Imperva°ä²¼ÓйØKashmirBlack½©Ê¬ÍøÂçµÄ·ÖÎö»ã±¨£»Nitro PDF´ó¹æÄ£Êý¾Ýй¶ӰÏì΢Èí¡¢¹È¸èºÍÆ»¹ûµÈ¹«Ë¾
°ä²¼¹¦·ò 2020-10-27
Imperva°ä²¼ÁËÓйØKashmirBlack½©Ê¬ÍøÂçµÄ·ÖÎö»ã±¨¡£¸Ã»ã±¨ÃèÊöÁËKashmirBlack½©Ê¬ÍøÂç±³ºóµÄ·¸×ï²Ù×÷£¬»áÉÌÁËÆäÖ÷ÕÅÒÔ¼°×êÑв½Öè¡£KashmirBlackÖØÒªÕë¶ÔÊ¢ÐеÄCMSƽ̨¡£ËüÀûÓÃÁËÖ¸±ê·þÎñÆ÷ÉϵÄÊýÊ®¸öÒÑÖª·ì϶£¬¾ùÔÈÿÌì¶ÔÈ«Çò30¶à¸ö·ÖÆç¹ú¶ÈµÄÊýǧÃûÊܺ¦Õß½øÐÐÊý°ÙÍò´Î¹¥»÷¡£´Ë±í£¬ÆäÔËÐм«¶È¸´ÔÓ£¬ÓÉһ̨C&C·þÎñÆ÷ÖÎÀí£¬²¢Ê¹ÓÃÁË60¶ą̀·þÎñÆ÷×÷ΪÆä»ù´¡ÉèÊ©µÄÒ»²¿ÃÅ¡£¿É´¦ÖÃÊý°Ù¸ö½©Ê¬·¨Ê½£¬Ö´Ðб©Á¦¹¥»÷¡¢×°ÖúóÃÅ¡¢²¢À©´ó½©Ê¬ÍøÂçµÄ¹æÄ£¡£
ÔÎÄÁ´½Ó£º
https://www.imperva.com/blog/crimeops-of-the-kashmirblack-botnet-part-i/
2.Area1°ä²¼Office 365µç×ÓÓʼþ·ÀÓùϵͳÍþв·ÖÎö»ã±¨

Area1°ä²¼ÁËOffice 365µç×ÓÓʼþ·ÀÓùºÍ³ÛÃû°²È«µç×ÓÓʼþÍø¹Ø£¨SEG£©Ãæ¶ÔµÄÖØÒªÍþвµÄ·ÖÎö»ã±¨¡£»ã±¨ÏÔʾ£¬´Ó2020Äê3Ôµ½8ÔµÄÁù¸öÔÂÖУ¬Óг¬¹ý925000·â¶ñÒâµç×ÓÓʼþ³É¹¦ÈƹýÁËOffice 365·ÀÓùºÍSEG¡£´Ë±í£¬¹¥»÷ÕßÔ½À´Ô½¶àµØÊ¹Óø߶ȸ´Ôӵġ¢ÓÐÕë¶ÔÐԵĹ¥»÷»î¶¯À´ÌӱܻùÓÚÒÑÖªÍþвµÄ´«Í³µç×ÓÓʼþ·ÀÓù£¬ÀýÈçóÒ×µç×ÓÓʼþ¹¥»÷¡£ÆäÖУ¬Type 3 BECs(»ùÓÚÕË»§½ÚÔìµÄ)ºÍType 4 BEC (¹©¸øÁ´ÍøÂç´¹µö)¿ÉÄÜÒÑÔì³ÉÊýÊ®ÒÚÃÀÔªµÄDZÔÚËðʧ¡£
ÔÎÄÁ´½Ó£º
https://www.area1security.com/office-365-anniversary-email-threats-report/
3.×êÑÐÈËÔ±·¢ÏÖ¿Éͨ¹ýWaze APIÖзì϶׷×ÙËÁÒâÓû§µÄµØÎ»

×êÑÐÈËÔ±Peter Gasper·¢ÏÖ¿Éͨ¹ýWaze APIÖзì϶׷×ÙËÁÒâÓû§µÄµØÎ»¡£µ±Óû§»ã±¨Ç°·½Óз·×è°»ò¾¯Ô±Ñ²Âßʱ£¬Waze API»á½«¸ÃÓû§µÄIDºÍÓû§Ãûһ··µ»Ø¸øÔڸô¦ËùÐÐÊ»µÄÆäËûÓû§¡£³ý·ÇÓû§½øÐÐÁË×¢½â£¬²»È»ÀûÓÃÖв»»áÏÔʾ´ËÊý¾Ý£¬µ«ÔÚAPIÏìÓ¦ÖлáÔ̺¬Óû§Ãû¡¢ID¡¢ÊÂÎñµÄµØÎ»¡¢ÉõÖÁÊǻ㱨¹¦·ò¡£ÓÉÓÚ´óÎÞÊýÓû§½«ÆäÕæÊµÐÕÃû×÷ΪÓû§Ãû£¬Òò¶ø¹¥»÷ÕßÓпɳÉÁ¢Ò»¸öÔ̺¬Óû§ÐÕÃûºÍIDµÄÊý¾Ý¿â¡£
ÔÎÄÁ´½Ó£º
https://latesthackingnews.com/2020/10/25/waze-app-vulnerability-could-allow-tracking-users-location/
4.Nitro PDF´ó¹æÄ£Êý¾Ýй¶ӰÏì΢Èí¡¢¹È¸èºÍÆ»¹ûµÈ¹«Ë¾

