Palo Alto NetworksÐû²¼2020Äê´º¼¾ÔÆÍþв±¨¸æ£»£»£»£»£»ÒÔÉ«ÁÐÕþµ³Ñ¡¾ÙÓ¦ÓÃй¶Áè¼Ý640Íò¹«ÃñÊý¾Ý

Ðû²¼Ê±¼ä 2020-02-10

1.Palo Alto NetworksÐû²¼2020Äê´º¼¾ÔÆÍþв±¨¸æ


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Palo Alto NetworksµÄUnit 42¿ËÈÕÐû²¼Á˰ëÄêÒ»´ÎµÄ¡¶ÔÆÍþв±¨¸æ¡·2020Äê´º¼¾°æ¡£¡£¡£¡£ ¡£¡£ÎªÁËÔÚÔÆÖÐÔ½À´Ô½¶àµØ×Ô¶¯»¯¹¹½¨Á÷³Ì£¬£¬£¬£¬ £¬£¬Ðí¶à×éÖ¯¶¼ÔÚ½ÓÄÉ»ù´¡¼Ü¹¹¼´´úÂ루IaC£©À´×ÊÖú¼ò»¯ÆäÔËÓª¡£¡£¡£¡£ ¡£¡£Unit 42ÆÊÎöÁ˳ÉǧÉÏÍò¸öIaCÄ£°å£¬£¬£¬£¬ £¬£¬ËûÃǵķ¢Ã÷Åú×¢IaCÄ£°åÖÐÓÐ199000¶à¸öDZÔÚÎó²î£¬£¬£¬£¬ £¬£¬×îÖ÷ÒªµÄÊÇÏÖÔÚÓÐÁè¼Ý43£¥µÄÔÆÊý¾Ý¿âδ¼ÓÃÜ£¬£¬£¬£¬ £¬£¬²¢ÇÒÖ»ÓÐ60£¥µÄÔÆ´æ´¢Ð§ÀÍÒÑÆôÓÃÈÕÖ¾¼Í¼¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://start.paloaltonetworks.com/unit-42-cloud-threat-report


2.Êý¾ÝÅú×¢2019ÄêÓÐ4000ÍòÃÀ¹úÈ˵ÄÒ½ÁÆÊý¾Ýй¶


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ƾ֤Fortified Health SecurityµÄ¡¶2020ÄêÒ½ÁƱ£½¡ÍøÂçÇ徲״̬±¨¸æ¡·£¬£¬£¬£¬ £¬£¬2019ÄêÓÐ4000ÍòÃÀ¹úÈËÊܵ½Ò½ÁÆÊý¾Ýй¶µÄÓ°Ïì¨CÓë2018ÄêµÄ1400ÍòÏà±ÈÔöÌíÁË65£¥¡£¡£¡£¡£ ¡£¡£¸Ã±¨¸æ»ã×ÜÁË2009ÄêÖÁ2019ÄêµÄÄê¶ÈÊý¾Ý£¬£¬£¬£¬ £¬£¬·¢Ã÷2019ÄêÊÇ×Ô2015ÄêÒÔÀ´µÄ×î¸ß¼Í¼¡£¡£¡£¡£ ¡£¡£¸Ã±¨¸æ³ÆÓÐ400¶à¸öÒ½ÁÆ»ú¹¹ÓÐÊ·ÒÔÀ´µÚÒ»´Î±¨¸æÔÚÒ»ÄêÄÚй¶ÁË500¸ö»¼ÕßÒÔÉϵÄÒ½ÁƼͼ¡£¡£¡£¡£ ¡£¡£±¨¸æÖ¸³öÖ»¹ÜÐí¶àÆóÒµ×ö³öÁËÒ»Á¬µÄÆð¾¢ÒÔ¾ÙÐÐˢУ¬£¬£¬£¬ £¬£¬µ«ÓÉÓÚÔ¤ËãÓÐÏÞ¡¢ÈËÁ¦×ÊԴȱ·¦ºÍ¾¯±¨¹ý¶àµÄÌôÕ½£¬£¬£¬£¬ £¬£¬ËûÃÇÈÔÈ»ÄÑÒÔÔÚÍøÂç·¸·¨·Ö×ÓÑÛǰ¼á³ÖÁìÏÈְλ¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securitymagazine.com/articles/91679-million-americans-affected-by-health-data-breaches-in-2019


