¸ßͨæçÁúоƬ¸ßΣ·ì϶£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂ˽Կй¶£» £»£»£»£»£»DMSÔâGandCrab¹¥»÷£» £»£»£»£»£»ÍÚ¿óÈí¼þBeapy

°ä²¼¹¦·ò 2019-04-26
1.¸ßͨæçÁúоƬ¸ßΣ·ì϶£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂQSEE¼ÓÃÜ˽Կй¶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¸ßͨоƬ×é´æÔÚÒ»¸ö²àÐÅ·¹¥»÷·ì϶£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶£¨CVE-2018-11976£©¿ÉÔÊÐí¹¥»÷Õß´Ó¸ßͨоƬµÄQSEE°²È«ÇøÓòÖмìË÷¼ÓÃÜ˽Կ¡£¡£¡£¡£¡£¡£¡£QSEEÊǸßͨоƬµÄ¿ÉÐÅÖ´Ðл·¾³£¨TEE£©£¬£¬£¬£¬£¬£¬£¬ÀàËÆÓÚÓ¢ÌØ¶ûµÄSGX¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝNCC×êÑÐÈËÔ±Keegan RyanµÄ±íÊö£¬£¬£¬£¬£¬£¬£¬¸ßͨоƬµÄ¼ÓÃÜÊðÃûËã·¨ECDSA£¨ÍÖÔ²ÇúÏßËã·¨£©´æÔÚ·ì϶£¬£¬£¬£¬£¬£¬£¬¿Éͨ¹ýËæ»úÊýµÄһЩbit´§Ä¦³ö256λECDSAÃÜÔ¿¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶µÄÀûÓñØÒªÉ豸µÄrootȨÏÞ¡£¡£¡£¡£¡£¡£¡£ÓÐ46¿î¸ßͨоƬ×éÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬Ô̺¬¶à¿îæçÁúоƬ¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶µÄ½¨¸´²¹¶¡ÒѾ­Ô̺¬ÔÚGoogle°ä²¼µÄ4ÔÂAndroid°²È«¸üÐÂÖÓ×£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/security-flaw-lets-attackers-recover-private-keys-from-qualcomm-chips/

2.DMSÔâGandCrab¹¥»÷£¬£¬£¬£¬£¬£¬£¬Ô¼38¸öÒ½ÁÆÖÐÐĵÄÊý¾ÝÊÜÓ°Ïì

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ò½ÁÆÕ˵¥·þÎñÌṩÉÌDoctors¡¯ Management Service£¨DMS£©Ôâµ½ÀÕË÷Èí¼þGandCrab¹¥»÷£¬£¬£¬£¬£¬£¬£¬½ü38¸öÒ½ÁÆÖÐÐĵϼÕßÊý¾ÝÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬Ô̺¬±´¸¥Àû±í¿ÆÐ­»á¡¢ÐÂÓ¢¸ñÀ¼Éñ¾­×êÑÐËù¡¢ÐÂÓ¢¸ñÀ¼ÉçÇøÒ½ÁÆ·þÎñµÈ¡£¡£¡£¡£¡£¡£¡£ÊÜËðÊý¾ÝÔ̺¬»¼ÕßµÄÓ×ÎÒÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÀýÈçÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢Éç»á°²È«ºÅÂë¡¢¼ÝÊ»ÅÆÕÕºÅÂë¡¢±£ÏÕ¡¢Ò½ÁƱ£ÏÕ/Ò½ÁƲ¹ÖúÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£¡£µ÷²éÁ˾ÖÅú×¢¶ÔDMSÍøÂçµÄ³õʼδÊÚȨ½Ó¼û²úÉúÔÚ2017Äê4ÔÂ1ÈÕ£¬£¬£¬£¬£¬£¬£¬Í¨¹ýDMS¹¤×÷Õ¾ÉϵÄRDPºÍ̸½øÐÐÈëÇÖ¡£¡£¡£¡£¡£¡£¡£DMSÒÑ´Ó±¸·ÝÖи´Ô­ÁËÊý¾Ý£¬£¬£¬£¬£¬£¬£¬ÎÞÐèÖ§¸¶Êê½ð¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/doctors-management-service-hit-with-gandcrab-ransomware-attack-compromising-patient-data-b6eebd02

3.Å·ÖÞÔì×÷ÉÌAebi SchmidtÔâδ֪ÀÕË÷Èí¼þ¹¥»÷

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

ÈðÊ¿ÊÐÕþºÍũҵ»úеÔì×÷ÉÌAebi Schmidt³ÉΪÀÕË÷Èí¼þ¹¥»÷µÄ×îÐÂÊܺ¦Õß¡£¡£¡£¡£¡£¡£¡£¾ÝTechCrunch±¨Â·£¬£¬£¬£¬£¬£¬£¬ÀÕË÷Èí¼þ¹¥»÷ÑϳÁÓ°ÏìÁËAebi SchmidtµÄÅ·ÖÞ»ùµØ£¬£¬£¬£¬£¬£¬£¬µ¼ÖºܶàϵͳÎÞ·¨ÔËÐУ¬£¬£¬£¬£¬£¬£¬Ô̺¬ÓйØÔì×÷ÒµÎñϵͳ¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾µÄµç×ÓÓʼþ·þÎñÒ²Êܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬²¿ÃÅÔ±¹¤±»ÆÈÆðÍ·ÐÝÎÞн¼Ù¡£¡£¡£¡£¡£¡£¡£Aebi Schmidt³Æ¹¥»÷µÄÔ­ÒòÈÔδȷ¶¨¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/unknown-ransomware-cripples-computer-systems-of-aebi-schmidt-ffa880fb

