¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181228

°ä²¼¹¦·ò 2018-12-28
1¡¢Exchange ServerºáÏòÉøÈëºÍÌáȨ£¬EXPÒѰ䲼

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ZDIÅû¶Exchange ServerÖеÄÒ»¸ö°²È«·ì϶£¨CVE-2018-8581£©µÄ¼¼Êõϸ½Ú¡£¸Ã·ì϶ÔÊÐíÈκξ­¹ýÉí·ÝÑéÖ¤µÄÓû§¼ÙÒâExchange ServerÉÏµÄÆäËüÓû§£¬¿ÉÓÃÓÚ´¹µö»î¶¯¡¢Êý¾Ýй¶µÈ¹¥»÷»î¶¯ÖС£¸Ã·ì϶ÊÇÒ»¸ö·þÎñÆ÷¶ËÒªÇóαÔ죨SSRF£©·ì϶£¬×êÑÐÈËÔ±ÑÝʾÁËÈôºÎÀûÓø÷ì϶Åú¸ÄÊܺ¦ÕßÓÊÏäµÄÈëÕ¾¹æ¶¨£¬²¢½«ËùÓеÄÈëÕ¾µç×ÓÓʼþ¶¼×ª·¢¸ø¹¥»÷Õߣ¬Æäexp¾ç±¾Äܹ»´Ógithub¸ßµÍÔØ¡£Î¢ÈíÔÚ11Ô·ݵĽ¨¸´²¹¶¡ÖÐͨ¹ýɾ³ýÒ»¸ö×¢²á±íÏîÀ´»º½â¸Ã·ì϶¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.zerodayinitiative.com/blog/2018/12/19/an-insincere-form-of-flattery-impersonating-users-on-microsoft-exchange


2¡¢ÀÕË÷Èí¼þCriaklµÄбäÌåͨ¹ýÀ¬»øÓʼþ´«²¼

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



AnyrunÔÚÊ¥µ®½ÚÆÚ¼ä·¢ÏÖÒ»¸öеÄÀÕË÷Èí¼þÑù±¾£¬¸ÃÑù±¾ÊÇcriaklµÄÒ»¸öбäÌå¡£Criakl³öÏÖÓÚ2014Äê×óÓÒ£¬ÖØÒªÕë¶ÔÓ¢¹ú£¬µ«ËæºóÏÕЩÒþû¡£×êÑÐÈËÔ±·¢ÏÖµÄÑù±¾Í¨¹ý´¹µöÓʼþ´«²¼£¬ÕâЩ´¹µöÓʼþµÄÓ¢ÎIJ¢²»ÊǺܺ㬺ܿÉÄÜÊÇͨ¹ýÆäËü˵»°»úе·­ÒëµÃÀ´¡£ÕâЩ´¹µöÓʼþ¾ùͨ¹ýSPFºÍDKIMÈÏÖ¤£¬ÆäÖÐÒ»¸öÔ̺¬.docÎĵµµÄzip¸½¼þ£¬ÁíÒ»¸öÔ̺¬.exeÎļþµÄrar¸½¼þ¡£¸ÃcriaklµÄбäÌåֻϰȾWindowsϵͳµÄÍÆËã»ú¡£

  

Ô­ÎÄÁ´½Ó£º

https://myonlinesecurity.co.uk/new-ransomware-possibly-criakl-version/


3¡¢Shamoon 3ÐÂÑù±¾±»ÉÏ´«ÖÁVirusTotal£¬Ê¹ÓùýÆÚµÄ°Ù¶ÈÖ¤Êé

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Êý¾Ý²Á³ýÈí¼þShamoon 3µÄÒ»¸öÐÂÑù±¾ÓÚ12ÔÂ23ÈÕÔÚ·¨¹úÉÏ´«ÖÁVirusTotalƽ̨¡£¸ÃÑù±¾Ê¹ÓÃÁ˹ýÆÚµÄ°Ù¶ÈÖ¤Ê飨´ËÖ¤ÊéÓÚ2015Äê3ÔÂ25ÈÕ°ä²¼£¬²¢ÓÚ2016Äê3ÔÂ26ÈÕ¹ýÆÚ£©£¬²¢Ê¹ÓÃóÒ×´ò°ü¹¤¾ßEnigma v4½øÐлìºÏ¡£Æ¾¾ÝAnomali³¢ÊÔÊҵķÖÎö£¬¸ÃÐÂÑù±¾Ê¹ÓÃÁ˵ã»ðµÄÃÀԪͼ°¸²¢Ô̺¬¡°ÎÒÃǽ«Îªº¢×ÓµÄѪÓëÀḴ³ð¡±×ÖÑù¡£

  

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/79248/malware/shamoon-3-france.html


4¡¢ÃÀÁª¹úÒµÎñίԱ»áÖÒ¸æÕë¶ÔNetflixÓû§µÄ´¹µö¹¥»÷

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹úÁª¹úÒµÎñίԱ»á£¨FTC£©ÖÒ¸æÕë¶ÔNetflix¿Í»§µÄÐÂÍøÂç´¹µö»î¶¯¡£ÕâЩ´¹µö»î¶¯Öй¥»÷Õß¼Ù×°³ÉNetflixÏòÓû§·¢ËÍ´¹µöÓʼþ£¬Ðû³ÆÓû§µÄÕË»§ÓÉÓÚ½áËãÎÊÌâ¶ø±»ÁÙÊ±Ëø¶¨£¬ÒªÇóËûÃǸüÐÂ×Ô¼ºµÄ¸¶¿î·½Ê½£¬µ«ÏÖʵÉÏÖ»ÊÇΪÁËÇÔÈ¡ÕâЩ¸¶¿îÐÅÏ¢¡£Netflix°µÊ¾¸Ã¹«Ë¾¾ø²»»áÒªÇóÓû§Í¨¹ýµç×ÓÓʼþ·¢ËÍÓ×ÎÒÐÅÏ¢¡¢¸¶¿îÐÅÏ¢»òÕË»§ÃÜÂëµÈ¡£

  

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/ftc-warns-of-netflix-phishing-scam-making-rounds/140378/


5¡¢BevMoÍøÕ¾±»×¢Èë¶ñÒâ´úÂ룬³¬¹ý1.4ÍòÓû§µÄÐÅϢй¶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹úÆÏÌѾƺÍÁÒ¾ÆÉ̵êBevMoÏòÆä¿Í»§Í¨Öª³Æ¸Ã¹«Ë¾Ôâ·êÊý¾Ýй¶ÊÂÎñ£¬³¬¹ý1.4ÍòÃû¿Í»§µÄÐÅϢй¶¡£Æ¾¾Ý¸Ã¹«Ë¾Ìá½»¸ø¼ÓÖݼì²ì³¤°ì¹«ÊҵĻ㱨£¬¹¥»÷ÕßÔÚÆäÍøÕ¾µÄ½áÕËÒ³Ãæ×¢ÈëÁ˶ñÒâ´úÂ룬ÓÃÓÚÇÔÈ¡¿Í»§µÄÐÕÃû¡¢µç»°ºÅÂë¡¢µØÖ·¡¢ÐÅÓþ¿¨ºÅÂëºÍ°²È«ÂëµÈ¡£¸ÃÊÂÎñÓ°ÏìÁË2018Äê8ÔÂ2ÈÕÖÁ9ÔÂ26ÈÕÆÚ¼äµÄ¶©µ¥¡£BevMoÒÑ´ÓÆäÔÚÏßÉ̵êÖÐɾ³ýÁ˶ñÒâ´úÂ룬²¢È·ÈÏÔÚ½øÐе÷²é¡£

  

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/79230/data-breach/bevmo-payment-card-breach.html


6¡¢·¨¹ú¼à¹Ü»ú¹¹CNILÒòÊý¾Ýй¶ÊÂÎñ¶ÔµçÐŹ«Ë¾Bouygues·£¿î25ÍòÅ·Ôª

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¾Ý°ÍÀè·͸É籨·£¬±¾ÖÜËÄ·¨¹úÊý¾ÝÒþÖÔ¼à¹Ü»ú¹¹CNIL¶ÔµçÐŹ«Ë¾Bouygues´¦ÒÔ25ÍòÅ·ÔªµÄ·£¿î£¨Ô¼28.5ÍòÃÀÔª£©¡£CNIL³ÆBouyguesδÄÜÈ·±£ÆäÍøÕ¾ÉÏÊý¾ÝµÄ°²È«ÐÔ£¬µ¼ÖÂÔ¼2°ÙÍòÓû§µÄÓ×ÎÒÊý¾ÝÊܵ½Êý¾Ýй¶ÊÂÎñµÄÓ°Ïì¡£CNIL»¹³Æ¸Ã¹«Ë¾ÒѾ­½¨¸´Á˸ÃÎÊÌâ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.reuters.com/article/us-france-bouygues-fine/french-watchdog-fines-bouygues-for-data-security-breach-idUSKCN1OQ0Q4


ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù