×êÑÐÈËÔ±Åû¶Microsoft WindowsÖÐ5¸ö0day£»£»£»£»£»£»£»£»ºÚ¿ÍÔÚ°µÍøÏúÊÛWishboneÖÐ4000ÍòÌõÓû§ÐÅÏ¢

°ä²¼¹¦·ò 2020-05-22

1.×êÑÐÈËÔ±Åû¶Microsoft WindowsÖÐ5¸ö0day£¬£¬£¬£¬£¬Ä¿Ç°ÉÐ佨¸´

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

Trend Micro°²È«×¨¼ÒÅû¶ÁËMicrosoft WindowsÖÐ5¸öÉÐ佨¸´µÄ0day£¬£¬£¬£¬£¬ÖØÒªÓ°ÏìÁËÓû§Ä£Ê½´òÓ¡»úÇý¶¯·¨Ê½µÄ¹ý³Ìsplwow64.exe¡£¡£¡£¡£¡£ÆäÖÐÈý¸ö·ì϶½ÏΪÑϳÁ£¬£¬£¬£¬£¬±»¸ú×ÙΪCVE-2020-0916¡¢CVE-2020-0986ºÍCVE-2020-0915£¬£¬£¬£¬£¬ÕâЩ·ì϶¿ÉÄܱ»ºÚ¿ÍÓÃÀ´ÌáȨ£¬£¬£¬£¬£¬CVSSÆÀ·ÖΪ7.0¡£¡£¡£¡£¡£µÚËĸöÊÇÓÉÓÚ¶Ìȱ¶ÔÓû§µÄÖµµÄÑéÖ¤µ¼ÖµĽϵͷçÏÕµÄÐÅϢй¶·ì϶£¬£¬£¬£¬£¬×îºóÒ»¸ö0dayÊÇ´¦ÖÃWLANÏνÓÅäÖÃÎļþʱµÄÌØÈ¨ÌáÉý·ì϶¡£¡£¡£¡£¡£Trend MicroÓÚ2019Äê12ÔÂÏòMicrosoft»ã±¨ÁËÕâЩ·ì϶£¬£¬£¬£¬£¬µ«Î¢Èí²¢Î´ÔÚ2020Äê5ÔµIJ¹¶¡Öн¨¸´ÕâЩÎÊÌâ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/103507/hacking/microsoft-windows-zero-days.html


2.ÈÕ±¾ÒÉ»óÈýÁ⹫˾Ôâµ½ÍøÂç¹¥»÷£¬£¬£¬£¬£¬»ò½«µ¼Öµ¼µ¯Êý¾Ýй¶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÈÕ±¾¹ÙÔ±ÖÜÈý°µÊ¾ÆäÔÚµ÷²é¿ÉÄÜ´æÔÚµÄÊý¾Ýй©ÊÂÎñ£¬£¬£¬£¬£¬Ô̺¬ÈýÁâµç»ú¹«Ë¾Ôâµ½ÁË´ó¹æÄ£ÍøÂç¹¥»÷¿ÉÄÜй¶ÁËÔ­Ð͵¼µ¯¾ßÌåÐÅÏ¢¡£¡£¡£¡£¡£¾ÝÈÕ±¾Ã½Ì屨·£¬£¬£¬£¬£¬ÈÕ±¾¹ú·À²¿ÒÉ»óÕâЩÐÅÏ¢¿ÉÄÜÊÇ´Ó¼¸¼Ò¹ú·ÀÉ豸Ôì×÷ÉÌ·¢Ë͵ÄÕбêÎļþÖÐй¶µÄ£¬£¬£¬£¬£¬µ«ÊÇÈýÁⲢδÖбê¡£¡£¡£¡£¡£¶øÈýÁâÔÚÉêÃ÷ÖаµÊ¾£¬£¬£¬£¬£¬ËüÒÑÏò¹ú·À²¿»ã±¨Á˽ñÄêËêÊ×Ôâµ½ÍøÂç¹¥»÷¿ÉÄܵ¼ÖÂÓйØÐÅϢй¶µÄÇé¿ö£¬£¬£¬£¬£¬²¢ÈÏ¿ÉÆäԼĪ8000È˵ÄÓ×ÎÒÊý¾Ý¿ÉÄÜÒѾ­Ð¹Â¶¡£¡£¡£¡£¡£½ñÄ꣬£¬£¬£¬£¬ÈÕ±¾ÆäËû¼¸¼Ò¹ú·À³Ð°üÉÌÒ²Ôâµ½ÁËÍøÂç¹¥»÷£¬£¬£¬£¬£¬Ô̺¬NEC Corp.£¬£¬£¬£¬£¬Pasco Corp.ºÍKobe Steel Ltd.¡£¡£¡£¡£¡£ÄÚ¸ó¹Ù·¿³¤Suga»Ø¾ø¶Ô´ËÊÂй©¸ü¶àϸ½Ú¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.seattletimes.com/business/japan-suspects-missile-data-leak-in-mitsubishi-cyberattack/


3.ºÚ¿ÍµÁÈ¡WishboneÖÐ4000ÍòÌõÓû§ÐÅÏ¢£¬£¬£¬£¬£¬²¢ÔÚ°µÍø±ê¼ÛÏúÊÛ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ºÚ¿ÍÇÔÈ¡ÁËWishboneÖÐ4000ÍòÌõÓû§ÐÅÏ¢£¬£¬£¬£¬£¬²¢ÒÔ0.85±ÈÌØ±Ò£¨Ô¼ºÏ8000ÃÀÔª£©µÄ¼ÛÖµÔÚ°µÍø¹«¿ªÏúÊÛ¡£¡£¡£¡£¡£Æ¾¾ÝºÚ¿ÍÌṩµÄÊý¾ÝʾÀý£¬£¬£¬£¬£¬Ð¹Â¶ÐÅÏ¢Ô̺¬Óû§Ãû¡¢µç×ÓÓʼþ¡¢µç»°ºÅÂë¡¢³ÇÊÐ/ÖÝ/¹ú¶ÈºÍ¹þÏ£ÃÜÂëµÅ×û§ÐÅÏ¢£¬£¬£¬£¬£¬ÒÔ¼°WishboneÓ×ÎÒ×ÊÁÏͼƬµÄÁ´½Ó¡£¡£¡£¡£¡£ºÚ¿ÍÐû³ÆÕâЩÊý¾ÝÊÇͨ¹ý½ñÄêËêÊ׵Ĺ¥»÷ÇÔÈ¡µÄ£¬£¬£¬£¬£¬Æ¾¾ÝÊý¾ÝÑù±¾ÖеŦ·ò´Á¿É×·Òäµ½2020Äê1Ô¡£¡£¡£¡£¡£¾ÝZDNetµ÷²é£¬£¬£¬£¬£¬¸ÃºÚ¿ÍĿǰÔÚÏúÊÛÊýÊ®¼ÒÆäËû¹«Ë¾µÄÊý¾Ý¿â£¬£¬£¬£¬£¬×ܼƳ¬¹ý15ÒÚÌõÊý¾Ý¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hacker-selling-40-million-user-records-from-popular-wishbone-app/


4.Å·ÖÞÒ½ÔºFreseniusÔâÀÕË÷Èí¼þSnake¹¥»÷£¬£¬£¬£¬£¬»¼ÕßÐÅϢй¶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Å·ÖÞÒ»¼Ò´óÐ͵Ä˽Á¢Ò½ÔºFreseniusÔâÀÕË÷Èí¼þSnake¹¥»÷£¬£¬£¬£¬£¬Æä»¼ÕßµÄÒ½ÁÆÊý¾ÝºÍÓ×ÎÒÉí·ÝÐÅϢй¶¡£¡£¡£¡£¡£¾ÝBleepingComputerµ÷²é£¬£¬£¬£¬£¬Ð¹Â¶ÐÅϢΪ¸ÃҽԺΪÂýÐÔÉöÔàË¥½ß»¼ÕßÌṩ͸Îö·þÎñµÄ²¿ÃÅ£¬£¬£¬£¬£¬ÆäÖÐй¶µÄÓ×ÎÒÐÅÏ¢°üÃû×ÖºÍÐÕÊÏ¡¢ÐԱ𡢵®ÉúÈÕÆÚ¡¢»¼ÕߵĹú¼®¡¢Ö°Òµ¡¢ÓÊÕþµØÖ·¡¢µç»°ºÅÂ뻹ÓнüÇ׵ľßÌåÐÅÏ¢£¨ÐÕÃûºÍµç»°£©£»£»£»£»£»£»£»£»Ð¹Â¶µÄÒ½ÁÆÊý¾ÝÊÇָȫ¿ÆÒ½ÉúµÄÐÕÃûºÍµç»°¡¢ÓйعýÃôµÄ×¢½â¡¢²âÊÔÁ˾ÖÒÔ¼°ÓйØÒ½ÖεÄÒ½Éú¶¨¼û¡£¡£¡£¡£¡£BleepingComputerÒÑÓë¸ÃÒ½Ôº»ñµÃÁªÏµÒÔÈ·ÈÏÊý¾Ý£¬£¬£¬£¬£¬µ«Ä¿Ç°Î´ÊÕµ½Èκλش𡣡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/snake-ransomware-leaks-patient-data-from-fresenius-medical-care/


