WordPress XSSºÍRCEÎó²î£»OilRig APT·Ö·¢KarkoffºÍDNSpionage£»QbotľÂíбäÖÖ
Ðû²¼Ê±¼ä 2019-04-25
WordPress²å¼þSocial WarfareÐû²¼Ð°汾3.5.3£¬ÐÞ¸´Ò»¸ö´æ´¢ÐÍXSSºÍRCEÎó²î£¨CVE-2019-9978£©£¬½¨ÒéÓû§¾¡¿ì¸üС£Social WarfareÊÇÒ»¸öÊ¢ÐеIJå¼þ£¬ÓÃÓÚÏòWordPressÍøÕ¾»ò²©¿ÍÌí¼ÓÉç½»·ÖÏí°´Å¥£¬ÆäÏÂÔØÁ¿Áè¼Ý90Íò´Î¡£ÓÉÓÚPoCÒѾй¶£¬¹¥»÷ÕßÒÑÔÚÒ°ÍâÆð¾¢Ê¹ÓøÃÎó²î¾ÙÐжñÒâÍÚ¿óÔ˶¯»òÍйܶñÒâ´úÂë¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/04/wordpress-plugin-hacking.html
2¡¢ChromeÐû²¼Ð°汾v74£¬¹²ÐÞ¸´39¸öÇå¾²Îó²î
ChromeÐû²¼Ð°汾v74.0.3729.108£¬ÔöÌíÁËй¦Ð§²¢ÐÞ¸´ÁË39¸öÇå¾²Îó²î¡£ÏÖÔÚChrome 74ÊÇÎȹ̰棬Chrome 75ºÍ76Ôò»®·ÖÊÇBetaºÍCanary°æ±¾¡£Õâ39¸öÎó²îÖÐûÓÐCritical¼¶±ðµÄÎó²î£¬µ«ÓÐÎå¸ö¸ßΣÎó²î£¬°üÀ¨use-after-freeÎó²î£¨CVE-2019-5805¡¢CVE-2019-5808ºÍCVE-2019-5809£©¡¢ÕûÊýÒç³öÎó²î£¨CVE-2019-5806£©ÒÔ¼°ÄÚ´æËð»µÎó²î£¨CVE-2019-5807£©¡£ÍêÕûµÄ¹¦Ð§±ä»»ºÍÎó²îÐÞ¸´Áбí¿ÉÔÚÒÔÏÂÁ´½ÓÖÐÕÒµ½¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/google/chrome-74-released-with-39-security-fixes-and-new-features/
3¡¢Google PlayϼÜ50¸ö¶ñÒâÓ¦Óã¬×°ÖÃÁ¿´ï3000Íò´Î
AvastÑо¿ÍŶÓÔÚGoogle PlayÖз¢Ã÷50¸ö¶ñÒâÓ¦Óã¬ÕâЩӦÓõÄ×ÜÏÂÔØ´ÎÊý´ï3000Íò´Î¡£Æ¾Ö¤AvastµÄ±¨¸æ£¬ÕâЩӦÓÃͨ¹ýµÚÈý·½¿âÏ໥¹ØÁª£¬¿ÉÈÆ¹ýAndroidµÄºǫ́·þÎñÏÞÖÆÒ»Ö±ÏòÓû§ÏÔʾԽÀ´Ô½¶àµÄ¹ã¸æ£¬ÔÚijЩÇéÐÎÏÂÉõÖÁÓÕʹÓû§×°ÖÃÆäËü¹ã¸æÈí¼þ¡£ÕâЩ¶ñÒâÓ¦ÓõÄÃû³Æ°üÀ¨Pro Piczoo¡¢Photo Blur Studio¡¢Mov-tracker¡¢Magic Cut OutºÍPro Photo EraserµÈ£¬ÏÂÔØÁ¿´Ó100Íòµ½1000´Î²»µÈ¡£
ÔÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/30-million-android-users-have-installed-malicious-lifestyle-apps/
4¡¢OilRig APTÔÚй¥»÷Ô˶¯Öзַ¢KarkoffºÍDNSpionage
ƾ֤˼¿ÆTalosµÄÆÊÎö±¨¸æ£¬ÒÁÀÊAPT×éÖ¯OilRigÔÚ×î½ü£¨4Ô·ݣ©µÄ¹¥»÷Ô˶¯ÖÐʹÓÃÁËжñÒâÈí¼þKarkoffºÍDNSpionage¡£ÕâЩ¹¥»÷Ô˶¯Ö÷ÒªÕë¶ÔÖж«µØÇø£¬°üÀ¨Àè°ÍÄۺͰ¢ÁªÇõ¡£¹¥»÷ÕßÕýÔÚʹÓÃеÄÕ½ÂÔ¡¢ÊÖÒպͳÌÐòÀ´Ìá¸ßÆä¹¥»÷ЧÂÊ¡£KarkoffÊÇ.NET¿ª·¢µÄжñÒâÈí¼þ£¬Ö÷ÒªÓÃÓÚÕì̽Ô˶¯£¬¿ÉÍøÂçÄ¿µÄµÄÊÂÇéÕ¾ÇéÐΡ¢OS¡¢Óò¡¢Àú³ÌÁбíµÈÐÅÏ¢£¬ÉõÖÁ¿ÉÒÔÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£DNSpionageÔòÊÇÒ»¸ö¶¨ÖƵÄRAT£¬Ö÷ҪʹÓÃHTTPºÍDNSͨѶÀ´ÅþÁ¬C£¦C·þÎñÆ÷¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/84418/malware/oilrig-apt-karkoff-dnspionage.html
5¡¢QbotľÂíбäÖÖ£¬ÒÑѬȾȫÇò2726ÃûÓû§
Varonis Security ResearchÔÚ3Ô·ݷ¢Ã÷ÁËQbotľÂíµÄÐÂÒ»²¨È«Çò¹¥»÷Ô˶¯£¬Æ¾Ö¤¶ÔÆäÖÐÒ»¸ö¹¥»÷·þÎñÆ÷µÄÆÊÎö£¬Ñо¿Ö°Ô±ÒѾȷÈÏÁË2726ÃûÊܺ¦Õߣ¬µ«ÏÖʵÊܺ¦ÈËÊý¿ÉÄܸü¸ß¡£QbotÒÔÆä¶à̬ÐÐΪ¼°ÀàËÆÈ䳿µÄÌØÕ÷¶øÖøÃû£¬ÕâÒ»´ÎQBotͨ¹ý´¹ÂÚÓʼþ¾ÙÐÐÈö²¥£¬Ö÷ÒªÕë¶ÔÃÀ¹ú¡¢Å·ÖÞ¡¢ÑÇÖÞºÍÄÏÃÀÖÞµÄÆóÒµ£¬ÆäÄ¿µÄÊÇÇÔÈ¡ÒøÐÐÆ¾Ö¤µÈ²ÆÎñÐÅÏ¢¡£
ÔÎÄÁ´½Ó£ºhttps://threatpost.com/qbot_new_campaign/144070/
6¡¢ÑÇÌØÀ¼´óÀÏÓ¥¶ÓµÄÔÚÏßÊÐËÁÔâµ½Magecart¹¥»÷
ÑÇÌØÀ¼´óÀÏÓ¥¶ÓµÄÔÚÏßÊÐËÁ³ÉΪMagecart¹¥»÷µÄ×îÐÂÊܺ¦Õߣ¬Æ¾Ö¤Sanguine SecurityµÄ±¨¸æ£¬¸ÃÊÐËÁµÄ¸¶¿îÒ³ÃæÑ¬È¾ÁËMagecart¶ñÒâ´úÂ룬µ¼ÖÂÓû§µÄÐÕÃû¡¢µØµãºÍÐÅÓÿ¨ÏêϸÐÅÏ¢±»ÇÔ¡£¸ÃÊÂÎñÓ°ÏìÁË4ÔÂ20ÈÕÖ®ºóÔÚÊÐËÁ¹ºÎïµÄÓû§£¬µ«Éв»ÇåÎúÊÜÓ°ÏìÓû§µÄÏêϸÊýÄ¿¡£Ñо¿Ö°Ô±ÒÔΪ¸Ã¹¥»÷»òÓëMagentoµÚÈý·½×é¼þµÄʹÓÃÓйء£
ÔÎÄÁ´½Ó£ºhttps://labs.sansec.io/2019/04/24/atlanta-hawks-magecart/


¾©¹«Íø°²±¸11010802024551ºÅ