Pwn2OwnºÚ¿Í´óÈüÊ×´ÎÉæ¼°¹¤Òµ¿ØÖÆÏµÍ³£»£»£»£»£»£»£»Î¢Èí³Æ2020Äê°ÂÔ˻Ὣ¿ÉÄܳÉΪAPT28µÄ¹¥»÷¹¤¾ß
Ðû²¼Ê±¼ä 2019-10-30
Pwn2OwnºÚ¿Í´óÈü½«ÌṩÁè¼Ý25ÍòÃÀÔªµÄ½±Àø£¬£¬£¬ÒÔÃãÀøÍÚ¾òICSºÍÏà¹ØÐÒéÎó²î¡£¡£¡£¡£¡£¡£¡£¸Ã»î¶¯½«ÓÚÃ÷Ä꣨1ÔÂ21ÈÕÖÁ1ÔÂ23ÈÕ£©ÔÚÂõ°¢ÃÜS4¾Û»áʱ´ú¾ÙÐС£¡£¡£¡£¡£¡£¡£¡°ºÍÆäËû¾ºÈüÒ»Ñù£¬£¬£¬Pwn2OwnÊÔͼͨ¹ýÕ¹ÏÖÎó²î²¢½«Ñо¿Ð§¹ûÌṩӦ¹©Ó¦ÉÌÀ´Ç¿»¯ÕâЩƽ̨¡±£¬£¬£¬Pwn2Own×éÖ¯Õß¡¢ZDIÌᳫÈËBrian GorencÔÚÖÜÒ»µÄÌû×ÓÖÐÌåÏÖ£¬£¬£¬¡°Pwn2OwnµÄÄ¿µÄʼÖÕÊÇÔÚ¹¥»÷Õ߯ð¾¢Ê¹ÓÃ֮ǰÐÞ¸´ÕâЩÎó²î¡±¡£¡£¡£¡£¡£¡£¡£Pwn2Own MiamiΪÎå¸öICSÀà±ðµÄÎó²îÌṩÁËÖÖÖÖ½±Àø£¬£¬£¬°üÀ¨¿ØÖÆÐ§ÀÍÆ÷½â¾ö¼Æ»®¡¢OPCЧÀÍÆ÷¡¢DNP3ͨѶÐÒé¡¢HMI/²Ù×÷Ô±Õ¾ºÍ¹¤³ÌÊÂÇéÕ¾Èí¼þ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/pwn2own-expands-industrial-control-systems/149594/2¡¢Ó¡¶È130ÍòÕÅÒøÐп¨ÐÅÏ¢ÔÚJoker's StashÉϳöÊÛ
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/details-for-1-3-million-indian-payment-cards-put-up-for-sale-on-jokers-stash/3¡¢·¨¹úʱÉÐÆ·ÅÆSixth June¹ÙÍøÔâMageCart¹¥»÷

·¨¹úʱÉÐÆ·ÅÆSixth June¹ÙÍøÔâMageCart¶ñÒâ¾ç±¾Ñ¬È¾£¬£¬£¬Çå¾²Ñо¿Ö°Ô±Jenkins·¢Ã÷ÁËÕâÒ»ÊÂÎñ²¢ÓÚÉÏÖÜ֪ͨÁ˸ù«Ë¾£¬£¬£¬µ«ÉÐδ»ñµÃ»Ø¸´¡£¡£¡£¡£¡£¡£¡£×èÖ¹ÏÖÔڸöñÒâ´úÂëÈÔ±£´æÓÚÍøÕ¾µÄÖ§¸¶Ò³ÃæÉÏ¡£¡£¡£¡£¡£¡£¡£Sixth JuneÔÚÅ·ÖÞºÜÊܽӴý£¬£¬£¬9ÔÂ·ÝÆäÍøÕ¾µÄ»á¼ûÁ¿Ô¼Îª7ÍòÈ˴Ρ£¡£¡£¡£¡£¡£¡£ÆäÍøÕ¾ÒÀÀµÓÚµç×ÓÉÌÎñƽ̨Magento£¬£¬£¬¹¥»÷Õß×¢²áÁËÒ»¸öαװ³ÉMagento¹Ù·½ÓòÃûµÄ¼ÙÓòÃûmogento[.]infoÀ´Òþ²Ø×Ô¼º¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/sixth-june-fashion-site-hacked-to-steal-credit-cards/4¡¢ÃÀ¹ú¿ì²ÍÁ¬ËøµêKrystalÐû²¼Í¨Öª³ÆÆä¿Í»§ÐÅϢй¶
