ÃÀ¹úÌìÈ»Æø¹Ü·ÔËÓªÉÌÔâµ½ÀÕË÷Èí¼þ¹¥»÷£»£»£»£»£»£»£»SharePointÔ¶³Ì´úÂëÖ´Ðзì϶(CVE-2019-0604)
°ä²¼¹¦·ò 2020-02-191.ÃÀ¹úÌìÈ»Æø¹Ü·ÔËÓªÉÌÔâµ½ÀÕË÷Èí¼þ¹¥»÷
ƾ¾ÝÃÀ¹úºÓɽ°²È«ÊýÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨DHS CISA£©°ä²¼µÄ´«µÝ£¬£¬£¬£¬£¬£¬£¬Ò»¼Òδ¾ßÃûµÄÃÀ¹úÌìÈ»ÆøÑ¹Ëõ¹¤³§ÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÔËÓªÖжÏÁËÁ½ÌìµÄ¹¦·ò¡£¡£¡£¡£¡£¡£¡£¡£CISA°µÊ¾¹¥»÷ÕßÊ×ÏÈÀûÓô¹µöÁ´½Ó»ñµÃÁ˶ԸÃ×éÖ¯ITÍøÂçµÄ½Ó¼û£¬£¬£¬£¬£¬£¬£¬¶øºóתÏòÆäOTÍøÂç²¢²¿ÊðÁËÉÌÓÃÀÕË÷Èí¼þ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÈí¼þͬʱÔÚITºÍOTÍøÂçÉ϶Թ«Ë¾µÄÊý¾Ý½øÐмÓÃÜ£¬£¬£¬£¬£¬£¬£¬ÒÔ×î´óˮƽµØ·ÛËéÆóÒµ£¬£¬£¬£¬£¬£¬£¬¶øºó²ÅÒªÇóÖ§¸¶Êê½ð¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÀÕË÷Èí¼þ²¢Î´Ó°ÏìÈκÎPLC£¬£¬£¬£¬£¬£¬£¬µ«ÈËÀà²Ù×÷Ô±ÎÞ·¨»ã×ܺͶÁÈ¡Óйع¤Òµ¹ý³ÌÖеÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬ÀýÈçHMI¡¢Êý¾Ýº¹Çà¼Í¼ºÍÂÖѯ·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÔ±¹¤ÎÞ·¨°ÑÎչܷÉèÊ©µÄÔËÐÐÇé¿ö¡£¡£¡£¡£¡£¡£¡£¡£¹Ü·ÔËÓªÉÌÖ´ÐÐÁË¡°ÓдòËãµÄ¡¢ÊܿصĹعء±´ëÊ©£¬£¬£¬£¬£¬£¬£¬ÒÔÔ¤·À²¢Ô¤·ÀÈκÎÊÂÎñµÄ²úÉú¡£¡£¡£¡£¡£¡£¡£¡£CISA°µÊ¾ÔËÓªÖжϳÖÐøÁËÔ¼Á½Ì죬£¬£¬£¬£¬£¬£¬¶øºó¸´ÔÁËÕý³£ÔË×÷¡£¡£¡£¡£¡£¡£¡£¡£CISAûÓÐй©ÀÕË÷Èí¼þµÄÃû³Æ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/dhs-says-ransomware-hit-us-gas-pipeline-operator/
2.SharePointÔ¶³Ì´úÂëÖ´Ðзì϶(CVE-2019-0604)
°²È«×êÑÐÔ±Dhiraj Mishra·¢ÏÖSharePoint´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2019-0604£©£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý·¢ËͶñÒâSharePointÊý¾Ý°üÀ´ÀûÓø÷ì϶¡£¡£¡£¡£¡£¡£¡£¡£Ó¡¶È˰Îñ¾Ö¹ÙÍø£¨incometaxindia.gov.in£©¼°ÂéÊ¡Àí¹¤µÄ˹¡ÖÎÀíÑ§ÔºÍøÕ¾¶¼Êܵ½¸Ã·ì϶µÄÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±±ðÀëÔÚ2ÔÂ12ÈÕºÍ13ÈÕ֪ͨÁËCERT-InºÍMIT°²È«ÍŶӣ¬£¬£¬£¬£¬£¬£¬ÕâÁ½¸öÍøÕ¾¶¼ÒѾ²Ä¬½¨¸´Á˸÷ì϶¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/98043/hacking/sharepoint-rce.html
3.·¸×ïÍÅ»ïAPT-C-23ÓÕÆÒÔÉ«Áйú·ÀÊ¿±ø×°ÖöñÒâÈí¼þ
ÒÔÉ«Áйú·À¾ü£¨IDF£©°µÊ¾¹þÂí˹¼¤½ø×éÖ¯ÀûÓÃÃÀÅ®µÄÕÕÆ¬ÓÕÆÒÔÉ«Áйú·ÀÊ¿±ø×°ÖöñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬¸Ã¹¥»÷Õß±»¼ø±ðΪAPT-C-23¡£¡£¡£¡£¡£¡£¡£¡£IDF½²»°ÈËHedy Silberman³Æ¹¥»÷Õß´´½¨ÁËÁù¸öÅ®ÐÔ½ÇÉ«£¬£¬£¬£¬£¬£¬£¬Í¨¹ý¶àÖÖÐÂÎÅ´«µÝƽ̨£¨Facebook¡¢WhatsApp¡¢Telegram¡¢Instagram£©ÓëÊ¿±øÌ¸Ì죬£¬£¬£¬£¬£¬£¬¶øºóÓÕʹËûÃÇ´ÓÒ»¸öÁ´½ÓÖÐÏÂÔØ¾Ý³ÆÀàËÆÓÚSnapchatµÄAPP¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩAPPÖ»ÊÇÊÖ»úÔ¶¿ØÄ¾Âí£¨MRAT£©µÄ¼Ù×°£¬£¬£¬£¬£¬£¬£¬¶ñÒâÈí¼þ½«Í¨¹ýMQTTºÍ̸ÓëC2·þÎñÆ÷½øÐÐͨѶ£¬£¬£¬£¬£¬£¬£¬²¢Äܹ»ÍøÂçÉ豸µÄÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬Ô̺¬µç»°ºÅÂë¡¢GPSÐÅÏ¢¡¢´æ´¢Êý¾ÝºÍSMSÐÂÎÅ¡£¡£¡£¡£¡£¡£¡£¡£IDFÖ¸³ö¸Ã¶ñÒâÈí¼þ»¹Äܹ»ÅÄÕÕ¡¢ÇÔÈ¡ÁªÏµÈËÁбíÒÔ¼°ÏÂÔØºÍÖ´ÐÐÎļþ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hacker-group-catfishes-israeli-soldiers-into-installing-mobile-rat/
4.°®ºÉ»ªÖÝÒ½ÁƱ£½¡¹«Ë¾MCHCй¶Լ7500Ãû»¼ÕßÐÅÏ¢
°®ºÉ»ªÖÝÒ½ÁƱ£½¡¹«Ë¾£¨MCHC£©ÔÚÖÜÒ»°ä²¼µÄÐÂÎÅÖгƣ¬£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯ÓÚ2019Äê12ÔÂ19ÈÕ·¢ÏÔìäµç×ÓÓʼþϵͳÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬Ô¼ÓÐ7500Ãû»¼ÕßµÄÒ½ÁÆÐÅÏ¢¿ÉÄÜй¶¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÔÚ2019Äê10ÔÂ28ÈÕÖÁ2020Äê1ÔÂ20ÈÕÖ®¼ä½Ó¼ûÁ˶à¸öÔ±¹¤µÄµç×ÓÓʼþÕË»§£¬£¬£¬£¬£¬£¬£¬¿ÉÄÜÇÔÈ¡µÄ»¼ÕßÐÅÏ¢Ô̺¬ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢µØÖ·¡¢±£ÏÕÐÅÏ¢ºÍÁÙ´²ÐÅÏ¢£¨ÀýÈç¾ÍÕïÔÒò£©¡£¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯°µÊ¾²¿ÃÅ»¼ÕßµÄÉç»á°²È«ºÅÂë¿ÉÄÜÒ²ÔâÇÔÈ¡¡£¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯°µÊ¾ËùÓÐMCHCÔ±¹¤¶¼±ØÐë³ÁÉèÆäµç×ÓÓʼþÕÊ»§ÃÜÂë²¢½ÓÊÜеÄÍøÂ簲ȫÅàѵ¡£¡£¡£¡£¡£¡£¡£¡£ÐÂΟ廹³ÆÊÜÓ°ÏìµÄ»¼ÕßÄܹ»Í¨¹ýMCHC»ñµÃÒ»ÄêµÄÐÅÓþ¼à¿Ø·þÎñ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.desmoinesregister.com/story/news/2020/02/17/monroe-iowa-county-hospital-patients-data-breach-victims/4790481002/
