ºÚ¿ÍÔÚ°µÍø¹ûȻӡ¶ÈBigBasketÔ¼2000Íò¸ö?Óû§µÄÐÅÏ¢£»ThreatpostÐû²¼ÃûΪ2021£ºÀÕË÷Èí¼þµÄÑݱäµÄ³ÂËß
Ðû²¼Ê±¼ä 2021-04-261.ºÚ¿ÍÔÚ°µÍø¹ûȻӡ¶ÈBigBasketÔ¼2000Íò¸öÓû§µÄÐÅÏ¢
BigBasketÊÇÓ¡¶ÈµÄÔÚÏßÔÓ»õÅäËÍ·þÎñ£¬¿ÉÔÚÓû§ÔÚÏß¹ºÖÃÎïÆ·Ö®ºó½«ÆäÔËË͵ּÒÖС£4ÔÂ25ÈÕÇ峿£¬ÖøÃûй¶Êý¾ÝÂô¼ÒShinyHunterÔÚ°µÍøÉÏÐû²¼ÁËÒ»¸ö¾Ý³ÆÊÇ´ÓBigBasket͵ȡµÄÊý¾Ý¿â£¬ÆäÖÐÓÐÁè¼Ý2000Íò¸öÓû§µÄ¼Ç¼£¬°üÂÞµç×ÓÓʼþµØÖ·¡¢SHA1¹þÏ£ÃÜÂë¡¢µØÖ·¡¢µç»°ºÅÂëºÍÆäËûÀàÐ͵ÄÐÅÏ¢µÈ¡£´ËÍ⣬¸ÃºÚ¿Í³ÆÆäÒѾʹÓÃSHA1Ëã·¨ÆÆ½âÁË200Íò¸öÃÜÂ룬ÆäÖÐ70ÍòÃû¿Í»§Ê¹ÓÃÁË¡°password¡±×÷ΪÃÜÂë¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hacker-leaks-20-million-alleged-bigbasket-user-records-for-free/
2.ThreatpostÐû²¼ÃûΪ2021£ºÀÕË÷Èí¼þµÄÑݱäµÄ³ÂËß
ThreatpostÐû²¼ÁËÃûΪ2021£ºÀÕË÷Èí¼þµÄÑݱäµÄ·ÖÎö³ÂËß¡£¸Ã³ÂËß°üÂÞÁËÀÕË÷Èí¼þµÄÐÂÇ÷ÊÆ¡¢ÀÕË÷Èí¼þ¾¼ÃÄÚĻһÀÀ¡¢ÍøÂç±£ÏÕÍÆ¶¯ÀÕË÷Èí¼þÖ§¸¶¼¤Ôö¡¢ÍþвÊÓ²ì:ÀÕË÷Èí¼þ¹¥»÷µÄ´ú¼Û¡¢48СʱÀÕË÷Èí¼þ¹¥»÷ÈռǺÍÖÆÖ¹ÀÕË÷Èí¼þµÄʵÓÃÖ¸Äϵȶà¸ö²¿ÃÅ¡£³ÂËßÖ¸³ö£¬¶ÔÉÌÒµ¡¢Ñ§Ð£ºÍÕþ¸®»ú¹¹µÄ¹öÑ©ÇòʽµÄ¹¥»÷ÏÖÔÚÊÇÖ÷ÒªµÄÍøÂçÄþ¾²ÎÊÌâ¡£¶øÇÒËæ×ÅÀÕË÷Èí¼þ¹¥»÷ÐÔÖʵIJ»Í£±ä»¯£¬Äþ¾²ÔËάҲ±äµÃÔ½·¢ÅÓ´ó£¬ÀýÈçSunCryptµÈÍÅ»ïÌᳫ¾Ü¾ø·þÎñ(DoS)¹¥»÷À´¸øÊܺ¦Õßʩѹ¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/ebook-2021-ransomware-emerging-risks/165477/
3.IvantiÐû²¼ÓйضþάÂëÄþ¾²ÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß
IvantiÐû²¼ÁËÓйضþάÂëÄþ¾²ÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß¡£¸ÃÑо¿ÔÚ½ñÄê2Ô¶ÔÃÀ¹ú¡¢Ó¢¹ú¡¢·¨¹ú¡¢µÂ¹ú¡¢ÖйúºÍÈÕ±¾µÄ4100¶àÃûÏû·ÑÕß½øÐÐÁËÊӲ졣³ÂËßÏÔʾ£¬ÓÐ57£¥µÄÊÜ·ÃÕßÉù³Æ¶þάÂëµÄʹÓÃÓÐËùÔö¼Ó£¬83£¥µÄÊÜ·ÃÕßÔòÌåÏÖËûÃÇÔÚÈ¥ÄêµÚÒ»´ÎʹÓöþάÂë½øÐи¶¿î»ò½»Òס£´ËÍ⣬³ÂËßÖ¸³öºÚ¿Í¿ÉÒÔͨ¹ý¶þάÂëµ¼ÖµÄÄþ¾²·çÏÕ°üÂÞÌí¼ÓÁªÏµÈËÁÐ±í¡¢´òµç»°¡¢·¢ËͶÌÐÅ¡¢±àдµç×ÓÓʼþ¡¢¸¶¿î¡¢ÏÔʾÓû§µÄλÖᢹØ×¢É罻ýÌåÕÊ»§ºÍÌí¼ÓÊ×Ñ¡µÄWi-FiÍøÂç¡£
ÔÎÄÁ´½Ó£º
