˼¿ÆÐû²¼Çå¾²¸üУ¬£¬£¬£¬ÐÞ¸´ASAºÍFTDÖеÄ·¾¶±éÀúÎó²î£»£»£»£»£»D-Link·ÓÉÆ÷¹Ì¼þδ¼ÓÃܵľµÏñ¿Éй¶¼ÓÃÜÃÜÔ¿ Ô´´ άËûÃü άËûÃüÇå¾² ½ñÌì
Ðû²¼Ê±¼ä 2020-07-241.˼¿ÆÐû²¼Çå¾²¸üУ¬£¬£¬£¬ÐÞ¸´ASAºÍFTDÖеÄ·¾¶±éÀúÎó²î
˼¿ÆÒÑÐû²¼Çå¾²¸üУ¬£¬£¬£¬ÐÞ¸´×Ô˳ӦÇå¾²×°±¸£¨ASA£©Èí¼þºÍFirepowerÍþв·ÀÓù£¨FTD£©Èí¼þWebЧÀÍÖеÄ·¾¶±éÀúÎó²î£¨CVE-2020-3452£©¡£¡£¡£¡£¡£¸ÃÎó²îÊÇÓÉÓÚÊÜÓ°Ïì×°±¸´¦Öóͷ£µÄHTTPÇëÇóÖеÄURLȱ·¦×¼È·µÄÊäÈëÑéÖ¤ËùÖ£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͰüÀ¨Ä¿Â¼±éÀú×Ö·ûÐòÁеÄÌØÖÆHTTPÇëÇóÀ´Ê¹ÓôËÎó²î¡£¡£¡£¡£¡£ÀֳɵÄʹÓú󣬣¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚÄ¿µÄ×°±¸ÉÏÉó²éWebЧÀÍÎļþϵͳÄÚµÄí§ÒâÎļþ¡£¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÁËAnyConnect»òWebVPNÉèÖõÄASAºÍFTDÈí¼þ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2020/07/23/cisco-releases-security-updates-asa-and-ftd-software
2.¿¨°Í˹»ù·¢Ã÷LazarusʹÓöñÒâÈí¼þMATAÇÔÈ¡Êý¾Ý
¿¨°Í˹»ù×î½ü·¢Ã÷³¯ÏÊ¿Í×éÖ¯LazarusʹÓöñÒâÈí¼þ¿ò¼ÜMATA¾ÙÐÐÀÕË÷Èí¼þ¹¥»÷ºÍÊý¾Ý͵ÇÔ£¬£¬£¬£¬Õë¶Ô¶à¸ö¹ú¼ÒºÍµØÇøµÄ¹«Ë¾£¬£¬£¬£¬°üÀ¨²¨À¼¡¢µÂ¹ú¡¢ÍÁ¶úÆä¡¢º«¹ú¡¢ÈÕ±¾ºÍÓ¡¶È¡£¡£¡£¡£¡£LazarusµÄÄ¿µÄ°üÀ¨µ«²»ÏÞÓÚÈí¼þ¿ª·¢¹«Ë¾¡¢»¥ÁªÍøÐ§ÀÍÌṩÉ̺͵ç×ÓÉÌÎñ¹«Ë¾¡£¡£¡£¡£¡£MATAÊÇÒ»¸öÄ£¿£¿£¿é»¯¿ò¼Ü£¬£¬£¬£¬¿ÉÓÃÓÚѬȾWindows¡¢LinuxºÍmacOSϵͳ¡£¡£¡£¡£¡£ÔÚ¹¥»÷Àú³ÌÖУ¬£¬£¬£¬ºÚ¿ÍʹÓÃMATA½«¶à¸ö²å¼þ¼ÓÔØµ½ÊÜѬȾϵͳµÄÄÚ´æÖУ¬£¬£¬£¬ÔËÐÐÏÂÁ£¬£¬£¬Ê¹ÓÃÎļþºÍÀú³Ì£¬£¬£¬£¬×¢ÈëDLL£¬£¬£¬£¬ÔÚWindows×°±¸ÉϽ¨ÉèHTTPÊðÀíºÍËíµÀ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/lazarus-hackers-deploy-ransomware-steal-data-using-mata-malware/
3.D-Link·ÓÉÆ÷¹Ì¼þδ¼ÓÃܵľµÏñ¿Éй¶¼ÓÃÜÃÜÔ¿
