¾ÅÓÎÀÏ¸ç¿Æ¼¼ÍþвÇ鱨Öܱ¨-2020ÄêµÚ9ÖÜ£¨2020.2.24-2020.3.01£©
2020-03-01
Ò»¡¢ Íþвͨ¸æ
? Microsoft Exchange ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î
¡¾Ðû²¼Ê±¼ä¡¿2020-02-26 20:00:00 GMT
¡¾¸ÅÊö¡¿
±±¾©Ê±¼ä2ÔÂ12ÈÕ£¬Î¢ÈíÔÚÐû²¼2ÔÂÇå¾²¸üв¹¶¡Öн«Ó°ÏìMicrosoft Exchange ServerµÄÎó²îCVE-2020-0688½ç˵ΪÄÚ´æËð»µÎó²î¡£2ÔÂ26ÈÕÓÐÇå¾²Ñо¿Ô±¹ûÕæÁ˸ÃÎó²îϸ½Ú£¬»ñÈ¡µ½ÓÊÏäÕË»§È¨Ï޵Ĺ¥»÷ÕßÏò·þÎñÆ÷·¢ËÍÈ«ÐĽṹµÄÇëÇ󣬿ÉÔÚ·þÎñÆ÷¶ËʵÏÖÔ¶³Ì´úÂëÖ´ÐУ¬Î¢Èí¹Ù·½Ò²½«Ö®Ç°ÃüÃûµÄÄÚ´æËð»µÎó²îÖØÃüÃûΪԶ³Ì´úÂëÖ´ÐÐÎó²î¡£
¡¾Á´½Ó¡¿
http://blog.nsfocus.net/cve-2020-0688/
¶þ¡¢ ÈÈÃÅ×ÊѶ
1. Google ChromeÐû²¼¸üÐÂÐÞ¸´0dayÎó²î
¡¾¸ÅÊö¡¿
ÍâµØÊ±¼ä2ÔÂ24ÈÕ£¬GoogleÕë¶Ô×ÀÃæ°æChromeä¯ÀÀÆ÷Ðû²¼¸üÐÂÒÔ½â¾ö¶à¸öÎó²î£¬ÆäÖаüÀ¨Òѱ»·¢Ã÷ÔÚҰʹÓõĸßΣÎó²îCVE-2020-6418¡£CVE-2020-6418ÊDZ£´æÓÚV8ÖеÄÀàÐÍ»ìÏýÎó²î£¬V8ÊÇGoogle ChromeµÄ¿ªÔ´JavaScriptºÍWebAssemblyÒýÇæ¡£¸ÃÎó²îÓÉGoogleÍþвÆÊÎöС×éµÄClement Lecigne·¢Ã÷²¢Éϱ¨¡£
¡¾²Î¿¼Á´½Ó¡¿
http://blog.nsfocus.net/cve-2020-6418/
2. OpenSMTPDÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î
¡¾¸ÅÊö¡¿
ÍâµØÊ±¼ä2020Äê2ÔÂ24ÈÕ£¬À´×ÔÇå¾²¹«Ë¾QualysµÄÑо¿Ö°Ô±ÔÚ¹ûÕæÓʼþ×éÖÐÐû²¼ÁËOpenSMTPDÖб£´æµÄÒ»¸öÔ¶³ÌÏÂÁîÖ´ÐÐÎó²îCVE-2020-8794¡£OpenSMTPD£¨Ò²³ÆÎªOpenBSD SMTP·þÎñÆ÷£©ÊÇOpenBSDÏîÄ¿µÄÒ»²¿·Ö£¬Ò»¸öÃâ·ÑµÄ·þÎñÆ÷¶ËSMTPÐÒéʵÏÖ£¬Í¨¹ýRFC5321½ç˵¡£CVE-2020-8794ÊÇÒ»¸öÔ½½ç¶ÁÈ¡Îó²î£¬¿É±»Ô¶³ÌʹÓã¬ÀֳɵÄʹÓÿɵ¼Ö¹¥»÷ÕßÒÔrootÉí·ÝÖ´ÐÐ×¢Èëµ½envelopeÎļþÖеÄí§ÒâÏÂÁî¡£
¡¾²Î¿¼Á´½Ó¡¿
http://blog.nsfocus.net/cve-2020-8794/
3. Vmware vRealize Operations for Horizon AdapterÔ¶³Ì´úÂëÖ´ÐÐÎó²î
¡¾¸ÅÊö¡¿
Vmware¿ËÈÕÐû²¼µÄͨ¸æÖÐÐû²¼ÁËÒ»¸ö±£´æÓÚvRealize Operations for Horizon AdapterÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2020-3943)¡£Îó²îÔµ¹ÊÔÓÉÊÇvRealize Operations for Horizon AdapterʹÓÃÁËûÓÐÇå¾²ÉèÖõÄJMX RMI·þÎñ¡£µ¼ÖÂδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýÍøÂç»á¼ûÔÚvRealize OperationsÖÐÖ´ÐÐí§Òâ´úÂë¡£
