Î÷ÃÅ×Ó¶à¿î¹¤ÒµÉ豸ÊÜLinuxÄں˷ì϶SegmentSmackÓ°Ï죻£»£»£»£»£»£»Å·ÖÞÄÜÔ´¹«Ë¾EDPϰȾRagnarLocker

°ä²¼¹¦·ò 2020-04-16

1.Î÷ÃÅ×Ó¶à¿î¹¤ÒµÉ豸ÊÜLinuxÄں˷ì϶SegmentSmackÓ°Ïì


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Î÷ÃÅ×Ó°ä²¼4Ô²¹¶¡¸üР£¬£¬£¬ £¬£¬£¬ £¬£¬ ÆäÖÐ3Ìõв¼¸æÍ¨Öª¿Í»§Æä¶à¿î¹¤ÒµÉ豸Êܵ½LinuxÄں˷ì϶SegmentSmackÓ°Ïì¡£¡£¡£¡£¡£SegmentSmackºÍFragmentSmack£¨±ðÀë±»¸ú×ÙΪCVE-2018-5390ºÍCVE-2018-5391£©ÊÇ×êÑÐÈËJuha-Matti TilliÔÚ2018Äê·¢ÏÖµÄÁ½¸öLinuxÄں˷ì϶ £¬£¬£¬ £¬£¬£¬ £¬£¬¹¥»÷ÕßÄܹ»Í¨¹ýÏòÖ¸±êϵͳ·¢ËͶñÒâÊý¾Ý°üÀ´ÌáÒéDoS¹¥»÷¡£¡£¡£¡£¡£ÔÚµÚÒ»·Ý²¼¸æÖÐÎ÷ÃÅ×Ó³ÆSegmentSmackºÍFragmentSmackÓ°ÏìÁËËüµÄIE/PB-LinkÉ豸¡¢RUGGEDCOM·ÓÉÆ÷¡¢»ùÓÚROXµÄVPNÖն˺ͷÀ»ðǽ¡¢SCALANCE·ÓÉÆ÷ºÍ·À»ðǽ¡¢SIMATICͨѶ´¦ÖÃÆ÷ºÍSinema Remote Connect¡£¡£¡£¡£¡£µÚ¶þ·Ý²¼¸æÖÐÎ÷ÃÅ×ÓÅû¶ÓëSegmentSmackÓйصÄDoS·ì϶£¨CVE-2019-19301£© £¬£¬£¬ £¬£¬£¬ £¬£¬¸Ã·ì϶ӰÏìÁËSIMATICͨѶÄ£¿£¿£¿£¿£¿£¿£¿é¡¢SCALANCE X»¥»»»úºÍSIPLUSÉ豸¡£¡£¡£¡£¡£µÚÈý·Ý²¼¸æÔòÅû¶ÁËÓ°ÏìÎ÷ÃÅ×ÓSIDOORÃÅÖÎÀíϵͳ¡¢SIMATICÉ豸¡¢SINAMICSת»»Æ÷ºÍSIPLUS²úÆ·µÄDoS·ì϶£¨CVE-2019-19300£©¡£¡£¡£¡£¡£



Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/siemens-industrial-devices-affected-segmentsmack-linux-kernel-flaw




2.Ó¢ÌØ¶û°ä²¼4Ô°²È«¸üР£¬£¬£¬ £¬£¬£¬ £¬£¬½¨¸´¶à¿î²úÆ·ÖеÄ9¸ö·ì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ó¢ÌØ¶ûÔÚ4Ô²¹¶¡¸üÐÂÖн¨¸´ÁË9¸ö·ì϶ £¬£¬£¬ £¬£¬£¬ £¬£¬ÕâЩ·ì϶¾ùΪÖиßΣ·ì϶ £¬£¬£¬ £¬£¬£¬ £¬£¬Ó°Ïì¶à¸öÈí¼þ¡¢¹Ì¼þ¼°Æ½Ì¨¡£¡£¡£¡£¡£Ó¢Ìضû½¨¸´ÁËPROSet/ÎÞÏßWiFi²úÆ·ÔÚWindows 10ÉϵÄÁ½¸ö·ì϶-¾­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÓÉÓÚ²»°²È«µÄ¼Ì³ÐȨÏÞ¶ø¿ÉÄÜͨ¹ý±¾µØ½Ó¼û½øÐÐÌØÈ¨Éý¼¶£¨CVE-2020-0557£©£»£»£»£»£»£»£»ÓÉÓÚÄÚºËÇý¶¯·¨Ê½ÖеĻº³åÇøÏ޶Ȳ»µ± £¬£¬£¬ £¬£¬£¬ £¬£¬ÎÞÌØÈ¨µÄ¹¥»÷Õß¿ÉÄÜͨ¹ýÏàÁÚÍøÂç½Ó¼ûÀ´µ¼Ö»ؾø·þÎñ£¨CVE-2020-0558£©¡£¡£¡£¡£¡£Ó¢Ìضû»¹½¨¸´ÁËNUC mini PCµÄϵͳ¹Ì¼þÖкÍÄ£¿£¿£¿£¿£¿£¿£¿é»¯·þÎñÆ÷MFS2600KISPPÍÆËãÄ£¿£¿£¿£¿£¿£¿£¿éÖеÄÁ½¸ö·ì϶ £¬£¬£¬ £¬£¬£¬ £¬£¬Ô̺¬²»ÕýÈ·µÄ»º³åÇøÏ޶ȵ¼ÖµÄLPE·ì϶£¨CVE-2020-0600£©ºÍǰÌá²é³­²»µ±µ¼ÖµÄÌáȨ·ì϶£¨CVE-2020-0578£©¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/intel-april-platform-update-fixes-high-severity-security-issues/


