MITREÐû²¼ÊÊÓÃÓÚ¹¤Òµ¿ØÖÆÏµÍ³µÄATT£¦CK¿ò¼Ü;Firefox 0dayÎó²î(CVE-2019-11707)
Ðû²¼Ê±¼ä 2020-01-09
1.MITREÐû²¼ÊÊÓÃÓÚ¹¤Òµ¿ØÖÆÏµÍ³µÄATT£¦CK¿ò¼Ü
±¾ÖܶþMITERÐû²¼ÁËÆäATT£¦CK¿ò¼ÜµÄ³õʼ°æ±¾£¬£¬£¬£¬£¬¸Ã°æ±¾ÖØµã¹Ø×¢ÁËÕë¶Ô¹¤Òµ¿ØÖÆÏµÍ³£¨ICS£©µÄ¶ñÒâ¹¥»÷ÕßʹÓõÄÕ½ÂÔºÍÊÖÒÕ¡£¡£¡£¡£¡£¡£¡£Ö¼ÔÚ×ÊÖúÒªº¦»ù´¡ÉèÊ©ºÍÆäËûʹÓÃICSµÄ×éÖ¯ÆÀ¹ÀÆäÍøÂçΣº¦¡£¡£¡£¡£¡£¡£¡£³ýÁËÌṩ¹¥»÷Õ½ÂÔºÍÊÖÒÕ¾ØÕóÍ⣬£¬£¬£¬£¬»¹ÏÈÈÝÁ˹¥»÷ÊÖÒÕµÄϸ½Ú¡¢¹¥»÷ÕßʹÓõĶñÒâÈí¼þÒÔ¼°ÒÑÖªµÄÕë¶ÔICSµÄ·¸·¨ÍŻ¡£¡£¡£¡£¡£¡£Ëü»¹°üÀ¨Ò»¸ö×ʲúÖֱ𣬣¬£¬£¬£¬ÓÃÓÚ×ÊÖú×éÖ¯Ïàʶ¿ÉÓ¦ÓÃÓÚÆäÇéÐεÄÊÖÒÕ¡£¡£¡£¡£¡£¡£¡£´Ë°æ±¾ÐÎòÁË81ÖÖ¹¥»÷ÊÖÒÕ¡¢17ÖÖ¶ñÒâÈí¼þ¡¢10¸ö·¸·¨ÍÅ»ïºÍ7ÖÖ×ʲú¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/mitre-releases-attck-knowledge-base-industrial-control-systems
2.Ã÷ÄáËÕ´ïÖÝAlomere HealthҽԺй¶½ü5Íò»¼ÕßÐÅÏ¢
Ã÷ÄáËÕ´ïÖÝAlomere HealthÒ½ÔºµÄÁ½ÃûÔ±¹¤µç×ÓÓÊÏäÕË»§ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬µ¼ÖÂ49351Ãû»¼ÕßµÄСÎÒ˽¼ÒºÍÒ½ÁÆÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£¸ÃÒ½ÔºµÄÊÓ²ìÏÔʾ£¬£¬£¬£¬£¬ÆäÖÐÒ»ÃûÔ±¹¤µÄÓÊÏäÕË»§ÔÚ2019Äê10ÔÂ31ÈÕÖÁ11ÔÂ1ÈÕʱ´úÔâµ½ÖÁÉÙÒ»¸öµÚÈý·½µÄδÊÚȨ»á¼û£¬£¬£¬£¬£¬ÁíÒ»ÃûÔ±¹¤µÄÓÊÏäÕË»§ÔÚ11ÔÂ6ÈÕ±»µÁ¡£¡£¡£¡£¡£¡£¡£ÊÓ²ìÎÞ·¨È·¶¨¹¥»÷ÕßÊÇ·ñÏÖʵÉó²éÁËÓÊÏäÖеÄÓʼþ»ò¸½¼þ£¬£¬£¬£¬£¬µ«¹¥»÷Õß¿ÉÄÜ»ñµÃµÄÐÅÏ¢°üÀ¨»¼ÕßµÄÐÕÃû¡¢µØµã¡¢³öÉúÈÕÆÚÒÔ¼°¼Í¼ID¡¢Ò½Áưü¹ÜÐÅÏ¢¡¢ÖÎÁÆÐÅÏ¢¡¢Õï¶ÏÐÅÏ¢µÈÒ½ÁÆÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬²¿·Ö»¼ÕßµÄÉç»áÇå¾²ºÅÂëºÍ¼ÝÕÕID¿ÉÄÜй¶¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/medical-info-of-roughly-50k-exposed-in-minnesota-hospital-breach/
3.APT×éÖ¯Lazarus¹¥»÷»î¶¯AppleJeusºóÐøÆÊÎö±¨¸æ
