Google°ä²¼chrome°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´WebGLÖдúÂëÖ´Ðзì϶£»£»£»£»£»£» £»LazarusÀûÓÃLinkedInÕÐÆ¸¸æ°×¹¥»÷¼ÓÃÜÇ®±Ò¹«Ë¾

°ä²¼¹¦·ò 2020-08-26

1.Google°ä²¼chrome°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´WebGLÖдúÂëÖ´Ðзì϶


1.jpg


Google°ä²¼chrome°²È«¸üУ¬£¬£¬£¬£¬£¬½¨¸´ÆäWebGLÖдúÂëÖ´Ðзì϶¡£¡£ ¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÓÉ˼¿ÆTalosµÄ×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬£¬£¬£¬ÆäλÓÚOpenGLºÍChromeä¯ÀÀÆ÷¼°ÆäËûÏîÄ¿ÔÚWindowsÉÏʹÓõÄDirect3DÖ®¼äµÄ¼æÈݲãANGLEÖУ¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ýÊʵ±µÄÄÚ´æ²¼¾ÖºóÀûÓø÷ì϶£¬£¬£¬£¬£¬£¬ÔÚä¯ÀÀÆ÷ÖÐÖ´ÐÐËÁÒâ´úÂë¡£¡£ ¡£¡£¡£¡£¡£¡£¸Ã·ì϶±»×·×ÙΪCVE-2020-6492£¬£¬£¬£¬£¬£¬CVSSv3ÆÀ·ÖΪ8.3£¬£¬£¬£¬£¬£¬Ó°ÏìÁËGoogle Chrome 81.0.4044.138£¨Stable£©£¬£¬£¬£¬£¬£¬84.0.4136.5£¨Dev£©ºÍ84.0.4143.7£¨Canary£©£¬£¬£¬£¬£¬£¬Ä¿Ç°Òѱ»Google½¨¸´¡£¡£ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/google-chrome-85-fixes-webgl-code-execution-vulnerability/


2.ÒÁÀʺڿÍͨ¹ý¹¥»÷¶³öµÄRDP·þÎñÆ÷À´×°ÖÃÀÕË÷Èí¼þDharma


2.jpg


ÒÁÀÊеĺڿÍ×é֯ͨ¹ý¹¥»÷¶³öµÄRDP·þÎñÆ÷À´×°ÖÃÀÕË÷Èí¼þDharma£¬£¬£¬£¬£¬£¬Õë¶Ô¶íÂÞ˹¡¢Ó¡¶È¡¢ÖйúºÍÈÕ±¾¹«Ë¾¡£¡£ ¡£¡£¡£¡£¡£¡£ËûÃÇͨ¹ý¿ªÔ´¶Ë¿ÚɨÃèÆ÷MasscanɨÃèInternetÉϵÄIPµØÖ·ÒÔ²éÕÒ¶³öµÄÔ¶³Ì×ÀÃæÏνӣ¨RDP£©£¬£¬£¬£¬£¬£¬Ö¼ÔÚÕÒµ½ÏàÒ˵ÄÊܺ¦Õß¡£¡£ ¡£¡£¡£¡£¡£¡£Ö®ºó»áʹÓÃNLBruteÆô¶¯±©Á¦ÆÆ½â·¨Ê½ÆÆ½âRDPÃÜÂë¡£¡£ ¡£¡£¡£¡£¡£¡£³É¹¦½øÈëºó£¬£¬£¬£¬£¬£¬ËûÃÇ»áÀûÓÃWindows 7ÖÁ10Öеľɷì϶£¨CVE-2017-0213£©½øÐÐÌáȨ¡£¡£ ¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯µÄÊê½ðÒªÇóÔÚ1-5±ÈÌØ±ÒÖ®¼ä£¨$ 11,700-$ 59,000£©£¬£¬£¬£¬£¬£¬ÓëÆäËûÀÕË÷Èí¼þ×éÖ¯Ïà±È½ð¶î½ÏÓס£¡£ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/iranian-hackers-attack-exposed-rdp-servers-to-deploy-dharma-ransomware/


