¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190214

°ä²¼¹¦·ò 2019-02-14
1¡¢Linux Snapd´æÔÚDirty_Sock·ì϶ £¬£¬£¬£¬£¬£¬£¬£¬¿É»ñÈ¡rootȨÏÞ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

°²È«×êÑÐÔ±Chris Moberly·¢ÏÖCanonical snapdÊØ»¤¹ý³ÌµÄREST APIÖдæÔÚзì϶Dirty_Sock £¬£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶¿ÉÔÊÐí¹¥»÷ÕßÔÚLinuxϵͳÉÏ»ñµÃrootȨÏÞ¡£¡£¡£¡£¡£¸Ã·ì϶»áÓ°Ïìµ½ÈκÎʹÓÃsnapdµÄLinuxϵͳ £¬£¬£¬£¬£¬£¬£¬£¬µ«·ì϶ÀûÓÿÉÄÜ»áÓÐËù·ÖÆç¡£¡£¡£¡£¡£CanonicalÒÑÔÚа汾Snapd 2.37.1Öн¨¸´ÁË´Ë·ì϶ £¬£¬£¬£¬£¬£¬£¬£¬½¨ÒéÖÎÀíÔ±¾¡¿ì×°ÖøüС£¡£¡£¡£¡£

  

 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/canonical-snapd-vulnerability-gives-root-access-in-linux/

2¡¢Adobe°ä²¼2Ô°²È«¸üР£¬£¬£¬£¬£¬£¬£¬£¬½¨¸´44¸ö¸ßΣ·ì϶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

Adobe°ä²¼2Ô°²È«¸üР£¬£¬£¬£¬£¬£¬£¬£¬¹²½¨¸´44¸ö¸ßΣ·ì϶¡£¡£¡£¡£¡£½ÏΪÑϳÁµÄ·ì϶Ô̺¬Flash PlayerÖеÄÔ½½ç¶Á·ì϶£¨CVE-2019-7090 £¬£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÐÅϢй¶£©¡¢ColdFusionÖеķ´ÐòÁл¯·ì϶£¨CVE-2019-7091 £¬£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐУ©ºÍxss·ì϶£¨CVE-2019-7092 £¬£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÐÅϢй¶£©ÒÔ¼°Cloud DesktopÖеÄDLL½Ù³Ö·ì϶£¨CVE-2019-7093 £¬£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÌáȨ£©¡£¡£¡£¡£¡£½¨ÒéÓû§¾¡¿ì¸üС£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/adobes-massive-patch-update-fixes-critical-acrobat-reader-bugs/

3¡¢×êÑÐÈËÔ±ÑÝʾÈôºÎÔÚIntel SGXÖÐÖ²Èë¶ñÒâÈí¼þ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

×êÑÐÈËÔ±ÑÝʾÈôºÎÔÚIntel SGXÖаµ²Ø¶ñÒâ´úÂë¡£¡£¡£¡£¡£Intel SGXÊÇSkylake´¦ÖÃÆ÷ÖÐÒýÈëµÄÐÂÖ°ÄÜ £¬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚ±£»£»£»£»£»¤Èí¼þµÄ´úÂëºÍÓйØÊý¾Ý £¬£¬£¬£¬£¬£¬£¬£¬È·±£Æä»úÃÜÐÔºÍÆëÈ«ÐÔ¡£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾ËûÃǵÄPoCÀûÓÃÁËTSXºÍASLRµÈ £¬£¬£¬£¬£¬£¬£¬£¬²¢Ö¸³öÆëÈ«µÄ·ì϶ÀûÓùý³ÌºÄʱ20.8Ãë¡£¡£¡£¡£¡£Õë¶Ô´ËÀ๥»÷µÄ»º½â´ëÊ©¿ÉÄÜÔÚ½«À´¼¸´úÓ¢ÌØ¶ûCPUÖÐÖ´ÐС£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/02/intel-sgx-malware-hacking.html

4¡¢AstarothľÂíбäÌå £¬£¬£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶Ô°ÍÎ÷ºÍÅ·ÖÞ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

CybereasonµÄNocturnus×êÑÐÍŶӷ¢ÏÖAstarothľÂíµÄбäÌå £¬£¬£¬£¬£¬£¬£¬£¬¸Ã±äÌåÖØÒªÕë¶Ô°ÍÎ÷ºÍÅ·ÖÞ £¬£¬£¬£¬£¬£¬£¬£¬²¢Í¨¹ýÀ¬»øÓʼþ·Ö·¢¡£¡£¡£¡£¡£Æäpayload»áÌìÉú¶ñÒâµÄwmic.exe¹ý³Ì £¬£¬£¬£¬£¬£¬£¬£¬²¢ÏòC2·þÎñÆ÷·¢ËÍÖ¸±êÍÆËã»úµÄÓйØÐÅÏ¢¡£¡£¡£¡£¡£¸ÃľÂí»¹»áÔÚAvast·À²¡¶¾Èí¼þµÄaswrundll.exeÔËÐÐʱDLLÖÐ×¢Èë¶ñÒâÄ£¿£¿ £¿£¿£¿£¿£¿é £¬£¬£¬£¬£¬£¬£¬£¬²¢ÀûÓÃËüÀ´ÍøÂçϵͳÐÅÏ¢ºÍ¼ÓÔØ¶î±íµÄÄ£¿£¿ £¿£¿£¿£¿£¿é¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-astaroth-trojan-variant-exploits-anti-malware-software-to-steal-info/

5¡¢ÒøÐÐľÂíTrickBotбäÌå £¬£¬£¬£¬£¬£¬£¬£¬¿ÉÇÔÈ¡RDP¡¢VNCºÍPuTTYÍ´´¦

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

Ç÷Ïò¿Æ¼¼µÄ×êÑÐÈËÔ±·¢ÏÖÒøÐÐľÂíTrickbotµÄÒ»¸öбäÌå £¬£¬£¬£¬£¬£¬£¬£¬¸Ã±äÌåΪÃÜÂëÇÔȡģ¿£¿ £¿£¿£¿£¿£¿éÐÂÔöÁËÈý¸öÖ°ÄÜ £¬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚÇÔÈ¡Óû§µÄRDP¡¢VNCºÍPuTTYÍ´´¦¡£¡£¡£¡£¡£¸Ã±äÌåÊÇ»ùÓÚ2018Äê11Ôµİ汾 £¬£¬£¬£¬£¬£¬£¬£¬Í¨¹ýÒÔ˰ÊÕ¼¤ÀøÍ¨ÖªÎªÖ÷ÌâµÄÀ¬»øÓʼþ½øÐд«²¼ £¬£¬£¬£¬£¬£¬£¬£¬Æä¶ñÒ⸽¼þΪXLSMÌåʽµÄexcelÎļþ¡£¡£¡£¡£¡£TrickBot×Ô2016Äê10Ô³öÏÖÒÔÀ´ £¬£¬£¬£¬£¬£¬£¬£¬Ò»ÏòÔÚ²»ÐݽøÐиüС£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/trickbot-banking-trojan-now-steals-rdp-vnc-and-putty-credentials/

6¡¢AZORultľÂíй¥»÷»î¶¯ £¬£¬£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÒâ´óÀû

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

Cybaze-Yori ZLAB·¢ÏÖAZORultľÂíµÄй¥»÷»î¶¯ £¬£¬£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÒâ´óÀû¡£¡£¡£¡£¡£¸ÃľÂíбäÌåͨ¹ý¼Ù×°³ÉDHL¿ìµÝ֪ͨµÄÓʼþ½øÐд«²¼ £¬£¬£¬£¬£¬£¬£¬£¬µ±Óû§´ò¿ª¶ñÒâµÄѹËõÎĵµ¸½¼þºó £¬£¬£¬£¬£¬£¬£¬£¬¾Í»áÏÂÔØ²¢ÔËÐиÃľÂí¡£¡£¡£¡£¡£¸ÃľÂíÄܹ»ÇÔÈ¡Webä¯ÀÀÆ÷ÒÔ¼°Óʼþ¿Í»§¶ËÖб£ÁôµÄÕË»§ºÍÍ´´¦ £¬£¬£¬£¬£¬£¬£¬£¬²¢Äܹ»×°ÖÃÆäËüµÄpayload¡£¡£¡£¡£¡£ÆäC2·þÎñÆ÷Ϊgoogodsgld[.]comºÍdriverconnectsearch[.]info¡£¡£¡£¡£¡£¸Ã±äÌåµÄÐÐΪÀàËÆÓÚBrushloader¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/specially-crafted-dhl-express-courier-emails-leveraged-to-distribute-a-variant-of-azorult-trojan-f9ea2931


ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù