ÃÀ¹úÄÜÔ´²¿È·ÈÏSolarWindsÒÑÈëÇÖºËÎäÆ÷¾ÖµÄÍøÂ磻Avast½üÆÚ·¢Ã÷28¿î¶ñÒâµÄä¯ÀÀÆ÷²å¼þ£¬Ó°Ïì300ÍòÓû§
Ðû²¼Ê±¼ä 2020-12-18
ÃÀ¹úÄÜÔ´²¿ÒѾȷÈÏ£¬SolarWinds±³ºóµÄºÚ¿Í×éÖ¯ÈëÇÖÁËÃÀ¹úºËÎäÆ÷»ú¹¹NNSAµÄÍøÂç¡£NNSAÊÇÒ»¸ö°ë×ÔÖÎÕþ¸®»ú¹¹£¬ÈÏÕæÎ¬»¤ºÍÈ·±£ÃÀ¹úºËÎäÆ÷¿â´æ£¬ÒÔ¼°Ó¦¶ÔÃÀ¹úº£ÄÚÍâµÄºËºÍ·ÅÉä½ôÆÈÇéÐΡ£FBI¡¢CISAºÍODNIÐû²¼ÍŽáÉùÃ÷³Æ£¬ºÚ¿ÍÈëÇÖÁ˶à¸öÃÀ¹úÕþ¸®µÄÍøÂ磬°üÀ¨ÃÀ¹ú²ÆÎñ²¿¡¢ÃÀ¹ú¹úÎñÔº¡¢ÃÀ¹úNTIA¡¢ÃÀ¹ú¹úÁ¢ÎÀÉúÑо¿Ôº¡¢DHS-CISAºÍÃÀ¹úÁìÍÁÇå¾²²¿¡£ÏÖÔÚ£¬Microsoft¡¢FireEyeºÍGoDaddyÒÑΪSolarWinds SunburstºóÃŽ¨ÉèÁËÒ»¸ökill switch£¬ÒÔÖÕÖ¹Êܺ¦ÕßÍøÂçÉϵÄѬȾ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/solarwinds-hackers-breach-us-nuclear-weapons-agency/
2.HPEÅû¶Æä·þÎñÆ÷ÖÎÀíÈí¼þÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î

»ÝÆÕÆóÒµ£¨HPE£©Åû¶ÆäWindowsºÍLinuxµÄHPE Systems Insight Manager£¨SIM£©Èí¼þÖб£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£HPE SIMÊÇÕë¶Ô¶à¸öHPE·þÎñÆ÷¡¢´æ´¢ºÍÍøÂç²úÆ·µÄÖÎÀíºÍÔ¶³ÌÖ§³Ö×Ô¶¯»¯½â¾ö¼Æ»®¡£¸ÃÎó²î±»×·×ÙΪCVE-2020-7200£¬ÑÏÖØÐÔÆÀ·ÖΪ9.8£¬¸ÃÎó²îÊÇÓÉÓÚ¶ÔÓû§ÌṩµÄÊý¾Ýȱ·¦Êʵ±µÄÑéÖ¤µ¼Ö²»¿ÉÐÅÊý¾ÝµÄ·´ÐòÁл¯£¬´Ó¶øÊ¹¹¥»÷ÕßÓпÉÄÜʹÓÃÕâЩÊý¾ÝÖ´ÐдúÂë¡£ÏÖÔÚ¸ÃÎó²îÉÐÎÞÇå¾²¸üУ¬¿ÉÊÇHPEÒÑÌṩWindows»º½âÒªÁì¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hpe-discloses-critical-zero-day-in-server-management-software/
3.Avast½üÆÚ·¢Ã÷28¿î¶ñÒâµÄä¯ÀÀÆ÷²å¼þ£¬Ó°Ïì300ÍòÓû§

Çå¾²¹«Ë¾Avast½üÆÚ·¢Ã÷28¿î¶ñÒâµÄä¯ÀÀÆ÷²å¼þ£¬°üÀ¨15¸öChromeÀ©Õ¹ºÍ13¸öEdgeÀ©Õ¹£¬ÒÑÓ°Ïì300ÍòÓû§¡£Õâ28¿î²å¼þ°üÀ¨´ó×ÚʵÏÖ¶ñÒâ²Ù×÷µÄ´úÂ룬ÀýÈ罫Óû§Á÷Á¿Öض¨Ïòµ½¹ã¸æ¡¢½«Óû§Á÷Á¿Öض¨Ïòµ½ÍøÂç´¹ÂÚÕ¾µã¡¢ÍøÂçСÎÒ˽¼ÒÊý¾Ý¡¢ÍøÂçä¯ÀÀ¼Í¼¡¢½«¸ü¶à¶ñÒâÈí¼þÏÂÔØµ½Óû§×°±¸ÉÏ¡£ÏÖÔÚ£¬GoogleÒÑɾ³ýÁË15¸ö¶ñÒâÀ©Õ¹³ÌÐòÖеÄ3¸ö£¬¶øMicrosoftÒòÎÞ·¨È·ÈÏAvastµÄ±¨¸æ¶øÉÐδ¾ÙÐÐɾ³ý¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/three-million-users-installed-28-malicious-chrome-or-edge-extensions/
4.ºÚ¿Í½«ÀÕË÷Èí¼þSystemBC×÷ΪTorÊðÀíºÍÔ¶³Ì¿ØÖƹ¤¾ß

ºÚ¿Í½«ÀÕË÷Èí¼þSystemBC×÷ΪTorÊðÀíºÍÔ¶³Ì¿ØÖƹ¤¾ß¡£SystemBCÓÚ2019ÄêÊ״ηºÆð£¬ÊÇÒ»ÖÖÊðÀíºÍÔ¶³ÌÖÎÀí¹¤¾ß¡£Ëü¼È³äµ±ÒþʽͨѶµÄÍøÂçÊðÀí£¬Óֳ䵱Զ³ÌÖÎÀí¹¤¾ß£¨RAT£©£¬Äܹ»Ö´ÐÐWindowsÏÂÁî²¢½»¸¶ºÍÖ´Ðо籾¡¢¶ñÒâ¿ÉÖ´ÐÐÎļþºÍ¶¯Ì¬Á´½Ó¿â£¨DLL£©£¬»¹¿ÉÒÔÌṩ³¤ÆÚµÄºóÃÅ¡£SystemBCµÄ×îÐÂÑù±¾ÖаüÀ¨µÄ´úÂëûÓÐͨ¹ýSOCKS5ÊðÀí³äµ±ÐéÄâ˽ÓÐÍøÂ磬¶øÊÇʹÓÃTorÄäÃûÍøÂç¼ÓÃܲ¢Òþ²ØÏÂÁîºÍ¿ØÖÆÁ÷Á¿µÄÄ¿µÄµØ¡£
ÔÎÄÁ´½Ó£º
https://news.sophos.com/en-us/2020/12/16/systembc/
5.еÄRubyGems¶ñÒâÈí¼þ°üÕë¶Ô¼ÓÃÜÇ®±Ò¹©Ó¦Á´

Çå¾²¹«Ë¾Sonatype·¢Ã÷еÄRubyGems¶ñÒâÈí¼þ°üÕë¶Ô¼ÓÃÜÇ®±Ò¹©Ó¦Á´£¬ÒÔÇÔÈ¡¼ÓÃÜÇ®±Ò¡£Sonatype±¨¸æ³Æ£¬Á½¸ö¶ñÒâÈí¼þ°üpretty_color-0.8.1.gemºÍ ruby-bitcoin-0.0.20.gem£¬Î±×°³É±ÈÌØ±Ò¿âºÍÓÃÓÚÏÔʾ²î±ðÑÕɫЧ¹ûµÄ×Ö·û´®µÄ¿â£¬×°ÖÃÁËÒ»¸ö¼ôÌù°åÇÔÈ¡¹¤¾ß¡£ËüÃÇ¿ÉÒÔ¼àÊÓWindows¼ôÌù°åµÄ¼ÓÃÜÇ®±ÒµØµã£¬ÈôÊǼì²âµ½¼ÓÃÜÇ®±ÒµØµã£¬½«»á°ÑËüÌæ»»Îª¹¥»÷Õߵĵص㣬ÒÔÇÔÈ¡¼ÓÃÜÇ®±Ò¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/malicious-rubygems-packages-used-in-cryptocurrency-supply-chain-attack/
6.FBI³ÆDoppelPaymerÓõ绰ÏÅ»£¾Ü¸¶Êê½ðµÄÊܺ¦Õß

FBI³ÆÀÕË÷Èí¼þÍÅ»ïDoppelPaymerÓôòµç»°µÄ·½·¨ÏÅ»£¾Ü¸¶Êê½ðµÄÊܺ¦Õß¡£FBIÌåÏÖ£¬ÕâЩÊÂÎñ×Ô2020Äê2ÔÂÒÔÀ´Ò»Ö±ÔÚ±¬·¢£¬²¢ÇÒÆäËûËĸöÀÕË÷Èí¼þ×éÖ¯Sekhmet ¡¢ Maze ¡¢ContiºÍRyukÒ²ÊÇÓùýÀàËÆµÄÕ½ÂÔ¡£±ðµÄ£¬¸Ã»ú¹¹»¹Ïêϸ˵Ã÷ÎúÒ»¸öÌØ¶¨°¸Àý£¬ÆäÖÐÍþв´ÓÊܹ¥»÷µÄ¹«Ë¾À©Õ¹µ½ÆäÔ±¹¤ÉõÖÁÊÇÇ×ÆÝ£¬³ÆÒª°ÑһСÎÒ˽¼ÒË͵½Ò»ÃûÔ±¹¤µÄ¼ÒÀï¡£µ«FBIÌåÏÖ£¬ÔÚÕâÖÖÇéÐÎÏ£¬±©Á¦Íþвͨ³£ÊÇÆÓªµÄ¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/fbi-says-doppelpaymer-ransomware-gang-is-harassing-victims-who-refuse-to-pay/


¾©¹«Íø°²±¸11010802024551ºÅ