3.΢Èí°ä²¼4ÔÂOffice°²È«¸üР£¬£¬£¬ £¬£¬£¬ £¬£¬½¨¸´55¸ö·ì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


΢ÈíÔÚ4ÔÂOffice°²È«¸üÐÂÖÐÕë¶Ô7¸ö²úÆ·½¨¸´ÁË55¸ö·ì϶ £¬£¬£¬ £¬£¬£¬ £¬£¬ÆäÖÐÔ̺¬Ó°ÏìÁËMicrosoft OfficeºÍMicrosoft Office SharePoint²úÆ·µÄ12¸öRCE·ì϶ £¬£¬£¬ £¬£¬£¬ £¬£¬ÕâЩ·ì϶¾ù±»¹éÀàΪÑϳÁ»ò³ÁÒª¼¶±ð £¬£¬£¬ £¬£¬£¬ £¬£¬¹¥»÷ÕßÄܹ»ÀûÓÃËüÃÇÔÚSharePointÀûÓ÷¨Ê½ºÍSharePoint·þÎñÆ÷ÕÊ»§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£Î¢Èí»¹½¨¸´ÁË10¸öXSS·ì϶ £¬£¬£¬ £¬£¬£¬ £¬£¬¹¥»÷Õß¿ÉÄÜÀûÓÃÕâЩ·ì϶ÔÚµ±Ç°Óû§µÄ°²È«¸ßµÍÎÄÖÐÔËÐо籾²¢¼ÙðÓû§¡¢ÇÔÈ¡Ãô¸ÐÊý¾Ý»òδ¾­ÊÚȨÔĶÁÄÚÈÝ¡£¡£¡£¡£¡£´Ë±í £¬£¬£¬ £¬£¬£¬ £¬£¬Î¢Èí½¨¸´ÁËÁ½¸öÌáȨ·ì϶ºÍËĸöºýŪ·ì϶¡£¡£¡£¡£¡£¾ßÌå·ì϶ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-office-april-security-updates-fix-critical-rce-bugs/


4.Å·ÖÞÄÜÔ´¹«Ë¾EDPϰȾRagnarLocker £¬£¬£¬ £¬£¬£¬ £¬£¬±»ÀÕË÷½ü1000ÍòÅ·Ôª


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


½üÈÕÆÏÌÑÑÀ¿ç¹úÄÜÔ´¾ÞÍ·Energias de Portugal£¨EDP£©Ôâµ½ÀÕË÷Èí¼þRagnarLocker¹¥»÷ £¬£¬£¬ £¬£¬£¬ £¬£¬±»ÀÕË÷1580 BTCµÄÊê½ð£¨Ô¼ºÏ1090ÍòÃÀÔª»ò990ÍòÅ·Ôª£©¡£¡£¡£¡£¡£EDP¼¯ÍÅÊÇÅ·ÖÞÄÜÔ´ÐÐÒµ£¨ÌìÈ»ÆøºÍµçÁ¦£©×î´óµÄÔËÓªÉÌÖ®Ò» £¬£¬£¬ £¬£¬£¬ £¬£¬Ò²ÊÇÊÀ½çµÚËÄ´ó·çÄܳö²úÉÌ¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚÈ«ÇòËĸö´óÖÞµÄ19¸ö¹ú¶È/µØÓòÕ¼ÓÐÒµÎñ £¬£¬£¬ £¬£¬£¬ £¬£¬²¢ÇÒÕ¼Óг¬¹ý11500ÃûÔ±¹¤ºÍΪ³¬¹ý1100Íò¿Í»§ÌṩÄÜÔ´¡£¡£¡£¡£¡£ÔÚ¹¥»÷¹ý³ÌÖÐ £¬£¬£¬ £¬£¬£¬ £¬£¬Ragnar Locker¹¥»÷ÍÅ»ïÐû³ÆÇÔÈ¡Á˳¬¹ý10 TBµÄ¹«Ë¾Ãô¸ÐÎļþ £¬£¬£¬ £¬£¬£¬ £¬£¬²¢Íþв³ÆÈôÊǸù«Ë¾»Ø¾øÖ§¸¶Êê½ð £¬£¬£¬ £¬£¬£¬ £¬£¬ËûÃǽ«°ä²¼µÁÈ¡µÄËùº±¼û¾Ý¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ragnarlocker-ransomware-hits-edp-energy-giant-asks-for-10m/


