CNCERT°ä²¼¡¶2019ÄêÉϰëÄêÎÒ¹ú»¥ÁªÍøÍøÂç°²È«Ì¬ÊÆ¡·£»Sweet ChatÒâ±íй¶½ü1000ÍòÓû§µÄÕÕÆ¬¼°Ì¸ÌìÄÚÈÝ
°ä²¼¹¦·ò 2019-08-14
ÔÎÄÁ´½Ó£ºhttps://www.cert.org.cn/publish/main/upload/File/2019%20First%20half%20year%20.pdf
2¡¢Sweet ChatÒâ±íй¶½ü1000ÍòÓû§µÄÕÕÆ¬¼°Ì¸ÌìÄÚÈÝ
°²È«×êÑÐÔ±Darryl Burke·¢ÏÖ̸ÌìÀûÓÃSweet ChatµÄÒ»¸ö²»°²È«µÄ·þÎñÆ÷¶³öÁ˳¬¹ý1000ÍòÓû§µÄÃô¸ÐÐÅÏ¢£¬ÕâЩÐÅÏ¢Ô̺¬ÊµÊ±Ì¸ÌìÄÚÈÝÒÔ¼°¸öÈËÕÕÆ¬µÈ¡£Burke°µÊ¾ÈκÎÕ¼ÓÐMQTT¹¥»÷¹¤¾ßµÄÈ˶¼Äܹ»ÔÚÏ߲鿴ÕâЩÐÅÏ¢¡£×êÑÐÈËÔ±ÓÚ7ÔÂ21ÈÕ֪ͨÁ˸ù«Ë¾£¬µ«¸Ã¹«Ë¾Ö±ÖÁ8ÔÂ12ÈղŶԸ÷þÎñÆ÷½øÐÐÁËһʱ½¨¸´¡£
ÔÎÄÁ´½Ó£ºhttps://blog.burke-consulting.net/sweet-chat/
3¡¢LEEÊý¾Ý¿âδÉèÃÜÂ룬369ÍòÓû§µÄÒþÖÔÐÅϢй¶
°²È«×êÑÐÔ±Jeremiah Fowler·¢ÏÖÊôÓÚ·ÇͶ»ú×éÖ¯LEEµÄÒ»¸öElasticsearchÊý¾Ý¿âδÊܱ£»¤£¬µ¼ÖÂ369ÍòÓû§µÄ520ÍòÌõÃô¸Ð¼Í¼й¶¡£Êý¾Ý¿âÖÐÔ̺¬µÄÃô¸ÐÐÅÏ¢Ô̺¬ÐÕÃû¡¢¼Òͥסַ¡¢ÐÔ±ð¡¢ÖÖ×åÒÔ¼°IPµØÖ·¡¢¶Ë±êÓï¡¢õè¾¶ÒÔ¼°´æ´¢ÐÅÏ¢µÈ¡£ÔÚ½Óµ½»ã±¨ºó£¬¸Ã×éÖ¯ÓÚ7ÔÂ31ÈÕÒÆ³ýÁËÊý¾Ý¿âµÄ¹«¿ª½Ó¼ûȨÏÞ¡£
ÔÎÄÁ´½Ó£ºhttps://securitydiscovery.com/leadership-for-educational-equity/
4¡¢Charleston CountyÒâ±íй¶800ÃûÔ±¹¤µÄÃô¸ÐÐÅÏ¢
ÃÀ¹úCharleston CountyÒâ±íй¶ÁË824ÃûÔ±¹¤µÄÒþÖÔÐÅÏ¢¡£Æ¾¾Ý±¾µØ¾¯Ô±³¤°ì¹«Êҽӹܵ½µÄ֪ͨ£¬ÕâÒ»ÊÂÎñµÄÆðÒòÊDZ¨´ðʧÎó£¬Ò»ÃûHRÃýÎ󵨽«Ô±¹¤ÐÅÏ¢ÁÐ±í·¢Ë͸øÒ»ÃûǰԱ¹¤¡£ÁбíÖеÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢Éç»á°²È«ºÅÂë¡¢ÐÔ±ð¡¢Ð½Ë®¡¢¹ÍÓ¶ÈÕÆÚÒÔ¼°ÓÐ¹ØÆÀ¼ÛµÈ¡£Ã»ÓÐÒøÐп¨ÐÅϢй¶¡£
