CrowdStrikeÐû²¼¡¶2020ÄêÈ«ÇòÍþв±¨¸æ¡·£»£» £»£»£»Ó¢¹úÊý¾Ýî¿Ïµ»ú¹¹¶Ô¹úÌ©º½¿Õ´¦ÒÔ50ÍòÓ¢°÷·£¿£¿£¿£¿£¿£¿£¿î

Ðû²¼Ê±¼ä 2020-03-05

1.CrowdStrikeÐû²¼¡¶2020ÄêÈ«ÇòÍþв±¨¸æ¡·

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

CrowdStrikeµÄ¡¶2020ÄêÈ«ÇòÍþв±¨¸æ¡·¶ÔÒÑÍùÒ»ÄêÖж¥¼¶ÍøÂçÍþвÇ÷ÊÆ¾ÙÐÐÁËÉîÈëÆÊÎö£¬£¬ £¬¸Ã±¨¸æµÄÒªµã°üÀ¨£º´óÐ͹¥»÷»î¶¯£¨BGH£©Ò»Ö±Éý¼¶£¬£¬ £¬Êê½ðÒªÇóì­ÉýÖÁÊý°ÙÍò£¬£¬ £¬²¢ÇÒÔì³É¼«´óµÄÆÆË𣻣» £»£»£»ÍøÂç·¸·¨·Ö×ÓÕýÔÚʹÃô¸ÐÊý¾ÝÎäÆ÷»¯£¬£¬ £¬ÒÔÔöÌí¶ÔÀÕË÷Èí¼þÊܺ¦ÕßµÄѹÁ¦£»£» £»£»£»eCrimeÉú̬ϵͳһֱÉú³¤£¬£¬ £¬±äµÃ³ÉÊìºÍרҵ»¯Ë®Æ½Ò»Ö±Ìá¸ß£»£» £»£»£»ÔÚBGHÖ®Í⣬£¬ £¬Õë¶ÔÈ«Çò½ðÈÚ»ú¹¹µÄeCrime»î¶¯ÓÐËùÔöÌí£»£» £»£»£»³¯ÏòÎÞ¶ñÒâÈí¼þÕ½ÂÔµÄÇ÷ÊÆÕýÔÚ¼ÓËÙ£»£» £»£»£»¹ú¼Ò×ÊÖúµÄÓÐÕë¶ÔÐÔµÄÈëÇֻ¼ÌÐøÕë¶Ô֪ʶ²úȨ/¾ºÕùÇ鱨£¬£¬ £¬Ôö½øÉçÇøÄÚ²¿µÄÆÆË飬£¬ £¬²¢ÊӲ쵽ÁËÓëÏȽøeCrime¹¥»÷ÕßµÄÏàÖú¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.crowdstrike.com/resources/reports/2020-crowdstrike-global-threat-report/


2.Ó¢¹úNCSCÐû²¼ÓйØÖÇÄÜ¼à¿ØÉãÏñÍ·µÄÇå¾²Ö¸ÄÏ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ó¢¹ú¹ú¼ÒÍøÂçÇå¾²ÖÐÐÄ£¨NCSC£©Ðû²¼ÓйØÔõÑù׼ȷÉèÖÃÖÇÄÜÇå¾²ÉãÏñÍ·ºÍÓ¤¶ù¼àÊÓÆ÷µÄÖ¸ÄÏ£¬£¬ £¬ÒÔ×èÖ¹Óû§Êܵ½¹¥»÷ÕߵĹ¥»÷¡£¡£¡£NCSCÌåÏÖ¡°ÖÇÄÜÉãÏñ»ú£¨ÓÃÓÚ¼àÊÓºâÓîÄÚºÍÖÜΧ»î¶¯µÄÇå¾²ÉãÏñ»úºÍÓ¤¶ù¼àÊÓÆ÷£©Í¨³£Ê¹ÓüÒÍ¥Wi-FiÅþÁ¬µ½»¥ÁªÍø£¬£¬ £¬ÔÚÉÙÉÙÊýÇéÐÎÏ£¬£¬ £¬Î´¾­ÊÚȨµÄ¹¥»÷Õß¿ÉÒÔ»á¼ûÖÇÄÜÉãÏñ»úµÄʵʱÁ÷»òͼÏñ£¬£¬ £¬Õâ»áʹÄúµÄÒþ˽Êܵ½Íþв¡£¡£¡£¡±ÎªÁ˵ÖÓù´ËÀ๥»÷£¬£¬ £¬NCSC½¨ÒéʹÓÃÇ¿Á¦µÄ¡¢»ùÓÚÃÜÂë¶ÌÓïµÄÃÜÂë¸ü¸Ä×°±¸µÄĬÈÏÃÜÂ룬£¬ £¬¸ÃÃÜÂë¿ÉÒÔʹÓÃÓû§Äܹ»¼Ç×ŵÄÈý¸öËæ»úµ¥´Ê¹¹½¨£¬£¬ £¬²¢ÇÒ¼á³ÖÇå¾²ÉãÏñÍ·µÄ¹Ì¼þΪ×îкͽûÓò»ÐëÒªµÄÔ¶³ÌÉó²é¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/uk-ncsc-releases-tips-on-securing-smart-security-cameras/


