ÐÅÏ¢Äþ¾²Öܱ¨-2020ÄêµÚ44ÖÜ

Ðû²¼Ê±¼ä 2020-11-02

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2020Äê10ÔÂ26ÈÕÖÁ11ÔÂ01ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´59¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇRuckus Networks Ruckus vRioT /service/v1/createUser endpoint´úÂëÖ´ÐЩ¶´£»Winston PrivacyÃüÁî×¢È멶´£»NVIDIA DGX Server BMC firmwareÓ²±àÂ멶´£»Synology Router ManagerÈÎÒâÃüÁîÖ´ÐЩ¶´£»Google chrome Freetype¶ÑÒç³ö´úÂëÖ´ÐЩ¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇеöÓã»î¶¯Ã°³äMicrosoft TeamsÕë¶ÔOffice 365Óû§£»ImpervaÐû²¼ÓйØKashmirBlack½©Ê¬ÍøÂçµÄ·ÖÎö³ÂËߣ»AvastÐû²¼ÓйØGoogle PlayÉ϶ñÒâÈí¼þµÄ·ÖÎö³ÂËߣ»ºÚ¿ÍÈëÇÖÌØÀÊÆÕ¾ºÑ¡ÍøÕ¾²¢Á÷´«Ðé¼ÙÐÅÏ¢£»CISAºÍCNMFÐû²¼Ð¶ñÒâÈí¼þ±äÌåZebrocyµÄ·ÖÎö³ÂËß¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


ÖØÒªÄþ¾²Â©¶´Áбí


1.Ruckus Networks Ruckus vRioT /service/v1/createUser endpoint´úÂëÖ´ÐЩ¶´


Ruckus Networks Ruckus vRioT /service/v1/createUser endpoint´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿Éͨ¹ýweb.pyÒÔrootȨÏÞÖ´ÐÐÈÎÒâÃüÁî¡£

https://support.ruckuswireless.com/security_bulletins/305


2.Winston PrivacyÃüÁî×¢È멶´


Winston PrivacyÉ豸¹ÜÀíAPI´æÔÚÃüÁî×¢È멶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ɽøÐÐÈÎÒâ´úÂëÖ´Ðй¥»÷£¬Èçͨ¹ý/api/advanced_settings¸ü¸ÄÉ豸¡£

https://labs.bishopfox.com/advisories/winston-privacy-version-1.5.4#CI


3.NVIDIA DGX Server BMC firmwareÓ²±àÂ멶´


NVIDIA DGX Server BMC firmware´æÔÚÓ²±àÂ멶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉδÊÚȨ·ÃÎÊ·þÎñÉ豸¡£

https://nvidia.custhelp.com/app/answers/detail/a_id/5010


4.Synology Router ManagerÈÎÒâÃüÁîÖ´ÐЩ¶´


Synology Router Manager 7786/7787¶Ë¿Ú´æÔÚ²»ÕýÈ··ÃÎÊ¿ØÖÆ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐÈÎÒâÃüÁî¡£

https://www.synology.com/zh-cn/security/advisory/Synology_SA_20_14


5.Google chrome Freetype¶ÑÒç³ö´úÂëÖ´ÐЩ¶´


Google chrome Freetype´æÔÚ¶ÑÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄWEBÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿É½øÐоܾø·þÎñ¹¥»÷»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.html


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢ÐµöÓã»î¶¯Ã°³äMicrosoft TeamsÕë¶ÔOffice 365Óû§


