°Í»ù˹̹1.15ÒÚÒÆ¶¯Óû§Êý¾ÝÔÚ°µÍø³öÊÛ£»£»£»£»Ñо¿Ö°Ô±Ê¹ÓÃ3D´òÓ¡ÈÆ¹ýÆ»¹û¡¢Î¢Èí¼°ÈýÐǵÄÖ¸ÎÆÈÏÖ¤

Ðû²¼Ê±¼ä 2020-04-13

1.°Í»ù˹̹1.15ÒÚÒÆ¶¯Óû§Êý¾ÝÔÚ°µÍø³öÊÛ


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


°Í»ù˹̹Çå¾²³§ÉÌRewterz·¢Ã÷£¬£¬£¬ £¬£¬£¬ÏÖÔÚÓÐ1.15ÒÚ°Í»ùË¹Ì¹ÒÆ¶¯Óû§µÄÊý¾ÝÔÚ°µÍøÂÛ̳³öÊÛ£¬£¬£¬ £¬£¬£¬¼ÛǮΪ300 BTC£¨Ô¼ºÏ210ÍòÃÀÔª£©¡£¡£¡£¡£¡£¡£¡£ÕâЩÊý¾Ý°üÀ¨Óû§µÄÏêϸСÎÒ˽¼ÒÐÅÏ¢£¬£¬£¬ £¬£¬£¬ÀýÈçÐÕÃû¡¢ÍêÕûµØµã¡¢ÊÖ»úºÅÂëÒÔ¼°NICºÅºÍ˰ÎñºÅÂë¡£¡£¡£¡£¡£¡£¡£RewterzÍþвÇ鱨ר¼ÒÒÔΪÕâЩÊý¾Ý¿ÉÄÜÊÇÒ»´Î»ò¶à´Îй¶µÄЧ¹û£¬£¬£¬ £¬£¬£¬ÏÖÔÚ»¹²»ÇåÎúÊÇ·ñÓÐÈκÎÌØ¶¨µÄµçÐÅÔËÓªÉÌ»òÊÇËùÓеçÐÅÔËÓªÉ̳ÉΪ´Ë´Î¹¥»÷µÄÊܺ¦Õß¡£¡£¡£¡£¡£¡£¡£¸Ãй¶Êý¾ÝµÄ¹æÄ£Òý·¢Á˶ԵçÐŹ«Ë¾Êý¾ÝÇå¾²ÐÔºÍÒþ˽ÐԵĵ£ÐÄ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

http://www.rewterz.com/articles/115-million-pakistani-mobile-users-data-go-on-sale-on-dark-web


2.ÓÎÏ·ÊÖ±ú³§ÉÌSCUF Gamingй¶110ÍòÌõ¿Í»§¼Í¼


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ÓÎÏ·ÊÖ±ú³§ÉÌSCUF GamingµÄÒ»¸ö¿Í»§Êý¾Ý¿âÔÚÍøÉÏ̻¶£¬£¬£¬ £¬£¬£¬¸ÃÊý¾Ý¿â°üÀ¨Áè¼Ý110ÍòÌõ¿Í»§¼Í¼£¬£¬£¬ £¬£¬£¬º­¸Ç¿Í»§µÄÐÕÃû¡¢ÁªÏµ·½·¨¡¢Ö§¸¶ÐÅÏ¢¡¢¶©µ¥ÀúÊ·¼Í¼ºÍάÐÞÆ±¾ÝµÈÊý¾Ý¡£¡£¡£¡£¡£¡£¡£ComparitechÇå¾²Ñо¿ÍŶÓÔÚÍøÉÏ·¢Ã÷Á˸ÃÊý¾Ý¿â£¬£¬£¬ £¬£¬£¬Êý¾Ý¿âÖеĴó´ó¶¼¼ÍÂ¼ËÆºõÊÇÓÉSCUF GamingÔÚ2017ÄêÖÁ2020Äêʱ´úÍøÂçµÄ£¬£¬£¬ £¬£¬£¬¸ÃÊý¾Ý¿âÔÚÍøÉÏ̻¶µÄʱ¼ä²»µ½48Сʱ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.comparitech.com/blog/information-security/scuf-gaming-data-leak/


3.Òâ´óÀûMonte dei PaschiÒøÐÐÔ±¹¤ÓÊÏäÔâºÚ¿ÍÈëÇÖ


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Òâ´óÀû¹úÓÐÒøÐÐMonte dei PaschiÔâµ½ÍøÂç¹¥»÷£¬£¬£¬ £¬£¬£¬ºÚ¿ÍÈëÇÖÁ˲¿·ÖÔ±¹¤µÄÓÊÏä²¢Ïò¿Í»§·¢ËÍÁË´øÓÐÓïÒô¸½¼þµÄµç×ÓÓʼþ¡£¡£¡£¡£¡£¡£¡£¾Ý·͸É籨µÀ£¬£¬£¬ £¬£¬£¬¸Ã¹¥»÷±¬·¢ÔÚ3ÔÂ30ÈÕ£¬£¬£¬ £¬£¬£¬¸ÃÒøÐÐûÓÐ͸¶ÊÇ·ñÓÐÊý¾ÝÔ⵽й¶£¬£¬£¬ £¬£¬£¬Ò²Ã»ÓÐÌá¼°ÊÇ·ñÓÐÈκοͻ§ÒòÕâЩÓʼþÔâÊÜËðʧ¡£¡£¡£¡£¡£¡£¡£¸ÃÒøÐÐҲûÓÐÌá¹©ÍøÂç¹¥»÷µÄÏêϸϸ½Ú£¬£¬£¬ £¬£¬£¬ÏÖÔÚÉв»ÇåÎú¹¥»÷ÕßÊÇ·ñ»á¼ûÁ˹«Ë¾Êý¾Ý¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ½üÆÚCOVID-19µÄ±¬·¢£¬£¬£¬ £¬£¬£¬Ðí¶àÒøÐС¢Õþ¸®»ú¹¹ÉõÖÁÒ½ÁÆÐ§ÀÍ»ú¹¹¶¼³ÉÎªÍøÂç¹¥»÷ÕßµÄÄ¿µÄ£¬£¬£¬ £¬£¬£¬½¨Òé¿Í»§¶ÔÒÔCOVID-19ΪÖ÷ÌâµÄµç×ÓÓʼþ¼á³ÖСÐÄ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/101427/cyber-crime/monte-dei-paschi-hack.html


4.Ñо¿Ö°Ô±Ê¹ÓÃ3D´òÓ¡ÈÆ¹ýÆ»¹û¡¢Î¢Èí¼°ÈýÐǵÄÖ¸ÎÆÈÏÖ¤


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Ñо¿Ö°Ô±·¢Ã÷£¬£¬£¬ £¬£¬£¬¿ÉÒÔʹÓÃ×ÔÖÆµÄ3D´òÓ¡»úÈÆ¹ýÆ»¹û¡¢Î¢ÈíºÍÈýÐÇ×°±¸µÄÖ¸ÎÆÈÏÖ¤¡£¡£¡£¡£¡£¡£¡£ËûÃǼƻ®µÄÔ¤ËãΪ2000ÃÀÔª£¬£¬£¬ £¬£¬£¬ÔÚ13̨ÖÇÄÜÊÖ»ú¡¢Ìõ¼Ç±¾µçÄÔ¡¢Æ½°åµçÄÔµÈ×°±¸ÉÏ£¨°üÀ¨iPhone 8¡¢ÈýÐÇS10¡¢Macbook Pro 2018¡¢åÚÏëYogaºÍAICase Padlock£©¾ÙÐÐÁ˲âÊÔ£¬£¬£¬ £¬£¬£¬Æ½¾ùÀÖ³ÉÂÊԼΪ80%£¬£¬£¬ £¬£¬£¬Ö»¹Ü¹¥»÷²¢½ûÖ¹Òס£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±¶Ô¶àÖÖÄ£¾ßÖÊÁϾÙÐÐÁ˲âÊÔ£¬£¬£¬ £¬£¬£¬°üÀ¨¹èÒÔ¼°»ìÏýÓе¼µç·ÛÄ©µÄÖÖÖÖ½ºË®£¬£¬£¬ £¬£¬£¬ËûÃǵÄʵÑéÖÐ×îÓÐÓõÄÖÊÁÏÊǵͱ¾Ç®µÄÖ¯Îコ¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±µÄ½áÂÛÊÇ£¬£¬£¬ £¬£¬£¬Ö¸ÎÆÈÏÖ¤×ãÒÔ±£»£»£»£»¤´ó´ó¶¼ÈË£¬£¬£¬ £¬£¬£¬¿ÉÊÇÈôÊÇ×ʽðÐÛºñ»òÆð¾¢ÐԸߵĹ¥»÷Õß¾öÒé½ÓÄÉÕâÖÖ¹¥»÷·½·¨£¬£¬£¬ £¬£¬£¬Ôò¸ß¼ÛֵĿµÄ¿ÉÄÜÅöÃæÁÙΣº¦¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.darkreading.com/endpoint/researchers-fool-biometric-scanners-with-3d-printed-fingerprints/d/d-id/1337522


