WordPress XSSºÍRCE·ì϶£»£»£»£»£»£»£»£»OilRig APT·Ö·¢KarkoffºÍDNSpionage£»£»£»£»£»£»£»£»QbotľÂíбäÖÖ
°ä²¼¹¦·ò 2019-04-25
WordPress²å¼þSocial Warfare°ä²¼Ð°汾3.5.3£¬£¬£¬£¬£¬£¬£¬½¨¸´Ò»¸ö´æ´¢ÐÍXSSºÍRCE·ì϶£¨CVE-2019-9978£©£¬£¬£¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì¸üС£¡£¡£¡£¡£¡£¡£Social WarfareÊÇÒ»¸öÊ¢ÐеIJå¼þ£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚÏòWordPressÍøÕ¾»ò²©¿ÍÔö³¤Éç½»·ÖÏí°´Å¥£¬£¬£¬£¬£¬£¬£¬ÆäÏÂÔØÁ¿³¬¹ý90Íò´Î¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚPoCÒѾй¶£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÒÑÔÚÒ°±í»ý¼«ÀûÓø÷ì϶½øÐжñÒâÍÚ¿ó»î¶¯»òÍйܶñÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/04/wordpress-plugin-hacking.html
2¡¢Chrome°ä²¼Ð°汾v74£¬£¬£¬£¬£¬£¬£¬¹²½¨¸´39¸ö°²È«·ì϶
Chrome°ä²¼Ð°汾v74.0.3729.108£¬£¬£¬£¬£¬£¬£¬Ôö³¤ÁËÐÂÖ°Äܲ¢½¨¸´ÁË39¸ö°²È«·ì϶¡£¡£¡£¡£¡£¡£¡£´Ë¿ÌChrome 74ÊDz»±ä°æ£¬£¬£¬£¬£¬£¬£¬Chrome 75ºÍ76Ôò±ðÀëÊÇBetaºÍCanary°æ±¾¡£¡£¡£¡£¡£¡£¡£Õâ39¸ö·ì϶ÖÐûÓÐCritical¼¶´ËÍâ·ì϶£¬£¬£¬£¬£¬£¬£¬µ«ÓÐÎå¸ö¸ßΣ·ì϶£¬£¬£¬£¬£¬£¬£¬Ô̺¬use-after-free·ì϶£¨CVE-2019-5805¡¢CVE-2019-5808ºÍCVE-2019-5809£©¡¢ÕûÊýÒç¶Âí½Å£¨CVE-2019-5806£©ÒÔ¼°ÄÚ´æ°Ü»µ·ì϶£¨CVE-2019-5807£©¡£¡£¡£¡£¡£¡£¡£ÆëÈ«µÄÖ°Äܵ÷»»ºÍ·ì϶½¨¸´Áбí¿ÉÔÚÒÔÏÂÁ´½ÓÖÐÕÒµ½¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/google/chrome-74-released-with-39-security-fixes-and-new-features/
3¡¢Google PlayϼÜ50¸ö¶ñÒâÀûÓ㬣¬£¬£¬£¬£¬£¬×°ÖÃÁ¿´ï3000Íò´Î
Avast×êÑÐÍŶÓÔÚGoogle PlayÖз¢ÏÖ50¸ö¶ñÒâÀûÓ㬣¬£¬£¬£¬£¬£¬ÕâЩÀûÓõÄ×ÜÏÂÔØ´ÎÊý´ï3000Íò´Î¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝAvastµÄ»ã±¨£¬£¬£¬£¬£¬£¬£¬ÕâЩÀûÓÃͨ¹ýµÚÈý·½¿â»¥ÓйØÁª£¬£¬£¬£¬£¬£¬£¬¿ÉÈÆ¹ýAndroidµÄºó¶Ü·þÎñÏ޶Ȳ»ÐÝÏòÓû§ÏÔʾԽÀ´Ô½¶àµÄ¸æ°×£¬£¬£¬£¬£¬£¬£¬ÔÚijЩÇé¿öÏÂÉõÖÁÓÕʹÓû§×°ÖÃÆäËü¸æ°×Èí¼þ¡£¡£¡£¡£¡£¡£¡£ÕâЩ¶ñÒâÀûÓõÄÃû³ÆÔ̺¬Pro Piczoo¡¢Photo Blur Studio¡¢Mov-tracker¡¢Magic Cut OutºÍPro Photo EraserµÈ£¬£¬£¬£¬£¬£¬£¬ÏÂÔØÁ¿´Ó100Íòµ½1000´Î²»µÈ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/30-million-android-users-have-installed-malicious-lifestyle-apps/
