2019ÄêQ1´¹ÂÚ¹¥»÷Ç÷ÊÆ±¨¸æ£»Êý°ÙÍòInstagramÕË»§ÐÅϢй¶£»Ë¹ÀïÀ¼¿¨11¼Ò»ú¹¹µÄ¹ÙÍøÔâºÚ¿Í¹¥»÷

Ðû²¼Ê±¼ä 2019-05-21
1¡¢Ë¹ÀïÀ¼¿¨11¼Ò»ú¹¹µÄ¹ÙÍøÔâºÚ¿Í¹¥»÷

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!
 
¾ÝÍâý±¨µÀ£¬5ÔÂ18ÈÕ˹ÀïÀ¼¿¨ÖÁÉÙ11¼Ò»ú¹¹µÄ¹ÙÍø£¨.lkºÍ.comÍøÕ¾£©ÔâºÚ¿Í¹¥»÷£¬ÊÜÓ°ÏìµÄ»ú¹¹Ãûµ¥°üÀ¨¿ÆÍþÌØ´óʹ¹Ý¡¢Talawakelle²èÒ¶Ñо¿Ëù¡¢Rajarata´óѧµÈ ¡£Ë¹ÀïÀ¼¿¨SLCERT³ÆÃ»ÓÐÕþ¸®ÍøÕ¾£¨gov.lk£©Êܵ½Ó°Ïì ¡£SLCERTÕýÔÚÓëTechCERTºÍÍøÂçÇå¾²ÔËÓª²¿·ÖÏàÖúÒÔÊÓ²ìÏ¢Õù¾ö´ËÊ ¡£5ÔÂ18ÈÕºÍ19ÈÕÊÇ˹ÀïÀ¼¿¨ÍâµØµÄÕ½ÕùÓ¢ÐÛ¼ÍÄîÈÕ£¬¹¥»÷ÕßµÄÄ¿µÄ¿ÉÄÜÓë´ËÓйØ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/websites-of-at-least-eleven-institutions-in-sri-lanka-hit-by-cyber-attacks-3d19a71f


2¡¢Ñо¿Ö°Ô±·¢Ã÷¶ñÒâÈí¼þWinntiµÄLinux±äÌå

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!
 
AlphabetÑо¿Ö°Ô±Chronicle·¢Ã÷¶ñÒâÈí¼þWinntiµÄLinux±äÌå ¡£ChronicleÌåÏָñäÌåÊÇÔÚÉϸöÔ°ݶúÖÆÒ©¹«Ë¾Ôâµ½¹¥»÷ºóÔÚÆäϵͳÉÏ·¢Ã÷µÄ ¡£¸Ã±äÌå¿É×·ËÝÖÁ2015Ä꣬ÆäʱËü±»ÓÃÓÚÕë¶ÔÔ½ÄÏÓÎÏ·¹«Ë¾µÄºÚ¿Í¹¥»÷ÖÐ ¡£¸Ã±äÌåÓÉÁ½²¿·Ö×é³É£ºÓÃÓÚÒþ²ØµÄrootkit×é¼þºÍÏÖʵµÄºóÃÅľÂí ¡£¸ÃLinux±äÌåÓëWindows°æ±¾µÄWinnti 2.0Ö®¼ä±£´æ´úÂëÏàËÆÐÔ£¬²¢ÇÒÓëC&CµÄͨѶЭÒéÒ²ÀàËÆ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/security-researchers-discover-linux-version-of-winnti-malware/


3¡¢TrickbotбäÌ壬Ö÷Ҫͨ¹ýÀ¬»øÓʼþÈö²¥

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!
 
Ç÷ÊÆ¿Æ¼¼Ñо¿ÍŶӼì²âµ½TrickbotµÄÒ»¸öбäÌ壬¸Ã±äÌåͨ¹ýÀ¬»øÓʼþ¾ÙÐÐÈö²¥£¬ÆäʹÓõÄÁ´½ÓÀàËÆÓÚURL hxxps://google[.]dm:443/url?q= ¡£¸ÃURLÖеÄÅÌÎÊ×Ö·û´®²¿·Ö£¨url£¿q = £©Êǽ«Óû§Öض¨Ïòµ½µÄ¶ñÒâURL ¡£ÓÉÓÚÕâÊÇÒ»¸öGoogleÖØ¶¨ÏòÍøÖ·£¬Òò´Ë¿ÉÒÔÈÆ¹ý¶ÔÀ¬»øÓʼþµÄ¹ýÂ˺ÍÓÕÆ­²»ÖªÇéµÄÓû§ ¡£Ò»µ©Ñ¬È¾×°±¸£¬¸Ã±äÌ廹»áʹÓÃMS17-010Îó²î¾ÙÐкáÏòÒÆ¶¯ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://blog.trendmicro.com/trendlabs-security-intelligence/trickbot-watch-arrival-via-redirection-url-in-spam/


4¡¢APWGÐû²¼2019ÄêQ1´¹ÂÚ¹¥»÷Ç÷ÊÆ±¨¸æ

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!
 
ƾ֤APWGµÄ2019ÄêQ1´¹ÂÚ¹¥»÷Ç÷ÊÆ±¨¸æ£¬Õë¶ÔSaaSºÍÍøÂçÓʼþ·þÎñµÄ´¹ÂÚ¹¥»÷ÔöÌíÖÁËùÓд¹ÂÚ¹¥»÷µÄ36%£¬Ê×´ÎÁè¼ÝÁËÖ§¸¶ÏµÍ³Öֱ𣨱¾¼¾¶È¸ÃÖÖ±ðÔâµ½µÄ´¹ÂÚ¹¥»÷Õ¼27%£© ¡£APWG¸ß¼¶Ñо¿Ô±Greg AaronÌåÏÖ£¬´¹ÂÚÕß¶ÔSaaSÍøÕ¾µÇ¼ƾ֤µÄÐËȤÊÇÓÉÓÚËûÃÇ¿ÉÒÔͨ¹ýÓã²æÊ½´¹ÂÚ»ñµÃ²ÆÎñÊý¾ÝºÍСÎÒ˽¼ÒÐÅÏ¢ ¡£2019ÄêQ1¼ì²âµ½µÄ´¹ÂÚÍøÕ¾×ÜÊýÊÇ180768£¬±È2018ÄêQ3µÄ151014ºÍQ4µÄ138328Òª¸ß ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.helpnetsecurity.com/2019/05/20/saas-webmail-phishing-increased/


5¡¢OGUsersÂÛ̳ÔâºÚ¿ÍÈëÇÖ£¬11.3ÍòÓû§ÐÅϢй¶

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!
 
OGUsersÊÇÒ»¸öÒÔ³öÊÛµÁºÅÕË»§ÖøÃûµÄÍøÂç·¸·¨ÂÛ̳£¬Æ¾Ö¤KrebsOnSecurityµÄÐÂÎÅ£¬5ÔÂ12ÈÕOGUsersÔâºÚ¿ÍÈëÇÖ£¬Ô¼11.3ÍòÓû§µÄÓû§Ãû¡¢µç×ÓÓʼþµØµã¡¢¹þÏ£ÃÜÂ롢˽ÈËÐÂÎźÍIPµØµãй¶ ¡£×î³õOGUsersµÄÖÎÀíÔ±ÒÔΪÕâÊÇÒ»´ÎÓ²Å̹ÊÕÏ£¬µ«ËæºóKrebsOnSecurity´ÓÁíÒ»¸öºÚ¿ÍÂÛ̳RaidForumsÉÏ»ñµÃÁ˱»µÁÊý¾Ý¿âµÄ¸±±¾ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/cybercrime-forum-ogusers-gets-hacked-attackers-steal-data-f067bcfc


6¡¢Î´ÉèÃÜÂëµÄÊý¾Ý¿âй¶Êý°ÙÍòInstagramÕË»§ÐÅÏ¢

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!
 
ƾ֤TechCrunch±¨µÀ£¬Çå¾²Ñо¿Ô±Anurag SenÔÚAWSÉÏ·¢Ã÷Ò»¸öδÊܱ£»¤µÄÊý¾Ý¿â£¬¸ÃÊý¾Ý¿â°üÀ¨Êý°ÙÍòInstagramÕË»§µÄÏà¹ØÐÅÏ¢ ¡£ÏÖÔÚ¸ÃÊý¾Ý¿âÒÑÓÐÁè¼Ý4900ÍòÌõ¼Í¼£¬µ«Êý¾ÝÁ¿ÈÔÔÚ°´Ð¡Ê±ÔöÌí ¡£¸ÃÊý¾Ý¿â°üÀ¨´ó×ÚÃûÈË¡¢ÃÀʳ²©Ö÷¡¢Æ·ÅÆÕË»§µÈÓ°ÏìÁ¦½Ï´óµÄInstagramÕË»§µÄÊý¾Ý£¬°üÀ¨Ð¡ÎÒ˽¼Ò×ÊÁÏÕÕÆ¬¡¢¹Ø×¢ÕßÊýÄ¿¡¢µØÀíλÖá¢Ë½ÈËÁªÏµÐÅÏ¢¡¢µç×ÓÓʼþµØµãºÍµç»°ºÅÂëµÈ ¡£¸ÃÊý¾Ý¿âÊôÓÚÓ¡¶ÈÉ罻ýÌåÓªÏú¹«Ë¾Chtrbox£¬ÏÖÔÚÉв»ÇåÎú¸Ã¹«Ë¾ÔõÑù»ñµÃÕâЩÊý¾Ý ¡£


Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/85905/data-breach/instagram-data-leak.html