FacebookÃ÷ÎÄ´æ´¢ÊýÒÚÃÜÂ룬£¬£¬£¬£¬£¬Ô±¹¤²éÎÊ900Íò´Î£»£»£»£»£»£»£»£»APT-C-27ºÍFin7
°ä²¼¹¦·ò 2019-03-22
±¾ÖÜËÄFacebookÈÏ¿ÉÊýÒÔÒڼƵÄFacebookºÍInstagramÓû§µÄÃÜÂë¶àÄêÀ´Ò»ÏòÒÔÃ÷ÎĵĴó¾Ö´æ´¢ÔÚÄÚ²¿Êý¾ÝϵͳÖÓ×£¡£¡£¡£¡£¡£FacebookÔÚ1Ô·ݵÄÀýÐа²È«Éó²éÆÚ¼ä·¢ÏÖÁËÕâÒ»ÎÊÌ⣬£¬£¬£¬£¬£¬¸Ã¹«Ë¾°µÊ¾ÕâЩÊý¾Ý²¢Î´Ôâµ½ÀÄÓᣡ£¡£¡£¡£¡£Æ¾¾Ý°²È«¼ÇÕßBrian KrebsµÄÒ»·Ý»ã±¨£¬£¬£¬£¬£¬£¬Ô¼2000Ãû¹¤³Ìʦ»ò¿ª·¢ÈËÔ±¶ÔÕâЩÊý¾Ý½øÐÐÁËԼĪ900Íò´ÎÄÚ²¿²éÎÊ¡£¡£¡£¡£¡£¡£FacebookÉÐδÅû¶ÊÜÓ°ÏìµÄ¾ßÌåÓû§ÈËÊý£¬£¬£¬£¬£¬£¬µ«KrebsµÄ»ã±¨ÖгÆÕâÒ»Êý×ÖΪ2ÒÚÖÁ6ÒÚÖ®¼ä¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/facebook-employees-could-access-unencrypted-passwords-for-millions-of-users/2¡¢Zoll Medical¹«Ë¾Ð¹Â¶27.7Íò»¼ÕßµÄÓ×ÎÒÐÅÏ¢
±¾ÖÜÒ»Ò½ÁÆÉ豸³§ÉÌZoll Medical»ã±¨³ÆÔÚÆä×î½üµÄ·þÎñÆ÷ǨáãÆÚ¼ä£¬£¬£¬£¬£¬£¬277319Ãû»¼ÕßµÄÓ×ÎÒÐÅÏ¢Ô⵽й¶¡£¡£¡£¡£¡£¡£Zoll³ÆÕâÒ»ÊÂÎñ²úÉúÔÚ2018Äê11ÔÂ8ÈÕÖÁ12ÔÂ28ÈÕÖ®¼ä£¬£¬£¬£¬£¬£¬µ«»Ø¾øÆÀÂÛ¸ÃÊÂÎñÊÇÎÞÒâÔì³É»¹ÊǺڿ͹¥»÷µÄÁ˾֡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÊý¾ÝÔ̺¬»¼ÕßµÄÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢Ò½ÁÆÐÅÏ¢ºÍÉç»á°²È«ºÅÂë¡£¡£¡£¡£¡£¡£Zoll³Æ²¢Î´·¢ÏÖÈκÎÓë´ËÓйصÄÉí·ÝڲƻòµÁÓÃÊÂÎñ£¬£¬£¬£¬£¬£¬ËùÓÐÐÅÏ¢ÏÖÒѵõ½±£ÏÕ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.modernhealthcare.com/technology/devicemaker-data-breach-exposes-277k-patients-information3¡¢VivaGymÊý¾Ý¿âδÉèÃÜÂ룬£¬£¬£¬£¬£¬6000¶àÇóÖ°ÕßÐÅϢй¶

×êÑÐÈËÔ±·¢ÏÖÎ÷°àÑÀ½¡Éí·¿VivaGymµÄÒ»¸öMongoDBÊý¾Ý¿âδÊܱ£»£»£»£»£»£»£»£»¤£¬£¬£¬£¬£¬£¬µ¼ÖÂ6608¸öÇóÖ°ÕßµÄÃô¸ÐÐÅÏ¢¼°ÉÙÁ¿ÒµÎñÊý¾Ýй¶¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÊÇVivaGymÕÐÆ¸ÍøÕ¾»ù´¡ÉèÊ©µÄÒ»²¿ÃÅ£¬£¬£¬£¬£¬£¬ÓÉÒ»¸ö¼¼ÊõºÏ×÷ͬ°é½øÐÐÖÎÀí£¬£¬£¬£¬£¬£¬Ð¹Â¶µÄÊý¾ÝÔ̺¬ÇóÖ°ÕßµÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢¾¹ý¼ÓÃܵÄÃÜÂë¡¢DNI¡¢Óû§Ãû¡¢µÇ¼ÈÕÆÚµÈÐÅÏ¢£¬£¬£¬£¬£¬£¬»¹Ô̺¬Ò»Ð©ÒµÎñÐÅÏ¢ºÍϵͳÈÕÖ¾¡£¡£¡£¡£¡£¡£ÔÚ3ÔÂ8ÈÕ×êÑÐÈËÔ±´«µÝVivaGymºó£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âÒѵõ½±£»£»£»£»£»£»£»£»¤¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securitydiscovery.com/spanish-gym-franchise-database-exposed-by-partners-data-breach/
4¡¢Fin7й¥»÷»î¶¯£¬£¬£¬£¬£¬£¬ÖØÒª·Ö·¢SQLRatºÍDNSbot
Flashpoint×êÑÐÈËÔ±¹Û²ìµ½·¸×ïÍÅ»ïFin7µÄй¥»÷»î¶¯£¬£¬£¬£¬£¬£¬Ö»¹ÜFin7µÄÈýÃû³ÁÒª³ÉÔ±±»²¶£¬£¬£¬£¬£¬£¬µ«¸Ã×éÖ¯ÒѾ»Ø¹é£¬£¬£¬£¬£¬£¬²¢ÀûÓÃÒ»¸öеÄÖÎÀíÃæ°åAstraºÍÁ½¸öжñÒâÈí¼þÑù±¾SQLRat¡¢DNSbotÀ´¹¥»÷ÆóÒµ¡£¡£¡£¡£¡£¡£AstraÊÇPHP±àдµÄ¾ç±¾ÖÎÀíϵͳ£¬£¬£¬£¬£¬£¬ÓÃÓÚ½«¶ñÒâ¾ç±¾ÍÆË͵½ÊÜϰȾµÄÍÆËã»ú¡£¡£¡£¡£¡£¡£SQLRatºÍDNSbot¾ùͨ¹ý´¹µöÓʼþ½øÐзַ¢£¬£¬£¬£¬£¬£¬SQLRatÓÃÓÚÏνӵ½¹¥»÷ÕßµÄÊý¾Ý¿â£¬£¬£¬£¬£¬£¬¶øDNSbotÔòÓÃÓÚ´«ÊäºÅÁî¼°Êý¾Ý¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/fin7-threat-actor-group-makes-a-come-back-with-sqlrat-and-dnsbot-27f1843f5¡¢APT-C-27¶Ô×¼Öж«µØÓò£¬£¬£¬£¬£¬£¬ÖØÒª·Ö·¢njRATºóÃÅ
×êÑÐÈËÔ±·¢ÏÖ·¸×ïÍÅ»ïGoldmouse£¨ÓÖ³ÆAPT-C-27£©µÄй¥»÷»î¶¯£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÖØÒªÀûÓÃWinRARÖеĴúÂëÖ´Ðзì϶·Ö·¢njRATºóÃÅ£¬£¬£¬£¬£¬£¬Öж«µØÓò³ÉÎªÖØÒªµÄ¹¥»÷Ö¸±ê¡£¡£¡£¡£¡£¡£µö¶üÎĵµÖÐÔ̺¬Óë¿Ö²ÀÏ®»÷ÓйصÄÐÅÏ¢£¬£¬£¬£¬£¬£¬ÒÔÓÕʹÓû§Ê¹ÓÃWinRAR½âѹ¸ÃÎĵµ¡£¡£¡£¡£¡£¡£ÔÚϰȾϵͳºó£¬£¬£¬£¬£¬£¬njRATºóÃÅ»á¹Ø¹Ø·À»ðǽ£¬£¬£¬£¬£¬£¬Æô¶¯¼üÅ̼ͼÏ̲߳¢ÓëC&C·þÎñÆ÷½øÐÐͨѶ£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þµÄÆäËüÖ°ÄÜ»¹Ô̺¬Ô¶³ÌSHELL¡¢²å¼þÖ§³Ö¡¢Ô¶³Ì×ÀÃæºÍÎļþÖÎÀí¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±»¹·¢ÏÖʹÓÃÁËÒ»ÑùC£¦C£¨82.137.255.56£©µÄ¶à¸öÖ¼ÔÚÕë¶ÔAndroidÉ豸µÄÑù±¾¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/goldmouse-aka-apt-c-27-targets-the-middle-east-by-leveraging-winrars-dated-security-bug-c8caf7796¡¢Ë¼¿Æ½¨¸´Nexus»¥»»»ú¼°NX-OSÖеÄ5¸ö°²È«·ì϶
˼¿Æ°ä²¼Nexus»¥»»»ú¼°NX-OSµÄ°²È«¸üУ¬£¬£¬£¬£¬£¬¹²½¨¸´5¸ö·ì϶£¬£¬£¬£¬£¬£¬Ô̺¬Nexus 9000ÖеÄShell Escape·ì϶ÒÔ¼°NX-OSÖеÄδÊÚȨ½Ó¼û¡¢»Ø¾ø·þÎñ¡¢ÊðÃûÑéÖ¤²»ÕýÈ·ºÍCLIºÅÁî×¢Èë·ì϶¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬Ë¼¿Æ»¹½¨¸´ÁËIP Phone 7800ºÍ8800ÖеĻؾø·þÎñ¼°´úÂëÖ´Ðзì϶£¨CVE-2019-1716£©¡¢´ÅÅ̺ľ¡·ì϶£¨CVE-2019-1766£©¡¢CSRF·ì϶£¨CVE-2019-1764£©ºÍõè¾¶±éÀú·ì϶£¨CVE-2019-1765£©¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/cisco-fixes-several-critical-bugs-patch-tuesday-week-3-march-2019-cb83776fÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