ºÚ¿ÍÔÚ°µÍø¹ûÕæ320Íò¸öPluto TVÓû§µÄÐÅÏ¢£»£» £»£»£»£»SafariµÄÁ´½Ó¹²Ïí¹¦Ð§¿ÉÐÞ¸ÄÎÊÌ⣬£¬£¬£¬£¬£¬¿ÉÄܱ»ÀÄÓÃ

Ðû²¼Ê±¼ä 2020-11-16

1.ºÚ¿ÍÔÚ°µÍø¹ûÕæ320Íò¸öPluto TVÓû§µÄÐÅÏ¢


1.png


ÉÏÖÜÈý£¬£¬£¬£¬£¬£¬ºÚ¿ÍÔÚ°µÍø¹ûÕæÁ˰üÀ¨320Íò¸öPluto TVÓû§ÐÅÏ¢µÄÊý¾Ý¿â¡£¡£ ¡£¡£¡£¡£¡£¡£Í¨¹ýÊý¾Ý¿âÑù±¾¿ÉÖª£¬£¬£¬£¬£¬£¬Ð¹Â¶Êý¾Ý°üÀ¨Óû§Ãû¡¢µç×ÓÓʼþµØµã¡¢bcrypt¹þÏ£ÃÜÂë¡¢ÉúÈÕ¡¢×°±¸Æ½Ì¨ºÍIPµØµã¡£¡£ ¡£¡£¡£¡£¡£¡£ºÚ¿ÍÉù³Æ´Ë´ÎÊý¾Ýй¶ÊÇÓÉShinyHuntersµ¼ÖµÄ£¬£¬£¬£¬£¬£¬¶ø¸ÃÊý¾Ý¿â¿ÉÄÜÊÇÁ½Äêǰй¶µÄ£¬£¬£¬£¬£¬£¬×îмͼÊÇÔÚ2018Äê10ÔÂ12ÈÕ½¨ÉèµÄ¡£¡£ ¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬Pluto TVÉÐδ֤ʵÊÇ·ñ±¬·¢ÁËÊý¾Ýй¶£¬£¬£¬£¬£¬£¬½öÌåÏÖËûÃÇÕýÔÚÊÓ²ìÖС£¡£ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hacker-shares-32-million-pluto-tv-accounts-for-free-on-forum/


2.ÐÂÐÅÓÿ¨¹¥»÷ͨ¹ýαÔìWebSocketsÇÔÈ¡Óû§ÐÅÏ¢


2.png


Ñо¿Ö°Ô±·¢Ã÷еÄÐÅÓÿ¨¹¥»÷·½·¨£¬£¬£¬£¬£¬£¬Í¨¹ýαÔìÐéαÐÅÓÿ¨ÂÛ̳ºÍWebSocketsÇÔÈ¡Óû§ÐÅÏ¢¡£¡£ ¡£¡£¡£¡£¡£¡£ºÚ¿ÍÊ×ÏÈ»á×¢Èë¶ñÒâ¾ç±¾£¬£¬£¬£¬£¬£¬½«ÌìÉúµÄ»á»°idºÍ¿Í»§¶ËIPµØµã´æ´¢ÔÚä¯ÀÀÆ÷µÄÍâµØ´æ´¢ÖУ¬£¬£¬£¬£¬£¬ÕâЩ²ÎÊýÔÚÉÔºóµÄ»á»°ºó»á·¢Ëͻع¥»÷Õß¡£¡£ ¡£¡£¡£¡£¡£¡£ÎªÁË»ñÈ¡Óû§µÄIPµØµã£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÇÉÃîµØÊ¹ÓÃÁËCloudflareµÄAPI¡£¡£ ¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃWebSocketsÈ¡´úÁËHTMLµÈÆäËûÒªÁìÀ´ÇÔÊØÐÅÏ¢£¬£¬£¬£¬£¬£¬Õâ¿Éʹ¹¥»÷µÄÔëÒô¸üÉÙ¡¢¸üÒþÃØ¡£¡£ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/skimmer-attack-fake-credit-card-steal-data/


