¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181008

Ðû²¼Ê±¼ä 2018-10-08
1¡¢Ñо¿ÍŶÓÐû²¼¹ØÓÚÆóÒµµç×ÓÓʼþÕ©Æ­£¨BEC£©Ç÷ÊÆµÄÆÊÎö±¨¸æ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ƾ֤Digital ShadowsµÄÆóÒµµç×ÓÓʼþÕ©Æ­£¨BEC£©±¨¸æ£¬£¬£¬ £¬£¬£¬£¬Êý°Ù¼Ò¹«Ë¾ÒòÉèÖùýʧ»ò½«²ÆÎñ²¿·ÖµÄµç×ÓÓʼþ/ÃÜÂëÔÚÏß̻¶£¬£¬£¬ £¬£¬£¬£¬µ¼Ö¸üÒ×Êܵ½BEC¹¥»÷ ¡£¡£¡£¡£¡£¡£¡£Ñо¿ÍŶÓͨ¹ýÉèÖùýʧµÄЧÀÍÆ÷¹²·¢Ã÷ÁËÁè¼Ý1200Íò¸öδÊܱ£» £»£»£»£»¤µÄµç×ÓÓʼþ´æµµ£¬£¬£¬ £¬£¬£¬£¬°üÀ¨.eml¡¢.msg¡¢.pst¡¢.ostºÍ.mboxµÈ ¡£¡£¡£¡£¡£¡£¡£Í¨¹ýËÑË÷ÕâЩ¿É¹ûÕæ»á¼ûµÄÎļþ£¬£¬£¬ £¬£¬£¬£¬×ÝÈ»ÊÇÊÖÒÕ²¢²»¸ßÃ÷µÄ¹¥»÷ÕßÒ²¿ÉÒÔºÜÈÝÒ×µØÕÒµ½Ãô¸ÐµÄСÎÒ˽¼Ò»ò²ÆÎñÐÅÏ¢ ¡£¡£¡£¡£¡£¡£¡£


   Ô­ÎÄÁ´½Ó£º
https://www.digitalshadows.com/about-us/news-and-press/business-email-compromise-made-easy-for-cybercriminals-as-12-5-million-company-email-inboxes-and-33000-finance-department-credentials-openly-accessible-on-the-web/


2¡¢Ñо¿ÍŶӷ¢Ã÷Ö÷ÒªÕë¶Ô¼ÓÄôóµÄ¶ñÒâÈí¼þZeroEvil

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

Blueliv LabsÑо¿ÍŶÓÔÚ9ÔÂÖÐÑ®¼ì²âµ½Ò»¸öеĶñÒâÈí¼þZeroEvil ¡£¡£¡£¡£¡£¡£¡£ZeroEvilÓëÔ¶¿ØÄ¾ÂíARS Loader¾ßÓÐÏàͬµÄ»î¶¯Ä£Ê½£¬£¬£¬ £¬£¬£¬£¬²¢ÇÒ¹²ÏíÁ˲¿·Ö´úÂëºÍ¹¦Ð§£¬£¬£¬ £¬£¬£¬£¬ÕâÒâζ×ÅÆä¿ª·¢ÕßÊÇͳһÈË»òͳһ×éÖ¯ ¡£¡£¡£¡£¡£¡£¡£ZeroEvilÖ÷ÒªÓÃÓÚÕë¶Ô¼ÓÄôóÆóÒµµÄÀ¬»øÓʼþºÍ¶ñÒâ¹ã¸æ»î¶¯ÖУ¬£¬£¬ £¬£¬£¬£¬Æä±³ºóµÄ¹¥»÷ÕßÊÇ·¸·¨ÍÅ»ïAirNaine£¨ÓÖÃûTA545£© ¡£¡£¡£¡£¡£¡£¡£ZeroEvil»áËÑË÷Ä¿µÄÅÌËã»úÓ²ÅÌÉϵÄtext¡¢datºÍdefault_walletÎļþ£¬£¬£¬ £¬£¬£¬£¬²¢½«Æä·¢ËÍÖÁ¹¥»÷Õß ¡£¡£¡£¡£¡£¡£¡£


  Ô­ÎÄÁ´½Ó£º
https://news.softpedia.com/news/airnaine-uses-new-ars-rat-strain-named-zeroevil-against-canadian-businesses-523078.shtml


3¡¢Git¿ª·¢ÍŶÓÐû²¼Çå¾²¸üУ¬£¬£¬ £¬£¬£¬£¬ÐÞ¸´Ò»¸ö¿Éµ¼ÖÂRCEµÄÇå¾²Îó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Git¿ª·¢ÍŶÓÐÞ¸´ÁËGitÏÂÁîÐпͻ§¶Ë¡¢Git DesktopÒÔ¼°AtomÖеÄÒ»¸ö¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐеÄÎó²î ¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î£¨CVE-2018-17456£©¿ÉÔÊÐí¶ñÒâ´úÂë¿ÍÕ»ÔÚÄ¿µÄϵͳÉÏÖ´ÐÐí§Òâ´úÂë ¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÓë¶ñÒâ´úÂë¿ÍÕ»ÖеÄ.gitmodulesÎļþÓйØ£¬£¬£¬ £¬£¬£¬£¬µ±Ê¹ÓÃÏÂÁî--recurse-submodules¿Ë¡´úÂë¿Íջʱ£¬£¬£¬ £¬£¬£¬£¬½«»áµ¼Ö´úÂëÖ´ÐÐ ¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÒÑÔÚGit v2.19.1¡¢GitHub Desktop 1.4.2ºÍAtom 1.31.2ÖÐÐÞ¸´£¬£¬£¬ £¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì¸üÐÂÖÁ×îа汾 ¡£¡£¡£¡£¡£¡£¡£


  Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/git-project-patches-remote-code-execution-vulnerability-in-git/


4¡¢Ñо¿ÍŶӷ¢Ã÷½ü200¸öαװ³ÉÓ¢¹úÐÂÎÅÍøÕ¾µÄ¶ñÒâÓòÃû

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

DomainTools·¢Ã÷197¸ö¸ßΣº¦µÄ¶ñÒâÓòÃû£¬£¬£¬ £¬£¬£¬£¬ÕâЩÓòÃûαװ³ÉBBC News¡¢Sky NewsºÍITV NewsµÈÓ¢¹úÐÂÎÅÍøÕ¾£¬£¬£¬ £¬£¬£¬£¬ÓÃÓÚÓÕÆ­Óû§»á¼û¹ã¸æ¡¢ÍøÂçÓû§ÐÅÏ¢ÉõÖÁÏÂÔØ¶ñÒâÈí¼þµÈ£¬£¬£¬ £¬£¬£¬£¬»òÕßÊÇÓÃÓÚÈö²¥ÐéαÐÂÎÅ ¡£¡£¡£¡£¡£¡£¡£ÕâЩÓòÃû°üÀ¨bbcnew[.]info¡¢theguarsian[.]com¡¢synews[.]coºÍifvnews[.]cnµÈ£¬£¬£¬ £¬£¬£¬£¬ÆäΣº¦ÆÀ·Ö¶¼Áè¼Ý70·Ö ¡£¡£¡£¡£¡£¡£¡£½¨ÒéÓû§ÔÚ»á¼ûÕâЩÐÂÎÅÍøÕ¾Ê±×Ðϸ¼ì²éÆäURL ¡£¡£¡£¡£¡£¡£¡£


  Ô­ÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/fake-news-domains-spoof-uk-news/


5¡¢North American Risk Services¹«Ë¾ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬ £¬£¬£¬£¬²¿·Ö¿Í»§µÄÐÅϢй¶

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

±±ÃÀΣº¦Ð§À͹«Ë¾£¨NARS£©ÔÚ2ÔÂ7ÈÕÖÁ3ÔÂ27ÈÕʱ´úÔâµ½ºÚ¿ÍÈëÇÖ£¬£¬£¬ £¬£¬£¬£¬Î´¾­ÊÚȨµÄ¹¥»÷Õß»á¼ûÁ˹«Ë¾µÄ²¿·Öµç×ÓÓʼþ£¬£¬£¬ £¬£¬£¬£¬Ô¼610Ãû¿Í»§µÄСÎÒ˽¼ÒÐÅϢй¶ ¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢Éç±£ºÅÂë¡¢¼ÝÕÕID¡¢ÒøÐÐÕË»§ÐÅÏ¢¡¢Ò½ÁÆÐÅÏ¢¡¢¿µ½¡°ü¹ÜÐÅÏ¢¡¢ÄÉ˰ÈËʶÓÖÃûÒÔ¼°Óû§Ãû/ÃÜÂëµÈ ¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ¿Í»§¶¼Î»ÓÚ¼ÓÖÝ£¬£¬£¬ £¬£¬£¬£¬¸Ã¹«Ë¾ÕýÔÚÏòÕâЩ¿Í»§·¢ËÍÏà¹ØÍ¨Öª ¡£¡£¡£¡£¡£¡£¡£


  Ô­ÎÄÁ´½Ó£º
https://news.softpedia.com/news/hundreds-of-california-residents-affected-by-north-american-risk-services-breach-523086.shtml


6¡¢°µÍøÊг¡Ë¿³ñ֮·µÄÖÎÀíÔ±ÈÏ×£¬£¬ £¬£¬£¬£¬¿ÉÄÜÃæÁÙ³¤´ï20ÄêµÄÐÌÆÚ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ÎÛÃûÕÑÖøµÄ°µÍøÊг¡Ë¿³ñ֮·µÄÖÎÀíÔ±Gary DavisÓÚÉÏÖÜÎåÈÏ×£¬£¬ £¬£¬£¬£¬Æä½«ÃæÁÙ×î¸ß¿É´ï20ÄêµÄÀÎÓüÖ®ÔÖ ¡£¡£¡£¡£¡£¡£¡£DavisÊǰ®¶ûÀ¼ÈË£¬£¬£¬ £¬£¬£¬£¬ÆäÔÚ2013ÄêΪ˿³ñ֮·µÄ¿Í»§ÌṩЧÀͺÍÖ§³Ö£¬£¬£¬ £¬£¬£¬£¬²¢ÇÒÿÖܶ¼ÊÕµ½ÈËΪ ¡£¡£¡£¡£¡£¡£¡£Ëû×ÊÖúÖÎÀíË¿³ñ֮·Êг¡£¬£¬£¬ £¬£¬£¬£¬²¢Îª¶¾Æ·ÉúÒâµÄÕùÒéµ£µ±Öٲà ¡£¡£¡£¡£¡£¡£¡£DavisÓÚ2014Äê1ÔÂÔÚ°®¶ûÀ¼±»²¶£¬£¬£¬ £¬£¬£¬£¬Ëæºó±»Òý¶ÉÖÁÃÀ¹ú ¡£¡£¡£¡£¡£¡£¡£¾ÝFBI³Æ£¬£¬£¬ £¬£¬£¬£¬2011Äê2ÔÂÖÁ2013Äê7Ô£¬£¬£¬ £¬£¬£¬£¬Ë¿³ñ֮·µÄÉúÒâ×ܶî´ï12ÒÚÃÀÔª ¡£¡£¡£¡£¡£¡£¡£


  Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2018/10/silkroad-admin-gary-davis.html


ÉùÃ÷£º±¾×ÊѶÓɼøºÚµ£±£ÍøÎ¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí