¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190225

Ðû²¼Ê±¼ä 2019-02-25
1¡¢½ü7ÍòÕŰͻùË¹Ì¹ÒøÐп¨ÐÅÏ¢ÔÚ°µÍø³öÊÛ £¬£¬£¬ÊÛ¼Û½ü350ÍòÃÀÔª

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

Group-IBÑо¿Ö°Ô±·¢Ã÷69189ÕŰͻùË¹Ì¹ÒøÐп¨µÄÐÅÏ¢ÔÚ°µÍøÉϳöÊÛ¡£¡£¡£ÕâÅúÊý¾Ý·ÖΪÁ½¸öÊý¾Ý¿â £¬£¬£¬×ÜÊÛ¼ÛԼΪ350ÍòÃÀÔª¡£¡£¡£µÚÒ»¸öÊý¾Ý¿âÊÇ1ÔÂβÔÚJoker's StashÉÏÐû²¼µÄ £¬£¬£¬¹²°üÀ¨1535ÕÅÒøÐп¨ÐÅÏ¢ £¬£¬£¬ÆäÖÐ96£¥µÄÒøÐп¨¶¼ÓëMeezan BankÓйØ¡£¡£¡£µÚ¶þ¸öÊý¾Ý¿âÊÇ1ÔÂ30ÈÕÔÚJoker's StashÉÏÐû²¼µÄ £¬£¬£¬°üÀ¨67654ÕÅÒøÐп¨ÐÅÏ¢ £¬£¬£¬Í¬ÑùÓÐ96£¥µÄÒøÐп¨ÓëMeezan BankÓйØ¡£¡£¡£ÕâЩÊý¾Ý¿ÉÄÜÅú×¢Îú¸ÃµØÇøÕë¶Ô½ðÈÚ»ú¹¹µÄ¹¥»÷ÕߵĻ¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/81579/cyber-crime/pakistani-banks-cards-darkweb.html

2¡¢¿ÏËþ»ùÖÝ×ÉѯÖÐÐÄǰ¹ÍÔ±ÇÔÈ¡»¼ÕßÐÅÏ¢ £¬£¬£¬²¨¼°1.6Íò»¼Õß

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

ÃÀ¹ú¿ÏËþ»ùÖÝ×ÉѯÖÐÐÄ£¨KCC£©×ª´ïÁËÒ»Æð»¼ÕßÐÅϢй¶ÊÂÎñ £¬£¬£¬¸ÃÊÂÎñ±¬·¢ÔÚ2018Äê12Ô £¬£¬£¬Ò»Ãûǰ¹ÍÔ±´ÓËûÃǵÄÅÌËã»úϵͳÖÐÇÔÈ¡Á˲¿·Ö»¼ÕßÐÅÏ¢¡£¡£¡£¸ÃÊÂÎñÓ°ÏìÁËÁè¼Ý1.6ÍòÃû»¼Õß £¬£¬£¬KCCÒѾ­ÏòHHSת´ïÁËÕâÆðÊÂÎñ¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨»¼ÕßµÄÐÕÃû¡¢µØµã¡¢³öÉúÈÕÆÚ¡¢µç×ÓÓʼþ¡¢µç»°ºÅÂë¡¢ÐÔ±ð¡¢Éç»áÇå¾²ºÅÂë¡¢»éÒöºÍ¾ÍÒµÇéÐεÈ¡£¡£¡£KCCÌåÏÖ½«ÎªÊÜÓ°ÏìµÄ»¼ÕßÌṩһÄêµÄÃâ·ÑÐÅÓÃ¼à¿ØÐ§ÀÍ¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/kentucky-counseling-center-notifies-more-than-16000-patients-after-insider-perp-steals-data-c03dadb7

3¡¢Ð¶ñÒâÈí¼þFbot £¬£¬£¬Ñ¬È¾´ó×ÚHiSilicon DVR/NVR Soc×°±¸

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

2ÔÂ16ÈÕÒÔÀ´ £¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷жñÒâÈí¼þFbotѬȾÁË´ó×ÚµÄHiSilicon DVR/NVR Soc×°±¸¡£¡£¡£¹¥»÷ÕßʹÓÃÁ˳§É̵ÄDVRIPЭÒéʵÑéÉϵÄÈõÇå¾²ÐÔ £¬£¬£¬Í¨¹ý×°±¸µÄĬÈÏÃÜÂëÀ´Ñ¬È¾×°±¸ £¬£¬£¬²¢½¨ÉètelnetºóÃźÍ×齨½©Ê¬ÍøÂçFbot¡£¡£¡£Ñо¿Ö°Ô±ÔÚÈ«Çò¹æÄ£ÄÚ¹²·¢Ã÷ÁË24528¸ö±»Ñ¬È¾µÄIPµØµã¡£¡£¡£Fbot½ÓÄÉÁËÁ½¸ö²î±ðµÄ¼ÓÃÜÏ¢ÕùÃܲãÀ´±ÜÃâ´úÂë±»ÆÊÎö¡£¡£¡£¸ü¶àIoCÖ¸±êÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/81567/malware/fbot-malware-hisilicon.html

