2020ÄêQ2 DDoS¹¥»÷µÄ´ÎÊý±ÈÈ¥Äêͬ±ÈÔöÌí570£¥£»£»£»£»£»£»£»ÐµĹ¥»÷ǰÑÔ¿ÉʹÓÃCitrix WorkspaceÎó²îÖ´ÐÐí§Òâ´úÂë

Ðû²¼Ê±¼ä 2020-09-24

1.2020ÄêQ2 DDoS¹¥»÷µÄ´ÎÊý±ÈÈ¥Äêͬ±ÈÔöÌí570£¥


1.png


ƾ֤Nexusguard±¨¸æ£¬ £¬£¬£¬£¬£¬£¬£¬DDoS¹¥»÷µÄ´ÎÊýÓëÈ¥ÄêͬÆÚÏà±ÈÔöÌíÁË570£¥¡£ ¡£¡£¡£¡£¹¥»÷Õß½ÓÄÉÁׯüϸÄåµÄ¹¥»÷·½·¨£¬ £¬£¬£¬£¬£¬£¬£¬ÒÔ·¢¶¯ÖÖÖÖ·Å´óºÍ»ùÓÚUDPµÄ¹¥»÷£¬ £¬£¬£¬£¬£¬£¬£¬ÓÃÁ÷Á¿ÑÍûĿµÄÍøÂ磬 £¬£¬£¬£¬£¬£¬£¬ÕâʹCSPºÜÄÑͨ¹ý¹Å°åµÄ»ùÓÚãÐÖµµÄÒªÁì¾ÙÐмì²â»ººÍ½â¡£ ¡£¡£¡£¡£Nexusguard»¹·¢Ã÷ÁËÒ»ÖÖеÄÇ÷ÊÆ£¬ £¬£¬£¬£¬£¬£¬£¬¼´¹¥»÷Õß½ÓÄÉ»ìÏý¹¥»÷ǰÑÔÀ´Ìᳫ¸üÆÕ±éµÄ»ùÓÚUDPµÄ¹¥»÷£¬ £¬£¬£¬£¬£¬£¬£¬Ä¿µÄÊÇÌá¸ßCSP¼ì²âºÍÇø·Ö¶ñÒâÁ÷Á¿ÓëÕýµ±Á÷Á¿µÄÄѶÈ¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2020/09/23/bit-and-piece-ddos-attacks-increased-570-in-q2-2020/


2.Kenna SecurityÐû²¼Óйضà¸öÐÐÒµµÄÎó²îÖÎÀí±¨¸æ


2.png


ÍøÂçÇå¾²¹«Ë¾Kenna SecurityÐû²¼ÁËÒ»·ÝÓйؽðÈÚ¡¢ÖÆÔìÒµ¡¢Ò½ÁƺÍÊÖÒÕÐÐÒµ¾ÙÐеÄÎó²îÖÎÀíµÄ±¨¸æ¡£ ¡£¡£¡£¡£Kenna SecurityÌåÏÖ£¬ £¬£¬£¬£¬£¬£¬£¬ÓëÆäËûÐÐÒµÏà±È£¬ £¬£¬£¬£¬£¬£¬£¬ÖÆÔìÒµ¹«Ë¾ÍùÍùÐèÒªÁ½±¶µÄʱ¼äÀ´ÐÞ¸´Îó²î£¬ £¬£¬£¬£¬£¬£¬£¬¿ÉÊÇÆäÖ»ÓÐ5£¥µÄÎó²îÊǸßΣº¦µÄ¡£ ¡£¡£¡£¡£Ïà±È֮ϣ¬ £¬£¬£¬£¬£¬£¬£¬ÊÖÒÕ¹«Ë¾µÄÎó²îÍùÍù½ÏÉÙ£¬ £¬£¬£¬£¬£¬£¬£¬²¹¶¡ÖÎÀíµÄËÙÂÊͨ³£¸ü¿ì¡£ ¡£¡£¡£¡£¶øÒ½ÁÆÐÐÒµ¾­³£Ôâµ½ÖîÈçÀÕË÷Èí¼þÔÚÄڵĹ¥»÷£¬ £¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ¹¥»÷ÕßÉîÐÅËûÃǻḶǮ£¬ £¬£¬£¬£¬£¬£¬£¬¶ø²»ÊǰÑÉúÃüÖÃÓÚΣÏÕÖ®ÖС£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/healthcare-lags-behind-in-vulnerability-management-banks-are-holding-their-ground/


