ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ49ÖÜ

Ðû²¼Ê±¼ä 2019-12-16

>±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2019Äê12ÔÂ09ÈÕÖÁ15ÈÕ¹²ÊÕ¼Çå¾²Îó²î57¸ö£¬£¬ £¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇGoogle Chrome WebAudio´úÂëÖ´ÐÐÎó²î; CA Release Automation DataManagement·´ÐòÁл¯´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»£»£»Advantech DiagAnywhere ServerÎļþ´«ÊäЧÀÍÕ»Òç³öÎó²î£»£»£»£»£»£»£»£»Micrsoft Windows Hyper-VÔ¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»£»£»Adobe AcrobatºÍReader CVE-2019-16445ÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î¡£¡£¡£¡£ ¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇĪ˹¿Æ¶¼»á¼à¿ØÏµÍ³»á¼ûȨÏÞÔÚ°µÍø³öÊÛ£»£»£»£»£»£»£»£»¿ÆÂÞÀ­¶àÖÝITЧÀÍÉÌCTSÔâµ½ÀÕË÷Èí¼þ¹¥»÷£»£»£»£»£»£»£»£»ÀÕË÷Èí¼þSnatch¿Éͨ¹ýÇå¾²Ä£Ê½ÖØÆôÀ´Èƹýɱ¶¾Èí¼þ£»£»£»£»£»£»£»£»Î¢ÈíÖÒÑÔ·¸·¨ÍÅ»ïGALLIUM¹¥»÷È«ÇòµÄµçÐŹ«Ë¾£»£»£»£»£»£»£»£»¶ñÒâÈí¼þKrampus-3PCÖ÷ÒªÃé×¼iphoneÓû§¡£¡£¡£¡£ ¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬ £¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£ ¡£


>Ö÷ÒªÇå¾²Îó²îÁбí


1. Google Chrome WebAudio´úÂëÖ´ÐÐÎó²î


Google Chrome WebAudio±£´æÇå¾²Îó²î£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇ󣬣¬ £¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣»£»£»£»£»£»£»òÖ´ÐÐí§Òâ´úÂ룬£¬ £¬£¬£¬ÏÖÔÚÒѾ­ÔÚҰʹÓᣡ£¡£¡£ ¡£

https://chromereleases.googleblog.com/2019/10/stable-channel-update-for-desktop_31.html


2. CA Release Automation DataManagement·´ÐòÁл¯´úÂëÖ´ÐÐÎó²î


CA Release Automation DataManagement service±£´æ·´ÐòÁл¯Îó²î£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬ £¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£ ¡£


https://seclists.org/bugtraq/2019/Dec/16


3. Advantech DiagAnywhere ServerÎļþ´«ÊäЧÀÍÕ»Òç³öÎó²î


Advantech DiagAnywhere ServerÎļþ´«ÊäЧÀͱ£´æÕ»Òç³öÎó²î£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬ £¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣»£»£»£»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£ ¡£

https://www.auscert.org.au/bulletins/ESB-2019.4660/


4. Micrsoft Windows Hyper-VÔ¶³Ì´úÂëÖ´ÐÐÎó²î


Micrsoft Windows Hyper-V±£´æÎ´Ã÷Çå¾²Îó²î£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬ £¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣»£»£»£»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£ ¡£

https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1471


5. Adobe AcrobatºÍReader CVE-2019-16445ÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î


Adobe AcrobatºÍReader´¦Öóͷ£ÄÚ´æ±£´æÊͷźóʹÓÃÎó²î£¬£¬ £¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇ󣬣¬ £¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬ £¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣»£»£»£»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£ ¡£

https://helpx.adobe.com/security/products/acrobat/apsb19-55.html


>Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢ÄªË¹¿Æ¶¼»á¼à¿ØÏµÍ³»á¼ûȨÏÞÔÚ°µÍø³öÊÛ


