IE RCE 0day¼°Defender DoS·ì϶£»£»£»£»£»£»2019ÄêÍøÂç¹¥»÷±¨´ð³É·Ö»ã±¨£»£»£»£»£»£»D-Link DNS-320 RCE·ì϶

°ä²¼¹¦·ò 2019-09-24
1.΢Èí´¹Î£½¨¸´IEÖеÄRCE 0day¼°DefenderÖеÄDoS·ì϶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

΢Èí°ä²¼´¹Î£°²È«¸üУ¬ £¬ £¬ £¬ £¬£¬£¬£¬½¨¸´IEÖеÄRCE 0day¼°Windows DefenderÖеÄDoS·ì϶¡£¡£¡£¡£¡£¡£ ¡£ÆäÖÐIE 0dayΪ¹È¸è×êÑÐÈËÔ±Cl¨¦mentLecigne·¢Ïֵľ籾ÒýÇæÄÚ´æ°Ü»µ·ì϶£¨CVE-2019-1367£©£¬ £¬ £¬ £¬ £¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚµ±Ç°Óû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£ ¡£¸Ã·ì϶Äܹ»Í¨¹ý½«Ö¸±êÓû§³Á¶¨ÏòÖÁ¶ñÒâÍøÕ¾À´ÀûÓ㬠£¬ £¬ £¬ £¬£¬£¬£¬ÊÜÓ°ÏìµÄ°æ±¾Ô̺¬IE9¡¢10ºÍ11¡£¡£¡£¡£¡£¡£ ¡£ÁíÒ»¸ö·ì϶ÊÇWindows DefenderÖеĻؾø·þÎñ·ì϶£¨CVE-2019-1255£©£¬ £¬ £¬ £¬ £¬£¬£¬£¬¸Ã·ì϶ÓëDefender´¦ÖÃÎļþµÄ·½Ê½ÓйØ£¬ £¬ £¬ £¬ £¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶×èÖ¹ºÏ·¨ÕË»§Ö´ÐкϷ¨µÄϵͳÎļþ¡£¡£¡£¡£¡£¡£ ¡£ÊÜÓ°ÏìµÄDefender°æ±¾Îª1.1.16300.1£¬ £¬ £¬ £¬ £¬£¬£¬£¬²¢ÒÑÔÚ1.1.16400.2Öн¨¸´¡£¡£¡£¡£¡£¡£ ¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/microsoft-releases-out-of-band-security-update-to-fix-ie-zero-day-defender-bug/

2.×êÑÐÈËÔ±Åû¶D-Link DNS-320É豸ÖеÄRCE·ì϶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


CyStack Security×êÑÐÈËÔ±·¢ÏÖD-Link DNS-320 ShareCenterÉ豸´æÔÚÒ»¸öºÅÁî×¢Èë·ì϶£¬ £¬ £¬ £¬ £¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶Զ³Ì½ÚÔìÉ豸²¢½Ó¼ûÉ豸ÉÏ´æ´¢µÄÎļþ¡£¡£¡£¡£¡£¡£ ¡£¸Ã·ì϶£¨CVE-2019-16057£©µÄCVSSÆÀ·ÖΪ10·Ö£¬ £¬ £¬ £¬ £¬£¬£¬£¬ËüÓ°ÏìÁ˹̼þ°æ±¾Îª2.05b10¼°¸üµÍµÄDNS-320É豸¡£¡£¡£¡£¡£¡£ ¡£Æ¾¾Ý×êÑÐÈËÔ±µÄ»ã±¨£¬ £¬ £¬ £¬ £¬£¬£¬£¬¸Ã·ì϶ÓëDNS-320ÖÎÀí½çÃæµÄµÇ¼Ä£¿£¿£¿£¿£¿£¿£¿éÓйØ£¬ £¬ £¬ £¬ £¬£¬£¬£¬ÊÜÓ°ÏìµÄÄ£¿£¿£¿£¿£¿£¿£¿é/cgi/login_mgr.cgiÔ̺¬Ò»¸ö¿ÉÄܱ»ÀûÓõIJÎÊýport£¬ £¬ £¬ £¬ £¬£¬£¬£¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚrootȨÏÞÏÂÖ´ÐÐËÁÒâºÅÁ £¬ £¬ £¬ £¬£¬£¬£¬´Ó¶øµ¼ÖÂÉ豸±»ÊÕÊÜ¡£¡£¡£¡£¡£¡£ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://blog.cystack.net/d-link-dns-320-rce/

