MITRE°ä²¼ºÏÓÃÓÚ¹¤Òµ½ÚÔìϵͳµÄATT£¦CK¿ò¼Ü;Firefox 0day·ì϶(CVE-2019-11707)

°ä²¼¹¦·ò 2020-01-09


1.MITRE°ä²¼ºÏÓÃÓÚ¹¤Òµ½ÚÔìϵͳµÄATT£¦CK¿ò¼Ü


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


±¾ÖܶþMITER°ä²¼ÁËÆäATT£¦CK¿ò¼ÜµÄ³õʼ°æ±¾£¬£¬£¬£¬ £¬£¬¸Ã°æ±¾³Áµã¹Ø×¢ÁËÕë¶Ô¹¤Òµ½ÚÔìϵͳ£¨ICS£©µÄ¶ñÒâ¹¥»÷ÕßʹÓõÄÕ½ÊõºÍ¼¼Êõ¡£¡£¡£¡£¡£Ö¼ÔÚÔ®Êֹؼü»ù´¡ÉèÊ©ºÍÆäËûʹÓÃICSµÄ×éÖ¯ÆÀ¹ÀÆäÍøÂç·çÏÕ¡£¡£¡£¡£¡£³ýÁËÌṩ¹¥»÷Õ½ÊõºÍ¼¼Êõ¾ØÕó±í£¬£¬£¬£¬ £¬£¬»¹½éÉÜÁ˹¥»÷¼¼ÊõµÄϸ½Ú¡¢¹¥»÷ÕßʹÓõĶñÒâÈí¼þÒÔ¼°ÒÑÖªµÄÕë¶ÔICSµÄ·¸×ïÍŻ¡£¡£¡£¡£Ëü»¹Ô̺¬Ò»¸ö×ʲúÀà±ð£¬£¬£¬£¬ £¬£¬ÓÃÓÚÔ®ÊÖ×éÖ¯Ïàʶ¿ÉÀûÓÃÓÚÆä»·¾³µÄ¼¼Êõ¡£¡£¡£¡£¡£´Ë°æ±¾ÃèÊöÁË81ÖÖ¹¥»÷¼¼Êõ¡¢17ÖÖ¶ñÒâÈí¼þ¡¢10¸ö·¸×ïÍÅ»ïºÍ7ÖÖ×ʲú¡£¡£¡£¡£¡£


  Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/mitre-releases-attck-knowledge-base-industrial-control-systems


2.Ã÷ÄáËÕ´ïÖÝAlomere HealthҽԺй¶½ü5Íò»¼ÕßÐÅÏ¢


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ã÷ÄáËÕ´ïÖÝAlomere HealthÒ½ÔºµÄÁ½ÃûÔ±¹¤µç×ÓÓÊÏäÕË»§ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬ £¬£¬µ¼ÖÂ49351Ãû»¼ÕßµÄÓ×ÎÒºÍÒ½ÁÆÐÅϢй¶¡£¡£¡£¡£¡£¸ÃÒ½ÔºµÄµ÷²éÏÔʾ£¬£¬£¬£¬ £¬£¬ÆäÖÐÒ»ÃûÔ±¹¤µÄÓÊÏäÕË»§ÔÚ2019Äê10ÔÂ31ÈÕÖÁ11ÔÂ1ÈÕÆÚ¼äÔâµ½ÖÁÉÙÒ»¸öµÚÈý·½µÄδÊÚȨ½Ó¼û£¬£¬£¬£¬ £¬£¬ÁíÒ»ÃûÔ±¹¤µÄÓÊÏäÕË»§ÔÚ11ÔÂ6ÈÕ±»µÁ¡£¡£¡£¡£¡£µ÷²éÎÞ·¨È·¶¨¹¥»÷ÕßÊÇ·ñÏÖʵ²é¿´ÁËÓÊÏäÖеÄÓʼþ»ò¸½¼þ£¬£¬£¬£¬ £¬£¬µ«¹¥»÷Õß¿ÉÄÜ»ñµÃµÄÐÅÏ¢Ô̺¬»¼ÕßµÄÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚÒÔ¼°¼Í¼ID¡¢Ò½ÁƱ£ÏÕÐÅÏ¢¡¢Ò½ÖÎÐÅÏ¢¡¢Õï¶ÏÐÅÏ¢µÈÒ½ÁÆÐÅÏ¢¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬ £¬£¬²¿ÃÅ»¼ÕßµÄÉç»á°²È«ºÅÂëºÍ¼ÝÕÕID¿ÉÄÜй¶¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/medical-info-of-roughly-50k-exposed-in-minnesota-hospital-breach/


3.APT×éÖ¯Lazarus¹¥»÷»î¶¯AppleJeusºóÐø·ÖÎö»ã±¨


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¿¨°Í˹»ù°ä²¼¹ØÓÚ³¯ÏÊLazarus APTµÄAppleJeusºóÐø¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£ÎªÁ˹¥»÷macOSÓû§£¬£¬£¬£¬ £¬£¬LazarusÀûÓù«¿ªµÄÔ´´úÂ루ÀýÈçCentrabit¿ª·¢µÄQtBitcoinTrader£©¿ª·¢ÁË×Ô¼ºµÄmacOS¶ñÒâÈí¼þ£¬£¬£¬£¬ £¬£¬²¢Ôö³¤ÁËÒ»ÖÖÉí·ÝÑéÖ¤»úÔì½»¸¶ÏÂÒ»½×¶Îpayload£¬£¬£¬£¬ £¬£¬ÉõÖÁ¿É½øÐÐÎÞÎļþ¼ÓÔØ¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬ £¬£¬ÎªÁ˹¥»÷WindowsÓû§£¬£¬£¬£¬ £¬£¬Lazarus¿ª·¢Á˶à½×¶ÎϰȾ·¨Ê½£¬£¬£¬£¬ £¬£¬²¢ÏÔÖø¸Ä½øÁË×îÖÕÓÐЧ¸ºÔØ¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÔڸúóÐø¹¥»÷»î¶¯ÖÐÈ·ÈÏÁ˶àÃûÊܺ¦Õߣ¬£¬£¬£¬ £¬£¬Ô̺¬Ó¢¹ú¡¢²¨À¼¡¢¶íÂÞ˹ºÍÖйúµÄ×éÖ¯¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬ £¬£¬×êÑÐÈËÔ±¿ÉÄÜÈ·ÈÏһЩÊܺ¦ÕßÓë¼ÓÃÜÇ®±ÒÒµÎñÓйØ¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://securelist.com/operation-applejeus-sequel/95596/


4.BitdefenderÅû¶»ùÓÚGo˵»°µÄ½©Ê¬ÍøÂçLiquorBot


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Bitdefender×êÑÐÈËÔ±ÓÚ2019Äê5ÔÂ31ÈÕ³õ´Î¹Û²ìµ½ÍÚ¿ó½©Ê¬ÍøÂçLiquorBot£¬£¬£¬£¬ £¬£¬¸Ã½©Ê¬ÍøÂçÊÇÓÉGolang£¨Go£©±àдµÄ£¬£¬£¬£¬ £¬£¬ÖÁ10ÔÂ10ÈÕËüÔø¾­ÀúÁË11¸ö¸üа汾¡£¡£¡£¡£¡£LiquorBotµÄÖ÷ÌâÊdzôÃûÔ¶ÑïµÄMiraiµÄ³ÁÐÂʵÏÖ£¬£¬£¬£¬ £¬£¬µ«ËüÓµÓмÓÃÜÇ®±ÒÍÚ¾òÖ°Äܶø²»ÊÇDDoS×é¼þ¡£¡£¡£¡£¡£LiquorBotÕë¶ÔARM¡¢ARM64¡¢x86¡¢x64ºÍMIPS¼Ü¹¹½øÐн»²æ±àÒ룬£¬£¬£¬ £¬£¬²¢ÇÒͨ¹ýÓëCPU¼Ü¹¹Î޹صÄdropper¾ç±¾ÏÂÔØËùÓÐÓÐЧ¸ºÔØ¡£¡£¡£¡£¡£LiquorBotÓµÓжà¸öºÅÁîºÍ½ÚÔ죨C2£©·þÎñÆ÷£¬£¬£¬£¬ £¬£¬Ô̺¬wpceservice.hldns.ru¡¢ardp.hldns.ruºÍbpsuck.hldns.ru¡£¡£¡£¡£¡£LiquorBotÖØÒªÒÀÀµÓÚSSH±©Á¦¹¥»÷½øÐÐÈëÇÖ£¬£¬£¬£¬ £¬£¬²¢ÇÒ¿ÉÀûÓÃd-Link¡¢Íø¼þ¡¢LinksysµÈ·ÓÉÆ÷ÖеÄ佨²¹·ì϶¹¥»÷É豸¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/go-based-liquorbot-adapts-cryptomining-payload-to-infected-host/


