¶ò¹Ï¶à¶û´ó²¿·Ö¹«ÃñÒþ˽й¶£¬£¬£¬£¬°üÀ¨670Íò¶ùͯÐÅÏ¢£»£»£»£»2430ÍòLumin PDFÓû§ÐÅÏ¢ÔÚ°µÍøÂÛ̳й¶
Ðû²¼Ê±¼ä 2019-09-171.¶ò¹Ï¶à¶û´ó²¿·Ö¹«ÃñÒþ˽й¶£¬£¬£¬£¬°üÀ¨670Íò¶ùͯÐÅÏ¢
Ñо¿Ö°Ô±·¢Ã÷Ò»¼ÒÍâµØ¹«Ë¾NovaestratµÄElasticsearchЧÀÍÆ÷̻¶Á˶ò¹Ï¶à¶û´ó´ó¶¼¹«ÃñµÄÒþ˽ÐÅÏ¢¡£¡£¡£¶ò¹Ï¶à¶ûµÄÉú³Ý»ùÊýΪ1660Íò£¬£¬£¬£¬¶ø¸ÃÊý¾Ý¿â°üÀ¨½ü2080ÍòÌõÓû§¼Í¼£¬£¬£¬£¬Áè¼ÝÁ˸ùúµÄÉú³ÝÊý¾Ý£¬£¬£¬£¬ÆäÔµ¹ÊÔÓÉÊÇÊý¾Ý¿âÖаüÀ¨Ò»Ð©Öظ´¼Í¼ºÍéæÃü¹«ÃñµÄ¼Í¼¡£¡£¡£Ð¹Â¶µÄÊý¾Ý°üÀ¨ÐÕÃû¡¢¼ÒÍ¥³ÉÔ±/¼Ò×åÊ÷¡¢¹«Ãñ×¢²áÊý¾Ý¡¢²ÆÎñ¼°ÊÂÇéÐÅÏ¢¡¢³µÁ¾ÐÅÏ¢µÈ¡£¡£¡£Êý¾Ý¿âÖл¹°üÀ¨Õþ¸®Ô±¹¤ÐÅÏ¢ºÍ677Íò¶ùͯÐÅÏ¢£¬£¬£¬£¬ÒÔ¼°700ÍòÌõ²ÆÎñ¼Í¼ºÍ250ÍòÌõ³µÁ¾¼Í¼¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/database-leaks-data-on-most-of-ecuadors-citizens-including-6-7-million-children/
2.2430ÍòLumin PDFÓû§ÐÅÏ¢ÔÚ°µÍøÂÛ̳й¶
Ò»ÃûºÚ¿ÍÔÚ°µÍøÂÛ̳ÉÏÐû²¼ÁËLumin PDF¹«Ë¾µÄÍêÕûÊý¾Ý¿âÏÂÔØÁ´½Ó£¬£¬£¬£¬¸ÃÊý¾Ý¿âΪ4.06GBµÄCSVÎļþ£¬£¬£¬£¬ÆäÖаüÀ¨2438ÍòÌõÓû§¼Í¼¡£¡£¡£Êý¾Ý°üÀ¨Óû§µÄÈ«Ãû¡¢ÓʼþµØµã¡¢ÐÔ±ð¡¢ÓïÑÔÉèÖᢹþÏ£ÃÜÂë»ò¹È¸è»á¼ûÁîÅÆ¡£¡£¡£ZDNetÑéÖ¤ÁËÕâЩÊý¾ÝµÄÕæÊµÐÔ¡£¡£¡£ºÚ¿Í³ÆÕâЩÊý¾ÝÀ´×ÔÓÚ2019Äê4Ô·ݸù«Ë¾Ì»Â¶ÔÚ¹«ÍøÉϵÄMongoDBÊý¾Ý¿âÖУ¬£¬£¬£¬¸ÃÊý¾Ý¿â²¢Î´Êܵ½ÃÜÂë±£»£»£»£»¤£¬£¬£¬£¬²¢Ëæºó±»ÀÕË÷Èí¼þÆÆË𡣡£¡£Lumin PDFÉÐδ¶Ô´ËʾÙÐлظ´¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/data-of-24-3-million-lumin-pdf-users-shared-on-hacking-forum/