5.Å·ÖÞÒøÐÐSantander´æÔÚ°²È«ÎÊÌ⣬£¬£¬£¬£¬µ¼ÖÂÃô¸ÐÐÅϢй¶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Å·ÖÞÒøÐÐSantanderµÄ±ÈÀûʱ³½ÐÐÒò´æÔÚ°²È«ÎÊÌ⣬£¬£¬£¬£¬µ¼ÖÂÃô¸ÐÐÅϢй¶¡£¡£¡£¡£¡£°²È«·ÖÎöʦ·¢ÏÖ£¬£¬£¬£¬£¬¸ÃÒøÐеIJ©¿Í×ÓÓòµÄwww¶ËµãÅäÖÃÃýÎ󣬣¬£¬£¬£¬ÔÊÐíËÑË÷ÒýÇæ½«ÆäËùÓÐÎļþ±àÈëË÷Òý¡£¡£¡£¡£¡£Òò¶ø»áµ¼ÖÂÃô¸ÐÐÅϢй¶£¬£¬£¬£¬£¬Ô̺¬SQLºÍJSONÎļþ£¬£¬£¬£¬£¬¶øºÚ¿ÍÄܹ»ÀûÓÃÕâЩÎļþÀ´ÓÕÆ­SantanderÒøÐеĿͻ§¡£¡£¡£¡£¡£×êÑÐÈËÔ±»¹·¢ÏÖй¶ÎļþÖÐÔ̺¬ÆäCloudfront APIÃÜÔ¿£¬£¬£¬£¬£¬  Õâ¿ÉÄÜ»áй¶CloudfrontÍйܵÄÄÚÈÝ¡£¡£¡£¡£¡£Ä¿Ç°SantanderÒøÐÐÒѾ­½¨¸´¸Ã·ì϶¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

/santander-leaking-sensitive-data.html?utm_source=rss&utm_medium=rss&utm_campaign=santander-leaking-sensitive-data


6.ºÚ¿Í×éÖ¯CyberWareΪÉìÕÅÕýÒ壬£¬£¬£¬£¬ÓÃÀÕË÷Èí¼þ¹¥»÷Ú¿Æ­¹«Ë¾


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ºÚ¿Í×éÖ¯CyberWareΪÉìÕÅÕýÒ壬£¬£¬£¬£¬Ê¹ÓÃÀÕË÷Èí¼þMilkmanVictoryºÍDDoS¹¥»÷Ú¿Æ­¹«Ë¾¡£¡£¡£¡£¡£CyberWare°µÊ¾£¬£¬£¬£¬£¬ËûÃÇÒÑÆðÍ·¶Ô´û¿îÚ¿Æ­¹«Ë¾ÌáÒé¹¥»÷¡£¡£¡£¡£¡£ËûÃÇÔÚ·¢ËÍÍøÂç´¹µöµç×ÓÓʼþ£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬¼ÙװΪPDFÎļþµÄ¿ÉÖ´ÐÐÎļþµÄÁ´½Ó£¬£¬£¬£¬£¬ÒÔ·Ö·¢ÀÕË÷Èí¼þ¡£¡£¡£¡£¡£ÕâЩÀÕË÷Èí¼þÊÇÒÔ·ÛËéΪÖ÷Õŵ쬣¬£¬£¬£¬ºÚ¿Í°µÊ¾ËûÃDz»ÊÇΪÁËÇ󲯡£¡£¡£¡£¡£ËûÃÇ»¹ÌáÒéÁËDDoS¹¥»÷£¬£¬£¬£¬£¬ÒÔ·ÛË鹫˾µÄÍøÕ¾¡£¡£¡£¡£¡£Òò¶ø£¬£¬£¬£¬£¬¸øÊܺ¦ÕßÁôϵÄÊê½ð×¢Ã÷Ϊ¡°ÎÒÃÇ֪·ÄúÊÇÆ­×Ó£¡¡±£¬£¬£¬£¬£¬ÒÔÖ¤Ã÷¸ÃÍÆËã»úÒѱ»ÈëÇÖ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/vigilante-hackers-target-scammers-with-ransomware-ddos-attacks/