2019Äê¼ÓÃÜÇ®±Ò·¸×ï»î¶¯ÒÑÔì³É44ÒÚÃÀÔªËðʧ£»Android·ì϶StrandHogg¿É¼Ù×°³ÉËÁÒâÀûÓÃ

°ä²¼¹¦·ò 2019-12-03

1.2019Äê¼ÓÃÜÇ®±Ò·¸×ï»î¶¯ÒÑÔì³É44ÒÚÃÀÔªËðʧ


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ƾ¾ÝCipherTraceµÄ»ã±¨£¬ÔÚ¾­Àú¹ýÁ½ÄêµÄ¶¥·åÆÚºó£¬Óë¼ÓÃÜÇ®±ÒÓйصÄÍøÂç·¸×ï»î¶¯£¨ÀýÈçÂòÂôËù±»ºÚ¿ÍÈëÇÖ¡¢Í˳öȦÌ׵ȣ©³öÏÖÁË´ó·ù½µÂ䣬Ȼ¶øÔì³ÉµÄËðʧȴ³öÏÖÁËÔö³¤ ¡£ÔÚ2019Äêǰ9¸öÔ£¬ÒÔ¼ÓÃÜÇ®±ÒΪÖ÷µÄÊý×Ö·¸×ïÔì³ÉÁ¶¯ß´ï44ÒÚÃÀÔªµÄËðʧ£¬ÓëÖ®Ïà±È2018 ÄêÕûÄêÓë¼ÓÃÜÇ®±ÒÓйصķ¸×ïËðʧ×ܶîΪ17ÒÚÃÀÔª£¬ÕâÒâζ׎ñÄêǰ¾Å¸öÔµÄÊý¾Ý±ÈÈ¥ÄêÕûÄêÔö³¤ÁË150% ¡£¾Ý·ÖÎö£¬PlusTokenºÍQuadrigaCXÁ½Æð¼ÓÃÜÇ®±Òڲƭ°¸Êǵ¼Ö½ñÄêËðʧ¼±¾çÉÏÉýµÄÖØÒªÔ­Òò ¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2019/12/02/crypto-crimes/


2.Å·ÖÞÐ̾¯×éÖ¯¹Ø¹Ø³¬¹ý30500¸öµÁ°æÍøÕ¾


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Å·ÖÞÐ̾¯×éÖ¯°ä·¢ÒÑÔÚÒ»ÏîºÍÃÀ¹ú·¨ÂÉ»ú¹¹ºÏ×÷µÄÈ«Çò½áºÏÐж¯ÖйعØÁË30506¸öµÁ°æÍøÕ¾ ¡£ÕâЩÓòÃû±»ÓÃÓÚÏúÊÛ¸÷ÀàµÁ°æ²úÆ·ºÍ·þÎñ£¬Ô̺¬µ«²»ÏÞÓÚµÁ°æµÄµçÓ°¡¢µçÊÓ½ÚÄ¿¡¢ÒôÀÖ¡¢Èí¼þºÍ¼ÙÒ©¡¢¼ÙðµÄµç×Ó²úÆ·µÈ ¡£Å·ÖÞÐ̾¯×éÖ¯»¹°µÊ¾£¬ÔÚÕâÏîÐж¯Öл¹¿ÛÁôÁË3Ãû·¸×ïÏÓÒÉÈË£¬²¢½É»ñÁË26000¼þÉÝ³ÞÆ·£¨ÏãË®¡¢Ò·þµÈ£©¡¢363Éý¾Æ¾«ÒûÁϺʹóÁ¿Ó²¼þÉ豸 ¡£ËûÃÇ»¹ÔÚ¶à¸öÒøÐÐÕË»§ºÍÔÚÏßÖ§¸¶Æ½Ì¨Öмø±ð²¢¶³½áÁ˳¬¹ý15ÍòÅ·Ôª ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/over-30-500-online-piracy-sites-shut-down-in-global-operation/


3.ÐÂÎ÷À¼Ç¹Ö§»Ø¹º´òËã¹ÙÍøÐ¹Â¶3.7Íò³ÖǹÕßÒþÖÔÐÅÏ¢


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ÐÂÎ÷À¼µ±¾ÖµÄǹ֧»Ø¹º´òËã¹ÙÍøÒâ±íй¶ÁË37000¶àÃû³ÖǹÕßµÄÓ×ÎÒÐÅÏ¢£¬Ô̺¬ËûÃÇµÄÆëÈ«ÁªÏµ·½Ê½¡¢Ç¹Ö§Ðí¿ÉÖ¤±àºÅÒÔ¼°ÒøÐÐÕË»§ÐÅÏ¢µÈ ¡£³Ö֤ǹ֧ËùÓÐÕßÀíÊ»ᣨCOLFO£©Åû¶ÁËÕâÒ»ÊÂÎñ£¬¾¯·½Ëæºó°ä·¢ÉêÃ÷³ÆÒѾ­Í¨´ï¸ÃÎÊÌâ²¢¹Ø¹ØÁËÍøÕ¾ ¡£COLFO°µÊ¾ÔÚ¾¯·½¹Ø¹ØÖ®Ç°Óû§×î¶àÄܹ»µÇ¼¸Ãϵͳ3¸öÓ×ʱ£¬Ä¿Ç°Éв»Ã÷ÏÔÕâЩÐÅϢ¶³öÁ˶೤¹¦·ò ¡£


Ô­ÎÄÁ´½Ó£º

https://www.computerworld.com/article/3482005/buyback-website-reveals-details-of-37-000-gun-owners.html


