Facebook 5.4ÒÚÓû§¼ÍÂ¼ÆØ¹â£»£»£»£»£»£»JS-SnifferѬȾ2440¸öÍøÕ¾£»£»£»£»£»£»2018ÄêAndroidÇå¾²¼°Òþ˽±¨¸æ

Ðû²¼Ê±¼ä 2019-04-04
1.Facebook 5.4ÒÚÓû§¼Í¼ÔÚÑÇÂíÑ·ÔÆ´æ´¢ÖÐÆØ¹â


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


UpGuardÑо¿ÍŶӷ¢Ã÷Á½¸öµÚÈý·½Ó¦ÓõÄÑÇÂíÑ·S3´æ´¢¿â¿É¹ûÕæ»á¼û£¬ £¬£¬£¬ £¬£¬£¬ÆäÖд洢ÁËÁè¼Ý5.4ÒÚFacebookÓû§µÄ¼Í¼ ¡£¡£¡£¡£¡£ÕâЩÓû§Êý¾Ý°üÀ¨µÚÈý·½Ó¦ÓõÄÃ÷ÎÄÃÜÂë¡¢FacebookÕË»§Ãû³Æ¡¢Óû§ID¡¢Ì¸ÂÛ¡¢ÐËȤ¡¢¹ØÏµ×´Ì¬µÈ ¡£¡£¡£¡£¡£Ò»¸öÊý¾Ý¿âÊôÓÚÄ«Î÷¸çýÌ幫˾Cultura Colectiva£¬ £¬£¬£¬ £¬£¬£¬¸ÃÊý¾Ý¿âÃûΪcc-datalake£¬ £¬£¬£¬ £¬£¬£¬¾ÞϸΪ146GB£¬ £¬£¬£¬ £¬£¬£¬°üÀ¨Ô¼5.4ÒÚÓû§¼Í¼ ¡£¡£¡£¡£¡£ÁíÒ»¸öÊý¾Ý¿âÊôÓÚµÚÈý·½Ó¦ÓÃAt the Pool£¬ £¬£¬£¬ £¬£¬£¬Ö»°üÀ¨2.2ÍòÓû§¼Í¼ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/540-mllion-facebook-records-leaked-by-public-amazon-s3-buckets/

2.×ôÖÎÑÇÀí¹¤Ñ§ÔºÔâºÚ¿Í¹¥»÷£¬ £¬£¬£¬ £¬£¬£¬130ÍòѧÉú¼°Ô±¹¤ÐÅϢй¶


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ÃÀ¹ú×ôÖÎÑÇÀí¹¤Ñ§ÔºÈ·ÈÏÓÚ2018Äê12ÔÂ14ÈÕÔâºÚ¿ÍÈëÇÖ£¬ £¬£¬£¬ £¬£¬£¬¶à´ï130ÍòѧÉú¡¢ÉêÇëÈ˺ÍÔ±¹¤µÄСÎÒ˽¼ÒÐÅϢй¶ ¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢µØµã¡¢Éç»áÇå¾²ºÅÂëºÍ³öÉúÈÕÆÚ ¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÒ»¸öWebÓ¦ÓÃÖеÄÎó²î£¬ £¬£¬£¬ £¬£¬£¬»ñµÃ¶ÔЧÀÍÆ÷µÄδÊÚȨ»á¼û ¡£¡£¡£¡£¡£ËäÈ»ÏÖÔÚ¸ÃÎó²îÒѱ»ÐÞ¸´£¬ £¬£¬£¬ £¬£¬£¬µ«¹¥»÷Õß¿ÉÄÜÒѾ­×°ÖÃÁ˶ñÒâÈí¼þµÈ ¡£¡£¡£¡£¡£ÕâÊÇ×ôÖÎÑÇÀí¹¤Ñ§ÔºÒ»ÄêÄÚ±¬·¢µÄµÚ¶þÆðÊý¾Ýй¶ÊÂÎñ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/georgia-tech-data-breach-exposes-info-for-13-million-people/

3.JS-SnifferѬȾȫÇò2440¸öÍøÕ¾£¬ £¬£¬£¬ £¬£¬£¬Ö÷ÒªÇÔÊØÐÅÓÿ¨ÐÅÏ¢


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ƾ֤Çå¾²³§ÉÌGroup-IBµÄÒ»·Ýб¨¸æ£¬ £¬£¬£¬ £¬£¬£¬½ü38¸ö²î±ðµÄJS-SnifferѬȾÁËÈ«Çò2440¸öµç×ÓÉÌÎñÍøÕ¾ ¡£¡£¡£¡£¡£JS-SnifferÊÇÒ»ÖÖJavaScript¶ñÒâ¾ç±¾£¬ £¬£¬£¬ £¬£¬£¬Ö¼ÔÚ×èµ²²¢ÇÔÈ¡Óû§ÊäÈëµÄÒøÐп¨ºÅ¡¢ÐÕÃû¡¢µØµã¡¢µÇ¼ÐÅÏ¢ºÍÃÜÂëµÈ ¡£¡£¡£¡£¡£Æ¾Ö¤Ô¤¼Æ£¬ £¬£¬£¬ £¬£¬£¬ÕâЩJS-sniffer¿ª·¢ÕßµÄÊÕÒæ¿É´ïÿÔÂÊýÊ®ÍòÃÀÔª ¡£¡£¡£¡£¡£ÔÚÕâЩJS-Sniffer¼Ò×åÖУ¬ £¬£¬£¬ £¬£¬£¬ÖÁÉÙÓÐ8¸ö֮ǰ´Óδ±»ÊÓ²ì¹ý ¡£¡£¡£¡£¡£ÔÚÊÜѬȾµÄÍøÕ¾ÖУ¬ £¬£¬£¬ £¬£¬£¬Áè¼ÝÒ»°ëµÄ¹¥»÷ÊÇÓÉJS-sniffer¼Ò×åMagentoNameÌᳫµÄ£¬ £¬£¬£¬ £¬£¬£¬¶øÁè¼Ý13%µÄ¹¥»÷ÊÇÓÉWebRank¼Ò×åÌᳫµÄ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/04/js-sniffers-credit-card-hacking.html

