ºÚ¿ÍʹÓÃSalesforceÕÊ»§·¢ËÍÐéα·¢Æ±¾ÙÐд¹ÂÚ£» £»£»ÀÕË÷Èí¼þNemtyбäÖÖͨ¹ýÐéαPayPalÍøÕ¾Èö²¥

Ðû²¼Ê±¼ä 2019-09-09

1.ÐÂÎ÷À¼µÚ¶þ¼¾¶ÈÒòÍøÂç¹¥»÷µ¼ÖÂ650ÍòÃÀÔª¾­¼ÃËðʧ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ÐÂÎ÷À¼ÌìÏÂÅÌËã»úÓ¦¼±ÏìӦС×飨CERT NZ£©Ðû²¼2019ÄêµÚ¶þ¼¾¶ÈÍøÂçÊÂÎñ±¨¸æ£¬£¬ £¬£¬±¨¸æÏÔʾQ2ÍøÂç¹¥»÷Ôì³ÉµÄ¾­¼ÃËðʧ´ï650ÍòÃÀÔª£¬£¬ £¬£¬ÊÇÆù½ñΪֹ±¨¸æµÄ×î¸ß½ð¶î¡£¡£¡£ ¡£¡£µÚ¶þ¼¾¶È¹²±¨¸æÁË1197ÆðÇå¾²ÊÂÎñ£¬£¬ £¬£¬±ÈµÚÒ»¼¾¶ÈÔöÌíÁË21%¡£¡£¡£ ¡£¡£ÔÚËùÓÐÊÂÎñÖУ¬£¬ £¬£¬ÓÐ23%Éæ¼°µ½Ä³ÖÖÀàÐ͵ľ­¼ÃËðʧ¡£¡£¡£ ¡£¡£Õ©Æ­ÓëڲƭÊÂÎñÔÚµÚ¶þ¼¾¶ÈÕ¼±È×î¸ß£¬£¬ £¬£¬´ï38%¡£¡£¡£ ¡£¡£ÀÕË÷Èí¼þÊÂÎñ±ÈÉÏÒ»¼¾¶ÈÔöÌíÁË38%£¬£¬ £¬£¬´ó´ó¶¼ÊÂÎñ±¨¸æÀ´×ÔÓÚÆóÒµºÍ×éÖ¯¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/scams-and-ransomware-cost-kiwis/


2.ºÚ¿ÍʹÓÃSalesforceÕÊ»§·¢ËÍÐéα·¢Æ±¾ÙÐд¹ÂÚ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


AvananÑо¿Ö°Ô±·¢Ã÷Ò»¸öеÄÍøÂç´¹ÂÚ¹¥»÷£¬£¬ £¬£¬¹¥»÷ÕßʹÓÃSalesforceµÄ·¢Æ±·¢Ë͹¦Ð§Ãé×¼Ò»¸öÈ«Çò²Æ²ú500Ç¿ÆóÒµ¡£¡£¡£ ¡£¡£¹¥»÷ÕßʹÓÃÄ¿µÄÆóÒµ¹©Ó¦É̵ÄSalesforceÕÊ»§Ïò¿Í»§·¢ËÍ´øÓÐÐéα·¢Æ±µÄ´¹ÂÚÓʼþ£¬£¬ £¬£¬ÓÉÓÚÕâЩÐéα·¢Æ±¸´ÖÆÁËÕýµ±·¢Æ±µÄģʽ£¬£¬ £¬£¬Òò´ËOffice 365µÄÇå¾²·À»¤¹¦Ð§ÏÕЩÎÞ·¨×·×ÙËüÃÇ¡£¡£¡£ ¡£¡£SalesforceÔÆÆ½Ì¨Òѱ»È«ÇòÁè¼Ý15Íò¼ÒÆóҵʹÓ㬣¬ £¬£¬Òò´Ë¿Í»§ºÜÈÝÒ×ÐÅÈÎÒԸù«Ë¾ÓòÃû×îºóµÄ·¢¼þÈËÐÅÏ¢¡£¡£¡£ ¡£¡£ÔÚ¸ÃÆð°¸ÀýÖУ¬£¬ £¬£¬Ä¿µÄÆóÒµÔ¼ÓÐ1056ÈËÊÕµ½ÁË´¹ÂÚÓʼþ£¬£¬ £¬£¬ÕâÊǸù«Ë¾µÄËùÓÐÁªÏµÈË¡£¡£¡£ ¡£¡£¹¥»÷ÕßµÄÖ÷ҪĿµÄÊÇÔÚÆóÒµÖÕ¶ËÉÏ×°ÖÃľÂí£¬£¬ £¬£¬Ñо¿Ö°Ô±ÒÔΪÕâÖÖ¹¥»÷ͬÑùÊÊÓÃÓÚ·¢Æ±Ú²Æ­ºÍƾ֤ÇÔÈ¡¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.avanan.com/resources/salesforce-phishing-attack


