Windows RDP 0day£¨CVE-2019-9510£©£»£» £» £»£»£»£»WestpacÒøÐÐÔâºÚ¿Í¹¥»÷£»£» £» £»£»£»£»APT34¹¤¾ßJasonÔ´Âëй¶

Ðû²¼Ê±¼ä 2019-06-05
1.WestpacÒøÐÐÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬£¬Ô¼10ÍòÃû¿Í»§ÐÅϢй¶

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ƾ֤ϤÄáÏÈÇý³¿±¨µÄ±¨µÀ£¬£¬£¬£¬£¬£¬£¬WestpacÒøÐÐÔâµ½ºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬£¬µ¼Ö½ü10Íò°Ä´óÀûÑÇÓû§µÄСÎÒ˽¼ÒÐÅϢй¶¡£¡£¡£¡£ ¡£¡£¹¥»÷ÕßÀ´×ÔÓÚÍâÑ󣬣¬£¬£¬£¬£¬£¬¶Ô¸ÃÒøÐеÄPayIDƽ̨¾ÙÐÐÁË¡°Ã¶¾Ù¹¥»÷¡±¡£¡£¡£¡£ ¡£¡£¾Ý³Æ¹¥»÷Õß¾ÙÐÐÁËԼĪ60Íò´ÎÅÌÎÊ£¬£¬£¬£¬£¬£¬£¬ÀֳɻñÈ¡ÁËÔ¼9.8Íò¿Í»§µÄÐÕÃû¡£¡£¡£¡£ ¡£¡£WestpacÌåÏÖ¿Í»§µÄ²ÆÎñÐÅϢûÓÐÊܵ½Ë𺦣¬£¬£¬£¬£¬£¬£¬¸ÃÒøÐеÄPayIDƽֻ̨´æ´¢Á˿ͻ§µÄÐÕÃûºÍÊÖ»úºÅÂë¡£¡£¡£¡£ ¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://au.finance.yahoo.com/news/100-000-australians-reportedly-risk-232227017.html

2.°Ä´óÀûÑǹúÁ¢´óѧÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬20ÍòѧÉú¼°Ô±¹¤ÐÅϢй¶

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

°Ä´óÀûÑǹúÁ¢´óѧÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬£¬´ó×ÚѧÉúºÍÔ±¹¤µÄÐÅϢй¶¡£¡£¡£¡£ ¡£¡£¸ÃδÊÚȨ»á¼ûÊÂÎñ±¬·¢ÔÚ2018Äêµ×£¬£¬£¬£¬£¬£¬£¬Ñ§Ð£ÒÑÈ·ÈÏÔ¼ÓÐ20ÍòÈËÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬Ð¹Â¶µÄÊý¾Ý×îÔç¿É×·ËÝÖÁ19Äêǰ¡£¡£¡£¡£ ¡£¡£ÔÚÊÂÎñÖÐй¶µÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØµã¡¢½ôÆÈÁªÏµÈËÐÅÏ¢¡¢ÄÉ˰ºÅÂë¡¢ÈËΪµ¥ÐÅÏ¢¡¢ÒøÐÐÕË»§ÐÅÏ¢¡¢»¤ÕÕÐÅÏ¢ºÍѧҵ¼Í¼µÈ¡£¡£¡£¡£ ¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.theguardian.com/australia-news/2019/jun/04/australian-national-university-hit-by-huge-data-breach

3.APT28ʹÓÃÐÂNimºóÃÅÃé×¼12¸ö¹ú¼ÒµÄÕþ¸®ÍøÕ¾

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

¿¨°Í˹»ùÑо¿ÍŶӷ¢Ã÷APT28µÄй¥»÷»î¶¯£¬£¬£¬£¬£¬£¬£¬¸Ã×é֯ʹÓÃкóÃÅÃé×¼¶à¸ö¹ú¼ÒµÄÕþ¸®ÍøÕ¾¡£¡£¡£¡£ ¡£¡£Õâ¸öеĺóÃÅʹÓÃбà³ÌÓïÑÔNim±àд£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃËüÀ´ÇÔȡƾ֤¼°ÔÚÊÜѬȾµÄϵͳÉϽ¨É賤ÆÚÐÔ¡£¡£¡£¡£ ¡£¡£¸ÃºóÃÅͨ¹ý´¹ÂÚ¹¥»÷¾ÙÐзַ¢£¬£¬£¬£¬£¬£¬£¬Ñо¿ÍŶӷ¢Ã÷¸Ã×éÖ¯¹²ÔÚÕë¶Ô12¸ö¹ú¼ÒµÄ¹¥»÷»î¶¯ÖÐʹÓÃÁ˸úóÃÅ£¬£¬£¬£¬£¬£¬£¬°üÀ¨µÂ¹ú¡¢Ó¢¹ú¡¢ÎÚ¿ËÀ¼¡¢°¢¸»º¹¡¢ÒÁÀÊ¡¢¹þÈø¿Ë˹̹µÈ¡£¡£¡£¡£ ¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/new-backdoor-family-identified-in-zebrocy-apt-groups-campaigns-61ee6a8a

