ÒÁÀʷǹٷ½TelegramÀûÓÃй¶4200ÍòÓû§Êý¾Ý£»Õë¶ÔÑÇÖÞµÄHoly waterË®¿Ó¹¥»÷
°ä²¼¹¦·ò 2020-04-011.ÒÁÀʷǹٷ½TelegramÀûÓÃй¶4200ÍòÓû§¼Í¼
°²È«×¨¼Ò±«²ª¡¤µÏÑÇÇÙ¿Æ£¨Bob Diachenko£©·¢ÏÖÒÁÀʷǹٷ½TelegramÀûÓõÄ4200Íò×¢²áÓû§ÐÅÏ¢ÔÚÍøÉÏй¶¡£ÒÁÀÊÓÚ2018ËêÊ×ÓÀÔ¶¹Ø±ÕÁËTelegram£¬Òò¶øºÜ¶àÓû§×ª¶øÊ¹Ó÷ǹٷ½°æ±¾µÄTelegram¡£ÕâЩÊý¾ÝÊÇÓÉHunting systemÍŶÓÔÚÒ»¸ö¿É¹«¿ª½Ó¼ûµÄElasticsearch¼¯ÈºÉ϶³öµÄ£¬ÔÚ3ÔÂ25ÈÕDiachenkoÏòÍйܷþÎñÉ̻㱨ÁË´ËÊÂÎñºó£¬¸ÃÊý¾Ý¿âÒѱ»¹Ø¹Ø¡£Diachenko°µÊ¾ÖÁÉÙÓÐÒ»¸öÓû§ÒѾ½Ó¼ûÁËÕâЩÊý¾Ý²¢½«Êý¾Ý°ä²¼µ½Á˺ڿÍÂÛ̳¡£Ð¹Â¶µÄ¼Í¼Ô̺¬Óû§µÄÕË»§ID¡¢Óû§Ãû¡¢µç»°ºÅÂë¡¢¹þÏ£¼°ÃÜÔ¿¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/100810/data-breach/unofficial-telegram-fork-leak.html
2.ÃÀ¹ú¹²ºÍµ³ÀƱAPP Campaign Sidekickй¶ѡÃñÊý¾Ý
ÃÀ¹ú¹²ºÍµ³Ê¹ÓõÄÑ¡ÃñÁªÏµºÍÀƱÀûÓÃCampaign Sidekickй¶ÁËÑ¡ÃñµÄÃô¸ÐÐÅÏ¢¡£Campaign SidekickÀûÓÿÉÔ®ÊÖÕû¶ÙÀƱ¹ý³ÌÖÐÓëÑ¡ÃñÖ®¼äµÄ»¥¶¯ÐÅÏ¢¡£2ÔÂ12ÈÕ°²È«³§ÉÌUpGuard·¢ÏÖapp.campaignsidekick.voteÉϵÄgitĿ¼¿Éͨ¹ýÍøÂ繫¿ª½Ó¼û£¬ÏÂÔØµ½µÄÎļþÖÐÔ̺¬Ò»Ð©Ãô¸ÐÊý¾Ý£¬Campaign SidekickÓÚ2ÔÂ15ÈÕÈ·ÈÏÁËÕâһй¶ÊÂÎñ£¬²¢¶ÔÊý¾Ý½øÐÐÁ˱£»¤¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/voter-data-exposed-app-us-elections/
3.ÍòºÀ¾ÆµêÅû¶ÐÂÊý¾Ýй¶ÊÂÎñ£¬Ó°Ïì520ÍòÓû§
