CrowdStrikeÐû²¼¡¶2020ÄêÈ«ÇòÍþв±¨¸æ¡·£»£»£»£»£»Ó¢¹úÊý¾Ýî¿Ïµ»ú¹¹¶Ô¹úÌ©º½¿Õ´¦ÒÔ50ÍòÓ¢°÷·£¿£¿£¿£¿£¿£¿£¿î
Ðû²¼Ê±¼ä 2020-03-051.CrowdStrikeÐû²¼¡¶2020ÄêÈ«ÇòÍþв±¨¸æ¡·
CrowdStrikeµÄ¡¶2020ÄêÈ«ÇòÍþв±¨¸æ¡·¶ÔÒÑÍùÒ»ÄêÖж¥¼¶ÍøÂçÍþвÇ÷ÊÆ¾ÙÐÐÁËÉîÈëÆÊÎö£¬£¬£¬¸Ã±¨¸æµÄÒªµã°üÀ¨£º´óÐ͹¥»÷»î¶¯£¨BGH£©Ò»Ö±Éý¼¶£¬£¬£¬Êê½ðÒªÇóìÉýÖÁÊý°ÙÍò£¬£¬£¬²¢ÇÒÔì³É¼«´óµÄÆÆË𣻣»£»£»£»ÍøÂç·¸·¨·Ö×ÓÕýÔÚʹÃô¸ÐÊý¾ÝÎäÆ÷»¯£¬£¬£¬ÒÔÔöÌí¶ÔÀÕË÷Èí¼þÊܺ¦ÕßµÄѹÁ¦£»£»£»£»£»eCrimeÉú̬ϵͳһֱÉú³¤£¬£¬£¬±äµÃ³ÉÊìºÍרҵ»¯Ë®Æ½Ò»Ö±Ìá¸ß£»£»£»£»£»ÔÚBGHÖ®Í⣬£¬£¬Õë¶ÔÈ«Çò½ðÈÚ»ú¹¹µÄeCrime»î¶¯ÓÐËùÔöÌí£»£»£»£»£»³¯ÏòÎÞ¶ñÒâÈí¼þÕ½ÂÔµÄÇ÷ÊÆÕýÔÚ¼ÓËÙ£»£»£»£»£»¹ú¼Ò×ÊÖúµÄÓÐÕë¶ÔÐÔµÄÈëÇֻ¼ÌÐøÕë¶Ô֪ʶ²úȨ/¾ºÕùÇ鱨£¬£¬£¬Ôö½øÉçÇøÄÚ²¿µÄÆÆË飬£¬£¬²¢ÊӲ쵽ÁËÓëÏȽøeCrime¹¥»÷ÕßµÄÏàÖú¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.crowdstrike.com/resources/reports/2020-crowdstrike-global-threat-report/
2.Ó¢¹úNCSCÐû²¼ÓйØÖÇÄÜ¼à¿ØÉãÏñÍ·µÄÇå¾²Ö¸ÄÏ
Ó¢¹ú¹ú¼ÒÍøÂçÇå¾²ÖÐÐÄ£¨NCSC£©Ðû²¼ÓйØÔõÑù׼ȷÉèÖÃÖÇÄÜÇå¾²ÉãÏñÍ·ºÍÓ¤¶ù¼àÊÓÆ÷µÄÖ¸ÄÏ£¬£¬£¬ÒÔ×èÖ¹Óû§Êܵ½¹¥»÷ÕߵĹ¥»÷¡£¡£¡£NCSCÌåÏÖ¡°ÖÇÄÜÉãÏñ»ú£¨ÓÃÓÚ¼àÊÓºâÓîÄÚºÍÖÜΧ»î¶¯µÄÇå¾²ÉãÏñ»úºÍÓ¤¶ù¼àÊÓÆ÷£©Í¨³£Ê¹ÓüÒÍ¥Wi-FiÅþÁ¬µ½»¥ÁªÍø£¬£¬£¬ÔÚÉÙÉÙÊýÇéÐÎÏ£¬£¬£¬Î´¾ÊÚȨµÄ¹¥»÷Õß¿ÉÒÔ»á¼ûÖÇÄÜÉãÏñ»úµÄʵʱÁ÷»òͼÏñ£¬£¬£¬Õâ»áʹÄúµÄÒþ˽Êܵ½Íþв¡£¡£¡£¡±ÎªÁ˵ÖÓù´ËÀ๥»÷£¬£¬£¬NCSC½¨ÒéʹÓÃÇ¿Á¦µÄ¡¢»ùÓÚÃÜÂë¶ÌÓïµÄÃÜÂë¸ü¸Ä×°±¸µÄĬÈÏÃÜÂ룬£¬£¬¸ÃÃÜÂë¿ÉÒÔʹÓÃÓû§Äܹ»¼Ç×ŵÄÈý¸öËæ»úµ¥´Ê¹¹½¨£¬£¬£¬²¢ÇÒ¼á³ÖÇå¾²ÉãÏñÍ·µÄ¹Ì¼þΪ×îкͽûÓò»ÐëÒªµÄÔ¶³ÌÉó²é¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/uk-ncsc-releases-tips-on-securing-smart-security-cameras/