5.AZORultľÂíбäÖÖ¼Ù×°³ÉProtonVPN×°Ö÷¨Ê½´«²¼
°²È«×êÑÐÈËÔ±¹Û²ìµ½AZORultľÂíµÄбäÖÖ¼Ù×°³ÉProtonVPN×°Ö÷¨Ê½½øÐзַ¢¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷»î¶¯×Ô2019Äê11ÔÂÆðÍ·£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ýÏò¶íÂÞ˹ע²áÉÌ×¢²áÓòÃû¡°protonvpn[.]store¡±À´ÌáÒé´Ë¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓöñÒâ¸æ°××÷ΪÆä³õʼϰȾý½é£¬£¬£¬£¬£¬£¬£¬AZORult½«ÍøÂçÊܺ¦ÕßµÄϵͳ»·¾³Êý¾Ý£¬£¬£¬£¬£¬£¬£¬²¢½«Æä·¢Ë͵½Î»ÓÚaccounts[.]protonvpn[.]storeµÄC2·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£¡£¸ÃľÂí»¹Äܹ»´Ó±¾µØÇ®°üÇÔÈ¡¼ÓÃÜÇ®±Ò£¨Electrum¡¢Bitcoin¡¢EtheriumµÈ£©£¬£¬£¬£¬£¬£¬£¬´ÓFileZillaÇÔÈ¡FTPµÇ¼ÃûºÍÃÜÂëÒÔ¼°ÇÔÈ¡µç×ÓÓʼþÍ´´¦ºÍä¯ÀÀÆ÷cookieµÈÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.tripwire.com/state-of-security/featured/azorult-trojan-disguised-itself-as-fake-protonvpn-installer/
6.×êÑÐÍŶӰ䲼Gamaredon APT¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨
Yoroy-Cybaze ZLabµÄ°²È«×¨¼Ò¶ÔGamaredon APTʹÓõĶñÒâÈí¼þ½øÐÐÁ˾ßÌåµÄ·ÖÎö¡£¡£¡£¡£¡£¡£¡£¡£Gamaredon×Ô2014ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬£¬£¬£¬£¬£¬£¬ÆäÖØÒªÓë¶íÂÞ˹ºÍÎÚ¿ËÀ¼µÄµØÔµÕþÖÎÓйء£¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯×ʹÓõĶñÒâÈí¼þÖ²È뷨ʽΪPteranodon»òPterodo£¬£¬£¬£¬£¬£¬£¬ËüÓɶ༶ºóÃÅ×é³É£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚÍøÂçÃô¸ÐÐÅÏ¢»òά³ÖÊÜϰȾ»úеµÄ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£PterodoÖØÒªÍ¨¹ýÕë¶Ô¾üÊÂÈËÔ±µÄ´¹µö»î¶¯·Ö·¢£¬£¬£¬£¬£¬£¬£¬×î½üµÄÒ»²¨¹¥»÷º£³±Äܹ»×·ÒäÖÁ2019Äê11Ô¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/97992/apt/gamaredon-espionage-campaign.html


¾©¹«Íø°²±¸11010802024551ºÅ