ÃÀ¹úÌØÇÚ¾ÖÖÒÑÔÕë¶ÔÍйÜЧÀÍÌṩÉÌ£¨MSP£©µÄ¹¥»÷Ôö¶à£»£»£»£»TalosÅû¶ChromeºÍFirefoxÎó²îµÄÊÖÒÕϸ½Ú

Ðû²¼Ê±¼ä 2020-07-07

1.ÃÀ¹úÌØÇÚ¾ÖÖÒÑÔ£¬£¬£¬£¬£¬£¬Õë¶ÔÍйÜЧÀÍÌṩÉÌ£¨MSP£©µÄ¹¥»÷Ôö¶à


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ÃÀ¹úÌØÇÚ¾ÖÏòÃÀ¹ú˽Ӫ²¿·ÖºÍÕþ¸®×éÖ¯·¢³öÁËÇå¾²¾¯±¨£¬£¬£¬£¬£¬£¬ÖÒÑÔÕë¶ÔÖÎÀíЧÀÍÌṩÉÌ£¨MSP£©µÄºÚ¿Í¹¥»÷ÓÐËùÔöÌí¡£¡£¡£ÃÀ¹úÌØÇÚ¾Ö¹ÙÔ±ÌåÏÖ£¬£¬£¬£¬£¬£¬ËûÃǵÄÊÓ²ìС×é·¢Ã÷Ô½À´Ô½¶àµÄºÚ¿Í¶ÔMSPÌᳫ¹¥»÷£¬£¬£¬£¬£¬£¬²¢½«ÆäÊÓΪ½øÈ빫˾ÄÚ²¿ÍøÂçµÄÌø°å¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬ºÚ¿Í»áͨ¹ý±»ºÚµÄMSPs¶Ô¹«Ë¾ÏµÍ³¾ÙÐй¥»÷£¬£¬£¬£¬£¬£¬ÊµÑéÉÌÒµµç×ÓÓʼþ¹¥»÷(BEC)£¬£¬£¬£¬£¬£¬²¢°²ÅÅÀÕË÷Èí¼þ¡£¡£¡£2019Ä걬·¢ÁËÊýÊ®ÆðMSP¹¥»÷ÊÂÎñ£¬£¬£¬£¬£¬£¬¶øGandCrabºÍREvilµÈÀÕË÷Èí¼þÍÅ»ïÒ²×îÏÈÃé×¼MSP£¬£¬£¬£¬£¬£¬È»ºóѬȾÆäÊܺ¦Õß¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/us-secret-service-reports-an-increase-in-hacked-managed-service-providers-msps/#ftag=RSSbaffb68


2.SanSecÐû²¼±¨¸æ³Æ³¯ÏÊÓëMagecart¹¥»÷ÓйØ


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ºÉÀ¼ÍøÂçÇå¾²¹«Ë¾SanSecÔÚ½ñÌìÐû²¼±¨¸æÖÐÌåÏÖ£¬£¬£¬£¬£¬£¬×Ô2019Äê5ÔÂÒÔÀ´£¬£¬£¬£¬£¬£¬³¯ÏÊÒ»Ö±ÔÚ¶ÔÍøÉÏÊÐËÁ¾ÙÐÐMagecart¹¥»÷£¬£¬£¬£¬£¬£¬Êܺ¦Õß°üÀ¨ÔÚ½ñÄê4ÔºÍ6ÔÂÔâµ½ÆÆËðÅä¼þÁ¬ËøµêClaire's¡£¡£¡£SanSec·¢Ã÷×î½üµÄÍøÂçä¯ÀÀ¹¥»÷ÖÐʹÓõÄÓòºÍЧÀÍÆ÷IPµØµãÓëÏÈǰÒÑÖªµÄ³¯ÏÊÕþ¸®×ÊÖúµÄºÚ¿Í»ù´¡ÉèÊ©Óйأ¬£¬£¬£¬£¬£¬²¢¿ÉÒÔ×·Ëݵ½Æ½ÈÀºÚ¿Í×éÖ¯Hindden Cobra¡£¡£¡£Æ½ÈÀµÄºÚ¿Í²»µ«¼ÓÈëÁËATMÍøÂçÇÀ½Ù£¬£¬£¬£¬£¬£¬»¹²ß»®Á˼ÓÃÜÇ®±ÒȦÌ×£¬£¬£¬£¬£¬£¬²¢¹¥»÷Á˼ÓÃÜÇ®±ÒÉúÒâËù¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/north-korean-hackers-linked-to-web-skimming-magecart-attacks-report-says/


