Å·ÖÞÍøÂ簲ȫ¾Ö°ä²¼º£Ê²¿ÃÅÍøÂ簲ȫָÄÏ£»ÒøÐÐľÂíGinpбäÖÖ½è¼ø¶ñÒâÈí¼þAnubisµÄ´úÂë

°ä²¼¹¦·ò 2019-12-02

1.Å·ÖÞÍøÂ簲ȫ¾Ö°ä²¼º£Ê²¿ÃÅÍøÂ簲ȫָÄÏ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Å·ÖÞÍøÂ簲ȫ¾Ö£¨ENISA£©ÒÔ¡¶¸Û¿ÚÍøÂ簲ȫ-º£Ê²¿ÃÅÍøÂ簲ȫʵ¼Ê¡·ÎªÌâ°ä²¼Á˺£Ê²¿ÃÅÍøÂ簲ȫָÄÏ£¬Îª¸Û¿ÚÉú̬ϵͳÓÈÆäÊǸۿڵ±¾ÖºÍ´¬²ºÔËÓªÉÌÖеÄCIOºÍCISOÔì¶©ÍøÂ簲ȫսÊõÌṩÁìµ¼ºÍÔ®ÊÖ ¡£¸ÃÖ¸ÄÏÁгöÁ˸ۿÚÉúÌ¬ÏµÍ³Ãæ¶ÔµÄÖØÒªÍþв£¬²¢ÃèÊöÁË¿ÉÄܶԸۿÚÉú̬ϵͳÔì³ÉÓ°ÏìµÄ¹Ø¼üÍøÂç¹¥»÷³¡¾° ¡£¸ÃÖ¸ÄÏΪÖն˱£»¤ºÍÐÔÃüÖÜÆÚÖÎÀí¡¢·ì϶ÖÎÀí¡¢ÈËÁ¦×ÊÔ´°²È«¡¢¹©¸øÁ´ÖÎÀíµÈÉè¼ÆÁ˰²È«´ëÊ© ¡£


Ô­ÎÄÁ´½Ó£º

https://www.enisa.europa.eu/publications/port-cybersecurity-good-practices-for-cybersecurity-in-the-maritime-sector/


2.×êÑл㱨ÏÔʾ½ü60%µÄ¶ñÒâ¸æ°×À´×ÔÈý¸ö¸æ°×ÉÌ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚConfiantµÄ2019ÄêµÚÈý¼¾¶ÈÐèÒªÖÊÁ¿»ã±¨ÖУ¬¸Ã¹«Ë¾·ÖÎöÁË2019Äê1ÔÂ1ÈÕµ½9ÔÂ20ÈÕÖ®¼äµÄ1200Òڴθæ°×չʾ£¬ÒÔ¶Ô¸÷Àà¶ñÒâ¸æ°×»î¶¯½øÐÐϸ·Ö ¡£ÔÚÓÉConfiant¼à¿ØµÄ75¸öSSP£¨¸æ°×ÉÌ£©ÖУ¬³¬¹ý60%µÄ¶ñÒâ¸æ°×À´×ÔÆäÖÐÈý¸ö£¬±ðÀëΪSSP-H¡¢SSP-IºÍSSP-D£¬ÆäÖÐÒ»¸öSSPÉõÖÁÕ¼µ½ÁË30%ÒÔÉÏ ¡£ÔÚ2019ÄêµÚÈý¼¾¶È£¬Ëĸö·¸×ïÍÅ»ïÕÆ¹Ü·Ö·¢´óÎÞÊý¶ñÒâ¸æ°×£¬Ô̺¬Scamclub¡¢eGobbler¡¢RunPMKºÍZirconium ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/almost-60-percent-of-malicious-ads-come-from-three-ad-providers/


3.SMA W2ÖÇÄÜÊÖ±©Â¶³ö5000¶à¶ùͯµÄλÏàÐÅÏ¢


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝAV-TESTµÄÎïÁªÍø²âÊÔ²¿ÃŰ䲼µÄÒ»·Ý»ã±¨£¬SMA W2¶ùͯÖÇÄÜÍó±í´æÔÚ¶à¸ö·ì϶£¬µ¼ÖÂ5000¶àÃû¶ùͯµÄλÏàÐÅϢ¶³ö ¡£Ê×ÏÈÆäWeb API·þÎñÆ÷ûÓÐÑéÖ¤Éí·ÝÑéÖ¤ÁîÅÆµÄÓÐЧÐÔ£¬µ¼Ö¹¥»÷ÕßÄܹ»Ïνӵ½¸ÃWeb API£¬ä¯ÀÀËùÓÐЧ»§µÄIP²¢ÍøÂç¶ùͯ¼°Æä¸¸Ä¸µÄÊý¾Ý ¡£×êÑÐÈËÔ±¿ÉÄܼø±ð³ö5000¶àÃû¶ùͯºÍ10000¶àÃû¼Ò³¤µÄÕË»§£¬´óÎÞÊý¶ùͯλÓÚÅ·ÖÞ£¬Ô̺¬ºÉÀ¼¡¢²¨À¼¡¢ÍÁ¶úÆä¡¢µÂ¹ú¡¢Î÷°àÑÀºÍ±ÈÀûʱµÈ¹ú¶È ¡£¹¥»÷Õß»¹Äܹ»Í¨¹ýÅú¸ÄÖ÷ÅäÖÃÎļþÖеÄÓû§IDÀ´Ç¿ÔìÓë¶ùͯÖÇÄÜÍó±íÅä¶Ô£¬ÕâÒ»²Ù×÷ÎÞÐ踸ÕË»§µÄÓÊÏ䵨ַºÍÃÜÂë ¡£Åä¶Ôºó£¬¹¥»÷Õß¾ÍÄܹ»¸ú×Ù¶ùͯµØÎ»²¢²¦´òÓïÒôµç»° ¡£µÂ¹ú·ÖÏúÉÌPearlÒÑÔÚ½Óµ½»ã±¨ºóϼÜÁ˸ÃÖÇÄÜÍó±í ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/cheap-kids-smartwatch-exposes-the-location-of-5000-children/


