΢Èí°ä²¼Õë¶ÔSMBv3·ì϶µÄKB4551762°²È«¸üУ»£»£»£»£»£»?ºÉÀ¼µ±¾ÖÃÔʧ³¬¹ý690ÍòÆ÷¹Ù¾èÏ×ÕßÊý¾Ý
°ä²¼¹¦·ò 2020-03-131.΢Èí°ä²¼Õë¶ÔSMBv3·ì϶µÄKB4551762°²È«¸üÐÂ
΢Èí½ñÌìÔçЩʱ³½°ä²¼ÁËÕë¶ÔSMBv3 RCE·ì϶£¨CVE-2020-0796£©µÄ²¹¶¡¸üУ¨KB4551762£©£¬£¬£¬£¬£¬Óû§Äܹ»Í¨¹ýWindows Update²é³¸üлò´Ó΢Èí²¹¶¡Ä¿Â¼£¨https://www.catalog.update.microsoft.com/Search.aspx?q=KB4551762£©ÉÏÊÖ¶¯ÏÂÔØÊʺÏ×Ô¼ºWindows°æ±¾µÄKB4551762¡£¡£¡£¡£¡£¡£Î¢Èí°µÊ¾¹ÌȻûÓз¢ÏÖÀûÓô˷ì϶µÄ¹¥»÷£¬£¬£¬£¬£¬µ«½¨ÒéÓû§ÓÅÏÈ×°Öô˸üС£¡£¡£¡£¡£¡£´Ë·ì϶Ҳ±»³ÆÎªSMBGhost»òEternalDarkness£¬£¬£¬£¬£¬½öÓ°ÏìÔËÐÐWindows 10°æ±¾1903ºÍ1909ÒÔ¼°Windows Server Server Core×°Öð汾1903ºÍ1909µÄÉ豸¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-releases-kb4551762-security-update-for-smbv3-vulnerability/
2.Turla APTÐÂË®¿Ó¹¥»÷£¬£¬£¬£¬£¬ÀûÓÃкóÃÅÕë¶ÔÑÇÃÀÄáÑÇ
ESET×êÑÐÈËÔ±·¢ÏÖ¶íÂÞ˹ºÚ¿ÍÍÅ»ïTurla APTµÄÐÂË®¿Ó¹¥»÷£¬£¬£¬£¬£¬¸Ã¹¥»÷ÖÁÉÙ´Ó2019ËêÊׯðÍ·£¬£¬£¬£¬£¬ÖÁÉÙÓÐËĸöÑÇÃÀÄáÑÇÍøÕ¾Êܵ½Ï°È¾£¬£¬£¬£¬£¬Ô̺¬¶íÂÞ˹ÑÇÃÀÄáÑÇ´óʹ¹ÝÁìÊ´¦£¨armconsul[.]ru£©¡¢Artsakh¹²ºÍ¹úÌìÈ»±£»£»£»£»£»£»¤ºÍÌìÈ»×ÊÔ´²¿£¨mnp.nkr[.]am£©¡¢ÑÇÃÀÄáÑǹú¼ÊºÍ°²È«ÊÂÎñ×êÑÐËù£¨aiisa[.]am£©ºÍÑÇÃÀÄáÑÇ´æ¿îµ£±£»£»£»£»£»£»ù½ð£¨adgf[.]am£©¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÀûÓÃÐéαµÄAdobe Flash¸üзַ¢Á½¸öеĶñÒâÈí¼þ£¬£¬£¬£¬£¬Ô̺¬¶ñÒâÈí¼þ¿ªÊÍÆ÷NetFlashºÍľÂíPyFlash¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.welivesecurity.com/2020/03/12/tracking-turla-new-backdoor-armenian-watering-holes/
3.Operation Overtrap¹¥»÷»î¶¯£¬£¬£¬£¬£¬Õë¶ÔÈÕ±¾ÒøÐÐÓû§
Ç÷Ïò¿Æ¼¼·¢ÏÖÕë¶ÔÈÕ±¾ÒøÐÐÓû§µÄй¥»÷»î¶¯¡°Operation Overtrap¡±£¬£¬£¬£¬£¬¸Ã»î¶¯×Ô2019Äê4ÔÂÒÔÀ´Ò»Ïò»îÔ¾£¬£¬£¬£¬£¬²¢ÇÒʹÓÃÈýÖÖ·ÖÆçµÄ¹¥»÷ý½éÀ´ÇÔÈ¡Êܺ¦ÕßµÄÒøÐÐÆ¾Ö¤£ºÍ¨¹ýÀ¬»øÓʼþ·¢ËͼÙ×°³ÉÒøÐÐÍøÕ¾µÄ´¹µöÁ´½Ó£»£»£»£»£»£»Í¨¹ýÀ¬»øÓʼþÒªÇóÊܺ¦Õß´ÓÁ´½ÓµÄÍøÕ¾¸ßµÍÔØ¶ñÒâÈí¼þµÄ¿ÉÖ´ÐÐÎļþ£»£»£»£»£»£»Í¨¹ý¶¨ÔìµÄ·ì϶ÀûÓù¤¾ß°ü£¨BottleEK£©´«²¼¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÖØÒªÊ¹ÓõĶñÒâÈí¼þÊÇÐÂÒøÐÐľÂíCinobi¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.trendmicro.com/trendlabs-security-intelligence/operation-overtrap-targets-japanese-online-banking-users-via-bottle-exploit-kit-and-brand-new-cinobi-banking-trojan/
