Pwn2OwnºÚ¿Í´óÈüÊ×´ÎÉæ¼°¹¤Òµ¿ØÖÆÏµÍ³£»£»£»£»£»£» £»Î¢Èí³Æ2020Äê°ÂÔ˻Ὣ¿ÉÄܳÉΪAPT28µÄ¹¥»÷¹¤¾ß

Ðû²¼Ê±¼ä 2019-10-30
1¡¢Pwn2OwnºÚ¿Í´óÈüÊ×´ÎÉæ¼°¹¤Òµ¿ØÖÆÏµÍ³

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

Pwn2OwnºÚ¿Í´óÈü½«ÌṩÁè¼Ý25ÍòÃÀÔªµÄ½±Àø £¬£¬£¬ÒÔÃãÀøÍÚ¾òICSºÍÏà¹ØÐ­ÒéÎó²î¡£¡£¡£¡£¡£ ¡£¡£¸Ã»î¶¯½«ÓÚÃ÷Ä꣨1ÔÂ21ÈÕÖÁ1ÔÂ23ÈÕ£©ÔÚÂõ°¢ÃÜS4¾Û»áʱ´ú¾ÙÐС£¡£¡£¡£¡£ ¡£¡£¡°ºÍÆäËû¾ºÈüÒ»Ñù £¬£¬£¬Pwn2OwnÊÔͼͨ¹ýÕ¹ÏÖÎó²î²¢½«Ñо¿Ð§¹ûÌṩӦ¹©Ó¦ÉÌÀ´Ç¿»¯ÕâЩƽ̨¡± £¬£¬£¬Pwn2Own×éÖ¯Õß¡¢ZDIÌᳫÈËBrian GorencÔÚÖÜÒ»µÄÌû×ÓÖÐÌåÏÖ £¬£¬£¬¡°Pwn2OwnµÄÄ¿µÄʼÖÕÊÇÔÚ¹¥»÷Õ߯ð¾¢Ê¹ÓÃ֮ǰÐÞ¸´ÕâЩÎó²î¡±¡£¡£¡£¡£¡£ ¡£¡£Pwn2Own MiamiΪÎå¸öICSÀà±ðµÄÎó²îÌṩÁËÖÖÖÖ½±Àø £¬£¬£¬°üÀ¨¿ØÖÆÐ§ÀÍÆ÷½â¾ö¼Æ»®¡¢OPCЧÀÍÆ÷¡¢DNP3ͨѶЭÒé¡¢HMI/²Ù×÷Ô±Õ¾ºÍ¹¤³ÌÊÂÇéÕ¾Èí¼þ¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/pwn2own-expands-industrial-control-systems/149594/

2¡¢Ó¡¶È130ÍòÕÅÒøÐп¨ÐÅÏ¢ÔÚJoker's StashÉϳöÊÛ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Group-IBÑо¿Ö°Ô±·¢Ã÷Áè¼Ý130ÍòÕÅÓ¡¶ÈÒøÐп¨ÐÅÏ¢ÔÚJoker's StashÉϳöÊÛ¡£¡£¡£¡£¡£ ¡£¡£Group-IBÌåÏÖÕâЩ¿¨µÄ×î¸ßÊÛ¼ÛΪÿÕÅ¿¨100ÃÀÔª £¬£¬£¬ÕâÒâζ×ÅÆä×ܼÛÖµÁè¼Ý1.3ÒÚÃÀÔª¡£¡£¡£¡£¡£ ¡£¡£ÓÉÓÚÕâЩÊý¾ÝÊÇÔÚ¼¸Ð¡Ê±Ç°Ðû²¼µÄ £¬£¬£¬Ñо¿Ö°Ô±ÉÐûÓÐʱ¼äÆÊÎöºÍÊÓ²ì¿ÉÄܵÄй¿à´Ô´¡£¡£¡£¡£¡£ ¡£¡£ÆðÔ´ÆÊÎöÅú×¢ÕâЩÐÅÏ¢¿ÉÄÜÊÇͨ¹ý×°ÖÃÔÚATM»òPoSϵͳÉÏµÄÆ²ÔüÆ÷ÇÔÈ¡µÄ¡£¡£¡£¡£¡£ ¡£¡£±ðµÄ £¬£¬£¬´Ó·¢¿¨ÒøÐÐÀ´¿´ £¬£¬£¬±»ÇÔ¿¨µÄÖÖÀà·±¶à £¬£¬£¬À´×ÔÓÚ¶à¼ÒÒøÐÐ £¬£¬£¬Õâɨ³ýÁ˵¥ÖðÒ»¼ÒÒøÐÐϵͳ±»ÈëÇֵĿÉÄÜÐÔ¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/details-for-1-3-million-indian-payment-cards-put-up-for-sale-on-jokers-stash/