4.OceanLotus APTʹÓÃÒþдÊõ¼ÓÔØºóÃÅDenes¼°Remy


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ƾ֤CylanceÑо¿ÍŶÓÐû²¼µÄ±¨¸æ£¬ £¬£¬£¬ £¬£¬£¬APT×éÖ¯OceanLotus£¨ÓÖ³ÆAPT32£©ÕýÔÚʹÓûùÓÚÒþдÊõµÄ¼ÓÔØÆ÷À´ÊÍ·ÅDenesºóÃźÍRemyºóÃŵÄбäÌå ¡£¡£¡£¡£¡£ÕâÖÖÒþдËã·¨ËÆºõÊÇרÃÅ¿ª·¢µÄ£¬ £¬£¬£¬ £¬£¬£¬Ö¼ÔÚʹÓÃPNGͼƬÒþ²Ø¼ÓÃܵĶñÒâÈí¼þpayload ¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÆÊÎöµÄ¼ÓÔØÆ÷Ñù±¾Ê¹ÓÃÁËDLLºÍCrypto++¿âµÄAES128Ë㷨ʵÏÖ£¬ £¬£¬£¬ £¬£¬£¬ËäÈ»ÕâЩÑù±¾±»ÓÃÓÚÔÚÄ¿µÄϵͳÉÏÊͷźóÃÅ£¬ £¬£¬£¬ £¬£¬£¬µ«¹¥»÷ÕßÒ²¿ÉÒÔÈÝÒ׵ؾÙÐÐÐÞ¸ÄÒÔÊÍ·ÅÆäËü¶ñÒâpayload ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/oceanlotus-apt-uses-steganography-to-load-backdoors/

5.¹È¸èÐû²¼2018ÄêAndroidÇå¾²¼°Òþ˽±¨¸æ£¬ £¬£¬£¬ £¬£¬£¬Ô¤×°ÖöñÒâÓ¦ÓÃÊýÄ¿ÉÏÉý


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


¹È¸èÐû²¼2018ÄêAndroidÇå¾²¼°Òþ˽±¨¸æ£¬ £¬£¬£¬ £¬£¬£¬³ÆÍ¨¹ýԤװÖûòÎÞÏ߸üзַ¢µÄPHA£¨Ç±ÔÚÓк¦Ó¦Óã©ÊýÄ¿ÉÏÉý ¡£¡£¡£¡£¡£¹È¸è³ÆÕâÖÖÊÖÒÕÓÈΪÁîÈ˵£ÐÄ£¬ £¬£¬£¬ £¬£¬£¬ÓÉÓÚÓû§ÎÞ·¨¿ØÖÆÔ¤×°ÖÃÔÚÊÖ»úÉϼ°Í¨¹ýϵͳ¸üÐÂÏÂÔØµÄÄÚÈÝ ¡£¡£¡£¡£¡£µ«¸Ã±¨¸æ»¹Ö¸³ö£¬ £¬£¬£¬ £¬£¬£¬2018ÄêÔËÐÐGoogle Play ProtectµÄAndroidÉè±¹ØÁ¬ÄPHAʵÀý×ÜÌå±ÈÉÏÒ»ÄêϽµÁË20% ¡£¡£¡£¡£¡£Õâ°üÀ¨Í¨¹ýµÚÈý·½Ó¦ÓÃÊÐËÁ¡¢Google Play¼°ÆäËü¶ñÒâ¹¥»÷ÖÐ×°ÖõÄPHA ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/google-warns-of-growing-android-attack-vector-backdoored-sdks-and-pre-installed-apps/143332/

6.Arizona BeveragesÔâÀÕË÷Èí¼þiEncrypt¹¥»÷£¬ £¬£¬£¬ £¬£¬£¬½ü200̨ЧÀÍÆ÷±»Ñ¬È¾

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾

ÒûÁÏÉÌArizona BeveragesÔâÀÕË÷Èí¼þ¹¥»÷£¬ £¬£¬£¬ £¬£¬£¬µ¼ÖÂÆäÏúÊÛÓªÒµ±»ÆÈ×èÖ¹½üÁ½ÖÜ ¡£¡£¡£¡£¡£ÊÂÎñµÄÔµ¹ÊÔ­ÓÉÊǸù«Ë¾µÄºó¶ËЧÀÍÆ÷ÔËÐÐÁ˹ýʱµÄWindowsϵͳ£¬ £¬£¬£¬ £¬£¬£¬µ¼Ö½ü200̨ÅþÁ¬µ½ÍøÂçµÄЧÀÍÆ÷ѬȾÀÕË÷Èí¼þiEncrypt ¡£¡£¡£¡£¡£ÔÚ˼¿ÆµÄ×ÊÖúÏ£¬ £¬£¬£¬ £¬£¬£¬¸Ã¹«Ë¾ÒÑ´ÓÀÕË÷Èí¼þ¹¥»÷Öлָ´£¬ £¬£¬£¬ £¬£¬£¬²¢ÒÑÔÚеÄÓ²¼þ¡¢Èí¼þºÍ»Ö¸´±¾Ç®ÉÏÆÆ·ÑÊýÊ®ÍòÃÀÔª ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/arizona-beverages-hit-by-a-massive-ransomware-attack-9bcd2630