4.ºÏÇڿƼ¼ÍøÂçÖÎÀíÈí¼þ16¸ö·ì϶£¬£¬£¬£¬£¬³§ÉÌÉÐ佨¸´
×êÑÐÈËÔ±ÔÚºÏÇڿƼ¼£¨Zyxel£©µÄÍøÂçÖÎÀíÈí¼þCloudCNM SecuManagerÖз¢ÏÖ16¸ö°²È«·ì϶£¬£¬£¬£¬£¬ÕâЩ·ì϶Ô̺¬¶à¸öºóÃźÍÓ²±àÂëµÄĬÈÏÍ´´¦¡¢ÃÜÔ¿µÈ¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±³ÆÊÜÓ°ÏìµÄ°æ±¾Ô̺¬CloudCNM SecuManager 3.1.0ºÍ3.1.1£¬£¬£¬£¬£¬¶øËüÃǵÄ×îиüÐÂÈÕÆÚΪ2018Äê11Ô¡£¡£¡£¡£¡£¡£Zyxel Gateway SBUµÄ¸ß¼¶¸±×ܲÃNathan Yen°µÊ¾¸Ã¹«Ë¾´Ë¿ÌÒÑÒâʶµ½ÎÊÌ⣬£¬£¬£¬£¬²¢ÔÚÖÂÁ¦Ñ¸ËÙ½¨¸´·ì϶¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/flaws-zyxels-network-management-software/153554/
5.AvastɱÈíÔÚÆØ³öÑϳÁ·ì϶ºó½ûÓÃJavaScriptɨÃèÒýÇæ
¹È¸è°²È«×êÑÐÈËÔ±Ëþά˹¡¤°ÂÂüµÏ£¨Tavis Ormandy£©·¢ÏÖAvastɱ¶¾Èí¼þ´æÔÚ·ì϶£¬£¬£¬£¬£¬¿ÉÔÊÐíºÚ¿ÍÔÚÓû§ÍÆËã»úÉÏÔ¶³ÌÖ´ÐжñÒâ´úÂë¡£¡£¡£¡£¡£¡£AvastÔÚÒ»ÖÜǰ¾Í½Óµ½Á˸÷ì϶µÄ»ã±¨£¬£¬£¬£¬£¬µ«ÈÔδ½â¾ö¸ÃÎÊÌ⣬£¬£¬£¬£¬¸Ã¹«Ë¾¾ö¶¨ÁÙʱ½ûÓÃɱÈíÖеÄJavaScriptɨÃèÒýÇæ¡£¡£¡£¡£¡£¡£Ormandy°µÊ¾¸Ã·ì϶ºÜÈÝÒ×±»ÀûÓ㬣¬£¬£¬£¬¹¥»÷ÕßÖ»Ðèͨ¹ýµç×ÓÓʼþ·¢ËͶñÒâJavaScript»òWSHÎļþ£¬£¬£¬£¬£¬»òÓÕʹÓû§´ò¿ªÔ̺¬¶ñÒâJavaScriptµÄÎļþ£¬£¬£¬£¬£¬¼´Äܹ»ÏµÍ³¼¶½Ó¼ûȨÏÞÖ´ÐжñÒâ²Ù×÷£¬£¬£¬£¬£¬ÀýÈç×°ÖöñÒâÈí¼þ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/avast-disables-javascript-engine-in-its-antivirus-following-major-bug/
6.ºÉÀ¼µ±¾ÖÃÔʧ³¬¹ý690ÍòÆ÷¹Ù¾èÏ×ÕßÊý¾Ý£¬£¬£¬£¬£¬Õ¼×ÜÈ˶¡½üÒ»°ë
ºÉÀ¼µ±¾Ö°µÊ¾ÃÔʧÁËÁ½¸ö´æÓÐ690ÍòÆ÷¹Ù¾èÔùÕßÊý¾ÝµÄÓ²ÅÌ£¬£¬£¬£¬£¬ÕâЩÊý¾ÝÊÇ1998Äê2ÔÂÖÁ2010Äê6ÔÂÆÚ¼äÏòºÉÀ¼¾èÔùÕߵǼǴ¦Ìá½»µÄËùÓоèÔùÕß±í¸ñµÄ±¸·Ý¡£¡£¡£¡£¡£¡£ÕâЩӲÅ̵Ä×îºóʹÓù¦·òÊÇ2016Ä꣬£¬£¬£¬£¬ËæºóËüÃDZ»¸éÖÃÔÚÒ»¸ö°²È«µÄ±£Ë¾¿âÖÓ×£¡£¡£¡£¡£¡£µ«ÔÚ½ñÄêÔçЩʱ³½µ±¾Ö·¢ÏÖÓ²ÅÌÃÔʧ£¬£¬£¬£¬£¬²¢ÇÒ´Ë¿ÌÒÀÈ»ÎÞ·¨ÕÒµ½¡£¡£¡£¡£¡£¡£Ó²ÅÌÖд洢µÄÐÅÏ¢Ô̺¬×¢²á¾èÔùÕßµÄÐÕÃû¡¢ÐԱ𡢵®ÉúÈÕÆÚ¡¢µØÖ·¡¢Æ÷¹Ù¾èÔùµÄÑ¡Ôñ¡¢IDÒÔ¼°ÊðÃû¡£¡£¡£¡£¡£¡£ºÉÀ¼µÄ×ÜÈ˶¡Îª1740Íò×óÓÒ£¬£¬£¬£¬£¬ÆäÖнüÒ»°ë±»ÒÔΪÊÇ×¢²á¾èÔùÕß¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/dutch-government-loses-hard-drives-with-data-of-6-9-million-registered-donors/


¾©¹«Íø°²±¸11010802024551ºÅ