ÐŰ²±êί¡¶ÍøÂ簲ȫ³ß¶Èʵ¼ÊÖ¸ÄÏ¡ªÔ¶³Ì°ì¹«°²È«·À»¤¡·£»£»£»£»£»£»2019Ä꿪Դ´úÂë·ì϶ÊýÁ¿Ôö³¤½ü50£¥
°ä²¼¹¦·ò 2020-03-171.ÐŰ²±êί¡¶ÍøÂ簲ȫ³ß¶Èʵ¼ÊÖ¸ÄÏ¡ªÔ¶³Ì°ì¹«°²È«·À»¤¡·

È«¹úÐÅÏ¢°²È«³ß¶È»¯¼¼ÊõίԱ»áÃØÊé´¦Õë¶ÔÔ¶³Ì°ì¹«°²È«ÎÊÌ⣬£¬£¬£¬£¬£¬×éÖ¯Óйس§É̺Ͱ²È«×¨¼Ò£¬£¬£¬£¬£¬£¬¼ÙÔìÁË¡¶ÍøÂ簲ȫ³ß¶Èʵ¼ÊÖ¸ÄÏ¡ªÔ¶³Ì°ì¹«°²È«·À»¤¡·¡£¡£¡£¡£¡£¡£¡¶Êµ¼ÊÖ¸ÄÏ¡·¸ø³öÁËÔ¶³Ì°ì¹«µÄµäÐÍÀûÓó¡¾°£¬£¬£¬£¬£¬£¬·ÖÎöÁËÔ¶³Ì°ì¹«¿ÉÄÜÃæ¶ÔµÄ°ì¹«ÏµÍ³×ÔÉí°²È«¡¢Êý¾Ý°²È«¡¢É豸°²È«ºÍÓ×ÎÒÐÅÏ¢±£»£»£»£»£»£»¤µÈ·çÏÕ£¬£¬£¬£¬£¬£¬Õë¶ÔÔ¶³Ì°ì¹«ÏµÍ³µÄʹÓ÷½ºÍÓû§£¬£¬£¬£¬£¬£¬±ðÀë¸ø³öÁ˰²È«½ÚÔì´ëÊ©½¨Òé¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬Ê¹Ó÷½Ó¦ÔÚÖÎÀíºÍ¼¼ÊõÁ½·½Ãæ·¢Õ¹°²È«·À»¤£¬£¬£¬£¬£¬£¬½¡È«Ô¶³Ì°ì¹«ÖÎÀíÔì¶È£¬£¬£¬£¬£¬£¬¼ÓÇ¿ÔËάÖÎÀí£¬£¬£¬£¬£¬£¬Ç¿»¯°²È«´ëÊ©¡£¡£¡£¡£¡£¡£Óû§Ó¦Ìá¸ß×ÔÉí°²È«Òâʶ£¬£¬£¬£¬£¬£¬³ÁµãÕë¶ÔÉ豸¡¢Êý¾Ý¡¢»·¾³µÈ·½ÃæµÄ°²È«·çÏÕ½øÐзÀ»¤¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.tc260.org.cn/upload/2020-03-13/1584090952093076364.pdf
2.2019Ä꿪Դ´úÂë·ì϶ÊýÁ¿³õ´Î³¬¹ý6000¸ö£¬£¬£¬£¬£¬£¬Ôö³¤½ü50£¥
ƾ¾Ý¿ªÔ´°²È«ÓëºÏ¹æ¹«Ë¾WhiteSourceµÄÒ»·Ý»ã±¨£¬£¬£¬£¬£¬£¬È¥Ä꿪Դ´úÂëÖеķì϶¼¤Ôö¡£¡£¡£¡£¡£¡£¸Ã»ã±¨³Æ£¬£¬£¬£¬£¬£¬2017ÄêºÍ2018Ä꿪Դ·ì϶µÄÊýÁ¿²»±äÔÚ4000¶à¸ö£¬£¬£¬£¬£¬£¬Óë2017Äê֮ǰ´ÓÎ´Í»ÆÆ2000¸öµÄÊý×ÖÏà±È£¬£¬£¬£¬£¬£¬·ì϶ÊýÁ¿Ôö³¤ÁËÒ»±¶ÒÔÉÏ¡£¡£¡£¡£¡£¡£¶øºóÔÚ2019Ä꣬£¬£¬£¬£¬£¬¿ªÔ´·ì϶ÊýÁ¿ÔÙ´ÎìÉý