¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180820
°ä²¼¹¦·ò 2018-08-20¡¾Íþвµý±¨¡¿×êÑÐÍŶӷ¢ÏÖ³¯ÏÊAPT×éÖ¯DarkhotelÀûÓÃVBScript¾ç±¾ÒýÇæ0dayµÄ¹¥»÷»î¶¯
Ç÷Ïò¿Æ¼¼µÄ°²È«×êÑÐÍŶӷ¢ÏÖ³¯ÏÊAPT×éÖ¯DarkhotelÔÚÀûÓÃ΢ÈíVBScript¾ç±¾ÒýÇæÖеÄÁãÈÕ·ì϶£¨CVE-2018-8373£©ÌáÒé¹¥»÷»î¶¯£¬¸Ã·ì϶ÊÇÒ»¸öuse-after-free·ì϶£¬¿ÉÔÊÐí¹¥»÷ÕßÔÚÖ¸±êÍÆËã»úÉÏÔËÐÐshellcode¡£ÔÚ×îа汾µÄWindowsÖУ¬Î¢ÈíÔÚä¯ÀÀÆ÷µÄĬÈÏÅäÖÃÖнûÓÃÁËVBScript£¬Ê¹Æä²»Ò×Êܵ½¹¥»÷¡£Î¢ÈíÒÑÔÚ8Ô°²È«¸üÐÂÖн¨¸´ÁË´Ë·ì϶¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/zero-day-in-microsofts-vbscript-engine-used-by-darkhotel-apt/
¡¾Íþвµý±¨¡¿×êÑÐÈËÔ±ÑÝʾÈôºÎÀûÓÃÓïÒôÐÅÏä½Ù³ÖPayPalºÍWhatsAppÕË»§
°²È«×êÑÐÈËÔ±Martin Vigo³Æ¹¥»÷Õß¿ÉÀûÓÃÓïÒôÐÅÏäÈëÇÖÓû§µÄÔÚÏßÕË»§£¬ÈçPayPalºÍWhatsAppµÈ¡£´óÎÞÊýÔËÓªÉ̲»½öÖ§³Öͨ¹ýÊÖ»ú½Ó¼ûÓïÒôÐÅÏ䣬»¹Ö§³Öͨ¹ýPINÂëʹÓÃ±í²¿µç»°ºÅÂë½Ó¼ûÓïÒôÐÅÏä¡£ºÜ¶àÓû§Ê¹ÓÃÁËĬÈϵÄPINÂ룬ÀýÈçµç»°ºÅÂëµÄºóËÄλ»òÕß1111¼°1234µÈµ¥Ò»ÃÜÂë¡£×êÑÐÈËÔ±ÑÝʾÁËÈôºÎÀûÓÃÓïÒôÐÅÏäÀ´³ÁÖÃÓû§µÄÔÚÏßÕË»§µÄÃÜÂ룬²¢×îÖÕ½Ù³ÖÓû§µÄPayPalºÍWhatsAppÕË»§¡£
ÔÎÄÁ´½Ó£ºhttps://www.kaspersky.com/blog/hacking-online-accounts-via-voice-mail/23499/
¡¾¶ñÒâÈí¼þ¡¿×êÑÐÍŶӷ¢ÏÖеÄAZORultľÂí±äÌå¼°ÀÕË÷Èí¼þAurora
Salesforce×êÑÐÈËÔ±Vishal Thakur·¢ÏÖеÄAZORultľÂí±äÌå¼°ÀÕË÷Èí¼þAurora¡£µ½2018Äê7Ôµף¬×êÑÐÈËÔ±¹Û²ìµ½¸ÃľÂí±»ÓÃÓÚÕë¶ÔÈ«ÇòÍÆËã»úµÄ¶ñÒâ¹¥»÷»î¶¯ÖУ¬×î³õµÄϰȾý½éÊÇÍøÂç´¹µöÓʼþ£¬ÆäÔ̺¬Á½¸öÓÐЧºÉÔØ£¬Ò»¸öÊÇÖØÒªÓÃÓÚÇÔÈ¡Óû§Í´´¦µÄľÂí£¬ÀýÈç±¾µØÕË»§ºÍä¯ÀÀÆ÷µÄÍ´´¦µÈ¡£ÁíÒ»¸öÓÐЧºÉÔØÊÇÀÕË÷Èí¼þAurora£¬ÆäÀÕË÷µÄÊê½ðΪ150ÃÀÔª¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/azorult-trojan-serving-aurora-ransomware-by-malactor-oktropys/