3.LazarusÀûÓÃLinkedInÕÐÆ¸¸æ°×¹¥»÷¼ÓÃÜÇ®±Ò¹«Ë¾


3.jpg


F-SecureµÄÍøÂ簲ȫ×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬£¬£¬£¬APT×éÖ¯LazarusÀûÓÃLinkedInÕÐÆ¸¸æ°×¹¥»÷¼ÓÃÜÇ®±Ò¹«Ë¾¡£¡£ ¡£¡£¡£¡£¡£¡£ÔÚÕâ´Î¹¥»÷»î¶¯ÖУ¬£¬£¬£¬£¬£¬LazarusÏòÖ¸±ê¹«Ë¾µÄϵͳÖÎÀíÔ±Ó×ÎÒLinkedInÕÊ»§Öз¢ËÍÕÐÆ¸¸æ°×£¬£¬£¬£¬£¬£¬×¢Ã÷Ò»¼ÒÇø¿éÁ´¼¼Êõ¹«Ë¾ÔÚ×·ÇóеÄsysadmin¡£¡£ ¡£¡£¡£¡£¡£¡£¸Ã¸æ°×½«ÓÕʹÊܺ¦Õ߯ôÓú꣬£¬£¬£¬£¬£¬ÒÔ´´½¨Ò»¸ö.LNKÎļþ£¬£¬£¬£¬£¬£¬¸ÃÎļþÖ¼ÔÚÖ´ÐÐÒ»¸öÃûΪmshta.exeµÄÎļþ£¬£¬£¬£¬£¬£¬²¢Å²ÓÃÏνӵ½VBScriptµÄbit.lyÁ´½Ó£¬£¬£¬£¬£¬£¬²¢½«²Ù×÷ÐÅÏ¢·¢Ë͵½C2·þÎñÆ÷¡£¡£ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/lazarus-group-strikes-cryptocurrency-firm-through-linkedin-job-adverts/


4.Zoom·þÎñÔÙ´ÎÖжÏ£¬£¬£¬£¬£¬£¬ÖØÒªÓ°ÏìÃÀ¹ú¶«º£°¶ºÍÓ¢¹úµÄÓû§


4.jpg


Zoom·þÎñÔÙ´ÎÖжÏ£¬£¬£¬£¬£¬£¬ÖØÒªÓ°ÏìÃÀ¹ú¶«º£°¶ºÍÓ¢¹úµÄÓû§¡£¡£ ¡£¡£¡£¡£¡£¡£Zoom°µÊ¾ÔÚÕâ´ÎÖжÏÖУ¬£¬£¬£¬£¬£¬ºÜ¶àÓû§ÎÞ·¨½Ó¼ûZoomÍøÕ¾£¨zoom.us£©£¬£¬£¬£¬£¬£¬²¢ÎÞ·¨Æô¶¯ºÍ²ÎÓëZoom Meetings¡£¡£ ¡£¡£¡£¡£¡£¡£½ØÖÁ´Ë¿Ì£¬£¬£¬£¬£¬£¬ZoomÒÑÈ·¶¨µ¼ÖÂÕâ´Î¹ÊÕϵÄÔ­Òò£¬£¬£¬£¬£¬£¬²¢ÒѽøÐн¨¸´¡£¡£ ¡£¡£¡£¡£¡£¡£Õâ²¢²»µÚÒ»´Î²úÉúÀàËÆ¹ÊÕÏ£¬£¬£¬£¬£¬£¬ÔçÔÚ4Ô£¬£¬£¬£¬£¬£¬ZoomÓû§°µÊ¾ËûÃÇÎÞ·¨Æô¶¯Web¿Í»§¶Ë²¢ÏÔʾ403 ForbiddenÃýÎ󣬣¬£¬£¬£¬£¬¶øÉÏÖÜÓû§Ò²·¢ÏÖÎÞ·¨Í¨¹ýZoom Web¿Í»§¶ËºÍWebSDK²ÎÓë»áÒé¡£¡£ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/technology/zoom-went-down-and-schools-got-a-digital-snow-day/


