×êÑÐÈËÔ±·¢ÏÖжñÒâÈí¼þTaurusͨ¹ý¶ñÒâ¸æ°×»î¶¯´«²¼£»£»£»£»£»£»£»Pandora FMSÖдæÔÚ¶à¸ö·ì϶£¬£¬£¬£¬£¬¿Éµ¼ÖÂÔ¶³ÌÖ´Ðй¥»÷
°ä²¼¹¦·ò 2020-09-29
×êÑÐÈËÔ±·¢ÏÖеÄÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þTaurusͨ¹ý¶ñÒâ¸æ°×»î¶¯´«²¼¡£¡£¡£¡£¡£¡£¡£¡£TaurusÊÇÒ»ÖÖÏà¶Ô½ÏеĶñÒâÈí¼þ£¬£¬£¬£¬£¬ÓÚ2020Äê´º¼¾³öÏÖ£¬£¬£¬£¬£¬Í¨¹ýÕë¶ÔÃÀ¹úÓû§µÄ¶ñÒâ¸æ°×»î¶¯½øÐд«²¼¡£¡£¡£¡£¡£¡£¡£¡£Æä×î³õÊÇÓÉPredatorµÄ´´½¨ÕßËù¿ª·¢£¬£¬£¬£¬£¬Òò¶ø¶þÕßÓµÓÐÒ»ÑùµÄÖ°ÄÜ£¬£¬£¬£¬£¬¼´´Óä¯ÀÀÆ÷¡¢FTP¡¢VPN¡¢µç×ÓÓʼþ¿Í»§¶ËÒÔ¼°¼ÓÃÜÇ®±ÒÇ®°üÇÔȡʹ´¦¡£¡£¡£¡£¡£¡£¡£¡£Õâ´Î×îз¢ÏֵĶñÒâ»î¶¯ÖØÒªÕë¶Ô³ÉÈËÍøÕ¾µÄ½Ó¼ûÕߣ¬£¬£¬£¬£¬Êܺ¦Õß´ó¶àÀ´×ÔÃÀ¹ú£¬£¬£¬£¬£¬Ò²ÓÐÀ´×Ô°Ä´óÀûÑǺÍÓ¢¹ú¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.malwarebytes.com/malwarebytes-news/2020/09/taurus-project-stealer-now-spreading-via-malvertising-campaign/
2.Pandora FMSÖдæÔÚ¶à¸ö·ì϶£¬£¬£¬£¬£¬¿Éµ¼ÖÂÔ¶³ÌÖ´Ðй¥»÷

Pandora FMSÖдæÔÚ¶à¸ö·ì϶£¬£¬£¬£¬£¬¿Éµ¼ÖÂÔ¶³ÌÖ´Ðй¥»÷¡£¡£¡£¡£¡£¡£¡£¡£Pandora FMSÊÇÒ»¸öÊ¢¿ªÔ´´úÂë½â¾ö¹æ»®£¬£¬£¬£¬£¬ËüÌṩÓÃÓÚ¼à¶½ÍøÂçÏνӡ¢ÀûÓ÷¨Ê½ÖÎÀí¡¢ÊÂÎñ¾¯±¨ÒÔ¼°Windows¡¢Linux¡¢UnixºÍAndroidϵͳµÄ´úÀíºÍÎÞ´úÀí¼à¶½µÄ½çÃæ¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÔÚPandora FMS°æ±¾742Öз¢ÏÖÁËËĸö·ì϶£¬£¬£¬£¬£¬±ðÀëΪpre-auth SQL×¢Èë·ì϶¡¢pre-auth PHAR·´ÐòÁл¯·ì϶¡¢ÌØÈ¨Óû§×îµÍµÄÔ¶³ÌÎļþÔ̺¬±àÂëÃýÎóÒÔ¼°¿çÕ¾µãÒªÇóαÔ죨CSRF£©·ì϶¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬pre-auth SQL×¢Èë·ì϶ÎÞÐèÈκνӼûȨÏÞ¼´¿ÉÔ¶³ÌÀûÓ㬣¬£¬£¬£¬²¢¶ÔÀûÓ÷¨Ê½ÆëÈ«ÊÕÊÜ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://portswigger.net/daily-swig/multiple-vulnerabilities-in-pandora-fms-could-trigger-remote-execution-attack
3.¹ú¼ÊÌØÉâ×éÅû¶¼äµýÈí¼þFinSpyÕë¶Ô°£¼°µÄ¹¥»÷»î¶¯

¹ú¼ÊÌØÉâ×éÖ¯¸æ·¢ÁËÕë¶Ô°£¼°Ãñ¼äÉç»á×éÖ¯µÄмල»î¶¯£¬£¬£¬£¬£¬¸Ã»î¶¯Ê¹ÓÃÁËÕë¶ÔLinuxºÍmacOSϵͳµÄ¼äµýÈí¼þFinSpy¡£¡£¡£¡£¡£¡£¡£¡£FinSpyÒ²³ÆFinFisher£¬£¬£¬£¬£¬ÓÉÒ»¼ÒµÂ¹ú¹«Ë¾¿ª·¢£¬£¬£¬£¬£¬ÓµÓжàÖÖ¼äµýÖ°ÄÜ£¬£¬£¬£¬£¬Ô̺¬°ÂÃØ´ò¿ªÍøÂçÉãÏñÍ·ºÍÂó¿Ë·ç¡¢ÔÚ¼üÅÌÉϼͼÊܺ¦Õß¼üÈëµÄËùÓÐÄÚÈÝ¡¢À¹½Øºô½ÐºÍÊý¾Ýй©¡£¡£¡£¡£¡£¡£¡£¡£ÆäÄܹ»Í¬Ê¹Øë¶Ô×ÀÃæºÍÒÆ¶¯²Ù×÷ϵͳ£¬£¬£¬£¬£¬Ô̺¬Android¡¢iOS¡¢Windows¡¢macOSºÍLinuxϵͳ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2020/09/finspy-malware-macos-linux.html
4.Next Caller°ä²¼COVID-19ÓйØÚ²Æ»î¶¯·ÖÎö»ã±¨

