GALLIUM¹¥»÷È«ÇòµÄµçÐŹ«Ë¾£»£»£»ZeppelinÖ÷ÒªÕë¶ÔITºÍÒ½ÁƱ£½¡¹«Ë¾

Ðû²¼Ê±¼ä 2019-12-13


1.΢ÈíÖÒÑÔ·¸·¨ÍÅ»ïGALLIUM¹¥»÷È«ÇòµÄµçÐŹ«Ë¾


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


΢ÈíÍþвÇ鱨ÖÐÐÄ£¨MSTIC£©ÖÒÑÔ·¸·¨ÍÅ»ïGALLIUMÕýÔÚÕë¶ÔÌìϸ÷µØµÄµçÐÅЧÀÍÉ̾ÙÐÐÒ»Á¬Ò»Ö±µÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¸Ã·¸·¨ÍÅ»ï¾ÙÐÐÁ˶à¸ö¹¥»÷»î¶¯£¬£¬£¬ £¬£¬£¬£¬MSTICÊӲ쵽Õë¶Ô¶«ÄÏÑÇ¡¢Å·Ö޺ͷÇÖ޵ĵçÐÅÔËÓªÉ̵Ĺ¥»÷¡£¡£¡£¡£¡£¡£¡£GALLIUMÖ÷Ҫͨ¹ýδ´ò²¹¶¡µÄWildFly/JBossЧÀÍÆ÷¾ÙÐÐÈëÇÖ£¬£¬£¬ £¬£¬£¬£¬Ò»µ©ÉøÍ¸µ½×éÖ¯µÄÍøÂçÖУ¬£¬£¬ £¬£¬£¬£¬GALLIUM±ã×îÏÈʹÓÃ×Ô½ç˵µÄ¶ñÒâÈí¼þÔÚÆóÒµÍøÂçÖкáÏòÒÆ¶¯ºÍÍøÂçÓòƾ֤¡£¡£¡£¡£¡£¡£¡£GALLIUM»¹Ê¹ÓÃSoftEther VPNÈí¼þÀ´ÔöÇ¿¶ÔÄ¿µÄÍøÂçµÄ»á¼ûºÍ¼á³Ö³¤ÆÚÐÔ¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤MSTICµÄ±¨¸æ£¬£¬£¬ £¬£¬£¬£¬GALLIUMµÄTTPºÍ¸Ã×é֯ʹÓõIJ¿·ÖÓòÓë2018ÄêµÄOperation SoftCellÏàͬ¡£¡£¡£¡£¡£¡£¡£


  Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-warns-of-gallium-threat-group-attacking-global-telcos/


2.¶ñÒâÈí¼þKrampus-3PCÖ÷ÒªÃé×¼iphoneÓû§


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Ò»¸öÕë¶ÔiPhoneÓû§µÄ¶ñÒâ¹ã¸æÖض¨Ïò»î¶¯ÒѾ­Ó°ÏìÁË100¶à¸ö³öÊéÉÌÍøÕ¾£¬£¬£¬ £¬£¬£¬£¬ÆäÖаüÀ¨ÔÚÏß±¨Ö½ÍøÕ¾ºÍ¹ú¼ÊÿÖÜÐÂÎÅÔÓÖ¾ÍøÕ¾µÈ¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤DSOÍŶӵÄ˵·¨£¬£¬£¬ £¬£¬£¬£¬¸Ã¶ñÒâÈí¼þKrampus-3PCαװ³ÉÔÓ»õµêµÄ³ê±ö¹ã¸æ£¬£¬£¬ £¬£¬£¬£¬´ÓÓû§ÄÇÀïÊվۻỰºÍcookieÐÅÏ¢£¬£¬£¬ £¬£¬£¬£¬²¢ÇÒÔÚÓû§µã»÷¹ã¸æÊ±Öض¨ÏòÖÁÒ»¸öÍøÂçСÎÒ˽¼ÒÐÅÏ¢µÄÐéÎ±ÍøÕ¾¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÊ×ÏÈÔÚ¹ã¸æÆ½Ì¨AdtechstackÉÏͶ·Å¹ã¸æ£¬£¬£¬ £¬£¬£¬£¬È»ºóʹÓÃÆ½Ì¨µÄAPI²åÈë¶ñÒâ´úÂ룬£¬£¬ £¬£¬£¬£¬ÕâЩ¶ñÒâ¹ã¸æËæºó±»·Ö·¢¸ø´ó×ÚÍøÕ¾¡£¡£¡£¡£¡£¡£¡£Krampus-3PC»á½«ÍøÂçµ½µÄÓû§ÐÅÏ¢·¢ËÍÖÁC2ÓòÃûboostsea2[.]com¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚÉв»ÇåÎú¹¥»÷ÕßµÄÉí·Ý¡£¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://threatpost.com/krampus-3pc-malware-iphone-users/151043/


3.ÀÕË÷Èí¼þZeppelinÖ÷ÒªÕë¶ÔITºÍÒ½ÁƱ£½¡¹«Ë¾


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ÔÚBlackBerry CylanceµÄ×îб¨¸æÖУ¬£¬£¬ £¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷ÀÕË÷Èí¼þZeppelin±»ÓÃÓÚÕë¶ÔITºÍÒ½ÁƱ£½¡¹«Ë¾µÄÕë¶ÔÐÔ¹¥»÷¡£¡£¡£¡£¡£¡£¡£ÔÚÆäÖÐһЩ¹¥»÷»î¶¯ÖУ¬£¬£¬ £¬£¬£¬£¬BlackBerry CylanceÒÔΪ¹¥»÷ÕßÃé×¼MSP£¨ÖÎÀíЧÀÍÌṩÉÌ£©µÄÄ¿µÄÊÇͨ¹ýÖÎÀíÈí¼þ½øÒ»²½Ñ¬È¾Æä¿Í»§¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚÉв»ÇåÎúZeppelinµÄ·Ö·¢·½·¨£¬£¬£¬ £¬£¬£¬£¬µ«ËüºÜ¿ÉÄÜÊÇͨ¹ý̻¶ÔÚ»¥ÁªÍøÉϵÄRDPЧÀÍÈö²¥¡£¡£¡£¡£¡£¡£¡£ÔÚ¼ÓÃÜÎļþʱ£¬£¬£¬ £¬£¬£¬£¬Zeppelin²»»áÌí¼ÓÌØÁíÍâÀ©Õ¹Ãû£¬£¬£¬ £¬£¬£¬£¬²¢ÇÒÎļþÃû¼á³ÖÎȹÌ£¬£¬£¬ £¬£¬£¬£¬µ«¼ÓÃܵÄÎļþºó½«»á°üÀ¨Ò»¸öZeppelinÎļþ±ê¼Ç¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚÉÐÎÞ·¨Ã⺬»ìÃܸÃÀÕË÷Èí¼þ¼ÓÃܵÄÎļþ¡£¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/zeppelin-ransomware-targets-healthcare-and-it-companies/


4.ÄÏ¿¨ÂÞÀ´ÄÉÖݰ¸¼þÖÎÀí»ú¹¹Ð¹Â¶Ô¼2.6ÍòÌõ¾Ð²¶¼Í¼


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Çå¾²³§ÉÌUpGuardÔÚSpartan Technology¹«Ë¾µÄ¿ª·ÅÔÆ´æ´¢Í°Öз¢Ã÷Ô¼2.6ÍòÈ˵ľв¶¼Í¼¡£¡£¡£¡£¡£¡£¡£Spartan Technology×ÊÖúÄÏ¿¨ÂÞÀ³ÄÉÖݵĵØÒªÁìÔº´æ´¢°¸¼þÖÎÀíÊý¾Ý£¬£¬£¬ £¬£¬£¬£¬Æ¾Ö¤Ñо¿Ö°Ô±µÄ±íÊö£¬£¬£¬ £¬£¬£¬£¬¾Ð²¶¼Í¼ÖаüÀ¨±»¿Ø·¸·¨ÕßµÄÐÕÃû¡¢Ìá³öÖ¸¿ØµÄÊܺ¦ÕßÒÔ¼°Ä³Ð©°¸ÀýÖеÄÖ¤ÈËÐÕÃûµÈ£¬£¬£¬ £¬£¬£¬£¬ÆäÖв¿·ÖÉæ°¸Ö°Ô±ÎªÇàÉÙÄê¡£¡£¡£¡£¡£¡£¡£Êý¾Ý¿âµÄ´ó×ÚÌõÄ¿»¹°üÀ¨³öÉúÈÕÆÚ¡¢µç»°ºÅÂëºÍ¼ÝÕÕID£¬£¬£¬ £¬£¬£¬£¬ÒÔ¼°Ô¼1.7Íò¸öÉç»áÇå¾²ºÅÂë¡£¡£¡£¡£¡£¡£¡£Spartan TechnologyÔÚÈ·ÈÏÊÂÎñºóÌåÏÖй¶µÄÊý¾Ý¾ùΪ²âÊÔÊý¾Ý¡£¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://gizmodo.com/arrest-data-exposed-by-south-carolina-firm-included-per-1840365182


