×êÑÐÈËÔ±·¢ÏÖжñÒâÈí¼þTaurusͨ¹ý¶ñÒâ¸æ°×»î¶¯´«²¼£»Pandora FMSÖдæÔÚ¶à¸ö·ì϶ £¬¿Éµ¼ÖÂÔ¶³ÌÖ´Ðй¥»÷

°ä²¼¹¦·ò 2020-09-29
1.×êÑÐÈËÔ±·¢ÏÖжñÒâÈí¼þTaurusͨ¹ý¶ñÒâ¸æ°×»î¶¯´«²¼


1.jpg


×êÑÐÈËÔ±·¢ÏÖеÄÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þTaurusͨ¹ý¶ñÒâ¸æ°×»î¶¯´«²¼ ¡£TaurusÊÇÒ»ÖÖÏà¶Ô½ÏеĶñÒâÈí¼þ £¬ÓÚ2020Äê´º¼¾³öÏÖ £¬Í¨¹ýÕë¶ÔÃÀ¹úÓû§µÄ¶ñÒâ¸æ°×»î¶¯½øÐд«²¼ ¡£Æä×î³õÊÇÓÉPredatorµÄ´´½¨ÕßËù¿ª·¢ £¬Òò¶ø¶þÕßÓµÓÐÒ»ÑùµÄÖ°ÄÜ £¬¼´´Óä¯ÀÀÆ÷¡¢FTP¡¢VPN¡¢µç×ÓÓʼþ¿Í»§¶ËÒÔ¼°¼ÓÃÜÇ®±ÒÇ®°üÇÔȡʹ´¦ ¡£Õâ´Î×îз¢ÏֵĶñÒâ»î¶¯ÖØÒªÕë¶Ô³ÉÈËÍøÕ¾µÄ½Ó¼ûÕß £¬Êܺ¦Õß´ó¶àÀ´×ÔÃÀ¹ú £¬Ò²ÓÐÀ´×Ô°Ä´óÀûÑǺÍÓ¢¹ú ¡£


Ô­ÎÄÁ´½Ó£º

https://blog.malwarebytes.com/malwarebytes-news/2020/09/taurus-project-stealer-now-spreading-via-malvertising-campaign/


2.Pandora FMSÖдæÔÚ¶à¸ö·ì϶ £¬¿Éµ¼ÖÂÔ¶³ÌÖ´Ðй¥»÷


2.jpg


Pandora FMSÖдæÔÚ¶à¸ö·ì϶ £¬¿Éµ¼ÖÂÔ¶³ÌÖ´Ðй¥»÷ ¡£Pandora FMSÊÇÒ»¸öÊ¢¿ªÔ´´úÂë½â¾ö¹æ»® £¬ËüÌṩÓÃÓÚ¼à¶½ÍøÂçÏνӡ¢ÀûÓ÷¨Ê½ÖÎÀí¡¢ÊÂÎñ¾¯±¨ÒÔ¼°Windows¡¢Linux¡¢UnixºÍAndroidϵͳµÄ´úÀíºÍÎÞ´úÀí¼à¶½µÄ½çÃæ ¡£×êÑÐÈËÔ±ÔÚPandora FMS°æ±¾742Öз¢ÏÖÁËËĸö·ì϶ £¬±ðÀëΪpre-auth SQL×¢Èë·ì϶¡¢pre-auth PHAR·´ÐòÁл¯·ì϶¡¢ÌØÈ¨Óû§×îµÍµÄÔ¶³ÌÎļþÔ̺¬±àÂëÃýÎóÒÔ¼°¿çÕ¾µãÒªÇóαÔ죨CSRF£©·ì϶ ¡£ÆäÖÐ £¬pre-auth SQL×¢Èë·ì϶ÎÞÐèÈκνӼûȨÏÞ¼´¿ÉÔ¶³ÌÀûÓà £¬²¢¶ÔÀûÓ÷¨Ê½ÆëÈ«ÊÕÊÜ ¡£


Ô­ÎÄÁ´½Ó£º

https://portswigger.net/daily-swig/multiple-vulnerabilities-in-pandora-fms-could-trigger-remote-execution-attack


3.¹ú¼ÊÌØÉâ×éÅû¶¼äµýÈí¼þFinSpyÕë¶Ô°£¼°µÄ¹¥»÷»î¶¯


3.jpg


¹ú¼ÊÌØÉâ×éÖ¯¸æ·¢ÁËÕë¶Ô°£¼°Ãñ¼äÉç»á×éÖ¯µÄмල»î¶¯ £¬¸Ã»î¶¯Ê¹ÓÃÁËÕë¶ÔLinuxºÍmacOSϵͳµÄ¼äµýÈí¼þFinSpy ¡£FinSpyÒ²³ÆFinFisher £¬ÓÉÒ»¼ÒµÂ¹ú¹«Ë¾¿ª·¢ £¬ÓµÓжàÖÖ¼äµýÖ°ÄÜ £¬Ô̺¬°ÂÃØ´ò¿ªÍøÂçÉãÏñÍ·ºÍÂó¿Ë·ç¡¢ÔÚ¼üÅÌÉϼͼÊܺ¦Õß¼üÈëµÄËùÓÐÄÚÈÝ¡¢À¹½Øºô½ÐºÍÊý¾Ýй© ¡£ÆäÄܹ»Í¬Ê¹Øë¶Ô×ÀÃæºÍÒÆ¶¯²Ù×÷ϵͳ £¬Ô̺¬Android¡¢iOS¡¢Windows¡¢macOSºÍLinuxϵͳ ¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2020/09/finspy-malware-macos-linux.html