Çå¾²Ñо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬D-Link·ÓÉÆ÷¹Ì¼þδ¼ÓÃܵľµÏñ¿Éй¶¼ÓÃÜÃÜÔ¿¡£¡£¡£¡£¡£ÔÚ×îÏÈÆÊÎöʱ£¬£¬£¬£¬Ñо¿Ö°Ô±´ÓÍøÕ¾ÏÂÔØÁËD-Link¹Ì¼þ£¨ 1.02B03°æ±¾£©£¬£¬£¬£¬È»ºóʹÓÃBinwalk¾ÙÐÐÆÊÎö£¬£¬£¬£¬·¢Ã÷ÁËÁ½¸ö¹Ì¼þÎļþDIR3040A1_FW102B03.binºÍDIR3040A1_FW102B03_uncrypted.bin¡£¡£¡£¡£¡£ÔÚÔËÐÐÒÔuncrypted×îºóµÄÎļþʱ·¢Ã÷£¬£¬£¬£¬¸Ã¾µÏñ°üÀ¨Î´¼ÓÃܵĹ̼þ¶þ½øÖÆÎļþ £¬£¬£¬£¬È»ºóËûÃÇ¿ÉÒÔÌáÈ¡²¢ÆÊÎö´æ´¢µÄ½âÃÜÃÜÔ¿¡£¡£¡£¡£¡£¾ÓɽøÒ»²½ÆÊÎö£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷½âÃܺͼÓÃÜÃÜÔ¿¾ù±»Ç¶Èë¶þ½øÖÆÎļþÖС£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/d-link-blunder-firmware-encryption-key-exposed-in-unencrypted-image/
4.еĽ©Ê¬ÍøÂçPrometeiʹÓÃWindows SMBÍÚ¾ò¼ÓÃÜÇ®±Ò
˼¿ÆTalosÔÚÒ°Íâ·¢Ã÷ÁËÒ»¸öеĽ©Ê¬ÍøÂçPrometei£¬£¬£¬£¬ÆäʹÓÃMicrosoft Windows SMBÐÒéºáÏòÒÆ¶¯£¬£¬£¬£¬Í¬Ê±ÉñÃØµØÍÚ¾ò¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£¸Ã½©Ê¬ÍøÂç×ܹ²ÓÐ15¸ö¿ÉÖ´ÐÐÄ£¿£¿£¿é£¬£¬£¬£¬ÕâЩģ¿£¿£¿éÓÉÒ»¸öÖ÷Ä£¿£¿£¿é¿ØÖÆ£¬£¬£¬£¬ÓÐÁ½¸öÖ÷Òª¹¦Ð§·ÖÖ§£ºÒ»¸öÊÇC ++·ÖÖ§£¬£¬£¬£¬×¨ÃÅÓÃÓÚ¼ÓÃÜÇ®±ÒÍÚ¾ò²Ù×÷£»£»£»£»£»ÁíÒ»¸öÊÇ»ùÓÚ.NETµÄ·ÖÖ§£¬£¬£¬£¬×¨ÃÅÓÃÓÚÆ¾Ö¤ÍµÇÔ£¬£¬£¬£¬ÀÄÓÃSMBºÍ»ìÏý¡£¡£¡£¡£¡£PrometeiÊ×ÏÈͨ¹ýʹÓÃEternal BlueµÈSMBÎó²îÆÆËðÅÌËã»úµÄWindows ServerÐÂÎſ飨SMB£©ÐÒé¡£¡£¡£¡£¡£È»ºóʹÓÃMimikatzºÍ±©Á¦¹¥»÷À´É¨Ãè¡¢´æ´¢ºÍ͵ȡƾ֤£¬£¬£¬£¬²¢½«·¢Ã÷µÄËùÓÐÃÜÂë·¢Ë͵½ÏÂÁîºÍ¿ØÖÆ£¨C2£©Ð§ÀÍÆ÷£¬£¬£¬£¬ÒÔ¹©ÆäËûÄ£¿£¿£¿éʹÓᣡ£¡£¡£¡£¸ÃºÚ¿Í×éÖ¯µÄһ̨C2ЧÀÍÆ÷ÔÚ6Ô±»²é·â£¬£¬£¬£¬µ«ÕâËÆºõ¶ÔPrometeiµÄ»î¶¯Ã»ÓÐÈκÎʵÖÊÐÔÓ°Ïì¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/prometei-botnet-is-infecting-machines-to-mine-for-cryptocurrency/#ftag=RSSbaffb68
