Ñо¿Ö°Ô±·¢Ã÷жñÒâÈí¼þTaurusͨ¹ý¶ñÒâ¹ã¸æ»î¶¯Èö²¥£»£»£»£»£»£»£»Pandora FMSÖб£´æ¶à¸öÎó²î £¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÔ¶³ÌÖ´Ðй¥»÷

Ðû²¼Ê±¼ä 2020-09-29
1.Ñо¿Ö°Ô±·¢Ã÷жñÒâÈí¼þTaurusͨ¹ý¶ñÒâ¹ã¸æ»î¶¯Èö²¥


1.jpg


Ñо¿Ö°Ô±·¢Ã÷еÄÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þTaurusͨ¹ý¶ñÒâ¹ã¸æ»î¶¯Èö²¥¡£¡£¡£¡£¡£¡£TaurusÊÇÒ»ÖÖÏà¶Ô½ÏеĶñÒâÈí¼þ £¬£¬£¬£¬£¬£¬ÓÚ2020Äê´º¼¾·ºÆð £¬£¬£¬£¬£¬£¬Í¨¹ýÕë¶ÔÃÀ¹úÓû§µÄ¶ñÒâ¹ã¸æ»î¶¯¾ÙÐÐÈö²¥¡£¡£¡£¡£¡£¡£Æä×î³õÊÇÓÉPredatorµÄ½¨ÉèÕßËù¿ª·¢ £¬£¬£¬£¬£¬£¬Òò´Ë¶þÕß¾ßÓÐÏàͬµÄ¹¦Ð§ £¬£¬£¬£¬£¬£¬¼´´Óä¯ÀÀÆ÷¡¢FTP¡¢VPN¡¢µç×ÓÓʼþ¿Í»§¶ËÒÔ¼°¼ÓÃÜÇ®±ÒÇ®°üÇÔȡƾ֤¡£¡£¡£¡£¡£¡£´Ë´Î×îз¢Ã÷µÄ¶ñÒâ»î¶¯Ö÷ÒªÕë¶Ô³ÉÈËÍøÕ¾µÄ»á¼ûÕß £¬£¬£¬£¬£¬£¬Êܺ¦Õß´ó¶àÀ´×ÔÃÀ¹ú £¬£¬£¬£¬£¬£¬Ò²ÓÐÀ´×Ô°Ä´óÀûÑǺÍÓ¢¹ú¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.malwarebytes.com/malwarebytes-news/2020/09/taurus-project-stealer-now-spreading-via-malvertising-campaign/


2.Pandora FMSÖб£´æ¶à¸öÎó²î £¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÔ¶³ÌÖ´Ðй¥»÷


2.jpg


Pandora FMSÖб£´æ¶à¸öÎó²î £¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÔ¶³ÌÖ´Ðй¥»÷¡£¡£¡£¡£¡£¡£Pandora FMSÊÇÒ»¸ö¿ª·ÅÔ´´úÂë½â¾ö¼Æ»® £¬£¬£¬£¬£¬£¬ËüÌṩÓÃÓÚ¼àÊÓÍøÂçÅþÁ¬¡¢Ó¦ÓóÌÐòÖÎÀí¡¢ÊÂÎñ¾¯±¨ÒÔ¼°Windows¡¢Linux¡¢UnixºÍAndroidϵͳµÄÊðÀíºÍÎÞÊðÀí¼àÊӵĽçÃæ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚPandora FMS°æ±¾742Öз¢Ã÷ÁËËĸöÎó²î £¬£¬£¬£¬£¬£¬»®·ÖΪpre-auth SQL×¢ÈëÎó²î¡¢pre-auth PHAR·´ÐòÁл¯Îó²î¡¢ÌØÈ¨Óû§×îµÍµÄÔ¶³ÌÎļþ°üÀ¨±àÂë¹ýʧÒÔ¼°¿çÕ¾µãÇëÇóαÔ죨CSRF£©Îó²î¡£¡£¡£¡£¡£¡£ÆäÖÐ £¬£¬£¬£¬£¬£¬pre-auth SQL×¢ÈëÎó²îÎÞÐèÈκλá¼ûȨÏÞ¼´¿ÉÔ¶³ÌʹÓà £¬£¬£¬£¬£¬£¬²¢¶ÔÓ¦ÓóÌÐòÍêÈ«½ÓÊÜ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://portswigger.net/daily-swig/multiple-vulnerabilities-in-pandora-fms-could-trigger-remote-execution-attack


3.¹ú¼ÊÌØÉâ×éÅûÂ¶ÌØ¹¤Èí¼þFinSpyÕë¶Ô°£¼°µÄ¹¥»÷»î¶¯


3.jpg


¹ú¼ÊÌØÉâ×éÖ¯½ÒÆÆÁËÕë¶Ô°£¼°Ãñ¼äÉç»á×éÖ¯µÄмàÊӻ £¬£¬£¬£¬£¬£¬¸Ã»î¶¯Ê¹ÓÃÁËÕë¶ÔLinuxºÍmacOSϵͳµÄÌØ¹¤Èí¼þFinSpy¡£¡£¡£¡£¡£¡£FinSpyÒ²³ÆFinFisher £¬£¬£¬£¬£¬£¬ÓÉÒ»¼ÒµÂ¹ú¹«Ë¾¿ª·¢ £¬£¬£¬£¬£¬£¬¾ßÓжàÖÖÌØ¹¤¹¦Ð§ £¬£¬£¬£¬£¬£¬°üÀ¨ÉñÃØ·­¿ªÍøÂçÉãÏñÍ·ºÍÂó¿Ë·ç¡¢ÔÚ¼üÅÌÉϼͼÊܺ¦Õß¼üÈëµÄËùÓÐÄÚÈÝ¡¢×èµ²ºô½ÐºÍÊý¾Ý×ß©¡£¡£¡£¡£¡£¡£Æä¿ÉÒÔͬʱÕë¶Ô×ÀÃæºÍÒÆ¶¯²Ù×÷ϵͳ £¬£¬£¬£¬£¬£¬°üÀ¨Android¡¢iOS¡¢Windows¡¢macOSºÍLinuxϵͳ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2020/09/finspy-malware-macos-linux.html


4.Next CallerÐû²¼COVID-19Ïà¹ØÚ²Æ­»î¶¯ÆÊÎö±¨¸æ


4.jpg


Next CallerÐû²¼COVID-19Ïà¹ØÚ²Æ­»î¶¯ÆÊÎö±¨¸æ £¬£¬£¬£¬£¬£¬ÏÔʾÓëCOVIDÏà¹ØµÄڲƭÐÐΪÒѶÔÃñÖÚ±¬·¢ÁËÆÕ±éÓ°Ïì¡£¡£¡£¡£¡£¡£±¨¸æÌåÏÖ £¬£¬£¬£¬£¬£¬55£¥µÄÃÀ¹úÈËÒÔΪËûÃÇÒѳÉΪÓëCOVIDÏà¹ØµÄڲƭÐÐΪµÄÄ¿µÄ £¬£¬£¬£¬£¬£¬Ö»¹ÜÔÆÔÆ £¬£¬£¬£¬£¬£¬ÈÔÓÐ59£¥µÄÃÀ¹úÈ˳ÆËûÃÇûÓнÓÄÉÈÎºÎÆäËûÔ¤·À²½·¥À´±£»£»£»£»£»£»£»¤×Ô¼ºÃâÊܹ¥»÷¡£¡£¡£¡£¡£¡£ÓнüÈý·ÖÖ®Ò»£¨30%£©µÄÃÀ¹úÈ˸üµ£ÐÄÔ⵽ڲƭ £¬£¬£¬£¬£¬£¬¶ø·ÇѬȾ²¡¶¾¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2020/09/28/covid-related-fraud-schemes/


