RazerÊý¾Ý¿â̻¶µ¼ÖÂÆäÔ¼10ÍòÓû§ÐÅϢй¶£»£»£»£»£»£»£»¿¨°Í˹»ùÐû²¼APT×éÖ¯Õë¶ÔLinuxµÄ¹¥»÷ÆÊÎö±¨¸æ

Ðû²¼Ê±¼ä 2020-09-14

1.RazerÊý¾Ý¿â̻¶µ¼ÖÂÆäÔ¼10ÍòÓû§ÐÅϢй¶


1.jpg


8ÔÂ19ÈÕ£¬£¬£¬Ñо¿Ô±Bob Diachenko·¢Ã÷ÓÎÏ·Ó²¼þÖÆÔìÉÌRazerµÄÔÚÏßÊÐËÁµÄÊý¾Ý¿â̻¶£¬£¬£¬µ¼ÖÂÆäÔ¼10ÍòÓû§ÐÅϢй¶¡£¡£¡£¡£¡£¡£´Ë´Îй¶µÄÐÅÏ¢°üÀ¨¿Í»§µÄÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢µç»°ºÅÂë¡¢¶©µ¥ºÅ¡¢¶©µ¥Ã÷ϸÒÔ¼°Õʵ¥ºÍËÍ»õµØµãµÈ¡£¡£¡£¡£¡£¡£RazerÓÚÔÚ9ÔÂ9ÈÕÐÞ¸´Á˸ÃÊý¾Ý¿âЧÀÍÆ÷£¬£¬£¬²¢ÌåÏÖ¸ÃÊÂÎñÖв¢Ã»ÓÐÆäËûÃô¸ÐÊý¾Ýй¶£¬£¬£¬ÀýÈçÐÅÓÿ¨ºÅ»òÃÜÂëµÈÐÅÏ¢¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/razer-data-leak-exposes-personal-information-of-gamers/


2.MailfireÊý¾Ý¿â̻¶£¬£¬£¬Ð¹Â¶882GBµÄÈÕÖ¾Îļþ


2.jpg


vpnMentorÑо¿Ö°Ô±ÓÚ8ÔÂβÔÚÍøÂçÉÏ·¢Ã÷ÁË̻¶µÄÊý¾Ý¿â£¬£¬£¬ÆäÊôÓÚÔ¼»áÍøÕ¾Mailfire¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÖд洢ÁËÁè¼Ý882GBµÄÈÕÖ¾Îļþ£¬£¬£¬ÆäÓëͨ¹ýMailfireµÄЧÀÍ·¢Ë͵ÄÍÆËÍ֪ͨÓйØ£¬£¬£¬ÈÕÖ¾»áËæ×ÅÐÂ֪ͨµÄ·¢ËÍʵʱ¸üС£¡£¡£¡£¡£¡£¸ÃÈÕÖ¾Îļþ×ܹ²°üÀ¨ÒÑÍù96¸öСʱÄÚ·¢Ë͵Ä6600ÍòÌõСÎÒ˽¼Ò֪ͨ£¬£¬£¬ÒÔ¼°ÊýÊ®ÍòÓû§µÄСÎÒ˽¼ÒÏêϸÐÅÏ¢£¬£¬£¬ÆäÖаüÀ¨°üÀ¨ÐÕÃû¡¢ÄêËê¡¢ÐԱ𡢵ç×ÓÓʼþµØµã¡¢µØÀíλÖúÍIPµØµãµÈ¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÓÚ9ÔÂ3ÈÕ±»ÐÞ¸´¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/leaky-server-exposes-users-of-dating-site-network/


3.΢ÈíÌåÏÖ¹ú¼ÒÖ§³ÖµÄºÚ¿ÍÒÑÃé×¼2020ÄêÃÀ¹ú´óÑ¡


3.jpg


΢ÈíÌåÏÖ£¬£¬£¬Óɹú¼Ò×ÊÖúµÄºÚ¿Í×éÖ¯ÒÑÃé×¼¼ÓÈë2020ÄêÃÀ¹ú×Üͳ´óÑ¡µÄ×éÖ¯ºÍСÎÒ˽¼Ò¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬¶íÂÞË¹ÍøÂçÌØ¹¤×éÖ¯APT28ÔøÔÚ2016Äê×Üͳ´óѡʱ´ú¹¥»÷ÁË200¶à¸öÓë´óÑ¡Ïà¹ØµÄ×éÖ¯ºÍСÎÒ˽¼Ò£¬£¬£¬ÆäÊÂÇéÖØµãÊÇÇÔȡĿµÄµÄƾ֤²¢ÆÆËðÆäÕÊ»§¡£¡£¡£¡£¡£¡£¶øÒÁÀʺڿÍNewsBeefÔÚ2020Äê5ÔÂÖÁ6Ô±»·¢Ã÷ÊÔͼµÇÂ¼ÌØÀÊÆÕ¾ºÑ¡ÖúÊÖºÍÃÀ¹úÕþ¸®¹ÙÔ±µÄÕË»§¡£¡£¡£¡£¡£¡£Î¢ÈíÌåÏÖ£¬£¬£¬ÔÚÈ¥Äê7ÔÂÆä·¢Ã÷ÓÉÕþ¸®Ö§³ÖµÄºÚ¿Í×éÖ¯µÄ¹¥»÷ºó£¬£¬£¬ÏòÊÜÓ°Ïì×éÖ¯·¢³öÁË781´ÎÖÒÑÔ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/microsoft-state-backed-hackers-are-targeting-the-2020-us-elections/


