Å·ÖÞÍøÂ簲ȫ¾Ö°ä²¼º£Ê²¿ÃÅÍøÂ簲ȫָÄÏ£»ÒøÐÐľÂíGinpбäÖÖ½è¼ø¶ñÒâÈí¼þAnubisµÄ´úÂë
°ä²¼¹¦·ò 2019-12-021.Å·ÖÞÍøÂ簲ȫ¾Ö°ä²¼º£Ê²¿ÃÅÍøÂ簲ȫָÄÏ

Å·ÖÞÍøÂ簲ȫ¾Ö£¨ENISA£©ÒÔ¡¶¸Û¿ÚÍøÂ簲ȫ-º£Ê²¿ÃÅÍøÂ簲ȫʵ¼Ê¡·ÎªÌâ°ä²¼Á˺£Ê²¿ÃÅÍøÂ簲ȫָÄÏ£¬Îª¸Û¿ÚÉú̬ϵͳÓÈÆäÊǸۿڵ±¾ÖºÍ´¬²ºÔËÓªÉÌÖеÄCIOºÍCISOÔì¶©ÍøÂ簲ȫսÊõÌṩÁìµ¼ºÍÔ®ÊÖ¡£¸ÃÖ¸ÄÏÁгöÁ˸ۿÚÉúÌ¬ÏµÍ³Ãæ¶ÔµÄÖØÒªÍþв£¬²¢ÃèÊöÁË¿ÉÄܶԸۿÚÉú̬ϵͳÔì³ÉÓ°ÏìµÄ¹Ø¼üÍøÂç¹¥»÷³¡¾°¡£¸ÃÖ¸ÄÏΪÖն˱£»¤ºÍÐÔÃüÖÜÆÚÖÎÀí¡¢·ì϶ÖÎÀí¡¢ÈËÁ¦×ÊÔ´°²È«¡¢¹©¸øÁ´ÖÎÀíµÈÉè¼ÆÁ˰²È«´ëÊ©¡£
ÔÎÄÁ´½Ó£º
https://www.enisa.europa.eu/publications/port-cybersecurity-good-practices-for-cybersecurity-in-the-maritime-sector/
2.×êÑл㱨ÏÔʾ½ü60%µÄ¶ñÒâ¸æ°×À´×ÔÈý¸ö¸æ°×ÉÌ
ÔÚConfiantµÄ2019ÄêµÚÈý¼¾¶ÈÐèÒªÖÊÁ¿»ã±¨ÖУ¬¸Ã¹«Ë¾·ÖÎöÁË2019Äê1ÔÂ1ÈÕµ½9ÔÂ20ÈÕÖ®¼äµÄ1200Òڴθæ°×չʾ£¬ÒÔ¶Ô¸÷Àà¶ñÒâ¸æ°×»î¶¯½øÐÐϸ·Ö¡£ÔÚÓÉConfiant¼à¿ØµÄ75¸öSSP£¨¸æ°×ÉÌ£©ÖУ¬³¬¹ý60%µÄ¶ñÒâ¸æ°×À´×ÔÆäÖÐÈý¸ö£¬±ðÀëΪSSP-H¡¢SSP-IºÍSSP-D£¬ÆäÖÐÒ»¸öSSPÉõÖÁÕ¼µ½ÁË30%ÒÔÉÏ¡£ÔÚ2019ÄêµÚÈý¼¾¶È£¬Ëĸö·¸×ïÍÅ»ïÕÆ¹Ü·Ö·¢´óÎÞÊý¶ñÒâ¸æ°×£¬Ô̺¬Scamclub¡¢eGobbler¡¢RunPMKºÍZirconium¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/almost-60-percent-of-malicious-ads-come-from-three-ad-providers/
3.SMA W2ÖÇÄÜÊÖ±©Â¶³ö5000¶à¶ùͯµÄλÏàÐÅÏ¢
ƾ¾ÝAV-TESTµÄÎïÁªÍø²âÊÔ²¿ÃŰ䲼µÄÒ»·Ý»ã±¨£¬SMA W2¶ùͯÖÇÄÜÍó±í´æÔÚ¶à¸ö·ì϶£¬µ¼ÖÂ5000¶àÃû¶ùͯµÄλÏàÐÅϢ¶³ö¡£Ê×ÏÈÆäWeb API·þÎñÆ÷ûÓÐÑéÖ¤Éí·ÝÑéÖ¤ÁîÅÆµÄÓÐЧÐÔ£¬µ¼Ö¹¥»÷ÕßÄܹ»Ïνӵ½¸ÃWeb API£¬ä¯ÀÀËùÓÐЧ»§µÄIP²¢ÍøÂç¶ùͯ¼°Æä¸¸Ä¸µÄÊý¾Ý¡£×êÑÐÈËÔ±¿ÉÄܼø±ð³ö5000¶àÃû¶ùͯºÍ10000¶àÃû¼Ò³¤µÄÕË»§£¬´óÎÞÊý¶ùͯλÓÚÅ·ÖÞ£¬Ô̺¬ºÉÀ¼¡¢²¨À¼¡¢ÍÁ¶úÆä¡¢µÂ¹ú¡¢Î÷°àÑÀºÍ±ÈÀûʱµÈ¹ú¶È¡£¹¥»÷Õß»¹Äܹ»Í¨¹ýÅú¸ÄÖ÷ÅäÖÃÎļþÖеÄÓû§IDÀ´Ç¿ÔìÓë¶ùͯÖÇÄÜÍó±íÅä¶Ô£¬ÕâÒ»²Ù×÷ÎÞÐ踸ÕË»§µÄÓÊÏ䵨ַºÍÃÜÂë¡£Åä¶Ôºó£¬¹¥»÷Õß¾ÍÄܹ»¸ú×Ù¶ùͯµØÎ»²¢²¦´òÓïÒôµç»°¡£µÂ¹ú·ÖÏúÉÌPearlÒÑÔÚ½Óµ½»ã±¨ºóϼÜÁ˸ÃÖÇÄÜÍó±í¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/cheap-kids-smartwatch-exposes-the-location-of-5000-children/
4.ÒøÐÐľÂíGinpбäÖÖ½è¼ø¶ñÒâÈí¼þAnubisµÄ´úÂë

ThreatFabric°²È«×¨¼Ò·¢ÏÖAndroidÒøÐÐľÂíGinpµÄ×îбäÖÖ¿ÉÇÔÈ¡µÇ¼ʹ´¦ºÍÐÅÓþ¿¨Êý¾Ý¡£×êÑÐÈËÔ±ÒÔΪGinp×Ô6Ô·ÝÒÔÀ´Ò»Ïò»îÔ¾£¬¸Ã¶ñÒâÈí¼þÒѽøÐÐÁËÎå´Î³Á´ó¸üУ¬ÆäÖÐ×î½üµÄ¸üÐÂ½è¼øÁËÒøÐÐľÂíAnubisµÄ´úÂë¡£¸Ã±äÌå²»ÔÙÕë¶ÔÉç½»APP£¬¶øÊÇÕë¶ÔÒøÐУ¬ÖØÒªÊÇÎ÷°àÑÀÒøÐС£ÆäÖ¸±êÁбíÔ̺¬7¼Ò·ÖÆçµÄÒøÐУ¬Ô̺¬Caixa¡¢Bankinter¡¢Bankia¡¢BBVA¡¢EVO Banco¡¢KutxabankºÍSantander¡£×êÑÐÈËÔ±ÒÔΪ¸Ã¶ñÒâÈí¼þµÄ×÷ÕßÔÚ½«ÆäÒµÎñÀ©´óÖÁÆäËü¹ú¶È¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/94533/cyber-crime/ginp-android-trojan-anubis.html
5.CStealer¿ÉÇÔÈ¡ChromeÍ´´¦²¢·¢ËÍÖÁÔ¶³ÌMongoDB

ÐÂWindowsľÂíCStealer¿ÉÇÔÈ¡±£ÁôÔڹȸèChromeÃÜÂëÖÎÀíÆ÷ÖеĵǼʹ´¦¡£Æ¾¾ÝMalwareHunterTeamµÄ·ÖÎö£¬¸Ã¶ñÒâÈí¼þûÓн«ÇÔÈ¡µÄÃÜÂë±àÒë³ÉÎļþ²¢·¢ËÍÖÁ¹¥»÷Õß½ÚÔìµÄC2·þÎñÆ÷£¬¶øÊÇÖ±½ÓÏνӵ½Ô¶³ÌMongoDBÊý¾Ý¿â²¢Ê¹ÓÃËüÀ´´æ´¢ÇÔÈ¡µÄÍ´´¦¡£Îª´Ë£¬¸Ã¶ñÒâÈí¼þÓ²±àÂëÁËMongoDBµÄÍ´´¦£¬²¢ÀûÓÃMongoDB CÇý¶¯·¨Ê½×÷Ϊ¿Í»§¶Ë¿âÏνӵ½Ô¶³ÌÊý¾Ý¿â¡£ÕâʹµÃÈκÎÈ˶¼Äܹ»Í¨¹ý¸ÃÓ²±àÂëµÄÍ´´¦½Ó¼û±»µÁµÄÓû§ÃÜÂë¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-chrome-password-stealer-sends-stolen-data-to-a-mongodb-database/
6.TrueDialogÒâ±íй¶Êý°ÙÍòÌõ¿Í»§¶ÌÐżÍ¼
°²È«×êÑÐÈËÔ±Noam RotemºÍRan Locar·¢ÏÖÒ»¸öÔ̺¬Êý°ÙÍòÌõ¶ÌÐżÍ¼µÄ¶³öÊý¾Ý¿â£¬¸ÃÊý¾Ý¿âÊôÓÚTrueDialog£¬ÆäÖдó²¿ÃŶÌÐÅÊÇÓÉÆóÒµ·¢Ë͸øËüÃǵÄDZÔÚ¿Í»§µÄ¡£TrueDialogÊǵ¿ËÈøË¹ÖݰÂ˹͡ÊеÄÒ»¼ÒΪÆóÒµºÍ¸ßµµ½ÌÓý»ú¹¹ÌṩÉÌÓöÌÕÛ·þÎñµÄ¹«Ë¾£¬¸ÃÊý¾Ý¿â´æ´¢Á˿ͻ§·¢Ë͵ĶÌÐÅ£¬µ«ÓÉÓÚδÉèÃÜÂ룬ʹµÃ»¥ÁªÍøÉϵÄÈκÎÈ˶¼¿É²é¿´Êý¾Ý¡£²¿ÃżÍ¼Ô̺¬Óйشóѧ²ÆÕþÀûÓ÷¨Ê½µÄÐÅÏ¢¡¢ÆóÒµµÄÕÛ¿ÛÂëÓªÏúÐÅÏ¢¡¢ÔÚÏßÒ½ÁÆ·þÎñµÄÑéÖ¤Âë¡¢FacebookºÍGoogleÕÊ»§µÄÍøÕ¾ÃÜÂë³ÁÖú͵Ǽ´úÂëÉõÖÁTrueDialog¿Í»§µÄÓû§ÃûºÍÃÜÂëµÈ¡£
ÔÎÄÁ´½Ó£º
https://techcrunch.com/2019/12/01/millions-sms-messages-exposed/


¾©¹«Íø°²±¸11010802024551ºÅ