2019ÄêQ1´¹ÂÚ¹¥»÷Ç÷ÊÆ±¨¸æ£»£»Êý°ÙÍòInstagramÕË»§ÐÅϢй¶£»£»Ë¹ÀïÀ¼¿¨11¼Ò»ú¹¹µÄ¹ÙÍøÔâºÚ¿Í¹¥»÷

Ðû²¼Ê±¼ä 2019-05-21
1¡¢Ë¹ÀïÀ¼¿¨11¼Ò»ú¹¹µÄ¹ÙÍøÔâºÚ¿Í¹¥»÷

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾
 
¾ÝÍâý±¨µÀ£¬£¬£¬5ÔÂ18ÈÕ˹ÀïÀ¼¿¨ÖÁÉÙ11¼Ò»ú¹¹µÄ¹ÙÍø£¨.lkºÍ.comÍøÕ¾£©ÔâºÚ¿Í¹¥»÷£¬£¬£¬ÊÜÓ°ÏìµÄ»ú¹¹Ãûµ¥°üÀ¨¿ÆÍþÌØ´óʹ¹Ý¡¢Talawakelle²èÒ¶Ñо¿Ëù¡¢Rajarata´óѧµÈ¡£¡£Ë¹ÀïÀ¼¿¨SLCERT³ÆÃ»ÓÐÕþ¸®ÍøÕ¾£¨gov.lk£©Êܵ½Ó°Ïì¡£¡£SLCERTÕýÔÚÓëTechCERTºÍÍøÂçÇå¾²ÔËÓª²¿·ÖÏàÖúÒÔÊÓ²ìÏ¢Õù¾ö´ËÊ¡£¡£5ÔÂ18ÈÕºÍ19ÈÕÊÇ˹ÀïÀ¼¿¨ÍâµØµÄÕ½ÕùÓ¢ÐÛ¼ÍÄîÈÕ£¬£¬£¬¹¥»÷ÕßµÄÄ¿µÄ¿ÉÄÜÓë´ËÓйØ¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/websites-of-at-least-eleven-institutions-in-sri-lanka-hit-by-cyber-attacks-3d19a71f


2¡¢Ñо¿Ö°Ô±·¢Ã÷¶ñÒâÈí¼þWinntiµÄLinux±äÌå

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾
 
AlphabetÑо¿Ö°Ô±Chronicle·¢Ã÷¶ñÒâÈí¼þWinntiµÄLinux±äÌå¡£¡£ChronicleÌåÏָñäÌåÊÇÔÚÉϸöÔ°ݶúÖÆÒ©¹«Ë¾Ôâµ½¹¥»÷ºóÔÚÆäϵͳÉÏ·¢Ã÷µÄ¡£¡£¸Ã±äÌå¿É×·ËÝÖÁ2015Ä꣬£¬£¬ÆäʱËü±»ÓÃÓÚÕë¶ÔÔ½ÄÏÓÎÏ·¹«Ë¾µÄºÚ¿Í¹¥»÷ÖС£¡£¸Ã±äÌåÓÉÁ½²¿·Ö×é³É£ºÓÃÓÚÒþ²ØµÄrootkit×é¼þºÍÏÖʵµÄºóÃÅľÂí¡£¡£¸ÃLinux±äÌåÓëWindows°æ±¾µÄWinnti 2.0Ö®¼ä±£´æ´úÂëÏàËÆÐÔ£¬£¬£¬²¢ÇÒÓëC&CµÄͨѶЭÒéÒ²ÀàËÆ¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/security-researchers-discover-linux-version-of-winnti-malware/


3¡¢TrickbotбäÌ壬£¬£¬Ö÷Ҫͨ¹ýÀ¬»øÓʼþÈö²¥

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾
 
Ç÷ÊÆ¿Æ¼¼Ñо¿ÍŶӼì²âµ½TrickbotµÄÒ»¸öбäÌ壬£¬£¬¸Ã±äÌåͨ¹ýÀ¬»øÓʼþ¾ÙÐÐÈö²¥£¬£¬£¬ÆäʹÓõÄÁ´½ÓÀàËÆÓÚURL hxxps://google[.]dm:443/url?q=¡£¡£¸ÃURLÖеÄÅÌÎÊ×Ö·û´®²¿·Ö£¨url£¿£¿£¿£¿£¿q = £©Êǽ«Óû§Öض¨Ïòµ½µÄ¶ñÒâURL¡£¡£ÓÉÓÚÕâÊÇÒ»¸öGoogleÖØ¶¨ÏòÍøÖ·£¬£¬£¬Òò´Ë¿ÉÒÔÈÆ¹ý¶ÔÀ¬»øÓʼþµÄ¹ýÂ˺ÍÓÕÆ­²»ÖªÇéµÄÓû§¡£¡£Ò»µ©Ñ¬È¾×°±¸£¬£¬£¬¸Ã±äÌ廹»áʹÓÃMS17-010Îó²î¾ÙÐкáÏòÒÆ¶¯¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://blog.trendmicro.com/trendlabs-security-intelligence/trickbot-watch-arrival-via-redirection-url-in-spam/


