2019ÄêQ1´¹µö¹¥»÷Ç÷Ïò»ã±¨£»Êý°ÙÍòInstagramÕË»§ÐÅϢй¶£»Ë¹ÀïÀ¼¿¨11¼Ò»ú¹¹µÄ¹ÙÍøÔâºÚ¿Í¹¥»÷

°ä²¼¹¦·ò 2019-05-21
1¡¢Ë¹ÀïÀ¼¿¨11¼Ò»ú¹¹µÄ¹ÙÍøÔâºÚ¿Í¹¥»÷

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
¾Ý±íý±¨Â·£¬5ÔÂ18ÈÕ˹ÀïÀ¼¿¨ÖÁÉÙ11¼Ò»ú¹¹µÄ¹ÙÍø£¨.lkºÍ.comÍøÕ¾£©ÔâºÚ¿Í¹¥»÷£¬ÊÜÓ°ÏìµÄ»ú¹¹Ãûµ¥Ô̺¬¿ÆÍþÌØ´óʹ¹Ý¡¢Talawakelle²èÒ¶×êÑÐËù¡¢Rajarata´óѧµÈ¡£Ë¹ÀïÀ¼¿¨SLCERT³ÆÃ»Óе±¾ÖÍøÕ¾£¨gov.lk£©Êܵ½Ó°Ïì¡£SLCERTÔÚÓëTechCERTºÍÍøÂ簲ȫÔËÓª²¿ÃźÏ×÷ÒÔµ÷²éºÍ½â¾ö´ËÊ¡£5ÔÂ18ÈÕºÍ19ÈÕÊÇ˹ÀïÀ¼¿¨±¾µØµÄÕ½ÕùÓ¢ÐÛÁôÏëÈÕ£¬¹¥»÷ÕßµÄÖ÷ÕÅ¿ÉÄÜÓë´ËÓйØ¡£


Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/websites-of-at-least-eleven-institutions-in-sri-lanka-hit-by-cyber-attacks-3d19a71f


2¡¢×êÑÐÈËÔ±·¢ÏÖ¶ñÒâÈí¼þWinntiµÄLinux±äÌå

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
Alphabet×êÑÐÈËÔ±Chronicle·¢ÏÖ¶ñÒâÈí¼þWinntiµÄLinux±äÌå¡£Chronicle°µÊ¾¸Ã±äÌåÊÇÔÚÉϸöÔ°ݶúÔìÒ©¹«Ë¾Ôâµ½¹¥»÷ºóÔÚÆäϵͳÉÏ·¢Ïֵġ£¸Ã±äÌå¿É×·ÒäÖÁ2015Ä꣬ÆäʱËü±»ÓÃÓÚÕë¶ÔÔ½ÄÏÓÎÏ·¹«Ë¾µÄºÚ¿Í¹¥»÷ÖС£¸Ã±äÌåÓÉÁ½²¿ÃÅ×é³É£ºÓÃÓÚ°µ²ØµÄrootkit×é¼þºÍÏÖʵµÄºóÃÅľÂí¡£¸ÃLinux±äÌåÓëWindows°æ±¾µÄWinnti 2.0Ö®¼ä´æÔÚ´úÂëÀàËÆÐÔ£¬²¢ÇÒÓëC&CµÄͨѶºÍ̸ҲÀàËÆ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/security-researchers-discover-linux-version-of-winnti-malware/


3¡¢TrickbotбäÌå£¬ÖØÒªÍ¨¹ýÀ¬»øÓʼþ´«²¼

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
Ç÷Ïò¿Æ¼¼×êÑÐÍŶӼì²âµ½TrickbotµÄÒ»¸öбäÌ壬¸Ã±äÌåͨ¹ýÀ¬»øÓʼþ½øÐд«²¼£¬ÆäʹÓõÄÁ´½ÓÀàËÆÓÚURL hxxps://google[.]dm:443/url?q=¡£¸ÃURLÖеIJéÎÊ×Ö·û´®²¿ÃÅ£¨url£¿q = £©Êǽ«Óû§³Á¶¨Ïòµ½µÄ¶ñÒâURL¡£ÓÉÓÚÕâÊÇÒ»¸öGoogle³Á¶¨ÏòÍøÖ·£¬Òò¶øÄܹ»Èƹý¶ÔÀ¬»øÓʼþµÄ¹ýÂ˺ͺýŪ²»ÖªÇéµÄÓû§¡£Ò»µ©Ï°È¾É豸£¬¸Ã±äÌ廹»áÀûÓÃMS17-010·ì϶½øÐкáÏòÒÆ¶¯¡£


Ô­ÎÄÁ´½Ó£ºhttps://blog.trendmicro.com/trendlabs-security-intelligence/trickbot-watch-arrival-via-redirection-url-in-spam/


