Î÷ÃÅ×Ó¶à¿îÒ½ÁÆÉ豸Ò×ÊÜWindows BlueKeep·ì϶ӰÏ죻£»£»£»£»¼üÅ̼ͼľÂíHawkEye¶Ô׼ȫÇòÆóÒµ
°ä²¼¹¦·ò 2019-05-29
ƾ¾ÝÎ÷ÃÅ×Ó°ä²¼µÄ°²È«²¼¸æ£¬£¬£¬£¬£¬¶à¿îÎ÷ÃÅ×ÓÒ½ÁÆÉ豸Ò×ÊÜWindows RDP·þÎñBlueKeep·ì϶µÄÓ°Ï죬£¬£¬£¬£¬Ô̺¬MagicLinkA¡¢MagicViewµÈÈí¼þ²úÆ·£¬£¬£¬£¬£¬System ACOM¡¢SensisµÈ¸ß¼¶Ò½ÖβúÆ·£¬£¬£¬£¬£¬Axiom¡¢MobilettµÈXÉäÏßÉ豸ÒÔ¼°Atellica¡¢AptioµÈ³¢ÊÔÊÒÕï¶Ï²úÆ·¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÒÑÒªÇó¿Í»§×°ÖÃ΢ÈíµÄ½¨¸´²¹¶¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬µ«²»Äܱ£Õϲ¹¶¡µÄ¼æÈÝÐÔ£¬£¬£¬£¬£¬¸Ã¹«Ë¾½¨ÒéÓû§²ÉÈ¡½ûÓÃRDP¡¢×èÖ¹TCP¶Ë¿Ú3389µÈ»º½â´ëÊ©¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/86222/security/siemens-healthineers-bluekeep.html2APT10ÀûÓÃмÓÔØÆ÷·Ö·¢Ô¶¿ØÄ¾Âí£¬£¬£¬£¬£¬ÖØÒªÕë¶Ô¶«ÄÏÑÇ
ƾ¾Ý°²È«³§ÉÌenSiloµÄ·ÖÎö»ã±¨£¬£¬£¬£¬£¬APT10ÔÚ4Ô·ݵÄй¥»÷»î¶¯ÖÐÀûÓÃÁ½¸öмÓÔØÆ÷·Ö·¢¶àÖÖpayload£¬£¬£¬£¬£¬Ô̺¬Ô¶¿ØÄ¾ÂíPlugXºÍQuasar¡£¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷»î¶¯ÖØÒªÕë¶Ô¶«ÄÏÑǵØÓòÈ·µ±¾Ö»ú¹¹ºÍ˽ӪÆóÒµ¡£¡£¡£¡£¡£¡£¡£ÕâÁ½¸ö¼ÓÔØÆ÷¶¼ÊµÏÖÁËDLL Side-Loading£¬£¬£¬£¬£¬ÕâÒâζ×ÅËüÃÇÄܹ»ÀûÓúϷ¨µÄ¿ÉÖ´ÐÐÎļþÀ´¼ÓÔØ¶ñÒâDLL¡£¡£¡£¡£¡£¡£¡£ÕâÁ½¸ö¼ÓÔØÆ÷¶¼Ê¹ÓÃjli.dll½«Êý¾ÝÎļþsvchost.binÓ³Éäµ½ÄÚ´æÖУ¬£¬£¬£¬£¬²¢¼ìË÷svchost.exe×¢ÈëÔ̺¬ÏÖʵpayloadµÄshellcode¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/86213/apt/apt10-new-loaders.html3¹¥»÷ÕßÀûÓüüÅ̼ͼľÂíHawkEye¶Ô׼ȫÇòÆóÒµ
ƾ¾ÝIBM X-ForceµÄ»ã±¨£¬£¬£¬£¬£¬ÔÚ4Ô·ݺÍ5Ô·ݹ¥»÷ÕßÀûÓüüÅ̼ͼľÂíHawkEye¶Ô׼ȫÇòÁìÓòÄ򵀮óÒµ£¬£¬£¬£¬£¬Ö¸±êÐÐÒµÔ̺¬ÔËÊäºÍÎïÁ÷¡¢Ò½ÁƱ£½¡¡¢½ø³ö¿Ú¡¢Êг¡ÓªÏúºÍũҵµÈ¡£¡£¡£¡£¡£¡£¡£HawkEyeÖ¼ÔÚÇÔÈ¡ÊÜϰȾÉ豸µÄÐÅÏ¢£¬£¬£¬£¬£¬ËüÒ²¿ÉÓÃ×÷¼ÓÔØÆ÷£¬£¬£¬£¬£¬ÀûÓý©Ê¬ÍøÂçÏòµÚÈý·½·¸×ïÕßÌṩpayload·Ö·¢·þÎñ¡£¡£¡£¡£¡£¡£¡£ÕâЩHawkEyeÑù±¾ÖØÒªÍ¨¹ýÀ¬»øÓʼþ½øÐзַ¢¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/malspam-campaigns-use-hawkeye-keylogger-to-target-businesses/
4Õë¶Ô°ÄÐÂÒøÐеĴ¹µö¹¥»÷º£³±£¬£¬£¬£¬£¬ÖØÒªÇÔÈ¡Óû§Í´´¦