4.Next Caller°ä²¼COVID-19ÓйØÚ²Æ­»î¶¯·ÖÎö»ã±¨


4.jpg


Next Caller°ä²¼COVID-19ÓйØÚ²Æ­»î¶¯·ÖÎö»ã±¨ £¬ÏÔʾÓëCOVIDÓйصÄڲƭÐÐΪÒѶÔÃñ¶à²úÉúÁË¿í·ºÓ°Ïì ¡£»ã±¨°µÊ¾ £¬55£¥µÄÃÀ¹úÈËÒÔΪËûÃÇÒѳÉΪÓëCOVIDÓйصÄڲƭÐÐΪµÄÖ¸±ê £¬Ö»¹ÜÈç´Ë £¬ÈÔÓÐ59£¥µÄÃÀ¹úÈ˳ÆËûÃÇûÓвÉÈ¡ÈÎºÎÆäËûÔ¤·À´ëÊ©À´±£»¤×Ô¼ºÃâÊܹ¥»÷ ¡£ÓнüÈý·ÖÖ®Ò»£¨30%£©µÄÃÀ¹úÈ˸ü²»°²Ô⵽ڲƭ £¬¶ø·ÇϰȾ²¡¶¾ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2020/09/28/covid-related-fraud-schemes/


5.ÌïÄÉÎ÷ÖݵijÇÊÐÔâµ½¹¥»÷ £¬µ¼Öµ±¾ÖÄÚ²¿ÍøÂçÁÙʱ¹Ø¹Ø


5.jpg


ÌïÄÉÎ÷ÖݵijÇÊпËÀ­¿Ë˹ά¶ûÔâµ½¹¥»÷ £¬µ¼Öµ±¾ÖÄÚ²¿ÍøÂçÁÙʱ¹Ø¹Ø ¡£Æä½²»°ÈËMichelle Newell°µÊ¾ £¬¸ÃÏØÉÏÖÜÎåÔâµ½ÁËÍøÂç¹¥»÷ £¬µ¼ÖÂÆäµ±¾ÖÄÚ²¿ÍøÂçÔÚÖÜÄ©ÁÙʱ¹Ø¹Ø £¬Ö±ÖÁÖÜÈÕÒÀÈ»ÎÞ·¨½Ó¼û ¡£Ä¿Ç°¸ÃÏØÔÚÊÔͼ½â¾ö¸ÃÎÊÌâ²¢¸´Ô­ÔËÓª £¬ÒѾ­Ö´ÐÐÁËÏàÓ¦¹æ»®²¢·¢Õ¹Á˵÷²é ¡£911ÖÐÐÄÖ÷ÈÎHope Petersen°µÊ¾ £¬¸ÃµØÓòµÄ911 CenterûÓÐÊܵ½µ±¾ÖÄÚÍø¹Ø¹ØµÄÓ°Ïì ¡£


Ô­ÎÄÁ´½Ó£º

https://clarksvillenow.com/local/data-security-incident-shuts-down-montgomery-countys-computer-network/


6.È«Ãñ½¡È«·þÎñҽԺϵͳϰȾRyuk £¬ÆäÈ«ÇòµÄ·ÖÔºÊܵ½Ó°Ïì


6.jpg


9ÔÂ26ÈÕÖÁ27ÈÕ £¬ÃÀ¹úµÄÈ«Ãñ½¡È«·þÎñÒ½Ôº£¨UHS£©ÏµÍ³Ï°È¾ÀÕË÷Èí¼þRyuk £¬ÆäÈ«ÇòµÄ·ÖÔºÊܵ½Ó°Ïì ¡£UHSÔÚÔÚÃÀ¹úºÍÓ¢¹úÖÎÀí×Å400¶à¼ÒÒ½ÔººÍ»¤ÀíÖÐÐÄ £¬¹ÌÈ»¹¥»÷µÄÕæÊµË®Æ½ÉдýÈ·¶¨ £¬µ«ÊÇÔçÆÚ±¨Â·³ÆUHSµÄÕû¸öÍøÂç¶¼Êܵ½ÁËÓ°Ïì ¡£ÃÀ¹ú±±¿¨ÂÞÀ³ÄÉÖÝ¡¢µÂ¿ËÈøË¹Öݵȶà¸öµØÓòµÄUHSÒ½ÔººÍ»¤ÀíÖÐÐÄÈ·ÈÏÆäITϵͳ³öÏÖÁËÎÊÌâ ¡£Ä¿Ç° £¬UHS½²»°È˲¢Î´»Ø¸´ÖÃÆÀÒªÇó £¬µ«Æäй©¸ÃÊÂÎñÊÇÓÉÃûΪRyukµÄÀÕË÷Èí¼þÔì³ÉµÄ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/uhs-hospital-network-hit-by-ransomware-attack/