Pwn2OwnºÚ¿Í´óÈüÊ×´ÎÉæ¼°¹¤Òµ¿ØÖÆÏµÍ³£»£»£»£»£»Î¢Èí³Æ2020Äê°ÂÔ˻Ὣ¿ÉÄܳÉΪAPT28µÄ¹¥»÷¹¤¾ß

Ðû²¼Ê±¼ä 2019-10-30
1¡¢Pwn2OwnºÚ¿Í´óÈüÊ×´ÎÉæ¼°¹¤Òµ¿ØÖÆÏµÍ³

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø

Pwn2OwnºÚ¿Í´óÈü½«ÌṩÁè¼Ý25ÍòÃÀÔªµÄ½±Àø£¬ £¬£¬£¬£¬£¬ÒÔÃãÀøÍÚ¾òICSºÍÏà¹ØÐ­ÒéÎó²î ¡£¡£¡£¸Ã»î¶¯½«ÓÚÃ÷Ä꣨1ÔÂ21ÈÕÖÁ1ÔÂ23ÈÕ£©ÔÚÂõ°¢ÃÜS4¾Û»áʱ´ú¾ÙÐÐ ¡£¡£¡£¡°ºÍÆäËû¾ºÈüÒ»Ñù£¬ £¬£¬£¬£¬£¬Pwn2OwnÊÔͼͨ¹ýÕ¹ÏÖÎó²î²¢½«Ñо¿Ð§¹ûÌṩӦ¹©Ó¦ÉÌÀ´Ç¿»¯ÕâЩƽ̨¡±£¬ £¬£¬£¬£¬£¬Pwn2Own×éÖ¯Õß¡¢ZDIÌᳫÈËBrian GorencÔÚÖÜÒ»µÄÌû×ÓÖÐÌåÏÖ£¬ £¬£¬£¬£¬£¬¡°Pwn2OwnµÄÄ¿µÄʼÖÕÊÇÔÚ¹¥»÷Õ߯ð¾¢Ê¹ÓÃ֮ǰÐÞ¸´ÕâЩÎó²î¡± ¡£¡£¡£Pwn2Own MiamiΪÎå¸öICSÀà±ðµÄÎó²îÌṩÁËÖÖÖÖ½±Àø£¬ £¬£¬£¬£¬£¬°üÀ¨¿ØÖÆÐ§ÀÍÆ÷½â¾ö¼Æ»®¡¢OPCЧÀÍÆ÷¡¢DNP3ͨѶЭÒé¡¢HMI/²Ù×÷Ô±Õ¾ºÍ¹¤³ÌÊÂÇéÕ¾Èí¼þ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/pwn2own-expands-industrial-control-systems/149594/

2¡¢Ó¡¶È130ÍòÕÅÒøÐп¨ÐÅÏ¢ÔÚJoker's StashÉϳöÊÛ

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


Group-IBÑо¿Ö°Ô±·¢Ã÷Áè¼Ý130ÍòÕÅÓ¡¶ÈÒøÐп¨ÐÅÏ¢ÔÚJoker's StashÉϳöÊÛ ¡£¡£¡£Group-IBÌåÏÖÕâЩ¿¨µÄ×î¸ßÊÛ¼ÛΪÿÕÅ¿¨100ÃÀÔª£¬ £¬£¬£¬£¬£¬ÕâÒâζ×ÅÆä×ܼÛÖµÁè¼Ý1.3ÒÚÃÀÔª ¡£¡£¡£ÓÉÓÚÕâЩÊý¾ÝÊÇÔÚ¼¸Ð¡Ê±Ç°Ðû²¼µÄ£¬ £¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÉÐûÓÐʱ¼äÆÊÎöºÍÊÓ²ì¿ÉÄܵÄй¿à´Ô´ ¡£¡£¡£ÆðÔ´ÆÊÎöÅú×¢ÕâЩÐÅÏ¢¿ÉÄÜÊÇͨ¹ý×°ÖÃÔÚATM»òPoSϵͳÉÏµÄÆ²ÔüÆ÷ÇÔÈ¡µÄ ¡£¡£¡£±ðµÄ£¬ £¬£¬£¬£¬£¬´Ó·¢¿¨ÒøÐÐÀ´¿´£¬ £¬£¬£¬£¬£¬±»ÇÔ¿¨µÄÖÖÀà·±¶à£¬ £¬£¬£¬£¬£¬À´×ÔÓÚ¶à¼ÒÒøÐУ¬ £¬£¬£¬£¬£¬Õâɨ³ýÁ˵¥ÖðÒ»¼ÒÒøÐÐϵͳ±»ÈëÇֵĿÉÄÜÐÔ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/details-for-1-3-million-indian-payment-cards-put-up-for-sale-on-jokers-stash/

