Android·ì϶StrandHogg 2.0Ó°Ï쳬¹ý10ÒŲ́É豸 £»2600ÍòLiveJournalÕÊ»§Êý¾ÝÔÚ¶à¸öºÚ¿ÍÂÛ̳´«²¼

°ä²¼¹¦·ò 2020-05-28

1.Android·ì϶StrandHogg 2.0±»Åû¶ £¬Ó°Ï쳬¹ý10ÒŲ́É豸


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


5ÔÂ26ÈÕ £¬Promon°²È«×êÑÐÈËÔ±Åû¶ÁËÒ»¸öÑϳÁµÄAndroid°²È«·ì϶StrandHogg 2.0£¨CVE-2020-0096£© £¬ËüÄܹ»½«¶ñÒâÀûÓüÙ×°³ÉºÏ·¨ÀûÓà £¬ÇÔÈ¡AndroidÓû§µÄÃô¸ÐÐÅÏ¢  ¡£¸Ã·ì϶ӰÏìÁËËùÓÐÔËÐÐAndroid 9.0¼°¸üµÍ°æ±¾µÄÉ豸£¨Googleͳ¼ÆÓÐ91.8£¥µÄAndroidÓû§Ê¹Óøð汾£© £¬»ò½«¸ß´ï10ÒŲ́É豸  ¡£Í¨¹ý´Ë·ì϶ £¬ºÚ¿ÍÄܹ»Ö´Ðи÷À๤×÷ £¬ÀýÈçͨ¹ýÂó¿Ë·çÇÔÊØÐÅÏ¢¡¢Í¨¹ýÏà»úÅÄÕÕ¡¢ÔĶÁºÍ·¢ËÍSMSÐÂÎÅ¡¢½øÐкͼͼµç»°¶Ô»°¡¢ÍøÂç´¹µöµÇ¼ʹ´¦¡¢½Ó¼ûÉ豸ÉÏËùÓиöÈËÕÕÆ¬ºÍÎļþ¡¢»ñÈ¡µØÎ»ºÍGPSÐÅÏ¢¡¢½Ó¼ûÁªÏµÈËÁÐ±í¡¢½Ó¼ûµç»°ÈÕÖ¾  ¡£GoogleÓÚ2020Äê4ÔÂΪAndroid 8.0¡¢8.1ºÍ9°ä²¼Á˰²È«²¹¶¡·¨Ê½ £¬Ä¿Ç°ÎªÖ¹ £¬¸Ã·ì϶»¹Î´±»ÔÚÒ°ÀûÓà  ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/critical-android-bug-lets-malicious-apps-hide-in-plain-sight/


2.2600Íò¸öLiveJournalÕÊ»§Êý¾ÝÔÚ¶à¸öºÚ¿ÍÂÛ̳´«²¼


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


½üÈÕ £¬2600Íò¸öLiveJournalÕÊ»§Êý¾ÝÔÚ¶à¸öºÚ¿ÍÂÛ̳ÉÏ´«²¼ £¬Õâ´Îй¶Êý¾ÝÔ̺¬µç×ÓÓʼþµØÖ·¡¢Óû§Ãû¡¢ÅäÖÃÎļþURLºÍ´¿Îı¾ÃÜÂë  ¡£Óд«ÑÔ³ÆLiveJournalÔÚ2014Äê±»ÈëÇÖ £¬²¢ÇÒÆä³¬¹ý3300ÍòÓû§µÄÕË»§ÐÅÏ¢±»µÁ  ¡£µ«Æ¾¾ÝbleepingcomputerµÄµ÷²é £¬ÆäÖÐÓÐЩÎļþÃûÏÔʾÊý¾Ýй¶ÊDzúÉúÔÚ2017Äê £¬Óë2014Äêй¶ÊÇÏàì¶ÜµÄ  ¡£LiveJournalÔò°ä²¼²¼¸æ £¬·ñ¶¨ÆäÔâµ½Á˹¥»÷  ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/26-million-livejournal-accounts-being-shared-on-hacker-forums/


3.¿¨Ëþ¶ûCOVID-19×·×ÙÀûÓôæÔÚ·ì϶ £¬Ð¹Â¶100ÍòÓû§Êý¾Ý


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


´óÉâ¹ú¼ÊÈËȨ×éÖ¯ÓÚÉÏÖܶþÖҸ濨Ëþ¶û £¬ÆäCOVID-19×·×ÙÀûÓôæÔÚ·ì϶ £¬Ð¹Â¶Á˳¬¹ý100ÍòÓû§µÄÃô¸ÐÊý¾Ý  ¡£¸ÃÀûÓÃÆôÓÃÁ˺öàȨÏÞ £¬Èç½Ó¼ûAndroidÉ豸ÉϵÄÎļþÒÔ¼°ÔÊÐí¸ÃÈí¼þ²¦´òµç»°  ¡£´óÉâ¹ú¼ÊµÄ°²È«³¢ÊÔÊÒ·¢ÏÖ £¬ÓÉÓÚ¸ÃÀûÓÃûÓвÉÈ¡Êʵ±µÄ°²È«´ëÊ©À´± £»¤ÕâЩÊý¾Ý £¬Ê¹µÃËûÃÇ¿ÉÄܽӼûһЩÃô¸ÐÐÅÏ¢ £¬Ô̺¬ÐÕÃû¡¢½¡È«Çé¿öºÍÓû§Ö¸¶¨¸ôÀëµØÖ·µÄGPS×ø±ê  ¡£Ä¿Ç° £¬¸Ã·ì϶ÒѾ­±»½¨¸´  ¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/qatar-tracing-app-flaw-exposed-1-mn-users-data-amnesty


4.ºÚ¿ÍÒÔ7.5Íò¬±ÈÏúÊÛ475ÍòÓ¡¶ÈTruecallerÓû§Êý¾Ý


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¾ÝÔÚÏßµý±¨¹«Ë¾Cyble³Æ £¬5ÔÂ26ÈÕ£¨PTI£© £¬Ò»ÃûºÚ¿ÍÏúÊÛÁË475ÍòÀ´×ÔÓ¡¶ÈÔÚÏßĿ¼TruecallerµÄÊý¾Ý £¬ÊÛ¼ÛԼΪ75000¬±È  ¡£ÏúÊÛµÄÊý¾ÝÔ̺¬µç»°ºÅÂë¡¢ÐԱ𡢳ÇÊÓ×¢ÒÆ¶¯ÍøÂç¡¢Facebook IDµÈ  ¡£CybleµÄ×êÑÐÈËÔ±·ÖÎö°µÊ¾ £¬ÕâÖÖй©¿ÉÄÜ»á¶ÔÓ¡¶ÈµÄ¿í´óÓû§Ôì³ÉÓ°Ïì £¬ÀýÈçÀ¬»øÓʼþ¡¢Ú¿Æ­¡¢Éí·Ý͵ÇÔµÈ  ¡£Truecaller½²»°ÈËÔò·ñ¶¨ÆäÊý¾Ý¿âÔâµ½Á˹¥»÷ £¬²¢°µÊ¾Õâ¿ÉÄÜÊÇÒѾ­Ð¹Â¶µÄÊý¾Ý¿â £¬¸Ã¹«Ë¾ÓÚ2019Äê5Ô²úÉú¹ýÀàËÆÊý¾ÝÏúÊÛµÄÎÊÌâ  ¡£


Ô­ÎÄÁ´½Ó£º

https://in.finance.yahoo.com/news/cyber-criminal-put-truecaller-records-134149107.html


