FacebookÃ÷ÎÄ´æ´¢ÊýÒÚÃÜÂ룬£¬£¬£¬£¬£¬£¬Ô±¹¤ÅÌÎÊ900Íò´Î£»£»£»APT-C-27ºÍFin7
Ðû²¼Ê±¼ä 2019-03-22
±¾ÖÜËÄFacebookÈÏ¿ÉÊýÒÔÒڼƵÄFacebookºÍInstagramÓû§µÄÃÜÂë¶àÄêÀ´Ò»Ö±ÒÔÃ÷ÎĵÄÐÎʽ´æ´¢ÔÚÄÚ²¿Êý¾ÝϵͳÖС£¡£¡£¡£¡£FacebookÔÚ1Ô·ݵÄÀýÐÐÇå¾²Éó²éʱ´ú·¢Ã÷ÁËÕâÒ»ÎÊÌ⣬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÌåÏÖÕâЩÊý¾Ý²¢Î´Ôâµ½ÀÄÓᣡ£¡£¡£¡£Æ¾Ö¤Çå¾²¼ÇÕßBrian KrebsµÄÒ»·Ý±¨¸æ£¬£¬£¬£¬£¬£¬£¬Ô¼2000Ãû¹¤³Ìʦ»ò¿ª·¢Ö°Ô±¶ÔÕâЩÊý¾Ý¾ÙÐÐÁËԼĪ900Íò´ÎÄÚ²¿ÅÌÎÊ¡£¡£¡£¡£¡£FacebookÉÐδÅû¶ÊÜÓ°ÏìµÄÏêϸÓû§ÈËÊý£¬£¬£¬£¬£¬£¬£¬µ«KrebsµÄ±¨¸æÖгÆÕâÒ»Êý×ÖΪ2ÒÚÖÁ6ÒÚÖ®¼ä¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/facebook-employees-could-access-unencrypted-passwords-for-millions-of-users/2¡¢Zoll Medical¹«Ë¾Ð¹Â¶27.7Íò»¼ÕßµÄСÎÒ˽¼ÒÐÅÏ¢
±¾ÖÜÒ»Ò½ÁÆ×°±¸³§ÉÌZoll Medical±¨¸æ³ÆÔÚÆä×î½üµÄЧÀÍÆ÷Ǩáãʱ´ú£¬£¬£¬£¬£¬£¬£¬277319Ãû»¼ÕßµÄСÎÒ˽¼ÒÐÅÏ¢Ô⵽й¶¡£¡£¡£¡£¡£Zoll³ÆÕâÒ»ÊÂÎñ±¬·¢ÔÚ2018Äê11ÔÂ8ÈÕÖÁ12ÔÂ28ÈÕÖ®¼ä£¬£¬£¬£¬£¬£¬£¬µ«¾Ü¾øÌ¸ÂÛ¸ÃÊÂÎñÊÇÎÞÒâÔì³ÉÕվɺڿ͹¥»÷µÄЧ¹û¡£¡£¡£¡£¡£Ð¹Â¶µÄÊý¾Ý°üÀ¨»¼ÕßµÄÐÕÃû¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢Ò½ÁÆÐÅÏ¢ºÍÉç»áÇå¾²ºÅÂë¡£¡£¡£¡£¡£Zoll³Æ²¢Î´·¢Ã÷ÈκÎÓë´ËÓйصÄÉí·ÝڲƻòµÁÓÃÊÂÎñ£¬£¬£¬£¬£¬£¬£¬ËùÓÐÐÅÏ¢ÏÖÒÑ»ñµÃ°ü¹Ü¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.modernhealthcare.com/technology/devicemaker-data-breach-exposes-277k-patients-information3¡¢VivaGymÊý¾Ý¿âδÉèÃÜÂ룬£¬£¬£¬£¬£¬£¬6000¶àÇóÖ°ÕßÐÅϢй¶

Ñо¿Ö°Ô±·¢Ã÷Î÷°àÑÀ½¡Éí·¿VivaGymµÄÒ»¸öMongoDBÊý¾Ý¿âδÊܱ£»£»£»¤£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂ6608¸öÇóÖ°ÕßµÄÃô¸ÐÐÅÏ¢¼°ÉÙÁ¿ÓªÒµÊý¾Ýй¶¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÊÇVivaGymÕÐÆ¸ÍøÕ¾»ù´¡ÉèÊ©µÄÒ»²¿·Ö£¬£¬£¬£¬£¬£¬£¬ÓÉÒ»¸öÊÖÒÕÏàÖúͬ°é¾ÙÐÐÖÎÀí£¬£¬£¬£¬£¬£¬£¬Ð¹Â¶µÄÊý¾Ý°üÀ¨ÇóÖ°ÕßµÄÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢¾ÓɼÓÃܵÄÃÜÂë¡¢DNI¡¢Óû§Ãû¡¢µÇ¼ÈÕÆÚµÈÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬»¹°üÀ¨Ò»Ð©ÓªÒµÐÅÏ¢ºÍϵͳÈÕÖ¾¡£¡£¡£¡£¡£ÔÚ3ÔÂ8ÈÕÑо¿Ö°Ô±×ª´ïVivaGymºó£¬£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âÒÑ»ñµÃ±£»£»£»¤¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securitydiscovery.com/spanish-gym-franchise-database-exposed-by-partners-data-breach/
4¡¢Fin7й¥»÷»î¶¯£¬£¬£¬£¬£¬£¬£¬Ö÷Òª·Ö·¢SQLRatºÍDNSbot
