ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ44ÖÜ

Ðû²¼Ê±¼ä 2020-11-02

> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2020Äê10ÔÂ26ÈÕÖÁ11ÔÂ01ÈÕ¹²ÊÕ¼Çå¾²Îó²î59¸ö£¬£¬ÖµµÃ¹Ø×¢µÄÊÇRuckus Networks Ruckus vRioT /service/v1/createUser endpoint´úÂëÖ´ÐÐÎó²î£»£»£»£»£»Winston PrivacyÏÂÁî×¢ÈëÎó²î£»£»£»£»£»NVIDIA DGX Server BMC firmwareÓ²±àÂëÎó²î£»£»£»£»£»Synology Router Managerí§ÒâÏÂÁîÖ´ÐÐÎó²î£»£»£»£»£»Google chrome Freetype¶ÑÒç³ö´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇд¹Âڻð³äMicrosoft TeamsÕë¶ÔOffice 365Óû§£»£»£»£»£»ImpervaÐû²¼ÓйØKashmirBlack½©Ê¬ÍøÂçµÄÆÊÎö±¨¸æ£»£»£»£»£»AvastÐû²¼ÓйØGoogle PlayÉ϶ñÒâÈí¼þµÄÆÊÎö±¨¸æ£»£»£»£»£»ºÚ¿ÍÈëÇÖÌØÀÊÆÕ¾ºÑ¡ÍøÕ¾²¢Èö²¥ÐéαÐÅÏ¢£»£»£»£»£»CISAºÍCNMFÐû²¼Ð¶ñÒâÈí¼þ±äÌåZebrocyµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£


Ö÷ÒªÇå¾²Îó²îÁбí


1.Ruckus Networks Ruckus vRioT /service/v1/createUser endpoint´úÂëÖ´ÐÐÎó²î


Ruckus Networks Ruckus vRioT /service/v1/createUser endpoint±£´æÊäÈëÑéÖ¤Îó²î£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬¿Éͨ¹ýweb.pyÒÔrootȨÏÞÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£

https://support.ruckuswireless.com/security_bulletins/305


2.Winston PrivacyÏÂÁî×¢ÈëÎó²î


Winston Privacy×°±¸ÖÎÀíAPI±£´æÏÂÁî×¢ÈëÎó²î£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬¿É¾ÙÐÐí§Òâ´úÂëÖ´Ðй¥»÷£¬£¬Èçͨ¹ý/api/advanced_settings¸ü¸Ä×°±¸¡£¡£¡£¡£¡£¡£

https://labs.bishopfox.com/advisories/winston-privacy-version-1.5.4#CI


3.NVIDIA DGX Server BMC firmwareÓ²±àÂëÎó²î


NVIDIA DGX Server BMC firmware±£´æÓ²±àÂëÎó²î£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬¿ÉδÊÚȨ»á¼ûЧÀÍ×°±¸¡£¡£¡£¡£¡£¡£

https://nvidia.custhelp.com/app/answers/detail/a_id/5010


4.Synology Router Managerí§ÒâÏÂÁîÖ´ÐÐÎó²î


Synology Router Manager 7786/7787¶Ë¿Ú±£´æ²»×¼È·»á¼û¿ØÖÆÎó²î£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬¿ÉÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£

https://www.synology.com/zh-cn/security/advisory/Synology_SA_20_14


5.Google chrome Freetype¶ÑÒç³ö´úÂëÖ´ÐÐÎó²î


Google chrome Freetype±£´æ¶ÑÒç³öÎó²î£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇ󣬣¬ÓÕʹÓû§ÆÊÎö£¬£¬¿É¾ÙÐоܾøÐ§À͹¥»÷»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£

https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.html


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢Ð´¹Âڻð³äMicrosoft TeamsÕë¶ÔOffice 365Óû§


