ºÚ¿ÍÔÚ°µÍø¹ûÕæ320Íò¸öPluto TVÓû§µÄÐÅÏ¢£»SafariµÄÁ´½Ó¹²Ïí¹¦Ð§¿ÉÐÞ¸ÄÎÊÌ⣬¿ÉÄܱ»ÀÄÓÃ
Ðû²¼Ê±¼ä 2020-11-161.ºÚ¿ÍÔÚ°µÍø¹ûÕæ320Íò¸öPluto TVÓû§µÄÐÅÏ¢

ÉÏÖÜÈý£¬ºÚ¿ÍÔÚ°µÍø¹ûÕæÁ˰üÀ¨320Íò¸öPluto TVÓû§ÐÅÏ¢µÄÊý¾Ý¿â¡£Í¨¹ýÊý¾Ý¿âÑù±¾¿ÉÖª£¬Ð¹Â¶Êý¾Ý°üÀ¨Óû§Ãû¡¢µç×ÓÓʼþµØµã¡¢bcrypt¹þÏ£ÃÜÂë¡¢ÉúÈÕ¡¢×°±¸Æ½Ì¨ºÍIPµØµã¡£ºÚ¿ÍÉù³Æ´Ë´ÎÊý¾Ýй¶ÊÇÓÉShinyHuntersµ¼Öµģ¬¶ø¸ÃÊý¾Ý¿â¿ÉÄÜÊÇÁ½Äêǰй¶µÄ£¬×îмͼÊÇÔÚ2018Äê10ÔÂ12ÈÕ½¨ÉèµÄ¡£ÏÖÔÚ£¬Pluto TVÉÐδ֤ʵÊÇ·ñ±¬·¢ÁËÊý¾Ýй¶£¬½öÌåÏÖËûÃÇÕýÔÚÊÓ²ìÖС£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hacker-shares-32-million-pluto-tv-accounts-for-free-on-forum/
2.ÐÂÐÅÓÿ¨¹¥»÷ͨ¹ýαÔìWebSocketsÇÔÈ¡Óû§ÐÅÏ¢

Ñо¿Ö°Ô±·¢Ã÷еÄÐÅÓÿ¨¹¥»÷·½·¨£¬Í¨¹ýαÔìÐéαÐÅÓÿ¨ÂÛ̳ºÍWebSocketsÇÔÈ¡Óû§ÐÅÏ¢¡£ºÚ¿ÍÊ×ÏÈ»á×¢Èë¶ñÒâ¾ç±¾£¬½«ÌìÉúµÄ»á»°idºÍ¿Í»§¶ËIPµØµã´æ´¢ÔÚä¯ÀÀÆ÷µÄÍâµØ´æ´¢ÖУ¬ÕâЩ²ÎÊýÔÚÉÔºóµÄ»á»°ºó»á·¢Ëͻع¥»÷Õß¡£ÎªÁË»ñÈ¡Óû§µÄIPµØµã£¬¹¥»÷ÕßÇÉÃîµØÊ¹ÓÃÁËCloudflareµÄAPI¡£±ðµÄ£¬¹¥»÷ÕßʹÓÃWebSocketsÈ¡´úÁËHTMLµÈÆäËûÒªÁìÀ´ÇÔÊØÐÅÏ¢£¬Õâ¿Éʹ¹¥»÷µÄÔëÒô¸üÉÙ¡¢¸üÒþÃØ¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/skimmer-attack-fake-credit-card-steal-data/
3.SafariµÄÁ´½Ó¹²Ïí¹¦Ð§¿ÉÐÞ¸ÄÎÊÌ⣬¿ÉÄܱ»ÀÄÓÃ

iOS°æ±¾Apple Safariä¯ÀÀÆ÷ÖеÄÁ´½Ó¹²Ïí¹¦Ð§Ê¹iPhone¡¢iPadºÍiPod TouchÓû§¿ÉÒÔÔÚ¹²Ïí²¿·ÖÍøÒ³Ê±¸ü¸ÄÎÊÌ⣬¸Ã¹¦Ð§¿É±»ÀÄÓÃÖÆÔì¼ÙÐÂÎÅ¡£µ±Ê¹ÓÃSafariä¯ÀÀÍøÒ³Ê±£¬Óû§¿ÉÒÔ·ÖÏí²¿·ÖÎı¾ÕªÒª¶ø²»ÊÇÕû¸öÒ³Ãæ£¬Ò²¿ÉÒÔ¿ØÖƺͱ༸ÃÎı¾¡£ÔÚͨ¹ýiMessageÓëÆäËûiPhoneÓû§¹²Ïí¸ÃÒ³ÃæÊ±£¬ÌìÉúµÄÁ´½ÓÔ¤ÀÀΪ¸ÃÎı¾µÄÄÚÈݶø·ÇÍøÒ³µÄÔʼÎÊÌâ¡£¸Ã¹¦Ð§¿É±»ÓÃÀ´ÖÆÔì²¢Èö²¥ÐéαÐÂÎÅ£¬ÏÖÔÚÉÐδ±»ÐÞ¸´¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/apple-ios-safari-feature-can-be-used-to-share-fake-news-headlines/
4.°ÄÖÞÕþ¸®Ðû²¼Ô¤¾¯ÎÀÉú²¿·ÖÐè×¢ÖØÌá·ÀSDBBot RAT