£¬£¬£¬£¬£¬£¬³õ´Î³¬¹ý6000¸ö£¬£¬£¬£¬£¬£¬Õâ´ú±íÁ˽ü50£¥µÄÔö³¤¡£¡£¡£¡£¡£¡£µ½Ä¿Ç°ÎªÖ¹¿ªÔ´·ì϶ÖÐ×î³£¼ûµÄÀàÐÍÊÇ¿çÕ¾µã¾ç±¾£¨XSS£©£¬£¬£¬£¬£¬£¬¸ÃÀàÐÍÏÕЩռËùÓзì϶µÄËÄ·ÖÖ®Ò»£¬£¬£¬£¬£¬£¬Æä´ÎÊÇÊäÈëÑéÖ¤²»ÕýÈ·¡¢»º³åÇøÃýÎó¡¢Ô½½ç¶ÁÈ¡ºÍÐÅϢй¶¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://nakedsecurity.sophos.com/2020/03/16/open-source-bugs-have-soared-in-the-past-year/
3.2020ÄêÔÆÅäÖÃÃýÎó»ã±¨£¬£¬£¬£¬£¬£¬´ÓǰÁ½Äêй¶330Òڱʼͼ
ƾ¾ÝDivvyCloudµÄ2020ÄêÔÆÅäÖÃÃýÎó»ã±¨£¬£¬£¬£¬£¬£¬2018ÄêºÍ2019ÄêÓнü334ÒڱʼͼÒòÔÆÅäÖÃÃýÎóµ¼ÖÂй¶£¬£¬£¬£¬£¬£¬È«ÇòÆóÒµµÄ³É±¾Îª½«½ü5ÍòÒÚÃÀÔª¡£¡£¡£¡£¡£¡£´Ó2018Äêµ½2019Ä꣬£¬£¬£¬£¬£¬ÔÆÅäÖÃÃýÎó¶³öµÄ¼Í¼ÊýÁ¿Í¬±ÈÔö³¤ÁË80£¥£¬£¬£¬£¬£¬£¬ÓëÖ®ÓйصĹ«Ë¾×ܳɱ¾Ò²ÓÐËùÔö³¤¡£¡£¡£¡£¡£¡£²»ÐÒµÄÊÇ£¬£¬£¬£¬£¬£¬×¨¼ÒÃÇÔ¤¼ÆÕâÖÖÉÏÉýÇ÷Ïò½«³ÖÐøÏÂÈ¥£¬£¬£¬£¬£¬£¬ÓÉÓÚ¹«Ë¾³ÖÐøÑ¸ËÙÑ¡È¡ÔÆ·þÎñµ«Î´ÄÜÖ´ÐÐÊʵ±µÄÔÆ°²È«´ëÊ©¡£¡£¡£¡£¡£¡£ElasticsearchÅäÖÃÃýÎóÕ¼ËùÓÐй¶µÄ20£¥£¬£¬£¬£¬£¬£¬µ«ÕâЩÊÂÎñй¶µÄ¼Í¼ÊýÁ¿Õ¼ËùÓмͼµÄ44£¥¡£¡£¡£¡£¡£¡£´Ó2018Äêµ½2019Ä꣬£¬£¬£¬£¬£¬ÓÉElasticsearchÅäÖÃÃýÎóµ¼ÖµÄй¶ÊýÁ¿ÏÕЩÔö³¤ÁËÁ½±¶¡£¡£¡£¡£¡£¡£S3´æ´¢Í°ÅäÖÃÃýÎóÕ¼ËùÓÐй¶µÄ16£¥£¬£¬£¬£¬£¬£¬µ«ÊÇÓë2018ÄêÏà±È£¬£¬£¬£¬£¬£¬2019ÄêÅäÖÃÃýÎóµÄS3·þÎñÆ÷Ï÷¼õÁË45£¥¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.computerweekly.com/news/252478833/Cost-of-cloud-misconfigurations-set-at-5tn?&web_view=true
