SignalµÈ̸ÌìÀûÓÃÖдæÔڿɼලÓû§µÄÂß¼·ì϶£»£»£»£»£»£»£»£»×êÑÐÍŶӷ¢ÏÖFreakOutÀûÓöà¸öзì϶µÄ¹¥»÷»î¶¯
°ä²¼¹¦·ò 2021-01-21
°²È«¹«Ë¾Malwarebytes³ÆSolarWinds±³ºóµÄºÚ¿ÍÒÑÈëÇÔìäÓʼþϵͳ¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ö¸³ö£¬£¬£¬£¬£¬£¬£¬¹ÌÈ»ÆäûÓÐʹÓÃSolarWinds£¬£¬£¬£¬£¬£¬£¬µ«ÓëÆäËû¹«Ë¾Ò»ÑùÔâµ½ÁËSolarWinds¹©¸øÁ´¹¥»÷¡£¡£¡£¡£¡£¹¥»÷²úÉúÔÚÈ¥Ä꣬£¬£¬£¬£¬£¬£¬ºÚ¿ÍÀûÓÃAzure Active DirectoryÖеķì϶ºÍ¶ñÒâOffice 365ÀûÓ÷¨Ê½£¬£¬£¬£¬£¬£¬£¬¶Ô¹«Ë¾²¿ÃÅϵͳÌáÒéÁ˹¥»÷¡£¡£¡£¡£¡£¾¹ýµ÷²é£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾È·¶¨¹¥»÷Õß½ö»ñµÃÁ˲¿ÃÅÄÚ²¿ÓʼþµÄ½Ó¼ûȨ£¬£¬£¬£¬£¬£¬£¬ÆäÄÚ²¿³ö²ú»·¾³²¢Î´Êܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬Ä¿Ç°ÈԿɰ²È«Ê¹ÓÃMalwarebytesÈí¼þ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/113628/hacking/malwarebytes-solarwinds-attack.html
2.SignalµÈ̸ÌìÀûÓÃÖдæÔڿɼලÓû§µÄÂß¼·ì϶

Google Project ZeroÅû¶ÁËSignalµÈ̸ÌìÀûÓÃÖдæÔڿɼලÓû§µÄÂß¼·ì϶¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÔÚSignal¡¢Google Duo¡¢Facebook Messenger¡¢JioChatºÍMochaÖз¢Ïָ÷ì϶£¬£¬£¬£¬£¬£¬£¬¿É±»ÓÃÀ´¼àÌý¶ÔÃæÓû§µÄÖÜΧ»·¾³¡£¡£¡£¡£¡£¸Ã·ì϶ΪFaceTimeŲÓÃ״̬»úÖеÄÂß¼ÃýÎ󣬣¬£¬£¬£¬£¬£¬Äܹ»Ç¿ÔìÖ¸±êÉ豸´«ÊäÒôƵ»òÊÓÆµÊý¾Ý¶øÎÞÐè½»»¥¡£¡£¡£¡£¡£×êÑÐÈËÔ±ºó·ÖÎöÁË7¿îÀûÓ㬣¬£¬£¬£¬£¬£¬·¢ÏÔìäÖÐ5¿î¾ùÓиÃÎÊÌâ¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶Òѱ»½¨¸´¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/bugs-in-signal-facebook-google-chat-apps-let-attackers-spy-on-users/
3.ALTDOS³ÆÆäÒÑÇÔÈ¡Êý°ÙGB BEXIMCOµÄÔ´ÂëµÈÎļþ

ALTDOS³ÆÆäÒÑÇÔÈ¡Êý°ÙGBÃϼÓÀ¹ú½ø³ö¿Ú¹«Ë¾BEXIMCOµÄÔ´ÂëµÈÎļþ¡£¡£¡£¡£¡£ALTDOSºÚ¿Í°µÊ¾ËûÃÇÔÚ12Ô¹¥»÷Á˸ù«Ë¾£¬£¬£¬£¬£¬£¬£¬×ܹ²´ÓÆä34¸öÍøÕ¾ÖÐÇÔÈ¡ÁËÊý°ÙGBµÄÎļþ¡¢Ô´´úÂëºÍÊý¾Ý¿â¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬ALTDOS»¹ÌṩÁ˲¿ÃÅÊý¾ÝµÄ½ØÍ¼£¬£¬£¬£¬£¬£¬£¬Ô̺¬´Ó2018Äê9ÔÂ24ÈÕµ½2019Äê5ÔÂ17ÈÕµÄÔ±¹¤³öÇÚÐÅÏ¢ºÍÔ̺¬¸¶¿î¼Í¼µÄpayment_infoµÈ13.6 GBµÄ42¸öѹËõÎļþ£¬£¬£¬£¬£¬£¬£¬²¢³ÆÆäÔÚ²é³Ëùº±¼û¾Ý¿âÒÔÆÀ¹ÀÊý¾Ý¼ÛÖµ¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬BEXIMCO¹«Ë¾²¢Î´¶Ô´ËʽøÐлØÓ¦¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.databreaches.net/hackers-claim-to-have-attacked-major-bangladeshi-conglomerate/
4.ShinyHuntersÔÚ°µÍø¹«¿ª190Íò¸öPixlrÓû§µÄÊý¾Ý