¿¨°Í˹»ùÐû²¼¹ØÓÚ³¯ÏÊLazarus APTµÄAppleJeusºóÐø¹¥»÷»î¶¯µÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£ÎªÁ˹¥»÷macOSÓû§£¬£¬£¬£¬£¬LazarusʹÓùûÕæµÄÔ´´úÂ루ÀýÈçCentrabit¿ª·¢µÄQtBitcoinTrader£©¿ª·¢ÁË×Ô¼ºµÄmacOS¶ñÒâÈí¼þ£¬£¬£¬£¬£¬²¢Ìí¼ÓÁËÒ»ÖÖÉí·ÝÑéÖ¤»úÖÆ½»¸¶ÏÂÒ»½×¶Îpayload£¬£¬£¬£¬£¬ÉõÖÁ¿É¾ÙÐÐÎÞÎļþ¼ÓÔØ¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬ÎªÁ˹¥»÷WindowsÓû§£¬£¬£¬£¬£¬Lazarus¿ª·¢Á˶à½×¶ÎѬȾ³ÌÐò£¬£¬£¬£¬£¬²¢ÏÔÖøË¢ÐÂÁË×îÖÕÓÐÓøºÔØ¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔڸúóÐø¹¥»÷»î¶¯ÖÐÈ·ÈÏÁ˶àÃûÊܺ¦Õߣ¬£¬£¬£¬£¬°üÀ¨Ó¢¹ú¡¢²¨À¼¡¢¶íÂÞ˹ºÍÖйúµÄ×éÖ¯¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬Ñо¿Ö°Ô±Äܹ»È·ÈÏһЩÊܺ¦ÕßÓë¼ÓÃÜÇ®±ÒÓªÒµÓйء£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/operation-applejeus-sequel/95596/
4.BitdefenderÅû¶»ùÓÚGoÓïÑԵĽ©Ê¬ÍøÂçLiquorBot
BitdefenderÑо¿Ö°Ô±ÓÚ2019Äê5ÔÂ31ÈÕÊ×´ÎÊӲ쵽ÍÚ¿ó½©Ê¬ÍøÂçLiquorBot£¬£¬£¬£¬£¬¸Ã½©Ê¬ÍøÂçÊÇÓÉGolang£¨Go£©±àдµÄ£¬£¬£¬£¬£¬ÖÁ10ÔÂ10ÈÕËüÒÑÂÄÀúÁË11¸ö¸üа汾¡£¡£¡£¡£¡£¡£¡£LiquorBotµÄ½¹µãÊÇÎÛÃûÕÑÖøµÄMiraiµÄÖØÐÂʵÏÖ£¬£¬£¬£¬£¬µ«Ëü¾ßÓмÓÃÜÇ®±ÒÍÚ¾ò¹¦Ð§¶ø²»ÊÇDDoS×é¼þ¡£¡£¡£¡£¡£¡£¡£LiquorBotÕë¶ÔARM¡¢ARM64¡¢x86¡¢x64ºÍMIPS¼Ü¹¹¾ÙÐн»Ö¯±àÒ룬£¬£¬£¬£¬²¢ÇÒͨ¹ýÓëCPU¼Ü¹¹Î޹صÄdropper¾ç±¾ÏÂÔØËùÓÐÓÐÓøºÔØ¡£¡£¡£¡£¡£¡£¡£LiquorBot¾ßÓжà¸öÏÂÁîºÍ¿ØÖÆ£¨C2£©Ð§ÀÍÆ÷£¬£¬£¬£¬£¬°üÀ¨wpceservice.hldns.ru¡¢ardp.hldns.ruºÍbpsuck.hldns.ru¡£¡£¡£¡£¡£¡£¡£LiquorBotÖ÷ÒªÒÀÀµÓÚSSH±©Á¦¹¥»÷¾ÙÐÐÈëÇÖ£¬£¬£¬£¬£¬²¢ÇÒ¿ÉʹÓÃd-Link¡¢Íø¼þ¡¢LinksysµÈ·ÓÉÆ÷ÖеÄδÐÞ²¹Îó²î¹¥»÷×°±¸¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/go-based-liquorbot-adapts-cryptomining-payload-to-infected-host/
