°ÄÖÞ2019ÄêQ1Êý¾Ýй¶ͳ¼Æ±¨¸æ £»SCADDÔâÀÕË÷Èí¼þ¹¥»÷ £»½ü90%°ÍÄÃÂí¹«ÃñÐÅϢй¶

Ðû²¼Ê±¼ä 2019-05-14
1¡¢ÈýÐÇÊÖ»úÈí¼þContainerAgent±£´æDoSÎó²î£¬¿Éµ¼ÖÂ×°±¸±äש

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!
 
·¨¹úÇå¾²Ñо¿Ô±Robert Baptiste·¢Ã÷ÈýÐÇÊÖ»úÈí¼þContainerAgentÖб£´æÒ»¸ö¿Éµ¼ÖÂDoSµÄÎó²î£¬¸ÃÎó²îÓ°ÏìÁËÏÕЩËùÓÐÈýÐÇÊÖ»ú£¬¿Éµ¼ÖÂ×°±¸±äש¡£Æ¾Ö¤BaptisteµÄ²©¿Í£¬ContainerAgentĬÈÏÆôÓù㲥ÎüÊÕÆ÷¹¦Ð§£¬¸ÃÎüÊÕÆ÷µÄOnReceiveÒªÁì±£´æÎó²î£¬Í¨¹ýµ÷½â²ÎÊý×îÖտɵ¼ÖÂ×°±¸Ëø¶¨¡£Baptiste»¹ÔÚGithubÉÏÐû²¼ÁËPoC£¬µ«ÈýÐÇÇå¾²ÍŶÓÒÔΪ¸ÃÎó²îûÓÐ/ÏÕЩûÓÐÇå¾²Ó°Ïì¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/white-hat-finds-out-faulty-application-that-reportedly-bricks-all-samsung-phones-e4dad8cc

2¡¢ºÚ¿Íͨ¹ýÈëÇÖAlpaca FormsºÍPicreel»ù´¡ÉèÊ©¹¥»÷4600¶à¸öÍøÕ¾

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!
 
ºÚ¿Íͨ¹ýÈëÇÖÆÊÎö·þÎñPicreelºÍ¿ªÔ´ÏîÄ¿Alpaca FormsµÄ»ù´¡ÉèÊ©Ìᳫ¹©Ó¦Á´¹¥»÷£¬ÒÑÓÐÁè¼Ý4600¸öÍøÕ¾Êܵ½Ñ¬È¾¡£Ñо¿Ö°Ô±Willem de Groot³ÆÕâÁ½¸ö¹¥»÷Ô˶¯ÊÇÓÉͳһ¸ö¹¥»÷ÕßËùΪ£¬µ«Éв»ÇåÎúÆäÈëÇÖ·½·¨¡£¹¥»÷ÕßÐÞ¸ÄÁËPicreel¼°Alpaca Forms CDN»ù´¡ÉèÊ©ÉϵÄJavaScriptÎļþ£¬ÓÃÓÚÇÔÈ¡Óû§ÔÚÍøÒ³±íµ¥ÖÐÊäÈëµÄÄÚÈݲ¢·¢ËÍÖÁλÓÚ°ÍÄÃÂíµÄ·þÎñÆ÷¡£Êܵ½Ñ¬È¾µÄPicreel¾ç±¾ÒÑÔÚ1249¸öÍøÕ¾ÉÏ·¢Ã÷£¬¶øAlpaca Forms¾ç±¾ÔòÓ°ÏìÁË3435¸öÍøÕ¾¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/hackers-are-collecting-payment-details-user-passwords-from-4600-sites/

3¡¢SCADDÔâÀÕË÷Èí¼þ¹¥»÷£¬Áè¼Ý2.5Íò»¼ÕßÐÅÏ¢ÊÜËð

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!
 
ÃÀ¹ú¿µÖݶ«Äϲ¿µÄ½ä¾Æ½ä¶¾Î¯Ô±»á£¨SCADD£©ÔâÀÕË÷Èí¼þ¹¥»÷¡£¸Ã¹¥»÷ÊÂÎñµ¼ÖÂ25148Ãû»¼ÕßµÄСÎÒ˽¼ÒÐÅÏ¢ÊÜËð£¬ÕâЩÐÅÏ¢°üÀ¨ÐÕÃû¡¢µØµã¡¢Éç»áÇå¾²ºÅÂëÒÔ¼°²¡Ê·ºÍÖÎÁÆÐÅÏ¢¡£SCADDÓÚ2ÔÂ18ÈÕ·¢Ã÷ÁËÕâÒ»ÊÂÎñ£¬¸Ã×éÖ¯Á¬Ã¦¾ÙÐÐÁËÖÜÈ«ÊӲ죬²¢ÓëµÚÈý·½Ç徲ר¼ÒÏàÖúÒÔÈ·ÈÏÄÄЩÐÅÏ¢Êܵ½Ë𺦡£SCADD½«ÎªÊÜÓ°ÏìµÄ»¼ÕßÌṩÃâ·ÑµÄÐÅÓÃ¼à¿ØºÍÉí·Ý± £»¤·þÎñ¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/the-southeastern-council-on-alcoholism-and-drug-dependence-hit-with-a-ransomware-attack-77498d74

4¡¢°ÄÖÞÐÅϢרԱ°ì¹«ÊÒÐû²¼2019ÄêQ1Êý¾Ýй¶ͳ¼Æ±¨¸æ

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!
 
°Ä´óÀûÑÇÐÅϢרԱ°ì¹«ÊÒ£¨OAIC£©Ðû²¼2019ÄêµÚÒ»¼¾¶ÈµÄÊý¾Ýй¶ͳ¼Æ±¨¸æ£¬¸Ã±¨¸æÍ³¼ÆÁË1ÔÂ1ÈÕÖÁ3ÔÂ31ÈÕOAICÎüÊÕµ½µÄÊý¾Ýй¶ÊÂÎñ֪ͨ¡£×ܵÄÀ´ËµOAIC¹²ÊÕµ½215¸öÊý¾Ýй¶֪ͨ£¬±ÈÉÏÒ»¼¾¶È£¨2018ÄêQ4£©µÄ262´ÎÒªÉÙ¡£Áè¼Ý1000ÍòÈËÔÚµ¥´ÎÊÂÎñÖÐÊܵ½Ó°Ï죬¶ø°Ä´óÀûÑǵÄÉú³ÝԼΪ2540Íò¡£±¾¼¾¶ÈÊÜÓ°Ïì×îÑÏÖØµÄСÎÒ˽¼ÒÐÅÏ¢ÊÇÁªÏµÐÅÏ¢£¬¹²ÓÐ186¸öÊý¾Ýй¶ÊÂÎñÓ°ÏìÁË´ËÀàÊý¾Ý£¬Æä´ÎÊÇСÎÒ˽¼Ò²ÆÎñÐÅÏ¢£¨Óë98¸öÊÂÎñÓйأ©ºÍÉí·ÝÐÅÏ¢£¨Óë55¸öÊÂÎñÓйأ©¡£OAICÌåÏÖÕâÊÇ×îºóÒ»´ÎÐû²¼¼¾¶È±¨¸æ£¬ÒÔºó½«Ã¿Áù¸öÔÂÐû²¼Ò»´Î¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/over-10-million-people-hit-in-single-australian-data-breach-oaic/

5¡¢Ñо¿ÍŶÓÐû²¼ScarCruft APT¶ñÒ⹤¾ßµÄÆÊÎö±¨¸æ

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!
 
¿¨°Í˹»ùÐû²¼³¯ÏÊAPT×éÖ¯ScarCruftµÄÆÊÎö±¨¸æ¡£¸Ã×éÖ¯±»ÒÔΪÊǹú¼ÒÔÞÖúµÄ¹¥»÷×éÖ¯£¬Ö÷ÒªÕë¶ÔÓ볯Ïʰ뵺ÓйصÄ×éÖ¯ºÍÆóÒµ¡£Æ¾Ö¤Æä×î½üµÄ¹¥»÷Ô˶¯£¬¸Ã×éÖ¯ÈÔȻʮ·Ö»îÔ¾£¬²¢ÇÒһֱˢÐÂÆä¹¥»÷¹¤¾ß¡£ScarCruftʹÓõijõʼdropper¿ÉÈÆ¹ýWindows UAC£¬²¢ÇÒʹÓÃÎó²îCVE-2018-8120ÏÂÔØ²¢Ö´ÐÐÏÂÒ»½×¶Îpayload£¨ROKRATºóÃÅ£©¡£±ðµÄ£¬ScarCruft»¹½¨ÉèÁËÒ»¸öÉÙ¼ûµÄ¶ñÒâÈí¼þ-À¶ÑÀ×°±¸ÍøÂçÆ÷£¬¸Ã¶ñÒâÈí¼þÓÃÓÚ²éÕÒÒÑÅþÁ¬µÄÀ¶ÑÀ×°±¸²¢ÇÔȡװ±¸ÐÅÏ¢¡£Ñо¿Ö°Ô±»¹·¢Ã÷¸Ã×éÖ¯µÄ¹¥»÷Ô˶¯ÓëDarkHotel APT±£´æ¹ØÁª¡£

Ô­ÎÄÁ´½Ó£ºhttps://securelist.com/scarcruft-continues-to-evolve-introduces-bluetooth-harvester/90729/

6¡¢Î´ÉèÃÜÂëµÄÊý¾Ý¿âй¶½ü90%°ÍÄÃÂí¹«ÃñÐÅÏ¢

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!
 
Çå¾²Ñо¿Ô±Bob DiachenkoʹÓÃShodanÔÚAWSÉÏ·¢Ã÷Ò»¸öδÊܱ £»¤µÄElasticsearchÊý¾Ý¿â£¬¸ÃÊý¾Ý¿âй¶ÁËÊý°ÙÍò°ÍÄÃÂí¹«ÃñµÄÃô¸ÐÐÅÏ¢¡£Æ¾Ö¤Ñо¿Ö°Ô±µÄ±íÊö£¬¸ÃÊý¾Ý¿â°üÀ¨3427396Ìõ±êǩΪ¡°»¼Õß¡±µÄ¼Í¼ÒÔ¼°468086Ìõ±êǩΪ¡°²âÊÔ»¼Õß¡±µÄ¼Í¼¡£ÕâЩÐÅÏ¢°üÀ¨ÐÕÃû¡¢³öÉúÈÕÆÚ¡¢Éí·ÝÖ¤ºÅÂë¡¢µØµã¡¢ÓÊÏäºÍµç»°ºÅÂëµÈ¡£ÈôÊÇÊý¾ÝûÓÐÖØ¸´£¬ÕâЩ¼Í¼Լռ¸Ã¹ú×ÜÉú³ÝµÄ90%¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/sensitive-information-of-millions-of-panama-citizens-leaked/