¶ò¹Ï¶à¶û´ó²¿·Ö¹«ÃñÒþ˽й¶£¬ £¬£¬£¬°üÀ¨670Íò¶ùͯÐÅÏ¢£»£» £»£»2430ÍòLumin PDFÓû§ÐÅÏ¢ÔÚ°µÍøÂÛ̳й¶

Ðû²¼Ê±¼ä 2019-09-17

1.¶ò¹Ï¶à¶û´ó²¿·Ö¹«ÃñÒþ˽й¶£¬ £¬£¬£¬°üÀ¨670Íò¶ùͯÐÅÏ¢


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ñо¿Ö°Ô±·¢Ã÷Ò»¼ÒÍâµØ¹«Ë¾NovaestratµÄElasticsearchЧÀÍÆ÷̻¶Á˶ò¹Ï¶à¶û´ó´ó¶¼¹«ÃñµÄÒþ˽ÐÅÏ¢¡£¡£¡£¶ò¹Ï¶à¶ûµÄÉú³Ý»ùÊýΪ1660Íò£¬ £¬£¬£¬¶ø¸ÃÊý¾Ý¿â°üÀ¨½ü2080ÍòÌõÓû§¼Í¼£¬ £¬£¬£¬Áè¼ÝÁ˸ùúµÄÉú³ÝÊý¾Ý£¬ £¬£¬£¬ÆäÔµ¹ÊÔ­ÓÉÊÇÊý¾Ý¿âÖаüÀ¨Ò»Ð©Öظ´¼Í¼ºÍéæÃü¹«ÃñµÄ¼Í¼¡£¡£¡£Ð¹Â¶µÄÊý¾Ý°üÀ¨ÐÕÃû¡¢¼ÒÍ¥³ÉÔ±/¼Ò×åÊ÷¡¢¹«Ãñ×¢²áÊý¾Ý¡¢²ÆÎñ¼°ÊÂÇéÐÅÏ¢¡¢³µÁ¾ÐÅÏ¢µÈ¡£¡£¡£Êý¾Ý¿âÖл¹°üÀ¨Õþ¸®Ô±¹¤ÐÅÏ¢ºÍ677Íò¶ùͯÐÅÏ¢£¬ £¬£¬£¬ÒÔ¼°700ÍòÌõ²ÆÎñ¼Í¼ºÍ250ÍòÌõ³µÁ¾¼Í¼¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/database-leaks-data-on-most-of-ecuadors-citizens-including-6-7-million-children/


2.2430ÍòLumin PDFÓû§ÐÅÏ¢ÔÚ°µÍøÂÛ̳й¶


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ò»ÃûºÚ¿ÍÔÚ°µÍøÂÛ̳ÉÏÐû²¼ÁËLumin PDF¹«Ë¾µÄÍêÕûÊý¾Ý¿âÏÂÔØÁ´½Ó£¬ £¬£¬£¬¸ÃÊý¾Ý¿âΪ4.06GBµÄCSVÎļþ£¬ £¬£¬£¬ÆäÖаüÀ¨2438ÍòÌõÓû§¼Í¼¡£¡£¡£Êý¾Ý°üÀ¨Óû§µÄÈ«Ãû¡¢ÓʼþµØµã¡¢ÐÔ±ð¡¢ÓïÑÔÉèÖᢹþÏ£ÃÜÂë»ò¹È¸è»á¼ûÁîÅÆ¡£¡£¡£ZDNetÑéÖ¤ÁËÕâЩÊý¾ÝµÄÕæÊµÐÔ¡£¡£¡£ºÚ¿Í³ÆÕâЩÊý¾ÝÀ´×ÔÓÚ2019Äê4Ô·ݸù«Ë¾Ì»Â¶ÔÚ¹«ÍøÉϵÄMongoDBÊý¾Ý¿âÖУ¬ £¬£¬£¬¸ÃÊý¾Ý¿â²¢Î´Êܵ½ÃÜÂë±£»£» £»£»¤£¬ £¬£¬£¬²¢Ëæºó±»ÀÕË÷Èí¼þÆÆË𡣡£¡£Lumin PDFÉÐδ¶Ô´ËʾÙÐлظ´¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/data-of-24-3-million-lumin-pdf-users-shared-on-hacking-forum/


3.EmotetÔÚÇÄÈ»4¸öÔºóÔÙ´ÎÌᳫÐÂÀ¬»øÓʼþ»î¶¯


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


×Ô5ÔÂβ½øÈëĬȻÒÔÀ´£¬ £¬£¬£¬½©Ê¬ÍøÂçEmotetÒѾ­ÇÄÈ»Á˽ü4¸öÔµÄʱ¼ä£¬ £¬£¬£¬ÔÚ´Ëʱ´úEmotetµÄC&CЧÀÍÆ÷×èÖ¹ÁËÏòÊÜѬȾװ±¸·¢ËÍÏÂÁî¡£¡£¡£Çå¾²Ñо¿Ô±Raashid BhatÊӲ쵽EmotetÔÚ9ÔÂ16ºÅÔÙ´ÎÌᳫÁËеÄÀ¬»øÓʼþ»î¶¯£¬ £¬£¬£¬ÏÖÔÚÕâЩÀ¬»øÓʼþÖ÷ÒªÕë¶Ô²¨À¼ºÍµÂ¹úÓû§£¬ £¬£¬£¬ÓʼþÖаüÀ¨¶ñÒ⸽¼þ»òÏÂÔØ¶ñÒâÈí¼þµÄÁ´½Ó¡£¡£¡£Õâ¸öÐµĹ¥»÷»î¶¯ÔÚÑо¿Ö°Ô±µÄÔ¤¼ÆÖ®ÖУ¬ £¬£¬£¬ÓÉÓÚÔÚ´ËǰµÄ±¨µÀÖÐEmotetµÄC&CЧÀÍÆ÷ÔÚ8ÔÂβÔٴνøÈë»îԾ״̬£¬ £¬£¬£¬µ«ËüÃDz¢Ã»ÓÐÁ¬Ã¦½øÈëÀ¬»øÓʼþ·¢ËÍģʽ£¬ £¬£¬£¬¶øÊÇÔÚ·Ö·¢EmotetµÄС°ºáÏòÒÆ¶¯¡±ºÍ¡°Æ¾Ö¤ÇÔÈ¡¡±Ä£¿£¿£¿£¿£¿£¿£¿é¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/emotet-todays-most-dangerous-botnet-comes-back-to-life/


4.AstarothбäÖÖʹÓÃFacebookºÍYouTubeÀ´Èƹý¼ì²â


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


CofenseÑо¿Ö°Ô±·¢Ã÷AstarothľÂíµÄÒ»¸öбäÌåʹÓÃFacebookºÍYouTubeÀ´Èƹý¼ì²â¡£¡£¡£Õâ¸öеĴ¹ÂڻÖ÷ÒªÕë¶Ô°ÍÎ÷¹«Ãñ£¬ £¬£¬£¬Ñ¬È¾Á´Ïàµ±ÖØ´ó£¬ £¬£¬£¬ÒÔÒ»¸ö.htm¸½¼þ×îÏÈ£¬ £¬£¬£¬µ±Óû§µã»÷¸½¼þʱ£¬ £¬£¬£¬»áÏÂÔØÒ»¸ö.zipÎļþ£¬ £¬£¬£¬½âѹËõ»ñµÃÒ»¸ö.lnkÎļþ£¬ £¬£¬£¬È»ºó´ÓÒ»¸öCloudflare workerÓòÃûÉÏÏÂÔØJavaScript´úÂ룬 £¬£¬£¬×îºóÔÙÏÂÔØÓÃÓÚ»ìÏýºÍÖ´ÐÐAstarothµÄ¶ñÒâÄ£¿£¿£¿£¿£¿£¿£¿éºÍpayload¡£¡£¡£Ñо¿Ö°Ô±ÊӲ쵽¸ÃAstaroth±äÌåʹÓÃYouTubeºÍFacebookµÄÓû§ÐÅÏ¢Ò³ÃæÀ´ÍйܺÍά»¤C2ÉèÖÃÊý¾Ý¡£¡£¡£ÕâÖÖ¼¼ÇÉ¿ÉÈÆ¹ýÄÚÈݹýÂ˵ÈÍøÂçÇå¾²²½·¥¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/91296/malware/astaroth-trojan-fb-youtube.html


5.·¸·¨ÍÅ»ïðûÊÕ˾¸ß¹Ü¹ºÖÃÊý×ÖÖ¤ÊéÀ´Èö²¥¶ñÒâÈí¼þ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ReversingLabs·¢Ã÷Ò»¸öÐµķ¸·¨ÍÅ»ïαװ³ÉÕýµ±»ú¹¹µÄ¸ß¹ÜÊÔͼڲƭÐԵعºÖÃÊý×ÖÖ¤Ê飬 £¬£¬£¬È»ºó½«ÕâЩÕýµ±Ö¤ÊéÔÚ°µÍøÉϳöÊÛÒÔ¶Ô¶ñÒâÎļþ£¨Ö÷ÒªÊÇ¹ã¸æÈí¼þ£©¾ÙÐÐÊðÃû¡£¡£¡£Ñо¿Ö°Ô±¸ÅÊöÁ˸Ãڲƭ»î¶¯µÄ¼¸¸öÖ÷Òª°ì·¨£¬ £¬£¬£¬°üÀ¨Í¨¹ýÑо¿¹ûÕæµÄÐÅÏ¢²¢×ñÕÕÌØ¶¨µÄ±ê×¼À´È·¶¨ÒªÎ±×°µÄÄ¿µÄ£¬ £¬£¬£¬¹¹½¨¿´ÆðÀ´Õýµ±µÄ»ù´¡ÉèÊ©£¨ÀýÈç×¢²áÓòÃû¡¢Öض¨Ïòµç×ÓÓʼþµÈ£©ÒÔÓÕÆ­Ö¤Êé½ÒÏþ»ú¹¹£¬ £¬£¬£¬×îºó¹ºÖÃÖ¤Êé²¢ÔÚ°µÍø³öÊÛ¡£¡£¡£Ñо¿Ö°Ô±ÊӲ쵽ÕâЩ֤Êé±»ÓÃÓÚ¶ÔOpenSupdaterµÈ¹ã¸æÈí¼þ¾ÙÐÐÊðÃû¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/threat-actor-buys-digital-certs-spreads-malware/148345/


6.ÃÜÂëÖÎÀíÆ÷LastPass²å¼þÎó²î¿Éµ¼ÖÂÆ¾Ö¤Ð¹Â¶


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


LastPassÃÜÂëÖÎÀíÆ÷²å¼þÖеÄÎó²î¿ÉÔÊÐí¹¥»÷ÕßÇÔÈ¡Óû§×îºóµÇÂ¼ÍøÒ³µÄƾ֤¡£¡£¡£¹È¸èÇå¾²Ñо¿Ô±Tavis Ormandy·¢Ã÷¹¥»÷Õß¿ÉΪʹÓÃlastpassµÇ¼ÕË»§µÄÓû§½¨ÉèÒ»¸öÓÐÓõĵã»÷Ð®ÖÆ³¡¾°£¬ £¬£¬£¬½«ÆäÖØ¶¨ÏòÖÁ°üÀ¨¶ñÒâiframeµÄÍøÕ¾¡£¡£¡£Í¨¹ýÔÚiframeÖа²ÅÅÓÃÓÚÌîдÃÜÂëµÄµ¯´°£¬ £¬£¬£¬¹¥»÷Õß¿ÉÌø¹ýÑéÖ¤Á´²¢ÇÔȡĿ½ñ±êÇ©×îºó»º´æµÄÖµ¡£¡£¡£ÕâÒâζ×Åͨ¹ýµã»÷Ð®ÖÆ¿ÉÒÔµ¼ÖÂÔÚÄ¿½ñ±êÇ©ÉϵǼµÄ×îºóÒ»¸öÍøÕ¾µÄƾ֤й¶¡£¡£¡£¸ÃÎÊÌâÖ÷ÒªÓ°ÏìÁËChromeºÍOperaä¯ÀÀÆ÷¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/password-revealing-bug-quickly-fixed-in-lastpass-extensions/