5.ºÉÀ¼¾¯·½Ò»ÖÜÄÚÈ¡µÞ15¸öDDoS³ö×âЧÀÍ


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ºÉÀ¼¾¯·½ÌåÏÖËûÃÇÔÚÒ»ÖÜÄÚÀÖ³ÉÈ¡µÞÁË15¸öDDoS³ö×âЧÀÍ£¬£¬£¬ £¬£¬£¬ÕâЩЧÀÍÔÊÐíÓû§×¢²á²¢ÌᳫÕë¶ÔÆäËüÍøÕ¾»òÍøÂç»ù´¡ÉèÊ©µÄDDoS¹¥»÷¡£¡£¡£¡£¡£¡£¡£ºÉÀ¼Õþ¸®ÌåÏÖÐж¯±¬·¢ÔÚÉÏÖÜ£¬£¬£¬ £¬£¬£¬ËûÃÇ»ñµÃÁËÍøÂçÍйܹ«Ë¾¡¢ÓòÃû×¢²áÉÌ¡¢Å·ÖÞÐ̾¯×éÖ¯¡¢¹ú¼ÊÐ̾¯×éÖ¯ºÍFBIµÄÖ§³Ö¡£¡£¡£¡£¡£¡£¡£Õþ¸®Ã»ÓÐÐû²¼15¸öDDoS³ö×âЧÀ͵ÄÃû³Æ¡£¡£¡£¡£¡£¡£¡£ÕâÊÇÒÑÍùÁù¸öÔÂÖкÉÀ¼¾¯·½µÚ¶þ´Î¶ÔDDoS³ö×âЧÀ;ÙÐÐÈ¡µÞ¡£¡£¡£¡£¡£¡£¡£ÔÚ2019Äê10Ô·Ý£¬£¬£¬ £¬£¬£¬ºÉÀ¼¾¯·½¹Ø±ÕÁËÒ»¼ÒÍøÂçÍйܹ«Ë¾£¬£¬£¬ £¬£¬£¬¸Ã¹«Ë¾ÎªÊýÊ®¸öDDoS½©Ê¬ÍøÂçÌṩÍйÜЧÀͺͺó¶Ë»ù´¡¼Ü¹¹¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/dutch-police-take-down-15-ddos-services-in-a-week/


6.Ñо¿Ö°Ô±·¢Ã÷Õë¶ÔWooCommerce²å¼þµÄÐÂÆ²ÔüÆ÷¹¥»÷


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


SucuriµÄÇ徲ר¼Ò·¢Ã÷Ò»¸öÕë¶ÔʹÓÃWooCommerce²å¼þµÄWordPressµç×ÓÉÌÎñÍøÕ¾µÄÐÂÆ²ÔüÆ÷¹¥»÷£¬£¬£¬ £¬£¬£¬¸Ã¶ñÒâ¾ç±¾ÓëMagecart¹¥»÷ÖÐʹÓõÄÀàËÆ¾ç±¾²î±ð¡£¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâ¾ç±¾±»×¢Èëµ½¡°./wp-includes/rest-api/class-wp-rest-api.php¡±ÎļþÖУ¬£¬£¬ £¬£¬£¬²¢ÇÒ½ÓÄÉÁ˶à²ã±àÂëºÍ´®ÁªÒÔÒþ²ØÆä½¹µã´úÂë¡£¡£¡£¡£¡£¡£¡£¶ñÒâ¾ç±¾»áÍøÂçÓû§µÄÖ§¸¶ÐÅÏ¢£¬£¬£¬ £¬£¬£¬²¢½«¿¨ºÅºÍCVVÂëÒÔCookieµÄ´¿Îı¾ÃûÌÃÉúÑÄ£¬£¬£¬ £¬£¬£¬È»ºóʹÓÃÕýµ±µÄfile_put_contentsº¯Êý½«ËüÃÇ´æ´¢µ½wp-content/uploadsĿ¼ÏµÄÁ½¸öͼƬÎļþ£¨.PNGÎļþºÍJPEG£©ÖС£¡£¡£¡£¡£¡£¡£ÔÚÑо¿Ö°Ô±ÆÊÎöʱ£¬£¬£¬ £¬£¬£¬Á½¸öÎļþ¶¼²»°üÀ¨Èκα»µÁµÄÊý¾Ý£¬£¬£¬ £¬£¬£¬ÕâÅú×¢¶ñÒâ´úÂë¿ÉÒÔÔÚ¹¥»÷Õß»ñÊØÐÅÏ¢ºó×Ô¶¯É¨³ýÎļþ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/101445/hacking/woocommerce-plugin-e-skimmer.html