BlackBerry°ä²¼¹ØÓÚBAHAMUT×éÖ¯µÄ·ÖÎö»ã±¨£»×êÑÐÔ±·¢ÏÖ¶ñÒânpm°üÇÔÈ¡²¢ÔÚGitHub°ä²¼Óû§Êý¾Ý
°ä²¼¹¦·ò 2020-10-12
BlackBerry°ä²¼Á˹ØÓÚBAHAMUTÍøÂç¼äµý×éÖ¯µÄ·ÖÎö»ã±¨£¬·¢ÏÔìä¶Ôµ±¾Ö¹ÙÔ±ºÍÖØÒªÐÐÒµÌáÒéÁË´óÁ¿¸ß¶È¸´ÔӵĹ¥»÷¡£×êÑÐÅú×¢£¬¸ÃÍÅ»ïµÄ»î¶¯ÁìÓò±ÈÒÔǰÒÔΪµÄÒª¿í·ºµÃ¶à£¬Ô̺¬ÁËGoogle PlayÉ̵êºÍApp StoreÖеÄÊ®¼¸¸ö¶ñÒâÀûÓ÷¨Ê½¡£´Ë±í£¬BlackBerry»¹ÒÔΪ£¬BAHAMUTÄܹ»ÓëÖÁÉÙÒ»Ãû0day¿ª·¢ÈËÔ±½Ó´¥£¬²¢ÀûÓÃ0day¹¥»÷¶à¸öÖ¸±ê£¬ÕâÔ¶Ô¶³¬³öÁË´óÎÞÊýÆäËûºÚ¿Í×éÖ¯µÄ¹¥»÷ˮƽ¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/cyber-espionage-bahamut-staggering/
2.×ôÖÎÑÇÖÝDHSй¶±¾µØ¶ùͯ¼°Æä¼Ò³¤µÄÃô¸ÐÐÅÏ¢

×ôÖÎÑÇÖÝÈËÃñ·þÎñ²¿£¨DHS£©ÉÏÖÜÎ尵ʾ£¬ÒòºÚ¿Í¹¥»÷µ¼Ö¶ùͯ¼°Æä¼Ò³¤µÄÃô¸ÐÐÅϢй¶¡£ÔÚ5ÔÂ3ÈÕÖÁ5ÔÂ15ÈÕÖ®¼ä£¬ºÚ¿Í»ñµÃÁ˶à¸öÔ±¹¤µç×ÓÓʼþÕÊ»§µÄ½Ó¼ûȨÏÞ£¬²¢ÇÒ±£ÁôÁ˺ܳ¤Ò»¶Î¹¦·ò¡£Õâ´Îй¶ÐÅÏ¢Ô̺¬¶ùͯ¼°¼ÒÍ¥³ÉÔ±µÄÈ«Ãû¡¢Óë¶ùͯµÄ¹ØÏµ¡¢¾ÓסµØÖ·¡¢DFCS°¸ÀýºÅ¡¢DFCS¼ø±ðºÅ¡¢µ®ÉúÈÕÆÚ¡¢´ºÇï¡¢ÁªÏµ´ÎÊý¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·¡¢Éç»á±£Ïպš¢Ò½ÁƲ¹Öú±êʶºÅ¡¢Ò½ÁƲ¹ÖúÒ½ÁƱ£ÏÕ±êʶºÅ¡¢Ò½ÁÆÌṩÕßÐÕÃûºÍÔ¤Ô¼ÈÕÆÚ¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/children-and-parent-info-exposed-in-georgia-dhs-data-breach/
3.FriendemicÒòÊý¾Ý¿âÅäÖÃÃýÎóй¶½ü300Íò¿Í»§Êý¾Ý

2020Äê9ÔÂ12ÈÕ£¬Comparitech×êÑÐÈËÔ±·¢ÏÖÓªÏú¹«Ë¾FriendemicÒòÊý¾Ý¿âÅäÖÃÃýÎóй¶½ü300Íò¿Í»§Êý¾Ý¡£Õâ´Îй¶µÄÊý¾ÝÔ̺¬¿Í»§µÄÐÕÃû¡¢µç×ÓÓʼþIDºÍµç»°ºÅÂ롣Ŀǰ£¬FriendemicÒÑÈ·ÈϸÃÊÂÎñ£¬Ðû³Æ´ËÊý¾Ý¿âÊÇ´æµµ±¸·Ý£¬²¢ÓÚ9ÔÂ15ÈÕ¶ÔÆä½øÐÐÁ˱£»¤¡£µ«FriendemicÉÐδȷÇÐ×¢Ã÷Õâ´ÎÊý¾Ýй¶µÄÓ°ÏìÁìÓò£¬Ö»ÊǰµÊ¾Êý¾Ý²»ÊôÓÚÆäÆû³µ¾ÏúÉ̿ͻ§¡£
ÔÎÄÁ´½Ó£º
https://www.hackread.com/marketing-firm-friendemic-customer-records-exposed/
4.×êÑÐÔ±·¢ÏÖ¶ñÒânpm°üÇÔÈ¡²¢ÔÚGitHub°ä²¼Óû§Êý¾Ý

SonatypeµÄ×êÑÐÈËÔ±·¢ÏÖÁ½¸önpm°üelectornºÍloadyaml£¬ÔÚÊܺ¦ÕßµÄÉ豸¸ßµÍÔØÓû§Êý¾Ý²¢°ä²¼µ½GitHubÉÏ¡£×êÑÐÈËÔ±°µÊ¾£¬ÕâÁ½ÖÖ°ü¶¼ÀûÓÃÁËTyposquatting¼¼Êõ£¬Õë¶ÔºÁÎÞ½äÐĵÄÓû§£¬Í¨¹ýÔì³É½ÏÓ×µÄÓ¡Ë¢ÃýÎó£¬ÓÕʹËûÃÇÔÚÆä»·¾³ÖÐ×°ÖöñÒâÈí¼þ°ü£¬¶ø²»ÊÇ×î³õ³ïËãÏÂÔØµÄÈí¼þ°ü¡£¸Ã°ü½«ÇÔÈ¡Êܺ¦ÕßµÄÊý¾Ý£¬Ô̺¬IPµØÖ·¡¢µØÀíµØÎ»¡¢Éè±¸Ö¸ÎÆ¡¢²¢½«ÆäÈ«Êý°ä²¼ÔÚGitHubÒ³ÃæÉÏ¡£
ÔÎÄÁ´½Ó£º
https://latesthackingnews.com/2020/10/11/malicious-npm-packages-published-users-data-on-github-page/
5.ÂíÈøÖîÈûÖݵÄÑ§ÇøÔâµ½¹¥»÷µ¼ÖÂѧÌÃÁÙʱ¹Ø¹Ø

ÂíÈøÖîÈûÖݵÄ˹ÆÕÁַƶûµÂ¹«Á¢Ñ§ÇøÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬µ¼ÖÂѧÌÃÁÙʱ¹Ø¹Ø¡£ÓÉÓÚCOVID-19ÔÒò£¬Ä¿Ç°¸ÃÑ§ÇøÒÔÔ¶³Ì½ø½¨Ä£Ê½ÊڿΡ£¸ÃÑ§ÇøÓÚ2020Äê10ÔÂ8ÈÕÔÚFacebook¡¢TwitterºÍ¼Ò³¤µç»°Öа䷢£¬ÓÉÓÚÍøÂçÎÊÌâ¹Ø¹ØÁËѧÌá£Ëæºó£¬Êг¤Domenic J. SarnoºÍ¶½Ñ§Daniel WarwickҲ֤ʵÁËÕâ´ÎÍøÂç¹¥»÷£¬²¢°ä·¢ÔÝÍ£Ô¶³Ì½ø½¨¡£Ä¿Ç°¸ÃÑ§ÇøÉв»È·¶¨¸´Ô¹¦·ò£¬¾ßÌåÈ¡¾öÓÚÀÕË÷Èí¼þ¹¥»÷¼ÓÃܵÄÉ豸ÊýÁ¿ÒÔ¼°¸´ÔËüÃÇËùÐèµÄ¹¦·ò¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/massachusetts-school-district-shut-down-by-ransomware-attack/
6.ÒѼÓÃܵÄTylerÏòRansomExxÖ§¸¶Êê½ðÀ´¸´Ô¼ÓÃÜÊý¾Ý

Tyler¼¼Êõ¹«Ë¾ÒÑÏòRansomExxÖ§¸¶ÁËÊê½ð£¬ÒÔ¸´ÔÔÚ×î½üµÄÀÕË÷Èí¼þ¹¥»÷Öб»¼ÓÃܵÄÎļþ¡£9ÔÂ23ÈÕ£¬TylerÔâµ½ÁËRansomExxÀÕË÷Èí¼þ¹¥»÷£¬Ö®ºóÆäµ±¼´¶Ï¿ªÁ˲¿ÃÅÍøÂ磬ÒÔ¶ôÔìÀÕË÷Èí¼þµÄ´«²¼²¢ÏÞ¶ÈÆä¿Í»§µÄ½Ó¼ûÁìÓò£¬Tyler°µÊ¾ÆäÊܵ½ÁËÑϳÁµÄÓ°Ïì²¢Ô¤¼Æ½«±ØÒª30ÌìÄÜÁ¦ÆëÈ«¸´ÔÔËÓª¡£ÐÂÎÅÈËÊ¿³Æ£¬Ä¿Ç°TylerÒÑÖ§¸¶Êê½ð£¬µ«ÊÇÉв»Ã÷ÏÔ¾ßÌåÓöȡ£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/tyler-technologies-paid-ransomware-gang-for-decryption-key/


¾©¹«Íø°²±¸11010802024551ºÅ