ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ44ÖÜ

Ðû²¼Ê±¼ä 2020-11-02

> ±¾ÖÜÇ徲̬ÊÆ×ÛÊö


2020Äê10ÔÂ26ÈÕÖÁ11ÔÂ01ÈÕ¹²ÊÕ¼Çå¾²Îó²î59¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇRuckus Networks Ruckus vRioT /service/v1/createUser endpoint´úÂëÖ´ÐÐÎó²î£»Winston PrivacyÏÂÁî×¢ÈëÎó²î£»NVIDIA DGX Server BMC firmwareÓ²±àÂëÎó²î£»Synology Router Managerí§ÒâÏÂÁîÖ´ÐÐÎó²î£»Google chrome Freetype¶ÑÒç³ö´úÂëÖ´ÐÐÎó²î¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇд¹ÂÚÔ˶¯Ã°³äMicrosoft TeamsÕë¶ÔOffice 365Óû§£»ImpervaÐû²¼ÓйØKashmirBlack½©Ê¬ÍøÂçµÄÆÊÎö±¨¸æ£»AvastÐû²¼ÓйØGoogle PlayÉ϶ñÒâÈí¼þµÄÆÊÎö±¨¸æ£»ºÚ¿ÍÈëÇÖÌØÀÊÆÕ¾ºÑ¡ÍøÕ¾²¢Èö²¥ÐéαÐÅÏ¢£»CISAºÍCNMFÐû²¼Ð¶ñÒâÈí¼þ±äÌåZebrocyµÄÆÊÎö±¨¸æ¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖС£


Ö÷ÒªÇå¾²Îó²îÁбí


1.Ruckus Networks Ruckus vRioT /service/v1/createUser endpoint´úÂëÖ´ÐÐÎó²î


Ruckus Networks Ruckus vRioT /service/v1/createUser endpoint±£´æÊäÈëÑéÖ¤Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿Éͨ¹ýweb.pyÒÔrootȨÏÞÖ´ÐÐí§ÒâÏÂÁî¡£

https://support.ruckuswireless.com/security_bulletins/305


2.Winston PrivacyÏÂÁî×¢ÈëÎó²î


Winston Privacy×°±¸ÖÎÀíAPI±£´æÏÂÁî×¢ÈëÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ɾÙÐÐí§Òâ´úÂëÖ´Ðй¥»÷£¬Èçͨ¹ý/api/advanced_settings¸ü¸Ä×°±¸¡£

https://labs.bishopfox.com/advisories/winston-privacy-version-1.5.4#CI


3.NVIDIA DGX Server BMC firmwareÓ²±àÂëÎó²î


NVIDIA DGX Server BMC firmware±£´æÓ²±àÂëÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉδÊÚȨ»á¼û·þÎñ×°±¸¡£

https://nvidia.custhelp.com/app/answers/detail/a_id/5010


4.Synology Router Managerí§ÒâÏÂÁîÖ´ÐÐÎó²î


Synology Router Manager 7786/7787¶Ë¿Ú±£´æ²»×¼È·»á¼û¿ØÖÆÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐí§ÒâÏÂÁî¡£

https://www.synology.com/zh-cn/security/advisory/Synology_SA_20_14


5.Google chrome Freetype¶ÑÒç³ö´úÂëÖ´ÐÐÎó²î


Google chrome Freetype±£´æ¶ÑÒç³öÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇó£¬ÓÕʹÓû§ÆÊÎö£¬¿É¾ÙÐоܾø·þÎñ¹¥»÷»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£

https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.html


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢Ð´¹ÂÚÔ˶¯Ã°³äMicrosoft TeamsÕë¶ÔOffice 365Óû§