4.ÒÁÀÊAPT34й¤¾ßJasonÔ´´úÂëÔÚTelegramÉÏй¶

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

Ò»¸öÃûΪLab DookhteganµÄÓû§ÔÚTelegramÉÏÐû²¼ÁËÒÁÀÊAPT34µÄºÚ¿Í¹¤¾ßJasonµÄÔ´´úÂ룬£¬£¬£¬£¬£¬£¬ÕâÊǸÃÓû§Åû¶µÄµÚÆß¸öAPT34ºÚ¿Í¹¤¾ßÔ´Âë¡£¡£¡£¡£ ¡£¡£Jason¿ª·¢ÓÚ2015Ä꣬£¬£¬£¬£¬£¬£¬ÕâÒâζ׏¥»÷ÕßÖÁÉÙÒÑʹÓÃÁËËüËÄÄ꣬£¬£¬£¬£¬£¬£¬µ«¸Ã¹¤¾ßÔÚ֮ǰµÄ¹¥»÷Öж¼Î´±»·¢Ã÷¡£¡£¡£¡£ ¡£¡£Æ¾Ö¤Ñо¿Ö°Ô±Omri Segev MoyalµÄ˵·¨£¬£¬£¬£¬£¬£¬£¬JasonÊÇÒ»¸öGUI¹¤¾ß£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚʹÓÃÔ¤±àÒëµÄÓû§ÃûºÍÃÜÂë±íÀ´±©Á¦ÆÆ½âMicrosoft Exchangeµç×ÓÓʼþЧÀÍÆ÷¡£¡£¡£¡£ ¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/another-iranian-hacking-tool-jason-leaked-on-telegram-2cc176cb

5.AppleÐÞ¸´Mac OSÖб£´æ½ü20ÄêµÄRCEÎó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

Çå¾²Ñо¿Ô±Joshua Hill·¢Ã÷Mac OSÖеÄÒ»¸ö±£´æÁË20ÄêµÄÎó²î£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²î×îÔç·ºÆðÓÚ1999ÄêÐû²¼µÄMac OS 9ÖУ¬£¬£¬£¬£¬£¬£¬µ«¶ÔÏÖ´úAppleϵͳͬÑùÓÐÓᣡ£¡£¡£ ¡£¡£¸ÃÎó²îʹÓÃÁËÒ»¸öÃûΪCCLEngineµÄAppleÈí¼þ×é¼þ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÔ¶³ÌÈÆ¹ýCCLEngineÖеÄÉí·ÝÑéÖ¤»úÖÆ£¬£¬£¬£¬£¬£¬£¬´Ó¶øÔÚÅÌËã»úÖ®¼ä½¨ÉèÔ¶³ÌÅþÁ¬ºÍÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬£¬£¬×îÖÕÍêÈ«»á¼ûºÍ¿ØÖÆÄ¿µÄÅÌËã»ú¡£¡£¡£¡£ ¡£¡£AppleÔÚ4Ô·ݵÄÇå¾²¸üÐÂÖÐÐÞ¸´ÁËÕâÒ»Îó²î¡£¡£¡£¡£ ¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/apple-fixes-20-year-old-modem-configuration-bug-cd6bf1b9

6.Windows RDPÐÂ0day£¬£¬£¬£¬£¬£¬£¬¿ÉÐ®ÖÆÔ¶³Ì×ÀÃæ»á»°

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

¿¨ÄÚ»ù÷¡CERT/CCÅû¶Windows RDPЧÀÍÖеÄÒ»¸öδÐÞ¸´µÄ0day£¨CVE-2019-9510£©£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²î¿ÉÔÊÐí¹¥»÷ÕßÈÆ¹ýÔ¶³Ì×ÀÃæ»á»°ÖÐµÄÆÁÄ»Ëø¶¨²¢Ð®ÖƻỰ¡£¡£¡£¡£ ¡£¡£¸ÃÎó²îÓëRDPµÄÍøÂçÉí·ÝÑéÖ¤NLAÓйأ¬£¬£¬£¬£¬£¬£¬CERTÐÎòµÄ¹¥»÷³¡¾°Îª£ºÓû§Ê¹ÓÃRDPÅþÁ¬µ½Windows 10 1803»òServer 2019»ò¸üеÄϵͳ£¬£¬£¬£¬£¬£¬£¬È»ºóËø¶¨Ô¶³Ì×ÀÃæ»á»°²¢ÍÑÀë¿Í»§¶Ë£¬£¬£¬£¬£¬£¬£¬´Ëʱ¹¥»÷Õß¿ÉÖÐÖ¹RDPÍøÂçÅþÁ¬£¬£¬£¬£¬£¬£¬£¬Õ⽫µ¼ÖÂËü×Ô¶¯ÖØÁ¬²¢ÈƹýWindowsÆÁÄ»Ëø¶¨£¬£¬£¬£¬£¬£¬£¬´Ó¶ø¾ÙÐв»·¨»á¼û¡£¡£¡£¡£ ¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/remote-desktop-zero-day-bug-allows-attackers-to-hijack-sessions/