¶ò¹Ï¶à¶û´ó²¿ÃŹ«ÃñÒþÖÔй¶£¬Ô̺¬670Íò¶ùͯÐÅÏ¢£»2430ÍòLumin PDFÓû§ÐÅÏ¢ÔÚ°µÍøÂÛ̳й¶
°ä²¼¹¦·ò 2019-09-171.¶ò¹Ï¶à¶û´ó²¿ÃŹ«ÃñÒþÖÔй¶£¬Ô̺¬670Íò¶ùͯÐÅÏ¢
×êÑÐÈËÔ±·¢ÏÖÒ»¼Ò±¾µØ¹«Ë¾NovaestratµÄElasticsearch·þÎñÆ÷¶³öÁ˶ò¹Ï¶à¶û´óÎÞÊý¹«ÃñµÄÒþÖÔÐÅÏ¢¡£¶ò¹Ï¶à¶ûµÄÈ˶¡»ùÊýΪ1660Íò£¬¶ø¸ÃÊý¾Ý¿âÔ̺¬½ü2080ÍòÌõÓû§¼Í¼£¬³¬¹ýÁ˸ùúµÄÈ˶¡Êý¾Ý£¬ÆäÔÒòÊÇÊý¾Ý¿âÖÐÔ̺¬Ò»Ð©³Á¸´¼Í¼ºÍéæÃü¹«ÃñµÄ¼Í¼¡£Ð¹Â¶µÄÊý¾ÝÔ̺¬ÐÕÃû¡¢¼ÒÍ¥³ÉÔ±/¼Ò×åÊ÷¡¢¹«Ãñ×¢²áÊý¾Ý¡¢²ÆÕþ¼°¹¤×÷ÐÅÏ¢¡¢³µÁ¾ÐÅÏ¢µÈ¡£Êý¾Ý¿âÖл¹Ô̺¬µ±¾ÖÔ±¹¤ÐÅÏ¢ºÍ677Íò¶ùͯÐÅÏ¢£¬ÒÔ¼°700ÍòÌõ²ÆÕþ¼Í¼ºÍ250ÍòÌõ³µÁ¾¼Í¼¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/database-leaks-data-on-most-of-ecuadors-citizens-including-6-7-million-children/
2.2430ÍòLumin PDFÓû§ÐÅÏ¢ÔÚ°µÍøÂÛ̳й¶
Ò»ÃûºÚ¿ÍÔÚ°µÍøÂÛ̳Éϰ䲼ÁËLumin PDF¹«Ë¾µÄÆëÈ«Êý¾Ý¿âÏÂÔØÁ´½Ó£¬¸ÃÊý¾Ý¿âΪ4.06GBµÄCSVÎļþ£¬ÆäÖÐÔ̺¬2438ÍòÌõÓû§¼Í¼¡£Êý¾ÝÔ̺¬Óû§µÄÈ«Ãû¡¢ÓʼþµØÖ·¡¢ÐÔ±ð¡¢Ëµ»°ÉèÖᢹþÏ£ÃÜÂë»ò¹È¸è½Ó¼ûÁîÅÆ¡£ZDNetÑéÖ¤ÁËÕâЩÊý¾ÝµÄÕæÊµÐÔ¡£ºÚ¿Í³ÆÕâЩÊý¾ÝÀ´×ÔÓÚ2019Äê4Ô·ݸù«Ë¾Â¶³öÔÚ¹«ÍøÉϵÄMongoDBÊý¾Ý¿âÖУ¬¸ÃÊý¾Ý¿â²¢Î´Êܵ½ÃÜÂë±£»¤£¬²¢Ëæºó±»ÀÕË÷Èí¼þ·ÛËé¡£Lumin PDFÉÐδ¶Ô´ËʽøÐлظ´¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/data-of-24-3-million-lumin-pdf-users-shared-on-hacking-forum/
3.EmotetÔÚÆ§¾²4¸öÔºóÔÙ´ÎÌáÒéÐÂÀ¬»øÓʼþ»î¶¯
×Ô5Ôµ׽øÈë¹ÑÑÔÒÔÀ´£¬½©Ê¬ÍøÂçEmotetÒѾƧ¾²Á˽ü4¸öԵŦ·ò£¬ÔÚ´ËÆÚ¼äEmotetµÄC&C·þÎñÆ÷ÖÕ³¡ÁËÏòÊÜϰȾÉ豸·¢ËͺÅÁî¡£°²È«×êÑÐÔ±Raashid Bhat¹Û²ìµ½EmotetÔÚ9ÔÂ16ºÅÔÙ´ÎÌáÒéÁËеÄÀ¬»øÓʼþ»î¶¯£¬Ä¿Ç°ÕâЩÀ¬»øÓʼþÖØÒªÕë¶Ô²¨À¼ºÍµÂ¹úÓû§£¬ÓʼþÖÐÔ̺¬¶ñÒ⸽¼þ»òÏÂÔØ¶ñÒâÈí¼þµÄÁ´½Ó¡£Õâ¸öÐµĹ¥»÷»î¶¯ÔÚ×êÑÐÈËÔ±µÄÔ¤¼ÆÖ®ÖУ¬ÓÉÓÚÔÚ´ËǰµÄ±¨Â·ÖÐEmotetµÄC&C·þÎñÆ÷ÔÚ8Ôµ×ÔٴνøÈë»îԾ״̬£¬µ«ËüÃDz¢Ã»ÓÐÂíÉϽøÈëÀ¬»øÓʼþ·¢ËÍģʽ£¬¶øÊÇÔÚ·Ö·¢EmotetµÄС°ºáÏòÒÆ¶¯¡±ºÍ¡°Í´´¦ÇÔÈ¡¡±Ä£¿é¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/emotet-todays-most-dangerous-botnet-comes-back-to-life/
4.AstarothбäÖÖÀûÓÃFacebookºÍYouTubeÀ´Èƹý¼ì²â
Cofense×êÑÐÈËÔ±·¢ÏÖAstarothľÂíµÄÒ»¸öбäÌåÀûÓÃFacebookºÍYouTubeÀ´Èƹý¼ì²â¡£Õâ¸öеĴ¹µö»î¶¯ÖØÒªÕë¶Ô°ÍÎ÷¹«Ãñ£¬Ï°È¾Á´Ï൱¸´ÔÓ£¬ÒÔÒ»¸ö.htm¸½¼þÆðÍ·£¬µ±Óû§µã»÷¸½¼þʱ£¬»áÏÂÔØÒ»¸ö.zipÎļþ£¬½âѹËõµÃµ½Ò»¸ö.lnkÎļþ£¬¶øºó´ÓÒ»¸öCloudflare workerÓòÃû¸ßµÍÔØJavaScript´úÂ룬×îºóÔÙÏÂÔØÓÃÓÚ»ìºÏºÍÖ´ÐÐAstarothµÄ¶ñÒâÄ£¿éºÍpayload¡£×êÑÐÈËÔ±¹Û²ìµ½¸ÃAstaroth±äÌåÀûÓÃYouTubeºÍFacebookµÄÓû§ÐÅÏ¢Ò³ÃæÀ´ÍйܺÍÊØ»¤C2ÅäÖÃÊý¾Ý¡£ÕâÖÖ¼¼ÇÉ¿ÉÈÆ¹ýÄÚÈݹýÂ˵ÈÍøÂ簲ȫ´ëÊ©¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/91296/malware/astaroth-trojan-fb-youtube.html
5.·¸×ïÍÅ»ï¼ÙÒ⹫˾¸ß¹Ü²É°ìÊý×ÖÖ¤ÊéÀ´´«²¼¶ñÒâÈí¼þ
ReversingLabs·¢ÏÖÒ»¸öеķ¸×ïÍÅ»ï¼Ù×°³ÉºÏ·¨»ú¹¹µÄ¸ß¹ÜÊÔͼڲÆÐԵزɰìÊý×ÖÖ¤Ê飬¶øºó½«ÕâЩºÏ·¨Ö¤ÊéÔÚ°µÍøÉÏÏúÊÛÒÔ¶Ô¶ñÒâÎļþ£¨ÖØÒªÊǸæ°×Èí¼þ£©½øÐÐÊðÃû¡£×êÑÐÈËÔ±¸ÅÊöÁ˸ÃڲƻµÄ¼¸¸öÖØÒª²½Ö裬Ô̺¬Í¨¹ý×êÑй«¿ªµÄÐÅÏ¢²¢×ñÑÌØ¶¨µÄ³ß¶ÈÀ´È·¶¨Òª¼Ù×°µÄÖ¸±ê£¬¹¹½¨¿´ÆðÀ´ºÏ·¨µÄ»ù´¡ÉèÊ©£¨ÀýÈç×¢²áÓòÃû¡¢³Á¶¨Ïòµç×ÓÓʼþµÈ£©ÒÔºýŪ֤ÊéÐû¸æ»ú¹¹£¬×îºó²É°ìÖ¤Êé²¢ÔÚ°µÍøÏúÊÛ¡£×êÑÐÈËÔ±¹Û²ìµ½ÕâЩ֤Êé±»ÓÃÓÚ¶ÔOpenSupdaterµÈ¸æ°×Èí¼þ½øÐÐÊðÃû¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/threat-actor-buys-digital-certs-spreads-malware/148345/
6.ÃÜÂëÖÎÀíÆ÷LastPass²å¼þ·ì϶¿Éµ¼ÖÂÍ´´¦Ð¹Â¶
LastPassÃÜÂëÖÎÀíÆ÷²å¼þÖеķì϶¿ÉÔÊÐí¹¥»÷ÕßÇÔÈ¡Óû§×îºóµÇÂ¼ÍøÒ³µÄÍ´´¦¡£¹È¸è°²È«×êÑÐÔ±Tavis Ormandy·¢ÏÖ¹¥»÷Õß¿ÉΪʹÓÃlastpassµÇ¼ÕË»§µÄÓû§´´½¨Ò»¸öÓÐЧµÄµã»÷½Ù³Ö³¡¾°£¬½«Æä³Á¶¨ÏòÖÁÔ̺¬¶ñÒâiframeµÄÍøÕ¾¡£Í¨¹ýÔÚiframeÖиéÖÃÓÃÓÚÌîдÃÜÂëµÄµ¯´°£¬¹¥»÷Õß¿ÉÌø¹ýÑéÖ¤Á´²¢ÇÔÈ¡µ±Ç°±êÇ©×îºó»º´æµÄÖµ¡£ÕâÒâζ×Åͨ¹ýµã»÷½Ù³ÖÄܹ»µ¼ÖÂÔÚµ±Ç°±êÇ©ÉϵǼµÄ×îºóÒ»¸öÍøÕ¾µÄÍ´´¦Ð¹Â¶¡£¸ÃÎÊÌâÖØÒªÓ°ÏìÁËChromeºÍOperaä¯ÀÀÆ÷¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/password-revealing-bug-quickly-fixed-in-lastpass-extensions/


¾©¹«Íø°²±¸11010802024551ºÅ