4.´¹µöÍøÕ¾ÀûÓÃÐéαSteamÔùÆ·ÇÔÈ¡Óû§Í´´¦


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


°²È«×êÑÐÈËÔ±nullcookies·¢ÏÖÒ»¸öÀûÓÃÐéαSteamÔùÆ·ÇÔÈ¡Óû§Í´´¦µÄ´¹µöÍøÕ¾£¬²¢ÔÚTwitterÉϰ䲼ÁËÖÒ¸æ ¡£¸ÃÍøÕ¾ÖØÒªÐû´«Ò»¸öÐéαµÄ¡°3ÍòÃÀÔªÔùÆ·¡±µÄ´ÙÏú»î¶¯£¬ÆäÖл¹Ô̺¬Ãâ·ÑµÄCSGOƤ·ôÔùÆ· ¡£¸Ã´¹µöÒ³ÃæµÄ×ó²à»¹ÓÐÒ»¸öαÔìµÄʵʱ̸ÌìÆÁÄ»£¬µ«ÏÖʵÉÏÏÔʾµÄ̸ÌìÐÅÏ¢Ò²ÊÇͨ¹ýJavaScript¾ç±¾Î±ÔìµÄ ¡£µ±Óû§µã»÷¡°Í¨¹ýSteamµÇ¼¡±°´Å¥ºó£¬½«±»ÒªÇóÔÚÐéαµÄµÇÂ¼Ò³ÃæÉÏÊäÈëÍ´´¦ ¡£ºÃÐÂÎÅÊÇÓÉÓÚ¸ÃÍøÕ¾±»ÍйÜÔÚCloudflareÉÏ£¬Òò¶ø³¢ÊÔ½Ó¼û¸ÃÒ³ÃæµÄÓû§½«»áÏÔʾ¿ÉÒÉÕ¾µãµÄÖÒ¸æ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/fake-steam-skin-giveaway-site-steals-your-login-credentials/


5.¼äµýÈí¼þCallerSpyÕë¶ÔÐÔ¹¥»÷µÄ·ÖÎö»ã±¨


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Ç÷Ïò¿Æ¼¼°ä²¼ÓйØÒƶ¯¼äµýÈí¼þCallerSpyµÄ·ÖÎö»ã±¨ ¡£¸Ã¼äµýÈí¼þÖØÒª¼Ù×°³É̸ÌìÀûÓ㬵«²¢²»¾ß±¸Ì¸ÌìÖ°ÄÜ£¬¶øÊǾ߱¸¶àÖÖ¼äµýÐÐΪ£¬Ô̺¬ÉèÖöà¸ö´òË㹤×÷£¬ÍøÂçÉ豸ÉϵÄͨ»°¼Í¼¡¢¶ÌÐÅ¡¢ÁªÏµÈ˺ÍÎļþÐÅÏ¢£»´ÓC£¦C·þÎñÆ÷½Ó¹ÜºÅÁ½ØÆÁ²¢·¢Ë͵½·þÎñÆ÷µÈ ¡£×êÑÐÈËÔ±±ðÀëÔÚ5ÔºÍ10Ô¹۲쵽¸Ã¶ñÒâÈí¼þ¼Ò×åµÄÕë¶ÔÐÔ¹¥»÷£¬µ«Æä¹¥»÷Ö¸±êÉÐδÃ÷È· ¡£»ã±¨ÖÐÁгöÁ˾ßÌåµÄIoCÖ¸±ê ¡£


Ô­ÎÄÁ´½Ó£º

https://blog.trendmicro.com/trendlabs-security-intelligence/mobile-cyberespionage-campaign-distributed-through-callerspy-mounts-initial-phase-of-a-targeted-attack/


6.Android·ì϶StrandHogg¿É¼Ù×°³ÉËÁÒâÀûÓÃ


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Promon°²È«×êÑÐÈËÔ±·¢ÏÖÒ»¸öеÄAndroid·ì϶StrandHogg£¬¸Ã·ì϶ÔÊÐí¶ñÒâÀûÓüÙ×°³ÉËÁÒâºÏ·¨ÀûÓà ¡£¸Ã·ì϶ÀûÓÃÁËAndroidµÄ¶à¹¤×÷´¦ÖÃÖ°ÄÜ£¬µ±Óû§µã»÷Ò»¸öÕý³£ÀûÓõÄͼ±êʱ£¬¶ñÒâÀûÓÃÄܹ»ÀûÓø÷ì϶À¹½ØÖ¸Áî²¢ÏòÓû§ÏÔʾһ¸öÐéαµÄ½çÃæ£¬´Ó¶øÓÕµ¼Óû§ÊÚÓè¸÷ÀàȨÏÞ ¡£×êÑÐÈËÔ±ÒѾ­·¢ÏÖÁË36¸öÔÚ»ý¼«ÀûÓô˷ì϶µÄ¶ñÒâÀûÓã¬Ô̺¬ÒøÐÐľÂíBankBot ¡£×êÑÐÈËÔ±³Æ¸Ã·ì϶µÄÓ°ÏìÁìÓò¼«¶È´ó£¬ÓÉÓÚĬÈÏÇé¿öÏ´óÎÞÊýÀûÓö¼Ò×Êܹ¥»÷£¬²¢ÇÒĿǰûÓп¿µÃסµÄ²½ÖèÀ´Ì½²â»ò×èÖ¹ÕâÖÖ¹¥»÷ ¡£¹È¸èÉÐδÔÚÖ°ºÎ°æ±¾µÄAndroidÉϽ¨¸´´ËÎÊÌâ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/actively-exploited-strandhogg-vulnerability-affects-android-os/