1.jpg


Abnormal Security·¢ÏÖеöÓã»î¶¯Ã°³äMicrosoft TeamsÕë¶ÔOffice 365Óû§¡£ÕâЩµöÓãÓʼþÊÇÒÔTeamsÖÐÓÐлΪÖ÷Ìâ·¢Ë͵Ä£¬¿´ÆðÀ´ÏñÊÇMicrosoft TeamsµÄ×Ô¶¯Í¨Öª£¬ÓÃÀ´¼û¸æÊܺ¦ÕßÓдí¹ýµÄÁÄÌì¡£ÓʼþÓÕʹÊܺ¦Õßµã»÷Team»Ø¸´Á´½Ó£¬ÒÔÖض¨Ïòµ½µöÓãÍøÕ¾£¬À´ÇÔÈ¡Office 365Óû§µÄƾ֤¡£Ñо¿ÈËÔ±ÊӲ쵽£¬¹¥»÷ÕßÒѾ­ÀûÓøÃÔ˶¯¹¥»÷ÁË15000ÖÁ50000¸öOffice 365Óû§¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/109938/cyber-crime/microsoft-teams-phishing-attacks.html


2¡¢ImpervaÐû²¼ÓйØKashmirBlack½©Ê¬ÍøÂçµÄ·ÖÎö³ÂËß


2.jpg


ImpervaÐû²¼ÁËÓйØKashmirBlack½©Ê¬ÍøÂçµÄ·ÖÎö³ÂËß¡£¸Ã³ÂËßÃèÊöÁËKashmirBlack½©Ê¬ÍøÂç±³ºóµÄ·¸×ï²Ù×÷£¬ÌÖÂÛÁËÆäÄ¿µÄÒÔ¼°Ñо¿ÒªÁì¡£KashmirBlackÖ÷ÒªÕë¶ÔÁ÷ÐеÄCMSƽ̨¡£ËüÀûÓÃÁËÄ¿±ê·þÎñÆ÷ÉϵÄÊýÊ®¸öÒÑ֪©¶´£¬Æ½¾ùÿÌì¶ÔÈ«Çò30¶à¸ö²îÒì¹ú¼ÒµÄÊýǧÃûÊܺ¦Õß½øÐÐÊý°ÙÍò´Î¹¥»÷¡£´ËÍ⣬ÆäÔËÐзdz£ÅÓ´ó£¬ÓÉһ̨C&C·þÎñÆ÷¹ÜÀí£¬²¢Ê¹ÓÃÁË60¶ą̀·þÎñÆ÷×÷ΪÆä»ù´¡ÉèÊ©µÄÒ»²¿ÃÅ¡£¿É´¦ÖÃÊý°Ù¸ö½©Ê¬·¨Ê½£¬Ö´Ðб©Á¦¹¥»÷¡¢°²×°ºóÃÅ¡¢²¢À©´ó½©Ê¬ÍøÂçµÄ¹æÄ£¡£    


Ô­ÎÄÁ´½Ó£º

https://www.imperva.com/blog/crimeops-of-the-kashmirblack-botnet-part-i/


3¡¢AvastÐû²¼ÓйØGoogle PlayÉ϶ñÒâÈí¼þµÄ·ÖÎö³ÂËß


3.jpg


ɱ¶¾Èí¼þÖÆÔìÉÌAvastÐû²¼ÓйØGoogle PlayÉ϶ñÒâÈí¼þµÄ·ÖÎö³ÂËß¡£¸Ã³ÂËß³ÆGoogle PlayÉ̵êÖÐÓÐ21¸öѬȾÁËHiddenAds¶ñÒâÈí¼þµÄAndroidÓ¦Ó÷¨Ê½£¬GoogleÒÑÓÚÖÜĩɾ³ýÁËÆäÖеÄ15¸ö¡£Avast¶ñÒâÈí¼þ·ÖÎöʦÌåÏÖ£¬ÕâЩӦÓÃÄ£·ÂÁËÁ÷ÐеÄÓÎÏ·£¬Ò»µ©Óû§°²×°ÁËÕâЩӦÓã¬HiddenAds¾Í»áÒþ²Ø¸ÃÓ¦Ó÷¨Ê½µÄͼ±êʹÓû§ÄÑÒÔ½øÐÐɾ³ý£¬È»ºó¿ªÊ¼Óùã¸æºäÕ¨Óû§¡£AvastÌåÏÖ£¬½ØÖÁÉÏÖÜÕâЩӦÓ÷¨Ê½ÒÑ´ï700Íò´ÎÏÂÔØÁ¿¡£