3¡¢·¨¹úʱÉÐÆ·ÅÆSixth June¹ÙÍøÔâMageCart¹¥»÷

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø

·¨¹úʱÉÐÆ·ÅÆSixth June¹ÙÍøÔâMageCart¶ñÒâ¾ç±¾Ñ¬È¾£¬ £¬£¬£¬£¬£¬Çå¾²Ñо¿Ö°Ô±Jenkins·¢Ã÷ÁËÕâÒ»ÊÂÎñ²¢ÓÚÉÏÖÜ֪ͨÁ˸ù«Ë¾£¬ £¬£¬£¬£¬£¬µ«ÉÐδ»ñµÃ»Ø¸´ ¡£¡£¡£×èÖ¹ÏÖÔڸöñÒâ´úÂëÈÔ±£´æÓÚÍøÕ¾µÄÖ§¸¶Ò³ÃæÉÏ ¡£¡£¡£Sixth JuneÔÚÅ·ÖÞºÜÊܽӴý£¬ £¬£¬£¬£¬£¬9ÔÂ·ÝÆäÍøÕ¾µÄ»á¼ûÁ¿Ô¼Îª7ÍòÈË´Î ¡£¡£¡£ÆäÍøÕ¾ÒÀÀµÓÚµç×ÓÉÌÎñƽ̨Magento£¬ £¬£¬£¬£¬£¬¹¥»÷Õß×¢²áÁËÒ»¸öαװ³ÉMagento¹Ù·½ÓòÃûµÄ¼ÙÓòÃûmogento[.]infoÀ´Òþ²Ø×Ô¼º ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/sixth-june-fashion-site-hacked-to-steal-credit-cards/

4¡¢ÃÀ¹ú¿ì²ÍÁ¬ËøµêKrystalÐû²¼Í¨Öª³ÆÆä¿Í»§ÐÅϢй¶


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ÃÀ¹ú¿ì²ÍÁ¬ËøµêKrystalÌåÏÖÆäÖ§¸¶´¦Öóͷ£ÏµÍ³ÔâÓöÇå¾²ÊÂÎñ£¬ £¬£¬£¬£¬£¬²¿·Ö²ÍÌüÊܵ½Ó°Ïì ¡£¡£¡£¸ÃÊÂÎñ±¬·¢ÔÚ2019Äê7ÔÂÖÁ9ÔÂÖ®¼ä£¬ £¬£¬£¬£¬£¬ÏÖÔÚÉв»ÖªµÀÊÜ´ËÇå¾²ÊÂÎñÓ°ÏìµÄ¿Í»§ÊýÄ¿ÒÔ¼°Ì»Â¶µÄ¸¶¿îÐÅÏ¢ÀàÐÍ£¬ £¬£¬£¬£¬£¬Ò²²»ÇåÎúÇå¾²ÊÂÎñ±³ºóµÄÔµ¹ÊÔ­ÓÉÊÇÖ§¸¶ÏµÍ³Êý¾Ý¿â̻¶/δÊÚȨ»á¼ûÕÕ¾ÉPoS¶ñÒâÈí¼þ¹¥»÷µÈ ¡£¡£¡£KrystalÌåÏÖÕýÔÚÆð¾¢È·¶¨ÄÄЩ²ÍÌüÊÜÓ°Ïì¼°ÏêϸµÄËùÔÚºÍÈÕÆÚ£¬ £¬£¬£¬£¬£¬Ëü»¹ÌåÏÖÒѾ­È·ÈÏÔ¼ÓÐÈý·ÖÖ®Ò»µÄ²ÍÌüûÓÐÊܵ½Ó°Ïì ¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/us-food-chain-alerts-customers-of-payment-card-incident/

