Î÷ÃÅ×Ó¶à¿î¹¤Òµ×°±¸ÊÜLinuxÄÚºËÎó²îSegmentSmackÓ°Ïì £»Å·ÖÞÄÜÔ´¹«Ë¾EDPѬȾRagnarLocker

Ðû²¼Ê±¼ä 2020-04-16

1.Î÷ÃÅ×Ó¶à¿î¹¤Òµ×°±¸ÊÜLinuxÄÚºËÎó²îSegmentSmackÓ°Ïì


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


Î÷ÃÅ×ÓÐû²¼4Ô²¹¶¡¸üР £¬ ÆäÖÐ3ÌõÐÂͨ¸æÍ¨Öª¿Í»§Æä¶à¿î¹¤Òµ×°±¸Êܵ½LinuxÄÚºËÎó²îSegmentSmackÓ°Ïì ¡£SegmentSmackºÍFragmentSmack£¨»®·Ö±»¸ú×ÙΪCVE-2018-5390ºÍCVE-2018-5391£©ÊÇÑо¿ÈËJuha-Matti TilliÔÚ2018Äê·¢Ã÷µÄÁ½¸öLinuxÄÚºËÎó²î  £¬¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÄ¿µÄϵͳ·¢ËͶñÒâÊý¾Ý°üÀ´ÌᳫDoS¹¥»÷ ¡£ÔÚµÚÒ»·Ýͨ¸æÖÐÎ÷ÃÅ×Ó³ÆSegmentSmackºÍFragmentSmackÓ°ÏìÁËËüµÄIE/PB-Link×°±¸¡¢RUGGEDCOM·ÓÉÆ÷¡¢»ùÓÚROXµÄVPNÖն˺ͷÀ»ðǽ¡¢SCALANCE·ÓÉÆ÷ºÍ·À»ðǽ¡¢SIMATICͨѶ´¦Öóͷ£Æ÷ºÍSinema Remote Connect ¡£µÚ¶þ·Ýͨ¸æÖÐÎ÷ÃÅ×ÓÅû¶ÓëSegmentSmackÓйصÄDoSÎó²î£¨CVE-2019-19301£©  £¬¸ÃÎó²îÓ°ÏìÁËSIMATICͨѶÄ£¿é¡¢SCALANCE X½»Á÷»úºÍSIPLUS×°±¸ ¡£µÚÈý·Ýͨ¸æÔòÅû¶ÁËÓ°ÏìÎ÷ÃÅ×ÓSIDOORÃÅÖÎÀíϵͳ¡¢SIMATIC×°±¸¡¢SINAMICSת»»Æ÷ºÍSIPLUS²úÆ·µÄDoSÎó²î£¨CVE-2019-19300£© ¡£



Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/siemens-industrial-devices-affected-segmentsmack-linux-kernel-flaw




2.Ó¢ÌØ¶ûÐû²¼4ÔÂÇå¾²¸üР £¬ÐÞ¸´¶à¿î²úÆ·ÖеÄ9¸öÎó²î


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


Ó¢ÌØ¶ûÔÚ4Ô²¹¶¡¸üÐÂÖÐÐÞ¸´ÁË9¸öÎó²î  £¬ÕâЩÎó²î¾ùΪÖиßΣÎó²î  £¬Ó°Ïì¶à¸öÈí¼þ¡¢¹Ì¼þ¼°Æ½Ì¨ ¡£Ó¢ÌضûÐÞ¸´ÁËPROSet/ÎÞÏßWiFi²úÆ·ÔÚWindows 10ÉϵÄÁ½¸öÎó²î-¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÓÉÓÚ²»Çå¾²µÄ¼ÌÐøÈ¨ÏÞ¶ø¿ÉÄÜͨ¹ýÍâµØ»á¼û¾ÙÐÐÌØÈ¨Éý¼¶£¨CVE-2020-0557£© £»ÓÉÓÚÄÚºËÇý¶¯³ÌÐòÖеĻº³åÇøÏÞÖÆ²»µ±  £¬ÎÞÌØÈ¨µÄ¹¥»÷Õß¿ÉÄÜͨ¹ýÏàÁÚÍøÂç»á¼ûÀ´µ¼Ö¾ܾø·þÎñ£¨CVE-2020-0558£© ¡£Ó¢Ìضû»¹ÐÞ¸´ÁËNUC mini PCµÄϵͳ¹Ì¼þÖкÍÄ£¿é»¯·þÎñÆ÷MFS2600KISPPÅÌËãÄ£¿éÖеÄÁ½¸öÎó²î  £¬°üÀ¨²»×¼È·µÄ»º³åÇøÏÞÖÆµ¼ÖµÄLPEÎó²î£¨CVE-2020-0600£©ºÍÌõ¼þ¼ì²é²»µ±µ¼ÖµÄÌáȨÎó²î£¨CVE-2020-0578£© ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/intel-april-platform-update-fixes-high-severity-security-issues/


