°Í»ù˹̹1.15ÒÚÒÆ¶¯Óû§Êý¾ÝÔÚ°µÍøÏúÊÛ £»×êÑÐÈËÔ±ÀûÓÃ3D´òÓ¡ÈÆ¹ýÆ»¹û¡¢Î¢Èí¼°ÈýÐǵÄÖ¸ÎÆÈÏÖ¤

°ä²¼¹¦·ò 2020-04-13

1.°Í»ù˹̹1.15ÒÚÒÆ¶¯Óû§Êý¾ÝÔÚ°µÍøÏúÊÛ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°Í»ù˹̹°²È«³§ÉÌRewterz·¢ÏÖ£¬Ä¿Ç°ÓÐ1.15ÒÚ°Í»ùË¹Ì¹ÒÆ¶¯Óû§µÄÊý¾ÝÔÚ°µÍøÂÛ̳ÏúÊÛ£¬¼ÛֵΪ300 BTC£¨Ô¼ºÏ210ÍòÃÀÔª£© ¡£ÕâЩÊý¾ÝÔ̺¬Óû§µÄ¾ßÌåÓ×ÎÒÐÅÏ¢£¬ÀýÈçÐÕÃû¡¢ÆëÈ«µØÖ·¡¢ÊÖ»úºÅÂëÒÔ¼°NICºÅºÍ˰ÎñºÅÂë ¡£RewterzÍþвµý±¨×¨¼ÒÒÔΪÕâЩÊý¾Ý¿ÉÄÜÊÇÒ»´Î»òÂÅ´Îй¶µÄÁ˾Ö£¬Ä¿Ç°»¹²»Ã÷ÏÔÊÇ·ñÓÐÈκÎÌØ¶¨µÄµçÐÅÔËÓªÉÌ»òÊÇËùÓеçÐÅÔËÓªÉ̳ÉΪÕâ´Î¹¥»÷µÄÊܺ¦Õß ¡£¸Ãй¶Êý¾ÝµÄ¹æÄ£Òý·¢Á˶ԵçÐŹ«Ë¾Êý¾Ý°²È«ÐÔºÍÒþÖÔÐÔµÄÓÇÓô ¡£


Ô­ÎÄÁ´½Ó£º

http://www.rewterz.com/articles/115-million-pakistani-mobile-users-data-go-on-sale-on-dark-web


2.ÓÎÏ·ÊÖ±ú³§ÉÌSCUF Gamingй¶110ÍòÌõ¿Í»§¼Í¼


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÓÎÏ·ÊÖ±ú³§ÉÌSCUF GamingµÄÒ»¸ö¿Í»§Êý¾Ý¿âÔÚÍøÉ϶³ö£¬¸ÃÊý¾Ý¿âÔ̺¬³¬¹ý110ÍòÌõ¿Í»§¼Í¼£¬º­¸Ç¿Í»§µÄÐÕÃû¡¢ÁªÏµ·½Ê½¡¢Ö§¸¶ÐÅÏ¢¡¢¶©µ¥º¹Çà¼Í¼ºÍά½¨µ¥¾ÝµÈÊý¾Ý ¡£Comparitech°²È«×êÑÐÍŶÓÔÚÍøÉÏ·¢ÏÖÁ˸ÃÊý¾Ý¿â£¬Êý¾Ý¿âÖеĴóÎÞÊý¼ÍÂ¼ËÆºõÊÇÓÉSCUF GamingÔÚ2017ÄêÖÁ2020ÄêÆÚ¼äÍøÂçµÄ£¬¸ÃÊý¾Ý¿âÔÚÍøÉ϶³öµÄ¹¦·ò²»µ½48Ó×ʱ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.comparitech.com/blog/information-security/scuf-gaming-data-leak/