3.ÀÕË÷Èí¼þNemtyбäÖÖͨ¹ýÐéαPayPalÍøÕ¾Èö²¥


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Çå¾²Ñо¿Ô±nao_sec·¢Ã÷ÀÕË÷Èí¼þNemtyµÄбäÖÖͨ¹ýÐéαµÄPayPalÍøÕ¾¾ÙÐÐÈö²¥¡£¡£¡£ ¡£¡£³ý´ËÖ®Í⣬£¬ £¬£¬¸ÃÀÕË÷Èí¼þ×î½ü»¹±»ÊӲ쵽ͨ¹ýRIG EK·Ö·¢£¬£¬ £¬£¬ÕâÒâζ×ÅNemty¹¥»÷ÕßÕýÔÚÆð¾¢ÊµÑéÖݪֲî±ðµÄ·Ö·¢ÇþµÀ¡£¡£¡£ ¡£¡£¸ÃÐéαPayPalÍøÕ¾Ä£ÄâÁËÕæÊµÒ³ÃæµÄÊÓ¾õЧ¹ûºÍ½á¹¹£¬£¬ £¬£¬»¹ÔÚÍøÕ¾¸÷¸ö²¿·ÖµÄÁ´½ÓÖÐʹÓÃÁËͬÐÎÒìÒåÓòÃûÓÕÆ­¹¥»÷£¨°üÀ¨×ÊÖú¡¢ÁªÏµÈË¡¢Óöȡ¢Çå¾²¡¢Ó¦ÓúÍÊÐËÁ£©¡£¡£¡£ ¡£¡£Ö÷Á÷ä¯ÀÀÆ÷½«¸ÃÍøÕ¾±ê¼ÇΪΣÏÕ£¬£¬ £¬£¬µ«ÈÔÓÐÓû§¿ÉÄÜ»áÈÆ¹ýÌáÐѼÌÐøÏÂÔØºÍÔËÐжñÒâÈí¼þ£¨cashback.exe£©¡£¡£¡£ ¡£¡£Çå¾²Ñо¿Ô±Vitali KremezÆÊÎöÁËNemtyµÄÕâÒ»±äÖÖ£¬£¬ £¬£¬·¢Ã÷ÆäΪ°æ±¾1.4²¢ÇÒ´øÓÐһЩbugÐÞ¸´¡£¡£¡£ ¡£¡£´ó´ó¶¼Çå¾²²úÆ·¿ÉÒÔ¼ì²âµ½¸Ã±äÖÖ£¬£¬ £¬£¬VirusTotalÉÏ68¸ö·À²¡¶¾ÒýÇæÖÐÓÐ36¸ö¿ÉÒÔ¼ì²âµ½Ëü¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fake-paypal-site-spreads-nemty-ransomware/


4.MeridianÉçÇøÑ§ÔºÅû¶1Ô·ÝÓû§Òþ˽й¶ÊÂÎñ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÃÜÎ÷Î÷±ÈÖÝMeridianÉçÇøÑ§Ôº£¨MCC£©Åû¶1Ô·ÝÔâÓöµÄÓû§Òþ˽й¶ÊÂÎñ¡£¡£¡£ ¡£¡£ÔÚ1ÔÂÏÂÑ®MCCÔâÓöÍøÂç´¹ÂÚÊÂÎñµ¼Ö²¿·ÖÓû§µÄƾ֤Ô⵽й¶£¬£¬ £¬£¬MCC×îÏÈÓëµÚÈý·½È¡Ö¤¹«Ë¾ÏàÖú¾ÙÐÐÊӲ졣¡£¡£ ¡£¡£4ÔÂ12ÈÕÊÓ²ìÖ°Ô±²»¿ÉÈ·Èϲ¿·ÖÔ±¹¤µÄÓÊÏäÕË»§ÊÇ·ñÔâδÊÚȨ»á¼û£¬£¬ £¬£¬MCC×îÏÈÊÖ¶¯Éó¼ÆÕâЩÕË»§µÄÓʼþºÍ¸½¼þÖеÄÃô¸ÐÐÅÏ¢¡£¡£¡£ ¡£¡£ÉóºËÓÚ6ÔÂ25ÈÕ¿¢Ê£¬£¬ £¬£¬È»ºóMCC×îÏÈ×·×ÙÊÜÓ°ÏìÓû§µÄÁªÏµ·½·¨¡£¡£¡£ ¡£¡£9ÔÂ5ÈÕMCCÐû²¼ÐÂΟåÅû¶ÁËÕâÒ»ÊÂÎñ¡£¡£¡£ ¡£¡£¿£¿£¿£¿ £¿ÉÄÜй¶µÄÓû§ÐÅÏ¢°üÀ¨ÐÕÃû¡¢Éç»áÇå¾²ºÅÂë¡¢¼ÝÕÕºÅÂë¡¢»¤ÕÕºÅÂë¡¢³öÉúÈÕÆÚ¡¢Óû§Ãû»òÓÊÏäÕË»§Ãû¼°ÃÜÂë¡¢Ò½ÁÆÐÅÏ¢¼°°ü¹ÜÐÅÏ¢µÈ¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://finance.yahoo.com/news/meridian-community-college-provides-notice-000000176.html