¡¾²Î¿¼Á´½Ó¡¿
http://blog.nsfocus.net/cve-2020-3943/
4. ÐÂÍøÂç¹¥»÷Ô˶¯Ê¹ÓÓ¹Ú×´²¡¶¾”Èö²¥¶ñÒâÈí¼þ
¡¾¸ÅÊö¡¿
ǰÆÚÓй¥»÷ÕßʹÓÃÒÔ“¹Ú×´²¡¶¾”ΪÖ÷ÌâµÄ´¹ÂÚÓʼþ·Ö·¢EmotetľÂíµÄ¹¥»÷Ô˶¯£¬¿ËÈÕÓÖ·¢Ã÷Ò»¸öÃûΪCoronaVirusSafetyMeasures.pdfµÄ¿ÉÒÉÎļþ£¬¸ÃÎļþ°üÀ¨µÄ¶ñÒâ´úÂë¿É¼àÊÓÓû§°´¼ü¡¢ÍøÂçÓû§µÄÃô¸ÐÐÅÏ¢µÈ£¬²¢½«ÆäËùÓÐÕ½ÀûÆ··¢Ë͵½Ö¸¶¨Ô¶³ÌÏÂÁîÓë¿ØÖÆ·þÎñÆ÷ÉÏ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://blog.yoroi.company/research/new-cyber-attack-campaign-leverages-the-covid-19-infodemic/
5. CerberusľÂíа汾¿ÉÇÔÈ¡Google AuthenticatorÓ¦ÓôúÂë²¢ÈÆ¹ý2FA
¡¾¸ÅÊö¡¿
а汾µÄCerberus°²×¿ÒøÐÐľÂí¿ÉÇÔÈ¡Google AuthenticatorÓ¦ÓÃÌìÉúµÄÒ»´ÎÐÔ´úÂ룬²¢Èƹý2FA±£»¤µÄÕ˺ţ¬¸ÃľÂíÖ÷ÒªÕë¶ÔÒøÐÐÓû§£¬ÓÚ2019Äê8ÔÂÊ״α»·¢Ã÷£¬¿ÉʵÏÖÁýÕÖ¹¥»÷¡¢×èµ²SMSÐÂÎÅ¡¢»á¼ûÁªÏµÈËÁбíµÈ¹¦Ð§¡£Google AuthenticatorÊÇÒ»ÖÖÒÆ¶¯Ó¦ÓóÌÐò£¬ÓÃÓÚÐí¶àÔÚÏßÕÊ»§µÄË«ÒòËØÉí·ÝÑéÖ¤£¨2FA£©²ã¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.threatfabric.com/blogs/2020_year_of_the_rat.html
6. KrookÎó²îÓ°ÏìÊýÊ®ÒŲ́WiFi×°±¸
¡¾¸ÅÊö¡¿
Ñо¿Ö°Ô±ÔÚWi-FiоƬÖз¢Ã÷ÁËÒ»¸öÒÔǰδ֪µÄÎó²î£¬²¢½«ÆäÃüÃûΪKr00k£¬¸ÃÎó²îCVE-2019-15126¿ÉʹÒ×Êܹ¥»÷×°±¸Ê¹ÓÃÈ«Áã¼ÓÃÜÃÜÔ¿À´¼ÓÃÜÓû§Í¨Ñ¶µÄÒ»²¿·Ö£¬ÕâÈù¥»÷Õß¿ÉÇáËɽâÃÜ´«ÊäÖеÄһЩÎÞÏßÍøÂçÊý¾Ý°ü¡£KrookÎó²î»áÓ°ÏìʹÓÃBroadcomºÍCypressµÄWi-FiоƬµÄ×°±¸£¬ÕâÁ½ÀàоƬÊÇÏÖÔÚÖ§³ÖWi-FiµÄ×°±¸£¨ÀýÈçÖÇÄÜÊÖ»ú¡¢Æ½°åµçÄÔ¡¢Ìõ¼Ç±¾µçÄÔºÍIoTС¹¤¾ß£©ÖÐʹÓõÄ×î³£¼ûµÄоƬ¡£
¡¾²Î¿¼Á´½Ó¡¿
https://www.welivesecurity.com/2020/02/26/krook-serious-vulnerability-affected-encryption-billion-wifi-devices/
https://www.welivesecurity.com/wp-content/uploads/2020/02/ESET_Kr00k.pdf
7. ObliqueRATľÂíÕë¶Ô¶«ÄÏÑÇ×éÖ¯
¡¾¸ÅÊö¡¿
½üÆÚÒ»Æð¶ñÒâÈí¼þÔ˶¯Ê¹ÓöñÒâµÄMicrosoft OfficeÎĵµÈö²¥ObliqueRATÔ¶³Ì»á¼ûľÂí£¬¸Ã¶ñÒâÎĵµÊ¹ÓöñÒâºêÀ´×ª´ïµÚ¶þ½×¶ÎRATÓÐÓøºÔØ£¬´Ë´Î¹¥»÷Ô˶¯Õë¶Ô¶«ÄÏÑÇ×éÖ¯¡£
¡¾²Î¿¼Á´½Ó¡¿
https://blog.talosintelligence.com/2020/02/obliquerat-hits-victims-via-maldocs.html

¾ÅÓÎÀϸçÔÆ