¡¾¶ñÒâÈí¼þ¡¿°²È«×êÑÐÈËÔ±·¢ÏÖÖØÒªÕë¶Ôº«¹úµÄÐÂÀÕË÷Èí¼þMAFIA
×êÑÐÈËÔ±·¢ÏÖÖØÒªÕë¶Ôº«¹úµÄÐÂÀÕË÷Èí¼þ¼Ò×åMAFIA¡£Ä¿Ç°»¹²»ÖªÂ·MAFIAÈôºÎ½øÈëÓû§µÄϵͳ£¬µ«ËüºÜ¿ÉÄÜÊÇͨ¹ýÍøÂç´¹µö»î¶¯ÊµÏÖÕâÒ»²½µÄ¡£MAFIAÀûÓÃOpenSSLÀ´¼ÓÃÜÎļþ£¬ËüʹÓÃAES-256Ëã·¨µÄCBCģʽ£¬²¢ÔÚ¼ÓÃܵÄÎļþºó¸½¼Ó.MAFIAÀ©´óÃû¡£ÓÉÓÚÆä¼ÓÃܹý³ÌºÜÂý£¬Óû§¿Éͨ¹ýÖÕÖ¹Æä¹ý³Ì£¨Í¨³£ÃûΪwinlogin.exe£©»ò¹Ø¹ØÍÆËã»úÀ´×èÖ¹Ëü¡£MAFIAʹÓÃTor´úÀí½øÐÐC2ͨѶ£¬Æäͨ¹ýHTTP GETÒªÇóÀ´·¢ËͼÓÃÜÃÜÔ¿ºÍIV¡£
ÔÎÄÁ´½Ó£ºhttps://bartblaze.blogspot.com/2018/08/mafia-ransomware-targeting-users-in.html
¡¾¶ñÒâÈí¼þ¡¿×êÑлú¹¹°ä²¼¹ØÓÚÒøÐÐľÂíTrickbotµÄбäÌåµÄ·ÖÎö»ã±¨
Cyberbit×êÑÐÍŶӷ¢ÏÖÒøÐÐľÂíTrickbotµÄбäÖÖʹÓÃÁËеÄÌӱܼì²â¼¼Êõ¡£Trickbot×Ô2016ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬ÆäÔ̺¬ÇÔÈ¡ä¯ÀÀÆ÷ÐÅÏ¢¡¢ÇÔÈ¡OutlookÐÅÏ¢¡¢Ëø¶¨ÍÆËã»ú¡¢ÍøÂçϵͳºÍÍøÂçÐÅÏ¢ÒÔ¼°ÇÔÈ¡ÓòÃûÍ´´¦µÈÄ£¿é¡£×êÑÐÈËÔ±·¢ÏÖTrickbotµÄбäÖÖѡȡ¹ý³ÌÍڿյĴúÂë×¢Èë¼¼Êõ£¬´óÎÞÊý°²È«²úÆ·¶¼ÎÞ·¨¼ì²âµ½ÕâÖÖÍþв¡£¸Ã±äÌåµÄÐÐΪģʽÀàËÆÓÚÒøÐÐľÂíFlokibot¡£
ÔÎÄÁ´½Ó£ºhttps://www.cyberbit.com/blog/endpoint-security/latest-trickbot-variant-has-new-tricks-up-its-sleeve/
¡¾·ì϶²¹¶¡¡¿×êÑÐÈËÔ±Åû¶¼ÓÄôóISPµÄTRSϵͳÖеÄÒ»¸ö°²È«·ì϶
8ÔÂ19ÈÕProject InsecurityµÄÁ½Ãû°²È«×êÑÐÈËÔ±Dominik PennerºÍManny MandÅû¶Soleo Communications¿ª·¢µÄTRSϵͳ´æÔÚÒ»¸ö±¾µØÎļþй¶·ì϶¡£TRSϵͳÊÇÖ¸µçÐÅÖм̷þÎñ£¬ÓÃÓÚÔ®ÊÖ¶úÁû»ò˵»°×谵Ȳм²ÈËͨ¹ý¼üÅÌ»òÆäËü¸¨ÖúÉ豸²¦´òµç»°¡£¼ÓÄôóµÄËùÓÐÖØÒªISP¶¼ÊÜÓ°Ï죬Ô̺¬Rogers¡¢TelusºÍBCEµÈ£¬ÕâЩISPµÄ·þÎñ¶ÔÏóº¸ÇÁ˳¬¹ý3000Íò¼ÓÄôó¹«Ãñ¡£ËùÓеÄÖØÒª¼ÓÄôóISP¶¼ÒѾ½¨¸´Á˸÷ì϶¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/canadian-telcos-patch-vulnerability-in-trs-systems/


¾©¹«Íø°²±¸11010802024551ºÅ