΢ÈíÐû²¼½ôÆÈ¸üУ¬ÐÞ¸´OfficeºÍPaint 3DÖжà¸öÎó²î£»ÃÀ¹úSBA¹ÙÍø±£´æÎó²îй¶8000¼ÒÆóÒµµÄÃô¸ÐÐÅÏ¢
Ðû²¼Ê±¼ä 2020-04-241.΢ÈíÐû²¼½ôÆÈ¸üУ¬ÐÞ¸´OfficeºÍPaint 3DÖжà¸öÎó²î
MicrosoftÐû²¼Á˽ôÆÈÇå¾²¸üУ¬ÒÔÐÞ¸´Ê¹ÓÃÁËAutodesk FBX¿âµÄMicrosoft²úÆ·£¬°üÀ¨¶à¸ö°æ±¾µÄMicrosoft OfficeºÍWindows 10Ó¦ÓóÌÐòPaint 3D¡£±¾´ÎÐÞ¸´µÄÎó²îΪFBX¿âÖеÄÔ¶³ÌÖ´ÐдúÂëÎó²î£¬¹¥»÷ÕßʹÓôËÎó²î¿ÉÒÔ»ñµÃÓëÍâµØÓû§ÏàͬµÄȨÏÞ£¬AutodeskÔÚ4ÔÂ15ÈÕÍÆ³öÁËÕë¶Ô´ËÎó²îµÄ²¹¶¡³ÌÐò¡£MicrosoftÌåÏÖ£¬ºÚ¿Í±ØÐèÓÕʹÓû§·¿ªÆäÌØÖÆµÄ3DÎļþ²Å¿ÉÒÔÀÖ³ÉʹÓôËÎó²î£¬Òò´Ë£¬ÔÚÇå¾²¸üÐÂ֮ǰÓû§ÐèÒªÔ¶ÀëÄÇЩ¿ÉÒÉÎļþÒÔ°ü¹ÜÇå¾²¡£
ÔÎÄÁ´½Ó£º
https://news.softpedia.com/news/microsoft-releases-emergency-update-for-windows-10-app-microsoft-office-529800.shtml
2.ÃÀ¹úSBA¹ÙÍø±£´æÎó²îй¶8000¼ÒÆóÒµµÄÃô¸ÐÐÅÏ¢
ÃÀ¹úСÐÍÆóÒµÖÎÀí¾Ö£¨SBA£©¹ÙÍø±£´æÎó²î£¬Ð¹Â¶ÁË8000¼ÒÆóÒµµÄÃô¸ÐÐÅÏ¢£¬½«µ¼ÖÂÆäÈÏÕæµÄ¾¼ÃΣÏÕÔÖÄÑ´û¿î£¨EIDL£©µÄ·Ö·¢ÑÓ³Ù¡£´Ë´ÎÊý¾Ýй¶ÊÇÓÉÓÚÕþ¸®°²ÅÅÍøÕ¾Ê±±£´æÎÊÌ⣬µ¼ÖÂÓû§ÔÚÉêÇë´û¿îµÄÒ³ÃæÊµÑéÍËȴʱ£¬±ã¿ÉÒÔ¿´µ½ÆäËûÆóÒµµÄÐÅÏ¢¡£Ð¹Â¶µÄÊý¾Ý°üÀ¨ÐÕÃû¡¢Éç»áÇå¾²ºÅÂ롢˰ºÅ¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢µç×ÓÓʼþ¡¢µç»°ºÅÂë¡¢»éÒöºÍ¹«Ãñ¹ØÏµ¡¢¼ÒÍ¥ÈËÊý¡¢ÊÕÈë¡¢Åû¶ÅÌÎÊÒÔ¼°½ðÈںͰü¹ÜÐÅÏ¢¡£ÐÂÎÅýÌåCNBCÌåÏÖ£¬Õþ¸®ÎªÁËÅâ³¥Êܵ½Ó°ÏìµÄÆóÒµ£¬½«ÎªÆäÌṩΪÆÚÒ»ÄêµÄÉí·Ý͵ÇÔ±£»¤·þÎñ¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/small-businesses-covid-19-loans-data-exposure/155013/
