¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190214
°ä²¼¹¦·ò 2019-02-14
°²È«×êÑÐÔ±Chris Moberly·¢ÏÖCanonical snapdÊØ»¤¹ý³ÌµÄREST APIÖдæÔÚзì϶Dirty_Sock£¬£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶¿ÉÔÊÐí¹¥»÷ÕßÔÚLinuxϵͳÉÏ»ñµÃrootȨÏÞ¡£¡£¡£¡£¡£¸Ã·ì϶»áÓ°Ïìµ½ÈκÎʹÓÃsnapdµÄLinuxϵͳ£¬£¬£¬£¬£¬£¬£¬£¬µ«·ì϶ÀûÓÿÉÄÜ»áÓÐËù·ÖÆç¡£¡£¡£¡£¡£CanonicalÒÑÔÚа汾Snapd 2.37.1Öн¨¸´ÁË´Ë·ì϶£¬£¬£¬£¬£¬£¬£¬£¬½¨ÒéÖÎÀíÔ±¾¡¿ì×°ÖøüС£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/canonical-snapd-vulnerability-gives-root-access-in-linux/2¡¢Adobe°ä²¼2Ô°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´44¸ö¸ßΣ·ì϶
Adobe°ä²¼2Ô°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬¹²½¨¸´44¸ö¸ßΣ·ì϶¡£¡£¡£¡£¡£½ÏΪÑϳÁµÄ·ì϶Ô̺¬Flash PlayerÖеÄÔ½½ç¶Á·ì϶£¨CVE-2019-7090£¬£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÐÅϢй¶£©¡¢ColdFusionÖеķ´ÐòÁл¯·ì϶£¨CVE-2019-7091£¬£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐУ©ºÍxss·ì϶£¨CVE-2019-7092£¬£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÐÅϢй¶£©ÒÔ¼°Cloud DesktopÖеÄDLL½Ù³Ö·ì϶£¨CVE-2019-7093£¬£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÌáȨ£©¡£¡£¡£¡£¡£½¨ÒéÓû§¾¡¿ì¸üС£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/adobes-massive-patch-update-fixes-critical-acrobat-reader-bugs/3¡¢×êÑÐÈËÔ±ÑÝʾÈôºÎÔÚIntel SGXÖÐÖ²Èë¶ñÒâÈí¼þ
×êÑÐÈËÔ±ÑÝʾÈôºÎÔÚIntel SGXÖаµ²Ø¶ñÒâ´úÂë¡£¡£¡£¡£¡£Intel SGXÊÇSkylake´¦ÖÃÆ÷ÖÐÒýÈëµÄÐÂÖ°ÄÜ£¬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚ±£»£»£»£»£»¤Èí¼þµÄ´úÂëºÍÓйØÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬È·±£Æä»úÃÜÐÔºÍÆëÈ«ÐÔ¡£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾ËûÃǵÄPoCÀûÓÃÁËTSXºÍASLRµÈ£¬£¬£¬£¬£¬£¬£¬£¬²¢Ö¸³öÆëÈ«µÄ·ì϶ÀûÓùý³ÌºÄʱ20.8Ãë¡£¡£¡£¡£¡£Õë¶Ô´ËÀ๥»÷µÄ»º½â´ëÊ©¿ÉÄÜÔÚ½«À´¼¸´úÓ¢ÌØ¶ûCPUÖÐÖ´ÐС£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/02/intel-sgx-malware-hacking.html4¡¢AstarothľÂíбäÌ壬£¬£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶Ô°ÍÎ÷ºÍÅ·ÖÞ
CybereasonµÄNocturnus×êÑÐÍŶӷ¢ÏÖAstarothľÂíµÄбäÌ壬£¬£¬£¬£¬£¬£¬£¬¸Ã±äÌåÖØÒªÕë¶Ô°ÍÎ÷ºÍÅ·ÖÞ£¬£¬£¬£¬£¬£¬£¬£¬²¢Í¨¹ýÀ¬»øÓʼþ·Ö·¢¡£¡£¡£¡£¡£Æäpayload»áÌìÉú¶ñÒâµÄwmic.exe¹ý³Ì£¬£¬£¬£¬£¬£¬£¬£¬²¢ÏòC2·þÎñÆ÷·¢ËÍÖ¸±êÍÆËã»úµÄÓйØÐÅÏ¢¡£¡£¡£¡£¡£¸ÃľÂí»¹»áÔÚAvast·À²¡¶¾Èí¼þµÄaswrundll.exeÔËÐÐʱDLLÖÐ×¢Èë¶ñÒâÄ£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬£¬£¬²¢ÀûÓÃËüÀ´ÍøÂçϵͳÐÅÏ¢ºÍ¼ÓÔØ¶î±íµÄÄ£¿£¿£¿£¿£¿£¿£¿é¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-astaroth-trojan-variant-exploits-anti-malware-software-to-steal-info/5¡¢ÒøÐÐľÂíTrickBotбäÌ壬£¬£¬£¬£¬£¬£¬£¬¿ÉÇÔÈ¡RDP¡¢VNCºÍPuTTYÍ´´¦
Ç÷Ïò¿Æ¼¼µÄ×êÑÐÈËÔ±·¢ÏÖÒøÐÐľÂíTrickbotµÄÒ»¸öбäÌ壬£¬£¬£¬£¬£¬£¬£¬¸Ã±äÌåΪÃÜÂëÇÔȡģ¿£¿£¿£¿£¿£¿£¿éÐÂÔöÁËÈý¸öÖ°ÄÜ£¬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚÇÔÈ¡Óû§µÄRDP¡¢VNCºÍPuTTYÍ´´¦¡£¡£¡£¡£¡£¸Ã±äÌåÊÇ»ùÓÚ2018Äê11Ôµİ汾£¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ýÒÔ˰ÊÕ¼¤ÀøÍ¨ÖªÎªÖ÷ÌâµÄÀ¬»øÓʼþ½øÐд«²¼£¬£¬£¬£¬£¬£¬£¬£¬Æä¶ñÒ⸽¼þΪXLSMÌåʽµÄexcelÎļþ¡£¡£¡£¡£¡£TrickBot×Ô2016Äê10Ô³öÏÖÒÔÀ´£¬£¬£¬£¬£¬£¬£¬£¬Ò»ÏòÔÚ²»ÐݽøÐиüС£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/trickbot-banking-trojan-now-steals-rdp-vnc-and-putty-credentials/6¡¢AZORultľÂíй¥»÷»î¶¯£¬£¬£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÒâ´óÀû

Cybaze-Yori ZLAB·¢ÏÖAZORultľÂíµÄй¥»÷»î¶¯£¬£¬£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÒâ´óÀû¡£¡£¡£¡£¡£¸ÃľÂíбäÌåͨ¹ý¼Ù×°³ÉDHL¿ìµÝ֪ͨµÄÓʼþ½øÐд«²¼£¬£¬£¬£¬£¬£¬£¬£¬µ±Óû§´ò¿ª¶ñÒâµÄѹËõÎĵµ¸½¼þºó£¬£¬£¬£¬£¬£¬£¬£¬¾Í»áÏÂÔØ²¢ÔËÐиÃľÂí¡£¡£¡£¡£¡£¸ÃľÂíÄܹ»ÇÔÈ¡Webä¯ÀÀÆ÷ÒÔ¼°Óʼþ¿Í»§¶ËÖб£ÁôµÄÕË»§ºÍÍ´´¦£¬£¬£¬£¬£¬£¬£¬£¬²¢Äܹ»×°ÖÃÆäËüµÄpayload¡£¡£¡£¡£¡£ÆäC2·þÎñÆ÷Ϊgoogodsgld[.]comºÍdriverconnectsearch[.]info¡£¡£¡£¡£¡£¸Ã±äÌåµÄÐÐΪÀàËÆÓÚBrushloader¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/specially-crafted-dhl-express-courier-emails-leveraged-to-distribute-a-variant-of-azorult-trojan-f9ea2931ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