4.Android¸ú×ÙÈí¼þMonitorMinor£¬£¬£¬£¬£¬£¬¿É¸ú×ÙGmailÓû§»î¶¯
¿¨°Í˹»ù°²È«×¨¼Ò·¢ÏÖÐÂAndroid¸ú×ÙÈí¼þMonitorMinor£¬£¬£¬£¬£¬£¬ËüÄܹ»¸ú×ÙGmail¡¢WhatsApp¡¢InstagramºÍFacebookµÄÓû§»î¶¯¡£¡£¡£¡£¡£¡£°²È«×¨¼Ò³ÆMonitorMinor±ÈÆä¼Ò×åµÄËùÓÐÏÖÓÐÈí¼þÖ°Äܸü׳´ó£¬£¬£¬£¬£¬£¬ËüÀûÓÃÁËSuperUserÀàÐ͵ÄÀûÓ÷¨Ê½£¨SUʵÓ÷¨Ê½£©À´»ñµÃϵͳµÄroot½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬£¬»¹Äܹ»ÌáÈ¡É豸ÉϵÄ/data/system/gesture.keyÎļþ£¬£¬£¬£¬£¬£¬¸ÃÎļþÔ̺¬ÁËÆÁÄ»½âËøÄ£Ê½/ÃÜÂëµÄ¹þÏ£Öµ¡£¡£¡£¡£¡£¡£MonitorMonor¹¥»÷ÕßÄܹ»ÀûÓÃËüÀ´½âËøÉ豸£¬£¬£¬£¬£¬£¬ÕâÊǵÚÒ»¸öʵÏÖ´ËÖ°Äܵĸú×ÙÈí¼þ¡£¡£¡£¡£¡£¡£MonitorMinor»¹ÀûÓÃAccessibility Services APIÀ´À¹½ØÖ¸±êAPPÖеÄÊÂÎñ£¬£¬£¬£¬£¬£¬¼´±ãûÓÐrootȨÏÞ£¬£¬£¬£¬£¬£¬ËüÒ²Äܹ»Ê¹ÓôËAPIÔÚËùÓÐÉ豸ÉÏÓÐЧÔËÐС£¡£¡£¡£¡£¡£Æ¾¾Ý¿¨°Í˹»ùµÄ˵·¨£¬£¬£¬£¬£¬£¬¸Ã¸ú×ÙÈí¼þ´óÎÞÊý×°ÖÃÔÚÓ¡¶È£¨14.71£¥£©¡¢Æä´ÎÊÇÄ«Î÷¸ç£¨11.76£¥£©¡¢µÂ¹ú¡¢É³Ìذ¢À²®ºÍÓ¢¹ú£¨5.88£¥£©¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/monitorminor-vicious-stalkerware/95575/?utm_source=rss&utm_medium=rss&utm_campaign=monitorminor-vicious-stalkerware
5.×êÑÐÍŶӰ䲼ÐÂÀÕË÷Èí¼þ¼Ò×åPXJµÄ·ÖÎö»ã±¨
IBM X-ForceµÄ°²È«×¨¼Ò·¢ÏÖÁËÒ»ÖÖеÄÀÕË÷Èí¼þPXJ Ransomware£¬£¬£¬£¬£¬£¬Ö»¹Ü¸ÃÀÕË÷Èí¼þʵÏÖÁË´óÎÞÊýÀÕË÷Èí¼þ¹²ÓеÄÖ°ÄÜ£¬£¬£¬£¬£¬£¬µ«ËüËÆºõ²¢Î´ÓëÒÑÖªµÄÀÕË÷Èí¼þ¼Ò×å¹²Ïíµ×²ã´úÂë¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÔÚ2ÔÂ29ÈÕ³õ´Î·¢ÏÖÁËPXJ£¬£¬£¬£¬£¬£¬ÆäʱÓÐÁ½¸öÑù±¾±»ÉÏ´«µ½VirusTotal¡£¡£¡£¡£¡£¡£PXJµÄÃû³ÆÀ´×Ô¸½¼Óµ½¼ÓÃÜÎļþµÄÀ©´óÃû£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÒ²±»³ÆÎªXVFXGW£¬£¬£¬£¬£¬£¬À´×ÔÓÚ¶ñÒâÈí¼þ´´½¨µÄ¡°XVFXGW DOUBLE SET¡±¼°ÀÕË÷µ¥¾ÝÖÐÔ̺¬µÄµç×ÓÓʼþµØÖ·£¨¡°xvfxgw3929@protonmail.com¡±ºÍ¡°xvfxgw213@decoymail.com¡±£©¡£¡£¡£¡£¡£¡£PXJʹÓÃAESºÍRSAËã·¨À´¼ÓÃÜÊý¾Ý¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±Ôڻ㱨ÖзÖÎöÁËÓйØPXJµÄ¼¼Êõϸ½Ú£¬£¬£¬£¬£¬£¬Ô̺¬ÈëÇÖÖ¸±ê£¨IoC£©¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityintelligence.com/posts/pxj-ransomware-campaign-identified-by-x-force-iris/
6.ÃÀ¹úÎÀÉúÓ빫¼Ò·þÎñ²¿£¨HHS£©ÔâDDoS¹¥»÷
ÃÀ¹úÎÀÉúÓ빫¼Ò·þÎñ²¿£¨HHS£©ÓÚÖÜÈÕÔâµ½DDoS¹¥»÷£¬£¬£¬£¬£¬£¬µ«¸Ã»ú¹¹°µÊ¾ÊÂÎñ²¢Î´Ôì³ÉÈκγÁ´ó·ÛËé¡£¡£¡£¡£¡£¡£³õ´Î±¨Â·ÕâÒ»ÊÂÎñµÄÅí²©Éç×î³õʹÓÃÁË¡°ÍøÂçÈëÇÖ¡±Ò»´Ê£¬£¬£¬£¬£¬£¬µ«ºóÀ´½«Æä´ÓÎÄÕÂÕýÎÄÖÐɾ³ý-µ«ÒÀÈ»±£ÁôÔÚ¸±±êÌâÖС£¡£¡£¡£¡£¡£¡¶»ªÊ¢¶ÙÓʱ¨¡·³ÆHSµÄÍøÕ¾ÏÖʵÉÏ´ÓδÒòÕâ´Î¹¥»÷¶ø±ÀÀ£¡£¡£¡£¡£¡£¡£Æ¾¾ÝһЩ±¨Â·£¬£¬£¬£¬£¬£¬¹¥»÷¿ÉÄÜÊÇÓɱí¹ú¹¥»÷ÕßÌáÒéµÄ£¬£¬£¬£¬£¬£¬ÆäÖ÷ÕÅÊÇ·ÛËéHHS¶ÔCOVID-19Σ»£»£»£»£»£»úµÄ·´Ó³£¬£¬£¬£¬£¬£¬µ«ÕâÒ»ÀíÂÛÉÐδµÃµ½Ö¤Êµ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/hhs-says-ddos-attack-failed-cause-disruption


¾©¹«Íø°²±¸11010802024551ºÅ