GALLIUM¹¥»÷È«ÇòµÄµçÐŹ«Ë¾£»£»£»£»£»£»£»ZeppelinÖØÒªÕë¶ÔITºÍÒ½ÁƱ£½¡¹«Ë¾

°ä²¼¹¦·ò 2019-12-13


1.΢ÈíÖҸ淸×ïÍÅ»ïGALLIUM¹¥»÷È«ÇòµÄµçÐŹ«Ë¾


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


΢ÈíÍþвµý±¨ÖÐÐÄ£¨MSTIC£©ÖҸ淸×ïÍÅ»ïGALLIUMÔÚÕë¶ÔÊÀ½ç¸÷µØµÄµçÕÛ·þÎñÉ̽øÐгÖÐø²»ÐݵĹ¥»÷¡£¡£¡£ ¡£¡£¡£¡£¸Ã·¸×ïÍÅ»ï½øÐÐÁ˶à¸ö¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬MSTIC¹Û²ìµ½Õë¶Ô¶«ÄÏÑÇ¡¢Å·Ö޺ͷÇÖ޵ĵçÐÅÔËÓªÉ̵Ĺ¥»÷¡£¡£¡£ ¡£¡£¡£¡£GALLIUMÖØÒªÍ¨¹ýδ´ò²¹¶¡µÄWildFly/JBoss·þÎñÆ÷½øÐÐÈëÇÖ£¬£¬£¬£¬£¬£¬Ò»µ©ÉøÈëµ½×éÖ¯µÄÍøÂçÖУ¬£¬£¬£¬£¬£¬GALLIUM±ãÆðÍ·ÀûÓÃ×Ô½ç˵µÄ¶ñÒâÈí¼þÔÚÆóÒµÍøÂçÖкáÏòÒÆ¶¯ºÍÍøÂçÓòÍ´´¦¡£¡£¡£ ¡£¡£¡£¡£GALLIUM»¹Ê¹ÓÃSoftEther VPNÈí¼þÀ´¼ÓÇ¿¶ÔÖ¸±êÍøÂçµÄ½Ó¼ûºÍά³ÖÓÆ¾ÃÐÔ¡£¡£¡£ ¡£¡£¡£¡£Æ¾¾ÝMSTICµÄ»ã±¨£¬£¬£¬£¬£¬£¬GALLIUMµÄTTPºÍ¸Ã×é֯ʹÓõIJ¿ÃÅÓòÓë2018ÄêµÄOperation SoftCellÒ»Ñù¡£¡£¡£ ¡£¡£¡£¡£


  Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-warns-of-gallium-threat-group-attacking-global-telcos/


2.¶ñÒâÈí¼þKrampus-3PCÖØÒª¶Ô×¼iphoneÓû§


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ò»¸öÕë¶ÔiPhoneÓû§µÄ¶ñÒâ¸æ°×³Á¶¨Ïò»î¶¯ÒѾ­Ó°ÏìÁË100¶à¸ö³ö°æÉÌÍøÕ¾£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬ÔÚÏß±¨Ö½ÍøÕ¾ºÍ¹ú¼ÊÿÖÜÐÂÎÅÔÓÖ¾ÍøÕ¾µÈ¡£¡£¡£ ¡£¡£¡£¡£Æ¾¾ÝDSOÍŶӵÄ˵·¨£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þKrampus-3PC¼Ù×°³ÉÔÓ»õµêµÄ³ê±ö¸æ°×£¬£¬£¬£¬£¬£¬´ÓÓû§ÄÇÀïÊÕÍÅÔ²»°ºÍcookieÐÅÏ¢£¬£¬£¬£¬£¬£¬²¢ÇÒÔÚÓû§µã»÷¸æ°×ʱ³Á¶¨ÏòÖÁÒ»¸öÍøÂçÓ×ÎÒÐÅÏ¢µÄÐéÎ±ÍøÕ¾¡£¡£¡£ ¡£¡£¡£¡£¹¥»÷ÕßÊ×ÏÈÔÚ¸æ°×ƽ̨AdtechstackÉÏͶ·Å¸æ°×£¬£¬£¬£¬£¬£¬¶øºóÀûÓÃÆ½Ì¨µÄAPI²åÈë¶ñÒâ´úÂ룬£¬£¬£¬£¬£¬ÕâЩ¶ñÒâ¸æ°×Ëæºó±»·Ö·¢¸ø´óÁ¿ÍøÕ¾¡£¡£¡£ ¡£¡£¡£¡£Krampus-3PC»á½«ÍøÂçµ½µÄÓû§ÐÅÏ¢·¢ËÍÖÁC2ÓòÃûboostsea2[.]com¡£¡£¡£ ¡£¡£¡£¡£Ä¿Ç°Éв»Ã÷ÏÔ¹¥»÷ÕßµÄÉí·Ý¡£¡£¡£ ¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://threatpost.com/krampus-3pc-malware-iphone-users/151043/


