ºÚ¿ÍÔÚGitHub´æ´¢¿âÖйûÕæCobalt StrikeÔ´´úÂ룻£»£»£»ºÚÝ®·¢Ã÷кڿ͹ÍÓ¶¾üCostaRicto£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÄÏÑÇ×éÖ¯
Ðû²¼Ê±¼ä 2020-11-13
ºÚ¿ÍÔÚGitHub´æ´¢¿âÖйûÕæCobalt Strike¹¤¾ß°üµÄÔ´´úÂë¡£¡£¡£¡£¡£¡£¡£Cobalt StrikeÊÇÕýµ±µÄÉøÍ¸²âÊÔ¹¤¾ß°ü£¬£¬£¬£¬£¬£¬£¬¿ÉÔÚÄ¿µÄ×°±¸Éϰ²ÅÅÐű꣬£¬£¬£¬£¬£¬£¬À´Ô¶³Ì½¨ÉèShell²¢Ö´ÐÐPowerShell¾ç±¾¡£¡£¡£¡£¡£¡£¡£Ó¢ÌضûÑо¿Ö°Ô±Éó²éÔ´´úÂëºóÒÔΪJava´úÂëÊÇÊÖ¶¯·´±àÒëµÄ£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍÐÞ¸´ÁËËùÓÐÒÀÀµ¹ØÏµ²¢É¾³ýÁËÔÊÐíÖ¤¼ì²é£¬£¬£¬£¬£¬£¬£¬ÒÔ±ã¶ÔÆä¾ÙÐбàÒë¡£¡£¡£¡£¡£¡£¡£×ÔÐû²¼ÒÔÀ´£¬£¬£¬£¬£¬£¬£¬¸Ã´æ´¢¿âÒѱ»forked 172´Î£¬£¬£¬£¬£¬£¬£¬ÕâʹµÃÔ´´úÂëµÄÈö²¥Ô½·¢ÄÑÒÔ¿ØÖÆ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/alleged-source-code-of-cobalt-strike-toolkit-shared-online/
2.ºÚ¿ÍÔÚ°µÍø³öÊÛAnimal Jam 4600Íò¸öÓû§µÄÊý¾Ý

ºÚ¿ÍÔÚ°µÍø³öÊÛAnimal Jam 4600Íò¸öÓû§µÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£Animal JamÊÇWildWorks½¨ÉèµÄÐéÄâÌìÏ£¬£¬£¬£¬£¬£¬£¬Îª¹ãÊܽӴýµÄ¶ùͯÔÚÏßÓÎÀÖ³¡¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚºÚ¿ÍÔÚ°µÍø¹²ÏíÁËÁ½¸ö¾Ý³ÆÊÇ´ÓShinyHunters»ñµÃµÄÊôÓÚAnimal JamµÄÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬Ãû³Æ»®·ÖΪgame_accountsºÍusers£¬£¬£¬£¬£¬£¬£¬°üÀ¨ÁËԼĪ4600Íò¸ö±»µÁÓû§¼Í¼¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤Ñù±¾¼Í¼ÉϵÄʱ¼ä´Á¼Ç£¬£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âºÜ¿ÉÄÜÔÚ2020Äê10ÔÂ12ÈÕ±»µÁµÄ¡£¡£¡£¡£¡£¡£¡£WildWorksͨ¹ýÊӲ췢Ã÷£¬£¬£¬£¬£¬£¬£¬ºÚ¿Í¿ÉÄÜÔÚÆÆËðÁ˹«Ë¾µÄSlackЧÀÍÆ÷ºó»ñµÃÁËWildWorkµÄAWSÃÜÔ¿¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/animal-jam-kids-virtual-world-hit-by-data-breach-impacts-46m-accounts/
3.΢ÈíÐû²¼OfficeÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´7¿î²úÆ·ÖеĶà¸öÎó²î

΢ÈíÐû²¼ÁË11ÔÂOfficeÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´7¿î²úÆ·ÖеÄ14¸öÎó²î¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄ×îΪÑÏÖØµÄÎó²îÊÇMicrosoft SharePointÖеÄÔ¶³ÌÖ´ÐдúÂ루RCE£©Îó²î£¨CVE-2020-17061£©£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓõÍÓû§È¨ÏÞÔ¶³ÌʹÓôËÎó²î¶øÎÞÐèÓëÓû§½»»¥¡£¡£¡£¡£¡£¡£¡£±ðµÄ»¹ÐÞ¸´ÁËMicrosoft ExcelÖеĶà¸öÔ¶³ÌÖ´ÐдúÂëÎó²î£¨CVE-2020-17065¡¢CVE-2020-17064¡¢CVE-2020-17066ºÍCVE-2020-17019£©ºÍ AccessÅþÁ¬ÒýÇæÔ¶³ÌÖ´ÐдúÂëÎó²î£¨CVE-2020-17062£©µÈ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/office-november-security-updates-fix-remote-code-execution-bugs/
4.NVIDIAÐÞ¸´GeForce NOWÔÆÓÎϷЧÀÍÖеĴúÂëÖ´ÐÐÎó²î

NVIDIAΪGeForce NowÔÆÓÎϷЧÀÍÐû²¼ÁËÒ»¸öÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÒÔÐÞ¸´¿ÉÄܵ¼ÖÂí§Òâ´úÂëÖ´ÐлòÌØÈ¨ÌáÉýµÄÎó²î¡£¡£¡£¡£¡£¡£¡£GeForce NowÊÇ»ùÓÚÔÆµÄÓÎÏ·Á÷ýÌåЧÀÍ£¬£¬£¬£¬£¬£¬£¬ËüÔÊÐíÓû§´ÓNVIDIAЧÀÍÆ÷ÉÏÍйܵÄÊý°Ù¸öÓÎÏ·¿âÖлñÈ¡ÓÎÏ·¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î±»×·×ÙΪCVE?2020?5992£¬£¬£¬£¬£¬£¬£¬±£´æÓÚÆä¿ªÔ´Èí¼þÒÀÀµÏîOpenSSL¿âÖУ¬£¬£¬£¬£¬£¬£¬Ò×Êܵ½ÍâµØÓû§µÄ¶þ½øÖÆ×¢Èë¹¥»÷£¬£¬£¬£¬£¬£¬£¬¿Éµ¼Ö´úÂëÖ´ÐлòÌØÈ¨Éý¼¶¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/nvidia-fixes-severe-flaw-in-geforce-now-cloud-gaming-service/
5.½©Ê¬ÍøÂçMuhstikÐÂÔöOracle WebLogicºÍDrupalÎó²î

Ñо¿Ö°Ô±·¢Ã÷½©Ê¬ÍøÂçMuhstikÐÂÔöOracle WebLogicºÍDrupalÎó²î¡£¡£¡£¡£¡£¡£¡£Muhstik½©Ê¬ÍøÂ磨Ҳ³ÆÎªMushtik£©Ò»Ö±Õë¶ÔÔÆ»ù´¡ÉèÊ©ºÍÎïÁªÍø£¬£¬£¬£¬£¬£¬£¬Í¨¹ýʹÓÃXMRigºÍcgminerµÈ¿ªÔ´¹¤¾ßÍÚ¾ò¼ÓÃÜÇ®±ÒÀ´×¬Ç®¡£¡£¡£¡£¡£¡£¡£ÔÆÇå¾²¹«Ë¾Lacework·¢Ã÷ÆäÒÑ×îÏÈʹÓÃOracle WebLogic ServerÎó²î£¨CVE-2019-2725ºÍCVE-2017-10271£©ºÍDrupal RCEÎó²î£¨CVE-2018-7600£©¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬Ñо¿·¢Ã÷MuhstikʹÓÃMiraiÔ´´úÂëͨ¹ýµ¥×Ö½ÚXOR¼ÓÃÜÀ´¼ÓÃÜÆäÓÐÓøºÔغÍɨÃèÄ£¿£¿£¿£¿éµÄÉèÖᣡ£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/110763/uncategorized/muhstik-botnet-weblogic-drupal.html
6.ºÚÝ®·¢Ã÷кڿ͹ÍÓ¶¾üCostaRicto£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÄÏÑÇ×éÖ¯

ºÚÝ®Ðû²¼ÁËÓйØÐµĺڿ͹ÍÓ¶¾ü×éÖ¯CostaRictoµÄÏêϸÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÄÏÑÇ×éÖ¯¡£¡£¡£¡£¡£¡£¡£¸Ã×é֯ȫÐIJ߻®ÁËÆÕ±éÅ·ÖÞ¡¢ÃÀÖÞ¡¢ÑÇÖÞ¡¢°Ä´óÀûÑǺͷÇÖ޵IJî±ð¹ú¼ÒµÄ¹¥»÷£¬£¬£¬£¬£¬£¬£¬µ«Êܺ¦Õ߶༯ÖÐÓÚÄÏÑÇ£¬£¬£¬£¬£¬£¬£¬ÓÈÆäÊÇÓ¡¶È¡¢ÃϼÓÀ¹úºÍÐÂ¼ÓÆÂ£¬£¬£¬£¬£¬£¬£¬²¢ÇҴ󲿷ÖÊôÓÚ½ðÈÚÐÐÒµ¡£¡£¡£¡£¡£¡£¡£ÕâÊǽñÄê·¢Ã÷µÄµÚÎå¸öºÚ¿Í¹ÍÓ¶×éÖ¯£¬£¬£¬£¬£¬£¬£¬ÆäËûËĸö»®·ÖΪBellTrox (ÓÖ³ÆDark Basin)¡¢DeathStalker (ÓÖ³ÆDeceptikons) ¡¢BahamutºÍUnnamed group¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/blackberry-discovers-new-costaricto-hacker-for-hire-group/


¾©¹«Íø°²±¸11010802024551ºÅ