BlackBerryÐû²¼¹ØÓÚBAHAMUT×éÖ¯µÄÆÊÎö±¨¸æ£»£» £»£»Ñо¿Ô±·¢Ã÷¶ñÒânpm°üÇÔÈ¡²¢ÔÚGitHubÐû²¼Óû§Êý¾Ý

Ðû²¼Ê±¼ä 2020-10-12
1.BlackBerryÐû²¼¹ØÓÚBAHAMUT×éÖ¯µÄÆÊÎö±¨¸æ


1.jpg


BlackBerryÐû²¼Á˹ØÓÚBAHAMUTÍøÂçÌØ¹¤×éÖ¯µÄÆÊÎö±¨¸æ £¬£¬£¬£¬ £¬£¬·¢Ã÷Æä¶ÔÕþ¸®¹ÙÔ±ºÍÖ÷ÒªÐÐÒµÌᳫÁË´ó×ڸ߶ÈÖØ´óµÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£Ñо¿Åú×¢ £¬£¬£¬£¬ £¬£¬¸ÃÍÅ»ïµÄ»î¶¯¹æÄ£±ÈÒÔǰÒÔΪµÄÒªÆÕ±éµÃ¶à £¬£¬£¬£¬ £¬£¬°üÀ¨ÁËGoogle PlayÊÐËÁºÍApp StoreÖеÄÊ®¼¸¸ö¶ñÒâÓ¦ÓóÌÐò¡£¡£¡£¡£¡£¡£¡£±ðµÄ £¬£¬£¬£¬ £¬£¬BlackBerry»¹ÒÔΪ £¬£¬£¬£¬ £¬£¬BAHAMUT¿ÉÒÔÓëÖÁÉÙÒ»Ãû0day¿ª·¢Ö°Ô±½Ó´¥ £¬£¬£¬£¬ £¬£¬²¢Ê¹ÓÃ0day¹¥»÷¶à¸öÄ¿µÄ £¬£¬£¬£¬ £¬£¬ÕâÔ¶Ô¶Áè¼ÝÁË´ó´ó¶¼ÆäËûºÚ¿Í×éÖ¯µÄ¹¥»÷ˮƽ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/cyber-espionage-bahamut-staggering/


2.×ôÖÎÑÇÖÝDHSй¶ÍâµØ¶ùͯ¼°Æä¼Ò³¤µÄÃô¸ÐÐÅÏ¢


2.jpg


×ôÖÎÑÇÖÝÈËÃñЧÀͲ¿£¨DHS£©ÉÏÖÜÎåÌåÏÖ £¬£¬£¬£¬ £¬£¬ÒòºÚ¿Í¹¥»÷µ¼Ö¶ùͯ¼°Æä¼Ò³¤µÄÃô¸ÐÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£ÔÚ5ÔÂ3ÈÕÖÁ5ÔÂ15ÈÕÖ®¼ä £¬£¬£¬£¬ £¬£¬ºÚ¿Í»ñµÃÁ˶à¸öÔ±¹¤µç×ÓÓʼþÕÊ»§µÄ»á¼ûȨÏÞ £¬£¬£¬£¬ £¬£¬²¢ÇÒ±£´æÁ˺ܳ¤Ò»¶Îʱ¼ä¡£¡£¡£¡£¡£¡£¡£´Ë´Îй¶ÐÅÏ¢°üÀ¨¶ùͯ¼°¼ÒÍ¥³ÉÔ±µÄÈ«Ãû¡¢Óë¶ùͯµÄ¹ØÏµ¡¢ÆÜÉíµØµã¡¢DFCS°¸ÀýºÅ¡¢DFCSʶÓÖÃû¡¢³öÉúÈÕÆÚ¡¢ÄêËê¡¢ÁªÏµ´ÎÊý¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØµã¡¢Éç»á°ü¹ÜºÅ¡¢Ò½ÁƽòÌù±êʶºÅ¡¢Ò½ÁƽòÌùÒ½Áưü¹Ü±êʶºÅ¡¢Ò½ÁÆÌṩÕßÐÕÃûºÍÔ¤Ô¼ÈÕÆÚ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/children-and-parent-info-exposed-in-georgia-dhs-data-breach/


