WHO¡¢CDC¡¢NIH¼°¸Ç´Ä»ù½ð»áÔ¼2.5ÍòÓÊÏäÆ¾Ö¤Ð¹Â¶£»£» £»£»£»Ç徲ר¼Ò·¢Ã÷28¸ö·À²¡¶¾²úÆ·±£´æsymlink raceÎó²î

Ðû²¼Ê±¼ä 2020-04-26

1.WHO¡¢CDC¡¢NIH¼°¸Ç´Ä»ù½ð»áÔ¼2.5ÍòÓÊÏäÆ¾Ö¤Ð¹Â¶


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¾Ý»ªÊ¢¶ÙÓʱ¨±¨µÀ£¬£¬£¬£¬¿ËÈÕWHO¡¢CDC¡¢NIH¼°¸Ç´Ä»ù½ðԼĪÓÐ2.5ÍòÓÊÏäÆ¾Ö¤Ð¹Â¶£¬£¬£¬£¬²¢±»ÓÒÒí¼«¶Ë·Ö×ӺͺڿÍÓÃÀ´Èö²¥COVID-19Ïà¹ØÒ¥ÑÔ¡£¡£¡£¡£ ¡£WHOÊÇ¡¶ÓÊÕþ¡·±¨¸æÖеÚÒ»¸ö¹ûÕæÈÏ¿ÉÆäÊÂÇéÖ°Ô±µÄµç×ÓÓÊÏäÆ¾Ö¤Ð¹Â¶µÄ×éÖ¯£¬£¬£¬£¬¿ÉÊÇûÓÐ͸©ÕâЩƾ֤ÊÇÔõÑùй¶µÄ¡£¡£¡£¡£ ¡£Lucy SecurityµÄCEO Colin BastableÔòÒÔΪ´Ë´ÎÊÂÎñÊÇÀ´×ÔÔçÆÚµÄÊý¾Ýй¶£¬£¬£¬£¬ºÚ¿ÍÏëҪʹÓÃÕâЩ¾Éƾ֤Õë¶ÔÄ¿½ñµÄCOVID-19¡£¡£¡£¡£ ¡£¸Ã»ú¹¹»¹ÌåÏÖ×ß©µÄÊý¾Ý²»»á¶ÔÄ¿½ñµÄWHOϵͳÔì³ÉÈκÎΣº¦£¬£¬£¬£¬ÓÉÓÚÕâЩÊý¾Ý²»ÊÇ×î½üµÄ£¬£¬£¬£¬Ö»ÊÇÓ°ÏìÁËÒ»¸öÓÉÊÀÎÀ×éÖ¯ÏÖÈκÍÍËÐÝÖ°Ô±ÒÔ¼°ÏàÖúͬ°éʹÓþɵÄÍâÁªÍø£¬£¬£¬£¬¸Ã×éÖ¯ÏÖÔÚÕýÔÚ½«ÊÜÓ°ÏìµÄϵͳǨáãµ½¸üÇå¾²µÄÉí·ÝÑé֤ϵͳ¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.darkreading.com/attacks-breaches/who-confirms-email-credentials-leak/d/d-id/1337650


