¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190305

Ðû²¼Ê±¼ä 2019-03-05
1¡¢Dalil¹«Ë¾MongoDB¿É¹ûÕæ»á¼û£¬£¬£¬£¬£¬£¬£¬ £¬500¶àÍòÓû§Êý¾Ýй¶

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


VPNMentorÑо¿ÍŶӷ¢Ã÷É³ÌØ°¢À­²®Í¨Ñ¶APP DalilµÄMongoDBÊý¾Ý¿â¿É¹ûÕæ»á¼û£¬£¬£¬£¬£¬£¬£¬ £¬µ¼ÖÂÁè¼Ý500ÍòÓû§µÄСÎÒ˽¼ÒÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£Dalilͨ¹ýÍøÂçÓû§ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ £¬¿ÉÒÔ×ÊÖúÓû§Ê¶±ðδ֪µÄµç»°ºÅÂ룬£¬£¬£¬£¬£¬£¬ £¬´Ó¶ø×èֹɧÈŵ绰»òÍÆÏúµç»°µÈ¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷ÆäMongoDBÊý¾Ý¿âδÉèÃÜÂ룬£¬£¬£¬£¬£¬£¬ £¬ÕâÒâζÕß¹¥»÷ÕßÎÞÐèÉí·ÝÑéÖ¤¼´¿É»á¼ûÓû§µÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬ £¬°üÀ¨ÊÖ»úºÅÂë¡¢IPµØµã¡¢×°±¸Ðͺš¢ÐòÁкš¢²Ù×÷ϵͳ¡¢IMEI¡¢SIM¿¨ÐÅÏ¢¡¢GPSÐÅÏ¢ÒÔ¼°ÓÊÏäÕË»§¡¢ÐÕÃû¡¢ÐÔ±ðºÍÖ°ÒµµÈ¡£¡£¡£¡£¡£¡£¡£

  

 Ô­ÎÄÁ´½Ó£º

https://www.vpnmentor.com/blog/dalil-data-breach/

2¡¢À­ÌØÀ¼Ò½ÁÆÖÐÐÄÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬ £¬Áè¼Ý7ÍòÃû»¼ÕßµÄÐÅϢй¶

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


¾Ý±¨µÀ£¬£¬£¬£¬£¬£¬£¬ £¬ÃÀ¹úÀ­ÌØÀ¼µØÇøÒ½ÁÆÖÐÐÄ£¨RRMC£©µÄÔ±¹¤ÓÊÏäÔ⵽δÊÚȨ»á¼û£¬£¬£¬£¬£¬£¬£¬ £¬Áè¼Ý7ÍòÃû»¼ÕßµÄÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£ÍƲâÕâÒ»ÊÂÎñ±¬·¢ÔÚ2018Äê12ÔÂ31ÈÕ£¬£¬£¬£¬£¬£¬£¬ £¬Ð¹Â¶µÄÐÅÏ¢°üÀ¨»¼ÕßµÄÐÕÃû¡¢ÁªÏµÐÅÏ¢ºÍÒ½ÁƼͼºÅÂ룬£¬£¬£¬£¬£¬£¬ £¬±ðµÄ£¬£¬£¬£¬£¬£¬£¬ £¬ÉÐÓÐÁè¼Ý4000¸öÉç»áÇå¾²ºÅÂ루SSN£©Ð¹Â¶¡£¡£¡£¡£¡£¡£¡£RRMCÒѾ­ÏòÃÀ¹úÎÀÉúÓ빫ÖÚЧÀͲ¿×ª´ïÁËÏà¹ØÊÂÎñ£¬£¬£¬£¬£¬£¬£¬ £¬²¢ÔÊÐíΪSSNй¶µÄ»¼ÕßÌṩÐÅÓÃ¼à¿ØºÍ»Ö¸´Ð§ÀÍ¡£¡£¡£¡£¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/data-breach-affects-over-72000-patients-of-rutland-regional-medical-center-79d12a09

3¡¢Ë¼¿ÆÐû²¼2019Äê¶ÈCISO»ù×¼Ñо¿±¨¸æ£¬£¬£¬£¬£¬£¬£¬ £¬Ì½ÌÖÇå¾²Ç÷ÊÆµÄת±ä

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

˼¿ÆÐû²¼2019Äê¶ÈCISO»ù×¼Ñо¿±¨¸æ£¬£¬£¬£¬£¬£¬£¬ £¬¸Ã±¨¸æÕë¶ÔÈ«Çò²î±ðÐÐÒµºÍ²î±ð¹æÄ£µÄÆóÒµµÄÊ×ϯÐÅÏ¢Çå¾²¹Ù¾ÙÐÐÁ˵÷ÑУ¬£¬£¬£¬£¬£¬£¬ £¬¹²ÓÐ18¸ö¹ú¼Ò/µØÇøµÄ3200¶àÃûÊÜ·ÃÕß½ÓÊÜÁ˵÷ÑС£¡£¡£¡£¡£¡£¡£µ÷Ñз¢Ã÷ÆóÒµµÄÍøÂçÍŶӺÍÇå¾²ÍŶӾÙÐÐЭ×÷¿ÉÒÔÏÔÖø½µµÍÇå¾²ÊÂÎñµÄ±¾Ç®-µÍÓÚ10ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬ £¬93£¥µÄÊ×ϯÐÅÏ¢Çå¾²¹Ù³ÆÇ¨áãµ½ÔÆÇéÐοÉÒÔÌá¸ßÍŶӵÄЧÂÊ¡£¡£¡£¡£¡£¡£¡£ÊӲ컹·¢Ã÷£¬£¬£¬£¬£¬£¬£¬ £¬Î£º¦ÆÀ¹ÀºÍΣº¦Ö¸±ê¹á´®ÁËÆóÒµµÄÓªÒµÁ÷³Ì¡£¡£¡£¡£¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://www.cisco.com/c/dam/m/digital/elq-cmcglobal/witb/1963786/2019CISOBenchmarkReportCiscoCybersecuritySeries.pdf