1.jpg


Abnormal Security·¢Ã÷д¹Âڻð³äMicrosoft TeamsÕë¶ÔOffice 365Óû§¡£¡£¡£¡£¡£¡£ÕâЩ´¹ÂÚÓʼþÊÇÒÔTeamsÖÐÓÐлΪÖ÷Ìâ·¢Ë͵Ä£¬£¬¿´ÆðÀ´ÏñÊÇMicrosoft TeamsµÄ×Ô¶¯Í¨Öª£¬£¬ÓÃÀ´¼û¸æÊܺ¦ÕßÓдí¹ýµÄ̸Ìì¡£¡£¡£¡£¡£¡£ÓʼþÓÕʹÊܺ¦Õßµã»÷Team»Ø¸´Á´½Ó£¬£¬ÒÔÖØ¶¨Ïòµ½´¹ÂÚÍøÕ¾£¬£¬À´ÇÔÈ¡Office 365Óû§µÄƾ֤¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÊӲ쵽£¬£¬¹¥»÷ÕßÒѾ­Ê¹ÓøÃÔ˶¯¹¥»÷ÁË15000ÖÁ50000¸öOffice 365Óû§¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/109938/cyber-crime/microsoft-teams-phishing-attacks.html


2¡¢ImpervaÐû²¼ÓйØKashmirBlack½©Ê¬ÍøÂçµÄÆÊÎö±¨¸æ


2.jpg


ImpervaÐû²¼ÁËÓйØKashmirBlack½©Ê¬ÍøÂçµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¸Ã±¨¸æÐÎòÁËKashmirBlack½©Ê¬ÍøÂç±³ºóµÄ·¸·¨²Ù×÷£¬£¬ÌÖÂÛÁËÆäÄ¿µÄÒÔ¼°Ñо¿ÒªÁì¡£¡£¡£¡£¡£¡£KashmirBlackÖ÷ÒªÕë¶ÔÊ¢ÐеÄCMSƽ̨¡£¡£¡£¡£¡£¡£ËüʹÓÃÁËÄ¿µÄЧÀÍÆ÷ÉϵÄÊýÊ®¸öÒÑÖªÎó²î£¬£¬Æ½¾ùÌìÌì¶ÔÈ«Çò30¶à¸ö²î±ð¹ú¼ÒµÄÊýǧÃûÊܺ¦Õß¾ÙÐÐÊý°ÙÍò´Î¹¥»÷¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬ÆäÔËÐкÜÊÇÖØ´ó£¬£¬ÓÉһ̨C&CЧÀÍÆ÷ÖÎÀí£¬£¬²¢Ê¹ÓÃÁË60¶ą̀ЧÀÍÆ÷×÷ΪÆä»ù´¡ÉèÊ©µÄÒ»²¿·Ö¡£¡£¡£¡£¡£¡£¿£¿£¿£¿É´¦Öóͷ£Êý°Ù¸ö½©Ê¬³ÌÐò£¬£¬Ö´Ðб©Á¦¹¥»÷¡¢×°ÖúóÃÅ¡¢²¢À©´ó½©Ê¬ÍøÂçµÄ¹æÄ£¡£¡£¡£¡£¡£¡£    


Ô­ÎÄÁ´½Ó£º

https://www.imperva.com/blog/crimeops-of-the-kashmirblack-botnet-part-i/


3¡¢AvastÐû²¼ÓйØGoogle PlayÉ϶ñÒâÈí¼þµÄÆÊÎö±¨¸æ


3.jpg


ɱ¶¾Èí¼þÖÆÔìÉÌAvastÐû²¼ÓйØGoogle PlayÉ϶ñÒâÈí¼þµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¸Ã±¨¸æ³ÆGoogle PlayÊÐËÁÖÐÓÐ21¸öѬȾÁËHiddenAds¶ñÒâÈí¼þµÄAndroidÓ¦ÓóÌÐò£¬£¬GoogleÒÑÓÚÖÜĩɾ³ýÁËÆäÖеÄ15¸ö¡£¡£¡£¡£¡£¡£Avast¶ñÒâÈí¼þÆÊÎöʦÌåÏÖ£¬£¬ÕâЩӦÓÃÄ£ÄâÁËÊ¢ÐеÄÓÎÏ·£¬£¬Ò»µ©Óû§×°ÖÃÁËÕâЩӦÓ㬣¬HiddenAds¾Í»áÒþ²Ø¸ÃÓ¦ÓóÌÐòµÄͼ±êʹÓû§ÄÑÒÔ¾ÙÐÐɾ³ý£¬£¬È»ºó×îÏÈÓÃ¹ã¸æºäÕ¨Óû§¡£¡£¡£¡£¡£¡£AvastÌåÏÖ£¬£¬×èÖ¹ÉÏÖÜÕâЩӦÓóÌÐòÒÑ´ï700Íò´ÎÏÂÔØÁ¿¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.avast.com/new-malware-apps-on-google-play-avast