3.Òâ´óÀûMonte dei PaschiÒøÐÐÔ±¹¤ÓÊÏäÔâºÚ¿ÍÈëÇÖ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Òâ´óÀû¹úÓÐÒøÐÐMonte dei PaschiÔâµ½ÍøÂç¹¥»÷£¬ºÚ¿ÍÈëÇÖÁ˲¿ÃÅÔ±¹¤µÄÓÊÏä²¢Ïò¿Í»§·¢ËÍÁË´øÓÐÓïÒô¸½¼þµÄµç×ÓÓʼþ ¡£¾Ý·͸É籨·£¬¸Ã¹¥»÷²úÉúÔÚ3ÔÂ30ÈÕ£¬¸ÃÒøÐÐûÓÐй©ÊÇ·ñº±¼û¾ÝÔ⵽й¶£¬Ò²Ã»ÓÐÌá¼°ÊÇ·ñÓÐÈκοͻ§ÒòÕâЩÓʼþÔâ·êËðʧ ¡£¸ÃÒøÐÐҲûÓÐÌá¹©ÍøÂç¹¥»÷µÄ¾ßÌåϸ½Ú£¬Ä¿Ç°Éв»Ã÷ÏÔ¹¥»÷ÕßÊÇ·ñ½Ó¼ûÁ˹«Ë¾Êý¾Ý ¡£ÓÉÓÚ½üÆÚCOVID-19µÄ·¢×÷£¬ºÜ¶àÒøÐÓ×¢µ±¾Ö»ú¹¹ÉõÖÁÒ½ÁÆ·þÎñ»ú¹¹¶¼³ÉÎªÍøÂç¹¥»÷ÕßµÄÖ¸±ê£¬½¨Òé¿Í»§¶ÔÒÔCOVID-19ΪÖ÷ÌâµÄµç×ÓÓʼþά³Ö¾¯Ìè ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/101427/cyber-crime/monte-dei-paschi-hack.html


4.×êÑÐÈËÔ±ÀûÓÃ3D´òÓ¡ÈÆ¹ýÆ»¹û¡¢Î¢Èí¼°ÈýÐǵÄÖ¸ÎÆÈÏÖ¤


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


×êÑÐÈËÔ±·¢ÏÖ£¬Äܹ»ÀûÓñãÒ˵Ä3D´òÓ¡»úÈÆ¹ýÆ»¹û¡¢Î¢ÈíºÍÈýÐÇÉ豸µÄÖ¸ÎÆÈÏÖ¤ ¡£ËûÃǹ滮µÄÔ¤ËãΪ2000ÃÀÔª£¬ÔÚ13̨ÖÇÄÜÊÖ»ú¡¢±Ê¼Ç±¾µçÄÔ¡¢Æ½°åµçÄÔµÈÉ豸ÉÏ£¨Ô̺¬iPhone 8¡¢ÈýÐÇS10¡¢Macbook Pro 2018¡¢åÚÏëYogaºÍAICase Padlock£©½øÐÐÁ˲âÊÔ£¬¾ùÔȳɹ¦ÂÊԼΪ80%£¬Ö»¹Ü¹¥»÷²¢²»ÈÝÒ× ¡£×êÑÐÈËÔ±¶Ô¶àÖÖÄ£¾ß×ÊÁϽøÐÐÁ˲âÊÔ£¬Ô̺¬¹èÒÔ¼°»ìºÏÓе¼µç·ÛÄ©µÄ¸÷Àེˮ£¬ËûÃǵij¢ÊÔÖÐ×îÓÐЧµÄ×ÊÁÏÊǵͳɱ¾µÄÖ¯Îコ ¡£×êÑÐÈËÔ±µÄ½áÂÛÊÇ£¬Ö¸ÎÆÈÏÖ¤×ãÒÔ± £»¤´óÎÞÊýÈË£¬µ«ÊÇÈôÊÇ×ʽðÐÛºñ»ò»ý¼«ÐԸߵĹ¥»÷Õß¾ö¶¨Ñ¡È¡ÕâÖÖ¹¥»÷·½Ê½£¬Ôò¸ß¼ÛÖµÖ¸±ê¿ÉÄÜ»áÎî¶Ô·çÏÕ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.darkreading.com/endpoint/researchers-fool-biometric-scanners-with-3d-printed-fingerprints/d/d-id/1337522


