Î÷ÃÅ×Ó¶à¿îÒ½ÁÆ×°±¸Ò×ÊÜWindows BlueKeepÎó²îÓ°Ï죻£»£»£»¼üÅ̼ͼľÂíHawkEyeÃé׼ȫÇòÆóÒµ

Ðû²¼Ê±¼ä 2019-05-29
1Î÷ÃÅ×Ó¶à¿îÒ½ÁÆ×°±¸Ò×ÊÜWindows BlueKeepÎó²îÓ°Ïì


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ƾ֤Î÷ÃÅ×ÓÐû²¼µÄÇ徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬¶à¿îÎ÷ÃÅ×ÓÒ½ÁÆ×°±¸Ò×ÊÜWindows RDPЧÀÍBlueKeepÎó²îµÄÓ°Ï죬£¬£¬£¬£¬£¬£¬°üÀ¨MagicLinkA¡¢MagicViewµÈÈí¼þ²úÆ·£¬£¬£¬£¬£¬£¬£¬System ACOM¡¢SensisµÈ¸ß¼¶ÖÎÁƲúÆ·£¬£¬£¬£¬£¬£¬£¬Axiom¡¢MobilettµÈXÉäÏß×°±¸ÒÔ¼°Atellica¡¢AptioµÈʵÑéÊÒÕï¶Ï²úÆ·¡£¡£¡£¡£ ¡£¡£¸Ã¹«Ë¾ÒÑÒªÇó¿Í»§×°ÖÃ΢ÈíµÄÐÞ¸´²¹¶¡£¡£¡£¡£ ¡£¡£¬£¬£¬£¬£¬£¬£¬µ«²»¿É°ü¹Ü²¹¶¡µÄ¼æÈÝÐÔ£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾½¨ÒéÓû§½ÓÄɽûÓÃRDP¡¢×èÖ¹TCP¶Ë¿Ú3389µÈ»º½â²½·¥¡£¡£¡£¡£ ¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/86222/security/siemens-healthineers-bluekeep.html

2APT10ʹÓÃмÓÔØÆ÷·Ö·¢Ô¶¿ØÄ¾Âí£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶Ô¶«ÄÏÑÇ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ƾ֤Çå¾²³§ÉÌenSiloµÄÆÊÎö±¨¸æ£¬£¬£¬£¬£¬£¬£¬APT10ÔÚ4Ô·ݵÄй¥»÷»î¶¯ÖÐʹÓÃÁ½¸öмÓÔØÆ÷·Ö·¢¶àÖÖpayload£¬£¬£¬£¬£¬£¬£¬°üÀ¨Ô¶¿ØÄ¾ÂíPlugXºÍQuasar¡£¡£¡£¡£ ¡£¡£¸Ã¹¥»÷»î¶¯Ö÷ÒªÕë¶Ô¶«ÄÏÑǵØÇøµÄÕþ¸®»ú¹¹ºÍ˽ӪÆóÒµ¡£¡£¡£¡£ ¡£¡£ÕâÁ½¸ö¼ÓÔØÆ÷¶¼ÊµÏÖÁËDLL Side-Loading£¬£¬£¬£¬£¬£¬£¬ÕâÒâζ×ÅËüÃÇ¿ÉÒÔʹÓÃÕýµ±µÄ¿ÉÖ´ÐÐÎļþÀ´¼ÓÔØ¶ñÒâDLL¡£¡£¡£¡£ ¡£¡£ÕâÁ½¸ö¼ÓÔØÆ÷¶¼Ê¹ÓÃjli.dll½«Êý¾ÝÎļþsvchost.binÓ³Éäµ½ÄÚ´æÖУ¬£¬£¬£¬£¬£¬£¬²¢¼ìË÷svchost.exe×¢Èë°üÀ¨ÏÖʵpayloadµÄshellcode¡£¡£¡£¡£ ¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/86213/apt/apt10-new-loaders.html

3¹¥»÷ÕßʹÓüüÅ̼ͼľÂíHawkEyeÃé׼ȫÇòÆóÒµ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ƾ֤IBM X-ForceµÄ±¨¸æ£¬£¬£¬£¬£¬£¬£¬ÔÚ4Ô·ݺÍ5Ô·ݹ¥»÷ÕßʹÓüüÅ̼ͼľÂíHawkEyeÃé׼ȫÇò¹æÄ£Ä򵀮óÒµ£¬£¬£¬£¬£¬£¬£¬Ä¿µÄÐÐÒµ°üÀ¨ÔËÊäºÍÎïÁ÷¡¢Ò½ÁƱ£½¡¡¢ÊÕÖ§¿Ú¡¢Êг¡ÓªÏúºÍũҵµÈ¡£¡£¡£¡£ ¡£¡£HawkEyeÖ¼ÔÚÇÔÈ¡ÊÜѬȾװ±¸µÄÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ËüÒ²¿ÉÓÃ×÷¼ÓÔØÆ÷£¬£¬£¬£¬£¬£¬£¬Ê¹Óý©Ê¬ÍøÂçÏòµÚÈý·½·¸·¨ÕßÌṩpayload·Ö·¢Ð§ÀÍ¡£¡£¡£¡£ ¡£¡£ÕâЩHawkEyeÑù±¾Ö÷Ҫͨ¹ýÀ¬»øÓʼþ¾ÙÐзַ¢¡£¡£¡£¡£ ¡£¡£
  Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/malspam-campaigns-use-hawkeye-keylogger-to-target-businesses/

4Õë¶Ô°ÄÐÂÒøÐеĴ¹ÂÚ¹¥»÷À˳±£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÇÔÈ¡Óû§Æ¾Ö¤


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


·¸·¨·Ö×ÓÕýÔÚʹÓðÄÐÂÒøÐУ¨ANZ Banking Group£©¾ÙÐÐÐÂÒ»²¨µÄ´¹ÂÚ¹¥»÷¡£¡£¡£¡£ ¡£¡£Æ¾Ö¤MailGuardµÄ±¨¸æ£¬£¬£¬£¬£¬£¬£¬´¹ÂÚÓʼþαװ³É¡°BPAY¸¶¿î֪ͨ¡±£¬£¬£¬£¬£¬£¬£¬°üÀ¨¿Í»§´úÂë¡¢¸¶¿î½ð¶î¡¢¸¶¿îÈÕÆÚµÈϸ½Ú£¬£¬£¬£¬£¬£¬£¬ÒªÇóÊÕ¼þÈËͨ¹ý»á¼ûÓʼþÖеÄÁ´½ÓÀ´ÑéÖ¤ÉúÒâ»ò¸üÐÂÆäÕË»§¡£¡£¡£¡£ ¡£¡£µ±Óû§µã»÷¸ÃÁ´½Óʱ£¬£¬£¬£¬£¬£¬£¬½«±»Öض¨ÏòÖÁÄ£ÄâANZµÄ´¹ÂÚÍøÕ¾£¬£¬£¬£¬£¬£¬£¬ÒÔÇÔÈ¡Óû§µÄÒøÐлá¼ûƾ֤¡£¡£¡£¡£ ¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.mailguard.com.au/blog/anz-phishing-email-scam-tells-users-their-security-challenge-answers-are-incorrect

5FlipboardÊý¾Ý¿âÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬Óû§Êý¾Ý±»ÇÔ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÐÂΞۺÏÍøÕ¾FlipboardÌåÏÖÆäÊý¾Ý¿âÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜÏÂÔØÁËÓû§µÄÕË»§ÐÅÏ¢ºÍÊý×ÖÁîÅÆµÈÊý¾Ý¡£¡£¡£¡£ ¡£¡£¹¥»÷Õß¹²ÔÚÁ½¸ö²î±ðµÄʱ¼ä¶Î»á¼ûÁËÆäÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬°üÀ¨2018Äê6ÔÂ2ÈÕµ½2019Äê3ÔÂ23ÈÕʱ´úºÍ2019Äê4ÔÂ21ÈÕÖÁ22ÈÕʱ´ú¡£¡£¡£¡£ ¡£¡£ÏÖÔÚÉв»¿ÉÈ·ÈÏÕâÁ½ÆðÊÂÎñÊÇ·ñΪͳһ¹¥»÷ÕßËùΪ¡£¡£¡£¡£ ¡£¡£FlipboardÌåÏÖÈÔÔÚ¾ÙÐÐÊӲ죬£¬£¬£¬£¬£¬£¬ÏÖÔÚ»¹²»ÇåÎúÓм¸¶àÓû§Êܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬µ«ÒѾöÒéÖØÖÃËùÓÐÓû§µÄÃÜÂë¡£¡£¡£¡£ ¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/flipboard-databases-hacked-and-user-information-exposed/

6¶à¸öCIЧÀÍй¶¹«Ë¾ÉñÃØ£¬£¬£¬£¬£¬£¬£¬°üÀ¨Github»á¼ûÁîÅÆ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ñо¿Ö°Ô±·¢Ã÷¶à¸öCIЧÀÍÈÔÈ»ÔÚÆä¹¹½¨ÈÕÖ¾ÖÐй¶¹«Ë¾µÄÉñÃØÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬°üÀ¨GithubµÄ»á¼ûÁîÅÆ¡£¡£¡£¡£ ¡£¡£Ò»Á¬¼¯³É£¨CI£©Ð§ÀÍÓÃÓÚÔÚÔçÆÚ½×¶Î¼ì²â±àÂëÀú³ÌÖеĹýʧ£¬£¬£¬£¬£¬£¬£¬ÕâЩЧÀ͵ÄÈÕÖ¾ÖмͼÁËÏîÄ¿ÈÕÖ¾¡¢ÓëÔ¶³ÌЧÀÍÆ÷ºÍAPIµÄ½»»¥¡¢ÃÜÂë¡¢SSHÃÜÔ¿¼°APIÁîÅÆµÈÃô¸ÐÐÅÏ¢¡£¡£¡£¡£ ¡£¡£ÓÉÓÚÓëGitHubµÄ¼¯³ÉÐÔ£¬£¬£¬£¬£¬£¬£¬Travis CIÊÇʹÓÃ×îÆÕ±éµÄCIЧÀÍ£¬£¬£¬£¬£¬£¬£¬ÆäËüCIЧÀͰüÀ¨Circle CIºÍGitLab CIµÈ¡£¡£¡£¡£ ¡£¡£Ñо¿Ö°Ô±·¢Ã÷GrammarlyºÍDiscourseµÄCI¹¹½¨ÈÕÖ¾¶¼Òò´Ëй¶Á˹«Ë¾ÐÅÏ¢¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/ci-services-expose-company-secrets-including-github-access-tokens-9e642006