WordPress XSSºÍRCEÎó²î£»£»£»OilRig APT·Ö·¢KarkoffºÍDNSpionage£»£»£»QbotľÂíбäÖÖ

Ðû²¼Ê±¼ä 2019-04-25
1¡¢WordPress²å¼þSocial WarfareÐÞ¸´XSSºÍRCEÎó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
WordPress²å¼þSocial WarfareÐû²¼Ð°汾3.5.3 £¬ £¬£¬£¬£¬£¬ÐÞ¸´Ò»¸ö´æ´¢ÐÍXSSºÍRCEÎó²î£¨CVE-2019-9978£© £¬ £¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì¸üС£ ¡£¡£¡£¡£¡£Social WarfareÊÇÒ»¸öÊ¢ÐеIJå¼þ £¬ £¬£¬£¬£¬£¬ÓÃÓÚÏòWordPressÍøÕ¾»ò²©¿ÍÌí¼ÓÉç½»·ÖÏí°´Å¥ £¬ £¬£¬£¬£¬£¬ÆäÏÂÔØÁ¿Áè¼Ý90Íò´Î¡£ ¡£¡£¡£¡£¡£ÓÉÓÚPoCÒѾ­Ð¹Â¶ £¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÒÑÔÚÒ°ÍâÆð¾¢Ê¹ÓøÃÎó²î¾ÙÐжñÒâÍÚ¿ó»î¶¯»òÍйܶñÒâ´úÂë¡£ ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/04/wordpress-plugin-hacking.html

2¡¢ChromeÐû²¼Ð°汾v74 £¬ £¬£¬£¬£¬£¬¹²ÐÞ¸´39¸öÇå¾²Îó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
ChromeÐû²¼Ð°汾v74.0.3729.108 £¬ £¬£¬£¬£¬£¬ÔöÌíÁËй¦Ð§²¢ÐÞ¸´ÁË39¸öÇå¾²Îó²î¡£ ¡£¡£¡£¡£¡£ÏÖÔÚChrome 74ÊÇÎÈ¹Ì°æ £¬ £¬£¬£¬£¬£¬Chrome 75ºÍ76Ôò»®·ÖÊÇBetaºÍCanary°æ±¾¡£ ¡£¡£¡£¡£¡£Õâ39¸öÎó²îÖÐûÓÐCritical¼¶±ðµÄÎó²î £¬ £¬£¬£¬£¬£¬µ«ÓÐÎå¸ö¸ßΣÎó²î £¬ £¬£¬£¬£¬£¬°üÀ¨use-after-freeÎó²î£¨CVE-2019-5805¡¢CVE-2019-5808ºÍCVE-2019-5809£©¡¢ÕûÊýÒç³öÎó²î£¨CVE-2019-5806£©ÒÔ¼°ÄÚ´æËð»µÎó²î£¨CVE-2019-5807£©¡£ ¡£¡£¡£¡£¡£ÍêÕûµÄ¹¦Ð§±ä»»ºÍÎó²îÐÞ¸´Áбí¿ÉÔÚÒÔÏÂÁ´½ÓÖÐÕÒµ½¡£ ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/google/chrome-74-released-with-39-security-fixes-and-new-features/

3¡¢Google PlayϼÜ50¸ö¶ñÒâÓ¦Óà £¬ £¬£¬£¬£¬£¬×°ÖÃÁ¿´ï3000Íò´Î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
AvastÑо¿ÍŶÓÔÚGoogle PlayÖз¢Ã÷50¸ö¶ñÒâÓ¦Óà £¬ £¬£¬£¬£¬£¬ÕâЩӦÓõÄ×ÜÏÂÔØ´ÎÊý´ï3000Íò´Î¡£ ¡£¡£¡£¡£¡£Æ¾Ö¤AvastµÄ±¨¸æ £¬ £¬£¬£¬£¬£¬ÕâЩӦÓÃͨ¹ýµÚÈý·½¿âÏ໥¹ØÁª £¬ £¬£¬£¬£¬£¬¿ÉÈÆ¹ýAndroidµÄºǫ́ЧÀÍÏÞÖÆÒ»Ö±ÏòÓû§ÏÔʾԽÀ´Ô½¶àµÄ¹ã¸æ £¬ £¬£¬£¬£¬£¬ÔÚijЩÇéÐÎÏÂÉõÖÁÓÕʹÓû§×°ÖÃÆäËü¹ã¸æÈí¼þ¡£ ¡£¡£¡£¡£¡£ÕâЩ¶ñÒâÓ¦ÓõÄÃû³Æ°üÀ¨Pro Piczoo¡¢Photo Blur Studio¡¢Mov-tracker¡¢Magic Cut OutºÍPro Photo EraserµÈ £¬ £¬£¬£¬£¬£¬ÏÂÔØÁ¿´Ó100Íòµ½1000´Î²»µÈ¡£ ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/30-million-android-users-have-installed-malicious-lifestyle-apps/

4¡¢OilRig APTÔÚй¥»÷»î¶¯Öзַ¢KarkoffºÍDNSpionage

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
ƾ֤˼¿ÆTalosµÄÆÊÎö±¨¸æ £¬ £¬£¬£¬£¬£¬ÒÁÀÊAPT×éÖ¯OilRigÔÚ×î½ü£¨4Ô·ݣ©µÄ¹¥»÷»î¶¯ÖÐʹÓÃÁËжñÒâÈí¼þKarkoffºÍDNSpionage¡£ ¡£¡£¡£¡£¡£ÕâЩ¹¥»÷»î¶¯Ö÷ÒªÕë¶ÔÖж«µØÇø £¬ £¬£¬£¬£¬£¬°üÀ¨Àè°ÍÄۺͰ¢ÁªÇõ¡£ ¡£¡£¡£¡£¡£¹¥»÷ÕßÕýÔÚʹÓÃеÄÕ½ÂÔ¡¢ÊÖÒպͳÌÐòÀ´Ìá¸ßÆä¹¥»÷ЧÂÊ¡£ ¡£¡£¡£¡£¡£KarkoffÊÇ.NET¿ª·¢µÄжñÒâÈí¼þ £¬ £¬£¬£¬£¬£¬Ö÷ÒªÓÃÓÚÕì̽»î¶¯ £¬ £¬£¬£¬£¬£¬¿ÉÍøÂçÄ¿µÄµÄÊÂÇéÕ¾ÇéÐΡ¢OS¡¢Óò¡¢Àú³ÌÁбíµÈÐÅÏ¢ £¬ £¬£¬£¬£¬£¬ÉõÖÁ¿ÉÒÔÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£ ¡£¡£¡£¡£¡£DNSpionageÔòÊÇÒ»¸ö¶¨ÖƵÄRAT £¬ £¬£¬£¬£¬£¬Ö÷ҪʹÓÃHTTPºÍDNSͨѶÀ´ÅþÁ¬C£¦CЧÀÍÆ÷¡£ ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/84418/malware/oilrig-apt-karkoff-dnspionage.html

5¡¢QbotľÂíбäÖÖ £¬ £¬£¬£¬£¬£¬ÒÑѬȾȫÇò2726ÃûÓû§

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
Varonis Security ResearchÔÚ3Ô·ݷ¢Ã÷ÁËQbotľÂíµÄÐÂÒ»²¨È«Çò¹¥»÷»î¶¯ £¬ £¬£¬£¬£¬£¬Æ¾Ö¤¶ÔÆäÖÐÒ»¸ö¹¥»÷ЧÀÍÆ÷µÄÆÊÎö £¬ £¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÒѾ­È·ÈÏÁË2726ÃûÊܺ¦Õß £¬ £¬£¬£¬£¬£¬µ«ÏÖʵÊܺ¦ÈËÊý¿ÉÄܸü¸ß¡£ ¡£¡£¡£¡£¡£QbotÒÔÆä¶à̬ÐÐΪ¼°ÀàËÆÈ䳿µÄÌØÕ÷¶øÖøÃû £¬ £¬£¬£¬£¬£¬ÕâÒ»´ÎQBotͨ¹ý´¹ÂÚÓʼþ¾ÙÐÐÈö²¥ £¬ £¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÃÀ¹ú¡¢Å·ÖÞ¡¢ÑÇÖÞºÍÄÏÃÀÖÞµÄÆóÒµ £¬ £¬£¬£¬£¬£¬ÆäÄ¿µÄÊÇÇÔÈ¡ÒøÐÐÆ¾Ö¤µÈ²ÆÎñÐÅÏ¢¡£ ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/qbot_new_campaign/144070/

6¡¢ÑÇÌØÀ¼´óÀÏÓ¥¶ÓµÄÔÚÏßÊÐËÁÔâµ½Magecart¹¥»÷

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨
 
ÑÇÌØÀ¼´óÀÏÓ¥¶ÓµÄÔÚÏßÊÐËÁ³ÉΪMagecart¹¥»÷µÄ×îÐÂÊܺ¦Õß £¬ £¬£¬£¬£¬£¬Æ¾Ö¤Sanguine SecurityµÄ±¨¸æ £¬ £¬£¬£¬£¬£¬¸ÃÊÐËÁµÄ¸¶¿îÒ³ÃæÑ¬È¾ÁËMagecart¶ñÒâ´úÂë £¬ £¬£¬£¬£¬£¬µ¼ÖÂÓû§µÄÐÕÃû¡¢µØµãºÍÐÅÓÿ¨ÏêϸÐÅÏ¢±»ÇÔ¡£ ¡£¡£¡£¡£¡£¸ÃÊÂÎñÓ°ÏìÁË4ÔÂ20ÈÕÖ®ºóÔÚÊÐËÁ¹ºÎïµÄÓû§ £¬ £¬£¬£¬£¬£¬µ«Éв»ÇåÎúÊÜÓ°ÏìÓû§µÄÏêϸÊýÄ¿¡£ ¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÒÔΪ¸Ã¹¥»÷»òÓëMagentoµÚÈý·½×é¼þµÄʹÓÃÓйØ¡£ ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://labs.sansec.io/2019/04/24/atlanta-hawks-magecart/