3.ÀÕË÷Èí¼þZeppelinÖØÒªÕë¶ÔITºÍÒ½ÁƱ£½¡¹«Ë¾


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÔÚBlackBerry CylanceµÄ×îл㱨ÖУ¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖÀÕË÷Èí¼þZeppelin±»ÓÃÓÚÕë¶ÔITºÍÒ½ÁƱ£½¡¹«Ë¾µÄÕë¶ÔÐÔ¹¥»÷¡£¡£¡£ ¡£¡£¡£¡£ÔÚÆäÖÐһЩ¹¥»÷»î¶¯ÖУ¬£¬£¬£¬£¬£¬BlackBerry CylanceÒÔΪ¹¥»÷Õß¶Ô×¼MSP£¨ÖÎÀí·þÎñÌṩÉÌ£©µÄÖ÷ÕÅÊÇͨ¹ýÖÎÀíÈí¼þ½øÒ»²½Ï°È¾Æä¿Í»§¡£¡£¡£ ¡£¡£¡£¡£Ä¿Ç°Éв»Ã÷ÏÔZeppelinµÄ·Ö·¢·½Ê½£¬£¬£¬£¬£¬£¬µ«ËüºÜ¿ÉÄÜÊÇͨ¹ý¶³öÔÚ»¥ÁªÍøÉϵÄRDP·þÎñ´«²¼¡£¡£¡£ ¡£¡£¡£¡£ÔÚ¼ÓÃÜÎļþʱ£¬£¬£¬£¬£¬£¬Zeppelin²»»áÔö³¤¶î±íµÄÀ©´óÃû£¬£¬£¬£¬£¬£¬²¢ÇÒÎļþÃûά³Ö²»±ä£¬£¬£¬£¬£¬£¬µ«¼ÓÃܵÄÎļþºó½«»áÔ̺¬Ò»¸öZeppelinÎļþÏóÕ÷¡£¡£¡£ ¡£¡£¡£¡£Ä¿Ç°ÉÐÎÞ·¨Ãâ·Ñ½âÃܸÃÀÕË÷Èí¼þ¼ÓÃܵÄÎļþ¡£¡£¡£ ¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/zeppelin-ransomware-targets-healthcare-and-it-companies/


4.ÄÏ¿¨ÂÞÀ´ÄÉÖݰ¸¼þÖÎÀí»ú¹¹Ð¹Â¶Ô¼2.6ÍòÌõ¿ÛÁô¼Í¼


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


°²È«³§ÉÌUpGuardÔÚSpartan Technology¹«Ë¾µÄÊ¢¿ªÔƴ洢ͰÖз¢ÏÖÔ¼2.6ÍòÈ˵ĿÛÁô¼Í¼¡£¡£¡£ ¡£¡£¡£¡£Spartan TechnologyÔ®ÊÖÄÏ¿¨ÂÞÀ³ÄÉÖݵĴ¦Ëù·¨Ôº´æ´¢°¸¼þÖÎÀíÊý¾Ý£¬£¬£¬£¬£¬£¬Æ¾¾Ý×êÑÐÈËÔ±µÄ±íÊö£¬£¬£¬£¬£¬£¬¿ÛÁô¼Í¼ÖÐÔ̺¬±»¿Ø·¸×ïÕßµÄÐÕÃû¡¢Ìá³öÖ¸¿ØµÄÊܺ¦ÕßÒÔ¼°Ä³Ð©°¸ÀýÖеÄÖ¤ÈËÐÕÃûµÈ£¬£¬£¬£¬£¬£¬ÆäÖв¿ÃÅÉæ°¸ÈËԱΪÇàÉÙÄê¡£¡£¡£ ¡£¡£¡£¡£Êý¾Ý¿âµÄ´óÁ¿Ìõ¿î»¹Ô̺¬µ®ÉúÈÕÆÚ¡¢µç»°ºÅÂëºÍ¼ÝÕÕID£¬£¬£¬£¬£¬£¬ÒÔ¼°Ô¼1.7Íò¸öÉç»á°²È«ºÅÂë¡£¡£¡£ ¡£¡£¡£¡£Spartan TechnologyÔÚÈ·ÈÏÊÂÎñºó°µÊ¾Ð¹Â¶µÄÊý¾Ý¾ùΪ²âÊÔÊý¾Ý¡£¡£¡£ ¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://gizmodo.com/arrest-data-exposed-by-south-carolina-firm-included-per-1840365182


5.·ðÂÞÀï´ïÖÝPRIDE¹«Ë¾ÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬ÏµÍ³ÈÔδ¸´Ô­


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


12ÔÂ7ÈÕ¸¥ÂÞÀï´ïÖÝPRIDE¹«Ë¾Ôâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬ÆäÍøÕ¾ºÍϵͳÈÔ´¦ÓڹعØ×´Ì¬¡£¡£¡£ ¡£¡£¡£¡£PRIDEÊÇÒ»¸ö·ÇͶ»ú×éÖ¯£¬£¬£¬£¬£¬£¬ÖÂÁ¦ÓÚÔ®ÊÖÇô·¸½ø½¨Ö°Òµ¼¼ÊõºÍ³öÓüºó¸üºÃµØÈÚÈëÉç»á¡£¡£¡£ ¡£¡£¡£¡£ÔÚÊܵ½¹¥»÷ºó£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾µÄÍøÕ¾¡¢¹¤×Êϵͳ¡¢µç×ÓÓʼþ¡¢¿Í»§ºÍ¹©¸øÉÌÁбíµÈ¶à¸öϵͳ¾ùÎÞ·¨½Ó¼û¡£¡£¡£ ¡£¡£¡£¡£PRIDEÊ×ϯÐÐÕþ¹ÙDee KiminkiÈ·ÈÏÁËÕâÒ»ÊÂÎñ£¬£¬£¬£¬£¬£¬²¢°µÊ¾ÔÚÓëFBIºÏ×÷½øÐе÷²é¡£¡£¡£ ¡£¡£¡£¡£Ä¿Ç°PRIDEÉÐδÌṩÓйØÕâ´Î¹¥»÷ÊÂÎñµÄ¸ü¶à¾ßÌåÐÅÏ¢¡£¡£¡£ ¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ransomware-hits-florida-pride-on-saturday-systems-still-down/


6.Apple½¨¸´macOS CatalinaÖеÄ50¶à¸ö·ì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Apple±¾Öܰ䲼ÁËmacOS Catalina¡¢iOSºÍiPadOS¡¢SafariµÈ²úÆ·µÄ°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´¶à¸ö·ì϶¡£¡£¡£ ¡£¡£¡£¡£ÆäÖÐmacOS CatalinaÊÕµ½ÁË×î¶àµÄ·ì϶²¹¶¡£¬£¬£¬£¬£¬£¬Îª52¸ö£¬£¬£¬£¬£¬£¬ÊÜÓ°Ïì×î´óµÄ×é¼þÊÇtcpdump£¨32¸ö·ì϶£©£¬£¬£¬£¬£¬£¬Óû§¿Éͨ¹ý¸üÐÂÖÁtcpdump°æ±¾4.9.3ºÍlibpcap°æ±¾1.9.1×°ÖÃÕâЩ²¹¶¡¡£¡£¡£ ¡£¡£¡£¡£·ì϶µÄÁìÓòÔ̺¬ÒÔϵͳ»òÄÚºËȨÏÞÖ´ÐÐËÁÒâ´úÂë¡¢»Ø¾ø·þÎñ¡¢Óû§ÐÅϢй¶¡¢ÌØÈ¨ÌáÉýÒÔ¼°¶ÁÈ¡ÊÜÏÞÄÚ´æµÈ¡£¡£¡£ ¡£¡£¡£¡£Ö»¹Ü´óÎÞÊý·ì϶½öÓ°ÏìmacOS Catalina 10.15£¬£¬£¬£¬£¬£¬µ«Ò²ÓÐһЩ·ì϶ӰÏìÁËmacOS High Sierra 10.13.6ºÍmacOS Mojave 10.14.6¡£¡£¡£ ¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/apple-patches-over-50-vulnerabilities-macos-catalina