3ÔÂ31ÈÕÍòºÀ¾ÆµêÅû¶һÏîÐÂÊý¾Ýй¶£¬¸ÃÊÂÎñÓ°ÏìÁ˳¬¹ý520ÍòʹÓÃÍòºÀÂÃÏí¼ÒAPPµÄ¾Æµê¿ÍÈË¡£Æ¾¾ÝÆäÍøÕ¾Éϰ䲼µÄÊý¾Ýй¶֪ͨ£¬ÍòºÀÓÚ2Ôµ׻ñϤ¸ÃÊÂÎñ£¬Æäʱ·¢ÏÖºÚ¿ÍÀûÓÃÁ½ÃûÔ±¹¤µÄµÇ¼ʹ´¦½Ó¼ûÁ˸ÃAPPµÄºó¶ËϵͳºÍ¹«Ë¾µÄ¿Í»§ÐÅÏ¢¡£ÍòºÀ³ÆÕâ´ÎºÚ¿Í¹¥»÷ÊÂÎñÄܹ»×·Òäµ½1ÔÂÖÐÑ®£¬µ«Ã»ÓÐй©ÓйØÊÂÎñ²úÉúµÄ¸ü¶àϸ½Ú¡£¹¥»÷ÕßÄܹ»½Ó¼ûµÄÊý¾ÝÔ̺¬¿ÍÈ˵ÄÁªÏµÈËÐÅÏ¢¡¢»áÔ¹ØË»§ÐÅÏ¢¡¢ÆäËüÓ×ÎÒÐÅÏ¢¡¢Í¬°é¹ØÏµºÍ´ÓÊô¹ØÏµÒÔ¼°Æ«ºÃ¡£ÍòºÀÍÆ³öÁËÒ»¸öÃÅ»§ÍøÕ¾£¬ÓÃÓÚÔ®ÊÖÓû§²é¿´ÆäÊý¾ÝÊÇ·ñй¶¡£ÕâÊǸþƵêÔÚ´Óǰ16¸öÔÂÖеڶþ´ÎÔâ·êÊý¾Ýй¶ÊÂÎñ¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/marriott-discloses-new-data-breach-impacting-5-2-million-hotel-guests/
4.Turnkey Consulting°ä²¼¡¶SAP°²È«×êÑл㱨¡·
ƾ¾ÝTurnkey ConsultingµÄ¡¶SAP°²È«×êÑл㱨¡·£¬³¬¹ýÈý·ÖÖ®¶þ£¨68.8£¥£©µÄSAPÓû§ÒÔΪÔÚÏÈǰµÄSAPÖ´Ðйý³ÌÖÐËûÃǵÄ×éÖ¯¶ÔIT°²È«ÐԵĹØ×¢²»¼°£¬¶ø53.4£¥µÄÓû§°µÊ¾ÔÚÉ󼯹ý³ÌÖз¢ÏÖSAP°²È«·ì϶¡°Ê®·Ôìձ顱¡£¸Ã×êÑл¹·¢ÏÖ£¬´óÎÞÊýÊÜ·ÃÕßûÓÐ×ã¹»µÄÄÜÁ¦À´ÖÎÀí·çÏÕ¡£Îå·ÖÖ®Ò»£¨20.8£¥£©µÄÈËÒÔΪ´óÎÞÊýÆóÒµ²»¾ß±¸ÓÐЧ±£»¤ÆäSAPÀûÓ÷¨Ê½ºÍ»·¾³µÄ¼¼ÊõºÍ¹¤¾ß£¬ÓÐ64.3£¥µÄÈ˰µÊ¾ËûÃÇÖ»Óв¿Ãż¼ÊõºÍ¹¤¾ß¡£×êÑл¹Åú×¢ÈËÃÇÔ½À´Ô½Òâʶµ½µ±½ñÆóÒµËùÃæ¶ÔµÄ°²È«ÌôÕ½£¬Òò¶øÑ¡È¡¡°Éè¼Æ°²È«¡±×÷Ϊ½â¾ö¹æ»®£¬74.0£¥µÄÈ˵«Ô¸IT°²È«ÐÔÔÚ½«À´µÄSAP²¿ÊðÖеõ½¸ü¸ßµÄÆ÷³Á£¬89.6£¥µÄÈËÔÞ³ÉÓ¦ÀñƸ°²È«×¨¼ÒÀ´Ö§³ÔìäSAP S/4 HANAת»»´òËã¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2020/03/31/sap-security-remediation/
