Pwn2OwnºÚ¿Í´óÈüÊ×´ÎÉæ¼°¹¤Òµ¿ØÖÆÏµÍ³ £»£»£»£»£»£»£»Î¢Èí³Æ2020Äê°ÂÔ˻Ὣ¿ÉÄܳÉΪAPT28µÄ¹¥»÷¹¤¾ß

Ðû²¼Ê±¼ä 2019-10-30
1¡¢Pwn2OwnºÚ¿Í´óÈüÊ×´ÎÉæ¼°¹¤Òµ¿ØÖÆÏµÍ³

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾

Pwn2OwnºÚ¿Í´óÈü½«ÌṩÁè¼Ý25ÍòÃÀÔªµÄ½±Àø£¬£¬£¬£¬ÒÔÃãÀøÍÚ¾òICSºÍÏà¹ØÐ­ÒéÎó²î¡£¡£¡£¡£¡£¡£¡£¸Ã»î¶¯½«ÓÚÃ÷Ä꣨1ÔÂ21ÈÕÖÁ1ÔÂ23ÈÕ£©ÔÚÂõ°¢ÃÜS4¾Û»áʱ´ú¾ÙÐС£¡£¡£¡£¡£¡£¡£¡°ºÍÆäËû¾ºÈüÒ»Ñù£¬£¬£¬£¬Pwn2OwnÊÔͼͨ¹ýÕ¹ÏÖÎó²î²¢½«Ñо¿Ð§¹ûÌṩӦ¹©Ó¦ÉÌÀ´Ç¿»¯ÕâЩƽ̨¡±£¬£¬£¬£¬Pwn2Own×éÖ¯Õß¡¢ZDIÌᳫÈËBrian GorencÔÚÖÜÒ»µÄÌû×ÓÖÐÌåÏÖ£¬£¬£¬£¬¡°Pwn2OwnµÄÄ¿µÄʼÖÕÊÇÔÚ¹¥»÷Õ߯ð¾¢Ê¹ÓÃ֮ǰÐÞ¸´ÕâЩÎó²î¡±¡£¡£¡£¡£¡£¡£¡£Pwn2Own MiamiΪÎå¸öICSÀà±ðµÄÎó²îÌṩÁËÖÖÖÖ½±Àø£¬£¬£¬£¬°üÀ¨¿ØÖÆÐ§ÀÍÆ÷½â¾ö¼Æ»®¡¢OPCЧÀÍÆ÷¡¢DNP3ͨѶЭÒé¡¢HMI/²Ù×÷Ô±Õ¾ºÍ¹¤³ÌÊÂÇéÕ¾Èí¼þ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/pwn2own-expands-industrial-control-systems/149594/

2¡¢Ó¡¶È130ÍòÕÅÒøÐп¨ÐÅÏ¢ÔÚJoker's StashÉϳöÊÛ

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Group-IBÑо¿Ö°Ô±·¢Ã÷Áè¼Ý130ÍòÕÅÓ¡¶ÈÒøÐп¨ÐÅÏ¢ÔÚJoker's StashÉϳöÊÛ¡£¡£¡£¡£¡£¡£¡£Group-IBÌåÏÖÕâЩ¿¨µÄ×î¸ßÊÛ¼ÛΪÿÕÅ¿¨100ÃÀÔª£¬£¬£¬£¬ÕâÒâζ×ÅÆä×ܼÛÖµÁè¼Ý1.3ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÕâЩÊý¾ÝÊÇÔÚ¼¸Ð¡Ê±Ç°Ðû²¼µÄ£¬£¬£¬£¬Ñо¿Ö°Ô±ÉÐûÓÐʱ¼äÆÊÎöºÍÊÓ²ì¿ÉÄܵÄй¿à´Ô´¡£¡£¡£¡£¡£¡£¡£ÆðÔ´ÆÊÎöÅú×¢ÕâЩÐÅÏ¢¿ÉÄÜÊÇͨ¹ý×°ÖÃÔÚATM»òPoSϵͳÉÏµÄÆ²ÔüÆ÷ÇÔÈ¡µÄ¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬´Ó·¢¿¨ÒøÐÐÀ´¿´£¬£¬£¬£¬±»ÇÔ¿¨µÄÖÖÀà·±¶à£¬£¬£¬£¬À´×ÔÓÚ¶à¼ÒÒøÐУ¬£¬£¬£¬Õâɨ³ýÁ˵¥ÖðÒ»¼ÒÒøÐÐϵͳ±»ÈëÇֵĿÉÄÜÐÔ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/details-for-1-3-million-indian-payment-cards-put-up-for-sale-on-jokers-stash/

3¡¢·¨¹úʱÉÐÆ·ÅÆSixth June¹ÙÍøÔâMageCart¹¥»÷

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾

·¨¹úʱÉÐÆ·ÅÆSixth June¹ÙÍøÔâMageCart¶ñÒâ¾ç±¾Ñ¬È¾£¬£¬£¬£¬Çå¾²Ñо¿Ö°Ô±Jenkins·¢Ã÷ÁËÕâÒ»ÊÂÎñ²¢ÓÚÉÏÖÜ֪ͨÁ˸ù«Ë¾£¬£¬£¬£¬µ«ÉÐδ»ñµÃ»Ø¸´¡£¡£¡£¡£¡£¡£¡£×èÖ¹ÏÖÔڸöñÒâ´úÂëÈÔ±£´æÓÚÍøÕ¾µÄÖ§¸¶Ò³ÃæÉÏ¡£¡£¡£¡£¡£¡£¡£Sixth JuneÔÚÅ·ÖÞºÜÊܽӴý£¬£¬£¬£¬9ÔÂ·ÝÆäÍøÕ¾µÄ»á¼ûÁ¿Ô¼Îª7ÍòÈ˴Ρ£¡£¡£¡£¡£¡£¡£ÆäÍøÕ¾ÒÀÀµÓÚµç×ÓÉÌÎñƽ̨Magento£¬£¬£¬£¬¹¥»÷Õß×¢²áÁËÒ»¸öαװ³ÉMagento¹Ù·½ÓòÃûµÄ¼ÙÓòÃûmogento[.]infoÀ´Òþ²Ø×Ô¼º¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/sixth-june-fashion-site-hacked-to-steal-credit-cards/

4¡¢ÃÀ¹ú¿ì²ÍÁ¬ËøµêKrystalÐû²¼Í¨Öª³ÆÆä¿Í»§ÐÅϢй¶


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ÃÀ¹ú¿ì²ÍÁ¬ËøµêKrystalÌåÏÖÆäÖ§¸¶´¦Öóͷ£ÏµÍ³ÔâÓöÇå¾²ÊÂÎñ£¬£¬£¬£¬²¿·Ö²ÍÌüÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñ±¬·¢ÔÚ2019Äê7ÔÂÖÁ9ÔÂÖ®¼ä£¬£¬£¬£¬ÏÖÔÚÉв»ÖªµÀÊÜ´ËÇå¾²ÊÂÎñÓ°ÏìµÄ¿Í»§ÊýÄ¿ÒÔ¼°Ì»Â¶µÄ¸¶¿îÐÅÏ¢ÀàÐÍ£¬£¬£¬£¬Ò²²»ÇåÎúÇå¾²ÊÂÎñ±³ºóµÄÔµ¹ÊÔ­ÓÉÊÇÖ§¸¶ÏµÍ³Êý¾Ý¿â̻¶/δÊÚȨ»á¼ûÕÕ¾ÉPoS¶ñÒâÈí¼þ¹¥»÷µÈ¡£¡£¡£¡£¡£¡£¡£KrystalÌåÏÖÕýÔÚÆð¾¢È·¶¨ÄÄЩ²ÍÌüÊÜÓ°Ïì¼°ÏêϸµÄËùÔÚºÍÈÕÆÚ£¬£¬£¬£¬Ëü»¹ÌåÏÖÒѾ­È·ÈÏÔ¼ÓÐÈý·ÖÖ®Ò»µÄ²ÍÌüûÓÐÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/us-food-chain-alerts-customers-of-payment-card-incident/