3.EmotetÔÚÇÄÈ»4¸öÔºóÔÙ´ÎÌᳫÐÂÀ¬»øÓʼþ»î¶¯
×Ô5ÔÂβ½øÈëĬȻÒÔÀ´£¬£¬£¬£¬½©Ê¬ÍøÂçEmotetÒѾÇÄÈ»Á˽ü4¸öÔµÄʱ¼ä£¬£¬£¬£¬ÔÚ´Ëʱ´úEmotetµÄC&CЧÀÍÆ÷×èÖ¹ÁËÏòÊÜѬȾװ±¸·¢ËÍÏÂÁî¡£¡£¡£Çå¾²Ñо¿Ô±Raashid BhatÊӲ쵽EmotetÔÚ9ÔÂ16ºÅÔÙ´ÎÌᳫÁËеÄÀ¬»øÓʼþ»î¶¯£¬£¬£¬£¬ÏÖÔÚÕâЩÀ¬»øÓʼþÖ÷ÒªÕë¶Ô²¨À¼ºÍµÂ¹úÓû§£¬£¬£¬£¬ÓʼþÖаüÀ¨¶ñÒ⸽¼þ»òÏÂÔØ¶ñÒâÈí¼þµÄÁ´½Ó¡£¡£¡£Õâ¸öÐµĹ¥»÷»î¶¯ÔÚÑо¿Ö°Ô±µÄÔ¤¼ÆÖ®ÖУ¬£¬£¬£¬ÓÉÓÚÔÚ´ËǰµÄ±¨µÀÖÐEmotetµÄC&CЧÀÍÆ÷ÔÚ8ÔÂβÔٴνøÈë»îԾ״̬£¬£¬£¬£¬µ«ËüÃDz¢Ã»ÓÐÁ¬Ã¦½øÈëÀ¬»øÓʼþ·¢ËÍģʽ£¬£¬£¬£¬¶øÊÇÔÚ·Ö·¢EmotetµÄС°ºáÏòÒÆ¶¯¡±ºÍ¡°Æ¾Ö¤ÇÔÈ¡¡±Ä£¿£¿£¿£¿£¿£¿£¿é¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/emotet-todays-most-dangerous-botnet-comes-back-to-life/
4.AstarothбäÖÖʹÓÃFacebookºÍYouTubeÀ´Èƹý¼ì²â
CofenseÑо¿Ö°Ô±·¢Ã÷AstarothľÂíµÄÒ»¸öбäÌåʹÓÃFacebookºÍYouTubeÀ´Èƹý¼ì²â¡£¡£¡£Õâ¸öеĴ¹ÂڻÖ÷ÒªÕë¶Ô°ÍÎ÷¹«Ãñ£¬£¬£¬£¬Ñ¬È¾Á´Ïàµ±ÖØ´ó£¬£¬£¬£¬ÒÔÒ»¸ö.htm¸½¼þ×îÏÈ£¬£¬£¬£¬µ±Óû§µã»÷¸½¼þʱ£¬£¬£¬£¬»áÏÂÔØÒ»¸ö.zipÎļþ£¬£¬£¬£¬½âѹËõ»ñµÃÒ»¸ö.lnkÎļþ£¬£¬£¬£¬È»ºó´ÓÒ»¸öCloudflare workerÓòÃûÉÏÏÂÔØJavaScript´úÂ룬£¬£¬£¬×îºóÔÙÏÂÔØÓÃÓÚ»ìÏýºÍÖ´ÐÐAstarothµÄ¶ñÒâÄ£¿£¿£¿£¿£¿£¿£¿éºÍpayload¡£¡£¡£Ñо¿Ö°Ô±ÊӲ쵽¸ÃAstaroth±äÌåʹÓÃYouTubeºÍFacebookµÄÓû§ÐÅÏ¢Ò³ÃæÀ´ÍйܺÍά»¤C2ÉèÖÃÊý¾Ý¡£¡£¡£ÕâÖÖ¼¼ÇÉ¿ÉÈÆ¹ýÄÚÈݹýÂ˵ÈÍøÂçÇå¾²²½·¥¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/91296/malware/astaroth-trojan-fb-youtube.html
