¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180820
°ä²¼¹¦·ò 2018-08-20¡¾Íþвµý±¨¡¿×êÑÐÍŶӷ¢ÏÖ³¯ÏÊAPT×éÖ¯DarkhotelÀûÓÃVBScript¾ç±¾ÒýÇæ0dayµÄ¹¥»÷»î¶¯
Ç÷Ïò¿Æ¼¼µÄ°²È«×êÑÐÍŶӷ¢ÏÖ³¯ÏÊAPT×éÖ¯DarkhotelÔÚÀûÓÃ΢ÈíVBScript¾ç±¾ÒýÇæÖеÄÁãÈÕ·ì϶£¨CVE-2018-8373£©ÌáÒé¹¥»÷»î¶¯£¬£¬£¬£¬£¬¸Ã·ì϶ÊÇÒ»¸öuse-after-free·ì϶£¬£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÔÚÖ¸±êÍÆËã»úÉÏÔËÐÐshellcode¡£¡£¡£¡£¡£¡£ÔÚ×îа汾µÄWindowsÖУ¬£¬£¬£¬£¬Î¢ÈíÔÚä¯ÀÀÆ÷µÄĬÈÏÅäÖÃÖнûÓÃÁËVBScript£¬£¬£¬£¬£¬Ê¹Æä²»Ò×Êܵ½¹¥»÷¡£¡£¡£¡£¡£¡£Î¢ÈíÒÑÔÚ8Ô°²È«¸üÐÂÖн¨¸´ÁË´Ë·ì϶¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/zero-day-in-microsofts-vbscript-engine-used-by-darkhotel-apt/
¡¾Íþвµý±¨¡¿×êÑÐÈËÔ±ÑÝʾÈôºÎÀûÓÃÓïÒôÐÅÏä½Ù³ÖPayPalºÍWhatsAppÕË»§
°²È«×êÑÐÈËÔ±Martin Vigo³Æ¹¥»÷Õß¿ÉÀûÓÃÓïÒôÐÅÏäÈëÇÖÓû§µÄÔÚÏßÕË»§£¬£¬£¬£¬£¬ÈçPayPalºÍWhatsAppµÈ¡£¡£¡£¡£¡£¡£´óÎÞÊýÔËÓªÉ̲»½öÖ§³Öͨ¹ýÊÖ»ú½Ó¼ûÓïÒôÐÅÏ䣬£¬£¬£¬£¬»¹Ö§³Öͨ¹ýPINÂëʹÓÃ±í²¿µç»°ºÅÂë½Ó¼ûÓïÒôÐÅÏä¡£¡£¡£¡£¡£¡£ºÜ¶àÓû§Ê¹ÓÃÁËĬÈϵÄPINÂ룬£¬£¬£¬£¬ÀýÈçµç»°ºÅÂëµÄºóËÄλ»òÕß1111¼°1234µÈµ¥Ò»ÃÜÂë¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÑÝʾÁËÈôºÎÀûÓÃÓïÒôÐÅÏäÀ´³ÁÖÃÓû§µÄÔÚÏßÕË»§µÄÃÜÂ룬£¬£¬£¬£¬²¢×îÖÕ½Ù³ÖÓû§µÄPayPalºÍWhatsAppÕË»§¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.kaspersky.com/blog/hacking-online-accounts-via-voice-mail/23499/
¡¾¶ñÒâÈí¼þ¡¿×êÑÐÍŶӷ¢ÏÖеÄAZORultľÂí±äÌå¼°ÀÕË÷Èí¼þAurora
Salesforce×êÑÐÈËÔ±Vishal Thakur·¢ÏÖеÄAZORultľÂí±äÌå¼°ÀÕË÷Èí¼þAurora¡£¡£¡£¡£¡£¡£µ½2018Äê7Ôµף¬£¬£¬£¬£¬×êÑÐÈËÔ±¹Û²ìµ½¸ÃľÂí±»ÓÃÓÚÕë¶ÔÈ«ÇòÍÆËã»úµÄ¶ñÒâ¹¥»÷»î¶¯ÖУ¬£¬£¬£¬£¬×î³õµÄϰȾý½éÊÇÍøÂç´¹µöÓʼþ£¬£¬£¬£¬£¬ÆäÔ̺¬Á½¸öÓÐЧºÉÔØ£¬£¬£¬£¬£¬Ò»¸öÊÇÖØÒªÓÃÓÚÇÔÈ¡Óû§Í´´¦µÄľÂí£¬£¬£¬£¬£¬ÀýÈç±¾µØÕË»§ºÍä¯ÀÀÆ÷µÄÍ´´¦µÈ¡£¡£¡£¡£¡£¡£ÁíÒ»¸öÓÐЧºÉÔØÊÇÀÕË÷Èí¼þAurora£¬£¬£¬£¬£¬ÆäÀÕË÷µÄÊê½ðΪ150ÃÀÔª¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/azorult-trojan-serving-aurora-ransomware-by-malactor-oktropys/