·¸×ï·Ö×ÓÔÚÀûÓðÄÐÂÒøÐУ¨ANZ Banking Group£©½øÐÐÐÂÒ»²¨µÄ´¹µö¹¥»÷¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝMailGuardµÄ»ã±¨£¬£¬£¬£¬£¬´¹µöÓʼþ¼Ù×°³É¡°BPAY¸¶¿î֪ͨ¡±£¬£¬£¬£¬£¬Ô̺¬¿Í»§´úÂë¡¢¸¶¿î½ð¶î¡¢¸¶¿îÈÕÆÚµÈϸ½Ú£¬£¬£¬£¬£¬ÒªÇóÊÕ¼þÈËͨ¹ý½Ó¼ûÓʼþÖеÄÁ´½ÓÀ´ÑéÖ¤ÂòÂô»ò¸üÐÂÆäÕË»§¡£¡£¡£¡£¡£¡£¡£µ±Óû§µã»÷¸ÃÁ´½Óʱ£¬£¬£¬£¬£¬½«±»³Á¶¨ÏòÖÁ·ÂÕÕANZµÄ´¹µöÍøÕ¾£¬£¬£¬£¬£¬ÒÔÇÔÈ¡Óû§µÄÒøÐнӼûÍ´´¦¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.mailguard.com.au/blog/anz-phishing-email-scam-tells-users-their-security-challenge-answers-are-incorrect5FlipboardÊý¾Ý¿âÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬Óû§Êý¾Ý±»ÇÔ
ÐÂΞۺÏÍøÕ¾Flipboard°µÊ¾ÆäÊý¾Ý¿âÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜÏÂÔØÁËÓû§µÄÕË»§ÐÅÏ¢ºÍÊý×ÖÁîÅÆµÈÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¹²ÔÚÁ½¸ö·ÖÆçµÄ¹¦·ò¶Î½Ó¼ûÁËÆäÊý¾Ý¿â£¬£¬£¬£¬£¬Ô̺¬2018Äê6ÔÂ2ÈÕµ½2019Äê3ÔÂ23ÈÕÆÚ¼äºÍ2019Äê4ÔÂ21ÈÕÖÁ22ÈÕÆÚ¼ä¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°Éв»ÄÜÈ·ÈÏÕâÁ½ÆðÊÂÎñÊÇ·ñΪͳһ¹¥»÷ÕßËùΪ¡£¡£¡£¡£¡£¡£¡£Flipboard°µÊ¾ÈÔÔÚ½øÐе÷²é£¬£¬£¬£¬£¬Ä¿Ç°»¹²»Ã÷ÏÔÓм¸¶àÓû§Êܵ½Ó°Ï죬£¬£¬£¬£¬µ«ÒѾö¶¨³ÁÖÃËùÓÐЧ»§µÄÃÜÂë¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/flipboard-databases-hacked-and-user-information-exposed/6¶à¸öCI·þÎñй¶¹«Ë¾»úÃÜ£¬£¬£¬£¬£¬Ô̺¬Github½Ó¼ûÁîÅÆ
×êÑÐÈËÔ±·¢ÏÖ¶à¸öCI·þÎñÒÀÈ»ÔÚÆä¹¹½¨ÈÕÖ¾ÖÐй¶¹«Ë¾µÄ»úÃÜÐÅÏ¢£¬£¬£¬£¬£¬Ô̺¬GithubµÄ½Ó¼ûÁîÅÆ¡£¡£¡£¡£¡£¡£¡£³ÖÐø¼¯³É£¨CI£©·þÎñÓÃÓÚÔÚÔçÆÚ½×¶Î¼ì²â±àÂë¹ý³ÌÖеÄÃýÎ󣬣¬£¬£¬£¬ÕâЩ·þÎñµÄÈÕÖ¾ÖмͼÁËÏîÄ¿ÈÕÖ¾¡¢ÓëÔ¶³Ì·þÎñÆ÷ºÍAPIµÄ½»»¥¡¢ÃÜÂë¡¢SSHÃÜÔ¿¼°APIÁîÅÆµÈÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÓëGitHubµÄ¼¯³ÉÐÔ£¬£¬£¬£¬£¬Travis CIÊÇʹÓÃ×î¿í·ºµÄCI·þÎñ£¬£¬£¬£¬£¬ÆäËüCI·þÎñÔ̺¬Circle CIºÍGitLab CIµÈ¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖGrammarlyºÍDiscourseµÄCI¹¹½¨ÈÕÖ¾¶¼Òò¶øÐ¹Â¶Á˹«Ë¾ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/ci-services-expose-company-secrets-including-github-access-tokens-9e642006


¾©¹«Íø°²±¸11010802024551ºÅ