°ÄÖÞ2019ÄêQ1Êý¾Ýй¶ͳ¼Æ»ã±¨ £»SCADDÔâÀÕË÷Èí¼þ¹¥»÷ £»½ü90%°ÍÄÃÂí¹«ÃñÐÅϢй¶

°ä²¼¹¦·ò 2019-05-14
1¡¢ÈýÐÇÊÖ»úÈí¼þContainerAgent´æÔÚDoS·ì϶£¬¿Éµ¼ÖÂÉ豸±äש

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
·¨¹ú°²È«×êÑÐÔ±Robert Baptiste·¢ÏÖÈýÐÇÊÖ»úÈí¼þContainerAgentÖдæÔÚÒ»¸ö¿Éµ¼ÖÂDoSµÄ·ì϶£¬¸Ã·ì϶ӰÏìÁËÏÕЩËùÓÐÈýÐÇÊÖ»ú£¬¿Éµ¼ÖÂÉ豸±äש¡£Æ¾¾ÝBaptisteµÄ²©¿Í£¬ContainerAgentĬÈÏÆôÓù㲥½Ó¹ÜÆ÷Ö°ÄÜ£¬¸Ã½Ó¹ÜÆ÷µÄOnReceive²½Öè´æÔÚ·ì϶£¬Í¨¹ýµ÷Õû²ÎÊý×îÖտɵ¼ÖÂÉè±¸Ëø¶¨¡£Baptiste»¹ÔÚGithubÉϰ䲼ÁËPoC£¬µ«ÈýÐǰ²È«ÍŶÓÒÔΪ¸Ã·ìϼû»ÓÐ/ÏÕЩûÓа²È«Ó°Ïì¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/white-hat-finds-out-faulty-application-that-reportedly-bricks-all-samsung-phones-e4dad8cc

2¡¢ºÚ¿Íͨ¹ýÈëÇÖAlpaca FormsºÍPicreel»ù´¡ÉèÊ©¹¥»÷4600¶à¸öÍøÕ¾

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
ºÚ¿Íͨ¹ýÈëÇÖ·ÖÎö·þÎñPicreelºÍ¿ªÔ´ÏîÄ¿Alpaca FormsµÄ»ù´¡ÉèÊ©ÌáÒ鹩¸øÁ´¹¥»÷£¬ÒÑÓг¬¹ý4600¸öÍøÕ¾Êܵ½Ï°È¾¡£×êÑÐÈËÔ±Willem de Groot³ÆÕâÁ½¸ö¹¥»÷»î¶¯ÊÇÓÉͳһ¸ö¹¥»÷ÕßËùΪ£¬µ«Éв»Ã÷ÏÔÆäÈëÇÖ·½Ê½¡£¹¥»÷ÕßÅú¸ÄÁËPicreel¼°Alpaca Forms CDN»ù´¡ÉèÊ©ÉϵÄJavaScriptÎļþ£¬ÓÃÓÚÇÔÈ¡Óû§ÔÚÍøÒ³±íµ¥ÖÐÊäÈëµÄÄÚÈݲ¢·¢ËÍÖÁλÓÚ°ÍÄÃÂíµÄ·þÎñÆ÷¡£Êܵ½Ï°È¾µÄPicreel¾ç±¾ÒÑÔÚ1249¸öÍøÕ¾ÉÏ·¢ÏÖ£¬¶øAlpaca Forms¾ç±¾ÔòÓ°ÏìÁË3435¸öÍøÕ¾¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/hackers-are-collecting-payment-details-user-passwords-from-4600-sites/

3¡¢SCADDÔâÀÕË÷Èí¼þ¹¥»÷£¬³¬¹ý2.5Íò»¼ÕßÐÅÏ¢ÊÜËð

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
ÃÀ¹ú¿µÖݶ«Äϲ¿µÄ½ä¾Æ½ä¶¾Î¯Ô±»á£¨SCADD£©ÔâÀÕË÷Èí¼þ¹¥»÷¡£¸Ã¹¥»÷ÊÂÎñµ¼ÖÂ25148Ãû»¼ÕßµÄÓ×ÎÒÐÅÏ¢ÊÜËð£¬ÕâЩÐÅÏ¢Ô̺¬ÐÕÃû¡¢µØÖ·¡¢Éç»á°²È«ºÅÂëÒÔ¼°²¡Ê·ºÍÒ½ÖÎÐÅÏ¢¡£SCADDÓÚ2ÔÂ18ÈÕ·¢ÏÖÁËÕâÒ»ÊÂÎñ£¬¸Ã×éÖ¯ÂíÉϽøÐÐÁËÈ«Ãæµ÷²é£¬²¢ÓëµÚÈý·½°²È«×¨¼ÒºÏ×÷ÒÔÈ·ÈÏÄÄЩÐÅÏ¢Êܵ½ÇÖº¦¡£SCADD½«ÎªÊÜÓ°ÏìµÄ»¼ÕßÌṩÃâ·ÑµÄÐÅÓþ¼à¿ØºÍÉí·Ý± £»¤·þÎñ¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/the-southeastern-council-on-alcoholism-and-drug-dependence-hit-with-a-ransomware-attack-77498d74

