Pwn2OwnºÚ¿Í´óÈü³õ´ÎÉæ¼°¹¤Òµ½ÚÔìϵͳ£»Î¢Èí³Æ2020Äê°ÂÔ˻Ὣ¿ÉÄܳÉΪAPT28µÄ¹¥»÷¶ÔÏó

°ä²¼¹¦·ò 2019-10-30
1¡¢Pwn2OwnºÚ¿Í´óÈü³õ´ÎÉæ¼°¹¤Òµ½ÚÔìϵͳ

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

Pwn2OwnºÚ¿Í´óÈü½«Ìṩ³¬¹ý25ÍòÃÀÔªµÄ¼Î½±£¬ÒÔ¼¤ÀøÍÚ¾òICSºÍÓйغÍ̸·ì϶¡£¸Ã»î¶¯½«ÓÚÃ÷Ä꣨1ÔÂ21ÈÕÖÁ1ÔÂ23ÈÕ£©ÔÚÂõ°¢ÃÜS4»áÒéÆÚ¼ä½øÐС£¡°ºÍÆäËû½ÏÁ¿Ò»Ñù£¬Pwn2OwnÊÔͼͨ¹ý½Òʾ·ì϶²¢½«×êÑÐÁ˾ÖÌṩ¸ø¹©¸øÉÌÀ´Ç¿»¯ÕâЩƽ̨¡±£¬Pwn2Own×éÖ¯Õß¡¢ZDIÌáÒéÈËBrian GorencÔÚÖÜÒ»µÄÌû×ÓÖаµÊ¾£¬¡°Pwn2OwnµÄÖ¸±êʼÖÕÊÇÔÚ¹¥»÷Õß»ý¼«ÀûÓÃ֮ǰ½¨¸´ÕâЩ·ì϶¡±¡£Pwn2Own MiamiΪÎå¸öICSÀà´ËÍâ·ì϶ÌṩÁ˸÷Àà¼Î½±£¬Ô̺¬½ÚÔì·þÎñÆ÷½â¾ö¹æ»®¡¢OPC·þÎñÆ÷¡¢DNP3ͨѶºÍ̸¡¢HMI/²Ù×÷ԹؾºÍ¹¤³Ì¹¤×÷Õ¾Èí¼þ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/pwn2own-expands-industrial-control-systems/149594/

2¡¢Ó¡¶È130ÍòÕÅÒøÐп¨ÐÅÏ¢ÔÚJoker's StashÉÏÏúÊÛ

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Group-IB×êÑÐÈËÔ±·¢ÏÖ³¬¹ý130ÍòÕÅÓ¡¶ÈÒøÐп¨ÐÅÏ¢ÔÚJoker's StashÉÏÏúÊÛ¡£Group-IB°µÊ¾ÕâЩ¿¨µÄ×î¸ßÊÛ¼ÛΪÿÕÅ¿¨100ÃÀÔª£¬ÕâÒâζ×ÅÆä×ܼÛÖµ³¬¹ý1.3ÒÚÃÀÔª¡£ÓÉÓÚÕâЩÊý¾ÝÊÇÔÚ¼¸Ó×ʱǰ°ä²¼µÄ£¬×êÑÐÈËÔ±ÉÐûÓй¦·ò·ÖÎöºÍµ÷²é¿ÉÄܵÄÐÂäį´Ô´¡£³õ²½·ÖÎöÅú×¢ÕâЩÐÅÏ¢¿ÉÄÜÊÇͨ¹ý×°ÖÃÔÚATM»òPoSϵͳÉÏµÄÆ²ÔüÆ÷ÇÔÈ¡µÄ¡£´Ë±í£¬´Ó·¢¿¨ÒøÐÐÀ´¿´£¬±»ÇÔ¿¨µÄÖÖÀà·±¶à£¬À´×ÔÓÚ¶à¼ÒÒøÐУ¬ÕâÅųýÁ˵¥ÖðÒ»¼ÒÒøÐÐϵͳ±»ÈëÇֵĿÉÄÜÐÔ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/details-for-1-3-million-indian-payment-cards-put-up-for-sale-on-jokers-stash/

3¡¢·¨¹úʱÉÐÆ·ÅÆSixth June¹ÙÍøÔâMageCart¹¥»÷

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

·¨¹úʱÉÐÆ·ÅÆSixth June¹ÙÍøÔâMageCart¶ñÒâ¾ç±¾Ï°È¾£¬°²È«×êÑÐÈËÔ±Jenkins·¢ÏÖÁËÕâÒ»ÊÂÎñ²¢ÓÚÉÏÖÜ֪ͨÁ˸ù«Ë¾£¬µ«ÉÐδµÃµ½»Ø´ð¡£½ØÖÁĿǰ¸Ã¶ñÒâ´úÂëÈÔ´æÔÚÓÚÍøÕ¾µÄÖ§¸¶Ò³ÃæÉÏ¡£Sixth JuneÔÚÅ·ÖÞºÜÊÜÓ­½Ó£¬9ÔÂ·ÝÆäÍøÕ¾µÄ½Ó¼ûÁ¿Ô¼Îª7ÍòÈ˴Ρ£ÆäÍøÕ¾ÒÀÀµÓÚµç×ÓÉÌÎñƽ̨Magento£¬¹¥»÷Õß×¢²áÁËÒ»¸ö¼Ù×°³ÉMagento¹Ù·½ÓòÃûµÄ¼ÙÓòÃûmogento[.]infoÀ´°µ²Ø×Ô¼º¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/sixth-june-fashion-site-hacked-to-steal-credit-cards/

