2024ÄêÈ«ÇòÊý¾Ýй¶³É±¾Ô¤¼Æ½«´ï5ÍòÒÚÃÀÔª£»£»£»£»£»£»£»£»¹¥»÷ÕßÀûÓÃOrcusºÍRevenge RATÕë¶Ôµ±¾ÖºÍ½ðÈÚ»ú¹¹
°ä²¼¹¦·ò 2019-08-30
1.2024ÄêÈ«ÇòÊý¾Ýй¶³É±¾Ô¤¼Æ½«´ï5ÍòÒÚÃÀÔª
ƾ¾ÝÕ°²©ÍøÂçµÄ×îÐÂÔ¤²â£¬£¬£¬£¬£¬Ëæ×żà¹Ü·£¿£¿£¿£¿£¿£¿£¿îµÄÖ´ÐÐÒÔ¼°ÆóÒµÔ½·¢ÒÀÀµÓÚÊý×Öϵͳ£¬£¬£¬£¬£¬µ½2024ÄêÈ«ÇòÊý¾Ýй¶µÄ³É±¾Ô¤¼Æ½«Ôö³¤µ½5ÍòÒÚÃÀÔªÒÔÉÏ¡£¡£¡£¡£¡£¡£¡£¡£ÕâÒ»Êý¾ÝÀ´×ÔÓڸù«Ë¾°ä²¼µÄ×îл㱨¡¶ÍøÂç·¸×ïºÍ°²È«µÄ½«À´£º2019-2024Íþв·ÖÎö¡¢Ó°ÏìÆÀ¹À»ººÍ½âÕ½Êõ»ã±¨¡·¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ðû³Æ£¬£¬£¬£¬£¬Ôڻ㱨ÆÚ¼äÄÚÔ¤¼ÆÊý¾Ýй¶³É±¾½«´Ó2019ÄêµÄ3ÍòÒÚÃÀԪÿÄêÔö³¤11%¡£¡£¡£¡£¡£¡£¡£¡£»ã±¨Öл¹³Æ¹ÌÈ»´ó¹æÄ£µÄÊý¾Ýй¶¿ÉÄܳÉΪͷÌõÐÂÎÅ£¬£¬£¬£¬£¬µ«ËüÃDz¢²»Ô¸¶¨»áÖ±½ÓÓ°Ïì³É±¾£¬£¬£¬£¬£¬ÓÉÓÚ·£¿£¿£¿£¿£¿£¿£¿îºÍÒµÎñËðʧÓëÊý¾Ýй¶µÄ¹æÄ£²¢²»çÇÃÜÓйء£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/breach-costs-trillion/
2.Google PlayÖÐÁ½¸ö¸æ°×ÀûÓÃÏÂÔØÁ¿³¬150Íò´Î
×êÑÐÈËÔ±ÔÚGoogle PlayÖз¢ÏÖÁ½¸ö¸æ°×ÀûÓ㬣¬£¬£¬£¬×ÜÏÂÔØÁ¿³¬¹ý150Íò´Î¡£¡£¡£¡£¡£¡£¡£¡£µÚÒ»¸öAPPÊÇOCRÎı¾É¨ÃèÒÇ£¬£¬£¬£¬£¬Æä×°ÖÃÊýÁ¿³¬¹ý100Íò£¬£¬£¬£¬£¬ÁíÒ»¸öÊÇÒ»¸ö½¡ÉíAPP£¬£¬£¬£¬£¬×°ÖÃÊýÁ¿³¬¹ý50Íò¡£¡£¡£¡£¡£¡£¡£¡£ËüÃÇÊôÓÚͳһ¿ª·¢ÕßIdea Master¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¸æ°×Èí¼þÀûÓÃAndroid Notification Manager·¢³öÐÂÎÅ£¬£¬£¬£¬£¬µ±Óû§µ¥»÷ÐÂÎÅʱ»á´¥·¢ÏÔʾ´øÓиæ°×µÄ°µ²ØÊÓͼ¡£¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿ª·¢ÕßÀûÓÃToast֪ͨ¼ÓÔØ¸æ°×£¬£¬£¬£¬£¬²¢Í¨¹ý½«Toast¶ÔÏó¶¨Î»ÔÚÆÁÄ»µÄ¿ÉÊÓÇøÓòÖ®±í£¬£¬£¬£¬£¬Ê¹µÃ¸æ°×¶ÔÓû§²»Ë½¼û¡£¡£¡£¡£¡£¡£¡£¡£¹ÌÈ»Óû§ÎÞ·¨¿´µ½¸æ°×£¬£¬£¬£¬£¬µ«ËûÃǵÄÂÄÀú»áÊܵ½Ó°Ï죬£¬£¬£¬£¬Ô̺¬É豸»úÄܽµÂä¡¢µçÁ¿¿÷ËðÒÔ¼°ÍøÂçÁ÷Á¿µÄʹÓÃÔö³¤¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/ghost-clicks-boost-ad-revenue-for-android-apps-with-15m-installs/
3.¹¥»÷ÕßÀûÓÃOrcusºÍRevenge RATÕë¶Ôµ±¾ÖºÍ½ðÈÚ»ú¹¹
˼¿ÆTalos×êÑÐÈËÔ±·¢ÏÖ¹¥»÷ÕßÔÚÀûÓÃRevenge RATºÍOrcus RATÕë¶Ôµ±¾Ö»ú¹¹¡¢½ðÈÚ·þÎñÆóÒµ¡¢ÐÅÏ¢¼¼Êõ·þÎñ¹©¸øÉ̺ÍÕ÷ѯ¹«Ë¾µÈ¡£¡£¡£¡£¡£¡£¡£¡£Revenge RATÊÇ2016ÄêÔÚDev PointºÚ¿ÍÂÛ̳ÉϹ«¿ª°ä²¼µÄRAT£¬£¬£¬£¬£¬ËüÄܹ»´ò¿ªÔ¶³Ìshell£¬£¬£¬£¬£¬ÔÊÐí¹¥»÷ÕßÖÎÀíϵͳÎļþ¡¢¹ý³Ì¡¢×¢²á±íºÍ·þÎñ¡¢¼Í¼°´¼ü¡¢ÍøÂçÃÜÂëÒÔ¼°½Ó¼ûÉãÏñÓŵȡ£¡£¡£¡£¡£¡£¡£¡£Orcus×Ô2016ËêÊ×ÒÔÀ´±»Ðû´«ÎªÔ¶³ÌÖÎÀí¹¤¾ß£¬£¬£¬£¬£¬µ«¼øÓÚËü»¹ÓµÓÐÔ¶¿ØÄ¾ÂíÖ°ÄÜ£¬£¬£¬£¬£¬´Ë¿ÌËüÒ²±»ÒÔΪÊÇÒ»ÖÖ¿ÉÄܼÓÔØ×Ô½ç˵²å¼þµÄ¶ñÒ⹤¾ß¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ¹¥»÷»î¶¯µÄÔËÓªÕßʹÓö¯Ì¬ÓòÃûϵͳ£¨DDNS£©À´°µ²ØËûÃǵÄC2·þÎñÆ÷£¬£¬£¬£¬£¬Ë¼¿ÆTalosÔڻ㱨ÖоßÌåÁгöÁ˶ñÒâÑù±¾¹þÏ£¡¢¹¥»÷ÓòÃûÒÔ¼°IPµØÖ·µÈ¹¥»÷Ö¸±ê£¨IOC£©¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/attackers-target-govt-and-financial-orgs-with-orcus-revenge-rats/
4.×êÑÐÈËÔ±ÔÚ¶à¸öWordPress²å¼þÖз¢ÏÖ9¸öSQL×¢Èë·ì϶
FortinetÔÚ9¸öÊ¢ÐеÄWordPress²å¼þÖз¢ÏÖ9¸öSQL×¢Èë·ì϶¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ²å¼þµÄÁìÓòº¸Ç¸æ°×¡¢¾èÔù¡¢Í¼¿â¡¢±í¸ñ¡¢ÐÂÎÅͨѶºÍÊÓÆµ²¥·ÅÆ÷µÈ£¬£¬£¬£¬£¬ÊýÒÔÊ®Íò¼ÆµÄWordPressÍøÕ¾ÔÚ»ý¼«Ê¹ÓÃÕâЩ²å¼þ£¬£¬£¬£¬£¬ÆäÖÐÒ»Ð©ÍøÕ¾ÔÚÆäÏàÓ¦µÄÀà±ðÖÐÅÅÃûµÚÒ»¡£¡£¡£¡£¡£¡£¡£¡£ËùÓÐ9¸ö·ì϶¶¼±»·ÖÅäÁËCVE±êʶ£¬£¬£¬£¬£¬²¢ÇÒ±»FortiGuardÆÀΪÑϳÁ¼¶±ðºÍ»ñµÃÁËCVSSÆÀ·Ö9.0·Ö¡£¡£¡£¡£¡£¡£¡£¡£Õâ9¸ö·ì϶ÖÐÓÐ8¸ö·ì϶ʹÓÃÁËÒ»ÑùµÄµ¥Ò»´úÂëģʽ¡£¡£¡£¡£¡£¡£¡£¡£¸÷²å¼þ¹©¸øÉ̶¼ÒѾ°ä²¼Á˽¨¸´²¹¶¡ºÍ¸üС£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.fortinet.com/blog/threat-research/wordpress-plugin-sql-injection-vulnerability.html