3.Proofpoint°ä²¼¡¶2019ÄêÍøÂç¹¥»÷Öеı¨´ð³É·Ö¡··ÖÎö»ã±¨

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

ƾ¾ÝProofpointµÄ¡¶2019ÄêÍøÂç¹¥»÷Öеı¨´ð³É·Ö¡··ÖÎö»ã±¨£¬ £¬ £¬ £¬ £¬£¬£¬£¬ÔÚ´Óǰ¼¸ÄêÖй¥»÷Õß½«´¹µö¹¥»÷ÌáÉýµ½ÁËÒ»¸öȫеÄˮƽ£¬ £¬ £¬ £¬ £¬£¬£¬£¬ËûÃÇ»ý¼«ÀûÓÃÏû·ÑÕߵĸÐÇ飬 £¬ £¬ £¬ £¬£¬£¬£¬ÔÚÈËÃDz»ÖªÇéµÄÇé¿öÏÂÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£ ¡£Êг¡ÓªÏúÐÐÒµÊÇ2018ÄêÖÁ2019ÄêµÄÖØÒª¹¥»÷Ö¸±êÖ®Ò»¡£¡£¡£¡£¡£¡£ ¡£ÕâЩ¹«Ë¾Õ¼ÓÐÓë¿Í»§ÓйصĴóÁ¿Ãô¸ÐÐÅÏ¢£¬ £¬ £¬ £¬ £¬£¬£¬£¬Ô̺¬ÐÕÃû¡¢µØµãµØÒÔ¼°¹¤×÷ϰ¹ßµÈ£¬ £¬ £¬ £¬ £¬£¬£¬£¬ÕâʹµÃËüÃdzÉΪ·¸×ï·Ö×ÓÓмÛÖµµÄÖ¸±ê¡£¡£¡£¡£¡£¡£ ¡£³ýÁ˸߹ÜÖ®±í£¬ £¬ £¬ £¬ £¬£¬£¬£¬Éç½»¹¤³Ì¹¥»÷µÄÖ¸±ê»¹Ô̺¬ÆóÒµÖеļ¼ÊõÖ§³ÖÍŶӡ¢HRÒÔ¼°²ÆÕþ¹ÜÕʵȡ£¡£¡£¡£¡£¡£ ¡£¸Ã»ã±¨»¹Ç¿µ÷³Æ£¬ £¬ £¬ £¬ £¬£¬£¬£¬·¸×ï·Ö×ÓҲͨ¹ýÔÚÉ罻ýÌåÉϳÉÁ¢×Ô¼ºµÄÆ·ÅÆ¡¢ÐÎÏóµÅ×ÕÆ­¸ü¶àµÄÊܺ¦Õß¡£¡£¡£¡£¡£¡£ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.proofpoint.com/us/resources/threat-reports/human-factor

4.ÐÂMac¶ñÒâÈí¼þGMERA.A¼Ù×°³ÉÂòÂôÈí¼þÇÔÈ¡Óû§ÐÅÏ¢


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ç÷Ïò¿Æ¼¼×êÑÐÈËÔ±·¢ÏÖÒ»¸ö¼Ù×°³ÉMacƽ̨ºÏ·¨ÂòÂôÈí¼þStockfolioµÄ¶ñÒâÈí¼þ¼Ò×åGMERA£¬ £¬ £¬ £¬ £¬£¬£¬£¬¸Ã¼Ò×åÔ̺¬Á½¸ö±äÌ壬 £¬ £¬ £¬ £¬£¬£¬£¬±ðÀëΪTrojan.MacOS.GMERA.AºÍTrojan.MacOS.GMERA.B£¬ £¬ £¬ £¬ £¬£¬£¬£¬µÚÒ»¸ö±äÌåÊÇÒ»¸öZIP´æµµÎļþ£¬ £¬ £¬ £¬ £¬£¬£¬£¬ÆäÖÐÔ̺¬Ò»¸ö°ó¸¿°üStockfoli.appºÍÒ»¸ö°µ²ØµÄ¼ÓÃÜÎļþ.app¡£¡£¡£¡£¡£¡£ ¡£¸ÃStockfoli.app¾­¹ý¶ñÒâÈí¼þ¿ª·¢ÕßµÄÊý×ÖÖ¤ÊéÊðÃû£¬ £¬ £¬ £¬ £¬£¬£¬£¬Apple°µÊ¾´ËÖ¤ÊéÒÑÓÚ2019Äê7Ô±»³·³ý¡£¡£¡£¡£¡£¡£ ¡£µÚ¶þ¸ö±äÌåζÔÚ¶Ë¿Ú25733-25736ÉÏ´´½¨ÏνÓÖÁC£¦C·þÎñÆ÷µÄ·´Ïòshell£¬ £¬ £¬ £¬ £¬£¬£¬£¬´Ó¶øÊ¹¹¥»÷Õß¿ÉÔÚÖ¸±ê»úеÉÏÖ´ÐÐshellºÅÁî¡£¡£¡£¡£¡£¡£ ¡£

