ESET·¢ÏÖºÚ¿ÍÀûÓÃαÔìµÄClubhouse·Ö·¢BlackRock£»£»£» £»£»£»ºÚ¿ÍÍÅ»ïSilverFishÀûÓÃÊܺ¦ÕßÍøÂç½øÐÐɳºÐ²âÊÔ

°ä²¼¹¦·ò 2021-03-22

1.ESET·¢ÏÖºÚ¿ÍÀûÓÃαÔìµÄClubhouse·Ö·¢BlackRock


1.jpg


ÉÏÖÜÎ壬 £¬£¬£¬£¬ESETµÄ×êÑÐÈËÔ±·¢ÏÖºÚ¿ÍÀûÓÃαÔìµÄAndroid°æClubhouse·Ö·¢BlackRock Trojan¡£¡£¡£¡£¡£¡£¡£ClubhouseÊÇÒôƵ̸ÌìÀûÓ㬠£¬£¬£¬£¬µ«Ä¿Ç°Ö»ÔÚiOSÊÜÆ­Ç°¿ÉÓ㬠£¬£¬£¬£¬ÉÐδ°ä²¼Android°æ±¾µÄClubhouse¡£¡£¡£¡£¡£¡£¡£BlackRock×î³õÓÚ2020Äê5Ô±»·¢ÏÖ£¬ £¬£¬£¬£¬Ö¼ÔÚÇÔÈ¡Óû§ÔÚ¸÷À໥ÁªÍøÀûÓ㨳¬¹ý458¸ö£©ÉϵÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¸ÃľÂí¿ÉÄÜÀ¹½ØºÍ´Û¸ÄSMSÐÂÎÅ¡¢°µ²ØÍ¨Öª¡¢ÔÚÓû§ÔËÐÐɱ¶¾Èí¼þʱ½«Æä³Á¶¨Ïòµ½É豸Ö÷ÆÁÄ»ºÍÔ¶³ÌËø¶¨ÆÁÄ»¡£¡£¡£¡£¡£¡£¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/fraudsters-jump-on-clubhouse-hype-to-push-malicious-android-app/


2.Netscout·¢ÏÖ´óÁ¿DTLS·þÎñÆ÷¿ÉÓÃÓÚDDoS·Å´ó¹¥»÷


2.jpg


°²È«¹«Ë¾Netscout·¢ÏÖ´óÁ¿DTLS·þÎñÆ÷¿ÉÓÃÓÚDDoS·Å´ó¹¥»÷£¬ £¬£¬£¬£¬·Å´ó±ÈÀýΪ37.34£º1¡£¡£¡£¡£¡£¡£¡£DTLSÊÇ´«Êä²ã°²È«ÐÔ£¨TLS£©ºÍ̸»ùÓÚUDPµÄ°æ±¾£¬ £¬£¬£¬£¬¿ÉÔ¤·À¶ÔÑÓ³¤Ãô¸ÐµÄÀûÓúͷþÎñ½øÐÐÇÔÌýºÍ´Û¸Ä¡£¡£¡£¡£¡£¡£¡£ÔçÔÚÈ¥Äê12Ô·ݣ¬ £¬£¬£¬£¬¾Í´æÔÚÀûÓÃCitrix ADCÉ豸µÄDTLSµÄDDoS¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£CitrixÓÚ½ñÄêÔÚ1Ô°䲼Á˲¹¶¡·¨Ê½£¬ £¬£¬£¬£¬µ«Ö±µ½´Ë¿ÌÈÔÓг¬¹ý4200¶ą̀DTLS·þÎñÆ÷¿É±»ÓÃÓÚ·´ÉäºÍ·Å´óDDoS¹¥»÷¡£¡£¡£¡£¡£¡£¡£Netscout°µÊ¾µ¥ÏòÁ¿DTLS·Å´óDDoS¹¥»÷¿É´ïÔ¼44.6 Gbps£¬ £¬£¬£¬£¬¶àÏòÁ¿¹¥»÷Ôò¸ß´ïÔ¼206.9 Gbps¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ddos-booters-now-abuse-dtls-servers-to-amplify-attacks/


3.ºÚ¿ÍÍÅ»ïSilverFishÀûÓÃÊܺ¦ÕßÍøÂç½øÐÐɳºÐ²âÊÔ


3.jpg


ÈðÊ¿°²È«¹«Ë¾ProdaftÉÏÖÜËijƣ¬ £¬£¬£¬£¬ÓëSolarWinds¹¥»÷ÓйصĺڿÍÍÅ»ïSilverFishÀûÓÃÊܺ¦ÕßÍøÂç½øÐÐɳºÐ²âÊÔ¡£¡£¡£¡£¡£¡£¡£SilverFishÒѹ¥»÷Á˳¬¹ý4720¸öÆóÒµºÍµ±¾Ö×éÖ¯£¬ £¬£¬£¬£¬Ô̺¬²Æ¸»500Ç¿ÆóÒµ¡¢µ±²¿ÃÅÃÅ¡¢º½¿Õ¹«Ë¾¡¢¹ú·À³Ð°üÉÌ¡¢Éó¼ÆºÍÕ÷ѯ¹«Ë¾ÒÔ¼°Æû³µÔì×÷ÉÌ¡£¡£¡£¡£¡£¡£¡£¸ÃÍŻ↑·¢ÁËÒ»¸öÓÉÊܺ¦ÕߵķþÎñÆ÷×é³ÉµÄ¶ñÒâÈí¼þ¼ì²âɳÏ䣬 £¬£¬£¬£¬Äܹ»ÓÃ·ÖÆçµÄÆóÒµAVºÍEDR½â¾ö¹æ»®À´²âÊÔËûÃǵÄpayload£¬ £¬£¬£¬£¬ÒÔÔö³¤Æä¹¥»÷µÄ³É¹¦ÂÊ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/solarwinds-linked-hacking-group-silverfish-abuses-enterprise-victims-in-sandbox-malware-tests/


