Intel 471°ä²¼°µÍøÖÐ25ÖÖÖØÒªRaaS²úÆ·µÄ·ÖÎö»ã±¨ £»Firefox°ä²¼°²È«¸üР£¬½¨¸´0day²¢ÐÂÔö½öHTTPSģʽ

°ä²¼¹¦·ò 2020-11-18

1.Intel 471°ä²¼°µÍøÖÐ25ÖÖÖØÒªRaaS²úÆ·µÄ·ÖÎö»ã±¨


1.jpg


Intel 471°ä²¼ÁËÓйذµÍøÖеÄ25ÖÖÖØÒªRaaS²úÆ·µÄ·ÖÎö»ã±¨  ¡£Intel 471°µÊ¾ £¬Ëüƾ¾ÝRaaSµÄ¸´ÔÓˮƽ¡¢Ö°Äܺͺ¹ÇཫÕâЩÀÕË÷Èí¼þ·ÖΪÈý¸öµµ´Î  ¡£µÚÒ»²ãΪµ±½ñ×î³ÛÃûµÄÀÕË÷Èí¼þ £¬Ô̺¬REvil¡¢Netwalker¡¢DopplePaymer¡¢Egregor£¨Maze£©ºÍRyuk  ¡£µÚ¶þ²ãΪÀÕË÷Èí¼þÊÀ½çµÄÐÂÐË´ú±í £¬Ô̺¬Avaddon¡¢Conti¡¢Clop¡¢DarkSide¡¢Mespinoza£¨Pysa£©¡¢RagnarLocker¡¢Ranzy£¨Ako£©¡¢SunCryptºÍThanos  ¡£µÚÈý²ãΪа䲼µÄRaaS²úÆ· £¬Ô̺¬CVartek.u45¡¢Exorcist¡¢Gothmog¡¢Lolkek¡¢Muchlove¡¢Nemty¡¢Rush¡¢Wally¡¢Xinof¡¢ZeoticusºÍZagreuS  ¡£


Ô­ÎÄÁ´½Ó£º

https://public.intel471.com/blog/ransomware-as-a-service-2020-ryuk-maze-revil-egregor-doppelpaymer/


2.Firefox°ä²¼°²È«¸üР£¬½¨¸´0day²¢ÐÂÔö½öHTTPSģʽ


2.jpg


Mozilla°ä²¼Firefox°²È«¸üР£¬½¨¸´0day²¢ÐÂÔö½öHTTPSģʽ  ¡£½öHTTPSÖ°ÄÜ¿É×Ô¶¯Åú¸ÄURL £¬µ±Óû§ÆôÓÃÁ˸Ãģʽʱ £¬Firefox»á½«Óû§½Ó¼ûµÄËùÓÐhttp£º// URL³ÁдΪÆä°²È«µÄhttps£º// £¬ÈôÊÇÎÞ·¨Ïνӵ½°²È«URL £¬Ëü½«ÏÔʾ°²È«ÏνӲ»³ÉÓõÄÃýÎóÖÒ¸æ  ¡£´Ë±í £¬Õâ´Î°²È«¸üл¹½¨¸´ÁË21¸ö·ì϶ £¬ÆäÖÐÔ̺¬FreetypeµÄ0day  ¡£¸Ã·ì϶ÓÉGoogle Project ZeroÅû¶ £¬¿ÉÓÃÓÚÕë¶ÔGoogle ChromeµÄ×Ô¶¯¹¥»÷  ¡£µ«ÆäÓ°ÏìÁËËùÓÐʹÓÃFreetypeµÄÈí¼þ £¬Ô̺¬Mozilla Firefox  ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/software/firefox-83-boosts-security-with-https-only-mode-zero-day-fix/


3.Citrix SD-WAN´æÔÚ¶à¸ö·ì϶ £¬¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ


3.jpg


Citrix SD-WAN´æÔÚ¶à¸ö·ì϶ £¬¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐкÍϵͳÊÕÊÜ  ¡£µÚÒ»¸ö·ì϶Ϊstop_pingÖÐδ¾­ÑéÖ¤µÄõè¾¶±éÀúºÍshell×¢Èë·ì϶£¨CVE-2020¨C8271£© £¬¿Éʹδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß»ñµÃrootȨÏÞ  ¡£µÚ¶þ¸ö·ì϶ΪConfigEditorÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2020¨C8272£© £¬ÓëCakePHP½«URIת»»Îª¶Ëµãº¯Êý²ÎÊýÓйØ  ¡£µÚÈý¸ö·ì϶ΪCreateAzureDeploymentÖеÄShell×¢Èë·ì϶£¨CVE-2020¨C8273£©  ¡£×êÑÐÈËÔ±°µÊ¾ £¬¹¥»÷Õß½áºÏʹÓÃÕâÈý¸ö·ì϶¿É³É¹¦ÊÕÊÜÏµÍ³ÍøÂç  ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/citrix-sd-wan-bugs-remote-code-execution/161274/


4.×êÑÐÈËÔ±³ÆÈÔÓнü25Íò¸öϵͳÈÔÒ×ÊÜBlueKeep RDP¹¥»÷


4.jpg


΢ÈíÅû¶ÁËÓ°ÏìWindows RDP·þÎñµÄBlueKeep·ì϶һÄê°ëÖ®ºó £¬ÒÀÈ»Óг¬¹ý245000¸öWindowsϵͳÒ×Êܵ½´ËÀ๥»÷  ¡£SANS ISC×êÑÐÈËÔ±³Æ £¬Ö»¹Ü¸Ã·ì϶¼«¶ÈÑϳÁ £¬²¢ÇÒ¹ú¶Èµ±¾ÖÒ²ÂŴΰ䲼¸üÐÂÖÒ¸æ £¬µ«ÈÔÓÐ25£¥Ò×ϰȾϵͳÒòδ֪ԭÒòδ½øÐиüР ¡£Í¬ÑùµØ £¬³¬¹ý103000¸öWindowsϵͳҲÈÔÈÝÒ×Êܵ½SMBGhostµÄ¹¥»÷  ¡£SMBGhostÊÇServer Message Block v3£¨SMB£©ºÍ̸Öеķì϶ £¬ÓëBlueKeepÒ»Ñù¶¼¿Éʹ¹¥»÷ÕßÔ¶³Ì½ÚÔìWindowsϵͳ  ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/more-than-245000-windows-systems-still-remain-vulnerable-to-bluekeep-rdp-bug/


5.ij¹«¿ªµÄÊý¾Ý¿âй¶10Íò¶à¸öFacebookÓû§µÄÐÅÏ¢


5.jpg


vpnMentorµÄ×êÑÐÈËÔ±·¢ÏÖÁËÒ»¸öÔÚÏß¹«¿ªµÄElasticSearchÊý¾Ý¿â £¬ÆäÖÐÔ̺¬³¬¹ý100000¸öFacebookÓû§µÄÐÅÏ¢  ¡£¸ÃÊý¾Ý¿âµÄÈÝÁ¿³¬¹ý5.5 GB £¬×ܹ²Ô̺¬13521774¸öÎļþ £¬ÓÚ½ñÄê6ÔÂÖÁ9Ô¼äά³ÖÊ¢¿ª×´Ì¬  ¡£Õâ´Îй¶µÄÐÅÏ¢Ô̺¬À¨µç×ÓÓʼþ¡¢ÐÕÃûºÍµç»°ºÅÂë £¬»¹Ô̺¬ÓйØÍøÂç·¸×ï·Ö×ÓÈôºÎ×Ô¶¯Ö´Ðй¥»÷Á÷³ÌµÄ¼¼ÊõÐÅÏ¢  ¡£vpnMentorÖ¸³ö¸ÃÊý¾Ý¿â¿ÉÄÜÊôÓÚµÚÈý·½ £¬Æäͨ¹ýÕë¶ÔFacebookÓû§µÄ´¹µöÍøÕ¾·¸·¨»ñµÃµÄÕË»§µÇ¼ʹ´¦  ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/111018/cyber-crime/100k-facebook-accounts-scam.html


6.AmericoldÔâµ½ÍøÂç¹¥»÷ £¬Æä¶à¸öϵͳÊܵ½Ó°Ïì


6.jpg


Àä¿â¹«Ë¾AmericoldÔâµ½ÍøÂç¹¥»÷ £¬Ô̺¬µç»°ÏµÍ³¡¢µç×ÓÓʼþ¡¢¿â´æÖÎÀíºÍ¶©µ¥ÏµÍ³ÔÚÄڵĶà¸öϵͳÊܵ½Ó°Ïì  ¡£AmericoldÊÇÒ»¼Òµ±ÏȵÄοزֿâÔËÓªÉÌ £¬ÎªÁãÊÛÉÌ¡¢Ê³Æ··þÎñÌṩÉ̺ͳö²úÉÌÌṩ¹©¸øÁ´·þÎñºÍ¿â´æÖÎÀí £¬AmericoldÔÚÈ«ÇòÕ¼ÓÐ183¸ö²Ö¿â  ¡£11ÔÂ16ÈÕ £¬AmericoldÈ·¶¨ÆäÔâµ½¹¥»÷ £¬²¢Á¢¼´²ÉÈ¡ÁËÏìÓ¦´ëÊ© £¬¹Ø¹ØÍÆËã»úϵͳÒÔÔ¤·À¹¥»÷ÊæÕ¹  ¡£¾ÝºÜ¶àÐÂÎÅÆðÔ´³Æ £¬ÕâÊÇÒ»ÖÖÀÕË÷Èí¼þ¹¥»÷ £¬µ«Ä¿Ç°Éв»Ïàʶ¹¥»÷ÏêÇé  ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/cold-storage-giant-americold-hit-by-cyberattack-services-impacted/