¡¾¶ñÒâÈí¼þ¡¿°²È«×êÑÐÈËÔ±·¢ÏÖÖØÒªÕë¶Ôº«¹úµÄÐÂÀÕË÷Èí¼þMAFIA
×êÑÐÈËÔ±·¢ÏÖÖØÒªÕë¶Ôº«¹úµÄÐÂÀÕË÷Èí¼þ¼Ò×åMAFIA¡£¡£¡£¡£¡£¡£Ä¿Ç°»¹²»ÖªÂ·MAFIAÈôºÎ½øÈëÓû§µÄϵͳ£¬£¬£¬£¬£¬µ«ËüºÜ¿ÉÄÜÊÇͨ¹ýÍøÂç´¹µö»î¶¯ÊµÏÖÕâÒ»²½µÄ¡£¡£¡£¡£¡£¡£MAFIAÀûÓÃOpenSSLÀ´¼ÓÃÜÎļþ£¬£¬£¬£¬£¬ËüʹÓÃAES-256Ëã·¨µÄCBCģʽ£¬£¬£¬£¬£¬²¢ÔÚ¼ÓÃܵÄÎļþºó¸½¼Ó.MAFIAÀ©´óÃû¡£¡£¡£¡£¡£¡£ÓÉÓÚÆä¼ÓÃܹý³ÌºÜÂý£¬£¬£¬£¬£¬Óû§¿Éͨ¹ýÖÕÖ¹Æä¹ý³Ì£¨Í¨³£ÃûΪwinlogin.exe£©»ò¹Ø¹ØÍÆËã»úÀ´×èÖ¹Ëü¡£¡£¡£¡£¡£¡£MAFIAʹÓÃTor´úÀí½øÐÐC2ͨѶ£¬£¬£¬£¬£¬Æäͨ¹ýHTTP GETÒªÇóÀ´·¢ËͼÓÃÜÃÜÔ¿ºÍIV¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://bartblaze.blogspot.com/2018/08/mafia-ransomware-targeting-users-in.html
¡¾¶ñÒâÈí¼þ¡¿×êÑлú¹¹°ä²¼¹ØÓÚÒøÐÐľÂíTrickbotµÄбäÌåµÄ·ÖÎö»ã±¨
Cyberbit×êÑÐÍŶӷ¢ÏÖÒøÐÐľÂíTrickbotµÄбäÖÖʹÓÃÁËеÄÌӱܼì²â¼¼Êõ¡£¡£¡£¡£¡£¡£Trickbot×Ô2016ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬£¬£¬£¬£¬ÆäÔ̺¬ÇÔÈ¡ä¯ÀÀÆ÷ÐÅÏ¢¡¢ÇÔÈ¡OutlookÐÅÏ¢¡¢Ëø¶¨ÍÆËã»ú¡¢ÍøÂçϵͳºÍÍøÂçÐÅÏ¢ÒÔ¼°ÇÔÈ¡ÓòÃûÍ´´¦µÈÄ£¿£¿£¿£¿£¿é¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖTrickbotµÄбäÖÖѡȡ¹ý³ÌÍڿյĴúÂë×¢Èë¼¼Êõ£¬£¬£¬£¬£¬´óÎÞÊý°²È«²úÆ·¶¼ÎÞ·¨¼ì²âµ½ÕâÖÖÍþв¡£¡£¡£¡£¡£¡£¸Ã±äÌåµÄÐÐΪģʽÀàËÆÓÚÒøÐÐľÂíFlokibot¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.cyberbit.com/blog/endpoint-security/latest-trickbot-variant-has-new-tricks-up-its-sleeve/
¡¾·ì϶²¹¶¡¡¿×êÑÐÈËÔ±Åû¶¼ÓÄôóISPµÄTRSϵͳÖеÄÒ»¸ö°²È«·ì϶
8ÔÂ19ÈÕProject InsecurityµÄÁ½Ãû°²È«×êÑÐÈËÔ±Dominik PennerºÍManny MandÅû¶Soleo Communications¿ª·¢µÄTRSϵͳ´æÔÚÒ»¸ö±¾µØÎļþй¶·ì϶¡£¡£¡£¡£¡£¡£TRSϵͳÊÇÖ¸µçÐÅÖм̷þÎñ£¬£¬£¬£¬£¬ÓÃÓÚÔ®ÊÖ¶úÁû»ò˵»°×谵Ȳм²ÈËͨ¹ý¼üÅÌ»òÆäËü¸¨ÖúÉ豸²¦´òµç»°¡£¡£¡£¡£¡£¡£¼ÓÄôóµÄËùÓÐÖØÒªISP¶¼ÊÜÓ°Ï죬£¬£¬£¬£¬Ô̺¬Rogers¡¢TelusºÍBCEµÈ£¬£¬£¬£¬£¬ÕâЩISPµÄ·þÎñ¶ÔÏóº¸ÇÁ˳¬¹ý3000Íò¼ÓÄôó¹«Ãñ¡£¡£¡£¡£¡£¡£ËùÓеÄÖØÒª¼ÓÄôóISP¶¼ÒѾ½¨¸´Á˸÷ì϶¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/canadian-telcos-patch-vulnerability-in-trs-systems/


¾©¹«Íø°²±¸11010802024551ºÅ