AMCAÊý¾Ýй¶»¹²¨¼°Ô¼770ÍòLabCorp¿Í»§£»ÑÇÂíÑ·CloudFront CDN±»×¢ÈëMagecart¶ñÒâ´úÂë

°ä²¼¹¦·ò 2019-06-06
1.AMCAÊý¾Ýй¶»¹²¨¼°Ô¼770ÍòLabCorp¿Í»§

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


LabCorpÒ²Êܵ½µÚÈý·½¹©¸øÉÌAMCAÊý¾Ýй¶ÊÂÎñµÄÓ°Ï죬Լ770Íò¿Í»§ÐÅϢй¶¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢µØÖ·¡¢µç»°ºÅÂë¡¢·þÎñÈÕÆÚÒÔ¼°ÐÅÓþ¿¨ºÍÒøÐÐÐÅÏ¢µÈ¡£¸ÃÊÂÎñ²úÉúÔÚ2018Äê8ÔÂ1ÈÕÖÁ2019Äê3ÔÂ30ÈÕÖ®¼ä£¬´Ëǰ±íý±¨Â·Quest DiagnosticsµÄ¿Í»§ÐÅÏ¢ÔÚ¸ÃÊÂÎñÖÐй¶¡£LabCorp°µÊ¾¿Í»§µÄÉç»á°²È«ºÅÂ벢δй¶£¬´Ë±í¿Í»§µÄ¼ì²âÁ˾֡¢Ò½ÁÆÕï¶ÏÐÅϢҲδй¶¡£

   

Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/around-77-million-labcorp-customers-impacted-from-amca-data-breach-c3edd754

2.UChicago MedicineÒâ±íй¶150Íò¾èÔùÕßÐÅÏ¢


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÓÉÓÚElasticSearch·þÎñÆ÷δÉèÃÜÂ룬UChicago MedicineÒâ±íй¶³¬¹ý150Íò¾èÔùÕßµÄÃô¸ÐÐÅÏ¢¡£ÕâÒ»ÊÂÎñÊÇÓɰ²È«×êÑÐÔ±Bob DiachenkoÔÚ5ÔÂ28ÈÕ·¢ÏÖ£¬ÔÚ½Óµ½»ã±¨ºó£¬¸Ã´óѧÔÚ48Ó×ʱÄÚ¶ÔÊý¾Ý¿â²ÉÈ¡Á˱£»¤´ëÊ©¡£Ð¹Â¶µÄÊý¾Ý¿â´óÓ×Ϊ34GB£¬Ô̺¬¾èÔùÕßµÄÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢µØÖ·¡¢µç»°ºÅÂë¡¢ÓÊÏ䵨ַ¡¢ÐԱ𡢻éÒöÇé¿ö¡¢²Æ¸»ÐÅÏ¢µÈ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/private-info-of-over-15m-donors-exposed-by-uchicago-medicine/

3.ÓÌÌ«ÉçÇøÔ¼»áAPP JCrushÒâ±íй¶20ÍòÓû§¼Í¼

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

רΪÓÌÌ«ÉçÇøÌṩ·þÎñµÄÔ¼»áAPP JCrushÒòÊý¾Ý¿âδÉèÃÜÂëÒâ±íй¶½ü20ÍòÓû§µÄÃô¸ÐÐÅÏ¢£¬Ô̺¬ÐÕÃû¡¢ÐÔ±ð¡¢ÓÊÏ䵨ַ¡¢IPµØÖ·¡¢µØÀíµØÎ»¡¢µ®ÉúÈÕÆÚ¡¢×Ú½ÌÐÅÑöÒÔ¼°ÕÕÆ¬µÈ¡£×êÑÐÈËÔ±Noam RotemºÍRan Locar·¢ÏÖÁËÕâһй¶ÊÂÎñ£¬Æ¾¾Ý×êÑÐÈËÔ±µÄ±íÊö£¬¸ÃÊý¾Ý¿â´æ´¢µÄÄÚÈݾùδ½øÐмÓÃÜ£¬ÆäÖÐһЩÓû§¼Í¼¿ÉÖ±½ÓÓëFacebook ID¹ØÁª¡£JCrushĸ¹«Ë¾Northsight CapitalÒѶԸÃÊý¾Ý¿â²ÉÈ¡Á˱£»¤´ëÊ©¡£

  

Ô­ÎÄÁ´½Ó£º

https://techcrunch.com/2019/06/04/jcrush-exposed-data-messages/

4.ÑÇÂíÑ·CloudFront CDN±»×¢ÈëMagecart¶ñÒâ´úÂë


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝMalwarebytes Labs°ä²¼µÄ»ã±¨£¬ÑÇÂíÑ·µÄCloudFront CDN±»¹¥»÷Õß×¢ÈëÖ¼ÔÚÇÔÈ¡ÒøÐп¨ÐÅÏ¢µÄMagecart¶ñÒâ´úÂë¡£ÕâЩ¶ñÒâJavaScript¾ç±¾ÀûÓÃBase64ºÍhex±àÂëÀ´°µ²ØÆäpayload£¬²¢½«ÇÔÈ¡µÄÐÅÏ¢±àÂëºó·¢Ëͻع¥»÷ÕߵĻù´¡ÉèÊ©¡£¸Ã¹¥»÷»î¶¯Ê¹ÓõÄһЩÓòÃû£¨ÀýÈçfont-assets[.]com£©Óë֮ǰRiskIQ»ã±¨µÄһЩ¹©¸øÁ´¹¥»÷Ò»Ñù¡£

  

Ô­ÎÄÁ´½Ó£º

https://blog.malwarebytes.com/threat-analysis/2019/06/magecart-skimmers-found-on-amazon-cloudfront-cdn/

5.APT×éÖ¯Gamaredonй¥»÷»î¶¯£¬ÖØÒªÕë¶ÔÎÚ¿ËÀ¼


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Cybaze-Yoroi ZLAB×êÑÐÈËÔ±·¢ÏÖAPT×éÖ¯Gamaredon GroupµÄз¸×ï»î¶¯£¬¹¥»÷ÕßÖØÒªÕë¶ÔÎÚ¿ËÀ¼È·µ±¾Ö»ú¹¹¡¢¾ü¶Ó¼°·¨Âɲ¿ÃŵĹÙÔ±¡£¹¥»÷Õß·¢Ë͵Ĵ¹µöÓʼþÖÐÔ̺¬¶ñÒâµÄRAR¸½¼þ£¬¸Ã¸½¼þÖÐÔ̺¬¡°.scr¡±ÌåʽµÄ¶ñÒâÎĵµ£¬ÆäÏÂÔØ²¢Ö´ÐеÄpayloadÓÃÓÚÇÔȡϵͳÐÅÏ¢¼°¿ªÊÍÔ¶¿ØÄ¾ÂíUltraVNC¡£¸ÃscrÎļþÔÚVirusTotalÉϵļì²âÂʽϵÍ£¬Ö»ÓÐ4¸öɱÈí½«Æä¼ø±ðΪ¶ñÒâÎļþ¡£

  

Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/security-researchers-uncover-new-campaign-linked-to-gamaredon-group-44a5eb92

6.Ðéα¼ÓÃÜÇ®±ÒÂòÂôƽ̨Cryptohopper£¬·Ö·¢VidarľÂí


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


×êÑÐÈËÔ±Fumik0_·¢ÏÖ¹¥»÷ÕßÒѾ­´´½¨ÁËÒ»¸öÐéαµÄ¼ÓÃÜÇ®±ÒÂòÂôƽ̨Cryptohopper£¬µ±Óû§½Ó¼û¸Ãƽ̨ʱ£¬½«»á×Ô¶¯ÏÂÔØÒ»¸öSetup.exe£¬¸Ã¶ñÒâÎļþʹÓÃCryptoHopperµÄlogo£¬µ«ÏÖʵÉÏÊÇVidarľÂíµÄ±äÌå¡£¸Ã±äÌåζÔÚÊÜϰȾµÄ»úеÉϼÓÔØÒ»¸ö¶ñÒâ¿ó¹¤ºÍÒ»¸ö¼ôÌù°å½Ù³Ö¹¤¾ß£¬ÒÔÇÔÈ¡Óû§µÄÍ´´¦ºÍ¼ÓÃÜÇ®±Ò¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fake-cryptocurrency-trading-site-pushes-crypto-stealing-malware/