3.΢ÈíÐû²¼4ÔÂOfficeÇå¾²¸üР £¬ÐÞ¸´55¸öÎó²î


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


΢ÈíÔÚ4ÔÂOfficeÇå¾²¸üÐÂÖÐÕë¶Ô7¸ö²úÆ·ÐÞ¸´ÁË55¸öÎó²î  £¬ÆäÖаüÀ¨Ó°ÏìÁËMicrosoft OfficeºÍMicrosoft Office SharePoint²úÆ·µÄ12¸öRCEÎó²î  £¬ÕâЩÎó²î¾ù±»¹éÀàΪÑÏÖØ»òÖ÷Òª¼¶±ð  £¬¹¥»÷Õß¿ÉÒÔʹÓÃËüÃÇÔÚSharePointÓ¦ÓóÌÐòºÍSharePoint·þÎñÆ÷ÕÊ»§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë ¡£Î¢Èí»¹ÐÞ¸´ÁË10¸öXSSÎó²î  £¬¹¥»÷Õß¿ÉÄÜʹÓÃÕâЩÎó²îÔÚÄ¿½ñÓû§µÄÇå¾²ÉÏÏÂÎÄÖÐÔËÐо籾²¢Ã°³äÓû§¡¢ÇÔÈ¡Ãô¸ÐÊý¾Ý»òδ¾­ÊÚȨÔĶÁÄÚÈÝ ¡£±ðµÄ  £¬Î¢ÈíÐÞ¸´ÁËÁ½¸öÌáȨÎó²îºÍËĸöÓÕÆ­Îó²î ¡£ÏêϸÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-office-april-security-updates-fix-critical-rce-bugs/


4.Å·ÖÞÄÜÔ´¹«Ë¾EDPѬȾRagnarLocker  £¬±»ÀÕË÷½ü1000ÍòÅ·Ôª


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


¿ËÈÕÆÏÌÑÑÀ¿ç¹úÄÜÔ´¾ÞÍ·Energias de Portugal£¨EDP£©Ôâµ½ÀÕË÷Èí¼þRagnarLocker¹¥»÷  £¬±»ÀÕË÷1580 BTCµÄÊê½ð£¨Ô¼ºÏ1090ÍòÃÀÔª»ò990ÍòÅ·Ôª£© ¡£EDP¼¯ÍÅÊÇÅ·ÖÞÄÜÔ´ÐÐÒµ£¨×ÔÈ»ÆøºÍµçÁ¦£©×î´óµÄÔËÓªÉÌÖ®Ò»  £¬Ò²ÊÇÌìϵÚËÄ´ó·çÄÜÉú²úÉÌ ¡£¸Ã¹«Ë¾ÔÚÈ«ÇòËĸö´óÖÞµÄ19¸ö¹ú¼Ò/µØÇøÓµÓÐÓªÒµ  £¬²¢ÇÒÓµÓÐÁè¼Ý11500ÃûÔ±¹¤ºÍΪÁè¼Ý1100Íò¿Í»§ÌṩÄÜÔ´ ¡£ÔÚ¹¥»÷Àú³ÌÖÐ  £¬Ragnar Locker¹¥»÷ÍÅ»ïÉù³ÆÇÔÈ¡ÁËÁè¼Ý10 TBµÄ¹«Ë¾Ãô¸ÐÎļþ  £¬²¢Íþв³ÆÈôÊǸù«Ë¾¾Ü¾øÖ§¸¶Êê½ð  £¬ËûÃǽ«Ðû²¼ÍµÈ¡µÄËùÓÐÊý¾Ý ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ragnarlocker-ransomware-hits-edp-energy-giant-asks-for-10m/


5.TA505¼ÌÐøÊ¹ÓÃSDBbot RATѬȾÆóÒµÍøÂç  £¬Ö÷ÒªÕë¶ÔÅ·ÖÞ


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


IBM X-ForceÍŶÓÊӲ쵽TA505¼ÌÐøÊ¹ÓÃSDBbot RATѬȾÆóÒµÍøÂç ¡£ÔÚ2019Äê11Ô  £¬X-Force IRISÊӲ쵽Óй¥»÷ÕßʹÓÃð³äµÄOnehub´¹ÂÚÓʼþ¹¥»÷Å·ÖÞµÄÆóÒµÔ±¹¤  £¬¸Ã´¹ÂÚÓʼþÖ¼ÔÚÇÔÈ¡Active Directory£¨AD£©Êý¾Ý¼°Óû§Æ¾Ö¤  £¬²¢Ê¹ÓÃSDBbot RATѬȾÆóÒµÍøÂçÇéÐÎ ¡£Æ¾Ö¤Ñо¿Ö°Ô±¶Ô¹¥»÷ÕßµÄTTP¡¢C£¦C»ù´¡ÉèÊ©ÒÔ¼°ÏÈǰ¹éÒòÓÚ¸Ã×éÖ¯µÄÌØ¶¨¶ñÒâÈí¼þµÄÆÊÎö  £¬X-Force IRISÒÔΪTA505ÊǸù¥»÷Ô˶¯±³ºóµÄ¹¥»÷ÍÅ»ï ¡£


Ô­ÎÄÁ´½Ó£º

https://securityintelligence.com/posts/ta505-continues-to-infect-networks-with-sdbbot-rat/


6.¾É½ðɽ»ú³¡¹¥»÷Õß»òΪ¶íÂÞ˹APT×éÖ¯Energetic Bear


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


ESETÑо¿Ö°Ô±ÒÔΪ  £¬¶Ô¾É½ðɽ¹ú¼Ê»ú³ ¡£¨SFO£©ÍøÕ¾µÄ¹¥»÷ÊÇÓɱ»³ÆÎªEnergetic BearµÄ¶íÂÞË¹ÍøÂçÌØ¹¤×éÖ¯¾ÙÐеÄ ¡£¸ÃAPT×éÖ¯×Ô2010ÄêÒÔÀ´Ò»Ö±ºÜ»îÔ¾  £¬Ö÷ÒªÕë¶ÔÄÜÔ´ºÍ¹¤ÒµÁìÓòµÄ×éÖ¯ ¡£SFOµÄ»ú³¡ÐÅÏ¢ÊÖÒպ͵çÐŲ¿·Ö£¨ITT£©ÌåÏÖ¹¥»÷ÕßÔÚ»ú³¡ÍøÕ¾ÉÏÖ²ÈëÁ˶ñÒâ´úÂëÒÔÇÔÈ¡Óû§µÄµÇ¼ƾ֤  £¬¿ÉÄÜÊܹ¥»÷Ó°ÏìµÄÓû§°üÀ¨Ê¹ÓÃWindows×°±¸»ò·ÇSFOά»¤µÄ×°±¸Í¨¹ýIEä¯ÀÀÆ÷´Ó»ú³¡ÍøÂçÍⲿ»á¼ûÕâÐ©ÍøÕ¾µÄÓû§ ¡£SFOµÄITÖ°Ô±ÒѾ­É¾³ýÁË×¢ÈëÆäÍøÕ¾ÖеĶñÒâ´úÂë  £¬²¢ÔÚ¹¥»÷±¬·¢ºó½«Á½Õß¶¼¾ÙÐÐÁËÍÑ»ú´¦Öóͷ£ ¡£ÎªÏìÓ¦´ËÊÂÎñ  £¬SFO»ú³¡ÖØÖÃÁËËùÓеĵç×ÓÓʼþºÍÍøÂçÃÜÂë ¡£ESET³Æ¹¥»÷ÕßʹÓÃSMB¹¦Ð§ºÍfile£º//ǰ׺À´ÊÕ¾Û»á¼ûÕßµÄWindowsƾ֤  £¬°üÀ¨Óû§ÃûºÍNTLM¹þÏ£ ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/101601/apt/energetic-bear-airport-hack.html