¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190121

°ä²¼¹¦·ò 2019-01-21
1¡¢DarkHydrus APTÔÚÖж«µØÓò·Ö·¢RogueRobinľÂíбäÖÖ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


APT×éÖ¯DarkHydrusÔÚÕë¶ÔÖж«µØÓòµÄй¥»÷»î¶¯Öд«²¼RogueRobinľÂíµÄбäÖÖ£¬£¬£¬£¬£¬ £¬£¬£¬²¢ÇÒÀûÓÃGoogle Drive×÷Ϊ´úÌæµÄC2ͨѶ»úÔì¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÍøÂçµ½µÄÈý·Ýµö¶üÎĵµ¶¼ÊÇ.xlsmÎļþ£¬£¬£¬£¬£¬ £¬£¬£¬ÎļþÖеĶñÒâºê½«¿ªÊÍÓÃC££±àдRogueRobinľÂí¡£¡£¡£¡£¡£¡£DarkHydrusÔÚ2018Äê12ÔÂÖÁ2019Äê1ÔÂÆÚ¼ä´´½¨ÁËÕâЩÎĵµ£¬£¬£¬£¬£¬ £¬£¬£¬ÕâЩÎĵµµÄ½»¸¶·½Ê½Î´Öª£¬£¬£¬£¬£¬ £¬£¬£¬µ«ºÜ¿ÉÄÜÊÇͨ¹ý´¹µöÓʼþ´«²¼¡£¡£¡£¡£¡£¡£¾ßÌåIoCÇë²Î¿¼ÒÔÏ»㱨Á´½Ó¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/darkhydrus-delivers-new-trojan-that-can-use-google-drive-for-c2-communications/


2¡¢ÒÁÀʺڿͽ«ÀÕË÷Èí¼þBlackRouter×÷ΪRaaSÍÆ¹ã

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


×êÑÐÈËÔ±A Shadow·¢ÏÖÒÁÀʺڿÍÔÚTelegramÖÐÍÆ¹ãÀÕË÷Èí¼þBlackRouterµÄRaaS·þÎñ£¬£¬£¬£¬£¬ £¬£¬£¬²ÎÓë¸ÃRaaS²¢·Ö·¢BlackRouterµÄÈËÄܹ»»ñµÃÊê½ðµÄ80%£¬£¬£¬£¬£¬ £¬£¬£¬ÆäÓà20%¹éÓÚBlackRouterµÄ¿ª·¢Õß¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷Õßͬʱ»¹ÔÚÍÆ¹ãÔ¶¿ØÄ¾ÂíBlackRat£¬£¬£¬£¬£¬ £¬£¬£¬BlackRatµÄÖ°ÄÜÔ̺¬¼ÓÃÜͨѶ¡¢Ìӱܼì²â¡¢ÆôÓÃRDP¡¢ÅäÖÃÍÚ¿óÈí¼þ¡¢¼üÅ̼ͼ¡¢ÇÔÈ¡¼ÓÃÜÇ®±ÒÇ®°üµÈ¡£¡£¡£¡£¡£¡£Ö»¹Ü¸Ã¹¥»÷ÕßÔÚÍÆ¹ã£¬£¬£¬£¬£¬ £¬£¬£¬µ«BlackRouterËÆºõ²¢Ã»ÓдóÁ¿´«²¼¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/blackrouter-ransomware-promoted-as-a-raas-by-iranian-developer/


3¡¢×êÑÐÍŶӰ䲼WindowsÁãÈÕ·ì϶µÄһʱ½¨¸´²¹¶¡

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Acros Security°ä²¼ÁËWindowsÁãÈÕ·ì϶#angrypolarbearbugµÄһʱ½¨¸´²¹¶¡¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇ×êÑÐÈËÔ±SandboxEscaperÓÚ12ÔÂ27ÈÕÅû¶µÄ£¬£¬£¬£¬£¬ £¬£¬£¬¿ÉÓÃÓÚÒÔSYSTEMȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£Æ¾¾ÝSandboxEscaperµÄPoC£¬£¬£¬£¬£¬ £¬£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ʹÓÃWindowsÃýÎó»ã±¨ÎļþµÄÄÚÈݸ²¸Çϵͳ×é¼þ¡°pci.sys¡±¡£¡£¡£¡£¡£¡£Acros SecurityµÄһʱ½¨¸´²¹¶¡ºÏÓÃÓÚ64λµÄWindows 10°æ±¾1803£¬£¬£¬£¬£¬ £¬£¬£¬µ«¸Ã¹«Ë¾¼¤ÀøÓû§ÁªÏµ¸Ã¹«Ë¾ÒÔ»ñµÃÆäËüWindows°æ±¾µÄ½¨¸´²¹¶¡¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/windows-zero-day-bug-that-overwrites-files-gets-interim-fix/


4¡¢×ʲúÖÎÀí¹«Ë¾BlackRockÒâ±íй¶ÊýǧÃû²ÆÕþÕÕ·÷µÄÃô¸ÐÐÅÏ¢

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


×ʲúÖÎÀí¹«Ë¾±´À³µÂ£¨BlackRock£©ÆìϵÄiShares»ù½ðÍøÕ¾ÉÏÒâ±íй¶ÁËÈý¸öÔ̺¬Ãô¸ÐÐÅÏ¢µÄµç×Ó±í¸ñ¡£¡£¡£¡£¡£¡£ÕâЩ±í¸ñÔ̺¬±´À³µÂµÄ12000¶àÃû²ÆÕþÕÕ·÷ºÍÏúÊÛÈËÔ±µÄÐÕÃû¼°µç×ÓÓʼþµØÖ·£¬£¬£¬£¬£¬ £¬£¬£¬²¢ÁгöÁËÿλ²ÆÕþÕÕ·÷ÔÚ¹«Ë¾µÄiShares ETFÖÐÖÎÀíµÄ×ʲú¡£¡£¡£¡£¡£¡£ÕâЩÎļþµÄÁ´½ÓÈÕÆÚÊÇ2018Äê12ÔÂ5ÈÕ£¬£¬£¬£¬£¬ £¬£¬£¬Ä¿Ç°Éв»Ã÷ÏÔËüÃÇÓÚºÎʱ±»°ä²¼µ½ÍøÕ¾ÉÏ¡£¡£¡£¡£¡£¡£ÔÚÉÏÖÜÎåÅí²©É籨·֮ºó£¬£¬£¬£¬£¬ £¬£¬£¬±´À³µÂÒѾ­É¾³ýÁËÕâЩÎļþ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.financialexpress.com/industry/technology/data-leak-blackrock-exposes-info-on-thousands-of-advisers-via-website/1448830/


5¡¢Lebanon VAÒ½ÁÆÖÐÐÄÒâ±íй¶½üǧÃû»¼ÕßµÄPHIÐÅÏ¢

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


±öϦ·¨ÄáÑÇÖݵÄLebanon VAÒ½ÁÆÖÐÐÄÒâ±íй¶993Ãû»¼ÕßµÄÃô¸ÐÒ½ÁÆÐÅÏ¢¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñ²úÉúÔÚ2018Äê11Ô£¬£¬£¬£¬£¬ £¬£¬£¬Ò½ÁÆÖÐÐĵÄÒ»ÃûÔ±¹¤ÔÚÏòÒ»ÃûÕ÷ѯÍËÒÛÎäÊ¿ÁÆÑøÉèÊ©µÄÓû§·¢ËÍÓʼþʱ£¬£¬£¬£¬£¬ £¬£¬£¬Òâ±í½«ÁÆÑøÔºµÄÓû§Ãûµ¥·¢ËͳöÈ¥¡£¡£¡£¡£¡£¡£¸ÃÃûµ¥Ô̺¬ÁËÍËÒÛÎäÊ¿µÄÐÕÃû¡¢Éç»á°²È«ºÅÂëËõд¡¢ÈëסµÄÁÆÑøÔººÍÒ½ÁÆÕï¶ÏµÈÐÅÏ¢¡£¡£¡£¡£¡£¡£Ò½ÁÆÖÐÐÄÒѾ­ÏòÊܵ½Ó°ÏìµÄÓû§·¢ËÍÁËÊý¾Ýй¶֪ͨ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hipaajournal.com/phi-of-almost-1000-lebanon-va-medical-center-patients-impermissibly-disclosed/


6¡¢Ç°¹ÍÔ±ÈëÇÖWordPress WPML²å¼þ¹ÙÍø£¬£¬£¬£¬£¬ £¬£¬£¬ÏòÓû§·¢ËÍÀ¬»øÓʼþ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


WordPress¶à˵»°·­Òë²å¼þWPMLµÄ¹ÙÍø±»ºÚ£¬£¬£¬£¬£¬ £¬£¬£¬Óû§½Ó¹Üµ½À¬»øÓʼþ³Æ¸Ã²å¼þ³ä³âÁË·ì϶¡£¡£¡£¡£¡£¡£Æ¾¾ÝWPMLµÄÚ¹ÊÍ£¬£¬£¬£¬£¬ £¬£¬£¬ÕâÊÇÓÉÓÚÒ»Ãûǰ¹ÍÔ±ÔÚÆäÍøÕ¾ÉÏÁôÏÂÁ˺óÃŵ¼ÖµÄ¡£¡£¡£¡£¡£¡£¹¥»÷Õß»¹ÔÚÍøÕ¾ÉϵIJɰìÒ³Ãæ´ó½«°²È«·ì϶Ôö³¤Îª¸Ã²å¼þµÄÒ»ÏîÖ°ÄÜ¡£¡£¡£¡£¡£¡£WPML¿ª·¢ÈËÔ±Amir Helzer°µÊ¾ÒѾ­½¨¸´ÁËÍøÕ¾²¢³Á½¨ÁË´úÂ룬£¬£¬£¬£¬ £¬£¬£¬µ«½¨ÒéËùÓÐЧ»§£¨Ô¼Îª60ÍòÈË£©³ÁÖÃÃÜÂë¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ex-employee-hacks-wpml-wordpress-plugin-site-and-spams-users/


ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù