FireEye°ä²¼½üÊýÄê0dayÀûÓõķÖÎö»ã±¨£»£»£»£»£»COVID-19ÆÚ¼äÕë¶ÔNASAµÄ´¹µö¹¥»÷´ó·ùÉÏÉý

°ä²¼¹¦·ò 2020-04-08

1.ʯÓ͹«Ë¾BerkineÔâMaze¹¥»÷£¬£¬£¬£¬£¬£¬³¬¹ý500MBÊý¾Ý±»ÇÔ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


4ÔÂ1ÈÕʯÓ͹«Ë¾BerkineÔâµ½ÀÕË÷Èí¼þÍÅ»ïMaze¹¥»÷£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÉè·¨ÇÔÈ¡Á˸ù«Ë¾µÄÊý¾Ý¿â£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬³¬¹ý500MBµÄ»úÃÜÎĵµ¡£¡£¡£ ¡£¡£¡£ÕâЩÎĵµÓëÔ¤Ëã¡¢×éÖ¯Õ½Êõ¡¢³ö²úÁ¿µÈÃô¸ÐÊý¾ÝÓйØ¡£¡£¡£ ¡£¡£¡£BerkineÊǰ¢¶û¼°ÀûÑǹúÓÐʯÓ͹«Ë¾SonatrachºÍÃÀ¹úʯÓ͹«Ë¾Anadarko Algeria CompanyµÄºÏ»ïÆóÒµ¡£¡£¡£ ¡£¡£¡£Æ¾¾ÝUnder BreachµÄ˵·¨£¬£¬£¬£¬£¬£¬Ð¹Â¶µÄÎĵµÓëBerkineµÄ²ÆÕþϸ½ÚºÍͶ×Ê´òËãÓйØ£¬£¬£¬£¬£¬£¬Ô̺¬BerkineʯÓ͵ÄÿͰ³É±¾¼ÛÖµ¡¢2020ÄêµÄ×éÖ¯Ö¸±êÒÔ¼°·ÖÅ䏸BerkineÁ½Î»ËùÓÐÕߵĸ÷À๤×÷µÄÔ¤Ëã¡£¡£¡£ ¡£¡£¡£Êý¾Ý¿âÖл¹Ô̺¬BerkineÔ±¹¤ÁªÏµ·½Ê½¼°¹Û¹âÖ¤¼þµÄÁбí¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/maze-ransomware-group-hacks-oil-giant-leaks-data/


2.Email.itÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬60ÍòÓû§Êý¾ÝÔÚ°µÍøÏúÊÛ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



Òâ´óÀûÓʼþ·þÎñÉÌEmail.itÈ·ÈÏÔâµ½ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬Ä¿Ç°Óг¬¹ý60ÍòÓû§µÄÊý¾ÝÔÚ°µÍøÏúÊÛ¡£¡£¡£ ¡£¡£¡£ºÚ¿ÍÍÅ»ïNN£¨No Name£©Hacking GroupÐû³ÆÈëÇÖÏÖʵ²úÉúÔÚÁ½Äê¶àÒÔǰµÄ2018Äê1Ô¡£¡£¡£ ¡£¡£¡£¸ÃÍÅ»ïÔÚ2ÔÂ1ÈÕÊÔͼÀÕË÷Email.it£¬£¬£¬£¬£¬£¬µ«Email.it»Ø¾øÖ§¸¶Êê½ð²¢Í¨ÖªÁËÒâ´óÀûÓÊÕþ¾¯Ô±¾Ö£¨CNAIPIC£©¡£¡£¡£ ¡£¡£¡£ÔÚÀÕË÷ʧ°Üºó£¬£¬£¬£¬£¬£¬¸ÃÍÅ»ï´Ë¿ÌÒÔ0.5ÖÁ3±ÈÌØ±Ò£¨3500ÖÁ22000ÃÀÔª£©µÄ¼ÛÖµÏúÊÛÕâЩÊý¾Ý¡£¡£¡£ ¡£¡£¡£¸ÃÍÅ»ïÐû³ÆÕ¼ÓдÓEmail.itϵͳÖÐÇÔÈ¡µÄ46¸öÊý¾Ý¿â£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬Ãâ·ÑEmail.itµç×ÓÓʼþÕÊ»§µÄÓû§ÐÅÏ¢¡£¡£¡£ ¡£¡£¡£ºÚ¿ÍÐû³ÆÊý¾Ý¿âÖÐÔ̺¬2007ÄêÖÁ2020ÄêÖ®¼ä×¢²áºÍʹÓø÷þÎñµÄ60¶àÍòÓû§µÄÃ÷ÎÄÃÜÂë¡¢°²È«ÌáÐÑÎÊÌâ¡¢µç×ÓÓʼþÄÚÈݺ͸½¼þ£¬£¬£¬£¬£¬£¬»¹Ðû³ÆÕ¼ÓÐͨ¹ýEmail.itµÄSMS·þÎñ·¢Ë͵Ĵ¿Îı¾SMSÐÂÎÅ£¬£¬£¬£¬£¬£¬ÒÔ¼°ËùÓÐEmail.itÍøÂçÀûÓ÷¨Ê½µÄÔ´´úÂë¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/email-provider-got-hacked-data-of-600000-users-now-sold-on-the-dark-web/