2.ÃÀ»ùÒò²âÊÔʵÑéÊÒÔâ´¹ÂÚ¹¥»÷£¬£¬£¬£¬23.3Íò¹«ÃñÐÅϢй¶


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÃÀ¹ú¼ÓÀû¸£ÄáÑÇÖݵĻùÒò²âÊÔʵÑéÊÒAmbry GeneticsÔâµ½´¹ÂÚ¹¥»÷£¬£¬£¬£¬23.3Íò¹«ÃñµÄҽѧÐÅϢй¶£¬£¬£¬£¬¸ÃÊÂÎñΪÃÀ¹ú2020ÄêµÚ¶þ´óÒ½ÁÆÊý¾Ý×ß©ÊÂÎñ¡£¡£¡£¡£ ¡£¸Ã»ú¹¹ÌåÏÖ£¬£¬£¬£¬¹¥»÷±¬·¢ÔÚ1ÔÂ22ÈÕÖÁ24ÈÕÖ®¼ä£¬£¬£¬£¬ºÚ¿Íδ¾­ÊÚȨ»á¼ûÁËÆäÔ±¹¤µÄµç×ÓÓʼþÕÊ»§¡£¡£¡£¡£ ¡£´Ë´Îй¶µÄÐÅÏ¢°üÀ¨¿Í»§ÐÕÃû¡¢Ò½ÁÆÐÅÏ¢¡¢Óë¿Í»§Ê¹ÓÃAmbryЧÀÍÏà¹ØµÄÐÅÏ¢¡¢ÉÐÓпÉÄܰüÀ¨Éç»áÇå¾²ºÅÂ룬£¬£¬£¬µ«¸Ã¹«Ë¾Ò»Ö±Ã»ÓлØÓ¦ÊÇ·ñ¿ÉÄÜ̻¶ÒÅ´«ÐÅÏ¢¡£¡£¡£¡£ ¡£2020Äê×î´óµÄÊý¾Ý×ß©ÊÂÎñÊǶíÀÕ¸ÔÖݵĿµ½¡¹²Ïí×éÖ¯£¨Health Share£©ÓÚ2Ô±¨¸æµÄ£¬£¬£¬£¬Æäδ¼ÓÃܵÄÌõ¼Ç±¾µçÄÔ±»ÇÔ£¬£¬£¬£¬Ó°ÏìÁ˽ü654400СÎÒ˽¼Ò¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://covid19.inforisktoday.com/genetic-testing-lab-hack-affects-233000-a-14182


3.ÃÀº«40ÍòÕÅÐÅÓÿ¨ÐÅÏ¢ÔÚ°µÍø³öÊÛ£¬£¬£¬£¬ÊÛ¼ÛÔ¼200ÍòÃÀÔª


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÏÖÔÚ£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷397365ÕÅÐÅÓÿ¨µÄÐÅÏ¢ÕýÔÚJoker's StashÉÏÒÔ1985835ÃÀÔª³öÊÛ£¬£¬£¬£¬ÆäÖÐ198233ÕÅÊôÓÚº«¹ú£¨Ô¼Õ¼×ÜÊýµÄ49.9£¥£©£¬£¬£¬£¬49.3£¥ÊôÓÚÃÀ¹úÒøÐкͽðÈÚ»ú¹¹¡£¡£¡£¡£ ¡£´Ë´Î³öÊÛµÄÊý¾ÝÖ÷ҪΪTrack 2Êý¾Ý£¬£¬£¬£¬°üÀ¨ÒøÐÐʶ±ðÂ루BIN£©¡¢Õʺ𢵽ÆÚÈÕÆÚ¡¢»¹¿ÉÄܰüÀ¨CVV£¬£¬£¬£¬¶øÕâЩÊý¾Ýͨ³£ÊÇ´ÓÓÐÎó²îµÄPOS»ú¡¢ATMºÍÖ§¸¶ÏµÍ³ÖÐй¶µÄ¡£¡£¡£¡£ ¡£¿ÉÊÇ£¬£¬£¬£¬ÏÖÔÚй¶Êý¾ÝµÄȪԴÈÔȻδ֪£¬£¬£¬£¬Î¨Ò»ÄÜÈ·¶¨µÄ¾ÍÊÇÕâЩÊý¾Ý²»ÊÇ´Ó±»Magecart¹¥»÷µÄµçÉÌÍøÕ¾ÖÐй¶µÄ¡£¡£¡£¡£ ¡£Group-IBµÄShawn TayÌåÏÖ×ÝÈ»ÕâЩ³öÊÛµÄÐÅϢȱ·¦ÒÔÓÃÀ´¾ÙÐÐÔÚÏßÖ§¸¶£¬£¬£¬£¬¿ÉÊǹºÖÃÕß¿ÉÒÔÔÚ·¢¿¨»ú¹¹»¹Ã»Óз¢Ã÷ʱ£¬£¬£¬£¬ÖÆ×÷¿Ë¡¿¨µ½ATMÈ¡¿î£¬£¬£¬£¬µÖ´ïµÁË¢µÄÄ¿µÄ¡£¡£¡£¡£ ¡£IB¼¯ÍÅÒѽ«´ËÊÂÎñ֪ͨÃÀ¹úºÍº«¹ú½ðÈÚ¹²Ïí×éÖ¯ºÍ¸Ã¹úCERT£¬£¬£¬£¬ÒÔ¼õÇá´Ë´Î×ß©µÄΣº¦¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/400000-us-south-korean-card-records-put-up-for-sale-online/


4.Ç徲ר¼Ò·¢Ã÷28¸ö·À²¡¶¾²úÆ·±£´æsymlink raceÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


RACK911 LabsµÄÇ徲ר¼ÒÔÚWindows¡¢macOSºÍLinuxƽ̨ÉϵÄ28¸öÊܽӴýµÄ·À²¡¶¾Èí¼þÖз¢Ã÷symlink raceÎó²î£¬£¬£¬£¬ÊÜÓ°ÏìµÄÆ·ÅÆ°üÀ¨×ÅÃûÆ·ÅÆAvast¡¢BitDefender¡¢F-Secure¡¢FireEye¡¢McAfeeºÍkasperskyµÈ¡£¡£¡£¡£ ¡£Ç徲ר¼Ò³Æ¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²îɾ³ýϵͳÉϵÄÎļþ£¨°üÀ¨·À²¡¶¾Èí¼þ»ò²Ù×÷ϵͳʹÓõÄÎļþ£©£¬£¬£¬£¬´Ó¶øµ¼Ö·À²¡¶¾Èí¼þÎÞ·¨ÊÂÇé»ò²Ù×÷ϵͳÍ߽⡣¡£¡£¡£ ¡£ÏêϸÀ´Ëµ£¬£¬£¬£¬´ó´ó¶¼·À²¡¶¾Èí¼þ¶¼Ã»ÓÐ˼Á¿µ½´ÓɨÃè³ö¶ñÒâÎļþµ½Ö´ÐÐɨ³ý²Ù×÷Ö®¼äµÄϸСʱ¼ä´°¿Ú£¬£¬£¬£¬ÍâµØ¹¥»÷Õß»ò¶ñÒâÈí¼þ×÷Õß¿ÉʹÓÃWindowsÖеÄĿ¼Á´½Ó»òLinux/macOSÖеķûºÅÁ´½ÓÀ´´¥·¢ÌáȨºÍ¾ºÕùÌõ¼þ£¬£¬£¬£¬´Ó¶ø½ûÓ÷À²¡¶¾Èí¼þ»ò×ÌÈŲÙ×÷ϵͳ¡£¡£¡£¡£ ¡£RACK911Ïò·À²¡¶¾³§É̱¨¸æÁËÆä·¢Ã÷Ч¹û£¬£¬£¬£¬´ó´ó¶¼³§ÉÌÒѾ­ÐÞ¸´ÁËÆä²úÆ·ÖеÄÎó²î¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/102230/hacking/symlink-race-antivirus-flaws.html


5.ÈÎÌìÌÃÈ·ÈÏ16ÍòÓû§ÕË»§±»Ð®ÖÆ£¬£¬£¬£¬ÒÑ·ºÆðµÁË¢°¸Àý


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÈÎÌìÌÃÏÖÔÚÈ·ÈÏÆäÖÁÉÙ16ÍòÓû§ÕË»§Òѱ»Ð®ÖÆ£¬£¬£¬£¬»¹·ºÆðÁ˵ÁË¢°¸Àý¡£¡£¡£¡£ ¡£Õâ´Î¹¥»÷ÊÇ´Ó3ÔÂÖÐÑ®×îÏȵ쬣¬£¬£¬ºÚ¿Íͨ¹ýαÔìNintendo Network ID £¨NNID£©²»·¨µÇ¼ÈÎÌìÌÃÕÊ»§£¬£¬£¬£¬ÇÔÈ¡ÁËÓû§µÄêdzơ¢³öÉúÈÕÆÚ¡¢Ô­¼®¹ú¡¢µØÇøºÍµç×ÓÓʼþµØµã£¬£¬£¬£¬»¹Ê¹ÓÃÁËijЩÓû§ÕË»§Öа󶨵ÄPayPal¹ºÖÃÓÎÏ·ÖеĹ¦Ð§ºÍÐéÄâÇ®±Ò£¨°üÀ¨Fortnite V-Bucks£©¡£¡£¡£¡£ ¡£NNIDÊǾÉʽµÇ¼ϵͳ£¬£¬£¬£¬ËüÔÊÐíÓû§ÔÚWii U»òNintendo 3DSÉÏÖÎÀíNintendoÕÊ»§¡£¡£¡£¡£ ¡£ÏÖÔڸù«Ë¾Ðû²¼ÏÖÒѾ­ÆÆ³ýÁËͨ¹ýNNIDÉϰ¶ÕË»§µÄ¹¦Ð§£¬£¬£¬£¬²¢½«ÎªÊÜÓ°ÏìµÄÕ˺ÅÖØÖÃÃÜÂë¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/102213/hacking/nintendo-account-hijacking-campaign.html


6.IoT½©Ê¬ÍøÂçHoaxcallsбäÖÖ°üÀ¨16ÖÖDDoS¹¦Ð§


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


2020Äê4ÔÂ20ÈÕ£¬£¬£¬£¬RadwareµÄÑо¿Ö°Ô±·¢Ã÷ÁËIoT½©Ê¬ÍøÂçHoaxcallsµÄбäÖÖ£¬£¬£¬£¬¸Ã±äÖÖ°üÀ¨16ÖÖDDoS¹¦Ð§¡£¡£¡£¡£ ¡£IoT½©Ê¬ÍøÂçHoaxcalls×î³õÊÇ½è¼øÁ˽©Ê¬ÍøÂçTsunamiºÍGafgytµÄ´úÂ룬£¬£¬£¬Ê¹ÓÃUDP£¬£¬£¬£¬DNSºÍHEX·ººé·¢¶¯DDoS¹¥»÷£¬£¬£¬£¬Õë¶ÔGrandstream UCM6200ϵÁÐ×°±¸ºÍDraytek Vigor·ÓÉÆ÷µÄCVE-2020-5722ºÍCVE-2020-8515Îó²î£¨CVSS v3.1 9.8£©¡£¡£¡£¡£ ¡£RadwareÌåÏÖ£¬£¬£¬£¬ÓëÒÔǰµÄÑùÄÚÇé±È¸ÃбäÖÖ¹¥»÷ÄÜÁ¦ÏÔÖøÌá¸ß£¬£¬£¬£¬ËüʵÏÖÁË16ÖÖеÄDDoS¹¦Ð§£¬£¬£¬£¬Ê¹ÓÃÁËGrandStream UCM SQL×¢ÈëÎó²îCVE-2020-5722¡£¡£¡£¡£ ¡£¸Ã±äÖÖÊÇ´ÓÒ»¸öÍйÜЧÀÍÆ÷£¨176.123.3.96£©×îÏÈÈö²¥µÄ£¬£¬£¬£¬ÔÚ±»·¢Ã÷µÄ48СʱÄÚʹÓÃÁË15¸öIPµØµã¾ÙÐÐÈö²¥£¬£¬£¬£¬¶øÏÖÔÚÍйÜЧÀÍÆ÷µÄÊýÄ¿ÒÑÁè¼Ý75¸ö£¬£¬£¬£¬¸Ã±äÖÖ»¹Í¨¹ýʹÓÃZyXEL Cloud CNM SecuManagerÖеÄÎó²îÀ©´óÁËÄ¿µÄ×°±¸Áбí¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/102202/malware/hoaxcalls-botnet-new-variant.html