5¡¢Î¢Èí³Æ2020Äê°ÂÔ˻Ὣ¿ÉÄܳÉΪAPT28µÄ¹¥»÷¹¤¾ß


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


΢ÈíÖÒÑÔ³Æ2020Äê¶«¾©°ÂÔË»á¿ÉÄܳÉΪ¶íÂÞ˹ºÚ¿Í×éÖ¯APT28£¨ÓÖÃû»¨Ê½ÐÜ£©µÄ¹¥»÷Ä¿µÄ¡£¡£¡£¡£¡£¡£¡£Î¢ÈíÍþвÇ鱨ÖÐÐÄÖ¸³ö£¬£¬£¬£¬ËûÃÇ×·×ÙÁËÕë¶ÔÌåÓýÖ÷¹Ü²¿·ÖºÍ·´Ð˷ܼÁ»ú¹¹µÄ´óÐÍÍøÂç¹¥»÷£¬£¬£¬£¬×Ô2019Äê9ÔÂ16ÈÕÒÔÀ´À´×ÔÈý´óÖÞµÄ16¸ö¹ú¼ÒºÍ¹ú¼Ê»ú¹¹ÒѾ­³ÉΪ¹¥»÷Ä¿µÄ¡£¡£¡£¡£¡£¡£¡£Õâ²»ÊÇ»¨Ê½ÐܵÚÒ»´ÎÕë¶Ô·´Ð˷ܼÁ»ú¹¹£¬£¬£¬£¬×Ô´ÓWADAÔÚ2016ÄêÀïÔ¼°ÂÔË»áÉÏեȡ¶íÂÞ˹ÔË·¢¶¯²ÎÈüºó£¬£¬£¬£¬¸Ã×éÖ¯Ò»Ö±Õë¶Ô¹ú¼Ê·´Ð˷ܼÁ»ú¹¹¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/10/cyber-attack-tokyo-olympics.html

6¡¢Ð¶ñÒâÈí¼þxHelperÒÑѬȾÁè¼Ý4.5Íǫ̀Android×°±¸

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


жñÒâÈí¼þxHelper×îÔçÓÚ3Ô±»·¢Ã÷£¬£¬£¬£¬8Ô·ÝxHelperÖð½¥Éú³¤µ½Ñ¬È¾ÁËÁè¼Ý3.2Íǫ̀װ±¸£¬£¬£¬£¬µ½10Ô·ÝÕâÒ»Êý×ÖÒѾ­ÔöÌíµ½4.5Íǫ̀¡£¡£¡£¡£¡£¡£¡£ÕâÅú×¢¸Ã¶ñÒâÈí¼þ´¦ÓÚÇåÎúµÄÉÏÉýÇ÷ÊÆ£¬£¬£¬£¬Æ¾Ö¤ÈüÃÅÌú¿ËµÄÊý¾Ý£¬£¬£¬£¬xHelperƽ¾ùÌìÌìѬȾ131ÃûÐÂÊܺ¦Õߣ¬£¬£¬£¬Ã¿ÔÂÔ¼ÓÐ2400ÃûÐÂÊܺ¦Õß¡£¡£¡£¡£¡£¡£¡£ÕâЩѬȾ´ó¶à±¬·¢ÔÚÓ¡¶È¡¢ÃÀ¹úºÍ¶íÂÞ˹¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤MalwarebytesµÄ˵·¨£¬£¬£¬£¬xHelperÖ÷Ҫͨ¹ýµÚÈý·½Ó¦ÓÃÊÐËÁ×°Ö㬣¬£¬£¬Ö÷ÒªÓÃÓÚÏÔʾÇÖÈëÐÔµ¯³ö¹ã¸æºÍ֪ͨÀ¬»øÓʼþ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/new-unremovable-xhelper-malware-has-infected-45000-android-devices/