¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180820
Ðû²¼Ê±¼ä 2018-08-20¡¾ÍþвÇ鱨¡¿Ñо¿ÍŶӷ¢Ã÷³¯ÏÊAPT×éÖ¯DarkhotelʹÓÃVBScript¾ç±¾ÒýÇæ0dayµÄ¹¥»÷»î¶¯
Ç÷ÊÆ¿Æ¼¼µÄÇå¾²Ñо¿ÍŶӷ¢Ã÷³¯ÏÊAPT×éÖ¯DarkhotelÕýÔÚʹÓÃ΢ÈíVBScript¾ç±¾ÒýÇæÖеÄÁãÈÕÎó²î£¨CVE-2018-8373£©Ìᳫ¹¥»÷»î¶¯£¬£¬£¬£¬¸ÃÎó²îÊÇÒ»¸öuse-after-freeÎó²î£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÔÚÄ¿µÄÅÌËã»úÉÏÔËÐÐshellcode¡£¡£¡£ÔÚ×îа汾µÄWindowsÖУ¬£¬£¬£¬Î¢ÈíÔÚä¯ÀÀÆ÷µÄĬÈÏÉèÖÃÖнûÓÃÁËVBScript£¬£¬£¬£¬Ê¹Æä²»Ò×Êܵ½¹¥»÷¡£¡£¡£Î¢ÈíÒÑÔÚ8ÔÂÇå¾²¸üÐÂÖÐÐÞ¸´ÁË´ËÎó²î¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/zero-day-in-microsofts-vbscript-engine-used-by-darkhotel-apt/
¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±ÑÝʾÔõÑùʹÓÃÓïÒôÐÅÏäÐ®ÖÆPayPalºÍWhatsAppÕË»§
Çå¾²Ñо¿Ö°Ô±Martin Vigo³Æ¹¥»÷Õß¿ÉʹÓÃÓïÒôÐÅÏäÈëÇÖÓû§µÄÔÚÏßÕË»§£¬£¬£¬£¬ÈçPayPalºÍWhatsAppµÈ¡£¡£¡£´ó´ó¶¼ÔËÓªÉ̲»µ«Ö§³Öͨ¹ýÊÖʱ»ú¼ûÓïÒôÐÅÏ䣬£¬£¬£¬»¹Ö§³Öͨ¹ýPINÂëʹÓÃÍⲿµç»°ºÅÂë»á¼ûÓïÒôÐÅÏä¡£¡£¡£Ðí¶àÓû§Ê¹ÓÃÁËĬÈϵÄPINÂ룬£¬£¬£¬ÀýÈçµç»°ºÅÂëµÄºóËÄλ»òÕß1111¼°1234µÈ¼òÆÓÃÜÂë¡£¡£¡£Ñо¿Ö°Ô±ÑÝʾÁËÔõÑùʹÓÃÓïÒôÐÅÏäÀ´ÖØÖÃÓû§µÄÔÚÏßÕË»§µÄÃÜÂ룬£¬£¬£¬²¢×îÖÕÐ®ÖÆÓû§µÄPayPalºÍWhatsAppÕË»§¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.kaspersky.com/blog/hacking-online-accounts-via-voice-mail/23499/
¡¾¶ñÒâÈí¼þ¡¿Ñо¿ÍŶӷ¢Ã÷еÄAZORultľÂí±äÌå¼°ÀÕË÷Èí¼þAurora
SalesforceÑо¿Ö°Ô±Vishal Thakur·¢Ã÷еÄAZORultľÂí±äÌå¼°ÀÕË÷Èí¼þAurora¡£¡£¡£µ½2018Äê7ÔÂ⣬£¬£¬£¬Ñо¿Ö°Ô±ÊӲ쵽¸ÃľÂí±»ÓÃÓÚÕë¶ÔÈ«ÇòÅÌËã»úµÄ¶ñÒâ¹¥»÷»î¶¯ÖУ¬£¬£¬£¬×î³õµÄѬȾǰÑÔÊÇÍøÂç´¹ÂÚÓʼþ£¬£¬£¬£¬Æä°üÀ¨Á½¸öÓÐÓúÉÔØ£¬£¬£¬£¬Ò»¸öÊÇÖ÷ÒªÓÃÓÚÇÔÈ¡Óû§Æ¾Ö¤µÄľÂí£¬£¬£¬£¬ÀýÈçÍâµØÕË»§ºÍä¯ÀÀÆ÷µÄƾ֤µÈ¡£¡£¡£ÁíÒ»¸öÓÐÓúÉÔØÊÇÀÕË÷Èí¼þAurora£¬£¬£¬£¬ÆäÀÕË÷µÄÊê½ðΪ150ÃÀÔª¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/azorult-trojan-serving-aurora-ransomware-by-malactor-oktropys/