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


MBKh MediaÊÓ²ì¼ÇÕßAndrey Kaganskikh·¢Ã÷Ī˹¿Æ¶¼»á¼à¿ØÏµÍ³ºÍÃæ²¿Ê¶±ðÊý¾ÝµÄ»á¼ûȨÏÞÕýÔÚµØÏÂÂÛ̳ºÍ̸ÌìÊÒÖгöÊÛ¡£¡£¡£¡£ ¡£AndreyÌåÏÖÂô·½ÊÇÖ´·¨Ö°Ô±/Õþ¸®¹ÙÔ±£¬£¬ £¬£¬£¬¿ÉÒԵǼĪ˹¿Æ¶¼»á¼àÊÓϵͳµÄÊý¾Ý´¦Öóͷ£ºÍ´æ´¢¼¯³ÉÖÐÐÄ£¨YTKD£©¡£¡£¡£¡£ ¡£¹ºÖÃÁËÉãÏñͷȨÏÞµÄÓû§½«»áÊÕµ½Ö¸Ïò¶¼»áCCTVϵͳµÄÒ»¸öÁ´½Ó£¬£¬ £¬£¬£¬¸ÃÁ´½Ó¿É»á¼ûËùÓй«¹²ÉãÏñÍ·£¬£¬ £¬£¬£¬Æä¿ÉÓÃʱ¼äΪ5Ìì¡£¡£¡£¡£ ¡£±ðµÄ£¬£¬ £¬£¬£¬¾ßÓÐÎÞÏÞ»á¼ûȨÏ޵ĵǼƾ֤¼ÛǮΪ30000¬²¼£¨470ÃÀÔª£©¡£¡£¡£¡£ ¡£ÊÓ²ìÖ°Ô±²âÊÔÁËÆäÕÕÆ¬£¬£¬ £¬£¬£¬Âô·½·µ»ØÁË238ÕÅͼƬ£¬£¬ £¬£¬£¬ÕâЩͼƬÀ´×Ô140̨ÉãÏñÍ·£¬£¬ £¬£¬£¬»¹ÁгöÁ˲¶»ñµ½µÄÏêϸµØµãºÍʱ¼ä£¬£¬ £¬£¬£¬µ«·µ»ØµÄÕÕÆ¬¶¼²»ÊÇÊÓ²ìÖ°Ô±µÄ£¬£¬ £¬£¬£¬Õâ¿ÉÄÜÓëÉãÏñÍ·µÄÊýÄ¿ºÍËã·¨ÓйØ£¬£¬ £¬£¬£¬ÏµÍ³¶ÔÆäÃæ²¿ÌØÕ÷µÄÆÀ¹ÀÏàËÆ¶ÈΪ67%¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/moscow-cops-sell-access-to-city-cctv-facial-recognition-data/


2¡¢¿ÆÂÞÀ­¶àÖÝITЧÀÍÉÌCTSÔâµ½ÀÕË÷Èí¼þ¹¥»÷


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


¿ÆÂÞÀ­¶àÖÝITЧÀÍÉÌCTSÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬ £¬£¬£¬²¨¼°100¶à¼ÒÑÀ¿ÆÕïËù¡£¡£¡£¡£ ¡£CTSרΪÑÀ¿ÆÕïËùÌṩITЧÀÍ£¬£¬ £¬£¬£¬°üÀ¨ÍøÂçÇå¾²¡¢Êý¾Ý±¸·ÝºÍIPÓïÒôµç»°µÈ¡£¡£¡£¡£ ¡£¸Ã¹«Ë¾ÓÚ11ÔÂ25ÈÕÔâµ½¹¥»÷£¬£¬ £¬£¬£¬µ¼ÖÂ100¶à¼ÒÑÀ¿ÆÕïËùµÄÅÌËã»úѬȾÁËÀÕË÷Èí¼þSodinokibi¡£¡£¡£¡£ ¡£CTS¾Ü¾øÁ˹¥»÷ÕßË÷Òª70ÍòÃÀÔªÊê½ðµÄÒªÇ󣬣¬ £¬£¬£¬ÓÉÓÚϵͳһֱÖÐÖ¹£¬£¬ £¬£¬£¬ÏÖÔÚÐí¶àÑÀ¿ÆÕïËùÈÔÈ»ÎÞ·¨Õý³£ÓªÒµ¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://krebsonsecurity.com/2019/12/ransomware-at-colorado-it-provider-affects-100-dental-offices/


