ÃÀ¹úÌØÇÚ¾ÖÖÒ¸æÕë¶ÔÍйܷþÎñÌṩÉÌ£¨MSP£©µÄ¹¥»÷Ôö¶à£»£»£»£»£»TalosÅû¶ChromeºÍFirefox·ì϶µÄ¼¼Êõϸ½Ú
°ä²¼¹¦·ò 2020-07-071.ÃÀ¹úÌØÇÚ¾ÖÖҸ棬£¬£¬£¬£¬£¬Õë¶ÔÍйܷþÎñÌṩÉÌ£¨MSP£©µÄ¹¥»÷Ôö¶à
ÃÀ¹úÌØÇÚ¾ÖÏòÃÀ¹ú˽Ӫ²¿Ãź͵±¾Ö×éÖ¯·¢³öÁ˰²È«¾¯±¨£¬£¬£¬£¬£¬£¬ÖÒ¸æÕë¶ÔÖÎÀí·þÎñÌṩÉÌ£¨MSP£©µÄºÚ¿Í¹¥»÷ÓÐËùÔö³¤¡£¡£¡£¡£¡£ÃÀ¹úÌØÇÚ¾Ö¹ÙÔ±°µÊ¾£¬£¬£¬£¬£¬£¬ËûÃǵĵ÷²éÓ××é·¢ÏÖÔ½À´Ô½¶àµÄºÚ¿Í¶ÔMSPÌáÒé¹¥»÷£¬£¬£¬£¬£¬£¬²¢½«ÆäÊÓΪ½øÈ빫˾ÄÚ²¿ÍøÂçµÄÌø°å¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬ºÚ¿Í»áͨ¹ý±»ºÚµÄMSPs¶Ô¹«Ë¾ÏµÍ³½øÐй¥»÷£¬£¬£¬£¬£¬£¬Ö´ÐÐóÒ×µç×ÓÓʼþ¹¥»÷(BEC)£¬£¬£¬£¬£¬£¬²¢²¿ÊðÀÕË÷Èí¼þ¡£¡£¡£¡£¡£2019Äê²úÉúÁËÊýÊ®ÆðMSP¹¥»÷ÊÂÎñ£¬£¬£¬£¬£¬£¬¶øGandCrabºÍREvilµÈÀÕË÷Èí¼þÍÅ»ïÒ²ÆðÍ·¶Ô×¼MSP£¬£¬£¬£¬£¬£¬¶øºóϰȾÆäÊܺ¦Õß¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/us-secret-service-reports-an-increase-in-hacked-managed-service-providers-msps/#ftag=RSSbaffb68
2.SanSec°ä²¼»ã±¨³Æ³¯ÏÊÓëMagecart¹¥»÷ÓйØ
ºÉÀ¼ÍøÂ簲ȫ¹«Ë¾SanSecÔÚ½ñÌì°ä²¼»ã±¨ÖаµÊ¾£¬£¬£¬£¬£¬£¬×Ô2019Äê5ÔÂÒÔÀ´£¬£¬£¬£¬£¬£¬³¯ÏÊÒ»ÏòÔÚ¶ÔÍøÉÏÉÌµê½øÐÐMagecart¹¥»÷£¬£¬£¬£¬£¬£¬Êܺ¦ÕßÔ̺¬ÔÚ½ñÄê4ÔºÍ6ÔÂÔâµ½·ÛËéÅä¼þÁ¬ËøµêClaire's¡£¡£¡£¡£¡£SanSec·¢ÏÖ×î½üµÄÍøÂçä¯ÀÀ¹¥»÷ÖÐʹÓõÄÓòºÍ·þÎñÆ÷IPµØÖ·ÓëÏÈǰÒÑÖªµÄ³¯Ïʵ±¾ÖÔÞÖúµÄºÚ¿Í»ù´¡ÉèÊ©Óйأ¬£¬£¬£¬£¬£¬²¢Äܹ»×·Ò䵽ƽÈÀºÚ¿Í×éÖ¯Hindden Cobra¡£¡£¡£¡£¡£Æ½ÈÀµÄºÚ¿Í²»½ö²Î¼ÓÁËATMÍøÂç°ÂÓ£¬£¬£¬£¬£¬£¬»¹²ß¶¯Á˼ÓÃÜÇ®±ÒȦÌ×£¬£¬£¬£¬£¬£¬²¢¹¥»÷Á˼ÓÃÜÇ®±ÒÂòÂôËù¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/north-korean-hackers-linked-to-web-skimming-magecart-attacks-report-says/
3.TalosÅû¶×î½ü½¨¸´µÄChromeºÍFirefox·ì϶µÄ¼¼Êõϸ½Ú
Cisco TalosµÄ×êÑÐÈËÔ±Åû¶ÁË×î½ü½¨¸´µÄChromeºÍFirefox Webä¯ÀÀÆ÷Öзì϶µÄ¼¼Êõϸ½Ú¡£¡£¡£¡£¡£µÚÒ»¸ö·ì϶±»¸ú×ÙΪCVE-2020-6463£¬£¬£¬£¬£¬£¬ÊÇÒ»¸öÄÚ´æ°Ü»µ·ì϶£¬£¬£¬£¬£¬£¬Ó°ÏìÁËChromeÖеÄPDFium¡£¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ýÓÕÆÓû§´ò¿ªÔ̺¬JavaScript´úÂëµÄÎĵ·´´¥·¢´Ë·ì϶£¬£¬£¬£¬£¬£¬²¢ÀûÓÃÆäÔÚä¯ÀÀÆ÷ÖÐÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£Google ÓÚ4Ô°䲼ÁËChrome 81.0.4044.122°æ±¾½¨¸´Á˸÷ì϶¡£¡£¡£¡£¡£µÚ¶þ¸ö·ì϶Ϊ±»¸ú×ÙΪCVE-2020-12418£¬£¬£¬£¬£¬£¬ÊÇFirefoxÖÐÓëURL mPathÖ°ÄÜÓйصÄÐÅϢй¶·ì϶£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÓÕʹÊܺ¦Õß½Ó¼ûÌØÔìµÄURLÀ´ÀûÓø÷ì϶£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÔ½½ç¶ÁÈ¡¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/105547/security/talos-chrome-firefox-flaws.html
4.΢ÈíÖÒ¸æÀÕË÷Èí¼þAvaddonÈÔÔÚʹÓÃExcel 4.0ºê´«²¼
΢ÈíÖÒ¸æËµ£¬£¬£¬£¬£¬£¬ÀÕË÷Èí¼þAvaddonÒѾ¾íÍÁ³ÁÀ´£¬£¬£¬£¬£¬£¬Æä¹¥»÷ËÆºõ¸ü¾ßÕë¶ÔÐÔ£¬£¬£¬£¬£¬£¬²¢ÇÒÒÀÈ»ÒÀ¸½¶ñÒâExcel 4.0ºê´«²¼¡£¡£¡£¡£¡£Microsoft Security IntelligenceÖ¸³ö£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄ¿Ç°ÖØÒª×¼¶ÔÒâ´óÀûµÄÌØ¶¨Ö¸±ê£¬£¬£¬£¬£¬£¬ËûÃÇͨ¹ý·¢ËÍ´øÓжñÒâExcel 4.0ºêµÄÎĵµµÄµç×ÓÓʼþÌáÒé¹¥»÷¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬ÓжñÒâÓʼþ¼Ù×°³ÉÊǶ¯¼à²ì¾ÖÏòÒ»¼ÒÓׯóÒµ·¢³öµÄÓйØÎ£»£»£»£»£»úʱÆÚÎ¥·´¹¤×÷»®¶¨µÄ֪ͨ£¬£¬£¬£¬£¬£¬²¢ÓÕÆÊܺ¦Õß´ò¿ª¸½¼þÖмÙ×°³É¹Ù·½Í¨ÖªµÄZIPÎļþ¡£¡£¡£¡£¡£Î¢Èí°µÊ¾£¬£¬£¬£¬£¬£¬×î½ü¼¸¸öÔÂÒÔÀ´ÔÚ¶ñÒâÈí¼þ»î¶¯ÖÐÀûÓÃExcel 4.0ºêÆðÍ·±äµÃÔ½À´Ô½Ê¢ÐС£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/avaddon-ransomware-shows-that-excel-40-macros-are-still-effective/
