Î÷ÃÅ×Ó¶à¿î¹¤ÒµÉ豸ÊÜLinuxÄں˷ì϶SegmentSmackÓ°Ïì £»Å·ÖÞÄÜÔ´¹«Ë¾EDPϰȾRagnarLocker

°ä²¼¹¦·ò 2020-04-16

1.Î÷ÃÅ×Ó¶à¿î¹¤ÒµÉ豸ÊÜLinuxÄں˷ì϶SegmentSmackÓ°Ïì


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Î÷ÃÅ×Ó°ä²¼4Ô²¹¶¡¸üР£¬ ÆäÖÐ3Ìõв¼¸æÍ¨Öª¿Í»§Æä¶à¿î¹¤ÒµÉ豸Êܵ½LinuxÄں˷ì϶SegmentSmackÓ°Ïì¡£SegmentSmackºÍFragmentSmack£¨±ðÀë±»¸ú×ÙΪCVE-2018-5390ºÍCVE-2018-5391£©ÊÇ×êÑÐÈËJuha-Matti TilliÔÚ2018Äê·¢ÏÖµÄÁ½¸öLinuxÄں˷ì϶ £¬¹¥»÷ÕßÄܹ»Í¨¹ýÏòÖ¸±êϵͳ·¢ËͶñÒâÊý¾Ý°üÀ´ÌáÒéDoS¹¥»÷¡£ÔÚµÚÒ»·Ý²¼¸æÖÐÎ÷ÃÅ×Ó³ÆSegmentSmackºÍFragmentSmackÓ°ÏìÁËËüµÄIE/PB-LinkÉ豸¡¢RUGGEDCOM·ÓÉÆ÷¡¢»ùÓÚROXµÄVPNÖն˺ͷÀ»ðǽ¡¢SCALANCE·ÓÉÆ÷ºÍ·À»ðǽ¡¢SIMATICͨѶ´¦ÖÃÆ÷ºÍSinema Remote Connect¡£µÚ¶þ·Ý²¼¸æÖÐÎ÷ÃÅ×ÓÅû¶ÓëSegmentSmackÓйصÄDoS·ì϶£¨CVE-2019-19301£© £¬¸Ã·ì϶ӰÏìÁËSIMATICͨѶÄ£¿é¡¢SCALANCE X»¥»»»úºÍSIPLUSÉ豸¡£µÚÈý·Ý²¼¸æÔòÅû¶ÁËÓ°ÏìÎ÷ÃÅ×ÓSIDOORÃÅÖÎÀíϵͳ¡¢SIMATICÉ豸¡¢SINAMICSת»»Æ÷ºÍSIPLUS²úÆ·µÄDoS·ì϶£¨CVE-2019-19300£©¡£



Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/siemens-industrial-devices-affected-segmentsmack-linux-kernel-flaw




2.Ó¢ÌØ¶û°ä²¼4Ô°²È«¸üР£¬½¨¸´¶à¿î²úÆ·ÖеÄ9¸ö·ì϶


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Ó¢ÌØ¶ûÔÚ4Ô²¹¶¡¸üÐÂÖн¨¸´ÁË9¸ö·ì϶ £¬ÕâЩ·ì϶¾ùΪÖиßΣ·ì϶ £¬Ó°Ïì¶à¸öÈí¼þ¡¢¹Ì¼þ¼°Æ½Ì¨¡£Ó¢Ìضû½¨¸´ÁËPROSet/ÎÞÏßWiFi²úÆ·ÔÚWindows 10ÉϵÄÁ½¸ö·ì϶-¾­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÓÉÓÚ²»°²È«µÄ¼Ì³ÐȨÏÞ¶ø¿ÉÄÜͨ¹ý±¾µØ½Ó¼û½øÐÐÌØÈ¨Éý¼¶£¨CVE-2020-0557£© £»ÓÉÓÚÄÚºËÇý¶¯·¨Ê½ÖеĻº³åÇøÏ޶Ȳ»µ± £¬ÎÞÌØÈ¨µÄ¹¥»÷Õß¿ÉÄÜͨ¹ýÏàÁÚÍøÂç½Ó¼ûÀ´µ¼Ö»ؾø·þÎñ£¨CVE-2020-0558£©¡£Ó¢Ìضû»¹½¨¸´ÁËNUC mini PCµÄϵͳ¹Ì¼þÖкÍÄ£¿é»¯·þÎñÆ÷MFS2600KISPPÍÆËãÄ£¿éÖеÄÁ½¸ö·ì϶ £¬Ô̺¬²»ÕýÈ·µÄ»º³åÇøÏ޶ȵ¼ÖµÄLPE·ì϶£¨CVE-2020-0600£©ºÍǰÌá²é³­²»µ±µ¼ÖµÄÌáȨ·ì϶£¨CVE-2020-0578£©¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/intel-april-platform-update-fixes-high-severity-security-issues/


3.΢Èí°ä²¼4ÔÂOffice°²È«¸üР£¬½¨¸´55¸ö·ì϶


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


΢ÈíÔÚ4ÔÂOffice°²È«¸üÐÂÖÐÕë¶Ô7¸ö²úÆ·½¨¸´ÁË55¸ö·ì϶ £¬ÆäÖÐÔ̺¬Ó°ÏìÁËMicrosoft OfficeºÍMicrosoft Office SharePoint²úÆ·µÄ12¸öRCE·ì϶ £¬ÕâЩ·ì϶¾ù±»¹éÀàΪÑϳÁ»ò³ÁÒª¼¶±ð £¬¹¥»÷ÕßÄܹ»ÀûÓÃËüÃÇÔÚSharePointÀûÓ÷¨Ê½ºÍSharePoint·þÎñÆ÷ÕÊ»§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂ롣΢Èí»¹½¨¸´ÁË10¸öXSS·ì϶ £¬¹¥»÷Õß¿ÉÄÜÀûÓÃÕâЩ·ì϶ÔÚµ±Ç°Óû§µÄ°²È«¸ßµÍÎÄÖÐÔËÐо籾²¢¼ÙðÓû§¡¢ÇÔÈ¡Ãô¸ÐÊý¾Ý»òδ¾­ÊÚȨÔĶÁÄÚÈÝ¡£´Ë±í £¬Î¢Èí½¨¸´ÁËÁ½¸öÌáȨ·ì϶ºÍËĸöºýŪ·ì϶¡£¾ßÌå·ì϶ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-office-april-security-updates-fix-critical-rce-bugs/


4.Å·ÖÞÄÜÔ´¹«Ë¾EDPϰȾRagnarLocker £¬±»ÀÕË÷½ü1000ÍòÅ·Ôª


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


½üÈÕÆÏÌÑÑÀ¿ç¹úÄÜÔ´¾ÞÍ·Energias de Portugal£¨EDP£©Ôâµ½ÀÕË÷Èí¼þRagnarLocker¹¥»÷ £¬±»ÀÕË÷1580 BTCµÄÊê½ð£¨Ô¼ºÏ1090ÍòÃÀÔª»ò990ÍòÅ·Ôª£©¡£EDP¼¯ÍÅÊÇÅ·ÖÞÄÜÔ´ÐÐÒµ£¨ÌìÈ»ÆøºÍµçÁ¦£©×î´óµÄÔËÓªÉÌÖ®Ò» £¬Ò²ÊÇÊÀ½çµÚËÄ´ó·çÄܳö²úÉÌ¡£¸Ã¹«Ë¾ÔÚÈ«ÇòËĸö´óÖÞµÄ19¸ö¹ú¶È/µØÓòÕ¼ÓÐÒµÎñ £¬²¢ÇÒÕ¼Óг¬¹ý11500ÃûÔ±¹¤ºÍΪ³¬¹ý1100Íò¿Í»§ÌṩÄÜÔ´¡£ÔÚ¹¥»÷¹ý³ÌÖÐ £¬Ragnar Locker¹¥»÷ÍÅ»ïÐû³ÆÇÔÈ¡Á˳¬¹ý10 TBµÄ¹«Ë¾Ãô¸ÐÎļþ £¬²¢Íþв³ÆÈôÊǸù«Ë¾»Ø¾øÖ§¸¶Êê½ð £¬ËûÃǽ«°ä²¼µÁÈ¡µÄËùº±¼û¾Ý¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ragnarlocker-ransomware-hits-edp-energy-giant-asks-for-10m/