3.¹È¸è°ä²¼4ÔÂAndroid°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´50¶à¸ö·ì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¹È¸è°ä²¼4ÔÂAndroid°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´50¶à¸ö·ì϶£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬ÏµÍ³×é¼þÖеÄ4¸öÑϳÁ·ì϶¡£¡£¡£ ¡£¡£¡£Õâ4¸ö·ì϶Ô̺¬CVE-2020-0070¡¢CVE-2020-0071¡¢CVE-2020-0072ºÍCVE-2020-0073£¬£¬£¬£¬£¬£¬¶¼¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬£¬£¬²¢ÇÒ¶¼Ó°ÏìAndroid 8.0¡¢8.1¡¢9ºÍ10£¬£¬£¬£¬£¬£¬Æä²¹¶¡Ô̺¬ÔÚ°²È«²¹¶¡·¨Ê½¼¶±ð2020-04-01ÖС£¡£¡£ ¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬¹È¸è»¹ÔÚ°²È«²¹¶¡·¨Ê½¼¶±ð2020-04-05Öн¨¸´ÁË43¸ö·ì϶£¬£¬£¬£¬£¬£¬Ô̺¬¿ò¼Ü×é¼þÖеÄ1¸öÐÅϢй¶·ì϶¡¢ÄÚºË×é¼þÖеÄ3¸öÌáȨ·ì϶¡¢FPC×é¼þÖеÄ1¸öÌáȨºÍ2¸öÐÅϢй¶·ì϶¡¢¸ßͨ×é¼þÖеÄ6¸ö·ì϶ÒÔ¼°¸ßͨ¹ØÔ´×é¼þÖеÄ30¸ö·ì϶¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/google-patches-critical-rce-vulnerabilities-androids-system-component


4.FireEye°ä²¼×î½üÊýÄê0dayÀûÓÃÇé¿öµÄ·ÖÎö»ã±¨


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


FireEye MandiantÍþвµý±¨ÍŶӼͼµÄ2019Äê0dayÀûÓÃÁ¿±ÈǰÈýÄêÖеÄÈκÎÒ»Äê¶¼Òª¶à¡£¡£¡£ ¡£¡£¡£Ö»¹Ü²¢²»Äܽ«Ã¿Ò»¸ö0dayÀûÓö¼¹éÒòµ½Ìض¨µÄ¹¥»÷Õߣ¬£¬£¬£¬£¬£¬µ«×êÑÐÈËÔ±°ÑÎȵ½Ô½À´Ô½¶àµÄ¹¥»÷Õß»ñµÃÁË0dayÀûÓõÄÄÜÁ¦¡£¡£¡£ ¡£¡£¡£FireEyeÒÔΪ£¬£¬£¬£¬£¬£¬ÕâÖÖ¼¤ÔöÖÁÉÙ²¿ÃÅÊÇÓÉÓÚ²»ÐÝ·¢Õ¹µÄ¹ÍÓ¶ºÚ¿ÍÐÐÒµ·¢Õ¹ÆðÀ´µÄ£¬£¬£¬£¬£¬£¬ÕâЩÐÐÒµ¿ª·¢0dayÀûÓù¤¾ß²¢½«ÆäÏúÊÛ¸øÊÀ½ç¸÷µØµÄµý±¨»ú¹¹¡£¡£¡£ ¡£¡£¡£¹¥»÷ÕßÓë0dayÀûÓÃÖ®¼äµÄ×î´ó×è°­²»ÊǼ¼Êõ£¬£¬£¬£¬£¬£¬¶øÊÇÏֽ𡣡£¡£ ¡£¡£¡£¾ßÌåÀ´Ëµ£¬£¬£¬£¬£¬£¬FireEyeÖ¸³öNSO Group¡¢Gamma GroupºÍHacking TeamÊÇÕâÀà³Ð°üÉÌ£¬£¬£¬£¬£¬£¬ÕâЩ³Ð°üÉÌʹһÅúеĹú¶È/µØÓò¿ÉÄܲɰì0dayÀûÓᣡ£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.fireeye.com/blog/threat-research/2020/04/zero-day-exploitation-demonstrates-access-to-money-not-skill.html


