WHO¡¢CDC¡¢NIH¼°¸Ç´Ä»ù½ð»áÔ¼2.5ÍòÓÊÏäÆ¾Ö¤Ð¹Â¶£»£»£»£»£»Ç徲ר¼Ò·¢Ã÷28¸ö·À²¡¶¾²úÆ·±£´æsymlink raceÎó²î

Ðû²¼Ê±¼ä 2020-04-26

1.WHO¡¢CDC¡¢NIH¼°¸Ç´Ä»ù½ð»áÔ¼2.5ÍòÓÊÏäÆ¾Ö¤Ð¹Â¶


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


¾Ý»ªÊ¢¶ÙÓʱ¨±¨µÀ£¬£¬£¬£¬£¬¿ËÈÕWHO¡¢CDC¡¢NIH¼°¸Ç´Ä»ù½ðԼĪÓÐ2.5ÍòÓÊÏäÆ¾Ö¤Ð¹Â¶£¬£¬£¬£¬£¬²¢±»ÓÒÒí¼«¶Ë·Ö×ӺͺڿÍÓÃÀ´Èö²¥COVID-19Ïà¹ØÒ¥ÑÔ¡£¡£¡£¡£WHOÊÇ¡¶ÓÊÕþ¡·±¨¸æÖеÚÒ»¸ö¹ûÕæÈÏ¿ÉÆäÊÂÇéÖ°Ô±µÄµç×ÓÓÊÏäÆ¾Ö¤Ð¹Â¶µÄ×éÖ¯£¬£¬£¬£¬£¬¿ÉÊÇûÓÐ͸©ÕâЩƾ֤ÊÇÔõÑùй¶µÄ¡£¡£¡£¡£Lucy SecurityµÄCEO Colin BastableÔòÒÔΪ´Ë´ÎÊÂÎñÊÇÀ´×ÔÔçÆÚµÄÊý¾Ýй¶£¬£¬£¬£¬£¬ºÚ¿ÍÏëҪʹÓÃÕâЩ¾Éƾ֤Õë¶ÔÄ¿½ñµÄCOVID-19¡£¡£¡£¡£¸Ã»ú¹¹»¹ÌåÏÖ×ß©µÄÊý¾Ý²»»á¶ÔÄ¿½ñµÄWHOϵͳÔì³ÉÈκÎΣº¦£¬£¬£¬£¬£¬ÓÉÓÚÕâЩÊý¾Ý²»ÊÇ×î½üµÄ£¬£¬£¬£¬£¬Ö»ÊÇÓ°ÏìÁËÒ»¸öÓÉÊÀÎÀ×éÖ¯ÏÖÈκÍÍËÐÝÖ°Ô±ÒÔ¼°ÏàÖúͬ°éʹÓþɵÄÍâÁªÍø£¬£¬£¬£¬£¬¸Ã×éÖ¯ÏÖÔÚÕýÔÚ½«ÊÜÓ°ÏìµÄϵͳǨáãµ½¸üÇå¾²µÄÉí·ÝÑé֤ϵͳ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.darkreading.com/attacks-breaches/who-confirms-email-credentials-leak/d/d-id/1337650


2.ÃÀ»ùÒò²âÊÔʵÑéÊÒÔâ´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬23.3Íò¹«ÃñÐÅϢй¶


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ÃÀ¹ú¼ÓÀû¸£ÄáÑÇÖݵĻùÒò²âÊÔʵÑéÊÒAmbry GeneticsÔâµ½´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬23.3Íò¹«ÃñµÄҽѧÐÅϢй¶£¬£¬£¬£¬£¬¸ÃÊÂÎñΪÃÀ¹ú2020ÄêµÚ¶þ´óÒ½ÁÆÊý¾Ý×ß©ÊÂÎñ¡£¡£¡£¡£¸Ã»ú¹¹ÌåÏÖ£¬£¬£¬£¬£¬¹¥»÷±¬·¢ÔÚ1ÔÂ22ÈÕÖÁ24ÈÕÖ®¼ä£¬£¬£¬£¬£¬ºÚ¿Íδ¾­ÊÚȨ»á¼ûÁËÆäÔ±¹¤µÄµç×ÓÓʼþÕÊ»§¡£¡£¡£¡£´Ë´Îй¶µÄÐÅÏ¢°üÀ¨¿Í»§ÐÕÃû¡¢Ò½ÁÆÐÅÏ¢¡¢Óë¿Í»§Ê¹ÓÃAmbryЧÀÍÏà¹ØµÄÐÅÏ¢¡¢ÉÐÓпÉÄܰüÀ¨Éç»áÇå¾²ºÅÂ룬£¬£¬£¬£¬µ«¸Ã¹«Ë¾Ò»Ö±Ã»ÓлØÓ¦ÊÇ·ñ¿ÉÄÜ̻¶ÒÅ´«ÐÅÏ¢¡£¡£¡£¡£2020Äê×î´óµÄÊý¾Ý×ß©ÊÂÎñÊǶíÀÕ¸ÔÖݵĿµ½¡¹²Ïí×éÖ¯£¨Health Share£©ÓÚ2Ô±¨¸æµÄ£¬£¬£¬£¬£¬Æäδ¼ÓÃܵÄÌõ¼Ç±¾µçÄÔ±»ÇÔ£¬£¬£¬£¬£¬Ó°ÏìÁ˽ü654400СÎÒ˽¼Ò¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://covid19.inforisktoday.com/genetic-testing-lab-hack-affects-233000-a-14182


3.ÃÀº«40ÍòÕÅÐÅÓÿ¨ÐÅÏ¢ÔÚ°µÍø³öÊÛ£¬£¬£¬£¬£¬ÊÛ¼ÛÔ¼200ÍòÃÀÔª


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ÏÖÔÚ£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷397365ÕÅÐÅÓÿ¨µÄÐÅÏ¢ÕýÔÚJoker's StashÉÏÒÔ1985835ÃÀÔª³öÊÛ£¬£¬£¬£¬£¬ÆäÖÐ198233ÕÅÊôÓÚº«¹ú£¨Ô¼Õ¼×ÜÊýµÄ49.9£¥£©£¬£¬£¬£¬£¬49.3£¥ÊôÓÚÃÀ¹úÒøÐкͽðÈÚ»ú¹¹¡£¡£¡£¡£´Ë´Î³öÊÛµÄÊý¾ÝÖ÷ҪΪTrack 2Êý¾Ý£¬£¬£¬£¬£¬°üÀ¨ÒøÐÐʶ±ðÂ루BIN£©¡¢Õʺ𢵽ÆÚÈÕÆÚ¡¢»¹¿ÉÄܰüÀ¨CVV£¬£¬£¬£¬£¬¶øÕâЩÊý¾Ýͨ³£ÊÇ´ÓÓÐÎó²îµÄPOS»ú¡¢ATMºÍÖ§¸¶ÏµÍ³ÖÐй¶µÄ¡£¡£¡£¡£¿ÉÊÇ£¬£¬£¬£¬£¬ÏÖÔÚй¶Êý¾ÝµÄȪԴÈÔȻδ֪£¬£¬£¬£¬£¬Î¨Ò»ÄÜÈ·¶¨µÄ¾ÍÊÇÕâЩÊý¾Ý²»ÊÇ´Ó±»Magecart¹¥»÷µÄµçÉÌÍøÕ¾ÖÐй¶µÄ¡£¡£¡£¡£Group-IBµÄShawn TayÌåÏÖ×ÝÈ»ÕâЩ³öÊÛµÄÐÅϢȱ·¦ÒÔÓÃÀ´¾ÙÐÐÔÚÏßÖ§¸¶£¬£¬£¬£¬£¬¿ÉÊǹºÖÃÕß¿ÉÒÔÔÚ·¢¿¨»ú¹¹»¹Ã»Óз¢Ã÷ʱ£¬£¬£¬£¬£¬ÖÆ×÷¿Ë¡¿¨µ½ATMÈ¡¿î£¬£¬£¬£¬£¬µÖ´ïµÁË¢µÄÄ¿µÄ¡£¡£¡£¡£IB¼¯ÍÅÒѽ«´ËÊÂÎñ֪ͨÃÀ¹úºÍº«¹ú½ðÈÚ¹²Ïí×éÖ¯ºÍ¸Ã¹úCERT£¬£¬£¬£¬£¬ÒÔ¼õÇá´Ë´Î×ß©µÄΣº¦¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/400000-us-south-korean-card-records-put-up-for-sale-online/


4.Ç徲ר¼Ò·¢Ã÷28¸ö·À²¡¶¾²úÆ·±£´æsymlink raceÎó²î


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


RACK911 LabsµÄÇ徲ר¼ÒÔÚWindows¡¢macOSºÍLinuxƽ̨ÉϵÄ28¸öÊܽӴýµÄ·À²¡¶¾Èí¼þÖз¢Ã÷symlink raceÎó²î£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄÆ·ÅÆ°üÀ¨×ÅÃûÆ·ÅÆAvast¡¢BitDefender¡¢F-Secure¡¢FireEye¡¢McAfeeºÍkasperskyµÈ¡£¡£¡£¡£Ç徲ר¼Ò³Æ¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²îɾ³ýϵͳÉϵÄÎļþ£¨°üÀ¨·À²¡¶¾Èí¼þ»ò²Ù×÷ϵͳʹÓõÄÎļþ£©£¬£¬£¬£¬£¬´Ó¶øµ¼Ö·À²¡¶¾Èí¼þÎÞ·¨ÊÂÇé»ò²Ù×÷ϵͳÍ߽⡣¡£¡£¡£ÏêϸÀ´Ëµ£¬£¬£¬£¬£¬´ó´ó¶¼·À²¡¶¾Èí¼þ¶¼Ã»ÓÐ˼Á¿µ½´ÓɨÃè³ö¶ñÒâÎļþµ½Ö´ÐÐɨ³ý²Ù×÷Ö®¼äµÄϸСʱ¼ä´°¿Ú£¬£¬£¬£¬£¬ÍâµØ¹¥»÷Õß»ò¶ñÒâÈí¼þ×÷Õß¿ÉʹÓÃWindowsÖеÄĿ¼Á´½Ó»òLinux/macOSÖеķûºÅÁ´½ÓÀ´´¥·¢ÌáȨºÍ¾ºÕùÌõ¼þ£¬£¬£¬£¬£¬´Ó¶ø½ûÓ÷À²¡¶¾Èí¼þ»ò×ÌÈŲÙ×÷ϵͳ¡£¡£¡£¡£RACK911Ïò·À²¡¶¾³§É̱¨¸æÁËÆä·¢Ã÷Ч¹û£¬£¬£¬£¬£¬´ó´ó¶¼³§ÉÌÒѾ­ÐÞ¸´ÁËÆä²úÆ·ÖеÄÎó²î¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/102230/hacking/symlink-race-antivirus-flaws.html


