ĦÂå¸çµ±¾ÖÓÃNSO Group¼äµýÈí¼þ¼à¶½¸Ã¹ú¼ÇÕß;ºÚ¿ÍÓÃGoogle AnalyticsÈÆ¹ýCSPÇÔÊØÐÅÓþ¿¨ÐÅÏ¢

°ä²¼¹¦·ò 2020-06-24

1.ĦÂå¸çµ±¾Ö»òÔÚÀûÓÃNSO GroupµÄ¼äµýÈí¼þ¼à¶½¸Ã¹ú¼ÇÕß


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¹ú¼ÊÌØÉâ×éÖ¯°µÊ¾£¬Æä°²È«ÍŶÓÔÚĦÂå¸ç¼ÇÕßµÄÊÖ»úÉÏ·¢ÏÖÁËNSO Group¿ª·¢µÄ¼äµýÈí¼þ£¬´ËÊ»òÓë¸Ã¹úµ±¾ÖÓйØ ¡£Ä¦Âå¸ç¼ÇÕßOmar RadiÔâµ½¼à¶½Èí¼þµÄ¹¥»÷£¬¸ÃÈí¼þ¿ÉÄܸú×ÙÎı¾¡¢µç»°¡¢µç×ÓÓʼþ¡¢ÉãÏñ»úµÈ ¡£ºÚ¿Íͨ¹ýÍøÂç×¢Èë¹¥»÷ÒÔÀ¹½ØºÍ²Ù¼«Ö¸±êµÄ»¥ÁªÍøÁ÷Á¿£¬¸Ã²½Öè²»±ØÒªÓëÊܺ¦Õß½»»¥£¬Ö»Ð轫ָ±êä¯ÀÀÆ÷³ÁзÓɵ½Ò»¸ö¶ñÒâÍøÕ¾ ¡£¹ú¼ÊÌØÉâ×éÖ¯°µÊ¾£¬¹¥»÷ÕßÉí·ÝËäδµÃµ½È·ÈÏ£¬µ«¸÷ÖÖÖ¤¾ÝÅú×¢¼à¶½ÕßΪĦÂå¸çµ±¾Ö£¬ÓÉÓÚNSO¼¯ÍÅÒ»ÔÙ°µÊ¾¸ÃÈí¼þ½ö±»ÏúÊÛ¸øÁ˵±¾Ö ¡£


Ô­ÎÄÁ´½Ó£º

https://www.cyberscoop.com/nso-group-spyware-amnesty-international-omar-radi-morocco/


2.ºÚ¿ÍʹÓÃGoogle AnalyticsÆ½Ì¨ÈÆ¹ýCSPÇÔÊØÐÅÓþ¿¨ÐÅÏ¢


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ºÚ¿ÍÔÚʹÓÃGoogle AnalyticsÆ½Ì¨ÈÆ¹ýÄÚÈݰ²È«Õþ²ß£¨CSP£©£¬À´ÇÔÈ¡ÔÚÏßÉ̵êÓû§Ìá½»µÄÐÅÓþ¿¨ÐÅÏ¢ ¡£ÍøÂ簲ȫ¹«Ë¾SansecºÍPerimeterXµÄ×îÐÂ×êÑÐÅú×¢£¬ÔÚ²¿ÊðÁËGoogle AnalyticsµÄÍøÕ¾ÉÏ£¬Ê¹ÓÃCSPÔ¤·ÀÐÅÓþ¿¨ÇÔÈ¡¹¥»÷ÒѾ­ºÁÎÞÒâ˼ ¡£ÓÉÓÚCSPÖ÷ÌâÖ°ÄÜÖдæÔÚ·ì϶£¬Ëü²»ÄÜ×èÖ¹»ùÓÚ×¢ÈëµÄ¹¥»÷£¬Òò¶øºÚ¿ÍÄܹ»Í¨¹ýÒ»¸öweb skimmer½ÅÕý±¾ÇÔÈ¡Êý¾Ý²¢½«ÆäÒÔ¼ÓÃܵĴó¾Ö·¢Ëͻع¥»÷Õß ¡£SansecµÄÍþв×êÑÐÓ××éй©£¬¹¥»÷ÕßÀûÓÃGoogle AnalyticsÒѾ­³É¹¦ÈƹýÊýÊ®¸öµç×ÓÉÌÎñÍøÕ¾ÉϵÄCSP ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hackers-use-google-analytics-to-steal-credit-cards-bypass-csp/


3.ºÚ¿ÍÔÚ°µÍøÏúÊÛÊ¢ÐÐÓÎÏ·StalkerÖг¬¹ý130ÍòÍæ¼ÒÐÅÏ¢


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


°²È«×êÑÐÈËÔ±·¢ÏÖ£¬ºÚ¿ÍÔÚ°µÍøÏúÊÛÁËÊ¢ÐÐÓÎÏ·StalkerÖг¬¹ý130ÍòÍæ¼ÒÐÅÏ¢£¬Ð¹Â¶ÐÅÏ¢Ô̺¬Óû§Ãû¡¢ÃÜÂë¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂëºÍIPµØÖ· ¡£Õâ´ÎÏúÊ۵Ĺ²ÓÐÁ½¸öÊý¾Ý¿â£¬±ðÀëΪ120Íò±Ê¼Í¼ºÍ136000±Ê¼Í¼ ¡£¸Ã¹«Ë¾°µÊ¾£¬Óû§µÄÃÜÂëÊǾ­¹ýMD5¼ÓÃܺͼÓÑδ¦ÖõÄ£¬Õâ¹ÌÈ»Êǰ²È«ÐԽϵ͵ÄËã·¨µ«±ÈÒÔ´¿Îı¾´ó¾Ö±£ÁôÃÜÂë¸üºÃ ¡£Ä¿Ç°£¬¸Ã¹«Ë¾ÒÑÓëºÚ¿ÍÔÚÏßÉ̵êµÄµç×ÓÉÌÎñƽ̨ÁªÏµ£¬´Ë¿ÌÒÑÍÑ»ú ¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/stalker-online-breach-13-m-user/


