¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181016
Ðû²¼Ê±¼ä 2018-10-16
Malwarebytes LabsÐû²¼2018ÄêµÚÈý¼¾¶ÈµÄÍøÂç·¸·¨Õ½ÂÔÓëÊÖÒÕÊӲ챨¸æ£¬£¬£¬£¬ÔÚǰÁ½¸ö¼¾¶ÈµÄ¼õ»ºÖ®ºó£¬£¬£¬£¬ÍøÂç·¸·¨·Ö×ÓÔÚµÚÈý¼¾¶ÈÔٴμÓËÙÁËËûÃǵĶñÒâ»î¶¯¡£¡£¡£¡£¡£±¾¼¾¶ÈµÄÍþвÇ÷ÊÆ°üÀ¨¶ñÒâÍÚ¿óÈí¼þºÍÎó²îʹÓù¤¾ß°ü±äµÃ³ÉÊ죬£¬£¬£¬ÀÕË÷Èí¼þÎȲ½ÔöÌí£¬£¬£¬£¬APT¹¥»÷¼°ÒøÐÐľÂí»î¶¯×îÏÈËÕÐѵȡ£¡£¡£¡£¡£±¾¼¾¶ÈÎÒÃǼì²âµ½µÄÕë¶ÔÆóÒµµÄÍþвÔöÌíÁË55%£¬£¬£¬£¬Ïà±ÈÖ®ÏÂÕë¶ÔÏûºÄÕßµÄÍþв½öÔöÌí4%£¬£¬£¬£¬ÕâÒâζ׏¥»÷ÕßÕýÔÚ×·Çó¸ü´óµÄÀûÒæ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.malwarebytes.com/malwarebytes-news/2018/10/labs-cybercrime-tactics-and-techniques-report-ctnt-shows-shift-to-business-targets/2¡¢Branch.ioЧÀͱ»ÆØ±£´æXSSÎó²î£¬£¬£¬£¬6.85ÒÚÓû§ÒÉÃæÁÙΣº¦

vpnMentorµÄÇå¾²Ñо¿Ö°Ô±·¢Ã÷Branch.ioЧÀͱ£´æXSSÎó²î£¬£¬£¬£¬Ðí¶àʹÓøÃЧÀ͵ĴóÐÍÍøÕ¾¶¼Êܵ½Ó°Ï죬£¬£¬£¬°üÀ¨Tinder¡¢Shopify¡¢Yelp¡¢Western UnionºÍImgurµÈ£¬£¬£¬£¬ÕâÒâζ×Ŷà´ï6.85ÒÚµÄÓû§¿ÉÄÜÃæÁÙΣº¦¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²î»á¼ûÓû§µÄÉèÖÃÎļþºÍÏêϸÐÅÏ¢¡£¡£¡£¡£¡£ËäÈ»¸ÃÎó²îÒÑÐÞ¸´£¬£¬£¬£¬µ«ÈÔ½¨ÒéʹÓùýÕâÐ©ÍøÕ¾µÄÓû§¼ì²é×Ô¼ºµÄÕË»§²¢ÇÒÐÞ¸ÄÃÜÂë¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.vpnmentor.com/blog/dom-xss-bug-affecting-tinder-shopify-yelp/3¡¢MS-ISACÅû¶PHPÖжà¸ö¿Éµ¼Ö´úÂëÖ´ÐеÄÎó²î

ÃÀ¹úµÄ¿çÖÝÐÅÏ¢¹²ÏíÓëÆÊÎöÖÐÐÄ£¨MS-ISAC£©Åû¶PHP°æ±¾7.1ºÍ7.2ÖеĶà¸ö¸ßΣº¦Îó²î¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²îÖ´ÐÐí§Òâ´úÂë»òµ¼Ö¾ܾøÐ§ÀÍ£¨DoS£©£¬£¬£¬£¬¸øÕþ¸®»ú¹¹¡¢ÆóÒµºÍ¼ÒÍ¥Óû§´øÀ´Î£º¦¡£¡£¡£¡£¡£PHP¿ª·¢ÍŶÓÒÑÔÚPHP°æ±¾7.1.23ºÍ7.2.11ÖÐÐÞ¸´ÁËÕâЩÎó²î£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì¾ÙÐÐÉý¼¶¡£¡£¡£¡£¡£ÏÖÔÚ»¹Ã»ÓйØÓÚÕâЩÎó²îÔÚÒ°ÍⱻʹÓõı¨¸æ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-php-could-allow-for-arbitrary-code-execution_2018-113/4¡¢ÎÚ¿ËÀ¼Õþ¸®»ú¹¹ÔÙÔâAPT×éÖ¯BlackEnergyÏ®»÷

