Sophos´¹Î£½¨¸´·À»ðǽÖеÄSQL×¢Èë0day£»£»£»£»£»£»ºÚ¿ÍÏúÊÛ»ãÒ½»ÛÓ°COVID-19 AI¸¨Öú¼ì²â¼¼ÊõµÄÔ´´úÂë

°ä²¼¹¦·ò 2020-04-27

1.Sophos´¹Î£½¨¸´·À»ðǽÖеÄSQL×¢Èë0day£¬£¬£¬£¬£¬£¬£¬Òѱ»Ò°±íÀûÓÃ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÍøÂ簲ȫ¹«Ë¾SophosÓÚÖÜÁù°ä²¼ÁË´¹Î£²¹¶¡ÒÔ½¨¸´ÒѾ­±»Ò°±íÀûÓõÄSQL×¢Èë0day£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶ӰÏìÁËÆäXG Firewall²úÆ·¡£¡£¡£ ¡£¡£¡£¡£4ÔÂ22ÈÕÍí£¬£¬£¬£¬£¬£¬£¬Sophos¹«Ë¾·¢ÏÖºÚ¿ÍÀûÓÃXG FirewallÖеÄSQL×¢Èë·ì϶ÇÔÈ¡Á˸ÃÉ豸ÖеÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬Ô̺¬·À»ðǽÉ豸ÖÎÀíÔ¹ØË»§¡¢·À»ðǽÃÅ»§ÍøÕ¾ÖÎÀíÔ¹ØË»§ºÍÔ¶³Ì½Ó¼ûÉ豸ÕË»§ÖеĵÄÓû§ÃûºÍ¹þÏ£ÃÜÂë¡£¡£¡£ ¡£¡£¡£¡£¸Ã¹«Ë¾°µÊ¾Õâ´Î¸üÐÂÒѾ­½¨¸´Á˸ÃSQL×¢Èë·ì϶£¬£¬£¬£¬£¬£¬£¬²¢ÇÒмÓÁËÌØÊâÌáÐÑÖ°ÄÜʹ¿Í»§ÖªÂ·ÆäÉ豸ÊÇ·ñÊܵ½ÁËÍþв¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hackers-are-exploiting-a-sophos-firewall-zero-day/


2.ºÚ¿ÍÏúÊÛ»ãÒ½»ÛÓ°COVID-19 AI¸¨Öú¼ì²â¼¼ÊõµÄÔ´´úÂë


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Êý¾Ýй¶֪ͨ¹«Ë¾Cyble×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°ºÚ¿ÍÔÚÏúÊÛ»ãÒ½»ÛÓ°COVID-19 AI¸¨Öú¼ì²â¼¼ÊõµÄÔ´´úÂëºÍ³¢ÊÔÊý¾Ý¡£¡£¡£ ¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬£¬£¬»ãÒ½»ÛÓ°ÔÚÓ뻪ΪºÏ×÷£¬£¬£¬£¬£¬£¬£¬¿ª·¢Ò»ÖÖ»ùÓÚAIµÄCOVID-19¼ì²âϵͳ£¬£¬£¬£¬£¬£¬£¬¸ÃϵͳÄܹ»´ÓÐØ²¿CTµÄDICOMͼÏñ¼ì²âÊÇ·ñ´æÔÚϰȾ֢״¡£¡£¡£ ¡£¡£¡£¡£»£»£»£»£»£»ãÒ½»ÛÓ°ÕýÒÔÿÔÂ50000ÃÀÔªµÄ¼ÛÖµÏúÊÛ¸Ãϵͳ¡£¡£¡£ ¡£¡£¡£¡£¶øºÚ¿ÍÐû³ÆÆäÒÑ»ñµÃCOVID-19¼ì²â¼¼ÊõÔ´´úÂëÒÔ¼°ÑéÊý¾Ý£¬£¬£¬£¬£¬£¬£¬²¢ÒÔ4±ÈÌØ±ÒµÄ¼ÛÖµÏò±íÏúÊÛ¡£¡£¡£ ¡£¡£¡£¡£±»µÁÊý¾ÝÔ̺¬Óû§ÐÅÏ¢£¨1.5 MB£©¡¢¼¼ÊõºÍÔ´´úÂ루1GB£©¡¢Covid-19³¢ÊÔÓйØÄÚÈÝ£¨150 MB£©¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/102270/data-breach/huiying-medical-technology-data-breach.html


3.ÍþÊ¿¼ÉÅÄÂôÍøÕ¾WhiskyAuctioneer±»¹¥»÷ÖÂÅÄÂôÎÞÏÞÑÓÆÚ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ó¢¹úÍþÊ¿¼ÉÅÄÂôÍøÕ¾WhiskyAuctioneerÓÚ4ÔÂ21ÈÕ22£º30°ä·¢ÆäÔâµ½Á˶ñÒâ¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÅÄÂô»î¶¯±»ÎÞÏÞÑÓÆÚ¡£¡£¡£ ¡£¡£¡£¡£¸ÃÊÂÎñ²úÉúÓÚ4ÔÂ20ÈÕ£¬£¬£¬£¬£¬£¬£¬¾ºÅĻ±¾¸Ã7µãʵÏÖ£¬£¬£¬£¬£¬£¬£¬µ«ÓÉÓÚÍøÕ¾Òì³££¬£¬£¬£¬£¬£¬£¬»î¶¯±»ÑÓÆÚÁË48Ó×ʱ¡£¡£¡£ ¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬£¬¸ÃÍøÕ¾·¢ÏÔìäÍøÕ¾ºÍÊý¾Ý¿âÔâµ½ÁËÓÐÕë¶ÔÐÔÇÒ¸´ÔӵĶñÒâ¹¥»÷¡£¡£¡£ ¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬¸ÃÍøÕ¾Ò»Ïò´¦ÓÚÍÑ»úÊØ»¤×´Ì¬£¬£¬£¬£¬£¬£¬£¬²¢°µÊ¾ÅÄÂô»î¶¯½«»á±»ÎÞÏÞÑÓÆÚ¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.theguardian.com/technology/2020/apr/25/online-auction-of-record-breaking-whisky-collection-hit-by-cyber-attack


4.ÐÂÎÄ×ÖÕ¨µ¯ÀûÓÃÐŵÂÓ£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂiOSºÍmac OSÉ豸±ÀÀ£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Graham Cluley·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬×î½üгöÁËÒ»ÖÖÔ̺¬ÐŵÂÓï×Ö·ûµÄÎÄ×ÖÕ¨µ¯£¬£¬£¬£¬£¬£¬£¬Êܺ¦Õ߲鿴Ô̺¬¸ÃÎÄ×ÖÕ¨µ¯µÄÎı¾Ê±£¬£¬£¬£¬£¬£¬£¬»áµ¼ÖÂiOSºÍmac OSÉ豸±ÀÀ£¡£¡£¡£ ¡£¡£¡£¡£ÐŵÂÓïÊǰͻù˹̹ʹÓõĹٷ½Ëµ»°Ö®Ò»£¬£¬£¬£¬£¬£¬£¬µ«ÊÇmacOSºÍiOSÎÞ·¨¼ø±ð¸Ã˵»°±àдµÄUnicode·ûºÅ£¬£¬£¬£¬£¬£¬£¬µ¼Ö²Ù×÷ϵͳÎÞ·¨Õý³£ÔËÐÓ×£¡£¡£ ¡£¡£¡£¡£¸ÃÎÊÌâ×îÔçÊÇÔÚÉÏÖÜËı»·¢Ïֵ쬣¬£¬£¬£¬£¬£¬±»³Æ×÷CapturetheFlag£¬£¬£¬£¬£¬£¬£¬²¢ÒѾ­ÔÚTwitterÉÏ´«²¼¿ªÀ´¡£¡£¡£ ¡£¡£¡£¡£CluleyÖ¸³ö£¬£¬£¬£¬£¬£¬£¬³ÁÐÂÆô¶¯É豸Äܹ»½â¾ö´ËÎÊÌâ¡£¡£¡£ ¡£¡£¡£¡£AppleÉ豸ÔÚ´ÓǰҲÓÐÀàËÆÎÊÌ⣬£¬£¬£¬£¬£¬£¬2013Äê°¢À­²®Óï×Ö·û¡¢2018ÄêÄÏÓ¡¶ÈµÄÈË̩¬¹ÌÓï¶¼Äܹ»Ê¹MacºÍiPhone±ÀÀ£¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/apple-text-bomb-crashes-iphones-message-notifications/155144/