4.WordPress²å¼þ±»±¬³ö¶à¸ö·ì϶£¬ £¬£¬£¬£¬¿É½Ù³Ö½üǧÍò¸öÍøÕ¾


4.jpg


×êÑÐÈËÔ±Åû¶ÁËWordPress²å¼þElementorºÍWP Super CacheÖеķì϶£¬ £¬£¬£¬£¬¿É±»ÓÃÓÚËÁÒâ´úÂëÖ´ÐÐÒÔ¼°ÊÕÊÜÍøÕ¾¡£¡£¡£¡£¡£¡£¡£Wordfence·¢ÏÖElementorÔªËØÖÐûÓжÔHTML±êÇ©½øÐзþÎñÆ÷¶ËÑéÖ¤£¬ £¬£¬£¬£¬Òò¶ø´æÔÚ¶à¸öXSS·ì϶£¬ £¬£¬£¬£¬CVSSÆÀ·ÖΪ6.4£¬ £¬£¬£¬£¬¿É±»ÓÃÀ´´´½¨ÖÎÀíÔ¹ØÊ»§»òÏòÍøÕ¾Ôö³¤ºóÃÅ£¬ £¬£¬£¬£¬Æä×°ÖÃÁ¿³¬¹ý700Íò¡£¡£¡£¡£¡£¡£¡£Patchstack·¢ÏÖ×°ÖÃÁ¿³¬¹ý200ÍòµÄWP Super CacheÖдæÔÚ¾­¹ýÉí·ÝÑéÖ¤µÄÔ¶³Ì´úÂëÖ´ÐÐ(RCE)·ì϶¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/115750/hacking/wordpress-plugins-flaws.html


5.Google°ä²¼2020ÄêijºÚ¿Í×éÖ¯¹¥»÷»î¶¯µÄ»ã±¨


5.jpg


Google¡¯s Project ZeroÍŶӰ䲼ÁË2020ÄêijºÚ¿Í×éÖ¯¹¥»÷»î¶¯µÄ»ã±¨¡£¡£¡£¡£¡£¡£¡£»ã±¨·¢ÏÖ£¬ £¬£¬£¬£¬¸ÃÍÅ»ïÔÚ2020Äê2ÔºÍ10ÔÂÌáÒéÁËÁ½´Î¹¥»÷»î¶¯£¬ £¬£¬£¬£¬ÀûÓÃÁËÖÁÉÙ11¸öÁãÈÕ·ì϶¡£¡£¡£¡£¡£¡£¡£ºÚ¿Íͨ¹ýһϵÁй¥»÷»î¶¯³ÉÁ¢¶ñÒâÍøÕ¾£¬ £¬£¬£¬£¬½«½Ó¼ûÕß³Á¶¨Ïòµ½ÍйÜÁËAndroid¡¢WindowsºÍiOSÉ豸µÄ¹¥»÷Á´µÄ·þÎñÆ÷ÉÏ¡£¡£¡£¡£¡£¡£¡£ÆäÖУ¬ £¬£¬£¬£¬2Ô·ݵĹ¥»÷ʹÓÃÁËCVE-2020-6418ºÍCVE-2020-0938µÈ4¸ö·ì϶£¬ £¬£¬£¬£¬10Ô·ݵĹ¥»÷ʹÓÃÁËCVE-2020-15999ºÍCVE-2020-17087µÈ7¸ö·ì϶¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://googleprojectzero.blogspot.com/2021/03/in-wild-series-october-2020-0-day.html


6.kaspersky°ä²¼2020ÄêStalkerware¹¥»÷»î¶¯µÄ»ã±¨


6.jpg


kaspersky°ä²¼ÁË2020ÄêStalkerware¹¥»÷»î¶¯µÄ»ã±¨¡£¡£¡£¡£¡£¡£¡£Stalkerware¶ñÒâÈí¼þµÄÖ°Äܸ÷²»Ò»Ñù£¬ £¬£¬£¬£¬µ«´óÎÞÊý¶¼Äܹ»¶ÔÊܺ¦ÕßµÄÊÖ»ú½øÐÐÈ«Ãæ¼à¿Ø¡£¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬ £¬£¬£¬£¬2018ÄêÈ«Çò½ü40000¸öÓû§Ôâµ½´ËÀà¶ñÒâÈí¼þµÄÓ°Ï죬 £¬£¬£¬£¬2019ÄêÍ»ÆÆÁË67000£¬ £¬£¬£¬£¬2020ÄêΪ½ü54000¸öÓû§¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìÓû§µÄÄê¶ÈÇúÏßÏÔʾ£¬ £¬£¬£¬£¬2020Äê3ÔÂÖÁ6Ô£¬ £¬£¬£¬£¬Êܺ¦ÕßµÄÊýÁ¿ÓÐËù½µÂä¡£¡£¡£¡£¡£¡£¡£ÔÚÈ«ÇòÁìÓòÄÚ£¬ £¬£¬£¬£¬¶íÂÞ˹¡¢°ÍÎ÷ºÍÃÀ¹úµÄStalkerwareÊýÁ¿×î¶à£»£»£» £»£»£»ÔÚÑÇÖÞ£¬ £¬£¬£¬£¬Ó¡¶ÈµÄÎÊÌâ×îΪÑϳÁ£»£»£» £»£»£»¶øÔÚÅ·ÖÞ£¬ £¬£¬£¬£¬ÊÜÓ°Ïì×î´óµÄÊǵ¹ú¡¢Òâ´óÀûºÍÓ¢¹ú¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.kaspersky.com/blog/stalkerware-in-2020/39102/