ºÚ¿ÍÔÚ°µÍø³öÊÛÁè¼Ý8Íò¸öSQLÊý¾Ý¿â£¬£¬£¬£¬£¬£¬Ã¿¸ö550ÃÀÔª£»£»Î¢ÈíÅûÂ¶ÔøÐ®ÖÆ¹ýChromeºÍEdgeµÈä¯ÀÀÆ÷µÄAdrozek

Ðû²¼Ê±¼ä 2020-12-11
1.ºÚ¿ÍÔÚ°µÍø³öÊÛÁè¼Ý8Íò¸öSQLÊý¾Ý¿â£¬£¬£¬£¬£¬£¬Ã¿¸ö550ÃÀÔª


1.jpg


ºÚ¿ÍÔÚ°µÍøÒÔÿ¸ö550ÃÀÔªµÄ¼ÛÇ®³öÊÛÁè¼Ý85000¸öSQLÊý¾Ý¿â¡£¡£¡£¡£¡£ºÚ¿Í×éÖ¯ÔÚÒ»Ö±µØÈëÇÖMySQLÊý¾Ý¿â£¬£¬£¬£¬£¬£¬ÏÂÔØ±í¸ñ£¬£¬£¬£¬£¬£¬É¾³ýԭʼÎĵµ£¬£¬£¬£¬£¬£¬²¢ÁôÏÂÊê½ð¼Í¼£¬£¬£¬£¬£¬£¬Í¨ÖªÊܺ¦ÕßÓëÆäÁªÏµÒÔÈ¡»ØÆäÊý¾Ý¡£¡£¡£¡£¡£ÈôÊÇÊܺ¦ÕßÔÚ¾ÅÌìÄÚûÓи¶¿î£¬£¬£¬£¬£¬£¬ËûÃǵÄÊý¾Ý½«ÔÚÊý¾ÝÐ¹Â¶ÍøÕ¾±»ÅÄÂô¡£¡£¡£¡£¡£Ëæ×ÅÊܺ¦ÕßÊýÄ¿µÄÔö¶à£¬£¬£¬£¬£¬£¬¹¥»÷Õß×îÏÈʹÓÃ×Ô¶¯»¯µÄÈëÇÖÁ÷³ÌºÍÅÄÂôÍøÒ³£¬£¬£¬£¬£¬£¬²¢²»»áÆÊÎö±»ÈëÇÖµÄÊý¾Ý¿âÖеÄÊý¾Ý¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬ÕâЩÊý¾Ý¿âµÄÊÛ¼Û»áËæ×ÅBTC/ USD»ãÂʵIJ¨¶¯ÓÐËùת±ä£¬£¬£¬£¬£¬£¬µ«Í¨³£Ê¼ÖÕ¼á³ÖÔÚ500ÃÀÔª×óÓÒ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hackers-are-selling-more-than-85000-sql-databases-on-a-dark-web-portal/


2.΢ÈíÅûÂ¶ÔøÐ®ÖÆ¹ýChromeºÍEdgeµÈä¯ÀÀÆ÷µÄAdrozek


2.jpg


΢ÈíÅû¶ÁËÔøÐ®ÖÆ¹ýChrome¡¢EdgeºÍFirefoxµÄ¶ñÒâÈí¼þAdrozek¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ´Ó2020Äê5ÔÂ×îÏÈ»îÔ¾£¬£¬£¬£¬£¬£¬ÔÚ8Ôµִïá¯ÁëʱÆÚ£¬£¬£¬£¬£¬£¬ÌìÌì¿ÉÐ®ÖÆÁè¼Ý30000̨װ±¸¡£¡£¡£¡£¡£Æ¾Ö¤ÄÚ²¿Ò£²â£¬£¬£¬£¬£¬£¬Êܺ¦ÕßÖ÷Òª¼¯ÖÐÔÚÅ·ÖÞ£¬£¬£¬£¬£¬£¬Æä´ÎÊÇÄÏÑǺͶ«ÄÏÑÇ¡£¡£¡£¡£¡£Î¢ÈíÌåÏÖ£¬£¬£¬£¬£¬£¬AdrozekÊÇͨ¹ýdrive-byµÄ·½·¨Èö²¥µÄ¡£¡£¡£¡£¡£ÀÖ³É×°Öúó¸Ã¶ñÒâÈí¼þ½«Ñ°ÕÒÍâµØ×°ÖõÄä¯ÀÀÆ÷£¬£¬£¬£¬£¬£¬²¢ÊÔͼÐÞ¸Ää¯ÀÀÆ÷µÄAppDataÎļþ¼ÐÇ¿ÖÆ×°ÖÃÀ©Õ¹£¬£¬£¬£¬£¬£¬±ðµÄËü»¹»áÐÞ¸ÄһЩä¯ÀÀÆ÷µÄDLLÎļþÀ´¸ü¸ÄÆäÉèÖò¢½ûÓÃÇå¾²ÌØÕ÷¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/microsoft-exposes-adrozek-malware-that-hijacks-chrome-edge-and-firefox/


3.ºÚ¿Í½«ÐÅÓÿ¨ÇÔÈ¡¾ç±¾Òþ²ØÔÚCSS´úÂëÖÐÀ´Èƹý¼ì²â


3.jpg


Çå¾²¹«Ë¾SansecµÄÑо¿Ö°Ô±·¢Ã÷ºÚ¿Í½«ÐÅÓÿ¨ÇÔÈ¡¾ç±¾Òþ²ØÔÚCSS´úÂëÖÐÀ´Èƹý¼ì²â¡£¡£¡£¡£¡£¹ºÎïÕßµã»÷½áÕÊʱ£¬£¬£¬£¬£¬£¬½«±»Öض¨Ïòµ½Ò»¸ö¼ÓÔØ²¢ÆÊÎö¶ñÒâCSS´úÂëµÄÐÂÒ³Ãæ£¬£¬£¬£¬£¬£¬È»ºó£¬£¬£¬£¬£¬£¬ºÚ¿ÍʹÓñ»ÈëÇÖµÄÒ³ÃæÉϵÄJavaScriptÆÊÎöÆ÷¼ÓÔØ²¢Ö´ÐÐCSS´úÂëÖеĶñÒâ¾ç±¾¡£¡£¡£¡£¡£Í¨¹ý´ËÖÖÒªÁ죬£¬£¬£¬£¬£¬¿ÉÀֳɵØÈƹý×Ô¶¯Ç徲ɨÃèÆ÷µÄ¼ì²â£¬£¬£¬£¬£¬£¬²¢ÇÒ×ÝÈ»ÔÚÊÖ¶¯Çå¾²´úÂëÉó¼ÆÖÐÒ²ºÁÎÞÆÆÕÀ¡£¡£¡£¡£¡£SansecÌåÏÖ£¬£¬£¬£¬£¬£¬Î´À´¹¥»÷Õß¿ÉÄÜ»¹»áʹÓÃÆäËûµØ·½µÄ¾²Ì¬Êý¾Ý¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/credit-card-stealer-hides-in-css-files-of-hacked-online-stores/