https://www.ivanti.com/blog/the-global-pandemic-has-led-to-unprecedented-qr-code-security-challenges
4.ºÚ¿ÍαÔìMicrosoft DirectX 12ÍøÕ¾·Ö·¢¶ñÒâÈí¼þ
ºÚ¿Í´´½¨ÁËÒ»¸öÐé¼ÙµÄMicrosoft DirectX 12ÏÂÔØÍøÕ¾£¬À´·Ö·¢ÇÔÈ¡¼ÓÃÜ»õ±ÒÇ®°üºÍÃÜÂëµÄ¶ñÒâÈí¼þ¡£¸ÃÍøÕ¾»¹ÓÐÁªÏµ±í¸ñ¡¢Òþ˽ȨÕþ²ß¡¢ÃâÔðÉùÃ÷ºÍDMCAÇÖÈ¨Ò³Ãæ£¬µ«ÊÇÍøÕ¾ºÍ·Ö·¢µÄ·¨Ê½¾ùûÓкϷ¨ÒÀ¾Ý¡£µ±Óû§µã»÷ÏÂÔØ°´Å¥Ê±»á±»Öض¨Ïòµ½Ò»¸öÍâ²¿Ò³Ãæ£¬À´ÏÂÔØ¶ñÒâÈí¼þ¡£¸Ã¶ñÒâÈí¼þÊÔͼ»ñÈ¡Êܺ¦ÕßµÄCookie¡¢Îļþ¡¢ÓйØÏµÍ³µÄÐÅÏ¢¡¢ÒѰ²×°µÄ·¨Ê½ºÍµ±Ç°×ÀÃæµÄÆÁÄ»½ØÍ¼£¬ÒÔ¼°WindowsÈí¼þµÄÖÖÖÖ¼ÓÃÜ»õ±ÒÇ®°ü£¬ÀýÈçLedger Live¡¢Waves.ExchangeºÍCoinomiµÈ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/fake-microsoft-directx-12-site-pushes-crypto-stealing-malware/
5.FacebookÅû¶½üÆÚ2¸ö°ÍÀÕ˹̹ºÚ¿ÍÍÅ»ïµÄ¼äµý»î¶¯
Facebook½üÆÚ·¢ÏÖÁË2¸ö·Ö±ðÔÚ2019ÄêºÍ2020Ä꿪ʼ»îÔ¾µÄ°ÍÀÕ˹̹ºÚ¿ÍÍÅ»ïµÄ¼äµý»î¶¯¡£ÕâÁ½¸ö×éÖ¯Ö®¼äËÆºõûÓÐÁªÏµ£¬µ«ËüÃǵÄÄ¿µÄËÆºõÏà·´¡£ËûÃǾùÀûÓÃÁËiOS¼äµýÈí¼þ£¬²¢ÒÔFacebookµÈÉ罻ýÌåÆ½Ì¨ÎªÆðµã£¬ÓëÄ¿±ê½¨Á¢ÁªÏµ²¢ÌᳫÉç»á¹¤³Ì¹¥»÷£¬ÓÕʹËûÃǽøÈëµöÓãÒ³ÃæºÍÆäËû¶ñÒâÍøÕ¾¡£Ñо¿ÈËÔ±ÍÆ¶ÏÆäÖÐÖ®Ò»Óë°ÍÀÕ˹̹Äþ¾²»ú¹¹Óйأ¬ÔÚÍÁ¶úÆä¡¢ÒÁÀ¿Ë¡¢Àè°ÍÄÛºÍÀû±ÈÑÇÒ²Óй¥»÷»î¶¯¡£ÁíÒ»×éÓëArid ViperÓйأ¬Ö÷ÒªÕë¶Ô·¨ËþºÕÕþµ³³ÉÔ±¡¢Õþ¸®¹ÙÔ±¡¢Äþ¾²¶ÓÎéºÍѧÉú¡£
ÔÎÄÁ´½Ó£º
https://www.wired.com/story/palestine-hacking-ios-custom-spyware/
6.Ìṩ¶©Æ±ÏµÍ³µÄRadixxÔâµ½¹¥»÷£¬Ó°Ïì20¶à¼Òº½¿Õ¹«Ë¾
Sabre CorporationµÄ×Ó¹«Ë¾RadixxÔÚ4ÔÂ22ÈÕÐû²¼£¬Radixx Res?ÔÚ4ÔÂ20ÈÕÔâµ½Á˹¥»÷£¬Ó°ÏìÁËÆäÔ¤¶©ÏµÍ³¡£RadixxÖ÷ҪΪÁ®¼Ûº½¿Õ¹«Ë¾Ìṩ»úƱ¶©Æ±ÏµÍ³£¬´Ë´ÎʼþÓ°ÏìÁË20¼Òº½¿Õ¹«Ë¾£¬°üÂÞÈÕ±¾Peach AviationºÍZIPAIR¡¢±ÈÀûʱº½¿Õ¡¢ÖÇÀûSky AirlinesºÍ¼ÓÄôóAir TransatµÈ¹«Ë¾£¬µ¼ÖÂËûÃǵĴî¿ÍÎÞ·¨Í¨¹ýº½¿Õ¹«Ë¾µÄÍøÕ¾À´Ô¤¶©¡¢¸ü¸Ä¡¢É¾³ýºÍÈ·ÈÏ»úƱ¡£
ÔÎÄÁ´½Ó£º
https://www.databreaches.net/malware-attack-on-radixx-res-disrupts-20-airlines-ticket-reservation-systems/