4¡¢ºÚ¿ÍÈëÇÖÌØÀÊÆÕ¾ºÑ¡ÍøÕ¾²¢Èö²¥ÐéαÐÅÏ¢


4.jpg


Õþ¸®¹ÙÔ±ÌåÏÖ£¬£¬ºÚ¿ÍÔÚÑ¡¾ÙÈÕǰһÖܵÄÐÇÆÚ¶þÈëÇÖÁËÌÆÄɵ¡¤ÌØÀÊÆÕµÄ¾ºÑ¡ÍøÕ¾¡£¡£¡£¡£¡£¡£donaldjtrump.comÍøÕ¾±»¡°Õâ¸öÍøÕ¾±»²é·âÁË¡±ÐÂÎÅËùÈ¡´ú£¬£¬²¢ÌåÏÖ¡°ÌìÏÂÒѾ­Êܹ»ÁËÌÆÄɵ¡¤J¡¤ÌØÀÊÆÕ×ÜͳÌìÌìÉ¢²¥µÄ¼ÙÐÂÎÅ¡±¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬ºÚ¿Í»¹ºôÓõÍøÃñ¾èÔùMoneroÊý×ÖÇ®±ÒÒÔÖ§³Ö»ò×赲й¶ÓëÌØÀÊÆÕÓйصÄÖ¤¾Ý¡£¡£¡£¡£¡£¡£ÌØÀÊÆÕ¾ºÑ¡½²»°ÈËTim MurtaughÌåÏÖ£¬£¬¸ÃÍøÕ¾ºÜ¿ì»ñµÃÐÞ¸´²¢Ã»ÓÐÈκÎÃô¸ÐÊý¾Ýй¶£¬£¬´Ë´Î¹¥»÷µÄȪԴ»¹ÔÚÊÓ²ìÖС£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/trump-campaign-website-broken-hackers


5¡¢CISAºÍCNMFÐû²¼Ð¶ñÒâÈí¼þ±äÌåZebrocyµÄÆÊÎö±¨¸æ


5.jpg


ÍøÂçÇå¾²ºÍ»ù´¡ÉèÊ©Çå¾²¾Ö£¨CISA£©ºÍ¹ú·À²¿£¨DOD£©ÍøÂç¹ú¼ÒÐû½Ì²½¶Ó£¨CNMF£©·¢Ã÷еĶñÒâÈí¼þ±äÌåZebrocy¡£¡£¡£¡£¡£¡£¸Ã±äÌåÊÇÒ»¸ö32λµÄWindows¿ÉÖ´ÐÐÎļþ£¬£¬Ê¹ÓÃGolang±à³ÌÓïÑÔ±àд£¬£¬½ÓÄɵIJÎÊýӦΪÒì»ò£¨XOR£©ºÍÊ®Áù½øÖƱàÂëµÄͳһ×ÊÔ´±êʶ·û£¨URI£©£¬£¬»òÕß¿ÉÒÔʹÓô¿Îı¾URIÔËÐС£¡£¡£¡£¡£¡£Ö´ÐÐʱ£¬£¬Ëü½«Ê¹Óø߼¶¼ÓÃܱê×¼£¨AES£©-128µç×ÓÃÜÂë²¾£¨ECB£©Ëã·¨¶ÔURI¾ÙÐмÓÃÜ£¬£¬²¢Ê¹ÓôÓÊܺ¦ÕßµÄÖ÷»úÃûÌìÉúµÄÃÜÔ¿£¬£¬±ðµÄ»¹»áÍøÂçÓйØÊÜÄ¿µÄϵͳµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/10/29/cisa-and-cnmf-identify-new-malware-variant-zebrocy