VMwareÐÞ¸´Fusion¡¢VMRCºÍHorizo??n ClientÖеÄÌáȨÎó²î£»£»£»¼ÓÄôóËÄËù¾üУÔâµ½¹¥»÷µ¼ÖÂÍøÂçÖÐÖ¹

Ðû²¼Ê±¼ä 2020-07-13

1.VMwareÐÞ¸´Fusion¡¢VMRCºÍHorizon ClientÖеÄÌáȨÎó²î


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


VMwareÐû²¼ÁËÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËÒ»¸öȨÏÞÌáÉýÎó²î£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÓ°ÏìÁËVMware Fusion¡¢ Mac°æ±¾µÄRemote ConsoleºÍHorizon Client£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓôËÎó²îÀ´¿ØÖÆÊÜÓ°Ïìϵͳ¡£¡£¡£¡£¡£¸ÃÎó²îÊÇÓÉÓÚXPC¿Í»§¶ËÑéÖ¤²»×¼È·µ¼ÖµÄ£¬£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²î¿Éʹ¾ßÓÐͨË×Óû§È¨Ï޵Ĺ¥»÷Õß½«ÆäȨÏÞÌáÉýµ½ÏµÍ³ÉϵÄrootÓû§¡£¡£¡£¡£¡£¸ÃÎó²îµÄCVSSv3ÆÀ·ÖΪ7.8¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/07/10/vmware-releases-security-updates-multiple-products


2.¼ÓÄôóËÄËù¾üУÔâµ½¹¥»÷µ¼ÖÂÍøÂçÖÐÖ¹£¬£¬£¬£¬£¬£¬£¬ÄîÍ·Éв»Ã÷È·


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


¼ÓÄôóËÄËù¾üУÔâµ½¹¥»÷µ¼ÖÂÍøÂçÔÝʱ̱»¾£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÄîÍ·Éв»ÇåÎú¡£¡£¡£¡£¡£´Ë´ÎÔâµ½¹¥»÷µÄѧУ»®·ÖΪ½ð˹¶ØµÄ»Ê¼Ò¾üÊÂѧԺ¡¢¿ý±±¿ËµÄRMC Saint-Jean¡¢¶àÂ×¶àµÄ¼ÓÄô󲽶ÓѧԺºÍÂÞ²®ÌذÂÈüµÂѧԺµÄChief Warrant Officer£¬£¬£¬£¬£¬£¬£¬ÕâЩѧУµÄ½¹µãϵͳ¾ùÔâµ½Á˹¥»÷¡£¡£¡£¡£¡£Æ¾Ö¤RMC¸±½ÌÊÚGreg PhillipsÔÚ7ÔÂ6ÈÕ½ÒÏþµÄ²©¿ÍÎÄÕ£¬£¬£¬£¬£¬£¬£¬´Ë´Î¹¥»÷ÖеĶñÒâÈí¼þʹÓÃÁËÇå¾²Îó²î¾ÙÐÐ×ÔÎÒ×°Ö㬣¬£¬£¬£¬£¬£¬È»ºó¶Ô´ÅÅÌÄÚÈݾÙÐмÓÃÜ£¬£¬£¬£¬£¬£¬£¬´Ó¶øÊ¹ÆäÎÞ·¨»á¼û¡£¡£¡£¡£¡£²¢ÒÔΪ¸ÃÊÂÎñΪÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬£¬µ«»Êºó´óѧ½ÌÊÚSkillicornÔòÒÔΪÊÇÆäËû¹ú¼ÒÊÔͼÈüÓÄôóÕþ¸®ÞÏÞΡ£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬Ñ§Ð£ÍøÂçÒÀÈ»ÔÚ»Ö¸´ÖС£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.kingstonist.com/news/motives-unclear-as-cyber-attack-shuts-down-rmc-network/


3.¶ñÒâÈí¼þÌí¼ÓAny.RunɳÏä¼ì²â¹¦Ð§ÒÔÌӱܯÊÎö


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


Çå¾²Ñо¿Ô±JAMESWT·¢Ã÷¶ñÒâÈí¼þÐÂÔöÁËAny.RunɳÏä¼ì²â¹¦Ð§£¬£¬£¬£¬£¬£¬£¬ÒÔÌÓ±ÜÑо¿Ö°Ô±µÄÆÊÎö¡£¡£¡£¡£¡£JAMESWT·¢Ã÷ÔÚеÄʹÓÃÀ¬»øÓʼþ·Ö·¢ÃÜÂëÇÔȡľÂíµÄ»î¶¯ÖУ¬£¬£¬£¬£¬£¬£¬¹¥»÷Õ߻ὫÁ½¸öPowerShell¾ç±¾ÏÂÔØµ½Êܺ¦ÕßµÄÅÌËã»ú¡£¡£¡£¡£¡£¶ñÒâÈí¼þÔÚÔËÐеڶþ¸ö¾ç±¾Ê±£¬£¬£¬£¬£¬£¬£¬Ê×ÏȽ«ÊµÑéÆô¶¯ÃÜÂëÇÔȡľÂíAzorult£¬£¬£¬£¬£¬£¬£¬ÈôÊǼì²âµ½¸Ã³ÌÐòÕýÔÚAny.RunÉÏÔËÐУ¬£¬£¬£¬£¬£¬£¬±ã»áÏÔʾÐÂÎÅ¡° Any.run Deteceted£¡¡±£¬£¬£¬£¬£¬£¬£¬È»ÍËÈ´³ö¡£¡£¡£¡£¡£Í¨¹ýÕâÖÖÒªÁ죬£¬£¬£¬£¬£¬£¬ºÚ¿ÍʹÑо¿Ö°Ô±Ô½·¢ÄÑÒÔʹÓÃ×Ô¶¯»¯ÏµÍ³À´ÆÊÎöÆä¹¥»÷¡£¡£¡£¡£¡£    


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/malware-adds-anyrun-sandbox-detection-to-evade-analysis/


4.Òò±£´æÇ徲Σº¦£¬£¬£¬£¬£¬£¬£¬Amazon½¨ÒéÔ±¹¤É¾³ýTikTokÓ¦ÓÃ


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


AmazonÏòÆäÔ±¹¤·¢Ë͵ç×ÓÓʼþ£¬£¬£¬£¬£¬£¬£¬ÒªÇó±ØÐèÔÚ7ÔÂ10ÈÕ֮ǰ´ÓÆä×°±¸ÖÐɾ³ýTikTokÓ¦ÓóÌÐò¡£¡£¡£¡£¡£¸Ãµç×ÓÓʼþÖÐÌᵽʹÓÃTikTokÓ¦ÓóÌÐò±£´æÇ徲Σº¦£¬£¬£¬£¬£¬£¬£¬µ«Î´Ïêϸ˵Ã÷ÊǺÎÖÖΣº¦¡£¡£¡£¡£¡£ÔÚÕâÖ®ºó£¬£¬£¬£¬£¬£¬£¬7ÔÂ10ÈÕAmazonÌåÏÖ¸ÃեȡʹÓÃTikTokµÄµç×ÓÓʼþÊÇÎ󷢵쬣¬£¬£¬£¬£¬£¬ÈÔ½«ÔÊÐíÔ±¹¤ÔÚÆä×°±¸ÉÏʹÓøÃÓ¦ÓóÌÐò¡£¡£¡£¡£¡£Ðí¶àÈËÖ¸Ôð¸ÃÓ¦ÓóÌÐò´ÓÓû§ÄÇÀïÍøÂçÐÅÏ¢²¢½«Æäת´ï¸øÖйúÕþ¸®£¬£¬£¬£¬£¬£¬£¬µ«¸ÃÐÂÎÅ´Óδ»ñµÃ֤ʵ¡£¡£¡£¡£¡£×ÔÈ¥ÄêÒÔÀ´£¬£¬£¬£¬£¬£¬£¬TikTok±»ÃÀ¹ú¾ü·½¡¢Ó¡¶ÈÕþ¸®ºÍÓ¡¶È¾ü¶ÓµÈեȡʹÓᣡ£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/amazon-tells-employees-to-remove-tiktok-from-their-phones-due-to-security-risk/#ftag=RSSbaffb68


