Group-IB°ä²¼¶ÔÀ´ÄêÍøÂçÍþвµÄÔ¤²â·ÖÎö»ã±¨£»£»£»£»£»£»Xbox´æÔڿɱ»ÓÃÀ´ÇÔÈ¡Íæ¼Òµç×ÓÓʼþµØÖ·µÄ·ì϶

°ä²¼¹¦·ò 2020-11-27

1.Group-IB°ä²¼¶ÔÀ´ÄêÍøÂçÍþвµÄÔ¤²â·ÖÎö»ã±¨


1.jpg


Group-IB°ä²¼Á˶ÔÀ´ÄêÍøÂçÍþвµÄÔ¤²â·ÖÎö»ã±¨£¬ £¬ £¬£¬£¬£¬×êÑÐÁË2019ÄêϰëÄêÖÁ2020ÄêÉϰëÄêÖ®¼ä¹ú¼ÊÍøÂç·¸×ï״ΪµÄÖØÒª±ä¶¯£¬ £¬ £¬£¬£¬£¬²¢¶ÔÀ´Äê×ö³öÁËÔ¤²â¡£¡£¡£ ¡£¡£»ã±¨Ö¸³ö£¬ £¬ £¬£¬£¬£¬ÀÕË÷Èí¼þ»î¶¯Ôì³ÉÁËÑϳÁµÄ¾­¼ÃËðʧ£¬ £¬ £¬£¬£¬£¬Ë½Óª¹«Ë¾ºÍµ±¾Ö»ú¹¹¶¼Î´ÄÜÐÒÃâ¡£¡£¡£ ¡£¡£ÔÚ´ËÆÚ¼ä£¬ £¬ £¬£¬£¬£¬×ܹ²ÓÐÕë¶Ô³¬¹ý45¸ö¹ú¶ÈµÄ500ÂÅ´ÎÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£ ¡£¡£Æ¾¾ÝGroup-IBµÄÊØ¾É¹À¼Æ£¬ £¬ £¬£¬£¬£¬ÀÕË÷Èí¼þÍÅ»ïÔì³ÉµÄ×ܲÆÕþËðʧ³¬¹ý10ÒÚÃÀÔª£¨1005186000ÃÀÔª£©¡£¡£¡£ ¡£¡£ÆäÖУ¬ £¬ £¬£¬£¬£¬MazeºÍREvilµÄÓ°Ïì×î´ó£¬ £¬ £¬£¬£¬£¬Õ¼ËùÓй¥»÷µÄ°ëÊýÒÔÉÏ£¬ £¬ £¬£¬£¬£¬Æä´ÎÊÇRyuk¡¢NetWalkerºÍDoppelPaymer¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.group-ib.com/media/gib-report-2020/


2.Xbox´æÔڿɱ»ÓÃÀ´ÇÔÈ¡Íæ¼Òµç×ÓÓʼþµØÖ·µÄ·ì϶


2.jpg


°²È«ÈËÔ±·¢ÏÖXbox´æÔڿɱ»ÓÃÀ´ÇÔÈ¡Íæ¼Òµç×ÓÓʼþµØÖ·µÄ·ì϶£¬ £¬ £¬£¬£¬£¬Ä¿Ç°Òѱ»½¨¸´¡£¡£¡£ ¡£¡£¸Ã·ì϶λÓÚenforcement.xbox.com£¬ £¬ £¬£¬£¬£¬Óû§µÇ¼ºó¸ÃÍøÕ¾»áÔÚÆää¯ÀÀÆ÷Öд´½¨Ò»¸öÔ̺¬Web»á»°ÐÅÏ¢cookieÎļþ£¬ £¬ £¬£¬£¬£¬ÒÔ±ÉÈ˴νӼûʱ×Ô¶¯µÇ¼²¢ÎÞÐè³ÁÐÂÉí·ÝÑéÖ¤¡£¡£¡£ ¡£¡£¶ø¸ÃcookieÎļþÖÐÔ̺¬Ò»¸öδ¼ÓÃܵÄXboxÓû§ID£¨XUID£©×ֶΣ¬ £¬ £¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓÃä¯ÀÀÆ÷¸½´øµÄ¹¤¾ß±à×ëXUID×ֶΡ£¡£¡£ ¡£¡£ÔÚ½«Æä´úÌæÎªÆäËûÓû§µÄXUIDºó£¬ £¬ £¬£¬£¬£¬±ãÄܹ»¿´µ½ÆäËûÓû§µÄµç×ÓÓʼþµØÖ·¡£¡£¡£ ¡£¡£Ä¿Ç°£¬ £¬ £¬£¬£¬£¬¸Ã·ì϶Òѱ»Microsoft½¨¸´¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/xbox-bug-could-have-allowed-hackers-to-link-gamer-tags-with-players-emails/


3.BeldenÔâµ½¹¥»÷£¬ £¬ £¬£¬£¬£¬ÆäÔ±¹¤ºÍºÏ×÷ͬ°éÐÅÏ¢ÒÑй¶


3.jpg


ÍøÂçºÍµçÀ²úÆ·µÄÔì×÷Ḛ́Ùͨ£¨Belden£©³ÆÆäÔâµ½Á˹¥»÷£¬ £¬ £¬£¬£¬£¬ÆäÔ±¹¤ºÍºÏ×÷ͬ°éÐÅÏ¢ÒÑй¶¡£¡£¡£ ¡£¡£¸Ã¹«Ë¾°ä²¼ÉêÃ÷³Æ£¬ £¬ £¬£¬£¬£¬BeldenÔâµ½Á˸´ÔÓµÄÍøÂç¹¥»÷£¬ £¬ £¬£¬£¬£¬¹¥»÷Õßδ¾­ÊÚȨ½Ó¼û²¢ÇÔÈ¡ÁËÆäÏÖÔ±¹¤ºÍǰԱ¹¤µÄÓ×ÎÒÐÅÏ¢£¬ £¬ £¬£¬£¬£¬ÒÔ¼°ÆäÒµÎñºÏ×÷¹«Ë¾µÄÐÅÏ¢¡£¡£¡£ ¡£¡£Ð¹Â¶ÐÅÏ¢Ô̺¬ÐÕÃû¡¢ÉúÈÕ¡¢Éí·ÝÖ¤ºÅÂë¡¢Ô±¹¤ÒøÐÐÕÊ»§ÐÅÏ¢¡¢¼Òͥסַ¡¢µç×ÓÓʼþµØÖ·µÈÓ×ÎÒÐÅÏ¢£¬ £¬ £¬£¬£¬£¬ÒÔ¼°ÆäºÏ×÷¹«Ë¾µÄÒøÐÐÕÊ»§ÊýºÍÄÉ˰ÈËIDºÅµÈ¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/111468/data-breach/belden-discloses-data-breach.html


4.GitHub½¨¸´ÆäActionsÖпɵ¼Ö´úÂë×¢ÈëµÄ·ì϶


4.jpg


GitHub½¨¸´ÁËÆäActionsÖ°ÄÜÖпɵ¼Ö´úÂë×¢ÈëµÄ·ì϶¡£¡£¡£ ¡£¡£¸Ã·ì϶ÓÉGoogle Project Zero×êÑÐÈËÔ±ÓÚ2020Äê7Ô·¢ÏÖ²¢»ã±¨£¬ £¬ £¬£¬£¬£¬Î»ÓÚGitHubµÄActionsÖ°ÄÜÖС£¡£¡£ ¡£¡£µ±runner¹ý³Ì½âÎöSTDOUTÖдúÂëÒÔ²éÕÒ¹¤×÷Á÷ºÅÁîʱ£¬ £¬ £¬£¬£¬£¬Ã¿Ò»¸öÔÚÖ´Ðйý³ÌÖдòÓ¡²»³ÉÐÅÄÚÈݵÄGitHub²Ù×÷³ÇÊÐÊܵ½¹¥»÷¡£¡£¡£ ¡£¡£ÔÚ´óÎÞÊýÇé¿öÏ£¬ £¬ £¬£¬£¬£¬ÉèÖÃËÁÒâ»·¾³±äÁ¿µÄÖ°ÄÜ»áÔÚÖ´ÐÐÁíÒ»¸ö¹¤×÷Á÷³ÌºóÁ¢¼´Ö´ÐÐÔ¶³Ì´úÂë¡£¡£¡£ ¡£¡£ 