3.·¸·¨ÍÅ»ïMoleratsй¥»÷»î¶¯£¬£¬ £¬Õë¶ÔÕþ¸®ºÍµçÐÅÐÐÒµ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Palo Alto NetworksµÄUnit42ÍŶÓÔÚ2019Äê10Ôµ½2019Äê12ÔÂÊӲ쵽¶à¸öÓë·¸·¨ÍÅ»ïMoleratsÓйصĴ¹ÂÚ¹¥»÷»î¶¯¡£¡£¡£¹¥»÷ÕßµÄÄ¿µÄº­¸ÇÕþ¸®¡¢µçÐÅ¡¢°ü¹ÜºÍÁãÊÛÐÐÒµ£¬£¬ £¬Éæ¼°6¸ö¹ú¼ÒµÄ8¸ö×éÖ¯¡£¡£¡£ËùÓÐÕâЩ¹¥»÷¶¼Éæ¼°µ½Ê¹Óô¹ÂÚÓʼþת´ï¶ñÒâÎĵµ£¬£¬ £¬²¢Ê¹ÓÃÉç½»¹¤³ÌÊÖÒÕÒªÇóÊÕ¼þÈËÖ´ÐÐijЩ²Ù×÷£¬£¬ £¬ÀýÈçÆôÓúê»òµã»÷Á´½ÓµÈ¡£¡£¡£´ó´ó¶¼´ËÀ๥»÷ÖеÄÓÐÓøºÔØÊÇSparkºóÃÅ£¬£¬ £¬¸ÃºóÃÅÔÊÐí¹¥»÷ÕßÔÚÊÜѬȾµÄϵͳÉÏ·­¿ªÓ¦ÓóÌÐò²¢ÔËÐÐÏÂÁî¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/molerats-delivers-spark-backdoor/


4.Ó¢¹úÊý¾Ýî¿Ïµ»ú¹¹¶Ô¹úÌ©º½¿Õ´¦ÒÔ50ÍòÓ¢°÷·£¿£¿£¿£¿£¿£¿£¿î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ó¢¹úÐÅϢרԱ°ì¹«ÊÒÒò2018Äê940ÍòÂÿÍÊý¾Ýй¶ÊÂÎñ¶Ô¹úÌ©º½¿Õ¹«Ë¾´¦ÒÔ50ÍòÓ¢°÷µÄ·£¿£¿£¿£¿£¿£¿£¿î¡£¡£¡£¸Ã¹¥»÷ÒÉËÆ±¬·¢ÔÚ2018Äê3Ô·Ý£¬£¬ £¬²¢ÓÚ5Ô·ݻñµÃÈ·ÈÏ£¬£¬ £¬Æäʱ¹úÌ©º½¿ÕµÄÊý¾Ý¿âÔâµ½Á˱©Á¦ÆÆ½â¹¥»÷¡£¡£¡£ICOÊÓ²ì³Æ¹úÌ©µÄϵͳÊܵ½ÁËÊý¾ÝÍøÂçÀà¶ñÒâÈí¼þµÄÓ°Ï죬£¬ £¬²¢·¢Ã÷¹úÌ©ÔÚÇå¾²ÐÔ·½ÃæµÄһЩȱ·¦£¬£¬ £¬°üÀ¨²»ÊÜÃÜÂë±£»£» £»£»£»¤µÄ±¸·ÝÎļþ¡¢Î´´ò²¹¶¡µÄWebЧÀÍÆ÷¡¢ÒѹýʱµÄ²Ù×÷ϵͳºÍȱ·¦·À²¡¶¾±£»£» £»£»£»¤µÈ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.theregister.co.uk/2020/03/04/ico_fines_cathay_pacific_500000/


