ºÚ¿ÍÔÚ°µÍø¹«¿ª320Íò¸öPluto TVÓû§µÄÐÅÏ¢£»SafariµÄÁ´½Ó¹²ÏíÖ°ÄÜ¿ÉÅú¸Ä±êÌ⣬¿ÉÄܱ»ÀÄÓÃ

°ä²¼¹¦·ò 2020-11-16

1.ºÚ¿ÍÔÚ°µÍø¹«¿ª320Íò¸öPluto TVÓû§µÄÐÅÏ¢


1.png


ÉÏÖÜÈý£¬ºÚ¿ÍÔÚ°µÍø¹«¿ªÁËÔ̺¬320Íò¸öPluto TVÓû§ÐÅÏ¢µÄÊý¾Ý¿â¡£Í¨¹ýÊý¾Ý¿âÑù±¾¿ÉÖª£¬Ð¹Â¶Êý¾ÝÔ̺¬Óû§Ãû¡¢µç×ÓÓʼþµØÖ·¡¢bcrypt¹þÏ£ÃÜÂë¡¢ÉúÈÕ¡¢É豸ƽ̨ºÍIPµØÖ·¡£ºÚ¿ÍÐû³ÆÕâ´ÎÊý¾Ýй¶ÊÇÓÉShinyHuntersµ¼ÖµÄ£¬¶ø¸ÃÊý¾Ý¿â¿ÉÄÜÊÇÁ½Äêǰй¶µÄ£¬×îмͼÊÇÔÚ2018Äê10ÔÂ12ÈÕ´´½¨µÄ¡£Ä¿Ç°£¬Pluto TVÉÐδ֤ʵÊÇ·ñ²úÉúÁËÊý¾Ýй¶£¬½ö°µÊ¾ËûÃÇÔÚµ÷²éÖС£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hacker-shares-32-million-pluto-tv-accounts-for-free-on-forum/


2.ÐÂÐÅÓþ¿¨¹¥»÷ͨ¹ýαÔìWebSocketsÇÔÈ¡Óû§ÐÅÏ¢


2.png


×êÑÐÈËÔ±·¢ÏÖеÄÐÅÓþ¿¨¹¥»÷·½Ê½£¬Í¨¹ýαÔìÐéαÐÅÓþ¿¨ÂÛ̳ºÍWebSocketsÇÔÈ¡Óû§ÐÅÏ¢¡£ºÚ¿ÍÊ×ÏÈ»á×¢Èë¶ñÒâ¾ç±¾£¬½«ÌìÉúµÄ»á»°idºÍ¿Í»§¶ËIPµØÖ·´æ´¢ÔÚä¯ÀÀÆ÷µÄ±¾µØ´æ´¢ÖУ¬ÕâЩ²ÎÊýÔÚÉÔºóµÄ»á»°ºó»á·¢Ëͻع¥»÷Õß¡£ÎªÁË»ñÈ¡Óû§µÄIPµØÖ·£¬¹¥»÷Õ߯æÃîµØÊ¹ÓÃÁËCloudflareµÄAPI¡£´Ë±í£¬¹¥»÷ÕßʹÓÃWebSockets°ü°ìÁËHTMLµÈÆäËû²½ÖèÀ´ÇÔÊØÐÅÏ¢£¬Õâ¿Éʹ¹¥»÷µÄÔëÒô¸üÉÙ¡¢¸üÒþÃØ¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/skimmer-attack-fake-credit-card-steal-data/


3.SafariµÄÁ´½Ó¹²ÏíÖ°ÄÜ¿ÉÅú¸Ä±êÌ⣬¿ÉÄܱ»ÀÄÓÃ


3.png


iOS°æ±¾Apple Safariä¯ÀÀÆ÷ÖеÄÁ´½Ó¹²ÏíÖ°ÄÜʹiPhone¡¢iPadºÍiPod TouchÓû§Äܹ»ÔÚ¹²Ïí²¿ÃÅÍøÒ³Ê±¸ü¸Ä±êÌ⣬¸ÃÖ°Äܿɱ»ÀÄÓÃÔì×÷¼ÙÐÂÎÅ¡£µ±Ê¹ÓÃSafariä¯ÀÀÍøÒ³Ê±£¬Óû§Äܹ»·ÖÏí²¿ÃÅÎı¾ÌáÒª¶ø²»ÊÇÕû¸öÒ³Ãæ£¬Ò²Äܹ»½ÚÔìºÍ±à×ë¸ÃÎı¾¡£ÔÚͨ¹ýiMessageÓëÆäËûiPhoneÓû§¹²Ïí¸ÃÒ³ÃæÊ±£¬ÌìÉúµÄÁ´½ÓÔ¤ÀÀΪ¸ÃÎı¾µÄÄÚÈݶø·ÇÍøÒ³µÄԭʼ±êÌâ¡£¸ÃÖ°Äܿɱ»ÓÃÀ´Ôì×÷²¢´«²¼ÐéαÐÂÎÅ£¬Ä¿Ç°ÉÐδ±»½¨¸´¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/apple-ios-safari-feature-can-be-used-to-share-fake-news-headlines/


4.°ÄÖÞµ±¾Ö°ä²¼Ô¤¾¯ÎÀÉú²¿ÃÅÐè°ÑÎÈ·À±¸SDBBot RAT


4.png


°Ä´óÀûÑǵ±¾Ö°ä²¼°²È«¾¯±¨£¬ÖÒ¸æÎÀÉú²¿ÃÅÐè°ÑÎÈ·À±¸SDBBot RAT¡£°Ä´óÀûÑÇÍøÂ簲ȫÖÐÐÄ£¨ACSC£©°µÊ¾£¬×î½üʹÓÃSDBBotÔ¶³Ì½Ó¼û¹¤¾ß£¨RAT£©¶Ô°Ä´óÀûÑÇÎÀÉú²¿ÃŵÄÕë¶ÔÐԻÓÐËùÔö³¤£¬²¢¶½´Ù¸Ã²¿ÃŵÄ×éÖ¯²é³­ÆäÍøÂ簲ȫ·ÀÓù´ëÊ©¡£¹ÌÈ»ACSCûÓÐÌṩÈκθÉÓڸù¥»÷»î¶¯µÄϸ½Ú£¬µ«SDBBot RAT»òÐíÓëºÚ¿Í×éÖ¯TA505ÓйØ¡£´Ë±í£¬ACSC»¹·¢ÏÖSDBBotÓÉ3¸ö²¿ÃÅ×é³É£¬±ðÀëΪһ¸ö³ÉÁ¢ÓƾÃÐÔµÄ×°Ö÷¨Ê½¡¢Ò»¸öÏÂÔØ¶î±í×é¼þµÄ¼ÓÔØ·¨Ê½ÒÔ¼°RAT×ÔÉí¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/australian-government-warns-of-possible-ransomware-attacks-on-health-sector/


5.Schneide°ä²¼ÓйØLinux¶ñÒâÈí¼þDrovorubµÄ°²È«²¼¸æ


5.png


Schneide°ä²¼ÁËÒ»¸ö°²È«²¼¸æ£¬ÖÒ¸æÆäÓû§°ÑÎÈLinux¶ñÒâÈí¼þDrovorub¡£ÔçÔÚ½ñÄê8Ô£¬NSAºÍFBI½áºÏ°ä²¼¾¯±¨²¢¶Ô¸Ã¶ñÒâÈí¼þ½øÐÐÁË·ÖÎö¡£¾Ý³Æ£¬¸Ã¶ñÒâÈí¼þÊôÓÚ¶íÂÞË¹ÍøÂç¼äµý×éÖ¯APT28£¬ÊÇÒ»ÖÖÄ£¿é»¯¶ñÒâÈí¼þ£¬Ô̺¬Ö²ÈëÎï¡¢ÄÚºËÄ£¿érootkit¡¢Îļþ´«Ê乤¾ß¡¢¶Ë¿Úת·¢Ä£¿éºÍºÅÁîÓë½ÚÔ죨C2£©·þÎñÆ÷£¬¿ÉÓÃÀ´ÇÔÈ¡Îļþ¡¢³ÉÁ¢ºóÃŲ¢Ô¶³Ì½ÚÔìÖ¸±êÍÆËã»ú¡£Schneider¶½´Ù¿Í»§Ö´ÐÐ×ÝÉî·ÀÓùÕ½Êõ£¬ÒÔ±£»¤Trio QÊý¾Ý¹ã²¥ºÍTrio JÊý¾Ý¹ã²¥É豸ÃâÊÜDrovorub¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/110920/cyber-crime/drovorub-linux-malware.html


6.ÁãÊÛ¹«Ë¾CencosudϰȾEgregor£¬¹«Ë¾µÄÔËÓªÊܵ½Ó°Ïì


6.png


ÁãÊÛ¹«Ë¾CencosudϰȾÀÕË÷Èí¼þEgregor£¬¹«Ë¾µÄÔËÓªÊܵ½Ó°Ïì¡£×ܲ¿Î»ÓÚÖÇÀûµÄ¿ç¹ú¹«Ë¾CencosudÊÇÀ­¶¡ÃÀÖÞ×î´óµÄÁãÊÛ¹«Ë¾Ö®Ò»£¬ÆäÔÚ°¢¸ùÍ¢¡¢°ÍÎ÷¡¢ÖÇÀû¡¢¸çÂ×±ÈÑǺÍÃØÂ³¾­Óª×Ÿ÷Àà¸÷ÑùµÄÉ̵ê¡£CencosudÓÚ±¾ÖÜÄ©Ôâµ½ÁËEgregorÀÕË÷Èí¼þ¹¥»÷£¬ÆäÉ̵êÖеÄÉ豸±»¼ÓÃÜ£¬²¢Ó°ÏìÁ˹«Ë¾µÄÔËÓª¡£²¿ÃÅÉ̵êÖÒ¸æÓÉÓÚ¼¼ÊõÎÊÌâ²»½ÓÊÜCencosudÐÅÓþ¿¨£¬²»½ÓÊÜÍË»õ»òÒ²²»ÔÊÐíÍøÉϹºÎï¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/retail-giant-cencosud-hit-by-egregor-ransomware-attack-stores-impacted/