3.SafariµÄÁ´½Ó¹²Ïí¹¦Ð§¿ÉÐÞ¸ÄÎÊÌ⣬£¬£¬£¬£¬£¬¿ÉÄܱ»ÀÄÓÃ


3.png


iOS°æ±¾Apple Safariä¯ÀÀÆ÷ÖеÄÁ´½Ó¹²Ïí¹¦Ð§Ê¹iPhone¡¢iPadºÍiPod TouchÓû§¿ÉÒÔÔÚ¹²Ïí²¿·ÖÍøÒ³Ê±¸ü¸ÄÎÊÌ⣬£¬£¬£¬£¬£¬¸Ã¹¦Ð§¿É±»ÀÄÓÃÖÆÔì¼ÙÐÂÎÅ¡£¡£ ¡£¡£¡£¡£¡£¡£µ±Ê¹ÓÃSafariä¯ÀÀÍøÒ³Ê±£¬£¬£¬£¬£¬£¬Óû§¿ÉÒÔ·ÖÏí²¿·ÖÎı¾ÕªÒª¶ø²»ÊÇÕû¸öÒ³Ãæ£¬£¬£¬£¬£¬£¬Ò²¿ÉÒÔ¿ØÖƺͱ༭¸ÃÎı¾¡£¡£ ¡£¡£¡£¡£¡£¡£ÔÚͨ¹ýiMessageÓëÆäËûiPhoneÓû§¹²Ïí¸ÃÒ³ÃæÊ±£¬£¬£¬£¬£¬£¬ÌìÉúµÄÁ´½ÓÔ¤ÀÀΪ¸ÃÎı¾µÄÄÚÈݶø·ÇÍøÒ³µÄԭʼÎÊÌâ¡£¡£ ¡£¡£¡£¡£¡£¡£¸Ã¹¦Ð§¿É±»ÓÃÀ´ÖÆÔì²¢Èö²¥ÐéαÐÂÎÅ£¬£¬£¬£¬£¬£¬ÏÖÔÚÉÐδ±»ÐÞ¸´¡£¡£ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/apple-ios-safari-feature-can-be-used-to-share-fake-news-headlines/


4.°ÄÖÞÕþ¸®Ðû²¼Ô¤¾¯ÎÀÉú²¿·ÖÐè×¢ÖØÌá·ÀSDBBot RAT


4.png


°Ä´óÀûÑÇÕþ¸®Ðû²¼Çå¾²¾¯±¨£¬£¬£¬£¬£¬£¬ÖÒÑÔÎÀÉú²¿·ÖÐè×¢ÖØÌá·ÀSDBBot RAT¡£¡£ ¡£¡£¡£¡£¡£¡£°Ä´óÀûÑÇÍøÂçÇå¾²ÖÐÐÄ£¨ACSC£©ÌåÏÖ£¬£¬£¬£¬£¬£¬×î½üʹÓÃSDBBotÔ¶³Ì»á¼û¹¤¾ß£¨RAT£©¶Ô°Ä´óÀûÑÇÎÀÉú²¿·ÖµÄÕë¶ÔÐԻÓÐËùÔöÌí£¬£¬£¬£¬£¬£¬²¢´ß´Ù¸Ã²¿·ÖµÄ×éÖ¯¼ì²éÆäÍøÂçÇå¾²·ÀÓù²½·¥¡£¡£ ¡£¡£¡£¡£¡£¡£ËäÈ»ACSCûÓÐÌṩÈκιØÓڸù¥»÷»î¶¯µÄϸ½Ú£¬£¬£¬£¬£¬£¬µ«SDBBot RAT»òÐíÓëºÚ¿Í×éÖ¯TA505ÓйØ¡£¡£ ¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬ACSC»¹·¢Ã÷SDBBotÓÉ3¸ö²¿·Ö×é³É£¬£¬£¬£¬£¬£¬»®·ÖΪһ¸ö½¨É賤ÆÚÐÔµÄ×°ÖóÌÐò¡¢Ò»¸öÏÂÔØÌØÊâ×é¼þµÄ¼ÓÔØ³ÌÐòÒÔ¼°RAT×Ô¼º¡£¡£ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/australian-government-warns-of-possible-ransomware-attacks-on-health-sector/


5.SchneideÐû²¼ÓйØLinux¶ñÒâÈí¼þDrovorubµÄÇ徲ͨ¸æ


5.png


SchneideÐû²¼ÁËÒ»¸öÇ徲ͨ¸æ£¬£¬£¬£¬£¬£¬ÖÒÑÔÆäÓû§×¢ÖØLinux¶ñÒâÈí¼þDrovorub¡£¡£ ¡£¡£¡£¡£¡£¡£ÔçÔÚ½ñÄê8Ô£¬£¬£¬£¬£¬£¬NSAºÍFBIÁªºÏÐû²¼¾¯±¨²¢¶Ô¸Ã¶ñÒâÈí¼þ¾ÙÐÐÁËÆÊÎö¡£¡£ ¡£¡£¡£¡£¡£¡£¾Ý³Æ£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÊôÓÚ¶íÂÞË¹ÍøÂçÌØ¹¤×éÖ¯APT28£¬£¬£¬£¬£¬£¬ÊÇÒ»ÖÖÄ£¿£¿£¿£¿£¿£¿ £¿é»¯¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬°üÀ¨Ö²ÈëÎï¡¢ÄÚºËÄ£¿£¿£¿£¿£¿£¿ £¿érootkit¡¢Îļþ´«Ê乤¾ß¡¢¶Ë¿Úת·¢Ä£¿£¿£¿£¿£¿£¿ £¿éºÍÏÂÁîÓë¿ØÖÆ£¨C2£©Ð§ÀÍÆ÷£¬£¬£¬£¬£¬£¬¿ÉÓÃÀ´ÇÔÈ¡Îļþ¡¢½¨ÉèºóÃŲ¢Ô¶³Ì¿ØÖÆÄ¿µÄÅÌËã»ú¡£¡£ ¡£¡£¡£¡£¡£¡£Schneider±Þ²ß¿Í»§ÊµÑé×ÝÉî·ÀÓùÕ½ÂÔ£¬£¬£¬£¬£¬£¬ÒÔ±£»£» £»£»£»£»¤Trio QÊý¾Ý¹ã²¥ºÍTrio JÊý¾Ý¹ã²¥×°±¸ÃâÊÜDrovorub¹¥»÷¡£¡£ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/110920/cyber-crime/drovorub-linux-malware.html


6.ÁãÊÛ¹«Ë¾CencosudѬȾEgregor£¬£¬£¬£¬£¬£¬¹«Ë¾µÄÔËÓªÊܵ½Ó°Ïì


6.png


ÁãÊÛ¹«Ë¾CencosudѬȾÀÕË÷Èí¼þEgregor£¬£¬£¬£¬£¬£¬¹«Ë¾µÄÔËÓªÊܵ½Ó°Ïì¡£¡£ ¡£¡£¡£¡£¡£¡£×ܲ¿Î»ÓÚÖÇÀûµÄ¿ç¹ú¹«Ë¾CencosudÊÇÀ­¶¡ÃÀÖÞ×î´óµÄÁãÊÛ¹«Ë¾Ö®Ò»£¬£¬£¬£¬£¬£¬ÆäÔÚ°¢¸ùÍ¢¡¢°ÍÎ÷¡¢ÖÇÀû¡¢¸çÂ×±ÈÑǺÍÃØÂ³Ä±»®×ÅÖÖÖÖ¸÷ÑùµÄÊÐËÁ¡£¡£ ¡£¡£¡£¡£¡£¡£CencosudÓÚ±¾ÖÜÄ©Ôâµ½ÁËEgregorÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬ÆäÊÐËÁÖеÄ×°±¸±»¼ÓÃÜ£¬£¬£¬£¬£¬£¬²¢Ó°ÏìÁ˹«Ë¾µÄÔËÓª¡£¡£ ¡£¡£¡£¡£¡£¡£²¿·ÖÊÐËÁÖÒÑÔÓÉÓÚÊÖÒÕÎÊÌâ²»½ÓÊÜCencosudÐÅÓÿ¨£¬£¬£¬£¬£¬£¬²»½ÓÊÜÍË»õ»òÒ²²»ÔÊÐíÍøÉϹºÎï¡£¡£ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/retail-giant-cencosud-hit-by-egregor-ransomware-attack-stores-impacted/