5.TA505³ÖÐøÀûÓÃSDBbot RATϰȾÆóÒµÍøÂç £¬ÖØÒªÕë¶ÔÅ·ÖÞ


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


IBM X-ForceÍŶӹ۲쵽TA505³ÖÐøÀûÓÃSDBbot RATϰȾÆóÒµÍøÂç¡£ÔÚ2019Äê11Ô £¬X-Force IRIS¹Û²ìµ½Óй¥»÷ÕßÀûÓüÙðµÄOnehub´¹µöÓʼþ¹¥»÷Å·ÖÞµÄÆóÒµÔ±¹¤ £¬¸Ã´¹µöÓʼþÖ¼ÔÚÇÔÈ¡Active Directory£¨AD£©Êý¾Ý¼°Óû§Í´´¦ £¬²¢Ê¹ÓÃSDBbot RATϰȾÆóÒµÍøÂç»·¾³¡£Æ¾¾Ý×êÑÐÈËÔ±¶Ô¹¥»÷ÕßµÄTTP¡¢C£¦C»ù´¡ÉèÊ©ÒÔ¼°ÏÈǰ¹éÒòÓÚ¸Ã×éÖ¯µÄÌØ¶¨¶ñÒâÈí¼þµÄ·ÖÎö £¬X-Force IRISÒÔΪTA505ÊǸù¥»÷»î¶¯±³ºóµÄ¹¥»÷ÍŻ


Ô­ÎÄÁ´½Ó£º

https://securityintelligence.com/posts/ta505-continues-to-infect-networks-with-sdbbot-rat/


6.¾É½ðɽ»ú³¡¹¥»÷Õß»òΪ¶íÂÞ˹APT×éÖ¯Energetic Bear


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ESET×êÑÐÈËÔ±ÒÔΪ £¬¶Ô¾É½ðɽ¹ú¼Ê»ú³¡£¨SFO£©ÍøÕ¾µÄ¹¥»÷ÊÇÓɱ»³ÆÎªEnergetic BearµÄ¶íÂÞË¹ÍøÂç¼äµý×éÖ¯½øÐеÄ¡£¸ÃAPT×éÖ¯×Ô2010ÄêÒÔÀ´Ò»ÏòºÜ»îÔ¾ £¬ÖØÒªÕë¶ÔÄÜÔ´ºÍ¹¤ÒµÁìÓòµÄ×éÖ¯¡£SFOµÄ»ú³¡ÐÅÏ¢¼¼ÊõºÍµçÐŲ¿ÃÅ£¨ITT£©°µÊ¾¹¥»÷ÕßÔÚ»ú³¡ÍøÕ¾ÉÏÖ²ÈëÁ˶ñÒâ´úÂëÒÔÇÔÈ¡Óû§µÄµÇ¼ʹ´¦ £¬¿ÉÄÜÊܹ¥»÷Ó°ÏìµÄÓû§Ô̺¬Ê¹ÓÃWindowsÉ豸»ò·ÇSFOÊØ»¤µÄÉ豸ͨ¹ýIEä¯ÀÀÆ÷´Ó»ú³¡ÍøÂç±í²¿½Ó¼ûÕâÐ©ÍøÕ¾µÄÓû§¡£SFOµÄITÈËÔ±ÒѾ­É¾³ýÁË×¢ÈëÆäÍøÕ¾ÖеĶñÒâ´úÂë £¬²¢ÔÚ¹¥»÷²úÉúºó½«Á½Õß¶¼½øÐÐÁËÍÑ»ú´¦Öá£ÎªÏìÓ¦´ËÊÂÎñ £¬SFO»ú³¡³ÁÖÃÁËËùÓеĵç×ÓÓʼþºÍÍøÂçÃÜÂë¡£ESET³Æ¹¥»÷ÕßÀûÓÃSMBÖ°ÄܺÍfile£º//ǰ׺À´ÍøÂç½Ó¼ûÕßµÄWindowsÍ´´¦ £¬Ô̺¬Óû§ÃûºÍNTLM¹þÏ£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/101601/apt/energetic-bear-airport-hack.html