°Ä´óÀûÑÇÕþ¸®Ðû²¼Çå¾²¾¯±¨£¬ÖÒÑÔÎÀÉú²¿·ÖÐè×¢ÖØÌá·ÀSDBBot RAT¡£°Ä´óÀûÑÇÍøÂçÇå¾²ÖÐÐÄ£¨ACSC£©ÌåÏÖ£¬×î½üʹÓÃSDBBotÔ¶³Ì»á¼û¹¤¾ß£¨RAT£©¶Ô°Ä´óÀûÑÇÎÀÉú²¿·ÖµÄÕë¶ÔÐÔÔ˶¯ÓÐËùÔöÌí£¬²¢´ß´Ù¸Ã²¿·ÖµÄ×éÖ¯¼ì²éÆäÍøÂçÇå¾²·ÀÓù²½·¥¡£ËäÈ»ACSCûÓÐÌṩÈκιØÓڸù¥»÷Ô˶¯µÄϸ½Ú£¬µ«SDBBot RAT»òÐíÓëºÚ¿Í×éÖ¯TA505Óйء£±ðµÄ£¬ACSC»¹·¢Ã÷SDBBotÓÉ3¸ö²¿·Ö×é³É£¬»®·ÖΪһ¸ö½¨É賤ÆÚÐÔµÄ×°ÖóÌÐò¡¢Ò»¸öÏÂÔØÌØÊâ×é¼þµÄ¼ÓÔØ³ÌÐòÒÔ¼°RAT×Ô¼º¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/australian-government-warns-of-possible-ransomware-attacks-on-health-sector/
5.SchneideÐû²¼ÓйØLinux¶ñÒâÈí¼þDrovorubµÄÇ徲ͨ¸æ

SchneideÐû²¼ÁËÒ»¸öÇ徲ͨ¸æ£¬ÖÒÑÔÆäÓû§×¢ÖØLinux¶ñÒâÈí¼þDrovorub¡£ÔçÔÚ½ñÄê8Ô£¬NSAºÍFBIÍŽáÐû²¼¾¯±¨²¢¶Ô¸Ã¶ñÒâÈí¼þ¾ÙÐÐÁËÆÊÎö¡£¾Ý³Æ£¬¸Ã¶ñÒâÈí¼þÊôÓÚ¶íÂÞË¹ÍøÂçÌØ¹¤×éÖ¯APT28£¬ÊÇÒ»ÖÖÄ£¿é»¯¶ñÒâÈí¼þ£¬°üÀ¨Ö²ÈëÎï¡¢ÄÚºËÄ£¿érootkit¡¢Îļþ´«Ê乤¾ß¡¢¶Ë¿Úת·¢Ä£¿éºÍÏÂÁîÓë¿ØÖÆ£¨C2£©·þÎñÆ÷£¬¿ÉÓÃÀ´ÇÔÈ¡Îļþ¡¢½¨ÉèºóÃŲ¢Ô¶³Ì¿ØÖÆÄ¿µÄÅÌËã»ú¡£Schneider±Þ²ß¿Í»§ÊµÑé×ÝÉî·ÀÓùÕ½ÂÔ£¬ÒÔ±£»¤Trio QÊý¾Ý¹ã²¥ºÍTrio JÊý¾Ý¹ã²¥×°±¸ÃâÊÜDrovorub¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/110920/cyber-crime/drovorub-linux-malware.html
6.ÁãÊÛ¹«Ë¾CencosudѬȾEgregor£¬¹«Ë¾µÄÔËÓªÊܵ½Ó°Ïì

ÁãÊÛ¹«Ë¾CencosudѬȾÀÕË÷Èí¼þEgregor£¬¹«Ë¾µÄÔËÓªÊܵ½Ó°Ïì¡£×ܲ¿Î»ÓÚÖÇÀûµÄ¿ç¹ú¹«Ë¾CencosudÊÇÀ¶¡ÃÀÖÞ×î´óµÄÁãÊÛ¹«Ë¾Ö®Ò»£¬ÆäÔÚ°¢¸ùÍ¢¡¢°ÍÎ÷¡¢ÖÇÀû¡¢¸çÂ×±ÈÑǺÍÃØÂ³Ä±»®×ÅÖÖÖÖ¸÷ÑùµÄÊÐËÁ¡£CencosudÓÚ±¾ÖÜÄ©Ôâµ½ÁËEgregorÀÕË÷Èí¼þ¹¥»÷£¬ÆäÊÐËÁÖеÄ×°±¸±»¼ÓÃÜ£¬²¢Ó°ÏìÁ˹«Ë¾µÄÔËÓª¡£²¿·ÖÊÐËÁÖÒÑÔÓÉÓÚÊÖÒÕÎÊÌâ²»½ÓÊÜCencosudÐÅÓÿ¨£¬²»½ÓÊÜÍË»õ»òÒ²²»ÔÊÐíÍøÉϹºÎï¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/retail-giant-cencosud-hit-by-egregor-ransomware-attack-stores-impacted/


¾©¹«Íø°²±¸11010802024551ºÅ