4¡¢APWGÐû²¼2019ÄêQ1´¹ÂÚ¹¥»÷Ç÷ÊÆ±¨¸æ

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾
 
ƾ֤APWGµÄ2019ÄêQ1´¹ÂÚ¹¥»÷Ç÷ÊÆ±¨¸æ£¬£¬£¬Õë¶ÔSaaSºÍÍøÂçÓʼþЧÀ͵Ĵ¹ÂÚ¹¥»÷ÔöÌíÖÁËùÓд¹ÂÚ¹¥»÷µÄ36%£¬£¬£¬Ê×´ÎÁè¼ÝÁËÖ§¸¶ÏµÍ³Öֱ𣨱¾¼¾¶È¸ÃÖÖ±ðÔâµ½µÄ´¹ÂÚ¹¥»÷Õ¼27%£©¡£¡£APWG¸ß¼¶Ñо¿Ô±Greg AaronÌåÏÖ£¬£¬£¬´¹ÂÚÕß¶ÔSaaSÍøÕ¾µÇ¼ƾ֤µÄÐËȤÊÇÓÉÓÚËûÃÇ¿ÉÒÔͨ¹ýÓã²æÊ½´¹ÂÚ»ñµÃ²ÆÎñÊý¾ÝºÍСÎÒ˽¼ÒÐÅÏ¢¡£¡£2019ÄêQ1¼ì²âµ½µÄ´¹ÂÚÍøÕ¾×ÜÊýÊÇ180768£¬£¬£¬±È2018ÄêQ3µÄ151014ºÍQ4µÄ138328Òª¸ß¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.helpnetsecurity.com/2019/05/20/saas-webmail-phishing-increased/


5¡¢OGUsersÂÛ̳ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬11.3ÍòÓû§ÐÅϢй¶

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾
 
OGUsersÊÇÒ»¸öÒÔ³öÊÛµÁºÅÕË»§ÖøÃûµÄÍøÂç·¸·¨ÂÛ̳£¬£¬£¬Æ¾Ö¤KrebsOnSecurityµÄÐÂÎÅ£¬£¬£¬5ÔÂ12ÈÕOGUsersÔâºÚ¿ÍÈëÇÖ£¬£¬£¬Ô¼11.3ÍòÓû§µÄÓû§Ãû¡¢µç×ÓÓʼþµØµã¡¢¹þÏ£ÃÜÂ롢˽ÈËÐÂÎźÍIPµØµãй¶¡£¡£×î³õOGUsersµÄÖÎÀíÔ±ÒÔΪÕâÊÇÒ»´ÎÓ²Å̹ÊÕÏ£¬£¬£¬µ«ËæºóKrebsOnSecurity´ÓÁíÒ»¸öºÚ¿ÍÂÛ̳RaidForumsÉÏ»ñµÃÁ˱»µÁÊý¾Ý¿âµÄ¸±±¾¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/cybercrime-forum-ogusers-gets-hacked-attackers-steal-data-f067bcfc


6¡¢Î´ÉèÃÜÂëµÄÊý¾Ý¿âй¶Êý°ÙÍòInstagramÕË»§ÐÅÏ¢

ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾
 
ƾ֤TechCrunch±¨µÀ£¬£¬£¬Çå¾²Ñо¿Ô±Anurag SenÔÚAWSÉÏ·¢Ã÷Ò»¸öδÊܱ£»£»¤µÄÊý¾Ý¿â£¬£¬£¬¸ÃÊý¾Ý¿â°üÀ¨Êý°ÙÍòInstagramÕË»§µÄÏà¹ØÐÅÏ¢¡£¡£ÏÖÔÚ¸ÃÊý¾Ý¿âÒÑÓÐÁè¼Ý4900ÍòÌõ¼Í¼£¬£¬£¬µ«Êý¾ÝÁ¿ÈÔÔÚ°´Ð¡Ê±ÔöÌí¡£¡£¸ÃÊý¾Ý¿â°üÀ¨´ó×ÚÃûÈË¡¢ÃÀʳ²©Ö÷¡¢Æ·ÅÆÕË»§µÈÓ°ÏìÁ¦½Ï´óµÄInstagramÕË»§µÄÊý¾Ý£¬£¬£¬°üÀ¨Ð¡ÎÒ˽¼Ò×ÊÁÏÕÕÆ¬¡¢¹Ø×¢ÕßÊýÄ¿¡¢µØÀíλÖá¢Ë½ÈËÁªÏµÐÅÏ¢¡¢µç×ÓÓʼþµØµãºÍµç»°ºÅÂëµÈ¡£¡£¸ÃÊý¾Ý¿âÊôÓÚÓ¡¶ÈÉ罻ýÌåÓªÏú¹«Ë¾Chtrbox£¬£¬£¬ÏÖÔÚÉв»ÇåÎú¸Ã¹«Ë¾ÔõÑù»ñµÃÕâЩÊý¾Ý¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/85905/data-breach/instagram-data-leak.html