Î÷ÃÅ×Ó¶à¿î¹¤Òµ×°±¸ÊÜLinuxÄÚºËÎó²îSegmentSmackÓ°Ï죻£»Å·ÖÞÄÜÔ´¹«Ë¾EDPѬȾRagnarLocker
Ðû²¼Ê±¼ä 2020-04-161.Î÷ÃÅ×Ó¶à¿î¹¤Òµ×°±¸ÊÜLinuxÄÚºËÎó²îSegmentSmackÓ°Ïì
Î÷ÃÅ×ÓÐû²¼4Ô²¹¶¡¸üУ¬£¬£¬£¬ ÆäÖÐ3ÌõÐÂͨ¸æÍ¨Öª¿Í»§Æä¶à¿î¹¤Òµ×°±¸Êܵ½LinuxÄÚºËÎó²îSegmentSmackÓ°Ïì¡£¡£¡£¡£SegmentSmackºÍFragmentSmack£¨»®·Ö±»¸ú×ÙΪCVE-2018-5390ºÍCVE-2018-5391£©ÊÇÑо¿ÈËJuha-Matti TilliÔÚ2018Äê·¢Ã÷µÄÁ½¸öLinuxÄÚºËÎó²î£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÄ¿µÄϵͳ·¢ËͶñÒâÊý¾Ý°üÀ´ÌᳫDoS¹¥»÷¡£¡£¡£¡£ÔÚµÚÒ»·Ýͨ¸æÖÐÎ÷ÃÅ×Ó³ÆSegmentSmackºÍFragmentSmackÓ°ÏìÁËËüµÄIE/PB-Link×°±¸¡¢RUGGEDCOM·ÓÉÆ÷¡¢»ùÓÚROXµÄVPNÖն˺ͷÀ»ðǽ¡¢SCALANCE·ÓÉÆ÷ºÍ·À»ðǽ¡¢SIMATICͨѶ´¦Öóͷ£Æ÷ºÍSinema Remote Connect¡£¡£¡£¡£µÚ¶þ·Ýͨ¸æÖÐÎ÷ÃÅ×ÓÅû¶ÓëSegmentSmackÓйصÄDoSÎó²î£¨CVE-2019-19301£©£¬£¬£¬£¬¸ÃÎó²îÓ°ÏìÁËSIMATICͨѶģ¿£¿£¿£¿£¿£¿é¡¢SCALANCE X½»Á÷»úºÍSIPLUS×°±¸¡£¡£¡£¡£µÚÈý·Ýͨ¸æÔòÅû¶ÁËÓ°ÏìÎ÷ÃÅ×ÓSIDOORÃÅÖÎÀíϵͳ¡¢SIMATIC×°±¸¡¢SINAMICSת»»Æ÷ºÍSIPLUS²úÆ·µÄDoSÎó²î£¨CVE-2019-19300£©¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/siemens-industrial-devices-affected-segmentsmack-linux-kernel-flaw
2.Ó¢ÌØ¶ûÐû²¼4ÔÂÇå¾²¸üУ¬£¬£¬£¬ÐÞ¸´¶à¿î²úÆ·ÖеÄ9¸öÎó²î
Ó¢ÌØ¶ûÔÚ4Ô²¹¶¡¸üÐÂÖÐÐÞ¸´ÁË9¸öÎó²î£¬£¬£¬£¬ÕâЩÎó²î¾ùΪÖиßΣÎó²î£¬£¬£¬£¬Ó°Ïì¶à¸öÈí¼þ¡¢¹Ì¼þ¼°Æ½Ì¨¡£¡£¡£¡£Ó¢ÌضûÐÞ¸´ÁËPROSet/ÎÞÏßWiFi²úÆ·ÔÚWindows 10ÉϵÄÁ½¸öÎó²î-¾ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÓÉÓÚ²»Çå¾²µÄ¼ÌÐøÈ¨ÏÞ¶ø¿ÉÄÜͨ¹ýÍâµØ»á¼û¾ÙÐÐÌØÈ¨Éý¼¶£¨CVE-2020-0557£©£»£»ÓÉÓÚÄÚºËÇý¶¯³ÌÐòÖеĻº³åÇøÏÞÖÆ²»µ±£¬£¬£¬£¬ÎÞÌØÈ¨µÄ¹¥»÷Õß¿ÉÄÜͨ¹ýÏàÁÚÍøÂç»á¼ûÀ´µ¼Ö¾ܾøÐ§ÀÍ£¨CVE-2020-0558£©¡£¡£¡£¡£Ó¢Ìضû»¹ÐÞ¸´ÁËNUC mini