5.Ñо¿Ô±·¢Ã÷¶ñÒâÈí¼þTrickBot·Ö·¢Æä²âÊÔ°æ±¾


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


Ó¢ÌØ¶û¹«Ë¾µÄVitali KremezÔÚÆÊÎöTrickBot¶ñÒâÈí¼þµÄ×îа汾ʱ·¢Ã÷£¬£¬£¬£¬£¬£¬£¬ºÚ¿Í¹ýʧµÄ·Ö·¢ÁËÆäÓÃÓÚÇÔÈ¡ÃÜÂëµÄÄ£¿£¿£¿£¿égrabber.dllµÄ²âÊÔ°æ±¾¡£¡£¡£¡£¡£¼ÓÔØºó¸Ã²âÊÔ°æ±¾ºó£¬£¬£¬£¬£¬£¬£¬´ËÄ£¿£¿£¿£¿é½«ÔÚĬÈÏä¯ÀÀÆ÷ÖÐÏÔʾÖÒÑÔ£¬£¬£¬£¬£¬£¬£¬Ö¸³ö¸Ã³ÌÐòÕýÔÚÍøÂçÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬²¢ÌáÐÑÊܺ¦ÕßÓ¦Á¬Ã¦×ÉѯÆäϵͳÖÎÀíÔ±¡£¡£¡£¡£¡£KremezÌåÏÖ£¬£¬£¬£¬£¬£¬£¬¸Ã²âÊÔÄ£¿£¿£¿£¿éËÆºõÓÉTrickBot¿ª·¢Ö°Ô±¿ª·¢µÄ£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚËüÓëÆäËûÄ£¿£¿£¿£¿é¾ùÊÇÒÔÏàͬµÄ·½·¨±àÂ룬£¬£¬£¬£¬£¬£¬ËûÒÔΪºÚ¿ÍÕýÔÚ²âÊÔа汾£¬£¬£¬£¬£¬£¬£¬È´ÒÅÍüÔÚÐû²¼ºó½«Æäɾ³ý¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/trickbot-malware-mistakenly-warns-victims-that-they-are-infected/


6.CheckPointÐû²¼±¨¸æ£¬£¬£¬£¬£¬£¬£¬PhorpiexÓ°ÏìÁ¦¼±¾çÔöÌí


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


CheckPointÐû²¼ÁËÆä×îеÄ2020Äê6ÔÂÈ«ÇòÍþвָÊý£¬£¬£¬£¬£¬£¬£¬·¢Ã÷PhorpiexÓ°ÏìÁ¦¼±¾çÔöÌí¡£¡£¡£¡£¡£¸Ã½©Ê¬ÍøÂçÒ»Ö±ÔÚ·Ö·¢ÐµÄÀÕË÷Èí¼þ¼´Ð§ÀÍ£¨RaaS£©ÀÕË÷Èí¼þAvaddon£¬£¬£¬£¬£¬£¬£¬ÓëÎåÔ·ÝÏà±È£¬£¬£¬£¬£¬£¬£¬ÆäÅÅÃûÉÏÉýÁË13룬£¬£¬£¬£¬£¬£¬Î»ÁжñÒâÈí¼þÅÅÐаñµÄµÚ2룬£¬£¬£¬£¬£¬£¬¶ÔÈ«Çò×éÖ¯µÄÓ°ÏìÁ¦·­ÁËÒ»·¬¡£¡£¡£¡£¡£ÔÚ6Ô·Ý£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁ¦×î´óµÄ¶ñÒâÈí¼þΪ¸ß¼¶RAT Agent Tesla£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁË3£¥µÄ×éÖ¯£¬£¬£¬£¬£¬£¬£¬Æä´ÎÊǽ©Ê¬ÍøÂçPhorpiexºÍ¿ªÔ´CPUÍÚ¾òÈí¼þXMRig£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁË2%µÄ×éÖ¯¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬±»Ê¹ÓÃ×îÑÏÖØµÄÎó²îΪOpenSSL TLS DTLSÐÄÌøÐÅϢй¶£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁË45£¥µÄ×éÖ¯£¬£¬£¬£¬£¬£¬£¬Æä´ÎÊÇMVPower DVRÔ¶³Ì´úÂëÖ´ÐÐÎó²îºÍGit´æ´¢¿âй¶£¬£¬£¬£¬£¬£¬£¬»®·ÖÓ°ÏìÁËÈ«Çò44£¥ºÍ38£¥µÄ×éÖ¯¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://finance.yahoo.com/news/june-2020-most-wanted-malware-100010951.html?&web_view=true