ºÚ¿ÍÐû³ÆÒÑÇÔÈ¡µçÐŹ«Ë¾T-MobileÔ¼1ÒÚ¿Í»§µÄÐÅÏ¢£ºFortbridgeÅû¶cPanelºÍWHMÖжà¸ö°²È«·ì϶µÄϸ½Ú
°ä²¼¹¦·ò 2021-08-16
![]()
¹¥»÷ÕßÐû³ÆÔÚÁ½ÖÜǰÈëÇÖÁËT-MobileµÄÓÃÓÚ³ö²úºÍ¿ª·¢µÄ·þÎñÆ÷£¬ÒÔ¼°Ò»¸öÔ̺¬Á˿ͻ§ÐÅÏ¢µÄOracleÊý¾Ý¿â·þÎñÆ÷¡£Õâ´Îй¶ÁËT-MobileµÄ1ÒÚ¸ö¿Í»§Ô¼106GBµÄÊý¾Ý£¬Ô̺¬IMSI¡¢IMEI¡¢µç»°ºÅÂë¡¢¿Í»§ÐÕÃû¡¢°²È«PIN¡¢Éç»á°²È«ºÅÂë¡¢¼ÝÕÕºÅÂëºÍµ®ÉúÈÕÆÚµÈÐÅÏ¢¡£Íþвµý±¨¹«Ë¾Hudson Rock°µÊ¾£¬Õâ´ÎºÚ¿ÍµÄ¹¥»÷ÐÐΪ¿ÉÄÜÊÇΪÁË·ÛËéÃÀ¹úµÄ»ù´¡ÉèÊ©£¬Ö¼ÔÚ±¨³ðÃÀ¹úÔøÓÚ2019Äê°ó¼Ü²¢ÕÛÄ¥ÁËJohn Erin Binns(CIA Raven-1)¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hacker-claims-to-steal-data-of-100-million-t-mobile-customers/

FortbridgeÅû¶cPanelºÍWHMÖжà¸ö°²È«·ì϶µÄϸ½Ú
FortbridgeµÄ×êÑÐÈËÔ±Åû¶ÁËÍøÂçÍÐ¹ÜÆ½Ì¨cPanelºÍWHMÖжà¸ö°²È«·ì϶µÄϸ½Ú¡£×êÑÐÈËÔ±ÔÚÕë¶ÔcPanelºÍWHMµÄºÚºÐÉøÈë²âÊÔÖз¢ÏÖÁËÕâЩ·ì϶£¬½áºÏʹÓÿÉÔ¶³ÌÖ´ÐдúÂë¡£ÆäÖÐÒ»¸ö·ì϶Ϊ¾ÏúÉÌÕÊ»§ÖеÄXML±í²¿ÊµÌå(XXE)·ì϶£¬ÊÇÓÉÓÚ¸ÃÕÊ»§Õ¼ÓÐÒÔXML»òXLFÌåʽ±à×ëºÍÔö³¤ÇøÓòÉèÖÃȨÏÞµ¼Öµġ£´Ë±í£¬×êÑÐÈËÔ±»¹Åû¶ÁËÒ»¸ö´æ´¢ÐÍXSS·ì϶ºÍCSRF·ì϶¡£µ«Ä¿Ç°£¬¹©¸øÉÌÖ»½¨¸´ÁËXXE·ì϶£¬²¢»Ø¾ø½¨¸´ÆäËü·ì϶¡£
ÔÎÄÁ´½Ó£º
https://latesthackingnews.com/2021/08/14/numerous-vulnerabilities-spotted-in-cpanel-and-whm-web-hosting-platform/

Unit42½üÆÚ·¢ÏÖ´óÁ¿ÈƹýCAPTCHA¼ì²âµÄ´¹µö»î¶¯
Unit42µÄ×êÑÐÈËÔ±½üÆÚ·¢ÏÖÁË´óÁ¿ÈƹýCAPTCHA¼ì²âµÄ´¹µö»î¶¯¡£¹¥»÷Õß½«´¹µöÒ³Ãæ°µ²ØÔÚCAPTCHAÖ®ºó¿ÉÔ¤·À°²È«ÅÀ³æ¼ì²âµ½¶ñÒâÄÚÈÝ£¬²¢Äܹ»Ê¹´¹µöµÇÂ¼Ò³Ãæ¿´ÆðÀ´Ô½·¢ºÏ·¨¡£¹ÌÈ»Õâ²¢·Ç×îеļ¼Êõ£¬µ«ÔÚ½üÆÚÔ½À´Ô½Ê¢ÐУºÉϸöÔÂUnit42ÔÚ4088¸ö¸¶·ÑµÄÓòÖз¢ÏÖÁË7572¸öѡȡÁË»ìºÏ²½ÖèµÄ¶ñÒâURL£¬Ò²¾ÍÊÇ˵¾ùÔÈÿÌìÓÐ529¸öʹÓÃÁËCAPTCHAµÄ¶ñÒâ URL¡£³ýÁË´¹µö¹¥»÷Ö®±í£¬ÀûÓÃCAPTCHAµÄڿƻҲÔÚÔö³¤¡£
ÔÎÄÁ´½Ó£º
https://unit42.paloaltonetworks.com/captcha-protected-phishing/

