Ñо¿Ö°Ô±Åû¶IBMÆóÒµÇå¾²Èí¼þÖеÄ4¸ö0day£»£»£»£»£»£»ÍÐÂ×˹ÊÐÔâdoppelpaymer¹¥»÷ £¬£¬£¬£¬£¬200GBÊý¾Ý±»µÁ

Ðû²¼Ê±¼ä 2020-04-23

1.Ñо¿Ö°Ô±Åû¶IBMÆóÒµÇå¾²Èí¼þÖеÄ4¸ö0day


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Çå¾²Ñо¿Ö°Ô±ÔÚÆÊÎöIBM Data Risk Manager£¨IDRM£©Ê±·¢Ã÷ÁË4¸ö0day £¬£¬£¬£¬£¬»®·ÖΪÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î¡¢ÏÂÁî×¢ÈëÎó²î¡¢²»Çå¾²µÄĬÈÏÃÜÂëÎó²îÒÔ¼°í§ÒâÎļþÏÂÔØÎó²î¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩÎó²î¿ÉÒÔµ¥¶ÀʹÓÃÒ²¿ÉÒÔ×éºÏʹÓà £¬£¬£¬£¬£¬×éºÏʹÓÃǰÈý¸öÎó²î¿ÉÒÔʹ¹¥»÷ÕßÒÔrootȨÏÞÔ¶³ÌÖ´ÐдúÂë £¬£¬£¬£¬£¬×éºÏʹÓõÚÒ»¸öºÍµÚËĸöÎó²î¿ÉÒÔʹδÊÚȨµÄ¹¥»÷ÕßÏÂÔØí§ÒâÎļþ¡£¡£¡£¡£¡£¡£¡£¡£Îó²îµÄÅû¶ÕßRibeiroÌåÏÖ £¬£¬£¬£¬£¬IDRMÊÇ´¦Öóͷ£Ãô¸ÐÐÅÏ¢µÄÆóÒµÇå¾²²úÆ· £¬£¬£¬£¬£¬ÈôÊÇÆäÔâµ½¹¥»÷»áµ¼Ö¹«Ë¾ÀûÒæÑÏÖØÊÜË𠣬£¬£¬£¬£¬Òò´ËÔÚIBM¾Ü¾ø½ÓÊÜÎó²î±¨¸æºóÑ¡Ôñ½«ÆäÐû²¼³öÀ´¡£¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ £¬£¬£¬£¬£¬IBM¹«Ë¾ÐÞ¸´ÁËIDRM2.0.1¼°¸ü¸ß°æ±¾ÖеÄí§ÒâÎļþÏÂÔØÎó²îºÍÏÂÁî×¢ÈëÎó²î £¬£¬£¬£¬£¬²¢ÇÒÕýÔÚÊÓ²ìÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/researcher-discloses-four-ibm-zero-days-after-refusal-to-fix/


2.Çå¾²³§ÉÌZecOpsÅû¶Apple iOSÖÐ2¸ö0day


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Çå¾²³§ÉÌZecOpsÔÚÉÏÖÜÈýÅû¶ÁËApple iOSÖеÄ2¸ö0day £¬£¬£¬£¬£¬»®·ÖΪԶ³Ì¶ÑÒç³öÎó²îºÍÔ½½çдÈëÎó²î £¬£¬£¬£¬£¬Îó²îÓ°ÏìÁËiOS 6µ½iOS 13.4.1µÄËùÓа汾 £¬£¬£¬£¬£¬¶øiOS 6֮ǰµÄ°æ±¾Ò²¿ÉÄÜ»áÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£¡£ZecOpsÑо¿·¢Ã÷ £¬£¬£¬£¬£¬¸ÃÎó²î×Ô2018Äê1Ô±㱣´æ £¬£¬£¬£¬£¬ºÚ¿Í¿ÉÒÔͨ¹ýÏòiOS MobileMail·¢ËͶñÒâÓʼþÀ´´¥·¢Îó²î £¬£¬£¬£¬£¬×ÔÎó²î±»·¢Ã÷ÒÔÀ´ £¬£¬£¬£¬£¬ÖÁÉÙÒѾ­ÓÐÁù¸öºÚ¿Í×éÖ¯ÔÚÑо¿ÔõÑùʹÓᣡ£¡£¡£¡£¡£¡£¡£ZecOpsÌåÏÖ¹¥»÷ÕßÐèÒªÁ¬ÏµinfoleakÎó²îºÍÄÚºËÎó²î²Å»ª¶ÔIOSÔì³ÉΣº¦ £¬£¬£¬£¬£¬¶øApple¹«Ë¾ÖÁ½ñÒÀȻδ¶Ô´ËÊÂ×÷³ö»ØÓ¦¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.darkreading.com/mobile/apple-ios-zero-day-vulnerabilities-exploited-in-targeted-attacks/d/d-id/1337625


3.ÍÐÂ×˹ÊÐÔâdoppelpaymer¹¥»÷ £¬£¬£¬£¬£¬200GBÊý¾Ý±»µÁ


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ÂåÉ¼í¶µÄÍÐÂ×˹ÊÐÔâµ½ÀÕË÷Èí¼þDoppelPaymer¹¥»÷ £¬£¬£¬£¬£¬Æäδ¼ÓÃܵÄÊý¾Ý±»µÁ²¢±»ÀÕË÷100±ÈÌØ±Ò£¨689,147ÃÀÔª£©µÄÊê½ð¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷±¬·¢ÔÚ3ÔÂ1ÈÕ £¬£¬£¬£¬£¬DoppelPaymerÍÅ»ïÉù³ÆËûÃÇ͵ȡÁËÁè¼Ý200GBµÄÊý¾Ý£¨°üÀ¨8067¸öĿ¼ÖеÄ269123¸öÎļþ£©²¢ÇÒɾ³ýÁËÍÐÂ×˹Êеı¸·Ý £¬£¬£¬£¬£¬Ö®ºó¶Ô¸ÃÊÐԼĪ150̨ЧÀÍÆ÷ºÍ500¸öÊÂÇéÕ¾¾ÙÐÐÁ˼ÓÃÜ¡£¡£¡£¡£¡£¡£¡£¡£BleepingComputerÒÑÓëÍÐÂ×˹ÊÐÁªÏµÒÔÈ·ÈϹ¥»÷ £¬£¬£¬£¬£¬µ«ÏÖÔÚδÊÕµ½»Ø¸´¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/doppelpaymer-ransomware-hits-los-angeles-county-city-leaks-files/


4.ºÚ¿ÍʹÓÃÌØ¹¤Èí¼þAgent Tesla¹¥»÷È«ÇòÄÜÔ´¹«Ë¾


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ºÚ¿Íð³ä°£¼°¹¤³Ì³Ð°üÉÌEnppi £¬£¬£¬£¬£¬ÓÃÌØ¹¤Èí¼þAgent Tesla¶ÔÈ«Çò¹æÄ£ÄÚµÄÄÜÔ´¹«Ë¾ÌᳫÓã²æÊ½´¹ÂÚ¹¥»÷ £¬£¬£¬£¬£¬Êܺ¦ÕßÖ÷ÒªÀ´×ÔʯÓͺÍ×ÔÈ»Æø¡¢Ä¾Ì¿¼Ó¹¤¡¢Ë®Á¦·¢µçÕ¾¡¢Ô­ÖÊÁÏÖÆÔìºÍ´óÐÍÉÌÆ·ÔËÊäµÈÐÐÒµ¡£¡£¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷Ö÷ÒªÕë¶ÔλÓÚÂíÀ´Î÷ÑÇ £¬£¬£¬£¬£¬ÃÀ¹ú £¬£¬£¬£¬£¬ÒÁÀÊ £¬£¬£¬£¬£¬ÄÏ·Ç £¬£¬£¬£¬£¬°¢ÂüºÍÍÁ¶úÆäÒÔ¼°·ÆÂɱöµÄ¹«Ë¾ £¬£¬£¬£¬£¬×ܹ²ÌᳫÁËÁ½´Î¡£¡£¡£¡£¡£¡£¡£¡£µÚÒ»´Î¹¥»÷ÊÇÔÚ3ÔÂ31ÈÕÖÁ4ÔÂ6ÈÕ¾ÙÐÐµÄ £¬£¬£¬£¬£¬ºÚ¿Íð³äEnppiÉù³Æ´ú±í×ÔÈ»Æø¹«Ë¾£¨Burullus£©Ô¼ÇëÊܺ¦Õß¼ÓÈëRosetta¹²ÏíÉèÊ©ÏîÄ¿ £¬£¬£¬£¬£¬²¢ÓÕʹÆä·­¿ªÎ±×°³É¸½¼þµÄÌØ¹¤Èí¼þ¡£¡£¡£¡£¡£¡£¡£¡£µÈÓû§·­¿ª¸½¼þºó £¬£¬£¬£¬£¬Ìع¤Èí¼þÇÔÈ¡Ãô¸ÐÐÅÏ¢ºÍÖÖÖÖÆ¾Ö¤ £¬£¬£¬£¬£¬È»ºó½«ÕâЩÊý¾Ý·¢Ë͵½C2ЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£¡£µÚ¶þ´Î¹¥»÷ÊÇÔÚ4ÔÂ12ÈÕ×îÏ鵀 £¬£¬£¬£¬£¬ºÚ¿Íͨ¹ýÓʼþ֪ͨÊܺ¦Õß·¢ËÍÔ¤¼Æ¿Ú°¶Ö§¸¶ÕË»§ÐÅÏ¢ £¬£¬£¬£¬£¬Óʼþ¸½¼þÖÐÒÀÈ»°üÀ¨Ìع¤Èí¼þAgent Tesla¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/oil-and-gas-agent-tesla-spyware/154973/


