ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ44ÖÜ

°ä²¼¹¦·ò 2020-11-02

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2020Äê10ÔÂ26ÈÕÖÁ11ÔÂ01ÈÕ¹²ÊÕ¼°²È«·ì϶59¸ö£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇRuckus Networks Ruckus vRioT /service/v1/createUser endpoint´úÂëÖ´Ðзì϶£»£»£»£»£»£»Winston PrivacyºÅÁî×¢Èë·ì϶£»£»£»£»£»£»NVIDIA DGX Server BMC firmwareÓ²±àÂë·ì϶£»£»£»£»£»£»Synology Router ManagerËÁÒâºÅÁîÖ´Ðзì϶£»£»£»£»£»£»Google chrome Freetype¶ÑÒç³ö´úÂëÖ´Ðзì϶¡£¡£¡£ ¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇд¹µö»î¶¯¼ÙÒâMicrosoft TeamsÕë¶ÔOffice 365Óû§£»£»£»£»£»£»Imperva°ä²¼ÓйØKashmirBlack½©Ê¬ÍøÂçµÄ·ÖÎö»ã±¨£»£»£»£»£»£»Avast°ä²¼ÓйØGoogle PlayÉ϶ñÒâÈí¼þµÄ·ÖÎö»ã±¨£»£»£»£»£»£»ºÚ¿ÍÈëÇÖÌØÀÊÆÕ¾ºÑ¡ÍøÕ¾²¢´«²¼ÐéαÐÅÏ¢£»£»£»£»£»£»CISAºÍCNMF°ä²¼Ð¶ñÒâÈí¼þ±äÌåZebrocyµÄ·ÖÎö»ã±¨¡£¡£¡£ ¡£¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£ ¡£¡£¡£¡£


³ÁÒª°²È«·ì϶Áбí


1.Ruckus Networks Ruckus vRioT /service/v1/createUser endpoint´úÂëÖ´Ðзì϶


Ruckus Networks Ruckus vRioT /service/v1/createUser endpoint´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿Éͨ¹ýweb.pyÒÔrootȨÏÞÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£ ¡£¡£¡£¡£

https://support.ruckuswireless.com/security_bulletins/305


2.Winston PrivacyºÅÁî×¢Èë·ì϶


Winston PrivacyÉ豸ÖÎÀíAPI´æÔÚºÅÁî×¢Èë·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿É½øÐÐËÁÒâ´úÂëÖ´Ðй¥»÷£¬£¬£¬£¬£¬Èçͨ¹ý/api/advanced_settings¸ü¸ÄÉ豸¡£¡£¡£ ¡£¡£¡£¡£

https://labs.bishopfox.com/advisories/winston-privacy-version-1.5.4#CI


3.NVIDIA DGX Server BMC firmwareÓ²±àÂë·ì϶


NVIDIA DGX Server BMC firmware´æÔÚÓ²±àÂë·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿ÉδÊÚȨ½Ó¼û·þÎñÉ豸¡£¡£¡£ ¡£¡£¡£¡£

https://nvidia.custhelp.com/app/answers/detail/a_id/5010


4.Synology Router ManagerËÁÒâºÅÁîÖ´Ðзì϶


Synology Router Manager 7786/7787¶Ë¿Ú´æÔÚ²»ÕýÈ·½Ó¼û½ÚÔì·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿ÉÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£ ¡£¡£¡£¡£

https://www.synology.com/zh-cn/security/advisory/Synology_SA_20_14


5.Google chrome Freetype¶ÑÒç³ö´úÂëÖ´Ðзì϶


Google chrome Freetype´æÔÚ¶ÑÒç¶Âí½Å£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇ󣬣¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬¿É½øÐлؾø·þÎñ¹¥»÷»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£ ¡£¡£¡£¡£

https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.html


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢Ð´¹µö»î¶¯¼ÙÒâMicrosoft TeamsÕë¶ÔOffice 365Óû§