Nitro PDF·þÎñ²úÉú´ó¹æÄ£µÄÊý¾Ýй¶£¬Ó°ÏìÁËÔ̺¬Google¡¢Apple¡¢Microsoft¡¢ChaseºÍCitibankÔÚÄÚµÄÖî¶à³ÛÃû×éÖ¯¡£10ÔÂ21ÈÕ£¬Nitro Software°ä²¼ÁËÒ»·ÝÕ÷ѯ£¬³ÆÆäÔâµ½µÍÓ°Ï찲ȫÊÂÎñ£¬µ«Æä¿Í»§Êý¾ÝûÓÐÊܵ½ÈκÎÓ°Ïì¡£ÍøÂ簲ȫµý±¨¹«Ë¾CybleÔò°µÊ¾£¬ºÚ¿ÍÔÚÏúÊÛÐû³ÆÊÇ´ÓNitroÔÆÖÐÇÔÈ¡µÄÓû§¡¢ÎĵµÊý¾Ý¿âÒÔ¼°1TBµÄÎĵµ¡£ÆäÖÐuser_credentialÊý¾Ý¿âÔ̺¬7000ÍòÌõÓû§¼Í¼£¬Ô̺¬µç×ÓÓʼþµØÖ·¡¢È«Ãû¡¢bcryptÉ¢ÁÐÃÜÂ롢ͷÏΡ¢¹«Ë¾Ãû³Æ¡¢IPµØÖ·ºÍÆäËûϵͳÓйØÊý¾Ý¡£ÕâЩÊý¾Ý¿â»¹Ô̺¬ÁËÓë¸÷³ÛÃû¹«Ë¾ÓйصĴóÁ¿Îĵµ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/massive-nitro-data-breach-impacts-microsoft-google-apple-more/
5.Trustwave·¢ÏÖºÚ¿ÍÔÚ°µÍøÏúÊÛ1.86ÒÚÃÀ¹úÑ¡ÃñÐÅÏ¢

ÍøÂ簲ȫ¹«Ë¾Trustwave·¢ÏÖºÚ¿ÍÔÚ°µÍøÏúÊÛÁ˳¬¹ý2ÒÚÃÀ¹úÈ˵ÄÓ×ÎÒ¼ø±ðÐÅÏ¢£¬ÆäÖÐÔ̺¬1.86ÒÚÃÀ¹úÑ¡ÃñÐÅÏ¢¡£Ð¹Â©µÄÊý¾ÝÔ̺¬ÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂëºÍÑ¡ÃñµÇ¼Ç¼Í¼¡£Trustwave°µÊ¾ÕâЩÊý¾ÝÊÇÓɽüÄêÀ´ÆóÒµÔâµ½¸÷À๥»÷Ëùй¶µÄÊý¾ÝÒÔ¼°´Óµ±¾ÖÍøÕ¾¼ìË÷µÄ¹«¿ªÊý¾Ý×é³ÉµÄ£¬¿ÉÓÃÓÚÉ罻ýÌå¡¢µç×ÓÓʼþÍøÂç´¹µöÒÔ¼°Îı¾ºÍµç»°Ú¿Æ»î¶¯ºÍÐéαÐÅÏ¢Ðû´«»î¶¯¡£
ÔÎÄÁ´½Ó£º
https://www.nbcnews.com/politics/2020-election/cybersecurity-firm-finds-hacker-selling-info-148-million-u-s-n1244211
6.Ó¡¶ÈPTI·þÎñÆ÷ÔâLockBit¹¥»÷µ¼Ö·þÎñÁÙʱÖжÏ

Ó¡¶ÈPTI£¨Press Trust of India¡¯s£©ÔâLockBit¹¥»÷µ¼Ö·þÎñÁÙʱÖжϡ£PTI½²»°ÈËÖÜÈÕ°µÊ¾£¬¸Ã¹«Ë¾µÄ·þÎñÆ÷Ôâ·êÁË´ó¹æÄ£ÀÕË÷Èí¼þ¹¥»÷£¬µ¼Ö·þÎñÖжÏÁËÊýÓ×ʱ£¬¾¹ý¹¤³Ìʦ³¹Ò¹ÖÂÁ¦ºóµÃÒÔ¸´Ô¡£¹¥»÷²úÉúÔÚÖÜÁùÍíÉÏ10µã×óÓÒ£¬ÀÕË÷Èí¼þLockBitϰȾÁËÓ¡¶È×ÜÀíͨѶÉçÏÕЩËùÓеķþÎñÆ÷£¬²¢¼ÓÃÜÁËËùº±¼û¾ÝºÍÀûÓ÷¨Ê½¡£µ«¸Ã½²»°È˰µÊ¾£¬µ½ÖÜÈÕÉÏÎç9µã£¬ÆäËùÓÐÒµÎñ¸ù»ù¶¼¸´ÔÕý³££¬²¢ÇÒûÓÐÖ§¸¶Êê½ð¡£
ÔÎÄÁ´½Ó£º
https://www.thehindubusinessline.com/info-tech/pti-services-disrupted-after-massive-ransomware-attack-on-servers/article32940254.ece


¾©¹«Íø°²±¸11010802024551ºÅ