2024ÄêÈ«ÇòÊý¾Ýй¶±¾Ç®Ô¤¼Æ½«´ï5ÍòÒÚÃÀÔª£»£»£»£»¹¥»÷ÕßʹÓÃOrcusºÍRevenge RATÕë¶ÔÕþ¸®ºÍ½ðÈÚ»ú¹¹

Ðû²¼Ê±¼ä 2019-08-30

1.2024ÄêÈ«ÇòÊý¾Ýй¶±¾Ç®Ô¤¼Æ½«´ï5ÍòÒÚÃÀÔª


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ƾ֤հ²©ÍøÂçµÄ×îÐÂÕ¹Íû£¬ £¬£¬£¬Ëæ×Åî¿Ïµ·£¿£¿îµÄʵÑéÒÔ¼°ÆóÒµÔ½·¢ÒÀÀµÓÚÊý×Öϵͳ£¬ £¬£¬£¬µ½2024ÄêÈ«ÇòÊý¾Ýй¶µÄ±¾Ç®Ô¤¼Æ½«ÔöÌíµ½5ÍòÒÚÃÀÔªÒÔÉÏ¡£¡£¡£¡£¡£ÕâÒ»Êý¾ÝÀ´×ÔÓڸù«Ë¾Ðû²¼µÄ×îб¨¸æ¡¶ÍøÂç·¸·¨ºÍÇå¾²µÄδÀ´£º2019-2024ÍþвÆÊÎö¡¢Ó°ÏìÆÀ¹À»ººÍ½âÕ½ÂÔ±¨¸æ¡·¡£¡£¡£¡£¡£¸Ã¹«Ë¾Éù³Æ£¬ £¬£¬£¬ÔÚ±¨¸æÊ±´úÄÚÔ¤¼ÆÊý¾Ýй¶±¾Ç®½«´Ó2019ÄêµÄ3ÍòÒÚÃÀԪÿÄêÔöÌí11%¡£¡£¡£¡£¡£±¨¸æÖл¹³ÆËäÈ»´ó¹æÄ£µÄÊý¾Ýй¶¿ÉÄܳÉΪͷÌõÐÂÎÅ£¬ £¬£¬£¬µ«ËüÃDz¢·×Æç¶¨»áÖ±½ÓÓ°Ï챾Ǯ£¬ £¬£¬£¬ÓÉÓÚ·£¿£¿îºÍÓªÒµËðʧÓëÊý¾Ýй¶µÄ¹æÄ£²¢²»Ï¸ÃÜÏà¹Ø¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/breach-costs-trillion/


2.Google PlayÖÐÁ½¸ö¹ã¸æÓ¦ÓÃÏÂÔØÁ¿³¬150Íò´Î


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Ñо¿Ö°Ô±ÔÚGoogle PlayÖз¢Ã÷Á½¸ö¹ã¸æÓ¦Ó㬠£¬£¬£¬×ÜÏÂÔØÁ¿Áè¼Ý150Íò´Î¡£¡£¡£¡£¡£µÚÒ»¸öAPPÊÇOCRÎı¾É¨ÃèÒÇ£¬ £¬£¬£¬Æä×°ÖÃÊýÄ¿Áè¼Ý100Íò£¬ £¬£¬£¬ÁíÒ»¸öÊÇÒ»¸ö½¡ÉíAPP£¬ £¬£¬£¬×°ÖÃÊýÄ¿Áè¼Ý50Íò¡£¡£¡£¡£¡£ËüÃÇÊôÓÚͳһ¿ª·¢ÕßIdea Master¡£¡£¡£¡£¡£¸Ã¹ã¸æÈí¼þʹÓÃAndroid Notification Manager·¢³öÐÂÎÅ£¬ £¬£¬£¬µ±Óû§µ¥»÷ÐÂÎÅʱ»á´¥·¢ÏÔʾ´øÓÐ¹ã¸æµÄÒþ²ØÊÓͼ¡£¡£¡£¡£¡£¿£¿ª·¢ÕßʹÓÃToast֪ͨ¼ÓÔØ¹ã¸æ£¬ £¬£¬£¬²¢Í¨¹ý½«Toast¹¤¾ß¶¨Î»ÔÚÆÁÄ»µÄ¿ÉÊÓÇøÓòÖ®Í⣬ £¬£¬£¬Ê¹µÃ¹ã¸æ¶ÔÓû§²»¿É¼û¡£¡£¡£¡£¡£ËäÈ»Óû§ÎÞ·¨¿´µ½¹ã¸æ£¬ £¬£¬£¬µ«ËûÃǵÄÌåÑé»áÊܵ½Ó°Ï죬 £¬£¬£¬°üÀ¨×°±¸ÐÔÄÜϽµ¡¢µçÁ¿ÏûºÄÒÔ¼°ÍøÂçÁ÷Á¿µÄʹÓÃÔöÌí¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ghost-clicks-boost-ad-revenue-for-android-apps-with-15m-installs/


