ImpervaÐû²¼ÓйØKashmirBlack½©Ê¬ÍøÂçµÄÆÊÎö±¨¸æ£»£» £»£»Nitro PDF´ó¹æÄ£Êý¾Ýй¶ӰÏì΢Èí¡¢¹È¸èºÍÆ»¹ûµÈ¹«Ë¾

Ðû²¼Ê±¼ä 2020-10-27
1.ImpervaÐû²¼ÓйØKashmirBlack½©Ê¬ÍøÂçµÄÆÊÎö±¨¸æ


1.jpg


ImpervaÐû²¼ÁËÓйØKashmirBlack½©Ê¬ÍøÂçµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¸Ã±¨¸æÐÎòÁËKashmirBlack½©Ê¬ÍøÂç±³ºóµÄ·¸·¨²Ù×÷£¬£¬ £¬£¬£¬£¬£¬£¬ÌÖÂÛÁËÆäÄ¿µÄÒÔ¼°Ñо¿ÒªÁì¡£¡£¡£¡£¡£¡£KashmirBlackÖ÷ÒªÕë¶ÔÊ¢ÐеÄCMSƽ̨¡£¡£¡£¡£¡£¡£ËüʹÓÃÁËÄ¿µÄЧÀÍÆ÷ÉϵÄÊýÊ®¸öÒÑÖªÎó²î£¬£¬ £¬£¬£¬£¬£¬£¬Æ½¾ùÌìÌì¶ÔÈ«Çò30¶à¸ö²î±ð¹ú¼ÒµÄÊýǧÃûÊܺ¦Õß¾ÙÐÐÊý°ÙÍò´Î¹¥»÷¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬ £¬£¬£¬£¬£¬£¬ÆäÔËÐкÜÊÇÖØ´ó£¬£¬ £¬£¬£¬£¬£¬£¬ÓÉһ̨C&CЧÀÍÆ÷ÖÎÀí£¬£¬ £¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃÁË60¶ą̀ЧÀÍÆ÷×÷ΪÆä»ù´¡ÉèÊ©µÄÒ»²¿·Ö¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿É´¦Öóͷ£Êý°Ù¸ö½©Ê¬³ÌÐò£¬£¬ £¬£¬£¬£¬£¬£¬Ö´Ðб©Á¦¹¥»÷¡¢×°ÖúóÃÅ¡¢²¢À©´ó½©Ê¬ÍøÂçµÄ¹æÄ£¡£¡£¡£¡£¡£¡£    


Ô­ÎÄÁ´½Ó£º

https://www.imperva.com/blog/crimeops-of-the-kashmirblack-botnet-part-i/


2.Area1Ðû²¼Office 365µç×ÓÓʼþ·ÀÓùϵͳÍþвÆÊÎö±¨¸æ


2.jpg


Area1Ðû²¼ÁËOffice 365µç×ÓÓʼþ·ÀÓùºÍ×ÅÃûÇå¾²µç×ÓÓʼþÍø¹Ø£¨SEG£©ÃæÁÙµÄÖ÷ÒªÍþвµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£±¨¸æÏÔʾ£¬£¬ £¬£¬£¬£¬£¬£¬´Ó2020Äê3Ôµ½8ÔµÄÁù¸öÔÂÖУ¬£¬ £¬£¬£¬£¬£¬£¬ÓÐÁè¼Ý925000·â¶ñÒâµç×ÓÓʼþÀÖ³ÉÈÆ¹ýÁËOffice 365·ÀÓùºÍSEG¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬ £¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔ½À´Ô½¶àµØÊ¹Óø߶ÈÖØ´óµÄ¡¢ÓÐÕë¶ÔÐԵĹ¥»÷»î¶¯À´ÌӱܻùÓÚÒÑÖªÍþвµÄ¹Å°åµç×ÓÓʼþ·ÀÓù£¬£¬ £¬£¬£¬£¬£¬£¬ÀýÈçÉÌÒµµç×ÓÓʼþ¹¥»÷¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬ £¬£¬£¬£¬£¬£¬Type 3 BECs(»ùÓÚÕË»§¿ØÖƵÄ)ºÍType 4 BEC (¹©Ó¦Á´ÍøÂç´¹ÂÚ)¿ÉÄÜÒÑÔì³ÉÊýÊ®ÒÚÃÀÔªµÄDZÔÚËðʧ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.area1security.com/office-365-anniversary-email-threats-report/