4¡¢ÃÀ¹ú¿ì²ÍÁ¬ËøµêKrystal°ä²¼Í¨Öª³ÆÆä¿Í»§ÐÅϢй¶


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ÃÀ¹ú¿ì²ÍÁ¬ËøµêKrystal°µÊ¾ÆäÖ§¸¶´¦ÖÃϵͳÔâ·ê°²È«ÊÂÎñ£¬²¿ÃŲÍÌüÊܵ½Ó°Ïì¡£¸ÃÊÂÎñ²úÉúÔÚ2019Äê7ÔÂÖÁ9ÔÂÖ®¼ä£¬Ä¿Ç°Éв»ÖªÂ·Êܴ˰²È«ÊÂÎñÓ°ÏìµÄ¿Í»§ÊýÁ¿ÒÔ¼°Â¶³öµÄ¸¶¿îÐÅÏ¢ÀàÐÍ£¬Ò²²»Ã÷ÏÔ°²È«ÊÂÎñ±³ºóµÄÔ­ÒòÊÇÖ§¸¶ÏµÍ³Êý¾Ý¿â¶³ö/δÊÚȨ½Ó¼û»¹ÊÇPoS¶ñÒâÈí¼þ¹¥»÷µÈ¡£Krystal°µÊ¾ÔÚÖÂÁ¦È·¶¨ÄÄЩ²ÍÌüÊÜÓ°Ïì¼°¾ßÌåµÄµØÖ·ºÍÈÕÆÚ£¬Ëü»¹°µÊ¾ÒѾ­È·ÈÏÔ¼ÓÐÈý·ÖÖ®Ò»µÄ²ÍÌüûÓÐÊܵ½Ó°Ïì¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/us-food-chain-alerts-customers-of-payment-card-incident/

5¡¢Î¢Èí³Æ2020Äê°ÂÔ˻Ὣ¿ÉÄܳÉΪAPT28µÄ¹¥»÷¶ÔÏó


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


΢ÈíÖÒ¸æ³Æ2020Äê¶«¾©°ÂÔË»á¿ÉÄܳÉΪ¶íÂÞ˹ºÚ¿Í×éÖ¯APT28£¨±ðÃû»¨Ê½ÐÜ£©µÄ¹¥»÷Ö¸±ê¡£Î¢ÈíÍþвµý±¨ÖÐÐÄÖ¸³ö£¬ËûÃÇ×·×ÙÁËÕë¶ÔÌåÓýÖ÷¹Ü²¿Ãźͷ´Ð˷ܼÁ»ú¹¹µÄ´óÐÍÍøÂç¹¥»÷£¬×Ô2019Äê9ÔÂ16ÈÕÒÔÀ´À´×ÔÈý´óÖÞµÄ16¸ö¹ú¶ÈºÍ¹ú¼Ê»ú¹¹ÒѾ­³ÉΪ¹¥»÷Ö¸±ê¡£Õâ²»ÊÇ»¨Ê½ÐܵÚÒ»´ÎÕë¶Ô·´Ð˷ܼÁ»ú¹¹£¬×Ô´ÓWADAÔÚ2016ÄêÀïÔ¼°ÂÔË»áÉϲ»ÈݶíÂÞ˹»î´øÍ·²ÎÈüºó£¬¸Ã×éÖ¯Ò»Ö¹Øë¶Ô¹ú¼Ê·´Ð˷ܼÁ»ú¹¹¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/10/cyber-attack-tokyo-olympics.html

6¡¢Ð¶ñÒâÈí¼þxHelperÒÑϰȾ³¬¹ý4.5Íǫ̀AndroidÉ豸

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


жñÒâÈí¼þxHelper×îÔçÓÚ3Ô±»·¢ÏÖ£¬8Ô·ÝxHelperÖð²½·¢Õ¹µ½Ï°È¾Á˳¬¹ý3.2Íǫ̀É豸£¬µ½10Ô·ÝÕâÒ»Êý×ÖÒѾ­Ôö³¤µ½4.5Íǫ̀¡£ÕâÅú×¢¸Ã¶ñÒâÈí¼þ´¦ÓÚÇ峺µÄÉÏÉýÇ÷Ïò£¬Æ¾¾ÝÈüÃÅÌú¿ËµÄÊý¾Ý£¬xHelper¾ùÔÈÿÌìϰȾ131ÃûÐÂÊܺ¦Õߣ¬Ã¿ÔÂÔ¼ÓÐ2400ÃûÐÂÊܺ¦Õß¡£ÕâЩϰȾ´ó¶à²úÉúÔÚÓ¡¶È¡¢ÃÀ¹úºÍ¶íÂÞ˹¡£Æ¾¾ÝMalwarebytesµÄ˵·¨£¬xHelperÖØÒªÍ¨¹ýµÚÈý·½ÀûÓÃÉ̵ê×°Öã¬ÖØÒªÓÃÓÚÏÔʾÇÖÈëÐÔµ¯³ö¸æ°×ºÍ֪ͨÀ¬»øÓʼþ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/new-unremovable-xhelper-malware-has-infected-45000-android-devices/