Akamai·¢Ã÷н©Ê¬ÍøÂçʹÓñÈÌØ±ÒÉúÒâÒþ²ØC2µØµã£»£»£»£»£»£»Ó¡¶ÈÕþ¸®ÍøÕ¾Ð¹Â¶Áè¼Ý800ÍòÌõCOVID-19¼ì²âЧ¹û

Ðû²¼Ê±¼ä 2021-02-26

1.Akamai·¢Ã÷н©Ê¬ÍøÂçʹÓñÈÌØ±ÒÉúÒâÒþ²ØC2µØµã


1.jpg


Akamai·¢Ã÷н©Ê¬ÍøÂçÕýÔÚʹÓñÈÌØ±ÒÇø¿éÁ´ÉúÒâÀ´Òþ²ØC2µØµã¡£¡£¡£¹¥»÷ʹÓÃÓ°ÏìÁËHadoop YarnºÍElasticsearchµÈÈí¼þÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©Îó²î£¬£¬£¬ £¬£¬£¬ÀýÈçCVE-2015-1427ºÍCVE-2019-9082¡£¡£¡£ÎªÁ˽«Ç®°üÊý¾Ýת»»ÎªIPµØµã£¬£¬£¬ £¬£¬£¬ºÚ¿ÍʹÓÃËĸöµ¥ÐеÄbash¾ç±¾Ïò±ÈÌØ±ÒÇ®°üµÄÇø¿éÁ´×ÊÔ´ÖÎÀíÆ÷API·¢ËÍHTTPÇëÇ󣬣¬£¬ £¬£¬£¬½«×î½üÁ½¸öÉúÒâÖеÄSatoshiֵת»»Îª±¸ÓÃC2µØµã¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/this-botnet-is-abusing-bitcoin-blockchains-to-stay-in-the-shadows/ 


2.Malwarebytes·¢Ã÷ÐÂAPT LazyScripterÃé×¼½»Í¨ÐÐÒµ


2.jpg


Çå¾²¹«Ë¾Malwarebytes·¢Ã÷еÄAPT×éÖ¯LazyScripterÃé×¼½»Í¨ÐÐÒµ¡£¡£¡£LazyScripter×Ô2018ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬£¬£¬ £¬£¬£¬Ê¹ÓÃÍøÂç´¹ÂÚ¹¥»÷Õë¶Ô¼ÓÄôóÒÆÃñ¡¢ÇóÖ°º½¿Õ¹«Ë¾ºÍ¹ú¼Êº½¿ÕÔËÊäЭ»á£¨IATA£©¡£¡£¡£LazyScripterÔÚÆä×îÐµĹ¥»÷»î¶¯Ê¹ÓÃÁËÃâ·ÑµÄ¶ñÒâÈí¼þOctopusºÍKoadic£¬£¬£¬ £¬£¬£¬Æä»¹ÔøÊ¹ÓùýLuminosityLink¡¢RMS¡¢Quasar¡¢njRatºÍRemcosµÈRAT¡£¡£¡£±ðµÄ£¬£¬£¬ £¬£¬£¬¸ÃÍŻﻹ½«Æä¹¤¾ß¼¯ÍйÜÔÚGitHubÉÏ£¬£¬£¬ £¬£¬£¬ÕâÊÇÒ»¸öÒÁÀÊAPT×éÖ¯ÒÑÍùʹÓõÄÒ»ÖÖÕ½ÂÔ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/new-lazyscripter-hacking-group-targets-airlines


3.Ó¡¶ÈÕþ¸®ÍøÕ¾Ð¹Â¶Áè¼Ý800ÍòÌõCOVID-19¼ì²âЧ¹û


3.jpg


Çå¾²Ñо¿Ô± Sourajeet Majumder·¢Ã÷Ó¡¶ÈÕþ¸®ÍøÕ¾Ð¹Â¶ÁËÁè¼Ý800ÍòÌõCOVID-19¼ì²âЧ¹û¡£¡£¡£¾ÝϤÕâЩÊý¾ÝÀ´×ÔÓ¡¶ÈÎ÷ÃϼÓÀ­°îÎÀÉú¸£Àû²¿£¬£¬£¬ £¬£¬£¬°üÀ¨ÁËÓйع«ÃñµÄÃô¸ÐÐÅÏ¢£¬£¬£¬ £¬£¬£¬ÀýÈçÐÕÃû¡¢ÄêËê¡¢ÑùÆ·¼ì²âµÄÈÕÆÚºÍʱ¼ä¡¢ÆÜÉíµØµãµÈ¡£¡£¡£Ð¹Â¶Ôµ¹ÊÔ­ÓÉÊÇ·¢Ë͸ø¼ì²âÕߵĶÌÐŵÄURLÖаüÀ¨Ò»¸öbase64±àÂëµÄ±¨¸æIDºÅ£¨¡°SRF ID¡±£©£¬£¬£¬ £¬£¬£¬¿ÉÒÔ½«¸Ã±¨¸æºÅ½âÂ룬£¬£¬ £¬£¬£¬²¢Í¨¹ýµÝÔöºÍµÝ¼õÒԽṹеÄURL¼¯£¬£¬£¬ £¬£¬£¬À´»á¼ûÆäËû»¼ÕßµÄCOVID-19¼ì²â±¨¸æ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/over-8-million-covid-19-test-results-leaked-online/    


