ºÚ¿ÍÀûÓÃSalesforceÕÊ»§·¢ËÍÐéα·¢Æ±½øÐд¹µö£»£»£»£»£»£»£»£»ÀÕË÷Èí¼þNemtyбäÖÖͨ¹ýÐéαPayPalÍøÕ¾´«²¼
°ä²¼¹¦·ò 2019-09-091.ÐÂÎ÷À¼µÚ¶þ¼¾¶ÈÒòÍøÂç¹¥»÷µ¼ÖÂ650ÍòÃÀÔª¾¼ÃËðʧ
ÐÂÎ÷À¼È«¹úÍÆËã»úÓ¦¼±ÏìÓ¦Ó××飨CERT NZ£©°ä²¼2019ÄêµÚ¶þ¼¾¶ÈÍøÂçÊÂÎñ»ã±¨£¬£¬£¬£¬£¬£¬£¬£¬»ã±¨ÏÔʾQ2ÍøÂç¹¥»÷Ôì³ÉµÄ¾¼ÃËðʧ´ï650ÍòÃÀÔª£¬£¬£¬£¬£¬£¬£¬£¬ÊÇÆù½ñΪֹ»ã±¨µÄ×î¸ß½ð¶î¡£¡£¡£¡£¡£¡£¡£¡£µÚ¶þ¼¾¶È¹²»ã±¨ÁË1197Æð°²È«ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬£¬±ÈµÚÒ»¼¾¶ÈÔö³¤ÁË21%¡£¡£¡£¡£¡£¡£¡£¡£ÔÚËùÓÐÊÂÎñÖУ¬£¬£¬£¬£¬£¬£¬£¬ÓÐ23%Éæ¼°µ½Ä³ÖÖÀàÐ͵ľ¼ÃËðʧ¡£¡£¡£¡£¡£¡£¡£¡£Ú¿ÆÓëÚ²ÆÊÂÎñÔÚµÚ¶þ¼¾¶ÈÕ¼±È×î¸ß£¬£¬£¬£¬£¬£¬£¬£¬´ï38%¡£¡£¡£¡£¡£¡£¡£¡£ÀÕË÷Èí¼þÊÂÎñ±ÈÉÏÒ»¼¾¶ÈÔö³¤ÁË38%£¬£¬£¬£¬£¬£¬£¬£¬´óÎÞÊýÊÂÎñ»ã±¨À´×ÔÓÚÆóÒµºÍ×éÖ¯¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/scams-and-ransomware-cost-kiwis/
2.ºÚ¿ÍÀûÓÃSalesforceÕÊ»§·¢ËÍÐéα·¢Æ±½øÐд¹µö
Avanan×êÑÐÈËÔ±·¢ÏÖÒ»¸öеÄÍøÂç´¹µö¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓÃSalesforceµÄ·¢Æ±·¢ËÍÖ°ÄܶÔ×¼Ò»¸öÈ«Çò²Æ¸»500Ç¿ÆóÒµ¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÀûÓÃÖ¸±êÆóÒµ¹©¸øÉ̵ÄSalesforceÕÊ»§Ïò¿Í»§·¢ËÍ´øÓÐÐéα·¢Æ±µÄ´¹µöÓʼþ£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚÕâЩÐéα·¢Æ±¸´ÔìÁ˺Ϸ¨·¢Æ±µÄģʽ£¬£¬£¬£¬£¬£¬£¬£¬Òò¶øOffice 365µÄ°²È«·À»¤Ö°ÄÜÏÕЩÎÞ·¨×·×ÙËüÃÇ¡£¡£¡£¡£¡£¡£¡£¡£SalesforceÔÆÆ½Ì¨Òѱ»È«Çò³¬¹ý15Íò¼ÒÆóҵʹÓ㬣¬£¬£¬£¬£¬£¬£¬Òò¶ø¿Í»§ºÜÈÝÒ×ÐÅÀµÒԸù«Ë¾ÓòÃû½áβµÄ·¢¼þÈËÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£ÔÚ¸ÃÆð°¸ÀýÖУ¬£¬£¬£¬£¬£¬£¬£¬Ö¸±êÆóÒµÔ¼ÓÐ1056ÈËÊÕµ½ÁË´¹µöÓʼþ£¬£¬£¬£¬£¬£¬£¬£¬ÕâÊǸù«Ë¾µÄËùÓÐÁªÏµÈË¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßµÄÖØÒªÖ÷ÕÅÊÇÔÚÆóÒµÖÕ¶ËÉÏ×°ÖÃľÂí£¬£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±ÒÔΪÕâÖÖ¹¥»÷ͬÑùºÏÓÃÓÚ·¢Æ±Ú²ÆºÍÍ´´¦ÇÔÈ¡¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.avanan.com/resources/salesforce-phishing-attack
