Facebook 5.4ÒÚÓû§¼ÍÂ¼ÆØ¹â£»JS-SnifferϰȾ2440¸öÍøÕ¾£»2018ÄêAndroid°²È«¼°ÒþÖԻ㱨
°ä²¼¹¦·ò 2019-04-04
UpGuard×êÑÐÍŶӷ¢ÏÖÁ½¸öµÚÈý·½ÀûÓõÄÑÇÂíÑ·S3´æ´¢¿â¿É¹«¿ª½Ó¼û£¬ÆäÖд洢Á˳¬¹ý5.4ÒÚFacebookÓû§µÄ¼Í¼¡£ÕâЩÓû§Êý¾ÝÔ̺¬µÚÈý·½ÀûÓõÄÃ÷ÎÄÃÜÂë¡¢FacebookÕË»§Ãû³Æ¡¢Óû§ID¡¢ÆÀÂÛ¡¢ÐËÖ¡¢¹ØÏµ×´Ì¬µÈ¡£Ò»¸öÊý¾Ý¿âÊôÓÚÄ«Î÷¸çýÌ幫˾Cultura Colectiva£¬¸ÃÊý¾Ý¿âÃûΪcc-datalake£¬´óÓ×Ϊ146GB£¬Ô̺¬Ô¼5.4ÒÚÓû§¼Í¼¡£ÁíÒ»¸öÊý¾Ý¿âÊôÓÚµÚÈý·½ÀûÓÃAt the Pool£¬Ö»Ô̺¬2.2ÍòÓû§¼Í¼¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/540-mllion-facebook-records-leaked-by-public-amazon-s3-buckets/2.×ôÖÎÑÇÀí¹¤Ñ§ÔºÔâºÚ¿Í¹¥»÷£¬130ÍòѧÉú¼°Ô±¹¤ÐÅϢй¶
ÃÀ¹ú×ôÖÎÑÇÀí¹¤Ñ§ÔºÈ·ÈÏÓÚ2018Äê12ÔÂ14ÈÕÔâºÚ¿ÍÈëÇÖ£¬¶à´ï130ÍòѧÉú¡¢ÉêÇëÈ˺ÍÔ±¹¤µÄÓ×ÎÒÐÅϢй¶¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢µØÖ·¡¢Éç»á°²È«ºÅÂëºÍµ®ÉúÈÕÆÚ¡£¹¥»÷ÕßÀûÓÃÒ»¸öWebÀûÓÃÖеķì϶£¬»ñµÃ¶Ô·þÎñÆ÷µÄδÊÚȨ½Ó¼û¡£¹ÌȻĿǰ¸Ã·ì϶Òѱ»½¨¸´£¬µ«¹¥»÷Õß¿ÉÄÜÒѾװÖÃÁ˶ñÒâÈí¼þµÈ¡£ÕâÊÇ×ôÖÎÑÇÀí¹¤Ñ§ÔºÒ»ÄêÄÚ²úÉúµÄµÚ¶þÆðÊý¾Ýй¶ÊÂÎñ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/georgia-tech-data-breach-exposes-info-for-13-million-people/3.JS-SnifferϰȾȫÇò2440¸öÍøÕ¾£¬ÖØÒªÇÔÊØÐÅÓþ¿¨ÐÅÏ¢
ƾ¾Ý°²È«³§ÉÌGroup-IBµÄÒ»·Ýл㱨£¬½ü38¸ö·ÖÆçµÄJS-SnifferϰȾÁËÈ«Çò2440¸öµç×ÓÉÌÎñÍøÕ¾¡£JS-SnifferÊÇÒ»ÖÖJavaScript¶ñÒâ¾ç±¾£¬Ö¼ÔÚÀ¹½Ø²¢ÇÔÈ¡Óû§ÊäÈëµÄÒøÐп¨ºÅ¡¢ÐÕÃû¡¢µØÖ·¡¢µÇ¼ÐÅÏ¢ºÍÃÜÂëµÈ¡£Æ¾¾Ý¹À¼Æ£¬ÕâЩJS-sniffer¿ª·¢ÕßµÄÊÕÒæ¿É´ïÿÔÂÊýÊ®ÍòÃÀÔª¡£ÔÚÕâЩJS-Sniffer¼Ò×åÖУ¬ÖÁÉÙÓÐ8¸ö֮ǰ´Óδ±»µ÷²é¹ý¡£ÔÚÊÜϰȾµÄÍøÕ¾ÖУ¬³¬¹ýÒ»°ëµÄ¹¥»÷ÊÇÓÉJS-sniffer¼Ò×åMagentoNameÌáÒéµÄ£¬¶ø³¬¹ý13%µÄ¹¥»÷ÊÇÓÉWebRank¼Ò×åÌáÒéµÄ¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/04/js-sniffers-credit-card-hacking.html4.OceanLotus APTÀûÓÃÒþдÊõ¼ÓÔØºóÃÅDenes¼°Remy
