¾ÅÓÎÀϸç

¾ÅÓÎÀϸç

¾ÅÓÎÀÏ¸ç¿Æ¼¼

  • »ù´¡ÉèÊ©Çå¾²

    »ù´¡ÉèÊ©Çå¾²
  • Êý¾ÝÇå¾²

    Êý¾ÝÇå¾²
  • ÔÆÅÌËãÇå¾²

    ÔÆÅÌËãÇå¾²
  • ¹¤Òµ»¥ÁªÍøÇå¾²

    ¹¤Òµ»¥ÁªÍøÇå¾²
  • ÎïÁªÍøÇå¾²

    ÎïÁªÍøÇå¾²
  • ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì

    ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì
  • ËùÓвúÆ·

    ËùÓвúÆ·
  • ËùÓнâ¾ö¼Æ»®

    ËùÓнâ¾ö¼Æ»®

»ù´¡ÉèÊ©Çå¾²


  • Õþ¸®

    Õþ¸®
  • ÔËÓªÉÌ

    ÔËÓªÉÌ
  • ½ðÈÚ

    ½ðÈÚ
  • ÄÜÔ´

    ÄÜÔ´
  • ½»Í¨

    ½»Í¨
  • ÆóÒµ

    ÆóÒµ
  • ¿Æ½ÌÎÄÎÀ

    ¿Æ½ÌÎÄÎÀ

  • ¾ÅÓÎÀϸçÔÆ ¾ÅÓÎÀϸçÔÆ
  • ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÏàÖúͬ°éÉó²é¸ü¶à >

ÏàÖúͬ°é¶¯Ì¬

³ÉΪÏàÖúͬ°é

  • ¾ÅÓÎÀϸçÔÆ ¾ÅÓÎÀϸçÔÆ
  • ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÊÖÒÕÖ§³ÖÉó²é¸ü¶à >

²úÆ·Ö§³Ö

  • ¾ÅÓÎÀϸçÔÆ ¾ÅÓÎÀϸçÔÆ
  • ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI ¾ÅÓÎÀϸçÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á ±±¾©¾ÅÓÎÀÏ¸ç¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

·µ»ØÁбí

¾ÅÓÎÀÏ¸ç¿Æ¼¼ÍþвÇ鱨Öܱ¨-2020ÄêµÚ9ÖÜ£¨2020.2.24-2020.3.01£©

2020-03-01

Ò»¡¢ Íþвͨ¸æ

? Microsoft Exchange ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î

 

¡¾Ðû²¼Ê±¼ä¡¿2020-02-26 20:00:00 GMT 

¡¾¸ÅÊö¡¿

±±¾©Ê±¼ä2ÔÂ12ÈÕ£¬Î¢ÈíÔÚÐû²¼2ÔÂÇå¾²¸üв¹¶¡Öн«Ó°ÏìMicrosoft Exchange ServerµÄÎó²îCVE-2020-0688½ç˵ΪÄÚ´æËð»µÎó²î¡£2ÔÂ26ÈÕÓÐÇå¾²Ñо¿Ô±¹ûÕæÁ˸ÃÎó²îϸ½Ú£¬»ñÈ¡µ½ÓÊÏäÕË»§È¨Ï޵Ĺ¥»÷ÕßÏò·þÎñÆ÷·¢ËÍÈ«ÐĽṹµÄÇëÇ󣬿ÉÔÚ·þÎñÆ÷¶ËʵÏÖÔ¶³Ì´úÂëÖ´ÐУ¬Î¢Èí¹Ù·½Ò²½«Ö®Ç°ÃüÃûµÄÄÚ´æËð»µÎó²îÖØÃüÃûΪԶ³Ì´úÂëÖ´ÐÐÎó²î¡£

¡¾Á´½Ó¡¿

http://blog.nsfocus.net/cve-2020-0688/

¶þ¡¢ ÈÈÃÅ×ÊѶ

1. Google ChromeÐû²¼¸üÐÂÐÞ¸´0dayÎó²î

¡¾¸ÅÊö¡¿

ÍâµØÊ±¼ä2ÔÂ24ÈÕ£¬GoogleÕë¶Ô×ÀÃæ°æChromeä¯ÀÀÆ÷Ðû²¼¸üÐÂÒÔ½â¾ö¶à¸öÎó²î£¬ÆäÖаüÀ¨Òѱ»·¢Ã÷ÔÚҰʹÓõĸßΣÎó²îCVE-2020-6418¡£CVE-2020-6418ÊDZ£´æÓÚV8ÖеÄÀàÐÍ»ìÏýÎó²î£¬V8ÊÇGoogle ChromeµÄ¿ªÔ´JavaScriptºÍWebAssemblyÒýÇæ¡£¸ÃÎó²îÓÉGoogleÍþвÆÊÎöС×éµÄClement Lecigne·¢Ã÷²¢Éϱ¨¡£

¡¾²Î¿¼Á´½Ó¡¿

http://blog.nsfocus.net/cve-2020-6418/

 

2. OpenSMTPDÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î

¡¾¸ÅÊö¡¿

ÍâµØÊ±¼ä2020Äê2ÔÂ24ÈÕ£¬À´×ÔÇå¾²¹«Ë¾QualysµÄÑо¿Ö°Ô±ÔÚ¹ûÕæÓʼþ×éÖÐÐû²¼ÁËOpenSMTPDÖб£´æµÄÒ»¸öÔ¶³ÌÏÂÁîÖ´ÐÐÎó²îCVE-2020-8794¡£OpenSMTPD£¨Ò²³ÆÎªOpenBSD SMTP·þÎñÆ÷£©ÊÇOpenBSDÏîÄ¿µÄÒ»²¿·Ö£¬Ò»¸öÃâ·ÑµÄ·þÎñÆ÷¶ËSMTPЭÒéʵÏÖ£¬Í¨¹ýRFC5321½ç˵¡£CVE-2020-8794ÊÇÒ»¸öÔ½½ç¶ÁÈ¡Îó²î£¬¿É±»Ô¶³ÌʹÓã¬ÀֳɵÄʹÓÿɵ¼Ö¹¥»÷ÕßÒÔrootÉí·ÝÖ´ÐÐ×¢Èëµ½envelopeÎļþÖеÄí§ÒâÏÂÁî¡£

¡¾²Î¿¼Á´½Ó¡¿

http://blog.nsfocus.net/cve-2020-8794/

 

3. Vmware vRealize Operations for Horizon AdapterÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¡¾¸ÅÊö¡¿

Vmware¿ËÈÕÐû²¼µÄͨ¸æÖÐÐû²¼ÁËÒ»¸ö±£´æÓÚvRealize Operations for Horizon AdapterÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2020-3943)¡£Îó²îÔµ¹ÊÔ­ÓÉÊÇvRealize Operations for Horizon AdapterʹÓÃÁËûÓÐÇå¾²ÉèÖõÄJMX RMI·þÎñ¡£µ¼ÖÂδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýÍøÂç»á¼ûÔÚvRealize OperationsÖÐÖ´ÐÐí§Òâ´úÂë¡£

¡¾²Î¿¼Á´½Ó¡¿

http://blog.nsfocus.net/cve-2020-3943/

 

4. ÐÂÍøÂç¹¥»÷Ô˶¯Ê¹ÓÓ¹Ú×´²¡¶¾”Èö²¥¶ñÒâÈí¼þ

¡¾¸ÅÊö¡¿

ǰÆÚÓй¥»÷ÕßʹÓÃÒÔ“¹Ú×´²¡¶¾”ΪÖ÷ÌâµÄ´¹ÂÚÓʼþ·Ö·¢EmotetľÂíµÄ¹¥»÷Ô˶¯£¬¿ËÈÕÓÖ·¢Ã÷Ò»¸öÃûΪCoronaVirusSafetyMeasures.pdfµÄ¿ÉÒÉÎļþ£¬¸ÃÎļþ°üÀ¨µÄ¶ñÒâ´úÂë¿É¼àÊÓÓû§°´¼ü¡¢ÍøÂçÓû§µÄÃô¸ÐÐÅÏ¢µÈ£¬²¢½«ÆäËùÓÐÕ½ÀûÆ··¢Ë͵½Ö¸¶¨Ô¶³ÌÏÂÁîÓë¿ØÖÆ·þÎñÆ÷ÉÏ¡£

¡¾²Î¿¼Á´½Ó¡¿

https://blog.yoroi.company/research/new-cyber-attack-campaign-leverages-the-covid-19-infodemic/

 

5. CerberusľÂíа汾¿ÉÇÔÈ¡Google AuthenticatorÓ¦ÓôúÂë²¢ÈÆ¹ý2FA

¡¾¸ÅÊö¡¿

а汾µÄCerberus°²×¿ÒøÐÐľÂí¿ÉÇÔÈ¡Google AuthenticatorÓ¦ÓÃÌìÉúµÄÒ»´ÎÐÔ´úÂ룬²¢Èƹý2FA± £»¤µÄÕ˺Å£¬¸ÃľÂíÖ÷ÒªÕë¶ÔÒøÐÐÓû§£¬ÓÚ2019Äê8ÔÂÊ״α»·¢Ã÷£¬¿ÉʵÏÖÁýÕÖ¹¥»÷¡¢×èµ²SMSÐÂÎÅ¡¢»á¼ûÁªÏµÈËÁбíµÈ¹¦Ð§¡£Google AuthenticatorÊÇÒ»ÖÖÒÆ¶¯Ó¦ÓóÌÐò£¬ÓÃÓÚÐí¶àÔÚÏßÕÊ»§µÄË«ÒòËØÉí·ÝÑéÖ¤£¨2FA£©²ã¡£

¡¾²Î¿¼Á´½Ó¡¿

https://www.threatfabric.com/blogs/2020_year_of_the_rat.html

 

6. KrookÎó²îÓ°ÏìÊýÊ®ÒŲ́WiFi×°±¸

¡¾¸ÅÊö¡¿

Ñо¿Ö°Ô±ÔÚWi-FiоƬÖз¢Ã÷ÁËÒ»¸öÒÔǰδ֪µÄÎó²î£¬²¢½«ÆäÃüÃûΪKr00k£¬¸ÃÎó²îCVE-2019-15126¿ÉʹÒ×Êܹ¥»÷×°±¸Ê¹ÓÃÈ«Áã¼ÓÃÜÃÜÔ¿À´¼ÓÃÜÓû§Í¨Ñ¶µÄÒ»²¿·Ö£¬ÕâÈù¥»÷Õß¿ÉÇáËɽâÃÜ´«ÊäÖеÄһЩÎÞÏßÍøÂçÊý¾Ý°ü¡£KrookÎó²î»áÓ°ÏìʹÓÃBroadcomºÍCypressµÄWi-FiоƬµÄ×°±¸£¬ÕâÁ½ÀàоƬÊÇÏÖÔÚÖ§³ÖWi-FiµÄ×°±¸£¨ÀýÈçÖÇÄÜÊÖ»ú¡¢Æ½°åµçÄÔ¡¢Ìõ¼Ç±¾µçÄÔºÍIoTС¹¤¾ß£©ÖÐʹÓõÄ×î³£¼ûµÄоƬ¡£

¡¾²Î¿¼Á´½Ó¡¿

https://www.welivesecurity.com/2020/02/26/krook-serious-vulnerability-affected-encryption-billion-wifi-devices/

https://www.welivesecurity.com/wp-content/uploads/2020/02/ESET_Kr00k.pdf

 

7. ObliqueRATľÂíÕë¶Ô¶«ÄÏÑÇ×éÖ¯

¡¾¸ÅÊö¡¿

½üÆÚÒ»Æð¶ñÒâÈí¼þÔ˶¯Ê¹ÓöñÒâµÄMicrosoft OfficeÎĵµÈö²¥ObliqueRATÔ¶³Ì»á¼ûľÂí£¬¸Ã¶ñÒâÎĵµÊ¹ÓöñÒâºêÀ´×ª´ïµÚ¶þ½×¶ÎRATÓÐÓøºÔØ£¬´Ë´Î¹¥»÷Ô˶¯Õë¶Ô¶«ÄÏÑÇ×éÖ¯¡£

¡¾²Î¿¼Á´½Ó¡¿

https://blog.talosintelligence.com/2020/02/obliquerat-hits-victims-via-maldocs.html

?

ÄúµÄÁªÏµ·½·¨

*ÐÕÃû
*µ¥Î»Ãû³Æ
*ÁªÏµ·½·¨
*ÑéÖ¤Âë ¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾
Ìá½»µ½ÓÊÏä

¹ºÖÃÈÈÏß

  • ¹ºÖÃ×Éѯ:

    400-818-6868-1

Ìá½»ÏîÄ¿ÐèÇó

½Ó´ý¼ÓÈë¾ÅÓÎÀÏ¸ç¿Æ¼¼£¬³ÉΪÎÒÃǵÄÏàÖúͬ°é£¡
  • *ÇëÐÎòÄúµÄÐèÇó
  • *×îÖÕ¿Í»§Ãû³Æ
  • *ÏîÄ¿Ãû³Æ
  • Äú¸ÐÐËȤµÄ²úÆ·
  • ÏîĿԤËã
ÄúµÄÁªÏµ·½·¨
  • *ÐÕÃû
  • *ÁªÏµµç»°
  • *ÓÊÏä
  • *Ö°Îñ
  • *¹«Ë¾
  • *¶¼»á
  • *ÐÐÒµ
  • *ÑéÖ¤Âë ¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾
  • Ìá½»µ½ÓÊÏä
¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾
¾ÅÓÎÀϸ硤(Öйú)¾ãÀÖ²¿¹Ù·½ÍøÕ¾

·þÎñÖ§³Ö

ÖÇÄܿͷþ
ÖÇÄܿͷþ
¹ºÖÃ/ÊÛºóÊÖÒÕÎÊÌâ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
ÔÚÏßÌáµ¥|ÖÇÄÜÎÊ´ð|֪ʶ¿â
Ö§³ÖÈÈÏß
Ö§³ÖÈÈÏß
400-818-6868
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÉçÇø
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÉçÇø
×ÊÁÏÏÂÔØ|ÔÚÏßÎÊ´ð|ÊÖÒÕ½»Á÷

? 2025 NSFOCUS ¾ÅÓÎÀÏ¸ç¿Æ¼¼ www.nsfocus.com All Rights Reserved . ¾©¹«Íø°²±¸ 11010802021605ºÅ ¾©ICP±¸14004349ºÅ ¾©ICPÖ¤110355ºÅ

ÍøÕ¾µØÍ¼