΢ÈíÈÏ¿ÉÔøÇ©Ê𺬶ñÒârootkitµÄÇý¶¯·¨Ê½Netfilter£»ºÚ¿ÍÔÚRaidForums³öÊÛ7ÒÚ¶àÌõLinkedInÓû§µÄ¼Ç¼

Ðû²¼Ê±¼ä 2021-06-29

1.ºÚ¿ÍÔÚRaidForums³öÊÛ7ÒÚ¶àÌõLinkedInÓû§µÄ¼Ç¼


1.jpg


Privacy SharksÑо¿ÈËÔ±·¢ÏÖÃûΪ¡°GOD User TomLiner¡±µÄºÚ¿ÍÕýÔÚRaidForumsÉϳöÊÛLinkedInÓû§µÄÊý¾Ý¡£¸Ã¹ã¸æÓÚ6ÔÂ22ÈÕÐû²¼ £¬Éù³Æ°üÂÞ7ÒÚÌõ¼Ç¼ £¬²¢¹ûÈ»ÁË100ÍòÌõÑù±¾×÷Ϊ֤¾Ý¡£´Ë´Îй¶µÄÐÅÏ¢°üÂÞ·¢ÏּǼ°üÂÞÈ«Ãû¡¢ÐԱ𡢵ç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂëºÍÐÐÒµÐÅÏ¢¡£Ä¿Ç°Éв»Çå³þÊý¾ÝµÄÀ´Ô´ÊÇʲô £¬µ«Ñо¿ÈËÔ±ÍÆ²â´Ë´ÎÊý¾Ýй¶Óë4Ô·ݳöÊÛµÄ5ÒÚÌõLinkedIn¼Ç¼¿ÉÄÜÊÇͬһÀ´Ô´¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/data-700m-linkedin-users-cyber-underground/167362/


2.WolfeÑÛ¿ÆÒ½Ôº³ÆÆäÔâµ½¹¥»÷ £¬Ô¼50Íò¿Í»§ÐÅϢй¶


2.jpg


WolfeÑÛ¿ÆÒ½ÔºÓÚÉÏÖܶþÌåÏÖÆäÔâµ½¹¥»÷ £¬Ô¼50Íò¿Í»§ÐÅϢй¶¡£Wolfe Eye ClinicλÓÚ°®ºÉ»ªÖÝÂíЪ¶û¶Ø £¬ÔÚÈ«ÖÝ40¸ö¶¼ÊоùÉèÓзÖÖ§»ú¹¹¡£¹¥»÷·¢ÉúÓÚ2021Äê2ÔÂ8ÈÕ £¬ºÚ¿ÍÒªÇó¸ÃÒ½ÔºÖ§¸¶Êê½ðÀ´½âÃÜÆäϵͳ £¬µ«Æä²¢Î´Ö§¸¶¡£ÔÚ·¢ÏÖÈëÇÖºó £¬Ò½ÔºÁ¢¿ÌÕ¹¿ªÊÓ²ì £¬²¢ÓÚÉϸöÔ·¢ÏÖ»¼Õ߼Ǽ¿ÉÄÜÒѱ»Ð¹Â¶¡£¸ÃÒ½Ôº½«ÎªÊÜÓ°ÏìµÄ»¼ÕßÌṩһÄêµÄÐÅÓÃ¼à¿ØºÍÉí·ÝµÁÓñ£»¤·þÎñ¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/cyberattack-exposes-eye-clinic/


3.΢ÈíÈÏ¿ÉÆäÔøÇ©Ê𺬶ñÒârootkitµÄÇý¶¯·¨Ê½Netfilter


3.jpg


΢ÈíÈÏ¿ÉÆäÇ©ÊðµÄÓÃÓÚWindowsµÄµÚÈý·½Çý¶¯·¨Ê½Netfilter°üÂÞ¶ñÒârootkit¡£ÉÏÖÜ £¬G DataµÄÄþ¾²¾¯±¨ÏµÍ³±êÖ¾ÁËÒ»¸ö¿´ËÆÎ󱨵«Êµ¼ÊÉϲ¢·ÇÈç´ËµÄÇý¶¯·¨Ê½Netfilter¡£Ñо¿ÈËÔ±·¢ÏÖ £¬¸ÃÓ¦ÓõĵÚÒ»¸öC2 URL»á·µ»ØÒ»×é¸ü¶àµÄ·ÓÉ£¨URL£© £¬ËüÃÇÓɹܵÀ£¨¡°|¡±£©·ûºÅÀ뿪 £¬ÆäÖÐÿһ¸ö¶¼Óе¥¶ÀÄ¿µÄ £¬ÀýÈçÒÔ¡°/p¡±½áβµÄURLÓëÊðÀíÉèÖÃÏà¹ØÁª¡¢"/s"Ìṩ±àÂëµÄÖØ¶¨ÏòIP¡¢¡°/v £¿¡±Óë¶ñÒâÈí¼þµÄ×ÔÎÒ¸üй¦Ð§ÓйØ¡£¹¥»÷Õß¿Éͨ¹ýÌØÖÆµÄ¶þ½øÖÆÎļþÀûÓøÃÓ¦Óà £¬Ìᳫ´ó¹æÄ£µÄ¹©Ó¦Á´¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/microsoft-netfilter-driver-sign-rootkit-malware/