5.¿¨°Í˹»ù°ä²¼ÓйØÍøÂç¼äµý×éÖ¯DeathStalkerµÄ·ÖÎö»ã±¨


5.jpg


¿¨°Í˹»ù·¢ÏÖÒ»¸öרÃÅ´ÓÊÂÇÔȡóÒ×»úÃܵÄÍøÂç·¸×ï×éÖ¯Ö¯DeathStalker£¬£¬£¬£¬£¬£¬²¢°ä²¼Õë¶ÔÆäµÄ·ÖÎö»ã±¨¡£¡£ ¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯×Ô2018Äê»ò¸üÔ磨¿ÉÄÜ×Ô2012Ä꣩¾ÍÆðÍ·»îÔ¾£¬£¬£¬£¬£¬£¬ÖØÒª¶Ô½ðÈڿƼ¼¹«Ë¾¡¢ÂÉʦÊÂÎñËùºÍ²ÆÕþÕÕ·÷¡£¡£ ¡£¡£¡£¡£¡£¡£DeathStalker²»»á²¿ÊðÀÕË÷Èí¼þ»òÇÔȡ֧¸¶Êý¾Ý£¬£¬£¬£¬£¬£¬Æä¹Ø×¢µÄ³ÁµãÊÇÃô¸ÐµÄÒµÎñÊý¾Ý£¬£¬£¬£¬£¬£¬ÕâÒâζ×ÅDeathStalke¿ÉÄÜÌṩÁËºÚ¿ÍÆ¸Ó÷þÎñ£¬£¬£¬£¬£¬£¬»òÕß³äÈÎÁ˽ðÈÚ½çµÄÐÅÏ¢¾­¼ÍÈË¡£¡£ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.kaspersky.com/blog/deathstalker-powersing/36815/


6.Ó¡¶ÈÓÎÀÀÍøÕ¾RailYatriÒòÊý¾Ý¿âÅäÖÃÃýÎóй¶3700Íò±Ê¼Í¼


6.jpg


SafetyDetectives 8ÔÂ10ÈÕÔÚÍøÂçÉÏ·¢ÏÖÁËRailYatriµÄûÓÐÃÜÂë±£»£»£»£»£»£» £»¤µÄElasticsearch·þÎñÆ÷£¬£¬£¬£¬£¬£¬Ð¹Â¶3700Íò±Ê¼Í¼¿Í»§ºÍ¹«Ë¾Êý¾Ý£¬£¬£¬£¬£¬£¬Ô̺¬Óû§µÄÈ«Ãû¡¢´ºÇï¡¢ÐÔ±ð¡¢ÏÖʵºÍµç×ÓÓʼþµØÖ·¡¢ÊÖ»úºÅÂë¡¢Ô¤Ô¼¾ßÌåÐÅÏ¢¡¢GPSµØÎ»ÒÔ¼°ÐÕÃû/Ö§¸¶¿¨µÄǰËÄλºÍºóËÄλ¡£¡£ ¡£¡£¡£¡£¡£¡£¶øÔڸù«Ë¾¶ÔÆäÊý¾Ý½øÐб£»£»£»£»£»£» £»¤Ö®Ç°£¬£¬£¬£¬£¬£¬Meow»úеÈËÓÚ8ÔÂ12ÈÕ¶ÔÆä²úÉú¹¥»÷£¬£¬£¬£¬£¬£¬É¾³ýÁ˳ý1GBÖ®±íµÄËùº±¼û¾Ý£¨×ܹ²43 GB£©¡£¡£ ¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/travel-site-exposed-37m-records/