5.TA505³ÖÐøÀûÓÃSDBbot RATϰȾÆóÒµÍøÂç £¬£¬£¬ £¬£¬£¬ £¬£¬ÖØÒªÕë¶ÔÅ·ÖÞ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


IBM X-ForceÍŶӹ۲쵽TA505³ÖÐøÀûÓÃSDBbot RATϰȾÆóÒµÍøÂç¡£¡£¡£¡£¡£ÔÚ2019Äê11Ô £¬£¬£¬ £¬£¬£¬ £¬£¬X-Force IRIS¹Û²ìµ½Óй¥»÷ÕßÀûÓüÙðµÄOnehub´¹µöÓʼþ¹¥»÷Å·ÖÞµÄÆóÒµÔ±¹¤ £¬£¬£¬ £¬£¬£¬ £¬£¬¸Ã´¹µöÓʼþÖ¼ÔÚÇÔÈ¡Active Directory£¨AD£©Êý¾Ý¼°Óû§Í´´¦ £¬£¬£¬ £¬£¬£¬ £¬£¬²¢Ê¹ÓÃSDBbot RATϰȾÆóÒµÍøÂç»·¾³¡£¡£¡£¡£¡£Æ¾¾Ý×êÑÐÈËÔ±¶Ô¹¥»÷ÕßµÄTTP¡¢C£¦C»ù´¡ÉèÊ©ÒÔ¼°ÏÈǰ¹éÒòÓÚ¸Ã×éÖ¯µÄÌØ¶¨¶ñÒâÈí¼þµÄ·ÖÎö £¬£¬£¬ £¬£¬£¬ £¬£¬X-Force IRISÒÔΪTA505ÊǸù¥»÷»î¶¯±³ºóµÄ¹¥»÷ÍŻ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityintelligence.com/posts/ta505-continues-to-infect-networks-with-sdbbot-rat/


6.¾É½ðɽ»ú³¡¹¥»÷Õß»òΪ¶íÂÞ˹APT×éÖ¯Energetic Bear


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ESET×êÑÐÈËÔ±ÒÔΪ £¬£¬£¬ £¬£¬£¬ £¬£¬¶Ô¾É½ðɽ¹ú¼Ê»ú³¡£¡£¡£¡£¡£¨SFO£©ÍøÕ¾µÄ¹¥»÷ÊÇÓɱ»³ÆÎªEnergetic BearµÄ¶íÂÞË¹ÍøÂç¼äµý×éÖ¯½øÐеÄ¡£¡£¡£¡£¡£¸ÃAPT×éÖ¯×Ô2010ÄêÒÔÀ´Ò»ÏòºÜ»îÔ¾ £¬£¬£¬ £¬£¬£¬ £¬£¬ÖØÒªÕë¶ÔÄÜÔ´ºÍ¹¤ÒµÁìÓòµÄ×éÖ¯¡£¡£¡£¡£¡£SFOµÄ»ú³¡ÐÅÏ¢¼¼ÊõºÍµçÐŲ¿ÃÅ£¨ITT£©°µÊ¾¹¥»÷ÕßÔÚ»ú³¡ÍøÕ¾ÉÏÖ²ÈëÁ˶ñÒâ´úÂëÒÔÇÔÈ¡Óû§µÄµÇ¼ʹ´¦ £¬£¬£¬ £¬£¬£¬ £¬£¬¿ÉÄÜÊܹ¥»÷Ó°ÏìµÄÓû§Ô̺¬Ê¹ÓÃWindowsÉ豸»ò·ÇSFOÊØ»¤µÄÉ豸ͨ¹ýIEä¯ÀÀÆ÷´Ó»ú³¡ÍøÂç±í²¿½Ó¼ûÕâÐ©ÍøÕ¾µÄÓû§¡£¡£¡£¡£¡£SFOµÄITÈËÔ±ÒѾ­É¾³ýÁË×¢ÈëÆäÍøÕ¾ÖеĶñÒâ´úÂë £¬£¬£¬ £¬£¬£¬ £¬£¬²¢ÔÚ¹¥»÷²úÉúºó½«Á½Õß¶¼½øÐÐÁËÍÑ»ú´¦Öᣡ£¡£¡£¡£ÎªÏìÓ¦´ËÊÂÎñ £¬£¬£¬ £¬£¬£¬ £¬£¬SFO»ú³¡³ÁÖÃÁËËùÓеĵç×ÓÓʼþºÍÍøÂçÃÜÂë¡£¡£¡£¡£¡£ESET³Æ¹¥»÷ÕßÀûÓÃSMBÖ°ÄܺÍfile£º//ǰ׺À´ÍøÂç½Ó¼ûÕßµÄWindowsÍ´´¦ £¬£¬£¬ £¬£¬£¬ £¬£¬Ô̺¬Óû§ÃûºÍNTLM¹þÏ£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/101601/apt/energetic-bear-airport-hack.html