3.¹¥»÷ÕßʹÓÃOrcusºÍRevenge RATÕë¶ÔÕþ¸®ºÍ½ðÈÚ»ú¹¹


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


˼¿ÆTalosÑо¿Ö°Ô±·¢Ã÷¹¥»÷ÕßÕýÔÚʹÓÃRevenge RATºÍOrcus RATÕë¶ÔÕþ¸®»ú¹¹¡¢½ðÈÚЧÀÍÆóÒµ¡¢ÐÅÏ¢ÊÖÒÕЧÀ͹©Ó¦É̺Í×Éѯ¹«Ë¾µÈ¡£¡£¡£¡£¡£Revenge RATÊÇ2016ÄêÔÚDev PointºÚ¿ÍÂÛ̳ÉϹûÕæÐû²¼µÄRAT£¬ £¬£¬£¬Ëü¿ÉÒÔ·­¿ªÔ¶³Ìshell£¬ £¬£¬£¬ÔÊÐí¹¥»÷ÕßÖÎÀíϵͳÎļþ¡¢Àú³Ì¡¢×¢²á±íºÍЧÀÍ¡¢¼Í¼°´¼ü¡¢ÍøÂçÃÜÂëÒÔ¼°»á¼ûÉãÏñÍ·µÈ¡£¡£¡£¡£¡£Orcus×Ô2016ÄêÍ·ÒÔÀ´±»Ðû´«ÎªÔ¶³ÌÖÎÀí¹¤¾ß£¬ £¬£¬£¬µ«¼øÓÚËü»¹¾ßÓÐÔ¶¿ØÄ¾Âí¹¦Ð§£¬ £¬£¬£¬ÏÖÔÚËüÒ²±»ÒÔΪÊÇÒ»ÖÖÄܹ»¼ÓÔØ×Ô½ç˵²å¼þµÄ¶ñÒ⹤¾ß¡£¡£¡£¡£¡£ÕâЩ¹¥»÷»î¶¯µÄÔËÓªÕßʹÓö¯Ì¬ÓòÃûϵͳ£¨DDNS£©À´Òþ²ØËûÃǵÄC2ЧÀÍÆ÷£¬ £¬£¬£¬Ë¼¿ÆTalosÔÚ±¨¸æÖÐÏêϸÁгöÁ˶ñÒâÑù±¾¹þÏ£¡¢¹¥»÷ÓòÃûÒÔ¼°IPµØµãµÈ¹¥»÷Ö¸±ê£¨IOC£©¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/attackers-target-govt-and-financial-orgs-with-orcus-revenge-rats/


4.Ñо¿Ö°Ô±ÔÚ¶à¸öWordPress²å¼þÖз¢Ã÷9¸öSQL×¢ÈëÎó²î


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


FortinetÔÚ9¸öÊ¢ÐеÄWordPress²å¼þÖз¢Ã÷9¸öSQL×¢ÈëÎó²î¡£¡£¡£¡£¡£ÕâЩ²å¼þµÄ¹æÄ£º­¸Ç¹ã¸æ¡¢¾èÔù¡¢Í¼¿â¡¢±í¸ñ¡¢ÐÂÎÅͨѶºÍÊÓÆµ²¥·ÅÆ÷µÈ£¬ £¬£¬£¬ÊýÒÔÊ®Íò¼ÆµÄWordPressÍøÕ¾ÕýÔÚÆð¾¢Ê¹ÓÃÕâЩ²å¼þ£¬ £¬£¬£¬ÆäÖÐÒ»Ð©ÍøÕ¾ÔÚÆäÏìÓ¦µÄÖÖ±ðÖÐÅÅÃûµÚÒ»¡£¡£¡£¡£¡£ËùÓÐ9¸öÎó²î¶¼±»·ÖÅÉÁËCVE±êʶ£¬ £¬£¬£¬²¢ÇÒ±»FortiGuardÆÀΪÑÏÖØ¼¶±ðºÍ»ñµÃÁËCVSSÆÀ·Ö9.0·Ö¡£¡£¡£¡£¡£Õâ9¸öÎó²îÖÐÓÐ8¸öÎó²îʹÓÃÁËÏàͬµÄ¼òÆÓ´úÂëģʽ¡£¡£¡£¡£¡£¸÷²å¼þ¹©Ó¦É̶¼ÒѾ­Ðû²¼ÁËÐÞ¸´²¹¶¡ºÍ¸üС£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.fortinet.com/blog/threat-research/wordpress-plugin-sql-injection-vulnerability.html


