ£¬ÒÔÇÔÈ¡Óû§µÇ½ƾ֤¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/new-alien-malware-can-steal-passwords-from-226-android-apps/


3.΢Èí¡¢Òâ´óÀûºÍºÉÀ¼°ä²¼Ô¤·ÀEmotet¹¥»÷»î¶¯µÄÔ¤¾¯


3.png


¼Ì·¨¹ú¡¢ÈÕ±¾ºÍÐÂÎ÷À¼ÐÂÎ÷À¼Ö®ºó£¬Î¢Èí¡¢Òâ´óÀûºÍºÉÀ¼Ò²°ä²¼ÁËÔ¤·ÀEmotet¹¥»÷»î¶¯µÄÔ¤¾¯¡£Cryptolaemus×êÑÐÈËÔ±°µÊ¾£¬×î½üÁ½ÖÜEmotet¹¥»÷³ÖÐøÔö³¤£¬ÆäÖÜÒ»ÊÕµ½ÁËԼĪ400·â´¹µöÓʼþ£¬¶øÕý³£Çé¿öÏÂÒ»ÌìÖ»ÓÐ12µ½100·â¡£´Ë±í£¬Î¢ÈíºÍÒâ´óÀûµ±¾Ö·¢ÏÖEmotetµÄ¹¥»÷»î¶¯ÓÐÁËб䶯£¬ÆäÆðÍ·ÀûÓÃÊÜÃÜÂë±£»¤µÄZIPÎļþ¶ø²»ÊÇOfficeÎĵµ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/microsoft-italy-and-the-netherlands-warn-of-increased-emotet-activity/


4.Group-IB·¢ÏÖרÃÅÕë¶Ô¶íÂÞ˹µÄкڿÍ×éÖ¯OldGremlin


4.png


°²È«¹«Ë¾Group-IB·¢ÏÖÒ»¸öеĺڿÍ×éÖ¯OldGremlin£¬ÆäÔÚ´ÓǰÁù¸öÔÂÖÐÒ»ÔÙÓöñÒâÈí¼þºÍÀÕË÷Èí¼þ¹¥»÷¶íÂÞ˹ÆóÒµ¡£OldGremlin¹¥»÷ͨ³£Ê¼ÓÚ´øÓжñÒâÈí¼þµÄZIPÎļþµÄÓã²æÊ½ÍøÂç´¹µöµç×ÓÓʼþ£¬¸Ãµç×ÓÓʼþͨ³£»áʹÓúóÃÅÌØÂåÒÁľÂíTinyNodeÈëÇÖÖ¸±ê×éÖ¯¡£Ö®ºó¹¥»÷Õß»áÔÚ½øÈëÖ¸±ê¹«Ë¾µÄÍøÂçºóºáÏòÀ©É¢µ½ÆäËûϵͳ£¬×îÖջᲿÊðÀÕË÷Èí¼þ¡£Group-IBÔÚ8Ô·ÝÈ·¶¨ÁËOldGremlin¼¯Ì壬µ«¸ÃÍÅ»ïµÄ¹¥»÷¿É×·ÒäÖÁ3Ô·Ý¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/ransomware-gang-targets-russian-businesses-in-rare-coordinated-attacks/


5.ÃÀ¹ú¹«Ë¾Town SportsÊý¾Ý¿â¶³ö£¬Ð¹Â¶60Íò¿Í»§ÐÅÏ¢


5.png


Comparitech·¢ÏÖ£¬ÃÀ¹ú½¡Éí¹«Ë¾Town SportsÊý¾Ý¿â¶³ö£¬Ð¹Â¶60Íò¿Í»§ÐÅÏ¢¡£Õâ´Îй¶µÄÓ×ÎÒÐÅÏ¢Ô̺¬ÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·¡¢ÐÅÓþ¿¨µÄºóËÄλÊý×Ö¡¢ÐÅÓþ¿¨µÄÓÐЧÆÚÒÔ¼°»áÔ±µÄÕʵ¥¼Í¼¡£×êÑÐÈËÔ±ÓÚ2020Äê9ÔÂ21ÈÕÁªÏµTown SportsÒÔ֪ͨÆä¶³öµÄÊý¾Ý¿â£¬²¢Î´ÊÕµ½»ØÓ¦£¬µ«ÔÚµÚ¶þÌì¸ÃÊý¾Ý¿âÒѱ»±£»¤¡£Ä¿Ç°£¬Town Sport¶ÔÓÚ´ËÊÂÎñ²¢Î´ÖÃÆÀ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-fitness-chains-suffer-data-breach-affecting-600k-customers/


6.ÎÚ¿ËÀ¼¹ú¶È¾¯Ô±µÄ¹ÙÍøÔâµ½¹¥»÷£¬µ¼ÖÂÍøÕ¾ÁÙʱÎÞ·¨½Ó¼û


6.png


ÎÚ¿ËÀ¼¹ú¶È¾¯Ô±¹ÙÍøÓÚ±¾ÖÜÈýÉÏÎç11:45Ôâµ½ÍøÂç¹¥»÷ £¬µ¼ÖÂÍøÕ¾ÁÙʱÎÞ·¨½Ó¼û¡£¹ú¶È¾¯Ô±È·ÈÏÕâÒ»ÊÂÎñµÄͬʱ£¬»¹Ð¹Â©Î´ÖªµÄºÚ¿ÍÔÚ·ÖÆçµØÓò¾¯Ô±²¿ÃÅÔËÓªµÄÄ³Ð©ÍøÕ¾Éϰ䲼ÁËÐéαÐÅÏ¢£¬Æäר¼ÒÒ²ÔÚÖÂÁ¦ÓÚÅųý¹ÊÕÏ¡£Ä¿Ç°Éв»Ã÷ÏÔµ½µ×²úÉúÁËʲô£¬ÒÔ¼°¸ÃÍøÕ¾ÊÇÈôºÎ±»·ÛËéµÄ£¬µ«Õâ²¢²»ÊÇÎÚ¿ËÀ¼³õ´ÎÔâµ½ÑϳÁµÄÍøÂç¹¥»÷¡£¼¸Äêǰ£¬ÎÚ¿ËÀ¼ÄÜÔ´²¿ÍøÕ¾Ôâµ½±ÈÌØ±ÒÀÕË÷Èí¼þ¹¥»÷£¬¶øÆäÓÊÕþ·þÎñ¡¢ÄÜÔ´²¿ÃÅ¡¢ºËµç³§ºÍ»ú³¡Ò²Ôâµ½¹ý¶ñÒâÈí¼þ¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/ukraine-national-police-website-shuts-down-hacker-intrusion/