3¡¢ÀÕË÷Èí¼þSnatch¿Éͨ¹ýÇå¾²Ä£Ê½ÖØÆôÀ´Èƹýɱ¶¾Èí¼þ


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ÀÕË÷Èí¼þSnatchÕýÔÚʹÓÃÒ»ÖÖǰËùδ¼ûµÄ¼¼ÇÉÀ´Èƹýɱ¶¾Èí¼þ£¬£¬ £¬£¬£¬ÏêϸÀ´Ëµ£¬£¬ £¬£¬£¬Ëü¿ÉÒÔ½«Êܺ¦ÕßµÄÅÌËã»úÒÔÇå¾²Ä£Ê½ÖØÐÂÆô¶¯£¬£¬ £¬£¬£¬È»ºóÔËÐмÓÃÜÀú³Ì¡£¡£¡£¡£ ¡£´ó´ó¶¼É±¶¾Èí¼þ¶¼ÎÞ·¨ÔÚWindowsÇ徲ģʽÏÂÆô¶¯£¬£¬ £¬£¬£¬Òò´ËSnatchÄÑÒÔ±»¼ì²âµ½¡£¡£¡£¡£ ¡£Æ¾Ö¤Sophos LabsµÄ±¨¸æ£¬£¬ £¬£¬£¬¸ÃÀÕË÷Èí¼þͨ¹ýWindows×¢²á±íÏîÌí¼ÓÁËÒ»¸öÔÚÇ徲ģʽÏÂÆô¶¯µÄЧÀÍ£¬£¬ £¬£¬£¬¸ÃЧÀͽ«ÔËÐÐSnatch¡£¡£¡£¡£ ¡£Ñо¿Ö°Ô±ÖÒÑÔ³ÆÕâÖÖģʽ¿ÉÄܻᱻÆäËüÀÕË÷Èí¼þËùÄ£Äâ¡£¡£¡£¡£ ¡£Snatch×Ô2018ÄêÏÄÈÕÒÔÀ´Ò»Ö±»îÔ¾£¬£¬ £¬£¬£¬ÆäÖ÷Òª¾ÙÐÐÕë¶ÔÐԵĹ¥»÷¡£¡£¡£¡£ ¡£Óë´ó´ó¶¼ÀÕË÷Èí¼þ²î±ð£¬£¬ £¬£¬£¬Snatch»¹»áÇÔÈ¡ÊÜѬȾϵͳÉϵÄÎļþ¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/snatch-ransomware-reboots-pcs-in-windows-safe-mode-to-bypass-antivirus-apps/