Ô­ÎÄÁ´½Ó£º
https://blog.trendmicro.com/trendlabs-security-intelligence/mac-malware-that-spoofs-trading-app-steals-user-information-uploads-it-to-website/

5.ÃÀTCADÔâÀÕË÷Èí¼þ¹¥»÷£¬ £¬ £¬ £¬ £¬£¬£¬£¬µç»°ºÍµç×ÓÓʼþµÈ·þÎñÖжÏ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÃÀ¹úÌØÀ­Î¬Ë¹ÏØÖÐÑëÆÀ¹ÀÇø£¨TCAD£©ÓÚ9ÔÂ19ÈÕÈ·ÈϳÆÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬ £¬ £¬ £¬ £¬£¬£¬£¬µ¼Ö¶àÏî·þÎñÖжϡ£¡£¡£¡£¡£¡£ ¡£TCADÕÆ¹Ü¶Ô¸ÃÏØµÄ·¿µØ²ú½øÐÐÆÀ¹À£¬ £¬ £¬ £¬ £¬£¬£¬£¬¸Ã»ú¹¹È·ÈϹ¥»÷ÊÂÎñ²úÉúÔÚ9ÔÂ11ÈÕÍíÉÏ9:30£¬ £¬ £¬ £¬ £¬£¬£¬£¬¸Ã¹¥»÷Ó°ÏìÁËÍøÕ¾µÄ·¿²úËÑË÷Ö°ÄÜÒÔ¼°µç×ÓÓʼþ¡¢µç»°ºÍÍÆËã»ú¸¨ÖúÆÀ¹Àϵͳ£¬ £¬ £¬ £¬ £¬£¬£¬£¬µ«¿Í»§·þÎñºÍÆÀ¹ÀÉê±çµÈÈÕ³£²Ù×÷²»ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£ ¡£·þÎñÆ÷ÉϵĺܶàÎļþ±»ÀÕË÷²¡¶¾¼ÓÃÜ£¬ £¬ £¬ £¬ £¬£¬£¬£¬µ¼Ö¸ûú¹¹µÄ²¿ÃÅ·þÎñÖжϡ£¡£¡£¡£¡£¡£ ¡£¸Ã»ú¹¹»Ø¾øÖ§¸¶Êê½ð£¬ £¬ £¬ £¬ £¬£¬£¬£¬²¢ÔÚÓëר¼ÒºÏ×÷ÒÔ´Ó±¸·ÝÊý¾ÝÖи´Ô­ÔËÓª¡£¡£¡£¡£¡£¡£ ¡£

Ô­ÎÄÁ´½Ó£º
https://www.traviscad.org/wp-content/uploads/2019/09/Cyber-Attack-FAQs.pdf

6.PhishLabs·¢ÏÖ¼Ù×°³É·çͶºÍ˽ļµÄд¹µö¹¥»÷

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


PhishLabs×êÑÐÈËÔ±·¢ÏÖ·¸×ï·Ö×ÓÔÚ¼ÙÒâ˽ļ¹«Ë¾Crossplane CapitalºÍEdgemont PartnersµÄÔ±¹¤À´ÓÕÆ­Êܺ¦Õß¡£¡£¡£¡£¡£¡£ ¡£ÎªÁËÓªÔìÕæÊµÐԺͽôÆÈ¸Ð£¬ £¬ £¬ £¬ £¬£¬£¬£¬·¸×ï·Ö×ÓʹÓÃÁËÕæÊµÔ±¹¤¡¢PE»òVCµÄÃû×Ö£¬ £¬ £¬ £¬ £¬£¬£¬£¬²¢ÇÒÔ̺¬Ò»¸öÒÑÊðÃûµÄ±£ÃܺÍ̸£¨NDA£©¡£¡£¡£¡£¡£¡£ ¡£¸ÃNDAλÓÚÒ»¸öͼƬÁ´½Óºó£¬ £¬ £¬ £¬ £¬£¬£¬£¬ÆäURLʹÓÃÁË×î½ü×¢²áµÄ·ÂÕÕÁËÕæÊµË½Ä¼¹«Ë¾µÄαÔìÓòÃû£¬ £¬ £¬ £¬ £¬£¬£¬£¬²¢×îÖÕ½«Êܺ¦Õß³Á¶¨ÏòÖÁhxxps://serversecuredhttp[.]com¡£¡£¡£¡£¡£¡£ ¡£¸ÃÍøÕ¾ÒªÇóÊܺ¦ÕߵǼÆäOffice 365ÕÊ»§ÒÔÏÂÔØÎĵµ£¬ £¬ £¬ £¬ £¬£¬£¬£¬ÕâÒ²ÕýÊÇ·¸×ï·Ö×ӵĴ¹µöÖ¸±ê¡£¡£¡£¡£¡£¡£ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://info.phishlabs.com/blog/spear-phishing-campaign-impersonates-vcs-and-pe-firms