ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ49ÖÜ
Ðû²¼Ê±¼ä 2019-12-16>±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
2019Äê12ÔÂ09ÈÕÖÁ15ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´57¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇGoogle Chrome WebAudio´úÂëÖ´ÐЩ¶´; CA Release Automation DataManagement·´ÐòÁл¯´úÂëÖ´ÐЩ¶´£»Advantech DiagAnywhere ServerÎļþ´«Êä·þÎñÕ»Òç³ö©¶´£»Micrsoft Windows Hyper-VÔ¶³Ì´úÂëÖ´ÐЩ¶´£»Adobe AcrobatºÍReader CVE-2019-16445ÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇĪ˹¿Æ¶¼Êмà¿Øϵͳ·ÃÎÊȨÏÞÔÚ°µÍø³öÊÛ£»¿ÆÂÞÀ¶àÖÝIT·þÎñÉÌCTSÔâµ½ÀÕË÷Èí¼þ¹¥»÷£»ÀÕË÷Èí¼þSnatch¿Éͨ¹ýÄþ¾²Ä£Ê½ÖØÆôÀ´Èƹýɱ¶¾Èí¼þ£»Î¢Èí¾¯¸æ·¸×ïÍÅ»ïGALLIUM¹¥»÷È«ÇòµÄµçÐŹ«Ë¾£»¶ñÒâÈí¼þKrampus-3PCÖ÷ÒªÃé×¼iphoneÓû§¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£
>ÖØÒªÄþ¾²Â©¶´Áбí
1. Google Chrome WebAudio´úÂëÖ´ÐЩ¶´
Google Chrome WebAudio´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄWEBÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂ룬ĿǰÒѾÔÚÒ°ÀûÓá£
https://chromereleases.googleblog.com/2019/10/stable-channel-update-for-desktop_31.html
2. CA Release Automation DataManagement·´ÐòÁл¯´úÂëÖ´ÐЩ¶´
CA Release Automation DataManagement service´æÔÚ·´ÐòÁл¯Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://seclists.org/bugtraq/2019/Dec/16
3. Advantech DiagAnywhere ServerÎļþ´«Êä·þÎñÕ»Òç³ö©¶´
Advantech DiagAnywhere ServerÎļþ´«Êä·þÎñ´æÔÚÕ»Òç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.auscert.org.au/bulletins/ESB-2019.4660/
4. Micrsoft Windows Hyper-VÔ¶³Ì´úÂëÖ´ÐЩ¶´
Micrsoft Windows Hyper-V´æÔÚδÃ÷Äþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1471
