Imperva°ä²¼ÓйØKashmirBlack½©Ê¬ÍøÂçµÄ·ÖÎö»ã±¨£»Nitro PDF´ó¹æÄ£Êý¾Ýй¶ӰÏì΢Èí¡¢¹È¸èºÍÆ»¹ûµÈ¹«Ë¾

°ä²¼¹¦·ò 2020-10-27
1.Imperva°ä²¼ÓйØKashmirBlack½©Ê¬ÍøÂçµÄ·ÖÎö»ã±¨


1.jpg


Imperva°ä²¼ÁËÓйØKashmirBlack½©Ê¬ÍøÂçµÄ·ÖÎö»ã±¨¡£¸Ã»ã±¨ÃèÊöÁËKashmirBlack½©Ê¬ÍøÂç±³ºóµÄ·¸×ï²Ù×÷ £¬»áÉÌÁËÆäÖ÷ÕÅÒÔ¼°×êÑв½Öè¡£KashmirBlackÖØÒªÕë¶ÔÊ¢ÐеÄCMSƽ̨¡£ËüÀûÓÃÁËÖ¸±ê·þÎñÆ÷ÉϵÄÊýÊ®¸öÒÑÖª·ì϶ £¬¾ùÔÈÿÌì¶ÔÈ«Çò30¶à¸ö·ÖÆç¹ú¶ÈµÄÊýǧÃûÊܺ¦Õß½øÐÐÊý°ÙÍò´Î¹¥»÷¡£´Ë±í £¬ÆäÔËÐм«¶È¸´ÔÓ £¬ÓÉһ̨C&C·þÎñÆ÷ÖÎÀí £¬²¢Ê¹ÓÃÁË60¶ą̀·þÎñÆ÷×÷ΪÆä»ù´¡ÉèÊ©µÄÒ»²¿ÃÅ¡£¿É´¦ÖÃÊý°Ù¸ö½©Ê¬·¨Ê½ £¬Ö´Ðб©Á¦¹¥»÷¡¢×°ÖúóÃÅ¡¢²¢À©´ó½©Ê¬ÍøÂçµÄ¹æÄ£¡£    


Ô­ÎÄÁ´½Ó£º

https://www.imperva.com/blog/crimeops-of-the-kashmirblack-botnet-part-i/


2.Area1°ä²¼Office 365µç×ÓÓʼþ·ÀÓùϵͳÍþв·ÖÎö»ã±¨


2.jpg


Area1°ä²¼ÁËOffice 365µç×ÓÓʼþ·ÀÓùºÍ³ÛÃû°²È«µç×ÓÓʼþÍø¹Ø£¨SEG£©Ãæ¶ÔµÄÖØÒªÍþвµÄ·ÖÎö»ã±¨¡£»ã±¨ÏÔʾ £¬´Ó2020Äê3Ôµ½8ÔµÄÁù¸öÔÂÖÐ £¬Óг¬¹ý925000·â¶ñÒâµç×ÓÓʼþ³É¹¦ÈƹýÁËOffice 365·ÀÓùºÍSEG¡£´Ë±í £¬¹¥»÷ÕßÔ½À´Ô½¶àµØÊ¹Óø߶ȸ´Ôӵġ¢ÓÐÕë¶ÔÐԵĹ¥»÷»î¶¯À´ÌӱܻùÓÚÒÑÖªÍþвµÄ´«Í³µç×ÓÓʼþ·ÀÓù £¬ÀýÈçóÒ×µç×ÓÓʼþ¹¥»÷¡£ÆäÖÐ £¬Type 3 BECs(»ùÓÚÕË»§½ÚÔìµÄ)ºÍType 4 BEC (¹©¸øÁ´ÍøÂç´¹µö)¿ÉÄÜÒÑÔì³ÉÊýÊ®ÒÚÃÀÔªµÄDZÔÚËðʧ¡£


Ô­ÎÄÁ´½Ó£º

https://www.area1security.com/office-365-anniversary-email-threats-report/


3.×êÑÐÈËÔ±·¢ÏÖ¿Éͨ¹ýWaze APIÖзì϶׷×ÙËÁÒâÓû§µÄµØÎ»


3.jpg


×êÑÐÈËÔ±Peter Gasper·¢ÏÖ¿Éͨ¹ýWaze APIÖзì϶׷×ÙËÁÒâÓû§µÄµØÎ»¡£µ±Óû§»ã±¨Ç°·½Óз·×è°­»ò¾¯Ô±Ñ²Âßʱ £¬Waze API»á½«¸ÃÓû§µÄIDºÍÓû§Ãûһ··µ»Ø¸øÔڸô¦ËùÐÐÊ»µÄÆäËûÓû§¡£³ý·ÇÓû§½øÐÐÁË×¢½â £¬²»È»ÀûÓÃÖв»»áÏÔʾ´ËÊý¾Ý £¬µ«ÔÚAPIÏìÓ¦ÖлáÔ̺¬Óû§Ãû¡¢ID¡¢ÊÂÎñµÄµØÎ»¡¢ÉõÖÁÊǻ㱨¹¦·ò¡£ÓÉÓÚ´óÎÞÊýÓû§½«ÆäÕæÊµÐÕÃû×÷ΪÓû§Ãû £¬Òò¶ø¹¥»÷ÕßÓпɳÉÁ¢Ò»¸öÔ̺¬Óû§ÐÕÃûºÍIDµÄÊý¾Ý¿â¡£ 