5.ºÉÀ¼¾¯·½Ò»ÖÜÄÚÈ¡µÞ15¸öDDoS³ö×â·þÎñ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ºÉÀ¼¾¯·½°µÊ¾ËûÃÇÔÚÒ»ÖÜÄڳɹ¦È¡µÞÁË15¸öDDoS³ö×â·þÎñ£¬ÕâЩ·þÎñÔÊÐíÓû§×¢²á²¢ÌáÒéÕë¶ÔÆäËüÍøÕ¾»òÍøÂç»ù´¡ÉèÊ©µÄDDoS¹¥»÷ ¡£ºÉÀ¼µ±¾Ö°µÊ¾Ðж¯²úÉúÔÚÉÏÖÜ£¬ËûÃǵõ½ÁËÍøÂçÍйܹ«Ë¾¡¢ÓòÃû×¢²áÉÌ¡¢Å·ÖÞÐ̾¯×éÖ¯¡¢¹ú¼ÊÐ̾¯×éÖ¯ºÍFBIµÄÖ§³Ö ¡£µ±¾ÖûÓа䲼15¸öDDoS³ö×â·þÎñµÄÃû³Æ ¡£ÕâÊÇ´ÓǰÁù¸öÔÂÖкÉÀ¼¾¯·½µÚ¶þ´Î¶ÔDDoS³ö×â·þÎñ½øÐÐÈ¡µÞ ¡£ÔÚ2019Äê10Ô·Ý£¬ºÉÀ¼¾¯·½¹Ø¹ØÁËÒ»¼ÒÍøÂçÍйܹ«Ë¾£¬¸Ã¹«Ë¾ÎªÊýÊ®¸öDDoS½©Ê¬ÍøÂçÌṩÍйܷþÎñºÍºó¶Ë»ù´¡¼Ü¹¹ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/dutch-police-take-down-15-ddos-services-in-a-week/


6.×êÑÐÈËÔ±·¢ÏÖÕë¶ÔWooCommerce²å¼þµÄÐÂÆ²ÔüÆ÷¹¥»÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


SucuriµÄ°²È«×¨¼Ò·¢ÏÖÒ»¸öÕë¶ÔʹÓÃWooCommerce²å¼þµÄWordPressµç×ÓÉÌÎñÍøÕ¾µÄÐÂÆ²ÔüÆ÷¹¥»÷£¬¸Ã¶ñÒâ¾ç±¾ÓëMagecart¹¥»÷ÖÐʹÓõÄÀàËÆ¾ç±¾·ÖÆç ¡£¸Ã¶ñÒâ¾ç±¾±»×¢Èëµ½¡°./wp-includes/rest-api/class-wp-rest-api.php¡±ÎļþÖУ¬²¢ÇÒѡȡÁ˶à²ã±àÂëºÍ´®ÁªÒÔ°µ²ØÆäÖ÷Ìâ´úÂë ¡£¶ñÒâ¾ç±¾»áÍøÂçÓû§µÄÖ§¸¶ÐÅÏ¢£¬²¢½«¿¨ºÅºÍCVVÂëÒÔCookieµÄ´¿Îı¾Ìåʽ±£Áô£¬¶øºóʹÓúϷ¨µÄfile_put_contentsº¯Êý½«ËüÃÇ´æ´¢µ½wp-content/uploadsĿ¼ÏµÄÁ½¸öͼƬÎļþ£¨.PNGÎļþºÍJPEG£©ÖÐ ¡£ÔÚ×êÑÐÈËÔ±·ÖÎöʱ£¬Á½¸öÎļþ¶¼²»Ô̺¬Èκα»µÁµÄÊý¾Ý£¬ÕâÅú×¢¶ñÒâ´úÂëÄܹ»ÔÚ¹¥»÷Õß»ñÊØÐÅÏ¢ºó×Ô¶¯¶Ï¸ùÎļþ ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/101445/hacking/woocommerce-plugin-e-skimmer.html