3.Wacom»æÍ¼°å±»·¢Ã÷¸ú×ÙÓû§·­¿ªµÄÓ¦ÓÃÐÅÏ¢


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Èí¼þ¹¤³ÌʦÂÞ²®ÌØ¡¤Ï£¶Ù£¨Robert Heaton£©·¢Ã÷Wacom»æÍ¼°å¸ú×ÙÓû§·­¿ªµÄÿһ¸öÓ¦ÓóÌÐò£¬£¬£¬£¬ £¬£¬ÒÉÇÖÕ¼Óû§Òþ˽¡£¡£¡£¡£ ¡£¡£WacomµÄ¹Ù·½Çý¶¯³ÌÐòÒþ˽սÂÔ½ÏΪģºý£¬£¬£¬£¬ £¬£¬ÈôÊÇÓû§½ÓÊܸÃÕ½ÂÔ£¬£¬£¬£¬ £¬£¬Ëü½«×îÏȸú×ÙÓû§ÔÚÆä×°±¸ÉÏ·­¿ªµÄÓ¦ÓóÌÐò¡£¡£¡£¡£ ¡£¡£Æ¾Ö¤HeatonµÄÊӲ죬£¬£¬£¬ £¬£¬ËùÓÐÊý¾Ý¶¼ÊÇʹÓÃGoogle Analytics£¨ÆÊÎö£©ÕÊ»§ÍøÂçµÄ¡£¡£¡£¡£ ¡£¡£ºÃÐÂÎÅÊǸÃÒþ˽սÂÔ²»ÊÇÇ¿ÖÆÐԵ쬣¬£¬£¬ £¬£¬WacomÓû§¿ÉÒԾܾø½ÓÊܸÃÕ½ÂÔ£¬£¬£¬£¬ £¬£¬²¢ÇÒÇý¶¯³ÌÐòÈÔ»á×°Öᣡ£¡£¡£ ¡£¡£±ðµÄ£¬£¬£¬£¬ £¬£¬ÒѾ­×°ÖÃÁËÇý¶¯³ÌÐòµÄÓû§¿ÉÒÔËæÊ±Ñ¡ÔñÍ˳ö¸ÃÕ½ÂÔ¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/wacom-drawing-tablets-track-every-app-you-open/


4.AnubisľÂíÕë¶Ô250¶à¸öAndroidÓ¦Ó㬣¬£¬£¬ £¬£¬¿ÉÐ®ÖÆÓû§×°±¸


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


CofenseÑо¿Ö°Ô±Marcel Feller·¢Ã÷Ò»¸öеĴ¹ÂÚ¹¥»÷»î¶¯£¬£¬£¬£¬ £¬£¬¹¥»÷ÕßÖ÷Òª·Ö·¢ÒøÐÐľÂíAnubis£¬£¬£¬£¬ £¬£¬¸Ã¶ñÒâÈí¼þ¿ÉÒÔÍêÈ«Ð®ÖÆAndroidÒÆ¶¯×°±¸ÒÔÇÔÈ¡Óû§Æ¾Ö¤¡¢×°ÖüüÅ̼ͼ³ÌÐòÉõÖÁÉúÑÄ×°±¸Êý¾ÝÒÔÀÕË÷Êê½ð¡£¡£¡£¡£ ¡£¡£Ñо¿Ö°Ô±ÌåÏָöñÒâÈí¼þÕë¶Ô250¶à¸öAndroidÓ¦ÓóÌÐò£¬£¬£¬£¬ £¬£¬°üÀ¨¾ßÓж¨ÖƵĵǼÁýÕÖÆÁÄ»£¨ÓÃÓÚ²¶»ñÊäÈëµ½Ó¦ÓóÌÐòÖÐµÄÆ¾Ö¤£©¡£¡£¡£¡£ ¡£¡£¶ñÒâÈí¼þÖ÷Ҫͨ¹ýµä·¶µÄ´¹ÂÚÓʼþ·Ö·¢£¬£¬£¬£¬ £¬£¬ÓʼþÖÐÒªÇóÓû§ÏÂÔØ·¢Æ±£¬£¬£¬£¬ £¬£¬µ«ÏÖʵÉÏ»áÏÂÔØÒ»¸öAPKÎļþ£¨Fattura002873.apk£©£¬£¬£¬£¬ £¬£¬¸ÃÎļþ»áÏÔʾÐéαµÄGoogle Play Protect£¬£¬£¬£¬ £¬£¬ÎªÓ¦ÓóÌÐòÌṩËùÐèµÄËùÓÐȨÏÞͬʱ½ûÓÃÁËÏÖʵµÄGoogle Play Protect¹¦Ð§¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/phishing-campaign-targets-250-android-apps-with-anubis-malware/152666/