1.jpg


Abnormal Security·¢ÏÖд¹µö»î¶¯¼ÙÒâMicrosoft TeamsÕë¶ÔOffice 365Óû§¡£¡£¡£ ¡£¡£¡£¡£ÕâЩ´¹µöÓʼþÊÇÒÔTeamsÖÐÓÐлΪÖ÷Ìâ·¢Ë͵쬣¬£¬£¬£¬¿´ÆðÀ´ÏñÊÇMicrosoft TeamsµÄ×Ô¶¯Í¨Öª£¬£¬£¬£¬£¬ÓÃÀ´·î¸æÊܺ¦ÕßÓдí¹ýµÄ̸Ìì¡£¡£¡£ ¡£¡£¡£¡£ÓʼþÓÕʹÊܺ¦Õßµã»÷Team»Ø´ðÁ´½Ó£¬£¬£¬£¬£¬ÒÔ³Á¶¨Ïòµ½´¹µöÍøÕ¾£¬£¬£¬£¬£¬À´ÇÔÈ¡Office 365Óû§µÄƾ֤¡£¡£¡£ ¡£¡£¡£¡£×êÑÐÈËÔ±¹Û²ìµ½£¬£¬£¬£¬£¬¹¥»÷ÕßÒѾ­ÀûÓøû¹¥»÷ÁË15000ÖÁ50000¸öOffice 365Óû§¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/109938/cyber-crime/microsoft-teams-phishing-attacks.html


2¡¢Imperva°ä²¼ÓйØKashmirBlack½©Ê¬ÍøÂçµÄ·ÖÎö»ã±¨


2.jpg


Imperva°ä²¼ÁËÓйØKashmirBlack½©Ê¬ÍøÂçµÄ·ÖÎö»ã±¨¡£¡£¡£ ¡£¡£¡£¡£¸Ã»ã±¨ÃèÊöÁËKashmirBlack½©Ê¬ÍøÂç±³ºóµÄ·¸×ï²Ù×÷£¬£¬£¬£¬£¬»áÉÌÁËÆäÖ÷ÕÅÒÔ¼°×êÑв½Öè¡£¡£¡£ ¡£¡£¡£¡£KashmirBlackÖØÒªÕë¶ÔÊ¢ÐеÄCMSƽ̨¡£¡£¡£ ¡£¡£¡£¡£ËüÀûÓÃÁËÖ¸±ê·þÎñÆ÷ÉϵÄÊýÊ®¸öÒÑÖª·ì϶£¬£¬£¬£¬£¬¾ùÔÈÿÌì¶ÔÈ«Çò30¶à¸ö·ÖÆç¹ú¶ÈµÄÊýǧÃûÊܺ¦Õß½øÐÐÊý°ÙÍò´Î¹¥»÷¡£¡£¡£ ¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ÆäÔËÐм«¶È¸´ÔÓ£¬£¬£¬£¬£¬ÓÉһ̨C&C·þÎñÆ÷ÖÎÀí£¬£¬£¬£¬£¬²¢Ê¹ÓÃÁË60¶ą̀·þÎñÆ÷×÷ΪÆä»ù´¡ÉèÊ©µÄÒ»²¿ÃÅ¡£¡£¡£ ¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿É´¦ÖÃÊý°Ù¸ö½©Ê¬·¨Ê½£¬£¬£¬£¬£¬Ö´Ðб©Á¦¹¥»÷¡¢×°ÖúóÃÅ¡¢²¢À©´ó½©Ê¬ÍøÂçµÄ¹æÄ£¡£¡£¡£ ¡£¡£¡£¡£    


Ô­ÎÄÁ´½Ó£º

https://www.imperva.com/blog/crimeops-of-the-kashmirblack-botnet-part-i/


3¡¢Avast°ä²¼ÓйØGoogle PlayÉ϶ñÒâÈí¼þµÄ·ÖÎö»ã±¨


3.jpg


ɱ¶¾Èí¼þÔì×÷ÉÌAvast°ä²¼ÓйØGoogle PlayÉ϶ñÒâÈí¼þµÄ·ÖÎö»ã±¨¡£¡£¡£ ¡£¡£¡£¡£¸Ã»ã±¨³ÆGoogle PlayÉ̵êÖÐÓÐ21¸öϰȾÁËHiddenAds¶ñÒâÈí¼þµÄAndroidÀûÓ÷¨Ê½£¬£¬£¬£¬£¬GoogleÒÑÓÚÖÜĩɾ³ýÁËÆäÖеÄ15¸ö¡£¡£¡£ ¡£¡£¡£¡£Avast¶ñÒâÈí¼þ·ÖÎöʦ°µÊ¾£¬£¬£¬£¬£¬ÕâЩÀûÓ÷ÂÕÕÁËÊ¢ÐеÄÓÎÏ·£¬£¬£¬£¬£¬Ò»µ©Óû§×°ÖÃÁËÕâЩÀûÓ㬣¬£¬£¬£¬HiddenAds¾Í»á°µ²Ø¸ÃÀûÓ÷¨Ê½µÄͼ±êʹÓû§ÄÑÒÔ½øÐÐɾ³ý£¬£¬£¬£¬£¬¶øºóÆðÍ·Óøæ°×ºäÕ¨Óû§¡£¡£¡£ ¡£¡£¡£¡£Avast°µÊ¾£¬£¬£¬£¬£¬½ØÖÁÉÏÖÜÕâЩÀûÓ÷¨Ê½ÒÑ´ï700Íò´ÎÏÂÔØÁ¿¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.avast.com/new-malware-apps-on-google-play-avast