5.¸çÂ×±ÈÑǹٷ½COVID-19 App´æÔÚ·ì϶й¶Óû§Êý¾Ý


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ZeroFOXµÄAlphaÍŶӷ¢ÏÖ¸çÂ×±ÈÑǵ±¾ÖÕýʽºË×¼µÄCOVID-19 APPÔ̺¬·ì϶£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÓû§Êý¾Ýй¶¡£¡£¡£ ¡£¡£¡£¸ÃAPPΪCoronApp-Columbia£¬£¬£¬£¬£¬£¬ÓÃÓÚÔ®ÊÖ¸çÂ×±ÈÑÇÈË·¢Ëͽ¡È«Çé¿ö¸üв¢½Ó¹Ü¹Ú×´²¡¶¾ÐÂÎÅ¡£¡£¡£ ¡£¡£¡£¸ÃAPPÕ¼Óг¬¹ý10Íò¸öÓû§¡£¡£¡£ ¡£¡£¡£ZeroFOXÍþвµý±¨×ܼàZack Allen°µÊ¾£¬£¬£¬£¬£¬£¬CoronApp-ColumbiaÀûÓÃÒÔÃ÷ÎÄ´ó¾Ö·¢ËÍÓ×ÎÒ½¡È«ÐÅÏ¢£¨PHI£©ºÍÓ×ÎÒÉí·ÝÐÅÏ¢£¨PII£©Êý¾Ý£¬£¬£¬£¬£¬£¬ÕâÔ̺¬»¤ÕÕºÅÂë¡¢ÃÜÂëºÍ×ÔÎÒÅû¶µÄ½¡È«ÐÅÏ¢¡£¡£¡£ ¡£¡£¡£ÕâÒýÆðÁËÈËÃǶԹٷ½ºË×¼/´´½¨µÄCOVID-19 APP°²È«ÐÔµÄÓÇÓô¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/vulnerabilities-covid19-app/


6.COVID-19ÆÚ¼äÕë¶ÔNASAµÄ´¹µö¹¥»÷´ó·ùÉÏÉý


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


NASA³ÆCOVID-19ÆÚ¼äÃñ×å¹ú¶ÈºÚ¿ÍºÍÍøÂç·¸×ï·Ö×ÓÕë¶Ôº½Ìì¾ÖϵͳºÍÔڼҰ칫Ա¹¤µÄ¶ñÒâ»î¶¯ÏÔÖøÔö³¤¡£¡£¡£ ¡£¡£¡£NASA°²È«ÔËÓªÖÐÐÄ£¨SOC£©»ã±¨µÄÍøÂç´¹µö¹¥»÷´ÎÊý·­ÁËÒ»·¬£¬£¬£¬£¬£¬£¬¶ñÒâÈí¼þ¹¥»÷³ÊÖ¸Êý¼¶Ôö³¤£¬£¬£¬£¬£¬£¬±»×èÖ¹µÄ¶ñÒâÕ¾µãÊýÁ¿Ò²·­ÁËÒ»·¬¡£¡£¡£ ¡£¡£¡£ÃÀ¹úÓ¾Ö°ì¹«ÊÒÏòËùÓÐNASAÈËÔ±°ä²¼µÄ±¸Íü¼ÖгÆ£¬£¬£¬£¬£¬£¬¹ú¶ÈºÍÍøÂç×ï·¸ÔÚ»ý¼«ÀûÓÃCOVID-19µÄÊ¢ÐÐÀ´Õë¶ÔNASAµç×ÓÉ豸¡¢ÍøÂçºÍÓ×ÎÒÉ豸£¬£¬£¬£¬£¬£¬ËûÃǵÄÖ¸±êÔ̺¬½Ó¼ûÃô¸ÐÐÅÏ¢¡¢Óû§ÃûºÍÃÜÂë¡¢½øÐлؾø·þÎñ¹¥»÷¡¢É¢²¼ÐéαÐÅÏ¢ÒÔ¼°½øÐÐڲƭ¡£¡£¡£ ¡£¡£¡£NASA°²È«×¨¼Ò»¹·¢ÏÖ£¬£¬£¬£¬£¬£¬Ä³Ð©¹¥»÷²»½öÕë¶Ǫ̂ʽ»ú£¬£¬£¬£¬£¬£¬²¢ÇÒ»¹Õë¶ÔÒÆ¶¯ÏµÍ³£¬£¬£¬£¬£¬£¬ÊÔͼÓÕÆ­Êܺ¦Õßй¼ûô¸ÐÐÅÏ¢¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/nasa-under-significantly-increasing-hacking-phishing-attacks/