SignalµÈ̸ÌìÓ¦ÓÃÖб£´æ¿É¼àÊÓÓû§µÄÂß¼Îó²î£»£»£»£»£»£»£»Ñо¿ÍŶӷ¢Ã÷FreakOutʹÓöà¸öÐÂÎó²îµÄ¹¥»÷»î¶¯
Ðû²¼Ê±¼ä 2021-01-21
Çå¾²¹«Ë¾Malwarebytes³ÆSolarWinds±³ºóµÄºÚ¿ÍÒÑÈëÇÖÆäÓʼþϵͳ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ö¸³ö£¬£¬£¬£¬£¬£¬ËäÈ»ÆäûÓÐʹÓÃSolarWinds£¬£¬£¬£¬£¬£¬µ«ÓëÆäËû¹«Ë¾Ò»ÑùÔâµ½ÁËSolarWinds¹©Ó¦Á´¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷±¬·¢ÔÚÈ¥Ä꣬£¬£¬£¬£¬£¬ºÚ¿ÍʹÓÃAzure Active DirectoryÖеÄÎó²îºÍ¶ñÒâOffice 365Ó¦ÓóÌÐò£¬£¬£¬£¬£¬£¬¶Ô¹«Ë¾²¿·ÖϵͳÌᳫÁ˹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£¾ÓÉÊӲ죬£¬£¬£¬£¬£¬¸Ã¹«Ë¾È·¶¨¹¥»÷Õß½ö»ñµÃÁ˲¿·ÖÄÚ²¿ÓʼþµÄ»á¼ûȨ£¬£¬£¬£¬£¬£¬ÆäÄÚ²¿Éú²úÇéÐβ¢Î´Êܵ½Ó°Ï죬£¬£¬£¬£¬£¬ÏÖÔÚÈÔ¿ÉÇ徲ʹÓÃMalwarebytesÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/113628/hacking/malwarebytes-solarwinds-attack.html
2.SignalµÈ̸ÌìÓ¦ÓÃÖб£´æ¿É¼àÊÓÓû§µÄÂß¼Îó²î

Google Project ZeroÅû¶ÁËSignalµÈ̸ÌìÓ¦ÓÃÖб£´æ¿É¼àÊÓÓû§µÄÂß¼Îó²î¡£¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚSignal¡¢Google Duo¡¢Facebook Messenger¡¢JioChatºÍMochaÖз¢Ã÷¸ÃÎó²î£¬£¬£¬£¬£¬£¬¿É±»ÓÃÀ´¼àÌýÆËÃæÓû§µÄÖÜΧÇéÐΡ£¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îΪFaceTimeŲÓÃ״̬»úÖеÄÂß¼¹ýʧ£¬£¬£¬£¬£¬£¬¿ÉÒÔÇ¿ÖÆÄ¿µÄ×°±¸´«ÊäÒôƵ»òÊÓÆµÊý¾Ý¶øÎÞÐè½»»¥¡£¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ºóÆÊÎöÁË7¿îÓ¦Ó㬣¬£¬£¬£¬£¬·¢Ã÷ÆäÖÐ5¿î¾ùÓиÃÎÊÌâ¡£¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬¸ÃÎó²îÒѱ»ÐÞ¸´¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/bugs-in-signal-facebook-google-chat-apps-let-attackers-spy-on-users/
3.ALTDOS³ÆÆäÒÑÇÔÈ¡Êý°ÙGB BEXIMCOµÄÔ´ÂëµÈÎļþ

ALTDOS³ÆÆäÒÑÇÔÈ¡Êý°ÙGBÃϼÓÀ¹úÊÕÖ§¿Ú¹«Ë¾BEXIMCOµÄÔ´ÂëµÈÎļþ¡£¡£¡£¡£¡£¡£¡£¡£ALTDOSºÚ¿ÍÌåÏÖËûÃÇÔÚ12Ô¹¥»÷Á˸ù«Ë¾£¬£¬£¬£¬£¬£¬×ܹ²´ÓÆä34¸öÍøÕ¾ÖÐÇÔÈ¡ÁËÊý°ÙGBµÄÎļþ¡¢Ô´´úÂëºÍÊý¾Ý¿â¡£¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬ALTDOS»¹ÌṩÁ˲¿·ÖÊý¾ÝµÄ½ØÍ¼£¬£¬£¬£¬£¬£¬°üÀ¨´Ó2018Äê9ÔÂ24ÈÕµ½2019Äê5ÔÂ17ÈÕµÄÔ±¹¤³öÇÚÐÅÏ¢ºÍ°üÀ¨¸¶¿î¼Í¼µÄpayment_infoµÈ13.6 GBµÄ42¸öѹËõÎļþ£¬£¬£¬£¬£¬£¬²¢³ÆÆäÕýÔÚ¼ì²éËùÓÐÊý¾Ý¿âÒÔÆÀ¹ÀÊý¾Ý¼ÛÖµ¡£¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬BEXIMCO¹«Ë¾²¢Î´¶Ô´ËʾÙÐлØÓ¦¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.databreaches.net/hackers-claim-to-have-attacked-major-bangladeshi-conglomerate/
4.ShinyHuntersÔÚ°µÍø¹ûÕæ190Íò¸öPixlrÓû§µÄÊý¾Ý

