Sophos½ôÆÈÐÞ¸´·À»ðǽÖеÄSQL×¢Èë0day£»ºÚ¿Í³öÊÛ»ãÒ½»ÛÓ°COVID-19 AI¸¨Öú¼ì²âÊÖÒÕµÄÔ´´úÂë

Ðû²¼Ê±¼ä 2020-04-27

1.Sophos½ôÆÈÐÞ¸´·À»ðǽÖеÄSQL×¢Èë0day £¬Òѱ»Ò°ÍâʹÓÃ


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


ÍøÂçÇå¾²¹«Ë¾SophosÓÚÖÜÁùÐû²¼Á˽ôÆÈ²¹¶¡ÒÔÐÞ¸´ÒѾ­±»Ò°ÍâʹÓõÄSQL×¢Èë0day £¬¸ÃÎó²îÓ°ÏìÁËÆäXG Firewall²úÆ· ¡£4ÔÂ22ÈÕÍí £¬Sophos¹«Ë¾·¢Ã÷ºÚ¿ÍʹÓÃXG FirewallÖеÄSQL×¢ÈëÎó²îÇÔÈ¡Á˸Ã×°±¸ÖеÄÊý¾Ý £¬°üÀ¨·À»ðǽװ±¸¹ÜÀíÔ±ÕË»§¡¢·À»ðǽÃÅ»§ÍøÕ¾¹ÜÀíÔ±ÕË»§ºÍÔ¶³Ì»á¼û×°±¸ÕË»§ÖеĵÄÓû§ÃûºÍ¹þÏ£ÃÜÂë ¡£¸Ã¹«Ë¾ÌåÏִ˴θüÐÂÒѾ­ÐÞ¸´Á˸ÃSQL×¢ÈëÎó²î £¬²¢ÇÒмÓÁËÌØÊâÌáÐѹ¦Ð§Ê¹¿Í»§ÖªµÀÆä×°±¸ÊÇ·ñÊܵ½ÁËÍþв ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hackers-are-exploiting-a-sophos-firewall-zero-day/


2.ºÚ¿Í³öÊÛ»ãÒ½»ÛÓ°COVID-19 AI¸¨Öú¼ì²âÊÖÒÕµÄÔ´´úÂë


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


Êý¾Ýй¶֪ͨ¹«Ë¾CybleÑо¿Ö°Ô±·¢Ã÷ £¬ÏÖÔÚºÚ¿ÍÕýÔÚ³öÊÛ»ãÒ½»ÛÓ°COVID-19 AI¸¨Öú¼ì²âÊÖÒÕµÄÔ´´úÂëºÍʵÑéÊý¾Ý ¡£¾ÝϤ £¬»ãÒ½»ÛÓ°ÕýÔÚÓ뻪ΪºÏ×÷ £¬¿ª·¢Ò»ÖÖ»ùÓÚAIµÄCOVID-19¼ì²âϵͳ £¬¸Ãϵͳ¿ÉÒÔ´ÓÐØ²¿CTµÄDICOMͼÏñ¼ì²âÊÇ·ñ±£´æÑ¬È¾Ö¢×´ ¡£»ãÒ½»ÛÓ°ÕýÒÔÿÔÂ50000ÃÀÔªµÄ¼ÛÇ®³öÊÛ¸Ãϵͳ ¡£¶øºÚ¿ÍÉù³ÆÆäÒÑ»ñµÃCOVID-19¼ì²âÊÖÒÕÔ´´úÂëÒÔ¼°ÑéÊý¾Ý £¬²¢ÒÔ4±ÈÌØ±ÒµÄ¼ÛÇ®ÏòÍâ³öÊÛ ¡£±»µÁÊý¾Ý°üÀ¨Óû§ÐÅÏ¢£¨1.5 MB£©¡¢ÊÖÒÕºÍÔ´´úÂ루1GB£©¡¢Covid-19ʵÑéÏà¹ØÄÚÈÝ£¨150 MB£© ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/102270/data-breach/huiying-medical-technology-data-breach.html


3.ÍþÊ¿¼ÉÅÄÂôÍøÕ¾WhiskyAuctioneer±»¹¥»÷ÖÂÅÄÂôÎÞÏÞÑÓÆÚ


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


Ó¢¹úÍþÊ¿¼ÉÅÄÂôÍøÕ¾WhiskyAuctioneerÓÚ4ÔÂ21ÈÕ22£º30Ðû²¼ÆäÔâµ½Á˶ñÒâ¹¥»÷ £¬ÅÄÂôÔ˶¯±»ÎÞÏÞÑÓÆÚ ¡£¸ÃÊÂÎñ±¬·¢ÓÚ4ÔÂ20ÈÕ £¬¾ºÅÄÔ˶¯±¾¸Ã7µã¿¢Ê £¬µ«ÓÉÓÚÍøÕ¾Òì³£ £¬Ô˶¯±»ÑÓÆÚÁË48Сʱ ¡£Ö®ºó £¬¸ÃÍøÕ¾·¢Ã÷ÆäÍøÕ¾ºÍÊý¾Ý¿âÔâµ½ÁËÓÐÕë¶ÔÐÔÇÒÖØ´óµÄ¶ñÒâ¹¥»÷ ¡£ÏÖÔÚ £¬¸ÃÍøÕ¾Ò»Ö±´¦ÓÚÍÑ»úά»¤×´Ì¬ £¬²¢ÌåÏÖÅÄÂôÔ˶¯½«»á±»ÎÞÏÞÑÓÆÚ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.theguardian.com/technology/2020/apr/25/online-auction-of-record-breaking-whisky-collection-hit-by-cyber-attack


