˼¿Æ°ä²¼¶àÖÖ²úÆ·µÄ°²È«¸üР£¬½¨¸´´úÂëÖ´Ðзì϶£»Ghost Squad¹¥»÷Å·ÖÞº½Ìì¾Ö(ESA) £¬ÍøÕ¾ÁÙʱÎÞ·¨½Ó¼û

°ä²¼¹¦·ò 2020-07-17

1.˼¿Æ°ä²¼¶àÖÖ²úÆ·µÄ°²È«¸üР£¬½¨¸´´úÂëÖ´Ðзì϶


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


˼¿Æ°ä²¼Á˰²È«¸üР£¬½¨¸´Ó°Ïì¶à¸ö²úÆ·µÄ·ì϶ £¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÀûÓÃÆäÖеÄijЩ·ì϶À´½ÚÔìÊÜÓ°Ïìϵͳ¡£Õâ´Î½¨¸´µÄ½ÏΪÑϳÁµÄ·ì϶Ô̺¬Ó×ÐÍÆóÒµ·À»ðǽRV110W Wireless-N VPN¾²Ì¬Ä¬ÈÏÍ´´¦·ì϶£¨CVE-2020-3330£©¡¢Ó×ÐÍÆóҵ·ÓÉÆ÷RV110W¡¢RV130¡¢RV130WºÍRV215WÖÎÀí½Ó¿ÚÔ¶³ÌºÅÁîÖ´Ðзì϶£¨CVE-2020-3323£©¡¢RV110W¡¢RV130¡¢RV130WºÍRV215W·ÓÉÆ÷Éí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2020-3144£©¡¢RV110WºÍRV215WϵÁзÓÉÆ÷ËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2020-3331£© £¬ÒÔ¼°Cisco Prime License ManagerÌØÈ¨Éý¼¶·ì϶£¨CVE-2020-3140£©¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/07/15/cisco-releases-security-updates-multiple-products


2.Ghost Squad¹¥»÷Å·ÖÞº½Ìì¾Ö(ESA) £¬ÍøÕ¾ÁÙʱÎÞ·¨½Ó¼û


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ºÚ¿Í×éÖ¯Ghost Squad Hackers¹¥»÷ÁËÅ·ÖÞº½Ìì¾Ö(ESA) £¬²¢µ¼ÖÂÆäÍøÕ¾ÁÙʱÎÞ·¨½Ó¼û¡£ÔÚÕâ´Î¹¥»÷ÖÐ £¬ºÚ¿ÍÀûÓ÷þÎñÆ÷ÖеķþÎñÆ÷¶ËÒªÇóαÔ죨SSRF£©Ô¶³Ì´úÂëÖ´Ðзì϶ £¬»ñµÃÁ˶Ôbusiness.esa.intÓòµÄ½Ó¼ûȨ²¢¶ÔÆä½øÐÐÁË·ÛËé¡£¸Ã×éÖ¯³ÉÔ±s1ege°µÊ¾ £¬ËûÃÇÊǺڿÍÖ÷ÒåÕß £¬Í¨³£»áÒò¼¤½øÖ÷ÒåµÄÔ­ÒòÌáÒé¹¥»÷ £¬¶øÕâ´Î¹¥»÷´¿ÕýÊdzöÓÚÓéÀÖÖ÷ÕÅ¡£¸Ã×éÖ¯ÔÚ½ü¼¸ÄêÒѾ­ÈëÇÖÁ˺ܶà×éÖ¯ºÍµ±¾Ö»ú¹¹ £¬Ô̺¬ÃÀ¾ü¡¢Å·ÃË¡¢»ªÊ¢¶ÙÌØÇø¡¢ÒÔÉ«Áйú·À¾ü¡¢Ó¡¶Èµ±¾ÖºÍһЩÖÐÑëÒøÐС£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/105918/hacktivism/european-space-agency-esa-site-defacement.html?utm_source=rss&utm_medium=rss&utm_campaign=european-space-agency-esa-site-defacement


