WhatsAppÅû¶ÆäÓ¦ÓÃÖеÄ6¸öÎó²î £¬£¬£¬£¬ £¬£¬ÏÖÒÑÐÞ¸´£»£»£»£»£»£»°¢¸ùÍ¢ÒÆÃñ¾ÖϵͳѬȾNetwalkerµ¼ÖÂЧÀÍÔÝÍ£4Сʱ

Ðû²¼Ê±¼ä 2020-09-07

1.WhatsAppÅû¶ÆäÓ¦ÓÃÖеÄ6¸öÎó²î £¬£¬£¬£¬ £¬£¬ÏÖÒÑÐÞ¸´



1.png


WhatsAppÅû¶ÆäÓ¦ÓÃÖб£´æµÄ6¸öÎó²î £¬£¬£¬£¬ £¬£¬ÏÖÒÑÐÞ¸´¡£¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄÎó²îÖнÏΪÑÏÖØµÄΪ¿ÍջдÈëÒç³öÎó²î£¨CVE-2020-1894£© £¬£¬£¬£¬ £¬£¬¿Éµ¼ÖÂí§Òâ´úÂëÖ´ÐÐ £¬£¬£¬£¬ £¬£¬32λװ±¸±£´æµÄдÒç³öÎó²î£¨CVE-2020-1891£©ºÍURLÑéÖ¤ÎÊÌ⣨CVE-2020-1890£© £¬£¬£¬£¬ £¬£¬¿Éµ¼ÖºڿÍÔÚûÓÐÓëÓû§½»»¥µÄÇéÐÎÏ´ӷ¢¼þÈ˵ÄURL¼ÓÔØÍ¼Ïñ¡£¡£¡£¡£¡£¡£ÆäËûÎó²îΪÇå¾²¼ì²âÈÆ¹ýÎÊÌ⣨CVE-2020-1889µÄ£©¡¢»º³åÇøÒç³öÎó²î£¨CVE-2020-1886£©ºÍÊäÈëÑéÖ¤ÎÊÌ⣨CVE-2019-11928£©¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/107950/security/whatsapp-undisclosed-flaws.html


2.¿¨°Í˹»ùÑо¿ÏÔʾÕë¶ÔÔÚÏß½ÌÓýµÄDDoS¹¥»÷ÔöÌí350£¥


2.png


¿¨°Í˹»ùµÄ×îÐÂÑо¿ÏÔʾ £¬£¬£¬£¬ £¬£¬2019Äê1ÔÂÖÁ2020Äê6ÔÂÖ®¼ä £¬£¬£¬£¬ £¬£¬Õë¶ÔÔÚÏß½ÌÓý×ÊÔ´µÄDDoS¹¥»÷ÔöÌíÁË350£¥¡£¡£¡£¡£¡£¡£ÔÚÈ«Çò¹æÄ£ÄÚ £¬£¬£¬£¬ £¬£¬Óë2019ÄêµÚÒ»¼¾¶ÈÏà±È £¬£¬£¬£¬ £¬£¬2020ÄêµÚÒ»¼¾¶ÈDDoS¹¥»÷µÄ×ÜÊýÔöÌíÁË80£¥ £¬£¬£¬£¬ £¬£¬ÆäÖÐÕë¶Ô½ÌÓý×ÊÔ´µÄ¹¥»÷Õ¼ÁËÔöÌíµÄºÜ´óÒ»²¿·Ö¡£¡£¡£¡£¡£¡£¸Ã±¨¸æ»¹·¢Ã÷ £¬£¬£¬£¬ £¬£¬ÓÐ168550Ãû¿¨°Í˹»ùÓû§Ôâµ½ÁËÒÔÖÖÖÖÔÚÏßѧϰƽ̨»òÊÓÆµ¾Û»áÓ¦ÓóÌÐòΪ»Ï×ÓÈö²¥µÄÍþв £¬£¬£¬£¬ £¬£¬ÊÜÓ°ÏìµÄƽ̨°üÀ¨Moodle¡¢Zoom¡¢edX¡¢Coursera¡¢Google Meet¡¢Google ClassroomºÍBlackboard¡£¡£¡£¡£¡£¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/ddos-attacks-on-virtual-education/


