Î÷ÃÅ×Ó¶à¿î¹¤Òµ×°±¸ÊÜLinuxÄÚºËÎó²îSegmentSmackÓ°Ï죻ŷÖÞÄÜÔ´¹«Ë¾EDPѬȾRagnarLocker
Ðû²¼Ê±¼ä 2020-04-161.Î÷ÃÅ×Ó¶à¿î¹¤Òµ×°±¸ÊÜLinuxÄÚºËÎó²îSegmentSmackÓ°Ïì
Î÷ÃÅ×ÓÐû²¼4Ô²¹¶¡¸üУ¬ ÆäÖÐ3ÌõÐÂͨ¸æÍ¨Öª¿Í»§Æä¶à¿î¹¤Òµ×°±¸Êܵ½LinuxÄÚºËÎó²îSegmentSmackÓ°Ïì¡£SegmentSmackºÍFragmentSmack£¨»®·Ö±»¸ú×ÙΪCVE-2018-5390ºÍCVE-2018-5391£©ÊÇÑо¿ÈËJuha-Matti TilliÔÚ2018Äê·¢Ã÷µÄÁ½¸öLinuxÄÚºËÎó²î£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÄ¿µÄϵͳ·¢ËͶñÒâÊý¾Ý°üÀ´ÌᳫDoS¹¥»÷¡£ÔÚµÚÒ»·Ýͨ¸æÖÐÎ÷ÃÅ×Ó³ÆSegmentSmackºÍFragmentSmackÓ°ÏìÁËËüµÄIE/PB-Link×°±¸¡¢RUGGEDCOM·ÓÉÆ÷¡¢»ùÓÚROXµÄVPNÖն˺ͷÀ»ðǽ¡¢SCALANCE·ÓÉÆ÷ºÍ·À»ðǽ¡¢SIMATICͨѶ´¦Öóͷ£Æ÷ºÍSinema Remote Connect¡£µÚ¶þ·Ýͨ¸æÖÐÎ÷ÃÅ×ÓÅû¶ÓëSegmentSmackÓйصÄDoSÎó²î£¨CVE-2019-19301£©£¬¸ÃÎó²îÓ°ÏìÁËSIMATICͨѶģ¿é¡¢SCALANCE X½»Á÷»úºÍSIPLUS×°±¸¡£µÚÈý·Ýͨ¸æÔòÅû¶ÁËÓ°ÏìÎ÷ÃÅ×ÓSIDOORÃÅÖÎÀíϵͳ¡¢SIMATIC×°±¸¡¢SINAMICSת»»Æ÷ºÍSIPLUS²úÆ·µÄDoSÎó²î£¨CVE-2019-19300£©¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/siemens-industrial-devices-affected-segmentsmack-linux-kernel-flaw
2.Ó¢ÌØ¶ûÐû²¼4ÔÂÇå¾²¸üУ¬ÐÞ¸´¶à¿î²úÆ·ÖеÄ9¸öÎó²î
Ó¢ÌØ¶ûÔÚ4Ô²¹¶¡¸üÐÂÖÐÐÞ¸´ÁË9¸öÎó²î£¬ÕâЩÎó²î¾ùΪÖиßΣÎó²î£¬Ó°Ïì¶à¸öÈí¼þ¡¢¹Ì¼þ¼°Æ½Ì¨¡£Ó¢ÌضûÐÞ¸´ÁËPROSet/ÎÞÏßWiFi²úÆ·ÔÚWindows 10ÉϵÄÁ½¸öÎó²î-¾ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÓÉÓÚ²»Çå¾²µÄ¼ÌÐøÈ¨ÏÞ¶ø¿ÉÄÜͨ¹ýÍâµØ»á¼û¾ÙÐÐÌØÈ¨Éý¼¶£¨CVE-2020-0557£©£»ÓÉÓÚÄÚºËÇý¶¯³ÌÐòÖеĻº³åÇøÏÞÖÆ²»µ±£¬ÎÞÌØÈ¨µÄ¹¥»÷Õß¿ÉÄÜͨ¹ýÏàÁÚÍøÂç»á¼ûÀ´µ¼Ö¾ܾø·þÎñ£¨CVE-2020-0558£©¡£Ó¢Ìضû»¹ÐÞ¸´ÁËNUC