5.BeaumontÒ½ÔºÔâºÚ¿Í¹¥»÷ £¬£¬£¬£¬£¬Áè¼Ý10Íò»¼ÕßÐÅϢй¶


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


µ×ÌØÂÉÒ½ÁÆ×éÖ¯BeaumontÈ·ÈÏÆäÍøÕ¾Ôâµ½ºÚ¿Í¹¥»÷ £¬£¬£¬£¬£¬Ô¼ÄªÓÐ112000Ãû»¼ÕßµÄÐÅÏ¢±»ÇÔ £¬£¬£¬£¬£¬°üÀ¨ÐÕÃû¡¢³öÉúÈÕÆÚ¡¢Éç»á°ü¹ÜºÅ¡¢Ò½ÁÆ×´Ì¬ £¬£¬£¬£¬£¬ÉõÖÁÉÐÓÐһЩÓû§µÄÒøÐÐÕË»§Êý¾ÝºÍ¼ÝÕÕºÅÂë¡£¡£¡£¡£¡£¡£¡£¡£¾ÝϤ £¬£¬£¬£¬£¬ºÚ¿ÍÊÇÔÚ2019Äê5ÔÂ23ÈÕÖÁ2019Äê6ÔÂ3ÈÕ¶ÔÍøÕ¾Ô±¹¤Ìá³«ÍøÂç´¹ÂÚ¹¥»÷²¢ÇÔÈ¡Êý¾ÝµÄ £¬£¬£¬£¬£¬¶øBeaumontÒ½ÔºÊÇ3ÔÂ29ÈÕ·¢Ã÷µÄ´Ë´Î¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£µ«BeaumontÒ½ÔºÌåÏÖÖÁ½ñ±»Ð¹Â¶µÄÊý¾Ý¶¼Ã»Óб»ÀÄÓà £¬£¬£¬£¬£¬¶øÊܺ¦ÕßҲȱ·¦Ò½Ôº½üÒ»Ä껼ÕßÊýÄ¿µÄ5%¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.cyberscoop.com/beaumont-health-data-breach/


6.Burning Shed¹«Ë¾ÔâºÚ¿Í¹¥»÷ £¬£¬£¬£¬£¬Óû§ÐÅÏ¢±»ÇÔ


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


×ÔÁ¦³ªÆ¬¹«Ë¾Burning ShedÔâµ½ºÚ¿Í¹¥»÷ £¬£¬£¬£¬£¬ÆäÓû§µÄÓÊÏ䵨µãºÍ¼ÓÃÜÃÜÂë±»ÇÔÈ¡¡£¡£¡£¡£¡£¡£¡£¡£È¥Äê12ÔÂ18ÈÕºÚ¿ÍÇÖÈëÁËBurning Shed´æÓÐÓû§ÐÅÏ¢µÄÊý¾Ý¿â²¢ÍµÈ¡Êý¾Ý £¬£¬£¬£¬£¬ËùÐÒ¸ÃÊý¾Ý¿âÄÚ²¢²»°üÀ¨Óû§ÐÅÓÿ¨ºÍPayPalµÈ²ÆÎñÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£Burning Shed¹«Ë¾ÊÇÔÚ4ÔÂ17ÈÕ·¢Ã÷´Ë´Î¹¥»÷µÄ £¬£¬£¬£¬£¬²¢Í¨¹ýÓʼþ¼û¸æÆäÓû§¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖÒѾ­¶ÔÍøÕ¾¾ÙÐÐÍÑ»úά»¤ºÍÇå¾²¸üР£¬£¬£¬£¬£¬ÍÑ»ú״̬ԼĪ»áά³Ö48Сʱ £¬£¬£¬£¬£¬Ö®ºóÓû§»á±»ÒªÇó¸ü¸ÄеÄÃÜÂë¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.theregister.co.uk/2020/04/21/burning_shed_hacked/