Next Caller°ä²¼COVID-19ÓйØÚ²Æ»î¶¯·ÖÎö»ã±¨£¬£¬£¬£¬£¬ÏÔʾÓëCOVIDÓйصÄÚ²ÆÐÐΪÒѶÔÃñ¶à²úÉúÁË¿í·ºÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£»ã±¨°µÊ¾£¬£¬£¬£¬£¬55£¥µÄÃÀ¹úÈËÒÔΪËûÃÇÒѳÉΪÓëCOVIDÓйصÄÚ²ÆÐÐΪµÄÖ¸±ê£¬£¬£¬£¬£¬Ö»¹ÜÈç´Ë£¬£¬£¬£¬£¬ÈÔÓÐ59£¥µÄÃÀ¹úÈ˳ÆËûÃÇûÓвÉÈ¡ÈÎºÎÆäËûÔ¤·À´ëÊ©À´±£»£»£»£»£»£»£»¤×Ô¼ºÃâÊܹ¥»÷¡£¡£¡£¡£¡£¡£¡£¡£ÓнüÈý·ÖÖ®Ò»£¨30%£©µÄÃÀ¹úÈ˸ü²»°²Ô⵽ڲƣ¬£¬£¬£¬£¬¶ø·ÇϰȾ²¡¶¾¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2020/09/28/covid-related-fraud-schemes/
5.ÌïÄÉÎ÷ÖݵijÇÊÐÔâµ½¹¥»÷£¬£¬£¬£¬£¬µ¼Öµ±¾ÖÄÚ²¿ÍøÂçÁÙʱ¹Ø¹Ø

ÌïÄÉÎ÷ÖݵijÇÊпËÀ¿Ë˹ά¶ûÔâµ½¹¥»÷£¬£¬£¬£¬£¬µ¼Öµ±¾ÖÄÚ²¿ÍøÂçÁÙʱ¹Ø¹Ø¡£¡£¡£¡£¡£¡£¡£¡£Æä½²»°ÈËMichelle Newell°µÊ¾£¬£¬£¬£¬£¬¸ÃÏØÉÏÖÜÎåÔâµ½ÁËÍøÂç¹¥»÷£¬£¬£¬£¬£¬µ¼ÖÂÆäµ±¾ÖÄÚ²¿ÍøÂçÔÚÖÜÄ©ÁÙʱ¹Ø¹Ø£¬£¬£¬£¬£¬Ö±ÖÁÖÜÈÕÒÀÈ»ÎÞ·¨½Ó¼û¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°¸ÃÏØÔÚÊÔͼ½â¾ö¸ÃÎÊÌâ²¢¸´ÔÔËÓª£¬£¬£¬£¬£¬ÒѾִÐÐÁËÏàÓ¦¹æ»®²¢·¢Õ¹Á˵÷²é¡£¡£¡£¡£¡£¡£¡£¡£911ÖÐÐÄÖ÷ÈÎHope Petersen°µÊ¾£¬£¬£¬£¬£¬¸ÃµØÓòµÄ911 CenterûÓÐÊܵ½µ±¾ÖÄÚÍø¹Ø¹ØµÄÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://clarksvillenow.com/local/data-security-incident-shuts-down-montgomery-countys-computer-network/
6.È«Ãñ½¡È«·þÎñҽԺϵͳϰȾRyuk£¬£¬£¬£¬£¬ÆäÈ«ÇòµÄ·ÖÔºÊܵ½Ó°Ïì

9ÔÂ26ÈÕÖÁ27ÈÕ£¬£¬£¬£¬£¬ÃÀ¹úµÄÈ«Ãñ½¡È«·þÎñÒ½Ôº£¨UHS£©ÏµÍ³Ï°È¾ÀÕË÷Èí¼þRyuk£¬£¬£¬£¬£¬ÆäÈ«ÇòµÄ·ÖÔºÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£¡£UHSÔÚÔÚÃÀ¹úºÍÓ¢¹úÖÎÀí×Å400¶à¼ÒÒ½ÔººÍ»¤ÀíÖÐÐÄ£¬£¬£¬£¬£¬¹ÌÈ»¹¥»÷µÄÕæÊµË®Æ½ÉдýÈ·¶¨£¬£¬£¬£¬£¬µ«ÊÇÔçÆÚ±¨Â·³ÆUHSµÄÕû¸öÍøÂç¶¼Êܵ½ÁËÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£ÃÀ¹ú±±¿¨ÂÞÀ³ÄÉÖÝ¡¢µÂ¿ËÈøË¹Öݵȶà¸öµØÓòµÄUHSÒ½ÔººÍ»¤ÀíÖÐÐÄÈ·ÈÏÆäITϵͳ³öÏÖÁËÎÊÌâ¡£¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬UHS½²»°È˲¢Î´»Ø¸´ÖÃÆÀÒªÇ󣬣¬£¬£¬£¬µ«Æäй©¸ÃÊÂÎñÊÇÓÉÃûΪRyukµÄÀÕË÷Èí¼þÔì³ÉµÄ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/uhs-hospital-network-hit-by-ransomware-attack/


¾©¹«Íø°²±¸11010802024551ºÅ