5.ÐÂÀÕË÷²¡¶¾[F]UnicornÀûÓÃCOVID-19Ö÷Ìâ £¬Õë¶ÔÒâ´óÀû


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


±¾ÖÜÒ» £¬Òâ´óÀûÊý×ÖÒâ´óÀû¾Ö£¨AgID£©µÄÍÆËã»ú´¹Î£ÏìÓ¦Ó××飨CERT£©°ä²¼Á˹ØÓÚÒ»ÖÖÃûΪ[F]UnicornµÄÀÕË÷Èí¼þµÄ²¼¸æ £¬²¢Í¨Öª¸Ã²¡¶¾ÒÑÔÚÈ«¹úÁìÓòÄÚ´«²¼  ¡£[F]UnicornÒÔCOVID-19֪ͨ¸üÐÂΪµö¶ü £¬ÓÕʹÓû§ÏÂÔØÎ±ÔìµÄÁªÏµÈ˸ú×ÙÀûÓÃImmuni£¨Òâ´óÀûµ±¾Ö½«ÔÚ±¾Ôµװ䲼£© £¬²¢Í¨¹ýÉç»á¹¤³Ìʹ¸ÃÀûÓÿ´ÆðÀ´À´×ÔÒâ´óÀûÒ©¼Áʦ½áºÏ»á£¨FOFI£©  ¡£ºÚ¿ÍÊ×ÏÈͨ¹ýÓʼþÓÕʹÓû§ÏÂÔØPC¶ËµÄBeta°æImmuni £¬»¹¿Ë¡ÁËFOFIÍøÕ¾²¢×¢²áÁËÓëԭʼÓòÃûÀàËÆµÄÓòÃû £¬ÔÚÖ´ÐиöñÒâÈí¼þºó»á»¹»áÏÔʾ´øÓÐCOVID-19ÐÅÏ¢µÄ½çÃæ  ¡£µ±Óû§ÅÔ¹Û½çÃæÐÅϢʱ £¬[F]Unicorn±ãÆðÍ·ÔÚϵͳÉϼÓÃÜÊý¾Ý  ¡£Êê½ð֪ͨҪÇóÊܺ¦ÕßÔÚÈýÌìÄÚÖ§¸¶300Å·Ôª £¬²»È»Êý¾Ý½«ÃÔʧ  ¡£CERT-AgID×êÑÐÈËÔ±°µÊ¾¸Ã²¡¶¾ºÜ´óˮƽÉÏÊÇ»ùÓÚHidden TearµÄ £¬Ö»ÊÇ×öÁËЩÐíŤת  ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-f-unicorn-ransomware-hits-italy-via-fake-covid-19-infection-map/


6.΢Èí°ä²¼ÖÒ¸æ £¬²¿Êð·ÀÓùÒÔµÖ¿¹ÐÂÀÕË÷Èí¼þPonyFinal


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


΢ÈíÍŶÓÓÚ°ä²¼ÁËÒ»·ÝÖÒ¸æ £¬Í¨ÖªÈ«Çò¸÷µØµÄ×éÖ¯²¿Êð·ÀÓù´ëÊ© £¬ÒÔÔ¤·À×î½üÊ¢ÐеÄÐÂÐÍÀÕË÷Èí¼þPonyFinal  ¡£ºÚ¿Íͨ³£ÊÇÕë¶ÔÖ¸±ê¹«Ë¾µÄÒ»¸öÕË»§ £¬ÀûÓÃÈõÃÜÂ뱩Á¦ÆÆ½â¸ÃÕË»§½øÈëÍøÂç £¬Ö®ºó²¿ÊðÒ»¸öVisual Basic¾ç±¾ÒÔÔËÐÐPowerShell·´Ïò±í¿Ç·¨Ê½ £¬ÓÃÀ´×ª´¢ºÍÇÔÈ¡±¾µØÊý¾Ý  ¡£ÓÐʱ³½¹¥»÷Õß»¹»áÔÚÖ¸±êÖ÷»ú×°ÖÃJRE £¬ÓÉÓÚPonyFinaÊÇlÓÃJava±àдµÄ  ¡£ºÚ¿ÍÒ»µ©°ÑÎÕÁËÖ¸±êÍøÂç £¬±ã»á²¿ÊðPonyFinal²¢ÔÚÆäËûϵͳÖд«²¼ £¬ÕâÓëÒÔÍùµÄͨ¹ýÀ¬»øÓʼþ»ò·ì϶¹¤¾ß°ü·Ö·¢ÀÕË÷Èí¼þµÄ·½Ê½·ÖÆç  ¡£¾Ý±¨Â· £¬Ó¡¶È¡¢ÒÁÀʺÍÃÀ¹úÒÑÓдËÀÕË÷Èí¼þµÄÊܺ¦Õß  ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/microsoft-warns-about-attacks-with-the-ponyfinal-ransomware/