4.APT28ʹÓÃÒÔCOVID-19ΪÖ÷ÌâµÄ´¹ÂÚ¹¥»÷·Ö·¢Zebrocy


4.jpg


Çå¾²¹«Ë¾Intezer·¢Ã÷£¬£¬£¬£¬£¬£¬¶íÂÞ˹ºÚ¿Í×éÖ¯APT28ʹÓÃÒÔCOVID-19ΪÖ÷ÌâµÄ´¹ÂÚ¹¥»÷·Ö·¢¶ñÒâÈí¼þZebrocy¡£¡£¡£¡£¡£´Ë´Î¹¥»÷»î¶¯ÊÇÔÚ11ÔÂÏÂÑ®¾ÙÐеÄ£¬£¬£¬£¬£¬£¬ºÚ¿ÍʹÓÃÒÔCOVID-19ΪÖ÷ÌâµÄ´¹ÂÚµç×ÓÓʼþÀ´·Ö·¢Go°æ±¾µÄZebrocy£¨»òZekapab£©¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ¿É³äµ±ºóÃźÍÏÂÔØÆ÷£¬£¬£¬£¬£¬£¬Äܹ»ÍøÂçϵͳÐÅÏ¢¡¢Îļþ²Ù×÷£¬£¬£¬£¬£¬£¬²¶»ñÆÁÄ»½ØÍ¼²¢Ö´ÐжñÒâÏÂÁ£¬£¬£¬£¬£¬È»ºó½«ÕâЩ¶ñÒâÏÂÁîÈö²¥µ½¹¥»÷Õß¿ØÖƵÄЧÀÍÆ÷¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2020/12/russian-apt28-hackers-using-covid-19-as.html


5.TalosÐû²¼2020ÄêÇï¼¾ÊÂÎñÏìÓ¦Ì¬ÊÆµÄÆÊÎö±¨¸æ


5.jpg


Cisco TalosÐû²¼ÁË2020ÄêÇï¼¾ÊÂÎñÏìÓ¦Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬£¬ÀÕË÷Èí¼þÔÚÍþвÁìÓòÈÔÕ¼ÓÐÖ÷µ¼Ö°Î»£¬£¬£¬£¬£¬£¬¶¥¼¶ÀÕË÷Èí¼þÍÅ»ïÊÇMazeºÍSodinokibi¡£¡£¡£¡£¡£ºÚ¿ÍÕë¶ÔÁËÆÕ±éµÄ±ÊÖ±ÁìÓò£¬£¬£¬£¬£¬£¬°üÀ¨Å©Òµ¡¢Ê³ÎïºÍÒûÁÏ¡¢Ò½ÁƱ£½¡¡¢½ÌÓý¡¢ÄÜÔ´ºÍ¹«ÓÃÊÂÒµ¡¢¹¤Òµ·ÖÏú¡¢Ö´·¨¡¢µØ·½Õþ¸®¡¢ÖÆÔìÒµºÍÊÖÒÕ¡£¡£¡£¡£¡£Ö÷ҪĿµÄÊÇÖÆÔìÒµ¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬ÓÉÓÚCOVID-19µÄ±¬·¢£¬£¬£¬£¬£¬£¬Õë¶ÔÎÀÉú±£½¡×éÖ¯µÄ¹¥»÷»î¶¯¼¤Ôö¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2020/12/quarterly-ir-report-fall-2020-q4.html


6.AdobeÇå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´Èý¿î²úÆ·ÖеĶà¸öÎó²î


6.jpg


AdobeÇå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËLightroom¡¢PreludeºÍExperience ManageÖеĶà¸öÎó²î¡£¡£¡£¡£¡£´Ë´ÎÐÞ¸´µÄÎó²î°üÀ¨µ¼ÖÂí§Òâ´úÂëÖ´ÐеIJ»ÊÜ¿ØËÑË÷·¾¶ÔªËØÎó²î£¨CVE-2020-24447£©£¬£¬£¬£¬£¬£¬²»ÊÜ¿ØÖƵÄËÑË÷·¾¶ÒýÆðµÄí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2020-24440£©£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÔÚä¯ÀÀÆ÷ÖÐí§ÒâÖ´ÐÐJavaScriptµÄ´æ´¢ÐÍXSSÎó²î£¨CVE-2020-24445£©ÒÔ¼°¿Éµ¼ÖÂÐÅϢй¶µÄÇëÇóαÔìÎó²î£¨CVE-2020-24444£©¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/adobe-security-update-squashes-critical-vulnerabilities-in-lightroom-prelude/