4.ÐÂÎÄ×ÖÕ¨µ¯Ê¹ÓÃÐŵÂÓï £¬¿Éµ¼ÖÂiOSºÍmac OS×°±¸Íß½â


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


Graham Cluley·¢Ã÷ £¬×î½üгöÁËÒ»ÖÖ°üÀ¨ÐŵÂÓï×Ö·ûµÄÎÄ×ÖÕ¨µ¯ £¬Êܺ¦ÕßÉó²é°üÀ¨¸ÃÎÄ×ÖÕ¨µ¯µÄÎı¾Ê± £¬»áµ¼ÖÂiOSºÍmac OS×°±¸Í߽⠡£ÐŵÂÓïÊǰͻù˹̹ʹÓõĹٷ½ÓïÑÔÖ®Ò» £¬¿ÉÊÇmacOSºÍiOSÎÞ·¨Ê¶±ð¸ÃÓïÑÔ±àдµÄUnicode·ûºÅ £¬µ¼Ö²Ù×÷ϵͳÎÞ·¨Õý³£ÔËÐÐ ¡£¸ÃÎÊÌâ×îÔçÊÇÔÚÉÏÖÜËı»·¢Ã÷µÄ £¬±»³Æ×÷CapturetheFlag £¬²¢ÒѾ­ÔÚTwitterÉÏÈö²¥¿ªÀ´ ¡£CluleyÖ¸³ö £¬ÖØÐÂÆô¶¯×°±¸¿ÉÒÔ½â¾ö´ËÎÊÌâ ¡£Apple×°±¸ÔÚÒÑÍùÒ²ÓÐÀàËÆÎÊÌâ £¬2013Äê°¢À­²®Óï×Ö·û¡¢2018ÄêÄÏÓ¡¶ÈµÄÈË̩¬¹ÌÓï¶¼¿ÉÒÔʹMacºÍiPhoneÍ߽⠡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/apple-text-bomb-crashes-iphones-message-notifications/155144/


5.TrickBotÍÅ»ïÔÚд¹ÂÚ¹¥»÷Öзַ¢BazarBackdoorºóÃÅ


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


Ñо¿Ö°Ô±·¢Ã÷TrickBotÍÅ»ïÕýÔÚʹÓÃд¹ÂÚ¹¥»÷·Ö·¢BazarBackdoorºóÃÅ £¬ÒÔÆÆËð²¢»ñµÃÆóÒµÍøÂçµÄÍêÈ«»á¼ûȨÏÞ ¡£¹¥»÷ÕßÊ×ÏÈÒÔ¿Í»§Í¶Ëß¡¢COVID-19Ö÷ÌâÈËΪ±¨¸æµÈÐÅϢΪÓÕ¶ü £¬ÓÕʹÊܺ¦Õß·­¿ªÎ±×°³ÉWordÎĵµ¡¢Excelµç×Ó±í¸ñ»òPDFµÄºóÃżÓÔØ³ÌÐòBazaLoader ¡£Ö®ºó £¬BazarLoaderͨ¹ýEmercoinÊèɢʽDNSÆÊÎö·þÎñÀ´ÆÊÎöʹÓà bazarÓòµÄÖÖÖÖÖ÷»úÃû ¡£ÆÊÎöµ½C2 IPµØÖ·ºó £¬¼ÓÔØ³ÌÐòÊ×ÏÈÅþÁ¬µ½Ò»¸öC2²¢Ö´ÐÐ×¢²á £¬ÔÙʹÓÃÁíÒ»¸öC2ÇëÇóÏÂÔØXOR¼ÓÃܵÄBazarBackdoor £¬½¨ÉèºóÃÅ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/bazarbackdoor-trickbot-gang-s-new-stealthy-network-hacking-malware/


6.Facebook 1400¶à¸öÓû§³ÉÎªÌØ¹¤Èí¼þPegasusÄ¿µÄ


×ðÁú¿­Ê± - ÈËÉú¾ÍÊDz«!


Facebook¶ÔÒÔÉ«ÁÐNSO GroupÌáÆðËßËÏ £¬Ö¸¿ØÆäʹÓÃÌØ¹¤Èí¼þPegasusÕë¶Ô1400¶à¸öÓû§ ¡£ÊÂÎñ±¬·¢ÔÚ2019Äê´º¼¾ £¬NSO GroupʹÓÃÁËWhatsApp VoIP¹¦Ð§ÖеÄÎó²î£¨ CVE-2019-3568£©Ö²ÈëÁËÌØ¹¤Èí¼þPegasus £¬¶ÔWhatsAppÓû§ÌᳫÁËÖÁÉÙ720´Î¹¥»÷ ¡£´Ë´ÎÊÂÎñµÄÊܺ¦ÕßΪ1400¶àÃûÓû§ £¬ÆäÖаüÀ¨¼ÇÕß¡¢ÈËȨÔ˶¯¼Ò¡¢ÕþÖÎÒìÒéÈËÊ¿¡¢Íâ½»¹Ù¡¢×´Ê¦ºÍÕþ¸®¹ÙÔ± ¡£½ñÄê4Ô £¬NSO GroupÌá³öÁËÉêËß £¬ÀíÓÉÊǸù«Ë¾ÎªÍâ¹úÆóÒµ £¬¼ÓÖÝ·¨ÔºÃ»ÓÐͳÁìȨÀ´Ö÷³Ö´Ë°¸ £¬µ«FacebookÖ´·¨ÍŶÓÈ´×èµ²Õâһ˵·¨ £¬ÌåÏÖNSO Group²»Ó¦¸Ã±»¿íÃâ ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/102260/laws-and-regulations/facebook-nso-group-lawsuit.html