VMware½¨¸´Fusion¡¢VMRCºÍHorizo??n ClientÖеÄÌáȨ·ì϶£»¼ÓÄôóËÄËù¾üУÔâµ½¹¥»÷µ¼ÖÂÍøÂçÖжÏ

°ä²¼¹¦·ò 2020-07-13

1.VMware½¨¸´Fusion¡¢VMRCºÍHorizon ClientÖеÄÌáȨ·ì϶


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


VMware°ä²¼Á˰²È«¸üР£¬½¨¸´ÁËÒ»¸öȨÏÞÌáÉý·ì϶ £¬¸Ã·ì϶ӰÏìÁËVMware Fusion¡¢ Mac°æ±¾µÄRemote ConsoleºÍHorizon Client £¬¹¥»÷Õß¿ÉÀûÓô˷ì϶À´½ÚÔìÊÜÓ°Ïìϵͳ¡£¸Ã·ì϶ÊÇÓÉÓÚXPC¿Í»§¶ËÑéÖ¤²»ÕýÈ·µ¼ÖµÄ £¬³É¹¦ÀûÓô˷ì϶¿ÉʹӵÓÐͨ³£Óû§È¨Ï޵Ĺ¥»÷Õß½«ÆäȨÏÞÌáÉýµ½ÏµÍ³ÉϵÄrootÓû§¡£¸Ã·ì϶µÄCVSSv3ÆÀ·ÖΪ7.8¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2020/07/10/vmware-releases-security-updates-multiple-products


2.¼ÓÄôóËÄËù¾üУÔâµ½¹¥»÷µ¼ÖÂÍøÂçÖжÏ £¬¶¯»úÉв»Ã÷È·


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¼ÓÄôóËÄËù¾üУÔâµ½¹¥»÷µ¼ÖÂÍøÂçÁÙʱ̱»¾ £¬Ä¿Ç°¶¯»úÉв»Ã÷ÏÔ¡£Õâ´ÎÔâµ½¹¥»÷µÄѧÌñðÀëΪ½ð˹¶ØµÄ»Ê¼Ò¾üÊÂѧԺ¡¢¿ý±±¿ËµÄRMC Saint-Jean¡¢¶àÂ×¶àµÄ¼ÓÄôó¶ÓÁÐѧԺºÍÂÞ²®ÌذÂÈüµÂѧԺµÄChief Warrant Officer £¬ÕâЩѧÌõÄÖ÷Ìâϵͳ¾ùÔâµ½Á˹¥»÷¡£Æ¾¾ÝRMC¸±½ÌÊÚGreg PhillipsÔÚ7ÔÂ6ÈÕ°ä·¢µÄ²©¿ÍÎÄÕ £¬Õâ´Î¹¥»÷ÖеĶñÒâÈí¼þÀûÓÃÁ˰²È«·ì϶½øÐÐ×ÔÎÒ×°Öà £¬¶øºó¶Ô´ÅÅÌÄÚÈݽøÐмÓÃÜ £¬´Ó¶øÊ¹ÆäÎÞ·¨½Ó¼û¡£²¢ÒÔΪ¸ÃÊÂÎñΪÀÕË÷Èí¼þ¹¥»÷ £¬µ«»Êºó´óѧ½ÌÊÚSkillicornÔòÒÔΪÊÇÆäËû¹ú¶ÈÊÔͼÈüÓÄô󵱾ÖÄÑ¿°¡£Ä¿Ç° £¬Ñ§ÌÃÍøÂçÒÀÈ»ÔÚ¸´Ô­ÖС£


Ô­ÎÄÁ´½Ó£º

https://www.kingstonist.com/news/motives-unclear-as-cyber-attack-shuts-down-rmc-network/


3.¶ñÒâÈí¼þÔö³¤Any.RunɳÏä¼ì²âÖ°ÄÜÒÔÌӱܷÖÎö


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


°²È«×êÑÐÔ±JAMESWT·¢ÏÖ¶ñÒâÈí¼þÐÂÔöÁËAny.RunɳÏä¼ì²âÖ°ÄÜ £¬ÒÔÌÓ±Ü×êÑÐÈËÔ±µÄ·ÖÎö¡£JAMESWT·¢´Ë¿ÌеÄÀûÓÃÀ¬»øÓʼþ·Ö·¢ÃÜÂëÇÔȡľÂíµÄ»î¶¯ÖÐ £¬¹¥»÷Õ߻ὫÁ½¸öPowerShell¾ç±¾ÏÂÔØµ½Êܺ¦ÕßµÄÍÆËã»ú¡£¶ñÒâÈí¼þÔÚÔËÐеڶþ¸ö¾ç±¾Ê± £¬Ê×ÏȽ«³¢ÊÔÆô¶¯ÃÜÂëÇÔȡľÂíAzorult £¬ÈôÊǼì²âµ½¸Ã·¨Ê½ÔÚAny.RunÉÏÔËÐÐ £¬±ã»áÏÔʾÐÂÎÅ¡° Any.run Deteceted£¡¡± £¬¶øºóÍ˳ö¡£Í¨¹ýÕâÖÖ²½Öè £¬ºÚ¿Íʹ×êÑÐÈËÔ±Ô½·¢ÄÑÒÔʹÓÃ×Ô¶¯»¯ÏµÍ³À´·ÖÎöÆä¹¥»÷¡£    


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/malware-adds-anyrun-sandbox-detection-to-evade-analysis/


4.Òò´æÔÚ°²È«·çÏÕ £¬Amazon½¨ÒéÔ±¹¤É¾³ýTikTokÀûÓÃ


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


AmazonÏòÆäÔ±¹¤·¢Ë͵ç×ÓÓʼþ £¬ÒªÇó±ØÐëÔÚ7ÔÂ10ÈÕ֮ǰ´ÓÆäÉ豸ÖÐɾ³ýTikTokÀûÓ÷¨Ê½¡£¸Ãµç×ÓÓʼþÖÐÌᵽʹÓÃTikTokÀûÓ÷¨Ê½´æÔÚ°²È«·çÏÕ £¬µ«Î´¾ßÌå×¢Ã÷ÊǺÎÖÖ·çÏÕ¡£ÔÚÕâÖ®ºó £¬7ÔÂ10ÈÕAmazon°µÊ¾¸Ã²»ÈÝʹÓÃTikTokµÄµç×ÓÓʼþÊÇÎó·¢µÄ £¬ÈÔ½«ÔÊÐíÔ±¹¤ÔÚÆäÉ豸ÉÏʹÓøÃÀûÓ÷¨Ê½¡£ºÜ¶àÈËÔð¹Ö¸ÃÀûÓ÷¨Ê½´ÓÓû§ÄÇÀïÍøÂçÐÅÏ¢²¢½«Æä´«µÝ¸øÖйúµ±¾Ö £¬µ«¸ÃÐÂÎÅ´ÓδµÃµ½Ö¤Êµ¡£×ÔÈ¥ÄêÒÔÀ´ £¬TikTok±»ÃÀ¹ú¾ü·½¡¢Ó¡¶Èµ±¾ÖºÍÓ¡¶È¾ü¶ÓµÈ²»ÈÝʹÓá£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/amazon-tells-employees-to-remove-tiktok-from-their-phones-due-to-security-risk/#ftag=RSSbaffb68


5.×êÑÐÔ±·¢ÏÖ¶ñÒâÈí¼þTrickBot·Ö·¢Æä²âÊÔ°æ±¾


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Ó¢ÌØ¶û¹«Ë¾µÄVitali KremezÔÚ·ÖÎöTrickBot¶ñÒâÈí¼þµÄ×îа汾ʱ·¢ÏÖ £¬ºÚ¿ÍÃýÎóµÄ·Ö·¢ÁËÆäÓÃÓÚÇÔÈ¡ÃÜÂëµÄÄ£¿égrabber.dllµÄ²âÊÔ°æ±¾¡£¼ÓÔØºó¸Ã²âÊÔ°æ±¾ºó £¬´ËÄ£¿é½«ÔÚĬÈÏä¯ÀÀÆ÷ÖÐÏÔʾÖÒ¸æ £¬Ö¸³ö¸Ã·¨Ê½ÔÚÍøÂçÐÅÏ¢ £¬²¢ÌáÐÑÊܺ¦ÕßÓ¦Á¢¼´Õ÷ѯÆäϵͳÖÎÀíÔ±¡£Kremez°µÊ¾ £¬¸Ã²âÊÔÄ£¿éËÆºõÓÉTrickBot¿ª·¢ÈËÔ±¿ª·¢µÄ £¬ÓÉÓÚËüÓëÆäËûÄ£¿é¾ùÊÇÒÔÒ»ÑùµÄ·½Ê½±àÂë £¬ËûÒÔΪºÚ¿ÍÔÚ²âÊÔа汾 £¬È´½¡ÍüÔÚ°ä²¼ºó½«Æäɾ³ý¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/trickbot-malware-mistakenly-warns-victims-that-they-are-infected/


6.CheckPoint°ä²¼»ã±¨ £¬PhorpiexÓ°ÏìÁ¦¼±¾çÔö³¤


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


CheckPoint°ä²¼ÁËÆä×îеÄ2020Äê6ÔÂÈ«ÇòÍþвָÊý £¬·¢ÏÖPhorpiexÓ°ÏìÁ¦¼±¾çÔö³¤¡£¸Ã½©Ê¬ÍøÂçÒ»ÏòÔÚ·Ö·¢ÐµÄÀÕË÷Èí¼þ¼´·þÎñ£¨RaaS£©ÀÕË÷Èí¼þAvaddon £¬ÓëÎåÔ·ÝÏà±È £¬ÆäÅÅÃûÉÏÉýÁË13λ £¬Î»ÁжñÒâÈí¼þÅÅÐаñµÄµÚ2λ £¬¶ÔÈ«Çò×éÖ¯µÄÓ°ÏìÁ¦·­ÁËÒ»·¬¡£ÔÚ6Ô·Ý £¬Ó°ÏìÁ¦×î´óµÄ¶ñÒâÈí¼þΪ¸ß¼¶RAT Agent Tesla £¬Ó°ÏìÁË3£¥µÄ×éÖ¯ £¬Æä´ÎÊǽ©Ê¬ÍøÂçPhorpiexºÍ¿ªÔ´CPUÍÚ¾òÈí¼þXMRig £¬Ó°ÏìÁË2%µÄ×éÖ¯¡£´Ë±í £¬±»ÀûÓÃ×îÑϳÁµÄ·ì϶ΪOpenSSL TLS DTLSÐÄÌøÐÅϢй¶ £¬Ó°ÏìÁË45£¥µÄ×éÖ¯ £¬Æä´ÎÊÇMVPower DVRÔ¶³Ì´úÂëÖ´Ðзì϶ºÍGit´æ´¢¿âй¶ £¬±ðÀëÓ°ÏìÁËÈ«Çò44£¥ºÍ38£¥µÄ×éÖ¯¡£


Ô­ÎÄÁ´½Ó£º

https://finance.yahoo.com/news/june-2020-most-wanted-malware-100010951.html?&web_view=true