¶à¸öÔ¼»áAPPÊý¾Ý¿âÎÞÃÜÂëµ¼Ö½ü4250ÍòÓû§¼Í¼й¶£»£»£»£»£»£»PyramidÒâ±íй¶¶à¼Ò¾ÆµêµÄ85GB°²È«Éó¼ÆÈÕÖ¾

°ä²¼¹¦·ò 2019-05-31
1¶à¸öÔ¼»áAPPÊý¾Ý¿âÎÞÃÜÂëµ¼Ö½ü4250ÍòÓû§¼Í¼й¶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


°²È«×êÑÐÈËÔ±Jeremiah Fowler·¢ÏÖÒ»¸öδÉèÃÜÂëµÄElasticÊý¾Ý¿â £¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âÔ̺¬¶à¸öÔ¼»áappµÄ½ü4250ÍòÓû§¼Í¼¡£¡£¡£¡£¡£Êܵ½Ó°ÏìµÄÔ¼»áappÔ̺¬Cougardating¡¢Christiansfinder¡¢Mingler¡¢FwbsºÍTS £¬£¬£¬£¬£¬Ð¹Â¶µÄÐÅÏ¢´óÎÞÊýÊôÓÚÃÀ¹úÓû§ £¬£¬£¬£¬£¬Ô̺¬Óû§Ãû¡¢´ºÇï¡¢µØÎ»ºÍIPµØÖ·µÈÐÅÏ¢¡£¡£¡£¡£¡£Ö»¹ÜÕâЩԼ»áappʹÓÃÁËͳһ¸öÊý¾Ý¿â £¬£¬£¬£¬£¬µ«ËüÃÇÐû³Æ±Ë´ËÖ®¼äÊǶÀÁ¢µÄ¹«Ë¾»òÓ×ÎÒ¡£¡£¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/unprotected-database-exposes-almost-425-million-records-from-chinese-dating-apps-bb4950a4

2Checkers²ÍÌüPoSϵͳ±»Ö²Èë¶ñÒâ´úÂë £¬£¬£¬£¬£¬¿Í»§Ö§¸¶ÐÅϢй¶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÃÀ¹úÁ¬Ëø²ÍÒûµêCheckers and Rally'sÔâºÚ¿ÍÈëÇÖ £¬£¬£¬£¬£¬¹¥»÷ÕßÔÚÆäPoSϵͳÉÏÖ²ÈëÁ˶ñÒâÈí¼þ £¬£¬£¬£¬£¬µ¼Ö²¿Ãſͻ§µÄÖ§¸¶ÐÅÏ¢±»ÇÔ¡£¡£¡£¡£¡£Æ¾¾ÝCheckers°ä²¼µÄÊý¾Ýй¶֪ͨ £¬£¬£¬£¬£¬¸ÃÊÂÎñÓ°ÏìÁË102¸öCheckers²ÍÌü £¬£¬£¬£¬£¬Ô¼Õ¼ÆäËùÓвÍÌüµÄ15%¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÁгöÁËÿ¸ö²ÍÌüÊܶñÒâÈí¼þÓ°ÏìµÄ¹¦·ò¶Î £¬£¬£¬£¬£¬´óÎÞÊýϰȾ²úÉúÔÚ2018ÄêÖÁ2019ÄêÖ®¼ä £¬£¬£¬£¬£¬Ò²ÓÐÉÙÊýϰȾ²úÉúÔÚ2016ºÍ2017Äê¡£¡£¡£¡£¡£¹¥»÷ÕßÖ²ÈëµÄ¶ñÒâÈí¼þÖ¼ÔÚ´ÓÒøÐп¨´ÅÌõÖÐÇÔÊØÐÅÏ¢ £¬£¬£¬£¬£¬Ô̺¬³Ö¿¨ÈËÐÕÃû¡¢ÒøÐп¨ºÅ¡¢ÑéÖ¤ÂëºÍµ½ÆÚÈÕÆÚµÈ¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/checkers-drive-in-restaurants-suffered-malware-attack-impacting-102-checkers-and-rallys-locations-f31199f1

3PyramidÒâ±íй¶¶à¼Ò¾ÆµêµÄ85GB°²È«Éó¼ÆÈÕÖ¾

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

VpnMentor×êÑÐÈËÔ±Noam RotemºÍRan Locar·¢Ï־ƵêºÍ¶È¼Ù´åÖÎÀí¹«Ë¾Pyramid Hotel GroupµÄÒ»¸öElasticsearchÊý¾Ý¿âδÉèÃÜÂë £¬£¬£¬£¬£¬µ¼Ö¶à¼Ò¾ÆµêµÄ85GB°²È«Éó¼ÆÈÕ־й¶¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ¾ÆµêÔ̺¬ÍòºÀ¡¢ÑÅÀÖÐù¡¢ÈøÀ­Ë÷ËþµÈ £¬£¬£¬£¬£¬Ð¹Â¶µÄÐÅÏ¢¿É×·ÒäÖÁ2019Äê4ÔÂ19ÈÕ £¬£¬£¬£¬£¬Ô̺¬·þÎñÆ÷APIÃÜÔ¿ºÍÃÜÂë¡¢É豸Ãû³Æ¡¢´«ÈëÏνӵÄIPµØÖ·¡¢·À»ðǽ¡¢Ê¢ÅüÍ·¿ÚÊý¾Ý¡¢¶ñÒâÈí¼þ¾¯±¨¡¢µÇ¼³¢ÊԼͼµÈ¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/unsecured-database-exposes-security-logs-of-major-hotel-chains/

4WordPress²å¼þConvert Plusзì϶ £¬£¬£¬£¬£¬¿É´´½¨ÖÎÀíÔ¹ØË»§


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Defiant×êÑÐÈËÔ±·¢ÏÖWordPress²å¼þConvert Plus´æÔÚÒ»¸ö°²È«·ì϶ £¬£¬£¬£¬£¬¸Ã·ì϶¿ÉÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß´´½¨ÓµÓÐÖÎÀíԱȨÏÞµÄÕË»§¡£¡£¡£¡£¡£¸Ã·ì϶ԴÓÚͨ¹ý²å¼þ±íµ¥´¦ÖÃÐÂÓû§¶©ÔÄʱ¶Ìȱ¹ýÂË¡£¡£¡£¡£¡£ÔÚ²»ÍâÂËж©ÔĵÄÇé¿öÏ £¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Ìá½»±íµ¥²¢Åú¸Äcp_set_user×Ö¶ÎÖµ£¨½«ÆäÉèÖÃΪadministrator£© £¬£¬£¬£¬£¬´Ó¶øÔÚÍøÕ¾ÉÏ´´½¨ÐÂÖÎÀíÔ¹ØË»§¡£¡£¡£¡£¡£Ð´´½¨µÄÕË»§ÓµÓÐËæ»úµÄÃÜÂë £¬£¬£¬£¬£¬µ«¹¥»÷ÕßÄܹ»ÒªÇó³ÁÖÃÃÜÂë¡£¡£¡£¡£¡£¸Ã·ì϶ӰÏìÁË3.4.2¼°Ö®Ç°µÄËùÓа汾 £¬£¬£¬£¬£¬½¨ÒéÓû§¸üÐÂÖÁ°æ±¾3.4.3¡£¡£¡£¡£¡£¸Ã²å¼þµÄ×°ÖÃÁ¿Ô¼Îª10Íò´Î¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/convert-plus-plugin-flaw-lets-attackers-become-a-wordpress-admin/

5жñÒâÈí¼þHiddenWasp £¬£¬£¬£¬£¬ÖØÒªÕë¶ÔLinuxϵͳ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Intezer Labs°²È«×êÑÐÔ±Nacho Sanmillan·¢ÏÖÐÂLinux¶ñÒâÈí¼þHiddenWasp £¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÓÉÓû§Ä£Ê½rootkit¡¢Ä¾ÂíºÍ³õʼ²¿Êð¾ç±¾×é³É¡£¡£¡£¡£¡£×êÑÐÈËÔ±³ÆHiddenWaspÓëÁíÒ»¸ö½üÆÚ·¢ÏÖµÄLinux¶ñÒâÈí¼þWenntiÓµÓÐÀàËÆµÄ½á¹¹ £¬£¬£¬£¬£¬²¢ÇÒʹÓÃÁ˲¿ÃÅChinaZ¡¢Adore-ng¼°MiraiµÄ´úÂë¡£¡£¡£¡£¡£HiddenWasp±»ÓÃ×÷µÚ¶þ½×¶Îpayload £¬£¬£¬£¬£¬µ«¹¥»÷µÄ³õÊ¼Ï°È¾ÔØÌåÉв»Ã÷ÏÔ¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/new-hiddenwasp-malware-found-targeting-linux-systems/

6APT×éÖ¯Turlaй¥»÷»î¶¯ £¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÅ·ÖÞ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ESET×êÑÐÈËÔ±·¢ÏÖAPT×éÖ¯TurlaµÄй¥»÷»î¶¯ £¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓÃеÄTTPÕë¶Ô¶«Å·µØÓòµÄ±í½»»ú¹¹¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓûùÓÚPowerShellµÄй¤¾ßÀ´Ö´ÐÐÎÞÎļþ¹¥»÷ £¬£¬£¬£¬£¬Æä¿ªÊ͵ÄpayloadÔ̺¬»ùÓÚRPCµÄºóÃźÍÀûÓÃOneDrive×÷ΪC&C·þÎñÆ÷µÄºóÃÅ¡£¡£¡£¡£¡£ESET×êÑÐÔ±Matthieu FaouÒÔΪÕâЩ¼¼ÊõÕý±»¸Ã×éÖ¯ÓÃÓÚ¹¥»÷È«ÇòÁìÓòÄÚµÄTurlaÖ¸±ê¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/eset-exposes-turla-malware-1/