3.FriendemicÒòÊý¾Ý¿âÉèÖùýʧй¶½ü300Íò¿Í»§Êý¾Ý


3.jpg


2020Äê9ÔÂ12ÈÕ £¬£¬£¬£¬ £¬£¬ComparitechÑо¿Ö°Ô±·¢Ã÷ÓªÏú¹«Ë¾FriendemicÒòÊý¾Ý¿âÉèÖùýʧй¶½ü300Íò¿Í»§Êý¾Ý¡£¡£¡£¡£¡£¡£¡£´Ë´Îй¶µÄÊý¾Ý°üÀ¨¿Í»§µÄÐÕÃû¡¢µç×ÓÓʼþIDºÍµç»°ºÅÂë¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ £¬£¬£¬£¬ £¬£¬FriendemicÒÑÈ·ÈϸÃÊÂÎñ £¬£¬£¬£¬ £¬£¬Éù³Æ´ËÊý¾Ý¿âÊÇ´æµµ±¸·Ý £¬£¬£¬£¬ £¬£¬²¢ÓÚ9ÔÂ15ÈÕ¶ÔÆä¾ÙÐÐÁ˱£»£» £»£»¤¡£¡£¡£¡£¡£¡£¡£µ«FriendemicÉÐδȷÇÐ˵Ã÷´Ë´ÎÊý¾Ýй¶µÄÓ°Ïì¹æÄ£ £¬£¬£¬£¬ £¬£¬Ö»ÊÇÌåÏÖÊý¾Ý²»ÊôÓÚÆäÆû³µ¾­ÏúÉ̿ͻ§¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/marketing-firm-friendemic-customer-records-exposed/


4.Ñо¿Ô±·¢Ã÷¶ñÒânpm°üÇÔÈ¡²¢ÔÚGitHubÐû²¼Óû§Êý¾Ý


4.png


SonatypeµÄÑо¿Ö°Ô±·¢Ã÷Á½¸önpm°üelectornºÍloadyaml £¬£¬£¬£¬ £¬£¬ÔÚÊܺ¦ÕßµÄ×°±¸ÉÏÏÂÔØÓû§Êý¾Ý²¢Ðû²¼µ½GitHubÉÏ¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖ £¬£¬£¬£¬ £¬£¬ÕâÁ½ÖÖ°ü¶¼Ê¹ÓÃÁËTyposquattingÊÖÒÕ £¬£¬£¬£¬ £¬£¬Õë¶ÔºÁÎÞ½äÐĵÄÓû§ £¬£¬£¬£¬ £¬£¬Í¨¹ýÔì³É½ÏСµÄÓ¡Ë¢¹ýʧ £¬£¬£¬£¬ £¬£¬ÓÕʹËûÃÇÔÚÆäÇéÐÎÖÐ×°ÖöñÒâÈí¼þ°ü £¬£¬£¬£¬ £¬£¬¶ø²»ÊÇ×î³õÍýÏëÏÂÔØµÄÈí¼þ°ü¡£¡£¡£¡£¡£¡£¡£¸Ã°ü½«ÇÔÈ¡Êܺ¦ÕßµÄÊý¾Ý £¬£¬£¬£¬ £¬£¬°üÀ¨IPµØµã¡¢µØÀíλÖá¢×°±¸Ö¸ÎÆ¡¢²¢½«ÆäËùÓÐÐû²¼ÔÚGitHubÒ³ÃæÉÏ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2020/10/11/malicious-npm-packages-published-users-data-on-github-page/