3¡¢·¨¹úʱÉÐÆ·ÅÆSixth June¹ÙÍøÔâMageCart¹¥»÷

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

·¨¹úʱÉÐÆ·ÅÆSixth June¹ÙÍøÔâMageCart¶ñÒâ¾ç±¾Ñ¬È¾ £¬£¬£¬Çå¾²Ñо¿Ö°Ô±Jenkins·¢Ã÷ÁËÕâÒ»ÊÂÎñ²¢ÓÚÉÏÖÜ֪ͨÁ˸ù«Ë¾ £¬£¬£¬µ«ÉÐδ»ñµÃ»Ø¸´¡£¡£¡£¡£¡£ ¡£¡£×èÖ¹ÏÖÔڸöñÒâ´úÂëÈÔ±£´æÓÚÍøÕ¾µÄÖ§¸¶Ò³ÃæÉÏ¡£¡£¡£¡£¡£ ¡£¡£Sixth JuneÔÚÅ·ÖÞºÜÊܽӴý £¬£¬£¬9ÔÂ·ÝÆäÍøÕ¾µÄ»á¼ûÁ¿Ô¼Îª7ÍòÈ˴Ρ£¡£¡£¡£¡£ ¡£¡£ÆäÍøÕ¾ÒÀÀµÓÚµç×ÓÉÌÎñƽ̨Magento £¬£¬£¬¹¥»÷Õß×¢²áÁËÒ»¸öαװ³ÉMagento¹Ù·½ÓòÃûµÄ¼ÙÓòÃûmogento[.]infoÀ´Òþ²Ø×Ô¼º¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/sixth-june-fashion-site-hacked-to-steal-credit-cards/

4¡¢ÃÀ¹ú¿ì²ÍÁ¬ËøµêKrystalÐû²¼Í¨Öª³ÆÆä¿Í»§ÐÅϢй¶


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÃÀ¹ú¿ì²ÍÁ¬ËøµêKrystalÌåÏÖÆäÖ§¸¶´¦Öóͷ£ÏµÍ³ÔâÓöÇå¾²ÊÂÎñ £¬£¬£¬²¿·Ö²ÍÌüÊܵ½Ó°Ïì¡£¡£¡£¡£¡£ ¡£¡£¸ÃÊÂÎñ±¬·¢ÔÚ2019Äê7ÔÂÖÁ9ÔÂÖ®¼ä £¬£¬£¬ÏÖÔÚÉв»ÖªµÀÊÜ´ËÇå¾²ÊÂÎñÓ°ÏìµÄ¿Í»§ÊýÄ¿ÒÔ¼°Ì»Â¶µÄ¸¶¿îÐÅÏ¢ÀàÐÍ £¬£¬£¬Ò²²»ÇåÎúÇå¾²ÊÂÎñ±³ºóµÄÔµ¹ÊÔ­ÓÉÊÇÖ§¸¶ÏµÍ³Êý¾Ý¿â̻¶/δÊÚȨ»á¼ûÕÕ¾ÉPoS¶ñÒâÈí¼þ¹¥»÷µÈ¡£¡£¡£¡£¡£ ¡£¡£KrystalÌåÏÖÕýÔÚÆð¾¢È·¶¨ÄÄЩ²ÍÌüÊÜÓ°Ïì¼°ÏêϸµÄËùÔÚºÍÈÕÆÚ £¬£¬£¬Ëü»¹ÌåÏÖÒѾ­È·ÈÏÔ¼ÓÐÈý·ÖÖ®Ò»µÄ²ÍÌüûÓÐÊܵ½Ó°Ïì¡£¡£¡£¡£¡£ ¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/us-food-chain-alerts-customers-of-payment-card-incident/

5¡¢Î¢Èí³Æ2020Äê°ÂÔ˻Ὣ¿ÉÄܳÉΪAPT28µÄ¹¥»÷¹¤¾ß


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


΢ÈíÖÒÑÔ³Æ2020Äê¶«¾©°ÂÔË»á¿ÉÄܳÉΪ¶íÂÞ˹ºÚ¿Í×éÖ¯APT28£¨ÓÖÃû»¨Ê½ÐÜ£©µÄ¹¥»÷Ä¿µÄ¡£¡£¡£¡£¡£ ¡£¡£Î¢ÈíÍþвÇ鱨ÖÐÐÄÖ¸³ö £¬£¬£¬ËûÃÇ×·×ÙÁËÕë¶ÔÌåÓýÖ÷¹Ü²¿·ÖºÍ·´Ð˷ܼÁ»ú¹¹µÄ´óÐÍÍøÂç¹¥»÷ £¬£¬£¬×Ô2019Äê9ÔÂ16ÈÕÒÔÀ´À´×ÔÈý´óÖÞµÄ16¸ö¹ú¼ÒºÍ¹ú¼Ê»ú¹¹ÒѾ­³ÉΪ¹¥»÷Ä¿µÄ¡£¡£¡£¡£¡£ ¡£¡£Õâ²»ÊÇ»¨Ê½ÐܵÚÒ»´ÎÕë¶Ô·´Ð˷ܼÁ»ú¹¹ £¬£¬£¬×Ô´ÓWADAÔÚ2016ÄêÀïÔ¼°ÂÔË»áÉÏեȡ¶íÂÞ˹ÔË·¢¶¯²ÎÈüºó £¬£¬£¬¸Ã×éÖ¯Ò»Ö±Õë¶Ô¹ú¼Ê·´Ð˷ܼÁ»ú¹¹¡£¡£¡£¡£¡£ ¡£¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/10/cyber-attack-tokyo-olympics.html

6¡¢Ð¶ñÒâÈí¼þxHelperÒÑѬȾÁè¼Ý4.5Íǫ̀Android×°±¸

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


жñÒâÈí¼þxHelper×îÔçÓÚ3Ô±»·¢Ã÷ £¬£¬£¬8Ô·ÝxHelperÖð½¥Éú³¤µ½Ñ¬È¾ÁËÁè¼Ý3.2Íǫ̀װ±¸ £¬£¬£¬µ½10Ô·ÝÕâÒ»Êý×ÖÒѾ­ÔöÌíµ½4.5Íǫ̀¡£¡£¡£¡£¡£ ¡£¡£ÕâÅú×¢¸Ã¶ñÒâÈí¼þ´¦ÓÚÇåÎúµÄÉÏÉýÇ÷ÊÆ £¬£¬£¬Æ¾Ö¤ÈüÃÅÌú¿ËµÄÊý¾Ý £¬£¬£¬xHelperƽ¾ùÌìÌìѬȾ131ÃûÐÂÊܺ¦Õß £¬£¬£¬Ã¿ÔÂÔ¼ÓÐ2400ÃûÐÂÊܺ¦Õß¡£¡£¡£¡£¡£ ¡£¡£ÕâЩѬȾ´ó¶à±¬·¢ÔÚÓ¡¶È¡¢ÃÀ¹úºÍ¶íÂÞ˹¡£¡£¡£¡£¡£ ¡£¡£Æ¾Ö¤MalwarebytesµÄ˵·¨ £¬£¬£¬xHelperÖ÷Ҫͨ¹ýµÚÈý·½Ó¦ÓÃÊÐËÁ×°Öà £¬£¬£¬Ö÷ÒªÓÃÓÚÏÔʾÇÖÈëÐÔµ¯³ö¹ã¸æºÍ֪ͨÀ¬»øÓʼþ¡£¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/new-unremovable-xhelper-malware-has-infected-45000-android-devices/