WHO¡¢CDC¡¢NIH¼°¸Ç´Ä»ù½ð»áÔ¼2.5ÍòÓÊÏäÆ¾Ö¤Ð¹Â¶£»£»£»£»£»°²È«×¨¼Ò·¢ÏÖ28¸ö·À²¡¶¾²úÆ·´æÔÚsymlink race·ì϶

°ä²¼¹¦·ò 2020-04-26

1.WHO¡¢CDC¡¢NIH¼°¸Ç´Ä»ù½ð»áÔ¼2.5ÍòÓÊÏäÆ¾Ö¤Ð¹Â¶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¾Ý»ªÊ¢¶ÙÓʱ¨±¨Â·£¬£¬£¬ £¬£¬£¬ £¬½üÈÕWHO¡¢CDC¡¢NIH¼°¸Ç´Ä»ù½ðԼĪÓÐ2.5ÍòÓÊÏäÆ¾Ö¤Ð¹Â¶£¬£¬£¬ £¬£¬£¬ £¬²¢±»ÓÒÒí¼«¶Ë·Ö×ӺͺڿÍÓÃÀ´´«²¼COVID-19ÓйØÒ¥ÑÔ¡£¡£¡£¡£¡£¡£ ¡£WHOÊÇ¡¶ÓÊÕþ¡·»ã±¨ÖеÚÒ»¸ö¹«¿ªÈÏ¿ÉÆä¹¤×÷ÈËÔ±µÄµç×ÓÓÊÏäÆ¾Ö¤Ð¹Â¶µÄ×éÖ¯£¬£¬£¬ £¬£¬£¬ £¬µ«ÊÇûÓÐ͸©ÕâЩƾ֤ÊÇÈôºÎй¶µÄ¡£¡£¡£¡£¡£¡£ ¡£Lucy SecurityµÄCEO Colin BastableÔòÒÔΪÕâ´ÎÊÂÎñÊÇÀ´×ÔÔçÆÚµÄÊý¾Ýй¶£¬£¬£¬ £¬£¬£¬ £¬ºÚ¿ÍÏëÒªÀûÓÃÕâЩ¾Éƾ֤Õë¶Ôµ±Ç°µÄCOVID-19¡£¡£¡£¡£¡£¡£ ¡£¸Ã»ú¹¹»¹°µÊ¾Ð¹Â©µÄÊý¾Ý²»»á¶Ôµ±Ç°µÄWHOϵͳÔì³ÉÈκηçÏÕ£¬£¬£¬ £¬£¬£¬ £¬ÓÉÓÚÕâЩÊý¾Ý²»ÊÇ×î½üµÄ£¬£¬£¬ £¬£¬£¬ £¬Ö»ÊÇÓ°ÏìÁËÒ»¸öÓÉÊÀÎÀ×éÖ¯ÏÖÈκÍÍËÐÝÈËÔ±ÒÔ¼°ºÏ×÷ͬ°éʹÓþɵıíÁªÍø£¬£¬£¬ £¬£¬£¬ £¬¸Ã×éÖ¯´Ë¿ÌÔÚ½«ÊÜÓ°ÏìµÄϵͳǨáãµ½¸ü°²È«µÄÉí·ÝÑé֤ϵͳ¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.darkreading.com/attacks-breaches/who-confirms-email-credentials-leak/d/d-id/1337650