3.FBIÔÙ´ÎÐû²¼ÓйØÀÕË÷Èí¼þProLockÇÔÈ¡Êý¾ÝµÄ¾¯±¨



3.png


FBIÔÚÉÏÖÜÔÙ´ÎÐû²¼ÁËÓйØÀÕË÷Èí¼þProLockÇÔÈ¡Êý¾ÝµÄ¾¯±¨¡£¡£¡£¡£¡£¡£FBIÏÈǰµÄ¾¯±¨ÔøÖÒÑÔ¹«Ë¾ProLockµÄ½âÃÜÆ÷ÎÞ·¨Õý³£ÊÂÇé £¬£¬£¬£¬ £¬£¬½âÃÜÀú³ÌÖÐÁè¼Ý64MBµÄÎļþ¿ÉÄÜ»áË𻵠£¬£¬£¬£¬ £¬£¬Òò´Ë½«µ¼ÖÂÊý¾Ýɥʧ¡£¡£¡£¡£¡£¡£Æ¾Ö¤FBIµÄÊý¾Ý £¬£¬£¬£¬ £¬£¬×Ô2020Äê3ÔÂÆð £¬£¬£¬£¬ £¬£¬ÀÕË÷Èí¼þProLock±³ºóµÄ×éÖ¯Ò»Ö±ÔÚ´ÓÊܺ¦ÕßµÄ×°±¸ÖÐÍøÂçºÍй¶ÐÅÏ¢ £¬£¬£¬£¬ £¬£¬²¢Ê¹ÓÃÇÔÈ¡µÄÊý¾ÝÒªÇóÊܺ¦×éÖ¯Ö§¸¶´Ó17.5ÍòÃÀÔªµ½66ÍòÃÀÔª²»µÈµÄÊê½ð¡£¡£¡£¡£¡£¡£µ½ÏÖÔÚΪֹ £¬£¬£¬£¬ £¬£¬ProLockÒÑÀֳɹ¥»÷ÁËÒ½ÁƱ£½¡¡¢ÐÞ½¨¡¢½ðÈÚ¡¢Ö´·¨µÈÐÐҵʵÌåºÍÃÀ¹úÕþ¸®»ú¹¹¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fbi-issues-second-alert-about-prolock-ransomware-stealing-data/


4.CISAÖÒÑÔÕë¶ÔÈ«Çò½ðÈÚºÍÉÌÒµ×éÖ¯µÄDDoS¹¥»÷»î¶¯



4.png


ÍøÂçÇå¾²ºÍ»ù´¡¼Ü¹¹Çå¾²¾Ö£¨CISA£©ÖÒÑÔÕë¶ÔÈ«Çò½ðÈÚºÍÉÌÒµ×éÖ¯µÄDDoS¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýÏòÄ¿µÄÖ÷»ú»òÍøÂç·¢ËÍÁ÷Á¿ÖÂÆäÎÞ·¨ÏìÓ¦»òÍ߽⠣¬£¬£¬£¬ £¬£¬¼´¿É×èֹĿµÄÓû§»á¼û £¬£¬£¬£¬ £¬£¬´Ó¶øÍê³ÉDoS¹¥»÷¡£¡£¡£¡£¡£¡£ÔÚDDoS¹¥»÷ÖÐ £¬£¬£¬£¬ £¬£¬´«ÈëÁ÷Á¿À´×ÔÐí¶à²î±ðµÄȪԴ £¬£¬£¬£¬ £¬£¬Òò´ËÎÞ·¨Í¨¹ý×èÖ¹µ¥¸öȪԴÀ´×èÖ¹¹¥»÷¡£¡£¡£¡£¡£¡£Êܺ¦×éÖ¯µÄ×ÊÔ´ºÍЧÀͽ«ÎÞ·¨»á¼û £¬£¬£¬£¬ £¬£¬Òò´Ë»ò½«µ¼ÖÂËðʧʱ¼äºÍ¿î×Ó¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/09/04/dos-and-ddos-attacks-against-multiple-sectors


5.ÃÀ¹úº£ÎéµÂÏØÑ§ÇøÑ¬È¾SunCrypt £¬£¬£¬£¬ £¬£¬Ð¹Â¶Î´¼ÓÃܵÄÎļþ


5.png


±±¿¨ÂÞÀ´ÄÉÖݺ£ÎéµÂÏØÑ§ÇøÓÚ2020Äê8ÔÂ24ÈÕÔâµ½ÁËSunCryptÀÕË÷Èí¼þ¹¥»÷ £¬£¬£¬£¬ £¬£¬Ð¹Â¶Î´¼ÓÃܵÄÎļþ¡£¡£¡£¡£¡£¡£´Ë´ÎÊÂÎñÖÐй¶ÁË5GBµÄµµ°¸ £¬£¬£¬£¬ £¬£¬°üÀ¨Ðí¶àÓëÑ§Çø¡¢Ñ§ÉúºÍÏÈÉúÓйصÄÃô¸ÐÎĵµºÍСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£¡£±ðµÄ £¬£¬£¬£¬ £¬£¬´Ë´Î¹¥»÷»¹µ¼ÖÂѧУϵͳÖеÄЧÀÍÆ÷¡¢»¥ÁªÍøºÍµç»°Ð§À͹رա£¡£¡£¡£¡£¡£¾­ÊÓ²ì £¬£¬£¬£¬ £¬£¬¹¥»÷ÕßÊ×ÏȽ¨ÉèÁËÒ»¸öÒÔÊܺ¦ÕßΪÃûµÄPowerShell¾ç±¾ £¬£¬£¬£¬ £¬£¬²¢½«Æä´æ´¢ÔÚWindowsÓò¿ØÖÆÆ÷ÉÏ¡£¡£¡£¡£¡£¡£Ö®ºó £¬£¬£¬£¬ £¬£¬ºÚ¿ÍÒþ²ØµØÇÔÈ¡ÎļþµÄͬʱ £¬£¬£¬£¬ £¬£¬½«ÀÕË÷Èí¼þ·Ö·¢µ½ÆäËû×°±¸¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/suncrypt-ransomware-shuts-down-north-carolina-school-district/


6.°¢¸ùÍ¢ÒÆÃñ¾ÖϵͳѬȾNetwalkerµ¼ÖÂЧÀÍÔÝÍ£4Сʱ



6.png


°¢¸ùÍ¢µÄ¹Ù·½ÒÆÃñ¾ÖDirecci¨®nNacional de MigracionesÔâµ½ÁËNetwalkerÀÕË÷Èí¼þ¹¥»÷ £¬£¬£¬£¬ £¬£¬µ¼ÖÂÆäЧÀÍÔÝÍ£4Сʱ¡£¡£¡£¡£¡£¡£Í¨¹ýÆÀ¹ÀÖÐÑëÊý¾ÝÖÐÐĺÍÂþÑÜʽЧÀÍÆ÷µÄ»ù´¡½á¹¹ÇéÐÎ £¬£¬£¬£¬ £¬£¬·¢Ã÷´Ë´Î¹¥»÷»î¶¯ÒѾ­Ó°ÏìÁËÆä»ùÓÚMS WindowsµÄϵͳÎļþÒÔ¼°Óû§ÎļþºÍ¹²ÏíÎļþ¼ÐÖб£´æµÄMicrosoft OfficeÎļþ¡£¡£¡£¡£¡£¡£Îª±ÜÃâÀÕË÷Èí¼þѬȾÆäËû×°±¸ £¬£¬£¬£¬ £¬£¬ÒÆÃñ¾Ö¹Ø±ÕÁËÆäʹÓõÄÅÌËã»úÍøÂç £¬£¬£¬£¬ £¬£¬ÕâÒ²µ¼ÖÂÁìÍÁ¹ý¾³µãµÄЧÀÍÔÝÍ£ÁË4¸öСʱ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ransomware-attack-halts-argentinian-border-crossing-for-four-hours/