Docker HubÔâÈëÇÖ£¬19ÍòÕ˺ű»Ð¹Â¶£»¶ñÒâÈí¼þBabyShark£»MagecartÒÑϰȾ200¶à¸öµçÉÌÍøÕ¾
°ä²¼¹¦·ò 2019-04-28
4ÔÂ25ÈÕDocker HubÔâºÚ¿ÍÈëÇÖ£¬µ¼ÖÂÔ¼19ÍòÓû§ÕË»§µÄÃô¸ÐÐÅϢй¶¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬ÓÃÓÚ×Ô¶¯¹¹½¨Docker¾µÏñ¶øÊÚȨ¸øDocker HubµÄGitHubºÍBitbucket½Ó¼ûÁîÅÆ£¬ÒÔ¼°Óû§ÃûºÍ¹þÏ£ÃÜÂ롣ƾ¾ÝDocker¹Ù·½µÄ˵·¨£¬ÊÜÓ°ÏìµÄÓû§Ô¼Õ¼×ÜÓû§ÊýÁ¿µÄ5%¡£Docker°µÊ¾ÔÚ·¢ÏÖÈëÇÖºóµ±¼´ÏòÓû§·¢ËÍÁËÓʼþ֪ͨ£¬²¢²ÉÈ¡´ëÊ©±£»¤Óû§µÄÊý¾Ý¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/docker-hub-database-hack-exposes-sensitive-data-of-190k-users/2.iLnkP2PÒ×ÊÜÖÐÑëÈ˹¥»÷£¬200¶àÍǫ̀ÔÚÏßÉ豸´æÔÚ·çÏÕ
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/84525/hacking/ilnkp2p-flaws-iot.html3.˼¿ÆTalosÅû¶Sierra Wireless AirLinkÍø¹ØÖеĶà¸ö·ì϶
˼¿ÆTalosÅû¶Sierra Wireless AirLinkϵÁеÄÍø¹ØºÍ·ÓÉÆ÷ÖеĶà¸ö°²È«·ì϶¡£ÕâЩÉ豸±»¿í·ºÓÃÓÚÆóÒµ»·¾³Öй¤ÒµÉ豸¡¢ÖÇÄÜÉ豸¡¢´«¸ÐÆ÷¡¢PoS¼°ICSµÄÏνӡ£·ì϶ÁìÓòÔ̺¬ËÁÒâ´úÂëÖ´ÐÓ×¢ÖÎÀíÔ±ÃÜÂë¸ü¸Ä¡¢ÏµÍ³ÉèÖÃÅú¸Ä¡¢Óû§Í´´¦Ð¹Â¶¡¢CSRF¡¢XSSµÈ¡£´óÎÞÊý·ì϶´æÔÚÓÚÉ豸¸½´øµÄWeb·þÎñÆ÷ACEManagerÖС£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/84533/security/sierra-wireless-airlink-es450-flaws.html4.¶ñÒâÈí¼þBabySharkµÄй¥»÷»î¶¯£¬·Ö·¢KimJongRATºÍPCRat
Palo Alto NetworksµÄUnit 42ÍŶӰ䲼¹ØÓÚBabySharkжñÒâ¹¥»÷»î¶¯µÄ·ÖÎö»ã±¨¡£BabySharkÊÇ2Ô·ݳöÏֵĶñÒâÈí¼þ£¬Æä¹¥»÷»î¶¯³ÖÐøµ½ÁË3ÔºÍ4Ô£¬×îй¥»÷»î¶¯µÄÖ÷ÕÅËÆºõÓÐÁ½¸ö£ºÕë¶ÔºË°²È«ºÍ³¯Ïʰ뵺¹ú¶È°²È«ÎÊÌâµÄ¼äµý»î¶¯£»ÒÔ¼°Õë¶Ô¼ÓÃÜÇ®±ÒÐÐÒ·´»ñÈ¡½ðÇ®¡£BabySharkµÄ¶ñÒâpayloadÔ̺¬KimJongRATºÍPCRat£¬µ«¹¥»÷ÕßÔÚ¶ñÒâ´úÂëÖн«ËüÃÇͳ³ÆÎªCowboy¡£
ÔÎÄÁ´½Ó£º
https://unit42.paloaltonetworks.com/babyshark-malware-part-two-attacks-continue-using-kimjongrat-and-pcrat/5.¹¥»÷ÕßÀûÓÃAtlassian Confluence Server·ì϶·Ö·¢GandCrabºÍDofloo
Ç÷Ïò¿Æ¼¼×êÑÐÈËÔ±Augusto II Remillano·¢ÏÖ¹¥»÷ÕßÔÚ»ý¼«ÀûÓÃAtlassian Confluence ServerÖеķì϶£¨CVE-2019-3396£©À´·Ö·¢ÀÕË÷Èí¼þGandCrabºÍľÂíDofloo¡£Æ¾¾ÝNVD£¬¸Ã·ì϶¿ÉÔÊÐíÔ¶³Ì¹¥»÷Õßͨ¹ýÄ£°å×¢ÈëʵÏÖõè¾¶±éÀúºÍÔ¶³Ì´úÂëÖ´ÐС£AtlassianÔÚ3ÔÂ20ÈÕ½¨¸´Á˸÷ì϶£¬ÓÉÓÚ¶à¸öexploit¹«¿ª¿ÉÓ㬹¥»÷ÕßÔÚ»ý¼«É¨ÃèÒ×Êܹ¥»÷µÄ·þÎñÆ÷À´Ö´Ðй¥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/vulnerable-confluence-servers-get-infected-with-ransomware-trojans/6.MagecartÇÔÈ¡Óû§Ö§¸¶ÐÅÏ¢£¬ÒÑϰȾ200¶à¸öµçÉÌÍøÕ¾
Magecart¹¥»÷ÊÇÖ¸½«¶ñÒâ¾ç±¾Ö²ÈëµçÉÌÍøÕ¾ÒÔÇÔÈ¡Óû§µÄÖ§¸¶ÐÅÏ¢£¬ÆäÊܺ¦ÕßÔ̺¬Ó¢¹úº½¿Õ¡¢Ðµ°ºÍFeedifyµÈ¡£MalwareBytes×êÑÐÈËÔ±ÔÚGithubÉÏ·¢ÏÖÒ»¸ö¶ñÒâMagecart¾ç±¾£¬¸Ã¾ç±¾ÓÚ4ÔÂ20ÈÕÉÏ´«£¬Í¨¹ýËÑË÷ÒýÇæurlscan.ioºÍPublicWWWÄܹ»·¢ÏÖÖÁÉÙÓÐ200¶à¸öµçÉÌÍøÕ¾Êܵ½¸Ã¾ç±¾µÄϰȾ¡£ÔÚ½Óµ½»ã±¨ºó£¬GitHubѸ¿ìɾ³ýÁ˶ñÒâ¾ç±¾£¬µ«ÊÜËðµÄÍøÕ¾ÈÔÃæ¶Ô±»ÈëÇֵķçÏÕ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/84564/cyber-crime/magecart-skimmer-github.html


¾©¹«Íø°²±¸11010802024551ºÅ