¡¾¶ñÒâÈí¼þ¡¿Çå¾²Ñо¿Ö°Ô±·¢Ã÷Ö÷ÒªÕë¶Ôº«¹úµÄÐÂÀÕË÷Èí¼þMAFIA
Ñо¿Ö°Ô±·¢Ã÷Ö÷ÒªÕë¶Ôº«¹úµÄÐÂÀÕË÷Èí¼þ¼Ò×åMAFIA¡£¡£¡£ÏÖÔÚ»¹²»ÖªµÀMAFIAÔõÑù½øÈëÓû§µÄϵͳ£¬£¬£¬£¬µ«ËüºÜ¿ÉÄÜÊÇͨ¹ýÍøÂç´¹ÂڻʵÏÖÕâÒ»²½µÄ¡£¡£¡£MAFIAʹÓÃOpenSSLÀ´¼ÓÃÜÎļþ£¬£¬£¬£¬ËüʹÓÃAES-256Ëã·¨µÄCBCģʽ£¬£¬£¬£¬²¢ÔÚ¼ÓÃܵÄÎļþºó¸½¼Ó.MAFIAÀ©Õ¹Ãû¡£¡£¡£ÓÉÓÚÆä¼ÓÃÜÀú³ÌºÜÂý£¬£¬£¬£¬Óû§¿Éͨ¹ýÖÕÖ¹ÆäÀú³Ì£¨Í¨³£ÃûΪwinlogin.exe£©»ò¹Ø±ÕÅÌËã»úÀ´×èÖ¹Ëü¡£¡£¡£MAFIAʹÓÃTorÊðÀí¾ÙÐÐC2ͨѶ£¬£¬£¬£¬Æäͨ¹ýHTTP GETÇëÇóÀ´·¢ËͼÓÃÜÃÜÔ¿ºÍIV¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://bartblaze.blogspot.com/2018/08/mafia-ransomware-targeting-users-in.html
¡¾¶ñÒâÈí¼þ¡¿Ñо¿»ú¹¹Ðû²¼¹ØÓÚÒøÐÐľÂíTrickbotµÄбäÌåµÄÆÊÎö±¨¸æ
CyberbitÑо¿ÍŶӷ¢Ã÷ÒøÐÐľÂíTrickbotµÄбäÖÖʹÓÃÁËеÄÌӱܼì²âÊÖÒÕ¡£¡£¡£Trickbot×Ô2016ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬£¬£¬£¬Æä°üÀ¨ÇÔÈ¡ä¯ÀÀÆ÷ÐÅÏ¢¡¢ÇÔÈ¡OutlookÐÅÏ¢¡¢Ëø¶¨ÅÌËã»ú¡¢ÍøÂçϵͳºÍÍøÂçÐÅÏ¢ÒÔ¼°ÇÔÈ¡ÓòÃûƾ֤µÈÄ£¿£¿£¿£¿£¿£¿£¿£¿é¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷TrickbotµÄбäÖÖ½ÓÄÉÀú³ÌÍڿյĴúÂë×¢ÈëÊÖÒÕ£¬£¬£¬£¬´ó´ó¶¼Çå¾²²úÆ·¶¼ÎÞ·¨¼ì²âµ½ÕâÖÖÍþв¡£¡£¡£¸Ã±äÌåµÄÐÐΪģʽÀàËÆÓÚÒøÐÐľÂíFlokibot¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.cyberbit.com/blog/endpoint-security/latest-trickbot-variant-has-new-tricks-up-its-sleeve/
¡¾Îó²î²¹¶¡¡¿Ñо¿Ö°Ô±Åû¶¼ÓÄôóISPµÄTRSϵͳÖеÄÒ»¸öÇå¾²Îó²î
8ÔÂ19ÈÕProject InsecurityµÄÁ½ÃûÇå¾²Ñо¿Ö°Ô±Dominik PennerºÍManny MandÅû¶Soleo Communications¿ª·¢µÄTRSϵͳ±£´æÒ»¸öÍâµØÎļþй¶Îó²î¡£¡£¡£TRSϵͳÊÇÖ¸µçÐÅÖмÌЧÀÍ£¬£¬£¬£¬ÓÃÓÚ×ÊÖú¶úÁû»òÓïÑÔÕϰµÈ²Ð¼²ÈËͨ¹ý¼üÅÌ»òÆäËü¸¨Öú×°±¸²¦´òµç»°¡£¡£¡£¼ÓÄôóµÄËùÓÐÖ÷ÒªISP¶¼ÊÜÓ°Ï죬£¬£¬£¬°üÀ¨Rogers¡¢TelusºÍBCEµÈ£¬£¬£¬£¬ÕâЩISPµÄЧÀ͹¤¾ßº¸ÇÁËÁè¼Ý3000Íò¼ÓÄÃÖÁ¹«Ãñ¡£¡£¡£ËùÓеÄÖ÷Òª¼ÓÄôóISP¶¼ÒѾÐÞ¸´Á˸ÃÎó²î¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/canadian-telcos-patch-vulnerability-in-trs-systems/


¾©¹«Íø°²±¸11010802024551ºÅ