4.ºÚ¿ÍÔÚ°µÍø³öÊÛ·¨¹ú½ü50Íò¹«ÃñµÄÒ½ÁƵµ°¸ÐÅÏ¢


4.jpg


Lib¨¦ration·¢Ã÷ºÚ¿ÍÔÚ°µÍø³öÊÛ·¨¹ú491840¸ö¹«ÃñµÄÒ½ÁƵµ°¸ÐÅÏ¢¡£¡£¡£Ð¹Â¶Êý¾Ý°üÀ¨ÐÕÃû¡¢µç»°ºÅÂë¡¢ÓÊÕþµØµã¡¢Éç»á°ü¹ÜºÅ¡¢³öÉúÈÕÆÚ¡¢ÑªÐÍ¡¢È«¿ÆÒ½Éú¡¢¿µ½¡°ü¹ÜÌṩÕß¡¢Ò½ÁÆÒªÁì¡¢°¬×̲¡¶¾×´Ì¬ºÍÈÑÉïÊÔÑéЧ¹ûµÈ¡£¡£¡£Lib¨¦ration³ÆÕâЩÊý¾ÝÀ´×Ô·¨¹úÎ÷±±µØÇøµÄ30¶à¸öҽѧʵÑéÊÒ£¬£¬£¬ £¬£¬£¬Îª2015ÄêÖÁ2020Äê10ÔÂÖ®¼äÊÕÂÞµÄÑù±¾¡£¡£¡£±ðµÄ£¬£¬£¬ £¬£¬£¬ÕâЩʵÑéÊÒËùÓÐʹÓÃÁËDedalus Healthcare Systems GroupÐû²¼µÄÒ½ÁÆÖÎÀíÈí¼þ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/500k-french-medical-records-leaked/


5.MozillaÐû²¼Çå¾²¸üУ¬£¬£¬ £¬£¬£¬ÐÞ¸´FirefoxÖеĶà¸öÎó²î


5.jpg


MozillaÐû²¼ÁËÇå¾²¸üУ¬£¬£¬ £¬£¬£¬ÐÞ¸´FirefoxÖеĶà¸öÎó²î¡£¡£¡£´Ë´ÎÐÞ¸´ÁËÄÚÈÝÇå¾²Õ½ÂÔ£¨CSP£©ÖеÄÁ½¸öÎó²î£¬£¬£¬ £¬£¬£¬°üÀ¨¿É±»Ô¶³Ì¹¥»÷ÕßʹÓÃÀ´ÇÔÈ¡Ãô¸ÐÊý¾ÝµÄCVE-2021-23969Îó²î£¬£¬£¬ £¬£¬£¬ÒÔ¼°¿É×ß©URIÖаüÀ¨µÄÃô¸ÐÐÅÏ¢µÄCVE-2021-23968Îó²î¡£¡£¡£±ðµÄ£¬£¬£¬ £¬£¬£¬»¹ÐÞ¸´Á˿ɵ¼Ö¶ÏÑÔÔÚ¶àÏß³Ìwasm´úÂëÖб»´¥·¢µÄCVE-2021-23970Îó²îºÍ¿É±»ÓÃÀ´ÈƹýHTML SanitizerµÄCVE-2021-23974Îó²îµÈ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/mozilla-firefox-bugs-cookie-tracking/164246/


6.ºÉÀ¼Ñо¿ÀíÊ»áѬȾDoppelPaymer£¬£¬£¬ £¬£¬£¬ÄÚ²¿Îļþй¶


6.jpg


ºÉÀ¼Ñо¿Î¯Ô±»á£¨NWO£©Ñ¬È¾ÁËDoppelPaymer£¬£¬£¬ £¬£¬£¬µ¼ÖÂЧÀÍÆ÷Í£ÓÃÒÔ¼°ÄÚ²¿Îļþй¶¡£¡£¡£NWOÊÇΪºÉÀ¼´óѧºÍÑо¿ËùµÄÑо¿Ö°Ô±Ìṩ×ʽðµÄÖ÷Òª»ú¹¹£¬£¬£¬ £¬£¬£¬Ã¿ÄêµÄͶ×ʶî¸ß´ï10ÒÚÅ·Ôª¡£¡£¡£¸Ã×éÖ¯ÓÚ2ÔÂ14ÈÕÐû²¼ÆäÔâµ½¹¥»÷£¬£¬£¬ £¬£¬£¬µ«Î´Ìṩϸ½Ú¡£¡£¡£DoppelPaymerÓÚ±¾ÖÜÈý¹ûÕæÁË´ÓNWOЧÀÍÆ÷ÇÔÈ¡µÄÓÐ¹ØÆäÔ±¹¤ÏêϸÐÅϢʮ¼¸¸öÎļþ£¬£¬£¬ £¬£¬£¬ÒÔ֤ʵ¹¥»÷µÄÀֳɡ£¡£¡£NWOÏÖÔÚÕýÔÚ»Ö¸´ÆäÍøÂ磬£¬£¬ £¬£¬£¬Ô¤¼Æ½«ÔÚ¼¸ÖÜÄÚ»Ö¸´Õý³£ÔËÓª¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/dutch-research-council-nwo-confirms-ransomware-attack-data-leak/