¾ÅÓÎÀÏ¸ç¿Æ¼¼ÍþвÇ鱨Öܱ¨-2020ÄêµÚ6ÖÜ£¨2020.2.03-2020.2.09£©
2020-02-09
|
Ò»¡¢ °µÍøÇ鱨 |
|
·ÖÀà |
·¢Ã÷ʱ¼ä |
°µÍøÉúÒâÎÊÌâ |
|
½ðÈÚ |
2020-02-03 22:36 |
¹ÉÃñÊý¾Ý10800Ìõ19ÄêÄ³Ö¤È¯Íøµãпª»§Êý¾Ý |
|
½ðÈÚ |
2020-02-03 16:55 |
59wÄ³ÒøÐÐÀí²Æ¿Í»§´øÊÖ»úºÅÉí·ÝÖ¤µØµãµÈ |
|
½ðÈÚ |
2020-02-03 23:26 |
12Íò8Ä³ÒøÐÐÐÅÓÿ¨³Ö¿¨È˺¬Éê°ìʱµÄËùÓÐÐÅÏ¢ |
|
½ðÈÚ |
2020-02-02 13:34 |
Ä³ÒøÐÐÆóҵͨѶ¼ |
|
½ðÈÚ |
2020-02-05 00:32 |
¹ÉÃñÊý¾Ý98w7ijͶ×ʹ«Ë¾Êý¾Ýº¬ÐÕÃûÊÖ»ú΢ÐÅ |
|
½ðÈÚ |
2020-02-05 01:19 |
8w8Õã½Ä³Í¶¹Ë¹«Ë¾19Äê¹ÉÃñÊý¾Ý |
|
½ðÈÚ |
2020-02-05 16:40 |
Ä³ÒøÐÐ_ÍòÍò¸»ºÀСÎÒ˽¼ÒÊý¾Ý |
|
½ðÈÚ |
2020-02-06 13:26 |
ij֤ȯ_¹ÉÃñÊý¾Ý23Íò |
| ½ðÈÚ | 2020-02-06 21:39 | Àí²ÆÊý¾Ý 10WÌõÄ³ÒøÐÐÀí²ÆÓû§ÐÅÏ¢ |
*¸ü¶àÏêϸÄÚÈÝ£¬¿ÉÓë¾ÅÓÎÀÏ¸ç¿Æ¼¼ÉÌÎñÖ°Ô±ÁªÏµ»òͨ¹ýcsc@nsfocus.comÓëÎÒÃÇÁªÏµ
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. ÐÛÂõ²úÆ·Îó²î
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬ÓÐÍâÑóÇå¾²Ñо¿Ô±Ö¸³öº£Ë¼£¨HiSilicon£©Ð¾Æ¬ÖÐÔ¤ÁôºóÃÅ£¬Êºó¶à·½Ñо¿Ô±ÒÔ¼°º£Ë¼¹Ù·½¶¼³ÎÇå²¢ÌåÏָúóÃÅÔ´ÓÚÐÛÂõÈí¼þµÄ×°±¸£¬²¢·Çº£Ë¼Ð¾Æ¬¡£ºóÃÅÖ÷ҪʹÓö˿Ú9530/tcpÕìÌýÌØÊâÏÂÁ¹¥»÷Õßͨ¹ý´Ë¶Ë¿Ú¿ªÆôtelnet·þÎñ£¬²¢Ê¹ÓÃĬÈϵĿÚÁîµÇ¼£¬´Ó¶ø¿ØÖÆ×°±¸¡£
¡¾²Î¿¼Á´½Ó¡¿
https://mp.weixin.qq.com/s/yMJWxJvtgeuzSfYTN6vn7Q
2. ˼¿ÆÐÞ¸´CDPÐÒéÎó²î
¡¾¸ÅÊö¡¿
±±¾©Ê±¼ä2ÔÂ6ÈÕ£¬Ë¼¿Æ£¨Cisco£©¹Ù·½ÐÞ¸´Á˱£´æÓÚCDPÐÒéÖеÄ5¸ö¸ßΣÎó²î£¬¸ÃÐÒé¿ÉÔÊÐí˼¿Æ×°±¸ÔÚÄÚÍøÇéÐÎͨ¹ý¶à²¥ÐÂÎÅÏ໥·ÖÏíÐÂÎÅ£¬Ö÷ÒªÓ°ÏìIPµç»°ºÍÉãÏñÍ·×°±¸¡£´Ë´Î¹ûÕæµÄ5¸öÎó²î¾ùÊôÓÚÄÚ´æÒç³öÎó²î£¬ÏÖʵʹÓÃÄѶȴó£¬ÔÚÌØ¶¨Ìõ¼þÏ¿ÉÔì³ÉÔ¶³Ì´úÂëÖ´ÐС£
¡¾²Î¿¼Á´½Ó¡¿
http://blog.nsfocus.net/cisco20200207/
3. °²×¿À¶ÑÀ×é¼þ¸ßΣÎó²î
¡¾¸ÅÊö¡¿
¿ËÈÕ£¬¹È¸èÐû²¼2Ô°²×¿Çå¾²²¹¶¡£¬ÆäÖÐÐÞ¸´ÁËÒ»¸ö¸ßΣµÄÀ¶ÑÀ×é¼þÎó²î£¨CVE-2020-0022£©¡£¸ÃÎó²îÎÞÐèÓû§µÄ½»»¥²Ù×÷£¬ÔÚ×°±¸·¿ªÀ¶ÑÀʱ¼´¿É±»¹¥»÷£¬¹¥»÷ÕßÀÖ³ÉʹÓøÃÎó²î¼´¿ÉÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂ롣ͬʱÑо¿Ö°Ô±»¹Ö¸³ö¸ÃÎó²î¿ÉÄܱ»¹¥»÷ÕßÓÃÀ´ÖÆ×÷¿ÉÒÔ×ÔÖ÷Èö²¥µÄÈ䳿ÐÍÎó²î¡£
