BlackBerry°ä²¼¹ØÓÚBAHAMUT×éÖ¯µÄ·ÖÎö»ã±¨£»×êÑÐÔ±·¢ÏÖ¶ñÒânpm°üÇÔÈ¡²¢ÔÚGitHub°ä²¼Óû§Êý¾Ý

°ä²¼¹¦·ò 2020-10-12
1.BlackBerry°ä²¼¹ØÓÚBAHAMUT×éÖ¯µÄ·ÖÎö»ã±¨


1.jpg


BlackBerry°ä²¼Á˹ØÓÚBAHAMUTÍøÂç¼äµý×éÖ¯µÄ·ÖÎö»ã±¨ £¬·¢ÏÔìä¶Ôµ±¾Ö¹ÙÔ±ºÍÖØÒªÐÐÒµÌáÒéÁË´óÁ¿¸ß¶È¸´ÔӵĹ¥»÷¡£×êÑÐÅú×¢ £¬¸ÃÍÅ»ïµÄ»î¶¯ÁìÓò±ÈÒÔǰÒÔΪµÄÒª¿í·ºµÃ¶à £¬Ô̺¬ÁËGoogle PlayÉ̵êºÍApp StoreÖеÄÊ®¼¸¸ö¶ñÒâÀûÓ÷¨Ê½¡£´Ë±í £¬BlackBerry»¹ÒÔΪ £¬BAHAMUTÄܹ»ÓëÖÁÉÙÒ»Ãû0day¿ª·¢ÈËÔ±½Ó´¥ £¬²¢ÀûÓÃ0day¹¥»÷¶à¸öÖ¸±ê £¬ÕâÔ¶Ô¶³¬³öÁË´óÎÞÊýÆäËûºÚ¿Í×éÖ¯µÄ¹¥»÷ˮƽ¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/cyber-espionage-bahamut-staggering/


2.×ôÖÎÑÇÖÝDHSй¶±¾µØ¶ùͯ¼°Æä¼Ò³¤µÄÃô¸ÐÐÅÏ¢


2.jpg


×ôÖÎÑÇÖÝÈËÃñ·þÎñ²¿£¨DHS£©ÉÏÖÜÎ尵ʾ £¬ÒòºÚ¿Í¹¥»÷µ¼Ö¶ùͯ¼°Æä¼Ò³¤µÄÃô¸ÐÐÅϢй¶¡£ÔÚ5ÔÂ3ÈÕÖÁ5ÔÂ15ÈÕÖ®¼ä £¬ºÚ¿Í»ñµÃÁ˶à¸öÔ±¹¤µç×ÓÓʼþÕÊ»§µÄ½Ó¼ûȨÏÞ £¬²¢ÇÒ±£ÁôÁ˺ܳ¤Ò»¶Î¹¦·ò¡£Õâ´Îй¶ÐÅÏ¢Ô̺¬¶ùͯ¼°¼ÒÍ¥³ÉÔ±µÄÈ«Ãû¡¢Óë¶ùͯµÄ¹ØÏµ¡¢¾ÓסµØÖ·¡¢DFCS°¸ÀýºÅ¡¢DFCS¼ø±ðºÅ¡¢µ®ÉúÈÕÆÚ¡¢´ºÇï¡¢ÁªÏµ´ÎÊý¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·¡¢Éç»á±£Ïպš¢Ò½ÁƲ¹Öú±êʶºÅ¡¢Ò½ÁƲ¹ÖúÒ½ÁƱ£ÏÕ±êʶºÅ¡¢Ò½ÁÆÌṩÕßÐÕÃûºÍÔ¤Ô¼ÈÕÆÚ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/children-and-parent-info-exposed-in-georgia-dhs-data-breach/


3.FriendemicÒòÊý¾Ý¿âÅäÖÃÃýÎóй¶½ü300Íò¿Í»§Êý¾Ý


3.jpg


2020Äê9ÔÂ12ÈÕ £¬Comparitech×êÑÐÈËÔ±·¢ÏÖÓªÏú¹«Ë¾FriendemicÒòÊý¾Ý¿âÅäÖÃÃýÎóй¶½ü300Íò¿Í»§Êý¾Ý¡£Õâ´Îй¶µÄÊý¾ÝÔ̺¬¿Í»§µÄÐÕÃû¡¢µç×ÓÓʼþIDºÍµç»°ºÅÂ롣Ŀǰ £¬FriendemicÒÑÈ·ÈϸÃÊÂÎñ £¬Ðû³Æ´ËÊý¾Ý¿âÊÇ´æµµ±¸·Ý £¬²¢ÓÚ9ÔÂ15ÈÕ¶ÔÆä½øÐÐÁ˱£»¤¡£µ«FriendemicÉÐδȷÇÐ×¢Ã÷Õâ´ÎÊý¾Ýй¶µÄÓ°ÏìÁìÓò £¬Ö»ÊǰµÊ¾Êý¾Ý²»ÊôÓÚÆäÆû³µ¾­ÏúÉ̿ͻ§¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/marketing-firm-friendemic-customer-records-exposed/


4.×êÑÐÔ±·¢ÏÖ¶ñÒânpm°üÇÔÈ¡²¢ÔÚGitHub°ä²¼Óû§Êý¾Ý


4.png


SonatypeµÄ×êÑÐÈËÔ±·¢ÏÖÁ½¸önpm°üelectornºÍloadyaml £¬ÔÚÊܺ¦ÕßµÄÉ豸¸ßµÍÔØÓû§Êý¾Ý²¢°ä²¼µ½GitHubÉÏ¡£×êÑÐÈËÔ±°µÊ¾ £¬ÕâÁ½ÖÖ°ü¶¼ÀûÓÃÁËTyposquatting¼¼Êõ £¬Õë¶ÔºÁÎÞ½äÐĵÄÓû§ £¬Í¨¹ýÔì³É½ÏÓ×µÄÓ¡Ë¢ÃýÎó £¬ÓÕʹËûÃÇÔÚÆä»·¾³ÖÐ×°ÖöñÒâÈí¼þ°ü £¬¶ø²»ÊÇ×î³õ³ïËãÏÂÔØµÄÈí¼þ°ü¡£¸Ã°ü½«ÇÔÈ¡Êܺ¦ÕßµÄÊý¾Ý £¬Ô̺¬IPµØÖ·¡¢µØÀíµØÎ»¡¢Éè±¸Ö¸ÎÆ¡¢²¢½«ÆäÈ«Êý°ä²¼ÔÚGitHubÒ³ÃæÉÏ¡£


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2020/10/11/malicious-npm-packages-published-users-data-on-github-page/


5.ÂíÈøÖîÈûÖݵÄÑ§ÇøÔâµ½¹¥»÷µ¼ÖÂѧÌÃÁÙʱ¹Ø¹Ø


5.png


ÂíÈøÖîÈûÖݵÄ˹ÆÕÁַƶûµÂ¹«Á¢Ñ§ÇøÔâµ½ÀÕË÷Èí¼þ¹¥»÷ £¬µ¼ÖÂѧÌÃÁÙʱ¹Ø¹Ø¡£ÓÉÓÚCOVID-19Ô­Òò £¬Ä¿Ç°¸ÃÑ§ÇøÒÔÔ¶³Ì½ø½¨Ä£Ê½ÊڿΡ£¸ÃÑ§ÇøÓÚ2020Äê10ÔÂ8ÈÕÔÚFacebook¡¢TwitterºÍ¼Ò³¤µç»°Öа䷢ £¬ÓÉÓÚÍøÂçÎÊÌâ¹Ø¹ØÁËѧÌá£Ëæºó £¬Êг¤Domenic J. SarnoºÍ¶½Ñ§Daniel WarwickҲ֤ʵÁËÕâ´ÎÍøÂç¹¥»÷ £¬²¢°ä·¢ÔÝÍ£Ô¶³Ì½ø½¨¡£Ä¿Ç°¸ÃÑ§ÇøÉв»È·¶¨¸´Ô­¹¦·ò £¬¾ßÌåÈ¡¾öÓÚÀÕË÷Èí¼þ¹¥»÷¼ÓÃܵÄÉ豸ÊýÁ¿ÒÔ¼°¸´Ô­ËüÃÇËùÐèµÄ¹¦·ò¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/massachusetts-school-district-shut-down-by-ransomware-attack/


6.ÒѼÓÃܵÄTylerÏòRansomExxÖ§¸¶Êê½ðÀ´¸´Ô­¼ÓÃÜÊý¾Ý


6.png


Tyler¼¼Êõ¹«Ë¾ÒÑÏòRansomExxÖ§¸¶ÁËÊê½ð £¬ÒÔ¸´Ô­ÔÚ×î½üµÄÀÕË÷Èí¼þ¹¥»÷Öб»¼ÓÃܵÄÎļþ¡£9ÔÂ23ÈÕ £¬TylerÔâµ½ÁËRansomExxÀÕË÷Èí¼þ¹¥»÷ £¬Ö®ºóÆäÁ¢¼´¶Ï¿ªÁ˲¿ÃÅÍøÂç £¬ÒÔ¶ôÔìÀÕË÷Èí¼þµÄ´«²¼²¢ÏÞ¶ÈÆä¿Í»§µÄ½Ó¼ûÁìÓò £¬Tyler°µÊ¾ÆäÊܵ½ÁËÑϳÁµÄÓ°Ïì²¢Ô¤¼Æ½«±ØÒª30ÌìÄÜÁ¦ÆëÈ«¸´Ô­ÔËÓª¡£ÐÂÎÅÈËÊ¿³Æ £¬Ä¿Ç°TylerÒÑÖ§¸¶Êê½ð £¬µ«ÊÇÉв»Ã÷ÏÔ¾ßÌåÓöÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/tyler-technologies-paid-ransomware-gang-for-decryption-key/