3.Å·ÖÞ³öÏÖÐÂÐ͵ÄATMºÚºÐ¹¥»÷ £¬Õë¶ÔProCash 2050xe ATMÖÕ¶Ë


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ATMÔì×÷ÉÌDiebold NixdorfÖÒ¸æÒøÐÐ £¬×î½üÔÚÅ·ÖÞ·¢ÏÖÁËÒ»ÖÖÐÂÐ͵ÄATMºÚºÐ¹¥»÷ £¬ÕâÊÇÒ»ÖÖÍ·½±£¨Jackpotting£©¹¥»÷ £¬Ôâµ½¹¥»÷µÄATM »áÏñÖÐÁËÍ·½±µÄÀÏ»¢»úÒ»Ñù £¬²»ÐÝͳöÏֽ𡣴ËÐÂÐ͹¥»÷½öÕë¶ÔProCash 2050xe ATMÖÕ¶Ë £¬¹¥»÷Õßͨ¹ýUSB¶Ë¿ÚÏνӵ½É豸¡£ºÚ¿ÍÊ×ÏÈ·ÛË鲿ÃŽṹÒÔ±ã½øÈë»úеÄÚ²¿ £¬½ÓÏÂÀ´°ÎµôCMD-V4·ÖÅäÆ÷ºÍרÓõç×ÓÉ豸֮¼äµÄUSBÏß £¬»òÕßרÓõç×ÓÉ豸ºÍATM PCÖ®¼äµÄÏß £¬²¢½«ÕâÌõÏßÏνӵ½¹¥»÷ÕߵĺںÐ £¬ÒÔ·¢ËÍ·¸·¨ºÅÁĿǰ £¬¸Ã¹«Ë¾ÔÚµ÷²éºÚ¿ÍÊÇÈôºÎ»ñµÃÕâЩÁã¼þµÄ¡£    


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/diebold-nixdorf-warns-of-a-new-class-of-atm-black-box-attacks-across-europe/#ftag=RSSbaffb68


4.кóÃÅBazarÓëTrickbotÓйØ £¬Õë¶ÔµÄÖ¸±êÊÇÃÀ¹úºÍÅ·ÖÞ


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Cybereason Nocturnus×êÑÐÓ××é·¢ÏÖÁËкóÃÅBazarÓëTrickbotÓйØ £¬×Ô½ñÄê4ÔÂÒÔÀ´ £¬¸ÃºóÃÅÒѱ»ÓÃÓÚ¹¥»÷ÃÀ¹úºÍÅ·ÖÞµÄÖ¸±ê £¬³ö¸ñÊÇÒ½ÁƱ£½¡¡¢IT¡¢Ôì×÷¡¢ÎïÁ÷ºÍÓÎÀÀÐÐÒµµÄ×éÖ¯¡£ÔÚ¾àÀëÁ½¸öÔºó £¬6Ô³öÏÖÁ˸úóÃŵÄÐÂÑù±¾ £¬ÒÔ¼°¸Ä½øµÄ´úÂëºÍ½¨¸´·¨Ê½¡£¸ÃºóÃÅÓëTrickbot¼ÓÔØ·¨Ê½ÓµÓÐÀàËÆµÄ´úÂë £¬Ô̺¬Ò»ÑùµÄWinAPI¡¢×Ô½ç˵RC4ʵÏֺͷ±ËöµÄ»ìºÏ¡£¼ÓÃܵÄBazar»áÖ±½Ó¼ÓÔØµ½ÄÚ´æÖÐ £¬ÒÔ¶ã±Üɱ¶¾Èí¼þµÄ¼ì²â¡£Ä¿Ç°Òѱ»¼ì²âµ½µÄBazarÓÐÈý¸ö°æ±¾ £¬´¦ÓÚ·ÖÆçµÄ¿ª·¢½×¶Î £¬Ô̺¬ÍøÂçºÍÇÔȡϵͳÊý¾Ý¡¢ÓëÖ¸»Ó½ÚÔì(C2)³ÉÁ¢ÏνÓ £¬ÒÔ¼°Ö´ÐжàÖÖÖ°ÄÜ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/new-bazar-backdoor-linked-to-trickbot-banking-trojan-campaigns/


5.Ó¡Äṫ˾BhinnekaÔâµ½¹¥»÷ £¬Ð¹Â¶³¬¹ý100Íò¸öÕÊ»§ÐÅÏ¢


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Hackread.com·¢ÏÖ £¬Ó¡ÄáÔÚÏßÉ̳ÇBhinnekaÔâµ½¹¥»÷й¶³¬¹ý100Íò¸öÕÊ»§ÐÅÏ¢¡£¾ÝϤ £¬Õâ´ÎÊÂÎñй¶ÁËÁ½¸öSQLÎļþ £¬×ܹ²Ô̺¬Ô¼Äª1262300¸öÕÊ»§µÄ¼Í¼ÐÅÏ¢¡£Ð¹Â¶ÐÅÏ¢Ô̺¬Î¨Ò»µÄID¡¢È«Ãû¡¢µç×ÓÓʼþµØÖ·¡¢ÐÔ±ð¡¢ÁªÏµµç»°¡¢ÃÜÂë¡¢¾ßÌ嵨ַ¡¢µ®ÉúÈÕÆÚ¡¢É罻ýÌåID¡¢ÈÕÖ¾¾ßÌåÐÅÏ¢¡¢Óû§Éí·Ý£¨ÊÇÖÎÀíÔ±»¹Êǹ¤×÷ÈËÔ±£© £¬»¹¿ÉÄÜÔ̺¬Ô±¹¤¾ßÌåÐÅÏ¢¡£¾ÝϤ £¬Õâ´Î¹¥»÷²úÉúÓÚ½ñÄê1ÔÂ27ÈÕ £¬ºÚ¿Í×î³õÊÔͼͨ¹ýÀÕË÷Êê½ð»òÏúÊÛÒÔ»ñÈ¡ÀûÒæ £¬µ«²»Öª³öÓÚºÎÖÖÔ­Òò £¬ºÚ¿Í×îºó½«ÆäÃâ·Ñ¹«¿ªÔÚÁËÍøÂçÉÏ¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/indonesia-bhinneka-database-dumped-1-million-accounts/


6.Kaspersky»ã±¨ £¬4¿î°ÍÎ÷ÒøÐÐľÂíÕë¶ÔÈ«Çò½ðÈÚ»ú¹¹


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Kaspersky»ã±¨ £¬½éÉÜÁËÕë¶ÔÈ«Çò½ðÈÚ»ú¹¹µÄ4¿î°ÍÎ÷ÒøÐÐľÂí¡£ÕâЩľÂíÔ̺¬Guildma¡¢Javali¡¢MelcozºÍGrandoreiro £¬ËüÃÇÒѾ­½ø»¯³öÁ˳äÈκóÃŵÄÄÜÁ¦ £¬²¢Ñ¡È¡Á˸÷Àà»ìºÏ¼¼ÊõÀ´°µ²ØÆä¶ñÒâ»î¶¯ £¬Ê¹Æä²»±»°²È«Èí¼þ·¢ÏÖ¡£Kaspersky×êÑÐÈËÔ±½«ËüÃÇͳ³ÆÎªTetrade £¬²¢Ö¸³öÆä¿ÉÄÜÒѾö¶¨½«¹¥»÷À©´óÖÁº£±í¡£GuildmaºÍJavali¾ùѡȡ¶à½×¶Î¶ñÒâÈí¼þ²¿Êð¹ý³Ì £¬Ê¹ÓÃÍøÂç´¹µöµç×ÓÓʼþ×÷Ϊ·Ö·¢³õʼÓÐÐ§ÔØºÉµÄ»úÔì¡£MelcozÊÇ¿ªÔ´RATÔ¶³Ì½Ó¼ûPCµÄÒ»ÖÖ±äÌå £¬ÇÔÈ¡ÃÜÂëºÍ±ÈÌØ±ÒÇ®°ü¡£Grandoreiro»áʹÓÃÓòÌìÉúËã·¨£¨DGA£©°µ²Ø¹¥»÷¹ý³ÌÖÐʹÓõÄC2µØÖ· £¬²¢½«ÆäÍйÜÔÚGoogleÕ¾µãÒ³ÃæÉÏ £¬Í¨¹ýÊÜϰȾµÄÍøÕ¾ºÍGoogle Ads £¬»òÓã²æÊ½ÍøÂç´¹µö½øÐзַ¢¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/the-tetrade-brazilian-banking-malware/97779/