4¡¢Î¢ÈíÖÒÑÔ·¸·¨ÍÅ»ïGALLIUM¹¥»÷È«ÇòµÄµçÐŹ«Ë¾


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


΢ÈíÍþвÇ鱨ÖÐÐÄ£¨MSTIC£©ÖÒÑÔ·¸·¨ÍÅ»ïGALLIUMÕýÔÚÕë¶ÔÌìϸ÷µØµÄµçÐÅЧÀÍÉ̾ÙÐÐÒ»Á¬Ò»Ö±µÄ¹¥»÷¡£¡£¡£¡£ ¡£¸Ã·¸·¨ÍÅ»ï¾ÙÐÐÁ˶à¸ö¹¥»÷»î¶¯£¬£¬ £¬£¬£¬MSTICÊӲ쵽Õë¶Ô¶«ÄÏÑÇ¡¢Å·Ö޺ͷÇÖ޵ĵçÐÅÔËÓªÉ̵Ĺ¥»÷¡£¡£¡£¡£ ¡£GALLIUMÖ÷Ҫͨ¹ýδ´ò²¹¶¡µÄWildFly/JBossЧÀÍÆ÷¾ÙÐÐÈëÇÖ£¬£¬ £¬£¬£¬Ò»µ©ÉøÍ¸µ½×éÖ¯µÄÍøÂçÖУ¬£¬ £¬£¬£¬GALLIUM±ã×îÏÈʹÓÃ×Ô½ç˵µÄ¶ñÒâÈí¼þÔÚÆóÒµÍøÂçÖкáÏòÒÆ¶¯ºÍÍøÂçÓòƾ֤¡£¡£¡£¡£ ¡£GALLIUM»¹Ê¹ÓÃSoftEther VPNÈí¼þÀ´ÔöÇ¿¶ÔÄ¿µÄÍøÂçµÄ»á¼ûºÍ¼á³Ö³¤ÆÚÐÔ¡£¡£¡£¡£ ¡£Æ¾Ö¤MSTICµÄ±¨¸æ£¬£¬ £¬£¬£¬GALLIUMµÄTTPºÍ¸Ã×é֯ʹÓõIJ¿·ÖÓòÓë2018ÄêµÄOperation SoftCellÏàͬ¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-warns-of-gallium-threat-group-attacking-global-telcos/


5¡¢¶ñÒâÈí¼þKrampus-3PCÖ÷ÒªÃé×¼iphoneÓû§


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Ò»¸öÕë¶ÔiPhoneÓû§µÄ¶ñÒâ¹ã¸æÖض¨Ïò»î¶¯ÒѾ­Ó°ÏìÁË100¶à¸ö³öÊéÉÌÍøÕ¾£¬£¬ £¬£¬£¬ÆäÖаüÀ¨ÔÚÏß±¨Ö½ÍøÕ¾ºÍ¹ú¼ÊÿÖÜÐÂÎÅÔÓÖ¾ÍøÕ¾µÈ¡£¡£¡£¡£ ¡£Æ¾Ö¤DSOÍŶӵÄ˵·¨£¬£¬ £¬£¬£¬¸Ã¶ñÒâÈí¼þKrampus-3PCαװ³ÉÔÓ»õµêµÄ³ê±ö¹ã¸æ£¬£¬ £¬£¬£¬´ÓÓû§ÄÇÀïÊվۻỰºÍcookieÐÅÏ¢£¬£¬ £¬£¬£¬²¢ÇÒÔÚÓû§µã»÷¹ã¸æÊ±Öض¨ÏòÖÁÒ»¸öÍøÂçСÎÒ˽¼ÒÐÅÏ¢µÄÐéÎ±ÍøÕ¾¡£¡£¡£¡£ ¡£¹¥»÷ÕßÊ×ÏÈÔÚ¹ã¸æÆ½Ì¨AdtechstackÉÏͶ·Å¹ã¸æ£¬£¬ £¬£¬£¬È»ºóʹÓÃÆ½Ì¨µÄAPI²åÈë¶ñÒâ´úÂ룬£¬ £¬£¬£¬ÕâЩ¶ñÒâ¹ã¸æËæºó±»·Ö·¢¸ø´ó×ÚÍøÕ¾¡£¡£¡£¡£ ¡£Krampus-3PC»á½«ÍøÂçµ½µÄÓû§ÐÅÏ¢·¢ËÍÖÁC2ÓòÃûboostsea2[.]com¡£¡£¡£¡£ ¡£ÏÖÔÚÉв»ÇåÎú¹¥»÷ÕßµÄÉí·Ý¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/krampus-3pc-malware-iphone-users/151043/