4¡¢APWG°ä²¼2019ÄêQ1´¹µö¹¥»÷Ç÷Ïò»ã±¨

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
ƾ¾ÝAPWGµÄ2019ÄêQ1´¹µö¹¥»÷Ç÷Ïò»ã±¨£¬Õë¶ÔSaaSºÍÍøÂçÓʼþ·þÎñµÄ´¹µö¹¥»÷Ôö³¤ÖÁËùÓд¹µö¹¥»÷µÄ36%£¬³õ´Î³¬¹ýÁËÖ§¸¶ÏµÍ³Àà±ð£¨±¾¼¾¶È¸ÃÀà±ðÔâµ½µÄ´¹µö¹¥»÷Õ¼27%£©¡£APWG¸ß¼¶×êÑÐÔ±Greg Aaron°µÊ¾£¬´¹µöÕß¶ÔSaaSÍøÕ¾µÇ¼ʹ´¦µÄÐËÖÂÊÇÓÉÓÚËûÃÇÄܹ»Í¨¹ýÓã²æÊ½´¹µö»ñµÃ²ÆÕþÊý¾ÝºÍÓ×ÎÒÐÅÏ¢¡£2019ÄêQ1¼ì²âµ½µÄ´¹µöÍøÕ¾×ÜÊýÊÇ180768£¬±È2018ÄêQ3µÄ151014ºÍQ4µÄ138328Òª¸ß¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.helpnetsecurity.com/2019/05/20/saas-webmail-phishing-increased/


5¡¢OGUsersÂÛ̳ÔâºÚ¿ÍÈëÇÖ£¬11.3ÍòÓû§ÐÅϢй¶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
OGUsersÊÇÒ»¸öÒÔÏúÊÛµÁºÅÕË»§ÎÅÃûµÄÍøÂç·¸×ïÂÛ̳£¬Æ¾¾ÝKrebsOnSecurityµÄÐÂÎÅ£¬5ÔÂ12ÈÕOGUsersÔâºÚ¿ÍÈëÇÖ£¬Ô¼11.3ÍòÓû§µÄÓû§Ãû¡¢µç×ÓÓʼþµØÖ·¡¢¹þÏ£ÃÜÂë¡¢¸öÈËÐÂÎźÍIPµØÖ·Ð¹Â¶¡£×î³õOGUsersµÄÖÎÀíÔ±ÒÔΪÕâÊÇÒ»´ÎÓ²Å̹ÊÕÏ£¬µ«ËæºóKrebsOnSecurity´ÓÁíÒ»¸öºÚ¿ÍÂÛ̳RaidForumsÉÏ»ñµÃÁ˱»µÁÊý¾Ý¿âµÄ¸±±¾¡£


Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/cybercrime-forum-ogusers-gets-hacked-attackers-steal-data-f067bcfc


6¡¢Î´ÉèÃÜÂëµÄÊý¾Ý¿âй¶Êý°ÙÍòInstagramÕË»§ÐÅÏ¢

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
ƾ¾ÝTechCrunch±¨Â·£¬°²È«×êÑÐÔ±Anurag SenÔÚAWSÉÏ·¢ÏÖÒ»¸öδÊܱ£»¤µÄÊý¾Ý¿â£¬¸ÃÊý¾Ý¿âÔ̺¬Êý°ÙÍòInstagramÕË»§µÄÓйØÐÅÏ¢¡£Ä¿Ç°¸ÃÊý¾Ý¿âÒÑÓг¬¹ý4900Íò±Ê¼Í¼£¬µ«Êý¾ÝÁ¿ÈÔÔÚ°´Ó×ʱÔö³¤¡£¸ÃÊý¾Ý¿âÔ̺¬´óÁ¿ÃûÈË¡¢ÃÀʳ²©Ö÷¡¢Æ·ÅÆÕË»§µÅ×°ÏìÁ¦½Ï´óµÄInstagramÕË»§µÄÊý¾Ý£¬Ô̺¬Ó×ÎÒ×ÊÁÏÕÕÆ¬¡¢¹Ø×¢ÕßÊýÁ¿¡¢µØÀíµØÎ»¡¢¸öÈËÁªÏµÐÅÏ¢¡¢µç×ÓÓʼþµØÖ·ºÍµç»°ºÅÂëµÈ¡£¸ÃÊý¾Ý¿âÊôÓÚÓ¡¶ÈÉ罻ýÌåÓªÏú¹«Ë¾Chtrbox£¬Ä¿Ç°Éв»Ã÷ÏԸù«Ë¾ÈôºÎ»ñµÃÕâЩÊý¾Ý¡£


Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/85905/data-breach/instagram-data-leak.html