1.jpg


Abnormal Security·¢Ã÷д¹ÂÚÔ˶¯Ã°³äMicrosoft TeamsÕë¶ÔOffice 365Óû§¡£ÕâЩ´¹ÂÚÓʼþÊÇÒÔTeamsÖÐÓÐÐÂÔ˶¯ÎªÖ÷Ìâ·¢Ë͵Ä£¬¿´ÆðÀ´ÏñÊÇMicrosoft TeamsµÄ×Ô¶¯Í¨Öª£¬ÓÃÀ´¼û¸æÊܺ¦ÕßÓдí¹ýµÄ̸Ìì¡£ÓʼþÓÕʹÊܺ¦Õßµã»÷Team»Ø¸´Á´½Ó£¬ÒÔÖض¨Ïòµ½´¹ÂÚÍøÕ¾£¬À´ÇÔÈ¡Office 365Óû§µÄƾ֤¡£Ñо¿Ö°Ô±ÊӲ쵽£¬¹¥»÷ÕßÒѾ­Ê¹ÓøÃÔ˶¯¹¥»÷ÁË15000ÖÁ50000¸öOffice 365Óû§¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/109938/cyber-crime/microsoft-teams-phishing-attacks.html


2¡¢ImpervaÐû²¼ÓйØKashmirBlack½©Ê¬ÍøÂçµÄÆÊÎö±¨¸æ


2.jpg


ImpervaÐû²¼ÁËÓйØKashmirBlack½©Ê¬ÍøÂçµÄÆÊÎö±¨¸æ¡£¸Ã±¨¸æÐÎòÁËKashmirBlack½©Ê¬ÍøÂç±³ºóµÄ·¸·¨²Ù×÷£¬ÌÖÂÛÁËÆäÄ¿µÄÒÔ¼°Ñо¿ÒªÁì¡£KashmirBlackÖ÷ÒªÕë¶ÔÊ¢ÐеÄCMSƽ̨¡£ËüʹÓÃÁËÄ¿µÄ·þÎñÆ÷ÉϵÄÊýÊ®¸öÒÑÖªÎó²î£¬Æ½¾ùÌìÌì¶ÔÈ«Çò30¶à¸ö²î±ð¹ú¼ÒµÄÊýǧÃûÊܺ¦Õß¾ÙÐÐÊý°ÙÍò´Î¹¥»÷¡£±ðµÄ£¬ÆäÔËÐкÜÊÇÖØ´ó£¬ÓÉһ̨C&C·þÎñÆ÷ÖÎÀí£¬²¢Ê¹ÓÃÁË60¶ą̀·þÎñÆ÷×÷ΪÆä»ù´¡ÉèÊ©µÄÒ»²¿·Ö¡ £¿É´¦Öóͷ£Êý°Ù¸ö½©Ê¬³ÌÐò£¬Ö´Ðб©Á¦¹¥»÷¡¢×°ÖúóÃÅ¡¢²¢À©´ó½©Ê¬ÍøÂçµÄ¹æÄ£¡£    


Ô­ÎÄÁ´½Ó£º

https://www.imperva.com/blog/crimeops-of-the-kashmirblack-botnet-part-i/


3¡¢AvastÐû²¼ÓйØGoogle PlayÉ϶ñÒâÈí¼þµÄÆÊÎö±¨¸æ


3.jpg


ɱ¶¾Èí¼þÖÆÔìÉÌAvastÐû²¼ÓйØGoogle PlayÉ϶ñÒâÈí¼þµÄÆÊÎö±¨¸æ¡£¸Ã±¨¸æ³ÆGoogle PlayÊÐËÁÖÐÓÐ21¸öѬȾÁËHiddenAds¶ñÒâÈí¼þµÄAndroidÓ¦ÓóÌÐò£¬GoogleÒÑÓÚÖÜĩɾ³ýÁËÆäÖеÄ15¸ö¡£Avast¶ñÒâÈí¼þÆÊÎöʦÌåÏÖ£¬ÕâЩӦÓÃÄ£ÄâÁËÊ¢ÐеÄÓÎÏ·£¬Ò»µ©Óû§×°ÖÃÁËÕâЩӦÓã¬HiddenAds¾Í»áÒþ²Ø¸ÃÓ¦ÓóÌÐòµÄͼ±êʹÓû§ÄÑÒÔ¾ÙÐÐɾ³ý£¬È»ºó×îÏÈÓùã¸æºäÕ¨Óû§¡£AvastÌåÏÖ£¬×èÖ¹ÉÏÖÜÕâЩӦÓóÌÐòÒÑ´ï700Íò´ÎÏÂÔØÁ¿¡£