PCµÄϵͳ¹Ì¼þÖкÍÄ£¿£¿£¿£¿£¿£¿é»¯Ð§ÀÍÆ÷MFS2600KISPPÅÌËãÄ£¿£¿£¿£¿£¿£¿éÖеÄÁ½¸öÎó²î£¬£¬£¬£¬°üÀ¨²»×¼È·µÄ»º³åÇøÏÞÖÆµ¼ÖµÄLPEÎó²î£¨CVE-2020-0600£©ºÍÌõ¼þ¼ì²é²»µ±µ¼ÖµÄÌáȨÎó²î£¨CVE-2020-0578£©¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/intel-april-platform-update-fixes-high-severity-security-issues/
3.΢ÈíÐû²¼4ÔÂOfficeÇå¾²¸üУ¬£¬£¬£¬ÐÞ¸´55¸öÎó²î
΢ÈíÔÚ4ÔÂOfficeÇå¾²¸üÐÂÖÐÕë¶Ô7¸ö²úÆ·ÐÞ¸´ÁË55¸öÎó²î£¬£¬£¬£¬ÆäÖаüÀ¨Ó°ÏìÁËMicrosoft OfficeºÍMicrosoft Office SharePoint²úÆ·µÄ12¸öRCEÎó²î£¬£¬£¬£¬ÕâЩÎó²î¾ù±»¹éÀàΪÑÏÖØ»òÖ÷Òª¼¶±ð£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃËüÃÇÔÚSharePointÓ¦ÓóÌÐòºÍSharePointЧÀÍÆ÷ÕÊ»§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£Î¢Èí»¹ÐÞ¸´ÁË10¸öXSSÎó²î£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜʹÓÃÕâЩÎó²îÔÚÄ¿½ñÓû§µÄÇå¾²ÉÏÏÂÎÄÖÐÔËÐо籾²¢Ã°³äÓû§¡¢ÇÔÈ¡Ãô¸ÐÊý¾Ý»òδ¾ÊÚȨÔĶÁÄÚÈÝ¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬Î¢ÈíÐÞ¸´ÁËÁ½¸öÌáȨÎó²îºÍËĸöÓÕÆÎó²î¡£¡£¡£¡£ÏêϸÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-office-april-security-updates-fix-critical-rce-bugs/
4.Å·ÖÞÄÜÔ´¹«Ë¾EDPѬȾRagnarLocker£¬£¬£¬£¬±»ÀÕË÷½ü1000ÍòÅ·Ôª
¿ËÈÕÆÏÌÑÑÀ¿ç¹úÄÜÔ´¾ÞÍ·Energias de Portugal£¨EDP£©Ôâµ½ÀÕË÷Èí¼þRagnarLocker¹¥»÷£¬£¬£¬£¬±»ÀÕË÷1580 BTCµÄÊê½ð£¨Ô¼ºÏ1090ÍòÃÀÔª»ò990ÍòÅ·Ôª£©¡£¡£¡£¡£EDP¼¯ÍÅÊÇÅ·ÖÞÄÜÔ´ÐÐÒµ£¨×ÔÈ»ÆøºÍµçÁ¦£©×î´óµÄÔËÓªÉÌÖ®Ò»£¬£¬£¬£¬Ò²ÊÇÌìϵÚËÄ´ó·çÄÜÉú²úÉÌ¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚÈ«ÇòËĸö´óÖÞµÄ19¸ö¹ú¼Ò/µØÇøÓµÓÐÓªÒµ£¬£¬£¬£¬²¢ÇÒÓµÓÐÁè¼Ý11500ÃûÔ±¹¤ºÍΪÁè¼Ý1100Íò¿Í»§ÌṩÄÜÔ´¡£¡£¡£¡£ÔÚ¹¥»÷Àú³ÌÖУ¬£¬£¬£¬Ragnar Locker¹¥»÷ÍÅ»ïÉù³ÆÇÔÈ¡ÁËÁè¼Ý10 TBµÄ¹«Ë¾Ãô¸ÐÎļþ£¬£¬£¬£¬²¢Íþв³ÆÈôÊǸù«Ë¾¾Ü¾øÖ§¸¶Êê½ð£¬£¬£¬£¬ËûÃǽ«Ðû²¼ÍµÈ¡µÄËùÓÐÊý¾Ý¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/ragnarlocker-ransomware-hits-edp-energy-giant-asks-for-10m/