4.ºÚ¿ÍÒÔTwitterÇå¾²ÏìÓ¦Îı¾ÎªÓÕ¶üÌᳫ´¹ÂÚ¹¥»÷


4.jpg


First Look MediaÑо¿Ö°Ô±·¢Ã÷£¬£¬£¬ºÚ¿ÍÒÔTwitterÇå¾²ÏìÓ¦Îı¾ÎªÓÕ¶üÌᳫ´¹ÂÚ¹¥»÷¡£¡£¡£¡£¡£¡£½üÒ»Äê×óÓÒ£¬£¬£¬TwitterÒ»Ö±´¦ÓÚÖÖÖÖÕùÒéÖ®ÖС£¡£¡£¡£¡£¡£ºÚ¿ÍÔòʹÓÃTwitterÍŶӶÔÕâЩÊÂÎñµÄÇå¾²ÏìÓ¦ÖеÄÎÄÔ­À´Ìᳫ´¹ÂÚ¹¥»÷¡£¡£¡£¡£¡£¡£ºÚ¿Í·¢Ë͵Ĵ¹ÂÚÓʼþÓë¹Ù·½ÍÆÎÄÏÕЩÏàͬ£¬£¬£¬Ò»µ©Óû§È·ÐÅÆäÕýµ±²¢µã»÷È·ÈÏÄúµÄÉí·Ýºó£¬£¬£¬±ã»á±»Öض¨Ïòµ½ÍøÂç´¹ÂÚÍøÒ³£¬£¬£¬²¢±»ÇÔÈ¡µÇ¼ƾ֤¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/twitter-phishing-scam-latest-security-response/


5.ÃÀ¹ú¹«Ë¾ArtechÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬ÆäÊý¾Ý»òÒÑй¶


5.jpg


ÃÀ¹úITÖ°Ô±ÉèÖù«Ë¾Artech Information SystemsÅû¶ÆäÓÚ2020Äê1Ô³õÔâµ½ÁËREvilÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬ÆäÊý¾Ý»òÒÑй¶¡£¡£¡£¡£¡£¡£¾­ÊӲ죬£¬£¬ArtechÈ·¶¨ÓÚ1ÔÂ5ÈÕÖÁ1ÔÂ8ÈÕÖ®¼äÓÐδ¾­ÊÚȨµÄµÚÈý·½»á¼ûÁËijЩϵͳ¡£¡£¡£¡£¡£¡£Óë´Ëͬʱ£¬£¬£¬ÀÕË÷Èí¼þÍÅ»ïREvil£¨Sodinokibi£©Ðû²¼ÁË337MBÊý¾Ý£¬£¬£¬²¢Éù³ÆÊǴӸù«Ë¾Ð§ÀÍÆ÷ÇÔÈ¡µÄÎļþ¡£¡£¡£¡£¡£¡£×èÖ¹ÏÖÔÚ£¬£¬£¬ArtechÉÐδ¶Ô´ËÊÂÎñ¾ÙÐÐÖÃÆÀ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-staffing-firm-artech-discloses-ransomware-attack-data-breach/


6.¿¨°Í˹»ùÐû²¼APT×éÖ¯Õë¶ÔLinuxµÄ¹¥»÷ÆÊÎö±¨¸æ


6.jpg


¿¨°Í˹»ùÈ«ÇòÑо¿ÓëÆÊÎöÍŶӣ¨GReAT£©Ðû²¼ÁËAPT×éÖ¯Õë¶ÔLinuxµÄ¹¥»÷ÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¸Ã±¨¸æÖ¸³ö£¬£¬£¬APTÕûÌåÔ½À´Ô½¶àµØ¶Ô»ùÓÚLinuxµÄ×°±¸Ö´ÐÐÓÐÕë¶ÔÐԵĹ¥»÷£¬£¬£¬°üÀ¨Turla¡¢Lazarus¡¢Barium¡¢Sofacy¡¢Lamberts¡¢EquationµÈAPT×éÖ¯£¬£¬£¬²¢¿ª·¢Á˸ü¶àÕë¶ÔLinuxµÄ¹¤¾ß¡£¡£¡£¡£¡£¡£¿£¿£¿£¿ £¿¨°Í˹»ùÌåÏÖ£¬£¬£¬ËäÈ»Õë¶Ô»ùÓÚLinuxµÄϵͳµÄ¹¥»÷²»³£¼û£¬£¬£¬µ«ÓÐÐí¶àÏà¹ØµÄ¶ñÒâÈí¼þ£¬£¬£¬°üÀ¨webshell¡¢ºóÃųÌÐò¡¢rootkitÉõÖÁ¶¨ÖÆÎó²îʹÓóÌÐò¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/an-overview-of-targeted-attacks-and-apts-on-linux/98440/