5.·¸·¨ÍÅ»ïðûÊÕ˾¸ß¹Ü¹ºÖÃÊý×ÖÖ¤ÊéÀ´Èö²¥¶ñÒâÈí¼þ
ReversingLabs·¢Ã÷Ò»¸öÐµķ¸·¨ÍÅ»ïαװ³ÉÕýµ±»ú¹¹µÄ¸ß¹ÜÊÔͼڲÆÐԵعºÖÃÊý×ÖÖ¤Ê飬£¬£¬£¬È»ºó½«ÕâЩÕýµ±Ö¤ÊéÔÚ°µÍøÉϳöÊÛÒÔ¶Ô¶ñÒâÎļþ£¨Ö÷ÒªÊÇ¹ã¸æÈí¼þ£©¾ÙÐÐÊðÃû¡£¡£¡£Ñо¿Ö°Ô±¸ÅÊöÁ˸ÃڲƻµÄ¼¸¸öÖ÷Òª°ì·¨£¬£¬£¬£¬°üÀ¨Í¨¹ýÑо¿¹ûÕæµÄÐÅÏ¢²¢×ñÕÕÌØ¶¨µÄ±ê×¼À´È·¶¨ÒªÎ±×°µÄÄ¿µÄ£¬£¬£¬£¬¹¹½¨¿´ÆðÀ´Õýµ±µÄ»ù´¡ÉèÊ©£¨ÀýÈç×¢²áÓòÃû¡¢Öض¨Ïòµç×ÓÓʼþµÈ£©ÒÔÓÕÆÖ¤Êé½ÒÏþ»ú¹¹£¬£¬£¬£¬×îºó¹ºÖÃÖ¤Êé²¢ÔÚ°µÍø³öÊÛ¡£¡£¡£Ñо¿Ö°Ô±ÊӲ쵽ÕâЩ֤Êé±»ÓÃÓÚ¶ÔOpenSupdaterµÈ¹ã¸æÈí¼þ¾ÙÐÐÊðÃû¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/threat-actor-buys-digital-certs-spreads-malware/148345/
6.ÃÜÂëÖÎÀíÆ÷LastPass²å¼þÎó²î¿Éµ¼ÖÂÆ¾Ö¤Ð¹Â¶
LastPassÃÜÂëÖÎÀíÆ÷²å¼þÖеÄÎó²î¿ÉÔÊÐí¹¥»÷ÕßÇÔÈ¡Óû§×îºóµÇÂ¼ÍøÒ³µÄƾ֤¡£¡£¡£¹È¸èÇå¾²Ñо¿Ô±Tavis Ormandy·¢Ã÷¹¥»÷Õß¿ÉΪʹÓÃlastpassµÇ¼ÕË»§µÄÓû§½¨ÉèÒ»¸öÓÐÓõĵã»÷Ð®ÖÆ³¡¾°£¬£¬£¬£¬½«ÆäÖØ¶¨ÏòÖÁ°üÀ¨¶ñÒâiframeµÄÍøÕ¾¡£¡£¡£Í¨¹ýÔÚiframeÖа²ÅÅÓÃÓÚÌîдÃÜÂëµÄµ¯´°£¬£¬£¬£¬¹¥»÷Õß¿ÉÌø¹ýÑéÖ¤Á´²¢ÇÔȡĿ½ñ±êÇ©×îºó»º´æµÄÖµ¡£¡£¡£ÕâÒâζ×Åͨ¹ýµã»÷Ð®ÖÆ¿ÉÒÔµ¼ÖÂÔÚÄ¿½ñ±êÇ©ÉϵǼµÄ×îºóÒ»¸öÍøÕ¾µÄƾ֤й¶¡£¡£¡£¸ÃÎÊÌâÖ÷ÒªÓ°ÏìÁËChromeºÍOperaä¯ÀÀÆ÷¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/password-revealing-bug-quickly-fixed-in-lastpass-extensions/