ÎÚ¿ËÀ¼Çå¾²¾Ö£¨SBU£©ÌåÏÖ×î½ü¶íÂÞ˹APT×éÖ¯BlackEnergyÔÙ´ÎÕë¶ÔÎÚ¿ËÀ¼Õþ¸®»ú¹¹µÄÐÅϢϵͳºÍµçÐÅϵͳÌᳫ¹¥»÷¡£¡£¡£¡£¡£SBUר¼ÒÖ¸³ö£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÁËеĶñÒâÈí¼þ£¬£¬£¬£¬Æä¹¦Ð§°üÀ¨Ô¶³ÌÖÎÀí²Ù×÷ϵͳÒÔ¼°Îļþ¸´ÖÆ¡¢¼à¿ØÓû§ÐÐΪºÍ×èµ²ÃÜÂëµÈ¡£¡£¡£¡£¡£Æ¾Ö¤SBUºÍÒ»¸öÇå¾²³§É̵ÄÊӲ죬£¬£¬£¬¹¥»÷ÖÐÉæ¼°µ½µÄ¶ñÒâÈí¼þÊÇIndustroyerºóÃŵÄбäÌå¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬SBU»¹·¢Ã÷ÁËÊôÓÚ¸ÃAPT×éÖ¯µÄ¶ÀÍ̹¤¾ß¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.ukrinform.net/rubric-crime/2557323-russian-hackers-mount-cyberattack-on-ukraines-state-bodies.html5¡¢¿¨°Í˹»ùÅû¶·¸·¨ÍÅ»ïDustSquadµÄй¤¾ßOctopus

¿¨°Í˹»ùʵÑéÊÒÅû¶·¸·¨ÍÅ»ïDustSquadʹÓõÄжñÒâÈí¼þOctopusµÄÊÖÒÕϸ½Ú¡£¡£¡£¡£¡£OctopusÖ÷ÒªÕë¶ÔÖÐÑǵØÇøµÄÍâ½»²¿·Ö£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ±»´ò°ü³ÉÒ»¸öÃûΪdvkmailer.zipµÄѹËõ°ü£¬£¬£¬£¬Æäʱ¼ä´ÁΪ2018Äê2ÔÂÖÁ3ÔÂÖ®¼ä¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÊÇÓÃDelphi±àдµÄ£¬£¬£¬£¬ÆäʹÓÃÁËһЩµÚÈý·½µÄ¿â£¬£¬£¬£¬Èç»ùÓÚJSONµÄC2ͨѶ°üIndyµÈ¡£¡£¡£¡£¡£Octopusͨ¹ýϵͳע²á±íÀ´ÊµÏÖ³¤ÆÚÐÔ£¬£¬£¬£¬ÆäЧÀÍÆ÷¶ËÊÇPHPµÄ£¬£¬£¬£¬°²ÅÅÔÚ²î±ð¹ú¼Ò/µØÇøµÄÉÌÒµÍйÜЧÀÍÖС£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/octopus-infested-seas-of-central-asia/88200/6¡¢Áè¼Ý3500ÍòÃÀ¹úÑ¡ÃñµÄ¼Í¼ÔÚºÚ¿ÍÂÛ̳ÉϳöÊÛ

±¾ÖÜÒ»Anomali LabsºÍIntel 471µÄÑо¿Ö°Ô±ÔÚ°µÍøÂÛ̳ÉÏ·¢Ã÷Ò»¸ö°üÀ¨´ó×ÚÑ¡ÃñÊý¾ÝµÄÊý¾Ý¿âÕýÔÚ³öÊÛ¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿â°üÀ¨À´×Ô19¸öÖݵĶà´ï3500ÍòÌõÑ¡Ãñ¼Í¼¡£¡£¡£¡£¡£ÕâЩ¼Í¼°üÀ¨ÐÕÃû¡¢µç»°ºÅÂ롢סַ¡¢Í¶Æ±ÀúÊ·ºÍÆäËüͶƱÊý¾ÝµÈ¡£¡£¡£¡£¡£Ñо¿Ö°Ô±¶Ô¸ÃÊý¾Ý¿âµÄÑù±¾¾ÙÐÐÁËÉó²é£¬£¬£¬£¬È·ÈÏÕâЩÊý¾ÝÓÐÓò¢ÇÒ¸ÃÊý¾Ý¿â¾ßÓи߶ȵĿÉÐŶȡ£¡£¡£¡£¡£¼øÓÚÃÀ¹ú2018ÄêµÄÖÐÆÚÑ¡¾Ù¼´½«µ½À´£¬£¬£¬£¬ÕâЩй¶µÄÊý¾Ý¿ÉÄܱ»¹¥»÷ÕßÓÃÀ´ÆÆËðÑ¡¾Ù»ò¾ÙÐÐÉí·Ý͵ÇԵȶñÒâ»î¶¯¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/up-to-35-million-2018-voter-records-for-sale-on-hacking-forum/138295/ÉùÃ÷£º±¾×ÊѶÓɼøºÚµ£±£ÍøÎ¬ËûÃüÇ徲С×é·ÒëºÍÕûÀí