ÃÀ¹ú¿ì²ÍÁ¬ËøµêKrystalÌåÏÖÆäÖ§¸¶´¦Öóͷ£ÏµÍ³ÔâÓöÇå¾²ÊÂÎñ£¬£¬£¬²¿·Ö²ÍÌüÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñ±¬·¢ÔÚ2019Äê7ÔÂÖÁ9ÔÂÖ®¼ä£¬£¬£¬ÏÖÔÚÉв»ÖªµÀÊÜ´ËÇå¾²ÊÂÎñÓ°ÏìµÄ¿Í»§ÊýÄ¿ÒÔ¼°Ì»Â¶µÄ¸¶¿îÐÅÏ¢ÀàÐÍ£¬£¬£¬Ò²²»ÇåÎúÇå¾²ÊÂÎñ±³ºóµÄÔµ¹ÊÔÓÉÊÇÖ§¸¶ÏµÍ³Êý¾Ý¿â̻¶/δÊÚȨ»á¼ûÕÕ¾ÉPoS¶ñÒâÈí¼þ¹¥»÷µÈ¡£¡£¡£¡£¡£¡£¡£KrystalÌåÏÖÕýÔÚÆð¾¢È·¶¨ÄÄЩ²ÍÌüÊÜÓ°Ïì¼°ÏêϸµÄËùÔÚºÍÈÕÆÚ£¬£¬£¬Ëü»¹ÌåÏÖÒѾȷÈÏÔ¼ÓÐÈý·ÖÖ®Ò»µÄ²ÍÌüûÓÐÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/us-food-chain-alerts-customers-of-payment-card-incident/
5¡¢Î¢Èí³Æ2020Äê°ÂÔ˻Ὣ¿ÉÄܳÉΪAPT28µÄ¹¥»÷¹¤¾ß
΢ÈíÖÒÑÔ³Æ2020Äê¶«¾©°ÂÔË»á¿ÉÄܳÉΪ¶íÂÞ˹ºÚ¿Í×éÖ¯APT28£¨ÓÖÃû»¨Ê½ÐÜ£©µÄ¹¥»÷Ä¿µÄ¡£¡£¡£¡£¡£¡£¡£Î¢ÈíÍþвÇ鱨ÖÐÐÄÖ¸³ö£¬£¬£¬ËûÃÇ×·×ÙÁËÕë¶ÔÌåÓýÖ÷¹Ü²¿·ÖºÍ·´Ð˷ܼÁ»ú¹¹µÄ´óÐÍÍøÂç¹¥»÷£¬£¬£¬×Ô2019Äê9ÔÂ16ÈÕÒÔÀ´À´×ÔÈý´óÖÞµÄ16¸ö¹ú¼ÒºÍ¹ú¼Ê»ú¹¹ÒѾ³ÉΪ¹¥»÷Ä¿µÄ¡£¡£¡£¡£¡£¡£¡£Õâ²»ÊÇ»¨Ê½ÐܵÚÒ»´ÎÕë¶Ô·´Ð˷ܼÁ»ú¹¹£¬£¬£¬×Ô´ÓWADAÔÚ2016ÄêÀïÔ¼°ÂÔË»áÉÏեȡ¶íÂÞ˹ÔË·¢¶¯²ÎÈüºó£¬£¬£¬¸Ã×éÖ¯Ò»Ö±Õë¶Ô¹ú¼Ê·´Ð˷ܼÁ»ú¹¹¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/10/cyber-attack-tokyo-olympics.html
6¡¢Ð¶ñÒâÈí¼þxHelperÒÑѬȾÁè¼Ý4.5Íǫ̀Android×°±¸
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/new-unremovable-xhelper-malware-has-infected-45000-android-devices/


¾©¹«Íø°²±¸11010802024551ºÅ