GoogleÐû²¼chromeÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´WebGLÖдúÂëÖ´ÐÐÎó²î £»£»£»£»LazarusʹÓÃLinkedInÕÐÆ¸¹ã¸æ¹¥»÷¼ÓÃÜÇ®±Ò¹«Ë¾

Ðû²¼Ê±¼ä 2020-08-26

1.GoogleÐû²¼chromeÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´WebGLÖдúÂëÖ´ÐÐÎó²î


1.jpg


GoogleÐû²¼chromeÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÆäWebGLÖдúÂëÖ´ÐÐÎó²î¡£¡£¡£ ¡£¡£¡£¡£¸ÃÎó²îÓÉ˼¿ÆTalosµÄÑо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬£¬£¬£¬ÆäλÓÚOpenGLºÍChromeä¯ÀÀÆ÷¼°ÆäËûÏîÄ¿ÔÚWindowsÉÏʹÓõÄDirect3DÖ®¼äµÄ¼æÈݲãANGLEÖУ¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÊʵ±µÄÄÚ´æ½á¹¹ºóʹÓøÃÎó²î£¬£¬£¬£¬£¬£¬£¬ÔÚä¯ÀÀÆ÷ÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£ ¡£¡£¡£¡£¸ÃÎó²î±»×·×ÙΪCVE-2020-6492£¬£¬£¬£¬£¬£¬£¬CVSSv3ÆÀ·ÖΪ8.3£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁËGoogle Chrome 81.0.4044.138£¨Stable£©£¬£¬£¬£¬£¬£¬£¬84.0.4136.5£¨Dev£©ºÍ84.0.4143.7£¨Canary£©£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚÒѱ»GoogleÐÞ¸´¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/google-chrome-85-fixes-webgl-code-execution-vulnerability/


2.ÒÁÀʺڿÍͨ¹ý¹¥»÷̻¶µÄRDPЧÀÍÆ÷À´×°ÖÃÀÕË÷Èí¼þDharma


2.jpg


ÒÁÀÊеĺڿÍ×é֯ͨ¹ý¹¥»÷̻¶µÄRDPЧÀÍÆ÷À´×°ÖÃÀÕË÷Èí¼þDharma£¬£¬£¬£¬£¬£¬£¬Õë¶Ô¶íÂÞ˹¡¢Ó¡¶È¡¢ÖйúºÍÈÕ±¾¹«Ë¾¡£¡£¡£ ¡£¡£¡£¡£ËûÃÇͨ¹ý¿ªÔ´¶Ë¿ÚɨÃèÆ÷MasscanɨÃèInternetÉϵÄIPµØµãÒÔ²éÕÒ̻¶µÄÔ¶³Ì×ÀÃæÅþÁ¬£¨RDP£©£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚÕÒµ½ºÏÊʵÄÊܺ¦Õß¡£¡£¡£ ¡£¡£¡£¡£Ö®ºó»áʹÓÃNLBruteÆô¶¯±©Á¦ÆÆ½â³ÌÐòÆÆ½âRDPÃÜÂë¡£¡£¡£ ¡£¡£¡£¡£ÀֳɽøÈëºó£¬£¬£¬£¬£¬£¬£¬ËûÃÇ»áʹÓÃWindows 7ÖÁ10ÖеľÉÎó²î£¨CVE-2017-0213£©¾ÙÐÐÌáȨ¡£¡£¡£ ¡£¡£¡£¡£¸Ã×éÖ¯µÄÊê½ðÒªÇóÔÚ1-5±ÈÌØ±ÒÖ®¼ä£¨$ 11,700-$ 59,000£©£¬£¬£¬£¬£¬£¬£¬ÓëÆäËûÀÕË÷Èí¼þ×éÖ¯Ïà±È½ð¶î½ÏС¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/iranian-hackers-attack-exposed-rdp-servers-to-deploy-dharma-ransomware/


3.LazarusʹÓÃLinkedInÕÐÆ¸¹ã¸æ¹¥»÷¼ÓÃÜÇ®±Ò¹«Ë¾


3.jpg


F-SecureµÄÍøÂçÇå¾²Ñо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬£¬£¬£¬APT×éÖ¯LazarusʹÓÃLinkedInÕÐÆ¸¹ã¸æ¹¥»÷¼ÓÃÜÇ®±Ò¹«Ë¾¡£¡£¡£ ¡£¡£¡£¡£Ôڴ˴ι¥»÷»î¶¯ÖУ¬£¬£¬£¬£¬£¬£¬LazarusÏòÄ¿µÄ¹«Ë¾µÄϵͳÖÎÀíԱСÎÒ˽¼ÒLinkedInÕÊ»§Öз¢ËÍÕÐÆ¸¹ã¸æ£¬£¬£¬£¬£¬£¬£¬ËµÃ÷Ò»¼ÒÇø¿éÁ´ÊÖÒÕ¹«Ë¾ÕýÔÚ×·ÇóеÄsysadmin¡£¡£¡£ ¡£¡£¡£¡£¸Ã¹ã¸æ½«ÓÕʹÊܺ¦Õ߯ôÓú꣬£¬£¬£¬£¬£¬£¬ÒÔ½¨ÉèÒ»¸ö.LNKÎļþ£¬£¬£¬£¬£¬£¬£¬¸ÃÎļþÖ¼ÔÚÖ´ÐÐÒ»¸öÃûΪmshta.exeµÄÎļþ£¬£¬£¬£¬£¬£¬£¬²¢Å²ÓÃÅþÁ¬µ½VBScriptµÄbit.lyÁ´½Ó£¬£¬£¬£¬£¬£¬£¬²¢½«²Ù×÷ÐÅÏ¢·¢Ë͵½C2ЧÀÍÆ÷¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/lazarus-group-strikes-cryptocurrency-firm-through-linkedin-job-adverts/


4.ZoomЧÀÍÔÙ´ÎÖÐÖ¹£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÓ°ÏìÃÀ¹ú¶«º£°¶ºÍÓ¢¹úµÄÓû§


4.jpg


ZoomЧÀÍÔÙ´ÎÖÐÖ¹£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÓ°ÏìÃÀ¹ú¶«º£°¶ºÍÓ¢¹úµÄÓû§¡£¡£¡£ ¡£¡£¡£¡£ZoomÌåÏÖÔÚ´Ë´ÎÖÐÖ¹ÖУ¬£¬£¬£¬£¬£¬£¬Ðí¶àÓû§ÎÞ·¨»á¼ûZoomÍøÕ¾£¨zoom.us£©£¬£¬£¬£¬£¬£¬£¬²¢ÎÞ·¨Æô¶¯ºÍ¼ÓÈëZoom Meetings¡£¡£¡£ ¡£¡£¡£¡£×èÖ¹ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬ZoomÒÑÈ·¶¨µ¼Ö´˴ιÊÕϵÄÔµ¹ÊÔ­ÓÉ£¬£¬£¬£¬£¬£¬£¬²¢ÒѾÙÐÐÐÞ¸´¡£¡£¡£ ¡£¡£¡£¡£Õâ²¢²»µÚÒ»´Î±¬·¢ÀàËÆ¹ÊÕÏ£¬£¬£¬£¬£¬£¬£¬ÔçÔÚ4Ô£¬£¬£¬£¬£¬£¬£¬ZoomÓû§ÌåÏÖËûÃÇÎÞ·¨Æô¶¯Web¿Í»§¶Ë²¢ÏÔʾ403 Forbidden¹ýʧ£¬£¬£¬£¬£¬£¬£¬¶øÉÏÖÜÓû§Ò²·¢Ã÷ÎÞ·¨Í¨¹ýZoom Web¿Í»§¶ËºÍWebSDK¼ÓÈë¾Û»á¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/technology/zoom-went-down-and-schools-got-a-digital-snow-day/


5.¿¨°Í˹»ùÐû²¼ÓйØÍøÂçÌØ¹¤×éÖ¯DeathStalkerµÄÆÊÎö±¨¸æ


5.jpg


¿¨°Í˹»ù·¢Ã÷Ò»¸öרÃÅ´ÓÊÂÇÔÈ¡ÉÌÒµÉñÃØµÄÍøÂç·¸·¨×éÖ¯Ö¯DeathStalker£¬£¬£¬£¬£¬£¬£¬²¢Ðû²¼Õë¶ÔÆäµÄÆÊÎö±¨¸æ¡£¡£¡£ ¡£¡£¡£¡£¸Ã×éÖ¯×Ô2018Äê»ò¸üÔ磨¿ÉÄÜ×Ô2012Ä꣩¾Í×îÏÈ»îÔ¾£¬£¬£¬£¬£¬£¬£¬Ö÷Òª¶Ô½ðÈڿƼ¼¹«Ë¾¡¢×´Ê¦ÊÂÎñËùºÍ²ÆÎñÕÕÁÏ¡£¡£¡£ ¡£¡£¡£¡£DeathStalker²»»á°²ÅÅÀÕË÷Èí¼þ»òÇÔȡ֧¸¶Êý¾Ý£¬£¬£¬£¬£¬£¬£¬Æä¹Ø×¢µÄÖØµãÊÇÃô¸ÐµÄÓªÒµÊý¾Ý£¬£¬£¬£¬£¬£¬£¬ÕâÒâζ×ÅDeathStalke¿ÉÄÜÌṩÁËºÚ¿ÍÆ¸ÓÃЧÀÍ£¬£¬£¬£¬£¬£¬£¬»òÕ߳䵱Á˽ðÈÚ½çµÄÐÅÏ¢¾­¼ÍÈË¡£¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.kaspersky.com/blog/deathstalker-powersing/36815/


6.Ó¡¶ÈÂÃÓÎÍøÕ¾RailYatriÒòÊý¾Ý¿âÉèÖùýʧй¶3700ÍòÌõ¼Í¼


6.jpg


SafetyDetectives 8ÔÂ10ÈÕÔÚÍøÂçÉÏ·¢Ã÷ÁËRailYatriµÄûÓÐÃÜÂë± £»£»£»£»¤µÄElasticsearchЧÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶3700ÍòÌõ¼Í¼¿Í»§ºÍ¹«Ë¾Êý¾Ý£¬£¬£¬£¬£¬£¬£¬°üÀ¨Óû§µÄÈ«Ãû¡¢ÄêËê¡¢ÐÔ±ð¡¢ÏÖʵºÍµç×ÓÓʼþµØµã¡¢ÊÖ»úºÅÂë¡¢Ô¤¶©ÏêϸÐÅÏ¢¡¢GPSλÖÃÒÔ¼°ÐÕÃû/Ö§¸¶¿¨µÄǰËÄλºÍºóËÄλ¡£¡£¡£ ¡£¡£¡£¡£¶øÔڸù«Ë¾¶ÔÆäÊý¾Ý¾ÙÐб £»£»£»£»¤Ö®Ç°£¬£¬£¬£¬£¬£¬£¬Meow»úеÈËÓÚ8ÔÂ12ÈÕ¶ÔÆä±¬·¢¹¥»÷£¬£¬£¬£¬£¬£¬£¬É¾³ýÁ˳ý1GBÖ®ÍâµÄËùÓÐÊý¾Ý£¨×ܹ²43 GB£©¡£¡£¡£ ¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/travel-site-exposed-37m-records/