Ô­ÎÄÁ´½Ó£º

https://blog.avast.com/new-malware-apps-on-google-play-avast


4¡¢ºÚ¿ÍÈëÇÖÌØÀÊÆÕ¾ºÑ¡ÍøÕ¾²¢Èö²¥ÐéαÐÅÏ¢


4.jpg


Õþ¸®¹ÙÔ±ÌåÏÖ£¬ºÚ¿ÍÔÚÑ¡¾ÙÈÕÇ°Ò»ÖܵÄÐÇÆÚ¶þÈëÇÖÁËÌÆÄɵ¡¤ÌØÀÊÆյľºÑ¡ÍøÕ¾¡£donaldjtrump.comÍøÕ¾±»¡°Õâ¸öÍøÕ¾±»²é·âÁË¡±ÐÂÎÅËùÈ¡´ú£¬²¢ÌåÏÖ¡°ÌìÏÂÒѾ­Êܹ»ÁËÌÆÄɵ¡¤J¡¤ÌØÀÊÆÕ×ÜͳÌìÌìÉ¢²¥µÄ¼ÙÐÂÎÅ¡±¡£±ðµÄ£¬ºÚ¿Í»¹ºôÓõÍøÃñ¾èÔùMoneroÊý×ÖÇ®±ÒÒÔÖ§³Ö»ò×赲й¶ÓëÌØÀÊÆÕÓйصÄÖ¤¾Ý¡£ÌØÀÊÆÕ¾ºÑ¡½²»°ÈËTim MurtaughÌåÏÖ£¬¸ÃÍøÕ¾ºÜ¿ì»ñµÃÐÞ¸´²¢Ã»ÓÐÈκÎÃô¸ÐÊý¾Ýй¶£¬´Ë´Î¹¥»÷µÄȪԴ»¹ÔÚÊÓ²ìÖС£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/trump-campaign-website-broken-hackers


5¡¢CISAºÍCNMFÐû²¼Ð¶ñÒâÈí¼þ±äÌåZebrocyµÄÆÊÎö±¨¸æ


5.jpg


ÍøÂçÇå¾²ºÍ»ù´¡ÉèÊ©Çå¾²¾Ö£¨CISA£©ºÍ¹ú·À²¿£¨DOD£©ÍøÂç¹ú¼ÒÐû½Ì²½¶Ó£¨CNMF£©·¢Ã÷еĶñÒâÈí¼þ±äÌåZebrocy¡£¸Ã±äÌåÊÇÒ»¸ö32λµÄWindows¿ÉÖ´ÐÐÎļþ£¬Ê¹ÓÃGolang±à³ÌÓïÑÔ±àд£¬½ÓÄɵIJÎÊýӦΪÒì»ò£¨XOR£©ºÍÊ®Áù½øÖƱàÂëµÄͳһ×ÊÔ´±êʶ·û£¨URI£©£¬»òÕß¿ÉÒÔʹÓô¿Îı¾URIÔËÐС£Ö´ÐÐʱ£¬Ëü½«Ê¹Óø߼¶¼ÓÃܱê×¼£¨AES£©-128µç×ÓÃÜÂë²¾£¨ECB£©Ëã·¨¶ÔURI¾ÙÐмÓÃÜ£¬²¢Ê¹ÓôÓÊܺ¦ÕßµÄÖ÷»úÃûÌìÉúµÄÃÜÔ¿£¬±ðµÄ»¹»áÍøÂçÓйØÊÜÄ¿µÄϵͳµÄÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/10/29/cisa-and-cnmf-identify-new-malware-variant-zebrocy