Intel 471°ä²¼°µÍøÖÐ25ÖÖÖØÒªRaaS²úÆ·µÄ·ÖÎö»ã±¨ £»Firefox°ä²¼°²È«¸üУ¬½¨¸´0day²¢ÐÂÔö½öHTTPSģʽ

°ä²¼¹¦·ò 2020-11-18

1.Intel 471°ä²¼°µÍøÖÐ25ÖÖÖØÒªRaaS²úÆ·µÄ·ÖÎö»ã±¨


1.jpg


Intel 471°ä²¼ÁËÓйذµÍøÖеÄ25ÖÖÖØÒªRaaS²úÆ·µÄ·ÖÎö»ã±¨¡£Intel 471°µÊ¾£¬Ëüƾ¾ÝRaaSµÄ¸´ÔÓˮƽ¡¢Ö°Äܺͺ¹ÇཫÕâЩÀÕË÷Èí¼þ·ÖΪÈý¸öµµ´Î¡£µÚÒ»²ãΪµ±½ñ×î³ÛÃûµÄÀÕË÷Èí¼þ£¬Ô̺¬REvil¡¢Netwalker¡¢DopplePaymer¡¢Egregor£¨Maze£©ºÍRyuk¡£µÚ¶þ²ãΪÀÕË÷Èí¼þÊÀ½çµÄÐÂÐË´ú±í£¬Ô̺¬Avaddon¡¢Conti¡¢Clop¡¢DarkSide¡¢Mespinoza£¨Pysa£©¡¢RagnarLocker¡¢Ranzy£¨Ako£©¡¢SunCryptºÍThanos¡£µÚÈý²ãΪа䲼µÄRaaS²úÆ·£¬Ô̺¬CVartek.u45¡¢Exorcist¡¢Gothmog¡¢Lolkek¡¢Muchlove¡¢Nemty¡¢Rush¡¢Wally¡¢Xinof¡¢ZeoticusºÍZagreuS¡£


Ô­ÎÄÁ´½Ó£º

https://public.intel471.com/blog/ransomware-as-a-service-2020-ryuk-maze-revil-egregor-doppelpaymer/


2.Firefox°ä²¼°²È«¸üУ¬½¨¸´0day²¢ÐÂÔö½öHTTPSģʽ


2.jpg


Mozilla°ä²¼Firefox°²È«¸üУ¬½¨¸´0day²¢ÐÂÔö½öHTTPSģʽ¡£½öHTTPSÖ°ÄÜ¿É×Ô¶¯Åú¸ÄURL£¬µ±Óû§ÆôÓÃÁ˸Ãģʽʱ£¬Firefox»á½«Óû§½Ó¼ûµÄËùÓÐhttp£º// URL³ÁдΪÆä°²È«µÄhttps£º//£¬ÈôÊÇÎÞ·¨Ïνӵ½°²È«URL£¬Ëü½«ÏÔʾ°²È«ÏνӲ»³ÉÓõÄÃýÎóÖҸ档´Ë±í£¬Õâ´Î°²È«¸üл¹½¨¸´ÁË21¸ö·ì϶£¬ÆäÖÐÔ̺¬FreetypeµÄ0day¡£¸Ã·ì϶ÓÉGoogle Project ZeroÅû¶£¬¿ÉÓÃÓÚÕë¶ÔGoogle ChromeµÄ×Ô¶¯¹¥»÷¡£µ«ÆäÓ°ÏìÁËËùÓÐʹÓÃFreetypeµÄÈí¼þ£¬Ô̺¬Mozilla Firefox¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/software/firefox-83-boosts-security-with-https-only-mode-zero-day-fix/


3.Citrix SD-WAN´æÔÚ¶à¸ö·ì϶£¬¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ


3.jpg


Citrix SD-WAN´æÔÚ¶à¸ö·ì϶£¬¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐкÍϵͳÊÕÊÜ¡£µÚÒ»¸ö·ì϶Ϊstop_pingÖÐδ¾­ÑéÖ¤µÄõè¾¶±éÀúºÍshell×¢Èë·ì϶£¨CVE-2020¨C8271£©£¬¿Éʹδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß»ñµÃrootȨÏÞ¡£µÚ¶þ¸ö·ì϶ΪConfigEditorÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2020¨C8272£©£¬ÓëCakePHP½«URIת»»Îª¶Ëµãº¯Êý²ÎÊýÓйØ¡£µÚÈý¸ö·ì϶ΪCreateAzureDeploymentÖеÄShell×¢Èë·ì϶£¨CVE-2020¨C8273£©¡£×êÑÐÈËÔ±°µÊ¾£¬¹¥»÷Õß½áºÏʹÓÃÕâÈý¸ö·ì϶¿É³É¹¦ÊÕÊÜÏµÍ³ÍøÂç¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/citrix-sd-wan-bugs-remote-code-execution/161274/