ƾ¾ÝCylance×êÑÐÍŶӰ䲼µÄ»ã±¨£¬APT×éÖ¯OceanLotus£¨ÓÖ³ÆAPT32£©ÔÚʹÓûùÓÚÒþдÊõµÄ¼ÓÔØÆ÷À´¿ªÊÍDenesºóÃźÍRemyºóÃŵÄбäÌå¡£ÕâÖÖÒþдËã·¨ËÆºõÊÇרÃÅ¿ª·¢µÄ£¬Ö¼ÔÚÀûÓÃPNGͼƬ°µ²Ø¼ÓÃܵĶñÒâÈí¼þpayload¡£×êÑÐÈËÔ±·ÖÎöµÄ¼ÓÔØÆ÷Ñù±¾Ê¹ÓÃÁËDLLºÍCrypto++¿âµÄAES128Ë㷨ʵÏÖ£¬¹ÌÈ»ÕâЩÑù±¾±»ÓÃÓÚÔÚÖ¸±êϵͳÉÏ¿ªÊͺóÃÅ£¬µ«¹¥»÷ÕßÒ²Äܹ»µÈÏеؽøÐÐÅú¸ÄÒÔ¿ªÊÍÆäËü¶ñÒâpayload¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/oceanlotus-apt-uses-steganography-to-load-backdoors/5.¹È¸è°ä²¼2018ÄêAndroid°²È«¼°ÒþÖԻ㱨£¬Ô¤×°ÖöñÒâÀûÓÃÊýÁ¿ÉÏÉý
¹È¸è°ä²¼2018ÄêAndroid°²È«¼°ÒþÖԻ㱨£¬³ÆÍ¨¹ýԤװÖûòÎÞÏ߸üзַ¢µÄPHA£¨Ç±ÔÚÓк¦ÀûÓã©ÊýÁ¿ÉÏÉý¡£¹È¸è³ÆÕâÖÖ¼¼ÊõÓÈΪÁîÈ˲»°²£¬ÓÉÓÚÓû§ÎÞ·¨½ÚÔìԤװÖÃÔÚÊÖ»úÉϼ°Í¨¹ýϵͳ¸üÐÂÏÂÔØµÄÄÚÈÝ¡£µ«¸Ã»ã±¨»¹Ö¸³ö£¬2018ÄêÔËÐÐGoogle Play ProtectµÄAndroidÉ豸ÉϵÄPHAÊ·ý×ÜÌå±ÈÉÏÒ»Äê½µÂäÁË20%¡£ÕâÔ̺¬Í¨¹ýµÚÈý·½ÀûÓÃÉ̵ꡢGoogle Play¼°ÆäËü¶ñÒâ¹¥»÷ÖÐ×°ÖõÄPHA¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/google-warns-of-growing-android-attack-vector-backdoored-sdks-and-pre-installed-apps/143332/6.Arizona BeveragesÔâÀÕË÷Èí¼þiEncrypt¹¥»÷£¬½ü200̨·þÎñÆ÷±»Ï°È¾
ÒûÁÏÉÌArizona BeveragesÔâÀÕË÷Èí¼þ¹¥»÷£¬µ¼ÖÂÆäÏúÊÛÒµÎñ±»ÆÈÖÕ³¡½üÁ½ÖÜ¡£ÊÂÎñµÄÔÒòÊǸù«Ë¾µÄºó¶Ë·þÎñÆ÷ÔËÐÐÁ˹ýÆÚµÄWindowsϵͳ£¬µ¼Ö½ü200̨Ïνӵ½ÍøÂçµÄ·þÎñÆ÷ϰȾÀÕË÷Èí¼þiEncrypt¡£ÔÚ˼¿ÆµÄÔ®ÊÖÏ£¬¸Ã¹«Ë¾ÒÑ´ÓÀÕË÷Èí¼þ¹¥»÷Öи´Ô£¬²¢ÒÑÔÚеÄÓ²¼þ¡¢Èí¼þºÍ¸´Ô³É±¾ÉÏÆÆ·ÑÊýÊ®ÍòÃÀÔª¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/arizona-beverages-hit-by-a-massive-ransomware-attack-9bcd2630


¾©¹«Íø°²±¸11010802024551ºÅ