ĦÂå¸çµ±¾ÖÓÃNSO Group¼äµýÈí¼þ¼à¶½¸Ã¹ú¼ÇÕß;ºÚ¿ÍÓÃGoogle AnalyticsÈÆ¹ýCSPÇÔÊØÐÅÓþ¿¨ÐÅÏ¢

°ä²¼¹¦·ò 2020-06-24

1.ĦÂå¸çµ±¾Ö»òÔÚÀûÓÃNSO GroupµÄ¼äµýÈí¼þ¼à¶½¸Ã¹ú¼ÇÕß


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¹ú¼ÊÌØÉâ×éÖ¯°µÊ¾£¬£¬£¬ £¬ £¬Æä°²È«ÍŶÓÔÚĦÂå¸ç¼ÇÕßµÄÊÖ»úÉÏ·¢ÏÖÁËNSO Group¿ª·¢µÄ¼äµýÈí¼þ£¬£¬£¬ £¬ £¬´ËÊ»òÓë¸Ã¹úµ±¾ÖÓйء£¡£¡£¡£¡£¡£¡£¡£Ä¦Âå¸ç¼ÇÕßOmar RadiÔâµ½¼à¶½Èí¼þµÄ¹¥»÷£¬£¬£¬ £¬ £¬¸ÃÈí¼þ¿ÉÄܸú×ÙÎı¾¡¢µç»°¡¢µç×ÓÓʼþ¡¢ÉãÏñ»úµÈ¡£¡£¡£¡£¡£¡£¡£¡£ºÚ¿Íͨ¹ýÍøÂç×¢Èë¹¥»÷ÒÔÀ¹½ØºÍ²Ù¼«Ö¸±êµÄ»¥ÁªÍøÁ÷Á¿£¬£¬£¬ £¬ £¬¸Ã²½Öè²»±ØÒªÓëÊܺ¦Õß½»»¥£¬£¬£¬ £¬ £¬Ö»Ð轫ָ±êä¯ÀÀÆ÷³ÁзÓɵ½Ò»¸ö¶ñÒâÍøÕ¾¡£¡£¡£¡£¡£¡£¡£¡£¹ú¼ÊÌØÉâ×éÖ¯°µÊ¾£¬£¬£¬ £¬ £¬¹¥»÷ÕßÉí·ÝËäδµÃµ½È·ÈÏ£¬£¬£¬ £¬ £¬µ«¸÷ÖÖÖ¤¾ÝÅú×¢¼à¶½ÕßΪĦÂå¸çµ±¾Ö£¬£¬£¬ £¬ £¬ÓÉÓÚNSO¼¯ÍÅÒ»ÔÙ°µÊ¾¸ÃÈí¼þ½ö±»ÏúÊÛ¸øÁ˵±¾Ö¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.cyberscoop.com/nso-group-spyware-amnesty-international-omar-radi-morocco/


2.ºÚ¿ÍʹÓÃGoogle AnalyticsÆ½Ì¨ÈÆ¹ýCSPÇÔÊØÐÅÓþ¿¨ÐÅÏ¢


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ºÚ¿ÍÔÚʹÓÃGoogle AnalyticsÆ½Ì¨ÈÆ¹ýÄÚÈݰ²È«Õþ²ß£¨CSP£©£¬£¬£¬ £¬ £¬À´ÇÔÈ¡ÔÚÏßÉ̵êÓû§Ìá½»µÄÐÅÓþ¿¨ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£ÍøÂ簲ȫ¹«Ë¾SansecºÍPerimeterXµÄ×îÐÂ×êÑÐÅú×¢£¬£¬£¬ £¬ £¬ÔÚ²¿ÊðÁËGoogle AnalyticsµÄÍøÕ¾ÉÏ£¬£¬£¬ £¬ £¬Ê¹ÓÃCSPÔ¤·ÀÐÅÓþ¿¨ÇÔÈ¡¹¥»÷ÒѾ­ºÁÎÞÒâ˼¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚCSPÖ÷ÌâÖ°ÄÜÖдæÔÚ·ì϶£¬£¬£¬ £¬ £¬Ëü²»ÄÜ×èÖ¹»ùÓÚ×¢ÈëµÄ¹¥»÷£¬£¬£¬ £¬ £¬Òò¶øºÚ¿ÍÄܹ»Í¨¹ýÒ»¸öweb skimmer½ÅÕý±¾ÇÔÈ¡Êý¾Ý²¢½«ÆäÒÔ¼ÓÃܵĴó¾Ö·¢Ëͻع¥»÷Õß¡£¡£¡£¡£¡£¡£¡£¡£SansecµÄÍþв×êÑÐÓ××éй©£¬£¬£¬ £¬ £¬¹¥»÷ÕßÀûÓÃGoogle AnalyticsÒѾ­³É¹¦ÈƹýÊýÊ®¸öµç×ÓÉÌÎñÍøÕ¾ÉϵÄCSP¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hackers-use-google-analytics-to-steal-credit-cards-bypass-csp/


3.ºÚ¿ÍÔÚ°µÍøÏúÊÛÊ¢ÐÐÓÎÏ·StalkerÖг¬¹ý130ÍòÍæ¼ÒÐÅÏ¢


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


°²È«×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬ £¬ £¬ºÚ¿ÍÔÚ°µÍøÏúÊÛÁËÊ¢ÐÐÓÎÏ·StalkerÖг¬¹ý130ÍòÍæ¼ÒÐÅÏ¢£¬£¬£¬ £¬ £¬Ð¹Â¶ÐÅÏ¢Ô̺¬Óû§Ãû¡¢ÃÜÂë¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂëºÍIPµØÖ·¡£¡£¡£¡£¡£¡£¡£¡£Õâ´ÎÏúÊ۵Ĺ²ÓÐÁ½¸öÊý¾Ý¿â£¬£¬£¬ £¬ £¬±ðÀëΪ120Íò±Ê¼Í¼ºÍ136000±Ê¼Í¼¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾°µÊ¾£¬£¬£¬ £¬ £¬Óû§µÄÃÜÂëÊǾ­¹ýMD5¼ÓÃܺͼÓÑδ¦ÖõÄ£¬£¬£¬ £¬ £¬Õâ¹ÌÈ»Êǰ²È«ÐԽϵ͵ÄËã·¨µ«±ÈÒÔ´¿Îı¾´ó¾Ö±£ÁôÃÜÂë¸üºÃ¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬ £¬ £¬¸Ã¹«Ë¾ÒÑÓëºÚ¿ÍÔÚÏßÉ̵êµÄµç×ÓÉÌÎñƽ̨ÁªÏµ£¬£¬£¬ £¬ £¬´Ë¿ÌÒÑÍÑ»ú¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/stalker-online-breach-13-m-user/


4.°ÄÖÞACCC°ä²¼»ã±¨£¬£¬£¬ £¬ £¬¸Ã¹úÈ¥ÄêÓг¬¹ý2.5ÍòÆð´¹µö¹¥»÷ÊÂÎñ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


°Ä´óÀûÑÇACCCÏÂÊôµÄScamwatch°ä²¼ÁËScamwatch Targeting scams£º×Ô2009ÄêÒÔÀ´¶Ôڲƭ»î¶¯µÄ»ØÊ׻㱨£¬£¬£¬ £¬ £¬Í³¼Æ2019Äê¸Ã¹ú²úÉúÁ˳¬¹ý2.5ÍòÆð´¹µö¹¥»÷ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£¡£ÔÚ2019Ä꣬£¬£¬ £¬ £¬ÍøÂç´¹µöÊÇ×î³£¼ûµÄڲƭ¼¿Á©£¬£¬£¬ £¬ £¬×ܹ²»ã±¨ÁËÓÐ25168ÆðÊÂÎñ£¬£¬£¬ £¬ £¬ÔÚËù»ã±¨ÖÐÓÐ513ÆðÔì³ÉÁ˲ÆÕþËðʧ£¬£¬£¬ £¬ £¬×ܼÆ150Íò°ÄÔª¡£¡£¡£¡£¡£¡£¡£¡£¶øÔì³ÉËðʧ×î´óµÄ¹¥»÷ÀàÐÍΪÆóÒµµç×ÓÓʼþй¶£¨BEC£©Ú¿Æ­£¬£¬£¬ £¬ £¬Ëðʧ1.32ÒÚ°ÄÔª£¬£¬£¬ £¬ £¬Æä´ÎΪÔì³ÉÁË1.26ÒÚ°ÄÔªËðʧµÄͶ×ÊÚ¿Æ­ºÍ8300Íò°ÄÔªµÄÔ¼»áÚ¿Æ­¡£¡£¡£¡£¡£¡£¡£¡£¶øÚ¿Æ­µÄÖØÒªõè¾¶ÒÀȻΪµç»°£¨69522Æð£©£¬£¬£¬ £¬ £¬Æä´ÎÊǵç×ÓÓʼþ£¨40277Æð£©£¬£¬£¬ £¬ £¬¶ÌÐÅ£¨27894Æð£©ºÍ»¥ÁªÍø£¨11776Æð£©¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/australians-reported-25000-phishing-scams-to-the-accc-last-year/


5.Apache Dubbo·´ÐòÁл¯Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-1948£©


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

2020Äê6ÔÂ23ÈÕApache¹Ù·½°ä²¼¹«¸æ£¬£¬£¬ £¬ £¬½¨¸´ÁËÒ»¸öApache DubboÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-1948£©¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ԴÓÚApache Dubbo Provider´æÔÚ·´ÐòÁл¯·ì϶£¬£¬£¬ £¬ £¬¹¥»÷ÕßÄܹ»·¢ËÍ´øÓÐÎÞ·¨Ê¶´ËÍâ·þÎñÃû»ò²½ÖèÃû¼°Ä³Ð©¶ñÒâ²ÎÊý¸ºÔصÄRPCÒªÇ󣬣¬£¬ £¬ £¬µ±¶ñÒâ²ÎÊý±»·´ÐòÁл¯Ê±½«µ¼Ö¶ñÒâ´úÂëÖ´ÐÓ×£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ӰÏìÁËËùÓÐʹÓÃ2.7.6»ò¸üµÍ°æ±¾µÄDubboÓû§¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://github.com/apache/dubbo/releases/tag/dubbo-2.7.7


6.ÀÕË÷Èí¼þREvilɨÃèÊܺ¦ÕßϵͳÖеÄPoSÒÔѰеĻñÀû·½Ê½


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


SymantecÍþвµý±¨ÍŶӵÄ×êÑÐÈËÔ±·¢ÏÖºÚ¿ÍÔÚеÄÀÕË÷»î¶¯ÖÐʹÓÃREvilɨÃèÊܺ¦ÕßϵͳÖеÄÐÅÓþ¿¨»òPoint of Sale£¨PoS£©Êý¾Ý£¬£¬£¬ £¬ £¬»òÔÚѰÕÒеĻñÀû·½Ê½¡£¡£¡£¡£¡£¡£¡£¡£µý±¨·ÖÎöʦJon DiMaggio°µÊ¾£¬£¬£¬ £¬ £¬ÈôÊÇËûÃÇɨÃèµ½ÁËPoSϵͳ£¬£¬£¬ £¬ £¬±ãÄܹ»×°ÖÃPOS¶ñÒâɨÃèÈí¼þÇÔÊØÐÅÓþ¿¨¾ßÌåÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£Symantec·ÖÎö·£¬£¬£¬ £¬ £¬²¿ÃÅÊܺ¦¹«Ë¾¹æÄ£½ÏÓ×£¬£¬£¬ £¬ £¬ÎÞ·¨Ö§¸¶Êê½ð£¬£¬£¬ £¬ £¬Òò¶ø¸ÃºÚ¿ÍÍÅ»ïɨÃèPoSϵͳÖеÄÐÅÓþ¿¨Êý¾Ý¿ÉÄÜÊÇΪÁËÊý¾Ý͵ÇÔ£¬£¬£¬ £¬ £¬»òÖ»ÊÇΪÁËʹ¼ÓÃܵÄÊý¾Ý¸üÓмÛÖµÒÔÒªÇóÊܺ¦ÕßÖ§¸¶Êê½ð¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/revil-ransomware-scans-victims-network-for-point-of-sale-systems/