5.·ðÂÞÀï´ïÖÝPRIDE¹«Ë¾ÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬ £¬£¬£¬£¬ÏµÍ³ÈÔδ»Ö¸´


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


12ÔÂ7ÈÕ¸¥ÂÞÀï´ïÖÝPRIDE¹«Ë¾Ôâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬ £¬£¬£¬£¬ÆäÍøÕ¾ºÍϵͳÈÔ´¦ÓڹرÕ״̬¡£¡£¡£¡£¡£¡£¡£PRIDEÊÇÒ»¸ö·ÇÓªÀû×éÖ¯£¬£¬£¬ £¬£¬£¬£¬ÖÂÁ¦ÓÚ×ÊÖúÇô·¸Ñ§Ï°Ö°ÒµÊÖÒպͳöÓüºó¸üºÃµØÈÚÈëÉç»á¡£¡£¡£¡£¡£¡£¡£ÔÚÊܵ½¹¥»÷ºó£¬£¬£¬ £¬£¬£¬£¬¸Ã¹«Ë¾µÄÍøÕ¾¡¢ÈËΪϵͳ¡¢µç×ÓÓʼþ¡¢¿Í»§ºÍ¹©Ó¦ÉÌÁбíµÈ¶à¸öϵͳ¾ùÎÞ·¨»á¼û¡£¡£¡£¡£¡£¡£¡£PRIDEÊ×ϯÐÐÕþ¹ÙDee KiminkiÈ·ÈÏÁËÕâÒ»ÊÂÎñ£¬£¬£¬ £¬£¬£¬£¬²¢ÌåÏÖÕýÔÚÓëFBIÏàÖú¾ÙÐÐÊӲ졣¡£¡£¡£¡£¡£¡£ÏÖÔÚPRIDEÉÐδÌṩÓйش˴ι¥»÷ÊÂÎñµÄ¸ü¶àÏêϸÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ransomware-hits-florida-pride-on-saturday-systems-still-down/


6.AppleÐÞ¸´macOS CatalinaÖеÄ50¶à¸öÎó²î


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Apple±¾ÖÜÐû²¼ÁËmacOS Catalina¡¢iOSºÍiPadOS¡¢SafariµÈ²úÆ·µÄÇå¾²¸üУ¬£¬£¬ £¬£¬£¬£¬ÐÞ¸´¶à¸öÎó²î¡£¡£¡£¡£¡£¡£¡£ÆäÖÐmacOS CatalinaÊÕµ½ÁË×î¶àµÄÎó²î²¹¶¡£¬£¬£¬ £¬£¬£¬£¬Îª52¸ö£¬£¬£¬ £¬£¬£¬£¬ÊÜÓ°Ïì×î´óµÄ×é¼þÊÇtcpdump£¨32¸öÎó²î£©£¬£¬£¬ £¬£¬£¬£¬Óû§¿Éͨ¹ý¸üÐÂÖÁtcpdump°æ±¾4.9.3ºÍlibpcap°æ±¾1.9.1×°ÖÃÕâЩ²¹¶¡¡£¡£¡£¡£¡£¡£¡£Îó²îµÄ¹æÄ£°üÀ¨ÒÔϵͳ»òÄÚºËȨÏÞÖ´ÐÐí§Òâ´úÂë¡¢¾Ü¾øÐ§ÀÍ¡¢Óû§ÐÅϢй¶¡¢ÌØÈ¨ÌáÉýÒÔ¼°¶ÁÈ¡ÊÜÏÞÄÚ´æµÈ¡£¡£¡£¡£¡£¡£¡£Ö»¹Ü´ó´ó¶¼Îó²î½öÓ°ÏìmacOS Catalina 10.15£¬£¬£¬ £¬£¬£¬£¬µ«Ò²ÓÐһЩÎó²îÓ°ÏìÁËmacOS High Sierra 10.13.6ºÍmacOS Mojave 10.14.6¡£¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/apple-patches-over-50-vulnerabilities-macos-catalina