ShinyHuntersÔÚ°µÍø¹«¿ªÁË190Íò¸öÔÚÏßͼƬ±à×ëÀûÓÃPixlrµÄÓû§µÄÊý¾Ý¡£¡£¡£¡£¡£Õâ´ÎÊÂÎñй¶ÁË1921141¸öÓû§¼Í¼£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬µç×ÓÓʼþµØÖ·¡¢µÇ¼Ãû¡¢SHA-512¹þÏ£ÃÜÂë¡¢¹ú¶È¡¢ÊÇ·ñ×¢²áÁËÐÂÎÅͨѶÒÔ¼°ÆäËûÄÚ²¿ÐÅÏ¢¡£¡£¡£¡£¡£ShinyHunters°µÊ¾£¬£¬£¬£¬£¬£¬£¬ËûÓÚ2020Äêµ×´Ó¸Ã¹«Ë¾µÄAWS´æ´¢Í°ÏÂÔØÁ˸ÃÊý¾Ý¿â¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬PixlrÉÐδ¶Ô´ËÊÂ×÷³ö»ØÓ¦£¬£¬£¬£¬£¬£¬£¬µ«BleepingComputerÒÑÈ·ÈÏÊý¾Ý¿âÖеÄÓʼþµØÖ·¾ùÊôÓÚPixlrµÄ×¢²á»áÔ±¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hacker-posts-19-million-pixlr-user-records-for-free-on-forum/
5.ÔÚÏßÉ̳ÇAnyvanÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬Óû§Êý¾Ýй¶

Å·ÖÞÔÚÏßÉ̳ÇAnyvan³ÆÆäÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬Óû§Êý¾Ýй¶¡£¡£¡£¡£¡£Anyvan°µÊ¾Êý¾Ýй¶²úÉúÔÚ9Ôµף¬£¬£¬£¬£¬£¬£¬ÓÚ12ÔÂ31ÈÕ±»·¢ÏÖ¡£¡£¡£¡£¡£Ö®ºó¸Ã¹«Ë¾¶Ô´ËʽøÐÐÁ˵÷²é£¬£¬£¬£¬£¬£¬£¬·¢ÏÖ¿Í»§µÄÐÕÃû¡¢µç×ÓÓʼþºÍÃÜÂëµÄ¹þÏ£ÒÑй¶¡£¡£¡£¡£¡£×÷ΪÏìÓ¦¸Ã¹«Ë¾Ç¿Ôì¸ü¸ÄÁËËùÓÐЧ»§µÄÃÜÂ룬£¬£¬£¬£¬£¬£¬²¢½¨ÒéÓû§¶¨ÆÚ¸ü¸ÄÃÜÂë¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.theregister.com/2021/01/19/anyvan_confirms_digital_breakin_says/
6.×êÑÐÍŶӷ¢ÏÖFreakOutÀûÓöà¸öзì϶µÄ¹¥»÷»î¶¯

×êÑÐÍŶӷ¢ÏÖ½©Ê¬ÍøÂçFreakOutÀûÓöà¸öзì϶µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£Õâ´Î¹¥»÷ÖØÒªÕë¶ÔTerraMaster²Ù×÷ϵͳ¡¢Zend FrameworkºÍLiferay Portal£¬£¬£¬£¬£¬£¬£¬ÀûÓÃÁËCVE-2020-28188¡¢ CVE-2021-3007ºÍCVE-2020-7961·ì϶¡£¡£¡£¡£¡£FreakOutÓµÓзþÎñ¶Ë¿ÚɨÃè¡¢ÍøÂçÐÅÏ¢¡¢ÍøÂçÐá̽»ò·¢ÆðÉ¢²¼Ê½»Ø¾ø·þÎñ(DDoS)¹¥»÷µÈÖ°ÄÜ£¬£¬£¬£¬£¬£¬£¬¿ÉϰȾLinuxÉ豸£¬£¬£¬£¬£¬£¬£¬²¢ÀûÓÃÆäÍÚ¼ÓÃÜÇ®±Ò¡¢ÔÚ¹«Ë¾ÍøÂçÉϺáÏò´«²¼»ò¼Ù×°³ÉÊÜÓ°ÏìµÄ¹«Ë¾¹¥»÷ÆäËûÖ¸±ê¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://research.checkpoint.com/2021/freakout-leveraging-newest-vulnerabilities-for-creating-a-botnet/


¾©¹«Íø°²±¸11010802024551ºÅ