Palo Alto NetworksÐû²¼2020Äê´º¼¾ÔÆÍþв±¨¸æ£»£»£»£»ÒÔÉ«ÁÐÕþµ³Ñ¡¾ÙÓ¦ÓÃй¶Áè¼Ý640Íò¹«ÃñÊý¾Ý

Ðû²¼Ê±¼ä 2020-02-10

1.Palo Alto NetworksÐû²¼2020Äê´º¼¾ÔÆÍþв±¨¸æ


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Palo Alto NetworksµÄUnit 42¿ËÈÕÐû²¼Á˰ëÄêÒ»´ÎµÄ¡¶ÔÆÍþв±¨¸æ¡·2020Äê´º¼¾°æ¡£¡£¡£¡£¡£ÎªÁËÔÚÔÆÖÐÔ½À´Ô½¶àµØ×Ô¶¯»¯¹¹½¨Á÷³Ì£¬£¬£¬£¬Ðí¶à×éÖ¯¶¼ÔÚ½ÓÄÉ»ù´¡¼Ü¹¹¼´´úÂ루IaC£©À´×ÊÖú¼ò»¯ÆäÔËÓª¡£¡£¡£¡£¡£Unit 42ÆÊÎöÁ˳ÉǧÉÏÍò¸öIaCÄ£°å£¬£¬£¬£¬ËûÃǵķ¢Ã÷Åú×¢IaCÄ£°åÖÐÓÐ199000¶à¸öDZÔÚÎó²î£¬£¬£¬£¬×îÖ÷ÒªµÄÊÇÏÖÔÚÓÐÁè¼Ý43£¥µÄÔÆÊý¾Ý¿âδ¼ÓÃÜ£¬£¬£¬£¬²¢ÇÒÖ»ÓÐ60£¥µÄÔÆ´æ´¢Ð§ÀÍÒÑÆôÓÃÈÕÖ¾¼Í¼¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://start.paloaltonetworks.com/unit-42-cloud-threat-report


2.Êý¾ÝÅú×¢2019ÄêÓÐ4000ÍòÃÀ¹úÈ˵ÄÒ½ÁÆÊý¾Ýй¶


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ƾ֤Fortified Health SecurityµÄ¡¶2020ÄêÒ½ÁƱ£½¡ÍøÂçÇ徲״̬±¨¸æ¡·£¬£¬£¬£¬2019ÄêÓÐ4000ÍòÃÀ¹úÈËÊܵ½Ò½ÁÆÊý¾Ýй¶µÄÓ°Ïì¨CÓë2018ÄêµÄ1400ÍòÏà±ÈÔöÌíÁË65£¥¡£¡£¡£¡£¡£¸Ã±¨¸æ»ã×ÜÁË2009ÄêÖÁ2019ÄêµÄÄê¶ÈÊý¾Ý£¬£¬£¬£¬·¢Ã÷2019ÄêÊÇ×Ô2015ÄêÒÔÀ´µÄ×î¸ß¼Í¼¡£¡£¡£¡£¡£¸Ã±¨¸æ³ÆÓÐ400¶à¸öÒ½ÁÆ»ú¹¹ÓÐÊ·ÒÔÀ´µÚÒ»´Î±¨¸æÔÚÒ»ÄêÄÚй¶ÁË500¸ö»¼ÕßÒÔÉϵÄÒ½ÁƼͼ¡£¡£¡£¡£¡£±¨¸æÖ¸³öÖ»¹ÜÐí¶àÆóÒµ×ö³öÁËÒ»Á¬µÄÆð¾¢ÒÔ¾ÙÐÐˢУ¬£¬£¬£¬µ«ÓÉÓÚÔ¤ËãÓÐÏÞ¡¢ÈËÁ¦×ÊԴȱ·¦ºÍ¾¯±¨¹ý¶àµÄÌôÕ½£¬£¬£¬£¬ËûÃÇÈÔÈ»ÄÑÒÔÔÚÍøÂç·¸·¨·Ö×ÓÑÛǰ¼á³ÖÁìÏÈְλ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securitymagazine.com/articles/91679-million-americans-affected-by-health-data-breaches-in-2019


