Imperva°ä²¼ÓйØKashmirBlack½©Ê¬ÍøÂçµÄ·ÖÎö»ã±¨£»£»£»£»£»£»£»Nitro PDF´ó¹æÄ£Êý¾Ýй¶ӰÏì΢Èí¡¢¹È¸èºÍÆ»¹ûµÈ¹«Ë¾

°ä²¼¹¦·ò 2020-10-27
1.Imperva°ä²¼ÓйØKashmirBlack½©Ê¬ÍøÂçµÄ·ÖÎö»ã±¨


1.jpg


Imperva°ä²¼ÁËÓйØKashmirBlack½©Ê¬ÍøÂçµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£ ¡£¡£¡£¸Ã»ã±¨ÃèÊöÁËKashmirBlack½©Ê¬ÍøÂç±³ºóµÄ·¸×ï²Ù×÷£¬£¬£¬£¬£¬ £¬£¬£¬»áÉÌÁËÆäÖ÷ÕÅÒÔ¼°×êÑв½Öè¡£¡£¡£¡£¡£ ¡£¡£¡£KashmirBlackÖØÒªÕë¶ÔÊ¢ÐеÄCMSƽ̨¡£¡£¡£¡£¡£ ¡£¡£¡£ËüÀûÓÃÁËÖ¸±ê·þÎñÆ÷ÉϵÄÊýÊ®¸öÒÑÖª·ì϶£¬£¬£¬£¬£¬ £¬£¬£¬¾ùÔÈÿÌì¶ÔÈ«Çò30¶à¸ö·ÖÆç¹ú¶ÈµÄÊýǧÃûÊܺ¦Õß½øÐÐÊý°ÙÍò´Î¹¥»÷¡£¡£¡£¡£¡£ ¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ £¬£¬£¬ÆäÔËÐм«¶È¸´ÔÓ£¬£¬£¬£¬£¬ £¬£¬£¬ÓÉһ̨C&C·þÎñÆ÷ÖÎÀí£¬£¬£¬£¬£¬ £¬£¬£¬²¢Ê¹ÓÃÁË60¶ą̀·þÎñÆ÷×÷ΪÆä»ù´¡ÉèÊ©µÄÒ»²¿ÃÅ¡£¡£¡£¡£¡£ ¡£¡£¡£¿£¿£¿£¿ £¿£¿£¿É´¦ÖÃÊý°Ù¸ö½©Ê¬·¨Ê½£¬£¬£¬£¬£¬ £¬£¬£¬Ö´Ðб©Á¦¹¥»÷¡¢×°ÖúóÃÅ¡¢²¢À©´ó½©Ê¬ÍøÂçµÄ¹æÄ£¡£¡£¡£¡£¡£ ¡£¡£¡£    


Ô­ÎÄÁ´½Ó£º

https://www.imperva.com/blog/crimeops-of-the-kashmirblack-botnet-part-i/


2.Area1°ä²¼Office 365µç×ÓÓʼþ·ÀÓùϵͳÍþв·ÖÎö»ã±¨


2.jpg


Area1°ä²¼ÁËOffice 365µç×ÓÓʼþ·ÀÓùºÍ³ÛÃû°²È«µç×ÓÓʼþÍø¹Ø£¨SEG£©Ãæ¶ÔµÄÖØÒªÍþвµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£ ¡£¡£¡£»ã±¨ÏÔʾ£¬£¬£¬£¬£¬ £¬£¬£¬´Ó2020Äê3Ôµ½8ÔµÄÁù¸öÔÂÖУ¬£¬£¬£¬£¬ £¬£¬£¬Óг¬¹ý925000·â¶ñÒâµç×ÓÓʼþ³É¹¦ÈƹýÁËOffice 365·ÀÓùºÍSEG¡£¡£¡£¡£¡£ ¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬ £¬£¬£¬¹¥»÷ÕßÔ½À´Ô½¶àµØÊ¹Óø߶ȸ´Ôӵġ¢ÓÐÕë¶ÔÐԵĹ¥»÷»î¶¯À´ÌӱܻùÓÚÒÑÖªÍþвµÄ´«Í³µç×ÓÓʼþ·ÀÓù£¬£¬£¬£¬£¬ £¬£¬£¬ÀýÈçóÒ×µç×ÓÓʼþ¹¥»÷¡£¡£¡£¡£¡£ ¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬ £¬£¬£¬Type 3 BECs(»ùÓÚÕË»§½ÚÔìµÄ)ºÍType 4 BEC (¹©¸øÁ´ÍøÂç´¹µö)¿ÉÄÜÒÑÔì³ÉÊýÊ®ÒÚÃÀÔªµÄDZÔÚËðʧ¡£¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.area1security.com/office-365-anniversary-email-threats-report/


