ºÚ¿ÍÉù³ÆÒÑÇÔÈ¡µçÐŹ«Ë¾T-MobileÔ¼1ÒÚ¿Í»§µÄÐÅÏ¢£ºFortbridgeÅû¶cPanelºÍWHMÖжà¸öÄþ¾²Â©¶´µÄϸ½Ú

Ðû²¼Ê±¼ä 2021-08-16

T-Mobile.jpg1.jpg


  ¹¥»÷ÕßÉù³ÆÔÚÁ½ÖÜǰÈëÇÖÁËT-MobileµÄÓÃÓÚÉú²úºÍ¿ª·¢µÄ·þÎñÆ÷£¬ÒÔ¼°Ò»¸ö°üÂÞÁ˿ͻ§ÐÅÏ¢µÄOracleÊý¾Ý¿â·þÎñÆ÷¡£´Ë´Îй¶ÁËT-MobileµÄ1ÒÚ¸ö¿Í»§Ô¼106GBµÄÊý¾Ý£¬°üÂÞIMSI¡¢IMEI¡¢µç»°ºÅÂë¡¢¿Í»§ÐÕÃû¡¢Äþ¾²PIN¡¢Éç»áÄþ¾²ºÅÂë¡¢¼ÝÕÕºÅÂëºÍ³öÉúÈÕÆÚµÈÐÅÏ¢¡£ÍþвÇ鱨¹«Ë¾Hudson RockÌåÏÖ£¬´Ë´ÎºÚ¿ÍµÄ¹¥»÷ÐÐΪ¿ÉÄÜÊÇΪÁËÆÆ»µÃÀ¹úµÄ»ù´¡ÉèÊ©£¬Ö¼ÔÚÅê»÷ÃÀ¹úÔøÓÚ2019Äê°ó¼Ü²¢ÕÛÄ¥ÁËJohn Erin Binns(CIA Raven-1)¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hacker-claims-to-steal-data-of-100-million-t-mobile-customers/

FortbridgeÅû¶cPanelºÍWHMÖжà¸öÄþ¾²Â©¶´µÄϸ½Ú.png


FortbridgeÅû¶cPanelºÍWHMÖжà¸öÄþ¾²Â©¶´µÄϸ½Ú


  FortbridgeµÄÑо¿ÈËÔ±Åû¶ÁËÍøÂçÍÐ¹ÜÆ½Ì¨cPanelºÍWHMÖжà¸öÄþ¾²Â©¶´µÄϸ½Ú¡£Ñо¿ÈËÔ±ÔÚÕë¶ÔcPanelºÍWHMµÄºÚºÐÉøÍ¸²âÊÔÖз¢ÏÖÁËÕâЩ©¶´£¬½áºÏʹÓÿÉÔ¶³ÌÖ´ÐдúÂë¡£ÆäÖÐÒ»¸ö©¶´Îª¾­ÏúÉÌÕÊ»§ÖеÄXMLÍⲿʵÌå(XXE)©¶´£¬ÊÇÓÉÓÚ¸ÃÕÊ»§ÓµÓÐÒÔXML»òXLF¸ñʽ±à¼­ºÍÌí¼ÓÇøÓòÉèÖÃȨÏÞµ¼ÖµÄ¡£´ËÍ⣬Ñо¿ÈËÔ±»¹Åû¶ÁËÒ»¸ö´æ´¢ÐÍXSS©¶´ºÍCSRF©¶´¡£µ«Ä¿Ç°£¬¹©Ó¦ÉÌÖ»ÐÞ¸´ÁËXXE©¶´£¬²¢¾Ü¾øÐÞ¸´ÆäËü©¶´¡£


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2021/08/14/numerous-vulnerabilities-spotted-in-cpanel-and-whm-web-hosting-platform/


Unit42½üÆÚ·¢ÏÖ´óÁ¿ÈƹýCAPTCHA¼ì²âµÄµöÓã»î¶¯.png


Unit42½üÆÚ·¢ÏÖ´óÁ¿ÈƹýCAPTCHA¼ì²âµÄµöÓã»î¶¯


  Unit42µÄÑо¿ÈËÔ±½üÆÚ·¢ÏÖÁË´óÁ¿ÈƹýCAPTCHA¼ì²âµÄµöÓã»î¶¯¡£¹¥»÷Õß½«µöÓãÒ³ÃæÒþ²ØÔÚCAPTCHAÖ®ºó¿É·ÀÖ¹Äþ¾²ÅÀ³æ¼ì²âµ½¶ñÒâÄÚÈÝ£¬²¢¿ÉÒÔʹµöÓãµÇÂ¼Ò³Ãæ¿´ÆðÀ´Ô½·¢ºÏ·¨¡£ËäÈ»Õâ²¢·Ç×îеļ¼Êõ£¬µ«ÔÚ½üÆÚÔ½À´Ô½Á÷ÐУºÉϸöÔÂUnit42ÔÚ4088¸ö¸¶·ÑµÄÓòÖз¢ÏÖÁË7572¸ö½ÓÄÉÁË»ìÏýÒªÁìµÄ¶ñÒâURL£¬Ò²¾ÍÊÇ˵ƽ¾ùÿÌìÓÐ529¸öʹÓÃÁËCAPTCHAµÄ¶ñÒâ URL¡£³ýÁ˵öÓã¹¥»÷Ö®Í⣬ÀûÓÃCAPTCHAµÄÕ©Æ­»î¶¯Ò²ÔÚÔö¼Ó¡£


Ô­ÎÄÁ´½Ó£º

https://unit42.paloaltonetworks.com/captcha-protected-phishing/


Ñо¿ÍŶӷ¢ÏÖAggahÕë¶ÔÑÇÖÞÖÆÔìÒµµÄÓã²æÊ½µöÓã»î¶¯.png


Ñо¿ÍŶӷ¢ÏÖAggahÕë¶ÔÑÇÖÞÖÆÔìÒµµÄÓã²æÊ½µöÓã»î¶¯


  AnomaliµÄÑо¿ÍŶӷ¢ÏÖÁËʼÓÚ2021Äê7ÔÂÉÏÑ®µÄÓã²æÊ½ÍøÂçµöÓã»î¶¯£¬Õë¶ÔÕû¸öÑÇÖÞµÄÖÆÔìÒµ¡£Aggah×îÔçÓÚ2019Äê3ÔÂÓÉUnit 42µÄÑо¿ÈËÔ±·¢ÏÖ£¬Ö÷ÒªÕë¶Ô°¢À­²®ÁªºÏÇõ³¤¹ú(UAE)µÄ×éÖ¯¡£´Ë´Î»î¶¯ÖУ¬¹¥»÷Õßαװ³ÉÓ¢¹úFoodHub.co.uk·¢Ë͵öÓãÓʼþ£¬ÓÕʹÓû§µÇ¼Òѱ»ÈëÇÖµÄmail.hoteloscar.in/imagesÍøÕ¾£¬²¢·Ö·¢Warzone RAT¡£¾Ý·ÖÎö£¬Aggah×îÐµĹ¥»÷Ä¿±ê°üÂÞÖйų́ÍåµÄÖÆÔ칫˾Fon-starºÍ¹¤³Ì¹«Ë¾FomoTech£¬ÒÔ¼°º«¹úµÄµçÁ¦¹«Ë¾ÏÖ´úµçÆø¡£


Ô­ÎÄÁ´½Ó£º

https://www.anomali.com/blog/aggah-using-compromised-websites-to-target-businesses-across-asia-including-taiwan-manufacturing-industry


Check PointÐû²¼ºÚ¿ÍÍÅ»ïIndra¹¥»÷»î¶¯.jpg


Check PointÐû²¼ºÚ¿ÍÍÅ»ïIndra¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß


  Check PointÐû²¼ÁËÓйغڿÍÍÅ»ïIndra¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß¡£Ñо¿ÈËÔ±·ÖÎöÁË2021Äê7ÔÂ9ÈÕÖÁ10ÈÕ¶ÔÒÁÀÊ»ð³µÏµÍ³µÄÍøÂç¹¥»÷Áôϵĺۼ££¬²¢½«´Ë´Î¹¥»÷¹éÒòÓÚÒ»¸ö×Ô³ÆÎªIndraµÄºÚ¿ÍÍŻ³ÂËßÖ¸³ö£¬¸ÃÍŻﻹÓë2019ÄêºÍ2020ÄêÕë¶ÔÐðÀûÑǶà¼Ò¹«Ë¾µÄ¹¥»÷ÓйØ£¬°üÂÞKaterji GroupºÍArfada Petroleum¡£´ËÍ⣬¹¥»÷ÕßÔÚÕâЩÄ꿪·¢ÁËÖÁÉÙ3¸ö²îÒì°æ±¾µÄwiper£¬·Ö±ð³ÆÎªMeteor¡¢StardustºÍComet£¬¸Ã³ÂËß»¹ÏêϸÃèÊöÁ˹¥»÷ÕßʹÓõŤ¾ßºÍTTPs¡£


Ô­ÎÄÁ´½Ó£º

https://research.checkpoint.com/2021/indra-hackers-behind-recent-attacks-on-iran/


KasperskyÐû²¼2021ÄêµÚ¶þ¼¾¶ÈÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß.jpg


KasperskyÐû²¼2021ÄêµÚ¶þ¼¾¶ÈÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß


  KasperskyÐû²¼ÁË2021ÄêµÚ¶þ¼¾¶ÈÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß¡£¸Ã³ÂËß·ÖÎöÁË2021ÄêQ2µÄ¶à¸öÓÐÕë¶ÔÐԵĹ¥»÷»î¶¯£¬°üÂÞÓëCycldekÍÅ»ïÏà¹ØµÄ¹¥»÷»î¶¯£¬ÔÚÒ°ÍâʹÓÃ×ÀÃæ´°¿Ú¹ÜÀíÆ÷ÖÐ0dayµÄ¹¥»÷»î¶¯£¬TunnelSnakeÐж¯£¬PuzzleMaker»î¶¯ºÍFerocious KittenÍÅ»ïÏà¹Ø»î¶¯µÈ¡£´ËÍ⣬³ÂËß»¹·ÖÎöÁ˶à¸ö¶ñÒâÈí¼þ£¬°üÂÞÀÕË÷Èí¼þJSWormºÍBlack Kingdom¡¢ÒøÐÐľÂíGootkitºÍBizarro¡¢APKPureÓ¦ÓÃÖжñÒâ´úÂëºÍBrowser lockersµÈ¡£

Ô­ÎÄÁ´½Ó£º

https://securelist.com/it-threat-evolution-q2-2021/103597/