ŲÍþÒé»áÓʼþϵͳÔâ¹¥»÷£¬£¬£¬£¬£¬£¬¹¤µ³ºÍÖÐÐĵ³¾ùÊÜÓ°Ï죻£»£»£»£»£»£»CiscoÖÒ¸æÆäIOS XR´æÔÚ0day²¢Òѱ»ÔÚÒ°ÀûÓÃ

°ä²¼¹¦·ò 2020-09-02

1.ŲÍþÒé»áÓʼþϵͳÔâ¹¥»÷£¬£¬£¬£¬£¬£¬¹¤µ³ºÍÖÐÐĵ³¾ùÊÜÓ°Ïì


1.png


ŲÍþÒé»á£¨Storting£©°ä²¼ÉêÃ÷£¬£¬£¬£¬£¬£¬°µÊ¾Óкڿ͹¥»÷Æä³ÉÔ±µÄµç×ÓÓʼþÕÊ»§²¢ÇÔÈ¡Êý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñÔÚµ÷²éÖУ¬£¬£¬£¬£¬£¬Ä¿Ç°Éв»Ã÷ÏÔ±»µÁÊý¾ÝµÄÊýÁ¿¡¢ÖÖÀàÒÔ¼°¹¥»÷µÄ·ÛËéˮƽ¡£¡£¡£¡£¡£¡£¡£¡£Å²Íþ¹¤µ³µÄJarle RoheimH?konsen֤ʵ£¬£¬£¬£¬£¬£¬¹¤µ³³ÉÔ±ºÍÕþ¿ÍÔÚÕâ´Î¹¥»÷ÖоùÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬Í¬Ê±ÖÐÐĵ³Ò²È·ÈÏÆä´ú±íºÍÔ±¹¤Êܵ½ÁËÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hackers-breached-norwegian-parliament-emails-to-steal-data/


2.ÃÀ¹úн×ÊЭ»áÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬Æä»áÔ±ÐÅÓþ¿¨ÐÅϢй¶


2.png


ÃÀ¹úн×ÊЭ»á£¨APA£©°µÊ¾Ôâµ½ÁËMagecart¹¥»÷£¬£¬£¬£¬£¬£¬Æä»áÔ±ÐÅÓþ¿¨ÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£¡£APAÓÚ2020Äê7ÔÂ23ÈÕ×óÓÒ·¢Ïֺڿ͹¥»÷ÁËÆäÍøÕ¾ºÍÔÚÏßÉ̵겢²¿ÊðÁË·ÖÀëÆ÷£¬£¬£¬£¬£¬£¬Ö¼ÔÚÍøÂçÃô¸ÐÐÅÏ¢²¢½«Æä·¢Ë͵½½ÚÔì·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£¡£ÔÚÕâ´Î¹¥»÷ÖУ¬£¬£¬£¬£¬£¬ºÚ¿ÍÀûÓøÃ×éÖ¯µÄÄÚÈÝÖÎÀíϵͳ(CMS)ÖеÄÒ»¸ö°²È«·ì϶£¬£¬£¬£¬£¬£¬ÈëÇÖÁËAPAµÄÍøÕ¾ºÍÔÚÏßÉ̵꣬£¬£¬£¬£¬£¬»ñµÃÁ˵ǼÐÅÏ¢(¼´Óû§ÃûºÍÃÜÂë)ºÍÓ×ÎÒÖ§¸¶¿¨ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£APAµÄ°²È«ÍŶӰµÊ¾£¬£¬£¬£¬£¬£¬¸Ã´Î¹¥»÷Äܹ»×·Òäµ½2020Äê5ÔÂ13ÈÕÃÀ¹ú¶«²¿¹¦·òÏÂÎç7:30×óÓÒ¡£¡£¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/american-payroll-association-discloses-credit-card-theft-incident/


3.CiscoÖÒ¸æÆäIOS XR´æÔÚ0day²¢Òѱ»ÔÚÒ°ÀûÓÃ


3.png


˼¿ÆÉÏÖÜÁùÖÒ¸æËµ£¬£¬£¬£¬£¬£¬ÆäIOS XR´æÔÚÒ»¸öеÄ0day£¬£¬£¬£¬£¬£¬Ä¿Ç°Òѱ»ºÚ¿ÍÔÚÒ°ÀûÓᣡ£¡£¡£¡£¡£¡£¡£¸Ã·ì϶±»¸ú×ÙCVE-2020-3566£¬£¬£¬£¬£¬£¬Ó°ÏìÁ˲Ù×÷ϵͳIOS XR°æ±¾¸½´øµÄ¾àÀëʸÁ¿×鲥·ÓɺÍ̸(DVMRP)Ö°ÄÜ£¬£¬£¬£¬£¬£¬¸Ã°æ±¾µÄ²Ù×÷ϵͳͨ³£×°ÖÃÔÚµçÐż¶ºÍÊý¾ÝÖÐÐÄ·ÓÉÆ÷ÉÏ¡£¡£¡£¡£¡£¡£¡£¡£Ë¼¿Æ°µÊ¾£¬£¬£¬£¬£¬£¬¸Ã·ì϶ÊÇÓÉÓÚInternet×éÖÎÀíºÍ̸£¨IGMP£©Êý¾Ý°üµÄ¶ÓÁÐÖÎÀí²»¼°ËùÖ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ý·¢ËÍÌØÔìµÄIGMPÁ÷Á¿À´ÀûÓô˷ì϶¡£¡£¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓø÷ì϶¿Éµ¼ÖÂÄÚ´æºÄ¾¡£¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÆäËû¹ý³Ì£¨ÈçÄÚ²¿ºÍ±í²¿Â·ÓɺÍ̸£©²»²»±ä¡£¡£¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/cisco-warns-of-actively-exploited-ios-xr-zero-day/


4.ºÚ¿ÍÀûÓÃQNAP NASÖÐÈýÄêǰµÄRCE·ì϶´´½¨ºóÃÅ


4.png


ºÚ¿ÍÔÚɨÃèÔËÐÐQNAP¹Ì¼þ°æ±¾µÄÍøÂ總¼Ó´æ´¢£¨NAS£©É豸£¬£¬£¬£¬£¬£¬ÊÔIJÀûÓÃQNAPÔÚÏÈǰ°æ±¾Öн¨¸´µÄÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©·ì϶´´½¨ºóÃÅ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßʹÓÃauthLogout.cgi¿ÉÖ´ÐÐÎļþÀ´½øÐÐÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬ÓÉÓڸ÷ì϶²»ÄܹýÂËÌØÊâ×Ö·û²¢Å²ÓÃϵͳº¯ÊýÀ´ÔËÐкÅÁî×Ö·û´®£¬£¬£¬£¬£¬£¬Òò¶øËüÄܹ»ÔÊÐíÔ¶³Ì×¢Èë´úÂëÖ´ÐÓ×£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°ÉÐδȷ¶¨¹¥»÷ÕßµÄ×îÖÕÖ¸±ê£¬£¬£¬£¬£¬£¬µ«ËûÃÇ»áÔÚÊÜϰȾµÄÉ豸Éϲ¿ÊðÁ½¸öÓÐЧ¸ºÔØ£¬£¬£¬£¬£¬£¬ÆäÖÐÖ®Ò»ÊÇTCP/1234¶Ë¿ÚÉϵķ´Ïòshell¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hackers-are-backdooring-qnap-nas-devices-with-3-year-old-rce-bug/


5.ÒÁÀʺڿÍÔÚ°µÍøÉÏÏúÊÛ¹¥»÷Ö¸±êµÄ½Ó¼ûȨÏÞ


5.png


ÍøÂ簲ȫ¹«Ë¾Crowdstrike·¢ÏÖ£¬£¬£¬£¬£¬£¬ÒÁÀʺڿÍ×éÖ¯Pioneer Kitten£¨Ò²³ÆÎªFox Kitten»òParisite£©ÔÚ°µÍøÏúÊÛ¹¥»÷Ö¸±êµÄ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯ÒÑÔÚ2019ÄêºÍ2020Äêͨ¹ýVPN ºÍÍøÂçÉ豸Öеķì϶ÈëÇÔìóÒµÍøÂçÈ磬£¬£¬£¬£¬£¬Pulse SecureÆóÒµVPN£¨CVE-2019-11510£©¡¢Fortinet VPN·þÎñÆ÷£¨CVE-2018-13379£©¡¢Global Protect VPN·þÎñÆ÷£¨CVE-2019-1579£©¡¢CitrixÍøÂçÍø¹ØºÍADC·þÎñÆ÷£¨CVE-2019-19781£©¡¢F5 Networks BIG-IP¸ºÔØÆ½ºâÆ÷£¨CVE-2020-5902£©¡£¡£¡£¡£¡£¡£¡£¡£¾Ý»ã±¨£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯Ò»ÏòÔÚÀûÓÃÉÏÊö·ì϶ÇÖÈëÍøÂçÉ豸¡¢Ö²ÈëºóÃÅ£¬£¬£¬£¬£¬£¬¶øºóΪÆäËûÒÁÀʺڿÍ×éÖ¯£¬£¬£¬£¬£¬£¬ÈçAPT33 (Shamoon)¡¢Oilrig (APT34)»òChaferÌṩ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/iranian-hackers-are-selling-access-to-compromised-companies-on-an-underground-forum/


6.APWG°ä²¼2020ÄêµÚ¶þ¼¾¶È´¹µö»î¶¯Ç÷Ïò»ã±¨


6.png


·´ÍøÂç´¹µö¹¤×÷×飨APWG£©ÓÚ±¾ÖÜÒ»°ä²¼2020ÄêµÚ¶þ¼¾¶È´¹µö»î¶¯Ç÷Ïò»ã±¨¡£¡£¡£¡£¡£¡£¡£¡£¾Ý»ã±¨£¬£¬£¬£¬£¬£¬2020ÄêQ2ºÚ¿Í×éÖ¯ÔÚÿ´ÎBEC¹¥»÷ÖоùÔÈ»ñÀû8ÍòÃÀÔª£¬£¬£¬£¬£¬£¬Ô¶¸ßÓÚQ1µÄ5.4ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬APWG»¹·¢ÏÖÁËÒ»¸öеĶíÂÞ˹BEC×éÖ¯Cosmic Lynx£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯×Ô2019Äê7ÔÂÒÔÀ´Ò»Ïò»îÔ¾£¬£¬£¬£¬£¬£¬ÆäÕë¶ÔÁù´óÖÞµÄ46¸öʵÌå·¢Õ¹ÁË200ÂŴι¥»÷»î¶¯£¬£¬£¬£¬£¬£¬Ã¿´Î¹¥»÷µÄ¾ùÔÈ»ñÀûΪ127ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/average-bec-attempts-are-now-80k-but-one-group-is-aiming-for-1-27m-per-attack/