CISA°ä²¼SolarWinds Orion¹¥»÷ÊÂÎñµÄ²¹³äÖ¸ÄÏ£»£»£»£»£»£»£»£»Æ»¹û¡¢¹È¸è¡¢Î¢ÈíºÍMozilla½ûÓùþÈø¿Ë˹̹µÄ¸ùÖ¤Êé
°ä²¼¹¦·ò 2020-12-22
CISA×î³õÓÚ12ÔÂ17ÈÕ°ä²¼ÁËÓйص±¾Ö»ú¹¹¡¢¹Ø¼ü»ù´¡ÉèÊ©ºÍ¹«Ë¾×éÖ¯µÄAPT¹¥»÷»î¶¯µÄ¾¯±¨£¬£¬£¬£¬£¬Ö®ºóÕë¶Ô¸Ã´¹Î£Ö¸Áî°ä²¼Á˲¹³äÖ¸ÄÏ¡£¡£¡£¡£¡£¡£²¹³äÖ¸ÄÏÔ̺¬ÊÜÓ°Ïì°æ±¾µÄ¸üС¢Õë¶ÔʹÓõÚÈý·½·þÎñÌṩÉ̵ĴúÀíµÄÖ¸ÄÏÒÔ¼°¶ÔËùÐè´ëÊ©µÄ½øÒ»²½×¢Ã÷¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬CISA»¹¸üÐÂÁ˸þ¯±¨£¬£¬£¬£¬£¬ÌṩÁËÐµĻº½â¹æ»®²¢¶©ÕýÁËIOC±í¸ñ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2020/12/19/cisa-updates-alert-and-releases-supplemental-guidance-emergency
2.ÏãÁϹ«Ë¾SymriseϰȾClop£¬£¬£¬£¬£¬500GBδ¼ÓÃܵÄÎļþ±»µÁ

Ï㾫ÏãÁϹ«Ë¾SymriseϰȾÀÕË÷Èí¼þClop£¬£¬£¬£¬£¬500GBδ¼ÓÃܵÄÎļþ±»µÁ£¬£¬£¬£¬£¬½ü1000̨É豸±»¼ÓÃÜ¡£¡£¡£¡£¡£¡£SymriseÊÇÈ«Çò³¬¹ý3ÍòÖÖ²úÆ·£¨Ô̺¬È¸³²ºÍÊʿڿÉÀÖ£©ÖÐʹÓõÄÏ㾫ÏãÁϵÄÖØÒª¿ª·¢ÉÌ£¬£¬£¬£¬£¬ÓÚÉÏÖÜÔâµ½ÁËÍøÂç¹¥»÷£¬£¬£¬£¬£¬²¢¹Ø¹ØÁËËùÓбØÒªµÄϵͳÒÔÔ¤·À¹¥»÷ÊæÕ¹¡£¡£¡£¡£¡£¡£ClopÍÅ»ïÐû³ÆÆäͨ¹ý´¹µö¹¥»÷ÈëÇÖÁËSymriseµÄÍøÂç²¢ÇÔÈ¡ÁË500 GBµÄδ¼ÓÃÜÎļþ£¬£¬£¬£¬£¬ÆäÔÚÊý¾ÝÐ¹Â¶ÍøÕ¾Éϰ䲼µÄ½ØÍ¼ÏÔʾ±»µÁÊý¾ÝÔ̺¬»¤ÕÕ¡¢¹ÜÕÊÆ¾Ö¤¡¢Éó¼Æ»ã±¨¡¢»¯×±Æ·³É·ÖºÍµç×ÓÓʼþµÈ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/flavors-designer-symrise-halts-production-after-clop-ransomware-attack/
3.ClearSky³ÆÒÁÀʺڿÍÀûÓÃPay2Key¶Ô×¼ÒÔÉ«ÁеĹ«Ë¾

Íþвµý±¨¹«Ë¾ClearSky³ÆÒÁÀʺڿÍÀûÓÃPay2Key¶Ô×¼ÒÔÉ«ÁеĹ«Ë¾¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷»î¶¯²úÉúÓÚ2020Äê11Ôµ½12Ô£¬£¬£¬£¬£¬»òÓëÒÁÀʺڿÍ×éÖ¯Fox KittenÓйء£¡£¡£¡£¡£¡£Fox KittenÉÆÓÚʹÓø÷À࿪ԴºÍ×ÔÖ÷¿ª·¢µÄ¹¥»÷¹¤¾ß£¬£¬£¬£¬£¬Í¨¹ýÖ¸±êÆóÒµµÄvpnÒÔ¼°F5 NetworksµÄBIG-IPÀûÓ÷¨Ê½½»¸¶½ÚÔìÆ÷(ADC)ÈëÇÖ¡£¡£¡£¡£¡£¡£ClearSky³ÆºÚ¿ÍÕë¶ÔÒÔÉ«ÁÐÊýÊ®¼Ò¹¤Òµ¡¢±£ÏÕºÍÎïÁ÷¹«Ë¾£¬£¬£¬£¬£¬À´×°ÖÃÀÕË÷Èí¼þÀ´¼ÓÃÜ·þÎñÆ÷ºÍ¹¤×÷Õ¾£¬£¬£¬£¬£¬ÒÔ¼°ÌáÒ鹩¸øÁ´¹¥»÷¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/iranian-hackers-target-israeli-companies-pay2key-ransomware
4.Æ»¹û¡¢¹È¸è¡¢Î¢ÈíºÍMozilla½ûÓùþÈø¿Ë˹̹µÄ¸ùÖ¤Êé

Æ»¹û¡¢¹È¸è¡¢Î¢ÈíºÍMozilla½ûÓùþÈø¿Ë˹̹µÄMitM HTTPSÖ¤Êé¡£¡£¡£¡£¡£¡£¸ÃÖ¤Êé×Ô2020Äê12ÔÂ6ÈÕÆðͷʹÓ㬣¬£¬£¬£¬¹þÈø¿Ë˹̹µ±¾ÖÇ¿Ôì×°Öô˸ùÖ¤ÊéÒÔÀ¹½ØºÍ¼à¶½¸Ã¹úÊ×¶¼Å¬¶ûËÕµ¤¾ÓÃñµÄHTTPSÁ÷Á¿¡£¡£¡£¡£¡£¡£´Ë½ûÁî°ä²¼ºó£¬£¬£¬£¬£¬¼´±ãÓû§ÒÑ×°ÖÃÖ¤Ê飬£¬£¬£¬£¬ÈÔÎÞ·¨½Ó¼ûChrome¡¢Edge¡¢MozillaºÍSafariµÈä¯ÀÀÆ÷£¬£¬£¬£¬£¬´Ó¶ø×èÖ¹¹þÈø¿Ë˹̹¹ÙÔ±À¹½ØÓû§Êý¾Ý¡£¡£¡£¡£¡£¡£ÕâÊÇËļҳ§É̵ڶþ´Î½ûÓùþÈø¿Ë˹̹µ±¾ÖÇ¿Ôì×°ÖõÄMitM HTTPSÖ¤Êé¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/apple-google-microsoft-and-mozilla-ban-kazakhstans-mitm-https-certificate/
5.Dell Wyse Thin¿Í»§¶Ë´æÔÚÁ½¸ö´úÂëÖ´Ðзì϶

Dell Wyse Thin¿Í»§¶Ë´æÔÚÁ½¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¬£¬£¬£¬£¬CVSSÑϳÁÐÔÆÀ·Ö¾ùΪ10¡£¡£¡£¡£¡£¡£ÆäÖÐÒ»¸ö·ì϶±»×·×ÙΪCVE-2020-29491£¬£¬£¬£¬£¬ÓÉÓÚ¶¨ÆÚping·þÎñÆ÷ÒÔ»ñÈ¡×îÐÂÅäÖ㬣¬£¬£¬£¬²¢ÎÞÐèÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬Òò¶øËùÓÐÈ˶¼¿É½Ó¼ûÕâЩ¿ÉÄÜÔ̺¬Ô¶³Ì½Ó¼ûÍ´´¦µÄÅäÖÃÎļþ¡£¡£¡£¡£¡£¡£ÁíÒ»¸ö·ì϶±»×·×ÙΪCVE-2020-29492£¬£¬£¬£¬£¬ÓÉÓÚ´æ´¢ÕâЩÅäÖõķþÎñÆ÷ÔÊÐí¶ÔÆäÅäÖÃÎļþ½øÐжÁд½Ó¼û£¬£¬£¬£¬£¬Òò¶øÈκÎÈ˶¼Äܹ»Ê¹ÓÃFTP¶ÁÈ¡ºÍ¸ü¸ÄËüÃÇ¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬ÕâÁ½¸ö·ì϶ÒѾ±»½¨¸´¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/critical-bugs-dell-wyse-thin-clients/162452/
6.Verizon°ä²¼2020ÄêÊý¾Ýй¶µÄµ÷²é·ÖÎö»ã±¨

Verizon°ä²¼ÁË2020ÄêÊý¾Ýй¶µÄµ÷²é·ÖÎö»ã±¨£¬£¬£¬£¬£¬×ܹ²·ÖÎöÁË157525ÆðÊÂÎñ£¬£¬£¬£¬£¬Éæ¼°µ½16¸ö´¹Ö±ÐÐÒµ¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö£¬£¬£¬£¬£¬ÔÚµ¼ÖÂÊý¾Ýй¶µÄ¹¥»÷·½Ê½ÖУ¬£¬£¬£¬£¬ÍøÂç´¹µö¡¢Ê¹Óñ»µÁÍ´´¦ºÍÅäÖÃÃýÎóµÄÕ¼±È×î´ó£¬£¬£¬£¬£¬¶øµ¼ÖÂÊý¾Ýй¶×î¶àµÄ¶ñÒâÈí¼þÀàÐÍΪÃÜÂëת´¢·¨Ê½¡¢´¹µöµç×ÓÓʼþºÍÖ±½Ó×°ÖÃÇÔÈ¡·¨Ê½¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬2020ÄêÓг¬¹ý80%µÄºÚ¿ÍÈëÇÖ»î¶¯Éæ¼°µ½±©Á¦¹¥»÷»òʹÓÃÃÔʧºÍ±»µÁµÄƾ֤¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://enterprise.verizon.com/resources/reports/dbir/2020/introduction/


¾©¹«Íø°²±¸11010802024551ºÅ