FireEyeÐû²¼½üÊýÄê0dayʹÓÃµÄÆÊÎö±¨¸æ £»£»£»£»£»COVID-19ʱ´úÕë¶ÔNASAµÄ´¹ÂÚ¹¥»÷´ó·ùÉÏÉý

Ðû²¼Ê±¼ä 2020-04-08

1.ʯÓ͹«Ë¾BerkineÔâMaze¹¥»÷£¬£¬ £¬£¬Áè¼Ý500MBÊý¾Ý±»ÇÔ


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


4ÔÂ1ÈÕʯÓ͹«Ë¾BerkineÔâµ½ÀÕË÷Èí¼þÍÅ»ïMaze¹¥»÷£¬£¬ £¬£¬¹¥»÷ÕßÏë·¨ÇÔÈ¡Á˸ù«Ë¾µÄÊý¾Ý¿â£¬£¬ £¬£¬ÆäÖаüÀ¨Áè¼Ý500MBµÄÉñÃØÎĵµ¡£¡£¡£¡£ÕâЩÎĵµÓëÔ¤Ëã¡¢×éÖ¯Õ½ÂÔ¡¢Éú²úÁ¿µÈÃô¸ÐÊý¾ÝÓйØ¡£¡£¡£¡£BerkineÊǰ¢¶û¼°ÀûÑǹúÓÐʯÓ͹«Ë¾SonatrachºÍÃÀ¹úʯÓ͹«Ë¾Anadarko Algeria CompanyµÄºÏ×ÊÆóÒµ¡£¡£¡£¡£Æ¾Ö¤Under BreachµÄ˵·¨£¬£¬ £¬£¬Ð¹Â¶µÄÎĵµÓëBerkineµÄ²ÆÎñϸ½ÚºÍͶ×ÊÍýÏëÓйأ¬£¬ £¬£¬°üÀ¨BerkineʯÓ͵ÄÿͰ±¾Ç®¼ÛÇ®¡¢2020ÄêµÄ×é֯ĿµÄÒÔ¼°·ÖÅɸøBerkineÁ½Î»ËùÓÐÕßµÄÖÖÖÖʹÃüµÄÔ¤Ëã¡£¡£¡£¡£Êý¾Ý¿âÖл¹°üÀ¨BerkineÔ±¹¤ÁªÏµ·½·¨¼°ÂÃÐÐÖ¤¼þµÄÁбí¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/maze-ransomware-group-hacks-oil-giant-leaks-data/


2.Email.itÔâºÚ¿ÍÈëÇÖ£¬£¬ £¬£¬60ÍòÓû§Êý¾ÝÔÚ°µÍø³öÊÛ


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø



Òâ´óÀûÓʼþЧÀÍÉÌEmail.itÈ·ÈÏÔâµ½ºÚ¿ÍÈëÇÖ£¬£¬ £¬£¬ÏÖÔÚÓÐÁè¼Ý60ÍòÓû§µÄÊý¾ÝÔÚ°µÍø³öÊÛ¡£¡£¡£¡£ºÚ¿ÍÍÅ»ïNN£¨No Name£©Hacking GroupÉù³ÆÈëÇÖÏÖʵ±¬·¢ÔÚÁ½Äê¶àÒÔǰµÄ2018Äê1Ô¡£¡£¡£¡£¸ÃÍÅ»ïÔÚ2ÔÂ1ÈÕÊÔͼÀÕË÷Email.it£¬£¬ £¬£¬µ«Email.it¾Ü¾øÖ§¸¶Êê½ð²¢Í¨ÖªÁËÒâ´óÀûÓÊÕþ¾¯Ô±¾Ö£¨CNAIPIC£©¡£¡£¡£¡£ÔÚÀÕË÷ʧ°Üºó£¬£¬ £¬£¬¸ÃÍÅ»ïÏÖÔÚÒÔ0.5ÖÁ3±ÈÌØ±Ò£¨3500ÖÁ22000ÃÀÔª£©µÄ¼ÛÇ®³öÊÛÕâЩÊý¾Ý¡£¡£¡£¡£¸ÃÍÅ»ïÉù³ÆÓµÓдÓEmail.itϵͳÖÐÇÔÈ¡µÄ46¸öÊý¾Ý¿â£¬£¬ £¬£¬ÆäÖаüÀ¨Ãâ·ÑEmail.itµç×ÓÓʼþÕÊ»§µÄÓû§ÐÅÏ¢¡£¡£¡£¡£ºÚ¿ÍÉù³ÆÊý¾Ý¿âÖаüÀ¨2007ÄêÖÁ2020ÄêÖ®¼ä×¢²áºÍʹÓøÃЧÀ͵Ä60¶àÍòÓû§µÄÃ÷ÎÄÃÜÂë¡¢Çå¾²ÌáÐÑÎÊÌâ¡¢µç×ÓÓʼþÄÚÈݺ͸½¼þ£¬£¬ £¬£¬»¹Éù³ÆÓµÓÐͨ¹ýEmail.itµÄSMSЧÀÍ·¢Ë͵Ĵ¿Îı¾SMSÐÂÎÅ£¬£¬ £¬£¬ÒÔ¼°ËùÓÐEmail.itÍøÂçÓ¦ÓóÌÐòµÄÔ´´úÂë¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/email-provider-got-hacked-data-of-600000-users-now-sold-on-the-dark-web/


3.¹È¸èÐû²¼4ÔÂAndroidÇå¾²¸üУ¬£¬ £¬£¬ÐÞ¸´50¶à¸öÎó²î


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


¹È¸èÐû²¼4ÔÂAndroidÇå¾²¸üУ¬£¬ £¬£¬ÐÞ¸´50¶à¸öÎó²î£¬£¬ £¬£¬ÆäÖаüÀ¨ÏµÍ³×é¼þÖеÄ4¸öÑÏÖØÎó²î¡£¡£¡£¡£Õâ4¸öÎó²î°üÀ¨CVE-2020-0070¡¢CVE-2020-0071¡¢CVE-2020-0072ºÍCVE-2020-0073£¬£¬ £¬£¬¶¼¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐУ¬£¬ £¬£¬²¢ÇÒ¶¼Ó°ÏìAndroid 8.0¡¢8.1¡¢9ºÍ10£¬£¬ £¬£¬Æä²¹¶¡°üÀ¨ÔÚÇå¾²²¹¶¡³ÌÐò¼¶±ð2020-04-01ÖС£¡£¡£¡£±ðµÄ£¬£¬ £¬£¬¹È¸è»¹ÔÚÇå¾²²¹¶¡³ÌÐò¼¶±ð2020-04-05ÖÐÐÞ¸´ÁË43¸öÎó²î£¬£¬ £¬£¬°üÀ¨¿ò¼Ü×é¼þÖеÄ1¸öÐÅϢй¶Îó²î¡¢ÄÚºË×é¼þÖеÄ3¸öÌáȨÎó²î¡¢FPC×é¼þÖеÄ1¸öÌáȨºÍ2¸öÐÅϢй¶Îó²î¡¢¸ßͨ×é¼þÖеÄ6¸öÎó²îÒÔ¼°¸ßͨ±ÕÔ´×é¼þÖеÄ30¸öÎó²î¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/google-patches-critical-rce-vulnerabilities-androids-system-component


4.FireEyeÐû²¼×î½üÊýÄê0dayʹÓÃÇéÐÎµÄÆÊÎö±¨¸æ


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


FireEye MandiantÍþвÇ鱨ÍŶӼͼµÄ2019Äê0dayʹÓÃÁ¿±ÈǰÈýÄêÖеÄÈκÎÒ»Äê¶¼Òª¶à¡£¡£¡£¡£Ö»¹Ü²¢²»¿É½«Ã¿Ò»¸ö0dayʹÓö¼¹éÒòµ½Ìض¨µÄ¹¥»÷Õߣ¬£¬ £¬£¬µ«Ñо¿Ö°Ô±×¢Öص½Ô½À´Ô½¶àµÄ¹¥»÷Õß»ñµÃÁË0dayʹÓõÄÄÜÁ¦¡£¡£¡£¡£FireEyeÒÔΪ£¬£¬ £¬£¬ÕâÖÖ¼¤ÔöÖÁÉÙ²¿·ÖÊÇÓÉÓÚÒ»Ö±Éú³¤µÄ¹ÍÓ¶ºÚ¿ÍÐÐÒµÉú³¤ÆðÀ´µÄ£¬£¬ £¬£¬ÕâЩÐÐÒµ¿ª·¢0dayʹÓù¤¾ß²¢½«Æä³öÊÛ¸øÌìϸ÷µØµÄÇ鱨»ú¹¹¡£¡£¡£¡£¹¥»÷ÕßÓë0dayʹÓÃÖ®¼äµÄ×î´óÕϰ­²»ÊÇÊÖÒÕ£¬£¬ £¬£¬¶øÊÇÏֽ𡣡£¡£¡£ÏêϸÀ´Ëµ£¬£¬ £¬£¬FireEyeÖ¸³öNSO Group¡¢Gamma GroupºÍHacking TeamÊÇÕâÀà³Ð°üÉÌ£¬£¬ £¬£¬ÕâЩ³Ð°üÉÌʹһÅúеĹú¼Ò/µØÇøÄܹ»¹ºÖÃ0dayʹÓᣡ£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.fireeye.com/blog/threat-research/2020/04/zero-day-exploitation-demonstrates-access-to-money-not-skill.html


5.¸çÂ×±ÈÑǹٷ½COVID-19 App±£´æÎó²îй¶Óû§Êý¾Ý


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ZeroFOXµÄAlphaÍŶӷ¢Ã÷¸çÂ×±ÈÑÇÕþ¸®ÕýʽÅú×¼µÄCOVID-19 APP°üÀ¨Îó²î£¬£¬ £¬£¬¿Éµ¼ÖÂÓû§Êý¾Ýй¶¡£¡£¡£¡£¸ÃAPPΪCoronApp-Columbia£¬£¬ £¬£¬ÓÃÓÚ×ÊÖú¸çÂ×±ÈÑÇÈË·¢ËÍ¿µ½¡×´Ì¬¸üв¢ÎüÊÕ¹Ú×´²¡¶¾ÐÂÎÅ¡£¡£¡£¡£¸ÃAPPÓµÓÐÁè¼Ý10Íò¸öÓû§¡£¡£¡£¡£ZeroFOXÍþвÇ鱨×ܼàZack AllenÌåÏÖ£¬£¬ £¬£¬CoronApp-ColumbiaÓ¦ÓÃÒÔÃ÷ÎÄÐÎʽ·¢ËÍСÎÒ˽¼Ò¿µ½¡ÐÅÏ¢£¨PHI£©ºÍСÎÒ˽¼ÒÉí·ÝÐÅÏ¢£¨PII£©Êý¾Ý£¬£¬ £¬£¬Õâ°üÀ¨»¤ÕÕºÅÂë¡¢ÃÜÂëºÍ×ÔÎÒÅû¶µÄ¿µ½¡ÐÅÏ¢¡£¡£¡£¡£ÕâÒýÆðÁËÈËÃǶԹٷ½Åú×¼/½¨ÉèµÄCOVID-19 APPÇå¾²ÐԵĵ£ÐÄ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/vulnerabilities-covid19-app/


6.COVID-19ʱ´úÕë¶ÔNASAµÄ´¹ÂÚ¹¥»÷´ó·ùÉÏÉý


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


NASA³ÆCOVID-19ʱ´úÃñ×å¹ú¼ÒºÚ¿ÍºÍÍøÂç·¸·¨·Ö×ÓÕë¶Ôº½Ìì¾ÖϵͳºÍÔڼҰ칫Ա¹¤µÄ¶ñÒâ»î¶¯ÏÔÖøÔöÌí¡£¡£¡£¡£NASAÇå¾²ÔËÓªÖÐÐÄ£¨SOC£©±¨¸æµÄÍøÂç´¹ÂÚ¹¥»÷´ÎÊý·­ÁËÒ»·¬£¬£¬ £¬£¬¶ñÒâÈí¼þ¹¥»÷³ÊÖ¸Êý¼¶ÔöÌí£¬£¬ £¬£¬±»×èÖ¹µÄ¶ñÒâÕ¾µãÊýĿҲ·­ÁËÒ»·¬¡£¡£¡£¡£ÃÀ¹úÓ¾Ö°ì¹«ÊÒÏòËùÓÐNASAÖ°Ô±Ðû²¼µÄ±¸Íü¼Öгƣ¬£¬ £¬£¬¹ú¼ÒºÍÍøÂç×ï·¸ÕýÔÚÆð¾¢Ê¹ÓÃCOVID-19µÄÊ¢ÐÐÀ´Õë¶ÔNASAµç×Ó×°±¸¡¢ÍøÂçºÍСÎÒ˽¼Ò×°±¸£¬£¬ £¬£¬ËûÃǵÄÄ¿µÄ°üÀ¨»á¼ûÃô¸ÐÐÅÏ¢¡¢Óû§ÃûºÍÃÜÂë¡¢¾ÙÐоܾøÐ§À͹¥»÷¡¢É¢²¼ÐéαÐÅÏ¢ÒÔ¼°¾ÙÐÐڲƭ¡£¡£¡£¡£NASAÇ徲ר¼Ò»¹·¢Ã÷£¬£¬ £¬£¬Ä³Ð©¹¥»÷²»µ«Õë¶Ǫ̂ʽ»ú£¬£¬ £¬£¬²¢ÇÒ»¹Õë¶ÔÒÆ¶¯ÏµÍ³£¬£¬ £¬£¬ÊÔͼÓÕÆ­Êܺ¦Õßй¶Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/nasa-under-significantly-increasing-hacking-phishing-attacks/