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2020/11/25/github-patched-a-vulnerability-months-after-googles-report/


5.µ¤ÂóÐÂÎÅÉçRitzauÔâÀÕË÷Èí¼þ¹¥»÷µ«¾Ü¸¶Êê½ð


5.jpg


µ¤Âó×î´óµÄÐÂÎÅÉçRitzauÔâÀÕË÷Èí¼þ¹¥»÷£¬ £¬ £¬£¬£¬£¬µ«»Ø¾øÖ§¸¶Êê½ð¡£¡£¡£ ¡£¡£RitzauÊÇÓÉErik RitzauÓÚ1866Äê´´½¨µÄµ¤Âó×î´óµÄ¶ÀÁ¢ÐÂÎÅÉ磬 £¬ £¬£¬£¬£¬ÆäÕ¼ÓÐ1000Íò¹ã²¥Ìý¶à¡£¡£¡£ ¡£¡£¸ÃÐÂÎÅÉç³ÆÆäÓÚ±¾ÖܶþÔ糿Ôâµ½¹¥»÷£¬ £¬ £¬£¬£¬£¬ºÚ¿ÍÈëÇֺͼÓÃÜÁËRitzauÍøÂçÉϳ¬¹ý100̨·þÎñÆ÷ÖеÄËÄ·ÖÖ®Ò»£¬ £¬ £¬£¬£¬£¬Æä±à×ëϵͳҲÒѾ­¹Ø¹Ø¡£¡£¡£ ¡£¡£µ«¸Ã¹«Ë¾ÆôÓÃÁË´¹Î£ÏµÍ³£¬ £¬ £¬£¬£¬£¬ÒÔÁíÒ»ÖÖ·½Ê½Ïò¸Ã¹úýÌå½øÐй㲥£¬ £¬ £¬£¬£¬£¬²¢ÇҸù«Ë¾µÄCEO°µÊ¾£¬ £¬ £¬£¬£¬£¬Ritzau²»»áÏòºÚ¿Í×éÖ¯Ö§¸¶Êê½ð¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/danish-news-agency-ritzau-refuses-to-pay-after-ransomware-attack/


6.°ÍÎ÷ҽԺй¶1600ÍòCOVID-19»¼ÕßµÄÓ×ÎÒÐÅÏ¢


6.jpg


°ÍÎ÷Ò½ÔºµÄÔ±¹¤ÔÚGitHubÉÏ´«ÁËÔ̺¬Óû§Ãû¡¢ÃÜÂëºÍµ±¾Öϵͳ½Ó¼ûÃÜÔ¿µÄµç×Ó±í¸ñ£¬ £¬ £¬£¬£¬£¬Ð¹Â¶Á˰ÍÎ÷1600¶àÍòCOVID-19»¼ÕßµÄÓ×ÎÒÐÅÏ¢¡£¡£¡£ ¡£¡£Õâ´ÎÐ¹Â¶Éæ¼°µ½Á½¸öÊý¾Ý¿â£¬ £¬ £¬£¬£¬£¬±ðÀëΪÓÃÓڼͼÇá¶ÈÖ¢×´»¼ÕßµÄE-SUS-VEºÍÓÃÓÚ¸ú×ÙסԺ²¡ÀýSivep-Gripe£¬ £¬ £¬£¬£¬£¬ÆäÖÐÔ̺¬µÄÃô¸ÐÐÅϢΪ»¼ÕßÐÕÃû¡¢µØÖ·¡¢IDÐÅÏ¢¡¢Ò½ÁƼͼ¡¢²¡Ê·ºÍÓÃÒ©¹æ»®µÈ¡£¡£¡£ ¡£¡£±¾µØ±¨Éç³Æ£¬ £¬ £¬£¬£¬£¬´ËÊÂÎñÓ°ÏìÁ˰ÍÎ÷27¸öÖݵľÓÃñ£¬ £¬ £¬£¬£¬£¬Ô̺¬°ÍÎ÷×Üͳ¡¢×ÜͳµÄ¼ÒÈË¡¢7Ãûµ±²¿Ãų¤ÒÔ¼°17¸öÖݵÄÖݳ¤µÈ³ÛÃûÈËÎï¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/personal-data-of-16-million-brazilian-covid-19-patients-exposed-online/