3.×êÑÐÈËÔ±·¢ÏÖ¿Éͨ¹ýWaze APIÖзì϶׷×ÙËÁÒâÓû§µÄµØÎ»


3.jpg


×êÑÐÈËÔ±Peter Gasper·¢ÏÖ¿Éͨ¹ýWaze APIÖзì϶׷×ÙËÁÒâÓû§µÄµØÎ»¡£¡£¡£¡£¡£ ¡£¡£¡£µ±Óû§»ã±¨Ç°·½Óз·×è°­»ò¾¯Ô±Ñ²Âßʱ£¬£¬£¬£¬£¬ £¬£¬£¬Waze API»á½«¸ÃÓû§µÄIDºÍÓû§Ãûһ··µ»Ø¸øÔڸô¦ËùÐÐÊ»µÄÆäËûÓû§¡£¡£¡£¡£¡£ ¡£¡£¡£³ý·ÇÓû§½øÐÐÁË×¢½â£¬£¬£¬£¬£¬ £¬£¬£¬²»È»ÀûÓÃÖв»»áÏÔʾ´ËÊý¾Ý£¬£¬£¬£¬£¬ £¬£¬£¬µ«ÔÚAPIÏìÓ¦ÖлáÔ̺¬Óû§Ãû¡¢ID¡¢ÊÂÎñµÄµØÎ»¡¢ÉõÖÁÊǻ㱨¹¦·ò¡£¡£¡£¡£¡£ ¡£¡£¡£ÓÉÓÚ´óÎÞÊýÓû§½«ÆäÕæÊµÐÕÃû×÷ΪÓû§Ãû£¬£¬£¬£¬£¬ £¬£¬£¬Òò¶ø¹¥»÷ÕßÓпɳÉÁ¢Ò»¸öÔ̺¬Óû§ÐÕÃûºÍIDµÄÊý¾Ý¿â¡£¡£¡£¡£¡£ ¡£¡£¡£ 


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2020/10/25/waze-app-vulnerability-could-allow-tracking-users-location/


4.Nitro PDF´ó¹æÄ£Êý¾Ýй¶ӰÏì΢Èí¡¢¹È¸èºÍÆ»¹ûµÈ¹«Ë¾


4.jpg


Nitro PDF·þÎñ²úÉú´ó¹æÄ£µÄÊý¾Ýй¶£¬£¬£¬£¬£¬ £¬£¬£¬Ó°ÏìÁËÔ̺¬Google¡¢Apple¡¢Microsoft¡¢ChaseºÍCitibankÔÚÄÚµÄÖî¶à³ÛÃû×éÖ¯¡£¡£¡£¡£¡£ ¡£¡£¡£10ÔÂ21ÈÕ£¬£¬£¬£¬£¬ £¬£¬£¬Nitro Software°ä²¼ÁËÒ»·ÝÕ÷ѯ£¬£¬£¬£¬£¬ £¬£¬£¬³ÆÆäÔâµ½µÍÓ°Ï찲ȫÊÂÎñ£¬£¬£¬£¬£¬ £¬£¬£¬µ«Æä¿Í»§Êý¾ÝûÓÐÊܵ½ÈκÎÓ°Ïì¡£¡£¡£¡£¡£ ¡£¡£¡£ÍøÂ簲ȫµý±¨¹«Ë¾CybleÔò°µÊ¾£¬£¬£¬£¬£¬ £¬£¬£¬ºÚ¿ÍÔÚÏúÊÛÐû³ÆÊÇ´ÓNitroÔÆÖÐÇÔÈ¡µÄÓû§¡¢ÎĵµÊý¾Ý¿âÒÔ¼°1TBµÄÎĵµ¡£¡£¡£¡£¡£ ¡£¡£¡£ÆäÖÐuser_credentialÊý¾Ý¿âÔ̺¬7000ÍòÌõÓû§¼Í¼£¬£¬£¬£¬£¬ £¬£¬£¬Ô̺¬µç×ÓÓʼþµØÖ·¡¢È«Ãû¡¢bcryptÉ¢ÁÐÃÜÂ롢ͷÏΡ¢¹«Ë¾Ãû³Æ¡¢IPµØÖ·ºÍÆäËûϵͳÓйØÊý¾Ý¡£¡£¡£¡£¡£ ¡£¡£¡£ÕâЩÊý¾Ý¿â»¹Ô̺¬ÁËÓë¸÷³ÛÃû¹«Ë¾ÓйصĴóÁ¿Îĵµ¡£¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/massive-nitro-data-breach-impacts-microsoft-google-apple-more/ 


