CrowdStrikeÐû²¼¡¶2020ÄêÈ«ÇòÍþв±¨¸æ¡·£»Ó¢¹úÊý¾Ýî¿Ïµ»ú¹¹¶Ô¹úÌ©º½¿Õ´¦ÒÔ50ÍòÓ¢°÷·£¿î
Ðû²¼Ê±¼ä 2020-03-051.CrowdStrikeÐû²¼¡¶2020ÄêÈ«ÇòÍþв±¨¸æ¡·
CrowdStrikeµÄ¡¶2020ÄêÈ«ÇòÍþв±¨¸æ¡·¶ÔÒÑÍùÒ»ÄêÖж¥¼¶ÍøÂçÍþвÇ÷ÊÆ¾ÙÐÐÁËÉîÈëÆÊÎö£¬¸Ã±¨¸æµÄÒªµã°üÀ¨£º´óÐ͹¥»÷Ô˶¯£¨BGH£©Ò»Ö±Éý¼¶£¬Êê½ðÒªÇóìÉýÖÁÊý°ÙÍò£¬²¢ÇÒÔì³É¼«´óµÄÆÆËð£»ÍøÂç·¸·¨·Ö×ÓÕýÔÚʹÃô¸ÐÊý¾ÝÎäÆ÷»¯£¬ÒÔÔöÌí¶ÔÀÕË÷Èí¼þÊܺ¦ÕßµÄѹÁ¦£»eCrimeÉú̬ϵͳһֱÉú³¤£¬±äµÃ³ÉÊìºÍרҵ»¯Ë®Æ½Ò»Ö±Ìá¸ß£»ÔÚBGHÖ®Í⣬Õë¶ÔÈ«Çò½ðÈÚ»ú¹¹µÄeCrimeÔ˶¯ÓÐËùÔöÌí£»³¯ÏòÎÞ¶ñÒâÈí¼þÕ½ÂÔµÄÇ÷ÊÆÕýÔÚ¼ÓËÙ£»¹ú¼Ò×ÊÖúµÄÓÐÕë¶ÔÐÔµÄÈëÇÖÔ˶¯¼ÌÐøÕë¶Ô֪ʶ²úȨ/¾ºÕùÇ鱨£¬Ôö½øÉçÇøÄÚ²¿µÄÆÆË飬²¢ÊӲ쵽ÁËÓëÏȽøeCrime¹¥»÷ÕßµÄÏàÖú¡£
ÔÎÄÁ´½Ó£º
https://www.crowdstrike.com/resources/reports/2020-crowdstrike-global-threat-report/
2.Ó¢¹úNCSCÐû²¼ÓйØÖÇÄÜ¼à¿ØÉãÏñÍ·µÄÇå¾²Ö¸ÄÏ
Ó¢¹ú¹ú¼ÒÍøÂçÇå¾²ÖÐÐÄ£¨NCSC£©Ðû²¼ÓйØÔõÑù׼ȷÉèÖÃÖÇÄÜÇå¾²ÉãÏñÍ·ºÍÓ¤¶ù¼àÊÓÆ÷µÄÖ¸ÄÏ£¬ÒÔ×èÖ¹Óû§Êܵ½¹¥»÷ÕߵĹ¥»÷¡£NCSCÌåÏÖ¡°ÖÇÄÜÉãÏñ»ú£¨ÓÃÓÚ¼àÊÓºâÓîÄÚºÍÖÜΧÔ˶¯µÄÇå¾²ÉãÏñ»úºÍÓ¤¶ù¼àÊÓÆ÷£©Í¨³£Ê¹ÓüÒÍ¥Wi-FiÅþÁ¬µ½»¥ÁªÍø£¬ÔÚÉÙÉÙÊýÇéÐÎÏ£¬Î´¾ÊÚȨµÄ¹¥»÷Õß¿ÉÒÔ»á¼ûÖÇÄÜÉãÏñ»úµÄʵʱÁ÷»òͼÏñ£¬Õâ»áʹÄúµÄÒþ˽Êܵ½Íþв¡£¡±ÎªÁ˵ÖÓù´ËÀ๥»÷£¬NCSC½¨ÒéʹÓÃÇ¿Á¦µÄ¡¢»ùÓÚÃÜÂë¶ÌÓïµÄÃÜÂë¸ü¸Ä×°±¸µÄĬÈÏÃÜÂ룬¸ÃÃÜÂë¿ÉÒÔʹÓÃÓû§Äܹ»¼Ç×ŵÄÈý¸öËæ»úµ¥´Ê¹¹½¨£¬²¢ÇÒ¼á³ÖÇå¾²ÉãÏñÍ·µÄ¹Ì¼þΪ×îкͽûÓò»ÐëÒªµÄÔ¶³ÌÉó²é¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/uk-ncsc-releases-tips-on-securing-smart-security-cameras/
3.·¸·¨ÍÅ»ïMoleratsй¥»÷Ô˶¯£¬Õë¶ÔÕþ¸®ºÍµçÐÅÐÐÒµ
Palo Alto NetworksµÄUnit42ÍŶÓÔÚ2019Äê10Ôµ½2019Äê12ÔÂÊӲ쵽¶à¸öÓë·¸·¨ÍÅ»ïMoleratsÓйصĴ¹ÂÚ¹¥»÷Ô˶¯¡£¹¥»÷ÕßµÄÄ¿µÄº¸ÇÕþ¸®¡¢µçÐÅ¡¢°ü¹ÜºÍÁãÊÛÐÐÒµ£¬Éæ¼°6¸ö¹ú¼ÒµÄ8¸ö×éÖ¯¡£ËùÓÐÕâЩ¹¥»÷¶¼Éæ¼°µ½Ê¹Óô¹ÂÚÓʼþת´ï¶ñÒâÎĵµ£¬²¢Ê¹ÓÃÉç½»¹¤³ÌÊÖÒÕÒªÇóÊÕ¼þÈËÖ´ÐÐijЩ²Ù×÷£¬ÀýÈçÆôÓúê»òµã»÷Á´½ÓµÈ¡£´ó´ó¶¼´ËÀ๥»÷ÖеÄÓÐÓøºÔØÊÇSparkºóÃÅ£¬¸ÃºóÃÅÔÊÐí¹¥»÷ÕßÔÚÊÜѬȾµÄϵͳÉÏ·¿ªÓ¦ÓóÌÐò²¢ÔËÐÐÏÂÁî¡£
ÔÎÄÁ´½Ó£º
https://unit42.paloaltonetworks.com/molerats-delivers-spark-backdoor/
4.Ó¢¹úÊý¾Ýî¿Ïµ»ú¹¹¶Ô¹úÌ©º½¿Õ´¦ÒÔ50ÍòÓ¢°÷·£¿î
Ó¢¹úÐÅϢרԱ°ì¹«ÊÒÒò2018Äê940ÍòÂÿÍÊý¾Ýй¶ÊÂÎñ¶Ô¹úÌ©º½¿Õ¹«Ë¾´¦ÒÔ50ÍòÓ¢°÷µÄ·£¿î¡£¸Ã¹¥»÷ÒÉËÆ±¬·¢ÔÚ2018Äê3Ô·ݣ¬²¢ÓÚ5Ô·ݻñµÃÈ·ÈÏ£¬Æäʱ¹úÌ©º½¿ÕµÄÊý¾Ý¿âÔâµ½Á˱©Á¦ÆÆ½â¹¥»÷¡£ICOÊÓ²ì³Æ¹úÌ©µÄϵͳÊܵ½ÁËÊý¾ÝÍøÂçÀà¶ñÒâÈí¼þµÄÓ°Ï죬²¢·¢Ã÷¹úÌ©ÔÚÇå¾²ÐÔ·½ÃæµÄһЩȱ·¦£¬°üÀ¨²»ÊÜÃÜÂë±£»¤µÄ±¸·ÝÎļþ¡¢Î´´ò²¹¶¡µÄWeb·þÎñÆ÷¡¢ÒѹýʱµÄ²Ù×÷ϵͳºÍȱ·¦·À²¡¶¾±£»¤µÈ¡£
ÔÎÄÁ´½Ó£º
https://www.theregister.co.uk/2020/03/04/ico_fines_cathay_pacific_500000/
5.¹È¸èÐû²¼3ÔÂAndroidÇå¾²¸üУ¬ÐÞ¸´70¶à¸öÎó²î
¹È¸èÐû²¼2020Äê3ÔÂAndroidÇå¾²¸üУ¬¹²ÐÞ¸´70¶à¸öÎó²î£¬ÆäÖÐ×îÑÏÖØµÄÎó²îÊÇýÌå¿ò¼Ü×é¼þÖеĴúÂëÖ´ÐÐÎó²î£¨CVE-2020-0032£©£¬¸ÃÎó²î¿ÉÄÜʹԶ³Ì¹¥»÷ÕßʹÓöñÒâÎļþÔÚÌØÈ¨Àú³ÌµÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂ룬¸ÃÎó²îÓ°ÏìÁËÔËÐÐAndroid 8.0¡¢8.1¡¢9ºÍ10°æ±¾µÄ×°±¸¡£±ðµÄ£¬¹È¸è»¹ÐÞ¸´ÁËýÌå¿ò¼ÜÖеÄÁíÍâÁ½¸öÑÏÖØÎó²î£¬°üÀ¨ÌØÈ¨ÌáÉýÎó²î£¨CVE-2020-0033£©ºÍÐÅϢй¶Îó²î£¨CVE-2020-0034£©¡£´Ë´Î¸üÐÂÐÞ¸´Á˸ßͨ±ÕÔ´×é¼þÖеÄ40¸öÎó²î£¬ÆäÖÐ16¸ö±»ÆÀΪÑÏÖØ¼¶±ð¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/98901/mobile-2/googles-march-2020-security-updates-android.html
6.¼ÎÄ껪ÓÎÂÖ¼¯ÍÅÔâºÚ¿ÍÈëÇÖ£¬¿Í»§Êý¾Ý¿ÉÄÜй¶
È«Çò×î´óµÄÓÎÂÖÔËÓªÉ̼ÎÄ껪ÓÎÂÖ¼¯ÍÅ£¨Carnival Corporation£¦plc£©ÔâºÚ¿ÍÈëÇÖ£¬¿Í»§Êý¾Ý¿ÉÄÜй¶¡£Æ¾Ö¤¸Ã¹«Ë¾µÄת´ï£¬ÔÚ2019Äê4ÔÂ11ÈÕÖÁ7ÔÂ23ÈÕÖ®¼äδ¾ÊÚȨµÄ¹¥»÷Õß»á¼ûÁËijЩ°üÀ¨¿Í»§ÐÅÏ¢µÄÔ±¹¤ÓÊÏäÕË»§£¬¿ÉÄÜй¶µÄÐÅÏ¢°üÀ¨¿Í»§µÄÐÕÃû¡¢µØµã¡¢Éç»áÇå¾²ºÅÂë¡¢Õþ¸®Ê¶ÓÖÃûÂ루ÀýÈ绤ÕÕID»ò¼ÝÕÕID£©¡¢ÐÅÓÿ¨ºÍÒøÐÐÕË»§ÐÅÏ¢ÒÔ¼°Ó뿵½¡×´Ì¬Ïà¹ØµÄÐÅÏ¢¡£¼ÎÄ껪»¹³ÆÄ¿½ñûÓÐÖ¤¾ÝÅú×¢ÊÂÎñ±¬·¢ºóÊÜÓ°Ïì¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢±»ÀÄÓá£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/carnival-cruise-line-operator-discloses-potential-data-breach/


¾©¹«Íø°²±¸11010802024551ºÅ