5.SnakeÔÚ¼ÓÃÜÎļþǰ»á½«Ö¸±êϵͳ¸ôÀ룬£¬£¬£¬£¬£¬ÒÔÔ¤·À±»×ÌÈÅ
ÍøÂ簲ȫ¹«Ë¾Deep InstinctµÄ·¢ÏÖÀÕË÷Èí¼þSnakeÔÚ¼ÓÃÜÎļþǰ»á½«Ö¸±êϵͳ¸ôÀ룬£¬£¬£¬£¬£¬ÒÔÔ¤·ÀÊܵ½×ÌÈÅ¡£¡£¡£¡£¡£ÔÚ×î½üµÄ¹¥»÷ÖеÄSnakeʾÑù±¾ÊµÏÖÁËÆôÓúͽûÓ÷À»ðǽ£¬£¬£¬£¬£¬£¬ÒÔ¼°ÀûÓÃÌØ¶¨ÊýÁî×èÖ¹ÓëϵͳµÄÓк¦ÏνӵÄÖ°ÄÜ¡£¡£¡£¡£¡£ÔÚ×î½üµÄ¹¥»÷ÖÐʹÓõÄSnakeÑù±¾ÊµÏÖÁËÆôÓúͽûÓ÷À»ðǽµÄÄÜÁ¦£¬£¬£¬£¬£¬£¬²¢Äܹ»ÀûÓÃÌØ¶¨ÊýÁî×èÖ¹²»±ØÒªµÄϵÍÂ䬽ӡ£¡£¡£¡£¡£SnakeÔÚÆðÍ·¼ÓÃÜ֮ǰ£¬£¬£¬£¬£¬£¬»áʹÓÃWindows·À»ðǽÀ´×èÖ¹Êܺ¦Õß»úеÉÏûÓÐÅäÖõÄÈκνø³öÍøÂçÏνӡ£¡£¡£¡£¡£Óë±í½ç¶Ï¿ªÏνӺ󣬣¬£¬£¬£¬£¬Snake»áɱËÀ¿ÉÄÜ×ÌÈżÓÃܵÄÓ²±àÂë¹ý³Ì£¬£¬£¬£¬£¬£¬Ô̺¬Ó빤ҵÓйصĹý³Ì£¬£¬£¬£¬£¬£¬ÒÔ¼°°²È«ºÍ±¸·Ý½â¾ö¹æ»®¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/105572/malware/snake-ransomware-isolates-systems.html?utm_source=rss&utm_medium=rss&utm_campaign=snake-ransomware-isolates-systems
6.¶à¸öÔ¼»áÀûÓÃÃýÎóÅäÖÃÊý¾Ý¿âй¶Êý°ÙÍòÓû§Ãô¸ÐÊý¾Ý
WizCaseµÄIT×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬£¬£¬£¬ÃÀ¹úºÍ¶«ÑǵÄ5¸öÔ¼»áÀûÓ÷¨Ê½ÒòÃýÎóÅäÖÃÊý¾Ý¿âµ¼ÖÂÊý°ÙÍòÓû§Ãô¸ÐÊý¾Ýй¶£¬£¬£¬£¬£¬£¬Ð¹Â¶Êý¾ÝÔ̺¬ÐÕÃû¡¢Õ˵¥µØÖ·¡¢µç»°ºÅÂë¡¢Ó×ÎÒ×ÊÁÏ£¬£¬£¬£¬£¬£¬ÉõÖÁÊǸöÈËÐÂÎŵÈÒþÖÔ¡£¡£¡£¡£¡£Õâ´Î²úÉúй©ÊÂÎñµÄapp±ðÀëΪÃÀ¹úµÄCatholicSinglesºÍ YESTIKI£¬£¬£¬£¬£¬£¬º«¹úµÄBlurryºÍCongdaq/Kongdaq£¬£¬£¬£¬£¬£¬ÈÕ±¾µÄCharinºÍKyuun¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬CatholicSingles»¹Â¶³öÁËÓû§µÄ¸¶¿î·½Ê½¡£¡£¡£¡£¡£WizCaseÒÔΪ£¬£¬£¬£¬£¬£¬ÕâЩÊý¾Ý¿ÉÄÜÊÇÔÚWeb Scrapping¹ý³Ì±»Ð¹Â¶£¬£¬£¬£¬£¬£¬¸Ã¹ý³Ì»áÍøÂçºÍ´æ´¢Óû§ÌṩµÄÐÅÏ¢¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/5-dating-apps-leak-millions-of-user-data/


¾©¹«Íø°²±¸11010802024551ºÅ