Akamai·¢ÏÖн©Ê¬ÍøÂçÀûÓñÈÌØ±ÒÂòÂô°µ²ØC2µØÖ·£»Ó¡¶Èµ±¾ÖÍøÕ¾Ð¹Â¶³¬¹ý800ÍòÌõCOVID-19¼ì²âÁ˾Ö

°ä²¼¹¦·ò 2021-02-26

1.Akamai·¢ÏÖн©Ê¬ÍøÂçÀûÓñÈÌØ±ÒÂòÂô°µ²ØC2µØÖ·


1.jpg


Akamai·¢ÏÖн©Ê¬ÍøÂçÔÚÀûÓñÈÌØ±ÒÇø¿éÁ´ÂòÂôÀ´°µ²ØC2µØÖ·¡£¹¥»÷ÀûÓÃÓ°ÏìÁËHadoop YarnºÍElasticsearchµÈÈí¼þÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©·ì϶ £¬ÀýÈçCVE-2015-1427ºÍCVE-2019-9082¡£ÎªÁ˽«Ç®°üÊý¾Ýת»»ÎªIPµØÖ· £¬ºÚ¿ÍʹÓÃËĸöµ¥ÐеÄbash¾ç±¾Ïò±ÈÌØ±ÒÇ®°üµÄÇø¿éÁ´×ÊÔ´ÖÎÀíÆ÷API·¢ËÍHTTPÒªÇó £¬½«×î½üÁ½¸öÂòÂôÖеÄSatoshiֵת»»Îª±¸ÓÃC2µØÖ·¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/this-botnet-is-abusing-bitcoin-blockchains-to-stay-in-the-shadows/ 


2.Malwarebytes·¢ÏÖÐÂAPT LazyScripter¶Ô×¼½»Í¨³©Òµ


2.jpg


°²È«¹«Ë¾Malwarebytes·¢ÏÖеÄAPT×éÖ¯LazyScripter¶Ô×¼½»Í¨³©Òµ¡£LazyScripter×Ô2018ÄêÒÔÀ´Ò»Ïò»îÔ¾ £¬ÀûÓÃÍøÂç´¹µö¹¥»÷Õë¶Ô¼ÓÄôóÒÆÃñ¡¢ÇóÖ°º½¿Õ¹«Ë¾ºÍ¹ú¼Êº½¿ÕÔËÊäЭ»á£¨IATA£©¡£LazyScripterÔÚÆä×îÐµĹ¥»÷»î¶¯Ê¹ÓÃÁËÃâ·ÑµÄ¶ñÒâÈí¼þOctopusºÍKoadic £¬Æä»¹ÔøÊ¹ÓùýLuminosityLink¡¢RMS¡¢Quasar¡¢njRatºÍRemcosµÈRAT¡£´Ë±í £¬¸ÃÍŻﻹ½«Æä¹¤¾ß¼¯ÍйÜÔÚGitHubÉÏ £¬ÕâÊÇÒ»¸öÒÁÀÊAPT×éÖ¯´ÓǰʹÓõÄÒ»ÖÖÕ½Êõ¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/new-lazyscripter-hacking-group-targets-airlines


3.Ó¡¶Èµ±¾ÖÍøÕ¾Ð¹Â¶³¬¹ý800ÍòÌõCOVID-19¼ì²âÁ˾Ö


3.jpg


°²È«×êÑÐÔ± Sourajeet Majumder·¢ÏÖÓ¡¶Èµ±¾ÖÍøÕ¾Ð¹Â¶Á˳¬¹ý800ÍòÌõCOVID-19¼ì²âÁ˾Ö¡£¾ÝϤÕâЩÊý¾ÝÀ´×ÔÓ¡¶ÈÎ÷ÃϼÓÀ­¹úÎÀÉú¸£Àû²¿ £¬Ô̺¬ÁËÓйع«ÃñµÄÃô¸ÐÐÅÏ¢ £¬ÀýÈçÐÕÃû¡¢´ºÇï¡¢ÑùÆ·¼ì²âµÄÈÕÆÚºÍ¹¦·ò¡¢¾ÓסµØÖ·µÈ¡£Ð¹Â¶Ô­ÒòÊÇ·¢Ë͸ø¼ì²âÕߵĶÌÐŵÄURLÖÐÔ̺¬Ò»¸öbase64±àÂëµÄ»ã±¨IDºÅ£¨¡°SRF ID¡±£© £¬Äܹ»½«¸Ã»ã±¨ºÅ½âÂë £¬²¢Í¨¹ýµÝÔöºÍµÝ¼õÒÔ»ú¹ØÐµÄURL¼¯ £¬À´½Ó¼ûÆäËû»¼ÕßµÄCOVID-19¼ì²â»ã±¨¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/over-8-million-covid-19-test-results-leaked-online/    