5.TA505¼ÌÐøÊ¹ÓÃSDBbot RATѬȾÆóÒµÍøÂ磬£¬£¬£¬Ö÷ÒªÕë¶ÔÅ·ÖÞ
IBM X-ForceÍŶÓÊӲ쵽TA505¼ÌÐøÊ¹ÓÃSDBbot RATѬȾÆóÒµÍøÂç¡£¡£¡£¡£ÔÚ2019Äê11Ô£¬£¬£¬£¬X-Force IRISÊӲ쵽Óй¥»÷ÕßʹÓÃð³äµÄOnehub´¹ÂÚÓʼþ¹¥»÷Å·ÖÞµÄÆóÒµÔ±¹¤£¬£¬£¬£¬¸Ã´¹ÂÚÓʼþÖ¼ÔÚÇÔÈ¡Active Directory£¨AD£©Êý¾Ý¼°Óû§Æ¾Ö¤£¬£¬£¬£¬²¢Ê¹ÓÃSDBbot RATѬȾÆóÒµÍøÂçÇéÐΡ£¡£¡£¡£Æ¾Ö¤Ñо¿Ö°Ô±¶Ô¹¥»÷ÕßµÄTTP¡¢C£¦C»ù´¡ÉèÊ©ÒÔ¼°ÏÈǰ¹éÒòÓÚ¸Ã×éÖ¯µÄÌØ¶¨¶ñÒâÈí¼þµÄÆÊÎö£¬£¬£¬£¬X-Force IRISÒÔΪTA505ÊǸù¥»÷»î¶¯±³ºóµÄ¹¥»÷ÍŻ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityintelligence.com/posts/ta505-continues-to-infect-networks-with-sdbbot-rat/
6.¾É½ðɽ»ú³¡¹¥»÷Õß»òΪ¶íÂÞ˹APT×éÖ¯Energetic Bear
ESETÑо¿Ö°Ô±ÒÔΪ£¬£¬£¬£¬¶Ô¾É½ðɽ¹ú¼Ê»ú³¡£¡£¡£¡£¨SFO£©ÍøÕ¾µÄ¹¥»÷ÊÇÓɱ»³ÆÎªEnergetic BearµÄ¶íÂÞË¹ÍøÂçÌØ¹¤×éÖ¯¾ÙÐеġ£¡£¡£¡£¸ÃAPT×éÖ¯×Ô2010ÄêÒÔÀ´Ò»Ö±ºÜ»îÔ¾£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÄÜÔ´ºÍ¹¤ÒµÁìÓòµÄ×éÖ¯¡£¡£¡£¡£SFOµÄ»ú³¡ÐÅÏ¢ÊÖÒպ͵çÐŲ¿·Ö£¨ITT£©ÌåÏÖ¹¥»÷ÕßÔÚ»ú³¡ÍøÕ¾ÉÏÖ²ÈëÁ˶ñÒâ´úÂëÒÔÇÔÈ¡Óû§µÄµÇ¼ƾ֤£¬£¬£¬£¬¿ÉÄÜÊܹ¥»÷Ó°ÏìµÄÓû§°üÀ¨Ê¹ÓÃWindows×°±¸»ò·ÇSFOά»¤µÄ×°±¸Í¨¹ýIEä¯ÀÀÆ÷´Ó»ú³¡ÍøÂçÍⲿ»á¼ûÕâÐ©ÍøÕ¾µÄÓû§¡£¡£¡£¡£SFOµÄITÖ°Ô±ÒѾɾ³ýÁË×¢ÈëÆäÍøÕ¾ÖеĶñÒâ´úÂ룬£¬£¬£¬²¢ÔÚ¹¥»÷±¬·¢ºó½«Á½Õß¶¼¾ÙÐÐÁËÍÑ»ú´¦Öóͷ£¡£¡£¡£¡£ÎªÏìÓ¦´ËÊÂÎñ£¬£¬£¬£¬SFO»ú³¡ÖØÖÃÁËËùÓеĵç×ÓÓʼþºÍÍøÂçÃÜÂë¡£¡£¡£¡£ESET³Æ¹¥»÷ÕßʹÓÃSMB¹¦Ð§ºÍfile£º//ǰ׺À´ÊÕ¾Û»á¼ûÕßµÄWindowsƾ֤£¬£¬£¬£¬°üÀ¨Óû§ÃûºÍNTLM¹þÏ£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/101601/apt/energetic-bear-airport-hack.html


¾©¹«Íø°²±¸11010802024551ºÅ