2.ÃÀ»ùÒò²âÊÔ³¢ÊÔÊÒÔâ´¹µö¹¥»÷£¬£¬£¬ £¬£¬£¬ £¬23.3Íò¹«ÃñÐÅϢй¶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÃÀ¹ú¼ÓÀû¸£ÄáÑÇÖݵĻùÒò²âÊÔ³¢ÊÔÊÒAmbry GeneticsÔâµ½´¹µö¹¥»÷£¬£¬£¬ £¬£¬£¬ £¬23.3Íò¹«ÃñµÄҽѧÐÅϢй¶£¬£¬£¬ £¬£¬£¬ £¬¸ÃÊÂÎñΪÃÀ¹ú2020ÄêµÚ¶þ´óÒ½ÁÆÊý¾Ýй©ÊÂÎñ¡£¡£¡£¡£¡£¡£ ¡£¸Ã»ú¹¹°µÊ¾£¬£¬£¬ £¬£¬£¬ £¬¹¥»÷²úÉúÔÚ1ÔÂ22ÈÕÖÁ24ÈÕÖ®¼ä£¬£¬£¬ £¬£¬£¬ £¬ºÚ¿Íδ¾­ÊÚȨ½Ó¼ûÁËÆäÔ±¹¤µÄµç×ÓÓʼþÕÊ»§¡£¡£¡£¡£¡£¡£ ¡£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬¿Í»§ÐÕÃû¡¢Ò½ÁÆÐÅÏ¢¡¢Óë¿Í»§Ê¹ÓÃAmbry·þÎñÓйصÄÐÅÏ¢¡¢»¹ÓпÉÄÜÔ̺¬Éç»á°²È«ºÅÂ룬£¬£¬ £¬£¬£¬ £¬µ«¸Ã¹«Ë¾Ò»ÏòûÓлØÓ¦ÊÇ·ñ¿ÉÄܶ³öÒÅ´«ÐÅÏ¢¡£¡£¡£¡£¡£¡£ ¡£2020Äê×î´óµÄÊý¾Ýй©ÊÂÎñÊǶíÀÕ¸ÔÖݵĽ¡È«¹²Ïí×éÖ¯£¨Health Share£©ÓÚ2Ô»㱨µÄ£¬£¬£¬ £¬£¬£¬ £¬Æäδ¼ÓÃܵıʼDZ¾µçÄÔ±»ÇÔ£¬£¬£¬ £¬£¬£¬ £¬Ó°ÏìÁ˽ü654400Ó×ÎÒ¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://covid19.inforisktoday.com/genetic-testing-lab-hack-affects-233000-a-14182


3.ÃÀº«40ÍòÕÅÐÅÓþ¿¨ÐÅÏ¢ÔÚ°µÍøÏúÊÛ£¬£¬£¬ £¬£¬£¬ £¬ÊÛ¼ÛÔ¼200ÍòÃÀÔª


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ŀǰ£¬£¬£¬ £¬£¬£¬ £¬×êÑÐÈËÔ±·¢ÏÖ397365ÕÅÐÅÓþ¿¨µÄÐÅÏ¢ÔÚJoker's StashÉÏÒÔ1985835ÃÀÔªÏúÊÛ£¬£¬£¬ £¬£¬£¬ £¬ÆäÖÐ198233ÕÅÊôÓÚº«¹ú£¨Ô¼Õ¼×ÜÊýµÄ49.9£¥£©£¬£¬£¬ £¬£¬£¬ £¬49.3£¥ÊôÓÚÃÀ¹úÒøÐкͽðÈÚ»ú¹¹¡£¡£¡£¡£¡£¡£ ¡£Õâ´ÎÏúÊÛµÄÊý¾ÝÖØÒªÎªTrack 2Êý¾Ý£¬£¬£¬ £¬£¬£¬ £¬Ô̺¬ÒøÐмø±ðÂ루BIN£©¡¢Õʺ𢵽ÆÚÈÕÆÚ¡¢»¹¿ÉÄÜÔ̺¬CVV£¬£¬£¬ £¬£¬£¬ £¬¶øÕâЩÊý¾Ýͨ³£ÊÇ´ÓÓзì϶µÄPOS»ú¡¢ATMºÍÖ§¸¶ÏµÍ³ÖÐй¶µÄ¡£¡£¡£¡£¡£¡£ ¡£µ«ÊÇ£¬£¬£¬ £¬£¬£¬ £¬Ä¿Ç°Ð¹Â¶Êý¾ÝµÄÆðÔ´ÒÀȻδ֪£¬£¬£¬ £¬£¬£¬ £¬Î¨Ò»ÄÜÈ·¶¨µÄ¾ÍÊÇÕâЩÊý¾Ý²»ÊÇ´Ó±»Magecart¹¥»÷µÄµçÉÌÍøÕ¾ÖÐй¶µÄ¡£¡£¡£¡£¡£¡£ ¡£Group-IBµÄShawn Tay°µÊ¾¼´±ãÕâЩÏúÊÛµÄÐÅÏ¢²»¼°ÒÔÓÃÀ´½øÐÐÔÚÏßÖ§¸¶£¬£¬£¬ £¬£¬£¬ £¬µ«ÊDzɰìÕßÄܹ»ÔÚ·¢¿¨»ú¹¹»¹Ã»Óз¢ÏÖʱ£¬£¬£¬ £¬£¬£¬ £¬Ôì×÷¿Ë¡¿¨µ½ATMÈ¡¿î£¬£¬£¬ £¬£¬£¬ £¬´ïµ½µÁË¢µÄÖ÷ÕÅ¡£¡£¡£¡£¡£¡£ ¡£IB¼¯ÍÅÒѽ«´ËÊÂÎñ֪ͨÃÀ¹úºÍº«¹ú½ðÈÚ¹²Ïí×éÖ¯ºÍ¸Ã¹úCERT£¬£¬£¬ £¬£¬£¬ £¬ÒÔ¼õÇáÕâ´Îй©µÄ·çÏÕ¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/400000-us-south-korean-card-records-put-up-for-sale-online/


4.°²È«×¨¼Ò·¢ÏÖ28¸ö·À²¡¶¾²úÆ·´æÔÚsymlink race·ì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


RACK911 LabsµÄ°²È«×¨¼ÒÔÚWindows¡¢macOSºÍLinuxƽ̨ÉϵÄ28¸öÊÜ»¶Ó­µÄ·À²¡¶¾Èí¼þÖз¢ÏÖsymlink race·ì϶£¬£¬£¬ £¬£¬£¬ £¬ÊÜÓ°ÏìµÄÆ·ÅÆÔ̺¬³ÛÃûÆ·ÅÆAvast¡¢BitDefender¡¢F-Secure¡¢FireEye¡¢McAfeeºÍkasperskyµÈ¡£¡£¡£¡£¡£¡£ ¡£°²È«×¨¼Ò³Æ¹¥»÷Õß¿ÉÀûÓÃÕâЩ·ì϶ɾ³ýϵͳÉϵÄÎļþ£¨Ô̺¬·À²¡¶¾Èí¼þ»ò²Ù×÷ϵͳʹÓõÄÎļþ£©£¬£¬£¬ £¬£¬£¬ £¬´Ó¶øµ¼Ö·À²¡¶¾Èí¼þÎÞ·¨¹¤×÷»ò²Ù×÷ϵͳ±ÀÀ£¡£¡£¡£¡£¡£¡£ ¡£¾ßÌåÀ´Ëµ£¬£¬£¬ £¬£¬£¬ £¬´óÎÞÊý·À²¡¶¾Èí¼þ¶¼Ã»ÓÐ˼¿¼µ½´ÓɨÃè³ö¶ñÒâÎļþµ½Ö´Ðжϸù²Ù×÷Ö®¼äµÄ΢Ó×¹¦·ò´°¿Ú£¬£¬£¬ £¬£¬£¬ £¬±¾µØ¹¥»÷Õß»ò¶ñÒâÈí¼þ×÷Õß¿ÉÀûÓÃWindowsÖеÄĿ¼Á´½Ó»òLinux/macOSÖеķûºÅÁ´½ÓÀ´´¥·¢ÌáȨºÍ¾ºÕùǰÌᣬ£¬£¬ £¬£¬£¬ £¬´Ó¶ø½ûÓ÷À²¡¶¾Èí¼þ»ò×ÌÈŲÙ×÷ϵͳ¡£¡£¡£¡£¡£¡£ ¡£RACK911Ïò·À²¡¶¾³§É̻㱨ÁËÆä·¢ÏÖÁ˾Ö£¬£¬£¬ £¬£¬£¬ £¬´óÎÞÊý³§ÉÌÒѾ­½¨¸´ÁËÆä²úÆ·Öеķì϶¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/102230/hacking/symlink-race-antivirus-flaws.html


