×êÑÐÈËÔ±Â½ÐøµÚÈýÌì°ä²¼Windows 0day¼°PoC£»2019ÄêQ1ڲƭ¹¥»÷Ì¬ÊÆ»ã±¨£¬Òƶ¯Ú²Æ­ì­Éý300%

°ä²¼¹¦·ò 2019-05-24
1¡¢×êÑÐÈËÔ±Â½ÐøµÚÈýÌì°ä²¼Windows 0day¼°PoC

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
SandboxEscaperÂ½ÐøµÚÈýÌì°ä²¼ÁËеÄWindows 0day£¬²¢ÔÚGitHubÉϰ䲼ÁËPoC´úÂë¡£×òÌìËý°ä²¼µÄWindowsÃýÎó»ã±¨·þÎñÖеÄLPE´Ó¼¼ÊõÉÏÀ´Ëµ²¢²»ÊÇ0day£¨Î¢ÈíµÄ5Ô°²È«¸üÐÂÒѾ­½¨¸´ÁËÕâ¸öÎÊÌ⣩£¬Òò¶ø½ñÌìµÄÁ½¸ö0dayÊÇËý°ä²¼µÄµÚÆßºÍµÚ°Ë¸ö0day¡£µÚÆß¸ö0dayÊÇÕë¶ÔCVE-2019-0841½¨¸´²¹¶¡µÄÈÆ¹ý£¬ÕâÊÇÒ»¸öLPE·ì϶¡£µÚ°Ë¸öÔòÊÇÓëWindows·¨Ê½½¨¸´×°Öùý³ÌÖеĶ̹¦·ò¾ºÕùǰÌáÓйØ£¬ÀûÓÃmsiexec /fa£¨½¨¸´×°Ö㩲Ù×÷Öеķì϶£¬µÍȨÏ޵Ĺ¥»÷Õß¿ÉÖ²Èë¶ñÒâÈí¼þ²¢ÊÕÊÜÍÆËã»ú¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/researcher-publishes-windows-zero-days-for-the-third-day-in-a-row/


2¡¢RSA°ä²¼2019ÄêQ1ڲƭ¹¥»÷Ì¬ÊÆ»ã±¨£¬Òƶ¯Ú²Æ­ì­Éý300%

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
ƾ¾ÝRSA°ä²¼µÄ2019ÄêQ1ڲƭ¹¥»÷Ì¬ÊÆ»ã±¨£¬Òƶ¯APPڲƭ¹¥»÷ÔÚµÚÒ»¼¾¶Èì­Éý300%£¬2019Äê1ÔÂ1ÈÕÒÆ¶¯Ú²Æ­¹¥»÷×ÜÊýΪ10390£¬µ«½ØÖÁ3ÔÂ31ÈÕ¸ÃÊý×ÖÒÑì­ÉýÖÁ41313¡£´Ë±í£¬¸Ã»ã±¨»¹·¢ÏÖÓë½ðÈÚÓйصÄڲƭ¹¥»÷Ôö³¤ÁË56%£¬´Ó2018ÄêQ4µÄ6603ÆðÔö³¤ÖÁ2019ÄêQ1µÄ10331Æð¡£ÍøÂç´¹µöÕ¼µÚÒ»¼¾¶ÈËùÓÐڲƭ¹¥»÷µÄ29%¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.infosecurity-magazine.com/news/fraud-attacks-from-mobile-spiked-1/


3¡¢4545ÃûTalkTalk¿Í»§µÄ²ÆÕþÐÅÏ¢ÔÚGoogleÉÏй¶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
ƾ¾ÝBBC WatchdogµÄµ÷²é£¬4545ÃûTalkTalk¿Í»§µÄÃô¸ÐÐÅÏ¢¿ÉÔÚGoogleËÑË÷ÖÐÕÒµ½£¬ÕâЩÐÅÏ¢Ô̺¬ÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢Õ˺š¢µç»°ºÅÂëºÍ²ÆÕþÐÅÏ¢¡£Õâ²¢²»ÁÏζ×ÅеÄÊý¾Ýй¶ÊÂÎñ£¬¶øÊÇÓë2015ÄêµÄ°²È«ÊÂÎñÓйØ¡£µ¥Ò»À´Ëµ£¬ÔÚÆäʱµÄÊÂÎñÖУ¬TalkTalkûÄÜÕýÈ·µØÍ¨ÖªÕâЩ¿Í»§ËûÃǵÄÊý¾ÝÔ⵽й¶£¬µ¼ÖÂÕâ4545Ãû¿Í»§µÄÐÅÏ¢×Ô2015ÄêÒÔÀ´Ò»ÏòÔÚÍøÉÏй¶¶ø²»×ÔÖª¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/talktalk-customer-financial-details-found-through-google-search/


4¡¢ºÉÀ¼¾¯·½È¡µÞ¼ÓÃÜÇ®±ÒÏ´Ç®·þÎñBestMixer.io

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
ºÉÀ¼¾¯·½È¡µÞ¼ÓÃÜÇ®±ÒÏ´Ç®·þÎñBestMixer.io¡£BestmixerÓÚ2018Äê5ÔÂÍÆ³ö£¬ÔÚÒ»ÄêµÄ¹¦·òÀïÒѾ­Ô®ÊÖ¿Í»§Ï´Ç®ÖÁÉÙ2ÒÚÃÀÔª¡£¸Ã·þÎñÄܹ»»ìºÏ±ÈÌØ±Ò£¨BTC£©¡¢±ÈÌØ±ÒÏÖ½ð£¨BCH£©ºÍÀ³Ìرң¨LTC£©£¬Í¨¹ý´óÁ¿»ìºÏÂòÂôʹµÃ½ðÇ®µÄÆðÔ´²»³É×·×Ù¡£ºÉÀ¼FIODºÍÅ·ÖÞÐ̾¯×éÖ¯²é»ñÁË6̨ÓÃÓÚÌṩ¸Ã·þÎñµÄ·þÎñÆ÷£¬²¢½«¶ÔÆäÊý¾Ý½øÇ°½øÒ»²½µÄ·ÖÎö¡£


Ô­ÎÄÁ´½Ó£ºhttps://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/crypto-currency-laundering-service-bestmixer-io-taken-down-by-law-enforcement/


5¡¢×êÑÐÍŶӰ䲼ÀÕË÷Èí¼þShadeй¥»÷»î¶¯µÄ·ÖÎö»ã±¨

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
ƾ¾Ýpalo alto networksµÄunit42ÍŶӵÄÒ»ÏîÐÂ×êÑУ¬2019Äê1Ôµ½3ÔÂÆÚ¼äÀÕË÷Èí¼þShadeÖØÒªÕë¶ÔµÄ¹ú¶ÈÓÐÃÀ¹ú¡¢ÈÕ±¾¡¢Ó¡¶È¡¢Ì©¹úºÍ¼ÓÄôó£¬ÖØÒªÕë¶ÔµÄÐÐÒµÔ̺¬¸ß¿Æ¼¼ÐÐÒµ¡¢Åú·¢ÒµºÍ½ÌÓýÁìÓò¡£Shade³õ´Î³öÏÖÓÚ2014Äê£¬ÖØÒªÕë¶ÔÔËÐÐWindowsµÄÖ÷»ú£¬Í¨¹ýÀ¬»øÓʼþºÍ·ì϶ÀûÓù¤¾ß°ü½øÐзַ¢¡£


Ô­ÎÄÁ´½Ó£ºhttps://unit42.paloaltonetworks.com/shade-ransomware-hits-high-tech-wholesale-education-sectors-in-u-s-japan-india-thailand-canada/


6¡¢×êÑÐÍŶӰ䲼ÀÕË÷Èí¼þGetCryptµÄ½âÃܹ¤¾ß

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 
EmsisoftÒѾ­°ä²¼ÁËÀÕË÷Èí¼þGetCryptµÄÃâ·Ñ½âÃÜÆ÷¡£GetCryptÊÇÒ»ÖÖͨ¹ýRIG EK·Ö·¢µÄÐÂÀÕË÷Èí¼þ£¬¸ÃÀÕË÷Èí¼þ»áÊ×ÏȲ鳭WindowsÊÇ·ñÉèÖÃΪÎÚ¿ËÀ¼Óï¡¢°×¶íÂÞ˹Óï¡¢¶íÓï»ò¹þÈø¿ËÓÈôÊÇÊÇÕâЩ˵»°£¬ÔòÖÕ³¡ÔËÐУ¬²»È»½«Ê¹ÓÃSalsa20ºÍRSA-4096Ëã·¨µÄ×éºÏÀ´¼ÓÃÜÎļþ£¬²¢ÔÚÎļþºó¸½¼ÓËæ»ú4¸ö×Ö·ûµÄÀ©´óÃû¡£ÆäÀÕË÷ÐÅÏ¢ÒªÇóÓû§ÁªÏµgetcrypt@cock[.]li½øÐи¶¿î¡£


Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/free-decryptor-released-for-getcrypt-ransomware-that-spreads-through-rig-exploit-kit-f4b5a4b2