ºÚ¿Í¹«¿ª¼ÓÃÜÇ®±ÒÂòÂôËùBuyucoinÓû§µÄÊý¾Ý£»£»£»£»£»Î±Ôì³É»ªÎªÒƶ¯ÀûÓõĶñÒâÈí¼þͨ¹ýWhatsApp·Ö·¢

°ä²¼¹¦·ò 2021-01-26

1.ºÚ¿Í¹«¿ª¼ÓÃÜÇ®±ÒÂòÂôËùBuyucoinÓû§µÄÊý¾Ý


1.jpg


ShinyHuntersÔÚ°µÍøÉϹ«¿ªÓ¡¶È¼ÓÃÜÇ®±ÒÂòÂôËùBuyucoinÓû§µÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£Õâ´Î×ܹ²Ð¹Â¶ÁËÈý¸öMongoDBÊý¾Ý¿â£¬£¬£¬ £¬£¬ÕâЩÊý¾Ý¿â¾ùÒÔ¹¦·ò¶¨Ãû£¬£¬£¬ £¬£¬±ðÀëΪ2020Äê6ÔÂ1ÈÕ¡¢2020Äê7ÔÂ14ÈÕºÍ2020Äê9ÔÂ5ÈÕ¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶Êý¾ÝÔ̺¬Óû§¼Í¼¡¢¼ÓÃÜÇ®±ÒÒµÎñÂòÂô¡¢Óû§Á´½ÓµÄÒøÐÐÕÊ»§ÐÅÏ¢ÒÔ¼°ÂòÂôËùÄÚ²¿Ê¹ÓÃµÄÆäËû±í£¬£¬£¬ £¬£¬ÆäÖÐÓû§¼Í¼±í´æ´¢ÁË161487¸ö³ÉÔ±µÄÐÅÏ¢£¬£¬£¬ £¬£¬Ô̺¬µç×ÓÓʼþµØÖ·¡¢¹ú¶È/µØÓò¡¢¹þÏ£ÃÜÂë¡¢ÊÖ»úºÅÂëºÍGoogleµÇ¼ÁîÅÆµÈ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/data-breach-at-buyucoin-crypto-exchange-leaks-user-info-trades/


2.IntelÈ·ÈÏÓÉÓÚÆäÄÚ²¿ÃýÎóµ¼Ö²ÆÕþÐÅϢй¶


2.jpg


IntelÈ·ÈÏÓÉÓÚÆä¹«Ë¾ÍøÂçûÓÐÊܵ½¹¥»÷£¬£¬£¬ £¬£¬ÊÇÄÚ²¿ÃýÎóµ¼Ö²ÆÕþÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£²»¾Ãǰ£¬£¬£¬ £¬£¬¸Ã¹«Ë¾³ÆÐÂÎűà×ëÊÒµÄÍøÕ¾Ôâµ½¹¥»÷£¬£¬£¬ £¬£¬ºÚ¿ÍÇÔÈ¡ÁËÆä¼¾¶ÈÊÕÒæ»ã±¨¡£¡£¡£¡£¡£¡£¡£¸Ã»ã±¨Ô­¶¨ÓÚÖÜËÄÔÚ»ª¶û½ÖÂòÂôÊÕÅ̺󼸸öÓ×ʱ°ä²¼£¬£¬£¬ £¬£¬ÏÖ²»µÃ²»ÔÚÊÕÅÌǰ½øÐа䲼¡£¡£¡£¡£¡£¡£¡£Ö±µ½ÖÜÎ壬£¬£¬ £¬£¬Intel°ä·¢ÉêÃ÷°µÊ¾²¢Ã»ÓкڿÍÈëÇÖ£¬£¬£¬ £¬£¬Õâ´Îй¶ÊÇÓÉÓÚÄÚ²¿ÃýÎóµ¼ÖÂURL±»ÎÞÒâ¼ä¹«¿ª²¢±»µÚÈý·½½Ó¼û¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬ £¬£¬¸Ã¹«Ë¾¹É¼ÛÖÜÎåÊÕÅ̵ø·ù³¬¹ý9£¥¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/113794/data-breach/intel-data-leak-2.html


3.×êÑÐÍŶӷ¢ÏÖAvaddonÀûÓÃDDoS¹¥»÷ÀÕË÷Êê½ð


3.png


×êÑÐÍŶӷ¢ÏÖÁíÒ»¸öÀÕË÷Èí¼þÍÅ»ïAvaddonÔÚʹÓÃDDoS¹¥»÷À´ÀÕË÷Êê½ð¡£¡£¡£¡£¡£¡£¡£ÔÚ2020Äê10Ô£¬£¬£¬ £¬£¬SunCryptºÍRagnarLockerÍÅ»ï¾ÍÆðͷʹÓÃÒÔDDoS¹¥»÷ΪÍþввÆÈÊܺ¦ÕßÖ§¸¶Êê½ðµÄÐÂÕ½Êõ¡£¡£¡£¡£¡£¡£¡£µ±¹«Ë¾ÔâÀÕË÷Èí¼þ¹¥»÷ʱ£¬£¬£¬ £¬£¬ºÜ¶àÊܺ¦Õß»á´Ó±¸·ÝÖи´Ô­²¢²»Óë¹¥»÷ÕßÁªÏµ¡£¡£¡£¡£¡£¡£¡£¶øAvaddonÔòʹÓÃDDoS¹¥»÷À´·ÛËéÊܺ¦ÕßµÄÍøÕ¾»òÍøÂ磬£¬£¬ £¬£¬Ö±µ½Êܺ¦ÕßÓëËûÃÇÁªÏµ²¢ÆðÍ·½øÐн»Éæ¡£¡£¡£¡£¡£¡£¡£·ÖÎöʦBrett Callow°µÊ¾DDoS¼ÛÖµ±ãÒËÇÒµ¥Ò»£¬£¬£¬ £¬£¬·¸×ï·Ö×Ó¶Ô¹«Ë¾Ê©¼ÓµÄѹÁ¦Ô½´ó£¬£¬£¬ £¬£¬Ô½ÈÝÒ׵õ½Êê½ð¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/another-ransomware-now-uses-ddos-attacks-to-force-victims-to-pay/


4.αÔì³É»ªÎªÒƶ¯ÀûÓõĶñÒâÈí¼þͨ¹ýWhatsApp·Ö·¢


4.png


ESET×êÑÐÈËÔ±Lukas Stefanko·¢ÏÖеÄαÔì³É»ªÎªÒƶ¯ÀûÓõĶñÒâÈí¼þ¿Éͨ¹ýWhatsApp·Ö·¢¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ»áÀûÓÃWhatsApp×Ô¶¯»Ø¸´Ö°ÄÜ·¢ËͶñÒâÁ´½Ó£¬£¬£¬ £¬£¬¸ÃÁ´½ÓÖ¸ÏòαÔìµÄ»ªÎªÒƶ¯ÀûÓ÷¨Ê½£¬£¬£¬ £¬£¬Óû§ÔÚµã»÷ºó»á±»³Á¶¨Ïòµ½Î±ÔìGoogle PlayÉ̵êÍøÕ¾¡£¡£¡£¡£¡£¡£¡£Óû§Ò»µ©×°Öú󣬣¬£¬ £¬£¬¸Ã¶ñÒâÈí¼þ»¹»áÌáÐÑÊܺ¦Õß´ò¿ªÃ÷Öª½Ó¼ûȨÏÞ£¬£¬£¬ £¬£¬¶øºóÖ´ÐÐÈ䳿¹¥»÷¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬ £¬£¬Ëü»¹ÄܽӼû²¢¸²¸Çºó¶ÜÔËÐÐµÄÆäËûÀûÓ㬣¬£¬ £¬£¬ÕâÒâζןÃÀûÓÃÄܹ»ÀûÓÃαÔìµÄ´°¿Ú¿ÉÀ´ÇÔȡʹ´¦ÒÔ¼°ÆäËûÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2021/01/beware-new-wormable-android-malware.html