3.Ó¢¹úµçÉÌRobert DyasÔâ¹¥»÷£¬Ô¼2Íò¿Í»§Ö§¸¶ÐÅÏ¢±»ÇÔ
3ÔÂ7ÈÕÖÁ30ÈÕ£¬Ó¢¹úµçÉ̹«Ë¾Robert DyasµÄÍøÕ¾Ôâµ½ÐÅÓÿ¨ÇÔÈ¡¶ñÒâ¾ç±¾µÄ¹¥»÷£¬Ð¹Â¶Á˸ù«Ë¾Ô¼2ÍòÃû¿Í»§µÄÖ§¸¶ÐÅÏ¢£¬°üÀ¨¿Í»§ÐÕÃû¡¢µØµã¡¢ÐÅÓÿ¨¿¨ºÅ¡¢ÓÐÓÃÆÚºÍÇå¾²´úÂ루CVV£©µÈ¡£¿ÉÒÔÈ·ÐŵÄÊǴ˴ι¥»÷ΪÐÅÓÿ¨ÇÔÈ¡¶ñÒâÈí¼þ¹¥»÷£¬µ«ÓÉÓÚÐÅϢȱ·¦ÏÖÔÚÎÞ·¨È·¶¨¸Ã¶ñÒâÈí¼þÊÇ·ñΪMagecart¡£ÕâÀ๥»÷ͨ³£ÊÇÕë¶Ô¹©Ó¦Á´µÄ£¬Í¨¹ýÆÆËðÖ§¸¶Ò³ÃæÖеĵÚÈý·½ÍøÕ¾½«¶ñÒâJavascript×¢Èëµ½¸¶¿îÒ³ÃæÖС£Robert Dyas¹«Ë¾ÌåÏÖ£¬×Ô3ÔÂ30ÈÕ·¢Ã÷¹¥»÷ºó£¬ËûÃǵÚһʱ¼ä½ÓÄÉÁ˲½·¥£¬²¢°ü¹Ü×Ô3ÔÂ31ÈÕÆðÍøÕ¾±ã¿ÉÒÔÇå¾²ÔËÐС£
ÔÎÄÁ´½Ó£º
https://www.theregister.co.uk/2020/04/22/robert_dyas_card_skimmer/
4.Tag BarnakleÈëÇÖÆóÒµ¹ã¸æ·þÎñÆ÷ReviveÈö²¥¶ñÒâ¹ã¸æ
¾Ý¹ã¸æÇå¾²¹«Ë¾Confiant±¨µÀ£¬Tag BarnakleºÚ¿Í×éÖ¯ÈëÃé×¼ÁËÆóÒµµÄ¿ªÔ´×ÔÍÐ¹Ü¹ã¸æ·þÎñÆ÷ReviveÒÔÈö²¥¶ñÒâ¹ã¸æ£¬½ü¼¸¸öÔÂÒѾÓм¸Ê®Ì¨·þÎñÆ÷±»¹¥»÷£¬°üÀ¨ÄÇЩÐû²¼ÉÌºÍ¹ã¸æ¹«Ë¾×ÔÓªµÄ¹ã¸æ·þÎñÆ÷¡£Tag BarnakleÍÅ»ïÊÇͨ¹ýÏòÍøÕ¾×¢Èë¶ñÒâJavaScript´úÂëʵÏÖ¹¥»÷µÄ£¬ÕâЩ´úÂë¿ÉÒÔ¼ì²âÄ¿µÄ»úеÊÇ·ñ·¿ªÁËFirebug»òä¯ÀÀÆ÷µÄ¿ª·¢Ö°Ô±¿ØÖÆÌ¨£¬ÈôÊÇδ·¿ª£¬Ôò½«Óû§Öض¨Ïòµ½·Ö·¢ÐéαAdobe Flash¸üеĶñÒâÍøÕ¾¡£ConfiantÊӲ췢Ã÷Tag Barnakle¹¥»÷ÁËÁè¼Ý360¸öÍøÕ¾¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/revive-ad-servers-being-hacked-to-distribute-malicious-ads/
5.Ñо¿Ö°Ô±·¢Ã÷3¿îÖÇÄܼҾÓϵͳ±£´æ¶à¸öÇå¾²Îó²î
ESET IoT ResearchÑо¿Ö°Ô±ÔÚ3¿î²î±ðµÄÖÇÄܼҾÓϵͳFibaro Home Center Lite¡¢Homematic Central Control Unit (CCU2) ºÍ eLAN-RF-003Öз¢Ã÷Á˶à¸öÇå¾²Îó²î£¬ÕâЩÎó²î¿ÉÄܵ¼ÖÂÃô¸ÐÊý¾Ýй¶¡¢Ô¶³Ì´úÂëÖ´ÐкÍÖÐÐÄÈ˹¥»÷µÈ¡£Fibaro²úÆ·ÓÉÓÚȱÉÙÖ¤ÊéÑé֤ʹµÃÆäTLSÁ´½ÓÈÝÒ×Êܵ½ÖÐÐÄÈ˹¥»÷£¬´Ó¶øÊ¹¹¥»÷Õß»ñµÃrootÓû§»á¼ûȨÏÞ¡£eQ?3µÄ²úÆ·CCU2±£´æRCEÎó²î£¬Ê¹¹¥»÷Õß¿ÉÒÔͨ¹ý´ó×ÚshellÏÂÁîÀ´Ê¹ÓÃRCEÎó²î£¬ÒÔrootÓû§Éí·ÝÖ´ÐÐδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì´úÂë¡£ELKO EPµÄ²úÆ·eLAN-RF-003 ÓÉÓÚ±£´æÒ»Ð©Îó²î£¬µ¼ÖÂÆä±£´æÃô¸ÐÐÅÏ¢×ß©¡¢Ò×ÊܼͼºÍÖØ·Å¹¥»÷µÄÎÊÌâ¡£ESET IoT ResearchÌåÏÖ£¬¼¸¼Ò×°±¸ÖÆÔìÉ̾ùÔÚ½ÓÊܱ¨¸æºóµÄ90ÌìÄÚÐÞ¸´ÁËÕâЩÎó²î¡£
ÔÎÄÁ´½Ó£º
https://www.welivesecurity.com/2020/04/22/serious-flaws-smart-home-hubs-is-your-device-among-them/
6.ºÚ¿ÍʹÓÃGoogleµÄ.app gTLD´¹ÂÚ¹¥»÷£¬ÇÔÈ¡Óû§Skypeƾ֤
CofenseÍøÂçÇå¾²¹«Ë¾·¢Ã÷ºÚ¿Íͨ¹ýÓÉGoogleÖÎÀíµÄ.APPͨÓö¥¼¶Óò£¨gTLD£©¶ÔÔ¶³ÌÊÂÇéÖ°Ô±ÌᳫÁËÍøÂç´¹ÂÚ¹¥»÷£¬ÒÔÇÔÈ¡ÆäSkypeƾ֤¡£ºÚ¿ÍÈ«ÐÄÉè¼ÆÁËÍøÂç´¹ÂÚÒ³Ãæ¼°ÆäÁ´½Ó£¬Í¨¹ýʹÓÃGoogleµÄ.APPͨÓö¥¼¶Óò£¨gTLD£©ÖеÄÁ´½Ó¾ÙÐгõÊ¼ÖØ¶¨Ïò£¬Ê¹ÆäÖ¸ÏòαÔìµÄÍøÂç´¹ÂÚÒ³Ãæ¡£ºÚ¿ÍʹÓÃÁË.APP gTLDÀֳɵÄÈÆ¹ýÍøÂç´¹ÂÚÓʼþµÄ¼ì²â£¬²¢ÇÒÔÚαÔìÒ³ÃæÉÏÏÔʾÁËÊܺ¦Õß¹«Ë¾µÄ»Õ±êºÍÇå¾²ÌáÐÑ£¬Ê¹µÃ´Ë´Î¹¥»÷¿´ÆðÀ´Ô½·¢ÕæÊµ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/creative-skype-phishing-campaign-uses-googles-app-gtld/


¾©¹«Íø°²±¸11010802024551ºÅ