ÔÎÄÁ´½Ó£ºhttps://www.live5news.com/2019/08/13/data-breach-exposes-information-more-than-charleston-co-employees/
5¡¢ÐÂAndroidÒøÐÐľÂíCerberus£¬¶Ô×¼30¶à¼ÒÒøÐÐ
ÐÂAndroidÒøÐÐľÂíCerberusÔÚ°µÍøÌṩ×âÓ÷þÎñ¡£CerberusµÄ¿ª·¢ÕßÔÚTwitterÉϳÆCerberus²¢Ã»ÓÐʹÓÃÈκÎÏÖÓÐÒøÐÐľÂíµÄ´úÂë¡£Ëû»¹°µÊ¾¸ÃľÂíÒÑÔÚ´ÓǰÁ½ÄêÖб»ÓÃÓÚ˽ÃܵĹ¥»÷»î¶¯£¬²¢ÓÚÁ½¸öÔÂǰÆðÍ·Ìṩ³ö×â·þÎñ£¬¼ÛֵΪ2000ÃÀÔªÒ»¸öÔ£¬°ëÄê»òÄê×âÓÐÓŻݡ£Æ¾¾ÝThreat Fabric×êÑÐÈËÔ±µÄ»ã±¨£¬¸ÃÒøÐÐľÂíͬʱ»¹ÓµÓÐÔ¶¿ØÖ°ÄÜ£¬¿ÉÕë¶Ô30¸öÖ¸±ê×éÖ¯£¬Ô̺¬7¼Ò·¨¹úÒøÐÓ×¢7¼ÒÃÀ¹úÒøÐкÍ1¼ÒÈÕ±¾ÒøÐеȡ£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/08/cerberus-android-banking-trojan.html
6¡¢Ð¶ñÒâÈí¼þXwo£¬ÖØÒªÇÔÈ¡Óû§µÄµÇ¼ʹ´¦
AT&T×êÑÐÍŶӷ¢ÏÖжñÒâÈí¼þXwo£¬¸Ã¶ñÒâÈí¼þÖØÒªÉ¨ÃèϵͳÉÏ´æ´¢µÄÍ´´¦ÒÔ¼°Â¶³öµÄ·þÎñ£¬²¢½«É¨ÃèÁ˾ַ¢ËÍÖÁC&C·þÎñÆ÷¡£ËüɨÃèµÄÖ¸±ê·þÎñÔ̺¬Ê¹ÓÃĬÈÏÃÜÂëµÄMongoDB¡¢Memcached¡¢MySQL¡¢PostgreSQL¡¢Tomcat¡¢RedisÒÔ¼°FTPµÈ£¬Ëü»¹Äܹ»´ÓĬÈÏSVN¼°Gitõè¾¶ÍøÂçÐÅÏ¢£¬×êÑÐÈËÔ±ÒÔΪÕâÖÖÐÅÏ¢ÍøÂç¿ÉÄÜÊÇΪ½«À´µÄ´ó¹æÄ£¹¥»÷»î¶¯×ö³ï±¸¡£XwoµÄ»ù´¡ÉèÊ©ÓëMongoLock¼°X Bash´æÔÚÀàËÆÖ®´¦£¬ÕâÒâζ×ÅÕâÈý¸ö¶ñÒâÈí¼þ¿ÉÄÜÀ´×ÔÓÚͳһ¸ö¹¥»÷Õß¡£
ÔÎÄÁ´½Ó£ºhttps://www.bmmagazine.co.uk/business/new-malware-xwo-can-swipe-all-your-credentials-at-once/


¾©¹«Íø°²±¸11010802024551ºÅ