5.΢ÈíÐÞ¸´AccessÖеÄÐÅϢй¶Îó²î£¨CVE-2019-1463£©
µç×ÓÓʼþÇå¾²¹«Ë¾Mimecast͸¶£¬£¬£¬£¬£¬Microsoft AccessÖеÄÐÅϢй¶Îó²î¿ÉÄܵ¼ÖÂϵͳÄÚ´æÖеÄÃô¸ÐÊý¾Ý±»ÎÞÒâÖÐÉúÑÄÔÚÊý¾Ý¿âÎļþÖС£¡£¡£¡£¡£¡£¡£¸ÃÎó²î£¨CVE-2019-1463£©±»³ÆÎªMDB Leaker£¬£¬£¬£¬£¬Óë¡°Ó¦ÓóÌÐò¶ÔϵͳÄÚ´æµÄ²»µ±ÖÎÀí¡±Óйأ¬£¬£¬£¬£¬Ëü¿ÉÄܵ¼ÖÂδ³õʼ»¯µÄÄÚ´æÔªËصÄÄÚÈÝÉúÑĵ½Microsoft Access MDBÎļþÖС£¡£¡£¡£¡£¡£¡£Ö»¹ÜÕâЩÊý¾Ý¿ÉÄܺÁÎÞÓô¦£¬£¬£¬£¬£¬µ«ËüÒ²¿ÉÄܰüÀ¨¸ß¶ÈÃô¸ÐµÄÐÅÏ¢£¬£¬£¬£¬£¬ÀýÈçÃÜÂë¡¢WebÇëÇó¡¢Ö¤ÊéÒÔ¼°Óò»òÓû§Êý¾Ý¡£¡£¡£¡£¡£¡£¡£MimecastÌåÏÖÏÖÔÚ²»»áÐû²¼ÓйØCVE-2019-1463µÄÈκÎÊÖÒÕÐÅÏ¢£¬£¬£¬£¬£¬Ò²Ã»ÓÐÖ¤¾ÝÅú×¢¸ÃÎó²îÒÑÔÚÒ°ÍⱻʹÓᣡ£¡£¡£¡£¡£¡£Î¢ÈíÒÑÔÚ2019Äê12ÔµIJ¹¶¡¸üÐÂÖÐÐÞ¸´Á˸ÃÎó²î£¬£¬£¬£¬£¬Æ¾Ö¤Î¢ÈíµÄ˵·¨£¬£¬£¬£¬£¬¸ÃÎó²î»áÓ°ÏìOffice 2010¡¢2013¡¢2016¡¢2019ºÍ365 ProPlus¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/microsoft-access-files-could-include-unintentionally-saved-sensitive-data
6.MozillaÐû²¼¸üÐÂ,ÐÞ¸´Firefox 0dayÎó²î(CVE-2019-11707)
MozillaÐû²¼ÁËFirefox 72.0.1ºÍFirefox ESR 68.4.1£¬£¬£¬£¬£¬ÐÞ¸´ÒÑÔÚÒ°Íâ±»Æð¾¢Ê¹ÓõÄ0day£¨CVE-2019-11707£©¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î±»¹éÀàΪÀàÐÍ»ìÏýÎó²î£¬£¬£¬£¬£¬Ó°ÏìÁËIonMonkey JIT±àÒëÆ÷£¬£¬£¬£¬£¬Æ¾Ö¤MozillaµÄÇ徲ͨ¸æ£¬£¬£¬£¬£¬IonMonkey JIT±àÒëÆ÷ÖÐÓÃÓÚÉèÖÃÊý×éÔªËØµÄÓÖÃûÐÅÏ¢²»×¼È·£¬£¬£¬£¬£¬¿ÉÄܻᵼÖÂÀàÐÍ»ìÏý¡£¡£¡£¡£¡£¡£¡£Ç±ÔÚ¹¥»÷Õß¿Éͨ¹ý½«Óû§Öض¨ÏòÖÁ¶ñÒâÍøÒ³À´´¥·¢¸ÃÎó²î£¬£¬£¬£¬£¬µ¼Ö´úÂëÖ´Ðлò´¥·¢Í߽⡣¡£¡£¡£¡£¡£¡£ÃÀ¹úCISAÒ²·¢³öÖÒÑԳƹ¥»÷Õß¿ÉÄÜʹÓôËÎó²îÀ´¿ØÖÆÊÜÓ°ÏìµÄϵͳ£¬£¬£¬£¬£¬²¢½¨ÒéÓû§Éó²éMozillaÇ徲ת´ïºÍÓ¦ÓÃÇå¾²¸üС£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/mozilla-firefox-7201-patches-actively-exploited-zero-day/