4.ÒøÐÐľÂíGinpбäÖÖ½è¼ø¶ñÒâÈí¼þAnubisµÄ´úÂë


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ThreatFabric°²È«×¨¼Ò·¢ÏÖAndroidÒøÐÐľÂíGinpµÄ×îбäÖÖ¿ÉÇÔÈ¡µÇ¼ʹ´¦ºÍÐÅÓþ¿¨Êý¾Ý ¡£×êÑÐÈËÔ±ÒÔΪGinp×Ô6Ô·ÝÒÔÀ´Ò»Ïò»îÔ¾£¬¸Ã¶ñÒâÈí¼þÒѽøÐÐÁËÎå´Î³Á´ó¸üУ¬ÆäÖÐ×î½üµÄ¸üÐÂ½è¼øÁËÒøÐÐľÂíAnubisµÄ´úÂë ¡£¸Ã±äÌå²»ÔÙÕë¶ÔÉç½»APP£¬¶øÊÇÕë¶ÔÒøÐУ¬ÖØÒªÊÇÎ÷°àÑÀÒøÐÐ ¡£ÆäÖ¸±êÁбíÔ̺¬7¼Ò·ÖÆçµÄÒøÐУ¬Ô̺¬Caixa¡¢Bankinter¡¢Bankia¡¢BBVA¡¢EVO Banco¡¢KutxabankºÍSantander ¡£×êÑÐÈËÔ±ÒÔΪ¸Ã¶ñÒâÈí¼þµÄ×÷ÕßÔÚ½«ÆäÒµÎñÀ©´óÖÁÆäËü¹ú¶È ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/94533/cyber-crime/ginp-android-trojan-anubis.html


5.CStealer¿ÉÇÔÈ¡ChromeÍ´´¦²¢·¢ËÍÖÁÔ¶³ÌMongoDB


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÐÂWindowsľÂíCStealer¿ÉÇÔÈ¡±£ÁôÔڹȸèChromeÃÜÂëÖÎÀíÆ÷ÖеĵǼʹ´¦ ¡£Æ¾¾ÝMalwareHunterTeamµÄ·ÖÎö£¬¸Ã¶ñÒâÈí¼þûÓн«ÇÔÈ¡µÄÃÜÂë±àÒë³ÉÎļþ²¢·¢ËÍÖÁ¹¥»÷Õß½ÚÔìµÄC2·þÎñÆ÷£¬¶øÊÇÖ±½ÓÏνӵ½Ô¶³ÌMongoDBÊý¾Ý¿â²¢Ê¹ÓÃËüÀ´´æ´¢ÇÔÈ¡µÄÍ´´¦ ¡£Îª´Ë£¬¸Ã¶ñÒâÈí¼þÓ²±àÂëÁËMongoDBµÄÍ´´¦£¬²¢ÀûÓÃMongoDB CÇý¶¯·¨Ê½×÷Ϊ¿Í»§¶Ë¿âÏνӵ½Ô¶³ÌÊý¾Ý¿â ¡£ÕâʹµÃÈκÎÈ˶¼Äܹ»Í¨¹ý¸ÃÓ²±àÂëµÄÍ´´¦½Ó¼û±»µÁµÄÓû§ÃÜÂë ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-chrome-password-stealer-sends-stolen-data-to-a-mongodb-database/


6.TrueDialogÒâ±íй¶Êý°ÙÍòÌõ¿Í»§¶ÌÐżÍ¼


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°²È«×êÑÐÈËÔ±Noam RotemºÍRan Locar·¢ÏÖÒ»¸öÔ̺¬Êý°ÙÍòÌõ¶ÌÐżÍ¼µÄ¶³öÊý¾Ý¿â£¬¸ÃÊý¾Ý¿âÊôÓÚTrueDialog£¬ÆäÖдó²¿ÃŶÌÐÅÊÇÓÉÆóÒµ·¢Ë͸øËüÃǵÄDZÔÚ¿Í»§µÄ ¡£TrueDialogÊǵ¿ËÈøË¹ÖݰÂ˹͡ÊеÄÒ»¼ÒΪÆóÒµºÍ¸ßµµ½ÌÓý»ú¹¹ÌṩÉÌÓöÌÕÛ·þÎñµÄ¹«Ë¾£¬¸ÃÊý¾Ý¿â´æ´¢Á˿ͻ§·¢Ë͵ĶÌÐÅ£¬µ«ÓÉÓÚδÉèÃÜÂ룬ʹµÃ»¥ÁªÍøÉϵÄÈκÎÈ˶¼¿É²é¿´Êý¾Ý ¡£²¿ÃżÍ¼Ô̺¬Óйشóѧ²ÆÕþÀûÓ÷¨Ê½µÄÐÅÏ¢¡¢ÆóÒµµÄÕÛ¿ÛÂëÓªÏúÐÅÏ¢¡¢ÔÚÏßÒ½ÁÆ·þÎñµÄÑéÖ¤Âë¡¢FacebookºÍGoogleÕÊ»§µÄÍøÕ¾ÃÜÂë³ÁÖú͵Ǽ´úÂëÉõÖÁTrueDialog¿Í»§µÄÓû§ÃûºÍÃÜÂëµÈ ¡£


Ô­ÎÄÁ´½Ó£º

https://techcrunch.com/2019/12/01/millions-sms-messages-exposed/