ShinyHuntersÔÚ°µÍø¹ûÕæÁË190Íò¸öÔÚÏßͼƬ±à¼Ó¦ÓÃPixlrµÄÓû§µÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÊÂÎñй¶ÁË1921141¸öÓû§¼Í¼£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨µç×ÓÓʼþµØµã¡¢µÇ¼Ãû¡¢SHA-512¹þÏ£ÃÜÂë¡¢¹ú¼Ò¡¢ÊÇ·ñ×¢²áÁËÐÂÎÅͨѶÒÔ¼°ÆäËûÄÚ²¿ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£ShinyHuntersÌåÏÖ£¬£¬£¬£¬£¬£¬ËûÓÚ2020Äêµ×´Ó¸Ã¹«Ë¾µÄAWS´æ´¢Í°ÏÂÔØÁ˸ÃÊý¾Ý¿â¡£¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬PixlrÉÐδ¶Ô´ËÊÂ×÷³ö»ØÓ¦£¬£¬£¬£¬£¬£¬µ«BleepingComputerÒÑÈ·ÈÏÊý¾Ý¿âÖеÄÓʼþµØµã¾ùÊôÓÚPixlrµÄ×¢²á»áÔ±¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hacker-posts-19-million-pixlr-user-records-for-free-on-forum/
5.ÔÚÏßÉ̳ÇAnyvanÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬Óû§Êý¾Ýй¶

Å·ÖÞÔÚÏßÉ̳ÇAnyvan³ÆÆäÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬Óû§Êý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£¡£AnyvanÌåÏÖÊý¾Ýй¶±¬·¢ÔÚ9ÔÂ⣬£¬£¬£¬£¬£¬ÓÚ12ÔÂ31ÈÕ±»·¢Ã÷¡£¡£¡£¡£¡£¡£¡£¡£Ö®ºó¸Ã¹«Ë¾¶Ô´ËʾÙÐÐÁËÊӲ죬£¬£¬£¬£¬£¬·¢Ã÷¿Í»§µÄÐÕÃû¡¢µç×ÓÓʼþºÍÃÜÂëµÄ¹þÏ£ÒÑй¶¡£¡£¡£¡£¡£¡£¡£¡£×÷ΪÏìÓ¦¸Ã¹«Ë¾Ç¿ÖƸü¸ÄÁËËùÓÐÓû§µÄÃÜÂ룬£¬£¬£¬£¬£¬²¢½¨ÒéÓû§°´ÆÚ¸ü¸ÄÃÜÂë¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.theregister.com/2021/01/19/anyvan_confirms_digital_breakin_says/
6.Ñо¿ÍŶӷ¢Ã÷FreakOutʹÓöà¸öÐÂÎó²îµÄ¹¥»÷»î¶¯

Ñо¿ÍŶӷ¢Ã÷½©Ê¬ÍøÂçFreakOutʹÓöà¸öÐÂÎó²îµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷Ö÷ÒªÕë¶ÔTerraMaster²Ù×÷ϵͳ¡¢Zend FrameworkºÍLiferay Portal£¬£¬£¬£¬£¬£¬Ê¹ÓÃÁËCVE-2020-28188¡¢ CVE-2021-3007ºÍCVE-2020-7961Îó²î¡£¡£¡£¡£¡£¡£¡£¡£FreakOut¾ßÓÐЧÀͶ˿ÚɨÃè¡¢ÍøÂçÐÅÏ¢¡¢ÍøÂçÐá̽»ò·¢¶¯ÂþÑÜʽ¾Ü¾øÐ§ÀÍ(DDoS)¹¥»÷µÈ¹¦Ð§£¬£¬£¬£¬£¬£¬¿ÉѬȾLinux×°±¸£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃÆäÍÚ¼ÓÃÜÇ®±Ò¡¢ÔÚ¹«Ë¾ÍøÂçÉϺáÏòÈö²¥»òαװ³ÉÊÜÓ°ÏìµÄ¹«Ë¾¹¥»÷ÆäËûÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://research.checkpoint.com/2021/freakout-leveraging-newest-vulnerabilities-for-creating-a-botnet/


¾©¹«Íø°²±¸11010802024551ºÅ