5.ÌïÄÉÎ÷Öݵͼ»áÔâµ½¹¥»÷ £¬£¬£¬£¬£¬£¬µ¼ÖÂÕþ¸®ÄÚ²¿ÍøÂçÔÝʱ¹Ø±Õ


5.jpg


ÌïÄÉÎ÷Öݵͼ»á¿ËÀ­¿Ë˹ά¶ûÔâµ½¹¥»÷ £¬£¬£¬£¬£¬£¬µ¼ÖÂÕþ¸®ÄÚ²¿ÍøÂçÔÝʱ¹Ø±Õ¡£¡£¡£¡£¡£¡£Æä½²»°ÈËMichelle NewellÌåÏÖ £¬£¬£¬£¬£¬£¬¸ÃÏØÉÏÖÜÎåÔâµ½ÁËÍøÂç¹¥»÷ £¬£¬£¬£¬£¬£¬µ¼ÖÂÆäÕþ¸®ÄÚ²¿ÍøÂçÔÚÖÜÄ©ÔÝʱ¹Ø±Õ £¬£¬£¬£¬£¬£¬Ö±ÖÁÖÜÈÕÒÀÈ»ÎÞ·¨»á¼û¡£¡£¡£¡£¡£¡£ÏÖÔÚ¸ÃÏØÕýÔÚÊÔͼ½â¾ö¸ÃÎÊÌâ²¢»Ö¸´ÔËÓª £¬£¬£¬£¬£¬£¬ÒѾ­ÊµÑéÁËÏìÓ¦¼Æ»®²¢Õö¿ªÁËÊӲ졣¡£¡£¡£¡£¡£911ÖÐÐÄÖ÷ÈÎHope PetersenÌåÏÖ £¬£¬£¬£¬£¬£¬¸ÃµØÇøµÄ911 CenterûÓÐÊܵ½Õþ¸®ÄÚÍø¹Ø±ÕµÄÓ°Ïì¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://clarksvillenow.com/local/data-security-incident-shuts-down-montgomery-countys-computer-network/


6.È«Ãñ¿µ½¡Ð§ÀÍҽԺϵͳѬȾRyuk £¬£¬£¬£¬£¬£¬ÆäÈ«ÇòµÄ·ÖÔºÊܵ½Ó°Ïì


6.jpg


9ÔÂ26ÈÕÖÁ27ÈÕ £¬£¬£¬£¬£¬£¬ÃÀ¹úµÄÈ«Ãñ¿µ½¡Ð§ÀÍÒ½Ôº£¨UHS£©ÏµÍ³Ñ¬È¾ÀÕË÷Èí¼þRyuk £¬£¬£¬£¬£¬£¬ÆäÈ«ÇòµÄ·ÖÔºÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£UHSÔÚÔÚÃÀ¹úºÍÓ¢¹úÖÎÀí×Å400¶à¼ÒÒ½ÔººÍÕչ˻¤Ê¿ÖÐÐÄ £¬£¬£¬£¬£¬£¬ËäÈ»¹¥»÷µÄÕæÊµË®Æ½ÉдýÈ·¶¨ £¬£¬£¬£¬£¬£¬¿ÉÊÇÔçÆÚ±¨µÀ³ÆUHSµÄÕû¸öÍøÂç¶¼Êܵ½ÁËÓ°Ïì¡£¡£¡£¡£¡£¡£ÃÀ¹ú±±¿¨ÂÞÀ³ÄÉÖÝ¡¢µÂ¿ËÈøË¹Öݵȶà¸öµØÇøµÄUHSÒ½ÔººÍÕչ˻¤Ê¿ÖÐÐÄÈ·ÈÏÆäITϵͳ·ºÆðÁËÎÊÌâ¡£¡£¡£¡£¡£¡£ÏÖÔÚ £¬£¬£¬£¬£¬£¬UHS½²»°È˲¢Î´»Ø¸´ÖÃÆÀÇëÇó £¬£¬£¬£¬£¬£¬µ«Æä͸¶¸ÃÊÂÎñÊÇÓÉÃûΪRyukµÄÀÕË÷Èí¼þÔì³ÉµÄ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/uhs-hospital-network-hit-by-ransomware-attack/