¡¾²Î¿¼Á´½Ó¡¿
http://blog.nsfocus.net/cve-2020-0022/
4. MyCERTÖÒÑÔAPT40¿ªÕ¹µÄÍøÂçÌØ¹¤Ô˶¯
¡¾¸ÅÊö¡¿
MyCERT(ÂíÀ´Î÷ÑÇÅÌËã»ú½ôÆÈÏìӦС×é)×î½üÊӲ쵽Õë¶ÔÂíÀ´Î÷ÑÇÕþ¸®¹ÙÔ±µÄ¹¥»÷Ô˶¯£¬¹¥»÷Õßͨ¹ý·¢¸øÕþ¸®¹ÙÔ±µÄÓã²æÊ½ÍøÂç´¹ÂÚÐÂÎÅ£¬Ã°³äÐÂÎżÇÕß¡¢ÉÌÒµ³öÊéÎïµÄСÎÒ˽¼Ò»òÏà¹Ø¾üÊÂ×éÖ¯£¬ÓÕµ¼Êܺ¦ÕßѬȾ¶ñÒâÈí¼þºó£¬´ÓÕþ¸®ÏµÍ³ÖÐÇÔÈ¡ÉñÃØÎļþ¡£´Ë´Î¹¥»÷Ô˶¯ÒÉËÆÓɹ¥»÷×éÖ¯APT40Ìᳫ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.mycert.org.my/portal/advisory?id=MA-770.022020
5. Gamaredon×éÖ¯ÔöÇ¿Õë¶ÔÎÚ¿ËÀ¼µÄ¹¥»÷
¡¾¸ÅÊö¡¿
ÔÚÒÑÍùµÄ¼¸ÔÂÖУ¬Íþв×éÖ¯GamaredonÒ»Ö±¸üÐÂÆä¹¤¾ß¼¯²¢ÔöÇ¿¶ÔÎÚ¿ËÀ¼Õþ¸®ºÍÖ´·¨²¿·ÖµÄ¹¥»÷Ô˶¯¡£GamaredonÊÇÒ»¸ö×Ô2013ÄêÒÔÀ´Ò»Ö±»îÔ¾ÍøÂçÍþв×éÖ¯£¬Ö÷ÒªÕë¶ÔÎÚ¿ËÀ¼Õþ¸®¾ÙÐжñÒâÔ˶¯£¬ÆäÖ÷ҪĿµÄÊÇÇÔÈ¡Õþ¸®£¬¾üÊÂÖ°Ô±×ÊÁÏÐÅÏ¢¡£
¡¾²Î¿¼Á´½Ó¡¿
https://labs.sentinelone.com/pro-russian-cyberspy-gamaredon-intensifies-ukrainian-security-targeting/
6. Charming Kitten×éÖ¯Õë¶ÔÌìϸ÷µØ¹«ÖÚÈËÎïµÄ¹¥»÷Ô˶¯
¡¾¸ÅÊö¡¿
½üÆÚ·¢Ã÷Charming Kitten×éÖ¯µÄһϵÁÐÍøÂç´¹ÂÚÔ˶¯£¬Ð¹¥»÷Ô˶¯µÄÖØµãÊÇÇÔÈ¡Êܺ¦Õߵĵç×ÓÓʼþÕÊ»§ÐÅÏ¢²¢²éÕÒÓйØËûÃǵÄÁªÏµÈË/ÍøÂçµÄÐÅÏ¢£¬Êܺ¦Õß°üÀ¨¼ÇÕß¡¢ÕþÖκÍÈËȨÔ˶¯¼Ò¡£Charming Kitten£¨ÓÖÃûGroup 83¡¢Newsbeef¡¢iKittens¡¢Parastoo¡¢Newscaster£©ÊÇÒÁÀÊÍøÂçÌØ¹¤×éÖ¯£¬×Ô2014Äê×óÓÒ×îÏÈ»îÔ¾¡£
¡¾²Î¿¼Á´½Ó¡¿
https://blog.certfa.com/posts/fake-interview-the-new-activity-of-charming-kitten/
7. MetamorfoбäÖÖÕë¶Ô¶à¸ö¹ú¼Ò½ðÈÚ»ú¹¹
¡¾¸ÅÊö¡¿
MetamorfoÊÇÒ»¸ö¶ñÒâÈí¼þ¼Ò×壬Õë¶ÔÔÚÏß½ðÈÚ»ú¹¹µÄ¿Í»§¡£2020Äê1Ô·¢Ã÷Metamorfo±äÖÖ½öÕë¶Ô°ÍÎ÷½ðÈÚ»ú¹¹µÄ¿Í»§£¬¿ËÈÕ·¢Ã÷MetamorfoµÚ¶þ¸ö±äÖÖ£¬Õë¶Ô¶à¸ö¹ú¼Ò/µØÇø¸ü¶à½ðÈÚ»ú¹¹µÄ¿Í»§£¬ÍøÂçÊܺ¦ÕßÅÌËã»úÊý¾Ý²¢ÓëÆäÏÂÁîºÍ¿ØÖÆ·þÎñÆ÷¾ÙÐÐͨѶ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.fortinet.com/blog/threat-research/another-metamorfo-variant-targeting-customers-of-financial-institutions.html

¾ÅÓÎÀϸçÔÆ