4.°ÄÖÞACCC°ä²¼»ã±¨£¬¸Ã¹úÈ¥ÄêÓг¬¹ý2.5ÍòÆð´¹µö¹¥»÷ÊÂÎñ


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


°Ä´óÀûÑÇACCCÏÂÊôµÄScamwatch°ä²¼ÁËScamwatch Targeting scams£º×Ô2009ÄêÒÔÀ´¶Ôڲƭ»î¶¯µÄ»ØÊ׻㱨£¬Í³¼Æ2019Äê¸Ã¹ú²úÉúÁ˳¬¹ý2.5ÍòÆð´¹µö¹¥»÷ÊÂÎñ ¡£ÔÚ2019Äê£¬ÍøÂç´¹µöÊÇ×î³£¼ûµÄڲƭ¼¿Á©£¬×ܹ²»ã±¨ÁËÓÐ25168ÆðÊÂÎñ£¬ÔÚËù»ã±¨ÖÐÓÐ513ÆðÔì³ÉÁ˲ÆÕþËðʧ£¬×ܼÆ150Íò°ÄÔª ¡£¶øÔì³ÉËðʧ×î´óµÄ¹¥»÷ÀàÐÍΪÆóÒµµç×ÓÓʼþй¶£¨BEC£©Ú¿Æ­£¬Ëðʧ1.32ÒÚ°ÄÔª£¬Æä´ÎΪÔì³ÉÁË1.26ÒÚ°ÄÔªËðʧµÄͶ×ÊÚ¿Æ­ºÍ8300Íò°ÄÔªµÄÔ¼»áÚ¿Æ­ ¡£¶øÚ¿Æ­µÄÖØÒªõè¾¶ÒÀȻΪµç»°£¨69522Æð£©£¬Æä´ÎÊǵç×ÓÓʼþ£¨40277Æð£©£¬¶ÌÐÅ£¨27894Æð£©ºÍ»¥ÁªÍø£¨11776Æð£© ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/australians-reported-25000-phishing-scams-to-the-accc-last-year/


5.Apache Dubbo·´ÐòÁл¯Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-1948£©


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

2020Äê6ÔÂ23ÈÕApache¹Ù·½°ä²¼¹«¸æ£¬½¨¸´ÁËÒ»¸öApache DubboÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-1948£© ¡£¸Ã·ì϶ԴÓÚApache Dubbo Provider´æÔÚ·´ÐòÁл¯·ì϶£¬¹¥»÷ÕßÄܹ»·¢ËÍ´øÓÐÎÞ·¨Ê¶´ËÍâ·þÎñÃû»ò²½ÖèÃû¼°Ä³Ð©¶ñÒâ²ÎÊý¸ºÔصÄRPCÒªÇ󣬵±¶ñÒâ²ÎÊý±»·´ÐòÁл¯Ê±½«µ¼Ö¶ñÒâ´úÂëÖ´ÐÐ ¡£¸Ã·ì϶ӰÏìÁËËùÓÐʹÓÃ2.7.6»ò¸üµÍ°æ±¾µÄDubboÓû§ ¡£


Ô­ÎÄÁ´½Ó£º

https://github.com/apache/dubbo/releases/tag/dubbo-2.7.7


6.ÀÕË÷Èí¼þREvilɨÃèÊܺ¦ÕßϵͳÖеÄPoSÒÔѰеĻñÀû·½Ê½


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


SymantecÍþвµý±¨ÍŶӵÄ×êÑÐÈËÔ±·¢ÏÖºÚ¿ÍÔÚеÄÀÕË÷»î¶¯ÖÐʹÓÃREvilɨÃèÊܺ¦ÕßϵͳÖеÄÐÅÓþ¿¨»òPoint of Sale£¨PoS£©Êý¾Ý£¬»òÔÚѰÕÒеĻñÀû·½Ê½ ¡£µý±¨·ÖÎöʦJon DiMaggio°µÊ¾£¬ÈôÊÇËûÃÇɨÃèµ½ÁËPoSϵͳ£¬±ãÄܹ»×°ÖÃPOS¶ñÒâɨÃèÈí¼þÇÔÊØÐÅÓþ¿¨¾ßÌåÐÅÏ¢ ¡£Symantec·ÖÎö·£¬²¿ÃÅÊܺ¦¹«Ë¾¹æÄ£½ÏÓ×£¬ÎÞ·¨Ö§¸¶Êê½ð£¬Òò¶ø¸ÃºÚ¿ÍÍÅ»ïɨÃèPoSϵͳÖеÄÐÅÓþ¿¨Êý¾Ý¿ÉÄÜÊÇΪÁËÊý¾Ý͵ÇÔ£¬»òÖ»ÊÇΪÁËʹ¼ÓÃܵÄÊý¾Ý¸üÓмÛÖµÒÔÒªÇóÊܺ¦ÕßÖ§¸¶Êê½ð ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/revil-ransomware-scans-victims-network-for-point-of-sale-systems/