5.΢Èí½¨¸´AccessÖеÄÐÅϢй¶·ì϶£¨CVE-2019-1463£©


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


µç×ÓÓʼþ°²È«¹«Ë¾Mimecastй©£¬£¬£¬£¬ £¬£¬Microsoft AccessÖеÄÐÅϢй¶·ì϶¿ÉÄܵ¼ÖÂϵͳÄÚ´æÖеÄÃô¸ÐÊý¾Ý±»ÎÞÒâÖб£ÁôÔÚÊý¾Ý¿âÎļþÖС£¡£¡£¡£¡£¸Ã·ì϶£¨CVE-2019-1463£©±»³ÆÎªMDB Leaker£¬£¬£¬£¬ £¬£¬Óë¡°ÀûÓ÷¨Ê½¶ÔϵͳÄÚ´æµÄ²»µ±ÖÎÀí¡±ÓйØ£¬£¬£¬£¬ £¬£¬Ëü¿ÉÄܵ¼ÖÂδ³õʼ»¯µÄÄÚ´æÔªËصÄÄÚÈݱ£Áôµ½Microsoft Access MDBÎļþÖС£¡£¡£¡£¡£Ö»¹ÜÕâЩÊý¾Ý¿ÉÄܺÁÎÞÓô¦£¬£¬£¬£¬ £¬£¬µ«ËüÒ²¿ÉÄÜÔ̺¬¸ß¶ÈÃô¸ÐµÄÐÅÏ¢£¬£¬£¬£¬ £¬£¬ÀýÈçÃÜÂë¡¢WebÒªÇó¡¢Ö¤ÊéÒÔ¼°Óò»òÓû§Êý¾Ý¡£¡£¡£¡£¡£Mimecast°µÊ¾Ä¿Ç°²»»á°ä²¼ÓйØCVE-2019-1463µÄÈκμ¼ÊõÐÅÏ¢£¬£¬£¬£¬ £¬£¬Ò²Ã»ÓÐÖ¤¾ÝÅú×¢¸Ã·ì϶ÒÑÔÚÒ°±í±»ÀûÓᣡ£¡£¡£¡£Î¢ÈíÒÑÔÚ2019Äê12ÔµIJ¹¶¡¸üÐÂÖн¨¸´Á˸÷ì϶£¬£¬£¬£¬ £¬£¬Æ¾¾Ý΢ÈíµÄ˵·¨£¬£¬£¬£¬ £¬£¬¸Ã·ì϶»áÓ°ÏìOffice 2010¡¢2013¡¢2016¡¢2019ºÍ365 ProPlus¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/microsoft-access-files-could-include-unintentionally-saved-sensitive-data


6.Mozilla°ä²¼¸üÐÂ,½¨¸´Firefox 0day·ì϶(CVE-2019-11707)


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Mozilla°ä²¼ÁËFirefox 72.0.1ºÍFirefox ESR 68.4.1£¬£¬£¬£¬ £¬£¬½¨¸´ÒÑÔÚÒ°±í±»»ý¼«ÀûÓõÄ0day£¨CVE-2019-11707£©¡£¡£¡£¡£¡£¸Ã·ì϶±»¹éÀàΪÀàÐÍ»ìºÏ·ì϶£¬£¬£¬£¬ £¬£¬Ó°ÏìÁËIonMonkey JIT±àÒëÆ÷£¬£¬£¬£¬ £¬£¬Æ¾¾ÝMozillaµÄ°²È«²¼¸æ£¬£¬£¬£¬ £¬£¬IonMonkey JIT±àÒëÆ÷ÖÐÓÃÓÚÉèÖÃÊý×éÔªËØµÄ±ðºÅÐÅÏ¢²»ÕýÈ·£¬£¬£¬£¬ £¬£¬¿ÉÄܻᵼÖÂÀàÐÍ»ìºÏ¡£¡£¡£¡£¡£Ç±ÔÚ¹¥»÷Õß¿Éͨ¹ý½«Óû§³Á¶¨ÏòÖÁ¶ñÒâÍøÒ³À´´¥·¢¸Ã·ì϶£¬£¬£¬£¬ £¬£¬µ¼Ö´úÂëÖ´Ðлò´¥·¢±ÀÀ£¡£¡£¡£¡£¡£ÃÀ¹úCISAÒ²·¢³öÖÒ¸æ³Æ¹¥»÷Õß¿ÉÄÜÀûÓô˷ì϶À´½ÚÔìÊÜÓ°ÏìµÄϵͳ£¬£¬£¬£¬ £¬£¬²¢½¨ÒéÓû§²é¿´Mozilla°²È«´«µÝºÍÀûÓð²È«¸üС£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/mozilla-firefox-7201-patches-actively-exploited-zero-day/