NSA°ä²¼Õë¶ÔÔ¶³Ì¹¤×÷ÕߺÍϵͳÖÎÀíÔ±µÄÍøÂ簲ȫָÄÏ£»£»£»£»£»×êÑÐÈËÔ±·¢ÏÖCloudflare WAFµÄ·ÀSQL×¢ÈëÕ½Êõ¿ÉÈÆ¹ý
°ä²¼¹¦·ò 2020-09-231.NSA°ä²¼Õë¶ÔÔ¶³Ì¹¤×÷ÕߺÍϵͳÖÎÀíÔ±µÄÍøÂ簲ȫָÄÏ

ÃÀ¹ú¹ú¶È°²È«¾Ö(NSA)°ä²¼ÁËÁ½·ÝÍøÂ簲ȫÐÅÏ¢±í(CSIs)£¬£¬£¬£¬£¬£¬£¬Îª¹ú¶È°²Õûϵͳ(NSS)ºÍ¹ú·À²¿(DoD)¹¤×÷ÈËÔ±ºÍϵͳÖÎÀíÔ±ÌṩÁ˹ØÓÚÔÚ¼Ò¹¤×÷ÆÚ¼ä±£»£»£»£»£»¤ÍøÂ簲ȫºÍÓ¦¶ÔÊÂÎñµÄ½¨Òé¡£¡£¡£¡£¡£¡£µÚÒ»·ÝÃûΪÊÜËðÓ×ÎÒÍøÂçÖ¸±ê»ººÍ½â´ëÊ©£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚÌṩÓйØÔ¶³Ì¹¤×÷ÕßÈôºÎ¼ø±ðºÍ¼õÇáÆäÓ×ÎÒÍøÂç·çÏյľßÌåÐÅÏ¢¡£¡£¡£¡£¡£¡£µÚ¶þ·ÝÃûΪִÐдø±íÍøÂçÖÎÀí£¬£¬£¬£¬£¬£¬£¬ÆäÏòϵͳÖÎÀíÔ±ÌṩÁËÈôºÎ¸ôÀëÖÎÀíÁ÷Á¿ºÍÔËÓªÁ÷Á¿µÄÐÅÏ¢¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/nsa-issues-cybersecurity-guidance-remote-workers-system-admins
2.ºÚ¿Í¶Ô×¼µÃ¿ËÈøË¹ÖÝÎÀÉú·þÎñ¾ÖÌáÒéÍøÂç´¹µö¹¥»÷

ºÚ¿ÍÊÔͼαÔìµÂ¿ËÈøË¹ÖÝÖÝÎÀÉú·þÎñ¾Ö£¨DSHS£©µÄµç×ÓÓʼþÀ´ÌáÒéÍøÂç´¹µö¹¥»÷¡£¡£¡£¡£¡£¡£µç×ÓÓʼþ±£»£»£»£»£»¤µÄ¹«Ë¾Abnormal Security·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬ÓкڿͼÙÒâÁ˵ÿËÈøË¹ÖÝDSHSµÄ´úÀíרԱJohn William Hellerstedt·¢ËÍ´¹µöÓʼþ£¬£¬£¬£¬£¬£¬£¬ÒªÇóÊܺ¦ÕßÌṩ20̨´¥ÃþÆÁ±Ê¼Ç±¾µçÄÔºÍ200̨±ãЯʽӲÅ̵ı¨¼Û¡£¡£¡£¡£¡£¡£Æä×îÖÕÖ÷ÕÅ¿ÉÄÜÊÇ»ñµÃ²úÆ·£¬£¬£¬£¬£¬£¬£¬²¢Í¨¹ýÏúÊÛÔßÎïÒÔıȡÀûÒæ¡£¡£¡£¡£¡£¡£×êÑÐÈËԱ˵£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚ·¢ËÍÓʼþʱÓ×Ðĵظ²¸ÇÁËÆäÐÐ×Ù£¬£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃVPN·þÎñ°µ²ØÁËËûÃǵĵØÎ»ºÍÕæÊµIPµØÖ·¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/texas-businesses-targeted-in-department-of-state-health-rfq-phishing/
3.×êÑÐÈËÔ±·¢ÏÖCloudflare WAFµÄ·ÀSQL×¢ÈëÕ½Êõ¿ÉÈÆ¹ý

ÍøÂ簲ȫ×êÑÐÔ±George Skouroupathis·¢ÏÖCloudflareµÄWebÀûÓ÷¨Ê½·À»ðǽ£¨WAF£©SQL×¢Èë±£»£»£»£»£»¤»úÔìÖдæÔÚ·ì϶£¬£¬£¬£¬£¬£¬£¬¿É±»Èƹý¡£¡£¡£¡£¡£¡£Ëû·¢ÏÖµ±Æä²éÎÊÒ»¸öÌØ¶¨µÄ±äÁ¿ÊÇ·ñÆ¥Åäij¸öǰÌáʱ£¬£¬£¬£¬£¬£¬£¬ÈôÊÇǰÌáÂú×ã¾Í»á¸ø³ö200¸öOK״̬֪ͨ£¬£¬£¬£¬£¬£¬£¬·´Ö®£¬£¬£¬£¬£¬£¬£¬·þÎñÆ÷·µ»ØÒ»¸ö500ÄÚ²¿·þÎñÆ÷ÃýÎ󡣡£¡£¡£¡£¡£»£»£»£»£»ùÓڸõÀÀí£¬£¬£¬£¬£¬£¬£¬Ëû±àдÁËÒ»¸ö¾ç±¾£¬£¬£¬£¬£¬£¬£¬½«DBMSµ±Ñ¡ÔñµÄ×Ö·û˳´ÎÓëËùÓÐ×Ö·û½øÐбÈÁ¦¡£¡£¡£¡£¡£¡£ÔÚ¾¹ý3´Î×¢Èë³¢ÊԺ󣬣¬£¬£¬£¬£¬£¬Æä³É¹¦µØÖ´ÐÐÁËSQL×¢Èë¹¥»÷¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/whitehat-hacker-bypass-sql-cloudflare-injection-filter/
4.Cisco³ÆÎÞÎļþµÄ¶ñÒâÈí¼þÊÇ2020Äê1H×î³£¼ûµÄÖÕ¶ËÍþв