5.Monster.comÒòµÚÈý·½»ú¹¹µ¼ÖÂÇóÖ°ÕßÐÅϢй¶


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ñо¿Ö°Ô±·¢Ã÷Ò»¸ö¿É¹ûÕæ»á¼ûµÄWebЧÀÍÆ÷й¶ÁËMonster.comÓû§µÄÐÅÏ¢£¬£¬ £¬£¬ÕâЩÐÅÏ¢°üÀ¨2014ÖÁ2017Äêʱ´úʹÓùý¸ÃÍøÕ¾µÄÇóÖ°ÕßÐÅÏ¢£¬£¬ £¬£¬Èçµç»°ºÅÂë¡¢¼Òͥסַ¡¢µç×ÓÓʼþµØµãºÍÊÂÇéÂÄÀúµÈ£¬£¬ £¬£¬µ«²»°üÀ¨ÈκβÆÎñÐÅÏ¢¡£¡£¡£ ¡£¡£MonsterÌåÏÖй¶±¬·¢ÔÚµÚÈý·½»ú¹¹µÄЧÀÍÆ÷ÉÏ£¬£¬ £¬£¬Òò´Ë¸Ã¹«Ë¾ÎÞ·¨Í¨ÖªÓû§¡£¡£¡£ ¡£¡£¸ÃµÚÈý·½»ú¹¹µÄÃû³ÆÎ´Öª£¬£¬ £¬£¬Monster³Æ²»ÔÙÓëÖ®¿ªÕ¹ÓªÒµ¡£¡£¡£ ¡£¡£µÚÈý·½»ú¹¹Ò²Ã»ÓÐ֪ͨÏà¹ØÊܺ¦Õߣ¬£¬ £¬£¬µ«Æ¾Ö¤MonsterµÄ˵·¨£¬£¬ £¬£¬Ð§ÀÍÆ÷ÔÚ½Óµ½Í¨ÖªºóÒѾ­»ñµÃÁ˱£» £»£»¤¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.darkreading.com/cloud/job-seeker-data-exposed-in-monster-file-leak/d/d-id/1335753


6.˼¿ÆTalosÅû¶Blynk-LibraryÖеÄÐÅϢй¶Îó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


˼¿ÆTalosÔÚBlynk-LibraryÖз¢Ã÷Ò»¸öÐÅϢй¶Îó²î¡£¡£¡£ ¡£¡£Blynk-LibraryÊÇÒ»¸öСÐͿ⣬£¬ £¬£¬ÓÃÓÚ½«400¶àÖÖ²î±ðµÄǶÈëʽװ±¸ÅþÁ¬µ½Ë½ÓлòÆóÒµBlynk-ServerʵÀý¡£¡£¡£ ¡£¡£¸ÃÎó²î£¨TALOS-2019-0854/CVE-2019-5065£©ÓëBlynk-LibraryµÄÊý¾Ý°üÆÊÎö¹¦Ð§ÓйØ£¬£¬ £¬£¬²»Çå¾²µÄstrncpyʹÓÃʹµÃ¹¥»÷Õß¿Éͨ¹ý·¢ËͶñÒâÊý¾Ý°ü´¥·¢ÐÅϢй¶¡£¡£¡£ ¡£¡£TalosÈ·ÈÏBlynk-LibraryµÄ0.6.1°æ±¾ÊÜ´ËÎó²îÓ°Ïì¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2019/09/vulnerability-spotlight-information.html