4.ºÚ¿ÍÔÚ°µÍøÏúÊÛ·¨¹ú½ü50Íò¹«ÃñµÄÒ½ÁƵµ°¸ÐÅÏ¢


4.jpg


Lib¨¦ration·¢ÏÖºÚ¿ÍÔÚ°µÍøÏúÊÛ·¨¹ú491840¸ö¹«ÃñµÄÒ½ÁƵµ°¸ÐÅÏ¢¡£Ð¹Â¶Êý¾ÝÔ̺¬ÐÕÃû¡¢µç»°ºÅÂë¡¢ÓÊÕþµØÖ·¡¢Éç»á±£Ïպ𢵮ÉúÈÕÆÚ¡¢ÑªÐÍ¡¢È«¿ÆÒ½Éú¡¢½¡È«±£ÏÕÌṩÕß¡¢Ò½ÁƲ½Öè¡¢°¬×̲¡¶¾Çé¿öºÍ»³Ì¥ÊÔÑéÁ˾ֵÈ¡£Lib¨¦ration³ÆÕâЩÊý¾ÝÀ´×Ô·¨¹úÎ÷±±µØÓòµÄ30¶à¸öҽѧ³¢ÊÔÊÒ £¬Îª2015ÄêÖÁ2020Äê10ÔÂÖ®¼ä²É¼¯µÄÑù±¾¡£´Ë±í £¬ÕâЩ³¢ÊÔÊÒÈ«ÊýʹÓÃÁËDedalus Healthcare Systems Group°ä²¼µÄÒ½ÁÆÖÎÀíÈí¼þ¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/500k-french-medical-records-leaked/


5.Mozilla°ä²¼°²È«¸üР£¬½¨¸´FirefoxÖеĶà¸ö·ì϶


5.jpg


Mozilla°ä²¼Á˰²È«¸üР£¬½¨¸´FirefoxÖеĶà¸ö·ì϶¡£Õâ´Î½¨¸´ÁËÄÚÈݰ²È«Õ½Êõ£¨CSP£©ÖеÄÁ½¸ö·ì϶ £¬Ô̺¬¿É±»Ô¶³Ì¹¥»÷ÕßÀûÓÃÀ´ÇÔÈ¡Ãô¸ÐÊý¾ÝµÄCVE-2021-23969·ì϶ £¬ÒÔ¼°¿Éй©URIÖÐÔ̺¬µÄÃô¸ÐÐÅÏ¢µÄCVE-2021-23968·ì϶¡£´Ë±í £¬»¹½¨¸´Á˿ɵ¼Ö¶ÏÑÔÔÚ¶àÏß³Ìwasm´úÂëÖб»´¥·¢µÄCVE-2021-23970·ì϶ºÍ¿É±»ÓÃÀ´ÈƹýHTML SanitizerµÄCVE-2021-23974·ì϶µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/mozilla-firefox-bugs-cookie-tracking/164246/


6.ºÉÀ¼×êÑÐÀíÊ»áϰȾDoppelPaymer £¬ÄÚ²¿Îļþй¶


6.jpg


ºÉÀ¼×êÑÐίԱ»á£¨NWO£©Ï°È¾ÁËDoppelPaymer £¬µ¼Ö·þÎñÆ÷Í£ÓÃÒÔ¼°ÄÚ²¿Îļþй¶¡£NWOÊÇΪºÉÀ¼´óѧºÍ×êÑÐËùµÄ×êÑÐÈËÔ±Ìṩ×ʽðµÄÖØÒª»ú¹¹ £¬Ã¿ÄêµÄͶ×ʶî¸ß´ï10ÒÚÅ·Ôª¡£¸Ã×éÖ¯ÓÚ2ÔÂ14ÈÕ°ä·¢ÆäÔâµ½¹¥»÷ £¬µ«Î´Ìṩϸ½Ú¡£DoppelPaymerÓÚ±¾ÖÜÈý¹«¿ªÁË´ÓNWO·þÎñÆ÷ÇÔÈ¡µÄÓÐ¹ØÆäÔ±¹¤¾ßÌåÐÅϢʮ¼¸¸öÎļþ £¬ÒÔÖ¤Ã÷¹¥»÷µÄ³É¹¦¡£NWOĿǰÔÚ¸´Ô­ÆäÍøÂç £¬Ô¤¼Æ½«ÔÚ¼¸ÖÜÄÚ¸´Ô­Õý³£ÔËÓª¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/dutch-research-council-nwo-confirms-ransomware-attack-data-leak/