5.Checkpoint°ä²¼2020ÄêQ4Æ·ÅÆÍøÂç´¹µöµÄ·ÖÎö»ã±¨


5.png


Checkpoint°ä²¼ÁË2020ÄêQ4Æ·ÅÆÍøÂç´¹µöµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£»ã±¨ÏÔʾ£¬£¬£¬ £¬£¬ÔÚ2020Äê×îºóÒ»¸ö¼¾¶ÈMicrosoftÈÔÕ¼¾ÝÊ®´óÆ·ÅÆµÄ°ñÊ×£¬£¬£¬ £¬£¬ºÜ¶àÍøÕ¾¶¼¼ÙÒâMicrosoftµÇ¼½çÃæÇÔÈ¡Óû§Í´´¦£¬£¬£¬ £¬£¬ÆäռȫÇòËùÓÐÆ·ÅÆÍøÂç´¹µö³¢ÊÔµÄ43£¥¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬ £¬£¬ÒÔDHL(18%)ºÍÑÇÂíÑ·µç×ÓÓʼþ(5%)´¹µöΪÖ÷µÄÔËÊäºÍÁãÊÛÒµ½ñÄê³õ´ÎõÒÉíǰÈýÃû£¬£¬£¬ £¬£¬²¢ÔÚ¼ÙÆÚºóÕ¼±ÈÔö³¤ÁËÒ»±¶¶à¡£¡£¡£¡£¡£¡£¡£Æä´Î£¬£¬£¬ £¬£¬Ê®´óÆ·ÅÆ»¹Ô̺¬LinkedIn(6%)¡¢Rakuten (4%)¡¢IKEA (3%)¡¢Google (2%)¡¢Paypal (2%)¡¢Chase (2%)ºÍYahoo (1%)¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.checkpoint.com/2021/01/14/brand-phishing-report-q4-2020/


6.Zscaler°ä²¼Óйؽ©Ê¬ÍøÂçDreamBusµÄ·ÖÎö»ã±¨


6.png


Zscaler°ä²¼ÁËÓйؽ©Ê¬ÍøÂçDreamBusµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±Ö¸³ö£¬£¬£¬ £¬£¬DreamBusΪ2019ËêÊ׳õ´Î³öÏÖµÄSystemdMinerµÄ¾É½©Ê¬ÍøÂçµÄ±äÌ壬£¬£¬ £¬£¬ÔÚÔ­°æ±¾ÉϽøÐÐÁËÈô¸É¸Ä½ø¡£¡£¡£¡£¡£¡£¡£ÆäÕë¶ÔLinux·þÎñÆ÷ÉÏÔËÐÐµÄÆóÒµÀûÓ÷¨Ê½£¬£¬£¬ £¬£¬¿ÉʹÓ÷ì϶ºÍ±©Á¦¹¥»÷PostgreSQL¡¢Redis¡¢SaltStack¡¢Hadoop YARN¡¢Apache Spark¡¢HashiCorp Consul¡¢SaltStackºÍSSH·þÎñµÈ¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬ £¬£¬DreamBus²ÉÈ¡Á˺ܶàÈÆ¹ý¼ì²âµÄÕ½Êõ£¬£¬£¬ £¬£¬Èçͨ¹ýеÄHTTP-over-HTTPS£¨DoH£©ºÍ̸Óë½©Ê¬ÍøÂçµÄC£¦C·þÎñÆ÷ͨѶ£¬£¬£¬ £¬£¬²¢½«C£¦CÍйÜÔÚTorÍøÂçÉÏÒÔ·À±»¹Ø¹Ø¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zscaler.com/blogs/security-research/dreambus-botnet-technical-analysis