4¡¢FireEyeÐû²¼¹ØÓÚ·¸·¨ÍÅ»ïAPT40µÄÆÊÎö±¨¸æ

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

FireEyeÐû²¼¹ØÓÚ·¸·¨ÍÅ»ïAPT40µÄÆÊÎö±¨¸æ£¬£¬£¬£¬£¬£¬£¬ £¬¸ÃÍÅ»ïÖÁÉÙ´Ó2013Äê×îÏÈÔË×÷£¬£¬£¬£¬£¬£¬£¬ £¬Ö÷ÒªÕë¶Ô¹¤³Ì¡¢ÔËÊäºÍ¹ú·À¹¤Òµ£¬£¬£¬£¬£¬£¬£¬ £¬ÓÈÆäÊÇÕâЩÐÐÒµÓ뺣ÊÂÊÖÒÕÖØµþµÄ·½Ãæ¡£¡£¡£¡£¡£¡£¡£Ò»Ð©ÏêϸĿµÄ°üÀ¨¼íÆÒÕ¯¡¢±ÈÀûʱ¡¢µÂ¹ú¡¢ÖйúÏã¸Û¡¢·ÆÂɱö¡¢ÂíÀ´Î÷ÑÇ¡¢Å²Íþ¡¢É³Ìذ¢À­²®¡¢ÈðÊ¿¡¢ÃÀ¹úºÍÓ¢¹ú¡£¡£¡£¡£¡£¡£¡£APT40Ö÷Ҫͨ¹ý´¹Âڻ¾ÙÐй¥»÷£¬£¬£¬£¬£¬£¬£¬ £¬ÆäÖ÷ҪʹÓÃÎó²îCVE-2012-0158¡¢CVE-2017-0199¡¢CVE-2017-8759ºÍCVE-2017-11882¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.fireeye.com/blog/threat-research/2019/03/apt40-examining-a-china-nexus-espionage-actor.html

5¡¢IBMÑо¿ÍŶÓÔÚ¶à¸ö·Ã¿ÍÖÎÀíϵͳÖз¢Ã÷19¸öÇå¾²Îó²î

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

IBM X-ForceÑо¿ÍŶÓÔÚÎå¸öÊ¢ÐеķÿÍÖÎÀíϵͳÖз¢Ã÷19¸öÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄϵͳ°üÀ¨HID Global£¨EasyLobby Solo£©¡¢Threshold£¨eVisitorPass£©¡¢Envoy£¨Envoy Passport£©ºÍThe Receptionist£¨The Receptionist£©¡£¡£¡£¡£¡£¡£¡£Îó²îµÄ¹æÄ£´ÓÊý¾Ýй¶¡¢³ÌÐò½ÓÊܵ½·Ã¿ÍʹÓÃWindowsÈȼü½øÈëÖÕ¶ËÇéÐεȡ£¡£¡£¡£¡£¡£¡£Ïà¹Ø¹©Ó¦ÉÌÒѾ­ÐÞ¸´ÁËÕâЩÎó²î£¬£¬£¬£¬£¬£¬£¬ £¬ÍêÕûÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/visitor-kiosk-bugs/142433/

6¡¢Õë¶ÔÒÔÉ«ÁеĹ¥»÷»î¶¯#OpJerusalem£¬£¬£¬£¬£¬£¬£¬ £¬Ö÷Òª·Ö·¢JCry

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ÉÏÖÜÄ©£¬£¬£¬£¬£¬£¬£¬ £¬Êý°Ù¸öÒÔÉ«ÁÐÍøÕ¾³ÉΪ#OpJerusalemµÄ¹¥»÷Ä¿µÄ£¬£¬£¬£¬£¬£¬£¬ £¬¹¥»÷ÕßÊÔͼʹÓÃÀÕË÷Èí¼þJCryѬȾWindowsÓû§¡£¡£¡£¡£¡£¡£¡£µ«ÓÉÓÚ¹¥»÷ÕߵĴúÂëÍÉ»¯£¬£¬£¬£¬£¬£¬£¬ £¬ÕâÐ©ÍøÕ¾Ö»ÊDZ»¸Ä¶¯ÁËÒ³Ãæ£¬£¬£¬£¬£¬£¬£¬ £¬²¢Ã»Óзַ¢JCry¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÐÞ¸ÄÁËÉÏÍø²å¼þnagichµÄDNS¼Í¼£¬£¬£¬£¬£¬£¬£¬ £¬µ±Óû§Ê¹Óøòå¼þ»á¼ûÍøÕ¾Ê±£¬£¬£¬£¬£¬£¬£¬ £¬¹¥»÷Õߵľ籾½«¼ì²âä¯ÀÀÆ÷ÊðÀíÒÔÈ·ÈÏÊÇ·ñWindowsϵͳ£¬£¬£¬£¬£¬£¬£¬ £¬ÈôÊÇÊÇ£¬£¬£¬£¬£¬£¬£¬ £¬Ôòͨ¹ýÐéαAdobe¸üзַ¢JCry¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/opjerusalem-targeted-israeli-windows-users-with-jcry-ransomware/

ÉùÃ÷£º±¾×ÊѶÓÉ¿­·¢k8άËûÃüÇ徲С×é·­ÒëºÍÕûÀí