4.ÃÀ¹úFINRA¾¯¸æÎ±×°³ÉFINRA SupportµÄµöÓã¹¥»÷»î¶¯


4.jpg


ÃÀ¹ú֤ȯҵ¼à¹Ü»ú¹¹FINRA¾¯¸æÎ±×°³ÉFINRA SupportµÄµöÓã¹¥»÷»î¶¯¡£FINRAÊÇÕþ¸®ÊÚȨµÄ·ÇÓªÀû×éÖ¯ £¬ÂôÁ¦¼à¹ÜÔÚÃÀ¹ú¹ûÈ»»î¶¯µÄËùÓн»Ò×ËùÊг¡ºÍ֤ȯ¹«Ë¾ £¬Ã¿Ìì·ÖÎöÊýÊ®ÒÚ¸öÊг¡½»Òס£ÕâЩÓʼþÉù³ÆÀ´×Ô¡°FINRA SUPPORT¡± £¬µØÖ·Îª¡°support@westour.org¡±¡£¸ÃÓʼþÒªÇóÊÕ¼þÈË×¢ÒâÏÂÃæËù¸½µÄ³ÂËß²¢Á¢¼´»Ø¸´ £¬»¹Ö¸³ö¸½¼þ°üÂÞ¸üÐµĹ«¹²Õþ²ßÐÅÏ¢ £¬µ«ÕâЩµç×ÓÓʼþ¿ÉÄÜ»ù´¡Ã»Óи½¼þ¡£ÔçÔÚ½ñÄê3ÔºÍ6Ô³õ £¬FINRA»¹¾¯¸æÁËαÔì³É¡°FINRAºÏ¹æÉ󼯡±ºÍÒÔ´¦·£ÎªÓÕ¶üµÄÁ½´ÎµöÓã»î¶¯¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/us-brokerage-firms-warned-of-finra-support-phishing-attacks/


5.Ó¢¹úFrench Connection³ÆÆäÔâµ½REvilÀÕË÷Èí¼þ¹¥»÷


5.jpg


Ó¢¹úʱÉй«Ë¾French Connection£¨FCUK£©³ÆÆäÔâµ½REvilÀÕË÷Èí¼þ¹¥»÷¡£Ôڴ˴ι¥»÷ÖÐ £¬ºÚ¿ÍÆÆ»µÁËFCUKµÄ·þÎñÆ÷ £¬ÇÔÈ¡¹«Ë¾µÄ´óÁ¿Êý¾Ý £¬²¢¹ûÈ»Á˸߹ܵĸöÈËÐÅÏ¢×÷ΪÑù±¾ £¬°üÂÞÊ×´´È˼æCEO Stephen Marks¡¢CFO Lee WilliamsºÍCOO Neil WilliamsµÄ»¤ÕÕºÍÉí·Ý֤ɨÃè¼þ¡£¸Ã¹«Ë¾ÌåÏÖ £¬ÔÚ·¢ÏÖ¹¥»÷ºóÁ¢¼´¹Ø±ÕÁËËùÓÐÊÜÓ°ÏìµÄϵͳ £¬Ä¿Ç°ÕýÔÚ»Ö¸´Æäϵͳ¡£


Ô­ÎÄÁ´½Ó£º

https://www.theregister.com/2021/06/24/french_connection_says_fcuk_as/


6.Aqua SecurityÐû²¼Õë¶ÔÈÝÆ÷µÄ¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß


6.jpg


Aqua SecurityÐû²¼ÁËÕë¶ÔÈÝÆ÷µÄ¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö £¬ÔÚÁù¸öÔµÄʱ¼äÀï £¬AquaµÄÃÛ¹Þ±»¹¥»÷ÁË17358 ´Î £¬±ÈÁù¸öÔÂǰÔö¼ÓÁË26%¡£50%ÅäÖôíÎóµÄDocker APIÔÚ56·ÖÖÓÄÚ»áÔâµ½¹¥»÷ £¬»úÆ÷ÈËÆ½¾ùÐèÒªÎå¸öСʱÀ´É¨ÃèÒ»¸öеÄÃÛ¹Þ £¬×î¿ìµÄɨÃèÖ»ÐèÒª¼¸·ÖÖÓ £¬¶ø×îÂýµÄɨÃèÐèÒª24Сʱ¡£ÓòÃûÇÀ×¢ºÍƾ֤Ìî³äÊǹ¥»÷Õß¹¥»÷ÈÝÆ÷ºÍDocker¾µÏñ×î³£¼ûµÄÁ½ÖÖ·½Ê½ £¬ÓëÈ¥ÄêͬÆÚÏà±È £¬2020ÄêϰëÄêµÄ¹¥»÷ÂÊÉÏÉýÁ˽ü600%¡£


Ô­ÎÄÁ´½Ó£º

https://info.aquasec.com/cloud-native-threats-aqua