4.жñÒâÍÚ¿óÈí¼þBeapy£¬£¬£¬£¬£¬£¬£¬ÒÑϰȾ³¬¹ý1.2Íò¸öÓû§

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÈüÃÅÌú¿Ë×êÑÐÈËÔ±·¢ÏÖжñÒâÍÚ¿óÈí¼þBeapyµÄ¹¥»÷»î¶¯ÔÚ½üÆÚì­Éý¡£¡£¡£¡£¡£¡£¡£Beapy³õ´Î³öÏÖÓÚ1Ô·ݣ¬£¬£¬£¬£¬£¬£¬×ÔÈýÔ·ÝÒÔÀ´ÒѾ­ÔÚ732¸öÆóÒµÖÐÒý·¢Á˳¬¹ý1.2ÍòÆðϰȾÊÂÎñ¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þͨ¹ý´¹µöÓʼþ´«²¼£¬£¬£¬£¬£¬£¬£¬Ò»µ©Êܺ¦Õß´ò¿ª¶ñÒ⸽¼þ£¬£¬£¬£¬£¬£¬£¬¶ñÒ⸽¼þ¾Í»á¿ªÊÍNSAºÚ¿Í¹¤¾ßDoublePulsar£¬£¬£¬£¬£¬£¬£¬ÔÚÊÜϰȾµÄÍÆËã»úÉÏ´´½¨ºóÃŲ¢Ê¹ÓÃNSAµÄEternalBlue·ì϶ÀûÓúáÏò´«²¼¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±³Æ³¬¹ý80£¥µÄBeapyϰȾ¶¼²úÉúÔÚÖйú¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://techcrunch.com/2019/04/25/cryptojacking-nsa-malware/

5.¹¥»÷ÕßÀÄÓÃGitHub·þÎñÍйÜÍøÂç´¹µö¹¤¾ß°ü


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Proofpoint×êÑÐÍŶӷ¢ÏÖ¶ñÒâ¹¥»÷ÕßÀÄÓÃGitHubµÄÍøÒ³¼Ä·Å·þÎñÀ´ÍйÜÍøÂç´¹µö¹¤¾ß°ü¡£¡£¡£¡£¡£¡£¡£ÕâÖÖ²½ÖèʹµÃ¹¥»÷ÕßÄܹ»ÀûÓÃgithub.ioÓòÃûÈÆ¹ý°×Ãûµ¥µÈ·ÀÓù´ëÊ©¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖÕâЩ´¹µö¹¤¾ß°ü´óÎÞÊýÓÃÓÚÍøÂçÊܺ¦ÕßµÄÍ´´¦£¨ÀýÈçÒøÐÐÕË»§Í´´¦£©µÈÃô¸ÐÐÅÏ¢²¢·¢ËÍÖÁ¹¥»÷ÕߵķþÎñÆ÷¡£¡£¡£¡£¡£¡£¡£GitHubÒÑÔÚ4ÔÂ19ÈÕ²ÉÈ¡´ëÊ©½ûÓÃÁËÕâЩ¶ñÒâÕË»§¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/github-service-abused-by-attackers-to-host-phishing-kits/

6.TA505ÀûÓÃLOLBinsºÍServHelper¶Ô×¼½ðÈÚ¹«Ë¾


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Cybereason×êÑÐÈËÔ±·¢ÏÖ·¸×ïÍÅ»ïTA505µÄй¥»÷»î¶¯ÀûÓöàÖÖºýŪ¼¼Êõ¶Ô×¼½ðÈÚ»ú¹¹¡£¡£¡£¡£¡£¡£¡£¸ÃÍÅ»ïѡȡÁ˶àÖÖÕ½ÊõÀ´Ìӱܼì²â£¬£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶Ô½ðÈÚÆóÒµµÄÌØ¶¨ÕË»§½øÐд¹µö¹¥»÷¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÁ˶à¸öC2ÓòÃûÒÔÈÆ¹ýºÚÃûµ¥¼ì²â£¬£¬£¬£¬£¬£¬£¬²¢ÔÚÖ¸±êϵͳÉÏ¿ªÊÍServHelperºóÃÅ¡£¡£¡£¡£¡£¡£¡£¸ÃServHelper±äÌåÒÀÀµÓÚËĸöLOLBinsºÍ±¾µØÏµÍ³¹ý³ÌÖ´ÐжñÒâ»î¶¯£¬£¬£¬£¬£¬£¬£¬´Ë±í£¬£¬£¬£¬£¬£¬£¬ServHelper»¹Ê¹ÓÃÁËSectigo RSA Code Signing CAÊðÃûµÄÓÐЧ֤ÊéÀ´Ìӱܼì²â¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/ta505-group-uses-lolbins-and-servhelper-backdoor-to-compromise-financial-firms-00550f4d