AMCAÊý¾Ýй¶»¹²¨¼°Ô¼770ÍòLabCorp¿Í»§£»ÑÇÂíÑ·CloudFront CDN±»×¢ÈëMagecart¶ñÒâ´úÂë
°ä²¼¹¦·ò 2019-06-06
ÔÎÄÁ´½Ó£º
https://cyware.com/news/around-77-million-labcorp-customers-impacted-from-amca-data-breach-c3edd7542.UChicago MedicineÒâ±íй¶150Íò¾èÔùÕßÐÅÏ¢
ÓÉÓÚElasticSearch·þÎñÆ÷δÉèÃÜÂ룬UChicago MedicineÒâ±íй¶³¬¹ý150Íò¾èÔùÕßµÄÃô¸ÐÐÅÏ¢¡£ÕâÒ»ÊÂÎñÊÇÓɰ²È«×êÑÐÔ±Bob DiachenkoÔÚ5ÔÂ28ÈÕ·¢ÏÖ£¬ÔÚ½Óµ½»ã±¨ºó£¬¸Ã´óѧÔÚ48Ó×ʱÄÚ¶ÔÊý¾Ý¿â²ÉÈ¡Á˱£»¤´ëÊ©¡£Ð¹Â¶µÄÊý¾Ý¿â´óÓ×Ϊ34GB£¬Ô̺¬¾èÔùÕßµÄÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢µØÖ·¡¢µç»°ºÅÂë¡¢ÓÊÏ䵨ַ¡¢ÐԱ𡢻éÒöÇé¿ö¡¢²Æ¸»ÐÅÏ¢µÈ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/private-info-of-over-15m-donors-exposed-by-uchicago-medicine/3.ÓÌÌ«ÉçÇøÔ¼»áAPP JCrushÒâ±íй¶20ÍòÓû§¼Í¼
רΪÓÌÌ«ÉçÇøÌṩ·þÎñµÄÔ¼»áAPP JCrushÒòÊý¾Ý¿âδÉèÃÜÂëÒâ±íй¶½ü20ÍòÓû§µÄÃô¸ÐÐÅÏ¢£¬Ô̺¬ÐÕÃû¡¢ÐÔ±ð¡¢ÓÊÏ䵨ַ¡¢IPµØÖ·¡¢µØÀíµØÎ»¡¢µ®ÉúÈÕÆÚ¡¢×Ú½ÌÐÅÑöÒÔ¼°ÕÕÆ¬µÈ¡£×êÑÐÈËÔ±Noam RotemºÍRan Locar·¢ÏÖÁËÕâһй¶ÊÂÎñ£¬Æ¾¾Ý×êÑÐÈËÔ±µÄ±íÊö£¬¸ÃÊý¾Ý¿â´æ´¢µÄÄÚÈݾùδ½øÐмÓÃÜ£¬ÆäÖÐһЩÓû§¼Í¼¿ÉÖ±½ÓÓëFacebook ID¹ØÁª¡£JCrushĸ¹«Ë¾Northsight CapitalÒѶԸÃÊý¾Ý¿â²ÉÈ¡Á˱£»¤´ëÊ©¡£
ÔÎÄÁ´½Ó£º
https://techcrunch.com/2019/06/04/jcrush-exposed-data-messages/4.ÑÇÂíÑ·CloudFront CDN±»×¢ÈëMagecart¶ñÒâ´úÂë
ƾ¾ÝMalwarebytes Labs°ä²¼µÄ»ã±¨£¬ÑÇÂíÑ·µÄCloudFront CDN±»¹¥»÷Õß×¢ÈëÖ¼ÔÚÇÔÈ¡ÒøÐп¨ÐÅÏ¢µÄMagecart¶ñÒâ´úÂë¡£ÕâЩ¶ñÒâJavaScript¾ç±¾ÀûÓÃBase64ºÍhex±àÂëÀ´°µ²ØÆäpayload£¬²¢½«ÇÔÈ¡µÄÐÅÏ¢±àÂëºó·¢Ëͻع¥»÷ÕߵĻù´¡ÉèÊ©¡£¸Ã¹¥»÷»î¶¯Ê¹ÓõÄһЩÓòÃû£¨ÀýÈçfont-assets[.]com£©Óë֮ǰRiskIQ»ã±¨µÄһЩ¹©¸øÁ´¹¥»÷Ò»Ñù¡£
ÔÎÄÁ´½Ó£º
https://blog.malwarebytes.com/threat-analysis/2019/06/magecart-skimmers-found-on-amazon-cloudfront-cdn/5.APT×éÖ¯Gamaredonй¥»÷»î¶¯£¬ÖØÒªÕë¶ÔÎÚ¿ËÀ¼
Cybaze-Yoroi ZLAB×êÑÐÈËÔ±·¢ÏÖAPT×éÖ¯Gamaredon GroupµÄз¸×ï»î¶¯£¬¹¥»÷ÕßÖØÒªÕë¶ÔÎÚ¿ËÀ¼È·µ±¾Ö»ú¹¹¡¢¾ü¶Ó¼°·¨Âɲ¿ÃŵĹÙÔ±¡£¹¥»÷Õß·¢Ë͵Ĵ¹µöÓʼþÖÐÔ̺¬¶ñÒâµÄRAR¸½¼þ£¬¸Ã¸½¼þÖÐÔ̺¬¡°.scr¡±ÌåʽµÄ¶ñÒâÎĵµ£¬ÆäÏÂÔØ²¢Ö´ÐеÄpayloadÓÃÓÚÇÔȡϵͳÐÅÏ¢¼°¿ªÊÍÔ¶¿ØÄ¾ÂíUltraVNC¡£¸ÃscrÎļþÔÚVirusTotalÉϵļì²âÂʽϵͣ¬Ö»ÓÐ4¸öɱÈí½«Æä¼ø±ðΪ¶ñÒâÎļþ¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/security-researchers-uncover-new-campaign-linked-to-gamaredon-group-44a5eb926.Ðéα¼ÓÃÜÇ®±ÒÂòÂôƽ̨Cryptohopper£¬·Ö·¢VidarľÂí
×êÑÐÈËÔ±Fumik0_·¢ÏÖ¹¥»÷ÕßÒѾ´´½¨ÁËÒ»¸öÐéαµÄ¼ÓÃÜÇ®±ÒÂòÂôƽ̨Cryptohopper£¬µ±Óû§½Ó¼û¸Ãƽ̨ʱ£¬½«»á×Ô¶¯ÏÂÔØÒ»¸öSetup.exe£¬¸Ã¶ñÒâÎļþʹÓÃCryptoHopperµÄlogo£¬µ«ÏÖʵÉÏÊÇVidarľÂíµÄ±äÌå¡£¸Ã±äÌåζÔÚÊÜϰȾµÄ»úеÉϼÓÔØÒ»¸ö¶ñÒâ¿ó¹¤ºÍÒ»¸ö¼ôÌù°å½Ù³Ö¹¤¾ß£¬ÒÔÇÔÈ¡Óû§µÄÍ´´¦ºÍ¼ÓÃÜÇ®±Ò¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/fake-cryptocurrency-trading-site-pushes-crypto-stealing-malware/


¾©¹«Íø°²±¸11010802024551ºÅ