WhatsAppÅû¶ÆäÓ¦ÓÃÖеÄ6¸öÎó²î £¬ÏÖÒÑÐÞ¸´ £»°¢¸ùÍ¢ÒÆÃñ¾ÖϵͳѬȾNetwalkerµ¼Ö·þÎñÔÝÍ£4Сʱ

Ðû²¼Ê±¼ä 2020-09-07

1.WhatsAppÅû¶ÆäÓ¦ÓÃÖеÄ6¸öÎó²î £¬ÏÖÒÑÐÞ¸´



1.png


WhatsAppÅû¶ÆäÓ¦ÓÃÖб£´æµÄ6¸öÎó²î £¬ÏÖÒÑÐÞ¸´¡£´Ë´ÎÐÞ¸´µÄÎó²îÖнÏΪÑÏÖØµÄΪ¿ÍջдÈëÒç³öÎó²î£¨CVE-2020-1894£© £¬¿Éµ¼ÖÂí§Òâ´úÂëÖ´ÐÐ £¬32λװ±¸±£´æµÄдÒç³öÎó²î£¨CVE-2020-1891£©ºÍURLÑéÖ¤ÎÊÌ⣨CVE-2020-1890£© £¬¿Éµ¼ÖºڿÍÔÚûÓÐÓëÓû§½»»¥µÄÇéÐÎÏ´ӷ¢¼þÈ˵ÄURL¼ÓÔØÍ¼Ïñ¡£ÆäËûÎó²îΪÇå¾²¼ì²âÈÆ¹ýÎÊÌ⣨CVE-2020-1889µÄ£©¡¢»º³åÇøÒç³öÎó²î£¨CVE-2020-1886£©ºÍÊäÈëÑéÖ¤ÎÊÌ⣨CVE-2019-11928£©¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/107950/security/whatsapp-undisclosed-flaws.html


2.¿¨°Í˹»ùÑо¿ÏÔʾÕë¶ÔÔÚÏß½ÌÓýµÄDDoS¹¥»÷ÔöÌí350£¥


2.png


¿¨°Í˹»ùµÄ×îÐÂÑо¿ÏÔʾ £¬2019Äê1ÔÂÖÁ2020Äê6ÔÂÖ®¼ä £¬Õë¶ÔÔÚÏß½ÌÓý×ÊÔ´µÄDDoS¹¥»÷ÔöÌíÁË350£¥¡£ÔÚÈ«Çò¹æÄ£ÄÚ £¬Óë2019ÄêµÚÒ»¼¾¶ÈÏà±È £¬2020ÄêµÚÒ»¼¾¶ÈDDoS¹¥»÷µÄ×ÜÊýÔöÌíÁË80£¥ £¬ÆäÖÐÕë¶Ô½ÌÓý×ÊÔ´µÄ¹¥»÷Õ¼ÁËÔöÌíµÄºÜ´óÒ»²¿·Ö¡£¸Ã±¨¸æ»¹·¢Ã÷ £¬ÓÐ168550Ãû¿¨°Í˹»ùÓû§Ôâµ½ÁËÒÔÖÖÖÖÔÚÏßѧϰƽ̨»òÊÓÆµ¾Û»áÓ¦ÓóÌÐòΪ»Ï×ÓÈö²¥µÄÍþв £¬ÊÜÓ°ÏìµÄƽ̨°üÀ¨Moodle¡¢Zoom¡¢edX¡¢Coursera¡¢Google Meet¡¢Google ClassroomºÍBlackboard¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/ddos-attacks-on-virtual-education/


3.FBIÔÙ´ÎÐû²¼ÓйØÀÕË÷Èí¼þProLockÇÔÈ¡Êý¾ÝµÄ¾¯±¨



3.png


FBIÔÚÉÏÖÜÔÙ´ÎÐû²¼ÁËÓйØÀÕË÷Èí¼þProLockÇÔÈ¡Êý¾ÝµÄ¾¯±¨¡£FBIÏÈǰµÄ¾¯±¨ÔøÖÒÑÔ¹«Ë¾ProLockµÄ½âÃÜÆ÷ÎÞ·¨Õý³£ÊÂÇé £¬½âÃÜÀú³ÌÖÐÁè¼Ý64MBµÄÎļþ¿ÉÄÜ»áË𻵠£¬Òò´Ë½«µ¼ÖÂÊý¾Ýɥʧ¡£Æ¾Ö¤FBIµÄÊý¾Ý £¬×Ô2020Äê3ÔÂÆð £¬ÀÕË÷Èí¼þProLock±³ºóµÄ×éÖ¯Ò»Ö±ÔÚ´ÓÊܺ¦ÕßµÄ×°±¸ÖÐÍøÂçºÍй¶ÐÅÏ¢ £¬²¢Ê¹ÓÃÇÔÈ¡µÄÊý¾ÝÒªÇóÊܺ¦×éÖ¯Ö§¸¶´Ó17.5ÍòÃÀÔªµ½66ÍòÃÀÔª²»µÈµÄÊê½ð¡£µ½ÏÖÔÚΪֹ £¬ProLockÒÑÀֳɹ¥»÷ÁËÒ½ÁƱ£½¡¡¢ÐÞ½¨¡¢½ðÈÚ¡¢Ö´·¨µÈÐÐҵʵÌåºÍÃÀ¹úÕþ¸®»ú¹¹¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fbi-issues-second-alert-about-prolock-ransomware-stealing-data/


