˼¿ÆÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´ASAºÍFTDÖеÄ·¾¶±éÀúÎó²î£»£»£»D-Link·ÓÉÆ÷¹Ì¼þδ¼ÓÃܵľµÏñ¿Éй¶¼ÓÃÜÃÜÔ¿ Ô´´ άËûÃü άËûÃüÇå¾² ½ñÌì
Ðû²¼Ê±¼ä 2020-07-241.˼¿ÆÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´ASAºÍFTDÖеÄ·¾¶±éÀúÎó²î
˼¿ÆÒÑÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´×Ô˳ӦÇå¾²×°±¸£¨ASA£©Èí¼þºÍFirepowerÍþв·ÀÓù£¨FTD£©Èí¼þWebЧÀÍÖеÄ·¾¶±éÀúÎó²î£¨CVE-2020-3452£©¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÊÇÓÉÓÚÊÜÓ°Ïì×°±¸´¦Öóͷ£µÄHTTPÇëÇóÖеÄURLȱ·¦×¼È·µÄÊäÈëÑéÖ¤ËùÖ£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͰüÀ¨Ä¿Â¼±éÀú×Ö·ûÐòÁеÄÌØÖÆHTTPÇëÇóÀ´Ê¹ÓôËÎó²î¡£¡£¡£¡£¡£¡£¡£¡£ÀֳɵÄʹÓú󣬣¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚÄ¿µÄ×°±¸ÉÏÉó²éWebЧÀÍÎļþϵͳÄÚµÄí§ÒâÎļþ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÁËAnyConnect»òWebVPNÉèÖõÄASAºÍFTDÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://us-cert.cisa.gov/ncas/current-activity/2020/07/23/cisco-releases-security-updates-asa-and-ftd-software
2.¿¨°Í˹»ù·¢Ã÷LazarusʹÓöñÒâÈí¼þMATAÇÔÈ¡Êý¾Ý
¿¨°Í˹»ù×î½ü·¢Ã÷³¯ÏÊ¿Í×éÖ¯LazarusʹÓöñÒâÈí¼þ¿ò¼ÜMATA¾ÙÐÐÀÕË÷Èí¼þ¹¥»÷ºÍÊý¾Ý͵ÇÔ£¬£¬£¬£¬£¬Õë¶Ô¶à¸ö¹ú¼ÒºÍµØÇøµÄ¹«Ë¾£¬£¬£¬£¬£¬°üÀ¨²¨À¼¡¢µÂ¹ú¡¢ÍÁ¶úÆä¡¢º«¹ú¡¢ÈÕ±¾ºÍÓ¡¶È¡£¡£¡£¡£¡£¡£¡£¡£LazarusµÄÄ¿µÄ°üÀ¨µ«²»ÏÞÓÚÈí¼þ¿ª·¢¹«Ë¾¡¢»¥ÁªÍøÐ§ÀÍÌṩÉ̺͵ç×ÓÉÌÎñ¹«Ë¾¡£¡£¡£¡£¡£¡£¡£¡£MATAÊÇÒ»¸öÄ£¿£¿£¿£¿é»¯¿ò¼Ü£¬£¬£¬£¬£¬¿ÉÓÃÓÚѬȾWindows¡¢LinuxºÍmacOSϵͳ¡£¡£¡£¡£¡£¡£¡£¡£ÔÚ¹¥»÷Àú³ÌÖУ¬£¬£¬£¬£¬ºÚ¿ÍʹÓÃMATA½«¶à¸ö²å¼þ¼ÓÔØµ½ÊÜѬȾϵͳµÄÄÚ´æÖУ¬£¬£¬£¬£¬ÔËÐÐÏÂÁ£¬£¬£¬£¬Ê¹ÓÃÎļþºÍÀú³Ì£¬£¬£¬£¬£¬×¢ÈëDLL£¬£¬£¬£¬£¬ÔÚWindows×°±¸ÉϽ¨ÉèHTTPÊðÀíºÍËíµÀ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/lazarus-hackers-deploy-ransomware-steal-data-using-mata-malware/
