AIR-FI¼¼Êõ¿ÉÀûÓÃRAMÇÔÈ¡ÆøÏ¶ÏµÍ³ÖÐÊý¾Ý  £»SophosºÍReversingLabs°ä²¼¶ñÒâÈí¼þÊý¾Ý¼¯SoReL-20M

°ä²¼¹¦·ò 2020-12-17

1.еÄAIR-FI¼¼Êõ¿ÉÀûÓÃRAMÀ´ÇÔÈ¡ÆøÏ¶ÏµÍ³ÖÐÊý¾Ý


1.jpg


ÒÔÉ«ÁÐѧÕß·¢ÏÖеÄAIR-FI¼¼Êõ £¬¿É½«RAM¿¨×ª»»ÎªÎÞÏß·¢ÉäÆ÷ £¬²¢ÔÚûÓÐWi-Fi¿¨µÄ·ÇÁªÍøÆøÏ¶ÏµÍ³ÖÐÇÔÈ¡Ãô¸ÐÊý¾Ý¡£AIR-FI¼¼ÊõµÄÖ÷ÌâÊÇ £¬µ±µçÁ÷ͨ¹ýÆÚ £¬Èκεç×ÓÔª¼þ³ÇÊвúÉúµç´Å²¨¡£Wi-FiÐźÅÊÇÎÞÏߵ粨 £¬¶øÎÞÏßµç¸ù»ùÉÏÊǵç´Å²¨ £¬Òò¶ø¹¥»÷ÕßÄܹ»Í¨¹ýÏòÆøÏ¶ÏµÍ³ÖÐÖ²Èë¶ñÒâ´úÂë £¬À´Äܹ»°Ñ³ÖRAM¿¨ÄÚ²¿µÄµçÁ÷²úÉúÇкÏÕý³£µÄwifiÐÅºÅÆµÆ×µÄµç´Å²¨¡£¶øºóÀûÓÃÆøÏ¶ÏµÍ³´øÓÐWi-FiÌìÏßµÄÉ豸À´»ñÈ¡¸ÃÐźÅ £¬ÒԸߴï100 b/sµÄËÙ¶ÈÇÔÈ¡Ãô¸ÐÊý¾Ý¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/academics-turn-ram-into-wifi-cards-to-steal-data-from-air-gapped-systems/


2.ºÚ¿ÍÀûÓ÷ÂÕÕÆ÷´Ó¶à¼ÒÅ·ÃÀÒøÐÐÇÔÈ¡Êý°ÙÍòÃÀÔª


2.jpg


ºÚ¿ÍÀûÓ÷ÂÕÕÆ÷´Ó¶à¼ÒÅ·ÃÀÒøÐÐÇÔÈ¡Êý°ÙÍòÃÀÔª¡£ºÚ¿ÍÀûÓó¬¹ý20¸ö·ÂÕÕÆ÷ºýŪ³¬¹ý16000̨ÊÜϰȾµÄÉ豸 £¬³Á¸´½Ó¼ûÊýǧ¸ö¿Í»§ÕÊ»§ £¬½öÓö̶̼¸ÌìµÄ¹¦·ò¾ÍÇÔÈ¡ÁËÊý°ÙÍòÃÀÔª¡£¸Ãڲƭ»î¶¯³É¹¦µØÊµÏÖÁË×Ô¶¯½Ó¼ûÕÊ»§¡¢Æô¶¯ÂòÂô¡¢½Ó¹ÜºÍÇÔÈ¡2FAµÄ¹ý³Ì £¬²¢Ê¹ÓÃÇÔÈ¡µ½µÄ´úÂëÀ´ÊµÏÖ·¸·¨ÂòÂô¡£ÕâЩ·ÂÕÕÆ÷ÉõÖÁ¿ÉÄÜʹÓÃÐ鹹רÓÃÍøÂ磨VPN£©·þÎñÀ´ºýŪÊÜϰȾÉ豸µÄGPSµØÎ» £¬ÒÔ°µ²ØÆä¶ñÒâ»î¶¯¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/emulated-mobile-devices-used-to-steal-millions-from-us-eu-banks/


3.½©Ê¬ÍøÂçGitpaste-12»Ø¹é £¬Í¨¹ýGitHubºÍPastebin´«²¼


3.jpg


½©Ê¬ÍøÂçGitpaste-12»Ø¹é £¬Í¨¹ýGitHubºÍPastebin´«²¼¡£Æä×î³õÊÇͨ¹ýX10-unix½øÐд«²¼µÄ £¬¶øºó´ÓGitHubÏÂÔØÏÂÒ»½×¶ÎµÄÓÐЧ¸ºÔØ¡£Juniper³Æ £¬¸ÃÈ䳿Õë¶ÔWebÀûÓ÷¨Ê½¡¢IPÉãÏñ»úºÍ·ÓÉÆ÷µÈ½øÐÐÁËһϵÁеĹ¥»÷ £¬Ô̺¬ÖÁÉÙ31¸öÒÑÖª·ì϶ £¬²¢ÊÔͼ¹¥»÷Ê¢¿ªµÄAndroid Debug BridgeÏνӺÍÏÖÓеĶñÒâÈí¼þºóÃÅ·¨Ê½¡£Æ¾¾ÝJuniperµÄ¹À¼Æ £¬¸Ã¶ñÒâÈí¼þʹÓÃÁËÖÁÉÙ100¸ö·ÖÆçµÄËÞÖ÷À´½øÐд«²¼¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2020/12/wormable-gitpaste-12-botnet-returns-to.html


4.мäµýÈí¼þGoontactÕë¶ÔÑÇÖÞµØÓòÓû§ÍøÂçÃô¸ÐÊý¾Ý


4.jpg


×êÑÐÈËÔ±·¢ÏÖÁËеļäµýÈí¼þGoontactÕë¶ÔÑÇÖÞµØÓòÓû§ÍøÂçÃô¸ÐÊý¾Ý¡£¸ÃÈí¼þ¿ÉÔÚAndroidºÍiOS°æ±¾ÖÐʹÓà £¬ÖØÒªÕë¶ÔÖÐÎĵĹú¶È¡¢º«¹úºÍÈÕ±¾ £¬¿ÉÄÜ´ÓÊÜϰȾµÄÊܺ¦ÕßÄÇÀïÍøÂçÊý¾Ý £¬ÀýÈçµç»°±êʶ·û¡¢ÁªÏµÈË¡¢SMSÐÂÎÅ¡¢ÕÕÆ¬ºÍλÏàÐÅÏ¢ £¬Ä¿Ç°ÉÐδÔÚAppleºÍGoogle¹Ù·½ÀûÓÃÉ̵êÉϼÜ¡£×êÑÐÈËÔ±²Â²â £¬¸ÃÀûÓ÷¨Ê½µÄÊý¾Ý¿ÉÄܻᱻÓÃÓÚÀÕË÷Êܺ¦ÕßÒÔÖ§¸¶Ó×¶îÊê½ð¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/new-goontact-spyware-discovered-targeting-android-and-ios-users/


5.SophosºÍReversingLabs°ä²¼¶ñÒâÈí¼þÊý¾Ý¼¯SoReL-20M


5.jpg


SophosºÍReversingLabs½áºÏ°ä²¼ÁËÔ̺¬1000Íò¸ö¶ñÒâÈí¼þÑù±¾µÄSoReL-20MÊý¾Ý¿â¡£SoReL-20MΪһ×é¾­¹ýÕû¶ÙºÍÏóÕ÷µÄÑù±¾ºÍ°²È«ÓйØÔªÊý¾Ý £¬¿ÉÓÃÓÚ·´¶ñÒâÈí¼þ½â¾ö¹æ»®ÖÐʹÓõĻúе½ø½¨ÒýÇæµÄѵÁ·Êý¾Ý¼¯¡£Ô̺¬ÁË2000Íò¸öWindows Portable¿ÉÖ´ÐÐÎļþµÄÔªÊý¾Ý¡¢±êÇ©ºÍÖ°ÄÜ £¬ÆäÖÐÔ̺¬1000Íò¶ñÒâÈí¼þÑù±¾¡£Reversinglabs°µÊ¾ÕâЩÊý¾Ý¿ÉΪ¿Í»§ÌṩÃ÷È·µÄÍþвµý±¨Êý¾Ý¼¯ £¬²¢ÔÚËûÃǵķÀÓùÖвûÑï×÷Óá£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/112302/malware/sorel-20m-free-malware-dataset.html


6.CybelAngelÔÚÍøÉÏ·¢ÏÖ³¬¹ý4500ÍòÕŶ³öµÄҽѧͼÏñ


6.jpg


CybelAngelÔÚÍøÉÏ·¢ÏÖÁ˳¬¹ý4500ÍòÕŶ³öµÄҽѧͼÏñ£¨Ô̺¬XÉäÏߺÍCTɨÃ裩¡£ÕâЩҽѧͼÏñµÄÿ±Ê¼Í¼Óжà´ï200ÐеÄÔªÊý¾Ý £¬Ô̺¬¸öÐÕÃû¡¢µ®ÉúÈÕÆÚºÍµØÖ·µÈPII(Ó×ÎÒÉí·ÝÐÅÏ¢£©ºÍPHIÉí¸ß £¬Ìå³ÁºÍÕï¶ÏµÈPHI£¨Ó×ÎÒÒ½ÁÆÐÅÏ¢£© £¬ÇÒÎÞÐèÓû§Ãû»òÃÜÂë¼´¿É½Ó¼û¡£CybelAngel³ÆÕâЩÊý¾Ý¿É±»ÓÃÓÚڲƭ»î¶¯ £¬»òÔÚ°µÍøÉϽøÐÐÏúÊÛ¡£


Ô­ÎÄÁ´½Ó£º

https://cybelangel.com/blog/medical-data-leaks/