FlashpointÑо¿Ö°Ô±ÊӲ쵽·¸·¨ÍÅ»ïFin7µÄй¥»÷»î¶¯£¬£¬£¬£¬£¬£¬£¬Ö»¹ÜFin7µÄÈýÃûÖ÷Òª³ÉÔ±±»²¶£¬£¬£¬£¬£¬£¬£¬µ«¸Ã×éÖ¯ÒѾ»Ø¹é£¬£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃÒ»¸öеÄÖÎÀíÃæ°åAstraºÍÁ½¸öжñÒâÈí¼þÑù±¾SQLRat¡¢DNSbotÀ´¹¥»÷ÆóÒµ¡£¡£¡£¡£¡£AstraÊÇPHP±àдµÄ¾ç±¾ÖÎÀíϵͳ£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚ½«¶ñÒâ¾ç±¾ÍÆË͵½ÊÜѬȾµÄÅÌËã»ú¡£¡£¡£¡£¡£SQLRatºÍDNSbot¾ùͨ¹ý´¹ÂÚÓʼþ¾ÙÐзַ¢£¬£¬£¬£¬£¬£¬£¬SQLRatÓÃÓÚÅþÁ¬µ½¹¥»÷ÕßµÄÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬¶øDNSbotÔòÓÃÓÚ´«ÊäÏÂÁî¼°Êý¾Ý¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/fin7-threat-actor-group-makes-a-come-back-with-sqlrat-and-dnsbot-27f1843f5¡¢APT-C-27Ãé×¼Öж«µØÇø£¬£¬£¬£¬£¬£¬£¬Ö÷Òª·Ö·¢njRATºóÃÅ
Ñо¿Ö°Ô±·¢Ã÷·¸·¨ÍÅ»ïGoldmouse£¨ÓÖ³ÆAPT-C-27£©µÄй¥»÷»î¶¯£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÖ÷ҪʹÓÃWinRARÖеĴúÂëÖ´ÐÐÎó²î·Ö·¢njRATºóÃÅ£¬£¬£¬£¬£¬£¬£¬Öж«µØÇø³ÉΪÖ÷ÒªµÄ¹¥»÷Ä¿µÄ¡£¡£¡£¡£¡£ÓÕ¶üÎĵµÖаüÀ¨Óë¿Ö²ÀÏ®»÷ÓйصÄÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÒÔÓÕʹÓû§Ê¹ÓÃWinRAR½âѹ¸ÃÎĵµ¡£¡£¡£¡£¡£ÔÚѬȾϵͳºó£¬£¬£¬£¬£¬£¬£¬njRATºóÃÅ»á¹Ø±Õ·À»ðǽ£¬£¬£¬£¬£¬£¬£¬Æô¶¯¼üÅ̼ͼÏ̲߳¢ÓëC&CЧÀÍÆ÷¾ÙÐÐͨѶ£¬£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þµÄÆäËü¹¦Ð§»¹°üÀ¨Ô¶³ÌSHELL¡¢²å¼þÖ§³Ö¡¢Ô¶³Ì×ÀÃæºÍÎļþÖÎÀí¡£¡£¡£¡£¡£Ñо¿Ö°Ô±»¹·¢Ã÷ʹÓÃÁËÏàͬC£¦C£¨82.137.255.56£©µÄ¶à¸öÖ¼ÔÚÕë¶ÔAndroid×°±¸µÄÑù±¾¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/goldmouse-aka-apt-c-27-targets-the-middle-east-by-leveraging-winrars-dated-security-bug-c8caf7796¡¢Ë¼¿ÆÐÞ¸´Nexus½»Á÷»ú¼°NX-OSÖеÄ5¸öÇå¾²Îó²î
˼¿ÆÐû²¼Nexus½»Á÷»ú¼°NX-OSµÄÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬¹²ÐÞ¸´5¸öÎó²î£¬£¬£¬£¬£¬£¬£¬°üÀ¨Nexus 9000ÖеÄShell EscapeÎó²îÒÔ¼°NX-OSÖеÄδÊÚȨ»á¼û¡¢¾Ü¾øÐ§ÀÍ¡¢ÊðÃûÑéÖ¤²»×¼È·ºÍCLIÏÂÁî×¢ÈëÎó²î¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬Ë¼¿Æ»¹ÐÞ¸´ÁËIP Phone 7800ºÍ8800ÖеľܾøÐ§Àͼ°´úÂëÖ´ÐÐÎó²î£¨CVE-2019-1716£©¡¢´ÅÅ̺ľ¡Îó²î£¨CVE-2019-1766£©¡¢CSRFÎó²î£¨CVE-2019-1764£©ºÍ·¾¶±éÀúÎó²î£¨CVE-2019-1765£©¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/cisco-fixes-several-critical-bugs-patch-tuesday-week-3-march-2019-cb83776fÉùÃ÷£º±¾×ÊѶÓɼøºÚµ£±£ÍøÎ¬ËûÃüÇ徲С×é·ÒëºÍÕûÀí