3.ÀÕË÷Èí¼þNemtyбäÖÖͨ¹ýÐéαPayPalÍøÕ¾´«²¼
°²È«×êÑÐÔ±nao_sec·¢ÏÖÀÕË÷Èí¼þNemtyµÄбäÖÖͨ¹ýÐéαµÄPayPalÍøÕ¾½øÐд«²¼¡£¡£¡£¡£¡£¡£¡£¡£³ý´ËÖ®±í£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÀÕË÷Èí¼þ×î½ü»¹±»¹Û²ìµ½Í¨¹ýRIG EK·Ö·¢£¬£¬£¬£¬£¬£¬£¬£¬ÕâÒâζ×ÅNemty¹¥»÷ÕßÔÚ»ý¼«³¢ÊÔ¸÷Àà·ÖÆçµÄ·Ö·¢Çþ·¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÐéαPayPalÍøÕ¾Ä£ÄâÁËÕæÊµÒ³ÃæµÄÊÓ¾õ³ÉЧºÍ½á¹¹£¬£¬£¬£¬£¬£¬£¬£¬»¹ÔÚÍøÕ¾¸÷¸ö²¿ÃŵÄÁ´½ÓÖÐʹÓÃÁËͬÐÎÒìÒåÓòÃûºýŪ¹¥»÷£¨Ô̺¬Ô®ÊÖ¡¢ÁªÏµÈË¡¢Óöȡ¢°²È«¡¢ÀûÓúÍÉ̵꣩¡£¡£¡£¡£¡£¡£¡£¡£Ö÷Á÷ä¯ÀÀÆ÷½«¸ÃÍøÕ¾ÏóÕ÷ΪΣÏÕ£¬£¬£¬£¬£¬£¬£¬£¬µ«ÈÔÓÐЧ»§¿ÉÄÜ»áÈÆ¹ýÌáÐѳÖÐøÏÂÔØºÍÔËÐжñÒâÈí¼þ£¨cashback.exe£©¡£¡£¡£¡£¡£¡£¡£¡£°²È«×êÑÐÔ±Vitali Kremez·ÖÎöÁËNemtyµÄÕâÒ»±äÖÖ£¬£¬£¬£¬£¬£¬£¬£¬·¢ÏÔìäΪ°æ±¾1.4²¢ÇÒ´øÓÐһЩbug½¨¸´¡£¡£¡£¡£¡£¡£¡£¡£´óÎÞÊý°²È«²úÆ·Äܹ»¼ì²âµ½¸Ã±äÖÖ£¬£¬£¬£¬£¬£¬£¬£¬VirusTotalÉÏ68¸ö·À²¡¶¾ÒýÇæÖÐÓÐ36¸öÄܹ»¼ì²âµ½Ëü¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/fake-paypal-site-spreads-nemty-ransomware/
4.MeridianÉçÇøÑ§ÔºÅû¶1Ô·ÝÓû§ÒþÖÔй¶ÊÂÎñ
ÃÜÎ÷Î÷±ÈÖÝMeridianÉçÇøÑ§Ôº£¨MCC£©Åû¶1Ô·ÝÔâ·êµÄÓû§ÒþÖÔй¶ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£¡£ÔÚ1ÔÂÏÂÑ®MCCÔâ·êÍøÂç´¹µöÊÂÎñµ¼Ö²¿ÃÅÓû§µÄÍ´´¦Ô⵽й¶£¬£¬£¬£¬£¬£¬£¬£¬MCCÆðÍ·ÓëµÚÈý·½È¡Ö¤¹«Ë¾ºÏ×÷½øÐе÷²é¡£¡£¡£¡£¡£¡£¡£¡£4ÔÂ12ÈÕµ÷²éÈËÔ±²»ÄÜÈ·Èϲ¿ÃÅÔ±¹¤µÄÓÊÏäÕË»§ÊÇ·ñÔâδÊÚȨ½Ó¼û£¬£¬£¬£¬£¬£¬£¬£¬MCCÆðÍ·ÊÖ¶¯Éó¼ÆÕâЩÕË»§µÄÓʼþºÍ¸½¼þÖеÄÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£ÉóºËÓÚ6ÔÂ25ÈÕʵÏÖ£¬£¬£¬£¬£¬£¬£¬£¬¶øºóMCCÆðÍ·×·×ÙÊÜÓ°ÏìÓû§µÄÁªÏµ·½Ê½¡£¡£¡£¡£¡£¡£¡£¡£9ÔÂ5ÈÕMCC°ä²¼ÐÂΟåÅû¶ÁËÕâÒ»ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿ÉÄÜй¶µÄÓû§ÐÅÏ¢Ô̺¬ÐÕÃû¡¢Éç»á°²È«ºÅÂë¡¢¼ÝÕÕºÅÂë¡¢»¤ÕÕºÅÂë¡¢µ®ÉúÈÕÆÚ¡¢Óû§Ãû»òÓÊÏäÕË»§Ãû¼°ÃÜÂë¡¢Ò½ÁÆÐÅÏ¢¼°±£ÏÕÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://finance.yahoo.com/news/meridian-community-college-provides-notice-000000176.html
5.Monster.comÒòµÚÈý·½»ú¹¹µ¼ÖÂÇóÖ°ÕßÐÅϢй¶
×êÑÐÈËÔ±·¢ÏÖÒ»¸ö¿É¹«¿ª½Ó¼ûµÄWeb·þÎñÆ÷й¶ÁËMonster.comÓû§µÄÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩÐÅÏ¢Ô̺¬2014ÖÁ2017ÄêÆÚ¼äʹÓùý¸ÃÍøÕ¾µÄÇóÖ°ÕßÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬Èçµç»°ºÅÂë¡¢¼Òͥסַ¡¢µç×ÓÓʼþµØÖ·ºÍ¹¤×÷¾ÑéµÈ£¬£¬£¬£¬£¬£¬£¬£¬µ«²»Ô̺¬ÈκβÆÕþÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£Monster°µÊ¾Ð¹Â¶²úÉúÔÚµÚÈý·½»ú¹¹µÄ·þÎñÆ÷ÉÏ£¬£¬£¬£¬£¬£¬£¬£¬Òò¶ø¸Ã¹«Ë¾ÎÞ·¨Í¨ÖªÓû§¡£¡£¡£¡£¡£¡£¡£¡£¸ÃµÚÈý·½»ú¹¹µÄÃû³ÆÎ´Öª£¬£¬£¬£¬£¬£¬£¬£¬Monster³Æ²»ÔÙÓëÖ®·¢Õ¹ÒµÎñ¡£¡£¡£¡£¡£¡£¡£¡£µÚÈý·½»ú¹¹Ò²Ã»ÓÐ֪ͨÓйØÊܺ¦Õߣ¬£¬£¬£¬£¬£¬£¬£¬µ«Æ¾¾ÝMonsterµÄ˵·¨£¬£¬£¬£¬£¬£¬£¬£¬·þÎñÆ÷ÔÚ½Óµ½Í¨ÖªºóÒѾµÃµ½Á˱£»£»£»£»£»£»£»£»¤¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.darkreading.com/cloud/job-seeker-data-exposed-in-monster-file-leak/d/d-id/1335753
6.˼¿ÆTalosÅû¶Blynk-LibraryÖеÄÐÅϢй¶·ì϶
˼¿ÆTalosÔÚBlynk-LibraryÖз¢ÏÖÒ»¸öÐÅϢй¶·ì϶¡£¡£¡£¡£¡£¡£¡£¡£Blynk-LibraryÊÇÒ»¸öÓ×ÐͿ⣬£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚ½«400¶àÖÖ·ÖÆçµÄǶÈëʽÉ豸Ïνӵ½Ë½ÓлòÆóÒµBlynk-ServerÊ·ý¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶£¨TALOS-2019-0854/CVE-2019-5065£©ÓëBlynk-LibraryµÄÊý¾Ý°ü½âÎöÖ°ÄÜÓйأ¬£¬£¬£¬£¬£¬£¬£¬²»°²È«µÄstrncpyʹÓÃʹµÃ¹¥»÷Õß¿Éͨ¹ý·¢ËͶñÒâÊý¾Ý°ü´¥·¢ÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£¡£TalosÈ·ÈÏBlynk-LibraryµÄ0.6.1°æ±¾ÊÜ´Ë·ì϶ӰÏì¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2019/09/vulnerability-spotlight-information.html


¾©¹«Íø°²±¸11010802024551ºÅ