5. Adobe AcrobatºÍReader CVE-2019-16445ÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´
Adobe AcrobatºÍReader´¦ÖÃÄÚ´æ´æÔÚÊͷźóʹÓ鶴£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://helpx.adobe.com/security/products/acrobat/apsb19-55.html
>ÖØÒªÄþ¾²Ê¼þ×ÛÊö
1¡¢ÄªË¹¿Æ¶¼Êмà¿Øϵͳ·ÃÎÊȨÏÞÔÚ°µÍø³öÊÛ
MBKh MediaÊÓ²ì¼ÇÕßAndrey Kaganskikh·¢ÏÖĪ˹¿Æ¶¼Êмà¿ØϵͳºÍÃ沿ʶ±ðÊý¾ÝµÄ·ÃÎÊȨÏÞÕýÔÚµØÏÂÂÛ̳ºÍÁÄÌìÊÒÖгöÊÛ¡£AndreyÌåÏÖÂô·½ÊÇÖ´·¨ÈËÔ±/Õþ¸®¹ÙÔ±£¬¿ÉÒԵǼĪ˹¿Æ¶¼ÊмàÊÓϵͳµÄÊý¾Ý´¦Öúʹ洢¼¯³ÉÖÐÐÄ£¨YTKD£©¡£¹ºÖÃÁËÉãÏñͷȨÏÞµÄÓû§½«»áÊÕµ½Ö¸Ïò¶¼ÊÐCCTVϵͳµÄÒ»¸öÁ´½Ó£¬¸ÃÁ´½Ó¿É·ÃÎÊËùÓй«¹²ÉãÏñÍ·£¬Æä¿ÉÓÃʱ¼äΪ5Ìì¡£´ËÍ⣬¾ßÓÐÎÞÏÞ·ÃÎÊȨÏ޵ĵǼƾ¾Ý¼Û¸ñΪ30000¬²¼£¨470ÃÀÔª£©¡£ÊÓ²ìÈËÔ±²âÊÔÁËÆäÕÕƬ£¬Âô·½·µ»ØÁË238ÕÅͼƬ£¬ÕâЩͼƬÀ´×Ô140̨ÉãÏñÍ·£¬»¹ÁгöÁ˲¶×½µ½µÄ¾ßÌåµØÖ·ºÍʱ¼ä£¬µ«·µ»ØµÄÕÕƬ¶¼²»ÊÇÊÓ²ìÈËÔ±µÄ£¬Õâ¿ÉÄÜÓëÉãÏñÍ·µÄÊýÁ¿ºÍËã·¨Óйأ¬ÏµÍ³¶ÔÆäÃ沿ÌØÕ÷µÄÆÀ¹ÀÏàËƶÈΪ67%¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/moscow-cops-sell-access-to-city-cctv-facial-recognition-data/
2¡¢¿ÆÂÞÀ¶àÖÝIT·þÎñÉÌCTSÔâµ½ÀÕË÷Èí¼þ¹¥»÷
¿ÆÂÞÀ¶àÖÝIT·þÎñÉÌCTSÔâÀÕË÷Èí¼þ¹¥»÷£¬²¨¼°100¶à¼ÒÑÀ¿ÆÕïËù¡£CTSרΪÑÀ¿ÆÕïËùÌṩIT·þÎñ£¬°üÂÞÍøÂçÄþ¾²¡¢Êý¾Ý±¸·ÝºÍIPÓïÒôµç»°µÈ¡£¸Ã¹«Ë¾ÓÚ11ÔÂ25ÈÕÔâµ½¹¥»÷£¬µ¼ÖÂ100¶à¼ÒÑÀ¿ÆÕïËùµÄ¼ÆËã»úѬȾÁËÀÕË÷Èí¼þSodinokibi¡£CTS¾Ü¾øÁ˹¥»÷ÕßË÷Òª70ÍòÃÀÔªÊê½ðµÄÒªÇó£¬ÓÉÓÚϵͳ²»Í£Öжϣ¬Ä¿Ç°Ðí¶àÑÀ¿ÆÕïËùÈÔÈ»ÎÞ·¨Õý³£ÓªÒµ¡£
ÔÎÄÁ´½Ó£º
https://krebsonsecurity.com/2019/12/ransomware-at-colorado-it-provider-affects-100-dental-offices/
3¡¢ÀÕË÷Èí¼þSnatch¿Éͨ¹ýÄþ¾²Ä£Ê½ÖØÆôÀ´Èƹýɱ¶¾Èí¼þ