3.TalosÅû¶×î½üÐÞ¸´µÄChromeºÍFirefoxÎó²îµÄÊÖÒÕϸ½Ú


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Cisco TalosµÄÑо¿Ö°Ô±Åû¶ÁË×î½üÐÞ¸´µÄChromeºÍFirefox Webä¯ÀÀÆ÷ÖÐÎó²îµÄÊÖÒÕϸ½Ú¡£¡£¡£µÚÒ»¸öÎó²î±»¸ú×ÙΪCVE-2020-6463£¬£¬£¬£¬£¬£¬ÊÇÒ»¸öÄÚ´æËð»µÎó²î£¬£¬£¬£¬£¬£¬Ó°ÏìÁËChromeÖеÄPDFium¡£¡£¡£¹¥»÷Õß¿Éͨ¹ýÓÕÆ­Óû§·­¿ª°üÀ¨JavaScript´úÂëµÄÎĵµÀ´´¥·¢´ËÎó²î£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃÆäÔÚä¯ÀÀÆ÷ÖÐÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£Google ÓÚ4ÔÂÐû²¼ÁËChrome 81.0.4044.122°æ±¾ÐÞ¸´Á˸ÃÎó²î¡£¡£¡£µÚ¶þ¸öÎó²îΪ±»¸ú×ÙΪCVE-2020-12418£¬£¬£¬£¬£¬£¬ÊÇFirefoxÖÐÓëURL mPath¹¦Ð§Ïà¹ØµÄÐÅϢй¶Îó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÓÕʹÊܺ¦Õß»á¼ûÌØÖÆµÄURLÀ´Ê¹ÓøÃÎó²î£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÔ½½ç¶ÁÈ¡¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/105547/security/talos-chrome-firefox-flaws.html


4.΢ÈíÖÒÑÔÀÕË÷Èí¼þAvaddonÈÔÔÚʹÓÃExcel 4.0ºêÈö²¥


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


΢ÈíÖÒÑÔ˵£¬£¬£¬£¬£¬£¬ÀÕË÷Èí¼þAvaddonÒѾ­¾íÍÁÖØÀ´£¬£¬£¬£¬£¬£¬Æä¹¥»÷ËÆºõ¸ü¾ßÕë¶ÔÐÔ£¬£¬£¬£¬£¬£¬²¢ÇÒÒÀÈ»ÒÀÀµ¶ñÒâExcel 4.0ºêÈö²¥¡£¡£¡£Microsoft Security IntelligenceÖ¸³ö£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÏÖÔÚÖ÷Ҫ׼¶ÔÒâ´óÀûµÄÌØ¶¨Ä¿µÄ£¬£¬£¬£¬£¬£¬ËûÃÇͨ¹ý·¢ËÍ´øÓжñÒâExcel 4.0ºêµÄÎĵµµÄµç×ÓÓʼþÌᳫ¹¥»÷¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬ÓжñÒâÓʼþαװ³ÉÊǶ¯¼à²ì¾ÖÏòÒ»¼ÒСÆóÒµ·¢³öµÄÓйØÎ£»£»£»£»úʱÆÚÎ¥·´ÊÂÇé»®¶¨µÄ֪ͨ£¬£¬£¬£¬£¬£¬²¢ÓÕÆ­Êܺ¦Õß·­¿ª¸½¼þÖÐαװ³É¹Ù·½Í¨ÖªµÄZIPÎļþ¡£¡£¡£Î¢ÈíÌåÏÖ£¬£¬£¬£¬£¬£¬×î½ü¼¸¸öÔÂÒÔÀ´ÔÚ¶ñÒâÈí¼þ»î¶¯ÖÐʹÓÃExcel 4.0ºê×îÏȱäµÃÔ½À´Ô½Ê¢ÐС£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/avaddon-ransomware-shows-that-excel-40-macros-are-still-effective/


5.SnakeÔÚ¼ÓÃÜÎļþǰ»á½«Ä¿µÄϵͳ¸ôÀ룬£¬£¬£¬£¬£¬ÒÔ×èÖ¹±»×ÌÈÅ


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ÍøÂçÇå¾²¹«Ë¾Deep InstinctµÄ·¢Ã÷ÀÕË÷Èí¼þSnakeÔÚ¼ÓÃÜÎļþǰ»á½«Ä¿µÄϵͳ¸ôÀ룬£¬£¬£¬£¬£¬ÒÔ×èÖ¹Êܵ½×ÌÈÅ¡£¡£¡£ÔÚ×î½üµÄ¹¥»÷ÖеÄSnakeʾÑù±¾ÊµÏÖÁËÆôÓúͽûÓ÷À»ðǽ£¬£¬£¬£¬£¬£¬ÒÔ¼°Ê¹ÓÃÌØ¶¨ÃüÁî×èÖ¹ÓëϵͳµÄÓк¦ÅþÁ¬µÄ¹¦Ð§¡£¡£¡£ÔÚ×î½üµÄ¹¥»÷ÖÐʹÓõÄSnakeÑù±¾ÊµÏÖÁËÆôÓúͽûÓ÷À»ðǽµÄÄÜÁ¦£¬£¬£¬£¬£¬£¬²¢¿ÉÒÔʹÓÃÌØ¶¨ÃüÁî×èÖ¹²»ÐèÒªµÄϽµµÍ¬½Ó¡£¡£¡£SnakeÔÚ×îÏȼÓÃÜ֮ǰ£¬£¬£¬£¬£¬£¬»áʹÓÃWindows·À»ðǽÀ´×èÖ¹Êܺ¦Õß»úеÉÏûÓÐÉèÖõÄÈκÎÊÕÖ§ÍøÂçÅþÁ¬¡£¡£¡£ÓëÍâ½ç¶Ï¿ªÅþÁ¬ºó£¬£¬£¬£¬£¬£¬Snake»áɱËÀ¿ÉÄÜ×ÌÈżÓÃܵÄÓ²±àÂëÀú³Ì£¬£¬£¬£¬£¬£¬°üÀ¨Ó빤ҵÏà¹ØµÄÀú³Ì£¬£¬£¬£¬£¬£¬ÒÔ¼°Çå¾²ºÍ±¸·Ý½â¾ö¼Æ»®¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/105572/malware/snake-ransomware-isolates-systems.html?utm_source=rss&utm_medium=rss&utm_campaign=snake-ransomware-isolates-systems


6.¶à¸öÔ¼»áÓ¦ÓùýʧÉèÖÃÊý¾Ý¿âй¶Êý°ÙÍòÓû§Ãô¸ÐÊý¾Ý


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


WizCaseµÄITÑо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬£¬£¬ÃÀ¹úºÍ¶«ÑǵÄ5¸öÔ¼»áÓ¦ÓóÌÐòÒò¹ýʧÉèÖÃÊý¾Ý¿âµ¼ÖÂÊý°ÙÍòÓû§Ãô¸ÐÊý¾Ýй¶£¬£¬£¬£¬£¬£¬Ð¹Â¶Êý¾Ý°üÀ¨ÐÕÃû¡¢Õ˵¥µØµã¡¢µç»°ºÅÂ롢СÎÒ˽¼Ò×ÊÁÏ£¬£¬£¬£¬£¬£¬ÉõÖÁÊÇ˽ÈËÐÂÎŵÈÒþ˽¡£¡£¡£´Ë´Î±¬·¢×ß©ÊÂÎñµÄapp»®·ÖΪÃÀ¹úµÄCatholicSinglesºÍ YESTIKI£¬£¬£¬£¬£¬£¬º«¹úµÄBlurryºÍCongdaq/Kongdaq£¬£¬£¬£¬£¬£¬ÈÕ±¾µÄCharinºÍKyuun¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬CatholicSingles»¹Ì»Â¶ÁËÓû§µÄ¸¶¿î·½·¨¡£¡£¡£WizCaseÒÔΪ£¬£¬£¬£¬£¬£¬ÕâЩÊý¾Ý¿ÉÄÜÊÇÔÚWeb ScrappingÀú³Ì±»Ð¹Â¶£¬£¬£¬£¬£¬£¬¸ÃÀú³Ì»áÍøÂçºÍ´æ´¢Óû§ÌṩµÄÐÅÏ¢¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/5-dating-apps-leak-millions-of-user-data/