×êÑÐÍŶӷ¢ÏÖAggahÕë¶ÔÑÇÖÞÔì×÷ÒµµÄÓã²æÊ½´¹µö»î¶¯
AnomaliµÄ×êÑÐÍŶӷ¢ÏÖÁËʼÓÚ2021Äê7ÔÂÉÏÑ®µÄÓã²æÊ½ÍøÂç´¹µö»î¶¯£¬Õë¶ÔÕû¸öÑÇÖÞµÄÔì×÷Òµ¡£Aggah×îÔçÓÚ2019Äê3ÔÂÓÉUnit 42µÄ×êÑÐÈËÔ±·¢ÏÖ£¬ÖØÒªÕë¶Ô°¢À²®½áºÏÇõ³¤¹ú(UAE)µÄ×éÖ¯¡£Õâ´Î»î¶¯ÖУ¬¹¥»÷Õß¼Ù×°³ÉÓ¢¹úFoodHub.co.uk·¢ËÍ´¹µöÓʼþ£¬ÓÕʹÓû§µÇ¼Òѱ»ÈëÇÖµÄmail.hoteloscar.in/imagesÍøÕ¾£¬²¢·Ö·¢Warzone RAT¡£¾Ý·ÖÎö£¬Aggah×îÐµĹ¥»÷Ö¸±êÔ̺¬Öйų́ÍåµÄÔì×÷¹«Ë¾Fon-starºÍ¹¤³Ì¹«Ë¾FomoTech£¬ÒÔ¼°º«¹úµÄµçÁ¦¹«Ë¾ÏÖ´úµçÆø¡£
ÔÎÄÁ´½Ó£º
https://www.anomali.com/blog/aggah-using-compromised-websites-to-target-businesses-across-asia-including-taiwan-manufacturing-industry

Check Point°ä²¼ºÚ¿ÍÍÅ»ïIndra¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨
Check Point°ä²¼ÁËÓйغڿÍÍÅ»ïIndra¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£×êÑÐÈËÔ±·ÖÎöÁË2021Äê7ÔÂ9ÈÕÖÁ10ÈÕ¶ÔÒÁÀÊ»ð³µÏµÍ³µÄÍøÂç¹¥»÷Áôϵĺۼ££¬²¢½«Õâ´Î¹¥»÷¹éÒòÓÚÒ»¸ö×Ô³ÆÎªIndraµÄºÚ¿ÍÍŻ»ã±¨Ö¸³ö£¬¸ÃÍŻﻹÓë2019ÄêºÍ2020ÄêÕë¶ÔÐðÀûÑǶà¼Ò¹«Ë¾µÄ¹¥»÷Óйأ¬Ô̺¬Katerji GroupºÍArfada Petroleum¡£´Ë±í£¬¹¥»÷ÕßÔÚÕâЩÄ꿪·¢ÁËÖÁÉÙ3¸ö·ÖÆç°æ±¾µÄwiper£¬±ðÀë³ÆÎªMeteor¡¢StardustºÍComet£¬¸Ã»ã±¨»¹¾ßÌåÃèÊöÁ˹¥»÷ÕßʹÓõŤ¾ßºÍTTPs¡£
ÔÎÄÁ´½Ó£º
https://research.checkpoint.com/2021/indra-hackers-behind-recent-attacks-on-iran/

Kaspersky°ä²¼2021ÄêµÚ¶þ¼¾¶ÈÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨
Kaspersky°ä²¼ÁË2021ÄêµÚ¶þ¼¾¶ÈÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¸Ã»ã±¨·ÖÎöÁË2021ÄêQ2µÄ¶à¸öÓÐÕë¶ÔÐԵĹ¥»÷»î¶¯£¬Ô̺¬ÓëCycldekÍÅ»ïÓйصĹ¥»÷»î¶¯£¬ÔÚÒ°±íʹÓÃ×ÀÃæ´°¿ÚÖÎÀíÆ÷ÖÐ0dayµÄ¹¥»÷»î¶¯£¬TunnelSnakeÐж¯£¬PuzzleMaker»î¶¯ºÍFerocious KittenÍÅ»ïÓйػµÈ¡£´Ë±í£¬»ã±¨»¹·ÖÎöÁ˶à¸ö¶ñÒâÈí¼þ£¬Ô̺¬ÀÕË÷Èí¼þJSWormºÍBlack Kingdom¡¢ÒøÐÐľÂíGootkitºÍBizarro¡¢APKPureÀûÓÃÖжñÒâ´úÂëºÍBrowser lockersµÈ¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/it-threat-evolution-q2-2021/103597/


¾©¹«Íø°²±¸11010802024551ºÅ