CrowdStrikeÐû²¼¡¶2020ÄêÈ«ÇòÍþв±¨¸æ¡·£»£»£»£»Ó¢¹úÊý¾Ýî¿Ïµ»ú¹¹¶Ô¹úÌ©º½¿Õ´¦ÒÔ50ÍòÓ¢°÷·£¿£¿£¿£¿ £¿î

Ðû²¼Ê±¼ä 2020-03-05

1.CrowdStrikeÐû²¼¡¶2020ÄêÈ«ÇòÍþв±¨¸æ¡·

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾

CrowdStrikeµÄ¡¶2020ÄêÈ«ÇòÍþв±¨¸æ¡·¶ÔÒÑÍùÒ»ÄêÖж¥¼¶ÍøÂçÍþвÇ÷ÊÆ¾ÙÐÐÁËÉîÈëÆÊÎö£¬£¬£¬£¬£¬¸Ã±¨¸æµÄÒªµã°üÀ¨£º´óÐ͹¥»÷»î¶¯£¨BGH£©Ò»Ö±Éý¼¶£¬£¬£¬£¬£¬Êê½ðÒªÇóì­ÉýÖÁÊý°ÙÍò£¬£¬£¬£¬£¬²¢ÇÒÔì³É¼«´óµÄÆÆË𣻣»£»£»ÍøÂç·¸·¨·Ö×ÓÕýÔÚʹÃô¸ÐÊý¾ÝÎäÆ÷»¯£¬£¬£¬£¬£¬ÒÔÔöÌí¶ÔÀÕË÷Èí¼þÊܺ¦ÕßµÄѹÁ¦£»£»£»£»eCrimeÉú̬ϵͳһֱÉú³¤£¬£¬£¬£¬£¬±äµÃ³ÉÊìºÍרҵ»¯Ë®Æ½Ò»Ö±Ìá¸ß£»£»£»£»ÔÚBGHÖ®Í⣬£¬£¬£¬£¬Õë¶ÔÈ«Çò½ðÈÚ»ú¹¹µÄeCrime»î¶¯ÓÐËùÔöÌí£»£»£»£»³¯ÏòÎÞ¶ñÒâÈí¼þÕ½ÂÔµÄÇ÷ÊÆÕýÔÚ¼ÓËÙ£»£»£»£»¹ú¼Ò×ÊÖúµÄÓÐÕë¶ÔÐÔµÄÈëÇֻ¼ÌÐøÕë¶Ô֪ʶ²úȨ/¾ºÕùÇ鱨£¬£¬£¬£¬£¬Ôö½øÉçÇøÄÚ²¿µÄÆÆË飬£¬£¬£¬£¬²¢ÊӲ쵽ÁËÓëÏȽøeCrime¹¥»÷ÕßµÄÏàÖú¡£¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.crowdstrike.com/resources/reports/2020-crowdstrike-global-threat-report/


2.Ó¢¹úNCSCÐû²¼ÓйØÖÇÄÜ¼à¿ØÉãÏñÍ·µÄÇå¾²Ö¸ÄÏ


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Ó¢¹ú¹ú¼ÒÍøÂçÇå¾²ÖÐÐÄ£¨NCSC£©Ðû²¼ÓйØÔõÑù׼ȷÉèÖÃÖÇÄÜÇå¾²ÉãÏñÍ·ºÍÓ¤¶ù¼àÊÓÆ÷µÄÖ¸ÄÏ£¬£¬£¬£¬£¬ÒÔ×èÖ¹Óû§Êܵ½¹¥»÷ÕߵĹ¥»÷¡£¡£¡£¡£¡£¡£¡£NCSCÌåÏÖ¡°ÖÇÄÜÉãÏñ»ú£¨ÓÃÓÚ¼àÊÓºâÓîÄÚºÍÖÜΧ»î¶¯µÄÇå¾²ÉãÏñ»úºÍÓ¤¶ù¼àÊÓÆ÷£©Í¨³£Ê¹ÓüÒÍ¥Wi-FiÅþÁ¬µ½»¥ÁªÍø£¬£¬£¬£¬£¬ÔÚÉÙÉÙÊýÇéÐÎÏ£¬£¬£¬£¬£¬Î´¾­ÊÚȨµÄ¹¥»÷Õß¿ÉÒÔ»á¼ûÖÇÄÜÉãÏñ»úµÄʵʱÁ÷»òͼÏñ£¬£¬£¬£¬£¬Õâ»áʹÄúµÄÒþ˽Êܵ½Íþв¡£¡£¡£¡£¡£¡£¡£¡±ÎªÁ˵ÖÓù´ËÀ๥»÷£¬£¬£¬£¬£¬NCSC½¨ÒéʹÓÃÇ¿Á¦µÄ¡¢»ùÓÚÃÜÂë¶ÌÓïµÄÃÜÂë¸ü¸Ä×°±¸µÄĬÈÏÃÜÂ룬£¬£¬£¬£¬¸ÃÃÜÂë¿ÉÒÔʹÓÃÓû§Äܹ»¼Ç×ŵÄÈý¸öËæ»úµ¥´Ê¹¹½¨£¬£¬£¬£¬£¬²¢ÇÒ¼á³ÖÇå¾²ÉãÏñÍ·µÄ¹Ì¼þΪ×îкͽûÓò»ÐëÒªµÄÔ¶³ÌÉó²é¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/uk-ncsc-releases-tips-on-securing-smart-security-cameras/


3.·¸·¨ÍÅ»ïMoleratsй¥»÷»î¶¯£¬£¬£¬£¬£¬Õë¶ÔÕþ¸®ºÍµçÐÅÐÐÒµ


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Palo Alto NetworksµÄUnit42ÍŶÓÔÚ2019Äê10Ôµ½2019Äê12ÔÂÊӲ쵽¶à¸öÓë·¸·¨ÍÅ»ïMoleratsÓйصĴ¹ÂÚ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßµÄÄ¿µÄº­¸ÇÕþ¸®¡¢µçÐÅ¡¢°ü¹ÜºÍÁãÊÛÐÐÒµ£¬£¬£¬£¬£¬Éæ¼°6¸ö¹ú¼ÒµÄ8¸ö×éÖ¯¡£¡£¡£¡£¡£¡£¡£ËùÓÐÕâЩ¹¥»÷¶¼Éæ¼°µ½Ê¹Óô¹ÂÚÓʼþת´ï¶ñÒâÎĵµ£¬£¬£¬£¬£¬²¢Ê¹ÓÃÉç½»¹¤³ÌÊÖÒÕÒªÇóÊÕ¼þÈËÖ´ÐÐijЩ²Ù×÷£¬£¬£¬£¬£¬ÀýÈçÆôÓúê»òµã»÷Á´½ÓµÈ¡£¡£¡£¡£¡£¡£¡£´ó´ó¶¼´ËÀ๥»÷ÖеÄÓÐÓøºÔØÊÇSparkºóÃÅ£¬£¬£¬£¬£¬¸ÃºóÃÅÔÊÐí¹¥»÷ÕßÔÚÊÜѬȾµÄϵͳÉÏ·­¿ªÓ¦ÓóÌÐò²¢ÔËÐÐÏÂÁî¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/molerats-delivers-spark-backdoor/


4.Ó¢¹úÊý¾Ýî¿Ïµ»ú¹¹¶Ô¹úÌ©º½¿Õ´¦ÒÔ50ÍòÓ¢°÷·£¿£¿£¿£¿ £¿î


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Ó¢¹úÐÅϢרԱ°ì¹«ÊÒÒò2018Äê940ÍòÂÿÍÊý¾Ýй¶ÊÂÎñ¶Ô¹úÌ©º½¿Õ¹«Ë¾´¦ÒÔ50ÍòÓ¢°÷µÄ·£¿£¿£¿£¿ £¿î¡£¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷ÒÉËÆ±¬·¢ÔÚ2018Äê3Ô·Ý£¬£¬£¬£¬£¬²¢ÓÚ5Ô·ݻñµÃÈ·ÈÏ£¬£¬£¬£¬£¬Æäʱ¹úÌ©º½¿ÕµÄÊý¾Ý¿âÔâµ½Á˱©Á¦ÆÆ½â¹¥»÷¡£¡£¡£¡£¡£¡£¡£ICOÊÓ²ì³Æ¹úÌ©µÄϵͳÊܵ½ÁËÊý¾ÝÍøÂçÀà¶ñÒâÈí¼þµÄÓ°Ï죬£¬£¬£¬£¬²¢·¢Ã÷¹úÌ©ÔÚÇå¾²ÐÔ·½ÃæµÄһЩȱ·¦£¬£¬£¬£¬£¬°üÀ¨²»ÊÜÃÜÂë±£»£»£»£»¤µÄ±¸·ÝÎļþ¡¢Î´´ò²¹¶¡µÄWebЧÀÍÆ÷¡¢ÒѹýʱµÄ²Ù×÷ϵͳºÍȱ·¦·À²¡¶¾±£»£»£»£»¤µÈ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.theregister.co.uk/2020/03/04/ico_fines_cathay_pacific_500000/


