ESET·¢Ã÷ºÚ¿ÍʹÓÃαÔìµÄClubhouse·Ö·¢BlackRock£»ºÚ¿ÍÍÅ»ïSilverFishʹÓÃÊܺ¦ÕßÍøÂç¾ÙÐÐɳºÐ²âÊÔ

Ðû²¼Ê±¼ä 2021-03-22

1.ESET·¢Ã÷ºÚ¿ÍʹÓÃαÔìµÄClubhouse·Ö·¢BlackRock


1.jpg


ÉÏÖÜÎå £¬ESETµÄÑо¿Ö°Ô±·¢Ã÷ºÚ¿ÍʹÓÃαÔìµÄAndroid°æClubhouse·Ö·¢BlackRock Trojan ¡£ClubhouseÊÇÒôƵ̸ÌìÓ¦Óà £¬µ«ÏÖÔÚÖ»ÔÚiOSÊÜÆ­Ç°¿ÉÓà £¬ÉÐδÐû²¼Android°æ±¾µÄClubhouse ¡£BlackRock×î³õÓÚ2020Äê5Ô±»·¢Ã÷ £¬Ö¼ÔÚÇÔÈ¡Óû§ÔÚÖÖÖÖ»¥ÁªÍøÓ¦Óã¨Áè¼Ý458¸ö£©ÉϵÄÐÅÏ¢ ¡£¸ÃľÂíÄܹ»×èµ²ºÍ¸Ä¶¯SMSÐÂÎÅ¡¢Òþ²ØÍ¨Öª¡¢ÔÚÓû§ÔËÐÐɱ¶¾Èí¼þʱ½«ÆäÖØ¶¨Ïòµ½×°±¸Ö÷ÆÁÄ»ºÍÔ¶³ÌËø¶¨ÆÁÄ» ¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/fraudsters-jump-on-clubhouse-hype-to-push-malicious-android-app/


2.Netscout·¢Ã÷´ó×ÚDTLS·þÎñÆ÷¿ÉÓÃÓÚDDoS·Å´ó¹¥»÷


2.jpg


Çå¾²¹«Ë¾Netscout·¢Ã÷´ó×ÚDTLS·þÎñÆ÷¿ÉÓÃÓÚDDoS·Å´ó¹¥»÷ £¬·Å´ó±ÈÀýΪ37.34£º1 ¡£DTLSÊÇ´«Êä²ãÇå¾²ÐÔ£¨TLS£©Ð­Òé»ùÓÚUDPµÄ°æ±¾ £¬¿É±ÜÃâ¶ÔÑÓ³ÙÃô¸ÐµÄÓ¦ÓúͷþÎñ¾ÙÐÐÇÔÌýºÍ¸Ä¶¯ ¡£ÔçÔÚÈ¥Äê12ÔÂ·Ý £¬¾Í±£´æÊ¹ÓÃCitrix ADC×°±¸µÄDTLSµÄDDoS¹¥»÷Ô˶¯ ¡£CitrixÓÚ½ñÄêÔÚ1ÔÂÐû²¼Á˲¹¶¡³ÌÐò £¬µ«Ö±µ½ÏÖÔÚÈÔÓÐÁè¼Ý4200¶ą̀DTLS·þÎñÆ÷¿É±»ÓÃÓÚ·´ÉäºÍ·Å´óDDoS¹¥»÷ ¡£NetscoutÌåÏÖµ¥ÏòÁ¿DTLS·Å´óDDoS¹¥»÷¿É´ïÔ¼44.6 Gbps £¬¶àÏòÁ¿¹¥»÷Ôò¸ß´ïÔ¼206.9 Gbps ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ddos-booters-now-abuse-dtls-servers-to-amplify-attacks/


3.ºÚ¿ÍÍÅ»ïSilverFishʹÓÃÊܺ¦ÕßÍøÂç¾ÙÐÐɳºÐ²âÊÔ


3.jpg


ÈðÊ¿Çå¾²¹«Ë¾ProdaftÉÏÖÜËÄ³Æ £¬ÓëSolarWinds¹¥»÷ÓйصĺڿÍÍÅ»ïSilverFishʹÓÃÊܺ¦ÕßÍøÂç¾ÙÐÐɳºÐ²âÊÔ ¡£SilverFishÒѹ¥»÷ÁËÁè¼Ý4720¸öÆóÒµºÍÕþ¸®×éÖ¯ £¬°üÀ¨²Æ²ú500Ç¿ÆóÒµ¡¢Õþ¸®²¿·Ö¡¢º½¿Õ¹«Ë¾¡¢¹ú·À³Ð°üÉÌ¡¢Éó¼ÆºÍ×Éѯ¹«Ë¾ÒÔ¼°Æû³µÖÆÔìÉÌ ¡£¸ÃÍŻ↑·¢ÁËÒ»¸öÓÉÊܺ¦ÕߵķþÎñÆ÷×é³ÉµÄ¶ñÒâÈí¼þ¼ì²âɳÏä £¬¿ÉÒÔÓòî±ðµÄÆóÒµAVºÍEDR½â¾ö¼Æ»®À´²âÊÔËûÃǵÄpayload £¬ÒÔÔöÌíÆä¹¥»÷µÄÀÖ³ÉÂÊ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/solarwinds-linked-hacking-group-silverfish-abuses-enterprise-victims-in-sandbox-malware-tests/