4.×êÑÐÈËÔ±³ÆÈÔÓнü25Íò¸öϵͳÈÔÒ×ÊÜBlueKeep RDP¹¥»÷


4.jpg


΢ÈíÅû¶ÁËÓ°ÏìWindows RDP·þÎñµÄBlueKeep·ì϶һÄê°ëÖ®ºó £¬ÒÀÈ»Óг¬¹ý245000¸öWindowsϵͳÒ×Êܵ½´ËÀ๥»÷¡£SANS ISC×êÑÐÈËÔ±³Æ£¬Ö»¹Ü¸Ã·ì϶¼«¶ÈÑϳÁ£¬²¢ÇÒ¹ú¶Èµ±¾ÖÒ²ÂŴΰ䲼¸üÐÂÖҸ棬µ«ÈÔÓÐ25£¥Ò×ϰȾϵͳÒòδ֪ԭÒòδ½øÐиüС£Í¬ÑùµØ£¬³¬¹ý103000¸öWindowsϵͳҲÈÔÈÝÒ×Êܵ½SMBGhostµÄ¹¥»÷¡£SMBGhostÊÇServer Message Block v3£¨SMB£©ºÍ̸Öеķì϶£¬ÓëBlueKeepÒ»Ñù¶¼¿Éʹ¹¥»÷ÕßÔ¶³Ì½ÚÔìWindowsϵͳ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/more-than-245000-windows-systems-still-remain-vulnerable-to-bluekeep-rdp-bug/


5.ij¹«¿ªµÄÊý¾Ý¿âй¶10Íò¶à¸öFacebookÓû§µÄÐÅÏ¢


5.jpg


vpnMentorµÄ×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸öÔÚÏß¹«¿ªµÄElasticSearchÊý¾Ý¿â£¬ÆäÖÐÔ̺¬³¬¹ý100000¸öFacebookÓû§µÄÐÅÏ¢¡£¸ÃÊý¾Ý¿âµÄÈÝÁ¿³¬¹ý5.5 GB£¬×ܹ²Ô̺¬13521774¸öÎļþ£¬ÓÚ½ñÄê6ÔÂÖÁ9Ô¼äά³ÖÊ¢¿ª×´Ì¬¡£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬À¨µç×ÓÓʼþ¡¢ÐÕÃûºÍµç»°ºÅÂ룬»¹Ô̺¬ÓйØÍøÂç·¸×ï·Ö×ÓÈôºÎ×Ô¶¯Ö´Ðй¥»÷Á÷³ÌµÄ¼¼ÊõÐÅÏ¢¡£vpnMentorÖ¸³ö¸ÃÊý¾Ý¿â¿ÉÄÜÊôÓÚµÚÈý·½£¬Æäͨ¹ýÕë¶ÔFacebookÓû§µÄ´¹µöÍøÕ¾·¸·¨»ñµÃµÄÕË»§µÇ¼ʹ´¦¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/111018/cyber-crime/100k-facebook-accounts-scam.html


6.AmericoldÔâµ½ÍøÂç¹¥»÷£¬Æä¶à¸öϵͳÊܵ½Ó°Ïì


6.jpg


Àä¿â¹«Ë¾AmericoldÔâµ½ÍøÂç¹¥»÷£¬Ô̺¬µç»°ÏµÍ³¡¢µç×ÓÓʼþ¡¢¿â´æÖÎÀíºÍ¶©µ¥ÏµÍ³ÔÚÄڵĶà¸öϵͳÊܵ½Ó°Ïì¡£AmericoldÊÇÒ»¼Òµ±ÏȵÄοزֿâÔËÓªÉÌ£¬ÎªÁãÊÛÉÌ¡¢Ê³Æ··þÎñÌṩÉ̺ͳö²úÉÌÌṩ¹©¸øÁ´·þÎñºÍ¿â´æÖÎÀí£¬AmericoldÔÚÈ«ÇòÕ¼ÓÐ183¸ö²Ö¿â¡£11ÔÂ16ÈÕ£¬AmericoldÈ·¶¨ÆäÔâµ½¹¥»÷£¬²¢µ±¼´²ÉÈ¡ÁËÏìÓ¦´ëÊ©£¬¹Ø¹ØÍÆËã»úϵͳÒÔÔ¤·À¹¥»÷ÊæÕ¹¡£¾ÝºÜ¶àÐÂÎÅÆðÔ´³Æ£¬ÕâÊÇÒ»ÖÖÀÕË÷Èí¼þ¹¥»÷£¬µ«Ä¿Ç°Éв»Ïàʶ¹¥»÷ÏêÇé¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/cold-storage-giant-americold-hit-by-cyberattack-services-impacted/