°ÄÖÞ2019ÄêQ1Êý¾Ýй¶ͳ¼Æ±¨¸æ£»£»£»£»SCADDÔâÀÕË÷Èí¼þ¹¥»÷£»£»£»£»½ü90%°ÍÄÃÂí¹«ÃñÐÅϢй¶

Ðû²¼Ê±¼ä 2019-05-14
1¡¢ÈýÐÇÊÖ»úÈí¼þContainerAgent±£´æDoSÎó²î£¬£¬£¬£¬¿Éµ¼ÖÂ×°±¸±äש

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
·¨¹úÇå¾²Ñо¿Ô±Robert Baptiste·¢Ã÷ÈýÐÇÊÖ»úÈí¼þContainerAgentÖб£´æÒ»¸ö¿Éµ¼ÖÂDoSµÄÎó²î£¬£¬£¬£¬¸ÃÎó²îÓ°ÏìÁËÏÕЩËùÓÐÈýÐÇÊÖ»ú£¬£¬£¬£¬¿Éµ¼ÖÂ×°±¸±äש¡£¡£¡£Æ¾Ö¤BaptisteµÄ²©¿Í£¬£¬£¬£¬ContainerAgentĬÈÏÆôÓù㲥ÎüÊÕÆ÷¹¦Ð§£¬£¬£¬£¬¸ÃÎüÊÕÆ÷µÄOnReceiveÒªÁì±£´æÎó²î£¬£¬£¬£¬Í¨¹ýµ÷½â²ÎÊý×îÖտɵ¼ÖÂ×°±¸Ëø¶¨¡£¡£¡£Baptiste»¹ÔÚGithubÉÏÐû²¼ÁËPoC£¬£¬£¬£¬µ«ÈýÐÇÇå¾²ÍŶÓÒÔΪ¸ÃÎó²îûÓÐ/ÏÕЩûÓÐÇå¾²Ó°Ïì¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/white-hat-finds-out-faulty-application-that-reportedly-bricks-all-samsung-phones-e4dad8cc

2¡¢ºÚ¿Íͨ¹ýÈëÇÖAlpaca FormsºÍPicreel»ù´¡ÉèÊ©¹¥»÷4600¶à¸öÍøÕ¾

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
ºÚ¿Íͨ¹ýÈëÇÖÆÊÎöЧÀÍPicreelºÍ¿ªÔ´ÏîÄ¿Alpaca FormsµÄ»ù´¡ÉèÊ©Ìᳫ¹©Ó¦Á´¹¥»÷£¬£¬£¬£¬ÒÑÓÐÁè¼Ý4600¸öÍøÕ¾Êܵ½Ñ¬È¾¡£¡£¡£Ñо¿Ö°Ô±Willem de Groot³ÆÕâÁ½¸ö¹¥»÷»î¶¯ÊÇÓÉͳһ¸ö¹¥»÷ÕßËùΪ£¬£¬£¬£¬µ«Éв»ÇåÎúÆäÈëÇÖ·½·¨¡£¡£¡£¹¥»÷ÕßÐÞ¸ÄÁËPicreel¼°Alpaca Forms CDN»ù´¡ÉèÊ©ÉϵÄJavaScriptÎļþ£¬£¬£¬£¬ÓÃÓÚÇÔÈ¡Óû§ÔÚÍøÒ³±íµ¥ÖÐÊäÈëµÄÄÚÈݲ¢·¢ËÍÖÁλÓÚ°ÍÄÃÂíµÄЧÀÍÆ÷¡£¡£¡£Êܵ½Ñ¬È¾µÄPicreel¾ç±¾ÒÑÔÚ1249¸öÍøÕ¾ÉÏ·¢Ã÷£¬£¬£¬£¬¶øAlpaca Forms¾ç±¾ÔòÓ°ÏìÁË3435¸öÍøÕ¾¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/hackers-are-collecting-payment-details-user-passwords-from-4600-sites/

3¡¢SCADDÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬Áè¼Ý2.5Íò»¼ÕßÐÅÏ¢ÊÜËð

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
ÃÀ¹ú¿µÖݶ«Äϲ¿µÄ½ä¾Æ½ä¶¾Î¯Ô±»á£¨SCADD£©ÔâÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¸Ã¹¥»÷ÊÂÎñµ¼ÖÂ25148Ãû»¼ÕßµÄСÎÒ˽¼ÒÐÅÏ¢ÊÜË𣬣¬£¬£¬ÕâЩÐÅÏ¢°üÀ¨ÐÕÃû¡¢µØµã¡¢Éç»áÇå¾²ºÅÂëÒÔ¼°²¡Ê·ºÍÖÎÁÆÐÅÏ¢¡£¡£¡£SCADDÓÚ2ÔÂ18ÈÕ·¢Ã÷ÁËÕâÒ»ÊÂÎñ£¬£¬£¬£¬¸Ã×éÖ¯Á¬Ã¦¾ÙÐÐÁËÖÜÈ«ÊӲ죬£¬£¬£¬²¢ÓëµÚÈý·½Ç徲ר¼ÒÏàÖúÒÔÈ·ÈÏÄÄЩÐÅÏ¢Êܵ½Ë𺦡£¡£¡£SCADD½«ÎªÊÜÓ°ÏìµÄ»¼ÕßÌṩÃâ·ÑµÄÐÅÓÃ¼à¿ØºÍÉí·Ý±£»£»£»£»¤Ð§ÀÍ¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/the-southeastern-council-on-alcoholism-and-drug-dependence-hit-with-a-ransomware-attack-77498d74

4¡¢°ÄÖÞÐÅϢרԱ°ì¹«ÊÒÐû²¼2019ÄêQ1Êý¾Ýй¶ͳ¼Æ±¨¸æ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
°Ä´óÀûÑÇÐÅϢרԱ°ì¹«ÊÒ£¨OAIC£©Ðû²¼2019ÄêµÚÒ»¼¾¶ÈµÄÊý¾Ýй¶ͳ¼Æ±¨¸æ£¬£¬£¬£¬¸Ã±¨¸æÍ³¼ÆÁË1ÔÂ1ÈÕÖÁ3ÔÂ31ÈÕOAICÎüÊÕµ½µÄÊý¾Ýй¶ÊÂÎñ֪ͨ¡£¡£¡£×ܵÄÀ´ËµOAIC¹²ÊÕµ½215¸öÊý¾Ýй¶֪ͨ£¬£¬£¬£¬±ÈÉÏÒ»¼¾¶È£¨2018ÄêQ4£©µÄ262´ÎÒªÉÙ¡£¡£¡£Áè¼Ý1000ÍòÈËÔÚµ¥´ÎÊÂÎñÖÐÊܵ½Ó°Ï죬£¬£¬£¬¶ø°Ä´óÀûÑǵÄÉú³ÝԼΪ2540Íò¡£¡£¡£±¾¼¾¶ÈÊÜÓ°Ïì×îÑÏÖØµÄСÎÒ˽¼ÒÐÅÏ¢ÊÇÁªÏµÐÅÏ¢£¬£¬£¬£¬¹²ÓÐ186¸öÊý¾Ýй¶ÊÂÎñÓ°ÏìÁË´ËÀàÊý¾Ý£¬£¬£¬£¬Æä´ÎÊÇСÎÒ˽¼Ò²ÆÎñÐÅÏ¢£¨Óë98¸öÊÂÎñÓйأ©ºÍÉí·ÝÐÅÏ¢£¨Óë55¸öÊÂÎñÓйأ©¡£¡£¡£OAICÌåÏÖÕâÊÇ×îºóÒ»´ÎÐû²¼¼¾¶È±¨¸æ£¬£¬£¬£¬ÒÔºó½«Ã¿Áù¸öÔÂÐû²¼Ò»´Î¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/over-10-million-people-hit-in-single-australian-data-breach-oaic/