Ô­ÎÄÁ´½Ó£º

https://blog.avast.com/new-malware-apps-on-google-play-avast


4¡¢ºÚ¿ÍÈëÇÖÌØÀÊÆÕ¾ºÑ¡ÍøÕ¾²¢Á÷´«Ðé¼ÙÐÅÏ¢


4.jpg


Õþ¸®¹ÙÔ±ÌåÏÖ£¬ºÚ¿ÍÔÚÑ¡¾ÙÈÕÇ°Ò»ÖܵÄÐÇÆÚ¶þÈëÇÖÁËÌÆÄɵ¡¤ÌØÀÊÆյľºÑ¡ÍøÕ¾¡£donaldjtrump.comÍøÕ¾±»¡°Õâ¸öÍøÕ¾±»²é·âÁË¡±ÏûÏ¢ËùÈ¡´ú£¬²¢ÌåÏÖ¡°ÊÀ½çÒѾ­Êܹ»ÁËÌÆÄɵ¡¤J¡¤ÌØÀÊÆÕ×ÜͳÿÌìÉ¢²¥µÄ¼ÙÐÂÎÅ¡±¡£´ËÍ⣬ºÚ¿Í»¹ºôÓõÍøÃñ¾èÔùMoneroÊý×Ö»õ±ÒÒÔÖ§³Ö»ò×赲й¶ÓëÌØÀÊÆÕÓйصÄÖ¤¾Ý¡£ÌØÀÊÆÕ¾ºÑ¡·¢ÑÔÈËTim MurtaughÌåÏÖ£¬¸ÃÍøÕ¾ºÜ¿ìµÃµ½ÐÞ¸´²¢Ã»ÓÐÈκÎÃô¸ÐÊý¾Ýй¶£¬´Ë´Î¹¥»÷µÄÀ´Ô´»¹ÔÚÊÓ²ìÖС£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/trump-campaign-website-broken-hackers


5¡¢CISAºÍCNMFÐû²¼Ð¶ñÒâÈí¼þ±äÌåZebrocyµÄ·ÖÎö³ÂËß


5.jpg


ÍøÂçÄþ¾²ºÍ»ù´¡ÉèÊ©Äþ¾²¾Ö£¨CISA£©ºÍ¹ú·À²¿£¨DOD£©ÍøÂç¹ú¼ÒÐû½Ì¶ÓÎ飨CNMF£©·¢ÏÖеĶñÒâÈí¼þ±äÌåZebrocy¡£¸Ã±äÌåÊÇÒ»¸ö32λµÄWindows¿ÉÖ´ÐÐÎļþ£¬Ê¹ÓÃGolang±à³ÌÓïÑÔ±àд£¬½ÓÄɵIJÎÊýӦΪÒì»ò£¨XOR£©ºÍÊ®Áù½øÖƱàÂëµÄͳһ×ÊÔ´±êʶ·û£¨URI£©£¬»òÕß¿ÉÒÔʹÓô¿Îı¾URIÔËÐС£Ö´ÐÐʱ£¬Ëü½«Ê¹Óø߼¶¼ÓÃܳ߶ȣ¨AES£©-128µç×ÓÃÜÂë²¾£¨ECB£©Ëã·¨¶ÔURI½øÐмÓÃÜ£¬²¢Ê¹ÓôÓÊܺ¦ÕßµÄÖ÷»úÃûÉú³ÉµÄÃÜÔ¿£¬´ËÍ⻹»áÊÕ¼¯ÓйØÊÜÄ¿±êϵͳµÄÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/10/29/cisa-and-cnmf-identify-new-malware-variant-zebrocy