5.EmotetÈ䳿ÈëÇÖÖÜΧµÄWi-FiÍøÂçÒÔÈö²¥¸øÐµÄÊܺ¦Õß


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Binary DefenseµÄÑо¿Ö°Ô±³Æ£¬£¬£¬£¬ £¬£¬×î½ü·¢Ã÷µÄEmotet±äÖÖ¾ßÓÐÒ»¸öWi-FiÈ䳿Ä£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬ £¬£¬¸ÃÄ£¿£¿£¿£¿£¿£¿éÔÊÐíEmotetÈëÇÖÖÜΧµÄWi-FiÍøÂçÒÔÈö²¥¸øÐÂÊܺ¦Õß¡£¡£¡£¡£ ¡£¡£¸Ã±äÖÖͨ¹ýʹÓÃwlanAPI.dllŲÓÃÀ´·¢Ã÷ÒÑѬȾÅÌËã»úÖÜΧµÄÎÞÏßÍøÂ磬£¬£¬£¬ £¬£¬²¢ÊµÑéͨ¹ý±©Á¦ÆÆ½â·½·¨ÈëÇÖ¡£¡£¡£¡£ ¡£¡£Ò»µ©ÀÖ³ÉÅþÁ¬µ½ÁíÒ»¸öÎÞÏßÍøÂ磬£¬£¬£¬ £¬£¬¸ÃÈ䳿½«×îÏȲéÕÒ¾ßÓзÇÒþ²Ø¹²ÏíÎļþ¼ÐµÄÆäËûWindows×°±¸£¬£¬£¬£¬ £¬£¬½ÓÏÂÀ´Ëü½«É¨ÃèÕâЩÉè±¹ØÁ¬ÄËùÓÐÕÊ»§£¬£¬£¬£¬ £¬£¬²¢ÊµÑéÕë¶ÔÖÎÀíÔ±ÕÊ»§ºÍËùÓÐÆäËüÓû§ÕË»§¾ÙÐб©Á¦¹¥»÷£¬£¬£¬£¬ £¬£¬ÀֳɺóÒÔservice.exe¶þ½øÖÆÎļþµÄÐÎʽ½«¶ñÒâpayloadÊͷŵ½Êܺ¦ÕßµÄÅÌËã»úÉÏ£¬£¬£¬£¬ £¬£¬²¢×°ÖÃÃûΪ¡°Windows DefenderϵͳЧÀÍ¡±µÄÐÂЧÀÍÒÔÔÚϵͳÉϼá³Ö³¤ÆÚÐÔ¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/emotet-hacks-nearby-wi-fi-networks-to-spread-to-new-victims/


6.ÒÔÉ«ÁÐÕþµ³Ñ¡¾ÙÓ¦ÓÃй¶Áè¼Ý640Íò¹«ÃñÊý¾Ý


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Ñо¿Ö°Ô±·¢Ã÷Elector SoftwareΪÒÔÉ«ÁÐÕþµ³Likud¿ª·¢µÄÑ¡¾ÙÓ¦ÓÃElector±£´æAPIÉèÖùýʧ£¬£¬£¬£¬ £¬£¬µ¼ÖÂÁè¼Ý640Íò¹«ÃñÊý¾Ýй¶¡£¡£¡£¡£ ¡£¡£LikudÊÇÓɸùúÏÖÈÎ×ÜÀí±¾½ÜÃ÷¡¤ÄÚËþÄáÑǺú£¨Benjamin Netanyahu£©Ïòµ¼µÄÕþµ³¡£¡£¡£¡£ ¡£¡£¸ÃÊÂÎñÊÇÓÉÑо¿Ö°Ô±Ran Bar-Zik¶ÔElector¾ÙÐÐÉó¼ÆÊ±·¢Ã÷µÄ£¬£¬£¬£¬ £¬£¬ÏÖÔÚÉв»ÇåÎú̻¶µÄЧÀÍÆ÷ºÍÊý¾ÝÊÇ·ñÒѱ»Î´ÊÚȨ»á¼û¡£¡£¡£¡£ ¡£¡£Bar-ZikÌåÏÖ¸ÃÍøÕ¾µÄ¿ª·¢Ö°Ô±½«API̻¶ÔÚÍøÉÏ£¬£¬£¬£¬ £¬£¬²¢ÇÒûÓÐÃÜÂë±£»£»£»£»£»¤£¬£¬£¬£¬ £¬£¬Ê¹µÃÈκÎÈ˶¼¿ÉÒÔÅÌÎÊÊý¾Ý¿âÖеĹ«ÃñÊý¾Ý£¬£¬£¬£¬ £¬£¬°üÀ¨ÐÕÃû¡¢µç»°ºÅÂë¡¢Éí·ÝÖ¤ºÅÂë¡¢¼Òͥסַ¡¢ÐÔ±ð¡¢ÄêËêºÍÕþÖÎÆ«ºÃµÈÐÅÏ¢£¬£¬£¬£¬ £¬£¬¸ÃAPI»¹¿ÉÒÔ·µ»ØÕ¾µãÖÎÀíÔ±µÄÏêϸÐÅÏ¢£¬£¬£¬£¬ £¬£¬°üÀ¨Ã÷ÎÄÃÜÂë¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/netanyahus-party-exposes-data-on-over-6-4-million-israelis/