5.ÈÎÌìÌÃÈ·ÈÏ16ÍòÓû§ÕË»§±»½Ù³Ö£¬£¬£¬ £¬£¬£¬ £¬ÒѳöÏÖµÁË¢°¸Àý


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÈÎÌìÌÃĿǰȷÈÏÆäÖÁÉÙ16ÍòÓû§ÕË»§Òѱ»½Ù³Ö£¬£¬£¬ £¬£¬£¬ £¬»¹³öÏÖÁ˵ÁË¢°¸Àý¡£¡£¡£¡£¡£¡£ ¡£Õâ´Î¹¥»÷ÊÇ´Ó3ÔÂÖÐÑ®ÆðÍ·µÄ£¬£¬£¬ £¬£¬£¬ £¬ºÚ¿Íͨ¹ýαÔìNintendo Network ID £¨NNID£©·¸·¨µÇ¼ÈÎÌìÌÃÕÊ»§£¬£¬£¬ £¬£¬£¬ £¬ÇÔÈ¡ÁËÓû§µÄêdzơ¢µ®ÉúÈÕÆÚ¡¢Ô­¼®¹ú¡¢µØÓòºÍµç×ÓÓʼþµØÖ·£¬£¬£¬ £¬£¬£¬ £¬»¹ÀûÓÃÁËijЩÓû§ÕË»§Öа󶨵ÄPayPal²É°ìÓÎÏ·ÖеÄÖ°ÄܺÍÐ鹹Ǯ±Ò£¨Ô̺¬Fortnite V-Bucks£©¡£¡£¡£¡£¡£¡£ ¡£NNIDÊǾÉʽµÇ¼ϵͳ£¬£¬£¬ £¬£¬£¬ £¬ËüÔÊÐíÓû§ÔÚWii U»òNintendo 3DSÉÏÖÎÀíNintendoÕÊ»§¡£¡£¡£¡£¡£¡£ ¡£Ä¿Ç°¸Ã¹«Ë¾°ä·¢ÏÖÒѾ­°Î³ýÁËͨ¹ýNNIDµÇ½ÕË»§µÄÖ°ÄÜ£¬£¬£¬ £¬£¬£¬ £¬²¢½«ÎªÊÜÓ°ÏìµÄÕ˺ųÁÖÃÃÜÂë¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/102213/hacking/nintendo-account-hijacking-campaign.html


6.IoT½©Ê¬ÍøÂçHoaxcallsбäÖÖÔ̺¬16ÖÖDDoSÖ°ÄÜ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


2020Äê4ÔÂ20ÈÕ£¬£¬£¬ £¬£¬£¬ £¬RadwareµÄ×êÑÐÈËÔ±·¢ÏÖÁËIoT½©Ê¬ÍøÂçHoaxcallsµÄбäÖÖ£¬£¬£¬ £¬£¬£¬ £¬¸Ã±äÖÖÔ̺¬16ÖÖDDoSÖ°ÄÜ¡£¡£¡£¡£¡£¡£ ¡£IoT½©Ê¬ÍøÂçHoaxcalls×î³õÊÇ½è¼øÁ˽©Ê¬ÍøÂçTsunamiºÍGafgytµÄ´úÂ룬£¬£¬ £¬£¬£¬ £¬Ê¹ÓÃUDP£¬£¬£¬ £¬£¬£¬ £¬DNSºÍHEX·ººé·¢ÆðDDoS¹¥»÷£¬£¬£¬ £¬£¬£¬ £¬Õë¶ÔGrandstream UCM6200ϵÁÐÉ豸ºÍDraytek Vigor·ÓÉÆ÷µÄCVE-2020-5722ºÍCVE-2020-8515·ì϶£¨CVSS v3.1 9.8£©¡£¡£¡£¡£¡£¡£ ¡£Radware°µÊ¾£¬£¬£¬ £¬£¬£¬ £¬ÓëÒÔǰµÄÑù±¾Ïà±È¸ÃбäÖÖ¹¥»÷ÄÜÁ¦ÏÔÖøÌá¸ß£¬£¬£¬ £¬£¬£¬ £¬ËüʵÏÖÁË16ÖÖеÄDDoSÖ°ÄÜ£¬£¬£¬ £¬£¬£¬ £¬ÀûÓÃÁËGrandStream UCM SQL×¢Èë·ì϶CVE-2020-5722¡£¡£¡£¡£¡£¡£ ¡£¸Ã±äÖÖÊÇ´ÓÒ»¸öÍйܷþÎñÆ÷£¨176.123.3.96£©ÆðÍ·´«²¼µÄ£¬£¬£¬ £¬£¬£¬ £¬ÔÚ±»·¢ÏÖµÄ48Ó×ʱÄÚÀûÓÃÁË15¸öIPµØÖ·½øÐд«²¼£¬£¬£¬ £¬£¬£¬ £¬¶øÈç½ñÍйܷþÎñÆ÷µÄÊýÁ¿Òѳ¬¹ý75¸ö£¬£¬£¬ £¬£¬£¬ £¬¸Ã±äÖÖ»¹Í¨¹ýÀûÓÃZyXEL Cloud CNM SecuManagerÖеķì϶À©´óÁËÖ¸±êÉ豸ÁÐ±í¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/102202/malware/hoaxcalls-botnet-new-variant.html