5.ÂíÈøÖîÈûÖݵÄÑ§ÇøÔâµ½¹¥»÷µ¼ÖÂѧУÔÝʱ¹Ø±Õ


5.png


ÂíÈøÖîÈûÖݵÄ˹ÆÕÁַƶûµÂ¹«Á¢Ñ§ÇøÔâµ½ÀÕË÷Èí¼þ¹¥»÷ £¬£¬£¬£¬ £¬£¬µ¼ÖÂѧУÔÝʱ¹Ø±Õ¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚCOVID-19Ôµ¹ÊÔ­ÓÉ £¬£¬£¬£¬ £¬£¬ÏÖÔÚ¸ÃÑ§ÇøÒÔÔ¶³ÌѧϰģʽÊڿΡ£¡£¡£¡£¡£¡£¡£¸ÃÑ§ÇøÓÚ2020Äê10ÔÂ8ÈÕÔÚFacebook¡¢TwitterºÍ¼Ò³¤µç»°ÖÐÐû²¼ £¬£¬£¬£¬ £¬£¬ÓÉÓÚÍøÂçÎÊÌâ¹Ø±ÕÁËѧУ¡£¡£¡£¡£¡£¡£¡£Ëæºó £¬£¬£¬£¬ £¬£¬Êг¤Domenic J. SarnoºÍ¶½Ñ§Daniel WarwickҲ֤ʵÁË´Ë´ÎÍøÂç¹¥»÷ £¬£¬£¬£¬ £¬£¬²¢Ðû²¼ÔÝÍ£Ô¶³Ìѧϰ¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ¸ÃÑ§ÇøÉв»È·¶¨»Ö¸´Ê±¼ä £¬£¬£¬£¬ £¬£¬Ïêϸȡ¾öÓÚÀÕË÷Èí¼þ¹¥»÷¼ÓÃܵÄ×°±¸ÊýÄ¿ÒÔ¼°»Ö¸´ËüÃÇËùÐèµÄʱ¼ä¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/massachusetts-school-district-shut-down-by-ransomware-attack/


6.ÒѼÓÃܵÄTylerÏòRansomExxÖ§¸¶Êê½ðÀ´»Ö¸´¼ÓÃÜÊý¾Ý


6.png


TylerÊÖÒÕ¹«Ë¾ÒÑÏòRansomExxÖ§¸¶ÁËÊê½ð £¬£¬£¬£¬ £¬£¬ÒÔ»Ö¸´ÔÚ×î½üµÄÀÕË÷Èí¼þ¹¥»÷Öб»¼ÓÃܵÄÎļþ¡£¡£¡£¡£¡£¡£¡£9ÔÂ23ÈÕ £¬£¬£¬£¬ £¬£¬TylerÔâµ½ÁËRansomExxÀÕË÷Èí¼þ¹¥»÷ £¬£¬£¬£¬ £¬£¬Ö®ºóÆäÁ¬Ã¦¶Ï¿ªÁ˲¿·ÖÍøÂç £¬£¬£¬£¬ £¬£¬ÒÔ×èÖ¹ÀÕË÷Èí¼þµÄÈö²¥²¢ÏÞÖÆÆä¿Í»§µÄ»á¼û¹æÄ£ £¬£¬£¬£¬ £¬£¬TylerÌåÏÖÆäÊܵ½ÁËÑÏÖØµÄÓ°Ïì²¢Ô¤¼Æ½«ÐèÒª30Ìì²Å»ªÍêÈ«»Ö¸´ÔËÓª¡£¡£¡£¡£¡£¡£¡£ÐÂÎÅÈËÊ¿³Æ £¬£¬£¬£¬ £¬£¬ÏÖÔÚTylerÒÑÖ§¸¶Êê½ð £¬£¬£¬£¬ £¬£¬¿ÉÊÇÉв»ÇåÎúÏêϸÓöÈ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/tyler-technologies-paid-ransomware-gang-for-decryption-key/