mini PCµÄϵͳ¹Ì¼þÖкÍÄ£¿é»¯·þÎñÆ÷MFS2600KISPPÅÌËãÄ£¿éÖеÄÁ½¸öÎó²î£¬°üÀ¨²»×¼È·µÄ»º³åÇøÏÞÖÆµ¼ÖµÄLPEÎó²î£¨CVE-2020-0600£©ºÍÌõ¼þ¼ì²é²»µ±µ¼ÖµÄÌáȨÎó²î£¨CVE-2020-0578£©¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/intel-april-platform-update-fixes-high-severity-security-issues/
3.΢ÈíÐû²¼4ÔÂOfficeÇå¾²¸üУ¬ÐÞ¸´55¸öÎó²î
΢ÈíÔÚ4ÔÂOfficeÇå¾²¸üÐÂÖÐÕë¶Ô7¸ö²úÆ·ÐÞ¸´ÁË55¸öÎó²î£¬ÆäÖаüÀ¨Ó°ÏìÁËMicrosoft OfficeºÍMicrosoft Office SharePoint²úÆ·µÄ12¸öRCEÎó²î£¬ÕâЩÎó²î¾ù±»¹éÀàΪÑÏÖØ»òÖ÷Òª¼¶±ð£¬¹¥»÷Õß¿ÉÒÔʹÓÃËüÃÇÔÚSharePointÓ¦ÓóÌÐòºÍSharePoint·þÎñÆ÷ÕÊ»§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂ롣΢Èí»¹ÐÞ¸´ÁË10¸öXSSÎó²î£¬¹¥»÷Õß¿ÉÄÜʹÓÃÕâЩÎó²îÔÚÄ¿½ñÓû§µÄÇå¾²ÉÏÏÂÎÄÖÐÔËÐо籾²¢Ã°³äÓû§¡¢ÇÔÈ¡Ãô¸ÐÊý¾Ý»òδ¾ÊÚȨÔĶÁÄÚÈÝ¡£±ðµÄ£¬Î¢ÈíÐÞ¸´ÁËÁ½¸öÌáȨÎó²îºÍËĸöÓÕÆÎó²î¡£ÏêϸÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-office-april-security-updates-fix-critical-rce-bugs/
4.Å·ÖÞÄÜÔ´¹«Ë¾EDPѬȾRagnarLocker£¬±»ÀÕË÷½ü1000ÍòÅ·Ôª
¿ËÈÕÆÏÌÑÑÀ¿ç¹úÄÜÔ´¾ÞÍ·Energias de Portugal£¨EDP£©Ôâµ½ÀÕË÷Èí¼þRagnarLocker¹¥»÷£¬±»ÀÕË÷1580 BTCµÄÊê½ð£¨Ô¼ºÏ1090ÍòÃÀÔª»ò990ÍòÅ·Ôª£©¡£EDP¼¯ÍÅÊÇÅ·ÖÞÄÜÔ´ÐÐÒµ£¨×ÔÈ»ÆøºÍµçÁ¦£©×î´óµÄÔËÓªÉÌÖ®Ò»£¬Ò²ÊÇÌìϵÚËÄ´ó·çÄÜÉú²úÉÌ¡£¸Ã¹«Ë¾ÔÚÈ«ÇòËĸö´óÖÞµÄ19¸ö¹ú¼Ò/µØÇøÓµÓÐÓªÒµ£¬²¢ÇÒÓµÓÐÁè¼Ý11500ÃûÔ±¹¤ºÍΪÁè¼Ý1100Íò¿Í»§ÌṩÄÜÔ´¡£ÔÚ¹¥»÷Àú³ÌÖУ¬Ragnar Locker¹¥»÷ÍÅ»ïÉù³ÆÇÔÈ¡ÁËÁè¼Ý10 TBµÄ¹«Ë¾Ãô¸ÐÎļþ£¬²¢Íþв³ÆÈôÊǸù«Ë¾¾Ü¾øÖ§¸¶Êê½ð£¬ËûÃǽ«Ðû²¼ÍµÈ¡µÄËùÓÐÊý¾Ý¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/ragnarlocker-ransomware-hits-edp-energy-giant-asks-for-10m/
5.TA505¼ÌÐøÊ¹ÓÃSDBbot RATѬȾÆóÒµÍøÂ磬Ö÷ÒªÕë¶ÔÅ·ÖÞ
IBM X-ForceÍŶÓÊӲ쵽TA505¼ÌÐøÊ¹ÓÃSDBbot RATѬȾÆóÒµÍøÂç¡£ÔÚ2019Äê11Ô£¬X-Force IRISÊӲ쵽Óй¥»÷ÕßʹÓÃð³äµÄOnehub´¹ÂÚÓʼþ¹¥»÷Å·ÖÞµÄÆóÒµÔ±¹¤£¬¸Ã´¹ÂÚÓʼþÖ¼ÔÚÇÔÈ¡Active Directory£¨AD£©Êý¾Ý¼°Óû§Æ¾Ö¤£¬²¢Ê¹ÓÃSDBbot RATѬȾÆóÒµÍøÂçÇéÐΡ£Æ¾Ö¤Ñо¿Ö°Ô±¶Ô¹¥»÷ÕßµÄTTP¡¢C£¦C»ù´¡ÉèÊ©ÒÔ¼°ÏÈǰ¹éÒòÓÚ¸Ã×éÖ¯µÄÌØ¶¨¶ñÒâÈí¼þµÄÆÊÎö£¬X-Force IRISÒÔΪTA505ÊǸù¥»÷Ô˶¯±³ºóµÄ¹¥»÷ÍŻ
ÔÎÄÁ´½Ó£º
https://securityintelligence.com/posts/ta505-continues-to-infect-networks-with-sdbbot-rat/
6.¾É½ðɽ»ú³¡¹¥»÷Õß»òΪ¶íÂÞ˹APT×éÖ¯Energetic Bear
ESETÑо¿Ö°Ô±ÒÔΪ£¬¶Ô¾É½ðɽ¹ú¼Ê»ú³¡£¨SFO£©ÍøÕ¾µÄ¹¥»÷ÊÇÓɱ»³ÆÎªEnergetic BearµÄ¶íÂÞË¹ÍøÂçÌØ¹¤×éÖ¯¾ÙÐеġ£¸ÃAPT×éÖ¯×Ô2010ÄêÒÔÀ´Ò»Ö±ºÜ»îÔ¾£¬Ö÷ÒªÕë¶ÔÄÜÔ´ºÍ¹¤ÒµÁìÓòµÄ×éÖ¯¡£SFOµÄ»ú³¡ÐÅÏ¢ÊÖÒպ͵çÐŲ¿·Ö£¨ITT£©ÌåÏÖ¹¥»÷ÕßÔÚ»ú³¡ÍøÕ¾ÉÏÖ²ÈëÁ˶ñÒâ´úÂëÒÔÇÔÈ¡Óû§µÄµÇ¼ƾ֤£¬¿ÉÄÜÊܹ¥»÷Ó°ÏìµÄÓû§°üÀ¨Ê¹ÓÃWindows×°±¸»ò·ÇSFOά»¤µÄ×°±¸Í¨¹ýIEä¯ÀÀÆ÷´Ó»ú³¡ÍøÂçÍⲿ»á¼ûÕâÐ©ÍøÕ¾µÄÓû§¡£SFOµÄITÖ°Ô±ÒѾɾ³ýÁË×¢ÈëÆäÍøÕ¾ÖеĶñÒâ´úÂ룬²¢ÔÚ¹¥»÷±¬·¢ºó½«Á½Õß¶¼¾ÙÐÐÁËÍÑ»ú´¦Öóͷ£¡£ÎªÏìÓ¦´ËÊÂÎñ£¬SFO»ú³¡ÖØÖÃÁËËùÓеĵç×ÓÓʼþºÍÍøÂçÃÜÂë¡£ESET³Æ¹¥»÷ÕßʹÓÃSMB¹¦Ð§ºÍfile£º//ǰ׺À´ÊÕ¾Û»á¼ûÕßµÄWindowsƾ֤£¬°üÀ¨Óû§ÃûºÍNTLM¹þÏ£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/101601/apt/energetic-bear-airport-hack.html


¾©¹«Íø°²±¸11010802024551ºÅ