5.Trustwave·¢ÏÖºÚ¿ÍÔÚ°µÍøÏúÊÛ1.86ÒÚÃÀ¹úÑ¡ÃñÐÅÏ¢


5.jpg


ÍøÂ簲ȫ¹«Ë¾Trustwave·¢ÏÖºÚ¿ÍÔÚ°µÍøÏúÊÛÁ˳¬¹ý2ÒÚÃÀ¹úÈ˵ÄÓ×ÎÒ¼ø±ðÐÅÏ¢£¬£¬£¬£¬£¬ £¬£¬£¬ÆäÖÐÔ̺¬1.86ÒÚÃÀ¹úÑ¡ÃñÐÅÏ¢¡£¡£¡£¡£¡£ ¡£¡£¡£Ð¹Â©µÄÊý¾ÝÔ̺¬ÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂëºÍÑ¡ÃñµÇ¼Ç¼Í¼¡£¡£¡£¡£¡£ ¡£¡£¡£Trustwave°µÊ¾ÕâЩÊý¾ÝÊÇÓɽüÄêÀ´ÆóÒµÔâµ½¸÷À๥»÷Ëùй¶µÄÊý¾ÝÒÔ¼°´Óµ±¾ÖÍøÕ¾¼ìË÷µÄ¹«¿ªÊý¾Ý×é³ÉµÄ£¬£¬£¬£¬£¬ £¬£¬£¬¿ÉÓÃÓÚÉ罻ýÌå¡¢µç×ÓÓʼþÍøÂç´¹µöÒÔ¼°Îı¾ºÍµç»°Ú¿Æ­»î¶¯ºÍÐéαÐÅÏ¢Ðû´«»î¶¯¡£¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.nbcnews.com/politics/2020-election/cybersecurity-firm-finds-hacker-selling-info-148-million-u-s-n1244211


6.Ó¡¶ÈPTI·þÎñÆ÷ÔâLockBit¹¥»÷µ¼Ö·þÎñÁÙʱÖжÏ


6.jpg


Ó¡¶ÈPTI£¨Press Trust of India¡¯s£©ÔâLockBit¹¥»÷µ¼Ö·þÎñÁÙʱÖжϡ£¡£¡£¡£¡£ ¡£¡£¡£PTI½²»°ÈËÖÜÈÕ°µÊ¾£¬£¬£¬£¬£¬ £¬£¬£¬¸Ã¹«Ë¾µÄ·þÎñÆ÷Ôâ·êÁË´ó¹æÄ£ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬ £¬£¬£¬µ¼Ö·þÎñÖжÏÁËÊýÓ×ʱ£¬£¬£¬£¬£¬ £¬£¬£¬¾­¹ý¹¤³Ìʦ³¹Ò¹ÖÂÁ¦ºóµÃÒÔ¸´Ô­¡£¡£¡£¡£¡£ ¡£¡£¡£¹¥»÷²úÉúÔÚÖÜÁùÍíÉÏ10µã×óÓÒ£¬£¬£¬£¬£¬ £¬£¬£¬ÀÕË÷Èí¼þLockBitϰȾÁËÓ¡¶È×ÜÀíͨѶÉçÏÕЩËùÓеķþÎñÆ÷£¬£¬£¬£¬£¬ £¬£¬£¬²¢¼ÓÃÜÁËËùº±¼û¾ÝºÍÀûÓ÷¨Ê½¡£¡£¡£¡£¡£ ¡£¡£¡£µ«¸Ã½²»°È˰µÊ¾£¬£¬£¬£¬£¬ £¬£¬£¬µ½ÖÜÈÕÉÏÎç9µã£¬£¬£¬£¬£¬ £¬£¬£¬ÆäËùÓÐÒµÎñ¸ù»ù¶¼¸´Ô­Õý³££¬£¬£¬£¬£¬ £¬£¬£¬²¢ÇÒûÓÐÖ§¸¶Êê½ð¡£¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.thehindubusinessline.com/info-tech/pti-services-disrupted-after-massive-ransomware-attack-on-servers/article32940254.ece