5.FBIÖÒ¸æÀÄÓÃKwampirsµÄÓɹú¶ÈÖ§³ÖµÄ¹©¸øÁ´¹¥»÷
FBIÔÚ¼¸ÖÜÄÚµÚÈý´Î°ä²¼¾¯±¨£¬ÖÒ¸æÓɹú¶ÈÖ§³ÖµÄ¹¥»÷ÕßʹÓÃKwampirs¶ñÒâÈí¼þÌáÒéµÄ¹©¸øÁ´¹¥»÷¡£FBIÇ¿µ÷¸ÃAPT×éÖ¯µÄÖ¸±êÊÇijЩÔÚÓ¦¶ÔCOVID-19µÄÒ½ÁƱ£½¡»ú¹¹¡£³ýÁ˰䲼PIN£¨¸öÈËÐÐҵ֪ͨ£©±í£¬FBI»¹°ä²¼ÁËÁ½¸öFlash¾¯±¨£¬ÆäÖÐÒ»¸öÔ̺¬ÓÃÓÚ¼ø±ðKwampirsµÄYARA¹æ¶¨£¬ÁíÒ»¸öÔ̺¬ÓëIOCÓйصļ¼Êõ»ã±¨¡£ÕâÁ½¸öFlash¾¯±¨¶¼ÊÇ2ÔºÍ1Ô¾¯±¨¼°ÆäËüÐÅÏ¢µÄ³Áа䲼¡£FBIµ÷²éÈËÔ±»¹°µÊ¾£¬¸Ã×éÖ¯×Ô2016ÄêÒÔÀ´¾ÍÒ»Ïò»îÔ¾¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/100794/breaking-news/fbi-alert-kwampirs-malware.html
6.¿¨°Í˹»ùÅû¶Õë¶ÔÑÇÖÞµÄHoly waterË®¿Ó¹¥»÷
¿¨°Í˹»ù×êÑÐÍŶÓÅû¶Õë¶ÔÑÇÖÞµÄÒ»¸öHoly waterË®¿Ó¹¥»÷£¬¹¥»÷Õßͨ¹ýÈëÇÖÍøÕ¾ºÍ·Ö·¢ÐéαAdobe Flash¸üеķ½Ê½Õë¶ÔÒ»¸öÑÇÖÞ×ڽ̺Í×åÒáȺÌå¡£×êÑÐÈËÔ±ÓÚ2019Äê12ÔÂ4ÈÕ·¢ÏÖÁËÕâÒ»¹¥»÷»î¶¯£¬½øÒ»²½µÄ×êÑÐÅú×¢¸Ã»î¶¯×Ô2019Äê5ÔÂÆðÍ·¾ÍÒ»Ïò½øÐС£¹²Óн«½ü10¸öÍøÕ¾±»ÉøÈ룬ÕâÐ©ÍøÕ¾ÊôÓÚ¹«¹²»ú¹¹¡¢´È±¯»ú¹¹ºÍ×éÖ¯µÈ£¬ÆäÖÐÒ»Ð©ÍøÕ¾£¨ÍйÜÔÚͳһ·þÎñÆ÷ÉÏ£©ÒÀÈ»Êܵ½Íþв¡£¹¥»÷ÕߵĻָ±êÉв»Ã÷ÏÔ£¬×êÑÐÈËÔ±Ò²ÎÞ·¨½«ÕâЩ¹¥»÷ÓëÈκÎÒÑÖªµÄAPT×éÖ¯ÓйØÁª¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/holy-water-ongoing-targeted-water-holing-attack-in-asia/96311/


¾©¹«Íø°²±¸11010802024551ºÅ