3.D-Link·ÓÉÆ÷¹Ì¼þδ¼ÓÃܵľµÏñ¿Éй¶¼ÓÃÜÃÜÔ¿
Çå¾²Ñо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬£¬D-Link·ÓÉÆ÷¹Ì¼þδ¼ÓÃܵľµÏñ¿Éй¶¼ÓÃÜÃÜÔ¿¡£¡£¡£¡£¡£¡£¡£¡£ÔÚ×îÏÈÆÊÎöʱ£¬£¬£¬£¬£¬Ñо¿Ö°Ô±´ÓÍøÕ¾ÏÂÔØÁËD-Link¹Ì¼þ£¨ 1.02B03°æ±¾£©£¬£¬£¬£¬£¬È»ºóʹÓÃBinwalk¾ÙÐÐÆÊÎö£¬£¬£¬£¬£¬·¢Ã÷ÁËÁ½¸ö¹Ì¼þÎļþDIR3040A1_FW102B03.binºÍDIR3040A1_FW102B03_uncrypted.bin¡£¡£¡£¡£¡£¡£¡£¡£ÔÚÔËÐÐÒÔuncrypted×îºóµÄÎļþʱ·¢Ã÷£¬£¬£¬£¬£¬¸Ã¾µÏñ°üÀ¨Î´¼ÓÃܵĹ̼þ¶þ½øÖÆÎļþ £¬£¬£¬£¬£¬È»ºóËûÃÇ¿ÉÒÔÌáÈ¡²¢ÆÊÎö´æ´¢µÄ½âÃÜÃÜÔ¿¡£¡£¡£¡£¡£¡£¡£¡£¾ÓɽøÒ»²½ÆÊÎö£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷½âÃܺͼÓÃÜÃÜÔ¿¾ù±»Ç¶Èë¶þ½øÖÆÎļþÖС£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/d-link-blunder-firmware-encryption-key-exposed-in-unencrypted-image/
4.еĽ©Ê¬ÍøÂçPrometeiʹÓÃWindows SMBÍÚ¾ò¼ÓÃÜÇ®±Ò
˼¿ÆTalosÔÚÒ°Íâ·¢Ã÷ÁËÒ»¸öеĽ©Ê¬ÍøÂçPrometei£¬£¬£¬£¬£¬ÆäʹÓÃMicrosoft Windows SMBÐÒéºáÏòÒÆ¶¯£¬£¬£¬£¬£¬Í¬Ê±ÉñÃØµØÍÚ¾ò¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£¡£¡£¡£¸Ã½©Ê¬ÍøÂç×ܹ²ÓÐ15¸ö¿ÉÖ´ÐÐÄ£¿£¿£¿£¿é£¬£¬£¬£¬£¬ÕâЩģ¿£¿£¿£¿éÓÉÒ»¸öÖ÷Ä£¿£¿£¿£¿é¿ØÖÆ£¬£¬£¬£¬£¬ÓÐÁ½¸öÖ÷Òª¹¦Ð§·ÖÖ§£ºÒ»¸öÊÇC ++·ÖÖ§£¬£¬£¬£¬£¬×¨ÃÅÓÃÓÚ¼ÓÃÜÇ®±ÒÍÚ¾ò²Ù×÷£»£»£»ÁíÒ»¸öÊÇ»ùÓÚ.NETµÄ·ÖÖ§£¬£¬£¬£¬£¬×¨ÃÅÓÃÓÚÆ¾Ö¤ÍµÇÔ£¬£¬£¬£¬£¬ÀÄÓÃSMBºÍ»ìÏý¡£¡£¡£¡£¡£¡£¡£¡£PrometeiÊ×ÏÈͨ¹ýʹÓÃEternal BlueµÈSMBÎó²îÆÆËðÅÌËã»úµÄWindows ServerÐÂÎſ飨SMB£©ÐÒé¡£¡£¡£¡£¡£¡£¡£¡£È»ºóʹÓÃMimikatzºÍ±©Á¦¹¥»÷À´É¨Ãè¡¢´æ´¢ºÍ͵ȡƾ֤£¬£¬£¬£¬£¬²¢½«·¢Ã÷µÄËùÓÐÃÜÂë·¢Ë͵½ÏÂÁîºÍ¿ØÖÆ£¨C2£©Ð§ÀÍÆ÷£¬£¬£¬£¬£¬ÒÔ¹©ÆäËûÄ£¿£¿£¿£¿éʹÓᣡ£¡£¡£¡£¡£¡£¡£¸ÃºÚ¿Í×éÖ¯µÄһ̨C2ЧÀÍÆ÷ÔÚ6Ô±»²é·â£¬£¬£¬£¬£¬µ«ÕâËÆºõ¶ÔPrometeiµÄ»î¶¯Ã»ÓÐÈκÎʵÖÊÐÔÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/prometei-botnet-is-infecting-machines-to-mine-for-cryptocurrency/#ftag=RSSbaffb68
5.½©Ê¬ÍøÂçEmotet×îÏÈ´ó×Ú·Ö·¢¶ñÒâÈí¼þQakBot
Ñо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬£¬½©Ê¬ÍøÂçEmotet×îÏȸßËٵطַ¢¶ñÒâÈí¼þQakBot£¬£¬£¬£¬£¬È¡´úÁË֮ǰºã¾ÃʹÓõÄTrickBot¡£¡£¡£¡£¡£¡£¡£¡£Çå¾²Ñо¿Ô±Bom·¢Ã÷ÁËÒ»¸öQakBotÑù±¾£¬£¬£¬£¬£¬²¢Ê¹ÓÃAny.Run¾ÙÐÐÆÊÎö£¬£¬£¬£¬£¬·¢Ã÷ÁËÆäÏÂÁîºÍ¿ØÖÆÐ§ÀÍÆ÷£¨C2£©µØµãµÄÁÐ±í¡£¡£¡£¡£¡£¡£¡£¡£ÍøÂç·¸·¨Ç鱨¹«Ë¾Intel 471½øÒ»²½ÆÊÎöÏÔʾ£¬£¬£¬£¬£¬´ËQBotÑù±¾ÖеÄ×Ö·û´®partner01Åú×¢£¬£¬£¬£¬£¬Emotet´Ë´Î»î¶¯ÓкÜÇ¿µÄÁªÏµ¡£¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬Éв»ÇåÎúQakBot»áÔÚÊÜѬȾµÄϵͳÉϰ²ÅÅʲô£¬£¬£¬£¬£¬µ«Ò»Ð©Êܺ¦Õß¿ÉÄÜ»áѬȾÀÕË÷Èí¼þ£¬£¬£¬£¬£¬ÓÈÆäÊÇProLock¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/emotet-botnet-is-now-heavily-spreading-qakbot-malware/
6.Ô¼¿Ë´óѧÔâÊý¾Ýй¶£¬£¬£¬£¬£¬»òÒòBlackbaudѬȾÀÕË÷Èí¼þ
Ô¼¿Ë´óѧÅû¶ÆäÔâµ½ÁËÊý¾Ýй¶£¬£¬£¬£¬£¬Ô±¹¤ºÍѧÉúÊý¾Ý±»µÁ£¬£¬£¬£¬£¬ÓëÆäµÚÈý·½ÔÆÅÌËãÌṩÉÌBlackbaudÓÚ2020Äê5ÔÂÔâµ½µÄÀÕË÷Èí¼þ¹¥»÷Óйء£¡£¡£¡£¡£¡£¡£¡£¸Ã´óѧÉÐδÅû¶¿ÉÄÜÊܵ½Ó°ÏìµÄСÎÒ˽¼ÒÊýÄ¿£¬£¬£¬£¬£¬µ«ÌåÏÖ´Ë´Îй¶µÄÊý¾Ý¿ÉÄܰüÀ¨ÁËÐÕÃû¡¢Ö°³Æ¡¢ÐԱ𡢳öÉúÈÕÆÚ¡¢Ñ§Éú±àºÅ¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØµã¡¢ÏÖʵµØµãºÍLinkedInСÎÒ˽¼Ò×ÊÁϼͼ¡¢¿Î³ÌÐÅÏ¢¡¢Ëù»ñµÃµÄ×ʸñ¡¢ÓйؿÎÍâ»î¶¯µÄÏêϸÐÅÏ¢¡¢Ö°Òµ¡¢¹ÍÖ÷¡¢ÊÓ²ì»Ø¸´ÒÔ¼°ÒѼͼµÄУÓѻºÍ³ï¿î»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜBlackbaudÒѾ֧¸¶Êê½ð£¬£¬£¬£¬£¬µ«²»¿É°ü¹ÜÊý¾ÝÒѰ´ÐÒéÏú»Ù£¬£¬£¬£¬£¬Òò´Ë¸Ã´óѧ»¹Õö¿ªÁË×Ô¼ºµÄÊӲ죬£¬£¬£¬£¬²¢½«´ËÊÂÎñ¼û¸æÊÂÇéÖ°Ô±¡¢Ñ§ÉúºÍÓ¢¹úÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/university-of-york-discloses-data-breach-staff-and-student-records-stolen/#ftag=RSSbaffb68


¾©¹«Íø°²±¸11010802024551ºÅ