Docker HubÔâÈëÇÖ£¬£¬£¬£¬£¬£¬19ÍòÕ˺ű»Ð¹Â¶£»£»£»£»£»£»£»¶ñÒâÈí¼þBabyShark£»£»£»£»£»£»£»MagecartÒÑϰȾ200¶à¸öµçÉÌÍøÕ¾
°ä²¼¹¦·ò 2019-04-28
4ÔÂ25ÈÕDocker HubÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬µ¼ÖÂÔ¼19ÍòÓû§ÕË»§µÄÃô¸ÐÐÅϢй¶¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬ÓÃÓÚ×Ô¶¯¹¹½¨Docker¾µÏñ¶øÊÚȨ¸øDocker HubµÄGitHubºÍBitbucket½Ó¼ûÁîÅÆ£¬£¬£¬£¬£¬£¬ÒÔ¼°Óû§ÃûºÍ¹þÏ£ÃÜÂë¡£¡£¡£¡£¡£Æ¾¾ÝDocker¹Ù·½µÄ˵·¨£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄÓû§Ô¼Õ¼×ÜÓû§ÊýÁ¿µÄ5%¡£¡£¡£¡£¡£Docker°µÊ¾ÔÚ·¢ÏÖÈëÇÖºóÁ¢¼´ÏòÓû§·¢ËÍÁËÓʼþ֪ͨ£¬£¬£¬£¬£¬£¬²¢²ÉÈ¡´ëÊ©±£»£»£»£»£»£»£»¤Óû§µÄÊý¾Ý¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/docker-hub-database-hack-exposes-sensitive-data-of-190k-users/2.iLnkP2PÒ×ÊÜÖÐÑëÈ˹¥»÷£¬£¬£¬£¬£¬£¬200¶àÍǫ̀ÔÚÏßÉ豸´æÔÚ·çÏÕ
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/84525/hacking/ilnkp2p-flaws-iot.html3.˼¿ÆTalosÅû¶Sierra Wireless AirLinkÍø¹ØÖеĶà¸ö·ì϶
˼¿ÆTalosÅû¶Sierra Wireless AirLinkϵÁеÄÍø¹ØºÍ·ÓÉÆ÷ÖеĶà¸ö°²È«·ì϶¡£¡£¡£¡£¡£ÕâЩÉ豸±»¿í·ºÓÃÓÚÆóÒµ»·¾³Öй¤ÒµÉ豸¡¢ÖÇÄÜÉ豸¡¢´«¸ÐÆ÷¡¢PoS¼°ICSµÄÏνӡ£¡£¡£¡£¡£·ì϶ÁìÓòÔ̺¬ËÁÒâ´úÂëÖ´ÐÓ×¢ÖÎÀíÔ±ÃÜÂë¸ü¸Ä¡¢ÏµÍ³ÉèÖÃÅú¸Ä¡¢Óû§Í´´¦Ð¹Â¶¡¢CSRF¡¢XSSµÈ¡£¡£¡£¡£¡£´óÎÞÊý·ì϶´æÔÚÓÚÉ豸¸½´øµÄWeb·þÎñÆ÷ACEManagerÖС£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/84533/security/sierra-wireless-airlink-es450-flaws.html4.¶ñÒâÈí¼þBabySharkµÄй¥»÷»î¶¯£¬£¬£¬£¬£¬£¬·Ö·¢KimJongRATºÍPCRat
Palo Alto NetworksµÄUnit 42ÍŶӰ䲼¹ØÓÚBabySharkжñÒâ¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£BabySharkÊÇ2Ô·ݳöÏֵĶñÒâÈí¼þ£¬£¬£¬£¬£¬£¬Æä¹¥»÷»î¶¯³ÖÐøµ½ÁË3ÔºÍ4Ô£¬£¬£¬£¬£¬£¬×îй¥»÷»î¶¯µÄÖ÷ÕÅËÆºõÓÐÁ½¸ö£ºÕë¶ÔºË°²È«ºÍ³¯Ïʰ뵺¹ú¶È°²È«ÎÊÌâµÄ¼äµý»î¶¯£»£»£»£»£»£»£»ÒÔ¼°Õë¶Ô¼ÓÃÜÇ®±ÒÐÐÒ·´»ñÈ¡½ðÇ®¡£¡£¡£¡£¡£BabySharkµÄ¶ñÒâpayloadÔ̺¬KimJongRATºÍPCRat£¬£¬£¬£¬£¬£¬µ«¹¥»÷ÕßÔÚ¶ñÒâ´úÂëÖн«ËüÃÇͳ³ÆÎªCowboy¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://unit42.paloaltonetworks.com/babyshark-malware-part-two-attacks-continue-using-kimjongrat-and-pcrat/5.¹¥»÷ÕßÀûÓÃAtlassian Confluence Server·ì϶·Ö·¢GandCrabºÍDofloo
Ç÷Ïò¿Æ¼¼×êÑÐÈËÔ±Augusto II Remillano·¢ÏÖ¹¥»÷ÕßÔÚ»ý¼«ÀûÓÃAtlassian Confluence ServerÖеķì϶£¨CVE-2019-3396£©À´·Ö·¢ÀÕË÷Èí¼þGandCrabºÍľÂíDofloo¡£¡£¡£¡£¡£Æ¾¾ÝNVD£¬£¬£¬£¬£¬£¬¸Ã·ì϶¿ÉÔÊÐíÔ¶³Ì¹¥»÷Õßͨ¹ýÄ£°å×¢ÈëʵÏÖõè¾¶±éÀúºÍÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£AtlassianÔÚ3ÔÂ20ÈÕ½¨¸´Á˸÷ì϶£¬£¬£¬£¬£¬£¬ÓÉÓÚ¶à¸öexploit¹«¿ª¿ÉÓ㬣¬£¬£¬£¬£¬¹¥»÷ÕßÔÚ»ý¼«É¨ÃèÒ×Êܹ¥»÷µÄ·þÎñÆ÷À´Ö´Ðй¥»÷¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/vulnerable-confluence-servers-get-infected-with-ransomware-trojans/6.MagecartÇÔÈ¡Óû§Ö§¸¶ÐÅÏ¢£¬£¬£¬£¬£¬£¬ÒÑϰȾ200¶à¸öµçÉÌÍøÕ¾
Magecart¹¥»÷ÊÇÖ¸½«¶ñÒâ¾ç±¾Ö²ÈëµçÉÌÍøÕ¾ÒÔÇÔÈ¡Óû§µÄÖ§¸¶ÐÅÏ¢£¬£¬£¬£¬£¬£¬ÆäÊܺ¦ÕßÔ̺¬Ó¢¹úº½¿Õ¡¢Ðµ°ºÍFeedifyµÈ¡£¡£¡£¡£¡£MalwareBytes×êÑÐÈËÔ±ÔÚGithubÉÏ·¢ÏÖÒ»¸ö¶ñÒâMagecart¾ç±¾£¬£¬£¬£¬£¬£¬¸Ã¾ç±¾ÓÚ4ÔÂ20ÈÕÉÏ´«£¬£¬£¬£¬£¬£¬Í¨¹ýËÑË÷ÒýÇæurlscan.ioºÍPublicWWWÄܹ»·¢ÏÖÖÁÉÙÓÐ200¶à¸öµçÉÌÍøÕ¾Êܵ½¸Ã¾ç±¾µÄϰȾ¡£¡£¡£¡£¡£ÔÚ½Óµ½»ã±¨ºó£¬£¬£¬£¬£¬£¬GitHubѸËÙɾ³ýÁ˶ñÒâ¾ç±¾£¬£¬£¬£¬£¬£¬µ«ÊÜËðµÄÍøÕ¾ÈÔÃæ¶Ô±»ÈëÇֵķçÏÕ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/84564/cyber-crime/magecart-skimmer-github.html


¾©¹«Íø°²±¸11010802024551ºÅ