5.TrickBotÍÅ»ïÔÚд¹µö¹¥»÷Öзַ¢BazarBackdoorºóÃÅ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


×êÑÐÈËÔ±·¢ÏÖTrickBotÍÅ»ïÔÚÀûÓÃд¹µö¹¥»÷·Ö·¢BazarBackdoorºóÃÅ£¬£¬£¬£¬£¬£¬£¬ÒÔ·ÛËé²¢µÃµ½ÆóÒµÍøÂçµÄÆëÈ«½Ó¼ûȨÏÞ¡£¡£¡£ ¡£¡£¡£¡£¹¥»÷ÕßÊ×ÏÈÒÔ¿Í»§Í¶Ëß¡¢COVID-19Ö÷Ì⹤×ʻ㱨µÈÐÅϢΪµö¶ü£¬£¬£¬£¬£¬£¬£¬ÓÕʹÊܺ¦Õß´ò¿ª¼Ù×°³ÉWordÎĵµ¡¢Excelµç×Ó±í¸ñ»òPDFµÄºóÃżÓÔØ·¨Ê½BazaLoader¡£¡£¡£ ¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬£¬BazarLoaderͨ¹ýEmercoin·ÖɢʽDNS½âÎö·þÎñÀ´½âÎöʹÓà bazarÓòµÄ¸÷ÀàÖ÷»úÃû¡£¡£¡£ ¡£¡£¡£¡£½âÎöµ½C2 IPµØÖ·ºó£¬£¬£¬£¬£¬£¬£¬¼ÓÔØ·¨Ê½Ê×ÏÈÏνӵ½Ò»¸öC2²¢Ö´ÐÐ×¢²á£¬£¬£¬£¬£¬£¬£¬ÔÙʹÓÃÁíÒ»¸öC2ÒªÇóÏÂÔØXOR¼ÓÃܵÄBazarBackdoor£¬£¬£¬£¬£¬£¬£¬´´½¨ºóÃÅ¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/bazarbackdoor-trickbot-gang-s-new-stealthy-network-hacking-malware/


6.Facebook 1400¶à¸öÓû§³ÉΪ¼äµýÈí¼þPegasusÖ¸±ê


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Facebook¶ÔÒÔÉ«ÁÐNSO GroupÌá¸æ×´ËÏ£¬£¬£¬£¬£¬£¬£¬Ö¸¿ØÆäÀûÓüäµýÈí¼þPegasusÕë¶Ô1400¶à¸öÓû§¡£¡£¡£ ¡£¡£¡£¡£ÊÂÎñ²úÉúÔÚ2019Äê´º¼¾£¬£¬£¬£¬£¬£¬£¬NSO GroupÀûÓÃÁËWhatsApp VoIPÖ°ÄÜÖеķì϶£¨ CVE-2019-3568£©Ö²ÈëÁ˼äµýÈí¼þPegasus£¬£¬£¬£¬£¬£¬£¬¶ÔWhatsAppÓû§ÌáÒéÁËÖÁÉÙ720´Î¹¥»÷¡£¡£¡£ ¡£¡£¡£¡£Õâ´ÎÊÂÎñµÄÊܺ¦ÕßΪ1400¶àÃûÓû§£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬¼ÇÕß¡¢ÈËȨ»î¶¯¼Ò¡¢ÕþÖÎÒìÒéÈËÊ¿¡¢±í½»¹Ù¡¢ÂÉʦºÍµ±¾Ö¹ÙÔ±¡£¡£¡£ ¡£¡£¡£¡£½ñÄê4Ô£¬£¬£¬£¬£¬£¬£¬NSO GroupÌá³öÁËÉêÊö£¬£¬£¬£¬£¬£¬£¬ÀíÓÉÊǸù«Ë¾Îª±í¹úÆóÒµ£¬£¬£¬£¬£¬£¬£¬¼ÓÖÝ·¨ÔºÃ»ÓйÜϽȨÀ´Ö÷³Ö´Ë°¸£¬£¬£¬£¬£¬£¬£¬µ«Facebook˾·¨ÍŶÓÈ´·ñ¾öÕâһ˵·¨£¬£¬£¬£¬£¬£¬£¬°µÊ¾NSO Group²»Ó¦¸Ã±»»íÃâ¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/102260/laws-and-regulations/facebook-nso-group-lawsuit.html