ºÚ¿ÍÔÚGitHub´æ´¢¿âÖй«¿ªCobalt StrikeÔ´´úÂ룻£»£»£»£»£»£»£»ºÚÝ®·¢ÏÖкڿ͹ÍÓ¶¾üCostaRicto£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÄÏÑÇ×éÖ¯

°ä²¼¹¦·ò 2020-11-13
1.ºÚ¿ÍÔÚGitHub´æ´¢¿âÖй«¿ªCobalt StrikeÔ´´úÂë


1.png


ºÚ¿ÍÔÚGitHub´æ´¢¿âÖй«¿ªCobalt Strike¹¤¾ß°üµÄÔ´´úÂë¡£¡£¡£¡£ ¡£¡£¡£Cobalt StrikeÊǺϷ¨µÄÉøÈë²âÊÔ¹¤¾ß°ü£¬£¬£¬£¬£¬¿ÉÔÚÖ¸±êÉ豸Éϲ¿ÊðÐű꣬£¬£¬£¬£¬À´Ô¶³Ì´´½¨Shell²¢Ö´ÐÐPowerShell¾ç±¾¡£¡£¡£¡£ ¡£¡£¡£Ó¢Ìضû×êÑÐÈËÔ±Éó²éÔ´´úÂëºóÒÔΪJava´úÂëÊÇÊÖ¶¯·´±àÒëµÄ£¬£¬£¬£¬£¬ºÚ¿Í½¨¸´ÁËËùÓÐÒÀÀµ¹ØÏµ²¢É¾³ýÁËÐí¿ÉÖ¤²é³­£¬£¬£¬£¬£¬ÒÔ±ã¶ÔÆä½øÐбàÒë¡£¡£¡£¡£ ¡£¡£¡£×Ô°ä²¼ÒÔÀ´£¬£¬£¬£¬£¬¸Ã´æ´¢¿âÒѱ»forked 172´Î£¬£¬£¬£¬£¬ÕâʹµÃÔ´´úÂëµÄ´«²¼Ô½·¢ÄÑÒÔ½ÚÔì¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/alleged-source-code-of-cobalt-strike-toolkit-shared-online/


2.ºÚ¿ÍÔÚ°µÍøÏúÊÛAnimal Jam 4600Íò¸öÓû§µÄÊý¾Ý


2.png


ºÚ¿ÍÔÚ°µÍøÏúÊÛAnimal Jam 4600Íò¸öÓû§µÄÊý¾Ý¡£¡£¡£¡£ ¡£¡£¡£Animal JamÊÇWildWorks´´½¨µÄÐé¹¹ÊÀ½ç£¬£¬£¬£¬£¬Îª¹ãÊÜ»¶Ó­µÄ¶ùͯÔÚÏßÓÎÀÖ³¡¡£¡£¡£¡£ ¡£¡£¡£Ä¿Ç°ºÚ¿ÍÔÚ°µÍø¹²ÏíÁËÁ½¸ö¾Ý³ÆÊÇ´ÓShinyHunters»ñµÃµÄÊôÓÚAnimal JamµÄÊý¾Ý¿â£¬£¬£¬£¬£¬Ãû³Æ±ðÀëΪgame_accountsºÍusers£¬£¬£¬£¬£¬Ô̺¬ÁËԼĪ4600Íò¸ö±»µÁÓû§¼Í¼¡£¡£¡£¡£ ¡£¡£¡£Æ¾¾ÝÑù±¾¼Í¼ÉϵŦ·ò´Á¼Ç£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âºÜ¿ÉÄÜÔÚ2020Äê10ÔÂ12ÈÕ±»µÁµÄ¡£¡£¡£¡£ ¡£¡£¡£WildWorksͨ¹ýµ÷²é·¢ÏÖ£¬£¬£¬£¬£¬ºÚ¿Í¿ÉÄÜÔÚ·ÛËéÁ˹«Ë¾µÄSlack·þÎñÆ÷ºó»ñµÃÁËWildWorkµÄAWSÃÜÔ¿¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/animal-jam-kids-virtual-world-hit-by-data-breach-impacts-46m-accounts/


3.΢Èí°ä²¼Office°²È«¸üУ¬£¬£¬£¬£¬½¨¸´7¿î²úÆ·ÖеĶà¸ö·ì϶


3.png


΢Èí°ä²¼ÁË11ÔÂOffice°²È«¸üУ¬£¬£¬£¬£¬½¨¸´7¿î²úÆ·ÖеÄ14¸ö·ì϶¡£¡£¡£¡£ ¡£¡£¡£Õâ´Î½¨¸´µÄ×îΪÑϳÁµÄ·ì϶ÊÇMicrosoft SharePointÖеÄÔ¶³ÌÖ´ÐдúÂ루RCE£©·ì϶£¨CVE-2020-17061£©£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÀûÓõÍÓû§È¨ÏÞÔ¶³ÌÀûÓô˷ì϶¶øÎÞÐèÓëÓû§½»»¥¡£¡£¡£¡£ ¡£¡£¡£´Ë±í»¹½¨¸´ÁËMicrosoft ExcelÖеĶà¸öÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2020-17065¡¢CVE-2020-17064¡¢CVE-2020-17066ºÍCVE-2020-17019£©ºÍ AccessÏνÓÒýÇæÔ¶³ÌÖ´ÐдúÂë·ì϶£¨CVE-2020-17062£©µÈ¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/office-november-security-updates-fix-remote-code-execution-bugs/


4.NVIDIA½¨¸´GeForce NOWÔÆÓÎÏ··þÎñÖеĴúÂëÖ´Ðзì϶


4.png


NVIDIAΪGeForce NowÔÆÓÎÏ··þÎñ°ä²¼ÁËÒ»¸ö°²È«¸üУ¬£¬£¬£¬£¬ÒÔ½¨¸´¿ÉÄܵ¼ÖÂËÁÒâ´úÂëÖ´ÐлòÌØÈ¨ÌáÉýµÄ·ì϶¡£¡£¡£¡£ ¡£¡£¡£GeForce NowÊÇ»ùÓÚÔÆµÄÓÎÏ·Á÷ýÌå·þÎñ£¬£¬£¬£¬£¬ËüÔÊÐíÓû§´ÓNVIDIA·þÎñÆ÷ÉÏÍйܵÄÊý°Ù¸öÓÎÏ·¿âÖлñÈ¡ÓÎÏ·¡£¡£¡£¡£ ¡£¡£¡£¸Ã·ì϶±»×·×ÙΪCVE?2020?5992£¬£¬£¬£¬£¬´æÔÚÓÚÆä¿ªÔ´Èí¼þÒÀÀµÏîOpenSSL¿âÖУ¬£¬£¬£¬£¬Ò×Êܵ½±¾µØÓû§µÄ¶þ½øÔì×¢Èë¹¥»÷£¬£¬£¬£¬£¬¿Éµ¼Ö´úÂëÖ´ÐлòÌØÈ¨Éý¼¶¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/nvidia-fixes-severe-flaw-in-geforce-now-cloud-gaming-service/


5.½©Ê¬ÍøÂçMuhstikÐÂÔöOracle WebLogicºÍDrupal·ì϶


5.png


×êÑÐÈËÔ±·¢ÏÖ½©Ê¬ÍøÂçMuhstikÐÂÔöOracle WebLogicºÍDrupal·ì϶¡£¡£¡£¡£ ¡£¡£¡£Muhstik½©Ê¬ÍøÂ磨Ҳ³ÆÎªMushtik£©Ò»Ö¹Øë¶ÔÔÆ»ù´¡ÉèÊ©ºÍÎïÁªÍø£¬£¬£¬£¬£¬Í¨¹ýʹÓÃXMRigºÍcgminerµÈ¿ªÔ´¹¤¾ßÍÚ¾ò¼ÓÃÜÇ®±ÒÀ´»ñÀû¡£¡£¡£¡£ ¡£¡£¡£Ôư²È«¹«Ë¾Lacework·¢ÏÔìäÒÑÆðÍ·ÀûÓÃOracle WebLogic Server·ì϶£¨CVE-2019-2725ºÍCVE-2017-10271£©ºÍDrupal RCE·ì϶£¨CVE-2018-7600£©¡£¡£¡£¡£ ¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬×êÑз¢ÏÖMuhstikʹÓÃMiraiÔ´´úÂëͨ¹ýµ¥×Ö½ÚXOR¼ÓÃÜÀ´¼ÓÃÜÆäÓÐЧ¸ºÔغÍɨÃèÄ£¿£¿£¿£¿£¿£¿£¿éµÄÅäÖᣡ£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/110763/uncategorized/muhstik-botnet-weblogic-drupal.html


6.ºÚÝ®·¢ÏÖкڿ͹ÍÓ¶¾üCostaRicto£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÄÏÑÇ×éÖ¯


6.png


ºÚÝ®°ä²¼ÁËÓйØÐµĺڿ͹ÍÓ¶¾ü×éÖ¯CostaRictoµÄ¾ßÌåÐÅÏ¢£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÄÏÑÇ×éÖ¯¡£¡£¡£¡£ ¡£¡£¡£¸Ã×éÖ¯¾«ÐIJ߶¯Á˱鼰ŷÖÞ¡¢ÃÀÖÞ¡¢ÑÇÖÞ¡¢°Ä´óÀûÑǺͷÇÖÞµÄ·ÖÆç¹ú¶ÈµÄ¹¥»÷£¬£¬£¬£¬£¬µ«Êܺ¦Õ߶༯ÖÐÓÚÄÏÑÇ£¬£¬£¬£¬£¬ÓÈÆäÊÇÓ¡¶È¡¢ÃϼÓÀ­¹úºÍÐÂ¼ÓÆÂ£¬£¬£¬£¬£¬²¢ÇÒ´ó²¿ÃÅÊôÓÚ½ðÈÚÐÐÒµ¡£¡£¡£¡£ ¡£¡£¡£ÕâÊǽñÄê·¢ÏֵĵÚÎå¸öºÚ¿Í¹ÍÓ¶×éÖ¯£¬£¬£¬£¬£¬ÆäËûËĸö±ðÀëΪBellTrox (ÓÖ³ÆDark Basin)¡¢DeathStalker (ÓÖ³ÆDeceptikons) ¡¢BahamutºÍUnnamed group¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/blackberry-discovers-new-costaricto-hacker-for-hire-group/