AdobeÐû²¼½ôÆÈ²¹¶¡ £¬ÐÞ¸´Æä3¿î²úÆ·ÖеÄ35¸öÎó²î£»ÀÕË÷Èí¼þShade±³ºó×éÖ¯ÊÕÊÖ £¬·Å³ö75Íò¸ö½âÃÜÃÜÔ¿

Ðû²¼Ê±¼ä 2020-04-29

1.AdobeÐû²¼½ôÆÈ²¹¶¡ £¬ÐÞ¸´Æä3¿î²úÆ·ÖеÄ35¸öÎó²î


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


Èí¼þ¹«Ë¾AdobeÓÚ4ÔÂ28ÈÕÐû²¼½ôÆÈÎó²î²¹¶¡ £¬×ܹ²ÐÞ¸´ÁË35¸öÎó²î £¬ÕâЩÎó²îÓ°ÏìµÄ²úÆ·ÓÐAdobe Illustrator¡¢Adobe BridgeºÍµçÉÌÆ½Ì¨Magento¡£´Ë´ÎÇå¾²¸üÐÂÐÞ¸´ÁËWindows°æ±¾Illustrator 2020ÖеÄ5¸ö´úÂëÖ´ÐÐÎó²î £¬Adobe Bridge 10.0.1¼°¸üÔç°æ±¾ÖеÄ17¸öÎó²î£¨14¸ö¿Éµ¼Ö´úÂëÖ´ÐÐÎó²î £¬3¸öÓйØÐÅϢй¶ÎÊÌ⣩ £¬ÉÌÒµ°æ±¾ºÍ¿ªÔ´°æ±¾µÄMagento CMSÖеÄ13¸öÎó²î¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2020/04/adobe-software-updates.html


2.ÀÕË÷Èí¼þShade±³ºó×éÖ¯ÊÕÊÖ £¬·Å³ö75Íò¸ö½âÃÜÃÜÔ¿


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


ÀÕË÷Èí¼þShade±³ºó×éÖ¯ÓÚÖÜÄ©Ðû²¼ÊÕÊÖ £¬²¢ÔÚGitHubÉÏÐû²¼ÁËÁè¼Ý75Íò¸ö½âÃÜÃÜÔ¿¡£¸Ã×éÖ¯ÌåÏÖÆäÔÚÈ¥ÄêÄêµ×¾Í×èÖ¹Á˹¥»÷Ðж¯ £¬ÏÖÔÚÐû²¼ÁË75Íò¸ö½âÃÜÃÜÔ¿ £¬Ò²ÒÑÏú»ÙÁËÇÔÈ¡µÄËùÓÐÊý¾Ý £¬Î´À´»¹»áÐû²¼½âÃÜÈí¼þ¡£ÂÄÀúÖ¤ £¬Õâ´ÎÐû²¼µÄ½âÃÜÃÜÔ¿¿ÉÒÔΪËùÓб»ÀÕË÷Èí¼þShade¼ÓÃܵÄÎļþ½âÃÜ¡£ShadeÊÇ×îÔçµÄÀÕË÷Èí¼þÖ®Ò» £¬ÓÚ2014ÄêµÚÒ»´Î±»·¢Ã÷ £¬Ö±µ½ÊÕÊÖ֮ǰһֱÔÚÒ»Ö±Ìᳫ¹¥»÷ £¬ÏÖÔÚÉв»ÇåÎú¸Ã×éÖ¯ÒòºÎÊÕÊÖ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/shade-troldesh-ransomware-shuts-down-and-releases-all-decryption-keys/


3.ºÚ¿ÍʹÓÃWordPressÖ÷ÌâOneToneÖеÄXSSÎó²î½¨ÉèºóÃÅ


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


¾ÝÍøÂçÇå¾²¹«Ë¾Sucuri±¨µÀ £¬WordPressµÄÖ÷ÌâOneToneÖб£´æXSSÎó²î £¬¶øºÚ¿ÍÔÚ±¾Ô³õ×îÏÈʹÓôËÎó²î £¬ÇÔÈ¡Á÷Á¿ºÍ½¨ÉèºóÃÅ¡£ºÚ¿ÍÊÇͨ¹ýXSSÎó²î×¢Èë¶ñÒâ´úÂëʵÏÖ¹¥»÷µÄ £¬¸Ã´úÂë¾ßÓÐÁ½¸ö¹¦Ð§ £¬Ò»Êǽ«Óû§Öض¨Ïòµ½ischeck[.]xyzÍйܵÄÁ÷Á¿·Ö·¢ÏµÍ³ £¬µÚ¶þ¸öÔòÊǽ¨ÉèºóÃÅ¡£¶ø½¨ÉèºóÃŹ²ÓÐÁ½ÖÖ·½·¨ £¬Ò»ÖÖÊÇÔÚWordPressÖÐÌí¼ÓÖÎÀíÔ±ÕÊ»§£¨Óû§ÃûΪsystem£© £¬ÁíÒ»ÖÖÊÇÔÚ·þÎñÆ÷¶Ë½¨ÉèÖÎÀíÔ±¼¶±ðµÄcookieÎļþ£¨ÃûΪTho3faeKµÄcookieÎļþ£©¡£ÏÖÔÚ¸ÃÎó²îÒÀȻδ±»ÐÞ¸´¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hackers-are-creating-backdoor-accounts-and-cookie-files-on-wordpress-sites-running-onetone/