4.WordPress²å¼þ±»±¬³ö¶à¸öÎó²î £¬¿ÉÐ®ÖÆ½üÍòÍò¸öÍøÕ¾


4.jpg


Ñо¿Ö°Ô±Åû¶ÁËWordPress²å¼þElementorºÍWP Super CacheÖеÄÎó²î £¬¿É±»ÓÃÓÚí§Òâ´úÂëÖ´ÐÐÒÔ¼°½ÓÊÜÍøÕ¾ ¡£Wordfence·¢Ã÷ElementorÔªËØÖÐûÓжÔHTML±êÇ©¾ÙÐзþÎñÆ÷¶ËÑéÖ¤ £¬Òò¶ø±£´æ¶à¸öXSSÎó²î £¬CVSSÆÀ·ÖΪ6.4 £¬¿É±»ÓÃÀ´½¨Éè¹ÜÀíÔ±ÕÊ»§»òÏòÍøÕ¾Ìí¼ÓºóÃÅ £¬Æä×°ÖÃÁ¿Áè¼Ý700Íò ¡£Patchstack·¢Ã÷×°ÖÃÁ¿Áè¼Ý200ÍòµÄWP Super CacheÖб£´æ¾­ÓÉÉí·ÝÑéÖ¤µÄÔ¶³Ì´úÂëÖ´ÐÐ(RCE)Îó²î ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/115750/hacking/wordpress-plugins-flaws.html


5.GoogleÐû²¼2020ÄêijºÚ¿Í×éÖ¯¹¥»÷Ô˶¯µÄ±¨¸æ


5.jpg


Google¡¯s Project ZeroÍŶÓÐû²¼ÁË2020ÄêijºÚ¿Í×éÖ¯¹¥»÷Ô˶¯µÄ±¨¸æ ¡£±¨¸æ·¢Ã÷ £¬¸ÃÍÅ»ïÔÚ2020Äê2ÔºÍ10ÔÂÌᳫÁËÁ½´Î¹¥»÷Ô˶¯ £¬Ê¹ÓÃÁËÖÁÉÙ11¸öÁãÈÕÎó²î ¡£ºÚ¿Íͨ¹ýһϵÁй¥»÷Ô˶¯½¨Éè¶ñÒâÍøÕ¾ £¬½«»á¼ûÕßÖØ¶¨Ïòµ½ÍйÜÁËAndroid¡¢WindowsºÍiOS×°±¸µÄ¹¥»÷Á´µÄ·þÎñÆ÷ÉÏ ¡£ÆäÖÐ £¬2Ô·ݵĹ¥»÷ʹÓÃÁËCVE-2020-6418ºÍCVE-2020-0938µÈ4¸öÎó²î £¬10Ô·ݵĹ¥»÷ʹÓÃÁËCVE-2020-15999ºÍCVE-2020-17087µÈ7¸öÎó²î ¡£


Ô­ÎÄÁ´½Ó£º

https://googleprojectzero.blogspot.com/2021/03/in-wild-series-october-2020-0-day.html


6.kasperskyÐû²¼2020ÄêStalkerware¹¥»÷Ô˶¯µÄ±¨¸æ


6.jpg


kasperskyÐû²¼ÁË2020ÄêStalkerware¹¥»÷Ô˶¯µÄ±¨¸æ ¡£Stalkerware¶ñÒâÈí¼þµÄ¹¦Ð§¸÷²»Ïàͬ £¬µ«´ó´ó¶¼¶¼¿ÉÒÔ¶ÔÊܺ¦ÕßµÄÊÖ»ú¾ÙÐÐÖÜÈ«¼à¿Ø ¡£±¨¸æÖ¸³ö £¬2018ÄêÈ«Çò½ü40000¸öÓû§Ôâµ½´ËÀà¶ñÒâÈí¼þµÄÓ°Ïì £¬2019ÄêÍ»ÆÆÁË67000 £¬2020ÄêΪ½ü54000¸öÓû§ ¡£ÊÜÓ°ÏìÓû§µÄÄê¶ÈÇúÏßÏÔʾ £¬2020Äê3ÔÂÖÁ6Ô £¬Êܺ¦ÕßµÄÊýÄ¿ÓÐËùϽµ ¡£ÔÚÈ«Çò¹æÄ£ÄÚ £¬¶íÂÞ˹¡¢°ÍÎ÷ºÍÃÀ¹úµÄStalkerwareÊýÄ¿×î¶à£»ÔÚÑÇÖÞ £¬Ó¡¶ÈµÄÎÊÌâ×îΪÑÏÖØ£»¶øÔÚÅ·ÖÞ £¬ÊÜÓ°Ïì×î´óµÄÊǵ¹ú¡¢Òâ´óÀûºÍÓ¢¹ú ¡£


Ô­ÎÄÁ´½Ó£º

https://www.kaspersky.com/blog/stalkerware-in-2020/39102/