¿¨°Í˹»ù°ä²¼2020Äê¹¤ÒµÍøÂ簲ȫµ÷²é×êÑл㱨£»£»£»£»£»£»£»£»ÐµĶñÒâÈí¼þMrbMinerÒÑϰȾÊýǧ¸öMSSQLÊý¾Ý¿â
°ä²¼¹¦·ò 2020-09-171.¿¨°Í˹»ù°ä²¼2020Äê¹¤ÒµÍøÂ簲ȫµ÷²é×êÑл㱨

¿¨°Í˹»ù¶ÔÒßÇéÆÚ¼äµÄ¹¤ÒµÍøÂ簲ȫÇé¿ö½øÐÐÁË×êÑУ¬£¬£¬£¬£¬²¢°ä²¼ÁË2020Äê¹¤ÒµÍøÂ簲ȫµ÷²é×êÑл㱨¡£¡£¡£¡£¡£»ã±¨ÏÔʾ£¬£¬£¬£¬£¬³¬¹ýÒ»°ë(53%)µÄÊÜ·ÃÕßÈϿɣ¬£¬£¬£¬£¬COVID-19µ¼Ö¸ü¶àÔ±¹¤ÔڼҰ칫£¬£¬£¬£¬£¬ÕâÒѳÉΪ¶ÔÐÅÏ¢°²È«·þÎñµÄÒ»ÖÖѹÁ¦²âÊÔ¡£¡£¡£¡£¡£ÓÉÓÚ±í²¿ÏνÓÊýÁ¿¶à¶à£¬£¬£¬£¬£¬´Ë¿Ì¾ø´óÎÞÊý¹«Ë¾¶¼ÔÚ¶ÔOTÍøÂçµÄ°²È«¼¶±ð½øÐж¨ÆÚÆÀ¹À¡£¡£¡£¡£¡£ºÜ¶à×éÖ¯²»µÃ²»³ÁÐÂ˼¿¼ËûÃÇÄÚÍøµÄ±£»£»£»£»£»£»£»£»¤²½Ö裬£¬£¬£¬£¬Ö»ÓÐ7%µÄÊÜ·ÃÕß°µÊ¾£¬£¬£¬£¬£¬ËûÃǵÄÍøÂ簲ȫսÊõÔÚCOVID-19ÆÚ¼äÏ൱ÓÐЧ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.kaspersky.com/blog/industrial-cybersecurity-2020/37031/
2.еĶñÒâÈí¼þMrbMinerÒÑϰȾÊýǧ¸öMSSQLÊý¾Ý¿â

×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬£¬£¬´ÓǰµÄ¼¸¸öÔÂÖУ¬£¬£¬£¬£¬ºÚ¿Í×éÖ¯ÒÑÀûÓÃеĶñÒâÈí¼þMrbMinerÈëÇÖÊýǧ¸öMicrosoft SQL Server£¨MSSQL£©²¢×°ÖÃÁ˼ÓÃܿ󹤡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þͨ¹ýɨÃèÍøÂçÉϵÄMSSQL·þÎñÆ÷½øÐд«²¼£¬£¬£¬£¬£¬¶øºóͨ¹ý·´¸´³¢ÊÔ¸÷ÀàÈõÃÜÂëµÄÖÎÀíÔ¹ØÊ»§À´½øÐб©Á¦¹¥»÷¡£¡£¡£¡£¡£Ò»µ©¹¥»÷Õ߳ɹ¦ÈëÇÖϵͳ£¬£¬£¬£¬£¬ËûÃDZã»áÏÂÔØassm.exeÎļþ£¬£¬£¬£¬£¬ÒÔ³ÉÁ¢ºóÃÅÕÊ»§¹©½«À´½Ó¼û¡£¡£¡£¡£¡£×îºó£¬£¬£¬£¬£¬Ëü½«ÏνÓC2·þÎñÆ÷£¬£¬£¬£¬£¬²¢ÏÂÔØÒ»¸öÀûÓÃÒÔÍÚ¾òMonero£¨XMR£©¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/new-mrbminer-malware-has-infected-thousands-of-mssql-databases/
3.Check PointÖÒ¸æÕë¶Ô½ÌÓýºÍѧÊõÁìÓòµÄDDoS¹¥»÷¼¤Ôö

ÍøÂ簲ȫ¹«Ë¾Check Point·¢ÏÖ£¬£¬£¬£¬£¬Õë¶Ô½ÌÓýºÍѧÊõÁìÓòµÄDDoS¹¥»÷¼¤Ôö¡£¡£¡£¡£¡£ÆäÖ¸³ö£¬£¬£¬£¬£¬´óÎÞÊý¹¥»÷¶¼ÊÇÕë¶ÔÃÀ¹úµÄ»ú¹¹£¬£¬£¬£¬£¬ÔÚ7ÔºÍ8Ô£¬£¬£¬£¬£¬Õë¶ÔѧÊõ²¿ÃŵĹ¥»÷¾ùÔÈÿÖÜÔö³¤30£¥£¬£¬£¬£¬£¬´ÓÎåÔºÍÁùÔµÄ468´ÎÔ¾ÉýÖÁ608´Î¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚÕë¶ÔÃÀ¹ú¡¢Å·ÖÞºÍÑÇÖ޵ĽÌÓýºÍ×êÑв¿ÃÅʱѡȡÁË·ÖÆçµÄ²½ÖèºÍÕ½Êõ£¬£¬£¬£¬£¬×îÖÕÖ¸±êËÆºõÒ²ÒòµØÓò¶øÒì¡£¡£¡£¡£¡£Õë¶ÔÅ·Ö޵Ĺ¥»÷ΪÐÅϢй¶£¬£¬£¬£¬£¬´ÓÎå¡¢ÁùÔµÄ638´ÎÔ¾ÉýÖÁÆß¡¢°ËÔµÄ793´Î£¬£¬£¬£¬£¬Ôö³¤ÁË24£¥¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/surge-in-ddos-attacks-targeting-education-and-academic-sector/
4.×êÑÐÈËÔ±·¢ÏÖWin10ÖеÄFingerºÅÁî¿É±»ÓÃÀ´ÇÔÈ¡Îļþ

×êÑÐÔ±John Page·¢ÏÖ£¬£¬£¬£¬£¬Microsoft Windows TCPIP FingerºÅÁÄܹ»³äÈÎÎļþÏÂÔØÆ÷ºÍmakeshiftºÅÁîÓë½ÚÔ죨C3£©·þÎñÆ÷£¬£¬£¬£¬£¬ÒÔÓÃÓÚ·¢ËͺÅÁîºÍÇÔÈ¡Êý¾Ý¡£¡£¡£¡£¡£ÓйØ×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬C2ºÅÁîÄܹ»¼Ù×°³Éfinger queriesÀ´ÇÔÈ¡Êý¾Ý£¬£¬£¬£¬£¬¶ø²»±»Windows Defender¼ì²âµ½ÕâÖÖÒì³£ÐÐΪ¡£¡£¡£¡£¡£ÕâÖÖ²½Ö轫ÔÊÐíͨ¹ý·À»ðǽ¹æ¶¨£¬£¬£¬£¬£¬²¢Ê¹Óò»ÊÜÏ޶ȵÄHTTP¶Ë¿ÚÓë·þÎñÆ÷ͨѶ¡£¡£¡£¡£¡£Í¨¹ýÕâÖÖ²½Ö裬£¬£¬£¬£¬Portproxy²éÎʱ»´«µÝµ½±¾µØIP£¬£¬£¬£¬£¬¶øºóת·¢µ½Ö¸¶¨µÄC2Ö÷»ú¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/windows-10-finger-command-can-be-abused-to-download-or-steal-files/
5.Adobe°ä²¼´ø±í¸üУ¬£¬£¬£¬£¬½¨¸´Media EncoderÖÐ3¸ö·ì϶

Adobe°ä²¼´ø±í¸üУ¬£¬£¬£¬£¬½¨¸´Adobe Media EncoderÖеÄ3¸öÑϳÁµÄ·ì϶¡£¡£¡£¡£¡£ÕâÈý¸ö·ì϶¾ùΪԽ½ç¶ÁÈ¡µ¼ÖµÄÐÅϢй¶·ì϶£¬£¬£¬£¬£¬±»×·×ÙΪCVE-2020-9739¡¢CVE-2020-9744ºÍCVE-2020-9745£¬£¬£¬£¬£¬¿ÉÄܻᵼÖÂÓû§µÄÃô¸ÐÐÅϢй©¡£¡£¡£¡£¡£Adobe½¨ÒéÓû§¾¡¿ì×°ÖÃAdobe Media Encoder 14.4À´½¨¸´ÕâÈý¸ö·ì϶£¬£¬£¬£¬£¬ÒÔ×èÖ¹ÊÔIJÀûÓÃ佨²¹µÄ·ì϶µÄ¹¥»÷¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/adobe-releases-out-of-band-security-update-for-adobe-media-encoder/
6.ÐÂÔóÎ÷´óѧҽԺϰȾSunCrypt£¬£¬£¬£¬£¬240 GBÊý¾Ý»òÒÑй©

ÐÂÔóÎ÷´óѧҽԺ£¨UHNJ£©Ôâµ½SunCryptÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬240 GBÊý¾Ý»òÒÑй©¡£¡£¡£¡£¡£ÀÕË÷Èí¼þ×éÖ¯SunCryptÐû³Æ£¬£¬£¬£¬£¬ÆäÔÚ9Ô·ÝÀÕË÷Èí¼þ¹¥»÷ÖдÓUHNJÇÔÈ¡ÁË240 GBÊý¾Ý£¬£¬£¬£¬£¬²¢ÇÒĿǰÒѾй©ÁË1.7 GBµÄ´æµµ£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬³¬¹ý48000¸öÎĵµ¡£¡£¡£¡£¡£Õâ´Îй¶µÄÊý¾ÝÔ̺¬À¨»¼ÕßÐÅÏ¢°ä²¼ÊÚȨ±í¡¢¼ÝÊ»ÅÆÕÕ¸±±¾¡¢Éç»á°²È«ºÅÂ루SSN£©¡¢µ®ÉúÈÕÆÚ£¨DOB£©ÒÔ¼°ÓйضÊ»áµÄ¼Í¼¡£¡£¡£¡£¡£ÖªÁµÈËÊ¿Åú×¢£¬£¬£¬£¬£¬UHNJµÄÒ»ÃûÔ±¹¤ÔÚ8Ôµ×ϰȾÁËTrickBotľÂí£¬£¬£¬£¬£¬Õâ¿ÉÄܵ¼ÖÂÍøÂçÊÜË𣬣¬£¬£¬£¬×îÖÕ»á×°ÖÃÀÕË÷Èí¼þ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/university-hospital-new-jersey-hit-by-suncrypt-ransomware-data-leaked/


¾©¹«Íø°²±¸11010802024551ºÅ