3.·¸·¨ÍÅ»ïMoleratsй¥»÷»î¶¯£¬£¬£¬Õë¶ÔÕþ¸®ºÍµçÐÅÐÐÒµ
Palo Alto NetworksµÄUnit42ÍŶÓÔÚ2019Äê10Ôµ½2019Äê12ÔÂÊӲ쵽¶à¸öÓë·¸·¨ÍÅ»ïMoleratsÓйصĴ¹ÂÚ¹¥»÷»î¶¯¡£¡£¡£¹¥»÷ÕßµÄÄ¿µÄº¸ÇÕþ¸®¡¢µçÐÅ¡¢°ü¹ÜºÍÁãÊÛÐÐÒµ£¬£¬£¬Éæ¼°6¸ö¹ú¼ÒµÄ8¸ö×éÖ¯¡£¡£¡£ËùÓÐÕâЩ¹¥»÷¶¼Éæ¼°µ½Ê¹Óô¹ÂÚÓʼþת´ï¶ñÒâÎĵµ£¬£¬£¬²¢Ê¹ÓÃÉç½»¹¤³ÌÊÖÒÕÒªÇóÊÕ¼þÈËÖ´ÐÐijЩ²Ù×÷£¬£¬£¬ÀýÈçÆôÓúê»òµã»÷Á´½ÓµÈ¡£¡£¡£´ó´ó¶¼´ËÀ๥»÷ÖеÄÓÐÓøºÔØÊÇSparkºóÃÅ£¬£¬£¬¸ÃºóÃÅÔÊÐí¹¥»÷ÕßÔÚÊÜѬȾµÄϵͳÉÏ·¿ªÓ¦ÓóÌÐò²¢ÔËÐÐÏÂÁî¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://unit42.paloaltonetworks.com/molerats-delivers-spark-backdoor/
4.Ó¢¹úÊý¾Ýî¿Ïµ»ú¹¹¶Ô¹úÌ©º½¿Õ´¦ÒÔ50ÍòÓ¢°÷·£¿£¿£¿£¿£¿£¿£¿î
Ó¢¹úÐÅϢרԱ°ì¹«ÊÒÒò2018Äê940ÍòÂÿÍÊý¾Ýй¶ÊÂÎñ¶Ô¹úÌ©º½¿Õ¹«Ë¾´¦ÒÔ50ÍòÓ¢°÷µÄ·£¿£¿£¿£¿£¿£¿£¿î¡£¡£¡£¸Ã¹¥»÷ÒÉËÆ±¬·¢ÔÚ2018Äê3Ô·ݣ¬£¬£¬²¢ÓÚ5Ô·ݻñµÃÈ·ÈÏ£¬£¬£¬Æäʱ¹úÌ©º½¿ÕµÄÊý¾Ý¿âÔâµ½Á˱©Á¦ÆÆ½â¹¥»÷¡£¡£¡£ICOÊÓ²ì³Æ¹úÌ©µÄϵͳÊܵ½ÁËÊý¾ÝÍøÂçÀà¶ñÒâÈí¼þµÄÓ°Ï죬£¬£¬²¢·¢Ã÷¹úÌ©ÔÚÇå¾²ÐÔ·½ÃæµÄһЩȱ·¦£¬£¬£¬°üÀ¨²»ÊÜÃÜÂë±£»£»£»£»£»¤µÄ±¸·ÝÎļþ¡¢Î´´ò²¹¶¡µÄWebЧÀÍÆ÷¡¢ÒѹýʱµÄ²Ù×÷ϵͳºÍȱ·¦·À²¡¶¾±£»£»£»£»£»¤µÈ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.theregister.co.uk/2020/03/04/ico_fines_cathay_pacific_500000/
5.¹È¸èÐû²¼3ÔÂAndroidÇå¾²¸üУ¬£¬£¬ÐÞ¸´70¶à¸öÎó²î
¹È¸èÐû²¼2020Äê3ÔÂAndroidÇå¾²¸üУ¬£¬£¬¹²ÐÞ¸´70¶à¸öÎó²î£¬£¬£¬ÆäÖÐ×îÑÏÖØµÄÎó²îÊÇýÌå¿ò¼Ü×é¼þÖеĴúÂëÖ´ÐÐÎó²î£¨CVE-2020-0032£©£¬£¬£¬¸ÃÎó²î¿ÉÄÜʹԶ³Ì¹¥»÷ÕßʹÓöñÒâÎļþÔÚÌØÈ¨Àú³ÌµÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂ룬£¬£¬¸ÃÎó²îÓ°ÏìÁËÔËÐÐAndroid 8.0¡¢8.1¡¢9ºÍ10°æ±¾µÄ×°±¸¡£¡£¡£±ðµÄ£¬£¬£¬¹È¸è»¹ÐÞ¸´ÁËýÌå¿ò¼ÜÖеÄÁíÍâÁ½¸öÑÏÖØÎó²î£¬£¬£¬°üÀ¨ÌØÈ¨ÌáÉýÎó²î£¨CVE-2020-0033£©ºÍÐÅϢй¶Îó²î£¨CVE-2020-0034£©¡£¡£¡£´Ë´Î¸üÐÂÐÞ¸´Á˸ßͨ±ÕÔ´×é¼þÖеÄ40¸öÎó²î£¬£¬£¬ÆäÖÐ16¸ö±»ÆÀΪÑÏÖØ¼¶±ð¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/98901/mobile-2/googles-march-2020-security-updates-android.html
6.¼ÎÄ껪ÓÎÂÖ¼¯ÍÅÔâºÚ¿ÍÈëÇÖ£¬£¬£¬¿Í»§Êý¾Ý¿ÉÄÜй¶
È«Çò×î´óµÄÓÎÂÖÔËÓªÉ̼ÎÄ껪ÓÎÂÖ¼¯ÍÅ£¨Carnival Corporation£¦plc£©ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬¿Í»§Êý¾Ý¿ÉÄÜй¶¡£¡£¡£Æ¾Ö¤¸Ã¹«Ë¾µÄת´ï£¬£¬£¬ÔÚ2019Äê4ÔÂ11ÈÕÖÁ7ÔÂ23ÈÕÖ®¼äδ¾ÊÚȨµÄ¹¥»÷Õß»á¼ûÁËijЩ°üÀ¨¿Í»§ÐÅÏ¢µÄÔ±¹¤ÓÊÏäÕË»§£¬£¬£¬¿ÉÄÜй¶µÄÐÅÏ¢°üÀ¨¿Í»§µÄÐÕÃû¡¢µØµã¡¢Éç»áÇå¾²ºÅÂë¡¢Õþ¸®Ê¶ÓÖÃûÂ루ÀýÈ绤ÕÕID»ò¼ÝÕÕID£©¡¢ÐÅÓÿ¨ºÍÒøÐÐÕË»§ÐÅÏ¢ÒÔ¼°Ó뿵½¡×´Ì¬Ïà¹ØµÄÐÅÏ¢¡£¡£¡£¼ÎÄ껪»¹³ÆÄ¿½ñûÓÐÖ¤¾ÝÅú×¢ÊÂÎñ±¬·¢ºóÊÜÓ°Ïì¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢±»ÀÄÓᣡ£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/carnival-cruise-line-operator-discloses-potential-data-breach/