5.ÈÎÌìÌÃÈ·ÈÏ16ÍòÓû§ÕË»§±»Ð®ÖÆ£¬£¬£¬£¬£¬ÒÑ·ºÆðµÁË¢°¸Àý


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ÈÎÌìÌÃÏÖÔÚÈ·ÈÏÆäÖÁÉÙ16ÍòÓû§ÕË»§Òѱ»Ð®ÖÆ£¬£¬£¬£¬£¬»¹·ºÆðÁ˵ÁË¢°¸Àý¡£¡£¡£¡£Õâ´Î¹¥»÷ÊÇ´Ó3ÔÂÖÐÑ®×îÏȵ쬣¬£¬£¬£¬ºÚ¿Íͨ¹ýαÔìNintendo Network ID £¨NNID£©²»·¨µÇ¼ÈÎÌìÌÃÕÊ»§£¬£¬£¬£¬£¬ÇÔÈ¡ÁËÓû§µÄêdzơ¢³öÉúÈÕÆÚ¡¢Ô­¼®¹ú¡¢µØÇøºÍµç×ÓÓʼþµØµã£¬£¬£¬£¬£¬»¹Ê¹ÓÃÁËijЩÓû§ÕË»§Öа󶨵ÄPayPal¹ºÖÃÓÎÏ·ÖеĹ¦Ð§ºÍÐéÄâÇ®±Ò£¨°üÀ¨Fortnite V-Bucks£©¡£¡£¡£¡£NNIDÊǾÉʽµÇ¼ϵͳ£¬£¬£¬£¬£¬ËüÔÊÐíÓû§ÔÚWii U»òNintendo 3DSÉÏÖÎÀíNintendoÕÊ»§¡£¡£¡£¡£ÏÖÔڸù«Ë¾Ðû²¼ÏÖÒѾ­ÆÆ³ýÁËͨ¹ýNNIDÉϰ¶ÕË»§µÄ¹¦Ð§£¬£¬£¬£¬£¬²¢½«ÎªÊÜÓ°ÏìµÄÕ˺ÅÖØÖÃÃÜÂë¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/102213/hacking/nintendo-account-hijacking-campaign.html


6.IoT½©Ê¬ÍøÂçHoaxcallsбäÖÖ°üÀ¨16ÖÖDDoS¹¦Ð§


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


2020Äê4ÔÂ20ÈÕ£¬£¬£¬£¬£¬RadwareµÄÑо¿Ö°Ô±·¢Ã÷ÁËIoT½©Ê¬ÍøÂçHoaxcallsµÄбäÖÖ£¬£¬£¬£¬£¬¸Ã±äÖÖ°üÀ¨16ÖÖDDoS¹¦Ð§¡£¡£¡£¡£IoT½©Ê¬ÍøÂçHoaxcalls×î³õÊÇ½è¼øÁ˽©Ê¬ÍøÂçTsunamiºÍGafgytµÄ´úÂ룬£¬£¬£¬£¬Ê¹ÓÃUDP£¬£¬£¬£¬£¬DNSºÍHEX·ººé·¢¶¯DDoS¹¥»÷£¬£¬£¬£¬£¬Õë¶ÔGrandstream UCM6200ϵÁÐ×°±¸ºÍDraytek Vigor·ÓÉÆ÷µÄCVE-2020-5722ºÍCVE-2020-8515Îó²î£¨CVSS v3.1 9.8£©¡£¡£¡£¡£RadwareÌåÏÖ£¬£¬£¬£¬£¬ÓëÒÔǰµÄÑùÄÚÇé±È¸ÃбäÖÖ¹¥»÷ÄÜÁ¦ÏÔÖøÌá¸ß£¬£¬£¬£¬£¬ËüʵÏÖÁË16ÖÖеÄDDoS¹¦Ð§£¬£¬£¬£¬£¬Ê¹ÓÃÁËGrandStream UCM SQL×¢ÈëÎó²îCVE-2020-5722¡£¡£¡£¡£¸Ã±äÖÖÊÇ´ÓÒ»¸öÍйÜЧÀÍÆ÷£¨176.123.3.96£©×îÏÈÈö²¥µÄ£¬£¬£¬£¬£¬ÔÚ±»·¢Ã÷µÄ48СʱÄÚʹÓÃÁË15¸öIPµØµã¾ÙÐÐÈö²¥£¬£¬£¬£¬£¬¶øÏÖÔÚÍйÜЧÀÍÆ÷µÄÊýÄ¿ÒÑÁè¼Ý75¸ö£¬£¬£¬£¬£¬¸Ã±äÖÖ»¹Í¨¹ýʹÓÃZyXEL Cloud CNM SecuManagerÖеÄÎó²îÀ©´óÁËÄ¿µÄ×°±¸ÁÐ±í¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/102202/malware/hoaxcalls-botnet-new-variant.html