4¡¢°ÄÖÞÐÅϢרԱ°ì¹«ÊÒ°ä²¼2019ÄêQ1Êý¾Ýй¶ͳ¼Æ»ã±¨

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
°Ä´óÀûÑÇÐÅϢרԱ°ì¹«ÊÒ£¨OAIC£©°ä²¼2019ÄêµÚÒ»¼¾¶ÈµÄÊý¾Ýй¶ͳ¼Æ»ã±¨£¬¸Ã»ã±¨Í³¼ÆÁË1ÔÂ1ÈÕÖÁ3ÔÂ31ÈÕOAIC½Ó¹Üµ½µÄÊý¾Ýй¶ÊÂÎñ֪ͨ¡£×ܵÄÀ´ËµOAIC¹²ÊÕµ½215¸öÊý¾Ýй¶֪ͨ£¬±ÈÉÏÒ»¼¾¶È£¨2018ÄêQ4£©µÄ262´ÎÒªÉÙ¡£³¬¹ý1000ÍòÈËÔÚµ¥´ÎÊÂÎñÖÐÊܵ½Ó°Ï죬¶ø°Ä´óÀûÑǵÄÈ˶¡Ô¼Îª2540Íò¡£±¾¼¾¶ÈÊÜÓ°Ïì×îÑϳÁµÄÓ×ÎÒÐÅÏ¢ÊÇÁªÏµÐÅÏ¢£¬¹²ÓÐ186¸öÊý¾Ýй¶ÊÂÎñÓ°ÏìÁË´ËÀàÊý¾Ý£¬Æä´ÎÊÇÓ×ÎÒ²ÆÕþÐÅÏ¢£¨Óë98¸öÊÂÎñÓйأ©ºÍÉí·ÝÐÅÏ¢£¨Óë55¸öÊÂÎñÓйأ©¡£OAIC°µÊ¾ÕâÊÇ×îºóÒ»´Î°ä²¼¼¾¶È»ã±¨£¬ÒÔÀ´½«Ã¿Áù¸öÔ°䲼һ´Î¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/over-10-million-people-hit-in-single-australian-data-breach-oaic/

5¡¢×êÑÐÍŶӰ䲼ScarCruft APT¶ñÒ⹤¾ßµÄ·ÖÎö»ã±¨

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
¿¨°Í˹»ù°ä²¼³¯ÏÊAPT×éÖ¯ScarCruftµÄ·ÖÎö»ã±¨¡£¸Ã×éÖ¯±»ÒÔΪÊǹú¶ÈÔÞÖúµÄ¹¥»÷×éÖ¯£¬ÖØÒªÕë¶ÔÓ볯Ïʰ뵺ÓйصÄ×éÖ¯ºÍÆóÒµ¡£Æ¾¾ÝÆä×î½üµÄ¹¥»÷»î¶¯£¬¸Ã×éÖ¯ÒÀÈ»¼«¶È»îÔ¾£¬²¢ÇÒ²»ÐݸĽøÆä¹¥»÷¹¤¾ß¡£ScarCruftʹÓõijõʼdropper¿ÉÈÆ¹ýWindows UAC£¬²¢ÇÒÀûÓ÷ì϶CVE-2018-8120ÏÂÔØ²¢Ö´ÐÐÏÂÒ»½×¶Îpayload£¨ROKRATºóÃÅ£©¡£´Ë±í£¬ScarCruft»¹´´½¨ÁËÒ»¸öÉÙ¼ûµÄ¶ñÒâÈí¼þ-À¶ÑÀÉè±¸ÍøÂçÆ÷£¬¸Ã¶ñÒâÈí¼þÓÃÓÚ²éÕÒÒÑÏνӵÄÀ¶ÑÀÉ豸²¢ÇÔÈ¡É豸ÐÅÏ¢¡£×êÑÐÈËÔ±»¹·¢ÏÖ¸Ã×éÖ¯µÄ¹¥»÷»î¶¯ÓëDarkHotel APT´æÔÚ¹ØÁª¡£

Ô­ÎÄÁ´½Ó£ºhttps://securelist.com/scarcruft-continues-to-evolve-introduces-bluetooth-harvester/90729/

6¡¢Î´ÉèÃÜÂëµÄÊý¾Ý¿âй¶½ü90%°ÍÄÃÂí¹«ÃñÐÅÏ¢

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
°²È«×êÑÐÔ±Bob DiachenkoʹÓÃShodanÔÚAWSÉÏ·¢ÏÖÒ»¸öδÊܱ £»¤µÄElasticsearchÊý¾Ý¿â£¬¸ÃÊý¾Ý¿âй¶ÁËÊý°ÙÍò°ÍÄÃÂí¹«ÃñµÄÃô¸ÐÐÅÏ¢¡£Æ¾¾Ý×êÑÐÈËÔ±µÄ±íÊö£¬¸ÃÊý¾Ý¿âÔ̺¬3427396Ìõ±êǩΪ¡°»¼Õß¡±µÄ¼Í¼ÒÔ¼°468086Ìõ±êǩΪ¡°²âÊÔ»¼Õß¡±µÄ¼Í¼¡£ÕâЩÐÅÏ¢Ô̺¬ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢Éí·ÝÖ¤ºÅÂë¡¢µØÖ·¡¢ÓÊÏäºÍµç»°ºÅÂëµÈ¡£ÈôÊÇÊý¾ÝûÓгÁ¸´£¬ÕâЩ¼Í¼Լռ¸Ã¹ú×ÜÈ˶¡µÄ90%¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/sensitive-information-of-millions-of-panama-citizens-leaked/