¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190131

Ðû²¼Ê±¼ä 2019-01-31
1¡¢Êý¾ÝÖÎÀí¹«Ë¾RubrikÒâÍâй¶´ó×Ú¿Í»§Êý¾Ý

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


Çå¾²Ñо¿Ô±Oliver Hough·¢Ã÷ÊôÓÚÊý¾ÝÖÎÀí¹«Ë¾RubrikµÄÒ»¸öElasticsearch·þÎñÆ÷δÊÜÃÜÂë± £»¤£¬¸ÃÊý¾Ý¿â´æ´¢ÁËÊýÊ®GBµÄÊý¾Ý£¬°üÀ¨ÆóÒµ¿Í»§µÄÃû³Æ¡¢ÁªÏµÐÅÏ¢ºÍÊÂÇé°¸Àý¡£Æ¾Ö¤Ê±¼ä´Á£¬ÕâЩÊý¾Ý¿É×·ËÝÖÁ2018Äê10Ô¡£¾­ÓÉÊӲ죬Rubrik³ÆÕâÒ»ÊÂÎñÊÇÓÉÈËΪ¹ýʧµ¼ÖµÄ¡£

   

Ô­ÎÄÁ´½Ó£º

https://techcrunch.com/2019/01/29/rubrik-data-leak/


2¡¢Å·ÖÞÖ´·¨»ú¹¹ÕýÔÚÊÓ²ìʹÓùýwebstresser.orgµÄÓû§

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!



Å·ÖÞÖ´·¨»ú¹¹ÕýÔÚÍŽáÈ«ÇòµÄÖ´·¨»ú¹¹¶ÔʹÓùýDDoS×âÓ÷þÎñwebstresser.orgµÄÓû§¾ÙÐÐÊӲ졣ÔÚ2018Äê4Ô¹رÕwebstresser.org·þÎñʱ£¬Å·ÖÞÐ̾¯×éÖ¯»ñµÃÁËÁè¼Ý15.1ÍòÃû×¢²áÓû§µÄÐÅÏ¢¡£Æ¾Ö¤ÕâЩÐÅÏ¢£¬È«ÇòÖ´·¨»ú¹¹½«¶ÔʹÓø÷þÎñÌᳫDDoS¹¥»÷µÄÓû§¾ÙÐÐÊÓ²ìºÍÆðËß¡£

  

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/80435/cyber-crime/europol-ddos-for-hire.html


3¡¢ÒÁÀÊAPT39жñÒâÔ˶¯£¬Ö÷ÒªÕë¶ÔÖж«µçÐÅÐÐÒµ

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


FireEyeÐû²¼¹ØÓÚÒÁÀÊAPT39жñÒâÔ˶¯µÄÆÊÎö±¨¸æ¡£ÓëÆäËüÒÁÀÊAPT×éÖ¯²î±ðµÄÊÇ£¬APT39¸ü×ÅÖØÓÚÇÔȡСÎÒ˽¼ÒÐÅÏ¢£¬ÒÔ±ãΪÒÁÀÊµÄ¼à¿Ø¡¢¸ú×ٺͼàÊÓÔ˶¯Ìṩ֧³Ö¡£ËäÈ»APT39µÄÄ¿µÄ±é²¼È«Çò£¬µ«ÆäÔ˶¯Ö÷Òª¼¯ÖÐÔÚÖж«µØÇø£¬²¢ÇÒÓÅÏÈÕë¶ÔµçÐÅÐÐÒµ£¬±ðµÄ£¬Ò²Ãé×¼ÂÃÓÎÒµºÍIT¹«Ë¾¡£APT39Ö÷ҪʹÓÃSEAWEEDºÍCACHEMONEYºóÃÅÒÔ¼°POWBATºóÃÅ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.fireeye.com/blog/threat-research/2019/01/apt39-iranian-cyber-espionage-group-focused-on-personal-information.html


