2020ÄêQ2 DDoS¹¥»÷µÄ´ÎÊý±ÈÈ¥Äêͬ±ÈÔö³¤570£¥£»£»£»£»£»£»£»ÐµĹ¥»÷ý½é¿ÉÀûÓÃCitrix Workspace·ì϶ִÐÐËÁÒâ´úÂë
°ä²¼¹¦·ò 2020-09-241.2020ÄêQ2 DDoS¹¥»÷µÄ´ÎÊý±ÈÈ¥Äêͬ±ÈÔö³¤570£¥

ƾ¾ÝNexusguard»ã±¨£¬£¬£¬£¬£¬£¬£¬£¬DDoS¹¥»÷µÄ´ÎÊýÓëÈ¥ÄêͬÆÚÏà±ÈÔö³¤ÁË570£¥¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßѡȡÁ˸ü¾«ÃܵĹ¥»÷·½Ê½£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ·¢Æð¸÷Àà·Å´óºÍ»ùÓÚUDPµÄ¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÓÃÁ÷Á¿¸²Ã»Ö¸±êÍøÂ磬£¬£¬£¬£¬£¬£¬£¬ÕâʹCSPºÜÄÑͨ¹ý´«Í³µÄ»ùÓÚãÐÖµµÄ²½Öè½øÐмì²â»ººÍ½â¡£¡£¡£¡£¡£¡£¡£Nexusguard»¹·¢ÏÖÁËÒ»ÖÖеÄÇ÷Ïò£¬£¬£¬£¬£¬£¬£¬£¬¼´¹¥»÷Õßѡȡ»ìºÏ¹¥»÷ý½éÀ´ÌáÒé¸ü¿í·ºµÄ»ùÓÚUDPµÄ¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Ö÷ÕÅÊÇÌá¸ßCSP¼ì²âºÍ·Ö±æ¶ñÒâÁ÷Á¿ÓëºÏ·¨Á÷Á¿µÄÄѶȡ£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2020/09/23/bit-and-piece-ddos-attacks-increased-570-in-q2-2020/
2.Kenna Security°ä²¼Óйضà¸öÐÐÒµµÄ·ì϶ÖÎÀí»ã±¨

ÍøÂ簲ȫ¹«Ë¾Kenna Security°ä²¼ÁËÒ»·ÝÓйؽðÈÚ¡¢Ôì×÷Òµ¡¢Ò½Áƺͼ¼ÊõÐÐÒµ½øÐеķì϶ÖÎÀíµÄ»ã±¨¡£¡£¡£¡£¡£¡£¡£Kenna Security°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬ÓëÆäËûÐÐÒµÏà±È£¬£¬£¬£¬£¬£¬£¬£¬Ôì×÷Òµ¹«Ë¾ÍùÍù±ØÒªÁ½±¶µÄ¹¦·òÀ´½¨¸´·ì϶£¬£¬£¬£¬£¬£¬£¬£¬µ«ÊÇÆäÖ»ÓÐ5£¥µÄ·ì϶ÊǸ߷çÏյġ£¡£¡£¡£¡£¡£¡£Ïà±È֮ϣ¬£¬£¬£¬£¬£¬£¬£¬¼¼Êõ¹«Ë¾µÄ·ì϶ÍùÍù½ÏÉÙ£¬£¬£¬£¬£¬£¬£¬£¬²¹¶¡ÖÎÀíµÄËÙ¶Èͨ³£¸ü¿ì¡£¡£¡£¡£¡£¡£¡£¶øÒ½ÁÆÐÐҵʱʱÔâµ½ÖîÈçÀÕË÷Èí¼þÔÚÄڵĹ¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ¹¥»÷ÕßóÆÐÅËûÃǻḶǮ£¬£¬£¬£¬£¬£¬£¬£¬¶ø²»ÊǰÑÐÔÃüÖÃÓÚΣÏÕÖ®ÖÓ×£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/healthcare-lags-behind-in-vulnerability-management-banks-are-holding-their-ground/
3.ÐµĹ¥»÷ý½é¿ÉÀûÓÃCitrix Workspace·ì϶ִÐÐËÁÒâ´úÂë

×êÑÐÈËÔ±·¢´Ë¿Ì7ÔÂÒѱ»½¨¸´µÄCitrix Workspace·ì϶£¨CVE-2020-8207£©ÓµÓÐеĸ¨Öú¹¥»÷ý½é£¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿Í¿ÉÀûÓÃÆäÌáÉýȨÏÞ²¢ÔÚSYSTEMÕÊ»§ÏÂÔ¶³ÌÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶´æÔÚÓÚCitrix¹¤×÷ÇøÀûÓ÷¨Ê½µÄ×Ô¶¯¸üзþÎñÖУ¬£¬£¬£¬£¬£¬£¬£¬µ±ÆôÓÃWindowsÎļþ¹²Ïí(SMB)ʱ£¬£¬£¬£¬£¬£¬£¬£¬Æä¿É±»ÓÃÀ´ÌáȨÒÔ¼°Ô¶ÈëÇÖÖ¸±êÍÆËã»ú¡£¡£¡£¡£¡£¡£¡£Pen Test Partners×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬£¬×î½üÓкڿÍͨ¹ýCitrixÊðÃûµÄMSI×°Ö÷¨Ê½£¨Windows InstallerÈí¼þ°ü£©À´ÀûÓô˷ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ½øÐÐËÁÒâ´úÂëÖ´ÐÓ×£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/citrix-workspace-new-attack/159459/
4.Mozilla°ä²¼Firefox°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´¶à¸öÑϳÁµÄ·ì϶

Mozilla°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬£¬£¬½¨¸´ÁËFirefox 81ºÍFirefox ESR 78.3µÄÖеĶà¸öÑϳÁµÄ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐһЩ¿É±»ÓÃÀ´Ö´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£Ô̺¬ä¯ÀÀÆ÷µÄÄڴ氲ȫ±£»£»£»£»£»£»£»¤·ì϶£¨CVE-2020-15674ºÍCVE-2020-15673£©£¬£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÖîÈ绺³åÇøÒç³öÖ®ÀàµÄÄÚ´æ½Ó¼ûÎÊÌ⣬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°Firefox 81µÄµÄWebͼÐο⣨WebGL£©ÖеĿªÊͺóʹÓ÷ì϶£¨CVE-2020-15675£©£¬£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÄÚ´æ°Ü»µºÍDZÔڵĿÉÀûÓñÀÀ£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬Firefox 81»¹½¨¸´ÁËÏÂÔØÔ´ºýŪ·ì϶£¨CVE-2020-15677£©¡¢¿çÕ¾µã¾ç±¾·ì϶£¨CVE-2020-15676£©ºÍ¿ªÊͺóʹÓ÷ì϶£¨CVE-2020-15678£©¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/firefox-81-release-bugs/159435/
5.ºÚ¿Í×éÖ¯APT28ʹÓÃαÔìµÄ±±Ô¼ÅàѵÎĵµ·Ö·¢¶ñÒâÈí¼þ

×êÑÐÈËÔ±·¢ÏÖ¶íÂÞ˹ºÚ¿Í×éÖ¯APT28ÓÃαÔìµÄ±±Ô¼ÅàѵÎĵµ£¬£¬£¬£¬£¬£¬£¬£¬Õë¶Ôµ±¾Ö»ú¹¹·Ö·¢¶ñÒâÈí¼þZebrocy¡£¡£¡£¡£¡£¡£¡£APT28·Ö·¢µÄ¶ñÒâÎļþµÄ±êÌâΪCourse 5¨C16 October 10.2020.zipx£¬£¬£¬£¬£¬£¬£¬£¬¿´ÆðÀ´Ö»ÊÇÒ»¸öÔ̺¬¿Î³Ì×ÊÁϵÄZIP°ü¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÔÚ¶ÔÆä½øÐзÖÎöʱ·¢ÏÖ£¬£¬£¬£¬£¬£¬£¬£¬ÆäʹÓÃÁËÀàËÆÓÚÈÆ¹ýµç×ÓÓʼþÍø¹ØµÄ¼¼ÊõÀ´ÈƹýAVs»òÆäËû¹ýÂËϵͳ£¬£¬£¬£¬£¬£¬£¬£¬Ê¹µÃÆä¼ì²âÂʼ«¶ÈµÍ£¬£¬£¬£¬£¬£¬£¬£¬Ö»ÓÐ3/61¡£¡£¡£¡£¡£¡£¡£QuoIntelligenceÒÉ»óÕâ¿î¶ñÒâÈí¼þµÄÖ¸±êÊǰ¢Èû°Ý½®µ±¾Ö»ú¹¹
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/russian-hackers-use-fake-nato-training-docs-to-breach-govt-networks/
6.ÀÕË÷Èí¼þAgeLockerÕë¶ÔQNAP NASÉ豸ÇÔÈ¡Êý¾Ý

×Ô8ÔÂµ×ÆðÍ·£¬£¬£¬£¬£¬£¬£¬£¬ÀÕË÷Èí¼þAgeLockerÕë¶ÔÈ«ÇòQNAP NASÉ豸ÌáÒé¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÇÔÈ¡Êý¾Ý¡£¡£¡£¡£¡£¡£¡£AgeLockerΪ2020Äê7ÔÂÆðÍ·»îÔ¾µÄеÄÀÕË÷Èí¼þ£¬£¬£¬£¬£¬£¬£¬£¬ÆäÀûÓÃAge¼ÓÃÜËã·¨°ü°ìGPGÀ´¼ÓÃÜÎļþ¡£¡£¡£¡£¡£¡£¡£ÔÚ¼ÓÃÜÎļþʱ£¬£¬£¬£¬£¬£¬£¬£¬Ëü»áÔÚ¼ÓÃÜÊý¾Ýǰ¼ÓÉÏÒ»¸öÒÔURL¡°age-encryption.org¡±¿ªÍ·µÄÎı¾Í·¡£¡£¡£¡£¡£¡£¡£×Ô2020Äê8Ôµ×ÒÔÀ´£¬£¬£¬£¬£¬£¬£¬£¬ÆäÒ»ÏòÒÔ¹«¿ªÂ¶³öµÄQNAP NASÉ豸Ϊָ±ê²¢¶ÔÆäÎļþ½øÐмÓÃÜ¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°»¹ÎÞ·¨Ãâ·Ñ¸´Ô±»AgeLocker¼ÓÃܵÄÎļþ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/agelocker-ransomware-targets-qnap-nas-devices-steals-data/


¾©¹«Íø°²±¸11010802024551ºÅ