5¡¢Î¢Èí³Æ2020Äê°ÂÔ˻Ὣ¿ÉÄܳÉΪAPT28µÄ¹¥»÷¹¤¾ß


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


΢ÈíÖÒÑÔ³Æ2020Äê¶«¾©°ÂÔË»á¿ÉÄܳÉΪ¶íÂÞ˹ºÚ¿Í×éÖ¯APT28£¨ÓÖÃû»¨Ê½ÐÜ£©µÄ¹¥»÷Ä¿µÄ ¡£¡£¡£Î¢ÈíÍþвÇ鱨ÖÐÐÄÖ¸³ö£¬ £¬£¬£¬£¬£¬ËûÃÇ×·×ÙÁËÕë¶ÔÌåÓýÖ÷¹Ü²¿·ÖºÍ·´Ð˷ܼÁ»ú¹¹µÄ´óÐÍÍøÂç¹¥»÷£¬ £¬£¬£¬£¬£¬×Ô2019Äê9ÔÂ16ÈÕÒÔÀ´À´×ÔÈý´óÖÞµÄ16¸ö¹ú¼ÒºÍ¹ú¼Ê»ú¹¹ÒѾ­³ÉΪ¹¥»÷Ä¿µÄ ¡£¡£¡£Õâ²»ÊÇ»¨Ê½ÐܵÚÒ»´ÎÕë¶Ô·´Ð˷ܼÁ»ú¹¹£¬ £¬£¬£¬£¬£¬×Ô´ÓWADAÔÚ2016ÄêÀïÔ¼°ÂÔË»áÉÏեȡ¶íÂÞ˹ÔË·¢¶¯²ÎÈüºó£¬ £¬£¬£¬£¬£¬¸Ã×éÖ¯Ò»Ö±Õë¶Ô¹ú¼Ê·´Ð˷ܼÁ»ú¹¹ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/10/cyber-attack-tokyo-olympics.html

6¡¢Ð¶ñÒâÈí¼þxHelperÒÑѬȾÁè¼Ý4.5Íǫ̀Android×°±¸

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


жñÒâÈí¼þxHelper×îÔçÓÚ3Ô±»·¢Ã÷£¬ £¬£¬£¬£¬£¬8Ô·ÝxHelperÖð½¥Éú³¤µ½Ñ¬È¾ÁËÁè¼Ý3.2Íǫ̀װ±¸£¬ £¬£¬£¬£¬£¬µ½10Ô·ÝÕâÒ»Êý×ÖÒѾ­ÔöÌíµ½4.5Íǫ̀ ¡£¡£¡£ÕâÅú×¢¸Ã¶ñÒâÈí¼þ´¦ÓÚÇåÎúµÄÉÏÉýÇ÷ÊÆ£¬ £¬£¬£¬£¬£¬Æ¾Ö¤ÈüÃÅÌú¿ËµÄÊý¾Ý£¬ £¬£¬£¬£¬£¬xHelperƽ¾ùÌìÌìѬȾ131ÃûÐÂÊܺ¦Õߣ¬ £¬£¬£¬£¬£¬Ã¿ÔÂÔ¼ÓÐ2400ÃûÐÂÊܺ¦Õß ¡£¡£¡£ÕâЩѬȾ´ó¶à±¬·¢ÔÚÓ¡¶È¡¢ÃÀ¹úºÍ¶íÂÞ˹ ¡£¡£¡£Æ¾Ö¤MalwarebytesµÄ˵·¨£¬ £¬£¬£¬£¬£¬xHelperÖ÷Ҫͨ¹ýµÚÈý·½Ó¦ÓÃÊÐËÁ×°Ö㬠£¬£¬£¬£¬£¬Ö÷ÒªÓÃÓÚÏÔʾÇÖÈëÐÔµ¯³ö¹ã¸æºÍ֪ͨÀ¬»øÓʼþ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/new-unremovable-xhelper-malware-has-infected-45000-android-devices/