5.¹È¸èÐû²¼3ÔÂAndroidÇå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´70¶à¸öÎó²î


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


¹È¸èÐû²¼2020Äê3ÔÂAndroidÇå¾²¸üУ¬£¬£¬£¬£¬¹²ÐÞ¸´70¶à¸öÎó²î£¬£¬£¬£¬£¬ÆäÖÐ×îÑÏÖØµÄÎó²îÊÇýÌå¿ò¼Ü×é¼þÖеĴúÂëÖ´ÐÐÎó²î£¨CVE-2020-0032£©£¬£¬£¬£¬£¬¸ÃÎó²î¿ÉÄÜʹԶ³Ì¹¥»÷ÕßʹÓöñÒâÎļþÔÚÌØÈ¨Àú³ÌµÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬¸ÃÎó²îÓ°ÏìÁËÔËÐÐAndroid 8.0¡¢8.1¡¢9ºÍ10°æ±¾µÄ×°±¸¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬¹È¸è»¹ÐÞ¸´ÁËýÌå¿ò¼ÜÖеÄÁíÍâÁ½¸öÑÏÖØÎó²î£¬£¬£¬£¬£¬°üÀ¨ÌØÈ¨ÌáÉýÎó²î£¨CVE-2020-0033£©ºÍÐÅϢй¶Îó²î£¨CVE-2020-0034£©¡£¡£¡£¡£¡£¡£¡£´Ë´Î¸üÐÂÐÞ¸´Á˸ßͨ±ÕÔ´×é¼þÖеÄ40¸öÎó²î£¬£¬£¬£¬£¬ÆäÖÐ16¸ö±»ÆÀΪÑÏÖØ¼¶±ð¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/98901/mobile-2/googles-march-2020-security-updates-android.html


6.¼ÎÄ껪ÓÎÂÖ¼¯ÍÅÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬¿Í»§Êý¾Ý¿ÉÄÜй¶


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


È«Çò×î´óµÄÓÎÂÖÔËÓªÉ̼ÎÄ껪ÓÎÂÖ¼¯ÍÅ£¨Carnival Corporation£¦plc£©ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬¿Í»§Êý¾Ý¿ÉÄÜй¶¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤¸Ã¹«Ë¾µÄת´ï£¬£¬£¬£¬£¬ÔÚ2019Äê4ÔÂ11ÈÕÖÁ7ÔÂ23ÈÕÖ®¼äδ¾­ÊÚȨµÄ¹¥»÷Õß»á¼ûÁËijЩ°üÀ¨¿Í»§ÐÅÏ¢µÄÔ±¹¤ÓÊÏäÕË»§£¬£¬£¬£¬£¬¿ÉÄÜй¶µÄÐÅÏ¢°üÀ¨¿Í»§µÄÐÕÃû¡¢µØµã¡¢Éç»áÇå¾²ºÅÂë¡¢Õþ¸®Ê¶ÓÖÃûÂ루ÀýÈ绤ÕÕID»ò¼ÝÕÕID£©¡¢ÐÅÓÿ¨ºÍÒøÐÐÕË»§ÐÅÏ¢ÒÔ¼°Ó뿵½¡×´Ì¬Ïà¹ØµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¼ÎÄ껪»¹³ÆÄ¿½ñûÓÐÖ¤¾ÝÅú×¢ÊÂÎñ±¬·¢ºóÊÜÓ°Ïì¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢±»ÀÄÓᣡ£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/carnival-cruise-line-operator-discloses-potential-data-breach/