4.ºÚ¿Íð³ä¿ìµÝ¹«Ë¾Ìᳫ´¹ÂÚ¹¥»÷ £¬·Ö·¢RATµÈ¶ñÒâÈí¼þ


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


¿¨°Í˹»ù£¨Kaspersky£©Ñо¿Ö°Ô±·¢Ã÷ÁËÐÂÒ»ÂÖ´¹ÂÚ¹¥»÷ £¬ºÚ¿Íð³ä¿ìµÝ¹«Ë¾£¨ÈçFedEx¡¢UPSºÍDHL£©·¢ËÍÒÔCOVID-19ΪÖ÷ÌâµÄÓʼþ £¬À´·Ö·¢¶ñÒâÈí¼þ¡£ºÚ¿Íαװ³ÉDHL £¬ÌáÐÑÓû§¶Ô¸½¼þÖеÄÔËÊäÎĵµ¾ÙÐиüÕý £¬ÒÔ´ËÀ´×°ÖÃBsymem¶ñÒâÈí¼þ¡£»¹Î±×°³ÉUPS £¬ÌáÐÑÊÕ¼þÈË·­¿ª¸½¼þÉó²éÎüÊÕ°ü¹üµÄ˵Ã÷ £¬¸Ã¸½¼þ×ÅʵÊǶñÒâÈí¼þµÄ¿ÉÖ´ÐÐÎļþ £¬Êܺ¦Õߵ㿪ºó½«ÏÂÔØºÍ×°ÖÃRAT Remcos¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fake-fedex-and-ups-delivery-issues-used-in-covid-19-phishing/


5.ÃÀ¹úCivicSmart¹«Ë¾ÔâÀÕË÷Èí¼þ¹¥»÷ £¬ÄÚ²¿Îļþй¶


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


ÃÀ¹úÖÇÄÜÍ£³µÊÕ·ÑÏµÍ³ÖÆÔìÉÌCivicSmartÔâµ½ÁËÀÕË÷Èí¼þSodinokibi¹¥»÷ £¬Æä159 GBµÄÊý¾Ý±»µÁ £¬°üÀ¨Ô±¹¤ÐÅÏ¢¡¢Ó빩ӦÉ̵ÄÌõÔ¼¡¢ÒøÐжÔÕʵ¥ÒÔ¼°¿Í»§ÐÅÓÿ¨ºÅÂë¡£Õâ¸öÐÂÎÅÊǺڿÍÐû²¼ÔÚÍøÉ쵀 £¬ËüÖ¸Ã÷ÎúÊܺ¦Õß²¢Ð¹Â¶Á˱»µÁÎļþÒÔÊÔͼÀÕË÷Êê½ð £¬ÕâÅú×¢CivicSmart¿ÉÄÜûÓÐÖ§¸¶×ã¹»µÄÊê½ð¡£ÒÔÉ«ÁÐÇå¾²¹«Ë¾Under Breach ÔÚ3Ô¾Í×¢ÖØµ½ÁËÕâ´Î¹¥»÷ £¬¿ÉÊDz¢Î´ÓèÒÔÅû¶¡£Ö®ºóCivicSmart¹«Ë¾Ö§¸¶ÁË×ã¹»µÄÊê½ð²¢ÐÞ¸´ÁËÎó²î £¬ºÚ¿ÍÒ²Ïú»ÙÁ˱»µÁÊý¾Ý¡£


Ô­ÎÄÁ´½Ó£º

https://statescoop.com/smart-parking-meter-vendor-data-stolen-ransomware-attack/


6.¼ÓÄôóParkviewÒ½ÔºÔâÀÕË÷Èí¼þMeditech¹¥»÷ÖÂϵͳ̱»¾


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


¼ÓÄôóµÄParkviewÒ½ÔºÓÚÉÏÖÜÎåÈ·ÈÏ £¬ÆäÔâµ½ÁËÍøÂç¹¥»÷ £¬²¢ÇҸù¥»÷ÒѾ­Ó°Ïìµ½ÁËÒ½ÔºµÄ»ù´¡ÉèÊ©¡£¹¥»÷±¬·¢ÔÚ4ÔÂ21ÈÕ £¬¾ÝÊÂÇéְԱ˵ £¬Ò½ÔºÓÃÓÚ´æ´¢»¼ÕßÐÅÏ¢µÄϵͳMeditech±»ÀÕË÷Èí¼þ¹¥»÷ £¬µ¼ÖÂÎÞ·¨Ê¹Ó᣸ÃÔºµÄ½²»°ÈËÒ²ÒÑÈ·ÈÏ £¬Ò½ÔºÏÖÔÚÕýÔÚʹÓÃÖ½ÖʵļͼϵͳÀ´¸ú×ÙºÍÖÎÁÆ»¼Õß¡£¸ÃÔºÌåÏÖ £¬ÏÖÔÚÊÂÎñÈÔÔÚÊӲ쵱ÖÐ £¬¶ø´Ë´Î¹¥»÷²»»á¶Ô»¼Õß±¬·¢ÈκÎÓ°Ïì¡£


Ô­ÎÄÁ´½Ó£º

https://www.fox21news.com/top-stories/it-incident-under-investigation-at-parkview-medical-center/