4¡¢ºÚ¿ÍÈëÇÖÌØÀÊÆÕ¾ºÑ¡ÍøÕ¾²¢´«²¼ÐéαÐÅÏ¢


4.jpg


µ±¾Ö¹ÙÔ±°µÊ¾£¬£¬£¬£¬£¬ºÚ¿ÍÔÚÑ¡¾ÙÈÕǰһÖܵÄÐÇÆÚ¶þÈëÇÖÁËÌÆÄɵ¡¤ÌØÀÊÆÕµÄ¾ºÑ¡ÍøÕ¾¡£¡£¡£ ¡£¡£¡£¡£donaldjtrump.comÍøÕ¾±»¡°Õâ¸öÍøÕ¾±»²é·âÁË¡±ÐÂÎÅËùÈ¡´ú£¬£¬£¬£¬£¬²¢°µÊ¾¡°ÊÀ½çÒѾ­Êܹ»ÁËÌÆÄɵ¡¤J¡¤ÌØÀÊÆÕ×ÜͳÿÌìÉ¢²¥µÄ¼ÙÐÂÎÅ¡±¡£¡£¡£ ¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ºÚ¿Í»¹ºôÓõÍøÃñ¾èÔùMoneroÊý×ÖÇ®±ÒÒÔÖ§³Ö»ò·ñ¾öй¶ÓëÌØÀÊÆÕÓйصÄÖ¤¾Ý¡£¡£¡£ ¡£¡£¡£¡£ÌØÀÊÆÕ¾ºÑ¡½²»°ÈËTim Murtaugh°µÊ¾£¬£¬£¬£¬£¬¸ÃÍøÕ¾ºÜ¿ìµÃµ½½¨¸´²¢Ã»ÓÐÈκÎÃô¸ÐÊý¾Ýй¶£¬£¬£¬£¬£¬Õâ´Î¹¥»÷µÄÆðÔ´»¹ÔÚµ÷²éÖÓ×£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/trump-campaign-website-broken-hackers


5¡¢CISAºÍCNMF°ä²¼Ð¶ñÒâÈí¼þ±äÌåZebrocyµÄ·ÖÎö»ã±¨


5.jpg


ÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©ºÍ¹ú·À²¿£¨DOD£©ÍøÂç¹ú¶ÈÐû½Ì¶ÓÁУ¨CNMF£©·¢ÏÖеĶñÒâÈí¼þ±äÌåZebrocy¡£¡£¡£ ¡£¡£¡£¡£¸Ã±äÌåÊÇÒ»¸ö32λµÄWindows¿ÉÖ´ÐÐÎļþ£¬£¬£¬£¬£¬Ê¹ÓÃGolang±à³Ì˵»°±àд£¬£¬£¬£¬£¬Ñ¡È¡µÄ²ÎÊýӦΪÒì»ò£¨XOR£©ºÍÊ®Áù½øÔì±àÂëµÄͳһ×ÊÔ´±êʶ·û£¨URI£©£¬£¬£¬£¬£¬»òÕßÄܹ»Ê¹Óô¿Îı¾URIÔËÐÓ×£¡£¡£ ¡£¡£¡£¡£Ö´ÐÐʱ£¬£¬£¬£¬£¬Ëü½«Ê¹Óø߼¶¼ÓÃܳ߶ȣ¨AES£©-128µç×ÓÃÜÂë²¾£¨ECB£©Ëã·¨¶ÔURI½øÐмÓÃÜ£¬£¬£¬£¬£¬²¢Ê¹ÓôÓÊܺ¦ÕßµÄÖ÷»úÃûÌìÉúµÄÃÜÔ¿£¬£¬£¬£¬£¬´Ë±í»¹»áÍøÂçÓйØÊÜÖ¸±êϵͳµÄÐÅÏ¢¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/10/29/cisa-and-cnmf-identify-new-malware-variant-zebrocy