4.CISAÖÒÑÔÕë¶ÔÈ«Çò½ðÈÚºÍÉÌÒµ×éÖ¯µÄDDoS¹¥»÷Ô˶¯



4.png


ÍøÂçÇå¾²ºÍ»ù´¡¼Ü¹¹Çå¾²¾Ö£¨CISA£©ÖÒÑÔÕë¶ÔÈ«Çò½ðÈÚºÍÉÌÒµ×éÖ¯µÄDDoS¹¥»÷Ô˶¯¡£¹¥»÷Õßͨ¹ýÏòÄ¿µÄÖ÷»ú»òÍøÂç·¢ËÍÁ÷Á¿ÖÂÆäÎÞ·¨ÏìÓ¦»òÍ߽⠣¬¼´¿É×èֹĿµÄÓû§»á¼û £¬´Ó¶øÍê³ÉDoS¹¥»÷¡£ÔÚDDoS¹¥»÷ÖÐ £¬´«ÈëÁ÷Á¿À´×ÔÐí¶à²î±ðµÄȪԴ £¬Òò´ËÎÞ·¨Í¨¹ý×èÖ¹µ¥¸öȪԴÀ´×èÖ¹¹¥»÷¡£Êܺ¦×éÖ¯µÄ×ÊÔ´ºÍ·þÎñ½«ÎÞ·¨»á¼û £¬Òò´Ë»ò½«µ¼ÖÂËðʧʱ¼äºÍ¿î×Ó¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/09/04/dos-and-ddos-attacks-against-multiple-sectors


5.ÃÀ¹úº£ÎéµÂÏØÑ§ÇøÑ¬È¾SunCrypt £¬Ð¹Â¶Î´¼ÓÃܵÄÎļþ


5.png


±±¿¨ÂÞÀ´ÄÉÖݺ£ÎéµÂÏØÑ§ÇøÓÚ2020Äê8ÔÂ24ÈÕÔâµ½ÁËSunCryptÀÕË÷Èí¼þ¹¥»÷ £¬Ð¹Â¶Î´¼ÓÃܵÄÎļþ¡£´Ë´ÎÊÂÎñÖÐй¶ÁË5GBµÄµµ°¸ £¬°üÀ¨Ðí¶àÓëÑ§Çø¡¢Ñ§ÉúºÍÏÈÉúÓйصÄÃô¸ÐÎĵµºÍСÎÒ˽¼ÒÐÅÏ¢¡£±ðµÄ £¬´Ë´Î¹¥»÷»¹µ¼ÖÂѧУϵͳÖеķþÎñÆ÷¡¢»¥ÁªÍøºÍµç»°·þÎñ¹Ø±Õ¡£¾­ÊÓ²ì £¬¹¥»÷ÕßÊ×ÏȽ¨ÉèÁËÒ»¸öÒÔÊܺ¦ÕßΪÃûµÄPowerShell¾ç±¾ £¬²¢½«Æä´æ´¢ÔÚWindowsÓò¿ØÖÆÆ÷ÉÏ¡£Ö®ºó £¬ºÚ¿ÍÒþ²ØµØÇÔÈ¡ÎļþµÄͬʱ £¬½«ÀÕË÷Èí¼þ·Ö·¢µ½ÆäËû×°±¸¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/suncrypt-ransomware-shuts-down-north-carolina-school-district/


6.°¢¸ùÍ¢ÒÆÃñ¾ÖϵͳѬȾNetwalkerµ¼Ö·þÎñÔÝÍ£4Сʱ



6.png


°¢¸ùÍ¢µÄ¹Ù·½ÒÆÃñ¾ÖDirecci¨®nNacional de MigracionesÔâµ½ÁËNetwalkerÀÕË÷Èí¼þ¹¥»÷ £¬µ¼ÖÂÆä·þÎñÔÝÍ£4Сʱ¡£Í¨¹ýÆÀ¹ÀÖÐÑëÊý¾ÝÖÐÐĺÍÂþÑÜʽ·þÎñÆ÷µÄ»ù´¡½á¹¹ÇéÐÎ £¬·¢Ã÷´Ë´Î¹¥»÷Ô˶¯ÒѾ­Ó°ÏìÁËÆä»ùÓÚMS WindowsµÄϵͳÎļþÒÔ¼°Óû§ÎļþºÍ¹²ÏíÎļþ¼ÐÖб£´æµÄMicrosoft OfficeÎļþ¡£Îª±ÜÃâÀÕË÷Èí¼þѬȾÆäËû×°±¸ £¬ÒÆÃñ¾Ö¹Ø±ÕÁËÆäʹÓõÄÅÌËã»úÍøÂç £¬ÕâÒ²µ¼ÖÂÁìÍÁ¹ý¾³µãµÄ·þÎñÔÝÍ£ÁË4¸öСʱ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ransomware-attack-halts-argentinian-border-crossing-for-four-hours/