3.Wacom»æÍ¼°å±»·¢Ã÷¸ú×ÙÓû§·­¿ªµÄÓ¦ÓÃÐÅÏ¢


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Èí¼þ¹¤³ÌʦÂÞ²®ÌØ¡¤Ï£¶Ù£¨Robert Heaton£©·¢Ã÷Wacom»æÍ¼°å¸ú×ÙÓû§·­¿ªµÄÿһ¸öÓ¦ÓóÌÐò£¬£¬£¬£¬ÒÉÇÖÕ¼Óû§Òþ˽¡£¡£¡£¡£¡£WacomµÄ¹Ù·½Çý¶¯³ÌÐòÒþ˽սÂÔ½ÏΪģºý£¬£¬£¬£¬ÈôÊÇÓû§½ÓÊܸÃÕ½ÂÔ£¬£¬£¬£¬Ëü½«×îÏȸú×ÙÓû§ÔÚÆä×°±¸ÉÏ·­¿ªµÄÓ¦ÓóÌÐò¡£¡£¡£¡£¡£Æ¾Ö¤HeatonµÄÊӲ죬£¬£¬£¬ËùÓÐÊý¾Ý¶¼ÊÇʹÓÃGoogle Analytics£¨ÆÊÎö£©ÕÊ»§ÍøÂçµÄ¡£¡£¡£¡£¡£ºÃÐÂÎÅÊǸÃÒþ˽սÂÔ²»ÊÇÇ¿ÖÆÐԵ쬣¬£¬£¬WacomÓû§¿ÉÒԾܾø½ÓÊܸÃÕ½ÂÔ£¬£¬£¬£¬²¢ÇÒÇý¶¯³ÌÐòÈÔ»á×°Öᣡ£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ÒѾ­×°ÖÃÁËÇý¶¯³ÌÐòµÄÓû§¿ÉÒÔËæÊ±Ñ¡ÔñÍ˳ö¸ÃÕ½ÂÔ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/wacom-drawing-tablets-track-every-app-you-open/


4.AnubisľÂíÕë¶Ô250¶à¸öAndroidÓ¦Ó㬣¬£¬£¬¿ÉÐ®ÖÆÓû§×°±¸


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


CofenseÑо¿Ö°Ô±Marcel Feller·¢Ã÷Ò»¸öеĴ¹ÂÚ¹¥»÷»î¶¯£¬£¬£¬£¬¹¥»÷ÕßÖ÷Òª·Ö·¢ÒøÐÐľÂíAnubis£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ¿ÉÒÔÍêÈ«Ð®ÖÆAndroidÒÆ¶¯×°±¸ÒÔÇÔÈ¡Óû§Æ¾Ö¤¡¢×°ÖüüÅ̼ͼ³ÌÐòÉõÖÁÉúÑÄ×°±¸Êý¾ÝÒÔÀÕË÷Êê½ð¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏָöñÒâÈí¼þÕë¶Ô250¶à¸öAndroidÓ¦ÓóÌÐò£¬£¬£¬£¬°üÀ¨¾ßÓж¨ÖƵĵǼÁýÕÖÆÁÄ»£¨ÓÃÓÚ²¶»ñÊäÈëµ½Ó¦ÓóÌÐòÖÐµÄÆ¾Ö¤£©¡£¡£¡£¡£¡£¶ñÒâÈí¼þÖ÷Ҫͨ¹ýµä·¶µÄ´¹ÂÚÓʼþ·Ö·¢£¬£¬£¬£¬ÓʼþÖÐÒªÇóÓû§ÏÂÔØ·¢Æ±£¬£¬£¬£¬µ«ÏÖʵÉÏ»áÏÂÔØÒ»¸öAPKÎļþ£¨Fattura002873.apk£©£¬£¬£¬£¬¸ÃÎļþ»áÏÔʾÐéαµÄGoogle Play Protect£¬£¬£¬£¬ÎªÓ¦ÓóÌÐòÌṩËùÐèµÄËùÓÐȨÏÞͬʱ½ûÓÃÁËÏÖʵµÄGoogle Play Protect¹¦Ð§¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/phishing-campaign-targets-250-android-apps-with-anubis-malware/152666/


5.EmotetÈ䳿ÈëÇÖÖÜΧµÄWi-FiÍøÂçÒÔÈö²¥¸øÐµÄÊܺ¦Õß


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Binary DefenseµÄÑо¿Ö°Ô±³Æ£¬£¬£¬£¬×î½ü·¢Ã÷µÄEmotet±äÖÖ¾ßÓÐÒ»¸öWi-FiÈ䳿Ä£¿£¿£¿£¿£¿é£¬£¬£¬£¬¸ÃÄ£¿£¿£¿£¿£¿éÔÊÐíEmotetÈëÇÖÖÜΧµÄWi-FiÍøÂçÒÔÈö²¥¸øÐÂÊܺ¦Õß¡£¡£¡£¡£¡£¸Ã±äÖÖͨ¹ýʹÓÃwlanAPI.dllŲÓÃÀ´·¢Ã÷ÒÑѬȾÅÌËã»úÖÜΧµÄÎÞÏßÍøÂ磬£¬£¬£¬²¢ÊµÑéͨ¹ý±©Á¦ÆÆ½â·½·¨ÈëÇÖ¡£¡£¡£¡£¡£Ò»µ©ÀÖ³ÉÅþÁ¬µ½ÁíÒ»¸öÎÞÏßÍøÂ磬£¬£¬£¬¸ÃÈ䳿½«×îÏȲéÕÒ¾ßÓзÇÒþ²Ø¹²ÏíÎļþ¼ÐµÄÆäËûWindows×°±¸£¬£¬£¬£¬½ÓÏÂÀ´Ëü½«É¨ÃèÕâЩÉè±¹ØÁ¬ÄËùÓÐÕÊ»§£¬£¬£¬£¬²¢ÊµÑéÕë¶ÔÖÎÀíÔ±ÕÊ»§ºÍËùÓÐÆäËüÓû§ÕË»§¾ÙÐб©Á¦¹¥»÷£¬£¬£¬£¬ÀֳɺóÒÔservice.exe¶þ½øÖÆÎļþµÄÐÎʽ½«¶ñÒâpayloadÊͷŵ½Êܺ¦ÕßµÄÅÌËã»úÉÏ£¬£¬£¬£¬²¢×°ÖÃÃûΪ¡°Windows DefenderϵͳЧÀÍ¡±µÄÐÂЧÀÍÒÔÔÚϵͳÉϼá³Ö³¤ÆÚÐÔ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/emotet-hacks-nearby-wi-fi-networks-to-spread-to-new-victims/


6.ÒÔÉ«ÁÐÕþµ³Ñ¡¾ÙÓ¦ÓÃй¶Áè¼Ý640Íò¹«ÃñÊý¾Ý


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Ñо¿Ö°Ô±·¢Ã÷Elector SoftwareΪÒÔÉ«ÁÐÕþµ³Likud¿ª·¢µÄÑ¡¾ÙÓ¦ÓÃElector±£´æAPIÉèÖùýʧ£¬£¬£¬£¬µ¼ÖÂÁè¼Ý640Íò¹«ÃñÊý¾Ýй¶¡£¡£¡£¡£¡£LikudÊÇÓɸùúÏÖÈÎ×ÜÀí±¾½ÜÃ÷¡¤ÄÚËþÄáÑǺú£¨Benjamin Netanyahu£©Ïòµ¼µÄÕþµ³¡£¡£¡£¡£¡£¸ÃÊÂÎñÊÇÓÉÑо¿Ö°Ô±Ran Bar-Zik¶ÔElector¾ÙÐÐÉó¼ÆÊ±·¢Ã÷µÄ£¬£¬£¬£¬ÏÖÔÚÉв»ÇåÎú̻¶µÄЧÀÍÆ÷ºÍÊý¾ÝÊÇ·ñÒѱ»Î´ÊÚȨ»á¼û¡£¡£¡£¡£¡£Bar-ZikÌåÏÖ¸ÃÍøÕ¾µÄ¿ª·¢Ö°Ô±½«API̻¶ÔÚÍøÉÏ£¬£¬£¬£¬²¢ÇÒûÓÐÃÜÂë±£»£»£»£»¤£¬£¬£¬£¬Ê¹µÃÈκÎÈ˶¼¿ÉÒÔÅÌÎÊÊý¾Ý¿âÖеĹ«ÃñÊý¾Ý£¬£¬£¬£¬°üÀ¨ÐÕÃû¡¢µç»°ºÅÂë¡¢Éí·ÝÖ¤ºÅÂë¡¢¼Òͥסַ¡¢ÐÔ±ð¡¢ÄêËêºÍÕþÖÎÆ«ºÃµÈÐÅÏ¢£¬£¬£¬£¬¸ÃAPI»¹¿ÉÒÔ·µ»ØÕ¾µãÖÎÀíÔ±µÄÏêϸÐÅÏ¢£¬£¬£¬£¬°üÀ¨Ã÷ÎÄÃÜÂë¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/netanyahus-party-exposes-data-on-over-6-4-million-israelis/