3.ÐµĹ¥»÷ǰÑÔ¿ÉʹÓÃCitrix WorkspaceÎó²îÖ´ÐÐí§Òâ´úÂë


3.png


Ñо¿Ö°Ô±·¢Ã÷ÔÚ7ÔÂÒѱ»ÐÞ¸´µÄCitrix WorkspaceÎó²î£¨CVE-2020-8207£©¾ßÓÐеĸ¨Öú¹¥»÷ǰÑÔ£¬ £¬£¬£¬£¬£¬£¬£¬ºÚ¿Í¿ÉʹÓÃÆäÌáÉýȨÏÞ²¢ÔÚSYSTEMÕÊ»§ÏÂÔ¶³ÌÖ´ÐÐí§ÒâÏÂÁî¡£ ¡£¡£¡£¡£¸ÃÎó²î±£´æÓÚCitrixÊÂÇéÇøÓ¦ÓóÌÐòµÄ×Ô¶¯¸üÐÂЧÀÍÖУ¬ £¬£¬£¬£¬£¬£¬£¬µ±ÆôÓÃWindowsÎļþ¹²Ïí(SMB)ʱ£¬ £¬£¬£¬£¬£¬£¬£¬Æä¿É±»ÓÃÀ´ÌáȨÒÔ¼°Ô¶ÈëÇÖÄ¿µÄÅÌËã»ú¡£ ¡£¡£¡£¡£Pen Test PartnersÑо¿Ö°Ô±·¢Ã÷£¬ £¬£¬£¬£¬£¬£¬£¬×î½üÓкڿÍͨ¹ýCitrixÊðÃûµÄMSI×°ÖóÌÐò£¨Windows InstallerÈí¼þ°ü£©À´Ê¹ÓôËÎó²î£¬ £¬£¬£¬£¬£¬£¬£¬ÒÔ¾ÙÐÐí§Òâ´úÂëÖ´ÐС£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/citrix-workspace-new-attack/159459/


4.MozillaÐû²¼FirefoxÇå¾²¸üУ¬ £¬£¬£¬£¬£¬£¬£¬ÐÞ¸´¶à¸öÑÏÖØµÄÎó²î


4.png


MozillaÐû²¼Çå¾²¸üУ¬ £¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËFirefox 81ºÍFirefox ESR 78.3µÄÖеĶà¸öÑÏÖØµÄÎó²î£¬ £¬£¬£¬£¬£¬£¬£¬ÆäÖÐһЩ¿É±»ÓÃÀ´Ö´ÐÐí§Òâ´úÂë¡£ ¡£¡£¡£¡£°üÀ¨ä¯ÀÀÆ÷µÄÄÚ´æÇå¾²±£»£»£»£»£»£»£»¤Îó²î£¨CVE-2020-15674ºÍCVE-2020-15673£©£¬ £¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÖîÈ绺³åÇøÒç³öÖ®ÀàµÄÄÚ´æ»á¼ûÎÊÌ⣬ £¬£¬£¬£¬£¬£¬£¬ÒÔ¼°Firefox 81µÄµÄWebͼÐο⣨WebGL£©ÖеÄÊͷźóʹÓÃÎó²î£¨CVE-2020-15675£©£¬ £¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÄÚ´æË𻵺ÍDZÔڵĿÉʹÓÃÍ߽⡣ ¡£¡£¡£¡£±ðµÄ£¬ £¬£¬£¬£¬£¬£¬£¬Firefox 81»¹ÐÞ¸´ÁËÏÂÔØÔ´ÓÕÆ­Îó²î£¨CVE-2020-15677£©¡¢¿çÕ¾µã¾ç±¾Îó²î£¨CVE-2020-15676£©ºÍÊͷźóʹÓÃÎó²î£¨CVE-2020-15678£©¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/firefox-81-release-bugs/159435/


5.ºÚ¿Í×éÖ¯APT28ʹÓÃαÔìµÄ±±Ô¼ÅàѵÎĵµ·Ö·¢¶ñÒâÈí¼þ


5.png


Ñо¿Ö°Ô±·¢Ã÷¶íÂÞ˹ºÚ¿Í×éÖ¯APT28ÓÃαÔìµÄ±±Ô¼ÅàѵÎĵµ£¬ £¬£¬£¬£¬£¬£¬£¬Õë¶ÔÕþ¸®»ú¹¹·Ö·¢¶ñÒâÈí¼þZebrocy¡£ ¡£¡£¡£¡£APT28·Ö·¢µÄ¶ñÒâÎļþµÄÎÊÌâΪCourse 5¨C16 October 10.2020.zipx£¬ £¬£¬£¬£¬£¬£¬£¬¿´ÆðÀ´Ö»ÊÇÒ»¸ö°üÀ¨¿Î³Ì×ÊÁϵÄZIP°ü¡£ ¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚ¶ÔÆä¾ÙÐÐÆÊÎöʱ·¢Ã÷£¬ £¬£¬£¬£¬£¬£¬£¬ÆäʹÓÃÁËÀàËÆÓÚÈÆ¹ýµç×ÓÓʼþÍø¹ØµÄÊÖÒÕÀ´ÈƹýAVs»òÆäËû¹ýÂËϵͳ£¬ £¬£¬£¬£¬£¬£¬£¬Ê¹µÃÆä¼ì²âÂʺÜÊǵͣ¬ £¬£¬£¬£¬£¬£¬£¬Ö»ÓÐ3/61¡£ ¡£¡£¡£¡£QuoIntelligenceÏÓÒÉÕâ¿î¶ñÒâÈí¼þµÄÄ¿µÄÊǰ¢Èû°Ý½®Õþ¸®»ú¹¹


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/russian-hackers-use-fake-nato-training-docs-to-breach-govt-networks/


6.ÀÕË÷Èí¼þAgeLockerÕë¶ÔQNAP NAS×°±¸ÇÔÈ¡Êý¾Ý


6.png


×Ô8ÔÂβ×îÏÈ£¬ £¬£¬£¬£¬£¬£¬£¬ÀÕË÷Èí¼þAgeLockerÕë¶ÔÈ«ÇòQNAP NAS×°±¸Ìᳫ¹¥»÷£¬ £¬£¬£¬£¬£¬£¬£¬ÒÔÇÔÈ¡Êý¾Ý¡£ ¡£¡£¡£¡£AgeLockerΪ2020Äê7ÔÂ×îÏÈ»îÔ¾µÄеÄÀÕË÷Èí¼þ£¬ £¬£¬£¬£¬£¬£¬£¬ÆäʹÓÃAge¼ÓÃÜË㷨ȡ´úGPGÀ´¼ÓÃÜÎļþ¡£ ¡£¡£¡£¡£ÔÚ¼ÓÃÜÎļþʱ£¬ £¬£¬£¬£¬£¬£¬£¬Ëü»áÔÚ¼ÓÃÜÊý¾Ýǰ¼ÓÉÏÒ»¸öÒÔURL¡°age-encryption.org¡±¿ªÍ·µÄÎı¾Í·¡£ ¡£¡£¡£¡£×Ô2020Äê8ÔÂβÒÔÀ´£¬ £¬£¬£¬£¬£¬£¬£¬ÆäÒ»Ö±ÒÔ¹ûÕæÌ»Â¶µÄQNAP NAS×°±¸ÎªÄ¿µÄ²¢¶ÔÆäÎļþ¾ÙÐмÓÃÜ¡£ ¡£¡£¡£¡£ÏÖÔÚ»¹ÎÞ·¨Ãâ·Ñ»Ö¸´±»AgeLocker¼ÓÃܵÄÎļþ¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/agelocker-ransomware-targets-qnap-nas-devices-steals-data/