5¡¢Ñо¿ÍŶÓÐû²¼ScarCruft APT¶ñÒ⹤¾ßµÄÆÊÎö±¨¸æ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
¿¨°Í˹»ùÐû²¼³¯ÏÊAPT×éÖ¯ScarCruftµÄÆÊÎö±¨¸æ¡£¡£¡£¸Ã×éÖ¯±»ÒÔΪÊǹú¼ÒÔÞÖúµÄ¹¥»÷×éÖ¯£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÓ볯Ïʰ뵺ÓйصÄ×éÖ¯ºÍÆóÒµ¡£¡£¡£Æ¾Ö¤Æä×î½üµÄ¹¥»÷»î¶¯£¬£¬£¬£¬¸Ã×éÖ¯ÈÔȻʮ·Ö»îÔ¾£¬£¬£¬£¬²¢ÇÒһֱˢÐÂÆä¹¥»÷¹¤¾ß¡£¡£¡£ScarCruftʹÓõijõʼdropper¿ÉÈÆ¹ýWindows UAC£¬£¬£¬£¬²¢ÇÒʹÓÃÎó²îCVE-2018-8120ÏÂÔØ²¢Ö´ÐÐÏÂÒ»½×¶Îpayload£¨ROKRATºóÃÅ£©¡£¡£¡£±ðµÄ£¬£¬£¬£¬ScarCruft»¹½¨ÉèÁËÒ»¸öÉÙ¼ûµÄ¶ñÒâÈí¼þ-À¶ÑÀ×°±¸ÍøÂçÆ÷£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÓÃÓÚ²éÕÒÒÑÅþÁ¬µÄÀ¶ÑÀ×°±¸²¢ÇÔȡװ±¸ÐÅÏ¢¡£¡£¡£Ñо¿Ö°Ô±»¹·¢Ã÷¸Ã×éÖ¯µÄ¹¥»÷»î¶¯ÓëDarkHotel APT±£´æ¹ØÁª¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://securelist.com/scarcruft-continues-to-evolve-introduces-bluetooth-harvester/90729/

6¡¢Î´ÉèÃÜÂëµÄÊý¾Ý¿âй¶½ü90%°ÍÄÃÂí¹«ÃñÐÅÏ¢

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
Çå¾²Ñо¿Ô±Bob DiachenkoʹÓÃShodanÔÚAWSÉÏ·¢Ã÷Ò»¸öδÊܱ£»£»£»£»¤µÄElasticsearchÊý¾Ý¿â£¬£¬£¬£¬¸ÃÊý¾Ý¿âй¶ÁËÊý°ÙÍò°ÍÄÃÂí¹«ÃñµÄÃô¸ÐÐÅÏ¢¡£¡£¡£Æ¾Ö¤Ñо¿Ö°Ô±µÄ±íÊö£¬£¬£¬£¬¸ÃÊý¾Ý¿â°üÀ¨3427396Ìõ±êǩΪ¡°»¼Õß¡±µÄ¼Í¼ÒÔ¼°468086Ìõ±êǩΪ¡°²âÊÔ»¼Õß¡±µÄ¼Í¼¡£¡£¡£ÕâЩÐÅÏ¢°üÀ¨ÐÕÃû¡¢³öÉúÈÕÆÚ¡¢Éí·ÝÖ¤ºÅÂë¡¢µØµã¡¢ÓÊÏäºÍµç»°ºÅÂëµÈ¡£¡£¡£ÈôÊÇÊý¾ÝûÓÐÖØ¸´£¬£¬£¬£¬ÕâЩ¼Í¼Լռ¸Ã¹ú×ÜÉú³ÝµÄ90%¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/sensitive-information-of-millions-of-panama-citizens-leaked/