¸ßͨæçÁúоƬ¸ßΣ·ì϶£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂ˽Կй¶£»£»£»£»£»£»DMSÔâGandCrab¹¥»÷£»£»£»£»£»£»ÍÚ¿óÈí¼þBeapy
°ä²¼¹¦·ò 2019-04-26
¸ßͨоƬ×é´æÔÚÒ»¸ö²àÐÅ·¹¥»÷·ì϶£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶£¨CVE-2018-11976£©¿ÉÔÊÐí¹¥»÷Õß´Ó¸ßͨоƬµÄQSEE°²È«ÇøÓòÖмìË÷¼ÓÃÜ˽Կ¡£¡£¡£¡£¡£¡£¡£QSEEÊǸßͨоƬµÄ¿ÉÐÅÖ´Ðл·¾³£¨TEE£©£¬£¬£¬£¬£¬£¬£¬ÀàËÆÓÚÓ¢ÌØ¶ûµÄSGX¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝNCC×êÑÐÈËÔ±Keegan RyanµÄ±íÊö£¬£¬£¬£¬£¬£¬£¬¸ßͨоƬµÄ¼ÓÃÜÊðÃûËã·¨ECDSA£¨ÍÖÔ²ÇúÏßËã·¨£©´æÔÚ·ì϶£¬£¬£¬£¬£¬£¬£¬¿Éͨ¹ýËæ»úÊýµÄһЩbit´§Ä¦³ö256λECDSAÃÜÔ¿¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶µÄÀûÓñØÒªÉ豸µÄrootȨÏÞ¡£¡£¡£¡£¡£¡£¡£ÓÐ46¿î¸ßͨоƬ×éÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬Ô̺¬¶à¿îæçÁúоƬ¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶µÄ½¨¸´²¹¶¡ÒѾÔ̺¬ÔÚGoogle°ä²¼µÄ4ÔÂAndroid°²È«¸üÐÂÖÓ×£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/security-flaw-lets-attackers-recover-private-keys-from-qualcomm-chips/2.DMSÔâGandCrab¹¥»÷£¬£¬£¬£¬£¬£¬£¬Ô¼38¸öÒ½ÁÆÖÐÐĵÄÊý¾ÝÊÜÓ°Ïì
ÔÎÄÁ´½Ó£º
https://cyware.com/news/doctors-management-service-hit-with-gandcrab-ransomware-attack-compromising-patient-data-b6eebd023.Å·ÖÞÔì×÷ÉÌAebi SchmidtÔâδ֪ÀÕË÷Èí¼þ¹¥»÷
ÈðÊ¿ÊÐÕþºÍũҵ»úеÔì×÷ÉÌAebi Schmidt³ÉΪÀÕË÷Èí¼þ¹¥»÷µÄ×îÐÂÊܺ¦Õß¡£¡£¡£¡£¡£¡£¡£¾ÝTechCrunch±¨Â·£¬£¬£¬£¬£¬£¬£¬ÀÕË÷Èí¼þ¹¥»÷ÑϳÁÓ°ÏìÁËAebi SchmidtµÄÅ·ÖÞ»ùµØ£¬£¬£¬£¬£¬£¬£¬µ¼ÖºܶàϵͳÎÞ·¨ÔËÐУ¬£¬£¬£¬£¬£¬£¬Ô̺¬ÓйØÔì×÷ÒµÎñϵͳ¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾µÄµç×ÓÓʼþ·þÎñÒ²Êܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬²¿ÃÅÔ±¹¤±»ÆÈÆðÍ·ÐÝÎÞн¼Ù¡£¡£¡£¡£¡£¡£¡£Aebi Schmidt³Æ¹¥»÷µÄÔÒòÈÔδȷ¶¨¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/unknown-ransomware-cripples-computer-systems-of-aebi-schmidt-ffa880fb4.жñÒâÍÚ¿óÈí¼þBeapy£¬£¬£¬£¬£¬£¬£¬ÒÑϰȾ³¬¹ý1.2Íò¸öÓû§
ÔÎÄÁ´½Ó£º
https://techcrunch.com/2019/04/25/cryptojacking-nsa-malware/5.¹¥»÷ÕßÀÄÓÃGitHub·þÎñÍйÜÍøÂç´¹µö¹¤¾ß°ü
Proofpoint×êÑÐÍŶӷ¢ÏÖ¶ñÒâ¹¥»÷ÕßÀÄÓÃGitHubµÄÍøÒ³¼Ä·Å·þÎñÀ´ÍйÜÍøÂç´¹µö¹¤¾ß°ü¡£¡£¡£¡£¡£¡£¡£ÕâÖÖ²½ÖèʹµÃ¹¥»÷ÕßÄܹ»ÀûÓÃgithub.ioÓòÃûÈÆ¹ý°×Ãûµ¥µÈ·ÀÓù´ëÊ©¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖÕâЩ´¹µö¹¤¾ß°ü´óÎÞÊýÓÃÓÚÍøÂçÊܺ¦ÕßµÄÍ´´¦£¨ÀýÈçÒøÐÐÕË»§Í´´¦£©µÈÃô¸ÐÐÅÏ¢²¢·¢ËÍÖÁ¹¥»÷ÕߵķþÎñÆ÷¡£¡£¡£¡£¡£¡£¡£GitHubÒÑÔÚ4ÔÂ19ÈÕ²ÉÈ¡´ëÊ©½ûÓÃÁËÕâЩ¶ñÒâÕË»§¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/github-service-abused-by-attackers-to-host-phishing-kits/6.TA505ÀûÓÃLOLBinsºÍServHelper¶Ô×¼½ðÈÚ¹«Ë¾
Cybereason×êÑÐÈËÔ±·¢ÏÖ·¸×ïÍÅ»ïTA505µÄй¥»÷»î¶¯ÀûÓöàÖÖºýŪ¼¼Êõ¶Ô×¼½ðÈÚ»ú¹¹¡£¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïѡȡÁ˶àÖÖÕ½ÊõÀ´Ìӱܼì²â£¬£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶Ô½ðÈÚÆóÒµµÄÌØ¶¨ÕË»§½øÐд¹µö¹¥»÷¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÁ˶à¸öC2ÓòÃûÒÔÈÆ¹ýºÚÃûµ¥¼ì²â£¬£¬£¬£¬£¬£¬£¬²¢ÔÚÖ¸±êϵͳÉÏ¿ªÊÍServHelperºóÃÅ¡£¡£¡£¡£¡£¡£¡£¸ÃServHelper±äÌåÒÀÀµÓÚËĸöLOLBinsºÍ±¾µØÏµÍ³¹ý³ÌÖ´ÐжñÒâ»î¶¯£¬£¬£¬£¬£¬£¬£¬´Ë±í£¬£¬£¬£¬£¬£¬£¬ServHelper»¹Ê¹ÓÃÁËSectigo RSA Code Signing CAÊðÃûµÄÓÐЧ֤ÊéÀ´Ìӱܼì²â¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/ta505-group-uses-lolbins-and-servhelper-backdoor-to-compromise-financial-firms-00550f4d


¾©¹«Íø°²±¸11010802024551ºÅ