4¡¢Ð´¹ÂÚ¹¥»÷»î¶¯Èö²¥BankBot £¬£¬£¬Ö÷ÒªÕë¶Ô²¨À¼ÒøÐÐ

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

SucuriÑо¿Ö°Ô±·¢Ã÷Ò»¸öÕë¶Ô²¨À¼ÒøÐм°ÆäÓû§µÄ´¹ÂÚ¹¥»÷»î¶¯¡£¡£¡£ÕâЩ´¹ÂÚÓʼþÖаüÀ¨¶ñÒâPHPÎļþµÄÁ´½Ó £¬£¬£¬²¢×îÖÕÏòÓû§·Ö·¢¶ñÒâÈí¼þBankBot¡£¡£¡£BankBot×îÔç·ºÆðÓÚ2016Äê £¬£¬£¬Ö÷ÒªÓÃÓÚÇÔÈ¡Óû§µÄÒøÐÐÐÅÏ¢ £¬£¬£¬ÒÔ¼°Óû§µÄ¶ÌÐÅ¡¢Í¨»°¼Í¼¡¢ÁªÏµÈ˺ÍλÖÃÐÅÏ¢µÈ¡£¡£¡£¸Ã¶ñÒâPHP´úÂëͨ¹ýHTMLÔªËØºÍJavaScript £¬£¬£¬»¹¼ÓÔØÁËÐéαµÄGoogle reCAPTCHAÀ´ÓÕÆ­Óû§¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://threatpost.com/phishing-scam-malware-google-recaptcha/142142/

5¡¢ÐÂÀÕË÷Èí¼þB0r0nt0K £¬£¬£¬Ö÷ҪѬȾLinuxЧÀÍÆ÷

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

Ñо¿Ö°Ô±·¢Ã÷Ò»¸öеÄÀÕË÷Èí¼þB0r0nt0K £¬£¬£¬¸ÃÀÕË÷Èí¼þÖ÷ÒªÕë¶ÔLinuxЧÀÍÆ÷ £¬£¬£¬µ«Ò²¿ÉѬȾWindowsϵͳ¡£¡£¡£B0r0nt0K»áÔÚ¼ÓÃܵÄÎļþºó¸½¼Ó.rontokÀ©Õ¹Ãû £¬£¬£¬²¢ÒªÇó20±ÈÌØ±Ò£¨¼ÛÖµÔ¼7.5ÍòÃÀÔª£©µÄÊê½ð¡£¡£¡£ÔÚ¸¶¿îÍøÕ¾µÄÔ´´úÂëÖÐ £¬£¬£¬±£´æÀàËÆÓÚ¡°Ô½ÄϺڿ͡±µÄ×¢ÊÍ £¬£¬£¬Õâ¿ÉÄÜÅú×¢¹¥»÷ÕßÀ´×ÔÓÚÔ½ÄÏ¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/b0r0nt0k-ransomware-wants-75-000-ransom-infects-linux-servers/

6¡¢WhatsAppÐÞ¸´iOSÓ¦ÓÃÖеÄFace IDºÍTouch IDÈÆ¹ýÎó²î

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

2Ô³õWhatsAppÔÚÆäiOSÓ¦ÓóÌÐòÖÐÒýÈëÁËFace IDºÍTouch IDÉí·ÝÑéÖ¤ £¬£¬£¬µ«RedditÓû§·¢Ã÷ÈôÊÇÓû§Ê¹ÓÃÁËiOSÖеÄShare Sheet¹¦Ð§ £¬£¬£¬²¢ÇÒδ½«Ëø¶¨¾àÀëÉ趨Ϊ¡°Á¬Ã¦¡± £¬£¬£¬Ôò¿ÉÒÔÈÆ¹ýÑ¡¶¨µÄÉí·ÝÑéÖ¤ÒªÁì¡£¡£¡£WhatsAppÒѾ­ÔÚ×îа汾µÄiOSÓ¦ÓÃÖÐÐÞ¸´ÁËÕâ¸öÎó²î £¬£¬£¬½¨ÒéÓû§¾¡¿ì¾ÙÐиüС£¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/81520/hacking/whatsapp-auth-bypass-flaw.html

ÉùÃ÷£º±¾×ÊѶÓÉ¿­·¢k8άËûÃüÇ徲С×é·­ÒëºÍÕûÀí