5.Check Point½¨¸´Endpoint SecurityÖеÄÌáȨ·ì϶
Check Point½¨¸´ÆäEndpoint Security¿Í»§¶ËÈí¼þÖеÄÌáȨ·ì϶£¬£¬£¬£¬£¬¸Ã·ì϶£¨CVE-2019-8461£©ÔÊÐíDZÔڵĹ¥»÷ÕßÌáÉýÆäȨÏÞÖÁSYSTEM²¢Ö´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£¡£SafeBreach Labs°²È«×êÑÐÔ±Peleg Hadar·¢ÏÖÁ˸ÃÎÊÌ⣬£¬£¬£¬£¬¼´¿Éͨ¹ý½«ËÁÒâδÊðÃûµÄDLL¼ÓÔØµ½Check Point Endpoint SecurityÈí¼þʹÓõÄWindows·þÎñÖ®Ò»À´ÊµÏÖȨÏÞÌáÉýºÍÓÆ¾ÃÐÔ¡£¡£¡£¡£¡£¡£¡£¡£Check PointÔÚ8ÔÂ27ÈÕ°ä²¼°æ±¾¸üн¨¸´ÁË´Ë·ì϶¡£¡£¡£¡£¡£¡£¡£¡£ÕâÊÇHadarÔÚ8Ô·ÝÏò°²È«³§É̻㱨µÄµÚÈý¸ö±¾µØÌáȨ·ì϶£¬£¬£¬£¬£¬Ç°Á½¸öÊÇÇ÷Ïò¿Æ¼¼¼°BitdefenderÖеÄÀàËÆ·ì϶£¨CVE-2019-14684ºÍCVE-2019-15295£©¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/check-point-patches-privilege-escalation-flaw-in-endpoint-client/
6.ÃÀ¹úÊý°Ù¼ÒÑÀ¿ÆÕïËùÔâÀÕË÷Èí¼þSodinokibi¹¥»÷
8ÔÂ26ÈÕÃÀ¹úÊý°Ù¼ÒÑÀ¿ÆÕïËùÔâÀÕË÷Èí¼þSodinokibi¹¥»÷£¬£¬£¬£¬£¬»¼ÕßÐÅÏ¢±»¼ÓÃÜ¡£¡£¡£¡£¡£¡£¡£¡£ÕâÊǹ¥»÷Õßͨ¹ýÈëÇÖÈí¼þ¹©¸øÉ̲¢ÀûÓÃÆä²úÆ·ÔÚ¿Í»§ÏµÍ³ÉÏÖ²ÈëÀÕË÷Èí¼þµÄÁíÒ»¸ö°¸Àý¡£¡£¡£¡£¡£¡£¡£¡£ÔÚ±¾ÆðÊÂÎñÖУ¬£¬£¬£¬£¬Èí¼þ¹©¸øÉÌÊÇThe Digital Dental RecordºÍPerCSoft£¬£¬£¬£¬£¬ËûÃǺÏ×÷¿ª·¢ÁËÒ½ÁƼͼ±£ÁôºÍ±¸·ÝÈí¼þDDS Safe¡£¡£¡£¡£¡£¡£¡£¡£ÉÏÖÜÄ©ºÚ¿ÍÍÅ»ïÈëÇÖÁ˸ÃÈí¼þ±³ºóµÄ»ù´¡ÉèÊ©£¬£¬£¬£¬£¬²¢ÀûÓÃËüÔÚÊý°Ù¸öÑÀÒ½ÕïËùµÄÍÆËã»úÉϲ¿ÊðÁËÀÕË÷Èí¼þSodinokibi¡£¡£¡£¡£¡£¡£¡£¡£ÕâÁ½¼Ò¹«Ë¾Ñ¡ÔñÖ§¸¶Êê½ð»ñÈ¡½âÃÜÆ÷£¬£¬£¬£¬£¬µ«Ä¿Ç°¸´Ô½ø¶È»ºÂý£¬£¬£¬£¬£¬Ò»Ð©ÑÀ¿ÆÕïËùÐû³Æ½âÃÜÆ÷Ҫô²»Æð×÷Ó㬣¬£¬£¬£¬ÒªÃ´Ã»Óи´ÔËùº±¼û¾Ý¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/ransomware-hits-hundreds-of-dentist-offices-in-the-us/


¾©¹«Íø°²±¸11010802024551ºÅ