Google°ä²¼Chrome°²È«¸üУ¬½¨¸´Òѱ»ÀûÓõÄ0day£»GravityRATбäÖÖ¿ÉϰȾAndroidºÍmacOSÉ豸

°ä²¼¹¦·ò 2020-10-21

1.Google°ä²¼Chrome°²È«¸üУ¬½¨¸´Òѱ»ÀûÓõÄ0day


1.png


Google°ä²¼ÁËChrome°æ±¾86.0.4240.111µÄ°²È«¸üУ¬½¨¸´Òѱ»ÔÚÒ°ÀûÓõÄ0day¡£¸Ã·ì϶±»×·×ÙΪCVE-2020-15999£¬ÊÇFreeType×ÖÌåäÖȾ¿âÖеÄÄÚ´æ°Ü»µ·ì϶¡£¹È¸èProject ZeroµÄ×êÑÐÈËÔ±·¢ÏÖÁËÀûÓôËFreeType·ì϶½øÐеÄÒ°±í¹¥»÷£¬µ«ÊÇÓйظ÷ì϶µÄÀûÓûµÄ¾ßÌåÐÅÏ¢ÉÐδ¹«¿ª¡£ÕâÊÇÔÚ´ÓǰһÄêÀ´µÄµÚÈý¸ö±»ÔÚÒ°ÀûÓõÄChrome 0day£¬Ç°Á½¸öÊÇCVE-2019-13720£¨2019Äê10Ô£©ºÍCVE-2020-6418£¨2020Äê2Ô£©¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/google-releases-chrome-security-update-to-patch-actively-exploited-zero-day/


2.NCSC³Æ¶íÂÞ˹ºÚ¿ÍÔڳﱸÕë¶Ô¶«¾©°ÂÔË»áµÄ¹¥»÷»î¶¯


2.png


Ó¢¹úNCSC³Æ¶íÂÞ˹ºÚ¿ÍÔڳﱸÕë¶Ô¶«¾©°ÂÔË»áºÍ²Ð°Â»áµÄ¹¥»÷»î¶¯£¬Ö¸±êÔ̺¬°ÂÔË»áµÄ×éÖ¯Õß¡¢ÎïÁ÷·þÎñºÍÔÞÖúÉÌ¡£Ó¢¹úµ±¾ÖÒÔΪ£¬¶íÂÞ˹ºÚ¿ÍÕâ´ÎÐж¯µÄÒâͼÀàËÆÓÚËûÃǶԺ«¹úƽ²ý2018Ä궬¼¾°ÂÔË»áºÍ²Ð°Â»á×éÖ¯Õß½øÐеÄÍøÂç¹¥»÷¡£Ö®ËùÒÔÌáÒé¹¥»÷£¬ÊÇÓÉÓÚ¹ú¼Ê°Âί»áÒÔ¹ú¶ÈÔÞÖúÐ˷ܼÁΪÓÉ£¬²»ÈݶíÂÞ˹»î´øÍ·²ÎÓë½ÇÖð¡£ÕâÓëÃÀ¹ú˾·¨²¿ÔçЩʱ³½¶ÔÁùÃûSandworm³ÉÔ±µÄÕýʽ¸æ×´ÏàÎÇºÏ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/uk-says-russia-was-preparing-cyber-attacks-against-the-tokyo-olympics/


3.GravityRATбäÖÖ¿ÉϰȾAndroidºÍmacOSÉ豸


3.png


¿¨°Í˹»ùµÄ×êÑÐÈËÔ±·¢ÏÖÁËGravityRAT¶ñÒâÈí¼þµÄбäÖÖ£¬¿ÉÓÃÀ´Ï°È¾AndroidºÍmacOSÉ豸¡£GravityRATÊÇÒ»ÖÖÕë¶ÔWindowsµÄ¶ñÒâÈí¼þ£¬¿Éͨ¹ý¼ì²âÍÆËã»úCPUζÈÒÔ¶ã¹ýÔÚɳÏäºÍÐé¹¹»úÖÐÖ´ÐС£×êÑÐÈËÔ±ÔÚÈ¥Äê·¢ÏÖÁË¿ÉÄÜϰȾmacOSºÍAndroidÉ豸µÄÑù±¾¡£¸Ã±äÌåÄÜÇÔÈ¡ÁªÏµÈË¡¢µç×ÓÓʼþºÍÎĵµ£¬¶øºó½«Æä·¢ËͻغÅÁîºÍ½ÚÔì·þÎñÆ÷£¨nortonupdates[.]online£©¡£¸ÃC£¦C·þÎñÆ÷»¹ÓëÆäËûÁ½¸öÕë¶ÔWindowsºÍmacOSµÄ¶ñÒâÀûÓã¨EnigmaºÍTitanium£©ÓйØÁª¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/109744/malware/gravityrat-malware-android-macos.html


4.ºÚ¿Í¿ÉÔÚSS7ÒÆ¶¯¹¥»÷Öнٳֵ籨ºÍµç×ÓÓʼþÕÊ»§


4.png


ºÚ¿Íͨ¹ý¹¥»÷ÓÃÓÚÏνÓÈ«ÇòÒÆ¶¯ÍøÂçµÄÐÅÁîϵͳ (Signaling System 7£¬SS7) £¬ÇÔÈ¡µç±¨ºÍµç×ÓÓʼþÊý¾Ý¡£Õâ´Î¹¥»÷²úÉúÔÚ9Ô·Ý£¬Ö¸±êÊÇPartner CommunicationsµÄÖÁÉÙ20ÃûÓû§£¬ËûÃǶ¼²Î¼ÓÁ˼ÓÃÜÇ®±ÒÏîÄ¿¡£×êÑÐÈËÔ±°µÊ¾£¬ºÚ¿ÍºÜ¿ÉÄÜͨ¹ýαÔìÒÆ¶¯ÍøÂçÔËÓªÉ̵ĶÌÕÛ·þÎñÖÐÐÄ(SMSC)£¬ÈÃÆäÏò¸Ã¹«Ë¾·¢Ë͸üÐÂÖ¸±êµç»°ºÅÂëµØÎ»µÄÒªÇ󣬶ø¸Ã¸üÐÂÒªÇóÏÖʵÉÏÊÇÒªÇóÏò¼ÙMSC·¢ËÍËùÓÐÕë¶ÔÊܺ¦ÕßµÄÓïÒôºô½ÐºÍ¶ÌÐÅ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hackers-hijack-telegram-email-accounts-in-ss7-mobile-attack/


5.жñÒâÈí¼þVizomʹÓÃÔ¶³Ì¸²¸Ç¹¥»÷À´½Ù³ÖÒøÐÐÕÊ»§


5.png


жñÒâÈí¼þVizomʹÓÃÔ¶³Ì¸²¸Ç¹¥»÷À´½Ù³ÖÒøÐÐÕÊ»§£¬ÖØÒªÕë¶Ô°ÍÎ÷µÄÒøÐС£IBM°²È«×êÑÐÈËÔ±·¢ÏÖVizomÀûÓÃÁËÔ¶³Ì¸²¸Ç¼¼ÊõºÍDLL½Ù³Ö£¬¼Ù×°³ÉÊÓÆµ»áÒéÈí¼þͨ¹ýÍøÂç´¹µö»î¶¯½øÐд«²¼£¬Ö¼ÔÚͨ¹ýÔÚÏß½ðÈÚ·þÎñÀ´·ÛËé°ÍÎ÷µÄÒøÐÐÕÊ»§¡£VizomÒ»µ©³É¹¦Ï°È¾Windows PC£¬½«Ê×ÏȽøÈëAppDataĿ¼ÆðͷϰȾÁ´¡£Í¨¹ýÀûÓÃDLL½Ù³Ö£¬¸Ã¶ñÒâÈí¼þ½«Ê¹ÓÃÆäĿ¼ÖеĺϷ¨Èí¼þËù½øÕ¹µÄÃû³ÆÀ´¶¨ÃûÆä»ùÓÚDelphiµÄ±äÌ壬À´ÊÔͼǿÔì¼ÓÔØ¶ñÒâDLL¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/this-new-malware-uses-remote-overlay-attacks-to-hijack-your-bank-account/


6.Albion³ÆÆäÂÛ̳Ôâµ½ºÚ¿ÍÈëÇÖ£¬Óû§ÃûºÍÃÜÂë»òÒѱ»Ð¹Â¶


6.png


ÓÎÏ·Ôì×÷ÉÌAlbion³ÆÆäÂÛ̳Ôâµ½ºÚ¿ÍÈëÇÖ£¬Óû§ÃûºÍÃÜÂë»òÒѱ»Ð¹Â¶¡£ÈëÇÖ²úÉúÔÚ10ÔÂ16ÈÕ£¬¹¥»÷ÕßÀûÓÃÁËÆäÂÛ̳ƽ̨WoltLab SuiteµÄÒ»¸ö·ì϶ÌáÒé¹¥»÷£¬Albion°µÊ¾¸Ã·ì϶ÏÖÒѽ¨¸´¡£Õâ´Îй¶µÄÊý¾ÝΪÂÛ̳Óû§Ó×ÎÒ×ÊÁÏ£¬ÆäÖÐÔ̺¬Ïνӵ½ÂÛ̳ÕÊ»§µÄµç×ÓÓʼþµØÖ·ÒÔ¼°¼ÓÃܵÄÃÜÂë¡£Õâ²»ÄÜÓÃÓڵǼAlbion OnlineÍøÕ¾£¬µ«ÊÇ¿ÉÓÃÓÚ¼ø±ðʹÓÃÈõ¿ÚÁîµÄÕÊ»§¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/albion-online-game-maker-discloses-data-breach/