3.Ñо¿Ö°Ô±·¢Ã÷¿Éͨ¹ýWaze APIÖÐÎó²î×·×Ùí§ÒâÓû§µÄλÖÃ


3.jpg


Ñо¿Ö°Ô±Peter Gasper·¢Ã÷¿Éͨ¹ýWaze APIÖÐÎó²î×·×Ùí§ÒâÓû§µÄλÖᣡ£¡£¡£¡£¡£µ±Óû§±¨¸æÇ°·½ÓÐõè¾¶Õϰ­»ò¾¯Ô±Ñ²Âßʱ£¬£¬ £¬£¬£¬£¬£¬£¬Waze API»á½«¸ÃÓû§µÄIDºÍÓû§ÃûÒ»Æð·µ»Ø¸øÔڸõط½ÐÐÊ»µÄÆäËûÓû§¡£¡£¡£¡£¡£¡£³ý·ÇÓû§¾ÙÐÐÁË×¢ÊÍ£¬£¬ £¬£¬£¬£¬£¬£¬²»È»Ó¦ÓÃÖв»»áÏÔʾ´ËÊý¾Ý£¬£¬ £¬£¬£¬£¬£¬£¬µ«ÔÚAPIÏìÓ¦Öлá°üÀ¨Óû§Ãû¡¢ID¡¢ÊÂÎñµÄλÖá¢ÉõÖÁÊDZ¨¸æÊ±¼ä¡£¡£¡£¡£¡£¡£ÓÉÓÚ´ó´ó¶¼Óû§½«ÆäÕæÊµÐÕÃû×÷ΪÓû§Ãû£¬£¬ £¬£¬£¬£¬£¬£¬Òò´Ë¹¥»÷ÕßÓпɽ¨ÉèÒ»¸ö°üÀ¨Óû§ÐÕÃûºÍIDµÄÊý¾Ý¿â¡£¡£¡£¡£¡£¡£ 


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2020/10/25/waze-app-vulnerability-could-allow-tracking-users-location/


4.Nitro PDF´ó¹æÄ£Êý¾Ýй¶ӰÏì΢Èí¡¢¹È¸èºÍÆ»¹ûµÈ¹«Ë¾


4.jpg


Nitro PDFЧÀͱ¬·¢´ó¹æÄ£µÄÊý¾Ýй¶£¬£¬ £¬£¬£¬£¬£¬£¬Ó°ÏìÁ˰üÀ¨Google¡¢Apple¡¢Microsoft¡¢ChaseºÍCitibankÔÚÄÚµÄÖî¶à×ÅÃû×éÖ¯¡£¡£¡£¡£¡£¡£10ÔÂ21ÈÕ£¬£¬ £¬£¬£¬£¬£¬£¬Nitro SoftwareÐû²¼ÁËÒ»·Ý×Éѯ£¬£¬ £¬£¬£¬£¬£¬£¬³ÆÆäÔâµ½µÍÓ°ÏìÇå¾²ÊÂÎñ£¬£¬ £¬£¬£¬£¬£¬£¬µ«Æä¿Í»§Êý¾ÝûÓÐÊܵ½ÈκÎÓ°Ïì¡£¡£¡£¡£¡£¡£ÍøÂçÇå¾²Ç鱨¹«Ë¾CybleÔòÌåÏÖ£¬£¬ £¬£¬£¬£¬£¬£¬ºÚ¿ÍÕýÔÚ³öÊÛÉù³ÆÊÇ´ÓNitroÔÆÖÐÇÔÈ¡µÄÓû§¡¢ÎĵµÊý¾Ý¿âÒÔ¼°1TBµÄÎĵµ¡£¡£¡£¡£¡£¡£ÆäÖÐuser_credentialÊý¾Ý¿â°üÀ¨7000ÍòÌõÓû§¼Í¼£¬£¬ £¬£¬£¬£¬£¬£¬°üÀ¨µç×ÓÓʼþµØµã¡¢È«Ãû¡¢bcryptÉ¢ÁÐÃÜÂ롢ͷÏΡ¢¹«Ë¾Ãû³Æ¡¢IPµØµãºÍÆäËûϵͳÏà¹ØÊý¾Ý¡£¡£¡£¡£¡£¡£ÕâЩÊý¾Ý¿â»¹°üÀ¨ÁËÓë¸÷×ÅÃû¹«Ë¾ÓйصĴó×ÚÎĵµ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/massive-nitro-data-breach-impacts-microsoft-google-apple-more/ 


5.Trustwave·¢Ã÷ºÚ¿ÍÔÚ°µÍø³öÊÛ1.86ÒÚÃÀ¹úÑ¡ÃñÐÅÏ¢


5.jpg


ÍøÂçÇå¾²¹«Ë¾Trustwave·¢Ã÷ºÚ¿ÍÔÚ°µÍø³öÊÛÁËÁè¼Ý2ÒÚÃÀ¹úÈ˵ÄСÎÒ˽¼Òʶ±ðÐÅÏ¢£¬£¬ £¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨1.86ÒÚÃÀ¹úÑ¡ÃñÐÅÏ¢¡£¡£¡£¡£¡£¡£×ß©µÄÊý¾Ý°üÀ¨ÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢µç»°ºÅÂëºÍÑ¡Ãñ¹ÒºÅ¼Í¼¡£¡£¡£¡£¡£¡£TrustwaveÌåÏÖÕâЩÊý¾ÝÊÇÓɽüÄêÀ´ÆóÒµÔâµ½ÖÖÖÖ¹¥»÷Ëùй¶µÄÊý¾ÝÒÔ¼°´ÓÕþ¸®ÍøÕ¾¼ìË÷µÄ¹ûÕæÊý¾Ý×é³ÉµÄ£¬£¬ £¬£¬£¬£¬£¬£¬¿ÉÓÃÓÚÉ罻ýÌå¡¢µç×ÓÓʼþÍøÂç´¹ÂÚÒÔ¼°Îı¾ºÍµç»°Õ©Æ­»î¶¯ºÍÐéαÐÅÏ¢Ðû´«»î¶¯¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.nbcnews.com/politics/2020-election/cybersecurity-firm-finds-hacker-selling-info-148-million-u-s-n1244211


6.Ó¡¶ÈPTIЧÀÍÆ÷ÔâLockBit¹¥»÷µ¼ÖÂЧÀÍÔÝʱÖÐÖ¹


6.jpg


Ó¡¶ÈPTI£¨Press Trust of India¡¯s£©ÔâLockBit¹¥»÷µ¼ÖÂЧÀÍÔÝʱÖÐÖ¹¡£¡£¡£¡£¡£¡£PTI½²»°ÈËÖÜÈÕÌåÏÖ£¬£¬ £¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾µÄЧÀÍÆ÷ÔâÓöÁË´ó¹æÄ£ÀÕË÷Èí¼þ¹¥»÷£¬£¬ £¬£¬£¬£¬£¬£¬µ¼ÖÂЧÀÍÖÐÖ¹ÁËÊýСʱ£¬£¬ £¬£¬£¬£¬£¬£¬¾­Óɹ¤³ÌʦͨÏüÆð¾¢ºóµÃÒÔ»Ö¸´¡£¡£¡£¡£¡£¡£¹¥»÷±¬·¢ÔÚÖÜÁùÍíÉÏ10µã×óÓÒ£¬£¬ £¬£¬£¬£¬£¬£¬ÀÕË÷Èí¼þLockBitѬȾÁËÓ¡¶È×ÜÀíͨѶÉçÏÕЩËùÓеÄЧÀÍÆ÷£¬£¬ £¬£¬£¬£¬£¬£¬²¢¼ÓÃÜÁËËùÓÐÊý¾ÝºÍÓ¦ÓóÌÐò¡£¡£¡£¡£¡£¡£µ«¸Ã½²»°ÈËÌåÏÖ£¬£¬ £¬£¬£¬£¬£¬£¬µ½ÖÜÈÕÉÏÎç9µã£¬£¬ £¬£¬£¬£¬£¬£¬ÆäËùÓÐÓªÒµ»ù±¾¶¼»Ö¸´Õý³££¬£¬ £¬£¬£¬£¬£¬£¬²¢ÇÒûÓÐÖ§¸¶Êê½ð¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.thehindubusinessline.com/info-tech/pti-services-disrupted-after-massive-ransomware-attack-on-servers/article32940254.ece