4¡¢Altran Technologies¹«Ë¾Ôâµ½ÀÕË÷Èí¼þLockerGoga¹¥»÷

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


·¨¹ú¹¤³Ì×Éѯ¹«Ë¾Altran TechnologiesÔâµ½ÀÕË÷Èí¼þLockerGoga¹¥»÷£¬ÆäÔÚһЩŷÖÞ¹ú¼ÒµÄÔËÓªÔ˶¯Êܵ½Ó°Ï졣ΪÁ˱ £»¤¿Í»§µÄÊý¾ÝºÍ×ʲú£¬AltranÔÝʱ¹Ø±ÕÁËÍøÂçºÍÓ¦ÓóÌÐò¡£ÕâÒ»ÊÂÎñ±¬·¢ÔÚ1ÔÂ24ÈÕ£¬µ«¸Ã¹«Ë¾²¢Ã»ÓÐÅû¶Ïà¹ØÏ¸½Ú£¬²¢³ÆÊÂÎñ»¹ÔÚÊÓ²ìÖ®ÖС£Æ¾Ö¤ÉÏ´«µ½VirusTotalµÄ¶ñÒâÑù±¾£¬LockerGoga»áÔÚ¼ÓÃܵÄÎļþºó¸½¼Ó.lockedÀ©Õ¹Ãû¡£

  

Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/altran-technologies-hit-by-lockergoga-ransomware-attack-e1f90570


5¡¢ÀÕË÷Èí¼þJobCrypterбäÖÖ£¬¿É½ØÈ¡ÆÁÄ»ÐÅÏ¢

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


Ç÷ÊÆ¿Æ¼¼Ñо¿Ö°Ô±·¢Ã÷ÀÕË÷Èí¼þJobCrypterµÄÒ»¸öбäÖÖ£¬¸Ã±äÖÖ¾ßÓÐÌØÁíÍâ¼ÓÃܲãºÍ¸ü³¤µÄÃÜÔ¿£¬»¹¿ÉÒÔͨ¹ýSMTP½«Ä¿µÄ×°±¸µÄÆÁÄ»½ØÍ¼·¢ËÍÖÁÖ¸¶¨µÄµç×ÓÓÊÏä¡£¸Ã±äÖÖ»áÏȽ«Îļþ¾ÙÐÐBase64±àÂ룬ȻºóʹÓÃTriple DESËã·¨¾ÙÐмÓÃÜ£¬×îºóÔÙ¾ÙÐÐÒ»´ÎBase64±àÂ룬ÃÜÔ¿ÓÉ67λÊý×Ö×é³É¡£¸Ã±äÖÖÒªÇóÊÜѬȾµÄÓû§ÔÚ24СʱÄÚÖ§¸¶1000Å·ÔªµÄÊê½ð¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.scmagazineuk.com/new-jobcrypter-ransomware-variant-captures-screenshots-infected-devices/article/1524199


6¡¢Î÷ÃÅ×ÓÐÞ¸´S7-1500 PLCÖеÄÁ½¸öDoSÎó²î

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!

Î÷ÃÅ×ÓÐÞ¸´Simatic S7-1500¿É±à³ÌÂß¼­¿ØÖÆÆ÷£¨PLC£©ÖеÄÁ½¸ö¿Éµ¼ÖÂDoSµÄÇå¾²Îó²î¡£ÕâÁ½¸öÎó²î£¨CVE-2018-16558ºÍCVE-2018-16559£©ÊÇÓÉPositive TechnologiesµÄÑо¿Ö°Ô±·¢Ã÷µÄ£¬ÆäCVSS v3.0µÃ·Ö¾ùΪ7.5¡£Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿Éͨ¹ýÏòTCP¶Ë¿Ú80»ò443·¢ËͶñÒâÊý¾Ý°üÀ´´¥·¢Îó²î¡£Î÷ÃÅ×ÓÔÚSimatic S7-1500¹Ì¼þ°æ±¾2.5ÖÐÐÞ¸´ÁËÕâЩÎó²î¡£

  

Ô­ÎÄÁ´½Ó£º

https://cert-portal.siemens.com/productcert/pdf/ssa-180635.pdf


ÉùÃ÷£º±¾×ÊѶÓÉ×ðÁú¿­Ê±Î¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí