CNCERTÐû²¼¡¶2019ÄêÉϰëÄêÎÒ¹ú»¥ÁªÍøÍøÂçÇå¾²Ì¬ÊÆ¡·£»£»£»£»Sweet ChatÒâÍâй¶½ü1000ÍòÓû§µÄÕÕÆ¬¼°Ì¸ÌìÄÚÈÝ
Ðû²¼Ê±¼ä 2019-08-14
ÔÎÄÁ´½Ó£ºhttps://www.cert.org.cn/publish/main/upload/File/2019%20First%20half%20year%20.pdf
2¡¢Sweet ChatÒâÍâй¶½ü1000ÍòÓû§µÄÕÕÆ¬¼°Ì¸ÌìÄÚÈÝ
Çå¾²Ñо¿Ô±Darryl Burke·¢Ã÷̸ÌìÓ¦ÓÃSweet ChatµÄÒ»¸ö²»Çå¾²µÄЧÀÍÆ÷̻¶ÁËÁè¼Ý1000ÍòÓû§µÄÃô¸ÐÐÅÏ¢£¬£¬£¬ÕâЩÐÅÏ¢°üÀ¨ÊµÊ±Ì¸ÌìÄÚÈÝÒÔ¼°Ë½ÈËÕÕÆ¬µÈ¡£¡£¡£¡£¡£¡£¡£BurkeÌåÏÖÈκÎÓµÓÐMQTT¹¥»÷¹¤¾ßµÄÈ˶¼¿ÉÒÔÔÚÏßÉó²éÕâЩÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÓÚ7ÔÂ21ÈÕ֪ͨÁ˸ù«Ë¾£¬£¬£¬µ«¸Ã¹«Ë¾Ö±ÖÁ8ÔÂ12ÈղŶԸÃЧÀÍÆ÷¾ÙÐÐÁËÔÝʱÐÞ¸´¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://blog.burke-consulting.net/sweet-chat/
3¡¢LEEÊý¾Ý¿âδÉèÃÜÂ룬£¬£¬369ÍòÓû§µÄÒþ˽ÐÅϢй¶

Çå¾²Ñо¿Ô±Jeremiah Fowler·¢Ã÷ÊôÓÚ·ÇÓªÀû×éÖ¯LEEµÄÒ»¸öElasticsearchÊý¾Ý¿âδÊܱ£»£»£»£»¤£¬£¬£¬µ¼ÖÂ369ÍòÓû§µÄ520ÍòÌõÃô¸Ð¼Í¼й¶¡£¡£¡£¡£¡£¡£¡£Êý¾Ý¿âÖаüÀ¨µÄÃô¸ÐÐÅÏ¢°üÀ¨ÐÕÃû¡¢¼Òͥסַ¡¢ÐÔ±ð¡¢ÖÖ×åÒÔ¼°IPµØµã¡¢¶Ë¿ÚºÅ¡¢Â·¾¶ÒÔ¼°´æ´¢ÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£¡£ÔÚ½Óµ½±¨¸æºó£¬£¬£¬¸Ã×éÖ¯ÓÚ7ÔÂ31ÈÕÒÆ³ýÁËÊý¾Ý¿âµÄ¹ûÕæ»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://securitydiscovery.com/leadership-for-educational-equity/
4¡¢Charleston CountyÒâÍâй¶800ÃûÔ±¹¤µÄÃô¸ÐÐÅÏ¢
ÃÀ¹úCharleston CountyÒâÍâй¶ÁË824ÃûÔ±¹¤µÄÒþ˽ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤ÍâµØ¾¯Ô±³¤°ì¹«ÊÒÎüÊÕµ½µÄ֪ͨ£¬£¬£¬ÕâÒ»ÊÂÎñµÄÒòÓÉÊÇÈËΪʧÎ󣬣¬£¬Ò»ÃûHR¹ýʧµØ½«Ô±¹¤ÐÅÏ¢ÁÐ±í·¢Ë͸øÒ»ÃûǰԱ¹¤¡£¡£¡£¡£¡£¡£¡£ÁбíÖеÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢³öÉúÈÕÆÚ¡¢Éç»áÇå¾²ºÅÂë¡¢ÐÔ±ð¡¢Ð½Ë®¡¢¹ÍÓ¶ÈÕÆÚÒÔ¼°Ïà¹ØÆÀ¼ÛµÈ¡£¡£¡£¡£¡£¡£¡£Ã»ÓÐÒøÐп¨ÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.live5news.com/2019/08/13/data-breach-exposes-information-more-than-charleston-co-employees/
5¡¢ÐÂAndroidÒøÐÐľÂíCerberus£¬£¬£¬Ãé×¼30¶à¼ÒÒøÐÐ
ÐÂAndroidÒøÐÐľÂíCerberusÕýÔÚ°µÍøÌṩ×âÓÃЧÀÍ¡£¡£¡£¡£¡£¡£¡£CerberusµÄ¿ª·¢ÕßÔÚTwitterÉϳÆCerberus²¢Ã»ÓÐʹÓÃÈκÎÏÖÓÐÒøÐÐľÂíµÄ´úÂë¡£¡£¡£¡£¡£¡£¡£Ëû»¹ÌåÏÖ¸ÃľÂíÒÑÔÚÒÑÍùÁ½ÄêÖб»ÓÃÓÚ˽ÃܵĹ¥»÷»î¶¯£¬£¬£¬²¢ÓÚÁ½¸öÔÂǰ×îÏÈÌṩ³ö×âЧÀÍ£¬£¬£¬¼ÛǮΪ2000ÃÀÔªÒ»¸öÔ£¬£¬£¬°ëÄê»òÄê×âÓÐÓŻݡ£¡£¡£¡£¡£¡£¡£Æ¾Ö¤Threat FabricÑо¿Ö°Ô±µÄ±¨¸æ£¬£¬£¬¸ÃÒøÐÐľÂíͬʱ»¹¾ßÓÐÔ¶¿Ø¹¦Ð§£¬£¬£¬¿ÉÕë¶Ô30¸öÄ¿µÄ×éÖ¯£¬£¬£¬°üÀ¨7¼Ò·¨¹úÒøÐС¢7¼ÒÃÀ¹úÒøÐкÍ1¼ÒÈÕ±¾ÒøÐеȡ£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/08/cerberus-android-banking-trojan.html
6¡¢Ð¶ñÒâÈí¼þXwo£¬£¬£¬Ö÷ÒªÇÔÈ¡Óû§µÄµÇ¼ƾ֤
AT&TÑо¿ÍŶӷ¢Ã÷жñÒâÈí¼þXwo£¬£¬£¬¸Ã¶ñÒâÈí¼þÖ÷ҪɨÃèϵͳÉÏ´æ´¢µÄƾ֤ÒÔ¼°Ì»Â¶µÄЧÀÍ£¬£¬£¬²¢½«É¨ÃèЧ¹û·¢ËÍÖÁC&CЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£ËüɨÃèµÄÄ¿µÄЧÀͰüÀ¨Ê¹ÓÃĬÈÏÃÜÂëµÄMongoDB¡¢Memcached¡¢MySQL¡¢PostgreSQL¡¢Tomcat¡¢RedisÒÔ¼°FTPµÈ£¬£¬£¬Ëü»¹¿ÉÒÔ´ÓĬÈÏSVN¼°Git·¾¶ÍøÂçÐÅÏ¢£¬£¬£¬Ñо¿Ö°Ô±ÒÔΪÕâÖÖÐÅÏ¢ÍøÂç¿ÉÄÜÊÇΪδÀ´µÄ´ó¹æÄ£¹¥»÷»î¶¯×ö×¼±¸¡£¡£¡£¡£¡£¡£¡£XwoµÄ»ù´¡ÉèÊ©ÓëMongoLock¼°X Bash±£´æÏàËÆÖ®´¦£¬£¬£¬ÕâÒâζ×ÅÕâÈý¸ö¶ñÒâÈí¼þ¿ÉÄÜÀ´×ÔÓÚͳһ¸ö¹¥»÷Õß¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bmmagazine.co.uk/business/new-malware-xwo-can-swipe-all-your-credentials-at-once/