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2020/10/25/waze-app-vulnerability-could-allow-tracking-users-location/


4.Nitro PDF´ó¹æÄ£Êý¾Ýй¶ӰÏì΢Èí¡¢¹È¸èºÍÆ»¹ûµÈ¹«Ë¾


4.jpg


Nitro PDF·þÎñ²úÉú´ó¹æÄ£µÄÊý¾Ýй¶ £¬Ó°ÏìÁËÔ̺¬Google¡¢Apple¡¢Microsoft¡¢ChaseºÍCitibankÔÚÄÚµÄÖî¶à³ÛÃû×éÖ¯¡£10ÔÂ21ÈÕ £¬Nitro Software°ä²¼ÁËÒ»·ÝÕ÷ѯ £¬³ÆÆäÔâµ½µÍÓ°Ï찲ȫÊÂÎñ £¬µ«Æä¿Í»§Êý¾ÝûÓÐÊܵ½ÈκÎÓ°Ïì¡£ÍøÂ簲ȫµý±¨¹«Ë¾CybleÔò°µÊ¾ £¬ºÚ¿ÍÔÚÏúÊÛÐû³ÆÊÇ´ÓNitroÔÆÖÐÇÔÈ¡µÄÓû§¡¢ÎĵµÊý¾Ý¿âÒÔ¼°1TBµÄÎĵµ¡£ÆäÖÐuser_credentialÊý¾Ý¿âÔ̺¬7000ÍòÌõÓû§¼Í¼ £¬Ô̺¬µç×ÓÓʼþµØÖ·¡¢È«Ãû¡¢bcryptÉ¢ÁÐÃÜÂ롢ͷÏΡ¢¹«Ë¾Ãû³Æ¡¢IPµØÖ·ºÍÆäËûϵͳÓйØÊý¾Ý¡£ÕâЩÊý¾Ý¿â»¹Ô̺¬ÁËÓë¸÷³ÛÃû¹«Ë¾ÓйصĴóÁ¿Îĵµ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/massive-nitro-data-breach-impacts-microsoft-google-apple-more/ 


5.Trustwave·¢ÏÖºÚ¿ÍÔÚ°µÍøÏúÊÛ1.86ÒÚÃÀ¹úÑ¡ÃñÐÅÏ¢


5.jpg


ÍøÂ簲ȫ¹«Ë¾Trustwave·¢ÏÖºÚ¿ÍÔÚ°µÍøÏúÊÛÁ˳¬¹ý2ÒÚÃÀ¹úÈ˵ÄÓ×ÎÒ¼ø±ðÐÅÏ¢ £¬ÆäÖÐÔ̺¬1.86ÒÚÃÀ¹úÑ¡ÃñÐÅÏ¢¡£Ð¹Â©µÄÊý¾ÝÔ̺¬ÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂëºÍÑ¡ÃñµÇ¼Ç¼Í¼¡£Trustwave°µÊ¾ÕâЩÊý¾ÝÊÇÓɽüÄêÀ´ÆóÒµÔâµ½¸÷À๥»÷Ëùй¶µÄÊý¾ÝÒÔ¼°´Óµ±¾ÖÍøÕ¾¼ìË÷µÄ¹«¿ªÊý¾Ý×é³ÉµÄ £¬¿ÉÓÃÓÚÉ罻ýÌå¡¢µç×ÓÓʼþÍøÂç´¹µöÒÔ¼°Îı¾ºÍµç»°Ú¿Æ­»î¶¯ºÍÐéαÐÅÏ¢Ðû´«»î¶¯¡£


Ô­ÎÄÁ´½Ó£º

https://www.nbcnews.com/politics/2020-election/cybersecurity-firm-finds-hacker-selling-info-148-million-u-s-n1244211


6.Ó¡¶ÈPTI·þÎñÆ÷ÔâLockBit¹¥»÷µ¼Ö·þÎñÁÙʱÖжÏ


6.jpg


Ó¡¶ÈPTI£¨Press Trust of India¡¯s£©ÔâLockBit¹¥»÷µ¼Ö·þÎñÁÙʱÖжÏ¡£PTI½²»°ÈËÖÜÈÕ°µÊ¾ £¬¸Ã¹«Ë¾µÄ·þÎñÆ÷Ôâ·êÁË´ó¹æÄ£ÀÕË÷Èí¼þ¹¥»÷ £¬µ¼Ö·þÎñÖжÏÁËÊýÓ×ʱ £¬¾­¹ý¹¤³Ìʦ³¹Ò¹ÖÂÁ¦ºóµÃÒÔ¸´Ô­¡£¹¥»÷²úÉúÔÚÖÜÁùÍíÉÏ10µã×óÓÒ £¬ÀÕË÷Èí¼þLockBitϰȾÁËÓ¡¶È×ÜÀíͨѶÉçÏÕЩËùÓеķþÎñÆ÷ £¬²¢¼ÓÃÜÁËËùº±¼û¾ÝºÍÀûÓ÷¨Ê½¡£µ«¸Ã½²»°È˰µÊ¾ £¬µ½ÖÜÈÕÉÏÎç9µã £¬ÆäËùÓÐÒµÎñ¸ù»ù¶¼¸´Ô­Õý³£ £¬²¢ÇÒûÓÐÖ§¸¶Êê½ð¡£


Ô­ÎÄÁ´½Ó£º

https://www.thehindubusinessline.com/info-tech/pti-services-disrupted-after-massive-ransomware-attack-on-servers/article32940254.ece