ÀÕË÷Èí¼þSnatchÕýÔÚʹÓÃÒ»ÖÖÇ°Ëùδ¼ûµÄ¼¼ÇÉÀ´Èƹýɱ¶¾Èí¼þ£¬¾ßÌåÀ´Ëµ£¬Ëü¿ÉÒÔ½«Êܺ¦ÕߵļÆËã»úÒÔÄþ¾²Ä£Ê½ÖØÐÂÆô¶¯£¬È»ºóÔËÐмÓÃܹý³Ì¡£´ó¶àÊýɱ¶¾Èí¼þ¶¼ÎÞ·¨ÔÚWindowsÄþ¾²Ä£Ê½ÏÂÆô¶¯£¬Òò´ËSnatchÄÑÒÔ±»¼ì²âµ½¡£Æ¾¾ÝSophos LabsµÄ³ÂËߣ¬¸ÃÀÕË÷Èí¼þͨ¹ýWindows×¢²á±íÏîÌí¼ÓÁËÒ»¸öÔÚÄþ¾²Ä£Ê½ÏÂÆô¶¯µÄ·þÎñ£¬¸Ã·þÎñ½«ÔËÐÐSnatch¡£Ñо¿ÈËÔ±¾¯¸æ³ÆÕâÖÖģʽ¿ÉÄܻᱻÆäËüÀÕË÷Èí¼þËùÄ£·Â¡£Snatch×Ô2018ÄêÏļ¾ÒÔÀ´Ò»Ö±»îÔ¾£¬ÆäÖ÷Òª½øÐÐÕë¶ÔÐԵĹ¥»÷¡£Óë´ó¶àÊýÀÕË÷Èí¼þ²îÒ죬Snatch»¹»áÇÔÈ¡ÊÜѬȾϵͳÉϵÄÎļþ¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/snatch-ransomware-reboots-pcs-in-windows-safe-mode-to-bypass-antivirus-apps/
4¡¢Î¢Èí¾¯¸æ·¸×ïÍÅ»ïGALLIUM¹¥»÷È«ÇòµÄµçÐŹ«Ë¾
΢ÈíÍþвÇ鱨ÖÐÐÄ£¨MSTIC£©¾¯¸æ·¸×ïÍÅ»ïGALLIUMÕýÔÚÕë¶ÔÊÀ½ç¸÷µØµÄµçÐÅ·þÎñÉ̽øÐÐÁ¬Ðø²»Í£µÄ¹¥»÷¡£¸Ã·¸×ïÍÅ»ï½øÐÐÁ˶à¸ö¹¥»÷»î¶¯£¬MSTICÊӲ쵽Õë¶Ô¶«ÄÏÑÇ¡¢Å·Ö޺ͷÇÖ޵ĵçÐÅÔËÓªÉ̵Ĺ¥»÷¡£GALLIUMÖ÷Ҫͨ¹ýδ´ò²¹¶¡µÄWildFly/JBoss·þÎñÆ÷½øÐÐÈëÇÖ£¬Ò»µ©Éø͸µ½×éÖ¯µÄÍøÂçÖУ¬GALLIUM±ã¿ªÊ¼ÀûÓÃ×Ô½ç˵µÄ¶ñÒâÈí¼þÔÚÆóÒµÍøÂçÖкáÏòÒƶ¯ºÍÊÕ¼¯Óòƾ¾Ý¡£GALLIUM»¹Ê¹ÓÃSoftEther VPNÈí¼þÀ´ÔöÇ¿¶ÔÄ¿±êÍøÂçµÄ·ÃÎʺͱ£³Ö³Ö¾ÃÐÔ¡£Æ¾¾ÝMSTICµÄ³ÂËߣ¬GALLIUMµÄTTPºÍ¸Ã×é֯ʹÓõIJ¿ÃÅÓòÓë2018ÄêµÄOperation SoftCellÏàͬ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-warns-of-gallium-threat-group-attacking-global-telcos/
5¡¢¶ñÒâÈí¼þKrampus-3PCÖ÷ÒªÃé×¼iphoneÓû§
Ò»¸öÕë¶ÔiPhoneÓû§µÄ¶ñÒâ¹ã¸æÖض¨Ïò»î¶¯ÒѾӰÏìÁË100¶à¸ö³öÊéÉÌÍøÕ¾£¬ÆäÖаüÂÞÔÚÏß±¨Ö½ÍøÕ¾ºÍ¹ú¼ÊÿÖÜÐÂÎÅÔÓÖ¾ÍøÕ¾µÈ¡£Æ¾¾ÝDSOÍŶӵÄ˵·¨£¬¸Ã¶ñÒâÈí¼þKrampus-3PCαװ³ÉÔÓ»õµêµÄ³ê±ö¹ã¸æ£¬´ÓÓû§ÄÇÀïÊÕ¼¯»á»°ºÍcookieÐÅÏ¢£¬¶øÇÒÔÚÓû§µã»÷¹ã¸æʱÖض¨ÏòÖÁÒ»¸öÊÕ¼¯¸öÈËÐÅÏ¢µÄÐé¼ÙÍøÕ¾¡£¹¥»÷ÕßÊ×ÏÈÔÚ¹ã¸æƽ̨AdtechstackÉÏͶ·Å¹ã¸æ£¬È»ºóÀûÓÃƽ̨µÄAPI²åÈë¶ñÒâ´úÂ룬ÕâЩ¶ñÒâ¹ã¸æËæºó±»·Ö·¢¸ø´óÁ¿ÍøÕ¾¡£Krampus-3PC»á½«ÊÕ¼¯µ½µÄÓû§ÐÅÏ¢·¢ËÍÖÁC2ÓòÃûboostsea2[.]com¡£Ä¿Ç°Éв»Çå³þ¹¥»÷ÕßµÄÉí·Ý¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/krampus-3pc-malware-iphone-users/151043/