4¡¢OilRig APTÔÚй¥»÷»î¶¯Öзַ¢KarkoffºÍDNSpionage
ƾ¾Ý˼¿ÆTalosµÄ·ÖÎö»ã±¨£¬£¬£¬£¬£¬£¬£¬ÒÁÀÊAPT×éÖ¯OilRigÔÚ×î½ü£¨4Ô·ݣ©µÄ¹¥»÷»î¶¯ÖÐʹÓÃÁËжñÒâÈí¼þKarkoffºÍDNSpionage¡£¡£¡£¡£¡£¡£¡£ÕâЩ¹¥»÷»î¶¯ÖØÒªÕë¶ÔÖж«µØÓò£¬£¬£¬£¬£¬£¬£¬Ô̺¬Àè°ÍÄۺͰ¢ÁªÇõ¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÔÚʹÓÃеÄÕ½Êõ¡¢¼¼ÊõºÍ·¨Ê½À´Ìá¸ßÆä¹¥»÷ЧÄÜ¡£¡£¡£¡£¡£¡£¡£KarkoffÊÇ.NET¿ª·¢µÄжñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬ÖØÒªÓÃÓÚ¿úËŻ£¬£¬£¬£¬£¬£¬£¬¿ÉÍøÂçÖ¸±êµÄ¹¤×÷Õ¾»·¾³¡¢OS¡¢Óò¡¢¹ý³ÌÁбíµÈÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÉõÖÁÄܹ»Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£DNSpionageÔòÊÇÒ»¸ö¶¨ÔìµÄRAT£¬£¬£¬£¬£¬£¬£¬ÖØÒªÊ¹ÓÃHTTPºÍDNSͨѶÀ´ÏνÓC£¦C·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/84418/malware/oilrig-apt-karkoff-dnspionage.html
5¡¢QbotľÂíбäÖÖ£¬£¬£¬£¬£¬£¬£¬ÒÑϰȾȫÇò2726ÃûÓû§
Varonis Security ResearchÔÚ3Ô·ݷ¢ÏÖÁËQbotľÂíµÄÐÂÒ»²¨È«Çò¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬£¬Æ¾¾Ý¶ÔÆäÖÐÒ»¸ö¹¥»÷·þÎñÆ÷µÄ·ÖÎö£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±ÒѾȷÈÏÁË2726ÃûÊܺ¦Õߣ¬£¬£¬£¬£¬£¬£¬µ«ÏÖʵÊܺ¦ÈËÊý¿ÉÄܸü¸ß¡£¡£¡£¡£¡£¡£¡£QbotÒÔÆä¶à̬ÐÐΪ¼°ÀàËÆÈ䳿µÄ¸öÐÔ¶øÎÅÃû£¬£¬£¬£¬£¬£¬£¬ÕâÒ»´ÎQBotͨ¹ý´¹µöÓʼþ½øÐд«²¼£¬£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔÃÀ¹ú¡¢Å·ÖÞ¡¢ÑÇÖÞºÍÄÏÃÀÖÞµÄÆóÒµ£¬£¬£¬£¬£¬£¬£¬ÆäÖ÷ÕÅÊÇÇÔÈ¡ÒøÐÐÆ¾Ö¤µÈ²ÆÕþÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://threatpost.com/qbot_new_campaign/144070/
6¡¢ÑÇÌØÀ¼´óÀÏÓ¥¶ÓµÄÔÚÏßÉ̵êÔâµ½Magecart¹¥»÷
ÑÇÌØÀ¼´óÀÏÓ¥¶ÓµÄÔÚÏßÉ̵ê³ÉΪMagecart¹¥»÷µÄ×îÐÂÊܺ¦Õߣ¬£¬£¬£¬£¬£¬£¬Æ¾¾ÝSanguine SecurityµÄ»ã±¨£¬£¬£¬£¬£¬£¬£¬¸ÃÉ̵êµÄ¸¶¿îÒ³ÃæÏ°È¾ÁËMagecart¶ñÒâ´úÂ룬£¬£¬£¬£¬£¬£¬µ¼ÖÂÓû§µÄÐÕÃû¡¢µØÖ·ºÍÐÅÓþ¿¨¾ßÌåÐÅÏ¢±»ÇÔ¡£¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñÓ°ÏìÁË4ÔÂ20ÈÕÖ®ºóÔÚÉ̵깺ÎïµÄÓû§£¬£¬£¬£¬£¬£¬£¬µ«Éв»Ã÷ÏÔÊÜÓ°ÏìÓû§µÄ¾ßÌåÊýÁ¿¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÒÔΪ¸Ã¹¥»÷»òÓëMagentoµÚÈý·½×é¼þµÄʹÓÃÓйء£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://labs.sansec.io/2019/04/24/atlanta-hawks-magecart/


¾©¹«Íø°²±¸11010802024551ºÅ