5.Check PointÐÞ¸´Endpoint SecurityÖеÄÌáȨÎó²î


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Check PointÐÞ¸´ÆäEndpoint Security¿Í»§¶ËÈí¼þÖеÄÌáȨÎó²î£¬ £¬£¬£¬¸ÃÎó²î£¨CVE-2019-8461£©ÔÊÐíDZÔڵĹ¥»÷ÕßÌáÉýÆäȨÏÞÖÁSYSTEM²¢Ö´ÐдúÂë¡£¡£¡£¡£¡£SafeBreach LabsÇå¾²Ñо¿Ô±Peleg Hadar·¢Ã÷Á˸ÃÎÊÌ⣬ £¬£¬£¬¼´¿Éͨ¹ý½«í§ÒâδÊðÃûµÄDLL¼ÓÔØµ½Check Point Endpoint SecurityÈí¼þʹÓõÄWindowsЧÀÍÖ®Ò»À´ÊµÏÖȨÏÞÌáÉýºÍ³¤ÆÚÐÔ¡£¡£¡£¡£¡£Check PointÔÚ8ÔÂ27ÈÕÐû²¼°æ±¾¸üÐÂÐÞ¸´ÁË´ËÎó²î¡£¡£¡£¡£¡£ÕâÊÇHadarÔÚ8Ô·ÝÏòÇå¾²³§É̱¨¸æµÄµÚÈý¸öÍâµØÌáȨÎó²î£¬ £¬£¬£¬Ç°Á½¸öÊÇÇ÷ÊÆ¿Æ¼¼¼°BitdefenderÖеÄÀàËÆÎó²î£¨CVE-2019-14684ºÍCVE-2019-15295£©¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/check-point-patches-privilege-escalation-flaw-in-endpoint-client/


6.ÃÀ¹úÊý°Ù¼ÒÑÀ¿ÆÕïËùÔâÀÕË÷Èí¼þSodinokibi¹¥»÷


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


8ÔÂ26ÈÕÃÀ¹úÊý°Ù¼ÒÑÀ¿ÆÕïËùÔâÀÕË÷Èí¼þSodinokibi¹¥»÷£¬ £¬£¬£¬»¼ÕßÐÅÏ¢±»¼ÓÃÜ¡£¡£¡£¡£¡£ÕâÊǹ¥»÷Õßͨ¹ýÈëÇÖÈí¼þ¹©Ó¦É̲¢Ê¹ÓÃÆä²úÆ·ÔÚ¿Í»§ÏµÍ³ÉÏÖ²ÈëÀÕË÷Èí¼þµÄÁíÒ»¸ö°¸Àý¡£¡£¡£¡£¡£ÔÚ±¾ÆðÊÂÎñÖУ¬ £¬£¬£¬Èí¼þ¹©Ó¦ÉÌÊÇThe Digital Dental RecordºÍPerCSoft£¬ £¬£¬£¬ËûÃÇÏàÖú¿ª·¢ÁËÒ½ÁƼͼÉúÑĺͱ¸·ÝÈí¼þDDS Safe¡£¡£¡£¡£¡£ÉÏÖÜÄ©ºÚ¿ÍÍÅ»ïÈëÇÖÁ˸ÃÈí¼þ±³ºóµÄ»ù´¡ÉèÊ©£¬ £¬£¬£¬²¢Ê¹ÓÃËüÔÚÊý°Ù¸öÑÀÒ½ÕïËùµÄÅÌËã»úÉϰ²ÅÅÁËÀÕË÷Èí¼þSodinokibi¡£¡£¡£¡£¡£ÕâÁ½¼Ò¹«Ë¾Ñ¡ÔñÖ§¸¶Êê½ð»ñÈ¡½âÃÜÆ÷£¬ £¬£¬£¬µ«ÏÖÔÚ»Ö¸´½ø¶È»ºÂý£¬ £¬£¬£¬Ò»Ð©ÑÀ¿ÆÕïËùÉù³Æ½âÃÜÆ÷Ҫô²»Æð×÷Ó㬠£¬£¬£¬ÒªÃ´Ã»Óлָ´ËùÓÐÊý¾Ý¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/ransomware-hits-hundreds-of-dentist-offices-in-the-us/