ƾ¾ÝCisco¶ÔÒ£²âÊý¾ÝµÄ×îзÖÎö£¬£¬£¬£¬£¬£¬£¬ÔÚ2020ÄêÉϰëÄ꣬£¬£¬£¬£¬£¬£¬Õë¶ÔÖն˵Ä×î³£¼ûµÄÍøÂ簲ȫÍþвÊÇÎÞÎļþ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£ÎÞÎļþÍþвΪ³õ´ÎϰȾºóÔÚÄÚ´æÖÐÔËÐеĶñÒâ´úÂ룬£¬£¬£¬£¬£¬£¬¶ø²»ÊÇ´æ´¢ÔÚÓ²ÅÌÉϵÄÎļþ£¬£¬£¬£¬£¬£¬£¬ÀýÈçKovter¡¢Poweliks¡¢DivegentºÍLemonDuck¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬ÁíÒ»¸ö³£¼ûµÄÕë¶ÔÖն˵ÄÍøÂçÍþвΪ˫Óô¦¹¤¾ß£¬£¬£¬£¬£¬£¬£¬ËüÃÇͨ³£ÓÃÓÚ¿ª·¢ºÍ¿ª·¢ºó¹¤×÷£¬£¬£¬£¬£¬£¬£¬ÀýÈçPowerShell Empire¡¢Cobalt Strike¡¢PowersploitºÍMetasploit¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/fileless-malware-critical-ioc-threats-2020/159422/
5.CISAÖÒ¸æ¶ñÒâÈí¼þLokiBotµÄʹÓÃÁ¿ÏÔ×ÅÔö³¤

ÃÀ¹úÍøÂ簲ȫÓë»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©ÖҸ棬£¬£¬£¬£¬£¬£¬ÆäÄÚ²¿°²È«Æ½Ì¨£¨ÈëÇÖ¼ì²âϵͳEINSTEIN£©ÒѼì²âµ½LokiBotϰȾµÄ³ÖÐø¶ñÒâ»î¶¯£¬£¬£¬£¬£¬£¬£¬²¢Ìá³öÁËÓйش¦ÖÃLokiBot¹¥»÷ºÍϰȾµÄ¼ì²â»ººÍ½â½¨Òé¡£¡£¡£¡£¡£¡£µ±Ç°£¬£¬£¬£¬£¬£¬£¬Óжà¸öºÚ¿Í×éÖ¯ÔÚͨ¹ý¸÷Àà¸÷ÑùµÄ¼¼ÊõÀ´·Ö·¢¸Ã¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬´ÓÀ¬»øÓʼþµ½ÆÆ½âµÄ×°Ö÷¨Ê½ÒÔ¼°ÓÕÆµÄÖÖ×ÓÎļþ¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬ÔÚÊ¢ÐÐÂʺÍÊýÁ¿·½Ã棬£¬£¬£¬£¬£¬£¬SpamHaus½«LokiBotÁÐΪ2019Äê×î»îÔ¾µÄºÅÁîºÍ½ÚÔì(C&C)·þÎñÆ÷µÄ¶ñÒâÈí¼þ¾úÖê¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/cisa-warns-of-notable-increase-in-lokibot-malware/
6.BingµÄһ̨ºó¶Ë·þÎñÆ÷¶³ö£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶³¬¹ý6.5TBÈÕÖ¾Îļþ

WizCaseµÄ°²È«×êÑÐÔ±Ata Hakcil·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬±¾ÔÂÔçЩʱ³½£¬£¬£¬£¬£¬£¬£¬Î¢ÈíµÄITÔ±¹¤Òâ±íµØ½«BingµÄÒ»¸öºó¶Ë·þÎñÆ÷¶³öÔÚÁËÍøÂçÉÏ¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñй¶Á˳¬¹ý6.5TBµÄÈÕÖ¾Îļþ£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬130ÒÚ¸öÀ´×ÔBingËÑË÷ÒýÇæµÄ¼Í¼¡£¡£¡£¡£¡£¡£¾Ýµ÷²é£¬£¬£¬£¬£¬£¬£¬²¢Ã»ÓÐЧ»§ÐÅÏ¢±»Ð¹Â¶£¬£¬£¬£¬£¬£¬£¬µ«ÊÇ·þÎñÆ÷¹«¿ªÁ˼¼Êõ¾ßÌåÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÀýÈçËÑË÷²éÎÊ¡¢ÓйØÓû§ÏµÍ³µÄ¾ßÌåÐÅÏ¢£¨É豸£¬£¬£¬£¬£¬£¬£¬²Ù×÷ϵͳ£¬£¬£¬£¬£¬£¬£¬ä¯ÀÀÆ÷µÈ£©¡¢µØÀíµØÎ»¾ßÌåÐÅÏ¢ÒÔ¼°¸÷ÀàÁîÅÆ¡¢¹þÏ£ºÍÓÅ»Ýȯ´úÂë¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/microsoft-secures-backend-server-that-leaked-bing-data/


¾©¹«Íø°²±¸11010802024551ºÅ