5.½©Ê¬ÍøÂçEmotet×îÏÈ´ó×Ú·Ö·¢¶ñÒâÈí¼þQakBot
Ñо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬½©Ê¬ÍøÂçEmotet×îÏȸßËٵطַ¢¶ñÒâÈí¼þQakBot£¬£¬£¬£¬È¡´úÁË֮ǰºã¾ÃʹÓõÄTrickBot¡£¡£¡£¡£¡£Çå¾²Ñо¿Ô±Bom·¢Ã÷ÁËÒ»¸öQakBotÑù±¾£¬£¬£¬£¬²¢Ê¹ÓÃAny.Run¾ÙÐÐÆÊÎö£¬£¬£¬£¬·¢Ã÷ÁËÆäÏÂÁîºÍ¿ØÖÆÐ§ÀÍÆ÷£¨C2£©µØµãµÄÁÐ±í¡£¡£¡£¡£¡£ÍøÂç·¸·¨Ç鱨¹«Ë¾Intel 471½øÒ»²½ÆÊÎöÏÔʾ£¬£¬£¬£¬´ËQBotÑù±¾ÖеÄ×Ö·û´®partner01Åú×¢£¬£¬£¬£¬Emotet´Ë´Î»î¶¯ÓкÜÇ¿µÄÁªÏµ¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬Éв»ÇåÎúQakBot»áÔÚÊÜѬȾµÄϵͳÉϰ²ÅÅʲô£¬£¬£¬£¬µ«Ò»Ð©Êܺ¦Õß¿ÉÄÜ»áѬȾÀÕË÷Èí¼þ£¬£¬£¬£¬ÓÈÆäÊÇProLock¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/emotet-botnet-is-now-heavily-spreading-qakbot-malware/
6.Ô¼¿Ë´óѧÔâÊý¾Ýй¶£¬£¬£¬£¬»òÒòBlackbaudѬȾÀÕË÷Èí¼þ
Ô¼¿Ë´óѧÅû¶ÆäÔâµ½ÁËÊý¾Ýй¶£¬£¬£¬£¬Ô±¹¤ºÍѧÉúÊý¾Ý±»µÁ£¬£¬£¬£¬ÓëÆäµÚÈý·½ÔÆÅÌËãÌṩÉÌBlackbaudÓÚ2020Äê5ÔÂÔâµ½µÄÀÕË÷Èí¼þ¹¥»÷Óйء£¡£¡£¡£¡£¸Ã´óѧÉÐδÅû¶¿ÉÄÜÊܵ½Ó°ÏìµÄСÎÒ˽¼ÒÊýÄ¿£¬£¬£¬£¬µ«ÌåÏÖ´Ë´Îй¶µÄÊý¾Ý¿ÉÄܰüÀ¨ÁËÐÕÃû¡¢Ö°³Æ¡¢ÐԱ𡢳öÉúÈÕÆÚ¡¢Ñ§Éú±àºÅ¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØµã¡¢ÏÖʵµØµãºÍLinkedInСÎÒ˽¼Ò×ÊÁϼͼ¡¢¿Î³ÌÐÅÏ¢¡¢Ëù»ñµÃµÄ×ʸñ¡¢ÓйؿÎÍâ»î¶¯µÄÏêϸÐÅÏ¢¡¢Ö°Òµ¡¢¹ÍÖ÷¡¢ÊÓ²ì»Ø¸´ÒÔ¼°ÒѼͼµÄУÓѻºÍ³ï¿î»î¶¯¡£¡£¡£¡£¡£Ö»¹ÜBlackbaudÒѾ֧¸¶Êê½ð£¬£¬£¬£¬µ«²»¿É°ü¹ÜÊý¾ÝÒѰ´ÐÒéÏú»Ù£¬£¬£¬£¬Òò´Ë¸Ã´óѧ»¹Õö¿ªÁË×Ô¼ºµÄÊӲ죬£¬£¬£¬²¢½«´ËÊÂÎñ¼û¸æÊÂÇéÖ°Ô±¡¢Ñ§ÉúºÍÓ¢¹úÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/university-of-york-discloses-data-breach-staff-and-student-records-stolen/#ftag=RSSbaffb68


¾©¹«Íø°²±¸11010802024551ºÅ