5.¹È¸èÐû²¼3ÔÂAndroidÇå¾²¸üУ¬£¬ £¬ÐÞ¸´70¶à¸öÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¹È¸èÐû²¼2020Äê3ÔÂAndroidÇå¾²¸üУ¬£¬ £¬¹²ÐÞ¸´70¶à¸öÎó²î£¬£¬ £¬ÆäÖÐ×îÑÏÖØµÄÎó²îÊÇýÌå¿ò¼Ü×é¼þÖеĴúÂëÖ´ÐÐÎó²î£¨CVE-2020-0032£©£¬£¬ £¬¸ÃÎó²î¿ÉÄÜʹԶ³Ì¹¥»÷ÕßʹÓöñÒâÎļþÔÚÌØÈ¨Àú³ÌµÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂ룬£¬ £¬¸ÃÎó²îÓ°ÏìÁËÔËÐÐAndroid 8.0¡¢8.1¡¢9ºÍ10°æ±¾µÄ×°±¸¡£¡£¡£±ðµÄ£¬£¬ £¬¹È¸è»¹ÐÞ¸´ÁËýÌå¿ò¼ÜÖеÄÁíÍâÁ½¸öÑÏÖØÎó²î£¬£¬ £¬°üÀ¨ÌØÈ¨ÌáÉýÎó²î£¨CVE-2020-0033£©ºÍÐÅϢй¶Îó²î£¨CVE-2020-0034£©¡£¡£¡£´Ë´Î¸üÐÂÐÞ¸´Á˸ßͨ±ÕÔ´×é¼þÖеÄ40¸öÎó²î£¬£¬ £¬ÆäÖÐ16¸ö±»ÆÀΪÑÏÖØ¼¶±ð¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/98901/mobile-2/googles-march-2020-security-updates-android.html


6.¼ÎÄ껪ÓÎÂÖ¼¯ÍÅÔâºÚ¿ÍÈëÇÖ£¬£¬ £¬¿Í»§Êý¾Ý¿ÉÄÜй¶


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


È«Çò×î´óµÄÓÎÂÖÔËÓªÉ̼ÎÄ껪ÓÎÂÖ¼¯ÍÅ£¨Carnival Corporation£¦plc£©ÔâºÚ¿ÍÈëÇÖ£¬£¬ £¬¿Í»§Êý¾Ý¿ÉÄÜй¶¡£¡£¡£Æ¾Ö¤¸Ã¹«Ë¾µÄת´ï£¬£¬ £¬ÔÚ2019Äê4ÔÂ11ÈÕÖÁ7ÔÂ23ÈÕÖ®¼äδ¾­ÊÚȨµÄ¹¥»÷Õß»á¼ûÁËijЩ°üÀ¨¿Í»§ÐÅÏ¢µÄÔ±¹¤ÓÊÏäÕË»§£¬£¬ £¬¿ÉÄÜй¶µÄÐÅÏ¢°üÀ¨¿Í»§µÄÐÕÃû¡¢µØµã¡¢Éç»áÇå¾²ºÅÂë¡¢Õþ¸®Ê¶ÓÖÃûÂ루ÀýÈ绤ÕÕID»ò¼ÝÕÕID£©¡¢ÐÅÓÿ¨ºÍÒøÐÐÕË»§ÐÅÏ¢ÒÔ¼°Ó뿵½¡×´Ì¬Ïà¹ØµÄÐÅÏ¢¡£¡£¡£¼ÎÄ껪»¹³ÆÄ¿½ñûÓÐÖ¤¾ÝÅú×¢ÊÂÎñ±¬·¢ºóÊÜÓ°Ïì¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢±»ÀÄÓᣡ£¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/carnival-cruise-line-operator-discloses-potential-data-breach/